Enhancement of the Privacy-Preserving Authentication Scheme in the PPA6-IoV Protocol
This paper analyzes and enhances PPA6-IoV, a six-step privacy-preserving authentication protocol for the Internet of Vehicles. Formal modeling reveals vulnerabilities to replay, desynchronization, key-compromise impersonation, pseudonym–identity linkage, and weak forward secrecy from elliptic-curve secret reuse. We propose a strengthened variant that uses long-term secrets only as seeds for Diffie-Hellman exchanges, generates salted session-specific pseudonyms, and derives session keys via a context-bound key derivation function. A comparative evaluation of security and performance in large-scale IoV deployments is planned.