LCMA: lightweight cross-domain mutual authentication scheme for Internet of Vehicles

The Internet of Vehicles (IoV) facilitates real-time information exchange through vehicle-to-everything (V2X) communications, thereby enhancing traffic safety and operational efficiency. However, high mobility, frequent handovers, and cross-domain access impose rigorous demands on authentication latency, scalability, and credential management. Many existing authentication and key agreement (AKA) schemes necessitate the online involvement of a trusted authority (TA), which can lead to communication bottlenecks and create a single point of failure. Additionally, many physical unclonable function (PUF)-based schemes continue to depend on centralized challenge–response pairs (CRPs) or require online CRP queries, which obstruct their implementation in dynamic cross-domain environments. To tackle these challenges, this paper introduces a lightweight cross-domain mutual authentication scheme (LCMA) for IoV. LCMA integrates a PUF-based hardware-rooted authentication mechanism with a rolling verifier-state update mechanism. This design reduces the need to maintain a large-scale pre-stored CRP database while avoiding repeated reuse of static authentication materials. Furthermore, it employs a decoupled trust architecture in which the TA is engaged solely in secure offline registration, system initialization, and conditional traceability, while online authentication and session-key establishment are conducted by vehicles and authorized roadside units (RSUs). ROR-based analysis demonstrates session-key indistinguishability under the specified adversarial assumptions, while AVISPA verification within the Dolev–Yao model confirms the goals of authentication and secrecy. Performance evaluations indicate that LCMA achieves low computational and communication overhead in comparison with representative schemes. Under a load of 10,000 vehicles, it maintains an average authentication latency of 2.154 ms, thereby illustrating its appropriateness for highly dynamic cross-domain IoV environments.

Authors

Institutions

Publication Details

Journal
Journal of King Saud University - Computer and Information Sciences
Published
2026-08-25
DOI
https://doi.org/10.1007/s44443-026-01194-4
Primary Topic
Vehicular Ad Hoc Networks (VANETs)
Type
article
Field-Weighted Citation Impact
0.00

Funders

Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

LCMA: lightweight cross-domain mutual authentication scheme for Internet of Vehicles

Xiyuan Ma, Junbeom Hur
Journal of King Saud University - Computer and Information Sciences
Vehicular Ad Hoc Networks (VANETs)
article

LCMA: lightweight cross-domain mutual authentication scheme for Internet of Vehicles

Xiyuan Ma, Junbeom Hur
article en

Abstract

The Internet of Vehicles (IoV) facilitates real-time information exchange through vehicle-to-everything (V2X) communications, thereby enhancing traffic safety and operational efficiency. However, high mobility, frequent handovers, and cross-domain access impose rigorous demands on authentication latency, scalability, and credential management. Many existing authentication and key agreement (AKA) schemes necessitate the online involvement of a trusted authority (TA), which can lead to communication bottlenecks and create a single point of failure. Additionally, many physical unclonable function (PUF)-based schemes continue to depend on centralized challenge–response pairs (CRPs) or require online CRP queries, which obstruct their implementation in dynamic cross-domain environments. To tackle these challenges, this paper introduces a lightweight cross-domain mutual authentication scheme (LCMA) for IoV. LCMA integrates a PUF-based hardware-rooted authentication mechanism with a rolling verifier-state update mechanism. This design reduces the need to maintain a large-scale pre-stored CRP database while avoiding repeated reuse of static authentication materials. Furthermore, it employs a decoupled trust architecture in which the TA is engaged solely in secure offline registration, system initialization, and conditional traceability, while online authentication and session-key establishment are conducted by vehicles and authorized roadside units (RSUs). ROR-based analysis demonstrates session-key indistinguishability under the specified adversarial assumptions, while AVISPA verification within the Dolev–Yao model confirms the goals of authentication and secrecy. Performance evaluations indicate that LCMA achieves low computational and communication overhead in comparison with representative schemes. Under a load of 10,000 vehicles, it maintains an average authentication latency of 2.154 ms, thereby illustrating its appropriateness for highly dynamic cross-domain IoV environments.

Journal of King Saud University - Computer and Information SciencesVol. 38(7)
Liaocheng University (CN), Korea University (KR)
National Research Foundation, National Research Foundation of Korea, Liaocheng University, Ministry of Science and ICT, South Korea, Institute for Information and Communications Technology Promotion
Openalex Percentile: Top 19%
Vehicular Ad Hoc Networks (VANETs)
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.