LCMA: lightweight cross-domain mutual authentication scheme for Internet of Vehicles
The Internet of Vehicles (IoV) facilitates real-time information exchange through vehicle-to-everything (V2X) communications, thereby enhancing traffic safety and operational efficiency. However, high mobility, frequent handovers, and cross-domain access impose rigorous demands on authentication latency, scalability, and credential management. Many existing authentication and key agreement (AKA) schemes necessitate the online involvement of a trusted authority (TA), which can lead to communication bottlenecks and create a single point of failure. Additionally, many physical unclonable function (PUF)-based schemes continue to depend on centralized challenge–response pairs (CRPs) or require online CRP queries, which obstruct their implementation in dynamic cross-domain environments. To tackle these challenges, this paper introduces a lightweight cross-domain mutual authentication scheme (LCMA) for IoV. LCMA integrates a PUF-based hardware-rooted authentication mechanism with a rolling verifier-state update mechanism. This design reduces the need to maintain a large-scale pre-stored CRP database while avoiding repeated reuse of static authentication materials. Furthermore, it employs a decoupled trust architecture in which the TA is engaged solely in secure offline registration, system initialization, and conditional traceability, while online authentication and session-key establishment are conducted by vehicles and authorized roadside units (RSUs). ROR-based analysis demonstrates session-key indistinguishability under the specified adversarial assumptions, while AVISPA verification within the Dolev–Yao model confirms the goals of authentication and secrecy. Performance evaluations indicate that LCMA achieves low computational and communication overhead in comparison with representative schemes. Under a load of 10,000 vehicles, it maintains an average authentication latency of 2.154 ms, thereby illustrating its appropriateness for highly dynamic cross-domain IoV environments.