Skip to content
Conference

Mitigating Sybil Attacks in V2X Communication Through Cryptographic Trust Anchors

Jul 2026 · International Conference on Future Internet of Things and Cloud · pp. 81-87 · 0 citations · 18 references

Abstract

Vehicle-to-Everything (V2X) communication enables vehicles to exchange safety-critical messages, but its reliance on temporary pseudonymous identities makes it vulnerable to Sybil attacks, where a single attacker fabricates multiple identities to inject false information into the network. This paper presents a lightweight cryptographic mechanism that combines SHA-256 Proof-of-Work token mining with a time-windowed ratecontrol layer to limit the number of new identities a vehicle can activate within a given interval. The mechanism was implemented in Java and evaluated through a parametric simulation across three independent variables: PoW difficulty, rate limit, and attack intensity. Results show that a difficulty of 4 and a rate limit of 5 tokens per 10-second window provide an effective balance between Sybil resistance and legitimate vehicle access in an 8-vehicle scenario, with an average mining time of 0.227 seconds. The evaluation identifies the rate-control layer as the primary security mechanism, while PoW difficulty increases the computational cost per identity without independently capping accepted tokens. The proposed approach is infrastructure-free and suitable for regulated V2X deployments where attackers represent a minority of the network.

View source

Similar papers

Open access 2026

Lightweight Distributed Sybil Detection and Whitewashing Mitigation in MANETs Using Mobility Correlation

—Characteristics of Mobile Ad Hoc Networks (MANETs), such as decentralized architecture, shared communication medium, and node mobility, make them vulnerable to a variety of security threats. Sybil attack is one of the most challenging threats in which a malicious node pretends to be multiple distinct nodes to gain disproportionate resources and disrupt network functionalities. Several traditional solutions have been proposed in the literature, but they are either extensive in resource consumption or inadequate for the MANET context. This paper introduces a distributed lightweight method that exploits Sybil identities’ mobility correlation to detect the attack. It disseminates detection results using a lightweight hashing function. In addition, it uses a probation period to mitigate whitewashing attempts. Simulations using the INET framework under the OMNeT++ simulator, and an independent cross-validation under NS-3, reveal high detection accuracy up to 99.79% with a false positive rate of 0%. Our method can operate as a standalone solution or be integrated into existing routing protocols or IDSs.

Samir Selmane, Abderrahmane Baadache, Fouzi Semchedine · 0 citations
Open access Oct 2026

Implicit end-point attestation for trusted channel establishment in the keystone TEE

Nowadays, various contexts and applications include IoT devices. Due to their limited resources and power constraints, these systems are a possible threat vector that adversaries may exploit for cyberattacks. Despite the protection of network communication with Secure Channels, such as TLS and IPsec, the endpoint with which we exchange information may still be compromised. Thus, an adversary may obtain access to sensitive information or send corrupted data without being detected by the other network nodes. Remote Attestation is a possible security control that can detect device misbehaviours, allowing an external entity to verify a platform’s trustworthiness. Attestation reports contain system measures and configuration information to prove the system state. So, the external entity can verify the platform’s authenticity and integrity by comparing the data included in the report with the corresponding expected values. Several solutions addressing this issue are presented in the literature, including Remote Attestation over secure channels. Trusted Channels is the name given to these protocols, as the trustworthiness of the endpoints is a security property guaranteed by the Channel, in addition to the properties of a secure channel. This paper proposes a new certification protocol for IoT devices that merges Remote Attestation with the issuance of a certificate for a key pair generated and stored securely on the platform. This new credential enables the establishment of TLS channels; therefore, the other endpoint obtains information about the node’s trustworthiness. We implemented the protocol within the Keystone framework, which enables a customisable Trusted Execution Environment that provides the Remote Attestation mechanism.

Giacomo Bruno, S. Sisinni, Enrico Bravi et al. · 0 citations

SUST Journal of Science and Technology

A hybrid key exchange protocol combining DHKE with Learning With Errors (LWE), a lattice-based post-quantum primitive that provides authentication via a Public Key Infrastructure together with CRYSTALS-Dilithium digital signature, resilience against MITM attacks, and robustness against classical and quantum threats.

A. K. M. Fakhrul Hossain, Article Info · 0 citations
Open access Jul 2026

Differentially private federated adversarial learning–based intrusion prevention for V2X communications

The suggested DP-FAL model is a privacy-conserving, scalable, and robust intrusion prevention system that can be used real-time V2X conditions and has the potential to be deployed safely, reliably, and sustainably in next-generation transportation systems.

S. Sonker, V. K. Raina, B. B. Sagar et al. · 0 citations
Review 2026

Improving resistance to Sybil attacks in decentralized networks using the RTCT protocol

This paper proposes Random Time Challenge-Tokens (RTCT) as a mechanism to economically enforce honest participation and deter Sybil attacks at the network level, and shows that RTCT can exponentially increase an attacker’s costs with higher challenge difficulty, making networks more resilient.

I. Parkhomenko, Larysa Myrutenko, Roman Ohiievych et al. · 0 citations
Open access Aug 2026

LCMA: lightweight cross-domain mutual authentication scheme for Internet of Vehicles

The Internet of Vehicles (IoV) facilitates real-time information exchange through vehicle-to-everything (V2X) communications, thereby enhancing traffic safety and operational efficiency. However, high mobility, frequent handovers, and cross-domain access impose rigorous demands on authentication latency, scalability, and credential management. Many existing authentication and key agreement (AKA) schemes necessitate the online involvement of a trusted authority (TA), which can lead to communication bottlenecks and create a single point of failure. Additionally, many physical unclonable function (PUF)-based schemes continue to depend on centralized challenge–response pairs (CRPs) or require online CRP queries, which obstruct their implementation in dynamic cross-domain environments. To tackle these challenges, this paper introduces a lightweight cross-domain mutual authentication scheme (LCMA) for IoV. LCMA integrates a PUF-based hardware-rooted authentication mechanism with a rolling verifier-state update mechanism. This design reduces the need to maintain a large-scale pre-stored CRP database while avoiding repeated reuse of static authentication materials. Furthermore, it employs a decoupled trust architecture in which the TA is engaged solely in secure offline registration, system initialization, and conditional traceability, while online authentication and session-key establishment are conducted by vehicles and authorized roadside units (RSUs). ROR-based analysis demonstrates session-key indistinguishability under the specified adversarial assumptions, while AVISPA verification within the Dolev–Yao model confirms the goals of authentication and secrecy. Performance evaluations indicate that LCMA achieves low computational and communication overhead in comparison with representative schemes. Under a load of 10,000 vehicles, it maintains an average authentication latency of 2.154 ms, thereby illustrating its appropriateness for highly dynamic cross-domain IoV environments.

Xiyuan Ma, Junbeom Hur · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.