Every day, millions of vehicles exchange a constant stream of wireless messages: position reports, hazard warnings, traffic signals, handshake requests with roadside units, and telemetry bound for smart-city control centers. The Internet of Vehicles, or IoV, has quietly become one of the foundational infrastructures of modern urban life, promising smoother traffic, faster emergency response, and safer roads. But the very openness that makes it powerful also makes it vulnerable. Unlike a cable plugged into a wall, a wireless channel can be listened to, spoofed, and jammed by anyone with modest equipment. A new study published in Cluster Computing by Gelare Oudi Ghadim, Parvin Rastegari, Mohammad Dakhilalian, Faramarz Hendessi, and Willy Susilo tackles this problem head-on with a protocol called BAS-IoV, a lightweight, blockchain-based authentication and key agreement scheme designed to keep vehicular networks both secure and fast as they scale to city-wide proportions.
The core weakness the researchers set out to fix is architectural. Most existing authentication schemes for vehicular networks rely on a single Trusted Authority, a central server that vouches for every vehicle and issues the cryptographic credentials needed to join the network. That model works reasonably well when the fleet is small, but it carries two structural flaws that grow worse with scale. First, as the number of vehicles climbs into the hundreds of thousands, the central authority becomes a computational bottleneck: every registration, every credential check, and every revocation must pass through one system. Second, and more dangerously, the authority represents a single point of failure. Compromise that one server, and an attacker can impersonate vehicles, forge safety messages, or silently disable the trust fabric of an entire transportation network. The team’s answer is to distribute trust across multiple Trusted Authorities using a blockchain as the shared, tamper-resistant ledger that lets them cooperate without a single dominant player.
Cross-domain authentication is the technical heart of the proposal. In a realistic smart-city deployment, vehicles do not stay within the jurisdiction of one authority. A car registered in one municipality may drive through neighboring regions, each managed by a different Trusted Authority with its own databases and policies. Under the traditional model, a vehicle crossing such a boundary either cannot authenticate at all or must re-register from scratch, wasting time and bandwidth. BAS-IoV enables what the authors call cross-TA authentication: authorities that have never directly trusted each other can verify a visiting vehicle’s credentials by consulting the blockchain, which records registration and authentication information in a form that no single party can alter retroactively. The result is a network in which trust is portable, and in which the failure or corruption of any one authority cannot cascade through the whole system.
What makes the protocol genuinely notable, however, is how little computation it demands. Blockchain-based security schemes have a reputation problem: they are often heavy, requiring expensive public-key operations that strain the modest processors embedded in vehicles and roadside units. The researchers deliberately built BAS-IoV from efficient cryptographic primitives. Elliptic Curve Cryptography provides strong security with comparatively small keys and fast operations, since the difficulty of the elliptic curve discrete logarithm problem underpins the scheme’s resistance to forgery. Hash functions compress and bind messages together, and XOR operations, among the cheapest operations a processor can perform, are used to combine secrets without costly modular arithmetic. The most intriguing ingredient is the Physical Unclonable Function, or PUF. A PUF exploits the microscopic, random manufacturing variations in a chip’s silicon to produce a device-specific fingerprint: challenge a PUF with an input and it returns an output that is effectively impossible to predict, copy, or duplicate, because no second chip shares the same physical imperfections. By anchoring authentication in hardware-level uniqueness, the protocol gains protection against physical attacks such as key extraction, since no long-term secret is ever stored in memory in a form an attacker could read out.
Security claims in cryptography are cheap; proofs are not. The authors subjected BAS-IoV to a battery of formal verification techniques that represent the current standard of rigor in protocol analysis. Using the Real-or-Random model, a well-established framework for proving the security of authenticated key exchange, they demonstrated that session keys established by the protocol are indistinguishable from random strings to any adversary, which means an eavesdropper who records an entire conversation learns nothing usable about the keys protecting it. They then turned to two automated formal verification tools, Tamarin and ProVerif, which symbolically explore every possible execution path of a protocol, including those involving a powerful attacker who controls the network, to search for hidden flaws. Both tools confirmed the protocol’s resilience against known attack classes, including impersonation, replay, man-in-the-middle, and privileged insider attacks. Formal verification of this kind matters because history is littered with vehicular authentication schemes that looked sound on paper and collapsed under careful cryptanalysis; indeed, the same research group previously published a cryptanalysis of existing IoV message communication protocols, giving them a practitioner’s skepticism toward unproven designs.
Proving security is only half the battle, because a protocol that is safe but slow would strangle a network that depends on millisecond-level message exchange. Vehicular safety applications, such as collision warnings and cooperative braking, require authentication overhead low enough that messages arrive while they are still relevant. To measure real-world performance, the team ran extensive simulations in NS-3, the widely used discrete-event network simulator, evaluating the protocol under large-scale deployments with high vehicle densities. The results showed high throughput, low End-to-End Delay, and a high Packet Delivery Ratio, the three metrics that together determine whether an authentication scheme can keep pace with live traffic rather than becoming the bottleneck it was meant to eliminate. The lightweight design choices, from elliptic curve arithmetic to XOR-based secret combination, translate directly into these favorable network-level numbers.
The implications reach well beyond academic cryptography. Smart cities are investing billions in connected infrastructure, from adaptive traffic lights to autonomous shuttle fleets, and every one of those systems inherits the security assumptions of the underlying vehicular network. A centralized authentication model that buckles under load, or that can be toppled by compromising a single server, is a poor foundation for safety-critical transportation. A distributed model anchored in a blockchain offers a different bargain: trust becomes a shared, auditable record rather than a promise from one institution, and the cost of that assurance is paid in cheap, hardware-accelerated operations rather than heavy computation. For automakers and infrastructure operators weighing how to secure fleets that will only grow, protocols of this kind sketch a plausible migration path from today’s fragmented, authority-bound systems toward something more resilient.
There are, of course, familiar caveats. Blockchain systems introduce their own questions about consensus overhead, ledger growth, and governance, and the study’s evaluation, while thorough in simulation, represents a model of radio conditions and vehicle mobility rather than a live deployment on crowded highways. The authors report that no datasets were generated or analyzed during the study, and the work received no specific external funding, with the analysis resting on simulation and formal proof rather than field trials. Real-world adoption would also require agreement among the many authorities, manufacturers, and regulators whose cooperation any cross-domain scheme implicitly demands, a coordination challenge that no protocol alone can solve.
Even with those qualifications, BAS-IoV is a compelling demonstration that the perceived trade-off between blockchain-grade security and vehicular-grade speed is not inevitable. By combining PUF-based hardware trust, elliptic curve efficiency, formally verified key agreement, and a multi-authority blockchain backbone, the researchers have assembled a design that addresses the two failure modes, centralization and computational cost, that have limited earlier generations of vehicular authentication. As the number of connected vehicles continues its steep climb, and as smart cities stake safety and efficiency on the integrity of wireless messages exchanged between machines, work of this kind moves from the margins of cryptographic literature toward the center of infrastructure engineering. The roads of the future will be governed less by asphalt and signage than by protocols, and studies like this one are writing the rules those protocols will follow.
Subject of Research: Blockchain-based cross-authority authentication and key agreement for secure, scalable Internet of Vehicles communications
Article Title: BAS-IoV: lightweight blockchain-based authentication for secure and scalable internet of vehicles
Article References: Ghadim, G. O., Rastegari, P., Dakhilalian, M., Hendessi, F., & Susilo, W. (2026). BAS-IoV: lightweight blockchain-based authentication for secure and scalable internet of vehicles. Cluster Computing, 29(14), Article 784. https://doi.org/10.1007/s10586-026-06595-8
Image Credits: AI Generated
DOI: 10.1007/s10586-026-06595-8
Keywords: Internet of Vehicles, blockchain, authentication, cryptography, Physical Unclonable Functions, Elliptic Curve Cryptography, Trusted Authority, NS-3 simulation, formal verification, smart cities, vehicular networks, security protocols

