<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE article  PUBLIC "-//NLM//DTD Journal Publishing DTD v3.0 20080202//EN" "http://dtd.nlm.nih.gov/publishing/3.0/journalpublishing3.dtd"><article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" dtd-version="3.0" xml:lang="en" article-type="research article"><front><journal-meta><journal-id journal-id-type="publisher-id">JIS</journal-id><journal-title-group><journal-title>Journal of Information Security</journal-title></journal-title-group><issn pub-type="epub">2153-1234</issn><publisher><publisher-name>Scientific Research Publishing</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.4236/jis.2022.131001</article-id><article-id pub-id-type="publisher-id">JIS-114903</article-id><article-categories><subj-group subj-group-type="heading"><subject>Articles</subject></subj-group><subj-group subj-group-type="Discipline-v2"><subject>Computer Science&amp;Communications</subject></subj-group></article-categories><title-group><article-title>
 
 
  A Trusted and Privacy-Preserving Carpooling Matching Scheme in Vehicular Networks
 
</article-title></title-group><contrib-group><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Hongliang</surname><given-names>Sun</given-names></name><xref ref-type="aff" rid="aff1"><sup>1</sup></xref></contrib><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Linfeng</surname><given-names>Wei</given-names></name><xref ref-type="aff" rid="aff1"><sup>1</sup></xref><xref ref-type="corresp" rid="cor1"><sup>*</sup></xref></contrib><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Libo</surname><given-names>Wang</given-names></name><xref ref-type="aff" rid="aff1"><sup>1</sup></xref></contrib><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Juli</surname><given-names>Yin</given-names></name><xref ref-type="aff" rid="aff1"><sup>1</sup></xref></contrib><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Wenxuan</surname><given-names>Ma</given-names></name><xref ref-type="aff" rid="aff1"><sup>1</sup></xref></contrib></contrib-group><aff id="aff1"><addr-line>College of Cyber Security, Jinan University, Guangzhou, China</addr-line></aff><pub-date pub-type="epub"><day>27</day><month>01</month><year>2022</year></pub-date><volume>13</volume><issue>01</issue><fpage>1</fpage><lpage>22</lpage><history><date date-type="received"><day>15,</day>	<month>December</month>	<year>2021</year></date><date date-type="rev-recd"><day>24,</day>	<month>January</month>	<year>2022</year>	</date><date date-type="accepted"><day>27,</day>	<month>January</month>	<year>2022</year></date></history><permissions><copyright-statement>&#169; Copyright  2014 by authors and Scientific Research Publishing Inc. </copyright-statement><copyright-year>2014</copyright-year><license><license-p>This work is licensed under the Creative Commons Attribution International License (CC BY). http://creativecommons.org/licenses/by/4.0/</license-p></license></permissions><abstract><p>
 
 
  With the rapid development of intelligent transportation, carpooling with the help of Vehicular Networks plays an important role in improving transportati
  on efficiency and solving environmental problems. However, attackers usually launch attacks and cause privacy leakage of carpooling users. In addition, the trust issue between unfamiliar vehicles and passengers reduces the efficiency of carpooling. To address these issues, this paper introduced a trusted and pr
  ivacy-preserving carpooling matching scheme in Vehicular Networks (TPCM). TPC
  M scheme introduced travel preferences during carpooling matching, according to the passengers’ individual travel preferences needs, which adopted th
  e privacy set intersection technology based on the Bloom filter to match the passengers with the vehicles to achieve the purpose of protecting privacy an
  d meeting the individual needs of passengers simultaneously. TPCM scheme adopted a multi-faceted trust management model, which calculated the trust val
  ue of different travel preferences of vehicle based on passengers’ carpooling feedback to evaluate the vehicle’s trustworthiness from multi-faceted when carpooling matching. Moreover, a series of experiments were conducted to verify the effectiveness and robustness of the proposed scheme. The results show that the proposed scheme has high accuracy, lower computational and communication costs when compared with the existing carpooling schemes.
 
</p></abstract><kwd-group><kwd>Vehicular Networks</kwd><kwd> Carpooling Matching</kwd><kwd> Travel Preference</kwd><kwd> Bloom Filter</kwd><kwd> Privacy Set Intersection</kwd><kwd> Trust Management</kwd></kwd-group></article-meta></front><body><sec id="s1"><title>1. Introduction</title><p>Vehicular Networks [<xref ref-type="bibr" rid="scirp.114903-ref1">1</xref>] is an important part of the intelligent transportation system. In the vehicular networks, vehicles can use wireless communication technology to communicate with nearby vehicles or infrastructure in a Vehicle-To-Vehicle (V2V) or Vehicle-To-Infrastructure (V2I) manner. With the development of vehicular networks, dynamic carpooling with the help of vehicular networks has become an important travel manner [<xref ref-type="bibr" rid="scirp.114903-ref2">2</xref>]. The dynamic carpooling service matches multiple passengers which have similar itineraries with the target vehicle based on the travel information provided by the passengers and the vehicle. Carpooling can improve the traffic environment [<xref ref-type="bibr" rid="scirp.114903-ref3">3</xref>], and reduce the number of vehicles on the road by increasing the utilization rate of vehicle seats to alleviate traffic congestion and improving road mobility. In addition, carpooling reduces fuel consumption and carbon emissions, thereby improving environmental pollution [<xref ref-type="bibr" rid="scirp.114903-ref4">4</xref>].</p><p>Privacy protection is an important concern in carpooling [<xref ref-type="bibr" rid="scirp.114903-ref5">5</xref>] since attackers usually launch attacks to eavesdrop on the private information of carpooling users, which will cause privacy leakage and reduce users’ willingness to participate in carpooling. Moreover, the private information of carpooling users usually includes sensitive information such as location and address [<xref ref-type="bibr" rid="scirp.114903-ref6">6</xref>]. Attackers can guess the user’s home address and other information by observing multiple carpooling information of users, which raises a major threat to the safety of carpooling users [<xref ref-type="bibr" rid="scirp.114903-ref7">7</xref>]. In recent years, many privacy-preserving schemes have been proposed to protect the anonymity and traceability of carpooling users [<xref ref-type="bibr" rid="scirp.114903-ref8">8</xref>]. These schemes may use encryption to protect the privacy of carpooling data [<xref ref-type="bibr" rid="scirp.114903-ref9">9</xref>] [<xref ref-type="bibr" rid="scirp.114903-ref10">10</xref>] or use anonymous identities to protect the privacy of carpooling users [<xref ref-type="bibr" rid="scirp.114903-ref11">11</xref>]. But anonymity and data encryption may cause difficulty in carpooling matching [<xref ref-type="bibr" rid="scirp.114903-ref12">12</xref>]. Some carpooling matching schemes have been proposed to solve the problem of difficulty in carpooling matching [<xref ref-type="bibr" rid="scirp.114903-ref13">13</xref>]. However, these schemes don’t consider the individual needs of passengers. For example, there may be non-smokers who do not want to travel with smoking drivers, and female passengers don’t want to travel with the smoking driver at night. If the individual needs of the passengers are ignored, it may cause a mismatch between the vehicle and the passengers. Therefore, the existing solutions can’t achieve a balance between precise carpooling matching and privacy protection [<xref ref-type="bibr" rid="scirp.114903-ref14">14</xref>].</p><p>Trust management is another problem in carpooling since it enables users to judge the trustworthiness of the information before accepting it [<xref ref-type="bibr" rid="scirp.114903-ref15">15</xref>]. In recent years, a large number of trust management schemes have been proposed for Vehicular Networks [<xref ref-type="bibr" rid="scirp.114903-ref16">16</xref>]. Some schemes assign reputation certificates to vehicles, and the vehicles verify the reputation certificate to determine whether the information comes from a legitimate vehicle to ensure the legitimacy of the received information [<xref ref-type="bibr" rid="scirp.114903-ref17">17</xref>] [<xref ref-type="bibr" rid="scirp.114903-ref18">18</xref>]. There are also some schemes using reputation score trust management methods. The vehicle judges whether to trust a vehicle by comparing the reputation score of the vehicle sending message with the threshold set by itself, and then accepts the corresponding message [<xref ref-type="bibr" rid="scirp.114903-ref19">19</xref>]. However, a single reputation score makes it impossible for passengers to evaluate the trustworthiness of the vehicle from multi-faceted.</p><p>To solve the aforementioned problems, this paper proposes a trusted and privacy-preserving carpooling matching (TPCM) scheme in vehicular networks. The main contributions are as follows:</p><p>1) TPCM scheme adopts the privacy set intersection based on Bloom filter, and judges whether the vehicle fulfills the individual needs of the passengers according to the travel preferences selected by the passengers and the preference attribute set of the vehicle. The privacy of carpooling users will not be leaked in this process. It can also fulfill the individual needs of passengers. TPCM scheme overcomes the problem of mismatch between vehicles and passengers, which achieves a balance between precise carpooling matching and privacy protection.</p><p>2) This paper proposes a multi-faceted trust management model based on travel preferences to solve the trust lack between passengers and vehicles during carpooling matching. This model uses a reputation set based on travel preferences instead of a single reputation score. Each trust value in the reputation set represents the trustworthiness of a certain type of travel preference of the vehicle, which realizes the multi-faceted accurate trust evaluation of the vehicle and effectively depicts trust between passengers and vehicles.</p><p>The remainder of this paper is structured as follows. Section 2 introduces some related work on carpooling and its limitations. Section 3 revisits the preliminaries. Section 4 introduces the system model, threat model and travel preferences classification. Section 5 details the proposed TPCM scheme. Section 6 and Section 7 detail the security analysis and performance evaluation, followed by the conclusion in Section 8.</p></sec><sec id="s2"><title>2. Related Work</title><p>In terms of privacy protection for carpooling matching, Yu et al. [<xref ref-type="bibr" rid="scirp.114903-ref7">7</xref>] proposed a privacy-preserving carpooling matching scheme which used encryption aggregation to calculate distance and protected the location privacy of vehicles and passengers by using homomorphic encryption. Hallgren et al. [<xref ref-type="bibr" rid="scirp.114903-ref20">20</xref>] proposed the scheme through the similarity between the starting point and the end point and trajectory matching to achieve carpooling matching, which adopted additional homomorphic encryption and threshold private set intersection protocol to protect user’s privacy. Li et al. [<xref ref-type="bibr" rid="scirp.114903-ref13">13</xref>] presented the way to achieve one-to-many proximity matching by using privacy proximity test during carpooling matching, which protected the privacy of vehicles and passengers simultaneously. However, these schemes don’t consider passenger’s travel preferences in carpooling matching [<xref ref-type="bibr" rid="scirp.114903-ref21">21</xref>], which cannot achieve a balance between precise matching of passengers and vehicles and privacy-preserving and may cause a mismatch between passengers and vehicles. Passengers may give negative feedback to the vehicle after the carpooling journey ends. And it affects the user experience and reduces the effectiveness of carpooling.</p><p>In terms of trust management, Caballero-Gil et al. [<xref ref-type="bibr" rid="scirp.114903-ref22">22</xref>] proposed the reputation update algorithm which considered the relationship chain between users, and calculated the trust rating through friendliness and user ratings to generate a trust rating between 0 and 1. Baza et al. [<xref ref-type="bibr" rid="scirp.114903-ref23">23</xref>] proposed a decentralized reputation system that generated two values based on whether the vehicle arrived at the agreed pick-up location and whether the carpooling journey was completed, and then used the two values to calculate the vehicle’s reputation score. S&#225;nchez et al. [<xref ref-type="bibr" rid="scirp.114903-ref24">24</xref>] presented a reputation management protocol which first aggregated the ratings of passengers, and then used negative truncation to normalize the reputation value of the vehicle. However, the aforementioned schemes only use a single reputation score to evaluate the trustworthiness of the vehicles, which not only causes reputation link attacks [<xref ref-type="bibr" rid="scirp.114903-ref25">25</xref>] but also cannot evaluate the trustworthiness of the vehicle from multi-faceted, such as the driver’s driving skills and the degree of cleanliness.</p></sec><sec id="s3"><title>3. Preliminaries</title><sec id="s3_1"><title>3.1. Bilinear Pairing</title><p>Let G 1 and G 2 be an addition cyclic group and a multiplication with the same prime order q. Let g be the generator of group G 1 . Let e : G 1 &#215; G 1 → G 2 denote a bilinear map which has following properties [<xref ref-type="bibr" rid="scirp.114903-ref26">26</xref>].</p><p>Bilinear: For all a , b ∈ Z q * , e ( g a , g b ) = e ( g , g ) a b .</p><p>Non-degeneracy: e ( g , g ) ≠ 1 .</p><p>Computability: For all g 1 , g 2 ∈ G 1 , there is an effective algorithm for calculation e ( g 1 , g 2 ) .</p></sec><sec id="s3_2"><title>3.2. ELGAMAL Encryption</title><p>The ElGamal encryption algorithm is a multiplicative homomorphic encryption algorithm. The process of the ElGamal encryption algorithm is as follows [<xref ref-type="bibr" rid="scirp.114903-ref27">27</xref>].</p><p>Key generation: Randomly select a large prime number q and a random number s ∈ Z q * . And calculate o = g s mod q . Then the public key is ( o , g , q ) and private key is s.</p><p>Encryption: Select a random number r that is relatively prime with q − 1 . And calculate the ciphertext of message M as</p><p>C = E ( M ) = ( c 1 , c 2 ) = ( g r mod q , s r M mod ( q − 1 ) ) (1)</p><p>Decryption: Decrypt the ciphertext C as</p><p>M = D ( C ) = c 2 / c 1 s ( mod q ) = d ( c 1 s ) − 1 mod q (2)</p></sec><sec id="s3_3"><title>3.3. BF-PSI</title><p>Bloom filter (BF) [<xref ref-type="bibr" rid="scirp.114903-ref28">28</xref>] is a probabilistic data structure that checks set membership and effectively saves space. The false negative rate of the Bloom filter is 0, but the Bloom filter has a certain false positive rate due to the collision rate of the hash function, the false positive rate p is calculated as [<xref ref-type="bibr" rid="scirp.114903-ref28">28</xref>]</p><p>p = ( 1 − ( 1 − 1 m ) k ⋅ n ) k ≈ ( 1 − e − k ⋅ n m ) k (3)</p><p>where m, k and n are the size of the bloom filter vector, the number of hash functions and the number of elements stored in the Bloom filter, respectively.</p><p>Privacy Set Intersection (PSI) [<xref ref-type="bibr" rid="scirp.114903-ref29">29</xref>] can judge whether there is an intersection between the input sets of the two parties without leaking privacy. The execution process of BF-PSI is: two parties A and B whose secret sets are S A = ( a 1 , a 2 , ⋯ , a n ) and S B = ( b 1 , b 2 , ⋯ , b n ) , respectively. A and B choose random value r a and r b , and then use k independent hash functions with the number bits s to represent the set as B F A and B F B . Next, A and B exchange random values and BF. Finally, it determines the intersection of two parties A and B. For example, if A executes P S I ( S A , B F B , r b ) , who uses m e m _ t e s t (   ) to judge whether a i ( i = 1 , 2 , ⋯ , n ) appears in B F B . If it returns a positive result, then a i ∈ B F B , and vice versa. In this way, A and B can learn I A , B = S A ∩ S B without leaking the privacy of the two parties.</p></sec></sec><sec id="s4"><title>4. Problem Statement</title><sec id="s4_1"><title>4.1. System Model</title><p>The system model of the TPCM scheme proposed in this paper is shown in <xref ref-type="fig" rid="fig1">Figure 1</xref>, which includes four entities: Trusted Authority (TA), RSU, vehicle and passenger.</p><p>When the TPCM scheme is deployed in the carpooling system, TA assigns public key, private key and reputation certificates to registered entities. Only TA can reveal the true identities of malicious users and punish them when users have malicious behaviors. TA also is responsible for collecting trust feedback and updating the user’s trust information. RSU is responsible for verifying the certificates and information signatures of vehicles and passengers and matching vehicles and passengers in carpooling. Passengers are responsible for sending</p><p>encrypted carpooling requests within the communication range of a certain RSU. The vehicles send an encrypted carpooling response after receiving the encrypted carpooling requests.</p></sec><sec id="s4_2"><title>4.2. Threat Model</title><p>We assume that the TA is completely trusted, whereas RSU is honest and curious in the threat model of this paper. That is, the RSU honestly performs the steps in carpooling, but it is curious about the carpooling information broadcasted in the carpooling system and the user’s private information. Specifically, RSU may launch passive attacks such as message eavesdropping attacks or privacy digging. Although it does not modify the information, it tries to obtain more private information from carpooling users. Vehicles and passengers may be malicious. They may launch passive attacks to eavesdrop on the private information in carpooling or launch active attacks to disrupt the carpooling network. For example, vehicles or passengers may launch message cheating attacks, and use a false identity to deceive other carpooling entities. And they may launch message modification attacks to modify the carpooling information.</p></sec><sec id="s4_3"><title>4.3. Travel Preferences Classification</title><p>The classification and attributes of travel preferences for the TPCM scheme in this paper are shown in <xref ref-type="table" rid="table1">Table 1</xref>. Travel preferences are divided into 7 categories, where I 1 ~ I 7 represents the trust value corresponding to travel preferences. The trust value of travel preference I m is T V V i ( I m ) . The vehicle reputation set is composed of trust value, which is used to evaluate the trustworthiness of the vehicle from multi-faceted. Each travel preference has two attributes, x 1 ， 1 ~ x 7 ， 2 represents the 14 attributes corresponding to the 7 travel preferences. The attributes of I 1 ~ I 4 is based on the range of trust values. That is, the attributes of preference I 1 ~ I 4 are converted from continuous variables to characters, where the range of trust values [ ω s , 0.5] is Good and the range (0.5, 1] is Very Good, ω s is the score threshold. The attributes of I 1 ~ I 4 is constantly updated with the changes of the trust value. The attributes of I 5 ~ I 7 is unchanged based on the real information when vehicle registration, and the trust</p><table-wrap id="table1" ><label><xref ref-type="table" rid="table1">Table 1</xref></label><caption><title> Travel preferences classification and attributes</title></caption><table><tbody><thead><tr><th align="center" valign="middle" >Travel preferences</th><th align="center" valign="middle" >Attribute</th></tr></thead><tr><td align="center" valign="middle" >Driver’s driving skill ( I 1 )</td><td align="center" valign="middle" >Very Good ( x 1 , 1 ), Good ( x 1 , 2 )</td></tr><tr><td align="center" valign="middle" >Driver’s sense of direction ( I 2 )</td><td align="center" valign="middle" >Very Good ( x 2 , 1 ), Good ( x 2 , 2 )</td></tr><tr><td align="center" valign="middle" >Driver’s attitude ( I 3 )</td><td align="center" valign="middle" >Very Good ( x 3 , 1 ), Good ( x 3 , 2 )</td></tr><tr><td align="center" valign="middle" >Cleanliness of the vehicle ( I 4 )</td><td align="center" valign="middle" >Very Good ( x 4 , 1 ), Good ( x 4 , 2 )</td></tr><tr><td align="center" valign="middle" >Driver smoking ( I 5 )</td><td align="center" valign="middle" >Yes ( x 5 , 1 ), No ( x 5 , 2 )</td></tr><tr><td align="center" valign="middle" >Vehicle music ( I 6 )</td><td align="center" valign="middle" >Yes ( x 6 , 1 ), No ( x 6 , 2 )</td></tr><tr><td align="center" valign="middle" >Driver’s gender ( I 7 )</td><td align="center" valign="middle" >Male ( x 7 , 1 ), Female ( x 7 , 2 )</td></tr></tbody></table></table-wrap><p>value reflects the trustworthiness of the corresponding travel preference. One of the attributes of each travel preference constitutes the preference attributes set P A V i of the vehicle V i , which is used to meet the individual needs of passengers.</p></sec></sec><sec id="s5"><title>5. Proposed Scheme</title><sec id="s5_1"><title>5.1. System Initialization</title><p>Given the security parameters 1 τ , TA generates the bilinear parameters ( G 1 , G 2 , e ) , where G 1 , G 2 is the cyclic group with prime order q, g 1 , g 2 is the generator of G 1 and G 2 , respectively. And the bilinear map e : G 1 &#215; G 1 → G 2 . Then TA calculates e ( g 1 , g 2 ) = F . Next, TA generates the master key M S K T = t and calculates P K T = g 1 t to be its public key, where t ∈ Z q * . TA selects two hash function: H 1 : { 0 , 1 } → Z q * , H 2 : { 0 , 1 } &#215; { 0 , 1 } → Z q * , and selects the filter function f, length l, and hash function set H s for the Bloom filter. TA sets the distance threshold φ s and φ d , time threshold ψ t and score threshold ω s . Finally, TA publishes the system parameters Θ = ( τ , G 1 , G 2 , e , q , F , P K T , f , l , H s , φ s , φ d , ψ t , ω s ) .</p><p>In order to prevent the vehicle from forging its travel preference attributes, TA will create preference attributes secret value as shown in <xref ref-type="table" rid="table2">Table 2</xref>, where S v i λ is the secret value corresponding to the preference attribute x i , λ is the time when TA generates all preference attributes secret value. The calculation method of S v i λ is S v i λ = h λ ( x i | | r λ ) , where h λ is the hash function for calculating the secret value and r λ is a random number. Due to the collision rate of the hash function, if the secret value of two different preference attributes is the same, TA recalculates the secret value for all preference attributes until the secret value of all preference attributes is different. In addition, TA regularly updates the preference attributes secret value.</p></sec><sec id="s5_2"><title>5.2. Entity Registration</title><p>When a passenger P i with the identity R I D P i registers with the carpooling system, TA generates the privacy key S K P i = p and calculates the public key P K P i = g 1 p for passenger P i , where p is a random number and p ∈ Z q * . TA generates the reputation certificate R C e r t P i = g 2 1 / ( H P i + M S K T + S K P i ) , where H P i = H 1 ( R I D P i | | P K P i | | P V P i ) , P V P i is the validity period of the reputation certificate. The anonymous identity of passenger P i is P I D P i = R I D P i ⊕ H 1 ( p | | P K T | | P K R i ) .</p><p>When vehicle V i with the identity R I D V i registers with the carpooling system, TA generates the privacy key S K V i = v and calculates the public key P K V i = g 1 v</p><table-wrap id="table2" ><label><xref ref-type="table" rid="table2">Table 2</xref></label><caption><title> Preference attributes secret value</title></caption><table><tbody><thead><tr><th align="center" valign="middle" >Preference attribute</th><th align="center" valign="middle" >x 1 , 1</th><th align="center" valign="middle" >x 1 , 2</th><th align="center" valign="middle" >…</th><th align="center" valign="middle" >x 7 , 1</th><th align="center" valign="middle" >x 7 , 2</th></tr></thead><tr><td align="center" valign="middle" >Secret value</td><td align="center" valign="middle" >S v 1 , 1 λ</td><td align="center" valign="middle" >S v 1 , 2 λ</td><td align="center" valign="middle" >…</td><td align="center" valign="middle" >S v 7 , 1 λ</td><td align="center" valign="middle" >S v 7 , 2 λ</td></tr></tbody></table></table-wrap><p>for vehicle V i , where v is a random number and v ∈ Z q * . TA generates the reputation certificate R C e r t V i = g 2 1 / ( H V i + M S K T + S K V i ) , where H V i = H 1 ( R I D V i | | P K V i | | P V V i ) .The anonymous identity of vehicle V i is P I D V i = R I D V i ⊕ H 1 ( v | | P K T | | P K R i ) . The reputation set of the vehicle V i is R S V i = ( T V V i ( I 1 ) ~ T V V i ( I 7 ) ) , where T V V i ( I 1 ) ~ T V V i ( I 7 ) represents the trust value of the 7 travel preference types of V i , and the reputation set is used to evaluate the trustworthiness of V i from multi-faceted. Since the travel preference I 1 ~ I 4 ’s trust value is initialized to 0.5 and the corresponding attributes are x 1 , 2 , x 2 , 2 , x 3 , 2 , x 4 , 2 , so the initial vehicle preference attribute set is P A V i = ( x 1 , 2 , x 2 , 2 , x 3 , 2 , x 4 , 2 x a , x b , x c ) , where x a , x b and x c are the real information registered by the vehicle V i . P A V i is used to meet the individual travel preferences needs of passengers. TA retrieves the secret value corresponding to the preference attribute from <xref ref-type="table" rid="table2">Table 2</xref>, and then sends the preference attribute secret value set P A S V i to the vehicle V i , where P A S V i = ( S v 1 , 2 β , S v 2 , 2 β , S v 3 , 2 β , S v 4 , 2 β , S v a β , S v b β , S v c β ) .</p><p>When RSU registers with the carpooling system, TA generates the privacy key S K R i = r and calculates the public key P K R i = g 1 r for R i , where r is a random number and r ∈ Z q * .</p></sec><sec id="s5_3"><title>5.3. Carpooling Requesting</title><p>When a passenger P i wants to carpool, who first chooses individual travel preferences, and then selects preference attributes from the attributes corresponding to the selected travel preferences. It is noted that passengers can only choose one of the two attributes corresponding to each travel preference. We assume that the preference attributes selected by the passenger are x m ~ x n , I m ′ ~ I n ′ are the corresponding travel preferences. Next, the passenger P i requests the secret value corresponding to the selected preference attributes from TA, and TA returns the corresponding secret value S v m α ~ S v n α to the passenger P i . We assume P S P i = ( S v m α ~ S v n α ) , then the passenger P i selects a random number r 1 and injects P S P i into Bloom filter by using B f P i = I n s e r t ( H s ( P S P i | | r 1 ) , B f P i ) . The passenger sets a preference score threshold χ m ∼ n . Finally, passenger P i selects the starting position and destination to form a carpooling request</p><p>Q M P i = ( P I D P i , R C e r t P i , B f P i , χ m ∼ n , l o c P i , d e s P i , α , T Q M P i ) (4)</p><p>where T Q M P i denotes the timestamp when the carpooling request is generated. And then passenger calculates the signature δ Q M P i = g 2 1 / ( H 2 ( Q M P i | | P K P i | | P K R i ) + S K P i ) . When the passenger is within the communication range of a certain RSU, who uses ElGamal encryption and parameter ( g 1 , P K R i ) to encrypt Q M P i to form a ciphertext</p><p>C P i = E ( Q M P i ) = ( c 1 , c 2 ) = ( g 1 w 1 mod q , P K R i w 1 Q M P i mod ( q − 1 ) ) (5)</p><p>Eventually passenger P i sends { C P i , R C e r t P i , δ Q M P i } to R i . After the R i receives the information { C P i , R C e r t P i , δ Q M P i } , which uses the decryption algorithm and the private key to decrypt ciphertext C P i to obtain the passenger’s carpooling request information, Q M P i = D ( C P i ) = c 2 ( c 1 S K R i ) − 1 mod q . Then R i obtains the current timestamp from the clock and verifies the freshness of the message by | T 1 − T Q M P i | &lt; ψ t . If it holds, then R i verifies the validity of the passenger’s reputation certificate and information signature by (6) and (7).</p><p>e ( g 1 H P i ⋅ P K T ⋅ P K P i , R C e r t P i ) = F (6)</p><p>e ( g 1 H 2 ( Q M P i | | P K P i | | P K R i ) ⋅ P K P i , δ Q M P i ) = F (7)</p><p>when all verifications are passed, R i will broadcast M s g R i to the nearby vehicles, where T M s g R i is the timestamp when M s g R i is generated.</p><p>M s g R i = ( P I D P i , B f P i , l o c P i , d e s P i , α , T M s g R i ) (8)</p></sec><sec id="s5_4"><title>5.4. Carpooling Responding</title><p>When the vehicle V i is within the communication range of R i , who first obtains the current timestamp from the clock after receiving the information M s g R i , and then checks the freshness of the message by | T 2 − T M s g R i | &lt; ψ t . If it holds, we assume the preference attribute secret value set of the vehicle V i is P A S V i = ( S v p β ~ S v q β ) . In order to ensure the time consistency of the preference attribute secret value of the vehicle V i and the passenger P i , the vehicle first checks whether α is equal to β that in P A S V i . If it holds, the vehicle selects a random number r 2 and inserts P A S V i into the Bloom filter by using B f V i = I n s e r t ( H s ( P A S V i | | r 2 ) , B f V i ) ; Otherwise, the vehicle requests to update secret value in P A S V i from TA, and then injects the updated P A S V i into the Bloom filter. Finally, vehicle sets the maximum number of carpooling to form a carpooling response</p><p>S M V i = ( P I D V i , R S V i , R C e r t V i , B f V i , l o c V i , d e s V i , C N max , T S M V i ) (9)</p><p>where l o c V i , d e s V i denotes the starting point and destination of vehicle, respectively, and T S M V i denotes the timestamps when the carpooling responding is generated. The vehicle calculates the signature δ S M V i = g 2 1 / ( H 2 ( S M V i | | P K V i | | P K R i ) + S K V i ) . Then vehicle V i adopts ElGamal encryption and uses the parameter ( g 1 , P K R i ) to encrypt the carpooling response of the vehicle to form ciphertext</p><p>C V i = E ( S M V i ) = ( c 3 , c 4 ) = ( g 1 w 2 mod q , P K R i w 2 S M V i mod ( q − 1 ) ) (10)</p><p>Eventually vehicle V i sends { C V i , R C e r t V i , δ S M V i } to R i .</p></sec><sec id="s5_5"><title>5.5. Carpooling Matching</title><p>After receiving the information { C V i , R C e r t V i , δ S M V i } , R i first uses the decryption algorithm and private key to decrypt the vehicle’s carpooling response ciphertext C V i to obtain S M V i = D ( C V i ) = c 4 ( c 3 S K R i ) − 1 mod q . Then it checks the freshness of carpooling response information by | T 3 − T S M V i | &lt; ψ t . If it holds, R i verifies the validity of V i ’s reputation certificate and information signature by (11) and (12).</p><p>e ( g 1 H V i ⋅ P K T ⋅ P K V i , R C e r t V i ) = F (11)</p><p>e ( g 1 H 2 ( S M V i | | P K V i | | P K R i ) ⋅ P K V i , δ S M V i ) = F (12)</p><p>After above verifications are passed, R i verifies (13) to match the starting position and destination of the vehicle and passengers. Then it checks whether all the T V V i ( I 1 ) ~ T V V i ( I 7 ) in R S V i is greater than χ m ~ n . In other words, it is to check whether the trust value corresponding to V i ’s travel preference categories selected by the passenger meets the passenger’s multi-faceted trust needs.</p><p>( | l o c P i − l o c V i | &lt; φ s ) ∧ ( | d e s P i − d e s V i | &lt; φ d ) (13)</p><p>Finally, R i uses BF-PSI to determine whether there is an intersection I n P i , V i between V i ’s preference attribute secret value set P A S V i and the set P S P i selected by P i . If I n P i , V i and P S P i are the same, V i fulfills all individual carpooling needs of passenger P i . Then the vehicle and passengers are successfully matched and the message M P i , V i is sent to the vehicle and passengers.</p><p>M P i , V i = ( P I D P i , P I D V i , S P i , V i , T M P i , V i ) (14)</p><p>where S P i , V i is the communication key between the vehicle and the passenger, and T M P i , V i is the timestamp of the successful carpooling matching. In order to understand the process of carpooling matching in our TPCM scheme, Algorithm 1 describes the carpooling matching scheme based on BF-PSI in <xref ref-type="table" rid="table3">Table 3</xref>.</p></sec><sec id="s5_6"><title>5.6. Trust Feedback and Reputation Updating</title><p>When the passenger P i arrives at the destination, who will calculate the feedback score F s P i → V i ( I m ′ ) ~ F s P i → V i ( I n ′ ) for the selected preference attribute ( x m ~ x n ) corresponds to the travel preferences ( I m ′ ~ I n ′ ) based on the actual experience in the carpooling journal. For ∀ I i ∈ ( I m ′ ~ I n ′ ) , the corresponding feedback score is F s P i → V i ( I i ) ∈ { 0 , 1 } , where 1 represents positive feedback and 0 represents negative feedback. Passenger P i calculates feedback scores for all selected travel preferences by using above method and generates a travel preference feedback set F s P i → V i = ( F s P i → V i ( I m ′ ) , ⋯ , F s P i → V i ( I n ′ ) ) , which forms the passenger P i ’s trust feedback tuple T f P i → V i = ( P I D P i , F s P i → V i , P I D V i , M P i , V i ) for the vehicle V i .</p><p>Since there is more than one carpooling passenger, multiple trust feedback tuples about the vehicle V i will be generated. These trust feedback tuples are aggregated by the RSU and sent to the TA in a safe manner. After the TA receives them, who first classifies and integrates this information into multiple preference feedback information sets about the vehicle based on the type of travel preference, for example</p><p>P F M V i ( I m ′ ) = ( P I D P i , F s P i → V i ( I m ′ ) , ⋯ , P I D P n , F s P n → V i ( I m ′ ) , P I D V i ) (15)</p><table-wrap id="table3" ><label><xref ref-type="table" rid="table3">Table 3</xref></label><caption><title> Carpooling matching scheme based on BF-PSI</title></caption><table><tbody><thead><tr><th align="center" valign="middle" >Algorithm 1: Carpooling matching scheme based on BF-PSI</th></tr></thead><tr><td align="center" valign="middle" >Input: Q M P i , S M V i , δ S M V i Output: Result = “successful matching” or “failed matching”</td></tr><tr><td align="center" valign="middle" >1: I n P i , V i = ∅</td></tr><tr><td align="center" valign="middle" >2: if | T 3 − T S M V i | &lt; ψ t then</td></tr><tr><td align="center" valign="middle" >3: R i verifies the reputation certificate and signature of V i 4: if equation (11) and (12) hold then</td></tr><tr><td align="center" valign="middle" >5: R i matches the starting position and destination of the V i and P i 6: if equation (13) holds then 7: R i verifies whether V i meets P i ’s multi-faceted trust needs 8: if all the T V V i ( I 1 ) ~ T V V i ( I 7 ) &gt; χ m − n then 9: V i meets P i ’s multi-faceted trust needs 10: end if 11: end if 12: end if 13: end if 14: for ∀ p ∈ { m , ⋯ , n } then 15: if mem_test { B f V i , r 2 , x p } then 16: I n P i , V i = I n P i , V i ∪ { x p } 17: end if 18: end for 19: if I n P i , V i and P S P i are the same then 20: Result = “successful matching” 21: else 22: Result = “failed matching”</td></tr><tr><td align="center" valign="middle" >23: end if</td></tr></tbody></table></table-wrap><p>TA updates the trust value of the travel preferences type selected by passengers</p><p>in the reputation set R S V i of vehicle V i based on ( P F M V i ( I m ′ ) ~ P F M V i ( I n ′ ) ) , the updating method is as follows:</p><p>T V V i ( I i ) t + 1 = { ∑ P I D P i ∈ P F M V i ( I i ) F s P i → V i ( I i ) ⋅ R s P i t ∑ P I D P i ∈ P F M V i ( I i ) R s P i t ,   if     ∑ P I D P i ∈ P F M V i ( I i ) R s P i t &gt; ω s ξ ⋅ T V V i ( I i ) t ,   otherwise (16)</p><p>where R s P i is the reputation score of passengers P i , ξ is a decay factor. If a vehicle does not carpool for a long time, the trust value corresponding to its travel preference will decay over time.</p><p>Then TA updates the attributes of the first four items in the vehicle V i ’s preference attribute set based on the updated trust value. Finally, TA sends the updated R S V i and P A S V i to the vehicle. In order to evaluate the overall trustworthiness of the vehicle, we use the weighted average method to calculate the average reputation score of the vehicle, the calculation method is as follows:</p><p>R s V i t + 1 = w s M ∑ ( T V V i ( I m ′ ) t + 1 + ⋯ + T V V i ( I n ′ ) t + 1 ) + w t N ∑ ( T V V i ( I p ′ ) t + ⋯ + T V V i ( I q ′ ) t ) (17)</p><p>where I m ′ ~ I n ′ is the travel preferences of vehicle V i corresponding to the preference attributes selected by passenger P i , the number is M, corresponding to the updated trust value is T V V i ( I m ′ ) t + 1 ~ T V V i ( I n ′ ) t + 1 , and the total weight is w s ; I p ′ ~ I q ′ is the travel preferences of vehicle V i not selected by the passenger,</p><p>the number is N, corresponding to the historical trust value is T V V i ( I p ′ ) t ~ T V V i ( I q ′ ) t , the total weight is w t , where w t = 1 − w s .</p></sec></sec><sec id="s6"><title>6. Security Analysis</title><sec id="s6_1"><title>6.1. Conditional Privacy Preservation</title><p>For the TPCM scheme, the TA assigns a pseudonym P I D V i to the vehicle when the vehicle is registered, and the vehicle uses the pseudonym identity to broadcast the carpooling information. Since the number v in P I D V i is a random number, which is kept secretly by the TA. Therefore, the adversary cannot reveal the identity of the vehicle from the pseudonym P I D V i to obtain private data. Only the TA can reveal the identity of the vehicle by using R I D V i = P I D V i ⊕ H 1 ( v | | P K T | | P K R i ) and punish the malicious vehicle. Therefore, the TPCM scheme not only protects the user’s identity privacy, but also tracks the real identity of malicious users and realizes the conditional privacy protection of users’ identities.</p></sec><sec id="s6_2"><title>6.2. Carpooling Data Privacy Preservation</title><p>When the carpooling information is generated, this paper uses ElGamal encryption algorithm to encrypt it. That is, the vehicles or passengers use the public key of the RSU to encrypt the carpooling information, and the RSU decrypts the encrypted carpooling information by using its private key to verify the identity of the vehicles or passengers. Since a random number needs to be selected when the ElGamal encryption algorithm is used to encrypt a carpooling message and the private key of the RSU is used to decrypt the message. The private key of the RSU is a random number and is kept secretly by the RSU. The adversary cannot initiate an attack to get the plaintext information after the carpooling information is encrypted. Therefore, the TPCM scheme protects the privacy of carpooling data. In addition, the encrypted ciphertext of the same carpooling message is also different within the communication range of different RSUs by using the ElGamal encryption algorithm. Moreover, the carpooling matching method in this paper introduces travel preferences, which uses BF-PSI technology to match passengers and vehicles to meet the individual needs of passengers. The carpooling matching method by using the BF-PSI not only protects the preference privacy of vehicles and passengers, but also prevents mismatch between vehicles and passengers caused by ignoring the passenger’s individual needs.</p></sec><sec id="s6_3"><title>6.3. Resistance to Message Modification Attacks</title><p>The attackers may modify the carpooling message by launching a message modification attack to disrupt the carpooling network. However, for the TPCM scheme in this paper, the passenger P i will calculate a signature δ Q M P i for the carpooling request Q M P i when he issues it. After the RSU within the communication range of P i receives Q M P i , which uses Equation (7) to verify the validity of the passenger’s carpooling request signature. If it holds, then the carpooling request Q M P i has not been modified. Otherwise, the carpooling message will be discarded. Therefore, the TPCM scheme can resist the message modification attack.</p></sec><sec id="s6_4"><title>6.4. Resistance to Message Cheating Attacks</title><p>Passengers or vehicles may initiate message cheating attacks and use false certificates to deceive each other. However, for the TPCM scheme in this paper, the reputation certificate of carpooling users has a validity period. When the reputation certificate expires, the TA will issue a new reputation certificate to the user. Although the internal attacker has a reputation certificate issued by the TA, the malicious user cannot repeatedly initiate a reputation certificate request to cover up his malicious behavior before the certificate expires. TA can reveal the identity of the internal attacker, who will reduce the trust value of a certain travel preference when the vehicle has malicious behavior. And TA will revoke the malicious vehicle when a certain trust value is lower than the score threshold. If an external attacker uses a fake reputation certificate to broadcast carpooling messages, who cannot pass the reputation certificate verification from RSU. Therefore, for the TPCM scheme in this paper, the reputation certificate with validity period can not only resist message cheating attacks and ensure the legitimacy of the carpooling user identity, but also avoid the communication delay of requesting the certificate every time for carpooling.</p></sec></sec><sec id="s7"><title>7. Performance Evaluation</title><sec id="s7_1"><title>7.1. Computation Cost</title><p>The computational cost of TPCM scheme mainly comes from ElGamal encryption and signature verification. We let T m be the time to perform the maptopoint function operation, T e be the time to perform the exponentiation operation, T b be the time to perform bilinear pairing, and T u be the time to perform multiplication. In the Intel i3-4170 3.7 GHz processor, 8 GB RAM and Windows 10 platform, the times of these operations are: T m = 3 . 7   ms , T e = 3 . 9   ms , T b = 4.5   ms , T u = 0.6   ms [<xref ref-type="bibr" rid="scirp.114903-ref30">30</xref>].</p><p>In order to compare the TPCM scheme with the FICA scheme [<xref ref-type="bibr" rid="scirp.114903-ref13">13</xref>] and SRSCB scheme [<xref ref-type="bibr" rid="scirp.114903-ref31">31</xref>], this paper considers the computation overhead of three stages of passenger carpooling request, information verification and vehicle carpooling response in <xref ref-type="table" rid="table4">Table 4</xref>. We let PCRG be the carpooling request generation stage,</p><table-wrap id="table4" ><label><xref ref-type="table" rid="table4">Table 4</xref></label><caption><title> Computation cost of different carpooling schemes</title></caption><table><tbody><thead><tr><th align="center" valign="middle" >Scheme</th><th align="center" valign="middle" >PCRG</th><th align="center" valign="middle" >RMV</th><th align="center" valign="middle" >VCRG</th></tr></thead><tr><td align="center" valign="middle" >FICA [<xref ref-type="bibr" rid="scirp.114903-ref13">13</xref>]</td><td align="center" valign="middle" >2 T m + 9 T e + 2 T b + 6 T u</td><td align="center" valign="middle" >2 T m + 9 T e + 5 T b + 3 T u</td><td align="center" valign="middle" >2 T m + 9 T e + 2 T b + 6 T u</td></tr><tr><td align="center" valign="middle" >SRSCB [<xref ref-type="bibr" rid="scirp.114903-ref31">31</xref>]</td><td align="center" valign="middle" >4 T m + 10 T e + T b + 2 T u</td><td align="center" valign="middle" >3 T e + 5 T b</td><td align="center" valign="middle" >2 T m + T e + 2 T b</td></tr><tr><td align="center" valign="middle" >TPCM</td><td align="center" valign="middle" >T m + 3 T e + T u</td><td align="center" valign="middle" >2 T m + 3 T e + 2 T b + 3 T u</td><td align="center" valign="middle" >T m + 3 T e + T u</td></tr></tbody></table></table-wrap><p>RMV be the information verification stage, and VCRG be the carpooling response generation stage.</p><p>The computation cost comparison of different carpooling schemes is shown in <xref ref-type="table" rid="table4">Table 4</xref>. In the FICA scheme, the time consumption of passenger carpooling request generation, RSU information verification, and carpooling response is 55.1 ms, 66.8 ms, and 55.1 ms, respectively. In the SRSCB scheme (assuming the number of attributes is 1), the time consumption for the passenger generates an encrypted carpooling request, RSU information verification, and driver generates a carpooling response is 59.5 ms, 34.2 ms, and 20.3 ms, respectively. For the TPCM scheme, the time consumption of carpooling request generation, RSU information verification and carpooling response is 16 ms, 29.9 ms, and 16 ms, respectively.</p><p><xref ref-type="fig" rid="fig2">Figure 2</xref> and <xref ref-type="fig" rid="fig3">Figure 3</xref> show the computation cost of different carpooling schemes as the number of passengers and vehicles changes. We can see that the computation cost gradually increases as the number of passengers and vehicles increases, but the computation cost of our TPCM scheme increases more slowly compared with other schemes and is lower than the computation cost of other schemes.</p></sec><sec id="s7_2"><title>7.2. Communication Overhead</title><p>We assume the pseudonym and key length are 16 bytes, the hash value length is 4 bytes, and the signature and homomorphic ciphertext length are 67 bytes and 512 bytes, respectively [<xref ref-type="bibr" rid="scirp.114903-ref30">30</xref>]. For our TPCM scheme, the length of passenger’s carpooling information ciphertext is 595 bytes totally. The message length in the carpooling response and RSU verification phases is 595 bytes and 16 bytes, respectively. Comparing the communication overhead of our TPCM scheme with the FICA scheme [<xref ref-type="bibr" rid="scirp.114903-ref13">13</xref>] and PRIS scheme [<xref ref-type="bibr" rid="scirp.114903-ref32">32</xref>], <xref ref-type="fig" rid="fig4">Figure 4</xref> and <xref ref-type="fig" rid="fig5">Figure 5</xref> show the communication overhead of different carpooling schemes as the number of passengers and vehicles change. We can see that when the number of changes of passengers and vehicles from 100 to 1000, the communication overhead of our TPCM scheme is lower than other schemes regardless of whether the number of changes of passengers or vehicles. And it has a smaller growth rate compared with other schemes.</p></sec><sec id="s7_3"><title>7.3. Probability of Successful Carpooling Matching</title><p>We propose a carpooling matching method that introduces travel preferences,</p><p>which uses the BF-PSI technology to match the vehicle’s preference attribute secret value set with the preference secret value set selected by the passenger. <xref ref-type="fig" rid="fig6">Figure 6</xref> shows the change process of the probability that the carpooling is successfully matched n times with the size of the Bloom filter. We can see that with the increase of the size of the Bloom filter, the single matching success rate of our TPCM scheme is close to 100%, and the probability of multiple matching is almost 0. Therefore, the proposed carpooling matching scheme based on BF-PSI not only has high matching accuracy, but also has fast matching speed.</p></sec><sec id="s7_4"><title>7.4. Evaluation of Trust Management Model</title><p>1) Simulation settings</p><p>In this section, we evaluate the robustness of the proposed trust management model. We mainly evaluate the robustness of the proposed model based on the changes in the average reputation scores of different carpooling vehicles. The factors that affect the average reputation score of a vehicle mainly include the percentage of malicious passengers in carpooling and the weight of passenger’s feedback. The detailed simulation parameter setting is shown in <xref ref-type="table" rid="table5">Table 5</xref>.</p><p>In addition, we use Rh and Rm to evaluate the robustness of the proposed trust management model, where Rh denotes the average reputation score of honest carpooling vehicles; Rm denotes the average reputation score of malicious carpooling vehicles. The reputation score range of passengers is (0, 1], which is generated by random sampling and obeys a normal distribution, where μ = 0.5 , σ = 0.5 / 3 .</p><p>f ( x | μ , σ ) = 1 2 π σ ∗ exp ( − ( x − μ ) 2 2 σ 2 ) (18)</p><p>2) Robustness evaluation</p><table-wrap id="table5" ><label><xref ref-type="table" rid="table5">Table 5</xref></label><caption><title> Simulation parameter settings</title></caption><table><tbody><thead><tr><th align="center" valign="middle" >Notations</th><th align="center" valign="middle" >Definition</th><th align="center" valign="middle" >Value</th></tr></thead><tr><td align="center" valign="middle" >Pm</td><td align="center" valign="middle" >Percentage of malicious passengers</td><td align="center" valign="middle" >5%, 10%, 15%, 20%</td></tr><tr><td align="center" valign="middle" >w<sub>s</sub></td><td align="center" valign="middle" >Weight of passenger’s feedback</td><td align="center" valign="middle" >0.6, 0.8</td></tr></tbody></table></table-wrap><p>We mainly evaluate the robustness of proposed trust management model, that is, malicious passengers deliberately provide false trust feedback after carpooling to reduce or increase the trust value of certain travel preferences of the vehicle, thereby affecting the average reputation score of the vehicle. In this paper, the percentage of malicious passengers in carpooling is set to 5% - 25%. Each carpooling vehicle is first initialized and then performed 5 - 25 carpooling tasks respectively. The number of travel preferences selected by passengers is 1 - 7. After the interval, TA updates the trust value of each travel preference and preference attribute set of the unrevoked vehicle in the local database, and then updates the average reputation score of the vehicle based on the trust value of each updated travel preference. In the process of reputation update, the trust value of the travel preference of the carpooling vehicle that is not selected is 0.5 by default.</p><p><xref ref-type="fig" rid="fig7">Figure 7</xref> shows how the average reputation score of honest vehicles changes with the percentage of malicious passengers and weight w<sub>s</sub>. We can see that when the percentage of malicious passengers gradually increases from 5% - 20%, the average reputation score of honest vehicles decreases slowly, which indicates that the presence of malicious passengers can’t largely affect the average reputation score of honest vehicles. Therefore, our trust management model can resist attacks from malicious passengers. As w<sub>s</sub> decreases, the average reputation score of honest carpooling vehicles decreases slightly, which is due to the fact that after the trust value of the travel preferences selected of honest vehicles are updated, the trust value of the corresponding travel preferences increases in a large extent</p><p>and is greater than the historical trust value of unselected travel preferences, reducing the weight w<sub>s</sub> is equivalent to reduce the weight of the travel preference selected and updated by passengers, and the average reputation score of honest vehicles is reduced.</p><p><xref ref-type="fig" rid="fig8">Figure 8</xref> shows the changing process of the average reputation score of malicious vehicles with the percentage of malicious passengers and weight w<sub>s</sub>. We can see that as the percentage of malicious passengers increases, the average reputation score of malicious vehicles increases very slowly, and the false feedback of malicious passengers can’t greatly increase the average reputation score of malicious vehicles. Therefore, the trust management model proposed in this paper shows robustness against malicious users’ attacks. With the weight w<sub>s</sub> decreases, the average reputation score of malicious vehicles has increased slightly, which is due to that after the trust value of travel preferences of vehicle reputation set selected by passengers is updated, the trust value rapidly decreases and is lower than the historical trust value of unselected travel preferences. Decreasing the weight w<sub>s</sub> is equivalent to increase w<sub>t</sub>, and the average reputation score of malicious vehicles is increased to a certain extent.</p></sec></sec><sec id="s8"><title>8. Conclusions</title><p>This paper adopts the privacy set intersection technology based on Bloom filter to propose a trusted and privacy-preserving carpooling matching scheme (TPCM). This scheme not only protects the privacy of vehicles and passengers during carpooling matching, but also solves the problem of carpooling mismatching caused by ignoring the individual needs of passengers by introducing travel preferences, which achieves a balance between precise carpooling matching and privacy protection; In addition, a multi-faceted trust management model is established to better describe the trust between the vehicles and the passengers, and to evaluate the trustworthiness of the vehicle from multi-faceted. Our TPCM scheme is robust against malicious attacks. Performance analysis shows that TPCM scheme can achieve fast and accurate carpooling matching, and has lower overhead compared with existing schemes.</p><p>In the future, we will consider the issue of batch authentication of multiple information, which will reduce the verification delay. And we will consider how to reduce the cost during the verification process and protect the privacy of the vehicle.</p></sec><sec id="s9"><title>Acknowledgements</title><p>This work was in part supported by Fundamental Research Funds for the Central Universities of Jinan University (Grant No. 21621417), Natural Science Foundation of Guangdong Province of China (Grant No. 2017A030308013), Science and Technology Planning Project of Guangdong Province of China (Grant No. KTP20200022), National Natural Science Foundation of China (Grant No. 62032025, No. 62102167).</p></sec><sec id="s10"><title>Conflicts of Interest</title><p>The authors declare no conflicts of interest regarding the publication of this paper.</p></sec><sec id="s11"><title>Cite this paper</title><p>Sun, H.L., Wei, L.F., Wang, L.B., Yin, J.L. and Ma, W.X. (2022) A Trusted and Privacy-Preserving Carpooling Matching Scheme in Vehicular Networks. Journal of Information Security, 13, 1-22. https://doi.org/10.4236/jis.2022.131001</p></sec></body><back><ref-list><title>References</title><ref id="scirp.114903-ref1"><label>1</label><mixed-citation publication-type="other" xlink:type="simple">Liu, Z., Ma, J., Weng, J., Huang, F., Wu, Y., Wei, L. and Li, Y. (2021) LPPTE: A Light-weight Privacy-Preserving Trust Evaluation Scheme for Facilitating Distributed Data Fusion in Cooperative Vehicular Safety Applications. Information Fusion, 73, 144-156. https://doi.org/10.1016/j.inffus.2021.03.003</mixed-citation></ref><ref id="scirp.114903-ref2"><label>2</label><mixed-citation publication-type="other" xlink:type="simple">Chang, I.C., Hung, S.N. and Yen, C.E. (2019) Designing a Dynamic Carpooling System Integrated with the VANET-Based Route-Planning Algorithm. Journal of the Chinese Institute of Engineers, 42, 132-142. https://doi.org/10.1080/02533839.2018.1552841</mixed-citation></ref><ref id="scirp.114903-ref3"><label>3</label><mixed-citation publication-type="other" xlink:type="simple">Wang, Y., Gu, J., Wang, S. and Wang, J. (2019) Understanding Consumers’ Willingness to Use Ride-Sharing Services: The Roles of Perceived Value and Perceived Risk. Transportation Research Part C: Emerging Technologies, 105, 504-519. https://doi.org/10.1016/j.trc.2019.05.044</mixed-citation></ref><ref id="scirp.114903-ref4"><label>4</label><mixed-citation publication-type="other" xlink:type="simple">Tamannaei, M. and Irandoost, I. (2019) Carpooling Problem: A New Mathematical Model, Branch-and-Bound, and Heuristic Beam Search Algorithm. Journal of Intelligent Transportation Systems, 23, 203-215. https://doi.org/10.1080/15472450.2018.1484739</mixed-citation></ref><ref id="scirp.114903-ref5"><label>5</label><mixed-citation publication-type="other" xlink:type="simple">Li, M., Zhu, L.H., Zhang, Z.J. and Xu, R.X. (2017) Achieving Differential Privacy of Trajectory Data Publishing in Participatory Sensing. Information Sciences, 400-401, 1-13. https://doi.org/10.1016/j.ins.2017.03.015</mixed-citation></ref><ref id="scirp.114903-ref6"><label>6</label><mixed-citation publication-type="other" xlink:type="simple">Sherif, A.B., Rabieh, K., Mahmoud, M.M. and Liang, X. (2016) Privacy-Preserving Ride Sharing Scheme for Autonomous Vehicles in Big Data Era. IEEE Internet of Things Journal, 4, 611-618. https://doi.org/10.1109/JIOT.2016.2569090</mixed-citation></ref><ref id="scirp.114903-ref7"><label>7</label><mixed-citation publication-type="other" xlink:type="simple">Yu, H., Jia, X., Zhang, H., Yu, X. and Shu, J. (2019) PSRide: Privacy-Preserving Shared Ride Matching for Online Ride Hailing Systems. IEEE Transactions on Dependable and Secure Computing, 18, 1425-1440. https://doi.org/10.1109/TDSC.2019.2931295</mixed-citation></ref><ref id="scirp.114903-ref8"><label>8</label><mixed-citation publication-type="other" xlink:type="simple">Wang, F., Zhu, H., Liu, X., Lu, R., Li, F., Li, H. and Zhang, S. (2018) Efficient and Privacy-Preserving Dynamic Spatial Query Scheme for Ride-Hailing Services. IEEE Transactions on Vehicular Technology, 67, 11084-11097. https://doi.org/10.1109/TVT.2018.2868869</mixed-citation></ref><ref id="scirp.114903-ref9"><label>9</label><mixed-citation publication-type="other" xlink:type="simple">Wernke, M., Dürr, F. and Rothermel, K. (2013) PShare: Ensuring Location Privacy in Non-Trusted Systems through Multi-Secret Sharing. Pervasive and Mobile Computing, 9, 339-352. https://doi.org/10.1016/j.pmcj.2013.01.001</mixed-citation></ref><ref id="scirp.114903-ref10"><label>10</label><mixed-citation publication-type="other" xlink:type="simple">Yu, H., Zhang, H., Yu, X., Du, X. and Guizani, M. (2020) PGRide: Privacy-Preserving Group Ridesharing Matching in Online Ride Hailing Services. IEEE Internet of Things Journal, 8, 5722-5735. https://doi.org/10.1109/JIOT.2020.3030274</mixed-citation></ref><ref id="scirp.114903-ref11"><label>11</label><mixed-citation publication-type="other" xlink:type="simple">Gruteser, M. and Grunwald, D. (2003) Anonymous Usage of Location-Based Services through Spatial and Temporal Cloaking. Proceedings of the 1st International Conference on Mobile Systems, Applications and Services, San Francisco, 5-8 May 2003, 31-42. https://doi.org/10.1145/1066116.1189037</mixed-citation></ref><ref id="scirp.114903-ref12"><label>12</label><mixed-citation publication-type="other" xlink:type="simple">Kou, B., Cao, S. and Lv, J. (2020, July) A Privacy Protection Scheme for Carpooling Service Using Fog Computing. Journal of Physics: Conference Series, 1601, Article ID: 032019. https://doi.org/10.1088/1742-6596/1601/3/032019</mixed-citation></ref><ref id="scirp.114903-ref13"><label>13</label><mixed-citation publication-type="other" xlink:type="simple">Li, M., Zhu, L. and Lin, X. (2018) Efficient and Privacy-Preserving Carpooling Using Blockchain-Assisted Vehicular Fog Computing. IEEE Internet of Things Journal, 6, 4573-4584. https://doi.org/10.1109/JIOT.2018.2868076</mixed-citation></ref><ref id="scirp.114903-ref14"><label>14</label><mixed-citation publication-type="other" xlink:type="simple">Tyagi, A.K. and Sreenath, N. (2016) Vehicular Ad Hoc Networks: New Challenges in Carpooling and Parking Services. International Journal of Computer Science and Information Security, 14, 13-24.</mixed-citation></ref><ref id="scirp.114903-ref15"><label>15</label><mixed-citation publication-type="other" xlink:type="simple">Liu, Z., Ma, J., Jiang, Z., Zhu, H. and Miao, Y. (2016) LSOT: A Lightweight Self-Organized Trust Model in VANETs. Mobile Information Systems, 2016, Article ID: 7628231. https://doi.org/10.1155/2016/7628231</mixed-citation></ref><ref id="scirp.114903-ref16"><label>16</label><mixed-citation publication-type="other" xlink:type="simple">Tangade, S., Manvi, S.S. and Lorenz, P. (2020) Trust Management Scheme Based on Hybrid Cryptography for Secure Communications in VANETs. IEEE Transactions on Vehicular Technology, 69, 5232-5243. https://doi.org/10.1109/TVT.2020.2981127</mixed-citation></ref><ref id="scirp.114903-ref17"><label>17</label><mixed-citation publication-type="other" xlink:type="simple">Jaimes, L.M.S., Ullah, K. and dos Santos Moreira, E. (2016) ARS: Anonymous Reputation System for Vehicular Ad Hoc Networks. 2016 8th IEEE Latin-American Conference on Communications (LATINCOM), Medellin, 15-17 November 2016, 1-6. https://doi.org/10.1109/LATINCOM.2016.7811600</mixed-citation></ref><ref id="scirp.114903-ref18"><label>18</label><mixed-citation publication-type="other" xlink:type="simple">Wang, S. and Yao, N. (2019) A RSU-Aided Distributed Trust Framework for Pseudonym-Enabled Privacy Preservation in VANETs. Wireless Networks, 25, 1099-1115. https://doi.org/10.1007/s11276-018-1681-8</mixed-citation></ref><ref id="scirp.114903-ref19"><label>19</label><mixed-citation publication-type="other" xlink:type="simple">Liu, Z., Guo, J., Huang, F., Cai, D., Wu, Y., Chen, X. and Konstantin Igorevich, K. (2021) Lightweight Trustworthy Message Exchange in Unmanned Aerial Vehicle Networks. IEEE Transactions on Intelligent Transportation Systems, 1-14. https://doi.org/10.1109/TITS.2021.3136304</mixed-citation></ref><ref id="scirp.114903-ref20"><label>20</label><mixed-citation publication-type="other" xlink:type="simple">Hallgren, P., Orlandi, C. and Sabelfeld, A. (2017) PrivatePool: Privacy-Preserving Ridesharing. 2017 IEEE 30th Computer Security Foundations Symposium (CSF), Santa Barbara, 21-25 August 2017, 276-291. https://doi.org/10.1109/CSF.2017.24</mixed-citation></ref><ref id="scirp.114903-ref21"><label>21</label><mixed-citation publication-type="other" xlink:type="simple">Salamanis, A., Kehagias, D.D., Tsoukalas, D. and Tzovaras, D. (2019) Reputation Assessment Mechanism for Carpooling Applications Based on Clustering User Travel Preferences. International Journal of Transportation Science and Technology, 8, 68-81. https://doi.org/10.1016/j.ijtst.2018.08.002</mixed-citation></ref><ref id="scirp.114903-ref22"><label>22</label><mixed-citation publication-type="other" xlink:type="simple">Caballero-Gil, C., Caballero-Gil, P., Molina-Gil, J., Martín-Fernández, F. and Loia, V. (2017) Trust-Based Cooperative Social System Applied to a Carpooling Platform for Smartphones. Sensors, 17, Article No. 245. https://doi.org/10.3390/s17020245</mixed-citation></ref><ref id="scirp.114903-ref23"><label>23</label><mixed-citation publication-type="other" xlink:type="simple">Baza, M., Lasla, N., Mahmoud, M., Srivastava, G. and Abdallah, M. (2019) B-Ride: Ride Sharing with Privacy-Preservation, Trust and Fair Payment Atop Public Blockchain. IEEE Transactions on Network Science and Engineering, 8, 1214-1299. https://doi.org/10.1109/TNSE.2019.2959230</mixed-citation></ref><ref id="scirp.114903-ref24"><label>24</label><mixed-citation publication-type="other" xlink:type="simple">Sánchez, D., Martínez, S. and Domingo-Ferrer, J. (2016) Co-Utile P2P Ridesharing via Decentralization and Reputation Management. Transportation Research Part C: Emerging Technologies, 73, 147-166. https://doi.org/10.1016/j.trc.2016.10.017</mixed-citation></ref><ref id="scirp.114903-ref25"><label>25</label><mixed-citation publication-type="other" xlink:type="simple">Abassi, R., Douss, A.B.C. and Sauveron, D. (2020) TSME: A Trust-Based Security Scheme for Message Exchange in Vehicular Ad Hoc Networks. Human-Centric Computing and Information Sciences, 10, Article No 43. https://doi.org/10.1186/s13673-020-00248-4</mixed-citation></ref><ref id="scirp.114903-ref26"><label>26</label><mixed-citation publication-type="other" xlink:type="simple">Farouk, F., Alkady, Y. and Rizk, R. (2020) Efficient Privacy-Preserving Scheme for Location Based Services in VANETSystem. IEEE Access, 8, 60101-60116. https://doi.org/10.1109/ACCESS.2020.2982636</mixed-citation></ref><ref id="scirp.114903-ref27"><label>27</label><mixed-citation publication-type="other" xlink:type="simple">Zhang, X. and Wang, D. (2019) Adaptive Traffic Signal Control Mechanism for Intelligent Transportation Based on a Consortium Blockchain. IEEE Access, 7, 97281-97295. https://doi.org/10.1109/ACCESS.2019.2929259</mixed-citation></ref><ref id="scirp.114903-ref28"><label>28</label><mixed-citation publication-type="other" xlink:type="simple">Kiss, S.Z., Hosszu, é., Tapolcai, J., Rónyai, L. and Rottenstreich, O. (2021) Bloom Filter with a False Positive Free zone. IEEE Transactions on Network and Service Management, 18, 2334-2349. https://doi.org/10.1109/TNSM.2021.3059075</mixed-citation></ref><ref id="scirp.114903-ref29"><label>29</label><mixed-citation publication-type="other" xlink:type="simple">Liu, Z., Huang, F., Weng, J., Cao, K., Miao, Y., Guo, J. and Wu, Y. (2020) BTMPP: Balancing Trust Management and Privacy Preservation for Emergency Message Dissemination in Vehicular Networks. IEEE Internet of Things Journal, 8, 5386-5407. https://doi.org/10.1109/JIOT.2020.3037098</mixed-citation></ref><ref id="scirp.114903-ref30"><label>30</label><mixed-citation publication-type="other" xlink:type="simple">Sun, G., Sun, S., Sun, J., Yu, H., Du, X. and Guizani, M. (2019) Security and Privacy Preservation in Fog-Based Crowd Sensing on the Internet of Vehicles. Journal of Network and Computer Applications, 134, 89-99. https://doi.org/10.1016/j.jnca.2019.02.018</mixed-citation></ref><ref id="scirp.114903-ref31"><label>31</label><mixed-citation publication-type="other" xlink:type="simple">Wang, D. and Zhang, X. (2020) Secure Ride-Sharing Services Based on a Consortium Blockchain. IEEE Internet of Things Journal, 8, 2976-2991. https://doi.org/10.1109/JIOT.2020.3023920</mixed-citation></ref><ref id="scirp.114903-ref32"><label>32</label><mixed-citation publication-type="other" xlink:type="simple">He, Y., Ni, J., Wang, X., Niu, B., Li, F. and Shen, X. (2018) Privacy-Preserving Partner Selection for Ride-Sharing Services. IEEE Transactions on Vehicular Technology, 67, 5994-6005. https://doi.org/10.1109/TVT.2018.2809039</mixed-citation></ref></ref-list></back></article>