Unmanned aerial vehicle identity authentication and key negotiation system and method

By introducing physical non-clone functions and Chebishev chaos mapping technology into the drone network, combined with fuzzy feature extraction, drone identity authentication and key negotiation are realized, solving the problems of high computing and communication overhead and insufficient security in the drone network, and improving communication security and ability to resist attacks.

CN120301602APending Publication Date: 2025-07-11JIANGSU SECOND NORMAL UNIVERSITY
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510490217.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-18
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

The existing drone networks have problems such as excessive computing and communication overhead and incomplete security functions in terms of identity authentication and key negotiation, especially in wireless communications that are vulnerable to malicious attacks, and the resources of drone equipment are limited and it is difficult to bear complex security protection mechanisms.

Method used

The physical non-clone function (PUF), fuzzy feature extraction and Chebishev chaos mapping technology are used, combined with trusted registration agencies, mobile terminals and cloud servers, drone identity authentication and key negotiation are realized, registration and authentication are carried out through secure channels, and a unique session key is generated to ensure communication security.

Benefits of technology

It effectively reduces the cost of computing and communication, enhances security, resists man-in-the-middle attacks and replay attacks, ensures forward confidentiality and untraceability of communication entities, and prevents identity information leakage.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

The invention discloses an unmanned aerial vehicle identity authentication and key negotiation system and method. The system comprises a trusted registration mechanism, an unmanned aerial vehicle, a cloud server and a mobile terminal, in a system initialization stage, a trusted registration mechanism publicly releases a single hash function and a symmetric encryption / decryption algorithm; in a mobile terminal registration stage, a trusted registration mechanism verifies a registration request of a user; in the unmanned aerial vehicle registration stage, the unmanned aerial vehicle sends its identity ID to the trusted registration mechanism to request registration, and the trusted registration mechanism distributes a unique challenge and random number to the unmanned aerial vehicle after receiving the identity ID; in the user login stage, a user ID, a password and biological characteristics are input into the mobile terminal, and the mobile terminal verifies the user identity through pre-stored parameters; in the identity authentication and key negotiation stage, mutual authentication is carried out among the mobile terminal, the cloud server and the unmanned aerial vehicle, and a session key for future encrypted communication is negotiated.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of unmanned aerial vehicles, and particularly relates to an identity authentication and key negotiation technology. Background Art

[0002] The authentication and key agreement (AKA) scheme is one of the key technologies to ensure data transmission security in the Internet of Drones (IoD) environment. Existing AKA schemes generally have problems of excessive computing and communication overheads and incomplete security functions. With the continuous expansion of the scale of the drone network and the increasing complexity of application scenarios, IoD based on cloud architecture also faces severe security challenges.

[0003] Users, cloud servers, and drones rely on wireless communication technology for remote control and data transmission. Malicious attackers may intercept, tamper with, or inject false data, destroying the integrity and confidentiality of data transmission and affecting the normal operation and decision-making process of drones. Due to limited resources, it is difficult for drone devices to carry complex security protection mechanisms and they are prone to becoming vulnerable links exploited by attackers.

[0004] Physical unclonable function, as an advanced security technology based on the inherent physical characteristics of devices, aims to generate unique and non-replicable responses by using the randomness and unpredictability in the microfabrication process. PUF technology can generate unique responses for each physical entity, thus providing a strong protection mechanism in security applications such as identity authentication and key generation. The fuzzy extractor is an advanced encryption technology that aims to extract robust and discriminative keys from noisy or inaccurate input data, such as biometric features or PUF responses. The Chebyshev chaotic map is a discrete chaotic map based on Chebyshev polynomials, which utilizes the inherent unpredictability of chaotic systems and extreme sensitivity to initial conditions. Summary of the Invention

[0005] In order to solve the technical problems of excessive computing and communication costs and potential hidden dangers in security protection, technical means of physical unclonability, fuzzy feature extraction, and Chebyshev chaotic mapping are adopted to implement a system and method for drone identity authentication and key negotiation.

[0006] The system includes a trusted registration authority, drones, a cloud server, and a mobile terminal; the trusted registration authority registers the mobile terminal and drones through a secure channel; the drones are deployed in different regions; the cloud server collects key data of the drones; users obtain real-time information, third-party services, and transmit control commands from the server or drones through the mobile terminal.

[0007] The method includes: In the system initialization stage, the trusted registration authority publicly releases a one-way hash function and a symmetric encryption / decryption algorithm, assigns a unique identity identifier and a master key to the cloud server, and stores them in the cloud server for subsequent authentication calculations; In the mobile terminal registration stage, the trusted registration authority receives the registration request of the mobile terminal, calculates the first user registration verification parameter through the publicly released one-way hash function, retrieves the database, verifies the registration request of the user, completes the identity registration for the mobile terminal, and stores the identity information; In the drone registration stage, the drone sends its identity ID to the trusted registration authority to request registration. After receiving it, the trusted registration authority assigns a unique challenge and a random number to it. The drone sends a PUF response to the trusted registration authority, and the trusted registration authority stores the drone identity ID, challenge, random number, and PUF response in the cloud server; In the user login stage, the user ID, password, and biometric features are input into the mobile terminal. The mobile terminal verifies the user's identity through the pre-stored parameters and provides services to the user according to the user request information; In the identity authentication and key negotiation stage, mutual authentication is performed among the mobile terminal, cloud server, and drone, and a session key for future encrypted communication is negotiated. The mobile terminal updates the temporary identity in the memory and stores the session key for encrypted communication between the cloud server and the drone.

[0008] Furthermore, in the mobile terminal registration stage, if the mobile terminal is not registered, the trusted registration authority assigns a unique temporary identity to it, uses the unique number of the mobile terminal, and calculates its pseudo-identity and the second user registration verification parameter through the one-way hash function.

[0009] The trusted registration authority records the secret credentials of the user-related identity information in the database of the cloud server, sends the relevant credentials to the mobile terminal through a secure channel. The user sets a unique password and enters its biometric features through the mobile terminal. The mobile terminal calculates the relevant credentials using the generation function, exclusive OR, and one-way hash function of the fuzzy feature extractor and stores them in the memory.

[0010] Furthermore, in the drone registration stage, the trusted registration authority calculates the first drone registration verification parameter, sends the challenge and the first drone registration verification parameter to the drone through a secure channel. The drone receives the credentials, extracts the challenge as the input of the physically unclonable function PUF(.), calculates the PUF response, and stores the drone identity ID, the first drone registration verification parameter, and the PUF(.) function in the memory.

[0011] Further, in the user login stage, the mobile terminal calculates biometric recovery data, biometric keys, first login verification parameters, and first login keys, extracts the first user registration ciphertext in the memory, and obtains second user verification parameters, pseudo-user IDs, and fifth user registration parameters according to the publicly released decryption function. Then it calculates the second login verification parameter. If it matches the fifth user registration verification parameter, the user logs in; otherwise, the process terminates.

[0012] Further, in the identity authentication and key negotiation stage, the mobile terminal sends a first message to the cloud server. After verification, the cloud server obtains the drone ID and sends a second message to the drone. After verification, the drone obtains the pseudo-user ID and sends a third message to the cloud server. Then the cloud server sends a fourth message to the mobile terminal.

[0013] The user selects a random number as the first random number and calculates the first chaotic mapping parameter. The mobile terminal selects an authorized drone ID from the memory, generates two random numbers as the second random number and the third random number, and uses the current time as the first timestamp. The mobile terminal calculates the first verification parameter and the first authentication key, and calculates the first ciphertext according to the first key. Through an insecure public channel, the first message is sent to the cloud server, and the first message includes the user's temporary identity, the third random number, the first ciphertext, and the first timestamp.

[0014] The cloud server extracts the first timestamp from the first message, calculates the difference between it and the current time, and takes the absolute value. If it is not greater than the maximum transmission delay, the message is determined to be fresh. The cloud server retrieves the database according to the temporary user ID. If there is an old temporary identity that is the same as the user's temporary identity, it extracts the associated mobile terminal number, calculates the second verification parameter and the second key, and decrypts the first ciphertext according to the second key. According to the decryption result obtained, it calculates the third verification parameter. If it matches the first verification parameter, it obtains the valid pseudo-user ID, drone ID, first chaotic mapping parameter, and second random number.

[0015] The cloud server retrieves the database according to the drone ID, obtains the corresponding identity information, generates the fourth random number and the fifth random number, and uses the current time as the second timestamp. It calculates the fourth verification parameter, the fifth verification parameter, the sixth verification parameter, and the third key, and calculates the second ciphertext according to the third key. Through an open and insecure channel, the second message is sent to the drone, and the second message includes the fifth random number, the second ciphertext, and the second timestamp.

[0016] The drone extracts the second timestamp from the second message. If the message is fresh, it extracts the first verification parameter for drone registration from memory, calculates the seventh verification parameter and the fourth key; decrypts the second ciphertext using the fourth key to obtain the pseudo-user ID, drone challenge, second random number, fourth random number, first chaotic mapping parameter, and sixth verification parameter; calculates the eighth verification parameter based on the obtained decryption result. If it matches the sixth verification parameter, it obtains the valid plaintext pseudo-user ID, drone challenge, second random number, fourth random number, and first timestamp; otherwise, it terminates the connection.

[0017] The drone obtains the PUF response based on the challenge, inputs the PUF response into the function for generating fuzzy feature extractor to obtain the recovery key and recovery data, generates two random numbers as the sixth random number and the seventh random number, and uses the current time as the third timestamp; calculates the session key between the user and the cloud service, the second chaotic mapping parameter, the shared credential, the session key between the user and the drone, the fifth key, the ninth verification parameter, and the third ciphertext, and stores the session keys between the user and the drone and the server; sends the third message to the cloud server through an insecure public channel, and the third message includes the third timestamp and the third ciphertext.

[0018] The cloud server confirms that the third message is fresh, calculates the sixth key, decrypts the third ciphertext using the sixth key to obtain the sixth random number, recovery data, second chaotic mapping parameter, and ninth verification parameter; calculates the tenth verification parameter. If it matches the ninth verification parameter, it calculates the response data key, the session key between the user and the drone, and the session key between the user and the cloud service based on the PUF response and the recovery data; the cloud server generates a new temporary identity for the user and stores the session keys between the user and the drone and the server; uses the current time as the fourth timestamp, calculates the eleventh verification parameter and the seventh key, and calculates the fourth ciphertext using the seventh key; sends the fourth message to the mobile terminal, and the fourth message includes the fourth ciphertext and the fourth timestamp.

[0019] The mobile terminal confirms that the fourth message is fresh, calculates the eighth key, decrypts the fourth ciphertext using the eighth key to obtain the fourth random number, sixth random number, user temporary identity, second chaotic mapping parameter, and eleventh verification parameter; calculates the twelfth verification parameter. If it matches the eleventh verification parameter, it obtains the valid plaintext fourth random number, sixth random number, user temporary identity, and second chaotic mapping parameter; calculates the session key between the mobile terminal and the cloud service, the shared credential, and the session key between the mobile terminal and the drone, updates the temporary identity in the memory, and stores the session keys.

[0020] The session keys adopted are constructed from short-term and long-term secret credentials unique to each session and communication entity, ensuring that attackers cannot trace session keys across sessions or communication entities, achieving forward secrecy.

[0021] The sent message contains the current timestamp, a random number, and a ciphertext encrypted with a secret credential specific to the session and the communication entity. The communication entity receiving the message verifies the timestamp and the ciphertext to confirm the freshness and authenticity of the message, and an attacker cannot perform a replay attack against this scheme.

[0022] The user's temporary identity is updated at the end of each authentication cycle. Even if the user's temporary identity is identified from the intercepted message, it cannot be used to trace the user, ensuring the untraceability of the communication entity.

[0023] In the absence of the user's identity ID, password, and biometric information, even if the secret credential stored in the mobile terminal is extracted through a side-channel attack, the first user's encrypted data cannot be decrypted, effectively resisting the leakage caused by the loss of the mobile terminal.

[0024] Each message contains a ciphertext generated by symmetric encryption and a verification parameter calculated from the corresponding plaintext. Any unauthorized message tampering will cause the receiving party to detect that the ciphertext is invalid. Even if all the messages transmitted during the identity authentication and key negotiation phases are intercepted, the tampering is ineffective, effectively resisting attacks of intermediate interception and tampering.

[0025] The cloud server retains the user's latest temporary identity and the temporary identity of the previous session, ensuring that there is always consistent identity information between them. Even if the message is intercepted and the mobile terminal's update of the temporary identity is interfered with, subsequent identity authentication and key negotiation can still proceed normally, being robust against desynchronization attacks. Detailed implementation manners

[0026] The technical solution of the present invention will be specifically described below.

[0027] A system is constructed using a trusted registration authority, drones, a cloud server, and mobile terminals; the trusted registration authority registers the mobile terminals and drones through a secure channel; the drones are deployed in different regions; the cloud server collects the key data of the drones; the user obtains real-time information, third-party services, and transmits control commands from the server or the drones through the mobile terminal.

[0028] In the system initialization phase, the trusted registration authority publicly releases a one-way hash function and a symmetric encryption / decryption algorithm, assigns a unique identity identifier and a master key to the cloud server, and stores them in the cloud server for subsequent authentication calculations.

[0029] In the mobile terminal registration phase, the trusted registration authority receives the registration request of the mobile terminal, calculates the first verification parameter for user registration through the publicly released one-way hash function, retrieves the database, verifies the registration request of the user, completes the identity registration of the mobile terminal, and stores the identity information.

[0030] If the mobile terminal is not registered, the trusted registration authority assigns it a unique temporary identity, uses the unique number of the mobile terminal, and calculates its pseudo-identity and the second user registration verification parameter through a one-way hash function.

[0031] The trusted registration authority records the secret credentials of the user-related identity information in the database of the cloud server, sends the relevant credentials to the mobile terminal through a secure channel. The user sets a unique password and enters their biometric features through the mobile terminal. The mobile terminal calculates the relevant credentials using the generation function of the fuzzy feature extractor, XOR, and one-way hash function, and stores them in the memory.

[0032] In the drone registration phase, the drone sends its identity ID to the trusted registration authority to request registration. After receiving it, the trusted registration authority assigns it a unique challenge and random number. The drone sends a PUF response to the trusted registration authority, and the trusted registration authority stores the drone identity ID, challenge, random number, and PUF response in the cloud server.

[0033] The trusted registration authority calculates the first drone registration verification parameter, sends the challenge and the first drone registration verification parameter to the drone through a secure channel. The drone receives the credentials, extracts the challenge as the input of the physically unclonable function PUF(.), calculates the PUF response, and stores the drone identity ID, the first drone registration verification parameter, and the PUF(.) function in the memory.

[0034] In the user login phase, the user ID, password, and biometric features are input into the mobile terminal. The mobile terminal verifies the user's identity through the pre-stored parameters and provides services to the user according to the user's request information.

[0035] The mobile terminal calculates the biometric recovery data, biometric key, first login verification parameter, first login key, extracts the first user registration ciphertext in the memory, obtains the second user verification parameter, pseudo-user ID, and the fifth user registration parameter according to the publicly released decryption function, and calculates the second login verification parameter. If it matches the fifth user registration verification parameter, the user logs in; otherwise, the process terminates.

[0036] In the identity authentication and key negotiation phase, mutual authentication is performed among the mobile terminal, cloud server, and drone, and a session key for future encrypted communication is negotiated. The mobile terminal updates the temporary identity in the memory and stores the session key for encrypted communication between the cloud server and the drone.

[0037] The mobile terminal sends a first message to the cloud server. The cloud server obtains the drone ID after comparison. The cloud server sends a second message to the drone. The drone obtains the pseudo-user ID after comparison. The drone sends a third message to the cloud server. The cloud server sends a fourth message to the mobile terminal.

[0038] The user selects a random number as the first random number and calculates the first chaotic mapping parameter. The mobile terminal selects an authorized drone ID from the memory, generates two random numbers as the second random number and the third random number, and uses the current time as the first timestamp. The mobile terminal calculates the first verification parameter, the first authentication key, and calculates the first ciphertext based on the first key. Through an insecure public channel, the first message is sent to the cloud server. The first message includes the user's temporary identity, the third random number, the first ciphertext, and the first timestamp.

[0039] The cloud server extracts the first timestamp from the first message, calculates the difference between it and the current time, takes the absolute value, and if it is not greater than the maximum transmission delay, determines that the message is fresh. The cloud server retrieves the database according to the temporary user ID. If there is an old temporary identity that is the same as the user's temporary identity, it extracts the associated mobile terminal number, calculates the second verification parameter and the second key, and decrypts the first ciphertext based on the second key. The third verification parameter is calculated based on the extracted decryption result. If it matches the first verification parameter, the valid pseudo-user ID, drone ID, first chaotic mapping parameter, and second random number are obtained.

[0040] The cloud server retrieves the database according to the drone ID, obtains the corresponding identity information, generates the fourth random number and the fifth random number, and uses the current time as the second timestamp. The fourth verification parameter, the fifth verification parameter, the sixth verification parameter, and the third key are calculated, and the second ciphertext is calculated based on the third key. Through an open and insecure channel, the second message is sent to the drone. The second message includes the fifth random number, the second ciphertext, and the second timestamp.

[0041] The drone extracts the second timestamp from the second message. If the message is fresh, it extracts the first verification parameter registered by the drone from the memory, calculates the seventh verification parameter and the fourth key. The second ciphertext is decrypted based on the fourth key to obtain the pseudo-user ID, drone challenge, second random number, fourth random number, first chaotic mapping parameter, and sixth verification parameter. The eighth verification parameter is calculated based on the obtained decryption result. If it matches the sixth verification parameter, the valid plaintext pseudo-user ID, drone challenge, second random number, fourth random number, and first timestamp are obtained; otherwise, the connection is terminated.

[0042] The drone obtains the PUF response according to the challenge, inputs the PUF response into the function of the fuzzy feature extractor to obtain the recovery key and recovery data, generates two random numbers as the sixth random number and the seventh random number, and uses the current time as the third timestamp; calculates the session key between the user and the cloud service, the second chaotic mapping parameter, the shared credential, the session key between the user and the drone, the fifth key, the ninth verification parameter, and the third ciphertext, and stores the session keys between the user and the drone and the server; sends the third message to the cloud server through an insecure public channel, and the third message includes the third timestamp and the third ciphertext.

[0043] The cloud server confirms the freshness of the third message, calculates the sixth key, decrypts the third ciphertext according to the sixth key to obtain the sixth random number, recovery data, the second chaotic mapping parameter, and the ninth verification parameter; calculates the tenth verification parameter, and if it matches the ninth verification parameter, calculates the response data key, the session key between the user and the drone, and the session key between the user and the cloud service according to the PUF response and the recovery data; the cloud server generates a new temporary identity for the user and stores the session keys between the user and the drone and the server; uses the current time as the fourth timestamp, calculates the eleventh verification parameter and the seventh key, and calculates the fourth ciphertext according to the seventh key; sends the fourth message to the mobile terminal, and the fourth message includes the fourth ciphertext and the fourth timestamp.

[0044] The mobile terminal confirms the freshness of the fourth message, calculates the eighth key, decrypts the fourth ciphertext according to the eighth key to obtain the fourth random number, the sixth random number, the user's temporary identity, the second chaotic mapping parameter, and the eleventh verification parameter; calculates the twelfth verification parameter, and if it matches the eleventh verification parameter, obtains the valid plaintext fourth random number, the sixth random number, the user's temporary identity, and the second chaotic mapping parameter; calculates the session key between the mobile terminal and the cloud service, the shared credential, and the session key between the mobile terminal and the drone, updates the temporary identity in the memory, and stores the session key.

[0045] The above are the embodiments of the present invention and do not limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention are all included in the protection scope of the present invention.

Claims

1. A system for UAV identity authentication and key negotiation, characterized in that, Including: A trusted registration authority, drones, a cloud server, and a mobile terminal; The trusted registration authority registers the mobile terminal and the drones through a secure channel; The drones are deployed in different areas; The cloud server collects key data of the drones; The user obtains real-time information, third-party services, and transmits control commands from the server or the drones through the mobile terminal.

2. A method for unmanned aerial vehicle identity authentication and key negotiation, characterized in that, The system for drone identity authentication and key negotiation according to claim 1, including: In the system initialization phase, the trusted registration authority publicly releases a one-way hash function and a symmetric encryption / decryption algorithm, assigns a unique identity identifier and a master key to the cloud server, and stores them in the cloud server for subsequent authentication calculations; In the mobile terminal registration phase, when the trusted registration authority receives the registration request of the mobile terminal, it calculates the first user registration verification parameter through the publicly released one-way hash function, retrieves the database, verifies the registration request of the user, completes the identity registration of the mobile terminal, and stores the identity information; In the drone registration phase, the drone sends its identity ID to the trusted registration authority to request registration. After receiving it, the trusted registration authority assigns a unique challenge and a random number to it. The drone sends a PUF response to the trusted registration authority, and the trusted registration authority stores the drone identity ID, challenge, random number, and PUF response in the cloud server; In the user login phase, the user ID, password, and biometric features are input into the mobile terminal. The mobile terminal verifies the user identity through the pre-stored parameters and provides services to the user according to the user request information; In the identity authentication and key negotiation phase, mutual authentication is performed among the mobile terminal, the cloud server, and the drones, and a session key for future encrypted communication is negotiated. The mobile terminal updates the temporary identity in the memory and stores the session key for encrypted communication between the cloud server and the drones.

3. The method for drone identity authentication and key negotiation according to claim 2, wherein The mobile terminal registration phase includes: If the mobile terminal is not registered, the trusted registration authority assigns a unique temporary identity to it, uses the unique number of the mobile terminal, and calculates its pseudo-identity and the second user registration verification parameter through the one-way hash function.

4. The method for drone identity authentication and key negotiation according to claim 3, wherein The mobile terminal registration phase further includes: The trusted registration authority records the secret credentials of the user-related identity information in the database of the cloud server, sends the relevant credentials to the mobile terminal through a secure channel. The user sets a unique password and enters its biometric features through the mobile terminal. The mobile terminal calculates the relevant credentials using the generation function of the fuzzy feature extractor, XOR, and the one-way hash function, and stores them in the memory.

5. The method for drone identity authentication and key negotiation according to claim 2, characterized in that, The drone registration phase includes: The trusted registration authority calculates the first drone registration verification parameter, sends the challenge and the first drone registration verification parameter to the drone through a secure channel. After receiving the credentials, the drone extracts the challenge as the input of the physically unclonable function PUF(.), calculates the PUF response, and stores the drone identity ID, the first drone registration verification parameter, and the PUF(.) function in the memory.

6. The method for drone identity authentication and key negotiation according to claim 2, wherein In the user login phase, it includes: the mobile terminal calculates biometric recovery data, a biometric key, a first login verification parameter, and a first login key, extracts the first user registration ciphertext in the memory, and obtains a second user verification parameter, a pseudo-user ID, and a fifth user registration parameter according to the publicly released decryption function, calculates a second login verification parameter. If it matches the fifth login verification parameter of the user registration, the user logs in; otherwise, the process terminates.

7. The method for drone identity authentication and key negotiation according to claim 2, characterized in that In the identity authentication and key negotiation phase, it includes: the mobile terminal sends a first message to the cloud server, the cloud server obtains the drone ID after comparison, the cloud server sends a second message to the drone, the drone obtains the pseudo-user ID after comparison, the drone sends a third message to the cloud server, and the cloud server sends a fourth message to the mobile terminal.

8. The method for UAV identity authentication and key negotiation according to claim 7, wherein In the identity authentication and key negotiation phase, it includes: the user selects a random number as the first random number and calculates the first chaotic mapping parameter; the mobile terminal selects an authorized drone ID from the memory, generates two random numbers as the second random number and the third random number, and uses the current time as the first timestamp; the mobile terminal calculates the first verification parameter and the first authentication key, and calculates the first ciphertext according to the first key; through an insecure public channel, the first message is sent to the cloud server, and the first message includes the user's temporary identity, the third random number, the first ciphertext, and the first timestamp. The cloud server extracts the first timestamp from the first message, calculates the difference between it and the current time, and takes the absolute value. If it is not greater than the maximum transmission delay, the message is determined to be fresh; the cloud server retrieves the database according to the temporary user ID. If there is an old temporary identity that is the same as the user's temporary identity, the associated mobile terminal number is extracted, the second verification parameter and the second key are calculated, and the first ciphertext is decrypted according to the second key; the third verification parameter is calculated according to the extracted decryption result. If it matches the first verification parameter, a valid pseudo-user ID, drone ID, first chaotic mapping parameter, and second random number are obtained. The cloud server retrieves the database according to the drone ID, obtains the corresponding identity information, generates a fourth random number and a fifth random number, and uses the current time as the second timestamp; calculates the fourth verification parameter, the fifth verification parameter, the sixth verification parameter, and the third key, and calculates the second ciphertext according to the third key; through an open and insecure channel, the second message is sent to the drone, and the second message includes the fifth random number, the second ciphertext, and the second timestamp. The drone extracts the second timestamp from the second message. If the message is fresh, it extracts the first verification parameter of the drone registration from the memory and calculates the seventh verification parameter and the fourth key; decrypts the second ciphertext according to the fourth key to obtain the pseudo-user ID, drone challenge, second random number, fourth random number, first chaotic mapping parameter, and sixth verification parameter; calculates the eighth verification parameter according to the obtained decryption result. If it matches the sixth verification parameter, a valid plaintext pseudo-user ID, drone challenge, second random number, fourth random number, and first timestamp are obtained; otherwise, the connection is terminated. The drone obtains the PUF response according to the challenge, inputs the PUF response into the function of the fuzzy feature extractor to obtain the recovery key and recovery data, generates two random numbers as the sixth random number and the seventh random number, and uses the current time as the third timestamp; calculates the session key between the user and the cloud service, the second chaotic mapping parameter, the shared credential, the session key between the user and the drone, the fifth key, the ninth verification parameter, and the third ciphertext, and stores the session keys between the user and the drone and the server; sends the third message to the cloud server through an insecure public channel, and the third message includes the third timestamp and the third ciphertext. The cloud server confirms the freshness of the third message, calculates the sixth key, decrypts the third ciphertext according to the sixth key to obtain the sixth random number, recovery data, the second chaotic mapping parameter, and the ninth verification parameter; calculates the tenth verification parameter, and if it matches the ninth verification parameter, calculates the response data key, the session key between the user and the drone, and the session key between the user and the cloud service according to the PUF response and the recovery data; the cloud server generates a new temporary identity for the user and stores the session keys between the user and the drone and the server; uses the current time as the fourth timestamp, calculates the eleventh verification parameter and the seventh key, and calculates the fourth ciphertext according to the seventh key; sends the fourth message to the mobile terminal, and the fourth message includes the fourth ciphertext and the fourth timestamp. The mobile terminal confirms the freshness of the fourth message, calculates the eighth key, decrypts the fourth ciphertext according to the eighth key to obtain the fourth random number, the sixth random number, the user's temporary identity, the second chaotic mapping parameter, and the eleventh verification parameter; calculates the twelfth verification parameter, and if it matches the eleventh verification parameter, obtains the valid plaintext fourth random number, the sixth random number, the user's temporary identity, and the second chaotic mapping parameter; calculates the session key between the mobile terminal and the cloud service, the shared credential, and the session key between the mobile terminal and the drone, updates the temporary identity in the memory, and stores the session key.

Citation Information

Cited By

  • Key negotiation method, device and equipment for bidirectional authentication of unmanned aerial vehicle, and medium

    CN121486109A

  • A method, device and medium for key negotiation of two-way authentication of a UAV

    CN121486109B