Multi-chain collaborative central node switching method for ensuring authentication efficiency and data reliability

CN120567486APending Publication Date: 2025-08-29XIAN TECH UNIV
View PDF 0 Cites 3 Cited by

Patent Information

Application Number
CN202510693020.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-27
Publication Date
2025-08-29

AI Technical Summary

Technical Problem

In the process of switching between air commanders, existing drone clusters have problems such as low authentication efficiency, strong dependence of central nodes, high switching delay and insufficient security, especially when facing attacks, it is difficult to respond quickly and switch quickly.

Method used

The multi-chain collaborative center node switching method is adopted, and the identity chain and authentication chain are used to manage the authentication between the identity and the air commander within the drone cluster, combined with RSA dynamic accumulator and threshold signature technology, and the computing load is shared through the edge computing center to achieve fast and secure command switching and communication.

Benefits of technology

It realizes fast and secure communication of the drone cluster during the air command aircraft switching process, reduces computing overhead and delays, ensures the security and response speed of the system, and can quickly switch and continue to perform tasks when the central node is threatened.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120567486A_ABST
    Figure CN120567486A_ABST
Patent Text Reader

Abstract

The invention discloses a multi-chain collaborative center node switching method for ensuring authentication efficiency and data reliability, which is applied to a system comprising an identity chain, an authentication chain, an edge computing center, a key generation center, a plurality of unmanned aerial vehicle clusters and at least two aerial directors, and is characterized in that the identity chain is used for identity management of all the unmanned aerial vehicle clusters; the authentication chain is jointly maintained by all the unmanned aerial vehicle clusters and all the air directors. According to the multi-chain collaborative central node switching method for ensuring the authentication efficiency and the data reliability provided by the invention, the secure communication between the clusters can be quickly established in the authentication process of the unmanned aerial vehicle clusters, and the switching of the central nodes can be quickly carried out when the central nodes are threatened and attacked in a multi-chain manner; the new central node continues to execute the flight task, and the forward and backward security is ensured in the switching process, so that the problems of low authentication efficiency of the unmanned aerial vehicle cluster, strong dependency of the central node and insufficient security in the switching process of the central node are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of combining drones and blockchains, and specifically relates to a multi-chain collaborative central node switching method that ensures authentication efficiency and data reliability. Background Art

[0002] As the use of Unmanned Aerial Vehicle (UAV) swarms becomes more and more widespread, their high maneuverability and low cost make them indispensable equipment. In addition, due to their multi-machine collaboration and task sharing features, they are also widely used in scenarios that require collaborative work.

[0003] The core of drone swarms lies in their swarm intelligence, that is, each drone accomplishes complex goals through communication, information sharing, and collaborative behavior. To ensure the effectiveness of swarm intelligence, drone swarms require an aerial command aircraft to coordinate and make decisions, so that the drone swarm can complete its mission under the leadership of the aerial command aircraft. However, during the execution of a flight mission, the aerial command aircraft may be attacked or threatened, and the original aerial command aircraft may be unable to lead the drone swarm to continue the flight mission. A new aerial command aircraft must take over the subsequent work tasks. Figure 1 As shown, the drone cluster completes the switch of the airborne command aircraft, and the new command aircraft leads the cluster to continue to perform combat missions.

[0004] However, ensuring high efficiency and security during the authentication and handoff process for aerial command aircraft presents significant challenges, and the network resource characteristics of the drones themselves must be considered. Traditional authentication mechanisms based on centralized servers present single-point failure risks, high handoff latency, and vulnerability to man-in-the-middle attacks. These shortcomings make existing systems unable to meet the elastic scalability and real-time response requirements of modern warfare. Furthermore, small terminals within drone swarms often face insufficient resources and computing power, making them difficult to support long-distance communications. Summary of the Invention

[0005] In order to solve the above problems existing in the prior art, the present invention provides a multi-chain collaborative central node switching method that ensures authentication efficiency and data reliability. The technical problem to be solved by the present invention is achieved through the following technical solutions:

[0006] The embodiment of the present invention provides a multi-chain collaborative center node switching method that ensures authentication efficiency and data reliability. The method is applied to a system including an identity chain, an authentication chain, an edge computing center, a key generation center, several drone clusters, and at least two aerial command aircraft. The identity chain is used for identity management of all drone clusters, and the authentication chain is jointly maintained by all drone clusters and all aerial command aircraft. The corresponding method includes:

[0007] Initialization process: The key generation center calculates the pseudo-identity, public and private keys corresponding to each aerial command aircraft and each cluster head node in the UAV cluster, and uploads the pseudo-identity and public key to the corresponding authentication chain. The pseudo-identity and private key of the cluster head node are sent to the corresponding cluster head node, and the pseudo-identity and private key of the aerial command aircraft are sent to the corresponding aerial command aircraft. The edge computing center uses RSA dynamic accumulator technology to calculate the first accumulated value of each UAV cluster and sends the first accumulated value to the corresponding cluster head node.

[0008] The mutual authentication process between each aerial command aircraft and all drone clusters: each cluster head node generates an authentication request based on its corresponding pseudo identity, private key and first accumulated value; the aerial command aircraft verifies the collected authentication requests of each cluster head node based on the pseudo identity and public key of the cluster head node obtained from the authentication chain, and sends them to the edge computing center after the verification is passed; the edge computing center uses RSA dynamic accumulator technology to calculate the second accumulated value of all drone clusters; the aerial command aircraft generates a first authentication response for each cluster head node based on the second accumulated value; each cluster head node verifies the received first authentication response based on the public key of the aerial command aircraft obtained from the authentication chain, and generates a second authentication response of the aerial command aircraft after the verification is passed; the aerial command verifies the received second authentication response, and if the verification is passed, it indicates that the aerial command aircraft and the cluster head node have established secure communication;

[0009] The switching process between any two aerial command aircraft: the first aerial command aircraft broadcasts a message to all drone clusters; each cluster head node verifies the received broadcast message, and after verification, sends verification parameters to the edge computing center; the edge computing center calculates the verification information of each cluster head node based on the verification parameters; each cluster head node generates a switching signature message of the first aerial command aircraft based on the received verification information; the first aerial command aircraft generates an aggregate signature message of each cluster head node based on the received switching signature message; each cluster head node verifies the received aggregate signature message, and after verification, it indicates that the aerial command aircraft has switched successfully.

[0010] Beneficial effects of the present invention:

[0011] The multi-chain collaborative central node switching method for ensuring authentication efficiency and data reliability proposed in the present invention solves the problems that the existing switching and authentication mechanisms are often affected by central agencies, high switching delays, and complex authentication processes. It can quickly establish secure communication between drone clusters during the identity authentication of drone clusters and the switching authentication of airborne command aircraft. Specifically: by using a dual-chain strategy, the identity chain is used for identity management within the drone cluster, and dynamic accumulator technology is used to ensure the uniqueness and legitimacy of the identity. The authentication chain focuses on efficient two-way authentication and command aircraft switching between the drone cluster head node and the airborne command aircraft, and uses smart contracts to automatically execute identity verification and key negotiation to achieve low-latency command authority transfer. At the same time, the dual-chain strategy is used to decouple identity data from dynamic authentication tasks, avoiding the throughput bottleneck of the single-chain system, and reducing node latency through a lightweight verification mechanism. The computing overhead is reduced; an edge computing center is introduced in the system design process, and the resource-intensive calculations in the authentication process are transferred to the edge computing center for calculation, reducing the number of interactions and the computing overhead of the nodes; a secure and reliable group authentication mechanism is proposed, which uses authentication chains and other technologies to achieve rapid authentication of the airborne command aircraft and cluster head nodes, and designs a secure communication model, uses smart contracts to verify the identity of the command aircraft, and ensures that the drone can only connect to the authenticated legitimate command aircraft when switching the command aircraft. The secure communication between drones is ensured by negotiating session keys, thereby improving the security and response speed of the system, and realizing the rapid switching of the central node when the central node is threatened and attacked through a multi-chain approach, so that the new central node continues to perform the flight mission, and ensures forward and backward security during the switching process. In general, the present invention is based on a dual-chain drone cluster identity authentication mechanism and an airborne command aircraft switching authentication scheme, which realizes the rapid switching of the airborne command aircraft and the secure communication of the drone cluster, and solves the problems of low drone cluster authentication efficiency, strong dependence on the central node, and insufficient security of the central node switching process.

[0012] The present invention will be further described in detail below with reference to the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] Figure 1 This is a schematic diagram of a system framework provided by an embodiment of the present invention, including an identity chain, an authentication chain, an edge computing center, a key generation center, a cluster of several drones, and at least two aerial command aircraft;

[0014] Figure 2 This is a flow chart of a multi-chain collaborative central node switching method that ensures authentication efficiency and data reliability, provided by an embodiment of the present invention;

[0015] Figure 3 Schematic diagram of the cluster head node initialization process in each drone cluster provided by an embodiment of the present invention;

[0016] Figure 4 Schematic diagram of the initialization process of each airborne command aircraft provided by an embodiment of the present invention;

[0017] Figure 5 Schematic diagram of the initialization process of each drone cluster provided by an embodiment of the present invention;

[0018] Figure 6 Schematic diagram of the mutual authentication process between each aerial command aircraft and all drone clusters provided by an embodiment of the present invention;

[0019] Figure 7 The diagram is a schematic diagram of the handover process between any two airborne command aircraft provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0020] The present invention will be further described in detail below with reference to specific examples, but the embodiments of the present invention are not limited thereto.

[0021] First, the key technologies used in the design process of the overall solution of the present invention are introduced as follows:

[0022] The present invention mainly includes the following two parts:

[0023] (1) RSA dynamic accumulator

[0024] During the initialization phase of the drone cluster, RSA dynamic accumulator technology is used to generate corresponding identity certificates for the member drones in the drone cluster. The cluster head node in the drone cluster saves the accumulated value for subsequent identity authentication and switching.

[0025] The RSA dynamic accumulator is a cryptographic accumulator built on the RSA puzzle. It supports dynamic addition and removal of set elements and provides efficient proofs of membership and non-membership. An accumulator is a cryptographic data structure used to efficiently represent a set and supports operations such as insertion, deletion, proofs of membership and non-membership. The RSA accumulator is particularly suitable for scenarios requiring high security because it relies on the RSA factorization puzzle, effectively preventing tampering and forgery.

[0026] Construction: First, select two large prime numbers p and q, and use their product N = p × q as the modulus to generate the element And the order of g is as large as possible to initialize the accumulator. For a given element set {x1, x2, x3, x4, ..., x n}, the calculation formula of the accumulated value AccX is:

[0027]

[0028] The accumulated value AccX contains the information of all elements and generates a proof Wit for each member. xi To prove that the element x i Whether it belongs to this element set.

[0029]

[0030] Element addition: When a new element x is added n+1 hour:

[0031]

[0032] Element addition: When element x is deleted n hour:

[0033]

[0034] Proof of membership: prove element x j Is it part of the element collection?

[0035]

[0036] (2) Threshold signature technology

[0037] During the switching process of the drone cluster, the threshold signature technology is used to generate a corresponding private key for each cluster head node in the drone cluster. When the aerial command aircraft issues an aerial command aircraft switching signal, the cluster head node uses the private key to sign the information. When at least t private keys sign the information, the final signature is calculated and verified by the aerial command aircraft. If it passes, it indicates that the aerial command aircraft switching is successful.

[0038] A threshold signature is a distributed digital signature scheme in which a private key is split into multiple subkeys, managed by multiple parties. A valid signature can only be generated when at least t (threshold) parties collaborate, while fewer than t parties cannot recover the private key or forge a signature.

[0039] Construction: Using the Shamir secret sharing scheme, a (t,n) threshold scheme is defined, where the master private key sk is split into n parts, and at least t parts are required to recover the complete private key.

[0040] Choose a random polynomial:

[0041] f(x)=sk+a1x+a2x 2 +...+a t-1 x t-1 mod q;

[0042] Calculate each party's share of the private key:

[0043] sk i =f(i)mod q 1≤i≤n;

[0044]

[0045] Perform aggregate signature operation on the information using the calculated private key:

[0046]

[0047] Verify the correctness of the signature (whether the following equation holds):

[0048] e(σ,g)=e(H(m),pk);

[0049] If the equation holds true, it means the airborne command aircraft has switched successfully.

[0050] Furthermore, before the drone cluster is authenticated with the airborne command aircraft, the member drones in the same drone cluster have the same functions. Each drone cluster is led and managed by a cluster head node. The airborne command aircraft leads all cluster head nodes to perform combat missions. The airborne command aircraft does not directly lead all member drones in the drone cluster. Figure 2 As shown in the figure, in a system including an edge computing center, a key generation center, several drone clusters, and at least two aerial command aircraft, all drone clusters and all aerial command aircraft jointly maintain the authentication chain.

[0051] (1) Identity Chain: It is an identity blockchain. Each drone cluster manages the member drones in the cluster through the identity chain. It is responsible for uploading the identities of the member drones in the cluster, which are jointly maintained by the drones in the cluster.

[0052] (2) Authentication Chain (Aut-Chain): It is an authentication blockchain, which is jointly maintained by the cluster head node and the airborne command aircraft of the drone cluster. It stores identity parameters and is mainly responsible for verifying the identity of the drone, negotiating keys between the cluster head node and the airborne command aircraft, and switching between airborne command aircraft.

[0053] (3) Edge Computing Center (CMC): Migrates computing and storage capabilities from the center to the edge of the network to quickly process drone data and improve network response speed.

[0054] (4) Key Generation Center KGC: Responsible for generating, distributing and managing pseudo identities and public-private key pairs required for drone communication, ensuring secure communication between drones and ground control stations and other drones.

[0055] (5) Cluster head (CH) in a drone cluster: A drone that takes on management and coordination roles in a drone cluster. It is mainly responsible for collecting data from member drones in the drone cluster and distributing identity credentials, leading member drones in the drone cluster to complete tasks. In this paper, the cluster head node is used to represent the entire drone cluster.

[0056] (6) Airborne Command Aircraft (ACA): establishes communication with the cluster head node in the UAV cluster, and coordinates and manages the UAV cluster led by the cluster head node.

[0057] (7) Smart contract: It is a program running on the blockchain that can be automatically executed when certain conditions are met or an interface call is made.

[0058] Based on the introduction of the above key technologies, please refer to Figure 1 , an embodiment of the present invention provides a multi-chain collaborative central node switching method that ensures authentication efficiency and data reliability, and the corresponding method includes:

[0059] S10. Initialization process: The key generation center calculates the pseudo-identity, public and private keys corresponding to each aerial command aircraft and each cluster head node in the drone cluster, and uploads the pseudo-identity and public key to the corresponding authentication chain, sends the pseudo-identity and private key of the cluster head node to the corresponding cluster head node, and sends the pseudo-identity and private key of the aerial command aircraft to the corresponding aerial command aircraft; the edge computing center uses RSA dynamic accumulator technology to calculate the first accumulated value of each drone cluster, and sends the first accumulated value to the corresponding cluster head node.

[0060] The embodiment of the present invention defines a cyclic additive group G1, with a generator of P, a cyclic multiplicative group G, with a generator of g, both with an order of q, a mapping function e: G1×G1→G, and a hash function H2:{0,1}*→{0,1} z . The key generation center KGC then selects a random number As the system's master key SK G =s, calculate the system's public key PK G =g s It is used to generate the identities of cluster head nodes and airborne controllers during the initial registration phase. Finally, the system parameters (PK, H1, H2, P, g, q) are announced.

[0061] Furthermore, in the embodiment of the present invention, the specific initialization process of the cluster head node in each drone cluster includes: each cluster head node in the drone cluster sends a first registration request to the key generation center; the key generation center generates a first pseudo identity, a first public key, and a first private key corresponding to each cluster head node according to the first registration request, and sends the first pseudo identity, the first public key, and the first private key to the corresponding cluster head node, and uploads the first pseudo identity and the first public key to the corresponding authentication chain; after each cluster head node receives the corresponding first pseudo identity, the first public key, and the first private key, it encrypts and saves the first private key. More specifically, as Figure 3 As shown, the cluster head node CH of the drone cluster A A For example:

[0062] Cluster head node CH in drone cluster A A , sends the first registration request to the key generation center KGC is the cluster head node CH in the drone cluster A A The unique identity of M1 is the cluster head node CH A The key generation center KGC receives the first registration request Then, the Registration Contract in SC is called for the cluster head node CH A Generate the corresponding first pseudo identity and the first public key and the first private key The key generation center KGC selects a random number By getting the first registration request in Calculate the corresponding first pseudo identity Indicates XOR operation, the first private key Second public key Will Perform the authentication chain uplink operation and Return to the cluster head node CH in the drone cluster A A ; Cluster head node CH A take over Afterwards, encrypt and save

[0063] In the embodiment of the present invention, the specific initialization process of each airborne command aircraft includes: each airborne command aircraft sends a second registration request to the key generation center; the key generation center generates a second pseudo identity, a second public key, and a second private key corresponding to each airborne command aircraft according to the second registration request, and sends the second pseudo identity, the second public key, and the second private key to the corresponding airborne command aircraft, and uploads the second pseudo identity and the second public key to the corresponding authentication chain; after each airborne command aircraft receives the corresponding second pseudo identity, the second public key, and the second private key, it encrypts and saves the second private key. More specifically, as Figure 4 As shown, taking the airborne command aircraft ACA1 as an example:

[0064] The airborne command aircraft ACA1 sends a second registration request to the key generation center KGC is the unique identity of the airborne command aircraft ACA1, M9 is the equipment information of the airborne command aircraft ACA1; the key generation center KGC receives the second registration request Then, the corresponding second pseudo identity is generated for the air command aircraft ACA1 by calling RegistrationContract in SC and the second public key Second private key The key generation center KGC selects a random number By obtaining the second registration request in Calculate the corresponding second pseudo identity Second private key Second public key Will Perform the authentication chain uplink operation and Return to the airborne control aircraft ACA1; the airborne control aircraft ACA1 receives Afterwards, encrypt and save

[0065] Furthermore, in the embodiment of the present invention, each drone cluster corresponds to an identity chain; initialization process: the edge computing center uses RSA dynamic accumulator technology to generate identity certificates for members of each drone cluster, and uploads the identity certificates to the corresponding identity chain. The specific initialization process of each drone cluster in the embodiment of the present invention includes: the cluster head node in each drone cluster collects the identity credentials of all members in the corresponding drone cluster, and sends a third registration request to the edge computing center; the edge computing center verifies the received third registration request, and after the verification, uses RSA dynamic accumulator technology to calculate the first accumulation value of each drone cluster, generates a unique identity certificate for each member of the drone cluster, and sends the first accumulation and the identity certificate to the cluster head node in the corresponding drone cluster, and also uploads the identity certificate to the corresponding identity chain; the cluster head node in each drone cluster distributes the identity certificate to each member of the corresponding drone cluster. More specifically, as Figure 5 As shown, the cluster head node CH of the drone cluster A A For example:

[0066] All member drones in the drone cluster A are directed to the cluster head node CH A Provide your own identity credentials and other related identity information, such as M, where M is the device information of a member drone in the current drone cluster A. (When i≠j, if The identity credentials need to be re-provided until they are unique). Represents the i-th member drone in the drone cluster A; cluster head node CH A After collecting the identity credentials of all drone members in the drone cluster, a third registration request is sent to the edge computing center CMC M2 is the identity certificate information of all drone members in drone cluster A. is the cluster head node CH in the drone cluster A A The first pseudo identity, sig is the signature information, T is the current timestamp; the edge computing center CMC receives the third registration request Request CH First confirm the receiving time Is it effective? If Indicates that the received data is valid and calculates g sig Is it equal to If they are different, terminate the subsequent operations. If they are the same, perform the following operations: The edge computing center CMC selects two large prime numbers p and q, and uses their product N = p × q as the modulus to generate the element The order of g is as large as possible, and the data set consisting of drone identity credentials is obtained from M2 Calculate the first accumulated value: n1 represents the number of member drones in drone cluster A, and the first accumulated value AccX A It contains information about all elements and generates a unique identity certificate for each member drone to verify whether the member belongs to the current set: Represents the identity of the i-th member drone in the drone cluster A. Finally, the edge computing center CMC converts R3=(AccX A ,M3) returns to the cluster head node in the drone cluster A To prove the identity of all member drones in drone cluster A, use the identity certificate in M3 Upload to the identity chain; cluster head node CH A take over After that, prove your identity Distribute to no one in the drone cluster.

[0067] S20. The mutual authentication process between each aerial command aircraft and all drone clusters: each cluster head node generates an authentication request based on its corresponding pseudo identity, private key and first accumulated value; the aerial command aircraft verifies the collected authentication request of each cluster head node based on the pseudo identity and public key of the cluster head node obtained from the authentication chain, and sends it to the edge computing center after the verification is passed; the edge computing center uses RSA dynamic accumulator technology to calculate the second accumulated value of all drone clusters; the aerial command aircraft generates a first authentication response for each cluster head node based on the second accumulated value; each cluster head node verifies the received first authentication response based on the public key of the aerial command aircraft obtained from the authentication chain, and generates a second authentication response of the aerial command aircraft after the verification is passed; the aerial command verifies the received second authentication response, and after the verification is passed, it indicates that the aerial command aircraft and the cluster head node have established secure communication.

[0068] In the embodiment of the present invention, the specific mutual authentication process between each aerial command aircraft and all drone clusters includes: the cluster head node in each drone cluster generates a first random number for verification, and generates an authentication request of the aerial command aircraft according to the first random number, the first pseudo identity, the first private key and the first accumulated value; the aerial command aircraft obtains the first pseudo identity and the first public key corresponding to all cluster head nodes from the authentication chain, and verifies the authentication request of the cluster head node according to the obtained first pseudo identity and the first public key corresponding to the cluster head node, and after the verification is passed, collects the first pseudo identity, the first accumulated value and the first random number corresponding to each cluster head node and sends them to the edge computing center, and stores the first pseudo identity and the first accumulated value; the edge computing center calculates the second accumulated value of all drone clusters according to all the first accumulated values, and sends the second accumulated value to Airborne command aircraft; the airborne command aircraft receives the second accumulated value, and generates a shared key between the airborne command aircraft and the cluster head node according to the first accumulated value and the second accumulated value, and generates a second random number, and generates a corresponding first authentication response according to the second private key, the shared key, the second random number, the second accumulated value and the second pseudo identity; each cluster head node verifies the received first authentication response according to the second public key of the airborne command aircraft obtained from the authentication chain, and verifies that the shared key between the airborne command aircraft and the cluster head node is calculated to achieve secure communication between the airborne command aircraft and the cluster head node, and generates a second authentication response according to the first private key of the cluster head node, the second accumulated value and the second random number; the airborne command aircraft verifies the received second authentication response, and if the verification is passed, it indicates that the airborne command aircraft and the cluster head node have established secure communication. More specifically, as Figure 6 As shown in the figure, take the mutual authentication between the cluster head nodes in all UAV clusters and the airborne command aircraft ACA1 as an example:

[0069] Drone Cluster A i Cluster head node Send an authentication request to the airborne control aircraft ACA1 For drone cluster A i The first pseudo identity of the cluster head node, For drone cluster A i Cluster head node Generate a first random number for verification, For drone cluster A i Signature information, For drone cluster A i The first accumulated value of the cluster head node, Represents drone cluster A i The first private key of the cluster head node, T i The current timestamp; after receiving the authentication request, the airborne control aircraft ACA1 first confirms the receiving time T* Is it valid? If |T * -T i |≤ΔT, then continue the subsequent authentication, otherwise terminate the authentication. If the authentication is continued, the airborne control aircraft ACA1 obtains the first pseudo identity of each cluster head node from the authentication chain. Thus, the first accumulated value of each cluster head node is calculated Then obtain each cluster head node from the authentication chain The first public key For the signature information σ i Perform verification operations and calculate Is it satisfied If it is established, the subsequent verification will continue; the airborne control aircraft ACA1 collects all the cluster head nodes The collected information is sent to the edge computing center CMC, and the first pseudo identity is stored in the edge computing center CMC First accumulated value The edge computing center CMC calculates a new cumulative value, namely the second cumulative value: The edge computing center CMC takes the second accumulated value AccX SK Sent to the airborne command aircraft ACA1; the airborne command aircraft ACA1 stores the second accumulated value AccX SK and M1 (message M1: each cluster head node ), each airborne command aircraft manages a distributed ledger to store the status (Pseudo identity, Cumulative, status) of each cluster head node. The ledger format is shown in Table 1.

[0070] Table 1 Format of distributed ledger

[0071]

[0072] The airborne control aircraft ACA1 receives the second accumulated value AccX sent by the edge computing center CMC SK After that, the cluster head nodes (in CH) of each UAV cluster are calculated. A For example) the shared key SK A-C =H2(AccX SK ||AccX A ), and generate a second random number Generate signature information The second private key of the drone ACA1, M4 = SK A-C (n'), The second pseudo identity of the aerial drone ACA1 is sent to the cluster head node CH A Send the first authentication response Responce A =(Sigi||M4||tab A ||T), T is the current timestamp; cluster head node CH A Receive the first authentication response Responce A After that, first determine whether the time T meets the requirements. If not, terminate the connection. If it meets the requirements, obtain the second public key of the air command aircraft ACA1 from the authentication chain. judge Is it true? If they are equal, calculate the second accumulated value Calculate the shared key SK A-C =H2(AccX SK ||AccX A ), obtain the second random number n', and send the second authentication response Responce to the air command aircraft ACA1 C =(sigi||M5||T), M5=AccX SK (n'+1); APA1 receives the second authentication response Responce C After that, first check whether the time T meets the requirements. If not, terminate the communication. If it meets the requirements, verify whether the signature is valid. Finally, pass SK A-C Decryption obtains a second random number n', and determines whether the change of the second random number n' is correct. If it is correct, it indicates that secure communication has been established; if it is wrong, the communication is rejected.

[0073] S30. The switching process of any two aerial command aircraft: the first aerial command aircraft broadcasts a message to all drone clusters; each cluster head node verifies the received broadcast message, and sends verification parameters to the edge computing center after the verification is passed; the edge computing center calculates the verification information of each cluster head node based on the verification parameters; each cluster head node generates a switching signature message of the first aerial command aircraft based on the received verification information; the first aerial command aircraft generates an aggregate signature message of each cluster head node based on the received switching signature message; each cluster head node verifies the received aggregate signature message, and after the verification is passed, it indicates that the aerial command aircraft has switched successfully.

[0074] In the embodiment of the present invention, the specific switching process of any two aerial command aircraft includes: the first aerial command aircraft sends a first switching request to the cluster head node in each drone cluster, and generates a broadcast message for all drone clusters according to the first switching request, the second private key of the first aerial command aircraft and the second pseudo identity of the second aerial drone; the cluster head node in each drone cluster verifies the broadcast message, and after the verification is passed, sends the verification parameters consisting of the first pseudo identity corresponding to the cluster head node, the first accumulated value and the first random number to the edge computing center; the edge computing center generates a secret, constructs a polynomial according to the secret, calculates the sub-secret of each cluster head node according to the polynomial and the first accumulated value, calculates the corresponding public value according to the sub-secret, and calculates the corresponding public value according to the sub-secret. The sub-secret and the first accumulated value generate a verification value of the corresponding cluster head node, and the verification information of the corresponding cluster head node is generated according to the verification value and the public value; the cluster head node in each UAV cluster calculates a signature value according to the first switching request and verification information in the broadcast information, generates a switching signature message according to the signature value and the first pseudo-identity of the cluster head node, and sends it to the first airborne command aircraft; the first airborne command aircraft performs a single signature verification operation and an aggregate signature operation according to the received switching signature message to generate an aggregate signature value, and generates an aggregate signature message of the corresponding cluster head node according to the aggregate signature value and the first switching request; the cluster head node in each UAV cluster verifies the received aggregate signature message, and if the verification is passed, it indicates that the airborne command aircraft has switched successfully. More specifically, if Figure 7 As shown, take the switching between the first and second airborne command aircraft as an example:

[0075] Before switching tasks, the first air command aircraft ACA1 broadcasts a message to all the cluster head nodes in the UAV cluster. M7=(exchange) is a signal that requires switching of the airborne control aircraft. Exchange is the first switching request. is the second pseudo identity of the second airborne command aircraft, T is the current timestamp; the cluster head node CH A For example, the cluster head node CH A After receiving the broadcast message, first verify whether the time T is legal. If |T * -T|<ΔT, then continue with the subsequent operations and use the second public key of the first airborne command aircraft ACA1 Verify the broadcast message. If The establishment indicates that the broadcast message is valid, and the cluster head node CH A Send verification parameters to the edge computing center CMC The edge computing center CMC generates a secret As the core password of the system signature, the public key P=g k, and select a t-1 order polynomial p(x) and t-1 integers so that p(0) = k, where t is the threshold value of the system, and p(x) = k + a1X + a2X 2 +...+a t-1 X t-1 Then, the sub-secret of the corresponding cluster head node is calculated using the polynomial and the first accumulated value. A ), the public value of the sub-secret is D i =g du , calculated di and AccX A Calculate the corresponding verification value Pi, Finally, the verification information C i '=(Pi,D i ) is returned to the corresponding cluster head node CH A ; Cluster head node CH A Receive the verification information C returned by the edge computing center CMC i '=(Pi,D i ) After verifying the value Pi, first calculate the sub-secret Then generate signature information sig=H1(exchange) based on the sub-secret di di , will switch the signed message Send to the first command machine ACA1; the first command machine ACA1 receives the A After the switch signature message is sent, the single signature verification operation is performed. The value of count is set to 0 first. When e(sig, g)=e(H1(exchange), D i ) indicates that the verification is performed by adding 1 to the count operation. When the cluster head node CH is satisfied A When at least t drones in the corresponding drone cluster complete the signature verification operation, the first airborne command aircraft ACA1 performs the aggregate signature operation to generate the final aggregate signature value S:

[0076]

[0077] After generating the aggregate signature value, the first airborne command aircraft APA1 sends a A Send aggregate signature message Sig A =H1(exchange) S ; Cluster head node CH A After receiving the aggregate signature message, verify the equation Is it true? If so, it means that the aggregate signature value S is valid, and the handover between the first airborne command aircraft APA1 and the second airborne command aircraft APA2 is successful.

[0078] Furthermore, the specific switching process of any two airborne command aircraft in the embodiment of the present invention also includes: the first airborne command aircraft sends a second switching request to the second airborne command aircraft, generates a switching message based on the first pseudo-identity, the first accumulated value and the second accumulated value of all cluster head nodes, as well as the second pseudo-identity of the first airborne command aircraft and the second switching request sent by the first airborne command aircraft, and sends it to the second airborne command aircraft; the second airborne command aircraft verifies the received switching message, and after the verification is passed, calculates the shared key between the second airborne command aircraft and the cluster head node based on the first accumulated value and the second accumulated value, so as to realize secure communication between the second airborne command aircraft and the cluster head node after the switching. More specifically, as Figure 7 As shown, take the switching between the first and second airborne command aircraft as an example:

[0079] The first airborne command aircraft ACA1 sends a switching message M to the second airborne command aircraft ACA2 via a secure channel. ex =(M8||E exchange ||tab ex ||T), E exchange For the second switching request, is the information of the cluster head node in the UAV cluster that needs to switch the command machine, and T is the current timestamp; after the second command machine ACA2 receives the switching message, it first checks the correctness of the time T. If it meets the requirements, it calculates the second accumulated value And calculate the shared key SK between the second airborne command aircraft ACA2 and the cluster head node A-C =H2(AccX SK ||AccX A ), and at the same time update its own distributed ledger and add the cluster head node information to the second distributed ledger.

[0080] After the above process, any cluster head node CH A Complete the switching of the aerial command aircraft and conduct secure communication. In the embodiment of the present invention, each aerial command aircraft manages a distributed ledger, which is used to store the first pseudo identity, first accumulated value, second accumulated value and status value of the cluster head node in each drone cluster. After the switching is completed, the first pseudo identity, first accumulated value, second accumulated value and status value of the cluster head node in each drone cluster are added to the distributed ledger of the second aerial command aircraft. It can be seen that during the switching process of the embodiment of the present invention, the new aerial command aircraft can quickly calculate the shared key with the cluster head node in the drone cluster through the distributed ledger, ensuring that the new aerial command aircraft quickly establishes secure communication with the cluster head node during the switching process.

[0081] In summary, the multi-chain collaborative central node switching method for ensuring authentication efficiency and data reliability proposed in the embodiment of the present invention solves the problems that the existing switching and authentication mechanisms are often affected by central agencies, high switching delays, and complex authentication processes. It can quickly establish secure communications between drone clusters during the identity authentication of drone clusters and the switching authentication of aerial command aircraft. Specifically: by using a dual-chain strategy, the identity chain is used for identity management within the drone cluster, and dynamic accumulator technology is used to ensure the uniqueness and legitimacy of the identity. The authentication chain focuses on efficient two-way authentication and command aircraft switching between drone cluster head nodes and aerial command aircraft, and uses smart contracts to automatically execute identity verification and key negotiation to achieve low-latency command authority transfer. At the same time, the dual-chain strategy is used to decouple identity data from dynamic authentication tasks, avoiding the throughput bottleneck of the single-chain system, and through a lightweight verification mechanism. The system reduces the computational overhead of nodes. An edge computing center is introduced during the system design process, and the resource-intensive computations in the authentication process are transferred to the edge computing center for computation, reducing the number of interactions and the computational overhead of nodes. A secure and reliable group authentication mechanism is proposed, which uses authentication chains and other technologies to achieve rapid authentication of the airborne command aircraft and cluster head nodes. A secure communication model is designed, and a smart contract is used to verify the identity of the command aircraft, ensuring that drones can only connect to authenticated and legitimate command aircraft when switching command aircraft. Secure communication between drones is ensured by negotiating session keys, thereby improving the security and response speed of the system. In addition, a multi-chain approach is used to achieve rapid switching of the central node when the central node is threatened or attacked, and the new central node continues to perform the flight mission. In addition, forward and backward security is guaranteed during the switching process. In general, the embodiment of the present invention, based on a dual-chain drone cluster identity authentication mechanism and an airborne command aircraft switching authentication scheme, achieves rapid switching of the airborne command aircraft and secure communication of the drone cluster, solving the problems of low drone cluster authentication efficiency, strong dependence on the central node, and insufficient security of the central node switching process.

[0082] In the description of the present invention, it should be understood that the terms "first" and "second" are used for descriptive purposes only and should not be understood to indicate or imply relative importance or implicitly specify the number of the technical features indicated. Therefore, a feature specified as "first" or "second" may explicitly or implicitly include one or more of the features. In the description of the present invention, "plurality" means two or more, unless otherwise specifically defined.

[0083] Although the present invention is described herein in conjunction with various embodiments, those skilled in the art may understand and implement other variations of the disclosed embodiments by reviewing the specification and accompanying drawings in the process of implementing the claimed invention. In the specification, the word "comprising" does not exclude other components or steps, and "a" or "an" does not exclude multiple components or steps. The fact that certain measures are described in different embodiments does not mean that these measures cannot be combined to produce good results.

[0084] The above is a further detailed description of the present invention in conjunction with specific preferred embodiments, and the specific implementation of the present invention should not be considered to be limited to these descriptions. For those skilled in the art of the present invention, without departing from the concept of the present invention, several simple deductions or substitutions can be made, which should be considered to fall within the scope of protection of the present invention.

Claims

1. A multi-chain collaborative central node switching method that ensures authentication efficiency and data reliability, characterized in that: Applied to a system that includes an identity chain, an authentication chain, an edge computing center, a key generation center, several drone clusters, and at least two aerial command aircraft. The identity chain is used for identity management of all drone clusters, and the authentication chain is jointly maintained by all drone clusters and all aerial command aircraft. The corresponding methods include: Initialization process: The key generation center calculates the pseudo-identity, public and private keys corresponding to each aerial command aircraft and each cluster head node in the UAV cluster, and uploads the pseudo-identity and public key to the corresponding authentication chain. The pseudo-identity and private key of the cluster head node are sent to the corresponding cluster head node, and the pseudo-identity and private key of the aerial command aircraft are sent to the corresponding aerial command aircraft. The edge computing center uses RSA dynamic accumulator technology to calculate the first accumulated value of each UAV cluster and sends the first accumulated value to the corresponding cluster head node. The mutual authentication process between each aerial command aircraft and all drone clusters: each cluster head node generates an authentication request based on its corresponding pseudo identity, private key and first accumulated value; the aerial command aircraft verifies the collected authentication requests of each cluster head node based on the pseudo identity and public key of the cluster head node obtained from the authentication chain, and sends them to the edge computing center after the verification is passed; the edge computing center uses RSA dynamic accumulator technology to calculate the second accumulated value of all drone clusters; the aerial command aircraft generates a first authentication response for each cluster head node based on the second accumulated value; each cluster head node verifies the received first authentication response based on the public key of the aerial command aircraft obtained from the authentication chain, and generates a second authentication response of the aerial command aircraft after the verification is passed; the aerial command verifies the received second authentication response, and if the verification is passed, it indicates that the aerial command aircraft and the cluster head node have established secure communication; The switching process between any two aerial command aircraft: the first aerial command aircraft broadcasts a message to all drone clusters; each cluster head node verifies the received broadcast message, and after verification, sends verification parameters to the edge computing center; the edge computing center calculates the verification information of each cluster head node based on the verification parameters; each cluster head node generates a switching signature message of the first aerial command aircraft based on the received verification information; the first aerial command aircraft generates an aggregate signature message of each cluster head node based on the received switching signature message; each cluster head node verifies the received aggregate signature message, and after verification, it indicates that the aerial command aircraft has switched successfully.

2. The multi-chain collaborative central node switching method for ensuring authentication efficiency and data reliability according to claim 1 is characterized in that: The specific initialization process of the cluster head node in each drone cluster includes: The cluster head node in each UAV cluster sends a first registration request to the key generation center; The key generation center generates a first pseudo identity, a first public key, and a first private key corresponding to each cluster head node according to the first registration request, and sends the first pseudo identity, the first public key, and the first private key to the corresponding cluster head node, and simultaneously uploads the first pseudo identity and the first public key to the corresponding authentication chain; After receiving the corresponding first pseudo identity, first public key and first private key, each cluster head node encrypts and stores the first private key.

3. The multi-chain collaborative central node switching method for ensuring authentication efficiency and data reliability according to claim 2 is characterized in that: The specific initialization process of each airborne command aircraft includes: Each airborne command aircraft sends a second registration request to the key generation center; The key generation center generates a second pseudo identity, a second public key, and a second private key corresponding to each airborne command aircraft based on the second registration request, sends the second pseudo identity, the second public key, and the second private key to the corresponding airborne command aircraft, and simultaneously uploads the second pseudo identity and the second public key to the corresponding authentication chain; After receiving the corresponding second pseudo identity, second public key, and second private key, each airborne command aircraft encrypts and stores the second private key.

4. The multi-chain collaborative central node switching method for ensuring authentication efficiency and data reliability according to claim 3 is characterized in that: The specific initialization process of each drone cluster includes: The cluster head node in each drone cluster collects the identity credentials of all members in the corresponding drone cluster and sends a third registration request to the edge computing center; The edge computing center verifies the received third registration request. After the verification is passed, the RSA dynamic accumulator technology is used to calculate the first accumulated value of each drone cluster, generate a unique identity certificate for each member of the drone cluster, and send the first accumulated value and the identity certificate to the cluster head node in the corresponding drone cluster, and upload the identity certificate to the corresponding identity chain. The cluster head node in each drone cluster distributes the identity certificate to each member of the corresponding drone cluster.

5. The multi-chain collaborative central node switching method for ensuring authentication efficiency and data reliability according to claim 3 is characterized in that: The specific mutual authentication process between each aerial command aircraft and all drone swarms includes: The cluster head node in each drone cluster generates a first random number for verification, and generates an authentication request for the airborne command aircraft based on the first random number, the first pseudo identity, the first private key, and the first accumulated value; The airborne command machine obtains the first pseudo identity and the first public key corresponding to all cluster head nodes from the authentication chain, and verifies the authentication request of the cluster head node according to the obtained first pseudo identity and the first public key corresponding to the cluster head node. After the verification is passed, the first pseudo identity, the first accumulated value and the first random number corresponding to each cluster head node are collected and sent to the edge computing center, and the first pseudo identity and the first accumulated value are stored; The edge computing center calculates a second accumulated value of all drone clusters based on all the first accumulated values, and sends the second accumulated value to the airborne command aircraft; The airborne command aircraft receives the second accumulated value, generates a shared key between the airborne command aircraft and the cluster head node based on the first accumulated value and the second accumulated value, generates a second random number, and generates a corresponding first authentication response based on the second private key, the shared key, the second random number, the second accumulated value, and the second pseudo identity; Each cluster head node verifies the received first authentication response based on the second public key of the airborne commander obtained from the authentication chain, and verifies the first authentication response by calculating a shared key between the airborne commander and the cluster head node to achieve secure communication between the airborne commander and the cluster head node, and generates a second authentication response based on the first private key of the cluster head node, the second accumulated value, and the second random number; The airborne control machine verifies the received second authentication response, and if the verification is successful, it indicates that the airborne control machine has established secure communication with the cluster head node.

6. The multi-chain collaborative central node switching method for ensuring authentication efficiency and data reliability according to claim 3 is characterized in that: The specific switching process between any two airborne command aircraft includes: The first aerial command aircraft sends a first handover request to a cluster head node in each drone cluster, and generates a broadcast message for all drone clusters according to the first handover request, the second private key of the first aerial command aircraft, and the second pseudo identity of the second aerial drone; The cluster head node in each drone cluster verifies the broadcast message, and after the verification is passed, sends the verification parameters consisting of the first pseudo identity corresponding to the cluster head node, the first accumulated value and the first random number to the edge computing center; The edge computing center generates a secret, constructs a polynomial based on the secret, calculates a sub-secret of each cluster head node based on the polynomial and the first accumulated value, calculates a corresponding public value based on the sub-secret, generates a verification value of the corresponding cluster head node based on the sub-secret and the first accumulated value, and generates verification information of the corresponding cluster head node based on the verification value and the public value; The cluster head node in each UAV cluster calculates a signature value according to the first switching request and verification information in the broadcast information, generates a switching signature message according to the signature value and the first pseudo identity of the cluster head node, and sends the message to the first airborne command aircraft; The first airborne command aircraft performs a single signature verification operation and an aggregate signature operation according to the received handover signature message to generate an aggregate signature value, and generates an aggregate signature message of the corresponding cluster head node according to the aggregate signature value and the first handover request; The cluster head node in each UAV cluster verifies the received aggregate signature message. If the verification is successful, it indicates that the aerial command aircraft has been switched successfully.

7. The multi-chain collaborative central node switching method for ensuring authentication efficiency and data reliability according to claim 6 is characterized in that: The specific switching process between any two airborne command aircraft also includes: The first airborne command aircraft sends a second handover request to the second airborne command aircraft, generates a handover message based on the first pseudo identities of all cluster head nodes, the first accumulated value, the second accumulated value, the second pseudo identity of the first airborne command aircraft, and the second handover request sent by the first airborne command aircraft, and sends the message to the second airborne command aircraft; The second airborne command machine verifies the received switching message, and after verification, calculates the shared key between the second airborne command machine and the cluster head node based on the first accumulated value and the second accumulated value to achieve secure communication between the second airborne command machine and the cluster head node after the switching.

8. The multi-chain collaborative central node switching method for ensuring authentication efficiency and data reliability according to claim 2 is characterized in that: Each aerial command aircraft manages a distributed ledger, which is used to store the first pseudo identity, the first accumulated value, the second accumulated value and the state value of the cluster head node in each drone cluster.

9. The multi-chain collaborative central node switching method for ensuring authentication efficiency and data reliability according to claim 8 is characterized in that: After the switching is completed, the first pseudo identity, the first accumulated value, the second accumulated value and the state value of the cluster head node in each drone cluster are added to the distributed ledger of the second air command aircraft.

Citation Information

Cited By

  • Authentication method and system of unmanned aerial vehicle swarm and electronic equipment

    CN121099324A

  • Unmanned aerial vehicle inspection path planning method and system for power grid line

    CN121457780A

  • Unmanned aerial vehicle inspection path planning method and system for power grid lines

    CN121457780B