Unmanned aerial vehicle group mutual authentication and key agreement method based on PUF (Physical Unclonable Function)
By using a PUF-based method for mutual authentication and key negotiation among drone swarms, and by real-time monitoring of node location and signal strength, combined with K-Means clustering and elliptic curve cryptography, efficient and stable communication and collaborative operation of drone swarms in complex environments are achieved, solving the problems of authentication lag and unstable key negotiation in existing technologies.
Patent Information
- Application Number
- CN202511612355.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-06
- Publication Date
- 2025-12-05
- Estimated Expiration
- 2045-11-06
AI Technical Summary
Existing drone swarm authentication and key negotiation mechanisms suffer from response delays and high resource consumption in dynamic environments. They also lack real-time perception of node physical characteristics, leading to authentication lag and unstable key negotiation, making it difficult to maintain communication security and collaborative stability in complex environments.
A PUF-based method for mutual authentication and key negotiation among drone swarms is adopted. By monitoring node location and signal strength in real time, K-Means clustering algorithm is used to analyze communication fluctuation characteristics. Combined with elliptic curve encryption mechanism and multi-channel random exchange mechanism, dynamic trust chain update and key negotiation are realized, and the drone swarm operation mode is adaptively adjusted.
It significantly improves the communication security and collaborative stability of UAV swarms in complex and dynamic environments, enables accurate identification and dynamic response to changes in node communication quality, enhances the randomness and anti-interference capability of the key negotiation process, and ensures the efficient collaborative operation of UAV swarms in complex environments.
Smart Images

Figure CN121078434A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of unmanned aerial vehicle group communication security and network authentication, and particularly relates to a mutual authentication and key agreement method for unmanned aerial vehicle groups based on PUF. BACKGROUND
[0002] In modern unmanned aerial vehicle cluster systems, group collaborative operation has become an important application direction in the fields of intelligent communication, border patrol, emergency rescue, logistics transportation, etc. Unmanned aerial vehicle groups usually realize information interaction and collaborative control through wireless communication networks. The running environment is complex and dynamically changes obviously. The communication links between nodes are often affected by factors such as terrain obstruction, electromagnetic interference, and climate conditions, resulting in fluctuations in communication quality and connection interruptions. When unmanned aerial vehicle nodes frequently move, join or exit the group during task execution, the network topology structure and trust relationship also change, bringing great challenges to the secure communication and collaborative scheduling of the system.
[0003] Existing unmanned aerial vehicle group authentication and key agreement mechanisms mostly rely on static preset keys or centralized management architecture. When the number of nodes changes or the communication link is unstable, such schemes often need global re-authentication or key update, causing system response delay and increased resource consumption. In addition, traditional authentication mechanisms lack real-time sensing capability for node spatial motion characteristics and signal fluctuation characteristics, making it difficult to accurately judge the reliability of nodes in dynamic scenarios. Especially in high-speed moving or complex border environments, node position drift and signal strength attenuation may cause misjudgment, thereby affecting the continuity of the trust chain and system security. On the other hand, although existing research attempts to introduce encryption algorithms or clustering analysis into communication quality evaluation and authentication mechanisms, there are still two shortcomings: one is the inability to achieve adaptive identification and hierarchical response of communication fluctuations, and the other is the lack of trusted identity authentication mechanisms based on node physical characteristics. Physical unclonable function (PUF) is considered an important means to build unmanned aerial vehicle node identity authentication and trust root because it can generate unique hardware fingerprints using randomness in the device manufacturing process. However, existing technologies have not organically combined PUF features with dynamic communication quality evaluation, trust chain update, and key agreement processes, resulting in problems such as authentication lag, unstable key agreement, and insufficient system robustness for unmanned aerial vehicle groups in complex environments. SUMMARY
[0004] The present application aims to provide a mutual authentication and key agreement method for unmanned aerial vehicle groups based on PUF, which solves the problems existing in the prior art.
[0005] To achieve the above object, the application provides the following technical scheme: a PUF-based mutual authentication and key negotiation method for a UAV group, comprising S1, obtaining change data by real-time monitoring of UAV node position coordinate tracking and connection signal strength, and performing state change detection on node moving speed to obtain a position coordinate tracking sequence after data synchronization update by using position deviation calculation and connection interruption record; S2, performing data point clustering on the position coordinate tracking sequence by using a K-Means clustering algorithm, and obtaining a change vector grouping under a group quantity setting by center point iteration and distance measurement calculation processing of the connection interruption record grouping; S3, evaluating the degree of communication quality fluctuation caused by the node moving speed according to the change vector grouping, and if the degree of fluctuation exceeds a preset threshold, starting signal strength analysis to obtain a fluctuation quantization index in combination with trend pattern recognition; S4, updating a trust chain model by using the fluctuation quantization index, and preliminarily verifying the position deviation calculation of the affected node by using an elliptic curve encryption mechanism to determine a trust chain vulnerability level; S5, initializing a re-authentication process for the trust chain vulnerability level, and extracting identity data from the verification node to obtain an authentication request sequence in combination with dynamic trend extraction; S6, combining the authentication request sequence with a key negotiation process, and if the sequence contains a newly added node, generating a temporary key pair based on clustering convergence judgment to obtain negotiation basic parameters; S7, after obtaining the negotiation basic parameters, generating a shared key by using a multi-channel random exchange mechanism, and using negotiation result consistency detection to judge a negotiation success state; S8, adjusting adaptive cooperative working parameters according to the negotiation success state, deriving a networking configuration from the shared key, and obtaining an optimized UAV group operation mode in combination with state change detection.
[0006] Preferably, S1 comprises real-time collection of position coordinate and signal strength data by the UAV node, obtaining an original data sequence by using a preset sampling frequency; for the original data sequence, calculating the position coordinate difference value of adjacent time points, obtaining a position deviation sequence by using the Euclidean distance formula; if the deviation of a certain time point in the position deviation sequence exceeds a preset threshold, determining that the node moving speed has changed, and generating a speed change marker sequence; detecting the connection interruption event in the signal strength data according to the speed change marker sequence, obtaining a connection interruption time sequence by using time window analysis; generating a smooth position coordinate sequence by using the Kalman filtering algorithm through the connection interruption time sequence and the position deviation sequence, obtaining a synchronous updated tracking sequence; for the synchronous updated tracking sequence, calculating the change trend of the coordinate sequence by using sliding window analysis, obtaining a node motion state sequence; determining the behavior mode of the UAV node in the patrol environment by using clustering analysis according to the node motion state sequence, and obtaining a behavior classification result.
[0007] Preferably, S2 comprises grouping the position coordinate sequence by using K-Means algorithm, generating a clustering grouping sequence by iteratively calculating the Euclidean distance of data points to the center point; for the clustering grouping sequence, if the number of data points in a group is lower than a preset threshold, merging it into the nearest neighbor group, using nearest neighbor distance calculation to obtain an adjusted grouping sequence; according to the adjusted grouping sequence, statistically analyzing the time distribution of connection interruption records in each group, using time window analysis to obtain an interruption time distribution sequence; for the interruption time distribution sequence, using density clustering method to identify the density interruption time region, obtaining an interruption dense time sequence; according to the interruption dense time sequence, calculating the spatial distribution characteristics of data points in each group, using spatial autocorrelation analysis to obtain a spatial distribution mode sequence; for the spatial distribution mode sequence, if the spatial distribution mode of a group deviates from a preset mode by more than a threshold, marking it as an abnormal group, obtaining an abnormal grouping sequence; according to the abnormal grouping sequence, using sliding window analysis to extract the coordinate change trend in the abnormal group, obtaining an abnormal motion trend sequence.
[0008] Preferably, S3 comprises according to the node moving speed, using acceleration sensor data acquisition to calculate the speed change sequence of each node in the time window, obtaining a speed change vector; for the speed change vector, using K-Means clustering algorithm to group the nodes, generating a speed vector grouping sequence; according to the speed vector grouping sequence, calculating the fluctuation amplitude of communication quality in each group, using time-frequency analysis method to obtain a communication quality fluctuation sequence; if the fluctuation amplitude of the communication quality fluctuation sequence exceeds a preset threshold, extracting the signal strength data of the corresponding group to generate a signal strength sequence; for the signal strength sequence, using moving average filtering method to smooth the time series data, obtaining a smoothed signal strength sequence; according to the smoothed signal strength sequence, using time series decomposition method to extract the trend mode, obtaining a communication quality trend sequence; for the communication quality trend sequence, calculating the fluctuation quantification index of each group, using standard deviation statistical method to obtain the fluctuation quantification result.
[0009] Preferably, S4 comprises obtaining time series fluctuation values from node communication data by using fluctuation quantization indicators, calculating fluctuation quantization indicators of each node to obtain fluctuation quantization sequences; comparing the fluctuation quantization sequences with preset thresholds, if the values of the fluctuation quantization sequences exceed the preset thresholds, extracting corresponding node position data to determine an affected node set; encrypting the node position data by using an elliptic curve encryption mechanism to generate encrypted position deviation data according to the affected node set; calculating position deviation values of each node for the encrypted position deviation data, and obtaining a deviation calculation accuracy sequence by using a mean square error method; adjusting trust chain model parameters by a trust chain model update algorithm according to the deviation calculation accuracy sequence to generate an updated trust chain model; calculating trust chain vulnerability values of each node for the updated trust chain model, and determining vulnerability level values by using a standard deviation statistical method; and classifying the vulnerability level values by using preset level thresholds, if the vulnerability level values exceed the preset thresholds, marking them as high-risk nodes to obtain a high-risk node list.
[0010] Preferably, S5 comprises obtaining identity data from a verification node, generating a node feature code by using a physically unclonable function to obtain a node identity; judging vulnerability by using a preset threshold according to the node identity and a trust chain level evaluation to obtain a trust chain vulnerability level; if the trust chain vulnerability level exceeds the preset threshold, extracting dynamic features from the node identity and obtaining dynamic trend data by combining time series analysis; generating an authentication request sequence by using the dynamic trend data to obtain an initial authentication sequence; performing sequence optimization processing on the initial authentication sequence, grouping the sequence by using a K-means clustering algorithm to obtain an optimized authentication sequence; performing node identity verification according to the optimized authentication sequence, and obtaining a verification result by using a support vector machine algorithm for classification; if the verification result indicates that the node identity is trustworthy, generating a final authentication request sequence to obtain a trustworthy authentication sequence.
[0011] Preferably, S6 comprises obtaining a node verification state from node identification data, judging the trustworthiness of a node by using a preset trust evaluation model to obtain a node trust level; extracting sequence priorities from an authentication request sequence according to the node trust level, sorting the requests by the sequence priorities to determine a priority sequence; obtaining dynamic parameter adjustment data in a key negotiation process for the priority sequence, and generating a temporary key pair if the dynamic parameter adjustment data meets a preset threshold; performing parameter optimization on the temporary key pair by clustering convergence analysis to obtain optimized negotiation basic parameters; extracting node identification data from the optimized negotiation basic parameters, and judging whether to update the key negotiation process by combining the verification state of a newly added node to determine an updated negotiation process; generating a new authentication request sequence according to the updated negotiation process, and outputting ordered sequence data.
[0012] Preferably, the S7 comprises obtaining negotiation basis parameters, extracting channel allocation data from the parameters by using a preset multi-channel allocation strategy, determining a channel allocation scheme; processing the channel allocation data by a random exchange mechanism according to the channel allocation scheme, generating a temporary shared key; obtaining key consistency data by using a consistency detection algorithm for the temporary shared key, judging a key consistency state; if the key consistency state meets a preset threshold value, confirming the validity of the shared key by a result verification logic, obtaining an effective shared key; extracting state confirmation data from the negotiation success state according to the effective shared key, determining a final negotiation state; generating a negotiation completion identifier by using a state confirmation rule for the final negotiation state, determining the end of the negotiation process.
[0013] Preferably, the S8 comprises extracting state association data from the negotiation success state, generating structured state information by using a preset data analysis rule, determining the integrity of the state association data; updating the collaborative working parameters by using an adaptive adjustment mechanism according to the structured state information, generating a dynamic parameter set, judging the applicability of the parameter set; if the applicability of the dynamic parameter set meets a preset threshold value, extracting key derivation data from the shared key by using a derived key generation logic, generating a derived key configuration.
[0014] Preferably, the S8 further comprises obtaining running mode change data by using a state change detection algorithm for the derived key configuration, determining the adjustment direction of the UAV group running mode; updating the UAV group running configuration by using a mode optimization rule according to the running mode adjustment direction, generating an optimized running mode; extracting mode verification data from the optimized running mode, judging the stability of the running mode by using a consistency detection algorithm, determining a final running mode; generating a running mode identifier by using a state confirmation rule for the final running mode, determining the UAV group running state.
[0015] From the above technical solutions, the present application has the following beneficial effects: The PUF-based unmanned aerial vehicle group mutual authentication and key agreement method significantly improves the communication security and cooperative stability of the unmanned aerial vehicle group in a complex dynamic environment by deeply integrating the physical unclonable function hardware features with dynamic trust evaluation and multi-channel key agreement mechanism. The method can monitor the position information and signal strength of the unmanned aerial vehicle node in real time, use the K-Means clustering algorithm to perform clustering analysis and quantitative evaluation on the communication fluctuation characteristics, thereby realizing accurate identification and dynamic response of the node communication quality change. When the system detects that the communication fluctuation exceeds the threshold or the trust chain vulnerability rises, the node position deviation is verified through the elliptic curve encryption mechanism, and the identity re-authentication process based on the PUF feature is automatically triggered to ensure the uniqueness and anti-fake of the node identity. At the same time, the system generates a shared key by combining the multi-channel random exchange and consistency detection mechanism, further enhancing the randomness and anti-interference ability of the key agreement process. After completing the key agreement, the adaptive cooperative parameter adjustment mechanism is used to dynamically optimize the group communication and task configuration, so that the unmanned aerial vehicle group can still maintain efficient and stable cooperative operation under the conditions of signal fluctuation, node change or complex terrain environment. The method not only effectively solves the problems of slow response, easy interruption of communication and unstable key agreement of the traditional unmanned aerial vehicle group authentication mechanism, but also realizes comprehensive improvement in security, robustness and intelligence, and is particularly suitable for unmanned aerial vehicle group application scenarios such as border patrol, disaster monitoring and emergency communication that require high security and high reliability. BRIEF DESCRIPTION OF DRAWINGS
[0016] Figure 1 The PUF-based unmanned aerial vehicle group mutual authentication and key agreement method flowchart. DETAILED DESCRIPTION
[0017] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.
[0018] As Figure 1As shown, the present application provides a technical solution: a PUF-based unmanned aerial vehicle group mutual authentication and key agreement method, comprising S1, obtaining change data by tracking and connecting signal strength through real-time monitoring of unmanned aerial vehicle node position coordinates, using position deviation calculation and connection interruption record to detect state change of node moving speed to obtain data synchronization updated position coordinate tracking sequence; S2, using K-Means clustering algorithm to cluster data points of position coordinate tracking sequence, and processing connection interruption record grouping through center point iteration and distance measurement calculation to obtain change vector grouping under group number setting; S3, according to the change vector grouping, the degree of communication quality fluctuation caused by the node moving speed is evaluated, if the fluctuation degree exceeds the preset threshold, then the signal strength analysis is started to obtain the fluctuation quantization index combined with the trend mode recognition; S4, using the fluctuation quantization index to update the trust chain model, and preliminarily verifying the position deviation calculation of the affected node through the elliptic curve encryption mechanism to determine the trust chain vulnerability level; S5, initializing the re-authentication process according to the trust chain vulnerability level, extracting identity data from the verification node to obtain the authentication request sequence combined with the dynamic trend extraction; S6, through the combination of the authentication request sequence and the key agreement process, if the sequence contains a newly added node, generate a temporary key pair based on the clustering convergence judgment to obtain the negotiation basic parameters; S7, after obtaining the negotiation basic parameters, generate a shared key through a multi-channel random exchange mechanism, and use the negotiation result consistency detection to judge the negotiation success state; S8, according to the negotiation success state, adjust the adaptive cooperative working parameters, derive the networking configuration from the shared key, and obtain the optimized unmanned aerial vehicle group operation mode combined with the state change detection.
[0019] The method generates a hardware fingerprint based on a physically unclonable function (PUF) as the basis for node identity, realizes the security authentication and dynamic key agreement between the UAV group. Through the collection and analysis of the real-time position information and signal strength of the UAV node, the system uses the position deviation and connection interruption characteristics to judge the movement state of the node, so as to keep the node synchronous update in the environment of spatial dynamic change. The K-Means clustering algorithm is used to aggregate the node position sequence into a number of change vector groups, reflecting the group motion trend and network topology change. When the node moving speed causes the communication quality fluctuation, the system quantifies the fluctuation through signal strength analysis and trend pattern recognition, and updates the trust chain model accordingly. The trust chain model based on elliptic curve encryption mechanism (ECC) weights the node trustworthiness, and outputs the trust vulnerability level. For the nodes with high vulnerability level, the system triggers the re-authentication process, and forms an authentication request sequence combined with the identity data generated by the PUF feature code. After the authentication request and key agreement, the system automatically generates a temporary key pair when a new node is identified, and judges the stability of the negotiation parameters through clustering convergence indicators. Finally, the multi-channel random exchange mechanism is used to generate a shared key, ensuring the randomness and unpredictability of the key generation process. The system confirms the effectiveness of the negotiation result through negotiation consistency detection, and if successful, updates the cooperative work parameters according to the shared key, realizes the adaptive network configuration and operation mode optimization of the UAV group.
[0020] The present application realizes hardware-level identity verification by introducing PUF technology, effectively prevents the access of fake nodes, and improves the security protection ability of the system. The combination of K-Means clustering and dynamic trust chain model enables the system to respond to communication fluctuations caused by node movement in real time, improving the stability and robustness of the authentication and key agreement process. The elliptic curve encryption mechanism ensures the efficiency and security of data transmission and verification process, and the multi-channel random exchange mechanism further enhances the anti-attack ability of key agreement. The method can adaptively adjust the cooperative work parameters in the self-organizing networking environment of the UAV group, optimize the group communication quality and energy consumption balance, and thus improve the overall efficiency and security of group task execution. In addition, through dynamic trend analysis and clustering convergence judgment mechanism, the present application has strong expansibility and can be flexibly applied in UAV groups of different numbers and different task types, and has high practical application value.
[0021] S1 includes collecting position coordinate and signal strength data in real time through the unmanned aerial vehicle node, using a preset sampling frequency to obtain an original data sequence; for the original data sequence, calculating the position coordinate difference value of adjacent time points, using the Euclidean distance formula to obtain a position deviation sequence; if the deviation of a certain time point in the position deviation sequence exceeds a preset threshold value, determining that the node moving speed changes, and generating a speed change marker sequence; according to the speed change marker sequence, detecting a connection interruption event in the signal strength data, using time window analysis to obtain a connection interruption time sequence; through the connection interruption time sequence and the position deviation sequence, using a Kalman filtering algorithm to generate a smooth position coordinate sequence, obtaining a synchronously updated tracking sequence; for the synchronously updated tracking sequence, using sliding window analysis to calculate the change trend of the coordinate sequence, obtaining a node motion state sequence; according to the node motion state sequence, using clustering analysis to determine the behavior pattern of the unmanned aerial vehicle node in the patrol environment, obtaining a behavior classification result.
[0022] In this embodiment, the first step is sampling and original sequence generation: the input is the maximum speed of the UAV and the spatial resolution or collision avoidance safety distance given by the task, and the output is the original data sequence. The sampling frequency is determined by dividing the maximum speed by the upper limit of the allowed single sampling displacement and then rounding up to no less than 10 times per second. The upper limit of the allowed single sampling displacement is directly given by the spatial resolution of the task, and if not given, it is taken as 1 / 10 of the collision avoidance safety distance. After the sampling frequency is set, it remains unchanged within one task period. The system synchronously collects timestamps, 3D positions, and signal strengths at this frequency and forms the original data sequence according to the sampling order; the second step is position deviation calculation: the input is the original data sequence, and the output is the position deviation sequence. The processing is to calculate the difference between the 3D positions of adjacent two records axis by axis, square each axis difference value, sum them up, and then take the square root to get the 3D straight-line distance of the current position relative to the previous time. Write this distance and the current timestamp into the position deviation sequence; the third step is speed change determination and marking: the input is the position deviation sequence, and the output is the speed change marker sequence. The key parameters are the speed change threshold and the minimum number of consecutive samples. The speed change threshold is determined by a two-stage method. In the calibration stage, which lasts for 30 seconds, the first 15 seconds are hovering, and the last 15 seconds are uniform straight-line flight. The system respectively calculates the upper bound of the deviation distribution in the hovering stage and the upper bound of the deviation distribution in the uniform stage, and takes the larger one multiplied by 1.5 as the initial threshold. In the online update stage, every 300 seconds, the latest 300 seconds of data are used to repeat the above statistics and compare the results with the current threshold. If the difference exceeds 10%, replace the threshold with the latest result, otherwise keep it unchanged. The minimum number of consecutive samples is set to 3 to suppress incidental noise. If the deviation value at a certain time exceeds the threshold and this exceeding condition is true at the current and next two sampling points, a speed change marker is generated at that time and written into the speed change marker sequence; the fourth step is connection interruption detection and time window analysis: the input is the signal strength time sequence and the speed change marker sequence, and the output is the connection interruption time sequence. The parameters include a time window length of 2 seconds, a window step of 0.5 seconds, a signal strength threshold, and a minimum interruption duration of 0.1 seconds. The signal strength threshold is determined by field link testing. The method is to gradually reduce the transmission power or increase the path loss until the data packet error rate first exceeds 0.001, and the corresponding signal strength value is fixed as the threshold. In detection, find the continuous low threshold and the duration not less than 0.1 second segment or the appearance of data time interval greater than 3 times the sampling interval gap, either condition is met is determined as 1 connection interruption event and record the start time, end time and duration of writing connection interruption time sequence, while recording the number of speed change markers in the window for subsequent fusion reference; Step 5 position smoothing and synchronous update: input is position deviation sequence, original position sequence and connection interruption time sequence, the output is the smoothed position coordinate sequence and synchronous as tracking sequence, using the standard process of Kalman filter algorithm and with the determination of parameters without formula and letter, the first original position is set as the initial position, the straight line distance of the first 2 original positions is divided by the sampling interval to set the initial speed, the statistical upper bound of the position deviation in the hovering calibration stage is set as the initial estimation error, the frequency and amplitude statistics of the speed change markers in the last 300 seconds are converted into process noise level and fixed as a numerical value, the statistical mean and upper bound of the position deviation in the hovering stage are combined to set the measurement noise level and fixed as a numerical value, the filter first gets the predicted position and predicted speed according to the smoothed position and smoothed speed of the last step combined with the sampling interval at each sampling time and gives the prediction uncertainty, then takes the original position at this time as the observation to get the difference between observation and prediction, i.e. residual, calculate the weight factor according to the residual size, prediction uncertainty and measurement uncertainty, use the weight factor to modify the predicted value to get the current smoothed position and smoothed speed and update the uncertainty, when the current time is in the connection interruption event interval, the measurement noise level is enlarged by 3 times to reduce the influence of abnormal observation, if the residual exceeds the residual threshold and appears continuously for 2 sampling points, the prediction value is directly written into the smoothed sequence by skipping the update, the residual threshold is 3 times the upper bound of the deviation in the hovering stage, the smoothed position coordinate sequence is obtained by time advance and updated as the tracking sequence; Step 6 sliding window trend calculation and node motion state generation: input is the synchronous updated tracking sequence and connection interruption time sequence, output is the node motion state sequence, parameters are window length 2 seconds, window step 0.5 seconds and the static speed threshold is determined by the upper bound of the speed estimation distribution in the hovering calibration phase, 4 indicators are calculated in each window and form the state feature group, which are the speed level, i.e., the time average of the smoothed speed in the window, the direction change rate, i.e., the time average of the adjacent motion direction angle in the window, the stay proportion, i.e., the time proportion of the smoothed speed lower than the static speed threshold in the window, and the event density, i.e., the number of connection interruption events in the window divided by the window length, and the 4 indicators and the window timestamp are written into the node motion state sequence; in the 7th step of clustering analysis and behavior classification, the input is the node motion state sequence, and the output is the behavior classification result, a clustering method based on center point iteration is adopted, the clustering number is determined by the inflection point method between 2 and 6, specifically, different numbers are taken for clustering in turn and the total sum of the distances in the group is calculated, if the decline ratio from the former 1 to the latter 1 is less than 10% for the first time, the former 1 number is taken as the final number, if it is not less than 10% in the whole range, 6 is taken, the distance measurement is the weighted sum of the linear scaling of the 4 indicators in the range of 0 to 1, the scaling is linearly transformed with the minimum and maximum values of all windows, the weights are fixed as 0.4 for the speed level, 0.3 for the direction change rate, 0.2 for the stay proportion, and 0.1 for the event density, the maximum iteration number is 100 times, and the convergence condition is that the average distance of the center changes in the last 2 iterations is less than 0.01 or the iteration upper limit is reached, after the clustering is completed, the deterministic mapping is performed according to the numerical values of the cluster centers: the average speed lower than the static speed threshold and the stay proportion not less than 0.7 are determined as standby, the average speed not less than 0.7 quantile of the global speed median and the stay proportion not higher than 0.2 are determined as high-speed transition, the direction change rate not less than 0.7 quantile of the global direction change rate median or the event density not less than 0.7 quantile of the global event density median are determined as obstacle avoidance or interference, and the rest that meet the average speed higher than the static speed threshold and the direction change rate and the event density are low are determined as patrol, the global statistics are calculated once in 1 task cycle and remain unchanged in the cycle, finally, the system assigns the behavior label to each window in time sequence and merges the windows adjacent and with the same label into continuous periods to form the behavior classification result. In the embodiment, the sampling frequency is determined by the maximum speed, the spatial resolution or the safety distance and is not less than 10 times per second, the upper limit of the single sampling displacement is 1 / 10 of the spatial resolution or the safety distance, the speed change threshold is obtained by 30-second calibration and 300-second online update and contains a safety factor of 1.5, the minimum number of continuous samples is 3, the time window length is 2 seconds, the window step is 0.5 seconds, the signal strength threshold is determined by the inflection point at which the error rate first exceeds 0.001, and the minimum interruption duration is 0.1 second, initial estimation error is taken from hover bias upper bound, process noise level is taken from the frequency and amplitude statistics of the last 300 seconds of speed change flags, measurement noise level is taken from the combination of hover bias mean and upper bound, residual threshold is 3 times the hover bias upper bound, stationary speed threshold is taken from the upper bound of the hover speed estimation distribution, the number of clusters is selected between 2 and 6 by the inflection point method, the maximum number of iterations is 100, the convergence condition is that the average distance of the center changes is less than 0.01 or the upper limit is reached, and the index weight is fixed at 0.4, 0.3, 0.2, 0.1.
[0023] S2 includes grouping the position coordinate sequence using the K-Means algorithm, generating a clustering grouping sequence by iteratively calculating the Euclidean distance of the data points to the center points; for the clustering grouping sequence, if the number of data points in a group is lower than a preset threshold, merging it into the nearest neighbor group, using nearest neighbor distance calculation to obtain an adjusted grouping sequence; according to the adjusted grouping sequence, the time distribution of the connection interruption records in each group is counted, and a time window analysis is used to obtain an interruption time distribution sequence; for the interruption time distribution sequence, a density clustering method is used to identify the density interruption time region, and an interruption dense time sequence is obtained; according to the interruption dense time sequence, the spatial distribution characteristics of the data points in each group are calculated, and a spatial autocorrelation analysis is used to obtain a spatial distribution mode sequence; for the spatial distribution mode sequence, if the spatial distribution mode of a group deviates from the preset mode by more than a threshold, it is marked as an abnormal group, and an abnormal grouping sequence is obtained; according to the abnormal grouping sequence, the coordinate change trend in the abnormal group is extracted using a sliding window analysis, and an abnormal motion trend sequence is obtained.
[0024] In the embodiment, the first stage is to group the position coordinate sequence by using the mean clustering algorithm and generate a clustering group sequence, the determined parameters include the clustering number, the initial center selection method, the maximum iteration number, the convergence threshold and the distance measure, the clustering number is given as a fixed integer by the task configuration or the system parameter table and does not change within one task period, the initial center is determined by extracting the same number of sample points as the clustering number at equal intervals on the whole sequence time axis, the maximum iteration number is set to 100, the convergence threshold is set to the moving distance of the center point being less than 0.01 in the last two times of updating, and the distance measure is the three-dimensional straight line distance; the specific calculation process is to first set the initial center, then assign each data point to the center with the minimum three-dimensional straight line distance in each iteration to form a temporary grouping, then take the arithmetic average of the coordinates of all points in each group as the new center of the group, and if the moving distance of all centers is less than 0.01 or the iteration count reaches 100, stop and output the clustering group sequence; the second stage is to merge the groups and generate an adjusted group sequence, the determined parameters are the minimum sample threshold in the group and the nearest neighbor merging rule, the minimum sample threshold in the group is the average value obtained by dividing the total number of samples by the clustering number multiplied by 0.5 and rounded up, and is not less than 10, the nearest neighbor merging rule is to select the adjacent group with the minimum distance as the merging target according to the three-dimensional straight line distance between the centers of the groups, and the merging process is to merge all data points of the group with the sample number below the threshold into the nearest neighbor group and immediately update the group center with the arithmetic average of the new set, until there is no group with the sample number below the threshold, and the adjusted group sequence is formed; the third stage is to count the time distribution of the connection interruption records in each group and form an interruption time distribution sequence, the determined parameters are the time window length and the window step, the time window length is 2 seconds, and the window step is 0.5 seconds, the calculation process being to count the number of interruption events and the total duration within the time sliding window for each packet that overlap with the packet sample time range and record the window start time, end time, event number and total duration as one interruption time distribution record of the packet, and all the windows sequentially constitute the interruption time distribution sequence; the fourth stage being to perform density clustering on the interruption time distribution sequence to identify the interruption dense time area and generate the interruption dense time sequence, the determined parameters being the time neighborhood radius and the minimum event number, the time neighborhood radius being set as 2 seconds to be consistent with the window length, and the minimum event number being set as 2, the calculation process being to regard the time window as a time point in each packet, when the number of events in the time neighborhood of a certain time point is not less than 2 and the neighborhood of the time point can be connected through neighborhood overlap, the time points are clustered into one dense area and the start time, end time and covered window number of the area are output, and all the areas are sorted by time to constitute the interruption dense time sequence; the fifth stage being to calculate the spatial distribution features of the data points in each packet and form the spatial distribution mode sequence, the determined parameters being the spatial neighborhood distance threshold and the mode judgment threshold, the spatial neighborhood distance threshold being determined by multiplying the average value of the three-dimensional straight line distance from each point in the packet to its nearest neighbor point by 1.5 and rounding off according to the positioning resolution, and the mode judgment threshold being set as the difference proportion not less than 0.2 relative to the average level of the whole group, the calculation process being to count the occurrence frequency of the same group points in the spatial neighborhood of each point in the packet and average the occurrence frequency in the whole group as the actual neighborhood frequency, and then compare the actual neighborhood frequency with the average level of the whole group, when the actual neighborhood frequency is higher than the average level of the whole group and the difference proportion is not less than 0.2, the packet is judged as the aggregation mode, when the actual neighborhood frequency is lower than the average level of the whole group and the difference proportion is not less than 0.2, the packet is judged as the discrete mode, and when the difference proportion is less than 0.2, the packet is judged as the uniform mode, and the mode type and intensity value are taken as one spatial distribution mode record of the packet, and all the packet records constitute the spatial distribution mode sequence; the sixth stage being to identify the abnormal packets according to the spatial distribution mode and form the abnormal packet sequence, the determined parameters being the preset mode and the deviation threshold, the preset mode being selected by the system in one of the uniform coverage, formation or concentration before the task starts and recorded to the parameter table, and the deviation threshold being set as 0.7, the calculation process being to compare each packet mode type and intensity with the preset mode item by item, when the mode type is different, it is directly judged as abnormal and the packet is added to the abnormal packet sequence, when the mode type is the same, the absolute proportion of the difference between the packet intensity and the preset intensity and 0.7 is compared, not less than 0.7, it is marked as abnormal and written into the abnormal packet sequence, otherwise it is judged as normal; the seventh stage being to extract the coordinate change trend of the abnormal packets and form the abnormal motion trend sequence, the determined parameters being the trend window length, the trend window step and the three discrimination thresholds, the trend window length being 2 seconds, the trend window step being 0.5 seconds, and the three discrimination thresholds being the direction consistency threshold 0.8, the turn-back number threshold 2 and the displacement monotonicity threshold 0.5, the calculation process is to process the abnormal group in turn according to the time sliding window, and calculate three deterministic indexes in each window, wherein the direction consistency is the proportion of the same direction of adjacent displacement direction in the window, the number of turn-backs is the number of times of reversing the displacement direction in the window, and the displacement monotonicity is the ratio of the straight line distance of the first and last displacement in the window to the cumulative displacement in the window, and then output the trend type and time stamp according to the fixed rule: when the direction consistency is not less than 0.8, the number of turn-backs is less than 2, and the displacement monotonicity is not less than 0.8, it is marked as straight trend; when the number of turn-backs is not less than 2 and the displacement monotonicity is less than 0.5, it is marked as back-and-forth oscillation; when the direction consistency is between 0.4 and 0.8, the displacement monotonicity is between 0.5 and 0.8, and there is time overlap with the time series of interruption concentration, it is marked as turning aggregation; each window outputs one trend record, and adjacent and similar trend windows are merged, and finally an abnormal motion trend sequence is formed. In the embodiment, the number of clusters is given as a fixed integer by task configuration, the initial center is selected by time equal division sampling, the maximum iteration number is 100 and the convergence threshold is 0.01 to ensure a reproducible balance between calculation accuracy and time cost, the minimum sample threshold in the group is the average sample number multiplied by 0.5 and rounded up, and is not less than 10 to avoid small cluster disturbance, the nearest neighbor merging is determined by the minimum three-dimensional straight line distance between the centers to ensure spatial continuity, the time window length is 2 seconds and the step is 0.5 seconds to ensure that the window contains enough samples for stable statistics, the time neighborhood radius is consistent with the window length to maintain the consistency of the time scale, the minimum event number is 2 to ensure the minimum intensity requirement of the dense area, the spatial neighborhood distance threshold is the average nearest neighbor distance multiplied by 1.5 and rounded according to the resolution to match the positioning accuracy, the mode determination threshold is 0.2 to ensure the deterministic identification of significant aggregation or dispersion phenomena, the preset mode is selected by the scene before the task and remains unchanged, the deviation threshold is 0.7 to determine the group significantly different from the preset mode as abnormal, the length and step of the trend window are consistent with the time window to facilitate linked analysis, the direction consistency threshold is 0.8, the number of turn-backs threshold is 2, and the displacement monotonicity threshold is 0.5, which are fixed in the parameter table after offline calibration of the test set and remain unchanged within one task period.
[0025] S3 includes collecting acceleration sensor data according to node moving speed, calculating speed change sequence of each node in time window to obtain speed change vector; for the speed change vector, using K-Means clustering algorithm, grouping the nodes to generate speed vector grouping sequence; according to the speed vector grouping sequence, calculating the fluctuation amplitude of communication quality in each group, using time-frequency analysis method to obtain communication quality fluctuation sequence; if the fluctuation amplitude of the communication quality fluctuation sequence exceeds the preset threshold, extracting the signal strength data of the corresponding group to generate signal strength sequence; for the signal strength sequence, using moving average filtering method, smoothing the time series data to obtain smoothed signal strength sequence; according to the smoothed signal strength sequence, using time series decomposition method, extracting trend mode to obtain communication quality trend sequence; for the communication quality trend sequence, calculating the fluctuation quantization index of each group, using standard deviation statistical method to obtain fluctuation quantization result.
[0026] In the present embodiment, the first step of velocity change vector calculation has parameters of acceleration sampling frequency, zero offset calibration duration, velocity calculation window length and step size. The acceleration sampling frequency is set to 100 times per second and is not less than 5 times of the position sampling frequency. The zero offset calibration duration is set to 30 seconds and the time average of each axis acceleration in this period is taken as the zero offset which is deducted throughout the whole process. The velocity calculation window length is set to 2 seconds and the step size is set to 0.5 seconds. The specific process is as follows: for each node, the acceleration is multiplied by the sampling interval to obtain the velocity sequence in the same window by sample-by-sample accumulation in ascending order of time. Then, the difference between adjacent velocity samples in the window is calculated and divided by the sampling interval to obtain the velocity change sequence. Subsequently, the time average, absolute value average and maximum value of the velocity change sequence in the window are calculated, and a 3-dimensional velocity change vector is formed in this order and is appended with the start and end time stamps of the window. All windows form the velocity change vector sequence of each node in turn. The second step of node grouping has parameters of cluster number, initial center selection strategy, maximum iteration number, convergence threshold and distance metric. The cluster number is between 2 and 6 and is determined by the inflection point method, i.e., the grouping of 2 to 6 is performed respectively and the total distance sum in each group is calculated. When the decline ratio from the previous number to the next number is less than 10% for the first time, the previous number is taken as the final number. If it is always not less than 10%, 6 is taken. The initial center is extracted at equal intervals in the velocity change vector sequence of the last 60 seconds according to the node number. The maximum iteration number is 100. The convergence threshold is that the distance of the center movement in the adjacent two times is less than 0.01. The distance metric is the 3-dimensional straight line distance. The assignment and center update are performed in a loop until the convergence is met or the iteration upper limit is reached, and the velocity vector grouping sequence is output and the grouping identifier is recorded for each node. The third step of communication quality fluctuation sequence calculation has parameters of statistical window length and step size. The statistical window length is set to 2 seconds and the step size is set to 0.5 seconds. The specific process is as follows: in each group, the ratio of the uninterrupted duration to the total duration in the sliding window is taken as the communication quality value of the window and a time sequence is formed. Then, the short-time Fourier transform is performed on the time sequence to obtain the frequency band energy distribution of each time period. After removing the zero-frequency energy, the remaining frequency band energies are added and squared to obtain the fluctuation amplitude of the period and the center time stamp is recorded, thereby obtaining the communication quality fluctuation sequence. The fourth step of threshold triggering and signal strength sequence generation has parameters of baseline period length and determination rule of fluctuation triggering threshold. The baseline period length is set to 60 seconds. The threshold is determined as the average value of the fluctuation amplitude sequence obtained by the same method in the third step in the baseline period plus 2 times the standard deviation and remains unchanged within 1 task cycle. When the fluctuation amplitude of any group in any time period is not less than the threshold, it is determined that the group triggers in the time period. Subsequently, the signal strength original samples of all nodes in the group in the time period are combined in ascending order of time stamp to form the signal strength sequence corresponding to the group. The fifth step of moving average filtering and smoothing has parameters of smoothing window length and step size. The smoothing window length is set to 1 second and the step size is set to 0.2 seconds, the endpoints are filled with mirror extension, the arithmetic mean of the signal intensity in the window is calculated by sliding the window in time to obtain the smoothed signal intensity sequence and keep the same timestamp density as the original sequence; the 6th step of time series decomposition extracts the trend, the parameter is the trend window length, the trend window length is 5 seconds, the additive decomposition method is used, that is, the trend part is first obtained by using the length of 5 seconds twice sliding average on the smoothed signal intensity sequence, then the short-term fluctuation part is obtained by subtracting the trend part from the smoothed signal intensity sequence at each time, and the trend part is output as the communication quality trend sequence according to time; the 7th step of fluctuation quantification, the parameters are quantification statistical caliber and aggregation caliber, the quantification statistical caliber is to calculate the standard deviation of the short-term fluctuation part using the timestamp set generated in the 5th step in each trigger time period, the specific process is to first calculate the average value of the short-term fluctuation part, then calculate the square of the difference between each sample and the average value, and then take the square root to obtain the standard deviation as the fluctuation quantification index of the grouping in the time period, and the aggregation caliber is to output the maximum value and the median value of all trigger time period indexes of the same grouping at the same time to supply subsequent decision. The acceleration sampling frequency is 100 times per second, which is determined by the sensor performance and anti-aliasing requirement and is not less than 5 times of the position sampling frequency, the zero offset calibration time is 30 seconds for obtaining stable zero offset, the speed calculation window is 2 seconds and the step is 0.5 seconds for balancing time resolution and robustness, the speed change vector dimension is fixed to 3 including time average, absolute average and maximum, the clustering number is selected in 2 to 6 by inflection point method to ensure stable grouping, the initial center takes equal interval sampling to avoid bias, the maximum iteration number is 100 and the convergence threshold is 0.01 to limit the calculation cost and convergence accuracy, the communication quality statistical window is 2 seconds and the step is 0.5 seconds, which is consistent with the 1st step to ensure step alignment, the length of the time period of short-time Fourier transform is consistent with the sliding of the statistical window to make the fluctuation measure consistent with the time positioning, the fluctuation trigger threshold is determined by the baseline average plus 2 times the standard deviation for stable detection of abnormal fluctuations in the natural jitter background, the smoothing window is 1 second and the step is 0.2 seconds to remove high-frequency jitter while retaining second-level changes, the trend window is 5 seconds for extracting slow-changing components, and the standard deviation is calculated as the fluctuation quantification index by segment in the trigger segment and outputs the maximum value and the median value for robust aggregation.
[0027] S4 includes a fluctuation quantization index, obtains a time series fluctuation value from node communication data, calculates the fluctuation quantization index of each node, obtains a fluctuation quantization sequence, compares the fluctuation quantization sequence with a preset threshold value, if the value of the fluctuation quantization sequence exceeds the preset threshold value, extracts the corresponding node position data, determines an affected node set, encrypts the node position data using an elliptic curve encryption mechanism according to the affected node set, generates encrypted position deviation data, calculates the position deviation value of each node according to the encrypted position deviation data, obtains a deviation calculation accuracy sequence using a mean square error method, adjusts the trust chain model parameters using a trust chain model update algorithm according to the deviation calculation accuracy sequence, generates an updated trust chain model, calculates the trust chain vulnerability value of each node according to the updated trust chain model, determines the vulnerability level value using a standard deviation statistical method, and classifies the vulnerability level value according to a preset level threshold value, if the vulnerability level value exceeds the preset threshold value, marks it as a high-risk node, and obtains a high-risk node list.
[0028] In the embodiment, the first step is to generate a fluctuation quantization sequence, with the parameters of a statistical window length and a window step. The statistical window length is 2 seconds, and the window step is 0.5 seconds. The process is to slide the statistical window on the timeline at each node, calculate the standard deviation of the short-term fluctuation of the communication quality in the window, and take the standard deviation as the fluctuation quantization index of the window. The fluctuation quantization sequences of all the windows are concatenated in time sequence to obtain the fluctuation quantization sequence of the node. The second step is to determine the affected nodes, with the parameters of a baseline period length and a fluctuation threshold determination rule. The baseline period length is 60 seconds, and the fluctuation threshold is equal to the average value of the fluctuation quantization sequence of the node in the baseline period plus 2 times the standard deviation and remains unchanged within 1 task cycle. When the fluctuation quantization index of any window of a node is not lower than the threshold, the node is added to the affected node set and the start and end time stamps of the triggering window are recorded. The third step is to perform encryption processing and generate encrypted position deviation data, with the parameters of an elliptic curve key length, a key update period, and a position encoding precision. The elliptic curve key length is 256 bits, the key update period is 60 seconds, and the position encoding precision is 3 decimal places. The process is to first calculate the position deviation sequence by subtracting the time-adjacent position samples of the affected nodes in each triggering window, and then round the integer sequence to the encoding precision. Then, the integer sequence is encrypted using the elliptic curve encryption mechanism with the public key of the node side, and the time stamp and node identification are attached to output the encrypted position deviation data. The fourth step is to generate a deviation calculation precision sequence, with the parameters of an error statistical window length and a window step. The error statistical window length is 2 seconds, and the window step is 0.5 seconds. The process is to decrypt the encrypted position deviation data in the controlled security calculation process to restore the integer deviation sequence, and then restore the position deviation value to the encoding precision. Then, the value at the same time stamp is compared with the adjacent position difference value calculated from the step S1 smooth position coordinate sequence to obtain an error sequence. The error statistical window is slid on the timeline, the average of the squares of the errors in the window is calculated, and the square root of the average is obtained to obtain the mean square error. The mean square errors of the windows are concatenated in time sequence to obtain the deviation calculation precision sequence of the node. The fifth step is to update the trust chain model, with the parameters of an initial trust value, a time decay coefficient, the weights of the two indexes, a normalized upper bound, and an update step. The initial trust value is 0.8, the time decay coefficient is 0.9, the weights of the two indexes are 0.6 for the fluctuation quantization index and 0.4 for the mean square error, the normalized upper bound is the larger one of the maximum value of the index of the corresponding node in the baseline period and the average value of the index plus 2 times the standard deviation, and the update step is 0.1, the processing process is to multiply the trust value of the last window by the time attenuation coefficient to obtain the attenuation trust value in each time window, divide the fluctuation quantization index of the current window by the respective upper limit of normalization to obtain the dimensionless value, and obtain the comprehensive penalty score by weighting and summing the weighted sum, subtract the update step size multiplied by the comprehensive penalty score from the attenuation trust value to obtain the new trust value, and truncate the result between 0 and 1, update all nodes in the entire time axis in turn to obtain the updated trust chain model; the 6th step is to calculate the trust chain vulnerability value, the parameters are the vulnerability statistical window length and the classification threshold, the vulnerability statistical window length is 60 seconds, and the classification threshold is equal to the average value of the standard deviation of the trust value of each node calculated by the length of the 60-second sliding window in the baseline period plus 2 times the standard deviation and remains unchanged within 1 task cycle, the processing process is to calculate the standard deviation of the trust value in the window for each node with the vulnerability statistical window sliding on the timeline, and the standard deviation is used as the trust chain vulnerability value of the window to form the vulnerability time sequence of the node in time sequence, and the standard deviation of the last 1 vulnerability statistical window is used as the current vulnerability value of the node; the 7th step is to classify and generate a list of high-risk nodes, the parameters are the high-risk threshold and the shortest duration, the high-risk threshold is the classification threshold of the 6th step, and the shortest duration is 2 seconds, the processing process is to mark the node as high-risk when the current vulnerability value of the node is not less than the high-risk threshold and the state is continuously maintained for not less than 2 seconds, and write the node identification, the time stamp of the first time reaching the threshold and the current time stamp into the high-risk node list, and record the end time and close the entry when the vulnerability value of the node is lower than the high-risk threshold. The determination rules of all the above parameters and thresholds are fixed and written into the system parameter table at the beginning of the task and remain unchanged within 1 task cycle or updated according to the explicit rules, including the statistical window length 2 seconds and the step size 0.5 seconds, the baseline period length 60 seconds, the fluctuation threshold equal to the average value plus 2 times the standard deviation, the elliptic curve key length 256 bits and the key update period 60 seconds, the position encoding accuracy 3 decimal places, the error statistical window length 2 seconds and the step size 0.5 seconds, the initial trust value 0.8, the time attenuation coefficient 0.9, the index weight 0.6 and 0.4, the upper limit of normalization is determined according to the larger one, the update step size 0.1, the vulnerability statistical window length 60 seconds, and the classification threshold equal to the average value plus 2 times the standard deviation and the shortest duration 2 seconds.
[0029] S5 includes obtaining identity identification data from the verification node, generating a node characteristic code using a physically unclonable function to obtain a node identity identification; according to the node identity identification, combined with the trust chain level evaluation, using a preset threshold to judge the vulnerability, to obtain the trust chain vulnerability level; if the trust chain vulnerability level exceeds the preset threshold, extract the dynamic features from the node identity identification, combined with time series analysis, to obtain dynamic trend data; using the dynamic trend data, generate an authentication request sequence, to obtain an initial authentication sequence; for the initial authentication sequence, perform sequence optimization processing, using the K-means clustering algorithm to group the sequence, to obtain the optimized authentication sequence; according to the optimized authentication sequence, execute node identity verification, using the support vector machine algorithm for classification, to obtain the verification result; if the verification result shows that the node identity is trusted, generate the final authentication request sequence, to obtain the trusted authentication sequence.
[0030] In this embodiment, the first step is node identity generation, with parameters including the number of challenges, the number of repeated confirmations, the stable bit determination ratio, and the consistency threshold. The number of challenges is set to 5, the number of repeated confirmations to 3, the stable bit determination ratio to 0.6, and the consistency threshold to 0.9. The processing involves sampling the same challenge 5 times consecutively at adjacent times and calculating the proportion of identical values for each bit. Positions with a value not lower than 0.6 are judged as stable bits, and the rest are unstable bits. For stable bits, three more repeated confirmations are performed, and the consistency ratio for each bit is calculated. Bits with a value not lower than 0.9 are retained, and those with a value lower than 0.9 are discarded. The retained bits are concatenated in a fixed order and the node number and device model are added to form the node identity. At the same time, the number of retained bits and the stable bit ratio are recorded as identification quality indicators. The second step... The vulnerability level of the trust chain is determined by parameters including the vulnerability level threshold and the classification boundary. The vulnerability level threshold is directly adopted from the classification threshold given in step S4. The classification boundary is 0.5 times the threshold and 1 times the threshold. The processing involves comparing the current vulnerability value of each node with the threshold. If it is less than 0.5 times, it is judged as low; if it is between 0.5 times and 1 times, it is judged as medium; and if it is not less than 1 times, it is judged as high. The trigger timestamp and corresponding window are recorded. Step 3, dynamic feature extraction and time series analysis, is triggered only when the level is high. The parameters are the analysis window length, window step size, and feature set. The analysis window length is 60 seconds, the window step size is 1 second, and the feature set consists of three types of deterministic features: one is the rate of change of the proportion of different bits between the two generation of the identity identifier to the total number of retained bits. The calculation consists of three steps: First, the difference in the ratio of the position difference between the first and last identity identifiers within the window, divided by the window duration and recorded over time. Second, the identity interaction interval statistics, calculated as the median, maximum, and percentage exceeding the threshold time interval between two adjacent identity interactions within the window, where the threshold is the 70th percentile of the global identity interaction interval. Third, the response stability ratio, calculated as the average percentage of all identity generation processes judged as stable positions within the window. These three features constitute one dynamic trend data entry for each window. The fourth step is the initial authentication sequence generation, with parameters including anomaly weight and upper limit of sequence length. The anomaly weight is set to 0.5, 0.3, and 0.2 for the position difference change rate, the percentage exceeding the threshold, and the low value of response stability, respectively. The upper limit of sequence length is 50. The first step involves processing the data. Within the last 60 seconds, all dynamic trend data entries are calculated for anomaly. Entries with anomaly scores of no more than 50 are selected from highest to lowest and organized in ascending chronological order. Each entry is then appended with a node identity summary and a window timestamp to form an initial authentication sequence. The fifth step is sequence optimization. The initial authentication sequence is grouped using a mean clustering algorithm to obtain an optimized authentication sequence. Parameters include the number of clusters, the maximum number of iterations, the convergence threshold, and the distance metric. The number of clusters is determined using the inflection point method, which involves sequentially trying 2 to 6 clusters and calculating the sum of the distances within each group. The previous cluster is selected when the decrease in the number from the previous cluster to the next is less than 10% for the first time; otherwise, 6 is selected. The maximum number of iterations is 100, and the convergence threshold is set to a center movement distance of less than 0.01, the distance metric is the weighted straight-line distance of the abnormality components linearly scaled in the range of 0 to 1, and the weight is still 0.5, 0.3, 0.2, the calculation process is to first select the initial center by equal interval sampling, then loop to perform item assignment and center update until convergence is met or the upper limit is reached, obtain several groups, then rearrange in each group according to the abnormality degree from high to low, and use the grouping round-robin way to stagger the extraction of items to avoid time concentration, and output the optimized authentication sequence; the 6th step is node identity verification, using support vector machine algorithm to classify each item of the optimized authentication sequence to obtain the verification result, the parameters are feature standardization method, kernel type, penalty coefficient, kernel width, acceptance threshold and passing judgment rule, the feature standardization method is to linearly scale each feature to the range of 0 to 1 with the minimum and maximum values of the training set, the kernel type is radial basis function kernel, the penalty coefficient is 10, and the kernel width is 0.5, the above two parameters are fixed to reproducible values through offline calibration of historical legal and abnormal samples before deployment, the acceptance threshold is 0.5, and the passing judgment rule is to obtain the node summary credibility score by weighted average of item credibility scores according to time weight in the latest 60 seconds, and the single item credibility proportion is not less than 80%, when the summary credibility score is not less than 0.5 and the single item credibility proportion is not less than 80%, the node identity verification result is output as credible, otherwise it is not credible and continues to accumulate items to enter the subsequent window for reevaluation; the 7th step is to generate a credible authentication sequence, the parameters are the effective period length and the minimum coverage item number, the effective period length is 60 seconds, and the minimum coverage item number is 10, the processing process is that when the node identity verification result is credible, the items used for this determination and judged as credible are merged into one credible authentication sequence in ascending order of time, the sequence header contains the node identity, the generation timestamp and the end time of the effective period, and the sequence body is the item timestamp and the corresponding dynamic feature digest list, if the number of items is less than 10, the remaining items from the initial authentication sequence are supplemented to 10 items in descending order of abnormality and repeated in step 6 before output. Challenge number 5 and repeated confirmation number 3 are used to improve feature stability, stable position judgment proportion 0.6 and consistency threshold 0.9 ensure identity reliability, vulnerability level threshold directly references step S4 output and grading boundary is 0.5 times and 1 times, analysis window length 60 seconds and step length 1 second guarantee timeliness and resolution, identity interaction interval threshold takes global 70% quantile to highlight abnormal frequency, abnormality weight 0.5 and 0.3 and 0.2 embody the dominant role of position difference change, sequence length upper limit 50 controls calculation overhead, cluster number is between 2 and 6 to determine the inflection point method, and the maximum iteration number is 100 and the convergence threshold is 0.01 to ensure group convergence, the penalty coefficient of support vector machine is 10 and the kernel width is 0.5, which is fixed by offline calibration, the acceptance threshold is 0.5 and the single item credibility proportion is 80%, which together form a strict passing condition, the effective period is 60 seconds and the minimum coverage item number is 10 to ensure time and sample sufficiency.
[0031] S6 comprises obtaining the node verification state from the node identification data, using a preset trust evaluation model to judge the trustworthiness of the node, and obtaining the node trust level; according to the node trust level, extracting the sequence priority from the authentication request sequence, sorting the request through the sequence priority, and determining the priority sequence; for the priority sequence, obtaining the dynamic parameter adjustment data in the key negotiation process, if the dynamic parameter adjustment data meets the preset threshold, generating a temporary key pair; through clustering convergence analysis, optimizing the parameters of the temporary key pair, and obtaining the optimized negotiation basic parameters; extracting the node identification data from the optimized negotiation basic parameters, combining the verification state of the newly added node, judging whether to update the key negotiation process, and determining the updated negotiation process; according to the updated negotiation process, generating a new authentication request sequence, and outputting the ordered sequence data.
[0032] In the present embodiment, the first step is node trustworthiness judgment and trust level generation, the parameters are evaluation time window length, time decay coefficient, verification result weight, connection stability weight, trust level boundary and minimum sample number, the evaluation time window length is 60 seconds, the time decay coefficient is 0.9, the verification result weight is 0.7, the connection stability weight is 0.3, the minimum sample number is 10, the trust level boundary is fixed as low level less than 0.5, medium level between 0.5 and 0.8, high level no less than 0.8, the calculation process is to obtain the weighted sequence by multiplying the verification state of the node in the evaluation time window by the decay coefficient from recent to remote, and to obtain the verification score by weighted average of the trusted 1 and the untrusted 0, at the same time, the handshake success ratio related to the node is extracted from the dynamic parameter adjustment data in the same time window as the connection stability score, then the node trustworthiness score is obtained by the weighted sum of the verification score and the connection stability score, if the effective sample in the window is less than 10, continue to accumulate until it meets the requirement, then give the node trust level according to the trustworthiness score and the boundary and record the time stamp; the second step is to extract the sequence priority from the authentication request sequence and sort to generate the priority sequence, the parameters are priority calculation weight, time limit weight, queue upper limit and rearrangement period, the priority calculation weight is 0.6 for the inverse importance of trust level and 0.4 for the request waiting time, the time limit weight is obtained by linear normalization from the request entry time to the current time, the queue upper limit is 100, the rearrangement period is 1 second, the calculation process is to map the trust level of the request corresponding node to the inverse importance value, wherein the low level is mapped to 1.0, the medium level is mapped to 0.6, and the high level is mapped to 0.3, at the same time, the waiting time of each request is linearly scaled to the interval of 0 to 1 according to the minimum and maximum waiting time of the current batch, then the priority score is obtained by adding the weights, and the sequence is sorted from high to low according to the score, if the number of requests exceeds 100, the first 100 are reserved to form the priority sequence and rearranged once every 1 second according to the above rules; the third step is to trigger the generation of temporary key pair according to the dynamic parameter adjustment data, the parameters are dynamic parameter threshold group, temporary key length, temporary key validity period and minimum generation interval, the dynamic parameter threshold group is handshake retry number threshold 3, round trip time median threshold 200 milliseconds, packet loss rate threshold 0.1, and near 60 seconds handshake failure proportion threshold 0.05composition, the temporary key length is 256 bits, the temporary key validity period is 60 seconds, the minimum generation interval of the same node is 30 seconds, the trigger judgment is that when the node of a request in the priority sequence is not lower than the corresponding threshold in any index within the evaluation window, the generation is triggered, the generation process is to call the random number source on the node side to generate the private key and calculate the public key to form the temporary key pair, bind the request and write the generation time and expiration time, if the distance from the last generation time is less than 30 seconds, the generation is not repeated; the fourth step is to perform clustering convergence analysis on the temporary key pair and optimize the negotiation basic parameters, the parameters are the clustering number range, the maximum iteration number, the convergence threshold, the feature set and the parameter mapping rule, the clustering number range is 2 to 5, the maximum iteration number is 100, the convergence threshold is that the center moving distance is less than 0.01, the feature set includes the round trip delay median, the round trip delay jitter, the packet loss rate, the handshake retry number, the handshake success rate in the last 1 minute, a total of 5, the calculation process is to execute the mean clustering with the above features of the node and the same batch of requests in the same time period as the sample, and try 2 to 5 clusters in turn to calculate the total distance sum, when the decline ratio from the previous number to the next number is less than 10% for the first time, the previous number is taken as the final number, otherwise 5 is taken, under the final number, the sample distribution and center update are executed in a loop until all center moving distances are less than 0.01 or 100 iterations are reached, which is considered to be converged, the parameter mapping rule is to linearly map the features of the final cluster center to the negotiation basic parameters and give a determined value: the handshake timeout is 3 times the cluster center round trip delay median and is truncated between 100 milliseconds and 1000 milliseconds, the retransmission interval is 2 times the cluster center round trip delay median, the maximum retry number is the cluster center handshake retry number rounded up by 1 and truncated between 2 and 6, the number of multi-channel parallel paths is determined according to the packet loss rate and the round trip delay jitter, when the packet loss rate is not lower than 0.1 or the round trip delay jitter is not lower than 50 milliseconds, 3 is taken, otherwise 2 is taken, 1 is taken in other cases, the encryption suite candidate order is arranged from high to low according to the handshake success rate in the last 1 minute, the output is the optimized negotiation basic parameters corresponding to the temporary key pair; the fifth step is to judge whether to update the key negotiation process according to the optimized negotiation basic parameters and the verification state of the newly added node, the parameters are the new addition proportion threshold and the high-risk node participation threshold, the new addition proportion threshold is 0.1, the high-risk node participation threshold is at least 1, the calculation process is to calculate the proportion of the number of nodes in the new addition state to the total number of nodes in the current batch and detect whether the batch contains any high-risk node, if the new addition proportion is not lower than 0.1 or contains at least 1 high-risk node, the process is switched to the cautious mode and the handshake timeout is multiplied by 1.5 and the maximum number of retries is increased by 1 based on the standard value, and the number of parallel paths is set to the maximum of the original value and 3, otherwise the standard mode is kept unchanged, finally the updated negotiation process is output and the mode type and effective time are recorded; the 6th step is to generate a new authentication request sequence and output the ordered sequence data, the parameters are sequence construction rules, deduplication rules and minimum coverage number, the sequence construction rules are to append the corresponding negotiation base parameters and temporary key pair identifier to each request in the priority sequence and arrange them from high to low priority, the deduplication rules are to keep only one latest request for the same node within the same temporary key validity period, and the minimum coverage number is 10, when the number of entries after deduplication is less than 10, it is supplemented to 10 from the next priority batch, the output ordered sequence data includes node identifier, generation timestamp, priority score, negotiation base parameter digest, current process mode and validity period information. Among them, the evaluation time window length is 60 seconds and the time decay coefficient is 0.9 to highlight recent status, the verification result weight is 0.7 and the connection stability weight is 0.3 to ensure that the identity is trusted result is given priority and the actual connection performance is considered, the trust level boundary is 0.5 and 0.8 to give a certain grade, the priority calculation weight is 0.6 and 0.4 and the rearrangement period is 1 second to ensure that the sorting is stable and time-effective, the queue upper limit is 100 to limit the instantaneous cost, the dynamic parameter threshold group is 3 and 200 milliseconds and 0.1 and 0.05 to determine the generation of temporary keys when retries are multiple, latency is high, loss is heavy or failure ratio is high, temporary key length is 256 bits, validity period is 60 seconds and minimum generation interval is 30 seconds to balance safety and timeliness, cluster number range is 2 to 5, maximum iteration number is 100, convergence threshold is 0.01 and drop threshold is 10% to ensure that the clustering process is reproducible and convergent, the parameter mapping rule directly converts the cluster center value to handshake timeout, retransmission interval, maximum number of retries and number of parallel paths with explicit truncation and multiplier fixation, the process update threshold newly adds the proportion of 0.1 and at least one high-risk node to ensure that the cautious mode is switched when the topology changes or the risk increases, and the sequence minimum coverage number is 10 and the deduplication rule ensures the stability of the load and coverage of downstream negotiation.
[0033] S7 includes obtaining negotiation base parameters, adopting a preset multi-channel allocation strategy, extracting channel allocation data from the parameters, and determining a channel allocation scheme; according to the channel allocation scheme, processing the channel allocation data through a random exchange mechanism to generate a temporary shared key; for the temporary shared key, adopting a consistency detection algorithm to obtain key consistency data and judging the key consistency state; if the key consistency state meets the preset threshold, then through the result verification logic, confirming the validity of the shared key, and obtaining the effective shared key; according to the effective shared key, extracting state confirmation data from the negotiation success state, and determining the final negotiation state; for the final negotiation state, adopting a state confirmation rule to generate a negotiation completion identifier and determining the end of the negotiation process.
[0034] In the embodiment, the first step channel allocation scheme is determined, and the parameters are allocation period, time frame length, rotation depth, path weight number and channel weight threshold. The allocation period is 1 second, the time frame length is 100 milliseconds, the rotation depth is 3, the path weight number is initially 1, and the channel weight threshold is 0.8. The processing process is that when the number of parallel paths is N, channels numbered 1 to N are created, 1 allocation period is divided into 10 time frames, the handshake success ratio of each channel in the last period is read at the beginning of each period, the path weight number of the channel not lower than 0.8 is set to 2, and the path weight number of the channel lower than 0.8 is kept to 1, then the channel allocation data of the period is generated by weighted round robin, specifically, in each time frame, the to-be-sent segments are assigned in the order of channel number from small to large, when the weight number of a channel is 2, the channel is assigned once in each of the adjacent two time frames, so that the high-reliability channel obtains a higher bearing opportunity, and finally the channel allocation scheme is output in the order of time frame; the second step is to generate a temporary shared key by random exchange mechanism, and the parameters are exchange round number, segment length, splicing length and exchange order seed. The exchange round number is 3, the segment length is 128 bits, the splicing length is 256 bits, and the exchange order seed is a non-negative integer obtained by adding the handshake timeout, the maximum number of retries, the number of parallel paths, the digital sum of the node identifiers of the two parties and the current allocation period sequence in a fixed order; the processing process is that the two parties independently obtain an exchange order sequence with a length of 10 by using the same exchange order seed and the same generation rule at their respective ends. The generation rule is that the channel number used in the frame is obtained by adding the seed and the time frame sequence number to the number of parallel paths and taking the remainder; in each round, the two parties process 10 time frames in turn according to the exchange order, the sender calls the local pseudo-random sequence to generate a segment with a length of 128 bits in each time frame and sends it on the channel specified in the channel allocation scheme, the receiver receives the segment on the corresponding channel and records the frame timestamp and the channel number, and the two parties independently splice the 10 received segments in the order of time frame from small to large to obtain the key piece of the round at their respective ends. After 3 rounds, the 3 key pieces are spliced in the order of round and the first 256 bits are taken from the starting position as the temporary shared key and written into the timestamp and source channel record; the third step is key consistency detection, and the parameters are segment size, check digit number, detection round and consistency threshold. The segment size is 32 bits, the check digit number is 2 bits, the detection round is 2, and the consistency threshold is 1.0; the processing process is to divide the temporary shared key into 8 segments by 32 bits, and the last 2 bits of the integer obtained by summing each segment by bit are taken as the check value of the segment. The 8 check values are combined into a check vector according to the segment sequence. Both sides only exchange the check vector and compare it segment by segment. All 8 segments are the same in 1 comparison, which is recorded as passed. Otherwise, it is recorded as not passed. If 2 consecutive comparisons are both passed, the consistency state is determined as passed. Otherwise, the consistency state is not passed and the process is restarted in the next distribution period. The result verification logic of step 4 is the same as the valid shared key confirmation. The parameters are the verification round number, the verification timeout and the pass threshold. The verification round number is 2, the verification timeout is the handshake timeout, and the pass threshold is all successful. The processing process is that both sides input the temporary shared key, the current time frame sequence number and the number of parallel paths into the deterministic transformation process in a fixed order to generate a verification tag with a length of 64 bits. It is sent 1 time in 2 different time frames. The receiving end independently generates a local tag using the same input and the same process and compares it with the received tag. If both times match, it is confirmed that the temporary shared key is valid and is marked as a valid shared key. Otherwise, it is discarded and retried in the next distribution period. Step 5 determines the final negotiation state. The parameters are the state confirmation data set and the success determination rule. The state confirmation data set includes the channel coverage, the total number of retries, the failed frame count and the valid shared key confirmation flag. The channel coverage is defined as the number of channels obtained in a distribution period divided by the number of parallel paths. The success determination rule is that the channel coverage is not less than 1, the failed frame count is 0, and the valid shared key confirmation flag is true. If the above conditions are met, the final negotiation state is recorded as successful. Otherwise, it is recorded as failed and the failure reason and corresponding time frame are recorded for subsequent retries. Step 6 generates a negotiation completion identifier. The parameters are the state confirmation rule, the shortest completion time and the record field. The state confirmation rule is to generate a completion identifier immediately when the final negotiation state is successful. The shortest completion time is 1 complete distribution period. The record field includes the initiator node identifier, the opposite node identifier, the number of parallel paths, the timestamp interval of the valid shared key, the set of time frame numbers used, the channel coverage, the total number of retries and the completion identifier generation timestamp. The distribution period is 1 second and the time frame length is 100 milliseconds to balance between time effectiveness and scheduling granularity. The rotation depth is 3 to ensure that the segments are sufficiently mixed in time. The path weight is initially 1 and temporarily increased to 2 when the success rate of the previous period handshake is not less than 0.8 to tilt the stable channel. The exchange round is 3, the segment length is 128 bits, and the splicing length is 256 bits to ensure the balance of entropy and time delay. The exchange order seed is determined by the negotiation basis parameters and the node identifier digital sum and the cycle sequence number to ensure that both sides are reproducible and do not need external dependence. The consistency detection segment size is 32 bits and the check bit number is 2 bits to provide sufficient confidence without revealing the key body. The detection round is 2 and the consistency threshold is 1.0 Ensure that only when all segments are completely consistent, pass, verify round 2 and verify timeout equal to the handshake timeout to ensure the determinacy and real-time of the verification phase, pass through the threshold value for all success to eliminate ambiguity, success determination rule requires channel coverage rate is not less than 1 and failure frame count is 0 and at the same time has valid shared key confirmation mark to ensure the negotiation quality, the shortest completion time 1 distribution cycle to ensure the record is complete.
[0035] S8 includes extracting state association data from the negotiation success state, generating structured state information using a preset data parsing rule, and determining the integrity of the state association data; according to the structured state information, using an adaptive adjustment mechanism, updating the cooperative working parameters, generating a dynamic parameter set, and judging the applicability of the parameter set; if the applicability of the dynamic parameter set meets the preset threshold, then through the derived key generation logic, extracting key derivation data from the shared key, generating a derived key configuration; for the derived key configuration, using a state change detection algorithm, obtaining running mode change data, and determining the adjustment direction of the UAV group running mode; according to the running mode adjustment direction, using the mode optimization rule, updating the UAV group running configuration, and generating the optimized running mode; extracting mode verification data from the optimized running mode, using a consistency detection algorithm to judge the stability of the running mode, and determining the final running mode; for the final running mode, using the state confirmation rule, generating the running mode identifier, and determining the UAV group running state.
[0036] In the embodiment, the first step state association data parsing and integrity determination, the parameters are the mandatory field set, the time freshness threshold and the missing tolerance, the mandatory field set fixedly includes the channel coverage, the total number of retry times, the failure frame count, the valid shared key confirmation mark, the parallel path number, the handshake timeout and the negotiation completion identification, the time freshness threshold takes 1 second, the missing tolerance takes 0, the processing process is to read each field according to the preset data parsing rule by key name and check whether the difference between the timestamp and the current time is not greater than 1 second, if any field is missing or out of time, the integrity mark is no and the subsequent steps are stopped, otherwise, the structured state information is written according to the fixed key sequence and the integrity mark is yes; the second step adaptive adjustment and dynamic parameter set generation and applicability determination, the parameters are the adjustment window length, the window step, the applicability threshold and the cooperative work parameter basic value, the adjustment window length takes 2 seconds, the window step takes 0.5 seconds, the determination rule of the applicability threshold is to calculate the comprehensive score sequence according to the same method in this step within the baseline segment 60 seconds of the task to take the larger one of the lower quartile and the fixed value 0.7 as the threshold, if the baseline cannot be completed, 0.7 is directly taken, the cooperative work parameter basic value is fixed as the broadcast period 200 milliseconds, the parallel path redundancy level 1, the task batch processing size 20, the position update interval 200 milliseconds; the processing process is to calculate 3 deterministic indexes in the adjustment window according to the structured state information: communication stability, time delay bearing degree and failure risk degree, the communication stability is calculated as 1 when the channel coverage is not less than 1 and the failure frame count is 0, otherwise, the channel coverage is taken as the starting score and 0.1 is deducted for each failure frame until not less than 0; the time delay bearing degree is calculated as follows: first, get the time delay score and the retry score two parts, the time delay score is 1 when the handshake timeout is not greater than 200 milliseconds, when the handshake timeout is between 200 milliseconds and 1000 milliseconds, it is linearly decreased to 0 at both ends, when it is greater than 1000 milliseconds, it is assigned as 0, the retry score is 1 when the total number of retry times is not more than 2, when it is between 2 and 6, it is linearly decreased to 0 at both ends, when it is greater than 6, it is assigned as 0, then the time delay score and the retry score are taken to get the arithmetic mean to get the time delay bearing degree; the failure risk degree takes 1 as the starting value, deducts 0.2 for each failure frame and deducts 0.05 for each time when the total number of retry times exceeds 3, the minimum is not less than 0; the comprehensive score is obtained by multiplying the weighted sum of the communication stability and the time delay bearing degree with the weight 0.6 and 0.4 by the failure risk degree, if the comprehensive score is not less than the applicability threshold, the dynamic parameter set is generated, otherwise, it is determined that it is not applicable and is returned to the basic value; the generation rule of the dynamic parameter set is: the broadcast period is multiplied by the coefficient based on the basic value, when the comprehensive score is not less than 0.9, 0.8 is taken, when it is between 0.8 and 0.9, 0.9 is taken, when it is between the applicability threshold and 0.8, 1.0 is taken; the parallel path redundancy level takes the determined value in 1 to 3, when the failure frame count is 0 and the channel coverage is not less than 1, 1 is taken, when the total number of retry times is not more than 2, 2 is taken, otherwise, 3 is taken; the task batch processing size is based on the basic value when the comprehensive score is not less than 0.9 Increase 20% otherwise increase 10%; location update interval shorten to 0.8 of base value when comprehensive score is no less than 0.9, shorten to 0.9 when between 0.8 and 0.9, remain unchanged otherwise; step 3, derived key generation and derived key configuration creation, only when dynamic parameter set is applicable, parameters are derived purpose tag set, derived key length, derived validity period and rotation period, derived purpose tag set is fixed as control channel, data channel and management channel, derived key length is 256 bits, derived validity period is 60 seconds, rotation period is 30 seconds, process is to perform derived key generation logic on the above 3 purpose tags in turn, first connect shared key, current timestamp, sum of both node identifiers and purpose sequence number in fixed order, get derived key raw material through 3 rounds of mixing after preset irreversible compression operation, then sequentially cut 256 bits from the start of the raw material as the derived key for this purpose and write it into the derived key configuration together with the validity period and rotation period; step 4, state change detection and running mode adjustment direction determination, parameters are detection window length, window step and change threshold, detection window length is 5 seconds, window step is 1 second, change threshold is 0.2, process is to calculate communication load change rate, topology change rate and task delay change rate in the detection window, communication load change rate is the absolute value of the relative change of the number of sent fragments per second in the window relative to the average value of the window, topology change rate is the proportion of the sum of newly added and left nodes in the window to the current number of nodes, task delay change rate is the absolute value of the relative change of the task completion time in the window relative to the average value of the window, calculate weighted value by weighting 0.4, 0.3 and 0.3, if any single item is no less than 0.2 or the weighted value is no less than 0.2, determine the adjustment direction according to the maximum, the maximum corresponds to the communication load, the direction is to improve throughput, the topology change corresponds to the robustness, the direction is to enhance, the task delay corresponds to the delay, the direction is to reduce, if all three are less than 0.2, the direction is to maintain; step 5, mode optimization and optimized running mode generation, parameters are direction rule table and hard threshold, direction rule table is fixed as taking the larger value between current value and 3 for parallel path redundancy level, taking the smaller value between current value and 0.8 times of it for broadcast period, increasing 20% of current value for task batch processing size when improving throughput; taking the larger value between current value and 3 for parallel path redundancy level, taking the smaller value between current value and 0.9 times of it for location update interval, taking the larger value between current value and 1 for maximum retry times when enhancing robustness; taking the smaller value between current value and 0.8 times of it for handshake timeout, taking the smaller value between current value and 0.8, the smaller value between 8 times, the task batch size is the smaller value between the current value and 10% reduction; keep the time does not change the parameters; the hard threshold is that the broadcast period cannot be less than 50 milliseconds, the parallel path redundancy level cannot be greater than 3, and the maximum number of retries cannot be greater than 6, the processing process is to apply the corresponding rules in the determined direction and replace the out-of-bounds value with the hard threshold when out-of-bounds, and the output is the optimized running mode; the 6th step is mode verification and final running mode determination, the parameters are verification window length, stability consistency threshold and verification retry upper limit, the verification window length is 5 seconds, the stability consistency threshold is 0.9, and the verification retry upper limit is 2, the processing process is to extract mode verification data from the optimized running mode in the verification window, including parameter adoption rate and key indicator improvement rate, the parameter adoption rate is the proportion of the number of parameter items actually adopted by each node to the number of items that should be adopted, and the key indicator improvement rate is the arithmetic average of the communication loss reduction ratio and the task delay reduction ratio. The parameter adoption rate and the key indicator improvement rate are weighted consistency scores with weights of 0.6 and 0.4. When the weighted consistency score is not less than 0.9 and the failure frame count in the verification window is 0, the optimized running mode is confirmed as the final running mode, otherwise, the direction rule is adjusted by half and verified again, with a maximum of 2 retries. If it still fails to meet the standard, it will be rolled back to the dynamic parameter set obtained in the 2nd step and record the reason for failure; the 7th step is state confirmation and running mode identification generation, the parameters are the shortest effective duration and identification composition rule, the shortest effective duration is 1 second, and the identification composition rule is to splice 3 segments of digital code, representing running mode type, last 3 digits of effective timestamp and parallel path redundancy level respectively, wherein the encoding 100 represents keeping, the encoding 200 represents improving throughput, the encoding 300 represents enhancing robustness, and the encoding 400 represents reducing latency. The processing process is to generate the identification immediately after the final running mode is determined and write the effective timestamp and the shortest effective duration, and output the UAV group running state as having taken effect and continuously monitor in the subsequent distribution period. If any period has a failure frame count greater than 0 or a parameter adoption rate less than 0.8, trigger rollback and return to the 2nd step to re-evaluate. The time freshness threshold is 1 second and the missing tolerance is 0 to ensure data reliability, the applicability threshold is the greater value of the lower quartile of the baseline segment and 0.7 or fixed at 0.7 when there is no baseline to ensure that the dynamic parameter set is only enabled in a stable background, the cooperative work parameter base value is written in the parameter table before the task starts and remains unchanged for 1 task period, the mapping of communication stability, delay bearing degree and failure risk degree adopts segmented linear and limiting to ensure reproducibility, the detection window is 5 seconds and the change threshold is 0.2 to balance sensitivity and anti-jitter, the direction rule table and the hard threshold ensure the clear boundaries of parameter adjustment, the verification window is 5 seconds, the stability consistency threshold is 0.9, and the verification retry upper limit is 2 to ensure that the final mode is stable and reliable, the shortest effective duration is 1 second, and the digital identification rule ensures that the state can be traced.
[0037] The input of the application includes position coordinate data, signal strength data and acceleration sensor data collected by the unmanned aerial vehicle node in real time. The output part is a shared key, a derived key configuration, a negotiation success state and an optimized unmanned aerial vehicle group operation mode.
[0038] While embodiments of the application have been shown and described, it is to be understood that the embodiments described are only by way of example and that modifications, changes, substitutions and variations can be made by those skilled in the art without departing from the spirit and principles of the application, the scope of which is defined by the claims and their equivalents.
Claims
1. A PUF-based mutual authentication and key agreement method for a UAV swarm, characterized in that, The application relates to a method for realizing adaptive cooperative work of a UAV group, which comprises the following steps: S1, obtaining changed data by real-time monitoring of UAV node position coordinate tracking and connection signal strength, detecting state change of node moving speed by position deviation calculation and connection interruption record to obtain a position coordinate tracking sequence after data synchronization update; S2, clustering data points of the position coordinate tracking sequence by using a K-Means clustering algorithm, and processing connection interruption records by center point iteration and distance measurement calculation to obtain a change vector grouping under a group quantity setting; S3, evaluating the communication quality fluctuation degree caused by the node moving speed according to the change vector grouping, and starting signal strength analysis to obtain a fluctuation quantization index if the fluctuation degree exceeds a preset threshold; S4, updating a trust chain model by using the fluctuation quantization index, and preliminarily verifying the position deviation calculation of the affected node by using an elliptic curve encryption mechanism to determine a trust chain vulnerability level; S5, initializing a re-authentication process according to the trust chain vulnerability level, and extracting identity data from the verification node to obtain an authentication request sequence by combining dynamic trend extraction; S6, combining the authentication request sequence with a key negotiation process, generating a temporary key pair if the sequence contains a newly added node, and obtaining negotiation basic parameters based on clustering convergence judgment; S7, generating a shared key by using a multi-channel random exchange mechanism after obtaining the negotiation basic parameters, and judging a negotiation success state by using negotiation result consistency detection; S8, adjusting adaptive cooperative work parameters according to the negotiation success state, deriving a networking configuration from the shared key, and obtaining an optimized UAV group operation mode by combining state change detection. 2.The PUF-based mutual authentication and key agreement method for UAV swarm according to claim 1, wherein: The S1 comprises the following steps: Collecting position coordinate and signal strength data of the UAV node in real time, obtaining an original data sequence by using a preset sampling frequency; Calculating position coordinate difference values of adjacent time points for the original data sequence, and obtaining a position deviation sequence by using a Euclidean distance formula; If the deviation of a certain time point in the position deviation sequence exceeds a preset threshold, it is determined that the node moving speed has changed, and a speed change marker sequence is generated; Detecting connection interruption events in the signal strength data according to the speed change marker sequence, and obtaining a connection interruption time sequence by using time window analysis; Generating a smooth position coordinate sequence by using a Kalman filtering algorithm according to the connection interruption time sequence and the position deviation sequence, and obtaining a synchronous updated tracking sequence; Calculating the change trend of the coordinate sequence by using sliding window analysis for the synchronous updated tracking sequence, and obtaining a node motion state sequence; Determining the behavior mode of the UAV node in the patrol environment by using clustering analysis according to the node motion state sequence, and obtaining a behavior classification result. 3.The PUF-based mutual authentication and key agreement method for UAV swarm according to claim 1, characterized in that: The S2 comprises the following steps: Grouping the position coordinate sequence by using a K-Means algorithm, and generating a clustering grouping sequence by iteratively calculating the Euclidean distance from data points to center points; If the number of data points in a certain group is lower than a preset threshold, merging the group into the nearest neighbor group, and obtaining an adjusted grouping sequence by using nearest neighbor distance calculation; According to the adjusted grouping sequence, the time distribution of the connection interruption records in each group is counted, and a time window analysis is adopted to obtain an interruption time distribution sequence; According to the interruption time distribution sequence, a density clustering method is adopted to identify the density interruption time region, and an interruption dense time sequence is obtained; According to the interruption dense time sequence, the spatial distribution characteristics of the data points in each group are calculated, and a spatial autocorrelation analysis is adopted to obtain a spatial distribution mode sequence; According to the spatial distribution mode sequence, if the spatial distribution mode of a certain group deviates from a preset mode by more than a threshold value, the group is marked as an abnormal group, and an abnormal group sequence is obtained; According to the abnormal group sequence, a sliding window analysis is adopted to extract the coordinate change trend in the abnormal group, and an abnormal motion trend sequence is obtained. 4.The PUF-based mutual authentication and key agreement method for UAV swarm according to claim 1, characterized in that: The S3 comprises: According to the node moving speed, acceleration sensor data acquisition is adopted to calculate the speed change sequence of each node in the time window, and a speed change vector is obtained; According to the speed change vector, a K-Means clustering algorithm is adopted to group the nodes, and a speed vector grouping sequence is generated; According to the speed vector grouping sequence, the fluctuation amplitude of the communication quality in each group is calculated, and a time-frequency analysis method is adopted to obtain a communication quality fluctuation sequence; If the fluctuation amplitude of the communication quality fluctuation sequence exceeds a preset threshold value, the signal strength data of the corresponding group is extracted, and a signal strength sequence is generated; According to the signal strength sequence, a moving average filtering method is adopted to smooth the time series data, and a smoothed signal strength sequence is obtained; According to the smoothed signal strength sequence, a time series decomposition method is adopted to extract the trend mode, and a communication quality trend sequence is obtained; According to the communication quality trend sequence, the fluctuation quantization index of each group is calculated, and a standard deviation statistical method is adopted to obtain the fluctuation quantization result.
5. The PUF-based mutual authentication and key agreement method for UAV swarm according to claim 1, characterized in that: The S4 comprises: Using the fluctuation quantization index, the time series fluctuation value is obtained from the node communication data, the fluctuation quantization index of each node is calculated, and a fluctuation quantization sequence is obtained; According to the fluctuation quantization sequence, a preset threshold value is compared, if the value of the fluctuation quantization sequence exceeds the preset threshold value, the corresponding node position data is extracted, and an affected node set is determined; According to the affected node set, an elliptic curve encryption mechanism is adopted to encrypt the node position data, and encrypted position deviation data is generated; According to the encrypted position deviation data, the position deviation value of each node is calculated, and a mean square error method is adopted to obtain a deviation calculation accuracy sequence; According to the deviation calculation accuracy sequence, the trust chain model parameter is adjusted through a trust chain model update algorithm, and an updated trust chain model is generated; According to the updated trust chain model, the trust chain vulnerability value of each node is calculated, and a standard deviation statistical method is adopted to determine the vulnerability level value; According to the vulnerability level value, a preset level threshold value is classified, if the vulnerability level value exceeds the preset threshold value, it is marked as a high-risk node, and a high-risk node list is obtained.
6. The PUF-based mutual authentication and key agreement method for UAV swarm according to claim 1, characterized in that: The S5 comprises: Identity data is obtained from the verification node, a physically unclonable function is adopted to generate a node feature code, and a node identity is obtained; According to the node identity, combined with the trust chain level evaluation, a preset threshold value is adopted for vulnerability judgment, and a trust chain vulnerability level is obtained; If the trust chain vulnerability level exceeds the preset threshold, dynamic features are extracted from the node identity, combined with time series analysis, and dynamic trend data is obtained; Using dynamic trend data, generate authentication request sequence, get initial authentication sequence; For the initial authentication sequence, perform sequence optimization processing, use K-means clustering algorithm to group the sequence, and get the optimized authentication sequence; According to the optimized authentication sequence, perform node identity verification, and use support vector machine algorithm for classification to get the verification result; If the verification result shows that the node identity is trustworthy, generate the final authentication request sequence to get the trusted authentication sequence.
7. The PUF-based mutual authentication and key agreement method for UAV swarm according to claim 1, characterized in that: The S6 includes: Obtain the node verification state from the node identification data, use the preset trust evaluation model to judge the trustworthiness of the node, and obtain the node trust level; According to the node trust level, extract the sequence priority from the authentication request sequence, sort the request through the sequence priority, and determine the priority sequence; For the priority sequence, obtain the dynamic parameter adjustment data in the key negotiation process, and if the dynamic parameter adjustment data meets the preset threshold, generate a temporary key pair; Through clustering convergence analysis, optimize the parameters of the temporary key pair to obtain the optimized negotiation base parameters; Extract the node identification data from the optimized negotiation base parameters, and combine the verification state of the newly added node to determine whether to update the key negotiation process and determine the updated negotiation process; According to the updated negotiation process, generate a new authentication request sequence, and output the ordered sequence data.
8. The PUF-based mutual authentication and key agreement method for UAV swarm according to claim 1, characterized in that: The S7 includes: Obtain the negotiation base parameters, use the preset multi-channel allocation strategy to extract the channel allocation data from the parameters, and determine the channel allocation scheme; According to the channel allocation scheme, process the channel allocation data through a random exchange mechanism to generate a temporary shared key; For the temporary shared key, use a consistency detection algorithm to obtain key consistency data and determine the key consistency state; If the key consistency state meets the preset threshold, confirm the validity of the shared key through the result verification logic to obtain the valid shared key; According to the valid shared key, extract state confirmation data from the negotiation success state to determine the final negotiation state; For the final negotiation state, use the state confirmation rule to generate a negotiation completion identifier to determine the end of the negotiation process.
9. The PUF-based mutual authentication and key agreement method for UAV swarm according to claim 1, characterized in that: The S8 includes: Extract state association data from the negotiation success state, use the preset data analysis rule to generate structured state information, and determine the integrity of the state association data; According to the structured state information, use the adaptive adjustment mechanism to update the collaborative work parameters to generate a dynamic parameter set and judge the applicability of the parameter set; If the applicability of the dynamic parameter set meets the preset threshold, extract key derivation data from the shared key through the derived key generation logic to generate a derived key configuration.
10. The PUF-based mutual authentication and key agreement method for UAV swarm according to claim 9, characterized in that: The S8 also includes: For the derived key configuration, use the state change detection algorithm to obtain the running mode change data to determine the adjustment direction of the UAV group running mode; According to the running mode adjustment direction, use the mode optimization rule to update the UAV group running configuration to generate the optimized running mode; The mode verification data is extracted from the optimized operation mode, a consistency detection algorithm is used to judge the stability of the operation mode, and the final operation mode is determined; For the final operation mode, a state confirmation rule is used to generate an operation mode identifier to determine the operation state of the UAV group.
Citation Information
Patent Citations
Method for encrypting communication data chain between unmanned aerial vehicle and ground station
CN104994112A
Anti-quantum-attack unmanned aerial vehicle group identity authentication key negotiation method
CN119421150A
Systems, devices, and methods for signal localization and verification of sensor data
US20200007331A1
Cited By
Equipment authentication method, system and equipment based on industrial internet of things, and medium
CN121530578A
Industrial internet of things based device authentication method, system, device and medium
CN121530578B