Method for secure routing in fanets based on trust mechanism

By combining multidimensional trust evaluation factors and fuzzy comprehensive evaluation method with the AOMDV protocol, a trusted routing path is established, which solves the problems of high computational load, high communication overhead and internal attacks in FANETs, ​​realizes efficient secure routing, improves packet delivery rate and network throughput, and reduces routing overhead and latency.

CN115119280BActive Publication Date: 2025-11-18AIR FORCE UNIV PLA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202210556140.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-05-20
Publication Date
2025-11-18
Estimated Expiration
2042-05-20

AI Technical Summary

Technical Problem

Existing technologies in unmanned aerial vehicle (FANET) networks suffer from problems such as high computational load, high communication overhead, difficulty in key management, and inability to defend against internal attacks. In particular, in highly dynamic and uncertain environments, traditional cryptographic-based schemes cannot effectively defend against internal attacks, and trust-based routing protocols have a single trust evaluation factor and low efficiency in high-speed networks.

Method used

The FANETs security routing method based on trust mechanism is adopted. Through multi-dimensional trust evaluation factors, AHP-DEMTEL weight optimization algorithm and fuzzy comprehensive evaluation method, the direct and indirect trust values ​​of nodes are calculated. Trusted routing paths are established in combination with AOMDV protocol, and malicious nodes are monitored and isolated in real time during data forwarding.

Benefits of technology

It effectively resists black hole and gray hole attacks, reduces the impact of frequent network topology changes, improves packet delivery rate and throughput, reduces routing overhead and average end-to-end latency, and improves network security and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115119280B_ABST
    Figure CN115119280B_ABST
Patent Text Reader

Abstract

The application discloses a kind of FANETs security routing method based on trust mechanism, first, according to the behavior of node, introduce multidimensional trust evaluation factor, and propose the weight optimization algorithm based on AHP-DEMTEL, for trust evaluation factor distribution optimal weight.Then, the nature of node is determined and the reward and punishment coefficient is determined by combining fuzzy comprehensive evaluation method, the credibility of node is calculated, and the trust model based on direct trust between nodes and trusted neighbor node recommendation trust is established.Finally, the trust model is applied to the routing discovery and maintenance process of AOMDV protocol, a trusted routing path is established, and communication security is ensured.Simulation results show that, compared with other related protocols, TAOMDV protocol can not only resist common black hole, grey hole attack, but also reduce the influence of network topology change and link interruption caused by high-speed node movement, effectively improve the network packet delivery rate and throughput.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of communication technology, specifically relating to a FANETs secure routing method based on a trust mechanism. Background Technology

[0002] Flying ad hoc networks (FANETs) are a type of distributed peer-to-peer network. Drones, with their small size, ease of operation, and high speed, can simultaneously act as terminals and routers, with nodes coordinating and sharing information to complete tasks. However, weather conditions, geographical obstacles, and high dynamism lead to rapid changes in network topology and frequent link interruptions. Drones also have limited battery power, storage space, and computing power, making them vulnerable to sleep-prevention attacks that exhaust drone resources and paralyze the network. Furthermore, nodes themselves perform routing and forwarding functions, making internal attacks at the routing layer, such as black holes, gray holes, and flooding, easy to execute and highly destructive.

[0003] In recent years, researchers have proposed many security mechanisms to ensure the security and reliability of routing in mobile ad hoc networks. These mechanisms are mainly divided into cryptographic and non-cryptographic techniques. Cryptographic techniques include symmetric cryptography, asymmetric cryptography, and hashing, while non-cryptographic techniques include trust mechanisms and anomaly detection algorithms. However, both approaches have the following drawbacks:

[0004] Traditional cryptography-based schemes have the following drawbacks: (1) High computational cost, communication overhead, and high latency. (2) Difficult key management. In the open distributed environment of self-organizing networks, the lack of an authoritative management center, even if it exists, will become a trapdoor in the network, and once breached, it will endanger the entire network. (3) Inability to resist internal attacks. When legitimate internal nodes are hijacked by attackers or transformed into malicious nodes, they still retain digital certificates and keys, and can launch internal attacks through a series of verifications.

[0005] Routing protocols based on trust mechanisms select routes based on node behavior and state, rather than the legitimacy of their identity, thus overcoming the shortcomings of the former and achieving lightweight and energy-efficient performance. However, most current trust-based routing protocols are only suitable for low-speed, self-organizing networks with relatively fixed topologies, and suffer from problems such as a single trust evaluation factor and low trust computation efficiency. Summary of the Invention

[0006] To address the issues of high dynamism and uncertainty in FANETs, ​​this invention provides a secure routing method for FANETs based on a trust mechanism.

[0007] The technical solution to achieve the purpose of this invention is as follows:

[0008] The FANETs secure routing method based on a trust mechanism is characterized by the following steps:

[0009] Step 1: Determine the multidimensional trust assessment factors;

[0010] Step 2: Based on the AHP-DEMTEL weight optimization algorithm, assign the optimal weight to each trust evaluation factor;

[0011] Step 3: Use fuzzy comprehensive evaluation method to determine the nature of the nodes and determine the reward and penalty coefficients for direct trust calculation;

[0012] Step 4: Perform direct trust calculation and indirect trust calculation based on Step 2 and Step 3;

[0013] Step 5: Establish an overall trust model based on direct trust between nodes and trusted neighbor node recommendation trust, and calculate the trustworthiness of nodes;

[0014] Step 6: Apply the trust model established in Step 5 to the route discovery and maintenance process of the AOMDV protocol to establish trusted routing paths, thereby achieving secure routing.

[0015] Compared with existing technologies, this method has the following advantages:

[0016] First, based on the characteristics of FANETs, ​​this invention considers the interaction behavior between nodes, determines multiple trust evaluation factors, and proposes a weight optimization algorithm based on AHP-DEMTEL to assign optimal weights to the trust evaluation factors.

[0017] Second, this invention employs fuzzy comprehensive evaluation to rate nodes and assign rewards and penalties. Combining weighted calculations with the reward and penalty results, a direct trust value is obtained. A trust model is then established by integrating the indirect trust values ​​of trusted neighbor nodes.

[0018] Third, this invention applies a trust model to the AOMDV protocol, considering the trustworthiness of the next-hop node during the route discovery phase to establish a trusted routing path; and adds a path alert mechanism to monitor and respond to malicious nodes in real time during data forwarding.

[0019] In summary, the method proposed in this invention reflects the interaction behavior between nodes from multiple perspectives, rationally allocates the weights of trust evaluation factors, and calculates the direct trust of nodes by combining fuzzy comprehensive evaluation. It also considers the indirect trust of other nodes in the network, aggregating the recommended trust of multiple neighboring nodes, thus mitigating the risks of spoofing attacks by the evaluated node and defamation attacks by the recommended node. Malicious nodes are detected and isolated based on trust values, establishing secure and reliable routing paths. This method can reduce the impact of frequent network topology changes, effectively resist black hole and gray hole attacks, and maintain high packet delivery rate and throughput, low routing overhead, and average end-to-end latency. Attached Figure Description

[0020] Figure 1 This is a schematic diagram of the fuzzy membership functions of each evaluation factor; where... Figure 1 (a)-(d) are the fuzzy membership functions of packet forwarding rate, probe packet reception rate, trusted interaction degree and historical trust, respectively;

[0021] Figure 2 This is a schematic diagram of the trust relationship model of the present invention;

[0022] Figure 3 This is a schematic diagram of path trust. Trust evaluation is asymmetric; therefore, path trust is divided into Forward Path Trust (FPT) and Reverse Path Trust (RPT). The former determines whether the source node sends data through the path, while the latter determines whether the destination node receives data from the path.

[0023] Figure 4 This is a schematic diagram of a path alert; malicious node information is released during communication to isolate malicious nodes in a timely manner.

[0024] Figure 5 This diagram illustrates the impact of different numbers of malicious nodes on protocol performance; where... Figure 5 (a)-(d) represent the impact of different numbers of malicious nodes on packet delivery rate, throughput, routing overhead and average end-to-end latency, respectively.

[0025] Figure 6 This diagram illustrates the comparison of protocol performance at different node movement speeds; where... Figure 6 (a)-(d) represent the impact of different node movement speeds on packet delivery rate, throughput, routing overhead, and average end-to-end latency, respectively.

[0026] Figure 7 This is a schematic diagram comparing protocol performance at different simulation time periods; where... Figure 7 (a)-(d) represent the impact of different simulation periods on packet delivery rate, throughput, routing overhead and average end-to-end latency, respectively. Detailed Implementation

[0027] To enable those skilled in the art to better understand the technical solutions of the present invention, the technical solutions of the present invention will be further described below in conjunction with the accompanying drawings and embodiments.

[0028] I. Trust Model

[0029] The foundation and core of trust-based routing strategies lies in the selection of evaluation factors and a reasonable and efficient trust calculation method. The selection of trust evaluation factors must consider two aspects: first, whether the relevant information collection for the indicator is feasible and does not require excessive resources; and second, whether the indicator can accurately reflect the node's state or malicious attack behavior. Therefore, this invention considers both directly observed node behavior trust and indirect neighbor node recommendation trust, employing a weighted average method with optimized weights and a fuzzy comprehensive evaluation method to assess and calculate node trust. The following sections will elaborate on both direct and indirect trust aspects.

[0030] 1. Direct Trust

[0031] (1) Select trust evaluation factors and periodically observe node behavior from different perspectives. This invention introduces four trust evaluation factors: packet forwarding rate, probe packet reception rate, trusted interaction degree, and historical trust. The definitions of each trust evaluation factor are as follows:

[0032] Definition 1 (Packet Forwarding Rate) is the ratio of packets received by the evaluated node from the evaluated node to packets forwarded by the evaluated node.

[0033] Black hole nodes and gray hole nodes often discard data packets instead of forwarding them. These malicious nodes can be identified by detecting their packet forwarding ratio (PFR). The definition of packet forwarding ratio (PFR) is:

[0034]

[0035] Where N RDP N represents the data packets received by the evaluated node from the evaluation node. FDP Forwarded data packets;

[0036] Definition 2 (Probe Packet Reception Rate): Using Hello messages, periodic link probes are performed on each neighbor node to calculate the probability that the probe packet successfully reaches the receiver.

[0037] The probe receive ratio (PRR) reflects the condition of the physical link and its surrounding environment. Its definition is as follows:

[0038]

[0039] Where N(tw,t) is the number of probe packets actually received by the evaluation node within the w time window, τ is the detection period, and w / τ is the theoretical number of probe packets that should be received, i.e. the number of probe packets sent by the evaluated node.

[0040] Definition 3 (Trusted Interaction Degree) refers to the activity level and stability of nodes in a network.

[0041] The more successful interactions a node has with other nodes, especially high-trust nodes, the higher its trustworthiness. The definition of Trusted Interaction (TI) is:

[0042]

[0043] Where L represents the number of trusted nodes that have successfully interacted with the node being evaluated, N represents the number of all other nodes that have successfully interacted with the node being evaluated, and δ is a constant greater than 0. The larger δ is, the faster φ(x) approaches 1.

[0044] Definition 4 (historical trust) refers to the trust value of the node being evaluated in the previous trust calculation period.

[0045] To gain a high trust score, malicious nodes may actively participate in routing and forwarding for a period of time, masquerading as legitimate nodes, and then suddenly launch an attack. If only the behavior of nodes in the current time period is considered, malicious nodes may be mistakenly identified as legitimate nodes, thereby disrupting normal network communication. To accurately assess the trustworthiness of nodes and avoid such situations, their historical trust records (HT) must be considered during the trust calculation process. The definition of HT is as follows:

[0046] HT(t)=T(t-1) (4).

[0047] (2) After selecting the trust evaluation factor, the direct trust of the node is calculated by using the weighted average method of weight optimization and the fuzzy comprehensive evaluation method.

[0048] Based on the above fundamental theories, this invention proposes a weight optimization algorithm based on AHP-DEMTEL to assign optimal weights to trust evaluation factors. The specific steps include:

[0049] Step 1: Determine the multidimensional trust assessment factors;

[0050] Step 2: Based on the AHP-DEMTEL weight optimization algorithm, assign the optimal weight to each trust evaluation factor;

[0051] Step 3: Use the adaptive fuzzy comprehensive evaluation method to determine the nature of the nodes and determine the reward and penalty coefficients for direct trust calculation;

[0052] Step 4: Perform direct trust calculation and indirect trust calculation based on Step 2 and Step 3;

[0053] Step 5: Establish an overall trust model based on direct trust between nodes and trusted neighbor node recommendation trust, and calculate the trustworthiness of nodes;

[0054] Step 6: Apply the trust model established in Step 5 to the route discovery and maintenance process of the AOMDV protocol to establish trusted routing paths, thereby achieving secure routing.

[0055] Furthermore, the specific operational steps of the weight optimization algorithm based on AHP-DEMTEL described in step 2 include:

[0056] Step 21: Based on the impact of each indicator on the network, determine the importance of the trust assessment factors, construct the discriminant matrix A, and use the Analytic Hierarchy Process (AHP) to initially calculate the weight vector W′ of each factor.

[0057] Step 22: Analyze the mutual influence relationships among the evaluation factors and determine the direct influence matrix: Divide the mutual influence relationships among the trust evaluation factors into 5 levels, use the 0-5 scaling method to establish the direct influence matrix B, and perform normalization to obtain the normalized direct influence matrix G:

[0058]

[0059] Among them, b ij This indicates the degree of influence of factor i on j, and m represents the number of factors;

[0060] Step 23: Based on the obtained direct influence matrix G, calculate the comprehensive influence matrix P, the formula of which is:

[0061]

[0062] Where E is the identity matrix, and p is an element in P. ij This indicates the overall influence of factor i on j, and also the overall influence of factor j on i.

[0063] Step 24: Calculate the influence degree D and the degree of being influenced C based on the obtained comprehensive influence matrix P. The calculation formulas for both are as follows:

[0064]

[0065]

[0066] Among them, the influence degree represents the combined influence of each factor on other factors, and this set is denoted as D; the affected degree represents the combined influence of each factor on other factors, and this set is denoted as C.

[0067] Step 25: Calculate the relationship matrix F between the degree of influence and the degree of being influenced using formula (9), and take the diagonal elements of the relationship matrix to form the influence vector f. i Then, the influence weight W″ is obtained by normalization:

[0068] F = D i T ·C i (9)

[0069]

[0070] Step 26: Construct a single-objective optimization model using the equal-weighted linear weighting method and determine the coefficients of the two weights. The expression for this model is:

[0071]

[0072] Step 27: By establishing the Lagrange function and solving for the coefficients α and β of the weights, the functional expression of the Lagrange function is:

[0073]

[0074] Where a ij To determine the elements in matrix A;

[0075] The solution obtained is:

[0076]

[0077] Step 28: Calculate the final weight vector based on the calculated weight coefficients α and β and the weight vectors W′ and W″.

[0078]

[0079] Furthermore, the specific operational steps of step 3 include:

[0080] Step 31: Let the evaluation factor set {packet forwarding rate, link quality, trusted interaction, historical trust} be U = {u1, u2, u3, u4}, and set 3 different evaluation levels {excellent, medium, poor} to form the comment set V = {v1, v2, v3};

[0081] Step 32: Determine the fuzzy membership functions of packet forwarding rate, probe packet reception rate, trusted interaction degree, and historical trust according to formulas (1), (2), (3), and (4). The fuzzy membership functions of packet forwarding rate, probe packet reception rate, trusted interaction degree, and historical trust are shown in the appendix. Figure 1 As shown in (a)-(d);

[0082] Step 33: Based on the fuzzy membership function, calculate the membership degree of each factor to each level, and construct the fuzzy relation R from U to V, which is the comprehensive evaluation matrix and R∈F(U×V):

[0083]

[0084] Where, r ij This represents the membership degree of the i-th evaluation factor, where j=1 is excellent, j=2 is average, and j=3 is poor.

[0085] Step 34: Perform fuzzy transformation based on the obtained fuzzy relation R to obtain a comprehensive evaluation matrix:

[0086]

[0087] The fuzzy transformation yields a comprehensive evaluation:

[0088] Where W∈F(U) is the evaluation factor weight vector, For fuzzy operators;

[0089] Using the M(+,·) operator, we can obtain:

[0090]

[0091] Step 35: Based on the comprehensive evaluation matrix B = {b1, b2, b3} obtained from equations (16) and (17), determine the comprehensive evaluation result of node credibility according to the principle of maximum membership; the reward and punishment coefficients corresponding to the three levels are shown in Table 1:

[0092] Table 1 Reward and Punishment Coefficients

[0093]

[0094] Step 36: Determine the reward and penalty coefficients for direct trust calculation based on the obtained comprehensive credibility evaluation results.

[0095] Furthermore, based on the results obtained above, the direct trust in step 4... The calculation formula is:

[0096]

[0097]

[0098] Where i represents the evaluation node and j represents the node being evaluated. For weighted direct trust, W is the weight, and U is the value of each evaluation factor. The reward and punishment coefficients for weighted direct trust;

[0099] The formula for calculating indirect trust mentioned in step 4 is as follows:

[0100]

[0101] Where θ is the threshold for determining whether a node is trustworthy.

[0102] Direct trust assessment primarily relies on an entity's own experience, which is subjective. However, indirectly utilizing the experience or information of other entities can mitigate the influence of subjective evaluation. Indirect trust refers to the recommendation measure of the trustworthiness of the node being assessed by neighboring nodes. The assessing node only accepts trust recommendations from trusted neighbors. To reduce network communication load and avoid recommendation recursion, thus lowering computational complexity, indirect trust recommendations are only performed between two nodes, without employing a pass-through iterative approach.

[0103] Furthermore, the overall trust model established in step 5 combines direct trust observed by the node with indirect trust observed by neighboring nodes to reliably assess the trustworthiness of the node being evaluated. The final trust relationship model is attached. Figure 2 As shown, the formula for calculating the final trust value using the overall trust model is as follows:

[0104]

[0105] Where ε represents the direct trust weight and η represents the indirect trust weight.

[0106] Each node in the network maintains a neighbor trust table, as shown in Table 2. To distinguish between nodes that maliciously lose packets and those that lose packets due to poor link quality, when the packet forwarding rate is less than 0.6, the node is marked as malicious and added to the blacklist.

[0107] Table 2: Neighbor Trust Table for Node vi

[0108]

[0109] The following is an algorithmic description of the overall trust model:

[0110]

[0111] AOMDV is a multipath routing protocol based on AODV, primarily designed for highly dynamic, self-organizing networks where link failures and route interruptions are frequent. AOMDV reduces the overhead of frequent route discovery initiation and possesses strong fault tolerance and recovery capabilities. Based on the characteristics of FANETs and the aforementioned trust model, this invention proposes a trust-based on-demand multipath distance vector routing protocol (TAOMDV), which considers the trustworthiness of the next-hop node, thereby isolating malicious nodes and establishing trusted paths during the routing process. It includes the following two aspects:

[0112] (1) Routing table design

[0113] First, we define Path Trust (PT) to calculate the trustworthiness of each node on the path. If any node is untrustworthy, the entire path is untrustworthy.

[0114] Definition 5: (Path Trust) is the degree of trustworthiness of a source node in transmitting data through a candidate path.

[0115] Because trust assessment is asymmetric, path trust is divided into forward path trust (FPT) and reverse path trust (RPT). The former determines whether the source node sends data through the path, while the latter determines whether the destination node receives data from the path.

[0116] The formula for calculating path trust PT is:

[0117]

[0118] Among them, v S As the source node, v D For the destination node, v M v K For any two adjacent nodes in the path, T MK Indicates v M For v K Trust value, T KM Indicates v K For v M Trust value;

[0119] As attached Figure 3 As shown, from the source node v S to destination node v D There are two paths, path P1(v S →v A →v B →v C →v D ), path P2(v S →v E →v F →v B →v G →v D Then the forward path trust FPT1 of P1 is min{T}. SA ,T AB ,T BC ,T CD} = 0.88, Reverse Path Trust RPT1 = min{T DC ,T CB ,T BA ,T AS =0.84. Similarly, the forward path trust FPT2 = 0.87 and the reverse path trust RPT2 = 0.8 for P2.

[0120] TAOMDV's routing table adds a path trust field to the original AOMMDV routing table, as shown in Table 3. When establishing a trusted path, it considers hop count, forward path trust, and reverse path trust simultaneously, providing multiple reliable paths for data transmission. Specifically, the broadcast hop count (Advertisedhopcount) represents the maximum number of hops to the destination node; for the same sequence number, the broadcast hop count remains unchanged. The last hop node (Lasthop) represents the node preceding the destination node, distinguishing different paths.

[0121] Table 3 TAOMDV Routing Table

[0122]

[0123]

[0124] (2) Trusted route establishment and maintenance

[0125] First, TAOMDV establishes bidirectional trusted paths during route discovery. The source node first checks its routing table for an available path. If no path exists, it initiates route discovery by broadcasting a route request (RREQ) message to its neighbors. An RPT field is added to the RREQ message, initialized to 1 and updated with each packet transmission. The route reply (RREP) message adds FPT and RPT fields; FPT is initialized to 1 and updated with each packet transmission, while RPT is obtained from the RREQ. The route discovery algorithm is described below.

[0126]

[0127]

[0128] Secondly, TAOMDV's routing maintenance mechanism is similar to AOMDV, adding a Routing Path Alert (RPA) message to publish malicious node information during communication and isolate malicious nodes in a timely manner. The RPA includes the unreachable destination address, sequence number, and last-hop node. Since there are multiple paths to the same destination in the routing table, the last-hop node is used to distinguish different paths. The RPA message format is shown in Table 4.

[0129] Table 4 Path Alarm Messages

[0130]

[0131]

[0132] During data forwarding, the FPT (Fixed Trust Point) is updated simultaneously. When the FPT falls below the trust threshold, it indicates that the next-hop node is untrusted, triggering a path alarm event. RPA (Road Protocol Alarm) unicasts the previous-hop node using the predecessor list in the routing table. When the previous-hop node receives the RPA, it looks up the unreachable destination in the RPA and checks if the Lasthop of the corresponding single path to the unreachable destination in its routing table matches the Lasthop reported by the RPA. If such a path exists, it deletes the relevant path and adds the corresponding unreachable destination to a new RPA. The next hop of the RPA is set to the predecessor node of the Lasthop in the relevant path, and the RPA continues to be sent until the source node receives the RPA, deletes the corresponding path, and selects another trusted path for communication. Because multiple links to the same destination in AOMDV are non-intersecting, changes in the trust of any node on the forwarding path do not affect other backup paths. This mechanism can handle malicious nodes that suddenly appear or are hidden in the path, ensuring efficient and reliable data transmission.

[0133] As attached Figure 4 As shown, assuming a trust threshold of 0.7, the trust requirements for both forward paths are met, and P1 has fewer hops, therefore v S When choosing to transmit data via P1, during data forwarding, v C To launch a malicious attack and discard v B Received data packet. v B v was detected C When the trust value drops below the threshold, a path alarm event is initiated. In the path alarm message, the last forwarding node in the RPA is set to v. C Then v B Send RPA to v via unicast A ,v A Then send to the source node v S v S Path P1 will be deleted. When a new data packet is to be sent, v S Path P2 will be selected.

[0134] Example

[0135] To verify the effectiveness of the routing method proposed in this invention, this invention uses the following four sets of performance indicators to simulate and compare AOMDV, AODV, TAOMDV and TEAOMDV, analyze the advantages of multipath routing protocols in scenarios with high-speed node movement and malicious attacks, and evaluate the performance of trust-based routing protocols.

[0136] 1. Simulation Environment Setup

[0137] The simulation experiment of this invention was completed using the NS2.35 simulator in a Linux system. Fifty UAV nodes were randomly distributed in a simulation area of ​​1500*1500m2, and 15 data connections were started at different times. The specific parameter settings are shown in Table 5.

[0138] Table 5 Parameter Settings

[0139]

[0140] 2. Simulation Results and Analysis

[0141] This experiment was conducted in three scenarios. Each experiment used the same data stream scenario and was run under 10 randomly generated node motion scenarios. The average value was taken as the final experimental result.

[0142] (1) Comparison of protocol performance under different numbers of malicious nodes

[0143] The maximum movement speed of all nodes was set to 10 m / s. The number of malicious nodes was varied, with a 1:1 ratio of black hole nodes to gray hole nodes. Both types of nodes generated false responses during route discovery to deceive the source node into minimizing the hop distance to the destination node. Black hole nodes dropped all received data packets, while gray hole nodes dropped 60% of the received data packets. The experimental results are attached. Figure 5 As shown.

[0144] Depend on Figure 5 (a) It can be seen that when there are no malicious nodes, the packet delivery rate of all four protocols is above 90%, while the packet delivery rate of the two routing protocols using the trust mechanism can reach 95%. This is mainly because they isolate nodes that lose packets due to poor link quality caused by high-speed movement and select other transmission paths with better link quality. As the number of malicious nodes increases, the probability of malicious nodes in the transmission path increases, and the packet delivery rate shows a downward trend. Since AOMDV and AODV do not take any defensive measures, their packet delivery rates are low and decrease significantly, while TAOMDV and TEAOMDV can detect and isolate malicious nodes and select paths with higher trustworthiness, resulting in a smaller decrease in packet delivery rate. Compared with TEAOMDV, TAOMDV's packet delivery rate decreases more steadily and is higher than TEAOMDV. When there are 10 malicious nodes in the network, the packet delivery rate can still remain above 85%, indicating that TAOMDV has higher malicious node detection efficiency and better defense effect.

[0145] Depend on Figure 5(b) It can be seen that AOMMDV and AODV suffer severe packet loss and a sharp decline in network throughput due to attacks from malicious nodes. TAOMDV and TEAOMDV avoid paths with malicious nodes, resulting in lower packet loss rates and smaller throughput declines, far exceeding those of protocols without trust mechanisms, thus mitigating the damage caused by malicious attacks. Among them, TAOMDV is more efficient at detecting malicious nodes, and its network throughput is higher than that of TEAOMDV as the number of malicious nodes increases.

[0146] Depend on Figure 5 (c) It can be seen that the routing overhead increases with the increase in the number of malicious nodes. This is because although the packet loss caused by malicious nodes reduces the number of data packets, the routing control message propagation is also reduced due to the routing spoofing of malicious nodes. The routing overhead of AOMDV is lower than that of AODV because AOMDV has multiple paths and only needs to switch to the backup path when affected by topology changes, while AODV needs to redo the route discovery. Although TAOMDV and TEAOMDV improve the packet delivery rate and reduce packet loss, the routing overhead increases instead. The main reasons are: (1) The trust field is added to the control packet, which increases the number of bytes. (2) More control packets need to be sent to establish a trusted routing path during the route discovery phase. (3) The increase in malicious nodes causes frequent changes in path trust and route maintenance, resulting in increased overhead. The routing overhead of TAOMDV is lower than that of TEAOMDV, which also shows that TAOMDV can detect malicious nodes more accurately, avoid unnecessary path switching and maintenance, and reduce routing overhead.

[0147] Depend on Figure 5 (d) It can be seen that as the number of malicious nodes increases, the average end-to-end latency of AOMDV is relatively stable, while the latency of AODV is much higher than that of AOMDV and is more affected by malicious nodes. After removing malicious nodes from the path, TAOMDV and TEAOMDV need to reselect a trusted route, which may increase the number of hops and thus lead to longer latency. When there are fewer than 6 malicious nodes, the latency of TAOMDV and TEAOMDV is similar. As the number of malicious nodes increases, the latency of TEAOMDV is significantly higher than that of TAOMDV, and it is more susceptible to the influence of malicious nodes, which may cause normal nodes to be misjudged and switch to other paths with higher hop counts. TAOMDV is less affected by malicious nodes, and its latency changes more steadily.

[0148] (2) Comparison of protocol performance at different node movement speeds

[0149] Six malicious nodes were set up, with a 1:1 ratio of black hole nodes to gray hole nodes, and the maximum movement speed of the nodes was varied. The experimental results are as follows: Figure 6 As shown.

[0150] Depend on Figure 6(a) It can be seen that when nodes are stationary, malicious attacks result in low packet delivery rates for AOMDV and AODV. TAOMDV and TEAOMDV isolate malicious nodes, improving packet delivery rates, with TAOMDV's packet delivery rate exceeding 90%. As node movement speed increases, network topology changes become more frequent, increasing the probability of transmission link interruptions, and packet delivery rates continuously decline. TAOMDV's packet delivery rate is consistently higher than TEAOMDV's, indicating that TAOMDV's trust model is more reasonable and its malicious node detection is more accurate. When node movement speed exceeds 20 m / s, TAOMDV's packet delivery rate remains around 85%, because in addition to isolating malicious nodes, it also isolates some nodes that suffer severe packet loss due to topology changes from the network.

[0151] Depend on Figure 6 (b) It can be seen that as the node movement speed increases, packet loss occurs more frequently, and network throughput continuously decreases. TAOMDV and TEAOMDV avoid paths with malicious nodes and nodes with severe packet loss, resulting in more stable communication links and higher packet delivery rates. Although throughput decreases, it still remains above 130kbps. TAOMDV's throughput is significantly higher than TEAOMDV's, mitigating the damage and impact caused by malicious nodes and frequent topology changes.

[0152] Depend on Figure 6 (c) It can be seen that the routing overhead increases with the increase of node movement speed. This is because frequent network topology changes require sending more control packets for route discovery and maintenance, and link interruptions lead to packet loss, further increasing the ratio of control packets to data packets. AODV maintains a single path, making it susceptible to the impact of node movement speed, while AOMDV maintains multiple paths, making it less affected by movement speed and resulting in lower routing overhead than AODV. Although TAOMDV and TEAOMDV improve packet delivery rate, they require sending more routing control packets to establish trusted paths, leading to increased routing overhead. TAOMDV has more accurate malicious node detection, improving packet delivery rate while avoiding sending unnecessary control packets for route maintenance, resulting in lower routing overhead compared to TEAOMDV.

[0153] Depend on Figure 6(d) It is evident that rapid node movement leads to frequent network topology changes. Before AOMDV performs path switching or AODV re-establishes a new path, data packets must wait in the buffer queue, causing the average end-to-end latency to continuously increase. Furthermore, AODV requires even longer to rebuild a new path, resulting in a significantly higher average end-to-end latency than AOMDV. TAOMDV and TEAOMDV choose other reliable paths, which may increase the number of routing hops, leading to even longer latency. Compared to TEAOMDV, TAOMDV establishes more efficient and reliable paths, resulting in a lower average end-to-end latency.

[0154] (3) Comparison of protocol performance under different simulation periods

[0155] Six malicious nodes were set up, with a black hole node to gray hole node ratio of 1:1. The maximum node movement speed was 10 m / s, and the statistical time interval was 20 s. The experimental results are as follows. Figure 7 As shown.

[0156] Depend on Figure 7 (a) It can be seen that in the first 20 seconds, the network topology changes are relatively small, making it easy for malicious nodes to cause damage. As the node positions change, the packet delivery rate decreases. When under malicious attack, the packet delivery rate drops significantly. TAOMDV and TEAOMDV isolate malicious nodes and improve packet delivery rate. In the first 40 seconds, TAOMDV's packet delivery rate is lower than TEAOMDV's. TEAOMDV adds all nodes with low trust values ​​to the blacklist, while TAOMDV only adds detected malicious nodes to the blacklist, temporarily isolating nodes with poor link quality, causing some packets to be dropped due to link interruption. After this, malicious node activity is frequent, and TAOMDV has higher malicious node detection efficiency, with a higher packet delivery rate than TAOMDV and tending to stabilize.

[0157] Depend on Figure 7 (b) It can be seen that in the first 60 seconds, some source nodes did not start sending data, resulting in low throughput and minimal damage from malicious nodes. The throughput of both TAOMDV and TEAOMDV increased to normal levels. After this, the throughput continued to climb, but decreased when subjected to malicious attacks. Due to more frequent node interactions in the network, the destructive power of malicious nodes increased. TAOMDV and TEAOMDV reduced the losses caused by malicious nodes and improved network throughput, with TAOMDV showing a more significant improvement than TEAOMDV.

[0158] Depend on Figure 7(c) It can be seen that in the initial stage of the simulation, the routing overhead is relatively high due to the need to establish paths. After that, only route maintenance and updates are required, and the overhead continuously decreases. Malicious attacks cause a large number of data packets to be dropped, increasing the routing overhead. Routing protocols that incorporate trust mechanisms need to switch trusted paths or re-discover routes, thus incurring significant overhead. In contrast, TAOMDV has higher efficiency in detecting malicious nodes, reducing unnecessary overhead, and has lower routing overhead compared to TAOMDV.

[0159] Depend on Figure 7 (d) It can be seen that the average end-to-end latency of AOMDV remained stable within 5ms throughout the simulation period, while the average end-to-end latency of AODV was significantly higher than that of AODV. In the early stages of the simulation, malicious nodes performed route spoofing during route discovery, leading to an increase in latency. After this, the average end-to-end latency tended to stabilize. TAOMDV and TEAOMDV isolated malicious nodes and selected other trusted forwarding nodes with higher hop counts, resulting in a slight increase in latency. The average end-to-end latency of TAOMDV was lower than that of TEAOMDV, especially in the early stages of the simulation, where the difference was significant. This also indicates that TEAOMDV misjudged some normal nodes, selecting nodes with higher hop counts. While improving packet delivery rate, the improvement in network throughput was similar to that of TAOMDV, but it caused greater unnecessary latency and overhead.

[0160] 3. Experimental Conclusions

[0161] By applying a trust model to the AOMDV protocol, the proposed TAOMDV protocol not only resists malicious attacks and achieves secure communication, but also meets performance requirements. Compared with the TEAOMDV protocol, TAOMDV's trust model is more reasonable, and its malicious node detection is more accurate and efficient. It improves packet delivery rate and network throughput while reducing routing overhead and average end-to-end latency, resulting in superior performance.

[0162] Contents not described in detail in this specification are existing technologies known to those skilled in the art. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or make equivalent substitutions for some of the technical features. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A FANETs secure routing method based on a trust mechanism, characterized in that, Includes the following steps: Step 1: Determine the multidimensional trust assessment factors; Step 2: Based on the AHP-DEMTEL weight optimization algorithm, assign the optimal weight to each trust evaluation factor; Step 3: Use the adaptive fuzzy comprehensive evaluation method to determine the nature of the nodes and determine the reward and penalty coefficients for direct trust calculation; Step 4: Perform direct trust calculation and indirect trust calculation based on Step 2 and Step 3; Step 5: Establish an overall trust model based on direct trust between nodes and trusted neighbor node recommendation trust, and calculate the trustworthiness of nodes; Step 6: Apply the trust model established in Step 5 to the route discovery and maintenance process of the AOMDV protocol to establish trusted routing paths, thereby achieving secure routing; The multidimensional trust evaluation factors mentioned in step 1 include packet forwarding rate, probe packet reception rate, trusted interaction degree, and historical trust, and the definitions of each evaluation factor are as follows: a) Packet forwarding rate, defined as: (1) in, The data packets received by the evaluated node from the evaluation node. Forwarded data packets; b) Probe packet reception rate, defined as: (2) in, To evaluate the node at The number of probe packets actually received within the time window. For the detection period, This represents the theoretically expected number of probe packets to be received, i.e., the number of probe packets sent by the node being evaluated. c) Trustworthy interaction degree, which is defined as: (3) in, L This indicates the number of trusted nodes that successfully interacted with the node being evaluated. N This represents the number of all other nodes that successfully interacted with the node being evaluated. δ is a constant greater than 0; the larger δ is, the higher the number of nodes. The faster it approaches 1; d) Historical trust, defined as follows: (4); The specific operation steps of the weight optimization algorithm based on AHP-DEMTEL described in step 2 include: Step 21: Based on the impact of each indicator on the network, determine the importance of the trust assessment factors and construct a discriminant matrix. A The weight vectors of each factor were initially calculated using the Analytic Hierarchy Process (AHP). ; Step 22: Divide the mutual influence relationships among the trust assessment factors into 5 levels, use the 0-5 scale method to analyze the mutual influence relationships among the trust assessment factors, and determine the direct influence matrix. B The matrix is ​​then normalized to obtain the normalized direct influence matrix. G : (5) in, b ij Indicator Factors i right j The extent of the impact m Indicates the number of factors; Step 23: Based on the obtained direct influence matrix G, Calculate the comprehensive impact matrix P The calculation formula is as follows: (6) in, E It is the identity matrix. P medium elements p ij Indicator Factors i right j The degree of overall impact also indicates the factors j Received i The degree of comprehensive impact; Step 24: Based on the obtained comprehensive influence matrix P Calculate the impact D And the degree of influence C The calculation formulas are as follows: (7) (8); Step 25: Calculate the relationship matrix between influence degree and the degree of influence using formula (9). F Take the diagonal elements of the relation matrix to construct the influence vector. The data is then normalized to obtain the influence weight vector of each factor. : (9) (10); Step 26: Construct an equal-weighted linearly weighted single-objective optimization model and determine the coefficients of the two weights: (11) Step 27: Solve for the coefficients of the weights by establishing a Lagrange function, and the established function is as follows: (12) in, For the discriminant matrix A Middle element; Solving equation (12) yields: (13); Step 28: Based on the calculated weighting coefficients and weight vector and The final weight vector is calculated as follows: (14); Step 3 includes the following specific steps: Step 31: Let the evaluation factor set {packet forwarding rate, link quality, trusted interaction, historical trust} be... There are three different evaluation levels {Excellent, Average, Poor}, which form a set of comments. ; Step 32: Determine the fuzzy membership functions for packet forwarding rate, probe packet reception rate, trusted interaction degree, and historical trust. Step 33: Based on the fuzzy membership function, calculate the membership degree of each factor to each level, and construct... U arrive V Fuzzy Relationship R : (15) in, R For comprehensive evaluation matrix, r ij Indicates the first i Membership degree of each evaluation factor j =1 is considered optimal. j =2 is the middle, j =3 is the difference; Step 34: Based on the obtained fuzzy relations R A fuzzy transformation is performed to obtain a comprehensive evaluation matrix: (16) in, For fuzzy operators, For the evaluation factor weight vector; use The fuzzy comprehensive evaluation vector can be obtained by calculating with the fuzzy operator as follows: (17); Step 35: The comprehensive evaluation matrix obtained from equations (16) and (17) The comprehensive evaluation result of node credibility can be determined based on the principle of maximum membership. Step 36: Determine the reward and penalty coefficients for direct trust calculation based on the obtained comprehensive credibility evaluation results.

2. The FANETs secure routing method based on a trust mechanism according to claim 1, characterized in that, Direct trust as described in step 4 The calculation formula is: (18), (19) Where i represents the evaluation node and j represents the node being evaluated. For weighted direct trust, W is the weight, and U is the value of each evaluation factor. The reward and punishment coefficients for weighted direct trust; Furthermore, the formula for calculating indirect trust mentioned in step 4 is as follows: (20) in, The threshold used to determine whether a node is trustworthy.

3. The FANETs secure routing method based on a trust mechanism according to claim 2, characterized in that, The formula for calculating the final trust value using the overall trust model established in step 5 is as follows: (21) in, Indicates direct trust weight. This indicates the trust weight in the summary.

4. The FANETs secure routing method based on a trust mechanism according to claim 3, characterized in that, Step 6 includes the following specific steps: Step 61: Add hop count and forward path trust to the AOMDV raw routing table FPT and reverse path trust RPT Fields; Step 62: Based on the routing table established in Step 61, complete the establishment of a bidirectional trusted path during the route discovery process; Step 63: Add a routing path alarm message RPA to the AOMDV-based routing maintenance mechanism. Use this path alarm message RPA to publish malicious node information during communication and isolate malicious nodes in a timely manner.

5. The FANETs secure routing method based on a trust mechanism according to claim 4, characterized in that, The specific steps in step 62 include: Step 621: The source node first checks if there is an available path in the routing table. If not, it initiates route discovery and broadcasts a route request RREQ message to neighboring nodes. Step 622: Add the following to the RREQ message RPT Fields, will RPT The value is initialized to 1 and updated as packets are transmitted; Step 623: Add to the RREP (Reply to Routing) message FPT and RPT Fields, FPT Initialized to 1, updated as messages are transmitted, and obtained in RREQ. RPT The value of .

6. The FANETs secure routing method based on a trust mechanism according to claim 5, characterized in that, The specific steps in step 63 include: Step 631: During the data forwarding process, for FPT Update when FPT When the value is below the trust threshold, it indicates that the next hop node is untrusted, triggering a path alarm event; Step 632: The RPA is unicast to the previous hop node using the predecessor list in the routing table. When the previous hop node receives the RPA, it looks up the unreachable destination of the RPA and checks whether the lasthop of the single path to the unreachable destination node in the routing table is the same as the lasthop reported by the RPA. If this type of path exists, the relevant path is deleted, and the corresponding unreachable destination is added to the new RPA. The next hop of the RPA is then set as the predecessor node of the lasthop in the relevant path, and the RPA is sent again until the source node receives the RPA, deletes the corresponding path, and selects another trusted path for communication.