A method and system for lightweight privacy protection authentication of a UAV network

By using a collaborative authentication method between PUF and ground stations in the drone network to generate pseudo-identities and session keys, the problem of private information exposure in the drone network is solved, and efficient and secure communication is achieved.

CN116321148BActive Publication Date: 2026-04-14NANJING UNIV OF POSTS & TELECOMM
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
NANJING UNIV OF POSTS & TELECOMM
Filing Date
2023-02-28
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

Unmanned aerial vehicle (UAV) networks are vulnerable to security attacks in open environments, leading to the exposure of private information and potentially causing major crises, especially during military operations.

Method used

A lightweight authentication method using a Physically Unclonable Function (PUF) and ground station is employed. By registering drones through a secure channel, a pseudo-identity and session key are generated, enabling third-party authentication, avoiding digital signature operations, and improving key negotiation efficiency.

Benefits of technology

It achieves anonymity and traceability of drone identities, while reducing computation time, improving security and communication efficiency, and preventing the leakage of private information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116321148B_ABST
    Figure CN116321148B_ABST
Patent Text Reader

Abstract

The application discloses a kind of unmanned aerial vehicle network lightweight privacy protection authentication method and system, comprising: obtaining initialization system parameter, unmanned aerial vehicle is registered with ground station based on physical unclonable function through secure channel;First unmanned aerial vehicle and second unmanned aerial vehicle complete three-party authentication with ground station by executing authentication algorithm, to realize secure communication session.The application improves the efficiency of key agreement, reduces the operation time, while meeting various security properties also realizes the anonymity and traceability requirements of unmanned aerial vehicle identity.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of identity authentication technology, and in particular to a lightweight privacy protection authentication method and system for unmanned aerial vehicle (UAV) networks. Background Technology

[0002] In recent years, the rapid development of aviation technology has brought about a technological revolution in drones. Currently, drone technology is favored in a range of military and civilian applications, including remote sensing, package delivery, and infrastructure inspection and monitoring. As many governments relax regulations on drone use, interest in this emerging technology is rising, leading to the development of more application areas. Drones typically occupy low-altitude airspace, which is expected to become increasingly densely occupied. Therefore, building an Internet of Drones (IoD), similar to vehicular ad hoc networks (VANETs), will greatly benefit drone traffic management and service quality. Furthermore, drones deployed for services such as package delivery often require autonomous driving, further increasing the strong demand for the IoD. Sharing real-time traffic and airspace information through the Internet of Things enables drone autopilot systems to make safer and more efficient flight plans.

[0003] Because drones are deployed in open environments and their communication with servers is established through insecure channels, they are vulnerable to various security attacks, including man-in-the-middle attacks, replay attacks, eavesdropping attacks, and physical attacks. For example, in military operations, an enemy drone could impersonate a legitimate drone to authenticate itself to a server, potentially causing serious crises such as the leakage of military intelligence. Therefore, security and privacy remain major issues in the drone internet environment. Summary of the Invention

[0004] The purpose of this section is to outline some aspects of embodiments of the present invention and to briefly describe some preferred embodiments. Simplifications or omissions may be made in this section, as well as in the abstract and title of this application, to avoid obscuring the purpose of these documents; however, such simplifications or omissions should not be construed as limiting the scope of the invention.

[0005] In view of the aforementioned existing problems, the present invention is proposed.

[0006] Therefore, this invention provides a lightweight privacy protection authentication method and system for unmanned aerial vehicle (UAV) networks to solve the problem of exposure of private information due to physical capture.

[0007] To solve the above-mentioned technical problems, the present invention provides the following technical solution:

[0008] In a first aspect, the present invention provides a lightweight privacy-preserving authentication method for unmanned aerial vehicle (UAV) networks, comprising the following steps:

[0009] The system parameters are obtained, and the UAV registers with the ground station through a secure channel based on the physically unclonable function.

[0010] The first and second UAVs complete a three-way authentication with the ground station by executing an authentication algorithm, thus achieving a secure communication session.

[0011] As a preferred embodiment of the lightweight privacy protection authentication method for drone networks described in this invention, the drone registers with the ground station through a secure channel by sending CR key-value pairs to the ground station. The ground station generates a pseudo-identity for the drone and stores the CR key-value pairs belonging to the drone in the ground station's database. At the same time, the drone stores the pseudo-identity in its own database.

[0012] As a preferred embodiment of the lightweight privacy protection authentication method for drone networks described in this invention, the first drone and the second drone complete a three-way authentication with the ground station by executing an authentication algorithm. If the authentication is successful, the ground station will update the CR key-value pair of the drone, and at the same time, the ground station and the drone will update the drone's pseudonym for the next authentication.

[0013] As a preferred embodiment of the lightweight privacy protection authentication method for unmanned aerial vehicle (UAV) networks described in this invention, the first UAV and the second UAV complete a three-way authentication with the ground station by executing an authentication algorithm. The two successfully authenticated UAVs can communicate through the session key negotiated during the authentication process, and they can also transmit information to the ground station through the session key between them.

[0014] As a preferred embodiment of the lightweight privacy protection authentication method for drone networks described in this invention, each drone is equipped with a PUF for generating responses. Before deployment, the drone registers with the ground station through a secure channel, and challenge-response pairs (C, R) are generated and securely added to the database of the ground station.

[0015] As a preferred embodiment of the lightweight privacy protection authentication method for drone networks described in this invention, the authentication process generates a session key between drones and a session key between each drone and the ground station in one session, thereby generating three session keys in one session.

[0016] As a preferred embodiment of the lightweight privacy protection authentication method for unmanned aerial vehicle networks described in this invention, the registration specifically includes the following steps:

[0017] drones Generate your own unique And send it to the ground station;

[0018] Ground station received Then, generate random numbers. and for Generate kana Generate a challenge and will Send to ;

[0019] Will Treat it as a challenge to get PUF ,Will Send to the ground station;

[0020] Ground station storage , Just store ;

[0021] in, Let i be the i-th, j-th drone; Represented as The true identity of the person in question; Represented as The katakana; Represented as a secure one-way hash function; Represented as PUF challenge and response key-value pairs; Represented as the XOR operator;

[0022] Secondly, the present invention provides a lightweight privacy protection authentication device for unmanned aerial vehicle (UAV) networks, comprising,

[0023] Thirdly, the present invention provides a computing device, comprising:

[0024] Memory, used to store programs;

[0025] A processor is configured to execute the computer-executable instructions, which, when executed by the processor, implement the steps of the lightweight privacy protection authentication method for unmanned aerial vehicle networks.

[0026] Fourthly, the present invention provides a computer-readable storage medium, comprising: when the program is executed by a processor, the step of implementing the lightweight privacy protection authentication method for unmanned aerial vehicle networks.

[0027] The beneficial effects of this invention are as follows: This invention generates three session keys in one session by executing the authentication algorithm, which improves the efficiency of key negotiation. It avoids the digital signature operation in the traditional authentication process by using the Physically Unclonable Function (PUF), which reduces the computation time. While satisfying various security properties, it also achieves the requirements of anonymity and traceability of drone identity. Attached Figure Description

[0028] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. Wherein:

[0029] Figure 1 This is a schematic diagram of the basic process of a lightweight privacy protection authentication method for unmanned aerial vehicle networks provided in one embodiment of the present invention;

[0030] Figure 2 A basic model diagram of a lightweight privacy protection authentication method for unmanned aerial vehicle networks provided in one embodiment of the present invention;

[0031] Figure 3 Comparative experimental diagram of a lightweight privacy protection authentication method for unmanned aerial vehicle networks provided in one embodiment of the present invention; Detailed Implementation

[0032] To make the above-mentioned objects, features, and advantages of the present invention more apparent and understandable, specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the protection scope of the present invention.

[0033] Many specific details are set forth in the following description in order to provide a full understanding of the invention. However, the invention may also be practiced in other ways different from those described herein, and those skilled in the art can make similar extensions without departing from the spirit of the invention. Therefore, the invention is not limited to the specific embodiments disclosed below.

[0034] Secondly, the term "one embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The phrase "in one embodiment" appearing in different places in this specification does not necessarily refer to the same embodiment, nor is it a single or selective embodiment that is mutually exclusive with other embodiments.

[0035] This invention is described in detail with reference to the schematic diagrams. When detailing the embodiments of this invention, for ease of explanation, the cross-sectional views illustrating the device structure may be partially enlarged, not adhering to the usual scale. Furthermore, the schematic diagrams are merely examples and should not be construed as limiting the scope of protection of this invention. In actual fabrication, the three-dimensional spatial dimensions of length, width, and depth should be included.

[0036] Furthermore, in the description of this invention, it should be noted that the terms "upper," "lower," "inner," and "outer," etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. These terms are used solely for the convenience of describing the invention and for simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on the invention. In addition, the terms "first," "second," or "third" are used for descriptive purposes only and should not be construed as indicating or implying relative importance.

[0037] Unless otherwise explicitly specified and limited, the terms "installation," "connection," and "joining" in this invention should be interpreted broadly. For example, they can refer to fixed connections, detachable connections, or integral connections; similarly, they can refer to mechanical connections, electrical connections, or direct connections, or indirect connections through an intermediate medium, or internal connections between two components. Those skilled in the art can understand the specific meaning of the above terms in this invention based on the specific circumstances.

[0038] Example 1

[0039] Reference Figure 1-2 As an embodiment of the present invention, a lightweight privacy protection authentication method for unmanned aerial vehicle (UAV) networks is provided, comprising:

[0040] like Figure 1 As shown, the present invention comprises two main components: a ground station (GS) and an unmanned aerial vehicle (UAV).

[0041] Ground Station: The ground station possesses the most powerful communication and computing capabilities, responsible for registering drones and assisting two drones in completing authentication. The drone registration process with the ground station must take place over a secure channel. The ground station is completely trusted and unbreakable.

[0042] Each drone is equipped with a Physical Unclonable Function (PUF). The PUF has a 320-bit response value and a 160-bit random number and hash value, which are used to generate the response. Before deployment, the drone registers with the ground station through a secure channel. Challenge-response pairs (C, R) are generated and securely added to the ground station's database.

[0043] S1: Obtain initial system parameters and register the UAV with the ground station through a secure channel based on the physically unclonable function;

[0044] Furthermore, the drone registers with the ground station through a secure channel by sending its CR key-value pair to the ground station. The ground station generates a pseudo-identity for the drone and stores the CR key-value pair belonging to the drone in the ground station's database. At the same time, the drone stores the pseudo-identity in its own database.

[0045] Furthermore, during the registration phase, drones Information needs to be transmitted with the ground station via a secure channel. The registration phase specifically includes the following steps:

[0046] A1: Drone Generate your own unique And send it to the ground station;

[0047] A2: Ground station received Then, generate random numbers. and for Generate kana Generate a challenge and will Send to ;

[0048] A3: Will Treat it as a challenge to get PUF ,Will Send to the ground station;

[0049] A4: Ground station storage , Just store ;

[0050] in, Let i be the i-th, j-th drone; Represented as The true identity of the person in question; Represented as The katakana; Represented as a secure one-way hash function; Represented as PUF challenge and response key-value pairs; Represented as the XOR operator;

[0051] S2: The first and second UAVs complete a three-way authentication with the ground station by executing an authentication algorithm to achieve a secure communication session.

[0052] Furthermore, the first and second drones complete a three-way authentication with the ground station by executing an authentication algorithm. If the authentication is successful, the ground station will update the drone's CR key-value pair, and the ground station and the drone will update the drone's pseudonym for the next authentication.

[0053] Furthermore, the first and second drones complete a three-way authentication with the ground station by executing an authentication algorithm. The two successfully authenticated drones can communicate through the session key negotiated during the authentication process, and they can also transmit information to the ground station through the session key between them.

[0054] Furthermore, during the authentication process, a session key is generated between drones and between each drone and the ground station in a single session, thus generating three session keys in one session.

[0055] Furthermore, in the certification phase, drones With drones Mutual authentication is achieved with the assistance of ground stations. The authentication phase includes the following steps:

[0056] and An authentication request is sent to the ground station. The ground station generates random data A, B, and C, and encrypts this random data using the PUF response value R stored during the registration phase. The encrypted A and B, along with their hash values, are then sent to... And send the encrypted A and C along with their hash values ​​to... ;

[0057] and Use PUF to generate response R, use R to decrypt the data sent by the ground station, and then use the decrypted data to verify the hash. If the hash values ​​are equal, the drone believes that the ground station is a legitimate ground station. Drone A and Drone B also generate random data, encrypt it using R, and send the encrypted data and the hash value of the original data to the ground station.

[0058] The ground station uses R to decrypt the encrypted data sent by the drone and then verifies the hash. If the hash values ​​match, the data is considered safe. and It is a legitimate drone. The ground station and the drone will use the result of the XOR operation of the response R and the encrypted data as the session key to communicate.

[0059] Generate random data, encrypt the random data using data A sent by the ground station, and send it along with the hash value of the random data to drone B;

[0060] Decrypt using data A sent from the ground station. The secret value is sent, and then its hash is verified. If the hash values ​​are equal, then it is believed. It's a legal drone. Then use it. The secret value sent by the sender and the A sent by the ground station are used to construct a session key, and the hash value of the session key is sent to... ;

[0061] Verify the hash value; if the hash values ​​are equal, then... believe It is a legal drone. and They will use a negotiated session key for communication.

[0062] Furthermore, the specific process of executing the authentication algorithm during the authentication phase can be represented as follows:

[0063] B1: Generate random numbers and will Send to .

[0064] B2: Generate random numbers and will Send to the ground station.

[0065] B3: The ground station retrieves data from the database. and Generate random numbers Then the ground station will Divided into , Divided into ,calculate:

[0066]

[0067]

[0068]

[0069]

[0070]

[0071]

[0072]

[0073]

[0074] The ground station will then Send to .

[0075] B4: Challenge Acting on PUF, to obtain ,Will Divided into , ,Will Divided into , ,calculate:

[0076]

[0077]

[0078]

[0079] then calculate If the equation is false, the authentication process terminates. If the equation is true, then... Generate random numbers , ,Will Challenges to be used for the next certification And apply it to PUF to obtain ,calculate:

[0080]

[0081]

[0082]

[0083]

[0084]

[0085]

[0086] Will Send to the ground station, Send to .

[0087] B5: Ground station received ,calculate:

[0088]

[0089]

[0090]

[0091]

[0092] Ground station calculation If the equation holds, then the session key... Will A connection is established with the ground station. The ground station then updates the database. Challenge response ).

[0093] B6: receive After that, the challenge will be Acting on PUF, to obtain And Divided into , ,Will Divided into , .then calculate:

[0094]

[0095]

[0096]

[0097] calculate If the equation holds true, then Generate random numbers Challenges for the next certification ,Will Effects and PUF . Continue calculation:

[0098]

[0099]

[0100]

[0101]

[0102]

[0103]

[0104] calculate If the equation holds true, then calculate:

[0105]

[0106]

[0107] Will Send to the ground station, Send to .

[0108] B7: Ground station received Then, calculate:

[0109]

[0110]

[0111]

[0112]

[0113] Subsequently, the ground station calculated... If the equation holds, then the session key... exist Establish connection with ground stations. Ground station updates. key-value pairs ).

[0114] B8: receive Then, calculate:

[0115]

[0116]

[0117] Subsequently calculate If the equation holds, then the session key... exist and Established between them.

[0118] B9: , Ground station updates kana:

[0119]

[0120]

[0121] in, It is represented as a connector.

[0122] The above is an illustrative scheme of a lightweight privacy protection authentication method for unmanned aerial vehicles (UAVs) networks according to this embodiment. It should be noted that the technical solution of this lightweight privacy protection authentication system for UAVs networks belongs to the same concept as the technical solution of the aforementioned lightweight privacy protection authentication method for UAVs networks. Details not described in detail in the technical solution of the lightweight privacy protection authentication system for UAVs networks in this embodiment can be found in the description of the technical solution of the aforementioned lightweight privacy protection authentication method for UAVs networks.

[0123] This embodiment also provides a lightweight privacy protection authentication system for unmanned aerial vehicle (UAV) networks, including:

[0124] The registration module is used to obtain initial system parameters and enable UAVs based on Physically Unclonable Function (PUF) to register with the ground station through a secure channel.

[0125] The authentication module enables the first and second UAVs to complete three-way authentication with the ground station by executing an authentication algorithm, thus achieving a secure communication session.

[0126] Furthermore, this also includes:

[0127] Memory, used to store programs;

[0128] A processor is used to load the program to execute the lightweight privacy-preserving authentication method for drone networks.

[0129] This embodiment also provides a computer-readable storage medium storing a program that, when executed by a processor, implements the aforementioned lightweight privacy protection authentication method for unmanned aerial vehicle networks.

[0130] The storage medium proposed in this embodiment belongs to the same inventive concept as the lightweight privacy protection authentication method for UAV networks proposed in the above embodiments. Technical details not described in detail in this embodiment can be found in the above embodiments, and this embodiment has the same beneficial effects as the above embodiments.

[0131] Based on the above description of the implementation methods, those skilled in the art can clearly understand that the present invention can be implemented using software and necessary general-purpose hardware, and of course, it can also be implemented using hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as a computer floppy disk, read-only memory (ROM), random access memory (RAM), flash memory, hard disk, or optical disk, etc., including several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods of the various embodiments of the present invention.

[0132] Example 2

[0133] Reference Figure 3 As an embodiment of the present invention, a lightweight privacy protection authentication method for unmanned aerial vehicle networks is provided. To verify its beneficial effects, a comparison of three schemes is provided.

[0134] Figure 3 This paper presents a comparison between the algorithm proposed in this invention and two other lightweight authentication algorithms. Algorithm 1 is a common algorithm based on PUF, and Algorithm 2 is an algorithm based on a fuzzy extractor. As can be clearly seen from the figures, the authentication algorithm proposed in this invention significantly outperforms the other two algorithms. With the increase in the number of drones, the running time of the algorithm proposed in this invention is consistently shorter than that of the other two algorithms. Furthermore, this method can generate three session keys per execution of the authentication algorithm, while Algorithm 1 and Algorithm 2 can only generate one and two session keys, respectively. Therefore, the algorithm proposed in this invention also has a certain advantage in the time required to generate a single session key.

[0135] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.

Claims

1. A lightweight privacy-preserving authentication method for unmanned aerial vehicle (UAV) networks, characterized in that, Includes the following steps: The system parameters are obtained, and the UAV registers with the ground station through a secure channel based on the physically unclonable function. The first and second UAVs complete a three-way authentication with the ground station by executing an authentication algorithm, thus achieving a secure communication session; The authentication process generates a session key between drones and a session key between each drone and the ground station in one session, so that three session keys can be generated in one session; The authentication process includes the following steps: and An authentication request is sent to the ground station. The ground station generates random data A, B, and C, and encrypts this random data using the PUF response value R stored during the registration phase. The encrypted data A and B, along with their hash values, are then sent to the ground station. And send the encrypted A and C along with their hash values ​​to... ; and Use PUF to generate response R, use R to decrypt the data sent by the ground station, and then use the decrypted data to verify the hash. If the hash values ​​are equal, the drone believes that the ground station is a legitimate ground station. Drone A and Drone B also generate random data, encrypt it using R, and send the encrypted data and the hash value of the original data to the ground station. The ground station uses R to decrypt the encrypted data sent by the drone and then verifies the hash. If the hash values ​​match, then the data is trusted. and It is a legitimate drone. The ground station and the drone will use the result of the XOR operation of the response R and the encrypted data as the session key to communicate. Generate random data, encrypt the random data using data A sent by the ground station, and send it along with the hash value of the random data to drone B; Decrypt using data A sent from the ground station. The secret value is sent, and then its hash is verified. If the hash values ​​match, then it is believed. It's a legal drone; then use it. The secret value sent by the sender and the A sent by the ground station are used to construct a session key, and the hash value of the session key is sent to... ; Verify the hash value; if the hash values ​​are equal, then... believe Legal drones; and They will use a negotiated session key for communication.

2. The lightweight privacy protection authentication method for unmanned aerial vehicle networks as described in claim 1, characterized in that: The drone registers with the ground station through a secure channel by sending CR key-value pairs to the ground station. The ground station generates a pseudo identity for the drone and stores the CR key-value pairs belonging to the drone in the ground station's database. At the same time, the drone stores the pseudo identity in its own database.

3. The lightweight privacy protection authentication method for unmanned aerial vehicle networks as described in claim 2, characterized in that: The first and second UAVs complete three-way authentication with the ground station by executing the authentication algorithm. If the authentication is successful, the ground station will update the UAV's CR key-value pair. At the same time, the ground station and the UAV will update the UAV's pseudonym for the next authentication.

4. The lightweight privacy protection authentication method for unmanned aerial vehicle networks as described in claim 3, characterized in that: The first and second UAVs complete three-way authentication with the ground station by executing an authentication algorithm. The two successfully authenticated UAVs communicate through the session key negotiated during the authentication process, and at the same time, they transmit information to the ground station through the session key between them and the ground station.

5. The lightweight privacy protection authentication method for unmanned aerial vehicle networks as described in claim 4, characterized in that: The registration process specifically includes the following steps: drones Generate your own unique And send it to the ground station; Ground station received Then, generate random numbers. and for Generate kana Generate a challenge and will Send to ; Will Treat it as a challenge to get PUF ,Will Send to the ground station; Ground station storage , Just store ; in, , Represented as the first , A drone; Represented as The true identity of the person in question; Represented as The katakana; Represented as a secure one-way hash function; Represented as PUF challenge and response key-value pairs; It is represented as the XOR operator.

6. A lightweight privacy protection authentication device for unmanned aerial vehicle (UAV) networks, characterized in that, The method of claim 1, comprising: The registration module is used to obtain initial system parameters and, based on the physically unclonable function, the UAV registers with the ground station through a secure channel. The authentication module enables the first and second UAVs to complete three-way authentication with the ground station by executing an authentication algorithm, thus achieving a secure communication session.

7. An electronic device, characterized in that, include: Memory, used to store programs; A processor for loading the program to execute the lightweight privacy-preserving authentication method for unmanned aerial vehicle networks as described in any one of claims 1-5.

8. A computer-readable storage medium storing a program, characterized in that, When the program is executed by the processor, it implements the lightweight privacy protection authentication method for unmanned aerial vehicle networks as described in any one of claims 1-5.

Citation Information

Patent Citations

  • Non-human-computer interaction authentication method, device, computer equipment and storage medium

    CN112637845A

  • Unmanned aerial vehicle identity authentication and key negotiation method based on location password

    CN115150828A