UAV-assisted multi-cluster concurrent access and switching authentication method for IoT devices
By introducing a registration process of long-term shared keys and PUF challenge values, combined with a negotiated key mechanism, the security threats and network discontinuity issues in the concurrent access and switching of multiple clusters of UAV-assisted IoT devices are resolved, and secure and efficient multi-cluster concurrent access and switching authentication is achieved.
Patent Information
- Application Number
- CN202411446718.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-16
- Publication Date
- 2025-09-12
- Estimated Expiration
- 2044-10-16
AI Technical Summary
In existing technologies, UAV-assisted multi-cluster IoT device communications face security threats, signaling conflicts, and network service discontinuity. Especially when a large number of devices are accessing and switching concurrently, it is difficult to achieve secure and efficient authentication and switching.
A registration process using a long-term shared key and PUF challenge value, combined with a negotiated key mechanism, ensures the establishment of a secure channel between the UAV and the ground network and IoT device clusters. The shared key is then used for rapid authentication during device switching, enabling concurrent access and switching of multiple clusters.
The system achieves the security and efficiency of concurrent access and switching of multiple clusters of UAV-assisted IoT devices, avoids signaling conflicts, ensures the security of communication data, and is suitable for resource-constrained IoT devices.
Smart Images

Figure CN119325088B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of communication technology, and in particular relates to a UAV-assisted multi-cluster concurrent access and switching authentication method for Internet of Things devices. Background Art
[0002] With the surge in the number of Internet of Things (IoT) devices, network infrastructure needs to rely on a large number of low-cost wireless sensors and energy-constrained nodes to meet the needs of applications such as smart cities, smart agriculture, and industrial smart manufacturing. As these applications become more popular, the requirements for communication systems are also increasing, including higher transmission rates and wider coverage. In this context, unmanned aerial vehicles (UAVs) can expand network coverage due to their flexibility and mobility, connecting IoT devices that are beyond the coverage area to the network, and providing high-reliability, high-throughput, and low-energy green communications. In particular, considering that the future sixth-generation mobile communication system (6G) network will support the access of hundreds of billions of IoT devices, problems such as signaling conflicts and congestion failures at key nodes may arise.
[0003] To address this issue, academics have proposed numerous group leader aggregation schemes. For example, a single group leader aggregates request messages from numerous devices and forwards them to an access point. The group leader can then broadcast responses to all members, effectively reducing signaling overhead. However, when the number of devices is large, single-leader aggregation can still lead to signaling conflicts and group leader congestion failures. To ensure that these massive numbers of devices can access terrestrial networks via UAVs, researchers have proposed the principle of clustering. Multiple clusters exist, each with a large number of members and a cluster head that aggregates and forwards messages within the cluster. Different clusters can simultaneously access orthogonal sub-channels using protocols such as Orthogonal Frequency Division Multiple Access (OFDMA). This allows UAVs to simultaneously assist multiple IoT device clusters in accessing terrestrial networks. However, UAV-assisted multi-cluster IoT device communication models face numerous security and performance challenges. First, because connections between IoT devices and UAVs, and between UAVs and terrestrial networks, are both established over insecure air interfaces, they are vulnerable to eavesdropping, forgery, and man-in-the-middle attacks. Second, IoT devices typically have limited computing and storage capabilities, making them incapable of deploying complex cryptographic algorithms. At the same time, IoT devices are often deployed in unmanned areas, such as suburban and remote areas, making them vulnerable to compromise. Furthermore, when a large number of devices in multiple IoT clusters are simultaneously connected to UAVs, each executing its own authentication mechanism, significant signaling overhead can result, potentially leading to signaling conflicts and congestion at critical nodes. Finally, due to the poor endurance and susceptibility of UAVs to failure, a single UAV cannot guarantee network service continuity. Therefore, new UAVs can be used to replace old ones, necessitating a handover mechanism between IoT devices and both new and old UAVs.
[0004] In summary, it is crucial to study a secure and efficient UAV-assisted multi-cluster concurrent access and handover authentication scheme for IoT devices. Summary of the Invention
[0005] In order to solve the above problems existing in the prior art, the present invention provides a UAV-assisted multi-cluster concurrent access and handover authentication method for IoT devices. The technical problem to be solved by the present invention is achieved through the following technical solutions:
[0006] An embodiment of the present invention provides a UAV-assisted concurrent access and handover authentication method for multiple IoT device clusters, which is applied to a communication system including a terrestrial network, a UAV, and multiple IoT device clusters, each of which includes multiple IoT devices and a gateway. The corresponding method includes:
[0007] Registration process: The UAV and each IoT device cluster register offline through the ground network. A long-term shared key is introduced for the UAV during offline registration through the ground network. A PUF challenge value is introduced for each IoT device cluster during offline registration through the ground network.
[0008] UAV access authentication process: Based on the long-term shared key, the UAV sends an access request message to the ground network. The ground network verifies the access request message sent by the UAV and returns an access response message. The UAV verifies the access response message sent by the ground network to complete the UAV access authentication. During the process, the negotiated key between the UAV and the ground network is calculated to establish a secure channel between the UAV and the ground network.
[0009] The IoT device multi-cluster concurrent access authentication process: The ground network sends the PUF challenge value to each IoT device cluster. Each IoT device cluster calculates the corresponding PUF response value based on the PUF challenge value and sends it to the gateway in the corresponding IoT device cluster. The gateway aggregates all PUF response values and sends them to the UAV. The UAV verifies and further aggregates the PUF response values and sends them to the ground network. The ground network verifies the UAV-aggregated PUF response value to complete the IoT device multi-cluster concurrent access authentication. In the process, the negotiated key between the IoT device in each IoT device cluster, the UAV, and the ground network is calculated to establish a secure channel between the IoT device cluster, the UAV, and the ground network.
[0010] Concurrent switching authentication process of multiple IoT device clusters: When the original UAV is replaced, before the new UAV replaces the original UAV, the original UAV first completes the switching preparation with each IoT device cluster. During the switching preparation process, a ciphertext including the shared key between UAVs and the negotiation key between the IoT devices in each IoT device cluster and the original UAV is generated; subsequently, when the IoT device cluster switches with the new UAV, the IoT device cluster uses the ciphertext generated during the switching preparation process to complete mutual authentication with the new UAV, and the negotiation key between the IoT devices in each IoT device cluster and the new UAV is calculated during the process to establish a secure channel between the IoT device cluster and the new UAV.
[0011] Beneficial effects of the present invention:
[0012] The UAV-assisted multi-cluster concurrent access and switching authentication method for IoT devices proposed in the present invention is a feasible, safe and efficient UAV-assisted multi-cluster concurrent access and switching authentication scheme for IoT devices, which comprehensively considers the registration stage of the communication system, the UAV access authentication stage, the multi-cluster concurrent access authentication stage of IoT devices and the multi-cluster concurrent switching authentication stage of IoT devices. In the registration stage, a long-term shared key is introduced for the UAV, and a PUF challenge value is introduced for each IoT device cluster. Then, in the UAV access verification stage, based on the shared key mechanism, the UAV can securely and efficiently access the ground network. At the same time, the UAV and the ground network share a negotiated key to ensure the security of subsequent communication data between the UAV and the ground network. In the multi-cluster concurrent access authentication stage of IoT devices, based on the PUF mechanism, it can effectively avoid the problems caused by the parallel access of a large number of devices. It can solve the problems of signaling conflicts and key node congestion failures caused by access and transmission, and prevent IoT devices from being threatened by physical attacks, and can ensure the security of IoT devices under the premise of low storage and computing overhead, making it suitable for resource-constrained IoT devices. At the same time, the IoT devices in each IoT device cluster share a negotiated key with the UAV and the ground network to ensure the security of the communication data between the IoT devices in each subsequent IoT device cluster and the UAV and the ground network. When switching to a new UAV in the concurrent switching authentication stage of multiple IoT clusters, based on the shared key between UAVs, multiple clusters of IoT devices can quickly and safely complete the switch with the new UAV. At the same time, the IoT devices in each IoT device cluster share a negotiated key with the new UAV to ensure the security of the communication data between the IoT devices in each subsequent IoT device cluster and the new UAV.
[0013] The present invention will be further described in detail below with reference to the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] Figure 1 Schematic diagram of the communication system architecture of UAV-assisted multi-cluster IoT devices provided by an embodiment of the present invention;
[0015] Figure 2 This is a flow chart of a method for concurrent access and handover authentication of multiple clusters of IoT devices based on UAV assistance, provided by an embodiment of the present invention;
[0016] Figure 3 This is a schematic diagram of the drone access authentication process provided by an embodiment of the present invention;
[0017] Figure 4 This is a schematic diagram of the concurrent access authentication process of multiple clusters of IoT devices provided by an embodiment of the present invention;
[0018] Figure 5 This is a schematic diagram of the concurrent switching authentication process of multiple clusters of IoT devices provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0019] The present invention will be further described in detail below with reference to specific examples, but the embodiments of the present invention are not limited thereto.
[0020] The embodiment of the present invention is based on Figure 1 The communication system framework of multiple IoT devices assisted by UAV is implemented as shown in the figure. The communication system includes a ground network, UAV and multiple IoT device clusters. The IoT device cluster can communicate with the ground network through UAV. Each IoT device cluster mainly includes multiple IoT devices and a gateway. IoT devices are usually installed as sensors, actuators, etc. in various environments. They are responsible for collecting various types of data, such as ambient temperature, humidity, etc., and usually have weak computing and storage capabilities. The gateway is responsible for aggregating data from multiple IoT devices in the IoT device cluster and transmitting this data to the ground network through UAV. UAV acts as a communication device to assist the IoT device cluster to access the ground network. Due to the limited weight and battery capacity of UAV, a single UAV cannot provide continuous network services for the IoT device cluster. When a UAV can no longer provide services, the ground network calls a new UAV to continue providing services. The ground network is responsible for verifying the legitimacy of the UAV and IoT devices. In the following example Figure 2 In the communication system shown, each IoT device in the IoT device cluster and the gateway, the gateway and the UAV, and the UAV and the ground network are generally connected through an insecure air interface channel.
[0021] against Figure 1 Communication system shown, see Figure 2 The embodiment of the present invention provides a UAV-assisted multi-cluster concurrent access and handover authentication method for IoT devices, the method comprising:
[0022] S10. Registration process: The UAV and each IoT device cluster register offline via the ground network. When the UAV registers offline via the ground network, a long-term shared key is introduced for the UAV. When each IoT device cluster registers offline via the ground network, a PUF challenge value is introduced for each IoT device cluster.
[0023] S20, UAV access authentication process: Based on the long-term shared key, the UAV sends an access request message to the ground network. The ground network verifies the access request message sent by the UAV and returns an access response message. The UAV verifies the access response message sent by the ground network to complete the UAV access authentication. In the process, the negotiated key between the UAV and the ground network is calculated to establish a secure channel between the UAV and the ground network.
[0024] S30, IoT device multi-cluster concurrent access authentication process: The ground network sends the PUF challenge value to each IoT device cluster, and each IoT device cluster calculates the corresponding PUF response value based on the PUF challenge value and sends it to the gateway in the corresponding IoT device cluster. The gateway aggregates all PUF response values and sends them to the UAV. The UAV verifies and further aggregates the PUF response values and sends them to the ground network. The ground network verifies the UAV aggregated PUF response value to complete the IoT device multi-cluster concurrent access authentication; and in the process, the negotiation key between the IoT device in each IoT device cluster and the UAV and the ground network is calculated to establish a secure channel between the IoT device cluster, the UAV and the ground network.
[0025] S40. Concurrent switching authentication process for multiple clusters of IoT devices: When the original UAV is replaced, before the new UAV replaces the original UAV, the original UAV first completes the switching preparation with each IoT device cluster. During the switching preparation process, a ciphertext including a shared key between UAVs and a negotiated key between the IoT devices in each IoT device cluster and the original UAV is generated; subsequently, when the IoT device cluster switches with the new UAV, the IoT device cluster uses the ciphertext generated during the switching preparation process to complete mutual authentication with the new UAV, and during the process, the negotiated key between the IoT devices in each IoT device cluster and the new UAV is calculated to establish a secure channel between the IoT device cluster and the new UAV.
[0026] Next, the implementation of the four processes is introduced in detail.
[0027] For ease of explanation, this embodiment of the present invention assumes that there are m IoT device clusters within a UAV coverage area, and each IoT device cluster has n IoT devices. The ground network first completes the communication system configuration. Specifically, the ground network selects a 256-bit random number X as the system master key, a random number GK as the shared key between UAVs in the coverage area, and a secure hash function H(): {0,1} * →{0,1} * , and the symmetric encryption algorithm ENC key (), symmetric decryption algorithm DEC key (), where key is a symmetric key; select a key derivation function KDF() and a physical unclonable function PUF(), where R = PUF(C), and C is the PUF challenge value and R is the PUF response value.
[0028] The specific process of offline registration of the UAV via the ground network in S10 of the embodiment of the present invention includes:
[0029] UAV will identify its ID UAV Send to the ground network;
[0030] The ground network generates a long-term shared key K for the UAV UAV 、Service validity period UAV , and according to ID UAV 、w UAV Calculate the temporary service identifier sID UAV =H(w UAV ,X)⊕ID UAV , and (sID UAV ,w UAV ,K UAV ) is sent to the UAV offline; where X is the system master key pre-selected by the ground network, H() represents the hash function, and ⊕ represents the exclusive OR operation.
[0031] In addition, the ground network also generates a random number GK in advance, uses GK as a shared key between UAVs, and sends (GK) to the UAV offline for switching between the new and old UAVs.
[0032] Furthermore, in S10 of the embodiment of the present invention, the specific process of implementing offline registration of each IoT device cluster through the ground network includes:
[0033] Each IoT device cluster selects an identity (ID GA ) A=1,...,m , ID GA Represents the identity of the Ath IoT device cluster, m represents the number of IoT device clusters in the communication system, and all IoT devices in each IoT device cluster are numbered SN Ai , SN Ai Indicates the number of the i-th IoT device in the A-th IoT device cluster, n indicates the number of IoT devices in the A-th IoT device cluster, according to ID GA and SN Ai Calculate the real identity of the corresponding IoT device as ID Ai =ID GA ||SN Ai , ID Ai Indicates the true identity of the i-th IoT device in the A-th IoT device cluster. For example, the n IoT devices in the A-th IoT device cluster are numbered {1,…,n}, that is, the first IoT device is numbered 1, the second IoT device is numbered 2, and so on, and the n-th IoT device is numbered n.
[0034] The ground network selects a set of PUF challenge values (C A1 ,…,C Al ,…,C AL ) A=1,...,m;l=1,...,L , C Alrepresents the lth PUF challenge value of the Ath IoT device cluster, where L represents the number of PUF challenge values, and sends it to each IoT device in the IoT device cluster;
[0035] Each IoT device in the IoT device cluster calculates a PUF response value (R Ail ) i=1,...,n;l=1,...,L =PUF(C Al ), R Ail represents the PUF response value calculated by the i-th IoT device in the A-th IoT device cluster for the l-th PUF challenge value, PUF() represents a physical unclonable function, and ({C Al ,R Ail} A=1,...,m;i=1,...,n;l=1,...,L ) is sent offline to the ground network.
[0036] The specific process of offline registration of each IoT device cluster through the ground network also includes:
[0037] The ground network stores (ID GA ,(C A1 ,…,C Al ,…,C AL ),(R Ail ) i=1,...,n;l=1,...,L ).
[0038] Furthermore, the UAV access authentication process in S20 of the embodiment of the present invention is as follows: Figure 3 As shown, specifically including:
[0039] The UAV obtains the access number of the ground network this time and calculates the serial number value SQN based on the access number UAV =H(K UAV ||'Access number'), according to SQN UAV Calculate the message authentication code MAC UAV =H(K UAV ||sID UAV ||SQN UAV ||w UAV ) and sends an access request message (sID UAV ,SQN UAV ,MAC UAV ,w UAV ) to the ground network; if the drone is initially accessing, the Access number is 0;
[0040] After receiving the UAV access request message, the ground network first verifies the UAV Is it valid? If so, the ground network decrypts and obtains the UAV's identity. According to ID UAV Find the long-term shared key K corresponding to the UAV UAV ; Then, the ground network checks SQN UAV Is the value valid? If valid, the ground network calculates the local message authentication code XMAC UAV =H(K UAV ||sID UAV ||SQN UAV ||w UAV ) and verify the received message authentication code MAC UAV Is it equal to the local message authentication code XMAC? UAV If they are equal, the ground network calculates the response value XRES for the UAV UAV =H(K UAV ||ID UAV ||SQN UAV ||w UAV ), and calculate the negotiated key K with the UAV UAV-N =KDF(K UAV ||ID UAV ||SQN UAV ); Finally, the ground network increases the number of access times of the UAV Accessnumber by 1 and sends an access response message (XRES UAV ) to the UAV;
[0041] The UAV calculates the local response value RES UAV =H(K UAV ||ID UAV ||SQN UAV ||w UAV ) and verify the received response value XRES UAV Is it equal to the local response value RES? UAV If the verification is successful, the UAV calculates the negotiated key K between it and the ground network. UAV-N =KDF(K UAV ||ID UAV ||SQN UAV ) and increase its access number Accessnumber by 1.
[0042] After the UAV access authentication process, the UAV and the ground network share the negotiated key K UAV-N , to ensure the security of communication data transmission in the communication system.
[0043] In addition, the ground network can update the UAV's temporary service identifier sID regularly or irregularly UAV And the service validity period UAV .
[0044] Furthermore, the embodiment of the present invention S30 IoT device multi-cluster concurrent access authentication process is as follows Figure 4 As shown, specifically including:
[0045] Each gateway in the IoT device cluster discovers a UAV and needs to interact with the ground network through the UAV, then the gateway sends a cluster access request message (ID GA ) to the UAV;
[0046] UAV aggregates cluster access request messages from all gateways and forwards multi-cluster access request messages ({ID GA} A=1,..,m ) to the ground network;
[0047] Ground network according to each ID GA Find the corresponding IoT device cluster information and randomly select a PUF challenge value C Al And a random number RAND, find ID GA The information of each IoT device in the IoT device cluster (ID Ai ,C Al ,R Ail ) and calculate the local message authentication code XMAC corresponding to each IoT device Ai =H(ID Ai ||C Al ||R Ail ||RAND), local response value XRES Ai =H(ID GA ||ID Ai ||C Al ||R Ail ||RAND) and the hashed response value XRES * Ai =H(XRES Ai ||sID UAV ); Then, the ground network sends a multi-cluster access response message (RAND, {ID GA ,C Al ,{XMAC Ai ,XRES Ai *} i=1,..,n} A=1,..,m ) to the UAV;
[0048] UAV broadcast cluster access response message (RAND, {ID GA ,C Al ,{XMAC Ai} i=1,..,n} A=1,..,m ) to all gateways and store locally ({ID GA ,{XRES Ai*} i=1,..,n} A=1,..,m );
[0049] Gateway broadcast access response message (RAND, C Al ,{XMAC Ai} i=1,..,n ) to each IoT device in the corresponding IoT device cluster;
[0050] Each IoT device in the IoT device cluster calculates the corresponding PUF response value R Ail =PUF(C Al ) and local message authentication code MAC Ai =H(ID Ai ||C Al ||R Ail ||RAND) and verify the received message authentication code XMAC Ai Is it equal to the local message authentication code MAC? Ai If the verification is successful, each IoT device in the IoT device cluster calculates the response value RES Ai =H(ID GA ||ID Ai ||C Al ||R Ail ||RAND), and sends an access confirmation message (RES Ai ) to the corresponding gateway; Finally, the negotiated key K between each IoT device in the IoT device cluster and the ground network i-N =KDF(ID Ai ||C Al ||R Ail ||RAND) and the negotiated key K between the UAV and the i-UAV =KDF(sID UAV ||K i-N ), KDF() represents the key derivation function;
[0051] After the gateway receives the corresponding access confirmation message, it calculates the aggregate response value of the corresponding IoT cluster And the hashed aggregate response value At the same time, the flag corresponding to the IoT device cluster RESA Set to 1; then, the gateway will send the cluster access confirmation message Send to UAV;
[0052] After receiving access confirmation response messages from multiple gateways, the UAV responds to each gateway based on the received flag. RESA Select the corresponding response value in local storage Calculate local aggregate response value Verify local aggregate response value Is it equal to the received aggregate response value RES? * A , if it is equal, then the UAV successfully authenticates each IoT device in the IoT device cluster corresponding to the gateway; at the same time, the UAV receives the aggregated response value RES from multiple gateways. A Calculate the aggregate response value RES UAV =RES A=1 ⊕...⊕RES A=m , and send a multi-cluster access confirmation message (RES UAV ,{flag RESA} A=1,..,m ) to the ground network;
[0053] After receiving the multi-cluster access confirmation message, the ground network RESA Select the response value XRES of each IoT device in the corresponding IoT device cluster Ai , calculate the local aggregate response value XRES UAV =(XRES 11 ⊕...⊕XRES 1n )⊕...⊕(XRES m1 ⊕...⊕XRES mn ), verify the received aggregate response value RES UAV Is it equal to the local aggregate response value XRES? UAV If the verification is successful, the ground network calculates the negotiation key K with each IoT device in the corresponding IoT device cluster. i-N =KDF(ID Ai ||C Al ||R Ail ||RAND), and the negotiation key K between each IoT device and the UAV in the corresponding IoT device cluster i-UAV =KDF(sID UAV ||K i-N ); Then, the ground network will negotiate the key K i-UAV Transmitted to the UAV.
[0054] After the IoT device multi-cluster concurrent access authentication process, the IoT devices in each IoT device cluster share the negotiated key K with the UAV. i-UAV , share the negotiated key K with the ground network i-N , to ensure the security of communication data transmission in the communication system.
[0055] Furthermore, the embodiment of the present invention is as follows: Figure 5 As shown, specifically including:
[0056] Before the handover is triggered, each IoT device cluster must complete handover preparations with the original UAV, including:
[0057] The original UAV calculates the symmetric key TK for each IoT device in the IoT device cluster corresponding to the gateway Ai =H(GK||ID GA ||sID UAV1 ||ID Ai ), GK represents a random number pre-generated by the ground network as a shared key between UAVs, sID UAV1 Indicates the temporary service identifier of the original UAV and uses the symmetric key TK Ai Calculate ciphertext Ai =ENC TKAi (H(K i-UAV ||ID Ai ||sID UAV1 )), ENC TKAi () indicates the use of symmetric key TK Ai Then, the original UAV sends a cluster switching preparation notification message ({ID GA ,{Cipher Ai} i=1,..,n} A=1,..,m ) to the corresponding gateway;
[0058] The gateway will send the switch preparation notification message ({Cipher Ai} i=1,..,n} A=1,..,m ) broadcast to each IoT device in the corresponding IoT device cluster;
[0059] Each IoT device in the IoT device cluster saves the corresponding (Cipher Ai );
[0060] After the handover is triggered, the gateway completes the handover between the physical network device in the IoT device cluster and the new UAV. The handover authentication process includes:
[0061] The new UAV generates a random number RAND1 and broadcasts a cluster switching notification message (sID UAV2 ,RAND1) to all gateways, sID UAV2 Indicates the temporary service identifier of the new UAV;
[0062] The gateway generates a random number RAND A And broadcast the switching notification message (sID UAV2 ,RAND1,RAND A ) to each IoT device in the corresponding IoT device cluster;
[0063] The gateway calculates the negotiation key K with the new UAV for each IoT device in the IoT device cluster. i-UAV * =KDF(H(K i-UAV ||ID Ai ||sID UAV1 )||RAND1||RAND A ), and the message authentication code MAC Ai * =H(ID Ai ||K i-UAV * ||RAND1||sID UAV1 ||sID UAV2 ||Cipher Ai ); Subsequently, the gateway sends a switching request message (ID Ai ,MAC Ai * ,Cipher Ai ) is sent to the corresponding gateway;
[0064] After receiving the handover request message, the gateway will Ai Corresponding flag MACA Set to 1 and calculate the aggregate message verification code for each IoT device in the IoT device cluster corresponding to the gateway Then, the gateway sends the cluster switching request message (ID GA ,MAC A * ,sID UAV1 ,RAND A ,flag MACA ,{Cipher Ai} i=1,..,n ) is sent to the new UAV;
[0065] After the new UAV receives cluster switching request messages from multiple gateways, it uses flags to MACA Find the ID of each IoT device in the corresponding IoT device cluster Ai , and calculate the symmetric key TK Ai =H(GK||ID GA ||sID UAV1 ||ID Ai ), and the negotiated key with each IoT device in the corresponding IoT device cluster Indicates the use of symmetric key TK Ai Symmetric decryption algorithm to verify the received message authentication code MAC A *Is it equal to the locally calculated message verification code?
[0066] ||sID UAV1 ||sID UAV2 ||Cipher An ), if the verification is successful, the response value is calculated Finally, the new UAV sends the cluster handover response message ({{XRES Ai *} i=1,..,n} A=1,..,m ) broadcast to all gateways;
[0067] The gateway will switch the response message ({XRES Ai *} i=1,..,n ,flag MACA ) broadcast to each IoT device in the corresponding IoT device cluster;
[0068] Each IoT device in each IoT device cluster calculates a local response value And verify the local response value RES Ai * Is it equal to the received response value XRES? Ai * , if they are equal, the switch is successful.
[0069] After the IoT device multi-cluster concurrent switching authentication process, the IoT devices in each IoT device cluster share the negotiation key K with the new UAV i-UAV * , to ensure the security of communication data transmission in the communication system.
[0070] In summary, the UAV-assisted multi-cluster concurrent access and switching authentication method for IoT devices proposed in the embodiment of the present invention is a feasible, secure and efficient UAV-assisted multi-cluster concurrent access and switching authentication scheme for IoT devices, which comprehensively considers the registration stage of the communication system, the UAV access authentication stage, the multi-cluster concurrent access authentication stage of IoT devices and the multi-cluster concurrent switching authentication stage of IoT devices. In the registration stage, a long-term shared key is introduced for UAV, and a PUF challenge value is introduced for each IoT device cluster. Then, in the UAV access verification stage, based on the shared key mechanism, UAV can access the ground network safely and efficiently. At the same time, UAV and the ground network share a negotiated key to ensure the security of subsequent communication data between UAV and the ground network. In the multi-cluster concurrent access authentication stage of IoT devices, based on the PUF mechanism, it can effectively avoid the risk of being overwhelmed by the sea. It can solve the problems of signaling conflicts and congestion failure of key nodes caused by the concurrent access of a large number of devices, and prevent IoT devices from being threatened by physical attacks, and can ensure the security of IoT devices under the premise of low storage and computing overhead, making it suitable for resource-constrained IoT devices. At the same time, the IoT devices in each IoT device cluster share a negotiation key with the UAV and the ground network to ensure the security of the communication data between the IoT devices in each subsequent IoT device cluster and the UAV and the ground network. When switching to a new UAV in the concurrent switching authentication stage of multiple IoT devices, based on the shared key between UAVs, multiple clusters of IoT devices can quickly and safely complete the switch with the new UAV. At the same time, the IoT devices in each IoT device cluster share a negotiation key with the new UAV to ensure the security of the communication data between the IoT devices in each subsequent IoT device cluster and the new UAV.
[0071] In the description of the present invention, it should be understood that the terms "first" and "second" are used for descriptive purposes only and should not be understood to indicate or imply relative importance or implicitly specify the number of the technical features indicated. Therefore, a feature specified as "first" or "second" may explicitly or implicitly include one or more of the features. In the description of the present invention, "plurality" means two or more, unless otherwise specifically defined.
[0072] Although the present invention is described herein in conjunction with various embodiments, those skilled in the art may understand and implement other variations of the disclosed embodiments by reviewing the specification and accompanying drawings in the process of implementing the claimed invention. In the specification, the word "comprising" does not exclude other components or steps, and "a" or "an" does not exclude multiple components or steps. The fact that certain measures are described in different embodiments does not mean that these measures cannot be combined to produce good results.
[0073] The above is a further detailed description of the present invention in conjunction with specific preferred embodiments, and the specific implementation of the present invention should not be considered to be limited to these descriptions. For those skilled in the art of the present invention, without departing from the concept of the present invention, several simple deductions or substitutions can be made, which should be considered to fall within the scope of protection of the present invention.
Claims
1. A UAV-assisted multi-cluster concurrent access and handover authentication method for IoT devices, characterized in that: Applied to a communication system including a terrestrial network, a UAV, and multiple IoT device clusters, each IoT device cluster including multiple IoT devices and a gateway; the corresponding method includes: Registration process: The UAV and each IoT device cluster register offline through the ground network. A long-term shared key is introduced for the UAV during offline registration through the ground network. A PUF challenge value is introduced for each IoT device cluster during offline registration through the ground network. UAV access authentication process: Based on the long-term shared key, the UAV sends an access request message to the ground network. The ground network verifies the access request message sent by the UAV and returns an access response message. The UAV verifies the access response message sent by the ground network to complete the UAV access authentication. During the process, the negotiated key between the UAV and the ground network is calculated to establish a secure channel between the UAV and the ground network. The IoT device multi-cluster concurrent access authentication process: The ground network sends the PUF challenge value to each IoT device cluster. Each IoT device cluster calculates the corresponding PUF response value based on the PUF challenge value and sends it to the gateway in the corresponding IoT device cluster. The gateway aggregates all PUF response values and sends them to the UAV. The UAV verifies and further aggregates the PUF response values and sends them to the ground network. The ground network verifies the UAV-aggregated PUF response value to complete the IoT device multi-cluster concurrent access authentication. In the process, the negotiated key between the IoT device in each IoT device cluster, the UAV, and the ground network is calculated to establish a secure channel between the IoT device cluster, the UAV, and the ground network. Concurrent switching authentication process of multiple IoT device clusters: When the original UAV is replaced, before the new UAV replaces the original UAV, the original UAV first completes the switching preparation with each IoT device cluster. During the switching preparation process, a ciphertext including the shared key between UAVs and the negotiation key between the IoT devices in each IoT device cluster and the original UAV is generated; subsequently, when the IoT device cluster switches with the new UAV, the IoT device cluster uses the ciphertext generated during the switching preparation process to complete mutual authentication with the new UAV, and the negotiation key between the IoT devices in each IoT device cluster and the new UAV is calculated during the process to establish a secure channel between the IoT device cluster and the new UAV.
2. The UAV-assisted multi-cluster concurrent access and handover authentication method for IoT devices according to claim 1 is characterized in that: The specific process of UAV offline registration through the ground network includes: UAV will identify its ID UAV Send to the ground network; The ground network generates a long-term shared key K for the UAV UAV 、Service validity period UAV , and according to ID UAV 、w UAV Calculate the temporary service identifier sID UAV =H(w UAV ,X)⊕ID UAV , and (sID UAV ,w UAV ,K UAV ) is sent offline to the UAV; where X is the system master key pre-selected by the ground network, H( ) represents the hash function, and ⊕ represents the exclusive-OR operation.
3. The UAV-assisted multi-cluster concurrent access and handover authentication method for IoT devices according to claim 2 is characterized in that: The specific process of offline registration of each IoT device cluster through the ground network includes: Each IoT device cluster selects an identity (ID GA ) A=1,...,m , ID GA Represents the identity of the Ath IoT device cluster, m represents the number of IoT device clusters in the communication system, and all IoT devices in each IoT device cluster are numbered SN Ai , SN Ai Indicates the number of the i-th IoT device in the A-th IoT device cluster, n indicates the number of IoT devices in the A-th IoT device cluster, according to ID GA and SN Ai Calculate the real identity of the corresponding IoT device as ID Ai =ID GA ||SN Ai , ID Ai represents the real identity of the i-th IoT device in the A-th IoT device cluster; The ground network selects a set of PUF challenge values (C A1 ,…,C Al ,…,C AL ) A=1,...,m;l=1,...,L , C Al represents the lth PUF challenge value of the Ath IoT device cluster, where L represents the number of PUF challenge values, and sends it to each IoT device in the IoT device cluster; Each IoT device in the IoT device cluster calculates a PUF response value (R Ail ) i=1,...,n;l=1,...,L =PUF(C Al ), R Ail represents the PUF response value calculated by the i-th IoT device in the A-th IoT device cluster for the l-th PUF challenge value, PUF() represents a physical unclonable function, and ({C Al ,R Ail } A=1,...,m;i=1,...,n;l=1,...,L ) is sent offline to the ground network.
4. The UAV-assisted multi-cluster concurrent access and handover authentication method for IoT devices according to claim 3 is characterized in that: The specific process of offline registration of each IoT device cluster through the ground network also includes: The ground network stores (ID GA ,(C A1 ,…,C Al ,…,C AL ),(R Ail ) i=1,...,n;l=1,...,L ).
5. The UAV-assisted multi-cluster concurrent access and handover authentication method for IoT devices according to claim 2 is characterized in that: The UAV access authentication process specifically includes: The UAV obtains the number of times it accesses the ground network, Accessnumber, and calculates the serial number value SQN based on Accessnumber. UAV =H(K UAV ||'Access number'), according to SQN UAV Calculate the message authentication code MAC UAV =H(K UAV ||sID UAV ||SQN UAV ||w UAV ) and sends an access request message (sID UAV ,SQN UAV ,MAC UAV ,w UAV ) to the ground network; After receiving the UAV access request message, the ground network first verifies the UAV Is it valid? If so, the ground network decrypts it to obtain the UAV's ID. UAV =H(w UAV ,X)⊕sID UAV , according to ID UAV Find the long-term shared key K corresponding to the UAV UAV ; Then, the ground network checks SQN UAV Is the value valid? If valid, the ground network calculates the local message authentication code XMAC UAV =H(K UAV ||sID UAV ||SQN UAV ||w UAV ) and verify the received message authentication code MAC UAV Is it equal to the local message authentication code XMAC? UAV If they are equal, the ground network calculates the response value XRES for the UAV UAV =H(K UAV ||ID UAV ||SQN UAV ||w UAV ), and calculate the negotiated key K with the UAV UAV-N =KDF(K UAV ||ID UAV ||SQN UAV ), KDF() represents the key derivation function; Finally, the ground network increases the access number of the UAV Accessnumber by 1 and sends an access response message (XRES UAV ) to the UAV; The UAV calculates the local response value RES UAV =H(K UAV ||ID UAV ||SQN UAV ||w UAV ) and verify the received response value XRES UAV Is it equal to the local response value RES? UAV If the verification is successful, the UAV calculates the negotiated key K between it and the ground network. UAV-N =KDF(K UAV ||ID UAV ||SQN UAV ) and increase its access number Accessnumber by 1.
6. The UAV-assisted multi-cluster concurrent access and handover authentication method for IoT devices according to claim 5 is characterized in that: After the UAV access authentication process, the UAV and the ground network share the negotiated key K UAV-N , to ensure the security of communication data transmission in the communication system.
7. The UAV-assisted multi-cluster concurrent access and handover authentication method for IoT devices according to claim 3 is characterized in that: The authentication process for concurrent access of multiple IoT device clusters specifically includes: Each gateway in the IoT device cluster discovers a UAV and needs to interact with the ground network through the UAV, then the gateway sends a cluster access request message (ID GA ) to the UAV; UAV aggregates cluster access request messages from all gateways and forwards multi-cluster access request messages ({ID GA } A=1,..,m ) to the ground network; Ground network according to each ID GA Find the corresponding IoT device cluster information and randomly select a PUF challenge value C Al And a random number RAND, find ID GA The information of each IoT device in the IoT device cluster (ID Ai ,C Al ,R Ail ) and calculate the local message authentication code XMAC corresponding to each IoT device Ai =H(ID Ai ||C Al ||R Ail ||RAND), local response value XRES Ai =H(ID GA ||ID Ai ||C Al ||R Ail ||RAND) and the hashed response value Then, the ground network sends a multi-cluster access response message (RAND, {ID GA ,C Al ,{XMAC Ai ,XRES Ai * } i=1,..,n } A=1,..,m ) to the UAV; UAV broadcast cluster access response message (RAND, {ID GA ,C Al ,{XMAC Ai } i=1,..,n } A=1,..,m ) to all gateways and store locally ({ID GA ,{XRES Ai * } i=1,..,n } A=1,..,m ); Gateway broadcast access response message (RAND, C Al ,{XMAC Ai } i=1,..,n ) to each IoT device in the corresponding IoT device cluster; Each IoT device in the IoT device cluster calculates the corresponding PUF response value R Ail =PUF(C Al ) and local message authentication code MAC Ai =H(ID Ai ||C Al ||R Ail ||RAND) and verify the received message authentication code XMAC Ai Is it equal to the local message authentication code MAC? Ai If the verification is successful, each IoT device in the IoT device cluster calculates the response value RES Ai =H(ID GA ||ID Ai ||C Al ||R Ail ||RAND), and sends an access confirmation message (RES Ai ) to the corresponding gateway; Finally, the negotiated key K between each IoT device in the IoT device cluster and the ground network i-N =KDF(ID Ai ||C Al ||R Ail ||RAND) and the negotiated key K between the UAV and the i-UAV =KDF(sID UAV ||K i-N ), KDF() represents the key derivation function; After the gateway receives the corresponding access confirmation message, it calculates the aggregate response value RES of the corresponding IoT cluster A =RES A1 ⊕...⊕RES An And the hashed aggregate response value At the same time, the flag corresponding to the IoT device cluster RESA Set to 1; then, the gateway will send the cluster access confirmation message Send to UAV; After receiving access confirmation response messages from multiple gateways, the UAV responds to each gateway based on the received flag. RESA Select the corresponding response value in local storage Calculate local aggregate response value Verify local aggregate response value Is it equal to the received aggregate response value? If they are equal, the UAV successfully authenticates each IoT device in the IoT device cluster corresponding to the gateway; at the same time, the UAV receives the aggregated response value RES from multiple gateways. A Calculate the aggregate response value RES UAV =RES A=1 ⊕...⊕RES A=m , and send a multi-cluster access confirmation message (RES UAV ,{flag RESA } A=1,..,m ) to the ground network; After receiving the multi-cluster access confirmation message, the ground network RESA Select the response value XRES of each IoT device in the corresponding IoT device cluster Ai , calculate the local aggregate response value XRES UAV =(XRES 11 ⊕...⊕XRES 1n )⊕...⊕(XRES m1 ⊕...⊕XRES mn ), verify the received aggregate response value RES UAV Is it equal to the local aggregate response value XRES? UAV If the verification is successful, the ground network calculates the negotiation key K with each IoT device in the corresponding IoT device cluster. i-N =KDF(ID Ai ||C Al ||R Ail ||RAND), and the negotiation key K between each IoT device and the UAV in the corresponding IoT device cluster i-UAV =KDF(sID UAV ||K i-N ); Then, the ground network will negotiate the key K i-UAV Transmitted to the UAV.
8. The UAV-assisted multi-cluster concurrent access and handover authentication method for IoT devices according to claim 7, characterized in that: After the IoT device multi-cluster concurrent access authentication process, the IoT devices in each IoT device cluster share the negotiated key K with the UAV. i-UAV , share the negotiated key K with the ground network i-N , to ensure the security of communication data transmission in the communication system.
9. The UAV-assisted multi-cluster concurrent access and handover authentication method for IoT devices according to claim 7, characterized in that: The authentication process for concurrent switching of multiple IoT clusters includes: Preparation for the switch includes: The original UAV calculates the symmetric key TK for each IoT device in the IoT device cluster corresponding to the gateway Ai =H(GK||ID GA ||sID UAV1 ||ID Ai ), GK represents a random number pre-generated by the ground network as a shared key between UAVs, sID UAV1 Indicates the temporary service identifier of the original UAV and uses the symmetric key TK Ai Calculate ciphertext Ai =ENC TKAi (H(K i-UAV ||ID Ai ||sID UAV1 )), ENC TKAi () indicates the use of symmetric key TK Ai Then, the original UAV sends a cluster switching preparation notification message ({ID GA ,{Cipher Ai } i=1,..,n } A=1,..,m ) to the corresponding gateway; The gateway will send the switch preparation notification message ({Cipher Ai } i=1,..,n } A=1,..,m ) broadcast to each IoT device in the corresponding IoT device cluster; Each IoT device in the IoT device cluster saves the corresponding (Cipher Ai ); Switching certification work includes: The new UAV generates a random number RAND1 and broadcasts a cluster switching notification message (sID UAV2 ,RAND1) to all gateways, sID UAV2 Indicates the temporary service identifier of the new UAV; The gateway generates a random number RAND A And broadcast the switching notification message (sID UAV2 ,RAND1,RAND A ) to each IoT device in the corresponding IoT device cluster; The gateway calculates the negotiation key K with the new UAV for each IoT device in the IoT device cluster. i-UAV * =KDF(H(K i-UAV ||ID Ai ||sID UAV1 )||RAND1||RAND A ), and the message authentication code MAC Ai * =H(ID Ai ||K i-UAV * ||RAND1||sID UAV1 ||sID UAV2 ||Cipher Ai ); Subsequently, the gateway sends a switching request message (ID Ai ,MAC Ai * ,Cipher Ai ) is sent to the corresponding gateway; After receiving the handover request message, the gateway will Ai Corresponding flag MACA Set to 1 and calculate the aggregate message authentication code MAC of each IoT device in the IoT device cluster corresponding to the gateway A * =MAC A1 * ⊕....⊕MAC An * ; Then, the gateway sends the cluster switching request message (ID GA ,MAC A * ,sID UAV1 ,RAND A ,flag MACA ,{Cipher Ai } i=1,..,n ) is sent to the new UAV; After the new UAV receives cluster switching request messages from multiple gateways, it uses flags to MACA Find the ID of each IoT device in the corresponding IoT device cluster Ai , and calculate the symmetric key TK Ai =H(GK||ID GA ||sID UAV1 ||ID Ai ), and the negotiated key with each IoT device in the corresponding IoT device cluster DEC TKAi () indicates the use of symmetric key TK Ai Symmetric decryption algorithm to verify the received message authentication code MAC A * Is it equal to the locally calculated message authentication code XMAC? A * =H(ID A1 ||K 1-UAV * ||RAND1||sID UAV1 ||sID UAV2 ||Cipher A1 )⊕...⊕H(ID An ||K n-UAV * ||RAND1 ||sID UAV1 ||sID UAV2 ||Cipher An ), if the verification is successful, the response value is calculated Finally, the new UAV sends the cluster handover response message ({{XRES Ai * } i=1,..,n } A=1,..,m ) broadcast to all gateways; The gateway will switch the response message ({XRES Ai * } i=1,..,n ,flag MACA ) broadcast to each IoT device in the corresponding IoT device cluster; Each IoT device in each IoT device cluster calculates a local response value And verify the local response value RES Ai * Is it equal to the received response value XRES? Ai * , if they are equal, the switch is successful.
10. The UAV-assisted multi-cluster concurrent access and handover authentication method for IoT devices according to claim 9, characterized in that: After the IoT device multi-cluster concurrent switching authentication process, the IoT devices in each IoT device cluster share the negotiation key K with the new UAV i-UAV * , to ensure the security of communication data transmission in the communication system.
Citation Information
Patent Citations
Unmanned aerial vehicle identity authentication and key negotiation method based on location password
CN115150828A
Authentication model and authentication method suitable for unmanned aerial vehicle auxiliary terminal access of 5G / 6G network
CN117479167A