Method for Negotiating Authentication Keys for UAV Swarms Against Quantum Attacks

By combining the grid cryptographic algorithms NTRU, PUF, ECC and ECDH algorithms, and combined with the UAV cluster identity authentication key negotiation method designed by Latin, the problem of difficulty in resisting quantum attacks and reducing computing overhead in the UAV cluster is solved, and efficient and secure identity authentication and key negotiation are achieved.

CN119421150BActive Publication Date: 2025-05-27NAT UNIV OF DEFENSE TECH

Patent Information

Application Number
CN202411554853.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-04
Publication Date
2025-05-27
Estimated Expiration
2044-11-04

AI Technical Summary

Technical Problem

The prior art is difficult to achieve identity authentication key negotiation in a drone swarm that simultaneously combats quantum attacks and lower computing overhead.

Method used

A lightweight drone group identity authentication key negotiation method based on grid cryptography algorithm NTRU, physical non-clone function PUF, elliptic curve cryptography ECC and ECDH algorithm is adopted, and k-round authentication is carried out in combination with Latin-side design to reduce calculation overhead and communication times.

Benefits of technology

It realizes identity authentication and key negotiation that effectively resists quantum attacks in a drone swarm, while reducing computing overhead and communication times, and is suitable for resource-constrained drone environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119421150B_ABST
    Figure CN119421150B_ABST
Patent Text Reader

Abstract

The present invention provides a method for drone swarm identity authentication key negotiation against quantum attacks, comprising the following steps: Step S1: Form 2k drones into a drone swarm, and initialize authentication information for each drone in the drone swarm, where k represents the number of authentication rounds; Step S2: Conduct k rounds of authentication based on Latin square design; in each round of authentication, conduct two-way identity authentication between two drone nodes based on the PUF and NTRU algorithms, and after the two-way identity authentication, conduct key negotiation between the drone nodes based on the ECDH algorithm; Step S3: After k rounds of authentication, obtain the negotiated key of the drone swarm. At the same time, the ability to resist quantum attacks and low computational overhead are ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of unmanned aerial vehicle (UAV) communication, and particularly to a method for authenticating the identity and negotiating keys of a UAV swarm against quantum attacks. Background Art

[0002] UAVs are widely used in fields such as military, logistics, agriculture, and film shooting, and are gradually entering critical infrastructures such as public safety, disaster relief, and intelligent transportation. Network attack events related to UAVs have increased rapidly, the attack means have become increasingly complex, and security issues have become increasingly prominent. Identity authentication and key negotiation protocols play an important role in ensuring the security of communication between UAVs.

[0003] However, due to the particularity of UAV systems, such as limited computing resources, limited storage capacity, and short battery life, traditional identity authentication and key negotiation methods are difficult to directly apply. For this reason, a variety of lightweight solutions have been proposed, which can ensure security while reducing resource consumption. At present, these solutions are mostly based on elliptic curve cryptography (ECC), which is very suitable for resource-constrained devices because of its short keys and high computing efficiency. However, with the development of quantum computing, traditional encryption algorithms such as ECC are facing threats. In particular, the Shor algorithm may break elliptic curve encryption in polynomial time, which means that identity authentication key negotiation methods designed completely based on ECC algorithms may not be able to effectively resist quantum computing attacks in the future.

[0004] In the field of post-quantum cryptography, encryption algorithms based on lattice theory have received extensive attention in recent years. The National Institute of Standards and Technology (NIST) of the United States has selected a variety of lattice-based encryption algorithms as possible future cryptographic standards through its quantum-resistant cryptography standardization project. These algorithms have strong anti-quantum attack capabilities. Among these algorithms, Kyber, NTRU (NTRUEncrypt), etc. are highly regarded candidate solutions. Identity authentication and key negotiation protocols derived from these algorithms, such as Kyber.AKE, can perform well in resisting quantum computing threats.

[0005] However, although these solutions are forward-looking in terms of security, they still have high computational overhead and communication costs, especially in resource-constrained environments. UAV swarms usually have characteristics such as a large number of nodes, limited computing resources, and limited storage capabilities, and cannot use identity authentication key negotiation solutions with large computational overheads. Summary of the Invention

[0006] The present invention proposes a method for authenticating the identity and negotiating keys of a UAV swarm against quantum attacks to solve the technical problem that it is difficult to simultaneously ensure effective resistance to quantum attacks and low computational overhead when authenticating the identity and negotiating keys of a UAV swarm in the prior art.

[0007] To solve the above technical problems, the present invention provides a method for authenticating key negotiation of an unmanned aerial vehicle (UAV) swarm against quantum attacks, including the following steps:

[0008] Step S1: Form 2 k UAVs into a UAV swarm, and initialize the authentication information for each UAV in the UAV swarm, where k represents the number of authentication rounds;

[0009] Step S2: Conduct k rounds of authentication based on Latin square design; in each round of authentication, perform two-way authentication between two UAV nodes based on the PUF and NTRU algorithms, and after the two-way authentication, conduct key negotiation between the UAV nodes based on the ECDH algorithm;

[0010] Step S3: After k rounds of authentication, obtain the negotiated key of the UAV swarm.

[0011] Preferably, in step S1, when the number of UAVs in the UAV swarm is less than 2 k , then supplement 2 k -n as virtual nodes.

[0012] Preferably, in step S1, the authentication information includes:

[0013] {f i , g i , ID i , N, q, p, G, C i};

[0014]

[0015] i where i represents the UAV number; ID represents the identity serial number; N represents the order of the polynomial ring i ; f i and g i represent the private key polynomials, and both f i and g are defined on the polynomial ring of order N; q represents the modulus of the coefficients; p represents the modulus of the private key polynomial of the NTRU algorithm; G represents the base point on the elliptic curve; C i represents the challenge value of UAV i; h i represents the public key polynomial of the i-th UAV; R i represents the result output by the PUF algorithm after the i-th UAV receives the challenge value C i of UAV i.

[0016] Preferably, in step S2, the method for conducting k rounds of authentication based on Latin square design includes: in each round of authentication, the UAV numbered x, UAV xSend the authentication information to the UAV numbered y y ; when x > 2 j-1 , y = x - 2 j-1 , when x ≤ 2 j-1 , y = 2 k +x - 2 j-1 , where j represents the current round of authentication.

[0017] Preferably, step S2 includes:

[0018] Step S21: The UAV x generates a random number r and then calculates r·G to obtain

[0019] Step S22: The UAV x calculates MR according to the following formula x :

[0020]

[0021] Step S23: The UAV x first calculates according to the following formula to obtain and then calculates MK x , and then splices the data to obtain Mes x = MK x ||MR x :

[0022]

[0023] In the formula, H1 and H2 represent mapping functions;

[0024] Step S24: The UAV x generates a random polynomial r x and then uses h y and r x to calculate e from Mes according to the following formula x :

[0025] e x = p×r x ·h x +Me y xmod q; s

[0026] h y = Hash(R y );

[0027] Step S25: The UAV x first calculates HM according to the following formula xy , and then packs the data into M(x, y) = {e x , IDx , HM xy} is sent to the UAV y :

[0028] HM xy = Hmac(hr y , e x || ID x );

[0029] Wherein, Hmac represents the message authentication code algorithm based on the hash function;

[0030] Step S26: The UAV y receives M(x, y) = {e x , ID x , HM xy}, first checks whether ID x corresponds, and then uses the challenge value C y stored in itself to obtain R y through the PUF y () function, then calculates hr y = Hash(R y ), and calculates HM xy . If HM xy is the same as the HM xy in M(x, y), the authentication passes; otherwise, the authentication fails;

[0031] Step S27: The UAV y finds the corresponding hr x = Hash(R x ) according to the received ID x ), and then uses f y , g y to obtain a y and mes x according to the following algorithm;

[0032] a y = f y ·e x mod q;

[0033]

[0034] Step S28: Split mes x into mk x and mr x , then check whether it is the same as hr x . If it is the same, the identity verification passes; otherwise, discard the data packet. After passing the verification, the UAV y will no longer accept the same ID xMessage packet;

[0035] Step S29: Unmanned Aerial Vehicle (UAV) y Calculate And then store Use it as the next round of K y ;

[0036] Step S210: Repeat steps S22 to S29 for k rounds until the authentication is completed.

[0037] Preferably, the expression of the negotiated key obtained in step S3 is:[[]]

[0038]

[0039] In the formula, S represents the number of UAVs, represents the value obtained by calculating r·G through the random number r during the first round of authentication of the UAV numbered i.

[0040] The present invention also provides an electronic device, including: a memory, a processor, and a computer program, where the computer program is stored in the memory and is configured to be executed by the processor to implement the above method.

[0041] The present invention also provides a computer-readable storage medium, in which a computer program is stored, and the computer program is executed by a processor to implement the above method.

[0042] The beneficial effects of the present invention at least include: The present invention proposes a lightweight UAV swarm identity authentication key negotiation method with quantum attack resistance by combining the lattice cryptography algorithm NTRU, the physical unclonable function PUF, the elliptic curve cryptography ECC, and the ECDH algorithm.

[0043] By integrating the lattice cryptography algorithm NTRU with anti-quantum attack and the PUF physical unclonable function, the vulnerability of traditional protocols such as DTLS, which rely on ECC or RSA and are vulnerable to quantum threats, is eliminated. This design ensures that the UAV network can maintain secure communication even in a quantum attack environment, especially its ability to resist quantum attacks in terms of identity authentication and key negotiation. And the Latin square design is adopted to greatly reduce the number of times required for large-scale node authentication in the UAV swarm. At the same time, it ensures the ability to resist quantum attacks and low computational overhead. Brief Description of the Drawings

[0044] Figure 1 It is a schematic flowchart of the method according to an embodiment of the present invention;

[0045] Figure 2 It is a schematic flowchart of the first round of authentication according to an embodiment of the present invention;

[0046] Figure 3 Schematic diagram of the j-th round of authentication in the embodiment of the present invention. Detailed implementation manner

[0047] Next, in combination with the accompanying drawings in the embodiments of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the protection scope of the present invention.

[0048] The present invention realizes two-way identity authentication between UAV nodes based on PUF and NTRU algorithms, draws on the ECDH algorithm to realize key negotiation between nodes, and uses Latin square design to greatly reduce the number of times required for large-scale node authentication in the UAV swarm.

[0049] Specifically, as Figure 1 shown, the embodiment of the present invention provides a method for identity authentication key negotiation of an anti-quantum attack UAV swarm, including the following steps:

[0050] Step S1: Form 2 k UAVs into a UAV swarm, and initialize the authentication information for each UAV in the UAV swarm, where k represents the number of authentication rounds;

[0051] Step S2: Perform k rounds of authentication based on Latin square design; in each round of authentication, perform two-way identity authentication between two UAV nodes based on PUF and NTRU algorithms, and after the two-way identity authentication, perform key negotiation between UAV nodes based on the ECDH algorithm;

[0052] Step S3: After performing k rounds of authentication, obtain the negotiated key of the UAV swarm.

[0053] Step S1 is mainly completed before the UAV swarm takes off, and the specific steps are as follows:

[0054] 1) All UAVs that need to participate in networking will be assigned relevant parameters during the initialization phase. Denote the total number of UAVs participating in networking as S. Taking the UAV UAV i with the number i as an example for illustration, the ground station will generate all f i , g i and h i in this phase, where both f and g are defined on the polynomial ring of order N, f i and g i represent the private key polynomials, and h i represents the public key polynomial of the i-th UAV.

[0055] Transmit the parameters {fi , g i , ID i , N, q, p, G, C i}, parameters Specific functions H1 and H2 are passed to the UAV, and the specific meanings of the parameters are shown in Table 1;

[0056] Table 1

[0057]

[0058]

[0059] 2) UAV i Calculate f separately i The inverses when the modulus is q and p and Ensure and Satisfy the following equations;

[0060]

[0061] 3) UAV i Use the Hash function to calculate The hash value of all R in

[0062] In step S2, after each independent UAV completes parameter initialization with the help of the ground station / control station, then the UAVs perform k rounds of authentication based on the Latin square design and conduct key negotiation. k is the number of rounds required for authentication and is related to the total number of UAVs. In the ideal state, the total number of UAVs is 2 k , in the embodiment of the present invention, if the number of UAVs is less than 2 k Then supplement 2 k -n as virtual nodes.

[0063] In the k-round identity authentication process, the first round of authentication and the j-th round of authentication are as Figure 2 and Figure 3 shown. Specifically, in the j-th round, UAV x Sends M (x,y ) to UAV y , where x > 2 j-1 When, y = x - 2 j-1 , when x ≤ 2 j-1 When, y = 2 k + x - 2 j-1 .

[0064] Based on the PUF and NTRU algorithms, two-way authentication between two UAV nodes is carried out. After two-way authentication, key negotiation between UAV nodes is carried out based on the ECDH algorithm, including the following steps.

[0065] 1) UAV x After temporarily generating a random number r, calculate r·G to obtain Subsequently, use C x as the challenge value to obtain R through the PUF x ( ) function. x .

[0066] 2) UAV x Calculate MR according to the following formula: x , where the value of P should be

[0067] MR x =R x +P.

[0068] 3) UAV x First, calculate according to the following formula to obtain and then calculate MK x . Subsequently, splice the data to obtain Mes x =MK x ||MR x ;

[0069]

[0070] 4) UAV x After generating a random polynomial r x , use h y and r x to calculate e according to the following formula for Mes x ; x ;

[0071] e x =p×r x ·h y +Mes x mod q.

[0072] 5) UAV x First, calculate HM according to the following formula xy . Subsequently, pack the data to be sent to UAV y into M(x, y)={e x , ID x , HM xy} and send it;

[0073] HM xy =Hmac(hr y , ex ||ID x )。

[0074] 6) Unmanned Aerial Vehicle (UAV) y Upon receiving M (x,y) ={x 1 , x 2 , x 3}, first check x 2 ; use the challenge value C stored in itself y to obtain R through the PUF y () function y and then calculate hr y =Hash(R y ), and calculate HM according to the following formula xy . If HM xy is the same as the x x in the information transmitted by UAV 3 , the data integrity check is passed; otherwise, discard the data packet.

[0075] HM xy =Hmac(hr y , x 1 ||x 2 );

[0076] It should be noted that the UAV y needs to generate parameters such as r (x,y) before receiving M x . That is to say, the UAV already has parameters such as r x before receiving M y . (x,y) before receiving M r y and other parameters.

[0077] 7) Unmanned Aerial Vehicle (UAV) y Based on x 2 identify the ID of the sending UAV x and find the corresponding hr x . Subsequently, use f y , g y to obtain a y first according to the following algorithm, and then obtain mes x ;

[0078] a y =f y ·x 1 mod q;

[0079]

[0080] After that, mesx Split into mk x and mr x Check afterwards whether it is the same as hr x If they are the same, the identity verification is passed; otherwise, the data packet is discarded. After passing the verification, the drone will no longer accept message packets with the same ID during this authentication process.

[0081] 8) Unmanned Aerial Vehicle (UAV) y Calculate and store afterwards Take it as the new K y Proceed to the next round;

[0082] It should be noted that only in the first round of authentication does the UAV i need to generate K. In subsequent authentication processes, the K generated in the previous round is used i .

[0083] After k rounds, each UAV obtains as the negotiation key. Taking the UAV 1 when S = 8 as an example, a total of 3 rounds are required. After the first round, the negotiation key of the UAV 1 is:

[0084]

[0085] After the second round, the negotiation key of the UAV 1 is

[0086]

[0087] After the third round, the negotiation key of the UAV 1 is

[0088]

[0089] Compared with widely used identity authentication key negotiation schemes such as DTLS, the embodiment of the present invention reduces the total computational overhead of the identity authentication key negotiation method by borrowing efficient lattice cryptography algorithms (NTRU algorithm), PUF technology, and ECC algorithm, and using algorithms with extremely low computational overhead such as polynomial multiplication, elliptic curve point addition, PUF function, and message authentication code (HMAC algorithm), thereby improving the efficiency. In addition, this method also reduces the communication times by combining Latin square design and elliptic curve cryptography. Usually, the communication times for S UAVs to authenticate and negotiate keys is S×(S - 1)×0.5, while this scheme only requires S×log 2 S. For example, 8 UAVs only require 24 communications, significantly reducing the communication times. It should be noted that the communication times here refer to at least one communication between each pair. If it is a broadcast, it is S 2。

[0090] Meanwhile, the solution of the embodiment of the present invention has extremely high scalability. In addition to being applied to the drone system, it can also meet the needs of Internet of Things (IoT) devices and applications with other lightweight requirements. The architecture of this protocol is flexible, facilitating integration into different types of lightweight terminals, and the protocol parameters can be adjusted according to specific application scenarios to adapt to different performance requirements. Especially in resource-constrained environments such as sensor networks, smart homes, wearable devices, etc., this method can not only provide efficient identity authentication and key negotiation, but also ensure its high security and low communication overhead, making it an ideal solution in IoT applications. This scalability endows the protocol with strong adaptability in a wide range of application scenarios.

[0091] The present invention also provides an electronic device, including: a memory, a processor, and a computer program. The computer program is stored in the memory and is configured to be executed by the processor to implement the above method.

[0092] The present invention also provides a computer-readable storage medium, in which a computer program is stored. The computer program is executed by a processor to implement the above method.

[0093] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. Only the preferred embodiments of the present invention are expressed. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the patent of the present invention. As long as the combination of these technical features does not conflict, it should be considered as within the scope described in this specification.

[0094] It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several modifications and improvements can still be made, and these all belong to the protection scope of the present invention. Therefore, the protection scope of the patent of the present invention should be subject to the appended claims.

Claims

1. A quantum attack-resistant drone swarm identity authentication key negotiation method, characterized by: The following steps are involved: Step S1: k The drones are formed into a drone swarm, and the authentication information is initialized for each drone in the drone swarm, where k represents the number of authentication rounds; Step S2: Perform k rounds of authentication based on Latin square design; in each round of authentication, perform two-way authentication between two drone nodes based on PUF and NTRU algorithms, and after two-way authentication, perform key negotiation between drone nodes based on ECDH algorithm; Step S3: After k rounds of authentication, the negotiation key of the drone group is obtained; In step S1, the authentication information includes: {f i ,g i ,ID i ,N,q,p,G,C i }; Where i represents the drone number; ID i represents the identity sequence number; N represents the polynomial ring The order of i and g i represents the private key polynomial, f i and g i are defined over a polynomial ring of order N q represents the modulus of the coefficient; p represents the modulus of the NTRU algorithm private key polynomial; G represents the base point on the elliptic curve; C i represents the challenge value of drone i; h i represents the public key polynomial of the i-th drone; R i Indicates that the i-th drone receives the challenge value C of drone i i Finally, the result is output by the PUF algorithm; In step S2, the Latin square designs a method for performing k rounds of authentication, including: in each round of authentication, the UAV numbered x x Send the authentication information to the UAV numbered y y ; When x>2 j-1 When y=x-2 j-1 , when x≤2 j-1 When y=2 k +x-2 j -1 , j represents the current authentication round number; Step S2 includes: Step S21: UAV x Generate a random number r and calculate r·G to get Step S22: UAV x MR is calculated according to the following formula x : Step S23: UAV x According to the following formula, we can first calculate Then calculate MK x , and then splice the data to get Mes x =MK x ||MR x : Where H1 and H2 represent mapping functions; Step S24: UAV x Generate a random polynomial r x After that, use h y and r x Mes x According to the following formula, e x : e x =p×r x ·h y +Mes x mod q; h y =Hash(R y ); Step S25: UAV x First calculate HM according to the following formula xy , and then pack the data into M(x, y) = {e x , ID x , H.M. xy }Send to UAV y : HM xy =Hmac(hr y ,e x ||ID x ); Where Hmax represents the message authentication code algorithm based on hash function; Step S26: UAV y Receive M(x, y) = {e x , ID x , H.M. xy } then check the ID first x Whether it corresponds, then use the challenge value C stored by itself y Through PUF y () function to get R y Calculate hr later y =Hash(R y ), and calculate HM xy , if HM xy and M(x, y ) xy If they are the same, the authentication passes, otherwise the authentication fails; Step S27: UAV y Based on the received ID x Find the corresponding hr x =Hash(R x ), then use f y , g y According to the following algorithm, we can get a y andmes x ; a y =f y ·e x mod q; Step S28: mes x Split into mk x With mr x Post-inspection Is it related to hr x If they are the same, the identity verification is passed, otherwise the data packet is discarded. After passing the verification, the UAV y The same ID will no longer be accepted during the authentication process x message package; Step S29: Drone IAV y calculate Post Storage Use it as K for the next round y ; Step S210: repeat steps S22 to S29 until k rounds of authentication are completed; The expression of the negotiated key obtained in step S3 is: In the formula, S represents the number of drones, It indicates the value obtained by calculating r·G using the random number r during the first round of authentication for the drone numbered i.

2. According to the quantum attack-resistant drone swarm identity authentication key negotiation method of claim 1, it is characterized by: In step S1, when the number of drones in the drone group is less than 2 k When 2 k -n rack as a virtual node.

3. An electronic device, comprising: A memory, a processor and a computer program, characterized in that the computer program is stored in the memory and is configured to be executed by the processor to implement the method according to any one of claims 1 to 2.

4. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and the computer program is executed by a processor to implement the method according to any one of claims 1 to 2.

Citation Information

Patent Citations

  • Unmanned aerial vehicle identity authentication and key negotiation method based on location password

    CN115150828A

  • Anti-quantum attack vehicle-ground authentication method and system based on NTRU public key encryption

    CN118102290A

Cited By

  • A Method and System for Unmanned Aerial Vehicle Key Distribution Based on Post-Quantum Cryptography

    CN122578158A