A Privacy Protection and Dynamic Certificateless Group Key Agreement Method in UAV Networks
By using a key generation center and a trusted registration agency to generate public and private keys in the drone network, and using a symmetric and asymmetric group key negotiation mechanisms to dynamically update the group keys, the problems of data transmission security and efficiency in the drone network are solved, and efficient and secure data transmission and privacy protection are achieved.
Patent Information
- Application Number
- CN202510252844.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-05
- Publication Date
- 2025-06-03
- Estimated Expiration
- 2045-03-05
AI Technical Summary
How to ensure the security and efficiency of data transmission in a drone network in a highly dynamic and large-scale interactive environment to prevent data leakage, tampering or abuse, especially in multi-device interaction and large-scale dynamic drone groups.
By introducing key generation centers and trusted registration agencies into the drone network, generating public and private keys, building a cryptographic system, and using symmetric and asymmetric group key negotiation mechanisms to dynamically update the group keys to ensure that the key updates when the drone joins or leaves the group.
It realizes efficient and secure data transmission of the drone network, has anonymity, forward and backward security, and temporary information security for known specific sessions, meeting the privacy protection and dynamic certificate-free group key negotiation requirements of the drone network.
Smart Images

Figure CN119743751B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of key negotiation, and in particular to a method for privacy protection and dynamic certificateless group key negotiation in a drone network. Background Art
[0002] With the rapid development of artificial intelligence and the Internet of Things, drones are increasingly widely used in multiple industries, especially in fields such as environmental monitoring, disaster response, and smart cities. Artificial intelligence has enhanced the autonomous decision-making ability of drones, and the Internet of Things enables them to be seamlessly connected to various devices. However, despite the great application potential of drones, they still face limitations in computing power, communication capabilities, and increasingly severe security challenges.
[0003] Drone networks usually face large-scale dynamics and high dispersion. How to ensure secure communication between different devices and drones is a key issue. Existing key management schemes based on public key infrastructure, although able to provide a certain degree of security, cannot meet the requirements of high dynamics and large-scale interactions in drone networks due to the complexity of certificate management and key escrow. In addition, as more devices (such as smartphones, wearable devices) interact with drone networks, how to effectively protect sensitive information, ensure privacy, and prevent identity forgery and data leakage are the core issues that need to be urgently solved in current drone network security. Especially in the interaction of multiple devices and large-scale dynamic drone groups, how to ensure the security and efficiency of data transmission and prevent internal data leakage, tampering, or abuse has become the core issue in improving drone network security. For the privacy protection and secure data interaction problems of drone groups, a method for privacy protection and dynamic certificateless group key negotiation applicable to drone networks is needed. Summary of the Invention
[0004] The purpose of the present invention is to provide a method for privacy protection and dynamic certificateless group key negotiation in a drone network.
[0005] To achieve the above object, the present invention is implemented according to the following technical solution:
[0006] The present invention includes the following steps:
[0007] Generate public and private keys based on a key generation center and a trusted registration authority to construct a drone network cryptographic system;
[0008] The drone obtains a temporary pseudonym and a partial private key to generate a complete key pair;
[0009] Select a group manager and complete symmetric and asymmetric group key negotiation through interaction;
[0010] Generate symmetric group keys and asymmetric group keys for intra-group and inter-group communication respectively;
[0011] When a drone joins or leaves a group, the group key is updated dynamically.
[0012] Furthermore, the key generation center selects an additive cyclic group, a multiplicative cyclic group, and a generator, selects a bilinear pairing operation and a hash function, and generates the system public and private keys;
[0013] The trusted registration authority selects a private key, calculates the public key, and sends it to the key generation center through a secure channel;
[0014] Furthermore, when a drone user registers, the drone receives the system public parameters, selects a secret value, calculates a partial public key, and sends a pseudonym request to the trusted registration authority;
[0015] The trusted registration authority receives the request, checks whether the drone is legal. If it is legal, it calculates a temporary value, sets a temporary pseudonym, and generates a partial private key request to send to the key generation center;
[0016] The key generation center receives the request, selects a random number, calculates a partial public key and a digest value, and generates a partial private key to send back to the drone;
[0017] The drone receives the partial private key reply, verifies it through a hash function. If the verification passes, it generates a complete public and private key pair; otherwise, it requests a pseudonym again.
[0018] Furthermore, during group key negotiation, the group manager initiates a group key negotiation request, generates an identity ring, selects a random number as the group key negotiation identifier, and broadcasts the group key initiation information;
[0019] The group members receive the group key initiation information, select a random number, calculate a random value, and send it to the previous drone through an open channel;
[0020] The group members receive the random number, calculate the digest value and the temporary value, generate a message authentication code, and send the authentication information through an open channel;
[0021] The group manager receives the authentication information, calculates the group key, and broadcasts the group key negotiation information;
[0022] The group members receive the group key negotiation information and generate a symmetric group key and an asymmetric group key.
[0023] Furthermore, the key generation method for the drone to join includes:
[0024] The group manager announces the information of a new group member joining, generates a new identity ring, and broadcasts the group key initiation information;
[0025] The new group member receives the group key initiation information, selects a random number, calculates the random number, and sends it to the previous user through an open channel;
[0026] The group members receive random numbers, calculate the digest values and temporary values, generate message authentication codes, and send the authentication information through the public channel;
[0027] The group manager receives the authentication information, calculates the group key, and broadcasts the group key negotiation information;
[0028] The group members receive the group key negotiation information and generate new symmetric group keys and asymmetric group keys.
[0029] Furthermore, the key generation method when the UAV leaves includes:
[0030] The group manager generates a new identity ring and broadcasts the group key initiation information;
[0031] The group members receive the group key initiation information, select random numbers, and send them to the previous user through the public channel;
[0032] The group members receive random numbers, calculate the digest values and temporary values, generate message authentication codes, and send the authentication information through the public channel;
[0033] The group manager receives the authentication information, calculates the group key, and broadcasts the group key negotiation information;
[0034] The group members receive the group key negotiation information and generate new symmetric group keys and asymmetric group keys.
[0035] Furthermore, the symmetric encryption method includes selecting a timestamp, generating a session key, calculating the ciphertext, and sending the ciphertext data through the public channel;
[0036] Furthermore, the symmetric decryption method includes receiving the ciphertext data, verifying the timestamp, generating the session key, and decrypting the ciphertext data.
[0037] Furthermore, the public key encryption method includes selecting a random number, calculating the random number, selecting a timestamp, calculating the ciphertext, and sending the ciphertext data through the public channel.
[0038] Furthermore, the private key decryption method includes receiving the ciphertext data, verifying the timestamp, and calculating the plaintext data.
[0039] The beneficial effects of the present invention are:
[0040] The present invention supports dynamic key updates when UAVs join or leave through symmetric group key negotiation and asymmetric group key negotiation mechanisms, improves the privacy protection of UAVs, the traceability of malicious UAVs, and has multiple security features such as anonymity, complete forward and backward security, and temporary information security of known specific sessions, and can greatly meet various security requirements of UAV networks.
[0041] By combining the symmetric group key negotiation and the asymmetric group key negotiation mechanisms, the present invention can generate a symmetric group key and an asymmetric group key for an unmanned aerial vehicle (UAV) cluster. The symmetric group key is used to provide efficient and secure communication protection for the members within the UAV group, and the asymmetric group key is used to ensure the transmission security when the group members interact with external devices (such as smart phones, wearable devices, etc.). Secondly, both types of group key negotiation mechanisms support dynamic update of the group key when a UAV joins or leaves the group, ensuring the data transmission security in the high-dynamic and high-mobility environment of the UAV network. More importantly, this method has a privacy protection function, which can effectively prevent data leakage, trace the behavior of malicious UAVs, ensure the anonymity and forward security of data interaction, and meet the high standards of privacy and security requirements of the UAV network. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] Figure 1 It is a schematic diagram of the system model of the privacy protection and dynamic certificateless group key negotiation method in the UAV network of the present invention;
[0043] Figure 2 It is a flow chart of the symmetric group key negotiation of the privacy protection and dynamic certificateless group key negotiation method in the UAV network of the present invention;
[0044] Figure 3 It is a flow chart of the asymmetric group key negotiation of the privacy protection and dynamic certificateless group key negotiation method in the UAV network of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0045] The present invention will be further described below in conjunction with the accompanying drawings and specific embodiments. The illustrative embodiments and descriptions of the present invention are used to explain the present invention, but not to limit the present invention.
[0046] As Figures 1-3 shown, the present invention includes the following steps:
[0047] Generate public and private keys based on a key generation center and a trusted registration authority, and construct a cryptographic system for the UAV network;
[0048] The UAV obtains a temporary pseudonym and a partial private key, and generates a complete key pair;
[0049] Select a group manager, and complete the symmetric and asymmetric group key negotiations through interaction;
[0050] Generate a symmetric group key and an asymmetric group key for intra-group and extra-group communications respectively;
[0051] When a UAV joins or leaves the group, dynamically update the group key.
[0052] It includes a key generation center, a trusted registration authority, and multiple member UAVs , wherein, Represents the true identity identifier of the drone device.
[0053] System initialization phase
[0054] In the system initialization phase, it mainly includes the generation of public and private keys of the key generation center and the trusted registration authority, as well as the generation of system public parameters, to complete the construction of the entire drone network cryptographic system. The specific process is as follows.
[0055] Based on the security parameters , the key generation center selects an additive cyclic group , a multiplicative cyclic group and a generator of the additive cyclic group , where the orders of and are both . After that, the key generation center selects a bilinear pairing operation , 5 hash functions , , , , , and a message authentication code HMAC function , where represents the bit length of the drone identity identifier, and represents the bit length of the symmetric key. After that, the key generation center sends some system public parameters to the trusted registration authority through a secure channel;
[0056] After receiving some system public parameters , the trusted registration authority first selects a random number as its own private key, and calculates as the public key of the trusted registration authority; secondly, the trusted registration authority sends the public key information to the key generation center through a secure channel;
[0057] After receiving the public key information of the trusted registration authority, the key generation center first selects a random number as the main system key and secretly saves it, and calculates as the system public key; finally, the key generation center generates system public parameters , and distributes to all devices in the drone network .
[0058] User registration phase
[0059] In the user registration phase, the drone Through secure interactions with the key generation center and the trusted registration authority, it is possible to obtain the generation of a temporary pseudonym and a partial private key to protect the privacy data of the drone, i.e., the real identity. Finally, the drone generates its own complete key based on its own secret value, as follows.
[0060] Secret value generation
[0061] Drone After receiving the system public parameters randomly selects as the secret value, calculates as its own partial public key, and sends the pseudonym request to the trusted registration authority through a secure channel.
[0062] Pseudonym generation
[0063] After receiving the pseudonym request from the drone the trusted registration authority checks whether it is in the list of legitimate drones. If not, the trusted registration authority discards it directly; otherwise, the trusted registration authority performs the following calculation operations.
[0064] Calculate the temporary value and where is the valid time of the pseudonym .
[0065] Set as the temporary pseudonym of the drone generate a partial private key request and send the partial private key request to .
[0066] Partial private key generation
[0067] After receiving the partial private key request the key generation center performs the following calculation process to generate the partial private key of the drone .
[0068] Select a random number calculate as the partial public key and the digest value of the drone, indicating the hash operation function;
[0069] Calculate as the partial private key of the drone and reply with the partial private key Send to the UAV via a secure channel .
[0070] Full key generation
[0071] UAV After receiving the partial private key reply , perform the following calculation process to generate its own full public-private key pair.
[0072] Calculate the temporary value , with the help of the hash function , judge whether the verification equation holds. If it holds, the UAV considers the pseudonym valid, and takes as its own temporary identity and continues with the next step; otherwise, the UAV considers the message illegal and reinitiates a pseudonym application.
[0073] With the help of the hash function calculate , judge whether the verification equation holds. If it holds, the UAV sets its own full private key as , and its own full public key as . Otherwise, the UAV considers the partial private key illegal and re-applies for a pseudonym.
[0074] Group key negotiation phase
[0075] If there is a UAV network application scenario and there is a UAV group , including UAV devices , when the cluster wants to generate a group key to ensure the secure transmission of data among group members, it can select a device with relatively rich computing and communication resources as the group manager to be responsible for distributing the group key information of other group members (if the computing and communication resources of all group members are the same, a node can be randomly selected as the group manager). In the group key distribution method proposed in the present invention, set as the UAV group management node, and complete the symmetric group key negotiation and the asymmetric group key negotiation through the interaction with other ordinary UAV devices.
[0076] The first step: The group manager initiates a group key negotiation request
[0077] Group manager After having obtained the public key information of other group members On the premise of, form an identity ring with the temporary identities of all group members according to the communication distance , where ;
[0078] After that, the group manager selects a random number as the identifier information for this group key negotiation, and sends the group key initiation information to all drones in the group by broadcasting .
[0079] Step 2: The group members After receiving the group key initiation information , perform the following calculations.
[0080] Select a random number , calculate the random value ;
[0081] According to the identity order in the identity ring , send to the previous drone device through the public channel , where .
[0082] Step 3: The group members After receiving the data sent by , perform the following calculations.
[0083] Based on the previously generated random number , and the received random number , with the help of the hash functions and , calculate the digest values , and ;
[0084] Calculate the temporary value ;
[0085] Calculate the temporary value and the digest value , where, represents the hash function;
[0086] With the help of the message authentication code function , generate the message authentication code , and send the authentication information } to through the public channel;
[0087] Step 4: The group members After receiving the sent data and the sent authentication information }, perform the following calculations.
[0088] Based on the previously generated random number and , with the help of hash functions and , calculate the digest value , , ;
[0089] Calculate the temporary values and ;
[0090] With the help of hash function , calculate , and determine whether the verification equation holds. If it holds, it means the authentication information }} is valid, and continue with the next step.
[0091] Based on hash functions and , calculate and ;
[0092] Calculate the temporary values and ;
[0093] Calculate and ;
[0094] With the help of the message authentication code function function, generate the message authentication code , send the authentication information }} to through the public channel, and transmit the group key negotiation information to all drones in the group in a broadcast manner;
[0095] Step 5: The group manager After receiving the sent authentication information }}, perform the following calculations to generate the group key:
[0096] Based on hash functions and , calculate the digest value , ;
[0097] Calculate the temporary value and ;
[0098] Based on the hash function and the message authentication code function calculate the digest value and determine whether the verification equation holds. If it holds, it means that the authentication information is valid and continue with the next operation.
[0099] Calculate and transmit the group key negotiation information to all the member drones in the group in a broadcast manner .
[0100] Step 6: Symmetric group key negotiation: Each member within the group After receiving the group key negotiation information broadcast by other members within the group perform the following calculation process to generate a symmetric key known only to the users within the group to ensure the secure transmission of data within the group. The specific process is as shown in the appendix Figure 2 .
[0101] Based on the multiple received group key negotiation information determine whether the verification equation holds. If it holds, it means that the received is valid and perform the next operation; otherwise, directly discard the message and initiate the group key negotiation again.
[0102] Calculate the temporary value in sequence according to the following calculation process
[0103]
[0104]
[0105]
[0106] …
[0107]
[0108] Judge whether it holds. If it holds, perform the next operation; otherwise, directly discard it;
[0109] Based on the hash function calculate the group symmetric key as the group symmetric key of the drone cluster to ensure the security of data transmission among group members with a symmetric encryption algorithm.
[0110] Step 7: Asymmetric group key negotiation: For each member within the group after receiving the group key negotiation information broadcast by other members within the group perform the following calculation process to generate a private key known only to the group members and a public key known to all users. The specific process is as shown in the appendix Figure 3 .
[0111] The group member sends the random number generated in Step 1 to the group administrator ;
[0112] The group administrator after receiving the random numbers sent by all users combines them with the one generated by itself and, for each device, based on the hash functions and successively calculates and ;
[0113] Generates the group public key according to the following calculation process ;
[0114]
[0115]
[0116]
[0117] After that, the group administrator disseminates the group public key information to all drone devices through broadcasting
[0118] The group member after receiving the group public key information successively calculates the ephemeral values , , …, ;
[0119] After that judge whether holds. If it holds, perform the next operation; otherwise, discard it directly
[0120] Finally calculate the group private key and judge whether the verification equation holds. If it holds, the group member considers the group asymmetric key It is valid, and the public-private key pair is used to asymmetrically encrypt the private data.
[0121] Group key encryption and decryption phases
[0122] This method can generate symmetric group keys and asymmetric group keys respectively. Therefore, group key encryption can be divided into two sub-parts: symmetric encryption and asymmetric encryption, as follows.
[0123] Group symmetric key encryption
[0124] Symmetric encryption
[0125] Assume that among the group members who want to transmit data to other members in the group, the specific encryption and decryption processes are as follows.
[0126] Select a timestamp , and with the help of a hash function , generate a session key , where is the hash function used to generate the session key;
[0127] Calculate the ciphertext , and broadcast the ciphertext data to other UAVs in the group through the public channel, where represents the symmetric encryption algorithm;
[0128] Symmetric decryption
[0129] Other group members After receiving the ciphertext data , perform the following calculations to restore the plaintext data .
[0130] Obtain the current timestamp , and judge the verification equation to judge whether the timestamp is valid, where represents the survival time of the ciphertext. If the verification fails, the ciphertext data has expired and is directly discarded; otherwise, continue with the next step.
[0131] With the help of a hash function , generate and to obtain the plaintext data . Among them, represents the symmetric decryption algorithm.
[0132] Group public key encryption
[0133] Public key encryption
[0134] Suppose there is a device outside the UAV cluster wanting to transmit data to the UAV group members , then the specific encryption process is as follows.
[0135] Select a random number and calculate the random number ;
[0136] Select a timestamp and calculate the ciphertext , and send the ciphertext data to the UAVs in the group through broadcast via the public channel , where represents the timestamp is the hash function used for encryption.
[0137] Decrypt with the private key
[0138] The UAVs in the group After receiving the ciphertext data , perform the following calculations to complete the restoration of the plaintext data .
[0139] Obtain the current timestamp , execute the verification equation to determine whether the timestamp is valid, where represents the ciphertext 's survival time. If the verification fails, the survival time of the ciphertext data has expired and it is directly discarded; otherwise, continue with the next step.
[0140] Based on the hash function , calculate to obtain the plaintext data .
[0141] UAV joining phase
[0142] Considering the fast mobility of UAV devices, if a UAV device outside the UAV group wants to join , then the group key must change dynamically accordingly. The specific process is as follows.
[0143] Step 1: The group administrator announces the information of the group member joining.
[0144] The UAV group manager sends the random number to the device ;
[0145] Drone group manager Generate a new identity ring and send the group key initiation information to the drones within the group via broadcast ;
[0146] Drone device After receiving the group key initiation information send the group key negotiation information to the device .
[0147] Step 2: New group member After receiving the group key initiation information perform the following calculations
[0148] Select a random number and calculate the random number ;
[0149] Send the random number to the previous user via the public channel ;
[0150] Step 3: Group member After receiving the random number perform the following calculations
[0151] Based on the previously generated random number , and the received , with the help of the hash functions and calculate the digest values and ;
[0152] Recalculate the temporary values and ;
[0153] Recalculate the temporary values and , indicating the hash function;
[0154] Based on the message authentication code function generate the message authentication code , and send the authentication information }} via the public channel to and broadcast the group key negotiation information to all the drones within the group;
[0155] Step 4: Group member After receiving the authentication information After that, perform the following calculations.
[0156] Based on the previously generated random number and , with the help of the hash function and , calculate the digest value , , ;
[0157] Calculate the temporary values and ;
[0158] Calculate the temporary value , and with the help of the message authentication code function , determine whether the verification equation holds. If it holds, it means the authentication message is valid, and continue with the next step.
[0159] With the help of the hash functions and , calculate the digest values and ;
[0160] Calculate the temporary values and ;
[0161] Calculate the temporary values and ;
[0162] With the help of the message authentication code function , generate the message authentication code , send the authentication message } through the public channel to , and transmit the group key negotiation information to all the drones in the group in a broadcast manner;
[0163] Step 5: The group manager After receiving the authentication message } sent by
[0164] With the help of the hash functions and , calculate the digest value , ;
[0165] Recalculate the temporary value and calculate ;
[0166] Based on the hash function and the message authentication code function , calculate the digest value , and determine whether the verification equation holds. If it holds, it means that the authenticated message } is valid, and continue with the next step.
[0167] Recalculate , and transmit the group key negotiation message to all member drones in the group in a broadcast manner.
[0168] Step 6: Symmetric group key negotiation: Each member within the group After receiving the broadcast group key negotiation message , perform the following calculation process to generate a new symmetric key known only to the users within the group to ensure data transmission, and the specific process is as follows.
[0169] Based on the received group key negotiation message , determine whether the verification equation holds. If it holds, it means that the received is valid, and perform the next step; otherwise, directly discard the message and initiate group key negotiation again.
[0170] Calculate the temporary value in sequence according to the following calculation process;
[0171]
[0172] …
[0173]
[0174]
[0175] Judge whether holds. If it holds, perform the next step; otherwise, directly discard it;
[0176] Recalculate the group symmetric key as the group symmetric key, and use the symmetric encryption algorithm to ensure the security of data transmission among group members.
[0177] Step 7: Asymmetric group key negotiation: Each member within the group After receiving the broadcast group key negotiation information , perform the following calculation process to generate a private key known only to the members within the group and a public key known to all users, and the specific process is as follows.
[0178] Group members Send the random number generated in the first step To the group administrator ;
[0179] Group administrator After receiving the random numbers sent by all users Combine with the one generated by himself ;
[0180] Group administrator For each drone device , based on the hash function And , calculate in sequence And ;
[0181] Group administrator After receiving the random numbers sent by all users Combine with the random number generated by himself , regenerate the group public key according to the following calculation process ;
[0182]
[0183] After that, the group administrator Broadcast the group public key information To all drone devices;
[0184] Group members After receiving the group public key information , calculate the temporary values in sequence according to the following calculation method , ,…, , ;
[0185]
[0186] …
[0187]
[0188]
[0189] After that, the group members Judge Whether it holds. If it holds, perform the next operation; otherwise, discard it directly;
[0190] Finally, the group members Calculate , and judge whether the verification equation Holds. If it holds, the group members It is considered that this group of asymmetric keys is valid, and the public-private key pair is used to perform asymmetric encryption on the privacy data.
[0191] Drone departure phase
[0192] Considering the fast mobility of the drone device, if a group of drone devices wants to leave the drone group , the group key must be dynamically changed accordingly. The specific process is as follows.
[0193] Step 1:
[0194] The drone group manager forms a new identity ring , and initiates the group key information and sends it to the drones in the group via broadcast .
[0195] Step 2: The group members After receiving the group key initiation information , perform the following calculations.
[0196] Send the random number to the previous user via the public channel ;
[0197] Step 3: The group members After receiving the random number , perform the following calculations.
[0198] Based on the previously generated random numbers , , and the received , with the help of the hash functions and , calculate and ;
[0199] Recalculate the temporary values and ;
[0200] Recalculate the temporary values and ;
[0201] With the help of the message authentication code function , generate the message authentication code , and send the authentication message } to via the public channel, and send the group key negotiation information Transmit it to all the drones in the group in a broadcast manner;
[0202] Step 4: Group members After receiving the authentication message }, perform the following calculations.
[0203] Based on the previously generated random number and , with the help of the hash functions and , calculate , and ;
[0204] Recalculate the temporary values and ;
[0205] Based on the hash function and the message authentication code function , calculate the temporary value , and determine whether the verification equation holds. If it holds, it means the authentication message } is valid, and continue with the next step.
[0206] Recalculate , and transmit the group key negotiation information to all the drones in the group in a broadcast manner;
[0207] Step 5: Symmetric group key negotiation: Each member within the group After receiving the group key negotiation information broadcast , perform the following calculation process to generate a new symmetric key known only to the new group members to ensure data transmission, and the specific process is as follows.
[0208] Based on the received group key negotiation information , determine whether the verification equation holds. If it holds, it means the received and are valid, and perform the next step; otherwise, directly discard the message and initiate the group key negotiation again.
[0209] Calculate the following temporary values in sequence: :
[0210]
[0211] …
[0212]
[0213] …
[0214]
[0215] Judge whether it holds. If it holds, perform the next operation; otherwise, discard it directly;
[0216] Based on the hash function , recalculate the group symmetric key as the new group symmetric key to ensure the security of data transmission among group members with a symmetric encryption algorithm.
[0217] Step 7: Asymmetric group key negotiation: Each group member After receiving the group key negotiation information broadcast , perform the following calculation process to generate a private key only known to group members and a public key known to all users. The specific process is as follows.
[0218] The group administrator After receiving the random numbers sent by all users , combine them with the one generated by itself ; Based on the hash functions and , calculate and in sequence;
[0219] Generate a new group public key according to the following calculation process:
[0220]
[0221] After that, the group administrator Disseminate the group public key information to all drone devices through broadcasting.
[0222] The group member After receiving the group public key information , calculate the temporary values , , …, in sequence according to the calculation process of symmetric group key negotiation;
[0223] After that, the group member Judge whether it holds. If it holds, perform the next operation; otherwise, discard it directly;
[0224] Finally, the group member Calculates the group private key , and judges whether the verification equation holds. If it holds, the group member It is considered that the set of asymmetric keys is valid, and the public-private key pair is used to perform asymmetric encryption on the privacy data.
[0225] To verify the security strength and feasibility of the proposed solution of the present invention, the present invention will discuss the security attributes that the proposed solution can satisfy, including non-repudiation, unlinkability, anonymity, traceability, privacy protection, perfect forward and backward security, and known session-specific ephemeral information security.
[0226] To prevent the drone from denying its participation in the group key negotiation, in the solution proposed by the present invention, the CDH security assumption and the message authentication code are adopted to prevent the drone from denying its participation in the calculation process. If a group member includes and the group key negotiation is successful, then during the negotiation process, will calculate based on the received , and , and send } to . After receiving }, it is necessary to complete the verification of . However, in the calculation of , , and can only be owned by legitimate . Based on the CDH security assumption , other attackers cannot forge the correct and pass the verification of . Therefore, if the verification passes, it means that the legitimacy verification of passes, and cannot deny that it has sent the } and participated in this round of group key negotiation.
[0227] During the group key negotiation process proposed by the present invention, based on the CDH security assumption, the attacker cannot calculate and obtain the real identity of any group member in a specific group key negotiation session. First, in the first step of the group key negotiation, the group administrator generates a ring R and sends it to all drones in the group. However, the temporary identity information of the drones is used in R. Since the private key of the trusted registration authority cannot be obtained , based on the CDH security assumption, the attacker cannot obtain the real identity of the drone. Second, for the communication between adjacent devices during the group key negotiation process, there are mainly } and In both cases, there is no explicit information to identify the drone 's true identity information. Therefore, the group key negotiation scheme proposed in the present invention can meet the anonymity requirement.
[0228] To protect the privacy data of drones, taking the true identity of the drone as privacy data, the scheme proposed in the present invention can achieve the protection of the drone's identity privacy under the security assumption of the CDH problem. To protect the drone's identity information, in the scheme proposed in the present invention, a trusted registration authority is added to assign a temporary legal pseudonym to each drone to achieve the secure protection of the drone's true identity. Since the private key of the trusted registration authority cannot be obtained, based on the CDH problem the attacker cannot calculate the correct and thus obtain the privacy data of the drone, that is, the true identity.
[0229] To ensure the rapid traceability of the true identity of malicious drones during the group key negotiation process, in the scheme proposed in the present invention, when the drone device discovers an illegal drone due to verification failure, the trusted registration authority can execute
[0230]
[0231] to complete the rapid traceability of the true identity of the illegal drone device and then perform corresponding security protection services. Therefore, the scheme proposed in the present invention meets the traceability requirement.
[0232] Similar to the proof process of anonymity, the attacker cannot determine whether the two group key negotiations are implemented by the same group based on the messages sent during the two group key negotiation processes. First, during the group key negotiation process, the drones all perform group key negotiation with pseudonyms. Due to the lack of }, and } belong to the same group members. Therefore, the scheme proposed in the present invention meets the unlinkability requirement.
[0233] Assume that the long-term private keys of all group members are leaked. The attacker still cannot calculate the correct group session key for previous or subsequent group key negotiations. The proof process is as follows. To calculate the correct group session key, the attacker must calculate the correct , , …, . However, for any , even if it is possible to calculate , and , but since the attacker cannot obtain and , based on the CDH security assumption, the attacker cannot calculate the correct . Therefore, the solution proposed by the present invention satisfies perfect forward and backward security.
[0234] Known session-specific ephemeral information security
[0235] Similar to the proof of perfect forward and backward security, if the attacker can obtain the random value of the group key negotiation process of each group member group key negotiation process , the attacker still cannot calculate the correct group key, and the proof is as follows. In the solution proposed by the present invention, in order to calculate the correct group key, the attacker must calculate . Based on the random numbers and , the attacker can successfully calculate , and . However, since all private keys of or all private keys of , based on the CDH security assumption, the attacker cannot calculate the correct , and thus cannot calculate the correct group session key. Therefore, the solution proposed by the present invention satisfies known session-specific ephemeral information security.
[0236] The embodiments of the present invention have been described in detail above. Specific examples are used in this article to elaborate on the principles and implementation manners of the present invention. The descriptions of the above embodiments are only used to help understand the core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to the present invention.
Claims
1. A privacy protection and dynamic certificateless group key negotiation method in a drone network, characterized in that: include: Generate public and private keys based on the key generation center and trusted registration agency to build a drone network cryptography system; The drone obtains a temporary pseudonym and part of the private key to generate a complete key pair; Select a group manager and complete symmetric and asymmetric group key negotiation through interaction; Generate a symmetric group key and an asymmetric group key for intra-group and extra-group communications respectively; When a drone joins or leaves the group, the group key is dynamically updated; During group key negotiation, the group manager initiates a group key negotiation request, generates an identity ring, selects a random number as a group key negotiation identifier, and broadcasts group key initiation information; The group member receives the group key initiation information, selects a random number, calculates the random value, and sends the random value to the previous drone through the public channel; The group members receive the random value, calculate the summary value and temporary value, generate the message verification code, and send the authentication information through the public channel; The group manager receives the authentication information, calculates the group key, and broadcasts the group key negotiation information; The group members receive the group key negotiation information and generate a symmetric group key and an asymmetric group key; The key generation method for the drone joining includes: The group manager announces the group member joining information, generates a new identity ring, and broadcasts the group key initiation information; The new member receives the group key initiation message, selects a random number, calculates the random value, and sends the random value to the previous user through a public channel; The group members receive the random value, calculate the summary value and temporary value, generate the message verification code, and send the authentication information through the public channel; The group manager receives the authentication information, calculates the group key, and broadcasts the group key negotiation information; The group members receive the group key agreement information and generate new symmetric group keys and asymmetric group keys.
2. A privacy protection and dynamic certificateless group key negotiation method in a drone network according to claim 1, characterized in that: The key generation center selects the additive cyclic group, the multiplicative cyclic group and the generator, selects the bilinear pairing operation and the hash function, and generates the system public and private keys; The trusted registration authority selects a private key, calculates a public key, and sends it to the key generation center through a secure channel; The key generation center generates system public parameters and sends them to all devices in the drone network through public channels.
3. The privacy protection and dynamic certificateless group key negotiation method in a drone network according to claim 1, characterized in that: When a drone user registers, the drone receives the system’s public parameters, selects a secret value, calculates a partial public key, and sends a pseudonym request to a trusted registration authority; The trusted registration authority receives the request and checks whether the drone is legal. If it is legal, it calculates the temporary value, sets a temporary pseudonym, generates a partial private key request and sends it to the key generation center. The key generation center receives the request, selects a random number, calculates a partial public key and digest value, generates a partial private key and sends it back to the drone; The drone receives a partial private key reply and verifies it through a hash function. If the verification is successful, the complete public and private key pair is generated. Otherwise, a new pseudonym is applied for.
4. The privacy protection and dynamic certificateless group key negotiation method in a drone network according to claim 1, characterized in that: The key generation methods when the drone leaves include: The group manager generates a new identity ring and broadcasts the group key initiation information; The group member receives the group key initiation information, selects a random number, and sends it to the previous user through a public channel; The group members receive the random number, calculate the summary value and temporary value, generate the message verification code, and send the authentication information through the public channel; The group manager receives the authentication information, calculates the group key, and broadcasts the group key negotiation information; The group members receive the group key agreement information and generate new symmetric group keys and asymmetric group keys.
5. The privacy protection and dynamic certificateless group key negotiation method in a drone network according to claim 1, characterized in that: The symmetric encryption method of the symmetric group key includes selecting a timestamp, generating a session key, calculating a ciphertext, and sending the ciphertext data through a public channel.
6. The privacy protection and dynamic certificateless group key negotiation method in a drone network according to claim 1, characterized in that: The asymmetric decryption method of the asymmetric group key includes receiving ciphertext data, verifying a timestamp, generating a session key, and decrypting the ciphertext data.
7. The privacy protection and dynamic certificateless group key negotiation method in a drone network according to claim 1, characterized in that: The method for public key encryption of the group key includes selecting a random number, calculating the random number, selecting a timestamp, calculating a ciphertext, and sending the ciphertext data through a public channel.
8. The privacy protection and dynamic certificateless group key negotiation method in a drone network according to claim 1, characterized in that: The method for decrypting the private key of the group key includes receiving ciphertext data, verifying a timestamp, and calculating plaintext data.
Citation Information
Patent Citations
Group authentication key negotiation method based on certificateless key system in unmanned aerial vehicle network
CN116961897A
Privacy protection and traceable certificateless anonymous bidirectional authentication method suitable for Internet of Things
CN118784229A