Method and apparatus for performing security authentication with an unmanned system

CN119853911BActive Publication Date: 2025-07-22BEIJING ZHONGYU WANTONG TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510337081.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-21
Publication Date
2025-07-22
Estimated Expiration
2045-03-21

AI Technical Summary

Technical Problem

In the existing unmanned system authentication methods, the key is easy to crack and cannot withstand quantum computing attacks, which poses a risk of data leakage.

Method used

The same symmetric key is built-in in unmanned systems and beacon systems, and the local paired public and private keys are generated, and key exchange is exchanged in combination with the grid encryption algorithm, and key exchange is used to ensure the security of the key exchange process.

Benefits of technology

It reduces the risk of key cracking, improves the security of authentication, resists quantum computing attacks, and ensures the security of the key exchange process and the reliability of authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119853911B_ABST
    Figure CN119853911B_ABST
Patent Text Reader

Abstract

The present application provides a method and device for performing security authentication with an unmanned system. The method includes: generating a first public key and a first private key for local pairing; decrypting the encrypted public key sent by the unmanned system using a first symmetric key to obtain a second public key of the unmanned system; performing lattice encryption operation on the unmanned system identifier, random number, and timestamp of the unmanned system using the first private key to obtain a first ciphertext; encrypting the first ciphertext and the first public key using the second public key to obtain a second ciphertext, and sending the second ciphertext to the unmanned system; generating a first system key according to the unmanned system identifier and the timestamp; encrypting the unmanned system identifier and the timestamp using the first system key to obtain a third ciphertext, and sending the third ciphertext to the unmanned system, so that the unmanned system decrypts the third ciphertext using a second system key to obtain decryption information, and determines that the authentication is successful when the decryption information is consistent with the relevant information on the unmanned system side.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of unmanned system authentication, and particularly to a method and device for secure authentication with an unmanned system. Background Art

[0002] The authentication between an unmanned system and a beacon system is an important part of the secure operation of the unmanned system. Traditional authentication methods usually use symmetric keys or asymmetric keys for authentication. Although symmetric key authentication is computationally simple, key distribution and update are difficult. Asymmetric key authentication has high security, but high computational complexity and high requirements for computing power.

[0003] In the prior art, there are usually two methods for the authentication between an unmanned system and a beacon:

[0004] 1. Key distribution: The beacon system and the central side of the unmanned system generate a symmetric key or an asymmetric key pair, and the key is distributed through a key management center. Encryption and decryption are performed using the key to complete the authentication.

[0005] 2. Built-in key: The beacon system and the central side of the unmanned system build in a symmetric key, and encryption and decryption are performed using the key to complete the authentication.

[0006] For the above authentication methods using key distribution or built-in symmetric keys, the risk factor of key cracking is extremely high. An attacker can easily crack the key and decrypt historical communication data. Traditional encryption algorithms such as SM2 (SM2 Elliptic Curve Public Key Cryptography Algorithm) and RSA (Rivest-Shamir-Adleman Algorithm) cannot resist quantum computing attacks, which easily causes the risk of data leakage. Summary of the Invention

[0007] Embodiments of this application provide a method and device for secure authentication with an unmanned system to solve the problems of high risk factor in the existing authentication method, easy cracking of the key, inability to resist quantum computing attacks, and easy risk of data leakage.

[0008] To solve the above technical problems, the embodiments of this application are implemented as follows:

[0009] In a first aspect, an embodiment of this application provides a method for secure authentication with an unmanned system, which is applied to a beacon system and includes:

[0010] Generate a locally paired first public key and first private key;

[0011] Decrypt the encrypted public key sent by the unmanned system using the first symmetric key to obtain the second public key of the unmanned system. The encrypted public key is obtained by encrypting the second public key generated on the unmanned system side using the second symmetric key. The first symmetric key and the second symmetric key are the same key;

[0012] Perform lattice encryption operation on the unmanned system identifier, random number, and timestamp of the unmanned system using the first private key to obtain the first ciphertext;

[0013] Encrypt the first ciphertext and the first public key using the second public key to obtain the second ciphertext, and send the second ciphertext to the unmanned system, so that the unmanned system decrypts the second ciphertext using the second private key to obtain the first ciphertext and the first public key, and decrypts the first ciphertext using the first public key to obtain the unmanned system identifier, random number, and timestamp. The second private key and the second public key are paired keys;

[0014] Generate the first system key according to the unmanned system identifier and the timestamp;

[0015] Encrypt the unmanned system identifier and timestamp using the first system key to obtain the third ciphertext, and send the third ciphertext to the unmanned system, so that the unmanned system decrypts the third ciphertext using the second system key to obtain the decryption information, and determines that the authentication is successful when the decryption information is consistent with the relevant information on the unmanned system side. The second system key is the key generated by the unmanned system according to the unmanned system identifier and the timestamp.

[0016] Optionally, the generation of the locally paired first public key and first private key includes:

[0017] Use a pseudo-random number generator to process the pre-input randomness parameter with a specified number of digits and the pre-defined fixed parameter to generate the first pseudo-random seed and the second pseudo-random seed;

[0018] Generate a K×K matrix based on the first pseudo-random seed and the number of rows and columns of the matrix, where K is a positive integer;

[0019] Generate the first vector and the second vector according to the matrix elements of the K×K matrix, the second pseudo-random seed, and the current authentication count value;

[0020] Perform k number-theoretic transform operations on the first vector and the second vector respectively to obtain the corresponding first frequency-domain representation and second frequency-domain representation;

[0021] Perform a linear combination operation on the first frequency-domain representation and the second frequency-domain representation to obtain the linear combination frequency-domain representation;

[0022] Perform encoding processing on the first frequency-domain representation and the linearly combined frequency-domain representation respectively to obtain the first public key and the first private key.

[0023] Optionally, performing lattice encryption operation on the unmanned system identifier, random number, and timestamp of the unmanned system using the first private key to obtain a first ciphertext includes:

[0024] Generate the basis vectors of the lattice;

[0025] Encode the unmanned system identifier, the random number, and the timestamp to obtain a message vector;

[0026] Encode the message vector as a target vector on the basis vectors of the lattice;

[0027] Perform lattice transformation on the target vector based on the first private key to generate the first ciphertext.

[0028] Optionally, sending the second ciphertext to the unmanned system includes:

[0029] Process the second ciphertext based on the SM3 cryptographic hashing algorithm to obtain a first digest value corresponding to the second ciphertext;

[0030] Send the second ciphertext and the first digest value to the unmanned system for the unmanned system to verify the first digest value, and after the first digest value is verified, decrypt the second ciphertext using the second private key.

[0031] Optionally, sending the third ciphertext to the unmanned system includes:

[0032] Process the third ciphertext based on the SM3 cryptographic hashing algorithm to obtain a second digest value corresponding to the third ciphertext;

[0033] Send the third ciphertext and the second digest value to the unmanned system for the unmanned system to verify the second digest value, and after the second digest value is verified, decrypt the third ciphertext using the second system key.

[0034] Optionally, after generating the first system key according to the unmanned system identifier and the timestamp, further include:

[0035] Record the generation time of the first system key;

[0036] Update the first system key when the interval period between the current time and the generation time reaches a set duration.

[0037] Optionally, after encrypting the unmanned system identifier and the timestamp with the first system key to obtain a third ciphertext and sending the third ciphertext to the unmanned system, the method further includes:

[0038] After successful authentication with the unmanned system, record the authentication time of this successful authentication;

[0039] When the interval period between the current time and the authentication time reaches the authentication duration, re - execute the authentication process with the unmanned system.

[0040] In a second aspect, an embodiment of the present application provides a device for secure authentication with an unmanned system, which is applied to a beacon system and includes:

[0041] A pairing key generation module, configured to generate a locally paired first public key and first private key;

[0042] An encrypted public key decryption module, configured to decrypt the encrypted public key sent by the unmanned system with a first symmetric key to obtain the second public key of the unmanned system. The encrypted public key is obtained by the unmanned system encrypting the second public key generated on the unmanned system side with a second symmetric key, and the first symmetric key and the second symmetric key are the same key;

[0043] A first ciphertext generation module, configured to perform lattice encryption operations on the unmanned system identifier, random number, and timestamp of the unmanned system with the first private key to obtain a first ciphertext;

[0044] A second ciphertext sending module, configured to encrypt the first ciphertext and the first public key with the second public key to obtain a second ciphertext, and send the second ciphertext to the unmanned system, so that the unmanned system decrypts the second ciphertext with a second private key to obtain the first ciphertext and the first public key, and decrypts the first ciphertext with the first public key to obtain the unmanned system identifier, random number, and timestamp. The second private key and the second public key are paired keys;

[0045] A system key generation module, configured to generate a first system key according to the unmanned system identifier and the timestamp;

[0046] A third ciphertext sending module, configured to encrypt the unmanned system identifier and the timestamp with the first system key to obtain a third ciphertext, and send the third ciphertext to the unmanned system, so that the unmanned system decrypts the third ciphertext with a second system key to obtain decryption information, and determines that the authentication is successful when the decryption information is consistent with the relevant information on the unmanned system side; the second system key is a key generated by the unmanned system according to the unmanned system identifier and the timestamp.

[0047] Optionally, the pairing key generation module includes:

[0048] A pseudo-random seed generation unit, configured to process a pre-input randomness parameter with a specified number of digits and a predefined fixed parameter using a pseudo-random number generator to generate a first pseudo-random seed and a second pseudo-random seed;

[0049] A matrix generation unit, configured to generate a K×K matrix based on the first pseudo-random seed and the number of rows and columns of the matrix, where K is a positive integer;

[0050] A vector generation unit, configured to generate a first vector and a second vector based on the matrix elements of the K×K matrix, the second pseudo-random seed, and the current authentication count value;

[0051] A frequency-domain representation acquisition unit, configured to perform k number-theoretic transform processes on the first vector and the second vector respectively to obtain corresponding first and second frequency-domain representations;

[0052] A combined frequency-domain representation acquisition unit, configured to perform a linear combination operation on the first frequency-domain representation and the second frequency-domain representation to obtain a linear combination frequency-domain representation;

[0053] A key acquisition unit, configured to perform encoding processes on the first frequency-domain representation and the linear combination frequency-domain representation respectively to obtain the first public key and the first private key.

[0054] Optionally, the first ciphertext generation module includes:

[0055] A basis vector generation unit, configured to generate a basis vector of a lattice;

[0056] A message vector acquisition unit, configured to encode the unmanned system identifier, the random number, and the timestamp to obtain a message vector;

[0057] A target vector acquisition unit, configured to encode the message vector into a target vector on the basis vector of the lattice;

[0058] A first ciphertext generation unit, configured to perform a lattice transformation on the target vector based on the first private key to generate the first ciphertext.

[0059] Optionally, the second ciphertext sending module includes:

[0060] A first digest value acquisition unit, configured to process the second ciphertext based on the SM3 cryptographic hash algorithm to obtain a first digest value corresponding to the second ciphertext;

[0061] A second ciphertext sending unit, configured to send the second ciphertext and the first digest value to the unmanned system, so that the unmanned system verifies the first digest value, and after the first digest value is verified successfully, decrypts the second ciphertext using the second private key.

[0062] Optionally, the third ciphertext sending module includes:

[0063] A second digest value obtaining unit, configured to process the third ciphertext based on the SM3 cryptographic hash algorithm to obtain a second digest value corresponding to the third ciphertext;

[0064] A third ciphertext sending unit, configured to send the third ciphertext and the second digest value to the unmanned system, so that the unmanned system verifies the second digest value, and after the second digest value is verified successfully, decrypts the third ciphertext using a second system key.

[0065] Optionally, the apparatus further includes:

[0066] A generation time recording module, configured to record the generation time of the first system key;

[0067] A system key updating module, configured to update the first system key when the time interval between the current time and the generation time reaches a set duration.

[0068] Optionally, the apparatus further includes:

[0069] An authentication time recording module, configured to record the authentication time of the successful authentication after successfully authenticating with the unmanned system;

[0070] An authentication process execution module, configured to re-execute the authentication process with the unmanned system when the time interval between the current time and the authentication time reaches the authentication duration.

[0071] In a third aspect, an embodiment of the present application provides an electronic device, including:

[0072] A memory, a processor, and a computer program stored on the memory and executable on the processor, where when the computer program is executed by the processor, it implements the method for performing secure authentication with an unmanned system according to any one of the above.

[0073] In a fourth aspect, an embodiment of the present application provides a readable storage medium, where when the instructions in the storage medium are executed by a processor of an electronic device, the electronic device is enabled to execute the method for performing secure authentication with an unmanned system according to any one of the above.

[0074] In an embodiment of the present application, a first public key and a first private key for local pairing are generated. The encrypted public key sent by the unmanned system is decrypted using the first symmetric key to obtain the second public key of the unmanned system. The encrypted public key is obtained by the unmanned system encrypting the second public key generated on the unmanned system side using the second symmetric key. The first symmetric key and the second symmetric key are the same key. The lattice encryption operation is performed on the unmanned system identifier, random number, and timestamp of the unmanned system using the first private key to obtain the first ciphertext. The second public key is used to encrypt the first ciphertext and the first public key to obtain the second ciphertext, and the second ciphertext is sent to the unmanned system for the unmanned system to decrypt the second ciphertext using the second private key to obtain the first ciphertext and the first public key, and use the first public key to decrypt the first ciphertext to obtain the unmanned system identifier, random number, and timestamp. The second private key and the second public key are paired keys. According to the unmanned system identifier and timestamp, a first system key is generated. The unmanned system identifier and timestamp are encrypted using the first system key to obtain the third ciphertext, and the third ciphertext is sent to the unmanned system for the unmanned system to decrypt the third ciphertext using the second system key to obtain the decryption information, and when the decryption information is consistent with the relevant information on the unmanned system side, it is determined that the authentication is successful. The second system key is the key generated by the unmanned system according to the unmanned system identifier and timestamp. In the embodiment of the present application, by embedding the same symmetric key in the unmanned system and the beacon system and using the paired key pairs for authentication, the method of cracking the key can be reduced and the authentication security can be improved. At the same time, using the lattice-based encryption algorithm for key exchange can ensure the security of the key exchange process, resist quantum computing attacks, and further improve the authentication security.

[0075] The above description is only an overview of the technical solution of the present application. In order to be able to understand the technical means of the present application more clearly, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features, and advantages of the present application more obvious and understandable, the specific embodiments of the present application are specifically exemplified below. BRIEF DESCRIPTION OF THE DRAWINGS

[0076] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for the description of the embodiments of the present application will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0077] Figure 1 It is a flowchart of the steps of a method for secure authentication with an unmanned system provided by an embodiment of the present application;

[0078] Figure 2 It is a schematic diagram of the dynamic authentication process between an unmanned system and a beacon system provided by an embodiment of the present application;

[0079] Figure 3 A schematic diagram of generating a key pair using a random seed provided by an embodiment of the present application;

[0080] Figure 4 A schematic structural diagram of a device for performing security authentication with an unmanned system provided by an embodiment of the present application;

[0081] Figure 5 A schematic structural diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners

[0082] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0083] Referring to Figure 1 , a flowchart of steps of a method for performing security authentication with an unmanned system provided by an embodiment of the present application is shown. This method is applied to a beacon system. As Figure 1 shown, the method for performing security authentication with an unmanned system may include: step 101, step 102, step 103, step 104, step 105, and step 106.

[0084] Step 101: Generate a first public key and a first private key for local pairing.

[0085] In this embodiment, an unmanned system refers to a system that can perform tasks autonomously without relying on direct human driving or operation. It covers various types of devices, such as unmanned aerial vehicles, unmanned ships, unmanned vehicles, etc. Among them, the unmanned system center side (Unmanned System Center) refers to the central part or main control end in the unmanned system responsible for overall control, management, and coordination.

[0086] A beacon system is a device used to send signals for other devices to receive and identify. It can emit various types of signals, such as radio waves, sound waves, optical signals, etc. These signals are mainly used for positioning, navigation, communication, or identifying a specific location or device.

[0087] The embodiments of the present application can be applied to a beacon system, that is, the execution subject is a beacon system.

[0088] When performing authentication with an unmanned system, a paired first public key and first private key can be generated locally in the beacon system. At the same time, a paired second public key and second private key can be generated on the unmanned system side.

[0089] The generation process of the first public key and the first private key can be a way of generating a key pair using a random seed. Specifically, it can be described in detail in combination with the following specific implementation methods.

[0090] In a specific implementation of the present application, step 101 above may include:

[0091] Sub-step A1: Use a pseudo-random number generator to process the randomly generated parameters of a pre-input specified number of digits and a predefined fixed parameter to generate a first pseudo-random seed and a second pseudo-random seed.

[0092] In this embodiment, a pseudo-random number generator (Pseudo-Random Number Generator, PRNG) is a random number generator based on a deterministic algorithm. It generates a series of seemingly random numbers through a fixed and repeatable calculation method (i.e., a deterministic algorithm). These numbers exhibit randomness in a wide range of statistical properties, but in fact they follow a certain algorithm rule, so they are not truly random numbers. A pseudo-random number generator usually starts the algorithm based on an initial value or "seed" and generates subsequent number sequences.

[0093] When generating the paired first public key and the first private key, a pseudo-random number generator can be used to process the randomly generated parameters of a pre-input specified number of digits and a predefined fixed parameter to generate a first pseudo-random seed and a second pseudo-random seed. Specifically, as Figure 3 shown, initialization can be performed first. In the initialization process, a 32-bit seed d can be input. . Then, the 32 + 1-byte randomness parameter d and the parameter k (a predefined fixed parameter) are extended by the pseudo-random number generator into two pseudo-random 32-byte seeds, namely the first pseudo-random seed and the second pseudo-random seed . This process can be expressed as: .

[0094] At the same time, the counter can be initialized. The counter N is initialized to 0, and N + 1 is incremented each time authentication is performed, and so on.

[0095] After obtaining the first pseudo-random seed and the second pseudo-random seed, sub-step A2 is executed.

[0096] Sub-step A2: Generate a K×K matrix based on the first pseudo-random seed and the number of rows and columns of the matrix, where K is a positive integer.

[0097] After obtaining the first pseudo-random seed and the second pseudo-random seed, a K×K matrix can be generated based on the first pseudo-random seed and the number of rows and columns of the matrix, where K is a positive integer. Specifically, as Figure 3 shown, a matrix can be generated, that is, a k×k matrix is generated , where each element is generated by the function SampleNTT. The function SampleNTT uses , , as inputs, , representing the row and column values of the matrix.

[0098] The process of generating each element of the K×K matrix can be as follows:

[0099]

[0100]

[0101]

[0102] end for

[0103] end for.

[0104] After generating the K×K matrix based on the first pseudo-random seed and the number of rows and columns of the matrix, sub-step A3 is executed.

[0105] Sub-step A3: Generate a first vector and a second vector according to the matrix elements of the K×K matrix, the second pseudo-random seed, and the current authentication count value.

[0106] After generating the K×K matrix based on the first pseudo-random seed and the number of rows and columns of the matrix, a first vector and a second vector can be generated according to the matrix elements of the K×K matrix, the second pseudo-random seed, and the current authentication count value. As Figure 3 shown, after generating the matrix, a vector can be generated, that is, a vector s (i.e., the first vector) of length k is generated, where each element (i.e., the i-th element in the s vector) is generated by the function SamplePolyCBD. The function SamplePolyCBD uses and N (N is a counter used to track the number of authentications, incremented by 1 each time an authentication is performed) as inputs and samples from the central binomial distribution (CBD). The generation process of the first vector can be:

[0107]

[0108]

[0109]

[0110] end for。

[0111] Meanwhile, a vector e (i.e., the second vector) of length k can be generated, where each element (i.e., the i-th element in the e vector) is generated by the function SamplePolyCBD. The function SamplePolyCBD uses and N as inputs and samples from the central binomial distribution. The generation process of the second vector can be as follows:

[0112]

[0113]

[0114]

[0115] end for。

[0116] After obtaining the first vector and the second vector, sub-step A4 is executed.

[0117] Sub-step A4: Perform k number-theoretic transform processes on the first vector and the second vector respectively to obtain corresponding first frequency-domain representations and second frequency-domain representations.

[0118] The number-theoretic transform (i.e., the NTT transform) is a mathematical transform method developed based on number-theoretic principles. The NTT transform operates in a finite field, avoiding floating-point precision errors and is particularly suitable for scenarios that require integer results.

[0119] After obtaining the first vector and the second vector, the first vector and the second vector can be respectively subjected to k number-theoretic transform processes (such as Figure 3 the steps of the NTT transform shown) to obtain corresponding first frequency-domain representations and second frequency-domain representations. Specifically, the NTT can be run on vector s and vector e k times to respectively obtain and . This transform process can be expressed as:

[0120] .

[0121] .

[0122] After performing k number-theoretic transform processes on the first vector and the second vector respectively to obtain corresponding first frequency-domain representations and second frequency-domain representations, sub-step A5 is executed.

[0123] Sub-step A5: Perform a linear combination operation on the first frequency-domain representation and the second frequency-domain representation to obtain a linearly combined frequency-domain representation.

[0124] After performing the k-th number-theoretic transform processing on the first vector and the second vector respectively to obtain the corresponding first frequency-domain representation and second frequency-domain representation, a linear combination operation can be performed on the first frequency-domain representation and the second frequency-domain representation to obtain a linearly combined frequency-domain representation (such as Figure 3 the steps of calculating the linear combination shown). Specifically, a noisy linear system can be run in the NTT domain to calculate the linear combination, and the implementation process can be: . That is the linearly combined frequency-domain representation.

[0125] After performing a linear combination operation on the first frequency-domain representation and the second frequency-domain representation to obtain a linearly combined frequency-domain representation, sub-step A6 is executed.

[0126] Sub-step A6: Perform encoding processing on the first frequency-domain representation and the linearly combined frequency-domain representation respectively to obtain the first public key and the first private key.

[0127] After performing a linear combination operation on the first frequency-domain representation and the second frequency-domain representation to obtain a linearly combined frequency-domain representation, encoding processing can be performed on the first frequency-domain representation and the linearly combined frequency-domain representation respectively to obtain the first public key and the first private key. Specifically, the above-obtained and can be encoded into byte form through the ByteEncode function to generate the public key PK (i.e., the first public key) and the private key SK (i.e., the first private key) respectively, and the key pair is returned (such as Figure 3 the steps of generating the key pair and returning the result shown). The implementation process can be:

[0128] .

[0129] .

[0130] return (PK, SK).

[0131] In specific implementation, the generation method of the second public key and the second private key for pairing on the unmanned system side is similar to the method of locally generating the paired first public key and first private key, and this embodiment will not elaborate here.

[0132] In the embodiments of the present application, through the security of the pseudo-random number generator and the appropriate selection of number-theoretic transforms, it is ensured that the generated public key and private key have sufficient randomness and security. In addition, by introducing the current authentication count value, the diversity and unpredictability of the keys can be further increased, and the leakage of keys can be avoided.

[0133] In this embodiment, the symmetric key built into the unmanned system and the beacon system can be represented as K, and the key pair on the central side of the unmanned system can be represented as: ( , ) (i.e., the second private key and the second public key), and the key pair on the beacon side can be represented as ( , ) (i.e., the first private key and the first public key).

[0134] After generating the paired first public key and first private key, step 102 is executed.

[0135] Step 102: Use the first symmetric key to decrypt the encrypted public key sent by the unmanned system to obtain the second public key of the unmanned system. The encrypted public key is obtained by the unmanned system encrypting the second public key generated on the unmanned system side with the second symmetric key. The first symmetric key and the second symmetric key are the same key.

[0136] The first symmetric key and the second symmetric key are the same key built into the beacon system and the unmanned system.

[0137] The encrypted public key can be obtained by the unmanned system encrypting the second public key generated on the unmanned system side with the second symmetric key. After obtaining the encrypted public key on the unmanned system side, the unmanned system can send the encrypted public key to the beacon system. Specifically, the unmanned system uses the symmetric key K to encrypt the public key , and sends the encrypted public key to the beacon side. The encryption formula can be: .

[0138] After receiving the encrypted public key, the beacon system can use the first symmetric key to decrypt the encrypted public key sent by the unmanned system to obtain the second public key of the unmanned system. That is, the beacon side uses the symmetric key K to decrypt the public key of the unmanned system . The decryption formula can be: .

[0139] After using the first symmetric key to decrypt the encrypted public key sent by the unmanned system to obtain the second public key of the unmanned system, step 103 is executed.

[0140] Step 103: Perform lattice encryption operation on the unmanned system identifier, random number, and timestamp of the unmanned system using the first private key to obtain the first ciphertext.

[0141] Timestamp: A digital label used to record the occurrence time of an event. Usually represented in a certain standard time format, such as year, month, day, hour, minute, second, or even accurate to milliseconds or microseconds. Widely used in computer systems, communication networks, databases, etc., for time sorting and recording of data, operations, or events.

[0142] After obtaining the second public key of the unmanned system, the unmanned system identifier of the unmanned system (such as the ID of the unmanned system) can be obtained. At the same time, a random number and a time stamp (the time stamp can be generated according to the current time) are generated. And the lattice encryption operation is performed on the unmanned system identifier, the random number and the time stamp of the unmanned system by using the first private key locally to obtain the first ciphertext. Specifically, the beacon obtains the ID of the unmanned system and generates a random number R and a time stamp TS0. Then, the private key of the beacon can be used to perform lattice operation encryption on "unmanned system ID, random number R, time stamp TS0" to generate a ciphertext . The ciphertext generation formula can be: .

[0143] The process of lattice operation encryption can be described in detail in combination with the following specific implementation manners.

[0144] In a specific implementation of the present application, the above step 103 may include:

[0145] Sub-step B1: Generate the basis vectors of the lattice.

[0146] In this embodiment, the lattice encryption operation is a cryptographic operation method based on the "lattice" structure in mathematics. A lattice is a discrete subset generated by integer linear combinations of a set of linearly independent vectors, and these vectors form a basis of the lattice. In lattice encryption, the operations mainly involve matrix-vector multiplication, linear summation, and modulo operations, etc., and these operations are relatively simple and efficient.

[0147] When performing the lattice encryption operation, initialization can be performed first, and a lattice basis is selected: First, a lattice basis needs to be selected, which is a set of linearly independent vectors used to define the structure of the lattice. That is, generate the basis vectors of the lattice.

[0148] After generating the basis vectors of the lattice, sub-step B2 is executed.

[0149] Sub-step B2: Encode the unmanned system identifier, the random number, and the time stamp to obtain a message vector.

[0150] After generating the basis vectors of the lattice, the unmanned system identifier, the random number, and the time stamp can be encoded to obtain a message vector. That is, "unmanned system ID, random number R, time stamp TS0" are combined into a vector, and this vector will be used as the encrypted message.

[0151] After encoding the unmanned system identifier, the random number, and the time stamp to obtain a message vector, sub-step B3 is executed.

[0152] Sub-step B3: Encode the message vector into a target vector on the basis vectors of the lattice.

[0153] After encoding the unmanned system identifier, random number, and timestamp to obtain a message vector, the message vector can be encoded into a target vector on the basis vectors of the lattice. Specifically, the message vector can be encoded into a certain point or vector on the lattice. Random perturbation (optional): To increase the security of encryption, a random perturbation vector can be added to the encoded vector.

[0154] After encoding the message vector into a target vector on the basis vectors of the lattice, execute sub-step B4.

[0155] Sub-step B4: Perform a lattice transformation on the target vector based on the first private key to generate the first ciphertext.

[0156] After encoding the message vector into a target vector on the basis vectors of the lattice, a lattice transformation can be performed on the target vector based on the first private key to generate the first ciphertext. That is, use the private key to perform a lattice transformation on the encoded and (optionally) perturbed vector, thereby obtaining a set of vectors, which is the first ciphertext.

[0157] The lattice-based cryptography of the embodiments of the present application provides higher security compared to traditional cryptography. Lattice-based encryption algorithms usually have a faster calculation speed. Lattice-based encryption technology is considered a potential cryptographic system against quantum attacks. By combining the forward-secure algorithm of the lattice, dynamic authentication between the central side of the unmanned system and the beacon is realized. Dynamic keys are generated through the unmanned system ID and timestamp to ensure the uniqueness of the keys for each authentication and improve the security of authentication. And by combining the forward-secure feature, a dynamic key generation and update mechanism is realized to ensure that even if the long-term key is leaked, the past communication content cannot be decrypted, solving the problem of high security risks in traditional authentication methods. Use the lattice-based encryption algorithm for key exchange to ensure the security of the key exchange process and resist quantum computing attacks. Generate ciphertext through lattice encryption operations to ensure the security and indecipherability of the ciphertext.

[0158] After obtaining the first ciphertext, execute step 104.

[0159] Step 104: Encrypt the first ciphertext and the first public key using the second public key to obtain a second ciphertext, and send the second ciphertext to the unmanned system, so that the unmanned system decrypts the second ciphertext using the second private key to obtain the first ciphertext and the first public key, and uses the first public key to decrypt the first ciphertext to obtain the unmanned system identifier, random number, and timestamp. The second private key and the second public key are paired keys.

[0160] After obtaining the first ciphertext, the second public key of the unmanned system can be used to encrypt the first ciphertext and the first public key on the beacon side, so as to obtain the second ciphertext.

[0161] After obtaining the second ciphertext, the second ciphertext can be sent to the unmanned system.

[0162] After receiving the second ciphertext, the unmanned system can decrypt the second ciphertext using the second private key to obtain the first ciphertext and the first public key, and decrypt the first ciphertext using the first public key to obtain the unmanned system identifier, random number, and timestamp. Among them, the second private key and the second public key are paired keys.

[0163] On the basis of the above solution, the beacon side can also generate a digest value corresponding to the second ciphertext and send the second ciphertext and the digest value to the unmanned system at the same time. Specifically, the beacon side can process the second ciphertext based on the SM3 cryptographic hash algorithm to obtain the first digest value corresponding to the second ciphertext. Furthermore, the second ciphertext and the first digest value can be sent to the unmanned system for the unmanned system to verify the first digest value, and after the first digest value is verified, the second ciphertext is decrypted using the second private key.

[0164] The ciphertext encryption and transmission process can be as follows:

[0165] 1. The beacon side encrypts the ciphertext and the beacon public key using the unmanned system public key to obtain the ciphertext , and calculates the SM3 digest value HB of the ciphertext . Furthermore, the beacon side can send the ciphertext and the digest HB to the unmanned system. The encryption formula can be: . The digest generation formula can be: .

[0166] 2. Ciphertext verification and decryption: The unmanned system center side calculates the digest value HC (that is, the unmanned system processes the second ciphertext using the SM3 cryptographic hash algorithm to obtain the digest value), verifies whether it is consistent with HB, and returns authentication failure if it is inconsistent. After verification, use the unmanned system private key to decrypt to obtain the ciphertext and the beacon public key . Among them, the digest calculation formula can be: . The decryption formula can be: .

[0167] The unmanned system can decrypt using the beacon side public key Obtain the "unmanned system ID, random number R, and timestamp TS0". The decryption formula can be: 。

[0168] Step 105: Generate a first system key according to the unmanned system identifier and the timestamp.

[0169] After completing the sending of the second ciphertext and the ciphertext decryption process of the unmanned system, the beacon system can generate a first system key according to the unmanned system identifier and the timestamp. At the same time, the unmanned system can also generate a second system key according to the unmanned system identifier and the timestamp. That is, the beacon side generates a key according to the unmanned system ID and the timestamp TSt (current time, accurate to minutes) 。The unmanned system center side generates a key according to the unmanned system ID and the timestamp TSt (current time, accurate to minutes) 。

[0170] The generation formula of the system key can be:

[0171] Beacon side: 。

[0172] Unmanned system: 。

[0173] In this embodiment, the first system key can also be updated regularly. Specifically, the generation time of the first system key can be recorded, and when the interval period between the current time and the generation time reaches a set duration, the first system key can be updated.

[0174] It can be understood that the second system key on the unmanned system side can also be updated according to the set duration to ensure the consistency of the system keys on the unmanned system and the beacon system sides.

[0175] After generating the first key system, execute step 106.

[0176] Step 106: Encrypt the unmanned system identifier and the timestamp using the first system key to obtain a third ciphertext, and send the third ciphertext to the unmanned system, so that the unmanned system decrypts the third ciphertext using the second system key to obtain decryption information, and when the decryption information is consistent with the relevant information on the unmanned system side, it is determined that the authentication is successful; the second system key is the key generated by the unmanned system according to the unmanned system identifier and the timestamp.

[0177] After generating the first key system, the first system key can be used to encrypt the unmanned system identifier and the timestamp to obtain the third ciphertext, and the third ciphertext is sent to the unmanned system, so that the unmanned system decrypts the third ciphertext using the second system key to obtain the decryption information, and when the decryption information is consistent with the relevant information on the unmanned system side, it is determined that the authentication is successful, where the second system key can be a key generated by the unmanned system according to the unmanned system identifier and the timestamp.

[0178] In this example, the relevant information on the unmanned system side can be the unmanned system identifier and the timestamp stored on the unmanned system side.

[0179] When sending the third ciphertext, the beacon system can also perform SM3 processing on the third ciphertext to generate a digest value of the third ciphertext, so as to send the third ciphertext and the digest value to the unmanned system at the same time. The unmanned system first verifies the digest value. After the verification passes, it can perform subsequent processing on the third ciphertext. Specifically, the beacon system can process the third ciphertext based on the SM3 cryptographic hash algorithm to obtain a second digest value corresponding to the third ciphertext. Furthermore, the third ciphertext and the second digest value can be sent to the unmanned system, so that the unmanned system verifies the second digest value, and after the second digest value verification passes, uses the second system key to decrypt the third ciphertext.

[0180] For the encryption and transmission process on the beacon system side, it can be:

[0181] The beacon system uses the first system key to encrypt "unmanned system ID + timestamp TSt" to generate the third ciphertext , and calculate the second digest value HB1 of the third ciphertext . Furthermore, the third ciphertext and the second digest value HB1 can be sent to the unmanned system.

[0182] The encryption formula can be: .

[0183] The formula for generating the second digest value can be: .

[0184] For the decryption and authentication process on the unmanned system side, it can be:

[0185] The unmanned system center side verifies the digest value, calculates the digest HC1 (which can be obtained by performing SM3 processing on the third ciphertext ), verifies whether it is consistent with HB1. If not, it returns authentication failure.

[0186] If the digest value verification passes, the unmanned system center side uses the second system key to decrypt the third ciphertext Decryption is performed. If the decryption is successful, the unmanned system ID and the timestamp TSt are obtained and compared with the unmanned system ID and the timestamp TSt stored locally. If the information is consistent, the authentication is successful.

[0187] Among them, the calculation formula of the digest HC1 can be: 。

[0188] The decryption formula can be: 。

[0189] After the beacon system and the unmanned system are successfully authenticated, the authentication time of this successful authentication can be recorded. When the interval period between the current time and the authentication time reaches the authentication duration, the authentication process with the unmanned system is re-executed. After each authentication, the old key is destroyed, and the above authentication steps are repeated to achieve dynamic authentication with the unmanned system.

[0190] For the current dynamic authentication process between the unmanned system center side and the beacon, it can be as Figure 2 shown, and it can include:

[0191] 1. Device initialization: The same symmetric key is built into the beacon and the UAV center side, and their respective public and private key pairs are generated separately.

[0192] 2. Key exchange: (1) The UAV encrypts its own public key using the symmetric key, and sends the public key and the symmetric key to the beacon. The beacon decrypts the UAV public key using the symmetric key. (2) The beacon performs lattice operation encryption on "UAV ID + random number + timestamp" using the private key to generate the ciphertext C1. (3) Encrypt the ciphertext C1 and the beacon public key using the UAV's public key to obtain the ciphertext C2, and perform SM3 digest on the ciphertext C2, and send the ciphertext and the digest value to the UAV together. (4) The UAV first verifies the digest value. After passing, it decrypts the ciphertext C1 and the beacon public key using the private key. (5) Decrypt the ciphertext C1 using the beacon public key to obtain the UAV ID, random number, and timestamp.

[0193] 3. Generate authentication key: (1) The beacon and the UAV center side generate a key respectively according to the UAV ID and the timestamp (current time). (2) The beacon encrypts "UAV ID and timestamp" using the generated key, and performs SM3 digest on the ciphertext, and sends it to the UAV regularly. (3) The UAV verifies the digest value, decrypts it using the generated key, and performs authentication. If the information is consistent, the authentication is successful.

[0194] 4. Continuous authentication: Subsequently, every minute, the beacon and the UAV update the key regularly according to "UAV ID + timestamp" and destroy the old key, and repeat the above process.

[0195] In the embodiments of the present application, by periodically updating the secret key and destroying the old secret key, the security and timeliness of the secret key are ensured, and forward security is achieved. Compared with traditional authentication methods, the optimization of algorithms and protocol design reduces the computational complexity and is applicable to resource-constrained Internet of Things devices and unmanned systems. Through dynamic secret key generation and update, the computational intensity of each authentication is reduced, the authentication efficiency is improved, and the efficiency and lightness of the authentication process are realized.

[0196] The method for secure authentication with an unmanned system provided by the embodiments of the present application generates a locally paired first public key and first private key. The encrypted public key sent by the unmanned system is decrypted using the first symmetric key to obtain the second public key of the unmanned system. The encrypted public key is obtained by the unmanned system encrypting the second public key generated on the unmanned system side using the second symmetric key. The first symmetric key and the second symmetric key are the same key. The lattice encryption operation is performed on the unmanned system identifier, random number, and timestamp of the unmanned system using the first private key to obtain the first ciphertext. The second public key is used to encrypt the first ciphertext and the first public key to obtain the second ciphertext, and the second ciphertext is sent to the unmanned system for the unmanned system to decrypt the second ciphertext using the second private key to obtain the first ciphertext and the first public key, and use the first public key to decrypt the first ciphertext to obtain the unmanned system identifier, random number, and timestamp. The second private key and the second public key are paired keys. According to the unmanned system identifier and timestamp, the first system key is generated. The first system key is used to encrypt the unmanned system identifier and timestamp to obtain the third ciphertext, and the third ciphertext is sent to the unmanned system for the unmanned system to decrypt the third ciphertext using the second system key to obtain the decryption information, and when the decryption information is consistent with the relevant information on the unmanned system side, the authentication is determined to be successful. The second system key is the key generated by the unmanned system according to the unmanned system identifier and timestamp. In the embodiments of the present application, by embedding the same symmetric key in the unmanned system and the beacon system and using the paired key pairs for authentication respectively, the method of cracking the secret key can be reduced, and the authentication security can be improved. At the same time, using the lattice-based encryption algorithm for key exchange can ensure the security of the key exchange process, resist quantum computing attacks, and further improve the authentication security.

[0197] Refer to Figure 4 , which shows a schematic structural diagram of a device for secure authentication with an unmanned system provided by the embodiments of the present application. This device can be applied to a beacon system. As Figure 4 shown, the device 400 for secure authentication with an unmanned system may include the following modules:

[0198] The paired key generation module 410 is used to generate a locally paired first public key and first private key;

[0199] An encryption public key decryption module 420 is configured to decrypt the encrypted public key sent by the unmanned system by using a first symmetric key to obtain a second public key of the unmanned system. The encrypted public key is obtained by encrypting the second public key generated on the unmanned system side by the unmanned system by using a second symmetric key. The first symmetric key and the second symmetric key are the same key;

[0200] A first ciphertext generation module 430 is configured to perform lattice encryption operation on the unmanned system identifier, random number, and timestamp of the unmanned system by using the first private key to obtain a first ciphertext;

[0201] A second ciphertext sending module 440 is configured to encrypt the first ciphertext and the first public key by using the second public key to obtain a second ciphertext, and send the second ciphertext to the unmanned system, so that the unmanned system decrypts the second ciphertext by using a second private key to obtain the first ciphertext and the first public key, and decrypts the first ciphertext by using the first public key to obtain the unmanned system identifier, random number, and timestamp. The second private key and the second public key are paired keys;

[0202] A system key generation module 450 is configured to generate a first system key according to the unmanned system identifier and the timestamp;

[0203] A third ciphertext sending module 460 is configured to encrypt the unmanned system identifier and timestamp by using the first system key to obtain a third ciphertext, and send the third ciphertext to the unmanned system, so that the unmanned system decrypts the third ciphertext by using a second system key to obtain decryption information, and determines that the authentication is successful when the decryption information is consistent with the relevant information on the unmanned system side; the second system key is a key generated by the unmanned system according to the unmanned system identifier and the timestamp.

[0204] Optionally, the paired key generation module includes:

[0205] A pseudo-random seed generation unit is configured to process a pre-input randomness parameter with a specified number of digits and a predefined fixed parameter by using a pseudo-random number generator to generate a first pseudo-random seed and a second pseudo-random seed;

[0206] A matrix generation unit is configured to generate a K×K matrix based on the first pseudo-random seed and the number of rows and columns of the matrix, where K is a positive integer;

[0207] A vector generation unit is configured to generate a first vector and a second vector according to the matrix elements of the K×K matrix, the second pseudo-random seed, and the current authentication times value;

[0208] A frequency-domain representation obtaining unit, configured to perform k number-theoretic transform processes on the first vector and the second vector respectively, to obtain corresponding first and second frequency-domain representations;

[0209] A combined frequency-domain representation obtaining unit, configured to perform a linear combination operation on the first frequency-domain representation and the second frequency-domain representation, to obtain a linearly combined frequency-domain representation;

[0210] A key obtaining unit, configured to perform encoding processes on the first frequency-domain representation and the linearly combined frequency-domain representation respectively, to obtain the first public key and the first private key.

[0211] Optionally, the first ciphertext generation module includes:

[0212] A basis vector generation unit, configured to generate basis vectors of a lattice;

[0213] A message vector obtaining unit, configured to encode the unmanned system identifier, the random number, and the time stamp, to obtain a message vector;

[0214] A target vector obtaining unit, configured to encode the message vector into a target vector on the basis vectors of the lattice;

[0215] A first ciphertext generation unit, configured to perform a lattice transformation on the target vector based on the first private key, to generate the first ciphertext.

[0216] Optionally, the second ciphertext sending module includes:

[0217] A first digest value obtaining unit, configured to process the second ciphertext based on the SM3 cryptographic hash algorithm, to obtain a first digest value corresponding to the second ciphertext;

[0218] A second ciphertext sending unit, configured to send the second ciphertext and the first digest value to the unmanned system, so that the unmanned system verifies the first digest value, and after the first digest value is verified successfully, decrypts the second ciphertext using the second private key.

[0219] Optionally, the third ciphertext sending module includes:

[0220] A second digest value obtaining unit, configured to process the third ciphertext based on the SM3 cryptographic hash algorithm, to obtain a second digest value corresponding to the third ciphertext;

[0221] A third ciphertext sending unit, configured to send the third ciphertext and the second digest value to the unmanned system, so that the unmanned system verifies the second digest value, and after the second digest value is verified successfully, decrypts the third ciphertext using a second system key.

[0222] Optionally, the device further includes:

[0223] A generation time recording module, configured to record the generation time of the first system key;

[0224] A system key update module, configured to update the first system key when the interval period between the current time and the generation time reaches a set duration.

[0225] Optionally, the device further includes:

[0226] An authentication time recording module, configured to record the authentication time of the successful authentication after the successful authentication with the unmanned system;

[0227] An authentication process execution module, configured to re-execute the authentication process with the unmanned system when the interval period between the current time and the authentication time reaches the authentication duration.

[0228] The device for secure authentication with an unmanned system provided by an embodiment of the present application generates a locally paired first public key and first private key. The encrypted public key sent by the unmanned system is decrypted using the first symmetric key to obtain the second public key of the unmanned system. The encrypted public key is obtained by the unmanned system encrypting the second public key generated on the unmanned system side using the second symmetric key. The first symmetric key and the second symmetric key are the same key. The unmanned system identifier, random number, and timestamp of the unmanned system are subjected to lattice encryption operation using the first private key to obtain a first ciphertext. The first ciphertext and the first public key are encrypted using the second public key to obtain a second ciphertext, and the second ciphertext is sent to the unmanned system, so that the unmanned system decrypts the second ciphertext using the second private key to obtain the first ciphertext and the first public key, and uses the first public key to decrypt the first ciphertext to obtain the unmanned system identifier, random number, and timestamp. The second private key and the second public key are paired keys. According to the unmanned system identifier and timestamp, a first system key is generated. The unmanned system identifier and timestamp are encrypted using the first system key to obtain a third ciphertext, and the third ciphertext is sent to the unmanned system, so that the unmanned system decrypts the third ciphertext using the second system key to obtain decryption information, and when the decryption information is consistent with the relevant information on the unmanned system side, it is determined that the authentication is successful. The second system key is the key generated by the unmanned system according to the unmanned system identifier and timestamp. By embedding the same symmetric key in the unmanned system and the beacon system and using the paired key pairs for authentication, the method of cracking the key can be reduced and the authentication security can be improved. At the same time, using the lattice-based encryption algorithm for key exchange can ensure the security of the key exchange process, resist quantum computing attacks, and further improve the authentication security.

[0229] An embodiment of the present application provides an electronic device, including: a memory, a processor, and a computer program stored on the memory and executable on the processor. When the computer program is executed by the processor, the above method for performing security authentication with an unmanned system is implemented.

[0230] Figure 5 FIG. 4 shows a schematic structural diagram of an electronic device 500 according to an embodiment of the present invention. As Figure 5 shown, the electronic device 500 includes a central processing unit (CPU) 501, which can execute various appropriate actions and processes according to computer program instructions stored in a read-only memory (ROM) 502 or computer program instructions loaded from a storage unit 508 into a random access memory (RAM) 503. In the RAM 503, various programs and data required for the operation of the electronic device 500 can also be stored. The CPU 501, the ROM 502, and the RAM 503 are connected to each other through a bus 504. An input / output (I / O) interface 505 is also connected to the bus 504.

[0231] Multiple components in the electronic device 500 are connected to the I / O interface 505, including: an input unit 506, such as a keyboard, a mouse, a microphone, etc.; an output unit 507, such as various types of displays, speakers, etc.; a storage unit 508, such as a magnetic disk, an optical disc, etc.; and a communication unit 509, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 509 allows the electronic device 500 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.

[0232] Each of the above processes and treatments can be executed by the processing unit 501. For example, the method of any of the above embodiments can be implemented as a computer software program, which is tangibly included in a computer-readable medium, such as the storage unit 508. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 500 via the ROM 502 and / or the communication unit 509. When the computer program is loaded into the RAM 503 and executed by the CPU 501, one or more actions in the above-described method can be executed.

[0233] An embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, each process of the above embodiment of the method for performing security authentication with an unmanned system is implemented, and the same technical effects can be achieved. To avoid repetition, it will not be described in detail here. Among them, the computer-readable storage medium is, for example, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disc, etc.

[0234] It should be noted that, in this article, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, such that a process, method, article or device comprising a series of elements not only includes those elements but also includes other elements not explicitly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising one..." does not exclude the existence of additional identical elements in the process, method, article or device comprising such element.

[0235] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-described method of the embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases the former is a better implementation. Based on such understanding, the technical solution of the present application, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions for causing a terminal (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of the present application.

[0236] The embodiments of the present application have been described above in conjunction with the accompanying drawings. However, the present application is not limited to the above specific embodiments. The above specific embodiments are merely illustrative and not restrictive. Under the inspiration of the present application, those of ordinary skill in the art can also make many forms without departing from the purpose of the present application and the scope protected by the claims, and all of them belong to the protection scope of the present application.

[0237] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in connection with the embodiments disclosed in the embodiments of the present application can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.

[0238] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.

[0239] In the embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the devices or units can be in electrical, mechanical or other forms.

[0240] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0241] In addition, in each embodiment of the present application, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit.

[0242] If the functions are implemented in the form of software function units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, ROM, RAM, magnetic disks, or optical discs that can store program codes.

[0243] As described above, it is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed in the present application, and all of them should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A method for secure authentication with an unmanned system, applied to a beacon system, characterized in that Including: Generating a first public key and a first private key for local pairing; Using the first symmetric key to decrypt the encrypted public key sent by the unmanned system to obtain the second public key of the unmanned system. The encrypted public key is obtained by the unmanned system encrypting the second public key generated on the unmanned system side using the second symmetric key. The first symmetric key and the second symmetric key are the same key; Performing lattice encryption operation on the unmanned system identifier, random number, and timestamp of the unmanned system using the first private key to obtain a first ciphertext; Using the second public key to encrypt the first ciphertext and the first public key to obtain a second ciphertext, and sending the second ciphertext to the unmanned system, so that the unmanned system decrypts the second ciphertext using the second private key to obtain the first ciphertext and the first public key, and uses the first public key to decrypt the first ciphertext to obtain the unmanned system identifier, random number, and timestamp. The second private key and the second public key are paired keys; Generating a first system key according to the unmanned system identifier and the timestamp; Using the first system key to encrypt the unmanned system identifier and timestamp to obtain a third ciphertext, and sending the third ciphertext to the unmanned system, so that the unmanned system decrypts the third ciphertext using the second system key to obtain decryption information, and determines that the authentication is successful when the decryption information is consistent with the relevant information on the unmanned system side. The second system key is a key generated by the unmanned system according to the unmanned system identifier and the timestamp.

2. The method according to claim 1, wherein The generating the first public key and the first private key for local pairing includes: Using a pseudo-random number generator to process a pre-input randomness parameter with a specified number of digits and a predefined fixed parameter to generate a first pseudo-random seed and a second pseudo-random seed; Generating a K×K matrix based on the first pseudo-random seed and the number of rows and columns of the matrix, where K is a positive integer; Generating a first vector and a second vector according to the matrix elements of the K×K matrix, the second pseudo-random seed, and the current authentication count value; Performing k number-theoretic transform processes on the first vector and the second vector respectively to obtain corresponding first frequency-domain representations and second frequency-domain representations; Performing a linear combination operation on the first frequency-domain representation and the second frequency-domain representation to obtain a linear combination frequency-domain representation; Performing encoding processes on the first frequency-domain representation and the linear combination frequency-domain representation respectively to obtain the first public key and the first private key.

3. The method according to claim 1, wherein The performing lattice encryption operation on the unmanned system identifier, random number, and timestamp of the unmanned system using the first private key to obtain a first ciphertext includes: Generating a basis vector of the lattice; Encoding the unmanned system identifier, the random number, and the timestamp to obtain a message vector; Encoding the message vector as a target vector on the basis vector of the lattice; Based on the first private key, performing a lattice transformation on the target vector to generate the first ciphertext.

4. The method according to claim 1, wherein The sending the second ciphertext to the unmanned system includes: Process the second ciphertext based on the SM3 cryptographic hash algorithm to obtain the first digest value corresponding to the second ciphertext; Send the second ciphertext and the first digest value to the unmanned system, so that the unmanned system verifies the first digest value, and after the first digest value is verified, decrypt the second ciphertext using the second private key.

5. The method according to claim 1, wherein The sending the third ciphertext to the unmanned system includes: Process the third ciphertext based on the SM3 cryptographic hash algorithm to obtain the second digest value corresponding to the third ciphertext; Send the third ciphertext and the second digest value to the unmanned system, so that the unmanned system verifies the second digest value, and after the second digest value is verified, decrypt the third ciphertext using the second system key.

6. The method according to claim 1, wherein After generating the first system key according to the unmanned system identifier and the timestamp, it further includes: Record the generation time of the first system key; Update the first system key when the interval period between the current time and the generation time reaches the set duration.

7. The method according to claim 1, characterized in that, After encrypting the unmanned system identifier and the timestamp using the first system key to obtain the third ciphertext and sending the third ciphertext to the unmanned system, it further includes: After successfully authenticating with the unmanned system, record the authentication time of this successful authentication; When the interval period between the current time and the authentication time reaches the authentication duration, re-execute the authentication process with the unmanned system.

8. A device for secure authentication with an unmanned system, applied to a beacon system, characterized in that, It includes: A pairing key generation module for generating a locally paired first public key and first private key; An encrypted public key decryption module for decrypting the encrypted public key sent by the unmanned system using the first symmetric key to obtain the second public key of the unmanned system. The encrypted public key is obtained by the unmanned system encrypting the second public key generated on the unmanned system side using the second symmetric key. The first symmetric key and the second symmetric key are the same key; A first ciphertext generation module for performing lattice encryption operations on the unmanned system identifier, random number, and timestamp of the unmanned system using the first private key to obtain the first ciphertext; A second ciphertext sending module for encrypting the first ciphertext and the first public key using the second public key to obtain the second ciphertext, and sending the second ciphertext to the unmanned system, so that the unmanned system decrypts the second ciphertext using the second private key to obtain the first ciphertext and the first public key, and decrypts the first ciphertext using the first public key to obtain the unmanned system identifier, random number, and timestamp. The second private key and the second public key are paired keys; A system key generation module for generating a first system key according to the unmanned system identifier and the timestamp; The third ciphertext sending module is used to encrypt the unmanned system identifier and the timestamp by using the first system key to obtain a third ciphertext, and send the third ciphertext to the unmanned system, so that the unmanned system decrypts the third ciphertext by using the second system key to obtain decryption information, and determines that the authentication is successful when the decryption information is consistent with the relevant information on the unmanned system side; the second system key is a key generated by the unmanned system according to the unmanned system identifier and the timestamp.

9. An electronic device, characterized in that, Comprising: A memory, a processor, and a computer program stored on the memory and executable on the processor, where the computer program, when executed by the processor, implements the method for secure authentication with an unmanned system according to any one of claims 1 to 7.

10. A readable storage medium, characterized in that, When the instructions in the storage medium are executed by the processor of the electronic device, the electronic device is enabled to execute the method for secure authentication with an unmanned system according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Identity-based authentication key negotiation method based on lattice

    CN114268439A

  • Public / private key system with increased security

    CN114902605A