Multi-factor security authentication method for unmanned aerial vehicle emergency rescue access control
By adopting a multi-factor security authentication method in the UAV emergency rescue application scenarios, combining password, biometrics and PUF technologies, the problems of privacy leakage, physical capture and high overhead are solved, and higher security and lower computing overhead are achieved.
Patent Information
- Application Number
- CN202510262576.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-06
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-03-06
AI Technical Summary
There are problems such as privacy leakage, physical capture of drones and high computing overhead in existing drone-assisted emergency rescue applications.
The multi-factor security authentication method is adopted to integrate passwords, biometrics and physical non-cloneable functions (PUFs) on the user side to realize the unique binding between the user and the rescue vehicle, and integrate PUFs in the drone to prevent physical attacks. Construct the session key using Chebishev Chaos Map to ensure forward confidentiality.
Enhanced security of user endpoints, prevent unauthorized access, protect the privacy of rescue data, reduce computing overhead, and meet the high response and low overhead requirements of real-time rescue scenarios.
Smart Images

Figure CN119997019A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of unmanned aerial vehicle (UAV) security applications, and in particular to a multi-factor security authentication method for unmanned aerial vehicle (UAV) emergency rescue access control. Background Art
[0002] In recent years, disasters such as floods and earthquakes have occurred frequently, bringing immeasurable economic losses and serious security threats. These disasters may cause roads to be damaged or blocked, making it difficult for rescue vehicles to enter the disaster area, or even completely inaccessible. Seriously delaying the implementation of rescue operations. At the same time, the damage to basic equipment and the interruption of communications have made it impossible to effectively transmit real-time information from the disaster area to rescue personnel and rescue vehicles, which has also brought great difficulties to the rescue operations. In addition, since the victims are usually scattered, rescue personnel and vehicles cannot fully cover all disaster-stricken areas in a timely manner, which further increases the difficulty of rescue. UAVs have become the best choice for auxiliary rescue due to their advantages such as rapid response, flexibility and mobility, and freedom from geographical and terrain restrictions. UAVs are equipped with advanced cameras, infrared thermal imagers, laser radars and other equipment. Through aerial images and videos, they can quickly search the disaster area, understand the severity and scope of the disaster, and promptly find trapped people and vehicles. UAVs can fly over a large area of disaster-stricken areas, and evaluate and monitor road and traffic conditions in real time by checking the integrity, passability and presence of obstacles on the road, providing rescue vehicles with real-time road information and the best rescue path. At the same time, as a temporary communication relay, the communication equipment in the drone can help rescuers keep in touch with people in the disaster area, transmit rescue instructions, collect help information, and provide real-time communication support. To ensure secure communication between various entities, a reliable identity authentication mechanism needs to be established between the user rescue vehicle and the drone before the rescue data is transmitted to prevent unauthorized users from illegally accessing the drone's real-time data information.
[0003] The existing authentication protocols have the following problems and shortcomings:
[0004] 1) Both the two-factor and three-factor authentication schemes used in existing protocols face security issues such as password cracking, smart card loss, or biometric information leakage, and the independent verification mechanism between rescue personnel and vehicles does not fully solve the security issues on the user device side.
[0005] 2) When drones are performing rescue missions, the information collected and transmitted usually involves private information such as the disaster situation, rescue routes, and personnel locations. Once this information is intercepted, tampered with, or deleted, it will lead to rescue personnel not being able to rescue in time, delaying the implementation of rescue, and even endangering lives. How to protect the anonymity of data privacy information during the identity authentication process is a key issue that existing technologies lack.
[0006] 3) Existing solutions do not consider the response mechanism for application scenarios where mobile devices are physically captured. Rescue vehicles and drones are highly mobile during mission execution. Once captured by an adversary, there may be a risk of being impersonated or destroyed.
[0007] 4) Most of the cryptographic protection mechanisms designed by existing schemes are based on expensive cryptographic primitives such as bilinear pairings and elliptic curve signatures, which result in high computational overhead. This is not practical for drones with limited computing, storage, and power. Summary of the invention
[0008] In view of the problems of privacy leakage, physical capture of drones and high overhead in drone-assisted emergency rescue application scenarios in the prior art, the present invention provides a multi-factor security authentication method for drone emergency rescue access control. The user rescue vehicle, with the authorization assistance of the rescue center, realizes security authentication and key negotiation with the drone. In order to enhance the security of the user endpoint, the user is uniquely bound to the rescue vehicle to ensure that only legitimate users with authorized devices can access it. At the same time, PUF is integrated into the rescue vehicle and the remote drone to prevent physical attacks. In addition, Chebyshev chaotic mapping is used to construct the session key between the user rescue vehicle and the remote drone to maintain perfect forward secrecy.
[0009] The present invention provides a multi-factor security authentication method for unmanned aerial vehicle emergency rescue access control, including an initialization phase, a registration phase, a login phase, and an authentication and key negotiation phase;
[0010] The initialization stage: the rescue center RC publishes initialization related parameter information; the related parameters include the secret extraction function BF(·), the secret reconstruction function RF(·), the single hash function h:{0,1} * and physical unclonable function PUF(·);
[0011] The registration phase includes the drone registration phase and the user and rescue vehicle registration phase;
[0012] The drone registration stage: UAV j Complete registration with the rescue center RC based on its own PUF response;
[0013] The user and rescue vehicle registration stage: User U i Based on identity ID i and password RPW i Send a registration application to the rescue center RC, and the rescue center RC will feedback the registration information to the user U after receiving it. i , user U i The registration information and biometric BIO i Send to rescue vehicle RVi , rescue vehicle RV i Complete registration with the rescue center RC based on its own PUF and the information received;
[0014] The login stage: User U i Password-based RPW i and biometrics i RV with rescue vehicle i Bind and rescue vehicle RV i Send verification message to the rescue center RC based on Chebyshev polynomial, and the rescue center RC will successfully log in after verification;
[0015] The authentication and key negotiation phase: User U i and rescue vehicle RV i UAV j With the assistance of the rescue center RC, they authenticate each other and negotiate a shared session key SK.
[0016] Furthermore, the specific process of the drone registration stage is as follows:
[0017] UAV j ID j Sent to the rescue center RC, the rescue center RC generates a set of random challenges Send to UAV j ;
[0018] UAV j Receive random challenge C j Then based on its own PUF (·), it generates the corresponding response R j =PUF(C j ), and the response Send to rescue center RC;
[0019] Rescue Center RC received the UAV j The response R j Generate drone anonymous identity DID j =h(ID j ||R j ), and {C j ,DID j}Stored in the rescue center database.
[0020] Furthermore, the specific process of the user and rescue vehicle registration stage is as follows:
[0021] UserU i Select ID i 、Password PW i and random numbers Calculate the anonymous password RPW i =h(PW i ||s i ), the anonymous password RPW i and the drone ID that the user wishes to access j Sent to the rescue center RC; where h() represents a one-way hash function;
[0022] The rescue center RC receives the anonymous password RPW i and the ID of the drone you wish to access j After that, generate a set of random challenges The anonymous identity DID corresponding to the drone that the user wants to access j and the random challenge C i Return to user U i ;
[0023] UserU i The received {C i ,DID j} and biometric information BIO i Send to rescue vehicle RV i , rescue vehicle RV i Calculate the response R based on its own PUF (·) i =(C i ), intermediate parameters Fusion Features and (UR i ,UP i )=BF(BR i ), where UR i is the secret value, UP i Correction code stored for secret value; while calculating anonymous identity PID i =h(ID i ||R i ), intermediate parameters and authentication message A 0 =h(RPW i ||ID i ||UR i );
[0024] {E i ,UP i ,DID j ,A 0 ,s i} is stored in the rescue vehicle database and the message body {A i ,PID i}To rescue center RC;
[0025] The rescue center RC receives the message body {A i ,PID i}, store {C i ,A i ,PID i} to the rescue center database.
[0026] Furthermore, the specific process of the login stage is as follows:
[0027] UserU i Enter your ID i 、Password PW i and biometrics i To the rescue vehicle RV i ;
[0028] Rescue Vehicle RV i Calculate the anonymous password RPW i ′=h(PW i ||s i ) and Challenges Calculate the response R based on its own PUF i ′=PUF(C i ′), and calculate the fusion feature Secret value UR i ′=RF(BRi′,UPi) and authentication message A0′=h(PPWi′|IDi|URi′), and verify whether A0 and A0′ in the rescue vehicle database are equal. If they are not equal, terminate; if they are equal, user U i and rescue vehicle RV i Successfully bound, continue to the next step;
[0029] Rescue Vehicle RV i Calculate the anonymous identity PID i ′=h(ID i ||R i ′), select a drone anonymous identity DID from the rescue vehicle database j , based on the drone anonymous identity PID j Calculate intermediate parameters and the intermediate parameter N 0 =h(PID i ′||DID j ), select random number s1 as the first temporary secret data, calculate Chebyshev polynomial N 1 =T s1 (N 0 ) and authentication information M 1 =h(DID j ||C i ′||N 1 ||URi ′), send verification message {PID i ′,F i ,N 1 ,M 1}To rescue center RC;
[0030] Rescue Center RC received rescue vehicle RV i The verification message sent {PID i ′,F i ,N 1 ,M 1}, based on PID i 'Find the corresponding challenge C from the database i and A i , then calculate the secret value Drone Anonymity And calculate the authentication information M 1 ′=h(DID j ′||C i ||N 1 ||UR i ″), verify M 1 ′ and M 1 Are they equal? If not, the login is terminated; if they are equal, the login is successful.
[0031] Furthermore, the specific process of the authentication and key agreement phase is as follows:
[0032] The rescue center RC selects the random number s2 as the second temporary secret data and calculates the Chebyshev polynomial Intermediate parameters And based on the drone anonymous identity DID j 'Search for challenge C from the rescue center database j , calculate the authentication information M 2 =h(DID j ′||PID i ||N 1 ||N 2 ), then send the message body {N 1 ,N 2 ,A 1 ,C j ,M 2}For UAV j ;
[0033] UAV j Received message body {N 1 ,N 2 ,A 1 ,C j,M 2}, the rescue center RC uses the PID obtained in the previous step i and DID j ′, calculate the same N as the user end 0 =h(PID i ||DID j ′), then select the random number s3 as the third temporary secret data, calculate the Chebyshev polynomial N 3 =T s3 (N 0 ),get And obtain the shared key SK = T s3 (N 1 ) and M 3 =h(SK||DID j ′||PID i ||N 1 ||N 3 ), and finally the message body {A 2 ,M 3}Send to rescue vehicle RV i ;
[0034] Rescue Vehicle RV i Receive UAV j The message body sent 2 ,M 3}, calculate and SK=T s1 (N 3 ), and calculate the authentication information M 3 ′=h(SK||DID j ||PID i ′||N 1 ||N 3 ), verify M 3 ′ and M 3 Are they equal? If they are equal, authentication succeeds; if they are not equal, authentication fails.
[0035] Further, the method also includes a password and biometric update phase;
[0036] Password and biometric update phase: User U i Enter your ID i ,Old Password and old biometric features To the rescue vehicle RV i , rescue vehicle RV i For User U i The old password and old biometrics are verified, and after verification, the user enters the identity ID i ,New Password and new biometric features And update the rescue vehicle RV based on the new password and new biometrics i The corresponding information in the database and the rescue center RC database.
[0037] Furthermore, the specific process of the password and biometric update stage is as follows:
[0038] UserU i First enter a unique ID i ,Old Password and old biometric features To the rescue vehicle RV i , rescue vehicle RV i Calculate anonymous password challenge Calculate R based on its own PUF (·) i =PUF(C i ), and calculate the fusion features Secret value UR i ′=RF(BR i ,UP i ) and A 0 ′=h(RPW i ||ID i ||UR i ′), and verify equation A 0 ′ and A 0 Are they equal? If not, terminate; otherwise, the rescue vehicle RV i To user U i Request a new password and new biometrics;
[0039] After receiving the request, user U i To the rescue vehicle RV i Input ID i , new and Rescue Vehicle RV i Calculate a new anonymous password Select an unused vehicle from the rescue vehicle database Calculate new Calculate a new response based on its own PUF (·) At the same time, new fusion features are calculated and Rescue Vehicle RV i use Replace {E in the rescue vehicle database i ,UP i ,DID j ,A 0 ,s i}; Rescue Vehicle RVi calculate And the new message body The rescue center RC receives the Stored in the rescue center database.
[0040] Furthermore, after the session is completed using the shared session key SK negotiated in the authentication and key agreement phase, the user password and biometric update phase is executed to update the information.
[0041] The beneficial effects of the present invention are:
[0042] (1) This invention proposes a security enhancement scheme based on password, biometrics and PUF. By integrating user biometrics and device PUF response at the user end, the device is bound to the user to prevent unauthorized users from logging in illegally. PUF is also used to protect rescue vehicles and remote drones from physical attacks. Password and biometric update mechanisms are applied to prevent password guessing and biometric leakage.
[0043] (2) Taking into account the limited resources of drones, the present invention adopts only lightweight cryptographic operations such as hashing and XOR to realize mutual authentication between rescue vehicles and drones, and realizes the session key negotiation between the two parties based on Chebyshev chaos mapping technology, thus avoiding complex public key operations. It has certain advantages in performance overhead such as computing, storage, and communication, and meets the high-response and low-overhead authentication requirements of real-time rescue emergency scenarios.
[0044] (3) Based on the 17 security goals proposed in this invention, the protocol is systematically analyzed, and the security of the proposed solution is proved from the information interaction level. Compared with the latest security protocols, the present invention is the only winner that meets all the set security attributes. In addition, the present invention maintains zero storage overhead, as well as low computational and communication overhead. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] Figure 1 A schematic diagram of a system simulation in a drone emergency rescue scenario provided by an embodiment of the present invention;
[0046] Figure 2 One of the feature fusion binding schematic diagrams provided in an embodiment of the present invention;
[0047] Figure 3 The second schematic diagram of feature fusion binding provided by an embodiment of the present invention;
[0048] Figure 4 A schematic diagram of a system flow of a security authentication method provided by an embodiment of the present invention;
[0049] Figure 5A schematic diagram of a drone registration process of a security authentication method provided by an embodiment of the present invention;
[0050] Figure 6 A schematic diagram of the user and rescue vehicle registration process of the safety authentication method provided in an embodiment of the present invention;
[0051] Figure 7 A schematic diagram of the login, authentication and key negotiation process of the security authentication method provided by an embodiment of the present invention;
[0052] Figure 8 Schematic diagram of OFMC and CL-ATSE results of AVISPA formal verification provided by the embodiment of the present invention;
[0053] Fig. 9 Schematic diagram of SPAN simulation results of AVISPA formal verification provided in an embodiment of the present invention. DETAILED DESCRIPTION
[0054] In order to make the purpose, technical solution and advantages of the present invention clearer, the technical solution in the embodiment of the present invention will be clearly described below in conjunction with the drawings in the embodiment of the present invention. Obviously, the described embodiment is a part of the embodiment of the present invention, not all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0055] Embodiment 1:
[0056] like Figure 1 As shown, the system in the drone emergency rescue scenario simulated by the embodiment of the present invention provides a multi-factor security authentication method for drone emergency rescue access control, including an initialization phase, a registration phase, a login phase, and an authentication and key negotiation phase;
[0057] Initialization phase: The rescue center RC publishes initialization-related parameter information; the relevant parameters include feature fusion extraction functions BF(·) and RF(·), single-term hash function h:{0,1} * and the Physical Unclonable Function PUF(·).
[0058] Among them, Figure 2 As shown, the secret extraction algorithm (UR i ,UP i )=BF(BR i ): This algorithm uses the user device fusion feature BR i As input, output a secret value UR i and the secretly stored correction code UP i .
[0059] like Figure 3 As shown, the secret reconstruction algorithm UR i =RF(BR i ′,UP i ): Given fusion feature BR i ′ and the stored correction code UP i , the algorithm outputs a secret value UR i ′. When BR i and BR i ′ is less than the fault tolerance threshold τ, then UR i ′=UR i Among them, BR i =BIO i ⊕R i , BIO i and R i Represent two different characteristics, UP i Is used to recover the secret value UR i Correction code.
[0060] like Figure 4 As shown, the embodiment of the present invention provides a schematic diagram of the interaction between the parties of the method, including the following stages:
[0061] Registration phase: includes the drone registration phase and the user and rescue vehicle registration phase;
[0062] Drone Registration Stage: UAV j Complete registration with the rescue center RC based on its own PUF response.
[0063] During the drone registration phase, before the drone is deployed to a specific area, the rescue center RC first needs to register the drone that will perform this mission and recognize its legal identity. Figure 5 As shown in the figure, the specific process of drone registration is as follows:
[0064] UAV j ID j Sent to the rescue center RC, the rescue center RC generates a set of random challenges Send to UAV j ;
[0065] UAV j Received random challenge C j Then based on its own PUF (·), it generates the corresponding response R j =PUF(C j ), and will respond Send to rescue center RC;
[0066] Rescue Center RC received the UAVj The response R j Generate drone anonymous identity DID j =h(ID j ||R j ), and {C j ,DID j}Stored in the rescue center database.
[0067] User and rescue vehicle registration stage: User U i Based on identity ID i and password RPW i Send a registration application to the rescue center RC, and the rescue center RC will feedback the registration information to the user U after receiving it. i , user U i Registration information and biometrics i Send to rescue vehicle RV i , rescue vehicle RV i Complete registration with the rescue center RC based on its own PUF and the information received;
[0068] During the user and rescue vehicle registration phase, when user U i Want to obtain UAV in a specific area j To obtain real-time data, you must first register with the rescue center RC. Figure 6 As shown, the specific process of the user and rescue vehicle registration stage is as follows:
[0069] UserU i Select ID i 、Password PW i and random numbers Calculate the anonymous password RPW i =h(PW i ||s i ), the anonymous password RPW i and the drone ID that the user wishes to access j Sent to the rescue center RC; where h() represents a one-way hash function;
[0070] Rescue Center RC received anonymous password RPW i and the ID of the drone you wish to access j After that, generate a set of random challenges The anonymous identity DID corresponding to the drone that the user wants to access j and random challenge C i Return to user U i ;
[0071] UserU i The received {C i ,DIDj} and biometric information BIO i Send to rescue vehicle RV i , rescue vehicle RV i Calculate the response R based on its own PUF (·) i =(C i ), intermediate parameters Fusion Features and (UR i ,UP i )=BF(BR i ), where UR i is the secret value, UP i Correction code stored for secret value; while calculating anonymous identity PID i =h(ID i ||R i ), intermediate parameters and authentication message A 0 =h(RPW i ||ID i ||UR i );
[0072] {E i ,UP i ,DID j ,A 0 ,s i} is stored in the rescue vehicle database and the message body {A i ,PID i}To rescue center RC;
[0073] The rescue center RC receives the message body {A i ,PID i}, store {C i ,A i ,PID i} to the rescue center database.
[0074] Login stage: User U i Password-based RPW i and biometrics i RV with rescue vehicle i Bind and rescue vehicle RV i Send verification message to the rescue center RC based on Chebyshev polynomial, and the rescue center RC will successfully log in after verification;
[0075] During the login phase, the user first binds to the rescue vehicle, and then the user and the rescue vehicle log in to the rescue center server. Figure 7 As shown in the figure, the specific process of the login stage is as follows:
[0076] UserU i Enter your ID i 、Password PW i and biometrics i To the rescue vehicle RV i ;
[0077] Rescue Vehicle RV i Calculate the anonymous password RPW i ′=h(PW i ||s i ) and Challenges Calculate the response R based on its own PUF i ′=PUF(C i ′), and calculate the fusion feature Secret value UR i ′=RF(BRi′,UPi) and authentication message A0′=h(RPW i ′|IDi|URi′), and verify whether A0 and A0′ in the rescue vehicle database are equal. If they are not equal, terminate; if they are equal, user U i and rescue vehicle RV i Successfully bound, continue to the next step;
[0078] Rescue Vehicle RV i Calculate the anonymous identity PID i ′=h(ID i ||R i ′), select a drone anonymous identity DID from the rescue vehicle database j , based on drone anonymous identity DID j Calculate intermediate parameters and the intermediate parameter N 0 =h(PID i ′||DID j ), select random number s1 as the first temporary secret data, calculate Chebyshev polynomial N 1 =T s1 (N 0 ) and authentication information M 1 =h(DID j ||C i ′||N 1 ||UR i ′), send verification message {PID i ′,F i ,N 1 ,M 1}To rescue center RC;
[0079] Rescue Center RC received rescue vehicle RV i The verification message sent {PIDi ′,F i ,N 1 ,M 1}, based on PID i 'Find the corresponding challenge C from the database i and A i , then calculate the secret value Drone Anonymity And calculate the authentication information M 1 ′=h(DID j ′||C i ||N 1 ||UR i ″), verify M 1 ′ and M 1 Are they equal? If not, the login is terminated; if they are equal, the login is successful.
[0080] Authentication and key negotiation phase: User U i and rescue vehicle RV i UAV j With the assistance of the rescue center RC, they authenticate each other and negotiate a shared session key SK.
[0081] In the authentication and key negotiation phase, the user, rescue vehicle, and drone authenticate each other with the help of the rescue center and negotiate a shared session key. The session key is based on the Chebyshev chaotic map, which generates different responses for each round of conversation between the rescue vehicle and the drone, ensuring the perfect forward secrecy of the protocol. In addition, the rescue center only participates in the authentication process and not the session negotiation process, avoiding the threat of session key leakage caused by malicious behavior of the rescue center. Figure 7 As shown in the figure, the authentication and key negotiation process is as follows:
[0082] The rescue center RC selects the random number s2 as the second temporary secret data and calculates the Chebyshev polynomial N 2 =s2⊕h(DID j ′), intermediate parameters And based on the drone anonymous identity DID j 'Find challenge C from the rescue center database j , calculate the authentication information M 2 =h(DID j ′||PID i ||N 1 ||N 2 ), then send the message body {N 1 ,N 2 ,A 1 ,C j ,M 2}For UAV j ;
[0083] UAV j Received message body {N 1 ,N 2 ,A 1 ,C j ,M 2}, the rescue center RC uses the PID obtained in the previous step i and DID j ′, calculate the same N as the user end 0 =h(PID i ||DID j ′), then select the random number s3 as the third temporary secret data, calculate the Chebyshev polynomial N 3 =T s3 (N 0 ),get And obtain the shared key SK = T s3 (N 1 ) and M 3 =h(SK||DID j ′||PID i ||N 1 ||N 3 ), and finally the message body {A 2 ,M 3}Send to rescue vehicle RV i ;
[0084] Rescue Vehicle RV i Receive UAV j The message body sent 2 ,M 3}, calculate and SK=T s1 (N 3 ), and calculate the authentication information M 3 ′=h(SK||DID j ||PID i ′||N 1 ||N 3 ), verify M 3 ′ and M 3 Are they equal? If they are equal, authentication succeeds; if they are not equal, authentication fails.
[0085] Furthermore, the method further comprises:
[0086] Password and biometric update phase: User U i Enter your ID i ,Old Password and old biometric features To the rescue vehicle RV i , rescue vehicle RV i For User U i The old password and old biometrics are verified, and after verification, the user enters the identity ID i ,New Password and new biometric features And update the rescue vehicle RV based on the new password and new biometrics i The corresponding information in the database.
[0087] When a user's password or biometrics is leaked, our solution provides password and biometric update functions and selects a new CRP to participate in each session to ensure the uniqueness of each session. Figure 7 As shown, the password and biometric update process is as follows:
[0088] UserU i First enter a unique ID i ,Old Password and old biometric features To the rescue vehicle RV i , rescue vehicle RV i Calculate anonymous password challenge Calculate R based on its own PUF (·) i =PUF(C i ), and calculate the fusion features Secret value UR i ′=RF(BR i ,UP i ) and A 0 ′=h(RPW i ||ID i ||UR i ′), and verify equation A 0 ′ and A 0 Are they equal? If not, terminate; otherwise, the rescue vehicle RV i To user U i Request a new password and new biometrics;
[0089] After receiving the request, user U i To the rescue vehicle RV i Input ID i , new and Rescue Vehicle RV i Calculate a new anonymous password Select an unused vehicle from the rescue vehicle database Calculate new Calculate a new response based on its own PUF (·) At the same time, new fusion features are calculated and Rescue Vehicle RV i use Replace {E in the rescue vehicle database i ,UP i ,DID j ,A 0 ,s i}; Rescue Vehicle RV i calculate And the new message body The rescue center RC receives the Stored in the rescue center database.
[0090] Furthermore, after the session is completed using the shared session key SK negotiated in the authentication and key agreement phase, the user password and biometric update phase is executed to update the information.
[0091] The method provided by the embodiment of the present invention integrates user biometrics and device PUF response at the user end to bind the device to the user and prevent unauthorized users from logging in illegally. PUF is also used to protect rescue vehicles and remote drones from physical attacks. Password and biometric update mechanisms are applied to prevent password guessing and biometric leakage.
[0092] Embodiment 2:
[0093] like Figure 8 and Fig. 9 As shown, the AVISPA formal software verification process provided by the embodiment of the present invention.
[0094] The embodiment of the present invention verifies the anti-attack capability (such as replay attack and man-in-the-middle attack) of the protocol scheme of the present invention under the DY model based on the formal security verification tool AVISPA of the High Level Protocol Specification Language (HLPSL). Since the calculation of cryptographic primitives in the protocol scheme of the present invention involves XOR operations, the security of the protocol is evaluated by executing the back-end dynamic model checker (OFMC) and the constraint logic-based attack searcher (CL-AtSE). First, the mobile user U is defined based on the HLPSL rules. i , rescue server RC and drone UAV j And other related roles as well as registration, login, authentication, key negotiation and other functions. Figure 8As shown in the figure, the SUMMARY output of the protocol analysis is SAFE, which proves that the protocol designed in this paper is safe. Secondly, the security protocol animator (SPAN) is used to simulate the attack behavior of malicious intruders. The simulation results are shown in Fig. 9 This proves that the method provided by the present invention has good security resilience in resisting passive or active attacks such as middleman and replay.
[0095] The present invention mainly meets 17 safety goals, and the detailed process is as follows:
[0096] G1 mutual identity authentication: In the method provided by the present invention, the rescue vehicle RV i By calculating A 0 =h(RPW i ||ID i ||UR i ) to authenticate user U i , because only legitimate user U i Pass the correct password PW i 、ID i and biometrics i The result can be combined with the specific PUF response to construct A 0 , so as to achieve user U i RV with rescue vehicle i The rescue center RC is calculated by M 1 =h(DID j ||C i ||N 1 ||UR i ) to certify the rescue vehicle RV i , UAV j By calculating M 1 =h(DID j ||C i ||N 1 ||UR i ) to certify the rescue center RC, it can be seen that UAV j Authenticated user U i , rescue vehicle RV i By calculating M 2 =h(DID j ||PID i ||N 1 ||N 2 ) UAV j Certification is completed for the rescue vehicle RV i UAV j mutual authentication between the two parties.
[0097] G2 security key negotiation: In the method provided by the present invention, the UAV j After authenticating the rescue center RC, the session key SK=T is generated through the secret parameters s3 (N 1 ), rescue vehicle RV i Receive UAV j The message sent also generates the session key SK=T s1 (N 3 ), and by calculating M 3 =h(SK||DID j ||PID i ||N 1 ||N 3 ) to verify the UAV j The correctness of the message sent. Here, according to the semigroup property of the extended Chebyshev chaotic mapping, we know that T s3 (N 1 )=T s1 (N 3 ), so the rescue vehicle RV i UAV j A common session key SK is negotiated between them.
[0098] G3 User anonymity and untraceability: In the method provided by the present invention, only when the PUF response R is known, i Under the premise of i =h(ID i ||R i ). However, due to the anti-collision property of PUF, it is difficult for the adversary to calculate PID i . And even if the adversary obtains {PID i ,F i ,N 1 ,M 1}, where PID i =h(ID i ||R i ), the adversary cannot extract the real ID of the user protected by the one-way hash i In addition, during the update phase, after each session negotiation is completed, the user's anonymous identity PID i Will respond with PUF R i Therefore, the adversary cannot trace the real identity of the user by linking multiple messages.
[0099] G4 Perfect forward secrecy: In the method provided by the present invention, the session key SK = T s3 (N 1 ) or SK=Ts1 (N 3 ), where N 1 =T s1 (N 0 ), N 3 =T s3 (N 0 ), N 0 =h(PID i ||DID j ), rescue vehicle RV i Storing long-term secrets i ,UP i ,DID j ,A 0 ,s i}, the rescue center RC end storage {C i ,DID j} and {C i ,A i ,PID i}. Even if the opponent calculates N 0 =h(PID i ||DID j ), and further eavesdropped on N 1 and N 3 ,According to the extended Chebyshev chaotic map CMDLP theorem, the adversary cannot obtain the random numbers s1 and s3, and thus cannot calculate the session key SK. Therefore, our protocol maintains perfect forward secrecy.
[0100] G5 Known Session Key Security: From the description of G3 security, we know that the current session is independent of the previous session, which makes it difficult for attackers to track the true identity of the device from different sessions. Furthermore, according to the security analysis of G4, the session key SK and the PUF response R i and R j , random numbers s1 and s3 are related. Among them, R i and R j The random numbers s1 and s3 are unique in each round of the session, so the session key SK generated in each round is independent. Therefore, even if the opponent obtains the session key of the previous round, it cannot infer the newly constructed session key of this round, thus achieving the security of the known session key.
[0101] G6 No clock synchronization: In the method provided by the present invention, random numbers are used instead of timestamps to ensure the freshness of messages, and the difficulty of clock synchronization settings between different participants is avoided.
[0102] G7 Multi-factor security: In the method provided by the present invention, a password PW is provided i , Biometricsi and rescue vehicles RV i The invention enhances the security of the user's device in response to three security factors. The invention ensures that the method is safe even if any two of the three factors are compromised. That is, without knowing all three factors, the adversary cannot successfully i The specific analysis is as follows: (1) Assume that the adversary knows the password PW i and user rescue vehicle RV i The PUF response R i , since the adversary cannot obtain the user's biometrics i , secret fusion eigenvalue UR i It cannot be obtained by the opponent, verify parameter A 0 =h(RPW i ||ID i ||UR i ) cannot be calculated, M 1 =h(DID j ||C i ||N 1 ||UR i ) cannot be calculated, user U i The authorized access to the rescue center RC will be blocked. (2) Assume that the adversary obtains the rescue vehicle RV. i PUF response and biometric BIO i , since the adversary does not know the password PW i , so the anonymous password RPW cannot be calculated i =h(PW i ||s i ), A cannot be calculated 0 =h(RPW i ||ID i ||UR i ), it is impossible to achieve authorized access to the rescue center RC. (3) Assume that the adversary obtains the password PW i and biometrics i Since the adversary cannot possess a rescue vehicle with a built-in PUF, the corresponding response R cannot be obtained due to the inherent non-clonability of PUF. i , based on the formula UR i =RF(BR i ,UP i ), the adversary cannot calculate the secret fusion eigenvalue UR i , it cannot be successfully verified.
[0103] Based on the above three situations, it can be proved that the method provided by the present invention can ensure multi-factor security.
[0104] G8 Biometric Privacy Protection: From the above analysis, we can see that biometrics plays an important role in three-factor authentication. i Biometrics required i RV i It is also a key factor for user vehicle login and rescue center RC verification. Therefore, the leakage of biometrics will cause serious privacy risks and even authentication failure. and UR i =RF(BR i ,UP i ) Biometrics i Rescue RV vehicle with built-in PUF i Response feature fusion, and only store auxiliary data UP i , achieving privacy protection of biometrics.
[0105] G9 defends against offline dictionary guessing attacks: Assuming the adversary obtains the rescue vehicle RV i PUF and corresponding user's biometric BIO i , according to the PUF response R i and biometrics i The secret fusion eigenvalue UR can be obtained i . Due to A 0 =h(RPW i ||ID i ||UR i ), RPW i =h(PW i ||s i ), so guess the ID i and PW i The combination is not easy.
[0106] G10 resists desynchronization attacks: Usually, updating CRP during the authentication process is prone to desynchronization attacks. Therefore, the password and biometric update in the method provided by the present invention is not based on server participation, which avoids the asynchrony between the user's local data and the rescue center data. And when a new session is carried out after a session ends, the rescue vehicles and drones with built-in PUF select new random CRPs to participate in the new authentication process, which not only meets the security requirements of different sessions based on different CRPs, but also can resist desynchronization attacks during authentication.
[0107] G11 Defense against privileged internal attacks: In the method provided by the present invention, the user's real identity ID i Only with PID i =h(ID i ||R i) and A 0 =h(RPW i ||ID i ||UR i ) even if the adversary has internal privileges and has access to the rescue vehicle RV i {E stored in i ,UP i ,DID j ,A 0 ,s i} and the rescue center RC end storage {C i ,DID j} and {C i ,A i ,PID i}, nor can the real identity ID protected by a one-way hash be extracted i . Similarly, the drone’s real ID j And it is also impossible to get from DID j =h(ID j ||R j ) is extracted from the hash protection. Meanwhile, the rescue vehicle RV i The rescue center RC does not store RV i The response R i and UAV j The response R j , and there will be no leakage of CRP. Therefore, our protocol can effectively resist privileged internal attacks.
[0108] G12 Resist UAV tampering and cloning attacks: The method provided by the present invention designs a PUF unit in the UAV to prevent tampering and counterfeiting after the UAV is captured. In other words, based on the inherent properties of PUF, even if the UAV j Captured, the adversary cannot tamper with or clone the real response R j Based on DID j =h(ID j ||R j ), N 0 =h(PID i ||DID j ), N 3 =T s3 (N 0 ), and the session key SK = T s1 (N 3 ) It can be concluded that the opponent cannot construct a true SK. In addition, UAV j No secret information is stored, therefore, the protocol is resistant to UAV tampering and cloning attacks.
[0109] G13 Resisting theft of user's vehicle: It has been clearly pointed out in the three-factor security analysis that in the method provided by the present invention, even if the adversary obtains the user's password and possesses the rescue vehicle equipment or obtains the user's biometrics and possesses the rescue vehicle equipment, the session key SK cannot be calculated. Furthermore, the information stored in the rescue vehicle is encrypted, and even if it is extracted by the adversary, no information related to SK can be obtained. Therefore, the protocol can resist theft of user's vehicle.
[0110] G14 Resisting secret leakage attacks: It has been proven in perfect forward secrecy that even if the long-term secrets stored by all participants are leaked, the security of the session key will not be affected. Therefore, the present invention only considers the impact of temporary secret data on. The temporary secret data s1, s2 and s3 randomly generated during the authentication process are encrypted during the transmission process, so the adversary cannot obtain this information. Furthermore, even if the adversary obtains s1, s2 and s3, the construction of the session key SK still requires the secret parameter R i With R j As can be seen from the above, both parameters require the adversary to obtain them based on a specific challenge and the corresponding PUF function. Based on the specific properties of PUF, the adversary will not be able to calculate the final session key. In addition, the PUF response is usually deleted in a very short time, and this threat can be ignored. Therefore, the method provided by the present invention can resist secret leakage attacks.
[0111] G15 Protection against common attacks: The system must provide security to protect against common threats such as man-in-the-middle, simulation and replay attacks. The method provided by the present invention transmits information {PID i ,F i ,N 1 ,M 1}、{N 1 ,N 2 ,A 1 ,C j ,M 2} and {A 2 ,M 3} are based on temporary secret data s1, s2 and s3, anonymous identity PID i and DID j and the PUF response R i and R jThese parameter information are updated in each session, and the adversary cannot send this information repeatedly to successfully authenticate. Therefore, the method provided by the present invention can resist replay attacks. In addition, the authentication process is based on real-time generation of PUF, and the messages are encrypted for transmission. Therefore, man-in-the-middle attacks can be resisted. Regarding simulation attacks, from the discussion of G7, no matter which two factors the adversary obtains, it cannot simulate the user or the rescue vehicle. Here, we focus on the rescue center RC simulation attack and the UAV UAV j Simulation attack. The adversary cannot clone the same PUF to achieve authentication, so the adversary cannot simulate the legitimate drone to send messages and successfully authenticate. For the rescue center RC simulation attack, if the adversary wants to simulate the rescue center RC, he needs to successfully construct the message {N 1 ,N 2 ,A 1 ,C j ,M 2} and passed the certification. Certification information M 2 =h(DID j ||PID i ||N 1 ||N 2 ) are constructed based on temporary secret data s1, s2 and PUF response R i and R j , where s1 and s2 are both encrypted. And R i and R j Since the adversary cannot copy and build the same PUF, it is impossible to simulate the correct message and pass the authentication. This proves that the present invention can resist the rescue center RC simulation attack.
[0112] G16 Update: Through the password and biometric update phase implementation process and the G5 security attribute analysis process, the present invention confirms that different CRPs are used in different sessions.
[0113] G17 Physical protection of user equipment: Based on the discussion of G13 security attributes, it can be seen that the present invention can provide physical protection for user login devices.
[0114] Based on the above security goals, the present invention provides a comprehensive evaluation mechanism, and compares it with the existing technologies [1], [2], [3], [4], and [5] to prove the effectiveness of the proposed protocol. As shown in Table 1, it can be seen that in the first two schemes, the user device only implements direct login authentication of the user identity in the owned device, which cannot prevent the adversary's illegal login. In addition, the owned device does not provide PUF physical protection function, so it cannot protect the user's correct password and biometrics from being unique to the specific device. Although the last three protocols have built-in PUF in the user's device for physical protection, [4] and [5] both use timestamps to verify the real-time nature of the message, so clock synchronization is required, which increases the difficulty of authentication. [3] and [4] cannot resist secret leakage attacks and do not provide password biometric updates. Furthermore, [4] lacks the ability to resist privileged internal attacks and password guessing attacks. Based on the above analysis, the present invention achieves all the expected goals. While balancing security and lightweight, it provides more functional features.
[0115] Table 1 Comparison of protocol security attributes
[0116]
[0117]
[0118] [1]Cui J, Yu J, Zhong H, et al. Chaotic map-based authentication scheme using physical unclonable function for internet of autonomous vehicle [J]. IEEE Transactions on Intelligent Transportation Systems, 2022, 24(3): 3167-3181.
[0119] [2]Wang D, Cao Y, Lam KY, et al. Authentication and Key Agreement BasedOn Three Factors and PUF for UAVs-Assisted Post-Disaster Emergency Communication[J]. IEEE Internet of Things Journal, 2024.
[0120] [3]Mao R, Ji H, Wang
[0121] [4]Su X,
[0122] [5] Yu S, Das AK, Park Y, et al. SLAP-IoD: Secure and lightweight authentication protocol using physical unclonable functions for internet ofdrones in smart city environments [J]. IEEE Transactions on VehicularTechnology, 2022, 71(10): 10374-10388.
[0123] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A multi-factor security authentication method for unmanned aerial vehicle emergency rescue access control, characterized in that: It includes initialization phase, registration phase, login phase, and authentication and key negotiation phase; The initialization stage: the rescue center RC publishes initialization related parameter information; the related parameters include the secret extraction function BF(·), the secret reconstruction function RF(·), the single hash function h:{0,1} * and physical unclonable function PUF(·); The registration phase includes the drone registration phase and the user and rescue vehicle registration phase; The drone registration stage: UAV j Complete registration with the rescue center RC based on its own PUF response; The user and rescue vehicle registration stage: User U i Based on identity ID i and password RPW i Send a registration application to the rescue center RC, and the rescue center RC will feedback the registration information to the user U after receiving it. i , user U i The registration information and biometric BIO i Send to rescue vehicle RV i , rescue vehicle RV i Complete registration with the rescue center RC based on its own PUF and the information received; The login stage: User U i Password-based RPW i and biometrics i RV with rescue vehicle i Bind and rescue vehicle RV i Send verification message to the rescue center RC based on Chebyshev polynomial, and the rescue center RC will successfully log in after verification; The authentication and key negotiation phase: User U i and rescue vehicle RV i UAV j With the assistance of the rescue center RC, they authenticate each other and negotiate a shared session key SK.
2. A multi-factor security authentication method for unmanned aerial vehicle emergency rescue access control according to claim 1, characterized in that: The specific process of the drone registration stage is as follows: UAV j ID j Sent to the rescue center RC, the rescue center RC generates a set of random challenges Send to UAV j ; UAV j Received random challenge C j Then based on its own PUF (·), it generates the corresponding response R j =PUF(C j ), and the response Send to rescue center RC; Rescue Center RC received the UAV j The response R j Generate drone anonymous identity DID j =h(ID j ||R j ), and {C j ,DID j }Stored in the rescue center database.
3. A multi-factor security authentication method for unmanned aerial vehicle emergency rescue access control according to claim 2, characterized in that: The specific process of the user and rescue vehicle registration stage is as follows: UserU i Select ID i 、Password PW i and random numbers Calculate the anonymous password RPW i =h(WP i ||s i ), the anonymous password RPW i and the drone ID that the user wishes to access j Send to rescue center RC; Where h() represents a one-way hash function; The rescue center RC receives the anonymous password RPW i and the ID of the drone you wish to access j After that, generate a set of random challenges The anonymous identity DID corresponding to the drone that the user wants to access j and the random challenge C i Return to user U i ; UserU i The received {C i ,DID j } and biometric information BIO i Send to rescue vehicle RV i , rescue vehicle RV i Calculate the response R based on its own PUF (·) i =(C i ), intermediate parameters Fusion Features and (UR i ,UP i )=BF(BR i ), where UR i is the secret value, UP i Correction code stored for secret value; while calculating anonymous identity PID i =h(ID i ||R i ), intermediate parameters and authentication message A0=h(RPW i ||ID i ||UR i ); {E i ,UP i ,DID j ,A0,s i } is stored in the rescue vehicle database and the message body {A i ,PID i }To rescue center RC; The rescue center RC receives the message body {A i ,PID i }, store {C i ,A i ,PID i } to the rescue center database.
4. A multi-factor security authentication method for unmanned aerial vehicle emergency rescue access control according to claim 3, characterized in that: The specific process of the login stage is as follows: UserU i Enter your ID i 、Password PW i and biometrics i To the rescue vehicle RV i ; Rescue Vehicle RV i Calculate the anonymous password RPW i ′=h(PW i ||s i ) and Challenges Calculate the response R based on its own PUF i ′=PUF(C i ′), and calculate the fusion feature Secret value UR i ′=RF(BRi′,UPi) and authentication message A0′=h(RPWi′|IDi|URi′), and verify whether A0 and A0′ in the rescue vehicle database are equal. If they are not equal, terminate; if they are equal, user U i and rescue vehicle RV i Successfully bound, continue to the next step; Rescue Vehicle RV i Calculate the anonymous identity PID i ′=h(ID i ||R i ′), select a drone anonymous identity DID from the rescue vehicle database j , based on drone anonymous identity DID j Calculate intermediate parameters and intermediate parameter N0=h(PID i ′||DID j ), select random number s1 as the first temporary secret data, calculate Chebyshev polynomial N1 = T s1 (N0) and authentication information M1 = h(DID j ||C i ′||N1||UR i ′), send verification message {PID i ′,F i ,N1,M1} to the rescue center RC; Rescue Center RC received rescue vehicle RV i The verification message sent {PID i ′,F i ,N1,M1}, based on PID i 'Find the corresponding challenge C from the database i and A i , then calculate the secret value Drone Anonymity And calculate the authentication information M1′=h(DID j ′||C i ||N1||UR i ″), verify whether M1′ and M1 are equal. If they are not equal, the login is terminated; if they are equal, the login is successful.
5. A multi-factor security authentication method for unmanned aerial vehicle emergency rescue access control according to claim 4, characterized in that: The specific process of the authentication and key negotiation phase is as follows: The rescue center RC selects the random number s2 as the second temporary secret data and calculates the Chebyshev polynomial Intermediate parameters And based on the drone anonymous identity DID j 'Search for challenge C from the rescue center database j , calculate the authentication information M2 = h(DID j ′||PID i ||N1||N2), and then send the message body {N1,N2,A1,C j ,M2} for UAV j ; UAV j Received message body {N1,N2,A1,C j ,M2}, the rescue center RC uses the PID obtained in the previous step i and DID j ', calculate the same N0=h(PID i ||DID j ′), then select the random number s3 as the third temporary secret data, calculate the Chebyshev polynomial N3 = T s3 (N0), we get And obtain the shared key SK = T s3 (N1) and M3 = h(SK || DID j ′||PID i ||N1||N3), and finally send the message body {A2,M3} to the rescue vehicle RV i ; Rescue Vehicle RV i Receive UAV j After sending the message body {A2,M3}, calculate and SK=T s1 (N3), and calculate the authentication information M3′=h(SK||DID j |PID i ′||N1||N3), verify whether M3′ and M3 are equal. If they are equal, the authentication succeeds; if they are not equal, the authentication fails.
6. A multi-factor security authentication method for unmanned aerial vehicle emergency rescue access control according to claim 1, characterized in that: The method also includes a password and biometric update phase; Password and biometric update phase: User U i Enter your ID i ,Old Password and old biometric features To the rescue vehicle RV i , rescue vehicle RV i For User U i The old password and old biometrics are verified, and after verification, the user enters the identity ID i ,New Password and new biometric features And update the rescue vehicle RV based on the new password and new biometrics i The corresponding information in the database and the rescue center RC database.
7. A multi-factor security authentication method for unmanned aerial vehicle emergency rescue access control according to claim 6, characterized in that: The specific process of the password and biometric update stage is as follows: UserU i First enter a unique ID i ,Old Password and old biometric features To the rescue vehicle RV i , rescue vehicle RV i Calculate anonymous password challenge Calculate R based on its own PUF (·) i =PUF(C i ), and calculate the fusion features Secret value UR i ′=RF(BR i ,UP i ) and A0′=h(RPW i ||ID i ||UR i ′), and verify whether equation A0′ is equal to A0. If they are not equal, terminate; otherwise, rescue vehicle RV i To user U i Request a new password and new biometrics; After receiving the request, user U i To the rescue vehicle RV i Input ID i , new and Rescue Vehicle RV i Calculate a new anonymous password Select an unused vehicle from the rescue vehicle database Calculate new Calculate a new response based on its own PUF (·) At the same time, new fusion features are calculated and Rescue Vehicle RV i use Replace {E in the rescue vehicle database i ,UP i ,DID j ,A0,s i }; Rescue Vehicle RV i calculate And the new message body The rescue center RC receives the Stored in the rescue center database.
8. A multi-factor security authentication method for unmanned aerial vehicle emergency rescue access control according to claim 6 or 7, characterized in that: After the session is completed using the shared session key SK negotiated in the authentication and key agreement phase, the user password and biometric update phase is executed to update the information.
Citation Information
Patent Citations
Automatic driving vehicle network authentication and key agreement method based on chaotic mapping
CN114205091A
Wireless ad hoc network system and method based on rescue, electronic equipment and medium
CN117255333A
Post-disaster elastic emergency communication method and system based on authentication and key agreement protocol
CN118413837A
Post-disaster safety emergency communication method and system based on authentication and key agreement protocol
CN118413838A
UAV assistance-based Internet of Things equipment multi-cluster concurrent access and switching authentication method
CN119325088A