A Multi-Factor Security Authentication Method for Emergency Rescue Access Control of Unmanned Aerial Vehicles

By employing a multi-factor authentication method in drone emergency rescue, combining cryptography, biometrics, and PUF, the problems of insufficient identity authentication security and high computational overhead are solved, achieving efficient data privacy protection and physical attack protection, and ensuring secure binding and information transmission between drones and user devices.

CN119997019BActive Publication Date: 2025-11-11Chinese People's Liberation Army Cyberspace Force Information Engineering University
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510262576.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-06
Publication Date
2025-11-11
Estimated Expiration
2045-03-06

AI Technical Summary

Technical Problem

Existing drone emergency rescue solutions suffer from problems such as insufficient identity authentication security, inadequate data privacy protection, high computational overhead, and the vulnerability of mobile devices to physical capture, leading to delays in rescue operations or information leaks.

Method used

A multi-factor authentication method is adopted, combining cryptography, biometrics, and physically unclonable functions (PUFs) to perform secure authentication and key negotiation between user rescue vehicles and drones. Chebyshev chaotic mapping is used to construct session keys to enhance the binding between devices and users, prevent physical attacks, and achieve authentication through lightweight cryptographic operations.

Benefits of technology

It improves identity authentication security and data privacy protection during drone emergency rescue, reduces computing and communication overhead, meets real-time rescue needs, prevents unauthorized access and physical attacks, and ensures the security and reliability of information transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119997019B_ABST
    Figure CN119997019B_ABST
Patent Text Reader

Abstract

This invention relates to the field of drone security applications, providing a multi-factor security authentication method for emergency rescue access control of drones. The method includes an initialization phase, a registration phase, a login phase, an authentication and key negotiation phase, and a password and biometric update phase. First, the rescue center (RC) initializes relevant parameter information. Then, the user, based on their password and biometrics, accesses the rescue vehicle (RV). i With drones (UAVs) j Each user registers with the RC based on their own PUF response. This is followed by mutual authentication and key negotiation. i Log in and bind to a specific rescue vehicle (RV) i Based on registration information, via RC and UAV j An authentication connection is established between the parties, and a session key is negotiated. Finally, after the current session concludes, the user password and biometric information are updated to prepare for the next session negotiation. This invention satisfies all configured security attributes while maintaining zero storage overhead and low computational and communication overhead.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of drone security applications, and in particular to a multi-factor security authentication method for emergency rescue access control of drones. Background Technology

[0002] In recent years, frequent disasters such as floods and earthquakes have brought incalculable economic losses and serious safety threats. These disasters can damage or block roads, making it difficult for rescue vehicles to enter disaster areas, or even completely impassable, severely delaying rescue operations. At the same time, damage to infrastructure and communication disruptions prevent the effective transmission of real-time information from disaster areas to rescue personnel and vehicles, further complicating rescue efforts. Moreover, because affected people are often scattered, rescue personnel and vehicles cannot promptly and comprehensively cover all affected areas, further exacerbating the difficulty of rescue operations. Drones, due to their rapid response, flexibility, and lack of geographical or terrain limitations, have become the best choice for assisting rescue efforts. Equipped with advanced cameras, infrared thermal imagers, and lidar, drones can quickly search disaster areas through aerial images and videos, understand the severity and scope of the disaster, and promptly locate trapped people and vehicles. Drones can fly over large areas of disaster zones, assessing and monitoring road and traffic conditions in real time by checking the integrity, accessibility, and presence of obstacles, providing rescue vehicles with real-time road information and optimal rescue routes. Simultaneously serving as a temporary communication relay, the communication equipment on drones can help rescue personnel maintain contact with people in the disaster area, transmit rescue instructions, collect requests for help, and provide real-time communication support. To ensure secure communication between various entities, a reliable authentication mechanism needs to be established between the user's rescue vehicle and the drone before rescue data transmission, preventing unauthorized users from illegally accessing the drone's real-time data information.

[0003] Existing authentication protocols have the following problems and shortcomings:

[0004] 1) Existing protocols, whether using two-factor or three-factor authentication schemes, face security issues such as password cracking, smart card loss, or leakage of biometric information. Furthermore, the independent verification mechanism between rescue personnel and vehicles does not fully address the security issues on the user device side.

[0005] 2) When drones perform rescue missions, the information they collect and transmit often includes private information such as the disaster situation, rescue routes, and personnel locations. If this information is intercepted, tampered with, or deleted, it will lead to untimely rescue efforts, delays in rescue implementation, and even endanger lives. How to protect the anonymity of data privacy information during the identity authentication process is a key issue that current technologies lack.

[0006] 3) Existing solutions do not consider response mechanisms for application scenarios where mobile devices are physically captured. Rescue vehicles and drones are highly mobile during missions, and if captured by an adversary, they may be impersonated or destroyed.

[0007] 4) Existing cryptographic protection mechanisms are mostly based on expensive cryptographic primitives such as bilinear pairing and elliptic curve signatures, resulting in high computational overhead. This makes them impractical for drones with limited computing, storage, and power. Summary of the Invention

[0008] To address the issues of privacy breaches, physical capture of drones, and high overhead in existing drone-assisted emergency rescue applications, this invention provides a multi-factor authentication (PUF) method for access control in drone emergency rescue. With authorization and assistance from the rescue center, the user's rescue vehicle achieves secure authentication and key negotiation with the drone. To enhance user endpoint security, the user is uniquely bound to the rescue vehicle, ensuring that only authorized users with authorized devices can access the system. PUF is integrated into both the rescue vehicle and the remote drone to prevent physical attacks. Furthermore, Chebyshev chaotic mapping is used to construct the session key between the user's rescue vehicle and the remote drone to maintain perfect forward confidentiality.

[0009] This invention provides a multi-factor security authentication method for access control in emergency rescue operations using unmanned aerial vehicles (UAVs), comprising an initialization phase, a registration phase, a login phase, and an authentication and key negotiation phase.

[0010] During the initialization phase: the Rescue Center (RC) releases initialization-related parameter information; these parameters include the secret extraction function BF(·), the secret reconstruction function RF(·), and the one-way hash function h:{0,1}. * And the physically unclonable function PUF(·);

[0011] The registration phase includes both the drone registration phase and the user and rescue vehicle registration phase; wherein...

[0012] The drone registration phase: UAV j Register with the Response Center (RC) based on your own PUF response;

[0013] The user and rescue vehicle registration phase: User U i Based on identity ID i and password RPW i The user submits a registration request to the rescue center (RC). Upon receiving the request, the rescue center (RC) sends the registration information back to the user. i User U i The registration information and biometrics (BIO) i Send to rescue vehicle RVi rescue vehicle RV i Register with the RC (Rescue Center) based on your own PUF (Public Assistance Facility) and the information you receive;

[0014] The login phase: User U i Based on cryptographic RPW i and biometrics BIO i With rescue vehicle RV i Binding is required; after binding, the rescue vehicle (RV) i The verification message is sent to the rescue center RC based on Chebyshev polynomial. Once the rescue center RC verifies the message, the login is successful.

[0015] The authentication and key negotiation phase: User U i and rescue vehicles RV i With drones (UAVs) j With the assistance of the rescue center RC, they authenticated each other and negotiated a shared session key SK.

[0016] Furthermore, the specific process of the drone registration stage is as follows:

[0017] UAVs j Identity ID j Send to the Rescue Center (RC), which generates a set of random challenges. Send to UAV j ;

[0018] UAVs j Received random challenge C j Then, based on its own PUF(·), the corresponding response R is generated. j =PUF(C j ), and the response Send to the Rescue Center (RC);

[0019] The rescue center (RC) received a UAV (unmanned aerial vehicle). j Response R j The drone's anonymous identity DID is then generated. j =h(ID) j ||R j ), and {C j DID j Stored in the rescue center's database.

[0020] Furthermore, the specific process of the user and rescue vehicle registration stage is as follows:

[0021] User U i Select Identity ID i Password PW i and random numbers Calculate the anonymous password RPW i =h(PW i ||s i ), the anonymous password RPW i and the drone identity ID that the user wants to access j Send to the Rescue Center (RC); where h() represents a one-way hash function.

[0022] The rescue center (RC) received the anonymous password RPW. i and the drone identity ID that you wish to access j Then, a set of random challenges is generated. The anonymous identity DID corresponding to the drone that the user wishes to access. j and the random challenge C i Return to user U i ;

[0023] User U i The received {C i DID j} and biometric information BIO i Send to rescue vehicle RV i rescue vehicle RV i The response R is calculated based on its own PUF(·). i =(C i ), intermediate parameters Fusion features and (UR) i ,UP i ) = BF(BR i ), of which UR i For secret value, UP i The verification code is stored as a secret value; the anonymous identity PID is calculated simultaneously. i =h(ID) i ||R i ), intermediate parameters And authentication message A0 = h(RPW) i ||ID i ||UR i );

[0024] {E i ,UP i DID j ,A0,s i} Stored in the rescue vehicle database, and simultaneously send message body {A i ,PID i} to the rescue center RC;

[0025] The rescue center RC received message body {A i,PID i After that, store {C} i A i ,PID i} to the rescue center database.

[0026] Furthermore, the specific process of the login phase is as follows:

[0027] User U i Enter identity ID i Password PW i and biometrics BIO i To the rescue vehicle RV i ;

[0028] rescue vehicle RV i Calculate the anonymous password RPW i ′=h(PW i ||s i ) and challenges Response R is calculated based on its own PUF. i =PUF(C) i Simultaneously calculate fusion features. Secret Value UR i The system calculates RF(BRi′,UPi) and authentication message A0′ = h(PPWi′|IDi|URi′), and verifies whether A0 and A0′ in the rescue vehicle database are equal. If they are not equal, the process terminates; if they are equal, then user U... i and rescue vehicle RV i Successfully linked. Proceed to the next step.

[0029] rescue vehicle RV i Calculate the anonymous identity PID i ′=h(ID i ||R i ′), Select a drone anonymous identity DID from the rescue vehicle database. j Based on the drone's anonymous PID j Calculate intermediate parameters and intermediate parameter N0 = h(PID) i ′||DID j Select a random number s1 as the first temporary secret data, and calculate the Chebyshev polynomial N1 = T. s1 (N0) and authentication information M1 = h(DID) j ||C i ′||N1||UR i Send verification message {PID ') i ′,F i N1, M1} to the rescue center RC;

[0030] The rescue center (RC) received the rescue vehicle RV. i The verification message sent {PID i ′,F i After N1, M1}, based on PID i Search the database for the corresponding challenge C i and A i Then calculate the secret value. Drone Anonymous And calculate the authentication information M1′=h(DID) j ′||C i ||N1||UR i The function verifies whether M1′ and M1 are equal. If they are not equal, the login process terminates; if they are equal, the login process succeeds.

[0031] Furthermore, the specific process of the authentication and key negotiation phase is as follows:

[0032] The rescue center (RC) selects a random number s2 as the second temporary secret data to calculate the Chebyshev polynomial. intermediate parameters And based on the drone's anonymous identity DID j Search for Challenge C in the rescue center database. j Calculate authentication information M2 = h(DID) j ′||PID i ||N1||N2), then send the message body {N1,N2,A1,C j M2} for UAVs j ;

[0033] UAVs j Received message body {N1,N2,A1,C j After M2}, the rescue center RC uses the PID obtained in the previous step. i and DID j ', calculate N0 = h(PID) which is the same as the user terminal. i ||DID j Then, a random number s3 is selected as the third temporary secret data, and the Chebyshev polynomial N3 = T is calculated. s3 (N0), thus obtaining And obtain the shared key SK=T s3 (N1) and M3 = h(SK||DID) j ′||PID i (||N1||N3), and finally send the message body {A2,M3} to the rescue vehicle RV. i ;

[0034] rescue vehicle RV i Received UAV j After sending the message body {A2,M3}, calculate and SK=T s1 (N3), and calculate the authentication information M3′=h(SK||DID) j ||PID i The function verifies whether M3′ and M3 are equal. If they are equal, the authentication passes; otherwise, the authentication fails.

[0035] Furthermore, the method also includes a password and biometric update phase;

[0036] The password and biometric update phase: User U i Enter identity ID i ,Old Password and old biological characteristics To the rescue vehicle RV i rescue vehicle RV i For user U i The system verifies the user's old password and biometric signature. After successful verification, the user enters their identity ID. i ,New Password and new biological characteristics The rescue vehicle RV will be updated based on the new password and new biometrics. i The corresponding information in the database and the rescue center's RC database.

[0037] Furthermore, the specific process of the password and biometric update stage is as follows:

[0038] User U i First, enter your unique ID. i ,Old Password and old biological characteristics To the rescue vehicle RV i rescue vehicle RV i Calculate anonymous passwords challenge Calculate R based on its own PUF(·) i =PUF(C i Simultaneously calculate fusion features Secret Value UR i ′=RF(BR i ,UP i ) and A0′=h(RPW i ||ID i ||UR iThe process involves checking whether equation A0′ is equal to A0. If they are not equal, the process terminates; otherwise, the rescue vehicle RV... i To user U i Request a new password and new biometrics;

[0039] After receiving the request, user U i To the rescue vehicle RV i Enter ID i new and rescue vehicle RV i Calculate new anonymous passwords Select unused vehicles from the rescue vehicle database. Calculate new Calculate the new response based on its own PUF(·) Simultaneously calculate new fusion features and rescue vehicle RV i use Replace {E} in the rescue vehicle database i ,UP i DID j ,A0,s i};Rescue vehicle RV i calculate and the new message body The message is passed to the rescue center RC. After receiving it, the rescue center RC will... Stored in the rescue center's database.

[0040] Furthermore, after completing the session using the shared session key SK negotiated in the authentication and key negotiation phase, the information is updated by performing the user password and biometric update phase.

[0041] The beneficial effects of this invention are as follows:

[0042] (1) This invention proposes a security enhancement scheme based on cryptography, biometrics, and PUF (Proof-of-Flight Detection). By integrating user biometrics and device PUF responses at the user end, the device is bound to the user, preventing unauthorized login. PUF is also used to protect rescue vehicles and remote drones from physical attacks. Password and biometric update mechanisms are applied to prevent password guessing and biometric leakage.

[0043] (2) Considering the limited resources such as drones, this invention uses only lightweight cryptographic operations such as hash and XOR to achieve mutual authentication between rescue vehicles and drones. Furthermore, it uses Chebyshev chaotic mapping technology to achieve session key negotiation between the two parties, avoiding complex public key operations. It has certain advantages in terms of performance overhead such as computing, storage, and communication, and meets the authentication requirements of high response and low overhead in real-time rescue emergency scenarios.

[0044] (3) Based on the 17 security objectives proposed in this invention, a systematic analysis of the protocol was conducted, demonstrating the security of the proposed solution from the information interaction level. Compared with the latest security protocols, this invention is the only one that satisfies all the set security attributes. Furthermore, this invention maintains zero storage overhead, as well as low computational and communication overhead. Attached Figure Description

[0045] Figure 1 This is a schematic diagram of a system simulation in an emergency rescue scenario using a drone, provided by an embodiment of the present invention.

[0046] Figure 2 This is one of the feature fusion binding diagrams provided in the embodiments of the present invention;

[0047] Figure 3 This is a second schematic diagram of feature fusion binding provided in an embodiment of the present invention;

[0048] Figure 4 This is a schematic diagram of the system flow of the security authentication method provided in the embodiments of the present invention;

[0049] Figure 5 A schematic diagram of the drone registration process for the security authentication method provided in this embodiment of the invention;

[0050] Figure 6 This is a schematic diagram illustrating the user and rescue vehicle registration process of the security authentication method provided in this embodiment of the invention.

[0051] Figure 7 This is a schematic diagram illustrating the login, authentication, and key negotiation process of the security authentication method provided in this embodiment of the invention.

[0052] Figure 8 This is a schematic diagram of the AVISPA formal verification OFMC and CL-ATSE results provided in an embodiment of the present invention;

[0053] Figure 9 This is a schematic diagram of the AVISPA formal verification SPAN simulation results provided in an embodiment of the present invention. Detailed Implementation

[0054] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of the embodiments of this invention will be clearly described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.

[0055] Example 1:

[0056] like Figure 1 As shown in the figure, the system in the simulated drone emergency rescue scenario of the present invention provides a multi-factor security authentication method for drone emergency rescue access control, including an initialization phase, a registration phase, a login phase, and an authentication and key negotiation phase;

[0057] Initialization Phase: The Rescue Center (RC) releases initialization-related parameter information; these parameters include the feature fusion extraction functions BF(·) and RF(·), and the one-way hash function h:{0,1}. * And the physically unclonable function PUF(·).

[0058] Among them, such as Figure 2 As shown, the secret extraction algorithm (UR) i ,UP i ) = BF(BR i This algorithm uses user equipment fusion features (BR) i As input, output a secret value UR i And the secret stored correction code UP i .

[0059] like Figure 3 As shown, the secret reconstruction algorithm UR i =RF(BR) i ′,UP i ): Given the fusion feature BR i ' and stored correction code UP i The algorithm outputs a secret value UR. i ′。 When BR i and BR i If the Hamming distance between ' and ' is less than the fault tolerance threshold τ, then UR i ′=UR i Among them, BR i =BIO i ⊕R i BIO i and R i They represent two different features, UP i It is used to restore the secret value UR i The correction code.

[0060] like Figure 4 As shown, the method provided in this embodiment of the invention includes the following interaction stages:

[0061] Registration phase: This includes the drone registration phase and the user and rescue vehicle registration phase; among which,

[0062] Drone Registration Phase: UAV j Register with the Response Center (RC) based on your own PUF response.

[0063] During the drone registration phase, before a drone is deployed to a specific area, the rescue center (RC) first needs to register the drone performing the mission, thus recognizing its legal status. For example... Figure 5 As shown, the specific process of drone registration is as follows:

[0064] UAVs j Identity ID j Send to the Rescue Center (RC), which generates a set of random challenges. Send to UAV j ;

[0065] UAVs j Received random challenge C j Then, based on its own PUF(·), the corresponding response R is generated. j =PUF(C j ), and will respond Send to the Rescue Center (RC);

[0066] The rescue center (RC) received a UAV (unmanned aerial vehicle). j Response R j The drone's anonymous identity DID is then generated. j =h(ID) j ||R j ), and {C j DID j Stored in the rescue center's database.

[0067] User and rescue vehicle registration phase: User U i Based on identity ID i and password RPW i The user submits a registration request to the rescue center (RC). Upon receiving the request, the rescue center (RC) sends the registration information back to the user. i User U i Registration information and biometrics BIO i Send to rescue vehicle RV i rescue vehicle RV iRegister with the RC (Rescue Center) based on your own PUF (Public Assistance Facility) and the information you receive;

[0068] During the user and rescue vehicle registration phase, when user U i We hope to acquire UAVs (Unmanned Aerial Vehicles) for a specific area. j When obtaining real-time data, you first need to register with the Rescue Center (RC), such as... Figure 6 As shown, the specific process for user and rescue vehicle registration is as follows:

[0069] User U i Select Identity ID i Password PW i and random numbers Calculate the anonymous password RPW i =h(PW i ||s i ), the anonymous password RPW i and the drone identity ID that the user wants to access j Send to the Rescue Center (RC); where h() represents a one-way hash function.

[0070] The rescue center (RC) received the anonymous password RPW. i and the drone identity ID you wish to access j Then, a set of random challenges is generated. The anonymous identity DID corresponding to the drone that the user wants to access. j and random challenge C i Return to user U i ;

[0071] User U i The received {C i DID j} and biometric information BIO i Send to rescue vehicle RV i rescue vehicle RV i The response R is calculated based on its own PUF(·). i =(C i ), intermediate parameters Fusion features and (UR) i ,UP i ) = BF(BR i ), of which UR i For secret value, UP i The verification code is stored as a secret value; the anonymous identity PID is calculated simultaneously. i =h(ID) i ||R i ), intermediate parameters And authentication message A0 = h(RPW) i||ID i ||UR i );

[0072] {E i ,UP i DID j ,A0,s i} Stored in the rescue vehicle database, and simultaneously send message body {A i ,PID i} to the rescue center RC;

[0073] The rescue center RC received message body {A i ,PID i After that, store {C} i A i ,PID i} to the rescue center database.

[0074] Login phase: User U i Based on cryptographic RPW i and biometrics BIO i With rescue vehicle RV i Binding is required; after binding, the rescue vehicle (RV) i The verification message is sent to the rescue center RC based on Chebyshev polynomial. Once the rescue center RC verifies the message, the login is successful.

[0075] During the login phase, the user first binds their account to the rescue vehicle's terminal, and then both the user and the rescue vehicle authorize login on the rescue center's server, such as... Figure 7 As shown, the specific process during the login phase is as follows:

[0076] User U i Enter identity ID i Password PW i and biometrics BIO i To the rescue vehicle RV i ;

[0077] rescue vehicle RV i Calculate the anonymous password RPW i ′=h(PW i ||s i ) and challenges Response R is calculated based on its own PUF. i =PUF(C) i Simultaneously calculate fusion features. Secret Value UR i ' = RF(BRi', UPi) and authentication message A0' = h(RPW) iThe system checks if A0 and A0′ in the rescue vehicle database are equal (|IDi|URi′). If they are not equal, the process terminates; if they are equal, then user U... i and rescue vehicle RV i Successfully linked. Proceed to the next step.

[0078] rescue vehicle RV i Calculate the anonymous identity PID i ′=h(ID i ||R i ′), Select an anonymous drone identity (DID) from the rescue vehicle database. j Based on drone anonymity DID j Calculate intermediate parameters and intermediate parameter N0 = h(PID) i ′||DID j Select a random number s1 as the first temporary secret data, and calculate the Chebyshev polynomial N1 = T. s1 (N0) and authentication information M1 = h(DID) j ||C i ′||N1||UR i Send verification message {PID ') i ′,F i N1, M1} to the rescue center RC;

[0079] The rescue center (RC) received the rescue vehicle RV. i The verification message sent {PID i ′,F i After N1, M1}, based on PID i Search the database for the corresponding challenge C i and A i Then calculate the secret value. Drone Anonymous And calculate the authentication information M1′=h(DID) j ′||C i ||N1||UR i The function verifies whether M1′ and M1 are equal. If they are not equal, the login process terminates; if they are equal, the login process succeeds.

[0080] Authentication and key negotiation phase: User U i and rescue vehicles RV i With drones (UAVs) j With the assistance of the rescue center RC, they authenticated each other and negotiated a shared session key SK.

[0081] During the authentication and key negotiation phase, users, rescue vehicles, and drones authenticate each other with the assistance of the rescue center and negotiate a shared session key. This session key is based on a Chebyshev chaotic mapping constructed from the different responses generated by the rescue vehicle and drone in each round of the session, ensuring perfect forward confidentiality of the protocol. Furthermore, the rescue center only participates in the authentication process and not in the session negotiation process, avoiding the threat of session key leakage due to malicious behavior by the rescue center. Figure 7 As shown, the authentication and key negotiation process is as follows:

[0082] The rescue center (RC) selects a random number s2 as the second temporary secret data and calculates the Chebyshev polynomial N2 = s2⊕h(DID). j ′), intermediate parameters And based on the drone's anonymous identity DID j Search for Challenge C in the rescue center database j Calculate authentication information M2 = h(DID) j ′||PID i ||N1||N2), then send the message body {N1,N2,A1,C j M2} for UAVs j ;

[0083] UAVs j Received message body {N1,N2,A1,C j After M2}, the rescue center RC uses the PID obtained in the previous step. i and DID j ', calculate N0 = h(PID) which is the same as the user terminal. i ||DID j Then, a random number s3 is selected as the third temporary secret data, and the Chebyshev polynomial N3 = T is calculated. s3 (N0), thus obtaining And obtain the shared key SK=T s3 (N1) and M3 = h(SK||DID) j ′||PID i (||N1||N3), and finally send the message body {A2,M3} to the rescue vehicle RV. i ;

[0084] rescue vehicle RV i Received UAV j After sending the message body {A2,M3}, calculate and SK=T s1 (N3), and calculate the authentication information M3′=h(SK||DID) j ||PID iThe function verifies whether M3′ and M3 are equal. If they are equal, the authentication passes; otherwise, the authentication fails.

[0085] Furthermore, the method also includes:

[0086] Password and biometric update phase: User U i Enter identity ID i ,Old Password and old biological characteristics To the rescue vehicle RV i rescue vehicle RV i For user U i The system verifies the user's old password and biometric signature. After successful verification, the user enters their identity ID. i ,New Password and new biological characteristics The rescue vehicle RV will be updated based on the new password and new biometrics. i The corresponding information in the database.

[0087] When a user's password or biometric data is compromised, our solution provides password and biometric update functionality and selects a new CRP participant for each session to ensure the uniqueness of each session. Figure 7 As shown, the process of updating the password and biometrics is as follows:

[0088] User U i First, enter your unique ID. i ,Old Password and old biological characteristics To the rescue vehicle RV i rescue vehicle RV i Calculate anonymous passwords challenge Calculate R based on its own PUF(·) i =PUF(C i Simultaneously calculate fusion features Secret Value UR i ′=RF(BR i ,UP i ) and A0′=h(RPW i ||ID i ||UR i The process involves checking whether equation A0′ is equal to A0. If they are not equal, the process terminates; otherwise, the rescue vehicle RV... i To user U i Request a new password and new biometrics;

[0089] After receiving the request, user U i To the rescue vehicle RV i Enter IDi new and rescue vehicle RV i Calculate new anonymous passwords Select unused vehicles from the rescue vehicle database. Calculate new Calculate the new response based on its own PUF(·) Simultaneously calculate new fusion features and rescue vehicle RV i use Replace {E} in the rescue vehicle database i ,UP i DID j ,A0,s i};Rescue vehicle RV i calculate and the new message body The message is passed to the rescue center RC. After receiving it, the rescue center RC will... Stored in the rescue center's database.

[0090] Furthermore, after completing the session using the shared session key SK negotiated during the authentication and key negotiation phase, the information is updated by performing a user password and biometric update phase.

[0091] The method provided in this invention binds the device to the user by integrating user biometrics and device PUF response on the user end, preventing unauthorized login. PUF is also used to protect rescue vehicles and remote drones from physical attacks. Password and biometric update mechanisms are applied to prevent password guessing and biometric leakage.

[0092] Example 2:

[0093] like Figure 8 and Figure 9 As shown, this embodiment of the invention provides the AVISPA formal software verification process.

[0094] This invention uses the formal security verification tool AVISPA, based on High Level Protocol Specification Language (HLPSL), to verify the anti-attack capability (e.g., replay attacks and man-in-the-middle attacks) of the protocol scheme under the DY model. Since the computation of cryptographic primitives in the protocol scheme involves XOR operations, the security of the protocol is evaluated by executing a Backend Dynamic Model Checker (OFMC) and a Constraint Logic-Based Attack Searcher (CL-AtSE). First, mobile user U is defined based on HLPSL rules.i Rescue server (RC) and UAV (Unmanned Aerial Vehicle) j This includes implementing relevant roles and functions such as registration, login, authentication, and key negotiation. For example... Figure 8 As shown, the SUMMARY output of the protocol analysis is SAFE, proving that the protocol designed in this paper is secure. Next, the security protocol animator (SPAN) is used to simulate the attack behavior of a malicious intruder. The simulation results are as follows. Figure 9 As shown in the figure. This demonstrates that the method provided by the present invention has excellent security resilience against passive or active attacks such as man-in-the-middle attacks and replay attacks.

[0095] This invention primarily satisfies 17 security objectives, and the process is described in detail below:

[0096] G1 Mutual Authentication: In the method provided by this invention, the rescue vehicle RV i By calculating A0 = h(RPW) i ||ID i ||UR i To authenticate user U i Because only legitimate user U i With the correct password PW i Identity ID i and biometrics BIO i Only by fusing the results with specific PUF responses can A0 be constructed, thereby realizing user U i With rescue vehicle RV i The unique binding. The Rescue Center (RC) calculates M1 = h(DID) j ||C i ||N1||UR i To certify rescue vehicles (RVs) i UAV (Unmanned Aerial Vehicle) j By calculating M1 = h(DID) j ||C i ||N1||UR i The certification of the rescue center (RC) indicates that the UAV (Unmanned Aerial Vehicle) is a type of drone. j User U was verified i rescue vehicle RV i Furthermore, by calculating M2 = h(DID) j ||PID i ||N1||N2) for UAVs j The certification process completes the verification of the rescue vehicle RV. i With drones (UAVs) j The mutual authentication objectives between them.

[0097] G2 Security Key Negotiation: In the method provided by this invention, the UAV (Unmanned Aerial Vehicle) j After the Authentication and Rescue Center (RC) is authenticated, a session key SK=T is generated using secret parameters. s3 (N1), rescue vehicle RV i Received UAV j The sent message also generates a session key SK=T s1 (N3), and by calculating M3=h(SK||DID) j ||PID i ||N1||N3) to verify the UAV (Unmanned Aerial Vehicle) j The correctness of the sent message. Here, according to the property of the extended Chebyshev chaotic mapping semigroup, it can be known that T s3 (N1)=T s1 (N3), therefore the rescue vehicle RV i With drones (UAVs) j They negotiated a shared session key, SK.

[0098] G3 User Anonymity and Untraceability: In the method provided by this invention, only when the PUF response R is known... i Only under these conditions can the adversary generate an anonymous identity PID. i =h(ID) i ||R i However, due to the collision resistance of PUF, it is difficult for adversaries to calculate PID. i Furthermore, even if the adversary obtains {PID} by monitoring public channels... i ,F i ,N1,M1}, where PID i =h(ID) i ||R i Furthermore, adversaries are unable to extract the real identity ID of a user protected by one-way hashes. i Furthermore, during the update phase, after each session negotiation is completed, the user's anonymous identity (PID) is... i All will respond with PUF R i It updates accordingly. Therefore, adversaries cannot track a user's true identity by linking multiple messages.

[0099] G4 Perfect Forward Secrecy: In the method provided by this invention, the session key SK = T s3 (N1) or SK = T s1 (N3), where N1 = T s1 (N0), N3 = T s3 (N0), N0 = h(PID) i ||DID j ), rescue vehicle RV i Storing long-term secrets {Ei ,UP i DID j ,A0,s i}, the rescue center RC terminal stores {C i DID j} and {C i A i ,PID i Even if the opponent calculates N0 = h(PID) i ||DID j Furthermore, by eavesdropping on N1 and N3, according to the extended Chebyshev chaotic mapping CMDLP theorem, the adversary cannot obtain the random numbers s1 and s3, and therefore cannot calculate the session key SK. Thus, our protocol maintains perfect forward secrecy.

[0100] G5 Known Session Key Security: Based on the security description of G3, we know that the current session is independent of previous sessions, making it difficult for attackers to trace the device's true identity across different sessions. Furthermore, according to the security analysis of G4, the session key SK and the PUF response R... i and R j Random numbers s1 and s3 are related. Where R... i and R j Since the random numbers s1 and s3 are unique and randomized in each round of the session, the session key SK generated in each round is independent. Therefore, even if an adversary obtains the session key from the previous round, they cannot deduce the newly constructed session key for the current round, thus achieving security with a known session key.

[0101] G6 without clock synchronization: In the method provided by this invention, random numbers are used instead of timestamps to ensure the freshness of messages and to avoid the difficulty of setting up clock synchronization between different participants.

[0102] G7 Multi-Factor Security: The method provided in this invention includes a cryptographic PW. i Biometrics BIO i and rescue vehicles RV i This invention enhances the security of user equipment by responding to three security factors. It ensures that the method remains secure even if any two of the three factors are compromised. In other words, without knowing all three factors, an adversary cannot successfully sabotage the RV. i Establish a valid connection with the rescue center RC. The specific analysis is as follows: (1) Assume that the adversary knows the password PW i and user rescue vehicles RV i PUF response R i Because the opponent cannot obtain the user's biometrics (BIO) iSecret fusion eigenvalue UR i It cannot be obtained by the opponent; verify parameter A0 = h(RPW) i ||ID i ||UR i ) cannot be calculated, M1 = h(DID) j ||C i ||N1||UR i It is also impossible to calculate, user U i Authorized access to the Rescue Center (RC) will be blocked. (2) Assuming the adversary obtains the Rescue Vehicle (RV). i PUF response and biomarkers BIO i Because the opponent did not know the password PW i Therefore, the anonymous password RPW cannot be calculated. i =h(PW i ||s i Unable to calculate A0 = h(RPW) i ||ID i ||UR i (3) Assuming the adversary obtains the password PW, then authorized access to the rescue center RC will be impossible. i and biometrics BIO i Since the adversary cannot possess a rescue vehicle with a built-in PUF, and due to the inherent non-cloning nature of PUF, they are unable to obtain the corresponding response. i Based on the formula UR i =RF(BR) i ,UP i The opponent cannot calculate the secret fusion characteristic value UR. i Therefore, it cannot be successfully verified.

[0103] Based on the above three situations, it can be proven that the method provided by this invention can guarantee multi-factor security.

[0104] G8 Biometric Privacy Protection: As the above analysis shows, biometrics play a crucial role in three-factor authentication, with secret fusion of feature values ​​(UR) being key. i Biometrics required i Only through participation can it be obtained. Rescue vehicle RV i This is also a key factor in user vehicle login and rescue center RC verification. Therefore, the leakage of biometric data can cause serious privacy risks and even authentication failure. This invention is based on... and UR i =RF(BR) i ,UP i Biometrics (BIO) i With built-in PUF rescue vehicle RV iThe response performs feature fusion and only stores auxiliary data (UP). i This achieves privacy protection for biometrics.

[0105] G9 defends against offline dictionary guessing attacks: assuming the adversary acquires the RV (Rescue Vehicle). i PUF and corresponding user biometrics (BIO) i According to the PUF response R i and biometrics BIO i The secret fusion characteristic value UR can be obtained. i Since A0 = h(RPW) i ||ID i ||UR i ), RPW i =h(PW i ||s i Therefore, we need to guess the ID. i and PW i The combination is not easy.

[0106] G10 Defense Against Desynchronization Attacks: Updating CRP during authentication is typically susceptible to desynchronization attacks. Therefore, the method provided in this invention updates passwords and biometrics without server involvement, avoiding asynchrony between user's local data and rescue center data. Furthermore, when a new session begins after the end of one session, rescue vehicles and drones with built-in PUF select a new random CRP for the new authentication process, satisfying the security requirement of different sessions using different CRPs and resisting desynchronization attacks during authentication.

[0107] G11 Defends Against Privileged Insider Attacks: In the method provided by this invention, the user's real identity ID i Only with PID i =h(ID) i ||R i ) and A0 = h(RPW i ||ID i ||UR i This is related to the fact that even if the opponent has internal privileges and obtains the rescue vehicle RV, it is still considered a valid outcome. i {E stored in i ,UP i DID j ,A0,s i} and the rescue center RC end storage {C i DID j} and {C i A i ,PID i It is also impossible to extract the real identity ID protected by one-way hash. i Similarly, the drone's real identity ID. jAnd also cannot be obtained from DID j =h(ID) j ||R j Extracted from the hash protection of ), at the same time, the rescue vehicle RV i RVs were not stored in the rescue center RC. i Response R i and UAVs j Response R j This prevents CRP leaks. Therefore, our protocol can effectively defend against privileged insider attacks.

[0108] G12 Protects Against UAV Tampering and Cloning Attacks: The method provided in this invention designs a PUF (Programmable Activated Firewall) unit in the UAV to prevent tampering and impersonation after the UAV is captured. In other words, based on the inherent properties of the PUF, even if the UAV is tampered with or cloned, it can still prevent such attacks. j Once captured, the opponent cannot tamper with or clone the real response R. j Based on DID j =h(ID) j ||R j ), N0 = h(PID) i ||DID j N3 = T s3 (N0), and session key SK=T s1 (N3) shows that the adversary cannot construct a true SK. Furthermore, UAVs... j It does not store any secret information, therefore, the protocol is resistant to UAV tampering and cloning attacks.

[0109] G13 defends against vehicle theft attacks: As clearly stated in the three-factor security analysis, even if an adversary obtains the user's password and possesses the rescue vehicle equipment, or if an adversary obtains the user's biometrics and possesses the rescue vehicle equipment, they cannot calculate the session key SK. Furthermore, the information stored in the rescue vehicle is encrypted; even if extracted by an adversary, no information related to SK can be obtained. Therefore, this protocol can defend against vehicle theft attacks.

[0110] G14 Defense Against Secret Leakage Attacks: Perfect forward secrecy has proven that even if the long-term secrets stored by all participants are leaked, the security of the session key remains unaffected. Therefore, this invention only considers the impact of temporary secret data pairs. The temporary secret data s1, s2, and s3, randomly generated during the authentication process, are encrypted during transmission, thus preventing adversaries from obtaining this information. Furthermore, even if an adversary obtains s1, s2, and s3, the construction of the session key SK still requires the secret parameter R. i With R jAs mentioned above, both parameters require an adversary to obtain them based on a specific challenge and the corresponding PUF function. Due to the specific properties of PUF, the adversary will be unable to calculate and obtain the final session key. Furthermore, PUF responses are usually deleted within a very short time, making this threat negligible. Therefore, the method provided by this invention can defend against secret disclosure attacks.

[0111] G15 Defense Against Common Attacks: The system must provide security against common threats such as man-in-the-middle, impersonation, and replay attacks. The method provided in this invention transmits information {PID} during the authentication process. i ,F i {N1,M1}、{N1,N2,A1,C} j Both {A2,M3} are based on temporary secret data s1, s2, and s3, and the anonymous identity PID. i and DID j and PUF response R i and R j The parameters are updated in each session, preventing adversaries from resending them for successful authentication. Therefore, the method provided by this invention is resistant to replay attacks. Furthermore, the authentication process is based on real-time generation using a PUF, and messages are transmitted encrypted. This also protects against man-in-the-middle attacks. Regarding simulation attacks, based on the G7 discussion, no matter which two factors an adversary obtains, they cannot simulate a user or a rescue vehicle. Here, we focus on RC (Rescue Center) simulation attacks and UAV (Unmanned Aerial Vehicle) attacks. j Simulated attack. The adversary cannot clone the same PUF to implement authentication, therefore it cannot simulate a legitimate drone sending messages and successfully authenticating. For a rescue center RC simulation attack, if the adversary wants to simulate a rescue center RC, it needs to successfully construct the message {N1, N2, A1, C...} j M2} passes authentication. Authentication information M2 = h(DID) j ||PID i The construction of ||N1||N2) is based on temporary secret data s1, s2 and PUF response R. i and R j , where s1 and s2 are both encrypted during transmission. And R i and R j Since the adversary cannot replicate the same PUF and therefore cannot construct it, they cannot simulate the correct message and pass authentication. This proves that the present invention can resist RC simulation attacks from the Rescue Center.

[0112] G16 Update: Through the implementation process of password and biometric update phases and the G5 security attribute analysis process, this invention confirms that different CRPs are used in different sessions.

[0113] G17 User Equipment Physical Protection: As can be seen from the discussion of G13 security attributes, this invention can provide physical protection for user login devices.

[0114] Based on the above security objectives, this invention provides a comprehensive evaluation mechanism to demonstrate the effectiveness of the proposed protocol by comparing it with existing technologies [1], [2], [3], [4], and [5]. As shown in Table 1, it can be seen that in the first two schemes, the user device only implements direct login authentication of the user's identity on the device, which cannot prevent unauthorized login by adversaries. Moreover, the device does not provide PUF physical protection, so it cannot protect the user's correct password and biometrics from the uniqueness of the specific device. Although the latter three protocols have built-in PUF for physical protection on the user's device, [4] and [5] both use timestamps to verify the real-time nature of messages, so clock synchronization is required, which increases the difficulty of authentication. [3] and [4] cannot resist secret leakage attacks and do not provide password biometric updates. Furthermore, [4] lacks the ability to resist privileged internal attacks and password guessing attacks. Based on the above analysis, this invention achieves all the expected objectives. While balancing security and lightweight, it provides more functional features.

[0115] Table 1 Comparison of Protocol Security Attributes

[0116]

[0117]

[0118] [1]Cui J, Yu J, Zhong H, et al. Chaotic map-based authentication scheme using physical unclonable function for internet of autonomous vehicle [J]. IEEE Transactions on Intelligent Transportation Systems, 2022, 24(3): 3167-3181.

[0119] [2]Wang D,Cao Y,Lam K Y,et al.Authentication and Key Agreement BasedOn Three Factors and PUF for UAVs-Assisted Post-Disaster EmergencyCommunication[J].IEEE Internet of Things Journal,2024.

[0120] [3]Mao R,Ji H,Wang X.Dynamic Authentication Mechanism Research andSecurity Protocol Design of HIOT[C] / / 2022IEEE Symposium on Computers andCommunications(ISCC).IEEE,2022:1-8.

[0121] [4]Su X,Xie Y,Wang H,et al.Secure and efficient anonymousauthentication key agreement scheme for smart industry[C] / / 2022IEEE 28thInternational Conference on Parallel and Distributed Systems(ICPADS).IEEE,2023:250-257.

[0122] [5]Yu S,Das AK,Park Y,et al.SLAP-IoD:Secure and lightweightauthentication protocol using physical unclonable functions for internet ofdrones in smart city environments[J].IEEE Transactions on VehicularTechnology,2022,71(10):10374-10388.

[0123] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A multi-factor security authentication method for emergency rescue access control of unmanned aerial vehicles (UAVs), characterized in that, It includes the initialization phase, registration phase, login phase, and authentication and key negotiation phase; During the initialization phase: the Rescue Center (RC) releases initialization-related parameter information; these parameters include the secret extraction function BF(·), the secret reconstruction function RF(·), and the one-way hash function h:{0,1}. * And the physically unclonable function PUF(·); The registration phase includes both the drone registration phase and the user and rescue vehicle registration phase; wherein... The drone registration phase: UAV j Register with the Response Center (RC) based on your own PUF response; The specific process of the drone registration phase is as follows: UAVs j Identity ID j Send to the Rescue Center (RC), which generates a set of random challenges. Send to UAV j ; UAVs j Received random challenge C j Then, based on its own PUF(·), the corresponding response R is generated. j =PUF(C j ), and the response Send to the Rescue Center (RC); The rescue center (RC) received a UAV (unmanned aerial vehicle). j Response R j The drone's anonymous identity DID is then generated. j =h(ID) j ||R j ), and {C j DID j Stored in the rescue center's database; The user and rescue vehicle registration phase: User U i Based on identity ID i and password RPW i The user submits a registration request to the rescue center (RC). Upon receiving the request, the rescue center (RC) sends the registration information back to the user. i User U i The registration information and biometrics (BIO) i Send to rescue vehicle RV i rescue vehicle RV i Register with the RC (Rescue Center) based on your own PUF (Public Assistance Facility) and the information you receive; The specific process for the user and rescue vehicle registration phase is as follows: User U i Select Identity ID i Password PW i and random numbers Calculate the anonymous password RPW i =h(PW i ||s i ), the anonymous password RPW i and the drone identity ID that the user wants to access j Send to the Rescue Center (RC); where h() represents a one-way hash function. The rescue center (RC) received the anonymous password RPW. i and the drone identity ID that you wish to access j Then, a set of random challenges is generated. The anonymous identity DID corresponding to the drone that the user wishes to access. j and the random challenge C i Return to user U i ; User U i The received {C i DID j } and biometric information BIO i Send to rescue vehicle RV i rescue vehicle RV i The response R is calculated based on its own PUF(·). i =(C i ), intermediate parameters Fusion features and (UR) i ,UP i ) = BF(BR i ), of which UR i For secret value, UP i The verification code is stored as a secret value; the anonymous identity PID is calculated simultaneously. i =h(ID) i ||R i ), intermediate parameters And authentication message A0 = h(RPW) i ||ID i ||UR i ); {E i ,UP i ,PID j ,A0,s i } Stored in the rescue vehicle database, and simultaneously send message body {A i ,PID i } to the rescue center RC; The rescue center RC received message body {A i ,PID i After that, store {C} i A i ,PID i } to the rescue center database; The login phase: User U i Based on cryptographic RPW i and biometrics BIO i With rescue vehicle RV i Binding is required; after binding, the rescue vehicle (RV) i The verification message is sent to the rescue center RC based on Chebyshev polynomial. Once the rescue center RC verifies the message, the login is successful. The authentication and key negotiation phase: User U i and rescue vehicles RV i With drones (UAVs) j With the assistance of the rescue center RC, they authenticated each other and negotiated a shared session key SK.

2. The multi-factor security authentication method for emergency rescue access control of unmanned aerial vehicles according to claim 1, characterized in that, The specific process of the login phase is as follows: User U i Enter identity ID i Password PW i and biometrics BIO i To the rescue vehicle RV i ; rescue vehicle RV i Calculate the anonymous password RPW i ′=h(PW i ||s i ) and challenges Response R is calculated based on its own PUF. i =PUF(C) i Simultaneously calculate fusion features. Secret Value UR i ′=RF(BR i ′,UP i ) and authentication message A0′ = h(RPW i ′||ID i ||UR i The system checks whether A0 and A0′ in the rescue vehicle database are equal. If they are not equal, the process terminates; if they are equal, then user U... i and rescue vehicle RV i Successfully linked. Proceed to the next step. rescue vehicle RV i Calculate the anonymous identity PID i ′=h(ID i ||R i ′), Select a drone anonymous identity DID from the rescue vehicle database. j Based on drone anonymity DID j Calculate intermediate parameters and intermediate parameter N0 = h(PID) i ′||DID j Select a random number s1 as the first temporary secret data, and calculate the Chebyshev polynomial N1 = T. s1 (N0) and authentication information M1 = h(DID) j ||C i ′||N1||UR i Send verification message {PID ') i ′,F i N1, M1} to the rescue center RC; The rescue center (RC) received the rescue vehicle RV. i The verification message sent {PID i ′,F i After N1, M1}, based on PID i Search the database for the corresponding challenge C i and A i Then calculate the secret value. Drone Anonymous And calculate the authentication information M1′=h(DID) j ′||C i ||N1||UR i The function verifies whether M1′ and M1 are equal. If they are not equal, the login process terminates; if they are equal, the login process succeeds.

3. A multi-factor security authentication method for emergency rescue access control of unmanned aerial vehicles according to claim 2, characterized in that, The specific process of the authentication and key negotiation phase is as follows: The rescue center (RC) selects a random number s2 as the second temporary secret data to calculate the Chebyshev polynomial. intermediate parameters And based on the drone's anonymous identity DID j Search for Challenge C in the rescue center database. j Calculate authentication information M2 = h(DID) j ′||PID i ||N1||N2), then send the message body {N1,N2,A1,C j M2} for UAVs j ; UAVs j Received message body {N ′ ,N2,A1,C j After M2}, the rescue center RC uses the PID obtained in the previous step. i and DID j ', calculate N0 = h(PID) which is the same as the user terminal. i ||DID j Then, a random number s3 is selected as the third temporary secret data, and the Chebyshev polynomial N3 = T is calculated. s3 (N0), thus obtaining And obtain the shared key SK=T s3 (N1) and M3 = h(SK||DID) j ′||PID i (||N1||N3), and finally send the message body {A2,M3} to the rescue vehicle RV. i ; rescue vehicle RV i Received UAV j After sending the message body {A2,M3}, calculate and SK=T s1 (N3), and calculate the authentication information M3′=h(SK||DID) j ||PID i The function verifies whether M3′ and M3 are equal. If they are equal, the authentication passes; otherwise, the authentication fails.

4. The multi-factor security authentication method for emergency rescue access control of unmanned aerial vehicles according to claim 1, characterized in that, The method also includes a password and biometric update phase; The password and biometric update phase: User U i Enter identity ID i ,Old Password and old biological characteristics To the rescue vehicle RV i rescue vehicle RV i For user U i The system verifies the user's old password and biometric signature. After successful verification, the user enters their identity ID. i ,New Password and new biological characteristics The rescue vehicle RV will be updated based on the new password and new biometrics. i The corresponding information in the database and the rescue center's RC database.

5. A multi-factor security authentication method for emergency rescue access control of unmanned aerial vehicles according to claim 4, characterized in that, The specific process of the password and biometric update phase is as follows: User U i First, enter your unique ID. i ,Old Password and old biological characteristics To the rescue vehicle RV i rescue vehicle RV i Calculate anonymous passwords challenge Calculate R based on its own PUF(·) i =PUF(C i Simultaneously calculate fusion features Secret Value UR i ′=RF(BR i ,UP i ) and A0′=h(RPW i ||ID i ||UR i The process involves checking whether equation A0′ is equal to A0. If they are not equal, the process terminates; otherwise, the rescue vehicle RV... i To user U i Request a new password and new biometrics; After receiving the request, user U i To the rescue vehicle RV i Enter ID i new and rescue vehicle RV i Calculate new anonymous passwords Select unused vehicles from the rescue vehicle database. Calculate new Calculate the new response based on its own PUF(·) Simultaneously calculate new fusion features and rescue vehicle RV i use Replace {E} in the rescue vehicle database i ,UP i DID j ,A0,s i };Rescue vehicle RV i calculate and the new message body The message is passed to the rescue center RC. After receiving it, the rescue center RC will... Stored in the rescue center's database.

6. A multi-factor security authentication method for emergency rescue access control of unmanned aerial vehicles according to claim 4 or 5, characterized in that, After completing the session using the shared session key SK negotiated in the authentication and key negotiation phase, the information is updated in the user password and biometrics update phase.

Citation Information

Patent Citations

  • Automatic driving vehicle network authentication and key agreement method based on chaotic mapping

    CN114205091A

  • Post-disaster elastic emergency communication method and system based on authentication and key agreement protocol

    CN118413837A