Lightweight unmanned aerial vehicle identity authentication method based on PUF
By adopting a lightweight PUF-based identity authentication method in drone communication, combined with TinyMT and Curve25519 algorithms, the problems of high complexity of identity authentication and insufficient attack resistance in drone communication are solved, low-power, high-efficiency identity authentication and key negotiation are achieved, and the security and flexibility of the system are enhanced.
Patent Information
- Application Number
- CN202510075791.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-17
- Publication Date
- 2025-05-16
AI Technical Summary
In existing UAV communications, the identity authentication complexity is high, the resource consumption is large, and the attack resistance is insufficient, making it difficult to meet the continuous mission needs of resource-constrained UAV equipment.
The lightweight drone identity authentication method based on PUF is adopted, combined with the TinyMT pseudo-random number generator and the Curve25519 elliptic curve encryption algorithm, and the non-clone feature of the PUF response value is used to achieve efficient identity authentication, and the system security is enhanced through memory integrity checksum dynamic key update.
It significantly reduces the computing and storage resource requirements of the authentication process, enhances the defense capabilities of man-in-the-middle attacks and replay attacks, improves the security and flexibility of the system, and is suitable for resource-constrained drone equipment.
Smart Images

Figure CN120017281A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of unmanned aerial vehicle communication security technology, and in particular to a lightweight unmanned aerial vehicle identity authentication method based on PUF. Background Art
[0002] With the rapid development of drone technology, drones have been widely used in logistics, military reconnaissance, disaster relief and other fields. However, the security of drone communication links has a crucial impact on the success of the mission. In an open communication environment, drones are vulnerable to security threats such as man-in-the-middle attacks, replay attacks and injection attacks, which can lead to mission failure or data leakage. Therefore, how to implement a lightweight, efficient and secure identity authentication mechanism has become a key issue in the field of drone communication security.
[0003] At present, most authentication methods are based on traditional symmetric encryption or public key encryption technology. However, although traditional authentication methods, such as AES and RSA, have good security, they significantly increase the system burden of drones in terms of computational complexity and energy consumption. In resource-limited drone devices, these algorithms lead to communication delays and shortened battery life, and cannot meet the needs of mission continuity. In recent years, Physical Unclonable Function (PUF) has gradually attracted attention as a lightweight authentication technology based on hardware characteristics. PUF generates random response values by utilizing the hardware uniqueness of the device, fundamentally reducing the storage requirements of encryption keys and reducing the algorithm complexity, which is particularly suitable for resource-constrained drone devices. However, existing PUF-based authentication methods still have many shortcomings, such as high encryption algorithm complexity and low memory integrity verification efficiency.
[0004] In view of the above problems, the present invention proposes a lightweight UAV identity authentication method based on PUF. By combining a lightweight pseudo-random number generator (TinyMT) and an elliptic curve encryption algorithm (Curve25519), it not only significantly reduces the computation and storage consumption of the authentication process, but also enhances the defense capability against man-in-the-middle attacks and replay attacks. In addition, the introduction of memory integrity verification further improves system security. This method makes full use of the non-clonable characteristics of the PUF response value, realizes efficient identity authentication of UAV equipment under resource-constrained conditions, and provides a feasible solution for UAV communication security. Summary of the invention
[0005] In view of the problems of high complexity, large resource consumption and insufficient anti-attack ability in existing drone communications, the present invention provides a lightweight drone identity authentication method based on PUF, which combines the physical unclonable function technology (PUF) with a lightweight encryption algorithm to significantly reduce the computing and storage resource requirements of the authentication process and enhance the security of the communication process.
[0006] To this end, the present invention proposes a lightweight identity authentication method for resource-constrained devices, which combines PUF technology to achieve efficient identity authentication, specifically including the following steps:
[0007] S1, the precondition, includes the following steps:
[0008] S1.1, the server pre-stores sufficient challenge-response pairs (CRPs) in a secure environment for device uniqueness verification. After storage is completed, the direct access path is permanently removed to enhance system security;
[0009] S1.2, the server assigns a unique identity to each drone and securely transmits the identity to the drone in an encrypted manner to ensure the security and confidentiality of the identity;
[0010] S1.3, the server and the drone complete the public key exchange in a secure environment for subsequent encrypted communication to ensure the confidentiality and integrity of data during the communication process;
[0011] S2, the registration phase, includes the following steps:
[0012] S2.1, the server uses the pre-stored CRP and pseudo-random number generator (PRNG) to generate an initial registration message containing a random number (Nonce) and a challenge (Challenge) for verifying the freshness of the message, and sends the message to drone A and drone B respectively;
[0013] S2.2, after receiving the message, the drone first verifies the freshness of the message to confirm that it has not been replayed, then generates a response value through PUF, and generates an identity identifier in combination with a hash function, and then integrates the identity identifier and the response value into registration verification information and sends it back to the server;
[0014] S2.3, after receiving the registration verification message, the server verifies the legitimacy of the drone identity, and uses PRNG to generate encryption parameters such as timestamp and auxiliary data, creates an encrypted message containing the identity, timestamp and auxiliary data, and encrypts it with the drone public key and sends it to the drone;
[0015] S2.4, after receiving the encrypted message, the drone uses the private key to decrypt and extract the timestamp and auxiliary data, verifies the correctness of the timestamp, locates the corresponding memory data block through the additional parameters, generates the memory integrity check value using the hash function, and generates the final verification message in combination with the verification information and sends it to the server;
[0016] S2.5, after receiving and decrypting the final verification message, the server checks the timestamp and integrity check value. After the verification is passed, it generates a registration confirmation message and sends it to the drone;
[0017] S2.6, after receiving the registration confirmation message, the drone decrypts and extracts the registration information and stores it securely locally, completing the registration process.
[0018] S3, the identity authentication phase, includes the following steps:
[0019] S3.1, UAV A generates a random number and processes it through a hash function to form an authentication request message, which is sent to UAV B;
[0020] S3.2, after receiving the authentication request message, UAV B verifies the integrity of the message and the freshness of the random number. After confirming that the message has not been tampered with, it generates a PUF response value, and generates an authentication value in combination with the identity identifier. At the same time, it generates a new random number, integrates the above information into an authentication reply message and sends it to UAV A;
[0021] S3.3, after receiving the authentication reply message, UAV A verifies the correctness of the hash value and the random number. After confirming that the message has not been tampered with, it generates a response value through PUF and verifies it in combination with the authentication value of UAV B. If the authentication values match, it generates a new authentication value and random number to form an authentication confirmation message and sends it to UAV B;
[0022] S3.4, after receiving the authentication confirmation message, UAV B verifies whether the authentication value in the message is consistent with the stored value, and verifies whether the random number meets the freshness requirement. If the verification is successful, the authentication is completed;
[0023] S3.5, UAV A and UAV B generate a shared session key based on the authentication result for subsequent secure communication.
[0024] Compared with the prior art, the present invention has the following beneficial effects:
[0025] (1) Low power consumption, high efficiency identity authentication and key negotiation
[0026] The present invention combines PUF technology, TinyMT pseudo-random number generator and Curve25519 elliptic curve encryption algorithm to achieve efficient identity authentication and key negotiation in a low-power environment. Compared with traditional solutions, the physical unclonability of PUF and the pseudo-random number generator with low computational overhead significantly reduce the computational complexity and resource consumption, which is particularly suitable for resource-constrained drone equipment.
[0027] (2) Memory integrity check and dynamic key update
[0028] The memory integrity verification mechanism proposed in this invention reduces the computational burden of the verification process and improves the anti-tampering capability by randomly selecting memory data blocks for hash verification. At the same time, the dynamic key update mechanism regularly updates the PUF key as the device runs, enhancing the long-term security of the authentication process and avoiding the risk of key leakage and long-term attacks.
[0029] (3) Multiple protection mechanisms
[0030] The present invention innovatively designs a multiple protection mechanism by combining a timestamp mechanism, a pseudo-random number generator and a hash function, which effectively prevents replay attacks, forgery attacks and data tampering. This mechanism ensures the uniqueness and security of each authentication, and is particularly suitable for drone communications with high security requirements.
[0031] (4) Cross-domain authentication capability
[0032] The authentication mechanism of the present invention provides flexible scalability for identity authentication between drones by combining a pseudo-random number generator and a challenge-response pair (CRP), and can support authentication in different domains. Although the current solution is mainly aimed at authentication needs within a single domain, its design can be flexibly expanded to multiple fields or regions to meet the needs of multi-drone collaborative operations and cross-domain applications. This scalability makes the system highly flexible and extensible, and is suitable for more complex application scenarios. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] Figure 1 A schematic diagram of the system module structure of an embodiment of the present invention;
[0034] Figure 2 A schematic diagram of a pre-condition operation according to an embodiment of the present invention;
[0035] Figure 3 A detailed flow chart of the registration phase of an embodiment of the present invention;
[0036] Figure 4 A detailed flow chart of the authentication phase of an embodiment of the present invention;
[0037] Figure 5 A schematic diagram of the memory integrity verification mechanism according to an embodiment of the present invention; Figure 6 A schematic diagram of the composition of an authentication device according to an embodiment of the present invention; DETAILED DESCRIPTION
[0038] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0039] See also Figures 1 to 5 ,The present invention provides a PUF-based lightweight UAV identity authentication method, which includes a precondition stage, a registration stage and an authentication stage.
[0040] For the overall framework phase, see Figure 1 The overall framework stage shows the functional division of labor and mutual cooperation between the modules in the present invention, which specifically includes the following modules:
[0041] S1.1, PUF module: This module is used to generate challenge-response pairs (CRP) to ensure the uniqueness of device authentication. CRP is generated through the physical unclonable function (PUF) to verify the legitimacy of the drone's identity and provide a basis for subsequent identity authentication;
[0042] S1.2, random number generator module: This module is responsible for generating random numbers and timestamps to ensure the uniqueness and freshness of each communication and effectively prevent replay attacks. The generation of random numbers is based on a lightweight pseudo-random number generator (TinyMT) to meet the efficiency requirements in resource-constrained environments;
[0043] S1.3, Authentication module: The authentication module is the core logic control center, responsible for coordinating data interaction between modules, completing encryption, decryption and identity authentication operations, and ensuring the smooth progress of the overall authentication process;
[0044] S1.4, encryption module: This module combines the elliptic curve cryptography (ECC) algorithm with the hash function to implement data encryption, identity generation and integrity verification operations, further improving the security of communications;
[0045] S1.5, Communication module: The communication module is used to transmit authentication-related data, ensure the security and integrity of data during transmission, and avoid the risk of data leakage or tampering;
[0046] Precondition stage, see Figure 2 ,The precondition stage is the initial interaction process completed between the server and the drone in a safe environment, including the secure transmission and storage of data.,When the server and the drone perform precondition settings in a safe environment,,it includes the following steps:
[0047] S2.1, in a secure environment, the server pre-stores a sufficient number of Challenge-Response Pairs (CRPs), which are generated by the drone based on the Physical Unclonable Function (PUF) and used to subsequently verify the legitimacy of the drone's identity. In order to enhance the security of the system, after storing the CRP, the server permanently removes the direct access path through physical isolation, thereby protecting the integrity and security of the CRP data and preventing it from being maliciously stolen or tampered with;
[0048] S2.2, the server and the drone complete the public key exchange in a secure environment. The server passes its own public key to the drone and receives the public key generated by the drone. Both parties use their respective public keys for subsequent encrypted communication and identity authentication operations. This step is to ensure that the communication between the drone and the server is encrypted and secure in the subsequent process to prevent man-in-the-middle attacks or data leaks;
[0049] S2.3, the server assigns a unique identity to each drone (such as ID A and ID B ) and pass these identities to the corresponding drones through a secure channel. The identity is used to generate unique authentication information in subsequent communications to ensure that each drone can safely and independently participate in the system authentication process. The generation of this identity can be achieved based on the response value generated by the PUF combined with the unique characteristics of the device to ensure that it cannot be copied or forged;
[0050] Registration phase, see Figure 3 The registration phase is a complete two-way interactive process between the server and the drone in an open environment, which is used for the drone to authenticate and establish a communication trust relationship with the server. During this process, the drone initiates a registration request to the server, the server verifies the legitimacy of the drone, and returns a complete registration confirmation message. It includes the following steps:
[0051] S3.1, the server generates an initial message
[0052] The local server randomly selects two challenge-response pairs C from A and B respectively from the memory A1 , R A1 , C B1 , R B1 , C A2 , R A2 , C B2 , R B2 , generate random numbers p and q, generate initial messages m1 and m2, message m1 contains challenge and random number m1=(C A1 ,p), message m2 contains the challenge and the random number m2=(C B1,q), at time t1, the server sends messages m1 and m2 to drone A and drone B at the same time. The random numbers p and q generated by the server ensure the uniqueness of the message, so that the drone can verify the freshness of the message;
[0053] S3.2, UAV verifies and generates response
[0054] After receiving the message m1, drone A determines the freshness of the message based on the random number p in it to ensure that the message is newly generated and has not been replayed. If the verification is correct, drone A continues to use its physical unclonable function (PUF) to calculate the response R A1 , and calculate the identity A through the hash function a =H(R A1 ⊕p). At the same time, a random number x is generated and packaged into a message m3=(A a ,x) sent to the local server to prove its identity;
[0055] After receiving the message m2, drone B also determines the freshness of the message based on the random number q in it to ensure that the message is newly generated and has not been replayed. If the verification is correct, drone B continues to use its physical unclonable function (PUF) to calculate the response R B1 , and calculate the identity B through the hash function b =H(R B1 ⊕q). At the same time, a random number y is generated and packaged into a message m4=(B b ,y) sent to the local server to prove its identity;
[0056] S3.3, the server verifies the message and generates encrypted content
[0057] The server verifies the received message, confirms the drone's identity, generates a timestamp T, and uses a pseudo-random number generator (PRNG) to generate a series of parameters Ф, φ, Ω, and n to increase encryption complexity. The server uses these parameters to generate an encrypted message m A0 and m B0 , and sent to drone A and drone B at the same time at time t3. Message m A0 Contains the identity information of device A, timestamp T and auxiliary data, encrypted with the ECC public key of drone A to ensure that only drone A can decrypt and verify. Message m B0 Contains device B’s identity information, timestamp T, and auxiliary data, encrypted with drone B’s ECC public key to ensure that only drone B can decrypt and verify;
[0058] S3.4, drone verification and generation of verification message
[0059] After receiving the message, drone A uses its own ECC private key SKECC,A Decrypt the message and get R B1 , R B2 , R A1 , R A2 ,n,Ф,φ,Ω,T, checks the timestamp and random number in it to determine the freshness and confirm that the message is the latest and valid. Then, according to the random number Ф,φ,Ω provided by the server, the corresponding storage data block is extracted from the memory, and the extracted memory part is hashed to generate the memory integrity check value. The PUF is then used to generate the response R A (R B1 ) and R A (R B2 ). A (R B1 ) and R A (R B2 ) performs XOR operation to obtain the result X A , X A Concatenate with n and calculate the hash value H(X A ||n), and then generate a random number T A , using the server's ECC public key PK ECC,S Encryption H(X A ||n), T A , generate message m A1 And send it to the server;
[0060] After receiving the message, drone B uses its own ECC private key SK ECC,B Decrypt the message and get R B1 , R B2 , R A1 , R A2 ,n,Ф,φ,Ω,T, checks the timestamp and random number in it to determine the freshness and confirm that the message is the latest and valid. Then, according to the random number Ф,φ,Ω provided by the server, the corresponding storage data block is extracted from the memory, and the extracted memory part is hashed to generate the memory integrity check value. The PUF is then used to generate the response R B (R A1 ) and R B (R A2 ). B (R A1 ) and R B (R A2 ) performs XOR operation and obtains the result X B , X B Concatenate with n and calculate the hash value H(X B ||n), and then generate a random number T B, using the server's ECC public key PK ECC,S Encryption H(X B ||n), T B , generate message m B1 And send it to the server;
[0061] S3.5, Server Verification Message and Processing
[0062] After receiving the message, the server first uses its own ECC private key SK ECC,S Decrypt the message, verify that the timestamp is within the allowed time window to prevent replay attacks, and then perform memory integrity verification and server comparison and To ensure that the memory status of both is consistent and has not been tampered with, the server performs an XOR operation on the hash result of drone A and its identity ID to generate α B :α B =H(X A ||n)⊕ID A . XOR the hash result of drone B with its identity ID to generate α A :α A =H(X B ||n)⊕ID B ;
[0063] The server uses drone A's ECC public key PK ECC,A Encryption alpha A And send it to drone A, using drone B's ECC public key PK ECC,B Encryption alpha B and sent to the drone;
[0064] S3.6, drone storage message
[0065] After receiving the message, drone A uses its own ECC private key SK ECC,A Decrypt message m A2 , we get (R A1 ,R A2 ,α A ,n), and adds it to its own storage. After receiving the message, drone B uses its own ECC private key SK ECC,B Decrypt message m B2 , we get (R B1 ,R B2 ,α B ,n), add to your own storage;
[0066] For the authentication phase, see Figure 4,The authentication phase is the process of completing identity authentication between drones through two-way interaction, which is used to establish a trust relationship between the two parties and generate a shared session key. ,In an open environment, when drone A initiates an authentication request to drone B, it includes the following steps:
[0067] S4.1, UAV A’s certification request
[0068] Drone A generates a random number N A , and then hash the data to generate the message H(n||R A1 ||R A2 ||N A ), the message contains n stored in the registration phase, the response value R A1 and R A2 , and a random number N A , and then send it to drone B;
[0069] S4.2, Response of UAV B
[0070] After receiving the message, drone B verifies the integrity of the hash value and the random number N A to confirm that the message has not been tampered with and the freshness is valid;
[0071] Drone B uses PUF to generate a response: R B (R A1 ) and R B (R A2 ), then for R B (R A1 ) and R B (R A2 ) performs XOR operation and obtains the result Y B : Y B =R B (R A1 )⊕R B (R A2 ). In order to ensure the reliability of PUF response in different environments, an error tolerance mechanism is introduced. If there is a slight change in the response result, an error correction code can be used to adjust it. Drone B sends Y B Concatenate it with n and compare the result with its own ID B Perform XOR operation to generate β B :
[0072] β B =(Y B ||n)⊕ID B . Then generate a random number N B , and then hash the data using a unified hash structure H(β B ||R B1||R B2 ||N B ), generate message m1 and send it to drone A;
[0073] S4.3, Verification of UAV A
[0074] After receiving the message, drone A checks the hash value and random number N B The correctness of the data is ensured to be fresh and unaltered, and then the stored α A Is it consistent with the received β B If they are equal, A has verified B’s identity. Further, drone A uses PUF to generate a response R A (R B1 ) and R A (R B2 ), for R A (R B1 ) and R A (R B2 ) performs XOR operation and obtains the result Y A : Y A =R A (R B1 )⊕R A (R B2 ). In order to ensure the reliability of PUF response in different environments, an error tolerance mechanism is introduced. If there is a slight change in the response result, an error correction code can be used to adjust it. Drone A sends Y A concatenate with n, and perform an XOR operation on the result and its own identity representation to generate β B :β B =(Y A ||n)⊕ID A The drone generates a new random number N A1 , and hash the data, using a unified hash structure H(β A ||N A1 ), generate message m2 and send it to drone B;
[0075] S4.4, Verification of UAV B
[0076] After receiving the message, drone B checks the hash value and random number N A1 The correctness of the data is ensured to ensure data integrity and freshness. B Is it consistent with the received β A Equal, if equal, B has verified A's identity;
[0077] S4.5, Generation of Session Keys
[0078] Drone A and Drone B generate a session key: SK = H(N A||N B ), the session key is used for subsequent communications;
[0079] Memory integrity check mechanism, see Figure 5 ,The memory integrity check mechanism is a process of randomly selecting some memory data blocks and ,generating check values by combining hash functions to verify the integrity and tamper-resistance of memory data. ,In the operation of the drone device, when the system issues a memory check, it includes the following steps:
[0080] S5.1, pseudo-random selection of memory blocks
[0081] The system generates random indexes through a pseudo-random number generator (TinyMT), and selects some memory data blocks as verification objects based on the indexes. The pseudo-random index generation process is unpredictable, which enhances the randomness and security of the verification mechanism and prevents attackers from predicting the data blocks to be verified.
[0082] S5.2, memory block sampling
[0083] According to the generated index, the target data block is extracted from the memory for subsequent integrity verification. This process avoids the verification of all memory blocks, reduces the computing and storage overhead, and meets the application requirements of the resource-constrained environment of drones;
[0084] S5.3, generate checksum value
[0085] The selected memory block data is processed using a hash function to generate an integrity check value. The hash function ensures the uniqueness and tamper resistance of the check value, thereby verifying the integrity of the memory data;
[0086] S5.4, check value matching judgment
[0087] The system compares the checksum values of the two drones. If the checksum values match, the verification is successful, indicating that the memory data block has not been tampered with and the normal process is entered. If they do not match, the verification fails and the exception handling mechanism is triggered.
[0088] Although the embodiments of the present invention have been described in conjunction with the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present invention, and such modifications and variations are all within the scope defined by the appended claims.
Claims
1. A lightweight UAV identity authentication method based on PUF, applied in the field of UAV communication security, characterized in that: The method The following phases are included: Precondition phase: provides initial settings for device authentication and key negotiation; Registration phase: complete the device identity registration and security initialization; Authentication phase: Verify device identity and negotiate session keys to ensure communication security; S1, the precondition, includes the following steps: S1.1, the server pre-stores sufficient challenge-response pairs (CRPs) in a secure environment for device uniqueness verification and removes direct access paths to ensure security; S1.2, the server assigns a unique identity to each drone and securely transmits the identity to the drone via encryption; S1.3, the server and the drone complete the public key exchange, providing security for subsequent encrypted communications; S2, the registration phase, includes the following steps: S2.1, the server uses the pre-stored CRP and pseudo-random number generator (PRNG) to generate an initial registration message, which includes a random number (Nonce) for verifying the freshness of the message and a challenge (Challenge), and sends the message to drone A and drone B respectively; S2.2, after receiving the message, the drone verifies the message freshness and confirms that it has not been replayed, generates a response value using PUF, generates an identity through a hash function, and integrates the generated registration verification information to send to the server; S2.3, after receiving the registration verification message, the server verifies the legitimacy of the drone identity, generates encryption parameters such as timestamp and auxiliary data using PRNG, and creates an encrypted message for the drone, the encrypted message including the identity, timestamp and auxiliary data, and encrypts the message using the drone's public key and sends it to the corresponding drone; S2.4, after receiving the encrypted message, the drone uses the private key to decrypt and extract the timestamp and auxiliary data, verifies the correctness of the timestamp, locates the corresponding memory block through the additional parameters, generates the integrity check value using the hash function and combines it with the verification information to form the final verification message, which is sent to the server; S2.5, the server decrypts and verifies the final verification message, checks the timestamp and integrity check value, and after the verification is passed, generates a registration confirmation message and sends it to the drone; S2.6, after receiving the registration confirmation message, the drone decrypts and extracts the registration information and stores it locally, completing the registration process. S3, the identity authentication phase, includes the following steps: S3.1, UAV A generates a random number and processes it through a hash function to form an authentication request message, which is sent to UAV B; S3.2, after receiving the authentication request message, UAV B verifies the integrity of the message and the freshness of the random number. After confirming that the message has not been tampered with, it generates a response value through PUF, calculates it with the identity identifier to generate an authentication value, and generates a new random number to form an authentication reply message and sends it to UAV A; S3.3, after receiving the authentication reply message, UAV A verifies the correctness of the hash value and the random number. After confirming that the message has not been tampered with, it generates a response value again through PUF and verifies it in combination with the authentication value sent by UAV B to determine whether the authentication value matches. If it matches, it generates a new authentication value and random number to form an authentication confirmation message and sends it to UAV B; S3.4, after receiving the authentication confirmation message, UAV B verifies whether the authentication value in the message is consistent with the stored value, and verifies whether the random number meets the freshness requirement. If the verification is successful, the authentication is completed; S3.5, UAV A and UAV B generate a shared session key based on the authentication result for subsequent secure communication.
2. According to claim 1, a PUF-based lightweight UAV identity authentication method is characterized in that: In the preconditions, the number of challenge-response pairs (CRPs) pre-stored in the server meets the system's long-term operation requirements, and after storage, external access is prevented through physical isolation (such as disconnecting the network interface or shielding the direct access path), thereby effectively avoiding the leakage of challenge-response pairs and improving the system's anti-tampering capabilities and overall security.
3. The PUF-based lightweight UAV identity authentication method according to claim 1, characterized in that: The server and the drone add a random number generated by a pseudo-random number generator to the sent message to ensure the uniqueness of the message, thereby effectively preventing replay attacks; The drone generates a response value through a physical unclonable function and combines it with a hash function to generate an identity to improve the security and reliability of the authentication process.
4. The PUF-based lightweight UAV identity authentication method according to claim 1, characterized in that: The elliptic curve encryption algorithm is used to encrypt and decrypt data in the registration stage and the identity authentication stage; the elliptic curve encryption algorithm is lightweight by reducing the key length, which greatly reduces the computational burden while ensuring security, so as to meet the needs of limited computing and storage resources of drones, and is combined with the random numbers of the pseudo-random number generator to improve the anti-attack capability of encrypted messages.
5. The PUF-based lightweight UAV identity authentication method according to claim 1, characterized in that: The memory integrity verification generates a random index through a pseudo-random number generator to select part of the memory data block for verification, without verifying all the memory data, thereby reducing the consumption of computing and storage resources; the drone uses the hash calculation of the selected data block to generate a check value, and completes the integrity check by combining the response value generated by the physical unclonable function to ensure the security and lightweight of the verification process.
6. A PUF-based lightweight UAV identity authentication method according to claim 1, characterized in that: By combining the random number and timestamp mechanism with the PUF response value, defense against replay attacks and forgery attacks can be achieved during the identity authentication process, and the risk of man-in-the-middle attacks can be effectively reduced.
7. The PUF-based lightweight UAV identity authentication method according to claim 1, characterized in that: The authentication module adopts a dynamic key update mechanism, in which the server takes the lead in completing the update of the PUF key, ensuring that the key information in the authentication process is continuously updated with changes in time and usage scenarios, enhancing the reliability and anti-tampering capabilities in a multi-device environment, and especially preventing the occurrence of man-in-the-middle attacks and replay attacks.
8. The PUF-based lightweight UAV identity authentication method according to claim 3, characterized in that: The pseudo-random number generator adopts the TinyMT pseudo-random number generation algorithm, which is based on a 128-bit state variable and generates pseudo-random numbers through shift, XOR and addition operations. It has the characteristics of low computational complexity and small memory usage, and is suitable for drones with limited computing and resources.
9. The PUF-based lightweight UAV identity authentication method according to claim 4, characterized in that: The elliptic curve encryption algorithm adopts the elliptic curve 25519 algorithm (Curve25519), which is based on the Montgomery curve and has low computational complexity and efficient key generation process. It can realize efficient encryption and decryption operations in an environment with limited computing resources of drones, and at the same time provide a 128-bit security level to meet communication security requirements and ensure the confidentiality and anti-attack capability of data transmission in the registration and authentication stages.
Citation Information
Cited By
In-band non-inductive authentication method and system for power system
CN120263535A
Lightweight security identity verification method based on hybrid authentication architecture
CN120378122A
A lightweight secure identity authentication method based on hybrid authentication architecture
CN120378122B
User security authentication method and system based on encryption processing
CN120582904A
User security authentication method and system based on encryption processing
CN120582904B