Safety communication system and method in unmanned aerial vehicle edge computing environment
By using blockchain network and smart contract technology for identity authentication and key management in the drone edge computing environment, the existing drone secure communication methods in security and computing resource consumption are solved, and safe, reliable and efficient communication between drone devices is achieved.
Patent Information
- Application Number
- CN202510200300.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-24
- Publication Date
- 2025-05-27
AI Technical Summary
The existing drone secure communication methods are insufficient in terms of security and cannot effectively resist various attack threats. At the same time, computing resources are consumed high, and the suitability is poor. The cloud-centered centralized authentication model has a single point of failure risk and limited scalability.
The blockchain network and smart contract technology between mobile users, ground stations and drones are adopted to authenticate and key management through the alliance blockchain network to ensure secure communication of drone devices in resource-constrained environments.
It realizes safe, reliable and efficient communication between drone equipment, resists various attack threats, reduces computing resource consumption, adapts to resource-constrained environments, and avoids the risk of single point of failure.
Smart Images

Figure CN120050656A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of unmanned aerial vehicles, and in particular, relates to a secure communication system and method in an unmanned aerial vehicle edge computing environment. Background Art
[0002] Drone edge computing is an innovative technology that aims to reduce network latency, bandwidth consumption, and significantly improve the real-time processing capabilities of tasks by moving computing tasks from traditional central servers or clouds to drone devices for local processing. Traditional computing models rely on remote cloud platforms, but in environments with weak network infrastructure, such as remote mountainous areas, post-disaster rescue scenarios, or military fronts, it is often difficult to meet key requirements such as low latency, high reliability, and real-time performance. In addition, relying on static edge servers to provide intelligent services in these scenarios is costly and inflexible, making it difficult to adapt to dynamically changing mission requirements. To address these limitations, drone edge computing technology has emerged. Drones have flexible deployment capabilities and fast mobility and can be used as edge computing nodes. By moving data processing, storage, and analysis from the cloud to drones close to the data source, drones can achieve localized real-time data processing and intelligent computing services, reduce dependence on network infrastructure, and significantly improve response speed. Compared with traditional cloud computing models, drone-enabled edge computing has multiple advantages. It not only reduces network transmission requirements by processing data locally, meeting the requirements for real-time and mission continuity, but also provides higher protection for data privacy and system security, providing a more intelligent and efficient solution for drone edge computing scenarios. However, drones operate in open skies, and the broadcast wireless channels used between drones and ground stations are also easily monitored and tampered with. This exposes drone communications to a series of serious threats, including man-in-the-middle attacks, replay attacks, denial of service attacks, impersonation attacks, and monitoring attacks. If they are not protected, they may cause huge losses to life and property. Therefore, it is very important to design a secure and lightweight authentication solution for drone edge computing scenarios.
[0003] Many current authentication schemes have the following design problems: Although authentication schemes based on public key cryptography have excellent security, these schemes are usually accompanied by high computational and storage overheads. This overhead is unacceptable for resource-constrained IoT environments, especially when devices have limited computing power, insufficient storage space, or are sensitive to energy consumption. Although authentication schemes based on symmetric cryptography have obvious advantages in terms of computational overhead and can better adapt to scenarios with limited resources, they rely on pre-distributing shared keys between entities during the initialization or registration phase. This design not only increases the complexity of key management, but is also vulnerable to a variety of attack threats. Some other schemes adopt a cloud-centric centralized authentication model. This architecture has the risk of single point failure and limited scalability, and is not suitable for the needs of large-scale IoT environments.
[0004] Through the above analysis, the problems and defects of the prior art are as follows:
[0005] (1) Although some existing drone secure communication methods are lightweight, they have obvious deficiencies in security and cannot effectively resist threats such as impersonation attacks, replay attacks, physical device capture attacks, and short-term secret leakage attacks.
[0006] (2) Some existing UAV secure communication methods improve the security of authentication schemes through complex computationally intensive algorithms. However, these algorithms consume a lot of computing resources, resulting in a significant decrease in authentication efficiency, and are not suitable for resource-constrained UAV environments.
[0007] (3) Some existing drone secure communication methods adopt a cloud-centric centralized authentication model. This architecture has the risk of single point failure and limited scalability, and is not suitable for the needs of drone network environments. Summary of the invention
[0008] In response to the problems existing in the prior art, the present invention provides a secure communication system and method in a drone edge computing environment.
[0009] The present invention is implemented as follows: a secure communication system in a drone edge computing environment includes:
[0010] Mobile user terminals, ground stations, and drones;
[0011] The mobile user terminal is connected to the ground station and the drone, and is used to request access to the entity of a specific drone device and control the drone device through remote management;
[0012] The ground station is connected to the mobile user terminal and the drone. It is used to connect the ground stations to each other to form a consortium blockchain network and deploy smart contracts on the blockchain to record secret data. The ground station provides network connection and computing services for mobile users and drone equipment.
[0013] Drones are connected to mobile user terminals and ground stations. They are used to deploy drone equipment in the open sky and connect to nearby ground stations wirelessly. Drones are deployed in resource-constrained areas to provide intelligent edge computing services for IoT devices in the area.
[0014] Furthermore, the secure communication between the mobile user terminal and the drone:
[0015] The first stage is the initialization stage of the system, where the ground station needs to generate the necessary parameters of the system, build the blockchain, and deploy smart contracts;
[0016] The second stage is the registration stage, where drones and mobile users connected to the system register with the ground station;
[0017] The third stage is the authentication stage, in which the mobile user realizes mutual authentication with the drone device through the ground station. After successful authentication, the two parties negotiate a session key for secure communication between them;
[0018] After the user registers, the registration information is stored in his or her mobile device;
[0019] When in use, the user logs in to the mobile device using a password and fingerprint. After successful login, the ground station sends a control request to the drone device, and then both parties verify each other's authenticity.
[0020] After successful authentication between both parties, a session key is generated to ensure secure communication between the mobile user and the drone device.
[0021] Further, the initialization phase:
[0022] During the initialization phase, the system administrator initializes each entity in the solution; the system administrator initializes each ground station GSS k Select a long-term key K; select a one-way hash function h(·) for the user, ground station, and drone device and store them in their storage.
[0023] Furthermore, the registration phase:
[0024] Drone Registration:
[0025] Step 1. Smart contract SC is the drone device DR j Generate a set of random challenges C = {C 1 ,C 2 ,...,C n}, and send the set C to the drone device DR through a secure channel j ;
[0026] Step 2. After receiving C from the smart contract SCj Afterwards, DR j Use the embedded PUF to calculate the response R corresponding to C, that is, R = PUF (C), and get R = {R 1 ,R 2 ,...,R n} and sends h(R) to GSS via a secure channel k ;
[0027] Step 3. After receiving message R, SC is DR j Select a unique ID j and temporary identity TID j , and calculate the identity certificate TC j =h(ID j ||K), where K is the GSS k long-term key; SC will {ID j ,TID j ,TC j ,C,h(R)} is stored in SC, and {TID j ,ID j}Stored in the ground station GSS k and transmit {TID j ,TC j}Send to drone device DR j ;
[0028] Step 4. Drone equipment DR j After receiving the message, store
[0029] Further, the user registers:
[0030] Step 1. User U i Select ID i and password PW i , and the biometric information BIO i Press MD on your mobile device i On the fuzzy extractor, two biometric parameters are calculated as (σ i ,τ i )=Gen(BIO i );MD i Generate a random number r i , and calculate HID i =h(ID i ||r i ), HPW i =h(PW i ||σ i ||r i); then register the request {HID i ,HPW i}Sent to the ground station GSS through a secure channel k ;
[0031] Step 2. After receiving the message, SC is U i Generate a random number R i and temporary identity TID i , each temporary identity is used only once; calculate TC i =h(HID i ||K|R i ),A i =TC i ⊕HPW i SC will Stored in SC, Store to GSS k In the end, GSS k MD through the secure channel i Send i ,TID i};
[0032] Step 3. After receiving the message, the mobile device calculates TC i =A i ⊕HPW i , B i =r i ⊕h(ID i ||PW i ||σ i ), Auth i =h(TC i ||HPW i ||σ i ), and finally, stored in its memory.
[0033] Furthermore, in the authentication stage:
[0034] Stage 1. User enters his / her ID i , and password PW i , and the biometric information BIO′ i Press on the mobile device, and then the fuzzy extractor calculates σ′ i =Rep(BIO′ i ,τ i ); Mobile device calculation: r′ i =B i ⊕h(ID i ||PW i ||σ'i ), HID' i =h(ID i ||r' i ), HPW' i =h(PW i ||σ' i ||r' i ), Calculate Auth′ i =h(TC i ||HPW′ i ||σ′ i ) Check if Auth i ′=Auth i , if they are equal, the user identity verification is successful; the mobile device generates a random number n 1 and the current timestamp t 1 , select the drone DR to be visited j ID j , and calculate M 1 =n 1 ⊕h(TC i ||t 1 ), M 2 =h(TC i ||n 1 ||t 1 ), M 3 =ID j ⊕h(TC i ||TID i ||t 1 ), and finally, the mobile device MD i To ground station GSS k Send message 1 ={M 1 ,M 2 ,M 3 ,TID i ,t 1};
[0035] Phase 2. Ground Station GSS k After receiving the message, first check Is it established? is the time when the message is received, Δt 1 Indicates the maximum allowed transmission delay between the mobile device and the ground station. If this condition is met, check TID i Is it in the memory? If it is, extract the corresponding TC from SC i ; Ground Station GSS k Calculation: n 1 =M 1 ⊕h(TCi ||t 1 ), examine If yes, GSS k Calculate ID j =M 3 ⊕h(TC i ||TID i ||t 1 ), for user U i Generate a new temporary identity And U i Old and new temporary identities Stored in its database; GSS k By ID j Find the corresponding {TID from SC j ,TC j ,C,h(R)}; then, GSS k Generate a random number n 2 and the current timestamp t 2 , select a random challenge C that has never been used for the drone device from a set of challenges C j , and delete C and its corresponding h(R) used in the previous session; then, generate a new temporary identity calculate: M 5 =(n 1 ||n 2 )⊕h(C j ||h(R j )||t 2 ), Finally, the ground station GSS k DR to drone equipment j Send message 2 ={M 5 ,M 6 ,M 7 ,C j ,t 2};
[0036] Phase 3. Drone equipment DR j After receiving the message, first check Is it established? is the time when the message is received, Δt 2 represents the maximum allowable transmission delay between the ground station and the UAV device. If this condition is met, calculate R j =PUF(C j ), (n 1 ||n 2 )=M 5⊕h(C j ||h(R j )||t 2 ), examine If yes, generate a random number n 3 and the current timestamp t 3 ,calculate: M 9 =h(SK||TC j ||n 3 ||t 3 ); Finally, the drone equipment DR j To ground station GSS k Send message 3 ={M 8 ,M 9 ,t 3};
[0037] Phase 4. Ground Station GSS k After receiving the message, first check Is it established? is the time when the message is received. If this condition is met, calculate examine If yes, it means the ground station GSS k Certified drone equipment DR j ; Then, the ground station GSS k calculate: Finally, the ground station GSS k MD to mobile device i Send message 4 ={M 4 ,M 10 ,M 11 ,M 12 ,t 4};
[0038] Stage 5. Mobile Device MD i After receiving the message, first check Is it established? is the time when the message is received. If this condition is met, calculate: examine If yes, it means the mobile device MD i Certified Ground Station GSS k ;
[0039] Password and fingerprint update phase:
[0040] Step 1. Move the MD device i Request user U i Enter your ID i and the old password PW i , and press the old fingerprint information BIO on the device i ;
[0041] Step 2. Mobile device calculates σ i =Rep(BIO i ,τ i ), r i =B i ⊕h(ID i ||PW i ||σ i ), HID i =(ID i ||r i ), HPW i =(PW i ||σ i ||r i ), and Check if If the conditions are met, continue with the following steps; otherwise, the login is terminated by the mobile device;
[0042] Step 3. Move MD to your device i Require the user to enter a new password And press the new fingerprint information MD i calculate and Finally, the mobile device will update the information stored in its memory.
[0043] Another object of the present invention is to provide a secure communication method in a drone edge computing environment, comprising:
[0044] Step 1, controlling the drone device through remote management via an entity used by a mobile user end to request access to a specific drone device;
[0045] Step 2: Use ground stations to connect to each other through ground stations to form a consortium blockchain network, and deploy smart contracts on the blockchain to record secret data; the ground stations provide network connection and computing services for mobile users and drone devices;
[0046] Step 3: Deploy drones in the open sky using drone equipment and connect wirelessly to nearby ground stations; deploy drones to resource-constrained areas to provide intelligent edge computing services for IoT devices in the area.
[0047] Another object of the present invention is to provide a computer device, which includes a memory and a processor, wherein the memory stores a computer program, and when the computer program is executed by the processor, the processor executes the steps of the secure communication method in the drone edge computing environment.
[0048] Another object of the present invention is to provide a computer-readable storage medium storing a computer program, which, when executed by a processor, enables the processor to perform the steps of the secure communication method in the drone edge computing environment.
[0049] Another object of the present invention is to provide an information data processing terminal, which is used to implement a secure communication system in the drone edge computing environment.
[0050] In combination with the above technical solutions and the technical problems solved, the advantages and positive effects of the technical solutions to be protected by the present invention are as follows:
[0051] First, the present invention mainly realizes secure communication between mobile users and drones, and its working principle is as follows: the first stage is the initialization stage of the system, and the ground station needs to generate the necessary parameters of the system, build a blockchain and deploy smart contracts. The second stage is the registration stage, and the drones and mobile users connected to the system register with the ground station. The third stage is that the mobile user realizes mutual authentication with the drone device through the ground station. After the authentication is successful, the two parties negotiate a session key for secure communication between them. After the user registers, the registration information is stored in his or her mobile device. When in use, the user uses a password and fingerprint to log in to the mobile device. After the login is successful, a control request is sent to the drone device through the ground station, and then the two parties verify the authenticity of each other. After the two parties successfully verify, a session key is generated to ensure secure communication between the mobile user and the drone device.
[0052] Second, drones, as edge computing servers, are designed to provide efficient edge computing services for IoT devices. In addition to traditional data transmission and computing functions, drones can act as flexible computing nodes in distributed computing architectures, processing information close to the data source, reducing data transmission latency and bandwidth usage, thereby significantly improving computing efficiency and real-time performance. This capability enables drones to drive the IoT from simple data collection and transmission to intelligent analysis and decision-making, and is considered one of the key drivers of the development of the IoT. The widespread application of drone edge computing is expected to profoundly transform multiple industries, including smart cities, smart transportation, environmental monitoring, industrial automation, and emergency rescue scenarios, to solve the bottleneck problem under the current centralized computing model. The implementation of this technical solution will not only optimize the computing architecture of the IoT system and improve service quality, but will also create huge market opportunities and promote the implementation of edge computing in various industries, thereby bringing considerable expected benefits and commercial value. BRIEF DESCRIPTION OF THE DRAWINGS
[0053] Figure 1 It is a structural block diagram of a secure communication system in a drone edge computing environment provided by an embodiment of the present invention.
[0054] Figure 2 It is a flow chart of a secure communication method in a drone edge computing environment provided by an embodiment of the present invention.
[0055] Figure 3 It is a structural diagram of drone edge computing provided by an embodiment of the present invention.
[0056] Figure 4 This is an authentication flow chart between a user, a ground station and a drone provided by an embodiment of the present invention. Figure 5 This is a diagram comparing the computational overhead of the technology provided by the embodiment of the present invention with other technologies.
[0057] Figure 1 Chinese: 1. Mobile user terminal; 2. Ground station; 3. UAV. DETAILED DESCRIPTION
[0058] In order to make the purpose, technical solution and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0059] like Figure 1 As shown, a secure communication system in a drone edge computing environment provided by an embodiment of the present invention includes:
[0060] Mobile user terminal 1, ground station 2, drone 3;
[0061] The mobile user terminal 1 is connected to the ground station 2 and the drone 3, and is used to request access to the entity of a specific drone device and control the drone device through remote management;
[0062] The ground station 2 is connected to the mobile user terminal 1 and the drone 3. The ground stations are connected to each other to form a consortium blockchain network, and the smart contracts are deployed on the blockchain to record secret data. The ground station provides network connection and computing services for mobile users and drone devices.
[0063] Drone 3 is connected to mobile user terminal 1 and ground station 2, and is used to deploy drone equipment in the open sky and connect to nearby ground stations wirelessly; drones are deployed in resource-constrained areas to provide intelligent edge computing services for IoT devices in the area.
[0064] The system consists of three core parts: mobile user terminal, ground station and drone. Each component is connected to each other through wireless network to achieve collaborative work. The mobile user terminal is responsible for initiating access requests and remotely managing and controlling specific drone equipment; the ground station, as an intermediate hub, not only establishes a stable connection with the mobile user terminal and drone, but also builds a consortium blockchain network; the drone is deployed in the open sky and accesses nearby ground stations wirelessly to provide edge computing services.
[0065] The ground station plays a vital role in the coordination of the system. It not only provides network connection and computing support for mobile users and drones, but also ensures the security and immutability of data transmission through the alliance blockchain network. Smart contracts are deployed on the blockchain to record and manage secret data, realize data encryption, identity authentication and permission control, and ensure the security and privacy protection of the entire communication system.
[0066] As the execution terminal of the system, drones are deployed in open airspace and interact with nearby ground stations in real time through wireless connections. When they enter resource-constrained areas, they can provide intelligent edge computing services for IoT devices in the area, including data collection, preliminary processing and real-time analysis, thereby reducing the burden on central servers and achieving more efficient network computing and information feedback.
[0067] First, the mobile user sends a request to the ground station to access a specific drone device through remote management; after receiving the request, the ground station verifies the user's identity through the blockchain network and calls the smart contract to confirm the authority, and records and verifies the relevant secret data. After verification, the ground station forwards the control command to the target drone, and the drone immediately adjusts its deployment status and starts to provide edge computing services, while feeding back the processing results and status information to the ground station in real time. Throughout the process, blockchain technology is used to ensure data transmission security, and smart contracts ensure the transparency and non-tamperability of the operation process, thereby building a safe and efficient drone edge computing communication system.
[0068] The secure communication between the mobile user terminal and the drone provided by the embodiment of the present invention:
[0069] The first stage is the initialization stage of the system, where the ground station needs to generate the necessary parameters of the system, build the blockchain, and deploy smart contracts;
[0070] The second stage is the registration stage, where drones and mobile users connected to the system register with the ground station;
[0071] The third stage is the authentication stage, in which the mobile user realizes mutual authentication with the drone device through the ground station. After successful authentication, the two parties negotiate a session key for secure communication between them;
[0072] After the user registers, the registration information is stored in his or her mobile device;
[0073] When in use, the user logs in to the mobile device using a password and fingerprint. After successful login, the ground station sends a control request to the drone device, and then both parties verify each other's authenticity.
[0074] After successful authentication between both parties, a session key is generated to ensure secure communication between the mobile user and the drone device.
[0075] The initialization phase provided by the embodiment of the present invention is as follows:
[0076] During the initialization phase, the system administrator initializes each entity in the solution; the system administrator initializes each ground station GSS k Select a long-term key K; select a one-way hash function h(·) for the user, ground station, and drone device and store them in their storage.
[0077] The registration phase provided by the embodiment of the present invention is as follows:
[0078] Drone Registration:
[0079] Step 1. Smart contract SC is the drone device DR j Generate a set of random challenges C = {C 1 ,C2 ,...,C n}, and send the set C to the drone device DR through a secure channel j ;
[0080] Step 2. After receiving C from the smart contract SC, DR j Use the embedded PUF to calculate the response R corresponding to C, that is, R = PUF (C), and get R = {R 1 ,R 2 ,...,R n} and sends h(R) to GSS via a secure channel k ;
[0081] Step 3. After receiving message R, SC is DR j Select a unique ID j and temporary identity TID j , and calculate the identity certificate TC j =h(ID j ||K), where K is the GSS k long-term key; SC will {ID j ,TID j ,TC j ,C,h(R)} is stored in SC, and {TID j ,ID j}Stored in the ground station GSS k and transmit {TID j ,TC j}Send to drone device DR j ;
[0082] Step 4. Drone equipment DR j After receiving the message, store
[0083] User registration provided by the embodiment of the present invention:
[0084] Step 1. User U i Select ID i and password PW i , and the biometric information BIO i Press MD on your mobile device i On the fuzzy extractor, two biometric parameters are calculated as (σ i ,τ i )=Gen(BIO i );MD i Generate a random number r i , and calculate HID i =h(IDi ||r i ), HPW i =h(PW i ||σ i ||r i ); then register the request {HID i ,HPW i}Sent to the ground station GSS through a secure channel k ;
[0085] Step 2. After receiving the message, SC is U i Generate a random number R i and temporary identity TID i , each temporary identity is used only once; calculate TC i =h(HID i ||K|R i ),A i =TC i ⊕HPW i SC will Stored in SC, Store to GSS k In the end, GSS k MD through the secure channel i Send i ,TID i};
[0086] Step 3. After the mobile device receives the message, it calculates TC i =A i ⊕HPW i , B i =r i ⊕h(ID i ||PW i ||σ i ), Auth i =h(TC i ||HPW i ||σ i ), and finally, stored in its memory.
[0087] The authentication stage provided by the embodiment of the present invention is as follows:
[0088] Stage 1. User enters his / her ID i , and password PW i , and the biometric information BIO′ i Press on the mobile device, and then the fuzzy extractor calculates σ′ i =Rep(BIO′i ,τ i ); Mobile device calculation: r′ i =B i ⊕h(ID i ||PW i ||σ′ i ), HID′ i =h(ID i ||r′ i ), HPW′ i =h(PW i ||σ′ i ||r′ i ), Calculate Auth′ i =h(TC i ||HPW′ i ||σ′ i ) Check if Auth i ′=Auth i , if they are equal, the user identity verification is successful; the mobile device generates a random number n 1 and the current timestamp t 1 , select the drone DR to be visited j ID j , and calculate M 1 =n 1 ⊕h(TC i ||t 1 ), M 2 =h(TC i ||n 1 ||t 1 ), M 3 =ID j ⊕h(TC i ||TID i ||t 1 ), and finally, the mobile device MD i To ground station GSS k Send message 1 ={M 1 ,M 2 ,M 3 ,TID i ,t 1};
[0089] Phase 2. Ground Station GSS k After receiving the message, first check Is it established? is the time when the message is received, Δt 1 Indicates the maximum allowed transmission delay between the mobile device and the ground station. If this condition is met, check TIDi Is it in the memory? If it is, extract the corresponding TC from SC i ; Ground Station GSS k Calculation: n 1 =M 1 ⊕h(TC i ||t 1 ), examine If yes, GSS k Calculate ID j =M 3 ⊕h(TC i ||TID i ||t 1 ), for user U i Generate a new temporary identity And U i Old and new temporary identities Stored in its database; GSS k By ID j Find the corresponding {TID from SC j ,TC j ,C,h(R)}; then, GSS k Generate a random number n 2 and the current timestamp t 2 , select a random challenge C that has never been used for the drone device from a set of challenges C j , and delete C and its corresponding h(R) used in the previous session; then, generate a new temporary identity calculate: M 5 =(n 1 ||n 2 )⊕h(C j ||h(R j )||t 2 ), Finally, the ground station GSS k DR to drone equipment j Send message 2 ={M 5 ,M 6 ,M 7 ,C j ,t 2};
[0090] Phase 3. Drone equipment DR j After receiving the message, first check Is it established? is the time when the message is received, Δt 2represents the maximum allowable transmission delay between the ground station and the UAV device. If this condition is met, calculate R j =PUF(C j ), (n 1 ||n 2 )=M 5 ⊕h(C j ||h(R j )||t 2 ), examine If yes, generate a random number n 3 and the current timestamp t 3 ,calculate: M 9 =h(SK||TC j ||n 3 ||t 3 ); Finally, the drone equipment DR j To ground station GSS k Send message 3 ={M 8 ,M 9 ,t 3};
[0091] Phase 4. Ground Station GSS k After receiving the message, first check Is it established? is the time when the message is received. If this condition is met, calculate examine If yes, it means the ground station GSS k Certified drone equipment DR j ; Then, the ground station GSS k calculate: Finally, the ground station GSS k MD to mobile device i Send message 4 ={M 4 ,M 10 ,M 11 ,M 12 ,t 4};
[0092] Stage 5. Mobile Device MD i After receiving the message, first check Is it established? is the time when the message is received. If this condition is met, calculate: examine If yes, it means the mobile device MD i Certified Ground Station GSS k ;
[0093] Password and fingerprint update phase:
[0094] Step 1. Move the MD device i Request user U i Enter your ID i and the old password PW i , and press the old fingerprint information BIO on the device i ;
[0095] Step 2. Mobile device calculates σ i =Rep(BIO i ,τ i ), r i =B i ⊕h(ID i ||PW i ||σ i ), HID i =(ID i ||r i ), HPW i =(PW i ||σ i ||r i ), and Check if If the conditions are met, continue with the following steps; otherwise, the login is terminated by the mobile device;
[0096] Step 3. Move MD to your device i Require the user to enter a new password And press the new fingerprint information MD i calculate and Finally, the mobile device will update the information stored in its memory.
[0097] like Figure 2 As shown, a secure communication method in a drone edge computing environment provided by an embodiment of the present invention includes:
[0098] S101, the user logs in using a mobile device and sends an authentication request to the ground station;
[0099] S102, the ground station checks the freshness of the message and authenticates the user. After successful authentication, it initiates an authentication request to the drone;
[0100] S103, the drone checks the freshness of the message and authenticates the ground station. After successful authentication, it initiates an authentication request to the ground station;
[0101] S104, the ground station verifies the freshness of the message and authenticates the drone. After successful authentication, it initiates an authentication request to the user;
[0102] S105, the user verifies the freshness of the message and authenticates the ground station. After successful authentication, a secure communication key is generated between the user, the ground station and the drone.
[0103] Another object of the present invention is to provide a computer device, which includes a memory and a processor, wherein the memory stores a computer program, and when the computer program is executed by the processor, the processor executes the steps of the secure communication method in the drone edge computing environment.
[0104] Another object of the present invention is to provide a computer-readable storage medium storing a computer program, which, when executed by a processor, enables the processor to perform the steps of the secure communication method in the drone edge computing environment.
[0105] Another object of the present invention is to provide an information data processing terminal, which is used to implement a secure communication system in the drone edge computing environment.
[0106] Figure 3 This is the structural diagram of drone edge computing.
[0107] Figure 4 It is the authentication flow chart between the user, ground station and drone.
[0108] Figure 5 This is a graph comparing the computational overhead of our technology with other technologies.
[0109] The technical solution of the present invention can be applied to the drone edge computing system to ensure communication security. The most typical application example is emergency rescue. In natural disasters (such as earthquakes, floods) or accident sites, the communication infrastructure may be destroyed. Drones serve as temporary edge computing servers and fly to the disaster area to provide rapid deployment and data processing services for IoT devices. Drone edge computing can provide important assistance to rescue personnel and rescue equipment. However, if the communication security of drones cannot be guaranteed, it may endanger the lives of the people and cause property losses.
[0110] In terms of security, the present invention can resist various known attacks, mainly including:
[0111] It can resist attacks such as stolen mobile devices, privileged insider attacks, desynchronization attacks, impersonation attacks, drone capture attacks, man-in-the-middle attacks, etc. It also has the characteristics of anonymity and untraceability of mobile users.
[0112] In terms of communication cost, the communication cost required by the present invention is relatively small. In order to facilitate the comparison of the communication costs of different systems, it is assumed that the length of the hash summary is 160 bits, the length of the temporary interaction number and the identity information is 128 bits, the symmetric encryption / decryption is 128 bits, and the timestamp is 32 bits. The present invention needs to transmit 4 messages, which requires a total of 2304 bits. In other similar communication systems, the system invented by Ever et al. requires a cost of 3200 bits, and the system invented by Zhang et al. requires a cost of 2528 bits.
[0113] In terms of computational cost, the present invention has a great advantage. In order to compare the computational costs of different systems, let T h , T fe and T puf denotes the computation time required for hash operation, fuzzy extractor generation or reproduction function and PUF function budget respectively. In our proposed protocol, the execution time required for mobile device, ground station and drone device is 14T respectively. h +T fe ≈18.038ms, 16T h ≈0.592ms and 9T h +1T puf ≈12.803ms, and the total execution time is about 31.433ms. The computational cost required by Ever et al.'s lightweight system is 281.378ms, and the cost required by Zhang et al.'s lightweight system is 83.022ms.
[0114] It should be noted that the embodiments of the present invention can be implemented by hardware, software, or a combination of software and hardware. The hardware part can be implemented using dedicated logic; the software part can be stored in a memory and executed by an appropriate instruction execution system, such as a microprocessor or dedicated design hardware. It can be understood by a person of ordinary skill in the art that the above-mentioned devices and methods can be implemented using computer executable instructions and / or contained in a processor control code, such as a carrier medium such as a disk, CD or DVD-ROM, a programmable memory such as a read-only memory (firmware), or a data carrier such as an optical or electronic signal carrier. Such code is provided on the carrier medium. The device and its modules of the present invention can be implemented by hardware circuits such as very large-scale integrated circuits or gate arrays, semiconductors such as logic chips, transistors, etc., or programmable hardware devices such as field programmable gate arrays, programmable logic devices, etc., can also be implemented by software executed by various types of processors, and can also be implemented by a combination of the above-mentioned hardware circuits and software, such as firmware.
[0115] The above description is only a specific implementation mode of the present invention, but the protection scope of the present invention is not limited thereto. Any modifications, equivalent substitutions and improvements made by any technician familiar with the technical field within the technical scope disclosed by the present invention and within the spirit and principle of the present invention should be covered by the protection scope of the present invention.
Claims
1. A secure communication system in an unmanned aerial vehicle edge computing environment, characterized in that: include: Mobile user terminals, ground stations, and drones; The mobile user terminal is connected to the ground station and the drone, and is used to request access to the entity of a specific drone device and control the drone device through remote management; The ground station is connected to the mobile user terminal and the drone. It is used to connect the ground stations to each other to form a consortium blockchain network and deploy smart contracts on the blockchain to record secret data. The ground station provides network connection and computing services for mobile users and drone equipment. Drones are connected to mobile user terminals and ground stations. They are used to deploy drone equipment in the open sky and connect to nearby ground stations wirelessly. Drones are deployed in resource-constrained areas to provide intelligent edge computing services for IoT devices in the area.
2. The secure communication system in the edge computing environment of a drone as claimed in claim 1, characterized in that: Secure communication between the mobile user terminal and the drone: The first stage is the initialization stage of the system, where the ground station needs to generate the necessary parameters of the system, build the blockchain, and deploy smart contracts; The second stage is the registration stage, where drones and mobile users connected to the system register with the ground station; The third stage is the authentication stage, in which the mobile user realizes mutual authentication with the drone device through the ground station. After successful authentication, the two parties negotiate a session key for secure communication between them; After the user registers, the registration information is stored in his or her mobile device; When in use, the user logs in to the mobile device using a password and fingerprint. After successful login, the ground station sends a control request to the drone device, and then both parties verify each other's authenticity. After successful authentication between both parties, a session key is generated to ensure secure communication between the mobile user and the drone device.
3. The secure communication system in the edge computing environment of a drone as claimed in claim 2, characterized in that: The initialization phase: During the initialization phase, the system administrator initializes each entity in the solution; the system administrator initializes each ground station GSS k Select a long-term key K; select a one-way hash function h(·) for the user, ground station, and drone device and store them in their storage.
4. The secure communication system in the edge computing environment of a drone as claimed in claim 2, characterized in that: The registration phase: Drone Registration: Step 1. Smart contract SC is the drone device DR j Generate a set of random challenges C = {C1, C2, ..., C n }, and send the set C to the drone device DR through a secure channel j ; Step 2. After receiving C from the smart contract SC j Afterwards, DR j Use its embedded PUF to calculate the response R corresponding to C, that is, R = PUF (C), and get R = {R1, R2, ..., R n } and sends h(R) to GSS via a secure channel k ; Step 3. After receiving message R, SC is DR j Select a unique ID j and temporary identity TID j , and calculate the identity certificate TC j =h(ID j ||K), where K is the GSS k long-term key; SC will {ID j ,TID j ,TC j ,C,h(R)} is stored in SC, and {TID j ,ID j }Stored in the ground station GSS k and transmit {TID j ,TC j }Send to drone device DR j ; Step 4. Drone equipment DR j After receiving the message, store 5. The secure communication system in the edge computing environment of a drone as claimed in claim 2, characterized in that: The user registration: Step 1. User U i Select ID i and password PW i , and transfer biometric information i Press MD on your mobile device i On the fuzzy extractor, two biometric parameters are calculated as (σ i ,τ i )=Gen(BIO i );MD i Generate a random number r i , and calculate HID i =h(ID i ||r i ), HPW i =h(PW i ||σ i ||r i ); then register the request {HID i ,HPW i }Sent to the ground station GSS through a secure channel k ; Step 2. After receiving the message, SC is U i Generate a random number R i and temporary identity TID i , each temporary identity is used only once; calculate TC i =h(HID i ||K|R i ), SC Stored in SC, Store to GSS k In the end, GSS k MD through the secure channel i Send i ,TID i }; Step 3. After the mobile device receives the message, it calculates Auth i =h(TC i ||HPW i ||σ i ), and finally, stored in its memory.
6. The secure communication system in the edge computing environment of a drone as claimed in claim 2, characterized in that: The authentication phase: Stage 1. User enters his / her ID i , and password PW i , and the biometric information BIO′ i Press on the mobile device, and then the fuzzy extractor calculates σ′ i =Rep(BIO′ i ,τ i ); Mobile device computing: HID′ i =h(ID i ||r′ i ), HPW′ i =h(PW i ||σ′ i ||r′ i ), Calculate Auth′ i =h(TC i ||HPW′ i ||σ′ i ) Check if Auth i ′=Auth i , if they are equal, the user identity verification is successful; the mobile device generates a random number n1 and the current timestamp t1, and selects the drone DR to be accessed j ID j , and calculate M2=h(TC i ||n1||t1), Finally, mobile device MD i To ground station GSS k Send message Msg1 = {M1, M2, M3, TID i ,t1}; Phase 2. Ground Station GSS k After receiving the message, first check Is it established? is the time when the message is received, Δt1 represents the maximum allowable transmission delay between the mobile device and the ground station. If this condition is met, check TID i Is it in the memory? If it is, extract the corresponding TC from SC i ; Ground Station GSS k calculate: examine If yes, GSS k calculate For user U i Generate a new temporary identity And U i Old and new temporary identities Stored in its database; GSS k By ID j Find the corresponding {TID from SC j ,TC j ,C,h(R)}; then, GSS k Generate a random number n2 and the current timestamp t2, and select a random challenge C that has never been used for the drone device from a set of challenges C j , and delete C and its corresponding h(R) used in the previous session; then, generate a new temporary identity calculate: Finally, the ground station GSS k DR to drone equipment j Send message Msg2 = {M5, M6, M7, C j ,t2}; Phase 3. Drone equipment DR j After receiving the message, first check Is it established? is the time when the message is received, Δt2 represents the maximum allowable transmission delay between the ground station and the UAV device. If this condition is met, calculate R j =PUF(C j ), examine If yes, generate a random number n3 and the current timestamp t3, and calculate: M9=h(SK||TC j ||n3||t3); Finally, the drone equipment DR j To ground station GSS k Send message Msg3 = {M8, M9, t3}; Phase 4. Ground Station GSS k After receiving the message, first check Is it established? is the time when the message is received. If this condition is met, calculate examine If yes, it means the ground station GSS k Certified drone equipment DR j ; Then, the ground station GSS k calculate: Finally, the ground station GSS k MD to mobile device i Send message Msg4 = {M4,M 10 ,M 11 ,M 12 ,t4}; Stage 5. Mobile Device MD i After receiving the message, first check Is it established? is the time when the message is received. If this condition is met, calculate: examine If yes, it means the mobile device MD i Certified Ground Station GSS k ; Password and fingerprint update phase: Step 1. Move the MD device i Request user U i Enter your ID i and the old password PW i , and press the old fingerprint information BIO on the device i ; Step 2. Mobile device calculates σ i =Rep(BIO i ,τ i ), HID i =(ID i ||r i ), HPW i =(PW i ||σ i ||r i ), and Check if If the phase is established, continue with the following steps; Otherwise, the login is terminated by the mobile device; Step 3. Move the MD device i Require the user to enter a new password And press the new fingerprint information MD i calculate and Finally, the mobile device will update the information stored in its memory.
7. A method for secure communication in a drone edge computing environment implementing the secure communication system in a drone edge computing environment as claimed in any one of claims 1 to 6, characterized in that: The secure communication method in the drone edge computing environment includes: Step 1, controlling the drone device through remote management via an entity used by a mobile user end to request access to a specific drone device; Step 2: Use ground stations to connect to each other through ground stations to form a consortium blockchain network, and deploy smart contracts on the blockchain to record secret data; the ground stations provide network connection and computing services for mobile users and drone devices; Step 3: Deploy drones in the open sky using drone equipment and connect wirelessly to nearby ground stations; deploy drones to resource-constrained areas to provide intelligent edge computing services for IoT devices in the area.
8. A computer device, characterized in that: The computer device includes a memory and a processor, the memory stores a computer program, and when the computer program is executed by the processor, the processor executes the steps of the secure communication method in the drone edge computing environment as claimed in claim 7.
9. A computer-readable storage medium storing a computer program, wherein when the computer program is executed by a processor, the processor executes the steps of the secure communication method in a drone edge computing environment as described in claim 7.
10. An information data processing terminal, characterized in that: The information data processing terminal is used to implement a secure communication system in a drone edge computing environment as described in any one of claims 1-6.