Unmanned aerial vehicle communication security authentication method and system based on PUF and LDPC
By adopting a security authentication method based on PUF and LDPC in the drone cluster network, the security challenges of the drone cluster network in the open airspace environment are solved, and fast, secure and low-energy drone communication authentication is achieved.
Patent Information
- Application Number
- CN202510186906.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-20
- Publication Date
- 2025-05-30
AI Technical Summary
UAV cluster networks face severe security challenges in open airspace environments, including physical capture attacks and man-in-the-middle attacks. The existing authentication solutions have high latency and energy consumption in actual deployment, making it difficult to meet the needs of nodes' fast network access authentication and real-time key updates.
The security authentication method of drone communication based on PUF and LDPC is adopted. By extracting fingerprint PUF and identity PUF from the system-on-chip chip of the drone, fuzzy matching and identity authentication are performed, and temporary anonymous address and point-to-point key are allocated after the authentication is successful to achieve secure communication.
This method can effectively resist physical capture attacks and man-in-the-middle attacks, reduce the computing and storage overhead of the authentication process, and is suitable for resource-constrained drone platforms, realizing millisecond authentication response and microwatt-level energy consumption control.
Smart Images

Figure CN120074833A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of wireless communication technologies, and particularly to a method and system for secure authentication of UAV communication based on PUF and LDPC. Background Art
[0002] With the rapid development of UAV technologies and the continuous improvement of the intelligent level, UAV swarm systems have demonstrated significant advantages in scenarios such as post-disaster life detection and material delivery, complex terrain and geological exploration, and 3D modeling of smart cities. Through multi-aircraft collaborative operations, UAV swarms can break through the payload and endurance limitations of single aircraft and achieve an exponential increase in task execution efficiency.
[0003] However, UAV swarm networks operating in open-airspace environments face severe security challenges: The wireless communication mechanisms and dynamic networking characteristics they adopt enable attackers to use signal interception devices to carry out physical capture attacks and obtain node keys through reverse engineering; at the same time, communication links in heterogeneous network topologies are vulnerable to man-in-the-middle attacks (MITM), resulting in the theft of sensitive telemetry data or the injection of malicious instructions. Existing authentication schemes based on elliptic curve cryptosystem (ECC) or RSA algorithms can provide theoretical security, but significant defects have emerged in actual deployments: Complex modular exponentiation operations and certificate management mechanisms result in a single authentication delay exceeding 200 ms, and the energy consumption level reaches 15%-20% of the available energy of micro UAVs, severely restricting the expansion of swarm scale and mission endurance capabilities. Especially in emergency scenarios with frequently changing dynamic topologies, traditional schemes are difficult to meet the timeliness requirements of rapid node access authentication and real-time key updates.
[0004] Therefore, the research and development of lightweight security authentication mechanisms for UAV swarm communication, while ensuring the strength of resistance to quantum computing attacks, achieving millisecond-level authentication responses and micro-watt-level energy consumption control, has become a key technical requirement for breaking through the bottleneck of large-scale applications of UAV swarm intelligence systems. Summary of the Invention
[0005] The purpose of the present invention is to provide a method and system for secure authentication of UAV communication with strong anti-attack ability, high security, low resource consumption, and strong real-time performance.
[0006] The technical solution for achieving the purpose of the present invention is: A method for secure authentication of UAV communication based on PUF and LDPC, comprising the following steps:
[0007] Step 1, extract the fingerprint PUF and identity PUF of the UAV from the UAV system-on-chip, and store the fingerprint PUF, identity PUF, and identity PUF extraction information in the ground station database;
[0008] Step 2: Before the drone executes the task, the ground station performs fuzzy matching on the drone using the fingerprint PUF.
[0009] Step 3: After successful fuzzy matching, the ground station authenticates the drone using the identity PUF and the information extracted from the identity PUF.
[0010] Step 4: After successful authentication, the ground station assigns a temporary anonymous address and a point-to-point key to the authenticated drone. The drone uses the temporary point-to-point key to encrypt communication data for secure communication.
[0011] Further, in Step 1, the fingerprint PUF and the identity PUF of the drone are extracted from the drone's system-on-chip (SoC) chip, and the fingerprint PUF, the identity PUF, and the information extracted from the identity PUF are stored in the ground station database as follows:
[0012] Step 1.1: Select an uninitialized static random access memory (RAM) in the drone's system-on-chip (SoC) chip as the PUF source.
[0013] Step 1.2: Use the PUF extraction function to start from the starting address of the RAM start and read an uninitialized area through a pointer, and record each byte array bit by bit in a file in binary. Multiple groups of binary strings are obtained by repeatedly powering on. Denote the proportion of '1' in the i-th column as p i and fit multiple groups of sequences into a sequence s for analysis according to the proportion, that is:
[0014]
[0015] If the number of '0' characters in each column is absolutely dominant, it is considered that the bit is '0'; if the number of '1' characters in each column is absolutely dominant, it is considered that the bit is '1'; the bit positions with a higher change frequency will be considered unstable bits and left blank for the next step of processing.
[0016] Step 1.3: Use a double-pointer to select a stable PUF segment, which needs to contain 256 stable bits with an ID of 32 bytes. Set the window left pointer win_left to record the starting position of the window, the window right pointer win_right to record the end position of the window containing 256 stable bits, and the array us_cnt[] to record the number of unstable bits in the current window. The left pointer moves one bit to the right each time, and the right pointer needs to move several bits to the right to ensure that the number of stable bits in the window is N bits. Since the minimum unit of pointer memory access is a byte, when traversing the array us_cnt[], the step is 8 bits to read the PUF. Finally, output the window position pos and the number of unstable bits when the number of unstable bits is the least.
[0017] Extract the identity PUF from the RAM segment, denoted as PUF ID , which is composed of N + us_cnt[pos] consecutive bits;
[0018] The reading position start of the PUF is offset from the RAM start by pos / 8 bytes, i.e.:
[0019]
[0020] The reading length of the PUF len is:
[0021]
[0022] The reading length needs to be rounded up to the total number of bits;
[0023] For the PUF ID , it is also necessary to record the positions of the unstable bits in the PUF segment, denoted as the unstable bit set S us , which is used to skip the unstable bits when the drone reads. The S us records the offset of the null character relative to the starting address of the PUF. After removing the unstable bits in the PUF, it is the registration ID of the drone. However, there may still be a few bit flips in the ID read when the drone is powered on. Therefore, on the basis of removing the unstable bits in the original PUF segment, it is also necessary to record the bits that may flip in the predicted unstable bit set S pus . The bits with a flip rate > 10% are classified as unstable bits, and the remaining bits are used as the ID sequence. The bits with a non-zero flip rate in the ID sequence are classified as predicted unstable bits for LDPC coding during authentication;
[0024] Select a part in the target RAM segment with a length greater than the set value and not overlapping with the PUF ID as the fingerprint PUF, denoted as PUF fp ;
[0025] Step 1.4. Use the communication address of the drone as an index to select an IP address, and register the PUF ID reading position and reading length, the unstable bit set and predicted unstable bit set in the PUF, PUF fp and the fuzzy matching threshold τ and a static key key static in the database, i.e.:
[0026] {IP, PUF start , PUF len , ID, S us , S pus , PUFfp , τ, key static}
[0027] where key static is used for timestamp encryption to resist replay attacks.
[0028] Furthermore, before the drone executes the task in step 2, the ground station performs fuzzy matching on the drone using fingerprint PUF as follows:
[0029] Step 2.1: The ground station generates a random challenge, and the drone generates a response fingerprint according to the challenge;
[0030] Step 2.2: The ground station verifies the similarity between the response fingerprint of the drone and the F-PUF stored in the database through a fuzzy matching algorithm. If the matching is successful, it enters the second stage.
[0031] Furthermore, after the fuzzy matching is successful in step 3, the ground station authenticates the drone using identity PUF and identity PUF extraction information as follows:
[0032] Step 3.1: The ground station sends the extraction information of ID-PUF to the drone, and the drone reads the ID-PUF according to the extraction information;
[0033] Step 3.2: The drone uses LDPC code to correct the errors of ID-PUF and recovers the correct ID-PUF;
[0034] Step 3.3: The ground station verifies the consistency between the recovered ID-PUF of the drone and the ID-PUF stored in the database. If they are consistent, the authentication is successful.
[0035] Furthermore, when the ground station sends the extraction information of ID-PUF to the drone in step 3.1, random perturbations are added to the extraction information of ID-PUF.
[0036] Furthermore, the encoding matrix of LDPC code in step 3.2 adopts quasi-cyclic LDPC code.
[0037] Furthermore, after the authentication is successful in step 4, the ground station assigns a temporary anonymous address and a point-to-point key to the authenticated drone. The drone uses the temporary point-to-point key to encrypt communication data for secure communication as follows:
[0038] Step 4.1: The communication in the flight network is divided into two types: data frames and network frames. Data frames are sent point-to-point, so data frames use P2P keys, while network frames are sent by broadcast, so network frames use broadcast keys;
[0039] The ground station uses the established key key tempSend the current broadcast key key to the newly authenticated drone bc Then, the ground station generates a P2P key set Set based on the authorized drones in the network P2P :
[0040]
[0041] Among them, the key set needs to include the communication key key between the newly authenticated drone and the ground station GS because in an ad-hoc network, all nodes are equal;
[0042] The ground station uses key bc to broadcast the address of the newly authenticated drone and the new P2P key set to the entire network, that is:
[0043]
[0044] Among them, IP G is the anonymous address of the ground station;
[0045] Step 4.2: For the newly authenticated drone, record the entire key set Set P2P For the authorized drones, only record the key key corresponding to the address IP of the newly authenticated drone new and its own address IP i During data transmission, the communication between the new drone IP i and the authorized drone IP new uses key i for encryption; To make the P2P key dynamic, the symmetric key allocated by the ground station is valid only once, and the effective number of times will be renegotiated and agreed upon when the two establish a data communication link for the first time; i From a global perspective, the communication key sets maintained by different drones form an adjacency matrix:
[0046] Among them, the new drone has not communicated with other drones, so the key iteration times for communicating with the new drone are all 1 time, and other drones have different degrees of updates;
[0047]
[0048]
[0049] Step 4.3: Since the frame format of the networking protocol is relatively fixed and the IP address is also fixed, the address of the newly authenticated drone and the new P2P key set are:
[0050]
[0051] That is, the ground station will assign a temporary random sequence to the drone before each mission As an address, the address in the P2P key set is also a random address. After any drone receives the broadcast key, it needs to use the first 32 bits in the subsequent received P2P key set as the temporary address for this task; the sequence number, length, and type fields in the ad hoc network protocol frame are not encrypted, and a hash value is used to prevent data from being tampered with;
[0052] Step 4.4, impose the following constraints on the generation method of the random vectors p and l:
[0053] The number of challenge-response pairs of the fingerprint PUF is directly related to the PUF length. Select 128 consecutive bytes as the PUF fp , a total of 512 bits; regard the PUF fp as a hexadecimal string composed of 128 characters, then the random number p i is exactly one byte, that is, p i ∈[0, 255]; select 4 random numbers, that is, the response fingerprint is composed of 4 segments;
[0054] For the random vector l generated by the drone, it is required that the sum is exactly 32 bytes, that is:
[0055]
[0056] Select the minimum length l min = 8, that is, 32 bits. Then when the drone generates 4 random numbers, it needs to meet:
[0057]
[0058] where the response length N = 256 and the number of segments L = 4;
[0059] Step 4.5, since the minimum read length is selected as 8 half-bytes, the registered fingerprint and the response fingerprint need to be initialized as an array in hexadecimal during matching; since the ground station knows the initial positions p i of different segments, then only need to select the operator with the minimum length read length l fp near the initial position of the PUF min , including a forward operator and a reverse operator, and then perform matrix multiplication with the response fingerprint:
[0060]
[0061] where is a 1×32-sized vector represented in hexadecimal, and w i is 1×l minAn operator of size, '⊙' means to perform exclusive OR sum after expanding the hexadecimal into binary and store the result in the amplitude array v i In it, using τ in the registration information, the positions in the amplitude array that exceed the matching threshold by 32τ bits are recorded in the peak array. Ideally, there is only one value in the peak array for each position, so the length between the peaks is the PUF challenge given by the drone:
[0062] l i = peek i+1 - peek i , peek 1 = 0, peek 5 = 257
[0063] Since the reading position p given by the ground station i is disordered, and the reading length l given by the drone i is also random, so for the response fingerprint there may be a situation where one segment contains another segment for different segments at two positions with the same reading direction. For two sequentially read positions p i > p j , i < j but l i << l j , then there will be two peaks after the exclusive OR sum operation in v i For two positions with reverse reading p i > p j , i < j but l i >> l j , there will also be two peaks. Since the response fingerprint is spliced in the order of the reading positions given by the ground station, some necessarily incorrect values are excluded through logical judgment, following the following two principles:
[0064] (1) The first peak at the latter position cannot be before the first peak at the previous position;
[0065] (2) The last peak at the previous position cannot be after the last peak at the latter position;
[0066] The reading positions are deleted according to the first principle from front to back and according to the second principle from back to front; for sequential reading when p i < p j , l i >> l j , i < j or for reverse reading when p i > p j , l i << l j, where i < j, make a judgment according to the formula; when selecting the RAM segment, it is also necessary to pay attention to whether the autocorrelation of the selected segment is periodic, otherwise a large number of peaks will be obtained in the peek array, and there may be multiple sets of legitimate solutions during fuzzy matching. Therefore, a fragmented PUF is adopted fp or increase the minimum read length l min in this way
[0067] Furthermore, the point-to-point key assigned by the ground station to the UAV in step 4 has a random lifespan and a random number of hash iterations, and is synchronized through the checksum field
[0068] A UAV communication security authentication system based on PUF and LDPC, which is used to implement the UAV communication security authentication method based on PUF and LDPC. The system includes a reading module, a fuzzy matching module, an authentication module, and a secure communication module, where
[0069] The reading module extracts the fingerprint PUF and identity PUF of the UAV from the UAV system-on-chip, and stores the fingerprint PUF, identity PUF, and identity PUF extraction information in the ground station database
[0070] The fuzzy matching module, before the UAV executes a task, the ground station uses the fingerprint PUF to perform fuzzy matching on the UAV
[0071] The authentication module, after successful fuzzy matching, the ground station uses the identity PUF and identity PUF extraction information to authenticate the UAV
[0072] The secure communication module, after successful authentication, the ground station assigns a temporary anonymous address and a point-to-point key to the authenticated UAV. The UAV uses the temporary point-to-point key to encrypt communication data for secure communication
[0073] A mobile terminal includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the UAV communication security authentication method based on PUF and LDPC
[0074] Compared with the prior art, the present invention has the following remarkable advantages: (1) By utilizing the uniqueness and non-clonability of PUF and combining the error correction ability of LDPC, it can not only effectively resist common attacks such as physical capture attacks and man-in-the-middle attacks, but also ensure the security and privacy of UAV communication through dynamic key distribution and anonymous address mechanisms; (2) Through the optimization of the fuzzy matching algorithm and LDPC codes, the computational and storage overheads in the authentication process are reduced, making it suitable for resource-constrained UAV platforms Description of the Drawings
[0075] Figure 1It is a schematic diagram of the scenario of the UAV communication system in the present invention.
[0076] Figure 2 It is a schematic flow diagram of a UAV communication security authentication method based on PUF and LDPC in the present invention.
[0077] Figure 3 It is a schematic flow diagram of PUF extraction and storage in the present invention.
[0078] Figure 4 It is a schematic flow diagram of the PUF extraction algorithm in the present invention.
[0079] Figure 5 It is a schematic flow diagram of the fuzzy matching algorithm in the present invention.
[0080] Figure 6 It is a schematic structural diagram of multi-peak values for sequential reading in the present invention. Specific embodiments
[0081] The following further elaborates on the present invention in detail in conjunction with the accompanying drawings and specific embodiments.
[0082] As Figure 1 shown, it is the system scenario diagram of the UAV communication system. All legitimate UAVs have registered a set of data in the database, including the communication address IP of the UAV, the fingerprint PUF, the identity PUF, and the extraction information of the identity PUF. Before the UAV executes a task, the ground station first performs fuzzy matching on the UAV using the fingerprint PUF, and then uses the symmetric key established after successful matching to guide the UAV to complete the reading and recovery of the ID. After successful authentication, a temporary symmetric key key temp is established. The ground station uses key temp to send the current broadcast key key bc of this task to the newly authorized UAV, and broadcasts the new P2P key set Set P2P to the UAV group. When transmitting data, the UAV will encrypt it with the P2P key key toIPi , and the data in the networking frame will be encrypted with key bc .
[0083] As Figure 2 shown, a UAV communication security authentication method based on PUF and LDPC in the present invention includes the following steps:
[0084] Step 1: Extract the fingerprint PUF and identity PUF of the UAV from the UAV system-on-chip, and store the fingerprint PUF, identity PUF, and identity PUF extraction information in the ground station database;
[0085] Step 2: Before the drone executes the task, the ground station performs fuzzy matching on the drone using the fingerprint PUF.
[0086] Step 3: After successful fuzzy matching, the ground station performs identity authentication on the drone using the identity PUF and the information extracted from the identity PUF.
[0087] Step 4: After successful authentication, the ground station assigns a temporary anonymous address and a point-to-point key to the authenticated drone. The drone uses the temporary point-to-point key to encrypt communication data for secure communication.
[0088] As a specific example, in Step 1, the fingerprint PUF and identity PUF of the drone are extracted from the drone's system-on-chip (SoC) chip, and the fingerprint PUF, identity PUF, and the information extracted from the identity PUF are stored in the ground station database, as Figure 3 shown below:
[0089] Step 1.1: Select an uninitialized static random access memory (RAM) in the drone's system-on-chip (SoC) chip as the PUF source.
[0090] Step 1.2: Use the PUF extraction function to start from the starting address RAM of the RAM start and read an uninitialized area through a pointer, and record each byte array bit by bit in a binary file. By repeatedly powering on, multiple groups of binary strings are obtained. Denote the proportion of '1' in the i-th column as p i , and fit multiple groups of sequences into a sequence s for analysis according to the proportion, that is:
[0091]
[0092] If the number of characters '0' in each column is dominant, it is considered that the bit is '0', and vice versa; the bit positions with higher change frequencies will be considered unstable bits and left blank for the next step of processing.
[0093] Step 1.3: Adopt a double-pointer to select a relatively stable PUF segment, which needs to contain 256-bit stable bits with an ID of 32 bytes. The double-pointer sliding window algorithm is as Figure 4As shown in the figure, the window left pointer win_left is set to record the starting position of the window, the window right pointer win_right is used to record the end position of the window containing 256 stable bits, and the array us_cnt[] is used to record the number of unstable bits in the current window; the left pointer moves one bit to the right each time, and the right pointer needs to move several bits to the right to ensure that the number of stable bits in the window is N bits; since the minimum unit for the pointer to access memory is a byte, when traversing the array us_cnt[], the step is 8 bits to facilitate reading the PUF; finally, the window position with the least number of unstable bits, that is, pos, and the number of unstable bits are output.
[0094] After using the above algorithm, the identity PUF is extracted from the RAM segment and denoted as PUF ID , which is composed of N + us_cnt[pos] consecutive bits;
[0095] The reading position start of the PUF is offset from the RAM start by pos / 8 bytes, that is:
[0096]
[0097] The reading length of the PUF len is:
[0098]
[0099] The reading length needs to be rounded up to the total number of bits;
[0100] For the PUF ID , it is also necessary to record the positions of the unstable bits in the PUF segment, denoted as the unstable bit set S us , which is used to skip the unstable bits when the drone reads. The values recorded in S us are the offsets of the null characters relative to the starting address of the PUF. After removing the unstable bits in the PUF, it is the registration ID of the drone. However, when the drone is powered on, the ID read may still have a few bit flips. Therefore, on the basis of removing the unstable bits from the original PUF segment, the bits that may flip need to be recorded in the predicted unstable bit set S pus . The bits with a flip rate > 10% are classified as unstable bits, and the remaining bits are used as the ID sequence. For the bits in the ID sequence with a non-zero flip rate, they are classified as predicted unstable bits for LDPC coding during authentication;
[0101] Select a relatively long part in the target RAM segment that does not overlap with the PUF ID as the fingerprint PUF and denote it as PUF fp ;
[0102] Step 1.4: Using the communication address of the drone, usually an IP address, index the PUF ID reading position and reading length, the unstable bit set and predicted unstable bit set in the PUF, the PUF fp and the fuzzy matching threshold τ and a static key key static in the database, that is:
[0103] {IP, PUF start , PUF len , ID, S us , S pus , PUF fp , τ, key static}
[0104] where key static is used for timestamp encryption to resist replay attacks.
[0105] As a specific example, in Step 2, before the drone executes a task, the ground station performs fuzzy matching on the drone using the fingerprint PUF, specifically as follows:
[0106] Step 2.1: The ground station generates a random challenge, and the drone generates a response fingerprint based on the challenge;
[0107] Step 2.2: The ground station verifies the similarity between the response fingerprint of the drone and the F-PUF stored in the database through a fuzzy matching algorithm. If the match is successful, it enters the second stage.
[0108] As a specific example, in Step 3, after successful fuzzy matching, the ground station authenticates the drone using the identity PUF and the information extracted from the identity PUF, specifically as follows:
[0109] Step 3.1: The ground station sends the extraction information of the ID-PUF to the drone, and the drone reads the ID-PUF according to the extraction information;
[0110] Step 3.2: The drone uses the LDPC code to correct the errors of the ID-PUF and recover the correct ID-PUF;
[0111] Step 3.3: The ground station verifies the consistency between the recovered ID-PUF of the drone and the ID-PUF stored in the database. If they are consistent, the authentication is successful.
[0112] As a specific example, when the ground station sends the extraction information of the ID-PUF to the drone in Step 3.1, random perturbations can be added to the extraction information of the ID-PUF to increase the security of the authentication process.
[0113] As a specific example, the encoding matrix of the LDPC code described in step 3.2 adopts a quasi-cyclic LDPC code to reduce the storage overhead.
[0114] As a specific example, in step 4, after successful authentication, the ground station assigns a temporary anonymous address and a point-to-point key to the authenticated drone. The drone uses the temporary point-to-point key to encrypt communication data for secure communication, as follows:
[0115] Step 4.1: The communication in the flight network is divided into two categories: data frames and network frames. Data frames are sent point-to-point, so data frames use the P2P key, while network frames are sent via broadcast, so network frames use the broadcast key;
[0116] The ground station uses the established key key temp to send the current broadcast key key bc to the newly authenticated drone, and then the ground station generates a set of P2P keys Set P2P based on the authorized drones in the network:
[0117]
[0118] The key set needs to include the communication key key GS between the newly authenticated drone and the ground station, because in the ad hoc network, all nodes are equal;
[0119] The ground station uses key bc to broadcast the address of the newly authenticated drone and the new set of P2P keys to the whole network, that is:
[0120]
[0121] where IP G is the anonymous address of the ground station;
[0122] Step 4.2: For the newly authenticated drone, it needs to record the entire key set Set P2P , while for the authorized drone, it only needs to record the key key new corresponding to the address IP i of the newly authenticated drone and its own address IP i . In data transmission, the communication between the new drone IP new and the authorized drone IP i uses key i for encryption; to make the P2P key dynamic, the symmetric key assigned by the ground station is valid only once, and the effective number of times will be renegotiated and agreed upon when the two establish a data communication link for the first time;
[0123] From a global perspective, the communication key sets maintained by different drones can form an adjacency matrix:
[0124]
[0125] Among them, since the new drone has not communicated with other drones, the number of key iterations for communicating with the new drone is 1 time each, and other drones have been updated to varying degrees;
[0126] Step 4.3: Since the frame format of the actual networking protocol is relatively fixed and the IP address is also fixed, if the data packet is directly encrypted with the key, the key will be partially exposed, putting the entire system at risk. Therefore, the newly authenticated drone address and the new P2P key set should be:
[0127]
[0128] That is, the ground station will assign a temporary random sequence to the drone before each mission as the address. The address in the P2P key set is also a random address. After any drone receives the broadcast key, it needs to use the first 32 bits in the subsequently received P2P key set as the temporary address for this mission to ensure the anonymity of the drone swarm. In addition, to ensure key security, some fields such as sequence numbers, lengths, and types in the ad-hoc networking protocol frame are not encrypted, but hash values are used to ensure that the data is not tampered with;
[0129] Step 4.4: The algorithm for reverse-solving the drone challenge is essentially a matrix multiplication. Since matrix multiplication is a computationally intensive operation, the generation methods of the random vectors p and l are constrained as follows:
[0130] The number of challenge-response pairs of the fingerprint PUF is directly related to the PUF length. However, to reduce memory consumption, a 128-byte continuous segment is selected as the PUF fp , which is a total of 512 bits. Considering that the time overhead of binary multiplication by bitwise XOR is quite large, if 1 byte is used as the minimum XOR unit, then the total number of randomly read positions p i will be directly reduced to 1 / 8 4 , so if the PUF fp is regarded as a hexadecimal string composed of 128 characters, the random number p i is exactly 1 byte, that is, p i ∈[0, 255], and the operation speed is increased by 4 times; 4 random numbers are selected, that is, the response fingerprint is composed of 4 segments to speed up the solution by the ground station;
[0131] For the random vector l generated by the drone, the sum needs to be exactly 32 bytes, that is:
[0132]
[0133] If l i is too short, the peak may be similar to the noise and the matching difficulty will be quite large; if l i is too long, the randomness will be greatly reduced. Therefore, the minimum length l min = 8, that is, 32 bits. Then when the UAV generates 4 random numbers, it needs to meet:
[0134]
[0135] where the response length N = 256 and the number of segments L = 4;
[0136] Step 4.5. Since the minimum read length is selected as 8 half - bytes, the registered fingerprint and the response fingerprint need to be initialized as arrays in hexadecimal when matching; since the ground station knows the initial positions p i of different segments, then only the operator with the minimum length read length l fp needs to be selected near the initial position of the PUF min . It contains a forward operator and a reverse operator, and then performs matrix multiplication with the response fingerprint:
[0137]
[0138] where is a 1×32 - sized vector represented in hexadecimal, w i is an operator of size 1×l min . '⊙' means performing "XOR sum" after expanding the hexadecimal to binary and storing the result in the amplitude array v i . Using τ in the registration information, the positions in the amplitude array that exceed the matching threshold by 32τ bits are recorded in the peak array. The algorithm flow is as Figure 5 shown. Ideally, there is only one value in the peak array at each position, then the length between the peaks is the PUF challenge given by the UAV:
[0139] l i = peek i+1 - peek i , peek 1 = 0, peek 5 = 257
[0140] Since the read positions p i given by the ground station are disordered and the read length l i given by the UAV is also random, the response fingerprint For two fragments at different positions read in the same direction, it is possible that one fragment contains the other. For two positions p read sequentially i > p j , i < j but l i << l j , then there will be two peaks after the "exclusive - OR sum" operation. For two positions p read in reverse order i > p i > p j , i < j but l i >> l j , there will also be two peaks, as shown in (a) of Figure 6 and (b) of Figure 6 . Since the response fingerprint is spliced in the order of the reading positions given by the ground station, some definitely incorrect values can be excluded through simple logical judgment, following the following two principles:
[0141] (1) The first peak at the latter position cannot be before the first peak at the previous position;
[0142] (2) The last peak at the previous position cannot be after the last peak at the latter position;
[0143] According to the reading positions, deletion can be performed from front to back according to the first principle and from back to front according to the second principle; for sequential reading when p i < p j , l i >> l j , i < j or for reverse reading when p i > p j , l i << l j , i < j, it can be judged according to the formula; when selecting the RAM fragment, it is also necessary to pay attention to whether the autocorrelation of the selected fragment is periodic. Otherwise, a large number of peaks will be obtained in the peek array, and there may be multiple sets of legitimate solutions during fuzzy matching. Therefore, the fragmented PUF fp or increasing the minimum reading length l min is adopted.
[0144] As a specific example, the point - to - point key assigned by the ground station to the UAV in step 4 has a random lifetime and a random number of hash iterations, and is synchronized through the checksum field.
[0145] The present invention also provides a UAV communication security authentication system based on PUF and LDPC, which is used to implement the UAV communication security authentication method based on PUF and LDPC. The system includes a reading module, a fuzzy matching module, an authentication module, and a secure communication module, where:
[0146] A reading module extracts the fingerprint PUF and identity PUF of the drone from the drone's system-on-chip, and stores the fingerprint PUF, identity PUF, and identity PUF extraction information in the ground station database;
[0147] A fuzzy matching module, before the drone executes a task, the ground station uses the fingerprint PUF to perform fuzzy matching on the drone;
[0148] An authentication module, after successful fuzzy matching, the ground station uses the identity PUF and identity PUF extraction information to authenticate the identity of the drone;
[0149] A secure communication module, after successful authentication, the ground station assigns a temporary anonymous address and a point-to-point key to the authenticated drone, and the drone uses the temporary point-to-point key to encrypt communication data for secure communication.
[0150] The present invention also provides a mobile terminal, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the above-mentioned drone communication security authentication method based on PUF and LDPC.
[0151] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.
Claims
1. A UAV communication security authentication method based on PUF and LDPC, characterized in that: The following steps are involved: Step 1: Extract the fingerprint PUF and identity PUF of the drone from the drone system-on-chip chip, and store the fingerprint PUF, identity PUF and identity PUF extraction information in the ground station database; Step 2: Before the drone performs a mission, the ground station uses the fingerprint PUF to perform fuzzy matching on the drone; Step 3: After the fuzzy match is successful, the ground station uses the identity PUF and identity PUF extraction information to authenticate the drone; Step 4: After successful authentication, the ground station assigns a temporary anonymous address and point-to-point key to the successfully authenticated drone. The drone uses the temporary point-to-point key to encrypt communication data for secure communication.
2. The UAV communication security authentication method based on PUF and LDPC according to claim 1 is characterized in that: In step 1, the fingerprint PUF and identity PUF of the drone are extracted from the drone system-on-chip chip, and the fingerprint PUF, identity PUF and identity PUF extraction information are stored in the ground station database as follows: Step 1.1, select an uninitialized static random access memory RAM in the drone system-on-chip SoC chip as the PUF source; Step 1.2: Use the PUF extraction function to extract the RAM from the starting address of the RAM start First, read an uninitialized area through the pointer, and record the byte array in the file one by one according to the binary bits. By repeatedly powering on, multiple sets of binary strings are obtained, and the proportion of '1' in the i-th column is recorded as p i , and fit multiple groups of sequences into a series of sequences s for analysis according to the proportion, that is: If the number of characters '0' in each column is overwhelmingly dominant, the bit is considered to be '0'; if the number of characters '1' in each column is overwhelmingly dominant, the bit is considered to be '1'; bits with a higher frequency of change are considered to be unstable bits and are left blank for the next step of processing; Step 1.3, use double pointers to select a stable PUF segment, which needs to include 256 stable bits with an ID of 32 bytes, set the window left pointer win_left to record the window start position, the window right pointer win_right to record the window end position containing 256 stable bits, and the array us_cnt[] to record the number of unstable bits in the current window; the left pointer moves one bit to the right each time, and the right pointer needs to move several bits to the right to ensure that the number of stable bits in the window is N bits; since the minimum unit of pointer access to memory is byte, the step is 8 bits when traversing the array us_cnt[] to read the PUF; finally, output the window position when the number of unstable bits is the least, that is, pos, and the number of unstable bits; The identity PUF is extracted from the RAM fragment and is denoted as PUF ID , the PUF is composed of N+us_cnt[pos] consecutive bits; The PUF reading position starts from RAM start Offset pos / 8 bytes, that is: Read Length PUF len for: The read length needs to be rounded up to the total number of bits; For PUF ID For the PUF segment, it is also necessary to record the location of the unstable bits in the PUF segment, which is recorded as the unstable bit set S us , used to skip unstable bits when the drone reads, S us What is recorded in is the offset of the null character relative to the PUF start address. After removing the unstable bits in the PUF, it is the registration ID of the drone. However, the ID read when the drone is powered on may still have a few bits flipped. Therefore, on the basis of removing the unstable bits in the original PUF fragment, it is also necessary to record the bits that may flip in the predicted unstable bit set S. pus In the algorithm, bits with a flip rate greater than 10% are classified as unstable bits, and the remaining bits are used as ID sequences. Bits with a flip rate not equal to zero in the ID sequence are classified as predicted unstable bits for LDPC coding during authentication. Select a segment in the target RAM segment that is longer than the set value and does not overlap with the PUF ID The overlapping part is used as the fingerprint PUF, recorded as PUF fp ; Step 1.4: Use the drone's communication address as the index, select the IP address, and insert the PUF ID Read position and read length, unstable bit set and predicted unstable bit set in PUF, PUF fp and a fuzzy matching threshold τ and a static key key static Register in the database, that is: {IP,PUF start ,PUF len ,ID,S us ,S pus ,PUF fp ,τ,key static } The key static Used for timestamp encryption to resist replay attacks.
3. The UAV communication security authentication method based on PUF and LDPC according to claim 1 is characterized in that: In step 2, before the drone performs a mission, the ground station uses the fingerprint PUF to perform fuzzy matching on the drone, as follows: Step 2.1: The ground station generates a random challenge, and the drone generates a response fingerprint based on the challenge; Step 2.2: The ground station verifies the similarity between the drone’s response fingerprint and the F-PUF stored in the database through a fuzzy matching algorithm. If the match is successful, it enters the second stage.
4. The UAV communication security authentication method based on PUF and LDPC according to claim 1 is characterized in that: After the fuzzy match is successful in step 3, the ground station uses the identity PUF and identity PUF extraction information to authenticate the drone as follows: Step 3.1: The ground station sends the ID-PUF extraction information to the drone, and the drone reads the ID-PUF based on the extraction information; Step 3.2: The drone uses LDPC code to correct the ID-PUF and recover the correct ID-PUF; Step 3.3: The ground station verifies the consistency between the ID-PUF recovered by the drone and the ID-PUF stored in the database. If they are consistent, the authentication is successful.
5. The UAV communication security authentication method based on PUF and LDPC according to claim 4 is characterized in that: When the ground station sends the extracted information of ID-PUF to the drone in step 3.1, random perturbations are added to the extracted information of ID-PUF.
6. The UAV communication security authentication method based on PUF and LDPC according to claim 4 is characterized in that: The coding matrix of the LDPC code in step 3.2 adopts a quasi-cyclic LDPC code.
7. The UAV communication security authentication method based on PUF and LDPC according to claim 1 is characterized in that: After successful authentication in step 4, the ground station assigns a temporary anonymous address and point-to-point key to the successfully authenticated drone. The drone uses the temporary point-to-point key to encrypt communication data for secure communication, as follows: Step 4.1, the communication in flight networking is divided into two categories: data frames and networking frames. Data frames are sent point-to-point, so data frames use P2P keys, while networking frames are sent through broadcast, so networking frames use broadcast keys; The ground station uses the established key temp Send the current broadcast key to the newly authenticated drone bc , then the ground station generates a P2P key set Set based on the authorized drones in the network P2P : Set P2P ={s GS ,s IP1 ,s IP2 ,...}={{IP GS ,key GS },{IP1,key1},{IP2,key2}} The key set needs to include the communication key between the newly authenticated drone and the ground station. GS , because in an ad hoc network, all nodes are equal; Ground station uses key bc Broadcast the newly authenticated drone address and new P2P key set to the entire network, namely: Among them, IP G is the anonymous address of the ground station; Step 4.2: For newly certified drones, record the entire key set Set P2P For authorized drones, only the newly authenticated drone address IP is recorded. new and your own IP address i The corresponding key i , New drone IP in data transmission new With the authorized drone IP i Communication between the two uses key i Encryption; In order to make the P2P key dynamic, the symmetric key assigned by the ground station is valid for one time. When the two parties establish a data communication link for the first time, they will renegotiate and agree on the number of validity times. From a global perspective, the communication key sets maintained by different drones form an adjacency matrix: Among them, the new drone did not communicate with other drones, so the number of key iterations for communicating with the new drone was 1, and other drones were updated to varying degrees; Step 4.3: Since the frame format of the networking protocol is relatively fixed and the IP address is also fixed, the newly authenticated drone address and new P2P key set are: That is, the ground station will assign a temporary random sequence to the drone before each mission. As the address, the address in the P2P key set is also a random address. After receiving the broadcast key, any drone needs to use the first 32 bits of the subsequently received P2P key set as the temporary address of this task; the sequence number, length and type fields in the ad hoc network protocol frame are not encrypted, and hash values are used to prevent data from being tampered with; Step 4.4: Constrain the generation of random vectors p,l as follows: The number of challenge-response pairs of fingerprint PUF is directly related to the length of PUF. A continuous segment of 128 bytes is selected as PUF. fp , a total of 512 bits; PUF fp is regarded as a hexadecimal string of 128 characters, then the random number p i Just one byte, that is, p i ∈[0,255]; select 4 random numbers, i.e. the response fingerprint It is composed of 4 segments; For the random vector l generated by the drone, the sum needs to be exactly 32 bytes, that is: Select the minimum length l min =8, i.e. 32 bits, then when the drone generates 4 random numbers, it needs to meet the following requirements: Wherein the response length N = 256, the number of fragments L = 4; Step 4.5: Since the minimum read length is selected as 8 nibbles, the registered fingerprint and the response fingerprint need to be initialized in hexadecimal arrays during matching; since the ground station knows the initial positions of different fragments p i , then we only need to fp Select the minimum length near the initial position of the read length l min The operator consists of a forward operator and a reverse operator, and then performs matrix multiplication with the response fingerprint: in is a 1×32 vector in hexadecimal notation, w i is 1×l min The size operator, '⊙' means to expand the hexadecimal to binary and then perform XOR and store the result in the amplitude array v i In the example, using the τ in the registration information, the positions in the amplitude array that exceed the matching threshold by 32τ bits are recorded in the peak array. Ideally, there is only one value in the peak array at each position, so the length between the peaks is the PUF challenge given by the drone: l i =peek i+1 -peek i ,peek1=0,peek5=257 Since the reading position p given by the ground station i is unordered, and the drone gives a read length l i is also random, so the response fingerprint For different fragments of two positions read in the same direction, one fragment may contain another fragment. For two positions read sequentially, i >p j ,i<j but l i <<l j , then in v i After the XOR operation, two peaks will appear, one for each of the two positions p read in reverse order. i >p j ,i<j but l i >>l j , there will also be two peaks. Since the response fingerprint is spliced in the order of the reading positions given by the ground station, some necessarily wrong values are excluded through logical judgment, following the following two principles: (1) The first peak of the latter position cannot be before the first peak of the former position; (2) The last peak of the previous position cannot be after the last peak of the next position; The read position is deleted according to the first principle from the front to the back, and deleted according to the second principle from the back to the front; for sequential reading, p i <p j ,l i >>l j , i<j or read in reverse order p i >p j ,l i <<l j , i<j, judge according to the formula; when selecting RAM segments, it is also necessary to pay attention to whether the autocorrelation of the selected segments is periodic, otherwise a large number of peaks will be obtained in the peek array, and it is possible to obtain multiple combinations of solutions during fuzzy matching, so fragmented PUF is used fp Or increase the minimum read length l min way.
8. The UAV communication security authentication method based on PUF and LDPC according to claim 7 is characterized in that: The point-to-point key assigned by the ground station to the drone in step 4 has a random lifetime and a random hash iteration number, and is synchronized through the checksum field.
9. A UAV communication security authentication system based on PUF and LDPC, characterized in that: The system is used to implement the UAV communication security authentication method based on PUF and LDPC as described in any one of claims 1 to 8, and the system includes a reading module, a fuzzy matching module, an authentication module and a secure communication module, wherein: The reading module extracts the fingerprint PUF and identity PUF of the drone from the drone system-on-chip chip and stores the fingerprint PUF, identity PUF and identity PUF extraction information in the ground station database; Fuzzy matching module: before the drone performs a mission, the ground station uses the fingerprint PUF to perform fuzzy matching on the drone; Authentication module,After the fuzzy matching is successful, the ground station uses the identity PUF and identity PUF extraction information to authenticate the drone; Secure communication module: After successful authentication, the ground station assigns a temporary anonymous address and point-to-point key to the successfully authenticated drone. The drone uses the temporary point-to-point key to encrypt communication data for secure communication.
10. A mobile terminal comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the UAV communication security authentication method based on PUF and LDPC is implemented as described in any one of claims 1 to 8.