Secure communication method of unmanned aerial vehicle group based on block chain
By using blockchain technology to perform node authentication and key negotiation in drone groups, the security threats faced by drone groups during the execution of tasks are solved, distributed network security is achieved, and the security of drone communication is improved.
Patent Information
- Application Number
- CN202510291081.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-12
- Publication Date
- 2025-05-30
AI Technical Summary
During the execution of tasks, drone groups are susceptible to security threats such as fake nodes, data eavesdropping and data tampering, and the existing technology security system is limited by the complexity of managing all nodes and single point of failure problems.
The secure communication method of a blockchain-based drone group is adopted, node registration and key negotiation management are carried out through blockchain technology, and the distributed and tamper-free characteristics are used to realize the network security of the drone group.
Effectively prevent the joining of fake nodes and the leakage of keys, ensure the integrity and authenticity of data transmission, solve the single point of failure and trust problems in security authentication in the drone network, and improve the security of drone communication.
Smart Images

Figure CN120075799A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of UAV communication, and particularly to a secure communication method for a UAV swarm based on blockchain. Background Art
[0002] During the process of a UAV group performing tasks, its frequency band is relatively fixed, and it is vulnerable to security threats such as fake nodes, data eavesdropping, and data tampering. In addition, UAVs usually adopt a mesh topology structure, and its security system is restricted by the complexity of managing all nodes and the single-point failure problem. Therefore, designing a reliable distributed network security scheme is crucial for ensuring group communication security. Summary of the Invention
[0003] Object of the Invention: In order to overcome the deficiencies in the prior art, the present invention provides a secure communication method for a UAV swarm based on blockchain, which uses blockchain technology as a platform for UAV node registration and key negotiation management, and gives full play to the distributed and tamper-proof characteristics of blockchain to achieve the network security of the UAV group.
[0004] Technical Solution: To achieve the above object, a secure communication method for a UAV swarm based on blockchain of the present invention includes a UAV key management center and several UAVs; several UAVs all serve as UAV nodes; the UAV key management center authenticates the UAVs as UAV nodes through blockchain as a node authentication platform; after the UAV node authentication is completed, several UAV nodes conduct a campaign to be the leading UAV node; then, the UAV group composed of several UAVs conducts group key negotiation based on the group key negotiation protocol of blockchain to determine the final session group key of the group key negotiation; the UAV nodes in the UAV group realize data transmission between the UAV node and the remaining UAV nodes through blockchain and the final session group key; when a UAV joins or leaves the UAV group, the session group key of the UAV group is updated in real time and dynamically.
[0005] Further, the UAV node authentication includes an initialization stage, a partial key generation stage, and an authentication stage; in the initialization stage, the UAV key management center initializes the system parameters to generate its own public key P and private key s, the UAV key management center selects a large prime number p, and defines a non-singular elliptic curve G on y 2 = x 3 + ax + b mod p, a cyclic group of prime order n on the non-singular elliptic curve G, with the generator g; the UAV key management center UAV-KMC randomly selects the private key s, and calculates the public key P = sg, obtaining the public-private key pair of the UAV key management center UAV-KMC as (P, s);
[0006] H(x) = g x mod p
[0007] In the formula, mod is the modulo operation, H(x) is the hash function, and g is the generator;
[0008] Each drone node U i Randomly selects a private key And calculates the public key Q i = a i g, the drone node U i The drone node U i The public key Q of i And the identity identifier UID of the drone node i Combined to obtain {UID i , Q i} and sent to the drone key management center UAV-KMC.
[0009] Furthermore, in the partial key generation stage, after the drone key management center UAV-KMC receives {UID i , Q i , Q i} of the drone node U, it calculates the partial private key d i And the partial public key Q' corresponding to the partial private key i ; And the partial public-private key pair (Q' i , d i ) combined with the partial private key d i and the partial public key Q' i is sent to the drone node U i ,
[0010] d i = s + b i mod p
[0011] Q i ' = d i g
[0012] In the formula, s is the private key of the drone key management center, b i is a random value, mod is the modulo operation, and g is the generator.
[0013] Furthermore, in the authentication stage, the drone node Ui randomly selects a temporary private key And calculates the temporary public key R corresponding to the temporary private key i , and the drone node simultaneously calculates the hash value h,
[0014] R i = r i g
[0015] h = H(R i || T)
[0016] Wherein, || is the concatenation operator, T is the timestamp, h is the hash value, and H is the hash function;
[0017] The digital signature of the message data sent by the UAV node to the UAV key management center i is σ i =(T, R i , h), and the UAV node U i sends the information (data i , UID i , σ i ) to the UAV key management center; after receiving the information (data i , UID i , σ i ), the UAV key management center checks whether the timestamp T is valid. When the timestamp T is valid, the UAV key management center calculates the verification temporary public key R' corresponding to the temporary private key of the UAV node Ui i ;
[0018] R' i =σ i ·g-a i ·Q i
[0019] When R' i =R i , then the UAV node U i is successfully authenticated.
[0020] Furthermore, group key negotiation is performed within the UAV group composed of several UAVs; each UAV U in the several UAVs randomly selects a negotiation temporary private key and uses a ring structure to calculate the shared key part K i1 and K i2 ;
[0021] K i1 =t i T i+1 modp, K i2 =t i T i-1 modp
[0022] Wherein, T i+1 and T i-1 are the negotiation temporary public keys of the right adjacent node and the left adjacent node respectively;
[0023] The obtained shared key parts K i1 and K i2 are both sent to the right adjacent UAV node U i+1 and the left adjacent UAV node U i-1 ; The right adjacent UAV node Ui+1 Receive the key K i1 and K i2 then calculate the secret value S i+1 , and calculate the hash value H i+1 ;
[0024] S i+1 = K i1 + K i2
[0025] H i+1 = H(S i+1 || T)
[0026] The left - adjacent UAV node U i-1 has the same calculation process as the right - adjacent UAV node U i+1 to obtain the secret value S i-1 and hash value H i-1 of the left - adjacent UAV node U i-1 ; Each UAV node U i transmits the corresponding secret value S i to the leader UAV node; The leader UAV node generates a member information list XL = {S i , S 1 ,..., S 2 ,...} based on the S i corresponding to each UAV, and broadcasts the tuple to the remaining UAV nodes in the UAV group;
[0027] After each UAV node U i receives the member information list XL sent by the leader UAV node, it starts to verify S i , and verifies whether the equation K i = H(S i || T) holds; When the equation holds, calculate the group key K session ;
[0028] K session = ∑ i K i
[0029] Each UAV node sends the group key K session to the leader UAV node, and the leader UAV node verifies the received group key K session . After successful verification, the leader UAV node broadcasts the group key K session as the final session group key for group key negotiation.
[0030] Furthermore, when UAV node A transmits data to UAV node B based on the blockchain, the following steps are included:
[0031] S1-1. The UAV node A symmetrically encrypts the data code to be transmitted through the session group key to obtain the ciphertext E code , and calculates the hash value H code of the ciphertext E code . The UAV node A packs the ciphertext E code , the hash value H code and the timestamp T into a data packet Z;
[0032] S1-2. The UAV node A transmits the data packet Z to the UAV node B through the UID of the target UAV, and the UAV node that receives the data packet Z records it in the blockchain;
[0033] S1-3. After receiving the data packet Z, the UAV node B extracts the ciphertext E code and the hash value H code . The UAV node B calculates and verifies the hash value H' code based on the ciphertext E code ; when the hash value H code is consistent with the verification hash value H' code , the UAV node B decrypts the ciphertext E session through the session group key K code to obtain the original data code;
[0034] S1-4. The UAV node B generates an acknowledgement message ACK based on the hash value H code and the timestamp T in the data packet Z, and broadcasts the acknowledgement message ACK to other UAV nodes through the network. The UAV node that receives the acknowledgement message ACK records it in the blockchain.
[0035] Further, when a new UAV joins a UAV group composed of several UAVs, the following steps are included:
[0036] S2-1. The new UAV node U n requests node authentication from the UAV key management center and sends the public key Q n and the temporary public key R n of the UAV node U n ;
[0037] S2-2. The UAV key management center calculates the partial private key d n and the partial public key Q' n of the UAV node U n and sends them to the UAV node U n , and performs node authentication based on the temporary public key R n of the UAV node U n ;
[0038] S2-3. The UAV node Un Send a group entry request to the leader drone node in the drone group, and the leader drone node sends a join request to all the original drone nodes; when the number of drone nodes that agree to the request exceeds half of all the original drone nodes, the leader drone node broadcasts to all drone nodes to agree that drone node U n Join request;
[0039] S2-4. Drone node U n Randomly select a negotiation temporary key t n , and calculate the negotiation temporary public key T corresponding to the negotiation temporary key n ; Each original drone node U i Calculate the shared key part K with drone node U n And K in And transmit it to the leader drone node, and the leader drone node calculates and broadcasts the updated session group key based on the shared key part. ni
[0040] Furthermore, when a drone leaves the drone group composed of several drones, the following steps are included:
[0041] S3-1. Drone node U L Notify the leader drone node that drone node U L Is about to leave; the leader drone node sends the information that drone node U L Leaves the group to all drone nodes;
[0042] S3-2. Except for drone node U in the drone group L Other drone nodes U i All randomly select a new negotiation temporary private key t' i , calculate the new negotiation temporary public key T' i ; And broadcast the new negotiation temporary private key t' i And the new negotiation temporary public key T' i To other drone nodes;
[0043] S3-3. Each drone node U i Calculate the new shared key part with adjacent drone nodes and transmit it to the leader drone node, and the leader drone node calculates and broadcasts the updated session group key based on the new shared key part.
[0044] Beneficial effects: A secure communication method for an unmanned aerial vehicle (UAV) swarm based on blockchain. The group key negotiation protocol based on blockchain can achieve distributed UAV node authentication and group key negotiation, effectively preventing the addition of fake nodes and the leakage of keys. The data transmission method based on blockchain ensures the integrity and authenticity of data transmission through communication verification without relying on digital signatures. By combining blockchain technology with network security, it solves the problems of blockchain application in the UAV network and ensures the security of the UAV network. It can effectively guarantee the communication security of distributed UAV groups, avoid the defects of the traditional UAV network security communication system, solve the single-point failure and trust problems in UAV security authentication in the existing technology, and improve the security of UAV communication. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] Figure 1 It is a schematic diagram of the system for secure communication negotiation of an unmanned aerial vehicle (UAV) swarm based on blockchain;
[0046] Figure 2 It is a schematic diagram of the architecture of the UAV group network security solution;
[0047] Figure 3 It is a schematic diagram of the structure of the data link;
[0048] Figure 4 It is a schematic diagram of the structure of a block in the data link;
[0049] Figure 5 It is a schematic diagram of the process of a new UAV joining the UAV group;
[0050] Figure 6 It is a schematic diagram of the process of a UAV leaving the UAV group. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0051] The present invention will be further described in detail below with reference to the accompanying drawings.
[0052] As Figure 1 shown, a secure communication method for an unmanned aerial vehicle (UAV) swarm based on blockchain includes a UAV key management center and a number of UAVs; the number of UAVs all serve as UAV nodes; the UAV key management center performs UAV node authentication on the UAVs through blockchain as a node authentication platform; after the UAV node authentication is completed, a number of UAV nodes compete to be the leading UAV node; then, the UAV group composed of a number of UAVs performs group key negotiation based on the group key negotiation protocol of blockchain to determine the final session group key of the group key negotiation; the UAV nodes in the UAV group realize data transmission between the UAV nodes and the rest of the UAV nodes through blockchain and the final session group key; when a UAV joins or leaves the UAV group, the session group key of the UAV group is updated in real time and dynamically.
[0053] AsFigure 2 As shown in the figure, in the system for secure communication of an unmanned aerial vehicle (UAV) swarm based on blockchain, it includes a blockchain layer, a network layer, and a communication layer with system layering; the blockchain layer adopts a consortium blockchain and smart contracts to achieve transaction storage, key generation, identity management, and data verification; the network layer adopts a consensus mechanism to achieve block synchronization; the communication layer uses a client and UAVs to achieve instruction sending and connection between nodes; in the interaction diagram, data verification storage, key calculation, node data synchronization and consistency are maintained, and data communication and terminal parameter passing are transmitted bidirectionally.
[0054] As Figure 3 shown in the figure, after each UAV node participates in the election for the leading UAV node, there is a probability of becoming the leader node and becoming the communication initiator, responsible for generating new block content, writing it into the blockchain and broadcasting it to the whole network, and the remaining UAV nodes participate in network consensus to synchronize the new block content. Among them, the network layer is composed of a data chain, which is jointly maintained by all UAV nodes within the UAV group. In one communication, the leading node interacts with the blockchain by sending transactions, and the remaining nodes synchronize the new block content through network consensus and maintain and update their local blockchain copies; the data chain is responsible for storing the acknowledgement information ACK generated by the message during each communication in the group and storing the acknowledgement information ACK in the blocks of the data chain to ensure the immutability and traceability of data reception; a communication security contract SMsecure is deployed on the data chain, and the target UAV decrypts the ciphertext after verifying the hash value. The data chain mainly adopts a chain structure, and by adding the number of messages, the ACK code generated by the message in the block header, in the data chain block body, not only the transaction records of each communication need to be stored, but also the ACK code needs to be stored; when performing communication queries, the communication content can be verified through the ACK code.
[0055] As Figure 4 shown in the figure, the block of the data chain includes a block header and a block body; due to the characteristics of fast node movement speed and strong real-time performance of the network during the communication of UAVs, the number of messages, ACK code, leading node UID, blockchain number, version number, previous block hash value, timestamp, and Merkle root are set in the data chain block header; the number of messages is the total number of messages recorded in the current block and increases continuously as the communication progresses; the ACK code is the identification number of the data chain, and transactions use it to find the corresponding target blockchain; the leading node UID is the blockchain UID of the leading UAV node of this block, that is, the message sender; the blockchain number is the identification number of the data chain, and transactions use it to find the corresponding target blockchain; the version number is the version of the blockchain protocol, used to distinguish different versions of the blockchain; the previous block hash value is the hash value of the previous block of this block, used to link different blocks in the blockchain; the timestamp is the time when the current block is generated; the Merkle root is the Merkle tree root hash value of all transactions in the current block, used to verify the integrity of the transactions.
[0056] Therefore, transactions in the data chain block body are used for data volume transactions. Transactions in the data chain are divided into genesis transactions; storage transactions: initiated by local devices, and every time information is sent, the communication content is sent to the blockchain for preservation through storage transactions; secure transactions: initiated by local devices. When verifying a certain communication, a verification transaction is sent, and the search and verification are carried out in the data chain according to the parameters in the transaction. The transaction format in the data chain contains five types: AimID, type, UID, time, and data; AimID, the target blockchain ID, is used by the drone node to select the target blockchain through this identifier. Type, the transaction type, uses 0, 1, 2 to represent different transaction types. For example, 0 is the genesis transaction, 1 is the storage transaction, and 2 is the secure transaction; UID, the sending node is the drone node that marks the sending of this transaction; Time, the timestamp is the time point when the transaction is sent; Data, the data is the data field, that is, the information carried by the transaction.
[0057] The UAV Key Management Center (UAV-KMC) is a semi-trusted entity that is responsible for providing partial private keys to UAVs; it is also responsible for system settings, trust management, and associating the real identities of UAVs with information; Unmanned Aerial Vehicles (UAVs) are the main participants in the system, and these entities participate in group key negotiation as group members; the blockchain is a decentralized, tamper-proof, and multi-party jointly maintained distributed database, which can effectively solve the problem of data trust; by maintaining a consortium chain between the UAV-KMC and the leader UAV node, a service for storing the legal secret information of UAVs is provided.
[0058] Let {U 1 ,U 2 ,...,U n} represent n UAVs in the execution of a certain task, and their identities are marked as UID = {UID 1 , UID 2 ,..., UID n}. This protocol adopts a ring structure, and the list is circularly defined as (U 1 , U 3 ,..., U n ) and U n+1 = U 1 . For any participating UAV node U i , it knows the order of other participants and its left neighbor node U i-1 and right neighbor node U i+1. The function of UAV node authentication is to provide identity authentication for UAVs, protect the identity information of UAVs from being leaked, and provide a trusted basis for subsequent group key negotiation and dynamic update phases; the UAV node authentication includes an initialization phase, a partial key generation phase, and an authentication phase;
[0059] In the initialization phase, the UAV key management center initializes the system parameters to generate its own public key P and private key s. The UAV key management center selects a large prime number p and defines a non-singular elliptic curve G on y 2 =x 3 +ax + b mod p, a cyclic group of prime order n on the non-singular elliptic curve G, with the generator g; the UAV key management center UAV-KMC randomly selects the private key s and calculates the public key P = sg, obtaining the public-private key pair (P, s) of the UAV key management center UAV-KMC;
[0060] H(x)=g x mod p;
[0061] In the formula, mod is the modulo operation, H(x) is the hash function, g is the generator, and p is the large prime number selected by the UAV key management center;
[0062] Each UAV node U i randomly selects a private key denoted as a i taking any integer value; and calculates the public key Q i =a i g. The UAV node U i sends the public key Q i of the UAV node U i and the identity identifier UID i of the UAV node to the UAV key management center UAV-KMC through the node authentication contract SMapprove; the identity identifier UID i of the UAV node i is generated in the blockchain network. i
[0063] In the partial key generation phase, after the UAV key management center UAV-KMC receives {UID i , Q i , Q i} of the UAV node U i , it calculates the partial private key d i and the partial public key Q' i corresponding to the partial private key; and combines the partial public-private key pair (Q′ i , d i , d i )Sent to the drone node U i ,
[0064] d i = s + b i mod p
[0065] Q' i = d i g
[0066] Wherein, s is the private key of the drone key management center, and b i is a random value, indicating that b i takes any integer value;; mod is the modulo operation; g is the generator; p is a large prime number selected by the drone key management center.
[0067] The drone node U i After receiving the partial public-private key pair (Q' i , d i ), calculates the complete public key P i ;;
[0068] P i = Q i '+ c i g
[0069] Wherein, c i is a randomly selected integer by the drone node U i to increase the randomness and security of the key; g is the generator;
[0070] The drone node U i Needs to initialize the drone complete public key list P = {P 1 , P 2 ,..., P i}. Only the partial public keys of the drones are stored in the blockchain. The complete public keys can be used within the drone group without directly exposing the real identities; the complete public keys are used for key exchange with other drone nodes to ensure the security of data communication; is the group negotiation identifier, ensuring anonymity; the obtained complete public key and private key pair (P i , d i ) are used for identity authentication. Before communicating with other nodes, the drone node needs to sign some authentication information with its own private key, and the other party uses the public key to verify the correctness of the signature; to protect anonymity, only partial public keys are stored in the blockchain, and the complete public keys are only maintained locally at the drone node. In this way, even if an attacker obtains the information on the blockchain, they cannot deduce the complete identity.
[0071] The UAV nodes within the UAV group maintain a group information list ML, which contains information such as identifiers, partial public keys, timestamps, etc.; ML maintains the information of all UAV nodes in the current group. If a new UAV joins or exits, ML needs to be updated accordingly; finally, when performing identity authentication and key negotiation, the UAV nodes will refer to ML to ensure that the communication objects belong to group members.
[0072] To ensure the initial security of the system, all UAVs need to be authenticated by UAV-KMC. After successful authentication through the node authentication contract SMapprove, the status information, identity information, and signature nodes of each UAV node are added to the node status management contract SMstatus, and the UAV node can participate in the subsequent operations of the network. In the authentication phase, the UAV node Ui randomly selects a temporary private key indicating that ri takes any integer value; and calculates the temporary public key R corresponding to the temporary private key i At the same time, the UAV node calculates the hash value h,
[0073] R i = r i g
[0074] h = H(R i ||T)
[0075] where R i is the temporary public key of the UAV node U i , || is the concatenation operator, T is the timestamp, h is the hash value, H is the hash function;
[0076] The digital signature of the message data i sent by the UAV node to the UAV key management center is σ i = (T, R i , h). The UAV node U i sends the information (data i , UID i , σ i ) to the UAV key management center UAV-KMC; after receiving the information (data i , UID i , σ i ), the UAV key management center UAV-KMC checks whether the timestamp T is valid. When the timestamp T is valid, the UAV key management center UAV-KMC calculates the verification temporary public key R' corresponding to the temporary private key of the UAV node U i ;
[0077] R' i = σ i ·g - a i ·Q i
[0078] σ i = r i + ha i
[0079] Wherein, a i is the private key of the UAV node U i and Q i is the public key of the UAV node U i and g is the generator; when R' i = R i then the UAV node U i is successfully authenticated.
[0080] In the dynamic group key negotiation, the generation and distribution of the group key are carried out after all UAV nodes are successfully authenticated; assume that m UAVs are successfully authenticated, where 1 ≤ m ≤ n. Group key negotiation is carried out within the UAV group composed of the several UAVs; each UAV U among the several UAVs randomly selects a negotiation temporary private key indicating that t i takes any integer value; and calculates the negotiation temporary public key T i , T i = t i g; uses a ring structure to calculate the shared key part K i between the UAV node U i1 and the adjacent UAV node and K i2 ;
[0081] K i1 = t i T i+1 mod p, K i2 = t i T i-1 mod p
[0082] Wherein, T i+1 and T i-1 are the negotiation temporary public keys of the right adjacent node and the left adjacent node respectively;
[0083] Send the obtained shared key parts Ki 1 and K i2 to both the right adjacent UAV node U i+1 and the left adjacent UAV node U i-1 ; The right adjacent UAV node U i+1 calculates the secret value S i1 and K i2 after receiving the keys K i+1 , and calculates the hash value H i+1 ;
[0084] S i+1 = K i1+K i2
[0085] H i+1 = H(S i+1 ||T)
[0086] Where T is the timestamp, H is the hash function, and || is the concatenation operator;
[0087] The left neighboring UAV node U i-1 Performs the same calculation process as the right neighboring UAV node U i+1 To obtain the secret value S i-1 Of the left neighboring UAV node U i-1 And the hash value H i-1 ; Each UAV node Ui obtains the corresponding secret value S i Which can be encrypted by the partial public key Q' i And transmitted to the leader UAV node; The leader UAV node then decrypts it using the partial public key Q' i According to the leader UAV node, based on the S corresponding to each UAV i Generate the member information list XL = {S 1 , S 2 ,..., S i}, And broadcast the tuple of the member information list XL to the remaining UAV nodes in the UAV group;
[0088] Each UAV node U i After receiving the member information list XL sent by the leader UAV node, starts to verify S i , The verification equation K i = H(S i ||T) to check if it holds, and calculates the shared key K i Corresponding to several S in the member information list; i When the equation holds, calculate the group key K session ; K session = ∑ i K i
[0089] Each UAV node sends the group key K session To the leader UAV node, and the leader UAV node verifies the received group key K session , The verification is that the group keys calculated by each UAV node should be the same; After successful verification, the leader UAV node broadcasts the group key K session As the final session group key for group key negotiation.
[0090] When data is transmitted within a drone group based on blockchain, the secure data transmission consists of the encryption of the data by drone A and the data decryption process of the target drone B. The transmission between any two drone nodes is the same as that between drone node A and drone node B. By encoding the communication data, illegal eavesdropping nodes are unable to interpret the information contained in the encoding, achieving the goal of allowing only the target node to interpret the information. When drone node A transmits data to drone node B based on blockchain, the following steps are included:
[0091] S1-1. Drone node A symmetrically encrypts the data code to be transmitted through the session group key to obtain the ciphertext E code ,
[0092] E code = AES(code, K session );
[0093] And calculate the hash value H code of the ciphertext E code , H code = H(E code ); Drone node A packs the ciphertext E code , the hash value H code and the timestamp T into a data packet Z,
[0094] Z = (E code , H code , T);
[0095] S1-2. Drone node A transmits the data packet Z to drone node B through the UID of the target drone. The drone node that receives the data packet Z records it in the blockchain to ensure the immutability and traceability of the data.
[0096] S1-3. After receiving the data packet Z, drone node B extracts the ciphertext E code and the hash value H code ;
[0097] (E code , H code ) = Blockchainget(Z);
[0098] Drone node B calculates and verifies the hash value H' code based on the ciphertext E code , H' code = H(E code ); When the hash value H code is consistent with the verification hash value H' code , drone node B decrypts the ciphertext E session through the session group key K code to obtain the original data code;
[0099] S1-4. The drone node B generates an acknowledgement message ACK based on the hash value H and timestamp T in the data packet Z, where ACK = (H, T); and broadcasts the acknowledgement message ACK to other drone nodes through the network. The drone nodes that receive the acknowledgement message ACK record it in the blockchain to ensure the immutability and traceability of data reception, thus completing a secure communication. code and timestamp T to generate an acknowledgement message ACK, ACK = (H code , T); and broadcasts the acknowledgement message ACK to other drone nodes through the network. The drone nodes that receive the acknowledgement message ACK record it in the blockchain to ensure the immutability and traceability of data reception, thus completing a secure communication.
[0100] As Figure 5 shown, during the group key update process, it is necessary to consider that when new drones apply to join the network, the group key needs to be updated to allow them to access system information. Secondly, when a drone is revoked, the group key needs to be updated to prevent the revoked drone from continuing to access network information. When new drones join a drone group composed of several drones, in the protocol, the newly joined drones do not need to be re-encrypted because during the dynamic update phase, the leader drone node stores information such as all drone node UIDs and keys in the blockchain. When a newly joined drone needs to obtain the information required to calculate the group key, it only needs to access the storage information component on the blockchain. Suppose m newly authenticated drones N u = {U n+1 ,..., U n+m} want to join the existing group O u = {U 1 ,..., U n}; the new drones are linked to the original group in a cyclic manner. It includes the following steps:
[0101] S2-1. The new drone node U n requests node authentication from the drone key management center and sends the public key Q n and the temporary public key R n of the drone node U n ; the drone node U n combines the public key Q n and the identity identifier UID n of the drone node U n to obtain {UID n , Q n} and the temporary public key R n ; n ;
[0102] S2-2. The drone key management center calculates the partial private key d n and the partial public key Q′ of the drone node U n based on the data sent by the drone node U n and the partial public key Q′n Send to the drone node U n and, based on the temporary public key R n of the drone node U n perform node authentication; the drone node U n calculate the complete public key P n according to the partial public key Q′ n ;
[0103] P n = Q′ n + c n g
[0104] where c n is a random integer selected by the drone node U n ;
[0105] S2-3. The drone node U n sends a group entry request to the leader drone node in the drone group, and the leader drone node sends a join request to all the original drone nodes; after receiving the request, all the original drone nodes feedback whether they agree. When the number of drone nodes that agree to the request exceeds half of all the original drone nodes, the leader drone node broadcasts a request for the drone node U n to join;
[0106] S2-4. The drone node U n randomly selects a negotiation temporary key t n , and calculates the negotiation temporary public key T n corresponding to the negotiation temporary key, T n = t n g; each original drone node U i calculates the shared key part K n with the drone node U in and K ni and transmits it to the leader drone node,
[0107] K in = t i T n mod p
[0108] K ni = t n T i mod p
[0109] where T n is the negotiation temporary public key of the drone node U n , T i is the negotiation temporary public key of the drone node Ui; t n is the drone node U nThe negotiated temporary private key, t i is for the drone node U i 's negotiated temporary private key;
[0110] The leading drone node calculates and broadcasts the updated session group key K based on the shared key part session ;
[0111] K session = ∑ i K i + K in + K ni mod p
[0112] In the formula, K in and K ni are the calculated parts with the shared key of the existing drone node U n and the new drone node U i respectively.
[0113] As Figure 6 shown, assume that {U 1 ,..., U n} is the current drone node set, and L = {U l1 ,..., U ln} is the set of members to be revoked. Then the set of remaining members at this time is expressed as A = {U a1 , U a2 ,..., U a(n-ln)} = U - L. When a drone leaves the drone group composed of several drones, the following steps are included:
[0114] S3-1. The drone node U L notifies the leading drone node that the drone node U L is about to leave; the leading drone node sends the information that the drone node U L leaves the group to all drone nodes;
[0115] S3-2. Other drone nodes U L in the drone group except the drone node U i all randomly select a new negotiated temporary private key t' i , calculate the new negotiated temporary public key T' i , T i ' = t' i g; and broadcast the new negotiated temporary private key t' i and the new negotiated temporary public key T' i to other drone nodes
[0116] S3-3. Each drone node U iCalculate the new shared key part with adjacent UAV nodes and transmit it to the leading UAV node;
[0117] K′ i1 = t′ i T′ i+1 mod p
[0118] K′ i2 = t′ i T i-1 mod p
[0119] Wherein, T′ i+1 and T' i-1 are the newly negotiated temporary public keys of the right adjacent node and the left adjacent node among the existing adjacent nodes respectively;
[0120] The leading UAV node calculates and broadcasts the updated session group key based on the new shared key part;
[0121] K′ session = ∑ i K i ′ mod p
[0122] Wherein, K′ i is the new shared key part calculated by the existing UAV node U i and K′ session is the updated session group key.
[0123] At the same time, in this scheme, in addition to the node authentication contract SMapprove, the node status management contract SMstatus, and the key communication security contract SMsecure, there is also a key negotiation contract SMconsult during key negotiation, and a key update contract SMrenew when keys are added and removed from UAV nodes; Since a consortium blockchain is adopted, in this design, the five smart contracts are written in the Go language respectively. After writing and testing, they can be directly deployed in the network. After being deployed in the Fabric network, transactions will automatically trigger the contract mechanism, and no more manual operation by managers is required. The form of each pseudocode is as follows:
[0124] The node authentication contract SMapprove is mainly responsible for registering and authenticating the nodes joining the network. The UAV key management center UAV-KMC registers the nodes and distributes part of the private keys to the nodes; The written code is as follows:
[0125]
[0126]
[0127] The key negotiation contract SMconsult negotiates and generates a group session key among multiple nodes, which is used to protect the communication security within the group and ensure that only group members can decrypt the communication content. The code written is as follows:
[0128]
[0129]
[0130] The key update contract SMrenew is responsible for managing the changes of group drones, such as new drones joining or existing drones leaving; and updating the group session key accordingly. The code written is as follows:
[0131]
[0132] The key communication security contract SMsecure ensures the communication security between drone nodes in the network. Through encryption and signature, it ensures that messages are not tampered with or forged during transmission, and only the intended recipients can decrypt the messages. The code written is as follows:
[0133]
[0134]
[0135] The node status management contract SMstatus is used to record and manage the status information of nodes in the network. Nodes can update their own status information, and other nodes can query this information;
[0136]
[0137] Embodiment
[0138] Suppose we have 10 drone nodes with node IDs UID = {UID 1 , UID 2 ,..., UID n}. Each node will register and authenticate according to the following steps. In the initialization phase, UAV-KMC selects a large prime number p as 23 and the generator g on the elliptic curve E as 5; UAV-KMC randomly selects the private key s = 3 and calculates the public key P = 3 * 5 = 15; each drone node randomly selects the private key and calculates the public key Q i = a i g. The drone node sends {UID i , Q i} to the drone key management center UAV-KMC;
[0139] Node ID <![CDATA[Private key a i > <![CDATA[Public key Q i > UID1 13 65 UID2 17 85 UID3 19 95 UID4 11 55 UID5 23 115 UID6 29 145 UID7 31 155 UID8 7 35 UID9 5 25 UID10 37 185
[0140] Partial key generation phase. UAV-KMC generates partial private keys for each UAV node; UAV-KMC sends the partial public and private key pairs (Q′ i , d i ) to the corresponding UAV node U i ;
[0141] Node ID <![CDATA[b i > <![CDATA[d i > <![CDATA[Q′ i > UID1 4 17 85 UID2 3 20 100 UID3 6 2 10 UID4 1 12 60 UID5 7 7 35 UID6 5 11 55 UID7 2 10 50 UID8 3 10 50 UID9 4 9 45 UID10 1 15 75
[0142] Each UAV node verifies whether the partial key Q′ i is valid, that is, checks whether Q′ = d i ·g holds. After successful verification, each UAV node aggregates the complete public and private key pairs (P i , d i );
[0143] Node ID <![CDATA[P i > <![CDATA[d i > UID1 105 17 UID2 115 20 UID3 40 2 UID4 70 12 UID5 70 7 UID6 80 11 UID7 60 10 UID8 65 10 UID9 65 9 UID10 80 15
[0144] Group key negotiation process for the UAV group. Taking 10 UAV nodes as an example; each UAV node generates a negotiation temporary key , verifies the keys of the left and right neighboring nodes, and sends the obtained keys K i1 and K i2 to the right neighboring node and the left neighboring node. Subsequently, start calculating S i , and the calculation results are shown in the following table:
[0145] Node ID <![CDATA[t i > <![CDATA[K i1 > <![CDATA[K i2 > <![CDATA[S i > UID1 17 918 850 1898 UID2 13 312 182 1602 UID3 19 950 684 972 UID4 11 154 660 1962 UID5 23 828 1012 784 UID6 21 1260 630 1756 UID7 16 704 928 2184 UID8 14 420 924 1892 UID9 22 1276 1188 1044 UID10 26 1716 624 2126
[0146] The leader UAV node collects all S i and forms and broadcasts the member information list XL:
[0147] XL = {1898, 1602, 972, 1962, 784, 1756, 2184, 1892, 1044, 2126}
[0148] Each UAV node U i calculates the session key K i = H 3 (S i ||T);
[0149] Node ID <![CDATA[K i > UID1 f53a74bc4eadd76609c10229d51ad4632c39c8a65e1802ad17e005c74cce7494 UID2 e2ec2220b7ef61264df3ee2df09487456f595638ac354631c9b5d46c6f67ebe5 UID3 7fbba83f57fa88724bd32ba19d9d3c7888ce5aa07b71cfdd41c774336b50830f UID4 a86a01bd4951e427bf71bd3a8c0b83cc7813a801b15201feaf81b39dd6421942 UID5 94c3b627e22675b93dec29decb0fe2df0a2f478ff5b16b521fe7b747a80a0eed UID6 4cdacb6c95d97c52e988b9c6e91420cff94ad394154d1b67a31c76b4fc7d350a UID7 288d07796e60480600ef5099be10fe06f623acf31856673e37a65e62a033b020 UID8 c6082c980a8d1fe00f3488e13b7d7c8c8030586aadd490396b2e7185b78eb37a UID9 6c44190f82d3c44daf441dd76fdab3665c37bfb3483ca034e72fdd20d9e59e41 UID10 df7d3547fecea083876de2b1750f5a12b5f865e23245151e2c19f8d369f15fcf
[0150] Then the final session group key is:
[0151] K session= 173e41d2147460e6cb4091d77fefa3a4256e62947fb94a3b47fcd1d839e59e6b。
[0152] During the key update process, if a new UAV node joins or an existing node leaves, the leader UAV node in the group needs to notify all members; subsequently, the new UAV node generates a negotiated temporary key pair, and by repeating the steps in the key negotiation process, exchanges the new negotiated temporary public key, calculates and confirms the new group session key; assuming a new UAV U11 joins, its leaving process is similar. The leader UAV node will first update the list XL and broadcast it to all UAV nodes. For example: when a new UAV U11 joins, the negotiated temporary keys and shared keys of all updated UAV nodes are shown in the following table:
[0153]
[0154]
[0155] The leader UAV node collects all S i and forms and broadcasts the member information list XL:
[0156] XL = {1532, 956, 972, 1962, 784, 1756, 2184, 1892, 836, 1876, 2566}
[0157] Each UAV node Ui calculates the session key K i = H 3 (S i ||T);
[0158] Node ID <![CDATA[K i > UID1 7bdf61d53d8c19238c2fde0a90690fb3cdecab4ba43722314ef7372e475fa2f7 UID2 30f5442fe0d8cbdcafa4dae15d072bf8bfcfa9e0bf2649fc3de246eac924375f UID3 7fbba83f57fa88724bd32ba19d9d3c7888ce5aa07b71cfdd41c774336b50830f UID4 a86a01bd4951e427bf71bd3a8c0b83cc7813a801b15201feaf81b39dd6421942 UID5 94c3b627e22675b93dec29decb0fe2df0a2f478ff5b16b521fe7b747a80a0eed UID6 4cdacb6c95d97c52e988b9c6e91420cff94ad394154d1b67a31c76b4fc7d350a UID7 288d07796e60480600ef5099be10fe06f623acf31856673e37a65e62a033b020 UID8 c6082c980a8d1fe00f3488e13b7d7c8c8030586aadd490396b2e7185b78eb37a UID9 7f721d7ae5e19e7a5f71e9aa43f07e9c2d32ca547914a850f3ca03f1a2b68793 UID10 b385ca17a3c09f18747f6021360cdc7983e65a1772084a9f86a27aea3670fb6e UID11 815fb730e4bfbc204c298c3cc9180a0e9830ce44a01902d4b7cda04a6cc8b7b6
[0159] Then the final group session key is:
[0160] K session = 5381a06518fba13b99c72feb05dcd9524db066fbe97dacfb0f31bdef904b54ef。
[0161] The above is only a description of the preferred embodiments of the present invention. Those of ordinary skill in the art, based on the above disclosure, make several modifications and optimizations without departing from the above basic principle content. These improvements and optimizations should be regarded as the protection scope understood by the present invention.
Claims
1. A secure communication method for drone swarms based on blockchain, characterized by: It includes a drone key management center and several drones; the several drones are used as drone nodes; the drone key management center uses blockchain as a node authentication platform to authenticate the drone nodes; after the drone node authentication is completed, several drone nodes compete for the leading drone node; then the drone group composed of several drones conducts group key negotiation based on the group key negotiation protocol of blockchain to determine the final session group key of the group key negotiation; The drone nodes in the drone group realize data transmission between the drone nodes and other drone nodes through blockchain and the final session group key; when a drone joins or leaves the drone group, the session group key of the drone group is updated in real time and dynamically.
2. According to claim 1, a blockchain-based secure communication method for drone swarms is characterized by: The drone node authentication includes an initialization phase, a partial key generation phase, and an authentication phase. In the initialization phase, the drone key management center initializes system parameters to generate its own public key P and private key s. The drone key management center selects a large prime number p and defines it in y 2 =x 3 +ax+bmodp non-singular elliptic curve G, a cyclic group of prime order n on the non-singular elliptic curve G, with generator g; The UAV-KMC randomly selects a private key s and calculates the public key P=sg, and obtains the public-private key pair of the UAV-KMC (P, s). H(x)=g x modp In the formula, mod is the modular operation, H(x) is the hash function, and g is the generator; Each drone node Ui randomly selects a private key And calculate the public key Q i =a i g, drone node U i Set the drone node U i The public key Q i and the UID of the drone node i Combined to get {UID i , Q i }Sent to the UAV Key Management Center UAV-KMC.
3. According to claim 2, a blockchain-based secure communication method for drone swarms is characterized by: In the partial key generation phase, the UAV key management center UAV-KMC receives {UID i , Q i }, calculate the partial private key d i And the partial public key Q′ corresponding to the partial private key i ; and transfer part of the private key d i and partial public key Q′ i The combined partial public-private key pair (Q′ i , d i ) is sent to the drone node U i , d i =s+b i modp Q i ′=d i g In the formula, s is the private key of the drone key management center, b i is a random value, mod is a modular operation, and g is a generator.
4. The secure communication method of a drone swarm based on blockchain according to claim 2, characterized in that: In the authentication phase, the drone node U i Randomly select a temporary private key And calculate the temporary public key R corresponding to the temporary private key i , the drone node simultaneously calculates the hash value h, R i =r i g h=H(R i |T) In the formula, || is the concatenation operator, T is the timestamp, h is the hash value, and H is the hash function; Message data sent by the drone node to the drone key management center i The digital signature of i =(T, R i ,h), UAV node U i Send information (data i , UID i , σ i ) to the drone key management center; The drone key management center receives the information (data i , UID i , σ i ), then check whether the timestamp T is valid. If the timestamp T is valid, the drone key management center calculates the drone node U i Verification temporary public key R′ corresponding to the temporary private key i ; R′ i =s i ·ga i ·Q i When R′ i =R i When i Authentication successful.
5. According to claim 3, a blockchain-based secure communication method for drone swarms is characterized by: The group key negotiation is performed within the drone group composed of the plurality of drones; each drone U among the plurality of drones randomly selects a temporary private key for negotiation The ring structure is used to calculate the shared key part K between the drone node Ui and the adjacent drone nodes i1 and K i2 ; K i1 =t i T i+1 modp,K i2 =t i T i-1 modp Where, T i+1 and T i-1 The right adjacent node and the left adjacent node negotiate the temporary public key respectively; The obtained shared key part K i1 and K i2 All are sent to the right neighboring drone node U i+1 and the left neighboring drone node U i-1 ; Right neighbor drone node U i+1 Receive the key K i1 and K i2 Then calculate the secret value S i+1 , and calculate the hash value H i+1 ; S i+1 =K i1 +K i2 H i+1 =H(S i+1 ||T) Left neighbor drone node U i-1 The calculation process and the right neighboring drone node U i+1 The same left neighboring drone node U is obtained i-1 The secret value S i-1 and hash value H i-1 ; Set each drone node U i Get the corresponding secret value S i Transmitted to the leading drone node; the leading drone node according to the S corresponding to each drone i Generate member information list XL = {S1, S2, ..., S i }, and broadcast the tuple to the rest of the drone nodes in the drone group; Each drone node U i After receiving the member information list XL sent by the leader drone node, it starts to i Verify and verify equation K i =H(S i ||T) is established; if the equation is established, the group key K is calculated session ; K session =∑ i K i Each drone node will use the group key K session Sent to the leader drone node, the leader drone node receives the group key K session After successful verification, the leading drone node broadcasts the group key K to all other drone nodes. session Serves as the final session group key for group key negotiation.
6. A blockchain-based secure communication method for drone swarms according to claim 5, characterized in that: When drone node A transmits data to drone node B based on blockchain, the following steps are included: S1-1, drone node A symmetrically encrypts the data code to be transmitted using the session group key to obtain the ciphertext E code , and calculate the ciphertext E code The hash value H code , drone node A will ciphertext E code 、Hash value H code and timestamp T are packaged into a data packet Z; S1-2, drone node A transmits data packet Z to drone node B via the UID of the target drone, and the drone node that receives data packet Z records it in the blockchain; S1-3, after receiving the data packet Z, the drone node B extracts the ciphertext E code and hash value H code , UAV node B is based on the ciphertext E code Calculate and verify the hash value H′ code ; When the hash value H code and verify the hash value H′ code When the agreement is reached, drone node B passes the session group key K session For ciphertext E code Decrypt to obtain the original data code; S1-4, drone node B based on the hash value H in data packet Z code The confirmation information ACK is generated based on the timestamp T, and the confirmation information ACK is broadcast to other drone nodes through the network. The drone nodes that receive the confirmation information ACK record it in the blockchain.
7. The secure communication method of a drone swarm based on blockchain according to claim 5, characterized in that: When a new drone joins a drone group consisting of several drones, the following steps are included: S2-1, New UAV Node U n Request node authentication from the drone key management center and send the drone node U n The public key Q n and the temporary public key R n ; S2-2, UAV key management center calculates UAV node U n Part of the private key d n and partial public key Q′ n Send to drone node U n In the UAV node U n The temporary public key R n Perform node authentication; S2-3, UAV node U n A request to join the group is sent to the leader drone node in the drone group, and the leader drone node sends a joining request to all the original drone nodes; when the number of drone nodes that agree to the request exceeds half of all the original drone nodes, the leader drone node broadcasts the agreement to all drone nodes. n Request to join; S2-4, UAV node U n Randomly select a negotiated temporary key t n , and calculate the negotiated temporary public key T corresponding to the negotiated temporary key n ; Each original drone node U i The average calculation is the same as the UAV node U n The shared key part K in and K ni And transmit it to the leader drone node, which calculates and broadcasts the updated session group key based on the shared key part.
8. The secure communication method of a drone swarm based on blockchain according to claim 5, characterized in that: When a drone leaves a drone group consisting of several drones, the following steps are included: S3-1, UAV node U L Notify the leader UAV node, UAV node U L About to leave; the leader drone node sends drone node U to all drone nodes L Information about leaving the group; S3-2, except for drone node U in the drone group L Other drone nodes U i A new negotiated temporary private key t′ is randomly selected i , calculate the new negotiated temporary public key T′ i ; and the new negotiated temporary private key t′ i and the new negotiated temporary public key T′ i Broadcast to other drone nodes; S3-3. Each drone node U i Each drone node calculates a new shared key part with the adjacent drone nodes and transmits it to the leading drone node. The leading drone node calculates and broadcasts the updated session group key based on the new shared key part.