Secure communication method, system and device between unmanned aerial vehicle and ground station, and readable medium

By deploying non-cloneable functions (PUFs) on drones and ground stations, secure communication between drones and ground stations is achieved, and the problem that drone communication is vulnerable to physical theft attacks is solved, ensuring high security and efficiency of communication.

CN120111484APending Publication Date: 2025-06-06JIAXING UNIV
View PDF 0 Cites 3 Cited by

Patent Information

Application Number
CN202311604850.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-28
Publication Date
2025-06-06

AI Technical Summary

Technical Problem

Communication between drones and ground stations is vulnerable to physical theft attacks. The existing authentication and key negotiation methods rely on trusted third parties and cannot be applied to the distribution structure of the drone Internet.

Method used

The non-clone function (PUF) is used to deploy on the drone and the ground station. Through the process of system initialization, ground station and drone registration, authentication, key negotiation and parameter update, secure communication between the drone and the ground station is achieved. This method does not rely on trusted third parties and leverages the unique properties of PUF to resist physical attacks.

Benefits of technology

Effectively resist physical theft attacks, ensure the security of communication between drones and ground stations, achieve efficient and secure communication, and reduce computing and communication overhead.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120111484A_ABST
    Figure CN120111484A_ABST
Patent Text Reader

Abstract

The invention relates to a secure communication method, system and device between an unmanned aerial vehicle and a ground station, and a readable medium. The method comprises the following steps: a control center generates and issues public parameters for safety communication of a system; registering the ground station and the unmanned aerial vehicle; the ground station and the unmanned aerial vehicle respectively send respective real identities to the control center; receiving and storing safety parameters and challenge sets which are respectively sent to the ground station and the unmanned aerial vehicle by the control center; randomly selecting a challenge from the received challenge set, and generating a registration parameter in combination with the public parameter; the ground station and the unmanned aerial vehicle generate mutually sent authentication information by using respective registration parameters to perform mutual authentication, and a session key special for secure communication is established between the ground station and the unmanned aerial vehicle after the authentication succeeds; and after authentication and key negotiation are successfully completed, the ground station and the unmanned aerial vehicle reselect challenges from respective stored challenge sets, and update authentication parameters. According to the invention, secure communication between the unmanned aerial vehicle and the ground station is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer network communication security, and more particularly to a method, system, device and readable medium for secure communication between an unmanned aerial vehicle and a ground station. Background Art

[0002] With the rapid development of aviation technology in recent years, unmanned aerial vehicles (UAV), commonly known as drones, are becoming the focus of public attention. At present, drones have been used in many fields, including but not limited to natural disaster medical surveillance, traffic monitoring, military operations, item delivery, task sharing, etc. As drones are gradually integrated into the Internet of Things, the Internet of Drones (IoD) has also emerged. Although drone technology and applications have developed rapidly, their reliance on wireless channels for communication makes them vulnerable to a variety of active attack methods such as replay attacks, man-in-the-middle attacks, and tampering attacks. Attackers can use these vulnerabilities to obtain sensitive information (such as location, flight mode, etc.), interfere with normal operations, or even maliciously interfere with or destroy data, resulting in serious negative effects. For example, in a military surveillance scenario, an enemy drone impersonates a legitimate drone and authenticates it to a ground station, thereby obtaining confidential information about the legitimate drone or sending malicious information to the ground station, which may cause serious interruptions in monitoring services and cause significant economic and personnel losses. Therefore, the communication security between drones and ground stations is crucial. To solve this problem, Authentication and Key Agreement (AKA) has become a reliable secure communication method that can be used to ensure the confidentiality and integrity of information exchange between drones and ground stations. However, the security of existing authentication and key agreement methods is based on an assumption that secrets stored in the device exist for a long time and cannot be obtained by malicious attackers. However, in actual situations, attackers can still steal secrets stored on the device through physical attacks, such as side channel attacks, posing a serious threat to communication security. How to defend against such physical theft attacks has become a major challenge at present.

[0003] In recent years, PUF has been widely used in various authentication and key agreement methods to ensure the physical security of devices. The Physical Unclonable Function (PUF) was first proposed in 2002 to prevent physical attacks on hardware. PUF usually receives a challenge string and generates a response string to form a unique mapping of challenge-response pairs (CRP). The implementation of PUF is based on the randomness of the integrated circuit (IC) manufacturing process, so it cannot be cloned even if the same industrial design is used. In addition, changes in the physical state of the integrated circuit will affect the response of the PUF, and any physical attack may cause it to behave abnormally. Therefore, the same challenge input always produces a fixed response, but once it is physically tampered with, the response will change. These characteristics of PUF make it widely used in ensuring the physical security of devices with limited resources. However, these methods are mainly applicable to devices such as smart meters in fixed locations, and cannot be directly applied to the drone Internet. Specifically, these methods rely on the existence of a trusted third party, requiring the trusted third party to store a subset of the device's challenge-response pairs when the device joins the system. The device then receives one or more challenge streams and is considered a trusted device if its response matches the value stored by the trusted third party. However, due to the high mobility of drones and the distributed structure of the drone Internet, it is not suitable for drone-to-ground station communications to rely on trusted third parties for intermediary authentication. Given the high mobility of drones and the managed structure of the drone Internet, secure communications between drones and ground stations should not rely on trusted third parties. Summary of the invention

[0004] In view of the above analysis, the present invention aims to disclose a secure communication method, system, device and readable medium between a drone and a ground station to achieve secure communication between the drone and the ground station, so as to cope with the unique challenges in the field of drone communications and ensure the high security of communication.

[0005] The present invention discloses a secure communication method between an unmanned aerial vehicle and a ground station, comprising:

[0006] System initialization: Based on the preset security parameters, the control center generates and publishes the public parameters for the system to communicate securely;

[0007] The ground station and the drone register; the ground station and the drone send their real identities to the control center respectively; receive and store the security parameters and challenge sets sent by the control center to the ground station and the drone respectively; and randomly select a challenge from the received challenge set, and generate registration parameters in combination with the public parameters;

[0008] Authentication and key negotiation: The ground station and the drone use their respective registration parameters to generate authentication information to be sent to each other for mutual authentication. After successful authentication, a session key dedicated to secure communication is established between the ground station and the drone.

[0009] Parameter update: After successfully completing authentication and key negotiation, the ground station and the drone reselect challenges from their respective stored challenge sets and update the authentication parameters for the next authentication and key negotiation.

[0010] Further, the system initialization includes:

[0011] Given a security parameter λ, the control center selects an elliptic curve G and a generator P, where the order of the elliptic curve is q;

[0012] The control center randomly selects a non-zero element As the master secret key; calculate the master public key P pub =s·P;

[0013] The control center introduces a hash function H: This hash function maps an input of any length to Elements for data summary and verification;

[0014] The control center generates the public parameters {G,P,P pub ,H} is published to the UAVs and ground stations participating in the communication.

[0015] Furthermore, the ground station registration process includes:

[0016] 1) The ground station sends its real identity Register at the control center;

[0017] 2) The control center uses the ground station's real ID j Generate security parameters and challenge set of the ground station and send them to the ground station;

[0018] Among the security parameters of the ground station,

[0019] The first safety parameter is the common point Y j =y j P; where the random number A random number selected for the control center;

[0020] The second safety parameter is η j =H(P pub )·y j +H(ID j ||Y j )·s(mod)q;

[0021] The challenge set of the ground station generated by the control center is {C j,v} v=1,2,…n ;

[0022] 3) The ground station calculates the PUF response of the ground station challenge and the hash value of the PUF response based on the received security parameters and challenge set;

[0023] PUF response R to the ground station challenge j,b =PUF(C j,b );C j,b For the challenge set {C j,v}v= 1,2,…n A challenge randomly selected from

[0024] PUF response hash value tem j,b =H(R j,b );

[0025] 4) The ground station uses the hash value of the PUF response and the second security parameter η j Calculate the ground station authentication parameter e j ;

[0026] Ground station registration parameters

[0027] 5) The ground station registration is completed and the received challenge set is stored {C j,v} v=1,2,…n , register parameter e j and the challenge of choosing C j,b The corresponding storage is {e j , C j,b}, the common point Y j Published for use by other communicating entities during authentication and key negotiation.

[0028] Further, the drone registration process includes:

[0029] 1) The drone sends its true identity Register at the control center;

[0030] 2) The control center uses the real ID of the drone i Generate the safety parameters and challenge set of the drone and send them to the drone;

[0031] Among the safety parameters of the drone,

[0032] The first safety parameter is the common point X i =x i P; where the random number A random number selected for the control center;

[0033] The second safety parameter is η i =H(P pub )·x i +H(X i )·s(mod)q;

[0034] The challenge set for drones is {C i,u} u=1,2,…n ;

[0035] 3) The drone calculates the PUF response of the drone challenge and the hash value of the PUF response based on the received security parameters and challenge set;

[0036] PUF response to drone challenge R i,a =PUF(C i,a );C i,a For the challenge set {C i,u} u=1,2,…n A challenge randomly selected from

[0037] PUF response hash value tem i,a =H(R i,a );

[0038] 4) The drone uses the hash value of the PUF response and the second security parameter η i Calculate the ground station authentication parameter e i ;

[0039] Drone registration parameters

[0040] 5) Drone registration is complete, and the received challenge set is stored {C i,u} u=1,2,…n , register parameter e i and the challenge of choosing C i,a The corresponding storage is {e i , C i,a}, the common point X i Published for use by other communicating entities during authentication and key negotiation.

[0041] Furthermore, the authentication and key negotiation process includes:

[0042] 1) The ground station will generate the first negotiation parameter {ID j , T j , A j}Broadcast to surrounding drones;

[0043] Among them, ID j is the true identity of the ground station; T j A timestamp generated for the ground station;

[0044] Parameter A j =H(ID j ||Y j ||R j,v ||r j ||T j )·P; where Y j is the common point of the ground station, R j,v For ground stations from the challenge set {C j,v} v=1,2,…n A challenge C is randomly selected from j,v Calculated PUF response Generate a random number for the ground station; P is the generator of the elliptic function;

[0045] 2) The drone receives the first negotiation parameter {ID j , T j , A j} and then timestamp T j If the validity is checked, the second negotiation parameter {PID i , A i , ρ i , T i}Send to ground station;

[0046] Among them, the drone’s pseudonym

[0047] Parameter A i =H(r i ||T i ||R i,u )·P;ID i For the true identity of the drone, Generate a random number for the drone; T i A timestamp generated for the drone; R i,u For drones from the challenge collection {C j,u} u=1,2,…n A challenge C is randomly selected from j,u Calculated PUF response R j,u =PUF(C j,u );P pub is the master public key;

[0048] Parameter ρ i =H(PID i ||X i ||A i ||B i ||T i ||T j ), where B i =η i ·A j, η i is the registration parameter stored from the drone i Obtained

[0049] 3) The ground station receives the second negotiation parameter {PID i , A i , ρ i , T i} and then timestamp T i The validity check is done, if it is valid, a parameter ρ is generated j For parameter ρ i To verify, if ρ i =ρ j Then calculate the session key k ji ;

[0050] Among them, ρ j =H(PID i ||X i ||A i ||B j ||T i ||T j );B j =H(ID j ||Y i ||R′ j,v ||r i ||T j )·(H(P pub )·X i +H(X i )·P pub ); from the challenge set {C j,v} v=1,2,…n A challenge C is randomly selected from j,v Calculated PUF response R′ j,v =PUF(C j,v );

[0051] Session key k ji =H(ω j ||B j ||ID j ||PID i );ω j =η j ·A i ; tem j,b =H(R j,b );R j,b =PUF(C j,b );

[0052] 4) The ground station sends the third negotiation parameter to the drone

[0053] in, T′ j Generate a timestamp for the ground station;

[0054] 5) The drone receives the third negotiation parameter Then timestamp T′ j If the validity is checked, the session key kij and parameters are generated.

[0055] Among them, k ij =H(ω i ||B i ||ID j ||PID i );

[0056]

[0057] ω i =H(R′ i,u ||r i ||T i )·(H(P pub )·Y j +H(Y j ||ID j )·P pub );

[0058] R′ i,u =PUF(C i,u );

[0059] 6) Drone inspection If they are equal, the mutual authentication between the drone and the ground station is completed, and a session key k is successfully established. ij (k ji ) for secure communications.

[0060] Furthermore, the drone parameter update process includes:

[0061] 1) The drone is selected from the stored challenge set {C i,u} u=1,2,…n Randomly select a challenge C′ i,a , calculate the PUF response of the challenge and the hash value of the PUF response;

[0062] Challenge C′ i,a The PUF response R′ i,a =PUF(C′ i,a ), PUF response R′ i,a The hash value of tem′ i,a =H(R′ i,a );

[0063] 2) The drone uses the hash value tem′ of the PUF response i,a and the second safety parameter η of the drone i Calculate the authentication parameter e′ for the updated ground station i ;

[0064] Updated ground station authentication parameters

[0065] 3) The drone will store the previously stored parameters {e i , C i,a} is updated to the parameter {e′ i , C′ i,a}, store it, and set the challenge {C i,u} u=1,2,…n Challenge C used before i,u and C i,a delete.

[0066] Furthermore, the ground station parameter update process includes:

[0067] 1) The ground station obtains the challenge set {C j,v} u=1,2,…n Randomly select a challenge C′ j,b , calculate the PUF response of the challenge and the hash value of the PUF response;

[0068] Challenge C′ j,b The PUF response R′ j,b =PUF(C′ j,b ), PUF response R′ j,b The hash value of tem′ j,b =H(R′ j,b );

[0069] 2) The ground station uses the hash value tem′ of the PUF response j,b and the second safety parameter η of the ground station j Calculate the authentication parameter e′ for the updated ground station j ;

[0070] Updated ground station authentication parameters

[0071] 3) The drone will store the previously stored parameters {e j , C j,b} is updated to the parameter {e′ j , C′ j,b}, store it, and set the challenge {C j,v} u=1,2,…n Challenge C used before j,v and Cj,b delete.

[0072] The present invention also discloses a secure communication system between a UAV and a ground station, comprising a control center, a ground station and a UAV;

[0073] The secure communication system adopts the secure communication method between the UAV and the ground station as described above to achieve system initialization, ground station and UAV registration, authentication and key negotiation, and parameter update.

[0074] The present invention also discloses an electronic device, comprising:

[0075] one or more processors;

[0076] A storage device for storing one or more programs;

[0077] When the one or more programs are executed by the one or more processors, the one or more processors implement the secure communication method between the drone and the ground station as described above.

[0078] The present invention also discloses a computer-readable medium on which a computer program is stored. When the program is executed by a processor, the secure communication method between the UAV and the ground station as described above is implemented.

[0079] The present invention can achieve one of the following beneficial effects:

[0080] While realizing mutual authentication and key negotiation between the UAV and the ground station, the present invention effectively copes with the threat of physical theft attacks by deploying unclonable functions on the UAV and the ground station. Different from the existing unclonable function-based method, the control center (trusted third party) of this method only assists when the UAV and the ground station register, and the authentication and key negotiation process no longer involves the participation of the control center (trusted third party).

[0081] During the authentication and key negotiation process, the drone will generate two responses, both of which are responses to the same challenge. By implicitly matching these two responses, if the match is successful, it means that the authentication and key negotiation process is not affected by physical attacks. Once the drone is physically attacked, the behavior of the unclonable function will be changed, resulting in the failure of implicit matching between the two responses. The same method can also be used to determine whether the ground station is physically attacked during the authentication and key negotiation process.

[0082] Moreover, the method of the present invention also provides conditional privacy protection by introducing a pseudonym mechanism, achieving the anonymity of legitimate drones and the tracking capability of malicious drones; compared with related methods, the method of the present invention can resist a variety of common attacks, including physical cloning attacks, imitation attacks, man-in-the-middle attacks, replay attacks, known session key attacks, and temporary secret leakage attacks. In addition, the method of the present invention also has significant advantages in terms of computing and communication overhead. Through these innovations, efficient and secure communication between drones and ground stations is achieved. BRIEF DESCRIPTION OF THE DRAWINGS

[0083] The accompanying drawings are only used for the purpose of illustrating specific embodiments and are not to be considered as limiting the present invention. In the entire drawings, the same reference symbols represent the same components;

[0084] Figure 1 The figure is a flow chart of a secure communication method between a UAV and a ground station in an embodiment of the present invention. DETAILED DESCRIPTION

[0085] The preferred embodiments of the present invention will be described in detail below in conjunction with the accompanying drawings, wherein the accompanying drawings constitute a part of this application and are used to illustrate the principles of the present invention together with the embodiments of the present invention.

[0086] Embodiment 1

[0087] One embodiment of the present invention discloses a secure communication method between a drone and a ground station, such as Figure 1 As shown, including:

[0088] Step S1, system initialization; based on the preset security parameters, the control center (Control Authority, CA) generates and publishes public parameters for the system to conduct secure communication;

[0089] Step S2, ground station (GS) and unmanned aerial vehicle (UAV) registration; the ground station and the unmanned aerial vehicle send their real identity to the control center respectively; receive and store the security parameters and challenge sets sent by the control center to the ground station and the unmanned aerial vehicle respectively; and randomly select a challenge from the received challenge set, and generate registration parameters in combination with the public parameters;

[0090] Step S3, authentication and key negotiation: The ground station and the UAV use their respective registration parameters to generate authentication information to be sent to each other for mutual authentication. After successful authentication, a session key dedicated to secure communication is established between the ground station and the UAV.

[0091] Step S4, parameter update: After successfully completing the authentication and key negotiation, the ground station and the UAV reselect challenges from their respective stored challenge sets and update the authentication parameters for the next authentication and key negotiation.

[0092] Specifically, in step S1, the system initialization includes:

[0093] 1) Given a security parameter λ, the control center selects an elliptic curve G and a generator P, where the order of the elliptic curve is q; these parameters will be used in the subsequent key generation and authentication process)

[0094] 2) The control center randomly selects a non-zero element As the master secret key; calculate the master public key P pub =s·P; this ensures the mathematical relationship between the master secret key and the master public key.

[0095] 3) The control center introduces a hash function H: This hash function maps an input of any length to Elements for data summary and verification;

[0096] 4) The control center generates the public parameters {G, P, P pub ,H} is published to the UAVs and ground stations participating in the communication.

[0097] These public parameters are used in subsequent registration, authentication, and key negotiation steps to ensure the security and reliability of communications.

[0098] Specifically, the ground station registration process in step S2 includes:

[0099] 1) The ground station sends its real identity Register at the control center;

[0100] 2) The control center uses the ground station's real ID j Generate the security parameters of the ground station {Y j ,η j} and challenge set, sent to the ground station;

[0101] Among the security parameters of the ground station,

[0102] The first safety parameter is the common point Y j =y j P; where the random number A random number selected for the control center;

[0103] The second safety parameter is η j =H(P pub )·yj +H(ID j ||Y j )·s(mod)q;

[0104] The challenge set of the ground station generated by the control center is {C j,v} v=1,2,…n ;

[0105] The calculation process of the first and second security parameters of the ground station ensures that the generated parameters are closely related to the master secret key, master public key and hash function of the control center.

[0106] 3) The ground station receives the security parameters {Y j ,η j} and the challenge set to calculate the PUF response of the ground station challenge and the hash value of the PUF response;

[0107] PUF response R to the ground station challenge j,b =PUF(C j,b );C j,b For the challenge set {C j,v} v=1,2,…n A challenge randomly selected from

[0108] PUF response hash value tem j,b =H(R j,b );

[0109] 4) The ground station uses the hash value of the PUF response and the second security parameter η j Calculate the ground station authentication parameter e j ;

[0110] Ground station registration parameters

[0111] 5) The ground station registration is completed and the received challenge set is stored {C j,v} v=1,2,…n , register parameter e j and the challenge of choosing C j,b The corresponding storage is {e j , C j,b}, the common point Y j Published for use by other communicating entities during authentication and key negotiation.

[0112] Specifically, the registration process of the drone in step S2 includes:

[0113] 1) The drone sends its true identity Register at the control center;

[0114] 2) The control center uses the real ID of the drone iGenerate the safety parameters of the drone {X i , η i} and challenge collection, sent to the drone;

[0115] Among the safety parameters of the drone,

[0116] The first safety parameter is the common point X i =x i P; where the random number A random number selected for the control center;

[0117] The second safety parameter is η i =H(P pub )·x i +H(X i )·s(mod)q;

[0118] The challenge set for drones is {C i,u} u=1,2,…n ;

[0119] The calculation process of the first and second security parameters of the drone ensures that the generated parameters are closely related to the master secret key, master public key and hash function of the control center.

[0120] 3) The drone receives the safety parameters {X i , η i} and the challenge set to calculate the PUF response of the drone challenge and the hash value of the PUF response;

[0121] PUF response to drone challenge R i,a =PUF(C i,a );C i,a For the challenge set {C i,u} u=1,2,…n A challenge randomly selected from

[0122] PUF response hash value tem i,a =H(R i,a );

[0123] 4) The drone uses the hash value of the PUF response and the second security parameter η i Calculate the ground station authentication parameter e i ;

[0124] Drone registration parameters

[0125] 5) Drone registration is complete, and the received challenge set is stored {C i,u} u=1,2,…n , register parameter e i and the challenge of choosing C i,a The corresponding storage is {ei , C i,a}, the common point X i Published for use by other communicating entities during authentication and key negotiation.

[0126] In the solution of this embodiment, the public parameters sent by the control center include only one hash function, and the public parameters are simpler. In addition, the control center only assists in the registration process, and the authentication and key negotiation process no longer involves the participation of the control center (trusted third party), thereby enhancing the confidentiality of communication.

[0127] Specifically, the authentication and key negotiation process in step S3 includes:

[0128] 1) The ground station will generate the first negotiation parameter {ID j , T j , A j}Broadcast to surrounding drones;

[0129] The first negotiation parameter {ID j , T j , A j The generation process of} includes:

[0130] (1) The ground station generates a random number and a timestamp T j ;

[0131] (2) The ground station is from the challenge set {C j,v} v=1,2,…n A challenge C is randomly selected from j,v Calculated PUF response R j,v =PUF(C j,v );

[0132] (3) Ground station calculation parameter A j =H(ID j ||Y j ||R j,v ||r j ||T j )·P

[0133] Among them, ID j is the true identity of the ground station; Y j is the common point of the ground station, P is the generator of the elliptic function in the common parameters;

[0134] (4) The first negotiation parameter {ID j , T j , A j} for broadcasting.

[0135] 2) The drone receives the first negotiation parameter {IDj , T j , A j} and then timestamp T j If the validity is checked, the second negotiation parameter {PID i , A i , ρ i , T i}Send to ground station;

[0136] The second negotiation parameter {PID i , A i , ρ i , T i The generation process of} includes:

[0137] (1) The drone generates a random number and a timestamp T i ;

[0138] (2) UAVs from the challenge set {C j,u} u=1,2,…n A challenge C is randomly selected from j,u Calculated PUF response R j,u =PUF(C j,u );

[0139] (3) Generate drone calculation pseudonym PID i and parameter A i ;

[0140] Among them, the drone’s pseudonym

[0141] Parameter A i =H(r i ||T i ||R i,u )·P;ID i For the true identity of the drone, P pub is the master public key in the public parameters;

[0142] (4) Generate parameter ρ i

[0143] Parameter ρ i =H(PID i ||X i ||A i ||B i ||T i ||T j ), where B i =η i ·A j , η i is the registration parameter stored from the drone iObtained

[0144] (5) The second negotiation parameter {PID i , A i , ρ i , T i}Sent to the ground station.

[0145] 3) The ground station receives the second negotiation parameter {PID i , A i , ρ i , T i} and then timestamp T i The validity check is done, and if it is valid, a parameter ρ is generated. j For parameter ρ i To verify, if ρ i =ρ j Then calculate the session key k ji ;

[0146] Specifically include:

[0147] (1) Perform timestamp T i Validity check; if valid, proceed to the next step;

[0148] (2) Calculate the verification parameter ρ j

[0149] The ground station is stored in the challenge set {C j,v} v=1,2,…n Randomly select a challenge C j,v , calculate the PUF response R′ of the challenge j,v =PUF(C j,v );

[0150] Calculate hash value B j =H(ID j ||Y i ||R′ j,v ||r i ||T j )·(H(P pub )·X i +H(X i )·P pub );

[0151] Calculate the verification parameter ρ j =H(PID i ||X i ||A i ||B j ||T i ||T j );

[0152] (3) Determine ρ i =ρ j Is it true? If it is true, calculate the session key k ji

[0153] Session key k ji =H(ω j ||B j ||ID j ||PID i );ω j =η j ·A i ; tem j,b =H(R j,b );R j,b =PUF(C j,b );

[0154] 4) The ground station sends the third negotiation parameter to the drone

[0155] Specifically include:

[0156] (1) The ground station generates a timestamp T′ j ;

[0157] (2) Generate parameters

[0158] in,

[0159] (3) Third Negotiation Parameter Send to drone.

[0160] 5) The drone receives the third negotiation parameter Then timestamp T′ j The validity check is performed, and if it is valid, the session key k is generated. ij and parameters

[0161] Specifically include:

[0162] (1) Perform timestamp T′ j Validity check; if valid, proceed to the next step;

[0163] (2) Calculation of R′ i,u =PUF(C i,u );

[0164] (3) Calculation parameter ω i =H(R′ i,u ||r i ||T i )·(H(P pub )·Yj +H(Y j ||ID j )·P pub );

[0165] (4) Calculate the session key k ij =H(ω i ||B i ||ID j ||PID i );

[0166] parameter

[0167] 6) Drone inspection If they are equal, the mutual authentication between the drone and the ground station is completed, and a session key k is successfully established. ij (k ji ) for secure communications.

[0168] In the authentication and key negotiation process of this embodiment, the drone generates two responses to the first negotiation parameter and the third negotiation parameter respectively; both responses are responses to the same challenge; by implicitly matching these two responses, if the match is successful, it indicates that the authentication and key negotiation process is not affected by physical attacks. Once the drone is subjected to a physical attack, the behavior of the unclonable function will be changed, resulting in the failure of implicit matching between the two responses, thus improving the security of communication.

[0169] Specifically, the drone parameter update process in step S4 includes:

[0170] 1) The drone is selected from the stored challenge set {C i,u} u=1,2,...n Randomly select a challenge C′ i,a , calculate the PUF response of the challenge and the hash value of the PUF response;

[0171] Challenge C′ i,a The PUF response R′ i,a =PUF(C′ i,a ), PUF response R′ i,a The hash value of tem′ i,a =H(R′ i,a );

[0172] 2) The drone uses the hash value tem′ of the PUF response i,a and the second safety parameter η of the drone i Calculate the authentication parameter e′ for the updated ground station i ;

[0173] Updated ground station authentication parameters

[0174] 3) The drone will store the previously stored parameters {e i , C i,a} is updated to the parameter {e′ i , C′ i,a}, store it, and set the challenge {C i,u} u=1,2,…n Challenge C used before i, u and C i, aDelete.

[0175] Specifically, the ground station parameter updating process in step S4 includes:

[0176] 1) The ground station obtains the challenge set {C j,v} u=1,2,…n Randomly select a challenge C′ j,b , calculate the PUF response of the challenge and the hash value of the PUF response;

[0177] Challenge C′ j,b The PUF response R′ j,b =PUF(C′ j,b ), PUF response R′ j,b The hash value of tem′ j,b =H(R′ j,b );

[0178] 2) The ground station uses the hash value tem′ of the PUF response j,b and the second safety parameter η of the ground station j Calculate the authentication parameter e′ for the updated ground station j ;

[0179] Updated ground station authentication parameters

[0180] 3) The drone will store the previously stored parameters {e j , C j,b} is updated to the parameter {e′ j , C′ j,b}, store it, and set the challenge {C j,v} u=1,2,…n Challenge C used before j,v and C j,b delete.

[0181] Furthermore, before using all the challenges of the physical unclonable function, the drone and the ground station need to request a new set of challenges from the control center. This ensures the security and sustainability of the system.

[0182] In summary, the method of the embodiment of the present invention not only realizes mutual authentication and key negotiation between the UAV and the ground station, but also effectively responds to the threat of physical theft attacks by deploying unclonable functions on the UAV and the ground station. Different from the existing method based on unclonable functions, the control center (trusted third party) of this method only assists when the UAV and the ground station register, and the authentication and key negotiation process no longer involves the participation of the control center (trusted third party).

[0183] During the authentication and key negotiation process, the drone will generate two responses, both of which are responses to the same challenge. By implicitly matching these two responses, if the match is successful, it means that the authentication and key negotiation process is not affected by physical attacks. Once the drone is physically attacked, the behavior of the unclonable function will be changed, resulting in the failure of implicit matching between the two responses. The same method can also be used to determine whether the ground station is physically attacked during the authentication and key negotiation process.

[0184] Moreover, the method of the present invention also provides conditional privacy protection by introducing a pseudonym mechanism, achieving the anonymity of legitimate drones and the tracking capability of malicious drones; compared with related methods, the method of the present invention can resist a variety of common attacks, including physical cloning attacks, imitation attacks, man-in-the-middle attacks, replay attacks, known session key attacks, and temporary secret leakage attacks. In addition, the method of the present invention also has significant advantages in terms of computing and communication overhead. Through these innovations, efficient and secure communication between drones and ground stations is achieved.

[0185] Embodiment 2

[0186] One embodiment of the present invention provides a secure communication system between a drone and a ground station, including a control center, a ground station, and a drone;

[0187] The secure communication system adopts the secure communication method between the UAV and the ground station described in Example 1 to achieve system initialization, ground station and UAV registration, authentication and key negotiation, and parameter update.

[0188] The remaining specific technical details and beneficial effects of this embodiment are the same as those in Embodiment 1. Please refer to them for details and will not be described in detail here.

[0189] Embodiment 3

[0190] An embodiment of the present invention provides an electronic device; the electronic device includes:

[0191] one or more processors;

[0192] A storage device for storing one or more programs;

[0193] When the one or more programs are executed by the one or more processors, the one or more processors implement the secure communication method between the drone and the ground station as described in Embodiment 1.

[0194] Embodiment 4

[0195] The embodiment of the present disclosure provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the secure communication method between the drone and the ground station described in Embodiment 1 are executed. The storage medium may be a volatile or non-volatile computer-readable storage medium.

[0196] The above description is only a preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily conceived by any technician familiar with the technical field within the technical scope disclosed by the present invention should be covered within the protection scope of the present invention.

Claims

1. A secure communication method between a drone and a ground station, It is characterized in that include: System initialization; Based on the preset security parameters, the control center generates and publishes the public parameters for the system to communicate securely; Ground station and drone registration; The ground station and the UAV send their real identities to the control center respectively; receive and store the security parameters and challenge sets sent by the control center to the ground station and the UAV respectively; and randomly select a challenge from the received challenge set, and generate registration parameters in combination with the public parameters; Authentication and key agreement; The ground station and the drone use their respective registration parameters to generate authentication information to be sent to each other for mutual authentication. After successful authentication, a session key dedicated to secure communication is established between the ground station and the drone. Parameter update; After successfully completing the authentication and key negotiation, the ground station and the drone reselect challenges from their respective stored challenge sets and update the authentication parameters for the next authentication and key negotiation.

2. The secure communication method between a drone and a ground station according to claim 1, It is characterized in that The system initialization includes: Given a security parameter λ, the control center selects an elliptic curve G and a generator P, where the order of the elliptic curve is q; The control center randomly selects a non-zero element As the master secret key; calculate the master public key P pub =s·P; The control center introduces a hash function H: This hash function maps an input of any length to Elements for data summary and verification; The control center generates the public parameters {G,P,P pub ,H} is published to the UAVs and ground stations participating in the communication.

3. The secure communication method between the UAV and the ground station according to claim 2, It is characterized in that The ground station registration process includes: 1) The ground station sends its real identity Register at the control center; 2) The control center uses the ground station's real ID j Generate security parameters and challenge set of the ground station and send them to the ground station; Among the security parameters of the ground station, The first safety parameter is the common point Y j =y j P; where the random number A random number selected for the control center; The second safety parameter is η j =H(P pub )·y j +H(ID j ||Y j )·s(mod)q; The challenge set of the ground station generated by the control center is {C j,v } v=1,2,…n ; 3) The ground station calculates the PUF response of the ground station challenge and the hash value of the PUF response based on the received security parameters and challenge set; PUF response R to the ground station challenge j,b =PUF(C j,b );C j,b For the challenge set {C j,v } v=1,2,…n A challenge randomly selected from PUF response hash value tem j,b =H(R j,b ); 4) The ground station uses the hash value of the PUF response and the second security parameter η j Calculate the ground station authentication parameter e j ; Ground station registration parameters j =η j ⊕tem j,b ; 5) The ground station registration is completed and the received challenge set is stored {C j,v } v=1,2,…n , register parameter e j and the challenge of choosing C j,b The corresponding storage is {e j ,C j,b }, the common point Y j Published for use by other communicating entities during authentication and key negotiation.

4. The secure communication method between the UAV and the ground station according to claim 3, It is characterized in that The registration process for a drone includes: 1) The drone sends its true identity Register at the control center; 2) The control center uses the real ID of the drone i Generate the safety parameters and challenge set of the drone and send them to the drone; Among the safety parameters of the drone, The first safety parameter is the common point X i =x i P; where the random number A random number selected for the control center; The second safety parameter is η i =H(P pub )·x i +H(X i )·s(mod)q; The challenge set for drones is {C i,u } u=1,2,…n ; 3) The drone calculates the PUF response of the drone challenge and the hash value of the PUF response based on the received security parameters and challenge set; PUF response to drone challenge R i,a =PUF(C i,a );C i,a For the challenge set {C i,u } u=1,2,…n A challenge randomly selected from PUF response hash value tem i,a =H(R i,a ); 4) The drone uses the hash value of the PUF response and the second security parameter η i Calculate the ground station authentication parameter e i ; Registration parameters of the drone i =η i ⊕tem i,a ; 5) Drone registration is complete, and the received challenge set is stored {C i,u } u=1,2,…n , register parameter e i and the challenge of choosing C i,a The corresponding storage is {e i ,C i,a }, the common point X i Published for use by other communicating entities during authentication and key negotiation.

5. The secure communication method between a drone and a ground station according to claim 4, It is characterized in that The authentication and key negotiation process includes: 1) The ground station will generate the first negotiation parameter {ID j ,T j ,A j }Broadcast to surrounding drones; Among them, ID j is the true identity of the ground station; T j A timestamp generated for the ground station; Parameter A j =H(ID j ||Y j ||R j,v ||r j ||T j )•P; where Y j is the common point of the ground station, R j,v For ground stations from the challenge set {C j,v } v=1,2,…n A challenge C is randomly selected from j,v Calculated PUF response R j,v =PUF(C j,v ), Generate a random number for the ground station; P is the generator of the elliptic function; 2) The drone receives the first negotiation parameter {ID j ,T j ,A j } and then timestamp T j If the validity is checked, the second negotiation parameter {PID i ,A i ,ρ i ,T i }Send to ground station; Among them, the drone pseudonym PID i =ID i ⊕H(H(r i ||T i ||R i,u )·P pub ); Parameter A i =H(r i ||T i ||R i,u )·P;ID i For the true identity of the drone, Generate a random number for the drone; T i A timestamp generated for the drone; R i,u For drones from the challenge collection {C j,u } u=1,2,…n A challenge C is randomly selected from j,u Calculated PUF response R j,u =PUF(C j,u );P pub is the master public key; Parameter ρ i =H(PID i ||X i ||A i ||B i ||T i ||T j ), where B i =η i ·A j , η i The registration parameters stored from the drone i Get η i =e i ⊕tem i,a ; 3) The ground station receives the second negotiation parameter {PID i ,A i ,ρ i ,T i } and then timestamp T i The validity check is done, if it is valid, a parameter ρ is generated j For parameter ρ i To verify, if ρ i =ρ j Then calculate the session key k ji ; Among them, ρ j =H(PID i ||X i ||A i ||B j ||T i ||T j );B j =H(ID j ||Y i ||R′ j,v ||r i ||T j )·(H(P pub )·X i +H(X i )·P pub ); From the challenge set {C j,v } v=1,2,…n A challenge C is randomly selected from j,v Calculated PUF response R′ j,v =PUF(C j,v ); Session key k ji =H(ω j ||B j ||ID j ||PID i );ω j =η j ·A i ; η j =e j ⊕tem j,b ;tem j,b =H(R j,b );R j,b =PUF(C j,b ); 4) The ground station sends the third negotiation parameter to the drone in, T′ j Generate a timestamp for the ground station; 5) The drone receives the third negotiation parameter Then timestamp T′ j The validity check is performed, and if it is valid, the session key k is generated. ij and parameters Among them, k ij =H(ω i ||B i ||ID j ||PID i ); ω i =H(R′ i,u ||r i ||T i )·(H(P pub )·Y j +H(Y j ||ID j )·P pub ); R′ i,u =PUF(C i,u ); 6) Drone inspection If they are equal, the mutual authentication between the drone and the ground station is completed, and a session key k is successfully established. ij (k ji ) for secure communications.

6. The secure communication method between the UAV and the ground station according to claim 5, It is characterized in that The drone parameter update process includes: 1) The drone is selected from the stored challenge set {C i,u } u=1,2,…n Randomly select a challenge C′ i,a , calculate the PUF response of the challenge and the hash value of the PUF response; Challenge C′ i,a The PUF response R′ i,a =PUF(C′ i,a ), PUF response R′ i,a The hash value of tem′ i,a =H(R′ i,a ); 2) The drone uses the hash value tem′ of the PUF response i,a and the second safety parameter η of the drone i Calculate the authentication parameter e′ for the updated ground station i ; Updated ground station authentication parameter e′ i =η i ⊕tem′ i,a ; 3) The drone will store the previously stored parameters {e i ,C i,a } is updated to the parameter {e′ i ,C′ i,a }, store it, and set the challenge {C i,u } u=1,2,…n Challenge C used before i,u and C i,a delete.

7. The secure communication method between a drone and a ground station according to claim 5, It is characterized in that The ground station parameter update process includes: 1) The ground station obtains the stored challenge set {C j,v } u=1,2,…n Randomly select a challenge C′ j,b , calculate the PUF response of the challenge and the hash value of the PUF response; Challenge C′ j,b The PUF response R′ j,b =PUF(C′ j,b ), PUF response R′ j,b The hash value of tem′ j,b =H(R′ j,b ); 2) The ground station uses the hash value tem′ of the PUF response j,b and the second safety parameter η of the ground station j Calculate the authentication parameter e′ for the updated ground station j ; Updated ground station authentication parameter e′ j =η j ⊕tem′ j,b ; 3) The drone will store the previously stored parameters {e j ,C j,b } is updated to the parameter {e′ j ,C′ j,b }, store it, and set the challenge {C j,v } u=1,2,…n Challenge C used before j,v and C j,b delete.

8. A secure communication system between a drone and a ground station, It is characterized in that Including control center, ground station and drone; The secure communication system adopts the secure communication method between the UAV and the ground station as described in any one of claims 1 to 7 to achieve system initialization, ground station and UAV registration, authentication and key negotiation, and parameter update.

9. An electronic device, It is characterized in that include: one or more processors; A storage device for storing one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the secure communication method between the drone and the ground station as described in any one of claims 1 to 7.

10. A computer readable medium having a computer program stored thereon, It is characterized in that When the program is executed by the processor, the secure communication method between the drone and the ground station as described in any one of items 1-7 is implemented.

Citation Information

Cited By

  • Unmanned aerial vehicle access authentication method based on LORA communication

    CN120358500A

  • Safe communication method and system for unmanned aerial vehicle and ground station

    CN121486814A

  • A secure communication method and system between an unmanned aerial vehicle (UAV) and a ground station

    CN121486814B