Lightweight dynamic asymmetric group key negotiation method and system for unmanned aerial vehicle cluster

By introducing blockchain and PUF technology into the drone cluster, lightweight dynamic asymmetric group key negotiation is realized, solving the problems of high computing complexity, insufficient data reliability and lack of physical attack protection capabilities in the prior art, and improving the security and performance of the system.

CN120111486APending Publication Date: 2025-06-06SOUTHEAST UNIV
View PDF 0 Cites 3 Cited by

Patent Information

Application Number
CN202510287551.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-12
Publication Date
2025-06-06

AI Technical Summary

Technical Problem

The prior art has problems such as high computational complexity, insufficient data reliability, weak privacy protection and lack of physical attack protection capabilities in the dynamic environment of drone clusters.

Method used

A lightweight dynamic asymmetric group key negotiation method for drone clusters is proposed. Blockchain technology is used to store and update keys dynamically, and combined with physical non-clone function (PUF) technology to dynamically recover decryption keys, realizing pairing-free certificate-free asymmetric group key negotiation.

Benefits of technology

It significantly reduces the computational complexity and communication overhead of the algorithm, improves the security and performance of the system, supports dynamic joining and exiting of drone cluster nodes, and enhances the ability to resist physical attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120111486A_ABST
    Figure CN120111486A_ABST
Patent Text Reader

Abstract

The invention discloses an unmanned aerial vehicle cluster-oriented lightweight dynamic asymmetric group key negotiation method and system, a key generation center generates system public and private keys and public parameters, unmanned aerial vehicles and a ground station register and verify partial public and private keys and complete public and private keys, and the ground station precomputes an initialized table to assist subsequent operation. The unmanned aerial vehicles generate signature messages respectively and send the signature messages to ground station nodes for identity verification, the ground stations negotiate and publish asymmetric group encryption keys to the block chain, and the unmanned aerial vehicles generate respective decryption keys; when a new unmanned aerial vehicle applies for joining, a signature message is sent to a ground station node, the ground station updates and publishes the asymmetric group encryption key, and the unmanned aerial vehicles update respective decryption keys; when the unmanned aerial vehicles apply for leaving, a leaving message is sent to the ground station node, the ground station updates and publishes the asymmetric group encryption key, and the unmanned aerial vehicles update respective decryption keys; the pairing-free certificateless asymmetric group key negotiation is realized, and the calculation and communication efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of information security, and mainly relates to a lightweight dynamic asymmetric group key negotiation method and system for unmanned aerial vehicle clusters. Background Art

[0002] With the rapid development of Unmanned Aerial Vehicle (UAV) technology, UAV swarms have been widely used in many fields, such as disaster relief, environmental monitoring, logistics and transportation, and military operations. The core advantages of UAV swarms lie in their scalability, collaboration, and flexibility in mission execution. However, in an open network environment, the security issues of UAV swarms are becoming more and more prominent, especially in key management and communication protection. In order to ensure the security of swarm communications, efficient group key negotiation technology becomes the key. However, traditional group key negotiation methods have many limitations in dealing with the dynamic and resource-constrained requirements of UAV swarms.

[0003] In drone swarm communications, security issues mainly focus on the following aspects. First, the high dynamics of nodes within the cluster makes it normal for members to frequently join and leave. For example, in a disaster monitoring mission, new drones may need to temporarily join the cluster to cover more areas, while damaged drones may need to exit. This dynamicity requires the group key agreement scheme to be able to quickly adapt to member changes. Second, drone devices have limited computing power, storage capacity, and battery life. The communication network of drone swarms usually relies on wireless channels, which makes data transmission vulnerable to eavesdropping, forgery, and man-in-the-middle attacks. Therefore, it is crucial to design an efficient group key agreement scheme to meet security and performance requirements.

[0004] At present, traditional group key agreement technologies are mainly divided into two categories: centralized and distributed. The centralized method relies on a trusted centralized management entity (such as a key generation center, KGC) to generate and distribute keys. The advantages of the centralized method are its simplicity and high computational efficiency, but it has a serious single point failure risk. Once the central node is attacked or fails, the security of the entire system will collapse. In addition, in a dynamic drone cluster, the centralized scheme needs to redistribute keys every time a node joins or exits, which will result in high communication overhead and delay.

[0005] In contrast, distributed group key agreement does not rely on a centralized entity, and the key is generated collaboratively by all participants. The group key agreement method based on symmetric encryption (SGKA) generates shared keys through multiple rounds of communication, which has high computational efficiency, but poor flexibility and is difficult to support the dynamic joining or exit of members. In addition, SGKA has low security, as all participants share the same key. Once the key is leaked, the security of the entire system will be threatened. The asymmetric group key agreement method (AGKA) provides each member with an independent decryption key, which enhances security and flexibility. However, most existing AGKA schemes rely on bilinear pairing technology, which has high computational complexity and is not suitable for resource-constrained drone clusters. Summary of the invention

[0006] The present invention aims at the problems of high computational complexity, insufficient data reliability, weak privacy protection and lack of equipment physical attack protection in the dynamic networking environment in the prior art, and proposes a lightweight dynamic asymmetric group key negotiation method and system for drone clusters. The key generation center first generates system public and private keys and public parameters, and the drone and ground station register and verify partial public and private keys and complete public and private keys. The ground station pre-calculates an initialization table to assist subsequent operations. The drone cluster generates a signature message and sends it to the ground station node to verify the identity. The ground station node negotiates and publishes the asymmetric group encryption key to the blockchain, and the drones generate their own decryption keys. When a new drone applies to join, it first generates a signature message and sends it to the ground station node to verify the identity. Then the ground station node updates and publishes the asymmetric group encryption key, and the drones update their own decryption keys. When a drone in the cluster applies to leave, it sends a leave message to the ground station node, and then the ground station node updates and publishes the asymmetric group encryption key, and the drones update their own decryption keys. In the method of the present invention, the ground station can flexibly divide the task content into subgroups according to the task requirements for encrypted distribution. The drones in the subgroup obtain the task information through their own decryption keys and collaborate to complete the task, ensuring the efficiency and confidentiality of the task distribution. The present invention realizes pairing-free and certificate-free asymmetric group key negotiation, which significantly improves the calculation and communication efficiency.

[0007] In order to achieve the above object, the technical solution adopted by the present invention is: a lightweight dynamic asymmetric group key negotiation method for drone clusters, comprising the following steps:

[0008] S1. Global settings: The key generation center generates system public parameters and master keys according to security parameters λ. The system public parameters Γ and master key MSK are specifically:

[0009] MSK=s,

[0010] Γ={q,G,P,Q,MPK,H 1 ,H 2,H′ 2 ,H 3 ,Λ tk ,MAC k};

[0011] Among them, G is a multiplicative group whose order is a large prime number q, P and Q are the generators of G; H 1 ,H 2 ,H' 2 ,H 3 is a collision-resistant hash function; tk is a symmetric encryption and decryption function; MAC k is the message authentication code function; k, tk, s are the integer groups from modulus q A random value randomly selected from ;

[0012] The system public parameter Γ is made public, and the master key MSK is kept secret;

[0013] S2, Registration: The drone node generates a pair of partial public-private keys (PSK i ,PPK i ), interact with the key generation center to generate a pair of complete public and private keys (FSK) for the drone node i ,FPK i ); The ground station generates a pair of partial public and private keys (PSK β ,PPK β ), interact with the key generation center to generate a pair of complete public and private keys (FSK) for the ground station β ,FPK β ); the expressions of the partial public-private key pair and the complete public-private key pair of the UAV and the ground station are respectively:

[0014] R i =PUF(C i ),R i =R i,1 ||R i,2 ,

[0015] PSK i =R i,1 ,PPK i =PSK i ·P,

[0016] FSK i =r i +MSK·L i ,FPK i =PPK i +r i Q,

[0017] PSK β =x β ,PPKβ =PSK β ·P,

[0018] FSK β =r β +MSK·L β ,FPK β =PPK β +r β Q;

[0019] Among them, L i =H 1 (PID i ,FPK i ), L β =H 1 (PID β ,FPK β ), C i 、r β 、x β 、r i is from A randomly selected element in

[0020] S3, initialization: The ground station pre-calculates an n-dimensional initial table and uploads it to the blockchain to assist in the change of group members in the cluster; the initial signature message The expression is:

[0021]

[0022] in From the group Two random numbers selected randomly; n represents the maximum number of drone racks in a cluster;

[0023] S4, Authentication and Negotiation: Assume that the t initial UAVs in the cluster are the provers in the authentication phase and generate a signed message σ i =(z i ,σ i,1 ,σ i,2 ,{(δ i,j,1 ,δ i,j,2 )} j∈{1,2,...,n}\i ) is sent to the ground station, which uses the initial table on the blockchain to batch verify t initial UAVs. If they pass, the ground station is responsible for negotiating an asymmetric group encryption key AGK = (AGK 1 AGK 2 ), each UAV calculates its own decryption key UK i =(UK i,1 ,UK i,2 );

[0024] S5, join: The index occupancy IO of the drone cluster is initialized to an n-bit all-zero binary string, where [IO] i Indicates the i-th position. If a drone wants to join the cluster as the m-th member, it first checks the index of the drone cluster occupying the m-th position [IO] m Is it 0? If so, the drone U m It can join the cluster as the mth member, and then the ground station verifies that the drone U m If the identity is passed, the ground station is responsible for updating the asymmetric group encryption key AGK = (AGK 1 AGK 2 ), UAV m Calculate your own decryption key UK m =(UK m,1 ,UK m,2 ), the other UAVs update their own decryption keys UK i =(UK i,1 ,UK i,2 );

[0025] S6. Leave: When the drone U l Leaving the cluster, after the ground station receives the departure message sent by the UAV in the cluster, the ground station updates the asymmetric group encryption key AGK = (AGK 1 AGK 2 ), the remaining drones update their own decryption keys UK i =(UK i,1 ,UK i,2 );

[0026] S7, encryption and decryption: Let the selected drone subgroup index be The ground station that performs task distribution updates the asymmetric group encryption key AGK according to the subgroup U = (AGK 1 AGK 2 ), calculate the ciphertext CT = (CT 1 ,CT 2 ,CT 3 ,CT 4 ) and sent to the selected drone subgroup, the drone updates its decryption key UK according to the subgroup U i =(UK i,1 ,UK i,2 ), and finally successfully decrypt the message m to obtain their respective tasks, thus achieving secure information sharing.

[0027] As an improvement of the present invention, the drone registration in step S2 specifically includes the following steps:

[0028] S21. Partial public and private key generation: The key generation center receives the UAV U i Real ID i After the group Randomly select a random value C i As a PUF challenge and returned to the drone U i , UAV i Will challenge C i As the input of PUF, it outputs a challenge R i =PUF(C i ), where R i =R i,1 ||R i,2 , R i,1 and R i,2 The length and The elements in are consistent, and then a partial public-private key pair is generated; the partial public-private key pair (PSK i ,PPK i ) is expressed as follows:

[0029] PSK i =R i,1 ,PPK i =PSK i ·P;

[0030] S22, complete public and private key generation: The key generation center is the drone U i Calculate pseudo identity PID i =SEnc(tk,ID i ||C i ), then from the group Randomly select a random number r i And calculate L i =H 1 (PID i ,FPK i ); The key generation center uses its own MSK to generate U i Calculate a complete public-private key pair; the complete public-private key pair (FSK i ,FPK i ) is:

[0031] FSK i =r i +MSK·L i ,FPK i =PPK i +r i Q;

[0032] S23, key self-verification: UAV i Verify the validity of the partial public-private key pair and the complete public-private key pair according to the verification formula. If the verification fails, terminate the Ui On the contrary, U i Order PK i =FPK i +MPK·L i , and calculate To hide FSK i ; The expression of the verification formula is:

[0033] PPK i +FSK i Q = FPK i +MPK·L i ;

[0034] S24. Initialization of blockchain network: A group of ground station nodes and key generation center form a blockchain network and i Registration information i ={PID i ,C i ,FPK i ,PK i}Publicly available in the blockchain, partial private keys and full private keys are owned by U i Keep it secret.

[0035] As another improvement of the present invention, the authentication and negotiation step S4 specifically includes the following steps:

[0036] S41. Partial and complete private key recovery: For 1≤i≤t, each drone U i First, retrieve the corresponding C from the blockchain ledger i , use your own PUF to recover your partial private key and complete private key; the partial private key PSK i and the complete private key FSK i The expression is as follows:

[0037] R i =PUF(C i ),R i =R i,1 ||R i,2 ,

[0038] PSK i =R i,1 ,

[0039] S42, signature message generation: t initial drones U in the cluster i Based on the partial private key PSK i and the complete private key FSK i Generate a signature message and broadcast it to the corresponding ground station node; the signature message σ i =(zi ,σ i,1 ,σ i,2 ,{(δ i,j,1 ,δ i,j,2 )} j∈{1,2,…,n}\i ) is:

[0040] δ i,j,1 =a i.1 +PSK i ·M j ,δ i,j,2 =a i,2 +FSK i ·M j ,

[0041] z i =a i.1 ·P+a i,2 Q,

[0042] σ i,1 =a i.1 +PSK i ·N i ,σ i,2 =a i,2 +FSK i ·N i ,

[0043] Where N i =H' 2 (PID i ||FPK i ||z i ||TID||{(δ i,j,1 ,δ i,j,2 )} j∈{1,2,…,n}\i ), M j =H 2 (TID||j), a i.1 ,a i,2 It's a drone i (1≤i≤t) from the group Two random numbers chosen at random;

[0044] S43, batch identity verification: The ground station verifies the validity of t signed messages according to the verification formula. If the batch signature verification fails, it terminates; otherwise, for 1≤i≤t, the smart contract sets [IO] i =1 and ι i =1 and update the pseudo-signature and round mapping table; the expression of the verification formula is:

[0045] Z=Z 1 ·P+Z 2 ·QZ 3 ,

[0046] in, It is automatically calculated by the smart contract based on the last column of the updated table;

[0047] S44, asymmetric group encryption key generation: the ground station calculates and publishes the asymmetric group encryption key to the blockchain; the asymmetric group encryption key AGK = (AGK 1 AGK 2 ) is:

[0048]

[0049] Among them, PK i =FPK i +MPK·L i , PK β =FPK β +MPK·L β ;

[0050] S45, Table Data Verification: UAV i Verify the validity of the first n columns of data in the table according to the verification formula; the expression of the verification formula is:

[0051] AGK 1 =Y i,1 ·P+Y i,2 ·QV i +z i ;

[0052] S46, decryption key generation: For 1≤i≤t, if the verification fails, terminate; if the verification succeeds, each drone U i According to the Δ of your own secret information i,i =(δ i,i,1 ,δ i,i,2 ) Calculate the respective decryption key UK i =(UK i,1 ,UK i,2 ); the decryption key UK i =(UK i,1 ,UK i,2 ) is:

[0053]

[0054] in,

[0055] As an improvement of the present invention, the step S5 specifically includes the following steps:

[0056] S51, signature message generation: UAV U m Generate a signed message σm , broadcast to the corresponding ground station node, and the ground station receives σ m Then, the validity of the signed message is verified according to the verification formula; the verification formula is specifically:

[0057] z m =σ m,1 ·P+σ m,2 Q-PK m ;

[0058] S52, asymmetric group encryption key update: the ground station updates and publishes the asymmetric group encryption key to the blockchain; the updated asymmetric group encryption key AGK = (AGK 1 AGK 2 ) is:

[0059]

[0060] S53, decryption key update: verify according to the table data in step S45, if the verification fails, terminate; if the verification succeeds, for 1≤i≤t, each drone U i According to the Δ of your own secret information i,i =(δ i,i,1 ,δ i,i,2 ) update their respective decryption keys; the updated decryption key UK i =(UK i,1 ,UK i,2 ) is:

[0061]

[0062] S54, decryption key calculation: UAV U m According to the parameters and secret information Δ m,m =(δ m,m,1 ,δ m,m,2 ) Calculate the decryption key UK m ; The decryption key UK m =(UK m,1 ,UK m,2 ) is:

[0063] UK m,1 =Y m,1 +δ m,m,1 ,UK m,2 =Y m,2 +δ m,m,2 ;

[0064] S55, Mapping table update: Smart contract automatic setting [IO] m =1, check ι i Does it exist and is less than 10? If so, let ιm =ι m +1; otherwise, let ι m =1.

[0065] As another improvement of the present invention, the step S6 specifically includes the following steps:

[0066] S61, asymmetric group encryption key update: When the ground station receives the UAV U l Broadcast leave message M l Or detect U l When leaving passively, the ground station updates and publishes the asymmetric group encryption key to the blockchain; the updated asymmetric group encryption key AGK = (AGK 1 AGK 2 ) is:

[0067]

[0068] S62, decryption key update: For all the members in the cluster except U l All drones except for i,i =(δ i,i,1 ,δ i,i,2 ) update their respective decryption keys; the updated decryption key UK i =(UK i,1 ,UK i,2 ) is:

[0069]

[0070] S63, Mapping table update: Smart contract automatic setting [IO] l =0, check ι l Does it exist and is less than 10? If so, let ι l =ι l +1; otherwise, let ι l =1.

[0071] As another improvement of the present invention, the encryption and decryption step S7 specifically includes the following steps:

[0072] S71, asymmetric group encryption key update: after the ground station node selects a subset of drones U for message transmission, it updates and publishes the asymmetric group encryption key to the blockchain; the updated asymmetric group encryption key AGK = (AGK 1 AGK 2 ) is:

[0073]

[0074] S72, ciphertext calculation: any ground station node from the group Randomly select a random number ∝, then calculate and return the ciphertext; the ciphertext CT=(CT 1 ,CT 2 ,CT 3 ,CT 4 ) is:

[0075] CT 1 =∝·P,CT 2 =∝·Q,CT 3 =∝·AGK 1 ,

[0076] κ 1 ||κ 2 =H 3 (∝·AGK 2 ),CT 4 =SEnc(κ 1 ,m),

[0077]

[0078] S73, decryption key update: After receiving U and CT, the selected drone subgroup updates its own decryption key; the updated decryption key UK i =(UK i,1 ,UK i,2 ) is:

[0079]

[0080] S74, integrity check: The drone checks the validity of the ciphertext according to the verification formula. If the verification is successful, it returns the message m. The expression of the verification formula is:

[0081]

[0082] Among them, κ' 1 ||κ' 2 =H 3 (Y),Y=CT 1 UK i,1 +CT 2 UK i,2 -CT 3 .

[0083] In order to achieve the above purpose, the technical solution adopted by the present invention is: a lightweight dynamic asymmetric group key agreement system for drone clusters, comprising at least a key generation center, a ground station, a drone cluster and a blockchain.

[0084] The key generation center: consists of several servers and is responsible for generating the public parameters of the system and the complete public and private keys of the ground station and the drone cluster;

[0085] The ground station is responsible for receiving information transmitted by the drone and performing mission planning. Each ground station pre-calculates an initial table and uploads it to the blockchain account book. It has the authority to write and update the account book and can execute smart contracts.

[0086] The drone cluster: is assigned to different subgroups according to different tasks. As an off-chain node, it only has read permissions and can join or leave tasks at any time as needed;

[0087] The blockchain: All ground stations constitute a permissioned blockchain to host system public parameters and initial tables. The list is updated when a node joins or leaves the cluster. The smart contract automatically calculates and updates the asymmetric group encryption key and auxiliary data of the drone cluster, and publishes announcements using smart contracts.

[0088] Compared with the prior art, the present invention has the following beneficial effects:

[0089] (1) The present invention realizes asymmetric group key negotiation based on pairing-free and certificate-free, abandons the complex calculation of traditional bilinear pairing, effectively solves the key escrow problem, reduces the computational complexity and communication overhead of the algorithm, and is suitable for resource-constrained drones.

[0090] (2) The present invention introduces blockchain technology into the key management of drone clusters, and uses its distributed storage and tamper-proof characteristics to store and dynamically update lists, preventing malicious nodes from tampering with data and ensuring data integrity. This not only improves the security and performance of the system, but also supports outsourced computing and receiver controllability. It also supports the dynamic joining and exiting of drone cluster nodes without the need to reinitialize the entire key negotiation process, significantly improving the efficiency and flexibility of key management, and providing an efficient, secure and dynamic environment-friendly solution for secure communications in drone clusters.

[0091] (3) The present invention introduces a pseudo-signature and round mapping table to achieve the anonymity feature of "one pseudo-signature for one task" and ensure that signatures between different tasks cannot be associated.

[0092] (4) The present invention combines physical unclonable function (PUF) technology and uses PUF to dynamically recover the decryption key, avoiding local storage of the key, significantly improving the system's ability to defend against physical attacks (such as device capture and tampering). Even if the device is captured, it is difficult for the attacker to crack the security system, fundamentally improving the drone's ability to resist physical attacks.

[0093] (5) The present invention also realizes efficient pairing-free and certificate-free asymmetric group key negotiation under low computing power conditions, providing technical support for the deployment of low-cost UAV systems. BRIEF DESCRIPTION OF THE DRAWINGS

[0094] Figure 1 It is a structural framework diagram of the system of the present invention;

[0095] Figure 2 It is a flow chart of the steps of the method of the present invention. DETAILED DESCRIPTION

[0096] The present invention will be further explained below in conjunction with the accompanying drawings and specific embodiments. It should be understood that the following specific embodiments are only used to illustrate the present invention and are not used to limit the scope of the present invention.

[0097] Example 1

[0098] The symbols and their definitions in this embodiment are shown in Table 1:

[0099] Table 1

[0100]

[0101]

[0102] In recent years, blockchain technology has provided a potential solution for dynamic group key negotiation due to its decentralization, immutability and transparency. Blockchain can be used to store the system's public parameters and some intermediate data in the group key negotiation process. Its immutability can enhance the security and credibility of the system. In addition, the introduction of blockchain smart contracts can automatically manage the dynamic joining and exit of members, while recording the operation history to support the traceability of the system and the restriction of frequent node changes. Lightweight dynamic asymmetric group key negotiation system for drone clusters, such as Figure 1 As shown, it includes at least a key generation center, a ground station, a drone cluster and a blockchain.

[0103] Key Generation Center (KGC): Usually composed of several servers with sufficient resources, it is semi-trusted and is responsible for generating the public parameters of the system and the complete public and private keys of GCS and UAV.

[0104] Ground Station (GCS): Responsible for receiving basic information transmitted by drones and performing mission planning. Each GCS pre-calculates an initial table and uploads it to the blockchain ledger. As a node on the chain, GCS has the authority to write and update the ledger and can execute smart contracts.

[0105] Unmanned aerial vehicles (UAVs): They are assigned to different subgroups according to different tasks. The storage and computing resources of UAVs are limited. Each UAV is equipped with an FPGA development board that can implement strong PUF and is connected via wires. As an off-chain node, the UAV only has read permissions, but it can join or leave the task at any time as needed.

[0106] Blockchain: All GCSs form a permissioned blockchain to host system public parameters and initial tables. The list is updated when nodes join or leave the cluster. Smart contracts automatically calculate and update the asymmetric group encryption keys and auxiliary data of the drone cluster, and use smart contracts to publish announcements.

[0107] A lightweight dynamic asymmetric group key negotiation method for drone clusters implemented using the above system, such as Figure 2 As shown, the specific steps include:

[0108] Step S1: Global settings: The Key Generation Center (KGC) generates system parameters and a master key according to the security parameter λ, the system public parameter Γ is made public, and the master key MSK is kept secret.

[0109] First, select a cyclic group G of prime order q, and select two independent generators P and Q from G.

[0110] The following four collision-resistant hash functions are defined: H 3 :{0,1} * →{0,1} 2k .

[0111] From the group Randomly select a random number s as the master key MSK, and calculate the corresponding master public key MPK=sQ.

[0112] Define a symmetric encryption and decryption function Λ tk =(SEnc,SDec), where tk is the symmetric encryption key used to ensure the privacy and anonymity of the message. To verify the integrity and authenticity of the message, a message authentication code function MAC based on the symmetric key k is used k .

[0113] KGC publishes the system public parameter Γ, secretly stores tk and the master key MSK=s. The expression of the system public parameter Γ is as follows:

[0114] Γ={q,G,P,Q,MPK,H 1 ,H 2 ,H′ 2 ,H 3 ,Λtk ,MAC k}.

[0115] Step S2: Registration. The drone node first generates a pair of partial public and private keys for itself, and then interacts with the key generation center to generate a pair of complete public and private keys for the drone node. Similarly, the ground station first generates a pair of partial public and private keys for itself, and then interacts with the key generation center to generate a pair of complete public and private keys for the ground station.

[0116] The specific steps of drone registration are as follows:

[0117] S211: UAV i Your real ID i Send to the key generation center;

[0118] S212: The key generation center generates a key from the group Randomly select a random value C i As a PUF challenge and returned to the drone U i ;

[0119] S213: UAV i Will challenge C i As the input of PUF, it outputs a challenge R i =PUF(C i ), where R i =R i,1 ||R i,2 , Then the drone U i Calculate your own partial private key PSK i =R i,1 , the corresponding partial public key PPK i =PSK i ·P; Finally, the drone U i PPK i Send to the key generation center;

[0120] S214: To protect the drone i The key generation center calculates the pseudo identity PID for it. i =SEnc(tk,ID i ||C i ), from the group Randomly select a random number r i And calculate L i =H 1 (PID i ,FPK i ); Then, the key generation center is U i Calculate the complete private key FSK i =r i+MSK·L i , the corresponding complete public key FPK i =PPK i +r i Q; the key generation center sends PID i ,FSK i ,FPK i Send to U i ;

[0121] S215: UAV i The correctness of the key is verified by the following formula:

[0122] PPK i +FSK i Q = FPK i +MPK·L i .

[0123] If the verification fails, terminate U i On the contrary, U i Order PK i =FPK i +MPK·L i , and calculate To hide FSK i ;

[0124] S216: Then a group of ground station nodes and key generation centers form a blockchain network and i Registration information i ={PID i ,C i ,FPK i ,PK i}Publicly available in the blockchain, partial private keys and full private keys are kept secret.

[0125] The steps involved in ground station registration are as follows:

[0126] S221: Ground station slave group Randomly pick a random value x β As part of your private key PSK β =x β , the corresponding partial public key PPK β =PSK β P; then enter your real ID β Send to the key generation center;

[0127] S222: The key generation center calculates the pseudonym PID for the ground station β =SEnc(tk,ID β ), choose a random number And calculate L β =H 1 (PID β ,FPK β ); Then, the key generation center calculates the complete private key FSK for the ground station β =r β +MSK·L β , the corresponding complete public key FPK β =PPK β +r β Q; The key generation center sends PID β ,FSK β ,FPK β Transmit to ground station;

[0128] S223: The ground station verifies the correctness of the key using the following formula:

[0129] PPK β +FSK β Q = FPK β +MPK·L β .

[0130] If the verification fails, the ground station registration is terminated; otherwise, the ground station orders PK β =FPK β +MPK·L β ;

[0131] S224: Then the ground station registration information RI β ={PID β ,FPK β ,PK β}Publicly available in the blockchain, partial private keys and full private keys are kept secret.

[0132] Step S3: Initialization. Assuming that a cluster contains at most n drones, the ground station pre-calculates an n-dimensional initial table to assist in subsequent group member changes (new members joining or members leaving the group); the initial signature message The expression is:

[0133]

[0134]

[0135] in From the group The two random numbers are randomly selected, and the specific steps are as follows:

[0136] First, for 1≤i≤n, the ground station from the group Randomly select two random numbers

[0137] Then, for 1≤i,j≤n,i≠j, the ground station first calculates M j =H 2 (TID||j), then calculate:

[0138]

[0139] For 1≤i≤n, the ground station calculates and the signature:

[0140]

[0141] in

[0142] For 1≤i≤n, the ground station uploads To the blockchain, the blockchain stores this initial table in its ledger.

[0143] The index IO of the drone cluster is initialized to an n-bit all-zero binary string, where [IO] i Indicates the i-th position. When the i-th position is occupied, [IO] i Set to 1; if not occupied, set to 0;

[0144] To avoid frequent join or leave operations, the system maintains an initially empty mapping table in the blockchain. i Indicates the round parameter limit used to limit the number of drones joining and leaving operations, ι i The initial value of is 0 and the maximum value is 10. Once i ≥10, the corresponding drone U i Remove from the cluster and add it to the blacklist of the blockchain to record and restrict subsequent operations.

[0145] Step S4: Authentication and negotiation. Assume that the t initial UAVs in the cluster are the provers in the authentication phase and generate a signed message σ i =(z i ,σ i,1 ,σ i,2 ,{(δ i,j,1 ,δ i,j,2 )} j∈{1,2,…,n}\i ) is sent to the ground station. The ground station uses the initial table on the blockchain to batch verify the t initial UAVs. If they pass, the ground station is responsible for negotiating an asymmetric group encryption key, and each UAV calculates its own decryption key.

[0146] S41: For 1≤i≤t, each drone U iFirst, retrieve the corresponding C from the blockchain ledger i , and then use your own PUF to recover your own PSK i and FSK i :

[0147] R i =PUF(C i ),R i =R i,1 ||R i,2 ,

[0148] PSK i =R i,1 ,

[0149] S42: For 1≤i≤t, drone U i From the group Randomly select two random numbers a i.1 ,a i,2 ;

[0150] S43: For 1≤i≤t,1≤j≤n, UAV U i First calculate M j =H 2 (TID||j), then calculate:

[0151] δ i,j,1 =a i.1 +PSK i ·M j ,δ i,j,2 =a i,2 +FSK i ·M j

[0152] Among them, only U i The corresponding Δ can be calculated i,i =(δ i,i,1 ,δ i,i,2 ) and need to be kept secret by oneself;

[0153] S44: For 1≤i≤t, drone U i Calculate z i =a i.1 ·P+a i,2 Q and Signature:

[0154] σ i,1 =a i.1 +PSK i ·N i ,σ i,2 =a i,2 +FSK i ·N i .

[0155] Where N i =H' 2 (PID i ||FPK i ||z i ||TID||{(δ i,j,1 ,δ i,j,2 )} j∈{1,2,…,n}\i );

[0156] S45: For 1≤i≤t, drone U i Broadcast i =(z i ,σ i,1 ,σ i,2 ,{(δ i,j,1 ,δ i,j,2 )} j∈{1,2,…,n}\i ), the ground station node receives the corresponding Replace with σ i The new table of itineraries in this embodiment is shown in Table 2 below.

[0157] Table 2

[0158]

[0159] In the above table, for 1≤i≤t, the blockchain automatically converts the initial table U i Corresponding Replace them with σ i , for t+1≤i≤n, the corresponding The second-to-last row of public parameters is also outsourced to the blockchain for calculation and publication, and the last row of private parameters is calculated by each drone U i According to Table 2 and combined with the Δ of one's own secret information i,i =(δ i,i,1 ,δ i,i,2 ) calculated.

[0160] S46: For 1≤i≤t, the ground station calculates N' i =H' 2 (PID i ||FPK i ||z i ||TID||{(δ i,j,1 ,δ i,j,2 )} j∈{1,2,…,n}\i ), for t≤i≤n, calculate

[0161] S47: The smart contract automatically calculates based on the last column of the new table:

[0162] S48: The ground station checks whether the following equation holds:

[0163] Z=Z 1 ·P+Z 2 ·QZ 3

[0164] S49: If batch signature verification fails, terminate; otherwise, for 1≤i≤t, smart contract settings [IO] i =1 and ι i =1, then the ground station calculates and publishes the asymmetric group encryption key AGK=(AGK 1 AGK 2 ) to the blockchain:

[0165]

[0166] S410: Smart contract calculates and updates the list:

[0167] S411: Each drone U i Verify that the following equation holds true based on the second-to-last row of data in Table 2:

[0168] AGK 1 =Y i,1 ·P+Y i,2 ·QV i +z i

[0169] S412: If the verification is successful, for 1≤i≤t, each drone U i According to the Δ of your own secret information i,i =(δ i,i,1 ,δ i,i,2 ) Calculate the respective decryption key UK i =(UK i,1 ,UK i,2 ):

[0170]

[0171] Step S5: Joining. During the mission execution, if a drone is lost due to hardware failure, energy exhaustion or unexpected events, new members need to join to maintain the functional integrity of the cluster. If [IO] m = 0, then the drone U m You can join the cluster as the mth member. This includes the following steps:

[0172] S51: UAV mAccording to steps S41-S45, a signature message σ is generated. m =(z m ,σ m,1 ,σ m,2 ,{(δ m,j,1 ,δ m,j,2 )} j∈{1,2,…,n}\m ) and broadcast it to the ground station;

[0173] S52: The ground station receives σ m After that, through z m =σ m,1 ·P+σ m,2 Q-PK m Verify U m If the verification fails, the smart contract will automatically Figure 1 The mth row of Replace with σ m , then update and upload the asymmetric group encryption key by following these steps:

[0174]

[0175] S53: For 1≤i≤t, if the equation in step S411 is verified, U i Follow the steps below to update its UK i :

[0176]

[0177] S54: U m According to the mth column parameter in the second to last row of Table 2 and its own secret information Δ m,m =(δ m,m,1 ,δ m,m,2 ) Calculate its UK m :

[0178] UK m,1 =Y m,1 +δ m,m,1 ,UK m,2 =Y m,2 +δ m,m,2 .

[0179] S55: Smart Contract Automatic Setup [IO] m =1; check ι i Does it exist and is less than 10? If so, let ι m =ι m +1; otherwise, let ι m =1.

[0180] Step S6: Leave. After completing its assigned mission, the drone can take the initiative to leave the cluster to save resources or return to recharge. Some drones will be forcibly removed and added to the blacklist due to too frequent joining and leaving and triggering the set restrictions (such as the round limit). l Leaving the cluster includes the following steps:

[0181] S61: If it is a drone l Actively leave, then broadcast a leave message M l ;

[0182] S62: When the ground station receives M l Or detect U l When leaving passively, the smart contract actively retrieves σ from Table 2 l , then σ l Replace with Update and upload the asymmetric group encryption key by following these steps:

[0183]

[0184] S63: For all clusters except U l All drones except U i Follow the steps below to update its UK i :

[0185]

[0186] S64: Smart Contract Automatic Setup [IO] l =0, check ι l Does it exist and is less than 10? If so, let ι l =ι l +1; otherwise, let ι l =1.

[0187] Step S7: Encryption and decryption. Any ground station node that knows the asymmetric group encryption key can send a message. The ground station node can not only securely transmit the message to the entire cluster S, but also select any subset of drones for message transmission. Let the selected drone subset index be This phase includes the following steps:

[0188] S71: Any ground station node calculation and

[0189] S72: Any ground station node from the group Randomly choose a random number ∝ and then calculate:

[0190] CT 1 =∝·P,CT 2 =∝·Q,CT 3 =∝·AGK 1 ,

[0191] κ 1 ||κ 2 =H 3 (∝·AGK 2 ),CT 4 =SEnc(κ 1 ,m),

[0192]

[0193] S73: Return U and ciphertext CT=(CT 1 ,CT 2 ,CT 3 ,CT 4 );

[0194] S74: After receiving U and CT, the selected drone subgroup updates its and

[0195] S75: For i∈U, each drone calculates M i =H 2 (TID||i) and κ' 1 ||κ' 2 =H 3 (γ), where γ = CT 1 UK i,1 +CT 2 UK i,2 -CT 3 ;

[0196] S76: Check whether the following equation holds:

[0197] S77: If established, return message m=SEnc(κ 1 ,CT 4 ).

[0198] Finally, all drones in the selected drone subgroup use their own secret information Δ i,i =(δ i,i,1 ,δ i,i,2 ) successfully decrypts the message, enabling secure information sharing.

[0199] The present invention discloses a lightweight dynamic asymmetric group key negotiation method and system for drone clusters. It is the first asymmetric group key negotiation method that supports pairing-free, outsourced computing, and receiver-controllable. This method instantly recovers keys through the hardware characteristics of the device, avoiding direct local storage, and can effectively prevent device cloning and forgery. In addition, with the assistance of distributed blockchain, the public data is guaranteed to be tamper-proof, solving the problems of data loss and consistency. At the same time, drones can outsource some computing-intensive tasks to ground stations with the help of blockchain, significantly reducing the local computing burden.

[0200] It should be noted that the above content only illustrates the technical idea of ​​the present invention and cannot be used to limit the protection scope of the present invention. For ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principle of the present invention. These improvements and modifications all fall within the protection scope of the claims of the present invention.

Claims

1. A lightweight dynamic asymmetric group key negotiation method for drone clusters, characterized by: The steps include: S1. Global settings: The key generation center generates system public parameters and master keys according to security parameters λ. The system public parameters Γ and master key MSK are specifically: MSK=s, Γ={q,G,P,Q,MPK,H1,H2,H′2,H3,Λ tk ,MAC k }; Among them, G is a multiplicative group whose order is a large prime number q, P and Q are the generators of G; H1, H2, H'2, H3 are collision-resistant hash functions; Λ tk is a symmetric encryption and decryption function; MAC k is the message authentication code function; k, tk, s are the integer groups from modulus q A random value randomly selected from ; The system public parameter Γ is made public, and the master key MSK is kept secret; S2, Registration: The drone node generates a pair of partial public-private keys (PSK i ,PPK i ), interact with the key generation center to generate a pair of complete public and private keys (FSK) for the drone node i ,FPK i ); The ground station generates a pair of partial public and private keys (PSK β ,PPK β ), interact with the key generation center to generate a pair of complete public and private keys (FSK) for the ground station β ,FPK β ); the expressions of the partial public-private key pair and the complete public-private key pair of the UAV and the ground station are respectively: R i =PUF(C i ),R i =R i,1 ∥R i,2 , PSK i =R i,1 ,PPK i =PSK i ·P, FSK i =r i +MSK·L i ,FPK i =PPK i +r i ·Q, PSK β =x β ,PPK β =PSK β ·P, FSK β =r β +MSK·L β ,FPK β =PPK β +r β ·Q; Among them, L i =H1(PID i ,FPK i ), L β =H1(PID β ,FPK β ), C i 、r β 、x β 、r i is from A randomly selected element in S3, initialization: The ground station pre-calculates an n-dimensional initial table and uploads it to the blockchain to assist in the change of group members in the cluster; the initial signature message The expression is: in M j =H2(TID∥j), From the group Two random numbers selected randomly; n represents the maximum number of drone racks in a cluster; S4, Authentication and Negotiation: Assume that the t initial UAVs in the cluster are the provers in the authentication phase and generate a signed message σ i =(z i ,σ i,1 ,σ i,2 ,{(δ i,j,1 ,δ i,j,2 )} j∈{1,2,…,n}\i ) is sent to the ground station, which uses the initial table on the blockchain to batch verify t initial UAVs. If they pass, the ground station is responsible for negotiating an asymmetric group encryption key AGK = (AGK1, AGK2), and each UAV calculates its own decryption key UK i =(UK i,1 ,UK i,2 ); S5, join: The index occupation IO of the drone cluster is initialized to an n-bit all-zero binary string, where [IO] i Indicates the i-th position. If a drone wants to join the cluster as the m-th member, it first checks the index of the drone cluster occupying the m-th position [IO] m Is it 0? If so, the drone U m It can join the cluster as the mth member, and then the ground station verifies that the drone U m If the identity is passed, the ground station is responsible for updating the asymmetric group encryption key AGK = (AGK1, AGK2), and the drone U m Calculate your own decryption key UK m =(UK m,1 ,UK m,2 ), the other UAVs update their own decryption keys UK i =(UK i,1 ,UK i,2 ); S6. Leave: When the drone U l Leaving the cluster, after the ground station receives the departure message sent by the drone in the cluster, the ground station updates the asymmetric group encryption key AGK = (AGK1, AGK2), and the remaining drones update their own decryption keys UK i =(UK i,1 ,UK i,2 ); S7, encryption and decryption: Let the selected drone subgroup index be The ground station that distributes tasks calculates the ciphertext CT = (CT1, CT2, CT3, CT4) based on the asymmetric group encryption key AGK = (AGK1, AGK2) of the subgroup U and sends it to the selected drone subgroup. The drone updates its decryption key UK based on the subgroup U. i =(UK i,1 ,UK i,2 ), and finally successfully decrypt the message m to obtain their respective tasks, thus achieving secure information sharing.

2. The lightweight dynamic asymmetric group key negotiation method for drone clusters according to claim 1, characterized in that: The drone registration in step S2 specifically includes the following steps: S21. Partial public and private key generation: The key generation center receives the UAV U i Real ID i After the group Randomly select a random value C i As a PUF challenge and returned to the drone U i , UAV i Will challenge C i As the input of PUF, it outputs a challenge R i =PUF(C i ), where R i =R i,1 ∥R i,2 , R i,1 and R i,2 The length and The elements in are consistent, and then a partial public-private key pair is generated; the partial public-private key pair (PSK i ,PPK i ) is expressed as follows: PSK i =R i,1 ,PPK i =PSK i ·P; S22, complete public and private key generation: The key generation center is the drone U i Calculate the pseudo identity PID i =SEnc(tk,ID i ∥C i ), then from the group Randomly select a random number r i And calculate L i =H1(PID i ,FPK i ); The key generation center uses its own MSK to generate U i Calculate a complete public-private key pair; the complete public-private key pair (FSK i ,FPK i ) is: FSK i =r i +MSK·L i ,FPK i =PPK i +r i ·Q; S23, key self-verification: UAV i Verify the validity of the partial public-private key pair and the complete public-private key pair according to the verification formula. If the verification fails, terminate the U i On the contrary, U i Order PK i =FPK i +MPK·L i , and calculate To hide FSK i ; The expression of the verification formula is: PPK i +FSK i ·Q=FPK i +MPK·L i ; S24. Initialization of blockchain network: A group of ground station nodes and key generation center form a blockchain network and i Registration information i ={PID i ,C i ,FPK i ,PK i }Publicly available in the blockchain, partial private keys and full private keys are owned by U i Keep it secret.

3. The lightweight dynamic asymmetric group key negotiation method for drone clusters according to claim 1, characterized in that: The authentication and negotiation step S4 specifically includes the following steps: S41. Partial and complete private key recovery: For 1≤i≤t, each drone U i First, retrieve the corresponding C from the blockchain ledger i , use your own PUF to recover your partial private key and complete private key; the partial private key PSK i and the complete private key FSK i The expression is as follows: R i =PUF(C i ),R i =R i,1 ∥R i,2 , PSK i =R i,1 , S42, signature message generation: t initial drones U in the cluster i Based on the partial private key PSK i and the complete private key FSK i Generate a signature message and broadcast it to the corresponding ground station node; the signature message σ i =(z i ,σ i,1 ,σ i,2 ,{(δ i,j,1 ,δ i,j,2 )} j∈{1,2,…,n}\i ) is: d i,j,1 =a i.1 +PSK i ·M j ,d i,j,2 =a i,2 +FSK i ·M j , z i =a i.1 ·P+a i,2 ·Q, s i,1 =a i.1 +PSK i ·N i ,s i,2 =a i,2 +FSK i ·N i , Where N i =H'2(PID i ∥FPK i ∥z i ∥TID∥{(δ i,j,1 ,δ i,j,2 )} j∈{1,2,…,n}\i ), M j =H2(TID∥j), a i.1 ,a i,2 It's a drone i (1≤i≤t) from the group Two random numbers chosen at random; S43, batch identity verification: The ground station verifies the validity of t signed messages according to the verification formula. If the batch signature verification fails, it terminates; otherwise, for 1≤i≤t, the smart contract sets [IO] i =1 and ι i =1 and update the pseudo-signature and round mapping table; the expression of the verification formula is: Z=Z1·P+Z2·Q-Z3, in, It is automatically calculated by the smart contract based on the last column of the updated table; S44, asymmetric group encryption key generation: the ground station calculates and publishes the asymmetric group encryption key to the blockchain; the expression of the asymmetric group encryption key AGK=(AGK1, AGK2) is: Among them, PK i =FPK i +MPK·L i , PK β =FPK β +MPK·L β ; S45, Table Data Verification: UAV i Verify the validity of the first n columns of data in the table according to the verification formula; the expression of the verification formula is: AGK1=Y i,1 ·P+Y i,2 ·Q-V i +z i ; S46, decryption key generation: For 1≤i≤t, if the verification fails, terminate; if the verification succeeds, each drone U i According to the Δ of your own secret information i,i =(δ i,i,1 ,δ i,i,2 ) Calculate the respective decryption key UK i =(UK i,1 ,UK i,2 ); the decryption key UK i =(UK i,1 ,UK i,2 ) is: in, 4. The lightweight dynamic asymmetric group key negotiation method for drone clusters as claimed in claim 3, characterized in that: The step S5 specifically includes the following steps: S51. Signature message generation: UAV U m Generate a signed message σ m , broadcast to the corresponding ground station node, and the ground station receives σ m Then, the validity of the signed message is verified according to the verification formula; the verification formula is specifically: z m =σ m,1 ·P+σ m,2 ·Q-PK m ; S52, asymmetric group encryption key update: the ground station updates and publishes the asymmetric group encryption key to the blockchain; the expression of the updated asymmetric group encryption key AGK=(AGK1, AGK2) is: S53, decryption key update: verify according to the table data in step S45, if the verification fails, terminate; if the verification succeeds, for 1≤i≤t, each drone U i According to the Δ of your own secret information i,i =(δ i,i,1 ,δ i,i,2 ) update their respective decryption keys; the updated decryption key UK i =(UK i,1 ,UK i,2 ) is: S54, decryption key calculation: UAV U m According to the parameters and secret information Δ m,m =(δ m,m,1 ,δ m,m,2 ) Calculate the decryption key UK m ; The decryption key UK m =(UK m,1 ,UK m,2 ) is: UK m,1 =Y m,1 +δ m,m,1 ,UK m,2 =Y m,2 +δ m,m,2 ; S55, Mapping table update: Smart contract automatic setting [IO] m =1, check ι i Does it exist and is less than 10? If so, let ι m =ι m +1; otherwise, let ι m =1.

5. The lightweight dynamic asymmetric group key negotiation method for drone clusters as claimed in claim 4, characterized in that: The step S6 exit specifically includes the following steps: S61, asymmetric group encryption key update: When the ground station receives the UAV U l Broadcast leave message M l Or detect U l When passively leaving, the ground station updates and publishes the asymmetric group encryption key to the blockchain; the expression of the updated asymmetric group encryption key AGK=(AGK1, AGK2) is: S62, decryption key update: For all the members in the cluster except U l All drones except for i,i =(δ i,i,1 ,δ i,i,2 ) update their respective decryption keys; the updated decryption key UK i =(UK i,1 ,UK i,2 ) is: S63, Mapping table update: Smart contract automatic setting [IO] l =0, check ι l Does it exist and is less than 10? If so, let ι l =ι l +1; otherwise, let ι l =1.

6. The lightweight dynamic asymmetric group key negotiation method for drone clusters according to claim 1, characterized in that: The encryption and decryption step S7 specifically includes the following steps: S71, asymmetric group encryption key update: after the ground station node selects a subset of drones U for message transmission, it updates and publishes the asymmetric group encryption key to the blockchain; the expression of the updated asymmetric group encryption key AGK=(AGK1, AGK2) is: S72, ciphertext calculation: any ground station node from the group Randomly select a random number ∝, then calculate and return the ciphertext; the expression of the ciphertext CT = (CT1, CT2, CT3, CT4) is: CT1=∝·P, CT2=∝·Q, CT3=∝·AGK1, κ1||κ2=H3(∝·AGK2),CT4=SEnc(κ1,m), S73, decryption key update: After receiving U and CT, the selected drone subgroup updates its own decryption key; the updated decryption key UK i =(UK i,1 ,UK i,2 ) is: S74, integrity check: The drone checks the validity of the ciphertext according to the verification formula. If the verification is successful, it returns the message m. The expression of the verification formula is: Where, κ'1∥κ'2=H3(Y), Y=CT1·UK i,1 +CT2·UK i,2 -CT3.

7. A lightweight dynamic asymmetric group key agreement system for drone clusters implementing the method of claim 1, characterized in that: At least including key generation center, ground station, drone cluster and blockchain, The key generation center: consists of several servers and is responsible for generating the public parameters of the system and the complete public and private keys of the ground station and the drone cluster; The ground station is responsible for receiving information transmitted by the drone and performing mission planning. Each ground station pre-calculates an initial table and uploads it to the blockchain account book. It has the authority to write and update the account book and can execute smart contracts. The drone cluster: is assigned to different subgroups according to different tasks. As an off-chain node, it only has read permissions and can join or leave tasks at any time as needed; The blockchain: All ground stations constitute a permissioned blockchain to host system public parameters and initial tables. The list is updated when a node joins or leaves the cluster. The smart contract automatically calculates and updates the asymmetric group encryption key and auxiliary data of the drone cluster, and publishes announcements using smart contracts.

Citation Information

Cited By

  • Lightweight and privacy-protected unmanned aerial vehicle group authentication and group key updating method

    CN120282136A

  • Lightweight distributed anonymous bidirectional authentication method for unmanned aerial vehicle under assistance of block chain

    CN120321650A

  • Block chain-based Web3.0 system registration method and spatial information network system

    CN121486808A