Lightweight distributed anonymous bidirectional authentication method for unmanned aerial vehicle under assistance of block chain

The blockchain-assisted lightweight distributed authentication method for UAVs addresses computational and communication limitations by using smart contracts and combining PUFs with fuzzy extractors, enhancing security and reducing overheads, thus optimizing UAV resource utilization and defense against attacks.

CN120321650AActive Publication Date: 2025-07-15ARMY ENG UNIV OF PLA

Patent Information

Application Number
CN202510796070.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-16
Publication Date
2025-07-15
Estimated Expiration
2045-06-16

AI Technical Summary

Technical Problem

The existing drone security authentication methods are inefficient when computing and communication resources are limited, and centralized base stations are prone to single point failure, which fails to effectively prevent unauthorized drones from accessing sensitive information.

Method used

The blockchain-assisted lightweight distributed anonymous two-way authentication method is adopted to realize permission control through smart contracts, and combine physical non-clone functions and fuzzy extractor technology to ensure the decentralization of information security storage and authentication processes, reducing computing and communication overhead.

Benefits of technology

It significantly improves the computing and communication resource utilization rate of drones, prevents centralized single point failure, improves authentication efficiency and security, and is suitable for drone equipment with resource-constrained.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120321650A_ABST
    Figure CN120321650A_ABST
Patent Text Reader

Abstract

The invention provides an unmanned aerial vehicle lightweight distributed anonymous bidirectional authentication method under the assistance of a block chain, and the method comprises the steps: firstly achieving the authority control through an intelligent contract disposed on the block chain, and guaranteeing that only an authorized entity can access secret information stored on the chain; then, a dynamic pseudonym mechanism is adopted, and the identity label and the session key of the unmanned aerial vehicle are updated in each session; besides, the physical unclonable function is combined with the fuzzy extractor, so that the inherent noise sensitivity problem of response of the physical unclonable function is effectively solved, and meanwhile, the security of the generated session key is kept. According to the invention, the problems of single-point fault and too high calculation / communication cost of a central ground station are solved, and the protocol does not have negative influence on the performance of the unmanned aerial vehicle because the unmanned aerial vehicle is equipment with limited calculation resources.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of unmanned aerial vehicle (UAV) communication security and blockchain, and particularly relates to a lightweight distributed anonymous two-way authentication method for UAVs assisted by blockchain. Background Technique

[0002] With the development of the low-altitude aviation intelligent network and the sixth-generation mobile communication (6G) era, UAVs have been widely used in daily life and the military field. UAVs not only have significant advantages such as low cost, small size, and light weight, but also perform well in terms of operation convenience, flexibility, environmental adaptability, and concealment performance. Based on the above advantages, UAVs play an important role in data collection fields such as remote sensing mapping, environmental monitoring, and agricultural monitoring. However, since UAVs communicate through public and insecure wireless channels, UAVs are vulnerable to various security threats, such as tampering attacks, replay attacks, etc. Therefore, the security issues of UAVs have been continuously concerned. 2. The existing security authentication methods mainly ensure data security by using complex encryption schemes. However, UAVs are resource-constrained devices, and it is difficult to run traditional encryption algorithms and store keys on UAVs. Therefore, how to ensure the security of communication and data transmission while controlling the performance cost of UAVs is crucial. The existing research mainly has the following three problems: 1. The limitations of UAVs in terms of computing and communication are not considered, resulting in the protocol having a negative impact on the performance of UAVs; 2. When performing security authentication through a base station (GS), the possible single-point failure problem of the centralized ground station is ignored; 3. During the security authentication process, due to the lack of detailed permission control over the information stored on the blockchain, unauthorized UAVs or base stations can illegally access sensitive information. Summary of the Invention

[0003] The present invention proposes a lightweight distributed anonymous two-way authentication method for UAVs assisted by blockchain.

[0004] The technical solution for achieving the purpose of the present invention is: a lightweight distributed anonymous two-way authentication method for UAVs assisted by blockchain, and the specific steps are as follows:

[0005] The UAV completes registration at the base station, and encrypts and stores the sensitive information generated during the registration process in the blockchain network;

[0006] Deploy a blockchain network with smart contract functions, and implement an automated execution mechanism through preset contract logic;

[0007] The UAV node sends a data packet containing identity authentication information and an encrypted request string to the base station;

[0008] After the base station receives the information, it verifies the digital identity of the UAV node. After successful authentication, it forwards the information to the target UAV node and simultaneously initiates an authentication request to the target UAV node.

[0009] After receiving the information from the base station, the target UAV node performs mutual authentication: after verifying the validity of the base station's identity, it generates a secure session key, returns an authentication response to the base station, and synchronously updates the session status on the blockchain.

[0010] The base station conducts a final verification on the response information of the target UAV node. After confirming the legitimacy of the identity, it completes the information relay.

[0011] After receiving the forwarded information, the sending UAV node ensures the security of the communication link by verifying the identity of the base station. Subsequently, it generates a session key and submits it for blockchain update, completing the entire secure session establishment process.

[0012] Compared with the prior art, the significant advantages of the present invention are as follows:

[0013] In the present invention, the sensitive information generated by identity authentication is distributed and stored in the blockchain network, and fine-grained access control is realized by using smart contracts, effectively solving the problem of centralized single-point failure existing in the traditional authentication system. In terms of the security mechanism design, the combination of the physically unclonable function (physically unclonable function response) and the fuzzy extractor technology significantly improves the anti-noise interference ability of the physically unclonable function response; at the same time, lightweight hash and exclusive-or operations and other efficient algorithms are adopted, so that the protocol can greatly reduce the computational and communication overhead while ensuring security, and is particularly suitable for resource-constrained Internet of Things devices. The present invention can not only significantly optimize the utilization rate of the computing and communication resources of UAVs, but also show excellent security protection performance in the face of various network attacks. It has significant advantages such as high authentication efficiency and low deployment cost, and has broad application prospects in scenarios such as UAV group authentication and Internet of Things secure access.

[0014] The following further describes the present invention in detail with reference to the accompanying drawings. Description of the Drawings

[0015] Figure 1 It is a basic scenario diagram of blockchain-assisted UAV security authentication.

[0016] Figure 2 It is a flowchart of mutual authentication and key negotiation between the sending UAV node UAVi and the target UAV node UAVj.

[0017] Figure 3 It is a comparison diagram of the time consumption of the sending UAV node with the increase in the number of messages.

[0018] Figure 4 It is a comparison diagram of the time consumption of the base station with the increase in the number of messages.

[0019] Figure 5 It is a comparison chart of the time consumption of the target UAV / user node with the increase in the number of messages. Specific implementation manner

[0020] A lightweight distributed anonymous two-way authentication method for UAVs assisted by blockchain. First, permission control is achieved through smart contracts deployed on the blockchain to ensure that only authorized entities can access the secret information stored on the chain. Then, a dynamic pseudonym mechanism is adopted, and the UAV identity identifier and session key are updated for each session. In addition, the combination of a physical unclonable function and a fuzzy extractor effectively solves the problem of the inherent noise sensitivity of the physical unclonable function response while maintaining the security of the generated session key. This method overcomes the single-point failure problem and the excessive computing / communication cost problem existing in the centralized ground station. And since UAVs are devices with limited computing resources, the protocol will not have a negative impact on the performance of UAVs. According to the security analysis, it is confirmed that the protocol can effectively resist various attacks, and the proposed protocol can effectively reduce the computing and communication overhead, enabling the protocol to maintain secure and reliable communication in resource-constrained UAV networks. The present invention includes the following steps:

[0021] (1) The UAV completes the registration process at the base station, and the sensitive information generated during the registration process is encrypted and stored in the blockchain network to ensure the data cannot be tampered with; (2) Deploy a blockchain network with smart contract functions, and implement an automated execution mechanism through preset contract logic, significantly reducing the need for human intervention and operation risks; (3) The sending UAV node UAVi sends a data packet containing identity authentication information and an encrypted request string to the ground station base station; (4) After receiving the information, the base station first verifies the digital identity of the sending UAV node UAVi. After successful authentication, the information is securely forwarded, and at the same time, an authentication request is initiated to the target UAV node UAVj; (5) After receiving the base station information, the target UAV node UAVj performs two-way authentication: after verifying the validity of the base station identity, a secure session key is generated, an authentication response is returned to the base station, and the session status is synchronously updated on the blockchain; (6) The base station finally verifies the response information of the target UAV node UAVj, and completes the information transfer after confirming the identity legality; (7) After receiving the forwarded information, the sending UAV node UAVi ensures the security of the communication link by verifying the base station identity, then generates a session key and submits it to the blockchain for update, completing the entire secure session establishment process. The specific implementation process is as follows:

[0022] Step 1: The UAV completes the registration process at the base station, encrypts the sensitive information generated during the registration process, and stores it in the blockchain network to ensure the data cannot be tampered with.

[0023] Such as Figure 1The figure shows the basic scenario diagram of blockchain-assisted UAV security authentication. Through the distributed characteristics of the blockchain, the automated execution of smart contracts, and a strict permission management mechanism, this model constructs a secure and reliable UAV authentication service platform. The main body of the model mainly consists of blockchain nodes, base stations, and UAVs. The blockchain nodes are deployed on cloud servers, jointly managing and maintaining a blockchain ledger, and at the same time providing services for UAVs and base stations that execute tasks. UAVs and base stations only act as light clients, interacting with the blockchain through smart contracts without the need to synchronize the entire chain data, ensuring that even when UAVs and base stations are attacked, attackers cannot obtain the secret information stored on the blockchain, effectively guaranteeing data security. When UAVs and base stations modify the ledger information stored on the chain through smart contracts, it will trigger the consensus mechanism of blockchain nodes. Only after the node network reaches a consensus verification can the modified information be written on the blockchain, ensuring the anti-counterfeiting and traceability of the authentication service.

[0024] Before deployment, the UAV needs to be registered on the base station. The registration process is as follows:

[0025] (1) The UAV node UAVi randomly generates a challenge , and generates the required physical unclonable function response ;

[0026] (2) The UAV node UAVi takes the physical unclonable function response and the real name as the input of the hash function, and jointly outputs the pseudonym used by the UAV node UAVi during the communication process, that is: ;

[0027] (3) The UAV node UAVi sends to the base station, where represents the hardware information of the UAV, such as the chip serial number, sensor identifier, etc. (each corresponding to a UAV is different). The UAV node UAVi stores in the database;

[0028] (4) The base station stores the information received from the UAV node UAVi on the blockchain in the form of a tuple;

[0029] (5) The registration phase of the target UAV node UAVj is the same as the above process.

[0030] Step 2: Deploy a blockchain network with smart contract functions, and implement an automated execution mechanism through preset contract functions, significantly reducing the need for human intervention and operational risks.

[0031] Blockchain technology is widely used in the financial and information security fields due to its characteristics of being tamper-proof and decentralized. These characteristics of blockchain make it of great value in scenarios where data needs to be permanently reliable and historical data cannot be changed or deleted. Ganache and Truffle are used as prototypes to build a test environment. The specific architecture is as follows:

[0032] (1) On-chain storage of sensitive information: UAV nodes and base stations use blockchain’s distributed ledger technology to store secret information generated during registration and authentication in the form of transaction records in a persistent manner in the blockchain’s data structure. Each blockchain node maintains a complete copy of the ledger to ensure data redundancy and consistency.

[0033] (2) Smart contract-driven access control: Base stations and drone nodes implement fine-grained access control on data on the blockchain by calling smart contracts. For example, only authorized entities (such as certified drone nodes) are allowed to trigger updates to their own information and access operations on chain information. At the same time, smart contracts can be automatically executed according to the defined contract logic without manual operation, greatly reducing the risk of human intervention.

[0034] (3) Verification architecture ensures data integrity: Any request for change or deletion of information by the base station and drone nodes will trigger the node consensus verification, rejecting illegal operations by users who are not registered on the blockchain. After the transaction passes the verification, a new block will be generated, which will be connected to the main chain after hash linking, making the authentication information between the drone node and the base station tamper-proof and traceable.

[0035] Smart contracts are deployed in the authentication and key negotiation protocols to provide decentralized auxiliary authentication services for drone nodes and base stations. The basic functions of smart contracts deployed in the blockchain are as follows: Figure 2 As shown, the contract functions preset by the smart contract are described in detail below:

[0036] (1) registerUAV: This function can only be called by ground station (base station) nodes that have been registered on the blockchain. It is used to implement the registration function of drone node devices;

[0037] (2) UpdateMempool: This function performs the transaction pool information update operation and can only be called by base stations / drones registered in the blockchain. The system will implement a double verification mechanism for the caller: when an unregistered base station initiates a request, an authorization failure response will be returned; if a malicious drone node is detected attempting to operate, the transaction execution will be forcibly terminated;

[0038] (3) QueryMempool: As an information query interface for the blockchain transaction pool, this function adopts an access control policy based on registered identities. It returns a valid query result only when the requester is a legally registered base station or drone node. When an unauthenticated user initiates a request, a query failure protocol will be triggered;

[0039] (4) UpdateBlockchain: This function implements the exclusive data update operation of the blockchain and is strictly limited to being called only by registered drone nodes. It mainly realizes the following functions: update the and data stored in the blockchain after completing the authentication process; adopt a timestamp synchronization recording mechanism to ensure the traceability of operations; implement a data version control policy (marking old data as invalid); bind the node identity with the operation permission, and only allow updating its own data to prevent malicious nodes from tampering with the blockchain information;

[0040] (5) QueryBlockchain: A blockchain data query function. The system implements access control by verifying the registration status of the requesting node, and an unregistered node will trigger a query failure response mechanism;

[0041] (6) revokeBlockchainByPID: This function is a security management function that grants operation permissions to registered base stations. When the system detects that a drone node has been hijacked or exhibits malicious behavior characteristics, the base station executes a credential revocation operation through this function, thereby excluding the invaded device from the authentication system and ensuring the overall security of the system;

[0042] Step 3: The drone node UAVi sends a data packet containing identity authentication information and an encrypted request string to the ground station base station.

[0043] The sending drone node UAVi will respond As the input of the fuzzy extractor, output the key , that is , where represents the generated auxiliary data, is the generated key. To ensure the security of the transmitted key, the auxiliary data needs to be encrypted for transmission, and the encrypted value . The sending drone node UAVi generates a random number and a request string , and at the same time requests the pseudonym of the communication object from the blockchain , and then calculates the first message and the second message : , . ​​​​​​​​

[0044] Send to the base station, and at the same time record the hash value of this information in a transaction pool on the blockchain and mark the above hash value as the to-be-verified state.

[0045] Step 4: After the base station receives the information, it first verifies the digital identity of the sending UAV node UAVi. After successful authentication, it forwards the information to the target UAV node UAVj and initiates an authentication request to the target UAV node UAVj.

[0046] Figure 2 It is a flowchart for mutual authentication and key negotiation between the sending UAV node UAVi and the target UAV node UAVj. Next, the steps for UAVs to perform identity verification and key establishment will be introduced in detail.

[0047] After the base station receives the information, it queries the information of the sending UAV node UAVi from the blockchain . Calculate the decrypted auxiliary data , and through the key of the sending UAV node UAVi can be calculated , decrypt the message to obtain the decrypted request string , random number and the hardware information of the sending UAV . Compare the hardware information of the sending UAV obtained from the chain with the decrypted hardware information of the sending UAV , then obtain the stored data from the blockchain , calculate the message according to the decrypted data, verify and whether they are equal, and at the same time verify whether the to-be-verified message in the transaction pool is consistent with the received message. If both are equal, it means the message verification is successful; otherwise, the message will be discarded.

[0048] If the message verification is successful, the base station generates a random number , and calculates the message to be sent , , and : , , , Send to the target UAV node UAVj, and at the same time record the hash value of this information in the transaction pool on the blockchain, marked as the state of being verified and waiting to be forwarded.

[0049] Step 5: After receiving the base station information, the target UAV node UAVj performs mutual authentication: after verifying the validity of the base station identity, it generates a secure session key, returns an authentication response to the base station, and synchronously updates the session status on the blockchain.

[0050] After the target UAV node UAVj receives the message sent by the base station, it first calculates the PUF response according to the challenge calculate the PUF response , and then calculate the decrypted pseudonym , the random number generated by the sending UAV , the random number generated by the base station , and the message : , , , , verify whether the calculated is the same as the received , and at the same time verify whether it is the same as the information in the transaction pool. If both are the same, the message verification is successful; otherwise, the message is discarded.

[0051] If the message verification is successful, the target UAV node UAVj calculates the key through the fuzzy extractor function . To ensure the security of the transmitted key, the auxiliary data needs to be encrypted for transmission, and the encrypted value . The target UAV node UAVj generates a random number , and at the same time generates a new physical unclonable function challenge . According to , generate the corresponding physical unclonable function response: . Then calculate the message , , and the newly generated pseudonym : , , . Send to the base station, and calculate the session key: . Record the hash of the session key in the transaction pool of the blockchain and mark it as the key generation status. Store the new physical unclonable function challenge and the newly generated pseudonym in the database. At the same time, update the newly generated pseudonym and the newly generated response in the blockchain.

[0052] Step 6: The base station performs a final verification on the response information of the target UAV node UAVj, and completes the information transfer after confirming the identity legality.

[0053] After the base station receives the message of the target UAV node UAVj, it calculates the decrypted auxiliary data , from the auxiliary data the key of the target UAV node UAVj can be obtained . Decrypt the received message to obtain the random number generated by the decrypted target UAV node UAVj , the decrypted response and the hardware information of the decrypted target UAV node UAVj . Compare the obtained from the chain with the decrypted , then calculate the message according to the decrypted data , verify the calculated is the same as the received message , and at the same time verify whether it is the same as the key generation information in the pool. If both are the same, the message verification is successful; otherwise, the message is discarded.

[0054] If the message verification is successful, the base station generates a random number , and calculates the message to be sent and : , , send to the sending UAV node UAVi, and at the same time update the hash value of this information to the blockchain transaction pool and mark it as the key transfer status.

[0055] Step 7: After receiving the forwarded information, the sending UAV node UAVi ensures the security of the communication link by verifying the identity of the base station, then generates a session key and submits a blockchain update to complete the entire secure session establishment process.

[0056] After the sending UAV node UAVi receives the message sent by the base station, the sending UAV node UAVi decrypts the received message to obtain the random number generated by the decrypted base station and the random number generated by the target UAV , then calculate the message according to the decrypted data , verify the calculated message is the same as the received message , and at the same time verify whether the key transfer information in the transaction pool is the same as the calculation result. If both are the same, the message verification is successful; otherwise, the message is discarded.

[0057] If the message verification is successful, the sending UAV node UAVi calculates the session key: , then send the UAV node UAVi to generate a new physical unclonable function challenge , calculate the new response , new pseudonym , the newly generated challenge and the new pseudonym are stored in the database, and the new pseudonym and the newly calculated in the blockchain are updated, verify whether they are the same as the session key hash value in the transaction pool, and at the same time update the status of the transaction pool on the blockchain to the completed state.

[0058] Through the above steps, the sending UAV node UAVi and the target UAV node UAVj have authenticated each other, and the session key for subsequent secure communication has been successfully established.

[0059] Performance evaluation:

[0060] Computational overhead: In this part, the present invention will compare and analyze the computational overhead of the above protocol with existing protocols. Let represent hash function, hash-based message authentication operation, physical unclonable function operation, symmetric encryption / decryption operation, multiplication operation and addition operation on an elliptic curve respectively. When performing the above operations, the libraries such as pycrypto and hashlib in Python are used. hashlib is one of the standard libraries of Python, which provides a series of common hash algorithms, such as MD5, SHA-1, SHA-256, etc. Hash algorithms can convert data of any length into a hash value of a fixed length, which is usually used in scenarios such as data encryption and data integrity verification; while pycrypto is a powerful third-party encryption library, which provides a variety of classical and modern encryption algorithms, such as AES, RSA, Diffie-Hellman key exchange, etc. They each provide different encryption tools and functions. The processing results are 0.001, 0.088, 0.015, 0.05, 0.632 and 0.016 ms respectively.

[0061] Taking the protocol proposed by the present invention as an example for calculation, the sending UAV node UAVi uses the hash 6 times, the physical unclonable function 2 times, and encryption / decryption 2 times; the base station uses the hash 9 times and encryption / decryption 3 times; the target UAV node UAVj uses the hash 9 times, the physical unclonable function 2 times, and encryption / decryption 1 time. Through calculation, the total computational overhead generated by the protocol during authentication is . The existing methods mainly include the following several types: , 1. Using multiplication operations on elliptic curves, 2. Using addition operations on elliptic curves, 3. Using chaotic maps and message authentication operations, 4. Using hash and exclusive-or functions, 5. Combining multiplication and addition operations on elliptic curves, etc. Compared with the above methods, the present invention integrates blockchain technology and solves problems such as single-point failures faced by these protocols. In the case of malicious behavior, the base station has the ability to trace the true identities of suspicious drone nodes. At the same time, the constructed blockchain provides access control for drone nodes, ensuring that only authorized drones or base stations can access the stored data. At the same time, drones and base stations do not store any sensitive information, effectively preventing the leakage of secrets caused by attacks on the base station and drones, and ensuring the security of the system.

[0062] The method using elliptic curve authentication uses and , resulting in a relatively high computational overhead. While the method proposed in the present invention uses lightweight hash and encryption / decryption operations, and has passed security tests. Also, the challenge-response of the physical unclonable function in the method proposed in the present invention is updated in each session to ensure forward security. Using chaotic maps and message authentication operations also leads to a higher computational overhead. The present invention uses a fuzzy extractor on the basis of the existing message authentication to reduce the noise that may be generated by the physical unclonable function, enhancing the security of the session key. The existing methods mainly using hash and exclusive-or do not update the credentials used during the session after each authentication, resulting in the easy leakage of the session key. While the method proposed in the present invention uses new credentials for authentication in each new session to ensure key security. For a detailed comparison of the computational overhead, see Table 1.

[0063] In addition, the computational overhead of the method proposed in the present invention still has significant advantages when the number of drones is very large. For example, in post-disaster reconstruction work, a large number of drones will be started simultaneously, resulting in a large amount of authentication information received by the base station and drones. Figures 3 - 5 Shows the comparison of the running time consumption for processing authentication messages on the sending drone node, base station, and target drone node / target user node compared with the existing methods. The present invention is more effective than the existing protocols for authentication message generation and key negotiation between drones. Therefore, the present invention performs well in terms of computational overhead.

[0064] Table 1 Comparison of Computational Overhead

[0065] Solution Transmitting UAV Node (ms) Base Station (ms) Target UAV / User Node (ms) Total (ms) Existing Method 1 <![CDATA[10T h +3T Ecm +T f > <![CDATA[12T h +T Ecm > <![CDATA[9T h +T f +2T Ecm > 3.853 Existing Method 2 <![CDATA[6T h +3T Ecm +T Eca > <![CDATA[8T h +4T Ecm +2T Enc > <![CDATA[4T h +3T Ecm > 6.454 Existing Method 3 <![CDATA[4T h +7T Enc +T f +4T m > <![CDATA[13T Enc +6T m +2T h > <![CDATA[2T h +7T Enc +T f +2T m > 2.444 Existing Method 4 <![CDATA[4T h +3T Enc +T f > <![CDATA[4T Enc +T h > <![CDATA[4T h +3T Enc +T f > 0.539 Existing Method 5 <![CDATA[6T h +5T Ecm +2T Eca > <![CDATA[4T h +T Ecm +T Eca > <![CDATA[5T h +7T Ecm +5T Eca > 8.359 Proposed Method <![CDATA[6T h +2T Enc +2T f > <![CDATA[9T h +3T Enc > <![CDATA[9T h +T Enc +2T f > 0.384

[0066] Communication overhead: To calculate the communication cost of the present invention, it is considered that the random number, pseudonym, hash output, encryption and decryption (considering the Advanced Encryption Standard AES), points on the elliptic curve, and timestamp are 128, 160, 160, 128, 160, and 32 bits respectively. In the method proposed in the present invention, a total of 4 messages are exchanged, namely: , , and , where is 128 bits, and the rest are all 160 bits. After calculation, the communication overhead of the method proposed in the present invention can be obtained as 1824 bits. The communication overhead of the existing protocol can also be calculated, as shown in Table 2. Although the communication overhead generated by the method mainly using hash and exclusive-or functions in the existing protocol is the smallest, this method has defects in terms of security performance. The communication overhead of the method proposed in the present invention is reduced by 52.6%, 59.6%, 29.8%, and 38.6% respectively compared with other existing protocols. It can be seen that the overall performance of the protocol proposed in this paper is good.

[0067] Table 2 Comparison of communication overhead

[0068] Solution Message 1 Message 2 Message 3 Message 4 Message 5 Message 6 Communication Overhead (bits) Existing Method 1 992 672 640 480 - - 2784 bits Existing Method 2 512 1024 672 704 - - 2912 bits Existing Method 3 416 288 416 544 416 288 2368 bits Existing Method 4 736 608 400 - - - 1744 bits Existing Method 5 672 1024 832 - - - 2528 bits Proposed Method 448 640 448 288 - - 1824 bits

Claims

1. A lightweight distributed anonymous two-way authentication method for drones assisted by blockchain, characterized in that The specific steps are: The drone completes registration at the base station, and the sensitive information generated during the registration process is encrypted and stored in the blockchain network; Deploy a blockchain network with smart contract functions and implement an automated execution mechanism through preset contract logic; The drone node sends a data packet containing identity authentication information and an encrypted request string to the base station; After receiving the information, the base station verifies the digital identity of the drone node. After the authentication is passed, the base station forwards the information to the target drone node and initiates an authentication request to the target drone node. After receiving the base station information, the target drone node performs two-way authentication: after verifying the validity of the base station identity, it generates a secure session key, returns an authentication response to the base station, and synchronously updates the session status on the blockchain; The base station conducts final verification of the response information of the target drone node and completes the information transfer after confirming the legitimacy of the identity; After receiving the forwarded information, the sending drone node ensures the security of the communication link by verifying the identity of the base station, then generates a session key and submits the blockchain update to complete the entire secure session establishment process.

2. The lightweight distributed anonymous mutual authentication method for drones assisted by blockchain according to claim 1, characterized in that, The specific process for drones to complete registration at the base station is as follows: (1) The sending drone node randomly generates a challenge and generates a physical unclonable function response . The specific formula is: , PUF is the physical unclonable function; (2) The sending UAV node sends the physical unclonable function response and the true name as the input of the hash function, and jointly outputs the pseudonym used by the sending UAV node UAVi during the communication process , that is: ; (3) The sending drone node will send it to the base station, where represents the hardware information of the drone, and the sending drone node stores it in the database; (4) The base station stores the information received from the sending drone node in the form of a tuple on the blockchain.

3. The lightweight distributed anonymous two-way authentication method for drones assisted by blockchain according to claim 1, characterized in that, The specific process of the drone node sending a data packet containing identity authentication information and an encrypted request string to the base station is as follows: The sending UAV node UAVi will respond As the input of the fuzzy extractor, determine the secret key, that is , where represents the generated auxiliary data, is the generated secret key; Encrypt and transmit the auxiliary data to obtain the encrypted auxiliary data ; The sending UAV node UAVi generates a random number and a request string , and simultaneously requests the pseudonym of the communication object from the blockchain ; Calculate the first message sent and the second message : , ; Send to the base station, and at the same time record the hash value of in a transaction pool on the blockchain and mark the hash value as a status to be verified.

4. The lightweight distributed anonymous two-way authentication method for drones assisted by blockchain according to claim 3, wherein, The encrypted auxiliary data specifically is .

5. The lightweight distributed anonymous two-way authentication method for drones assisted by blockchain according to claim 3, characterized in that After the base station receives the information, the specific method of verifying the digital identity of the drone node is: After receiving the information, the base station queries the information of the sending UAV node UAVi from the blockchain ; Calculate the decrypted auxiliary data , through the auxiliary data after decryption Calculate the key for sending the drone node UAVi , the first message Decrypt to get the decrypted request string , random numbers And send the drone's hardware information ; The sending drone hardware information obtained from the chain is compared with the decrypted sending drone hardware information If they match exactly, the data stored in the blockchain is retrieved and the second decryption message is calculated based on the decrypted data and the second decryption message is verified to check if it is equal to the second message At the same time, it is verified whether the message to be verified in the transaction pool is consistent with the received message. If both are equal, it means the message verification is successful; otherwise, the message is discarded.

6. The lightweight distributed anonymous two-way authentication method for drones assisted by blockchain according to claim 5, characterized in that, After the digital identity authentication of the drone node is passed, the information is forwarded to the target drone node, and the specific process of initiating an authentication request to the target drone node is as follows: The base station generates a random number and calculates the third message to be sent , the fourth message , the fifth message and the sixth message : , , , ; Send to the target UAV node UAVj, and at the same time record the hash value of in the transaction pool on the blockchain, marked as the state of being verified and waiting to be forwarded.

7. The lightweight distributed anonymous mutual authentication method for drones assisted by blockchain according to claim 6, characterized in that, The specific process of the target drone node performing two-way authentication after receiving the base station information is as follows: After the target UAV node UAVj receives the message sent by the base station, it calculates the PUF response according to the challenge Calculate the PUF response ; Calculate the kana after decryption , the random number generated by the sending drone , the random number generated by the base station and the sixth decryption message : , , , , Verify the calculated is the same as the received at the same time, verify whether it is the same as the information in the transaction pool. If both are the same, the message verification is successful; otherwise, the message is discarded. If the message verification is successful, the target UAV node UAVj calculates the key through the fuzzy extractor function , specifically ; Encrypt and transmit the auxiliary data The encrypted value The target UAV node UAVj generates a random number At the same time, a new physical unclonable function challenge is generated According to Generate the corresponding physical unclonable function response: ; Calculate the seventh message to be sent , the eighth and the newly generated kana : , , , and send to the base station, and calculate the session key: , record the hash of the session key into the transaction pool of the blockchain, and mark it as the key generation status; New Physical Unclonable Function Challenges and newly generated pseudonyms are stored in the database. Meanwhile, the newly generated pseudonyms and newly generated responses in the blockchain are updated.

8. The lightweight distributed anonymous two-way authentication method for unmanned aerial vehicles assisted by blockchain according to claim 7, wherein The base station conducts final verification of the response information of the target drone node and completes the information transfer after confirming the legitimacy of the identity. The specific method is as follows: After the base station receives the message of the target UAV node UAVj, it calculates the decrypted auxiliary data , from the auxiliary data the key of the target UAV node UAVj is obtained ; Decrypt the received seventh message to obtain the random number generated by the decrypted target UAV node UAVj , the decrypted response and the decrypted hardware information of the target UAV node UAVj ; The one obtained from the chain is compared with the decrypted , and the message is calculated according to the decrypted data . Verify the calculated is the same as the received message . At the same time, verify whether it is the same as the key generation information in the pool. If both are the same, the message verification is successful; otherwise, the message is discarded. If the message verification is successful, the base station generates a random number , and calculates the ninth message to be sent and the tenth : , ; Send to the sending UAV node UAVi, and at the same time update the hash value of to the blockchain transaction pool and mark it as the key transfer status.

9. The lightweight distributed anonymous two-way authentication method for drones assisted by blockchain according to claim 8, characterized in that After receiving the forwarded information, the sending drone node ensures the security of the communication link by verifying the identity of the base station, then generates a session key and submits the blockchain update. The specific method to complete the entire secure session establishment process is as follows: After receiving the message sent by the base station, the sending UAV node UAVi will forward the received message to decrypt and obtain the random number generated by the base station after decryption and the random number generated by the target UAV ; Calculate the tenth decryption message based on the decrypted data , verify the tenth decryption message with the received tenth message to check if they are the same. At the same time, verify if the key transfer information in the transaction pool is the same as the calculation result. If both are the same, the message verification is successful; otherwise, discard the message. If the message verification is successful, the sending UAV node UAVi calculates the session key: ; The sending UAV node UAVi generates a new physical unclonable function challenge , calculates a new response , a new pseudonym , and will generate the new challenge and the new pseudonym are stored in the database. The new pseudonym in the blockchain and the newly calculated are updated, verify whether they are the same as the session key hash value in the transaction pool, and at the same time update the status of the transaction pool on the blockchain to the completed state.

Citation Information

Patent Citations

  • Lightweight dynamic security association double-layer unmanned aerial vehicle block chain construction method and device

    CN118843114A

  • Extensible unmanned aerial vehicle Internet of Things authentication key negotiation method

    CN119906995A

  • Lightweight dynamic asymmetric group key negotiation method and system for unmanned aerial vehicle cluster

    CN120111486A

Cited By

  • Mobile intelligent node lightweight identity authentication method based on block chain

    CN120602087A

  • Blockchain-based mobile intelligent node lightweight identity authentication method

    CN120602087B