Certificateless FANET distributed authentication and key management method and system

Through the key distribution method of drone registration in ground center and drone management nodes collaboratively, the inefficiency of key configuration and dynamic network access in the drone cluster is solved, and efficient and secure key management and dynamic network access authentication is achieved, which is suitable for drone cluster security guarantee in complex scenarios.

CN120434641AActive Publication Date: 2025-08-05NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510557429.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-29
Publication Date
2025-08-05
Estimated Expiration
2045-04-29

AI Technical Summary

Technical Problem

The existing technology is difficult to efficiently complete key configuration and dynamic network access authentication in a drone cluster environment, and cannot meet the security needs in complex scenarios. Especially when the number of drone clusters is large, the motion trajectory is complex, the task preparation time is short, and the network topology changes quickly, the traditional methods are inefficient and the calculation and communication cost are high.

Method used

A certificate-free FANET distributed authentication and key management method is designed, including the drone registering and obtaining legal certificates in the ground center, obtaining key permissions through the drone management node, and performing key distribution and group key distribution before the task. It adopts batch wireless injection based on secret sharing and aggregation access authentication protocol without certificate signature to achieve efficient key configuration and dynamic network access.

Benefits of technology

It improves the efficiency of key configuration before task execution, ensures the security of task key injection and dynamic network entry processes before task execution, and is suitable for security guarantees of large-scale drone clusters, can resist attacks and quickly respond to topological changes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120434641A_ABST
    Figure CN120434641A_ABST
Patent Text Reader

Abstract

The invention discloses a certificateless FANET distributed authentication and key management method and system, and relates to an unmanned aerial vehicle and data security technology, and the method comprises the steps: enabling the unmanned aerial vehicle to be registered in a ground center, so as to obtain a legal certificate for indicating the identity of the unmanned aerial vehicle; under the condition that the cooperative task is executed, the unmanned aerial vehicle management node sends a task demand and a legal proof to a ground center so as to obtain an air dense management permission; before the cooperative task is executed, task key distribution between the unmanned aerial vehicle and the unmanned aerial vehicle management node is controlled; and after the task key is distributed, unmanned aerial vehicle network access and group key distribution and updating are completed based on the unmanned aerial vehicle management node. According to the method, the key configuration efficiency before task execution can be improved, the safety of the processes of task key injection before task execution, dynamic network access in task execution and the like is ensured, and a technical basis is provided for the safety guarantee of the FANET based on the unmanned aerial vehicle cluster.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the fields of drones and data security technology, and in particular to a certificateless FANET distributed authentication and key management method and system. Background Art

[0002] With the rapid development of information technology, drones have received widespread attention and application in military and civilian fields such as real-time monitoring, traffic management, aerial base stations, and reconnaissance operations due to their low cost, easy deployment, and freedom from complex geographical restrictions. They are widely regarded by academia and industry as one of the important technologies in emerging application fields such as future intelligent transportation, unmanned combat, and mobile edge computing.

[0003] In recent years, with the continuous expansion of business scenarios and increasing mission requirements, single drones, limited by their own resources, have been unable to meet the growing business demands. To address this issue, FANET technologies for multi-drone swarms have been proposed. FANETs based on drone swarms offer wide mission coverage and strong execution capabilities, effectively addressing the bottleneck problem of mission failure caused by single drone failures. FANETs based on drone swarms primarily rely on wireless links to interconnect massive drones. These open wireless communication links and uncontrolled deployment environments pose risks of eavesdropping, tampering, interception, forgery, and impersonation. Authentication and key management are crucial for ensuring drone network security, but traditional methods are not well suited for FANETs based on drone swarms. FANETs based on drone swarms are characterized by a large number of nodes, complex motion trajectories, short mission preparation times, rapidly changing network topologies, and a highly hostile mission environment. These challenges present unprecedented challenges for existing authentication and key management technologies.

[0004] To ensure that the FANET based on drone clusters can safely and efficiently complete collaborative tasks in complex scenarios, the following two aspects need to be considered.

[0005] Mission key injection problem. Considering the possibility of drones being captured in complex confrontation scenarios, in order to ensure safety, drones need to inject the mission keys involved into the device in advance before each mission. Traditionally, in single or small-scale drone mission scenarios, the main method used is manual one-to-one injection by key injection equipment. The biggest feature of drone clusters is the large number of nodes, long security cycle, and low efficiency. Traditional means with a single method are difficult to meet the key security needs in cluster collaborative mission scenarios. Although there are a large number of mature key distribution and injection mechanisms in wired networks, due to the special self-organizing network architecture of drone clusters, as well as the requirements for anti-destruction and persistence and short-term batch injection, they cannot be well applied to drone environments.

[0006] Dynamic network access authentication and key update issues. To achieve secure collaboration of massive drone nodes in complex mission scenarios, it is necessary to securely authenticate the nodes entering the network to build a secure and reliable group communication link to protect business data transmission. Research on security authentication technology is now quite mature. Solutions based on symmetric cryptography have the advantages of small key size and low algorithm computational complexity. However, such solutions have difficulty implementing message signatures, do not support advanced security properties, and have a large key management and storage burden. Solutions based on public key cryptography can effectively achieve highly secure direct authentication between entities, provide advanced security properties such as anonymity, non-repudiation, and unlinkability, and can resist denial of service attacks and man-in-the-middle attacks. However, due to the lack of effective aggregated authentication methods, the above solutions are not well suited for drone cluster environments. Group authentication based on aggregated algorithms is an important means to solve group authentication problems in massive terminal environments. It can effectively simplify the group member identity verification process, reduce network communication costs, and avoid signaling congestion. However, FANET based on drone clusters has the characteristics of strong group dynamics and rapid topological changes. The group merging and splitting processes require timely key management after the topological structure changes. However, the above scheme has the problems of high computational and communication costs in the key update and distribution process, and difficult maintenance of the revocation list. Summary of the Invention

[0007] The embodiments of the present application provide a certificateless FANET distributed authentication and key management method and system, which improves the efficiency of key configuration before task execution, ensures the security of processes such as task key injection before task execution and dynamic network access during task execution, and provides a technical foundation for the security of FANET based on drone clusters.

[0008] The present invention provides a certificateless FANET distributed authentication and key management method, which is applied to the identity authentication and key management of a drone cluster, including the following steps:

[0009] Register the drone at a ground center to obtain legal proof of its identity;

[0010] In the case of collaborative missions, the UAV management node sends the mission requirements and legal proof to the ground center to obtain air confidentiality management authority, where the UAV management node is the designated UAV in the cluster;

[0011] Before executing the collaborative task, the task key is distributed between the control drone and the drone management node;

[0012] After the mission key is distributed, the drone network access and group key distribution and update are completed based on the drone management node.

[0013] The present application provides a certificateless FANET distributed authentication and key management system, which is applied to the identity authentication and key management of a drone cluster, wherein the drone cluster includes drones and a drone management node, and the drone cluster establishes a communication connection with a ground center;

[0014] The drone cluster and ground center include a processor and a memory, and the memory stores a computer program. When the computer program is executed by the processor, it collaboratively implements the steps of the aforementioned certificateless FANET distributed authentication and key management method.

[0015] The method of the embodiment of the present application can improve the efficiency of key configuration before task execution, ensure the security of processes such as task key injection before task execution and dynamic network access during task execution, and provide a technical basis for the security of FANET based on drone clusters.

[0016] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Various other advantages and benefits will become apparent to those skilled in the art upon reading the detailed description of the preferred embodiment below. The accompanying drawings are for illustration purposes only and are not to be considered as limiting the present application. The same reference symbols are used throughout the drawings to represent the same components. In the drawings:

[0018] Figure 1 The following is a basic flow chart of the certificateless FANET distributed authentication and key management method according to an embodiment of the present application. DETAILED DESCRIPTION

[0019] Exemplary embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although exemplary embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. Rather, these embodiments are provided to enable a more thorough understanding of the present disclosure and to fully convey the scope of the present disclosure to those skilled in the art.

[0020] This application addresses the security protection needs of drone swarms in complex mission scenarios and proposes an identity authentication and key management security solution suitable for large-scale drone swarms. The solution mainly includes the following aspects:

[0021] 1. Based on the construction of a new multi-layer distributed management architecture, a batch wireless injection method of mission keys based on secret sharing is designed to complete the key configuration of massive drone nodes in parallel;

[0022] 2. Design an authentication and key management protocol based on certificateless signature and aggregatable access;

[0023] 3. Propose a key distribution method that efficiently responds to topology changes. As a basic cryptographic protocol, this protocol can be applied to scenarios with a large number of terminals, fast mobility, and complex network heterogeneity, such as unmanned swarms and Internet of Vehicles, to protect communication security and improve cryptographic protection capabilities.

[0024] The embodiment of the present application provides a certificateless FANET distributed authentication and key management method, which is applied to the identity authentication and key management of drone clusters, mainly including initialization and node registration, drone mission key configuration, drone network access authentication and group key distribution. Figure 1 As shown, the following steps are included:

[0025] In step S101, the UAV is registered at the ground center KGC to obtain a legal certificate AUTH for indicating its identity.

[0026] In step S102, in the case of performing a collaborative task, the UAV management node sends the task requirements and legal proof to the ground center KGC to obtain air confidentiality management authority, where the UAV management node is the designated UAV in the cluster.

[0027] In step S103, before executing the collaborative task, the task key is distributed between the control drone and the drone management node.

[0028] In step S104, after the mission key is distributed, the drone network access and group key distribution and update are completed based on the drone management node.

[0029] In some embodiments, the system initialization and node registration steps further include: the ground center KGC performs the following initialization process:

[0030] Choose large prime numbers p and q, and E / Fp is an elliptic curve over a finite field;

[0031] Select a generator P of order q on E / Fp to generate a cyclic group G;

[0032] choose As the master key, calculate the public key P pub =x·P.

[0033] In some embodiments, the drone registration step includes:

[0034] Drone random selection Calculate S i =s i P is sent to KGC as a certificate;

[0035] At the center of the ground, randomly select Calculate R i =r i P, ID i =H(S i ,R i ), AUTH i =ID i ×x+r i , and set AUTH i , R i Send to drone;

[0036] Drone receives AUTH i , R i After that, verify the AUTH equation i P=H(S i ,R i )·P pub +R i Establish, calculate and save (ID i ,AUTH i ,R i ,s i ) to form legal proof.

[0037] In the UAV mission key configuration step, when a collaborative mission is required, the UAV management node sends the mission requirements and its own identity to the KGC to request airborne key management authority. In some embodiments, the UAV management node sends the mission requirements and legal proof to the ground center to obtain airborne key management authority, including:

[0038] According to the mission requirements, the ground center KGC first randomly generates the air authority value y, Calculate K pub =k·P,Y pub =y·P;

[0039] Select a distributed key management authority threshold value t and select a t-1 order polynomial. For example, select a suitable distributed key management authority threshold value t and select two t-1 order polynomials.

[0040] f(z)=y+a1z+a2z 2 +…+a t-1 z t-1

[0041] g(z)=k+b1z+b2z 2+…+b t-1 z t-1

[0042] Then calculate the secret management authority component x i =f(H(S i ,R i )),k i =g(H(S i ,R i )) and pass the permission component (y i ,k i ) is injected into the drone management node.

[0043] A distribution key table is generated at the ground center, and the distribution key table contains m mutually prime keys dk1…dk m , corresponding to the m UAVs in this collaborative mission.

[0044] In some embodiments, the task key distribution step between the control drone and the drone management node includes:

[0045] Before the mission is executed, start the UAV i Follow the steps below to obtain the key:

[0046] calculate C i =c i P, and send it to the UAV management node (such as U j )Send task key request (AUTH i ,S i ,R i ,C i );

[0047] After receiving the request, the drone management node verifies the equation AUTH i P=H(S i ,R i )·P pub +R i , verification passed, and calculated (key1, key2) = s j ×C i +S i ×c j ,psk i-j =H(ID i ,C i )×y j +k j ,CT i-j =E key1 (psk i-j ,tk i ), (AUTH j ,Sj ,R j ,C j ,CT i-j )Send to UAV U i ;

[0048] UAVU i Received (AUTH j ,S j ,R j ,C j ,CT i-j ) after verifying the equation AUTH j P=H(S j ,R j )·P pub +R j To confirm that it is a legitimate drone management node, if the verification is passed, (key1, key2) = s i ×C j +S j ×c i ,psk i-j ,tk i =D key1 (CT i-j );

[0049] On the received PSK i-j When the number meets the threshold, calculate

[0050] Save the task private key sk i =k+y×H(ID i ,C i )+H(ID i )×x+r i and dk i .

[0051] In some embodiments, the steps of drone network access authentication and group key distribution include:

[0052] Taking efficiency into consideration during the task execution process, multiple drone management nodes adopt a master-slave mode, determine the current master access point through broadcasting, and the master access point completes the drone network access and key distribution and update.

[0053] In some embodiments, completing drone network access and group key distribution and update based on the drone management node specifically includes:

[0054] When the drone is connected to the ad hoc network and cooperates with other drones, it uses its saved mission private key sk i Calculate and generate network access certificate V i =ski H(ID i ,E i ,T i )+e, where E i =e i ·P, send (V i ,ID i ,C j ,E i ,R i ,T i ) Go to the drone management node for network verification;

[0055] The drone management node of the main access point receives (V i ,ID i ,C j ,E i ,R i ,T i ), directly verify equation V i P = K pub +H(ID i ,E i ,T i )H(ID i ,C i )Y pub +H(ID i )H(ID i ,E i ,T i )P pub +

[0056] H(ID i ,E i ,T i )R i +E i .

[0057] In some embodiments, completing drone network access and group key distribution and update based on the drone management node specifically includes performing batch authentication in the following manner:

[0058]

[0059] Subsequent calculation of the group key token:

[0060] TOKEN=[DS1 ′ DS1(gkg,T)+…+DS ′ m DS m (gkg,T)](mod dk)

[0061] where dk = dk1dk2…dk n , DS′ i DS i =1(mod dk i ), gkg is the group key generation factor;

[0062] Send TOKEN and timestamp T to the drone;

[0063] The drone calculates gkg, T = TOKEN (mod dk i ), verify whether the received timestamps are consistent,

[0064] Calculate GK=KDF(gkg) as the group key for subsequent communications.

[0065] In some embodiments, the method further includes: when a group key update is required, adding or deleting a corresponding dk and recalculating a TOKEN to complete the group key update.

[0066] The secret sharing-based batch wireless injection method for mission keys designed in this application realizes efficient wireless injection of cryptographic resources suitable for drone clusters, can complete key configuration in batches during the mission preparation phase, and at the same time achieves a certain degree of anti-destruction capability based on the secret sharing algorithm.

[0067] The certificateless signature-based aggregatable dynamic access authentication protocol designed in this application realizes efficient and secure network access authentication in large-scale drone cluster scenarios, can effectively resist man-in-the-middle attacks, replay attacks, etc., and can prevent unauthorized drones from accessing the task group and obtaining any sensitive information.

[0068] The key distribution method designed in this application can effectively improve the group key distribution speed and achieve efficient response to topology changes.

[0069] The present application also proposes a certificateless FANET distributed authentication and key management system, which is applied to the identity authentication and key management of a drone cluster, wherein the drone cluster includes drones and a drone management node, and the drone cluster establishes a communication connection with a ground center;

[0070] The drone cluster and ground center include a processor and a memory, and the memory stores a computer program. When the computer program is executed by the processor, it collaboratively implements the steps of the aforementioned certificateless FANET distributed authentication and key management method.

[0071] It should be noted that, in the various embodiments of the present application, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or apparatus comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or apparatus comprising the element.

[0072] The serial numbers of the above embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.

[0073] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a number of instructions for enabling a terminal (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in each embodiment of the present application.

[0074] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of this application, ordinary technicians in this field can also make many forms without departing from the purpose of this application and the scope of protection of the claims, all of which are protected by this application.

Claims

1. A certificateless FANET distributed authentication and key management method, characterized in that: Identity authentication and key management for drone clusters include the following steps: Register the drone at a ground center to obtain legal proof of its identity; In the case of collaborative missions, the UAV management node sends the mission requirements and legal proof to the ground center to obtain air confidentiality management authority, where the UAV management node is the designated UAV in the cluster; Before executing the collaborative task, the task key is distributed between the control drone and the drone management node; After the mission key is distributed, the drone network access and group key distribution and update are completed based on the drone management node.

2. The certificateless FANET distributed authentication and key management method according to claim 1, wherein: Also includes: The ground center performs the following initialization process: Choose large prime numbers p and q, and E / Fp is an elliptic curve over a finite field; Select a generator P of order q on E / Fp to generate a cyclic group G; choose As the master key, calculate the public key P pub =x·P.

3. The certificateless FANET distributed authentication and key management method according to claim 2, wherein: Registering a drone with a ground center to obtain legal proof of its identity includes: Drone random selection Calculate S i =s i P is sent to the ground center as a voucher; At the center of the ground, randomly select Calculate R i =r i P, ID i =H(S i ,R i ), AUTH i =ID i ×x+r i , and set AUTH i , R i Send to drone; Drone receives AUTH i , R i After that, verify the AUTH equation i P=H(S i ,R i )·P pub +R i Establish, calculate and save (ID i ,AUTH i ,R i ,s i ) to form legal proof.

4. The certificateless FANET distributed authentication and key management method according to claim 3, wherein: The drone management node sends the mission requirements and legal proof to the ground center to obtain airborne confidential management authority, including: According to the mission requirements, the ground center randomly generates the air authority value Calculate K pub =k·P,Y pub =y·P; Select the distributed key management authority threshold value t and choose two t-1 order polynomials; Calculate the secret management authority component x separately i =f(H(S i ,R i )),k i =g(H(S i ,R i )) and pass the permission component (y i ,k i )Inject into the drone management node; A distribution key table is generated at the ground center, and the distribution key table contains m mutually prime keys dk1…dk m , corresponding to the m UAVs in this collaborative mission.

5. The certificateless FANET distributed authentication and key management method according to claim 3, wherein: The distribution of mission keys between the control drone and the drone management node includes: Start the drone i Follow the steps below to obtain the key: calculate C i =c i ·P, and send a task key request (AUTH i ,S i ,R i ,C i ); After receiving the request, the drone management node verifies the equation AUTH i P=H(S i ,R i )·P pub +R i , verification passed, and calculated (key1, key2) = s j ×C i +S i ×c j ,psk i-j =H(ID i ,C i )×y j +k j ,CT i-j =E key1 (psk i-j ,tk i ), (AUTH j ,S j ,R j ,C j ,CT i-j )Send to UAV U i ; UAVU i Received (AUTH j ,S j ,R j ,C j ,CT i-j ) after verifying the equation AUTH j P=H(S j ,R j )·P pub +R j To confirm that it is a legitimate drone management node, if the verification is passed, (key1, key2) = s i ×C j +S j ×c i ,psk i-j ,tk i =D key1 (CT i-j ); On the received PSK i-j When the number meets the threshold, calculate Save the task private key sk i =k+y×H(ID i ,C i )+H(ID i )×x+r i and dk i .

6. The certificateless FANET distributed authentication and key management method according to claim 1, wherein: The drone network access and group key distribution and update based on the drone management node include: Multiple drone management nodes adopt the master-slave mode, determine the current main access point through broadcasting, and the main access point completes the drone network access and key distribution and update.

7. The certificateless FANET distributed authentication and key management method according to claim 6, wherein: The completion of drone network access and group key distribution and update based on the drone management node specifically includes: When the drone is connected to the ad hoc network and cooperates with other drones, it uses its saved mission private key sk i Calculate and generate network access certificate V i =sk i H(ID i ,E i ,T i )+e, where E i =e i ·P, send (V i ,ID i ,C j ,E i ,R i ,T i ) Go to the drone management node for network verification; The drone management node of the main access point receives (V i ,ID i ,C j ,E i ,R i ,T i ), directly verify equation V i P = K pub +H(ID i ,E i ,T i )H(ID i ,C i )Y pub +H(ID i )H(ID i ,E i ,T i )P pub + H(ID i ,E i ,T i )R i +E i 。 8. The certificateless FANET distributed authentication and key management method according to claim 7, wherein: Completing drone network access and group key distribution and update based on the drone management node specifically includes performing batch authentication in the following ways: Subsequent calculation of the group key token: TOKEN=[DS′1DS1(gkg,T)+…+DS′ m DS m (gkg,T)](mod dk) where dk = dk1dk2…dk n , DS′ i DS i =1(mod dk i ), gkg is the group key generation factor; Send TOKEN and timestamp T to the drone; The drone calculates gkg, T = TOKEN (mod dk i ), verify whether the received timestamps are consistent, and calculate GK=KDF(gkg) as the group key for subsequent communications.

9. The certificateless FANET distributed authentication and key management method according to claim 8, wherein: Also includes: When a group key update is required, add or delete the corresponding dk and recalculate the TOKEN to complete the group key update.

10. A certificateless FANET distributed authentication and key management system, characterized in that: Identity authentication and key management for drone clusters, which include drones and drone management nodes, and have a communication connection with a ground center; The drone cluster and ground center include a processor and a memory, and a computer program is stored on the memory. When the computer program is executed by the processor, it collaboratively implements the steps of the certificateless FANET distributed authentication and key management method as described in any one of claims 1 to 9.

Citation Information

Patent Citations

  • Identity-based unmanned aerial vehicle key management and networking authentication system and method

    CN109218018A

  • Method and device for distributing and migrating secret keys in batches in trusted execution environment of cluster mobile terminal

    CN117499055A

  • Unmanned aerial vehicle group distributed management method based on mobile active secret sharing technology

    CN119653363A

  • Hybrid pki-based drone authentication system and drone management server

    KR1020180057468A