Certificateless fanet distributed authentication and key management method and system

CN120434641BActive Publication Date: 2026-09-22NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510557429.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-29
Publication Date
2026-09-22
Estimated Expiration
2045-04-29

AI Technical Summary

Technical Problem

但是基于无人机集群的FANET具有群组动态性强、拓扑变化快的特点,群组合并、分裂过程需要在拓扑结构变化后及时进行密钥管理,而上述方案则存在密钥更新、分发过程存在的计算与和通信代价较高、撤销列表维护难的问题

Benefits of technology

[0015]本申请实施例的方法能够提升任务执行前密钥配置效率,确保任务执行前任务密钥注入、任务执行中动态入网等过程的安全,为基于无人机集群的FANET的安全保障提供技术基础。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120434641B_ABST
    Figure CN120434641B_ABST
Patent Text Reader

Abstract

The application discloses a certificateless FANET distributed authentication and key management method and system, relates to unmanned aerial vehicles and data security technology, and comprises the following steps: registering an unmanned aerial vehicle at a ground center to obtain a legal certificate for indicating the identity of the unmanned aerial vehicle; in the case of performing a cooperative task, an unmanned aerial vehicle management node sends task requirements and the legal certificate to the ground center to obtain an air pipe authority; before performing the cooperative task, task key distribution is performed between the unmanned aerial vehicle and the unmanned aerial vehicle management node; after the task key distribution, the unmanned aerial vehicle management node completes unmanned aerial vehicle network access and group key distribution and updating. The method can improve the key configuration efficiency before task execution, ensures the safety of processes such as task key injection before task execution and dynamic network access during task execution, and provides a technical basis for the security guarantee of a FANET based on an unmanned aerial vehicle cluster.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the fields of unmanned aerial vehicles (UAVs) and data security technology, and in particular to a certificateless FANET distributed authentication and key management method and system. Background Technology

[0002] With the rapid development of information technology, drones, with their low cost, easy deployment and no restrictions from complex terrain, have received widespread attention and application in military and civilian fields such as real-time monitoring, traffic management, aerial base stations, and reconnaissance operations. They are widely regarded by academia and industry as one of the important technologies for emerging application fields such as intelligent transportation, unmanned combat, and mobile edge computing in the future.

[0003] In recent years, with the continuous expansion of business scenarios and the increasing demands of tasks, the limitations of single drones have made it difficult to meet the growing business needs. To address this issue, FANET technology, which targets multi-drone swarms, has been proposed. FANET based on drone swarms features a large task coverage and strong task execution capabilities, and can effectively solve the bottleneck problem of task failure caused by a single drone malfunction. FANET based on drone swarms mainly relies on wireless links to achieve interconnection of massive numbers of drones. Its open wireless communication links and uncontrolled deployment environment are vulnerable to attacks such as eavesdropping, tampering, interception, forgery, and impersonation. Authentication and key management are crucial for ensuring drone network security, but traditional methods are not well-suited for FANET based on drone swarms. FANET based on drone swarms is characterized by a large number of nodes, complex movement trajectories, short task preparation time, rapid network topology changes, and strong adversarial task environments, all of which pose unprecedented challenges to existing authentication and key management technologies.

[0004] To ensure that FANET based on drone swarms can safely and efficiently complete collaborative tasks in complex scenarios, the following two aspects need to be considered.

[0005] The issue of task key injection. Considering the possibility of drones being captured in complex adversarial scenarios, to ensure security, drones need to inject the relevant task keys into the device before each mission. Traditional single or small-scale drone missions primarily rely on manual one-to-one key injection via the injection device. However, the biggest characteristic of drone swarms is the large number of nodes, resulting in long security cycles and low efficiency. Traditional methods, with their limited scope, are insufficient to meet the key security requirements of collaborative swarm missions. While many mature key distribution and injection mechanisms exist in wired networks, they are not well-suited for drone environments due to the unique self-organizing network architecture of drone swarms and the need for robust resilience and short-term batch injection.

[0006] Dynamic network access authentication and key update issues. To achieve secure collaboration among massive drone nodes in complex task scenarios, secure authentication of network access nodes is required to build a secure and reliable group communication link to ensure business data transmission. Research on secure authentication technologies is quite mature. Schemes based on symmetric cryptography have the advantages of small key size and low algorithm computational complexity; however, these schemes are difficult to implement message signing, do not support advanced security attributes, and have a significant key management and storage burden. Schemes based on public-key cryptography can effectively achieve highly secure direct authentication between entities, providing advanced security attributes such as anonymity, non-repudiation, and non-linkability, while resisting denial-of-service attacks and man-in-the-middle attacks. However, the above schemes are not well-suited for drone swarm environments due to the lack of effective aggregation authentication methods. Group authentication based on aggregation algorithms is an important means to solve group authentication in environments with massive terminals. It can effectively simplify the identity verification process of group members, reduce network communication costs, and avoid signaling congestion. However, FANET based on drone swarms is characterized by strong group dynamics and rapid topology changes. The process of merging and splitting groups requires timely key management after the topology changes. The above-mentioned scheme has problems such as high computation and communication costs in the key update and distribution process, and difficulty in maintaining the revocation list. Summary of the Invention

[0007] This application provides a certificateless FANET distributed authentication and key management method and system, which improves the efficiency of key configuration before task execution, ensures the security of processes such as task key injection before task execution and dynamic network access during task execution, and provides a technical foundation for the security of FANET based on UAV clusters.

[0008] This application provides a certificate-free FANET distributed authentication and key management method, applied to identity authentication and key management of a drone cluster, including the following steps:

[0009] Register the drone at a ground center to obtain legal proof of its identity;

[0010] When performing collaborative tasks, the drone management node sends the task requirements and legal proof to the ground center to obtain airborne control permissions. The drone management node is the drone specified in the cluster.

[0011] Before executing a collaborative task, task keys are distributed between the control drone and the drone management node;

[0012] After the task key is distributed, the drone network access and group key distribution and update are completed based on the drone management node.

[0013] This application provides a certificate-free FANET distributed authentication and key management system, applied to the identity authentication and key management of a drone cluster. The drone cluster includes drones and drone management nodes, and the drone cluster establishes a communication connection with a ground center.

[0014] The drone swarm and ground center include a processor and a memory. The memory stores a computer program, which, when executed by the processor, collaboratively implements the steps of the aforementioned certificateless FANET distributed authentication and key management method.

[0015] The method in this application embodiment can improve the efficiency of key configuration before task execution, ensure the security of processes such as task key injection before task execution and dynamic network access during task execution, and provide a technical foundation for the security of FANET based on drone clusters.

[0016] The above description is only an overview of the technical solution of this application. In order to better understand the technical means of this application and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this application more obvious and understandable, the following are specific embodiments of this application. Attached Figure Description

[0017] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the scope of this application. Furthermore, the same reference numerals denote the same parts throughout the drawings. In the drawings:

[0018] Figure 1 This is a basic flowchart illustrating the certificate-free FANET distributed authentication and key management method in this application. Detailed Implementation

[0019] Exemplary embodiments of the present disclosure will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the disclosure to those skilled in the art.

[0020] This application addresses the security needs of drone swarms in complex task scenarios, proposing a security scheme for identity authentication and key management applicable to large-scale drone swarms, mainly including the following aspects:

[0021] 1. Based on the construction of a new multi-layer distributed management architecture, a batch wireless injection method for task keys based on secret sharing was designed to complete the key configuration of a large number of UAV nodes in parallel.

[0022] 2. The design is based on a certificateless signature and an aggregateable access authentication and key management protocol;

[0023] 3. A key distribution method with efficient response to topology changes is proposed. This protocol, as a basic cryptographic protocol, can be applied to scenarios with a large number of terminals, high mobility, and complex heterogeneous networks, such as unmanned swarms and vehicle-to-everything (V2X) networks, to protect communication security and improve cryptographic protection capabilities.

[0024] This application provides a certificate-free FANET distributed authentication and key management method for identity authentication and key management in a drone cluster. It mainly includes three parts: initialization and node registration, drone mission key configuration, and drone network access authentication and group key distribution. Figure 1 As shown, it includes the following steps:

[0025] In step S101, the drone is registered at the ground center KGC to obtain a valid AUTH certificate to prove its identity.

[0026] In step S102, when performing a collaborative task, the drone management node sends the task requirements and legal proof to the ground center KGC to obtain airborne control permissions, wherein the drone management node is the drone specified in the cluster.

[0027] In step S103, before executing the collaborative task, the task key is distributed between the control drone and the drone management node.

[0028] In step S104, after the task key is distributed, the drone network access and group key distribution and update are completed based on the drone management node.

[0029] In some embodiments, the system initialization and node registration steps further include: the ground control center (KGC) performing the following initialization process:

[0030] Choose large prime numbers p and q, and E / Fp is an elliptic curve over a finite field;

[0031] Choose a generator P with order q above E / Fp to generate the cyclic group G;

[0032] choose As the master key, calculate the public key P. pub =x·P.

[0033] The drone registration process, in some embodiments, involves registering the drone at a ground center to obtain legal proof of its identity, including:

[0034] Drones are randomly selected Calculate S i =s i • P is sent to KGC as a credential;

[0035] At the center of the ground, randomly selected Calculate R i =r i ·P,ID i =H(S) i ,R i ), AUTH i =ID i ×x+r i and AUTH i R i Send to the drone;

[0036] The drone received AUTH i R i Then, verify the equation AUTH. i ·P=H(S i ,R i )·P pub +R i Establish, calculate and save (ID) i ,AUTH i ,R i ,s i ( ), in order to form legal proof.

[0037] The drone mission key configuration steps involve the drone management node sending the mission requirements and its own identity to the KGC when a collaborative mission is needed, requesting airborne secure control permissions. In some embodiments, the drone management node sends the mission requirements and valid credentials to the ground center to obtain airborne secure control permissions, including:

[0038] Based on mission requirements, the ground control center (KGC) first randomly generates an airborne access control value y. Calculate K pub =k·P,Y pub =y·P;

[0039] Choose a distributed security management permission threshold value t, and select a polynomial of order t-1. For example, choose a suitable distributed security management permission threshold value t and select two polynomials of order t-1.

[0040] f(z) = y + a1z + a2z 2 +…+a t-1 z t-1

[0041] g(z) = k + b1z + b2z 2+…+b t-1 z t-1

[0042] Then, the confidential access component x was calculated separately. i =f(H(S) i ,R i )),k i =g(H(S) i ,R i And pass the permission component (y) through a secure channel. i ,k i Inject into the drone management node.

[0043] A distribution key table is generated at the ground center, the distribution key table containing m pairwise coprime keys dk1….dk m , which correspond to the m drones in this collaborative mission.

[0044] In some embodiments, the task key distribution step, which controls the distribution of task keys between the drone and the drone management node, includes:

[0045] Before the mission is executed, start the UAV. i To obtain the key, follow these steps:

[0046] calculate C i =c i ·P, and to the drone management node (such as U j Send Task Key Request (AUTH) i ,S i ,R i C i );

[0047] After receiving the request, the drone management node verifies the equation AUTH. i ·P=H(S i ,R i )·P pub +R i The verification passed, and (key1, key2) = s was calculated. j ×C i +S i ×c j ,psk i-j =H(ID) i C i )×y j +k j CT i-j =E key1 (psk i-j ,tk i ), will (AUTH j ,Sj ,R j C j CT i-j Send to UAV i ;

[0048] UAV i Received (AUTH) j ,S j ,R j C j CT i-j After that, verify the equation AUTH. j ·P=H(S j ,R j )·P pub +R j To determine if it is a legitimate drone management node, if the verification is successful, calculate (key1, key2) = s. i ×C j +S j ×c i ,psk i-j ,tk i =D key1 (CT i-j );

[0049] In the received PSK i-j Calculate if the quantity meets the threshold.

[0050] Save the task private key sk i =k+y×H(ID) i C i )+H(ID i )×x+r i and dk i .

[0051] In some embodiments, the drone network access authentication and group key distribution steps, based on the drone management node, include the following:

[0052] To address efficiency concerns during mission execution, multiple drone management nodes employ a primary / backup mode. The primary access point is determined via broadcast, and it is then responsible for drone network access, key distribution, and updates.

[0053] In some embodiments, the process of completing drone network access, group key distribution, and updates based on the drone management node specifically includes:

[0054] When a drone connects to an ad hoc network and collaborates with other drones, it utilizes its stored mission private key sk. i Calculate and generate network access certificate V i =ski H(ID i E i ,T i )+e, where E i =e i ·P, send (V) i ID i C j E i ,R i ,T i The drone will be sent to the drone management node for network access verification.

[0055] The drone management node of the main access point received (V i ID i C j E i ,R i ,T i ), directly verify equation V i ·P=K pub +H(ID i E i ,T i )H(ID i C i )Y pub +H(ID i )H(ID i E i ,T i )P pub +

[0056] H(ID i E i ,T i )R i +E i .

[0057] In some embodiments, the process of completing drone network access, group key distribution, and updates based on the drone management node further includes performing batch authentication in the following manner:

[0058]

[0059] Subsequent computation group key token:

[0060] TOKEN = [DS1] ′ DS1(gkg,T)+…+DS ′ m DS m (gkg,T)](mod dk)

[0061] Where dk = dk1dk2…dk n , DS′ i DS i =1 (mod dk) i ), gkg is the group key generation factor;

[0062] Send the token and timestamp T to the drone;

[0063] The drone calculates gkg,T = TOKEN (mod dk) i Verify that the received timestamps are consistent.

[0064] Calculate GK = KDF(gkg) as the group key for subsequent communication.

[0065] In some embodiments, the method further includes: when a group key update is required, adding or deleting the corresponding dk and recalculating the TOKEN to complete the group key update.

[0066] The secret-sharing-based task key batch wireless injection method designed in this application achieves efficient wireless injection of cryptographic resources suitable for UAV swarms. It can complete key configuration in batches during the task preparation stage, and at the same time, it achieves a certain degree of anti-destruction capability based on the secret-sharing algorithm.

[0067] The certificate-free signature-based aggregated dynamic access authentication protocol designed in this application achieves efficient and secure network access authentication in large-scale drone swarm scenarios. It can effectively resist man-in-the-middle attacks, replay attacks, etc., and prevent unauthorized drones from accessing the task group to obtain any sensitive information.

[0068] The key distribution method designed in this application can effectively improve the group key distribution speed and achieve efficient response to topology changes.

[0069] This application also proposes a certificate-free FANET distributed authentication and key management system for identity authentication and key management of a drone cluster, wherein the drone cluster includes drones and drone management nodes, and the drone cluster has a communication connection with the ground center.

[0070] The drone swarm and ground center include a processor and a memory. The memory stores a computer program, which, when executed by the processor, collaboratively implements the steps of the aforementioned certificateless FANET distributed authentication and key management method.

[0071] It should be noted that, in the embodiments of this application, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0072] The sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0073] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of this application.

[0074] The embodiments of this application have been described above with reference to the accompanying drawings. However, this application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of this application without departing from the spirit and scope of the claims. All of these forms are within the protection scope of this application.

Claims

1. A certificate-free FANET distributed authentication and key management method, characterized in that, Identity authentication and key management for drone swarms include the following steps: Register the drone at a ground center to obtain legal proof of its identity; When performing collaborative tasks, the drone management node sends the task requirements and legal proof to the ground center to obtain airborne control permissions. The drone management node is the drone specified in the cluster. Before executing a collaborative task, task keys are distributed between the control drone and the drone management node; After the task key is distributed, the drone network access and group key distribution and update are completed based on the drone management node; This also includes: the ground center performing the following initialization process: Choose large prime numbers p and q , E / Fp It is an elliptic curve over a finite field; choose E / Fp The upper level is q generator P Generate a cyclic group G ; choose As the master key, calculate the public key. ; Registering a drone at a ground center to obtain legal proof of its identity includes: Drones are randomly selected ,calculate Send as proof to the ground center; At the center of the ground, randomly selected calculate and will , Send to the drone; The drone received , Then, verify the equation. = + Establish, calculate and save ( , ), to form legal proof; The drone management node sends mission requirements and legal documentation to the ground center to obtain airborne surveillance permissions, including: Based on mission requirements, the ground control center randomly generates airborne access control values. ,calculate , ; Choose a distributed security management threshold value t, and select two t-1 order polynomials; Calculate the control access components separately and pass the permission components through a secure channel ( Inject into the drone management node; A distribution key table is generated at the ground center, the distribution key table containing A pairwise coprime key These correspond to the tasks in this collaborative mission. ; Controlling the distribution of mission keys between the drone and the drone management node includes: Start the drone To obtain the key, follow these steps: calculate , And send a mission key request to the drone management node. ); After receiving the request, the drone management node verifies the equation. = + Validation passed, and (key1, key2) = + , , ,Will( Send to drone ; drones receive( After that, verify the equation. = + To determine if it is a legitimate drone management node, if the verification is successful, calculate (key1, key2) = + , ; In received Calculate if the quantity meets the threshold. = ; Save the task private key and .

2. The certificate-free FANET distributed authentication and key management method as described in claim 1, characterized in that, The process of drone network access, group key distribution, and updates based on the drone management node includes: Multiple drone management nodes adopt a primary / backup mode, using broadcast to determine the current primary access point, which then completes the drone network access and key distribution and updates.

3. The certificate-free FANET distributed authentication and key management method as described in claim 2, characterized in that, The process of completing drone network access, group key distribution, and updates based on the drone management node specifically includes: When a drone connects to an ad hoc network and collaborates with other drones, it utilizes its stored mission private key. Calculate and generate network access certificate ,in ,send( , The drone will be sent to the drone management node for network access verification. The drone management node of the main access point received ( , ), directly verify the equation .

4. The certificate-free FANET distributed authentication and key management method as described in claim 3, characterized in that, The process of completing drone network access, group key distribution, and updates based on the drone management node also includes performing batch authentication in the following ways: ; Subsequent computation group key token: in , Group key generation factor; send and timestamp To drones; Drones through calculation Verify that the received timestamps are consistent, and calculate... This serves as the group key for subsequent communications.

5. The certificate-free FANET distributed authentication and key management method as described in claim 4, characterized in that, Also includes: When group key updates are required, add or delete corresponding... Recalculate To complete the group key update.

6. A certificate-free FANET distributed authentication and key management system, characterized in that, This is applied to identity authentication and key management for drone swarms, which include drones and drone management nodes, and establish a communication connection between the drone swarm and the ground center. The drone swarm and ground center include a processor and a memory. The memory stores a computer program, which, when executed by the processor, collaboratively implements the steps of the certificateless FANET distributed authentication and key management method as described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Identity-based unmanned aerial vehicle key management and networking authentication system and method

    CN109218018A

  • Method and device for distributing and migrating secret keys in batches in trusted execution environment of cluster mobile terminal

    CN117499055A