Quantum security unmanned system swarm communication method and system
Through quantum secure identity authentication and data encryption, combined with dynamic key management and supplement mechanisms, the problem of low security in unmanned system swarm communications has been solved, the anti-attack capability has been improved, and continuous quantum secure encrypted communication has been achieved.
Patent Information
- Application Number
- CN202511080661.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-04
- Publication Date
- 2025-09-05
- Estimated Expiration
- 2045-08-04
AI Technical Summary
The communication security of unmanned system swarms during mission execution is low and their anti-attack capabilities are poor. Any attack on any unmanned system may affect the overall mission execution.
Quantum-secure identity authentication and data encryption methods are adopted, and a secure identity is assigned to each unmanned terminal through the control center. Quantum-secure key management and dynamic key replenishment mechanisms are used in the swarm construction and data communication process to ensure communication security and anti-attack capabilities.
It ensures the legitimacy of unmanned terminal devices in the unmanned system swarm and the security of data communications, improves the swarm's anti-attack capability, supports large-scale network deployment, ensures the real-time and continuity of quantum secure encryption communications, and avoids the risk of broadcast key leakage.
Smart Images

Figure CN120602937A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of unmanned systems, and in particular to a quantum-secure swarm communication method and system for unmanned systems. Background Art
[0002] Unmanned systems (US) are completely autonomous systems operating without human intervention. They are the product of a highly integrated approach to information technology and mechanization. These systems must be both autonomous and operate in a collaborative "unmanned / unmanned" mode. Unmanned systems encompass three components: unmanned aerial, ground, and maritime systems. These systems are exemplified by drones, unmanned vehicles, unmanned ships, robots, unmanned swarms, and hybrid systems. They are comprised of an unmanned platform and several auxiliary components, encompassing an integrated system capable of autonomously completing predetermined missions.
[0003] While autonomous unmanned systems can certainly complete tasks independently, the increasing complexity of existing tasks often requires the collaboration of multiple unmanned systems, or systems with diverse functions. In recent years, with the development of cluster technologies such as communication networking, intelligent decision-making, and collaborative control, unmanned systems have evolved from single-system execution to a clustered model. A cluster of multiple unmanned systems is called an unmanned system swarm.
[0004] In complex mission environments, a swarm of unmanned systems (UAS) can achieve network connectivity between individual UAS within the swarm and between the UAS and the control center through a mesh (wireless mesh) self-organizing communication network. In this model, all UAS nodes function identically, possessing both terminal and routing capabilities. When a node cannot communicate directly with others, it can use multi-hop routing to reach other nodes, achieving interconnectivity across the entire network. However, due to this interconnected nature, if any UAS in the swarm is attacked, not only could its own information be compromised, but it could also potentially affect other UAS in the swarm through communication, ultimately impacting overall mission execution.
[0005] In view of this, how to ensure the communication security of unmanned system swarms during mission execution and improve the unmanned system's anti-attack capabilities have become technical problems that need to be urgently solved in the current operation of unmanned system swarms. Summary of the Invention
[0006] Purpose of the Invention: This invention aims to provide a quantum-secure unmanned system swarm communication method and system, addressing the low communication security and poor anti-attack capabilities of existing unmanned system swarms during mission execution. This invention utilizes quantum-secure identity authentication during swarm construction and quantum-secure data encryption during swarm data communication, ensuring the legitimacy of unmanned terminal devices and the security of data communications.
[0007] Technical Solution: The present invention provides a quantum-safe unmanned system swarm communication method. The participants of the method are a control center and multiple unmanned terminals. The method includes the following steps:
[0008] (1) The control center assigns a security identity to each unmanned terminal; each unmanned terminal is pre-installed with a secondary control center communication key pool for communicating with the control center, and the control center is pre-installed with a primary control center communication key pool that has a symmetric key with the secondary control center communication key pool of each unmanned terminal; and the control center and each unmanned terminal are also pre-installed with a broadcast communication key pool with the same key;
[0009] (2) The control center selects an unmanned terminal as the first unmanned terminal. The first unmanned terminal acts as the identity authentication party to authenticate the identities of other unmanned terminals. The unmanned terminals that have passed the authentication are constructed into an unmanned system swarm, and the first unmanned terminal is added to the unmanned system swarm.
[0010] (3) The terminal communication key pool in each unmanned terminal constituting the unmanned system swarm receives a preset key, so that any unmanned terminal is preset with a key corresponding to other unmanned terminals in the swarm;
[0011] (4) When any two unmanned terminals in the swarm conduct point-to-point communication, the keys in their respective terminal communication key pools are consumed; if the unmanned terminal detects that the remaining key amount in the terminal communication key pool is less than or equal to the set terminal key remaining threshold parameter, the key replenishment operation is performed;
[0012] When any unmanned terminal performs broadcast communication with multiple other unmanned terminals, the keys in their respective broadcast communication key pools are consumed; if the unmanned terminal detects that the remaining key in the broadcast communication key pool is less than or equal to the broadcast key threshold, the unmanned terminal requests a broadcast key update operation from the control center;
[0013] When any unmanned terminal communicates with the control center, it consumes the key in the communication key pool of the respective control center; if the unmanned terminal detects that the key remainder in the communication key pool of the control center is less than or equal to the control center communication key threshold, the unmanned terminal requests the control center to update the control center communication key.
[0014] Furthermore, before adding the first unmanned terminal to the unmanned system swarm, the method further includes: selecting an unmanned terminal from the unmanned system swarm to perform identity authentication on the first unmanned terminal as the identity authentication party.
[0015] Furthermore, the specific process of the control center assigning a security identity to each unmanned terminal is as follows:
[0016] The control center generates a hash value based on the device serial number IDX of the unmanned terminal. The hash value serves as the security identity of the unmanned terminal. The process is as follows: the control center generates an irreducible polynomial locally , record the string consisting of the coefficients of each term except the highest term in the irreducible polynomial as The control center then obtains the first key K1 from the broadcast communication key pool as the input random number, using the irreducible polynomial And the first key K1 generates a hash function ; Input the device serial number IDX of the unmanned terminal into the hash function Get a secure identity ; The control center records the first index idx1 of the first key K1 in the broadcast communication key pool.
[0017] Furthermore, the specific process of identity authentication is as follows:
[0018] 1) The security identity of the unmanned terminal to be authenticated is The control center obtains the communication encryption key K2 from the main control center communication key pool that has a symmetric key with the secondary control center communication key pool of the first unmanned terminal, records the second index idx2 of the communication encryption key K2, and then uses the communication encryption key K2 to encrypt the string , the first index idx1 and the security identity identifier of the unmanned terminal to be authenticated , get the ciphertext , the ciphertext and the second index idx2 are sent to the first unmanned terminal;
[0019] 2) The first unmanned terminal obtains the communication decryption key from the local secondary control center communication key pool that communicates with the control center according to the second index idx2 , using the communication decryption key Ciphertext Decrypt and get the string ,index and hash value ;
[0020] 3) The first unmanned terminal is based on the index Get the key from the broadcast communication key pool As input random number, according to the string Generate irreducible polynomials , then based on the irreducible polynomial and key Generate hash function ;
[0021] 4) The first unmanned terminal obtains the device serial number from the unmanned terminal to be authenticated , using a hash function Computing device serial number The hash value is obtained ;
[0022] 5) The first unmanned terminal compares and calculates the hash value and hash value If they are consistent, the authentication is successful, and the first unmanned terminal accepts the unmanned terminal whose identity is to be authenticated as one of the unmanned system swarm, and proceeds to the next step; if they are inconsistent, the first unmanned terminal refuses to include the unmanned terminal whose identity is to be authenticated into the unmanned system swarm;
[0023] 6) The first unmanned terminal feeds back the authentication result to the control center, and the control center incorporates the unmanned terminal to be authenticated into the swarm management.
[0024] Furthermore, the provision of pre-installed keys for each unmanned terminal corresponding to other unmanned terminals in the swarm means:
[0025] First, each unmanned terminal in the unmanned system swarm obtains the number of unmanned terminals n in the swarm from the control center, and then divides its own terminal communication key pool into n-1 sub-terminal communication key pools;
[0026] Each unmanned terminal then establishes a one-to-one correspondence between its own n-1 sub-terminal communication key pool and the corresponding sub-terminal communication key pools of the other (n-1) unmanned terminals except itself.
[0027] Furthermore, the point-to-point communication between any two unmanned terminals refers to:
[0028] The Kth unmanned terminal, acting as the sender, obtains the encryption key K3 from the local sub-terminal communication key pool corresponding to the Mth unmanned terminal, acting as the receiver, based on the data to be sent. It records the key index idx3 of the encryption key K3, then uses the encryption key K3 to encrypt the data to obtain the ciphertext DATA. Finally, the ciphertext DATA and the key index idx3 are sent to the Mth unmanned terminal, acting as the receiver.
[0029] The Mth unmanned terminal obtains the decryption key from the local sub-terminal communication key pool corresponding to the Kth unmanned terminal according to the received key index idx3 , using this decryption key Decrypt the received ciphertext DATA to obtain the plaintext data , the plaintext data This is the communication data between the Kth unmanned terminal and the Mth unmanned terminal.
[0030] Furthermore, the specific process of performing the key supplement operation is:
[0031] A1: The Xth unmanned terminal, acting as one of the two parties in the key supplementation process, first finds the sub-terminal communication key pool to be supplemented corresponding to the Yth unmanned terminal, acting as the other party in the key supplementation process. It then generates a key supplement instruction and sends it to a local true random number generator. The key supplement instruction includes a supplement key size parameter, which is the storage size of the sub-terminal communication key pool to be supplemented minus the remaining key size in the current sub-terminal communication key pool.
[0032] A2: The true random number generator responds to the key supplement instruction and generates a set of true random numbers of a size equal to the supplement key size parameter as a supplement key; the Xth unmanned terminal then sends the supplement key to the sub-terminal communication key pool to be supplemented, and sends the supplement key to the Yth unmanned terminal;
[0033] A3: The Yth unmanned terminal finds the sub-terminal communication key pool to be supplemented corresponding to the Xth unmanned terminal, and then fills the supplementary key into the remaining keys of the sub-terminal communication key pool to be supplemented to form a new communication key file.
[0034] Furthermore, the specific process of the broadcast key update operation is:
[0035] B1: The control center sends the updated key J-UP of length j to the broadcast communication key pool in each unmanned terminal in the unmanned system swarm;
[0036] B2: Each unmanned terminal divides the original broadcast key of length J in the local broadcast communication key pool into (i+1) subkeys according to the granularity of length j; where i = [J / j], the 1st to i-th subkeys are denoted as J1 to Ji, all with length j; the (i+1)th subkey is denoted as J(i+1), with length Ji*j;
[0037] B3: Use the updated key J-UP to perform an XOR operation with each of the 1st to i-th subkeys to obtain a new , until the new ; For subkey J(i+1), intercept the key J-UP1 from the first to the Ji*jth bit in the update key J-UP and perform an XOR operation with the subkey J(i+1) to obtain the new ; After the XOR is completed, a new broadcast key of length J is obtained.
[0038] The present invention also includes a system based on the above-mentioned quantum-secure unmanned system swarm communication method, the system comprising a control center and an unmanned system swarm connected to the control center, wherein the unmanned system swarm is composed of a plurality of unmanned terminals connected in pairs;
[0039] The control center is used to assign a security identity to each unmanned terminal and communicate with each unmanned terminal; it is also used to respond to requests from unmanned terminals to perform control center communication key update operations and broadcast key update operations;
[0040] The unmanned terminals in the unmanned system swarm are used to communicate with the control center and the unmanned terminals in the swarm; and are also used to respond to requests from the unmanned terminals to perform key supplement operations.
[0041] Furthermore, each unmanned terminal in the unmanned system swarm includes a quantum security module, which includes a terminal association unit, a data communication unit, a status reporting unit, a key management unit, and a terminal key supplement unit. The terminal association unit, the key management unit, the terminal key supplement unit, and the data communication unit are connected in sequence, and the data communication unit is also connected to the key management unit and the terminal association unit.
[0042] The terminal association unit includes a terminal identity authentication component for performing identity authentication and forming unmanned terminals that pass identity authentication into a swarm;
[0043] The data communication unit is used to receive and send data, and obtain the corresponding key from the key management unit according to data requirements to encrypt or decrypt the data;
[0044] The status reporting unit is used to send a heartbeat to the control center to confirm whether the unmanned terminal where the quantum security module is located is online;
[0045] The key management unit includes a terminal communication key pool, a sub-control center communication key pool, a broadcast communication key pool and a key remainder detection component, and the key remainder detection component is connected to the broadcast communication key pool and the sub-control center communication key pool respectively; the terminal communication key pool is used to provide the key required for the encryption and decryption process of communication data between the unmanned terminal and other unmanned terminals in the bee colony; the sub-control center communication key pool is used to provide the key required for the encryption and decryption process of information sent by the control center received via the data communication unit; the broadcast communication key pool is used to provide the key required for the encryption and decryption process of broadcast messages in the bee colony; the key remainder detection component is used to monitor the key remainder in the broadcast communication key pool and the sub-control center communication key pool, and to generate a request for a key update operation to the control center;
[0046] The terminal key supplement unit includes a terminal key detection component, a true random number generator and a key distribution component connected in sequence, and the terminal key detection component and the key distribution component are both connected to the terminal communication key pool; the terminal key detection component is used to monitor the key residue in the terminal communication key pool, and to generate a key supplement instruction and send it to the true random number generator; the true random number generator is used to receive the key supplement instruction, generate a true random number as a supplement key, and send the supplement key to the key distribution component; the key distribution component is used to send the supplement key directly to the terminal communication key pool, and to send the supplement key to the unmanned terminal required for key supplement through the data communication unit.
[0047] Beneficial effects of the present invention:
[0048] (1) Quantum-secure identity authentication is used in the swarm construction process, and quantum-secure data encryption is used in the swarm data communication process, ensuring the legitimacy of the unmanned terminal devices in the entire unmanned system swarm and the security of data communications;
[0049] (2) Through the technical solution of dynamic and real-time supplementation of communication keys during the communication process, the real-time and security of quantum secure encrypted communication in the unmanned system swarm is effectively ensured, and large-scale network deployment is supported. Without the need for human intervention, the unmanned terminal can be separated from the swarm to perform key supplementation operations, so that quantum secure encrypted communication can be carried out continuously and permanently.
[0050] (3) Using a small number of update keys to act on the original broadcast key avoids the problem of occupying a large amount of communication bandwidth caused by the full update of the broadcast key. Moreover, the update key does not replace the original broadcast key, and the original broadcast key is preset in advance, which effectively avoids the risk of broadcast key leakage. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] Figure 1 This is a schematic diagram of the structure of the unmanned system swarm communication system of the present invention;
[0052] Figure 2 This is a schematic diagram of the structure of the quantum security module of the present invention;
[0053] Figure 3 This is a schematic diagram of the control center and the unmanned terminal presetting the control center communication key;
[0054] Figure 4 A schematic diagram showing the corresponding relationship between the unmanned terminal of the present invention and other unmanned terminals other than itself in establishing a sub-terminal communication key pool;
[0055] Figure 5 This is a schematic diagram of broadcast key update according to the present invention;
[0056] Figure 6 Schematic diagram of the unmanned system swarm communication method of the present invention. DETAILED DESCRIPTION
[0057] The present invention will be further described below with reference to the accompanying drawings and embodiments:
[0058] Existing unmanned system swarms suffer from low communication security and poor anti-attack capabilities during mission execution. If any unmanned system in the swarm is attacked, not only will its own information be leaked, but it may also affect other unmanned systems in the swarm through communication, ultimately impacting the overall mission execution. Given these current issues, ensuring the communication security of unmanned system swarms during mission execution and improving their anti-attack capabilities have become urgent technical challenges in the current operation of unmanned system swarms.
[0059] In view of this, the present invention proposes a quantum secure unmanned system swarm communication system, such as Figure 1 As shown, the system includes a control center 1 and an unmanned system swarm 2 connected to the control center 1. The unmanned system swarm 2 is composed of multiple unmanned terminals connected in pairs. This embodiment uses unmanned system swarms composed of first, second, third, and n unmanned terminals as examples to illustrate the quantum-secure unmanned system swarm communication system proposed in this application. In the system, the control center 1 is used to assign a security identity to each unmanned terminal and communicate with each unmanned terminal. It is also used to respond to requests from the unmanned terminals to perform control center communication key update operations and broadcast key update operations. The unmanned terminals in the unmanned system swarm are used to communicate with the control center 1 and the unmanned terminals in the swarm and to respond to requests from the unmanned terminals to perform key replenishment operations.
[0060] Among them, the unmanned terminals in the unmanned system swarm 2 all include quantum security modules 3, such as Figure 2As shown, the quantum security module 3 includes a terminal association unit 31, a data communication unit 32, a status reporting unit 33, a key management unit 34 and a terminal key supplement unit 35. The terminal association unit 31, the key management unit 34, the terminal key supplement unit 35 and the data communication unit 32 are connected in sequence, and the data communication unit 32 is also connected to the key management unit 34 and the terminal association unit 31;
[0061] The terminal association unit 31 includes a terminal identity authentication component 311 for performing identity authentication and forming unmanned terminals that pass identity authentication into a swarm;
[0062] The data communication unit 32 is used to receive and send data, and obtain the corresponding key from the key management unit 34 according to the data requirements to encrypt or decrypt the data;
[0063] The status reporting unit 33 is used to send a heartbeat to the control center 1 to confirm whether the unmanned terminal where the quantum security module is located is online;
[0064] The key management unit 34 includes a terminal communication key pool 341, a sub-control center communication key pool 342, a broadcast communication key pool 343, and a key remainder detection component 344. The key management unit 34 is used to store and manage all the keys required by the unmanned terminal where the quantum security module 3 is located in the communication process, and to detect the key remainders in the broadcast communication key pool 343 and the sub-control center communication key pool 342; wherein the key remainder detection component 344 is connected to the broadcast communication key pool 343 and the sub-control center communication key pool 342 respectively; the terminal communication key pool 341 is used to provide the unmanned terminal with the key remaining in the swarm. The sub-control center communication key pool 342 is used to provide the keys required for the encryption and decryption process of the communication data of other unmanned terminals received via the data communication unit 32, and the control center 1 has a key pool symmetrical to the sub-control center communication key pool 342; the broadcast communication key pool 343 is used to provide the keys required for the encryption and decryption process of the broadcast messages in the swarm, and the keys of the broadcast communication key pool 343 in each unmanned terminal in the same unmanned system swarm 2 are consistent; before the unmanned terminal starts working, the key management unit 34 will preset the key. The key remainder detection component 344 is provided with a broadcast key threshold and a sub-control center communication key threshold. These two thresholds are the key remainder alarm values in the broadcast communication key pool 343 and the sub-control center communication key pool 342. It can be seen that the key remainder detection component 344 is used to monitor the key remainder in the broadcast communication key pool 343 and the sub-control center communication key pool 342, and to generate a request for a key update operation to the control center 1;
[0065] As the swarm progresses, the keys in the terminal communication key pool 341 are consumed much faster than those in the secondary control center communication key pool 342 and the broadcast communication key pool 343. However, during operation, it is not suitable to separate the unmanned system from the swarm for key replenishment operations. Therefore, the quantum security module 3 is also equipped with a terminal key replenishment unit 35 for replenishing keys for both communicating unmanned terminals. The terminal key supplement unit 35 includes a terminal key detection component 351, a true random number generator 352 and a key distribution component 353 connected in sequence. The terminal key detection component 351 and the key distribution component 353 are both connected to the terminal communication key pool 341; the terminal key detection component 351 is used to monitor the key remainder in the terminal communication key pool 341, and to generate a key supplement instruction and send it to the true random number generator 352. The terminal key detection component 351 is set with a terminal key remainder threshold parameter. The terminal key detection component 351 detects the key remainder in the terminal communication key pool 341 based on the terminal key remainder threshold parameter. When the key remainder is less than or equal to the terminal key remainder threshold parameter, a key supplement instruction is generated and sent to the true random number generator 352; the true random number generator 352 is used to receive the key supplement instruction, generate a true random number as a supplementary key, and send the supplementary key to the key distribution component 353; the key distribution component 353 is used to send the supplementary key directly to the terminal communication key pool 341, and send the supplementary key to the unmanned terminal required for key supplement through the data communication unit 32. The quantum security module 3 can be present in the unmanned terminal in the form of a plug-in (for example, a chip), without requiring any hardware modification of the existing unmanned terminal to meet the communication requirements of quantum security.
[0066] The system can supplement communication keys during the communication process without the need for subsequent human intervention. By separating the unmanned terminal from the swarm to perform key supplementation operations, quantum secure encrypted communications can be carried out continuously and permanently; ensuring the communication security of the unmanned system swarm during mission execution and improving the unmanned system's anti-attack capabilities.
[0067] Based on the above-mentioned unmanned system swarm communication system, this embodiment further proposes a quantum-safe unmanned system swarm communication method. The participants of this method are a control center 1 and multiple unmanned terminals. The method includes the following steps:
[0068] (1) The control center 1 assigns a security identity to each unmanned terminal. In this case, the unmanned terminal is an unmanned terminal to be part of an unmanned system swarm. Each unmanned terminal is pre-installed with a secondary control center communication key pool for communicating with the control center 1. The control center 1 is pre-installed with a primary control center communication key pool that has a symmetric key with the secondary control center communication key pool of each unmanned terminal. In addition, the control center 1 and each unmanned terminal are also pre-installed with a broadcast communication key pool with the same key.
[0069] For example, taking the second and third unmanned terminals that will form the unmanned system swarm as an example, the control center 1 can generate an identity based on the device serial numbers of the second and third unmanned terminals. Because each unmanned terminal has a different serial number, this serial number can serve as the public identity of the second unmanned terminal. The identity can be generated by generating a hash value based on the device serial number.
[0070] like Figure 3 As shown, the control center 1 is configured with a second main control center communication key pool 102 having a symmetric key with the second sub-control center communication key pool 201 in the second unmanned terminal, a third main control center communication key pool 103 having a symmetric key with the third sub-control center communication key pool 301 in the third unmanned terminal, and a broadcast communication key pool c having the same key as the second unmanned terminal and the third unmanned terminal broadcast communication key pool c;
[0071] The specific process of the control center 1 assigning a security identity to each unmanned terminal is as follows:
[0072] The control center 1 generates a hash value based on the device serial number IDX of the unmanned terminal. The hash value serves as the security identity of the unmanned terminal. The process is as follows: the control center 1 generates an irreducible polynomial locally , record the string consisting of the coefficients of each term except the highest term in the irreducible polynomial as ; The control center 1 then obtains the first key K1 from the broadcast communication key pool as the input random number, using the irreducible polynomial And the first key K1 generates a hash function ; Input the device serial number IDX of the unmanned terminal into the hash function Get a secure identity ; The control center 1 records the first index idx1 of the first key K1 in the broadcast communication key pool.
[0073] Since the keys in the broadcast key pool c of the control center 1 and each unmanned terminal are consistent, directly using the keys in the broadcast key pool as the input random number can save the step of key sharing between the control center and the unmanned terminal. Moreover, because there are many unmanned terminals that make up the swarm, key sharing between the control center and different unmanned terminals will consume more resources and the operation process is complicated. The solution of directly reusing the keys in the broadcast key pool is highly operational.
[0074] (2) The control center 1 selects any unmanned terminal as the first unmanned terminal. The first unmanned terminal acts as the identity authentication party. The first unmanned terminal performs identity authentication on other unmanned terminals, constructs the unmanned terminals that have passed the authentication into an unmanned system swarm, and then adds the first unmanned terminal to the unmanned system swarm. In the swarm, the first unmanned terminal can communicate with any other unmanned terminal in the unmanned system swarm. The first unmanned terminal here is a general term. The control center 1 can select any unmanned terminal to form the unmanned system swarm as the first unmanned terminal to perform the identity authentication operation. Moreover, before adding the first unmanned terminal to the unmanned system swarm, the process may also include: selecting any unmanned terminal from the unmanned system swarm to perform identity authentication on the first unmanned terminal as the identity authentication party.
[0075] The specific process of identity authentication is as follows:
[0076] 1) The security identity of the unmanned terminal to be authenticated is , the control center 1 obtains the communication encryption key K2 from the main control center communication key pool that has a symmetric key with the secondary control center communication key pool of the first unmanned terminal, records the second index idx2 of the communication encryption key K2, and then uses the communication encryption key K2 to encrypt the string , the first index idx1 and the security identity identifier of the unmanned terminal to be authenticated , get the ciphertext , the ciphertext and the second index idx2 are sent to the terminal identity authentication component of the first unmanned terminal;
[0077] 2) The terminal identity authentication component of the first unmanned terminal obtains the communication decryption key from the local secondary control center communication key pool that communicates with the control center according to the second index idx2 , using the communication decryption key Ciphertext Decrypt and get the string ,index and hash value ;
[0078] 3) The terminal identity authentication component of the first unmanned terminal is based on the index Get the key from the broadcast communication key pool As input random number, according to the string Generate irreducible polynomials , then based on the irreducible polynomial and key Generate hash function ;
[0079] 4) The first unmanned terminal obtains the device serial number from the unmanned terminal to be authenticated , using a hash function Computing device serial number The hash value is obtained ;
[0080] 5) The first unmanned terminal compares and calculates the hash value and hash value If they are consistent, the authentication is successful, and the first unmanned terminal accepts the unmanned terminal to be authenticated as one of the unmanned system swarm, and proceeds to the next step; if they are inconsistent, the unmanned terminal to be authenticated is an illegal terminal, and the first unmanned terminal refuses to include the unmanned terminal to be authenticated into the unmanned system swarm;
[0081] 6) The first unmanned terminal feeds back the authentication result to the control center, and the control center incorporates the unmanned terminal to be authenticated into the swarm management.
[0082] In this embodiment, when the number of unmanned terminals to form an unmanned system swarm is relatively large, relying solely on the first unmanned terminal to authenticate all other unmanned terminals would result in low authentication efficiency. In this case, other unmanned terminals, such as the seventh unmanned terminal, can also use the same authentication method described above to authenticate other unmanned terminals. These other unmanned terminals could be the fourth unmanned terminal, the mth unmanned terminal, and so on. This allows multiple unmanned terminals to perform identity authentication in parallel, allowing for mutual authentication of unmanned terminal identities. This improves the efficiency of the authentication process and allows for the swift completion of the unmanned system swarm construction.
[0083] This embodiment uses quantum-secure identity authentication during swarm construction and quantum-secure data encryption during swarm data communication, ensuring the legitimacy of unmanned terminal devices and the security of data communications within the entire unmanned system swarm.
[0084] (3) The terminal communication key pool in each unmanned terminal constituting the unmanned system swarm accepts preset keys, so that any unmanned terminal is preset with a key corresponding to other unmanned terminals in the swarm; for example, the first unmanned terminal is preset with key files k12 to k1n corresponding to the other (n-1) unmanned terminals in the swarm.
[0085] Each unmanned terminal is pre-set with a key corresponding to other unmanned terminals in the swarm. Taking the pre-set terminal communication key pool of the first unmanned terminal as an example, the key pre-setting process in the unmanned terminal is explained:
[0086] First, the first unmanned terminal in the unmanned system swarm obtains the number of unmanned terminals n in the unmanned system swarm from the control center, and then divides its own terminal communication key pool into n-1 sub-terminal communication key pools, such as Figure 4 As shown;
[0087] The first unmanned terminal then establishes a one-to-one correspondence between its own n-1 sub-terminal communication key pool and the corresponding sub-terminal communication key pools of the other (n-1) unmanned terminals except itself. Figure 4 As shown, the dotted lines represent the corresponding relationship between the sub-terminal communication key pools. For example, the first-second sub-terminal communication key pool 122 in the first unmanned terminal corresponds to the second-first sub-terminal key pool 221 in the second unmanned terminal, and are pre-installed with the same communication key file k12; the first-N sub-terminal communication key pool 12n in the first unmanned terminal corresponds to the N-th sub-terminal communication key pool n21 in the n-th unmanned terminal, and are pre-installed with the same communication key file k1n; the second-N sub-terminal communication key pool 22n in the second unmanned terminal corresponds to the N-second sub-terminal communication key pool n22 in the n-th unmanned terminal, and are pre-installed with the same communication key file k2n. The pre-installed key files in other unmanned terminals refer to Figure 4 The preset is performed as shown to obtain communication key files k12 to k1n corresponding to the first unmanned terminal and other (n-1) unmanned terminals.
[0088] (4) When any two unmanned terminals in the swarm conduct point-to-point communication, the keys in their respective terminal communication key pools are consumed; if the unmanned terminal detects that the remaining amount of keys in the terminal communication key pool is less than or equal to the set terminal key remaining threshold parameter, a key replenishment operation is performed; for example, when the first unmanned terminal and the second unmanned terminal conduct point-to-point communication, the keys in the first-second sub-terminal communication key pool 122 and the second-first sub-terminal communication key pool 221 are consumed, and when the terminal key detection component detects that the remaining amount of keys in the first-second sub-terminal communication key pool 122 is less than or equal to the set terminal key remaining threshold parameter, a key replenishment operation of the terminal communication key pool is performed.
[0089] Point-to-point communication between any two unmanned terminals means:
[0090] The Kth unmanned terminal, acting as the sender, obtains the encryption key K3 from the local sub-terminal communication key pool corresponding to the Mth unmanned terminal, acting as the receiver, based on the data to be sent. It records the key index idx3 of the encryption key K3, then uses the encryption key K3 to encrypt the data to obtain the ciphertext DATA. Finally, the ciphertext DATA and the key index idx3 are sent to the Mth unmanned terminal, acting as the receiver.
[0091] The Mth unmanned terminal obtains the decryption key from the local sub-terminal communication key pool corresponding to the Kth unmanned terminal according to the received key index idx3 , using this decryption key Decrypt the received ciphertext DATA to obtain the plaintext data , the plaintext data This is the communication data between the Kth unmanned terminal and the Mth unmanned terminal. Simply speaking, the first unmanned terminal obtains the encryption key from the first-second sub-terminal communication key pool 122, and the second unmanned terminal obtains the decryption key from the second-first sub-terminal communication key pool 221.
[0092] The communication process here can also be referred to the Chinese patent "A Mesh Self-organizing Network Global Quantum Secure Communication Method and System" with application date of December 19, 2024 and application number 202411874129.5 (publication number CN119675862A, publication date of March 21, 2025), which will not be repeated here.
[0093] The specific process of performing the key supplement operation is as follows:
[0094] A1: The Xth unmanned terminal, one of the two parties performing key supplementation, first finds the sub-terminal communication key pool to be supplemented corresponding to the Yth unmanned terminal, the other party performing key supplementation. Its key detection component then generates a key supplement instruction and sends it to a local true random number generator. The key supplement instruction includes a supplement key size parameter, which is the storage size of the sub-terminal communication key pool to be supplemented minus the remaining key size in the current sub-terminal communication key pool.
[0095] A2: The true random number generator responds to the key supplement instruction, generates a set of true random numbers with a size equal to the supplement key size parameter as the supplement key, and sends the supplement key to the key distribution component; the key distribution component of the Xth unmanned terminal then sends the supplement key to the sub-terminal communication key pool to be supplemented, and sends the supplement key to the Yth unmanned terminal via the data communication unit; the sending process of the data communication unit here can be encrypted sending, consuming keys from the remaining keys in the sub-terminal communication key pool.
[0096] A3: The Yth unmanned terminal finds the sub-terminal communication key pool to be supplemented corresponding to the Xth unmanned terminal, and then fills the supplementary key into the remaining keys of the sub-terminal communication key pool to be supplemented to form a new communication key file.
[0097] It can be seen that through the dynamic and real-time supplementation of communication keys between unmanned terminals in the swarm, the real-time and security of quantum secure encrypted communication in the unmanned system swarm is effectively ensured, supporting large-scale network deployment without the need for human intervention at a later stage. By separating the unmanned terminals from the swarm and performing key supplementation operations, quantum secure encrypted communication can be carried out continuously and for a long time.
[0098] When any unmanned terminal performs broadcast communication with multiple other unmanned terminals, the broadcast communication keys in their respective broadcast communication key pools are consumed; if the key remainder detection component of the unmanned terminal detects that the key remainder in the broadcast communication key pool is less than or equal to the broadcast key threshold, the unmanned terminal requests a broadcast key update operation from the control center through the data communication unit;
[0099] like Figure 5 As shown in the figure, the specific process of the broadcast key update operation is as follows:
[0100] B1: The control center sends an update key J-UP of length j to the broadcast communication key pool in each unmanned terminal in the unmanned system swarm; the length j can be, for example, 1K;
[0101] B2: Each unmanned terminal divides the original broadcast key of length J in the local broadcast communication key pool into (i+1) subkeys according to the granularity of length j; where i = [J / j], the 1st to i-th subkeys are denoted as J1 to Ji, all with length j; the (i+1)th subkey is denoted as J(i+1), with length Ji*j;
[0102] B3: Use the updated key J-UP to perform an XOR operation with each of the 1st to i-th subkeys to obtain a new , until the new ; For subkey J(i+1), intercept the key J-UP1 from the first to the Ji*jth bit in the update key J-UP and perform an XOR operation with the subkey J(i+1) to obtain the new After the XOR is completed, a new broadcast key of length J is obtained. It can be understood that for the last subkey J(i+1), the control center and the unmanned terminal can also negotiate the interception position in the updated key J-UP. As long as the length of the key J-UP1 intercepted by each unmanned terminal is consistent, the new broadcast key of each unmanned terminal after the key update is consistent.
[0103] When any unmanned terminal communicates with the control center, such as Figure 3As shown, the keys in the communication key pools of the respective control centers are consumed; if the unmanned terminal detects that the key balance in the communication key pool of the control center is less than or equal to the control center communication key threshold, the unmanned terminal requests the control center to update the control center communication key. For example, when the first unmanned terminal communicates with the control center, the keys in the secondary control center communication key pool in the first unmanned terminal and the primary control center communication key pool in the control center that has a symmetric key with the secondary control center communication key pool of the first unmanned terminal are consumed; when the key balance detection component of the first unmanned terminal detects that the key balance in the secondary control center communication key pool is less than or equal to the control center communication key threshold, the first unmanned terminal requests the control center to update the control center communication key through the data communication unit. The update method can be consistent with the update method of the broadcast communication key pool or the supplementary method with the terminal communication key, which will not be repeated here.
[0104] like Figure 6 As shown, the three situations that occur in step (4) of this embodiment are communication situations that may occur in unmanned terminals in the bee colony, and are not steps with a sequential relationship. As can be seen, this embodiment uses a small number of update keys to act on the original broadcast key, avoiding the problem of occupying a large amount of communication bandwidth caused by the full update of the broadcast key. Moreover, the update key does not replace the original broadcast key, and the original broadcast key is preset in advance, effectively avoiding the risk of broadcast key leakage.
Claims
1. A quantum-safe unmanned system swarm communication method, characterized in that: The participants of the method are a control center and multiple unmanned terminals, and the method includes the following steps: (1) The control center assigns a security identity to each unmanned terminal; each unmanned terminal is pre-installed with a secondary control center communication key pool for communicating with the control center, and the control center is pre-installed with a primary control center communication key pool that has a symmetric key with the secondary control center communication key pool of each unmanned terminal; and the control center and each unmanned terminal are also pre-installed with a broadcast communication key pool with the same key; (2) The control center selects an unmanned terminal as the first unmanned terminal. The first unmanned terminal acts as the identity authentication party to authenticate the identities of other unmanned terminals. The unmanned terminals that have passed the authentication are constructed into an unmanned system swarm, and the first unmanned terminal is added to the unmanned system swarm. (3) The terminal communication key pool in each unmanned terminal constituting the unmanned system swarm receives a preset key, so that any unmanned terminal is preset with a key corresponding to other unmanned terminals in the swarm; (4) When any two unmanned terminals in the swarm conduct point-to-point communication, the keys in their respective terminal communication key pools are consumed; if the unmanned terminal detects that the remaining key amount in the terminal communication key pool is less than or equal to the set terminal key remaining threshold parameter, the key replenishment operation is performed; When any unmanned terminal performs broadcast communication with multiple other unmanned terminals, the keys in their respective broadcast communication key pools are consumed; if the unmanned terminal detects that the remaining key in the broadcast communication key pool is less than or equal to the broadcast key threshold, the unmanned terminal requests a broadcast key update operation from the control center; When any unmanned terminal communicates with the control center, it consumes the key in the communication key pool of the respective control center; if the unmanned terminal detects that the key remainder in the communication key pool of the control center is less than or equal to the control center communication key threshold, the unmanned terminal requests the control center to update the control center communication key.
2. A quantum-safe unmanned system swarm communication method according to claim 1, characterized in that: Before adding the first unmanned terminal to the unmanned system swarm, the method further includes: selecting an unmanned terminal from the unmanned system swarm to perform identity authentication on the first unmanned terminal as the identity authentication party.
3. The quantum-safe unmanned system swarm communication method according to claim 1, characterized in that: The specific process of the control center assigning a security identity to each unmanned terminal is as follows: The control center generates a hash value based on the device serial number IDX of the unmanned terminal. The hash value serves as the security identity of the unmanned terminal. The process is as follows: the control center generates an irreducible polynomial locally , record the string consisting of the coefficients of each term except the highest term in the irreducible polynomial as The control center then obtains the first key K1 from the broadcast communication key pool as the input random number, using the irreducible polynomial And the first key K1 generates a hash function ; Input the device serial number IDX of the unmanned terminal into the hash function Get a secure identity ; The control center records the first index idx1 of the first key K1 in the broadcast communication key pool.
4. The quantum-safe unmanned system swarm communication method according to claim 3, characterized in that: The specific process of identity authentication is as follows: 1) The security identity of the unmanned terminal to be authenticated is The control center obtains the communication encryption key K2 from the main control center communication key pool that has a symmetric key with the secondary control center communication key pool of the first unmanned terminal, records the second index idx2 of the communication encryption key K2, and then uses the communication encryption key K2 to encrypt the string , the first index idx1 and the security identity identifier of the unmanned terminal to be authenticated , get the ciphertext , the ciphertext and the second index idx2 are sent to the first unmanned terminal; 2) The first unmanned terminal obtains the communication decryption key from the local secondary control center communication key pool that communicates with the control center according to the second index idx2 , using the communication decryption key Ciphertext Decrypt and get the string ,index and hash value ; 3) The first unmanned terminal is based on the index Get the key from the broadcast communication key pool As input random number, according to the string Generate irreducible polynomials , then based on the irreducible polynomial and key Generate hash function ; 4) The first unmanned terminal obtains the device serial number from the unmanned terminal to be authenticated , using a hash function Computing device serial number The hash value is obtained ; 5) The first unmanned terminal compares and calculates the hash value and hash value If they are consistent, the authentication is successful, and the first unmanned terminal accepts the unmanned terminal whose identity is to be authenticated as one of the unmanned system swarm, and proceeds to the next step; if they are inconsistent, the first unmanned terminal refuses to include the unmanned terminal whose identity is to be authenticated into the unmanned system swarm; 6) The first unmanned terminal feeds back the authentication result to the control center, and the control center incorporates the unmanned terminal to be authenticated into the swarm management.
5. The quantum-safe unmanned system swarm communication method according to claim 1, characterized in that: The provision of pre-installed keys for each unmanned terminal corresponding to other unmanned terminals in the swarm means: First, each unmanned terminal in the unmanned system swarm obtains the number of unmanned terminals n in the swarm from the control center, and then divides its own terminal communication key pool into n-1 sub-terminal communication key pools; Each unmanned terminal then establishes a one-to-one correspondence between its own n-1 sub-terminal communication key pool and the corresponding sub-terminal communication key pools of the other (n-1) unmanned terminals except itself.
6. The quantum-safe unmanned system swarm communication method according to claim 5, characterized in that: The point-to-point communication between any two unmanned terminals refers to: The Kth unmanned terminal, acting as the sender, obtains the encryption key K3 from the local sub-terminal communication key pool corresponding to the Mth unmanned terminal, acting as the receiver, based on the data to be sent. It records the key index idx3 of the encryption key K3, then uses the encryption key K3 to encrypt the data to obtain the ciphertext DATA. Finally, the ciphertext DATA and the key index idx3 are sent to the Mth unmanned terminal, acting as the receiver. The Mth unmanned terminal obtains the decryption key from the local sub-terminal communication key pool corresponding to the Kth unmanned terminal according to the received key index idx3 , using this decryption key Decrypt the received ciphertext DATA to obtain the plaintext data , the plaintext data This is the communication data between the Kth unmanned terminal and the Mth unmanned terminal.
7. The quantum-safe unmanned system swarm communication method according to claim 5, characterized in that: The specific process of performing the key supplement operation is as follows: A1: The Xth unmanned terminal, acting as one of the two parties in the key supplementation process, first finds the sub-terminal communication key pool to be supplemented corresponding to the Yth unmanned terminal, acting as the other party in the key supplementation process. It then generates a key supplement instruction and sends it to a local true random number generator. The key supplement instruction includes a supplement key size parameter, which is the storage size of the sub-terminal communication key pool to be supplemented minus the remaining key size in the current sub-terminal communication key pool. A2: The true random number generator responds to the key supplement instruction and generates a set of true random numbers of a size equal to the supplement key size parameter as a supplement key; the Xth unmanned terminal then sends the supplement key to the sub-terminal communication key pool to be supplemented, and sends the supplement key to the Yth unmanned terminal; A3: The Yth unmanned terminal finds the sub-terminal communication key pool to be supplemented corresponding to the Xth unmanned terminal, and then fills the supplementary key into the remaining keys of the sub-terminal communication key pool to be supplemented to form a new communication key file.
8. The quantum-safe unmanned system swarm communication method according to claim 1, characterized in that: The specific process of the broadcast key update operation is: B1: The control center sends the updated key J-UP of length j to the broadcast communication key pool in each unmanned terminal in the unmanned system swarm; B2: Each unmanned terminal divides the original broadcast key of length J in the local broadcast communication key pool into (i+1) subkeys according to the granularity of length j; Where i = [J / j], the 1st to i-th subkeys are recorded as J1 to Ji, and their lengths are all j; the (i+1)th subkey is recorded as J(i+1), and its length is Ji*j; B3: Use the updated key J-UP to perform an XOR operation with each of the 1st to i-th subkeys to obtain a new J1, until the new ; For subkey J(i+1), intercept the key J-UP1 from the first to the Ji*jth bit in the update key J-UP and perform an XOR operation with the subkey J(i+1) to obtain the new ; After the XOR is completed, a new broadcast key of length J is obtained.
9. A system based on the quantum-safe unmanned system swarm communication method according to any one of claims 1 to 8, characterized in that: The system includes a control center and an unmanned system swarm connected to the control center, wherein the unmanned system swarm is composed of a plurality of unmanned terminals connected in pairs; The control center is used to assign a security identity to each unmanned terminal and communicate with each unmanned terminal; it is also used to respond to requests from unmanned terminals to perform control center communication key update operations and broadcast key update operations; The unmanned terminals in the unmanned system swarm are used to communicate with the control center and the unmanned terminals in the swarm; and are also used to respond to requests from the unmanned terminals to perform key supplement operations.
10. The system according to claim 9, characterized in that: All unmanned terminals in the unmanned system swarm include a quantum security module, which includes a terminal association unit, a data communication unit, a status reporting unit, a key management unit, and a terminal key supplement unit. The terminal association unit, the key management unit, the terminal key supplement unit, and the data communication unit are connected in sequence, and the data communication unit is also connected to the key management unit and the terminal association unit. The terminal association unit includes a terminal identity authentication component for performing identity authentication and forming unmanned terminals that pass identity authentication into a swarm; The data communication unit is used to receive and send data, and obtain the corresponding key from the key management unit according to data requirements to encrypt or decrypt the data; The status reporting unit is used to send a heartbeat to the control center to confirm whether the unmanned terminal where the quantum security module is located is online; The key management unit includes a terminal communication key pool, a sub-control center communication key pool, a broadcast communication key pool and a key remainder detection component, and the key remainder detection component is connected to the broadcast communication key pool and the sub-control center communication key pool respectively; the terminal communication key pool is used to provide the key required for the encryption and decryption process of communication data between the unmanned terminal and other unmanned terminals in the bee colony; the sub-control center communication key pool is used to provide the key required for the encryption and decryption process of information sent by the control center received via the data communication unit; the broadcast communication key pool is used to provide the key required for the encryption and decryption process of broadcast messages in the bee colony; the key remainder detection component is used to monitor the key remainder in the broadcast communication key pool and the sub-control center communication key pool, and to generate a request for a key update operation to the control center; The terminal key supplement unit includes a terminal key detection component, a true random number generator and a key distribution component connected in sequence, and the terminal key detection component and the key distribution component are both connected to the terminal communication key pool; the terminal key detection component is used to monitor the key residue in the terminal communication key pool, and to generate a key supplement instruction and send it to the true random number generator; the true random number generator is used to receive the key supplement instruction, generate a true random number as a supplement key, and send the supplement key to the key distribution component; the key distribution component is used to send the supplement key directly to the terminal communication key pool, and to send the supplement key to the unmanned terminal required for key supplement through the data communication unit.
Citation Information
Patent Citations
Flight mission-oriented unmanned aerial vehicle block chain establishment method, system, device and terminal
CN113949432A
Quantum security communication system of unmanned aerial vehicle
CN117041946A
Anti-attack global quantum security key supplement method
CN119653359A
Mesh ad hoc network global quantum security communication method and system
CN119675862A
Mobile quantum random number supplementing device and system
CN213279683U
Cited By
Multi-robot communication system, method, storage medium and computer program product
CN122027152A