Quantum security unmanned system group bee colony communication method and system
By employing a quantum-safe unmanned system swarm communication method, and utilizing the control center to allocate swarm identifiers and security identity identifiers, a symmetric key pool and a broadcast communication key pool are established. This solves the problems of spectrum resource competition, complex topology changes, and security threats in unmanned system swarms, and achieves efficient and secure cross-swarm collaborative communication.
Patent Information
- Application Number
- CN202511080783.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-04
- Publication Date
- 2025-11-11
AI Technical Summary
Unmanned system swarms face challenges such as intensified competition for spectrum resources, decreased channel utilization, complex topology changes, rigid resource allocation, lack of coordination in cross-swarm communication, and security threats. They are particularly vulnerable to problems in dynamic mission scenarios, making it difficult to adapt to mission requirements and ensure communication security.
A quantum-safe unmanned system swarm communication method is adopted. The control center allocates swarm identifiers and security identity identifiers, establishes a symmetric key pool and a broadcast communication key pool, realizes quantum-safe communication within and between groups, and uses a quantum-safe module for identity authentication and key management, supporting cross-group collaboration and dynamic key replenishment.
It improves the communication security level of unmanned system swarms, adapts to large-scale deployment and dynamic tasks, enhances communication efficiency and anti-attack capabilities, and realizes quantum-secure unmanned terminal communication.
Smart Images

Figure CN120935558A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of quantum communication technology, and in particular to a quantum-safe unmanned system swarm communication method and system. Background Technology
[0002] In existing technologies, unmanned system swarms mostly adopt a single-swarm communication mode, with all nodes sharing the same communication resource pool. This leads to intensified spectrum resource competition and decreased channel utilization during large-scale deployments. Especially under the communication requirements of dynamic mission scenarios (such as area search and coordinated strike), the high mobility of nodes within the swarm further triggers frequent topology changes, making traditional routing protocols and time slot allocation mechanisms inefficient. In addition, a single swarm structure is difficult to support differentiated mission requirements. For example, some nodes need high-frequency interaction (such as formation control), while other nodes only need low-frequency state synchronization. Existing methods cannot flexibly adapt to this, resulting in the following problems: each group operates independently, with insufficient inter-group coordination and a lack of efficient relay mechanisms for cross-group communication, leading to global information synchronization delays; fixed group divisions are difficult to adapt to dynamic mission changes, resource allocation is rigid, and spectrum resource waste or conflicts are easily caused; when nodes switch between groups, routing needs to be reconstructed, topology maintenance is complex, and control overhead is increased.
[0003] Meanwhile, a swarm of unmanned systems may not only involve individual unmanned terminals collaborating directly to complete a single task, but it may also involve a single step in a complete task, requiring a group of unmanned terminals to work together. The entire task is completed through the collaboration of multiple unmanned terminal groups. Especially when there are a large number of unmanned terminal groups within the swarm, data security is more vulnerable to threats in multi-node communication.
[0004] In unmanned system swarm communication involving multiple unmanned terminals, the distributed, dynamic, multi-hop network architecture and cross-group collaboration and heterogeneous data interaction present various security threats that can affect the reliability and confidentiality of swarm tasks. During group collaboration, if a relay node is compromised, it may tamper with or forge cross-group data, leading to communication interruptions, data corruption, or swarm disconnection, ultimately causing global task chaos. Attackers may impersonate legitimate unmanned terminals to join the swarm, disrupting the topology by sending false routing information (e.g., black hole attacks), or stealing intra-group communication data and interfering with resource allocation within the group. Regarding the use of communication keys in unmanned system swarms, traditional public key infrastructure (PKI) is ill-suited for highly mobile scenarios; delayed key updates or uneven distribution can lead to decryption failures or key leaks.
[0005] Therefore, there is an urgent need for a communication method for multiple unmanned terminal swarms, which can achieve efficient collaboration of large-scale unmanned system swarms through reasonable hierarchical resource scheduling and secure cross-swarm relay mechanisms. Summary of the Invention
[0006] Purpose of the invention: This application provides a quantum-safe unmanned system swarm communication method and system to solve the problems existing in the prior art.
[0007] Technical Solution: This invention provides a quantum-safe swarm communication method for unmanned systems. The participants in the method include a control center and multiple unmanned terminals. The method includes the following steps:
[0008] Step 1: The control center divides the unmanned terminals into corresponding groups according to their work tasks and assigns them a swarm identifier and a group identifier; among them, the swarm identifiers of unmanned terminals within the same group are the same.
[0009] Step 2: The control center assigns a security identity to each unmanned terminal based on the bee colony identifier; wherein, each unmanned terminal in the small group bee colony is pre-configured with a secondary control center communication key pool that communicates with the control center, and the control center is pre-configured with a primary control center communication key pool that has a symmetric key with the secondary control center communication key pool of each unmanned terminal; and each unmanned terminal in the control center and the small group bee colony is configured with a broadcast communication key pool for each group.
[0010] Step 3: The control center selects one unmanned terminal in each group as the first unmanned terminal in that group and adds a swarm identifier; the first unmanned terminal in the group acts as the identity authenticator to authenticate other unmanned terminals in the same group, and the unmanned terminals that have passed the authentication in the same group are built into an unmanned terminal group; after all groups have completed the above identity authentication operation, the unmanned terminal groups that have passed the authentication are built into an unmanned system group swarm.
[0011] Step 4: The terminal communication key pool of each unmanned terminal in each unmanned terminal group that constitutes the unmanned system swarm accepts a preset key so that all unmanned terminal communications within the same group have a symmetric key, and all unmanned terminal communications across groups have a symmetric key.
[0012] Step 5: When any two unmanned terminals in the unmanned system swarm communicate point-to-point, they consume the keys in their respective terminal communication key pools; if an unmanned terminal detects that the remaining key amount in its terminal communication key pool is less than or equal to the set terminal key remaining threshold parameter, it performs a key replenishment operation accordingly.
[0013] When any unmanned terminal conducts broadcast communication with multiple other unmanned terminals in the unmanned system swarm, it consumes the key in its respective broadcast communication key pool; if the unmanned terminal detects that the remaining key in the broadcast communication key pool is less than or equal to the broadcast key threshold, the unmanned terminal requests a broadcast key update operation from the control center.
[0014] When any unmanned terminal communicates with the control center, it consumes the key in its respective control center's communication key pool. If the unmanned terminal detects that the remaining key in the control center's communication key pool is less than or equal to the control center's communication key threshold, the unmanned terminal requests a control center communication key update operation from the control center.
[0015] As an improvement to the present invention, in step 2, the broadcast communication key pool configured for each group refers to:
[0016] Each unmanned terminal in the control center and the swarm of groups divides its broadcast communication key pool into m sub-key pools according to the number of terminal groups m. The control center and each unmanned terminal have the same key file pre-set in the first to the mth sub-key pools of the broadcast communication key pool.
[0017] As an improvement of the present invention, the specific process of the control center assigning a security identity to each unmanned terminal based on the bee colony identifier in step 2 includes: the control center generating a device serial number IDNX based on the bee colony identifier N of the unmanned terminal, and generating a hash value based on the device serial number IDNX; the hash value serves as the security identity of the unmanned terminal.
[0018] As an improvement of the present invention, the process of generating the hash value is as follows: the control center generates an irreducible polynomial p1(x) locally, and records the string composed of the coefficients of each term except the highest term in the irreducible polynomial as str1; the control center then obtains the first key K1 from the nth group of the broadcast communication sub-key pool of the broadcast communication key pool as the input random number, and uses the irreducible polynomial p1(x) and the first key K1 to generate a hash function hp1,K1; the device serial number IDNX of the unmanned terminal is input into the hash function hp1,K1 to obtain the security identity identifier = hp1,K1(IDNX); the control center records the first index idx1 of the first key K1 in the nth group of the broadcast communication sub-key pool.
[0019] As an improvement of the present invention, the symmetric key for communication of all unmanned terminals within the same group in step 4 includes: the key pool for intra-group communication in the Na-th unmanned terminal within the group with beehive identifier N is the n-th group terminal communication sub-key pool; the Na-th unmanned terminal divides the n-th group terminal communication sub-key pool into x-1 grandchild terminal communication key pools according to the number x of unmanned terminals in its group; and establishes a one-to-one correspondence between its own x-1 grandchild terminal communication key pools and the corresponding grandchild terminal communication key pools in the other (x-1) unmanned terminals within the group;
[0020] In step 4, all unmanned terminal communications between groups have symmetric keys, including: the key files pre-set in the sub-key pool KNH of the h-th group terminal communication in each unmanned terminal in the group with bee colony identifier N are the same as those in the sub-key pool KHN of the n-th group terminal communication in each unmanned terminal in the group with bee colony identifier H.
[0021] As an improvement of the present invention, in step 4, all unmanned terminal communication between groups has a symmetric key or includes: the h-th group terminal communication sub-key pool in each unmanned terminal in the group with beehive identifier N divides the h-th group terminal communication sub-key pool into t grandchild terminal communication key pools according to the number t of unmanned terminals in the group with beehive identifier H, and establishes a one-to-one correspondence between its own t grandchild terminal communication key pools and the corresponding grandchild terminal communication key pools in the t unmanned terminals in the group with beehive identifier H, and the key files preset in the corresponding grandchild terminal communication key pools are the same.
[0022] As an improvement of the present invention, in step 5, the point-to-point communication between any two unmanned terminals includes: the two unmanned terminals are the Na-th unmanned terminal in the group identified as N and the Hb-th unmanned terminal in the group identified as H, wherein the key pool for this communication in the Na-th unmanned terminal as the sender is the terminal communication sub-key pool KNH of the h-th group, and the key pool for this communication in the Hb-th unmanned terminal as the receiver is the terminal communication sub-key pool KHN of the n-th group;
[0023] The Na-th unmanned terminal compares the key start position information k-startnh of the h-th group terminal communication sub-key pool KNH recorded locally with the key start position information k-starthn of the n-th group terminal communication sub-key pool KHN recorded locally by the Hb-th unmanned terminal. If k-startnh ≠ k-starthn, the larger of k-startnh and k-starthn is used as the new start position of the key file in the two group terminal communication sub-key pools; if k-startnh = k-starthn, the two group terminal communication sub-key pools are not updated.
[0024] The Na-th unmanned terminal selects a communication key k-mnh of the same length as the data mes1 to be sent, starting from the key start position k-startnh in the communication sub-key pool KNH of the h-th group terminal. It records the key index idx-mnh of the communication key k-mnh, uses the communication key k-mnh to perform an encryption operation on the data mes1, and obtains the ciphertext MES1. The ciphertext MES1 and the key index idx-mnh are sent to the Hb-th unmanned terminal. At the same time, the Na-th unmanned terminal updates the key start position information k-startnh in the communication sub-key pool KNH of the h-th group terminal and broadcasts the start position information k-startnh to all unmanned terminals in the beehive identified as N for updating.
[0025] The Hb unmanned terminal obtains the decryption key k-mhn from the local nth group terminal communication sub-key pool KHN based on the received key index idx-mnh. It uses the decryption key k-mhn to decrypt the received ciphertext MES1 to obtain the plaintext data mes1′. This plaintext data is the communication data sent by the Nath unmanned terminal to the Hb unmanned terminal. At the same time, the Hb unmanned terminal updates the key start position information k-starthn in the nth group terminal communication sub-key pool KHN and broadcasts the start position information k-starthn to all unmanned terminals in the beehive identified as H for updating.
[0026] As an improvement of the present invention, in step 5, the specific process of performing the intra-group or inter-group key supplementation operation is as follows:
[0027] A1: The Xth unmanned terminal, acting as one of the key supplementing parties, first finds the group terminal communication sub-key pool to be supplemented corresponding to the Yth unmanned terminal, which is also acting as the key supplementing party. Then, it generates a key supplementation instruction and sends it to the local true random number generator. This key supplementation instruction contains a supplementary key size parameter, which is the storage size of the group terminal communication sub-key pool to be supplemented minus the remaining key size in the current group terminal communication sub-key pool. Here, X and Y include the bee colony identifier and the intra-group identifier.
[0028] A2: The true random number generator responds to the key replenishment instruction and generates a set of true random numbers with a size equal to the replenishment key size parameter as the replenishment key; the Xth unmanned terminal then sends the replenishment key to the communication subkey pool of the group terminal to be replenished, and sends the replenishment key to the Yth unmanned terminal;
[0029] A3: The Yth unmanned terminal finds the group terminal communication sub-key pool corresponding to the Xth unmanned terminal, and then fills the remaining key in the group terminal communication sub-key pool with the supplementary key to form a new communication key file.
[0030] As an improvement of the present invention, the terminal communication key pool includes an intra-group terminal communication sub-key pool and an inter-group terminal communication sub-key pool. The same key file is pre-set in the inter-group terminal communication sub-key pool of all unmanned terminals in the unmanned system swarm.
[0031] In step 5, the two unmanned terminals are two unmanned terminals in different groups, and the point-to-point communication includes:
[0032] B1: The unmanned terminal that is sending the message and the unmanned terminal that is receiving the message perform an alignment operation on the starting position of the inter-group communication key in the inter-group terminal communication sub-key pool, and take the larger key starting position of the two as the starting position of the inter-group communication key add1.
[0033] B2: The sending unmanned terminal uses the inter-group communication key starting position add1 as the initial key starting position, obtains the inter-group communication key of the corresponding length according to the length requirement of this communication data, and records the corresponding key index. After encrypting the communication data, it sends the ciphertext, key index and updated inter-group communication key starting position add2 to the receiving unmanned terminal. The receiving unmanned terminal obtains the decryption key from the local inter-group terminal communication sub-key pool according to the key index, decrypts the communication data, and updates the local inter-group communication key starting position.
[0034] B3: The unmanned terminal acting as the sender or the unmanned terminal acting as the receiver broadcasts the updated inter-group communication key starting position add2 within the swarm to notify other unmanned terminals to update.
[0035] As an improvement of the present invention, in step 5, the specific process of performing broadcast communication is as follows:
[0036] The receiving unmanned terminal parses the swarm identifier of the sending unmanned terminal, addresses the corresponding group broadcast communication subkey pool based on the swarm identifier, obtains the corresponding broadcast communication key from the corresponding group broadcast communication subkey pool based on the key index carried in the broadcast message, and uses the broadcast communication key to encrypt and decrypt the broadcast message before communication.
[0037] As an improvement of the present invention, a system based on the quantum-safe unmanned system group terminal group communication method described above is also provided. The system includes a control center and an unmanned system group swarm connected to the control center. The unmanned system group swarm consists of multiple terminal groups connected in pairs, and each terminal group consists of multiple unmanned terminals connected in pairs.
[0038] The control center is used to assign a security identity to each unmanned terminal and to communicate with each unmanned terminal; it is also used to perform control center communication key update operations and broadcast key update operations in response to requests from unmanned terminals.
[0039] The unmanned terminals in the terminal group are used to communicate with the control center and other unmanned terminals in the terminal group; they are also used to perform key replenishment operations in response to requests from unmanned terminals.
[0040] As an improvement of the present invention, the unmanned terminals in the unmanned system swarm all include a quantum security module. The quantum security module includes a terminal association unit, a data communication unit, a status reporting unit, a key management unit, and a terminal key supplementation unit. The terminal association unit, the key management unit, the terminal key supplementation unit, and the data communication unit are connected in sequence. The data communication unit is also connected to the key management unit and the terminal association unit.
[0041] The terminal association unit includes a terminal identity authentication component and a terminal group identity component connected by communication. The terminal identity authentication component is used to perform identity authentication and to form terminal groups and swarms of unmanned terminals that have passed the identity authentication. The terminal group identity component is used to assign swarm identifiers to unmanned terminals, record the terminal group to which the unmanned terminal belongs, and feed back the group information to which the unmanned terminal belongs to the control center.
[0042] The data communication unit is used to receive and send data, and to obtain the corresponding key from the key management unit to encrypt or decrypt the data according to the data requirements.
[0043] The status reporting unit is used to send a heartbeat to the control center to confirm whether the unmanned terminal where the quantum security module is located is online.
[0044] The key management unit includes a terminal communication key pool, a secondary control center communication key pool, a broadcast communication key pool, and a key balance detection component. The key balance detection component is connected to the broadcast communication key pool and the secondary control center communication key pool, respectively. The terminal communication key pool includes multiple sub-key pools for group terminal communication, used to provide the keys required for the encryption and decryption of communication data between the unmanned terminal and other unmanned terminals in the group swarm. The secondary control center communication key pool is used to provide the keys required for the encryption and decryption of information received from the control center via the data communication unit. The broadcast communication key pool includes multiple sub-key pools for group broadcast communication, used to provide the keys required for the encryption and decryption of broadcast messages in the group swarm. The key balance detection component is used to monitor the key balance in the broadcast communication key pool and the secondary control center communication key pool, and to generate a key update request to the control center.
[0045] The terminal key replenishment unit includes a terminal key detection component, a true random number generator, and a key distribution component connected in sequence. Both the terminal key detection component and the key distribution component are connected to the terminal communication key pool. The terminal key detection component is used to monitor the key balance in the terminal communication key pool and to generate a key replenishment command to send to the true random number generator. The true random number generator is used to receive the key replenishment command, generate a true random number as a replenishment key, and send the replenishment key to the key distribution component. The key distribution component is used to send the replenishment key directly to the terminal communication key pool and to send the replenishment key to the unmanned terminal required for key replenishment through a data communication unit.
[0046] Beneficial effects: (1) A method for quantum-safe communication between unmanned terminals in an unmanned system swarm is proposed, which raises the communication security level of the entire unmanned system swarm to the quantum-safe level;
[0047] (2) The swarm scheme proposed in this embodiment is suitable for the deployment of large-scale unmanned systems and has strong scalability; the quantum-safe identity authentication method prevents unauthorized unmanned terminals from intervening in the swarm.
[0048] (3) The existence of the quantum security module enables existing unmanned terminals to achieve quantum security through the addition of the quantum security module without the need for hardware modification. Attached Figure Description
[0049] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0050] Figure 1 This is a schematic diagram of the swarm system of the unmanned system group in this application;
[0051] Figure 2 This is a schematic diagram of the structure of the unmanned terminal quantum security module of this application;
[0052] Figure 3 This is a flowchart illustrating the swarm communication method for the unmanned system group in this application;
[0053] Figure 4 This is a schematic diagram of the broadcast communication key pool structure in the unmanned terminal of this application;
[0054] Figure 5 A schematic diagram showing the correspondence between the unmanned terminal of this application and other unmanned terminals in the group to establish a grandchild terminal communication key pool;
[0055] Figure 6 A schematic diagram showing the correspondence between the unmanned terminal of this application and other unmanned terminals in a cross-group to establish a sub-key pool for group terminal communication;
[0056] Figure 7 A schematic diagram illustrating the correspondence between the unmanned terminal of this application and other unmanned terminals across groups in establishing a grandchild terminal communication key pool;
[0057] Figure 8 This is a schematic diagram of another embodiment of the terminal communication key pool of this application;
[0058] Figure 9 This is a schematic diagram illustrating the process of updating the broadcast key for this application. Detailed Implementation
[0059] To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0060] In an unmanned system swarm, it's not just individual unmanned terminals directly collaborating to complete a single task; it might also be a part of a complete task requiring a group of unmanned terminals to work together. The entire task is completed through the collaboration of multiple unmanned terminal teams. In such cases, the unmanned system swarm system involved in this invention... Figure 1 As shown, the unmanned system swarm system consists of multiple unmanned terminal groups, each of which includes at least one unmanned terminal. The system includes a control center and an unmanned system swarm connected to the control center. Each unmanned system swarm is composed of multiple terminal groups connected in pairs, and each terminal group consists of multiple unmanned terminals connected in pairs. In the unmanned system swarm system of this invention, the control center is used to assign a secure identity to each unmanned terminal and communicate with each unmanned terminal; it is also used to respond to requests from unmanned terminals to perform control center communication key update operations and broadcast key update operations; the unmanned terminals in the terminal groups are used to communicate with the control center and other unmanned terminals in the terminal groups; and they are also used to respond to requests from unmanned terminals to perform key replenishment operations.
[0061] In embodiments of the present invention, such as Figure 2As shown, each unmanned terminal in the unmanned system swarm includes a quantum security module. The quantum security module includes a terminal association unit, a data communication unit, a status reporting unit, a key management unit, and a terminal key replenishment unit. The terminal association unit, key management unit, terminal key replenishment unit, and data communication unit are connected in sequence. The data communication unit is also connected to the key management unit and the terminal association unit.
[0062] The terminal association unit includes a terminal identity authentication component and a terminal group identity component connected by communication. The terminal identity authentication component is used to perform identity authentication and to form terminal groups and swarms of unmanned terminals that have passed the identity authentication. The terminal group identity component is used to assign swarm identifiers to unmanned terminals, record the terminal group to which the unmanned terminal belongs, and feed back the group information to which the unmanned terminal belongs to the control center.
[0063] The data communication unit is used to receive and send data, and to obtain the corresponding key from the key management unit to encrypt or decrypt the data according to the data requirements.
[0064] The status reporting unit is used to send a heartbeat to the control center to confirm whether the unmanned terminal where the quantum security module is located is online.
[0065] The key management unit includes a terminal communication key pool, a secondary control center communication key pool, a broadcast communication key pool, and a key balance detection component. The key balance detection component is connected to both the broadcast communication key pool and the secondary control center communication key pool. The terminal communication key pool also includes sub-key pools for each unmanned terminal group, where the sub-key pool is used for encrypted data communication between unmanned terminals within the group, and the sub-key pools for encrypted data communication between unmanned terminals in other groups. The secondary control center communication key pool provides the keys required for encrypting and decrypting information received from the control center via the data communication unit. The broadcast communication key pool includes sub-key pools for broadcast communication, providing the keys required for encrypting and decrypting broadcast messages in the group swarm, and enabling the reception of broadcast information from other unmanned terminal groups. The key balance detection component monitors the key balance in the broadcast communication key pool and the secondary control center communication key pool, and generates requests for key update operations to the control center.
[0066] The terminal key replenishment unit includes a terminal key detection component, a true random number generator, and a key distribution component connected in sequence. Both the terminal key detection component and the key distribution component are connected to the terminal communication key pool. The terminal key detection component is used to monitor the key balance in the terminal communication key pool and to generate a key replenishment command to send to the true random number generator. The true random number generator is used to receive the key replenishment command, generate a true random number as a replenishment key, and send the replenishment key to the key distribution component. The key distribution component is used to send the replenishment key directly to the terminal communication key pool and to send the replenishment key to the unmanned terminal required for key replenishment through a data communication unit.
[0067] The aforementioned quantum-safe module can exist in the form of a plug-in (e.g., a chip) in an unmanned terminal without requiring any hardware modifications to existing unmanned terminals to meet the communication requirements of quantum security.
[0068] This system can replenish communication keys during communication without manual intervention. By detaching the unmanned terminal from the swarm for key replenishment, continuous and long-term quantum-secure encrypted communication can be achieved. This ensures the communication security of the unmanned system swarm during mission execution and enhances the unmanned system's resistance to attacks.
[0069] Based on the aforementioned unmanned terminal device and unmanned system swarm system, this invention proposes a quantum-safe unmanned system swarm communication method adapted to this unmanned terminal device and unmanned system swarm system. For example... Figure 3 As shown, the communication method includes the following steps:
[0070] Step 1: The control center divides the unmanned terminals into corresponding groups according to their work tasks, and assigns a swarm identifier and a group identifier to each unmanned terminal. Unmanned terminals within the same group have the same swarm identifier. For example, the swarm identifier of all unmanned terminals in the first unmanned terminal group can be group 1, and the swarm identifier of all unmanned terminals in the Mth unmanned terminal group can be group M. For another example, the group identifier of the second unmanned terminal in the first unmanned terminal group can be 2, and this unmanned terminal can be referred to as unmanned terminal 1-2.
[0071] Step 2: The control center assigns a security identity to each unmanned terminal based on the bee colony identifier; wherein, each unmanned terminal in the small group bee colony is pre-configured with a secondary control center communication key pool that communicates with the control center, and the control center is pre-configured with a primary control center communication key pool that has a symmetric key with the secondary control center communication key pool of each unmanned terminal; and each unmanned terminal in the control center and the small group bee colony is configured with a broadcast communication key pool for each group.
[0072] Specifically, each unmanned terminal in the swarm is configured with a broadcast communication key pool for each group. When the control center assigns a security identity to an unmanned terminal, it selects a key from the broadcast communication key of the corresponding group as the input random number based on the swarm identifier of the unmanned terminal.
[0073] More specifically, such as Figure 4 As shown, the broadcast communication key pool configured for each group refers to the following: each unmanned terminal in the control center and the group swarm divides its broadcast communication key pool into m sub-key pools according to the number of terminal groups m. The control center and each unmanned terminal have the same key file pre-set in the first to the mth sub-key pools of the broadcast communication key pool.
[0074] In this embodiment, the meaning of each unmanned terminal in the above-mentioned swarm being configured with a broadcast communication key pool for each group is illustrated by the preset key situation of the broadcast communication key pool in the first unmanned terminal (unmanned terminal 1-1) in the first unmanned terminal group. The number of unmanned terminal groups is m, meaning the unmanned system swarm includes unmanned terminal groups from the first to the Mth unmanned terminal groups. Figure 1 As shown, the first unmanned terminal (1-1) is the first unmanned terminal in the first unmanned terminal group, and its swarm identifier can be marked as group 1. The broadcast communication key pool in the first unmanned terminal (1-1) includes the broadcast communication sub-key pools of the first group to the broadcast communication sub-key pools of the m-th group. The broadcast communication sub-key pool corresponding to the swarm identifier (group 1) of the group to which the first unmanned terminal (1-1) belongs is the broadcast communication sub-key pool of the first group, and the preset key file is the same as the key file in the broadcast communication sub-key pools of the first group in the first unmanned terminals (1-2 to 1-s1). Other group broadcast communication sub-key pools in the first unmanned terminal (1-1), for example, the broadcast communication sub-key pool of the m-th group, have a swarm identifier corresponding to the m-th group broadcast communication sub-key pool as group M (i.e., the M-th unmanned terminal group). The preset key in the broadcast communication sub-key pool of the m-th group is the same as the key file in the broadcast communication sub-key pools of the M-1 to M-sM unmanned terminals in the M-th unmanned terminal group.
[0075] In other words, the broadcast communication key pool of each unmanned terminal in the swarm and its sub-broadcast communication key pool are the same.
[0076] More specifically, in this embodiment, the process of generating a secure identity identifier includes:
[0077] The control center generates a device serial number IDNX based on the swarm identifier N of the unmanned terminal, and then generates a hash value based on the device serial number IDNX. Each unmanned terminal has a unique device serial number, which serves as the unmanned terminal's publicly disclosed primary identity. The process of generating the hash value is as follows: The control center locally generates an irreducible polynomial p1(x), and denotes the string formed by the coefficients of each term except the highest term as str1. The control center then obtains the first key K1 from the nth group of the broadcast communication sub-key pool as the input random number, and uses the irreducible polynomial p1(x) and the first key K1 to generate a hash function hp1,K1. The device serial number IDNX of the unmanned terminal is input into this hash function hp1,K1 to obtain the security identity = hp1,K1(IDNX). The control center records the first index idx1 of the first key K1 in the nth group of the broadcast communication sub-key pool.
[0078] Step 3: The control center selects one unmanned terminal in each group as the first unmanned terminal in that group and adds a swarm identifier; the first unmanned terminal in the group acts as the identity authenticator to authenticate other unmanned terminals in the same group, and the unmanned terminals that have passed the authentication in the same group are built into an unmanned terminal group; after all groups have completed the above identity authentication operation, the unmanned terminal groups that have passed the authentication are built into an unmanned system group swarm.
[0079] Specifically, step 3 includes:
[0080] Step 3-1: The control center selects one unmanned terminal in the Nth group as the first unmanned terminal in the group, and adds a bee group identifier N, which is recorded as the N-1th unmanned terminal;
[0081] Step 3-2: Let the security identity identifier of the unmanned terminal to be authenticated in the Nth group be hp1,K1(IDNY). The control center obtains the communication encryption key K2 from the main control center communication key pool that has a symmetric key with the secondary control center communication key pool of the N-1 unmanned terminal. Record the second index idx2 of the communication encryption key K2. Then use the communication encryption key K2 to encrypt the string str1, the first index idx1 and the security identity identifier hp1,K1(IDNY) of the unmanned terminal to be authenticated, to obtain the ciphertext m = K2⊕(str1,idx1,hp1,K1(IDNY)). Send the ciphertext m and the second index idx2 to the N-1 unmanned terminal.
[0082] Step 3-3: The N-1 unmanned terminal obtains the communication decryption key K2′ from the communication key pool of the local secondary control center that communicates with the control center according to the second index idx2. It uses the communication decryption key K2′ to decrypt the ciphertext m to obtain the string str1′, the index idx1′ and the hash value h′p1,K1(IDNY);
[0083] Steps 3-4: The (N-1)th unmanned terminal obtains the key K1′ from the nth group of the broadcast communication sub-key pool of the broadcast communication key pool according to the index idx1′ as the input random number, generates an irreducible polynomial p′1(x) based on the string str1′, and then generates a hash function h″p1,K1 based on the irreducible polynomial p′1(x) and the key K1′.
[0084] Steps 3-5: The (N-1)th unmanned terminal obtains the device serial number IDNY′ from the unmanned terminal whose identity is to be authenticated, and uses the hash function h″p1,K1 to calculate the hash value of the device serial number IDNY′ to obtain h″p1,K1(IDNY′);
[0085] Step 3-6: The (N-1)th unmanned terminal compares the hash value h″p1,K1(IDNY′) obtained in the calculation with the hash value h′p1,K1(IDNY) obtained in step 3-3. If they match, the authentication is successful, and the (N-1)th unmanned terminal accepts the unmanned terminal with the identity to be authenticated as one of the unmanned terminal groups N and proceeds to the next step; if they do not match, the (N-1)th unmanned terminal refuses to include the unmanned terminal with the identity to be authenticated in the unmanned terminal group N.
[0086] Steps 3-7: The control center executes steps 3-1 to 3-6 for groups 1 to M. Unmanned terminals 1-1 in group 1 to M-1 in group M send their authentication results back to the control center. The control center then adds the unmanned terminals awaiting authentication to the group swarm management system. The control center can perform these operations sequentially for groups 1 to M, or allocate multiple threads to perform authentication operations for multiple groups simultaneously, improving system efficiency.
[0087] Step 4: The terminal communication key pool of each unmanned terminal in each unmanned terminal group that constitutes the unmanned system swarm accepts a preset key so that all unmanned terminal communications within the same group have a symmetric key, and all unmanned terminal communications across groups have a symmetric key.
[0088] In this step, the meaning of "all unmanned terminals communicating within the same group have symmetric keys" is as follows: the key pool used for intra-group communication in the Na-th unmanned terminal within the group with beehive identifier N is the n-th group terminal communication sub-key pool. The Na-th unmanned terminal divides the n-th group terminal communication sub-key pool into x-1 grandchild terminal communication key pools according to the number x of unmanned terminals in its group; and establishes a one-to-one correspondence between its own x-1 grandchild terminal communication key pools and the corresponding grandchild terminal communication key pools in the other (x-1) unmanned terminals within the group.
[0089] Taking the first-to-first unmanned terminal as an example, this explains the meaning of symmetric keys in communication among all unmanned terminals within the same group: For example... Figure 5 As shown, the key pool used for intra-group communication in the first-1 unmanned terminal is the first group group terminal communication sub-key pool. The key presetting process for communication in the first-1 unmanned terminal is as follows:
[0090] First, the unmanned terminal 1-1 in the first group obtains the number x of unmanned terminals in the first group from the control center, and then divides its own first group terminal communication sub-key pool into x-1 grandchild terminal communication key pools.
[0091] The first unmanned terminal then establishes a one-to-one correspondence between its own x-1 grandchild terminal communication key pools and the corresponding grandchild terminal communication key pools of the other (x-1) unmanned terminals in the same group (excluding itself). For example... Figure 5 As shown, the dashed lines represent the correspondence between the grandchild terminal communication key pools. For example, the grandchild terminal communication key pool 122 in the first-1 unmanned terminal corresponds to the grandchild terminal key pool 221 in the second group terminal communication sub-key pool of the first-2 unmanned terminal, and both have the same preset key file k12; the grandchild terminal communication key pool 12x in the first-1 unmanned terminal corresponds to the grandchild terminal communication key pool x21 in the first-x unmanned terminal, and both have the same preset communication key file k1x; the grandchild terminal communication key pool 22x in the first-2 unmanned terminal corresponds to the grandchild terminal communication key pool x22 in the first-x unmanned terminal, and both have the same preset communication key file k2x. The preset key files in other unmanned terminals within the same group are referenced. Figure 5 As shown, the preset is performed to obtain key files k12 to k1x that correspond one-to-one with the other (n-1) unmanned terminals in the first group.
[0092] In addition to communicating with other unmanned terminals within the same group, a single unmanned terminal in a swarm can also communicate with any unmanned terminal in other groups. In this embodiment, the number of unmanned terminals forming a swarm is often large. However, in actual operation, it is possible that a single unmanned terminal may not communicate with all other unmanned terminals in the swarm, but only with a few. In this case, many pre-set keys will not be used, resulting in a waste of keys.
[0093] In this step, the meaning of all unmanned terminal communications across groups having symmetric keys can be that the key files pre-set in the h-th group terminal communication sub-key pool KNH of each unmanned terminal in the group with bee colony identifier N are the same as those pre-set in the n-th group terminal communication sub-key pool KHN of each unmanned terminal in the group with bee colony identifier H.
[0094] The following example illustrates the key file presetting process in the terminal communication key pool of unmanned terminals across groups, using the first unmanned terminal group's first unmanned terminal 1-1, the second unmanned terminal group's second unmanned terminal 2-1, and the X-1 unmanned terminal group's X unmanned terminal 2-1 as examples.
[0095] The correspondence between the communication subkey pools of other group terminals in each unmanned terminal is as follows: Figure 6 As shown, the second group terminal communication sub-key pool K12 in the first-1 unmanned terminal corresponds to the first group terminal communication sub-key pool K21 in the second-1 unmanned communication terminal. Similarly, the xth group terminal communication sub-key pool K1x in the first-1 unmanned terminal corresponds to the first group terminal communication sub-key pool Kx1 in the (X-1)th unmanned communication terminal.
[0096] For example, the key file k12 preset in the second group terminal communication sub-key pool K12 of the first unmanned terminal (group 1) is the same as the key file k21 preset in the first group terminal communication sub-key pool K21 of the second unmanned terminal (group 2). The preset key files in the second group terminal communication sub-key pools of each unmanned terminal (group 1) are all the same as key file k12. The preset key files in the first group terminal communication sub-key pools of each unmanned terminal (group 2) are all the same as key file k21.
[0097] Furthermore, in this step, the cross-group communication of all unmanned terminals has the meaning of symmetric key, or it means that: the h-th group terminal communication sub-key pool in each unmanned terminal in the group with beehive identifier N divides the h-th group terminal communication sub-key pool into t grandchild terminal communication key pools according to the number t of unmanned terminals in the group with beehive identifier H, and establishes a one-to-one correspondence between its own t grandchild terminal communication key pools and the corresponding grandchild terminal communication key pools in the t unmanned terminals in the group with beehive identifier H, and the key files preset in the corresponding grandchild terminal communication key pools are the same.
[0098] The following example uses the first unmanned terminal in the first unmanned terminal group and the second unmanned terminal in the second unmanned terminal group to illustrate the key file presetting process in the communication key pool of the grandchild terminal in the unmanned terminals across groups.
[0099] like Figure 7 As shown, the second group terminal communication sub-key pool K12 in each unmanned terminal within the first group is divided into 10 grandchild terminal communication key pools according to the number t of unmanned terminals in the second group, for example, 10, such as the 1st grandchild terminal communication key pool to the 10th grandchild terminal communication key pool:
[0100] The first group terminal communication sub-key pool K21 in each unmanned terminal in the second group is divided into 8 grandchild terminal communication key pools according to the number of unmanned terminals o in the first group, for example 8. The first grandchild terminal communication key pool is divided into 8 grandchild terminal communication key pools from the 1st grandchild terminal communication key pool to the 8th grandchild terminal communication key pool.
[0101] A one-to-one correspondence is established between the communication key pools of the grandchild terminals on both sides:
[0102] For example, the preset key file in the communication key pool of the third grandson terminal in the first unmanned terminal of the first group is the same as the preset key file in the communication key pool of the first grandson terminal in the second group of the second unmanned terminals.
[0103] Step 5: When any two unmanned terminals in the unmanned system swarm communicate point-to-point, they consume the keys in their respective terminal communication key pools; if an unmanned terminal detects that the remaining key amount in its terminal communication key pool is less than or equal to the set terminal key remaining threshold parameter, it performs a key replenishment operation accordingly.
[0104] In step 5, the point-to-point communication between any two unmanned terminals includes: the two unmanned terminals are the Na-th unmanned terminal in group N of the beehive and the Hb-th unmanned terminal in group H, wherein the key pool for this communication in the Na-th unmanned terminal as the sender is the terminal communication sub-key pool KNH of group h, and the key pool for this communication in the Hb-th unmanned terminal as the receiver is the terminal communication sub-key pool KHN of group n;
[0105] (1): The Na-th unmanned terminal compares the key start position information k-startnh of the h-th group terminal communication sub-key pool KNH recorded locally with the key start position information k-starthn of the n-th group terminal communication sub-key pool KHN recorded locally by the Hb-th unmanned terminal. If k-startnh≠k-starthn, the larger of k-startnh and k-starthn is taken as the new start position of the key file in the two group terminal communication sub-key pools; if k-startnh=k-starthn, the two group terminal communication sub-key pools are not updated.
[0106] (2): The Na-th unmanned terminal selects a communication key k-mnh of the same length as the data mes1 to be sent, starting from the key start position k-startnh in the communication sub-key pool KNH of the h-th group terminal, and records the key index idx-mnh of the communication key k-mnh. It then uses the communication key k-mnh to perform an encryption operation on the data mes1 to obtain the ciphertext MES1, and sends the ciphertext MES1 and the key index idx-mnh to the H-th unmanned terminal. At the same time, the Na-th unmanned terminal updates the key start position information k-startnh in the communication sub-key pool KNH of the h-th group terminal and broadcasts the start position information k-startnh to all unmanned terminals in the bee group identified as N for updating.
[0107] (3): The Hb unmanned terminal obtains the decryption key k-mhn from the local nth group terminal communication sub-key pool KHN according to the received key index idx-mnh, and uses the decryption key k-mhn to decrypt the received ciphertext MES1 to obtain the plaintext data mes1′. This plaintext data is the communication data sent by the Nath unmanned terminal to the Hb unmanned terminal. At the same time, the Hb unmanned terminal updates the key start position information k-starthn in the nth group terminal communication sub-key pool KHN and broadcasts the start position information k-starthn to all unmanned terminals with the beehive identifier H for updating.
[0108] The following example illustrates the communication process between unmanned terminals across different groups, using the communication process between unmanned terminal 1-1 in the first unmanned terminal group and unmanned terminal 2-1 in the second unmanned terminal group as an example.
[0109] When unmanned terminal 1-1 in the first unmanned terminal group communicates with unmanned terminal 2-1 in the second unmanned terminal group, the communication process includes:
[0110] (1): The first-1 unmanned terminal compares the key start position information k-start12 in the second group terminal communication sub-key pool K12 recorded locally with the key start position information k-start21 in the first group terminal communication sub-key pool K21 recorded locally by the second-1 unmanned terminal. If k-start12≠k-start21, the larger of k-start12 and k-start21 is taken as the new start position of the key in key pools K12 and K21; if k-start12=k-start21, key pools K12 and K21 are not updated.
[0111] Since the first-1 unmanned terminal may also communicate with other unmanned terminals identified as group 2, or other unmanned terminals identified as group 1 may also communicate with the second-1 unmanned terminal, although according to the following steps (2) and (3), after the unmanned terminal completes the inter-group communication, it will broadcast the new key start position information in the sub-key pool after this communication within the group, but in order to prevent the broadcast from failing or the communication sub-key pool of a certain terminal not updating the key start position information in time, a comparison operation of the key start position in the sub-key pool between the two communicating terminals is added here to determine the consistency of the key files of the two parties during communication.
[0112] (2): The first-1 unmanned terminal selects a communication key k-m12 with the same length as the data mes1 to be sent, starting from the key start position k-start12 in the second group terminal communication sub-key pool K12, and records the key index idx-m12 of the communication key k-m12. It uses the communication key k-m12 to perform encryption operation on the data mes1 to obtain the ciphertext MES1. The ciphertext MES1 and the key index idx-m12 are sent to the second-1 unmanned terminal. At the same time, the second group terminal communication sub-key pool K12 updates the key start position information k-start12 in the sub-key pool at this time, and broadcasts the start position information k-start to all unmanned terminals in the bee group identified as group 1 for updating.
[0113] (3): The 2-1 unmanned terminal obtains the decryption key k-m21 from the first group terminal communication subkey pool K21 according to the received key index idx-m12, and uses the decryption key k-m21 to decrypt the received ciphertext MES1 to obtain the plaintext data mes1′. This plaintext data is the communication data sent by the 1-1 unmanned terminal to the 2-1 unmanned terminal. At the same time, the first group terminal communication subkey pool K21 updates the key start position information k-start21 in the subkey pool at this time, and broadcasts the start position information k-start21 to all unmanned terminals in the bee group identified as group 2 for updating.
[0114] By broadcasting the key start position information in the key pool of the group terminal communication after each inter-group communication, it is ensured that the keys used in inter-group communication are deleted, so that the communication between unmanned terminals in the group strictly follows the one-time pad principle, thus ensuring the quantum security of unmanned terminals in inter-group communication.
[0115] When any unmanned terminal in the swarm detects that the remaining key amount in the terminal communication key pool is less than or equal to the set terminal key remaining threshold parameter, a key replenishment operation needs to be performed. The specific process is as follows:
[0116] A1: The key supplementing parties and the unmanned terminal to be supplemented can be in the same group or different groups. Specifically, the Xth unmanned terminal, which is one of the key supplementing parties, first finds the group terminal communication sub-key pool corresponding to the Yth unmanned terminal, which is the other party in the key supplementing parties, and then generates a key supplementation instruction and sends it to the local true random number generator. The key supplementation instruction contains a supplementary key size parameter, which is the storage size of the group terminal communication sub-key pool to be supplemented minus the remaining key size in the current group terminal communication sub-key pool. Here, X and Y include a beehive identifier and a group identifier, which are used to indicate the specific unmanned terminal. For example, if X is 1-1, the Xth unmanned terminal is the first unmanned terminal in the first group; if Y is 2-1, the Yth unmanned terminal is the first unmanned terminal in the second group.
[0117] A2: The true random number generator responds to the key replenishment instruction and generates a set of true random numbers with a size equal to the replenishment key size parameter as the replenishment key; the Xth unmanned terminal then sends the replenishment key to the communication subkey pool of the group terminal to be replenished, and sends the replenishment key to the Yth unmanned terminal;
[0118] A3: The Yth unmanned terminal finds the group terminal communication sub-key pool corresponding to the Xth unmanned terminal, and then fills the remaining key in the group terminal communication sub-key pool with the supplementary key to form a new communication key file.
[0119] In some cases, the number of unmanned terminal groups in an unmanned system swarm is large. Unmanned terminals within the first unmanned terminal group may not communicate with all other groups. In this situation, if each unmanned terminal's terminal communication sub-key pool corresponds to every group, it would result in a waste of keys in multiple pre-set sub-key pools for each group's terminal communication. Therefore, in this embodiment, the deployment of the terminal communication key pool in the key management unit within the unmanned terminal can be as follows: Figure 8 As shown, the terminal communication key pool only includes the intra-group terminal communication sub-key pool and the inter-group terminal communication sub-key pool. The key presetting and communication method of the intra-group terminal communication sub-key pool are the same as above, and will not be repeated here. All unmanned terminals in this hive have the same pre-set key file in their inter-group terminal communication sub-key pools. In this case, point-to-point communication between any two unmanned terminals includes:
[0120] B1: The unmanned terminal that is sending the message and the unmanned terminal that is receiving the message perform an alignment operation on the starting position of the inter-group communication key in the inter-group terminal communication sub-key pool, and take the larger key starting position of the two as the starting position of the inter-group communication key add1.
[0121] Taking the first unmanned terminal in the first unmanned terminal group and the second unmanned terminal in the second unmanned terminal group as an example: the first unmanned terminal and the second unmanned terminal perform an alignment operation on the starting position of the inter-group communication key in the inter-group terminal communication sub-key pool, and take the largest key starting position among the three as the starting position of the inter-group communication key in this communication process, and select the starting position of the inter-group communication key add1;
[0122] B2: The sending unmanned terminal uses the inter-group communication key starting position add1 as the initial key starting position, obtains the inter-group communication key of the corresponding length according to the length requirement of this communication data, and records the corresponding key index. After encrypting the communication data, it sends the ciphertext, key index and updated inter-group communication key starting position add2 to the receiving unmanned terminal. The receiving unmanned terminal obtains the decryption key from the local inter-group terminal communication sub-key pool according to the key index, decrypts the communication data, and updates the local inter-group communication key starting position.
[0123] B3: The unmanned terminal acting as the sender or the unmanned terminal acting as the receiver broadcasts the updated inter-group communication key starting position add2 within the swarm to notify other unmanned terminals to update.
[0124] When any unmanned terminal conducts broadcast communication with multiple other unmanned terminals in the unmanned system swarm, it consumes the key in its respective broadcast communication key pool; if the unmanned terminal detects that the remaining key in the broadcast communication key pool is less than or equal to the broadcast key threshold, the unmanned terminal requests a broadcast key update operation from the control center.
[0125] In this step, the specific process of conducting broadcast communication is as follows:
[0126] Specifically, as described in step 2, each unmanned terminal in the swarm has the same broadcast communication key pool. When any unmanned terminal in the swarm sends a broadcast message, the receiving unmanned terminal only needs to parse the swarm identifier of the sending unmanned terminal, then use the swarm identifier to address the corresponding group's broadcast communication sub-key pool, and obtain the corresponding broadcast communication key from the corresponding group's broadcast communication sub-key pool based on the key index carried in the broadcast message. The broadcast communication key is then used to encrypt and decrypt the broadcast message before communication.
[0127] In this step, such as Figure 9 As shown, the specific process of the broadcast key update operation is as follows:
[0128] C1: The control center sends an update key J-UP of length j to each group broadcast communication sub-key pool in the broadcast communication key pool of each unmanned terminal in the unmanned system group swarm;
[0129] C2: Each unmanned terminal divides the original broadcast communication key of length J in each sub-key pool of the local broadcast communication key pool into (i+1) subkeys with a granularity of length j; where i = [J / j], the first to the i subkeys are denoted as J1 to Ji, each with a length of j; the (i+1)th subkey is denoted as J(i+1), with a length of Ji*j;
[0130] C3: Perform an XOR operation between the updated key J-UP and each of the 1st to ith subkeys to obtain a new J1′=(J-UP)⊕J1, until a new Ji′=(J-UP)⊕Ji; For subkey J(i+1), extract the first to the Ji*jth bit length of the updated key J-UP and perform an XOR operation with the subkey J(i+1) to obtain a new J(i+1)′=(J-UP1)⊕J(i+1); After the XOR operation is completed, a new broadcast communication key of length J is obtained.
[0131] When any unmanned terminal communicates with the control center, it consumes the key in its respective control center's communication key pool. If the unmanned terminal detects that the remaining key in the control center's communication key pool is less than or equal to the control center's communication key threshold, the unmanned terminal requests a control center communication key update operation from the control center.
[0132] Specifically, for example, when the first unmanned terminal (UAV) communicates with the control center, it consumes keys from the secondary control center communication key pool in the first UAV and the primary control center communication key pool in the control center that has a symmetric key with the secondary control center communication key pool of the first UAV. When the key balance detection component of the first UAV detects that the key balance in the secondary control center communication key pool is less than or equal to the control center communication key threshold, the first UAV requests a control center communication key update operation from the control center through the data communication unit. The update method can be consistent with the update method of the broadcast communication key pool or the supplementation method of the terminal communication key, and will not be elaborated here.
Claims
1. A quantum-safe unmanned system swarm communication method, characterized in that, The participants in the method include a control center and multiple unmanned terminals, and the method includes the following steps: Step 1: The control center divides the unmanned terminals into corresponding groups according to their work tasks and assigns them a swarm identifier and a group identifier; among them, the swarm identifiers of unmanned terminals within the same group are the same. Step 2: The control center assigns a security identity to each unmanned terminal based on the bee colony identifier; wherein, each unmanned terminal in the small group bee colony is pre-configured with a secondary control center communication key pool that communicates with the control center, and the control center is pre-configured with a primary control center communication key pool that has a symmetric key with the secondary control center communication key pool of each unmanned terminal; and each unmanned terminal in the control center and the small group bee colony is configured with a broadcast communication key pool for each group. Step 3: The control center selects one unmanned terminal in each group as the first unmanned terminal in that group and adds a swarm identifier; the first unmanned terminal in the group acts as the identity authenticator to authenticate other unmanned terminals in the same group, and the unmanned terminals that have passed the authentication in the same group are built into an unmanned terminal group; after all groups have completed the above identity authentication operation, the unmanned terminal groups that have passed the authentication are built into an unmanned system group swarm. Step 4: The terminal communication key pool of each unmanned terminal in each unmanned terminal group that constitutes the unmanned system swarm accepts a preset key so that all unmanned terminal communications within the same group have a symmetric key, and all unmanned terminal communications across groups have a symmetric key. Step 5: When any two unmanned terminals in the unmanned system swarm communicate point-to-point, they consume the keys in their respective terminal communication key pools; if an unmanned terminal detects that the remaining key amount in its terminal communication key pool is less than or equal to the set terminal key remaining threshold parameter, it performs a key replenishment operation accordingly. When any unmanned terminal conducts broadcast communication with multiple other unmanned terminals in the unmanned system swarm, it consumes the key in its respective broadcast communication key pool; if the unmanned terminal detects that the remaining key in the broadcast communication key pool is less than or equal to the broadcast key threshold, the unmanned terminal requests a broadcast key update operation from the control center. When any unmanned terminal communicates with the control center, it consumes the key in its respective control center's communication key pool. If the unmanned terminal detects that the remaining key in the control center's communication key pool is less than or equal to the control center's communication key threshold, the unmanned terminal requests a control center communication key update operation from the control center.
2. The quantum-safe unmanned system swarm communication method according to claim 1, characterized in that, In step 2, the broadcast communication key pool configured for each group refers to: Each unmanned terminal in the control center and the swarm of groups divides its broadcast communication key pool into m sub-key pools according to the number of terminal groups m. The control center and each unmanned terminal have the same key file pre-set in the first to the mth sub-key pools of the broadcast communication key pool.
3. The quantum-safe unmanned system swarm communication method according to claim 1 or 2, characterized in that, The specific process of the control center assigning a security identity to each unmanned terminal based on the swarm identifier in step 2 includes: the control center generating a device serial number IDNX based on the swarm identifier N of the unmanned terminal, and generating a hash value based on the device serial number IDNX; the hash value serves as the security identity of the unmanned terminal.
4. The quantum-safe unmanned system swarm communication method according to claim 3, characterized in that, The process of generating the hash value is as follows: The control center generates an irreducible polynomial p1(x) locally, and records the string composed of the coefficients of each term except the highest term in the irreducible polynomial as str1; The control center then obtains the first key K1 from the nth group of the broadcast communication sub-key pool of the broadcast communication key pool as the input random number, and uses the irreducible polynomial p1(x) and the first key K1 to generate a hash function hp1,K1; The device serial number IDNX of the unmanned terminal is input into the hash function hp1,K1 to obtain the security identity identifier = hp1,K1(IDNX); The control center records the first index idx1 of the first key K1 in the nth group of the broadcast communication sub-key pool.
5. The quantum-safe unmanned system swarm communication method according to claim 1, characterized in that, In step 4, the symmetric key used for communication among all unmanned terminals within the same group includes: the key pool for intra-group communication in the Na-th unmanned terminal within the group with beehive identifier N is the n-th group terminal communication sub-key pool; the Na-th unmanned terminal divides the n-th group terminal communication sub-key pool into x-1 grandchild terminal communication key pools according to the number x of unmanned terminals in its group; and establishes a one-to-one correspondence between its own x-1 grandchild terminal communication key pools and the corresponding grandchild terminal communication key pools in the other (x-1) unmanned terminals within the group. In step 4, all unmanned terminal communications between groups have symmetric keys, including: the key files pre-set in the sub-key pool KNH of the h-th group terminal communication in each unmanned terminal in the group with bee colony identifier N are the same as those in the sub-key pool KHN of the n-th group terminal communication in each unmanned terminal in the group with bee colony identifier H.
6. The quantum-safe unmanned system swarm communication method according to claim 5, characterized in that, In step 4, all unmanned terminal communications between groups have a symmetric key or include: the h-th group terminal communication sub-key pool in each unmanned terminal in the group with beehive identifier N is divided into t grandchild terminal communication key pools according to the number t of unmanned terminals in the group with beehive identifier H. The t grandchild terminal communication key pools of the unmanned terminal in the group are established in a one-to-one correspondence with the corresponding grandchild terminal communication key pools in the t unmanned terminals in the group with beehive identifier H. The key files preset in the corresponding grandchild terminal communication key pools are the same.
7. The quantum-safe unmanned system swarm communication method according to claim 5, characterized in that, In step 5, the point-to-point communication between any two unmanned terminals includes: the two unmanned terminals are the Na-th unmanned terminal in group N of the beehive and the Hb-th unmanned terminal in group H, wherein the key pool for this communication in the Na-th unmanned terminal as the sender is the terminal communication sub-key pool KNH of group h, and the key pool for this communication in the Hb-th unmanned terminal as the receiver is the terminal communication sub-key pool KHN of group n; The Na-th unmanned terminal compares the key start position information k-startnh of the h-th group terminal communication sub-key pool KNH recorded locally with the key start position information k-starthn of the n-th group terminal communication sub-key pool KHN recorded locally by the Hb-th unmanned terminal. If k-startnh ≠ k-starthn, the larger of k-startnh and k-starthn is used as the new start position of the key file in the two group terminal communication sub-key pools; if k-startnh = k-starthn, the two group terminal communication sub-key pools are not updated. The Na-th unmanned terminal selects a communication key k-mnh of the same length as the data mes1 to be sent, starting from the key start position k-startnh in the communication sub-key pool KNH of the h-th group terminal. It records the key index idx-mnh of the communication key k-mnh, uses the communication key k-mnh to perform an encryption operation on the data mes1, and obtains the ciphertext MES1. The ciphertext MES1 and the key index idx-mnh are sent to the Hb-th unmanned terminal. At the same time, the Na-th unmanned terminal updates the key start position information k-startnh in the communication sub-key pool KNH of the h-th group terminal and broadcasts the start position information k-startnh to all unmanned terminals in the beehive identified as N for updating. The Hb unmanned terminal obtains the decryption key k-mhn from the local nth group terminal communication sub-key pool KHN based on the received key index idx-mnh. It uses the decryption key k-mhn to decrypt the received ciphertext MES1 to obtain the plaintext data mes1′. This plaintext data is the communication data sent by the Nath unmanned terminal to the Hb unmanned terminal. At the same time, the Hb unmanned terminal updates the key start position information k-starthn in the nth group terminal communication sub-key pool KHN and broadcasts the start position information k-starthn to all unmanned terminals in the beehive identified as H for updating.
8. The quantum-safe unmanned system swarm communication method according to claim 1, characterized in that, In step 5, the specific process of performing the intra-group or inter-group key replenishment operation is as follows: A1: The Xth unmanned terminal, acting as one of the key supplementing parties, first finds the group terminal communication sub-key pool to be supplemented corresponding to the Yth unmanned terminal, which is also acting as the key supplementing party. Then, it generates a key supplementation instruction and sends it to the local true random number generator. This key supplementation instruction contains a supplementary key size parameter, which is the storage size of the group terminal communication sub-key pool to be supplemented minus the remaining key size in the current group terminal communication sub-key pool. Here, X and Y include the bee colony identifier and the intra-group identifier. A2: The true random number generator responds to the key replenishment instruction and generates a set of true random numbers with a size equal to the replenishment key size parameter as the replenishment key; the Xth unmanned terminal then sends the replenishment key to the communication subkey pool of the group terminal to be replenished, and sends the replenishment key to the Yth unmanned terminal; A3: The Yth unmanned terminal finds the group terminal communication sub-key pool corresponding to the Xth unmanned terminal, and then fills the remaining key in the group terminal communication sub-key pool with the supplementary key to form a new communication key file.
9. The quantum-safe unmanned system swarm communication method according to claim 1, characterized in that, The terminal communication key pool includes an intra-group terminal communication sub-key pool and an inter-group terminal communication sub-key pool. The same key file is pre-set in the inter-group terminal communication sub-key pool of all unmanned terminals in the unmanned system group bee colony. In step 5, the two unmanned terminals are two unmanned terminals in different groups, and the point-to-point communication includes: B1: The unmanned terminal that is sending the message and the unmanned terminal that is receiving the message perform an alignment operation on the starting position of the inter-group communication key in the inter-group terminal communication sub-key pool, and take the larger key starting position of the two as the starting position of the inter-group communication key add1. B2: The sending unmanned terminal uses the inter-group communication key starting position add1 as the initial key starting position, obtains the inter-group communication key of the corresponding length according to the length requirement of this communication data, and records the corresponding key index. After encrypting the communication data, it sends the ciphertext, key index and updated inter-group communication key starting position add2 to the receiving unmanned terminal. The receiving unmanned terminal obtains the decryption key from the local inter-group terminal communication sub-key pool according to the key index, decrypts the communication data, and updates the local inter-group communication key starting position. B3: The unmanned terminal acting as the sender or the unmanned terminal acting as the receiver broadcasts the updated inter-group communication key starting position add2 within the swarm to notify other unmanned terminals to update.
10. The quantum-safe unmanned system swarm communication method according to claim 2, characterized in that, In step 5, the specific process of conducting broadcast communication is as follows: The receiving unmanned terminal parses the swarm identifier of the sending unmanned terminal, addresses the corresponding group broadcast communication subkey pool based on the swarm identifier, obtains the corresponding broadcast communication key from the corresponding group broadcast communication subkey pool based on the key index carried in the broadcast message, and uses the broadcast communication key to encrypt and decrypt the broadcast message before communication.
11. A system based on the quantum-safe unmanned system group terminal group communication method according to any one of claims 1 to 10, characterized in that: The system includes a control center and a swarm of unmanned systems connected to the control center. The swarm of unmanned systems consists of multiple terminal groups connected in pairs, and each terminal group consists of multiple unmanned terminals connected in pairs. The control center is used to assign a security identity to each unmanned terminal and to communicate with each unmanned terminal; it is also used to respond to requests from unmanned terminals to perform control center communication key update operations and broadcast key update operations. The unmanned terminals in the terminal group are used to communicate with the control center and other unmanned terminals in the terminal group; they are also used to perform key replenishment operations in response to requests from unmanned terminals.
12. The system according to claim 11, characterized in that: The unmanned terminals in the unmanned system swarm all include a quantum security module. The quantum security module includes a terminal association unit, a data communication unit, a status reporting unit, a key management unit, and a terminal key replenishment unit. The terminal association unit, key management unit, terminal key replenishment unit, and data communication unit are connected in sequence. The data communication unit is also connected to the key management unit and the terminal association unit. The terminal association unit includes a terminal identity authentication component and a terminal group identity component connected by communication. The terminal identity authentication component is used to perform identity authentication and to form terminal groups and swarms of unmanned terminals that have passed the identity authentication. The terminal group identity component is used to assign swarm identifiers to unmanned terminals, record the terminal group to which the unmanned terminal belongs, and feed back the group information to which the unmanned terminal belongs to the control center. The data communication unit is used to receive and send data, and to obtain the corresponding key from the key management unit to encrypt or decrypt the data according to the data requirements. The status reporting unit is used to send a heartbeat to the control center to confirm whether the unmanned terminal where the quantum security module is located is online. The key management unit includes a terminal communication key pool, a secondary control center communication key pool, a broadcast communication key pool, and a key balance detection component. The key balance detection component is connected to the broadcast communication key pool and the secondary control center communication key pool, respectively. The terminal communication key pool includes multiple sub-key pools for group terminal communication, used to provide the keys required for the encryption and decryption of communication data between the unmanned terminal and other unmanned terminals in the group swarm. The secondary control center communication key pool is used to provide the keys required for the encryption and decryption of information received from the control center via the data communication unit. The broadcast communication key pool includes multiple sub-key pools for group broadcast communication, used to provide the keys required for the encryption and decryption of broadcast messages in the group swarm. The key balance detection component is used to monitor the key balance in the broadcast communication key pool and the secondary control center communication key pool, and to generate a key update request to the control center. The terminal key replenishment unit includes a terminal key detection component, a true random number generator, and a key distribution component connected in sequence. Both the terminal key detection component and the key distribution component are connected to the terminal communication key pool. The terminal key detection component is used to monitor the key balance in the terminal communication key pool and to generate a key replenishment command to send to the true random number generator. The true random number generator is used to receive the key replenishment command, generate a true random number as a replenishment key, and send the replenishment key to the key distribution component. The key distribution component is used to send the replenishment key directly to the terminal communication key pool and to send the replenishment key to the unmanned terminal required for key replenishment through a data communication unit.