NTRU-based efficient unmanned aerial vehicle security identity authentication method and system
By adopting an efficient UAV security authentication method based on NTRU, and utilizing the batch aggregation verification mechanism of the cluster head UAV node and dynamic noise multinomial technology, the computational efficiency and key management bottlenecks of identity authentication in UAV clusters are solved, achieving efficient and secure identity authentication, which is suitable for resource-constrained UAV platforms.
Patent Information
- Application Number
- CN202511129621.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-13
- Publication Date
- 2025-12-09
AI Technical Summary
Existing drone swarm authentication technologies suffer from bottlenecks in computational efficiency and key management, failing to meet the rapid authentication needs of large-scale dynamic networking environments. Furthermore, traditional solutions have high computational overhead and large signature sizes, leading to increased communication load and making them difficult to deploy effectively on resource-constrained drone platforms.
An efficient UAV security authentication method based on NTRU is adopted. By generating basic parameters, master public key and master key, and combining the batch aggregation verification mechanism of cluster head UAV nodes, lightweight signature optimization and dynamic noise polynomial technology are achieved, reducing key management and computational overhead, enhancing anti-interference ability, and supporting fast identity authentication.
It significantly reduces key management and encryption/decryption computation overhead, improves authentication efficiency, enhances system stability and anti-interference capabilities, is suitable for resource-constrained UAV platforms, possesses quantum security advantages, and solves the problems of low computational efficiency and high communication load of traditional solutions.
Smart Images

Figure CN121098484A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of unmanned aerial vehicle (UAV) communication security technology, and more specifically, to an efficient UAV secure identity authentication method and system based on NTRU. Background Technology
[0002] With the rapid development of wireless communication, automatic control, and artificial intelligence technologies, unmanned aerial vehicle (UAV) swarm systems are playing an increasingly important role in military reconnaissance, disaster relief, agricultural monitoring, and logistics transportation. In the military field, UAV swarms can perform complex tasks such as coordinated reconnaissance, electronic jamming, and precision strikes; in the civilian field, they can be used for large-scale farmland monitoring, emergency material delivery, and infrastructure inspection. Through multi-unit collaborative operation, UAV swarms not only improve mission efficiency but also enable operations in dangerous or inaccessible environments, significantly reducing operational risks. This distributed collaborative operation mode places extremely high demands on communication security, as a security vulnerability in any node within the swarm can lead to the entire system being compromised, causing serious consequences. Existing research mainly focuses on communication protocol optimization and channel enhancement technologies, which, while improving transmission reliability, have not fundamentally solved the problem of secure communication in UAV swarms. Therefore, research on UAV swarm security protection technologies from an information security perspective has significant theoretical and practical value.
[0003] Because drone swarms rely entirely on wireless channels for data transmission and coordinated control, their communication processes face multiple security threats. First, the open channel environment makes them vulnerable to eavesdropping attacks, allowing attackers to intercept sensitive mission information or control commands. Second, wireless signals are easily forged and tampered with, leading to man-in-the-middle attacks, where attackers can hijack communication sessions or inject malicious commands. Furthermore, drone swarms are also susceptible to denial-of-service (DoS) attacks, where attackers can exhaust system resources by interfering with communication frequencies or forging numerous connection requests. More seriously, replay attacks can cause drones to execute outdated or repetitive commands, while spoofing attacks can lead to unauthorized control of drones. These security vulnerabilities can have serious consequences in practical applications, including mission information leakage, drone hijacking, swarm coordination failure, and even major security incidents.
[0004] Identity authentication technology, as a crucial security measure, effectively prevents unauthorized access and can effectively mitigate various network attacks. However, current identity authentication technologies are not entirely suitable for drone swarm scenarios. While traditional symmetric encryption schemes offer high computational efficiency, they suffer from fundamental flaws in large-scale dynamic networking scenarios. For a swarm containing N drones, each drone needs to maintain N(N-1) / 2 symmetric encryption key pairs, which not only consumes significant storage resources but also makes key management and updates extremely complex. Public Key Infrastructure (PKI) solutions address the key explosion problem by introducing digital certificate mechanisms, but their complex certificate management places a heavy burden on the limited computing resources of drones. More importantly, PKI requires reliable certificate authorities and complex revocation mechanisms, which are difficult to implement effectively in dynamic drone networks where nodes frequently join and leave.
[0005] In recent years, Identity-Based Encryption (IBE) and Certificate-Less Public Key Cryptography (CL-PKC) have been proposed, providing new approaches to drone security authentication. IBE schemes avoid complex certificate management issues and simplify key distribution by directly using the user's identity as the public key; while CL-PKC further solves the key escrow problem in IBE schemes, enabling users to have complete control over their private keys. However, these schemes face severe performance challenges in drone swarm scenarios. On the one hand, most existing schemes rely on complex bilinear parallel computations, the computational overhead of which far exceeds the capacity of the drone's embedded processor. On the other hand, existing signature schemes typically generate signatures in the thousands of bits, significantly increasing channel load in large-scale swarm communication. In particular, when hundreds of drones access the network simultaneously, traditional one-to-one authentication methods can lead to severe signaling storms, and existing schemes lack efficient aggregation authentication mechanisms, failing to meet the demand for rapid identity authentication in dynamic networking environments. These problems severely restrict the practical deployment effectiveness of security solutions on resource-constrained drone platforms. Summary of the Invention
[0006] The present invention aims to provide an efficient UAV security authentication method and system based on NTRU, so as to solve the problems existing in the authentication scheme in the above-mentioned UAV swarm mission scenario.
[0007] This invention provides an efficient unmanned aerial vehicle (UAV) secure identity authentication method based on NTRU, comprising: The key management center generates basic parameters, the public key, and the master key; Ground control base stations, drone nodes, and key management centers use basic parameters, master public key, and master key to complete member drone registration; The cluster leader UAV node requests the mission key from the ground control base station; The ground control base station sends the mission key to the cluster head UAV node; The member drone node completes the network access request; Cluster leader drone node authenticates member drone nodes; Member drone nodes receive the mission private key.
[0008] Furthermore, the key management center generates basic parameters, a public key, and a master key, including: (1) Generate the predefined basic parameters of the public-key encryption system, including the degree parameter of the polynomial ring. Modulus , must meet ,coefficient To control polynomial sparsity, it must satisfy the following conditions: Polynomial constraints: In the polynomial ring It is not possible to make an agreement with China. It is a set of integers; (2) Generate basic parameters for the signature system, including security parameters. , , Polynomial ring , modulus The coefficient is in Middle; Polynomial ring , modulus The coefficient is in middle, For model The set of integers; Defined as the modular multiplication of polynomials for ; prime number , , ,in It is a positive integer; , This is the asymptotic lower bound in complexity theory; and For ring polynomials on, and ; (3) Generate the signature system's public key and private key. , The set of real numbers, specifically including: (3.1) From integer lattice Discrete Gaussian distribution on Selecting polynomials and ,in The standard deviation of the Gaussian distribution; (3.2) If , or Then calculate Make ,in and ; (3.3) Using the Babais algorithm through ( ), ( ), ... Integer linear combination approximation pair ; (3.4) Let the output be , satisfy existence , where k is an integer; (3.5) Obtain the trapdoor base and polynomial ,in This represents the inverse loop matrix corresponding to the polynomial. It refers to the ring The set of all invertible elements in the set; finally, let For the system master public key, This is the system's master private key.
[0009] Furthermore, the ground control base station, UAV nodes, and key management center utilize basic parameters, the master public key, and the master key to complete member UAV registration, including: (1) Unmanned Aerial Vehicle Node and ground control base stations A registration request is sent to the key management center via a secure link. The registration information mainly includes the real identity. ; (2) The key management center generates partial signature keys: (2.1) Generate a fake identity ,in This is a storage key used to reveal the true identity of malicious users. For timestamps, Used to retrieve drone nodes from the database His true identity It is a symmetric encryption algorithm. It is a hash algorithm; (2.2) Running the Gaussian sampling algorithm Generate a partial private key And send it to the drone node. ,in The standard deviation is the Gaussian distribution. (3) Unmanned Aerial Vehicle Node or ground control base station Generate a signing private key: (3.1) Unmanned Aerial Vehicle Node verify This ensures that the vector norm is within the safety bound; and simultaneously verifies... If the verification passes, Set as a partial private key; otherwise, reject. (3.2) Unmanned Aerial Vehicle Node Random selection Generate private key ,calculate , Generate public key ,storage .
[0010] Furthermore, the cluster leader UAV node requests a mission key from the ground control base station, including: (1) The cluster leader UAV node initiates an authentication request to the ground control base station to obtain the symmetric keys of all member UAV nodes under its jurisdiction. Specifically, it inputs its private key. and timestamp ; (2) Unmanned Aerial Vehicle Node Random from discrete Gaussian distribution Selecting polynomials ; (3) Calculate the UAV airborne noise polynomial: , , , ,in For drone aerial noise; (4) Calculate the challenge value ,in and It is a homomorphic hash function that satisfies ( Defined as ), Simultaneously calculate the signature response. Its matrix form is:
[0011] in, , , For drone aerial noise; (5) Drone node With probability Output message groups ,in And send it to the ground control base station.
[0012] Furthermore, the ground control base station sends a mission key to the cluster-head UAV node, including: (1) Ground control base station receives message packets ,calculate To ensure the freshness of the data; among which The time for DA to receive the signature. The maximum delay caused by signature transmission in the channel; (2) Verify whether the following equation is true:
[0013] Simultaneously check norm constraints: , , , If both conditions are met, the signature is accepted; otherwise, it is rejected. (3) Generate a signature in the same way as above, which is used for the cluster head drone node to authenticate itself; (4) Generate task key tables for all member UAV nodes under the jurisdiction of the cluster leader UAV node, according to the task requirements. ; (5) Encrypt the corresponding symmetric keys corresponding to the target member drone nodes respectively. To generate task key distribution tokens
[0014] in Set the task duration; simultaneously set the task key table. Encrypt the mission key distribution token using the symmetric key of the cluster leader drone node. Send to the cluster leader drone node; (6) The cluster leader UAV node verifies the signature of the ground control base station in the same way and decrypts to obtain the task key table. We are waiting for member drone nodes to apply for network access.
[0015] Furthermore, the member drone node completes the network access request, including: (1) Input: Data Private key ,in For a portion of the private key, For the secret value and the timestamp ; (2) Randomly select a polynomial that conforms to a discrete Gaussian distribution. Combined with real-time noise calculate:
[0016] in, It is additive noise, and its randomness is used to enhance signature security; (3) Calculate the hash value Use homomorphic hash function Generate a hash value for the following content : ;in It is about data The hash processing maps it to ; The polynomial in the system public key; (4) Constructing a signature Define matrix For the private key related parts:
[0017] in , For hash functions, For the node's pseudo identity; (5) Output signature message And send; where the public key ,satisfy ;in It consists of two parts: .
[0018] Furthermore, the cluster leader drone node authenticates member drone nodes, including: 1. Signature aggregation: (1) Input: from sensor nodes ( A single signature ,in For signature components, It is a hash value; (2) For all individual signatures Perform linear summation to obtain the components of the aggregate signature. :
[0019] in Contains part of the private key and secret value A linear combination of; For noise polynomial vectors, Gaussian distributed random numbers and real-time noise constitute; (3) Generate aggregate signature message ;in This is the aggregate hash value; and This can be viewed as an aggregated pseudo-identity and public key; 2. Aggregated signature verification: (1) Input: Aggregate signature message ; (2) Preprocessing calculation For the data of each node Calculate the hash value to obtain ; : Aggregate data hash value; (3) Verify whether the following equation is true:
[0020] Expanding the aggregate signature components, from the correctness of individual signatures... ,get:
[0021] Verify that the first term on the left side of the equation is factored into:
[0022] because and There is no direct linear relationship; this relies on a hash function. Input structure: aggregated noise polynomial and With aggregated data hash Both serve as input, and The hash result must be matched; (4) The cluster leader drone node encrypts the mission keys of each member drone and sends them.
[0023] Furthermore, the member drone node receives the mission private key, including: (1) Input: Signature message Current time ; (2) Using public keys The verification value is recalculated using the hash function and checked against the value in the signed message. Consistency:
[0024] Will Substitute the first item on the left:
[0025] Verification conditions using partial private key and public key definition ,in Simplifying, we get:
[0026] Similarly, for The derivation yields:
[0027] Therefore, the first term on the left side of the equation simplifies to:
[0028] Verify whether it is calculated during signature generation. The input is consistent.
[0029] This invention also provides an efficient unmanned aerial vehicle (UAV) security authentication system based on NTRU, including a ground control base station, UAV nodes, and a key management center; the UAV nodes include a cluster leader UAV node and member UAV nodes; The ground control base station, UAV node, and key management center are used to execute the aforementioned efficient UAV security authentication system based on NTRU.
[0030] In summary, this invention is based on the NTRU lattice cryptosystem, leveraging its relatively higher computational efficiency and security. Specifically, by implementing an efficient batch aggregation verification mechanism, it solves the problem of excessively large signature sizes inherent in traditional NTRU. Simultaneously, this invention implements a lightweight NTRU signature optimization algorithm and introduces dynamic noise multinomial technology, achieving efficient identity authentication while ensuring security. These technological innovations together constitute a complete solution, providing a secure and efficient identity authentication scheme for drone swarms.
[0031] This invention represents a systematic innovation across three levels: cryptographic design, engineering implementation, and scenario adaptation. It offers significant advantages over traditional solutions and provides a scalable infrastructure for future quantum-secure communication. The specific advantages are as follows: 1. This invention uses a dedicated one-time task key within each task cycle (i.e., the period during which a private key is derived once), combined with a fast and efficient NTRU encryption scheme, significantly reducing the overhead of key management and encryption / decryption operations. Through pseudo-identity binding and dynamic task key table technology, the storage requirements for long-term keys are effectively reduced. This design solves the problems of low key update efficiency and complex key transmission and management in traditional schemes, and is particularly suitable for dynamic networking scenarios such as drone swarms. Compared to traditional symmetric encryption schemes, this invention avoids the problem of the number of keys growing rapidly with the number of drones, significantly reducing storage and communication overhead.
[0032] 2. This invention introduces noise polynomial technology and a fault-tolerant signature verification mechanism, integrating communication noise into the encryption process through mathematical methods. This technology not only enhances the system's anti-interference capability but also effectively resists side-channel attacks. Simultaneously, the designed aggregate signature mechanism reduces the impact of single-packet loss on overall communication, significantly improving the system's stability in complex electromagnetic environments. Compared to traditional solutions that require re-initiating the entire handshake process when data packets are lost, the fault-tolerant mechanism of this invention greatly reduces communication overhead and latency.
[0033] 3. This invention designs a cluster-leader UAV application for efficient authentication of member UAV identities using aggregated signatures, significantly improving authentication efficiency by batch verifying multiple signatures. This method solves the problems of low authentication efficiency, excessively long signatures, and high communication load in existing NTRU schemes. In UAV swarm scenarios, traditional single verification methods can lead to severe performance bottlenecks, while the aggregated verification mechanism of this invention can verify the identities of multiple UAVs simultaneously, greatly improving the convergence speed of the network topology.
[0034] 4. Compared to existing ECDH schemes, the NTRU encryption system employed in this invention offers significant advantages in quantum security. Traditional ECDH protocols face threats from quantum computers, while the NTRU scheme, based on lattice cryptography, is resistant to quantum computing attacks. Furthermore, NTRU boasts higher computational efficiency, making it more suitable for resource-constrained UAV platforms. This invention also addresses the lack of an authentication mechanism in the ECDH protocol, effectively preventing man-in-the-middle attacks through a robust signature verification process.
[0035] 5. This invention employs pseudo-identity generation technology to achieve identity anonymization, hiding the true identity through symmetric encryption and hash obfuscation. This design protects the privacy and security of drone nodes while meeting regulatory requirements. The innovative batch aggregation verification algorithm not only protects identity privacy but also balances system load, solving key performance bottlenecks in resource-constrained scenarios. Compared to traditional solutions that directly expose the true identity of devices, this invention effectively prevents the possibility of drones being tracked and targeted. Attached Figure Description
[0036] Figure 1 This is a schematic diagram of an efficient unmanned aerial vehicle (UAV) security authentication method and device based on NTRU, provided in an embodiment of the present invention.
[0037] Figure 2 This is a schematic diagram of the drone cluster architecture in an embodiment of the present invention. Detailed Implementation
[0038] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. The components of the embodiments of the present invention described and shown in the accompanying drawings can generally be arranged and designed in various different configurations.
[0039] Therefore, the following detailed description of the embodiments of the invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely to illustrate selected embodiments of the invention. All other embodiments obtained by those skilled in the art based on the embodiments of the invention without inventive effort are within the scope of protection of the invention.
[0040] Example like Figure 1 , Figure 2 As shown, the entities involved in this invention include: Member UAVs: They have the ability to collect data, communicate locally, and execute tasks. Each member UAV communicates directly only with other UAVs in the group and interacts with the cluster leader UAV through a lightweight protocol to submit data or respond to commands.
[0041] Cluster Head UAV: Serves as the cluster's decision and control node (DCN). Core functions include: batch verification of member data packets, aggregation and signing of multi-source information, and instruction distribution.
[0042] Gateway UAV node: As a communication relay node between and within clusters, it enables topology-aware routing of data packets and address filtering and verification of cross-domain messages.
[0043] Ground Control Station (GCS): It has global task orchestration and aggregate signature verification capabilities, and interacts with UAV swarms through a multi-hop relay network.
[0044] Key Management Center (KMC): Communicates with UAV nodes and ground control base stations through a secure link, is responsible for selecting and initializing common system parameters, and participates in the generation of initial keys for each UAV and ground control base station.
[0045] like Figure 1 As shown, this embodiment of the invention provides an efficient unmanned aerial vehicle (UAV) secure identity authentication method based on NTRU, including: The first step is for the key management center to generate basic parameters, the public key, and the master key: (1) Generate the predefined basic parameters for the public-key encryption system, including: Prime numbers, used as degree parameters for polynomial rings.
[0046] Prime numbers, as modulo numbers, must satisfy the following conditions: .
[0047] Positive integers, controlling the sparsity of polynomials, must satisfy... .
[0048] Polynomial constraints: In the polynomial ring The ring structure is irreducible, ensuring that the ring structure is a domain and avoiding zero factors. It is a set of integers.
[0049] (2) Generate basic parameters for the signature system, including: Integer, used as a security parameter, i.e., matrix dimension. ,in To ensure that the dimensions of the grid are large enough.
[0050] : Polynomial ring, modulus is The coefficient is in middle.
[0051] : Polynomial ring, modulus is The coefficient is in middle, For model The set of integers, Represents coefficients in a finite field A polynomial ring on. Simultaneously... Defined as the modular multiplication of polynomials for .
[0052] prime number , , ,in It is a positive integer. , This is the asymptotic lower bound in complexity theory.
[0053] and For ring polynomials on, and .
[0054] (3) Generate the signature system's public key and private key. , The set of real numbers, specifically including: (3.1) From integer lattice Discrete Gaussian distribution on Selecting polynomials and , where integer cells express n 1-dimensional integer lattice, i.e., all n A dimensional vector, where each component is an integer; denoted as the standard deviation of the Gaussian distribution.
[0055] (3.2) If , or Then calculate Make ,in and .
[0056] (3.3) Using the Babais algorithm through ( ), ( ), ... Integer linear combination approximation pair .
[0057] (3.4) Let the output be , satisfy existence ,in k It is an integer.
[0058] (3.5) Obtain the trapdoor base and polynomial .in It refers to the ring The set of all invertible elements in the set, where Let represent the inverse loop matrix corresponding to the polynomial. Finally, let For the system master public key, This is the system's master private key.
[0059] For polynomials Its corresponding n 3D inverse circular matrix Defined as:
[0060] Polynomial multiplication It can be equivalently converted into matrix multiplication. .
[0061] The second step involves ground control base stations, drone nodes, and the key management center using basic parameters, the public key, and the master key to complete member drone registration. (1) Unmanned Aerial Vehicle Node and ground control base stations A registration request is sent to the key management center via a secure link. The registration information mainly includes the real identity. .
[0062] (2) The key management center generates partial signature keys: (2.1) Generate a fake identity ,in This is a storage key used to reveal the true identity of malicious users. For timestamps, Used to retrieve drone nodes from the database His true identity It is a symmetric encryption algorithm. This is a hash algorithm.
[0063] (2.2) Running the Gaussian sampling algorithm Generate a partial private key And send it to the drone node. .in The master private key, For the node's pseudo identity, The standard deviation of the Gaussian distribution ( This ensures that the norm of the sampling vector is small enough.
[0064] (3) Unmanned Aerial Vehicle Node or ground control base station Generate a signing private key (3.1) Unmanned Aerial Vehicle Node verify This ensures that the vector norm is within the safety bound; and simultaneously verifies... If the verification passes, Set as a partial private key; otherwise, reject.
[0065] (3.2) Unmanned Aerial Vehicle Node Random selection Generate private key ,calculate , Generate public key ,storage .
[0066] The third step involves the cluster leader drone node requesting a mission key from the ground control base station: (1) The cluster leader UAV node initiates an authentication request to the ground control base station to obtain the symmetric keys of all member UAV nodes under its jurisdiction. Specifically, it inputs its private key. and timestamp .
[0067] (2) Unmanned Aerial Vehicle Node Random from discrete Gaussian distribution Selecting polynomials The Gaussian sampling function should conform to the standard requirements as follows: enter: n The basis of Vigne Λ, standard deviation ,center .
[0068] for : calculate
[0069]
[0070]
[0071] and .
[0072] return .
[0073] (3) Calculate the UAV airborne noise polynomial: , , , ,in This refers to the aerial noise from drones.
[0074] (4) Calculate the challenge value ,in and It is a homomorphic hash function that satisfies ( Defined as ), Simultaneously calculate the signature response. Its matrix form is:
[0075] in, , , This refers to the aerial noise from drones.
[0076] (5) Drone node With probability Output message groups ,in And send it to the ground control base station.
[0077] The fourth step involves the ground control base station sending the mission key to the cluster leader UAV node. (1) Ground control base station receives message packets ,calculate To ensure the freshness of the data. The time for DA to receive the signature. This represents the maximum delay caused by the transmission of the signature in the channel.
[0078] (2) Verify whether the following equation is true:
[0079] Simultaneously check norm constraints: , , , If both conditions are met, the signature is accepted; otherwise, it is rejected.
[0080] (3) Generate a signature in the same way as above, which is used for the cluster head drone node to authenticate itself.
[0081] (4) Generate task key tables for all member UAV nodes under the jurisdiction of the cluster leader UAV node, according to the task requirements.
[0082] (5) Encrypt the corresponding symmetric keys corresponding to the target member drone nodes respectively. To generate task key distribution tokens
[0083] in The task duration. The task key table will also be included. Encrypt the mission key distribution token using the symmetric key of the cluster leader drone node. Send to the cluster leader drone node.
[0084] (6) The cluster leader UAV node verifies the signature of the ground control base station in the same way and decrypts it to obtain the signature. We are waiting for member drone nodes to apply for network access.
[0085] Step 5: Member drone nodes complete the network access request: (1) Input: Data Private key ,in For a portion of the private key, For the secret value and the timestamp .
[0086] (2) Randomly select polynomials (Discrete Gaussian distribution), combined with real-time noise calculate:
[0087] in, It is additive noise, and its randomness is used to enhance signature security.
[0088] (3) Calculate the hash value Use homomorphic hash function Generate a hash value for the following content :
[0089] in It is about data The hash processing maps it to ; This is the polynomial in the system's public key.
[0090] (4) Constructing a signature Define matrix For the private key related parts:
[0091] in , For hash functions, This serves as a pseudo-identity for the node.
[0092] (5) Output signature message And send it. The public key is... ,satisfy .in It consists of two parts:
[0093] Step 6: Cluster leader drone node authenticates member drone nodes. 1. Signature aggregation (1) Input: from sensor nodes ( A single signature ,in For signature components, This is a hash value.
[0094] (2) For all individual signatures Perform linear summation to obtain the components of the aggregate signature. :
[0095] in Contains part of the private key and secret value A linear combination of; For noise polynomial vectors, Gaussian distributed random numbers and real-time noise constitute.
[0096] (3) Generate aggregate signature message .in This is the aggregate hash value; and It can be viewed as an aggregated pseudo-identity and public key.
[0097] 2. Aggregated signature verification (1) Input: Aggregate signature message .
[0098] (2) Preprocessing calculation For the data of each node Calculate the hash value to obtain ; : Aggregate data hash value.
[0099] (3) Verify whether the following equation is true:
[0100] Expanding the aggregate signature components, the correctness of each individual signature ( ), we can obtain:
[0101] Verify that the first term on the left side of the equation can be factored into:
[0102] because and There is no direct linear relationship; this relies on a hash function. Input structure: aggregated noise polynomial and With aggregated data hash Both serve as input, and The hash result must be matched.
[0103] (4) The cluster leader drone node encrypts the mission keys of each member drone and sends them.
[0104] Step 7: Member drone nodes receive the mission private key: (1) Input: Signature message Current time .
[0105] (2) Using public keys The verification value is recalculated using the hash function and checked against the value in the signed message. Consistency:
[0106] Will Substitute the first item on the left:
[0107] Verification conditions using partial private key and public key definition ,in Simplifying, we get:
[0108] Similarly, for The derivation yields:
[0109] Therefore, the first term on the left side of the equation simplifies to:
[0110] Verify whether it is calculated during signature generation. The input is consistent.
[0111] like Figure 1 As shown, this embodiment of the invention also provides a high-efficiency unmanned aerial vehicle (UAV) security authentication system based on NTRU, including a ground control base station, UAV nodes, and a key management center; the UAV nodes include a cluster leader UAV node and member UAV nodes; The ground control base station, UAV node, and key management center are used to execute the above-mentioned efficient UAV security identity authentication system based on NTRU. The specific working principle can be referred to the description in the aforementioned method embodiments, and will not be repeated here.
[0112] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Claims
1. A highly efficient UAV secure identity authentication method based on NTRU, characterized in that, include: The key management center generates basic parameters, the public key, and the master key; Ground control base stations, drone nodes, and key management centers use basic parameters, master public key, and master key to complete member drone registration; The cluster leader UAV node requests the mission key from the ground control base station; The ground control base station sends the mission key to the cluster head UAV node; The member drone node completes the network access request; Cluster leader drone node authenticates member drone nodes; Member drone nodes receive the mission private key.
2. The efficient UAV security authentication method based on NTRU according to claim 1, characterized in that, The key management center generates basic parameters, a master public key, and a master private key, including: (1) Generate the predefined basic parameters of the public-key encryption system, including the degree parameter of the polynomial ring. Modulus , must meet ,coefficient To control polynomial sparsity, it must satisfy the following conditions: Polynomial constraints: In the polynomial ring It is not possible to make an agreement with China. It is a set of integers; (2) Generate basic parameters for the signature system, including security parameters. , , Polynomial ring , modulus The coefficient is in Middle; Polynomial ring , modulus The coefficient is in middle, For model The set of integers; Defined as the modular multiplication of polynomials for ; prime number , , ,in It is a positive integer; , This is the asymptotic lower bound in complexity theory; and For ring polynomials on, and ; (3) Generate the signature system's public key and private key. , The set of real numbers, specifically including: (3.1) From integer lattice Discrete Gaussian distribution on Selecting polynomials and ,in Let $\mathbf{a}$ be the standard deviation of the Gaussian distribution. (3.2) If , or Then calculate Make ,in and ; (3.3) Using the Babais algorithm through ( ), ( ), ... Integer linear combination approximation pair ; (3.4) Let the output be , satisfy existence , where k is an integer; (3.5) Obtain the trapdoor base and polynomial ,in This represents the inverse loop matrix corresponding to the polynomial. It refers to the ring The set of all invertible elements in the set; finally, let For the system master public key, This is the system's master private key.
3. The efficient UAV security authentication method based on NTRU according to claim 2, characterized in that, The ground control base station, UAV nodes, and key management center use basic parameters, master public key, and master key to complete member UAV registration, including: (1) Unmanned Aerial Vehicle Node and ground control base stations A registration request is sent to the key management center via a secure link. The registration information mainly includes the real identity. ; (2) The key management center generates partial signature keys: (2.1) Generate a fake identity ,in This is a storage key used to reveal the true identity of malicious users. For timestamps, Used to retrieve drone nodes from the database His true identity It is a symmetric encryption algorithm. It is a hash algorithm; (2.2) Running the Gaussian sampling algorithm Generate a partial private key And send to the drone node ,in The standard deviation is the Gaussian distribution. (3) Unmanned Aerial Vehicle Node or ground control base station Generate a signing private key: (3.1) Unmanned Aerial Vehicle Node verify This ensures that the vector norm is within the safety bound; and simultaneously verifies... If the verification passes, Set as a partial private key; otherwise, reject. (3.2) Unmanned Aerial Vehicle Node Random selection Generate private key ,calculate , Generate public key ,storage .
4. The efficient UAV security authentication method based on NTRU according to claim 3, characterized in that, The cluster leader UAV node requests a mission key from the ground control base station, including: (1) The cluster leader UAV node initiates an authentication request to the ground control base station to obtain the symmetric keys of all member UAV nodes under its jurisdiction. Specifically, it inputs its private key. and timestamp ; (2) Unmanned Aerial Vehicle Node Random from discrete Gaussian distribution Selecting polynomials ; (3) Calculate the UAV airborne noise polynomial: , , , ,in For drone aerial noise; (4) Calculate the challenge value ,in and It is a homomorphic hash function that satisfies ( Defined as ), Simultaneously calculate the signature response. Its matrix form is: in, , , For drone aerial noise; (5) Drone node With probability Output message groups ,in And send it to the ground control base station.
5. The efficient UAV security authentication method based on NTRU according to claim 4, characterized in that, The ground control base station sends a mission key to the cluster leader UAV node, including: (1) Ground control base station receives message packets ,calculate To ensure the freshness of the data; among which The time when DA receives the signature. The maximum delay caused by signature transmission in the channel; (2) Verify whether the following equation is true: Simultaneously check norm constraints: , , , If both conditions are met, the signature is accepted; otherwise, it is rejected. (3) Generate a signature in the same way as above, which is used for the cluster head drone node to authenticate itself; (4) Generate task key tables for all member UAV nodes under the jurisdiction of the cluster leader UAV node, according to the task requirements. ; (5) Encrypt the corresponding symmetric keys corresponding to the target member drone nodes respectively. To generate task key distribution tokens in Set the task duration; simultaneously set the task key table. Encrypt the mission key distribution token using the symmetric key of the cluster leader drone node. Send to the cluster leader drone node; (6) The cluster leader UAV node verifies the signature of the ground control base station in the same way and decrypts to obtain the task key table. We are waiting for member drone nodes to apply for network access.
6. The efficient UAV security authentication method based on NTRU according to claim 5, characterized in that, The member drone node completes the network access request, including: (1) Input: Data Private key ,in For a portion of the private key, For the secret value and the timestamp ; (2) Randomly select a polynomial that conforms to a discrete Gaussian distribution. Combined with real-time noise calculate: in, It is additive noise, and its randomness is used to enhance signature security; (3) Calculate the hash value Use homomorphic hash function Generate a hash value for the following content : ;in It is about data The hash processing maps it to ; The polynomial in the system public key; (4) Constructing a signature Define matrix For the private key related parts: in , For hash functions, For the node's pseudo identity; (5) Output signature message And send; where the public key ,satisfy ;in It consists of two parts: .
7. The efficient UAV security authentication method based on NTRU according to claim 6, characterized in that, The cluster leader drone node authenticates member drone nodes, including signature aggregation and aggregated signature verification; The signature aggregation includes: (1) Input: from sensor nodes ( A single signature ,in For signature components, It is a hash value; (2) For all individual signatures Perform linear summation to obtain the components of the aggregate signature. : in Contains part of the private key and secret value A linear combination of; For noise polynomial vectors, Gaussian distributed random numbers and real-time noise constitute; (3) Generate aggregate signature message ;in It is the aggregate hash value; and This is considered as an aggregated pseudo-identity and public key; The aggregate signature verification includes: (1) Input: Aggregate signature message ; (2) Preprocessing calculation For the data of each node Calculate the hash value to obtain ; : Aggregate data hash value; (3) Verify whether the following equation is true: Expanding the aggregate signature components, from the correctness of individual signatures... ,get: Verify that the first term on the left side of the equation is factored into: because and There is no direct linear relationship; this relies on a hash function. Input structure: aggregated noise polynomial and With aggregated data hash Both serve as input, and The hash result must be matched; (4) The cluster leader drone node encrypts the mission keys of each member drone and sends them.
8. The efficient UAV security authentication method based on NTRU according to claim 7, characterized in that, The member drone node receives the task private key, including: (1) Input: Signature message Current time ; (2) Using public keys The verification value is recalculated using the hash function and checked against the signature in the message. Consistency: Will Substitute the first item on the left: Verification conditions using partial private key and public key definition ,in Simplifying, we get: Similarly, for The derivation yields: Therefore, the first term on the left side of the equation simplifies to: Verify whether it is calculated during signature generation. The input is consistent.
9. A high-efficiency unmanned aerial vehicle (UAV) security authentication system based on NTRU, characterized in that, It includes a ground control base station, drone nodes, and a key management center; the drone nodes include a cluster leader drone node and member drone nodes; The ground control base station, UAV node, and key management center are used to implement the efficient UAV security authentication system based on NTRU as described in any one of claims 1-8.