Zero-trust unmanned aerial vehicle network security routing method fusing SDN and block chain
By integrating SDN and blockchain into a zero-trust architecture, and combining beam search and near-end policy optimization algorithms, a lightweight security authentication model and quantitative credibility index are designed. This solves the high dynamic and high-threat problems of UAV networks in post-disaster emergency communication, and achieves low latency, low energy consumption and high security routing path calculation.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-26
- Publication Date
- 2026-04-10
AI Technical Summary
Drone networks face challenges in post-disaster emergency communications, including high dynamism, high threats, and zero prior trust. Existing technologies suffer from drawbacks such as easily tampered trust tables, single points of failure, and prolonged route reconstruction. Furthermore, there is a contradiction between the slow latency of blockchain consensus and insufficient onboard computing power.
By integrating the zero-trust architecture of software-defined networking (SDN) and blockchain, and using beam search (BS) and proximal policy optimization (PPO) algorithms, a lightweight security threshold authentication model is designed and node trustworthiness is quantified. This enables the construction of an adaptive UAV network security routing method that dynamically balances transmission latency, energy consumption, and security performance.
It achieves fast, low-energy, and highly secure routing path calculation in dynamic network environments, effectively responding to network attacks and ensuring the communication efficiency and security of UAV networks.
Smart Images

Figure CN121842689A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of drone routing technology, and in particular to a zero-trust drone network security routing method that integrates SDN and blockchain. Background Technology
[0002] Under the vision of a 6G converged air-space-ground-sea network, drones have rapidly become a core means of emergency communication after disasters. They can be quickly deployed as temporary airborne backbones in areas with damaged infrastructure to achieve critical services such as disaster video transmission and vital sign monitoring. However, rescue scenarios are characterized by high dynamism, high threats, and zero prior trust: high-speed node movement leads to frequent link breaks, battery capacity is limited and requires extremely low overhead, and more seriously, attackers can paralyze the network by forging identities, injecting false data, or seizing channels. To ensure the communication security of drone networks, it is necessary to strengthen research on drone network security communication technologies and applications to improve the efficiency and reliability of drone communication networks.
[0003] Existing research is mostly based on single-point trust assessment or centralized ground control, which has drawbacks such as the trust table being easily tampered with, single-point failure resulting in network-wide blindness, and prolonged routing reconstruction. Simply introducing blockchain to assist in ensuring communication security also faces the contradiction that although blockchain can guarantee the immutability of the ledger, there are slow on-chain consensus latency and insufficient onboard computing power.
[0004] Unmanned aerial vehicle (UAV) routing algorithms are a crucial research area for ensuring their security. In environments with high communication quality requirements and strong network heterogeneity, routing algorithms can help UAV network systems plan the most efficient and secure data transmission paths to improve the efficiency and security of UAV network communication. However, the dynamic and heterogeneous nature of UAV networks makes them vulnerable to network attacks, leading to routing disruptions. Therefore, designing a secure routing mechanism that dynamically balances transmission latency, energy consumption, and security performance, and is capable of adaptively reconstructing routes, is of great significance. Summary of the Invention
[0005] The purpose of this invention is to propose a zero-trust network routing method for unmanned aerial vehicles (UAVs) that integrates Software-defined Networking (SDN) and blockchain. The goal is to minimize the weighted sum of total routing latency and total energy consumption. A secure network environment is constructed through a zero-trust architecture that integrates SDN and blockchain. The routing problem is restated as a Markov decision process and solved using beam search (BS) and proximal policy optimization (PPO) algorithms, while also considering the trustworthiness of node security metrics. This method is adaptable to dynamic environments, has low computational cost, and can obtain a trusted routing path in a short time. It effectively balances low latency, low energy consumption, and high security, ensuring both efficiency and security in UAV routing problems where network transmission fails due to network attacks.
[0006] To achieve the above-mentioned technical objectives, the technical solution adopted by the present invention is as follows:
[0007] A zero-trust drone network security routing method integrating SDN and blockchain includes the following steps:
[0008] S1. Design the network architecture of a drone swarm in emergency communication. Describe the secure routing scenario in a dynamic, time-varying, and highly heterogeneous communication environment where drones are vulnerable to network attacks. This includes determining the number and location of drones, base stations, and the destination node emergency center in the network topology, the flight trajectory and relative position of drones, the routing data to be transmitted, the communication route and network topology link status of each drone node, and ensuring that both the source drone node and the destination node are secure nodes.
[0009] S2 designs a lightweight security threshold authentication model. Based on the fact that packet loss or abnormal data length is easily caused by network attacks, the excessive data packet length is marked as an anomaly and used as the security authentication result during the transmission process of each drone node. Data anomalies are regarded as being attacked. Each drone node must perform security authentication during transmission, and the authentication result will be recorded on the blockchain in real time.
[0010] S3. Design a new indicator, security score, to quantify the trustworthiness of nodes. This indicator considers both the trustworthiness of neighboring nodes and the node's historical transmission success rate, defining the security score of each transmission node. The higher the security score, the less susceptible the node is to network attacks, and the more trustworthy the node is.
[0011] S4, based on the security authentication model and security level, designs a zero-trust security architecture based on the integration of software-defined networking (SDN) and blockchain. The blockchain records node identity, security level, abnormal events, and identity authentication results; the SDN controller centrally monitors the blockchain and the status of the entire network links in real time, calculates the security level, and uniformly distributes routing decisions; the forwarding of any data packet requires security authentication, thus building a zero-trust security network environment of "never trusting, always verifying".
[0012] S5, based on a zero-trust network security communication environment built by integrating SDN and blockchain; designs a free space path loss model between drone nodes, and obtains the maximum permissible transmission rate of a single hop between each drone node and the next-hop drone node under the premise of desired link quality and signal-to-noise ratio.
[0013] S6. Based on the distance between UAV nodes and the transmission and forwarding of data packets, consider the communication energy consumption required by the UAV during transmission, including sending energy consumption and receiving energy consumption, and obtain the total energy consumption required for communication during the routing process.
[0014] S7, based on the real-time status of the routing path, considers the latency of multiple components, including the request latency of the UAV node sending requests, the processing latency of the SDN controller in processing requests and making routing decisions, the response latency of the SDN controller, the end-to-end latency of transmission between UAV nodes, and the destination latency of transmission from the UAV node to the destination node; in addition, it considers the rerouting latency based on the impact of network attacks, and transforms the UAV network routing problem into minimizing the weighted sum of energy consumption and latency based on total energy consumption and total latency, and constructs a minimization objective function;
[0015] S8 abstracts the network topology into an undirected graph and uses beam search (BS) to pre-select transmission nodes based on security. Then, the problem is reconstructed into a Markov decision process, and the near-end policy optimization (PPO) reinforcement learning algorithm is used to solve for minimizing the objective function, obtaining the optimal policy that balances latency and energy consumption. Based on this policy, the routing path is selected. The designed BS and PPO fusion routing algorithm BSPPO can adaptively adjust the routing path and quickly respond to attacks by reconstructing the route.
[0016] Step S1 further includes:
[0017] It has A low-altitude drone is deployed in a square area with sides of length [missing information]. , This represents a collection of drones, each flying along a predetermined trajectory at a fixed altitude and equipped with sensors for real-time environmental monitoring. In the event of a ground emergency, it forwards response data packets to the ground destination node, the emergency medical center, via multi-hop transmission. The location of the drone is represented as... The maximum communication radius is The SDN controller is deployed on a base station in a fixed location, and uses blockchain to centrally manage and control routing in real time.
[0018] Step S2 further includes:
[0019] A lightweight threshold verification method is employed and deployed on each drone to detect and verify the length of data packets. Whether it is within the normal range is used to determine whether the drone has been attacked and whether the data is secure.
[0020]
[0021] in, and Depend on and Calculated separately This represents the expected length of a normal data packet. Indicates standard deviation, Represents the threshold coefficient, indicator Used to indicate whether the data packet is in a normal state, i.e.
[0022] .
[0023] In step S3, the safety degree of the node is calculated using the following formula. :
[0024]
[0025] in This indicates the trustworthiness of the drones adjacent to this node. This indicates the historical reliability of the node. These are weighting coefficients used to balance the credibility of neighboring nodes with historical credibility; drone nodes The credibility of neighbors is used To calculate, Represents the set of all neighboring nodes, calculated as
[0026]
[0027] in Represents the number of neighboring drone nodes. Representing drones In the Adjacency confidence of jumps, initial Historical experience shows that once a drone completes security certification, the trustworthiness of its neighboring nodes will increase accordingly. The state update, i.e.
[0028]
[0029] It is a decrease factor used to avoid over-punishment.
[0030] drones In the Historical credibility of the jump Defined as the number of times security verification is passed The ratio of the total number of security verifications in history:
[0031]
[0032] in Indicates drone Number of verification failures and All along Changes and updates, i.e.
[0033] .
[0034] In step S4, the zero-trust framework integrating SDN and blockchain mainly consists of the following parts:
[0035] Event detection and on-chain recording: When the source drone detects an emergency during monitoring, it immediately encrypts and packages the location information, event category, and transmission request locally into an event announcement, which is then broadcast to the blockchain. Simultaneously, the source drone records sensor and camera data in a cache, checks its legality and integrity, and records the event on the blockchain.
[0036] SDN Monitoring and Routing Planning: The SDN controller continuously monitors the blockchain. When it detects information related to an emergency, the SDN controller immediately activates the routing planning algorithm to calculate the route. The calculation result is then transmitted to the source drone.
[0037] Routing execution: After receiving routing instructions from the SDN controller, the source drone transmits data packets through relay drones. Each drone performs security authentication on the data from the previous drone based on the zero-trust principle and updates its security status on the blockchain.
[0038] Anomaly detection and dynamic rerouting: When an anomaly record is detected on the blockchain, the SDN controller immediately performs dynamic route recalculation, discards the abnormal data packet, avoids the abnormal drone, and sends the new path policy to the previous safe drone. Then, the safe drone in front of the attacked drone will use its buffer storage to retransmit the data, thereby repairing the route and realizing dynamic adaptive reconstruction of the route.
[0039] In step S5, based on the zero-trust network security communication environment built by integrating SDN and blockchain, a free-space path loss model is designed between drone nodes to determine the maximum permissible transmission rate. The calculation is as follows:
[0040] use Indicates the drone in the communication channel and drones signal-to-noise ratio, This indicates the bandwidth of the communication channel.
[0041] In step S6, since flight energy consumption and monitoring energy consumption are relatively fixed, the main consideration is the communication energy consumption during the routing process, including the transmission energy consumption required for hop-by-hop forwarding. and receiving energy consumption ,Right now
[0042] and ,
[0043] in Represents the size of the data packet. It is the energy consumption per bit of an electronic circuit. Representing drones and The transmission power between them, therefore, the total energy consumption Calculated as
[0044]
[0045] This represents the set of candidate drones required for transmission along all routing paths.
[0046] In step S7, request latency must be considered. Processing delay Response latency End-to-end delay Destination delay and rerouting latency that varies depending on the attack situation :
[0047] This refers to the request latency and processing latency when a drone monitors environmental issues and uploads the information to the blockchain. Depend on and Adding the results, after detecting an abnormal record, the SDN controller needs to query the consensus information on the blockchain, which is recorded as the query time. Then the SDN controller calculates the SDN for each node. The processing delay The calculation is as follows:
[0048]
[0049] in, This represents the time required to calculate the safety level of each node. This represents the computational load of each node. This indicates the controller's computation clock frequency and the response latency of the SDN sending routing information to the source drone. Represented as:
[0050]
[0051] This represents the size of the routed data packet, while It refers to the bandwidth and end-to-end latency between the source drone and the SDN controller. Including transmission latency and self-security authentication latency, from drones To drones The time delay between them is calculated as follows:
[0052]
[0053] in Representing drones The security authentication delay, Representing drones and The distance between them Representing the speed of light, the total end-to-end delay is expressed as:
[0054]
[0055] binary variables Indicates the link connection status between drones. The representative data will come from drones Transmitted to drone 0 indicates the opposite, destination delay. Represented as:
[0056]
[0057] Therefore, when no attack occurs, the total latency of the entire routing process is... The calculation is as follows:
[0058]
[0059] When an attack occurs and the attacked drone node is detected during security authentication, SDN needs to make a rerouting decision to avoid the abnormal node and replan the path. The rerouting latency is calculated as follows: ,Right now
[0060]
[0061] in represent One detected attack, This represents the total number of attacks detected. Include , and Due to possible impact Second attack, total rerouting latency The calculation is as follows:
[0062]
[0063] The actual emergency communication routing latency for drones is expressed as follows:
[0064]
[0065] The objective function is to jointly minimize the weighted sum of communication latency and energy consumption, expressed as:
[0066]
[0067] in It is the set of variables in the problem, representing the sets of candidate drones. The set of variables for the connection link between the drone and the drone ; using coefficients This represents the weighted average of latency and energy consumption. This represents the minimum signal-to-noise ratio (SNR) value; communication conditions require an SNR of not less than [value missing]. ; This represents the minimum security threshold that each communication drone must meet; Represented as drone The remaining energy of the drone must not be less than the energy threshold after each communication. This limits the energy consumption of each communication. This is the maximum communication distance of the drone.
[0068] In step S8, the network topology is abstracted into an undirected graph. The Beam Search (BS) algorithm pre-screens transmission nodes based on their security scores, selecting nodes with high security scores that meet the objective function constraints. The path score obtained from the BS pre-screening is represented as follows:
[0069]
[0070] Represents the origin node to the destination node A complete path, filtered according to path score. The candidate paths are merged into a set of vertices and edges, which are represented as follows: and .
[0071] In step S8, the problem is further reconstructed as a Markov decision process for solution, and the Policy Gradient Clipping (PPO) reinforcement learning algorithm is used to find a routing policy that minimizes the objective function, where:
[0072] state Including the location of drones , legitimate neighbor nodes Each node and potential link costs ,in Action space is represented as The reward function is set to the normalized time delay. and energy consumption The negative of the weighted sum is used to reconstruct the objective as maximizing the reward function. To represent the weights, adjusting the proportions of energy consumption and latency, i.e.
[0073] ,
[0074] In this reward, This represents the total number of training time steps, currently at the [number]th step. reward value of steps Is it considering starting from the current time step? Beginning, Future Cumulative rewards for each step This represents the future. The connection status of the drone link during the step.
[0075] In step S8, the BSPPO-based routing decision can quickly adjust and adaptively reconstruct routes after encountering an attack node, ensuring communication security. Specifically, it is described as follows:
[0076] During hop-by-hop routing, when an attacked node is detected, the agent performs fallback and dynamic rerouting operations to ensure transmission security. The SDN controller recalculates based on continuous zero-trust security authentication results. By excluding the attacked node and reconstructing the local topology, the agent then reselects the previously safe node, which is the second to last node in the path history, performs rerouting based on the BS candidate set, and continues to perform PPO-based routing decisions until the destination is reached.
[0077] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0078] First, the zero-trust secure routing framework proposed in this invention integrates SDN and blockchain, designs a lightweight threshold security verification model and a security index that quantifies the degree of trust, and achieves real-time detection and security isolation of network attacks through blockchain security records and centralized control of SDN, effectively improving the security of the network environment and routing process.
[0079] Second, this invention models the UAV network routing problem as a Markov decision process constrained by security, energy, and communication, and designs a beam search-near-end policy optimization (BSPPO) algorithm to complete hop-by-hop routing decisions under dynamic attack conditions and achieve adaptive route reconstruction in the face of security threats.
[0080] Third, the zero-trust UAV network security routing method integrating SDN and blockchain of the present invention was simulated in a UAV network with dynamic network attacks. The results show that the designed routing decision algorithm based on BSPPO is superior to other algorithms in terms of convergence, latency, energy consumption and transmission success rate, and effectively solves the routing problem in network environments with security threats such as attacks. Attached Figure Description
[0081] Figure 1 This is a schematic diagram of secure routing in a zero-trust drone network for emergency scenarios covered by this invention.
[0082] Figure 2 This is a schematic diagram of the latency calculation in routing involved in this invention; wherein, (a) shows the latency calculation process when no network attack is detected; and (b) shows the latency calculation process considering the rerouting part after an attack is detected.
[0083] Figure 3 The following are experimental simulation diagrams of the convergence curves of the four algorithms involved in this invention; (a) shows the convergence process of the routing algorithm in a secure environment without network attacks; (b) shows the convergence process of the routing algorithm under dynamic network attacks.
[0084] Figure 4 The following is an experimental simulation diagram showing the relationship between routing delay and data packet size for the four algorithms involved in this invention;
[0085] Figure 5 The figures show the experimental simulation results of the relationship between routing energy consumption and data packet size for the four algorithms involved in this invention.
[0086] Figure 6 The figure shows the experimental simulation diagram of the relationship between the transmission success rate and the number of detected attack nodes for the four algorithms involved in this invention.
[0087] Figure 7The simulation diagram shows the relationship between routing latency and the number of detected attack nodes for different algorithms involved in this invention.
[0088] Figure 8 This is an experimental simulation diagram showing the relationship between routing energy consumption and the number of detected attack nodes for different algorithms involved in this invention. Detailed Implementation
[0089] The embodiments of the present invention will be described in further detail below with reference to the accompanying drawings.
[0090] Figure 1 This invention illustrates a zero-trust secure routing diagram in a drone network with emergency communication capabilities, based on a specific embodiment. The invention discloses a zero-trust secure routing method for drone networks integrating SDN and blockchain, comprising the following steps:
[0091] Step 1) Design the network architecture of the drone swarm in emergency communication. The network architecture describes the secure routing scenario in a dynamic, time-varying, and highly heterogeneous communication environment where drones are vulnerable to network attacks. This includes determining the number and location of drones, base stations, and the destination node emergency center in the network topology, the flight trajectory and relative position of the drones, the routing data to be transmitted, the communication route and network topology link status of each drone node, and ensuring that both the source drone node and the destination node are secure nodes.
[0092] In this embodiment, both the source UAV node and the destination node are secure nodes.
[0093] Step 2) Design a lightweight security threshold authentication model. Based on the fact that packet loss or abnormal data length is easily caused by network attacks, the excessive data packet length is marked as an anomaly and used as the security authentication result during the transmission process of each drone node. Data anomalies are regarded as being attacked. Each drone node must perform security authentication during transmission, and the authentication result will be recorded in the blockchain in real time.
[0094] Step 3) Design a new security index to quantify the trustworthiness of nodes. This index considers both the trustworthiness of neighboring nodes and the historical transmission success rate of the nodes, and defines the security level of each transmission node.
[0095] Step 4) Based on the security authentication model and security level, design a zero-trust security architecture that integrates SDN and blockchain. The blockchain records node identity, security level, abnormal events and identity authentication results; the SDN controller centrally monitors the blockchain and the status of the entire network links in real time, calculates the security level and uniformly issues routing decisions; the forwarding of any data packet must pass security authentication, thus building a zero-trust security network environment of "never trusting, always verifying".
[0096] Step 5) Based on the free space path loss model between UAV nodes, obtain the maximum permissible transmission rate per hop between each UAV node and the next hop UAV node; the link quality and signal-to-noise ratio need to meet the communication constraints.
[0097] Step 6) Based on the distance between UAV nodes and the transmission and forwarding of data packets, consider the communication energy consumption required by the UAV during transmission, including sending energy consumption and receiving energy consumption, and obtain the total energy consumption required for communication during the routing process.
[0098] Step 7) Based on the real-time status of the routing path, consider the latency of multiple components, including the request latency of the UAV node sending the request, the processing latency of the SDN controller in processing the request and making routing decisions, the response latency of the SDN controller, the end-to-end latency of transmission between UAV nodes, and the destination latency of transmission from the UAV node to the destination node; in addition, consider the rerouting latency based on the impact of network attacks. Based on the total energy consumption and total latency, the UAV network routing problem is transformed into minimizing the weighted sum of energy consumption and latency, and a minimization objective function is constructed.
[0099] Step 8) Abstract the network topology into an undirected graph and use Beam Search (BS) to pre-screen transmission nodes based on security. Then, reconstruct the problem into a Markov decision process and use the Proximal Policy Optimization (PPO) reinforcement learning algorithm to solve for minimizing the objective function to obtain the optimal policy that balances latency and energy consumption. Based on this policy, select the routing path. Based on the routing algorithm (BSPPO) that integrates BS and PPO, realize adaptive route security reconstruction.
[0100] Figure 1 A schematic diagram of zero-trust secure routing in a drone network with emergency communication is shown in a specific embodiment.
[0101] In the above process:
[0102] In step 1), there is a set A low-altitude drone is deployed in a square area with sides of length [missing information]. , This represents a collection of drones. Each drone flies along a predetermined trajectory at a fixed altitude and is equipped with sensors for real-time environmental monitoring. In the event of emergencies such as sudden fires on the ground, it forwards response data packets to the ground-based emergency response center via multi-hop transmission. The location of a drone is represented as... The maximum communication radius is The SDN controller is deployed on a fixed-location base station, using blockchain-based real-time records for centralized management and control of routing.
[0103] In step 2), a lightweight threshold verification method is deployed on each drone to detect and verify the length of data packets. Whether it is within the normal range is used to determine whether the drone has been attacked and whether the data is secure.
[0104]
[0105] in, and It can be by and It is calculated. This represents the expected length of a normal data packet. Indicates standard deviation, This represents the threshold coefficient. (Indicator) Used to indicate whether the data packet is in a normal state, i.e.
[0106]
[0107] In step 3), the security degree of the node The calculation is as follows:
[0108] in This indicates the trustworthiness of the drones adjacent to this node. This indicates the historical reliability of the node. These are weighting coefficients used to balance the credibility of neighboring nodes with historical credibility; drone nodes The credibility of neighbors is used To calculate, The set of all neighboring nodes is calculated as follows:
[0109]
[0110] in Represents the number of neighboring drone nodes. Representing drones In the Adjacency confidence of jumps, initial Historical experience shows that once a drone completes security certification, the trustworthiness of its neighboring nodes will increase accordingly. The state update, i.e.
[0111]
[0112] It is a decrease factor used to avoid over-penalization. (Drone) In the Historical credibility of the jump Defined as the number of times security verification is passed The ratio of the total number of security verifications in history:
[0113]
[0114] in Indicates drone Number of verification failures and All along Changes and updates, i.e.
[0115]
[0116] Based on the above formula It can be updated to:
[0117]
[0118] In step 4), based on the security authentication model, a zero-trust security architecture integrating SDN and blockchain is designed, including...
[0119] Event detection and on-chain recording: When the source drone detects an emergency during monitoring, it immediately encrypts and packages its geographical location information, event category, and transmission request locally into an event announcement, which is then broadcast to the blockchain. Simultaneously, the source drone records sensor and camera data in a cache. Miners check the legitimacy and integrity of this data and record the event on the blockchain.
[0120] SDN Monitoring and Routing Planning: The SDN controller continuously monitors the blockchain. When it detects information related to an emergency, the SDN controller immediately activates the routing planning algorithm to calculate a route. The calculation result is then transmitted to the source drone.
[0121] Routing execution: After receiving routing instructions from the SDN controller, the source drone transmits data packets through relay drones. Each drone performs security authentication on data from the previous drone based on the zero-trust principle and updates its security status on the blockchain.
[0122] Anomaly detection and dynamic rerouting: When an anomaly record is detected on the blockchain, the SDN controller immediately performs dynamic route recalculation, discards the abnormal data packet, avoids the abnormal drone, and sends the new path policy to the preceding safe drone. Then, the safe drone ahead of the attacked drone uses its buffer storage to retransmit the data, thereby repairing the route and achieving dynamic adaptive route reconstruction.
[0123] In step 5), based on the zero-trust network security communication environment built by integrating SDN and blockchain, a free-space path loss model between drone nodes is designed, with the maximum permissible transmission rate. The calculation is as follows:
[0124] use Indicates the drone in the communication channel and drones signal-to-noise ratio, This indicates the bandwidth of the communication channel.
[0125] In step 6), the communication energy consumption during the routing process is considered, including the transmission energy consumption required for hop-by-hop forwarding. and receiving energy consumption ,Right now and ,
[0126] in Represents the size of the data packet. It is the energy consumption per bit of an electronic circuit. Representing drones and The power transmitted between them. Therefore, the total energy consumption. It can be calculated as follows:
[0127]
[0128] This represents the set of candidate drones required for transmission along all routing paths.
[0129] In step 7), request latency is taken into account. Processing delay Response latency End-to-end delay Destination delay and rerouting latency that varies depending on the attack situation The specific process is through Figure 2 exhibit. This indicates the request latency when a drone monitors environmental issues and uploads the information to the blockchain. Processing latency. Depend on and Adding the results, after detecting an abnormal record, the SDN controller needs to query the consensus information on the blockchain, which is recorded as the query time. Then the SDN controller calculates the SDN for each node. The processing delay The calculation is as follows:
[0130] in, This represents the time required to calculate the safety level of each node. This represents the computational load of each node. This indicates the controller's computational clock frequency. The SDN's response latency in sending routing information to the source UAV is also mentioned. Represented as:
[0131]
[0132] This represents the size of the routed data packet, while This refers to the bandwidth between the source drone and the SDN controller. Routing packets is done using... To mark:
[0133]
[0134] in, It's a timestamp. For the drone's identity authentication information, It is a data transmission connection. The data collected and transmitted by the drone. End-to-end latency. Including transmission latency and self-security authentication latency, from drones To drones The time delay between them is calculated as follows:
[0135]
[0136] in Representing drones The security authentication delay, Representing drones and The distance between them Represents the speed of light. The total end-to-end delay is expressed as:
[0137]
[0138] binary variables Indicates the link connection status between drones. The representative data will come from drones Transmitted to drone 0 indicates the opposite. Destination delay Represented as:
[0139]
[0140] Therefore, when no attack occurs, the total latency of the entire routing process is... It can be calculated as follows:
[0141]
[0142] When an attack occurs and the attacked drone node is detected during security authentication, SDN needs to make a rerouting decision to avoid the abnormal node and replan the path. The rerouting latency can be calculated as follows: ,Right now
[0143]
[0144] in represent One detected attack, This represents the total number of attacks detected. Include , and Due to possible impact Second attack, total rerouting latency The calculation is as follows:
[0145]
[0146] The actual emergency communication routing delay for drones can be expressed as:
[0147]
[0148] The objective function is to jointly minimize the weighted sum of communication latency and energy consumption, expressed as:
[0149]
[0150] in It is the set of variables in the problem, representing the sets of candidate drones. The set of variables for the connection link between the drone and the drone ; using coefficients This represents the weighted average of latency and energy consumption. This represents the minimum signal-to-noise ratio (SNR) value; communication conditions require an SNR of not less than [value missing]. ; This represents the minimum security threshold that each communication drone must meet; Represented as drone The remaining energy of the drone must not be less than the energy threshold after each communication. This limits the energy consumption of each communication. This is the maximum communication distance of the drone.
[0151] In step 8), the network topology is abstracted as an undirected graph. Furthermore, Beam Search (BS) is used to pre-filter transmission nodes based on their security scores, selecting nodes with high security scores that also meet the objective function constraints. The path score obtained from the BS algorithm's pre-filtering is represented as follows:
[0152]
[0153] Represents the origin node to the destination node A complete path. The filtered results are ranked according to path score. The candidate paths are merged into a set of vertices and edges, which are represented as follows: and .
[0154] The problem is further reconstructed as a Markov decision process for solution, and the Policy Gradient Pruning (PPO) reinforcement learning algorithm is used to find a routing policy that minimizes the objective function, where: the state Including the location of drones , legitimate neighbor nodes Each node and potential link costs ,in Action space is represented as The reward function is set to the normalized time delay. and energy consumption The negative of the weighted sum is used to reconstruct the objective as maximizing the reward function. To represent the weights, the proportions of energy consumption and latency are adjusted, that is:
[0155]
[0156] In this reward, This represents the total number of training time steps, currently at the [number]th step. reward value of steps Is it considering starting from the current time step? Beginning, Future Cumulative rewards for each step This represents the future. The connection status of the drone link during the step.
[0157] BSPPO-based routing decisions can quickly adjust and adaptively reconstruct routes in the face of attacked nodes, ensuring communication security. Specifically, during hop-by-hop routing, when an attacked node is detected, the agent performs fallback and dynamic rerouting operations to ensure transmission security. The SDN controller recalculates based on continuous zero-trust security authentication results. By excluding the attacked node, the local topology is reconstructed. Then, the agent reselects the previously safe node (the second to last node in the path history), performs rerouting based on the BS candidate set, and continues to perform PPO-based routing decisions until the destination is reached.
[0158] exist Figure 3-8 In this invention, the Beam Search-Near-End Policy Optimization (BSPPO) algorithm is used to solve the secure routing problem in UAV networks under network attack environments. It is compared and analyzed with three other algorithms—PPO, BSQL, and BSA2C—under both network attack and non-network attack conditions, as detailed below:
[0159] Figure 3 The convergence results of four algorithms are shown. Figure 3 (a) in the diagram represents the convergence in a secure environment where no attacks are present. Figure 3 (b) shows the convergence under an insecure environment with attacks. It can be seen that convergence is stable and fast in a secure environment, with a larger reward. While the algorithm also achieves good convergence in an insecure environment with network attacks, the curve fluctuates more and converges slower compared to the secure environment. This is because network attacks increase the randomness and complexity of the environment, requiring more iterations for learning. However, all designed BSPPO algorithms achieve optimal convergence.
[0160] Figure 4 The total latency of routing transmission in secure and insecure environments was evaluated separately. It can be seen that as the packet size increases, the transmission time also increases. The latency in the secure state is much lower than that in the insecure state. This is because when an attack node is detected, route reconstruction and recovery are required, which increases the transmission time.
[0161] Figure 5 The communication energy consumption of routing transmissions was evaluated in both secure and insecure environments. The results are consistent with the effects on latency.
[0162] Figure 6 The comparison of transmission success rates for each algorithm is shown when the number of attacking nodes changes. It can be seen that as the number of attacking nodes increases, the transmission success rate of each algorithm gradually decreases, but BSPPO consistently maintains the highest data transmission success rate, and its success rate is at least 10% higher than other algorithms.
[0163] Figure 7 and Figure 8The latency and energy consumption performance of each algorithm are shown under the same number of detected attack nodes. It can be seen that as the number of attack nodes in the path increases, both latency and energy consumption increase. This is because each detected attack node requires route reconstruction and restoration. As the number of detected attack nodes increases, the number of rerouting operations also increases, leading to increased communication latency and energy consumption during the routing process. The algorithm designed in this invention maintains low latency and energy consumption under all variations, demonstrating stability and efficiency in handling dynamic and uncertain environments.
[0164] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code. The solutions in the embodiments of this application can be implemented in various computer languages, such as the object-oriented programming language Java and the interpreted scripting language JavaScript.
[0165] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, produce instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0166] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0167] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment, causing a series of operational steps to be executed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that run on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0168] Although preferred embodiments of this application have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of this application.
[0169] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. A method for secure routing in zero-trust UAV networks by fusing SDN and blockchain, characterized in that, The method comprises the following steps: S1, designing a network architecture of a UAV group in emergency communication, describing a secure routing scenario of the UAV in a dynamic time-varying and heterogeneous communication environment through the network architecture, including determining the number and position of the UAV, the base station and the destination node emergency center in the network topology, the flight trajectory and relative position of the UAV, the routing data to be transmitted, the communication routing of each UAV node and the network topology link state, and the source UAV node and the destination node being secure nodes; S2, designing a lightweight security threshold authentication model, based on the fact that the packet loss or data length anomaly caused by network attack, marking the data packet length exceeding the limit as an abnormality, as the security authentication result of each UAV node in the transmission process, and regarding the data anomaly as being attacked; each UAV node needs to perform security authentication during transmission, and the authentication result will be recorded in the blockchain in real time; S3, designing a new index of security degree for quantifying the credibility of the node, which considers the credibility of the adjacent node and the historical transmission success rate of the node, and defines the security degree of each transmission node; The higher the security degree, the less likely the node is attacked, and the more credible the node is; S4, based on the security authentication model and the security degree, designing a zero-trust security architecture based on the fusion of software-defined network (SDN) and blockchain, recording the node identity, security degree, abnormal event and identity authentication result in the blockchain; The SDN controller centrally monitors the blockchain and the link state of the whole network, calculates the security degree and uniformly issues the routing decision; the forwarding of any data packet needs to pass through security authentication, and a zero-trust security network environment of "never trust, always verify" is constructed; S5, according to the zero-trust network security communication environment constructed by fusing SDN and blockchain; designing a free space path loss model between UAV nodes, obtaining the maximum allowable transmission rate of each UAV node and the next hop UAV node under the premise of expected link quality and signal-to-noise ratio; S6, according to the distance between the UAV nodes and the transmission and forwarding of the data packet, considering the communication energy consumption required by the UAV during transmission, including the sending energy consumption and the receiving energy consumption, obtaining the total energy consumption required for communication in the routing process; S7, according to the real-time state of the routing path, considering the time delay of multiple parts, including the request time delay of the UAV node, the processing time delay of the SDN controller for processing the request and making the routing decision, the response time delay of the SDN controller, the end-to-end time delay of the transmission between the UAV nodes, and the destination time delay of the transmission of the UAV node to the destination node; in addition, considering the re-routing time delay according to the influence of the network attack, based on the total energy consumption and the total time delay, the UAV network routing problem is converted into a weighted sum of minimizing the energy consumption and the time delay, and a minimum objective function is constructed; S8, abstracting the network topology into an undirected graph, and using beam search (BS) to pre-screen the transmission nodes based on the security degree; Then the problem is reconstructed as a Markov decision process, and the proximal policy optimization (PPO) reinforcement learning algorithm is used to solve the minimization objective function to obtain the optimal strategy balancing the delay and energy consumption, and the routing path is selected based on the strategy. The routing algorithm BS and PPO (BSPPO) designed by fusing BS and PPO can adaptively adjust the routing path and quickly respond to routing reconstruction when facing attacks.
2. The fusion of SDN and blockchain-based zero-trust UAV network security routing method according to claim 1, characterized in that, Step S1 further comprises: Provided are a low-altitude unmanned aerial vehicle deployed in a square area with a side length of , representing a set of unmanned aerial vehicles, each unmanned aerial vehicle flying along a predetermined trajectory at a fixed height and equipped with sensors for real-time environmental monitoring, and in the event of a ground emergency, the data packets generated in response will be forwarded to the ground destination node emergency center under multi-hop transmission. The position of the unmanned aerial vehicle is represented by , the maximum communication radius is , and the SDN controller is deployed on a fixed-position base station to centrally manage and control routing based on real-time record-based blockchain. 3.The fusion SDN and blockchain based zero-trust UAV network security routing method of claim 2, wherein, Step S2 further comprises: A lightweight threshold verification method is deployed on each UAV to determine whether the UAV is under attack and the data is safe by detecting and verifying the length of the data packet whether it is within a normal range , wherein, and are calculated from and respectively, represents the expected length of a normal data packet, denotes the standard deviation, denotes a threshold coefficient, the index is used to indicate whether the state of the data packet is normal, i.e. 。 4. The fusion of SDN and blockchain-based zero-trust UAV network security routing method according to claim 3, characterized in that, In step S3, the security degree of the node is calculated by using the following formula : , wherein represents the trustworthiness of the neighboring drones of the node, represents the historical trustworthiness of the node, is a weight coefficient used to balance the trustworthiness of neighboring nodes and the historical trustworthiness; the drone node The trustworthiness of the neighbor of the node is calculated by represents the set of all neighbor nodes, calculated as , wherein represents a number of neighbor drone nodes, represents a drone In the first of the hop, the initial From historical experience, when the drone completes the security authentication, the neighboring node credibility of the drone will be updated with the status, that is , is a decreasing factor to avoid over-penalization, Drones In the first Historical credibility of jumps Defined as the number of times the user has passed security verification And the ratio of the total number of security verifications in history: , in Indicates drone Number of verification failures and All along Changes and updates, i.e. 。 5. The fusion of SDN and blockchain-based zero-trust UAV network security routing method according to claim 4, characterized in that, In step S4, the zero-trust framework fusing SDN and blockchain mainly consists of the following parts: Event awareness and record chaining: When the source drone detects an emergency during monitoring, it will immediately encrypt and package the geographic location information, event category and transmission request as an event announcement, and then broadcast it to the blockchain. At the same time, the source drone records sensor and camera data in the cache, checks its legality and integrity, and chains the event record, SDN monitoring and routing planning: The SDN controller continuously monitors the blockchain, and when it detects emergency-related information, the SDN controller will immediately activate the routing planning algorithm for routing calculation, and then transmit the calculation results to the source drone, Routing execution: After receiving the routing instructions from the SDN controller, the source drone transmits data packets through relay drones, and each drone will perform security authentication on data from the previous drone based on the zero-trust principle and update the security status on the blockchain, Abnormal awareness and dynamic rerouting: When abnormal records are detected on the blockchain, the SDN controller will immediately perform dynamic routing recalculation, discard abnormal data packets, avoid abnormal drones, and send new path strategies to the previous safe drone. Then, the safe drone before the attacked drone will use its buffer storage to retransmit data, thereby repairing the route and achieving dynamic adaptive reconstruction of the route.
6. The fusion of SDN and blockchain-based zero-trust UAV network security routing method according to claim 5, characterized in that, In step S5, according to the zero-trust network security communication environment constructed by fusing SDN and blockchain, a free space path loss model between unmanned aerial vehicle nodes is designed, and a maximum allowable transmission rate is determined The calculation is: , with representing the signal-to-noise ratio of the communication channel and the drone , representing the bandwidth of the communication channel.
7. The fusion of SDN and blockchain-based zero-trust UAV network security routing method according to claim 6, characterized in that, In step S6, since the flight energy consumption and the monitoring energy consumption are relatively fixed, the communication energy consumption in the routing process is mainly considered, including the transmission energy consumption required by hop-by-hop forwarding and receiving energy consumption i.e. and , wherein represents the size of the data packet, is the energy consumption per bit of the electronic circuit, represents the transmission power between the drone and the total energy consumption is calculated as , represents the set of candidate drones required for transmission in all routing paths.
8. The fusion of SDN and blockchain-based zero-trust UAV network security routing method according to claim 7, characterized in that, In step S7, the request latency is taken into account , the processing latency , the response latency , the end-to-end latency , the destination latency and the re-routing latency which varies according to the attack situation : denotes the request latency when the UAV monitors the environmental problem event and uploads the information to the blockchain, the processing latency denoted by and is added, after detecting the abnormal record, the SDN controller needs to query the consensus information on the blockchain, denoted as query time Then the SDN controller calculates the The latency of this processing is The calculation is: , wherein, denotes the time needed to calculate the security degree of each node, denotes the computing load of each node, denotes the computing clock frequency of the controller, the response delay of the SDN to issue routing information to the source drone denotes that: , represents the size of the routing packet, while is the bandwidth between the source drone and the SDN controller, end-to-end latency contains the transmission latency and the self-security authentication latency, from the drone to the drone The latency between the drone and the drone is calculated as: , wherein a safety certification latency, of the UAV, a safety certification latency, and a distance between the UAV, representing the speed of light, the total end-to-end latency is expressed as: , Binary variable represents the link connection state between the UAVs, represents that data will be transmitted from the UAV to the UAV , 0 represents the opposite, the destination delay is represented as: , Thus, when no attack occurs, the total latency of the entire routing procedure is calculated as: , When an attack occurs and the attacked drone node is detected at the time of security authentication, the SDN needs to make a decision on the re-routing, replanning the path to avoid the abnormal node, and the re-routing delay calculation is i.e. , wherein represent detected attacks, denotes the total number of detected attacks, contains , and since it can be subjected to attacks, the total re-routing latency is calculated as: , The actual delay of the emergency communication routing of the drone is represented as: ; The objective function is the weighted sum of the joint minimization of communication delay and energy consumption, which is expressed as: , wherein is a set of variables in the problem, respectively representing a set of candidate UAVs is a set of variables of inter-UAV connection links ; with coefficients representing the weighted proportion of latency and energy consumption, represents the minimum signal-to-noise ratio value, and the communication condition needs to satisfy that the signal-to-noise ratio is not less than ; represents the minimum safety threshold that each communication UAV safety cannot be less than; represents the residual energy of the UAV , and the energy of the UAV cannot be less than the energy threshold after each communication ends, so as to limit the energy consumption of each communication; is the maximum communication distance of the UAV. 9.The fusion SDN and blockchain based zero-trust UAV network security routing method of claim 8, wherein, In step S8, the network topology is abstracted as an undirected graph And the beam search BS pre-screens the transmission nodes according to the security degrees of the nodes, and screens out the nodes with high security degrees and meeting the restrictions of the target function, wherein the path score of the BS algorithm for pre-screening is represented as: , representing from the origin node to the destination node a complete path, the first candidate paths filtered according to path score are merged into a set of points and edges, represented as and .
10. The fusion of SDN and blockchain-based zero-trust UAV network security routing method of claim 9, wherein, In step S8, the problem is further reconstructed as a Markov decision process for solving, and the policy gradient clipping reinforcement learning algorithm PPO is used to find the routing strategy that minimizes the objective function, wherein: State including the position of the UAV , legal neighbor nodes , each node and possible link cost , wherein ; the action space is represented as ; the reward function is set as the inverse of the normalized delay and energy consumption weighted sum, the objective is restructured to maximize the reward function, with to represent the weight, adjusting the proportion of energy consumption and delay, namely , The reward in this case, represents the total number of time steps of training, at the current step , the reward value is the cumulative reward of the future steps, considering from the current time step , the connection state of the UAV link at the future steps; In step S8, the routing decision based on BSPPO can quickly adjust and adaptively reconstruct the routing after facing the attack node, ensuring the communication security, which is specifically expressed as: In the process of hop-by-hop routing, when the attacked node is detected, the agent will perform fallback and dynamic rerouting operations to ensure transmission security, and the SDN controller will recalculate , by excluding the attacked node, reconstructing the local topology, then the agent reselects the previous safe node, i.e., the second last node in the path history, performs rerouting based on the BS candidate set, and continues to perform PPO-based routing decisions until reaching the destination.