Lightweight identity-based authentication and key exchange for constrained unmanned aerial vehicle environments
Abstract
Increasing use of the internet of drones (IoD) in defence and tactical applications demands lightweight but secure cryptographic mechanisms that provide privacy, integrity, and authenticity. This paper details a refined identity-based encryption framework that utilizes elliptic curve cryptography and bilinear pairing to provide a safe and efficient method of communication between IoD networks. Unlike traditional public-key cryptography, the proposed approach avoids certificate-management overhead by deriving public credentials from entity identities and by using the certificate authority as the Private Key Generator (PKG) only for offline private-key issuance, revocation, and update. Moreover, key exchange is performed between the drone and the Ground Control Station (GCS) using identity-bound ephemeral key values, hence ensuring that forward secrecy is achieved. The established session key can be used for end-to-end encryption of IoD-critical applications, including secure command, telemetry, and status-message exchange using lightweight symmetric encryption. The design also presents time-bound identity-based key revocation and updates, hence protecting against key threats over long durations. A testbed evaluation of the post-authentication data-channel phase demonstrates the suitability of encrypted unmanned aerial vehicle command exchange after the session key has been established. A detailed comparison with recent schemes shows that the proposed framework provides Identity-Based Key Management without Certificates and Time-Bound Credential Revocation, thus providing a favorable trade-off.