Security and Performance Assessment of UAVs Authentication Protocols
In the past few years, unmanned aerial vehicles (UAVs) have significantly gained attention and popularity from industry, government, and academia. With their rapid development and deployment into the civilian airspace, UAVs play an important role in different applications, including goods delivery, search-and-rescue, and traffic monitoring. Therefore, providing secure communication through authentication models for UAVs is necessary for a successful and reliable flight mission. The performance and resilience of UAV authentication protocols against various cyber attacks are of great concern as thousands of UAVs are deployed in the wild. The fundamental security properties that need to be achieved when designing
an authentication scheme include confidentiality, integrity, availability, and non-repudiation. However, these properties should also consider performance requirements for UAV-oriented applications (e.g., mobility, energy consumption). While UAV authentication protocols enable secure communication, they raise security and performance challenges that need to be addressed.
In this project, we analyze the security and performance of 27 recent UAV authentication works by considering ten different key metrics. First, in the performance analysis, we show that the majority of UAV authentication schemes are lightweight in their communication cost. However, the storage overhead or the energy consumption is not reported by many authentication studies. Then, we reveal in the security analysis the widely employed formal models (i.e., abstract description of an authentication protocol through a mathematical model), while most of the studies lack coverage of many attacks that can target UAV systems. Afterwards, we highlight the challenges that need to be addressed in order to design and implement secure and reliable UAV authentication schemes. Finally, we summarize the lessons learned on the authentication strategies for UAVs to motivate promising direction for further research.
Project Description
Motivation
The recent advancement in UAV technology, particularly in military and civilian applications, has demonstrated that authentication is a common requirement for a secure and safe flight mission. A significant number of authentication schemes have been proposed to prevent malicious actors from jeopardizing UAV operations. However, these solutions often incur security-performance tradeoffs due to the constrained computational and energy resources of UAVs.
Despite these research efforts, there is limited understanding of how these authentication protocols perform in real-world deployments. More specifically, no prior work has jointly assessed both the security and performance aspects of UAV authentication schemes. To bridge this gap, we are motivated to perform a comprehensive investigation to provide a systematic and metric-driven assessment that can guide future designs of UAV authentication protocols.
Scope and Study Objectives
In our project, we examine 27 UAV authentication protocols published between 2019 and 2022, targeting various environments such as:
- Smart city surveillance
- Internet of Drones (IoD)
- 5G wireless infrastructure
- Software-defined UAV networks
- Mobile edge computing and battlefield scenarios
Our objective is to show how UAV authentication schemes are designed and implemented from a security and performance standpoint across different target environments. In particular, we indicate that designing an UAV authentication scheme highly depends on the target environment.
Analyzed Authentication Studies
In what follows, we outline all 27 considered UAV authentication studies and their target environments:
| Work | Year | Target Environment |
|---|---|---|
| Yu et al. [1] | 2022 | Smart city environment |
| Lounis et al. [2] | 2022 | Internet of Drones environment |
| Pu et al. [3] | 2022 | Internet of Drones environment |
| Tian et al. [4] | 2022 | Multi-domain environment |
| Zhang et al. [5] | 2022 | Smart UAV networks environment |
| Tan et al. [6] | 2022 | Industrial Internet of Things environment |
| Tanveer et al. [7] | 2022 | Internet of Drones environment |
| Yahuza et al. [8] | 2021 | Internet of Drones environment |
| Asghar Khan et al. [9] | 2021 | 5G wireless networking infrastructure |
| Lei et al. [10] | 2021 | Internet of Drones environment |
| Jan et al. [11] | 2021 | Internet of Drones environment |
| Gope et al. [12] | 2021 | RFID-enabled UAV applications |
| Mall et al. [13] | 2021 | Unattended environments (e.g., forest, battlefield) |
| Nikooghadam et al. [14] | 2021 | Smart city surveillance environment |
| Hussain et al. [15] | 2021 | Internet of Drones environment |
| Chen et al. [16] | 2020 | 3.5G (14 Mbps) |
| Alladi et al. [17] | 2020 | SDN-backed multi UAV networks environment |
| Pu et al. [18] | 2020 | UAV network |
| Kirsal Ever et al. [19] | 2020 | Wireless Sensor Networks |
| Cho et al. [20] | 2020 | Internet of Drones environment |
| Ali et al. [21] | 2020 | Smart city surveillance environment |
| Khanh et al. [22] | 2020 | Dynamic environment for a swarm of UAVs |
| Alladi et al. [23] | 2020 | Internet of Drones environment |
| Srinivas et al. [24] | 2019 | Internet of Drones environment |
| Wazid et al. [25] | 2019 | Internet of Drones environment |
| Tian et al. [26] | 2019 | Mobile Edge Computing environment |
| Rodrigues et al. [27] | 2019 | Wireless Sensor Networks |
Authentication Models Considered
We categorize the studied schemes into several models based on how they establish trust between UAVs and ground control stations:
- Certificate-based authentication: It consists of using a digital certificate to authenticate UAVs over public communication channels. In particular, it relies on a trusted authority center that provides valid digital certificates for legitimate UAVs participating in the flight mission.
- Challenge-response authentication: In this type of authentication, the UAV is challenged by the GCS and must provide a valid response. Recent works consider the use of physical unclonable functions (PUF) to authenticate UAVs using a challenge-response authentication mechanism.
- Identity-based authentication: It consists of verifying the legitimate identity of the UAV participating in the flight mission and preventing impersonation and masquerade attacks.
- Anonymous-based authentication: This method of authentication satisfies the anonymity property for the UAVs. It consists of authenticating legitimate UAVs without revealing their identity.
- Credential-based authentication: This type of authentication requires the UAVs to provide credentials, which can be defined as UAV-related information for the authentication. Generally, credential-based authentication includes a trusted third party during the authentication process.
- Hash-based authentication: It consists of authenticating UAVs by involving the use of cryptographic hash functions. Moreover, hash-based authentication guarantees integrity and authentication simultaneously.
- Asymmetric cryptosystem authentication: These authentication schemes rely solely on cryptographic primitives. In particular, authentication frameworks that implement various elliptic curve mechanisms, Diffie-Hellman key exchange protocol, and hash functions.
Evaluation Framework
We introduce a novel evaluation framework that combines six performance metrics and four security metrics to enable a comprehensive analysis of each scheme.
Performance Metrics:
- Communication Cost: Also known as data transfer overhead, it represents the number of bytes an authentication scheme needs to exchange over the GCS-2-UAV communication channel. Such data enables the authenticity of UAVs during a flight mission.
- Computation Cost: It consists of the amount of time required by a processor to perform computations during the authentication process. Since UAVs are resource-constrained devices with limited processing functionality, it is important to consider reducing the computation costs while designing the authentication model.
- Storage Overhead: It corresponds to the size of memory space used during the UAV authentication process. The storage overhead is an important metric that measures authentication protocols’ performance. An authentication technique with a low storage overhead can enable larger storage space for the onboard UAV software.
- Energy Consumption: This metric illustrates the amount of energy consumed by the UAVs during the authentication process. It is worth mentioning that several characteristics influence the energy consumption of UAVs (e.g., speed, weather, payload).
- Experimental Method: In this metric, we identify the experimental settings under which the proposed UAV authentication scheme is evaluated (e.g., hardware, simulation).
- Network Topology: This metric considers the UAV network architecture proposed by the authentication scheme and its corresponding characteristics (e.g., throughput, end-to-end delay, networking environment).
Security Metrics:
- Formal Security Analysis: Also known as provable security analysis. It is an abstract description of an authentication protocol through a mathematical model (e.g., Dolev-Yao adversarial model, random oracle model-ROM). Such a description consists of formally proving the security properties of a system model (e.g., authentication, integrity, secrecy).
- Informal Security Analysis: Given a UAV authentication model, the informal security analysis evaluates its security features under the assumption considered in the threat model. Thus, it demonstrates informally its resilience against known cyber attacks (e.g., spoofing attack, replay attack, impersonation attack, insider attack). Here, we choose fifteen different attacks that are covered in most of the selected studies, and which we believe are more practical than others in real use-case scenarios.
- Cryptographic Features: This metric identifies the cryptographic algorithms used by the proposed UAV authentication scheme (e.g., hash functions, fuzzy extractors, password-based-key-derivation functions).
- Authentication Factors: It consists of specifying the factor utilized by the proposed UAV authentication scheme (e.g., password authentication, biometric authentication, digital certificates).
By unifying these ten metrics, our evaluation enables a balanced and comparative analysis of UAV authentication protocols from both system-level and cryptographic standpoints. In the figure below, we illustrate the taxonomy of our metrics, which we will consider as a reference model throughout our assessment process.

Figure: Taxonomy of performance and security metrics used in our evaluation of UAV authentication protocols.
References of the Analyzed Studies
- [1] Yu, S., Das, A. K., Park, Y., and Lorenz, P. 2022. “SLAP-IoD: Secure and Lightweight Authentication Protocol Using Physical Unclonable Functions for Internet of Drones in Smart City Environments.” IEEE Transactions on Vehicular Technology 71(10): 10374–10388.
- [2] Lounis, K., Ding, S. H., and Zulkernine, M. 2022. “D2D-MAP: A Drone-to-Drone Authentication Protocol Using Physical Unclonable Functions.” IEEE Transactions on Vehicular Technology 72: 5079–5093.
- [3] Pu, C., and Li, Y. 2020. “Lightweight Authentication Protocol for UAVs Using Physical Unclonable Function and Chaotic System.” In IEEE LANMAN, 1–6.
- [4] Tian, Y., Yuan, J., and Song, H. 2019. “Efficient Privacy-Preserving Authentication Framework for Edge-Assisted Internet of Drones.” Journal of Information Security and Applications 48: 102354.
- [5] Zhang, H., Wang, W., and Guo, Q. 2022. “PUF-Based Mutual Authentication for Smart UAV Networks.” Wireless Networks 28: 1234–1249.
- [6] Tan, Y., et al. 2022. “Blockchain-Assisted Lightweight Authentication for Industrial UAVs.” IEEE Internet of Things Journal 9(12): 10351–10362.
- [7] Tanveer, M., et al. 2022. “RUAM: Robust and Lightweight Authentication Mechanism for IoD.” IEEE Access 10: 76300–76312.
- [8] Yahuza, M., et al. 2021. “Edge-Assisted Secure Lightweight Authentication for Internet of Drones.” IEEE Access 9: 31420–31440.
- [9] Khan, M. A., et al. 2021. “Privacy-Preserving Authentication for UAV-Enabled ITS.” IEEE Transactions on Industrial Informatics 18(5): 3416–3425.
- [10] Lei, Y., et al. 2021. “Lightweight Authentication Protocol for UAV Networks.” IEEE Access 9: 53769–53785.
- [11] Jan, S. U., Qayum, F., and Khan, H. U. 2021. “Lightweight Authentication Protocol for Securing IoD.” IEEE Access 9: 69287–69306.
- [12] Gope, P., Millwood, O., and Saxena, N. 2021. “Secure Authentication for RFID-Enabled UAVs.” Computer Communications 166: 19–25.
- [13] Mall, P., et al. 2021. “CoMSeC++: PUF-Based Mutual Authentication for Drone WSNs.” Computer Networks 199: 108476.
- [14] Nikooghadam, M., et al. 2021. “Secure and Lightweight Authentication for IoD in Smart Cities.” Journal of Systems Architecture 115: 101955.
- [15] Hussain, S., et al. 2021. “ECC-Based Authentication Scheme for IoD.” IEEE Systems Journal 15(3): 4431–4438.
- [16] Chen, C. L., et al. 2020. “Traceable and Privacy-Preserving Authentication for UAV Control.” Electronics 9(1): 62.
- [17] Alladi, T., et al. 2020. “SecAuthUAV: Novel Authentication for UAV-to-GCS and UAV-to-UAV.” IEEE Transactions on Vehicular Technology 69(12): 15068–15077.
- [18] Pu, C., et al. 2020. “Lightweight Multi-Layered UAV Authentication.” In IEEE Smart Cities Conference.
- [19] Kirsal Ever, Y. 2020. “Secure Authentication for Mobile-Sinks in IoD.” Computer Communications 155: 143–149.
- [20] Cho, G., et al. 2020. “SENTINEL: Secure Authentication for UAVs.” Applied Sciences 10(9): 3149.
- [21] Ali, Z., et al. 2020. “Lightweight UAV Authentication for Smart City Surveillance.” IEEE Access 8: 43711–43724.
- [22] Khanh, T. D., et al. 2020. “TRA: Authentication Mechanism for UAV Swarms.” In IEEE SSCI, 1852–1858.
- [23] Alladi, T., et al. 2020. “PARTH: Two-Stage Mutual Authentication for UAV Surveillance.” Computer Communications 160: 81–90.
- [24] Srinivas, J., et al. 2019. “TCALAS: Anonymous Lightweight Authentication for IoD.” IEEE Transactions on Vehicular Technology 68(7): 6903–6916.
- [25] Wazid, M., et al. 2019. “Secure Remote User Authentication in IoD.” IEEE Internet of Things Journal 6(2): 3572–3584.
- [26] Tian, Y., et al. 2019. “Privacy-Preserving Authentication for MEC-Enabled IoD.” Journal of Information Security and Applications 48: 102354.
- [27] Rodrigues, M., et al. 2019. “Authentication Methods for UAVs.” In IEEE ISCC, 1210–1215.
Key Findings
Insight: Our findings showed that the majority of the UAV authentication schemes are quite lightweight in terms of their communication costs while demonstrating strong security features to some extent. In addition, the computation cost is the most widely reported performance metric among the UAV authentication studies. However, many UAV authentication studies do not consider the storage overhead or their scheme’s energy consumption, which can negatively affect the performance of resource-constrained UAVs such as micro aerial vehicles. Finally, several UAV authentication studies provide a formal or informal security analysis of their schemes. While the Random Oracle Model and Dolev-Yao models are the most widely employed formal models for informal security analysis, the studies lack coverage of many attacks that can target UAV systems. Overall, efficient UAV authentication strategies must require a balance between security and performance. This calls for more balanced approaches in future UAV authentication protocol design.
Publications:
- Yassine Mekdad, Ahmet Aris, Abbas Acar, Mauro Conti, Riccardo Lazzeretti, Abdeslam El Fergougui, and Selcuk Uluagac. “A comprehensive security and performance assessment of UAV authentication schemes.” Security and Privacy 7, no. 1 (2024): e338.[pdf] [bibtex]
- Yassine Mekdad, Ahmet Aris, Leonardo Babun, Abdeslam El Fergougui, Mauro Conti, Riccardo Lazzeretti, and A. Selcuk Uluagac. “A survey on security and privacy issues of UAVs.” Computer networks 224 (2023) [pdf] [bibtex]
Presentations and Talks:
- TBD [poster]




