Security and Performance Assessment of UAVs Authentication Protocols

In the past few years, unmanned aerial vehicles (UAVs) have significantly gained attention and popularity from industry, government, and academia. With their rapid development and deployment into the civilian airspace, UAVs play an important role in different applications, including goods delivery, search-and-rescue, and traffic monitoring. Therefore, providing secure communication through authentication models for UAVs is necessary for a successful and reliable flight mission. The performance and resilience of UAV authentication protocols against various cyber attacks are of great concern as thousands of UAVs are deployed in the wild. The fundamental security properties that need to be achieved when designing
an authentication scheme include confidentiality, integrity, availability, and non-repudiation. However, these properties should also consider performance requirements for UAV-oriented applications (e.g., mobility, energy consumption). While UAV authentication protocols enable secure communication, they raise security and performance challenges that need to be addressed.

In this project, we analyze the security and performance of 27 recent UAV authentication works by considering ten different key metrics. First, in the performance analysis, we show that the majority of UAV authentication schemes are lightweight in their communication cost. However, the storage overhead or the energy consumption is not reported by many authentication studies. Then, we reveal in the security analysis the widely employed formal models (i.e., abstract description of an authentication protocol through a mathematical model), while most of the studies lack coverage of many attacks that can target UAV systems. Afterwards, we highlight the challenges that need to be addressed in order to design and implement secure and reliable UAV authentication schemes. Finally, we summarize the lessons learned on the authentication strategies for UAVs to motivate promising direction for further research.

 


Overview of UAV Authentication Landscape

Figure: Visual representation of malicious and benign UAV communication with the Ground Control Station

Project Description

Motivation

The recent advancement in UAV technology, particularly in military and civilian applications, has demonstrated that authentication is a common requirement for a secure and safe flight mission. A significant number of authentication schemes have been proposed to prevent malicious actors from jeopardizing UAV operations. However, these solutions often incur security-performance tradeoffs due to the constrained computational and energy resources of UAVs.

Despite these research efforts, there is limited understanding of how these authentication protocols perform in real-world deployments. More specifically, no prior work has jointly assessed both the security and performance aspects of UAV authentication schemes. To bridge this gap, we are motivated to perform a comprehensive investigation to provide a systematic and metric-driven assessment that can guide future designs of UAV authentication protocols.

Scope and Study Objectives

In our project, we examine 27 UAV authentication protocols published between 2019 and 2022, targeting various environments such as:

  • Smart city surveillance
  • Internet of Drones (IoD)
  • 5G wireless infrastructure
  • Software-defined UAV networks
  • Mobile edge computing and battlefield scenarios

Our objective is to show how UAV authentication schemes are designed and implemented from a security and performance standpoint across different target environments. In particular, we indicate that designing an UAV authentication scheme highly depends on the target environment.

Analyzed Authentication Studies

In what follows, we outline all 27 considered UAV authentication studies and their target environments:

Table: The Analyzed UAV Authentication Studies
Work Year Target Environment
Yu et al. [1] 2022 Smart city environment
Lounis et al. [2] 2022 Internet of Drones environment
Pu et al. [3] 2022 Internet of Drones environment
Tian et al. [4] 2022 Multi-domain environment
Zhang et al. [5] 2022 Smart UAV networks environment
Tan et al. [6] 2022 Industrial Internet of Things environment
Tanveer et al. [7] 2022 Internet of Drones environment
Yahuza et al. [8] 2021 Internet of Drones environment
Asghar Khan et al. [9] 2021 5G wireless networking infrastructure
Lei et al. [10] 2021 Internet of Drones environment
Jan et al. [11] 2021 Internet of Drones environment
Gope et al. [12] 2021 RFID-enabled UAV applications
Mall et al. [13] 2021 Unattended environments (e.g., forest, battlefield)
Nikooghadam et al. [14] 2021 Smart city surveillance environment
Hussain et al. [15] 2021 Internet of Drones environment
Chen et al. [16] 2020 3.5G (14 Mbps)
Alladi et al. [17] 2020 SDN-backed multi UAV networks environment
Pu et al. [18] 2020 UAV network
Kirsal Ever et al. [19] 2020 Wireless Sensor Networks
Cho et al. [20] 2020 Internet of Drones environment
Ali et al. [21] 2020 Smart city surveillance environment
Khanh et al. [22] 2020 Dynamic environment for a swarm of UAVs
Alladi et al. [23] 2020 Internet of Drones environment
Srinivas et al. [24] 2019 Internet of Drones environment
Wazid et al. [25] 2019 Internet of Drones environment
Tian et al. [26] 2019 Mobile Edge Computing environment
Rodrigues et al. [27] 2019 Wireless Sensor Networks

Authentication Models Considered

We categorize the studied schemes into several models based on how they establish trust between UAVs and ground control stations:

  • Certificate-based authentication: It consists of using a digital certificate to authenticate UAVs over public communication channels. In particular, it relies on a trusted authority center that provides valid digital certificates for legitimate UAVs participating in the flight mission.
  • Challenge-response authentication: In this type of authentication, the UAV is challenged by the GCS and must provide a valid response. Recent works consider the use of physical unclonable functions (PUF) to authenticate UAVs using a challenge-response authentication mechanism.
  • Identity-based authentication: It consists of verifying the legitimate identity of the UAV participating in the flight mission and preventing impersonation and masquerade attacks.
  • Anonymous-based authentication: This method of authentication satisfies the anonymity property for the UAVs. It consists of authenticating legitimate UAVs without revealing their identity.
  • Credential-based authentication: This type of authentication requires the UAVs to provide credentials, which can be defined as UAV-related information for the authentication. Generally, credential-based authentication includes a trusted third party during the authentication process. 
  • Hash-based authentication: It consists of authenticating UAVs by involving the use of cryptographic hash functions. Moreover, hash-based authentication guarantees integrity and authentication simultaneously.
  • Asymmetric cryptosystem authentication: These authentication schemes rely solely on cryptographic primitives. In particular, authentication frameworks that implement various elliptic curve mechanisms, Diffie-Hellman key exchange protocol, and hash functions.

Evaluation Framework

We introduce a novel evaluation framework that combines six performance metrics and four security metrics to enable a comprehensive analysis of each scheme.

Performance Metrics:

  • Communication Cost: Also known as data transfer overhead, it represents the number of bytes an authentication scheme needs to exchange over the GCS-2-UAV communication channel. Such data enables the authenticity of UAVs during a flight mission.
  • Computation Cost: It consists of the amount of time required by a processor to perform computations during the authentication process. Since UAVs are resource-constrained devices with limited processing functionality, it is important to consider reducing the computation costs while designing the authentication model.
  • Storage Overhead:  It corresponds to the size of memory space used during the UAV authentication process. The storage overhead is an important metric that measures authentication protocols’ performance. An authentication technique with a low storage overhead can enable larger storage space for the onboard UAV software.
  • Energy Consumption: This metric illustrates the amount of energy consumed by the UAVs during the authentication process. It is worth mentioning that several characteristics influence the energy consumption of UAVs (e.g., speed, weather, payload). 
  • Experimental Method: In this metric, we identify the experimental settings under which the proposed UAV authentication scheme is evaluated (e.g., hardware, simulation).
  • Network Topology: This metric considers the UAV network architecture proposed by the authentication scheme and its corresponding characteristics (e.g., throughput, end-to-end delay, networking environment).

Security Metrics:

  • Formal Security Analysis: Also known as provable security analysis. It is an abstract description of an authentication protocol through a mathematical model (e.g., Dolev-Yao adversarial model, random oracle model-ROM). Such a description consists of formally proving the security properties of a system model (e.g., authentication, integrity, secrecy).
  • Informal Security Analysis: Given a UAV authentication model, the informal security analysis evaluates its security features under the assumption considered in the threat model. Thus, it demonstrates informally its resilience against known cyber attacks (e.g., spoofing attack, replay attack, impersonation attack, insider attack). Here, we choose fifteen different attacks that are covered in most of the selected studies, and which we believe are more practical than others in real use-case scenarios.
  • Cryptographic Features: This metric identifies the cryptographic algorithms used by the proposed UAV authentication scheme (e.g., hash functions, fuzzy extractors, password-based-key-derivation functions).
  • Authentication Factors: It consists of specifying the factor utilized by the proposed UAV authentication scheme (e.g., password authentication, biometric authentication, digital certificates).

By unifying these ten metrics, our evaluation enables a balanced and comparative analysis of UAV authentication protocols from both system-level and cryptographic standpoints. In the figure below, we illustrate the taxonomy of our metrics, which we will consider as a reference model throughout our assessment process.


Evaluation Metrics Overview

Figure: Taxonomy of performance and security metrics used in our evaluation of UAV authentication protocols.

References of the Analyzed Studies

  1. [1] Yu, S., Das, A. K., Park, Y., and Lorenz, P. 2022. “SLAP-IoD: Secure and Lightweight Authentication Protocol Using Physical Unclonable Functions for Internet of Drones in Smart City Environments.” IEEE Transactions on Vehicular Technology 71(10): 10374–10388.
  2. [2] Lounis, K., Ding, S. H., and Zulkernine, M. 2022. “D2D-MAP: A Drone-to-Drone Authentication Protocol Using Physical Unclonable Functions.” IEEE Transactions on Vehicular Technology 72: 5079–5093.
  3. [3] Pu, C., and Li, Y. 2020. “Lightweight Authentication Protocol for UAVs Using Physical Unclonable Function and Chaotic System.” In IEEE LANMAN, 1–6.
  4. [4] Tian, Y., Yuan, J., and Song, H. 2019. “Efficient Privacy-Preserving Authentication Framework for Edge-Assisted Internet of Drones.” Journal of Information Security and Applications 48: 102354.
  5. [5] Zhang, H., Wang, W., and Guo, Q. 2022. “PUF-Based Mutual Authentication for Smart UAV Networks.” Wireless Networks 28: 1234–1249.
  6. [6] Tan, Y., et al. 2022. “Blockchain-Assisted Lightweight Authentication for Industrial UAVs.” IEEE Internet of Things Journal 9(12): 10351–10362.
  7. [7] Tanveer, M., et al. 2022. “RUAM: Robust and Lightweight Authentication Mechanism for IoD.” IEEE Access 10: 76300–76312.
  8. [8] Yahuza, M., et al. 2021. “Edge-Assisted Secure Lightweight Authentication for Internet of Drones.” IEEE Access 9: 31420–31440.
  9. [9] Khan, M. A., et al. 2021. “Privacy-Preserving Authentication for UAV-Enabled ITS.” IEEE Transactions on Industrial Informatics 18(5): 3416–3425.
  10. [10] Lei, Y., et al. 2021. “Lightweight Authentication Protocol for UAV Networks.” IEEE Access 9: 53769–53785.
  11. [11] Jan, S. U., Qayum, F., and Khan, H. U. 2021. “Lightweight Authentication Protocol for Securing IoD.” IEEE Access 9: 69287–69306.
  12. [12] Gope, P., Millwood, O., and Saxena, N. 2021. “Secure Authentication for RFID-Enabled UAVs.” Computer Communications 166: 19–25.
  13. [13] Mall, P., et al. 2021. “CoMSeC++: PUF-Based Mutual Authentication for Drone WSNs.” Computer Networks 199: 108476.
  14. [14] Nikooghadam, M., et al. 2021. “Secure and Lightweight Authentication for IoD in Smart Cities.” Journal of Systems Architecture 115: 101955.
  15. [15] Hussain, S., et al. 2021. “ECC-Based Authentication Scheme for IoD.” IEEE Systems Journal 15(3): 4431–4438.
  16. [16] Chen, C. L., et al. 2020. “Traceable and Privacy-Preserving Authentication for UAV Control.” Electronics 9(1): 62.
  17. [17] Alladi, T., et al. 2020. “SecAuthUAV: Novel Authentication for UAV-to-GCS and UAV-to-UAV.” IEEE Transactions on Vehicular Technology 69(12): 15068–15077.
  18. [18] Pu, C., et al. 2020. “Lightweight Multi-Layered UAV Authentication.” In IEEE Smart Cities Conference.
  19. [19] Kirsal Ever, Y. 2020. “Secure Authentication for Mobile-Sinks in IoD.” Computer Communications 155: 143–149.
  20. [20] Cho, G., et al. 2020. “SENTINEL: Secure Authentication for UAVs.” Applied Sciences 10(9): 3149.
  21. [21] Ali, Z., et al. 2020. “Lightweight UAV Authentication for Smart City Surveillance.” IEEE Access 8: 43711–43724.
  22. [22] Khanh, T. D., et al. 2020. “TRA: Authentication Mechanism for UAV Swarms.” In IEEE SSCI, 1852–1858.
  23. [23] Alladi, T., et al. 2020. “PARTH: Two-Stage Mutual Authentication for UAV Surveillance.” Computer Communications 160: 81–90.
  24. [24] Srinivas, J., et al. 2019. “TCALAS: Anonymous Lightweight Authentication for IoD.” IEEE Transactions on Vehicular Technology 68(7): 6903–6916.
  25. [25] Wazid, M., et al. 2019. “Secure Remote User Authentication in IoD.” IEEE Internet of Things Journal 6(2): 3572–3584.
  26. [26] Tian, Y., et al. 2019. “Privacy-Preserving Authentication for MEC-Enabled IoD.” Journal of Information Security and Applications 48: 102354.
  27. [27] Rodrigues, M., et al. 2019. “Authentication Methods for UAVs.” In IEEE ISCC, 1210–1215.

Key Findings

Lightweight Protocols: Most UAV authentication schemes exhibit low communication cost and fit within wireless protocol frames. Message sizes range from 336 to 5536 bits.
Execution Time: Computation times vary between 0.002 ms and 35 ms. Protocols using elliptic curve cryptography show better overall efficiency.
Storage Gaps: Over 50% of surveyed schemes do not report storage overhead, thereby raising serious concerns for small drones such as Micro Aerial Vehicles with limited memory.
Unreported Energy Usage: Energy consumption is rarely addressed. Only 3 out of 27 schemes provided measurable energy data.
Security Tradeoffs: Most protocols offer limited formal or informal analysis, but none are resilient against all 15 common attacks. The average number of attacks considered by the studies is 5 attacks per study, representing 33.33% of the attacks.
Network Topology Limitations: Few schemes validate their performance across different UAV topologies. Scalability and throughput are rarely analyzed.

 

Insight: Our findings showed that the majority of the UAV authentication schemes are quite lightweight in terms of their communication costs while demonstrating strong security features to some extent. In addition, the computation cost is the most widely reported performance metric among the UAV authentication studies. However, many UAV authentication studies do not consider the storage overhead or their scheme’s energy consumption, which can negatively affect the performance of resource-constrained UAVs such as micro aerial vehicles. Finally, several UAV authentication studies provide a formal or informal security analysis of their schemes. While the Random Oracle Model and Dolev-Yao models are the most widely employed formal models for informal security analysis, the studies lack coverage of many attacks that can target UAV systems. Overall, efficient UAV authentication strategies must require a balance between security and performance. This calls for more balanced approaches in future UAV authentication protocol design.

Project Team Members

Yassine Mekdad
Graduate Research Assistant
Ahmet Aris
Post Doctoral Associate
Abbas Acar
Post Doctoral Associate
Riccardo Lazzeretti
Associate Professor
Mauro Conti
Full Professor
Abdeslam El Fergougui
Full Professor
Selcuk Uluagac
Eminent Scholar Chaired Professor

Publications:

  • Yassine Mekdad, Ahmet Aris, Abbas Acar, Mauro Conti, Riccardo Lazzeretti, Abdeslam El Fergougui, and Selcuk Uluagac. “A comprehensive security and performance assessment of UAV authentication schemes.” Security and Privacy 7, no. 1 (2024): e338.[pdf] [bibtex]
  • Yassine Mekdad, Ahmet Aris, Leonardo Babun, Abdeslam El Fergougui, Mauro Conti, Riccardo Lazzeretti, and A. Selcuk Uluagac. “A survey on security and privacy issues of UAVs.” Computer networks 224 (2023) [pdf] [bibtex]

Presentations and Talks:

  • TBD [poster]