Skip to content
Open access

A Lightweight Forward-Unlinkable Authenticated Key Agreement Protocol for Secure UAV Communication in Internet of Drones Environments

Aug 2026 · International journal of computer information systems and industrial management applications · 0 citations

Abstract

Secure authentication, confidentiality, and communication privacy are critical requirements in mission-critical Internet of Drones (IoD) applications such as disaster response, defense, border monitoring, and surveillance, where Unmanned Aerial Vehicles (UAVs) are being increasingly used. Many lightweight authentication and key agreement protocols initially developed for IoT and wireless sensor networks, however, are not sufficiently robust to provide an appropriate level of security for IoD applications, especially considering physical drone capture, long-term credential compromise, and post-compromise transcript correlation challenges. This paper proposes a lightweight forward-unlinkable authenticated key agreement protocol for secure UAV communication in adversarial IoD environments. The protocol is based on an authenticated ephemeral X25519 Diffie–Hellman exchange, key derivation from HKDF, transcript authentication using HMAC and explicit key confirmation. The session keys are based on newly created ephemeral secrets and don't necessarily stem from long-term stored credentials, so if a drone's memory is compromised, the session keys of previous sessions are not exposed. Pseudonym rotation and context-bound key derivation are incorporated to strengthen session separation and reduce the possibility of linking previous or future protocol transcripts after drone capture. The proposed protocol is analyzed under an extended Dolev–Yao adversary model with drone-capture capability and is supported through ProVerif-style symbolic validation. The analysis indicates that the protocol provides mutual authentication, session-key secrecy, replay resistance, man-in-the-middle protection, forward secrecy, and forward unlinkability. Operation-level cost analysis and published embedded-platform benchmarks show that the cryptographic overhead remains lightweight, with per-session computation requiring only a few milliseconds and communication overhead remaining within a few hundred bytes. The results demonstrate that lightweight authenticated key agreement can provide practical cyber-security and privacy protection for resource-constrained UAV communication without relying on heavy infrastructures such as blockchain, certificate-based PKI, or zero-knowledge proof systems.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.