Uppsats
Lightweight PKI-Based Authentication and Privacy-Preserving Verification for Partially Encrypted Drone RemoteID Broadcasts
Master-uppsats
Linköpings universitet/Institutionen för datavetenskap
Publicerad: 2026
Språk: Engelska
Nyckelord
klicka för att sökaSammanfattning
Remote Identification (RemoteID) improves accountability and situational awareness for unmanned aerial vehicles (UAVs), but plaintext RemoteID broadcasts can expose persistent identity and sensitive telemetry information to any nearby observer. This creates privacy risks such as long-term tracking, while the broadcast-only nature of RemoteID makes interactive authentication mechanisms unsuitable. This thesis addresses the problem of authenticating partially encrypted RemoteID broadcasts while reducing unnecessary plaintext exposure and maintaining lightweight operation for resource-constrained UAV environments. The thesis proposes a lightweight Public Key Infrastructure (PKI)-based broadcast authentication mechanism based on a hybrid Type A/Type B structure. Type A broadcasts carry frequent signed and partially encrypted RemoteID payloads using temporary signing keys, while Type B manifests provide infrequent Trust Anchor-authorized binding of those temporary keys to validity windows. This separation allows public observers to verify authenticity offline using cached authorization state, while resolver-restricted payload fields remain inaccessible to general observers. The proposed hybrid mechanism was implemented in a software-based simulation framework and evaluated against a certificate-per-packet reference benchmark using protocol-level correctness metrics, cold-start delay, cryptographic timing, observer-state occupancy, and communication-overhead measurements, supported by Bluetooth Low Energy (BLE)-oriented payload feasibility indicators. The evaluation showed that the hybrid mechanism preserved verification correctness under clean delivery, manifest loss, and delayed authorization conditions. Manifest loss caused temporary unverifiability and cold-start delay rather than false acceptance or integrity failure. The largest measured p95 cryptographic timing was 241.20 microseconds, well below the one-second simulation tick, and observer cache and buffer usage remained within configured bounds. The hybrid Type A broadcast measured 232 bytes compared with 452 bytes for the certificate-per-packet reference benchmark, reducing the frequent serialized broadcast size by approximately 49%. At 50 UAVs, the hybrid mechanism reduced airtime-correct transmitted bytes per second by approximately 45.25% while maintaining comparable verified throughput behavior under density degradation. The results support selected Drone Remote Identification Protocol (DRIP)-aligned properties, including offline observer-side verification, Trust Anchor-based authorization, authorization amortization, and bounded observer-side state. The work does not claim full DRIP compliance or deployment readiness, but demonstrates that a lightweight PKI-based hybrid mechanism can support privacy-preserving verification of partially encrypted RemoteID broadcasts under controlled simulation assumptions.
Information
- Författare
- Emojorho, Success
- Lärosäte / institution
- Linköpings universitet/Institutionen för datavetenskap
- Publiceringsdatum
- 2026
- Uppsatstyp
- Master-uppsats
- Språk
- Engelska