computer security

CDA: Privacy-Preserving and Provably Secure Cross Domain Authentication Scheme for Internet of Drones

arXiv:2607.12288

summary

The paper proposes P³CDA, a privacy-preserving and provably secure cross‑domain authentication scheme for Internet‑of‑Drones that uses adaptive pseudonym management, an enhanced Merkle hash tree, and cryptographic accumulators to enable efficient anonymous authentication and revocation.

Abstract

With the rapid expansion of the Internet of Drones (IoD) and the increasing mobility of drones, cross-domain interactions among geographically distributed domains have become inevitable. Cross-domain authentication is therefore a fundamental security requirement for IoD. However, existing authentication schemes often struggle to simultaneously achieve strong security, high efficiency, and identity privacy, making them unsuitable for the stringent requirements of highly dynamic and resource-constrained IoD environments. To address this challenge, we propose CDA, a privacy-preserving and provably secure cross-domain authentication scheme. First, we design an efficient pseudonym management mechanism that supports adaptive pseudonym generation as well as batch registration, verification, and revocation. Second, we propose a structurally enhanced Merkle Hash Tree (MHT) that supports batch pseudonym updates, thereby reducing the pseudonym storage overhead of drones. Building on these components, we develop a cryptographic accumulator-based cross-domain authentication protocol that enables anonymous authentication with authorized pseudonyms while preserving the traceability and efficient revocation of malicious drones. We rigorously analyze the security of CDA and formally prove its security under the Canetti--Krawczyk (CK) adversary model. Extensive experiments demonstrate that CDA achieves lower computational, communication, and storage overhead than state-of-the-art schemes.

Submitted to IEEE Transactions on Dependable and Secure Computing

Topics & keywords

#drone security#cross-domain authentication#privacy-preserving#pseudonym management#merkle hash treecryptographic accumulatoradaptive pseudonym generationbatch registrationCK adversary modelIoD