LightSecurePUF: A Lightweight PUF-Based Mutual Authentication and Session Key Establishment Protocol for Secure UAV-Ground Station Communications
Singh A1*
DOI:10.31033/IJEMR/16.3.2026.1930
1* Anjali Singh, Department of Computer Science and Engineering, Netaji Subhas University of Technology, Dwarka, New Delhi, India.
The rapid deployment of Unmanned Aerial Vehicles (UAVs) in military, surveillance, disaster management, precision agriculture, and intelligent transportation systems has significantly increased the demand for secure and lightweight authentication mechanisms. Due to the limited computational capability and energy constraints of UAV platforms, conventional public-key cryptographic protocols often impose excessive computational and communication overhead. Furthermore, wireless UAV-Ground Station (GS) communication is vulnerable to replay, impersonation, man-in-the-middle, and session hijacking attacks. To address these challenges, this paper proposes LightSecurePUF, a lightweight mutual authentication and session key establishment protocol based on Physically Unclonable Functions (PUFs), cryptographic hash functions, and Hash-based Message Authentication Codes (HMACs). The proposed protocol employs a challenge-response PUF mechanism to uniquely authenticate UAV devices while deriving a fresh session key from the long-term shared secret, PUF response, random nonces, and session identifier. Consequently, each communication session establishes an independent session key without increasing computational complexity. The security of the proposed protocol is formally verified using the Scyther protocol verification tool under the Dolev-Yao adversarial model. The verification results demonstrate that the protocol satisfies secrecy, mutual authentication, non-injective agreement, synchronization, and key confirmation properties, with no attacks detected within the verification bounds. Furthermore, the protocol achieves lower computational and communication overhead than existing authentication schemes, making it suitable for resource-constrained UAV-assisted Internet of Things (IoT) and cyber-physical systems.
Keywords: UAV Security, Physically Unclonable Function, Session Key Establishment, Lightweight Cryptography, HMAC, Scyther Verification, Internet of Things
| Corresponding Author | How to Cite this Article | To Browse |
|---|---|---|
| , Department of Computer Science and Engineering, Netaji Subhas University of Technology, Dwarka, New Delhi, India. Email: |
Singh A, LightSecurePUF: A Lightweight PUF-Based Mutual Authentication and Session Key Establishment Protocol for Secure UAV-Ground Station Communications. Int J Engg Mgmt Res. 2026;16(3):101-112. Available From https://ijemr.vandanapublications.com/index.php/j/article/view/1930 |


© 