Cryptanalysis of the PUF-Enabled UAV-Ground Station and UAV-UAV Authentication Mechanism
摘要
Recently, Karmakar et al. designed a mutual authentication and key agreement mechanism for an unmanned aerial vehicle (UAV) and the ground station. They claimed that their mechanism is resilient against common security threats. However, our analysis reveals that their mechanism fails to resist eavesdropping attack and ephemeral secret leakage attack. Moreover, this mechanism further becomes vulnerable to the impersonation attack when the ephemeral secret is leaked. Specifically, an adversary can obtain the session key established in the current session in the event that an ephemeral secret is leaked. After identifying the root causes of these vulnerabilities, we propose targeted countermeasures to strengthen protocol security.