PUG: A PUF-Anchored Unified Group Key Management Protocol for Internet of Drones
Tajdid Ul Alam, Mohamed YounisDrone swarms operate collaboratively and serve critical missions, which require a common session encryption key to secure exchanged data. This key must be updated when new drones join—or existing ones depart—the swarm. Classical key management protocols force a trade-off between multi-message re-key chains and high broadcast cost, and they often degrade under packet loss and jamming. This paper presents PUG, a physically unclonable function (PUF)-anchored unified group key management protocol for the Internet of Drones that completes every membership event—join, leave, eviction, or re-key—with a single self-contained authenticated broadcast. The group controller encrypts the new session key separately for each drone under secrets derived from their PUFs. The controller then treats each node-specific ciphertext as a Chinese Remainder Theorem residue under a prime modulus that is node- and time-specific and derived from the PUF response. Solving this system of congruences yields a group lock, which is broadcast to all members in one message. Long-term private key material is never written to the drone’s nonvolatile memory, and a captured node is evicted from the group to keep future communication secured within the group and to prevent durable secrets that could be used to recover past group traffic. Membership update ensures forward and backward secrecy at epoch granularity. The simulation results show that our protocol is effective across various loss rates, maintains the largest share of the swarm keyed under sustained jamming, and imposes limited control traffic while being efficient in terms of communication and computation overheads.