TELK OMNIKA T elecommunication, Computing, Electr onics and Contr ol V ol. 24, No. 3, June 2026, pp. 991 1002 ISSN: 1693-6930, DOI: 10.12928/TELK OMNIKA.v24i3.27677 991 A r ob ust blind signcryption scheme f or secur e inter net of dr ones communication T ahri Rachid 1 , Abdellah Ouammou 1 , Abdellatif Lasbahani 2 , Hibat Eallah Mohtadi 1 1 F aculty of Sciences and T echnologies, Hassan First Uni v ersity , Settat, Morocco 2 F aculty of Sciences and T echnologies, Sultan Moulay Slimane Uni v ersity , Beni Mellal, Morocco Article Inf o Article history: Recei v ed No v 18, 2025 Re vised Mar 3, 2026 Accepted Mar 29, 2026 K eyw ords: F ormal v erication Hyper -elliptic curv e cryptograph y Identity-based cryptograph y Internet of drones Lightweight cryptograph y Pri v ac y preserv ation Secure communication ABSTRA CT The rapid deplo yment of the internet of drones (IoD) e xposes aerial netw orks to authentication f ailures, ea v esdropping, data theft, and impersonation attacks due to open wireless communication. This paper presents a lightweight identity- based bl ind signcryption scheme for secure IoD communication. The scheme le v erages h yper -elliptic curv e cryptograph y to pro vide strong security with reduced computational o v erhead, making it suitable for resource-constrained drones. The blind signcryption mechanism enhances pri v ac y by pre v ent ing the signer from accessing message content . Informal analysis sho ws that the scheme achie v es condentiality , authentication, anon ymit y , forw ard secrec y , and resis- tance to common protocol-le v el attacks. F ormal v eri cation using the Sc yther tool conrms secrec y , agreement, and authentication properties under a stan- dard symbolic adv ersary model. Analytical and simulation-based e v aluations demonstrate a v erage reductions of 59.60% in computational cost, 48.86% in communication o v erhead, and 55.75% in ener gy consumption compared with e xisting schemes. While the res ults conrm protocol-le v el ef cienc y , real-w orld implementation and testbed v alidation remain future w ork. This is an open access article under the CC BY -SA license . Corresponding A uthor: T ahri Rachid F aculty of Sciences and T echnologies, Hassan First Uni v ersity Km 3, B.P . 577 Route de Casablanca, Settat, Morocco Email: rachid.tahritr@gmail.com 1. INTR ODUCTION The internet of drones (IoD) interconnects unmanned aerial v ehicles (U A Vs) to support c oo r dinated operations and real-time data e xchange across di v erse application domains [1], [2]. In IoD en vironments, drones communicate with neighbori ng U A Vs, ground stations, and e xternal IoT infrastructures through hetero- geneous wireless technologies such as wireless delity (W i-Fi), cellular netw orks (e.g., fourth/fth generation (4G/5G)), and U A V -to-U A V links. As illustrated in Figure 1, a typical IoD architecture comprises drone, com- munication, and application layers, enabling scalable and interoperable system operation [3]. This architecture supports latenc y-sensiti v e services, including disaster response and surv eillance, as well as data-intensi v e ap- plications such as real-time video transmission for logistics and en vironmental monitoring [4]. Despite these adv antages, the open and dynamic nature of IoD communications introduces si gnicant security risks. W ireless broadcast channels e xpose systems to ea v esdropping, impersonat ion, replay attacks, and unauthorized command injection [5]. W eak authentication may enable session hijacking and malicious U A V control, while insuf cient condentiality can compromise sensiti v e mission data [6], [7]. Con v entional J ournal homepage: https://telk omnika.uad.ac.id/inde x.php/TELK OMNIKA Evaluation Warning : The document was created with Spire.PDF for Python.
992 ISSN: 1693-6930 approaches rely on separate signature and encryption mechanisms, which increase computational and commu- nication o v erhead and are often unsuitable for resource-constrained U A V platforms. Figure 1. T ypical architecture of the IoD Signcryption inte grates encryption and digital signature into a single operation, reducing o v erhead while preserving essent ial security properties [8]-[10]. Identity-based cryptograph y (IBC) further simplies k e y management by deri ving public k e ys from unique identiers, eliminating certicate infrastructure [11]. Blind signcryption enhances pri v ac y by pre v enting the signer from accessing message content during the sign- ing process [12], [13]. T o meet IoD resource constraints, h yper -elliptic curv e cryptograph y (HECC) of fers reduced k e y sizes and lo wer computational comple xit y compared with con v entional ell iptic curv e schemes under equi v alent security assumptions [14]-[16]. Moti v ated by these challenges, this paper proposes an identity-based blind signcryption scheme for secure IoD communication. The main contrib utions are summarized as: - A lightweight identity-based blind signcryption scheme based on h yper -elliptic curv e cryptograph y for secure and pri v ac y-a w are IoD communication. - Inte grated authentication and condentiality with pri v ac y preserv ation, forw ard secrec y , and resistance to impersonation, replay , Sybil, denial-of-service (DoS), and man-in-the-middle (MiTM) attacks under standard adv ersary assumptions. - Comprehensi v e security e v aluation through informal analysis and formal symbolic v erication. - Performance assessment demonstrat ing reduced computational cost, communication o v erhead, and ener gy consumption compared with representati v e state-of-the-art schemes under unied analytical assumptions. 2. RELA TED W ORK Signcryption has been e xtensi v ely studi ed as an ef cient mechanism for securing communications in U A V netw orks and IoD en vironm ents. By inte grating digital signature and encryption into a single operation, signcryption reduces computational and communication o v erhead while preserving condentialit y , inte grity , and authentication. Certicateless and elliptic curv e cryptograph y (ECC)-based signcryption schemes ha v e been widely e xplored. Y u and W ang [17] proposed a certicateless blind signcryption scheme with reduced computational comple xity; ho we v er , replay and Sybil attack mitig ation are not e xplicitly addressed. Da et al. [18] introduced a TELK OMNIKA T elecommun Comput El Control, V ol. 24, No. 3, June 2026: 991–1002 Evaluation Warning : The document was created with Spire.PDF for Python.
TELK OMNIKA T elecommun Comput El Control 993 certicateless scheme for U A V cluster netw orks that ensures authentication and replay resistance, though with relati v ely high o v erhead and without automated formal v erication. Similarly , Y ang et al. [19] presented a het- erogeneous signcryption scheme supporting multi-cipherte xt equality testing, while Ullah et al. [20] proposed a generalized ring signcryption scheme pro viding anon ymity and traceability . Despite enhanced functional- ity , these ECC-based approaches often incur increased computational cost or lack comprehensi v e protection ag ainst replay and Sybil attacks. P airing-based constructions ha v e also been in v estig ated to strengthen security guarantees. Qu and Zeng [21] de v eloped a certicateless proxy signcryption scheme in the standard model with resistance to re- play and man-in-the-middle attacks; ho we v er , bilinear pairings signicantly increase computational and ener gy consumption. Hundera et al. [22] proposed an online/of ine heterogeneous proxy signcryption scheme to re- duce online o v erhead, though forw ard secrec y is not fully ensured. T o impro v e ef cienc y , lightweight designs ha v e been proposed. Khan et al. [23] introduced a certicate- based ring signcryption scheme using HECC, achie ving impro v ed ef cienc y and replay resistance. V erma et al. [24] proposed a signcryption-based data aggre g ation scheme with batch v erication, though it remains vulnerable to denial-of-service attacks. Other aggre g ate and heterogeneous approaches [25]-[27] focus on ef - cienc y and authentication b ut often lack anon ymity guarantees or comprehensi v e formal v alidation. More recently , identity-based and online/of ine signcryption schemes ha v e aimed to simplify k e y management and reduce o v erhead. Ali et al. [28] presented an identity-based online/of ine scheme for U A V -to- ground communication with formal security analysis under the random oracle model. Zou et al. [29] proposed a certicateless aggre g ated signcryption scheme for edge-assisted aerial and v ehicular netw orks, achie ving authentication and ef cienc y b ut still relying on elliptic curv e operations with non-ne gligible resource con- sumption. Recent surv e ys emphasize that most e xisting IoD signcryption schemes focus primarily on prot ocol- le v el security and analytical e v aluation [30]. Implementation-le v el threats including side-channel leakage, ph ysical capture, weak randomness, and hardw are-induced vulnerabilities are typically outs ide the scope of symbolic v erication tools [31], [32]. These limitations moti v ate t he proposed identity-based blind signcryp- tion scheme, which combines lightweight HECC-based design, form al symbolic v erication, and consideration of implementation-oriented security aspects for resource-constrained IoD en vironments. 3. NETW ORK MODEL The proposed architecture consists of three entities: drones, a k e y generation center (KGC), and a ground station (GS), as illustrated in Figure 2. These entities enable secure and pri v ac y-a w are communication in IoD en vironments under resource and mobility constraints. Drones operate across dif ferent re gions to per form sensing and monitoring tasks. The y c o m municate with neighboring U A Vs via short-range drone-to-drone (D2D) links (e.g., mesh or W i-Fi) and with the GS through medium- or long-range wi reless technologies such as 4G/5G. This h ybrid connecti vity supports local coordination and reliable data deli v ery . The GS serv es as a g ate w ay between drones and the control infrastructure. It recei v es signcrypted messages, v eries their authenticity , decrypts v alid cipherte xts, and forw ards v eried data to upper -layer appli- cations. T o enhance pri v ac y , drones interact with the GS using pseudo-identities rather than real identities. The KGC is a trusted-b ut-curious authority responsible for identity-based k e y generation. During initialization, drones and the GS submit pseudo-identities to the KGC, which generates and securely distrib utes corresponding pri v ate k e ys. Although trusted to e x ecute k e y generation correctly , the KGC does not access plainte xt messages. In the blind signcryption process, it operates only on blinded v alues and cannot link signatures to specic communications. When transmitting sensiti v e data, a drone performs blind signcryption by generating a signature with its identity-based pri v ate k e y and encrypting the message using a session k e y deri v ed from the GS’ s public pa- rameters. Upon reception, the GS e x ecutes unsigncryption, v erifying authenticity before decrypting the cipher - te xt. This design ensures authenticated and pri v ac y - preserving communication under the assumed adv ersarial model. A r ob ust blind signcryption sc heme for secur e internet of dr ones communication (T ahri Rac hid) Evaluation Warning : The document was created with Spire.PDF for Python.
994 ISSN: 1693-6930 Figure 2. Flo w of the proposed scheme 4. CONSTR UCTION OF THE PR OPOSED SCHEME This section presents the proposed identity-based blind signcryption scheme under standard crypto- graphic assumptions and a protocol-le v el adv ersary model. The adopted notation is summarized in T able 1. T able 1. Symbols used in the proposed scheme Symbol Explanation Symbol Explanation M p v K GC Master pri v ate k e y of the KGC M p b K GC Master public k e y of the KGC P id entity Pseudo-identity α entity Pri v ate k e y β entity Public k e y B F Blinding f actor δ Blind signature k Ephemeral pri v ate k e y n Nonce C Cipherte xt S h Shared secret sk Session k e y 5. INFORMAL SECURITY AN AL YSIS This section analyzes the security of the proposed identity-based blind signcryption scheme under a protocol-le v el adv ersary model. The analysis assumes standard cryptographic hardness (HECDLP) and secure k e y initialization. A comparison with representati v e schemes is summarized in T able 2. - Authentication: is ensured by v erifying the blind signature δ and response v alue R . V alidi ty of δ conrms KGC authorization, while R requires kno wledge of the drone’ s pri v ate k e y α dr one . F or gery is computation- ally infeasible under the HECDLP assumption. - Condentiality: messages are encrypted using a session k e y sk deri v ed from the shared secret S h . W ithout the corresponding ephemeral pri v ate k e ys, an adv ersary cannot reco v er sk . - Inte grity: is guaranteed through hash functions H 1 , H 2 , and H 3 , as an y modication alters v erication v alues and leads to rejection. - Anon ymity and pri v ac y preserv ation: ps eudo-identities P id entity conceal real identities, while blind sign- cryption pre v ents the KGC from accessing message content or linking signatures to specic sessions. - F orw ard secrec y: fresh ephemeral k e ys are generated for each session; compromise of long-term k e ys does not re v eal pre viously established session k e ys. - Replay and impersonation mitig ation: the nonce n ensures freshness and pre v ents replay . Impersonation is infeasible without the KGC master k e y or the drone’ s pri v ate k e y . - Sybil-attack mitig ation: pseudo-identities are issued and controlled by the KGC, pre v enting arbitrary identity generation. TELK OMNIKA T elecommun Comput El Control, V ol. 24, No. 3, June 2026: 991–1002 Evaluation Warning : The document was created with Spire.PDF for Python.
TELK OMNIKA T elecommun Comput El Control 995 - DoS mitig ation: the GS v eries δ and R prior to decryption, enabling early rejection of in v alid messages and reducing resource e xhaustion. - Collision resistance: collision-resistant hash functions pre v ent adv ersaries from generating distinct inputs with identical hash outputs. - Node-capture considerations: ephemeral k e y usage limits e xposure of past sessions in case of de vice com- promise; ho we v er , ph ysical capture and side-channel threats remain outside the protocol-le v el model. - MiTM mitig ation: authenticated k e y establishment and signature v erication pre v ent message alteration or injection without le gitimate pri v ate k e ys. T able 2. Comparati v e security analysis of e xisting schemes and the proposed approach Scheme F1 F2 F3 F4 F5 F6 F7 F8 F9 F10 F11 F12 F13 F14 F15 [17] Y Y Y Y Y N Y N N Y Y Y Y Y N [19] Y Y Y N N N Y N N Y Y Y Y Y N [21] Y Y Y N N Y Y N N Y N N N Y N [23] Y Y Y Y N Y Y N Y Y Y Y N Y N [26] Y Y Y N N Y Y Y Y Y Y N Y Y N Proposed Y Y Y Y Y Y Y Y Y Y Y Y Y Y Y F1 : Authentication F9 : Sybil-attack mitig ation F2 : Condentiality F10 : Impersonation-attack mitig ation F3 : Inte grity F11 : Collision-attack resistance F4 : Anon ymity F12 : Node-capture resilience F5 : Pri v ac y preserv ation F13 : F orw ard secrec y F6 : Replay-attack mitig ation F14 : Man-in-the-middle (MiTM) mitig ation F7 : Ea v esdropping resilience F15 : F ormal security v erication using automated tools F8 : DoS-attack mitig ation Y : Y es N : No 5.1. P arameter rationale The adopted parameters follo w prior lightweight internet of things (IoT) and HECC-based s ecurity schemes to ensure f air comparison. Genus-2 h yper -elliptic curv es balance ef cienc y and security , while SHA- 3 with domain separation mitig ates cross-protocol collisions. Message size and security-le v el mappings are selected for relati v e benchmarking under unied analytical assumpt ions rather t han absolute depl o yment guar - antees. 6. PERFORMANCE AN AL YSIS This section e v aluates the proposed identity-based blind signcryption scheme through c omparati v e analysis with representat i v e approaches, focusing on computational and communicati on costs, which are crit- ical in resource-constrained IoD en vironments. The e v aluation follo ws standard analytical modeling and benchmark-based measurements under uni ed assumptions. The reported results reect protocol-le v el ef - cienc y . Hardw are-specic latenc y , wireless channel v ariability , and battery dischar ge beha vior are not directly measured and remain topics for future e xperimental v alidation. 6.1. Computational cost Computational cost represents the total e x ecution time of dominant cryptographic operations during signcryption and unsigncryption. Lightweight operations (e.g., has hing and concatenation) are ne glected, con- sistent with prior comparati v e studies. The considered operations include bilinear pairing ( β P ), pairing multiplication ( p m ), elliptic-curv e scalar multiplication ( εC m ), and h yper -elliptic curv e di visor multiplication ( hεD m ). Their a v erage e x ecution times are summarized in T able 3, based on benchmarks reported in [23], [27]. All simulations were conducted using an Intel Core i7-6700 @ 3.40 GHz with 8 GB RAM under Ub untu 16.04 using the MIRA CL cryptographic library . This conguration serv es solely as a consistent base- line for comparison and does not represent a specic IoD deplo yment. Benchmarking scope: t he ti ming v alues adopted from [23], [27]. ensure consistenc y with prior studies. Results should therefore be interpre ted as relati v e analytical comparisons rather than absolute performance guarantees for real-w orld drone hardw are. A r ob ust blind signcryption sc heme for secur e internet of dr ones communication (T ahri Rac hid) Evaluation Warning : The document was created with Spire.PDF for Python.
996 ISSN: 1693-6930 T able 3. Single operation time consumption (milliseconds) Operation β P p m εC m hεD m T ime (ms) 4.669 0.788 0.341 0.1705 T ables 4 and 5 present the number of cryptographic operations and the corresponding total e x ecution time for each scheme. As illustrated in Figure 3, the proposed scheme achie v es the lo west computational cost under the adopted benchmark assumptions. T able 4. Computational cost in terms of operations used Schemes Signcryption Unsigncryption T otal [17] 5 εC m 2 εC m 7 εC m [19] 3 εC m 2 εC m 5 εC m [21] 6 p m 3 β P + 5 p m 3 β P + 11 p m [23] 3 εC m 1 εC m 4 εC m [26] 3 εC m 2 εC m 5 εC m Proposed 4 hεD m 1 hεD m 5 hεD m T able 5. Computational cost comparison in milliseconds Schemes Signcryption Unsigncryption T otal [17] 1.705 0.682 2.387 [19] 1.023 0.682 1.705 [21] 4.728 17.947 22.675 [23] 1.023 0.341 1.364 [26] 1.023 0.682 1.705 Proposed 0.682 0.1705 0.8525 Figure 3. Computational cost comparison among e xisting and proposed schemes Using the standard reduction metric Reduction (%) = Existing Proposed Existing × 100 , the proposed scheme achie v es computational cost reductions of 64.28%, 49.99%, 96.24%, 37.51%, and 50% compared with [17], [19], [21], [23], [26], respecti v ely , with an a v erage impro v ement of 59.60%. 6.2. Communication cost Communication cost is dened as the total number of transmitted bits. Consistent with prior studies, | G | = 1024 bits, | E | = 160 bits, | n | = 80 bits, and the message size | m | = 1000 bits. T able 6 and Figure 4 summarize the communication o v erhead. The pairing-based scheme in [21] incurs the highest cost due to lar ge group elements, while ECC-based schemes [17], [19], [23], [26] e xhibit moderate o v erhead. The proposed HECC-based design achie v es the lo west communication cost o wing to shorter di visor representations. Compared with [17], [19], [21], [23], [26], the proposed approach reduces communication cost by 63.74%, 52.86%, 81.52%, 19.51%, and 26.67%, respecti v ely , with an a v erage reduction of 48.86%. TELK OMNIKA T elecommun Comput El Control, V ol. 24, No. 3, June 2026: 991–1002 Evaluation Warning : The document was created with Spire.PDF for Python.
TELK OMNIKA T elecommun Comput El Control 997 T able 6. Communication cost comparison Schemes Expression Bits [17] 3 | m | + 4 | E | 3640 [19] 2 | m | + 5 | E | 2800 [21] | m | + 6 | G | 7144 [23] | m | + 4 | E | 1640 [26] | m | + 5 | E | 1800 Proposed | m | + 4 | n | 1320 Figure 4. Communication cost comparison among e xisting and proposed schemes 7. FORMAL SECURITY V ALID A TION This section presents the formal v alidation of the proposed identity-based blind signcryption scheme using the Sc yther v erication tool [32]. The objecti v e is to v erify the logical correctness of the protocol under a standard symbolic adv ersary model rather than to claim implementation-le v el security . Sc yther operates under the Dole v–Y ao assumption, where the adv ersary has full control o v er the com- munication channel b ut cannot break cryptographic primiti v es. Accordingly , the analysis focuses on secrec y , authentication, agreement, and freshness properties at the protocol le v el. The protocol is specied in security protocol description language (SPDL), where roles, m essage o ws, cryptographic operations, and security cla ims are e xplicitly modeled. The adv ersary is assumed capable of intercepting, modifying, replaying, and injecting messages, while cryptographic primiti v es are treated as ideal. This automated analysis complements the informal e v aluation by v erifying protocol correctness within the symbolic frame w ork. 7.1. V eried security claims The follo wing standard Sc yther claims were specied to assess secrec y and authentication guarantees: - Secrec y: ensures that condential protocol elements, including session k e ys and transmitted messages, are not disclosed to the adv ersary . - Ali v eness: conrms that a protocol participant completes a run with an acti v e peer . - W eak agreement (weak-agree): ensures that communicating entities agree on the occurrence of a protocol run and share at least one common v alue. - Non-injecti v e agreement (Ni-agree): strengthens authentication by ensuring mutual agreement on e xchanged data v alues. - Non-injecti v e synchronization (Ni-synch): v eries c o r rect message orderi ng and freshness, contrib uting to replay-attack resistance. A r ob ust blind signcryption sc heme for secur e internet of dr ones communication (T ahri Rac hid) Evaluation Warning : The document was created with Spire.PDF for Python.
998 ISSN: 1693-6930 7.2. V erication r esults The protocol roles, parameters, and v erication settings used in the Sc yther en vironment are il lustrated in Figure 5, and the corresponding v erication outcomes are sho wn in Figure 6. The analysis reports no attack traces for an y of the specied security claims. These results indicate that the proposed protocol satises secrec y , authentication, agreement, and freshness properties within the Sc yther symbolic model. Accordingly , the scheme is formally v alidated ag ainst protocol-le v el attacks such as replay , impersonation, and man-in-the-middle attacks under the assumed v eri- cation scope. Figure 5. Simulation parameters used for Sc yther v erication Figure 6. V erication results sho wing successful v alidation of all security claims 7.3. Discussion on implementation-le v el security While the formal v alidation conrms protocol correctness, implementation-le v el threats such as side- channel leakage, f ault injection, weak random number generation, and ph ysic al de vice capture remain outside the scope of symbolic v erication tools. In practical deplo yments, these risks ca n be mitig ated through constant-time cryptographic imple- mentations, hardw are-assisted k e y storage (e.g., secure elements or trusted e x ecution en vironments), secure boot mechanisms, and side-channel e v aluation tools such as ChipWhisperer or test v ector leakage assessment (TVLA). Hardw are-le v el protections ag ainst tampering and f ault-based attacks remain important directions for future e xperimental studies. TELK OMNIKA T elecommun Comput El Control, V ol. 24, No. 3, June 2026: 991–1002 Evaluation Warning : The document was created with Spire.PDF for Python.
TELK OMNIKA T elecommun Comput El Control 999 8. DISCUSSION Although the proposed scheme pro vides strong protocol-le v el security guarantee s, se v eral practi cal challenges must be considered before real-w orld deplo yment in IoD en vironments. These limitations stem from architectural assumptions and implementation constraints and moti v ate further research to w ard scalable inte gration. - Centralized KGC architecture: dependence on a centralized KGC may create scalabil ity bottlenecks and a potential single point of f ailure in lar ge-scale or sw arm-based IoD deplo yments. - Interoperability constraints: compatibility with e xisting IoD protocols such as MA VLink and unmanned aerial v ehicle controller area netw ork (U A VCAN) has not been e xp e rimentally v alidated, and inte gration with platforms such as PX4 and ArduPilot remains an open challenge. - Post-quantum r eadiness: the scheme relies on classical cryptographic assumptions and does not incorporate post-quantum primiti v es or e xplicitly model emer ging 5G/B5G communication en vironments. - Implementation-le v el vulnerabilities: as discussed in section 7. Side-channel leakage, f ault injection, weak randomness, and ph ysical de vice capture are be yond the scope of the current protocol-le v el analysis. - Mobility-induced o v erhead: frequent drone mobility and zone transitions may require repeated authentication and k e y updates, potentially af fecting communication continuity . - Netw ork-induced latenc y v ariability: wireless interference, congestion, and dynamic topology changes in- troduce latenc y v ariations that are not fully captured by analytical cryptographic e v aluation. T o address these limitations, se v eral research directions are identied: - De v eloping distrib uted or hierarchical KGC architectures based on threshold cryptograph y to impro v e scal- ability and f ault tolerance. - Designing middle w are adapters to inte grate blind signcryption with MA VLink and U A VCAN message for - mats for seamless deplo yment on e xisting drone platforms. - In v estig ating h ybrid post-quantum e xtensions and e v aluating performance on ph ysical testbeds under realistic mobility , interference, and side-channel conditions. - Incorporating hardw are-assisted protection mechanisms (e.g., secure elements or trusted e x ecution en viron- ments) within resource-a w are security architectures aligned with emer ging standards. - Exploring quality-of-service–a w are scheduling, edge-assisted pre-computation, and dele g ated zone-based authentication to reduce re-authentication latenc y . Addressing these challenges wil l f acilitate the transition of the proposed sche me from a protocol-le v el construct to a scalable and deplo yment-ready security frame w ork for future lar ge-scale autonomous aerial netw orks. 9. CONCLUSION This paper addressed security and ef cienc y challenges in IoD communications by proposing a light- weight identity-based blind signcryption scheme for resource-constrained aerial en vironments. By inte grating encryption and digital signature into a unied operation, the scheme reduces computational and communication o v erhead while preserving essential security properties. The incorporated blinding mechanism further enhances pri v ac y by pre v enting the signing authority from accessing message contents or linking protocol e x ecutions. Informal analysis conrmed support for authentication, condentiality , inte grity , anon ymity , pri v ac y preserv ation, and resistance to common protocol-le v el attacks. F ormal v alidation using the Sc yther tool v eri- ed secrec y , agreement, and freshness properties under a symbolic adv ersary model. Performance e v aluation demonstrated signicant reductions in computational cost, communication o v erhead, and ener gy consumption compared with representati v e state-of-the-art schemes. Ov erall, the proposed design pro vides an ef cient and pri v ac y-a w are security frame w ork suitable for IoD en vironments with strict resource constraints. Future w ork will focus on hardw are-le v el implementation and lar ge-scale sw arm v alidation to further assess deplo yment feasibility . FUNDING INFORMA TION The authors declare that no funding w as recei v ed to support this research. A r ob ust blind signcryption sc heme for secur e internet of dr ones communication (T ahri Rac hid) Evaluation Warning : The document was created with Spire.PDF for Python.
1000 ISSN: 1693-6930 A UTHOR CONTRIB UTIONS ST A TEMENT This journal uses the Cont rib utor Roles T axonomy (CRediT) to recognize indi vidual author contrib u- tions, reduce authorship disputes, and f acilitate collaboration. Name of A uthor C M So V a F o I R D O E V i Su P Fu T ahri Rachid Abdellah Ouammou Abdellatif Lasbahani Hibat Eallah Mohtadi C : C onceptualization I : I n v estig ation V i : V i sualization M : M ethodology R : R esources Su : Su pervision So : So ftw are D : D ata Curation P : P roject Administration V a : V a lidation O : Writing - O riginal Draft Fu : Fu nding Acquisition F o : F o rmal Analysis E : Writing - Re vie w & E diting CONFLICT OF INTEREST ST A TEMENT The authors declare that the y ha v e no kno wn competing nancial interests or personal rela tionships that could ha v e appeared to inuence the w ork reported in this paper . Authors state no conict of interest. D A T A A V AILABILITY The data that support the ndings of this study are a v ailable from the corresponding author , R T , upon reasonable request. REFERENCES [1] A. Derhab et al. , “Internet of drones security: T axonomies, open issues, and future directions, V ehicular Communications , v ol. 39, p. 100552, Feb . 2023, doi: 10.1016/j.v ehcom.2022.100552. [2] W . Y ang, S. W ang, X. Y in, X. W ang, and J. Hu, A Re vie w on Security Issues and Solutions of the Internet of Drones, IEEE Open J ournal of the Computer Society , v ol. 3, pp. 96–110, 2022, doi: 10.1109/OJCS.2022.3183003. [3] D. Mandloi, R. Arya, and A. K. V erma, “Internet of Drones, in Recent T r ends in Articial Intellig ence T owar ds a Smart W orld, Spring er , 2024, pp. 353–373. doi: 10.1007/978-981-97-6790-8 13. [4] J . B. R. Rose, T . Arulmozhinathan, V . T . Gopinathan, and J. V . B. Benif a, “Internet of Drones: Applications, Challenges, Opportu- nities, in Internet of Dr ones, Boca Raton: CRC Pr ess , 2023, pp. 1–18. doi: 10.1201/9781003252085-1. [5] L. Ab ualig ah, A. Diabat, P . Sumari, and A. H. Gandomi, Applications, Deplo yments, and Inte gration of Internet of Drones (IoD): A Re vie w , IEEE Sensor s J ournal , v ol. 21, no. 22, pp. 25532–25546, No v . 2021, doi: 10.1109/JSEN.2021.3114266. [6] A. F . Aldweesh and A. M. Almuhaideb, Authentication T echniques in Internet of Drones (IoD): T axonomy , Open Challenges and Future Directions, J ournal of Sensor and Actuator Networks , v ol. 14, no. 3, p. 57, May 2025, doi: 10.3390/jsan14030057. [7] S . Sciancalepore, “Pri v ac y and Condentiality Issues in Drone Operations: Challenges and Road Ahead, IEEE Network , v ol. 38, no. 6, pp. 227–233, No v . 2024, doi: 10.1109/MNET .2024.3432730. [8] Y . Zheng, “Digital signcryption or ho w to achie v e cost(Signature &: Encryption) ¡¡ cost(signature) + cost(encryption), in Lectur e Notes in Computer Science (including subseries Lectur e Notes in Articial Intellig ence and Lectur e Notes in Bioinformatics) , v ol. 1294, 1997, pp. 165–179. doi: 10.1007/BFb0052234. [9] A. Shamir , “Identity-Based Cryptosystems and Signature Schemes, in Advances in Cryptolo gy , Berlin, Heidelber g: Spring er Berlin Heidelber g , pp. 47–53. doi: 10.1007/3-540-39568-7 5. [10] S. Ullah and N. Din, “Blind signcryption scheme based on h yper elliptic curv es cryptosystem, P eer -to-P eer Network ing and Appli- cations , v ol. 14, no. 2, pp. 917–932, Mar . 2021, doi: 10.1007/s12083-020-01044-8. [11] B . Hassan et al. , A Cos t Ef fecti v e Identity-Based Authentication Scheme for Internet of Things-Enabl ed Agriculture, W ir eless Communications and Mobile Computing , v ol. 2022, no. 1, Jan. 2022, doi: 10.1155/2022/4275243. [12] Z. Jamroz et al. , An Optimal Authentication Scheme through Dual Signat ure for the Internet of Medical Things, Futur e Internet , v ol. 15, no. 8, p. 258, Jul. 2023, doi: 10.3390/15080258. [13] D. Cha um, “Blind Signatures for Untraceable P ayments, in Advances in Cryptolo gy , Boston, MA: Springer US, 1983, pp. 199–203. doi: 10.1007/978-1-4757-0602-4 18. [14] N. K oblitz, “Hyperelliptic cryptosystems, J ournal of Cryptolo gy , v ol. 1, no. 3, pp. 139–150, Oct. 1989, doi: 10.1007/BF02252872. [15] M . A. Khan et al. , An Impro vised Certicate-Based Proxy Signature Using Hyperelliptic Curv e Cryptograph y for Secure U A V Communications, IEEE T r ansactions on Intellig ent T r ansportation Systems , v ol. 26, no. 4, pp. 5264–5275, Apr . 2025, doi: 10.1109/TITS.2024.3524575. [16] I. Ullah et al. , A Multi-Message Multi-Recei v er Signcryption Scheme with Edge Computing for Secure and Reliable W ireless Internet of Medical Things Communications, Sustainability , v ol. 13, no. 23, p. 13184, No v . 2021, doi: 10.3390/su132313184. TELK OMNIKA T elecommun Comput El Control, V ol. 24, No. 3, June 2026: 991–1002 Evaluation Warning : The document was created with Spire.PDF for Python.