TELK
OMNIKA
T
elecommunication,
Computing,
Electr
onics
and
Contr
ol
V
ol.
24,
No.
3,
June
2026,
pp.
991
∼
1002
ISSN:
1693-6930,
DOI:
10.12928/TELK
OMNIKA.v24i3.27677
❒
991
A
r
ob
ust
blind
signcryption
scheme
f
or
secur
e
inter
net
of
dr
ones
communication
T
ahri
Rachid
1
,
Abdellah
Ouammou
1
,
Abdellatif
Lasbahani
2
,
Hibat
Eallah
Mohtadi
1
1
F
aculty
of
Sciences
and
T
echnologies,
Hassan
First
Uni
v
ersity
,
Settat,
Morocco
2
F
aculty
of
Sciences
and
T
echnologies,
Sultan
Moulay
Slimane
Uni
v
ersity
,
Beni
Mellal,
Morocco
Article
Inf
o
Article
history:
Recei
v
ed
No
v
18,
2025
Re
vised
Mar
3,
2026
Accepted
Mar
29,
2026
K
eyw
ords:
F
ormal
v
erication
Hyper
-elliptic
curv
e
cryptograph
y
Identity-based
cryptograph
y
Internet
of
drones
Lightweight
cryptograph
y
Pri
v
ac
y
preserv
ation
Secure
communication
ABSTRA
CT
The
rapid
deplo
yment
of
the
internet
of
drones
(IoD)
e
xposes
aerial
netw
orks
to
authentication
f
ailures,
ea
v
esdropping,
data
theft,
and
impersonation
attacks
due
to
open
wireless
communication.
This
paper
presents
a
lightweight
identity-
based
bl
ind
signcryption
scheme
for
secure
IoD
communication.
The
scheme
le
v
erages
h
yper
-elliptic
curv
e
cryptograph
y
to
pro
vide
strong
security
with
reduced
computational
o
v
erhead,
making
it
suitable
for
resource-constrained
drones.
The
blind
signcryption
mechanism
enhances
pri
v
ac
y
by
pre
v
ent
ing
the
signer
from
accessing
message
content
.
Informal
analysis
sho
ws
that
the
scheme
achie
v
es
condentiality
,
authentication,
anon
ymit
y
,
forw
ard
secrec
y
,
and
resis-
tance
to
common
protocol-le
v
el
attacks.
F
ormal
v
eri
cation
using
the
Sc
yther
tool
conrms
secrec
y
,
agreement,
and
authentication
properties
under
a
stan-
dard
symbolic
adv
ersary
model.
Analytical
and
simulation-based
e
v
aluations
demonstrate
a
v
erage
reductions
of
59.60%
in
computational
cost,
48.86%
in
communication
o
v
erhead,
and
55.75%
in
ener
gy
consumption
compared
with
e
xisting
schemes.
While
the
res
ults
conrm
protocol-le
v
el
ef
cienc
y
,
real-w
orld
implementation
and
testbed
v
alidation
remain
future
w
ork.
This
is
an
open
access
article
under
the
CC
BY
-SA
license
.
Corresponding
A
uthor:
T
ahri
Rachid
F
aculty
of
Sciences
and
T
echnologies,
Hassan
First
Uni
v
ersity
Km
3,
B.P
.
577
Route
de
Casablanca,
Settat,
Morocco
Email:
rachid.tahritr@gmail.com
1.
INTR
ODUCTION
The
internet
of
drones
(IoD)
interconnects
unmanned
aerial
v
ehicles
(U
A
Vs)
to
support
c
oo
r
dinated
operations
and
real-time
data
e
xchange
across
di
v
erse
application
domains
[1],
[2].
In
IoD
en
vironments,
drones
communicate
with
neighbori
ng
U
A
Vs,
ground
stations,
and
e
xternal
IoT
infrastructures
through
hetero-
geneous
wireless
technologies
such
as
wireless
delity
(W
i-Fi),
cellular
netw
orks
(e.g.,
fourth/fth
generation
(4G/5G)),
and
U
A
V
-to-U
A
V
links.
As
illustrated
in
Figure
1,
a
typical
IoD
architecture
comprises
drone,
com-
munication,
and
application
layers,
enabling
scalable
and
interoperable
system
operation
[3].
This
architecture
supports
latenc
y-sensiti
v
e
services,
including
disaster
response
and
surv
eillance,
as
well
as
data-intensi
v
e
ap-
plications
such
as
real-time
video
transmission
for
logistics
and
en
vironmental
monitoring
[4].
Despite
these
adv
antages,
the
open
and
dynamic
nature
of
IoD
communications
introduces
si
gnicant
security
risks.
W
ireless
broadcast
channels
e
xpose
systems
to
ea
v
esdropping,
impersonat
ion,
replay
attacks,
and
unauthorized
command
injection
[5].
W
eak
authentication
may
enable
session
hijacking
and
malicious
U
A
V
control,
while
insuf
cient
condentiality
can
compromise
sensiti
v
e
mission
data
[6],
[7].
Con
v
entional
J
ournal
homepage:
https://telk
omnika.uad.ac.id/inde
x.php/TELK
OMNIKA
Evaluation Warning : The document was created with Spire.PDF for Python.
992
❒
ISSN:
1693-6930
approaches
rely
on
separate
signature
and
encryption
mechanisms,
which
increase
computational
and
commu-
nication
o
v
erhead
and
are
often
unsuitable
for
resource-constrained
U
A
V
platforms.
Figure
1.
T
ypical
architecture
of
the
IoD
Signcryption
inte
grates
encryption
and
digital
signature
into
a
single
operation,
reducing
o
v
erhead
while
preserving
essent
ial
security
properties
[8]-[10].
Identity-based
cryptograph
y
(IBC)
further
simplies
k
e
y
management
by
deri
ving
public
k
e
ys
from
unique
identiers,
eliminating
certicate
infrastructure
[11].
Blind
signcryption
enhances
pri
v
ac
y
by
pre
v
enting
the
signer
from
accessing
message
content
during
the
sign-
ing
process
[12],
[13].
T
o
meet
IoD
resource
constraints,
h
yper
-elliptic
curv
e
cryptograph
y
(HECC)
of
fers
reduced
k
e
y
sizes
and
lo
wer
computational
comple
xit
y
compared
with
con
v
entional
ell
iptic
curv
e
schemes
under
equi
v
alent
security
assumptions
[14]-[16].
Moti
v
ated
by
these
challenges,
this
paper
proposes
an
identity-based
blind
signcryption
scheme
for
secure
IoD
communication.
The
main
contrib
utions
are
summarized
as:
-
A
lightweight
identity-based
blind
signcryption
scheme
based
on
h
yper
-elliptic
curv
e
cryptograph
y
for
secure
and
pri
v
ac
y-a
w
are
IoD
communication.
-
Inte
grated
authentication
and
condentiality
with
pri
v
ac
y
preserv
ation,
forw
ard
secrec
y
,
and
resistance
to
impersonation,
replay
,
Sybil,
denial-of-service
(DoS),
and
man-in-the-middle
(MiTM)
attacks
under
standard
adv
ersary
assumptions.
-
Comprehensi
v
e
security
e
v
aluation
through
informal
analysis
and
formal
symbolic
v
erication.
-
Performance
assessment
demonstrat
ing
reduced
computational
cost,
communication
o
v
erhead,
and
ener
gy
consumption
compared
with
representati
v
e
state-of-the-art
schemes
under
unied
analytical
assumptions.
2.
RELA
TED
W
ORK
Signcryption
has
been
e
xtensi
v
ely
studi
ed
as
an
ef
cient
mechanism
for
securing
communications
in
U
A
V
netw
orks
and
IoD
en
vironm
ents.
By
inte
grating
digital
signature
and
encryption
into
a
single
operation,
signcryption
reduces
computational
and
communication
o
v
erhead
while
preserving
condentialit
y
,
inte
grity
,
and
authentication.
Certicateless
and
elliptic
curv
e
cryptograph
y
(ECC)-based
signcryption
schemes
ha
v
e
been
widely
e
xplored.
Y
u
and
W
ang
[17]
proposed
a
certicateless
blind
signcryption
scheme
with
reduced
computational
comple
xity;
ho
we
v
er
,
replay
and
Sybil
attack
mitig
ation
are
not
e
xplicitly
addressed.
Da
et
al.
[18]
introduced
a
TELK
OMNIKA
T
elecommun
Comput
El
Control,
V
ol.
24,
No.
3,
June
2026:
991–1002
Evaluation Warning : The document was created with Spire.PDF for Python.
TELK
OMNIKA
T
elecommun
Comput
El
Control
❒
993
certicateless
scheme
for
U
A
V
cluster
netw
orks
that
ensures
authentication
and
replay
resistance,
though
with
relati
v
ely
high
o
v
erhead
and
without
automated
formal
v
erication.
Similarly
,
Y
ang
et
al.
[19]
presented
a
het-
erogeneous
signcryption
scheme
supporting
multi-cipherte
xt
equality
testing,
while
Ullah
et
al.
[20]
proposed
a
generalized
ring
signcryption
scheme
pro
viding
anon
ymity
and
traceability
.
Despite
enhanced
functional-
ity
,
these
ECC-based
approaches
often
incur
increased
computational
cost
or
lack
comprehensi
v
e
protection
ag
ainst
replay
and
Sybil
attacks.
P
airing-based
constructions
ha
v
e
also
been
in
v
estig
ated
to
strengthen
security
guarantees.
Qu
and
Zeng
[21]
de
v
eloped
a
certicateless
proxy
signcryption
scheme
in
the
standard
model
with
resistance
to
re-
play
and
man-in-the-middle
attacks;
ho
we
v
er
,
bilinear
pairings
signicantly
increase
computational
and
ener
gy
consumption.
Hundera
et
al.
[22]
proposed
an
online/of
ine
heterogeneous
proxy
signcryption
scheme
to
re-
duce
online
o
v
erhead,
though
forw
ard
secrec
y
is
not
fully
ensured.
T
o
impro
v
e
ef
cienc
y
,
lightweight
designs
ha
v
e
been
proposed.
Khan
et
al.
[23]
introduced
a
certicate-
based
ring
signcryption
scheme
using
HECC,
achie
ving
impro
v
ed
ef
cienc
y
and
replay
resistance.
V
erma
et
al.
[24]
proposed
a
signcryption-based
data
aggre
g
ation
scheme
with
batch
v
erication,
though
it
remains
vulnerable
to
denial-of-service
attacks.
Other
aggre
g
ate
and
heterogeneous
approaches
[25]-[27]
focus
on
ef
-
cienc
y
and
authentication
b
ut
often
lack
anon
ymity
guarantees
or
comprehensi
v
e
formal
v
alidation.
More
recently
,
identity-based
and
online/of
ine
signcryption
schemes
ha
v
e
aimed
to
simplify
k
e
y
management
and
reduce
o
v
erhead.
Ali
et
al.
[28]
presented
an
identity-based
online/of
ine
scheme
for
U
A
V
-to-
ground
communication
with
formal
security
analysis
under
the
random
oracle
model.
Zou
et
al.
[29]
proposed
a
certicateless
aggre
g
ated
signcryption
scheme
for
edge-assisted
aerial
and
v
ehicular
netw
orks,
achie
ving
authentication
and
ef
cienc
y
b
ut
still
relying
on
elliptic
curv
e
operations
with
non-ne
gligible
resource
con-
sumption.
Recent
surv
e
ys
emphasize
that
most
e
xisting
IoD
signcryption
schemes
focus
primarily
on
prot
ocol-
le
v
el
security
and
analytical
e
v
aluation
[30].
Implementation-le
v
el
threats
including
side-channel
leakage,
ph
ysical
capture,
weak
randomness,
and
hardw
are-induced
vulnerabilities
are
typically
outs
ide
the
scope
of
symbolic
v
erication
tools
[31],
[32].
These
limitations
moti
v
ate
t
he
proposed
identity-based
blind
signcryp-
tion
scheme,
which
combines
lightweight
HECC-based
design,
form
al
symbolic
v
erication,
and
consideration
of
implementation-oriented
security
aspects
for
resource-constrained
IoD
en
vironments.
3.
NETW
ORK
MODEL
The
proposed
architecture
consists
of
three
entities:
drones,
a
k
e
y
generation
center
(KGC),
and
a
ground
station
(GS),
as
illustrated
in
Figure
2.
These
entities
enable
secure
and
pri
v
ac
y-a
w
are
communication
in
IoD
en
vironments
under
resource
and
mobility
constraints.
Drones
operate
across
dif
ferent
re
gions
to
per
form
sensing
and
monitoring
tasks.
The
y
c
o
m
municate
with
neighboring
U
A
Vs
via
short-range
drone-to-drone
(D2D)
links
(e.g.,
mesh
or
W
i-Fi)
and
with
the
GS
through
medium-
or
long-range
wi
reless
technologies
such
as
4G/5G.
This
h
ybrid
connecti
vity
supports
local
coordination
and
reliable
data
deli
v
ery
.
The
GS
serv
es
as
a
g
ate
w
ay
between
drones
and
the
control
infrastructure.
It
recei
v
es
signcrypted
messages,
v
eries
their
authenticity
,
decrypts
v
alid
cipherte
xts,
and
forw
ards
v
eried
data
to
upper
-layer
appli-
cations.
T
o
enhance
pri
v
ac
y
,
drones
interact
with
the
GS
using
pseudo-identities
rather
than
real
identities.
The
KGC
is
a
trusted-b
ut-curious
authority
responsible
for
identity-based
k
e
y
generation.
During
initialization,
drones
and
the
GS
submit
pseudo-identities
to
the
KGC,
which
generates
and
securely
distrib
utes
corresponding
pri
v
ate
k
e
ys.
Although
trusted
to
e
x
ecute
k
e
y
generation
correctly
,
the
KGC
does
not
access
plainte
xt
messages.
In
the
blind
signcryption
process,
it
operates
only
on
blinded
v
alues
and
cannot
link
signatures
to
specic
communications.
When
transmitting
sensiti
v
e
data,
a
drone
performs
blind
signcryption
by
generating
a
signature
with
its
identity-based
pri
v
ate
k
e
y
and
encrypting
the
message
using
a
session
k
e
y
deri
v
ed
from
the
GS’
s
public
pa-
rameters.
Upon
reception,
the
GS
e
x
ecutes
unsigncryption,
v
erifying
authenticity
before
decrypting
the
cipher
-
te
xt.
This
design
ensures
authenticated
and
pri
v
ac
y
-
preserving
communication
under
the
assumed
adv
ersarial
model.
A
r
ob
ust
blind
signcryption
sc
heme
for
secur
e
internet
of
dr
ones
communication
(T
ahri
Rac
hid)
Evaluation Warning : The document was created with Spire.PDF for Python.
994
❒
ISSN:
1693-6930
Figure
2.
Flo
w
of
the
proposed
scheme
4.
CONSTR
UCTION
OF
THE
PR
OPOSED
SCHEME
This
section
presents
the
proposed
identity-based
blind
signcryption
scheme
under
standard
crypto-
graphic
assumptions
and
a
protocol-le
v
el
adv
ersary
model.
The
adopted
notation
is
summarized
in
T
able
1.
T
able
1.
Symbols
used
in
the
proposed
scheme
Symbol
Explanation
Symbol
Explanation
M
p
v
K
GC
Master
pri
v
ate
k
e
y
of
the
KGC
M
p
b
K
GC
Master
public
k
e
y
of
the
KGC
P
id
entity
Pseudo-identity
α
entity
Pri
v
ate
k
e
y
β
entity
Public
k
e
y
B
F
Blinding
f
actor
δ
Blind
signature
k
Ephemeral
pri
v
ate
k
e
y
n
Nonce
C
Cipherte
xt
S
h
Shared
secret
sk
Session
k
e
y
5.
INFORMAL
SECURITY
AN
AL
YSIS
This
section
analyzes
the
security
of
the
proposed
identity-based
blind
signcryption
scheme
under
a
protocol-le
v
el
adv
ersary
model.
The
analysis
assumes
standard
cryptographic
hardness
(HECDLP)
and
secure
k
e
y
initialization.
A
comparison
with
representati
v
e
schemes
is
summarized
in
T
able
2.
-
Authentication:
is
ensured
by
v
erifying
the
blind
signature
δ
and
response
v
alue
R
.
V
alidi
ty
of
δ
conrms
KGC
authorization,
while
R
requires
kno
wledge
of
the
drone’
s
pri
v
ate
k
e
y
α
dr
one
.
F
or
gery
is
computation-
ally
infeasible
under
the
HECDLP
assumption.
-
Condentiality:
messages
are
encrypted
using
a
session
k
e
y
sk
deri
v
ed
from
the
shared
secret
S
h
.
W
ithout
the
corresponding
ephemeral
pri
v
ate
k
e
ys,
an
adv
ersary
cannot
reco
v
er
sk
.
-
Inte
grity:
is
guaranteed
through
hash
functions
H
1
,
H
2
,
and
H
3
,
as
an
y
modication
alters
v
erication
v
alues
and
leads
to
rejection.
-
Anon
ymity
and
pri
v
ac
y
preserv
ation:
ps
eudo-identities
P
id
entity
conceal
real
identities,
while
blind
sign-
cryption
pre
v
ents
the
KGC
from
accessing
message
content
or
linking
signatures
to
specic
sessions.
-
F
orw
ard
secrec
y:
fresh
ephemeral
k
e
ys
are
generated
for
each
session;
compromise
of
long-term
k
e
ys
does
not
re
v
eal
pre
viously
established
session
k
e
ys.
-
Replay
and
impersonation
mitig
ation:
the
nonce
n
ensures
freshness
and
pre
v
ents
replay
.
Impersonation
is
infeasible
without
the
KGC
master
k
e
y
or
the
drone’
s
pri
v
ate
k
e
y
.
-
Sybil-attack
mitig
ation:
pseudo-identities
are
issued
and
controlled
by
the
KGC,
pre
v
enting
arbitrary
identity
generation.
TELK
OMNIKA
T
elecommun
Comput
El
Control,
V
ol.
24,
No.
3,
June
2026:
991–1002
Evaluation Warning : The document was created with Spire.PDF for Python.
TELK
OMNIKA
T
elecommun
Comput
El
Control
❒
995
-
DoS
mitig
ation:
the
GS
v
eries
δ
and
R
prior
to
decryption,
enabling
early
rejection
of
in
v
alid
messages
and
reducing
resource
e
xhaustion.
-
Collision
resistance:
collision-resistant
hash
functions
pre
v
ent
adv
ersaries
from
generating
distinct
inputs
with
identical
hash
outputs.
-
Node-capture
considerations:
ephemeral
k
e
y
usage
limits
e
xposure
of
past
sessions
in
case
of
de
vice
com-
promise;
ho
we
v
er
,
ph
ysical
capture
and
side-channel
threats
remain
outside
the
protocol-le
v
el
model.
-
MiTM
mitig
ation:
authenticated
k
e
y
establishment
and
signature
v
erication
pre
v
ent
message
alteration
or
injection
without
le
gitimate
pri
v
ate
k
e
ys.
T
able
2.
Comparati
v
e
security
analysis
of
e
xisting
schemes
and
the
proposed
approach
Scheme
F1
F2
F3
F4
F5
F6
F7
F8
F9
F10
F11
F12
F13
F14
F15
[17]
Y
Y
Y
Y
Y
N
Y
N
N
Y
Y
Y
Y
Y
N
[19]
Y
Y
Y
N
N
N
Y
N
N
Y
Y
Y
Y
Y
N
[21]
Y
Y
Y
N
N
Y
Y
N
N
Y
N
N
N
Y
N
[23]
Y
Y
Y
Y
N
Y
Y
N
Y
Y
Y
Y
N
Y
N
[26]
Y
Y
Y
N
N
Y
Y
Y
Y
Y
Y
N
Y
Y
N
Proposed
Y
Y
Y
Y
Y
Y
Y
Y
Y
Y
Y
Y
Y
Y
Y
F1
:
Authentication
F9
:
Sybil-attack
mitig
ation
F2
:
Condentiality
F10
:
Impersonation-attack
mitig
ation
F3
:
Inte
grity
F11
:
Collision-attack
resistance
F4
:
Anon
ymity
F12
:
Node-capture
resilience
F5
:
Pri
v
ac
y
preserv
ation
F13
:
F
orw
ard
secrec
y
F6
:
Replay-attack
mitig
ation
F14
:
Man-in-the-middle
(MiTM)
mitig
ation
F7
:
Ea
v
esdropping
resilience
F15
:
F
ormal
security
v
erication
using
automated
tools
F8
:
DoS-attack
mitig
ation
Y
:
Y
es
N
:
No
5.1.
P
arameter
rationale
The
adopted
parameters
follo
w
prior
lightweight
internet
of
things
(IoT)
and
HECC-based
s
ecurity
schemes
to
ensure
f
air
comparison.
Genus-2
h
yper
-elliptic
curv
es
balance
ef
cienc
y
and
security
,
while
SHA-
3
with
domain
separation
mitig
ates
cross-protocol
collisions.
Message
size
and
security-le
v
el
mappings
are
selected
for
relati
v
e
benchmarking
under
unied
analytical
assumpt
ions
rather
t
han
absolute
depl
o
yment
guar
-
antees.
6.
PERFORMANCE
AN
AL
YSIS
This
section
e
v
aluates
the
proposed
identity-based
blind
signcryption
scheme
through
c
omparati
v
e
analysis
with
representat
i
v
e
approaches,
focusing
on
computational
and
communicati
on
costs,
which
are
crit-
ical
in
resource-constrained
IoD
en
vironments.
The
e
v
aluation
follo
ws
standard
analytical
modeling
and
benchmark-based
measurements
under
uni
ed
assumptions.
The
reported
results
reect
protocol-le
v
el
ef
-
cienc
y
.
Hardw
are-specic
latenc
y
,
wireless
channel
v
ariability
,
and
battery
dischar
ge
beha
vior
are
not
directly
measured
and
remain
topics
for
future
e
xperimental
v
alidation.
6.1.
Computational
cost
Computational
cost
represents
the
total
e
x
ecution
time
of
dominant
cryptographic
operations
during
signcryption
and
unsigncryption.
Lightweight
operations
(e.g.,
has
hing
and
concatenation)
are
ne
glected,
con-
sistent
with
prior
comparati
v
e
studies.
The
considered
operations
include
bilinear
pairing
(
β
P
),
pairing
multiplication
(
p
m
),
elliptic-curv
e
scalar
multiplication
(
εC
m
),
and
h
yper
-elliptic
curv
e
di
visor
multiplication
(
hεD
m
).
Their
a
v
erage
e
x
ecution
times
are
summarized
in
T
able
3,
based
on
benchmarks
reported
in
[23],
[27].
All
simulations
were
conducted
using
an
Intel
Core
i7-6700
@
3.40
GHz
with
8
GB
RAM
under
Ub
untu
16.04
using
the
MIRA
CL
cryptographic
library
.
This
conguration
serv
es
solely
as
a
consistent
base-
line
for
comparison
and
does
not
represent
a
specic
IoD
deplo
yment.
Benchmarking
scope:
t
he
ti
ming
v
alues
adopted
from
[23],
[27].
ensure
consistenc
y
with
prior
studies.
Results
should
therefore
be
interpre
ted
as
relati
v
e
analytical
comparisons
rather
than
absolute
performance
guarantees
for
real-w
orld
drone
hardw
are.
A
r
ob
ust
blind
signcryption
sc
heme
for
secur
e
internet
of
dr
ones
communication
(T
ahri
Rac
hid)
Evaluation Warning : The document was created with Spire.PDF for Python.
996
❒
ISSN:
1693-6930
T
able
3.
Single
operation
time
consumption
(milliseconds)
Operation
β
P
p
m
εC
m
hεD
m
T
ime
(ms)
4.669
0.788
0.341
0.1705
T
ables
4
and
5
present
the
number
of
cryptographic
operations
and
the
corresponding
total
e
x
ecution
time
for
each
scheme.
As
illustrated
in
Figure
3,
the
proposed
scheme
achie
v
es
the
lo
west
computational
cost
under
the
adopted
benchmark
assumptions.
T
able
4.
Computational
cost
in
terms
of
operations
used
Schemes
Signcryption
Unsigncryption
T
otal
[17]
5
εC
m
2
εC
m
7
εC
m
[19]
3
εC
m
2
εC
m
5
εC
m
[21]
6
p
m
3
β
P
+
5
p
m
3
β
P
+
11
p
m
[23]
3
εC
m
1
εC
m
4
εC
m
[26]
3
εC
m
2
εC
m
5
εC
m
Proposed
4
hεD
m
1
hεD
m
5
hεD
m
T
able
5.
Computational
cost
comparison
in
milliseconds
Schemes
Signcryption
Unsigncryption
T
otal
[17]
1.705
0.682
2.387
[19]
1.023
0.682
1.705
[21]
4.728
17.947
22.675
[23]
1.023
0.341
1.364
[26]
1.023
0.682
1.705
Proposed
0.682
0.1705
0.8525
Figure
3.
Computational
cost
comparison
among
e
xisting
and
proposed
schemes
Using
the
standard
reduction
metric
Reduction
(%)
=
Existing
−
Proposed
Existing
×
100
,
the
proposed
scheme
achie
v
es
computational
cost
reductions
of
64.28%,
49.99%,
96.24%,
37.51%,
and
50%
compared
with
[17],
[19],
[21],
[23],
[26],
respecti
v
ely
,
with
an
a
v
erage
impro
v
ement
of
59.60%.
6.2.
Communication
cost
Communication
cost
is
dened
as
the
total
number
of
transmitted
bits.
Consistent
with
prior
studies,
|
G
|
=
1024
bits,
|
E
|
=
160
bits,
|
n
|
=
80
bits,
and
the
message
size
|
m
|
=
1000
bits.
T
able
6
and
Figure
4
summarize
the
communication
o
v
erhead.
The
pairing-based
scheme
in
[21]
incurs
the
highest
cost
due
to
lar
ge
group
elements,
while
ECC-based
schemes
[17],
[19],
[23],
[26]
e
xhibit
moderate
o
v
erhead.
The
proposed
HECC-based
design
achie
v
es
the
lo
west
communication
cost
o
wing
to
shorter
di
visor
representations.
Compared
with
[17],
[19],
[21],
[23],
[26],
the
proposed
approach
reduces
communication
cost
by
63.74%,
52.86%,
81.52%,
19.51%,
and
26.67%,
respecti
v
ely
,
with
an
a
v
erage
reduction
of
48.86%.
TELK
OMNIKA
T
elecommun
Comput
El
Control,
V
ol.
24,
No.
3,
June
2026:
991–1002
Evaluation Warning : The document was created with Spire.PDF for Python.
TELK
OMNIKA
T
elecommun
Comput
El
Control
❒
997
T
able
6.
Communication
cost
comparison
Schemes
Expression
Bits
[17]
3
|
m
|
+
4
|
E
|
3640
[19]
2
|
m
|
+
5
|
E
|
2800
[21]
|
m
|
+
6
|
G
|
7144
[23]
|
m
|
+
4
|
E
|
1640
[26]
|
m
|
+
5
|
E
|
1800
Proposed
|
m
|
+
4
|
n
|
1320
Figure
4.
Communication
cost
comparison
among
e
xisting
and
proposed
schemes
7.
FORMAL
SECURITY
V
ALID
A
TION
This
section
presents
the
formal
v
alidation
of
the
proposed
identity-based
blind
signcryption
scheme
using
the
Sc
yther
v
erication
tool
[32].
The
objecti
v
e
is
to
v
erify
the
logical
correctness
of
the
protocol
under
a
standard
symbolic
adv
ersary
model
rather
than
to
claim
implementation-le
v
el
security
.
Sc
yther
operates
under
the
Dole
v–Y
ao
assumption,
where
the
adv
ersary
has
full
control
o
v
er
the
com-
munication
channel
b
ut
cannot
break
cryptographic
primiti
v
es.
Accordingly
,
the
analysis
focuses
on
secrec
y
,
authentication,
agreement,
and
freshness
properties
at
the
protocol
le
v
el.
The
protocol
is
specied
in
security
protocol
description
language
(SPDL),
where
roles,
m
essage
o
ws,
cryptographic
operations,
and
security
cla
ims
are
e
xplicitly
modeled.
The
adv
ersary
is
assumed
capable
of
intercepting,
modifying,
replaying,
and
injecting
messages,
while
cryptographic
primiti
v
es
are
treated
as
ideal.
This
automated
analysis
complements
the
informal
e
v
aluation
by
v
erifying
protocol
correctness
within
the
symbolic
frame
w
ork.
7.1.
V
eried
security
claims
The
follo
wing
standard
Sc
yther
claims
were
specied
to
assess
secrec
y
and
authentication
guarantees:
-
Secrec
y:
ensures
that
condential
protocol
elements,
including
session
k
e
ys
and
transmitted
messages,
are
not
disclosed
to
the
adv
ersary
.
-
Ali
v
eness:
conrms
that
a
protocol
participant
completes
a
run
with
an
acti
v
e
peer
.
-
W
eak
agreement
(weak-agree):
ensures
that
communicating
entities
agree
on
the
occurrence
of
a
protocol
run
and
share
at
least
one
common
v
alue.
-
Non-injecti
v
e
agreement
(Ni-agree):
strengthens
authentication
by
ensuring
mutual
agreement
on
e
xchanged
data
v
alues.
-
Non-injecti
v
e
synchronization
(Ni-synch):
v
eries
c
o
r
rect
message
orderi
ng
and
freshness,
contrib
uting
to
replay-attack
resistance.
A
r
ob
ust
blind
signcryption
sc
heme
for
secur
e
internet
of
dr
ones
communication
(T
ahri
Rac
hid)
Evaluation Warning : The document was created with Spire.PDF for Python.
998
❒
ISSN:
1693-6930
7.2.
V
erication
r
esults
The
protocol
roles,
parameters,
and
v
erication
settings
used
in
the
Sc
yther
en
vironment
are
il
lustrated
in
Figure
5,
and
the
corresponding
v
erication
outcomes
are
sho
wn
in
Figure
6.
The
analysis
reports
no
attack
traces
for
an
y
of
the
specied
security
claims.
These
results
indicate
that
the
proposed
protocol
satises
secrec
y
,
authentication,
agreement,
and
freshness
properties
within
the
Sc
yther
symbolic
model.
Accordingly
,
the
scheme
is
formally
v
alidated
ag
ainst
protocol-le
v
el
attacks
such
as
replay
,
impersonation,
and
man-in-the-middle
attacks
under
the
assumed
v
eri-
cation
scope.
Figure
5.
Simulation
parameters
used
for
Sc
yther
v
erication
Figure
6.
V
erication
results
sho
wing
successful
v
alidation
of
all
security
claims
7.3.
Discussion
on
implementation-le
v
el
security
While
the
formal
v
alidation
conrms
protocol
correctness,
implementation-le
v
el
threats
such
as
side-
channel
leakage,
f
ault
injection,
weak
random
number
generation,
and
ph
ysic
al
de
vice
capture
remain
outside
the
scope
of
symbolic
v
erication
tools.
In
practical
deplo
yments,
these
risks
ca
n
be
mitig
ated
through
constant-time
cryptographic
imple-
mentations,
hardw
are-assisted
k
e
y
storage
(e.g.,
secure
elements
or
trusted
e
x
ecution
en
vironments),
secure
boot
mechanisms,
and
side-channel
e
v
aluation
tools
such
as
ChipWhisperer
or
test
v
ector
leakage
assessment
(TVLA).
Hardw
are-le
v
el
protections
ag
ainst
tampering
and
f
ault-based
attacks
remain
important
directions
for
future
e
xperimental
studies.
TELK
OMNIKA
T
elecommun
Comput
El
Control,
V
ol.
24,
No.
3,
June
2026:
991–1002
Evaluation Warning : The document was created with Spire.PDF for Python.
TELK
OMNIKA
T
elecommun
Comput
El
Control
❒
999
8.
DISCUSSION
Although
the
proposed
scheme
pro
vides
strong
protocol-le
v
el
security
guarantee
s,
se
v
eral
practi
cal
challenges
must
be
considered
before
real-w
orld
deplo
yment
in
IoD
en
vironments.
These
limitations
stem
from
architectural
assumptions
and
implementation
constraints
and
moti
v
ate
further
research
to
w
ard
scalable
inte
gration.
-
Centralized
KGC
architecture:
dependence
on
a
centralized
KGC
may
create
scalabil
ity
bottlenecks
and
a
potential
single
point
of
f
ailure
in
lar
ge-scale
or
sw
arm-based
IoD
deplo
yments.
-
Interoperability
constraints:
compatibility
with
e
xisting
IoD
protocols
such
as
MA
VLink
and
unmanned
aerial
v
ehicle
controller
area
netw
ork
(U
A
VCAN)
has
not
been
e
xp
e
rimentally
v
alidated,
and
inte
gration
with
platforms
such
as
PX4
and
ArduPilot
remains
an
open
challenge.
-
Post-quantum
r
eadiness:
the
scheme
relies
on
classical
cryptographic
assumptions
and
does
not
incorporate
post-quantum
primiti
v
es
or
e
xplicitly
model
emer
ging
5G/B5G
communication
en
vironments.
-
Implementation-le
v
el
vulnerabilities:
as
discussed
in
section
7.
Side-channel
leakage,
f
ault
injection,
weak
randomness,
and
ph
ysical
de
vice
capture
are
be
yond
the
scope
of
the
current
protocol-le
v
el
analysis.
-
Mobility-induced
o
v
erhead:
frequent
drone
mobility
and
zone
transitions
may
require
repeated
authentication
and
k
e
y
updates,
potentially
af
fecting
communication
continuity
.
-
Netw
ork-induced
latenc
y
v
ariability:
wireless
interference,
congestion,
and
dynamic
topology
changes
in-
troduce
latenc
y
v
ariations
that
are
not
fully
captured
by
analytical
cryptographic
e
v
aluation.
T
o
address
these
limitations,
se
v
eral
research
directions
are
identied:
-
De
v
eloping
distrib
uted
or
hierarchical
KGC
architectures
based
on
threshold
cryptograph
y
to
impro
v
e
scal-
ability
and
f
ault
tolerance.
-
Designing
middle
w
are
adapters
to
inte
grate
blind
signcryption
with
MA
VLink
and
U
A
VCAN
message
for
-
mats
for
seamless
deplo
yment
on
e
xisting
drone
platforms.
-
In
v
estig
ating
h
ybrid
post-quantum
e
xtensions
and
e
v
aluating
performance
on
ph
ysical
testbeds
under
realistic
mobility
,
interference,
and
side-channel
conditions.
-
Incorporating
hardw
are-assisted
protection
mechanisms
(e.g.,
secure
elements
or
trusted
e
x
ecution
en
viron-
ments)
within
resource-a
w
are
security
architectures
aligned
with
emer
ging
standards.
-
Exploring
quality-of-service–a
w
are
scheduling,
edge-assisted
pre-computation,
and
dele
g
ated
zone-based
authentication
to
reduce
re-authentication
latenc
y
.
Addressing
these
challenges
wil
l
f
acilitate
the
transition
of
the
proposed
sche
me
from
a
protocol-le
v
el
construct
to
a
scalable
and
deplo
yment-ready
security
frame
w
ork
for
future
lar
ge-scale
autonomous
aerial
netw
orks.
9.
CONCLUSION
This
paper
addressed
security
and
ef
cienc
y
challenges
in
IoD
communications
by
proposing
a
light-
weight
identity-based
blind
signcryption
scheme
for
resource-constrained
aerial
en
vironments.
By
inte
grating
encryption
and
digital
signature
into
a
unied
operation,
the
scheme
reduces
computational
and
communication
o
v
erhead
while
preserving
essential
security
properties.
The
incorporated
blinding
mechanism
further
enhances
pri
v
ac
y
by
pre
v
enting
the
signing
authority
from
accessing
message
contents
or
linking
protocol
e
x
ecutions.
Informal
analysis
conrmed
support
for
authentication,
condentiality
,
inte
grity
,
anon
ymity
,
pri
v
ac
y
preserv
ation,
and
resistance
to
common
protocol-le
v
el
attacks.
F
ormal
v
alidation
using
the
Sc
yther
tool
v
eri-
ed
secrec
y
,
agreement,
and
freshness
properties
under
a
symbolic
adv
ersary
model.
Performance
e
v
aluation
demonstrated
signicant
reductions
in
computational
cost,
communication
o
v
erhead,
and
ener
gy
consumption
compared
with
representati
v
e
state-of-the-art
schemes.
Ov
erall,
the
proposed
design
pro
vides
an
ef
cient
and
pri
v
ac
y-a
w
are
security
frame
w
ork
suitable
for
IoD
en
vironments
with
strict
resource
constraints.
Future
w
ork
will
focus
on
hardw
are-le
v
el
implementation
and
lar
ge-scale
sw
arm
v
alidation
to
further
assess
deplo
yment
feasibility
.
FUNDING
INFORMA
TION
The
authors
declare
that
no
funding
w
as
recei
v
ed
to
support
this
research.
A
r
ob
ust
blind
signcryption
sc
heme
for
secur
e
internet
of
dr
ones
communication
(T
ahri
Rac
hid)
Evaluation Warning : The document was created with Spire.PDF for Python.
1000
❒
ISSN:
1693-6930
A
UTHOR
CONTRIB
UTIONS
ST
A
TEMENT
This
journal
uses
the
Cont
rib
utor
Roles
T
axonomy
(CRediT)
to
recognize
indi
vidual
author
contrib
u-
tions,
reduce
authorship
disputes,
and
f
acilitate
collaboration.
Name
of
A
uthor
C
M
So
V
a
F
o
I
R
D
O
E
V
i
Su
P
Fu
T
ahri
Rachid
✓
✓
✓
✓
✓
✓
✓
✓
✓
✓
✓
Abdellah
Ouammou
✓
✓
✓
✓
✓
✓
✓
✓
Abdellatif
Lasbahani
✓
✓
✓
✓
✓
Hibat
Eallah
Mohtadi
✓
✓
✓
✓
✓
C
:
C
onceptualization
I
:
I
n
v
estig
ation
V
i
:
V
i
sualization
M
:
M
ethodology
R
:
R
esources
Su
:
Su
pervision
So
:
So
ftw
are
D
:
D
ata
Curation
P
:
P
roject
Administration
V
a
:
V
a
lidation
O
:
Writing
-
O
riginal
Draft
Fu
:
Fu
nding
Acquisition
F
o
:
F
o
rmal
Analysis
E
:
Writing
-
Re
vie
w
&
E
diting
CONFLICT
OF
INTEREST
ST
A
TEMENT
The
authors
declare
that
the
y
ha
v
e
no
kno
wn
competing
nancial
interests
or
personal
rela
tionships
that
could
ha
v
e
appeared
to
inuence
the
w
ork
reported
in
this
paper
.
Authors
state
no
conict
of
interest.
D
A
T
A
A
V
AILABILITY
The
data
that
support
the
ndings
of
this
study
are
a
v
ailable
from
the
corresponding
author
,
R
T
,
upon
reasonable
request.
REFERENCES
[1]
A.
Derhab
et
al.
,
“Internet
of
drones
security:
T
axonomies,
open
issues,
and
future
directions,
”
V
ehicular
Communications
,
v
ol.
39,
p.
100552,
Feb
.
2023,
doi:
10.1016/j.v
ehcom.2022.100552.
[2]
W
.
Y
ang,
S.
W
ang,
X.
Y
in,
X.
W
ang,
and
J.
Hu,
“
A
Re
vie
w
on
Security
Issues
and
Solutions
of
the
Internet
of
Drones,
”
IEEE
Open
J
ournal
of
the
Computer
Society
,
v
ol.
3,
pp.
96–110,
2022,
doi:
10.1109/OJCS.2022.3183003.
[3]
D.
Mandloi,
R.
Arya,
and
A.
K.
V
erma,
“Internet
of
Drones,
”
in
Recent
T
r
ends
in
Articial
Intellig
ence
T
owar
ds
a
Smart
W
orld,
Spring
er
,
2024,
pp.
353–373.
doi:
10.1007/978-981-97-6790-8
13.
[4]
J
.
B.
R.
Rose,
T
.
Arulmozhinathan,
V
.
T
.
Gopinathan,
and
J.
V
.
B.
Benif
a,
“Internet
of
Drones:
Applications,
Challenges,
Opportu-
nities,
”
in
Internet
of
Dr
ones,
Boca
Raton:
CRC
Pr
ess
,
2023,
pp.
1–18.
doi:
10.1201/9781003252085-1.
[5]
L.
Ab
ualig
ah,
A.
Diabat,
P
.
Sumari,
and
A.
H.
Gandomi,
“
Applications,
Deplo
yments,
and
Inte
gration
of
Internet
of
Drones
(IoD):
A
Re
vie
w
,
”
IEEE
Sensor
s
J
ournal
,
v
ol.
21,
no.
22,
pp.
25532–25546,
No
v
.
2021,
doi:
10.1109/JSEN.2021.3114266.
[6]
A.
F
.
Aldweesh
and
A.
M.
Almuhaideb,
“
Authentication
T
echniques
in
Internet
of
Drones
(IoD):
T
axonomy
,
Open
Challenges
and
Future
Directions,
”
J
ournal
of
Sensor
and
Actuator
Networks
,
v
ol.
14,
no.
3,
p.
57,
May
2025,
doi:
10.3390/jsan14030057.
[7]
S
.
Sciancalepore,
“Pri
v
ac
y
and
Condentiality
Issues
in
Drone
Operations:
Challenges
and
Road
Ahead,
”
IEEE
Network
,
v
ol.
38,
no.
6,
pp.
227–233,
No
v
.
2024,
doi:
10.1109/MNET
.2024.3432730.
[8]
Y
.
Zheng,
“Digital
signcryption
or
ho
w
to
achie
v
e
cost(Signature
&:
Encryption)
¡¡
cost(signature)
+
cost(encryption),
”
in
Lectur
e
Notes
in
Computer
Science
(including
subseries
Lectur
e
Notes
in
Articial
Intellig
ence
and
Lectur
e
Notes
in
Bioinformatics)
,
v
ol.
1294,
1997,
pp.
165–179.
doi:
10.1007/BFb0052234.
[9]
A.
Shamir
,
“Identity-Based
Cryptosystems
and
Signature
Schemes,
”
in
Advances
in
Cryptolo
gy
,
Berlin,
Heidelber
g:
Spring
er
Berlin
Heidelber
g
,
pp.
47–53.
doi:
10.1007/3-540-39568-7
5.
[10]
S.
Ullah
and
N.
Din,
“Blind
signcryption
scheme
based
on
h
yper
elliptic
curv
es
cryptosystem,
”
P
eer
-to-P
eer
Network
ing
and
Appli-
cations
,
v
ol.
14,
no.
2,
pp.
917–932,
Mar
.
2021,
doi:
10.1007/s12083-020-01044-8.
[11]
B
.
Hassan
et
al.
,
“
A
Cos
t
Ef
fecti
v
e
Identity-Based
Authentication
Scheme
for
Internet
of
Things-Enabl
ed
Agriculture,
”
W
ir
eless
Communications
and
Mobile
Computing
,
v
ol.
2022,
no.
1,
Jan.
2022,
doi:
10.1155/2022/4275243.
[12]
Z.
Jamroz
et
al.
,
“
An
Optimal
Authentication
Scheme
through
Dual
Signat
ure
for
the
Internet
of
Medical
Things,
”
Futur
e
Internet
,
v
ol.
15,
no.
8,
p.
258,
Jul.
2023,
doi:
10.3390/15080258.
[13]
D.
Cha
um,
“Blind
Signatures
for
Untraceable
P
ayments,
”
in
Advances
in
Cryptolo
gy
,
Boston,
MA:
Springer
US,
1983,
pp.
199–203.
doi:
10.1007/978-1-4757-0602-4
18.
[14]
N.
K
oblitz,
“Hyperelliptic
cryptosystems,
”
J
ournal
of
Cryptolo
gy
,
v
ol.
1,
no.
3,
pp.
139–150,
Oct.
1989,
doi:
10.1007/BF02252872.
[15]
M
.
A.
Khan
et
al.
,
“
An
Impro
vised
Certicate-Based
Proxy
Signature
Using
Hyperelliptic
Curv
e
Cryptograph
y
for
Secure
U
A
V
Communications,
”
IEEE
T
r
ansactions
on
Intellig
ent
T
r
ansportation
Systems
,
v
ol.
26,
no.
4,
pp.
5264–5275,
Apr
.
2025,
doi:
10.1109/TITS.2024.3524575.
[16]
I.
Ullah
et
al.
,
“
A
Multi-Message
Multi-Recei
v
er
Signcryption
Scheme
with
Edge
Computing
for
Secure
and
Reliable
W
ireless
Internet
of
Medical
Things
Communications,
”
Sustainability
,
v
ol.
13,
no.
23,
p.
13184,
No
v
.
2021,
doi:
10.3390/su132313184.
TELK
OMNIKA
T
elecommun
Comput
El
Control,
V
ol.
24,
No.
3,
June
2026:
991–1002
Evaluation Warning : The document was created with Spire.PDF for Python.