Internet of Drones (IoD) systems increasingly support mission-critical applications that require secure collaboration, selective data access, and privacy-preserving analytics under stringent resource and latency constraints. Existing solutions typically address authentication, encrypted storage, searchable retrieval, or blockchain-based trust independently, without providing an integrated framework for authorized encrypted search, verifiable retrieval, and post-quantum resilience. This paper presents a lightweight, post-quantum-aware authentication and data-access framework for fog-assisted IoD based on a unified epoch-driven architecture. Drone identities are established through PUF-sealed mutual authentication with ML-KEM, eliminating persistent private-key storage. The framework introduces Capability-Bound Searchable Objects (CBSOs), Authorization-Bound Trapdoors (ABTs), and a Two-Level Capability-Aware Search (TCAS) mechanism to enable policy-isolated encrypted retrieval without online policy evaluation. Retrieval integrity is ensured through Verification-Ready Retrieval Packages (VR-RPs), validated using Sparse Merkle proofs against blockchain-anchored searchable-state commitments. Experimental results show that the proposed framework incurs only a 10% authentication overhead during the first epoch exchange and becomes 45% faster than classical RSA-based authentication thereafter. Compared with representative schemes, it achieves up to 95% faster trapdoor generation, 90.6% faster encrypted search, 8.5× higher verifiable retrieval throughput, and reduces drone-side computation and energy consumption by up to 98.6% and 97.9%, respectively. Formal security analysis demonstrates authentication soundness, forward-secure epoch isolation, authorization correctness, adaptive searchable privacy, verifiable retrieval, and resistance against replay, trapdoor-forgery, Sybil, flooding, and insider-fog attacks, demonstrating the practicality of the framework for large-scale resource-constrained IoD deployments.
更多