Source-linked AI summary
Fast, Reliable, and Secure Drone Communication: A Comprehensive Survey
Vikas Hassija, Vinay Chamola, Adhar Agrawal, Adit Goyal, Nguyen Cong Luong, Dusit Niyato, F. Richard Yu, Mohsen Guizani
TL;DR
Drone applications are expanding while resource constraints and communication vulnerabilities leave their security-critical uses exposed. This survey synthesizes application-specific risks, attacks, and emerging architectures, concluding that blockchain, SDN, machine learning, and fog/edge computing provide key approaches for secure drone communication.
Problem
Expanding drone applications face security challenges, while resource constraints limit deployment of heavy security algorithms on board.
Method
The paper comprehensively surveys drone applications, communication threats, vulnerabilities, and solution architectures using blockchain, SDN, machine learning, and fog/edge computing.
Results
The survey identifies application-specific vulnerabilities and discusses architectures using blockchain for data integrity, machine learning for detection, SDN for traffic control, and fog computing for nearby processing.
Takeaways & Limitations
These technologies are presented as approaches for improving security, reliability, and computational support in drone communication.
Abstract
from arXiv · showhide
Drone security is currently a major topic of discussion among researchers and industrialists. Although there are multiple applications of drones, if the security challenges are not anticipated and required architectural changes are not made, the upcoming drone applications will not be able to serve their actual purpose. Therefore, in this paper, we present a detailed review of the security-critical drone applications, and security-related challenges in drone communication such as DoS attacks, Man-in-the-middle attacks, De-Authentication attacks, and so on. Furthermore, as part of solution architectures, the use of Blockchain, Software Defined Networks (SDN), Machine Learning, and Fog/Edge computing are discussed as these are the most emerging technologies. Drones are highly resource-constrained devices and therefore it is not possible to deploy heavy security algorithms on board. Blockchain can be used to cryptographically store all the data that is sent to/from the drones, thereby saving it from tampering and eavesdropping. Various ML algorithms can be used to detect malicious drones in the network and to detect safe routes. Additionally, the SDN technology can be used to make the drone network reliable by allowing the controller to keep a close check on data traffic, and fog computing can be used to keep the computation capabilities closer to the drones without overloading them.
I. INTRODUCTION
Drone use is expanding across applications, but resource constraints and insecure communication links create serious safety and security risks. This survey reviews prior work and presents a comprehensive account of drone-security challenges, solutions, and future research directions.
- Motivation: Drone applications are rapidly expanding, increasing the importance of securing their communication links.The drone-application market was projected to grow from 69 billion dollars in 2018 to 141 billion dollars in 2023.
- Motivation: Resource-constrained drones are vulnerable to physical and cyber attacks because their storage and battery capacities are limited.Attackers may compromise chips and sensors to access information stored inside the drone.
- Motivation: Compromised drone communication can create life-threatening consequences, including flight interference with other aircraft.A hacked drone in Las Vegas entered the path of a tour helicopter, although a crash was avoided.
- Related Surveys: Existing surveys typically examine specific drone domains or communication contexts rather than the full range of drone-security challenges.Prior work covers smart-city drone–IoT collaboration, civilian drones, cellular communications, or UAV communication networks.
- Contributions: This paper provides a comprehensive survey of critical and emerging drone-communication security challenges and related solutions.Its contributions include reviewing attacks, recommending secure communication architectures, analyzing emerging solutions, and assessing future research areas and open issues.
B. Organization
The paper organizes drone communication security around attack mechanisms and application vulnerabilities, emphasizing that unmanned, resource-constrained drones require specialized protection. It introduces denial-of-service and de-authentication attacks as examples of threats that disrupt drone operation.
- Security Challenges: Drone communication faces both drone-specific threats and generic cyber-threats because unmanned systems must handle unexpected issues dynamically.Drone security differs from that of traditional IoT devices and requires attention to specialized vulnerabilities.
- Resource Constraints: Complex encryption and decryption can be difficult to deploy because drones have limited computational resources.The paper notes that large data exchanges make computational requirements for complex security algorithms more consequential.
- Denial of Service Attacks: A denial-of-service attack overloads shared resources with superfluous requests, restricting legitimate access and potentially stopping normal drone operation.DoS is described as a common and relatively simple attack against drone networks.
- Denial of Service Attacks: Experiments evaluated Netwox, LOIC, and Hping3 against AR Drone 2.0 and 3DR Solo to analyze the effects of DoS attacks on drone behavior.The evaluation examined image quality transmission under attack.
- De-Authentication Attacks: De-authentication attacks disrupt communication between a drone and Wi-Fi access point, causing the pilot to lose control.Attackers can transmit de-authentication frames without encryption after discovering the drone’s MAC address.
- De-Authentication Attacks: SkyJack demonstrates how de-authentication can disconnect a drone from its user before an adversary issues commands through a substitute access point.The attack uses an AR Drone 2.0, Raspberry Pi, wireless adapters, Aircrack-ng, and Pine-AP.
2) Man-In-The-Middle Attack:
Drone communication is exposed to interception, command manipulation, GPS spoofing, and physical compromise when links or onboard protections are weak. Reported incidents show that attackers can redirect, control, or disable drones through communication and navigation attacks.
- Man-In-The-Middle Attack: Man-in-the-middle attackers position themselves between the controller and drone to intercept acknowledgements and inject forced commands.Wi-Fi Pineapple can impersonate or exploit the drone’s access point, causing unintended actions to be implemented.
- Man-In-The-Middle Attack: Weak encryption and insecure communication chains enable man-in-the-middle attacks over Wi-Fi.One demonstration reported that hardware costing about 40 dollars was sufficient to steal control of a police quadcopter.
- GPS Spoofing: GPS spoofing combines false transmitted signals with targeted antennas to provide drones or controllers with incorrect location information.Drones without chipboard encryption are easier to track and mislead, particularly when they depend on GPS for flight paths.
- GPS Spoofing: An American UAV was reportedly spoofed with false GPS coordinates and forced to fly over Iran before being detected and shot down.The incident illustrates the operational consequences of manipulating navigation data in military drones.
- Drone Compromise: Reverse engineering can expose a drone’s internal design and stored information after attackers gain access.The supplied passage states that the attacker accessed and reverse-engineered the entire drone.
4) Radar:
Drone security risks extend beyond detection: radar provides a way to locate and characterize drones, while jamming and routing attacks can disrupt communication or compromise network integrity. These threats affect both individual drones and multi-node UAV networks.
- Radar: Mono-static radar detects drones by transmitting electromagnetic signals and analyzing reflections to estimate velocity, direction, and altitude.Radar signals travel long distances and can identify drone presence from reflected energy.
- Radar: Radar is described as superior to optic and infrared sensors for drone detection because those alternatives have range and weather-related reliability limitations.Optic and infrared sensing can be less reliable at night, in rain, and in fog.
- Jamming: Jammers disrupt drone communication by transmitting sufficiently powerful signals on the target’s frequency, blocking signals at the receiver.A UAV-assisted jammer can block communication between a drone and backup serving base station, making the drone non-responsive.
- Jamming: GPS jamming reportedly brought down 46 drones during a Hong Kong show despite their fail-safe return capabilities.The jamming signal was strong enough that the drones began dropping mid-air rather than returning to their launch location.
- Wormhole Attacks: Wormhole attacks exploit FANET routing by making distant nodes appear nearby, enabling control-packet manipulation and data-traffic capture without cryptographic keys.The attack is identified as a high-level multi-node risk in UAV ad hoc networks.
B. Potential Vulnerabilities In Different Drone Applications
Drone applications span mining, disaster response, agriculture, military operations, delivery, and urban planning, but each application faces distinct security consequences. Attacks can waste resources, disrupt operations, or create risks to life and property.
- Mining: Mining drones can use infrared cameras and metal detectors to locate ores while reducing miners’ workload, exposure to risk, and mining costs.These capabilities support surface and underground mining applications.
- Disaster Management: In disaster response, malicious drones can send false positives that waste emergency resources or false negatives that delay warnings and deliveries.The latter can contribute to loss of life and property by preventing timely disaster-related messages.
- Agriculture: Agricultural drones can pollinate seeds and distribute them in programmed quantities, reducing farmers’ workload and seed waste.The drones can use field datasets to target required sprinkling amounts.
- Military: Silent drones increase military utility by enabling covert flight to remote locations and supporting enemy surveillance during strikes.Cameras installed on these drones can help identify enemy locations.
- Delivery: Drones support last-mile delivery of food, medicine, newspapers, and other necessities, with reported deployments delivering medicine and packages rapidly.The supplied examples include a 2015 FAA-approved medicine delivery and a 13-minute Amazon package delivery.
- Urbanization: Urban-planning drones equipped with GIS can capture, analyze, and manipulate geographical data for renovation, construction, and water-management decisions.Their use is linked to analyzing city water-supply plans.
C. Classification of Drone Communication Systems
Drone communication includes peer-to-peer drone links and infrastructure connections through satellites, cellular networks, and ground stations. The survey presents blockchain, SDN, machine learning, and fog or edge computing as emerging security approaches for these systems.
- Drone-to-Drone Communication: Drone-to-drone communication resembles a peer-to-peer network and is susceptible to DoS, DDoS, and jamming attacks.D2D communication has not yet been standardized.
- Drone-to-Infrastructure Communication: Drone-to-infrastructure communication includes drone-to-satellite, drone-to-network, and drone-to-ground-station categories.Satellite links support GPS coordination, cellular links support network connectivity, and ground stations commonly use Bluetooth or Wi-Fi.
- Drone-to-Ground Station: Ground-station links based on public Bluetooth and Wi-Fi technologies are insecure and susceptible to man-in-the-middle attacks and eavesdropping.The survey contrasts these links with satellite communication, which it describes as safer and more secure despite higher setup and maintenance costs.
- Emerging Security Technologies: The survey focuses on blockchain, machine learning, SDN, and fog computing as four emerging technologies for fast, reliable, and secure drone communication.The technologies are presented as security approaches rather than as a single communication architecture.
- Emerging Security Technologies: Blockchain is presented as a way to secure, preserve, and manage drone transactions using cryptographically linked blocks and configurable network types or consensus algorithms.The survey discusses public, private, consortium, and hybrid blockchains alongside PoW, PoS, PoB, and DAG approaches.
B. Drone Communication Architecture Using SDN
The section reviews SDN, machine learning, and fog computing as architectures for improving drone communication security. These approaches centrally manage traffic, detect malicious behavior, and move processing closer to resource-constrained drones.
- SDN: SDN separates data forwarding from centralized control and application layers, enabling programmable and consistent network management.Each drone can behave as an individual switch while the centralized controller processes network data.
- SDN: SDN can improve reliability and quality of service by automatically controlling traffic, particularly for real-time drone video streaming.Its decoupled layers support direct network control and better QoS.
- Machine Learning: Machine learning learns from training data to improve predictions and can support malicious-drone detection, attack prevention, and fault recovery.The cited applications include man-in-the-middle and spoofing attacks, as well as neural-network and LSTM-based recovery.
- Fog Computing: Fog computing places a decentralized processing layer between end devices and cloud servers to reduce retrieval latency, cloud load, and cost.Nearby fog nodes use LAN connectivity rather than relying on higher-latency and higher-cost WAN access to the cloud.
- Integrated Security Technologies: The surveyed drone applications use blockchain, SDN, machine learning, or fog computing as technologies for securing drone communication.The paper discusses their usage and benefits in detail.
IV. APPLICATIONS OF BLOCKCHAIN FOR DRONE COMMUNICATION SECURITY
This section surveys blockchain applications for drone communication security, including air-traffic management and collision prevention. It presents blockchain-based mechanisms for coordinating drone paths and addressing limitations of non-blockchain approaches.
- Overview: Blockchain-based drone-security applications address data security and physical flight risks across increasingly important drone domains.The paper focuses on models and mechanisms for securing drone communication as drone use expands in agriculture, security, wildlife conservation, and delivery.
- Air Traffic Management: Increasing UAV numbers create collision risks because drone paths can cross and air traffic must be managed in three dimensions.Traditional GPS-based localization is difficult to apply to complex paths because of pilot errors and intrusion attacks.
- Air Traffic Management: The neural-blockchain based transport model uses three blockchain networks to form a master blockchain for optimizing air-traffic violations.The model is proposed for coordinating complex UAV paths and addressing the limitations of internet-based systems.
- Preventing Mid-Air Collisions: A blockchain-based air-traffic-control solution uses peer-to-peer blockchain transactions to support physical drone protection under heavy air traffic.The approach targets prevention of mid-air collisions, which can be worsened by resource constraints and communication delays.
- Preventing Mid-Air Collisions: Proof of Graph selects paths limiting mid-air collisions using the Simplified Memory Bounded A* algorithm.The paper compares SMA* with A* and Dijkstra’s algorithms; SMA* uses bounded memory, unlike A*’s exponential memory.
B. Geo-fencing System
The section describes blockchain and related networking approaches for geofencing, secure data dissemination, and drone localization. It emphasizes decentralized coordination while noting privacy, latency, and scalability concerns.
- Geo-fencing System: Geofencing creates virtual boundaries that prevent UAVs from entering sensitive areas such as prisons, airports, and private properties.Applying geofencing is more complex for drones because flight lacks fixed pathways and occurs in three dimensions.
- Geo-fencing System: Blockchain-based flight-space allocation adds UAV air-space requests to a decentralized ledger and selects trajectories that avoid restricted zones and crossing paths.Blockchain is used for both geofencing and traffic-violation avoidance, with immutability and cyber-attack resistance identified as benefits.
- Privacy and Data Security: Drone sensor and geographic data can profile individuals, creating a privacy-leakage risk when processing is moved to the cloud.The passage also reports that zero-knowledge proofs are vulnerable to high latency and high false rates.
- Secure Data Dissemination: A blockchain-based IoD algorithm uses tamper-proof and transparent storage to secure important data sent by drones.Its focus differs from collision and restricted-area prevention by emphasizing the security of drone-generated data.
- Secure Data Dissemination: Blockchain-based data dissemination secures transfers between drones and controllers through user, infrastructure, and IoD layers.The user layer verifies and secures each transaction.
- Secure Localization: Secure localization can use decentralization, peer-to-peer communication, and distributed verification without a central trust node.Anchor drones provide coordinates, which are verified and added to a distributed blockchain ledger; localization uses RSSI when at least three one-hop anchors respond.
A. DoS Attacks
The section reviews SDN-based defenses against DoS, DDoS, jamming, and disruption attacks in resource-constrained drone networks. Reported approaches improve attack detection or outage prevention but may introduce responsiveness or delay trade-offs.
- DoS Attacks: NetFence uses in-network traffic policing and congestion feedback to create a scalable SDN-based drone network resistant to large-scale DoS attacks.Non-NetFence senders use a legacy channel with the lowest packet-forwarding priority, while bottleneck routers detect congestion.
- DDoS Attacks: DDoS attacks involve multiple compromised hosts, requiring lightweight detection and mitigation suited to resource-constrained Internet-of-Drones networks.The distinction from normal DoS attacks is based on the number of compromised hosts.
- DDoS Attacks: The SDN-based DDoS detector uses packet-in message-rate vectors, cosine similarity, and thresholds to classify attacks and identify the launching device quickly.Compared with IP filtering, simulations reported fewer flow-table items and fewer packets received by the controller during DDoS attacks.
- DDoS Attacks: The DDoS approach is reactive because it detects attacks after launch and lacks a proactive prevention scheme.The paper identifies this as a limitation of the proposed algorithm.
- Avoiding Intentional Disruption: 18% lower average end-to-end outage rate was reported for the SDN-based model than for traditional shortest-path and shortest-multipath algorithms.The model also prevented complete network outage and frequent link disconnections under jamming and intentional disruption.
- Avoiding Intentional Disruption: 12% higher end-to-end delay accompanied the outage reduction compared with the traditional algorithms.The paper calls for methods that prevent intentional disruptions without increasing average network delay.
D. Malfunctioning devices
SDN-based approaches address malfunctioning devices and attacks in drone communication by authenticating traffic, coordinating controllers, and optimizing secure data paths. Machine learning complements these mechanisms through drone detection and traffic classification.
- SDN-based mitigation: SDN controllers can authenticate network traffic to help identify malfunctioning devices in drone communication.
- SDN-based mitigation: Multiple SDN controllers improve resilience because another controller can take over if one fails.Controllers maintain partial network views and exchange information, which can also improve network performance.
- SDN-based mitigation: Middlebox-Guard manages dataflow, places middleboxes along short communication links, and uses ILP to optimize routes and loads.It addresses switch constraints involving CPU and RAM while reducing latency and balancing middlebox load.
- SDN-based mitigation: SDN can help prevent DoS, DDoS, intentional disruption, and jamming attacks while maintaining drone data integrity.
- Machine-learning support: ML supports drone security by detecting unauthorized drones and classifying traffic as benign or attack-related.Radar-based SVM models classified drones versus birds and different drone types with test accuracy above 90%.
B. Drone detection using RNN and CRNN
RNN, CRNN, LSTM, and related machine-learning models are surveyed for detecting drones, securing communication, and identifying attacks. The approaches show promising accuracy and operational capabilities, but dataset realism, resource demands, and environmental sensitivity remain important boundaries.
- B. Drone detection using RNN and CRNN: RNN and CRNN models detect drones from propeller-audio data augmented with background noise to mimic real-life conditions.The dataset was acquired from drone propeller audio and overlapped with varied background noises.
- B. Drone detection using RNN and CRNN: Artificially created datasets reduce reliability, and the reviewed approach cannot identify the specific drone type.
- C. Fault detection and Recovery of UAV data using LSTM: LSTM models extract spatial-temporal features from 11 UAV parameters to support real-time data reliability and low-latency transmission.The parameters include roll angle, altitude, and indicated airspeed, sensed through airborne sensors.
- D. DoS attacks: ML models detect communication attacks, including DoS, with RF accuracy of 99.95% and MLP accuracy of 98.87% on CIC IDS 2017.The MLP used 30% training records, while RF used 50%; further multi-classification and feature reduction remained necessary.
- E. Privacy Leakage: Deep-learning privacy protection reconstructed data with 81.3% accuracy on MNIST, while auto-encoder processing enabled operation on Raspberry Pi 3B.The model weights were unknown to adversaries, making retrieval of the original data almost impossible.
- F. Adversarial attacks: A visual adversary-tracking platform achieved 77% accuracy at 5.22 fps and operated in GPS-denied environments.Its detection algorithm remained sensitive to poor lighting.
VII. APPLICATIONS OF FOG COMPUTING FOR DRONE COMMUNICATION SECURITY
Fog computing brings computation and data closer to resource-constrained drones, reducing latency while supporting security against several communication attacks. The surveyed applications address GPS spoofing, man-in-the-middle attacks, eavesdropping, and related threats through fog-layer mechanisms.
- Fog-computing rationale: Fog computing keeps computation and data near drones, reducing latency and supporting mobility, scalability, heterogeneity, and platform independence.It is presented as a complement to cloud computing for large drone networks with unpredictable connections.
- Attack mitigation: Traditional man-in-the-middle detection based on packet-arrival timing can fail when heavy background noise affects the transmission channel.The method infers an attack when packets arrive later than an expected threshold.
- Attack mitigation: Multicast authentication using Shamir’s secret sharing improves reliability but requires storing many keys, which is unsuitable for resource-constrained drones.The secret is unlocked when the authenticator has enough shares.
- Attack mitigation: Fog-layer IDS and IPS mechanisms are proposed to prevent man-in-the-middle attacks by monitoring receiver behavior and isolating compromised nodes.The described design uses encrypted packets, AES, Diffie-Hellman key exchange, and periodic interrogation of fog nodes.
- Attack mitigation: Fog Security Service addresses drone eavesdropping by offloading cryptographic operations to fog nodes and combining identity verification, asymmetric encryption, hashing, and nonces.The model uses RSA for public-key encryption and nonce values to prevent replay attacks.
D. Resource constraint issues
Fog-assisted architectures address drone resource constraints by distributing computation and data handling across nearby devices. The surveyed approaches reduce latency and energy demands, but emerging technologies still impose implementation constraints that require careful deployment.
- Resource constraint issues: Fog Computing aided Swarm of Drones architecture distributes tasks among nearby drones using ADMM to address computation and latency demands.An initiator drone assigns subtasks to available neighboring drones.
- Resource constraint issues: The Proximal Jacobi ADMM algorithm reduced transmission and computation latency, considered transmission and computation energy, and outperformed LRGA-MIE and a Linear Programming algorithm.The algorithm converged after the 14th iteration.
- Resource constraint issues: A decentralized game-theoretic task-allocation model requires more iterations and provides less reliability than the ADMM-based model.The comparison concerns the model discussed in and the ADMM approach in.
- Resource constraint issues: Edge caching stores commonly captured files in cache-enabled UAVs for direct transmission to requesting users, reducing repeated data dissemination.Requested data can be generated by merging files collected by different UAV sensors.
- Resource constraint issues: The paper cautions that security technologies must be evaluated against their own constraints before implementation in different drone applications.The UAV industry continues to face challenges despite anticipated benefits from these technologies.
- Resource constraint issues: Blockchain, SDN, and machine learning are described as security approaches for drone communication, although their suitability depends on application and network constraints.The paper associates them with protection against attacks including DoS, GPS spoofing, jamming, wormhole, and black hole attacks.
- Resource constraint issues: Fog computing is presented as improving QoS, scalability, flexibility, low latency, platform independence, and network security for drone applications.The surveyed security scope includes GPS spoofing, man-in-the-middle, eavesdropping, hijacking, and DoS attacks.
B. Future Research Directions and Open Challenges
The paper identifies open challenges involving resource limits, vulnerable gateways, incomplete fog coordination, blockchain scalability, and SDN controller security. It calls for further research to adapt security architectures to these practical constraints.
- B. Future Research Directions and Open Challenges: Blockchain security can increase drone storage and computation demands, reduce flight time, and introduce high latency for critical data such as location coordinates.The paper calls for security algorithms designed around drones’ resource-constrained nature.
- B. Future Research Directions and Open Challenges: Gateways linking drones, ground controllers, and satellites remain vulnerable because compromising a gateway can compromise the entire network.Further analysis is required to secure gateways between communication hops.
- B. Future Research Directions and Open Challenges: Fog computing does not currently support inter-fog resource and task sharing, limiting opportunities for less-loaded fog nodes to exchange work.The paper suggests that inter-fog sharing could reduce fog-to-cloud data transfer and enhance security.
- B. Future Research Directions and Open Challenges: Blockchain architecture is limited by the number of nodes in permissioned networks and by throughput in permissionless networks.Consensus algorithms are being designed to support both higher throughput and larger numbers of nodes or users.
- B. Future Research Directions and Open Challenges: Distributed or multiple SDN controllers may address single-controller failure, but secure near-real-time communication among controllers remains unresolved.The paper identifies inter-controller security as requiring further work.
- IX. CONCLUSION: The survey reviews drone applications, threats, vulnerabilities, and solution architectures based on SDN, blockchain, fog/edge computing, and machine learning.It also discusses benefits, improvement suggestions, open issues, and future research directions.