CAPSID: A Private Session ID System for Small UAVs

Yueshen Li, Jianli Jin, Kirill Levchenko

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

The US Federal Aviation Administration (FAA) has recently mandated that small unmanned aerial vehicles (UAVs) be equipped with a transmitter that broadcasts the UAV’s serial number, location, and altitude. The inclusion of a unique identifier in the form of a UAV serial number has stoked fears that the identifier will be used to track UAV operators and has even led some UAV perators to file a lawsuit against the FAA. In this paper, we propose CAPSID, an implementation of the FAA session ID concept that provides message authentication—something current Remote ID implementations lack—and strong operator anonymity. The FAA (or its equivalent in other jurisdictions) retains the ability to de-anonymize operators, but only in circumstances prescribed by law. To make this possible, CAPSID introduces a partially trusted third party, the Custodian, that serves as the bridge between anonymous identifiers and true operator identity. The Custodian ensures that the legal requirements for de-anonymization are met, preventing unnecessary mass collection of personally identifying information by a government agency. We formally verify the message authentication property of CAPSID using a cryptographic protocol checker and provide a formal proof of identifier non-linkability, even in the presence of corrupt (but non-colluding) authorities.

Original languageEnglish (US)
Title of host publicationCCS 2024 - Proceedings of the 2024 ACM SIGSAC Conference on Computer and Communications Security
PublisherAssociation for Computing Machinery
Pages1791-1805
Number of pages15
ISBN (Electronic)9798400706363
DOIs
StatePublished - Dec 9 2024
Event31st ACM SIGSAC Conference on Computer and Communications Security, CCS 2024 - Salt Lake City, United States
Duration: Oct 14 2024Oct 18 2024

Publication series

NameCCS 2024 - Proceedings of the 2024 ACM SIGSAC Conference on Computer and Communications Security

Conference

Conference31st ACM SIGSAC Conference on Computer and Communications Security, CCS 2024
Country/TerritoryUnited States
CitySalt Lake City
Period10/14/2410/18/24

Keywords

  • Anonymity
  • Authentication
  • Privacy
  • Remote ID
  • UAV

ASJC Scopus subject areas

  • Computer Networks and Communications
  • Computer Science Applications
  • Software

Fingerprint

Dive into the research topics of 'CAPSID: A Private Session ID System for Small UAVs'. Together they form a unique fingerprint.

Cite this