What cryptographic measures protect the communication between a drone operator and its drone?
The drone scenario requires encryption (confidentiality of commands/footage), authentication (prevent unauthorized control), integrity (prevent command modification), and non-repudiation (logging who issued commands).
The drone communication faces all classic attacks:
| Threat | Attack | Countermeasure |
|---|---|---|
| Eavesdropping on video feed | Eavesdropping | Encryption |
| Sending fake commands | Masquerade | Authentication protocol (C-R) |
| Modifying flight commands | Modifying | MAC or digital signature |
| Replaying old commands | Replay | Sequence numbers / timestamps, covered by the MAC |
| Blocking commands | Delete | MAC-covered sequence numbers + timeout |
| Denying having issued a command | Repudiation | Digital signatures on commands |
Are sequence numbers a cryptographic measure? Not on their own. A counter or timestamp is ordinary data, and an attacker who can tamper with messages can rewrite it just as easily. It becomes a security measure only once it is covered by the MAC or signature: the drone verifies the tag first, then checks that the number is fresh (higher than the last one seen, or inside the time window). The number supplies freshness; the cryptography is what binds it to the message so it can't be forged. The timeout is likewise a policy on top of authenticated data, not a primitive.
Key takeaway: Real-world systems need all 4 principles combined plus application-level measures. No single cryptographic mechanism is sufficient — security is always a composition of multiple protections.