Solving the Identity-Privacy Paradox

How to Identify Friend or Foe Without Self-Disclosure?

Master Thesis (2026)
Author(s)

E. Šujster (TU Delft - Electrical Engineering, Mathematics and Computer Science)

Contributor(s)

E.A. Markatou – Mentor (TU Delft - Electrical Engineering, Mathematics and Computer Science)

G. Smaragdakis – Mentor (TU Delft - Electrical Engineering, Mathematics and Computer Science)

P. Pawelczak – Graduation committee member (TU Delft - Electrical Engineering, Mathematics and Computer Science)

K. Wrona – Mentor ( NATO Communications and Information Agency)

Faculty
Electrical Engineering, Mathematics and Computer Science
More Info
expand_more
Publication Year
2026
Language
English
Graduation Date
17-07-2026
Awarding Institution
Delft University of Technology
Programme
Computer Science
Sponsors
NATO Communications and Information Agency
Faculty
Electrical Engineering, Mathematics and Computer Science
Downloads counter
62
Reuse Rights

Other than for strictly personal use, it is not permitted to download, forward or distribute the text or part of it, without the consent of the author(s) and/or copyright holder(s), unless the work is under an open content license such as Creative Commons.

Abstract

Reliable identification of cooperative UAVs in contested environments remains challenging because infrastructure connectivity cannot be assumed, while persistent identifiers expose friendly assets to passive tracking. Existing Identification Friend or Foe (IFF) systems rely on centralised certificate infrastructures and stable communication links, motivating a privacy-preserving alternative that operates autonomously at the tactical edge. This thesis presents the IFF Relation (RIFF), a non-interactive zero-knowledge attestation protocol in which a prover demonstrates federation membership, possession of an enrolled hardware secret, and valid mission credentials without revealing any underlying attributes, using a single Groth16 proof. The protocol jointly constrains membership and hardware attestation within one zero-knowledge relation, preventing cross-asset credential composition, replay attacks through nonce binding, and attribute disclosure, while enabling independent re-verification by multiple observers. The relation is defined over collision-resistant hash functions and Merkle paths, making it migratable to post-quantum backends, although the current Groth16/BN128 instantiation is not post-quantum secure. A proof-of-concept implementation evaluated on x86-64 and ARM hardware under controlled network impairment and adversarial scenarios completes authentication in under 2.2 s on x86-64 but requires 25-28 s on ARM, constraining feasible encounter distances to over 350 m at typical closure speeds. The results demonstrate that privacy-preserving control-state attestation is achievable on capable platforms, while relay attacks remain unmitigated, enabling an adversary without credentials to be classified as friendly by relaying a legitimate proof. Closing this vulnerability requires distance-bounding or channel-binding mechanisms beyond the current design.

Files

License info not available