Yuji Sang, Chenglong Xu, Long Lv, Lijun Liu · 5 authors
Abstract Aiming at the security issues of open channel vulnerability, limited node resources, and single-point failure caused by centralized authentication in unmanned aerial vehicle (UAV) swarm networks, this paper proposes an authentication and key agreement scheme integrating Physical Unclonable Function (PUF), Chebyshev chaotic map and blockchain. The scheme constructs an integrated architecture of physical security, lightweight encryption and distributed trust, which supports mutual authentication in dual scenarios of UAV-Ground Control Station (GCS) and UAV-UAV. Decentralized trusted authentication is realized via blockchain and smart contracts, ensuring that authentication information is tamper-proof and traceable. Formal security verification based on the ROR model and informal analysis demonstrate that the proposed scheme satisfies multiple security requirements including anonymity and forward secrecy, and can resist common attacks such as replay attack, man-in-the-middle attack and physical capture attack. Performance evaluation results indicate that the scheme completes authentication with only two rounds of interaction. Its computational and communication overheads are significantly lower than those of existing schemes, making it suitable for resource-constrained UAV swarms.
Decentralized unmanned aerial vehicle (UAV) swarms require low-latency peer communication while remaining resilient to spoofing, replay, command injection, key compromise, and malicious membership changes. This study develops a zero-trust communication framework that separates the real-time swarm data plane from a permissioned Byzantine-fault-tolerant trust ledger. The method is grounded in an existing GPS-denied UAV software baseline implementing canonical packet hashing, HMAC-SHA256 authentication, trust epochs, timestamp and sequence freshness checks, onboard security-state transitions, command-policy gating, and firmware trust records. The proposed extension introduces per-node identities, authenticated session establishment, AEAD-protected peer traffic, and event-sparse ledger anchoring for trust-changing evidence. Formal models are derived for message acceptance, trust dynamics, Byzantine tolerance, consensus traffic, storage growth, processing overhead, and energy cost. Under a representative analytical case of 100 swarm messages/s, a 1% anchoring ratio reduces ledger event rate and modeled consensus-control traffic by 100 times compared with per-packet anchoring. Repository benchmark measurements are reported separately from blockchain projections. The analysis supports using blockchain as a decentralized trust anchor rather than as a transport for flight-critical telemetry.
Aircraft maintenance records are critical to airworthiness and asset valuation, yet they are often fragmented across stakeholders, creating verification bottlenecks and information asymmetry that may suppress aircraft residual value. This paper proposes a blockchain-anchored decentralized application (dApp) based on a dual-layer architecture that combines InterPlanetary File System (IPFS)-based off-chain storage with on-chain anchoring of Content Identifiers (CIDs) and selected metadata. With respect to off-chain file size, the on-chain payload per record remains $\mathcal{O}(1)$, compared with $\mathcal{O}(n)$ for direct on-chain file storage. The architecture incorporates metadata and traceability controls informed by Federal Aviation Administration (FAA) electronic recordkeeping guidance. The main contribution is an economic framework that models the relationship between tamper-evident maintenance-record provenance, audit workflow duration, aircraft residual value, and operational cost. In a 7-kB experiment conducted on the BNB Smart Chain testnet, CID anchoring reduced gas consumption by 93.9\% compared with direct on-chain storage. Under explicitly stated scenario assumptions, the audit-cost model indicates potential savings of more than 90\%. These results support the technical feasibility of the prototype and illustrate its economic potential, while the estimated financial benefits remain to be validated using operational data.
A privacy-preserving compliance audit architecture for unmanned aerial vehicle (UAV) swarm operations. The central contribution is a deconfliction-to-containment reduction: rather than comparing n trajectories after the fact (a quadratic, disclosure-bound check), a planner assigns pairwise-disjoint spatial tubes before take-off and establishes their separation once, so that each vehicle subsequently attests only that its own samples stayed inside its own tube. Collision-freedom follows as a consequence (Theorem 2), and the pairwise cost is paid a single time at planning. The commitment layer (Layer 1) is implemented and evaluated as a decision-support audit pipeline that produces non-disclosing, tamper-evident audit artifacts via pre-flight Merkle commitments. It is evaluated in an emulated UAV swarm environment with systematic adversarial injection, in configurations up to 200 vehicles × 500 samples (100,000 sample statements), reporting artifact size, commit/prove/verify/disjunction times, and tamper-detection rates. We then formally identify the security boundary of the implemented layer: it provides coordinate hiding and tamper evidence, but cannot by itself make self-reported containment truthful, which we state as a security game and an impossibility result (Theorem 3). We specify the additional soundness layers (range proof, continuity, provenance and freshness, and aggregation) needed for full containment assurance, proving that composing a knowledge-sound range argument closes the gap (Theorem 4). Throughout, we separate the implemented and measured Layer 1 from the specified and proved—but not yet benchmarked—Layers 2–4, and we make no claim of full zero-knowledge geofence compliance, of swarm-scale deployment, or of deployment readiness.
The aviation industry depends on data integrity across supply chains spanning OEMs, MRO organizations, airlines, lessors, and national regulators. Centralized data management systems — still dominant in the sector — expose the ecosystem to single points of failure and provide limited traceability of millions of aircraft parts circulating annually. This paper presents a structured review of blockchain-based security architectures for aviation networks, synthesized from 14 peer-reviewed sources published between 2018 and 2025, retrieved from IEEE Xplore, ScienceDirect, SpringerLink, ACM Digital Library, and Wiley/Hindawi. On this basis, a thirteen-step design method is proposed for integrating permissioned blockchain with distributed cloud infrastructure in aviation environments. The method is grounded in quantitative acceptance criteria — throughput ≥ 500 TPS, smart contract execution latency < 200 ms (p95), system availability 99.9% — and maps each design phase to specific security controls (integrity, access control, auditability, privacy, resilience, governance). Core mechanisms are formalized via hash-chain integrity verification, attribute-based access control functions, zero-knowledge proof verification, and a composite pre-ledger trust-scoring model. The principal finding: permissioned blockchain architectures — Hyperledger Fabric in particular — can support aviation requirements for immutable audit trails, decentralized identity management, and regulatory compliance with EASA and FAA; adoption remains constrained by organizational readiness and the unresolved GIGO problem at the ledger boundary.
The high-level integration of generative artificial intelligence (AI) in edge computing systems has raised the question of the integrity and reliability of deploying Model-as-a-Service. Edge servers are not required to follow the so-called generative model to minimize computational cost, whereas users and service providers want validation mechanisms that do not compromise proprietary model information. To address this challenge, this study proposes a cooperative unmanned aerial vehicle (UAV)-swarm-enabled zero-knowledge verification framework for secure, privacy-preserving verification of edge-based generative artificial intelligence inference. The proposed framework involves edge servers producing an interactive cryptographic zero-knowledge proof to verify the execution of generative AI, and UAV swarms that fly freely to confirm verification operations, subject to mobility and energy constraints. The age of verification metric is proposed to trust verification information, jointly reflecting the unverified server reliability and verification freshness, and to provide dynamic priority to risky edge servers. To effectively plan the behaviour of a UAV swarm, a trust-based multi-agent reinforcement learning approach is developed that enables decentralized decision-making while training is centralized. Extensive simulation results show that the proposed framework significantly improves the state-of-the-art baseline schemes in verification timeliness, malicious server detection delay, energy efficiency, and scalability. The findings validate that integrating cooperative UAV swarms, trust-aware verification, and multi-agent learning is an efficient approach to providing reliable generative AI services in dynamic edge computing environments.
О. М. Литвинов, О. В. Чуприна, В. О. Гребеніков, М. В. Чуприна
The article explores the concept of containerized mobile hubs as an innovative solution for the infrastructural support of autonomous operations integrating civil aviation and civil unmanned aerial vehicles (UAVs). The relevance of transitioning to flexible, decentralized, and highly automated solutions is substantiated in the context of the development of Advanced Air Mobility (AAM) and Urban Air Mobility (UAM), which require new approaches to ground infrastructure organization. The key problem is identified as the infrastructure gap between the rapid advancement of UAV technologies and the limited capabilities of traditional aeronautical systems.A concept of a mobile hub based on a standardized ISO container (in particular, High Cube or refrigerated type) is proposed. The hub performs the functions of power supply, dispatching, communication, maintenance, and charging of exclusively civil and commercial UAVs. The hub is considered as an intelligent node integrated with civil UTM/U-space systems, ensuring the coordination of manned and unmanned flights within a unified digital airspace. The scope of practical application of the complex is outlined, encompassing environmental monitoring, support for humanitarian missions, and civil protection operations. Existing commercial "drone-in-a-box" solutions are analyzed, and their limitations are identified, including narrow functionality and insufficient mobility.Special attention is paid to the technical aspects of hub implementation, including container design selection, climate control, energy efficiency, and rapid deployment capabilities in environments where stationary infrastructure is absent or damaged. It is demonstrated that the proposed approach significantly reduces operational costs and enables continuous 24/7 operations of civil UAVs.It is concluded that containerized mobile hubs can become a key element in forming a new decentralized aeronautical infrastructure for civil aviation, particularly in the context of the peaceful recovery of Ukraine's transport sector, providing rapid deployment, versatility, and a high level of autonomy.
Open access
UAV Applications and Optimization
Military Technology and Strategies
Advanced Control and Stabilization in Aerospace Systems
As unmanned aerial vehicles (UAVs) become increasingly integral in domains such as agriculture, logistics, and military operations, secure cross-domain authentication mechanisms are essential. Existing centralized protocols are prone to single points of failure, privacy vulnerabilities, and physical capture risks. This paper presents a novel blockchain-based, privacy-preserving authentication protocol for UAVs operating across multiple domains. By combining zero-Knowledge succinct non-interactive arguments of knowledge (zk-SNARKs) and physical unclonable functions (PUFs), the proposed protocol ensures secure identity verification without disclosing sensitive information. The blockchain platform offers a decentralized, tamper-resistant environment for UAV authentication, addressing the challenges of scalability, privacy, and security in cross-domain operations. We demonstrate the security and effectiveness of the protocol through formal and informal security proofs and performance evaluations. The results indicate that the proposed protocol outperforms traditional methods, achieving significant reductions in both computational and communication costs while maintaining high security standards.
Sufian Al majmaie, Ghazal Ghajari, Niraj Prasad Bhatta, Fathi Amsaad
The integration of Fog Computing with Flying Ad-Hoc Networks (FANETs) offers promising capabilities for decentralized, low-latency intelligence in UAV-based applications. However, the distributed nature, mobility, and resource constraints of FANETs expose them to significant security and privacy challenges, particularly against quantum threats. To address these issues, this work introduces a blockchain-based, AI-enhanced key management framework designed for fog-enabled FANETs. The proposed scheme employs a Post-Quantum Multivariate Identity-Based Signature Scheme (PQ-MISS) and Zero-Knowledge Proofs (ZKPs) to achieve secure key establishment, privacy-preserving data aggregation, and integrity verification. A polynomial composition-based encryption mechanism and an aggregate signature model support secure and efficient multi-device communication across fog and UAV layers. Fog servers construct partial blockchain blocks from validated UAV data. These blocks are completed and mined by Cloud Servers (CSs). AI algorithms then analyze the verified data to generate accurate predictions and insights. NS-3 simulations validate the efficiency of PQ-MISS in reducing communication overhead while improving the speed and reliability of data aggregation and verification. Comparative analysis demonstrates the proposed scheme's advantages over existing methods in computational cost, post-quantum security, and scalability, making it a robust solution for secure, intelligent, and future-ready FANET systems.
The following paper presents research aimed at identifying the most critical risks and their mitigations in Urban Air Mobility (UAM) operations. This topic is one of aviation's most significant challenges in the coming decades. Having many flying vehicles in a single airspace requires an innovative approach, rule redefinition, and traffic management. Some solutions are scalable and can be adapted from general aviation. Therefore, stakeholders must address new risks and implement dedicated methods while maintaining the highest level of operational safety. Simulation research is needed to validate solutions before systems operate in real environments. The response to those challenges is the development of a simulation tool that can serve as a test benchmark. The study is divided into two sections: identifying potential risks associated with the rapidly growing UAV market and its applications in urban environments and developing a simulation tool that addresses various Urban Air Mobility challenges. A set of test cases is presented to demonstrate the tool’s functionality and capabilities for further analysis. The paper reviews the United States and European Union approaches to UAM integration, including NASA, FAA, SESAR, and EASA initiatives, and highlights differences in operational concepts and regulatory frameworks. The research identifies major categories of risks related to UAV operations, including technical failures, environmental hazards, human factors, and cybersecurity threats. Long-term challenges associated with increasing traffic density, autonomous operations, and airspace organization are also discussed. The research evaluates scalable safety solutions derived from commercial aviation and analyzes urban airspace concepts such as layers, zones, sky-lanes, and sky-corridors. The developed simulation environment, implemented for the Warsaw metropolitan area, enables modeling of large-scale UAV and VTOL operations, no-fly zones, vertiport hubs, and traffic distribution. The results demonstrate the importance of dedicated traffic structures, altitude separation, and decentralized traffic management systems in ensuring safe and efficient Urban Air Mobility operations.
Secure cross-domain UAV authentication is challenging because identity verification alone is insufficient to guarantee safe operation. In many UAV applications, it is equally critical to verify that a UAV is currently located within an authorized geographic region. Existing approaches often expose precise GPS coordinates, rely on static identifiers that enable tracking, or fail to guarantee the freshness and authenticity of location evidence. These weaknesses allow replay, location spoofing, and trajectory inference attacks, especially in multi-domain environments. To address these limitations, we propose PrivLocAuth, a zero-knowledge-based cross-domain UAV authentication protocol that enforces geofence restrictions without revealing actual locations. In PrivLocAuth, UAVs encode their current coordinates into fresh Pedersen commitments, which are attested by the home Local Domain Server (LDS) using short-lived Schnorr signatures. Based on these attested commitments, UAVs generate Bulletproof range proofs to demonstrate compliance with cross-domain server-defined geofences. This design ensures that UAVs operate within authorized airspace while preserving strong location privacy. PrivLocAuth further incorporates a lightweight elliptic curve cryptography (ECC) and Schnorr signature-based credential framework that enables unlinkable authentication across-domains, preventing session correlation and identity tracking. Formal security analysis demonstrates resistance to impersonation, replay, geofence-bypass, and linkage attacks. Experimental evaluation shows low computational latency and minimal communication overhead, confirming the protocol’s suitability for resource-constrained UAV platforms operating in dynamic cross-domain environments.
SATHISHKUMAR RANGANATHAN, Muralindran Mariappan, M. Karthigayan
Swarm robotics is an emerging field capable of accomplishing complex tasks through collective behaviour. However, it continues to face persistent challenges in secure communication, decentralized decision-making, and scalability. To operate effectively in resource-constrained environments, swarm networks require a decentralized mechanism that is secure, fast, and efficient. Although many studies have explored the use of blockchain technology for swarm robotics, existing blockchain consensus algorithms such as Proof of Work (PoW), Proof of Stake (PoS), and their variants remain unsuitable due to high computational complexity and risk of stake centralization. To address these challenges, we introduce the blockchain-based Rotational Leadership Role (RLR) consensus algorithm, a voting-based consensus re-engineered from the Raft approach, together with Decentralized Task Authorization and Validation (DeTAV), a token-based mechanism for context-aware task validation. This design ensures efficiency, security, and scalability in swarm robotics and drone systems. RLR is lightweight and well suited to operate within the limited computing resources of small robots or aerial drones. To validate its performance, a custom-built robotic simulator was developed as part of this research. Experiments conducted with up to 70 concurrent robots demonstrated that RLR consumed under 90 MB Random Access Memory (RAM) and 12% Central Processing Unit (CPU), whereas PoW required 460 MB RAM and 27% CPU with a minimum difficulty level of 21, reflecting an 80% reduction in memory usage and a 55% reduction in CPU consumption. Scalability tests with 4 to 70 robots further revealed RLR’s scalability with an average of 78% higher throughput, 47% lower election latency, and 34% lower consensus latency. Additionally, under the simulated attack scenarios and assuming uncompromised cryptographic keys, DeTAV’s context-based validation consistently achieved 100% success in detecting and isolating Byzantine nodes, while reducing Quality of Detection (QoD) time by 67%. Collectively, these results confirm that RLR with DeTAV effectively meets the efficiency, security, and scalability requirements of swarm robotic and drone networks.
Digital twins are digital representations that enable real-time monitoring, analysis, andprediction of outcomes of physical systems. They depend on continuous communicationto work, which increases the attack surface of the system and introduces security risks,especially regarding unauthorized access to digital twin data and operations. This thesisinvestigates how blockchain-based smart contracts can be used as an authorization mech-anism for a digital twin, by implementing a digital twin for a Crazyflie 2.1 and controllingaccess to it through a smart contract-based authorization layer.A prototype of this system was developed using Python and connected to the physicalUAV using the Crazyradio interface. Flight data was collected and used to identify a sim-plified digital twin representing the vertical subsystem. A blockchain-based authorizationlayer with role-based permissions was then implemented using Solidity smart contracts ina local Hardhat environment.The findings from this thesis show that such a system is feasible to implement. Flighttest runs show that the twin remained numerically stable at all times and estimated thephysical UAV’s state with bounded error. The authorization mechanism enforced the de-fined role-based access-control rules in the tested scenarios, with measured authorizationlatency in the local environment around 14–15 ms. Gas measurements were also used toestimate the relative computational cost of the smart contract operations.
Distributed spectrum allocation for large-scale UAV swarm remains a challenging issue, due to spectrum allocation collisions and the high communication overhead required to reach consensus. To address these challenges, we propose a lightweight consensus protocol for distributed collision-free spectrum allocation (LCCFSA), where UAV nodes in the swarm form a blockchain and spectrum allocation consensus is reached on the chain. Specifically, a fast low-complexity allocation scheme is developed for each UAV based on an interference graph, where each UAV adaptively adjusts its occupancy area to avoid mutual interference. To further reduce the consensus overhead, we design a lightweight consensus protocol with a transaction-based blockchain ledger and provide a formal security analysis of the proposed protocol. A prototype is built to validate the feasibility of the proposed scheme. Simulation results show that the average consensus latency can be reduced by more than 20% in scenarios with 100 consensus nodes.
Abdullah Aljumah, Tariq Ahamed Ahanger, Imdad Ullah
Unmanned Aerial Vehicles (UAVs) are increasingly deployed across diverse domains such as surveillance, logistics, and disaster management. However, ensuring the safety, security, and trustworthiness of UAV operations remains a significant challenge, primarily due to vulnerabilities in centralized data processing architectures. Traditional UAV systems rely on remote cloud servers to perform machine learning (ML)-based analytics, which introduces issues such as data exposure, latency, scalability bottlenecks, and susceptibility to cyberattacks during data transmission and storage. These challenges underscore the urgent need for a decentralized, verifiable, and privacy-preser ving learning mechanism that can support collaborative UAV intelligence without centralized control. To address these limitations, this study proposes a blockchain-enabled distributed ML framework that facilitates secure, peer-to-peer collaboration among UAV nodes. The framework integrates blockchain’s immutable ledger and smart contracts with decentralized ML models, enabling UAVs to share and validate trained models rather than raw data. This ensures data confidentiality, integrity, and transparency throughout the learning process. A stacking-based ensemble mechanism is employed to enhance predictive performance through collaborative knowledge aggregation. The proposed system is experimentally validated using a collaborative intrusion detection (ID) scenario using the KDD99 network attack data set and real-world implementation. The results demonstrate significant improvements in detection accuracy, latency and F1-score compared to conventional centralized ML methods, achieving an average accuracy of 97.9%, latency 198ms, and F1-score exceeding 97%. These outcomes confirm that the integration of blockchain and decentralized ML effectively mitigates cybersecurity risks while enabling scalable, trustworthy UAV intelligence.
Vehicular ad-hoc networks (VANETs) play a vital role in enhancing modern transportation systems, facilitating real-time data exchange in dynamic environments. However, VANETs face challenges such as limited range and interference in dense areas. This paper introduces an unmanned aerial vehicle (UAV)-aided reputation-based cluster routing (URCR) protocol to address issues such as improving data transmission, reducing delay, and lowering hop count. The proposed URCR protocol utilizes VANET clustering, UAV-aided communication, and a Proof-of-Stake based cluster head-toggling algorithm to achieve balanced energy consumption. Blockchain-based reputation management is integrated into the protocol to evaluate the trustworthiness of the member nodes and prevent malicious behavior in the VANET. Simulations using Network Simulator 3 show that URCR improves the average hop count by 47.6% and 15.2%, the packet delivery ratio by 22.9% and 4.3%, and the end-to-end delay by 48.8% and 22.3%, compared to drone-assisted cooperative routing (DACR) and VANET routing with UAV assistance (VRU), respectively.
The integration of decentralized security mechanisms into smart drone surveillance systems marks a transformative advancement in the field of unmanned aerial monitoring. Traditional centralized architectures are often vulnerable to single points of failure, data breaches and latency issues specifically in case of operation in hostile or remote environments. By leveraging blockchain technology, drone networks can establish a tamper-proof, distributed ledger that ensures the integrity and authenticity of surveillance data in real time. Internet of Drones is a decentralized network linking drones access to controlled airspace, providing high adaptability to complex scenarios and services to various drone applications such as package delivery, traffic surveillance and rescue including navigation services. One of the potential methods to enhance user privacy, data security and authentication, especially in peer-to-peer UAV networks is blockchain technology, which has now been gained prominence.
Drone delivery services are encountering issues related to transparency, authenticity, and safeguarding privacy, highlighting the urgent need for an innovative approach that incorporates blockchain technology. This innovation aims to solidify the permanence of records, enable instantaneous verification, and streamline data handling in these intricate, self-operating transactions. In this paper, we use of blockchain for creating Non-Fungible Tokens (NFTs), which act as unalterable logs of purchase within the realm of delivery logistics. Our method adopts a distinctive two-fold strategy that places equal emphasis on both tangible goods and information. When integrating our solution with the Polygon network, we have achieved a substantial reduction in the costs associated with transactions while simultaneously enhancing the speed at which these transactions are processed. Our work not only addresses the existing challenges faced by unmanned aerial vehicle (UAV) communication systems but also sets a new standard for efficiency and security in the delivery logistics sector, paving the way for more reliable and transparent UAV-based delivery services.
The integration of Uncrewed Aerial Vehicles (UAVs) into low-altitude airspace has led authorities to adopt distributed Uncrewed Traffic Management (UTM) architectures that ensure interoperability and safety. Blockchain has been proposed as an enabler for trustworthy coordination among UTM stakeholders. Yet, its real-time performance under aeronautical constraints remains insufficiently characterized. This paper presentes a quantitative benchmark comparing two regulation compliant distributed architectures: the federated InterUSS platform maintained by the Linux Foundation and a permissioned blockchain based on Hyperledger Fabric. Both systems were evaluated through Operational Intent Reference (OIR) registration work loads generated via Hyperledger Caliper, measuring throughput, latency, and transaction loss under loads up to 50 transactions per second. Results show that InterUSS sustained sub-second latency and stable performance up to 30 TPS. At the same time, Fabric exhibited exponential degradation with median latency exceeding 3 s and tail latencies above 15 s beyond that point. These findings demonstrate that blockchain-based architectures must be redesigned to meet aeronautical timing and scalability requirements, suggesting that hybrid models combining distributed ledgers for auditability with federated frameworks for real-time coordination are more suitable for future UTM deployments.
Unmanned Aerial Vehicles (UAVs) are increasingly deployed in inspection and monitoring missions, yet onboard computation and communication impose significant energy burdens that limit flight time and operational scope. In this work, we introduce a novel, blockchain-enabled framework-grounded in the Distributed Autonomous Organization (DAO) paradigm-for orchestrating distributed analytics across a swarm of UAVs. Leveraging the OASEES project's smart-contract architecture, each drone embeds a Metrics Module for real-time power monitoring, a Behavioral Module for adaptive control, and a Blockchain Agent that autonomously proposes, votes on, and executes collective decisions. Three concurrent threads-Proposal Trigger, Voting, and Action Execution-enable fully decentralized governance of swarm behavior: from detecting critical energy thresholds and formulating swarm-wide conservation maneuvers, to executing approved strategies across all members. We validate our framework in a UAV-based infrastructure inspection scenario, employing a YOLOv5 object-detection pipeline to classify four corrosion classes on a telecommunications mast under three video-capture modalities (short-distance, long-distance, and horizontally concatenated streams). Across all configurations, our system achieves near-perfect precision, recall, and mean Average Precision (mAP50-95$\approx 0.995$), demonstrating both the efficacy of distributed workload inference and the feasibility of treating a single drone as a multi-feed processor. These results underscore the potential of DAO-driven UAV swarms for energy-aware, resilient aerial analytics, and pave the way for fully decentralized 5G/6G-enabled airborne networks.
The proliferation of unmanned aerial vehicle (UAV) swarms in mission-critical applications for 6G and the Internet of Things (IoT) introduces significant security vulnerabilities stemming from their dynamic, distributed, and resource-constrained nature. Traditional security paradigms are often inadequate for these complex cyber-physical systems. This paper proposes a novel, cross-layer security framework that ensures robust and lightweight operation for UAV swarms. The framework is founded on a novel Entropy-Derived Physically Unclonable Function (EPUF) based on DRAM, which employs a data-driven characterization process designed to achieve near 100% reliability in simulation through a data-driven characterization process, which is validated through extensive simulation, addressing a critical limitation of conventional PUFs. To counteract sophisticated threats, we formulate the key management problem as a Markov Decision Process (MDP) and introduce a deep reinforcement learning (DRL) agent that dynamically optimizes key update frequency, balancing security posture against energy consumption. Furthermore, we leverage a lightweight, permissioned blockchain as a decentralized trust anchor for public key management, providing an immutable and resilient ledger and enhancing the principles of distributed and edge intelligence. The core authentication protocol's security is formally verified using the ProVerif tool and Belief Logic, proving its robustness against a Dolev-Yao adversary. Experimental simulations demonstrate that our framework significantly outperforms conventional methods, reducing authentication latency and energy consumption by over 95% compared to PKI-based schemes while effectively mitigating replay and impersonation attacks.