项目概览
Overview
基于轻量级安全通信协议的机器人快递交付系统
Design, analysis and implementation of a smart next generation secure shipping infrastructure using autonomous robot
GitHub github.com/Jiapei-Yang/Secure-Robotic-Shipping
论文 Paper doi.org/10.1016/j.comnet.2020.107779 · 开放稿open manuscript
面向机器人最后一公里配送:默认以轻量级密码学协议完成离线认证;扫码反复失败时切到视觉路径(行人检测 + Siamese Person Re-ID),找到收件人后再回到认证与交付。 若超时仍未完成扫码、重识别多次失败或二次认证仍失败,则中止投递。整条链路在 TurtleBot3 真机上跑通,并用 ProVerif 对协议做了形式化分析。
Built for robotic last-mile delivery: the default path authenticates offline with a lightweight cryptographic protocol; after repeated QR failures it switches to vision (pedestrian detection + Siamese person re-identification), then returns to authentication and delivery once the recipient is found. If scanning times out, re-identification fails repeatedly, or secondary authentication still fails, the delivery is aborted. The full loop runs on a TurtleBot3, with the protocol analyzed in ProVerif.
设计原则:交付必须可验证;认证可以降级,身份判断不能含糊 Scope: cooperative offline authentication, non-cooperative person re-ID, TurtleBot3 demo, ProVerif analysis
Design rule: delivery must be verifiable—fallback is allowed, ambiguous identity is not
核心能力
Capabilities
系统由三条互相咬合的能力组成:主路径认证、失败时的视觉降级,以及真机与安全验证。
Three interlocking pieces: the primary auth path, a vision fallback when that path fails, and hardware plus security validation.
- 合作式离线认证 Cooperative offline authentication 客户、服务端与机器人三端协议:一次性密钥、nonce 与 QR 密文比对。收件人出示二维码即可完成验证,无需长期在线。 A client–server–robot protocol with one-time keys, nonce, and encrypted QR matching. The recipient authenticates by presenting a QR code—no long-lived online session required.
- 非合作降级:检测 + Siamese Re-ID Non-cooperative fallback: detection + Siamese Re-ID 扫码连续失败后切换模式:机器人拍摄现场、检测行人,再用度量学习判断是否为客户本人;确认后再回到扫码交付。 After repeated QR failures, the robot captures the scene, detects pedestrians, and uses metric learning to decide whether the person matches the client—then returns to QR delivery.
- 真机闭环与形式化安全分析 Hardware loop and formal security analysis 在 TurtleBot3 上完成导航与交付演示;用 ProVerif 分析协议在泄露、伪造等威胁下的性质;并以一作论文固化设计与实验结论。 Navigation and delivery are demonstrated on TurtleBot3; ProVerif analyzes the protocol against threats such as disclosure and forgery; the design and results are recorded in a first-author paper.
系统流程
How it works
主路径走合作认证;扫码连续失败后进入视觉找人,成功后再回到扫码交付。超时未扫码、重识别多次失败,或二次认证仍失败时,任务中止。
Cooperative QR auth is the main path. After repeated scan failures, vision search runs; on success the system returns to QR delivery. Timeout without a scan, repeated Re-ID failures, or another failed auth round aborts the job.
实现与演示
Demo evidence
下面是系统设计图与真机过程截图,点击可全屏查看。
System design figures and hardware captures below—click any image to enlarge.
系统总览
System overview
整体结构、双模式认证设计,以及实现拓扑。
Overall architecture, dual-mode authentication design, and implementation topology.
fig1
fig2
fig3
合作认证 · 真机
Cooperative authentication on hardware
机器人导航到达后扫描二维码,密文比对通过即完成交付。
After navigation, the robot scans the QR code; a ciphertext match completes delivery.
fig4
fig5
fig6
非合作降级 · Re-ID
Non-cooperative fallback with Re-ID
扫码失败后切换模式,检测行人并用重识别确认客户身份。
After QR failure, the system switches modes, detects pedestrians, and confirms identity with re-identification.
fig7
fig8
fig9
回到合作认证 · 完成交付
Return to cooperative auth and finish
找到收件人后再次扫码,匹配成功后结束任务。
Once the recipient is found, QR authentication runs again and the task completes on a successful match.
fig10
fig11
演示视频
Demo videos
真机与仿真录屏,托管在 YouTube。
Hardware and simulation recordings hosted on YouTube.
技术取舍
Tech choices
- TurtleBot3 + ROS — 用真机验证导航与交付,而不只停留在仿真。 — to validate navigation and delivery on real hardware, not only in simulation.
- Crypto + QR(hash / asymmetric / nonce) — 合作路径可离线验证,并减少长期密钥暴露。 — keeps the cooperative path offline-verifiable and limits long-lived key exposure.
- Siamese Network · Person Re-ID — 用度量学习回答「是不是同一个人」,覆盖收件人不配合的场景。 — metric learning answers “same person or not” when the recipient cannot cooperate.
- CUHK01 — 用于训练与 CMC 评测的公开行人重识别数据集。 — a public person Re-ID dataset for training and CMC evaluation.
- ProVerif — 对合作协议做形式化分析,覆盖泄露、伪造等威胁模型。 — formal analysis of the cooperative protocol under threats such as disclosure and forgery.
结果与边界
Outcomes & boundaries
- 发表:一作发表于 Computer Networks(Elsevier, 2021),覆盖系统设计、真机实现与安全分析。
- Publication: first-author paper in Computer Networks (Elsevier, 2021), covering system design, hardware implementation, and security analysis.
- 系统:合作认证与非合作 Re-ID 降级均可在真机路径演示;协议经 ProVerif 分析。
- System: both cooperative auth and the non-cooperative Re-ID fallback are demoable on hardware; the protocol is analyzed with ProVerif.
- 边界:Re-ID 使用经典 Siamese 与 CUHK01,目标是配送系统里可靠的降级模块,而不是视觉方向的 SOTA 模型。
- Boundary: Re-ID uses a classic Siamese setup on CUHK01—intended as a reliable fallback inside the delivery system, not a vision SOTA model.
论文开放稿: White Rose Research Online
Open-access manuscript: White Rose Research Online
项目链接
Links
- 代码与说明: Code and notes: github.com/Jiapei-Yang/Secure-Robotic-Shipping
- DOI: 10.1016/j.comnet.2020.107779
- 开放稿: Open manuscript: eprints.whiterose.ac.uk/172499
- 本站案例: This case page: www.yangjiapei.com/cases/robotic-shipping
- 本站源码: Site source: github.com/Jiapei-Yang/portfolio
- ← 返回作品集首页← Back to portfolio home