Identity authentication and access control method and device for low-altitude aircraft

Through the dynamic multi-factor authentication mechanism and an AI-driven intelligent decision-making engine, the authentication factor combination is generated, which solves the security and efficiency problems of the low-altitude aircraft identity authentication system, and realizes intelligent security control in complex environments, which is suitable for high-density low-altitude traffic scenarios.

CN120301715AActive Publication Date: 2025-07-11SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD

Patent Information

Application Number
CN202510780977.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-12
Publication Date
2025-07-11
Estimated Expiration
2045-06-12

AI Technical Summary

Technical Problem

The existing low-altitude aircraft identity authentication system lacks dynamic adaptability and cannot intelligently adjust the authentication strength based on real-time environmental parameters and equipment status, resulting in insufficient security and inefficient efficiency, especially in high-risk scenarios that are prone to illegal access missed judgments.

Method used

The dynamic multi-factor authentication mechanism is adopted and combined with an AI-driven intelligent decision-making engine. By obtaining environmental data, device status and historical authentication logs, a pre-trained deep reinforcement learning model is used to generate authentication factor combinations, actively identify forged or abnormal devices, and authenticate through main factors and backup factors, and dynamically adjust the permission level and access scope.

Benefits of technology

It has achieved the improvement of certification safety and efficiency in complex airspace environments, and can flexibly respond to high-risk scenarios, ensuring that the system automatically implements strict control under conditions such as signal interference and positioning deviations. It is suitable for high-density, multi-type, and dynamically changing low-altitude traffic scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120301715A_ABST
    Figure CN120301715A_ABST
Patent Text Reader

Abstract

The invention provides an identity authentication and access control method and device for a low-altitude aircraft, and the method comprises the steps: obtaining environment data, equipment state data and a historical authentication log of the low-altitude aircraft, and obtaining collection data; inputting the collected data into an AI decision engine, and generating an authentication factor combination through a pre-trained deep reinforcement learning model to obtain a main factor and a standby factor; performing identity authentication of the aircraft by using the main factor, and when the matching degree of the identity authentication of the main factor is in a preset interval, triggering a standby factor to perform secondary identity authentication to obtain an authentication result; and an access token is generated according to the authentication result and the risk assessment model, and the aircraft performs access control according to the access token. The invention relates to the field of low-altitude security management and control, and solves the technical problems that the identity authentication security of a low-altitude aircraft is insufficient and the low-altitude aircraft cannot dynamically adapt to a complex airspace environment in the prior art.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of low-altitude security control, and specifically relates to an identity authentication and access control method for low-altitude aircraft. Background Art

[0002] With the wide application of low-altitude aircraft, their identity authentication and access control have become key links in airspace security management. The current mainstream authentication systems are mostly based on static multi-factor authentication mechanisms, such as fixed combination key authentication, digital certificates, or geofencing technology. However, the identity authentication strategies of existing solutions lack dynamic adaptability and cannot intelligently adjust the authentication intensity according to real-time environmental parameters and device status, resulting in insufficient security protection in high-risk scenarios, easy omission of illegal access judgments, and thus the risk of single-point breakthrough. In addition, traditional systems often sacrifice efficiency in high-density low-altitude traffic scenarios in exchange for security by prolonging the authentication time. Summary of the Invention

[0003] This application provides an identity authentication and access control method and device for low-altitude aircraft, which solves the technical problems of insufficient security in the identity authentication of low-altitude aircraft and inability to dynamically adapt to complex airspace environments in the prior art.

[0004] To achieve the above object, this application adopts the following technical solutions: In the first aspect, an identity authentication and access control method for low-altitude aircraft is provided, including: Obtain the environmental data, device status data, and historical authentication logs of the low-altitude aircraft to obtain the collected data; Input the collected data into the AI decision engine, and generate an authentication factor combination through a pre-trained deep reinforcement learning model to obtain a primary factor and a backup factor; wherein, the authentication accuracy of the authentication method of the backup factor is higher than that of the primary factor; Use the primary factor to authenticate the identity of the aircraft. When the matching degree of the primary factor identity authentication is within a preset range, trigger the backup factor for secondary identity authentication to obtain an authentication result; Generate an access token according to the authentication result and the risk assessment model, and the aircraft performs access control according to the access token; wherein, the access token is used to describe the relationship between the permission level, the authentication factor, and the environmental data, and the risk assessment model is built into the AI decision engine.

[0005] Based on the above technical solution, the identity authentication and access control method for low-altitude aircraft provided by this application can flexibly generate factor authentication combinations through a dynamic multi-factor authentication mechanism, combined with an AI-driven intelligent decision-making engine, actively identify forged or abnormal devices, and effectively intercept illegal access behaviors. The environmental risk model can evaluate complex airspace conditions in real time, dynamically adjust the permission level and access range, ensure strict control is automatically implemented in high-risk scenarios such as signal interference and positioning deviation, and can significantly improve airspace security.

[0006] Combined with the first aspect above, in a possible implementation manner, the collected data includes: Environmental data including signal strength, spectrum interference value, horizontal dilution of precision, temperature, humidity, and air pressure; Device status data including the remaining battery capacity of the aircraft, CPU or GPU load, remaining storage space, and the altitude, speed, and heading of the flight; Authentication logs including the authentication results, authentication time consumption, authentication factor combinations, and corresponding environmental data and device status data of recent multiple identity authentications.

[0007] Combined with the first aspect above, in a possible implementation manner, the AI decision-making engine includes: A decision generation unit for processing the collected data using a built-in deep reinforcement learning model and outputting an authentication factor combination; A risk assessment unit for calculating the environmental risk coefficient according to the environmental data using a built-in risk assessment model.

[0008] Combined with the first aspect above, in a possible implementation manner, calculating the environmental risk coefficient according to the environmental data using the risk assessment model includes: Normalizing the numerical values of each index in the environmental data to obtain the normalized values of each index, including: Normalize the signal strength RSSI to obtain the signal normalized value RSSI norm , and the calculation formula is: ; where RSSI min represents the preset lower limit of signal strength, and RSSI max represents the preset upper limit of signal strength; Normalize the horizontal dilution of precision HDOP to obtain the positioning precision normalized value HDOP norm , and the calculation formula is: ; Calculate the spectrum normalized value Interf norm according to the formula: ; where Interf k represents the spectrum interference value of the kth frequency band, and Nbands Indicates the number of monitored frequency bands, Interf max Indicates the maximum spectrum interference value; The temperature normalization value is calculated according to the formula T: ; where T opt Indicates the ideal temperature value, T max Indicates the maximum temperature deviation value; The air pressure normalization value is calculated according to the formula P: ; where P std Indicates the standard air pressure value, P max Indicates the maximum air pressure deviation value; The humidity normalization value is calculated according to the formula H: ; where H thr Indicates the preset humidity threshold, H max Indicates the maximum humidity deviation value, ReLU() represents the ReLU function; The normalization values of the above indicators are weighted and summed to obtain the calculated environmental risk coefficient R env Risk assessment model, the formula is: R env =w s ×(1 - RSSI norm ) + w i ×Interf norm +w h ×HDOP norm +w t × T + w p × P + w hum × H; where w s , w i , w h , w t , w p , w hum respectively represent the coefficients of each item, and the sum is 1.

[0009] Combined with the first aspect above, in a possible implementation manner, the training process of the pre-trained deep reinforcement learning model includes: Set the state space, action space and reward function of the deep reinforcement learning model; where, The construction of the state space is: collect historical authentication logs, where each authentication log includes a timestamp, an authentication result, an authentication time consumption, an authentication factor combination, environmental data, and device status data; Normalize each piece of data in the historical authentication log and then splice them to obtain the state space. Among them, the authentication result is normalized using the binary method: 0 represents authentication failure, 1 represents authentication success, and the combination of authentication factors is normalized using the one-hot encoding method. The definition rule of the action space is: Define the predefined authentication factor library as the action space, and each action in the action space corresponds to a factor combination strategy. A factor combination strategy includes at least one primary factor and at least one backup factor. The calculation formula of the reward function R is: ; where, AS ∈ {0, 1} represents the authentication result, TS’ represents the normalized authentication time, and R env represents the environmental risk coefficient calculated by the risk assessment model, α1, α2, and α3 respectively represent the weight coefficients of each item, and β represents the fixed penalty value for authentication failure. Adopt the deep Q-network or proximal policy optimization algorithm to construct a deep reinforcement learning model. The input layer dimension of the deep reinforcement learning model is the dimension of the state space, and the output layer dimension is the size of the action space. Use the historical authentication log to iteratively train and optimize and verify the deep reinforcement learning model to obtain a pre-trained deep reinforcement learning model with the input data being the collected data and the output being the optimal combination of authentication factors including the primary factor and the backup factor.

[0010] Combined with the first aspect above, in a possible implementation, the primary factors include but are not limited to the following authentication methods: multi-band radio frequency fingerprint authentication, key authentication, digital certificate authentication, and geofence authentication. Among them, the geofence authentication means identity authentication by comparing the real-time position of the low-altitude aircraft with the preset geofence database. The backup factors include but are not limited to the following authentication methods: biometric authentication, blockchain identity traceability authentication. Among them, the biometric authentication includes but is not limited to fingerprint authentication, face authentication, and voiceprint authentication of the staff. The blockchain identity traceability authentication means verifying the historical flight records and working status of the low-altitude aircraft through a smart contract. When the low-altitude aircraft has no historical flight records, or the working status is revoked or unknown, the verification fails. The authentication factor library includes but is not limited to all the authentication methods included in the primary factors and the backup factors.

[0011] Combined with the first aspect above, in a possible implementation, the matching degree of the primary factor identity authentication includes: When the main factor is multi - band RF fingerprint authentication, the RF matching degree S is obtained by calculating the cosine similarity between the feature vectors of each band and the registered template and performing weighted summation. RF , and the calculation formula is: ; where n represents the number of bands, Interf i represents the spectral interference value of the i - th band, and S RF,i represents the cosine similarity between the feature vector of the i - th band and the registered template. When the main factor is key authentication, when the decrypted challenge value is the same as the original challenge value sent by the authentication system, or when the decrypted message authentication code is the same as the message hash value locally calculated by the authentication system, the key matching degree S resp is calculated according to the deviation T Key between the decrypted timestamp and the current time of the authentication system, and the formula is: ; where T th represents the preset time threshold. When the main factor is digital certificate authentication, the calculation formula of the certificate matching degree S Cert is ; where Valid chain ∈ {0, 1}, representing the certificate chain verification result, and Valid chain = 1 indicates that the certificate chain is valid, Valid chain = 0 indicates that the certificate chain is invalid, and Valid signature ∈ {0, 1} represents the signature verification result, and Valid signature = 1 indicates that the signature is valid, Valid signature = 0 indicates that the signature is invalid, and γ1, γ2 represent weight coefficients, and their sum is 1. When the main factor is geofence authentication, the minimum distance D between the real - time position of the low - altitude aircraft and the geofence is calculated min , and the geographical matching degree S th is calculated according to the preset distance threshold d Geo , and the formula is: .

[0012] Combined with the above - mentioned first aspect, in a possible implementation manner, when the main factor includes multiple authentication methods, the matching degree of the main - factor identity authentication is the average of the matching degrees of these multiple authentication methods.

[0013] Combined with the above - mentioned first aspect, in a possible implementation manner, the generating of the access token according to the authentication result and the risk assessment model includes: When the main - factor authentication is successful or the backup - factor authentication is successful, the environmental risk coefficient R env calculated according to the risk assessment model and the number N factorCalculate the permission value P using the formula: ; where λ1 and λ2 represent the weight coefficients of each item, and their sum is 1, η represents the amplification factor with a value of 10, and the number of authentication factors represents the total number of triggered primary factors and / or backup factors; When the permission value is within the preset first interval, allocate the operation permission and token validity period corresponding to the first permission; When the permission value is within the preset second interval, allocate the operation permission and token validity period corresponding to the second permission; When the permission value is within the preset third interval, allocate the operation permission and token validity period corresponding to the third permission; Generate an access token based on the signature algorithm, and the access token includes the operation permission and the token validity period.

[0014] Based on the above technical solution, this application realizes the leap from fixed-policy authentication to intelligent adaptive authentication, significantly improving the authentication efficiency and flexibility of low-altitude aircraft in complex environments while ensuring security, and is particularly applicable to future high-density, multi-type, and dynamically changing low-altitude traffic scenarios.

[0015] In a second aspect, there is provided an identity authentication and access control device for low-altitude aircraft, including: a communication unit and a processing unit; the communication unit is used to obtain the collected data including the environmental data, device status data, and historical authentication logs of the low-altitude aircraft, and is also used to transmit the identity authentication result and the access token; The processing unit is used to input the collected data into the AI decision engine, generate an authentication factor combination through a pre-trained deep reinforcement learning model to obtain the primary factor and the backup factor; use the primary factor for the identity authentication of the aircraft, and when the matching degree of the primary factor identity authentication is within the preset interval, trigger the backup factor for secondary identity authentication to obtain the authentication result; generate an access token according to the authentication result and the risk assessment model, and the aircraft performs access control according to the access token.

[0016] In a third aspect, this application provides an identity authentication and access control device for low-altitude aircraft, including: a processor and a storage medium; the storage medium includes instructions, and the processor is used to run the instructions to implement the method described in the first aspect and any possible implementation manner of the first aspect. The identity authentication and access control device for low-altitude aircraft can be an electronic device or a chip in an electronic device.

[0017] In a fourth aspect, this application provides an identity authentication and access control system for low-altitude aircraft, including: A data acquisition module, which is used to obtain the environmental data, device status data, and historical authentication logs of the low-altitude aircraft to obtain the collected data; An AI decision-making engine module for processing the collected data, generating a combination of authentication factors through a pre-trained deep reinforcement learning model, and calculating the environmental risk coefficient using a risk assessment model based on environmental data; An identity authentication module for authenticating the identity of the aircraft using the primary factor, triggering a secondary authentication using the backup factor when the matching degree of the primary factor identity authentication is within a preset range and obtaining an authentication result, and generating an access token based on the authentication result and the environmental risk coefficient, and the aircraft performs access control based on the access token.

[0018] In a fifth aspect, the present application provides a computer-readable storage medium, in which instructions are stored. When the instructions run on an identity authentication and access control device for low-altitude aircraft, the identity authentication and access control device for low-altitude aircraft is caused to execute the methods described in the first aspect and any possible implementation manner of the first aspect.

[0019] In a sixth aspect, the present application provides a computer program product containing instructions. When the computer program product runs on an identity authentication and access control device for low-altitude aircraft, the identity authentication and access control device for low-altitude aircraft is caused to execute the methods described in the first aspect and any possible implementation manner of the first aspect.

[0020] The present application provides an identity authentication and access control method and device for low-altitude aircraft, which can flexibly generate a factor authentication combination through a dynamic multi-factor authentication mechanism combined with an AI-driven intelligent decision-making engine, actively identify forged or abnormal devices, and effectively intercept illegal access behaviors; real-time evaluate complex airspace conditions, dynamically adjust the permission level and access range, ensure strict control is automatically implemented in high-risk scenarios, significantly improve airspace security, authentication efficiency and flexibility, and are applicable to low-altitude traffic scenarios with high density, multiple types and dynamic changes.

[0021] It should be understood that the description of technical features, technical solutions, beneficial effects or similar languages in the present application does not imply that all features and advantages can be achieved in any single embodiment. On the contrary, it can be understood that the description of features or beneficial effects means that at least one embodiment includes specific technical features, technical solutions or beneficial effects. Therefore, the descriptions of technical features, technical solutions or beneficial effects in this specification do not necessarily refer to the same embodiment. Furthermore, the technical features, technical solutions and beneficial effects described in this embodiment can be combined in any appropriate manner. Those skilled in the art will understand that an embodiment can be implemented without one or more specific technical features, technical solutions or beneficial effects of a specific embodiment. In other embodiments, additional technical features and beneficial effects can also be identified in specific embodiments that do not embody all embodiments.

[0022] Compared with the prior art, the beneficial effects of the present invention are as follows: By combining a dynamic multi-factor authentication mechanism with an AI-driven intelligent decision-making engine, the present invention significantly improves the security and flexibility of low-altitude aircraft authentication. Specifically, the system collects environmental data, device status data, and historical authentication logs, and uses a pre-trained deep reinforcement learning model to dynamically generate combinations of primary factors and backup factors, which can actively identify forged or abnormal devices and effectively intercept illegal access behaviors. For example, the primary factors include multi-band radio frequency fingerprint authentication, key authentication, etc., and the backup factors cover biometric authentication, blockchain identity traceability authentication, etc. Through the collaborative verification of multiple factors, a multi-level security protection system is constructed; In terms of risk control and permission management, the built-in environmental risk assessment model can analyze multi-dimensional data such as signal strength, spectrum interference, and positioning accuracy in real time, generate an environmental risk coefficient through normalization processing and weighted calculation, and dynamically adjust the permission level and access scope accordingly. When the matching degree of the primary factor authentication is within a preset range, the system automatically triggers the backup factor for secondary authentication; at the same time, an access token including the permission level and validity period is generated according to the authentication result and the risk coefficient, ensuring strict control is automatically implemented in high-risk scenarios such as signal interference and positioning deviation, and realizing the dynamic adaptation of security policies to environmental changes. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention, and those of ordinary skill in the art can obtain other drawings without creative efforts based on these drawings.

[0024] Figure 1 It is a system architecture diagram of an identity authentication and access control system for low-altitude aircraft provided by an embodiment of the present application; Figure 2 It is a flowchart of a method for identity authentication and access control of low-altitude aircraft provided by an embodiment of the present application; Figure 3 It is a flowchart of another method for identity authentication and access control of low-altitude aircraft provided by an embodiment of the present application; Figure 4 It is a structural diagram of an identity authentication and access control device for low-altitude aircraft provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0025] The technical solution of the present invention will be clearly and completely described below in conjunction with the embodiments. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0026] In the description of this application, unless otherwise specified, " / " means "or". For example, A / B may represent A or B. The "and / or" herein is only a description of the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, "at least one" means one or more, and "a plurality" means two or more. The words such as "first" and "second" do not limit the quantity and execution order, and the words such as "first" and "second" do not necessarily limit being different.

[0027] It should be noted that in this application, words such as "exemplary" or "for example" are used to represent examples, illustrations or explanations. Any embodiment or design solution described as "exemplary" or "for example" in this application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Exactly speaking, using words such as "exemplary" or "for example" aims to present relevant concepts in a specific way.

[0028] A method for identity authentication and access control for low-altitude aircraft provided by an embodiment of this application can be applied to, for example, Figure 1 as shown in an identity authentication and access control system for low-altitude aircraft, as Figure 1 shown, the communication system includes: a data acquisition module, an AI decision engine module, and an identity authentication module.

[0029] Among them, the data acquisition module is used to obtain the environmental data, device status data, and historical authentication logs of the low-altitude aircraft to obtain the acquisition data.

[0030] The AI decision engine module is used to process the acquisition data, generate a combination of authentication factors through a pre-trained deep reinforcement learning model, and calculate the environmental risk coefficient according to the environmental data using a risk assessment model.

[0031] The identity authentication module is used to perform identity authentication of the aircraft using the main factor, trigger the backup factor for secondary authentication and obtain the authentication result when the matching degree of the main factor identity authentication is within a preset interval, and generate an access token according to the authentication result and the environmental risk coefficient. The aircraft performs access control according to the access token.

[0032] To solve the technical problems of insufficient security in the identity authentication of low-altitude aircraft and the inability to dynamically adapt to complex airspace environments in the prior art, an embodiment of the present application provides an identity authentication and access control method for low-altitude aircraft, which includes: obtaining multi-dimensional acquisition data, intelligently generating a combination of authentication factors, hierarchically performing identity authentication, and dynamically generating access tokens, thereby realizing the intelligent and secure management and control of low-altitude aircraft.

[0033] As Figure 2 shown, an identity authentication and access control method for low-altitude aircraft provided by an embodiment of the present application includes: S1. Obtain the environmental data, device status data, and historical authentication logs of the low-altitude aircraft to obtain acquisition data.

[0034] Among them, the acquisition data is a basic information set for authentication decision-making, which is used to reflect the aircraft operating environment, device status, and historical authentication behavior characteristics.

[0035] In some implementation manners, the environmental data may include airspace environment parameters such as signal strength, spectrum interference value, and horizontal dilution of precision, the device status data may include device operation indicators such as battery capacity, flight altitude, and speed, and the historical authentication logs may record historical information such as authentication results, time consumption, and factor combinations.

[0036] It should be noted that the type of acquisition data can be extended according to the actual application scenario, such as adding weather data or airspace control information, etc.

[0037] Exemplarily, the signal strength (RSSI) in the environmental data can be collected in real time by a sensor, and the flight altitude in the device status data can be obtained through the built-in GPS module of the aircraft.

[0038] S2. Input the acquisition data into the AI decision engine, and generate a combination of authentication factors through a pre-trained deep reinforcement learning model to obtain a main factor and a backup factor; where the main factor and the backup factor represent different authentication methods.

[0039] Among them, the AI decision engine is the core module for realizing intelligent authentication, and the deep reinforcement learning model is used to extract features from the acquisition data and generate an optimal authentication strategy.

[0040] In some implementation manners, the combination of authentication factors may include a combination strategy of multiple main factors (such as radio frequency fingerprint authentication, key authentication) and backup factors (such as biometric authentication).

[0041] It should be noted that the model training process needs to construct a state space based on the historical authentication logs, and optimize the security and efficiency of the factor combination through a reward function.

[0042] Exemplarily, the primary factor may preferably select multi-band radio frequency fingerprint authentication, and the backup factor may be configured as fingerprint authentication, which is applicable to the conventional airspace environment.

[0043] S3. Use the primary factor to perform aircraft identity authentication. When the matching degree of the primary factor identity authentication is within a preset range, trigger the backup factor to perform secondary identity authentication to obtain an authentication result.

[0044] Among them, the matching degree of the primary factor authentication is used to measure the consistency between the authentication information and the registration template, and the preset range can be dynamically adjusted according to the risk level. Moreover, the registration template represents the benchmark data or rule set stored in advance for verifying the identity of the aircraft, and different authentication methods correspond to different forms of registration templates.

[0045] In some implementation manners, the primary factor authentication may include methods such as multi-band radio frequency fingerprint similarity calculation and key decryption verification, and the matching degree can be generated by integrating the results of various authentication methods. For example, for authentication methods such as key decryption verification and digital signature verification, when the authentication is passed, such as when the key hash value is exactly the same as the registration template and the signature verification is successful, the matching degree is set to 1; when the authentication fails, the matching degree is set to 0; for multi-band radio frequency fingerprint and sensor feature vector-based authentication methods (similarity matching based on continuous features), the matching degree can be generated by calculating the cosine similarity, Euclidean distance, or dynamic time warping (DTW) distance between the authentication data and the registration template; for authentication methods such as dynamic token time synchronization and response delay, the matching degree can be generated by calculating the absolute value of the time difference at the time of successful authentication and comparing it with a preset threshold.

[0046] It should be noted that the preset range is usually the threshold range of "authentication successful but there is a certain risk". For example, when the matching degree is 60%-80%, secondary authentication is triggered.

[0047] Exemplarily, when the aircraft enters the area control zone, it sends an identity authentication request to the authentication system. At this time, the system will first send a data collection request to the aircraft to obtain device status data, retrieve the historical authentication log according to the aircraft ID, and at the same time obtain environmental data from the environmental monitoring sensor or the built-in sensor of the aircraft to obtain all the collected data. Then, after normalizing the collected data, the authentication system inputs it into the AI decision engine, and generates an authentication factor combination including the main factor and the backup factor through a pre-trained deep reinforcement learning model. The system sends a main factor authentication instruction to the aircraft, such as performing multi-band radio frequency fingerprint authentication or key authentication. After the aircraft completes the authentication operation, it returns the result to the system, and the system calculates the matching degree of the main factor identity authentication. If the matching degree reaches the first preset threshold, it indicates that the authentication is successful. If the matching degree is less than the second preset threshold, it indicates that the authentication fails. At this time, a signal prohibiting access is sent to the aircraft, and the permission interception is enforced through the risk control module built in the authentication system, and all operation requests of the aircraft are rejected. If the matching degree is within the preset interval of [the first preset threshold, the second preset threshold], the system will trigger the backup factor for secondary identity authentication, such as biometric authentication or blockchain identity traceability authentication, and the aircraft will perform the authentication again and feedback the result.

[0048] It should be noted that if the authentication system detects that a new aircraft has accessed the network in the area control zone but has not sent an identity authentication request, the system will actively send a data collection request to the aircraft. If the aircraft refuses the collection request, the permission interception will be directly enforced through the risk control module built in the authentication system, and all operation requests of the aircraft will be rejected.

[0049] S4. Generate an access token according to the authentication result and the risk assessment model, and the aircraft performs access control according to the access token.

[0050] Among them, the access token is used to describe the association relationship between the permission level, the validity period, the authentication factor, and the environmental risk, and is the core credential for access control.

[0051] In some implementation manners, the risk assessment model can calculate the risk coefficient based on the environmental data, and the permission level can be divided into levels such as basic, intermediate, and advanced, and different levels correspond to different operation permissions and token validity periods.

[0052] It should be pointed out that no access token is generated when the authentication result is a failure, and access may be restricted or prohibited in a high-risk environment.

[0053] Exemplarily, if the environmental risk coefficient is relatively high (such as strong signal interference), even if the authentication is successful, only a basic permission token is generated to limit the flight altitude and speed of the aircraft.

[0054] Based on the above technical solutions, this application provides multi-dimensional data support for authentication decisions by obtaining environmental data, device status data, and historical authentication logs of low-altitude aircraft; with the help of an AI decision engine and a pre-trained deep reinforcement learning model, it dynamically generates combinations of primary factors and backup factors, constructs a flexible multi-factor authentication mechanism, can actively identify abnormal devices and intercept illegal access; dynamically triggers the backup factor for secondary authentication through the matching degree of primary factor authentication, improving the reliability of the authentication process; combines the authentication result with a built-in risk assessment model to generate an access token, realizing intelligent control of dynamically adjusting the permission level and access range according to environmental risks, effectively improving the authentication security, flexibility, and adaptability to airspace risks of low-altitude aircraft in complex environments.

[0055] Obtain the environmental data, device status data, and historical authentication logs of the low-altitude aircraft to obtain the collected data; Input the collected data into the AI decision engine, and generate an authentication factor combination through a pre-trained deep reinforcement learning model to obtain the primary factor and the backup factor; Use the primary factor for the identity authentication of the aircraft. When the matching degree of the primary factor identity authentication is within a preset range, trigger the backup factor for secondary identity authentication to obtain the authentication result; Generate an access token according to the authentication result and the risk assessment model, and the aircraft performs access control according to the access token; wherein, the access token is used to describe the relationship between the permission level, the authentication factor, and the environmental data, and the risk assessment model is built into the AI decision engine.

[0056] In this embodiment, the collected data includes: Environmental data including signal strength, spectrum interference value, horizontal dilution of precision, temperature, humidity, and air pressure; Device status data including the remaining battery capacity of the aircraft, CPU or GPU load, remaining storage space, and flight altitude, speed, and heading; Authentication logs including the authentication results, authentication time consumption, authentication factor combinations, and corresponding environmental data and device status data of recent multiple identity authentications.

[0057] It should be noted that the index data of the environmental data needs to be collected in real time through sensors, and the collection frequency can be dynamically adjusted according to airspace risks; the device status data can be obtained through sensors and system logs built into the aircraft, for example, reading the remaining power through the battery management system and obtaining real-time flight parameters through the flight control system.

[0058] In a possible implementation manner of the embodiment of this application, the above S2 can be specifically implemented through the following S201, S202, and S203, which are specifically described below: S201. Initialize the components of the AI decision-making engine.

[0059] Among them, the AI decision-making engine includes a decision generation unit and a risk assessment unit: The decision generation unit processes the collected data using a built-in deep reinforcement learning model and outputs an authentication factor combination. The risk assessment unit calculates the environmental risk coefficient according to the environmental data using a risk assessment model.

[0060] It should be noted that the two units can work together, and the risk assessment result can be fed back to the decision generation unit to adjust the factor combination strategy.

[0061] Exemplarily, when the risk assessment unit detects high-frequency spectrum interference, the decision generation unit preferentially selects multi-band radio frequency fingerprint authentication as the main factor.

[0062] S202. Generate an authentication factor combination through a deep reinforcement learning model.

[0063] Among them, the input of the deep reinforcement learning model is the normalized collected data, and the output is the main factor and the backup factor.

[0064] In some implementation manners, the model training process includes: 1. Data collection and preprocessing: First, extract at least 100,000 authentication logs from the historical operation records of the low-altitude aircraft authentication system. Each log contains the following fields: Timestamp: accurate to milliseconds; Authentication result: including a binary label of success / failure; Authentication time consumption: unit: ms; Authentication factor combination: including the main factor type and the backup factor type; Environmental data: including signal strength RSSI, spectrum interference Interf, HDOP, temperature T, humidity H, air pressure P; Device status data: including battery capacity, CPU load, flight altitude, speed.

[0065] Then, perform normalization processing on each item of data in the historical authentication log. Among them, the normalization processing method of the environmental data is as shown in step S203. The normalization processing method includes: For the timestamp: convert the timestamp to the number of milliseconds of the epoch time, such as January 1, 2020 00:00:00 UTC, and then through the linear normalization formula Map to the [0,1] interval, where and are respectively the minimum and maximum values of the timestamp in the historical log.

[0066] For the authentication time consumption: Linear normalization is adopted, and the formula is , where TS is the original time consumption (unit: ms), TS min and TS max are the minimum and maximum values of the historical authentication time consumption respectively, and the value range after normalization is [0, 1].

[0067] For the authentication factor combination: One-Hot Encoding is adopted to map the predefined authentication factor library (such as main factors: multi-band radio frequency fingerprint authentication, key authentication; alternative factors: biometric authentication, blockchain traceability authentication) into binary vectors. For example, the combination of the main factor "key authentication" + the alternative factor "biometric authentication" can be encoded as ([0, 1, 1, 0]) (assuming the length of the main factor library is 2 and the length of the alternative factor library is 2), ensuring that each factor combination corresponds to a unique sparse vector representation.

[0068] It should be noted that the authentication accuracy of the alternative factors in this application being higher than that of the main factors means that: the authentication method of the alternative factors generates authentication vouchers based on non-tamperable or unique features, and its authentication error rate is lower than that of the main factor authentication method, where the authentication error rate can be the weighted average of the false acceptance rate (FAR) and the false rejection rate (FRR).

[0069] For example, the alternative factors include at least one of biometric authentication and blockchain identity traceability authentication, and biometric authentication is verified based on the uniqueness of biometric features such as fingerprints, faces, and voiceprints, and its false acceptance rate is usually less than or equal to 0.001%; Blockchain identity traceability authentication verifies the historical flight records of the aircraft through smart contracts, and uses the distributed non-tamperable feature of the blockchain to ensure that the authentication vouchers cannot be forged or tampered with, and its false acceptance rate is usually less than or equal to 0.0001%.

[0070] The authentication methods of the main factors include at least one of multi-band radio frequency fingerprint authentication, key authentication, digital certificate authentication, and geofence authentication. In actual operation, the main factors are usually easier to decrypt than the alternative factors, resulting in a reduction in their authentication accuracy. Therefore, in a high-risk environment where the current network may be under external intrusion, the model will trigger the alternative factors at this time to increase the difficulty of identity authentication. That is, the authentication accuracy of the alternative factors being higher than that of the main factors, the authentication difficulty of the alternative factors being higher than that of the main factors, or the authentication error rate of the alternative factors being lower than that of the main factors has the same meaning.

[0071] For each numerical data in the device status data, through the linear normalization formula Processing, where X is the original value of each index in the device status data (such as remaining battery capacity, CPU load, flight altitude), X min and X max are the minimum and maximum values of this index respectively.

[0072] Next, construct the state space: Concatenate the normalized environmental data, device status data, authentication result, authentication time consumption, and factor combination encoding in sequence to form a state vector of length L .

[0073] 2. Environmental Modeling and Action Space Definition: First, abstract the authentication system as a reinforcement learning environment E, where: State S t : That is, the above-mentioned normalized state vector; Action A t : The combined strategy selected from the predefined authentication factor library, including: Main factor set: {Multi-band RF fingerprint authentication (F1), Key authentication (F2), Geofencing authentication (F3), Digital certificate authentication (F4)}; Alternative factor set: {Biometric authentication (B1), Blockchain traceability authentication (B2)}; Size of the action space: One alternative factor must be selected (it can actually not be triggered), and at least one main factor must be selected, with a total of 45 combined strategies.

[0074] Next, set the reward function as: ; where, AS ∈ {0, 1} represents the authentication result, TS’ represents the normalized authentication time consumption, R env represents the environmental risk coefficient calculated through the risk assessment model, α1, α2, α3 respectively represent the weight coefficients of each item, and the default values are: α1 = 10, α2 = 5, α3 = 4, β represents the fixed penalty value for authentication failure, and the default value is 8.

[0075] 3. Algorithm Selection and Network Architecture: Taking the proximal policy optimization algorithm as an example, construct a deep reinforcement learning model, including: Policy network: The input layer dimension is L, the hidden layer contains at least 2 layers of fully connected and activation functions, the output layer dimension is the size of the action space of 45 (including both main factors and alternative factors), and the output action probability distribution , for example, assign a probability of 0.8 to the action of "main factor = RF fingerprint authentication, alternative factor = biometric authentication", and assign lower probabilities to other actions, then the finally obtained factor combination is [main factor = RF fingerprint authentication, alternative factor = biometric authentication]; Value Network: The input layer is the same as the policy network. The hidden layer contains at least two fully connected layers. The output layer outputs a scalar value V(S t ), estimating the state value.

[0076] 4. Iterative Training and Optimization: Set the training parameters as follows: Set the batch size: 512 logs / batch; learning rate: initial value of 3×10 -4 , decaying by 10% every 1000 rounds; number of training rounds: at least 5000 rounds until the reward value converges (with a fluctuation amplitude <5% as the standard); discount factor: γ = 0.99.

[0077] Execute the training process: Data Sampling: Randomly sample a batch of data from historical logs . Policy Update: Update the policy network parameters θ through the PPO loss function , where is the ratio of the new and old policy probabilities, is the estimated value of the advantage function, =0.2 is the clipping parameter, and clip() represents the clipping function; Value Network Update: Optimize the value network through the mean squared error (MSE) loss .

[0078] Loop Iteration: Repeat the above steps. The model parameters can be saved every 500 rounds, and metrics such as the authentication success rate and average time consumption can be evaluated.

[0079] 5. Model Verification and Deployment: Reserve 20,000 historical logs that have not participated in training as the validation set. And define the evaluation metrics as follows: Authentication Success Rate: Number of successful authentications / Total number of validations (target ≥ 95%); Average Authentication Time: Average time consumption for successful authentication (target ≤ 500ms); Risk Coverage Rate: Proportion of triggering the backup factor in high-risk environments (such as R env ≥0.7) (target ≥ 90%). Save the model whose evaluation metrics reach the target to obtain a pre-trained deep reinforcement learning model with the input data being the collected data and the output being the optimal authentication factor combination including the main factor and the backup factor, and deploy it on the authentication system.

[0080] After the model is deployed, collect the latest authentication logs (about 100 logs per hour) every hour to form a sliding window dataset, and regularly update the model parameters through incremental learning to ensure adaptation to the changes in the airspace environment.

[0081] Exemplarily, in a low-risk environment, the model outputs the main factor as key authentication and the backup factor as fingerprint authentication to balance efficiency and security.

[0082] S203, calculate the environmental risk coefficient based on environmental data.

[0083] Specifically, first, normalize the numerical values of each index in the environmental data to obtain the normalized values of each index, including: Signal normalized value RSSI norm : ; where RSSI min represents the preset lower limit of signal strength, and RSSI max represents the preset upper limit of signal strength; Positioning accuracy normalized value HDOP norm : ; Spectrum normalized value Interf norm : ; where Interf k represents the spectrum interference value of the kth frequency band, N bands represents the number of monitored frequency bands, and Interf max represents the maximum spectrum interference value; Temperature normalized value T: ; where T opt represents the ideal temperature value, T max represents the maximum temperature deviation value; Atmospheric pressure normalized value P: ; where P std represents the standard atmospheric pressure value, P max represents the maximum atmospheric pressure deviation value; Humidity normalized value H: ; where H thr represents the preset humidity threshold, H max represents the maximum humidity deviation value, and ReLU() represents the ReLU function.

[0084] Then, sum up the normalized values of each index with weights to obtain the risk assessment model for calculating the environmental risk coefficient R env The formula is: R env = w s ×(1 - RSSI norm ) + w i ×Interf norm + w h ×HDOP norm + w t × T + w p × P + whum × H; where, w s 、w i 、w h 、w t 、w p 、w hum respectively represent each coefficient, and the default values are: w s = 0.35, w i = 0.25, w h = 0.20, w t = 0.10, w p = 0.07, w hum = 0.03.

[0085] Based on the above technical solution, the AI decision-making engine dynamically generates a combination of authentication factors through a data-driven intelligent algorithm, realizing the adaptive matching of the authentication policy and the environmental risk. Specifically, the engine includes two core components: a decision generation unit and a risk assessment unit. The decision generation unit is built with a pre-trained deep reinforcement learning model, which can construct a state space based on the collected data, and use the predefined authentication factor library as the action space, and iteratively optimize the factor combination strategy through a reward function. The risk assessment unit normalizes the environmental data such as signal strength, spectrum interference, and positioning accuracy, generates an environmental risk coefficient through weighted summation, and feeds it back to the decision generation unit in real time, prompting the model to automatically select a high-strength multi-factor combination in high-risk scenarios and preferentially use low-strength factors for fast authentication in low-risk scenarios, realizing the dynamic adaptation of "the higher the risk, the greater the authentication strength".

[0086] In a possible implementation manner of the embodiment of the present application, in combination with Figure 2 , as Figure 3 shown, the above S3 can be specifically implemented through the following steps: First, perform the main factor identity authentication. The main factors include multi-band radio frequency fingerprint authentication, key authentication, digital certificate authentication, geofence authentication, etc. Different authentication methods correspond to different verification logics.

[0087] For example, the multi-band radio frequency fingerprint authentication calculates the cosine similarity S RF,i between the feature vector of each frequency band and the registered template, and combines the spectrum interference value Interf i of this frequency band to perform weighted summation to obtain the radio frequency matching degree S RF , and the formula is , and the frequency band with less interference has a higher weight; The key authentication needs to verify whether the decrypted challenge value is consistent with the original value. If it is consistent, the key matching degree S resp is calculated according to the deviation T Key between the decryption timestamp and the system time. The formula is: ; where T th represents a preset time threshold, such as 20 ms. The smaller the deviation, the higher the matching degree; The matching degree of digital certificate authentication is obtained by weighted summation calculation through the certificate chain verification result Valid chain and the signature verification result Valid signature , and the formula is: ; where Valid chain = 1 indicates that the certificate chain is valid, and Valid chain = 0 indicates that the certificate chain is invalid. Valid signature = 1 indicates that the signature is valid, and Valid signature = 0 indicates that the signature is invalid. γ1 and γ2 represent weight coefficients, and their sum is 1. The default values are: γ1 = 0.4, γ2 = 0.6; Geofence authentication calculates the minimum distance D between the real-time position of the aircraft and the preset fence min , and generates a geographical matching degree S according to the formula , where the closer the distance, the higher the matching degree. Among them, d Geo represents a preset distance threshold, such as d th = 10 m. th

[0088] Next, calculate the main factor authentication matching degree. If the main factor includes multiple authentication methods (such as enabling radio frequency fingerprint and key authentication simultaneously), the matching degree is the average of the matching degrees of each authentication method. The preset interval is usually set to 60% - 80%, indicating that the authentication is successful but there are certain risks: when the matching degree > 80%, the authentication is directly successful; when the matching degree < 60%, the authentication fails; only when the matching degree is in the interval of 60% - 80% does the secondary authentication of the backup factor be triggered. Among them, the preset interval is [the second threshold, the first threshold], and the first threshold and the second threshold can be set according to specific situations.

[0089] Finally, trigger the secondary authentication of the backup factor. The backup factors include biometric authentication (fingerprint, face, voiceprint, etc.) and blockchain identity traceability authentication.

[0090] For example, biometric authentication is verified by comparing the cosine similarity between the fingerprint feature vector collected in real time and the fingerprint registration template; blockchain identity traceability authentication queries the historical flight records and working status of the aircraft through a smart contract. If the status is revoked, unknown, or there is no record, the verification fails. Only when the backup factor authentication is passed, the final authentication result is determined to be successful, otherwise it fails.

[0091] Based on the above technical solutions, the present application realizes a dual mechanism of fast verification of the main factor and risk guarantee of the backup factor, ensuring the provision of adaptable authentication intensity at different risk levels and improving the reliability and security of identity authentication.

[0092] In a possible implementation manner of the embodiment of the present application, the above S4 can be specifically implemented through the following steps: First, according to the authentication result (primary factor authentication successful, secondary factor authentication successful or failed) and the environmental risk coefficient Renv calculated by the risk assessment model, combined with the number Nfactor of the triggered primary factor and secondary factor, calculate the permission value P. The calculation formula is , where λ1 and λ2 are weight coefficients, and λ1 + λ2 = 1, η is an amplification factor with a value of 10.

[0093] For example, if 2 primary factors and 1 secondary factor are triggered, then N factor = 3. Assuming the environmental risk coefficient R env = 0.6, λ1 = 0.7, λ2 = 0.3, then P = floor(0.7×3 + 0.3×0.6×10) = floor(2.1 + 1.8) = 3.

[0094] Next, allocate the corresponding operation permission level and token validity period according to the permission value P. Among them, the preset permission levels are divided into three levels: When P is in the first interval [0 - 2], allocate basic permissions, allowing the aircraft to perform basic flight operations (such as straight flight, altitude holding), and the token validity period is 2 hours; When P is in the second interval [3 - 5], allocate intermediate permissions, allowing flight in a specific area (such as a designated low - altitude test area), and the validity period is 1 hour; When P is in the third interval [6 - 10], allocate high - level permissions, allowing full - airspace flight and performing complex operations (such as route change, mission loading), and the validity period is 0.5 hour.

[0095] It should be noted that the permission level and validity period can be dynamically adjusted according to the real - time airspace control policy. For example, the permission level is automatically reduced near a temporary no - fly zone.

[0096] Finally, generate an access token containing permission information based on an asymmetric encryption signature algorithm (such as RSA). The token content includes: permission level (such as "intermediate"), token validity period (such as "from 2025 - 05 - 28T09:00:00 to 2025 - 05 - 28T13:00:00"), unique aircraft identifier (such as IMEI code), timestamp (for anti - replay attack) and signature value (encrypted by the private key for the above information). The generated token is transmitted to the aircraft in binary or JSON format. After the aircraft verifies the signature validity through the built - in public key, it executes the corresponding access control logic according to the permission level in the token, such as rejecting flight instructions or data access requests that exceed the permission range.

[0097] Based on the above technical solution, the present application realizes the dynamic mapping from authentication strength and environmental risk to access rights, ensuring that the aircraft obtains the minimum necessary rights in different scenarios and improving the safety and refined management ability of airspace access.

[0098] The above mainly introduces the solution of the embodiment of the present application from the perspective of device implementation. It can be understood that for each device, for example, an identity authentication and access control device for low-altitude aircraft to implement the above functions, it includes at least one of the corresponding hardware structures and software modules for executing each function. Those skilled in the art should easily realize that, combined with the units and algorithm steps of each example described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the way of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.

[0099] The embodiments of the present application can divide the functional units of an identity authentication and access control device for low-altitude aircraft according to the above method examples. For example, each functional unit can be divided corresponding to each function, or two or more functions can be integrated into one processing unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit. It should be noted that the division of units in the embodiments of the present application is illustrative, only a logical functional division, and there may be other division methods in actual implementation.

[0100] In the case of adopting an integrated unit, Figure 4 FIG. shows a possible structural schematic diagram of an identity authentication and access control device (denoted as device 40) for low-altitude aircraft involved in the above embodiments. The device 40 includes a processing unit 401 and a communication unit 402, and may further include a storage unit 403. Figure 4 The shown structural schematic diagram can be used to illustrate the structure of the device involved in the above embodiments.

[0101] When Figure 4 the shown structural schematic diagram is used to illustrate the structure of the device involved in the above embodiments, the processing unit 401 is used to control and manage the actions of the device, the communication unit 402 is used for the device to communicate with other devices (such as low-altitude aircraft, sensor networks), and the storage unit 403 is used to store the program code and data of the device (such as historical authentication logs, registration templates, permission configuration policies).

[0102] For example, the communication unit 402 is configured to collect the environmental data (such as signal strength, spectrum interference, etc.), device status data (such as battery capacity, flight altitude, etc.) of the low-altitude aircraft, and historical authentication logs, and transmit them to the processing unit; The processing unit 401 is configured to input the collected data into the AI decision engine, generate a combination of authentication factors through a deep reinforcement learning model, perform primary factor authentication and calculate the matching degree, trigger secondary authentication of backup factors according to the matching degree, and generate an access token by combining the authentication result and the risk assessment model.

[0103] In a possible implementation, the processing unit 401 is further configured to perform normalization processing on the environmental data, calculate the environmental risk coefficient, and dynamically adjust the permission level according to the permission value calculation formula.

[0104] In a possible implementation, the communication unit 402 is further configured to send the access token and permission information to the low-altitude aircraft, and the processing unit 401 is further configured to verify the matching degree between the real-time position of the aircraft and the geographical fence, or query the status of the aircraft through a blockchain smart contract.

[0105] Wherein, the processing unit 401 can be a processor or a controller, and the communication unit 402 can be a communication interface, transceiver, transceiver, transceiver circuit, transceiver device, etc. Among them, the communication interface is a general term and can include one or more interfaces. The storage unit 403 can be a memory. When the device 40 is a chip, the processing unit 401 can be a processor or a controller, and the communication unit 402 can be an input interface and / or output interface, pin or circuit, etc. The storage unit 403 can be the storage unit inside the chip (such as a register, cache, etc.), or the storage unit located outside the chip (such as a read-only memory ROM, random access memory RAM, etc.).

[0106] Wherein, the communication unit can also be referred to as a transceiver unit. The antenna and control circuit with transceiver functions in the device 40 can be regarded as the communication unit 402 of the device 40, and the processor with processing functions can be regarded as the processing unit 401 of the device 40. Optionally, the device for realizing the receiving function in the communication unit 402 can be regarded as the communication unit, and the communication unit is used to execute the receiving steps in the embodiments of the present application. The communication unit can be a receiver, receiver, receiving circuit, etc. The device for realizing the sending function in the communication unit 402 can be regarded as the sending unit, and the sending unit is used to execute the sending steps in the embodiments of the present application. The sending unit can be a transmitter, transmitter, sending circuit, etc.

[0107] Figure 4If the integrated unit in [description] is implemented in the form of a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiments of the present application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) or a processor to execute all or part of the steps of the methods described in the various embodiments of the present application. The storage media storing the computer software product include: various media such as USB flash drives, mobile hard disks, read-only memories, random access memories, magnetic disks, or optical discs that can store program codes.

[0108] The embodiments of the present application also provide a computer-readable storage medium, including instructions, which when running on a computer, cause the computer to execute any of the above methods.

[0109] The embodiments of the present application also provide a computer program product containing instructions, which when running on a computer, cause the computer to execute any of the above methods.

[0110] The embodiments of the present application also provide a chip, which includes a processor and an interface circuit. The interface circuit is coupled to the processor. The processor is used to run a computer program or instructions to implement the above method, and the interface circuit is used to communicate with other modules outside the chip.

[0111] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using a software program, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired manner (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or a wireless manner (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that the computer can access or a data storage device such as a server or data center that contains one or more integrated media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid state disk (SSD), etc.).

[0112] Although the present application has been described in conjunction with various embodiments, however, in the process of implementing the claimed present application, those skilled in the art can understand and implement other variations of the disclosed embodiments by viewing the drawings, the disclosure, and the appended claims. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "one" does not exclude a plurality. A single processor or other unit can implement several functions recited in the claims. Certain measures are recited in mutually different dependent claims, but this does not mean that these measures cannot be combined to produce good results.

[0113] Although the present application has been described in conjunction with specific features and their embodiments, it is obvious that various modifications and combinations can be made without departing from the spirit and scope of the present application. Accordingly, the present specification and the drawings are merely exemplary illustrations of the present application defined by the appended claims, and are considered to have covered any and all modifications, variations, combinations, or equivalents within the scope of the present application. Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application also intends to include these changes and modifications.

Claims

1. An identity authentication and access control method for low-altitude aircraft, characterized in that, Including: Obtain the environmental data, device status data, and historical authentication logs of the low-altitude aircraft to obtain the collected data; Use the artificial intelligence AI decision engine to process the collected data, and generate an authentication factor combination through the pre-trained reinforcement learning model built in the engine; the authentication factor combination includes a primary factor and a backup factor, and both the primary factor and the backup factor include multiple authentication methods, and the authentication accuracy of the authentication method of the backup factor is higher than that of the authentication method of the primary factor; Calculate the environmental risk coefficient through the risk assessment model built in the engine; Trigger the primary factor to perform aircraft identity authentication. If the matching degree of the primary factor identity authentication is within the preset range, trigger the backup factor to perform secondary identity authentication to obtain the authentication result; When the authentication result is successful, determine the operation authority and token validity period according to the environmental risk coefficient and the number of authentication methods of the triggered primary factor and / or backup factor, and send the access token including the operation authority and token validity period to the aircraft.

2. The identity authentication and access control method for low-altitude aircraft according to claim 1, characterized in that, The environmental data includes: environmental data such as signal strength, spectrum interference value, horizontal dilution of precision, temperature, humidity, and air pressure; The device status data includes: device status data such as the remaining battery capacity of the aircraft, CPU or GPU load, remaining storage space, and flight altitude, speed, and heading; The historical authentication logs include: authentication results, authentication time consumption, authentication factor combinations, and corresponding environmental data and device status data of recent multiple identity authentications.

3. The identity authentication and access control method for low-altitude aircraft according to claim 1, characterized in that, The calculating the environmental risk coefficient through the risk assessment model built in the engine includes: Normalize each index value in the environmental data to obtain the normalized value of each index; Sum the weighted normalized values of the above indicators to obtain the calculated environmental risk coefficient R env risk assessment model, the formula is: R env = w s ×(1 - RSSI norm ) + w i ×Interf norm + w h ×HDOP norm + w t × T + w p × P + w hum × H; where w s , w i , w h , w t , w p , w hum respectively represent the coefficients of each item, and the sum is 1, RSSI norm represents the signal normalized value, Interf norm represents the spectrum normalized value, HDOP norm represents the positioning accuracy normalized value, T represents the temperature normalized value, P represents the air pressure normalized value, H represents the humidity normalized value.

4. The identity authentication and access control method for low-altitude aircraft according to claim 3, characterized in that, The normalizing each index value in the environmental data includes: Normalize the signal strength RSSI in the environmental data to obtain the signal normalization value RSSI norm , and the calculation formula is: ; where RSSI min represents the preset lower limit of the signal strength, and RSSI max represents the preset upper limit of the signal strength; Normalize the horizontal dilution of precision HDOP to obtain the normalized positioning accuracy value HDOP norm , and the calculation formula is: ; The spectral normalization value Interf is calculated according to the formula norm : ; where Interf k represents the spectral interference value of the k-th frequency band, N bands represents the number of monitored frequency bands, and Interf max represents the maximum spectral interference value; The temperature normalization value is calculated according to the formula T: ; where T opt represents the preset ideal temperature value, T max represents the maximum temperature deviation value; The air pressure normalization value is calculated according to the formula P: ; where, P std represents the standard air pressure value, P max represents the maximum deviation value of the air pressure; The humidity normalization value is calculated according to the formula H: ; where, H thr represents a preset humidity threshold value, H max represents the maximum humidity deviation value, and ReLU() represents the ReLU function.

5. The identity authentication and access control method for low-altitude aircraft according to claim 1, characterized in that The training process of the pre-trained deep reinforcement learning model includes: Set the state space, action space, and reward function of the deep reinforcement learning model; where, The construction of the state space is: Collect historical authentication logs, where each authentication log includes a timestamp, authentication result, authentication time consumption, authentication factor combination, environmental data, and device status data; splice each item of data in the historical authentication logs after normalization to obtain the state space; where, the authentication result is normalized using the binary method: 0 indicates authentication failure, 1 indicates authentication success, and the authentication factor combination is normalized through one-hot encoding; The definition rule of the action space is: define the predefined authentication factor library as the action space, and each action in the action space corresponds to a factor combination strategy, and a factor combination strategy includes at least one primary factor and at least one backup factor; The calculation formula of the reward function R is as follows: ; where AS ∈ {0, 1} represents the authentication result, TS’ represents the normalized authentication time, and R env represents the environmental risk coefficient calculated by the risk assessment model, α1, α2, and α3 respectively represent the weight coefficients of each item, and β represents the fixed penalty value for authentication failure; Adopt the deep Q network or proximal policy optimization algorithm to construct a deep reinforcement learning model, where the input layer dimension of the deep reinforcement learning model is the dimension of the state space, and the output layer dimension is the size of the action space; Use the historical authentication logs to perform iterative training and optimization verification on the deep reinforcement learning model to obtain a pre-trained deep reinforcement learning model with the input data being the collected data and the output being the optimal authentication factor combination including the primary factor and the backup factor.

6. The identity authentication and access control method for low-altitude aircraft according to claim 5, characterized in that The main factors include at least one of the following authentication methods: multi-band radio frequency fingerprint authentication, key authentication, digital certificate authentication, and geofence authentication; wherein, the geofence authentication means performing identity authentication by comparing the real-time position of the low-altitude aircraft with a preset geofence database. The backup factors include at least one of the following authentication methods: biometric authentication, blockchain identity traceability authentication; wherein, the biometric authentication includes fingerprint authentication, face authentication, and voiceprint authentication of the staff; the blockchain identity traceability authentication means verifying the historical flight records and working status of the low-altitude aircraft through a smart contract. When the low-altitude aircraft has no historical flight records, or the working status is revoked or unknown, the authentication fails. The predefined authentication factor library contains all the authentication methods included in the main factors and the backup factors.

7. The identity authentication and access control method for low-altitude aircraft according to claim 1, characterized in that The matching degree of the main factor identity authentication includes: When the main factor is multi-band radio frequency fingerprint authentication, the cosine similarity between the feature vector of each band and the registered template is calculated, and the radio frequency matching degree S is obtained through weighted summation RF , and the calculation formula is: ; where n represents the number of frequency bands, Interf i represents the spectral interference value of the i-th frequency band, and S RF,i represents the cosine similarity between the feature vector of the i-th frequency band and the registered template; When the main factor is key authentication, when the challenge value obtained by decryption is the same as the original challenge value sent by the authentication system, or when the message authentication code obtained by decryption is the same as the message hash value calculated locally by the authentication system, according to the deviation T between the timestamp obtained by decryption and the current time of the authentication system resp Calculate the key matching degree S Key , the formula is: ; where T th represents the preset time threshold; When the main factor is digital certificate authentication, the certificate matching degree S Cert is calculated by the formula ; where, Valid chain ∈{0, 1}, representing the certificate chain verification result, and Valid chain = 1 indicates that the certificate chain is valid, and Valid chain = 0 indicates that the certificate chain is invalid, Valid signature ∈{0, 1} represents the signature verification result, and Valid signature = 1 indicates that the signature is valid, and Valid signature = 0 indicates that the signature is invalid, γ1 and γ2 represent the weight coefficients, and their sum is 1; When the main factor is geofence authentication, calculate the minimum distance D between the real-time position of the low-altitude aircraft and the geofence min , according to the preset distance threshold d th Calculate the geographical matching degree S Geo , the formula is: ; When the main factor includes multiple authentication methods, the matching degree of the main factor identity authentication is the average value of the matching degrees of the multiple authentication methods.

8. The identity authentication and access control method for low-altitude aircraft according to claim 1, characterized in that The generation method of the access token includes: When the authentication result is successful, the environmental risk coefficient R calculated according to the risk assessment model env and the number N of authentication factors factor Calculate the permission value P, and the formula is: ; where λ1 and λ2 represent the weight coefficients of each item, and their sum is 1, η represents the amplification factor, and its value is 10. The number of authentication factors represents the total number of triggered main factors and / or standby factors; Allocating the operation permission level and the token validity period according to the permission value, and generating an access token based on the signature algorithm.

9. The identity authentication and access control method for low-altitude aircraft according to claim 8, characterized in that, The access token contains the operation permission, the token validity period, the unique identifier of the aircraft, the timestamp, and the signature value.

10. An identity authentication and access control device for low-altitude aircraft, characterized in that, Includes: A communication unit and a processing unit; The communication unit is used to obtain the environmental data, device status data, and historical authentication logs of the low-altitude aircraft to obtain the collected data, and transmit the identity authentication result and the access token. The processing unit is used to process the collected data by using the AI decision engine, generate an authentication factor combination through a pre-trained reinforcement learning model built in the engine to obtain the main factor and the backup factor, and calculate the environmental risk coefficient through a risk assessment model built in the engine. Trigger the main factor to perform the identity authentication of the aircraft. If the matching degree of the main factor identity authentication is within a preset interval, trigger the backup factor to perform secondary identity authentication to obtain the authentication result. When the authentication result is successful, determine the operation permission and the token validity period according to the environmental risk coefficient and the number of the triggered main factor and / or backup factor, and send the access token containing the operation permission and the token validity period to the aircraft.

Citation Information

Patent Citations

  • System and method for adaptively determining an optimal authentication scheme

    CN113383333A

  • Unmanned aerial vehicle identity recognition method based on dual authentication mechanism

    CN118474741A

  • Unmanned aerial vehicle cluster security authentication method and system

    CN118870324A

  • Remote identity recognition method and system based on unmanned aerial vehicle management and control requirements

    CN119728081A

  • Unmanned aerial vehicle safety certifiable information communication processing method based on cloud platform

    CN119966747A

Cited By

  • AI vision-based transformer substation operator dynamic authority management and control system

    CN121278706A

  • Intelligent control method and system for special equipment based on Internet of Things

    CN121302341A

  • Special equipment intelligent control method and system based on internet of things

    CN121302341B

  • Power equipment distributed identity authentication method and equipment based on SAC algorithm

    CN121396660A

  • A power equipment distributed identity authentication method and device based on SAC algorithm

    CN121396660B