Unmanned aerial vehicle credible digital identity recognition method and system

By integrating the digital identity identification module on the drone and connecting it with the trusted digital identity management platform, and generating and managing identity certificates, the problems of untrustworthy identity and full life cycle security control are solved, identity uniqueness and traceability are achieved, and air traffic management efficiency and security are improved.

CN120475375AActive Publication Date: 2025-08-12EASTCOMPEACE TECH

Patent Information

Application Number
CN202510523993.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-24
Publication Date
2025-08-12
Estimated Expiration
2045-04-24

AI Technical Summary

Technical Problem

The existing drone technology lacks a safe and trustworthy digital identity identifier, the real-time operation identification information broadcast has low credibility, and the entire life cycle safety control mechanism is lacking, resulting in difficulties in air traffic management and limited drone applications.

Method used

The drone digital identity identification module is integrated on the drone, and connected with the trusted digital identity management platform through binding relationship verification and two-way authentication, generate and manage the drone digital identity certificate, collect and report flight trajectory information in real time, and use AES symmetric cryptography technology to ensure the uniqueness and traceability of identity.

Benefits of technology

It has enhanced the credibility of drone identity, established a trusted chain throughout the life cycle, improved the efficiency and safety of air traffic management, and promoted the healthy development of the drone industry.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120475375A_ABST
    Figure CN120475375A_ABST
Patent Text Reader

Abstract

The invention provides an unmanned aerial vehicle credible digital identity recognition method and system, and the method comprises the steps: integrating an unmanned aerial vehicle digital identity recognition module on an unmanned aerial vehicle, and verifying whether the binding relation with an unmanned aerial vehicle flight control system is changed or not when the unmanned aerial vehicle is powered on each time; after verification of the binding relation is completed, the unmanned aerial vehicle digital identity recognition module accesses the trusted digital identity management platform to perform bidirectional authentication; in the real-name registration stage, the platform associates the unmanned aerial vehicle basic information with the real-name registration code to generate an unmanned aerial vehicle digital identity certificate, and creates a configuration management task; after the bidirectional authentication is passed, the configuration management task is acquired from the platform, and a certificate is installed in an unmanned aerial vehicle digital identity recognition module; and the unmanned aerial vehicle digital identity recognition module uploads the certificate to the platform, and collects, stores and reports the flight path information of the unmanned aerial vehicle to the platform in real time through networking. The invention aims to solve the problems of traffic management and safety management and control of aerial and ground unmanned systems including unmanned equipment, humanoid robots and the like.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of unmanned aerial vehicles (UAVs), and in particular to a method and system for identifying a trusted digital identity of an UAV. Background Art

[0002] In recent years, with the rapid development of drone technology and the significant reduction in manufacturing costs, drones have expanded from their initial military applications to a wide range of civilian applications, including aerial photography, logistics distribution, agricultural plant protection, power inspection, and surveying and mapping. The widespread use of drones has greatly improved work efficiency, reduced labor costs, and promoted innovation and development in related industries. However, this explosive growth in the drone market has also brought significant challenges to low-altitude airspace management.

[0003] Drone identity authentication issues:

[0004] Existing drones lack a secure and reliable digital identity before leaving the factory, making it difficult to trace drone information back to its source. The current solution of using after-market integrated terminal devices as drone identification is prone to disassembly and illegal misappropriation, making it unreliable as a unique and reliable drone identity.

[0005] Real-time operation to identify the credibility of information broadcast:

[0006] According to national policy, drones are required to broadcast their operational identification information in real time during flight for air traffic management purposes. However, existing safety and control solutions often use mounted or integrated operational identification tags for real-time broadcasting. These devices are not issued by trusted institutions, so the operational identification information they broadcast is not reliable and is not suitable as a data source for air traffic management and flight audits.

[0007] Lack of full life cycle safety control mechanism:

[0008] Existing drone safety management solutions lack a comprehensive safety management mechanism for the entire drone lifecycle, from manufacturing, real-name registration, flight control, to deregistration. This lack of a mechanism creates loopholes in drone safety management throughout its lifecycle, making effective full-chain supervision and control difficult.

[0009] In summary, existing drone technology faces multiple challenges in low-altitude airspace management, including unreliable identity authentication, low reliability of real-time operational identification information broadcasts, and a lack of a full lifecycle safety and control mechanism. These issues not only impact air traffic safety and order but also hinder the further development and application of drone technology. Summary of the Invention

[0010] In response to the shortcomings of the existing technology, the present invention provides a method and system for trusted digital identity recognition of drones, aiming to solve the problems of traffic management and safety control of aerial and ground unmanned systems including unmanned equipment and humanoid robots.

[0011] The present invention achieves the above-mentioned purpose through the following technical solutions:

[0012] A method for identifying a trusted digital identity of a drone, comprising:

[0013] The drone is integrated with a drone digital identification module to achieve the binding between the drone and the drone digital identification module. Each time it is powered on, it verifies whether the binding relationship with the drone flight control system has changed, and records the binding relationship verification results.

[0014] After the binding relationship is verified, the drone digital identity module accesses the trusted digital identity management platform and establishes an HTTPS / MQTTS secure connection with the platform and performs two-way authentication. Only legitimate drone digital identity modules can upload data.

[0015] During the real-name registration phase, the trusted digital identity management platform associates the drone's basic information with the real-name registration code, generates a drone digital identity certificate, and creates a configuration management task. After two-way authentication is successful, the drone's digital identity module obtains the configuration management task from the trusted digital identity management platform and installs the drone's digital identity certificate into the drone's digital identity module.

[0016] During the operation phase, the drone digital identity recognition module uploads the drone digital identity certificate to the platform for verifying the drone and real-name registration information; the drone digital identity recognition module collects, stores and reports the drone flight trajectory information to the drone trusted digital identity management platform in real time, and the drone trusted digital identity management platform records the flight trajectory information reported by the drone digital identity recognition module online.

[0017] According to a method for identifying a trusted digital identity of a drone provided by the present invention, after the drone is powered on, the drone's digital identity module uses symmetric cryptography to verify with the flight control system whether the binding relationship has changed, specifically including:

[0018] If a change in the binding relationship is detected, a multiple verification mechanism is activated, and the multiple verification mechanism is set with a predetermined number of verifications; if the consistency of the binding relationship cannot be successfully verified within the number of verifications, the drone digital identity recognition module automatically generates abnormal log information and records the details of the verification failure, and at the same time triggers the invalidation processing process of the drone digital identity certificate, making the drone digital identity certificate invalid.

[0019] According to a method for identifying a trusted digital identity of a drone provided by the present invention, the two-way authentication process includes:

[0020] The drone digital identity recognition module calls the two-way authentication interface of the trusted digital identity management platform and sends the device certificate chain, which includes at least the issuing authority root certificate, the device manufacturer certificate, and the device certificate, to the trusted digital identity management platform;

[0021] The trusted digital identity management platform checks whether the certificate system is supported based on the public key ID in the issuing organization's root certificate. If supported, it verifies the legitimacy of the root certificate, device manufacturer certificate, and device certificate in turn.

[0022] If the root certificate, device manufacturer certificate, and device certificate are all legitimate, the trusted digital identity management platform will deem the drone to be issued by a legitimate organization.

[0023] According to the present invention, a method for identifying a trusted digital identity of a drone, after determining that the drone is issued by a legitimate organization, further includes:

[0024] The trusted digital identity management platform sends the platform certificate chain including at least the issuing authority root certificate and the platform certificate to the drone digital identity recognition module;

[0025] The drone digital identity recognition module verifies the legitimacy of the received platform certificate chain. The drone digital identity authentication module first verifies whether the issuing agency's root certificate is the same as the locally stored root certificate. If they are the same, the public key of the root certificate is used to verify the legitimacy of the platform certificate.

[0026] If the platform certificate chain is legal, the drone digital identity recognition module will consider the drone trusted digital identity management platform to be legal. At this point, the two-way authentication process between the drone and the drone trusted digital identity management platform is completed.

[0027] According to the method for identifying a trusted digital identity of a drone provided by the present invention, after the two-way authentication is passed, the method further includes the following steps:

[0028] The drone digital identity recognition module synchronizes device anomaly information and drone digital identity certificates to the drone trusted digital identity management platform;

[0029] The drone trusted digital identity management platform synchronizes the received device anomaly information and drone digital identity certificate to the air traffic management platform;

[0030] The air traffic management platform verifies the legitimacy of the synchronized drone digital identity certificate;

[0031] If the drone's digital identity certificate is legal, the air traffic management platform will identify the drone's identity information and the operational identification information associated with the drone based on the information in the drone's digital identity certificate. The drone's identity information includes at least the drone manufacturer, the drone's unique product identification code, the drone's flight control serial number, the drone's digital identity module, and real-name registration information.

[0032] According to a method for identifying a trusted digital identity of a drone provided by the present invention, when the drone digital identity module detects an inconsistency in the binding relationship with the flight control system, a multiple verification mechanism is initiated, and the drone digital identity module performs verification operations according to the following steps:

[0033] Initial Verification: Use AES symmetric encryption technology to perform the initial verification of the current binding relationship and generate an encrypted binding verification code. This verification code is a unique value calculated based on the AES algorithm and the binding relationship information of both parties. The generated verification code is compared with the verification code stored in advance or provided by the flight control system to verify the consistency of the binding relationship.

[0034] Repeated verification: If the initial verification fails, that is, the binding relationship verification is inconsistent, the repeated verification mechanism is activated. The repeated verification uses the same AES symmetric encryption technology as the initial verification, but may apply different encryption parameters or initialization vectors (IVs). According to a predetermined algorithm or rule, the binding relationship information is encrypted multiple times and a corresponding verification code is generated. The verification code generated by each repeated verification is compared with the expected value. If a verification code matches, the binding relationship is determined to be consistent in that verification, and the repeated verification can be stopped. The predetermined algorithm or rule at least includes adjusting encryption parameters, changing the encryption order, and introducing random factors.

[0035] Verification times control: After each verification, the verification times are recorded. If the verification times reach the preset threshold, the verification is stopped.

[0036] Exception handling: If all checks fail to verify the consistency of the binding relationship within the verification number threshold, the drone digital identity recognition module determines that the binding relationship is abnormal and automatically triggers the abnormal log generation logic.

[0037] Thus, the present invention proposes a method for reliable digital identity recognition of drones, which builds a secure and reliable digital identity certificate system for drones and their real-name registration information. The following are the beneficial effects of the method of the present invention:

[0038] Enhanced drone identity credibility: This invention ensures the uniqueness and traceability of drone identity by incorporating key information into the drone's digital identity certificate, including the drone's unique product identification code, flight control serial number, unique identification code of the drone's digital identification module, device manufacturer ID, and real-name registration code. The digital identity certificate utilizes advanced cryptographic encryption to effectively prevent information tampering or forgery, enhancing the credibility of the drone's identity.

[0039] Establishing a trust chain throughout the entire life cycle: This invention incorporates digital identity recognition technology into all aspects of drone production, real-name registration, flight control, and drone deregistration, forming a complete trust chain. This ensures that the drone's identity information and real-name registration information throughout its entire life cycle can be accurately traced, providing strong support for the safe management and supervision of drones.

[0040] Improve the efficiency of air traffic management: The introduction of drone digital identity certificates enables air traffic management departments to quickly and accurately identify the identity and flight status of each drone, helping air traffic management departments to more effectively arrange flight plans, plan flight routes, and avoid flight conflicts, thereby improving the efficiency and safety of air traffic management.

[0041] Promoting the healthy development of the drone industry: This invention provides a secure and reliable identification and management solution for the drone industry, helping to regulate the drone market. By ensuring the legal identity and flight behavior of drones, this invention promotes the healthy development of the drone industry and lays a solid foundation for its widespread application.

[0042] In summary, the proposed method for trusted digital drone identity recognition has significant benefits. It not only enhances the credibility of drone identities and establishes a trust chain throughout their lifecycle, but also improves the efficiency of air traffic management and promotes the healthy development of the drone industry. This method provides strong support for the safe management and regulation of drones and has broad application prospects and practical value.

[0043] A trusted digital identity recognition system for drones, comprising:

[0044] A drone digital identity recognition module, configured to execute the steps of the above-mentioned drone trusted digital identity recognition method;

[0045] A trusted digital identity management and control platform is used to establish a secure connection with the drone's digital identity module, perform two-way identity authentication, and receive and store information synchronized by the drone's digital identity module;

[0046] The air traffic management platform is used to verify the legitimacy of drone digital identity certificates and monitor and manage flight activities based on the identified drone information.

[0047] According to the present invention, a drone trusted digital identity recognition system is provided. The drone digital identity recognition module includes an application processor, a baseband processor, a GNSS positioning processor, and an eSIM. The module has the following functions:

[0048] Mobile communication capabilities: Through the collaborative work of the baseband processor and eSIM, it achieves connection with the mobile communication network and data transmission, supports access and authentication of mobile communication services, and ensures that the drone can perform stable data communication during flight;

[0049] Flight trajectory collection capability: Utilizes the multi-constellation GNSS receiver function supported by the GNSS positioning processor to collect the UAV's flight trajectory information in real time;

[0050] Ability to securely store sensitive information: A secure storage area is provided in the eSIM to store basic drone information, digital identity certificates, and other sensitive data related to drone authentication and safe flight.

[0051] According to a drone trusted digital identity recognition system provided by the present invention, the application processor serves as a scheduling management function module and specifically includes:

[0052] A digital identity management component, which is configured to connect to a trusted digital identity management platform to query and execute digital identity management tasks issued by the platform, parse and install received drone digital identity certificates, and collect the drone's GNSS position information and report it online to the relevant platform or system;

[0053] The Profile management component is configured to connect to a trusted digital identity management platform to query and execute Profile management tasks issued by the platform, parse and install received Profiles, and assist in remote management of Profiles.

[0054] According to a drone trusted digital identity recognition system provided by the present invention, the baseband processor is configured as follows:

[0055] Encodes and decodes wireless signals to enable data transmission and reception, thereby providing mobile communication services; communicates with the eSIM through the ISO7816 protocol to implement the authentication process of the mobile communication network; and transparently transmits CSIM AT commands sent by the application processor to the eSIM to cooperate with the implementation of the drone's digital identity management function;

[0056] The eSIM is configured to:

[0057] When receiving the CSIM AT command from the baseband processor, it performs the corresponding mobile communication authentication operation according to the command content; supports dynamic loading and switching of profiles of different operators to select the optimal mobile communication service according to the current area of the drone or preset strategy; provides a secure storage area for storing the drone's basic information, device certificates, drone digital identity certificates and sensitive data related to mobile communications; works in conjunction with the application processor to respond to the application processor's requests for drone digital identity management functions.

[0058] As can be seen, the drone digital identity module of the present invention serves as the trusted source of a drone's digital identity. It is uniformly issued and managed by a designated national agency, ensuring the authority and credibility of this identity information. The module operates independently, independent of other drone components, ensuring the stability and reliability of identity recognition.

[0059] Through the drone digital identity recognition module, the present invention can realize online tracking and management of the entire life cycle of drones, including production and manufacturing, real-name registration, flight control, and drone cancellation, which helps to establish a complete drone management file, improve management efficiency, and ensure the legal and compliant use of drones.

[0060] The drone digital identity recognition module can independently realize identity authentication, online issuance of digital certificates, real-name registration, flight information recording, online reporting and other functions with the trusted digital identity management platform, providing a trusted data source for air traffic management or air law enforcement, ensuring the accuracy and effectiveness of management decisions.

[0061] The drone's digital identity module features secure storage, ensuring the digital certificates stored within cannot be tampered with. Flight information record data is authentic, complete, and non-repudiable, providing reliable data support for the air traffic management platform.

[0062] Based on the trusted link established by the drone's digital identity recognition module, the air traffic management platform can obtain drone flight information in real time and make timely management decisions, which helps to improve the efficiency and accuracy of air traffic management and ensure the safety and order of air traffic.

[0063] The implementation of this invention provides a unified and standardized identity recognition and management solution for the drone industry, which helps promote the healthy development of the industry. By ensuring the legal identity and flight behavior of drones, this invention provides a strong guarantee for the widespread application of drones.

[0064] The present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0065] Figure 1 This is a flowchart of an embodiment of a method for identifying a trusted digital identity of a drone according to the present invention.

[0066] Figure 2 The present invention is a flowchart of an embodiment of a method for identifying a trusted digital identity of a drone.

[0067] Figure 3 This is a schematic diagram of an embodiment of a trusted digital identity recognition system for drones according to the present invention.

[0068] Figure 4 This is a schematic diagram of a drone digital identity recognition module in an embodiment of a drone trusted digital identity recognition system of the present invention. DETAILED DESCRIPTION

[0069] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only some of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.

[0070] References herein to "embodiments" mean that a particular feature, structure, or characteristic described in connection with the embodiments may be included in at least one embodiment of the present application. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor does it constitute an independent or alternative embodiment that is mutually exclusive of other embodiments. It is understood, both explicitly and implicitly, by those skilled in the art that the embodiments described herein may be combined with other embodiments.

[0071] A method for identifying a trusted digital identity of a drone

[0072] See also Figure 1 and Figure 2 This embodiment provides a method for identifying a trusted digital identity of a drone, including:

[0073] Step S1: The drone integrates the drone digital identity module to implement binding between the drone and the drone digital identity module. Each time the drone is powered on, it verifies whether the binding relationship with the drone flight control system has changed, and records the binding relationship verification result.

[0074] Step S2: After the binding relationship is verified, the drone digital identity module accesses the trusted digital identity management platform and establishes an HTTPS / MQTTS secure connection with the platform and performs two-way authentication. Only legitimate drone digital identity modules can upload data.

[0075] Step S3, the real-name registration phase, where the trusted digital identity management platform associates the drone’s basic information with the real-name registration code, generates a drone digital identity certificate, and creates a configuration management task;

[0076] Step S4: After the two-way authentication is passed, the drone digital identity recognition module obtains the configuration management task from the trusted digital identity management platform and installs the drone digital identity certificate into the drone digital identity recognition module;

[0077] Step S5: During the operation phase, the drone digital identity module uploads the drone digital identity certificate to the platform for verification of the drone and real-name registration information;

[0078] In step S6, the drone digital identity recognition module collects, stores and reports the drone flight trajectory information to the drone trusted digital identity management platform in real time, and the drone trusted digital identity management platform records the flight trajectory information reported by the drone digital identity recognition module online.

[0079] This embodiment proposes a drone digital identity identification method, including a drone digital identity identification module and a drone trusted digital identity management platform, whose operating principle is as follows: First, the drone digital identity identification module is installed on the drone, and the drone digital identity identification module is dynamically bound to the drone flight control system by issuing the drone digital identity certificate online, ensuring that the drone digital identity identification module can only work normally on the bound drone; second, each time the drone is turned on, it will request the drone trusted digital identity management platform through the drone digital identity identification module to perform identity authentication, ensuring that only authorized drones can access the platform; third, during the drone operation stage, the drone digital identity identification module collects, stores, and reports the drone flight trajectory information online in real time; fourth, the drone trusted digital identity management platform issues a digital certificate for the drone digital identity identification module online, performs two-way authentication with the drone digital identity identification module, and records the flight trajectory information reported by the drone digital identity identification module online, providing a trusted data source for low-altitude drone air traffic management and flight auditing.

[0080] Through the above solution, a reliable drone digital identity identification method is provided for low-altitude air traffic management. Through this method, a drone digital identity certificate is issued online for each drone, that is, a drone electronic ID card is issued, and the drone is given a trusted digital identity identification code. It can not only accurately identify each drone, but also promote the transformation of the low-altitude drone safety management model to pre-emptive prevention, and achieve the safety management and control effects of "pre-emptive prevention", "in-process monitoring" and "post-event audit".

[0081] In this embodiment, after the drone is powered on, the drone's digital identity module uses symmetric cryptography to verify with the flight control system whether the binding relationship has changed, specifically including:

[0082] If a change in the binding relationship is detected, a multiple verification mechanism is activated, and the multiple verification mechanism is set with a predetermined number of verifications; if the consistency of the binding relationship cannot be successfully verified within the number of verifications, the drone digital identity recognition module automatically generates abnormal log information and records the details of the verification failure, and at the same time triggers the invalidation processing process of the drone digital identity certificate, making the drone digital identity certificate invalid.

[0083] In step S1 above, the method provided in this embodiment integrates a drone digital identity module into the drone. After powering on, the module accesses the drone's trusted digital identity management platform. The platform writes the drone's basic information (including but not limited to the unique product identification code and flight control serial number) into the drone digital identity module, and activates the one-to-one binding between the drone digital identity module and the drone. The drone digital identity module serves as the drone's "electronic ID card," used to identify the drone's digital identity.

[0084] In step S3 above, the two-way authentication process includes:

[0085] The drone digital identity recognition module calls the two-way authentication interface of the trusted digital identity management platform and sends the device certificate chain, which includes at least the issuing authority root certificate, the device manufacturer certificate, and the device certificate, to the trusted digital identity management platform;

[0086] The trusted digital identity management platform checks whether the certificate system is supported based on the public key ID in the issuing organization's root certificate. If supported, it verifies the legitimacy of the root certificate, device manufacturer certificate, and device certificate in turn.

[0087] If the root certificate, device manufacturer certificate, and device certificate are all legitimate, the trusted digital identity management platform will deem the drone to be issued by a legitimate organization.

[0088] After deeming that the drone is issued by a legitimate organization, the trusted digital identity management platform sends the platform certificate chain, which includes at least the issuing organization's root certificate and the platform certificate, to the drone's digital identity module;

[0089] The drone digital identity recognition module verifies the legitimacy of the received platform certificate chain. The drone digital identity authentication module first verifies whether the issuing agency's root certificate is the same as the locally stored root certificate. If they are the same, the public key of the root certificate is used to verify the legitimacy of the platform certificate.

[0090] If the platform certificate chain is legal, the drone digital identity recognition module will consider the drone trusted digital identity management platform to be legal. At this point, the two-way authentication process between the drone and the drone trusted digital identity management platform is completed.

[0091] Specifically, during identity authentication, the drone digital identity module calls the two-way authentication interface of the drone trusted digital identity management platform and sends the device certificate's certificate chain to the platform. This device certificate chain includes, but is not limited to, the issuing authority's root certificate, the device manufacturer's certificate, and the device certificate. The drone trusted digital identity management platform first checks whether it supports the certificate system based on the public key ID in the issuing authority's root certificate. If supported, it verifies whether the root certificate matches its stored root certificate. If so, it uses the root certificate's public key to verify the validity of the device manufacturer's certificate. If so, it verifies the validity of the device certificate. If so, the platform deems the drone to be issued by a legitimate organization. The platform then sends its own platform certificate chain to the drone digital identity module. The platform certificate chain includes, but is not limited to, the issuing authority's root certificate and the platform certificate. The drone digital identity authentication module first verifies whether the issuing authority's root certificate matches its locally stored root certificate. If so, it uses the root certificate's public key to verify the validity of the platform certificate. If so, the drone trusted digital identity management platform is deemed legitimate, completing the two-way authentication process.

[0092] In the above step S4, after the two-way authentication is passed, the following steps are also included:

[0093] The drone digital identity recognition module synchronizes the device abnormality information and the drone digital identity certificate to the drone trusted digital identity management platform; the drone trusted digital identity management platform synchronizes the received device abnormality information and the drone digital identity certificate to the air traffic management platform; the air traffic management platform verifies the legitimacy of the synchronized drone digital identity certificate; if the drone digital identity certificate is legal, the air traffic management platform identifies the drone identity information based on the information in the drone digital identity certificate, as well as the operation identification information associated with the drone. The drone identity information includes at least the drone manufacturer, the drone unique product identification code, the drone flight control serial number, the drone digital identity recognition module, and the real-name registration information.

[0094] In this embodiment, when the drone digital identity module detects an inconsistency in the binding relationship with the flight control system, a multiple verification mechanism is initiated. The drone digital identity module performs verification operations according to the following steps:

[0095] Initial Verification: Use AES symmetric encryption technology to perform the initial verification of the current binding relationship and generate an encrypted binding verification code. This verification code is a unique value calculated based on the AES algorithm and the binding relationship information of both parties. The generated verification code is compared with the verification code stored in advance or provided by the flight control system to verify the consistency of the binding relationship.

[0096] Repeated verification: If the initial verification fails, that is, the binding relationship verification is inconsistent, the repeated verification mechanism is activated. The repeated verification uses the same AES symmetric encryption technology as the initial verification, but may apply different encryption parameters or initialization vectors (IVs). According to a predetermined algorithm or rule, the binding relationship information is encrypted multiple times and a corresponding verification code is generated. The verification code generated by each repeated verification is compared with the expected value. If a verification code matches, the binding relationship is determined to be consistent in that verification, and the repeated verification can be stopped. The predetermined algorithm or rule at least includes adjusting encryption parameters, changing the encryption order, and introducing random factors.

[0097] Verification times control: After each verification, the verification times are recorded. If the verification times reach the preset threshold, the verification is stopped.

[0098] Exception handling: If all checks fail to verify the consistency of the binding relationship within the verification number threshold, the drone digital identity recognition module determines that the binding relationship is abnormal and automatically triggers the abnormal log generation logic.

[0099] Exception log generation: Based on the predefined log format and content, the system records detailed information about binding relationship verification failures, including verification time, number of verifications, binding relationship status, etc., generates exception log information, and stores it in the system-specified log file for subsequent analysis and troubleshooting.

[0100] Through the above implementation principle, the multiple verification mechanism can leverage the security and reliability of AES symmetric encryption technology to accurately and repeatedly verify the binding relationship between the drone's digital identity module and the flight control system, ensuring the correctness and security of the binding relationship.

[0101] In summary, this embodiment proposes a method for identifying a trusted digital identity of a drone, which builds a secure and reliable digital identity certificate system for drones and their real-name registration information.

[0102] This embodiment ensures the uniqueness and traceability of the drone's identity by incorporating key information into the drone's digital identity certificate, including the drone's unique product identification code, flight control serial number, unique identification code for the drone's digital identification module, device manufacturer ID, and real-name registration code. The digital identity certificate utilizes advanced cryptographic encryption to effectively prevent information tampering or forgery, enhancing the credibility of the drone's identity.

[0103] This embodiment incorporates digital identity recognition technology into all aspects of drone production, real-name registration, flight control, and drone deregistration, forming a complete chain of trust. This ensures that the drone's identity information and real-name registration information can be accurately traced throughout its entire life cycle, providing strong support for the safe management and supervision of drones.

[0104] The introduction of drone digital identity certificates enables air traffic management departments to quickly and accurately identify the identity and flight status of each drone, helping air traffic management departments to more effectively arrange flight plans, plan flight routes, and avoid flight conflicts, thereby improving the efficiency and safety of air traffic management.

[0105] This embodiment provides a secure and reliable identity identification and management solution for the drone industry, helping to regulate the drone market. By ensuring the legal identity and flight behavior of drones, this invention promotes the healthy development of the drone industry and lays a solid foundation for the widespread application of drones.

[0106] An embodiment of a trusted digital identity recognition system for drones

[0107] like Figure 3 and Figure 4 As shown, this embodiment provides a drone trusted digital identity recognition system, including:

[0108] A drone digital identity recognition module, configured to execute the steps of the above-mentioned drone trusted digital identity recognition method;

[0109] A trusted digital identity management and control platform is used to establish a secure connection with the drone's digital identity module, perform two-way identity authentication, and receive and store information synchronized by the drone's digital identity module;

[0110] The air traffic management platform is used to verify the legitimacy of drone digital identity certificates and monitor and manage flight activities based on the identified drone information.

[0111] This embodiment implements drone digital identity recognition through a drone digital identity recognition module and a drone trusted digital identity management platform. The issuance management process of the drone digital identity recognition module includes:

[0112] (1) Manufacturing of drone digital identity modules: The national designated agency authorizes the drone digital identity module manufacturer to issue a device manufacturer certificate, and the device manufacturer issues a device certificate for the drone digital identity module based on the device manufacturer certificate. During the drone digital identity module production phase, the device certificate is installed into the security chip in the drone digital identity module. The information in the device certificate includes but is not limited to the drone digital identity module unique identification code, device manufacturer ID, root certificate public key ID, and other information. The device certificate of the drone digital identity module is used for end-to-end identity authentication with the drone trusted digital identity management platform.

[0113] (2) The drone digital identity module is integrated and bound to the drone: During the drone production and assembly phase, the drone manufacturer purchases the drone digital identity module from a designated national agency and integrates the module with the drone’s flight control system through software and hardware integration. Before the drone leaves the factory, the drone digital identity module is powered on and first uses the device certificate to perform a two-way authentication with the trusted digital identity management platform. After the authentication is passed, the drone’s trusted digital identity management platform writes the drone’s basic information (including but not limited to the drone’s unique product identification code and flight control serial number) into the drone digital identity module and activates the one-to-one binding relationship between the drone digital identity module and the drone’s flight control system.

[0114] Issuance and Installation of Drone Digital Identity Certificates: After a drone leaves the factory, each time it is powered on, the drone's digital identity module will access the trusted digital identity management and control platform for identity authentication and synchronize the drone's basic information with the trusted digital identity management and control platform. The trusted digital identity management and control platform accesses the air traffic management platform and uses the drone's unique product identification code to query whether the drone has real-name registration information. If so, the real-name registration code information is obtained from the air traffic management platform. The air traffic management platform associates the drone's basic information with the drone's real-name registration code, generates a drone digital identity certificate (the certificate information includes but is not limited to the unique product identification code, flight control serial number, drone digital identity module unique identification code, device manufacturer ID, real-name registration code, etc.), and then installs the drone digital identity certificate into the drone's digital identity module.

[0115] In this embodiment, the drone digital identification module includes an application processor, a baseband processor, a GNSS positioning processor, and an eSIM. It can be seen that the drone digital identification module is a module that is sealed with multiple core processors. The core processors include but are not limited to the application processor (AP), baseband processor (BP), GNSS positioning processor, and eSIM. The drone digital identification module can exist in the form of a communication module chip or an independent terminal device. The module has the following functions:

[0116] Mobile communication capabilities: Through the collaborative work of the baseband processor and eSIM, connection with the mobile communication network and data transmission are achieved, supporting access and authentication of mobile communication services, ensuring that the drone can perform stable data communication during flight.

[0117] Flight trajectory collection capability: Utilizing the multi-constellation GNSS receiver function supported by the GNSS positioning processor, the UAV's flight trajectory information, including position, speed, altitude and other parameters, is collected in real time, providing accurate data support for the UAV's flight control and safety monitoring.

[0118] Secure storage capability for sensitive information: A secure storage area is provided in the eSIM to store basic drone information, digital identity certificates, and other sensitive data related to drone authentication and safe flight, ensuring the confidentiality, integrity, and availability of this data during storage and transmission, and preventing unauthorized access and tampering.

[0119] Through the above functional configuration, the drone digital identity recognition module can fully meet the drone's communication, positioning and secure storage needs during flight, providing strong technical support for the drone's safe flight and remote management.

[0120] In this embodiment, the application processor serves as a scheduling management function module, specifically including:

[0121] A digital identity management component, which is configured to connect to a trusted digital identity management platform to query and execute digital identity management tasks issued by the platform, parse and install received drone digital identity certificates, and collect the drone's GNSS position information and report it online to the relevant platform or system;

[0122] The profile management component is configured to connect to the trusted digital identity management platform to query and execute profile management tasks issued by the platform, parse and install received profiles, and assist in remote management of profiles, including but not limited to updating, deleting, or adjusting the configuration of profiles.

[0123] In this embodiment, the baseband processor is configured to:

[0124] Encodes and decodes wireless signals to enable data transmission and reception, thereby providing mobile communication services; communicates with the eSIM through the ISO7816 protocol to implement the authentication process of the mobile communication network; and transparently transmits CSIM AT commands sent by the application processor to the eSIM to cooperate with the implementation of the drone's digital identity management function;

[0125] In this embodiment, the eSIM is configured as follows:

[0126] When receiving the CSIM AT command from the baseband processor, it performs the corresponding mobile communication authentication operation according to the command content; supports dynamic loading and switching of profiles of different operators to select the optimal mobile communication service according to the current area of the drone or preset strategy; provides a secure storage area for storing the basic information of the drone, device certificates, drone digital identity certificates and sensitive data related to mobile communications, and supports the installation of certificates such as device certificates and drone digital identity certificates; works in conjunction with the application processor to respond to the application processor's requests for drone digital identity management functions.

[0127] In this embodiment, the GNSS positioning processor is configured to:

[0128] Supports multi-constellation GNSS receiver function, can be compatible with and process signals from multiple positioning systems such as GPS, BDS, GLONASS, Galileo, etc.; realize fast and accurate positioning services, and provide real-time position, speed and time information for drones to meet the needs of drone flight control, navigation and safety monitoring.

[0129] In addition, the drone digital identity recognition module in this embodiment can be in the form of a communication module, a chip, or a terminal.

[0130] In this embodiment, the drone digital identity module is integrated with the drone flight control system to achieve one-to-one binding with the drone, but it can be not integrated with the drone flight control system as needed, and the function can be configured to not enable the binding function;

[0131] In this embodiment, the drone digital identity module can be integrated into the drone cabin, or it can be mounted on the outside of the drone fuselage through other fastening structures;

[0132] In this embodiment, the drone digital identity recognition module can be used to identify the digital identity of the drone, and can also be used for the digital identity recognition of other low-altitude unmanned equipment, including but not limited to: unmanned ships, unmanned vehicles, unmanned boats, and humanoid robots;

[0133] In this embodiment, the trusted computing function of the drone digital identity recognition module can be implemented based on the international asymmetric ECC and AES algorithms, or based on the SM2, SM3, and SM4 algorithms.

[0134] In summary, the drone digital identity module of this embodiment serves as the trusted source of a drone's digital identity. Issued and managed uniformly by a designated national agency, it ensures the authority and credibility of this identity information. This module operates independently, independent of other drone components, ensuring the stability and reliability of identity recognition.

[0135] This embodiment utilizes the drone digital identity module to enable online tracking and management of the entire drone lifecycle, including manufacturing, real-name registration, flight control, and deregistration. This helps establish a comprehensive drone management profile, improves management efficiency, and ensures the legal and compliant use of drones. The drone digital identity module can independently implement identity authentication, online digital certificate issuance, real-name registration, flight information recording, and online reporting with a trusted digital identity management platform. This provides a trusted data source for air traffic management and law enforcement, ensuring the accuracy and effectiveness of management decisions.

[0136] The drone's digital ID module features secure storage, ensuring that the digital certificates stored therein cannot be illegally tampered with. Flight information records are authentic, complete, and non-repudiable, providing reliable data support for the air traffic management platform. Based on the trusted link established by the drone's digital ID module, the air traffic management platform can obtain real-time drone flight information and make timely management decisions, helping to improve the efficiency and accuracy of air traffic management and ensure the safety and order of air traffic.

[0137] Therefore, the method and system of this embodiment provide a unified and standardized identity identification and management solution for the drone industry, which helps promote the healthy development of the industry and provides strong guarantees for the widespread application of drones by ensuring the legal identity and flight behavior of drones.

[0138] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0139] The above embodiments are only preferred embodiments of the present invention and cannot be used to limit the scope of protection of the present invention. Any non-substantial changes and replacements made by technicians in this field on the basis of the present invention fall within the scope of protection required by the present invention.

Claims

1. A method for identifying a trusted digital identity of a drone, characterized in that: include: The drone is integrated with a drone digital identification module to achieve the binding between the drone and the drone digital identification module. Each time it is powered on, it verifies whether the binding relationship with the drone flight control system has changed, and records the binding relationship verification results. After the binding relationship is verified, the drone digital identity module accesses the trusted digital identity management platform and establishes an HTTPS / MQTTS secure connection with the platform and performs two-way authentication. Only legitimate drone digital identity modules can upload data. During the real-name registration phase, the trusted digital identity management platform associates the drone's basic information with the real-name registration code, generates a drone digital identity certificate, and creates a configuration management task. After two-way authentication is successful, the drone's digital identity module obtains the configuration management task from the trusted digital identity management platform and installs the drone's digital identity certificate into the drone's digital identity module. During the operation phase, the drone digital identity module uploads the drone digital identity certificate to the platform for verification of drone and real-name registration information; The drone digital identity recognition module collects, stores and reports the drone flight trajectory information to the drone trusted digital identity management platform in real time. The drone trusted digital identity management platform records the flight trajectory information reported by the drone digital identity recognition module online.

2. The method according to claim 1, wherein: After the drone is powered on, the drone's digital identity module uses symmetric cryptography to verify whether the binding relationship with the flight control system has changed. Specifically, the following steps are performed: If a change in the binding relationship is detected, a multiple verification mechanism is activated, and the multiple verification mechanism is set with a predetermined number of verifications; if the consistency of the binding relationship cannot be successfully verified within the number of verifications, the drone digital identity recognition module automatically generates abnormal log information and records the details of the verification failure, and at the same time triggers the invalidation processing process of the drone digital identity certificate, making the drone digital identity certificate invalid.

3. The method according to claim 1, characterized in that The two-way authentication process includes: The drone digital identity recognition module calls the two-way authentication interface of the trusted digital identity management platform and sends the device certificate chain, which includes at least the issuing authority root certificate, the device manufacturer certificate, and the device certificate, to the trusted digital identity management platform; The trusted digital identity management platform checks whether the certificate system is supported based on the public key ID in the issuing organization's root certificate. If supported, it verifies the legitimacy of the root certificate, device manufacturer certificate, and device certificate in turn. If the root certificate, device manufacturer certificate, and device certificate are all legitimate, the trusted digital identity management platform will deem the drone to be issued by a legitimate organization.

4. The method according to claim 3, characterized in that After the drone is deemed to be issued by a legal agency, it also includes: The trusted digital identity management platform sends the platform certificate chain including at least the issuing authority root certificate and the platform certificate to the drone digital identity recognition module; The drone digital identity recognition module verifies the legitimacy of the received platform certificate chain. The drone digital identity authentication module first verifies whether the issuing agency's root certificate is the same as the locally stored root certificate. If they are the same, the public key of the root certificate is used to verify the legitimacy of the platform certificate. If the platform certificate chain is legal, the drone digital identity recognition module will consider the drone trusted digital identity management platform to be legal. At this point, the two-way authentication process between the drone and the drone trusted digital identity management platform is completed.

5. The method according to claim 4, characterized in that After two-way authentication is passed, the following steps are also included: The drone digital identity recognition module synchronizes device anomaly information and drone digital identity certificates to the drone trusted digital identity management platform; The drone trusted digital identity management platform synchronizes the received device anomaly information and drone digital identity certificate to the air traffic management platform; The air traffic management platform verifies the legitimacy of the synchronized drone digital identity certificate; If the drone's digital identity certificate is legal, the air traffic management platform will identify the drone's identity information and the operational identification information associated with the drone based on the information in the drone's digital identity certificate. The drone's identity information includes at least the drone manufacturer, the drone's unique product identification code, the drone's flight control serial number, the drone's digital identity module, and real-name registration information.

6. The method according to any one of claims 1 to 5, characterized in that: When the drone digital identification module detects an inconsistency in the binding relationship with the flight control system, it initiates a multiple verification mechanism. The drone digital identification module performs verification operations according to the following steps: Initial Verification: Use AES symmetric encryption technology to perform the initial verification of the current binding relationship and generate an encrypted binding verification code. This verification code is a unique value calculated based on the AES algorithm and the binding relationship information of both parties. The generated verification code is compared with the verification code stored in advance or provided by the flight control system to verify the consistency of the binding relationship. Repeated verification: If the initial verification fails, that is, the binding relationship verification is inconsistent, the repeated verification mechanism is activated. The repeated verification uses the same AES symmetric encryption technology as the initial verification, but may apply different encryption parameters or initialization vectors (IVs). According to a predetermined algorithm or rule, the binding relationship information is encrypted multiple times and a corresponding verification code is generated. The verification code generated by each repeated verification is compared with the expected value. If a verification code matches, the binding relationship is determined to be consistent in that verification, and the repeated verification can be stopped. The predetermined algorithm or rule at least includes adjusting encryption parameters, changing the encryption order, and introducing random factors. Verification times control: After each verification, the verification times are recorded. If the verification times reach the preset threshold, the verification is stopped. Exception handling: If all checks fail to verify the consistency of the binding relationship within the verification number threshold, the drone digital identity recognition module determines that the binding relationship is abnormal and automatically triggers the abnormal log generation logic.

7. A UAV trusted digital identity recognition system, characterized by: include: A drone digital identity recognition module, configured to execute the steps of the drone trusted digital identity recognition method according to any one of claims 1 to 5; A trusted digital identity management and control platform is used to establish a secure connection with the drone's digital identity module, perform two-way identity authentication, and receive and store information synchronized by the drone's digital identity module; The air traffic management platform is used to verify the legitimacy of drone digital identity certificates and monitor and manage flight activities based on the identified drone information.

8. The system according to claim 7, characterized in that: The drone digital identity module includes an application processor, a baseband processor, a GNSS positioning processor, and an eSIM. The module has the following functions: Mobile communication capabilities: Through the collaborative work of the baseband processor and eSIM, it achieves connection with the mobile communication network and data transmission, supports access and authentication of mobile communication services, and ensures that the drone can perform stable data communication during flight; Flight trajectory collection capability: Utilizes the multi-constellation GNSS receiver function supported by the GNSS positioning processor to collect the UAV's flight trajectory information in real time; Ability to securely store sensitive information: A secure storage area is provided in the eSIM to store basic drone information, digital identity certificates, and other sensitive data related to drone authentication and safe flight.

9. The system according to claim 8, characterized in that The application processor serves as a scheduling management function module, specifically including: A digital identity management component, which is configured to connect to a trusted digital identity management platform to query and execute digital identity management tasks issued by the platform, parse and install received drone digital identity certificates, and collect the drone's GNSS position information and report it online to the relevant platform or system; The Profile management component is configured to connect to a trusted digital identity management platform to query and execute Profile management tasks issued by the platform, parse and install received Profiles, and assist in remote management of Profiles.

10. The system according to claim 8, characterized in that: The baseband processor is configured to: Encodes and decodes wireless signals to enable data transmission and reception, thereby providing mobile communication services; communicates with the eSIM through the ISO7816 protocol to implement the authentication process of the mobile communication network; and transparently transmits CSIMAT commands sent by the application processor to the eSIM to cooperate with the implementation of the drone's digital identity management function; The eSIM is configured to: When receiving a CSIM AT command from the baseband processor, it performs corresponding mobile communication authentication operations according to the command content; it supports dynamic loading and switching of profiles of different operators to select the optimal mobile communication service based on the current area of the drone or the preset strategy; Provide a secure storage area for storing basic drone information, device certificates, drone digital identity certificates, and sensitive data related to mobile communications; Works with the application processor to respond to the application processor's requests for drone digital identity management functions.

Citation Information

Patent Citations

  • Unmanned aerial vehicle authentication method and system, unmanned aerial vehicle supervision platform and first equipment

    CN109995719A

  • Unmanned aerial vehicle digital identity management method, device, and medium

    CN112348529A

  • Identity generation and credibility authentication method for mobile terminal operating system

    CN116321175A

  • Communication method, apparatus, and system

    US20230014494A1

  • Method for establishing device binding relationship, and device

    WO2022217602A1

Cited By

  • Identity beacon authentication method based on commercial password technology and electric unmanned aerial vehicle system

    CN120857117A