Unmanned aerial vehicle data sharing method and device based on privacy protection

By using privacy computing technology to protect and collaboratively analyze drone data, protected data is generated, solving the problems of data leakage and centralization vulnerability in drone data sharing, and realizing secure and efficient data sharing and computing capabilities.

CN121356830APending Publication Date: 2026-01-16SHANDONG CHAOYUE DATA CONTROL ELECTRONICS CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202511444560.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-10
Publication Date
2026-01-16

AI Technical Summary

Technical Problem

Existing drone data sharing solutions suffer from risks of data leakage due to decryption and subsequent computation, single-point vulnerability of centralized architecture, and inability to dynamically adapt to the security requirements of complex scenarios.

Method used

Privacy computing technology is used to protect and process the flight data, environmental perception information and mission status data collected by the UAV, generate protected data, and upload it to the sharing platform through a secure channel for collaborative computing and analysis to generate intermediate results. Finally, the results are fed back to the UAV and the ground control terminal without decryption.

Benefits of technology

While ensuring the absolute security of sensitive information, it maintains efficient multi-party collaborative computing capabilities, achieves a balance between privacy protection and data value mining, and solves the data leakage risks and centralized architecture vulnerabilities in traditional encryption schemes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121356830A_ABST
    Figure CN121356830A_ABST
Patent Text Reader

Abstract

The invention discloses an unmanned aerial vehicle data sharing method and device based on privacy protection, and the method comprises the steps: collecting flight data, environment perception information and task state data through an unmanned aerial vehicle, combining an operation instruction, scheduling information and user authority data of a ground control end, and intelligently recognizing to-be-shared privacy data. According to the data type and the sensitivity level, the system performs protection processing on the sensitive data by adopting a privacy computing technology such as homomorphic encryption or differential privacy, generates protected data and uploads the protected data to a sharing platform through a secure channel. The platform directly executes cooperative calculation and analysis on the protected data without decryption, generates an intermediate result, and feeds back the intermediate result to a related terminal after inverse processing. The risk of data leakage caused by calculation after decryption in a traditional encryption scheme is solved, the high-efficiency multi-party cooperative calculation capability is maintained while absolute security of sensitive information is guaranteed, and a solution which gives consideration to privacy protection and data value mining is provided for an unmanned aerial vehicle system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of unmanned aerial vehicles (UAVs), and more particularly to a method and apparatus for sharing UAV data based on privacy protection. Background Technology

[0002] With the deep integration and widespread application of drone technology in logistics, agricultural plant protection, and emergency rescue, the frequency and volume of data interaction between drones and ground control stations have experienced explosive growth. This interactive data typically contains highly sensitive information, such as the aircraft's real-time precise trajectory, high-definition environmental images, mission execution status, and user identification. If this data is maliciously intercepted or tampered with during transmission or processing, it could not only lead to the failure of critical missions but also trigger serious privacy breaches and even national security risks.

[0003] Currently, mainstream solutions for ensuring the security of such data still rely on traditional encryption algorithms, such as AES or RSA. These solutions typically encrypt data before transmission and decrypt it at the receiving end before performing calculations and analysis. However, this decryption-then-computation model has inherent flaws: the decrypted data is in plaintext, facing the risk of leakage from within or outside the system during processing. Furthermore, existing systems often rely on a centralized third-party platform for data storage and computation, making this central node a prime target for attackers and posing a single point of failure risk. More importantly, traditional encryption technologies cannot effectively prevent inference attacks that use the final computation results (such as statistical aggregation data) to deduce sensitive individual information, making it difficult to balance data availability and individual privacy protection in collaborative group scenarios.

[0004] On the other hand, existing solutions typically lack dynamic adaptability, and their security strategies are often static and fixed. It is difficult to intelligently adjust the technical path and strength of data protection based on different task types (such as routine inspections and classified reconnaissance), fluctuating network conditions, and the dynamic sensitivity level of the data itself. Summary of the Invention

[0006] This application provides a privacy-preserving method and apparatus for sharing drone data, which addresses the risks of privacy leakage caused by the need for decryption calculations during drone data sharing, the single-point vulnerability of centralized architecture, and the inability to dynamically adapt to the security requirements of complex scenarios in existing technologies.

[0007] Firstly, this application provides a privacy-preserving method for sharing drone data, including:

[0008] The drones are used to collect flight data, environmental perception information and mission status data, while the ground control terminal is used to collect operation instructions, scheduling information and user permission data.

[0009] Based on flight data, environmental awareness information, mission status data, operational instructions, scheduling information, and user permission data, determine the privacy data to be shared;

[0010] Based on the data type and sensitivity level of privacy data, privacy computing technology is used to protect and process privacy data in order to generate protected data;

[0011] The protected data is uploaded to the sharing platform through a secure channel, so that the sharing platform can perform collaborative calculation and analysis on the protected data without decryption, and generate intermediate results in the corresponding transformed form;

[0012] The intermediate results are then reverse-processed, and the final result is fed back to the UAV and / or ground control terminal.

[0013] Secondly, this application provides a privacy-preserving drone data sharing device, comprising:

[0014] The data acquisition module is configured to collect flight data, environmental perception information and mission status data using the UAV, and to collect operation instructions, scheduling information and user permission data using the ground control terminal.

[0015] The privacy data determination module is configured to determine the privacy data to be shared based on flight data, environmental awareness information, mission status data, operation instructions, scheduling information, and user permission data.

[0016] The protected data generation module is configured to use privacy computing technology to protect privacy data based on the data type and sensitivity level of the privacy data in order to generate protected data.

[0017] The intermediate result determination module is configured to upload the protected data to the sharing platform through a secure channel, so that the sharing platform can perform collaborative calculation and analysis on the protected data without decrypting the protected data, and generate intermediate results in the corresponding transformed form;

[0018] The feedback module is configured to perform corresponding inverse processing on the intermediate results and feed back the processed final results to the UAV and / or ground control terminal.

[0019] Thirdly, this application provides a readable medium including executable instructions, which, when executed by a processor of an electronic device, cause the electronic device to perform any of the methods described in the first aspect.

[0020] Fourthly, this application provides an electronic device including a processor and a memory storing execution instructions, wherein when the processor executes the execution instructions stored in the memory, the processor performs the method as described in any of the first aspects.

[0021] This application provides a privacy-preserving method and apparatus for sharing unmanned aerial vehicle (UAV) data. It utilizes the UAV to collect flight data, environmental perception information, and mission status data, and uses a ground control terminal to collect operation commands, scheduling information, and user permission data. Based on the flight data, environmental perception information, mission status data, operation commands, scheduling information, and user permission data, privacy-preserving data to be shared is determined. Based on the data type and sensitivity level of the privacy-preserving data, privacy computing technology is used to protect and process the data, generating protected data. The protected data is uploaded to a sharing platform via a secure channel, allowing the sharing platform to perform collaborative computation and analysis on the protected data without decryption, generating intermediate results in corresponding transformed forms. The intermediate results undergo inverse processing, and the final processed result is fed back to the UAV and / or the ground control terminal. This solution addresses the data leakage risk caused by decryption before computation in traditional encryption schemes, maintaining efficient multi-party collaborative computing capabilities while ensuring the absolute security of sensitive information, providing a solution for UAV systems that balances privacy protection and data value mining.

[0022] The further effects of the aforementioned non-conventional preferred method will be explained below in conjunction with specific embodiments. Attached Figure Description

[0023] To more clearly illustrate the embodiments of this application or the existing technical solutions, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0024] Figure 1 A schematic flowchart illustrating a privacy-preserving drone data sharing method according to an embodiment of this application;

[0025] Figure 2 A flowchart illustrating another privacy-preserving drone data sharing method provided in an embodiment of this application;

[0026] Figure 3 A flowchart illustrating another privacy-preserving drone data sharing method provided in an embodiment of this application;

[0027] Figure 4This is a schematic diagram of the structure of a privacy-protected drone data sharing device provided in one embodiment of this application;

[0028] Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0029] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below in conjunction with specific embodiments and corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0030] With the deep integration and widespread application of drone technology in logistics, agricultural plant protection, and emergency rescue, the frequency and volume of data interaction between drones and ground control stations have experienced explosive growth. This interactive data typically contains highly sensitive information, such as the aircraft's real-time precise trajectory, high-definition environmental images, mission execution status, and user identification. If this data is maliciously intercepted or tampered with during transmission or processing, it could not only lead to the failure of critical missions but also trigger serious privacy breaches and even national security risks.

[0031] Currently, mainstream solutions for ensuring the security of such data still rely on traditional encryption algorithms, such as AES or RSA. These solutions typically encrypt data before transmission and decrypt it at the receiving end before performing calculations and analysis. However, this decryption-then-computation model has inherent flaws: the decrypted data is in plaintext, facing the risk of leakage from within or outside the system during processing. Furthermore, existing systems often rely on a centralized third-party platform for data storage and computation, making this central node a prime target for attackers and posing a single point of failure risk. More importantly, traditional encryption technologies cannot effectively prevent inference attacks that use the final computation results (such as statistical aggregation data) to deduce sensitive individual information, making it difficult to balance data availability and individual privacy protection in collaborative group scenarios.

[0032] On the other hand, existing solutions typically lack dynamic adaptability, and their security strategies are often static and fixed. It is difficult to intelligently adjust the technical path and strength of data protection based on different task types (such as routine inspections and classified reconnaissance), fluctuating network conditions, and the dynamic sensitivity level of the data itself.

[0033] To address this issue, this application proposes a privacy-preserving drone data sharing method, aiming to resolve the privacy leakage risks caused by decryption calculations required during drone data sharing in existing technologies, the single point of vulnerability of centralized architectures, and the inability to dynamically adapt to the security requirements of complex scenarios. In this embodiment, a privacy-preserving drone data sharing method includes:

[0034] Step 101: Use the UAV to collect flight data, environmental perception information and mission status data, and use the ground control terminal to collect operation instructions, scheduling information and user permission data.

[0035] As a mobile data source, drones continuously collect various key information generated during mission execution. Flight data mainly includes real-time three-dimensional coordinates, flight speed vector, flight altitude, heading angle, and flight trajectory, providing fundamental support for subsequent path planning and mission scheduling. Environmental perception information encompasses surrounding environmental data acquired through onboard sensors, such as weather conditions, terrain, obstacle distribution, and target recognition results; this type of information is crucial for the safety and effectiveness of mission execution. Mission status data reflects the drone's current operating status, including operational parameters such as battery level, equipment health, mission progress, and payload status.

[0036] The ground control center, acting as the command hub, is responsible for collecting various information related to mission management and system control. Operational instructions include commands for flight path planning, mission allocation, and emergency control, reflecting the decision-making intentions of ground operators. Scheduling information covers management data such as resource allocation, time scheduling, and priority settings in multi-aircraft collaborative missions. User access data includes security management information such as operator authentication, access permission levels, and operation logs, ensuring the compliance and traceability of system operations.

[0037] Step 102: Based on flight data, environmental awareness information, mission status data, operation instructions, scheduling information, and user permission data, determine the privacy data to be shared.

[0038] The system first performs a comprehensive analysis of multi-source heterogeneous data, including flight data, environmental awareness information, mission status data, operational instructions, scheduling information, and user permission data. Based on data content characteristics, application scenario requirements, and security policy requirements, it identifies subsets of data with privacy sensitivity or confidentiality. This process needs to consider the direct sensitivity of the data, such as precise geographic coordinates and high-resolution environmental images, which are clearly sensitive information. It also needs to identify the indirect sensitivity of the data, that is, data whose sensitive information can be inferred through data mining or correlation analysis.

[0039] In identifying privacy-sensitive data, the system employs a multi-dimensional evaluation mechanism. First, it performs an initial classification based on data type, categorizing location information, image data, and user identifiers as highly sensitive, while general task status and device parameters are classified as medium- to low-sensitivity. Second, it considers the specificities of the application scenario; for example, in high-security scenarios such as military or emergency rescue, data that was initially classified as low-sensitivity may require an upgraded protection level. The system also dynamically evaluates the timeliness and relevance of the data to ensure that the identification of privacy-sensitive data is both comprehensive and accurate, providing precise input for subsequent protection processing.

[0040] Step 103: Based on the data type and sensitivity level of the privacy data, privacy computing technology is used to protect the privacy data in order to generate protected data.

[0041] Once the privacy data is identified, the system selects the most suitable privacy-preserving computation technology for protection based on the data characteristics. This ensures the complete protection of the data's privacy attributes while maintaining its computational value. The system first assesses the sensitivity level of the privacy data, establishing a multi-level classification system from low to high sensitivity, with different levels of sensitivity corresponding to different strengths of protection measures.

[0042] Data type analysis is a crucial basis for selecting protection technologies. For data requiring precise numerical calculations, such as coordinate positions and sensor readings, the system tends to employ homomorphic encryption to ensure that addition and multiplication operations can still be performed in encrypted form. For aggregated data primarily used for statistical analysis, such as group behavior patterns and resource usage statistics, differential privacy technology is more suitable, protecting individual privacy by adding carefully designed noise. During the protection process, the system also considers practical constraints such as computational efficiency, storage overhead, and network transmission costs, seeking the optimal balance between privacy protection strength and system performance.

[0043] Step 104: Upload the protected data to the sharing platform through a secure channel so that the sharing platform can perform collaborative calculation and analysis on the protected data without decryption, and generate intermediate results in the corresponding transformed form.

[0044] Protected data is uploaded to the sharing platform via a pre-established secure communication channel. The sharing platform has the capability to perform calculations directly on encrypted or noisy data. The establishment of the secure channel employs multiple security mechanisms, including transport layer encryption, authentication, and integrity verification, to ensure that data is not eavesdropped on or tampered with during transmission. As the core node for data processing, the sharing platform deploys a dedicated privacy computing engine capable of identifying different types of protected data and invoking corresponding computational algorithms.

[0045] For homomorphically encrypted data, the platform leverages the properties of homomorphic operations to directly perform various mathematical operations on the ciphertext, generating computation results that are also encrypted. For differentially private data, the platform uses a specially designed aggregation algorithm to extract valuable statistical information while maintaining differential privacy. Throughout the entire computation process, the platform does not need to access any plaintext data, effectively avoiding the risk of data leakage. The computation results exist in a corresponding transformed form, preparing for subsequent result processing and distribution.

[0046] Step 105: Perform the corresponding reverse processing on the intermediate results and feed back the processed final results to the UAV and / or ground control terminal.

[0047] The inverse processing of intermediate results requires performing corresponding reverse operations based on the type of protection technology used in the initial stages. For results generated by homomorphic encryption, the system uses the corresponding private key to decrypt the ciphertext, converting it into a directly usable plaintext form. For results after differential privacy processing, the system employs specialized denoising algorithms and statistical estimation methods to maximize the usability of the recovered results while maintaining privacy protection.

[0048] The processed results are selectively fed back to the drone, ground control, or both, based on their content characteristics and application requirements. The feedback mechanism supports multiple formats, including real-time push notifications, periodic batch transmissions, and on-demand queries, to adapt to different application scenarios. For drones, the feedback results are primarily used for real-time adjustment of flight parameters and optimization of mission execution strategies; for ground control, the results are more often used for global decision support, resource scheduling optimization, and situational awareness updates. The entire feedback process also adheres to secure transmission protocols to ensure the confidentiality and integrity of the final results, forming a complete closed loop for privacy-protected data sharing.

[0049] As can be seen from the above technical solutions, the beneficial effects of this embodiment are:

[0050] This application provides a privacy-preserving UAV data sharing method. It utilizes the UAV to collect flight data, environmental perception information, and mission status data, and uses a ground control terminal to collect operation commands, scheduling information, and user permission data. Based on the flight data, environmental perception information, mission status data, operation commands, scheduling information, and user permission data, privacy-preserving data to be shared is determined. Based on the data type and sensitivity level of the privacy-preserving data, privacy computing technology is used to protect and process the data, generating protected data. The protected data is uploaded to a sharing platform through a secure channel, allowing the sharing platform to perform collaborative computation and analysis on the protected data without decryption, generating intermediate results in corresponding transformed forms. The intermediate results are then subjected to inverse processing, and the final processed result is fed back to the UAV and / or the ground control terminal. This method solves the data leakage risk caused by decryption before computation in traditional encryption schemes, maintaining efficient multi-party collaborative computing capabilities while ensuring the absolute security of sensitive information, providing a solution for UAV systems that balances privacy protection and data value mining.

[0051] Figure 1 The example shown is merely a basic embodiment of a privacy-preserving drone data sharing method according to this application. With certain optimizations and extensions, other preferred embodiments of a privacy-preserving drone data sharing method can be obtained.

[0052] like Figure 2 The image shows another specific embodiment of a privacy-preserving drone data sharing method according to this application.

[0053] In this embodiment, a privacy-preserving method for sharing drone data includes the following steps:

[0054] Step 201: Use the UAV to collect flight data, environmental perception information and mission status data, and use the ground control terminal to collect operation instructions, scheduling information and user permission data.

[0055] Step 202: Based on flight data, environmental awareness information, mission status data, operation instructions, scheduling information, and user permission data, determine the privacy data to be shared.

[0056] Step 203: Based on the data type and sensitivity level of the privacy data, privacy computing technology is used to protect the privacy data in order to generate protected data.

[0057] Step 204: Based on homomorphic encryption technology, encrypt the numerical sensitive information in the privacy data to generate homomorphic ciphertext.

[0058] The system specifically implements homomorphic encryption protection for numerically sensitive information, which typically includes sensitive data that can be mathematically processed, such as the precise coordinates of a drone, numerical readings collected by sensors, and equipment status parameters. The system first identifies and analyzes the data type of the privacy data, extracts the numerical information, and preprocesses it, including data format standardization, precision adjustment, and range normalization, to ensure that these values ​​are compatible with the input requirements of the homomorphic encryption algorithm.

[0059] The choice of homomorphic encryption technology is based on specific application requirements and computational complexity. For scenarios requiring complex floating-point operations, the system prioritizes the CKKS (Cheon-Kim-Kim-Song) scheme, which specifically supports approximate numerical calculations and is particularly suitable for handling continuous values ​​such as coordinate positions and sensor readings. For scenarios primarily involving integer operations, the system can choose the BFV (Brakerski-Fan-Vercauteren) or BGV (Brakerski-Gentry-Vercauteren) schemes, which provide precise homomorphic operation support in the integer domain. During encryption, the system uses a pre-generated public key to independently encrypt each numerically sensitive piece of information, generating corresponding homomorphic ciphertext. These homomorphic ciphertexts completely hide the plaintext information while maintaining the original numerical operation characteristics, making it impossible for an attacker to deduce the original value even if they obtain the ciphertext.

[0060] Step 205: Determine the homomorphic ciphertext as protected data.

[0061] The ciphertext generated after homomorphic encryption is officially designated as protected data. This confirmation process includes integrity verification and security assessment. The system performs quality checks on the generated homomorphic ciphertext to ensure the correctness of the encryption process and the validity of the ciphertext. This includes verifying whether the ciphertext format meets the requirements of subsequent calculations, checking whether the noise level of the ciphertext is within an acceptable range, and confirming that the ciphertext can support the expected homomorphic operations.

[0062] The identification of protected data also involves the secure processing of metadata. The system assigns a unique identifier to each homomorphic ciphertext and establishes a mapping between the ciphertext and attributes such as the original data type, computational requirements, and security level. This metadata is also protected to prevent the leakage of sensitive information through metadata analysis. Simultaneously, the system records information such as the ciphertext's generation time, encryption parameters, and intended use, providing necessary contextual information for subsequent ciphertext management and decryption operations. This entire verification process ensures the security, availability, and manageability of the protected data, laying the foundation for subsequent secure transmission and collaborative computing.

[0063] Step 206: Upload the protected data to the sharing platform through a secure channel so that the sharing platform can perform collaborative calculation and analysis on the protected data without decryption, and generate intermediate results in the corresponding transformed form.

[0064] The sharing platform performs ciphertext addition or ciphertext multiplication on the homomorphic ciphertext to determine the first aggregated statistical result corresponding to the homomorphic ciphertext; the first aggregated statistical result is input into the path planning algorithm or decision model running in the ciphertext state to generate path planning suggestions or task decision schemes in the encrypted state; the path planning suggestions or task decision schemes are determined as intermediate results.

[0065] The protected homomorphic ciphertext is uploaded to the sharing platform via an established secure channel. The sharing platform is equipped with a dedicated homomorphic computing engine, capable of performing complex mathematical operations and algorithmic processing without decrypting the data. The secure channel employs a multi-layered protection mechanism, combining transmission encryption, digital signatures, and timestamping technologies to ensure the confidentiality, integrity, and authenticity of the ciphertext during transmission. Upon receiving the homomorphic ciphertext, the platform first performs identity verification and format validation to confirm the legitimacy of the data source and the integrity of the data structure.

[0066] The shared platform performs ciphertext addition on multiple received homomorphic ciphertexts to achieve aggregated statistics on distributed data, such as calculating the average position and overall energy consumption of multiple drones. Ciphertext multiplication supports more complex mathematical models, such as covariance calculation and regression analysis. The results of these basic operations form the first aggregated statistical result, providing input data for advanced algorithms.

[0067] The sharing platform further inputs the aggregation results into path planning algorithms specifically adapted for homomorphic computation. These algorithms are specially designed to perform complex calculations such as shortest path search, obstacle avoidance planning, and multi-objective optimization in encrypted form. The decision model also runs in an encrypted environment, generating decision schemes such as task allocation and resource scheduling based on encrypted state information and constraints. Throughout the entire computation process, the data remains encrypted, and the generated path planning suggestions and task decision schemes also exist in encrypted form, becoming intermediate results for subsequent processing.

[0068] Step 207: Perform the corresponding reverse processing on the intermediate results and feed back the processed final results to the UAV and / or ground control terminal.

[0069] Using the private key corresponding to the public key used when encrypting private data, the intermediate results are decrypted to obtain the plaintext results; the plaintext results are then sent to the drone as the final results to adjust the drone's flight path or mission status.

[0070] The inverse processing of intermediate results requires decryption of the ciphertext using the private key paired with the encryption key. Decryption involves more than just simple key manipulation; it includes complex steps such as noise management, precision recovery, and format conversion. Because homomorphic operations accumulate noise, the decrypted result may require precision correction and numerical optimization to ensure the accuracy and usability of the final result. The system employs specialized noise control techniques and error correction algorithms to maximize the accuracy of the recovered calculation results.

[0071] The decrypted plaintext results, after being formatted and verified, are sent as the final result to the appropriate recipient. For UAVs, these results mainly include directly executable control information such as optimized flight path coordinates, speed adjustment suggestions, and mission parameter modification commands. Upon receiving these results, the UAV can immediately apply them to its flight control system to perform operations such as path adjustment, speed optimization, and mission status updates. The result transmission also employs a secure communication protocol to ensure that the final result is not tampered with or intercepted during transmission. The entire process achieves a complete conversion from encrypted computation to plaintext application, guaranteeing the practicality and security of data processing.

[0072] As can be seen from the above technical solutions, the beneficial effects of this embodiment are as follows: By employing homomorphic encryption technology to provide end-to-end protection for numerically sensitive information, accurate numerical calculations and complex algorithm execution are achieved while maintaining complete data encryption, fundamentally solving the data exposure risk caused by decryption before calculation in traditional solutions. By supporting basic operations such as addition and multiplication in encrypted state, as well as advanced algorithms such as path planning and decision optimization, a perfect unity between data privacy protection and computational functions is achieved, ensuring that sensitive location information and sensor data remain encrypted throughout the entire processing flow. Through a specially designed homomorphic computation engine and noise management mechanism, high-precision encrypted calculation results are achieved, ensuring that privacy protection does not come at the expense of computational accuracy, providing a secure and practical data sharing solution for UAV systems.

[0073] like Figure 3 The image shows another specific embodiment of a privacy-preserving drone data sharing method according to this application. This embodiment is further described based on the foregoing embodiments.

[0074] In this embodiment, a privacy-preserving method for sharing drone data includes the following steps:

[0075] Step 301: Use the UAV to collect flight data, environmental perception information and mission status data, and use the ground control terminal to collect operation instructions, scheduling information and user permission data.

[0076] Step 302: Based on flight data, environmental awareness information, mission status data, operation instructions, scheduling information, and user permission data, determine the privacy data to be shared.

[0077] Step 303: Based on the data type and sensitivity level of the privacy data, privacy computing technology is used to protect the privacy data in order to generate protected data.

[0078] Step 304: Determine the privacy budget corresponding to the privacy data.

[0079] The system first assesses overall privacy requirements based on the importance level of the tasks, the sensitivity of the data, and the expected query frequency. The privacy budget is typically represented by an ε value, which controls the strength of differential privacy protection. A smaller ε value indicates stricter privacy protection, but also means more noise is added and data availability is relatively lower. The system employs a multi-tiered budget allocation strategy, allocating different budget amounts based on the importance and sensitivity of different types of data.

[0080] During the budget determination process, the system also needs to consider budget consumption over time. Because differential privacy has a combinatorial nature, multiple queries will accumulate and consume the privacy budget; therefore, the system has established a dynamic budget management mechanism. For frequently queried data types, the system allocates a relatively large initial budget and implements a budget reset strategy; for sensitive data with infrequent queries, the system adopts a more conservative budget allocation scheme.

[0081] Meanwhile, taking into account the different privacy protection needs of different mission scenarios, the system can adopt a more lenient privacy budget in daily training mode, while adopting stricter budget control in high-security scenarios such as actual combat or emergency rescue, to ensure data security in critical missions.

[0082] Step 305: Determine the corresponding noise perturbation mechanism based on the data type and sensitivity level of the privacy data; the noise perturbation mechanism includes the Laplace mechanism and the Gaussian mechanism.

[0083] The system performs mechanism matching based on the specific characteristics of the privacy data, primarily considering factors such as data distribution characteristics, query type, and accuracy requirements. The Laplace mechanism is suitable for handling numerical queries with bounded sensitivity, especially linear statistical operations such as counting and summation queries. Its noise distribution exhibits double-exponential characteristics, providing good data utility while ensuring ε-differential privacy. For scenarios such as location statistics, battery level summarization, and mission completion counting in UAV systems, the Laplace mechanism offers ideal privacy protection.

[0084] Gaussian mechanisms are better suited for scenarios with lower sensitivity or requiring finer control. Based on a Gaussian noise distribution, they provide (ε,δ)-differential privacy guarantees. In scenarios requiring complex statistical analysis or machine learning tasks, Gaussian mechanisms typically offer better data utility.

[0085] The system also considers computational complexity and implementation difficulty during mechanism selection. The Laplace mechanism is relatively simple to implement and has low computational overhead, making it suitable for resource-constrained UAV environments. While the Gaussian mechanism performs better in certain scenarios, it requires more computational resources and more complex parameter tuning. The system has established an intelligent mechanism selection algorithm that can automatically select the optimal noise perturbation mechanism based on real-time data characteristics and system status.

[0086] Step 306: Based on the noise perturbation mechanism and privacy budget, inject the corresponding perturbation noise into the privacy data to generate the corresponding noise perturbation data.

[0087] Based on a defined noise perturbation mechanism and privacy budget, the system begins to precisely inject perturbation noise into the original privacy data. The noise injection process must adhere to the mathematical principles of differential privacy, ensuring that the added noise satisfies privacy requirements without excessively compromising data usability. For the Laplace mechanism, the system calculates the noise amplitude parameter based on the sensitivity of the query function and the privacy budget ε, and then samples the corresponding noise values ​​from the Laplace distribution. The noise amplitude is directly proportional to the sensitivity and inversely proportional to the privacy budget, ensuring that more noise is added in scenarios with high sensitivity or strict privacy requirements.

[0088] For the implementation of the Gaussian mechanism, the system needs to consider two privacy parameters, ε and δ, and determine the standard deviation of Gaussian noise through more complex mathematical calculations. During the noise injection process, the system also implements several optimization strategies to improve data utility. These include using intelligent rounding techniques to reduce the impact of noise on integer data, using post-processing consistency constraints to ensure the logical relationships between related data, and implementing adaptive noise adjustment to cope with dynamic changes in data distribution. The generated noise-perturbed data maintains the basic statistical characteristics and business meaning of the original data, but individual records are effectively protected. Even if an attacker obtains the perturbed data, they cannot accurately infer the true information of any specific individual.

[0089] Step 307: Determine the noise disturbance data as protected data.

[0090] Noise-perturbed data is officially designated as protected data after quality verification and security assessment. First, the system verifies whether the perturbed data meets the preset differential privacy parameter requirements, confirming the correctness and sufficiency of the noise addition through theoretical analysis and statistical testing. Second, the system assesses the usability loss of the perturbed data, ensuring that the data can still support the intended analysis and decision-making tasks while meeting privacy protection requirements.

[0091] The verification of protected data also includes format standardization and metadata processing. The system assigns a unique identifier to each piece of noise-perturbed data and records key information such as its corresponding privacy parameters, perturbation mechanism type, and generation time. This metadata will be used for subsequent data management and analysis operations.

[0092] Meanwhile, the system establishes a version management mechanism for protected data, supporting data traceability and auditing to ensure the transparency and verifiability of the entire privacy protection process. Once confirmed, this protected data becomes the input for subsequent secure transmission and collaborative computing, laying the foundation for the smooth operation of the entire privacy-protected data sharing process.

[0093] Step 308: Upload the protected data to the sharing platform through a secure channel so that the sharing platform can perform collaborative calculation and analysis on the protected data without decryption, and generate intermediate results in the corresponding transformed form.

[0094] The shared platform performs an aggregation query operation on the noise disturbance data to generate the corresponding second aggregation statistical result; based on the second aggregation statistical result, it performs group task status analysis or resource demand assessment to generate task scheduling suggestions or resource reallocation schemes; and it determines the task scheduling suggestions or resource reallocation schemes as intermediate results.

[0095] After noise disturbance data is uploaded to the sharing platform via a secure channel, the platform processes and analyzes the data using a specially designed differential privacy aggregation algorithm. The platform first performs aggregation queries on the received multi-source noise disturbance data. These operations are specifically optimized for differential privacy data, enabling the extraction of valuable statistical information even in the presence of noise. Aggregation queries include basic statistical operations such as count queries, summation queries, and mean calculations, as well as more complex advanced operations such as grouping statistics and conditional queries. Through these aggregation operations, the platform generates second aggregated statistical results that reflect the overall status and trends of the drone swarm, without revealing the specific information of any individual drone.

[0096] Based on the second aggregated statistical results, the platform further performs group task status analysis and resource demand assessment. Group task status analysis identifies bottlenecks and optimization opportunities in overall task execution through comprehensive analysis of information such as the progress, battery status, and location distribution of multiple drone tasks. Resource demand assessment, based on aggregated resource usage data, predicts future resource demand trends and allocation priorities. These analytical processes are conducted under differential privacy protection, ensuring that the analysis results cannot be used to infer sensitive information about individual drones. Finally, the platform generates task scheduling suggestions and resource reallocation schemes. These schemes are formulated based on group statistical characteristics, optimizing overall system performance without compromising individual privacy.

[0097] Step 309: Perform the corresponding reverse processing on the intermediate results and feed back the processed final results to the UAV and / or ground control terminal.

[0098] The intermediate results are denoised using a mathematical filtering algorithm to generate statistical reports or scheduling instructions; the statistical reports or scheduling instructions are then used as the final results and broadcast to the UAV and / or ground control terminal.

[0099] The inverse processing of intermediate results mainly involves noise removal and signal recovery. The system employs mathematical filtering algorithms to process noisy intermediate results. These algorithms maximize the recovery of useful information while maintaining differential privacy. The filtering process includes noise estimation based on statistical characteristics, denoising techniques based on signal processing theory, and adaptive filtering methods based on machine learning. Different filtering algorithms are suitable for different types of query results and application scenarios. The system automatically selects the optimal denoising strategy based on the characteristics of the intermediate results.

[0100] After noise reduction, the system generates standardized statistical reports and specific dispatch instructions. The statistical reports present the group analysis results in various formats, including charts, numerical values, and text, providing decision-makers with comprehensive situational awareness information. The dispatch instructions include actionable suggestions such as task allocation, path adjustments, and resource reconfiguration. These final results maintain necessary accuracy and practicality while ensuring that no sensitive information about any individual can be inferred from the analysis. Results broadcasting employs multi-channel concurrent transmission to ensure that all relevant UAVs and ground control terminals receive the latest dispatch information and statistical reports in a timely manner, achieving coordinated operation of the entire system.

[0101] As can be seen from the above technical solutions, the beneficial effects of this embodiment are as follows: By employing the Laplace and Gaussian noise mechanisms in differential privacy technology, strong protection is achieved for sensitive individual data, ensuring that even if an attacker obtains the processing results, they cannot infer the true state information of any specific drone, fundamentally preventing privacy leakage attacks based on statistical inference. Through privacy budget allocation strategies and noise injection algorithms, an optimal balance between privacy protection strength and data availability is achieved, satisfying the needs of group collaborative analysis while ensuring the absolute security of individual data. Through specially optimized differential privacy aggregation algorithms and intelligent denoising technology, high-quality group analysis and accurate decision support are achieved in noisy environments, providing a data sharing solution for drone swarm systems that both protects privacy and supports effective collaboration.

[0102] like Figure 4 The image shown is a specific embodiment of a privacy-preserving drone data sharing device according to this application. This embodiment describes a privacy-preserving drone data sharing device, specifically used for executing... Figures 1 to 3 A physical device for a privacy-preserving drone data sharing method is described. Its technical solution is essentially the same as the embodiments described above, and the corresponding descriptions in the embodiments above also apply to this embodiment. This embodiment of a privacy-preserving drone data sharing device includes:

[0103] The data acquisition module 401 is configured to collect flight data, environmental perception information and mission status data using the UAV, and to collect operation instructions, scheduling information and user permission data using the ground control terminal.

[0104] The privacy data determination module 402 is configured to determine the privacy data to be shared based on flight data, environmental awareness information, mission status data, operation instructions, scheduling information and user permission data.

[0105] The protected data generation module 403 is configured to use privacy computing technology to protect privacy data based on the data type and sensitivity level of the privacy data in order to generate protected data.

[0106] The intermediate result determination module 404 is configured to upload the protected data to the sharing platform through a secure channel, so that the sharing platform can perform collaborative calculation and analysis on the protected data without decrypting the protected data, and generate intermediate results in the corresponding transformed form;

[0107] Feedback module 405 is configured to perform corresponding inverse processing on intermediate results and feed back the processed final results to the UAV and / or ground control terminal.

[0108] Figure 5This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. At the hardware level, the electronic device includes a processor, and optionally also includes an internal bus, a network interface, and a memory. The memory may include RAM, such as high-speed random-access memory (RAM), or non-volatile memory, such as at least one disk storage device. Of course, the electronic device may also include other hardware required for other services.

[0109] The processor, network interface, and memory can be interconnected via an internal bus, which can be an ISA (Industry Standard Architecture) bus, a PCI (Peripheral Component Interconnect) bus, or an EISA (Extended Industry Standard Architecture) bus, etc. This bus can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 5 The symbol is represented by a single double-headed arrow, but this does not mean that there is only one bus or one type of bus.

[0110] Memory is used to store instructions for execution. Specifically, instructions for execution are computer programs that can be executed. Memory can include main memory and non-volatile memory, and it provides the processor with execution instructions and data.

[0111] In one possible implementation, the processor reads the corresponding execution instructions from non-volatile memory into main memory and then executes them. Alternatively, it may obtain the corresponding execution instructions from other devices to logically form a privacy-preserving drone data sharing device. The processor executes the execution instructions stored in the memory to implement a privacy-preserving drone data sharing method provided in any embodiment of this application.

[0112] The above is as stated in this application. Figure 4The method implemented by the privacy-preserving drone data sharing device in the illustrated embodiment can be applied to or implemented by a processor. The processor may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by integrated logic circuits in the processor's hardware or by instructions in software form. The processor can be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; it can also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor.

[0113] The steps of the method disclosed in the embodiments of this application can be directly manifested as being executed by a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software modules can reside in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. This storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method.

[0114] This application also proposes a readable medium storing execution instructions. When these instructions are executed by the processor of an electronic device, the electronic device can perform a privacy-preserving drone data sharing method provided in any embodiment of this application, specifically for executing, as... Figure 1 or Figure 2 or Figure 3 The method shown.

[0115] The electronic devices in the foregoing embodiments may be computers.

[0116] Those skilled in the art will understand that the embodiments of this application can be provided as methods or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or a combination of software and hardware.

[0117] The various embodiments in this application are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the apparatus embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions of the method embodiments.

[0118] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0119] The above are merely embodiments of this application and are not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.

Claims

1. A privacy-preserving method for sharing drone data, characterized in that, include: The drones are used to collect flight data, environmental perception information and mission status data, while the ground control terminal is used to collect operation instructions, scheduling information and user permission data. Based on the flight data, the environmental awareness information, the mission status data, the operation instructions, the scheduling information, and the user permission data, determine the privacy data to be shared; Based on the data type and sensitivity level of the privacy data, privacy computing technology is used to protect the privacy data in order to generate protected data. The protected data is uploaded to the sharing platform through a secure channel, so that the sharing platform can perform collaborative calculation and analysis on the protected data without decrypting it, and generate intermediate results in the corresponding transformed form. The intermediate results are then subjected to inverse processing, and the final processed result is fed back to the UAV and / or the ground control terminal.

2. The method according to claim 1, characterized in that, The privacy computing technology employs homomorphic encryption. Therefore, the process of protecting the privacy data based on its data type and sensitivity level, using privacy computing technology to generate protected data, includes: Based on the homomorphic encryption technology, the numerical sensitive information in the privacy data is encrypted to generate homomorphic ciphertext; The homomorphic ciphertext is identified as the protected data.

3. The method according to claim 2, characterized in that, The step of performing collaborative computation and analysis on the protected data to generate intermediate results in the corresponding transformed form includes: The sharing platform performs ciphertext addition or ciphertext multiplication on the homomorphic ciphertext to determine the first aggregated statistical result corresponding to the homomorphic ciphertext; The first aggregated statistical result is input into the path planning algorithm or decision model running in the encrypted state to generate path planning suggestions or task decision schemes in the encrypted state. The path planning suggestion or the task decision scheme is determined as the intermediate result.

4. The method according to claim 3, characterized in that, The step of performing corresponding inverse processing on the intermediate results and feeding back the processed final results to the UAV and / or the ground control terminal includes: The intermediate result is decrypted using the private key corresponding to the public key used to encrypt the privacy data to obtain the plaintext result. The plaintext result is sent to the drone as the final result to adjust the drone's flight path or mission status.

5. The method according to claim 1, characterized in that, The privacy computing technology employs differential privacy technology. Therefore, the process of using privacy computing technology to protect the privacy data based on its data type and sensitivity level to generate protected data includes: Determine the privacy budget corresponding to the privacy data; Based on the data type and sensitivity level of the privacy data, a corresponding noise perturbation mechanism is determined; the noise perturbation mechanism includes the Laplace mechanism and the Gaussian mechanism; Based on the noise perturbation mechanism and the privacy budget, corresponding perturbation noise is injected into the privacy data to generate corresponding noise perturbation data; The noise disturbance data is identified as the protected data.

6. The method according to claim 5, characterized in that, The step of performing collaborative computation and analysis on the protected data to generate intermediate results in the corresponding transformed form includes: The sharing platform performs an aggregation query operation on the noise disturbance data to generate a corresponding second aggregation statistical result; Based on the second aggregated statistical results, perform group task status analysis or resource demand assessment, and generate task scheduling suggestions or resource reallocation schemes. The task scheduling suggestion or the resource reallocation scheme is determined as the intermediate result.

7. The method according to claim 6, characterized in that, The step of performing corresponding inverse processing on the intermediate results and feeding back the processed final results to the UAV and / or the ground control terminal includes: The intermediate results are denoised using a mathematical filtering algorithm to generate statistical reports or scheduling instructions. The statistical report or the scheduling instruction is taken as the final result, and the final result is broadcast to the UAV and / or the ground control terminal.

8. A privacy-preserving drone data sharing device, characterized in that, include: The data acquisition module is configured to collect flight data, environmental perception information and mission status data using the UAV, and to collect operation instructions, scheduling information and user permission data using the ground control terminal. The privacy data determination module is configured to determine the privacy data to be shared based on the flight data, the environmental awareness information, the mission status data, the operation instructions, the scheduling information, and the user permission data. The protected data generation module is configured to use privacy computing technology to protect the privacy data based on the data type and sensitivity level of the privacy data in order to generate protected data. The intermediate result determination module is configured to upload the protected data to the sharing platform through a secure channel, so that the sharing platform can perform collaborative calculation and analysis on the protected data without decrypting the protected data, and generate intermediate results in the corresponding transformation form; The feedback module is configured to perform corresponding inverse processing on the intermediate results and feed back the processed final results to the UAV and / or the ground control terminal.

9. A computer-readable storage medium storing a computer program, characterized in that, The computer program is used to execute a privacy-preserving drone data sharing method as described in any one of claims 1-7.

10. An electronic device, characterized in that, The electronic device includes: processor; Memory used to store the processor's executable instructions; The processor is configured to read the executable instructions from the memory and execute the instructions to implement the privacy-preserving drone data sharing method according to any one of claims 1-7.

Citation Information

Cited By

  • Homomorphic encryption cross-border compliance medical data sharing privacy protection system and method

    CN121644247A