Geofencing device with dynamic characteristics

By using geofencing equipment and authentication systems, the safety issues of unmanned aerial vehicles during flight have been resolved, enabling effective flight control and authentication, preventing unauthorized flights and hijacking, optimizing resource utilization, and improving operational safety.

CN115033028BActive Publication Date: 2026-02-27SZ DJI TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210722827.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2015-03-31
Publication Date
2026-02-27
Estimated Expiration
2035-03-31

AI Technical Summary

Technical Problem

Unmanned aerial vehicles (UAVs) pose safety risks during flight, such as unrestricted flight, unauthorized entry into sensitive areas, hijacking, misuse, waste of resources, and difficulty in operational supervision, and lack an effective flight safety guarantee mechanism.

Method used

A geofencing device is provided that collects data through input elements, determines flight control using a processor, and controls the flight of unmanned aerial vehicles (UAVs) through output elements. This enables a flight control and authentication system that ensures only authorized parties can operate the device, provides flight control information, monitors and allows for user manual control, prevents hijacking and abuse, and optimizes resource utilization.

Benefits of technology

It improves the flight safety of unmanned aerial vehicles, prevents unauthorized flights, monitors hijacking and abuse, optimizes resource use, provides effective flight control and authentication mechanisms, and ensures user authentication and equipment security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115033028B_ABST
    Figure CN115033028B_ABST
Patent Text Reader

Abstract

Systems and methods for unmanned aerial vehicle safety are provided. An authentication system can be used to confirm unmanned aerial vehicle and / or user identity and provide secure communication between a user and an unmanned aerial vehicle. The unmanned aerial vehicle can operate in accordance with a set of flight regulations. The set of flight regulations can be associated with a geofencing device in the vicinity of the unmanned aerial vehicle.
Need to check novelty before this filing date? Find Prior Art

Description

BACKGROUND

[0001] Unmanned vehicles, such as unmanned aerial vehicles (UAVs), have been developed for use in various fields, including consumer applications and industry applications. For example, unmanned aerial vehicles can be maneuvered for entertainment, photography / video, surveillance, delivery, or other applications.

[0002] Unmanned aerial vehicles expand aspects of personal life. However, as the use of unmanned aerial vehicles becomes more widespread, safety issues and challenges arise. For example, when the flight of unmanned aerial vehicles is not restricted, unmanned aerial vehicles can fly over areas where flight is prohibited or should be prohibited. This can occur intentionally or unintentionally. In some cases, a novice user can lose control of an unmanned aerial vehicle or be unfamiliar with aviation flight rules. There is also a risk of hijacking or hacking the control of an unmanned aerial vehicle. SUMMARY

[0003] The safety systems and methods described herein improve the safety of unmanned aerial vehicle (UAV) flight. Flight control and authentication systems and methods can be provided that can help track the use of unmanned aerial vehicles. The systems can uniquely identify the parties that are interacting (e.g., user, remote controller, unmanned aerial vehicle, geo-fencing device). In some cases, an authentication process can occur and only authorized parties can be allowed to operate the unmanned aerial vehicle. Flight regulations can be imposed on the operation of the unmanned aerial vehicle and can override user manual control. In some cases, a geo-fencing device can be used to provide information about the flight regulations or assist in the flight regulation process.

[0004] Aspects of the invention can include a geo-fencing device comprising: an input element configured to collect data that facilitates determining a set of flight regulations; one or more processors individually or collectively configured to: determine the set of flight regulations based on the data collected by the input element; and one or more output elements configured to output a signal that causes the unmanned aerial vehicle to fly in accordance with the set of flight regulations.

[0005] According to further aspects of the invention, a method of controlling the flight of an unmanned aerial vehicle (UAV) can be provided, the method comprising: collecting, using an input element of a geo-fencing device, data that facilitates determining a set of flight regulations; determining, by means of one or more processors, the set of flight regulations based on the data collected by the input element; and outputting, by means of one or more output elements of the geo-fencing device, a signal that causes the unmanned aerial vehicle to fly in accordance with the set of flight regulations.

[0006] It should be understood that different aspects of the invention can be understood individually, jointly, or in combination with each other. The various aspects of the invention described herein are applicable to any particular application set forth below or to any other type of movable object. Any description herein of aircraft, such as unmanned aerial vehicles, is applicable to and used for any movable object, such as any vehicle. Furthermore, the systems, devices, and methods disclosed herein in the context of aerial movement (e.g., flight) are also applicable to other types of movement, such as movement on land or water, underwater movement, or movement in space.

[0007] Other objects and features of the invention will become apparent upon examination of the specification, claims, and drawings.

[0008] Incorporation

[0009] All publications, patents and patent applications mentioned in this specification are incorporated herein by reference as if specifically and individually indicated that each individual publication, patent or patent application is incorporated by reference. Attached Figure Description

[0010] The novel features of this invention are particularly embodied in the following claims. For a better understanding of the features and beneficial effects of this invention, reference can be made to the following specific embodiments and corresponding drawings:

[0011] Figure 1 An example of an interaction between one or more users and one or more unmanned aerial vehicles according to an embodiment of the present invention is shown.

[0012] Figure 2 An example of an authentication system according to an embodiment of the present invention is shown.

[0013] Figure 3 Examples of one or more factors that can participate in generating a set of flight control measures, according to embodiments of the present invention, are shown.

[0014] Figure 4 An example of a flight control unit according to an embodiment of the present invention is shown.

[0015] Figure 5 An additional example of a flight control unit according to an embodiment of the present invention is shown.

[0016] Figure 6 An example of a flight control unit that tracks the identifier of a chip on a flight control unit according to an embodiment of the present invention is shown.

[0017] Figure 7 The diagram illustrates a scenario including various types of flight control according to an embodiment of the present invention.

[0018] Figure 8 A process to consider whether to authorize a user to operate a UAV is shown, according to an embodiment of the application.

[0019] Figure 9 A process to determine whether to allow a user to operate a UAV is shown, according to an embodiment of the application.

[0020] Figure 10 A diagram showing a flight regulation level that can be affected by a degree of authentication is shown, according to an embodiment of the application.

[0021] Figure 11 An example of device information that can be stored in a memory is shown, according to an embodiment of the application.

[0022] Figure 12 A diagram showing a scenario where a hijacker attempts to take over control of a UAV is shown, according to an embodiment of the application.

[0023] Figure 13 An example of a UAV flight deviation is shown, according to an embodiment of the application.

[0024] Figure 14 An example of a monitoring system using one or more recorders is shown, according to an embodiment of the application.

[0025] Figure 15 A diagram showing two-way authentication between a UAV and an authentication center is shown, according to an embodiment of the application.

[0026] Figure 16 A process for sending a message with an encrypted signature is shown, according to an embodiment of the application.

[0027] Figure 17 Another process for verifying a message by decrypting a signature is shown, according to an embodiment of the application.

[0028] Figure 18 An example of a UAV and a geo-fencing device is shown, according to an embodiment of the application.

[0029] Figure 19 A side view of a geo-fencing device, a geo-fencing boundary, and a UAV is shown, according to an embodiment of the application.

[0030] Figure 20 A system in which a geo-fencing device directly transmits information to a UAV is shown, according to an embodiment of the application.

[0031] Figure 21 A system in which an air traffic control system can communicate with a geo-fencing device and / or a UAV is shown.

[0032] Figure 22 A system in which a UAV detects a geo-fencing device is shown, according to an embodiment of the application.

[0033] Figure 23 An example of the UAV system in which the UAV and the geo-fencing device do not need to communicate directly with each other is shown, according to an embodiment of the application.

[0034] Figure 24 An example of a geo-fencing device that can have multiple flight restricted zones is shown.

[0035] Figure 25 A process for generating a set of flight regulations is shown, according to an embodiment of the application.

[0036] Figure 26 A process for authenticating a geo-fencing device is shown, according to an embodiment of the application.

[0037] Figure 27 Another example of device information that can be stored in memory is shown, according to an embodiment of the application.

[0038] Figure 28 A geo-fencing device that can provide different sets of flight restrictions in different scenarios is shown, according to an embodiment of the application.

[0039] Figure 29 An example of a geo-fencing device that has multiple sets of flight regulations that can change over time is shown, according to an embodiment of the application.

[0040] Figure 30 A scenario in which a UAV can be provided in overlapping regions of multiple geo-fencing devices is shown, according to an embodiment of the application.

[0041] Figure 31 An example of different regulations for different geo-fencing devices is shown, according to an aspect of the application.

[0042] Figure 32 An example of a mobile geo-fencing device is shown, according to an embodiment of the application.

[0043] Figure 33 An example of mobile geo-fencing devices that are in proximity to each other is shown, according to an embodiment of the application.

[0044] Figure 34 Another example of a mobile geo-fencing device is shown, according to an embodiment of the application.

[0045] Figure 35 An example of a user interface showing information about one or more geo-fencing devices is shown, according to an embodiment of the application.

[0046] Figure 36 An unmanned aerial vehicle is illustrated in accordance with an embodiment of the application.

[0047] Figure 37 A movable object including a carrier and a payload is illustrated in accordance with an embodiment of the application.

[0048] Figure 38 A system for controlling a movable object is illustrated in accordance with an embodiment of the application.

[0049] Figure 39 Different types of communications between an unmanned aerial vehicle and geo-fencing devices are shown in accordance with an embodiment of the application.

[0050] Figure 40 An example of multiple geo-fencing devices each having a corresponding geo-fencing identifier is shown in accordance with an embodiment of the application.

[0051] Figure 41 An example of an unmanned aerial vehicle system in which an air-traffic control system interacts with multiple unmanned aerial vehicles and multiple geo-fencing devices is shown in accordance with an embodiment of the application.

[0052] Figure 42 An example of an environment with an unmanned aerial vehicle that can be traversing a flight path within the environment and one or more geo-fencing devices is shown.

[0053] Figure 43 An example of a device that can receive user input to control one or more geo-fencing devices is provided in accordance with an embodiment of the application.

[0054] Figure 44 A diagram of how a geo-fencing device can be used with a private residence to limit the use of unmanned aerial vehicles is provided in accordance with an embodiment of the application.

[0055] Figure 45 A diagram of how a geo-fencing device can be used to control an unmanned aerial vehicle is provided in accordance with an embodiment of the application. DETAILED DESCRIPTION

[0056] Unmanned vehicles, such as unmanned aerial vehicles (UAVs), can operate in accordance with safety systems for improving the safety of flight of unmanned vehicles. Any description herein of an unmanned aerial vehicle can apply to any type of unmanned vehicle (e.g., a sky-based vehicle, a land-based vehicle, a water-based vehicle, or a space-based vehicle). Flight control and authentication systems and methods that facilitate monitoring and control of the use of unmanned aerial vehicles can be provided. The systems can uniquely identify parties that are interacting (e.g., a user, a remote controller, an unmanned aerial vehicle, a geo-fencing device). In some cases, an authentication process can occur and only authorized parties can be allowed to operate the unmanned aerial vehicle. Flight regulations can be imposed on the operation of the unmanned aerial vehicle and can override manual control by a user. A geo-fencing device can be used to provide information about flight regulations or assist in the flight regulation process. The geo-fencing device can provide a physical reference for one or more geo-fence boundaries that can be associated with a corresponding set of flight regulations.

[0057] Flight safety challenges during the use of unmanned aerial vehicles can come in many different forms. For example, traditionally, the flight of unmanned aerial vehicles is not regulated (e.g., an unmanned aerial vehicle can fly over somewhere that it should be prohibited from flying over). For example, an unmanned aerial vehicle can fly un-authorized into a sensitive area (e.g., an airport, a military base). In addition, an unmanned aerial vehicle can fly un-authorized into the flight path of other aircraft. An unmanned aerial vehicle can fly un-authorized into a corporate property or a personal property, causing noise pollution, personal injury, and property damage. In some cases, an unmanned aerial vehicle can fly un-authorized into a public area and can cause personal injury and property damage. The systems and methods provided herein can provide a set of flight regulations that can impose necessary restrictions on an unmanned aerial vehicle, which can be geographically-based, time-based, and / or activity-based. An unmanned aerial vehicle can automatically comply with the flight regulations without the need for input from a user. In some cases, control of the unmanned aerial vehicle can be generated based on flight regulations that can override manual input from a user.

[0058] The flight of an unmanned aerial vehicle can be controlled by a user with the aid of one or more remote controllers. In some cases, there is a potential risk that the flight is hijacked. A hijacker can interfere with the instructions of an authorized user to the unmanned aerial vehicle. If the unmanned aerial vehicle receives and accepts a counterfeit instruction, it can perform an uncontrolled task and produce undesirable consequences. The systems and methods provided herein can identify when a hijacking occurs. When a hijacking occurs, the systems and methods can alert the user. The systems and methods can also cause the unmanned aerial vehicle to take action in response to the detected hijacking and can override the control of the hijacker.

[0059] An unmanned aerial vehicle can carry various sensors on board that can be used to obtain data. Hackers can attempt to steal the data obtained. For example, the data of the unmanned aerial vehicle can be intercepted, or the data transmitted to the ground over a remote wireless link can be listened to. The systems and methods provided herein can provide encryption and authentication so that only authorized users can receive the data.

[0060] In another example of unmanned aerial vehicle flight safety challenges, unmanned aerial vehicles can be misused. Traditionally, there is a lack of alerting measures, identifying measures, or measures to stop violations, particularly when an unmanned aerial vehicle operator intentionally misuses the unmanned aerial vehicle. For example, an unmanned aerial vehicle can be used for illegal advertising, unauthorized attacks, or invasion of privacy (e.g., unauthorized paparazzi). The systems and methods provided herein can monitor usage, which can help identify when misuse of an unmanned aerial vehicle occurs. The data can also be used for law enforcement to track down those involved in misuse or any related data. Systems and methods can also be provided that can alert users or other entities when misuse occurs and / or that can override any controls that support misuse.

[0061] When operating, unmanned aerial vehicles can transmit or receive data wirelessly. In some cases, unmanned aerial vehicles can misuse wireless resources and / or air resources, which can result in a waste of public resources. For example, an unmanned aerial vehicle can interfere with authorized communications, or steal bandwidth from other communications. The systems and methods provided herein can identify when such activities occur, and can provide warnings or prevent such interference from occurring.

[0062] In general, there are challenges in supervising the operation of unmanned aerial vehicles. As different types of unmanned aerial vehicles become more common in different types of uses, there is traditionally a lack of authorization systems for unmanned aerial vehicle flights. It is difficult to distinguish between abnormal flights and normal flights; detect small unmanned aerial vehicles; visually detect unmanned aerial vehicles flying at night; track and punish anonymous flights, and / or bind the flight of an unmanned aerial vehicle to its user or owner in an unforgeable manner. The systems and methods described herein can perform one or more of these goals. Identification data can be collected and one or more identifiers can be authenticated. While it can be traditionally difficult to provide security controls due to a lack of one or more of the following: a secure channel between a controller and the owner or user of the unmanned aerial vehicle, a direct alert or warning mechanism, a legal mechanism for the controller to take control, a mechanism for the unmanned aerial vehicle to distinguish between a controller and a hijacker, and measures to force stop a violation of the unmanned aerial vehicle, the systems and methods provided herein can provide one or more of these functions.

[0063] Similarly, there is a need for an evaluation or rating mechanism for the performance, capabilities, and permissions of unmanned aircraft. There is also a need for an evaluation or check mechanism for the operating skills and record of the user of the unmanned aircraft. The systems and methods provided herein can advantageously provide this type of evaluation. Optionally, flight regulations can be generated and implemented based on the evaluation.

[0064] As previously mentioned, conventional unmanned aircraft systems do not have a safeguard mechanism regarding the flight safety of the unmanned aircraft. For example, there is a lack of a warning mechanism for flight safety; a lack of an information sharing mechanism for the flight environment; or an emergency rescue mechanism. The described flight safety systems and methods can perform one or more of the above functions.

[0065] System Overview

[0066] Figure 1 An example of interaction between one or more users 110a, 110b, 110c and one or more unmanned aircraft 120a, 120b, 120c is shown. A user can interact with an unmanned aircraft by means of a remote controller 115a, 115b, 115c. An authentication system can include a memory storage 130 that can store information about the user, the remote controller, and / or the unmanned aircraft.

[0067] A user 110a, 110b, 110c can be an individual associated with an unmanned aircraft. The user can be a handler of the unmanned aircraft. The user can be an individual authorized to operate the unmanned aircraft. The user can provide input to control the unmanned aircraft. The user can provide input to control the unmanned aircraft with a remote controller 115a, 115b, 115c. The user can provide user input to control the flight of the unmanned aircraft, the operation of a payload of the unmanned aircraft, the status of the payload relative to the unmanned aircraft, the operation of one or more sensors of the unmanned aircraft, the operation of the communication of the unmanned aircraft, or other functions of the unmanned aircraft. The user can receive data from the unmanned aircraft. Data obtained using one or more sensors of the unmanned aircraft can be provided to the user, optionally via the remote controller. The user can be an owner of the unmanned aircraft. The user can be a registered owner of the unmanned aircraft. The user can be registered as authorized to operate the unmanned aircraft. The user can be a human handler. The user can be an adult or a child. The user can or can not have line of sight with the unmanned aircraft when operating the unmanned aircraft. The user can communicate directly with the unmanned aircraft using a remote controller. Alternatively, the user can communicate indirectly with the unmanned aircraft over a network (optionally using a remote controller).

[0068] A user can have a user identifier (e.g., user ID 1, user ID 2, user ID 3,...) that identifies the user. The user identifier can be unique to the user. Other users can have different identifiers than the user. The user identifier can uniquely distinguish and / or differentiate the user from other individuals. Each user can be assigned only a single user identifier. Alternatively, a user can be able to register multiple user identifiers. In some cases, a single user identifier can be assigned to only a single user. Alternatively, a single user identifier can be shared by multiple users. In a preferred implementation, a one-to-one correspondence can be provided between a user and a corresponding user identifier.

[0069] Optionally, a user can be authenticated as an authorized user of a user identifier. An authentication process can include verification of the user's identity. Examples of authentication processes are described in greater detail elsewhere herein.

[0070] The unmanned aerial vehicles 120a, 120b, 120c can be operable when powered on. The unmanned aerial vehicles can be in a flight state or can be in a landed state. The unmanned aerial vehicles can use one or more sensors (optionally, the payload can be a sensor) to collect data. The unmanned aerial vehicles can operate in response to control from a user (e.g., manually through a remote controller), autonomously (e.g., without user input), or semi-autonomously (e.g., can include some user input but can also include aspects that are not dependent on user input). The unmanned aerial vehicles can be capable of responding to commands from the remote controllers 115a, 115b, 115c. The remote controllers can not be connected to the unmanned aerial vehicles, the remote controllers can wirelessly communicate with the unmanned aerial vehicles from a distance. The remote controllers can accept and / or detect user input. The unmanned aerial vehicles can be capable of following a set of preprogrammed instructions. In some cases, the unmanned aerial vehicles can operate semi-autonomously by responding to one or more commands from a remote controller, while otherwise operating autonomously. For example, one or more commands from a remote controller can initiate a series of autonomous or semi-autonomous actions by the unmanned aerial vehicle according to one or more parameters. The unmanned aerial vehicles can switch between manual operation, autonomous operation, and / or semi-autonomous operation. In some cases, the activities of the unmanned aerial vehicles can be governed by one or more sets of flight regulations.

[0071] The UAV can have one or more sensors. The UAV can include one or more vision sensors, such as image sensors. For example, the image sensor can be a monocular camera, a stereo vision camera, a radar, a sonar, or an infrared camera. The UAV can also include other sensors that can be used to determine the location of the UAV, such as a global positioning system (GPS) sensor, inertial sensors (e.g., accelerometers, gyroscopes, magnetometers) that can be used as part of or separate from an inertial measurement unit (IMU), lidar, ultrasonic sensors, acoustic sensors, WiFi sensors. Various examples of sensors can include, but are not limited to, a position sensor (e.g., a global positioning system (GPS) sensor, a mobile device transmitter that supports position triangulation), a vision sensor (e.g., an imaging device capable of detecting visible, infrared, or ultraviolet light, such as a camera), a distance or range sensor (e.g., an ultrasonic sensor, a lidar, a Time-Of-Flight camera, or a depth camera), an inertial sensor (e.g., an accelerometer, a gyroscope, an inertial measurement unit (IMU)), an altitude sensor, an attitude sensor (e.g., a compass), a pressure sensor (e.g., a barometer), an audio sensor (e.g., a microphone), or a field sensor (e.g., a magnetometer, an electromagnetic sensor). Any suitable number and combination of sensors can be used, such as one, two, three, four, five, or more sensors.

[0072] Optionally, data can be received from different types of sensors (e.g., two, three, four, five, or more types). Different types of sensors can measure different types of signals or information (e.g., position, orientation, velocity, acceleration, distance, pressure, etc.) and / or utilize different types of measurement techniques to acquire data. For example, sensors can include any suitable combination of active sensors (e.g., sensors that generate and measure energy from their respective energy sources) and passive sensors (e.g., sensors that detect available energy). As another example, some sensors can generate absolute measurement data based on a global coordinate system (e.g., position data from a GPS sensor, attitude data from a compass or magnetometer), while other sensors can generate relative measurement data based on a local coordinate system (e.g., relative angular velocity from a gyroscope; relative translational acceleration from an accelerometer; relative attitude information from a visual sensor; relative distance information from an ultrasonic sensor, lidar, or time-of-flight camera). Onboard or external sensors of the UAV can collect information such as the UAV's position, the position of other objects, the UAV's orientation, or environmental information. A single sensor can collect a complete set of information about an environment, or a group of sensors can operate together to collect a complete set of information about the environment. Sensors can be used for location mapping, navigation between locations, obstacle detection, or target detection. Sensors can be used for monitoring the environment or a subject of interest. Sensors can be used to identify target objects. Target objects can be distinguished from other objects in the environment.

[0073] The unmanned aerial vehicle (UAV) can be an aircraft. The UAV may have one or more power units that allow it to move freely in the air. The one or more power units enable the UAV to move about one or more, two or more, three or more, four or more, five or more, six or more degrees of freedom. In some cases, the UAV may be able to rotate about one, two, three or more axes of rotation. These axes of rotation may be orthogonal to each other. The axes of rotation may remain orthogonal to each other throughout the flight of the UAV. The axes of rotation may include a pitch axis, a roll axis, and / or a yaw axis. The UAV may be able to move along one or more dimensions. For example, the UAV may be able to move upwards due to lift generated by one or more rotors. In some cases, the UAV may be able to move along the Z-axis (which may be upwards relative to the UAV's orientation), the X-axis, and / or the Y-axis (which may be lateral). The UAV may be able to move along one, two, or three axes that may be orthogonal to each other.

[0074] The unmanned aerial vehicle can be a multicopter. In some instances, the unmanned aerial vehicle can be a multicopter that can include a plurality of rotors. The plurality of rotors can be capable of rotating to generate lift for the unmanned aerial vehicle. The rotors can be power units that can enable the unmanned aerial vehicle to move freely in the air. The rotors can rotate at the same rate and / or can generate equal amounts of lift or thrust. The rotors can optionally rotate at varying rates, which can generate unequal amounts of lift or thrust and / or allow the unmanned aerial vehicle to rotate. In some instances, one, two, three, four, five, six, seven, eight, nine, ten, or more rotors can be provided on the unmanned aerial vehicle. The rotors can be arranged such that their axes of rotation are parallel to one another. In some instances, the rotors can have axes of rotation that are at any angle with respect to one another, which can affect the motion of the unmanned aerial vehicle.

[0075] The illustrated unmanned aerial vehicle can have a plurality of rotors. The rotors can be connected to a body of the unmanned aerial vehicle, which can include a control unit, one or more sensors, a processor, and a power source. The sensors can include vision sensors and / or other sensors that can collect information about the environment of the unmanned aerial vehicle. Information from the sensors can be used to determine the location of the unmanned aerial vehicle. The rotors can be connected to the body via one or more arms or extensions that can branch off from a central portion of the body. For example, one or more arms can extend radially from a central body of the unmanned aerial vehicle, and at the end of the arms or near the end of the arms can have rotors. In another example, the unmanned aerial vehicle can include one or more arms that include one or more additional support members that can have one, two, three, or more rotors attached to them. For example, a T-bar configuration can be used to support the rotors.

[0076] By maintaining and / or adjusting the output to one or more power units of the unmanned aerial vehicle, the vertical position and / or velocity of the unmanned aerial vehicle can be controlled. For example, increasing the rotational speed of one or more rotors of the unmanned aerial vehicle can facilitate the unmanned aerial vehicle increasing in altitude or increasing in altitude at a faster rate. Increasing the rotational speed of the one or more rotors can increase the thrust of the rotors. Decreasing the rotational speed of one or more rotors of the unmanned aerial vehicle can facilitate the unmanned aerial vehicle decreasing in altitude or decreasing in altitude at a faster rate. Decreasing the rotational speed of the one or more rotors can decrease the thrust of the one or more rotors. When the unmanned aerial vehicle is taking off, the output that can be provided to the power units can be increased from its previous landed state. When the unmanned aerial vehicle is landing, the output provided to the power units can be decreased from its previous flying state. The unmanned aerial vehicle can be configured to take off and / or land in a substantially vertical manner.

[0077] By maintaining and / or adjusting the output to one or more power units of the UAV, the lateral position and / or velocity of the UAV can be controlled. The altitude of the UAV and the rotational speed of one or more rotors of the UAV can affect the lateral movement of the UAV. For example, the UAV can tilt in a particular direction to move in that direction, and the speed of the rotors of the UAV can affect the speed and / or trajectory of the lateral movement. The lateral position and / or velocity of the UAV can be controlled by changing or maintaining the rotational speed of one or more rotors of the UAV.

[0078] The UAV can have a small size. The UAV can be capable of being carried and / or transported by a human. The UAV can be capable of being carried by a human in a single hand.

[0079] The UAV can have a maximum dimension (e.g., length, width, height, diagonal, diameter) of no more than 100 cm. In some instances, the maximum dimension can be less than or equal to 1 mm, 5 mm, 1 cm, 3 cm, 5 cm, 10 cm, 12 cm, 15 cm, 20 cm, 25 cm, 30 cm, 35 cm, 40 cm, 45 cm, 50 cm, 55 cm, 60 cm, 65 cm, 70 cm, 75 cm, 80 cm, 85 cm, 90 cm, 95 cm, 100 cm, 110 cm, 120 cm, 130 cm, 140 cm, 150 cm, 160 cm, 170 cm, 180 cm, 190 cm, 200 cm, 220 cm, 250 cm, or 300 cm. Alternatively, the maximum dimension of the UAV can be greater than or equal to any of the values described herein. The UAV can have a maximum dimension falling within a range between any two of the values described herein.

[0080] The UAV can be lightweight. For example, the UAV can weigh less than or equal to 1 mg, 5 mg, 10 mg, 50 mg, 100 mg, 500 mg, 1 g, 2 g, 3 g, 5 g, 7 g, 10 g, 12 g, 15 g, 20 g, 25 g, 30 g, 35 g, 40 g, 45 g, 50 g, 60 g, 70 g, 80 g, 90 g, 100 g, 120 g, 150 g, 200 g, 250 g, 300 g, 350 g, 400 g, 450 g, 500 g, 600 g, 700 g, 800 g, 900 g, 1 kg, 1.1 kg, 1.2 kg, 1.3 kg, 1.4 kg, 1.5 kg, 1.7 kg, 2 kg, 2.2 kg, 2.5 kg, 3 kg, 3.5 kg, 4 kg, 4.5 kg, 5 kg, 5.5 kg, 6 kg, 6.5 kg, 7 kg, 7.5 kg, 8 kg, 8.5 kg, 9 kg, 9.5 kg, 10 kg, 11 kg, 12 kg, 13 kg, 14 kg, 15 kg, 17 kg, or 20 kg. The UAV can have a weight that is greater than or equal to any of the values described herein. The UAV can have a weight that falls within a range between any of the two values described herein.

[0081] The UAV can have a UAV identifier (e.g., UAV ID 1, UAV ID 2, UAV ID 3,...) that identifies the UAV. The UAV identifier can be unique to the UAV. Other UAVs can have different identifiers than the UAV. The UAV identifier can uniquely distinguish and / or differentiate the UAV from other UAVs. Each UAV can be assigned only a single UAV identifier. Alternatively, multiple UAV identifiers can be registered for a single UAV. In some instances, a single UAV identifier can be assigned to only a single UAV. Alternatively, a single UAV identifier can be shared by multiple UAVs. In preferred embodiments, a one-to-one correspondence can be provided between a UAV and a corresponding UAV identifier.

[0082] Optionally, the UAV can be authenticated as an authorized UAV for the UAV identifier. The authentication process can include verification of the UAV identity. Examples of authentication processes are described in greater detail elsewhere herein.

[0083] In some embodiments, the remote controller can have a remote controller identifier that identifies the remote controller. The remote controller identifier can be unique to the remote controller. Other remote controllers can have different identifiers than the remote controller. The remote controller identifier can uniquely distinguish and / or differentiate the remote controller from other remote controllers. Each remote controller can be assigned only a single remote controller identifier. Alternatively, multiple remote controller identifiers can be assigned to a single remote controller. In some cases, a single remote controller identifier can be assigned to only a single remote controller. Alternatively, a single remote controller identifier can be shared by multiple remote controllers. In preferred embodiments, a one-to-one correspondence can be provided between remote controllers and corresponding remote controller identifiers. The remote controller identifier can or can not be associated with a corresponding user identifier.

[0084] Optionally, the remote controller can be authenticated as an authorized remote controller for the remote controller identifier. The authentication process can include verification of the remote controller identity. Examples of authentication processes are described in greater detail elsewhere herein.

[0085] The remote controller can be any type of device. The device can be a computer (e.g., a personal computer, a laptop computer, a server), a mobile device (e.g., a smartphone, a cellular phone, a tablet computer, a personal digital assistant), or any other type of device. The device can be a network device capable of communicating over a network. The device can include one or more memory storage units that can include non-transitory computer-readable media that can store code, logic or instructions for performing one or more steps described elsewhere herein. The device can include one or more processors that can individually or collectively execute the one or more steps in accordance with the code, logic or instructions of the non-transitory computer-readable media as described herein. The remote controller can be handheld. The remote controller can accept input from a user via any user interaction mechanism. In one example, the device can have a touchscreen that can record user input when the user touches or swipes the screen. The device can have any other type of user interaction component, such as a button, a mouse, a joystick, a trackball, a touchpad, a stylus, an inertial sensor, an image capture device, a motion capture device, or a microphone. The device can sense when the device is tilted, which can affect operation of the unmanned aerial vehicle. The remote controller can be a single piece configured to perform the various functions of the remote controller described elsewhere herein. Alternatively, the remote controller can be provided as multiple pieces or components that can individually or collectively perform the various functions of the remote controller as provided elsewhere herein.

[0086] The authentication system can include a memory storage 130 that can store information about users, remote controllers, and / or unmanned aerial vehicles. The memory storage can include one or more memory storage units. The one or more memory storage units can collectively provide or can be distributed over a network and / or distributed at different locations. In some cases, the memory storage can be a cloud storage system. The memory storage can include one or more databases that store information.

[0087] The information can include identification information about users, remote controllers, and / or unmanned aerial vehicles. For example, the identification can include user identifiers (e.g., user ID 1, user ID 2, user ID 3,...) and / or unmanned aerial vehicle identifiers (e.g., unmanned aerial vehicle ID 1, unmanned aerial vehicle ID 2, unmanned aerial vehicle ID 3,...). Remote controller identifiers can also optionally be stored. The information can be stored in long-term memory storage or can only be stored for a short period of time. The information can be received and buffered.

[0088] Figure 1 Scenarios are shown in which various users 110a, 110b, 110c can control corresponding unmanned aerial vehicles 120a, 120b, 120c. For example, a first user 110a can control a first unmanned aerial vehicle 120a by means of a remote controller. A second user 110b can control a second unmanned aerial vehicle 120b by means of a remote controller. A third user 110c can control a third unmanned aerial vehicle 120c by means of a remote controller. The users can be far apart from each other. Alternatively, the users can operate the unmanned aerial vehicles in the same area. The users can operate their corresponding unmanned aerial vehicles at the same time or can operate them at different times. The times of use can overlap. The users and unmanned aerial vehicles can be individually identifiable so that instructions from each user can only be accepted by the corresponding unmanned aerial vehicle and not by other unmanned aerial vehicles. This can reduce the likelihood of interfering signals when multiple unmanned aerial vehicles are operating at the same time.

[0089] Each user can control a corresponding user's unmanned aerial vehicle. The users can be pre-registered with the unmanned aerial vehicles so that only authorized users can control the corresponding unmanned aerial vehicles. The unmanned aerial vehicles can be pre-registered so that the users can only control the authorized unmanned aerial vehicles. The relationship and / or association between the users and the unmanned aerial vehicles can be known. Optionally, the relationship and / or association between the users and the unmanned aerial vehicles can be stored in the memory storage 130. User identifiers can be associated with unmanned aerial vehicle identifiers of corresponding unmanned aerial vehicles.

[0090] The memory storage unit can track commands of the user to the UAV. The stored commands can be associated with a corresponding user identifier of the user and / or a corresponding UAV identifier of the UAV. Optionally, an identifier of the corresponding remote controller can also be stored.

[0091] The identity of the devices or parties involved in the operation of the UAV can be authenticated. For example, the identity of the user can be authenticated. The user can be verified as the user associated with the user identifier. The identity of the UAV can be authenticated. The UAV can be verified as the UAV associated with the UAV identifier. The identity of the remote controller can optionally be authenticated. The remote controller can be verified as the remote controller associated with the remote controller identifier.

[0092] Figure 2 An example of an authentication system according to an embodiment of the application is shown. The authentication system can be or can operate as part of a UAV safety system. The authentication system can provide improved UAV safety. The authentication system can authenticate users, UAVs, remote controllers, and / or geo-fencing devices.

[0093] The authentication system can include an identity (ID) registry database 210. The ID registry database can be in communication with an authentication center 220. The authentication system can be in communication with an air traffic control system 230, which can include a flight monitoring module 240, a flight regulation module 242, a flight rights management module 244, a user access control module 246, and a UAV access control module 248.

[0094] The ID registry database 210 can maintain identity information for users 250a, 250b, 250c and UAVs 260a, 260b, 260c. The ID registry database can assign a unique identifier to each user and each UAV (connection 1). The unique identifier can optionally be a randomly generated alphanumeric string or any other type of identifier that uniquely identifies the user from other users or the UAV from other UAVs. The unique identifier can be generated by the ID registry database or can be selected from a list of possible identifiers that are maintained unassigned. The ID registry database can optionally assign unique identifiers to geo-fencing devices and / or remote controllers or any other devices that can be involved in the UAV safety system. The identifiers can be used to authenticate users, UAVs, and / or other devices. The ID registry database can or can not interact with one or more users or one or more UAVs.

[0095] The authentication center 220 can provide authentication of the identity of a user 250a, 250b, 250c or a UAV 260a, 260b, 260c. The authentication center can optionally provide authentication of the identity of geo-fencing devices and / or remote controllers or any other devices that can be involved in a UAV safety system. The authentication center can obtain information about users and UAVs (and / or any other devices involved in a UAV safety system) from the ID registry database 210 (connection 2). Further details about the authentication process are provided elsewhere herein.

[0096] The air control system 230 can interact with the authentication center 220. The air control system can obtain information about users and UAVs (and / or any other devices involved in a UAV safety system) from the authentication center (connection 4). The information can include user identifiers and UAV identifiers. The information can relate to confirmation or identification of user identity and / or UAV identity. The air control system can be a management cluster that can include one or more subsystems, such as a flight monitoring module 240, a flight regulation module 242, a flight rights management module 244, a user access control module 246, and a UAV access control module 248. The one or more subsystems can be used for flight control, air flight rights control, related authorization, user and UAV access management, and other functions.

[0097] In one example, the flight monitoring module / subsystem 240 can be used to monitor the flight of UAVs within an assigned airspace. The flight monitoring module can be configured to detect when one or more UAVs deviate from a predetermined flight path. The flight monitoring module can detect when one or more UAVs perform an unauthorized action or an action that was not input by a user. The flight monitoring module can also detect when one or more unauthorized UAVs enter an assigned airspace. The flight monitoring module can issue a warning or alert to an unauthorized UAV. The alert can be provided to a remote controller operated by a user operating the unauthorized UAV. The alert can be issued visually, audibly, or tactilely.

[0098] The flight monitoring module can utilize data collected by one or more sensors on board the unmanned aerial vehicle. The flight monitoring module can utilize data collected by one or more sensors off board the unmanned aerial vehicle. Data can be collected by a radar, an electro-optical sensor, or an acoustic sensor that can monitor the unmanned aerial vehicle or other activity within the assigned airspace. Data can be collected by one or more base stations, landing pads, battery stations, geo-fencing devices, or networks. Data can be collected by stationary devices. The stationary devices can or can not be configured for physical interaction with the unmanned aerial vehicle (e.g., to recharge the unmanned aerial vehicle, to accept a delivery from the unmanned aerial vehicle, or to provide repair to the unmanned aerial vehicle). Data can be provided from wired or wireless communication.

[0099] The air traffic control system can also include a flight regulation module / subsystem 242. The flight regulation module can be configured to generate and store one or more sets of flight regulations. Airspace management can be regulated based on a set of flight regulations. Generation of flight regulations can include creating flight regulations from scratch, or can include selecting one or more sets of flight regulations from a plurality of sets of flight regulations. Generation of flight regulations can include combining selected sets of flight regulations.

[0100] The unmanned aerial vehicle can operate in accordance with one or more sets of imposed flight regulations. Flight regulations can regulate any aspect of the operation of the unmanned aerial vehicle (e.g., flight, sensors, communications, payload, navigation, power usage, carried items). For example, flight regulations can dictate where the unmanned aerial vehicle can or can not fly. Flight regulations can dictate when the unmanned aerial vehicle can or can not fly in a particular region. Flight regulations can dictate when data can be collected, transmitted, and / or recorded by one or more sensors on board the unmanned aerial vehicle. Flight regulations can dictate when a payload can be operable. For example, a payload can be an image capture device, and flight regulations can dictate when and where the image capture device can capture, transmit, and / or store images. Flight regulations can dictate how communications can occur (e.g., channels or methods that can be used) or what types of communications can occur.

[0101] The flight regulation module can include one or more databases that store information about flight regulations. For example, the one or more databases can store one or more locations where flight of the unmanned aerial vehicle is restricted. The flight regulation module can store a plurality of sets of flight regulations for a plurality of types of unmanned aerial vehicles, and the plurality of sets of flight regulations can be associated with a particular unmanned aerial vehicle. Access to a set of flight regulations associated with a particular type of unmanned aerial vehicle from among the plurality of types of unmanned aerial vehicles can be possible.

[0102] The flight regulation module can approve or reject one or more flight plans for a UAV. In some instances, a flight plan can be assigned that includes a suggested flight path for a UAV. The flight path can be provided with respect to the UAV and / or the environment. The flight path can be fully defined (all points along the path are defined), semi-defined (e.g., can include one or more waypoints, but the path to reach the waypoints can be variable), or not very defined (e.g., can include a final destination or other parameters, but the path to reach the final destination can be undefined). The flight regulation module can receive a flight plan and can approve or reject the flight plan. The flight regulation module can reject a flight plan if the flight plan contradicts a set of flight regulations for the UAV. The flight regulation module can suggest modifications to the flight plan that can cause the flight plan to comply with the set of flight regulations. The flight regulation module can generate or suggest a set of flight plans for a UAV that can comply with the set of flight regulations. A user can input one or more parameters or objectives for a UAV mission, and the flight regulation module can generate or suggest a set of flight plans that can satisfy the one or more parameters while complying with the set of flight regulations. Examples of parameters or objectives for a UAV mission can include a destination, one or more waypoints, timing requirements (e.g., overall time limit, time to be at certain locations), maximum speed, maximum acceleration, type of data to be collected, type of images to be captured, any other parameter or objective.

[0103] An air traffic control system can be provided with an air traffic management module / subsystem 244. The air traffic management module can be configured to receive requests for resources from users. Examples of resources can include, but are not limited to, wireless resources (e.g., bandwidth, access to a communication device), locations or spaces (e.g., locations or spaces for a flight plan), times (e.g., times for a flight plan), access to a base station, access to a docking station, access to a battery station, access to a delivery or pickup point, or any other type of resource. The air traffic management module can be configured to plan a flight corridor for a UAV in response to the request. The flight corridor can utilize the assigned resources. The air traffic management module can be configured to plan a mission for a UAV, which can optionally include a flight corridor and operation of any sensors or other devices on the UAV. The mission can utilize any assigned resources.

[0104] The flight rights management module can be configured to adjust the mission based on a condition detected in the assigned airspace. For example, the flight rights management module can adjust a predetermined flight path based on a detected condition. Adjusting the flight path can include adjusting the entire predetermined flight path, adjusting a waypoint of a semi-defined flight path, or adjusting a destination of the flight path. The detected condition can include weather, a change in available airspace, an accident, establishment of a geo-fencing device, or a change in flight regulations. The flight rights management module can inform the user of the adjustment to the mission, such as the adjustment to the flight path.

[0105] The users 250a, 250b, 250c can be individuals associated with the UAVs 260a, 260b, 260c, such as the individuals operating the UAVs. Examples of users and UAVs are described elsewhere herein. A communication channel can be provided between the user and the corresponding UAV, which can be used to control operation of the UAV (connection 3). Controlling operation of the UAV can include controlling flight of the UAV or any other part of the UAV as described elsewhere herein.

[0106] A communication channel can be provided between the UAV and the air traffic control system (connection 5), as the air traffic control system can identify conditions, alert the user about the conditions, and / or take over the UAV to improve the conditions. The communication channel can also facilitate identity authentication when the user and / or the UAV undergoes an authentication process. Optionally, the communication channel can be established between the air traffic control system and the user's remote controller, and can provide some similar functions. In a system including geo-fencing devices, a communication channel can be provided between the geo-fencing devices for identification / authentication and / or condition identification, alerting, and / or taking over.

[0107] A communication channel can be provided between the user and the air traffic control system (connection 6), as the air traffic control system can identify conditions, alert the user about the conditions, and / or take over the UAV to improve the conditions. The communication channel can also facilitate identity authentication when the user and / or the UAV undergoes an authentication process.

[0108] Optionally, connection 1 can be a logical channel. Connections 2 and 4 can be network connections. For example, connections 2 and 4 can be provided through a local area network (LAN), a wide area network (WAN) such as the Internet, a telecommunication network, a data network, a cellular network, or any other type of network. Connections 2 and 4 can be provided through indirect communication (e.g., indirect communication through a network). Alternatively, they can be provided through a direct communication channel. Connections 3, 5, and 6 can be network connections provided via a remote controller or a ground station, mobile access network connections, or any other type of connection. They can be provided via an indirect communication channel or a direct communication channel.

[0109] An authorized third party, such as an air control system, a geo-fencing system, etc., can identify a corresponding unmanned aircraft through an authentication center according to its unmanned aircraft identifier (ID) and obtain relevant information, such as the configuration of the unmanned aircraft, its capability level and safety level. The safety system can be able to handle different types of unmanned aircrafts. Different types of unmanned aircrafts can have different physical characteristics (e.g., model, shape, size, engine power, range, battery life, sensors, performance capabilities, payload, payload rating or capabilities) or can be used to perform different tasks (e.g., surveillance, video recording, communication, delivery). Different types of unmanned aircrafts can have different safety levels or priorities. For example, different types of unmanned aircrafts can be authorized to perform different activities. For example, an unmanned aircraft with a first authorization type can be authorized to enter an area that an unmanned aircraft with a second authorization type is not authorized to enter. Unmanned aircraft types can include different unmanned aircraft types created by the same manufacturer or designer or by different manufacturers or designers.

[0110] An authorized third party, such as an air control system, a geo-fencing system, etc., can identify a corresponding user by a user identifier (ID) through an authentication center and obtain relevant information. The security system can be able to handle different types of users. Different types of users can have different skill levels, amounts of experience, associations with different types of unmanned vehicles, levels of authorization, or different demographic information. For example, users with different skill levels can be considered different types of users. A user can go through a proof or test to verify the user's skill level. One or more other users can attest or verify the user's skill level. For example, a user's instructor can verify the user's skill level. A user can also self-identify the user's skill level. Users with different amounts of experience can be considered different types of users. For example, a user can have a determined number of hours of operating unmanned vehicles or a number of missions flown using unmanned vehicles logged or attested. Other users can verify or attest to the user's amount of experience. The user can self-identify the user's amount of experience. A user type can indicate a user's level of training. A user's skill level and / or experience can be general to unmanned vehicles. Alternatively, a user's skill level and / or experience can be specific to unmanned vehicle types. For example, a user can have a high skill level and a rich amount of experience with a first type of unmanned vehicle, but a low skill level and a less rich amount of experience with a second type of unmanned vehicle. Different types of different users can include users with different authorization types. Different authorization types can mean that a different set of flight regulations can be imposed on different users. In some cases, some users can have a higher security level than other users, which can mean that fewer flight regulations or restrictions can be imposed on the users. In some cases, regular users can be distinguished from administrative users, which can be able to take over control from regular users. Regular users can be distinguished from control entity users (e.g., members of a government agency, members of an emergency service, such as law enforcement). In some embodiments, administrative users can be control entity users or can be distinguished from control entity users. In another example, a parent can be able to take over flight control from the parent's child, or an instructor can be able to take over flight control from a student. A user type can indicate a category or kind of user that operates one or more types of unmanned vehicles. Other user type information can be based on user demographic information (e.g., address, age, etc.).

[0111] Similarly, any other device or party involved in the security system can have its own type. For example, a geo-fence identifier can indicate a geo-fence device type, or a remote controller identifier can indicate a remote controller type.

[0112] An unmanned aerial vehicle operating within a safety system can be assigned an unmanned aerial vehicle ID and key. The ID and key can be assigned from an ID registry database. The ID and key can be globally unique and optionally uncopyable. A user operating an unmanned aerial vehicle within a safety system can be assigned a user ID and key. The ID and key can be assigned from an ID registry database. The ID and key can be globally unique and optionally uncopyable.

[0113] The unmanned aerial vehicle and the air control system can have mutual authentication using the IDs and keys, allowing the unmanned aerial vehicle to be operated. In some cases, the authentication can include obtaining permission to fly in a restricted area. The user and the air control system can have mutual authentication using the IDs and keys, allowing the user to operate the unmanned aerial vehicle.

[0114] The keys can be provided in various forms. In some embodiments, the key of an unmanned aerial vehicle can be inseparable from the unmanned aerial vehicle. The key can be designed to prevent the key from being stolen. The key can be implemented by a one-time writable and externally unreadable memory (e.g., a cryptographic chip) or by a solidified universal subscriber identity module (USIM). In some cases, the user key or remote controller key can be inseparable from the user's remote controller. The key can be used by an authentication center to authenticate the unmanned aerial vehicle, the user, and / or any other device.

[0115] An authentication system as provided herein can include an identification registry database configured to store one or more unmanned aerial vehicle identifiers that uniquely identify unmanned aerial vehicles with respect to each other and one or more user identifiers that uniquely identify users with respect to each other, an authentication center configured to authenticate the identity of the unmanned aerial vehicle and the identity of the user, and an air control system configured to receive the unmanned aerial vehicle identifier of the authenticated unmanned aerial vehicle and the user identifier of the authenticated user and provide a set of flight regulations based on at least one of the authenticated unmanned aerial vehicle identifier and the authenticated user identifier.

[0116] The authentication system can be implemented using any hardware configuration or arrangement known in the art or later developed. For example, one or more servers can be used to operate the ID registry database, the authentication center, and / or the air control system, either separately or collectively. One or more servers can be used to implement one or more subsystems of the air control system, such as a flight monitoring module, a flight regulation module, a flight authorization management module, a user access control module, a UAV access control module, or any other module, either separately or collectively. Any description of a server can apply to any other type of device. The device can be a computer (e.g., a personal computer, a laptop computer, a server), a mobile device (e.g., a smartphone, a cellular phone, a tablet computer, a personal digital assistant), or any other type of device. The device can be a network device capable of communicating over a network. The device includes one or more memory storage units, which can include non-transitory computer-readable media, which can store code, logic or instructions for performing one or more steps described elsewhere herein. The device can include one or more processors, which can perform one or more steps, either separately or collectively, in accordance with the code, logic or instructions of the non-transitory computer-readable media, as described herein.

[0117] The various components, such as the ID registry database, the authentication center, and / or the air control system, can be implemented at the same location on hardware or can be implemented at different locations. The authentication system components can be implemented using the same device or multiple devices. In some cases, a cloud computing infrastructure can be implemented to provide the authentication system. Alternatively, the authentication system can utilize a peer-to-peer (P2P) relationship.

[0118] The components can be provided off-board the UAV, on-board the UAV, or some combination thereof. The components can be provided off-board the remote controller, on-board the remote controller, or some combination thereof. In some preferred embodiments, the components can be provided off-board the UAV or off-board the remote controller, and can communicate with the UAV (and / or other UAVs) and the remote controller (and / or other remote controllers). The components can communicate directly with the UAV or indirectly. In some cases, the communication can be relayed via another device. The other device can be a remote controller or another UAV.

[0119] Flight Regulations

[0120] The activities of the UAV can be governed in accordance with a set of flight regulations. A set of flight regulations can include one or more flight regulations. Various types and examples of flight regulations are described herein.

[0121] Flight regulations can govern the physical arrangement of the UAV. For example, flight regulations can govern flight of the UAV, takeoff of the UAV, and / or landing of the UAV. Flight regulations can indicate a surface area over which the UAV can or can not fly, or a volume of space in which the UAV can or can not fly. Flight regulations can relate to the location of the UAV (e.g., where the UAV is in space or above a surface) and / or the orientation of the UAV. In some examples, flight regulations can prevent the UAV from flying within an assigned volume (e.g., airspace) and / or over an assigned area (e.g., ground or water surface below). Flight regulations can include one or more boundaries within which the UAV is not allowed to fly. In other examples, flight regulations can only allow the UAV to fly within an assigned volume and / or over an assigned area. Flight regulations can include one or more boundaries within which the UAV is allowed to fly. Optionally, flight regulations can prevent the UAV from flying above an upper altitude limit, which can be fixed or variable. In another case, flight regulations can prevent the UAV from flying below a lower altitude limit, which can be fixed or variable. The UAV can be required to fly at an altitude between a lower altitude limit and an upper altitude limit. In another example, the UAV can not be able to fly within one or more altitude ranges. For example, flight regulations can only allow a range of UAV orientations, or can not allow a range of UAV orientations. The range of UAV orientations can be with respect to one, two, or three axes. The axes can be orthogonal axes, such as a heading axis, a pitch axis, or a roll axis.

[0122] Flight regulations can govern movement of the UAV. For example, flight regulations can govern translational velocity of the UAV, translational acceleration of the UAV, angular velocity of the UAV (e.g., angular velocity about one, two, or three axes), or angular acceleration of the UAV (e.g., angular acceleration about one, two, or three axes). Flight regulations can set a maximum limit for UAV translational velocity, UAV translational acceleration, UAV angular velocity, or UAV angular acceleration. Thus, the set of flight regulations can include limiting flight velocity and / or flight acceleration of the UAV. Flight regulations can set a minimum threshold for UAV translational velocity, UAV translational acceleration, UAV angular velocity, or UAV angular acceleration. Flight regulations can require the UAV to move between the minimum threshold and the maximum limit. Alternatively, flight regulations can prevent the UAV from moving within one or more translational velocity ranges, translational acceleration ranges, angular velocity ranges, or angular acceleration ranges. In one example, the UAV can not be allowed to hover within the assigned airspace. The UAV can be required to fly above a minimum translational velocity of 0 mph. In another example, the UAV can not be allowed to fly too fast (e.g., fly below a maximum velocity limit of 40 mph). Movement of the UAV can be governed with respect to the assigned volume and / or above the assigned region.

[0123] Flight regulations can govern takeoff and / or landing procedures of the UAV. For example, the UAV can be allowed to fly in the assigned region without landing in the region. In another example, the UAV can only be able to takeoff from the assigned region in a certain manner or at a certain velocity. In another example, manual takeoff or landing can not be allowed within the assigned region, but must use an autonomous landing or takeoff procedure. Flight regulations can govern whether takeoff is allowed, whether landing is allowed, any rules that must be adhered to for takeoff or landing (e.g., velocity, acceleration, direction, orientation, flight mode). In some embodiments, only automated sequences for takeoff and / or landing are allowed, without allowing manual landing or takeoff, or vice versa. Takeoff and / or landing procedures of the UAV can be governed with respect to the assigned volume and / or above the assigned region.

[0124] In some cases, flight regulations can govern operation of a payload of a UAV. The payload of the UAV can be a sensor, an emitter, or any other object that can be carried by the UAV. The payload can be powered on or off. The payload can appear operable (e.g., powered on) or inoperable (e.g., powered off). The flight regulations can include conditions that do not allow the UAV to operate the payload. For example, in an assigned airspace, the flight regulations can require the payload to be powered off. The payload can emit a signal and the flight regulations can govern a nature of the signal, an amplitude of the signal, a range of the signal, a direction of the signal, or any mode of operation. For example, if the payload is a light source, the flight regulations can require that the light be no brighter than a threshold light intensity within the assigned airspace. In another example, if the payload is a speaker for emitting sound, the flight regulations can require that the speaker not transmit any noise outside of the assigned airspace. The payload can be a sensor that collects information, and the flight regulations can govern a mode of collecting information, a mode of how to pre-process or process the information, a resolution at which to collect the information, a frequency or sampling rate at which to collect the information, a range from which to collect the information, or a direction from which to collect the information. For example, the payload can be an image capture device. The image capture device can be capable of capturing still images (e.g., still pictures) or dynamic images (e.g., video). The flight regulations can govern a zoom of the image capture device, a resolution of an image captured by the image capture device, a sampling rate of the image capture device, a shutter speed of the image capture device, an aperture of the image capture device, whether to use a flash, a mode of the image capture device (e.g., illumination mode, color mode, still vs. video mode), or a focus of the image capture device. In one example, a camera can not be allowed to capture images over the assigned region. In another example, a camera can be allowed to capture images over the assigned region but not sound. In another example, a camera can be allowed to capture only high resolution photos over the assigned region and low resolution photos outside of the assigned region. In another example, the payload can be an audio capture device. The flight regulations can govern whether the audio capture device is allowed to be powered on, a sensitivity of the audio capture device, a range of decibels that the audio capture device can receive, a directionality of the audio capture device (e.g., directionality for a parabolic microphone), or any other quality of the audio capture device. In one example, an audio capture device can be allowed or can not be allowed to capture sound over the assigned region. In another example, an audio capture device can be allowed to capture only sound within a particular frequency range over the assigned region. Operation of the payload can be governed with respect to the assigned volume and / or over the assigned region.

[0125] Flight regulations can dictate whether a payload can transmit or store information. For example, if the payload is an image capture device, flight regulations can dictate whether images (still or moving) can be recorded. Flight regulations can dictate whether images can be recorded in the on-board memory of the image capture device or on the memory of the UAV. For example, an image capture device can be allowed to power on and show captured images on a local display, but can not be allowed to record any images. Flight regulations can dictate whether images can flow off the image capture device or off the UAV. For example, flight regulations can dictate that an image capture device on a UAV can be allowed to stream video down to a terminal off the UAV when the UAV is located within an assigned airspace, but can not be able to stream video off when the UAV is located outside of the assigned airspace. Similarly, if the payload is an audio capture device, flight regulations can dictate whether sound can be recorded in the on-board memory of the audio capture device or on the memory of the UAV. For example, an audio capture device can be allowed to power on and play back captured sound on a local speaker, but can not be allowed to record any sound. Flight regulations can dictate whether images can flow off the audio capture device or any other payload. Storage and / or transmission of collected data can be dictated with respect to the assigned volume and / or over the assigned region.

[0126] In some cases, a payload can be an item carried by the UAV, and flight regulations can dictate characteristics of the payload. Examples of payload characteristics can include a size of the payload (e.g., height, width, length, diameter, diagonal), a weight of the payload, a stability of the payload, a material of the payload, a fragility of the payload, or a type of the payload. For example, flight regulations can dictate that a UAV can carry no more than 3 lbs of a package while flying over an assigned region. In another example, flight regulations can allow a UAV to carry a package with a size greater than 1 foot only within an assigned volume. Another flight regulation can allow a UAV to fly within an assigned volume for 5 minutes while carrying a package of 1 lb or more, and can cause the UAV to automatically land if the UAV has not left the assigned volume within the 5 minutes. Restrictions on the type of payload itself can be provided. For example, unstable or potentially explosive payloads can not be carried by a UAV. Flight restrictions can prevent fragile objects from being carried by a UAV. Payload characteristics can be regulated with respect to the assigned volume and / or over the assigned region.

[0127] The flight regulations can also specify activities that can be performed with respect to an item carried by the unmanned aerial vehicle. For example, the flight regulations can specify whether an item can be dropped from the assigned volume and / or over the assigned area. Similarly, the flight regulations can specify whether an item can be picked up from the assigned volume and / or over the assigned area. The unmanned aerial vehicle can have a mechanical arm or other mechanical structure that can facilitate dropping or picking up an item. The unmanned aerial vehicle can have a payload compartment that can allow the unmanned aerial vehicle to carry an item. Activities involving the payload can be regulated with respect to the assigned volume and / or the assigned area.

[0128] The positioning of the payload relative to the unmanned aerial vehicle can be dictated by the flight regulations. The position of the payload relative to the unmanned aerial vehicle can be adjustable. The translational position of the payload relative to the unmanned aerial vehicle and / or the orientation of the payload relative to the unmanned aerial vehicle can be adjustable. The translational position can be adjustable with respect to one, two, or three orthogonal axes. The orientation of the payload can be adjustable with respect to one, two, or three orthogonal axes (e.g., a pitch axis, a yaw axis, or a roll axis). In some embodiments, the payload can be connected to the unmanned aerial vehicle with a carrier that can control the positioning of the payload relative to the unmanned aerial vehicle. The carrier can support the weight of the payload on the unmanned aerial vehicle. The carrier can optionally be a gimbal that can allow the payload to rotate relative to the unmanned aerial vehicle with respect to one, two, or three axes. One or more gantry assemblies and one or more actuators that can enable adjustment of the positioning of the payload can be provided. The flight regulations can control the carrier or any other mechanism that adjusts the position of the payload relative to the unmanned aerial vehicle. In one example, the flight regulations can not allow the payload to face downward in orientation when flying over the assigned area. For example, the area can have sensitive data that can not be desirable for the payload to capture. In another example, the flight regulations can move the payload to move downward in translation relative to the unmanned aerial vehicle when located within the assigned airspace, which can allow for a wider field of view, such as for panoramic image capture. The positioning of the payload can be dictated with respect to the assigned volume and / or over the assigned area.

[0129] The flight regulations can dictate the operation of one or more sensors of the unmanned aerial vehicle. For example, the flight regulations can dictate whether or which sensors to turn on or off, the mode of collecting information, the mode of how to pre-process or process information, the resolution at which to collect information, the frequency or sampling rate at which to collect information, the range from which to collect information, or the direction from which to collect information. The flight regulations can dictate whether a sensor can store or transmit information. In one example, a GPS sensor can be turned off while a vision sensor or an inertial sensor is turned on for navigation purposes when the unmanned aerial vehicle is located within the assigned volume. In another example, an audio sensor of the unmanned aerial vehicle can be turned off when flying over the assigned area. The operation of one or more sensors can be dictated with respect to the assigned volume and / or over the assigned area.

[0130] Communication of the UAV can be controlled according to one or more sets of flight regulations. For example, the UAV can be capable of remote communication with one or more remote devices. Examples of remote devices can include a remote controller that can control operation of the UAV, a payload, a carrier, a sensor, or any other component of the UAV, a display terminal that can show information received by the UAV, a database that can collect information from the UAV, or any other external device. Remote communication can be wireless communication. The communication can be direct communication between the UAV and the remote device. Examples of direct communication can include WiFi, WiMax, radio frequency, infrared, visual, or other types of direct communication. The communication can be indirect communication between the UAV and the remote device, which can include one or more intermediary devices or networks. Examples of indirect communication can include 3G, 4G, LTE, satellite, or other types of communication. Flight regulations can specify whether remote communication is turned on or off. Flight regulations can include conditions under which the UAV is not allowed to communicate under one or more wireless conditions. For example, communication can not be allowed when the UAV is within an assigned airspace volume. Flight regulations can specify communication modes that can or can not be allowed. For example, flight regulations can specify whether a direct communication mode is allowed, whether an indirect communication mode is allowed, or whether priority is established between a direct communication mode and an indirect communication mode. In one example, only direct communication is allowed within an assigned volume. In another example, over an assigned region, priority can be established for direct communication as long as direct communication is available, otherwise indirect communication can be used, and outside the assigned region, no communication is allowed. Flight regulations can specify characteristics of the communication, such as bandwidth used, frequency used, protocol used, encryption used, devices that can use auxiliary communication. For example, flight regulations can only allow communication with existing networks when the UAV is located within a predetermined volume. Flight regulations can govern communication of the UAV with respect to an assigned volume and / or over an assigned region.

[0131] Other functions of the UAV, such as navigation, power usage, and monitoring, can be governed according to flight regulations. Examples of power usage and monitoring can include an amount of remaining flight time based on battery and power usage information, a state of charge of the battery, or an estimated amount of remaining distance based on battery and power usage information. For example, flight regulations can require that a UAV operating within an assigned volume have at least 3 hours of remaining battery life. In another example, flight regulations can require that a UAV have at least a 50% state of charge when located outside an assigned region. Such additional functions can be governed by flight regulations with respect to an assigned volume and / or over an assigned region.

[0132] The assigned volume and / or the assigned region can be static for a set of flight regulations. For example, the boundaries for the assigned volume and / or the assigned region can remain the same for the set of flight regulations. Alternatively, the boundaries can change over time. For example, the assigned region can be a school, and the boundaries for the assigned region can include the school during school hours. After school, the boundaries can shrink or the assigned region can be removed. During the period after school, an assigned region can be created at a nearby park where children attend after-school activities. The rules for the assigned volume and / or the assigned region can remain the same for the set of flight regulations or can change over time. The changes can be dictated by a time of day, a day of the week, a week of the month, a month, a season, a year, or any other time-dependent factor. Information from a clock, which can provide a time of day, a date, or other time-dependent information, can be used to implement changes in boundaries or rules. A set of flight regulations can have dynamic components that are responsive to factors other than time. Examples of other factors can include weather, temperature, detected light levels, detected presence of individuals or machines, environmental complexity, physical traffic (e.g., land traffic, pedestrian traffic, aircraft traffic), wireless or network traffic, detected noise levels, detected movement, detected heat signatures, or any other factor.

[0133] The assigned volume and / or the assigned region can or can not be associated with a geofence device. The geofence device can be a reference point for the assigned volume and / or the assigned region. As described elsewhere herein, the location of the assigned volume and / or the assigned region can be provided based on the location of the geofence device. Alternatively, the assigned volume and / or region can be provided without the need for a geofence device to be present. For example, without the need for a geofence device to be at an airport, the known coordinates of the airport can be provided and used as a reference for the assigned volume and / or the assigned region. Any combination of assigned volumes and / or regions can be provided, some of which can rely on a geofence device and some of which can not rely on the device.

[0134] The flight regulations can cause any type of flight response measure by the UAV. For example, the UAV can change a flight path. The UAV can automatically enter an autonomous or semi-autonomous flight control mode from a manual mode, or can not respond to certain user inputs. The UAV can allow another user to take over control of the UAV. The UAV can automatically land or take off. The UAV can send a warning to the user. The UAV can automatically slow down or speed up. The UAV can adjust operation of a payload, carrier, sensor, communication unit, navigation unit, power regulation unit (which can include ceasing operation or changing an operational parameter thereof). The flight response measure can occur immediately, or can occur after a period of time (e.g., 1 minute, 3 minutes, 5 minutes, 10 minutes, 15 minutes, 30 minutes). The period of time can be a grace period for the user to react and exercise some control over the UAV before the flight response measure takes effect. For example, if the user approaches a flight restricted zone, the user can be warned and can change a flight path of the UAV to exit the flight restricted zone. If the user does not respond within the grace period, the UAV can automatically land within the flight restricted zone. The UAV can operate normally according to one or more flight commands from a remote controller operated by a remote user. When the set of flight regulations and the one or more flight commands conflict, the flight response measure can override the one or more flight commands. For example, if the user commands the UAV to enter a no-fly zone, the UAV can automatically change a flight path to avoid the no-fly zone.

[0135] The set of flight regulations can include information regarding one or more of: (1) an assigned volume and / or region over which a set of flight regulations can be imposed, (2) one or more rules (e.g., operation of the UAV, payload, carrier, sensor, communication unit, navigation unit, power unit), (3) one or more flight response measures to cause the UAV to follow the rules (e.g., response of the UAV, payload, carrier, sensor, communication unit, navigation unit, power unit), or (4) a temporal or any other factor that can affect the assigned volume and / or region, the rules, or the flight response measures. A set of flight regulations can include a single flight regulation, which can include information regarding (1), (2), (3), and / or (4). A set of flight regulations can include multiple flight regulations, which can each include information regarding (1), (2), (3), and / or (4). Any type of flight regulation can be incorporated, and any combination of flight response measures can occur in accordance with the flight regulations. One or more assigned volumes and / or regions can be provided for a set of flight regulations. For example, a set of flight regulations can be provided for a UAV, where the set of flight regulations does not allow the UAV to fly within an assigned first volume, allows the UAV to fly within an assigned second volume below an altitude cap but does not allow operation of a camera on the UAV, and only allows the UAV to record audio data within an assigned third volume. The UAV can have flight response measures that can cause the UAV to comply with the flight regulations. Manual operation of the UAV can be overridden to cause the UAV to comply with the rules of the flight regulations. One or more flight response measures can occur automatically to override manual input by a user.

[0136] A set of flight regulations can be generated for a UAV. The generation of the set of flight regulations can include creating the flight regulations from scratch. The generation of the set of flight regulations can include selecting a set of flight regulations from among a plurality of available sets of flight regulations. The generation of the set of flight regulations can include incorporating features of one or more sets of flight regulations. For example, the generation of a set of flight regulations can include determining elements such as determining an assigned volume and / or region, determining one or more rules, determining one or more flight response measures, and / or determining any factors that can cause any of the elements to be dynamic elements. The elements can be generated from scratch or can be selected from one or more pre-existing element options. In some cases, the flight regulations can be manually selected by a user. Alternatively, the flight regulations can be automatically selected with the aid of one or more processors without user intervention. In some cases, some user input can be provided, but the one or more processors can cause the final determination of the flight regulations to comply with the user input.

[0137] Figure 3Examples of one or more factors that can be involved in the generation of a set of flight regulations are shown. For example, user information 310, unmanned vehicle information 320, and / or geo-fencing device information 330 can be involved in the generation of a set of flight regulations 340. In some cases, only user information, only unmanned vehicle information, only geo-fencing information, only remote control information, or any number or any combination of these factors are considered in the process of generating the set of flight regulations.

[0138] Additional factors can be considered in the process of generating the set of flight regulations. These factors can include information about the local environment (e.g., environmental complexity, urban vs. rural, traffic flow information, weather information), information from one or more third party sources (e.g., government sources such as the FAA), time related information, user inputted preferences, or any other factor.

[0139] In some embodiments, a set of flight regulations for a particular terrain (e.g., an assigned volume, an assigned region) can be the same regardless of user information, unmanned vehicle information, geo-fencing device information, or any other information. For example, all users can receive the same set of flight regulations. In another case, all unmanned vehicles can receive the same set of flight regulations.

[0140] Alternatively, a set of flight regulations for a particular terrain (e.g., an assigned volume, an assigned region) can differ based on user information, unmanned vehicle information, and / or geo-fencing device information. User information can include information specific to an individual user (e.g., user flight history, record of previous user flights) and / or can include a user type (e.g., user skill category, user experience category) as described elsewhere herein. Unmanned vehicle information can include information specific to an individual unmanned vehicle (e.g., unmanned vehicle flight history, record of maintenance or incidents, unique serial number) and / or can include an unmanned vehicle type (e.g., unmanned vehicle model, characteristics) as described elsewhere herein.

[0141] A set of flight regulations can be generated based on a user identifier that indicates a user type. A system for controlling an unmanned aerial vehicle (UAV) can be provided. The system can include a first communication module; one or more processors operably coupled to the first communication module and individually or collectively configured to: receive, using the first communication module or a second communication module, a user identifier that indicates a user type; generate, based on the user identifier, a set of flight regulations for the unmanned aerial vehicle; and transmit, using the first communication module or the second communication module, the set of flight regulations to the unmanned aerial vehicle.

[0142] A method for controlling an unmanned aerial vehicle (UAV) can include receiving a user identifier indicative of a user type, generating, by way of one or more processors, a set of flight regulations for the UAV based on the user identifier, and transmitting, by way of a communication module, the set of flight regulations to the UAV. Similarly, a non-transitory computer readable medium containing program instructions for operating an unmanned aerial vehicle (UAV) can include program instructions for receiving a user identifier indicative of a user type, program instructions for generating a set of flight regulations for the UAV based on the user identifier, and program instructions for generating a signal to transmit, by way of a communication module, the set of flight regulations to the UAV.

[0143] An unmanned aerial vehicle can include one or more power units that enable flight of the unmanned aerial vehicle, a communication module configured to receive one or more flight commands from a remote user, and a flight control unit configured to generate flight control signals that are delivered to the one or more power units, wherein the flight control signals are generated in accordance with a set of flight regulations for the unmanned aerial vehicle, wherein the flight regulations are generated based on a user identifier indicative of a user type of the remote user.

[0144] A user type can have any characteristic as described elsewhere herein. For example, a user type can indicate a level of experience of a user operating an unmanned aerial vehicle, a level of training or certification of a user operating an unmanned aerial vehicle, or a class of users operating one or more types of unmanned aerial vehicles. A user identifier can uniquely identify the user from other users. A user identifier can be received from a remote controller that is remote from the unmanned aerial vehicle.

[0145] The set of flight regulations is generated by selecting a set of flight regulations from a plurality of sets of flight regulations based on the user identifier. The set of flight regulations is generated by an air traffic control system that is external to the unmanned aerial vehicle. The unmanned aerial vehicle can communicate with the air traffic control system via a direct communication channel. The unmanned aerial vehicle can communicate with the air traffic control system through a user or a remote controller operated by the user. The unmanned aerial vehicle can communicate with the air traffic control system through one or more other unmanned aerial vehicles.

[0146] A set of flight regulations can be generated based on a UAV identifier that indicates a UAV type. A system for controlling an unmanned aerial vehicle (UAV) can be provided. The system can include a first communication module; one or more processors operably coupled to the first communication module and individually or collectively configured to: receive, using the first communication module or a second communication module, a UAV identifier that indicates a UAV type; generate, based on the UAV identifier, a set of flight regulations for the UAV; and transmit, using the first communication module or a second communication module, the set of flight regulations to the UAV.

[0147] In some embodiments, a method for controlling an unmanned aerial vehicle (UAV) can include receiving a UAV identifier that indicates a UAV type; generating, by way of one or more processors, a set of flight regulations for the UAV based on the UAV identifier; and transmitting, by way of a communication module, the set of flight regulations to the UAV. Similarly, a non-transitory computer readable medium containing program instructions for operating an unmanned aerial vehicle (UAV) can include program instructions for receiving a UAV identifier that indicates a UAV type; program instructions for generating a set of flight regulations for the UAV based on the UAV identifier; and program instructions for generating a signal to transmit, by way of a communication module, the set of flight regulations to the UAV.

[0148] A UAV can be provided that includes one or more power units that enable flight of the UAV; a communication module configured to receive one or more flight commands from a remote user; and a flight control unit configured to generate flight control signals that are delivered to the one or more power units, wherein the flight control signals are generated in accordance with a set of flight regulations for the UAV, wherein the flight regulations are generated based on a UAV identifier that indicates a UAV type of the remote user.

[0149] The UAV type can have any of the characteristics as described elsewhere herein. For example, the UAV type can indicate a model of the UAV, a performance of the UAV, or a payload of the UAV. The UAV identifier can uniquely identify the UAV from other UAVs. The user identifier can be received from a remote controller that is remotely located from the UAV.

[0150] A set of flight regulations can be generated based on including one or more additional factors, such as those described elsewhere herein. For example, environmental conditions can be considered. For example, more restrictions can be provided if the environmental complexity is high, while fewer restrictions can be provided if the environmental complexity is low. More restrictions can be provided if the population density is high, while fewer restrictions can be provided if the population density is low. More restrictions can be provided if there is a higher degree of traffic (e.g., air traffic or surface-based traffic), while fewer restrictions can be provided if there is a lower degree of traffic. In some implementations, more restrictions can be provided if the environmental climate has a more favorable temperature, has less wind, has no precipitation, or has little or no chance of lightning, than if the environmental climate has an extreme temperature, has wind, includes precipitation, or has a chance of lightning.

[0151] A set of flight regulations can be generated based on including one or more additional factors, such as those described elsewhere herein. For example, environmental conditions can be considered. For example, more restrictions can be provided if the environmental complexity is high, while fewer restrictions can be provided if the environmental complexity is low. More restrictions can be provided if the population density is high, while fewer restrictions can be provided if the population density is low. More restrictions can be provided if there is a higher degree of traffic (e.g., air traffic or surface-based traffic), while fewer restrictions can be provided if there is a lower degree of traffic. In some implementations, more restrictions can be provided if the environmental climate has a more favorable temperature, has less wind, has no precipitation, or has little or no chance of lightning, than if the environmental climate has an extreme temperature, has wind, includes precipitation, or has a chance of lightning.

[0152] As described previously, various types of flight regulations can be provided in a set of flight regulations. Flight regulations can be specific to a UAV or user or need not be specific to a UAV and / or user.

[0153] Figure 7 A diagram showing a scenario including various types of flight regulations is shown. Various regions can be provided. Boundaries can be provided to define the regions. A set of flight regulations can affect one or more regions (e.g., airspace over a two-dimensional surface region or a volume of airspace). The set of flight regulations can include one or more rules associated with one or more regions.

[0154] In one example, a flight regulation region 710 can be provided, a communication regulation region 720 can be provided, and a payload regulation region 730 can be provided. A payload and communication regulation region 750 can be provided, as well as a non-regulation region 760. The regions can have boundaries of any shape or size. For example, a region can have a regular shape, such as a circle, an ellipse, an oval, a square, a rectangle, any type of quadrilateral, a triangle, a pentagon, a hexagon, an octagon, a strip, a curvilinear shape, etc. A region can have an irregular shape, which can include convex or concave components.

[0155] A flight regulation zone 710 can impose one or more rules regarding the arrangement or movement of the UAV. The flight regulation zone can impose flight response measures that can affect the flight of the UAV. For example, the UAV can only be able to fly at altitudes between a lower altitude limit and an upper altitude limit when located within the flight regulation zone, while no flight restrictions are imposed outside the flight regulation zone.

[0156] A payload regulation zone 720 can impose one or more rules regarding the operation or positioning of the payload of the UAV. The payload regulation zone can impose flight response measures that can affect the flight of the payload of the UAV. For example, the UAV can not be able to use the image capture device payload to capture images when located within the payload regulation zone, while no payload restrictions are imposed outside the payload regulation zone.

[0157] A communication regulation zone 730 can impose one or more rules regarding the operation of the communication unit of the UAV. The communication regulation zone can impose flight response measures that affect the operation of the communication unit of the UAV. For example, the UAV can not be able to transmit captured data when located in the communication regulation zone, but can be allowed to receive flight control signals, while no communication restrictions are imposed outside the communication regulation zone.

[0158] A payload and communication regulation zone 750 can impose one or more rules regarding the operation / positioning of the payload of the UAV and the communication unit of the UAV. For example, the UAV can not be able to store images captured by the image capture device payload on board the UAV and can also not be able to stream or transmit the images off board the UAV when located within the payload and communication regulation zone, while no such restrictions are imposed outside the payload and communication regulation zone.

[0159] One or more non-regulation zones can be provided. The non-regulation zones can be outside one or more boundaries, or can be within one or more boundaries. When located within the non-regulation zone, the user can retain control of the UAV without the automatic initiation of one or more flight response measures. The user can be able to freely operate the UAV within the physical limitations of the UAV.

[0160] One or more of the zones can overlap. For example, the flight regulation zone can overlap with the communication regulation zone 715. For another example, the communication regulation zone can overlap with the payload regulation zone 725. For yet another example, the flight regulation zone can overlap with the payload regulation zone 735. In some cases, the flight regulation zone, the communication regulation zone, and the payload regulation zone can all overlap 740.

[0161] When multiple zones overlap, the rules from the multiple zones can remain in place. For example, the flight restrictions and the communication restrictions can both remain in place in the overlapping zone. In some cases, the rules from the multiple zones can remain in place as long as they do not conflict with each other.

[0162] If there is a conflict between the rules, various rule responses can be applied. For example, the most restrictive set of rules can be applied. For example, if a first zone requires a UAV to fly below 400 feet and a second zone requires a UAV to fly below 200 feet, in an overlapping zone, the rule regarding flying below 200 feet can be applied. This can include mixing and matching a set of rules to form the most restrictive set. For example, if a first zone requires a UAV to fly above 100 feet and below 400 feet, and a second zone requires a UAV to fly above 50 feet and below 200 feet, when the UAV is located in the overlapping zone, it can use the lower flight limit from the first zone and the upper flight limit from the second zone, thereby flying between 100 feet and 200 feet.

[0163] In another case, the zones can be provided with a level. Rules from a zone with a higher level can take precedence regardless of whether they are more or less restrictive than rules from a zone with a lower level. The levels can be indicated according to the type of regulation. For example, flight regulations for a UAV's location can be higher in level than communication regulations, which can be higher in level than payload regulations. In other cases, rules regarding whether a UAV is not allowed to fly within a particular zone can take precedence over other regulations for that zone. The levels can be pre-selected or pre-entered. In some cases, a user providing a set of rules for the zones can indicate which zones are higher in level than other zones. For example, a first zone can require a UAV to fly below 400 feet and a payload must be turned off. A second zone can require a UAV to fly below 200 feet and have no payload restrictions. If the first zone is higher in level, the rules from the first zone can be applied without applying any rules from the second zone. For example, the UAV can fly below 400 feet and have the payload turned off. If the second zone is higher in level, the rules from the second zone can be applied without applying any rules from the first zone. For example, the UAV can fly below 200 feet and have no payload restrictions.

[0164] As described previously, when a UAV is located in a zone, a set of flight regulations can impose different types of rules on the UAV. This can include restricting payload use based on the UAV's location, or restricting wireless communication based on the UAV's location.

[0165] Aspects of the application can relate to a UAV payload control system comprising: a first communication module; and one or more processors operatively coupled to the first module and individually or collectively configured for: receiving, using the first communication module or a second communication module, a signal indicative of a location-dependent payload usage parameter; and generating one or more UAV operation signals effecting payload operation in compliance with the payload usage parameter.

[0166] A method for constraining payload usage of a UAV, the method comprising: receiving a signal indicative of a location-dependent payload usage parameter; and generating, by means of one or more processors, one or more UAV operation signals effecting payload operation in compliance with the payload usage parameter. Similarly, a non-transitory computer readable medium containing program instructions for constraining payload usage of a UAV can be provided, the computer readable medium comprising: program instructions for receiving a signal indicative of a location-dependent payload usage parameter; and program instructions for generating one or more UAV operation signals effecting payload operation in compliance with the payload usage parameter.

[0167] According to embodiments of the present system, a UAV can comprise: a payload; a communication module configured for receiving one or more payload commands from a remote user; and a flight control unit configured for generating payload control signals delivered to the payload or a carrier supporting the payload, wherein the payload control signals are generated in accordance with one or more UAV operation signals, wherein the UAV operation signals are generated based on a location-dependent payload usage parameter.

[0168] The payload usage parameter can limit payload usage at one or more predetermined locations. As previously described, the payload can be an image capture device, and the payload usage parameter can limit operation of the image capture device at one or more predetermined locations. The payload usage parameter can limit recording one or more images using the image capture device at one or more predetermined locations. The payload usage parameter can limit transmitting one or more images using the image capture device at one or more predetermined locations. In other embodiments, the payload can be an audio capture device, and the payload usage parameter limits operation of the audio capture device at one or more predetermined locations.

[0169] Alternatively or in combination, the load usage parameters can allow for usage of the load at one or more predetermined locations. When the load is an image capture device, the load usage parameters can allow for operation of the image capture device at one or more predetermined locations. The load usage parameters can allow for usage of the image capture device to record one or more images at one or more predetermined locations. The load usage parameters can allow for usage of the image capture device to transmit one or more images at one or more predetermined locations. The load can be an audio capture device, and the load usage parameters can allow for operation of the audio capture device at one or more predetermined locations.

[0170] The one or more processors can also be individually or collectively configured to receive a signal indicative of a location of the UAV using the first or second communication module, and compare the location of the UAV to the location-dependent load usage parameters and determine whether the UAV is located at a location where operation of the load is restricted or allowed. The location can be a flight restricted zone. The flight restricted zone can be determined by a regulator. The flight restricted zone can be within a predetermined distance from an airport, a public gathering, government property, a school, a private residence, a power plant, or any other area that can be designated as a flight restricted zone. The location can remain stationary at all times, or can change over time.

[0171] The signal indicative of the location-dependent load usage parameters can be received from a control entity. The control entity can be a regulator, an international organization or corporation, or any other type of control entity as described elsewhere herein. The control entity can be a global authority, such as any of the authorities and organizations described elsewhere herein. The control entity can be an off-board or on-board source of the UAV. The control entity can be an air traffic control system off-board the UAV or any other portion of an authentication system off-board the UAV. The control entity can be a database, which can be stored in memory of the UAV or can be stored off-board the UAV. The database can be configured to be updatable. The control entity can be a transmission device, which can be positioned at a location where operation of the load is restricted or allowed. In some instances, the control entity can be a geo-fencing device as described elsewhere herein. In some instances, the signal can be sent based on a user identifier indicative of a user of the UAV and / or a UAV identifier indicative of a type of the UAV.

[0172] One aspect of the application can relate to a UAV communication control system comprising: a first communication module; and one or more processors operatively coupled to the first communication module and individually or collectively configured for: receiving, using the first communication module or a second communication module, a signal indicative of a location-dependent communication usage parameter; and generating one or more UAV operation signals that effect operation of a UAV communication unit in compliance with the communication usage parameter.

[0173] Further, a method for constraining wireless communication of a UAV is provided, comprising: receiving a signal indicative of a location-dependent communication usage parameter; and generating, by means of one or more processors, one or more UAV operation signals that effect operation of a communication unit in compliance with the communication usage parameter. Similarly, a non-transitory computer readable medium containing program instructions for constraining wireless communication of a UAV (UAV) can be provided, the computer readable medium comprising: program instructions for receiving a signal indicative of a location-dependent communication usage parameter; and program instructions for generating one or more UAV operation signals that effect operation of a communication unit in compliance with the communication usage parameter.

[0174] Additional aspects of the application can include a UAV comprising: a communication unit configured for receiving or transmitting wireless communication; and a flight control unit configured for generating a communication control signal that is delivered to the communication unit to effect operation of the communication unit, wherein the communication control signal is generated in accordance with one or more UAV operation signals, wherein the UAV operation signals are generated based on a location-dependent communication usage parameter.

[0175] The communication usage parameters can limit wireless communication usage at one or more predetermined locations. The wireless communication can be direct communication. The wireless communication can include radio frequency communication, WiFi communication, Bluetooth communication, or infrared communication. The wireless communication can be indirect communication. The wireless communication can include 3G, 4G, or LTE communication. The communication usage can be limited by disallowing any wireless communication. The communication usage can be limited by allowing wireless communication usage only within selected frequency bands. The communication usage can be limited by allowing the wireless communication usage only when it does not interfere with higher priority communication. In some cases, all other pre-existing wireless communication can have higher priority than the UAV communication. For example, various wireless communication occurring in the vicinity can be considered to have higher priority if a UAV is flying in the vicinity. In some cases, certain types of communication can be considered to be higher priority communication - e.g., emergency service communication, government or official communication, medical device or service communication, etc. Alternatively or in combination, the communication usage parameters can allow wireless communication usage at one or more predetermined locations. For example, indirect communication can be allowed within a designated area, while direct communication is disallowed.

[0176] The one or more processors can also be individually or collectively configured to receive a signal indicating a location of the UAV using the first or second communication module, and compare the location of the UAV to the location-dependent communication usage parameters and determine whether the UAV is located at a location that limits or allows operation of the communication unit. The location can be a communication restricted zone. The communication restricted zone can be determined by a regulator or by a private party. The flight restricted zone can be within a predetermined distance from a private residence, an airport, a public gathering, government property, a school, a power plant, or any other area that can be designated as a flight restricted zone. The location can remain static or can change over time.

[0177] The location can depend on existing wireless communication within an area. For example, an area can be identified as a communication restricted zone if operation of the communication unit would interfere with one or more existing wireless communication within the area. Operation of the UAV communication unit in compliance with the communication usage parameters can reduce electromagnetic or audio interference. For example, certain operations of the UAV communication unit can interfere with surrounding electronic devices if they are in use, e.g., interfere with their wireless signals. Operation of the UAV communication unit in compliance with the communication usage parameters can reduce or eliminate the interference. For example, operation of the UAV communication unit within a limited frequency band can not interfere with surrounding electronic device operations or communications. In another case, suspension of operation of the UAV communication unit within an area can prevent interference with surrounding electronic device operations or communications.

[0178] A signal indicating a location-related communication usage parameter can be received from a control entity. The control entity can be a regulator, an international organization, or a company, or any other type of control entity as described elsewhere herein. The control entity can be a global authority, such as any of the authorities and organizations described elsewhere herein. The control entity can be an off-board or on-board source of the UAV. The control entity can be an air traffic control system off-board the UAV or any other part of an authentication system off-board the UAV. The control entity can be a database, which can be stored in memory of the UAV or off-board the UAV. The database can be configured to be updatable. The control entity can be a transmission device, which can be positioned at a location where a payload operation is restricted or allowed. In some instances, the control entity can be a geo-fencing device as described elsewhere herein. In some instances, the signal can be sent based on a user identifier indicating a user of the UAV and / or a UAV identifier indicating a UAV type.

[0179] Identification module

[0180] A UAV can include one or more power units that can propel the UAV. In some instances, a power unit can include a rotor assembly that can include one or more motors that drive rotation of one or more rotor blades. The UAV can be a multicopter UAV that can include multiple rotor assemblies. The rotor blades, when rotated, can provide a propulsion force, such as lift, to the UAV. The various rotor blades of the UAV can be able to rotate at the same speed or at different speeds. Operation of the rotor blades can be used to control flight of the UAV. Operation of the rotor blades can be used to control takeoff and / or landing of the UAV. Operation of the rotor blades can be used to control maneuvering of the UAV in airspace.

[0181] The UAV can include a flight control unit. The flight control unit can generate one or more signals that can control operation of the rotor assembly. The flight control unit can generate one or more signals that control operation of one or more motors of the rotor assembly, which can in turn affect the rotational speed of the rotor blades. The flight control unit can receive data from one or more sensors. The data from the sensors can be used to generate one or more flight control signals to the rotor assembly. Examples of sensors can include, but are not limited to, a GPS unit, an inertial sensor, a vision sensor, an ultrasonic sensor, a thermal sensor, a magnetometer, or other types of sensors. The flight control unit can receive data from a communication unit. The data from the communication unit can include commands from a user. The commands can be input via a remote control, which can be transmitted to the UAV. The data from the communication unit and / or sensors can include detection of a geo-fencing device or information transmitted from a geo-fencing device. The data from the communication unit can be used to generate one or more flight control signals to the rotor assembly.

[0182] In some embodiments, the flight control unit can control other functions of the UAV in addition to or instead of flight. The flight control unit can control operation of a payload on the UAV. For example, the payload can be an image capture device, and the flight control unit can control operation of the image capture device. The flight control unit can control positioning of a payload on the UAV. For example, a carrier can support a payload, such as an image capture device. The flight control unit can control operation of the carrier to control positioning of the payload. The flight control unit can control operation of one or more sensors on the UAV. This can include any of the sensors described elsewhere herein. The flight control unit can control communication of the UAV, navigation of the UAV, power usage of the UAV, or any other function on the UAV.

[0183] Figure 4 An example of a flight control unit according to embodiments of the application is shown. The flight control module 400 can include an identification module 410, one or more processors 420, and one or more communication modules 430. In some embodiments, the flight control module of a UAV can be a circuit board, which can include one or more chips, such as one or more identification chips, one or more processor chips, and / or one or more communication chips.

[0184] The identification module 410 can be unique to the UAV. The identification module can be capable of being uniquely identified and distinguished from other UAVs by other UAVs. The identity module can include a UAV identifier and a key of the UAV.

[0185] The UAV identifier stored in the identification module can be unalterable. The UAV identifier can be stored in the identification module in an unalterable state. The identification module can be a hardware component that stores the unique UAV identifier of the UAV in a manner that prevents a user from altering the unique identifier.

[0186] The UAV key can be configured to provide authentication verification for the UAV. The UAV key can be unique to the UAV. The UAV key can be an alphanumeric string that can be unique to the UAV and can be stored in the identification module. The UAV key can be randomly generated.

[0187] The UAV identifier and the UAV key can be used in conjunction to authenticate the UAV and allow operation of the UAV. An authentication center can be used to authenticate the UAV identifier and the UAV key. The authentication center can be off-board the UAV. The authentication center can be part of an authentication system as described elsewhere herein (e.g., the authentication center 220 in Figure 2 ).

[0188] The UAV identifier and the UAV key can be issued by an ID registration database as described elsewhere herein (e.g., the ID registration module 210 in Figure 2 ). The ID registration database can be off-board the UAV. The identification module can be configured to receive the UAV identifier and the UAV key once and not alter after the initial receipt. Thus, the UAV identifier and the UAV key can be unalterable once they have been determined. In other cases, the UAV identifier and key can be fixed after receipt and can never be written again. Alternatively, the UAV identifier and the UAV key can only be modified by an authorized party. The regular operator of the UAV can not be able to alter or modify the UAV identifier and the UAV key in the identification module.

[0189] In some cases, the ID registration database can issue the identification module itself, which can be manufactured into the UAV. The ID registration database can issue the identifier before or at the same time as the UAV is manufactured. The ID registration database can issue the identifier before the UAV is sold or distributed.

[0190] The identification module can be implemented as a USIM. The identification module can be a one-time writable memory. The identification module can optionally be externally unreadable.

[0191] The identification module 410 can be inseparable from the flight control unit 400. The identification module cannot be removed from the rest of the flight control unit without damaging the functionality of the flight control unit. The identification module cannot be removed from the rest of the flight control unit by hand. An individual cannot manually remove the identification module from the flight control unit.

[0192] An unmanned aircraft can include a flight control unit configured to control operation of the unmanned aircraft; and an identification module integrated into the flight control unit, wherein the identification module uniquely identifies the unmanned aircraft from other unmanned aircrafts. A method of identifying an unmanned aircraft can be provided, the method comprising: controlling operation of the unmanned aircraft using a flight control unit; and uniquely identifying the unmanned aircraft from other unmanned aircrafts using an identification module integrated into the flight control unit.

[0193] The identification module can be physically joined or attached to the flight control unit. The identification module can be integrated into the flight control unit. For example, the identification module can be a chip soldered onto a circuit board of the flight control unit. Various physical techniques can be employed to prevent the identification module from being separated from the rest of the flight control unit.

[0194] System in package (SIP) technology can be employed. For example, multiple functional chips (including a processor, a communication module, and / or an identification module) can be integrated in one package, thereby performing a complete function. If the identification module is to be separated, the other modules in the package will be damaged, thereby rendering the unmanned aircraft inoperable.

[0195] Figure 5 An additional example of a flight control unit 500 according to embodiments of the present application is shown. A possible configuration utilizing SIP technology is illustrated. The identification module 510 and the processor 520 can be packaged in the same chip. The identification module can not be separated from the processor, and any attempt to remove the identification module will result in removal or damage to the processor, which will result in damage to the flight control unit. The identification module can be integrated with one or more other components of the flight control unit within one package of the same chip. In other examples, the identification module can be packaged in the same chip with the communication module 530. In some cases, the identification module, the processor, and the communication module can all be packaged within one chip.

[0196] A chip on board (COB) package can be employed. The bare chip can be adhered to the interconnect substrate with conductive or non-conductive glue. Wire bonding can then be performed to achieve its electrical connections, also known as soft packaging. The identification module can be soldered onto the circuit board of the flight control unit. After the COB package, the identification module, once soldered onto the circuit board, can not be removed in its entirety. Attempts to physically remove the identification module will result in damage to the circuit board or other parts of the flight control unit.

[0197] Software can be used to ensure that the identification module is inseparable from the rest of the flight control unit of the unmanned aerial vehicle. For example, each unmanned aerial vehicle can burn a software version corresponding to its identification module. In other words, there can be a one-to-one correspondence between the software version and the identity module. The software version can be unique or substantially unique to the unmanned aerial vehicle. Normal operation of the software requires obtaining the unmanned aerial vehicle key stored in the identification module. Without the corresponding unmanned aerial vehicle key, the software version can not run. If the identification module is changed or removed, the software of the unmanned aerial vehicle cannot operate normally.

[0198] In some embodiments, the identification module can be issued by a control entity. The control entity can be any entity that exercises some form of power for identifying unmanned aerial vehicles or exercising some form of power over unmanned aerial vehicles. In some cases, the control entity can be a government agency or an operator authorized by the government. The government can be a national government, a state / provincial government, a city government, or any form of local government. The control entity can be a government agency, such as the Federal Aviation Administration (FAA), the Federal Trade Commission (FTC), the Federal Communications Commission (FCC), the National Telecommunications and Information Administration (NTIA), the Department of Transportation (DoT), or the Department of Defense (DoD). The control entity can be a regulator. The control entity can be a national or international organization or a company. The control entity can be a manufacturer of unmanned aerial vehicles or a distributor of unmanned aerial vehicles.

[0199] Figure 6 An example of a flight control unit that tracks the identification of chips on the flight control unit is shown, in accordance with embodiments of the present application. The flight control unit 600 can have an identification module 610 and one or more chips (e.g., chip 1 620, chip 2 630,...). The identification module can have a unique unmanned aerial vehicle identifier 612, a chip record 614, and one or more processors 616.

[0200] The identification module 610 can be inseparable from the rest of the flight control unit 600. Alternatively, the identification module can be removable from the flight control unit. The identification module can uniquely identify the unmanned aerial vehicle from other unmanned aerial vehicles by the unique unmanned aerial vehicle identifier 612.

[0201] The identification module can include a chip record 614 that can store a record of one or more peripheral chips 620, 630. Examples of other chips can include one or more processing chips, communication chips, or any other type of chip. The chip record can store any type of data about the one or more peripheral chips, such as the type of peripheral chip (e.g., model number), information about the chip manufacturer, a serial number of the chip, performance characteristics of the chip, or any other data about the chip. The record can be unique to a particular chip, unique to a type of chip, and / or can include parameters that are not necessarily unique to a chip or chip type. The chip record can be a memory unit.

[0202] When the UAV is started, the identification module can initiate a self-check, which can aggregate information about the peripheral chips and compare the aggregated information to the information stored in the chip record. One or more processors 616 of the identification module can be used to perform the comparison. The identification module can check whether the peripheral chips match the chip record internal to it, thereby discerning whether the identification module has been transplanted. For example, if the information currently gathered during the self-check matches the initial chip record, it is likely that the identification module has not been transplanted. If the information currently gathered during the self-check procedure does not match the initial chip record, it is likely that the identification module has been transplanted. An indication of whether the identification module has been transplanted or the likelihood of a transplant occurring can be provided to a user or another device. For example, when the initial chip record does not match the peripheral chip information at the time of the self-check, a warning can be sent to a user device or to a control entity.

[0203] In some embodiments, the chip record information can not change. The chip record information can be a write-once memory. The chip record can include information about the one or more peripheral chips gathered at the first start of the UAV. The information about the peripheral chips can be hardwired into the chip record. The information about the peripheral chips can be provided by the manufacturer and can be built into the chip record. In some cases, the chip record can be externally unreadable.

[0204] In alternative embodiments, the chip record information can change. The chip record information can be updated each time the self-check procedure occurs. For example, the information about the peripheral chips can be used to replace or supplement the existing record about the peripheral chips. A comparison can be made between the initial chip record and the chip information aggregated during the self-check. If no change is detected, it is likely that the identification module has not been transplanted. If a change is detected, it is likely that the identification module has been transplanted. Similarly, an indication of whether a transplant has occurred can be provided.

[0205] For example, an initial chip can include a record showing two peripheral chips, one of which is a model X with a serial number ABCD123 and the other of which is a model Y with a serial number DCBA321. A self-check procedure can occur. During the self-check procedure, information about the peripheral chips can be aggregated, which can show two chips, one of which is a model X with a serial number 12345FG and the other of which is a model S with a serial number HIJK987. Because the data does not match, a higher likelihood that the identification module has been transplanted can be provided. The initial identification module, which would have had a record in the chip of a model X with a serial number 12345FG and a model S with a serial number HIJK987, can have been removed. The initial identification module can be replaced by a new identification module taken from a different unmanned vehicle, where the flight control unit of the different unmanned vehicle has a chip of a model X with a serial number ABCD123 and a model Y with a serial number DCBA321. The initial chip record can include a record of the unmanned vehicle's peripheral chips from the initial manufacturer or initial configuration of the unmanned vehicle or from a previous operation of the unmanned vehicle. Regardless, the discrepancy can indicate that the identification module has been transplanted for the unmanned vehicle since the initial manufacture or initial configuration or since the previous operation.

[0206] Thus, an unmanned vehicle can be provided that includes a flight control unit configured to control operation of the unmanned vehicle, where the flight control unit includes an identification module and a chip, where the identification module is configured to (1) uniquely identify the unmanned vehicle from other unmanned vehicles, (2) include an initial record of the chip, and (3) aggregate information about the chip after including the initial record of the chip, where the identification module is configured to undergo a self-check procedure that compares the aggregated information about the chip to the initial record of the chip, and where the identification module is configured to provide a warning when the aggregated information about the chip is inconsistent with the initial record of the chip.

[0207] A method of identifying an unmanned vehicle can include using a flight control unit to control operation of the unmanned vehicle, where the flight control unit includes an identification module and a chip; using the identification module to uniquely identify the unmanned vehicle from other unmanned vehicles, where the identification module includes an initial record of the chip; aggregating information about the chip after including the initial record of the chip; using the identification module, comparing the aggregated information about the chip to the initial record of the chip, thereby undergoing a self-check procedure; and providing a warning when the aggregated information about the chip is inconsistent with the initial record of the chip.

[0208] The chip record can be an integral part of the identification module. The chip record can be inseparable from the rest of the identification module. In some cases, the chip record cannot be removed from the identification module without damaging the identification module and / or the rest of the flight control.

[0209] The self-test can occur automatically without any user input. The self-test program can automatically start when the unmanned aerial vehicle is powered on. For example, the self-test program can proceed as soon as the unmanned aerial vehicle is turned on. The self-test program can automatically start when the unmanned aerial vehicle begins to fly. The self-test program can automatically start when the unmanned aerial vehicle is powered off. The self-test program can automatically start periodically (e.g., automatically start at regular or irregular time intervals) during operation of the unmanned aerial vehicle. The self-test program can also occur in response to a detected event or in response to user input.

[0210] In some embodiments, an authentication system can be involved in the process of issuing identification modules. The authentication system can issue physical identification modules or data that can be provided in identification modules. An ID registration module and / or an authentication center can be involved in the process of issuing identification modules. A control authority can be involved in implementing the authentication system. A control entity can be involved in the process of issuing identification modules. The control entity can be a specific government agency or an operator authorized by the government, or any other type of control entity as described elsewhere herein.

[0211] To prevent an unmanned aerial vehicle from being illegally modified (e.g., with a new identification module or a new identifier), an authentication system (e.g., an authentication center) can require periodic inspections of the unmanned aerial vehicle. Once the unmanned aerial vehicle is qualified and no tampering is detected, the authentication process can continue. The authentication process can uniquely identify the unmanned aerial vehicle and confirm that the unmanned aerial vehicle is the actual unmanned aerial vehicle identified by the identifier.

[0212] Identification for operation

[0213] A user of the unmanned aerial vehicle can be uniquely identified. The user can be uniquely identified by means of a user identifier. The user identifier can uniquely identify the user and can distinguish that user from other users. The user can be an operator of the unmanned aerial vehicle. The user can be an individual who controls the unmanned aerial vehicle. The user can control flight of the unmanned aerial vehicle, control loading and / or stowage operations of the unmanned aerial vehicle, control communications of the unmanned aerial vehicle, control one or more sensors of the unmanned aerial vehicle, control navigation of the unmanned aerial vehicle, control power usage of the unmanned aerial vehicle, or control any other function of the unmanned aerial vehicle.

[0214] The UAV can be uniquely identified. The UAV can be uniquely identified by means of a UAV identifier. The UAV identifier can uniquely identify the UAV and can distinguish the UAV from other UAVs.

[0215] In some cases, users can be authorized to operate the UAV. One or more individual users can need to be identified before being able to operate the UAV. In some cases, all users can be authorized to operate the UAV when identified. Alternatively, only a selected group of users can be authorized to operate the UAV when identified. Some users can not be authorized to operate the UAV.

[0216] Figure 8 A process is shown that considers whether a user is authorized to operate a UAV before allowing the user to operate the UAV, according to embodiments of the application. The process can include receiving a user identifier 810 and receiving a UAV identifier 820. A determination can be made whether the user is authorized to operate the UAV 830. If the user is not authorized to operate the UAV, the user is not allowed to operate the UAV 840. If the user is authorized to operate the UAV, the user is allowed to operate the UAV 850.

[0217] A user identifier can be received 810. The user identifier can be received from a remote controller. The user identifier can be received from user input. The user identifier can be pulled from memory based on user input. The user input can optionally be provided to a remote controller or another device. In providing the user identifier, the user can log in or go through any authentication procedure. The user can manually enter the user identifier. The user identifier can be stored on a user device. The user identifier can be stored in memory without the user manually entering the user identifier.

[0218] A UAV identifier can be received 820. The user identifier can be received from a UAV. The UAV identifier can be received from user input. The UAV identifier can be pulled from memory based on user input. The user input can optionally be provided to a remote controller or another device. In providing the UAV identifier, the user can go through an authentication procedure. Alternatively, the UAV can automatically go through a self-identification or self-authentication procedure. The UAV identifier can be stored on a UAV or user device. The UAV identifier can be stored in memory without the user manually entering the UAV identifier. The UAV identifier can be stored on an identification module of the UAV. The UAV identifier for the UAV can optionally be unchangeable.

[0219] The unmanned aerial vehicle (UAV) may broadcast its UAV identifier during operation. The UAV identifier may be broadcast continuously. Alternatively, the UAV identifier may be broadcast upon request. The UAV identifier may be broadcast upon request to an external air traffic control system, an external authentication system, or any other device. The UAV identifier may be broadcast when communication between the UAV and the air traffic control system may be encrypted or authenticated. In some cases, the UAV identifier may be broadcast in response to an event. For example, the UAV identifier may be broadcast automatically when the UAV is activated. The UAV identifier may be broadcast during initialization procedures. The UAV identifier may be broadcast during authentication procedures. Optionally, the UAV identifier may be broadcast via wireless signals (e.g., radio signals, light signals, or acoustic signals). The identifier may be broadcast using direct communication. Alternatively, the identifier may be broadcast using indirect communication.

[0220] User identifiers and / or UAV identifiers may be received by an authentication system. User identifiers and / or UAV identifiers may be received at the authentication center of the authentication system or at an air traffic control system. User identifiers and / or UAV identifiers may be received by the UAV and / or the UAV's remote controller. User identifiers and / or UAV identifiers may be received at one or more processors that can determine whether a user is authorized to operate the UAV.

[0221] The determination of whether a user is authorized to operate the unmanned aerial vehicle 830 can be made using one or more processors. This determination can be made on or off the unmanned aerial vehicle. It can be made on or off the user's remote controller. It can be made at a device separate from the unmanned aerial vehicle and / or remote controller. In some cases, the determination can be made at a component of the authentication system. It can be made at the authentication center of the authentication system (e.g., such as...). Figure 2 The certification center 220 shown in the diagram) or the air traffic control system of the certification system (e.g., such as...) Figure 2 The determination is made at point 230 of the air traffic control system shown in the diagram.

[0222] The determination can be made at a device or system capable of generating one or more sets of flight control. For example, it can be made at an air traffic control system capable of generating one or more sets of flight control to which an unmanned aerial vehicle (UAV) will operate. The set of one or more sets of flight control may depend on the UAV's location or any other factors concerning the UAV. The set of one or more sets of flight control may be generated based on a user identifier and / or an UAV identifier.

[0223] When determining whether to authorize a user to operate a UAV, the user identifier and the UAV identifier can be considered. In some instances, only the user identifier and the UAV identifier can be considered. Alternatively, additional information can be considered. Information about the user can be associated with the user identifier. For example, information about the user's type (e.g., skill level, experience level, certification, license, training) can be associated with the user identifier. The user's flight history (e.g., locations flown by the user, types of UAVs flown by the user, whether the user has had any accidents) can be associated with the user identifier. Information about the UAV can be associated with the UAV identifier. For example, information about the type of UAV (e.g., model, manufacturer, characteristics, performance parameters, level of difficulty to operate) can be associated with the UAV identifier. The UAV's flight history (e.g., locations flown by the UAV, users who have previously interacted with the UAV) can also be associated with the UAV identifier. The information associated with the user identifier and / or the UAV identifier can be considered in the process of determining whether to authorize the user to operate the UAV. In some instances, additional factors can be considered, such as geographic factors, timing factors, environmental factors, or any other type of factor.

[0224] Optionally, only a single user is authorized to operate a corresponding UAV. A one-to-one correspondence can be provided between the authorized user and the corresponding UAV. Alternatively, multiple users can be authorized to operate a UAV. A many-to-one correspondence can be provided between the authorized users and the corresponding UAVs. A user can be authorized to operate only a single corresponding UAV. Alternatively, a user can be authorized to operate multiple UAVs. A one-to-many correspondence can be provided between the authorized user and the multiple corresponding UAVs. Multiple users can be authorized to operate multiple corresponding UAVs. A many-to-many correspondence can be provided between the authorized users and the multiple corresponding UAVs.

[0225] In some cases, a user can pre-register to operate a UAV. For example, only users who pre-register to operate a UAV can be authorized to operate the UAV. The user can be a registered owner of the UAV. When the user purchases or receives the UAV, the user can register as the owner and / or operator of the UAV. In some cases, multiple users can be able to register as the owner and / or operator of the UAV. Alternatively, only one user can be able to register as the owner and / or operator of the UAV. The single user can be able to designate one or more other users who are allowed to operate the UAV. In some cases, only users with a user identifier who have pre-registered to operate a UAV can be authorized to operate the UAV. One or more registration databases can store information about registered users who are allowed to operate a UAV. The registration database can be on-board or off-board the UAV. A user identifier can be compared to the information in the registration database, and the user can be allowed to operate the UAV only when the user identifier matches a user identifier associated with the UAV in the registration database. The registration database can be specific to a UAV. For example, a first user can pre-register to operate UAV 1, but not UAV 2. The user can then be allowed to operate UAV 1, but not UAV 2. In some cases, the registration database can be specific to a type of UAV (e.g., all UAVs with a particular model number).

[0226] In other cases, the registration database can be open, independent of the UAV. For example, a user can pre-register as an operator of a UAV. The user can be allowed to operate any UAV, as long as those particular UAVs do not have any other requirements for authorization.

[0227] Alternatively, the UAV can default to allowing all users to operate the UAV. All users can be authorized to operate the UAV. In some cases, all users not on a "blacklist" can be authorized to operate the UAV. Thus, when determining whether to authorize a user to operate a UAV, the user can be authorized to operate the UAV so long as the user is not on the blacklist. One or more blacklist databases can store information about users that are not allowed to operate a UAV. The blacklist database can store user identifiers of users that are not allowed to operate a UAV. The blacklist database can be on-board or off-board the UAV. A user identifier can be compared to the information in the blacklist database, and the user can be allowed to operate the UAV only if the user identifier matches a user identifier in the blacklist database. The blacklist registration can be specific to a UAV or a type of UAV. For example, a user can be listed on a blacklist that prohibits the user from operating a first UAV, but can not be listed on a blacklist that prohibits the user from operating a second UAV. The blacklist registration can be specific to a UAV type. For example, a user can be prohibited from operating a particular model of UAV, but allowed to operate other models of UAVs. Alternatively, the blacklist registration need not be specific to a UAV or a UAV type. The blacklist registration can be applicable to all UAVs. For example, if a user is prohibited from operating any UAV, the user can not be authorized to operate a UAV regardless of the UAV identity or type, and operation of the UAV is not allowed.

[0228] Pre-registration or blacklist registration can also apply to other factors besides the UAV or UAV type. For example, pre-registration or blacklist registration can apply to a particular location or jurisdiction. For example, a user can be pre-registered to operate a UAV within a first jurisdiction, but not pre-registered to operate a UAV within a second jurisdiction. This can or can not be known to the identity or type of the UAV itself. In another example, pre-registration or blacklist registration can apply to a particular weather condition. For example, a user can be listed on a blacklist that prohibits the user from operating a UAV when the wind speed exceeds 30 mph. In another example, other environmental conditions can be considered, such as environmental complexity, population density, or air traffic volume.

[0229] Additional considerations for whether to authorize a user to operate a UAV can depend on the user type. For example, a user's skill or experience level can be considered in determining whether to authorize the user to operate a UAV. Information about the user, such as the user type, can be associated with the user identifier. Information about the user, such as the user type, can be considered when determining whether to authorize the user to operate a UAV. In one example, a user can only be authorized to operate a UAV if the user has reached a threshold skill level. For example, a user can be authorized to operate a UAV if the user has undergone training for UAV flight. For another example, a user can be authorized to operate a UAV if the user has undergone certification of certain flight skills for the user. In another example, a user can only be authorized to operate a UAV if the user has reached a threshold experience level. For example, a user can be authorized to operate a UAV if the user has logged at least a threshold number of flight time units. In some cases, the threshold number can apply to flight time units of any UAV or only to flight time units of UAVs having a type matching the UAV. Information about the user can include demographic information about the user. For example, a user can only be authorized to operate a UAV if the user reaches a threshold age (e.g., is an adult). Information about the user and / or the UAV can be pulled and considered by way of one or more processors in determining whether to authorize the user to operate a UAV. One or more considerations can be made from a non-transitory computer-readable medium in determining whether to authorize the user to operate a UAV.

[0230] As previously described, additional factors, such as geographic factors, temporal factors, or environmental factors, can be considered in determining whether to authorize a user to operate a UAV. For example, only some users can be authorized to operate a UAV at night, while other users can be authorized to operate a UAV only during the day. In one example, a user who has undergone night flight training can be authorized to operate a UAV during the day and at night, while a user who has not undergone night flight training can only be authorized to operate a UAV during the day.

[0231] In some instances, different modes of UAV authentication can be provided. For example, in a pre-registration mode, only pre-registered users can be authorized to manipulate the UAV. In an open mode, all users can be authorized to manipulate the UAV. In a skill-based mode, only users who have demonstrated a certain skill or level of experience can be allowed to manipulate the UAV. In some instances, a single mode can be provided for user authentication. In other instances, a user can switch between modes of user operation. For example, an owner of a UAV can switch the authentication mode in which the UAV is to be operated. In some instances, other factors such as the location of the UAV, air traffic flow levels, environmental conditions, etc. can determine the authentication mode in which the UAV is to be operated. For example, if the environmental conditions are windy or otherwise difficult to fly, the UAV can automatically only allow authorized users in a skill mode to manipulate the UAV.

[0232] When an unauthorized user operates the UAV, the user can not be allowed to operate the UAV 840. In some instances, this can result in the UAV not responding to commands from the user and / or the user's remote controller. The user can not be able to cause the UAV to fly or control the flight of the UAV. The user can not be able to control any other components of the UAV such as a payload, a carrier, a sensor, a communication unit, a navigation unit, or a power unit. The user can or can not be able to power on the UAV. In some instances, the user can power on the UAV, but the UAV does not respond to the user. If the user is unauthorized, the UAV can optionally power off by itself. In some instances, the user can be provided with a warning or message that he or she is not authorized to operate the UAV. The reason the user is not authorized can or can not be provided. Optionally, a second user can be provided with a warning or message that the user is not authorized to operate the UAV or that the user has attempted to operate the UAV. The second user can be the owner or operator of the UAV. The second user can be an individual who is authorized to operate the UAV. The second user can be an individual who exercises control over the UAV.

[0233] In some alternative embodiments, when an unauthorized user operates the UAV, the user can only be allowed to operate the UAV in a limited manner. This can include a geographic restriction, a time restriction, a speed restriction, a restriction on the use of one or more additional components (e.g., a payload, a carrier, a sensor, a communication unit, a navigation unit, a power unit, etc.). This can include an operational mode. In one example, when an unauthorized user operates the UAV, the user can not operate the UAV at selected locations. In another example, when an unauthorized user operates the UAV, the user can only operate the UAV at selected locations.

[0234] The user can be able to control flight of the UAV or any other component of the UAV. The user can manually control the UAV through user input via a remote controller of the user. In some instances, the UAV can automatically override user input to comply with a set of flight regulations. The set of flight regulations can be pre-established or can be received in-flight. In some instances, one or more geo-fencing devices can be used in establishing or providing the set of flight regulations.

[0235] Aspects of the disclosure can relate to a method of operating a UAV. The method can include receiving a UAV identifier that uniquely identifies the UAV from other UAVs; receiving a user identifier that uniquely identifies the user from other users; evaluating, by way of one or more processors, whether the user identified by the user identifier is authorized to operate the UAV identified by the UAV identifier; and allowing the user to operate the UAV when the user is authorized to operate the UAV. Similarly, a non-transitory computer-readable medium containing program instructions for operating a UAV can be provided, the computer-readable medium comprising: program instructions for receiving a UAV identifier that uniquely identifies the UAV from other UAVs; program instructions for receiving a user identifier that uniquely identifies the user from other users; program instructions for evaluating whether the user identified by the user identifier is authorized to operate the UAV identified by the UAV identifier; and program instructions for allowing the user to operate the UAV when the user is authorized to operate the UAV.

[0236] Additionally, a UAV authorization system can be provided that includes a first communication module; and one or more processors operatively coupled to the first communication module and individually or collectively configured to receive a UAV identifier that uniquely identifies the UAV from other UAVs; receive a user identifier that uniquely identifies the user from other users; evaluate whether the user identified by the user identifier is authorized to operate the UAV identified by the UAV identifier; and transmit a signal to allow the user to operate the UAV when the user is authorized to operate the UAV. A UAV (UAV) authorization module can include one or more processors individually or collectively configured to receive a UAV identifier that uniquely identifies the UAV from other UAVs; receive a user identifier that uniquely identifies the user from other users; evaluate whether the user identified by the user identifier is authorized to operate the UAV identified by the UAV identifier; and transmit a signal to allow the user to operate the UAV when the user is authorized to operate the UAV.

[0237] The second user can be able to take control of the UAV from the first user. In some cases, both the first user and the second user can be authorized to operate the UAV. Alternatively, only the second user can be authorized to operate the UAV. The first user can be authorized to operate the UAV in a more limited manner than the second user. The second user can be authorized to operate the UAV in a less limited manner than the first user. One or more operational levels can be provided. A higher operational level can indicate a priority in which a user can operate a vehicle. For example, a user at a higher operational level can have priority over a user at a lower operational level in operating a UAV. A user at a higher operational level can be able to take control of a UAV from a user at a lower operational level. In some cases, the second user can be at a higher operational level than the first user. A user at a higher operational level can optionally be authorized to operate a UAV in a less limited manner than a user at a lower operational level. A user at a lower operational level can optionally be authorized to operate a UAV in a more limited manner than a user at a higher operational level. When the second user is authorized to operate the UAV and has a higher operational level than the operational level of the first user, the second user can take over operation of the UAV from the first user.

[0238] The second user can be allowed to operate the UAV when the UAV authenticates the second user's privilege to operate the UAV. The authentication can occur by way of a digital signature and / or digital certificate that verifies the second user's identity. Authentication of the second user and / or the first user can occur using any authentication process as described elsewhere herein.

[0239] In some embodiments, the second user that can take over control can be part of an emergency service. For example, the second user can be part of a law enforcement agency, a fire service, a medical service, or a disaster relief service. The second user can be an electronic police officer. In some cases, the second user can be part of a government agency, such as an agency that can regulate air traffic flow or other types of traffic flow. The second user can be an air traffic control system operator. The user can be a member or administrator of the authentication system. The second user can be a member of a defense force or quasi-defense force. For example, the second user can be a member of the United States Air Force, the United States Coast Guard, the United States National Guard, or any other type of defense force or equivalent organization in any jurisdiction in the world.

[0240] The first user can be notified when the second user takes over control. For example, the first user can be provided with a warning or message. The warning or message can be provided via the first user's remote control. The warning can be a visual display, or can be audible or haptically discernible. In some embodiments, the second user can request to take over control of the UAV from the first user. The first user can choose to accept or deny the request. Alternatively, the second user can be able to take over control without requiring acceptance or permission from the first user. In some embodiments, there can be some lag time between the time the first user is warned about the second user's impending takeover of control and the time the second user takes over control. Alternatively, little or no lag time is provided so that the second user can be able to take over immediately. The second user can be able to take over control within less than 1 minute, 30 seconds, 15 seconds, 10 seconds, 5 seconds, 3 seconds, 2 seconds, 1 second, 0.5 seconds, 0.1 seconds, 0.05 seconds, or 0.01 seconds of attempting to take over control.

[0241] The second user can take over control from the first user in response to any scenario. In some embodiments, the second user can take over control when the UAV enters a restricted area. Control can be returned to the first user when the UAV leaves the restricted area. The second user can operate the UAV while the UAV is within the restricted area. In another case, the second user can be able to take over control of the UAV at any time. In some cases, the second user can be able to control the UAV when a safety or security threat is determined. For example, if it is detected that the UAV is proceeding on a course that will collide with an aircraft, the second user can be able to take over control to avoid the collision of the UAV with the aircraft.

[0242] Authentication

[0243] A user of the UAV can be authenticated. The user can be uniquely identified by means of a user identifier. The user identifier can be authenticated to verify that the user is indeed the user associated with the user identifier. For example, if a user self-identifies using a user identifier associated with Bob Smith, the user can be authenticated to confirm that the user is indeed Bob Smith.

[0244] The UAV can be authenticated. The UAV can be uniquely identified by means of a UAV identifier. The UAV identifier can be authenticated to verify that the UAV is indeed the UAV associated with the UAV identifier. For example, if a UAV self-identifies using a UAV identifier associated with UAV ABCD1234, the UAV can be authenticated to confirm that the UAV is indeed UAV ABCD1234.

[0245] In some cases, a user can be authorized to operate the UAV. One or more individual users can need to be identified before being able to operate the UAV. The identity of the user can need to be authenticated as the individual that the user claims to be in order to allow the user to operate the UAV. The user identity must first be authenticated and confirmed before allowing the user to operate the UAV, the authenticated identity being authorized to operate the UAV.

[0246] Figure 9A process of determining whether to allow a user to operate a UAV is shown in accordance with an embodiment of the application. The process can include authenticating the user 910 and authenticating the UAV 920. If the user fails the authentication process, the user can not be allowed to operate the UAV 940. If the UAV fails the authentication process, the user can not be allowed to operate the UAV 940. A determination can be made as to whether the user is authorized to operate the UAV 930. If the user is not authorized to operate the UAV, the user can not be allowed to operate the UAV 940. If the user passes the authentication process, the user can be allowed to operate the UAV 950. If the UAV passes the authentication process, the user can be allowed to operate the UAV 950. If the user is authorized to operate the UAV, the user can be allowed to operate the UAV 950. In some cases, both the user and the UAV must pass the authentication process before the user is allowed to operate the UAV 950. Alternatively, both the user and the UAV must pass the authentication process and the user must be authorized to operate the UAV before the user is allowed to operate the UAV 950.

[0247] In some cases, permission to operate a UAV can apply in all situations, or can apply only within one or more assigned volumes or areas. For example, a user / UAV can need to pass an authentication to operate the UAV at all. In other cases, a user can generally be able to operate a UAV, but can need to be authenticated to operate the UAV within selected airspace, such as a restricted area.

[0248] One aspect of the disclosure can relate to a method of operating an unmanned aerial vehicle, the method comprising: authenticating an identity of the unmanned aerial vehicle, wherein the identity of the unmanned aerial vehicle is uniquely distinguishable from other unmanned aerial vehicles; authenticating an identity of a user, wherein the identity of the user is uniquely distinguishable from other users; evaluating, with the aid of one or more processors, whether the user is authorized to operate the unmanned aerial vehicle; and allowing the user to operate the unmanned aerial vehicle when the user is authorized to operate the unmanned aerial vehicle and both the unmanned aerial vehicle and the user are authenticated. Similarly, a non-transitory computer-readable medium containing program instructions for operating an unmanned aerial vehicle can be provided, the computer-readable medium comprising: program instructions for authenticating an identity of the unmanned aerial vehicle, wherein the identity of the unmanned aerial vehicle is uniquely distinguishable from other unmanned aerial vehicles; program instructions for authenticating an identity of a user, wherein the identity of the user is uniquely distinguishable from other users; program instructions for evaluating, with the aid of one or more processors, whether the user is authorized to operate the unmanned aerial vehicle; and program instructions for allowing the user to operate the unmanned aerial vehicle when the user is authorized to operate the unmanned aerial vehicle and both the unmanned aerial vehicle and the user are authenticated.

[0249] Moreover, the systems and methods provided herein can include an unmanned aerial vehicle authentication system comprising: a first communication module; and one or more processors operatively coupled to the first communication module and individually or collectively configured to: authenticate an identity of the unmanned aerial vehicle, wherein the identity of the unmanned aerial vehicle is uniquely distinguishable from other unmanned aerial vehicles; authenticate an identity of a user, wherein the identity of the user is uniquely distinguishable from other users; evaluate whether the user is authorized to operate the unmanned aerial vehicle; and transmit a signal to allow the user to operate the unmanned aerial vehicle when the user is authorized to operate the unmanned aerial vehicle and both the unmanned aerial vehicle and the user are authenticated. An unmanned aerial vehicle authentication module can include one or more processors individually or collectively configured to: authenticate an identity of the unmanned aerial vehicle, wherein the identity of the unmanned aerial vehicle is uniquely distinguishable from other unmanned aerial vehicles; authenticate an identity of a user, wherein the identity of the user is uniquely distinguishable from other users; evaluate whether the user is authorized to operate the unmanned aerial vehicle; and transmit a signal to allow the user to operate the unmanned aerial vehicle when the user is authorized to operate the unmanned aerial vehicle and both the unmanned aerial vehicle and the user are authenticated.

[0250] The user identifier and / or the UAV identifier can be aggregated in any manner described elsewhere herein. For example, the UAV can broadcast its identity information on an ongoing basis or at any time necessary during a flight. For example, the UAV can broadcast the user identifier when receiving a monitoring instruction from an air control system (e.g., a police officer) or when the communication between the UAV and the air control system is to be encrypted and authenticated. The broadcast of the identification information can be implemented in various ways (e.g., a radio signal, an optical signal, an acoustic signal, or any other type of direct or indirect communication method as described elsewhere herein).

[0251] The user and / or the UAV can be authenticated using any technique known in the art or later developed. Further details and examples of user and / or UAV authentication are provided elsewhere herein.

[0252] The UAV

[0253] The UAV can be authenticated by means of a key of the UAV. The UAV can have a unique UAV identifier. The UAV can further be authenticated by means of the UAV identifier. The UAV identifier and the UAV key information can be used in combination to authenticate the UAV. The UAV identifier and / or the UAV key can be provided on-board the UAV. The UAV identifier and / or the key can be part of an identification module of the UAV. The identification module can be part of a flight control unit of the UAV. As described elsewhere herein, the identification module can be inseparable from the flight control unit. The UAV identifier and / or the UAV key can be non-removable from the UAV. The UAV can not be disassociated from the UAV identifier and the UAV key on-board the UAV. In preferred embodiments, the UAV identifier and / or the UAV key can not be cleared or changed.

[0254] Further details of UAV authentication are provided elsewhere herein. Further details of how UAV authentication using the UAV identifier and / or the key can occur are provided in greater detail elsewhere herein.

[0255] According to some embodiments of the present application, the authentication center can not authenticate any unmanned aircraft that does not have an unmanned aircraft identifier and an unmanned aircraft key. If the unmanned aircraft identifier or the unmanned aircraft key is lost, the unmanned aircraft can not successfully access the air control system and can not perform any activities within the flight restricted area. In some cases, the user can not be allowed to fully operate the unmanned aircraft if the unmanned aircraft identity is not authenticated. Alternatively, the user can not be allowed to operate the unmanned aircraft within the restricted airspace, but can be allowed to operate the unmanned aircraft in other areas. Any violation activities of such unmanned aircraft can be stopped and punished.

[0256] In certain specific circumstances, the unmanned aircraft and the user can not be authenticated and can directly start a flight mission. For example, when the unmanned aircraft and the user are unable to establish a communication connection with the authentication center, the user can still be allowed to start the mission. In some cases, if a communication connection is established during the mission, authentication of the user and / or the unmanned aircraft can occur. If the user and / or the unmanned aircraft fails the authentication, a response measure can be taken. For example, the unmanned aircraft lands after a predetermined period of time. In another case, the unmanned aircraft can return to the flight starting point. If the user and / or the unmanned aircraft passes the authentication, the user can be able to continue to operate the unmanned aircraft in an uninterrupted manner. In some cases, even if a communication connection is established during the mission, authentication of the user and / or the unmanned aircraft does not occur.

[0257] If the task has been initiated without authentication, authentication can occur in a later task. Depending on whether authentication is passed, flight response measures can or can not be taken. Alternatively, when authentication can occur, authentication does not occur in a later task. The determination of whether to continue with authentication during a task can be made based on any number of factors. For example, one or more environmental conditions can be considered. For example, environmental climate, topology, population density, air traffic flow or surface traffic flow, environmental complexity, or any other environmental condition can be considered. For example, the unmanned vehicle can be able to determine (e.g., with the aid of GPS and a map) whether it is located in a city or in a suburb, and if it is located in a suburb, authentication can not be necessary. Thus, authentication can be required when there is a higher population density, and can not be required when there is a lower population density. Authentication can be required when the population density exceeds a population density threshold. In another case, authentication can be required when there is a higher air traffic flow density, and can not be required when there is a lower air traffic flow density. Authentication can be required when the air traffic flow density exceeds a threshold. Similarly, authentication can be required when the environmental complexity (e.g., a higher number or density of surrounding objects) is higher, and can not be required when the environmental complexity is lower. Authentication can be required when the environmental complexity exceeds a threshold. Other types of factors, such as geography, time, and any other factors described elsewhere herein, can be considered in the process of determining whether authentication is required.

[0258] When the unmanned vehicle is flown without authentication, its flight capabilities can be limited. The unmanned vehicle can be limited in flight according to a set of flight regulations. The set of flight regulations can include one or more rules that can affect the operation of the unmanned vehicle. In some embodiments, the unmanned vehicle can be limited in flight according to the flight regulations only when it is flown without authentication, otherwise if the unmanned vehicle is authenticated, no set of flight regulations is imposed. Alternatively, during normal operation, the unmanned vehicle can be limited in flight according to a set of flight regulations, and if the unmanned vehicle is not authenticated, an additional set of flight regulations can be imposed. In some embodiments, the unmanned vehicle can be limited in operation according to a set of flight regulations regardless of whether the unmanned vehicle is authenticated, but the set of flight regulations can require different rules based on whether the unmanned vehicle is authenticated. In some cases, the rules can be more restrictive if the unmanned vehicle is not authenticated. Overall, not authenticating the unmanned vehicle can result in less freedom for the operator of the unmanned vehicle to control the unmanned vehicle in terms of any aspect of the unmanned vehicle (e.g., flight, payload operation or positioning, carrier, sensors, communication, navigation, power usage, or any other aspect).

[0259] Examples of types of UAV flight capabilities that can be restricted can include one or more of the following, or can include other types of restrictions on UAVs as described elsewhere herein. For example, the distance that the UAV can fly can be limited, e.g., it must be within the user's line of sight. The height and / or speed of the flight can be limited. Optionally, a device carried by the UAV, such as a camera or other type of payload, can be required to pause operation.

[0260] Different restrictions can be imposed depending on the user's level. For example, for more experienced users, fewer restrictions can be imposed. For example, a user with a higher level of experience or skill can be allowed to perform functions that a novice user can not be allowed to perform. A user with a higher level of experience or skill can be allowed to fly in areas or locations that a novice user can not be allowed to fly. As described elsewhere herein, a set of flight regulations for a UAV can be tailored to the user type and / or UAV type.

[0261] The UAV can communicate with an authentication system. In some examples, the authentication system can have one or more characteristics as described elsewhere herein (e.g., Figure 2 ). The UAV can communicate with an air traffic control system of the authentication system. Any description herein of communication between a UAV and an air traffic control system can apply to any communication between a UAV and any other part of the authentication system. Any description herein of communication between a UAV and an air traffic control system can apply to communication between a UAV and any other external device or system that can contribute to the safety, security, or regulation of UAV flight.

[0262] The UAV can communicate with the air traffic control system in any manner. For example, the UAV can form a direct communication channel with the air traffic control system. Examples of direct communication channels can include a radio connection, WiFi, WiMax, infrared, Bluetooth, or any other type of direct communication. The UAV can form an indirect communication channel with the air traffic control system. The communication can be relayed via one or more intermediary devices. In one example, the communication can be relayed via the user and / or a user device, such as a remote control. Alternatively or additionally, the communication can be relayed via a single or multiple other UAVs. The communication can be relayed via a ground station, router, tower, or satellite. The UAV can communicate using a single method or multiple methods as described herein. Any communication mode can be combined. In some cases, different communication modes can be used simultaneously. Alternatively or additionally, the UAV can switch between different communication modes.

[0263] After mutual authentication with the certification center (or any part of the certification system), the UAV (possibly in conjunction with the user) can obtain a secure communication connection with the air control system. A secure communication connection between the UAV and the user can also be obtained. The UAV can communicate directly with the air situation monitoring server of the air control system and / or one or more geo-fencing devices. The UAV can also communicate with the user and can relay, via the user, to the certification center or the air control system. In some embodiments, the direct communication with the air situation monitoring server and / or one or more geo-fencing devices can only occur after authentication of the UAV and / or the user has occurred. Alternatively, the direct communication can occur even if authentication has not occurred. In some embodiments, the communication between the UAV and the user can only occur after authentication of the UAV and / or the user has occurred. Alternatively, the communication between the UAV and the user can occur even if authentication of the UAV and / or the user has not occurred.

[0264] In some embodiments, the air control system can be utilized to pre-register a flight plan for the UAV. For example, the user can be required to specify a planned location and / or flight timing. The air control system can be able to determine whether to allow the UAV to fly according to the flight plan. The flight plan can be precise or can be a rough estimate. During the flight, the UAV can be autonomously controlled or semi-autonomously controlled to fly according to the flight plan. Alternatively, the UAV can have free reign to manually control the UAV, but should remain within the estimate of the flight plan. In some cases, the flight of the UAV can be monitored and if the manual control deviates too far from the suggested flight plan, the UAV can be forced to take a flight response measure. The flight response measure can include forcing the UAV to return to a flight path (e.g., take over flight by a computer or another entity), forcing the UAV to land, forcing the UAV to hover, or forcing the UAV to return to its point of origin. In some cases, the air control system can determine whether to allow the UAV to fly according to the flight plan based on flight plans of other UAVs, currently monitored air situations, environmental conditions, any flight restrictions for the region and / or time, or any other factors. In alternative embodiments, pre-registration of a flight plan can not be required.

[0265] After a secure connection is established, the UAV can apply for resources (e.g., air routes and times of passage or any other resources described elsewhere herein) from the air rights management module of the air control system. The air rights management module can manage air rights. The UAV can accept a set of flight regulations (e.g., distance, altitude, speed, or any other type of flight regulation described elsewhere herein) for the flight. The UAV can only take off if it obtains flight permission. The flight plan can be documented in the air rights management.

[0266] During flight, the UAV can periodically report its status to the air situation monitoring subsystem of the air control system. The status of the UAV can be communicated to the air situation monitoring subsystem using any technique. Direct or indirect communications, such as those described elsewhere herein, can be used. External sensor data can or can not be used in determining the status of the UAV and communicating the status information to the air situation monitoring subsystem. In some examples, the UAV status information can be broadcast, or can be relayed to the air traffic management subsystem by a ground station or other intermediary. The UAV can be under the surveillance of the air traffic management system. The air traffic management subsystem can communicate with the UAV using direct or indirect communication methods, such as those described elsewhere herein. If the scheduled flight is to be modified, the UAV can submit an application to the air traffic management subsystem. The application can be submitted before the UAV begins flight, or can occur after the UAV has begun flight. The application can be made while the UAV is in flight. The air traffic management can have the ability to monitor the flight of the UAV. The air traffic management subsystem can monitor the flight of the UAV based on information from the UAV and / or information from one or more sensors external to the UAV.

[0267] During flight, the UAV can communicate with other devices, including but not limited to other UAVs or geo-fencing devices. During flight, the UAV can also be capable of authentication (including but not limited to digital signature + digital certificate) and / or response (e.g., in response to an authenticated geo-fencing device).

[0268] During flight, the UAV can accept take-over control from a higher-level user, such as the air control system or an electronic police officer, as further detailed elsewhere herein. The higher-level user can take the control if the UAV authenticates the privilege.

[0269] After flight, the UAV can release the resources of the application. The applied resources can also be released if a response to the air traffic management subsystem times out. For example, the resources can be the location and / or timing of the scheduled UAV flight. When the flight ends, the UAV can send a signal to the air traffic management subsystem to release the resources. Alternatively, the air traffic management subsystem can self-initiate the release of the resources. The air traffic management subsystem can self-initiate the release of the resources if the UAV stops communicating with the air traffic management subsystem after a predetermined period of time. In some cases, the air traffic management subsystem can self-initiate the release of the resources if the period of the application ends (e.g., if the UAV is locked out for the period of 3:00-4:00 PM because of a mission, and 4:00 has passed).

[0270] An unmanned aircraft can respond to authentication requests and / or identity query requests. The requests can come from an authentication system. In some cases, the requests can come from a airspace monitoring server. The requests can occur when the unmanned aircraft is powered on. The requests can occur when the unmanned aircraft requests a resource. The requests can come before the unmanned aircraft's flight. Or, the requests can come during the unmanned aircraft's flight. In some embodiments, a secure-capable unmanned aircraft will respond to authentication requests and / or identity query requests from an airspace monitoring server. In some implementations, the response can occur in any situation, which can include authentication failure.

[0271] During a flight, if the unmanned aircraft loses communication with and / or contact with the air control system, the unmanned aircraft can be able to quickly return to a relatively limited rights flight state and quickly return home. Thus, if the unmanned aircraft loses communication with the air control system, a flight response measure can be taken. In some cases, the flight response measure can be to automatically return the unmanned aircraft to the point of origin. The flight response measure can be to automatically fly the unmanned aircraft to the location of the user of the unmanned aircraft. The flight response measure can be to automatically return the unmanned aircraft to a home location, which can or can not be the point of origin of the unmanned aircraft's flight. The flight response measure can be to automatically land. The flight response measure can be to automatically enter an autonomous flight mode, in which the unmanned aircraft flies according to a pre-registered flight plan.

[0272] User

[0273] A user can be a handler of an unmanned aircraft. Users can be ranked according to user type. In one example, users can be ranked according to skill and / or experience level of the user. An authentication system can issue identification information for users. For example, an authentication system can be responsible for issuing certificates to users and assigning corresponding user identifiers and / or user keys. In some cases, an ID registry database can perform one or more functions. For example, an ID registry database can provide user identifiers and / or user keys.

[0274] Users can be authenticated. User authentication can occur using any technique known in the art or later developed. User authentication techniques can be similar to or different from unmanned aircraft authentication techniques.

[0275] In one example, a user can be authenticated based on information provided by the user. A user can be authenticated based on knowledge that the user can have. In some cases, the knowledge can be known only to the user and not to other users. For example, a user can be authenticated by providing a correct username and password. A user can be authenticated by submitting a password, a passcode, a typed or swiped movement, a signature, or any other type of information by the user. A user can be authenticated by correctly responding to one or more inquiries by the system. In some embodiments, a user can apply for a login name and / or password from an authentication center. The user can be able to login using the login name and password.

[0276] A user can be authenticated based on a physical characteristic of the user. A user can be authenticated using biometric information about the unmanned aerial vehicle. For example, a user can be authenticated by submitting biometric information. For example, a user can undergo a fingerprint scan, a palm print scan, an iris scan, a retinal scan, or a scan of any other part of the user's body. A user can provide a body sample, such as saliva, blood, a clipped fingernail, or a clipped hair that can be analyzed to identify the user. In some cases, a DNA analysis of a sample from the user can occur. A user can be authenticated by undergoing facial recognition or gait identification. A user can be authenticated by submitting a voice print. A user can submit a height and / or weight of the user for analysis.

[0277] A user can be authenticated based on a device that can be in possession of the user. A user can be authenticated based on a memory unit that can be in possession of the user and / or information on the memory unit. For example, a user can have a memory device that is issued by an authentication center, other parts of the authentication system, or any other source. The memory device can be an external memory device, such as a U disk (e.g., a USB drive), an external hard drive, or any other type of memory device. In some embodiments, an external device can be coupled to a user remote control. For example, an external device, such as a U disk, can be physically connected to a remote control (e.g., embedded / inserted into the remote control) or can be in communication with the remote control (e.g., transmit a signal that can be received by the remote control). The device can be a physical memory storage device.

[0278] A user can be authenticated based on information that can be stored in a memory that can be in the possession of the user. A separate physical memory device can or can not be used. For example, a token, such as a digital token, can be in the possession of the user. The digital token can be stored on a U-Flash, a hard drive, or other form of memory. The digital token can be stored on a memory of a remote controller. For example, the digital token can be received by the remote controller from an authentication center, an ID registry database, or any other source. In some embodiments, the digital token can not be externally readable from the memory of the remote controller. The digital token can or can not be alterable on the memory of the remote controller.

[0279] A user can be authenticated by means of an identification module that can be provided on the remote controller. The identification module can be associated with the user. The identification module can include a user identifier. In some embodiments, the identification module can include user key information. The data stored in the identification module can or can not be externally readable. The data stored in the identification module can optionally be unalterable. The identification module can optionally be inseparable from the remote controller. The identification can optionally not be removable from the remote controller without damaging the remote controller. The identification module can optionally be integrated in the remote controller. The information in the identification module can be recorded via an authentication center. For example, the authentication center can keep a record of the information from the identification module of the remote controller. In one example, the user identifier and / or the user key can be recorded by the authentication center.

[0280] A user can be authenticated by going through a mutual authentication process. In some cases, the mutual authentication process can be similar to an authentication and key agreement (AKA) process. The user can be authenticated by means of a key on a user terminal used by the user to communicate with the UAV. The terminal can optionally be a remote controller that can send one or more command signals to the UAV. The terminal can be a display device that can show information based on data received from the UAV. Optionally, the key can be part of an identification module of the user terminal and can be integrated into the user terminal. The key can be part of an identification module of the remote controller and can be integrated into the remote controller. The key can be provided by an authentication system, for example, an ID registry database of the authentication system. Further examples and details of the mutual authentication of the user can be provided in more detail elsewhere herein.

[0281] In some embodiments, a user can need to have software or an application to operate the UAV. The software and application itself can be authorized as part of the user authentication process. In one example, a user can have a smartphone app that can be used to operate the UAV. The smartphone app itself can be authorized directly. When the smartphone app used by the user is authenticated, further user authentication can or can not be used. In some cases, the smartphone authorization can be coupled with additional user authentication steps detailed elsewhere herein. In some cases, the smartphone app authorization can be sufficient to authenticate the user.

[0282] A user can be authenticated by way of an authentication system. In some cases, a user can be authenticated by an authentication center of the authentication system (e.g., authentication center 220 as illustrated in FIG. 2) or any other component of the authentication system. Figure 2

[0283] ​User authentication can occur at any point in time. In some embodiments, user authentication can occur automatically when the UAV is turned on. User authentication can occur automatically when the remote controller is turned on. User authentication can occur when the remote controller forms a communication channel with the UAV. User authentication can occur when the remote controller and / or the UAV form a communication channel with the authentication system. User authentication can occur in response to input from the user. For example, user authentication can occur when the user attempts to log in or provide information about the user (e.g., a username, password, biometric information). In another example, user authentication can occur when information from a memory device (e.g., a USB stick) is provided to the authentication system, or when information (e.g., a digital token or key) is provided to the authentication system. The authentication process can thus be initiated from the user or user device. In another example, user authentication can occur when authentication is requested from the authentication system or another external source. The authentication center of the authentication system or an air traffic control system can request authentication of the user. The authentication center or air traffic control system can request authentication from the user one or more times. Authentication can occur before a flight of the UAV and / or during a flight of the UAV. In some cases, the user can be authenticated before a flight mission using the UAV is performed. The user can be authenticated before a flight plan can be approved. The user can be authenticated before the user can exercise control over the UAV. The user can be authenticated before the UAV can be allowed to take off. The user can be authenticated after a connection with the authentication system is lost and / or reestablished. The user can be authenticated when one or more events or conditions are detected (e.g., an unusual UAV flight pattern). The user can be authenticated when a suspicious, unauthorized takeover of the UAV occurs. The user can be authenticated when a suspicious, communication jamming of the UAV occurs. The user can be authenticated when the UAV deviates from an expected flight plan.

[0284] Similarly, UAV authentication can occur at any time, such as the times mentioned above for user authentication. User and UAV authentication can occur substantially simultaneously (e.g., within 5 minutes or less, 4 minutes or less, 3 minutes or less, 2 minutes or less, 1 minute or less, 30 seconds or less, 15 seconds or less, 10 seconds or less, 5 seconds or less, 3 seconds or less, 1 second or less, 0.5 seconds or less, or 0.1 seconds or less of each other). User and UAV authentication can occur in similar conditions or scenarios. Alternatively, they can occur at different times and / or in response to different conditions or scenarios.

[0285] Information about a user can be collected after the user has been authenticated. Information about a user can include any information described elsewhere herein. For example, the information can include a user type. A user type can include a skill and / or experience level of the user. The information can include past flight data of the user.

[0286] authentication center

[0287] An authentication system can be provided in accordance with embodiments of the application. The authentication system can include an authentication center. Any description herein of an authentication center can apply to any component of an authentication system. Any description herein of an authentication system can apply to an external device or entity, or one or more functions of an authentication system can be performed on board a UAV and / or on a remote controller.

[0288] An authentication center can be responsible for maintaining data about one or more users and / or UAVs. Data can include an associated user identifier, an associated user key, an associated UAV identifier, and / or an associated UAV key. An authentication center can receive an identity of a user and / or an identity of a UAV. In some embodiments, an authentication system can be responsible for maintaining all data about one or more users and UAVs. Alternatively, an authentication system can be responsible for maintaining a subset of all data about one or more users and UAVs.

[0289] A controller of a UAV (e.g., a remote controller of a user) and a UAV can make a login request to an air control system. A controller and / or a UAV can make a login request prior to a flight of a UAV. A controller and / or a UAV can make a login request prior to allowing a flight of a UAV. A controller and / or a UAV can make a login request when the controller and / or UAV is turned on. A controller and / or a UAV can make a login request when a connection is established between the controller and the UAV, or when a connection is established between the controller and an external device, or when a connection is established between the UAV and an external device. A controller and / or a UAV can make a login request in response to a detected event or condition. A controller and / or a UAV can make a login request when an instruction for authentication is provided. A controller and / or a UAV can make a login request when an instruction for authentication is provided by an external source (e.g., an authentication center). A controller and / or a UAV can initiate a login request, or can provide a login request in response to an initiation from outside the controller and / or UAV. A controller and / or a UAV can make a login request at a single point in time during a UAV session. Alternatively, a controller and / or a UAV can make a login request at multiple points in time during a UAV session.

[0290] The controller and the UAV can make the login requests substantially simultaneously (e.g., within less than 5 minutes, less than 3 minutes, less than 2 minutes, less than 1 minute, less than 30 seconds, less than 15 seconds, less than 10 seconds, less than 5 seconds, less than 3 seconds, less than 1 second, less than 0.5 seconds, or less than 0.1 seconds of each other). Alternatively, the controller and the UAV can make the login requests at different times. The controller and the UAV can make the login requests based on detection of the same event or condition. For example, the controller and the UAV can both make the login requests when a connection is established between the controller and the UAV. Alternatively, the controller and the UAV can make the login requests based on different events or conditions. Thus, the controller and the UAV can make the login requests independently of each other. For example, the controller can make the login request when the controller is powered on, and the UAV can make the login request when the UAV is powered on. These events can occur at different times from each other.

[0291] Any description of a login request can apply to any type of authentication as described elsewhere herein. For example, any description of a login request can apply to the provision of a username and password. In another example, any description of a login request can apply to the initiation of an AKA protocol. In another example, any description of a login request can include the provision of a user's biometric feature. The login request can be the initiation of an authentication process or a request for authentication.

[0292] After receiving the login request from the user of the UAV and / or the UAV, the authentication system can initiate an authentication process. In some cases, the air control system can receive the login request and can use an authentication center to initiate the authentication process. Alternatively, the authentication center can receive the login request and initiate the authentication process on its own. The login request information can be transmitted to the authentication center, which can authenticate the identity information. In some cases, the login request information can include a username and / or a password. In some embodiments, the login information can include a user identifier, a user key, a UAV identifier, and / or a UAV key.

[0293] The communication connection between the air control system and the authentication center can be secure and reliable. Optionally, the air control system and the authentication center can utilize one or more of the same set of processors and / or memory storage units. Alternatively, they can not utilize the one or more of the same set of processors and / or memory storage units. The air control system and the authentication center can or can not utilize the same set of hardware. The air control system and the authentication center can or can not be provided at the same location. In some cases, a hardwired connection can be provided between the air control system and the authentication center. Alternatively, wireless communication can be provided between the air control system and the authentication center. Direct communication can be provided between the air control system and the authentication center. Alternatively, indirect communication can be provided between the air control system and the authentication center. The communication between the air control system and the authentication center can or can not traverse a network. The communication connection between the air control system and the authentication center can be encrypted.

[0294] After authentication of the user and / or the UAV at the authentication center, a communication connection is established between the UAV and the air control system. In some embodiments, authentication of both the user and the UAV can be requested. Alternatively, authentication of the user or authentication of the UAV can be sufficient. A communication connection can optionally be established between the remote controller and the air control system. Alternatively or additionally, a communication connection can be established between the remote controller and the UAV. Further authentication can or can not occur after a communication connection, such as the connections described herein, has been established.

[0295] The UAV can communicate with the air control system via a direct communication channel. Alternatively, the UAV can communicate with the air control system via an indirect communication channel. The UAV can communicate with the air control system through a UAV operated by the user or a remote controller. The UAV can communicate with the air control system through one or more other UAVs. Any other type of communication, such as those described elsewhere herein, can be provided.

[0296] The remote controller of the user can communicate with the air control system via a direct communication channel. Alternatively, the remote controller can communicate with the air control system via an indirect communication channel. The remote controller can communicate with the air control system through a UAV operated by the user. The remote controller can communicate with the air control system through one or more other UAVs. Any other type of communication, such as those described elsewhere herein, can be provided. In some cases, a communication connection between the remote controller and the air control system need not be provided. In some cases, a communication connection between the remote controller and the UAV can be sufficient. Any type of communication, such as those described elsewhere herein, can be provided between the remote controller and the UAV.

[0297] After authenticating the user and / or the unmanned vehicle, the unmanned vehicle can be allowed to apply for resources to the traffic management module of the air control system. In some embodiments, authentication of the user and the unmanned vehicle can be requested. Alternatively, authentication of the user or authentication of the unmanned vehicle can be sufficient.

[0298] The resources can include air routes and / or times of transit. The resources can be used in accordance with a flight plan. The resources can include one or more of: sensing and avoidance assistance, access to one or more geo-fencing devices, access to a battery station, access to a fuel station, or access to a base station and / or a docking station. Any other resources as described elsewhere herein can be provided.

[0299] The traffic management module of the air control system can record one or more flight plans for the unmanned vehicle. The unmanned vehicle can be allowed to apply for modifications to a scheduled flight of the unmanned vehicle. The unmanned vehicle can be allowed to modify a flight plan for the unmanned vehicle prior to commencing the flight plan. The unmanned vehicle can be allowed to modify the flight plan while the unmanned vehicle is executing the flight plan. The traffic management module can make a determination of whether to allow the requested modification by the unmanned vehicle. If the requested modification by the unmanned vehicle is allowed, the flight plan can be updated to include the requested modification. If the requested modification by the unmanned vehicle is not allowed, the flight plan can not be changed. The unmanned vehicle can be required to adhere to the original flight plan. If the unmanned vehicle deviates significantly from the flight plan (whether original or updated), flight response measures can be imposed on the unmanned vehicle.

[0300] In some embodiments, after authenticating the user and / or the unmanned vehicle at the authentication center, a communication connection can be established between the unmanned vehicle and one or more geo-fencing devices. Further details regarding geo-fencing devices are provided elsewhere herein.

[0301] After authenticating the user and / or the unmanned vehicle at the authentication center, a communication connection can be established between the unmanned vehicle and one or more authenticated intermediary objects. The authenticated intermediary object can be another authenticated unmanned vehicle or an authenticated geo-fencing device. The authenticated intermediary object can be a base station or a station or device that can relay communications. The authenticated intermediary object can undergo any type of authentication process, such as those described elsewhere herein. For example, the authenticated intermediary object can be authenticated using an AKA process.

[0302] A determination of whether a user is authorized to operate the UAV can be made. The determination can be made before authenticating the user and / or the UAV, while authenticating the user and / or the UAV, or after authenticating the user and / or the UAV. If the user is not authorized to operate the UAV, the user can not be allowed to operate the UAV. If the user is not authorized to operate the UAV, the user can only be able to operate the UAV in a limited manner. When the user is not authorized to operate the UAV, the user can only be allowed to operate the UAV at selected locations. One or more flight restrictions, such as those described elsewhere herein, can be imposed on a user that is not authorized to operate the UAV. In some implementations, a set of flight restrictions imposed on a user when the user is not authorized to operate the UAV can be more restrictive or more stringent than restrictions that can be imposed on the user when the user is authorized to operate the UAV. When the user is authorized to operate the UAV, a set of flight restrictions can or can not be imposed on the user. When a user is authorized to operate the UAV, a set of flight restrictions imposed on the user can include a null value. When the user is authorized to operate the UAV, the user can be able to operate the UAV in an unrestricted manner. Alternatively, some restrictions can be imposed, but these restrictions can not be as stringent or can be different than restrictions that can be imposed on the user when the user is not authorized to operate the UAV.

[0303] A set of flight restrictions can depend on the identity of the UAV and / or the identity of the user. In some cases, the set of flight restrictions can be changed depending on the identity of the UAV and / or the identity of the user. Restrictions on flight of the UAV can be adjusted or maintained based on the identity of the UAV. Restrictions on flight of the UAV can be adjusted or maintained based on the identity of the user. In some implementations, a default set of restrictions on flight of the UAV can be provided. The default value can be in place prior to authenticating and / or identifying the UAV. The default value can be in place prior to authenticating and / or identifying the user. The default value can be maintained or adjusted depending on the authenticated identity of the user and / or the UAV. In some cases, the default value can be adjusted to a less restrictive set of flight restrictions. In other cases, the default value can be adjusted to a more restrictive set of flight restrictions.

[0304] In some embodiments, a user can be authorized to operate a UAV if the user and / or the UAV are identified and authenticated. In some cases, a user can not be authorized to operate a UAV even if the user and / or the UAV are identified and authenticated. Whether a user is authorized to operate a UAV can be independent of whether the user and / or the UAV are authenticated. In some cases, identification and / or authentication can occur prior to determining whether a user is authorized, such that the user and / or the UAV are confirmed prior to determining whether the user is authorized to operate the UAV.

[0305] In some cases, only a single user can be authorized to operate a UAV. Alternatively, multiple users can be authorized to operate a UAV.

[0306] A UAV can be authenticated prior to allowing the UAV to take off. A user can be authenticated prior to allowing the UAV to take off. A user can be authenticated prior to allowing the user to exercise control over a UAV. A user can be authenticated prior to allowing the user to send one or more operational commands to a UAV via a user remote controller.

[0307] Degree of authentication

[0308] Different degrees of authentication can occur. In some cases, different authentication processes, such as those described elsewhere herein, can occur. In some cases, a higher degree of authentication can occur, while in other cases, a lower degree of authentication can occur. In some embodiments, a determination can be made as to the degree or type of authentication process to undergo.

[0309] One aspect of the disclosure provides a method of determining a level of authentication for operation of an unmanned aerial vehicle (UAV), the method comprising: receiving situational information about the UAV; using one or more processors, assessing a degree of authentication of the UAV or a user of the UAV based on the situational information; implementing authentication of the UAV or the user according to the degree of authentication; and allowing the user to operate the UAV when the degree of authentication is complete. Similarly, a non-transitory computer readable medium containing program instructions for determining a level of authentication for operation of an unmanned aerial vehicle (UAV) can be provided, the computer readable medium comprising: program instructions for receiving situational information about the UAV; program instructions for assessing a degree of authentication of the UAV or a user of the UAV based on the situational information; program instructions for implementing authentication of the UAV or the user according to the degree of authentication; and program instructions for providing a signal allowing the user to operate the UAV when the degree of authentication is complete.

[0310] An unmanned aerial vehicle (UAV) authentication system may include: a communication module; and one or more processors operatively coupled to the communication module and configured individually or jointly to: receive context information about the UAV; assess the level of authentication for the UAV or its user based on the context information; and authenticate the UAV or its user according to the level of authentication. An UAV authentication module may also be provided, comprising: one or more processors configured individually or jointly to: receive context information about the UAV; assess the level of authentication for the UAV or its user based on the context information; and authenticate the UAV or its user according to the level of authentication.

[0311] The level of authentication for users and / or unmanned aerial vehicles (UAVs) can be provided. In some cases, the level of authentication for users can be variable. Alternatively, the level of authentication for users can be fixed. The level of authentication for UAVs can be variable. Alternatively, the level of authentication for UAVs can be fixed. In some implementations, both the level of authentication for users and UAVs can be variable. Optionally, both the level of authentication for users and UAVs can be fixed. Alternatively, the level of authentication for users can be variable while the level of authentication for UAVs can be fixed, or the level of authentication for users can be fixed while the level of authentication for UAVs can be variable.

[0312] The level of authentication can include any authentication that does not require the user and / or the drone. For example, the level of authentication can be zero. Therefore, the level of authentication can include no authentication of the drone or the user. The level of authentication can include authentication of both the drone and the user. The level of authentication can include authenticating the drone without authenticating the user, or it can include authenticating the user without authenticating the drone.

[0313] The level of authentication can be selected from a plurality of options for a level of authentication for the unmanned aerial vehicle and / or the user. For example, three options for a level of authentication for the unmanned aerial vehicle and / or the user can be provided (e.g., a high level of authentication, a medium level of authentication, or a low level of authentication). Any number of options for a level of authentication can be provided (e.g., 2 or more, 3 or more, 4 or more, 5 or more, 6 or more, 7 or more, 8 or more, 9 or more, 10 or more, 12 or more, 15 or more, 20 or more, 25 or more options). In some instances, a level of authentication can be generated and / or determined without selection from one or more predetermined options. The level of authentication can be generated in flight.

[0314] A higher level of authentication can provide a higher level of certainty that the user is the identified user or the unmanned aerial vehicle is the identified unmanned aerial vehicle than a lower level of authentication. A higher level of authentication can provide a higher level of certainty that the user identifier matches the actual user and / or the unmanned aerial vehicle identifier matches the actual unmanned aerial vehicle than a lower level of authentication. A higher level of authentication can be a more rigorous authentication process than a lower level of authentication. A higher level of authentication can include the authentication process of a lower level of authentication plus additional authentication processes. For example, a lower level of authentication can include only a username / password combination, while a higher level of authentication can include a username / password combination plus an AKA authentication process. Optionally, a higher level of authentication can consume more resources or computational power. Optionally, a higher level of authentication can consume a greater amount of time.

[0315] Any description herein of a level of authentication can apply to a type of authentication. For example, the type of authentication can be selected from a plurality of different options. The type of authentication can or can not indicate a higher level of authentication. Different types of authentication processes can be selected based on situational information. For example, based on situational information, a username / password combination can be used for authentication, or biometric data can be used for authentication. Based on situational information, an AKA authentication process plus biometric data authentication can occur, or a username / password plus biometric sample data authentication can occur. Any description herein of selecting a level of authentication can also apply to selecting a type of authentication.

[0316] Scenario information can be used to assess the degree of authentication. Scenario information can include information about the user, the UAV, the remote controller, the geo-fencing device, environmental conditions, geographic conditions, timing conditions, communication or network conditions, mission risk (e.g., risk of attempted takeover or interference), or any other type of information that can be relevant to the mission. Scenario information can include information provided by the user, the remote controller, the UAV, the geo-fencing device, the authentication system, external devices (e.g., external sensors, external data sources), or any other device.

[0317] In one example, scenario information can include environmental conditions. For example, scenario information can include the environment in which the UAV is to be operated. The environment can be an environment type, such as a rural area, a suburban area, or an urban area. A higher degree of authentication can be required when the UAV is located in an urban area than when the UAV is located in a rural area. A higher degree of authentication can be required when the UAV is located in a suburban area than when the UAV is located in a rural area. A higher degree of authentication can be required when the UAV is located in a suburban area than when the UAV is located in an urban area.

[0318] Environmental conditions can include a population density of the environment. A higher degree of authentication can be required when the UAV is located in an environment having a higher population density than when the UAV is located in an environment having a lower population density. A higher degree of authentication can be required when the UAV is located in an environment having a population density that meets or exceeds a population threshold, while a lower degree of authentication can be required when the UAV is located in an environment having a population density that does not exceed or is below a population threshold. Any number of population thresholds can be provided, which can be used to determine the degree of authentication. For example, three population thresholds can be provided, where an increasing degree of authentication can be required as each threshold is met and / or exceeded.

[0319] Environmental conditions can include a degree of traffic flow within the environment. Traffic flow can include aerial traffic flow and / or surface-based traffic flow. Surface-based traffic flow can include ground vehicles and / or water vehicles in the environment. A higher degree of authentication can be required when the UAV is located in an environment having a higher degree of traffic flow than when the UAV is located in an environment having a lower degree of traffic flow. A higher degree of authentication can be required when the UAV is located in an environment having a degree of traffic flow that meets or exceeds a traffic flow threshold, while a lower degree of authentication can be required when the UAV is located in an environment having a degree of traffic flow that does not exceed or is below a traffic flow threshold. Any number of traffic flow thresholds can be provided, which can be used to determine the degree of authentication. For example, five traffic flow thresholds can be provided, where an increasing degree of authentication can be required as each threshold is met and / or exceeded.

[0320] The environmental conditions can include an environmental complexity of the environment. The environmental complexity can indicate obstacles and / or potential safety hazards within the environment. An environmental complexity factor can be used to represent the degree to which obstacles occupy the environment. The environmental complexity factor can be a quantitative or qualitative measure. In some embodiments, the environmental complexity factor can be determined based on one or more of: a number of obstacles, a volume or percentage of space occupied by obstacles, a volume or percentage of space within a certain distance of the UAV that is occupied by obstacles, a volume or percentage of space that is unobstructed by obstacles, a volume or percentage of space within a certain distance of the UAV that is unobstructed by obstacles, a distance of obstacles from the UAV, a density of obstacles (e.g., number of obstacles per unit of space), a type of obstacles (e.g., stationary or moving), a spatial arrangement of obstacles (e.g., position, orientation), a motion of obstacles (e.g., velocity, acceleration), etc. For example, an environment with a relatively high density of obstacles would be associated with a high environmental complexity factor (e.g., indoor environment, urban environment), while an environment with a relatively low density of obstacles would be associated with a low environmental complexity factor (e.g., high altitude environment). For another example, an environment in which obstacles occupy a large percentage of the space would have a higher complexity, while an environment with a large percentage of unobstructed space would have a lower complexity. The environmental complexity factor can then be calculated based on the generated environmental representation. The environmental complexity factor can be determined based on a three-dimensional digital representation of the environment generated using sensor data. The three-dimensional digital representation can include a three-dimensional point cloud or an occupancy grid. A higher degree of authentication can be required when the UAV is in an environment with a higher environmental complexity than when the UAV is in an environment with a lower environmental complexity. A higher degree of authentication can be required when the UAV is in an environment with an environmental complexity that meets or exceeds an environmental complexity threshold, while a lower degree of authentication can be required when the UAV is in an environment with an environmental complexity that does not exceed or is below an environmental complexity threshold. Any number of environmental complexity thresholds can be provided, which can be used to determine the degree of authentication. For example, two environmental complexity thresholds can be provided, where an increased degree of authentication can be required when each threshold is met and / or exceeded.

[0321] The environmental conditions can include environmental weather conditions. Examples of weather conditions can include, but are not limited to, temperature, precipitation, wind speed or wind direction, or any other weather condition. A higher degree of authentication can be required when the UAV is located in an environment having more extreme or potentially harmful weather conditions than when the UAV is located in an environment having less extreme or harmful weather conditions. A higher degree of authentication can be required when the UAV is located in an environment that reaches or exceeds a weather threshold, while a lower degree of authentication can be required when the UAV is located in an environment that does not exceed or is below a weather threshold. Any number of weather thresholds can be provided, which can be used to determine the degree of authentication. For example, multiple weather thresholds can be provided, where an increasing degree of authentication can be required when each threshold is reached and / or exceeded.

[0322] The situational information can include geographic information. For example, the situational information can include a location of the UAV. The situational information can include geographic flight restrictions for the location of the UAV. Some locations can be classified as sensitive locations. In some examples, the locations can include airports, schools, campuses, hospitals, military zones, secure zones, research facilities, jurisdictional landmarks, power plants, private residences, shopping centers, gathering places, any other type of location. In some cases, the locations can be categorized into one or more categories that can indicate a level of "sensitivity" of the location. A higher degree of authentication can be required when the UAV is located at a location having a higher sensitivity than when the UAV is located at a location having a lower sensitivity. For example, a higher degree of authentication can be required when the UAV is located at a secure military facility than when the user is located at a shopping center. A higher degree of authentication can be required when the UAV is located at a location having a sensitivity that reaches or exceeds a location sensitivity threshold, while a lower degree of authentication can be required when the UAV is located at a location having a sensitivity that does not exceed or is below a location sensitivity threshold. Any number of location sensitivity thresholds can be provided, which can be used to determine the degree of authentication. For example, multiple location sensitivity thresholds can be provided, where an increasing degree of authentication can be required when each threshold is reached and / or exceeded.

[0323] Context information can include time-based information. Time-based information can include a time of day, a day of the week, a date, a month, a quarter, a season, a year, or any other time-based information. A higher degree of authentication can be required for these time periods than for other time periods. For example, a higher degree of authentication can be required on a day of the week with a higher historical traffic volume. A higher degree of authentication can be required for a time of day with a higher historical traffic volume or accidents. A higher degree of authentication can be required for a season with more extreme environmental conditions. A higher degree of authentication can be required when the time is within one or more specified time ranges. Any number of specified time ranges can be provided, which can be used to determine the degree of authentication. For example, ten time ranges can be provided, and for each time range, a different degree or type of authentication is required. In some cases, multiple types of time ranges can be weighted simultaneously in determining the degree of authentication. For example, a time of day and a day of the week can be considered and weighted to determine the degree of authentication.

[0324] Context information can include information about the user. Context information can include the identity of the user. The identity of the user can indicate a user type. Context information can include the user type. Examples of user types can include the skill level and / or experience of the user. Any other user information as described elsewhere herein can be used as context information. A higher degree of authentication can be required when the user has less skill or experience than when the user has more skill or experience. A higher degree of authentication can be required when the user has a skill or experience level that meets or exceeds a skill or experience threshold, and a lower degree of authentication can be required when the user has a skill or experience level that is below or equal to the skill or experience threshold. Any number of skill or experience thresholds can be provided, which can be used to determine the degree of authentication. For example, three skill or experience thresholds can be provided, where a decreasing degree of authentication can be required as each threshold is met and / or exceeded.

[0325] The situational information can include information about the UAV. The situational information can include an identity of the UAV. The identity of the UAV can indicate a UAV type. The situational information can include the UAV type. An example of the UAV type can include a model of the UAV. Any other UAV information as described elsewhere herein can be used as situational information. A higher degree of authentication can be required when the UAV model is a more complex or more difficult to operate model than when the UAV model is a simpler or easier to operate model. A higher degree of authentication can be required when the complexity or difficulty of the UAV model meets or exceeds a complexity or difficulty threshold, and a lower degree of authentication can be required when the complexity or difficulty of the UAV model is below or equal to the complexity or difficulty threshold. Any number of complexity or difficulty thresholds can be provided, which can be used to determine the degree of authentication. For example, four complexity or difficulty thresholds can be provided, where an increasing degree of authentication can be required when each threshold is met and / or exceeded.

[0326] The situational information can include a complexity of a task to be performed by the UAV. The UAV can perform one or more tasks during a mission. A task can include flying along a flight path. A task can include collecting information about the UAV's environment. A task can include transmitting data from the UAV. A task can include picking up, carrying, and / or placing a payload. A task can include managing power on the UAV. A task can include monitoring or photographing a mission. In some cases, a task can be more complex when more computing or processing resources on the UAV are used in the course of completing the task. In one example, a task of detecting a moving target and following the moving target with the UAV can be more complex than a task of playing a pre-recorded music from a speaker of the UAV. A higher degree of authentication can be required when the UAV task is more complex than when the UAV task is simpler. A higher degree of authentication can be required when the complexity of the UAV task meets or exceeds a task complexity threshold, and a lower degree of authentication can be required when the complexity of the UAV task is below or equal to the task complexity threshold. Any number of task complexity thresholds can be provided, which can be used to determine the degree of authentication. For example, multiple task complexity thresholds can be provided, where an increasing degree of authentication can be required when each threshold is met and / or exceeded.

[0327] The situational information can include information about surrounding communication systems. For example, the presence or absence of wireless signals in the environment can be an example of situational information. In some cases, the likelihood of an impact to one or more surrounding wireless signals can be provided as situational information. The number of wireless signals in the environment can or can not affect the likelihood of an impact to one or more surrounding wireless signals. If a greater number of signals are provided, there can be a higher likelihood that at least one of them can be impacted. The security level of wireless signals in the environment can or can not affect the likelihood of an impact to one or more surrounding wireless signals. For example, the more wireless signals that have some safeguards, the less likely they will be impacted. A higher degree of authentication can be required when the likelihood of an impact to one or more surrounding wireless signals is high than when the likelihood of an impact to one or more surrounding wireless signals is low. A higher degree of authentication can be required when the likelihood of an impact to one or more surrounding wireless signals meets or exceeds a communication threshold than when the likelihood of an impact to one or more surrounding wireless signals is below or equal to a communication threshold. Any number of communication thresholds can be provided, which can be used to determine the degree of authentication. For example, multiple communication thresholds can be provided, where an increasing degree of authentication can be required when each threshold is met and / or exceeded.

[0328] The risk of interfering with the operation of the unmanned aerial vehicle can be an example of situational information. The situational information can include information about the risk of hacking / jacking of the unmanned aerial vehicle. Another user can attempt to take control of the unmanned aerial vehicle in an unauthorized manner. A higher degree of authentication can be required when there is a higher risk of hacking / jacking than when the risk of hacking / jacking is lower. A higher degree of authentication can be required when the risk of hacking / jacking meets or exceeds a risk threshold than when the risk of hacking / jacking is below or equal to a risk threshold. Any number of risk thresholds can be provided, which can be used to determine the degree of authentication. For example, multiple risk thresholds can be provided, where an increasing degree of authentication can be required when each threshold is met and / or exceeded.

[0329] The situational information can include information about the risk of interfering with the communication of the unmanned aircraft. For example, another unauthorized user can interfere with the communication of the authorized user with the unmanned aircraft in an unauthorized manner. The unauthorized user can interfere with the commands of the authorized user to the unmanned aircraft, which can affect the control of the unmanned aircraft. The unauthorized user can interfere with the data sent from the unmanned aircraft to the device of the authorized user. A higher degree of authentication can be required when there is a higher risk of interfering with the communication of the unmanned aircraft than when there is a lower risk of interfering with the communication of the unmanned aircraft. A higher degree of authentication can be required when the risk of interfering with the communication of the unmanned aircraft reaches or exceeds a risk threshold, and a lower degree of authentication can be required when the risk of interfering with the communication of the unmanned aircraft is below or equal to the risk threshold. Any number of risk thresholds can be provided, which can be used to determine the degree of authentication. For example, multiple risk thresholds can be provided, where an increasing degree of authentication can be required when each threshold is reached and / or exceeded.

[0330] The situational information can include information about one or more sets of flight regulations. The situational information can include information about the degree of flight restrictions in the area. This can be based on current flight restrictions or historical flight restrictions. The flight restrictions can be imposed by a controlling entity. A higher degree of authentication can be required when there is a higher degree of flight restrictions in the area than when there is a lower degree of flight restrictions in the area. A higher degree of authentication can be required when the degree of flight restrictions in the area reaches or exceeds a restriction threshold, and a lower degree of authentication can be required when the degree of flight restrictions in the area is below or equal to the restriction threshold. Any number of restriction thresholds can be provided, which can be used to determine the degree of authentication. For example, multiple restriction thresholds can be provided, where an increasing degree of authentication can be required when each threshold is reached and / or exceeded.

[0331] Any type of situational information can be used, either individually or in combination, in determining the degree of authentication for the user and / or the unmanned aircraft. The type of situational information used can remain the same at all times or can change. When multiple types of situational information are evaluated, they can be evaluated substantially simultaneously to arrive at a determination of the degree of authentication. The multiple types of situational information can be considered to be the same factor. Alternatively, the multiple types of situational information can be given a weight and need not necessarily be the same factor. The type of situational information with a greater weight can have a greater impact on the determined degree of authentication.

[0332] The determination of the level of authentication can be made on-board the UAV. The UAV can receive and / or generate the situational information used. One or more processors of the UAV can receive the situational information from an external data source (e.g., an authentication system) or a data source on-board the UAV (e.g., a sensor, a clock). In some embodiments, the one or more processors can receive information from an air traffic control system external to the UAV. The information from the air traffic control system can be evaluated to determine the level of authentication. The information from the air traffic control system can be situational information or can be in addition to the types of situational information described elsewhere herein. The one or more processors can use the received situational information to make the determination.

[0333] The determination of the level of authentication can be made external to the UAV. For example, the determination can be made by an authentication system. In some cases, an air traffic control system or authentication center external to the UAV can make the determination regarding the level of authentication. One or more processors of the authentication system can receive the situational information from an external data source (e.g., a UAV, an external sensor, a remote controller) or a data source on the authentication system (e.g., a clock, information about other UAVs). In some embodiments, the one or more processors can receive information from a UAV, a remote controller, a remote sensor, or other external device external to the authentication system. The one or more processors can use the received situational information to make the determination.

[0334] In another case, the determination can be made on a remote controller of the user. The remote controller can receive and / or generate the situational information used. One or more processors of the remote controller can receive the situational information from an external data source (e.g., an authentication system) or a data source on the remote controller (e.g., a memory, a clock). In some embodiments, the one or more processors can receive information from an air traffic control system external to the remote controller. The information from the air traffic control system can be evaluated to determine the level of authentication. The information from the air traffic control system can be situational information or can be in addition to the types of situational information described elsewhere herein. The one or more processors can use the received situational information to make the determination.

[0335] In making the determination of the level of authentication based on situational information, any other external device can be used. A single external device can be used or multiple external devices can be used in conjunction. The other external device can receive situational information from a source external to the vehicle or from a source on-board the vehicle. The other external device can include one or more processors that can use the received situational information to make the determination.

[0336] Figure 10A diagram showing flight regulation levels that can be affected by a level of authentication according to embodiments of the application is shown. A set of flight regulations that can affect operation of an unmanned aerial vehicle can be generated. The set of flight regulations can be generated based on a level of authentication. The set of flight regulations can be generated based on a level of authentication that is completed. Whether or not authentication was successfully passed can be considered. The level of authentication can apply to any portion of the system, such as unmanned aerial vehicle authentication, user authentication, remote controller authentication, geofencing device authentication, and / or any other type of authentication.

[0337] In some embodiments, as the level of authentication 1010 increases, the flight regulation level 1020 can decrease. If a higher level of authentication has been established, less concern and need for restrictions on flight can be imposed. The level of authentication and the flight regulation level can be inversely proportional. The level of authentication and the flight regulation level can be linearly proportional (e.g., linearly inversely proportional). The level of authentication and the flight regulation level can be exponentially proportional (e.g., exponentially inversely proportional). Any other inverse relationship between the level of authentication and the flight regulation level can be provided. In alternative embodiments, the relationship can be directly proportional. The relationship can be directly linearly proportional, directly exponentially proportional, or any other relationship. The flight regulation level can depend on the level of authentication that is performed. In alternative embodiments, the flight regulation level can be independent of the level of authentication. The flight regulation level can or can not be selected with respect to the level of authentication. A more restrictive set of flight regulations can be generated when the level of authentication is lower. A less restrictive set of flight regulations can be generated when the level of authentication is higher. The set of flight regulations can or can not be generated based on the level of authentication.

[0338] One aspect of the application relates to a method of determining a flight regulation level for operation of an unmanned aerial vehicle, the method comprising: evaluating, using one or more processors, a level of authentication of the unmanned aerial vehicle or a user of the unmanned aerial vehicle; implementing authentication of the unmanned aerial vehicle or the user according to the level of authentication; generating a set of flight regulations based on the level of authentication; and implementing operation of the unmanned aerial vehicle according to the set of flight regulations. Similarly, embodiments of the application can relate to a non-transitory computer readable medium containing program instructions for determining a flight regulation level for an unmanned aerial vehicle, the computer readable medium comprising: program instructions for evaluating a level of authentication of an unmanned aerial vehicle or a user of the unmanned aerial vehicle; program instructions for implementing authentication of the unmanned aerial vehicle or the user according to the level of authentication; program instructions for generating a set of flight regulations based on the level of authentication; and program instructions for providing a signal that allows implementation of operation of the unmanned aerial vehicle according to the set of flight regulations.

[0339] An unmanned aircraft authentication system can be provided, comprising: a communication module; and one or more processors operatively coupled to the communication module and individually or collectively configured for: assessing a degree of authentication for the unmanned aircraft or a user of the unmanned aircraft; effecting authentication of the unmanned aircraft or the user in accordance with the degree of authentication; and generating a set of flight regulations based on the degree of authentication. An unmanned aircraft authentication module can comprise: one or more processors individually or collectively configured for: assessing a degree of authentication for the unmanned aircraft or a user of the unmanned aircraft; effecting authentication of the unmanned aircraft or the user in accordance with the degree of authentication; and generating a set of flight regulations based on the degree of authentication.

[0340] As described elsewhere herein, the degree of authentication can include no authentication of the user and / or the unmanned aircraft. For example, the degree of authentication can be zero. Thus, the degree of authentication can include no authentication of the unmanned aircraft or the user. The degree of authentication can include authentication of both the unmanned aircraft and the user. The degree of authentication can include authentication of the unmanned aircraft without authentication of the user, or can include authentication of the user without authentication of the unmanned aircraft.

[0341] The degree of authentication can be selected from a plurality of options for the degree of authentication of the unmanned aircraft and / or the user. For example, three options for the degree of authentication of the unmanned aircraft and / or the user can be provided (e.g., high degree of authentication, medium degree of authentication, or low degree of authentication). Any number of options for the degree of authentication can be provided (e.g., 2 or more, 3 or more, 4 or more, 5 or more, 6 or more, 7 or more, 8 or more, 9 or more, 10 or more, 12 or more, 15 or more, 20 or more, 25 or more options). In some cases, the degree of authentication can be generated and / or determined without selection from one or more predetermined options. The degree of authentication can be generated in flight. The unmanned aircraft and / or the user can be authenticated in accordance with the degree of authentication. The unmanned aircraft and / or the user can be considered authenticated if / when they pass an authentication process. The unmanned aircraft and / or the user can be considered unauthenticated if they undergo but do not pass an authentication process. For example, an identifier / key mismatch can be an example of a failure to pass authentication. Biometric data provided that does not match biometric data regarding a file can be another example of a failure to pass authentication. Providing an incorrect login username / password combination can be an additional example of a failure to pass an authentication process.

[0342] The information about the extent of authentication can include a level or a type of authentication that has occurred. The level or type can be qualitative and / or quantitative. The information about the extent of authentication can include one or more types of authentication that have occurred. The information about the extent of authentication can include data collected during authentication (e.g., if authentication includes processing biological data, the biological data itself can be provided).

[0343] A set of flight regulations can be generated based on the extent of authentication. Any description of the extent of authentication herein can also apply to the type of authentication. The set of flight regulations can be generated according to any of the techniques as described elsewhere herein. For example, the set of flight regulations is generated by selecting a set of flight regulations from a plurality of sets of flight regulations. In another example, the set of flight regulations can be generated from scratch. The set of flight regulations can be generated with the aid of input from a user.

[0344] The set of flight regulations can be generated with the aid of one or more processors. The generation of the set of flight regulations can occur on board the UAV. The extent of authentication used can be received and / or generated by the UAV. The one or more processors of the UAV can receive information about the extent of authentication from an external data source or a data source on board the UAV. In some embodiments, the one or more processors can receive information from an air control system external to the UAV. The information from the air control system can be evaluated to generate the set of flight regulations. The one or more processors can use the received information about the extent of authentication to make a determination.

[0345] The generation of the set of flight regulations can occur external to the UAV. For example, the generation of the set of flight regulations can be implemented by an authentication system. In some cases, an air control system or authentication center external to the UAV can generate a set of flight regulations. The one or more processors of the authentication system can receive information about the extent of authentication from an external data source or a data source on the authentication system. In some embodiments, the one or more processors can receive information from a UAV, a remote controller, a remote sensor, or other external device external to the authentication system. The one or more processors can use the received information about the extent of authentication to make a determination.

[0346] In another case, the generation of the set of flight regulations can occur on a remote controller of a user. The extent of authentication used can be received and / or generated by the remote controller. The one or more processors of the remote controller can receive information about the extent of authentication from an external data source or a data source on the remote controller. In some embodiments, the one or more processors can receive information from an air control system external to the remote controller. The information from the air control system can be evaluated to generate the set of flight regulations. The one or more processors can use the information about the extent of authentication to make a determination.

[0347] Any other external device can be used in generating the set of flight regulations based on the authentication level. A single external device can be used or multiple external devices can be used in conjunction. The other external device can receive situational information regarding the authentication level from an off-board source or an on-board source. The other external device can include one or more processors that can use the received information regarding the authentication level to make a determination.

[0348] The UAV can be operated in accordance with the set of flight regulations. A user of the UAV can issue one or more commands to effect operation of the UAV. The commands can be issued by way of a remote controller. The operation of the UAV can be effected in compliance with the set of flight regulations. If the one or more commands do not comply with the set of flight regulations, the commands can be overridden so that the UAV remains in compliance with the set of flight regulations. When the commands comply with the set of flight regulations, the commands need not be overridden and can be able to effect control of the UAV without interference.

[0349] Device identification storage

[0350] Figure 11 An example of device information that can be stored in memory according to embodiments of the application is shown. A memory storage system 1110 can be provided. Information from one or more users 1115a, 1115b, one or more user terminals 1120a, 1120b, and / or one or more UAVs 1130a, 1130b can be provided. The information can include one or more commands, associated user identifiers, associated UAV identifiers, associated timing information, and any other associated information. One or more sets of information 1140 can be stored.

[0351] The memory storage system 1110 can include one or more memory storage units. The memory storage system can include one or more databases that can store information described herein. The memory storage system can include computer-readable media. One or more electronic storage units, such as a memory (e.g., read-only memory, random-access memory, flash memory) or a hard disk, can be provided. "Storage" class media can include any or all of the tangible memory of or in a computer, processor, etc., or associated modules, such as various semiconductor memories, tape, magnetic disk storage and the like, which can provide non-transitory storage of software programming at any time. In some embodiments, nonvolatile storage media includes, for example, optical or magnetic disks, such as any of the storage devices in any computer(s) or the like, such as can be used to implement a database, etc. Volatile storage media includes dynamic memory, such as the main memory of such a computer platform. Tangible transmission media include coaxial cables, copper wire and fiber optics, including the wires that comprise a bus within a computer system. Carrier-wave transmission media can take the form of electric or electromagnetic signals, or acoustic or light waves such as those generated during radio frequency (RF) and infrared (IR) data communications. Common forms of computer-readable media therefore include, for example: floppy disk, flexible disk, hard disk, magnetic tape, any other magnetic medium, CD-ROM, DVD or DVD-ROM, any other optical medium, punch cards, paper tape, any other physical storage medium that can be used to store desired program code means in the form of individual or groups of instructions, RAM, ROM, PROM and EPROM, FLASH-EPROM, any other memory chip or cartridge, a carrier wave transporting data or instructions, cables or links transporting such a carrier wave, or any other medium from which desired program code means can be derived. A variety of

[0352] The memory storage system can be provided at a single location, or can be distributed across multiple locations. In some embodiments, the memory storage system can include a single memory storage unit or multiple memory storage units. A cloud computer infrastructure can be provided. In some cases, a peer-to-peer (P2P) memory storage system can be provided.

[0353] The memory storage system can be provided outside of the UAV. The memory storage system can be provided on a device external to the UAV. The memory storage system can be provided outside of the remote controller. The memory storage system can be provided on a device external to the remote controller. The memory storage system can be provided outside of the UAV and the remote controller. The memory storage system can be part of an authentication system. The memory storage system can be part of an air control system. The memory storage system can include one or more memory units, which can be one or more memory units of an authentication system, such as an air control system. Alternatively, the memory storage system can be separate from the authentication system. The memory storage system can be owned and / or operated by the same entity as the authentication system. Alternatively, the memory storage system can be owned and / or operated by a different entity than the authentication system.

[0354] The communication system can include one or more recorders. The one or more recorders can receive data from any device of the communication system. For example, the one or more recorders can receive data from one or more UAVs. The one or more recorders can receive data from one or more users and / or remote controllers. One or more memory storage units can be provided by the one or more recorders. For example, one or more memory storage units can be provided by the one or more recorders receiving one or more messages from a UAV, a user, and / or a remote controller. The one or more recorders can or can not have a limited range of receiving information. For example, a recorder can be configured to receive data from devices located within the same physical area as the recorder. For example, a first recorder can receive information from a UAV when the UAV is located in a first zone, and a second recorder can receive information from the UAV when the UAV is located in a second zone. Alternatively, a recorder does not have a limited range and can receive information from devices (e.g., UAVs, remote controllers) regardless of where the devices are located. The recorders can be memory storage units and / or can transmit aggregated information to memory storage units.

[0355] Information from one or more users 1115a, 1115b can be stored in the memory storage system. The information can include user identification information. Examples of user identification information can include user identifiers (e.g., user ID 1, user ID 2, user ID 3,...). The user identifiers can be unique to the users. In some instances, information from a user can include information that facilitates identification and / or authentication of the user. Information from one or more users can include information about the users. Information from one or more users can include one or more commands from the users (e.g., command 1, command 2, command 3, command 4, command 5, command 6,...). The one or more commands can include commands that implement operation of the unmanned aerial vehicle. The one or more commands can be used to control flight of the unmanned aerial vehicle, takeoff of the unmanned aerial vehicle, landing of the unmanned aerial vehicle, operation of a payload of the unmanned aerial vehicle, operation of a carrier of the unmanned aerial vehicle, operation of one or more sensors on board the unmanned aerial vehicle, one or more communication units of the unmanned aerial vehicle, one or more power units of the unmanned aerial vehicle, one or more navigation units of the unmanned aerial vehicle, and / or any feature of the unmanned aerial vehicle. Any other type of information can be provided from one or more users and can be stored in the memory storage system.

[0356] In some embodiments, all user inputs can be stored in the memory storage system. Alternatively, only selected user inputs can be stored in the memory storage system. In some instances, only certain types of user inputs are stored in the memory storage system. For example, in some embodiments, only user identification inputs and / or command information are stored in the memory storage system.

[0357] A user can optionally provide information to the memory storage system by way of one or more user terminals 1120a, 1120b. A user terminal can be a device that is capable of interacting with a user. A user terminal can be a device that is capable of interacting with an unmanned aerial vehicle. A user terminal can be a remote control that is configured to send one or more operation commands to an unmanned aerial vehicle. A user terminal can be a display device that is configured to show data based on information received from an unmanned aerial vehicle. A user terminal can be capable of simultaneously sending information to an unmanned aerial vehicle and receiving information from an unmanned aerial vehicle.

[0358] A user can provide information to the memory storage system by way of any other type of device. For example, one or more computers or other devices can be provided that can be capable of receiving user inputs. The devices can be capable of communicating the user inputs to the memory storage device. The devices need not interact with an unmanned aerial vehicle.

[0359] User terminals 1120a, 1120b can provide information to the memory storage system. The user terminals can provide information about the user, user commands, or any other type of information. The user terminals can provide information about the user terminals themselves. For example, a user terminal identification can be provided. In some cases, a user identifier and / or a user terminal identifier can be provided. A user key and / or a user terminal key can optionally be provided. In some examples, the user does not provide any input regarding the user key, but the user key information can be stored on the user terminal or can be accessible by the user terminal. In some cases, the user key information can be stored on a physical memory of the user terminal. Alternatively, the user key information can be stored off-board (e.g., on a cloud) and can be accessible by the user terminal. In some implementations, the user terminal can transmit the user identifier and / or an associated command.

[0360] Drones 1130a, 1130b can provide information to the memory storage system. The drones can provide information about the drones. For example, drone identification information can be provided. Examples of drone identification information can include drone identifiers (e.g., drone ID 1, drone ID 2, drone ID 3,...). The drone identifiers can be unique to the drones. In some cases, information from a drone can include information that facilitates identification and / or authentication of the drone. Information from one or more drones can include information about the drones. Information from one or more drones can include one or more commands (e.g., command 1, command 2, command 3, command 4, command 5, command 6,...) received by the drones. The one or more commands can include commands that implement operations of the drones. The one or more commands can be used to control flight of the drones, takeoff of the drones, landing of the drones, operation of a payload of the drones, operation of a carrier of the drones, operation of one or more sensors on-board the drones, one or more communication units of the drones, one or more power units of the drones, one or more navigation units of the drones, and / or any feature of the drones. Any other type of information can be provided from one or more drones and can be stored in the memory storage system.

[0361] In some embodiments, a user can be authenticated prior to storing user-related information in the memory storage system. For example, a user can be authenticated prior to obtaining a user identifier and / or storing the user identifier by the memory storage system. Thus, in some implementations, only authenticated user identifiers are stored in the memory storage system. Alternatively, a user need not be authenticated and a purported user identifier can be stored in the memory storage system prior to authentication. If authentication is passed, an indication can be made that the user identifier has been verified. If authentication is not passed, an indication can be made that the user identifier has been flagged for suspicious activity or that a failed authentication attempt has been made using the user identifier.

[0362] Optionally, a UAV can be authenticated prior to storing UAV-related information in the memory storage system. For example, a UAV can be authenticated prior to obtaining a UAV identifier and / or storing the UAV identifier by the memory storage system. Thus, in some implementations, only authenticated UAV identifiers are stored in the memory storage system. Alternatively, a UAV need not be authenticated and a purported UAV identifier can be stored in the memory storage system prior to authentication. If authentication is passed, an indication can be made that the UAV identifier has been verified. If authentication is not passed, an indication can be made that the UAV identifier has been flagged for suspicious activity or that a failed authentication attempt has been made using the UAV identifier.

[0363] In some embodiments, one or more flight commands are permitted only when a user is authorized to operate a UAV. The user and / or the UAV can or can not be authenticated prior to determining whether the user is authorized to operate the UAV. The user and / or the UAV can be authenticated prior to permitting the user to be authorized to operate the UAV. In some cases, commands in the memory storage system can only be stored when a user is authorized to operate a UAV. Commands in the memory storage system can only be stored when the user and / or the UAV are authenticated.

[0364] The memory storage unit can store one or more information sets 1140. The information sets can include information from a user, a user terminal, and / or a UAV. The information sets can include one or more commands, a user identifier, a UAV identifier, and / or an associated time. The user identifier can be associated with a user that issued a command. The UAV identifier can be associated with a UAV that received and / or executed a command. The time can be a time that a command was issued and / or received. The time can be a time that a command was stored in the memory. The time can be a time that a UAV executed a command. In some instances, a single information set can be provided with a single command. Alternatively, a single information set can be provided with multiple commands. The multiple commands can include a command issued by a user and a corresponding command received by a UAV. Alternatively, a single command can be provided that can be logged when issued from a user or that can be logged when received by a UAV and / or executed by a UAV.

[0365] Accordingly, multiple information sets can be provided with related commands. For example, a first information set can be stored when a user issues a command. The time for the first information set can reflect when the user issued the command or when the information set was stored in the memory storage system. Alternatively, data from a remote controller can be used to provide the first information set. A second information set can be stored when a UAV receives a command. The time for the second information set can reflect when the UAV received the command or when the information set was stored in the memory storage system. Alternatively, data from a UAV can be used to provide the second information set based on related commands. A third information set can be stored when a UAV executes a command. The time for the third information set can reflect when the UAV executed the command or when the information set was stored in the memory storage system. Alternatively, data from a UAV can be used to provide the third information set based on related commands.

[0366] The memory storage system can store a set of information regarding a particular interaction between the first user and the first unmanned vehicle. For example, a plurality of commands can be issued during an interaction between the first user and the first unmanned vehicle. The interaction can be the performance of a mission. In some cases, the memory storage unit can store only information regarding the particular interaction. Alternatively, the memory storage system can store information regarding a plurality of interactions (e.g., a plurality of missions) between the first user and the first unmanned vehicle. The memory storage system can optionally store the information according to a user identifier. Data associated with the first user can be stored together. Alternatively, the memory storage unit can store the information according to an unmanned vehicle identifier. Data associated with the first unmanned vehicle can be stored together. The memory storage unit can store the information according to a user-unmanned vehicle interaction. For example, data associated with the first unmanned vehicle and the first user together can be stored together. In some cases, only information regarding the user, the unmanned vehicle, or the user-unmanned vehicle combination can be stored in the memory storage unit.

[0367] Alternatively, the memory storage system can store a set of information regarding interactions between a plurality of users and / or unmanned vehicles. The memory storage system can be a data repository that collects information from a plurality of users and / or unmanned vehicles. The memory storage system can store information from a plurality of missions, which can include individual users, individual unmanned vehicles, and / or individual user-unmanned vehicle combinations. In some cases, the set of information in the memory storage system can be searchable or indexable. The set of information can be searched or indexed according to any parameter, such as user identity, unmanned vehicle identity, time, user-unmanned vehicle combination, command type, location, or any other information. The set of information can be stored according to any parameter.

[0368] In some cases, information in the memory storage system can be analyzed. The set of information can be analyzed to detect one or more patterns of behavior. The set of information can be analyzed to detect one or more characteristics that can be relevant to an incident or an adverse condition. For example, if a particular user frequently crashes a particular model of unmanned aerial vehicle, that data can be extracted. In another example, if another user tends to attempt to maneuver the unmanned aerial vehicle into an area that is not permitted to fly according to a set of flight regulations, such information can be extracted. The set of information in the memory storage unit can be statistically analyzed. Such statistical analysis can be helpful in identifying trends or related factors. For example, it can be noted that certain unmanned aerial vehicle models can have a higher rate of incidents overall than other unmanned aerial vehicle models. The set of information can be analyzed to determine that there can be a generally higher rate of unmanned aerial vehicle malfunctions when the temperature in the environment falls below 5 degrees Celsius. Thus, the information in the memory storage system can be analyzed in aggregate to synthesize information about the operation of unmanned aerial vehicles. Such synthesized analysis need not be in response to a particular event or scenario.

[0369] Information from the memory storage system can be analyzed in response to a particular event or scenario. For example, if an unmanned aerial vehicle crash occurs, the information associated with that unmanned aerial vehicle can be analyzed to provide further forensic information about the crash. If the unmanned aerial vehicle crash occurs during a mission, the set of information collected during that mission can be pulled together and analyzed. For example, a mismatch between an issued command and a received command can be identified. The environmental conditions at the time of the crash can be analyzed. The presence of other unmanned aerial vehicles or obstacles in the area can be analyzed. In some implementations, the set of information for the unmanned aerial vehicle from other missions can also be pulled. For example, in other missions, it can be detected that there were several near misses or malfunctions. Such information can be useful in determining the cause of the crash and / or any actions that need to be taken after the crash.

[0370] Information in the set of information can be used to track individualized unmanned aerial vehicle activity. For example, one or more commands, an associated one or more user identifiers, and an associated one or more unmanned aerial vehicle identifiers can be used to track individualized unmanned aerial vehicle activity.

[0371] The information set can store commands, user information, unmanned vehicle information, timing information, location information, environmental condition information, flight regulation information, or any detected conditions. Any information can correspond to a command. For example, the geographic information can include the location of the unmanned vehicle and / or remote controller when the command was issued. The geographic information can also indicate whether the unmanned vehicle fell into a zone for flight regulation purposes. The environmental conditions can include one or more environmental conditions of the area. For example, the environmental complexity of the area surrounding the unmanned vehicle can be considered when the command is issued or received. The climate that the unmanned vehicle is experiencing when the command is issued or received can be considered. The command can occur at a point in time.

[0372] The memory storage system can be updated in real time. For example, as commands are issued, received, and / or executed, they can be recorded in the memory storage system along with any other information from the information set. This can occur in real time. The commands and any related information in the information set can be stored within less than 10 minutes, 5 minutes, 3 minutes, 2 minutes, 1 minute, 30 seconds, 15 seconds, 10 seconds, 5 seconds, 3 seconds, 1 second, 0.5 seconds, or 0.1 seconds of the command being issued, received, and / or executed. The information set can be stored or recorded in the memory storage system in any manner. The information set can be recorded as it enters without considering other parameters, such as user identity, unmanned vehicle identity, or user-unmanned vehicle combination. Alternatively, the other parameters can be considered and recorded with them. For example, all information sets for the same user can be stored together. Even if the information sets are not all stored together, they can be searchable and / or indexable to find associated information. For example, if information sets for a particular user enter at different points in time and are recorded with information sets from other users, the information sets can be searchable to find all information sets associated with the user.

[0373] In alternative implementations, the memory storage system can not need to be updated in real-time. The memory storage system can be periodically updated at regular or irregular time intervals. For example, the memory storage system can be updated every week, every day, every several hours, every hour, every half hour, every 15 minutes, every 10 minutes, every 5 minutes, every 3 minutes, every minute, every 30 seconds, every 15 seconds, every 10 seconds, every 5 seconds, or every second. In some cases, an update schedule can be provided, which can include regular or irregular update times. The update schedule can be fixed, or can be changeable. In some cases, the update schedule can be changed by an operator or administrator of the memory storage system. The update schedule can be changed by an operator or administrator of the authentication system. A user of the unmanned aerial vehicle can or can not be able to change the update schedule. A user of the unmanned aerial vehicle can be able to change the update schedule for the unmanned aerial vehicle associated with that user. The user can be able to change the update schedule for the unmanned aerial vehicles that the user is authorized to operate.

[0374] The memory storage system can be updated in response to a detected event or condition. For example, when an operator of the memory storage system requests information, the memory storage system can request or pull a set of information from one or more external sources (e.g., remote controller, unmanned aerial vehicle, user). In another example, when a detected condition, such as a detected crash, occurs, the memory storage system can be able to request or pull a set of information. In some examples, one or more external sources (e.g., remote controller, unmanned aerial vehicle, user) can push a set of information to the memory storage system. For example, if an unmanned aerial vehicle detects that it is approaching a flight restricted zone, the unmanned aerial vehicle can push a set of information to the memory storage system. In another example, if a remote controller or unmanned aerial vehicle is aware that there can be some interfering wireless signals, they can push a set of information to the memory storage unit.

[0375] One aspect of the present application can relate to a method of recording unmanned aerial vehicle (UAV) behavior, the method comprising: receiving an UAV identifier that uniquely identifies the UAV from other unmanned aerial vehicles; receiving a user identifier that uniquely identifies the user from other users, wherein the user provides one or more commands via a remote controller to effect operation of the UAV; and recording the one or more commands, the user identifier associated with the one or more commands, and the UAV identifier associated with the one or more commands in one or more memory storage units. Similarly, in accordance with embodiments of the present application, a non-transitory computer readable medium containing program instructions for recording unmanned aerial vehicle (UAV) behavior can be provided, the computer readable medium comprising: program instructions for associating a user identifier with one or more commands from a user, wherein the user identifier uniquely identifies the user from other users, and wherein the user provides one or more commands via a remote controller to effect operation of the UAV; program instructions for associating an UAV identifier with the one or more commands, wherein the UAV identifier uniquely identifies the UAV from other unmanned aerial vehicles; and program instructions for recording the one or more commands, the user identifier associated with the one or more commands, and the UAV identifier associated with the one or more commands in one or more memory storage units.

[0376] In accordance with embodiments of the present application, a system for recording unmanned aerial vehicle (UAV) behavior can be provided. The system can comprise: one or more memory storage units; and one or more processors operatively coupled to the one or more memory storage units and individually or collectively configured for: receiving an UAV identifier that uniquely identifies the UAV from other unmanned aerial vehicles; receiving a user identifier that uniquely identifies the user from other users, wherein the user provides one or more commands via a remote controller to effect operation of the UAV; and recording the one or more commands, the user identifier associated with the one or more commands, and the UAV identifier associated with the one or more commands in one or more memory storage units.

[0377] A memory storage system can store information sets for any period of time. In some cases, information sets can be stored indefinitely until they are deleted. Deletion of information sets can or can not be permitted. In some cases, only an operator or administrator of a memory storage system can be permitted to interact with data stored in the memory storage system. In some cases, only an operator of an authentication system (e.g., air traffic control system, authentication center) can be permitted to interact with data stored in the memory storage system.

[0378] Optionally, the information sets can be automatically deleted after a period of time. The period of time can be pre-established. For example, the information sets can be automatically deleted after greater than a predetermined period of time. Examples of predetermined periods of time can include, but are not limited to, 20 years, 15 years, 12 years, 10 years, 7 years, 5 years, 4 years, 3 years, 2 years, 1 year, 9 months, 6 months, 3 months, 2 months, 1 month, 4 weeks, 3 weeks, 2 weeks, 1 week, 4 days, 3 days, 2 days, 1 day, 18 hours, 12 hours, 6 hours, 3 hours, 1 hour, 30 minutes, or 10 minutes. In some cases, information sets can only be manually deleted after the predetermined period of time has elapsed.

[0379] Taking control

[0380] In some embodiments, operation of a UAV can be compromised. In one example, a user can operate a UAV. Another user (e.g., a hijacker) can attempt to take control of the UAV in an unauthorized manner. Systems and methods described herein can allow detection of such attempts. Systems and methods described herein can also provide a response to such hijacking attempts. In some embodiments, information collected in a memory storage system can be analyzed to detect hijacking.

[0381] Figure 12 A diagram illustrating a scenario in which a hijacker attempts to take control of a UAV in accordance with embodiments of the present application is shown. A user 1210 can use a user remote controller 1215 to issue user commands to a UAV 1220. A hijacker 1230 can use a hijacker remote controller 1235 to issue hijacker commands to the UAV 1220. The hijacker commands can interfere with the user commands.

[0382] In some embodiments, the user 1210 can be an authorized user of the UAV 1220. The user can have an initial relationship with the UAV. The user can optionally pre-register with the UAV. The user can operate the UAV before a hijacker attempts to take control of the UAV. In some cases, if the user is an authorized user of the UAV, the user can operate the UAV. If the user is not an authorized user of the UAV, the user can not be allowed to operate the UAV, or can be able to operate the UAV in a limited manner.

[0383] The user identity can be authenticated. In some cases, the user identity can be authenticated before the user operates the UAV. The user can be authenticated before, at the same time, or after determining whether the user is an authorized user of the UAV. If the user is authenticated, the user can operate the UAV. If the user is not authenticated, the user can not be allowed to operate the UAV, or can be able to operate the UAV in a limited manner.

[0384] The user 1210 can use a user remote controller 1215 to control the operation of the UAV 1220. The remote controller can take user input. The remote controller can transmit user commands to the UAV. The user commands can be generated based on the user input. The user commands can control the operation of the UAV. For example, the user commands can control the flight (e.g., flight path, takeoff, landing) of the UAV. The user commands can control the operation of one or more payloads, the position of one or more payloads, the operation of one or more carriers, the operation of one or more sensors, the operation of one or more communication units, the operation of one or more navigation units, and / or the operation of one or more power units.

[0385] In some cases, user commands can be continuously sent to the UAV. Commands can be sent to the UAV to maintain the status quo or based on recent inputs provided by the user even if the user is not actively providing input at a particular moment. For example, if the user input includes movement of a joystick and the user holds the joystick at a particular angle, flight commands can be sent to the UAV based on the known angle of the joystick from the previous movement. In some cases, user input can be continuously provided to the remote controller even if the user is not actively moving or physically changing anything. For example, if the user input includes tilting the remote controller to a particular pose and the user does not adjust the pose that has been set, user input can be continuously provided based on the continuously measured pose of the remote controller. For example, if the remote controller is at angle A for an extended period of time, during that period of time, the user input can be interpreted as "the pose of the remote controller is angle A." Flight commands can be transmitted to the UAV that indicate a response to the flight command of "the pose of the remote controller is angle A." User commands to the UAV can be updated in real time. User commands can reflect user input for less than 1 minute, 30 seconds, 15 seconds, 10 seconds, 5 seconds, 3 seconds, 2 seconds, 1 second, 0.5 seconds, 0.1 seconds, 0.05 seconds, or 0.01 seconds.

[0386] Optionally, user commands need not be continuously sent to the UAV. User commands can be sent at regular or irregular time periods. For example, user commands can be sent for less than or equal to every hour, every 30 minutes, every 15 minutes, every 10 minutes, every 5 minutes, every 3 minutes, every minute, every 30 seconds, every 15 seconds, every 10 seconds, every 5 seconds, every 3 seconds, every 2 seconds, every 1 second, every 0.5 seconds, or every 0.1 seconds. User commands can be sent according to a schedule. The schedule can or can not be changeable. User commands can be sent in response to one or more detected events or conditions.

[0387] User commands can be received by the UAV 1220. The UAV can be able to operate according to commands from the user when the user commands received at the UAV match the user commands sent from the user remote controller 1215. The communication link between the UAV and the remote controller can be operable when the sent commands match the received commands. If the sent commands and the received commands match, the commands can not have been dropped. In some embodiments, if the sent commands and the received commands do not match, the commands can have been dropped (e.g., the communication link between the remote controller and the UAV can have been dropped), or interfering commands can have been sent.

[0388] The hijacker 1230 can use a hijacker remote controller 1235 to control operation of the UAV 1220. The remote controller can take hijacker input. The remote controller can transmit hijacker commands to the UAV. The hijacker commands can be generated based on the hijacker input. The hijacker commands can control operation of the UAV. For example, the hijacker commands can control flight of the UAV (e.g., flight path, takeoff, landing). The hijacker commands can control operation of one or more payloads, position of one or more payloads, operation of one or more carriers, operation of one or more sensors, operation of one or more communication units, operation of one or more navigation units, and / or operation of one or more power units.

[0389] In some instances, hijacker commands can be transmitted to the UAV continuously. This can occur in a manner similar to how user commands are transmitted to the UAV continuously. Alternatively, hijacker commands need not be transmitted to the UAV continuously. This can occur in a manner similar to how user commands need not be transmitted to the UAV continuously. Hijacker commands can be transmitted at regular or irregular time periods. Hijacker commands can be transmitted according to a schedule. Hijacker commands can be transmitted in response to one or more detected events or conditions.

[0390] The hijacker commands can be received by the UAV 1220. The UAV can be able to operate according to the commands from the hijacker when the hijacker commands received at the UAV match the hijacker commands transmitted from the hijacker remote controller 1235. The communication link between the UAV and the hijacker remote controller can be operable when the transmitted and received commands match. The hijacker can have successfully taken control of the UAV when the commands received by the UAV match the commands transmitted from the hijacker remote controller. In some instances, the hijacker can have successfully taken control of the UAV when the UAV performs one or more operations according to the hijacker commands. In some instances, the hijacker can have successfully taken control of the UAV when the UAV does not perform one or more operations according to the user commands.

[0391] When the hijacker commands are received at the unmanned vehicle, the unmanned vehicle can or can not also receive user commands. In one type of hijack, the communication link between the unmanned vehicle and the hijacker remote control can interfere with the communication link between the unmanned vehicle and the user remote control. This can prevent user commands from reaching the unmanned vehicle, or can cause user commands to be received by the unmanned vehicle only unreliably. The hijacker commands can or can not be received by the unmanned vehicle. In some embodiments, when the hijacker issues a command to take over control of the unmanned vehicle, the hijacker connection can interfere with the user connection. In this scenario, the unmanned vehicle can receive only the hijacker commands. The unmanned vehicle can operate according to the hijacker commands. In another embodiment, when the hijacker does not necessarily send commands to the unmanned vehicle, the hijacker connection can interfere with the user connection. The interference with the signals can be sufficient to constitute a hijacking of the unmanned vehicle or a hacking of the user's operation of the unmanned vehicle. The unmanned vehicle can optionally receive no commands (e.g., can stop receiving the user commands that were previously coming in). The unmanned vehicle can have one or more default actions that can occur when communication with the user is lost. For example, the unmanned vehicle can hover in place. In another example, the unmanned vehicle can return to a mission start point.

[0392] In another type of hijack, the unmanned vehicle can receive both user commands and hijacker commands. The communication link between the unmanned vehicle and the hijacker remote control need not necessarily interfere with the communication link between the unmanned vehicle and the user remote control. The unmanned vehicle can operate according to the hijacker commands. The unmanned vehicle can choose to operate according to the hijacker commands, ignoring the user commands. Or, when the unmanned vehicle receives multiple sets of commands, the unmanned vehicle can take one or more default actions. For example, the unmanned vehicle can hover in place. In another example, the unmanned vehicle can return to a mission start point.

[0393] The hijacker can be an individual that is not authorized to operate the unmanned vehicle. The hijacker can be an individual that is not pre-registered with the unmanned vehicle. The hijacker can be an individual that is not authorized to take over control from the user to operate the unmanned vehicle. The hijacker can be authorized to operate the unmanned vehicle in other ways. However, the hijacker can not be authorized to interfere with the user's operation of the unmanned vehicle when the user is already operating the unmanned vehicle.

[0394] The systems and methods described herein can include detecting interference with one or more commands from a user. This can include hijacking of a UAV. A user command can be interfered with when the user command does not reach the UAV. The user command can be interfered with due to a communication connection between the UAV and a hijacker. In some cases, the hijacker can attempt to jam the signal between the user and the UAV. The jamming of the signal can occur in response to the hijacker communicating with the UAV. Alternatively, the hijacker can jam the signal between the user and the UAV without communicating with the UAV. For example, the hijacker device can broadcast a signal that can interfere with the user's communication with the UAV even though the hijacker device is not issuing any hijacker commands. The user command can be interfered with even if the user command reaches the UAV. The user command can be interfered with if the UAV does not perform an operation in accordance with the user command. For example, the UAV can elect to perform an operation in accordance with a hijacker command instead of the user command. Alternatively, the UAV can elect to take a default action or no action in place of the user command.

[0395] The hijacker command can or can not contradict the user command. The unauthorized communication can interfere with one or more commands from a user that provide contradictory commands to the UAV. In one example, a user command can enable flight of the UAV while a hijacker command can enable flight in a different manner. For example, a user command can command the UAV to turn right while a hijacker command can command the UAV to continue forward. A user command can command the UAV to rotate about a pitch axis while a hijacker command can command the UAV to rotate about a yaw axis.

[0396] In addition to detecting interference, the systems and methods herein can also allow for actions to be taken in response to the detected interference with one or more commands from a user. The actions can include alerting the user about the interference. The actions can include alerting one or more others (e.g., an operator or administrator of the authentication system) about the interference. The actions can include one or more default actions of the UAV (e.g., landing, hovering in place, returning to a starting point).

[0397] One aspect of the application relates to a method of alerting a user when operation of an unmanned vehicle is compromised, the method comprising: authenticating a user to enable operation of an unmanned vehicle; receiving one or more commands from a hijacking attempt remote control that receives user input to enable operation of the unmanned vehicle; detecting an unauthorized, interfering communication of the one or more commands from the user; and alerting the user via the remote control about the unauthorized communication. In a similar aspect, a non-transitory computer readable medium containing program instructions for alerting a user when operation of an unmanned vehicle is compromised can be provided. The computer readable medium can comprise: program instructions for authenticating a user to enable operation of an unmanned vehicle; program instructions for receiving one or more commands from a remote control that receives user input to enable operation of the unmanned vehicle; and program instructions for generating an alert to be provided to the user via the remote control, the alert about a detected unauthorized communication that interferes with the one or more commands from the user.

[0398] According to embodiments of the application, an unmanned vehicle alert system can be provided, the unmanned vehicle alert system comprising: a communication module; and one or more processors operatively coupled to the communication module and individually or collectively configured for: authenticating a user to enable operation of an unmanned vehicle; receiving one or more commands from a remote control that receives user input to enable operation of the unmanned vehicle; detecting an unauthorized, interfering communication of the one or more commands from the user; and generating a signal to alert the user via the remote control about the unauthorized communication. An unmanned vehicle alert module can comprise: one or more processors individually or collectively configured for: authenticating a user to enable operation of an unmanned vehicle; receiving one or more commands from a remote control that receives user input to enable operation of the unmanned vehicle; detecting an unauthorized, interfering communication of the one or more commands from the user; and generating a signal to alert the user via the remote control about the unauthorized communication.

[0399] The unauthorized communication can comprise a hijacker command. The unauthorized communication can indicate a hijacking attempt by an unauthorized user. The hijacker command can optionally comprise one or more commands to control operation of the unmanned vehicle. The unauthorized communication indicates a signal jamming attempt by an unauthorized user. The unauthorized communication causing the signal jamming need not comprise a hijacker command to control operation of the unmanned vehicle.

[0400] Warnings can be generated regarding unauthorized communications. Warnings can be provided to users attempting to operate the drone, to other entities (e.g., operators and / or managers of authentication systems, individuals within law enforcement agencies, individuals in emergency services), and / or to the controlling entity.

[0401] Warnings can be provided visually, audibly, and / or tactilely. For example, a warning can be provided on the display screen of a user remote control. For example, text or images indicating unauthorized communication can be provided. Text or images indicating interference with user commands can be provided. In another example, a warning can be provided audibly via a user remote control. The user remote control may have a speaker capable of producing sound. Sound can indicate unauthorized communication. Sound can indicate interference with user commands. Warnings can be provided tactilely via a remote control. The user remote control may vibrate or bounce. Alternatively, the user remote control may shake, heat up or cool down, deliver a mild electric shock, or provide any other tactile indication. Tactile effects can indicate unauthorized communication. Tactile effects can indicate interference with user commands.

[0402] Warnings can indicate the type of unauthorized communication. The type of unauthorized communication can be selected from one or more categories. For example, unauthorized communication can be adversarial flight commands, signal jamming communications, adversarial load manipulation commands, or adversarial communication (e.g., data transmission) commands. Warnings can visually distinguish different types of unauthorized communication. For example, different text and / or images can be provided. Warnings can auditorily distinguish different types of unauthorized communication. For example, different sounds can be provided. Different sounds can be different words or different tones. Warnings can tactilely distinguish different types of unauthorized communication. For example, different vibrations or pulsations can be used.

[0403] Various methods can be implemented to detect unauthorized communication. For example, unauthorized communication can be detected when the user identifier associated with it is not authenticated or does not indicate a user authorized to interact with the UAV. For example, the hijacker may not be authenticated as a user. In some cases, a separate hijacker identifier can be extracted. It can be determined that the hijacker identifier is not an individual authorized to operate the UAV or is not an individual authorized...

Claims

1. A geo-fencing device comprising: an input element configured to collect data that is helpful in determining a set of flight regulations; one or more processors, individually or collectively, configured to: determine the set of flight regulations based on the data collected by the input element; and one or more output elements configured to output a signal that causes a UAV to fly in accordance with the set of flight regulations, the set of flight regulations capable of causing different types of flight response measures by the UAV; wherein (1) there are multiple geo-fencing devices, the multiple geo-fencing devices capable of forming a network that shares information with each other; and / or (2) the geo-fencing device is capable of sharing information with the UAV, the shared information including environmental condition information, an environmental condition including a degree of traffic flow within an environment. 2.The geo-fencing device of claim 1, wherein the input element is a sensor and the data is sensory data indicative of one or more environmental conditions of the geo-fencing device. 3.The geo-fencing device of claim 2, wherein the one or more environmental conditions include one or more of the following: weather, environmental complexity, aerial traffic flow near the geo-fencing device. 4.The geo-fencing device of claim 1, wherein the input element is a detector configured to detect a presence of the UAV, and the data is indicative of one or more of the following: presence of the UAV, location of the UAV, type of the UAV, identifier of the UAV. 5.The geo-fencing device of claim 1, wherein the input element is a communication module configured to receive wireless signals; the data collected by the input element includes one or more of the following: wherein user input information, information from one or more surrounding geo-fencing devices, information from an air traffic control system. 6.The geo-fencing device of claim 1, wherein the set of flight regulations includes one or more geo-fencing boundaries for one or more flight restrictions, and / or one or more types of flight restrictions. 7.The geo-fencing device of claim 1, wherein the signal includes one or more of the following: the set of flight regulations; trigger information that causes an external device to send the set of flight regulations to the UAV; an identifier that causes the UAV to select the determined set of flight regulations from a memory of the UAV. 8.The geo-fencing device of claim 1, wherein the input element is a user interface onboard the geo-fencing device for updating the set of flight regulations, such that the flight regulations are manually updated. 9.A method of controlling flight of a UAV, the method comprising: collecting, using an input element of a geo-fencing device, data that is helpful in determining a set of flight regulations; determining, by means of one or more processors, the set of flight regulations based on the data collected by the input element; and ​ ​ output, via one or more output elements of the geo-fencing device, a signal causing the UAV to fly in accordance with the set of flight regulations, the set of flight regulations capable of causing different types of flight response measures by the UAV; wherein (1) the geo-fencing device is one of a plurality of geo-fencing devices, the plurality of geo-fencing devices capable of forming a network that shares information with each other; and / or (2) the geo-fencing device is capable of sharing information with the UAV, the shared information comprising environmental condition information, the environmental condition comprising a degree of traffic flow within an environment.

10. The method of claim 9, wherein the input element is a sensor, and the data is sensory data indicative of one or more environmental conditions of the geo-fencing device.

11. The method of claim 10, wherein, The one or more environmental conditions comprise one or more of: weather, environmental complexity, aerial traffic flow proximate to the geo-fencing device.

12. The method of claim 9, wherein the input element is a detector configured to detect a presence of the UAV; wherein, The data is used to indicate one or more of: the presence of the UAV, a location of the UAV, a type of the UAV, an identifier of the UAV.

13. The method of claim 9, wherein the input element is a communication module configured to receive wireless signals; wherein The data collected by the input element comprises one or more of: user input information, information from one or more surrounding geo-fencing devices, information from an air traffic control system.

14. The method of claim 9, wherein the set of flight regulations comprises: one or more geo-fencing boundaries for one or more flight restrictions; and / or one or more types of flight restrictions.

15. The method of claim 9, wherein the signal comprises one or more of: the set of flight regulations; trigger information causing an external device to transmit the set of flight regulations to the UAV; an identifier causing the UAV to select the determined set of flight regulations from a memory of the UAV.

16. The method of claim 9, wherein the input element is a user interface onboard the geo-fencing device for updating the set of flight regulations, such that the flight regulations are updated by manual operation.

Citation Information

Patent Citations

  • Method for preventing skyjacking by using GPS and electronic map

    WO2003025690A1