An air-ground communication access control method, device, equipment and storage medium

By establishing an authentication link based on the RFC 6733 protocol in the air-to-ground communication system and authenticating airborne clients using a preset authentication protocol, the target data transmission link is filtered, thus solving the problem of illegal user data transmission and improving the security of air-to-ground communication.

CN115942315BActive Publication Date: 2026-05-29CHINA ELECTRONICS TECHNOLOGY AVIONICS CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA ELECTRONICS TECHNOLOGY AVIONICS CO LTD
Filing Date
2021-08-23
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

In existing technologies, unauthorized users can use air-to-ground communication links to transmit data, resulting in insufficient security for air-to-ground communication.

Method used

An air-to-ground communication authentication link is established based on the RFC 6733 protocol. The authentication information of the airborne client is obtained using a preset air-to-ground authentication protocol for authentication. If the authentication is successful, the target service data transmission link is selected; otherwise, the use of the service data transmission link is prohibited.

Benefits of technology

This effectively prevents unauthorized users from transmitting data via the air-to-ground communication link, thus improving the security of air-to-ground communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115942315B_ABST
    Figure CN115942315B_ABST
Patent Text Reader

Abstract

The application discloses an air-ground communication access control method and device, equipment and a storage medium, comprising: establishing an air-ground communication authentication link with an airborne client based on an RFC 6733 protocol; obtaining an authentication request carrying authentication information sent by the airborne client through the air-ground communication authentication link based on a preset air-ground authentication protocol, and authenticating the airborne client by using the authentication information; the preset air-ground authentication protocol is a protocol added in advance on the RFC 6733 protocol; if the authentication is successful, a corresponding authentication success notification is returned to the airborne client, and a target service data transmission link for sending service data messages is screened for the airborne client, so that the airborne client develops service communication between the air and the ground through the target service data transmission link. By using the authentication information to authenticate the airborne client, the access control of the air-ground communication of the airborne client can be realized, and the security of the air-ground communication is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of communication technology, and in particular to an air-to-ground communication access control method, apparatus, device, and storage medium. Background Technology

[0002] With the development of science and technology, air-to-ground communication for civil aircraft is evolving from traditional high-frequency (HF) and very high-frequency (VHF) communications to IP-based communication methods such as cockpit satellite communication (L-band), air-to-ground (ATG) broadband communication, and Ku / Ka-band broadband satellite communication. Furthermore, during flight, data such as air traffic control data, airline operational data, maintenance and health management data, and passenger internet+ application data need to be transmitted to ground terminal equipment via air-to-ground wireless communication links. However, in current practical applications, there are instances of unauthorized users using wireless communication links for air-to-ground communication. Therefore, how to implement access control for airborne clients during air-to-ground communication, ensuring that their behavior is controlled and preventing responses to data transmitted by unauthorized users, thereby improving the security of air-to-ground communication, is a pressing issue that needs to be addressed. Summary of the Invention

[0003] In view of this, the purpose of this invention is to provide an air-to-ground communication access control method, apparatus, device, and storage medium, which can realize access control of airborne client air-to-ground communication and effectively prevent unauthorized users from transmitting data via the air-to-ground communication link, thereby improving the security of air-to-ground communication. The specific solution is as follows:

[0004] The first aspect of this application provides an air-to-ground communication access control method, applied to an air-to-ground wireless link management server, comprising:

[0005] An air-to-ground communication authentication link between the airborne client and the RFC 6733 protocol is established.

[0006] The authentication request carrying authentication information sent by the airborne client through the airborne communication authentication link is obtained based on a preset air-to-ground authentication protocol, and the authentication information is used to authenticate the airborne client; the preset air-to-ground authentication protocol is a protocol pre-added to the RFC 6733 protocol;

[0007] If authentication is successful, a corresponding authentication success notification is returned to the airborne client, and a target service data transmission link for sending service data packets is selected for the airborne client, so that the airborne client can carry out air-to-ground service communication through the target service data transmission link.

[0008] Optionally, authenticating the airborne client using the authentication information includes:

[0009] The airborne client is authenticated using its user information and attribute information.

[0010] Optionally, after authenticating the airborne client using the authentication information, the method further includes:

[0011] If authentication fails, a corresponding authentication failure notification is returned to the airborne client, and the airborne client is prohibited from using the business data transmission link.

[0012] Optionally, the step of filtering the target service data transmission links for sending service data packets for the airborne client includes:

[0013] The communication capability negotiation request carrying communication capability requirements is obtained from the airborne client based on a preset air-to-ground communication negotiation protocol; the preset air-to-ground communication negotiation protocol is a protocol pre-added to the RFC6733 protocol.

[0014] Determine whether there exists a service data transmission link that can meet the communication capability requirements. If so, return a corresponding negotiation success notification to the airborne client and select the service data transmission link that meets the communication capability requirements as the target service data transmission link.

[0015] Optionally, the step of filtering out service data transmission links that meet the communication capability requirements includes:

[0016] The target business data transmission link is obtained by selecting the business data transmission link that matches the communication capability requirements from all business data transmission links.

[0017] Optionally, obtaining the communication capability negotiation request carrying communication capability requirements sent by the airborne client based on a preset air-to-ground communication negotiation protocol includes:

[0018] Based on a preset air-to-ground communication negotiation protocol, the system obtains a communication capability negotiation request sent by the airborne client, which carries the airborne client's bandwidth requirement information, preemption type, and QoS level information.

[0019] The second aspect of this application provides an air-to-ground communication access control method, applied to an airborne client, comprising:

[0020] An air-to-ground communication authentication link is established between the air-to-ground wireless link management server and the RFC 6733 protocol.

[0021] Based on a preset air-to-ground authentication protocol, an authentication request carrying authentication information is sent to the air-to-ground wireless link management server through the air-to-ground communication authentication link, so that the air-to-ground wireless link management server can use the authentication information to authenticate the airborne client; the preset air-to-ground authentication protocol is a protocol pre-added to the RFC 6733 protocol.

[0022] If authentication is successful, the system receives a corresponding authentication success notification from the air-to-ground wireless link management server and initiates air-to-ground service communication through the target service data transmission link selected by the air-to-ground wireless link management server.

[0023] A third aspect of this application provides an air-to-ground communication access control device, comprising:

[0024] The authentication link establishment module is used to establish an air-to-ground communication authentication link with the airborne client based on the RFC 6733 protocol.

[0025] The authentication module is used to obtain the authentication request carrying authentication information sent by the airborne client through the airborne communication authentication link based on the preset air-to-ground authentication protocol, and to authenticate the airborne client using the authentication information. When the authentication is successful, the module returns a corresponding authentication success notification to the airborne client. The preset air-to-ground authentication protocol is a protocol that is added to the RFC 6733 protocol in advance.

[0026] The link selection module is used to filter the target service data transmission links for the airborne client to send service data packets, so that the airborne client can carry out air-to-ground service communication through the target service data transmission links.

[0027] A fourth aspect of this application provides an electronic device comprising a processor and a memory; wherein the memory is used to store a computer program, the computer program being loaded and executed by the processor to implement the aforementioned air-to-ground communication access control method.

[0028] The fifth aspect of this application provides a computer-readable storage medium storing computer-executable instructions, which, when loaded and executed by a processor, implement the aforementioned air-to-ground communication access control method.

[0029] In this application, an air-to-ground communication authentication link is first established based on the RFC 6733 protocol with the airborne client. Then, based on a preset air-to-ground authentication protocol, the authentication request carrying authentication information sent by the airborne client through the air-to-ground communication authentication link is obtained, and the authentication information is used to authenticate the airborne client. The preset air-to-ground authentication protocol is a protocol pre-added to the RFC 6733 protocol. If authentication is successful, a corresponding authentication success notification is returned to the airborne client, and a target service data transmission link for sending service data packets is selected for the airborne client, allowing the airborne client to conduct air-to-ground service communication through the target service data transmission link. By establishing an air-to-ground communication authentication link based on the RFC 6733 protocol, authenticating the airborne client using the authentication information, and selecting a target service data transmission link for sending service data packets after successful authentication, access control for the airborne client's air-to-ground communication is achieved. This method effectively prevents unauthorized users from sending service data packets using the service data transmission link, improving the security of air-to-ground communication. Attached Figure Description

[0030] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0031] Figure 1 A flowchart of an air-to-ground communication access control method provided in this application;

[0032] Figure 2 A schematic diagram of a specific airborne service flow attribute configuration file provided in this application;

[0033] Figure 3 This application provides a schematic diagram of a specific airborne client authentication process;

[0034] Figure 4 A flowchart of a specific air-to-ground communication access control method provided in this application;

[0035] Figure 5 This application provides a schematic diagram of a specific communication capability negotiation process;

[0036] Figure 6 A flowchart of a specific air-to-ground communication access control method provided in this application;

[0037] Figure 7A flowchart of a specific air-to-ground communication access control method provided in this application;

[0038] Figure 8 A schematic diagram of the device structure for an air-to-ground communication access control method provided in this application;

[0039] Figure 9 This application provides a structural diagram of an electronic device for an air-to-ground communication access control method. Detailed Implementation

[0040] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0041] In existing technologies, when transmitting service data, IP-based air-to-ground communication presents the problem that unauthorized users can use the service data transmission link for air-to-ground communication. To overcome this technical problem, this application provides an air-to-ground communication access control method that can control the access of airborne clients to air-to-ground communication, thereby effectively prohibiting unauthorized users from using the service data transmission link to send service data packets and improving the security of air-to-ground communication.

[0042] Figure 1 A flowchart illustrating an air-to-ground communication access control method provided in an embodiment of this application. See also... Figure 1 As shown, the air-to-ground communication access control method includes:

[0043] S11: Establish an air-to-ground communication authentication link with the airborne client based on the RFC 6733 protocol.

[0044] In this embodiment, the air-to-ground wireless link management server establishes an air-to-ground communication authentication link with various airborne clients requiring air-to-ground communication based on the RFC 6733 (Diameter Base Protocol) protocol. It can be understood that the air-to-ground wireless link management server can establish one or more communication links with the airborne clients based on the RFC 6733 protocol. Specifically, for various airborne clients requiring air-to-ground communication, they can be divided into single service flows based on the six-tuple in the standard IP packet header. Corresponding attribute configuration files (DynamicClient Profiles) can be defined for each flow, identified by Profile-Name (modifying the registry) and Flow-ID. The six-tuple in the standard IP packet header includes: source IP address, destination IP address, source port, destination port, protocol, and ToS / DSCP (Type of Service / Differentiated Services Code Point) fields. For example... Figure 2 As shown, Figure 2 This embodiment provides a specific example of an airborne service flow attribute configuration file. It can be understood that the air-to-ground wireless link management server can establish the aforementioned air-to-ground communication authentication link with the airborne client based on the information in the attribute configuration file.

[0045] S12 obtains the authentication request carrying authentication information sent by the airborne client through the airborne communication authentication link based on the preset air-to-ground authentication protocol, and uses the authentication information to authenticate the airborne client; the preset air-to-ground authentication protocol is a protocol pre-added to the RFC 6733 protocol.

[0046] In this embodiment, the air-to-ground wireless link management server obtains the authentication request (Client-Authentication-Request, CAR) sent by the airborne client through the air-to-ground communication authentication link, carrying authentication information, based on a preset air-to-ground authentication protocol. The authentication information includes the airborne client's user information and attribute information. The server then uses this user information and attribute information to authenticate the airborne client. The user information can include a username, password, user ID, etc. It is understood that the air-to-ground wireless link management server locally stores user information and attribute information for various airborne clients. When it receives an authentication request carrying the airborne client's user information and attribute information, it matches the obtained information with the locally stored information to obtain the corresponding authentication result.

[0047] S13: If authentication is successful, return a corresponding authentication success notification to the airborne client, and select a target service data transmission link for the airborne client to send service data packets, so that the airborne client can carry out air-to-ground service communication through the target service data transmission link.

[0048] In this embodiment, when the authentication information sent by the airborne client matches the information stored locally, the airborne client is successfully authenticated. The air-to-ground wireless link management server returns a corresponding authentication success notification to the airborne client, and then selects a target service data transmission link for the airborne client so that the airborne client can carry out air-to-ground service communication through the selected target service data transmission link.

[0049] In this embodiment, the service data transmission link can be a pre-determined link or a link determined after communication negotiation. In a specific embodiment, the service processing node can obtain the service data packets sent by the airborne client based on the preset service transmission link. It is understood that in practical applications, the preset service transmission link should be a communication link that can meet the communication capability requirements of the airborne client when transmitting service data packets. However, the preset service transmission link may not meet the communication capability requirements of the airborne client for transmitting special service data packets, and therefore, the transmission of service data packets may also fail through the preset service transmission link. Transmitting service data packets through the preset service transmission link eliminates the need for communication negotiation, which can improve the transmission speed of service data packets, but there is a possibility of service data packet transmission failure, and it will cause unnecessary waste of resources. In another specific embodiment, the service processing node can obtain the service data packets sent by the airborne client based on the service transmission link determined through communication negotiation between the air-to-ground radio link management server and the airborne client. In practical applications, using the service transmission link determined through communication negotiation to transmit service data packets can better allocate communication resources and avoid the special situation where the service data transmission link does not meet the communication capability requirements of the airborne client, resulting in the failure of service data packet transmission. It is understood that after obtaining the service data packet, the service processing node responds to the service data packet. In addition, the above-mentioned service processing node includes, but is not limited to, ground-based air-to-ground radios, ground control personnel's computer terminals, tower systems, etc.

[0050] In this embodiment, when the authentication information sent by the airborne client does not match the information stored locally, the authentication of the airborne client fails. The air-to-ground radio link management server returns a corresponding authentication failure notification to the airborne client and prohibits the airborne client from using the service data transmission link. This effectively controls the airborne client's access to air-to-ground communication and effectively prevents unauthorized users from transmitting service data packets via the service data transmission link, thereby improving the security of air-to-ground communication. It is understood that after authenticating the airborne client, the air-to-ground radio link management server returns an authentication result notification (Client-Authentication-Answer, CAA) to the airborne client so that the airborne client can determine the corresponding authentication result and proceed with subsequent service data packets.

[0051] For example Figure 3 As shown, Figure 3 This embodiment provides a specific airborne client authentication process. The air-to-ground wireless link management server establishes a communication connection with the airborne client that needs to communicate with the airborne client based on the RFC 6733 protocol. Then, it obtains the authentication request (CAR) carrying authentication information sent by the airborne client, authenticates the airborne client based on the authentication information in the authentication request (CAR), and returns the corresponding authentication result (CAA) to the airborne client.

[0052] As can be seen, in this embodiment, an air-to-ground communication authentication link is first established based on the RFC 6733 protocol with the airborne client. Then, based on a preset air-to-ground authentication protocol, the authentication request (CAA) sent by the airborne client through the air-to-ground communication authentication link, carrying the user information and attribute information of the airborne client, is obtained. The authentication information is then used to authenticate the airborne client. The preset air-to-ground authentication protocol is a protocol pre-added to the RFC 6733 protocol. After authenticating the airborne client, a corresponding authentication result notification (CAR) is returned to the airborne client. If authentication is successful, a corresponding authentication success notification is returned to the airborne client, and a target service data transmission link for sending service data packets is selected for the airborne client, allowing the airborne client to conduct air-to-ground service communication through the target service data transmission link. If authentication fails, a corresponding authentication failure notification is returned to the airborne client, and the airborne client is prohibited from using the service data transmission link. The above methods enable access control of airborne client air-to-ground communication and effectively prevent unauthorized users from transmitting business data packets using the business data transmission link, thereby improving the security of air-to-ground communication.

[0053] Figure 4A flowchart illustrating a specific air-to-ground communication access control method provided in this application embodiment. See also... Figure 4 As shown, the air-to-ground communication access control method includes:

[0054] S21: Establish an air-to-ground communication authentication link with the airborne client based on the RFC 6733 protocol.

[0055] S22: Obtain the authentication request carrying authentication information sent by the airborne client through the airborne communication authentication link based on the preset air-to-ground authentication protocol, and use the authentication information to authenticate the airborne client; the preset air-to-ground authentication protocol is a protocol pre-added to the RFC 6733 protocol.

[0056] S23: If authentication is successful, return a corresponding authentication success notification to the airborne client.

[0057] S24: Obtain the communication capability negotiation request sent by the airborne client carrying communication capability requirements based on the preset air-to-ground communication negotiation protocol; the preset air-to-ground communication negotiation protocol is a protocol pre-added to the RFC6733 protocol.

[0058] In this embodiment, after successful authentication of the airborne client, the airborne client can send service data packets to the air-to-ground radio link management server. Since different airborne clients have different communication capability requirements for sending service data packets, the air-to-ground radio link management server needs to negotiate communication capability with the airborne client. Therefore, after successful authentication of the airborne client, the air-to-ground radio link management server obtains a Communication-Change-Request (CCR) sent by the airborne client, which carries the airborne client's bandwidth requirement information, preemption type, and QoS (Quality of Service) level information, based on a preset air-to-ground communication negotiation protocol. This preset air-to-ground communication negotiation protocol is a protocol pre-added to the RFC 6733 protocol. The bandwidth requirement information includes the maximum requested bandwidth and minimum bandwidth requirement required by the airborne client to send service data packets. It is understood that the air-to-ground wireless link management server in this embodiment obtains the communication capability negotiation request through the communication capability negotiation link. The communication capability negotiation link is specifically an air-to-ground communication link built based on the RFC 6733 protocol before authentication. This communication capability negotiation link can be another air-to-ground communication link different from the air-to-ground communication authentication link, or it can be the same link as the air-to-ground communication authentication link.

[0059] S25: Determine whether there is a service data transmission link that can meet the communication capability requirements. If there is, return a corresponding negotiation success notification to the airborne client and filter out the service data transmission links that meet the communication capability requirements so that the airborne client can use the filtered service data transmission links to carry out air-to-ground service communication.

[0060] In this embodiment, based on the communication capability requirements carried in the communication capability negotiation request, the air-to-ground radio link management server determines whether a service data transmission link that can meet the communication capability requirements exists locally, and returns a corresponding negotiation result notification (Communication-Change-Answer, abbreviated as CCA) to the airborne client. It can be understood that if the air-to-ground radio link management server has a service data transmission link that can meet the communication capability requirements locally, it returns a corresponding negotiation success notification to the airborne client and selects the service data transmission link that meets the communication capability requirements as the target service data transmission link. Specifically, the air-to-ground radio link management server can select the service data transmission link that matches the communication capability requirements from all service data transmission links to obtain the target service data transmission link. It should be noted that in practical applications, there can be one or more service data transmission links that meet the communication capability requirements. When multiple service data transmission links meet the communication capability requirements, the service data transmission link closest to the communication capability requirements can be selected to avoid unnecessary waste of resources. If the local communication resources of the air-to-ground wireless link management server cannot meet the communication capability requirements, a corresponding negotiation failure notification is returned to the airborne client, prohibiting the airborne client from using the service data transmission link. It is understood that when returning the corresponding negotiation failure notification to the airborne client, the corresponding local communication resource information can also be sent to the airborne client, so that the airborne client can make corresponding adjustments to the communication capability requirements and re-initiate the communication capability negotiation request, thereby enabling the successful transmission of the service data packets.

[0061] For example Figure 5 As shown, Figure 5 In this embodiment, a specific communication capability negotiation process is provided. After successful authentication of the airborne client, a communication capability negotiation request (CCR) carrying communication capability requirements is obtained from the airborne client. Then, it is determined whether the local communication resources meet the communication capability requirements, and a corresponding negotiation result notification (CCA) is returned to the airborne client. The target service data transmission link corresponding to the communication capability requirements is determined so that the airborne client can carry out air-to-ground service communication through the target service data transmission link.

[0062] In this embodiment, the specific processes of steps S21, S22, and S23 can be referred to the corresponding content disclosed in the previous embodiments, and will not be repeated here.

[0063] As can be seen, in this embodiment, after successful authentication of the airborne client, a corresponding authentication success notification is returned to the airborne client. Then, based on a preset air-to-ground communication negotiation protocol, the communication capability negotiation request carrying communication capability requirements sent by the airborne client is obtained. The preset air-to-ground communication negotiation protocol is a protocol pre-added to the RFC 6733 protocol. Then, it is determined whether the local communication resources meet the communication capability requirements. If they do, a corresponding negotiation success notification is returned to the airborne client, and a target service data transmission link for sending service data packets is selected for the airborne client, so that the airborne client can carry out air-to-ground service communication through the target service data transmission link. This method determines the most suitable service data transmission link based on the communication capability requirements of the airborne client, avoiding the situation where the service data transmission link fails to meet the communication capability requirements of the airborne client when transmitting service data packets, and also avoiding unnecessary waste of resources.

[0064] Figure 6 A flowchart illustrating a specific air-to-ground communication access control method provided in this application embodiment. See also... Figure 6 As shown, the air-to-ground communication access control method includes:

[0065] S31: Establish an air-to-ground communication authentication link with the air-to-ground wireless link management server based on the RFC 6733 protocol.

[0066] S32: Based on the preset air-to-ground authentication protocol, an authentication request carrying authentication information is sent to the air-to-ground wireless link management server through the air-to-ground communication authentication link, so that the air-to-ground wireless link management server can use the authentication information to authenticate the airborne client; the preset air-to-ground authentication protocol is a protocol pre-added to the RFC 6733 protocol.

[0067] In this embodiment, an authentication request carrying the user information and attribute information of the airborne client is sent to the airborne wireless link management server based on a preset air-to-ground authentication protocol.

[0068] S33: If authentication is successful, receive the corresponding authentication success notification returned by the air-to-ground wireless link management server, and carry out air-to-ground service communication through the target service data transmission link selected by the air-to-ground wireless link management server.

[0069] In this embodiment, if authentication is successful, the system receives a successful authentication notification from the air-to-ground radio link management server. Then, based on a preset air-to-ground communication negotiation protocol, a communication capability negotiation request carrying communication capability requirements is sent to the air-to-ground radio link management server. This allows the air-to-ground radio link management server to determine if a service data transmission link exists locally that can meet the communication capability requirements. The preset air-to-ground communication negotiation protocol is a protocol pre-added to the RFC 6733 protocol. If a link exists, the system receives a successful negotiation notification from the air-to-ground radio link management server and initiates air-to-ground service communication through the target service data transmission link selected by the air-to-ground radio link management server. It should be noted that the communication capability requirements include the bandwidth requirements, preemption type, and QoS level information of the airborne client. The target service data transmission link is a service data transmission link selected by the air-to-ground radio link management server from all service data transmission links that matches the communication capability requirements.

[0070] For example Figure 7 As shown, Figure 7 This embodiment provides a flowchart of a specific air-to-ground communication access control method, applied to an airborne client.

[0071] The airborne client establishes an air-to-ground communication authentication link with the air-to-ground radio link management server based on the RFC 6733 protocol. Based on a preset air-to-ground authentication protocol, the client sends an authentication request carrying its user information and attribute information to the air-to-ground radio link management server via this link. The air-to-ground radio link management server then authenticates the client using this information. If authentication is successful, the client receives a success notification from the air-to-ground radio link management server. Then, based on a preset air-to-ground communication negotiation protocol, the client sends a communication capability negotiation request carrying communication capability requirements to the air-to-ground radio link management server. The server then determines whether a service data transmission link exists locally that meets the communication capability requirements. If such a link exists, the client transmits service data packets through the link determined by the air-to-ground radio link management server. If not, the client is prohibited from sending service data packets using the service transmission link, thus blocking air-to-ground communication. If authentication fails, a corresponding authentication failure notification is returned to the air-to-ground wireless link management server, and the service data transmission link is stopped, thereby blocking communication between the air and ground.

[0072] As can be seen, in this embodiment, an air-to-ground communication authentication link is established between the air-to-ground wireless link management server and the RFC 6733 protocol. Then, based on a preset air-to-ground authentication protocol, an authentication request carrying authentication information is sent to the air-to-ground wireless link management server through the air-to-ground communication authentication link. The air-to-ground wireless link management server then uses the authentication information to authenticate the airborne client. The preset air-to-ground authentication protocol is a protocol pre-added to the RFC 6733 protocol. If authentication is successful, a corresponding authentication success notification is received from the air-to-ground wireless link management server, and air-to-ground service communication is initiated through the target service data transmission link selected by the air-to-ground wireless link management server. Through this method, access control for airborne client air-to-ground communication can be achieved, effectively preventing unauthorized users from using the air-to-ground communication link to transmit data, thus improving the security of air-to-ground communication.

[0073] See Figure 8 As shown in the figure, this application also discloses an air-to-ground communication access control device, including:

[0074] The authentication link establishment module 11 is used to establish an air-to-ground communication authentication link with the airborne client based on the RFC 6733 protocol;

[0075] The authentication module 12 is used to obtain the authentication request carrying authentication information sent by the airborne client through the airborne communication authentication link based on the preset air-to-ground authentication protocol, and to authenticate the airborne client using the authentication information. When the authentication is successful, the module returns a corresponding authentication success notification to the airborne client. The preset air-to-ground authentication protocol is a protocol that is added to the RFC 6733 protocol in advance.

[0076] The link selection module 13 is used to filter the target service data transmission link for the airborne client to send service data packets, so that the airborne client can carry out service communication between air and ground through the target service data transmission link.

[0077] As can be seen, in this embodiment, an air-to-ground communication authentication link is first established based on the RFC 6733 protocol with the airborne client. Then, based on a preset air-to-ground authentication protocol, the authentication request carrying authentication information sent by the airborne client through the air-to-ground communication authentication link is obtained, and the authentication information is used to authenticate the airborne client. The preset air-to-ground authentication protocol is a protocol pre-added to the RFC 6733 protocol. If authentication is successful, a corresponding authentication success notification is returned to the airborne client, and a target service data transmission link for sending service data packets is selected for the airborne client, so that the airborne client can conduct air-to-ground service communication through the target service data transmission link. If authentication fails, a corresponding authentication failure notification is returned to the airborne client, and the airborne client is prohibited from using the service data transmission link. Through the above method, access control for air-to-ground communication of the airborne client can be achieved, and unauthorized users can be effectively prohibited from using the service data transmission link to transmit service data packets, thus improving the security of air-to-ground communication.

[0078] In some specific embodiments, the authentication module 12 specifically includes:

[0079] The information authentication unit is used to authenticate the airborne client using the user information and attribute information of the airborne client.

[0080] In some specific embodiments, the air-to-ground communication access control device further includes:

[0081] The permission prohibition module is used to return a corresponding authentication failure notification to the airborne client and prohibit the airborne client from using the business data transmission link if authentication fails.

[0082] In some specific embodiments, the link selection module 13 specifically includes:

[0083] The request acquisition submodule is used to acquire the communication capability negotiation request sent by the airborne client carrying communication capability requirements based on a preset air-to-ground communication negotiation protocol; the preset air-to-ground communication negotiation protocol is a protocol pre-added to the RFC6733 protocol;

[0084] The link determination submodule is used to determine whether there is a service data transmission link that can meet the communication capability requirements. If there is, it returns a corresponding negotiation success notification to the airborne client and filters out the service data transmission links that meet the communication capability requirements as the target service data transmission link.

[0085] In some specific embodiments, the link determination submodule specifically includes:

[0086] The link filtering unit is used to filter out the service data transmission links that match the communication capability requirements from all service data transmission links to obtain the target service data transmission link.

[0087] In some specific embodiments, the request acquisition submodule is specifically used to acquire, based on a preset air-to-ground communication negotiation protocol, a communication capability negotiation request sent by the airborne client, which carries the bandwidth requirement information, preemption type, and QoS level information of the airborne client.

[0088] Furthermore, embodiments of this application also provide an electronic device. Figure 9 This is a structural diagram of an electronic device 20 according to an exemplary embodiment. The content of the diagram should not be construed as limiting the scope of this application.

[0089] Figure 9 This is a schematic diagram of the structure of an electronic device 20 provided in an embodiment of this application. Specifically, the electronic device 20 may include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 stores a computer program, which is loaded and executed by the processor 21 to implement the relevant steps in the air-to-ground communication access control method disclosed in any of the foregoing embodiments. Alternatively, the electronic device 20 in this embodiment may specifically be an electronic computer.

[0090] In this embodiment, the power supply 23 is used to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows can be any communication protocol applicable to the technical solution of this application, and is not specifically limited here; the input / output interface 25 is used to acquire external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs, and is not specifically limited here.

[0091] In addition, the memory 22, as a carrier for resource storage, can be a read-only memory, random access memory, disk or optical disk, etc. The resources stored thereon can include operating system 221 and computer program 222, and the storage method can be temporary storage or permanent storage.

[0092] The operating system 221 is used to manage and control the various hardware devices on the electronic device 20 and the computer program 222, which may be Windows Server, Netware, Unix, Linux, etc. In addition to including a computer program capable of performing the air-to-ground communication access control method executed by the electronic device 20 as disclosed in any of the foregoing embodiments, the computer program 222 may further include a computer program capable of performing other specific tasks.

[0093] Furthermore, this application also discloses a storage medium storing a computer program. When the computer program is loaded and executed by a processor, it implements the steps of the air-to-ground communication access control method disclosed in any of the foregoing embodiments.

[0094] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to in the method section.

[0095] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0096] The air-to-ground communication access control method, apparatus, device, and storage medium provided by the present invention have been described in detail above. Specific examples have been used to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only for the purpose of helping to understand the method and core ideas of the present invention. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of the present invention. Therefore, the content of this specification should not be construed as a limitation of the present invention.

Claims

1. A method for air-to-ground communication access control, characterized in that, Applications include air-to-ground wireless link management servers, including: An air-to-ground communication authentication link between the airborne client and the RFC 6733 protocol is established. The authentication request carrying authentication information sent by the airborne client through the airborne communication authentication link is obtained based on a preset air-to-ground authentication protocol, and the authentication information is used to authenticate the airborne client; the preset air-to-ground authentication protocol is a protocol pre-added to the RFC 6733 protocol; If authentication is successful, a corresponding authentication success notification is returned to the airborne client, and a target business data transmission link for sending business data packets is selected for the airborne client, so that the airborne client can carry out air-to-ground business communication through the target business data transmission link; The step of filtering the target service data transmission links for sending service data packets for the airborne client includes: The communication capability negotiation request carrying communication capability requirements sent by the airborne client is obtained based on a preset air-to-ground communication negotiation protocol; the preset air-to-ground communication negotiation protocol is a protocol pre-added to the RFC 6733 protocol. Determine whether there is a service data transmission link that can meet the communication capability requirements. If there is, return a corresponding negotiation success notification to the airborne client and filter out the service data transmission links that meet the communication capability requirements as the target service data transmission links. The step of obtaining the communication capability negotiation request carrying communication capability requirements sent by the airborne client based on a preset air-to-ground communication negotiation protocol includes: Based on a preset air-to-ground communication negotiation protocol, the communication capability negotiation request sent by the airborne client carries the bandwidth requirement information, preemption type, and QoS level information of the airborne client. The process of selecting service data transmission links that meet the communication capability requirements includes: The target business data transmission link is obtained by selecting the business data transmission link that matches the communication capability requirements from all business data transmission links.

2. The air-to-ground communication access control method according to claim 1, characterized in that, The authentication of the onboard client using the authentication information includes: The airborne client is authenticated using its user information and attribute information.

3. The air-to-ground communication access control method according to claim 1, characterized in that, After authenticating the onboard client using the authentication information, the process further includes: If authentication fails, a corresponding authentication failure notification is returned to the airborne client, and the airborne client is prohibited from using the business data transmission link.

4. A method for air-to-ground communication access control, characterized in that, Applied to airborne clients, including: An air-to-ground communication authentication link is established between the air-to-ground wireless link management server and the RFC 6733 protocol. Based on a preset air-to-ground authentication protocol, an authentication request carrying authentication information is sent to the air-to-ground wireless link management server through the air-to-ground communication authentication link, so that the air-to-ground wireless link management server can use the authentication information to authenticate the airborne client; the preset air-to-ground authentication protocol is a protocol pre-added to the RFC 6733 protocol. If authentication is successful, the system receives the corresponding authentication success notification from the air-to-ground wireless link management server and initiates air-to-ground business communication through the target business data transmission link selected by the air-to-ground wireless link management server. If authentication is successful, the system receives a corresponding authentication success notification from the air-to-ground wireless link management server, including: If authentication is successful, the system receives a success notification from the air-to-ground wireless link management server. Then, based on a preset air-to-ground communication negotiation protocol, it sends a communication capability negotiation request carrying communication capability requirements to the air-to-ground wireless link management server. This allows the air-to-ground wireless link management server to determine if a service data transmission link exists locally that can meet the communication capability requirements. The preset air-to-ground communication negotiation protocol is a protocol pre-added to the RFC 6733 protocol. If a link exists, the system receives a negotiation success notification from the air-to-ground wireless link management server and initiates air-to-ground service communication through the target service data transmission link selected by the air-to-ground wireless link management server. The communication capability requirements include the airborne client's bandwidth requirements, preemption type, and QoS level information. The target service data transmission link is a service data transmission link selected by the air-to-ground wireless link management server from all service data transmission links that matches the communication capability requirements.

5. An air-to-ground communication access control device, characterized in that, include: The authentication link establishment module is used to establish an air-to-ground communication authentication link with the airborne client based on the RFC 6733 protocol. The authentication module is used to obtain the authentication request carrying authentication information sent by the airborne client through the airborne communication authentication link based on the preset air-to-ground authentication protocol, and to authenticate the airborne client using the authentication information. When the authentication is successful, the module returns a corresponding authentication success notification to the airborne client. The preset air-to-ground authentication protocol is a protocol pre-added to the RFC 6733 protocol; The link selection module is used to filter the target service data transmission link for the airborne client to send service data packets, so that the airborne client can carry out air-to-ground service communication through the target service data transmission link. The request acquisition submodule is used to acquire the communication capability negotiation request sent by the airborne client carrying communication capability requirements based on a preset air-to-ground communication negotiation protocol. The preset air-to-ground communication negotiation protocol is a protocol pre-added to the RFC 6733 protocol; The link determination submodule is used to determine whether there is a service data transmission link that can meet the communication capability requirements. If there is, it returns a corresponding negotiation success notification to the airborne client and filters out the service data transmission links that meet the communication capability requirements as the target service data transmission link. The request acquisition submodule is specifically used to acquire, based on a preset air-to-ground communication negotiation protocol, a communication capability negotiation request sent by the airborne client, which carries the bandwidth requirement information, preemption type and QoS level information of the airborne client. The link filtering unit is used to filter out the service data transmission links that match the communication capability requirements from all service data transmission links to obtain the target service data transmission link.

6. An electronic device, characterized in that, The electronic device includes a processor and a memory; wherein the memory is used to store a computer program, which is loaded and executed by the processor to implement the air-to-ground communication access control method as described in any one of claims 1 to 4.

7. A computer-readable storage medium, characterized in that, Used to store computer-executable instructions, which, when loaded and executed by a processor, implement the air-to-ground communication access control method as described in any one of claims 1 to 4.