A method for establishing a secure connection between a drone and a control console

By authenticating and encrypting data when the drone is connected to the console, the efficient connection and data confidentiality problems in the case of limited resources of the drone are solved, and fast connection and efficient encrypted transmission are achieved.

CN116132984BActive Publication Date: 2025-05-06ZHEJIANG UNIV OF TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211558233.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-06
Publication Date
2025-05-06
Estimated Expiration
2042-12-06

AI Technical Summary

Technical Problem

During the connection between the drone and the console, it is difficult for the prior art to achieve efficient connections with limited resources while ensuring the confidentiality of data transmission.

Method used

Start the authentication process and data encryption by sending a connection request to the console when the drone is first turned on and after confirming the drone's identity on the console. The specific steps include sending the fuselage sequence code and parameters by the drone, authenticating the console and selecting a suitable encryption algorithm, and intermittently encrypting the data and decomposing and transmitting it.

Benefits of technology

It realizes efficient connections under limited drone resources, shortens business establishment time, and improves data confidentiality and encryption efficiency through encryption algorithms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116132984B_ABST
    Figure CN116132984B_ABST
Patent Text Reader

Abstract

A method for establishing a secure connection between a drone and a control console. When the drone is turned on for the first time, it sends a connection request to the drone control console. After the control console receives the connection request message, it sends an identity query request to the drone. After the drone receives the identity query request, it sends its own fuselage serial code and parameters to the control console. After the control console confirms the identity of the drone, it starts the drone authentication process, and after the authentication is completed, it uses an encryption algorithm to encrypt the data. After the control console accepts the drone's connection request, it sends a message of agreeing to connect to the drone. After the drone receives the message, it replies to the control console with a message of completing the connection, indicating that the connection is completed. The present invention further shortens the time for the drone to connect to the control console, and also improves the encryption strength of the data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of unmanned aerial vehicle wireless communication, and in particular to a method for connecting an unmanned aerial vehicle to a control console. Background Art

[0002] In recent years, with the development of wireless communication technology and the decline in the manufacturing cost of drones, drone wireless communication technology has gradually become a current research hotspot, and it has a very wide range of application scenarios, such as aerial photography, traffic control, cargo transportation, military fields, and disaster relief. In the field of wireless communication, two or more parties can only transmit information after establishing a connection with each other, and data transmission involves confidentiality and security issues. Therefore, reducing the connection time and ensuring the security of data transmission are important indicators of wireless communication technology. How to connect as efficiently as possible and ensure the confidentiality of data transmission under limited drone resources is very critical.

[0003] Obviously, the methods used to establish data transmission in the field of wireless communications are different, and different methods mean different data encryption methods. Therefore, a method suitable for establishing a connection between the drone and the console is crucial. The most critical thing is to choose a method that ensures efficient connection while ensuring data security. Summary of the invention

[0004] In view of this, in view of the connection time and data confidentiality issues existing in the above-mentioned drone connection console, the present invention provides a more efficient and confidential method for drone connection console

[0005] The technical solution of the present invention is:

[0006] A method for establishing a secure connection between a drone and a control console, the method comprising the following steps:

[0007] 1) When the drone is powered on for the first time, a connection request is sent to the drone console;

[0008] 2) After receiving the connection request message, the console sends an identity query request to the drone;

[0009] 3) After receiving the identity query request, the drone sends its own fuselage serial code and parameters to the console;

[0010] 4) After the console confirms the identity of the drone, it starts the drone authentication process and after the authentication is completed, it uses an encryption algorithm to encrypt the data;

[0011] 5) After the console accepts the drone's connection request, it sends a message to the drone agreeing to the connection;

[0012] 6) After receiving the message, the drone replies to the console with a message indicating that the connection is complete;

[0013] Furthermore, in step 1), information such as the device model, system configuration, and supported encryption algorithms of the drone are added to the connection request message sent by the drone to the console, and the console adjusts its own parameter configuration based on this information; while the drone sends a connection request to the console, it also requests a data network connection from the console.

[0014] Furthermore, in step 2), after the drone control console receives the identity query request from the drone, it uses the console's user server system to extract the drone-related security information from the drone's fuselage serial code and parameters, and after obtaining the drone-related authentication 4-tuple, sends an authentication request message to the drone.

[0015] Furthermore, the authentication 4-tuple includes a random number RAND, an expected authentication response XRES, K ASNE and authentication token AUTN; the drone generates an authentication response RES through the authentication algorithm based on the RAND and AUTN contained in the authentication request message, and sends it to the console; the console determines whether the authentication is successful by comparing whether RES and XRES are equal. If they are equal, it means that the authentication is successful and the drone user is a legitimate user.

[0016] In step 6), the data encryption operation is initiated by the console. The console determines the data encryption algorithm supported by itself and the drone in the encryption algorithm list in the user server system, and puts the algorithm into an encryption command message and sends it to the drone. After receiving the message, the drone starts data encryption according to the algorithm and replies to the console with a message that the encryption is completed.

[0017] The data encryption algorithm decomposes the data to be sent into at least two parts in an intermittent manner according to a set functional relationship, and uses different encryption functions in the algorithm to encrypt the decomposed data, and then marks the encrypted decomposed data and puts them into different logical channels on the transmission channel for transmission. After receiving the encrypted data, the receiving end decrypts the received data through the corresponding decryption function, and finally combines the decomposed data into the original data according to the corresponding combination function;

[0018] After data encryption is completed, the corresponding drone context is created in the console, and the bearer is established through the interaction between the console and the service gateway and the data gateway; after the interaction is completed, the console sends a message to the drone agreeing to the connection, and assigns an identification and timer information to the drone after the drone joins the console.

[0019] When the console accepts the drone connection, it sends a bearer context activation request to the drone and adds the bearer configuration, the ID, IP address, APN and service quality level identifier QCI information assigned by the core network to the message. The drone establishes the bearer according to the content of the bearer establishment message and sends a bearer establishment response message to the console, indicating that the bearer is established successfully and the drone context is complete.

[0020] By adopting the above structure, the present invention has the following advantages compared with the prior art: the method of connecting the drone to the control console can greatly shorten the time of establishing the service, and the data flow set by the method is very tight, which can greatly reduce the processing delay; the data encryption algorithm used in the method first decomposes the data in an intermittent manner and then encrypts it, and then uses different channels for transmission, which increases the difficulty of encryption and decryption and can enhance the confidentiality of the data, and after the data is split, it can reduce the amount of calculation of the system, thereby improving the efficiency of encryption and decryption. Under the technology of the present invention, while further shortening the time of connecting the drone to the control console, it also improves the encryption strength of the data. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] Figure 1 A flowchart of connecting a drone to a console provided by the present invention;

[0022] Figure 2 A flowchart of the console provided by the present invention obtaining the identity of the drone;

[0023] Figure 3 The flowchart of the authentication interaction between the drone and the console provided by the present invention;

[0024] Figure 4 This is a diagram of the data encryption processing process provided by the present invention. DETAILED DESCRIPTION

[0025] The present invention will be further described below in conjunction with the accompanying drawings.

[0026] Reference Figure 1 to Figure 4 A method for establishing a secure connection between a drone and a control console, the method comprising the following steps:

[0027] 1) When the drone is powered on for the first time, a connection request is sent to the drone console;

[0028] 2) After receiving the connection request message, the console sends an identity query request to the drone;

[0029] 3) After receiving the identity query request, the drone sends its own fuselage serial code and parameters to the console;

[0030] 4) After the console confirms the identity of the drone, it starts the drone authentication process and after the authentication is completed, it uses an encryption algorithm to encrypt the data;

[0031] 5) After the console accepts the drone's connection request, it sends a message to the drone agreeing to the connection;

[0032] 6) After receiving the message, the drone replies to the console with a message indicating that the connection is complete;

[0033] In step 1), when the drone sends a connection request to the console, the drone's device model, system configuration, supported encryption algorithm and other information are added to the message, and the console adjusts its own parameter configuration based on this information. In addition, when the drone sends a connection request to the console, it also requests a data network connection from the console to facilitate future data transmission. For example, when using a drone for aerial photography, the drone needs to use a data network to transmit the captured pictures or videos to the console.

[0034] In step 2), after receiving the connection request from the drone, the drone console will query whether there is an identification of the drone in the system through its own user server system. If not, it will send an identity query request to the drone. After receiving the identity query request replied by the drone, the console will use the user server system to extract the drone-related security information from the received drone's fuselage serial code and parameters, and after obtaining the drone-related authentication 4-tuple, send an authentication request message to the drone.

[0035] The authentication 4-tuple contains the random number RAND, the expected authentication response XRES, K ASNE The authentication request message sent by the console to the drone contains the two parameters RAND and AUTN. The drone generates an authentication response RES based on the received RAND and AUTN and the authentication algorithm, and sends it to the console. The console determines whether the authentication is successful by comparing whether RES and XRES are equal. If they are equal, it indicates that the authentication is successful, which means that the drone user is a legitimate user.

[0036] After authentication, the console will initiate a data encryption operation to the drone. First, the console will determine the data encryption algorithm supported by itself and the drone in the encryption algorithm list in the user server system, and put the algorithm into the encryption command message and send it to the drone. After the drone receives the message, it starts data encryption according to the algorithm and replies to the console with a message that encryption is complete. After the drone and the console complete data encryption for the first time, in subsequent data reception and transmission, encryption and decryption will be automatically performed according to the algorithm determined in this encryption operation.

[0037] The above data encryption algorithm will set a data decomposition function, and add an intermittent process to the decomposition function. The decomposition function can decompose the data to be sent into at least two parts. The intermittent process is to ensure that the decomposed data is not coherent. After the data processing is completed, the data is encrypted using different encryption functions in the algorithm, which can greatly improve the encryption strength. In order to facilitate transmission control, different tags can be added before data transmission, and then the encrypted decomposed data can be placed in different logical channels on the transmission channel for transmission. After the receiving end receives the encrypted data, it decrypts the received data through the corresponding decryption function, and then the data can be restored according to the corresponding combination function.

[0038] In the step 6), after the data encryption is completed, the console will create a corresponding drone context in the system, and establish a bearer through the interaction between the console and the service gateway and the data gateway. After the interaction is completed, the console sends a message to the drone agreeing to connect, and adds the identifier and timer information assigned by the console to the drone to facilitate the identification of the drone in the future. When the console accepts the drone connection, it sends a request to activate the bearer context to the drone, and adds the configuration of the bearer, the ID assigned by the core network to the bearer, the IP address, the APN and the service quality level identifier (QCI) and other information to the message. In order to save system resources, the QCI of the bearer is usually set to 9, which has the lowest priority. The drone establishes the bearer according to the content of the bearer establishment message, and sends a bearer establishment response message to the console, indicating that the bearer is successfully established and the drone context is complete. Finally, the drone will send a connection success message to the console, which indicates that the drone and the console have been successfully connected.

[0039] The present invention is described in further detail above by combining specific examples, but the specific implementation of the present invention is not limited to the above description. In short, for the relevant content of the present invention, any simple calculation or substitution made within the protection scope of the claims of the present invention is within the protection scope of the present invention.

Claims

1. A method for establishing a secure connection between a drone and a control console, characterized in that: The method comprises the following steps: 1) When the drone is powered on for the first time, it sends a connection request to the console; 2) After receiving the connection request message, the console sends an identity query request to the drone; 3) After receiving the identity query request, the drone sends its own fuselage serial code and parameters to the console; 4) After the console confirms the identity of the drone, it starts the drone authentication process and after the authentication is completed, it uses an encryption algorithm to encrypt the data; 5) After the console accepts the drone’s connection request, it sends a message to the drone agreeing to the connection; 6) After receiving the message, the drone replies to the console with a message indicating that the connection is complete; In step 3), after receiving the identity query request from the drone, the console uses the user server system of the console to extract the drone-related security information from the drone's fuselage serial code and parameters, and after obtaining the drone-related authentication 4-tuple, sends an authentication request message to the drone; The authentication 4-tuple includes a random number RAND, an expected authentication response XRES, K ASNE and authentication token AUTN; the drone generates an authentication response RES through the authentication algorithm according to the RAND and AUTN contained in the authentication request message, and sends it to the console; the console determines whether the authentication is successful by comparing whether RES and XRES are equal. If they are equal, it means that the authentication is successful and the drone user is a legitimate user; After data encryption is completed, the corresponding drone context is created in the console, and the console interacts with the service gateway and the data gateway to establish a bearer; after the interaction is completed, the console sends a message to the drone agreeing to connect, and assigns an identifier and timer information to the drone after the drone joins the console; When the console accepts the drone connection, it sends a bearer context activation request to the drone and adds the bearer configuration, the ID, IP address, APN and service quality level identifier QCI information assigned by the core network to the message. The drone establishes the bearer according to the content of the bearer establishment message and sends a bearer establishment response message to the console, indicating that the bearer is established successfully and the drone context is complete.

2. The method for establishing a secure connection between a drone and a control console according to claim 1, characterized in that: In the step 1), the device model, system configuration and supported encryption algorithm information of the drone are added to the connection request message sent by the drone to the console, and the console adjusts its parameter configuration according to this information; while the drone sends the connection request to the console, it also requests a data network connection from the console.

3. The method for establishing a secure connection between a drone and a control console according to claim 1 or 2, characterized in that: In step 6), the data encryption operation is initiated by the console. The console determines the data encryption algorithm supported by itself and the drone in the encryption algorithm list in the user server system, and puts the algorithm into an encryption command message and sends it to the drone. After receiving the message, the drone starts data encryption according to the algorithm and replies to the console with a message that the encryption is completed.

4. The method for establishing a secure connection between a drone and a control console according to claim 3, characterized in that: The data encryption algorithm decomposes the data to be sent into at least two parts in an intermittent manner according to the set functional relationship, and uses different encryption functions in the algorithm to encrypt the decomposed data. The encrypted decomposed data is marked and placed in different logical channels on the transmission channel for transmission. After the receiving end receives the encrypted data, it decrypts the received data through the corresponding decryption function, and finally combines the decomposed data into the original data according to the corresponding combination function.

Citation Information

Patent Citations

  • Authentication connection method based on TD-LTE wireless communication network and base station

    CN106034300A

  • Flight equipment management method and device, equipment and storage medium

    CN114093201A