UAV Communication Data Processing Method and System Based on TUMIA
By adopting the TUMIA-based drone communication data processing method in the drone communication system, multi-domain drones are pooled into clusters, and the problem of drone communication data being susceptible to interference and eavesdropping in complex environments is solved, thereby achieving efficient and secure drone cluster communication.
Patent Information
- Application Number
- CN202411275916.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-12
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2044-09-12
AI Technical Summary
UAV communication data is easily disturbed in complex electromagnetic environments and has the risk of eavesdropping and tampering. Especially in multi-domain drone group communication, it is difficult to achieve cross-domain authentication and confidential communication.
UAV communication data processing methods and systems based on TUMIA (Three-or-more-layer Unified Multi-domain Identifier Authentication) are adopted to temporarily gather multi-domain drones into clusters or swarms, and multi-machine collaboration is realized using TUMIA technology to ensure the secure transmission and authentication of instruction data by encrypting communication data and signature information.
It realizes efficient processing and secure transmission of UAV communication data in complex electromagnetic environments, ensures the reliability and security of command data transmission between drone groups, and avoids the risks of signal interference and data leakage.
Smart Images

Figure CN119052784B_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present disclosure relate to the field of information security technology, and more particularly to a method and system for processing UAV communication data based on TUMIA (Three-or-more-layer Unified Multi-domain Identifier Authentication). Background Art
[0002] A UAV system mainly consists of the following parts: a UAV airframe (including power), a flight control system, a ground command and control system, a communication link system, an on-board equipment system (aerial photography equipment, weapon equipment, etc.), a launch and recovery system, etc.
[0003] The ground command center is connected to the UAVs, and the UAVs are connected to each other through wireless communication. It is extremely vulnerable to interference from the external complex electromagnetic environment. In the case of interference, the UAV may not receive the signal, or even if it receives the signal, it cannot determine its correctness. In addition, the communication data between the command center and the UAVs, and the communication data between the UAV swarms are at risk of being eavesdropped and tampered with without protection. Summary of the Invention
[0004] The purpose of the embodiments of the present disclosure is to provide a method and system for processing UAV communication data based on TUMIA, which temporarily aggregates UAVs from multiple domains into clusters or swarms, and uses TUMIA technology to achieve excellent performance of multi-UAV cooperation.
[0005] In a first aspect of the embodiments of the present disclosure, a method for processing UAV communication data based on TUMIA is provided. The method is applied to a UAV command center, and the method includes: sending encrypted communication data to the cluster head UAV in a specified cluster, where the encrypted communication data includes an encrypted cluster head UAV identifier, a UAV command center identifier, instruction data, and signature information, so that the cluster head UAV broadcasts the instruction data to other cluster member UAVs in the specified cluster; receiving an acknowledgment message replied by the cluster head UAV, where a cluster is a cluster composed of several UAVs from different domains, and a cluster head is a UAV that forwards the instruction data sent by the UAV command center to other UAVs in its cluster.
[0006] In some embodiments of the present disclosure, the method further includes: receiving a registration message sent by a drone and signature information of the registration message, where the registration message includes the drone identifier, the drone's accompanying public key, location information, a drone random number, and a registration request; determining the public key of the drone according to the drone identifier, and verifying the signature information by using the public key of the drone; after the signature information is verified successfully, sending a feedback message and signature information of the feedback message to the drone, and generating a session key between the drone command center and the drone, where the feedback message includes the drone command center identifier, the center's accompanying public key, and a center random number; receiving a verification code returned by the drone, and verifying the verification code by using the session key; when the verification code is verified correctly, determining that the drone is successfully registered in the drone command center, and adding the drone to the command queue of the drone command center, so as to classify the drone into a specified cluster.
[0007] In some embodiments of the present disclosure, after determining that the drone is successfully registered in the drone command center, the method further includes: encrypting a clustering instruction by using the session key between the drone command center and the drone, and sending the encrypted clustering instruction to the drone, where the clustering instruction includes a cluster name, a cluster member list, and roles within the cluster, and the roles within the cluster include a cluster head and cluster members.
[0008] In some embodiments of the present disclosure, the instruction data includes: cluster member list update data.
[0009] A second aspect of the embodiments of the present disclosure provides a method for processing drone communication data based on TUMIA. A cluster is a group of several drones from different domains, and a cluster head is a drone that forwards instruction data sent by the drone command center to other drone members in its cluster. The method is applied to drones within the cluster, and the method includes: when the cluster head drone within the cluster receives the encrypted communication data sent by the drone command center, the cluster head drone decrypts the encrypted communication data, and verifies the signature information in the decrypted encrypted communication data by using the public key of the drone command center. The encrypted communication data includes the encrypted cluster head drone identifier, the drone command center identifier, instruction data, and signature information; after the signature information is verified successfully, the cluster head drone replies to the drone command center with an acknowledgement message; the cluster head drone encrypts the instruction data by using a cluster broadcast key, and broadcasts the encrypted instruction data to other cluster member drones in the cluster where the cluster head drone is located.
[0010] In some embodiments of the present disclosure, the method further includes the registration process of all the drones within a cluster with the drone command center: sending a registration message and the signature information of the registration message to the drone command center, where the registration message includes the drone identifier, the drone accompanying public key, the location information, the drone random number, and the registration request; receiving the feedback message and the signature information of the feedback message sent by the drone command center, where the feedback message includes the drone command center identifier, the center accompanying public key, and the center random number; verifying the signature information of the feedback message using the public key of the drone command center; when the signature information is verified successfully, generating a session key between the drone command center and the drone; generating a verification code using the session key, and sending the verification code to the drone command center for verification to determine whether to include the drone in the command queue of the drone command center.
[0011] In some embodiments of the present disclosure, the method further includes: receiving a clustering instruction sent by the drone command center, where the clustering instruction includes the cluster name, the cluster member list, and the roles within the cluster, and the roles within the cluster include the cluster head and the cluster members.
[0012] In some embodiments of the present disclosure, after receiving the clustering instruction sent by the drone command center, the method further includes: the cluster head drone within the cluster receives the intra-cluster registration message and the signature information of the intra-cluster registration message sent by the cluster member drones within the corresponding cluster, where the intra-cluster registration message includes the cluster member drone identifier, the cluster member drone accompanying public key, the cluster member drone random number, and the intra-cluster registration request; the cluster head drone determines the public key of the cluster member drone according to the cluster member drone identifier, and verifies the signature information of the intra-cluster registration message using the public key of the cluster member drone; when the signature information of the intra-cluster registration message is verified successfully, the cluster head drone sends a reply message and the signature information of the reply message to the cluster member drone, and generates a session key between the cluster head drone and the cluster member drone, where the reply message includes the cluster head drone identifier, the cluster head drone accompanying public key, and the cluster head drone random number; the cluster head drone receives the verification code returned by the cluster member drone, and verifies the verification code using the session key between the cluster head drone and the cluster member drone; when the verification code is verified correctly, it is determined that the cluster member drone is successfully registered within the cluster head drone cluster, and the generated cluster broadcast key is encrypted using the session key between the cluster head drone and the cluster member drone and sent to the corresponding cluster member drone; when the cluster head drone receives the cluster broadcast key acknowledgement message replied by the cluster member drone, it encrypts the local cluster member list using the cluster broadcast key and broadcasts it within the cluster.
[0013] In some embodiments of the present disclosure, when the instruction data is cluster member list update data, the method further includes: the cluster head UAV updates the local cluster member list using the cluster member list update data and generates a new cluster broadcast key; the cluster head UAV encrypts the new cluster broadcast key using the session key between it and the cluster member UAVs and sends it to the corresponding cluster member UAVs respectively; when the cluster head UAV receives the acknowledgement message of the new cluster broadcast key replied by the cluster member UAVs, it encrypts the updated local cluster member list using the new cluster broadcast key and broadcasts it within the cluster.
[0014] The third aspect of the embodiments of the present disclosure provides a UAV communication data processing system for a unified multi-domain identity public key processing system TUMIA based on a three-layer or higher structure. The system includes: multiple UAVs and a UAV command center. Among them, the multiple UAVs include N hierarchical domains, an identity mapping public key IMPK architecture from the first hierarchical domain to the N-1th hierarchical domain, and an identity binding public key IBPK architecture of the Nth hierarchical domain, N≥3. A cluster is a group of several UAVs from different domains, and the cluster head is a UAV that forwards the instruction data sent by the UAV command center to other UAVs in its cluster. Among them, the UAV command center is used to: send encrypted communication data to the cluster head UAV in a specified cluster, and the encrypted communication data includes the encrypted cluster head UAV identifier, the UAV command center identifier, the instruction data, and the signature information, so that the cluster head UAV broadcasts the instruction data to other cluster member UAVs in the specified cluster; receive the acknowledgement message replied by the cluster head UAV; the cluster head UAV in the specified cluster is used to: when receiving the encrypted communication data sent by the UAV command center, decrypt the encrypted communication data and verify the signature information in the encrypted communication data after decryption using the public key of the UAV command center. The encrypted communication data includes the encrypted cluster head UAV identifier, the UAV command center identifier, the instruction data, and the signature information; when the signature information is verified to be passed, reply an acknowledgement message to the UAV command center; encrypt the instruction data using the cluster broadcast key and broadcast the encrypted instruction data to other cluster member UAVs in the cluster where the cluster head UAV is located.
[0015] Other features and advantages of the embodiments of the present disclosure will be described in detail in the subsequent specific implementation part. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] The drawings are used to provide a further understanding of the embodiments of the present disclosure, and constitute a part of the specification. Together with the following specific implementation, they are used to explain the embodiments of the present disclosure, but do not constitute a limitation to the embodiments of the present disclosure. In the drawings:
[0017] Figure 1It is a schematic diagram of the identifiers of each terminal corresponding to the four-level TUMIA identifier management mode provided by an embodiment of the present disclosure;
[0018] Figure 2 It is a schematic diagram of the overall architecture of unmanned aerial vehicle (UAV) secure communication provided by an embodiment of the present disclosure;
[0019] Figure 3 It is a schematic flowchart of a method for processing UAV communication data based on TUMIA provided by an embodiment of the present disclosure;
[0020] Figure 4 It is a schematic flowchart of another method for processing UAV communication data based on TUMIA provided by an embodiment of the present disclosure;
[0021] Figure 5 It is a schematic flowchart of the registration process between UAV members and the UAV command center provided by an embodiment of the present disclosure;
[0022] Figure 6 It is a schematic flowchart of the clustering process of cluster member UAVs provided by an embodiment of the present disclosure;
[0023] Figure 7 It is a schematic flowchart of the process for the UAV command center to issue commands provided by an embodiment of the present disclosure;
[0024] Figure 8 It is a schematic flowchart of the update process of the cluster member list and the cluster broadcast key provided by an embodiment of the present disclosure;
[0025] Figure 9 It is a schematic diagram of a system for processing UAV communication data based on TUMIA provided by an embodiment of the present disclosure. Detailed implementation manners
[0026] To make the objectives, technical solutions, and advantages of the embodiments of the present disclosure clearer, the technical solutions of the embodiments of the present disclosure will be clearly and completely described below with reference to the accompanying drawings. Apparently, the described embodiments are some but not all of the embodiments of the present disclosure. All other embodiments obtained by those skilled in the art based on the described embodiments of the present disclosure without creative efforts shall also fall within the scope of protection of the present disclosure.
[0027] Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by those skilled in the art to which the subject matter of the present disclosure belongs. Further, it will be understood that terms such as those defined in commonly used dictionaries shall be interpreted as having a meaning consistent with their meaning in the context of the specification and the relevant art, and shall not be interpreted in an idealized or overly formal form unless otherwise clearly defined herein.
[0028] Since a single unmanned aerial vehicle (UAV) is prone to failures during mission execution, multiple UAVs are usually selected to form a self-organizing network during mission execution. Generally, the self-organizing network is divided into two networking modes: flat and distributed. In the flat self-organizing network networking mode, all nodes have equal status and are interconnected, but this requires huge communication overhead, which is obviously not suitable for large networks such as multi-UAV formations. In the distributed self-organizing network networking mode, the network is divided into several clusters, and communication is carried out through the method of cluster head UAVs and cluster member UAVs, which is more suitable for large networks such as multi-UAV formations. Simply put, several (usually dozens or hundreds) of UAVs act collectively, and one of them is designated as the "head", which is called the "cluster head", and these UAVs form a cluster. Several clusters act together under unified command to form a swarm.
[0029] Based on the characteristics of high-speed movement of UAVs in the air, their communication method must be wireless communication, mainly including 4G communication, self-organizing network communication, Beidou short message communication, and civil satellite high-throughput communication, etc. These communications are undoubtedly exposed to the external environment. Without protection, the communication link is extremely likely to become the focus of attention of attackers, posing a huge threat to the security of the communication link. It is mainly manifested in: facing the risk of signal interference attack; facing the risk of data leakage; facing the risk of information deception attack.
[0030] In response to the above risks, for the complex situation of multi-cluster swarms from multiple domains, it is obviously inappropriate to only use the symmetric algorithm method, because using different symmetric keys between each pair is very difficult for key management alone, and it is even more impossible to achieve cross-domain authentication and secure communication. Using a combination of asymmetric and symmetric algorithms has more advantages. However, in this case, since authentication and secure communication need to be carried out between the UAV and the command center, and between UAVs, both the command center and the UAVs must have their own public and private key pairs, and the public keys must meet the conditions for cross-domain authentication. Using certificates can naturally achieve cross-domain authentication. But even without considering the cost, the authentication of the certificate chain will increase the delay and is not suitable for application in this complex scenario.
[0031] The TUMIA technology has the characteristics of certificate-free cross-domain authentication, and cross-domain authentication is as fast and convenient as intra-domain authentication, with obvious advantages. The embodiments of the present disclosure are based on the TUMIA technology to construct authentication and secure communication suitable for complex UAV scenarios, which can be widely applied to various industries such as military, agriculture, and electric power.
[0032] Given the large number of drones described in the embodiments of the present disclosure and the special requirements of multi - center flat command and management, a four - level TUMIA identity management mode can be adopted in the embodiments of the present disclosure. Among them, the first - level domain to the third - level domain are IMPK (Identity Map to Public Key) architectures, and the fourth - level domain is an IBPK (Identity Bound Public Key) architecture. Among them, the IMPK architecture is used to generate the key base of the first - level domain according to a preset mapping function, using the key base of the root domain and the identity of the first - level domain, and starting from the second - level domain, according to the preset mapping function, using the key base of the previous - level domain and the identity of this level domain, to generate the key base of this level domain. The IBPK architecture is used to generate and distribute the keys corresponding to the terminals within the fourth - level domain managed by it and the accompanying public keys.
[0033] The identities of each terminal corresponding to the four - level TUMIA identity management mode are as Figure 1 shown, consisting of four parts: a global identity of 128 bits, a large - domain identity of 32 bits, a medium - domain identity of 16 bits, a domain (also known as an implementation domain or a base domain, which manages specific personnel and devices) identity of 16 bits, and an in - domain identity of 64 bits. In the embodiments of the present disclosure, taking the headquarters as the root domain, the root domain is responsible for allocating large - domain identities and for defining a set of private - key bases and corresponding public - key bases. Let the private - key base be , and the corresponding public - key base be . Usually, m = 64 can be set for the four - level TUMIA identity management mode. Among them, the public - key base is a public parameter that is globally public and is uniformly released by the root domain. At the same time, the root domain is responsible for distributing public and private - key bases to the large domains. The large domain is responsible for allocating medium - domain identities to the medium domains under it and for distributing public and private - keys to the medium domains. The medium domain is responsible for allocating domain identities and for distributing public and private - keys to the domains. Among them, it is necessary to calculate the public - key bases of the large domain and the medium domain respectively, then calculate the domain public key, and finally calculate the terminal public key.
[0034] The IMPK mapping from the root domain to the large domain is jointly determined by the preset mapping function . When is the private - key base, the output of the function is a k - element subset of the private - key base. Usually, k = 16 can be set. When is the public - key base, the output of the function is a k - element subset of the public - key base. The result of this mapping is the private - key base and the public - key base of the large domain.
[0035] In the embodiments of the present disclosure, the preset mapping function is any one of the following mapping methods:
[0036] The first identification indication method corresponds each public key factor in the public key base of the previous-level domain with each identification bit in the identification of the current-level domain, extracts the public key factors in the public key base of the previous-level domain corresponding to 1 in the identification of the current-level domain as the public key base of the current-level domain. Taking the identification of the large domain as 64 bits as an example, it contains 32 1s and 32 0s, where 1 indicates selecting the corresponding public key or private key factor, and 0 indicates not selecting the corresponding public key or private key factor. In this way, the mapping from the large domain identification to its corresponding large domain public key base (or private key base) is indicated by the identification itself, that is, the positions of 1s in the large domain identification determine how to select the large domain's public key base (private key base) from the global public key base (private key base). Generally, when m = 2f, the identification bits of the large domain in the identification indication method should be m bits, with exactly f 1s and f 0s.
[0037] The second identification table building method uses a preset correspondence table containing the correspondence between identifications and public key bases to find the public key base corresponding to the identification of the current-level domain. When the number of large domains is small, for example, when the number of large domains is less than 256, 8 bits can be used to identify the large domain, and a correspondence table is established. The table gives the correspondence between the large domain identification and its public key base (private key base). Since the number of large domains is small, a table with no more than 256 rows can determine the mapping.
[0038] The third identification calculation method first sets 32 1s, then calculates the hash value 16 times using the identification of the large domain until 32 0s are generated, and then determines 32 elements according to the identification indication method to generate the public key (private key) base of the large domain from the global public key (private key) base.
[0039] Similarly, from the large domain to the medium domain, through a preset mapping function, the public key (private key) base of the medium domain is finally obtained.
[0040] In addition, the IMPK mapping from the medium domain to the domain is also an injection, which is composed of the following two functions in combination:
[0041] Formula (1)
[0042] Formula (2)
[0043] And . Therefore, it is a function jointly determined by the medium domain public key base and the domain identification, and the result is to generate the public and private key pairs of the domain.
[0044] The identification indication method can be used, or the identification calculation method can be used, or the same calculation method as UMIA can be used. For example, when is 4 selected from 16, then It is evenly divided into 4 segments, each segment being 64 bits. They are respectively multiplied by four selected key parameters and then added together to obtain the key of the domain. Let the four selected parameters be , and they are divided into four segments which are respectively , then the calculation formula is as follows:
[0045] Formula (3)
[0046] When is the public key, the calculation result is which is the domain public key; when is the private key, the calculation result is which is the domain private key.
[0047] The headquarters as the root domain is responsible for allocating the large domain identifier and the key base. The large domain is responsible for allocating the identifier and key base of the medium domain. The medium domain is responsible for allocating the identifier of the domain and the public and private key pairs. The domain is responsible for allocating the identifier and private key of the drones under its jurisdiction. The premise for implementing this embodiment of the present disclosure is that the public and private key bases (large domain, medium domain) or public and private key pairs (domain) have been allocated according to the TUMIA method, and the private key and the accompanying public key have been distributed to the central gateway and each drone. That is to say, in the overall architecture of drone secure communication as shown in Figure 2 , it mainly includes multiple drones, a drone command center, and the TUMIA security components of all parties. Among them, the TUMIA security components include the security module at the drone end and the secure communication gateway at the drone command center end, that is, Figure 2 The part within the thick solid line box in belongs to the TUMIA-based drone communication data processing system described in this embodiment of the present disclosure. At the drone end, the drone adaptation and the TUMIA secure communication module are responsible for secure authentication and confidential communication, and can be docked with the flight control system. It is responsible for both authenticating with the communication object (drone command center or other drones) and data encryption and decryption, and passing the command data to the drone flight control system. At the drone command center end, the drone command system and the drone management system do not belong to the TUMIA-based drone communication data processing system, while the TUMIA secure communication gateway within the thick solid line box belongs to the TUMIA-based drone communication data processing system. The communication gateway provides the authentication and confidential communication functions with the communication object on the side of the drone command center. The private key and the accompanying public key have been distributed in both the secure communication gateway of the drone command center and the TUMIA secure communication module of the drone.
[0048] As shown in Figure 3 , this embodiment of the present disclosure provides a flowchart of a method for processing drone communication data based on TUMIA. As shown in Figure 3 , the method is applied to a drone command center, and the method includes the following steps:
[0049] Step 310, send encrypted communication data to the cluster head UAV in the specified cluster. The encrypted communication data includes the encrypted cluster head UAV identifier, the UAV command center identifier, command data, and signature information, so that the cluster head UAV broadcasts the command data to other cluster member UAVs in the specified cluster;
[0050] Step 320, receive the receipt message replied by the cluster head UAV.
[0051] Among them, a cluster is a cluster composed of several UAVs from different domains, and the cluster head is the UAV that forwards the command data sent by the UAV command center to other UAVs in its cluster.
[0052] When the UAV command center commands a specified cluster to perform a certain task, for example, commands the UAVs in the specified cluster to fly to a specified location and perform a certain task, the UAV command center first generates command data locally and signs it, and then uses the session key between the UAV command center and the cluster head UAV to encrypt the cluster head UAV identifier, the UAV command center identifier, the command data, and the signature information to obtain encrypted communication data, and sends the encrypted communication data to the cluster head UAV in the specified cluster, so that the cluster head UAV broadcasts the command data to other cluster member UAVs in the specified cluster, so as to execute the command data. Among them, after receiving the command data, other cluster member UAVs in the specified cluster will also return a receipt message to the UAV command center.
[0053] Before the UAVs form a cluster, they need to register with the UAV command center. Specifically, the UAV command center receives the registration message sent by the UAV and the signature information of the registration message. The registration message includes the UAV identifier, the UAV accompanying public key, location information, UAV random number, and registration request. After that, the UAV command center determines the public key of the UAV according to the UAV identifier, and uses the public key of the UAV to verify the signature information. When the signature information is verified successfully, the UAV command center sends a feedback message and the signature information of the feedback message to the UAV, and generates a session key between the UAV command center and the UAV. The feedback message includes the UAV command center identifier, the center accompanying public key, and the center random number. After that, the UAV command center receives the verification code returned by the UAV, and uses the session key to verify the verification code. When the verification code is verified correctly, the UAV command center determines that the UAV has been successfully registered in the UAV command center and includes the UAV in the command queue of the UAV command center, so as to classify the UAV into a specified cluster.
[0054] Among them, after the UAV command center receives the registration messages sent by multiple UAVs and the signature information of the registration messages, it can determine the public key of the hierarchical domain where the UAV is located according to the UAV identifier. Specifically, it looks up the public key base of the corresponding large domain according to the large domain identifier in each UAV identifier, then calculates or looks up the public key base of the corresponding medium domain according to the medium domain identifier in the UAV identifier, then calculates the domain public key of the corresponding domain, and then calculates the public key corresponding to the UAV by using the domain public key, the UAV identifier and the UAV accompanying public key. After that, it uses the public key corresponding to each UAV to verify its corresponding signature information. When the signature information corresponding to each UAV passes the verification, the UAV command center sends a feedback message and the signature information of the feedback message to the passed UAV, and generates and saves the session key between the UAV command center and the UAV. Among them, the session key between the UAV command center and the UAV can be obtained according to the following formula (4) between the session key :
[0055] Formula (4)
[0056] where is the i-th UAV registered with the UAV command center CG, is the private key of the UAV command center CG, is the UAV 's public key, is the central random number, is the UAV random number, is the hash function using the SM3 algorithm.
[0057] After the UAV receives the feedback message and the signature information of the feedback message, it will also verify the signature information of the feedback message. After passing the verification, it will generate a check code using the session key and send it to the UAV command center.
[0058] After the UAV command center receives the check code returned by the UAV, it verifies the check code using the session key between the two. The UAV command center can obtain the check code of the UAV according to the following formula (5) 's check code :
[0059] Formula (5)
[0060] where is the UAV identifier, is the UAV command center identifier, is the UAV random number, is the central random number.
[0061] The UAV command center verifies whether the verification code obtained locally is consistent with the verification code returned by the UAV. If they are consistent, it determines that the verification code is verified correctly, determines that the UAV is successfully registered in the UAV command center, and includes the UAV in the command queue of the UAV command center so as to classify the UAV into a specified cluster. If the verification code is inconsistent, it indicates that the UAV may not have correctly calculated the session key between the two, and an instruction for the UAV to recalculate the session key can be returned.
[0062] When it is determined that each UAV is successfully registered in the UAV command center and a session key is established between each UAV and the UAV command center, the UAV command center can perform clustering processing on multiple UAVs, encrypt the clustering instruction using the session key between the UAV command center and the UAV, and send the encrypted clustering instruction to the UAV. The clustering instruction includes a cluster name, a cluster member list, and an in-cluster role. The in-cluster role includes a cluster head and cluster members. Among them, one UAV in each cluster is designated as the cluster head UAV, and the other UAVs in the cluster are designated as cluster member UAVs.
[0063] In an implementation manner of the embodiments of the present disclosure, the management of the UAV cluster is a dynamic process. When a problem occurs with a member in the cluster, for example, when a certain cluster member UAV is blacklisted, the UAV command center will send the updated data of the cluster member list as instruction data to the cluster head UAV in the cluster. The updated data of the cluster member list can be blacklist data or an updated cluster member list.
[0064] In the embodiments of the present disclosure, since TUMIA has the advantage of certificate-free cross-domain authentication, if necessary, any two UAVs can also perform authentication and negotiate a session key. Similarly, when multiple clusters form a swarm, regardless of which domain these UAVs come from, the UAV command center can authenticate and negotiate keys with each UAV and assign it to a certain cluster at the same time. Then the UAV command center only needs to command the cluster head UAVs of each cluster.
[0065] As Figure 4 shown, the embodiments of the present disclosure provide a schematic flowchart of a method for processing UAV communication data based on TUMIA. As Figure 4 shown, the method is applied to UAVs in a cluster, and the method includes the following steps:
[0066] Step 410, when the cluster head UAV in the cluster receives the encrypted communication data sent by the UAV command center, the cluster head UAV decrypts the encrypted communication data and uses the public key of the UAV command center to verify the signature information in the decrypted encrypted communication data. The encrypted communication data includes the encrypted cluster head UAV identifier, the UAV command center identifier, the instruction data, and the signature information.
[0067] Step 420, when the signature information is verified successfully, the cluster head UAV sends a receipt message to the UAV command center.
[0068] Step 430, the cluster head UAV encrypts the instruction data with the cluster broadcast key and broadcasts the encrypted instruction data to other cluster member UAVs in the cluster where the cluster head UAV is located.
[0069] Wherein, a cluster is a cluster composed of several UAVs from different domains, and the cluster head is a UAV that forwards the instruction data sent by the UAV command center to other UAV members in its cluster.
[0070] When the UAV command center commands a certain cluster to perform a certain task, for example, commands the UAVs in the cluster to fly to a certain designated location and perform a certain task, it will send encrypted communication data to the cluster head UAV in the cluster. After receiving the encrypted communication data, the cluster head UAV decrypts it. Then, it looks up the public key base of its corresponding large domain according to the large domain identifier in the UAV command center identifier, calculates or looks up the public key base of the corresponding middle domain according to the middle domain identifier in the UAV command center identifier, then calculates the domain public key of the corresponding domain, and then calculates the public key corresponding to the UAV command center by using the domain public key, the UAV command center identifier, and the central adjoint public key. After that, the cluster head UAV uses the public key of the UAV command center to verify the signature information in the decrypted encrypted communication data.
[0071] When the signature information is verified successfully, the cluster head UAV sends a receipt message to the UAV command center. After that, the cluster head UAV encrypts the instruction data with the cluster broadcast key and broadcasts the encrypted instruction data to other cluster member UAVs in the cluster where the cluster head UAV is located, so that all UAVs in the cluster can receive the instruction data and execute it. At the same time, the cluster member UAVs that receive the instruction data will send receipt messages to the UAV command center.
[0072] Similarly, before the UAVs form a cluster, all members within the cluster (including the UAVs that will be designated as the cluster head UAVs later) need to register with the UAV command center. Specifically, the UAV sends a registration message and the signature information of the registration message to the UAV command center. The registration message includes the UAV identifier, the UAV accompanying public key, the location information, the UAV random number, and a registration request. After that, the UAV receives the feedback message and the signature information of the feedback message sent by the UAV command center. The feedback message includes the UAV command center identifier, the center accompanying public key, and the center random number, and uses the public key of the UAV command center to verify the signature information of the feedback message. When the signature information is verified successfully, the UAV generates a session key between the UAV command center and the UAV, generates a verification code using the session key, and sends the verification code to the UAV command center for verification to determine whether to include the UAV in the command queue of the UAV command center.
[0073] Among them, after the UAV sends a registration message and the signature information of the registration message to the UAV command center, it receives the feedback message and the signature information of the feedback message from the UAV command center. Look up the public key base of the corresponding large domain according to the large domain identifier in the UAV command center identifier, then calculate or look up the public key base of the corresponding middle domain according to the middle domain identifier in the UAV command center identifier, then calculate the domain public key of the corresponding domain, and then calculate the public key corresponding to the UAV command center using the domain public key, the UAV command center identifier, and the center accompanying public key. Use the public key of the UAV command center to verify the signature information of the feedback message. When the signature information is verified successfully, generate and save the session key between the UAV command center and the UAV. The session key between the UAV and the UAV command center can be obtained according to the following formula (6) The session key between the UAV and the UAV command center :
[0074] Formula (6)
[0075] Among them, is the private key of the UAV , is the public key of the UAV command center CG.
[0076] The UAV can generate the corresponding verification code using the session key according to formula (5) and send the verification code to the UAV command center for verification to determine whether to include the UAV in the command queue of the UAV command center. Among them, the verification code is to ensure that the UAV has received the reply from the UAV command center and has correctly calculated the session key.
[0077] After a drone registers with a drone command center, it can also receive a clustering instruction sent by the drone command center. The clustering instruction includes a cluster name, a cluster member list, and a role within the cluster. The role within the cluster includes a cluster head and cluster members. Among them, the clustering instruction defines the cluster to which each drone belongs and its role in the corresponding cluster, and a unique cluster head is designated in each cluster.
[0078] After the drones are clustered, the drone members in each cluster will register with the cluster head drone in their corresponding cluster and negotiate a session key. The registration process is similar to the process of a drone registering with a drone command center. Specifically, the cluster head drone in the cluster receives the in-cluster registration message and the signature information of the in-cluster registration message sent by the drone members in the corresponding cluster. The in-cluster registration message includes the drone member identification, the accompanying public key of the drone member, the random number of the drone member, and an in-cluster registration request. Then, the cluster head drone determines the public key of the drone member according to the drone member identification and uses the public key of the drone member to verify the signature information of the in-cluster registration message. When the signature information of the in-cluster registration message is verified successfully, the cluster head drone sends a reply message and the signature information of the reply message to the drone member and generates a session key between the cluster head drone and the drone member. The reply message includes the cluster head drone identification, the accompanying public key of the cluster head drone, and the random number of the cluster head drone. Then, the cluster head drone receives the verification code returned by the drone member and verifies the verification code using the session key between the cluster head drone and the drone member. When the verification code is verified correctly, it is determined that the drone member has successfully registered within the cluster head drone's cluster, and the generated cluster broadcast key is encrypted using the session key between the cluster head drone and the drone member and sent to the corresponding drone member. Among them, the cluster broadcast key can be randomly generated locally by the cluster head drone, and the specific generation rule is not limited in the embodiments of the present disclosure. When the cluster head drone receives the cluster broadcast key receipt confirmation message replied by the drone member, it encrypts the local cluster member list using the cluster broadcast key and broadcasts it within the cluster.
[0079] The following takes the drones in the power system as an example for description. Among them, the power bureau of a certain city is the root domain, the power bureaus of each district under the jurisdiction of the city are large domains, the power supply departments of each street under the district are medium domains, and the power supply units of each community in each street are domains, forming a four-level management structure. Taking each node (including each drone, drone command center, key management center, etc.) having four-level identifiers as an example, the drone members from Community A, Street A, District A and the drone members from Community B, Street B, District B The UAV command center is a cluster Clu, and the UAV command center is CG, such as the power control equipment C under the power bureau of a district in the city. In actual applications, CG and the UAV command center may be integrated or separated. CG is used to replace the UAV command center below. According to the instructions of A District A Street A Community, According to the instructions of B District B Street B Community, fly to the designated location near CG, register with CG and accept the command. Here, .
[0080] When the above drone members arrive at the designated location, the registration process between the drone members and the drone command center is as follows Figure 5 As shown, the following steps are included:
[0081] Step 510, Send a registration message and the signature information of the registration message to CG, requesting registration and generating a session key. The registration message includes the drone identification. , drone accompanied by public key , location information , drone random number With registration request ;
[0082] Step 520, CG calculation and verify the public key Signature information.
[0083] Among them, calculation When the public key is The first large domain identifier is used to find the public key base of District A (District B), and then the public key base of Street A in District A (Street B in District B) is found according to the second identifier. Then the domain public key of Community A (Community B) is calculated according to the third identifier. Domain identity, accompanied by public key Calculated with the domain public key of cell A (cell B) and verify the public key Signature information.
[0084] Step 530: After verification, CG sends Send the feedback message and the signature information of the feedback message, and generate Session key And save, the feedback message includes the drone command center logo , Center accompanied by public key With the center random number ;
[0085] Step 540, Calculate CG's public key and verify CG's signature information.
[0086] Among them, the public key of the power control device C can also be calculated. Assuming that the power control device C belongs to the C department of the C unit in Area A, its large-domain identifier is Area A, the medium-domain identifier is the C unit, and the third identifier is the C department. Calculate the domain public key of the C department, and then use the in-domain identifier and adjoint public key of CG to calculate the public key of CG and verify the signature information of CG.
[0087] Step 550, after the verification passes, calculate the session key with CG and save it. At the same time, use to generate a check code and send it to CG;
[0088] Step 560, CG verifies the check code , if it is correct, CG will include it in the command queue, otherwise it will not be included.
[0089] Unmanned aerial vehicle After registering with CG, CG will encrypt the clustering instruction using its session key with each unmanned aerial vehicle, and and will be grouped into cluster Clu and designated as the cluster head unmanned aerial vehicle. Among them, the clustering instruction includes the cluster name, the cluster member list, and the in-cluster role. The in-cluster role includes the cluster head and the cluster members. For the designation of the cluster head, the position of each unmanned aerial vehicle in the cluster can be considered, and the unmanned aerial vehicle located in the center can be designated as the cluster head unmanned aerial vehicle to improve the communication effect between the cluster head unmanned aerial vehicle and the cluster member unmanned aerial vehicles. Of course, the cluster head can also be designated according to user requirements, which is not limited in the embodiments of the present disclosure.
[0090] Next, the unmanned aerial vehicles grouped into cluster Clu and also need to complete registration with the cluster head unmanned aerial vehicle in order to negotiate the corresponding session key and distribute the cluster broadcast key to the cluster member unmanned aerial vehicles. Here, . As Figure 6 shown, it includes the following steps:
[0091] Step 610, Send the in-cluster registration message and the signature information of the in-cluster registration message to requesting registration and generating a session key. The in-cluster registration message includes the cluster member unmanned aerial vehicle identifier , the cluster member unmanned aerial vehicle adjoint public key , the cluster member unmanned aerial vehicle random number and the in-cluster registration request ;
[0092] Step 620, Calculate 's public key and verify 's signature information;
[0093] Step 630, after verification, Send a reply message and the signature information of the reply message to Meanwhile, generate a session key with and save it. The reply message includes the cluster head UAV identifier 、the public key associated with the cluster head UAV and the random number of the cluster head UAV ; ;
[0094] Step 640, Calculate 's public key and verify 's signature information;
[0095] Step 650, after verification, Calculate the session key with and save it. Meanwhile, use to generate a check code and send it to ; ;
[0096] Step 660, Verify the check code , if correct, determine that Registration is successful;
[0097] Step 670, Generate a cluster broadcast key , and use the session key with to encrypt and send the cluster broadcast key to the corresponding ; ;
[0098] Step 680, when receives the confirmation message of the cluster broadcast key replied by , use the cluster broadcast key to encrypt the local cluster member list and broadcast it within the cluster.
[0099] When the UAV command center CG needs the UAVs in the cluster Clu to execute an instruction , CG first sends the instruction data to the cluster head UAV , and the cluster head UAV uses the cluster broadcast key Encrypt the instruction data and then broadcast it within the cluster, as Figure 7 shown, including the following steps:
[0100] Step 710, CG sends the encrypted communication data encrypted using the session key between it and to the in cluster Clu. The encrypted communication data includes the encrypted cluster head UAV identifier , the UAV command center identifier , the instruction data , and the signature information;
[0101] Step 720, decrypt the received encrypted communication data using the session key between it and CG , and calculate the public key of CG to verify its signature information;
[0102] Step 730, after verification passes, reply to CG with an acknowledgement message, and encrypt the instruction data using the cluster broadcast key and broadcast it within the cluster;
[0103] Step 740, after receiving the broadcast, decrypt using the cluster broadcast key QUOTE to obtain the instruction data , and at the same time reply to CG with an acknowledgement message.
[0104] Among them, after the cluster member UAV receives the instruction data, it can forward it to the corresponding flight control system to execute the operation.
[0105] The management of the UAV cluster is a dynamic process, and there may be an increase or decrease in cluster members. Therefore, the cluster broadcast key within the cluster may need to be updated when the members change.
[0106] When a cluster member UAV joins the cluster, the cluster head UAV has already distributed the cluster broadcast key to each cluster member UAV. If a new cluster member UAV joins, the cluster head UAV can directly distribute the current cluster broadcast key, or generate a new cluster broadcast key. If a cluster member UAV directly leaves or is shot down, there is no need to update the session key, or generate a new cluster broadcast key. If a cluster member UAV is blacklisted, the cluster head UAV can generate a new cluster broadcast key and encrypt and distribute it to each legal cluster member UAV respectively. In fact, due to the change of the cluster member UAVs within the cluster, it can be understood as creating a new cluster, and the cluster head UAV can generate a new cluster broadcast key and distribute it to each legal cluster member UAV within the cluster.
[0107] When there is a problem with the cluster member drones within a cluster and the cluster member list needs to be updated, the UAV command center can encrypt and send the cluster member list update data to the cluster head UAV, as Figure 8 shown, including the following steps:
[0108] Step 810, CG sends to the encrypted cluster member list update data using the session key between and . The cluster member list update data includes the cluster head UAV identifier , the UAV command center identifier , the new cluster member list , and the signature information;
[0109] Step 820, uses the session key between and CG to decrypt the received encrypted cluster member list update data and uses the public key of CG to verify its signature information;
[0110] Step 830, when the verification passes, uses the new cluster member list to update the local cluster member list and replies to CG that the list has been updated;
[0111] Step 840, generates a new cluster broadcast key , and encrypts the new cluster broadcast key using the session key between and , and sends it to respectively.
[0112] Here, .
[0113] Step 850, receives and decrypts to obtain the new cluster broadcast key , and replies with an acknowledgement message;
[0114] Step 860, after receiving the acknowledgement message, encrypts the updated local cluster member list using the new cluster broadcast key and broadcasts it within the cluster;
[0115] Step 870, updates the local cluster member list and replies to that the list has been updated.
[0116] Embodiments of the present disclosure temporarily gather UAVs from multiple domains into a cluster or swarm, and utilize the TUMIA technology to achieve excellent performance of multi-UAV cooperation.
[0117] As shown Figure 9 in the figure, the embodiment of the present disclosure also provides a TUMIA-based UAV communication data processing system 90, including: multiple UAVs 91 and a UAV command center 92. Among them, the multiple UAVs 91 include N hierarchical domains, an identity mapping public key IMPK architecture from the first hierarchical domain to the (N-1)th hierarchical domain, and an identity binding public key IBPK architecture of the Nth hierarchical domain, where N≥3. Among them, a cluster is a group of several UAVs from different domains, and a cluster head is a UAV that forwards the instruction data sent by the UAV command center to other UAVs in its cluster,
[0118] wherein, the UAV command center 92 is used for:
[0119] sending encrypted communication data to the cluster head UAV in a specified cluster, where the encrypted communication data includes the encrypted cluster head UAV identifier, the UAV command center identifier, instruction data, and signature information, so that the cluster head UAV broadcasts the instruction data to other cluster member UAVs in the specified cluster; receiving the receipt message replied by the cluster head UAV;
[0120] the cluster head UAV in the specified cluster among the multiple UAVs 91 is used for:
[0121] when receiving the encrypted communication data sent by the UAV command center, decrypting the encrypted communication data and verifying the signature information in the decrypted encrypted communication data by using the public key of the UAV command center, where the encrypted communication data includes the encrypted cluster head UAV identifier, the UAV command center identifier, instruction data, and signature information; when the signature information is verified to be passed, replying a receipt message to the UAV command center; encrypting the instruction data by using a cluster broadcast key and broadcasting the encrypted instruction data to other cluster member UAVs in the cluster where the cluster head UAV is located.
[0122] The specific working principle and benefits of the TUMIA-based UAV communication data processing system provided by the embodiment of the present disclosure are similar to those of the TUMIA-based UAV communication data processing method provided by the embodiment of the present disclosure, and will not be elaborated here.
[0123] Those skilled in the art should understand that the embodiments of the present disclosure can be provided as a system or a computer program product. Therefore, the present disclosure can be implemented in the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present disclosure can be implemented in the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0124] This disclosure is described with reference to flowchart illustrations and / or block diagrams of systems (apparatus), and computer program products according to embodiments of the disclosure. It should be understood that each flow and / or block in the flowchart illustrations and / or block diagrams, and combinations of flows and / or blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processors of general purpose computers, special purpose computers, embedded processors, or other programmable data processing devices to produce a machine, such that the instructions executed by the processors of the computer or other programmable data processing devices create means for implementing the functions specified in Figure 1 one or more of the flows Figure 1 or blocks.
[0125] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable memory produce a manufacture including instruction means that implement the functions specified in Figure 1 one or more of the flows Figure 1 or blocks.
[0126] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operational steps are performed on the computer or other programmable device to produce a computer-implemented process, thereby providing steps for implementing the functions specified in Figure 1 one or more of the flows Figure 1 or blocks.
[0127] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.
[0128] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM), and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. The memory is an example of computer-readable media.
[0129] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.
[0130] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.
[0131] The above are only embodiments of the present disclosure and are not intended to limit the present disclosure. For those skilled in the art, the present disclosure may have various modifications and variations. Any modification, equivalent substitution, improvement, etc. made within the spirit and principle of the present disclosure shall be included in the scope of the claims of the present disclosure.
Claims
1. A method for processing UAV communication data based on a unified multi-domain identification public key processing system TUMIA with a three-layer or higher structure, characterized in that: The method is applied to a drone command center, and the method comprises: Sending encrypted communication data to a cluster head drone in a designated cluster, wherein the encrypted communication data includes an encrypted cluster head drone identifier, a drone command center identifier, command data, and signature information, so that the cluster head drone broadcasts the command data to other cluster member drones in the designated cluster; Receive the receipt message replied by the cluster head drone, A cluster is a group of drones from different domains, and a cluster head is a drone that forwards command data sent by the drone command center to other drones in its cluster. Wherein, the method further comprises: Receive a registration message and signature information of the registration message sent by the drone, wherein the registration message includes the drone identification, the drone accompanying public key, location information, the drone random number and the registration request; Determine the public key of the drone according to the drone identifier, and verify the signature information using the public key of the drone; When the signature information is verified, a feedback message and the signature information of the feedback message are sent to the drone, and a session key is generated between the drone command center and the drone, wherein the feedback message includes the drone command center identifier, the center accompanying public key and the center random number; receiving a verification code returned by the drone, and verifying the verification code using the session key; When the verification code is verified to be correct, it is determined that the drone is successfully registered in the drone command center, and the drone is included in the command queue of the drone command center so as to be classified into a designated cluster.
2. The method according to claim 1, characterized in that After determining that the drone is successfully registered at the drone command center, the method further includes: The clustering instruction is encrypted using the session key between the drone command center and the drone, and the encrypted clustering instruction is sent to the drone, wherein the clustering instruction includes a cluster name, a cluster member list, and roles within the cluster, wherein the roles within the cluster include a cluster head and a cluster member.
3. The method according to claim 1, characterized in that The instruction data includes: cluster member list update data.
4. A method for processing UAV communication data based on a unified multi-domain identification public key processing system TUMIA with a three-layer or higher structure, characterized in that: A cluster is a group of several drones from different domains, and a cluster head is a drone that forwards command data sent by a drone command center to other drone members in the cluster. The method is applied to drones, and the method includes: When the cluster head drone in the cluster receives the encrypted communication data sent by the drone command center, the cluster head drone decrypts the encrypted communication data and uses the public key of the drone command center to verify the signature information in the decrypted encrypted communication data, wherein the encrypted communication data includes the encrypted cluster head drone identification, drone command center identification, instruction data and signature information; When the signature information is verified, the cluster head drone replies with a receipt message to the drone command center; The cluster head drone encrypts the command data using a cluster broadcast key, and broadcasts the encrypted command data to other cluster member drones in the cluster where the cluster head drone is located. The method further includes a registration process of all drones in the cluster to the drone command center: Sending a registration message and signature information of the registration message to the drone command center, wherein the registration message includes the drone identification, drone accompanying public key, location information, drone random number and registration request; Receive a feedback message and signature information of the feedback message sent by the drone command center, wherein the feedback message includes an identifier of the drone command center, a center accompanying public key, and a center random number; Verifying the signature information of the feedback message using the public key of the drone command center; When the signature information is verified, a session key between the drone command center and the drone is generated; A verification code is generated using the session key, and the verification code is sent to the drone command center for verification to determine whether the drone is included in the command queue of the drone command center.
5. The method according to claim 4, characterized in that The method further comprises: A clustering instruction sent by the drone command center is received, wherein the clustering instruction includes a cluster name, a cluster member list, and roles within the cluster, wherein the roles within the cluster include a cluster head and a cluster member.
6. The method according to claim 5, characterized in that After receiving the clustering instruction sent by the drone command center, the method further includes: The cluster head drone in the cluster receives the cluster registration message and the signature information of the cluster registration message sent by the cluster member drone in the corresponding cluster, wherein the cluster registration message includes the cluster member drone identifier, the cluster member drone accompanying public key, the cluster member drone random number and the cluster registration request; The cluster head drone determines the public key of the cluster member drone according to the cluster member drone identifier, and verifies the signature information of the cluster registration message using the public key of the cluster member drone; When the signature information of the cluster registration message is verified, the cluster head UAV sends a reply message and the signature information of the reply message to the cluster member UAV, and generates a session key between the cluster head UAV and the cluster member UAV, wherein the reply message includes the cluster head UAV identifier, the cluster head UAV accompanying public key and the cluster head UAV random number; The cluster head UAV receives the verification code returned by the cluster member UAV, and verifies the verification code using the session key between the cluster head UAV and the cluster member UAV; When the verification code is verified to be correct, it is determined that the cluster member drone is successfully registered in the cluster head drone cluster, and the generated cluster broadcast key is encrypted using the session key between the cluster head drone and the cluster member drone and sent to the corresponding cluster member drone; When the cluster head UAV receives the cluster broadcast key confirmation message replied by the cluster member UAV, it uses the cluster broadcast key to encrypt the local cluster member list and broadcasts it within the cluster.
7. The method according to claim 4, characterized in that When the instruction data is cluster member list update data, the method further includes: The cluster head drone updates the local cluster member list using the cluster member list update data and generates a new cluster broadcast key; The cluster head UAV encrypts the new cluster broadcast key using the session key between it and the cluster member UAVs, and sends it to the corresponding cluster member UAVs respectively; When the cluster head UAV receives the confirmation message of the new cluster broadcast key replied by the cluster member UAV, it uses the new cluster broadcast key to encrypt the updated local cluster member list and broadcasts it within the cluster.
8. A UAV communication data processing system based on a unified multi-domain identification public key processing system TUMIA with a three-layer or higher structure, characterized in that: The system comprises: A plurality of drones and a drone command center, wherein the plurality of drones include N hierarchical domains, an identity mapping public key IMPK architecture from the first hierarchical domain to the N-1th hierarchical domain, and an identity binding public key IBPK architecture of the Nth hierarchical domain, N≥3, wherein a cluster is a cluster of several drones from different domains, and a cluster head is a drone that forwards command data sent by the drone command center to other drones in its cluster, Wherein, the drone command center is used for: Sending encrypted communication data to a cluster head drone in a designated cluster, wherein the encrypted communication data includes an encrypted cluster head drone identifier, a drone command center identifier, command data, and signature information, so that the cluster head drone broadcasts the command data to other cluster member drones in the designated cluster; Receive a receipt message replied by the cluster head drone; The UAV command center is also used for: Receive a registration message and signature information of the registration message sent by the drone, wherein the registration message includes the drone identification, the drone accompanying public key, location information, the drone random number and the registration request; Determine the public key of the drone according to the drone identifier, and verify the signature information using the public key of the drone; When the signature information is verified, a feedback message and the signature information of the feedback message are sent to the drone, and a session key is generated between the drone command center and the drone, wherein the feedback message includes the drone command center identifier, the center accompanying public key and the center random number; receiving a verification code returned by the drone, and verifying the verification code using the session key; When the verification code is verified to be correct, it is determined that the drone is successfully registered in the drone command center, and the drone is included in the command queue of the drone command center, so as to classify the drone into a designated cluster; The drone is used for: When the cluster head drone in the designated cluster receives the encrypted communication data sent by the drone command center, the encrypted communication data is decrypted, and the signature information in the decrypted encrypted communication data is verified using the public key of the drone command center, wherein the encrypted communication data includes the encrypted cluster head drone identification, drone command center identification, instruction data and signature information; When the signature information is verified, a receipt message is sent to the drone command center; The command data is encrypted using a cluster broadcast key, and the encrypted command data is broadcast to other cluster member drones in the cluster where the cluster head drone is located. The drone is also used for the registration process with the drone command center: Sending a registration message and signature information of the registration message to the drone command center, wherein the registration message includes the drone identification, drone accompanying public key, location information, drone random number and registration request; Receive a feedback message and signature information of the feedback message sent by the drone command center, wherein the feedback message includes an identifier of the drone command center, a center accompanying public key, and a center random number; Verifying the signature information of the feedback message using the public key of the drone command center; When the signature information is verified, a session key between the drone command center and the drone is generated; A verification code is generated using the session key, and the verification code is sent to the drone command center for verification to determine whether the drone is included in the command queue of the drone command center.
Citation Information
Patent Citations
Unified multi-domain identification public key processing method and system based on structure of three or more layers
CN118101202A