A method, system and computer program product for self-organizing networking of unmanned equipment

Through the identity authentication mechanism of certificates and challenge codes, devices are automatically discovered and networked, solving the problem of low flexibility in device networking in the existing technology, and achieving rapid and flexible networking and fault tolerance between unmanned devices.

CN119383606BActive Publication Date: 2025-08-29HUAZHI (BEIJING) TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411659165.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-19
Publication Date
2025-08-29
Estimated Expiration
2044-11-19

AI Technical Summary

Technical Problem

There are problems in the process of networking of existing equipment, such as low flexibility, relying on main control equipment, requiring manual intervention, unable to adapt to unmanned equipment scenarios, and slow networking speed.

Method used

The identity authentication mechanism based on certificates and challenge codes is adopted. The devices are automatically discovered and authenticated through broadcast messages, and a trusted device is dynamically selected for networking, and a master-slip switching mechanism is introduced to ensure system reliability and flexibility.

Benefits of technology

It realizes automated networking between unmanned equipment, reduces manual intervention, improves network speed and system flexibility, and can dynamically adjust the network structure and adapt to multiple scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119383606B_ABST
    Figure CN119383606B_ABST
Patent Text Reader

Abstract

The present application discloses a method, system and program product for self-organizing networking of unmanned devices, wherein different types of business applications are running on the unmanned devices; for each business application, a corresponding certificate is installed on the unmanned devices; the method comprises: when executing a networking collaboration task, the discovery party unmanned device that initiates the task sends a broadcast message as the main device, the broadcast message carries the business application type that needs to be coordinated and a first challenge code; based on the business application type that needs to be coordinated, the certificate corresponding to the business application type and the first challenge code, the discovery party unmanned device that receives the broadcast message is authenticated, and after the authentication is passed, the discovery party unmanned device and the discovered party unmanned device mark each other as trustworthy; and some unmanned devices are selected from the unmanned devices that have reached a trust consensus for networking. The present application adopts an identity authentication mechanism based on certificates and challenge codes, which can dynamically select appropriate unmanned devices for task collaboration and networking, greatly improving flexibility.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and in particular to a method, system and computer program product for self-organizing networking of unmanned equipment. Background Art

[0002] Device networking plays an important role and plays a significant role in actual application scenarios, especially for distributed systems and IoT environments. It can achieve seamless connection and communication between different devices, enabling devices in the network to share resources (such as data, computing power, storage space, etc.), collaborate to complete complex tasks, enhance user experience, and improve system reliability.

[0003] Device networking includes three steps: device discovery, identity authentication, and device connection:

[0004] (1) Device discovery allows a device to identify and locate other devices in the network.

[0005] (2) Identity authentication technology is used to determine the legal identity of the user.

[0006] (3) Establish a connection through identity authentication devices to form a network.

[0007] Common device discovery technologies include broadcast and multicast. These technologies enable devices to announce their presence and obtain information about other devices through broadcast or multicast messages within the local area network.

[0008] Identity authentication requires establishing a trust relationship between devices. Different methods are used in different scenarios. For example:

[0009] (1) In the IoT field, a device with a screen is required as a master control device in the networking equipment. The user enters the PIN code (or the QR code on the body) provided by the slave device on the master control device.

[0010] (2) In the CT and IT fields, networking equipment needs to be configured through a central control unit to achieve networking.

[0011] Devices that have passed identity authentication establish a secure connection between the two parties. If a network is to be established, the above process is required between all devices.

[0012] The inventors realized that the above-mentioned existing networking process requires a clear master control device or central control. The network is highly dependent on the master control device, which is fixed and cannot be changed, and its reliability and flexibility are limited. Relying on PIN codes or QR codes on the body to network is not flexible, and the networking information needs to be configured in advance and cannot be dynamically adjusted.

[0013] In addition, the existing networking solutions are not applicable to scenarios where the devices do not have screens. They require manual participation and have a low overall level of intelligence. Their use in unmanned equipment application scenarios is limited. Moreover, the networking speed between devices is slow, and a long waiting time is required when there are many clustered devices. Summary of the Invention

[0014] The present application provides a method, system and computer program product for self-organizing networking of unmanned equipment, aiming to solve the technical problem of low flexibility in existing networking processes.

[0015] In a first aspect, a method for self-organizing an unmanned device network, wherein different types of business applications are running on the unmanned device; for each business application, a corresponding certificate is installed on the unmanned device; the method comprises:

[0016] S1, when executing a network collaboration task, the discovery party unmanned device that initiates the task acts as the master device to send a broadcast message, the broadcast message carries the service application type that needs to be coordinated and a first challenge code;

[0017] S2: Authenticate the discovered unmanned device that receives the broadcast message based on the business application type that needs to be coordinated, the certificate corresponding to the business application type, and the first challenge code. After the authentication is successful, the discovering unmanned device and the discovered unmanned device mark each other as trusted.

[0018] S3, select some unmanned devices from the unmanned devices that have reached a trust consensus to form a network.

[0019] In the above solution, optionally, the certificate is installed together with the business application when the business application is installed, or the certificate is dynamically downloaded and installed when the business application is started after installation; the certificate is protected by hardware.

[0020] In the above solution, optionally, step S2 includes:

[0021] The unmanned device on the discovered side checks whether the business application types it supports match the business application types that need to be coordinated;

[0022] If a match occurs, the unmanned device on the discovered party uses the certificate corresponding to the service application type that needs to be coordinated to perform calculations based on the first challenge code and locally generate a second challenge code; the unmanned device on the discovered party sends the calculation result obtained based on the first challenge code and the second challenge code as a response message to the unmanned device on the discovered party;

[0023] The unmanned device of the discovering party verifies whether the calculation result obtained based on the first challenge code meets the requirements;

[0024] If the challenge is met, the discovering unmanned device performs calculation based on the second challenge code; the discovering unmanned device sends the calculation result obtained based on the second challenge code to the discovered unmanned device, and marks the discovered unmanned device as trustworthy;

[0025] The unmanned device of the discovered party verifies whether a calculation result obtained based on the second challenge code is correct;

[0026] If correct, the unmanned device on the discovered side will mark the unmanned device on the discovered side as trustworthy.

[0027] In the above solution, further optionally, the method further includes:

[0028] The unmanned device of the discovering party regularly publishes the locally maintained list of trusted devices through broadcast messages;

[0029] The unmanned device on the discovered side that receives the broadcast message updates the local trusted device list.

[0030] In the above solution, further optionally, the method further includes:

[0031] According to the order in which the unmanned devices of the discovered party reply to the response message, the unmanned devices of the discovered party will be used as backup devices of the main device in turn;

[0032] The master device synchronizes task execution information to the backup device and periodically sends survival messages to the backup device.

[0033] When the backup device detects a failure in the primary device, it immediately starts the primary-backup switchover and notifies other unmanned devices in the network.

[0034] In the above solution, optionally, step S3 includes:

[0035] The discovering unmanned device sends a network resource query message to the discovered unmanned device that has reached a trust consensus;

[0036] The unmanned device on the discovered side that has reached a trust consensus sends a networking resource report message to the unmanned device on the discovering side;

[0037] The discovering unmanned device selects a device from the discovered unmanned devices that have reached a trust consensus based on the task resource budget, and sends a networking notification message to the selected discovered unmanned device;

[0038] The discovering unmanned device establishes a network connection with the selected discovered unmanned device.

[0039] In the above solution, optionally, the method further includes:

[0040] When the network collaboration task is completed, the master device initiates a broadcast message to disband the network of the current business application;

[0041] The unmanned device that receives the network disbanding broadcast message disconnects the existing network connection.

[0042] In a second aspect, an unmanned device self-organizing network system is provided, wherein different types of business applications are run on the unmanned devices; for each business application, a corresponding certificate is installed on the unmanned device; the system comprises:

[0043] A broadcast message sending module is used to, when executing a network collaboration task, enable the unmanned device that initiates the task to send a broadcast message as a master device, wherein the broadcast message carries the service application type that needs to be collaborated and a first challenge code;

[0044] A trusted device marking module is used to authenticate the unmanned device of the discovered party that receives the broadcast message based on the business application type that needs to be coordinated, the certificate corresponding to the business application type, and the first challenge code. After the authentication is passed, the discovering unmanned device and the discovered unmanned device mark each other as trusted;

[0045] The networking module is used to select some unmanned devices from the unmanned devices that have reached a trust consensus for networking.

[0046] According to a third aspect, a computer program product comprises a computer program / instruction, wherein the computer program / instruction implements the steps of the method according to the first aspect when executed by a processor.

[0047] Compared with the prior art, this application has at least the following beneficial effects:

[0048] In the method provided in the embodiment of the present application, there is no fixed master control device or central control unit. Instead, an identity authentication mechanism based on certificates and challenge codes is adopted between devices. Without manual intervention, suitable unmanned devices can be dynamically selected for task collaboration and networking. During the device discovery and authentication process, it automatically determines which unmanned devices can participate in the networking. There is no need to set up a fixed master control device, which improves flexibility. When performing a task, the device will automatically initiate a discovery request and verify each other's identity through the authentication mechanism to ensure that only trusted devices can join the network. This automated process greatly improves flexibility and does not require pre-configuration or manual input of information.

[0049] This application also proposes a master-slave switching mechanism to solve the fault tolerance problem of devices in the network. During the discovery phase, the device determines the backup device according to the response order of the challenge code; when the main device fails, the backup device can automatically take over the task to ensure the continuous operation of the entire system; therefore, the network no longer relies on a fixed master control device, but can be dynamically adjusted according to actual conditions, thereby improving the reliability and flexibility of the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] Figure 1 A flowchart of a method for self-organizing a network of unmanned devices provided in one embodiment of the present application;

[0051] Figure 2 A block diagram of the module architecture of an unmanned equipment self-organizing network system provided in one embodiment of the present application. DETAILED DESCRIPTION

[0052] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0053] In the description of this application: unless otherwise specified, the meaning of "plurality" is two or more. The terms "first", "second", "third", etc. in this application are intended to distinguish the objects referred to and do not have any special meaning in terms of technical connotation (for example, they should not be understood as emphasizing the importance or order, etc.). Expressions such as "including", "comprising", "having", etc. also mean "not limited to" (certain units, components, materials, steps, etc.).

[0054] In one embodiment, a method for self-organizing networks of unmanned devices is provided. Different types of business applications are run on the unmanned devices. For each business application, a corresponding certificate is installed on the unmanned device. Specifically, the certificate is installed along with the business application when it is installed, or dynamically downloaded and installed when the business application is started after installation. The certificate is hardware-protected.

[0055] In other words, certificates are issued based on business applications. Different types of business applications can run on unmanned devices. If business applications on different devices need to work together, they are authenticated using business certificates. The certificates are installed with the applications or dynamically downloaded and installed when the applications start, and are protected by the hardware.

[0056] When storing and using certificates, their security can be enhanced by using a hardware security module (HSM) or protected hardware components (such as a TPM, Trusted Platform Module). Hardware protection ensures that the certificate's private key (especially during encryption or signing operations) is not exposed to the operating system or applications, and cannot be accessed by malware or unauthorized users.

[0057] That is, the certificate's private key is not stored in the normal file system or memory, but instead is stored in a protected hardware module (such as an HSM or TPM). This way, even if an attacker gains access to the device's operating system or applications, they cannot obtain the private key. The HSM or TPM provides physical security protection, preventing physical tampering and cracking, ensuring that the private key cannot be extracted or leaked.

[0058] like Figure 1 As shown, the method specifically includes the following steps:

[0059] S1, when executing a networking collaboration task, the discovery party unmanned device that initiates the task acts as a master device to send a broadcast message, which carries the business application type that needs to be collaborated and a first challenge code.

[0060] S2, based on the business application type that needs to be coordinated, the certificate corresponding to the business application type and the first challenge code, authenticate the unmanned device of the discovered party that receives the broadcast message. After the authentication is passed, the unmanned device of the discovering party and the unmanned device of the discovered party mark each other as trustworthy.

[0061] Furthermore, step S2 includes:

[0062] The unmanned device on the discovered side checks whether the business application types it supports match the business application types that need to be coordinated;

[0063] If a match occurs, the unmanned device on the discovered party uses the certificate corresponding to the business application type that needs to be coordinated to perform calculations based on the first challenge code and locally generate a second challenge code; the unmanned device on the discovered party sends the calculation result obtained based on the first challenge code and the second challenge code as a response message to the unmanned device on the discovering party;

[0064] The unmanned device of the discovering party verifies whether the calculation result obtained based on the first challenge code meets the requirements;

[0065] If the challenge is met, the discovering unmanned device performs calculation based on the second challenge code; the discovering unmanned device sends the calculation result obtained based on the second challenge code to the discovered unmanned device, and marks the discovered unmanned device as trustworthy;

[0066] The unmanned device of the discovered party verifies whether the calculation result obtained based on the second challenge code is correct;

[0067] If correct, the unmanned device on the discovered side will mark the unmanned device on the discovered side as trustworthy.

[0068] Furthermore, the method further comprises:

[0069] The unmanned device of the discovering party regularly publishes the locally maintained list of trusted devices through broadcast messages;

[0070] The unmanned device on the discovered side that receives the broadcast message updates the local trusted device list.

[0071] In other words, step S2 implements device service discovery and authentication. When an unmanned device is performing a task and wants to obtain cooperation from surrounding devices, it goes through the following process:

[0072] Step 1: The device that initiates the task automatically becomes the master device and sends a broadcast message (discovery request) that carries the business application type and challenge code that require collaboration.

[0073] When the master device broadcasts a message, the challenge code it carries can be a randomly generated value (called a Challenge code). The purpose of the Challenge code is mainly to verify the identity of the device and prevent replay attacks.

[0074] Step 2: Surrounding devices that receive the broadcast message:

[0075] Check whether the business types you support match the business application types requested;

[0076] The challenge code is calculated using the certificate corresponding to the requested service type, and the calculation result and the locally generated challenge code are sent to the requester as a response message (discoveryresponse).

[0077] In other words, after receiving the challenge code, the device that receives the broadcast message uses its certificate and an algorithm to calculate the response. For example, the device can use the private key or shared key in its stored business application certificate to encrypt or hash the challenge code.

[0078] Step 3: After receiving the response message, the device discoverer first verifies whether the calculation result of its own challenge code meets the requirements. If it does, it performs specific calculations based on the challenge code of the discovered device, sends the calculation result to the discovered party (discovery ack), and marks the discovered party as trustworthy.

[0079] For example, after receiving a response message from the target device, the initiating device can use the corresponding public key or private key to verify the result returned by the target device. If the calculation result is correct, it proves that the target device indeed possesses the certificate and can correctly calculate the challenge code, thus establishing trust.

[0080] The specific calculation based on the challenge code of the discovered device can be based on a certain algorithm (such as a hash algorithm, a symmetric encryption algorithm, etc.). The specific calculation may include the following steps:

[0081] (1) Verify the challenge code of the discoverer: First, the device discoverer verifies the challenge code of the discovered device according to its own preset algorithm (such as SHA-256 hash) to confirm whether the challenge code is consistent with the expected result.

[0082] (2) Generate a new challenge code: If the discoverer passes the verification, a new challenge code can be generated based on a certain key (such as using a public-private key pair). The challenge code is generated by encrypting the device's identity information and the shared session key.

[0083] (3) Challenge code encryption: For example, the discoverer uses a symmetric encryption method (such as AES) to encrypt the generated challenge code and then sends it to the discovered party. After receiving the encrypted challenge code, the discovered party uses the shared key to decrypt it and verify its correctness.

[0084] This step can be used to encrypt and decrypt the challenge code by creating a temporary session key. The specific process is as follows:

[0085] Session key generation: Once the device is discovered successfully, the two parties can negotiate a session key (which can be generated using methods such as the Diffie-Hellman key exchange protocol and elliptic curve cryptography).

[0086] Challenge code encryption and exchange: Based on the session key, the challenge code is encrypted and exchanged over a secure channel. Only when both parties have the same session key can the encrypted challenge code be correctly decrypted and verified, ensuring trustworthy communication between devices.

[0087] In other words, the challenge code calculation adopts a two-way authentication method:

[0088] (1) The device discoverer initiates a challenge: The device discoverer sends a request containing a challenge code to the discovered device.

[0089] (2) The discovered device responds to the challenge: The discovered device generates a challenge code based on certain security protocols, performs a hash operation, and then responds to the device discoverer.

[0090] (3) Verification process: After receiving the response challenge code from the discovered device, the device discoverer performs verification again and returns the verification result to the discovered device.

[0091] It can ensure that the challenge code exchange process between devices is safe and reliable, and effectively perform identity authentication and trust establishment, ensuring secure communication and collaborative work between devices.

[0092] Step 4: The discovered party checks the calculation result of the challenge code in the ack message. If it is correct, the discovered party is marked as trusted.

[0093] Step 5: The device discoverer regularly broadcasts a locally maintained list of trusted devices (discoverynotify). The receiving device updates its local list of trusted devices, allowing all participating devices to reach a trust consensus. All trust consensus is based on specific services.

[0094] S3, select some unmanned devices from the unmanned devices that have reached a trust consensus to form a network.

[0095] Furthermore, step S3 includes:

[0096] The discovering unmanned device sends a network resource query message to the discovered unmanned device that has reached a trust consensus;

[0097] The unmanned device on the discovered side that has reached a trust consensus sends a networking resource report message to the unmanned device on the discovering side;

[0098] The discovering unmanned device selects a device from the discovered unmanned devices that have reached a trust consensus based on the task resource budget, and sends a networking notification message to the selected discovered unmanned device;

[0099] The discovering unmanned device establishes a network connection with the selected discovered unmanned device.

[0100] In other words, this step implements device networking, selecting some devices from those that have reached a trust consensus for networking. The selection criteria include:

[0101] (1) Whether multiple services are allowed to share equipment

[0102] (2) Average resource utilization of equipment

[0103] Step 1: The master device sends a network resource query message.

[0104] Step 2: Send a network resource report message from the device;

[0105] Step 3: The master device selects a device with abundant resources based on the task resource budget and sends a groupnotify message.

[0106] Step 4: All devices involved in the networking establish network connections.

[0107] Furthermore, the method further comprises:

[0108] According to the order in which the unmanned devices of the discovered party reply to the response message, the unmanned devices of the discovered party will be used as backup devices of the main device in turn;

[0109] The master device synchronizes task execution information to the backup device and periodically sends survival messages to the backup device.

[0110] When the backup device detects a failure in the primary device, it immediately starts the primary-backup switchover and notifies other unmanned devices in the network.

[0111] In other words, this step implements master-slave switching: the slave devices act as backups for the master device in the order in which they reply to the response messages in the device discovery phase. The master device synchronizes task execution information to the backup device and periodically sends survival messages to the backup device. When the backup device detects a failure in the master device, it immediately initiates master-slave switching and notifies other devices in the network.

[0112] Furthermore, the method further comprises:

[0113] When the network collaboration task is completed, the master device initiates a broadcast message to disband the network of the current business application;

[0114] The unmanned device that receives the network disbanding broadcast message disconnects the existing network connection.

[0115] In other words, this step realizes network dissolution: when the network collaboration task is completed, the master device initiates a network dissolution broadcast message for the current business application, and the device that receives the message disconnects the existing network connection.

[0116] The embodiments of the present application provide an identity authentication mechanism based on certificates and specific algorithms, an automated method for device discovery, authentication, networking, and network dissolution, and a method for master-slave switching in a self-organizing network.

[0117] In the method provided in the embodiments of the present application, there is no fixed master device or central control unit. Instead, devices dynamically select appropriate devices for task collaboration and networking through a mutually trusted discovery and authentication mechanism. Devices automatically determine which devices can participate in networking during the device discovery and authentication process through identity authentication and trust establishment (an authentication mechanism based on certificates and specific algorithms). In this way, even if some devices malfunction or fail, the system can flexibly select other devices to continue executing the task.

[0118] This application also proposes a master-backup switching mechanism to address the issue of device fault tolerance in the network. During the discovery phase, devices determine the backup device based on the order in which they respond to the challenge code. If the master device fails, the backup device automatically takes over, ensuring the continued operation of the entire system. As a result, the network no longer relies on a fixed master device but can dynamically adjust based on actual conditions, improving system reliability and flexibility.

[0119] Traditional device networking usually relies on PIN codes, QR codes, or pre-configured network information. These methods are less flexible, lack dynamism in the networking process, and often require manual intervention, making them unsuitable for unmanned equipment and intelligent scenarios.

[0120] This solution utilizes a certificate-based authentication mechanism, combined with an automated device discovery and authentication process, eliminating the need for manual intervention. Devices automatically initiate discovery requests when performing tasks and verify each other's identities through authentication, ensuring that only trusted devices can join the network. This automated process significantly increases flexibility and eliminates the need for pre-configuration or manual input.

[0121] Unlike traditional PIN or QR code methods, this solution dynamically generates and adjusts networking information. When executing a task, devices select appropriate collaborating devices in real time based on current application requirements and device resource availability. Through "resource query" and "resource reporting" mechanisms, devices dynamically evaluate and select resource-rich devices for networking based on task requirements. This dynamic networking approach significantly enhances the system's flexibility and adaptability.

[0122] During the discovery and authentication process, devices exchange and calculate challenge codes to form a trust consensus based on specific services. This trust consensus mechanism ensures the reliability of devices, and this trust establishment is automated, reducing the need for manual intervention. Trust relationships between devices can be continuously adjusted as tasks progress, further enhancing network flexibility.

[0123] This invention effectively solves the problems of traditional networking solutions, such as reliance on master control devices, fixed network structures, lack of flexibility and dynamic adjustment, through a decentralized self-organizing network mechanism, dynamic certificate authentication, automated device discovery and authentication, a master-slave switching mechanism, and flexible task resource management.

[0124] (1) Decentralization: There is no fixed master control device. Devices spontaneously form a collaborative network through trust and authentication mechanisms, which improves the reliability and flexibility of the system.

[0125] (2) Dynamic Adaptation: Resource query and reporting mechanisms between devices enable the network to dynamically adjust according to real-time needs, independent of static configuration.

[0126] (3) Intelligence and automation: Automatic discovery, authentication, trust establishment, and device switching reduce manual intervention, improve the system's intelligence level, and are suitable for automated scenarios involving unmanned equipment.

[0127] In one embodiment, Figure 2As shown, a self-organizing network system for unmanned devices is provided, in which different types of business applications are run on the unmanned devices; for each business application, a corresponding certificate is installed on the unmanned device; the system includes the following program modules:

[0128] The broadcast message sending module 201 is used to, when executing a network collaboration task, enable the unmanned device that initiates the task to discover the task to act as the master device to send a broadcast message, where the broadcast message carries the service application type that needs to be collaborated and a first challenge code;

[0129] The trusted device marking module 202 is configured to authenticate the unmanned device on the discovered side that receives the broadcast message based on the business application type to be coordinated, the certificate corresponding to the business application type, and the first challenge code. After the authentication is successful, the discovering unmanned device and the discovered unmanned device mark each other as trusted.

[0130] The networking module 203 is used to select some unmanned devices from the unmanned devices that have reached a trust consensus to form a network.

[0131] The specific implementation content of each module can be found in the above definition of an unmanned equipment self-organizing network method, which will not be repeated here.

[0132] In one embodiment, a computer-readable storage medium is further provided, on which a computer program is stored, which involves all or part of the processes in the above-mentioned embodiment method.

[0133] In one embodiment, a computer program product is further provided, including a computer program / instruction, which implements all or part of the process in the above embodiment method when executed by a processor.

[0134] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

Claims

1. A method for self-organizing networking of unmanned equipment, characterized in that: Different types of business applications are running on the unmanned device; for each business application, a corresponding certificate is installed on the unmanned device; the method includes: S1, when executing a network collaboration task, the discovery party unmanned device that initiates the task acts as the master device to send a broadcast message, the broadcast message carries the service application type that needs to be coordinated and a first challenge code; S2, authenticating the discovered unmanned device that receives the broadcast message based on the business application type that needs to be coordinated, the certificate corresponding to the business application type, and the first challenge code. After the authentication is successful, the discovering unmanned device and the discovered unmanned device mark each other as trusted; specifically, including: The unmanned device on the discovered side checks whether the business application types it supports match the business application types that need to be coordinated; If a match occurs, the unmanned device on the discovered party uses the certificate corresponding to the service application type that needs to be coordinated to perform calculations based on the first challenge code and locally generate a second challenge code; the unmanned device on the discovered party sends the calculation result obtained based on the first challenge code and the second challenge code as a response message to the unmanned device on the discovered party; The unmanned device of the discovering party verifies whether the calculation result obtained based on the first challenge code meets the requirements; If the challenge is met, the discovering unmanned device performs calculation based on the second challenge code; the discovering unmanned device sends the calculation result obtained based on the second challenge code to the discovered unmanned device, and marks the discovered unmanned device as trustworthy; The unmanned device of the discovered party verifies whether a calculation result obtained based on the second challenge code is correct; If it is correct, the unmanned device on the discovered side will mark the unmanned device on the discovered side as trustworthy; S3, select some unmanned devices from the unmanned devices that have reached a trust consensus to form a network.

2. The unmanned equipment self-organizing network method according to claim 1, characterized in that: The certificate is installed along with the business application when the business application is installed, or dynamically downloaded and installed when the business application is started after installation; the certificate is protected by hardware.

3. The unmanned equipment self-organizing network method according to claim 1, characterized in that: The method further comprises: The unmanned device of the discovering party regularly publishes the locally maintained list of trusted devices through broadcast messages; The unmanned device on the discovered side that receives the broadcast message updates the local trusted device list.

4. The unmanned equipment self-organizing network method according to claim 1, characterized in that: The method further comprises: According to the order in which the unmanned devices of the discovered party reply to the response message, the unmanned devices of the discovered party will be used as backup devices of the main device in turn; The master device synchronizes task execution information to the backup device and periodically sends survival messages to the backup device. When the backup device detects a failure in the primary device, it immediately starts the primary-backup switchover and notifies other unmanned devices in the network.

5. The unmanned equipment self-organizing network method according to claim 1, characterized in that: Step S3 includes: The discovering unmanned device sends a network resource query message to the discovered unmanned device that has reached a trust consensus; The unmanned device on the discovered side that has reached a trust consensus sends a networking resource report message to the unmanned device on the discovering side; The discovering unmanned device selects a device from the discovered unmanned devices that have reached a trust consensus based on the task resource budget, and sends a networking notification message to the selected discovered unmanned device; The discovering unmanned device establishes a network connection with the selected discovered unmanned device.

6. The unmanned equipment self-organizing network method according to claim 1, characterized in that: The method further comprises: When the network collaboration task is completed, the master device initiates a broadcast message to disband the network of the current business application; The unmanned device that receives the network disbanding broadcast message disconnects the existing network connection.

7. An unmanned equipment self-organizing network system, characterized in that: Different types of business applications are running on the unmanned device; for each business application, a corresponding certificate is installed on the unmanned device; the system includes: A broadcast message sending module is used to, when executing a network collaboration task, enable the unmanned device that initiates the task to send a broadcast message as a master device, wherein the broadcast message carries the service application type that needs to be collaborated and a first challenge code; A trusted device marking module is used to authenticate the unmanned device of the discovered party that receives the broadcast message based on the business application type that needs to be coordinated, the certificate corresponding to the business application type, and the first challenge code. After the authentication is passed, the unmanned device of the discovered party and the unmanned device of the discovered party mark each other as trusted; including: the unmanned device of the discovered party checks whether the business application type supported by itself matches the business application type that needs to be coordinated; if it matches, the unmanned device of the discovered party uses the certificate corresponding to the business application type that needs to be coordinated, calculates based on the first challenge code, and generates a second challenge code locally; the unmanned device of the discovered party sends the calculation result obtained by calculating based on the first challenge code and the second challenge code as a response message to the unmanned device of the discovered party; the unmanned device of the discovered party verifies whether the calculation result obtained by calculating based on the first challenge code meets the requirements; if it meets the requirements, the unmanned device of the discovered party calculates based on the second challenge code; the unmanned device of the discovered party sends the calculation result obtained by calculating based on the second challenge code to the unmanned device of the discovered party, and marks the unmanned device of the discovered party as trusted; the unmanned device of the discovered party verifies whether the calculation result obtained by calculating based on the second challenge code is correct; if it is correct, the unmanned device of the discovered party marks the unmanned device of the discovered party as trusted; The networking module is used to select some unmanned devices from the unmanned devices that have reached a trust consensus for networking.

8. A computer program product comprising a computer program / instructions, characterized in that The computer program / instructions, when executed by a processor, implement the steps of the method of claim 1.

Citation Information

Patent Citations

  • Unmanned ship cluster trusted networking method and system based on block chain, and storage medium

    CN112564895A

  • Identity authentication method and device and user equipment

    CN117998356A