Safe communication method and device with unmanned aerial vehicle, electronic equipment and storage medium
By exchanging and deriving keys in communication between the drone and the ground station, the shared key and session key are generated, the problem of low communication security of the drone is solved and higher communication security is achieved.
Patent Information
- Application Number
- CN202510010952.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-03
- Publication Date
- 2025-05-13
AI Technical Summary
Communication between drones and ground stations is low in security, and is susceptible to monitoring, intercept, tampering or forgery. Sensitive flight data and operation instructions are easily leaked and vulnerable to malicious attacks.
After completing identity authentication with the drone, the key and temporary encryption key sent by the drone are obtained, combined with the key and temporary encryption key generated locally by the ground station, a shared key is generated, and the session key is obtained through the key derivation function, for secure communication.
Enhanced the security of the key, and generates a new key for each communication, improves the security of the communication and prevents attacks such as listening, interception, tampering and forgery.
Smart Images

Figure CN119997008A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of secure communication technology, and in particular to a method, device, electronic device and storage medium for secure communication with an unmanned aerial vehicle. Background Art
[0002] With the innovation of science and technology, the state's regulatory requirements for civil unmanned aerial vehicles ("drones") are becoming increasingly stringent, but the communication security between drones and ground stations still faces challenges.
[0003] At present, the communication signaling between the drone and the ground station is transmitted in plain text or with a fixed password. When the drone and the ground station communicate in plain text or with a fixed password, they will face the following problems:
[0004] Low security: Fixed passwords have low security, and any third party with suitable receiving equipment can monitor, intercept, tamper with or forge these communication signals.
[0005] Privacy leakage: Sensitive flight data and operating instructions can be easily obtained.
[0006] Vulnerable: Drones may be subject to malicious attacks, such as replay attacks, man-in-the-middle attacks, etc. Summary of the invention
[0007] The technical problem to be solved by the embodiments of the present application is to provide a method, device, electronic device and storage medium for secure communication with a drone, so as to improve the communication security between a ground station and the drone.
[0008] In a first aspect, an embodiment of the present application provides a method for secure communication with a drone, which is applied to a ground station, and the method includes:
[0009] After completing identity authentication with the drone, obtaining a first key and a first temporary encryption key sent by the drone;
[0010] Generate a shared key according to the second key and the second temporary encryption key generated locally by the ground station, and the first key and the first temporary encryption key of the drone;
[0011] Performing key derivation processing on the shared key based on a key derivation function to obtain a session key for communicating with the drone;
[0012] The session key is used to securely communicate with the drone.
[0013] In a second aspect, an embodiment of the present application provides a secure communication device with a drone, which is applied to a ground station, and the device includes:
[0014] A drone key acquisition module, used to acquire a first key and a first temporary encryption key sent by the drone after completing identity authentication with the drone;
[0015] a shared key generation module, configured to generate a shared key according to a second key and a second temporary encryption key generated locally by the ground station, and the first key and the first temporary encryption key of the drone;
[0016] A session key acquisition module, used to perform key derivation processing on the shared key based on a key derivation function to obtain a session key for communicating with the drone;
[0017] A secure communication module is used to communicate securely with the drone using the session key.
[0018] In a third aspect, an embodiment of the present application provides an electronic device, including:
[0019] A processor, a memory, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, any of the above-mentioned methods for secure communication with a drone is implemented.
[0020] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium. When the instructions in the storage medium are executed by a processor of an electronic device, the electronic device is enabled to execute any of the above-mentioned methods for secure communication with a drone.
[0021] Compared with the prior art, the embodiments of the present application have the following advantages:
[0022] In an embodiment of the present application, after completing identity authentication with the drone, the first key and the first temporary encryption key sent by the drone are obtained. A shared key is generated based on the second key and the second temporary encryption key generated locally by the ground station, and the first key and the first temporary encryption key of the drone. The shared key is subjected to key derivation processing based on the key derivation function to obtain a session key for communicating with the drone, and the session key is used to communicate securely with the drone. The embodiment of the present application generates a shared key by exchanging keys with the drone, thereby enhancing the security of the key. At the same time, a key derivation algorithm is used to derive a session key SK for encrypted communication. A new key is generated for each communication, thereby improving the security of the communication.
[0023] It should be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] Figure 1A flowchart of a method for secure communication with a drone provided in an embodiment of the present application;
[0025] Figure 2 A flowchart of a method for obtaining a shared key provided in an embodiment of the present application;
[0026] Figure 3 A flowchart of a method for obtaining a session key provided in an embodiment of the present application;
[0027] Figure 4 A flowchart of a method for generating a session key provided in an embodiment of the present application;
[0028] Figure 5 A flowchart of a method for updating a session key provided in an embodiment of the present application;
[0029] Figure 6 A schematic diagram of the structure of a secure communication device with a drone provided in an embodiment of the present application;
[0030] Figure 7 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0031] In order to make the above-mentioned objects, features and advantages of the present application more obvious and easy to understand, the present application is further described in detail below in conjunction with the accompanying drawings and specific implementation methods.
[0032] The terms used in the embodiments of the present application are only for the purpose of describing specific embodiments, and are not intended to limit the present application. The singular forms "a", "said" and "the" used in the embodiments of the present application and the appended claims are also intended to include plural forms, unless the context clearly indicates other meanings.
[0033] Reference Figure 1 , shows a flowchart of a method for secure communication with a drone provided by an embodiment of the present application, which can be applied to a ground station. Figure 1 As shown, the method for secure communication with a drone may include: step 101, step 102, step 103 and step 104.
[0034] Step 101: After completing identity authentication with the drone, obtain a first key and a first temporary encryption key sent by the drone.
[0035] The embodiments of the present application can be applied to a ground station, that is, the execution entity is a ground station.
[0036] Authentication refers to the process of verifying the identity of an entity to confirm whether it has the right to access a system or perform a specific operation. In drone systems, authentication between ground stations and drones is crucial, as it not only prevents unauthorized access and operation, but also ensures the integrity and security of data. Authentication between ground stations and drones is a key link in ensuring the safe and effective operation of drones. By adopting appropriate authentication methods and technologies and continuously optimizing authentication processes and mechanisms, the safety and reliability of drones can be effectively improved.
[0037] After the ground station and the drone complete identity authentication, the ground station can exchange data securely with the drone. At this time, the first key and the first temporary encryption key sent by the drone can be obtained. Among them, the first key and the first temporary encryption key can both be keys generated by the drone side. In this example, the first key can include: a public key and a private key. Similarly, the first temporary encryption key can also include: a temporary encryption public key and a temporary encryption private key.
[0038] In a specific implementation, the first key can be generated by the drone based on a certain encryption algorithm (such as a symmetric encryption algorithm or an asymmetric encryption algorithm, etc.). Specifically, the drone can use a secure key pair generation algorithm to generate a public key and a private key. These algorithms can ensure that the generated key pair is sufficiently secure and difficult to crack. The first temporary encryption key is also generated by the drone side using a certain encryption algorithm (such as a symmetric encryption algorithm, etc.). Unlike the first key, it is usually used to temporarily encrypt specific data or sessions. After use, the temporary encryption key is usually destroyed or replaced to ensure the security of communication. After the first key and the first temporary encryption key are generated, the drone can send the first key and the first temporary encryption key to the ground station in a secure manner (such as an encrypted communication protocol, etc.).
[0039] After obtaining the first key and the first temporary encryption key sent by the drone, execute step 102.
[0040] Step 102: Generate a shared key based on the second key and the second temporary encryption key generated locally by the ground station, and the first key and the first temporary encryption key of the drone.
[0041] The second key and the second temporary encryption key are keys generated locally by the ground station. In this example, the second key may include: a public key and a private key. Similarly, the second temporary encryption key may also include: a temporary encryption public key and a temporary encryption private key.
[0042] In a specific implementation, the second key may be generated by the ground station based on a certain encryption algorithm (such as a symmetric encryption algorithm or an asymmetric encryption algorithm, etc.). The second temporary encryption key is also generated by the ground station through a certain encryption algorithm. Unlike the second key, it is usually used to temporarily encrypt specific data or sessions. After use, the temporary encryption key is usually destroyed or replaced to ensure the security of communication.
[0043] After obtaining the first key and the first temporary encryption key of the drone, a shared key can be generated based on the second key and the second temporary encryption key generated locally by the ground station, as well as the first key and the first temporary encryption key of the drone. In this embodiment, a triple key exchange method can be used to generate a shared key. Figure 2 This is described in detail as follows.
[0044] Reference Figure 2 , shows a flowchart of a method for obtaining a shared key provided by an embodiment of the present application. Figure 2 As shown, the shared key acquisition method may include: step 201, step 202, step 203 and step 204.
[0045] Step 201: Based on a preset key exchange protocol, the second private key and the first temporary encryption public key are exchanged to obtain a first shared key.
[0046] In this embodiment, the first key may include: a first private key and a first public key, the first temporary encryption key may include: a first temporary encryption public key and a first temporary encryption private key, the second key may include: a second private key and a second public key, and the second temporary encryption key may include: a second temporary encryption public key and a second temporary encryption private key.
[0047] The preset key exchange protocol may be Diffie-Hellman, and the key exchange protocol Diffie-Hellman, also known as the DH key exchange protocol, is a secure key exchange method. The Diffie-Hellman key exchange protocol allows two users (usually two parties who need secure communication) to securely exchange encryption keys over an insecure communication channel.
[0048] In this example, the second private key and the first temporary encryption public key can be exchanged based on a preset key exchange protocol to obtain a first shared key. a ) and drone B’s temporary encryption public key (EK B ) performs Diffie-Hellman key exchange to obtain the shared key DH1, that is, DH1 = DH (IK a ,EK B ).
[0049] Step 202: Based on a preset key exchange protocol, the second temporary encryption public key and the first private key are exchanged to obtain a second shared key.
[0050] In this example, the second temporary encryption public key and the first private key can be exchanged based on a preset key exchange protocol to obtain a second shared key. Specifically, the temporary encryption public key (EK A ) and drone B’s private key (IK b ) to exchange keys and obtain the shared key DH2, that is, DH2 = DH (EK A ,IK b ).
[0051] Step 203: Based on a preset key exchange protocol, the first temporary encryption public key and the second temporary encryption public key are exchanged to obtain a third shared key.
[0052] In this example, the first temporary encryption public key and the second temporary encryption public key can be exchanged based on the preset key exchange protocol to obtain the third shared key. Specifically, the temporary encryption public key (EK A ) and drone B’s temporary encryption public key (EK B ) to exchange keys and obtain the shared key DH3, that is, DH3 = DH (EK A ,EK B ).
[0053] Step 204: The first shared key, the second shared key and the third shared key are collectively used as the shared key.
[0054] After the first shared key, the second shared key and the third shared key are obtained, the first shared key, the second shared key and the third shared key may be used together as the shared key for this time.
[0055] The embodiment of the present application ensures the integrity and confidentiality of key exchange by adopting a triple key exchange method.
[0056] After a shared key is generated according to the second key and the second temporary encryption key generated locally by the ground station, and the first key and the first temporary encryption key of the drone, step 103 is performed.
[0057] Step 103: Perform key derivation processing on the shared key based on a key derivation function to obtain a session key for communicating with the drone.
[0058] A key derivation function (KDF) is a cryptographic technique used to generate one or more derived keys from one or more original keys (also called "source keys", "master keys", etc.). These derived keys can be used for various cryptographic operations, such as data encryption, message authentication code (MAC) generation, etc., thereby enhancing the overall security of the system.
[0059] After generating a shared key based on the second key and the second temporary encryption key generated locally by the ground station, and the first key and the first temporary encryption key of the drone, the key derivation function can be used to derive the shared key to obtain the session key for communicating with the drone. Figure 3 This is described in detail as follows.
[0060] Reference Figure 3 , shows a flow chart of the steps of a method for obtaining a session key provided by an embodiment of the present application. Figure 3 As shown, the session key acquisition method may include: step 301 and step 302.
[0061] Step 301: concatenate the first shared key, the second shared key and the third shared key to obtain a concatenated shared key.
[0062] In this embodiment, after the first shared key, the second shared key and the third shared key are obtained, the first shared key, the second shared key and the third shared key may be concatenated to obtain a concatenated shared key.
[0063] In a specific implementation, the concatenation order of the three shared keys may be pre-specified to ensure that both parties can generate the same concatenated shared key.
[0064] After the first shared key, the second shared key and the third shared key are concatenated to obtain a concatenated shared key, step 302 is performed.
[0065] Step 302: Perform key derivation processing on the concatenated shared key based on the key derivation function to obtain the session key.
[0066] After the first shared key, the second shared key and the third shared key are concatenated to obtain the concatenated shared key, the concatenated shared key can be subjected to key derivation processing based on the key derivation function to obtain a session key for communication with the drone. The session key SK = KDF (DH1||DH2||DH3).
[0067] The key derivation function can be combined with the shared key to generate the session key. Figure 4This is described in detail as follows.
[0068] Reference Figure 4 , shows a flow chart of the steps of a session key generation method provided by an embodiment of the present application. Figure 4 As shown, the session key generation method may include: step 401 and step 402.
[0069] Step 401: Obtain the specified key derivation length and the derivation parameters corresponding to the key derivation function.
[0070] In this embodiment, the length of the specified key derivation and the derivation parameters corresponding to the key derivation function can be obtained. In this example, the length of the specified derived key can be 32 bytes, and the derivation parameters can be the Appinfo application information of the KDF, which is used to add context information of the key derivation process in the KDF.
[0071] After obtaining the specified key derivation length and the derivation parameters corresponding to the key derivation function, step 402 is executed.
[0072] Step 402: Perform hash processing on the concatenated shared key and the derived parameter based on the SM3 hash algorithm to obtain the session key of the specified key derivation length.
[0073] After obtaining the derived parameters corresponding to the key derivation function, the concatenated shared key and the derived parameters can be hashed based on the SM3 hash algorithm to obtain a session key of the specified key derivation length for secure communication with no one.
[0074] Among them, the SM3 algorithm is a cryptographic hash algorithm issued by the China National Cryptography Administration, similar to SHA-256, and is used to generate a fixed-length hash value of data. The process of obtaining the session key can be to concatenate the shared key and the derived parameter into a string. For example, if the shared key is shared_key and the derived parameter is derived_param, the concatenated string is shared_key+derived_param. Then, the SM3 algorithm can be used to hash the concatenated string, and the resulting hash value is the session key.
[0075] The embodiment of the present application derives a session key by using a combination of the KDF algorithm and the SM3 hash algorithm, which can ensure the strength and security of the session key, thereby improving the communication security between the ground station and the drone.
[0076] In this embodiment, an update key may also be generated based on the encryption key, the authentication key, and the derived parameters, so that when the update condition of the session key is met, the update key is used to update the session key. Figure 5This is described in detail as follows.
[0077] Reference Figure 5 , shows a flow chart of the steps of a session key update method provided by an embodiment of the present application. Figure 5 As shown, the session key updating method may include: step 501 and step 502.
[0078] Step 501: The session key and the derived parameter are hashed based on the SM3 hash algorithm to obtain an encryption key for encryption and an authentication key for message authentication.
[0079] After the concatenated shared key and the derived parameter are hashed based on the SM3 hash algorithm to obtain the session key, the session key and the derived parameter can be hashed based on the SM3 hash algorithm to obtain an encryption key for encryption and an authentication key for message authentication. Specifically, the session key and the derived parameter can be concatenated into a string, and the SM3 algorithm is used to hash the string to obtain an encryption key for encryption and an authentication key for message authentication.
[0080] After the session key and the derived parameters are hashed based on the SM3 hash algorithm to obtain an encryption key for encryption and an authentication key for message authentication, step 502 is executed.
[0081] Step 502: The encryption key, the authentication key and the derived parameter are hashed based on the SM3 hash algorithm to generate an updated session key to securely communicate with the drone through the updated session key.
[0082] Determining that the update condition of the session key is currently met may include at least one of the following:
[0083] 1. When the time between the current time and the generation time of the session key reaches the set time, it is determined that the update condition of the session key is met. In network security and data communication, the update of the session key is an important security measure to enhance the security of communication. The session key is used to securely transmit data between the communicating parties. As time goes by, the security of the key may decrease, so it is necessary to update the session key regularly. In this example, it is necessary to set a maximum validity period of the session key. This period can be set according to security requirements, communication frequency, and the complexity of key management. When a new session key is generated, the generation time of the key needs to be recorded. This timestamp will be used to determine whether the key needs to be updated later. During the communication process, the current time is checked regularly (or each time communication is performed), and the time difference is calculated based on the recorded key generation time and the current time, and the calculated time difference is compared with the set maximum validity period. If the time difference is greater than or equal to the maximum validity period, it is determined that the update condition of the session key is met.
[0084] 2. When a security threat is detected in the communication with the drone, determine that the update conditions of the session key are met. Specifically, a special security monitoring system can be deployed to monitor abnormal behavior or potential threats in the drone communication process in real time, such as using advanced detection technologies such as radar detection, radio frequency detection and optical detection, etc., to improve the monitoring capabilities of drone communications. When the monitoring system detects abnormal behavior, it immediately performs threat identification to determine whether it is a potential security threat. Threat identification can be based on known attack patterns, behavioral characteristics or abnormal traffic. After identifying the security threat, it is determined that the update conditions of the session key are met.
[0085] 3. When the communication with the drone is disconnected and reconnected, determine that the update conditions of the session key are met. Specifically, a special communication status monitoring system can be deployed to monitor the communication status between the drone and the ground control station in real time. After the communication is reestablished, strict identity authentication and connection verification are performed to ensure the validity and security of the connection. After the verification is passed, it can be determined that the update conditions of the session key are met.
[0086] It is understandable that the update conditions of the session key are not limited to the above three conditions. In a specific implementation, the update conditions of the session key can also be set according to business requirements, which is not limited in this embodiment.
[0087] When it is determined that the update conditions for the session key are currently met, the encryption key, authentication key and derived parameters can be hashed based on the SM3 hash algorithm to obtain an updated session key, so as to communicate securely with the drone through the updated session key.
[0088] The embodiment of the present application performs hash processing on encryption keys, authentication keys and derived parameters based on the SM3 hash algorithm to obtain an updated session key, and uses the key to communicate securely with the drone, which can significantly enhance the security of communications, improve the efficiency of key updates, ensure data integrity, and support a variety of application scenarios.
[0089] After the shared key is subjected to key derivation processing based on the key derivation function to obtain the session key for communicating with the drone, step 104 is executed.
[0090] Step 104: Use the session key to communicate securely with the drone.
[0091] After the shared key is derived based on the key derivation function to obtain the session key for communicating with the drone, the session key can be used to communicate securely with the drone. Specifically, the ground station can use the session key SK to encrypt communication signaling and communication data. Each time it communicates with the drone, a session key SK is calculated to ensure that both parties can exchange keys securely even in an insecure communication channel, and use these keys to encrypt communications and verify the integrity of messages.
[0092] It can be understood that since the shared key is generated by exchanging keys with the drone during the session key generation process, the same session key as that on the ground station side can also be generated on the drone side, which can be used to decrypt encrypted communication signaling and communication data to realize the data decryption process.
[0093] The secure communication method with the drone provided in the embodiment of the present application obtains the first key and the first temporary encryption key sent by the drone after completing identity authentication with the drone. A shared key is generated based on the second key and the second temporary encryption key generated locally by the ground station, as well as the first key and the first temporary encryption key of the drone. The shared key is key-derived based on the key derivation function to obtain a session key for communicating with the drone, and the session key is used to communicate securely with the drone. The embodiment of the present application generates a shared key by exchanging keys with the drone, thereby enhancing the security of the key. At the same time, a key derivation algorithm is used to derive a session key SK for encrypted communication. A new key is generated for each communication, thereby improving the security of the communication.
[0094] Reference Figure 6 , shows a schematic diagram of the structure of a secure communication device with a drone provided in an embodiment of the present application, which can be applied to a ground station. Figure 6 As shown, the secure communication device 600 with the drone may include the following modules:
[0095] The drone key acquisition module 610 is used to acquire the first key and the first temporary encryption key sent by the drone after completing identity authentication with the drone;
[0096] A shared key generation module 620, configured to generate a shared key according to the second key and the second temporary encryption key generated locally by the ground station, and the first key and the first temporary encryption key of the drone;
[0097] A session key acquisition module 630, configured to perform key derivation processing on the shared key based on a key derivation function to obtain a session key for communicating with the drone;
[0098] The secure communication module 640 is used to use the session key to communicate securely with the drone.
[0099] Optionally, the first key includes: a first private key and a first public key, the first temporary encryption key includes: a first temporary encryption public key and a first temporary encryption private key, the second key includes: a second private key and a second public key, the second temporary encryption key includes: a second temporary encryption public key and a second temporary encryption private key,
[0100] The shared key generation module comprises:
[0101] A first shared key acquisition unit, configured to perform key exchange on the second private key and the first temporary encryption public key based on a preset key exchange protocol to obtain a first shared key;
[0102] A second shared key acquisition unit, configured to perform a key exchange on the second temporary encryption public key and the first private key based on a preset key exchange protocol to obtain a second shared key;
[0103] A third shared key acquisition unit, configured to perform key exchange on the first temporary encryption public key and the second temporary encryption public key based on a preset key exchange protocol to obtain a third shared key;
[0104] The shared key acquisition unit is used to use the first shared key, the second shared key and the third shared key together as the shared key.
[0105] Optionally, the session key acquisition module includes:
[0106] a shared key concatenation unit, configured to concatenate the first shared key, the second shared key and the third shared key to obtain a concatenated shared key;
[0107] The session key acquisition unit is used to perform key derivation processing on the concatenated shared key based on the key derivation function to obtain the session key.
[0108] Optionally, the session key obtaining unit includes:
[0109] A derived parameter acquisition subunit, used to acquire the specified key derivation length and the derived parameters corresponding to the key derivation function;
[0110] The session key acquisition subunit is used to perform hash processing on the concatenated shared key and the derived parameter based on the SM3 hash algorithm to obtain the session key of the specified key derivation length.
[0111] Optionally, the device further comprises:
[0112] A key acquisition module, used for performing hash processing on the session key and the derived parameter based on the SM3 hash algorithm to obtain an encryption key for encryption and an authentication key for message authentication;
[0113] The update key generation module is used to, when it is determined that the update condition of the session key is currently met, hash the encryption key, the authentication key and the derived parameter based on the SM3 hash algorithm to generate an updated session key, so as to communicate securely with the drone through the updated session key.
[0114] Optionally, the session key update module includes:
[0115] The first condition determination unit is used to determine that the update condition of the session key is met when the time length between the current time and the generation time of the session key reaches a set time length.
[0116] Optionally, the session key update module includes:
[0117] The second condition determination unit is used to determine whether the update condition of the session key is met when a security threat is detected in the communication with the drone.
[0118] Optionally, the session key update module includes:
[0119] The third condition determination unit is used to determine whether the update condition of the session key is met when the communication with the drone is disconnected and reconnected.
[0120] The secure communication device with the drone provided in the embodiment of the present application obtains the first key and the first temporary encryption key sent by the drone after completing identity authentication with the drone. A shared key is generated based on the second key and the second temporary encryption key generated locally by the ground station, as well as the first key and the first temporary encryption key of the drone. The shared key is key-derived based on the key derivation function to obtain a session key for communicating with the drone, and the session key is used to communicate securely with the drone. The embodiment of the present application generates a shared key by exchanging keys with the drone, thereby enhancing the security of the key. At the same time, a key derivation algorithm is used to derive a session key SK for encrypted communication. A new key is generated for each communication, thereby improving the security of the communication.
[0121] An embodiment of the present application also provides an electronic device, including: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program implements the above-mentioned method for secure communication with a drone when executed by the processor.
[0122] Figure 7 FIG. 7 is a schematic diagram showing the structure of an electronic device 700 according to an embodiment of the present invention. Figure 7 As shown, the electronic device 700 includes a central processing unit (CPU) 701, which can perform various appropriate actions and processes according to computer program instructions stored in a read-only memory (ROM) 702 or computer program instructions loaded from a storage unit 708 into a random access memory (RAM) 703. In the RAM 703, various programs and data required for the operation of the electronic device 700 can also be stored. The CPU 701, the ROM 702, and the RAM 703 are connected to each other via a bus 704. An input / output (I / O) interface 705 is also connected to the bus 704.
[0123] Multiple components in the electronic device 700 are connected to the I / O interface 705, including: an input unit 706, such as a keyboard, a mouse, a microphone, etc.; an output unit 707, such as various types of displays, speakers, etc.; a storage unit 708, such as a disk, an optical disk, etc.; and a communication unit 709, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 709 allows the electronic device 700 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.
[0124] The various processes and processing described above may be performed by the processing unit 701. For example, the method of any of the above embodiments may be implemented as a computer software program, which is tangibly contained in a computer-readable medium, such as the storage unit 708. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 700 via the ROM 702 and / or the communication unit 709. When the computer program is loaded into the RAM 703 and executed by the CPU 701, one or more actions in the method described above may be performed.
[0125] In addition, an embodiment of the present application further provides a computer-readable storage medium on which a computer program is stored, and when the program is executed by a processor, the above-mentioned method for secure communication with a drone is implemented.
[0126] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.
[0127] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, devices, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0128] The embodiments of the present application are described with reference to the flowcharts and / or block diagrams of the methods, terminals (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0129] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing terminal to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0130] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal so that a series of operating steps are executed on the computer or other programmable terminal to produce a computer-implemented process, thereby providing instructions for implementing the process in the computer or other programmable terminal. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0131] Although the preferred embodiments of the present application have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the embodiments of the present application.
[0132] Finally, it should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or terminal including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or terminal. In the absence of further restrictions, the elements defined by the statement "comprise a ..." do not exclude the presence of other identical elements in the process, method, article or terminal including the elements.
[0133] The above is a detailed introduction to a method, device, electronic device and computer-readable storage medium for secure communication with a drone provided by the present application. Specific examples are used in this article to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea; at the same time, for general technicians in this field, according to the ideas of the present application, there will be changes in the specific implementation methods and application scopes. In summary, the content of this specification should not be understood as a limitation on the present application.
Claims
1. A method for secure communication with a drone, characterized in that: Applied to a ground station, the method comprises: After completing identity authentication with the drone, obtaining a first key and a first temporary encryption key sent by the drone; Generate a shared key according to the second key and the second temporary encryption key generated locally by the ground station, and the first key and the first temporary encryption key of the drone; Performing key derivation processing on the shared key based on a key derivation function to obtain a session key for communicating with the drone; The session key is used to securely communicate with the drone.
2. The method according to claim 1, characterized in that The first key includes: a first private key and a first public key, the first temporary encryption key includes: a first temporary encryption public key and a first temporary encryption private key, the second key includes: a second private key and a second public key, the second temporary encryption key includes: a second temporary encryption public key and a second temporary encryption private key, The step of generating a shared key according to the second key and the second temporary encryption key generated locally by the ground station, and the first key and the first temporary encryption key of the drone comprises: Performing key exchange on the second private key and the first temporary encryption public key based on a preset key exchange protocol to obtain a first shared key; Performing a key exchange on the second temporary encryption public key and the first private key based on a preset key exchange protocol to obtain a second shared key; Performing key exchange on the first temporary encryption public key and the second temporary encryption public key based on a preset key exchange protocol to obtain a third shared key; The first shared key, the second shared key and the third shared key are collectively used as the shared key.
3. The method according to claim 2, characterized in that The step of performing key derivation processing on the shared key based on a key derivation function to obtain a session key for communicating with the drone includes: Concatenate the first shared key, the second shared key, and the third shared key to obtain a concatenated shared key; The concatenated shared key is subjected to key derivation processing based on the key derivation function to obtain the session key.
4. The method according to claim 3, characterized in that The step of performing key derivation processing on the concatenated shared key based on the key derivation function to obtain the session key includes: Obtaining a specified key derivation length and a derivation parameter corresponding to the key derivation function; The concatenated shared key and the derived parameter are hashed based on the SM3 hash algorithm to obtain the session key of the specified key derivation length.
5. The method according to claim 4, characterized in that After performing hash processing on the concatenated shared key and the derived parameter based on the SM3 hash algorithm to obtain the session key of the specified key derivation length, the method further includes: Performing hash processing on the session key and the derived parameter based on the SM3 hash algorithm to obtain an encryption key for encryption and an authentication key for message authentication; When it is determined that the update condition of the session key is currently met, the encryption key, the authentication key and the derived parameter are hashed based on the SM3 hash algorithm to generate an updated session key to securely communicate with the drone through the updated session key.
6. The method according to claim 5, characterized in that The determining that the update condition of the session key is currently met includes: When the time length between the current time and the generation time of the session key reaches the set time length, it is determined that the update condition of the session key is met.
7. The method according to claim 5, characterized in that The determining that the update condition of the session key is currently met includes: In the event that a security threat is detected in the communication with the drone, it is determined that a condition for updating the session key is met.
8. The method according to claim 5, characterized in that The determining that the update condition of the session key is currently met includes: When the communication with the drone is disconnected and reconnected, it is determined that the update condition of the session key is met.
9. A secure communication device with a drone, characterized in that: Applied to a ground station, the device comprises: A drone key acquisition module, used to acquire a first key and a first temporary encryption key sent by the drone after completing identity authentication with the drone; a shared key generation module, configured to generate a shared key according to a second key and a second temporary encryption key generated locally by the ground station, and the first key and the first temporary encryption key of the drone; A session key acquisition module, used to perform key derivation processing on the shared key based on a key derivation function to obtain a session key for communicating with the drone; A secure communication module is used to communicate securely with the drone using the session key.
10. An electronic device, characterized in that: include: A processor, a memory, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method for secure communication with a drone according to any one of claims 1 to 8 when executing the program.
11. A computer-readable storage medium, characterized in that: When the instructions in the storage medium are executed by a processor of an electronic device, the electronic device is enabled to execute the method for secure communication with a drone according to any one of claims 1 to 8.