Access method and device of flight equipment, processing equipment and storage medium

By establishing a security verification mechanism between the terminal and the gateway, the problem of low security in the predetermined network is solved, secure access to flight equipment is ensured, and network security and reliability are improved.

CN120034865APending Publication Date: 2025-05-23CHINA MOBILE CHENGDU INFORMATION & TELECOMM TECH CO LTD +1
View PDF 0 Cites -1 Cited by

Patent Information

Application Number
CN202311571248.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-22
Publication Date
2025-05-23

Smart Images

  • Figure CN120034865A_ABST
    Figure CN120034865A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses an access method and device of flight equipment, processing equipment and a storage medium. The method comprises the following steps: in response to received first request information sent by flight equipment, sending second request information to a gateway; receiving first response information sent by the gateway for the second request information; wherein the first response information indicates that the flight equipment has the authority or does not have the authority; and based on the first response information, accessing the flight equipment to the predetermined network under the condition of determining to establish the communication connection between the terminal and the flight equipment. According to the embodiment of the invention, the flight equipment can be ensured to be safely accessed to the predetermined network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to but is not limited to the field of communications, and in particular to an access method, device, processing device and storage medium for flight equipment. Background Art

[0002] In the related art, a predetermined network can be used to provide services for the flight equipment to ensure a good flight effect of the flight equipment. However, in the related art, in the process of using the predetermined network to provide services for the flight equipment, the predetermined network may be attacked by the outside network, resulting in the predetermined network being unable to safely provide services for the flight equipment. In this way, the security of the predetermined network in the related art is low, and it is difficult for the predetermined network to provide safe services for the flight equipment. Summary of the invention

[0003] In view of this, the embodiments of the present disclosure disclose an access method, device, processing device and storage medium for aircraft equipment, which can enable the aircraft equipment to safely access a predetermined network. The technical solution disclosed in the embodiments of the present disclosure can solve the technical problem of how to ensure the security of the predetermined network.

[0004] According to a first aspect of an embodiment of the present disclosure, a method for accessing an aircraft device is provided, the method being applied to a terminal, the method comprising:

[0005] In response to receiving the first request information sent by the flight device, sending a second request information to the gateway; wherein the first request information is used to request to establish a communication connection between the terminal and the flight device; the terminal is used for the flight device to access a predetermined network through the terminal, and the predetermined network is used to provide services for at least two flight devices; the second request information is used to request the gateway to perform security verification on the flight device to determine whether the flight device has the authority to establish a communication connection with the terminal;

[0006] Receiving a first response message sent by the gateway in response to the second request message; wherein the first response message indicates that the flight device has the authority or does not have the authority;

[0007] Based on the first response information, when it is determined that a communication connection between the terminal and the aircraft device is established, the aircraft device is connected to the predetermined network.

[0008] In one embodiment, the second request information indicates a first identifier, which is determined jointly based on the device identifier of the aircraft device and the terminal identifier of the terminal; the second request information is used to request the gateway to perform security verification on the first identifier to determine whether the aircraft device has the authority to establish a communication connection with the terminal.

[0009] In one embodiment, the method further comprises:

[0010] In response to the first response information indicating that the aircraft device has the authority, determining to establish a communication connection between the terminal and the aircraft device;

[0011] or,

[0012] In response to the first response information indicating that the aircraft device does not have the authority, determining not to establish a communication connection between the terminal and the aircraft device.

[0013] In one embodiment, the terminal is not connected to the predetermined network, the second request information is used to request the gateway to perform security verification on the aircraft device and the terminal to determine whether the aircraft device has the authority to establish a communication connection with the terminal and whether the terminal has the authority to access the predetermined network, and in response to the first response information indicating that the aircraft device has the authority, determining to establish a communication connection between the terminal and the aircraft device includes:

[0014] In response to the first response information indicating that the flight device has the authority to establish a communication connection with the terminal and the terminal has the authority to access the predetermined network, establishing a communication connection between the gateway and the terminal; wherein the gateway is used for the terminal to access the predetermined network through the gateway;

[0015] In response to a successful establishment of a communication connection between the gateway and the terminal, it is determined to establish a communication connection between the terminal and the flight device.

[0016] In one embodiment, the receiving gateway sends a first response message in response to the second request message, including:

[0017] receiving a second response message sent by the gateway in response to the second request message; wherein the second response message indicates a verification result of the safety verification of the flight device;

[0018] In response to the verification result being a verification pass result, sending a third request message to the gateway; wherein the third request message is used to request the gateway to determine whether the flight device is in a device list corresponding to the terminal; the flight device in the device list has the authority to establish a communication connection with the terminal;

[0019] The first response information sent by the gateway in response to the third request information is received.

[0020] According to a second aspect of an embodiment of the present disclosure, a method for accessing an aircraft device is provided, the method being applied to a gateway, the method comprising:

[0021] , receiving second request information sent by a terminal; wherein the second request information is information sent by the terminal when receiving the first request information sent by the aircraft device; the terminal is used for the aircraft device to access a predetermined network through the terminal, and the predetermined network is used to provide services for at least two aircraft devices; the first request information is used to request to establish a communication connection between the terminal and the aircraft device; the second request information is used to perform security verification on the aircraft device to determine whether the aircraft device has the authority to establish a communication connection with the terminal;

[0022] In response to receiving the second request information, a first response information is sent to the terminal; wherein the first response information indicates that the aircraft device has the authority, or the first response information indicates that the aircraft device does not have the authority; the first response information is used for: allowing the terminal to connect the aircraft device to the predetermined network when determining to establish the communication connection based on the first response information.

[0023] In one embodiment, in response to receiving the second request information, sending first response information to the terminal, the method further includes:

[0024] In response to receiving the second request information, performing security verification on the aircraft device to determine whether the aircraft device has the authority, and obtaining a determination result;

[0025] Based on the determination result, the first response information is sent to the terminal.

[0026] In one embodiment, the second request information indicates a first identifier, and the first identifier is jointly determined according to a device identifier of the aircraft device and a terminal identifier of the terminal; and the performing security verification on the aircraft device to determine whether the aircraft device has the authority includes:

[0027] The first identification is subjected to security verification to determine whether the aircraft device has the authority to establish a communication connection with the terminal.

[0028] In one embodiment, in response to receiving the second request information, performing security verification on the aircraft device to determine whether the aircraft device has the authority, and obtaining a determination result includes:

[0029] In response to receiving the second request information, sending a second response information to the terminal; wherein the second response information indicates a verification result of the safety verification of the flight equipment;

[0030] In response to the verification result being a verification passed result, receiving a third request message sent by the terminal in response to the second response message; wherein the third request message is used to determine whether the aircraft device is in a device list corresponding to the terminal; and the aircraft device in the device list has the authority to establish a communication connection with the terminal;

[0031] Determine whether the flying device is in the device list and obtain a determination result.

[0032] According to a third aspect of an embodiment of the present disclosure, there is provided a method for accessing an aircraft device, the method being applied to an aircraft device, the method comprising:

[0033] In response to the distance between the aircraft device and the terminal being within a first distance, sending a first request message to the terminal; wherein the first request message is used to request to establish a communication connection between the terminal and the aircraft device and trigger the terminal to send a second request message to a gateway; the second request message is used to request the gateway to perform security verification on the aircraft device to determine whether the aircraft device has the authority to establish a communication connection with the terminal; the terminal is used for the aircraft device to access a predetermined network through the terminal, and the predetermined network is used to provide services for at least two aircraft devices;

[0034] In response to the aircraft device having the authority to establish a communication connection with the terminal, a communication connection is established between the aircraft device and the terminal, and the predetermined network is accessed through the terminal.

[0035] According to a fourth aspect of an embodiment of the present disclosure, there is provided an access device for a flight device, the access device comprising:

[0036] A first sending module is configured to send a second request message to a gateway in response to receiving a first request message sent by an aircraft device; wherein the first request message is used to request to establish a communication connection between the terminal and the aircraft device; the terminal is used for the aircraft device to access the predetermined network through the terminal, and the predetermined network is used to provide services for at least two aircraft devices; and the second request message is used to request the gateway to perform security verification on the aircraft device to determine whether the aircraft device has the authority to establish a communication connection with the terminal;

[0037] A first receiving module is configured to receive a first response message sent by the gateway in response to the second request message; wherein the first response message indicates that the flight device has the authority or does not have the authority;

[0038] The first connection module is configured to connect the aircraft device to the predetermined network when it is determined that a communication connection between the terminal and the aircraft device is to be established based on the first response information.

[0039] According to a fifth aspect of an embodiment of the present disclosure, there is provided an access device for a flight device, the access device comprising:

[0040] a second receiving module, configured to receive second request information sent by a terminal; wherein the second request information is information sent by the terminal when the terminal receives the first request information sent by the aircraft device; the terminal is used for the aircraft device to access a predetermined network through the terminal, and the predetermined network is used to provide services for at least two aircraft devices; the first request information is used to request to establish a communication connection between the terminal and the aircraft device; the second request information is used to perform security verification on the aircraft device to determine whether the aircraft device has the authority to establish a communication connection with the terminal;

[0041] A second sending module is used to send a first response message to the terminal in response to receiving the second request information; wherein, the first response information indicates that the aircraft device has the authority, or the first response information indicates that the aircraft device does not have the authority; the first response information is used for; when the terminal determines to establish the communication connection based on the first response information, the aircraft device is connected to the predetermined network.

[0042] According to a sixth aspect of an embodiment of the present disclosure, there is provided an access device for a flight device, the access device comprising:

[0043] A third sending module, in response to the distance between the aircraft device and the terminal being within a first distance, sends a first request message to the terminal; wherein the first request message is used to request to establish a communication connection between the terminal and the aircraft device and trigger the terminal to send a second request message to the gateway; the second request message is used to request the gateway to perform security verification on the aircraft device to determine whether the aircraft device has the authority to establish a communication connection with the terminal; the terminal is used for the aircraft device to access a predetermined network through the terminal, and the predetermined network is used to provide services for at least two aircraft devices;

[0044] The second connection module establishes a communication connection between the aircraft device and the terminal in response to the aircraft device having the authority to establish a communication connection with the terminal, and accesses the predetermined network through the terminal.

[0045] According to a seventh aspect of an embodiment of the present disclosure, a processing device is provided, the processing device comprising:

[0046] A memory for storing executable programs;

[0047] The processor is used to implement any method described in the embodiments of the present disclosure when executing the executable program stored in the memory.

[0048] According to an eighth aspect of the embodiments of the present disclosure, a computer storage medium is provided, wherein the computer storage medium stores an executable program, and when the executable program is executed by a processor, it implements any method described in the embodiments of the present disclosure.

[0049] In the embodiment of the present disclosure, since the second request information is sent to the gateway, the gateway is requested to perform security verification on the aircraft device through the second request information to determine whether the aircraft device has the authority to establish a communication connection with the terminal. Therefore, before the aircraft device accesses the predetermined network, the gateway can be used to verify the security of the aircraft device in advance to ensure that only the aircraft device with high security has the authority to establish a communication connection with the terminal. At this time, when it is necessary to determine whether to establish a communication connection between the aircraft device and the terminal so that the aircraft device connected to the terminal can access the predetermined network through the terminal, that is, when it is necessary to determine whether the aircraft device can access the predetermined network, only the communication connection between the aircraft device with high security and the terminal can be established so that only the aircraft device with high security can access the predetermined network. Compared with the method in the related art that the predetermined network cannot safely provide services to the aircraft devices in the predetermined network, in the embodiment of the present disclosure, the aircraft devices with high security that can access the predetermined network can be determined before the aircraft device accesses the network, and only the aircraft devices with high security are connected to the predetermined network to ensure the security of the predetermined network when providing services. In this way, the high security of flight equipment connected to the scheduled network can be ensured in advance, and the situation in which the scheduled network has been attacked by network and caused losses due to security verification of the flight equipment only after the unsafe flight equipment is connected to the scheduled network can be reduced. The security of the scheduled network can be ensured, and the service effect of the secure scheduled network for each flight device can be ensured. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] Figure 1 FIG. 1 is a flow chart of a method for accessing a flight device according to an exemplary embodiment. Figure 1 ;

[0051] Figure 2 FIG. 1 is a flow chart of a method for accessing a flight device according to an exemplary embodiment. Figure 2 ;

[0052] Figure 3 FIG. 1 is a flow chart of a method for accessing a flight device according to an exemplary embodiment. Figure 3 ;

[0053] Figure 4 FIG. 1 is a flow chart of a method for accessing a flight device according to an exemplary embodiment. Figure 4 ;

[0054] Figure 5 FIG. 1 is a flow chart of a method for accessing a flight device according to an exemplary embodiment. Figure 5 ;

[0055] Figure 6 FIG. 1 is a flow chart of a method for accessing a flight device according to an exemplary embodiment. Figure 6 ;

[0056] Figure 7 FIG. 1 is a flow chart of a method for accessing a flight device according to an exemplary embodiment. Figure 7 ;

[0057] Figure 8 This is a schematic diagram of a structure for a flight device to access a predetermined network according to an exemplary embodiment;

[0058] Fig. 9 FIG. 1 is a flow chart of a method for accessing a flight device according to an exemplary embodiment. Figure 8 ;

[0059] Fig.10 FIG. 1 is a schematic diagram of a structure of an access device for a flying device according to an exemplary embodiment. Figure 1 ;

[0060] Fig.11 FIG. 1 is a schematic diagram of a structure of an access device for a flying device according to an exemplary embodiment. Figure 2 ;

[0061] Fig.12 FIG. 1 is a schematic diagram of a structure of an access device for a flying device according to an exemplary embodiment. Figure 3 . DETAILED DESCRIPTION

[0062] In order to make the purpose, technical solutions and advantages of the present invention clearer, the present invention will be further described in detail below in conjunction with the accompanying drawings. The described embodiments should not be regarded as limiting the present invention. All other embodiments obtained by ordinary technicians in the field without making creative work are within the scope of protection of the present invention.

[0063] In the following description, reference is made to “some embodiments”, which describe a subset of all possible embodiments, but it will be understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.

[0064] In the following description, the terms "first\second\third" involved are merely used to distinguish similar objects and do not represent a specific ordering of the objects. It can be understood that "first\second\third" can be interchanged with a specific order or sequence where permitted, so that the embodiments of the present invention described herein can be implemented in an order other than that illustrated or described herein.

[0065] In the following description, “greater than” and “less than” are involved. It should be noted that in the present disclosure, “greater than” can be used to indicate “greater than” or “equal to”; “less than” can be used to indicate “less than” or “equal to”.

[0066] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art to which the present invention belongs. The terms used herein are only for the purpose of describing the embodiments of the present invention and are not intended to limit the present invention.

[0067] In order to better understand the technical solution of the present disclosure, the application scenarios of the flight equipment access method in the related art are described below through some exemplary embodiments:

[0068] In some embodiments, the related technologies generally rely on the functional superposition of network security devices and the development of network security situational awareness technology supported by artificial intelligence (AI) big data to ensure the network security of the predetermined network. The related technologies basically focus on the detection, blocking and subsequent remediation of the network edge side, and adopt a mechanism of connecting first and then authenticating. On the basis of the Transmission Control Protocol (TCP) / Internet Protocol (IP) protocol, the virtual private network (VPN) mode is combined to achieve secure access to the terminal. However, the related technologies lack application security mechanisms, let alone strong security and strong identity authentication mechanisms. At this time, simple password verification can be easily cracked or bypassed, and it is easy to directly attack the predetermined network and be controlled, becoming a new direction for network attacks.

[0069] With the access of the fifth generation mobile communication 5G network, that is, when the scheduled network is a 5G network, the network boundary is blurred. At this time, the boundary protection system based on horizontal isolation and vertical encryption cannot effectively guarantee the safe access of such terminals. Therefore, the widespread application of 5G networked flight equipment has increased flexibility while also expanding the attack exposure surface, facing problems such as distributed denial of service (DDOS) attacks, side channel attacks and open application programming interface (API) threats. Network slicing technology also brings new network security issues such as resource sharing, cross-domain security and authentication authorization.

[0070] In some embodiments, there are some solutions based on zero-trust mechanism in the field of Internet of Things applications to ensure the security of the predetermined network. However, the related technologies all use the management and control platform and the zero-trust gateway to uniformly authenticate, record and monitor all terminals within the range, which are based on security authentication and control between the terminal and the management platform.

[0071] In some embodiments, with the rapid update of flight equipment, various models and uses of flight equipment emerge in an endless stream, but the security issues brought by flight equipment are also increasingly concerned. Because a large number of flight equipment use open source systems and software, there are shortcomings in security protection, which makes the security capabilities of flight equipment themselves uneven. A large number of flight equipment face identity forgery, data leakage, signaling replay, DDoS attacks and other security risks. Lawless elements scan the predetermined network to find vulnerabilities in flight equipment, and then attack it, maliciously control, steal and tamper with data, etc. Attackers will also implant malware through the vulnerabilities of flight equipment, and more and more third-party devices and systems enter the business system, and are forced to expose more and more business service ports to the predetermined network, providing hackers with a unified attack entrance. Once the terminal is breached, a "chain" reaction will be formed, causing the user's personal privacy data to be leaked. Especially in some scenarios involving confidentiality, such as smart cities, aerial map production and other fields, the safety of flight equipment is particularly important. In addition, because there are fatal weaknesses such as short battery life in current flight equipment, there are a large number of parking devices in actual scene applications, which provide convenience for charging, parking and data transmission of flight equipment. After the parking device is connected to the predetermined network through the communication module, it provides convenience for the large-scale promotion of the parking device, especially in mountainous areas and highways.

[0072] The scheduled network can be a 5G network. At this time, in the application scenario of 5G networked flight equipment, there are many different data interaction modes, such as the terminal corresponding to the parking device actively reporting data to the service platform used to provide services for the flight equipment, the service platform initiating data requests to the terminal, and the direct transmission of data between the terminal and the flight equipment. After accessing the 5G mobile public network, the terminal will lose physical isolation and wired private network protection. At this time, the network listening port opened by the terminal will face the threat of east-west traffic within the slice. In the 5G slicing environment, it is difficult for the network where the flight equipment is located to use the fine-grained isolation of self-built private networks on a large scale to eliminate east-west security risks. Operators cannot effectively provide east-west isolation because they do not have business access relationships, making the network security boundary very vague.

[0073] Based on this, Figure 1 As shown, an embodiment of the present disclosure provides a method for accessing an aircraft device, the method being applied to a terminal, the method comprising:

[0074] Step S110, in response to receiving the first request information sent by the aircraft device, sending a second request information to the gateway; wherein the first request information is used to request to establish a communication connection between the terminal and the aircraft device; the terminal is used for the aircraft device to access a predetermined network through the terminal, and the predetermined network is used to provide services for at least two aircraft devices; the second request information is used to request the gateway to perform security verification on the aircraft device to determine whether the aircraft device has the authority to establish a communication connection with the terminal;

[0075] Step S120, receiving a first response message sent by the gateway in response to the second request message; wherein the first response message indicates that the flight device has the authority or does not have the authority;

[0076] Step S130: Based on the first response information, when it is determined that a communication connection is to be established between the terminal and the aircraft device, the aircraft device is connected to the predetermined network.

[0077] It should be noted that any of the methods described in the embodiments of the present disclosure can be used to determine whether to securely connect an aircraft device to a predetermined network. For example, before the aircraft device connects to the predetermined network, the embodiments of the present disclosure can perform security verification on the aircraft device to determine whether the aircraft device has the authority to securely establish a communication connection with a terminal, so that the aircraft device can be securely connected to the predetermined network only when the aircraft device can securely establish a communication connection with the terminal.

[0078] Here, the type of the predetermined network may not be limited. For example, the predetermined network may be a fifth-generation mobile communication 5G network, or the predetermined network may be a fourth-generation mobile communication 5G network. The predetermined network provides services for at least two flight devices, which may mean that, in the predetermined network, services are provided to at least two flight devices through a first service platform that has been established. The service may include but is not limited to at least one of the following: route planning service, data collection service, and status monitoring service. The route planning service includes a service for pre-configuring or real-time configuration of flight parameters of the flight device, and the flight parameters include at least one of the following: take-off time, route, and take-off altitude. The data collection service includes a service for collecting and / or processing flight data of the flight device. The flight data includes at least one of the following: flight altitude, speed, wind speed outside the flight device, and temperature outside the flight device. The status monitoring service includes a service for monitoring the status of the flight device.

[0079] In one embodiment, in a predetermined network, services can be provided for at least two flight devices through a first service platform, and the at least two flight devices may include flight devices produced by at least two manufacturers. Here, compared with the method in the related art that a dedicated service platform needs to be set up to provide services for flight devices for each manufacturer or for each type of flight device, in the embodiment of the present disclosure, when the flight device securely accesses the predetermined network, security services can be provided for flight devices produced by different manufacturers at the same time through a first service platform. In this way, different types of flight devices can be compatible, and security services can be uniformly provided to all flight devices, reducing the cost of building a service platform and improving the efficiency of providing services for flight devices.

[0080] In one embodiment, the terminal is used to allow the aircraft device to access a predetermined network through the terminal when a communication connection is established between the terminal and the aircraft device. Here, the initial connection relationship between the terminal and the predetermined network may not be limited when the aircraft device has not yet accessed the predetermined network. For example, when the aircraft device has not yet accessed the predetermined network, the terminal may have accessed the predetermined network, or the terminal may not have accessed the predetermined network. In the embodiment of the present disclosure, it is only necessary to ensure that the terminal has accessed the predetermined network when the communication connection between the aircraft device and the terminal is to be established, and it is only necessary to ensure that the terminal can be used to allow the aircraft device to access the predetermined network through the terminal when a communication connection is established between the terminal and the aircraft device.

[0081] In one embodiment, the terminal may manage a parking device, in which the aircraft device is to be parked. The parking device is used to provide services for the aircraft device. The terminal may manage the switch state of the parking device, and the switch state includes an open state and a closed state. In the open state, the parking device is used to provide services for the aircraft device. In the closed state, the parking device does not provide services for the aircraft device. When a communication connection is established between the terminal and the aircraft device, the terminal may issue an opening instruction to the parking device to put it in the open state. The service may include at least one of the following: parking service, charging service and maintenance service. The parking service includes a service of providing a parking area for the aircraft device, the charging service includes a service of charging the aircraft device, and the maintenance service includes a service of replacing parts and / or repairing the aircraft device.

[0082] Exemplarily, the flying device may be any type of electronic device with flight capability. For example, the flying device may be a drone. The parking device may be a drone hangar, and the terminal may be a communication terminal for managing the drone hangar. The terminal may manage the switch state of the drone hangar. The switch state includes an on state and a off state. In the on state, the drone hangar is used to provide services for the drone, and in the off state, the drone hangar does not provide services for the drone.

[0083] Here, in the process of leapfrogging between the parking devices corresponding to different terminals, different types of drones from different manufacturers can quickly and safely access the predetermined network through the terminal, so that the drone can safely authenticate and access after leapfrogging between different parking devices, effectively ensuring the trusted access of various types of drone terminals from different manufacturers. Strengthening the security access control of the drone system has greatly improved the network security and data security of the drone system, reduced the risk of drone hijacking, and improved the safety of drone flight.

[0084] In one embodiment, the gateway may perform at least one of the following security verification operations on the aircraft device: a first operation for verifying the identity of the aircraft device, and / or a second operation for verifying whether the aircraft device has the system authority to access the predetermined network. Here, when the gateway performs security verification on the aircraft device and the verification result is passed, it is determined that the aircraft device has the authority to establish a communication connection with the terminal, or when the gateway performs security verification on the aircraft device and the verification result is failed, it is determined that the aircraft device does not have the authority to establish a communication connection with the terminal.

[0085] In one embodiment, the first operation can also be used to verify the identity of the terminal, and the second operation can also be used to verify whether the terminal has the system authority to access the predetermined network. That is, while the gateway performs security verification on the aircraft device, the gateway can also perform security verification on the terminal. Here, the second request information can request the gateway to perform security verification on the aircraft device and the terminal to determine whether the aircraft device has the authority to communicate with the terminal.

[0086] Here, it can also be determined that the flight device has the authority to establish a communication connection with the terminal when the gateway's security verification results for the flight device and the terminal are both passed, or it can be determined that the flight device does not have the authority to establish a communication connection with the terminal when the gateway's security verification results for the flight device and / or the terminal are failed.

[0087] In one embodiment, the second request information may be used to request the gateway to perform the first operation and / or the second operation to determine whether the aircraft device has the authority to establish a communication connection with the terminal.

[0088] In the embodiment of the present disclosure, since a second request message is sent to the gateway to request the gateway to perform security verification on the flight device to determine whether the flight device has the authority to establish a communication connection with the terminal, the gateway can be used to verify the security of the flight device in advance to ensure that only the flight device with high security has the authority to establish a communication connection with the terminal. At this time, when it is necessary to determine whether to establish a communication connection between the flight device and the terminal so that the flight device connected to the terminal can access the predetermined network through the terminal, that is, when it is necessary to determine whether the flight device can access the predetermined network, only the communication connection between the flight device with high security and the terminal can be established so that the flight device with high security can access the predetermined network. Compared with the method in the related art that the predetermined network cannot safely provide services to the flight devices in the predetermined network, in the embodiment of the present disclosure, the flight devices with high security that can access the predetermined network can be determined before the flight device accesses the network, and only the flight devices with high security can be connected to the predetermined network. In this way, the high security of flight equipment connected to the scheduled network can be ensured in advance, and the situation in which the scheduled network has been attacked by network and caused losses due to security verification of the flight equipment only after the unsafe flight equipment is connected to the scheduled network can be reduced. The security of the scheduled network can be ensured, and the service effect of the secure scheduled network for each flight device can be ensured.

[0089] In one embodiment, the second request information indicates a first identifier, which is determined jointly based on the device identifier of the aircraft device and the terminal identifier of the terminal; the second request information is used to request the gateway to perform security verification on the first identifier to determine whether the aircraft device has the authority to establish a communication connection with the terminal.

[0090] In one embodiment, the first identifier is used to characterize the identity of the aircraft device and the terminal. The second request information can be used to request the gateway to perform identity authentication and authorization for the first identifier to complete the security verification of the aircraft device and the terminal. The gateway can determine whether the aircraft device has the authority to establish a communication connection with the terminal based on the security verification of the aircraft device and the terminal.

[0091] In one embodiment, the device identification and the terminal identification may be fused to obtain the first identification. The fusion operation includes at least one of the following: multiplication, division, addition and subtraction of the device identification and the terminal identification.

[0092] It should be noted that there is a preset mapping relationship between the first identifier, the terminal and the flight device. For each combination of the terminal and each flight device, there is a unique first identifier. The gateway can perform security verification on the terminal and the flight device through the unique first identifier.

[0093] Here, since the first identification is jointly determined based on the device identification of the aircraft device and the terminal identification of the terminal, the second request information is used to request the gateway to perform security verification on the first identification to determine whether the aircraft device has the authority to establish a communication connection with the terminal. Therefore, in the process of the gateway performing security verification on the aircraft device and the terminal, the gateway can quickly complete the security authentication of the aircraft device and the terminal by performing security authentication on a first identification. Compared with the method in the related art that requires security authentication of the aircraft device based on the device identification and security authentication of the terminal based on the terminal identification, in the embodiment of the present disclosure, the gateway can quickly complete the security authentication of the aircraft device and the terminal based on the first identification. In this way, the speed of security authentication of the aircraft device and the terminal can be improved.

[0094] In one embodiment, whether to establish a communication connection between the terminal and the aircraft device may be determined based on the first response information. If it is determined that the communication connection between the terminal and the aircraft device is established, the aircraft device may be connected to the predetermined network. Alternatively, if it is determined that the communication connection between the terminal and the aircraft device is not established, the aircraft device may not be connected to the predetermined network.

[0095] In one embodiment, in response to the first response information indicating that the aircraft device has the authority, it can be determined to establish a communication connection between the terminal and the aircraft device; or, in response to the first response information indicating that the aircraft device does not have the authority, it can be determined not to establish a communication connection between the terminal and the aircraft device.

[0096] Here, before the aircraft device accesses the predetermined network through the terminal, a security verification will be performed on the aircraft device to determine whether the aircraft device has the authority to establish a communication connection with the terminal. Only when the aircraft device has passed the security verification and has the authority to establish a communication connection with the terminal, the connection between the aircraft device and the terminal will be established, so that the aircraft device can safely access the predetermined network through the terminal. In this way, the security of the aircraft device accessing the predetermined network is ensured, the situation where the predetermined network and the devices in the predetermined network are attacked due to the access of dangerous devices to the predetermined network is reduced, and the predetermined network can provide security services for the devices in the network.

[0097] In one embodiment, the terminal may always be in a state of accessing a predetermined network. When the flight device needs to access the predetermined network through the terminal, in response to the first response information indicating that the flight device has the authority to establish a communication connection with the terminal, only a communication connection may be established between the flight device and the terminal so that the flight device can access the predetermined network through the terminal.

[0098] Exemplarily, in response to receiving a first request message sent by an aircraft device, a second request message is sent to a gateway; wherein the first request message is used to request the establishment of a communication connection between the terminal and the aircraft device; the terminal is used for the aircraft device to access the predetermined network through the terminal, and the predetermined network is used to provide services for at least two aircraft devices; in response to the first response message indicating that the aircraft device has the authority to establish a communication connection with the terminal, it is determined to establish a communication connection between the terminal and the aircraft device. In the case of determining to establish a communication connection between the terminal and the aircraft device, the aircraft device is connected to the predetermined network. Alternatively, in response to the first response message indicating that the aircraft device does not have the authority to establish a communication connection with the terminal, the communication connection between the terminal and the aircraft device is not established. In the case of determining not to establish a communication connection between the terminal and the aircraft device, the aircraft device is not connected to the predetermined network. In this way, while ensuring that the terminal can safely access the predetermined network, the waste of resources caused by the terminal frequently accessing the predetermined network can be reduced.

[0099] In one embodiment, each time the aircraft device needs to access a predetermined network through a terminal, in response to the first response information indicating that the aircraft device has the authority to establish a communication connection with the terminal, the terminal needs to re-access the predetermined network and establish a communication connection between the terminal and the aircraft device, so that the terminal can be used for the aircraft device to access the predetermined network through the terminal. At this time, the terminal may be in a state of accessing the predetermined network, or the terminal may be in a state of not accessing the predetermined network. In the case where the terminal is in a state of accessing the predetermined network, the communication connection between the terminal and the predetermined network may be disconnected and the terminal may be re-accessed to the predetermined network.

[0100] Exemplarily, in response to receiving a first request message sent by an aircraft device, a second request message is sent to a gateway; wherein the first request message is used to request the establishment of a communication connection between the terminal and the aircraft device; the second request message is used to request the gateway to perform security verification on the aircraft device and the terminal to determine whether the aircraft device has the authority to establish a communication connection with the terminal, and to determine whether the terminal has the authority to access a predetermined network; in response to the first response message indicating that the aircraft device has the authority to establish a communication connection with the terminal and the terminal has the authority to access a predetermined network, a communication connection is established between the gateway and the terminal; wherein the gateway is used for the terminal to access the predetermined network through the gateway; in response to the successful establishment of the communication connection between the gateway and the terminal, it is determined to establish a communication connection between the terminal and the aircraft device and to access the aircraft device to the predetermined network. Alternatively, in response to the first response message indicating that the aircraft device does not have the authority to establish a communication connection with the terminal and / or the terminal does not have the authority to access the predetermined network, the communication connection between the gateway and the terminal is not established, and the communication connection between the terminal and the aircraft device is not established. At this time, the aircraft device is not connected to the predetermined network. In this way, each time the aircraft device needs to access a predetermined network through a terminal, it can be re-determined whether there is a security risk between the aircraft device and the terminal, so that both the terminal and the aircraft device can safely access the predetermined network.

[0101] Here, the first response information may be request information for the gateway to establish a communication connection with the terminal based on a predetermined protocol; it can be understood that when the first response information is request information for the gateway to establish a communication connection with the terminal based on a predetermined protocol, the first response information may indicate that the flight equipment has the authority to establish a communication connection with the terminal and / or that the terminal has the authority to access a predetermined network.

[0102] In one embodiment, Figure 2As shown, in the case where the terminal is not connected to the predetermined network, the second request information is used to request the gateway to perform security verification on the aircraft device and the terminal to determine whether the aircraft device has the authority to establish a communication connection with the terminal and whether the terminal has the authority to access the predetermined network, and the response to the first response information indicating that the aircraft device has the authority to determine to establish a communication connection between the terminal and the aircraft device includes:

[0103] Step S210, in response to the first response information indicating that the aircraft device has the authority to establish a communication connection with the terminal and the terminal has the authority to access the predetermined network, establishing a communication connection between the gateway and the terminal; wherein the gateway is used for the terminal to access the predetermined network through the gateway;

[0104] Step S220: In response to the successful establishment of the communication connection between the gateway and the terminal, determine to establish a communication connection between the terminal and the flight device.

[0105] Here, since the terminal is allowed to access the predetermined network and establish a communication connection between the terminal and the aircraft device only when the aircraft device has the authority to establish a communication connection with the terminal and the terminal has the authority to access the predetermined network, so that the aircraft device can access the predetermined network through the terminal, it is possible to fully consider the security risks generated by the aircraft device and the terminal when accessing the predetermined network, so that the aircraft device can access the network through the terminal under safe conditions. In this way, it can ensure that the aircraft device can safely access the predetermined network through the terminal, reduce the possibility of the predetermined network being attacked, and ensure network security.

[0106] In one embodiment, Figure 3 As shown, the first response information sent by the receiving gateway in response to the second request information includes:

[0107] Step S310, receiving a second response message sent by the gateway in response to the second request message; wherein the second response message indicates a verification result of the safety verification of the flight device;

[0108] Step S320: In response to the verification result being a verification pass result, a third request message is sent to the gateway; wherein the third request message is used to request the gateway to determine whether the aircraft device is in a device list corresponding to the terminal; and the aircraft device in the device list has the authority to establish a communication connection with the terminal;

[0109] Step S330: receiving the first response information sent by the gateway in response to the third request information.

[0110] In one embodiment, a second response message sent by the gateway to the second request message is received; wherein the second response message indicates a verification result of a safety verification of the flight device; in response to the verification result being a verification passed result, a third request message is not sent to the gateway.

[0111] In one embodiment, in response to the verification result being a verification pass result, sending a third request message to the gateway includes: in response to the second response message including an authorization credential sent by the second service platform, sending the third request message to the gateway. The authorization credential is used to indicate that the verification result of the safety verification of the flight device is a verification pass result.

[0112] It is understandable that here, the gateway can use the second service platform to perform security verification on the flight device and obtain the verification result of the security verification on the flight device. For example, after the gateway signs the second request information sent by the terminal, the gateway can forward the second request information with the command signature to the second service platform to request the second service platform to perform security verification on the flight device and obtain the verification result of the security verification on the flight device.

[0113] In one embodiment, the second service platform may include an identity management system, a terminal authority management system, and a security situation awareness system. Among them, the identity management system is used to manage the identity information of the terminal and the flight equipment, and the identity information may include the terminal identification of the terminal, the equipment identification of the flight equipment, and / or the first identification described in any of the embodiments of the present disclosure. The terminal authority management system is used to manage the permissions possessed by the terminal and / or the flight equipment. The security situation awareness system is used to monitor whether the terminal and / or the flight equipment is in a safe state. The second service platform may be a cloud service platform.

[0114] In one embodiment, different terminals may correspond to the same device list, or different terminals may correspond to different device lists. Whether the aircraft device is in the device list corresponding to the terminal may be determined based on at least one of the device identification, device type, manufacturer, and communication type of the aircraft device. The device list may include pre-agreed aircraft devices that can establish a communication connection with the terminal.

[0115] In one embodiment, when the flight device is not located in the device list corresponding to the terminal, the first response information may indicate that the flight device does not have the authority to establish a communication connection with the terminal; alternatively, when the flight device is located in the device list corresponding to the terminal, the first response information may indicate that the flight device has the authority to establish a communication connection with the terminal.

[0116] Here, when the result of the security verification of the aircraft device is that the verification is passed, the communication connection between the aircraft device and the terminal will not be directly established, and it will continue to determine whether the aircraft device is in the device list corresponding to the terminal. Only when the aircraft device is in the device list corresponding to the terminal, the first response information will indicate that the aircraft device has the authority to establish a communication connection with the terminal, and the communication connection between the aircraft device and the terminal will be established. In this way, the connection security of the communication connection established between the aircraft device and the terminal can be ensured.

[0117] In one embodiment, Figure 4 As shown, the method is applied to a gateway, and the method includes:

[0118] Step S410, receiving second request information sent by the terminal;

[0119] The second request information is information sent by the terminal when receiving the first request information sent by the flight device; the terminal is used for the flight device to access a predetermined network through the terminal, and the predetermined network is used to provide services for at least two flight devices; the first request information is used to request to establish a communication connection between the terminal and the flight device; the second request information is used to perform security verification on the flight device to determine whether the flight device has the authority to establish a communication connection with the terminal;

[0120] Step S420, in response to receiving the second request information, sending a first response information to the terminal; wherein the first response information indicates that the flight device has the authority, or the first response information indicates that the flight device does not have the authority; the first response information is used for: the terminal to connect the flight device to the predetermined network when determining to establish the communication connection based on the first response information.

[0121] It should be noted that the gateway here can be provided with a zero-trust security suite, which is used to forward information based on a zero-trust mechanism and to perform security verification on terminals and / or flight equipment.

[0122] In one embodiment, in response to receiving the second request information, the gateway may directly perform security verification on the aircraft device to determine whether the aircraft device has the authority to establish a communication connection with the terminal, and obtain a determination result. Alternatively, in response to receiving the second request information, the gateway may indirectly perform security verification on the aircraft device using the second service platform to determine whether the aircraft device has the authority to establish a communication connection with the terminal, and obtain a determination result.

[0123] Here, the second service platform may include an identity management system, a terminal authority management system, and a security situation awareness system. Among them, the identity management system is used to manage the identity information of the terminal and the flight equipment, and the identity information may include the terminal identification of the terminal, the equipment identification of the flight equipment, and / or the first identification described in any of the embodiments of the present disclosure. The terminal authority management system is used to manage the permissions possessed by the terminal and / or the flight equipment. The security situation awareness system is used to monitor whether the terminal and / or the flight equipment is in a safe state. The second service platform may be a cloud service platform.

[0124] In one embodiment, in response to the gateway being able to use the second service platform to indirectly perform security verification on the flight device, the method further includes: in response to receiving the second request information, the gateway performs an instruction signature operation on the second request information to obtain a fourth request information; wherein the fourth request information is used to request the second service platform to perform security verification on the flight device; receiving a third response information returned by the second service platform in response to the fourth request information; wherein the third response information is used to indicate that the flight device has the authority to establish a communication connection with the terminal or does not have the authority to establish a communication connection with the terminal. At this time, the first response information can be sent to the terminal based on the third response information.

[0125] In one embodiment, when the verification result of the second service platform's security verification of the flight device is a passed verification result, the third response information may include an authorization credential sent by the second service platform; the authorization credential is used to indicate that the verification result of the security verification of the flight device is a passed verification result.

[0126] In one embodiment, the gateway and / or the second service platform may perform at least one of the following security verification operations on the aircraft device: a first operation for verifying the identity of the aircraft device, and / or a second operation for verifying whether the aircraft device has the system authority to access the predetermined network. Here, when the gateway performs security verification on the aircraft device and the verification result is a passed verification, it may be determined that the aircraft device has the authority to establish a communication connection with the terminal, or when the gateway performs security verification on the aircraft device and the verification result is a failed verification, it may be determined that the aircraft device does not have the authority to establish a communication connection with the terminal.

[0127] In one embodiment, the first operation can also be used to verify the identity of the terminal, and the second operation can also be used to verify whether the terminal has the system authority to access the predetermined network. That is, while the gateway performs security verification on the aircraft device, the gateway can also perform security verification on the terminal. Here, the second request information can request the gateway to perform security verification on the aircraft device and the terminal to determine whether the aircraft device has the authority to communicate with the terminal.

[0128] Here, it can also be determined that the flight device has the authority to establish a communication connection with the terminal when the gateway's security verification results for the flight device and the terminal are both passed, or it can be determined that the flight device does not have the authority to establish a communication connection with the terminal when the gateway's security verification results for the flight device and / or the terminal are failed.

[0129] In one embodiment, the second request information may be used to request the gateway and / or the second service platform to perform the first operation and / or the second operation to determine whether the flying device has the authority to establish a communication connection with the terminal.

[0130] In the embodiment of the present disclosure, since the gateway receives the second request information for requesting security verification of the aircraft device to determine whether the aircraft device has the authority to establish a communication connection with the terminal, and the terminal is used for the aircraft device to access the predetermined network that can serve at least two aircraft devices through the terminal, when the terminal determines whether to establish a communication connection between the aircraft device and the terminal based on the first response information sent by the gateway to the second request information, it can establish a secure communication connection between the aircraft device and the terminal when the aircraft device passes the security verification and has the authority, that is, when there is no security risk in the aircraft device, and after the aircraft device and the terminal establish a secure communication connection, the aircraft device can securely access the predetermined network through the terminal. Compared with the method in the related art that the predetermined network cannot securely provide services for the aircraft devices in the predetermined network, in the embodiment of the present disclosure, the aircraft device can securely access the predetermined network through the terminal, thereby reducing the situation that there is a security risk in the predetermined network due to the aircraft device with security risks accessing the predetermined network, and reducing the situation that the predetermined network cannot provide security services. In this way, the security of the predetermined network can be ensured, and the effect of the service provided by the predetermined network can be ensured.

[0131] In one embodiment, Figure 5 As shown, in response to receiving the second request information, sending first response information to the terminal, the method further includes:

[0132] Step S510, in response to receiving the second request information, performing security verification on the aircraft device to determine whether the aircraft device has the authority, and obtaining a determination result;

[0133] Step S520: Send the first response information to the terminal based on the determination result.

[0134] Here, compared with the method in the related art that needs to use the second service platform to indirectly perform security verification on the aircraft device to determine whether the aircraft device has the authority to establish a communication connection with the terminal, in the embodiment of the present disclosure, the gateway can directly perform security verification on the aircraft device to determine whether the aircraft device has the authority to establish a communication connection with the terminal. In this way, the speed of obtaining the determination result of whether the aircraft device has the authority can be accelerated, so that the first response information can be quickly sent to the terminal based on the quickly obtained determination result, thereby improving the response speed.

[0135] In one embodiment, the second request information indicates a first identifier, and the first identifier is jointly determined according to a device identifier of the aircraft device and a terminal identifier of the terminal; and the performing security verification on the aircraft device to determine whether the aircraft device has the authority includes:

[0136] The first identification is subjected to security verification to determine whether the aircraft device has the authority to establish a communication connection with the terminal.

[0137] In one embodiment, the first identifier is used to characterize the identity of the aircraft device and the terminal. The second request information can be used to request the gateway to perform identity authentication and authorization for the first identifier to complete the security verification of the aircraft device and the terminal. The gateway can determine whether the aircraft device has the authority to establish a communication connection with the terminal based on the security verification of the aircraft device and the terminal.

[0138] It should be noted that there is a preset mapping relationship between the first identifier, the terminal and the flight device. For each combination of the terminal and each flight device, there is a unique first identifier. The gateway can perform security verification on the terminal and the flight device through the unique first identifier.

[0139] Here, since the first identification is jointly determined based on the device identification of the aircraft device and the terminal identification of the terminal, the second request information is used to request the gateway to perform security verification on the first identification to determine whether the aircraft device has the authority to establish a communication connection with the terminal. Therefore, in the process of the gateway performing security verification on the aircraft device and the terminal, the gateway can quickly complete the security authentication of the aircraft device and the terminal by performing security authentication on a first identification. Compared with the method in the related art that requires security authentication of the aircraft device based on the device identification and security authentication of the terminal based on the terminal identification, in the embodiment of the present disclosure, the gateway can quickly complete the security authentication of the aircraft device and the terminal based on the first identification. In this way, the speed of security authentication of the aircraft device and the terminal can be improved.

[0140] In one embodiment, Figure 6As shown, in response to receiving the second request information, performing security verification on the aircraft device to determine whether the aircraft device has the authority, and obtaining a determination result, including:

[0141] Step S610, in response to receiving the second request information, sending a second response information to the terminal; wherein the second response information indicates a verification result of the safety verification of the flight equipment;

[0142] Step S620, in response to the verification result being a verification passed result, receiving a third request message sent by the terminal in response to the second response message; wherein the third request message is used to determine whether the aircraft device is in a device list corresponding to the terminal; and the aircraft device in the device list has the authority to establish a communication connection with the terminal;

[0143] Step S630, determining whether the flying device is in the device list, and obtaining a determination result.

[0144] In one embodiment, in response to the gateway being able to indirectly perform security verification on the flight device using the second service platform and when the verification result is a result of passing the verification, the second response information can be determined based on the third response information described in any of the embodiments of the present disclosure; the second response information and the third response information can both include the authorization certificate sent by the second service platform; the authorization certificate is used to indicate that the verification result of the security verification on the flight device is a result of passing the verification. It can be understood that here, the gateway can play the role of forwarding the authorization certificate sent by the second service platform to the terminal.

[0145] In one embodiment, different terminals may correspond to the same device list, or different terminals may correspond to different device lists. The gateway and / or the second service platform may determine whether the flight device is in the device list corresponding to the terminal based on at least one of the device identification, device type, manufacturer, and communication type of the flight device. The device list may include pre-agreed flight devices that can establish a communication connection with the terminal.

[0146] In one embodiment, when the flight device is not located in the device list corresponding to the terminal, the first response information may indicate that the flight device does not have the authority to establish a communication connection with the terminal; alternatively, when the flight device is located in the device list corresponding to the terminal, the first response information may indicate that the flight device has the authority to establish a communication connection with the terminal.

[0147] Here, when the result of the security verification of the aircraft device is that the verification is passed, the communication connection between the aircraft device and the terminal will not be directly established, and it will continue to determine whether the aircraft device is in the device list corresponding to the terminal. Only when the aircraft device is in the device list corresponding to the terminal, the first response information will indicate that the aircraft device has the authority to establish a communication connection with the terminal, and the communication connection between the aircraft device and the terminal will be established. In this way, the connection security of the communication connection established between the aircraft device and the terminal can be ensured.

[0148] In one embodiment, in response to receiving the second request information, a fourth request information may be sent to the second service platform, the fourth request information being used to request the second service platform to determine whether the flight device is in the device list corresponding to the terminal; a fourth response information sent by the second service platform in response to the fourth request information is received, and a determination result is obtained based on the fourth response information. Based on the determination result, the first response information is sent to the terminal.

[0149] In one embodiment, in response to the determination result that the flight device is in the device list corresponding to the terminal, a first response message is sent to the terminal, the first response message indicating that the flight device has the authority to establish a communication connection with the terminal. In the case where the terminal is not connected to the predetermined network or the terminal needs to be reconnected to the predetermined network, the first response message may also indicate that the terminal has the authority to establish a communication connection with the gateway, and the gateway is used for the terminal to access the predetermined network through the gateway.

[0150] In one embodiment, any of the communication connections described in the embodiments of the present disclosure may be a communication connection established based on a predetermined protocol. For example, the predetermined protocol may be a Transport Layer Security (TLS) protocol.

[0151] like Figure 7 As shown, an embodiment of the present disclosure provides a method for accessing an aircraft device, the method being applied to an aircraft device, the method comprising:

[0152] Step S710, in response to the distance between the flying device and the terminal being within a first distance, sending first request information to the terminal;

[0153] The first request information is used to request to establish a communication connection between the terminal and the aircraft device and trigger the terminal to send a second request information to the gateway; the second request information is used to request the gateway to perform security verification on the aircraft device to determine whether the aircraft device has the authority to establish a communication connection with the terminal; the terminal is used for the aircraft device to access a predetermined network through the terminal, and the predetermined network is used to provide services for at least two aircraft devices;

[0154] Step S720: In response to the flying device having the permission to establish a communication connection with the terminal, establish a communication connection between the flying device and the terminal, and access the predetermined network through the terminal.

[0155] In one embodiment, the first distance can be determined according to the flying speed of the flying device. The first distance can be positively correlated with the flying speed of the flying device.

[0156] In the embodiments of the present disclosure, since the terminal sends second request information for requesting security verification of the flying device to determine whether the flying device has the permission to establish a communication connection with the terminal to the gateway, and in response to the flying device having the permission to establish a communication connection with the terminal, a communication connection between the flying device and the terminal is established and the predetermined network is accessed through the terminal. Therefore, when the terminal determines whether to establish a communication connection between the flying device and the terminal based on the first response information sent by the gateway for the second request information, a secure communication connection between the flying device and the terminal can be established when the flying device passes the security verification and has the permission, that is, when the flying device has no security risk, and after the flying device and the terminal establish a secure communication connection, the flying device can safely access the predetermined network through the terminal. Compared with the related art in which the predetermined network cannot provide services for the flying devices in the predetermined network safely, in the embodiments of the present disclosure, the flying device can safely access the predetermined network through the terminal, thereby reducing the situation that the predetermined network has security risks due to the access of flying devices with security risks, and reducing the situation that the predetermined network cannot provide secure services. In this way, the security of the predetermined network can be ensured, and the effect of the predetermined network providing services is good.

[0157] In one embodiment, after establishing a communication connection between the flying device and the terminal, an identity authentication operation can be performed on the user information corresponding to the flying device; in response to the result of the identity authentication operation being authentication passed, the flying device is allowed to operate in the predetermined network. Here, the user information includes a username and a password, and the identity authentication operation can be completed through two-factor authentication of the username and the password.

[0158] In one embodiment, in response to the identity authentication operation, an access control operation and an authorization operation are performed on the aircraft device. The access control operation is used to limit or grant the aircraft device access rights to different areas according to the user status corresponding to the aircraft device, and the authorization operation is used to send an authorization credential to the aircraft device when the aircraft device is granted access rights. It is understandable that only after the access control operation and the authorization operation are performed on the aircraft device, the authorized aircraft device can access the predetermined resources in the predetermined network. In the predetermined network, the access control operation and the authorization operation can be performed according to the preset policy.

[0159] In one embodiment, in response to the completion of the access control operation and the authorization operation for the aircraft device, and the aircraft device is about to perform a data transmission operation in a predetermined network, a predetermined encryption technology and a predetermined protocol are used for data transmission. For example, the predetermined protocol may include a TLS protocol, or the predetermined protocol may be an Internet Protocol Security (IPSec). The predetermined network may also be a VPN. Here, the integrity, confidentiality and authenticity of the data during the transmission process can be ensured. Or, as Figure 8 As shown, the predetermined network may be Ethernet, or the predetermined network may be a wireless fidelity network (WiFi), or the predetermined network may be a fourth generation mobile communication 4G network, or the predetermined network may be a fifth generation mobile communication 5G network.

[0160] In one embodiment, in a predetermined network, a real-time monitoring operation can be performed on the predetermined network to obtain a monitoring result; in response to the monitoring result being a result of monitoring a security risk, a security protection operation is performed. Here, the predetermined network can be monitored and responded to in real time to timely discover security events and threats, and take corresponding measures to deal with them, so as to timely discover and resolve security risks.

[0161] In one embodiment, the flight device may be a drone device. In the application scenarios of highway and power grid inspection, there are a large number of hangars, and the leapfrog function of drones between different hangars is an indispensable function. In order to more safely and efficiently manage the identities of drones and hangars, the security situation awareness system of the second service platform can be used in the embodiment of the disclosure to perceive the behavior information of the terminal, flight device and gateway in real time, so as to dynamically manage the behavior strategies corresponding to the terminal, gateway and flight device.

[0162] In one embodiment, a zero-trust security agent suite is provided in the terminal. The zero-trust security suite provided in the terminal can collect the behavior information of the terminal in real time and report the behavior information to the second service platform. The second service platform can monitor the terminal in real time based on the pre-set security policy, and issue the behavior policy to the gateway based on the security behavior baseline of the business; the gateway can dynamically control the behavior of the terminal and the flight equipment based on the behavior policy, thereby performing real-time blocking, isolation or auditing operations on the behavior of the terminal. Here, the security behavior baseline can be used to detect at least one of the following for the terminal: whether the terminal is in the blacklist; whether the terminal is in the whitelist; whether threat intelligence is detected; whether a virus in the virus library is detected; and whether a DDOS attack behavior is detected. The blacklist is a list of terminals in an unsafe state, and the whitelist is a list of terminals in a safe state.

[0163] In one embodiment, Figure 8 As shown, an embodiment of the present disclosure provides a system architecture for an aircraft device to access a predetermined network, the system architecture comprising:

[0164] A perception layer, the perception layer comprising any terminal and flight equipment described in the embodiments of the present disclosure;

[0165] Among them, the terminal and the flight equipment are both equipped with a zero-trust security agent software development security package (SDK, Software Development Kit); the zero-trust security agent SDK is used to enable the terminal and the flight equipment to communicate securely based on the zero-trust mechanism;

[0166] A network layer, the network layer comprising the gateway described in any one of the embodiments of the present disclosure;

[0167] wherein, in response to receiving a first request message sent by the flight device, the terminal sends a second request message to the gateway; wherein the first request message is used to request the establishment of a communication connection between the terminal and the flight device; the terminal is used for the flight device to access the predetermined network through the terminal, and the predetermined network is used to provide services for at least two flight devices; the second request message is used to request the gateway to perform a security verification on the flight device to determine whether the flight device has the authority to establish a communication connection with the terminal; the terminal will receive a first response message sent by the gateway in response to the second request message; wherein the first response message indicates that the flight device has the authority or does not have the authority; the terminal will, based on the first response message, connect the flight device to the predetermined network if it is determined to establish a communication connection between the terminal and the flight device; application layer, the application layer includes the first service platform and the second service platform described in any one of the embodiments of the present disclosure;

[0168] Among them, the gateway can use the first service platform to perform security verification on the flight equipment to determine whether the flight equipment has the authority to establish a communication connection with the terminal. The predetermined network to provide services for the flight equipment can mean using the second service platform to provide services for the flight equipment under the predetermined network.

[0169] It should be noted that, here, the perception layer described in any of the embodiments of the present disclosure can also be understood as the terminal side of the system architecture, the network layer described in any of the embodiments of the present disclosure can also be understood as the network side of the system architecture, and the application layer described in any of the embodiments of the present disclosure can also be understood as the platform side of the system architecture. The terminal side can also include a flight device that has established a communication connection with the terminal, a mission payload corresponding to the flight device, and a parking device for parking the flight device.

[0170] Here, the first service platform and the second service platform can jointly constitute the cloud authentication center of the system architecture, and the cloud authentication center is used to perform security verification and / or provide services for at least two flight devices in the cloud; the gateway can provide a secure transmission pipeline between the first service platform, the second service platform, the terminal and the flight device. At this time, in the process of using the gateway, the terminal and the second service platform to perform security verification on the flight device so that the flight device can securely access the first service platform, a full-link secure access system of the cloud, the terminal and the transmission pipeline can be formed, thereby improving the security of the flight device accessing the predetermined network.

[0171] In one embodiment, the gateway can close all TCP interfaces, and only when the flight device passes the security verification, the gateway opens the TCP interface to the flight device, so that the flight device can access the predetermined network through the gateway. The gateway can be provided with a zero-trust security suite to close all TCP interfaces.

[0172] To better understand the technical solutions in the embodiments of the present disclosure, please refer to Fig. 9 , Fig. 9 An exemplary method for accessing a flight device is shown, the method comprising:

[0173] Step S9001, in response to the flying device being within a first distance of the terminal, sending first request information to the terminal;

[0174] The first request information is used to request to establish a communication connection between the terminal and the flight device;

[0175] Step S9002: In response to receiving the first request information, the terminal determines a first identifier based on the terminal identifier of the terminal and the device identifier of the flight device;

[0176] Step S9003: The terminal sends a second request message to the gateway based on the first identifier;

[0177] Among them, the second request information is used to request the gateway to perform a security verification on the first identifier to determine whether the flying device has the permission to establish a communication connection with the terminal;

[0178] Step S9004, the gateway performs an instruction signature operation on the second request information, obtains the fourth request information, and sends the fourth request information to the second service platform;

[0179] Among them, the fourth request information is used to request the second service platform to perform a security verification on the first identifier to determine whether the flying device has the permission to establish a communication connection with the terminal;

[0180] Step S9005, the first service platform performs a security verification on the first identifier;

[0181] Step S9006, in response to the verification result that the security verification of the flying device by the second service platform is a passed result, the second service platform sends a third response information to the gateway;

[0182] Among them, the third response information includes an authorization credential, and the authorization credential is used to represent that the verification result of the security verification of the flying device is a passed result;

[0183] Step S9007, the gateway sends a second response information to the terminal for the second request information;

[0184] Among them, the second response information includes the authorization credential;

[0185] Step S9008, in response to receiving the authorization credential, the terminal sends a third request information to the gateway;

[0186] Among them, the third request information is used to request the gateway to determine whether the flying device is in the device list corresponding to the terminal; the flying devices in the device list have the permission to establish a communication connection with the terminal;

[0187] Step S9009, in response to determining that the flying device is in the device list, the gateway sends a first response information to the terminal to establish a communication connection between the terminal and the gateway;

[0188] Among them, the gateway is used for the terminal to access a predetermined network through the gateway, and the first response information can be a request information for the gateway to request to establish a communication connection with the terminal based on the TLS protocol; it can be understood that when the first response information is a request information for the gateway to request to establish a communication connection with the terminal based on the TLS protocol, the first response information can indicate that the flying device has the permission to establish a communication connection with the terminal;

[0189] Step S9010, in response to the successful establishment of the communication connection between the terminal and the gateway, establish a communication connection between the terminal and the flight device.

[0190] like Fig.10 As shown, an embodiment of the present disclosure provides an access device for a flight device, the access device comprising:

[0191] The first sending module 101 is configured to send a second request message to the gateway in response to receiving a first request message sent by the aircraft device; wherein the first request message is used to request to establish a communication connection between the terminal and the aircraft device; the terminal is used for the aircraft device to access the predetermined network through the terminal, and the predetermined network is used to provide services for at least two aircraft devices; the second request message is used to request the gateway to perform security verification on the aircraft device to determine whether the aircraft device has the authority to establish a communication connection with the terminal;

[0192] A first receiving module 102 is configured to receive a first response message sent by the gateway in response to the second request message; wherein the first response message indicates that the flight device has the permission or does not have the permission;

[0193] The first connection module 103 is configured to connect the aircraft device to the predetermined network if it is determined that a communication connection between the terminal and the aircraft device is to be established based on the first response information.

[0194] like Fig.11 As shown, an embodiment of the present disclosure provides an access device for a flight device, the access device comprising:

[0195] The second receiving module 111 is used to receive second request information sent by the terminal; wherein the second request information is information sent by the terminal when receiving the first request information sent by the aircraft device; the terminal is used for the aircraft device to access a predetermined network through the terminal, and the predetermined network is used to provide services for at least two aircraft devices; the first request information is used to request to establish a communication connection between the terminal and the aircraft device; the second request information is used to perform security verification on the aircraft device to determine whether the aircraft device has the authority to establish a communication connection with the terminal;

[0196] The second sending module 112 is used to send a first response message to the terminal in response to receiving the second request information; wherein, the first response information indicates that the aircraft device has the authority, or the first response information indicates that the aircraft device does not have the authority; the first response information is used for: the terminal to connect the aircraft device to the predetermined network when determining to establish the communication connection based on the first response information.

[0197] like Fig.12 As shown, an embodiment of the present disclosure provides an access device for a flight device, the access device comprising:

[0198] The third sending module 121 sends a first request message to the terminal in response to the distance between the aircraft device and the terminal being within a first distance; wherein the first request message is used to request to establish a communication connection between the terminal and the aircraft device and trigger the terminal to send a second request message to the gateway; the second request message is used to request the gateway to perform security verification on the aircraft device to determine whether the aircraft device has the authority to establish a communication connection with the terminal; the terminal is used for the aircraft device to access a predetermined network through the terminal, and the predetermined network is used to provide services for at least two aircraft devices;

[0199] The second connection module 122 establishes a communication connection between the aircraft device and the terminal in response to the aircraft device having the authority to establish a communication connection with the terminal, and accesses the predetermined network through the terminal.

[0200] The present disclosure provides a processing device, the processing device comprising:

[0201] A memory for storing executable programs;

[0202] The processor is used to implement any method described in the embodiments of the present disclosure when executing the executable program stored in the memory.

[0203] It can be understood that the memory can be a volatile memory or a non-volatile memory, and can also include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a magnetic random access memory (FRAM), a flash memory, a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM); the magnetic surface memory can be a disk memory or a tape memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), synchronous static random access memory (SSRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM, SyncLink Dynamic Random Access Memory), and direct RAM bus random access memory (DRRAM, Direct Rambus Random Access Memory).The memories described in the embodiments of the present application are intended to include, but are not limited to, these and any other suitable types of memories.

[0204] Among them, the access method of the flight equipment disclosed in the present invention can be applied to the processor or implemented by the processor. The processor can be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the access method of the flight equipment can be completed by the hardware integrated logic circuit or software instructions in the processor. The above-mentioned processor can be a general-purpose processor, a digital signal processor (DSP, Digital Signal Processor), or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The processor can implement or execute the various methods, steps and logic block diagrams disclosed in the present invention. The general-purpose processor can be a microprocessor or any conventional processor, etc. In combination with the steps of the method disclosed in the present invention, it can be directly embodied as a hardware decoding processor to execute, or it can be executed by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium, which is located in a memory. The processor reads the information in the memory and completes the steps of the access method of the flight equipment provided in the embodiment of the present application in combination with its hardware.

[0205] The present invention also provides a computer storage medium, wherein the computer storage medium stores an executable program, and when the executable program is executed by a processor, the flight equipment access method described in any one of the embodiments of the present disclosure is implemented. Specifically, it can be a computer-readable storage medium, such as a memory that stores a computer program, and the above-mentioned computer program can be executed by a processor of a processing device to complete the steps described in the method of the embodiment of the present application. The computer-readable storage medium can be a memory such as ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disk, or CD-ROM.

[0206] The above is only a specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art who is familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present invention, which should be included in the protection scope of the present invention. Therefore, the protection scope of the present invention shall be based on the protection scope of the claims.

Claims

1. A method for accessing a flight device, It is characterized in that The method is applied to a terminal, and the method includes: In response to receiving the first request information sent by the flight device, sending a second request information to the gateway; wherein the first request information is used to request to establish a communication connection between the terminal and the flight device; the terminal is used for the flight device to access a predetermined network through the terminal, and the predetermined network is used to provide services for at least two flight devices; the second request information is used to request the gateway to perform security verification on the flight device to determine whether the flight device has the authority to establish a communication connection with the terminal; Receiving a first response message sent by the gateway in response to the second request message; wherein the first response message indicates that the flight device has the authority or does not have the authority; Based on the first response information, when it is determined that a communication connection between the terminal and the aircraft device is established, the aircraft device is connected to the predetermined network.

2. The method according to claim 1, It is characterized in that The second request information indicates a first identifier, which is determined jointly based on the device identifier of the aircraft device and the terminal identifier of the terminal; the second request information is used to request the gateway to perform security verification on the first identifier to determine whether the aircraft device has the authority to establish a communication connection with the terminal.

3. The method according to claim 1 or 2, It is characterized in that The method further comprises: In response to the first response information indicating that the aircraft device has the authority, determining to establish a communication connection between the terminal and the aircraft device; or, In response to the first response information indicating that the aircraft device does not have the authority, determining not to establish a communication connection between the terminal and the aircraft device.

4. The method according to claim 3, It is characterized in that the terminal is not connected to the predetermined network, the second request information is used to request the gateway to perform security verification on the aircraft device and the terminal to determine whether the aircraft device has the authority to establish a communication connection with the terminal and whether the terminal has the authority to access the predetermined network, and in response to the first response information indicating that the aircraft device has the authority, determining to establish a communication connection between the terminal and the aircraft device, includes: In response to the first response information indicating that the flight device has the authority to establish a communication connection with the terminal and the terminal has the authority to access the predetermined network, establishing a communication connection between the gateway and the terminal; wherein the gateway is used for the terminal to access the predetermined network through the gateway; In response to a successful establishment of a communication connection between the gateway and the terminal, it is determined to establish a communication connection between the terminal and the flight device.

5. The method according to claim 3, It is characterized in that The first response information sent by the receiving gateway in response to the second request information includes: receiving a second response message sent by the gateway in response to the second request message; wherein the second response message indicates a verification result of the safety verification of the flight device; In response to the verification result being a verification pass result, sending a third request message to the gateway; wherein the third request message is used to request the gateway to determine whether the flight device is in a device list corresponding to the terminal; the flight device in the device list has the authority to establish a communication connection with the terminal; The first response information sent by the gateway in response to the third request information is received.

6. A method for accessing a flight device, It is characterized in that The method is applied to a gateway, and the method comprises: receiving second request information sent by a terminal; wherein the second request information is information sent by the terminal when the terminal receives the first request information sent by the aircraft device; the terminal is used for the aircraft device to access a predetermined network through the terminal, and the predetermined network is used to provide services for at least two aircraft devices; the first request information is used to request to establish a communication connection between the terminal and the aircraft device; the second request information is used to perform security verification on the aircraft device to determine whether the aircraft device has the authority to establish a communication connection with the terminal; In response to receiving the second request information, a first response information is sent to the terminal; wherein the first response information indicates that the aircraft device has the authority, or the first response information indicates that the aircraft device does not have the authority; the first response information is used for: allowing the terminal to connect the aircraft device to the predetermined network when determining to establish the communication connection based on the first response information.

7. The method according to claim 6, It is characterized in that In response to receiving the second request information, sending first response information to the terminal, the method further includes: In response to receiving the second request information, performing security verification on the aircraft device to determine whether the aircraft device has the authority, and obtaining a determination result; Based on the determination result, the first response information is sent to the terminal.

8. The method according to claim 7, It is characterized in that The second request information indicates a first identifier, where the first identifier is jointly determined based on a device identifier of the aircraft device and a terminal identifier of the terminal; and the performing security verification on the aircraft device to determine whether the aircraft device has the authority includes: The first identification is subjected to security verification to determine whether the aircraft device has the authority to establish a communication connection with the terminal.

9. The method according to claim 6, It is characterized in that In response to receiving the second request information, performing security verification on the aircraft device to determine whether the aircraft device has the authority, and obtaining a determination result, includes: In response to receiving the second request information, sending a second response information to the terminal; wherein the second response information indicates a verification result of the safety verification of the flight equipment; In response to the verification result being a verification passed result, receiving a third request message sent by the terminal in response to the second response message; wherein the third request message is used to determine whether the aircraft device is in a device list corresponding to the terminal; and the aircraft device in the device list has the authority to establish a communication connection with the terminal; Determine whether the flying device is in the device list and obtain a determination result.

10. A method for accessing a flight device, It is characterized in that The method is applied to a flight device, and the method comprises: In response to the distance between the aircraft device and the terminal being within a first distance, sending a first request message to the terminal; wherein the first request message is used to request to establish a communication connection between the terminal and the aircraft device and trigger the terminal to send a second request message to a gateway; the second request message is used to request the gateway to perform security verification on the aircraft device to determine whether the aircraft device has the authority to establish a communication connection with the terminal; the terminal is used for the aircraft device to access a predetermined network through the terminal, and the predetermined network is used to provide services for at least two aircraft devices; In response to the aircraft device having the authority to establish a communication connection with the terminal, a communication connection is established between the aircraft device and the terminal, and the predetermined network is accessed through the terminal.

11. An access device for flight equipment, It is characterized in that The access device comprises: A first sending module is configured to send a second request message to a gateway in response to receiving a first request message sent by an aircraft device; wherein the first request message is used to request to establish a communication connection between a terminal and the aircraft device; the terminal is used for the aircraft device to access a predetermined network through the terminal, and the predetermined network is used to provide services for at least two aircraft devices; and the second request message is used to request the gateway to perform security verification on the aircraft device to determine whether the aircraft device has the authority to establish a communication connection with the terminal; A first receiving module is configured to receive a first response message sent by the gateway in response to the second request message; wherein the first response message indicates that the flight device has the authority or does not have the authority; The first connection module is configured to connect the aircraft device to the predetermined network when it is determined that a communication connection between the terminal and the aircraft device is to be established based on the first response information.

12. An access device for flight equipment, It is characterized in that The access device comprises: a second receiving module, configured to receive second request information sent by a terminal; wherein the second request information is information sent by the terminal when the terminal receives the first request information sent by the aircraft device; the terminal is used for the aircraft device to access a predetermined network through the terminal, and the predetermined network is used to provide services for at least two aircraft devices; the first request information is used to request to establish a communication connection between the terminal and the aircraft device; the second request information is used to perform security verification on the aircraft device to determine whether the aircraft device has the authority to establish a communication connection with the terminal; A second sending module is used to send a first response message to the terminal in response to receiving the second request information; wherein, the first response information indicates that the aircraft device has the authority, or the first response information indicates that the aircraft device does not have the authority; the first response information is used for: the terminal to connect the aircraft device to the predetermined network when determining to establish the communication connection based on the first response information.

13. An access device for flight equipment, It is characterized in that The access device comprises: A third sending module, in response to the distance between the aircraft device and the terminal being within a first distance, sends a first request message to the terminal; wherein the first request message is used to request to establish a communication connection between the terminal and the aircraft device and trigger the terminal to send a second request message to the gateway; the second request message is used to request the gateway to perform security verification on the aircraft device to determine whether the aircraft device has the authority to establish a communication connection with the terminal; the terminal is used for the aircraft device to access a predetermined network through the terminal, and the predetermined network is used to provide services for at least two aircraft devices; The second connection module establishes a communication connection between the aircraft device and the terminal in response to the aircraft device having the authority to establish a communication connection with the terminal, and accesses the predetermined network through the terminal.

14. A processing device, It is characterized in that The processing equipment comprises: A memory for storing executable programs; A processor, configured to implement the method according to any one of claims 1 to 10 when executing the executable program stored in the memory.

15. A computer storage medium, It is characterized in that The computer storage medium stores an executable program, and when the executable program is executed by a processor, the method according to any one of claims 1 to 10 is implemented.