Unmanned aerial vehicle cluster secret communication technology verification environment simulation platform and method based on Docker and NS-3
Through the verification environment simulation platform for confidential communication technology of the drone cluster based on Docker and NS-3, the problems of insufficient dynamic scenario simulation capabilities, low resource utilization efficiency, and disconnection between communication and task coordination in the existing technology are solved, and efficient and flexible drone cluster communication environment simulation is achieved.
Patent Information
- Application Number
- CN202510187721.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-20
- Publication Date
- 2025-05-23
AI Technical Summary
The existing UAV cluster communication environment simulation system has problems such as insufficient dynamic scenario simulation capabilities, low resource utilization efficiency, and disconnection between communication and task coordination in complex dynamic scenarios and practical application requirements.
The environment simulation platform for the confidential communication technology of the drone cluster based on Docker and NS-3 is used to verify the environment, manage Docker containers through Kubernetes, and use OpenVPN clients to establish logical network connections with the NS-3 simulation server to realize high-fidelity simulation of the drone cluster communication environment.
It realizes efficient simulation in complex dynamic scenarios, improves resource utilization efficiency, supports the simulation requirements of large-scale drone clusters, and deeply simulates the communication bottlenecks of drone cluster mission collaboration and confidential communication technology.
Smart Images

Figure CN120034895A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of unmanned aerial vehicle simulation, and more specifically to the technical field of a simulation platform and method for verifying a secure communication technology verification environment for unmanned aerial vehicle clusters based on Docker and NS-3. Background Art
[0002] With the rapid development of drone swarm technology, its wide application in military, logistics and other fields has made it an important part of modern unmanned systems. However, due to the characteristics of drone swarms such as distribution, high dynamics and resource constraints, its network communication faces increasingly severe security threats, such as communication eavesdropping, malicious interference, and forged instructions. Existing confidential communication technologies and cryptographic systems are difficult to fully adapt to the complex and changing application scenarios of drone swarms. Related research urgently needs a high-fidelity and scalable verification environment to simulate the characteristics of drone swarm networks and test security mechanisms. To this end, it is particularly important to build a drone swarm network communication simulation environment to verify confidential communication technologies and cryptographic protocols.
[0003] At present, mainstream UAV swarm network communication simulation systems usually use dedicated network simulation tools (such as NS-3, OMNeT++) or combine with physical simulation platforms (such as Gazebo, AirSim) for joint simulation. These systems have the following characteristics: 1. Wide support for network protocols, such as NS-3, OPNET, etc. support a variety of network protocols (such as WI-FI, LTE, Ad-hoc, MANET, etc.); 2. Combination of communication and physics: Gazebo, AirSim and other systems support associating the motion trajectory of UAVs with communication to achieve a more realistic simulation effect; 3. Open source software and good community updates and maintenance: Software such as NS-3 (https: / / gitlab.com / nsnam / NS-3-dev / ) is open source and has an active community, which can support functional expansion and customized development for specific needs.
[0004] Although the current UAV cluster communication environment simulation system is powerful, it still has the following limitations in complex dynamic scenarios and actual application requirements:
[0005] 1) Insufficient dynamic scenario simulation capabilities: It is impossible to flexibly simulate dynamically changing communication environments. Especially in certain specific scenarios, events such as channel interference, link interruption, and node movement will cause sharp fluctuations in communication signals. Existing systems usually require manual configuration and lack automated and intelligent dynamic scenario simulation capabilities.
[0006] 2) Low resource utilization efficiency: Traditional simulation systems are prone to bottlenecks in computing resources and memory in large-scale node scenarios, lack scalability, and are difficult to simulate large-scale drone clusters.
[0007] 3) Disconnection between communication and mission coordination: Many simulation systems focus on network performance, but lack in-depth simulation and analysis capabilities for communication bottlenecks in UAV cluster mission coordination, confidential communication technology, and cryptographic systems. It is difficult to evaluate the direct impact of communication conditions on the completion and implementation efficiency of technologies such as mission coordination and confidential communication. Summary of the invention
[0008] The purpose of the present invention is to solve the technical problems of insufficient dynamic scene simulation capability, low resource utilization efficiency and disconnection between communication and task coordination in existing drone cluster communication. The present invention provides a simulation platform and method for drone cluster secure communication technology verification environment based on Docker and NS-3. It increases the adaptation of technologies such as task coordination and secure communication, and improves the simulation efficiency of drone cluster secure communication technology verification environment.
[0009] In order to achieve the above-mentioned purpose, the present invention specifically adopts the following technical solutions:
[0010] The first aspect of the present invention provides a UAV cluster secure communication technology verification environment simulation platform based on Docker and NS-3, including Kubernetes (K8S), several Docker containers, OpenVPN clients and NS-3 simulation servers;
[0011] Each drone node in the drone cluster runs the virtualization of the control data simulation program as a Docker container. Kubernetes (K8S) provides Docker container orchestration functions to deploy, schedule and manage distributed virtual unmanned nodes. Each Docker container establishes a logical network connection with the NS-3 simulation server through the OpenVPN client to form a logically unified virtual communication environment; the traffic between each Docker container is aggregated to the NS-3 simulation server through the OpenVPN client, which takes over and applies the dynamic characteristics of the communication environment (such as delay, packet loss, bandwidth limitation, etc.) to realize the simulation of the drone cluster communication environment.
[0012] Specifically, the simulation of the verification environment for the secure communication technology of drone clusters refers to the use of computer simulation technology to simulate the behavior, performance and characteristics of drone clusters in the communication network. It mainly targets scenarios where multiple drones collaborate through wireless communication or other network protocols, simulating their communication topology, link quality, interference, delay, packet loss and other characteristics to study the network communication quality of drone clusters, secure communication technology and its safety, reliability and efficiency.
[0013] This solution aims to simulate the environment of the UAV cluster communication network through network simulation tools, under the premise of simulating the control program data. Specifically, a flexible and highly communication feature-reducing distributed network simulation platform is built by combining containerization technology, network simulation tools and virtual private networks. The overall technical architecture design is as follows: Figure 1 shown.
[0014] In one embodiment, in terms of container simulation, a Docker container that runs a control data simulation program is used to simulate unmanned nodes in a cluster. Each drone node is virtualized into a Docker container. Each Docker container simulates an independent network node and runs a target secure communication program. The core application logic and secure communication technology of the node are run in each Docker container.
[0015] Specifically, the Docker container that runs the control data simulation program is used to simulate the unmanned nodes in the cluster. Based on the lightweight virtualization environment, each hardware platform can quickly deploy and run multiple nodes to simulate the distributed system of the drone cluster.
[0016] In one embodiment, the control data simulation program is executed in one of C++ and Python.
[0017] The running control data simulation program is implemented in languages such as C++ and Python. In addition to C++ and Python, it can also be other computer languages that can meet the design requirements.
[0018] In one embodiment, in terms of container management, Kubernetes (K8S) is used as the control plane. Kubernetes (K8S) provides container orchestration capabilities to efficiently deploy, schedule and manage distributed virtual unmanned node Docker containers. It can dynamically create and destroy Docker containers for drone nodes, ensure that Docker containers in the cluster can be expanded on demand, meet the simulation requirements of large-scale drone clusters, and ensure high availability and elastic expansion of simulated unmanned nodes.
[0019] In one embodiment, the OpenVPN client logically connects the virtual unmanned nodes (Docker containers) on each hardware platform (virtualized host machine) to the NS-3 simulation server, hiding the complex network topology of each hardware and software platform in the virtual and real environment, providing a logically unified network environment, so that the communication between Docker containers can be simulated through the NS-3 simulation server for network characteristics. The virtual network of the OpenVPN client isolates the simulation environment from the actual physical network environment, and the simulated network characteristics (such as high latency and packet loss) will not affect the performance of the host machine or other networks, which facilitates simulation data collection and technical iteration and tuning.
[0020] In one embodiment, it also includes a Linux Kernel that plays a role in network management and data flow in the overall technical architecture, so that the Docker container can communicate with the NS-3 simulation server through the OpenVPN client, and at the same time support the TAP interface and the TAPBridge bridging of the NS-3 simulation server to realize the simulation data flow of the distributed network.
[0021] Specifically, the Linux Kernel plays a key role in network management and data transfer in the overall technical architecture of the present invention. The Linux Kernel provides functions such as virtual network devices (such as TUN / TAP and Veth) and network namespace.
[0022] The second aspect of the present invention provides a method for simulating a drone cluster secure communication technology verification environment based on Docker and NS-3, comprising the following steps:
[0023] S1. After each Docker container is started, it runs the OpenVPN client and automatically connects to the OpenVPN server on the NS-3 simulation server. At the same time, the OpenVPN client creates a virtual network interface TUN inside the container, which is responsible for encapsulating and decapsulating VPN data packets. The Docker container obtains an assigned virtual address through the OpenVPN server and communicates based on this virtual network.
[0024] S2. The application running inside the Docker container generates a data packet, which is processed by the confidential communication program, and then the target address is set to the virtual IP of other virtual unmanned nodes. The data packet is directed to the virtual network interface TUN through the routing table of the Docker container; the OpenVPN client encapsulates the data packet into a VPN data packet and sends it to the OpenVPN server of the NS-3 simulation server through the physical network interface eth0 of the Docker container;
[0025] The OpenVPN server on the S3 and NS-3 simulation servers receives the encapsulated data packets from the Docker container, and the OpenVPN server decapsulates the data and passes it to the TAPBri dge interface of the NS-3 simulation server;
[0026] The S4 and NS-3 simulation servers apply simulation characteristics to the data packets according to the established scenarios, and return to the OpenVPN server after execution, and are delivered to the target virtual unmanned node after encapsulation and decapsulation by the virtual network interface TUN.
[0027] The beneficial effects of the present invention are as follows:
[0028] 1. The present invention can simulate the communication environment through NS-3, and can more accurately simulate complex network characteristics such as delay, packet loss rate, bandwidth limitation, etc. in the communication network characteristics. Especially in the dynamic change of network topology or interference scenario, it can restore the behavior characteristics of the real network environment.
[0029] 2. Docker containerization technology supports rapid deployment and dynamic expansion of the number of nodes. Each container is open source and independently simulates an unmanned node, which is convenient for large-scale distributed network experiments. Combined with OpenVPN technology, it can realize distributed simulation across physical hosts and build a flexible and unified virtual confidential communication technology verification network environment.
[0030] 3. The OpenVPN client uniformly introduces the traffic of distributed container nodes into the NS-3 simulation server to achieve centralized management and unified control, simplifying the collection of simulation data, simulation traffic processing and other tasks. At the same time, the virtual network is isolated from the real network, which improves the controllability of the simulation environment. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments. It should be understood that the following drawings only show certain embodiments of the present invention and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without creative work.
[0032] Figure 1 It is a structural schematic diagram of a UAV cluster secure communication technology verification environment simulation platform based on Docker and NS-3 of the present invention;
[0033] Figure 2 It is a flow chart of a method for simulating an environment for verifying secure communication technology of a drone cluster based on Docker and NS-3 of the present invention. DETAILED DESCRIPTION
[0034] In order to make the technical problems, technical solutions and technical effects of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Generally, the components of the embodiments of the present invention described and shown in the drawings here can be arranged and designed in various different configurations.
[0035] Example 1
[0036] like Figure 1As shown, this embodiment provides a UAV cluster secure communication technology verification environment simulation platform based on Docker and NS-3, including Kubernetes (K8S), several Docker containers, OpenVPN clients and NS-3 simulation servers;
[0037] Each drone node in the drone cluster runs the virtualization of the control data simulation program as a Docker container. Kubernetes (K8S) provides Docker container orchestration functions to deploy, schedule and manage distributed virtual unmanned nodes. Each Docker container establishes a logical network connection with the NS-3 simulation server through the OpenVPN client to form a logically unified virtual communication environment; the traffic between each Docker container is aggregated to the NS-3 simulation server through the OpenVPN client, which takes over and applies the dynamic characteristics of the communication environment (such as delay, packet loss, bandwidth limitation, etc.) to realize the simulation of the drone cluster communication environment.
[0038] Specifically, the simulation of the verification environment for the secure communication technology of drone clusters refers to the use of computer simulation technology to simulate the behavior, performance and characteristics of drone clusters in the communication network. It mainly targets scenarios where multiple drones collaborate through wireless communication or other network protocols, simulating their communication topology, link quality, interference, delay, packet loss and other characteristics to study the network communication quality of drone clusters, secure communication technology and its safety, reliability and efficiency.
[0039] This solution aims to simulate the environment of the UAV cluster communication network through network simulation tools, under the premise of simulating the control program data. Specifically, a flexible and highly communication feature-reducing distributed network simulation platform is built by combining containerization technology, network simulation tools and virtual private networks. The overall technical architecture design is as follows: Figure 1 shown.
[0040] In terms of container simulation, a Docker container that runs a control data simulation program is used to simulate the unmanned nodes in the cluster. Each drone node is virtualized into a Docker container. Each Docker container simulates an independent network node and runs the target confidential communication program. Each Docker container runs the node’s core application logic and confidential communication technology.
[0041] Specifically, the Docker container that runs the control data simulation program is used to simulate the unmanned nodes in the cluster. Based on the lightweight virtualization environment, each hardware platform can quickly deploy and run multiple nodes to simulate the distributed system of the drone cluster.
[0042] Run the control data simulation program in one of C++ or Python.
[0043] The running control data simulation program is implemented in languages such as C++ and Python. In addition to C++ and Python, it can also be other computer languages that can meet the design requirements.
[0044] In terms of container management, Kubernetes (K8S) serves as the control plane. Kubernetes (K8S) provides container orchestration capabilities to efficiently deploy, schedule and manage distributed virtual unmanned node Docker containers. It can dynamically create and destroy Docker containers for drone nodes to ensure that Docker containers in the cluster can be expanded on demand, meet the simulation needs of large-scale drone clusters, and ensure the high availability and elastic expansion of simulated unmanned nodes.
[0045] The OpenVPN client logically connects the virtual unmanned nodes (Docker containers) on each hardware platform (virtualized host) to the NS-3 simulation server, hiding the complex network topology of each hardware and software platform in the virtual-real environment, providing a logically unified network environment, so that the communication between Docker containers can be simulated through the NS-3 simulation server for network characteristics. The virtual network of the OpenVPN client isolates the simulation environment from the actual physical network environment. The simulated network characteristics (such as high latency and packet loss) will not affect the performance of the host or other networks, which facilitates simulation data collection and technical iteration and tuning.
[0046] It also includes the Linux Kernel, which plays a role in network management and data flow in the overall technical architecture. It enables the Docker container to communicate with the NS-3 simulation server through the OpenVPN client, and supports the TAP interface and the TAPBridge bridge of the NS-3 simulation server to realize the simulation data flow of the distributed network.
[0047] Specifically, the Linux Kernel plays a key role in network management and data transfer in the overall technical architecture of the present invention. The Linux Kernel provides functions such as virtual network devices (such as TUN / TAP and Veth) and network namespace.
[0048] Example 2
[0049] This embodiment provides a method for simulating a drone cluster secure communication technology verification environment based on Docker and NS-3, including the following steps:
[0050] S1. After each Docker container is started, it runs the OpenVPN client and automatically connects to the OpenVPN server on the NS-3 simulation server. At the same time, the OpenVPN client creates a virtual network interface TUN inside the container, which is responsible for encapsulating and decapsulating VPN data packets. The Docker container obtains an assigned virtual address through the OpenVPN server and communicates based on this virtual network.
[0051] S2. The application running inside the Docker container generates a data packet, which is processed by the confidential communication program, and then the target address is set to the virtual IP of other virtual unmanned nodes. The data packet is directed to the virtual network interface TUN through the routing table of the Docker container; the OpenVPN client encapsulates the data packet into a VPN data packet and sends it to the OpenVPN server of the NS-3 simulation server through the physical network interface eth0 of the Docker container;
[0052] The OpenVPN server on the S3 and NS-3 simulation servers receives the encapsulated data packets from the Docker container, and the OpenVPN server decapsulates the data and passes it to the TAPBridge interface of the NS-3 simulation server;
[0053] The S4 and NS-3 simulation servers apply simulation characteristics to the data packets according to the established scenarios, and return to the OpenVPN server after execution, and are delivered to the target virtual unmanned node after encapsulation and decapsulation by the virtual network interface TUN.
Claims
1. A UAV cluster secure communication technology verification environment simulation platform based on Docker and NS-3, characterized in that: Includes Kubernetes (K8S), several Docker containers, OpenVPN client, and NS-3 simulation server; Each drone node in the drone cluster runs the virtualization of the control data simulation program as a Docker container. Kubernetes (K8S) provides Docker container orchestration functions to deploy, schedule and manage distributed virtual unmanned nodes. Each Docker container establishes a logical network connection with the NS-3 simulation server through the OpenVPN client to form a logically unified virtual communication environment; the traffic between each Docker container is aggregated to the NS-3 simulation server through the OpenVPN client, which takes over and applies the dynamic characteristics of the communication environment to realize the simulation of the drone cluster communication environment.
2. According to claim 1, a UAV cluster secure communication technology verification environment simulation platform based on Docker and NS-3 is characterized in that: In terms of container simulation, a Docker container that runs a control data simulation program is used to simulate the unmanned nodes in the cluster. Each drone node is virtualized into a Docker container. Each Docker container simulates an independent network node and runs the target confidential communication program. Each Docker container runs the node’s core application logic and confidential communication technology.
3. According to claim 2, a UAV cluster secure communication technology verification environment simulation platform based on Docker and NS-3 is characterized in that: Run the control data simulation program in one of C++ or Python.
4. According to claim 2, a UAV cluster secure communication technology verification environment simulation platform based on Docker and NS-3 is characterized in that: In terms of container management, Kubernetes (K8S) serves as the control plane. Kubernetes (K8S) provides container orchestration capabilities to deploy, schedule and manage distributed virtual unmanned node Docker containers. It can dynamically create and destroy Docker containers for drone nodes to ensure that Docker containers in the cluster can be expanded on demand to meet the simulation needs of large-scale drone clusters and ensure high availability and elastic expansion of simulated unmanned nodes.
5. According to claim 4, a UAV cluster secure communication technology verification environment simulation platform based on Docker and NS-3 is characterized in that: The OpenVPN client logically connects the virtual unmanned nodes (Docker containers) on each hardware platform to the NS-3 simulation server, hiding the complex network topology of each hardware and software platform in the virtual-real environment, providing a logically unified network environment, so that the communication between Docker containers can be simulated through the NS-3 simulation server for network characteristics. The virtual network of the OpenVPN client isolates the simulation environment from the actual physical network environment. The simulated network characteristics will not affect the performance of the host machine or other networks, which facilitates simulation data collection and technical iteration and tuning.
6. The UAV cluster secure communication technology verification environment simulation platform based on Docker and NS-3 according to claim 5 is characterized in that: It also includes the Linux Kernel, which plays a role in network management and data flow in the overall technical architecture. It enables the Docker container to communicate with the NS-3 simulation server through the OpenVPN client, and supports the TAP interface and the TAPBridge bridge of the NS-3 simulation server to realize the simulation data flow of the distributed network.
7. A simulation method for verifying the secure communication technology of drone cluster based on Docker and NS-3, characterized in that: A drone cluster secure communication technology verification environment simulation platform based on Docker and NS-3 as described in any one of claims 1 to 6.
8. The method for simulating a verification environment for a drone cluster secure communication technology based on Docker and NS-3 according to claim 7 is characterized in that: The steps include: S1. After each Docker container is started, it runs the OpenVPN client and automatically connects to the OpenVPN server on the NS-3 simulation server. At the same time, the OpenVPN client creates a virtual network interface TUN inside the container, which is responsible for encapsulating and decapsulating VPN data packets. The Docker container obtains an assigned virtual address through the OpenVPN server and communicates based on this virtual network. S2. The application running inside the Docker container generates a data packet, which is processed by the confidential communication program, and then the destination address is set to the virtual IP of other virtual unmanned nodes. The data packet is directed to the virtual network interface TUN through the routing table of the Docker container; the OpenVPN client encapsulates the data packet into a VPN data packet and sends it to the OpenVPN server of the NS-3 simulation server through the physical network interface eth0 of the Docker container; The OpenVPN server on the S3 and NS-3 simulation servers receives the encapsulated data packets from the Docker container, and the OpenVPN server decapsulates the data and passes it to the TAPBridge interface of the NS-3 simulation server; The S4 and NS-3 simulation servers apply simulation characteristics to the data packets according to the established scenarios, and return to the OpenVPN server after execution, and are delivered to the target virtual unmanned node after encapsulation and decapsulation by the virtual network interface TUN.