Authentication method of unmanned aerial vehicle, management and control device, unmanned aerial vehicle and system
By conducting joint certification of unmanned aerial vehicles and operators, the problem of inability to authenticate operators in the prior art is solved, and the flight safety supervision and responsibility allocation of unmanned aerial vehicles are achieved.
Patent Information
- Application Number
- CN202510205795.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-24
- Publication Date
- 2025-06-10
AI Technical Summary
The prior art is difficult to authenticate operators of unmanned aerial vehicles and cannot meet the requirements of the operator's identity confirmation and authorization of the new flight management regulations.
By receiving the authentication request sent by the unmanned aerial vehicle, the first authentication is performed using the unmanned aerial vehicle identification information, and the second authentication is performed based on the operator's certificate, the authentication response is sent to the unmanned aerial vehicle, and the authentication result information is carried.
The joint certification of unmanned aerial vehicles and operators has been achieved, and the operators can be supervised, and the responsibility for abnormal flight behaviors has been clarified, which has improved the flight safety of unmanned aerial vehicles.
Smart Images

Figure CN120122682A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technologies, and in particular, to an authentication method for an unmanned aerial vehicle, an unmanned aerial vehicle control device, an unmanned aerial vehicle, an unmanned aerial vehicle system, a computer-readable storage medium, and a computer program product. Background Art
[0002] Currently, new regulations for the flight management of unmanned aerial vehicles have come into effect. In the new flight management regulations, it is stipulated that for personnel operating unmanned aerial vehicles, they need to obtain an operator's license. Moreover, for unmanned aerial vehicles that violate relevant management regulations, it is usually necessary to hold the operator of the unmanned aerial vehicle accountable. Therefore, in response to the new flight management regulations, it is necessary to simultaneously perform identity verification and authorization and other authentication for both the unmanned aerial vehicle and the operator. However, for existing authentication methods for flight management, they can only authenticate the unmanned aerial vehicle, and there is no technical solution for authenticating the operator of the unmanned aerial vehicle. Summary of the Invention
[0003] The present disclosure provides an authentication method for an unmanned aerial vehicle, an unmanned aerial vehicle control device, an unmanned aerial vehicle, an unmanned aerial vehicle system, a computer-readable storage medium, and a computer program product.
[0004] According to a first aspect of the present disclosure, there is provided an authentication method for an unmanned aerial vehicle, which is applied to an unmanned aerial vehicle control device and includes: receiving an authentication request sent by the unmanned aerial vehicle, where the authentication information carried in the authentication request includes unmanned aerial vehicle identification information and an operator credential; performing a first authentication on the unmanned aerial vehicle according to the unmanned aerial vehicle identification information, and performing a second authentication on the operator of the unmanned aerial vehicle according to the operator credential; sending an authentication response to the unmanned aerial vehicle, where the authentication response carries authentication result information of performing the first authentication and the second authentication.
[0005] Optionally, the performing a second authentication on the operator of the unmanned aerial vehicle according to the operator credential includes: obtaining the license information of the operator according to the operator credential; performing the second authentication on the operator according to the license information.
[0006] Optionally, the second authentication includes at least one of the following: verifying the validity of the license information, verifying whether the license information matches the type of the unmanned aerial vehicle, and verifying whether the license information has the authorization to operate the unmanned aerial vehicle.
[0007] Optionally, obtaining the license information of the operator according to the operator credential includes: obtaining a dynamic key corresponding to the operator credential; using the dynamic key to decrypt the operator credential to obtain the license information.
[0008] Optionally, receiving the operator credential and the dynamic key sent by the operator registration center; establishing a correspondence between the operator credential and the dynamic key.
[0009] Optionally, using a first key to decrypt the encrypted authentication information to obtain the unmanned aerial vehicle identification information, the operator credential, and a first verification information; using a second key to verify the first verification information; and determining that the unmanned aerial vehicle identification information and the operator credential are valid when the first verification information passes the verification.
[0010] Optionally, using the first key to generate a second verification information corresponding to the authentication result information; using the second key to encrypt the authentication result information and the second verification information to generate the encrypted authentication response.
[0011] Optionally, during the process of registering the unmanned aerial vehicle to the communication system, receiving the authentication request sent by the unmanned aerial vehicle system network function or the network exposure function; wherein, the unmanned aerial vehicle sends the authentication request to the security and authentication proxy function, and the security and authentication proxy function forwards the authentication request to the unmanned aerial vehicle system network function or the network exposure function; sending the authentication response to the unmanned aerial vehicle system network function or the network exposure function; wherein, the unmanned aerial vehicle system network function or the network exposure function sends the authentication response to the security and authentication proxy function, and the security and authentication proxy function forwards the authentication response to the unmanned aerial vehicle.
[0012] Optionally, during the process of the unmanned aerial vehicle requesting to establish a session connection, receiving the authentication request sent by the unmanned aerial vehicle system network function or the network exposure function; wherein, the unmanned aerial vehicle sends the authentication request to the connection management function, and the connection management function forwards the authentication request to the unmanned aerial vehicle system network function or the network exposure function; sending the authentication response to the unmanned aerial vehicle system network function; wherein, the unmanned aerial vehicle system network function or the network exposure function sends the authentication response to the connection management function, and the connection management function forwards the authentication response to the unmanned aerial vehicle.
[0013] Optionally, in the case where the first authentication is successful and the second authentication is successful, a third key is added to the authentication result information. After the first authentication is successful and the second authentication is successful, the unmanned aerial vehicle uses the third key to process the information interacting with the unmanned aerial vehicle control device.
[0014] Optionally, in the case where the first authentication is successful and the second authentication is successful, an association relationship is established between the unmanned aerial vehicle identification information and the license information; and joint control is performed on the unmanned aerial vehicle and the control device corresponding to the operator according to the association relationship.
[0015] According to a second aspect of the present disclosure, there is provided an authentication method for an unmanned aerial vehicle, which is applied to the unmanned aerial vehicle and includes: sending an authentication request to an unmanned aerial vehicle control device, where the authentication information carried in the authentication request includes unmanned aerial vehicle identification information and operator credentials; receiving an authentication response sent by the unmanned aerial vehicle control device; where the authentication response carries authentication result information obtained by the unmanned aerial vehicle control device through a first authentication based on the unmanned aerial vehicle identification information and a second authentication based on the operator credentials.
[0016] Optionally, before sending the authentication request, an initial connection is established with the control device of the operator; and the operator credentials sent by the control device are received.
[0017] Optionally, the control device receives the operator credentials sent by an operator registration center; where the operator registration center encrypts the license information of the operator according to a dynamic key to generate the operator credentials.
[0018] Optionally, a first verification information corresponding to the unmanned aerial vehicle identification information and the operator credentials is generated using the second key; and the authentication information is encrypted using the first key for the first verification information corresponding to the unmanned aerial vehicle identification information and the operator credentials.
[0019] Optionally, the authentication response is decrypted using the second key to obtain the authentication result information and a second verification information; the second verification information is verified using the first key; and when the second verification information passes the verification, it is determined that the authentication result information is valid.
[0020] Optionally, during the process of registering to the communication system, the authentication request is sent to the security and authentication proxy function; wherein, the security and authentication proxy function forwards the authentication request to the drone system network function or the network exposure function, and the drone system network function or the network exposure function sends the authentication request to the unmanned aerial vehicle control device; receive the authentication response sent by the security and authentication proxy function; wherein, the unmanned aerial vehicle control device sends the authentication response to the drone system network function or the network exposure function, and the drone system network function or the network exposure function sends the authentication response to the security and authentication proxy function.
[0021] Optionally, during the process of requesting to establish a session connection, the authentication request is sent to the connection management function; wherein, the connection management function forwards the authentication request to the drone system network function or the network exposure function, and the drone system network function or the network exposure function sends the authentication request to the unmanned aerial vehicle control device; receive the authentication response sent by the connection management function; wherein, the unmanned aerial vehicle control device sends the authentication response to the drone system network function or the network exposure function, and the drone system network function or the network exposure function sends the authentication response to the connection management function.
[0022] Optionally, in the case where the first authentication is successful and the second authentication is successful, a control connection with the control device is established.
[0023] According to a third aspect of the present disclosure, there is provided an unmanned aerial vehicle control device, including: a first receiving module, configured to receive an authentication request sent by an unmanned aerial vehicle, wherein the authentication information carried in the authentication request includes unmanned aerial vehicle identification information and operator credentials; a joint authentication module, configured to perform a first authentication on the unmanned aerial vehicle according to the unmanned aerial vehicle identification information, and perform a second authentication on the operator of the unmanned aerial vehicle according to the operator credentials; a first sending module, configured to send an authentication response to the unmanned aerial vehicle, wherein the authentication response carries authentication result information of performing the first authentication and the second authentication.
[0024] According to a fourth aspect of the present disclosure, there is provided an unmanned aerial vehicle control device, including: a memory; and a processor coupled to the memory, the processor being configured to execute the authentication method of the unmanned aerial vehicle as described above based on instructions stored in the memory.
[0025] According to a fifth aspect of the present disclosure, there is provided an unmanned aerial vehicle, comprising: a second sending module configured to send an authentication request to an unmanned aerial vehicle control device, wherein the authentication information carried in the authentication request includes unmanned aerial vehicle identification information and operator credentials; and a second receiving module configured to receive an authentication response sent by the unmanned aerial vehicle control device; wherein the authentication response carries authentication result information of the unmanned aerial vehicle control device performing a first authentication based on the unmanned aerial vehicle identification information and a second authentication based on the operator credentials.
[0026] According to a sixth aspect of the present disclosure, there is provided an unmanned aerial vehicle, comprising: a memory; and a processor coupled to the memory, the processor being configured to execute the authentication method of the unmanned aerial vehicle as described above based on instructions stored in the memory.
[0027] According to a seventh aspect of the present disclosure, there is provided an unmanned aerial vehicle system, comprising: the unmanned aerial vehicle control device as described above and the unmanned aerial vehicle as described above.
[0028] According to an eighth aspect of the present disclosure, there is provided a computer-readable storage medium storing computer instructions, the computer instructions being executed by a processor to perform the method as described above.
[0029] According to a ninth aspect of the present disclosure, there is provided a computer program product storing computer instructions, the computer instructions being executed by a processor to perform the method as described above.
[0030] The authentication method of the unmanned aerial vehicle, the unmanned aerial vehicle control device, the unmanned aerial vehicle, the unmanned aerial vehicle system, the computer-readable storage medium and the computer program product of the present disclosure can perform joint authentication on the unmanned aerial vehicle and the operator, can supervise the operator of the unmanned aerial vehicle, can clarify the responsibility attribution for abnormal flight control behaviors of the unmanned aerial vehicle, and improve the flight safety of the unmanned aerial vehicle. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] By describing the embodiments of the present disclosure in more detail in conjunction with the accompanying drawings, the above and other objects, features and advantages of the present disclosure will become more apparent. The drawings are used to provide a further understanding of the embodiments of the present disclosure, and constitute a part of the specification, and are used to explain the present disclosure together with the embodiments of the present disclosure, and do not constitute a limitation to the present disclosure. The above and other objects and advantages of the present disclosure will be further described below in conjunction with specific embodiments and with reference to the accompanying drawings. In the drawings, the same or corresponding technical features or components will be denoted by the same or corresponding reference numerals.
[0032] Figure 1 Schematic flowchart of some embodiments of a method for authenticating an unmanned aerial vehicle according to the present disclosure;
[0033] Figure 2 Schematic flowchart of authenticating an operator in some embodiments of a method for authenticating an unmanned aerial vehicle according to the present disclosure;
[0034] Figure 3 Schematic flowchart of processing using a key in some embodiments of a method for authenticating an unmanned aerial vehicle according to the present disclosure;
[0035] Figure 4 Schematic flowchart of performing joint control in some embodiments of a method for authenticating an unmanned aerial vehicle according to the present disclosure;
[0036] Figure 5 Schematic flowchart of the authentication process when an unmanned aerial vehicle is registered to a communication system in some embodiments of a method for authenticating an unmanned aerial vehicle according to the present disclosure;
[0037] Figure 6 Schematic flowchart of the authentication process when an unmanned aerial vehicle requests to establish a session connection in some embodiments of a method for authenticating an unmanned aerial vehicle according to the present disclosure;
[0038] Figure 7 Schematic flowchart of application layer authentication in some embodiments of a method for authenticating an unmanned aerial vehicle according to the present disclosure;
[0039] Figure 8 Schematic flowchart of some other embodiments of a method for authenticating an unmanned aerial vehicle according to the present disclosure;
[0040] Figure 9 Schematic diagram of modules of some embodiments of a control device for an unmanned aerial vehicle according to the present disclosure;
[0041] Figure 10 Schematic diagram of modules of some other embodiments of a control device for an unmanned aerial vehicle according to the present disclosure;
[0042] Figure 11 Schematic diagram of modules of some embodiments of an unmanned aerial vehicle according to the present disclosure;
[0043] Figure 12 Schematic diagram of modules of some other embodiments of an unmanned aerial vehicle according to the present disclosure. Detailed implementation manners
[0044] The exemplary embodiments of the present disclosure will be described below in conjunction with the accompanying drawings. For clarity and conciseness, not all features of the embodiments are described in the specification. However, it should be understood that many implementation-specific settings must be made during the implementation of the embodiments in order to achieve the specific goals of the developer, for example, to comply with those restrictions related to the device and the business, and these restrictions may vary with different implementations. In addition, it should also be understood that although the development work may be very complex and time-consuming, for those skilled in the art who benefit from the present disclosure, such development work is merely a routine task.
[0045] It should be noted that: Unless otherwise specifically stated, the relative arrangements, numerical expressions, and numerical values of the components and steps set forth in these embodiments do not limit the scope of the present disclosure.
[0046] Those skilled in the art can understand that terms such as "first", "second", etc. in the embodiments of the present disclosure are only used to distinguish different steps, devices, or modules, etc., and neither represent any specific technical meaning nor indicate an inevitable logical order between them.
[0047] It should also be understood that in the embodiments of the present disclosure, "a plurality of" may refer to two or more, and "at least one" may refer to one, two, or more.
[0048] It should also be understood that for any component, data, or structure mentioned in the embodiments of the present disclosure, without clear definition or contrary indication in the context, it can generally be understood as one or more.
[0049] In addition, the term "and / or" in the present disclosure is merely a description of the association relationship of the associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in the present disclosure generally represents an "or" relationship between the associated objects before and after.
[0050] It should also be understood that the present disclosure emphasizes the differences between the various embodiments. The similarities or similarities between them can be referred to each other. For the sake of brevity, they will not be elaborated one by one.
[0051] At the same time, it should be understood that for the convenience of description, the sizes of the various parts shown in the drawings are not drawn in actual proportional relationships.
[0052] The following description of at least one exemplary embodiment is actually merely illustrative and in no way limits the present disclosure or its application or use.
[0053] Known technologies, methods, and devices that are known to those of ordinary skill in the relevant art may not be discussed in detail, but where appropriate, such technologies, methods, and devices should be considered as part of the specification.
[0054] It should be noted that like reference numerals and letters refer to like items in the following figures, and thus, once an item is defined in one figure, it need not be further discussed in subsequent figures.
[0055] In addition, to avoid obscuring the present disclosure with unnecessary details, only the processing steps and / or device structures that are closely related to at least the solutions according to the present disclosure are shown in the figures, while other details that are not closely related to the present disclosure are omitted. It should also be noted that like reference numerals and letters in the figures indicate like items, and thus, once an item is defined in one figure, it need not be further discussed for subsequent figures.
[0056] Figure 1 It is a schematic flowchart of some embodiments of a method for authenticating an uncrewed aerial vehicle according to the present disclosure. As Figure 1 shown, the method for authenticating an uncrewed aerial vehicle is applied to an uncrewed aerial vehicle control device and includes steps S101 - S103.
[0057] Step S101, receiving an authentication request sent by the uncrewed aerial vehicle, where the authentication information carried in the authentication request includes uncrewed aerial vehicle identification information and operator credentials.
[0058] An Uncrewed Aerial System (UAS) is a combination of an uncrewed aerial vehicle (UAV) and a UAV controller; the UAV controller (a control device used by an operator) is operated by the operator as a single unit, and the operator needs to have operating qualifications and be accountable; when the UAV controller is platform - based, its operator can be an enterprise operating the platform.
[0059] A UAS Service Supplier (USS) is an entity that provides services to the operator of a UAS to meet the UTM operation requirements for supporting the safe and effective use of airspace. The USS can provide a subset of functions to meet the business objectives of the provider (such as UTM, remote identification).
[0060] Uncrewed Aerial System Traffic Management (UTM for short) is a system that can safely and effectively integrate in-flight unmanned aerial vehicles with other airspace users, providing a set of functions and services for managing the operations of a series of autonomous aircraft (such as verifying UAVs, authorizing UAS services, managing UAS policies, and controlling UAV traffic in the airspace, etc.).
[0061] The Uncrewed Aerial Vehicle (UAV) can be various types of drones, etc.; the UAV identification information can be information such as the UAV ID at the CAA (Civil Aviation Administration) level, and the operator credentials can be various types of credentials. The UAV ID at the CAA level is the drone identity identifier assigned by the USS or UTM, which can uniquely identify an uncrewed aerial vehicle within the USS scope.
[0062] Step S102: Perform the first authentication on the uncrewed aerial vehicle according to the UAV identification information, and perform the second authentication on the operator of the uncrewed aerial vehicle according to the operator credentials.
[0063] Step S103: Send an authentication response to the uncrewed aerial vehicle, where the authentication response carries the authentication result information of the first authentication and the second authentication.
[0064] The UAV control device can use various methods for the first authentication and the second authentication, and can generate authentication result information according to the first authentication result and the second authentication result. If both the first authentication and the second authentication are passed, the authentication result information includes information indicating that both the first authentication and the second authentication are passed; if the first authentication and / or the second authentication fails, the authentication result information includes the reason information indicating that the first authentication and / or the second authentication fails.
[0065] The authentication method of the uncrewed aerial vehicle in the present disclosure can perform the first authentication on the uncrewed aerial vehicle according to the UAV identification information, perform the second authentication on the operator of the uncrewed aerial vehicle according to the operator credentials, and generate the authentication result information based on the first authentication result of the first authentication and the second authentication result of the second authentication, which can perform joint authentication on the uncrewed aerial vehicle and the operator, can supervise the operator of the uncrewed aerial vehicle, can clarify the responsibility attribution for abnormal flight control behaviors of the uncrewed aerial vehicle, and improve the flight safety of the uncrewed aerial vehicle.
[0066] Figure 2Schematic diagram of the process for authenticating an operator in some embodiments of the authentication method for an unmanned aerial vehicle according to the present disclosure, as Figure 2 shown:
[0067] Step S201: Obtain the license information of the operator according to the operator credential.
[0068] Before the unmanned aerial vehicle sends an authentication request, the operator needs to log in to the operator registration center and obtain the operator credential assigned by the operator registration center. The operator can send the license information of the operator to the operator registration center, and the license information can be the license ID, etc. The operator registration center can use a dynamic key and a variety of preset encryption algorithms to encrypt the license information of the operator and generate an operator credential. The operator registration center and the unmanned aerial vehicle control device synchronize information, including the operator credential, the dynamic key, etc.
[0069] The unmanned aerial vehicle control device receives information such as the operator credential and the dynamic key sent by the operator registration center, and establishes the corresponding relationship between the operator credential and the dynamic key. Based on the corresponding relationship, the unmanned aerial vehicle control device obtains the dynamic key corresponding to the operator credential, and uses the dynamic key and the preset encryption algorithm to decrypt the operator credential to obtain the license information.
[0070] Step S202: Perform a second authentication on the operator according to the license information.
[0071] The unmanned aerial vehicle control device can perform a first authentication on the CAA-level UAV ID, and the first authentication includes determining whether the CAA-level UAV ID is legal and valid, etc. After obtaining the license information, the unmanned aerial vehicle control device performs a second authentication, and the second authentication includes one or more of the following: verifying the validity of the license information, verifying whether the license information matches the type of the unmanned aerial vehicle, verifying whether the license information has the authorization to operate the unmanned aerial vehicle, etc.
[0072] Figure 3 Schematic diagram of the process for processing using keys in some embodiments of the authentication method for an unmanned aerial vehicle according to the present disclosure, as Figure 3 shown:
[0073] Step S301: Use the first key to decrypt the encrypted authentication information to obtain the unmanned aerial vehicle identification information, the operator credential, and the first verification information.
[0074] Step S302: Use the second key to verify the first verification information.
[0075] The first key and the second key can be various types of keys. For example, the first key and the second key are a pair of keys, including a public key and a private key. When encrypting using the first key or the second key, the public key and a preset asymmetric algorithm can be used to encrypt the information. When decrypting using the first key or the second key, the private key of the same key pair as the public key and a preset asymmetric algorithm can be used to decrypt the information. When generating verification information (signature) using the first key or the second key, the private key can be used to process the information. When verifying information using the first key or the second key, the public key of the same key pair as the private key can be used for verification (signature verification).
[0076] The unmanned aerial vehicle control device decrypts the encrypted authentication information using the first key to obtain the unmanned aerial vehicle identification information, the operator's credential, and the first verification information. The first verification information can be various types of verification information. For example, the unmanned aerial vehicle uses the second key and a preset verification algorithm to calculate the unmanned aerial vehicle identification information and / or the operator's credential to obtain the first verification information.
[0077] There are various methods for the unmanned aerial vehicle control device to verify the first verification information using the second key. For example, the unmanned aerial vehicle control device can use the second key and a preset verification algorithm to calculate the first verification information to obtain the verification information. Compare the verification information with information such as the unmanned aerial vehicle identification information and the operator's credential. If they are the same, the first verification information passes the verification. If they are different, the first verification information fails the verification.
[0078] Step S303, in the case where the first verification information passes the verification, determine that the unmanned aerial vehicle identification information and the operator's credential are valid.
[0079] Step S304, use the first key to generate the second verification information corresponding to the authentication result information.
[0080] There are various methods to generate the second verification information. For example, the unmanned aerial vehicle control device can use the first key and a preset verification algorithm to calculate the authentication result information to obtain the second verification information.
[0081] Step S305, use the second key to encrypt the authentication result information and the second verification information to generate the encrypted authentication response.
[0082] There are various methods to generate the encrypted authentication response. For example, the unmanned aerial vehicle control device can use the second key and a preset encryption algorithm to encrypt the authentication result information and the second verification information to obtain the encrypted authentication response.
[0083] When the first authentication is successful and the second authentication is successful, a third key can be added to the authentication result information, wherein after the first authentication is successful and the second authentication is successful, the unmanned aerial vehicle uses the third key to process information interacting with the unmanned aerial vehicle control device.
[0084] In some embodiments, before the unmanned aerial vehicle sends an authentication request, the operator can log in to the operator registration center through a mobile phone, control device, etc. to request operator credentials; the operator registration center uses a dynamic key to encrypt the operator's license information to obtain the operator credentials; the operator registration center returns the operator credentials to the operator, and sends the operator credentials, dynamic keys and other information to the unmanned aerial vehicle control device; the unmanned aerial vehicle control device receives the operator credentials and dynamic keys sent by the operator registration center, and establishes a corresponding relationship between the operator credentials and the dynamic keys.
[0085] The unmanned aerial vehicle performs proximity discovery and discovers the operator's control device, and the unmanned aerial vehicle establishes an initial connection with the operator's control device; the operator's control device sends the operator credentials to the unmanned aerial vehicle; the unmanned aerial vehicle initiates a UUAA request to the unmanned aerial vehicle control device through a network connection, carrying a CAA-level UAV ID (unmanned aerial vehicle identification information), operator credentials, etc.
[0086] The USS UAV Authorization / Authentication (UUAA) process is used to ensure that the UAV successfully registers with the USS and obtains the flight authorization from the USS. Before enabling a connection that supports UAS services, the UAV can be authenticated and authorized through the UUAA process with the support of the 3GPP system.
[0087] The unmanned aerial vehicle control device may include devices or systems such as USS and / or UTM; while authenticating the unmanned aerial vehicle, the unmanned aerial vehicle control device uses the pre-established correspondence between the operator credential and the dynamic key to query its corresponding dynamic key, decrypt the operator credential using the dynamic key, obtain the operator's license information, verify the validity of the operator's license and its matching degree with the unmanned aerial vehicle, authorization relationship, etc., and obtain the joint authentication result; the operator credential is dynamically generated, has a validity period, and can be updated regularly; the dynamic key can correspond to an operator one-to-one, or can be shared by all operators. The unmanned aerial vehicle control device returns a UUAA request response to the unmanned aerial vehicle, carrying the authentication result.
[0088] Figure 4 FIG. 1 is a flow chart of joint control in some embodiments of the unmanned aerial vehicle authentication method according to the present disclosure, such asFigure 4 as shown in:
[0089] Step S401, when the first authentication is successful and the second authentication is successful, establish an association relationship between the unmanned aerial vehicle identification information and the license information.
[0090] Step S402, perform joint control on the unmanned aerial vehicle and the control device corresponding to the operator according to the association relationship.
[0091] After passing the first authentication and the second authentication, the unmanned aerial vehicle management and control device associates the unmanned aerial vehicle identification information with the operator's license information, and performs joint control on the unmanned aerial vehicle and the control device corresponding to the operator according to the management and control requirements. For example, when the unmanned aerial vehicle exhibits non-compliant behavior, in addition to issuing commands to control the unmanned aerial vehicle, the unmanned aerial vehicle management and control device can also hold the control platform and the operator accountable. For example, it can disconnect the network connection of the control device corresponding to the operator, cancel the operator's license qualification, etc.
[0092] The UUAA process of the unmanned aerial vehicle can be completely decoupled from the signaling process of the communication network. The network only provides a connection channel between the unmanned aerial vehicle and the USS, and the authentication is fully executed at the application layer. The communication network can support the embedding of the UUAA process into its own process, which can effectively prevent illegal access in a timely manner or better protect network resources.
[0093] The UUAA process embedded in the communication network includes UUAA-MM and UUAA-SM; UUAA-MM is the UUAA executed when registering in the communication network according to the operator's policy; if required by the operator, when there is UAV-related UE subscription in the UAV access and mobile subscription data and the CAA-level UAV ID is provided in the registration request message, UUAA-MM is executed. If UUAA-MM is not executed, then during the PDU session establishment process of the UAS service, UUAA-SM is executed to authenticate the UAV.
[0094] In some embodiments, during the process of the unmanned aerial vehicle registering to the communication system, the unmanned aerial vehicle management and control device receives an authentication request sent by the unmanned aerial vehicle system network function or the network exposure function; wherein, the unmanned aerial vehicle sends an authentication request to the security and authentication proxy function, and the security and authentication proxy function forwards the authentication request to the unmanned aerial vehicle system network function or the network exposure function.
[0095] The unmanned aerial vehicle management and control device sends an authentication response to the unmanned aerial vehicle system network function or the network exposure function; wherein, the unmanned aerial vehicle system network function or the network exposure function sends an authentication response to the security and authentication proxy function, and the security and authentication proxy function forwards the authentication response to the unmanned aerial vehicle.
[0096] The security and authentication proxy function can be applied to multiple network elements, such as the AMF (Access and Mobility Management Function); the AMF is a network element in the control plane of the 5G core network, mainly responsible for various functions including registration management, connection management, access management, mobility management, and functions related to security, access management, and authorization.
[0097] Figure 5 It is a schematic diagram of the authentication process when a drone registers to a communication system in some embodiments of the authentication method for drones according to the present disclosure, as Figure 5 shown below:
[0098] Step 500, the drone (UE) sends a registration message to the network, and this message is first sent to the AMF.
[0099] The information carried in the registration message includes GPSI (Global Positioning System Identifier), CAA-class UAV ID (drone identification information), operator credentials, etc.
[0100] Step S501, the AMF triggers the execution of UUAA.
[0101] For drones (UEs) that need to perform UUAA, the AMF triggers the UUAA-MM process.
[0102] Step S502, the AMF invokes the Nnef_Authentication_AuthenticateAuthorize Request message, and the information carried in this message can include GPSI, CAA-class UAV ID, operator credentials, etc. The drone system network function UAS-NF (Network Function) should store the AMF ID providing the service.
[0103] Step S503, the UAS-NF sends the Naf_Authentication_AuthenticateAuthorizeRequest message to the USS / UTM, and the information carried in this message can include GPSI, CAA-class UAV ID, operator credentials, etc. The drone control device includes the USS and / or UTM.
[0104] Step S504a, the USS / UTM sends a Naf_Authentication_AuthenticateAuthorizeReponse message to the UAS-NF. The information carried in this message may include GPSI, indication of information to be supplemented, etc.
[0105] Whether information for supplementary interaction is required depends on the specific authentication algorithm. There may be multiple interactions or no interaction. If no interaction is required, steps S504a - S504f do not need to be executed. The indication of information to be supplemented may include intermediate processing results of a preset algorithm, and the returned supplemented information may include results of further calculations for authentication use.
[0106] Step S504b, the UAS-NF sends a Nnef_Authentication_AuthenticateAuthorizeReponse message to the AMF. The information carried in this message may include GPSI, indication of information to be supplemented, etc.
[0107] Step S504c, the AMF sends a NAS MM Transport message to the unmanned aerial vehicle (UE). The information carried in this message may include indication of information to be supplemented, etc.
[0108] Step S504d, the unmanned aerial vehicle (UE) sends a NAS MM Transport message to the AMF. The information carried in this message may include supplemented information, etc.
[0109] Step S504e, the AMF sends a Nnef_Authentication_AuthenticateAuthorizeRequest message to the UAS-NF. The information carried in this message may include GPSI, supplemented information, etc.
[0110] Step S504f, the UAS-NF sends a Naf_Authentication_AuthenticateAuthorizeRequest message to the USS / UTM. The information carried in this message may include GPSI, supplemented information, etc.
[0111] Step S505, the USS / UTM performs joint authentication to obtain the joint authentication result.
[0112] The USS / UTM, while performing the first authentication of the unmanned aerial vehicle based on the unmanned aerial vehicle identification information, decrypts the operator's credentials to obtain license information, and performs the second authentication of the operator based on the operator's credentials to obtain the joint authentication result.
[0113] Step S506, the USS / UTM sends a Naf_Authentication_AuthenticateAuthorizeResponse message to the UAS-NF. The information carried in this message may include GPSI, CAA-level UAV ID, operator credentials, authentication results, etc.
[0114] The authentication result includes a combined authentication result of a first authentication of the unmanned aerial vehicle based on the CAA-level UAV ID and a second authentication of the operator of the unmanned aerial vehicle based on the operator credentials. This message may also carry an indication related to the authentication result. For example, it indicates whether network resources related to the UAS service can be released in case of UUAA failure.
[0115] Step S507, the UAS-NF sends a Nnef_Authentication_AuthenticateAuthorizeResponse message to the AMF. The information carried in this message may include GPSI, CAA-level UAV ID, operator credentials, authentication results, etc.
[0116] Step S508a, if the authentication is successful and the UAS-NF has not subscribed to the mobility events of the AMF before, the UAS-NF sends a Namf_EventExposure_Subscribe message with a subscription association ID to subscribe to the AMF to obtain mobile event notifications.
[0117] Step S508b, if the authentication fails and the UAS-NF has subscribed to the AMF to obtain mobility event notifications before, the UAS-NF requests to cancel the subscription by sending a Namf_EventExposure_Unsubscribe message with a subscription association ID.
[0118] Step S509a, the AMF confirms the subscription request in Step S508a by sending a Namf_EventExposure_SubscribeResponse with a subscription association ID.
[0119] Step S509b, the AMF confirms the unsubscribe request in Step S508b by sending a Namf_EventExposure_Unsubscribe Response.
[0120] Step S510, the AMF sends a NAS MM Transport message to the unmanned aerial vehicle (UE). The information carried in this message includes the authentication result (success / failure), etc.
[0121] Step S511, if the UUAA-MM is successful, the AMF will trigger a UE configuration update process and transmit various authorization information to the UAV.
[0122] Step S512, if the UUAA-MM authentication fails, and there is a PDU session established using the UAS service, and the USS has indicated that the network resources can be released, the AMF may trigger the release of the PDU session.
[0123] In some embodiments, during the process of the unmanned aerial vehicle requesting to establish a session connection, the unmanned aerial vehicle management and control device receives an authentication request sent by the unmanned aerial vehicle system network function or the network exposure function; wherein, the unmanned aerial vehicle sends an authentication request to the connection management function, and the connection management function forwards the authentication request to the unmanned aerial vehicle system network function or the network exposure function.
[0124] The unmanned aerial vehicle management and control device sends an authentication response to the unmanned aerial vehicle system network function; wherein, the unmanned aerial vehicle system network function or the network exposure function sends an authentication response to the connection management function, and the connection management function forwards the authentication response to the unmanned aerial vehicle.
[0125] The connection management function can be multiple network elements, such as an SMF (Session Management Function); the SMF is a network element in the control plane of the 5G core network, controls the session establishment of the UE, manages the session, and stores the session context of the UE to control the user plane forwarding path of the terminal.
[0126] The scenario of UUAA-SM can be: when the unmanned aerial vehicle requests to establish a PDU session / PDN connection, the PDU session / PDN connection requires the UUAA authorization of the unmanned aerial vehicle. The UUAA-SM process can be triggered by the SMF, and the authentication is based on the SM subscription data obtained from the UDM and the CAA-level UAV ID provided by the unmanned aerial vehicle in the PDU session establishment request.
[0127] Figure 6 It is a schematic diagram of the authentication process when the unmanned aerial vehicle requests to establish a session connection in some embodiments of the authentication method for the unmanned aerial vehicle according to the present disclosure, as Figure 6 shown:
[0128] Step S600, the PDU session establishment request process.
[0129] The unmanned aerial vehicle (UE) passes network authentication and requests to establish a PDU session for the UAS service. The information carried in the request includes the CAA-level UAV ID of the unmanned aerial vehicle, operator credentials, etc., and may also include the USS address and optional authentication information data.
[0130] Step S601, the SMF sends an Nnef_Authentication_AuthenticateAuthorizeRequest message to the UAS-NF / NEF.
[0131] The SMF determines that the DNN / S-NSSAI combination in the request sent by the unmanned aerial vehicle is dedicated to air services, and the request contains a CAA-level UAV ID, and determines that UUAA-SM is required. The SMF sends an Nnef_Authentication_AuthenticateAuthorize message, and the information carried in this message includes the CAA-level UAV ID, operator credentials, GPSI, location, etc. sent by the unmanned aerial vehicle, and may also include the PEI and UE IP address.
[0132] Step S602, the UAS NF / NEF sends an Naf_Authentication_AuthenticateAuthorize message to the USS, forwarding the authentication request message received from the SMF.
[0133] The NEF (Network Exposure Function) is a network element in the control plane of the 5G core network, which performs the gateway function of opening up network capabilities, providing functions such as authorization for capability invocation, parameter adaptation, and security isolation; the NEF can act as a UAS NF, supporting air functions related to UAV identification, authentication / authorization, and tracking, and supporting remote identification.
[0134] Step S603a, the USS sends an Naf_Authentication_AuthenticateAuthorizeReponse message to the UAS NF / NEF.
[0135] Step S603b, the UAS NF / NEF sends an Nnef_Authentication_AuthenticateAuthorize Reponse message to the SMF.
[0136] Step S603c, the SMF sends a Namf Communicatio-N1N2MessageTransfer message to the AMF.
[0137] Step S604d, the AMF sends a NAS MM Transport message to the unmanned aerial vehicle (UE), and the information carried in this message may include authentication information, etc.
[0138] Step S603e, the unmanned aerial vehicle (UE) sends a NAS MM Transport message to the AMF, and the information carried by this message may include authentication information, etc.
[0139] Step S603f, the AMF sends an NSmf_PDUSession_UpdataSM context message to the SMF.
[0140] Step S603g, the SMF sends an Nnef_Authentication_AuthenticateAuthorize Request message to the UAS NF / NEF, and the information carried by this message may include GPSI, CAA-level UAV ID, operator credentials, authentication information, etc.
[0141] Step S603h, the UAS NF / NEF sends an Naf_Authentication_AuthenticateAuthorizeRequest message to the USS, and the information carried by this message may include GPSI, CAA-level UAV ID, operator credentials, authentication information, etc.
[0142] Step S604, the USS performs joint authentication to obtain a joint authentication result.
[0143] While the USS performs the first authentication on the unmanned aerial vehicle according to the unmanned aerial vehicle identification information, it decrypts the operator credentials to obtain license information, and performs the second authentication on the operator based on the operator credentials to obtain a joint authentication result.
[0144] Step S605, the USS sends an Naf_Authentication_AuthenticateAuthorizeResponse message to the UAS NF / NEF, and the information carried by this message may include GPSI, CAA-level UAV ID, operator credentials, authentication result, etc.
[0145] The authentication result includes the joint authentication result of the first authentication of the unmanned aerial vehicle according to the CAA-level UAV ID and the second authentication of the operator of the unmanned aerial vehicle according to the operator credentials; this message may also carry an indication related to the authentication result. For example, it indicates whether the network resources related to the UAS service can be released in the case of UUAA failure. If the joint authentication fails, the drone cannot establish a connection session, including the connections to the controller / console and the USS; if the authentication is successful, the USS subscribes to the PDU session status event.
[0146] Step S606, the UAS NF / NEF sends an Nnef_Authentication_AuthenticateAuthorizeResponse message to the SMF. The information carried in this message may include GPSI, CAA-level UAV ID, operator credentials, authentication results, etc.
[0147] Step S607, subscribe to the PDU session status event.
[0148] Step S608, issue PDU session-related policies.
[0149] Step S609, report the PDU session establishment event.
[0150] Figure 7 It is a schematic diagram of the application layer authentication process in some embodiments of the authentication method for an unmanned aerial vehicle according to the present disclosure, as Figure 7 shown:
[0151] Step S700, the UAV operating enterprise assigns a CAA-level UAV ID to the UAV, and pre-sets the management and control platform password MC (the first password) and the UAV initial password VC0 (the second password) in the unmanned aerial vehicle.
[0152] The unmanned aerial vehicle may be a UAV, and the unmanned aerial vehicle management and control device may be a UAV management and control device. The UAV operating enterprise synchronizes the UAV ID, VC0 and its characteristic information to the UAV management and control device; when the UAV starts, it first needs to establish a connection with the operator / controller and obtain the operator credentials. Before the UAV obtains the operator credentials, steps S701 - S703b are performed:
[0153] Step S701, the operator / controller logs in to the operator registration center.
[0154] Step S702, the operator registration center calculates the operator license ID according to the dynamic key to generate the operator credentials. The operator registration center can encrypt and calculate the operator license ID according to the dynamic key and using a variety of encryption algorithms to obtain the operator credentials.
[0155] Step S703a, the operator registration center returns the operator credentials to the operator.
[0156] Step S703b, the operator registration center synchronizes the operator license information, operator credentials and OC (dynamic key) to the UAV management and control device. Starting from step S704 is the authentication process:
[0157] Step S704, the UAV and the controller discover each other and establish an initial connection.
[0158] Step S705, the operator provides the operator credentials to the UAV through the controller.
[0159] Step S706, the UAV processes the UAV ID, operator credentials, etc. using VC0 to form verification information (the first verification information), and encrypts the authentication information including the UAV ID, operator credentials, verification information, etc. using MC.
[0160] Step S707, the UAV sends an authentication request (carrying the encrypted authentication information).
[0161] Step S708, the UAV control device decrypts the authentication information using MC, verifies the verification information using VC0, obtains the UAV ID and operator credentials, and authenticates the UAV.
[0162] Step S709, the UAV control platform verifies the credentials using OC, obtains the operator's license information, and verifies the validity of the license.
[0163] Step S710, the UAV control platform matches the UAV feature information and the operator license information. If the match is successful, the joint authentication is passed.
[0164] Step S711, the UAV control platform generates VC1 based on VC0, processes the UAV ID, VC1 (the third key), etc. using MC to form verification information (the second verification information), and encrypts the authentication response using VC0.
[0165] Step S712, the UAV control platform returns an authentication response to the UAV. The authentication response includes the encrypted authentication information, including the authentication result information, UAV ID, VC1, and verification information, etc.
[0166] Step S713, the UAV decrypts the authentication response using VC0, verifies the verification information using MC, obtains the authentication result and VC1, and VC1 is used for subsequent communication interactions.
[0167] Step S714, if the authentication is passed and the previous initial connection cannot be used for control signaling transmission, the UAV triggers the establishment of a control connection with the controller to carry the control signaling of the controller.
[0168] The operator registration center generates operator credentials through dynamic keys and updates them regularly or irregularly; the unmanned aerial vehicle and the unmanned aerial vehicle control device use key pairs to encrypt the interaction information respectively for secure information transmission, and this key can also be a dynamic key and is updated regularly or irregularly.
[0169] The authentication method for an unmanned aerial vehicle in the above embodiments can perform joint authentication on the unmanned aerial vehicle and the operator, supervise the operator of the unmanned aerial vehicle, clarify the responsibility attribution for abnormal flight control behaviors of the unmanned aerial vehicle, improve the flight safety of the unmanned aerial vehicle, standardize the flight control of low-altitude economic unmanned aerial vehicles and their related responsibilities, and contribute to the development of the low-altitude industry.
[0170] Figure 8 FIG. is a schematic flowchart of some other embodiments of the authentication method for an unmanned aerial vehicle according to the present disclosure, which is applied to an unmanned aerial vehicle, as Figure 8 shown:
[0171] Step S801: Send an authentication request to the unmanned aerial vehicle control device. The authentication information carried in the authentication request includes unmanned aerial vehicle identification information and an operator credential.
[0172] Step S802: Receive an authentication response sent by the unmanned aerial vehicle control device. The authentication response carries authentication result information obtained by the unmanned aerial vehicle control device through a first authentication based on the unmanned aerial vehicle identification information and a second authentication based on the operator credential.
[0173] In the case where both the first authentication and the second authentication are successful, the unmanned aerial vehicle establishes a control connection with the control device.
[0174] In some embodiments, before sending the authentication request, the unmanned aerial vehicle establishes an initial connection with the operator's control device and receives the operator credential sent by the control device. The control device receives the operator credential sent by the operator registration center. The operator registration center encrypts the operator's license information according to a dynamic key to generate the operator credential.
[0175] The unmanned aerial vehicle uses a second key to generate a first verification information corresponding to the unmanned aerial vehicle identification information and the operator credential. The unmanned aerial vehicle uses a first key to encrypt the first verification information corresponding to the unmanned aerial vehicle identification information and the operator credential to generate encrypted authentication information.
[0176] The unmanned aerial vehicle decrypts the authentication response using the second key to obtain the authentication result information and a second verification information. The unmanned aerial vehicle verifies the second verification information using the first key. When the second verification information passes the verification, the unmanned aerial vehicle determines that the authentication result information is valid.
[0177] In some embodiments, during the process of registering to a communication system, an unmanned aerial vehicle (UAV) sends an authentication request to a security and authentication proxy function. The security and authentication proxy function forwards the authentication request to a UAV system network function or a network exposure function, and the UAV system network function or the network exposure function sends the authentication request to a UAV control device.
[0178] The UAV receives an authentication response sent by the security and authentication proxy function. The UAV control device sends the authentication response to the UAV system network function or the network exposure function, and the UAV system network function or the network exposure function sends the authentication response to the security and authentication proxy function.
[0179] During the process of requesting to establish a session connection, the UAV sends an authentication request to a connection management function. The connection management function forwards the authentication request to the UAV system network function or the network exposure function, and the UAV system network function or the network exposure function sends the authentication request to the UAV control device.
[0180] The UAV receives an authentication response sent by the connection management function. The UAV control device sends the authentication response to the UAV system network function or the network exposure function, and the UAV system network function or the network exposure function sends the authentication response to the connection management function.
[0181] In some embodiments, as Figure 9 shown, the present disclosure provides a UAV control device 90, including a first receiving module 901, a joint authentication module 902, and a first sending module 903.
[0182] The first receiving module 901 receives an authentication request sent by the UAV. The authentication information carried in the authentication request includes UAV identification information and operator credentials. The joint authentication module 902 performs a first authentication on the UAV according to the UAV identification information, and performs a second authentication on the operator of the UAV according to the operator credentials. The first sending module 903 sends an authentication response to the UAV, and the authentication response carries authentication result information of the first authentication and the second authentication.
[0183] In some embodiments, the joint authentication module 902 obtains license information of the operator according to the operator credentials. The joint authentication module 902 performs the second authentication on the operator according to the license information. The second authentication includes one or more of the following: verifying the validity of the license information, verifying whether the license information matches the type of the UAV, verifying whether the license information has the authorization to operate the UAV, etc.
[0184] The joint authentication module 902 obtains the dynamic key corresponding to the operator credential; the joint authentication module 902 uses the dynamic key to decrypt the operator credential to obtain the license information.
[0185] The joint authentication module 902 receives the operator credential and the dynamic key sent by the operator registration center, and establishes a corresponding relationship between the operator credential and the dynamic key.
[0186] The joint authentication module 902 uses the first key to decrypt the encrypted authentication information to obtain the unmanned aerial vehicle identification information, the operator credential, and the first verification information; the joint authentication module 902 uses the second key to verify the first verification information; when the first verification information passes the verification, the joint authentication module 902 determines that the unmanned aerial vehicle identification information and the operator credential are valid.
[0187] The joint authentication module 902 uses the first key to generate the second verification information corresponding to the authentication result information; the joint authentication module 902 uses the second key to encrypt the authentication result information and the second verification information to generate the encrypted authentication response.
[0188] When the first authentication is successful and the second authentication is successful, the joint authentication module 902 adds a third key to the authentication result information, where after the first authentication is successful and the second authentication is successful, the unmanned aerial vehicle uses the third key to process the information interacting with the unmanned aerial vehicle control device.
[0189] When the first authentication is successful and the second authentication is successful, the joint authentication module 902 establishes an association relationship between the unmanned aerial vehicle identification information and the license information; the joint authentication module 902 performs joint control on the unmanned aerial vehicle and the control device corresponding to the operator according to the association relationship.
[0190] In some embodiments, during the process of the unmanned aerial vehicle registering to the communication system, the first receiving module 901 receives the authentication request sent by the unmanned aerial vehicle system network function or the network exposure function; wherein, the unmanned aerial vehicle sends the authentication request to the security and authentication proxy function, and the security and authentication proxy function forwards the authentication request to the unmanned aerial vehicle system network function or the network exposure function.
[0191] The first sending module 903 sends the authentication response to the UAV system network function or the network openness function; wherein, the UAV system network function or the network openness function sends the authentication response to the security and authentication proxy function, and the security and authentication proxy function forwards the authentication response to the unmanned aerial vehicle.
[0192] During the process of the unmanned aerial vehicle requesting to establish a session connection, the first receiving module 901 receives the authentication request sent by the UAV system network function or the network openness function; wherein, the unmanned aerial vehicle sends the authentication request to the connection management function, and the connection management function forwards the authentication request to the UAV system network function or the network openness function.
[0193] The first sending module 903 sends the authentication response to the UAV system network function; wherein, the UAV system network function or the network openness function sends the authentication response to the connection management function, and the connection management function forwards the authentication response to the unmanned aerial vehicle.
[0194] In some embodiments, as Figure 10 shown, the unmanned aerial vehicle control device may include a memory 1001, a processor 1002, a communication interface 1003, and a bus 1004. The memory 1001 is used to store instructions. The processor 1002 is coupled to the memory 1001, and the processor 1002 is configured to execute the authentication method of the unmanned aerial vehicle applied to the unmanned aerial vehicle control device based on the instructions stored in the memory 1001.
[0195] The memory 1001 may be a high-speed RAM memory, a non-volatile memory, etc. The memory 1001 may also be a memory array. The memory 1001 may also be partitioned, and the partitions may be combined into virtual volumes according to certain rules. The processor 1002 may be a central processing unit CPU, or an application specific integrated circuit ASIC (Application Specific Integrated Circuit), or one or more integrated circuits configured to implement the authentication method of the unmanned aerial vehicle applied to the unmanned aerial vehicle control device of the present disclosure.
[0196] In some embodiments, as Figure 11As shown in the figure, the present disclosure provides an unmanned aerial vehicle 110, including a second sending module 1101 and a second receiving module 1102. The second sending module 1101 sends an authentication request to the unmanned aerial vehicle control device, wherein the authentication information carried in the authentication request includes unmanned aerial vehicle identification information and operator credentials; the second receiving module 1102 receives the authentication response sent by the unmanned aerial vehicle control device; wherein, the authentication response carries the authentication result information of the unmanned aerial vehicle control device for performing a first authentication based on the unmanned aerial vehicle identification information and a second authentication based on the operator credentials.
[0197] As Figure 11 shown in the figure, the unmanned aerial vehicle 110 further includes an authentication processing module 1103. Before sending the authentication request, the authentication processing module 1103 establishes an initial connection with the control device of the operator and receives the operator credentials sent by the control device. The control device receives the operator credentials sent by the operator registration center; wherein, the operator registration center encrypts the operator's license information based on a dynamic key to generate the operator credentials.
[0198] The authentication processing module 1103 uses the second key to generate a first verification information corresponding to the unmanned aerial vehicle identification information and the operator credentials; the authentication processing module 1103 uses the first key to encrypt the first verification information corresponding to the unmanned aerial vehicle identification information and the operator credentials to generate the encrypted authentication information.
[0199] The authentication processing module 1103 decrypts the authentication response using the second key to obtain the authentication result information and the second verification information; the authentication processing module 1103 performs a verification process on the second verification information using the first key; the authentication processing module 1103 determines that the authentication result information is valid when the second verification information passes the verification. The authentication processing module 1103 establishes a control connection with the control device when the first authentication is successful and the second authentication is successful.
[0200] In some embodiments, during the process of registering to the communication system, the second sending module 1101 sends the authentication request to the security and authentication proxy function; wherein, the security and authentication proxy function forwards the authentication request to the unmanned aerial vehicle system network function or the network openness function, and the unmanned aerial vehicle system network function or the network openness function sends the authentication request to the unmanned aerial vehicle control device.
[0201] The second receiving module 1102 receives the authentication response sent by the security and authentication proxy function; wherein, the unmanned aerial vehicle control device sends the authentication response to the unmanned aerial vehicle system network function or the network opening function, and the unmanned aerial vehicle system network function or the network opening function sends the authentication response to the security and authentication proxy function.
[0202] During the process of requesting to establish a session connection, the second sending module 1101 sends the authentication request to the connection management function; wherein, the connection management function forwards the authentication request to the unmanned aerial vehicle system network function or the network opening function, and the unmanned aerial vehicle system network function or the network opening function sends the authentication request to the unmanned aerial vehicle control device.
[0203] The second receiving module 1102 receives the authentication response sent by the connection management function; wherein, the unmanned aerial vehicle control device sends the authentication response to the unmanned aerial vehicle system network function or the network opening function, and the unmanned aerial vehicle system network function or the network opening function sends the authentication response to the connection management function.
[0204] In some embodiments, as Figure 12 shown, the unmanned aerial vehicle may include a memory 1201, a processor 1202, a communication interface 1203, and a bus 1204. The memory 1201 is used to store instructions, the processor 1202 is coupled to the memory 1201, and the processor 1202 is configured to execute the authentication method for the unmanned aerial vehicle applied to the unmanned aerial vehicle based on the instructions stored in the memory 1201.
[0205] The memory 1201 may be a high-speed RAM memory, a non-volatile memory, etc., and the memory 1201 may also be a memory array. The memory 1201 may also be partitioned, and the partitions may be combined into virtual volumes according to certain rules. The processor 1202 may be a central processing unit CPU, or an application specific integrated circuit ASIC (Application Specific Integrated Circuit), or one or more integrated circuits configured to implement the authentication method for the unmanned aerial vehicle applied to the unmanned aerial vehicle of the present disclosure.
[0206] In some embodiments, the present disclosure provides an unmanned aerial vehicle system, including: an unmanned aerial vehicle control device according to any one of the above embodiments, and an unmanned aerial vehicle according to any one of the above embodiments.
[0207] In some embodiments, the present disclosure provides a computer-readable storage medium storing computer instructions that, when executed by a processor, implement the methods in any of the foregoing embodiments.
[0208] The computer-readable storage medium may be any combination of one or more readable media. The readable media may be a readable signal medium or a readable storage medium. The readable storage medium may include, for example, but is not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the foregoing. More specific examples (non-exhaustive list) of the readable storage medium may include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0209] Embodiments of the present disclosure may also be computer program products that include computer program instructions that, when run by a processor, cause the processor to execute the steps in the methods according to various embodiments of the present disclosure described in the "Exemplary Methods" section above of this specification.
[0210] The basic principles of the present disclosure have been described above in conjunction with specific embodiments. However, it should be noted that the advantages, benefits, effects, etc. mentioned in the present disclosure are only examples and not limitations, and it cannot be considered that these advantages, benefits, effects, etc. are essential for each embodiment of the present disclosure. Additionally, the specific details disclosed above are only for illustrative and easy-to-understand purposes and not limitations, and the above details do not limit the present disclosure to necessarily implement using the above specific details.
[0211] Each embodiment in this specification is described in a progressive manner, with each embodiment focusing on the differences from other embodiments. For the same or similar parts between the embodiments, reference may be made to each other. For system embodiments, since they basically correspond to method embodiments, they are described relatively simply, and reference may be made to the relevant parts of the method embodiments for the related content.
[0212] The block diagrams of the devices, apparatuses, equipment, and systems involved in this disclosure are merely illustrative examples and are not intended to require or imply that they must be connected, arranged, and configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, equipment, and systems can be connected, arranged, and configured in any manner. Words such as "including," "comprising," "having," etc. are open-ended terms, meaning "including but not limited to," and can be used interchangeably with each other. The word "or" and "and" used herein refer to the phrase "and / or" and can be used interchangeably with it, unless the context clearly indicates otherwise. The phrase "such as" used herein refers to the phrase "such as but not limited to" and can be used interchangeably with it.
[0213] It should also be noted that in the devices, equipment, and methods of this disclosure, each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent solutions of this disclosure.
[0214] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use this disclosure. Various modifications to these aspects are very obvious to those skilled in the art, and the general principles defined herein can be applied to other aspects without departing from the scope of this disclosure. Therefore, this disclosure is not intended to be limited to the aspects shown herein, but rather to the broadest scope consistent with the principles and novel features disclosed herein.
[0215] The above description has been given for purposes of illustration and description. In addition, this description is not intended to limit the embodiments of this disclosure to the forms disclosed herein. Although multiple example aspects and embodiments have been discussed above, those skilled in the art should understand that the above embodiments are merely illustrative and do not limit the scope of this disclosure. Those skilled in the art should understand that the above embodiments can be combined, modified, or replaced without departing from the scope and essence of this disclosure.
Claims
1. An unmanned aerial vehicle authentication method, applied to an unmanned aerial vehicle control device, comprising: Receiving an authentication request sent by an unmanned aerial vehicle, wherein the authentication information carried in the authentication request includes unmanned aerial vehicle identification information and operator credentials; Performing a first authentication on the unmanned aerial vehicle according to the unmanned aerial vehicle identification information, and performing a second authentication on the operator of the unmanned aerial vehicle according to the operator credential; An authentication response is sent to the unmanned aerial vehicle, wherein the authentication response carries authentication result information of the first authentication and the second authentication.
2. The method of claim 1, wherein: The second authentication of the operator of the unmanned aerial vehicle according to the operator credential includes: obtaining the operator's license information according to the operator's credential; The second authentication is performed on the operator based on the license information.
3. The method of claim 2, wherein: The second authentication includes at least one of the following: Verify the validity of the license information, verify whether the license information matches the type of the unmanned aerial vehicle, and verify whether the license information has authorization to operate the unmanned aerial vehicle.
4. The method of claim 2, wherein: The obtaining the operator's license information according to the operator's credential includes: obtaining a dynamic key corresponding to the operator credential; The operator credential is decrypted using the dynamic key to obtain the license information.
5. The method of claim 4, comprising: Receiving the operator credential and the dynamic key sent by the operator registration center; A correspondence between the operator credential and the dynamic key is established.
6. The method of claim 1, comprising: Decrypting the encrypted authentication information using the first key to obtain the unmanned aerial vehicle identification information, the operator credential and the first verification information; Using a second key to verify the first verification information; In a case where the first verification information passes verification, it is determined that the unmanned aerial vehicle identification information and the operator credentials are valid.
7. The method of claim 6, comprising: Using the first key, generating second verification information corresponding to the authentication result information; The authentication result information and the second verification information are encrypted using the second key to generate the encrypted authentication response.
8. The method of claim 1, comprising: During the process of registering the unmanned aerial vehicle with the communication system, receiving the authentication request sent by the network function or the network open function of the unmanned aerial vehicle system; wherein the unmanned aerial vehicle sends the authentication request to the security and authentication proxy function, and the security and authentication proxy function forwards the authentication request to the unmanned aerial vehicle system network function or the network open function; Sending the authentication response to the UAV system network function or the network open function; The drone system network function or the network open function sends the authentication response to the security and authentication proxy function, and the security and authentication proxy function forwards the authentication response to the unmanned aerial vehicle.
9. The method of claim 1, comprising: In the process of the unmanned aerial vehicle requesting to establish a session connection, receiving the authentication request sent by the unmanned aerial vehicle system network function or the network open function; wherein the unmanned aerial vehicle sends the authentication request to a connection management function, and the connection management function forwards the authentication request to the unmanned aerial vehicle system network function or the network opening function; sending the authentication response to the UAV system network function; The drone system network function or the network open function sends the authentication response to the connection management function, and the connection management function forwards the authentication response to the unmanned aerial vehicle.
10. The method of claim 1, further comprising: In the case where the first authentication is successful and the second authentication is successful, a third key is added to the authentication result information, wherein after the first authentication is successful and the second authentication is successful, the unmanned aerial vehicle uses the third key to process information interacting with the unmanned aerial vehicle control device.
11. The method according to any one of claims 2 to 10, further comprising: In case the first authentication is successful and the second authentication is successful, establishing an association relationship between the unmanned aerial vehicle identification information and the license information; The unmanned aerial vehicle and the control device corresponding to the operator are jointly controlled according to the association relationship.
12. An authentication method for an unmanned aerial vehicle, applied to the unmanned aerial vehicle, comprising: Sending an authentication request to the unmanned aerial vehicle control device, wherein the authentication information carried in the authentication request includes the unmanned aerial vehicle identification information and the operator credentials; Receiving an authentication response sent by the unmanned aerial vehicle control device; Among them, the authentication response carries authentication result information that the unmanned aerial vehicle control device performs a first authentication based on the unmanned aerial vehicle identification information and performs a second authentication based on the operator credentials.
13. The method of claim 12, comprising: Before sending the authentication request, establishing an initial connection with the operator's control device; The operator credential sent by the control device is received.
14. The method of claim 13, comprising: The control device receives the operator credential sent by the operator registration center; The operator registration center encrypts the operator's license information according to the dynamic key to generate the operator credential.
15. The method of claim 13, comprising: using the second key, generating first verification information corresponding to the unmanned aerial vehicle identification information and the operator credential; The first key is used to encrypt the unmanned aerial vehicle identification information and the first verification information corresponding to the operator credential to generate the encrypted authentication information.
16. The method of claim 13, comprising: Decrypting the authentication response using a second key to obtain the authentication result information and second verification information; Using the first key to perform verification processing on the second verification information; When the second verification information passes the verification, it is determined that the authentication result information is valid.
17. The method of claim 12, comprising: sending said authentication request to the security and authentication proxy function during registration to the communication system; wherein the security and authentication proxy function forwards the authentication request to the drone system network function or the network open function, and the drone system network function or the network open function sends the authentication request to the unmanned aerial vehicle control device; receiving the authentication response sent by the security and authentication proxy function; Among them, the unmanned aerial vehicle control device sends the authentication response to the unmanned aerial vehicle system network function or the network open function, and the unmanned aerial vehicle system network function or the network open function sends the authentication response to the security and authentication proxy function.
18. The method of claim 12, comprising: In the process of requesting to establish a session connection, sending the authentication request to the connection management function; wherein the connection management function forwards the authentication request to the drone system network function or the network open function, and the drone system network function or the network open function sends the authentication request to the unmanned aerial vehicle control device; receiving the authentication response sent by the connection management function; Among them, the unmanned aerial vehicle control device sends the authentication response to the drone system network function or the network open function, and the drone system network function or the network open function sends the authentication response to the connection management function.
19. The method according to any one of claims 13 to 18, comprising: When the first authentication is successful and the second authentication is successful, a control connection with the control device is established.
20. An unmanned aerial vehicle control device, comprising: A first receiving module, configured to receive an authentication request sent by an unmanned aerial vehicle, wherein the authentication information carried in the authentication request includes the unmanned aerial vehicle identification information and the operator credentials; a joint authentication module, configured to perform a first authentication on the unmanned aerial vehicle according to the unmanned aerial vehicle identification information, and to perform a second authentication on the operator of the unmanned aerial vehicle according to the operator credential; The first sending module is used to send an authentication response to the unmanned aerial vehicle, wherein the authentication response carries authentication result information of the first authentication and the second authentication.
21. An unmanned aerial vehicle control device, comprising: Memory; and a processor coupled to the memory, wherein the processor is configured to execute the unmanned aerial vehicle authentication method according to any one of claims 1 to 11 based on instructions stored in the memory.
22. An unmanned aerial vehicle comprising: A second sending module, configured to send an authentication request to the unmanned aerial vehicle control device, wherein the authentication information carried in the authentication request includes the unmanned aerial vehicle identification information and the operator credentials; A second receiving module, used to receive an authentication response sent by the unmanned aerial vehicle control device; Among them, the authentication response carries authentication result information that the unmanned aerial vehicle control device performs a first authentication based on the unmanned aerial vehicle identification information and performs a second authentication based on the operator credentials.
23. An unmanned aerial vehicle, comprising: Memory; and a processor coupled to the memory, wherein the processor is configured to execute the unmanned aerial vehicle authentication method according to any one of claims 12 to 19 based on instructions stored in the memory.
24. An unmanned aerial vehicle system comprising: An unmanned aerial vehicle control device as described in claim 20 or 21, and an unmanned aerial vehicle as described in claim 22 or 23.
25. A computer-readable storage medium storing computer instructions, wherein the computer instructions are executed by a processor to perform the method according to any one of claims 1 to 19.
26. A computer program product, wherein the computer program product stores computer instructions, wherein the computer instructions are executed by a processor to perform the method according to any one of claims 1 to 19.