A Trusted Identity Management System and Method for Unmanned Aerial Vehicles

Through the combination of dynamic trust scores and Merkel tree structure, the problems of single point failure and inefficient management in the communication system of the drone cluster are solved, and efficient and secure identity management of the drone cluster in complex mission environments are achieved.

CN120150968BActive Publication Date: 2025-07-25CIVIL AVIATION FLIGHT UNIV OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510619992.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-14
Publication Date
2025-07-25
Estimated Expiration
2045-05-14

AI Technical Summary

Technical Problem

Traditional drone cluster communication systems rely on centralized management of ground stations, and have a single point of failure risk, making it difficult to cope with complex and changeable task environments, affecting the real-time and security of task execution.

Method used

The dynamic trust scoring mechanism and Merkel tree structure are adopted, combining the historical performance and real-time information of the nodes, the trust score is dynamically adjusted, the local Merkel tree is built for authentication, and the dynamic rotation of the cluster head nodes is performed after the task cycle is over.

Benefits of technology

It improves the real-time and security of drone clusters in complex mission environments, reduces the risk of network failure, enhances the flexibility and robustness of the system, and reduces the management burden of ground stations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120150968B_ABST
    Figure CN120150968B_ABST
Patent Text Reader

Abstract

The present invention discloses a trusted identity management system and method for drones based on trust scoring and Merkle tree structure, which relates to the identity management of drones. The purpose of the present invention is to specifically provide a trusted identity management system and method for drones in view of the identity verification and trust evaluation scenarios in a dynamic environment. Based on the existing trust scoring mechanism technology, improvements are made in the method. Based on dynamic trust scoring and Merkle tree structure, and considering the influence of node behavior changes in the cooperation of drone groups, the historical performance and real-time information of nodes are comprehensively considered in the identity management process, reducing the risk of network paralysis caused by single-point failures, and providing a safe and efficient identity management method adapted to complex task environments.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the identity management of unmanned aerial vehicles (UAVs), and particularly to a trusted identity management system and method for UAVs based on trust scores and Merkle tree structures. Background Art

[0002] With the rapid development of UAV technology, network communication based on UAVs has gradually become an important application mode. However, traditional UAV cluster communication systems often rely on ground stations for centralized management and control. Although this centralized management mode improves the overall controllability and coordination of the system, it also has obvious defects and room for improvement.

[0003] Firstly, centralized management leads to the risk of single point of failure. As the core node of the communication system, once the ground station is attacked or fails, it may cause the interruption and paralysis of the entire network, seriously affecting the smooth progress of the mission. This management method relying on a single central point significantly increases the vulnerability of the system when facing attacks. Secondly, traditional identity management and trust evaluation mechanisms are difficult to cope with the networking environment with a large number of nodes and complex structures under a centralized architecture. The system is difficult to reflect the dynamic performance of each node in real time and accurately, resulting in malicious nodes that may hide in the system, posing a threat to the security of communication. In addition, the ground station needs to monitor all nodes in real time and simultaneously handle issues such as path planning, data processing, and task allocation, resulting in an overly heavy management burden and reduced operation efficiency. In a complex and changeable mission environment, this mode severely restricts the combat effectiveness and response speed of UAV clusters.

[0004] In UAV network communication, although the centralized management mode improves the overall controllability and coordination of the system, in fact, due to the single-point dependence on the ground station, it is difficult to achieve efficient and flexible management. During the mission execution, the potential single point of failure will inevitably pose a risk of network paralysis, which makes the stability of the system vulnerable to a certain extent. In the mission execution scenario, the vulnerability will seriously affect the overall performance of the system.

[0005] In a complex mission environment scenario, if the ground station fails or is attacked, it will have a serious negative impact on the coordinated operation of the UAV group, thus affecting the response speed, flexibility, and security of the system, and even possibly affecting the successful progress of the entire mission. Therefore, ensuring the reliability design of the communication network is very important. Summary of the Invention

[0006] The purpose of the present invention is to overcome the deficiencies of the prior art and provide a trusted identity management system and method for unmanned aerial vehicles. The technical problem to be solved is that traditional identity management systems mainly rely on centralized management and control of ground stations for unmanned aerial vehicle cluster communication, which has a large error in dynamic and complex unmanned aerial vehicle networking communication scenarios, and may affect the real-time performance and security of mission execution, especially in scenarios of emergency response and complex cooperative operations.

[0007] The purpose of the present invention is to specifically provide a trusted identity management system and method for unmanned aerial vehicles in the scenario of identity verification and trust evaluation in a dynamic environment. Based on the existing trust scoring mechanism technology, improvements are made in the method. Based on dynamic trust scoring and Merkle tree structure, and considering the impact of node behavior changes in the cooperation of unmanned aerial vehicle groups, the historical performance and real-time information of nodes are comprehensively considered in the identity management process, reducing the risk of network paralysis caused by single-point failures, and providing a secure and efficient identity management method adapted to complex task environments.

[0008] The purpose of the present invention is mainly achieved through the following technical solutions:

[0009] The present invention is a trusted identity management system for unmanned aerial vehicles, and the system includes: a model initialization module, a dynamic trust scoring module, a Merkle tree dynamic verification and update module, and a cluster head identity update module;

[0010] Before the unmanned aerial vehicles execute tasks, the model initialization module completes the preparations for identity verification and trust evaluation of the unmanned aerial vehicle cluster. The preparations include: first, setting the task time, defining the trust level, and assigning identity identifiers to each node of the unmanned aerial vehicle cluster; on this basis, the ground station randomly designates the cluster head unmanned aerial vehicle, the secondary cluster head unmanned aerial vehicle, and the member unmanned aerial vehicles, and finally constructs an initial Merkle tree according to the identity information of each node, and the identity information of each node is used as the leaf node data of the Merkle tree;

[0011] After the node identity assignment is completed, the cluster head node uses the dynamic trust scoring module to perform trust scoring on the task performance of all unmanned aerial vehicles;

[0012] During the task execution cycle of the unmanned aerial vehicles, the dynamic trust scoring module combines the dynamic scoring adjustment mechanism to calculate the working trust score and energy trust score of each node to obtain a comprehensive trust score. The comprehensive trust score is used for the trust evaluation of each node, and finally, based on the comprehensive trust score, the trust score level assessment and node task performance analysis are realized;

[0013] After the mission cycle of the UAVs ends, a trust threshold mechanism is adopted to generate dynamic trust score thresholds and trust level evaluation criteria for each UAV node within the current mission cycle. The trust score thresholds are used to evaluate the trust levels of the UAV nodes according to the set thresholds;

[0014] After all node trust scores are calculated, the cluster head node identity and the trust levels of all member nodes will be updated by combining the Merkle tree dynamic verification and update module and the cluster head identity update module;

[0015] The Merkle tree dynamic verification and update module includes a Merkle tree construction unit and a Merkle tree verification unit; the Merkle tree construction unit calculates the hash value of each member node according to the member node identity information, and then recursively calculates the root hash within each cluster and stores it in the cluster head node. Finally, the cluster head node generates and maintains a local Merkle tree within the cluster; the Merkle tree verification unit is used by the cluster head UAV to verify the integrity of the identity information and trust scores of the member nodes within the cluster;

[0016] The trust score and trust level of the cluster head are dynamically updated after the mission cycle of the UAVs ends. If the comprehensive trust score of the cluster head is lower than the threshold, the cluster head identity update module is activated to select the secondary cluster head node as the new cluster head node, and the member node with the highest trust score within the cluster is selected as the new secondary cluster head node.

[0017] The present invention also includes a trusted identity management method for UAVs, which can be applied to the above system. The specific steps are as follows:

[0018] Step S1: At the initial stage of the mission, the ground station randomly assigns the cluster head UAVs, secondary cluster head UAVs, and member UAVs in the hierarchical network;

[0019] Step S2: After the mission cycle ends, the trust scores are evaluated based on the task performance of each node, the trust levels of the nodes are dynamically updated, and finally, it is determined whether to elect a new cluster head node and update the trusted levels of the nodes;

[0020] Step S3: To ensure the security and credibility of the node identities and trust scores, the Merkle tree structure is used to store the identity information; the cluster head node is responsible for managing and verifying the identity information of its own cluster, constructing a local Merkle tree, and dynamically updating the Merkle tree root hash value according to the node trust scores;

[0021] Step S4: The cluster head node regularly submits a local trust score table to the ground station, and the ground station combines this with its own trust score of the cluster head node to generate a global trust score table, thereby realizing the identity management of the UAV cluster.

[0022] To further optimize the above technical solution, the dynamic trust scoring module uses a dynamic scoring adjustment mechanism to calculate the trust scores;

[0023] The working trust score is based on the interaction performance between UAV nodes, including the task participation frequency, historical task completion rate, and verification failure rate. Denote the working trust score as , and calculate the working trust score of each node through a dynamic scoring adjustment mechanism. The specific calculation formula is as follows:

[0024]

[0025] Among them, is the task participation frequency, is the corresponding weight of the task participation frequency; is the historical task completion rate, is the corresponding weight of the historical task completion rate; is the verification failure rate, is the corresponding weight of the verification failure rate;

[0026] The energy trust score is based on the remaining battery level and total battery of the node. Denote the energy trust score as , and its calculation formula is as follows:

[0027]

[0028] Among them, is the remaining battery of the node; is the total battery of the node;

[0029] The comprehensive trust score is calculated through the working trust score and energy trust score. Denote the comprehensive trust score as Generate the final comprehensive score according to the working performance and energy status, which is used as the trust evaluation standard for cluster head nodes. The calculation formula is as follows:

[0030]

[0031] Among them, is the working trust score; is the energy trust score;

[0032] is the time decay factor, which controls the time decay speed of the score and prevents the influence of historical scores from being too large. is the time;

[0033] On this basis, introduce a trust threshold mechanism, set a trust threshold, and define a scoring standard;

[0034] After the end of the task cycle, each cluster head node forms a dynamic trust score threshold within its respective cluster for subsequent trust level evaluation. The calculation formula is as follows:

[0035]

[0036] Among them, is the dynamically calculated trust score threshold for the cluster in the current cycle, applicable to all nodes within the cluster; is the average trust score of all member nodes within the cluster in the current cycle; is the standard deviation of the trust score; is the trust score adjustment factor;

[0037] The evaluation of the node trust level is as follows:

[0038] When it is a high-trust node L1: continue to work and have the opportunity to become a new cluster head or sub-cluster head node, participating in task management;

[0039] When it is a medium-trust node L2: maintain the current working state, continue to participate in tasks, and need to strengthen the monitoring of its performance;

[0040] When and the trust path proof verification is successful, it is a low-trust node L3: marked as an observed object, its tasks are suspended, waiting for further evaluation to decide whether to resume normal work;

[0041] When and the trust path proof verification fails, it is an L4 untrusted node: immediately isolated from the communication environment, stop all its tasks, notify the ground station for interception and handling, and the node identity will be uploaded to the ground station for further analysis;

[0042] In the trust evaluation criteria, the selection of the member node trust level follows: after the task cycle ends, the trust score of a qualified member node should be higher than , and its trust level should be higher than the medium-trust level standard of L2, and the original cluster head node verifies its identity information as qualified.

[0043] To further optimize the above technical solution, the Merkle tree construction unit specifically includes:

[0044] The identity information of each member node will be used as the input data of the leaf node. The identity information includes node ID, cluster number Ci (i = 1, 2, 3,...), task role, trust score, denoted as , where there are a total of N nodes. Calculate the hash value for the identity data of each node. For each node data D j (j ∈ (1, N)), generate the hash value H(Dj) of the leaf node through an encryption-secure hash function: H(Dj) = SHA-256(Dj);

[0045] Recursively operate on the hash values of leaf nodes to obtain a recursive hash. The hash values of adjacent leaf nodes H(D1) and H(D2) are combined and then hashed again to generate the hash value of the intermediate node. Recursively proceed until finally generating a unique root hash H[root(Ci)]. The root hash is stored in the cluster head node and periodically backed up to the secondary cluster head and the ground station.

[0046] Manage the UAV cluster in a hierarchical manner. Divide the entire cluster into several sub-clusters. Build an independent Merkle tree within each sub-cluster, called a local Merkle tree. The cluster head node of each sub-cluster serves as the main maintainer second only to the ground station, maintaining the root hash H[root(Ci)] of its own subtree. The main cluster head, that is, the ground station, is responsible for maintaining the global root hash H(global-root) and generating the global Merkle tree by combining the root hash values of all clusters.

[0047] To further optimize the above technical solution, the Merkle tree verification unit is used to verify the integrity of the identity information and trust scores of the member nodes within the cluster. During the task execution process, the cluster head ensures the integrity of the identity data and trust scores by verifying the Merkle tree path. The verification path is a process of confirming whether the data is complete and not tampered with by comparing the complete root hash value stored in the given cluster head or secondary cluster head node with the hash value of the node to be verified layer by layer in the corresponding Merkle tree. If the data of this leaf node, that is, the member node, is tampered with, then the complete path hash value from this node to the cluster head node will not correspond to the root hash value stored in the cluster head node.

[0048] Verification when a new node joins:

[0049] When a new node joins, it will completely replace the old UAV node that can no longer work in the original cluster structure to achieve the succession of task information. The cluster head will also perform a partial verification path, and the partial verification path is to verify the hash path of the new node. The cluster head verifies the identity information and trust score of the node through the partial verification path of the local Merkle tree where it is located to ensure consistency with the existing Merkle tree data.

[0050] To further optimize the above technical solution, the cluster head identity update module performs a cluster head trust score on the cluster head after each task cycle. If the score is lower than the threshold, the cluster head rotation mechanism is activated;

[0051] The cluster head trust score is the same as the trust score content of the member nodes, but the scoring rules are more stringent. At the end of the task cycle, the trust score of the cluster head must be higher than the minimum cluster head trust score , and the specific formula is as follows:

[0052] ;

[0053] where is the lowest cluster head trust threshold, and its value is higher than the average scoring standard of ordinary nodes;

[0054] is the dynamic trust scoring threshold calculated and generated for the cluster where it is located during the current period, and is applicable to all nodes within the cluster;

[0055] is the standard deviation of the trust scores within the cluster, which is used to ensure that the trust level of the cluster head is more stable than that of ordinary nodes;

[0056] The trust score of the cluster head must be dynamically updated after the end of the task cycle. When the comprehensive trust score of the cluster head is lower than the set threshold during the task execution , it is necessary to immediately initiate the cluster head rotation mechanism, and the cluster head rotation mechanism includes:

[0057] The sub-cluster head automatically takes over the functions of the cluster head and succeeds to the task status and Merkle tree data within the current cluster;

[0058] The member node with the highest trust score ranking within the cluster becomes the new sub-cluster head.

[0059] To further optimize the above technical solution, the cluster head identity update module further includes a cluster head failure handling mechanism. During the task execution, it will monitor the trust score and energy level of the cluster head node in real time. When the cluster head node has too low energy, communication failure, or a sudden drop in the trust score, the failure handling mechanism will be immediately triggered;

[0060] The situation of too low energy means that the remaining energy is lower than 30%;

[0061] The communication failure means that the cluster head cannot communicate normally with the nodes within the cluster;

[0062] The sudden drop in the trust score means that the comprehensive trust score of the cluster head drops below ;

[0063] The failure handling mechanism is that when the cluster head fails, the sub-cluster head quickly takes over its responsibilities.

[0064] To further optimize the above technical solution, the cluster head identity update module further includes a sub-cluster head backup and replacement mechanism. The sub-cluster head plays a backup role in the overall cluster management and quickly takes over the responsibilities of the cluster head when it fails; the sub-cluster head is responsible for sharing some of the tasks of the cluster head and backing up the key information within the cluster;

[0065] To prevent the cluster head node from failing due to overloading or insufficient energy, a load balancing mechanism is introduced. The load balancing mechanism is that when the remaining energy of the cluster head is lower than 30%, some of the tasks of the cluster head are transferred to the sub-cluster head node to ensure that the cluster head does not fail due to overloading or insufficient energy;

[0066] When the trust score of the cluster head is lower than or the cluster head fails, the system will automatically select a secondary cluster head node to take over the functions of the cluster head, which is called the secondary cluster head succession; after the secondary cluster head succession, a new secondary cluster head is selected from the nodes with the highest trust score within the cluster.

[0067] The model initialization module specifically includes:

[0068] Set the task time, set the total task time as T, and divide T into t time periods;

[0069] Define the trust levels, define 4 trust levels, namely L4 untrusted nodes, low trust nodes L3, medium trust nodes L2, and high trust nodes L1, expressed as L4 < L3 < L2 < L1;

[0070] Assign identity identifiers to each node of the UAV cluster. The ground station assigns a unique identity identifier to each node Di, including the task role and the initial position. Nodes that join midway must apply to the ground station for the identity identifier and the Merkle tree verification path of the corresponding group;

[0071] Randomly assign cluster heads and secondary cluster heads to the nodes. In the initialization stage, all cluster head and secondary cluster head identities are randomly assigned by the ground station; the cluster head is responsible for in-cluster identity verification and trust score calculation, and the secondary cluster head acts as a backup node and a load balancing node, taking over its functions when the cluster head fails and its efficiency is insufficient;

[0072] According to the identity information of each node, generate leaf node hash values through a hash function, and then recursively generate the root node, finally forming the Merkle tree structure within the cluster, constructing the initial Merkle tree. The cluster head node is responsible for storing the root hash value and regularly passing it to the secondary cluster head for backup.

[0073] The working principle of this solution:

[0074] Regarding the problems of the real-time performance and security of task execution in traditional identity management systems, the trust score mechanism, as a technology for quantifying the credibility of nodes, has gradually received attention. Through the analysis and evaluation of the historical behaviors of nodes, the trust score can dynamically reflect the performance of nodes in the network, effectively improving the real-time performance and flexibility of the system. Adopting the trust score mechanism can promote cooperation among nodes, enhance the security and robustness of the system, and provide strong support for distributed identity management.

[0075] To further ensure the security of node identities and trust data, the present invention introduces a Merkle tree structure. A Merkle tree is a hierarchical data structure widely used in fields such as blockchain, distributed storage, and authentication, which can effectively guarantee the integrity and consistency of data. Its basic composition is as follows: each leaf node stores a piece of data, including the identity information and trust score of the node, and generates a unique hash value through a hash function; the hash value of each parent node is generated by combining the hash values of its child nodes; the root node represents the integrity of the entire tree. When the data of any leaf node changes, the hash values of its corresponding parent node and root node will also change, thereby enabling rapid detection of data tampering behavior.

[0076] In the solution of the present invention, the Merkle tree structure is used to store and verify the identity information of nodes; the cluster head node generates and maintains a local Merkle tree within the cluster, is responsible for verifying the identity information of its member nodes, and regularly submits a local trust score table to the ground station; the ground station generates a global trust score based on the data submitted by the cluster head node, thereby ensuring the security and efficiency of the entire network identity management; adopting the Merkle tree structure can significantly improve the credibility of identity management, and when a malicious node is discovered, quickly isolate its potential threat to the network.

[0077] In summary, the present invention has the following beneficial effects compared with the prior art:

[0078] 1. Dynamic trust scoring mechanism: Compared with the prior art, the present invention proposes a dynamic trust scoring mechanism based on the performance of nodes within a task cycle. This mechanism adjusts the trust score of nodes in real time according to multiple dimensions such as the work participation frequency, task success rate, and energy consumption of nodes in each task cycle, and calculates a comprehensive trust score in combination with the historical performance of nodes to ensure the dynamics and flexibility of the scoring.

[0079] 2. Identity authentication based on Merkle tree and guarantee of scoring integrity: By introducing the Merkle tree structure, the present invention encrypts and records the identity identifiers and trust scores of UAV nodes to ensure that the data cannot be tampered with. The identity information of each node serves as a leaf node of the Merkle tree, and the root hash value is generated through recursive hash calculation for subsequent node identity authentication and integrity verification of trust scores in tasks.

[0080] 3. Dynamic cluster head rotation mechanism: The present invention proposes a dynamic cluster head rotation mechanism based on trust scores. During the task cycle, the system dynamically adjusts the cluster head node according to the trust scores of each node, ensuring that the selection of the cluster head node is based on the latest task performance, avoiding a single node occupying the cluster head role for a long time, thereby preventing potential security threats or low efficiency in task execution. Brief Description of the Drawings

[0081] The accompanying drawings described herein are used to provide a further understanding of the embodiments of the present invention, form a part of this application, and do not limit the embodiments of the present invention. In the drawings:

[0082] Figure 1 is a flowchart of the system execution of a trusted identity management system for drones according to the present invention;

[0083] Figure 2 is a flowchart of the trust level update of a trusted identity management system for drones according to the present invention. Detailed implementation manners

[0084] To make the objectives, technical solutions, and advantages of the present invention clearer and more understandable, the present invention will be further described in detail below in combination with embodiments and the accompanying drawings. The illustrative embodiments of the present invention and their descriptions are only used to explain the present invention and do not limit the present invention.

[0085] Traditional identity management systems mainly rely on centralized management and control of ground stations for drone cluster communication. There are significant errors in applying them to dynamic and complex drone networking communication scenarios, which may affect the real-time performance and security of task execution, especially in scenarios such as emergency response and complex cooperative operations. In view of this, the present invention provides the following embodiments to solve the above technical problems.

[0086] In specific embodiment 1:

[0087] A trusted identity management system for drones is as Figure 1 shown, including: a model initialization module, a dynamic trust scoring module, a Merkle tree dynamic verification and update module, and a cluster head identity update module.

[0088] Before the drones execute tasks, the model initialization module prepares for identity verification and trust evaluation in the drone cluster. The preparation work includes: first setting the task time, defining the trust level, and assigning identity identifiers to each node in the drone cluster; on this basis, the ground station randomly assigns cluster head drones, sub-cluster head drones, and member drones, and finally constructs an initial Merkle tree according to the identity information of each node, and the identity information of each node is used as the leaf node calculation value of the Merkle tree.

[0089] After the node identity assignment is completed, the cluster head node uses the dynamic trust scoring module to perform trust scoring on the task performance of all member drones.

[0090] The dynamic trust scoring module adopts a dynamic scoring adjustment mechanism and a trust threshold mechanism.

[0091] During the mission cycle of the UAV, the dynamic scoring adjustment mechanism calculates the work trust score and energy trust score of each node to obtain the comprehensive trust score, which is used for the trust evaluation of each node. Finally, based on the comprehensive trust score, the trust score level assessment and node task performance analysis are realized.

[0092] After the mission cycle of the UAV ends, the trust threshold mechanism will generate dynamic trust score thresholds and trust level evaluation criteria for each UAV node in the current mission cycle. The trust score threshold is used to evaluate the trust level of the UAV node according to the set threshold.

[0093] The trust scoring mechanism, as a technology for quantifying the credibility of nodes, has gradually received attention. By analyzing and evaluating the historical behavior of nodes, the trust score can dynamically reflect the performance of nodes in the network, effectively improving the real-time performance and flexibility of the system. Adopting the trust scoring mechanism can promote cooperation among nodes, enhance the security and robustness of the system, and provide strong support for distributed identity management.

[0094] After all node trust scores are calculated, the Merkle tree dynamic verification update module and the cluster head identity update module will be combined to update the identity of the cluster head node and the trust levels of all member nodes.

[0095] The Merkle tree dynamic verification update module includes a Merkle tree construction unit and a Merkle tree verification unit. The Merkle tree construction unit calculates the hash value of each node based on the prepared node identity information, recursively calculates the root hash within each cluster, stores it in the cluster head node, and the cluster head node generates and maintains the local Merkle tree within the cluster. The Merkle tree verification unit is used by the cluster head UAV to verify the identity information and trust score integrity of the member nodes within the cluster.

[0096] To further ensure the security of node identities and trust data, the Merkle tree (Merkle-Tree) structure is introduced. The Merkle tree is a hierarchical data structure widely used in blockchain, distributed storage, and authentication, etc., which can effectively guarantee the integrity and consistency of data. Its basic composition is: each leaf node stores a piece of data (such as the identity information of the node) and generates a unique hash value through a hash function; the hash value of each parent node is generated by combining the hash values of its child nodes; the root node represents the integrity of the entire tree. When the data of any leaf node changes, the hash values of its corresponding parent node and root node will also change, so that data tampering behavior can be quickly detected.

[0097] The trust score of the cluster head is dynamically updated after the mission cycle of the UAV ends. If the comprehensive trust score of the cluster head is lower than the threshold, the cluster head identity update module is activated to replace the cluster head with the sub-cluster head, and the node with the highest trust score within the cluster becomes the new sub-cluster head.

[0098] The Merkle tree structure is used to store and verify the identity information of nodes. The cluster head node generates and maintains a local Merkle tree within the cluster, is responsible for verifying the identity information of its member nodes, and regularly submits a local trust score table to the ground station. The ground station generates a global trust score based on the data submitted by the cluster head node, thereby ensuring the security and efficiency of the entire network identity management. Adopting the Merkle tree structure can significantly improve the credibility of identity management, and when a malicious node is detected, quickly isolate its potential threat to the network.

[0099] The present invention also includes a trusted identity management method for unmanned aerial vehicles. This method can be applied to the above system, and the specific steps are as follows:

[0100] Step S1: At the initial stage of the task, the ground station randomly assigns the cluster head UAV, sub-cluster head UAV, and member UAVs in the hierarchical network;

[0101] Step S2: After the task cycle ends, evaluate the trust score according to the task performance of each node, dynamically update the node trust level, and finally determine whether to elect a new cluster head node and update the node trust level;

[0102] Step S3: To ensure the security and credibility of the node identity and trust score, use the Merkle tree structure to store the identity information; the cluster head node is responsible for managing and verifying the identity information of its own cluster, constructing a local Merkle tree, and dynamically updating the Merkle root hash value according to the node trust score;

[0103] Step S4: The cluster head node regularly submits a local trust score table to the ground station. The ground station combines this with its own trust score for the cluster head node to generate a global trust score table, realizing the identity management of the UAV cluster. And through distributed management, the management burden of the ground station is reduced, thereby improving the identity management efficiency of the UAV network.

[0104] First, before the task starts, the model initialization module prepares for the identity authentication and trust evaluation of the UAV cluster, specifically including:

[0105] Set the task time, set the total task time as T, and the unit of time is minutes, hours, etc. Divide T into t time periods; the length of each period is adjusted according to the task complexity. For example, each period of the sub-cluster head backup and replacement mechanism can be 10 minutes, or it can be fine-tuned according to the real-time requirements of the task.

[0106] Define the trust levels, define 4 trust levels, namely untrusted, low trust, medium trust, and high trust, expressed as L4 < L3 < L2 < L1.

[0107] The ground control station assigns a unique identity to each node Di of the UAV cluster, including the mission role and the initial position. Nodes that join midway must apply to the GCS for a new identity and the historical Merkle tree path hash value of the node to be replaced.

[0108] In the initialization phase, all cluster heads and sub-cluster heads are randomly assigned by the ground control station; the cluster head is responsible for in-cluster authentication and trust score calculation, and the sub-cluster head acts as a backup node and a load balancing node, taking over its functions when the cluster head fails or is insufficient in efficiency.

[0109] Based on the identity information of each node, the leaf node hash value is generated through a hash function, and then the root node is generated recursively, finally forming the Merkle tree structure within the cluster to construct the initial Merkle tree. The cluster head node is responsible for storing the root hash value and regularly passing it to the sub-cluster head for backup.

[0110] The hash algorithm, namely the transliteration of the hashing algorithm, Hash-algorithm. Generally speaking, its basic function is to generate a fixed-length string through certain calculations for any length of input, and the output string becomes the hash value of the input. Currently, the algorithms that have been proposed and widely used include the Message Digest (MD) series and the Secure Hash Algorithm (SHA) series.

[0111] The hash algorithm should possess characteristics such as forward speed, input sensitivity, reverse difficulty, and strong collision resistance. It is these characteristics that make the hash algorithm particularly suitable for flight plan verification.

[0112] Among them, forward speed means that for given data, the corresponding hash value can be quickly calculated. Therefore, it is very fast to calculate the hash value of each flight plan, and the calculation overhead is small.

[0113] Input sensitivity means that even if there is any slight change in the input information, the hash value will be very different from the original hash value, making it easy to detect any errors in the flight plan.

[0114] Reverse difficulty means that it is very difficult to calculate the input value based on the hash value, which can ensure the confidentiality of flight plan verification.

[0115] Strong collision resistance means that it is very difficult for different inputs to generate the same hash output, ensuring the uniqueness of the hash value of each flight plan.

[0116] The characteristics of the hash algorithm determine its unique role in the process of simplifying, identifying, hiding, and verifying information, and the security performance of the algorithm is guaranteed.

[0117] For example Figure 2 , during the mission execution process, the dynamic trust score module and the Merkle tree dynamic verification and update module start working simultaneously. When the UAV cluster is numbered by clusters, the mission execution begins.

[0118] The dynamic trust scoring module calculates the trust score by using the dynamic scoring adjustment mechanism.

[0119] The work trust score is based on the interaction performance between UAV nodes, including the task participation frequency, historical task completion rate, and verification failure rate. Denote the work trust score as , and calculate the work trust score of each node through the dynamic scoring adjustment mechanism. The specific calculation formula is as follows:

[0120]

[0121] where is the task participation frequency, is the corresponding weight of the task participation frequency; is the historical task completion rate, is the corresponding weight of the historical task completion rate; is the verification failure rate, is the corresponding weight of the verification failure rate. In this embodiment, the value of the corresponding weight is .

[0122] The energy trust score is based on the remaining battery level and total battery capacity of the node. Denote the energy trust score as , and its calculation formula is as follows:

[0123]

[0124] where is the remaining battery level of the node; is the total battery capacity of the node.

[0125] Calculate the comprehensive trust score through the work trust score and energy trust score. Denote the comprehensive trust score as , generate the final comprehensive score according to the work performance and energy state, and use it as the trust evaluation standard for the cluster head node. The calculation formula is as follows:

[0126]

[0127] where is the work trust score; is the energy trust score.

[0128] is the time decay factor, which controls the time decay speed of the score and prevents the influence of historical scores from being too large. is the time.

[0129] In the design of this embodiment, introduce the time decay factor To control the time decay rate of the comprehensive trust score, thus avoiding the excessive influence of historical scores on the current trust score level. The main purpose of the decay factor is to adjust the time weight of the score, making the influence level of the trust score in the latest mission cycle of the UAV higher, while the influence of long-term missions gradually decreases.

[0130] Time decay factor The value range and rationality are closely related to the actual operation scenario. The specific value is set according to requirements such as actual application needs, the time cycle of UAV mission execution, and the response speed of the trust level. Decay factor The value range is:

[0131] : No decay, the influence of historical scores on the current trust level remains unchanged, applicable to the initial trust scoring stage.

[0132] : There is a decay effect. As the value increases, the decay rate of the trust score accelerates, and the influence of historical scores gradually decreases.

[0133] The specific confirmation method during implementation:

[0134] First, divide the mission cycle, and then fine-tune the decay factor.

[0135] The ground station is the global management center for trust scores and trust levels. The ground station is responsible for dividing the mission cycle. In the present invention, the value of the time decay factor decreases as the mission time increases.

[0136] For example, divide the mission cycle into 20%, 50%, and 90% stages, corresponding to the first 2 minutes, 5 minutes, and the first 9 minutes of the mission cycle (taking the mission cycle as 10 minutes as an example). Since in the 20% stage of the mission cycle, the UAV needs to quickly respond to mission requirements, set the value to 0.8. When the mission reaches half of the specified cycle and the UAV continues to execute, at this time the trust score gradually tends to be stable, and the decay factor needs to be further reduced. At this time, the value is set to 0.5. When the mission reaches the 90% stage, approaching the end of the cycle and the stable stage of the trust score result, the decay factor will be selected as 0.1 to ensure that the influence of historical scores on the trust level gradually decreases.

[0137] Then introduce the trust threshold mechanism, set the trust threshold, and define the scoring criteria.

[0138] After the mission cycle ends, each cluster head node forms a dynamic trust score threshold within its respective cluster for subsequent trust level evaluation. The calculation formula is as follows:

[0139]

[0140] Among them, is the dynamically generated trust score threshold for the cluster in the current period, which is applicable to all nodes within the cluster. This threshold is used to perform trust scoring on all nodes within the cluster in the current period, including the cluster head node and member nodes. is the average trust score of all member nodes within the cluster in the current period; is the standard deviation of the trust score; is the trust score adjustment factor, which can be flexibly adjusted according to the actual task requirements of the system.

[0141] Trust score adjustment factor The main function is to adjust the trust score threshold according to the distribution of trust scores of all nodes in the current period, so as to realize the flexible evaluation of the trust level of UAVs. When the distribution of trust scores is relatively concentrated and it is impossible to distinguish obvious trust levels, by lowering the value to reduce the influence of the standard deviation; while when the distribution of trust scores is relatively dispersed, the value can be appropriately increased to facilitate the quantitative grading of trust scores.

[0142] Trust score adjustment factor The value range needs to be determined according to the actual application requirements. The value should meet the following requirements:

[0143] Lower limit: When , the trust score threshold only depends on the average trust score, and the standard deviation has no influence on the threshold. This situation only applies to the case where the distribution of trust scores is relatively concentrated, the task requires quick response, and the initial stage.

[0144] Upper limit: The closer the value is to 1, the more obvious the influence of the standard deviation on the trust score threshold can be enhanced, which is convenient for separating trust levels.

[0145] The lower the value, the lower the trust threshold, and more nodes may be classified as high trust level (L1). This situation is applicable to the loose management scenario. When

[0146] The specific confirmation method during the implementation process:

[0147] After the comprehensive trust score calculation is completed, analyze the distribution of the trust scores. Assuming that the trust scores among nodes are relatively concentrated within the current cycle at this time, it means that the difference in trust scores among nodes is small and the trust levels cannot be effectively distinguished. Then, the parameter values will be determined according to the number of nodes.

[0148] For example, when the number of nodes is small (20 or less), the difference in trust scores is not obvious, and is selected to make the scoring result more lenient. Most of the member nodes' identities are high-trust nodes L1 and will continue to work. When the number of nodes is large (more than 20), then or close to 1, and the distribution difference of the node trust scores is large, and the trust levels will be more clearly distinguished.

[0149] The exact values of the above parameters need to be flexibly set according to the actual task during the specific implementation stage.

[0150] The specific evaluation of the node trust level is as follows:

[0151] L1 High-trust node : Continue to work and have the opportunity to become a new cluster head or sub-cluster head node and participate in task management.

[0152] L2 Medium-trust node : Maintain the current working state, continue to participate in tasks, and the monitoring of its performance needs to be strengthened.

[0153] L3 Low-trust node And the trust path proof verification is successful: Marked as an observation object, its task is suspended, waiting for further evaluation to decide whether to resume normal work.

[0154] L4 Un-trustworthy node And the trust path proof verification fails: Immediately isolate it from the communication environment, stop all its tasks, notify the ground station to intercept and process it, and the node identity will be uploaded to the ground station for further analysis.

[0155] In the trust evaluation criteria, the selection of the member node trust level follows: After the task cycle ends, the trust score of a qualified member node should be higher than , and its trust level should be higher than the L2 medium-trust level standard, and the original cluster head verifies the Merkle tree hash path for it and it is qualified.

[0156] And during the task execution, the Merkle tree dynamic verification and update module works simultaneously.

[0157] The construction of the Merkle tree in the Merkle tree dynamic verification and update module specifically includes:

[0158] Data Preparation: The identity information of each node will be used as the input data for the leaf nodes. The identity information includes the node ID, cluster number Ci (i = 1, 2, 3, …), task role, trust score, etc. Denote the identity information of each node as , where there are a total of N nodes. After compression, these data generate hash values of a fixed length to reduce the data volume of the leaf nodes.

[0159] Perform hash calculation on each node. The data of each node Dj (j ∈ (1, N)) passes through an encryption-secure hash function. In this embodiment, the SHA-256 hash algorithm is used to generate the hash value of the leaf node H(Dj): H(Dj) = SHA-256(Dj).

[0160] Perform recursive operations on the hash values of the leaf nodes to obtain recursive hashes. The adjacent leaf node hash values H(D1) and H(D2) are combined and then hashed again to generate the hash value of the intermediate node; this is done recursively until finally generating a unique root hash H[root(Ci)]. The root hash is stored in the cluster head node and periodically backed up to the secondary cluster head and the ground station.

[0161] In a large-scale cluster, dividing the entire cluster into several sub-clusters and performing hierarchical management can make the data organizational structure clear. Each layer has its clear responsibilities, which is convenient for independent maintenance and improves efficiency. The UAV cluster in this embodiment is also a large-scale cluster, so the UAV cluster is hierarchically managed. The entire cluster is divided into several sub-clusters, and an independent Merkle tree, called the local Merkle tree of the cluster head node, is constructed within each sub-cluster to maintain the root hash H[root(Ci)] of the subtree; the main cluster head, that is, the ground station, is responsible for maintaining the global root hash H(global-root), which is the Merkle tree of all sub-cluster root hashes.

[0162] A Merkle tree is a tree-shaped data structure, usually in the form of a binary tree, which contains a set of nodes. Among them, the tree root containing basic information has a large number of leaf nodes; each intermediate node is the hash value of its two child nodes; the root node of the tree is also formed by two child nodes.

[0163] Taking 4 nodes, that is, 4 UAVs performing tasks, as an example, a Figure 2 Merkle tree can be constructed.

[0164] The characteristic of the Merkle tree recording data layer by layer makes it sensitive to data modification. Therefore, it can quickly compare a large amount of data and locate the modification of data blocks.

[0165] Quickly compare a large amount of data. A slight change in the leaf node data will cause the root node to change. The root node can be used to determine whether the data has been modified.

[0166] Quickly locate the modification of data blocks. For example, if the data corresponding to a leaf node is modified, the data block that actually changed can be located by simply calculating from the root node to the leaf node.

[0167] The Merkle tree verification unit in the Merkle tree dynamic verification update module is used to verify the identity information and trust score integrity of the nodes in the cluster. When the node joins and during the task execution, the cluster head and sub-cluster head ensure the integrity of the data by verifying the path. Path verification is the process of confirming whether the data is complete and has not been tampered with by comparing the storage value of a given cluster head or sub-cluster head with the hash value of the node corresponding to its position in the Merkle tree. When there is now a node that is determined to be complete, based on the data of this node and its hash value, as well as the complete Merkle tree, it can be calculated layer by layer along the path from the root to the leaf node. If the hash value of the node's data matches the hash value of the specified position in the tree, then it can be confirmed that this data was added when the original tree was built and maintained integrity.

[0168] Verification when a new node joins now:

[0169] When a new node joins, the cluster head performs a partial verification path. The partial verification path is the hash path to verify the new node. The cluster head verifies the identity information and trust score of the node through the partial verification path of the local Merkle tree to ensure consistency with the existing Merkle tree data.

[0170] Trust Level Verification:

[0171] Based on the trust score of the node , divide the nodes into different trust levels and adopt different levels of verification measures:

[0172] L1 High Trust Node : Only simplified identity verification is performed to verify that their identity hash is valid, without the need for frequent full Merkle tree path verification.

[0173] Trusted Nodes in L2 : Some key paths need to be verified through cluster heads or ground stations to reduce unnecessary calculations while ensuring data integrity.

[0174] L3 Low Trust Node : A complete trust path proof must be provided, which includes its identity information and historical data of the trust score to ensure that the data has not been tampered with; if the verification fails, it may be downgraded to L4.

[0175] L4 Untrusted Node If the trust path proof verification fails: the untrusted node will be isolated from the communication environment and the ground station will be notified for interception; the identity information of the node will be uploaded to the ground station for further analysis to prevent potential security threats.

[0176] After each task cycle ends, the cluster head identity update module conducts a cluster head trust score evaluation on the cluster head. If the score is lower than the threshold, the cluster head rotation mechanism is initiated.

[0177] To ensure that the selected cluster head nodes have sufficient capabilities in terms of reliability, stability, and resources, the cluster head trust score should have stricter criteria than ordinary nodes. The cluster head trust score is consistent with the trust score content of member nodes, but the scoring rules are more stringent. At the end of the task cycle, the trust score of the cluster head must be higher than the minimum cluster head trust score. , and the specific formula is as follows:

[0178]

[0179] where is the minimum cluster head trust threshold, and its value is higher than the average scoring standard of ordinary nodes;

[0180] is the dynamically generated trust score threshold calculated for the cluster during the current cycle, applicable to all nodes within the cluster;

[0181] is the standard deviation of the trust scores within the cluster, used to ensure that the trust level of the cluster head is more stable than that of ordinary nodes.

[0182] The trust score of the cluster head must be updated dynamically after the task cycle ends. When the comprehensive trust score of the cluster head is lower than the set threshold during task execution , the cluster head rotation mechanism needs to be initiated immediately. The cluster head rotation mechanism includes:

[0183] The sub-cluster head automatically takes over the cluster head function and succeeds to the task status and Merkle tree data within the current cluster.

[0184] The member node with the highest trust score ranking within the cluster becomes the new sub-cluster head.

[0185] The cluster head identity update module also includes a cluster head failure handling mechanism. During task execution, it will monitor the trust score and energy level of the cluster head node in real time. When the cluster head node experiences low energy, communication failure, or a sudden drop in trust score, the failure handling mechanism will be triggered immediately.

[0186] Low energy means the remaining energy is less than 30%.

[0187] Communication failure means that the cluster head cannot communicate normally with the nodes within the cluster.

[0188] A sudden drop in trust score means that the comprehensive trust score of the cluster head drops below .

[0189] The failure handling mechanism is that when the cluster head fails, the secondary cluster head quickly takes over its responsibilities.

[0190] The cluster head identity update module also includes a secondary cluster head backup and replacement mechanism. The secondary cluster head plays a backup role in the overall cluster management and quickly takes over the responsibilities of the cluster head when it fails; the secondary cluster head is responsible for sharing some of the tasks of the cluster head and backing up the key information within the cluster.

[0191] To prevent the cluster head node from failing due to overloading or insufficient energy, a load balancing mechanism is introduced. The load balancing mechanism is that when the remaining energy of the cluster head is lower than 30%, the system automatically starts the load sharing mechanism to transfer some of the tasks of the cluster head to the secondary cluster head node, ensuring that the cluster head does not fail due to overloading or insufficient energy.

[0192] When the trust score of the cluster head is lower than or the cluster head fails, the system will automatically select a secondary cluster head node to take over the functions of the cluster head, which is called the succession of the secondary cluster head; after the succession of the secondary cluster head, a new secondary cluster head is selected from the nodes with the first trust score ranking within the cluster.

[0193] The specific embodiments described above further elaborate on the purpose, technical solutions, and beneficial effects of the present invention. It should be understood that the above are only specific embodiments of the present invention and are not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included in the protection scope of the present invention.

Claims

1. A trusted identity management system for unmanned aerial vehicles, characterized in that, Including: A model initialization module, a dynamic trust scoring module, a Merkle tree dynamic verification and update module, and a cluster head identity update module; Before the UAVs execute tasks, the model initialization module completes the preparations for the UAV cluster to perform identity authentication and trust evaluation. The preparations include: first, setting the task time, defining the trust level, and assigning identity identifiers to each node of the UAV cluster; on this basis, the ground station randomly designates the cluster head UAV, the secondary cluster head UAV, and the member UAVs, and finally constructs an initial Merkle tree according to the identity information of each node, and the identity information of each node is used as the leaf node data of the Merkle tree; After the node identity assignment is completed, the cluster head node uses the dynamic trust scoring module to perform trust scoring on the task performance of all UAVs; Among them, the dynamic trust scoring module uses a dynamic scoring adjustment mechanism to calculate the trust score; The work trust score is based on the interaction performance between UAV nodes, including the task participation frequency, historical task completion rate, and verification failure rate. Denote the work trust score as . Calculate the work trust score of each node through a dynamic scoring adjustment mechanism. The specific calculation formula is as follows: , Among them, is the task participation frequency, is the corresponding weight of the task participation frequency; is the historical task completion rate, is the corresponding weight of the historical task completion rate; is the verification failure rate, is the corresponding weight of the verification failure rate; The energy trust score is based on the remaining battery level and the total battery capacity of the node. Denote the energy trust score as , and its calculation formula is as follows: ; wherein, is the remaining power of the node; is the total power of the node; The comprehensive trust score is calculated from the work trust score and the energy trust score, and the comprehensive trust score is denoted as , and the final comprehensive score is generated based on the work performance and energy state and used as the trust evaluation criterion for the cluster head node. The calculation formula is as follows: , Among them, is the work trust score; is the energy trust score; is the time decay factor, is the time; During the UAV task execution cycle, the dynamic trust scoring module combines the dynamic scoring adjustment mechanism to calculate the working trust score and the energy trust score of each node to obtain a comprehensive trust score. The comprehensive trust score is used for the trust evaluation of each node, and finally the trust score level assessment and node task performance analysis are realized based on the comprehensive trust score; After the UAV task execution cycle ends, a trust threshold mechanism is adopted to generate dynamic trust score thresholds and trust level evaluation criteria for each UAV node in the current task cycle. The trust score threshold completes the evaluation of the trust level of the UAV node according to the set threshold; After all node trust scores are calculated, the Merkle tree dynamic verification and update module and the cluster head identity update module are combined to update the cluster head node identity and the trust levels of all member nodes; The Merkle tree dynamic verification and update module includes a Merkle tree construction unit and a Merkle tree verification unit; the Merkle tree construction unit calculates the hash value of each member node according to the member node identity information, and then recursively calculates the root hash within each cluster and stores it in the cluster head node. Finally, the cluster head node generates and maintains the local Merkle tree within the cluster; the Merkle tree verification unit is used by the cluster head UAV to verify the integrity of the identity information and trust score of the member nodes within the cluster; The trust score and trust level of the cluster head are dynamically updated after the UAV task execution cycle ends. If the comprehensive trust score of the cluster head is lower than the threshold, the cluster head identity update module is started to select the secondary cluster head node as the new cluster head node, and the member node with the first trust score within the cluster is selected as the new secondary cluster head node.

2. The trusted identity management system for UAVs according to claim 1, characterized in that The dynamic trust scoring module also introduces a trust threshold mechanism, sets a trust threshold, and defines a scoring standard; After the task cycle ends, each cluster head node forms a dynamic trust score threshold within its own cluster for subsequent trust level evaluation, and its calculation formula is as follows: , Among them, is the dynamically generated trust score threshold for the cluster in the current cycle, applicable to all nodes within the cluster; is the average trust score of all member nodes within the cluster in the current cycle; is the standard deviation of the trust score; is the trust score adjustment factor; The node trust level evaluation is specifically as follows: When it is a high-trust node L1: continue to work and have the opportunity to become a new cluster head or sub-cluster head node and participate in task management; When it is an intermediate trusted node L2: maintain the current working state, continue to participate in the task, and strengthen the monitoring of its performance; When And if the trust path proof verification is successful, it is a low-trust node L3: marked as an observation object, its task is suspended, waiting for further evaluation to decide whether to resume normal operation; When And if the trust path proof verification fails, it is an untrusted node at L4: immediately isolate it from the communication environment, stop all its tasks, notify the ground station for interception and handling, and the node identity will be uploaded to the ground station for further analysis; In the trust evaluation criteria, the selection of the trust level of member nodes follows: after the task cycle ends, the trust score of qualified member nodes should be higher than , and its trust level should be higher than the trust node L2 level standard, and the original cluster head node verifies its identity information as qualified.

3. The trusted identity management system for an unmanned aerial vehicle according to claim 1, characterized in that, The Merkle tree construction unit specifically includes: The identity information of each member node will be used as the input data of the leaf node. The identity information includes node ID, cluster number Ci (i = 1, 2, 3,...), task role, and trust score, denoted as , where there are a total of N nodes. Hash calculation is performed on the identity data of each node. Each node data D j (j ∈ (1, N)) generates the hash value H(Dj) of the leaf node through an encryption-secure hash function: H(Dj) = SHA-256(Dj); Recursively operate on the hash values of leaf nodes to obtain a recursive hash. The hash values of adjacent leaf nodes H(D1) and H(D2) are combined and then hashed again to generate the hash value of the intermediate node; this is done recursively until a unique root hash H[root(Ci)] is finally generated. The root hash is stored in the cluster head node and periodically backed up to the secondary cluster head and the ground station. The UAV cluster is hierarchically managed. The entire cluster is divided into several sub-clusters. An independent Merkle tree, called a local Merkle tree, is constructed within each sub-cluster. The cluster head node of each sub-cluster serves as the main maintainer second only to the ground station and maintains the root hash H[root(Ci)] of its own subtree; the main cluster head, which is the ground station, is responsible for maintaining the global root hash H(global-root) and generating the global Merkle tree by combining the root hash values of all clusters.

4. The trusted identity management system for an unmanned aerial vehicle according to claim 1, wherein The Merkle tree verification unit is used to verify the integrity of the identity information and trust scores of the member nodes within the cluster. During the task execution process, the cluster head ensures the integrity of the identity data and trust scores by verifying the Merkle tree path. The verification path is a process of recursively deriving the hash value layer by layer by comparing the complete root hash value stored in a given cluster head or secondary cluster head node with the position of the node to be verified in the corresponding Merkle tree to confirm whether the data is complete and has not been tampered with. If the data of this leaf node, that is, the member node, has been tampered with, then the complete path hash value from this node to the cluster head node will not correspond to the root hash value stored in the cluster head node. Verification when a new node joins: When a new node joins, it will completely replace the old UAV node that can no longer work in the original cluster structure to achieve the succession of task information. The cluster head will also perform a partial verification path, which is to verify the hash path of the new node. The cluster head verifies the identity information and trust score of the node through the partial verification path of the local Merkle tree where it is located to ensure consistency with the existing Merkle tree data.

5. The trusted identity management system for an unmanned aerial vehicle according to claim 1, wherein The cluster head identity update module calculates the trust score of the cluster head at the end of each task cycle. When the score is lower than the threshold, the cluster head rotation mechanism is activated; The trust score of the cluster head is consistent with the trust score content of the member nodes, but the scoring rules are more stringent. At the end of the task cycle, the trust score of the cluster head must be higher than the minimum cluster head trust score , and the specific formula is as follows: , Among them is the lowest cluster head trust threshold, and its value is higher than the average scoring standard of ordinary nodes; The dynamically generated trust score threshold calculated for the cluster where it is located during the current period, applicable to all nodes within the cluster; It is the standard deviation of the trust score within the cluster and is used to ensure that the trustworthiness of the cluster head is more stable than that of ordinary nodes; The trust score of the cluster head must be dynamically updated after the end of the task cycle. When the comprehensive trust score of the cluster head is lower than the set threshold during the task execution , it is necessary to immediately start the cluster head rotation mechanism, and the cluster head rotation mechanism includes: The secondary cluster head automatically takes over the functions of the cluster head and succeeds to the current task status and Merkle tree data within the cluster; The member node with the highest trust score within the cluster becomes the new secondary cluster head.

6. The trusted identity management system for an unmanned aerial vehicle according to claim 5, wherein The cluster head identity update module also includes a cluster head failure handling mechanism. During the task execution process, it will monitor the trust score and energy level of the cluster head node in real time. When the cluster head node has too low energy, communication failure, or a sudden drop in the trust score, the failure handling mechanism will be immediately triggered; The "too low energy" means that the remaining energy is less than 30%; The "communication failure" means that the cluster head cannot communicate normally with the nodes within the cluster; The sudden drop in the trust score means that the comprehensive trust score of the cluster head drops below ; The failure handling mechanism is that when the cluster head fails, the secondary cluster head quickly takes over its responsibilities.

7. The trusted identity management system for an unmanned aerial vehicle according to claim 5, characterized in that, The cluster head identity update module also includes a secondary cluster head backup and succession mechanism. The secondary cluster head plays a backup role in the overall cluster management and quickly takes over the responsibilities of the cluster head when it fails; the secondary cluster head is responsible for sharing some of the tasks of the cluster head and backing up the key information within the cluster. To prevent the cluster head nodes from failing due to overloading or insufficient energy, a load balancing mechanism is introduced. When the remaining energy of the cluster head is lower than 30%, the tasks of some cluster heads are transferred to the sub-cluster head nodes to ensure that the cluster heads do not fail due to overloading or insufficient energy; When the trust score of the cluster head is lower than or the cluster head fails, the system will automatically select a secondary cluster head node to take over the functions of the cluster head, which is called the secondary cluster head succession; after the secondary cluster head succession, a new secondary cluster head is selected from the nodes with the first trust score ranking within the cluster.

8. The trusted identity management system for an unmanned aerial vehicle according to claim 1, wherein, The model initialization module specifically includes: Set the task time, set the total task time as T, and divide T into t time periods; Define the trust levels, define 4 trust levels, namely L4 untrusted nodes, low trust nodes L3, medium trust nodes L2, and high trust nodes L1, expressed as L4 < L3 < L2 < L1; Assign identity identifiers to each node of the UAV cluster. The ground station assigns a unique identity identifier to each node Di, including the task role and the initial position. The nodes joining midway must apply to the ground station for the identity identifier and the Merkle tree verification path of the corresponding group; Randomly assign cluster heads and sub-cluster heads to the nodes. In the initialization stage, the identities of all cluster heads and sub-cluster heads are randomly assigned by the ground station; the cluster heads are responsible for in-cluster identity verification and trust score calculation, and the sub-cluster heads act as backup nodes and load balancing nodes to take over their functions when the cluster heads fail and are inefficient; According to the identity information of each node, generate leaf node hash values through a hash function, and then recursively generate the root node, finally forming the Merkle tree structure within the cluster, constructing the initial Merkle tree. The cluster head node is responsible for storing the root hash value and regularly passing it to the sub-cluster head for backup.

9. A trusted identity management method for an unmanned aerial vehicle, characterized in that, The method is applied to a trusted identity management system for UAVs according to any one of claims 1 to 8, and the specific steps are as follows: Step S1: In the initial stage of the task, the ground station randomly assigns cluster head UAVs, sub-cluster head UAVs, and member UAVs in the hierarchical network; Step S2: After the task cycle ends, evaluate the trust score according to the task performance of each node, dynamically update the node trust level, and finally determine whether to elect a new cluster head node and update the node trust level; Step S3: To ensure the security and credibility of the node identity and trust score, use the Merkle tree structure to store the identity information; the cluster head node is responsible for managing and verifying the identity information of its own cluster, constructing a local Merkle tree, and dynamically updating the Merkle tree root hash value according to the node trust score; Step S4: The cluster head node regularly submits a local trust score table to the ground station. The ground station combines this with its own trust score of the cluster head node to generate a global trust score table to achieve the identity management of the UAV cluster.

Citation Information

Patent Citations

  • Industrial Internet of Things node consensus method based on blockchain

    CN111182510A

  • Data transmission and protection parallel group awareness method in Internet of Vehicles environment

    CN115695461A