Unmanned aerial vehicle access authentication method based on LORA communication
By adopting LORA communication and AKA protocols between drone and ground-controlled sites, the problems of high cost, limited coverage and low security in drone communication are solved, and efficient communications that can quickly deploy, flexibly adapt and reduce costs are achieved.
Patent Information
- Application Number
- CN202510839446.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-23
- Publication Date
- 2025-07-22
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The communication between existing drones and ground-controlled sites has problems such as high cost, limited coverage, difficulty in multi-site management, low communication security, low reliability and poor confidentiality.
UAV access authentication method based on LORA communication is adopted. By installing LORA communication modules on the ground-controlled site, communication between broadcast channels and dedicated channels is realized, and identity authentication and session key negotiation of drones are carried out in combination with AKA protocol to ensure safe and reliable communication between the drone and the ground-controlled site.
It realizes rapid deployment, flexible adaptation to changing environments, reduces construction and maintenance costs, improves the reliability and security of communication systems, and is suitable for communication needs in a variety of complex scenarios.
Smart Images

Figure CN120358500A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of unmanned aerial vehicles, and particularly relates to an access authentication method for unmanned aerial vehicles based on LORA communication. Background Art
[0002] With the rapid development of unmanned aerial vehicle technology, unmanned aerial vehicles are increasingly widely used in various fields, such as agricultural plant protection, power line inspection, logistics distribution, etc. However, in the actual application of unmanned aerial vehicles, how to ensure safe and reliable communication between unmanned aerial vehicles and ground control stations is an urgent problem to be solved. At present, the communication between unmanned aerial vehicles and ground control stations mainly uses dedicated channels, but this method has problems such as high cost and limited coverage. Therefore, a new access authentication method for unmanned aerial vehicles is needed to improve the communication efficiency and security between unmanned aerial vehicles and ground control stations. Among them, the access authentication of unmanned aerial vehicles is an important link to ensure the safe and reliable operation of the unmanned aerial vehicle system. Summary of the Invention
[0003] The purpose of the present invention is to overcome the deficiencies of the prior art and provide an access authentication method for unmanned aerial vehicles based on LORA communication, so as to solve the problems existing in the existing unmanned aerial vehicle communication, such as high cost, limited coverage, difficult management of multiple stations and multiple unmanned aerial vehicles, low communication security coefficient, low reliability, and poor confidentiality, and improve the reliability, stability, and security of the unmanned aerial vehicle communication system.
[0004] The purpose of the present invention is achieved by the following technical solutions: An access authentication method for unmanned aerial vehicles based on LORA communication, which is applied between a ground control station and an unmanned aerial vehicle terminal. The method includes the following steps: S1. Install a LORA communication module on the ground control station. The LORA communication module is used to provide a broadcast channel and a dedicated channel for communicating with the unmanned aerial vehicle; S2. Before taking off, the unmanned aerial vehicle sends an authentication request to the ground control station through the dedicated channel. The authentication request contains the identification information and flight plan information of the unmanned aerial vehicle; S3. After receiving the authentication request, the ground control station verifies the identification information and flight plan information of the unmanned aerial vehicle; S4. If the verification is passed, the ground control station sends an authentication success message to the unmanned aerial vehicle through the broadcast channel and sends the flight plan information of the unmanned aerial vehicle to the relevant stations; S5. After receiving the authentication success message, the unmanned aerial vehicle sends a weather data acquisition request to the ground control station through the broadcast channel; S6. After receiving the weather data acquisition request, the ground control station obtains weather data from the meteorological department through the dedicated channel and sends the weather data to the unmanned aerial vehicle through the broadcast channel; During the flight of the drone, it reports the main intention data to the ground control station through the broadcast channel, and the ground control station forwards the main intention data to the relevant departments through the dedicated channel.
[0005] Further, before step S2, an initialization phase is also included. The specific process is as follows: The ground control station generates system parameters, including a public key and a private key, and broadcasts the public key to all drones; After receiving the public key, the drone generates its own key pair and submits the drone registration information to the ground control station for registration. The drone registration information includes the drone model, serial number, flight parameters, and the public key; The ground control station reviews the drone's registration information. After passing the review, it assigns a unique identifier to the drone and stores it in the database.
[0006] Further, steps S2 and S3 specifically include: When the drone needs to access the network, it sends an authentication request to the ground control station. The authentication request includes the drone's identity identifier, the current timestamp, and a message signed with the drone's private key; After receiving the authentication request, the ground control station uses the drone's public key to verify the validity of the signature. If the signature is valid, the ground control station continues with the next authentication step; otherwise, it rejects the drone's access request; The ground control station generates a random number as a challenge value and sends it to the drone; After receiving the challenge value, the drone encrypts the challenge value using its own private key and sends the encrypted result back to the ground control station as a response value; The ground control station decrypts the response value using the drone's public key. If the decrypted result is the same as the challenge value, the ground control station considers the drone to have passed the authentication and assigns a session key to it; otherwise, it rejects the drone's access request.
[0007] Further, in steps S2 and S3, through the LORA communication module, the Authentication and Key Agreement (AKA) protocol is used to authenticate the drone user and negotiate the session key. The specific authentication process of the AKA protocol is as follows: The drone user entity UE sends an access request message to the ground control center MME. The access request contains the drone user identification code IMSI of the local machine and the identity identifier of the user management server HSS ; After receiving the access request message, the ground control center MME, according to Send an authentication data request to the corresponding user management server HSS. The authentication data request includes the UAV user identification code IMSI and the identity identifier SNID of this service network. After receiving the authentication data request, the user management server HSS searches the database for the corresponding IMSI and SNID, verifies their identity authenticity. If the verification passes, it generates an authentication vector group. As an authentication data response, it is sent to the ground control center MME. Among them, the authentication vector AV consists of an authentication token AUTN, a random number RAND, an expected response XRES. It is composed of a quadruple. The random number RAND is generated by the user management server HSS, and the expected response XRES represents the response information expected to be received by the ground control center MME from the UAV user entity UE. As the key identifier for generating the base key used for generating the keys for subsequent communications, which is generated by the key generation function KDF. After receiving the authentication data response, the ground control center MME stores in the database, randomly selects a vector , extracts , , , and assigns a key identifier for , and then sends a user authentication request to the UAV user entity UE. After receiving the user authentication request, the UAV user entity UE extracts the address information of the MME ground control center from to calculate the address information key identifier, compares whether the two are equal, and checks whether the serial number identifier is within the normal range. If the above tests pass, it verifies the authenticity of the HSS. If the authentication passes, the MME ground station calculates the expected response of the UAV user entity UE response information and , and sends the UE expected response to the UAV user entity UE. The UE UAV user entity compares the received and the expected calculated by the ground station. If the comparison result is consistent, the authentication passes. After the two-way authentication is completed, the ground control center MME and the UAV user entity UE use as the base key, and deduce the encryption key CK and the integrity protection key IK according to the agreed algorithm for subsequent secure communications.
[0008] Further, after the ground control center MME successfully authenticates the UAV user entity UE, the ground control center MME allocates a temporary identity identifier TMSI to the UAV user to replace the UAV user identification code IMSI, and the TMSI is updated every once in a while for subsequent data communication.
[0009] Further, during the data transmission process in the steps S4 - S7, the UAV and the ground control station encrypt and decrypt the transmitted data using the session key.
[0010] Further, the main intention data includes the current position, flight status, and task execution information of the UAV, and the method further includes: The ground control station and relevant departments monitor the flight status of the UAV in real time according to the received main intention data; The ground control station sends an action instruction to the UAV through a dedicated channel according to the flight status of the UAV. The action instruction includes changing the flight route and executing a specific task; after receiving the action instruction, the UAV performs corresponding operations according to the instruction.
[0011] The beneficial effects of the present invention are: 1) Quick deployment: Using LORA as the communication carrier and wireless transmission, it can be quickly deployed to multiple locations without complex infrastructure construction, greatly improving the response speed of the communication system.
[0012] 2) High flexibility: The UAV ground control station nodes can dynamically adjust the access quantity according to communication requirements and environmental changes to optimize the communication link and improve communication quality. This flexibility enables the technical solution of the present invention to adapt to various complex and changeable communication environments.
[0013] 3) Cost reduction: The present invention does not require laying fixed communication lines or building facilities such as base stations, reducing the construction and maintenance costs and improving the economic benefits of the communication system.
[0014] 4) Wide application: The present invention is applicable to various scenarios, such as disaster area communication restoration, communication guarantee for temporary large-scale events, etc., and can meet the communication requirements in different scenarios. Brief Description of the Drawings
[0015] Figure 1 are the specific implementation steps of the solution of the present invention; Figure 2 is the specific process block diagram of two-way access authentication. Detailed Embodiment
[0016] The technical solution of the present invention will be clearly and completely described below in conjunction with the embodiments. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative efforts belong to the scope of protection of the present invention.
[0017] Refer to Figure 1 - Figure 2 , the present invention provides a technical solution: An unmanned aerial vehicle (UAV) access authentication method based on long-range radio (LORA) communication, which is applied between a ground control station and a UAV terminal, as Figure 1 shown, the method includes the steps: S1. Install a long-range radio (LORA) communication module on the ground control station. The long-range radio (LORA) communication module is used to provide a broadcast channel and a dedicated channel for communicating with the UAV; the broadcast channel is used to implement broadcast communication between the ground control station and the UAV, and the dedicated channel is used to implement point-to-point communication with the UAV.
[0018] S2. Before taking off, the UAV sends an authentication request to the ground control station through the dedicated channel. The authentication request contains the identification information and flight plan information of the UAV; the identification information of the UAV can be the serial number, MAC address, etc. of the UAV, and the flight plan information includes the takeoff location, flight route, flight altitude, flight speed, etc.
[0019] S3. After receiving the authentication request, the ground control station verifies the identification information and flight plan information of the UAV; the ground control station can verify the identification information and flight plan information of the UAV bidirectionally by querying the database or checking information with relevant departments to ensure the legality and safety of the UAV.
[0020] S4. If the verification is passed, the ground control station sends an authentication success message to the UAV through the broadcast channel and sends the flight plan information of the UAV to the relevant stations; the relevant base stations can provide corresponding communication services and navigation services for the UAV according to the flight plan information of the UAV.
[0021] S5. After receiving the authentication success message, the UAV sends a meteorological data acquisition request to the ground control station through the broadcast channel; the meteorological data acquisition request can contain the current position information and flight altitude information of the UAV so that the ground control station can provide accurate meteorological data for the UAV.
[0022] S6. After the ground control station receives a meteorological data acquisition request, it obtains meteorological data from the meteorological department through a dedicated channel and sends the meteorological data to the UAV through a broadcast channel. The meteorological data may include information such as wind speed, wind direction, temperature, air pressure, humidity, etc. These information are of great significance for the flight safety and mission execution of the UAV.
[0023] S7. During the flight of the UAV, it reports the main intention data to the ground control station through the broadcast channel, and the ground control station forwards the main intention data to the relevant departments through the dedicated channel. Further, the main intention data includes information such as the current position, flight status, and mission execution status of the UAV. These information are of important reference value for the relevant departments to make decisions and manage.
[0024] The method further includes: The ground control station and the relevant departments monitor the flight status of the UAV in real time according to the received main intention data; The ground control station sends an action instruction to the UAV through the dedicated channel according to the flight status of the UAV. The action instruction includes changing the flight route and executing a specific task. After receiving the action instruction, the UAV executes the corresponding operation according to the instruction.
[0025] In this embodiment, before step S2, it further includes an initialization phase. The specific process is as follows: The ground control station generates system parameters, including a public key and a private key, and broadcasts the public key to all UAVs; After receiving the public key, the UAV generates its own key pair, submits the UAV registration information to register with the ground control station. The UAV registration information includes the UAV model, serial number, flight parameters, and the public key; The ground control station reviews the registration information of the UAV. After passing the review, it assigns a unique identifier to the UAV and stores it in the database.
[0026] Before each flight, the UAV needs to send an authentication request to the ground control station. The ground control station verifies the authentication request of the UAV. After passing the verification, it sends a message of successful authentication to the UAV, allowing the UAV to fly, that is, two-way access authentication between the ground control station and the UAV is required.
[0027] In a specific embodiment, steps S2 and S3 specifically include: When the UAV needs to access the network, it sends an authentication request to the ground control station. The authentication request includes the identity identifier of the UAV, the current timestamp, and a message signed with the UAV's private key; After the ground control station receives the authentication request, it uses the public key of the drone to verify the validity of the signature. If the signature is valid, the ground control station continues with the next step of authentication; otherwise, it rejects the access request of the drone; The ground control station generates a random number as a challenge value and sends it to the drone; After receiving the challenge value, the drone encrypts the challenge value using its own private key and sends the encrypted result back to the ground control station as a response value; The ground control station decrypts the response value using the public key of the drone. If the decrypted result is the same as the challenge value, the ground control station considers the drone to have passed the authentication and assigns a session key to it; otherwise, it rejects the access request of the drone.
[0028] Furthermore, in steps S2 and S3, the AKA protocol is used through the LORA communication module to authenticate the drone user and negotiate the session key. The specific authentication process of the AKA protocol is as follows: The drone user entity UE sends an access request message to the ground control center MME. The access request contains the drone user identification code IMSI of the local machine and the identity identifier of the user management server HSS ; There is a pre-shared key K between the drone user entity UE and the user management server HSS; After receiving the access request message, the ground control center MME sends an authentication data request to the corresponding user management server HSS according to The authentication data request contains the drone user identification code IMSI and the identity identifier SNID of the local service network; After receiving the authentication data request, the user management server HSS checks whether there is a corresponding IMSI and SNID in the database, verifies their identity authenticity. If the verification passes, it generates an authentication vector group as an authentication data response and sends it to the ground control center MME; Among them, the authentication vector AV consists of an authentication token AUTN, a random number RAND, an expected response XRES, a quadruple. The random number RAND is generated by the user management server HSS, and the expected response XRES represents the response information expected to be received by the ground control center MME from the drone user entity UE; As the key identifier, it is the base key used to generate the keys for subsequent communications and is generated through the key generation function KDF; After receiving the authentication data response, the ground control center MME stores in the database, randomly selects a vector , extracts , , , for allocate a key identifier , and then send a user authentication request to the drone user entity UE; After receiving the user authentication request, the drone user entity UE extracts the address information of the MME ground control center from to calculate the address information key identifier, compare whether the two are equal, and check the serial number identifier whether it is within the normal range. If the above verification passes, the authenticity of the HSS is verified. If the authentication passes, the MME ground station calculates the expected response of the drone user entity UE's response and , and send the UE expected response to the drone user entity UE; The UE drone user entity compares the received and the expected calculated by the ground station. If the comparison result is consistent, the authentication is passed; After the mutual authentication is completed, the ground control center MME and the drone user entity UE will as the base key, and deduce the encryption key CK and the integrity protection key IK according to the agreed algorithm for subsequent secure communication.
[0029] Furthermore, after the ground control center MME authenticates the drone user entity UE successfully, the ground control center MME assigns a temporary identity identifier TMSI to the drone user to replace the drone user identification code IMSI, and the TMSI is updated every once in a while for subsequent data communication, aiming to enhance the confidentiality of the system and prevent illegal attackers from obtaining the IMSI or tracking the user's location by listening to the signaling on the wireless link.
[0030] Furthermore, during the data transmission process of the steps S4 - S7, the drone and the ground control station use the session key to encrypt and decrypt the transmitted data.
[0031] The above authentication process based on the Authentication and Key Agreement protocol AKA protocol is secure. The specific security analysis is as follows: Anti-forgery attack: The authentication request of the drone contains a message signed with its private key. Only the drone with the correct private key can generate a valid signature. Therefore, an attacker cannot forge the authentication request of the drone.
[0032] Anti-replay attack: The authentication request contains a timestamp, and the ground control station can determine whether the authentication request is fresh by checking the timestamp. If the timestamp of the authentication request differs significantly from the current time, the ground control station will reject the request, thus preventing replay attacks.
[0033] Anti-eavesdropping attack: The communication data between the drone and the ground control station is encrypted using a session key. Even if an attacker eavesdrops on the communication data, they cannot decrypt useful information.
[0034] Key security: The private key of the ground control station is stored in a secure environment and can only be accessed by authorized personnel. The key pair of the drone is stored in the secure module of the drone after generation, making it difficult for attackers to obtain.
[0035] The technical key point of the present invention is to use LORA communication devices to network the drone and the ground control center, optimize the communication link, and achieve fast, flexible, and cost-effective encrypted communication. To achieve this goal, the present invention has made innovations in multiple aspects such as the design of two-way access authentication, the scheduling and management of the ground control center, the communication protocol and control algorithm of the user terminal, etc. By implementing the technical solution of the present invention, the following beneficial effects will be produced: Rapid deployment: Using LORA as the communication carrier and wireless transmission, it can be rapidly deployed to multiple locations without complex infrastructure construction, greatly improving the response speed of the communication system.
[0036] Highly flexible: The drone ground control station nodes can dynamically adjust the number of accesses according to communication requirements and environmental changes to optimize the communication link and improve communication quality. This flexibility enables the technical solution of the present invention to adapt to various complex and changeable communication environments.
[0037] Cost reduction: The present invention does not require laying fixed communication lines or building base stations and other facilities, reducing construction and maintenance costs and improving the economic benefits of the communication system.
[0038] Widely applicable: The present invention is applicable to various scenarios, such as communication restoration in disaster areas, communication guarantee for temporary large-scale events, etc., and can meet the communication requirements in different scenarios.
[0039] The above is only the preferred embodiment of the present invention. It should be understood that the present invention is not limited to the form disclosed herein, should not be regarded as an exclusion of other embodiments, but can be used in various other combinations, modifications, and environments, and can be changed within the scope of the concept described herein through the above teachings or the technology or knowledge in related fields. And the changes and alterations made by those skilled in the art that do not depart from the spirit and scope of the present invention should all be within the protection scope of the appended claims of the present invention.
Claims
1. A method for UAV access authentication based on LORA communication, characterized in that, Applied between the ground control station and the UAV terminal, the method includes the steps of: S1. Install a LORA communication module on the ground control station. The LORA communication module is used to provide a broadcast channel and a dedicated channel for communicating with the UAV. S2. Before taking off, the UAV sends an authentication request to the ground control station through the dedicated channel. The authentication request contains the identification information and flight plan information of the UAV. S3. After receiving the authentication request, the ground control station verifies the identification information and flight plan information of the UAV. S4. If the verification is passed, the ground control station sends an authentication success message to the UAV through the broadcast channel and sends the flight plan information of the UAV to the relevant stations. S5. After receiving the authentication success message, the UAV sends a meteorological data acquisition request to the ground control station through the broadcast channel. S6. After receiving the meteorological data acquisition request, the ground control station obtains meteorological data from the meteorological department through the dedicated channel and sends the meteorological data to the UAV through the broadcast channel. S7. During the flight of the UAV, the UAV reports the main intention data to the ground control station through the broadcast channel, and the ground control station forwards the main intention data to the relevant departments through the dedicated channel.
2. The method for authenticating the access of an unmanned aerial vehicle based on LORA communication according to claim 1, wherein: Before step S2, there is also an initialization phase. The specific process is as follows: The ground control station generates system parameters, including a public key and a private key, and broadcasts the public key to all UAVs. After receiving the public key, the UAV generates its own key pair, submits the UAV registration information to the ground control station for registration. The UAV registration information includes the UAV model, serial number, flight parameters, and the public key. The ground control station reviews the registration information of the UAV. After the review is passed, a unique identifier is assigned to the UAV and stored in the database.
3. The method for authenticating the access of a drone based on LORA communication according to claim 2, wherein: The specific steps of step S2 and step S3 include: When the UAV needs to access the network, it sends an authentication request to the ground control station. The authentication request includes the identity identifier of the UAV, the current timestamp, and a message signed with the UAV's private key. After receiving the authentication request, the ground control station verifies the validity of the signature using the UAV's public key. If the signature is valid, the ground control station continues with the next authentication step; otherwise, it rejects the access request of the UAV. The ground control station generates a random number as a challenge value and sends it to the UAV. After receiving the challenge value, the UAV encrypts the challenge value using its own private key and sends the encrypted result back to the ground control station as a response value. The ground control station decrypts the response value using the UAV's public key. If the decrypted result is the same as the challenge value, the ground control station considers the UAV to have passed the authentication and assigns a session key to it; otherwise, it rejects the access request of the UAV.
4. The method for authenticating the access of an unmanned aerial vehicle based on LORA communication according to claim 3, wherein: In step S2 and step S3, the AKA protocol is used to authenticate the UAV user and negotiate the session key through the LORA communication module. The specific authentication process of the AKA protocol is as follows: The drone user entity UE sends an access request message to the ground control center MME. The access request contains the drone user identification code IMSI of this device and the identity identifier of the user management server HSS ; After the ground control center MME receives the access request information, according to send an authentication data request to the corresponding user management server HSS. The authentication data request includes the UAV user identification code IMSI and the identity identifier SNID of this service network; After the user management server HSS receives an authentication data request, it searches the database for the corresponding IMSI and SNID, verifies their identity authenticity. If the verification passes, it generates an authentication vector group As an authentication data response, it is sent to the ground control center MME; among them, the authentication vector AV consists of an authentication token AUTN, a random number RAND, an expected response XRES, a quadruple. The random number RAND is generated by the user management server HSS, and the expected response XRES represents the response information expected to be received by the ground control center MME from the drone user entity UE; As the key identifier, it is the basic key used to generate the keys for subsequent communications and is generated through the key generation function KDF; After the ground control center MME receives the authentication data response, it will store it in the database and randomly select a vector , extract , , , and assign a key identifier for . Next, it sends a user authentication request to the drone user entity UE; After the drone user entity UE receives a user authentication request, it extracts the address information of the MME ground control center from to calculate the address information key identifier, compares whether the two are equal, and checks the serial number identifier to see if it is within the normal range. If the above tests pass, the authenticity of the HSS is verified. If the authentication passes, the MME ground station calculates the expected response of the drone user entity UE's response with , and sends the UE expected response to the drone user entity UE; The UE drone user entity compares the received and with the expected calculated by the ground station. If the comparison results are consistent, the authentication is passed; After the two-way authentication is completed, the ground control center MME and the drone user entity UE will Using it as the base key, the encryption key CK and the integrity protection key IK are deduced according to the agreed algorithm for subsequent secure communication.
5. The method for authenticating the access of a drone based on LORA communication according to claim 4, wherein: After the ground control center MME successfully authenticates the drone user entity UE, the ground control center MME allocates a temporary identity identifier TMSI to the drone user to replace the drone user identification code IMSI, and the TMSI is updated every once in a while for subsequent data communication.
6. The method for authenticating the access of an unmanned aerial vehicle based on LORA communication according to claim 1, characterized in that: During the data transmission process from step S4 to step S7, the drone and the ground control station encrypt and decrypt the transmitted data using the session key.
7. The method for authenticating the access of an unmanned aerial vehicle based on LoRa communication according to claim 1, wherein: The main intention data includes the current position, flight status, and task execution status information of the drone, and the method further includes: The ground control station and relevant departments monitor the flight status of the drone in real time according to the received main intention data; The ground control station sends an action instruction to the drone through a dedicated channel according to the flight status of the drone. The action instruction includes changing the flight route and executing a specific task. After receiving the action instruction, the drone performs corresponding operations according to the instruction.
Citation Information
Patent Citations
Access authentication and key agreement protocol and method of special network for space-aeronautics-vehicle-ground tracks
CN107204847A
Unmanned aerial vehicle cluster wireless data transmission system and method based on Lora protocol
CN118175583A
Equipment access method and device, authentication server and storage medium
CN119583157A
Secure communication method, system and device between unmanned aerial vehicle and ground station, and readable medium
CN120111484A
Method and device for terminal authentication in wireless communication system
US20250150818A1
Cited By
Unmanned aerial vehicle electronic identity card identification and management method based on 4G / 5G cloud control
CN120768564A
Flight data transceiving method, notification method, receiving method and computing device
CN121099311A