Unmanned control system dynamic key trust chain construction method based on Feiteng E2000TCM
By building a dynamic key trust chain based on Feiteng E2000TCM, and using hash algorithm to derive multi-layer keys, the information security risks of the UAV flight control system are solved, real-time and reliability are improved, and malicious threats and virus attacks are prevented.
Patent Information
- Application Number
- CN202510870725.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-26
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2045-06-26
AI Technical Summary
UAV flight control systems face information security risks. The existing protection methods cannot meet the strict requirements of real-time and reliability, and are vulnerable to malicious threats and virus attacks.
Based on Feiteng E2000TCM, the unmanned control system dynamic key trust chain construction method is used to derive the hardware root key, system key, task key and interaction key, and the trusted computing power of the flight control system is enhanced through a hierarchical isolation mechanism, and dynamically encrypted data communication.
Effectively defend against malicious threats and viruses, ensure the safety of drone flight missions, meet the strict requirements of real-time and reliability, and prevent control from being hijacked.
Smart Images

Figure CN120378874A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the technical field of UAV security, and particularly to a method for constructing a dynamic key trust chain of an unmanned control system based on Feiteng E2000 TCM. Background Art
[0002] Unmanned aerial vehicles (UAVs) are increasingly widely used in many fields and have become an indispensable part of human production and life. However, with the rapid development of modern UAV equipment and technology, and the deep integration of UAVs with modern computer technology and communication network technology, the information security risks faced by UAVs are becoming increasingly prominent. If these risks are ignored, UAVs may be maliciously exploited by illegal personnel and organizations through their security vulnerabilities, posing potential threats to industrial applications. Therefore, it is crucial to comprehensively sort out the information security risks of UAVs, which helps to timely discover and identify the security vulnerabilities of UAVs, and further provides important support for formulating effective measures to avoid potential security risks.
[0003] Firstly, there are information security risks in the UAV's native system.
[0004] The wide application of UAVs in modern society exposes them to many information security risks. These risks not only stem from the vulnerability of the technology itself but are also closely related to the increasingly complex network environment and evolving malicious threat means. The native vulnerabilities in the UAV flight control system (flight control system) not only directly affect its flight safety but may also cause extensive and serious consequences. Most UAVs and ground stations use foreign open-source operating systems, which are usually intelligent, and most of the UAV external devices also have their own operating systems. There are cases where system vulnerabilities are not repaired, and it is very likely that illegal personnel and organizations will use these vulnerabilities to invade UAVs or ground stations. Once information leakage occurs, extremely serious consequences will arise, such as illegally entering sensitive facilities, interfering with large-scale public activities, and even threatening flight safety. Therefore, the information security risks of the UAV native system cannot be ignored.
[0005] Secondly, there are risks of the diversity of UAV information security vulnerabilities.
[0006] With the rapid development of UAV technology, its system composition and flight mechanism have become increasingly complex. This makes UAV information security issues no longer limited to the software or network level but extend to multiple aspects such as hardware, sensors, audio-visual equipment, and communication links. Any vulnerability in a single link, once maliciously exploited, may lead to catastrophic consequences.
[0007] The drone system application client is vulnerable to malware infection. A communication protocol is enabled in the drone system to allow users to control the drone through wireless remote control (such as tablets, laptops, and mobile phones). However, this technology is insecure, which allows illegal individuals and organizations to create a reverse shell TCP payload and inject it into the drone's memory, thus secretly installing malware on the drone ground station.
[0008] The drone data link is vulnerable to interference and interception. The telemetry signal of the drone can monitor traffic information and transmit information through an open and insecure radio, making the drone vulnerable to various threats, including data interception, malicious data injection, changing the preset flight route, etc. Moreover, illegal individuals and organizations have the opportunity to install and insert many infected digital files (videos, images) into the ground station through the drone, and even fly someone else's drone back.
[0009] It can be seen that it is very necessary to improve the security protection performance of the drone, especially the security protection performance of the flight control system of the drone. However, the currently proposed protection measures have all reached the bottleneck of performance improvement and cannot meet the strict requirements of the flight control system of the drone for the real-time and reliability of security. Summary of the Invention
[0010] In view of this, the embodiments of the present application propose a method for constructing a dynamic key trust chain of an unmanned control system based on Feiteng E2000 TCM, aiming to utilize the security features of the TCM (Trusted Computing Module) built into Feiteng E2000 to construct a key management system suitable for the flight control system of high-real-time drones, thereby realizing a dynamic trust security protection mechanism for data communication of the flight control system of drones, enhancing the trusted computing ability of the flight control system of drones from the bottom layer, effectively defending against malicious threats and viruses, and meeting the strict requirements of the flight control system of drones for the real-time and reliability of security.
[0011] To achieve the above object, an embodiment of the present application proposes a method for constructing a dynamic key trust chain of an unmanned control system based on Feiteng E2000 TCM, which is applicable to the flight control system of an unmanned aerial vehicle. The method includes the following steps: generating an unexportable hardware root key using the TCM of Feiteng E2000 as the starting point of the entire trust chain; after the flight control system of the unmanned aerial vehicle is powered on and initialized, deriving a system key for encrypting the firmware and core algorithms of the flight control system of the unmanned aerial vehicle based on the hardware root key and the device unique identification code of the flight control system of the unmanned aerial vehicle using a hashing algorithm; after the unmanned aerial vehicle takes off, determining the current flight phase, and deriving a task key for encrypting the data generated in the current flight phase based on the system key and the identification of the current flight phase using a hashing algorithm; when the unmanned aerial vehicle needs to communicate with a ground station or other unmanned aerial vehicles in the current flight phase, obtaining the current environmental risk level, and deriving an interaction key for encrypting the data of this communication based on the task key corresponding to the current flight phase and the environmental risk level using a hashing algorithm; wherein, after detecting a flight phase switch, immediately destroying the task key corresponding to the flight phase before the switch, and after detecting the completion of this communication, immediately destroying the interaction key corresponding to this communication.
[0012] To achieve the above object, an embodiment of the present application also proposes a device for constructing a dynamic key trust chain of an unmanned control system based on Feiteng E2000 TCM, which is applicable to the flight control system of an unmanned aerial vehicle. The system includes: a root key generation module for generating an unexportable hardware root key using the TCM of Feiteng E2000 as the starting point of the entire trust chain; a system key derivation module for deriving a system key for encrypting the firmware and core algorithms of the flight control system of the unmanned aerial vehicle based on the hardware root key and the device unique identification code of the flight control system of the unmanned aerial vehicle using a hashing algorithm after the flight control system of the unmanned aerial vehicle is powered on and initialized; a task key derivation module for determining the current flight phase of the unmanned aerial vehicle after the unmanned aerial vehicle takes off, and deriving a task key for encrypting the data generated in the current flight phase based on the system key and the identification of the current flight phase using a hashing algorithm; an interaction key derivation module for obtaining the current environmental risk level when detecting that the unmanned aerial vehicle needs to communicate with a ground station or other unmanned aerial vehicles in the current flight phase, and deriving an interaction key for encrypting the data of this communication based on the task key corresponding to the current flight phase and the environmental risk level using a hashing algorithm; a key destruction module for immediately destroying the task key corresponding to the flight phase before the switch after detecting a flight phase switch, and immediately destroying the interaction key corresponding to this communication after detecting the completion of this communication.
[0013] To achieve the above object, an embodiment of the present application further provides an electronic device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute a method for constructing a dynamic key trust chain of an unmanned control system based on Feiteng E2000 TCM as described above.
[0014] To achieve the above object, an embodiment of the present application further provides a computer-readable storage medium storing a computer program, which, when executed by a processor, can implement a method for constructing a dynamic key trust chain of an unmanned control system based on Feiteng E2000 TCM as described above.
[0015] A method for constructing a dynamic key trust chain of an unmanned control system based on Feiteng E2000 TCM proposed by the present application makes full use of the hardware security capabilities of Feiteng E2000 TCM. By designing a key dynamic derivation mechanism through a hashing algorithm to ensure the uniqueness of the data communication link, the derivation of keys is dynamically random, and illegal personnel and organizations cannot crack and obtain all keys at any time, so they cannot invade the data communication link. The present application designs a hierarchical isolation mechanism, and the entire trust chain is derived step by step from "hardware root key, system key, task key, and interaction key", physically isolating the intrusion risk. When deriving the task key, the flight stage of the unmanned aerial vehicle (UAV) is fully considered. At different flight stages, different task keys are derived for dynamic encryption of the data of the flight mission, ensuring that the flight mission of the UAV is not tampered with. After the flight stage is switched, the old task key is immediately destroyed, and even if the old task key is leaked, it does not affect the latest flight mission. When deriving the interaction key, the environmental risk level is fully considered. For different levels of environmental risks, different-strength interaction keys are derived to encrypt the data of this communication, ensuring the smoothness and unique security of the communication between the UAV and the ground station or other UAVs, and ensuring that the control right of the UAV cannot be hijacked. All in all, the dynamic key trust chain constructed by the present application enhances the trusted computing ability of the flight control system of the UAV from the bottom layer, can effectively defend against malicious threats and viruses, and meets the strict requirements of the flight control system of the UAV for security real-time performance and reliability.
[0016] Optionally, generating an in-exportable hardware root key using the TCM of Feiteng E2000 as the starting point of the entire trust chain includes: Generating random bits through the true random number generator built into the TCM of Feiteng E2000; Processing the random bits generated by the true random number generator using the SM3 hashing algorithm to obtain the first SM3 hash value, and taking the first 256 bits of the first SM3 hash value as the 256-bit hardware root key ; Write the hardware root key into the secure storage area of the TCM, and prohibit export and external access; The hardware root key is represented by the formula: ; wherein, represents random bits generated by a true random number generator, represents the first SM3 hash value, represents the SM3 hash algorithm, represents taking the first 256 bits.
[0017] Optionally, after the flight control system of the unmanned aerial vehicle is powered on and initialized, based on the hardware root key and the device unique identification code of the flight control system of the unmanned aerial vehicle, a system key for encrypting the firmware and core algorithms of the flight control system of the unmanned aerial vehicle is derived by using a hash algorithm, including: After the flight control system of the unmanned aerial vehicle is powered on and initialized, first perform a verification of the basic parameter configuration; If the verification of the basic parameter configuration passes, read the device unique identification code of the flight control system and the fixed salt value preset in the TCM; Use the SM3 hash algorithm to process the hardware root key , the device unique identification code of the flight control system and the fixed salt value, obtain a second SM3 hash value, and take the first 256 bits of the second SM3 hash value as a 256-bit system key for encrypting the firmware and core algorithms of the flight control system of the unmanned aerial vehicle ; The system key is represented by the formula: ; wherein, represents the device unique identification code of the flight control system, represents the fixed salt value, represents a separator that does not affect the logic, represents the second SM3 hash value.
[0018] Optionally, the flight phases of the unmanned aerial vehicle include a takeoff phase, a cruise phase, and a landing phase. After the unmanned aerial vehicle takes off, determine the current flight phase, and based on the system key and the identifier of the current flight phase, use a hash algorithm to derive a task key for encrypting the data generated in the current flight phase, including: After the unmanned aerial vehicle takes off, read the identifier of the flight phase to determine the current flight phase, represents the takeoff phase, Indicates the cruise phase, Indicates the landing phase; Read the start timestamp of the current flight phase, obtain the sensor noise value and dynamic flight parameters, and construct derived parameters based on the identifier of the current flight phase , the start timestamp of the current flight phase, the sensor noise value, and the dynamic flight parameters; among them, the dynamic flight parameters include flight altitude, flight speed, and GPS positioning accuracy; Use the SM3 hashing algorithm to process the system key and the derived parameters to obtain the third SM3 hash value, and take the first 256 bits of the third SM3 hash value as the 256-bit task key for encrypting the data generated in the current flight phase ; The task key Is represented by the formula: ; ; Among them, Represents the derived parameter, Represents the sensor noise value, Represents the start timestamp of the current flight phase, Represents the dynamic flight parameter, Represents the third SM3 hash value.
[0019] Optionally, when the drone needs to communicate with the ground station or other drones during the current flight phase, obtain the current environmental risk level, and based on the task key and environmental risk level corresponding to the current flight phase, use the hashing algorithm to derive an interaction key for encrypting the data of this communication, including: When the drone needs to communicate with the ground station or other drones during the current flight phase, generate a random number through a true random number generator , and obtain the current communication delay jitter and GPS signal loss duration; Through the following formula, calculate the current environmental risk level based on the communication delay jitter and GPS signal loss duration , and then calculate the number of iterations ; ; ; Among them, Represents the communication delay jitter, Represents the GPS signal loss duration; Use the SM3 hashing algorithm based on KDF to process the task key , the generated random number , environmental risk level and the number of iterations are processed to obtain a key stretching value, and the first 256 bits of the key stretching value are taken as the 256-bit interactive key for encrypting the data of this communication ; The interactive key is represented by the formula as: ; wherein, represents the key stretching value, represents the SM3 hash algorithm based on KDF
[0020] Optionally, when there is a new task key , the following steps are performed for local key distribution: Use the most recent interactive key to encrypt the new task key , and send the encrypted ciphertext information to each execution agency of the local machine; Each execution agency of the local machine uses to decrypt the ciphertext information and verify the HMAC signature. After successfully verifying the HMAC signature, obtain , and return an acknowledgment signal; After receiving the acknowledgment signals returned by each execution agency, broadcast to each execution agency an effective instruction and destroy the old task key .
[0021] Optionally, when the drone is performing a flight mission, a task start planned time node and a task end planned time node are preset. If the corresponding flight mission has not started when reaching the task start planned time node, or the corresponding flight mission has not been completed when reaching the task end planned time node, then immediately based on the system key and the preset emergency root key, use the hash algorithm to derive a temporary emergency key and start the backup link to ensure communication security; during the whole process of the drone performing the flight mission, continuously detect whether the change rate of the sensor data exceeds the preset change threshold. When it is detected that the change rate of the sensor data exceeds the preset change threshold, immediately based on the system key and the emergency root key, use the hash algorithm to derive a temporary emergency key and start the backup link to ensure communication security Description of the Drawings
[0022] To more clearly illustrate the embodiments of the present application or the technical solutions in the related art, the following will briefly introduce the drawings required for use in the description of the embodiments of the present application or the related art. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0023] Figure 1 is a flowchart of a method for constructing a dynamic key trust chain of an unmanned control system based on Feiteng E2000 TCM provided in an embodiment of the present application; Figure 2 is a schematic diagram of a flight stage and its subdivision provided in an embodiment of the present application; Figure 3 is a flowchart of local key distribution for a new task key provided in an embodiment of the present application; Figure 4 is a schematic structural diagram of a device for constructing a dynamic key trust chain of an unmanned control system based on Feiteng E2000 TCM provided in another embodiment of the present application; Figure 5 is a schematic structural diagram of an electronic device provided in another embodiment of the present application. Detailed implementation manners
[0024] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the following will elaborate on each embodiment of the present application in conjunction with the drawings. However, those of ordinary skill in the art can understand that in each embodiment of the present application, many technical details are provided to help readers better understand the present application. However, even without these technical details and various changes and modifications based on the following embodiments, the technical solutions claimed in the present application can still be implemented. The following division of each embodiment is for convenience of description and should not constitute any limitation on the specific implementation manner of the present application. Each embodiment can be combined and cross-referenced with each other on the premise of not being contradictory.
[0025] An embodiment of the present application proposes a method for constructing a dynamic key trust chain of an unmanned control system based on Feiteng E2000 TCM, which is applicable to the flight control system of an unmanned aerial vehicle and is applied to a device for constructing a dynamic key trust chain of the flight control system, hereinafter simply referred to as the construction device. The following specifically describes the implementation details of a method for constructing a dynamic key trust chain of an unmanned control system based on Feiteng E2000 TCM proposed in this embodiment. The following content is only implementation details provided for convenience of understanding and is not necessary for implementing this solution.
[0026] The specific process of a method for constructing a dynamic key trust chain of an unmanned control system based on Feiteng E2000 TCM proposed in this embodiment can be asFigure 1 As shown in the figure, it includes: Step 101: Use the TCM of Feiteng E2000 to generate a non-exportable hardware root key as the starting point of the entire trust chain.
[0027] In a specific implementation, the building device first constructs the starting point of the entire trust chain, which depends on the TCM of Feiteng E2000 to achieve. The TCM is a secure hardware module that can securely store keys and verify startup integrity. The building device uses the TCM of Feiteng E2000 to generate a non-exportable hardware root key as the starting point of the entire trust chain, that is, as the source for deriving all child keys. The hardware root key has the longest life cycle and will be permanently stored in the TCM.
[0028] In an example, when the building device constructs the hardware root key, it first generates random bits through the true random number generator (TRNG) built into the TCM of Feiteng E2000. Subsequently, the SM3 hashing algorithm is used to process the random bits generated by the true random number generator to obtain the first SM3 hash value, and the first 256 bits of the first SM3 hash value are taken as the 256-bit hardware root key. . Finally, the hardware root key is written into the secure storage area of the TCM, and export and external access are prohibited to ensure the security of the hardware root key to the greatest extent. security.
[0029] In an example, the hardware root key is represented by the formula: ; where represents the random bits generated by the true random number generator, represents the first SM3 hash value, represents the SM3 hashing algorithm, represents taking the first 256 bits.
[0030] Step 102: After the flight control system of the drone is powered on and initialized, based on the hardware root key and the device unique identification code of the flight control system of the drone, use the hashing algorithm to derive a system key for encrypting the firmware and core algorithms of the flight control system of the drone.
[0031] In a specific implementation, the hardware root key is the origin of the entire trust chain, and the next-level key is the system key derived from the hardware root key. After obtaining the hardware root key, the construction device waits for the flight control system of the drone to be powered on and start, and continues to wait for the flight control system of the drone to be initialized. After the initialization is completed, based on the hardware root key and the device unique identification code of the flight control system of the drone, the system key for encrypting the firmware and core algorithm of the flight control system of the drone is derived using the hash algorithm. The life cycle of the system key is a single mission cycle, starting from the power-on and startup of the flight control system of the drone and the completion of initialization, and ending with the power-off after the drone lands.
[0032] In one example, when deriving the system key, the construction device waits for the flight control system of the drone to be powered on and start, and continues to wait for the flight control system of the drone to be initialized. After the initialization is completed, the basic parameter configuration is first verified, including the basic parameter configuration of the sensor, the basic parameter configuration of the processor, and the interface configuration, etc. When the verification of the basic parameter configuration passes, the device unique identification code of the flight control system and the fixed salt value preset in the TCM are read. Subsequently, the hardware root key 、the device unique identification code of the flight control system and the fixed salt value are processed using the SM3 hash algorithm to obtain the second SM3 hash value, and the first 256 bits of the second SM3 hash value are taken as the 256-bit system key for encrypting the firmware and core algorithm of the flight control system of the drone .
[0033] In one example, the system key is represented by the formula: ; where, represents the device unique identification code of the flight control system, represents the fixed salt value, represents a separator that does not affect the logic, represents the second SM3 hash value.
[0034] In one example, when the drone lands and powers off, all the flight tasks of this time have been completed, and the flight control system will also enter the sleep state. The system key of this time will also become invalid and needs to be destroyed immediately.
[0035] In one example, there is a valid fault-tolerant key reserved in the TCM. When deriving the system key, if the derivation fails three times in a row, this fault-tolerant key is used as the system key and an alarm is triggered, which not only ensures the security of the drone system but also can solve the problem of key derivation failure in the shortest time. This technology will be adopted subsequently when deriving task keys and interaction keys, and will not be elaborated further hereafter.
[0036] Step 103: After the UAV takes off, determine the current flight phase. Based on the system key and the identifier of the current flight phase, use the hash algorithm to derive a task key for encrypting the data generated in the current flight phase.
[0037] In a specific implementation, after the UAV takes off, the construction device needs to determine the current flight phase in real time. Based on the system key and the identifier of the current flight phase, use the hash algorithm to derive a task key for encrypting the data generated in the current flight phase.
[0038] In one example, as Figure 2 shown, the flight phase of the UAV can be divided into three main phases: takeoff phase, cruise phase, and landing phase. Each main phase can be further divided into three sub - phases. The takeoff phase can be divided into three sub - phases: taxiing phase, liftoff phase, and climbing phase. The cruise phase can be divided into three sub - phases: level flight phase, turning phase, and adjustment phase (including speed and altitude adjustment). The landing phase can be divided into three sub - phases: descent phase, approach phase, and touchdown phase.
[0039] After the UAV takes off, the construction device needs to read the identifier of the flight phase to determine the current flight phase (both the main phase and the sub - phase can be read out through ), represents the takeoff phase, represents the cruise phase, represents the landing phase.
[0040] In the sub - phases of the takeoff phase, represents the taxiing phase, represents the liftoff phase, represents the climbing phase.
[0041] In the sub - phases of the cruise phase, represents the level flight phase, represents the turning phase, represents the adjustment phase.
[0042] In the sub - phases of the landing phase, represents the descent phase, represents the approach phase, represents the touchdown phase.
[0043] After determining the current flight phase, the construction device will read the start timestamp of the current flight phase, obtain the sensor noise value and dynamic flight parameters, and then based on the identifier of the current flight phase , construct derived parameters using the start timestamp of the current flight phase, the sensor noise value, and the dynamic flight parameters. The dynamic flight parameters include, but are not limited to, flight altitude, flight speed, and GPS positioning accuracy.
[0044] Finally, the construction device needs to use the SM3 hashing algorithm to process the system key and the derived parameters to obtain the third SM3 hash value, and take the first 256 bits of the third SM3 hash value as the 256-bit task key for encrypting the data generated in the current flight phase .
[0045] In one example, the task key can be represented by the formula: ; ; where represents the derived parameter, represents the sensor noise value, represents the start timestamp of the current flight phase, represents the dynamic flight parameter, represents the third SM3 hash value.
[0046] In one example, when deriving the task key, the construction device can assign a dynamic weight to the derived parameter (actually to the sensor noise value),
[0047] thereby reducing the impact of abnormal data.
[0048] In one example, when the drone is performing a flight mission, there are preset task start planned time nodes and task end planned time nodes. If the corresponding flight mission has not started when reaching the task start planned time node, or the corresponding flight mission has not been completed when reaching the task end planned time node, then immediately derive a temporary emergency key based on the system key and the preset emergency root key using the hashing algorithm, and activate the backup link to ensure communication security.
[0049] In one example, during the entire process of the drone performing a flight mission, the construction device needs to continuously detect whether the change rate of the sensor data exceeds a preset change threshold. When it is detected that the change rate of the sensor data exceeds the preset change threshold (unexpected situation), then immediately derive a temporary emergency key based on the system key and the emergency root key using the hashing algorithm, and activate the backup link to ensure communication security.
[0050] In one example, if the sensor noise value exceeds a reasonable range (such as a sudden change in the gyroscope reading exceeding the threshold), the historical sliding window mean can be used to replace the outlier.
[0050] In one example, after detecting a flight phase switch, the construction device needs to immediately destroy the task key corresponding to the flight phase before the switch, fundamentally preventing the occurrence of key theft incidents.
[0051] Step 104, when the UAV needs to communicate with the ground station or other UAVs in the current flight phase, obtain the current environmental risk level, and based on the task key corresponding to the current flight phase and the environmental risk level, use the hash algorithm to derive an interaction key for encrypting the data of this communication.
[0052] In a specific implementation, during the execution of the flight mission of the UAV, data information such as position coordinates, attitude data, star force intensity and quantity will be transmitted to the ground station or other UAVs in real time. During the communication process of the data link, it is vulnerable to risks such as signal interference, electromagnetic signal suppression, and false satellite signal spoofing. Therefore, the construction device designs an interaction key at the end of the trust chain. When the UAV needs to communicate with the ground station or other UAVs in the current flight phase, obtain the current environmental risk level, and based on the task key corresponding to the current flight phase and the environmental risk level, use the hash algorithm to derive an interaction key for encrypting the data of this communication.
[0053] In one example, when the UAV needs to communicate with the ground station or other UAVs in the current flight phase, the construction device will generate a random number through a true random number generator , and obtain the current communication delay jitter and GPS signal loss duration.
[0054] Next, through the following formula, based on the communication delay jitter and GPS signal loss duration, calculate the current environmental risk level , and then calculate the number of iterations : ; ; Among them, represents the communication delay jitter, represents the GPS signal loss duration.
[0055] Finally, use the SM3 hash algorithm based on KDF to process the task key , the generated random number , the environmental risk level and the number of iterations to obtain a key stretch value, and take the first 256 bits of the key stretch value as the 256-bit interaction key for encrypting the data of this communication .
[0056] In one example, the interaction key is represented by the formula: ; wherein represents the key stretching value, represents the SM3 hashing algorithm based on KDF.
[0057] In one example, to ensure security, after detecting the completion of the current communication, the construction device will immediately destroy the interaction key corresponding to the current communication.
[0058] In one example, when the communication interference exceeds the preset threshold, the construction device will shorten the interaction key rotation period to 30 seconds, that is, the key can also be changed during the communication process, thereby further enhancing the protection ability.
[0059] In one example, the interaction key is also a tool for secure distribution of task keys.
[0060] When there is a new task key the construction device will perform secure distribution of the local key, use the most recent interaction key to encrypt the new task key and send the encrypted ciphertext information to each execution mechanism of the local machine. Each execution mechanism of the local machine uses to decrypt the ciphertext information and verify the HMAC signature. After successfully verifying the HMAC signature, obtain and return an acknowledgment signal. After receiving the acknowledgment signals returned by each execution mechanism, the construction device broadcasts an activation instruction to each execution mechanism and destroys the old task key . This process can be as Figure 3 shown.
[0061] In one example, when the current unmanned aerial vehicle is the master unmanned aerial vehicle, it is necessary to synchronize and update the task key and the interaction key to other slave vehicles, which needs to be implemented based on the threshold signature scheme of SM2, and more than half of the slave vehicles need to agree to update the key.
[0062] A method for constructing a dynamic key trust chain of an unmanned control system based on Feiteng E2000 TCM proposed in this embodiment makes full use of the hardware security capabilities of Feiteng E2000 TCM. By designing a key dynamic derivation mechanism through a hash algorithm to ensure the uniqueness of the data communication link, the derivation of keys is dynamically random. Illegal personnel and illegal organizations cannot crack and obtain all keys at any time, so they cannot invade the data communication link. This application designs a hierarchical isolation mechanism, and the entire trust chain is derived step by step from "hardware root key, system key, task key, and interaction key", physically isolating the intrusion risk. When deriving the task key, the flight stage of the unmanned aerial vehicle (UAV) is fully considered. At different flight stages, different task keys are derived to dynamically encrypt the data of the flight task, ensuring that the flight task of the UAV is not tampered with. After the flight stage is switched, the old task key is immediately destroyed, and even if the old task key is leaked, it does not affect the latest flight task. When deriving the interaction key, the environmental risk level is fully considered. For different levels of environmental risks, different strengths of interaction keys are derived to encrypt the data of this communication, ensuring the smoothness and unique security of the communication between the UAV and the ground station or other UAVs, and ensuring that the control right of the UAV cannot be hijacked. All in all, the dynamic key trust chain constructed in this application enhances the trusted computing ability of the flight control system of the UAV from the bottom layer, can effectively defend against malicious threats and viruses, and meets the stringent requirements of the flight control system of the UAV for the real-time performance and reliability of security.
[0063] The step division of the above various methods is only for clear description. When implemented, they can be combined into one step, or some steps can be split into multiple steps. As long as the same logical relationship is included, it is within the protection scope of this application. Making insignificant modifications to the algorithm or process or introducing insignificant designs, but not changing the core design of its algorithm and process, are all within the protection scope of this application.
[0064] Another embodiment of this application proposes a device for constructing a dynamic key trust chain of an unmanned control system based on Feiteng E2000 TCM, which is applicable to the flight control system of the UAV. The details of a device for constructing a dynamic key trust chain of an unmanned control system based on Feiteng E2000 TCM proposed in this embodiment are specifically described below. The following content is only implementation details provided for easy understanding and is not necessary for implementing this example. Figure 4 It is a schematic structural diagram of a device for constructing a dynamic key trust chain of an unmanned control system based on Feiteng E2000 TCM proposed in this embodiment, including: a root key generation module 201, a system key derivation module 202, a task key derivation module 203, an interaction key derivation module 204, and a key destruction module 205.
[0065] The root key generation module 201 is used to generate a non-exportable hardware root key by using the TCM of Feiteng E2000 as the starting point of the entire trust chain.
[0066] The system key derivation module 202 is used to, after the flight control system of the unmanned aerial vehicle is powered on and initialized, derive a system key for encrypting the firmware and core algorithms of the flight control system of the unmanned aerial vehicle by using a hash algorithm based on the hardware root key and the device unique identification code of the flight control system of the unmanned aerial vehicle.
[0067] The mission key derivation module 203 is used to, after the unmanned aerial vehicle takes off, determine the current flight phase of the unmanned aerial vehicle, and derive a mission key for encrypting the data generated in the current flight phase by using a hash algorithm based on the system key and the identification of the current flight phase.
[0068] The interaction key derivation module 204 is used to, when it is detected that the unmanned aerial vehicle needs to communicate with a ground station or other unmanned aerial vehicles in the current flight phase, obtain the current environmental risk level, and derive an interaction key for encrypting the data of this communication by using a hash algorithm based on the mission key corresponding to the current flight phase and the environmental risk level.
[0069] The key destruction module 205 is used to immediately destroy the mission key corresponding to the flight phase before the switch after detecting the flight phase switch, and immediately destroy the interaction key corresponding to this communication after detecting the completion of this communication.
[0070] It is not difficult to find that this embodiment is a system embodiment corresponding to the above method embodiment, and this embodiment can be implemented in cooperation with the above method embodiment. The relevant technical details and technical effects mentioned in the above embodiments are still valid in this embodiment. To avoid repetition, they are not elaborated here. Correspondingly, the relevant technical details mentioned in this embodiment can also be applied to the above embodiments.
[0071] It is worth mentioning that each module involved in this embodiment is a logical module. In practical applications, a logical unit can be a physical unit, a part of a physical unit, or a combination of multiple physical units. In addition, to highlight the innovative part of this application, units that are not closely related to solving the technical problems proposed in this application are not introduced in this embodiment, but this does not mean that there are no other units in this embodiment.
[0072] Another embodiment of this application proposes an electronic device, and its specific structure can be as Figure 5As shown in the figure, it includes: at least one processor 301; and a memory 302 communicatively connected to the at least one processor 301; wherein, the memory 302 stores instructions executable by the at least one processor 301, and the instructions are executed by the at least one processor 301 to enable the at least one processor 301 to execute a method for constructing a dynamic key trust chain of an unmanned control system based on Feiteng E2000 TCM as described in the above method embodiments.
[0073] Among them, the memory and the processor are connected by a bus. The bus may include any number of interconnected buses and bridges, and the bus connects various circuits of one or more processors and the memory together. The bus may also connect various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art, so they will not be further described herein. The bus interface provides an interface between the bus and the transceiver. The transceiver may be an element or multiple elements, such as multiple receivers and transmitters, and provides a unit for communicating with various other devices on the transmission medium. The data processed by the processor is transmitted on the wireless medium through the antenna. Further, the antenna also receives data and transmits the data to the processor.
[0074] The processor is responsible for managing the bus and general processing, and can also provide various functions, including timing, peripheral interface, voltage regulation, power management, and other control functions. The memory can be used to store the data used by the processor when executing operations.
[0075] Another embodiment of the present application proposes a computer-readable storage medium storing a computer program, which when executed by a processor, can implement a method for constructing a dynamic key trust chain of an unmanned control system based on Feiteng E2000 TCM as described in the above method embodiments.
[0076] That is, those skilled in the art can understand that all or part of the steps in implementing the above method embodiments can be completed by instructing relevant hardware through a program. This program is stored in a storage medium, including several instructions for enabling a device (which can be a single-chip microcomputer, a chip, etc.) or a processor to execute all or part of the steps of the method described in various embodiments of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories, random access memories, magnetic disks, or optical discs that can store program codes.
[0077] Those of ordinary skill in the art can understand that the above embodiments are specific embodiments for implementing the present application, and in practical applications, various changes can be made in form and details without departing from the spirit and scope of the present application.
Claims
1. A method for constructing a dynamic key trust chain of an unmanned control system based on Feiteng E2000 TCM, applicable to the flight control system of an unmanned aerial vehicle, characterized in that The method includes: Using the TCM of Feiteng E2000 to generate an unexportable hardware root key as the starting point of the entire trust chain; After the flight control system of the unmanned aerial vehicle (UAV) is powered on and initialized, based on the hardware root key and the device unique identification code of the flight control system of the UAV, use the hash algorithm to derive a system key for encrypting the firmware and core algorithms of the flight control system of the UAV; After the UAV takes off, determine the current flight phase, and based on the system key and the identification of the current flight phase, use the hash algorithm to derive a task key for encrypting the data generated in the current flight phase; When the UAV needs to communicate with the ground station or other UAVs during the current flight phase, obtain the current environmental risk level, and based on the task key corresponding to the current flight phase and the environmental risk level, use the hash algorithm to derive an interaction key for encrypting the data of this communication; Among them, after detecting the flight phase switch, immediately destroy the task key corresponding to the flight phase before the switch, and after detecting the completion of this communication, immediately destroy the interaction key corresponding to this communication.
2. A method for constructing a dynamic key trust chain of an unmanned control system based on Feiteng E2000 TCM according to claim 1, characterized in that, Using the TCM of Feiteng E2000 to generate an unexportable hardware root key as the starting point of the entire trust chain includes: Generating random bits through the true random number generator built into the TCM of Feiteng E2000; Process the random bits generated by the true random number generator using the SM3 hash algorithm to obtain the first SM3 hash value, and take the first 256 bits of the first SM3 hash value as the 256-bit hardware root key ; Write the hardware root key into the secure storage area of the TCM, and prohibit export and external access; Hardware root key It is expressed by the formula as follows: ; Wherein, represents the random bits generated by the true random number generator, represents the first SM3 hash value, represents the SM3 hash algorithm, represents taking the first 256 bits.
3. The method for constructing a dynamic key trust chain of an unmanned control system based on Feiteng E2000 TCM according to claim 2, characterized in that, After the flight control system of the UAV is powered on and initialized, based on the hardware root key and the device unique identification code of the flight control system of the UAV, using the hash algorithm to derive a system key for encrypting the firmware and core algorithms of the flight control system of the UAV includes: After the flight control system of the UAV is powered on and initialized, first perform the verification of the basic parameter configuration; If the verification of the basic parameter configuration passes, read the device unique identification code of the flight control system and the fixed salt value preset in the TCM; Process the hardware root key the device unique identification code of the flight control system and the fixed salt value by using the SM3 hashing algorithm to obtain a second SM3 hash value, and take the first 256 bits of the second SM3 hash value as the 256-bit system key for encrypting the firmware and core algorithms of the flight control system of the drone ; System key It is expressed by the formula as follows: ; Among them, represents the unique device identification code of the flight control system, represents the fixed salt value, represents a separator that does not affect the logic, represents the second SM3 hash value.
4. A method for constructing a dynamic key trust chain of an unmanned control system based on Feiteng E2000 TCM according to claim 3, characterized in that, The flight phases of the UAV include the takeoff phase, the cruise phase, and the landing phase. After the UAV takes off, determine the current flight phase, and based on the system key and the identification of the current flight phase, use the hash algorithm to derive a task key for encrypting the data generated in the current flight phase includes: After the drone takes off, read the identifier of the flight phase to determine the current flight phase, indicating the takeoff phase, indicating the cruise phase, indicating the landing phase; Read the start timestamp of the current flight phase, obtain the sensor noise value and dynamic flight parameters, and construct derived parameters based on the identifier of the current flight phase Construct derived parameters based on , the start timestamp of the current flight phase, the sensor noise value, and the dynamic flight parameters; wherein, the dynamic flight parameters include flight altitude, flight speed, and GPS positioning accuracy; Process the system key and the derived parameters using the SM3 hashing algorithm to obtain a third SM3 hash value, and take the first 256 bits of the third SM3 hash value as the 256-bit task key for encrypting the data generated in the current flight phase ; Task key Expressed by the formula as: ; ; Among them, represents a derived parameter, represents the sensor noise value, represents the start timestamp of the current flight phase, represents the dynamic flight parameter, represents the third SM3 hash value.
5. A method for constructing a dynamic key trust chain of an unmanned control system based on Feiteng E2000 TCM according to claim 4, wherein, When the UAV needs to communicate with the ground station or other UAVs during the current flight phase, obtain the current environmental risk level, and based on the task key corresponding to the current flight phase and the environmental risk level, use the hash algorithm to derive an interaction key for encrypting the data of this communication includes: When the drone needs to communicate with the ground station or other drones during the current flight phase, a random number is generated by a true random number generator , and the current communication delay jitter and GPS signal loss duration are obtained; Based on the communication delay jitter and the duration of GPS signal loss, the current environmental risk level is calculated through the following formula , and then the number of iterations is calculated ; ; ; Among them, represents communication delay jitter, represents the duration of GPS signal loss; Use the SM3 hashing algorithm based on KDF for the task key , the generated random number , the environmental risk level and the number of iterations for processing to obtain the key stretching value, and take the first 256 bits of the key stretching value as the 256-bit interactive key for encrypting the data of this communication ; Interaction key Expressed by the formula as: ; Among them, represents the key stretching value, represents the SM3 hashing algorithm based on KDF.
6. A method for constructing a dynamic key trust chain of an unmanned control system based on Feiteng E2000 TCM, characterized in that, When there is a new task key the following steps are taken for local key distribution: Use the most recent interaction key to encrypt the new task key and send the ciphertext information generated by the encryption to each execution agency of this machine; Used by each actuator of this machine Decrypt the ciphertext information and verify the HMAC signature. After successfully verifying the HMAC signature, obtain , and return an acknowledgement signal; After receiving the confirmation signals returned by each executing agency, broadcast to each executing agency the effective instruction and destroy the old task key .
7. A method for constructing a dynamic key trust chain of an unmanned control system based on Feiteng E2000 TCM according to any one of claims 1 to 6, characterized in that, When the UAV is performing a flight mission, a task start planned time node and a task end planned time node are preset. If the corresponding flight mission has not started when reaching the task start planned time node, or the corresponding flight mission has not been completed when reaching the task end planned time node, then immediately based on the system key and the preset emergency root key, use the hash algorithm to derive a temporary emergency key and start the backup link to ensure communication security; During the entire process of the UAV performing flight missions, it is necessary to detect in real time whether the change rate of the sensor data exceeds a preset change threshold. When it is detected that the change rate of the sensor data exceeds the preset change threshold, a temporary emergency key is immediately derived using the hash algorithm based on the system key and the emergency root key, and the backup link is activated to ensure communication security.
8. A dynamic key trust chain construction device for an unmanned control system based on Feiteng E2000 TCM, applicable to the flight control system of an unmanned aerial vehicle, characterized in that, The system includes: A root key generation module, which is used to generate a non-exportable hardware root key using the TCM of Feiteng E2000 as the starting point of the entire trust chain; A system key derivation module, which is used to derive a system key for encrypting the firmware and core algorithms of the UAV's flight control system using the hash algorithm based on the hardware root key and the device unique identification code of the UAV's flight control system after the flight control system of the UAV is powered on and initialized; A task key derivation module, which is used to determine the current flight phase of the UAV after the UAV takes off, and derive a task key for encrypting the data generated in the current flight phase using the hash algorithm based on the system key and the identification of the current flight phase; An interaction key derivation module, which is used to obtain the current environmental risk level when it is detected that the UAV needs to communicate with the ground station or other UAVs in the current flight phase, and derive an interaction key for encrypting the data of this communication using the hash algorithm based on the task key corresponding to the current flight phase and the environmental risk level; A key destruction module, which is used to immediately destroy the task key corresponding to the flight phase before the switch after detecting the flight phase switch, and immediately destroy the interaction key corresponding to this communication after detecting the completion of this communication.
9. An electronic device, characterized in that, It includes: At least one processor; And a memory communicatively connected to the at least one processor; Wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute a method for constructing a dynamic key trust chain of an unmanned control system based on Feiteng E2000 TCM as described in any one of claims 1 to 7.
10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it can implement a method for constructing a dynamic key trust chain of an unmanned control system based on Feiteng E2000 TCM as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Double-control key management method and system, encryption machine and storage medium
CN114499825A
Key service method and device, and storage medium
CN119276469A
Unmanned aerial vehicle inspection traffic control system and method based on chaotic system
CN119946201A
KR20250063424A
Cited By
Shipborne communication data encryption transmission method and system based on satellite 5G fusion network
CN121218162A
Unmanned aerial vehicle flight control and data transmission integrated safety protection system
CN121386871A
Unified module for protecting information channels of unmanned aircraft systems
RU243229U1