Emergency communication method, system and device based on unmanned aerial vehicle and storage medium
Through the drone-based emergency communication method, preset emergency geofence authentication and dynamic QoS strategy are used, combined with dual-path transmission of satellite-based and ground user-surface functional nodes, the problem of communication obstruction in traditional communication networks during disasters is solved, and efficient and safe emergency communication services are achieved.
Patent Information
- Application Number
- CN202510559836.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-30
- Publication Date
- 2025-08-08
AI Technical Summary
Traditional communication networks cannot work properly due to infrastructure damage, power interruption or network congestion when disasters occur, resulting in the communication between rescuers and the outside world being blocked, affecting the rescue efficiency and the accuracy of command and dispatch. In addition, the existing emergency communication systems of drones and satellites have problems such as insufficient security, poor data encryption flexibility, weak transmission optimization capabilities, and slow failover speed.
UAV-based emergency communication method is adopted, and through preset emergency geofence authentication, dynamic QoS policy, layered encryption and multicast distribution processing, combined with dual-path transmission of satellite-mounted and ground user-surface functional nodes, fast access, secure transmission and failover are achieved to ensure the reliability and security of the communication system.
It improves the efficiency and security performance of emergency communication, can quickly deploy and provide high-reliability communication services in complex disaster environments, ensuring the security and continuity of data transmission.
Smart Images

Figure CN120455979A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of emergency communication technology, and in particular to an emergency communication method, system, device and storage medium based on a drone. Background Art
[0002] At the scene of emergency rescue, fast and reliable communications are crucial for rescue and emergency response. Traditional communication networks often malfunction during disasters due to infrastructure damage, power outages, or network congestion. This hinders rescue workers' ability to communicate with the outside world, severely impacting rescue efficiency and the accuracy of command and dispatch. Furthermore, the complex environment at disaster sites places higher demands on the communication system's coverage, transmission speed, anti-interference capabilities, and security.
[0003] In related technologies, emergency communications are achieved through the collaboration of drones and satellites. However, there are still problems with low transmission efficiency and poor security performance. Summary of the Invention
[0004] The purpose of the present invention is to solve one of the technical problems existing in the prior art to at least a certain extent.
[0005] To this end, the purpose of the present invention is to provide an efficient drone-based emergency communication method, system, device and storage medium.
[0006] In order to achieve the above technical objectives, one aspect of an embodiment of the present invention provides an emergency communication method based on a drone, comprising the following steps: obtaining video data through a target terminal, and if the location of the target terminal enters a preset emergency geofence, issuing an access request and establishing a session between the target terminal and the communication network; wherein the preset emergency geofence corresponds to the target terminal; uploading the video data to a user plane function node, performing secure transmission and multicast distribution processing on the video data; and dynamically adjusting the transmission strategy and resource allocation according to network status and environmental changes; and performing security cleanup if the task based on the video data is completed or the emergency situation is resolved. This application can achieve efficient communication by adjusting the transmission strategy and resource allocation, and combining secure transmission and multicast distribution processing of the video data, which is beneficial to improving the efficiency and safety performance of emergency communications.
[0007] In some embodiments, the method further comprises:
[0008] The access request is subjected to a three-way check by the access and mobility management function, including:
[0009] Perform ephemeris matching;
[0010] Determining whether the target terminal is located within a preset emergency geo-fence by decrypting the location of the target terminal;
[0011] Perform a timeliness check on the timestamp in the access request.
[0012] In some embodiments, establishing a session between the target terminal and the communication network includes:
[0013] Dynamically configure session policies through session management capabilities;
[0014] The policy control function generates dynamic QoS policies based on real-time network status analysis using the network data analysis function, including:
[0015] Based on satellite latency, it is determined to lower the service quality level, reduce bandwidth guarantees, and activate the dual-path parallel transmission mechanism.
[0016] In some embodiments, uploading the video data to a user plane function node and performing secure transmission and multicast distribution processing on the video data includes:
[0017] Perform physical layer dynamic anti-interference;
[0018] The data payload is encrypted using a quantum key pool, and the key index is distributed via a secure control channel;
[0019] Processing the video data in layers, and determining the received data layer according to different terminal types and capabilities;
[0020] Add signatures to video key frames and high-risk targets. If the signature verification fails, the three-level response mechanism is triggered.
[0021] In some embodiments, dynamically adjusting transmission strategies and resource allocation according to network status and environmental changes includes:
[0022] Dynamically adjust the level of modulation and coding scheme according to channel quality;
[0023] If the predicted satellite overpass time is less than the preset time, the quantum key pool is reset;
[0024] Dynamically adjust slice quotas based on the weight of encryption overhead.
[0025] In some embodiments, the method further comprises:
[0026] Monitor satellite link quality and switch to a backup path if the primary path fails;
[0027] Set the backup path to single-layer encrypted multicast to ensure continuous data transmission;
[0028] If satellite link fluctuations are detected, the enhancement layer bit rate is reduced to increase the base layer redundancy;
[0029] If the number of group members is greater than the preset group member threshold, broadcast optimization mode is enabled.
[0030] In some embodiments, the security cleanup is achieved by the following steps:
[0031] Send a termination instruction with a preset termination tag through the emergency command center;
[0032] Perform several random code overwriting operations on the quantum key storage area;
[0033] Record the service level agreement compliance rate and generate security audit reports to determine service termination.
[0034] On the other hand, an embodiment of the present invention provides an emergency communication system based on a drone, comprising:
[0035] A first module is configured to acquire video data from a target terminal, and if the location of the target terminal enters a preset emergency geofence, issue an access request and establish a session between the target terminal and a communication network; wherein the preset emergency geofence corresponds to the target terminal;
[0036] The second module is used to upload the video data to the user plane function node, perform secure transmission and multicast distribution processing on the video data; and dynamically adjust the transmission strategy and resource allocation according to network status and environmental changes;
[0037] The third module is used to perform safety cleanup if the task based on the video data is completed or the emergency situation is resolved.
[0038] On the other hand, an embodiment of the present invention provides an emergency communication device based on a drone, comprising:
[0039] at least one processor;
[0040] at least one memory for storing at least one program;
[0041] When the at least one program is executed by the at least one processor, the at least one processor implements the above-mentioned drone-based emergency communication method.
[0042] On the other hand, an embodiment of the present invention provides a storage medium storing a program executable by a processor, wherein the program executable by the processor is used to implement the above-mentioned drone-based emergency communication method when executed by the processor.
[0043] The embodiments of the present application include at least the following beneficial effects: the method provided by the embodiments of the present invention includes: obtaining video data through a target terminal, and if the location of the target terminal enters a preset emergency geofence, issuing an access request and establishing a session between the target terminal and the communication network; wherein the preset emergency geofence corresponds to the target terminal; uploading the video data to a user plane function node, performing secure transmission and multicast distribution processing on the video data; and dynamically adjusting the transmission strategy and resource allocation according to network status and environmental changes; and performing security cleanup if the task based on the video data is completed or the emergency situation is resolved. The present application can achieve efficient communication by adjusting the transmission strategy and resource allocation, combined with secure transmission and multicast distribution processing of the video data, which is conducive to improving the efficiency and safety performance of emergency communications. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following introduction is made to the drawings of the embodiments of the present invention or the related technical solutions in the prior art. It should be understood that the drawings introduced below are only for the convenience of clearly describing some embodiments of the technical solutions of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without any creative work.
[0045] Figure 1 A flowchart of an embodiment of the emergency communication method based on a drone provided by the present invention;
[0046] Figure 2 A schematic diagram of the modules corresponding to the UAV emergency communication method provided by the present invention;
[0047] Figure 3 A flowchart of another embodiment of the drone-based emergency communication method provided by the present invention;
[0048] Figure 4 A schematic structural diagram of an embodiment of a drone-based emergency communication system provided by the present invention;
[0049] Figure 5 A schematic structural diagram of an embodiment of a drone-based emergency communication device provided by the present invention. DETAILED DESCRIPTION
[0050] The embodiments of the present invention are described in detail below, examples of which are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present invention and are not to be construed as limiting the present invention. The step numbers in the following embodiments are provided for ease of explanation only and do not limit the order of the steps. The order of execution of the steps in the embodiments can be adaptively adjusted according to the understanding of those skilled in the art.
[0051] The present invention relates to a disaster site emergency communication system. First, the terms involved in the present invention are explained:
[0052] 1. Emergency Geofencing: A pre-set geographic area boundary that limits drones to trigger emergency communication access requests within a specific area. When a drone enters this area, the system automatically initiates the emergency communication process.
[0053] 2. User Plane Function-Satellite (UPF-SAT): A satellite-based user plane function node (UPF-SAT) is a primary path node that supports transmission protocols optimized for space environments (such as enhanced VXLAN), tolerates high latency, and performs data encryption and transmission.
[0054] 3. Ground UPF-GND (User Plane Function-Ground): The ground user plane function node, located in the ground edge data center, serves as a backup node and is configured with an IPsec secure tunnel and uses the military-grade AES-256-GCM encryption algorithm. It is used to switch to the ground backup network in the event of a satellite link failure.
[0055] 4. Quantum Key Distribution (QKD): A technology that uses the principles of quantum mechanics to distribute keys. It can provide highly secure encryption keys for the encryption process of data transmission and ensure the security of communications.
[0056] 5. Enhanced VXLAN Protocol: A virtual extended local area network protocol optimized for space environments. It supports efficient data transmission over satellite links, can tolerate propagation delays of up to 300ms, and allows a certain degree of packet loss.
[0057] 6. Forward Error Correction (FEC): A coding technique used to correct errors during data transmission. By adding redundant information at the sending end, the receiving end can automatically detect and correct errors that occur during transmission, enhancing the signal's resistance to interference.
[0058] 7.5QI (5G QoS Indicator): A parameter used to identify the service quality level in 5G networks. Different 5QI values correspond to different service quality requirements, such as latency and packet loss rate, and are used to dynamically adjust network resource allocation.
[0059] 8. NWDAF (Network Data Analytics Function): This function is used to analyze network status in real time, including channel quality, load, encryption performance, etc., providing data support for network optimization and dynamic adjustment.
[0060] 9.SM9 algorithm: An identity-based encryption algorithm used to encrypt and verify signatures to ensure data integrity and security.
[0061] 10. DVB-S2X standard: A digital video broadcasting standard used for basic layer transmission in satellite communications, with the characteristics of wide coverage and strong compatibility.
[0062] 11.NR MBS standard: 5G new air interface multicast broadcast standard, used for high-order modulation transmission of the enhancement layer, supporting higher transmission rates and better spectrum efficiency.
[0063] 12. SLA (Service Level Agreement): A service level agreement used to define and measure the service quality standards agreed upon between the service provider and the user, including indicators such as availability, performance, and security.
[0064] At the scene of emergency rescue, fast and reliable communications are crucial for rescue and emergency response. Traditional communication networks often fail to function properly during disasters due to infrastructure damage, power outages, or network congestion. This hinders rescue workers' ability to communicate with the outside world, severely impacting rescue efficiency and the accuracy of command and dispatch. Furthermore, the complex environment of disaster sites places higher demands on the communication system's coverage, transmission speed, anti-interference capabilities, and security. Therefore, developing an emergency communication system that can be rapidly deployed, efficiently operated, and highly reliable in complex disaster environments is crucial.
[0065] In recent years, the rapid development of drone and satellite communication technologies has provided new solutions for emergency communications. Drones, with their maneuverability and rapid deployment, can quickly reach disaster sites and provide communication relay services. Satellite communications, on the other hand, offer wide coverage, long transmission distances, and are unrestricted by terrain, providing reliable communication links even when ground-based communication networks are down. Combining drone and satellite communication technologies to build a collaborative emergency communication system can leverage the strengths of both and meet the emergency communication needs of disaster sites.
[0066] Although existing technologies have made certain progress in the field of coordinated emergency communications between drones and satellites, there are still some shortcomings. First, the access authentication mechanism of the existing system is relatively simple, lacking comprehensive verification of the drone's identity, making it vulnerable to access attacks by illegal devices, resulting in increased communication security risks. Secondly, existing technologies mostly use a single encryption algorithm for data encryption, which lacks flexibility and dynamic adjustment capabilities, making it difficult to meet encryption requirements in complex environments. In addition, the existing system performs poorly in transmission optimization and fails to fully consider the dynamic changes of satellite links and the load conditions of ground networks, resulting in low transmission efficiency. Finally, existing technologies have obvious defects in fault switching speed and security cleanup after emergency termination. They are unable to quickly restore communications or completely destroy keys, affecting the reliability and security of the system.
[0067] In response to the shortcomings of existing technologies, the present invention aims to provide an emergency communication system and method based on the collaboration of drones and satellites to address the problems of insufficient security, poor data encryption flexibility, weak transmission optimization capabilities, and slow fault switching speeds in existing technologies. The present invention ensures that only legitimate devices can access the communication network through an innovative access authentication mechanism; adopts dynamic encryption algorithm switching and multi-layer encryption strategies to improve the security and flexibility of data transmission; optimizes data transmission efficiency by monitoring network status in real time and dynamically adjusting transmission strategies; and can quickly switch to a backup path when the primary path fails and quickly perform security cleanup after the mission is terminated, ensuring the reliability and security of the system.
[0068] The following describes in detail an emergency communication method and system based on a drone according to an embodiment of the present invention with reference to the accompanying drawings. First, the emergency communication method based on a drone according to an embodiment of the present invention will be described with reference to the accompanying drawings.
[0069] Reference Figure 1In an embodiment of the present invention, a drone-based emergency communication method is provided. The drone-based emergency communication method in the embodiment of the present invention can be applied to a terminal, a server, or software running in a terminal or a server. The terminal can be a tablet computer, a laptop computer, a desktop computer, etc., but is not limited thereto. The server can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms. The drone-based emergency communication method in the embodiment of the present invention mainly includes the following steps:
[0070] S100: Acquire video data through a target terminal. If the location of the target terminal enters a preset emergency geofence, issue an access request and establish a session between the target terminal and a communication network; wherein the preset emergency geofence corresponds to the target terminal.
[0071] S200: Uploading the video data to a user plane function node, performing secure transmission and multicast distribution processing on the video data; and dynamically adjusting transmission strategies and resource allocation according to network status and environmental changes;
[0072] S300: If the task based on the video data is completed or the emergency situation is resolved, perform safety cleanup.
[0073] In some embodiments, the method further comprises:
[0074] The access request is subjected to a three-way check by the access and mobility management function, including:
[0075] Perform ephemeris matching;
[0076] Determining whether the target terminal is located within a preset emergency geo-fence by decrypting the location of the target terminal;
[0077] Perform a timeliness check on the timestamp in the access request.
[0078] Reference Figure 2As shown in the figure, the access authentication module is responsible for secure drone access authentication at disaster sites, ensuring legitimate device access to the communication network. It comprises four submodules: access request generation, additional information processing, three-way verification, and authentication result processing. The access request generation submodule: When a drone enters a preset geofence, it generates an access request containing its device ID, location signature (SM9 encrypted GPS coordinates), and timestamp, and sends it to the satellite gNB. The additional information processing submodule: After receiving the request, the satellite gNB appends the timestamp and orbital parameters (satellite ID, location, and altitude) and forwards the encrypted NGAP message to the AMF via the N2 interface. The three-way verification submodule: The AMF performs ephemeris matching, geofence decryption verification, and timeliness checks on the access request to ensure its legitimacy and timeliness. The authentication result processing submodule: Based on the three-way verification result, the AMF notifies the drone of the success or failure of access. If a failure occurs, a security event log is triggered and the location tracking process is initiated.
[0079] In some embodiments, establishing a session between the target terminal and the communication network includes:
[0080] Dynamically configure session policies through session management capabilities;
[0081] The policy control function generates dynamic QoS policies based on real-time network status analysis using the network data analysis function, including:
[0082] Based on satellite latency, it is determined to lower the service quality level, reduce bandwidth guarantees, and activate the dual-path parallel transmission mechanism.
[0083] This application provides a session establishment module: This module is responsible for establishing sessions between drones and communication networks, and dynamically configuring session policies and resource allocation. It includes four sub-modules: session request initiation, security context attachment, policy configuration and analysis, and resource allocation and notification. Session request initiation sub-module: The drone initiates a PDU session request, including SUPI, DNN, and S-NSSAI, and forwards it to the AMF through the N2 interface of the gNB. Security context attachment sub-module: The AMF attaches the satellite authentication level and QKD status to the session request and forwards the request to the SMF. Policy configuration and analysis sub-module: The SMF interacts with the PCF to dynamically configure the session policy. The PCF subscribes to the network status analysis of the NWDAF, obtains the satellite round-trip delay, ground network load, and encryption algorithm support capabilities, and generates a dynamic QoS policy. Resource allocation and notification sub-module: The SMF selects the onboard UPF-SAT and the ground UPF-GND to implement dual-path configuration based on the policy requirements provided by the PCF, starts end-to-end performance testing, and dynamically adjusts the policy based on the test results, notifying the drone that the session establishment is successful.
[0084] In some embodiments, uploading the video data to a user plane function node and performing secure transmission and multicast distribution processing on the video data includes:
[0085] Perform physical layer dynamic anti-interference;
[0086] The data payload is encrypted using a quantum key pool, and the key index is distributed via a secure control channel;
[0087] Processing the video data in layers, and determining the received data layer according to different terminal types and capabilities;
[0088] Add signatures to video key frames and high-risk targets. If the signature verification fails, the three-level response mechanism is triggered.
[0089] This application provides a data transmission module: This module is responsible for the secure transmission and multicast distribution of drone data to ensure data integrity and efficient transmission. It includes four sub-modules: physical layer anti-interference, data encryption, multicast distribution, and security mechanism. Physical layer anti-interference sub-module: Dynamically adjust the frequency modulation rate according to the satellite elevation angle and interference conditions, and activate the forward error correction mechanism (FEC) to enhance the signal's anti-interference capability. Data encryption sub-module: Use the quantum key pool to encrypt the data payload, and the key index is distributed through a secure control channel. When the key pool capacity is insufficient, switch to AES-256 encryption and send an alarm notification. Multicast distribution sub-module: Divide the data into basic layer (BL), enhancement layer 1 (EL1) and enhancement layer 2 (EL2), and receive different data layers according to different terminal types and capabilities. Security mechanism sub-module: Add SM9 signatures to video key frames and high-risk targets. When the signature verification fails, a three-level response mechanism is triggered, including packet loss retransmission and security event reporting.
[0090] In some embodiments, dynamically adjusting transmission strategies and resource allocation according to network status and environmental changes includes:
[0091] Dynamically adjust the level of modulation and coding scheme according to channel quality;
[0092] If the predicted satellite overpass time is less than the preset time, the quantum key pool is reset;
[0093] Dynamically adjust slice quotas based on the weight of encryption overhead.
[0094] This application provides a dynamic adjustment module: This module is responsible for dynamically adjusting the transmission strategy and resource allocation according to network status and environmental changes. It includes four sub-modules: network status analysis, QoS parameter update, encryption and slicing adjustment, and resource scaling and monitoring. Network status analysis sub-module: NWDAF analyzes the status of the entire network every 30 seconds, including channel quality, load and encryption overhead, and predicts rainfall attenuation in combination with meteorological data, and pushes the results to PCF. QoS parameter update sub-module: PCF dynamically adjusts the modulation and coding scheme (MCS) level according to the analysis results of NWDAF, and dynamically switches the enhancement layer (EL2) according to the network congestion situation. Encryption and slicing adjustment sub-module: Reset the quantum key pool in advance to ensure the freshness of the key. Dynamically adjust the slice quota according to the encryption overhead to allow mission-critical slices to preempt resources. Resource scaling and monitoring sub-module: NSSF performs resource elastic scaling according to PCF instructions, and monitors key indicators such as latency, packet loss rate and encryption throughput to verify the effectiveness of the policy.
[0095] In some embodiments, the method further comprises:
[0096] Monitor satellite link quality and switch to a backup path if the primary path fails;
[0097] Set the backup path to single-layer encrypted multicast to ensure continuous data transmission;
[0098] If satellite link fluctuations are detected, the enhancement layer bit rate is reduced to increase the base layer redundancy;
[0099] If the number of group members is greater than the preset group member threshold, broadcast optimization mode is enabled.
[0100] This application provides a fault switching module: this module is responsible for quickly switching to the backup path when the main path fails to ensure the continuity of data transmission. It includes four sub-modules: main path monitoring, backup path activation, transmission optimization, and multicast optimization. Main path monitoring sub-module: monitors the quality of the satellite link, such as RTT changes and bit error rate. When the main path (UPF-SAT) fails, quickly switch to the backup path (UPF-GND). Backup path activation sub-module: The backup path uses single-layer encrypted multicast to ensure the continuity of data transmission. Dynamically adjust the data layer transmission according to the capabilities of the receiving end. Transmission optimization sub-module: When the satellite link fluctuates, reduce the enhancement layer (EL) bit rate, improve the base layer (BL) redundancy, and optimize resource utilization. Multicast optimization sub-module: When the number of group members exceeds 50, enable the broadcast optimization mode to reduce control signaling overhead.
[0101] In some embodiments, the security cleanup is achieved by the following steps:
[0102] Send a termination instruction with a preset termination tag through the emergency command center;
[0103] Perform several random code overwriting operations on the quantum key storage area;
[0104] Record the service level agreement compliance rate and generate security audit reports to determine service termination.
[0105] This application provides a security cleanup module: This module is responsible for security cleanup after the task is terminated to ensure the security of key information and the integrity of the system. It includes four sub-modules: termination instruction reception, key destruction, security audit, and rapid termination. Termination instruction reception sub-module: The emergency command center sends a termination instruction with the "EMERG_END" label, and the UPF triggers the security cleanup protocol after receiving the instruction. Key destruction sub-module: Overwrite the quantum key storage area and perform 3 random fillings to ensure that the key information is irrecoverable and prevent malicious use. Security audit sub-module: UDM records the service level agreement (SLA) compliance rate, and generates a security audit report that meets relevant standards, recording the entire service process. Rapid termination sub-module: The entire service termination process is completed within 2 seconds to ensure the security and integrity of the system.
[0106] The method provided by this application is described in detail below with a specific embodiment:
[0107] S1. At the disaster site, a drone, acting as a terminal device (UE), initiates the emergency communication protocol and begins capturing a 4K infrared video stream for on-site rescue and emergency response. When the drone's location coordinates enter a pre-set emergency geofence (set in advance), the access request process is triggered. The secure access authentication phase then begins. The UE first generates an access request, which includes a device ID, location signature, and timestamp information. The location signature encrypts the drone's GPS coordinates using the SM9 algorithm. Upon receiving the UE's access request, the satellite gNB appends the timestamp and current orbital parameters (satellite ID, satellite position, and satellite altitude). After appending this information, the gNB forwards the encrypted NGAP message to the AMF via the N2 interface, which then passes the UE's request to the core network. Upon receiving the access request, the AMF performs a three-way check. First, it performs an ephemeris match, querying the satellite's expected position in the database based on the satellite ID and comparing it with the satellite position in the request to ensure an error of less than 5 kilometers. Next, the AMF performs geofence decryption verification, using the SM9 algorithm provided by the UDM to decrypt the UE's location signature to ensure the UE is within the pre-set geofence. Finally, the AMF performs a timeliness check, verifying the deviation between the timestamp in the request and the network time, ensuring that the deviation does not exceed 10 seconds. If all verifications (three-way verification) pass, the AMF notifies the UE of the successful access and proceeds to the next step. If the verification fails, the AMF triggers a security time log (types include: unknown satellite anomaly / invalid location signature / time synchronization attack) and initiates the drone positioning and tracking program.
[0108] After S2 access is approved, the UE initiates a PDU session request containing the SUPI, DNN, and S-NSSAI, which is forwarded to the AMF via the gNB's N2 interface. The AMF then attaches security context information to the message, including the satellite authentication level (1-3, with 3 being the highest; initially 3) and the quantum key distribution (QKD) status (activated / demoted), and forwards it to the SMF. After receiving the PDU session establishment request, the SMF interacts with the PCF to dynamically configure the session policy. Simultaneously, the PCF subscribes to NWDAF's real-time network status analysis through the Nnwdaf_AnalyticsSubscription service, obtaining information about satellite round-trip delay (RTT), ground network load, and encryption algorithm support capabilities (priority: QKD > AES-256 > SM4). Based on this data, the PCF generates a dynamic QoS policy, initially setting the QoS level to 5QI = 82 (Ultra-Reliable Low Latency Communication). The policy also defines the following rules: If the satellite link latency exceeds 600ms or the bit error rate exceeds 1 in 100,000, the 5QI is automatically set to 80 (failure to the terrestrial backup network) and the AMBR is adjusted to 80 Mbps uplink and 150 Mbps downlink. If the satellite link latency remains below 500ms for more than 10 seconds, the primary satellite path is restored. The policy also includes guaranteed bandwidth (100 Mbps uplink, 200 Mbps downlink) and a list of encryption algorithm priorities. After generation, the policy is returned to the SMF. Based on the policy requirements provided by the PCF, the SMF selects two UPFs to implement a dual-path configuration. The onboard UPF-SAT, deployed on the satellite, serves as the primary path node. It supports a transport protocol optimized for space environments (enhanced VXLAN over the N3 interface) and can tolerate up to 300ms of propagation delay (accepting two consecutive packet losses). This node is preloaded with a quantum key pool, storing at least 1,000 key sets and set to a 5-minute key rotation cycle. The ground-based UPF-GND serves as a backup node, located in a ground edge data center. It is configured with an IPsec secure tunnel, using the military-grade AES-256-GCM encryption algorithm and the Diffie-Hellman Group 21 (RFC 3526) key exchange group. After completing resource configuration, the SMF initiates end-to-end performance testing, sending a test data stream to the satellite-to-ground link and continuously monitoring the average round-trip latency, packet loss rate, and effective throughput within 2 seconds. Based on measured data, the SMF dynamically adjusts its policy: when satellite latency exceeds 600ms, the service quality level is downgraded to 5QI = 80 (enhanced mobile broadband) and the bandwidth guarantee is reduced. Simultaneously, a dual-path parallel transmission mechanism is activated to ensure a 960ms overlapping transmission window when the primary path switches, avoiding service interruption. Finally, the SMF notifies the UE of the successful session establishment and assigns a session identifier (PDU Session ID).
[0109] S3. If the 4K infrared video stream uploaded by the drone enters UPF-SAT, real-time encryption and multicast distribution mechanisms need to be triggered, as open space is susceptible to interference or eavesdropping. First, dynamic anti-interference measures are taken at the physical layer. When the satellite is at a high elevation angle (>30 degrees), the frequency modulation rate of the onboard UPF-SAT is 500 hops / second. When the satellite is at a low elevation angle (≤30 degrees) or strong interference is detected, the frequency modulation rate is increased to 800 hops / second, and the forward error correction mechanism (FEC) is activated to enhance the signal's anti-interference capability. Then, at the MAC layer, UPF-SAT uses a preloaded quantum key pool to encrypt the data payload, and the key index is distributed via a secure control channel. When the key pool capacity falls below a preset number of groups (for example, 100 groups), UPF-SAT automatically switches to AES-256 encryption and sends an alarm notification via an independent control channel to ensure the continuity and security of the encryption process. SM9 signatures are added to key frames of the video (such as I frames or scene mutation frames) and high-risk targets identified by AI (confidence greater than 90%). If the signature verification at the receiving end fails, a three-level response mechanism will be triggered: first, try to retransmit the lost packet. If the retransmission fails, report the security incident to ensure the integrity and credibility of the data. When the QoS policy triggers the switch to the ground UPF-GND, layered encryption is disabled and only IPsec standard encryption (AES-256-GCM+HMAC-SHA384) is retained. At the same time, the multicast stream is changed to single-layer transmission (the base layer and the enhancement layer are merged) to improve transmission efficiency. When performing multicast distribution, UPF-SAT divides the encrypted data into the following three layers:
[0110] 1. Basic layer (BL): adopts the DVB-S2X standard, has a transmission rate of 10Mbps, wide coverage, and is compatible with all terminals.
[0111] 2. Enhancement Layer 1 (EL1): Adopts the NR MBS standard, has a transmission rate of 20 Mbps, uses 256QAM high-order modulation, and covers the central area.
[0112] 3. Enhanced Layer 2 (EL2): Dynamically transmits high-precision thermal imaging data on demand, with bandwidth adaptively allocated based on demand.
[0113] Different types of terminals receive different data layers based on their needs and capabilities. For the command center: Receive the BL, EL1, and EL2 layers, performing end-to-end signature verification and quantum encryption. For rescuer terminals: Receive the BL and EL1 layers, performing local key frame checksum and AES encryption. For sensors, only the BL layer is received, without signature verification. When the number of group members exceeds 50, broadcast optimization mode is enabled to reduce control signaling overhead. If the satellite link fluctuates (RTT changes by more than 20%), the EL layer code rate is reduced and the BL layer redundancy is increased to optimize resource utilization. When the primary path (UPF-SAT) fails, the gNB switches to single-layer encrypted multicast on the backup path (UPF-GND) within 50ms. If the layered content signature does not match the receiving end's capabilities, the system will forcibly downgrade to the base layer to ensure consistent data transmission.
[0114] S4, dynamic adjustment part. NWDAF analyzes the status of the entire network every 30 seconds, including satellite channel quality, ground load, and encryption overhead. It then combines real-time meteorological data and historical channel models to predict rainfall attenuation. When the predicted value exceeds 15dB, NWDAF generates an early warning and pushes it to PCF. In addition, NWDAF also analyzes the delay fluctuations and signature verification success rate during the encryption process. If the encryption delay fluctuation exceeds 20% or the signature verification success rate is less than 99%, the encryption performance is determined to be abnormal and the results are pushed to PCF. Based on the analysis results provided by NWDAF, PCF updates the QoS parameters and triggers corresponding actions:
[0115] 1. Dynamically adjust the modulation and coding scheme (MCS) level based on channel quality. When channel quality degrades, the MCS level is lowered to ensure stability; when channel quality recovers, the MCS level is increased to improve transmission efficiency. Furthermore, the Enhancement Layer (EL2) is dynamically enabled and disabled based on network congestion, suspending the transmission of high-precision thermal imaging data during periods of network congestion to reduce network load.
[0116] 2. When the predicted satellite pass time is less than 5 minutes, the quantum key pool is reset in advance to ensure key freshness and security. When the encryption load exceeds 80%, the signing mode is switched to sign only the highest priority targets to reduce processing overhead.
[0117] 3. Dynamically adjust slice quotas based on the weight of encryption overhead. In emergency situations, such as when satellite links deteriorate due to heavy rain, mission-critical slices are allowed to seize 20% of enhanced mobile broadband (eMBB) resources to ensure that critical missions are not affected.
[0118] NSSF then executes resource elastic scaling based on PCF instructions. Within one second of policy delivery, it monitors key metrics such as latency, packet loss rate fluctuations, and encrypted throughput to verify that the policy has taken effect as planned. If the policy does not take effect as planned, an alternative configuration template is activated and an alarm is issued to notify relevant personnel so that remedial measures can be taken promptly.
[0119] S5. After the mission is completed or the emergency situation is resolved, the emergency command center sends a termination command with the "EMERG_END" tag. When this command reaches the UPF, it triggers the security cleanup protocol. Upon receiving the termination command, the UPF destroys the quantum key. It overwrites the quantum key storage area and performs three random padding operations to completely destroy the stored quantum key. This ensures the irrecoverability of the key information and prevents malicious use of the key after the service is terminated. The UDM then records the mission's service level agreement (SLA) compliance and generates a security audit report compliant with the ISO 21434 standard. This report details the security measures and key events during the service initiation, execution, and termination process, providing strong support for compliance checks and security audits. The entire service termination process must be completed within 2 seconds to ensure system security and integrity. This strict time requirement reflects the need for rapid response and efficient processing for mission-critical services. It also ensures that system resources can be quickly restored in an emergency to prepare for other missions or services.
[0120] It should be noted that the specific threshold values and the values of related parameters in the above examples are all illustrative examples and are not specifically limited in this application.
[0121] Reference Figure 3 As shown, the data interaction involved in the communication process is as follows:
[0122] 1. First, the UAV (UE) generates an access request and initiates the emergency protocol to capture a 4K infrared video stream. When entering the geofence, it generates an access request (containing the SM9-encrypted location signature, device ID, and timestamp) and sends it to the satellite gNB.
[0123] 2. After receiving the access request, the satellite gNB attaches the satellite orbit parameters and forwards it to the core network.
[0124] 3. The AMF encrypts the NGAP message via the N2 interface, performs access processing, and returns the access result to the UE.
[0125] 4.UE sends PDU session request to SMF.
[0126] 5. After receiving the session request, SMF requests a dynamic QoS policy from PCF.
[0127] 6. PCF generates a dynamic QoS policy and returns it to SMF.
[0128] 7.SMF performs dual-path configuration.
[0129] 8. The UE uploads a 4K video stream and transmits it to the UPF, which performs anti-interference processing, layered multicast, and fault switching.
[0130] 9. NWDAF monitors satellite channel quality, encryption delay fluctuations, weather forecasts, etc. to generate recommended changes and send them to PCF
[0131] 10. PCF makes dynamic policy adjustments based on NWDAF's predictions, including adjusting the MCS level, resetting the subkey pool in advance, and emergency resource preemption.
[0132] 11. When termination is required, the emergency command center sends the "EMERG_END" tag to UPF.
[0133] Therefore, this application provides a multi-factor security access mechanism based on geo-fence: triple dynamic authentication through SM9 algorithm encryption of drone location signature, satellite ephemeris matching (error <5km) and timestamp synchronization verification (deviation ≤10 seconds), to achieve strong security protection for drone access in emergency scenarios, ensuring the legality of the equipment, location credibility and timeliness.
[0134] This application provides a satellite-ground dual-path dynamic QoS assurance system: a 5QI dynamic switching strategy (600ms switching threshold for the main path satellite link) based on real-time network status analysis (latency / bit error rate), combined with an onboard quantum key pool (1000 groups of keys / 5-minute rotation) and ground AES-256 encryption dual-path redundancy, supporting ultra-low latency transmission (main path tolerates 300ms delay) and lossless business continuity with a 960ms overlapping switching window.
[0135] This application provides layered encrypted multicast and anti-interference adaptive technology: physical layer dynamic frequency hopping (500-800 hops / second), automatic switching of quantum key / AES dual-mode encryption (degradation is triggered when the key pool is <100), combined with layered transmission of video streams (DVB-S2X basic layer + NR MBS enhanced layer) and terminal differentiated signature verification strategy (full signature verification by the command center / no signature verification by the sensor), to achieve a balance between multicast security and transmission efficiency, support 50-node broadcast optimization and adaptive adjustment of redundancy during link fluctuations.
[0136] This application provides elastic resource scheduling based on real-time network analysis: through NWDAF, it dynamically monitors satellite channel quality, encryption performance (delay fluctuation <20%) and weather forecast (rain attenuation >15dB warning), triggers dynamic adjustment of QoS parameters (MCS level, EL layer switch), early reset of quantum key pool (satellite overhead time <5 minutes) and emergency resource preemption (key slices preempt 20% eMBB resources), to achieve intelligent elastic scaling of network resources.
[0137] This application provides a secure service termination and quantum key destruction mechanism: upon mission termination, the onboard quantum key pool is completely destroyed by overwriting (3 times of random filling) to ensure that the key is irrecoverable; a security audit report that complies with relevant standards is simultaneously generated, recording security events throughout the entire process and SLA compliance rates, and service cleanup is completed within 2 seconds to meet high security and compliance requirements.
[0138] Compared to existing technologies, this invention offers significant advantages in security, flexibility, and reliability. Through innovative access authentication mechanisms, dynamic encryption algorithm switching, and a multi-layer encryption strategy, this invention significantly improves the security of the communication system. It also allows for flexible adjustment of transmission strategies in complex environments, optimizing data transmission efficiency and rapidly switching to backup paths in the event of a failure, ensuring communication continuity. Furthermore, after a task is terminated, this invention can quickly perform a security cleanup, completely destroying keys and preventing information leakage, further enhancing system security.
[0139] In summary, the method provided by the embodiment of the present application includes: obtaining video data through a target terminal, and if the location of the target terminal enters a preset emergency geofence, issuing an access request and establishing a session between the target terminal and the communication network; wherein the preset emergency geofence corresponds to the target terminal; uploading the video data to a user plane function node, performing secure transmission and multicast distribution processing on the video data; and dynamically adjusting the transmission strategy and resource allocation according to network status and environmental changes; and performing security cleanup if the task based on the video data is completed or the emergency situation is resolved. The present application can achieve efficient communication by adjusting the transmission strategy and resource allocation, combined with secure transmission and multicast distribution processing of the video data, which is beneficial to improving the efficiency and safety performance of emergency communications.
[0140] Secondly, refer to the attached Figure 4 An emergency communication system based on a drone according to an embodiment of the present invention is described. The system specifically includes:
[0141] A first module 410 is configured to obtain video data from a target terminal, and if the location of the target terminal enters a preset emergency geofence, issue an access request and establish a session between the target terminal and a communication network; wherein the preset emergency geofence corresponds to the target terminal;
[0142] The second module 420 is configured to upload the video data to a user plane function node, perform secure transmission and multicast distribution processing on the video data, and dynamically adjust transmission strategies and resource allocation according to network status and environmental changes;
[0143] The third module 430 is configured to perform a safety cleanup if the task based on the video data is completed or the emergency situation is resolved.
[0144] It can be seen that the contents of the above method embodiments are all applicable to the present system embodiments. The functions specifically implemented by the present system embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.
[0145] Reference Figure 5 , an embodiment of the present invention provides an emergency communication device based on a drone, comprising:
[0146] at least one processor 510;
[0147] at least one memory 520, for storing at least one program;
[0148] When the at least one program is executed by the at least one processor 510, the at least one processor 510 implements the drone-based emergency communication method.
[0149] Similarly, the contents of the above method embodiments are applicable to the present device embodiments. The functions specifically implemented by the present device embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.
[0150] An embodiment of the present invention also provides a computer-readable storage medium, which stores a program executable by a processor. When the program executable by the processor is executed by the processor, it is used to execute the above-mentioned drone-based emergency communication method.
[0151] Similarly, the contents of the above method embodiments are applicable to the present storage medium embodiment. The functions specifically implemented by the present storage medium embodiment are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.
[0152] In some optional embodiments, the function / operation mentioned in the block diagram may not occur in the order mentioned in the operation diagram. For example, depending on the function / operation involved, the two boxes shown in succession can actually be executed substantially simultaneously or the boxes can sometimes be executed in reverse order. In addition, the embodiment presented and described in the flow chart of the present invention is provided in an exemplary manner for the purpose of providing a more comprehensive understanding of the technology. The disclosed method is not limited to the operation and logic flow presented herein. Optional embodiments are contemplated in which the order of the various operations is changed and the sub-operations described as a part of a larger operation are performed independently.
[0153] In addition, although the present invention is described in the context of functional modules, it should be understood that, unless otherwise stated, one or more of the functions and / or features may be integrated into a single physical device and / or software module, or one or more functions and / or features may be implemented in separate physical devices or software modules. It is also understood that a detailed discussion of the actual implementation of each module is not necessary for understanding the present invention. More specifically, given the properties, functions, and internal relationships of the various functional modules in the devices disclosed herein, the actual implementation of the module will be understood within the ordinary skill of an engineer. Therefore, a person skilled in the art will be able to implement the present invention set forth in the claims using ordinary skill without undue experimentation. It is also understood that the specific concepts disclosed are merely illustrative and are not intended to limit the scope of the present invention, which is determined by the full scope of the appended claims and their equivalents.
[0154] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several programs for enabling a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0155] The logic and / or steps represented in a flowchart or otherwise described herein, for example, may be considered as an ordered list of executable programs for implementing the logical functions, and may be embodied in any computer-readable medium for use by, or in conjunction with, a program execution system, apparatus, or device (e.g., a computer-based system, a system including a processor, or other system that can retrieve and execute a program from a program execution system, apparatus, or device). For purposes of this specification, a "computer-readable medium" may be any device that can contain, store, communicate, propagate, or transport a program for use by, or in conjunction with, a program execution system, apparatus, or device.
[0156] More specific examples (a non-exhaustive list) of computer-readable media include the following: an electrical connection with one or more wires (electronic devices), a portable computer disk cartridge (magnetic devices), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), a fiber optic device, and a portable compact disc read-only memory (CDROM). In addition, the computer-readable medium may even be paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, deciphering, or processing in another suitable manner as necessary, and then stored in a computer memory.
[0157] It should be understood that various parts of the present invention can be implemented using hardware, software, firmware, or a combination thereof. In the above-described embodiments, multiple steps or methods can be implemented using software or firmware stored in a memory and executed by a suitable program execution system. For example, if implemented using hardware, as in another embodiment, any one of the following technologies known in the art or a combination thereof can be used: a discrete logic circuit having a logic gate circuit for implementing a logic function on a data signal, an application-specific integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.
[0158] In the above description of this specification, reference to the terms "one embodiment / example," "another embodiment / example," or "certain embodiments / examples" means that the specific features, structures, materials, or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representation of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in any one or more embodiments or examples.
[0159] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to the embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the claims and their equivalents.
[0160] The above is a specific description of the preferred implementation of the present invention, but the present invention is not limited to the embodiments. Those skilled in the art can make various equivalent modifications or substitutions without violating the spirit of the present invention. These equivalent modifications or substitutions are all included in the scope defined by the claims of the present invention.
Claims
1. An emergency communication method based on drone, characterized in that: The following steps are involved: Acquiring video data through a target terminal, and if the location of the target terminal enters a preset emergency geofence, issuing an access request and establishing a session between the target terminal and a communication network; wherein the preset emergency geofence corresponds to the target terminal; Uploading the video data to the user plane function node, performing secure transmission and multicast distribution processing on the video data; and dynamically adjusting transmission strategies and resource allocation according to network status and environmental changes; If the task based on the video data is completed or the emergency situation is resolved, a safety cleanup is performed.
2. The emergency communication method based on drone according to claim 1, characterized in that: The method further comprises: The access request is subjected to a three-way check by the access and mobility management function, including: Perform ephemeris matching; Determining whether the target terminal is located within a preset emergency geo-fence by decrypting the location of the target terminal; Perform a timeliness check on the timestamp in the access request.
3. The emergency communication method based on drone according to claim 1, characterized in that: The establishing of a session between the target terminal and the communication network includes: Dynamically configure session policies through session management capabilities; The policy control function generates dynamic QoS policies based on real-time network status analysis using the network data analysis function, including: Based on satellite latency, it is determined to lower the service quality level, reduce bandwidth guarantees, and activate the dual-path parallel transmission mechanism.
4. The emergency communication method based on drone according to claim 1, characterized in that: The uploading of the video data to the user plane function node and performing secure transmission and multicast distribution processing on the video data includes: Perform physical layer dynamic anti-interference; The data payload is encrypted using a quantum key pool, and the key index is distributed via a secure control channel; Processing the video data in layers, and determining the received data layer according to different terminal types and capabilities; Add signatures to video key frames and high-risk targets. If the signature verification fails, the three-level response mechanism is triggered.
5. The emergency communication method based on drone according to claim 1, characterized in that: The dynamic adjustment of transmission strategies and resource allocation according to network status and environmental changes includes: Dynamically adjust the level of modulation and coding scheme according to channel quality; If the predicted satellite overpass time is less than the preset time, the quantum key pool is reset; Dynamically adjust slice quotas based on the weight of encryption overhead.
6. The emergency communication method based on drone according to claim 1, characterized in that: The method further comprises: Monitor satellite link quality and switch to a backup path if the primary path fails; Set the backup path to single-layer encrypted multicast to ensure continuous data transmission; If satellite link fluctuations are detected, the enhancement layer bit rate is reduced to increase the base layer redundancy; If the number of group members is greater than the preset group member threshold, broadcast optimization mode is enabled.
7. The emergency communication method based on drone according to claim 1, characterized in that: The safe cleanup is achieved through the following steps: Send a termination instruction with a preset termination tag through the emergency command center; Perform several random code overwriting operations on the quantum key storage area; Record the service level agreement compliance rate and generate security audit reports to determine service termination.
8. An emergency communication system based on drones, characterized in that: include: A first module is configured to acquire video data from a target terminal, and if the location of the target terminal enters a preset emergency geofence, issue an access request and establish a session between the target terminal and a communication network; wherein the preset emergency geofence corresponds to the target terminal; The second module is used to upload the video data to the user plane function node, perform secure transmission and multicast distribution processing on the video data; and dynamically adjust the transmission strategy and resource allocation according to network status and environmental changes; The third module is used to perform safety cleanup if the task based on the video data is completed or the emergency situation is resolved.
9. An emergency communication device based on a drone, characterized in that: include: at least one processor; at least one memory for storing at least one program; When the at least one program is executed by the at least one processor, the at least one processor implements the drone-based emergency communication method according to any one of claims 1 to 7.
10. A computer-readable storage medium storing a program executable by a processor, characterized in that: The processor-executable program is used to implement the drone-based emergency communication method according to any one of claims 1 to 7 when executed by the processor.
Citation Information
Patent Citations
Method and system for storing and forwarding user plane data
CN117641272A
Emergency call method, system and equipment based on VONR (Voice Over Noise Ratio) technology
CN119325145A
Emergency communication method, core network, medium and system
CN119485242A
Air-space cooperative unmanned aerial vehicle emergency communication system and communication method
CN119727860A
Preserved resource based SOS message relay using ATG connections
US20250133382A1