Unmanned aerial vehicle password application security detection method
By building a drone flight test scenario set and penetration test, the password security and stability of the drone communication system are evaluated, and the comprehensiveness and real-time problems of drone communication testing are solved, and the security and stability of the drone communication system are improved.
Patent Information
- Application Number
- CN202510934268.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-08
- Publication Date
- 2025-08-08
AI Technical Summary
The existing UAV communication security test lacks comprehensiveness and real-timeness, and traditional methods fail to effectively cover multi-dimensional factors such as communication protocols, encryption algorithms, flight trajectory and mission execution, resulting in insufficient security and stability of UAV communication systems in complex environments.
By obtaining the flight history data of the drone, building a flight test scenario set, formulating a test plan set, conducting penetration test and real-time data reading, evaluating password security, effectiveness and stability, establishing a response mapping between communication evaluation results and test plan, and generating test verification results.
It realizes a comprehensive security assessment of the UAV communication system in complex environments, improves the accuracy and timeliness of testing, and enhances the system's anti-attack ability and communication protection capabilities.
Smart Images

Figure CN120456023A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of drone communication security technology, and in particular to a drone cryptographic application security detection method. Background Art
[0002] With the rapid development of drone technology and its widespread application in fields such as security and agriculture, drone communication systems have become a core component. However, drones often rely on wireless communications for real-time data transmission during missions, which poses a significant challenge to communication security. Due to the open nature and uncontrolled environment of wireless communications, information transmission is vulnerable to attacks such as eavesdropping and tampering. Therefore, drone communication security, especially the security of encryption and authentication mechanisms, has become a crucial factor in ensuring the overall safety and reliability of drone systems.
[0003] Currently, drone communication systems rely heavily on traditional encryption algorithms to ensure data security. However, existing testing and verification mechanisms primarily focus on static assessments and simple cryptographic strength analysis, lacking comprehensive dynamic, real-time testing. Given the complex and ever-changing flight environment, traditional testing methods fail to effectively encompass multiple factors, including communication protocols, encryption algorithms, flight trajectories, and mission execution. Therefore, there is an urgent need for drone cryptographic application security testing methods that can comprehensively analyze the security, effectiveness, and stability of drone communications. Summary of the Invention
[0004] This application provides a method for detecting the security of drone cryptographic applications, aiming to solve the technical problem that the existing technology lacks comprehensiveness and real-time performance in drone communication cryptographic security testing.
[0005] In view of the above problems, this application provides a method for security detection of drone cryptographic applications.
[0006] The present application discloses a method for detecting the security of cryptographic applications of drones, which includes obtaining flight history data of the drone, constructing a flight test scenario set based on the flight history data, and establishing a test solution set according to the scenario characteristics and test preferences of the flight test scenario set; performing a penetration test of the drone based on the test solution set, and reading real-time drone communication data; performing a communication evaluation on the real-time drone communication data, and establishing a communication evaluation result, wherein the communication evaluation includes a cryptographic security evaluation, a cryptographic validity evaluation, a stability test, and a recovery test; establishing a response mapping between the communication evaluation result and the test solution set, and generating a test verification result according to the response mapping.
[0007] One or more technical solutions provided in this application have at least the following technical effects or advantages: By employing a drone cryptographic application security testing method, and by acquiring historical flight data, constructing a set of flight test scenarios, and establishing a set of test plans based on scenario characteristics and test preferences, this system addresses the technical issues of existing drone communication cryptographic security testing, which lack comprehensiveness and real-time capabilities. Through targeted penetration testing, real-time data reading, and communication security evaluation, the system ensures a comprehensive assessment of cryptographic security and effectiveness. Furthermore, it can dynamically optimize test plans under different flight environments, improving the accuracy and timeliness of testing and ensuring the security of drone communications in complex scenarios. This results in a technical improvement in drone communication cryptographic protection capabilities and enhanced system anti-attack capabilities.
[0008] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS
[0009] Figure 1 A flowchart of a method for detecting the security of drone cryptographic applications is provided for an embodiment of the present application. DETAILED DESCRIPTION
[0010] The overall idea of the technical solution provided by this application is as follows: An embodiment of the present application provides a method for detecting the security of drone cryptographic applications. First, the drone's flight history data is acquired, and a set of flight test scenarios is constructed based on this data. A set of test scenarios is then developed based on the scenario characteristics and test preferences. The system performs penetration testing on drone communications and reads communication data in real time to assess cryptographic security, effectiveness, and stability. Ultimately, test verification results are generated through response mapping. This solution is designed specifically for the security assessment of external drone systems. Through non-invasive data collection and black-box penetration testing techniques, it enables independent security testing of the target drone's communication system without relying on the target system's internal collaboration.
[0011] After introducing the basic principles of the present application, various non-limiting implementation methods of the present application will be specifically introduced in conjunction with the drawings in the specification.
[0012] Examples, such as Figure 1 As shown, the embodiment of the present application provides a method for detecting the security of drone password applications, the method comprising: Step S100: Acquire flight history data of the UAV, construct a flight test scenario set based on the flight history data, and establish a test solution set according to the scenario characteristics and test preferences of the flight test scenario set.
[0013] Specifically, a drone's flight history data refers to relevant data from past missions, including flight trajectories, altitudes, speeds, communication logs, and sensor data. This data can reflect the drone's flight performance under different environments and missions. A flight test scenario set is a collection of multiple flight test scenarios constructed based on flight history data. Each test scenario includes different flight conditions (such as weather conditions and flight areas) and mission requirements (such as photography and reconnaissance). These scenarios help simulate different flight states to verify the security of the drone's communication system. Scenario characteristics refer to key factors within a test scenario, such as the flight scenario's location, weather conditions, and flight mode, that influence communication security and stability. Test preferences are priorities set by testers based on mission objectives or test requirements, such as whether to prioritize communication encryption strength and resilience or focus more on communication stability and latency. A test plan set is a series of test plans generated based on flight history data and the test scenario set, combined with test preferences.
[0014] First, the system acquires the drone's historical flight data. This data typically includes flight logs, location trajectories, and weather data recorded by the drone's control system or ground control station. Next, based on this historical data, the system constructs a flight test scenario set. This flight test scenario set is a collection of multiple simulated flight environments, each reflecting a different flight state.
[0015] After constructing the scenario set, the system generates a set of test scenarios based on each scenario's characteristics and pre-defined test preferences. For example, in Scenario A, testers want to test the drone's communication interference in an urban environment, so the test scenario will include assessments of communication stability and anti-interference capabilities. In Scenario B, however, testers are more concerned with the drone's communication resilience and cryptographic security in adverse weather conditions. Test preferences can be adjusted based on the specific task, such as prioritizing cryptographic effectiveness and communication latency.
[0016] This module enables the system to automatically construct a highly targeted set of flight test scenarios based on historical flight data and generate a set of test plans based on test preferences. This not only improves the targeting and accuracy of tests, but also enables a comprehensive assessment of the safety and reliability of drone communication systems in a changing environment.
[0017] Step S200: Perform a penetration test on the drone based on the test solution set and read real-time drone communication data.
[0018] Specifically, penetration testing is a testing method that simulates attacks to uncover security vulnerabilities in a system. By simulating hacker attacks, the vulnerability of drone communication systems to attack or tampering is assessed, and the vulnerabilities of encryption mechanisms, authentication systems, and key management are examined. Encryption algorithms, key management, and authentication are implemented during data transmission to ensure data security. Real-time drone communication data refers to various data transmitted in real time over wireless networks during drone flight, including flight status, sensor data, remote control commands, and video streams. This data is encrypted during transmission to prevent eavesdropping or tampering.
[0019] First, you need to select a specific test scenario based on the previously generated test scenario set. Each test scenario includes different security assessment objectives, such as encryption strength testing, identity authentication verification, and communication resilience. For example, a tester might choose to conduct a penetration test targeting a flight mission scenario, focusing on whether the encryption algorithm used during communication is strong enough to prevent man-in-the-middle attacks and replay attacks.
[0020] Next, penetration testing is conducted. The purpose of penetration testing is to simulate hacker attacks and discover vulnerabilities in the drone's communication system. Attackers attempt to circumvent encryption algorithms, authentication mechanisms, key management, and other mechanisms by impersonating legitimate users or third parties, thereby stealing or tampering with data. Common penetration testing methods include: man-in-the-middle attacks, where attackers intercept and tamper with communication data; replay attacks, where attackers resend old communication data in an attempt to deceive the recipient; and brute force attacks, where attackers attempt to brute force the encryption algorithm's key. To test a third party's drone system, a set of applicable test scenarios is first developed based on the target drone's flight history and known communication characteristics. This set of test scenarios will include various simulated scenarios, such as hypothetical drone behavior under certain weather conditions, geographical conditions, or malicious attack scenarios. These scenarios can be based on publicly available drone usage data or known attack scenarios. For example, if testers discover that the target drone uses an encryption protocol, an attacker could potentially break this encryption protocol to steal the drone's flight data. In this step, testers will verify the existence of this vulnerability through actual attack methods.
[0021] During the penetration test, real-time drone communication data is read and recorded. Encryption and decryption of this data ensures that only authorized recipients can read the data. Specifically, a combination of asymmetric encryption algorithms (such as RSA) and symmetric encryption algorithms (such as AES) can be used to ensure data confidentiality and integrity. First, RSA is used for key exchange and authentication. During the initial communication phase, the drone and ground station exchange a symmetric key using an RSA-encrypted public key. This symmetric key is used for subsequent data encryption and decryption operations. The RSA public key is used for encryption, while the private key is used for decryption. Once the symmetric key exchange is complete, both parties use the AES algorithm to encrypt and decrypt data. AES is a fast and secure symmetric encryption algorithm suitable for encrypting data in real-time communications. When transmitting real-time data, the drone encrypts it using the AES algorithm and a shared symmetric key and sends the encrypted data to the recipient. The recipient uses the same symmetric key to decrypt the received data, ensuring that only authorized recipients can read the data.
[0022] Penetration testing based on a suite of test scenarios allows for a comprehensive assessment of the security of drone communication systems under various attack conditions. Real-time acquisition and monitoring of communication data can help testers identify weaknesses in encryption systems and address them promptly.
[0023] Step S300: Perform communication evaluation on the real-time UAV communication data and establish a communication evaluation result. The communication evaluation includes cryptographic security evaluation, cryptographic validity evaluation, stability test, and recovery test.
[0024] Specifically, communication evaluation is a comprehensive assessment of the security, effectiveness, and stability of a drone's communication system. By analyzing real-time communication data to detect vulnerabilities and potential risks, it assesses whether encryption algorithms and communication protocols comply with security standards, ensuring that data transmitted during communication cannot be eavesdropped or tampered with. Cryptographic security evaluation involves a security analysis of cryptographic technologies, such as encryption algorithms, key management, and authentication, used in communication. This assessment assesses whether the cryptographic algorithms are sufficiently robust to effectively resist various attacks (such as brute force cracking and replay attacks) and ensure the confidentiality of communication data. Cryptographic effectiveness evaluation involves testing and analyzing the effectiveness of encryption mechanisms to ensure that the cryptographic algorithms and authentication mechanisms used during communication consistently function and effectively authenticate the identities of both communicating parties, preventing identity forgery or replay attacks. Stability testing assesses the stability of drone communication systems during long-term operation or in complex environments, specifically whether communication interruptions or packet loss may occur under conditions of high interference and high load. Recovery testing assesses the drone communication system's ability to recover after interruptions, interference, or attacks. The system measures the time it takes to restore to normal and the security of data during the recovery process, ensuring that drones can quickly and securely restore communications after a failure or attack.
[0025] First, the system acquires real-time communication data from the drone's communication module, including flight control commands, sensor data, and image transmissions. Next, the system conducts a multi-dimensional assessment, specifically analyzing encryption algorithms (such as AES-256), key management methods, and authentication mechanisms to detect vulnerabilities. For example, if the key length is too short or an outdated encryption algorithm is used, the system will identify the cryptographic security as substandard.
[0026] Further analysis of the actual effectiveness of the encryption mechanism is conducted, such as checking whether the encryption algorithm is correctly applied and verifying whether there are any vulnerabilities that could lead to unauthorized access. For example, if the password verification mechanism fails to effectively identify legitimate identities or poses a risk of replay attacks during testing, it will be marked as invalid.
[0027] By simulating different flight environments (such as high-interference areas and remote control), the stability of communication signals is tested. For example, when a drone flies far from a base station, will communication interruptions or delays occur, affecting flight control? By analyzing flight data, the stability of signal transmission is evaluated.
[0028] This system simulates the recovery process of drone communications after a failure, such as signal interruption or interference. The system tests whether the drone can quickly restore connectivity after signal loss and ensure secure data transmission. For example, if drone communications are interrupted by interference, the system tests whether there are any security vulnerabilities or data loss during the recovery process.
[0029] By comprehensively evaluating drone communication data, the system can detect and analyze communication security, effectiveness, stability, and resilience at multiple levels. This multi-dimensional assessment ensures that drone data transmission remains secure, stable, and reliable in complex flight environments. This ensures the drone's communication system continues to function, preventing data leakage or loss in the face of high interference, extended flight times, and communication interruptions, thereby enhancing the drone system's anti-attack capabilities and operational stability.
[0030] Step S400: establishing a response mapping between the communication evaluation result and the test solution set, and generating a test verification result according to the response mapping.
[0031] Specifically, the communication evaluation results are the result of a comprehensive assessment of the multi-dimensional characteristics of the UAV communication system demonstrated during testing, including security, effectiveness, and stability. These assessments cover aspects such as cryptographic security, communication stability, and resilience. A test scenario set is a collection of test scenarios designed based on historical flight data, test preferences, and other factors. It incorporates a variety of test methods and objectives to assess different security dimensions of the UAV communication system. Response mapping is the process of mapping the relationship between communication evaluation results and each test scenario. By analyzing the evaluation results of each test scenario, the specific communication characteristics or behaviors revealed by each specific test scenario are identified. The evaluation results are then linked to the test scenarios to form a response mapping. The test verification results are the final output generated based on the response mapping and are typically a summary and conclusion of the testing process. They reflect the overall performance of the UAV communication system across multiple test scenarios, providing a comprehensive assessment of system security and stability, and providing a basis for subsequent optimization and improvement.
[0032] First, based on the previous penetration testing and communication security analysis, the performance of the drone's communication system in each test scenario needs to be evaluated, forming a communication evaluation result. For example, if the tester detects through penetration testing that the drone's password strength in a certain flight environment is insufficient, resulting in its being cracked by a man-in-the-middle attack, this result will be part of the communication evaluation and reflect the security issues of the encryption algorithm.
[0033] Next, we create a response mapping process that associates communication evaluation results with test items within different test scenarios. For example, Test Plan A focuses on cryptographic security, while Test Plan B focuses on communication recovery. By comparing the feedback and evaluation results from these test scenarios, we can establish a clear mapping to determine which test results (such as cracked encryption or slow recovery) belong to which test scenario.
[0034] During this process, testers use various tools for data analysis and mapping. For example, they use data analysis tools (such as the Pandas library in Python) to organize communication evaluation results and compare them with the test scenario's objectives (such as communication stability and resilience), thereby generating a response mapping table. This table clearly indicates which communication evaluation indicators are ultimately affected by testing a specific test scenario.
[0035] Finally, based on the established response mapping, the system generates test verification results, which summarize the performance of all test scenarios and provide a comprehensive evaluation. For example, the test verification results may reveal issues such as poor communication stability in complex weather conditions, insufficient encryption strength, and slow communication recovery speed. These results provide clear guidance for further optimization of the drone communication system.
[0036] This module maps communication evaluation results to a set of test scenarios, accurately linking system issues revealed by each test scenario with specific communication performance defects. This process helps testers systematically analyze the impact of each test scenario and translate it into specific optimization recommendations and action plans.
[0037] Furthermore, the step S300 also includes the following steps: parsing the real-time drone communication data to obtain a communication encryption algorithm; performing an algorithm complexity analysis on the communication encryption algorithm to establish a first analysis result; obtaining the communication protocol of the communication encryption algorithm, performing an access authentication analysis of the identity authentication mechanism based on the communication protocol, and establishing a second analysis result, wherein the access authentication analysis includes an identity authentication mechanism analysis and a replay authentication analysis; establishing a cryptographic security evaluation based on the first analysis result and the second analysis result, and using the cryptographic security evaluation to establish a communication evaluation result.
[0038] Specifically, a communication encryption algorithm is a mathematical algorithm used to encrypt and decrypt data, ensuring it cannot be eavesdropped or tampered with during transmission. Common communication encryption algorithms include symmetric encryption (such as AES) and asymmetric encryption (such as RSA). Algorithm complexity analysis is a performance analysis of encryption algorithms, evaluating the computational resources (such as time and memory) required in actual use and the difficulty of cracking them. Complexity analysis typically focuses on the security and efficiency of the algorithm, ensuring that the algorithm does not significantly impact system performance while ensuring security. Communication protocols are the rules and standards that define how communicating parties exchange information. Common protocols include TCP / IP and SSL / TLS. In encrypted communication, protocols encompass not only the data transmission format but also encryption methods and authentication mechanisms. Authentication mechanisms are security mechanisms that ensure the legitimacy of the communicating parties, typically using methods such as usernames and passwords, digital certificates, or biometrics. The purpose of authentication mechanisms is to ensure that only authorized parties can access communication content. Replay authentication analysis evaluates authentication mechanisms to prevent replay attacks. Replay attacks occur when an attacker intercepts valid communication data and retransmits it at a later time, thereby masquerading as a legitimate user. An effective replay protection mechanism should ensure that the data packets of each communication are unique and non-repeatable.
[0039] First, the system needs to parse real-time drone communication data. This means the system captures and analyzes all real-time communication data streams between the drone and the ground station. For example, the system extracts flight data, sensor data, or control commands from wireless communication signals and further analyzes these data for any security vulnerabilities.
[0040] Next, the system extracts the encryption algorithms used to encrypt data from the real-time communication data. For example, it may detect that the drone uses AES-256 (symmetric encryption algorithm) or RSA (asymmetric encryption algorithm) to protect data transmission. The system then performs an algorithmic complexity analysis on these encryption algorithms to assess their robustness against brute force attacks. This analysis typically involves evaluating factors such as the algorithm's mathematical complexity and key length to determine the difficulty for an attacker to crack it. For example, the AES-256 algorithm has a significantly higher complexity than AES-128, thus providing stronger security protection.
[0041] On this basis, the system also needs to obtain communication protocols, such as SSL / TLS, which describe the transmission rules for encrypted data and the key exchange process. Simultaneously, based on the extracted communication protocols, the system performs access authentication analysis of the authentication mechanisms. This analysis assesses whether identity authentication during the communication process meets expectations and effectively prevents unauthorized access. Authentication mechanisms include digital certificates and two-factor authentication. Furthermore, the system performs replay authentication analysis to determine whether the communication is adequately protected against replay attacks. If the communication protocol includes mechanisms such as timestamps or unique identifiers, this can help prevent replay attacks.
[0042] By summarizing the above analysis results, the system will establish a cryptographic security evaluation based on algorithm complexity analysis and authentication mechanism analysis. This evaluation comprehensively assesses the effectiveness of the encryption algorithm, communication protocol, and authentication mechanism. For example, if the AES algorithm complexity is appropriate, the communication protocol uses TLS / SSL for encryption, and the authentication mechanism is relatively secure, the cryptographic security evaluation will be determined to be "high security." Ultimately, the cryptographic security evaluation will be used to generate communication evaluation results, providing a basis for subsequent communication security optimization.
[0043] By analyzing real-time drone communication data, the complexity of encryption algorithms, the authentication mechanisms of communication protocols, and replay authentication, the system comprehensively assesses the cryptographic security of drone communications. This process ensures that drone communications remain highly secure against a variety of attack vectors and provides specific recommendations for improvement.
[0044] Furthermore, the step S300 also includes the following steps: parsing the real-time drone communication data, obtaining the password verification mechanism, performing verification mechanism analysis on the password verification mechanism, and establishing a third analysis result; obtaining key length data, and establishing a fourth analysis result based on the key length data; obtaining the life cycle of the password, and establishing a fifth analysis result based on the life cycle; generating a password validity evaluation based on the third analysis result, the fourth analysis result, and the fifth analysis result; and establishing a communication evaluation result based on the password security evaluation and the password validity evaluation.
[0045] Specifically, a cryptographic authentication mechanism is a security mechanism used to verify the correctness of the encryption and decryption processes for communicated data. It ensures that both communicating parties verify each other's identities and the validity of the data through some means. Common cryptographic authentication mechanisms include digital signatures and message authentication codes (MACs), which are used to ensure data integrity and prevent tampering. Authentication mechanism analysis is the process of evaluating and analyzing the effectiveness of cryptographic authentication mechanisms to determine whether they can effectively prevent various attacks, such as forgery, tampering, and replay attacks. Key length refers to the number of bits in the key used for encryption and decryption in an encryption algorithm. Key length directly determines the security of the encryption algorithm. Generally speaking, longer key lengths increase the difficulty of cracking. For example, AES-256 uses a 256-bit key, which is more secure than AES-128 (128-bit key). The lifecycle refers to the entire process from the generation of a key or password to its destruction or replacement. The lifecycle includes stages such as generation, distribution, use, update, expiration, and destruction. Effective key lifecycle management can prevent key leakage and misuse, ensuring communication security. Cryptographic effectiveness evaluation is a comprehensive assessment of cryptographic system components such as encryption algorithms, key lengths, and verification mechanisms. It aims to determine whether these components are strong enough to ensure the security of data throughout its life cycle and prevent it from being cracked or leaked.
[0046] In this step, the system first extracts the cryptographic authentication mechanism used to verify the communication data from the real-time drone communication data. For example, the system discovers that the drone's communication data uses digital signatures to verify the integrity of the data and the identity of the sender. The system then analyzes this authentication mechanism to determine whether it effectively prevents forgery and tampering. For example, the system analyzes the digital signature generation and verification process to confirm whether the signature algorithm is secure, key management is appropriate, and whether the signature uses a sufficiently long key.
[0047] Next, the system extracts key length data, which refers to the length of the key used by the encryption algorithm. For example, if the drone uses the AES encryption algorithm, the system will extract the key length (e.g., 128-bit, 192-bit, or 256-bit). This key length data is used to create a fourth analysis result, assessing the security of that key length under the current threat model. Longer key lengths generally provide greater encryption strength.
[0048] The system also captures password lifecycle information, analyzing the entire process from key generation, use, and destruction. Password lifecycle management is crucial to preventing key leakage or misuse. For example, the system assesses whether a key expiration management mechanism is in place and whether there is a policy for regular key updates. This process generates the fifth analysis result.
[0049] Based on the results of the above three analyses (verification mechanism analysis, key length analysis, and lifecycle analysis), the system will generate a cryptographic effectiveness evaluation, which is a comprehensive assessment to determine whether the current encryption scheme is strong enough to protect drone communication data from various attacks such as brute force cracking, replay attacks, forgery, etc.
[0050] Finally, combined with the previous cryptographic security evaluation, the system generates a final communication evaluation result. This is a comprehensive assessment of the drone communication system's encryption capabilities, authentication mechanisms, and key management. For example, if the system determines that the communication system's encryption strength is insufficient, the authentication mechanism has vulnerabilities, or the key management does not meet best practices, the communication evaluation results will provide clear guidance for optimizing the drone communication system.
[0051] By comprehensively analyzing cryptographic authentication mechanisms, key lengths, and lifecycles, the system accurately assesses the cryptographic effectiveness of drone communication systems. This process ensures that the cryptographic components within the communication system are robust against existing and future security threats, preventing potential password cracking, identity forgery, and key compromise.
[0052] Furthermore, the step S300 also includes the following steps: obtaining UAV flight data and mission execution data based on the real-time UAV communication data; establishing a fitting flight trajectory based on the mission execution data, performing trajectory stability analysis on the UAV flight data according to the fitting flight trajectory, and establishing a first stability analysis result; performing task completion analysis on the mission execution data, and establishing a second stability analysis result; establishing a stability test based on the first stability analysis result and the second stability analysis result; and establishing a communication evaluation result based on the stability test, the cryptographic security evaluation, and the cryptographic validity evaluation.
[0053] Specifically, flight data includes real-time drone flight status information, such as location (GPS coordinates), speed, attitude (e.g., pitch angle, roll angle), and altitude. Flight data is used to analyze the drone's flight performance, stability, and deviations from the planned path. Mission data refers to data generated by a drone while performing specific missions (e.g., filming, dropping items, etc.). This data can include images, videos, sensor measurements, and other information, as well as mission status information, such as whether the target was achieved or any anomalies occurred. Flight trajectory fitting involves mathematically modeling the drone's flight data (e.g., GPS coordinates) and comparing the actual trajectory with the planned trajectory to derive a theoretical ideal trajectory. This process typically uses methods such as regression analysis and curve fitting to connect discrete flight data points into a smooth curve, facilitating subsequent stability analysis. Trajectory stability analysis analyzes the differences between the fitted and actual flight trajectories to assess the drone's flight accuracy and stability. This analysis includes flight trajectory deviations and fluctuations to determine whether there are any excessive deviations from the planned path, impacting flight stability. Mission completion analysis is used to assess the drone's performance in performing specific missions. It compares the mission's intended objectives with the actual execution status to determine whether the mission was successfully completed, whether there were any failures or anomalies, and whether there were other problems during the mission (such as sensor failure, error accumulation, etc.).
[0054] First, flight data and mission data are extracted from real-time drone communication data. Flight data includes the drone's GPS location, flight speed, altitude, and other information. Mission data is data generated while the drone is performing a specific mission, such as captured photos, videos, and sensor data. Based on this data, a fitted flight trajectory is constructed.
[0055] The process of fitting a flight trajectory involves using techniques such as regression analysis and interpolation algorithms to combine real-time flight data points to generate an idealized flight trajectory. For example, if a drone flies from point A to point B, the actual trajectory may be affected by factors such as airflow and operational errors, resulting in slight deviations. Through fitting, a theoretically smooth flight path can be obtained, which facilitates subsequent trajectory stability analysis.
[0056] Next, trajectory stability analysis evaluates the drone's flight stability by calculating the difference between the actual flight trajectory and the fitted trajectory. This process uses error analysis methods, such as calculating the root mean square error (RMSE) of the trajectory deviation, to determine if there are significant deviations during flight. If the analysis results show significant trajectory fluctuations, this indicates instability in the drone's flight control.
[0057] Next, mission completion analysis is performed on the mission data. This analysis assesses whether the drone completed its mission objectives as expected. For example, if the mission involves capturing a series of images of a specific area, the target area is compared with the actual imaged area to check for any omissions or to determine if the image quality meets the required standards. This analysis uses statistical methods to determine mission success rates, anomaly rates, and other factors.
[0058] After completing trajectory stability analysis and mission completion analysis, a stability test is conducted. This test comprehensively considers the stability of the flight trajectory and mission completion, evaluating the stability of the entire mission execution process. For example, if the drone's flight trajectory deviates significantly but the mission is successfully executed, it indicates that the drone's flight control system can accommodate large errors. Conversely, if flight stability is poor and the mission is not completed, the mission will be flagged as having a major issue.
[0059] Finally, a communication evaluation result is generated based on comprehensive data including stability test results, cryptographic security evaluation, and cryptographic effectiveness evaluation. This result provides a comprehensive assessment of the drone's safety and reliability, identifying strengths and areas for improvement. This communication evaluation result can help drone developers improve flight control algorithms, mission planning, or enhance the security of encrypted communications.
[0060] By combining flight data, mission execution data, cryptographic security assessments, and stability analysis, a comprehensive assessment of a drone's communication security, flight stability, and mission completion can be made. This comprehensive analysis not only identifies security vulnerabilities in encryption and communications, but also reveals potential issues with flight control systems or mission execution.
[0061] Furthermore, the step S300 also includes the following steps: obtaining the recovery speed of communication recovery, and establishing a first recovery evaluation based on the recovery speed; obtaining the recovery security of communication recovery, and establishing a second recovery evaluation based on the recovery security; establishing a recovery test based on the first recovery evaluation and the second recovery evaluation, and establishing a communication evaluation result based on the recovery test, the stability test, the password security evaluation, and the password validity evaluation.
[0062] Specifically, the recovery speed of communication recovery refers to the time required to restore normal communications after a communication interruption (such as signal loss or interference) within the drone. Recovery speed reflects the efficiency of the communication system in returning to normal operation in the face of external interference or signal loss. Recovery security refers to whether data security and encryption protection remain intact after the communication is restored to normal, and whether there is any risk of theft, tampering, or other forms of attack. Recovery security assessments ensure that encryption protection remains effective even after communication is restored. Recovery evaluations comprehensively consider communication recovery speed and recovery security, assessing the communication system's ability to recover in the face of interference, failure, or attack. This evaluation reflects the system's resilience and security in the face of unexpected issues.
[0063] First, monitor the drone's communication status to determine the speed of communication recovery. For example, if a drone experiences a signal interruption during flight, record the duration of the signal loss and the time it takes to restore normal communication. This process can be achieved by simulating signal interference or loss events, such as intentionally jamming the communication signal or disconnecting the communication link, and recording the time it takes to restore normal communication.
[0064] Secondly, recovery security must be assessed. Specifically, after communication is restored, the security of data and communications must be ensured. For example, if a drone's communication signal is restored, verification of data tampering or encryption algorithm vulnerabilities is necessary to ensure that restored communications cannot be exploited by attackers for tampering or theft. This process is typically performed using cryptographic verification tools, such as verifying recovered encryption keys and verifying the integrity of communication protocols.
[0065] After obtaining the recovery speed and recovery security, a recovery evaluation is constructed, combining these two indicators to evaluate the recovery capability of the communication system. For example, if the recovery speed is slow and the security after recovery is low, a low recovery evaluation is given, indicating that the performance under abnormal conditions is not ideal; conversely, if the recovery speed is fast and the security after recovery is high, the evaluation is good.
[0066] Recovery testing is then conducted based on recovery evaluation, stability testing, cryptographic security evaluation, and cryptographic effectiveness evaluation to verify the overall recovery capabilities of the drone communication system in the event of interference, failure, and other abnormal conditions. Recovery testing not only considers recovery speed and recovery security but also integrates other test results, such as flight trajectory stability in stability testing and encryption algorithm strength in cryptographic security evaluation, to comprehensively assess the communication system's response capabilities.
[0067] Ultimately, by combining the above test results, a comprehensive communication evaluation result is generated. This result not only includes communication recovery capabilities, but also comprehensively evaluates other key factors such as the effectiveness of cryptographic protection and flight stability, helping developers understand the security and stability of drone systems in complex environments.
[0068] This step allows for the evaluation and optimization of the drone's communication system's resilience, ensuring rapid recovery from unexpected situations such as signal loss or attacks while maintaining data security. Recovery testing not only assesses recovery speed but also focuses on the security of communications after restoration, further enhancing the drone's anti-interference capabilities and safety and reliability.
[0069] Furthermore, the step S300 also includes the following steps: establishing a multi-level sensitivity level based on the drone's mission execution data; performing hierarchical encryption verification based on the multi-level sensitivity level to establish an auxiliary analysis result; and using the auxiliary analysis result to compensate for the cryptographic security evaluation.
[0070] Specifically, mission data refers to data generated by a drone while performing a specific mission. This mission data includes the drone's mission objectives, sensor data, captured images or videos, and mission status information. Multi-level sensitivity levels are defined based on the type of mission the drone is performing and the sensitivity of the data involved. Hierarchical encryption verification uses encryption technologies of varying strengths according to the sensitivity level of the data. For highly sensitive data, more complex and powerful encryption algorithms (such as AES-256) are used, while for less sensitive data, weaker encryption methods are used. Encryption verification ensures that data at each level is adequately protected according to its sensitivity. Auxiliary analysis results, based on hierarchical encryption verification, are used to supplement and improve the cryptographic security assessment. These analysis results help confirm whether data of different sensitivity levels is appropriately encrypted, further enhancing the accuracy and comprehensiveness of the cryptographic security assessment. Cryptographic security assessment compensation involves correcting or enhancing cryptographic security based on the auxiliary analysis results.
[0071] First, a multi-level sensitivity hierarchy is established based on mission data, such as images, videos, or sensor data collected by drones during filming missions. For example, when a drone performs a security surveillance mission, the images and information collected are classified as highly sensitive and require the strictest security measures. On the other hand, if a drone performs a simple weather monitoring mission, the data collected is classified as less sensitive. These sensitivity levels are typically determined based on the nature of the mission, the confidentiality requirements of the data, and the level of risk involved in executing the mission.
[0072] Based on the determined sensitivity level, different encryption strengths and algorithms are set for different levels of data. This is the process of hierarchical encryption verification. For highly sensitive task data, advanced encryption algorithms such as AES (Advanced Encryption Standard) 256-bit encryption are used to ensure high security during data transmission and storage. For less sensitive task data, lower-strength encryption such as AES 128-bit encryption is used to meet certain security requirements while conserving computing resources.
[0073] During hierarchical encryption verification, sensitive data for each task is analyzed to determine whether its encryption strength is sufficient. Based on the results of the encryption verification, auxiliary analysis results are generated to supplement the cryptographic security evaluation. For example, if a sensitive task data is found to be encrypted using a weak encryption algorithm during transmission, the auxiliary analysis results will indicate that the encryption is insecure and require adjustment of the encryption algorithm or encryption key length.
[0074] The results of the auxiliary analysis are used to further compensate for password security. This means adjustments will be made based on the analysis results to optimize the original password security rating. For example, if the sensitivity level of certain task data is underestimated, stronger encryption measures will be applied to this data and the password security rating will be recalculated to ensure the security of the task data is fully protected.
[0075] By combining the sensitivity level of mission data with encryption measures, encryption strategies can be dynamically adjusted according to the security requirements of different missions to ensure the security of mission data.
[0076] Furthermore, the method further includes: establishing an encryption weakness database according to the test verification results, generating optimization feedback based on the encryption weakness database, and performing password test management according to the optimization feedback.
[0077] Specifically, based on the test verification results, weaknesses in encryption protection are analyzed and recorded, and feedback information is generated. This feedback information can provide a basis for subsequent improvements to cryptographic protection mechanisms and assist developers in optimization. The Cryptographic Weakness Database is a database that stores information such as encryption algorithms, key lengths, and protocols that are insufficiently protected, have vulnerabilities, or do not meet security standards. This database is used to record encryption weaknesses discovered in the system and provide data support for further optimization of encryption schemes. Optimization feedback is a series of improvement suggestions generated based on the information in the Cryptographic Weakness Database. These suggestions include modifying encryption algorithms, increasing key lengths, and strengthening protocol security, with the goal of improving encryption protection levels. Cryptographic test management refers to the process of continuously monitoring and managing encryption schemes, encryption algorithms, encryption keys, etc. This includes adjusting and optimizing existing encryption test schemes to ensure that encryption measures are always secure and can respond to new security threats.
[0078] During the testing and verification process, weaknesses in encryption measures are identified and recorded. For example, during a penetration test of drone communications, if the encryption algorithm used for certain communications (such as AES-128) is found to be at risk of being cracked, the system will record this issue in the encryption vulnerability database. The database contains detailed information on the encryption algorithm, key length, communication protocol, and other aspects, indicating which areas have potential security vulnerabilities or do not meet best security standards.
[0079] Once cryptographic weaknesses are identified and stored in a database, they are analyzed and feedback is generated to optimize them. This feedback includes suggestions such as switching to a stronger encryption algorithm (e.g., upgrading from AES-128 to AES-256), increasing key lengths, improving key management strategies, or modifying communication protocols to include data validation. This feedback can be directly applied to optimizing encryption strategies and can also serve as a basis for future cryptographic security testing and policy adjustments.
[0080] Guided by optimization feedback, cryptographic testing management aims to regularly update and adjust encryption schemes to adapt to new security threats or attack methods. For example, if an encryption algorithm is found to be vulnerable to quantum computer attacks, optimization feedback may recommend switching to a quantum-resistant encryption algorithm. Cryptographic testing management involves not only executing tests and providing feedback, but also continuously monitoring the performance of the encryption system to ensure its continued effectiveness and security.
[0081] By establishing a database of cryptographic weaknesses and generating optimization feedback, weaknesses in encryption measures can be quickly identified and remediated, thereby continuously improving the security of drone systems. This mechanism provides a dynamic, feedback-driven encryption optimization process, ensuring that drone communication systems always utilize the latest and most secure encryption technologies. Cryptographic testing management enables continuous monitoring and adjustment of encryption schemes, safeguarding data from attacks and preventing potential encryption cracking or data leaks.
[0082] In summary, the drone password application security detection method provided by the embodiment of the present application has the following technical effects: 1. By establishing a set of test scenarios and linking them with the drone's flight history, we can precisely construct test scenarios tailored to the specific flight scenarios, improving the targetedness and accuracy of testing. By optimizing test scenarios based on flight data and test preferences, we can flexibly adapt to different flight scenarios and ensure that all safety hazards are covered. This approach optimizes the efficiency of drone password testing, reduces resource waste, and improves the accuracy of test results.
[0083] 2. Through a comprehensive analysis of password authentication mechanisms, key lengths, and password lifecycles, the effectiveness and stability of passwords have been further enhanced. This meticulous assessment of each factor ensures that the encryption technology employed by the system remains effective under varying operating conditions, preventing password expiration or failure. This approach enhances the security of drone systems during extended missions and improves their ability to combat password cracking and leaks.
[0084] 3. Testers in this application do not need access to the target drone's internal design, source code, or configuration files; their assessment is based entirely on external communication data. By capturing, analyzing, and penetrating communication links, the solution can assess potential security vulnerabilities in the target drone's communications, such as weaknesses in encryption algorithms and deficiencies in authentication mechanisms. This allows independent security assessments regardless of the target drone's manufacturer, enhancing the versatility and universality of security testing.
[0085] Any step of the method described above can be stored as a computer instruction or program in an unlimited computer memory, and can be called and recognized by an unlimited computer processor to implement any method in the embodiments of the present application, without any unnecessary restrictions.
[0086] Furthermore, the terms "first" or "second" as described above not only represent an order relationship but also represent specific concepts and / or refer to the selectability of multiple elements, either individually or in combination. Obviously, those skilled in the art may make various modifications and variations to this application without departing from the scope of this application. Thus, if such modifications and variations fall within the scope of this application and its equivalents, this application is intended to include such modifications and variations.
Claims
1. The drone password application security detection method is characterized by: The method comprises: Acquire flight history data of the UAV, construct a flight test scenario set based on the flight history data, and establish a test solution set according to the scenario characteristics and test preferences of the flight test scenario set; Conduct penetration testing of drones based on a set of test scenarios and read real-time drone communication data; Performing communication evaluation on the real-time UAV communication data and establishing a communication evaluation result, wherein the communication evaluation includes a cryptographic security evaluation, a cryptographic validity evaluation, a stability test, and a recovery test; A response mapping between the communication evaluation result and the test scenario set is established, and a test verification result is generated according to the response mapping.
2. The drone password application security detection method according to claim 1, characterized in that: The performing communication evaluation on the real-time UAV communication data and establishing a communication evaluation result includes: Parsing the real-time drone communication data to obtain a communication encryption algorithm; Performing algorithm complexity analysis on the communication encryption algorithm to establish a first analysis result; Obtaining a communication protocol of the communication encryption algorithm, performing access authentication analysis of an identity authentication mechanism based on the communication protocol, and establishing a second analysis result, wherein the access authentication analysis includes identity authentication mechanism analysis and replay authentication analysis; A cryptographic security evaluation is established based on the first analysis result and the second analysis result, and a communication evaluation result is established using the cryptographic security evaluation.
3. The drone password application security detection method according to claim 2, characterized in that: The method of establishing a communication evaluation result by utilizing the password security evaluation includes: parsing the real-time drone communication data, obtaining a password verification mechanism, performing a verification mechanism analysis on the password verification mechanism, and establishing a third analysis result; obtaining key length data, and establishing a fourth analysis result based on the key length data; Obtaining a life cycle of the password, and establishing a fifth analysis result based on the life cycle; generating a password validity evaluation based on the third analysis result, the fourth analysis result, and the fifth analysis result; A communication evaluation result is established based on the password security evaluation and the password validity evaluation.
4. The drone password application security detection method according to claim 3, characterized in that: The establishing of a communication evaluation result according to the password security evaluation and the password validity evaluation includes: Acquire UAV flight data and mission execution data based on the real-time UAV communication data; Establishing a fitting flight trajectory based on the mission execution data, performing trajectory stability analysis on the UAV flight data according to the fitting flight trajectory, and establishing a first stability analysis result; Performing a task completion analysis on the task execution data to establish a second stable analysis result; Establishing a stability test according to the first stability analysis result and the second stability analysis result; A communication evaluation result is established based on the stability test, the password security evaluation, and the password validity evaluation.
5. The drone password application security detection method according to claim 4, characterized in that: The establishing of a communication evaluation result based on the stability test, the password security evaluation, and the password validity evaluation further includes: Acquiring a recovery speed of communication recovery, and establishing a first recovery evaluation based on the recovery speed; Obtaining restoration security of communication restoration, and establishing a second restoration evaluation based on the restoration security; A recovery test is established based on the first recovery evaluation and the second recovery evaluation, and a communication evaluation result is established based on the recovery test, the stability test, the password security evaluation, and the password validity evaluation.
6. The drone password application security detection method according to claim 2, characterized in that: The step of establishing a password security evaluation based on the first analysis result and the second analysis result further includes: Establish multi-level sensitivity levels based on drone mission data; Perform hierarchical encryption verification according to the multi-level sensitivity levels and establish auxiliary analysis results; The auxiliary analysis result is used to compensate for the password security evaluation.
7. The drone password application security detection method according to claim 1, characterized in that: The method further comprises: An encryption weakness database is established according to the test verification results, optimization feedback is generated based on the encryption weakness database, and password test management is performed according to the optimization feedback.