Unmanned aerial vehicle trusted digital identity recognition method and system thereof
By integrating a digital identity recognition module with a trusted management platform for binding and authentication, generating identity certificates, and collecting flight trajectories in real time, the problems of untrusted drone identities and lack of security control are solved, achieving trusted traceability of drone identities and efficient and secure air traffic management.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- EASTCOMPEACE TECH
- Filing Date
- 2025-04-24
- Publication Date
- 2026-07-24
AI Technical Summary
Existing drones suffer from problems such as unreliable identity authentication, low credibility of real-time operational identification information broadcasting, and a lack of full life-cycle safety management mechanisms, which affect air traffic safety and order and restrict the development of drone technology.
By integrating a drone digital identity recognition module onto the drone, binding and two-way authentication with a trusted digital identity management platform are achieved, generating and managing drone digital identity certificates, collecting and reporting flight trajectory information in real time, and using symmetric cryptography technology for multiple verifications to ensure the consistency and security of the binding relationship.
This enhances the credibility of drone identities, establishes a trust chain throughout the entire lifecycle, improves the efficiency and safety of air traffic management, and promotes the healthy development of the drone industry.
Smart Images

Figure CN120475375B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of unmanned aerial vehicle (UAV) technology, and more specifically to a method and system for trusted digital identity recognition of UAVs. Background Technology
[0002] In recent years, with the rapid development of drone technology and the significant reduction in manufacturing costs, drones have expanded widely from their initial military applications to civilian sectors, including aerial photography, logistics delivery, agricultural plant protection, power line inspection, and surveying. The widespread use of drones has greatly improved work efficiency, reduced labor costs, and driven innovation in related industries. However, the explosive growth of the drone market has also brought significant challenges to low-altitude airspace management.
[0003] Drone authentication issues:
[0004] Currently, drones lack secure and reliable digital identities before leaving the factory, making it difficult to trace drone information from its source. The current method of integrating terminal form factors as drone identifiers is prone to disassembly and illegal misuse, and cannot serve as a unique and reliable identity for drones.
[0005] The credibility issue of real-time identification information broadcasting:
[0006] According to national policy, drones should broadcast operational identification information in real time during flight for air traffic management purposes. However, existing safety control solutions mostly rely on mounted or integrated operational identification tag devices for real-time broadcasting. These devices are not issued by authorized institutions, therefore the reliability of the broadcast operational identification information is low, and it is not suitable as a data source for air traffic management and flight auditing.
[0007] The lack of a full lifecycle security management mechanism:
[0008] Existing drone safety management solutions lack a comprehensive safety control mechanism covering the entire drone lifecycle, from manufacturing and registration to flight control and deregistration. This deficiency creates loopholes in drone safety management throughout its lifecycle, hindering effective end-to-end supervision and control.
[0009] In summary, existing drone technology faces multiple challenges in low-altitude airspace management, including unreliable identity authentication, low credibility of real-time operational identification information broadcasts, and a lack of a comprehensive lifecycle safety management mechanism. These issues not only affect air traffic safety and order but also hinder the further development and application of drone technology. Summary of the Invention
[0010] To address the shortcomings of existing technologies, this invention provides a reliable digital identity recognition method and system for unmanned aerial vehicles (UAVs), aiming to solve the problems of traffic management and safety control of unmanned aerial and ground systems, including unmanned equipment and humanoid robots.
[0011] The present invention achieves the above objectives through the following technical solutions:
[0012] A method for trusted digital identity verification of unmanned aerial vehicles (UAVs) includes:
[0013] The drone integrates a drone digital identity recognition module to bind the drone and the drone digital identity recognition module. Each time it is powered on, the binding relationship with the drone flight control system is verified to see if it has changed, and the binding relationship verification result is recorded.
[0014] Once the binding relationship is verified, the drone digital identity recognition module accesses the trusted digital identity management platform and establishes an HTTPS / MQTTS secure connection with the platform, and performs two-way authentication. Only legitimate drone digital identity recognition modules can upload data.
[0015] During the real-name registration phase, the trusted digital identity management platform associates the drone's basic information with the real-name registration code, generates a drone digital identity certificate, and creates a configuration management task. After two-way authentication is successful, the drone digital identity recognition module obtains the configuration management task from the trusted digital identity management platform and installs the drone digital identity certificate into the drone digital identity recognition module.
[0016] During operation, the drone digital identity recognition module uploads the drone digital identity certificate to the platform for verification of the drone and real-name registration information. The drone digital identity recognition module collects, stores, and reports the drone flight trajectory information to the drone trusted digital identity management platform in real time. The drone trusted digital identity management platform records the flight trajectory information reported by the drone digital identity recognition module.
[0017] According to the present invention, a reliable digital identity recognition method for unmanned aerial vehicles (UAVs) is provided. After the UAV is powered on, the UAV digital identity recognition module uses symmetric cryptography to verify whether the binding relationship with the flight control system has changed. Specifically, the method includes:
[0018] If a change in the binding relationship is detected, a multi-verification mechanism is initiated, which is set with a predetermined number of verifications. If the consistency of the binding relationship cannot be verified within the number of verifications, the UAV digital identity recognition module automatically generates an exception log message and records the details of the verification failure. At the same time, it triggers the invalidation process of the UAV digital identity certificate, making the UAV digital identity certificate invalid.
[0019] According to the present invention, a method for trusted digital identity recognition of unmanned aerial vehicles (UAVs) includes a two-way authentication process comprising:
[0020] The drone digital identity recognition module calls the two-way authentication interface of the trusted digital identity management platform and sends the device certificate chain, which includes at least the issuing authority root certificate, the device manufacturer certificate, and the device certificate, to the trusted digital identity management platform.
[0021] The trusted digital identity management platform queries whether the certificate system is supported based on the public key ID in the root certificate of the issuing authority. If it is supported, the platform will sequentially verify the legitimacy of the root certificate, the device manufacturer certificate, and the device certificate.
[0022] If the root certificate, device manufacturer certificate, and device certificate are all valid, the trusted digital identity management platform considers the drone to be issued by a legitimate organization.
[0023] According to the present invention, a method for identifying a trusted digital identity of a drone, after determining that the drone is issued by a legitimate organization, further includes:
[0024] The trusted digital identity management platform will send a platform certificate chain, including at least the issuing authority root certificate and the platform certificate, to the drone digital identity recognition module;
[0025] The drone digital identity recognition module verifies the legitimacy of the received platform certificate chain; among them, the drone digital identity authentication module first verifies whether the issuing authority root certificate is the same as the root certificate stored locally. If they are the same, the public key of the root certificate is used to verify the legitimacy of the platform certificate.
[0026] If the platform certificate chain is valid, the drone digital identity recognition module considers the drone trusted digital identity management platform to be legitimate, thus completing the two-way authentication process between the drone and the drone trusted digital identity management platform.
[0027] According to the UAV trusted digital identity recognition method provided by the present invention, after two-way authentication is successful, the method further includes the following steps:
[0028] The drone digital identity recognition module synchronizes device anomaly information and drone digital identity certificates to the drone trusted digital identity management platform;
[0029] The drone trusted digital identity management platform synchronizes the received device anomaly information and drone digital identity certificates to the air traffic management platform;
[0030] The air traffic management platform verifies the legality of the synchronized drone digital identity certificates;
[0031] If the drone's digital identity certificate is valid, the air traffic management platform will identify the drone's identity information and the operational identification information associated with the drone based on the information in the drone's digital identity certificate. The drone's identity information includes at least the drone manufacturer, the drone's unique product identification code, the drone's flight control serial number, the drone's digital identity recognition module, and real-name registration information.
[0032] According to the reliable digital identity recognition method for unmanned aerial vehicles (UAVs) provided by the present invention, when the UAV digital identity recognition module detects an inconsistency in its binding relationship with the flight control system, a multi-verification mechanism is initiated. The UAV digital identity recognition module performs verification operations according to the following steps:
[0033] Initial verification: The current binding relationship is verified for the first time using AES symmetric cryptography, generating an encrypted binding relationship verification code. This verification code is a unique value calculated based on the AES algorithm and the binding relationship information of both parties. The generated verification code is compared with a pre-stored verification code or a verification code provided by the flight control system to verify the consistency of the binding relationship.
[0034] Repeated verification: If the initial verification fails, indicating an inconsistency in the binding relationship verification, a repeated verification mechanism is initiated. Repeated verification employs the same AES symmetric cryptography as the initial verification, but may use different encryption parameters or initialization vectors (IVs). Following a predetermined algorithm or rules, the binding relationship information is encrypted multiple times, generating corresponding checksums. The checksums generated in each repeated verification are compared with the expected value. If a checksum matches, the binding relationship is determined to be consistent in that verification, and repeated verification can be stopped. The predetermined algorithm or rules include at least adjusting encryption parameters, changing the encryption order, and introducing random factors.
[0035] Verification count control: After each verification, the number of verifications is recorded. If the number of verifications reaches a preset threshold, verification is stopped.
[0036] Anomaly Handling: If all verifications fail to confirm the consistency of the binding relationship within the verification count threshold, the drone digital identity recognition module determines that the binding relationship is abnormal and automatically triggers the anomaly log generation logic.
[0037] Therefore, this invention proposes a trusted digital identity recognition method for drones, constructing a secure and reliable digital identity certificate system for drones and their real-name registration information. The following are the beneficial effects of this invention:
[0038] Enhancing the Credibility of Drone Identity: This invention ensures the uniqueness and traceability of a drone's identity by incorporating key information such as the drone's unique product identification code, flight control serial number, unique identification code of the drone's digital identity recognition module, equipment manufacturer ID, and real-name registration code into the drone's digital identity certificate. Furthermore, the digital identity certificate employs advanced cryptographic technology for encryption, effectively preventing information tampering or forgery and enhancing the credibility of the drone's identity.
[0039] Establishing a trustworthy chain throughout the entire lifecycle: This invention integrates digital identity recognition technology into all aspects of drone manufacturing, real-name registration, flight control, and drone deregistration, forming a complete trustworthy chain. This ensures that the identity information and real-name registration information of drones can be accurately traced throughout their entire lifecycle, providing strong support for the safety management and supervision of drones.
[0040] Improving the efficiency of air traffic management: The introduction of digital identity certificates for drones enables air traffic management departments to quickly and accurately identify the identity and flight status of each drone, which helps air traffic management departments to more effectively arrange flight plans, plan flight routes, and avoid flight conflicts, thereby improving the efficiency and safety of air traffic management.
[0041] Promoting the Healthy Development of the Drone Industry: The implementation of this invention provides the drone industry with a safe and reliable identification and management solution, helping to regulate the drone market order. By ensuring the legal identity and flight behavior of drones, this invention promotes the healthy development of the drone industry and lays a solid foundation for the widespread application of drones.
[0042] In summary, the UAV trusted digital identity recognition method proposed in this invention has significant beneficial effects. It not only enhances the credibility of UAV identities and establishes a trust chain throughout the entire lifecycle, but also improves the efficiency of air traffic management and promotes the healthy development of the UAV industry. This method provides strong support for the safety management and supervision of UAVs and has broad application prospects and practical value.
[0043] A trusted digital identity recognition system for unmanned aerial vehicles (UAVs) includes:
[0044] The drone digital identity recognition module is used to perform the steps of the above-described drone trusted digital identity recognition method;
[0045] The trusted digital identity management platform is used to establish a secure connection with the drone digital identity recognition module, perform two-way identity authentication, and receive and store information synchronized by the drone digital identity recognition module.
[0046] The air traffic management platform is used to verify the legitimacy of drone digital identity certificates and to monitor and manage flight activities based on the identified drone information.
[0047] According to the present invention, a trusted digital identity recognition system for unmanned aerial vehicles (UAVs) is provided. The UAV digital identity recognition module includes an application processor, a baseband processor, a GNSS positioning processor, and an eSIM. The module has the following functions:
[0048] Mobile communication capabilities: Through the collaborative work of the baseband processor and eSIM, it enables connection and data transmission with mobile communication networks, supports access and authentication of mobile communication services, and ensures that the drone can conduct stable data communication during flight;
[0049] Flight trajectory acquisition capability: Utilizing the multi-constellation GNSS receiver function supported by the GNSS positioning processor, the flight trajectory information of the UAV is acquired in real time;
[0050] Sensitive information secure storage capability: The eSIM has a secure storage area for storing basic information about the drone, digital identity certificates, and other sensitive data related to drone identity authentication and safe flight.
[0051] According to the present invention, a trusted digital identity recognition system for unmanned aerial vehicles (UAVs) is provided, wherein the application processor serves as a scheduling and management function module, specifically including:
[0052] The digital identity management component is configured to connect to a trusted digital identity management platform to query and execute digital identity management tasks issued by the platform, parse and install received UAV digital identity certificates, and collect UAV GNSS location information and report it to relevant platforms or systems via the network.
[0053] The Profile Management Component is configured to connect to a trusted digital identity management platform to query and execute Profile management tasks issued by the platform, parse and install received Profiles, and assist in remote Profile management.
[0054] According to the present invention, a trusted digital identity recognition system for unmanned aerial vehicles (UAVs) is provided, wherein the baseband processor is configured as follows:
[0055] It encodes and decodes wireless signals to enable data transmission and reception, thereby providing mobile communication services; it communicates with the eSIM via the ISO7816 protocol to realize the authentication process of the mobile communication network; and it transmits CSIM AT commands sent by the application processor to the eSIM to facilitate the implementation of digital identity management functions for drones.
[0056] The eSIM is configured as follows:
[0057] Upon receiving a CSIM AT command from the baseband processor, it performs the corresponding mobile communication authentication operation according to the command content; it supports dynamically loading and switching profiles of different operators to select the optimal mobile communication service based on the current location of the drone or a preset policy; it provides a secure storage area for storing the drone's basic information, device certificate, drone digital identity certificate, and sensitive data related to mobile communication; and it works in conjunction with the application processor to respond to the application processor's requests for drone digital identity management functions.
[0058] Therefore, the UAV digital identity recognition module of this invention serves as a trusted digital identity source for UAVs, uniformly issued and managed by a nationally designated agency, ensuring the authority and credibility of the identity information. This module operates independently, without relying on other UAV attachments, guaranteeing the stability and reliability of identity recognition.
[0059] This invention, through a drone digital identity recognition module, enables online tracking and management of the entire lifecycle of drones, including manufacturing, registration, flight control, and deregistration. This helps establish complete drone management files, improves management efficiency, and ensures the legal and compliant use of drones.
[0060] The drone digital identity recognition module can independently perform functions such as identity authentication, online digital certificate issuance, real-name registration, flight information recording, and network reporting with a trusted digital identity management platform, providing a reliable data source for air traffic management or air law enforcement and ensuring the accuracy and effectiveness of management decisions.
[0061] The drone's digital identity module features secure storage, ensuring that the digital certificate stored within cannot be illegally tampered with. Flight information records are authentic, complete, and non-repudiable, providing reliable data support for air traffic management platforms.
[0062] Based on the trusted link established by the drone digital identity recognition module, the air traffic management platform can obtain drone flight information in real time, make timely management decisions, and help improve the efficiency and accuracy of air traffic management, ensuring the safety and order of air traffic.
[0063] The implementation of this invention provides a unified and standardized identification and management solution for the drone industry, which helps to promote the healthy development of the industry. By ensuring the legal identity and flight behavior of drones, this invention provides a strong guarantee for the widespread application of drones.
[0064] The present invention will now be described in further detail with reference to the accompanying drawings and specific embodiments. Attached Figure Description
[0065] Figure 1 This is a flowchart of an embodiment of a trusted digital identity recognition method for unmanned aerial vehicles (UAVs) according to the present invention.
[0066] Figure 2 This is a flowchart illustrating an embodiment of a trusted digital identity recognition method for unmanned aerial vehicles (UAVs) according to the present invention.
[0067] Figure 3 This is a schematic diagram of an embodiment of a trusted digital identity recognition system for unmanned aerial vehicles (UAVs) according to the present invention.
[0068] Figure 4 This is a schematic diagram of the drone digital identity recognition module in an embodiment of a drone trusted digital identity recognition system according to the present invention. Detailed Implementation
[0069] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.
[0070] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.
[0071] An embodiment of a trusted digital identity recognition method for unmanned aerial vehicles
[0072] See Figure 1 and Figure 2 This embodiment provides a method for trusted digital identity recognition of unmanned aerial vehicles (UAVs), including:
[0073] Step S1: The drone integrates a drone digital identity recognition module to bind the drone and the drone digital identity recognition module. Each time the drone is powered on, the binding relationship with the drone flight control system is checked to see if it has changed, and the binding relationship check result is recorded.
[0074] Step S2: After the binding relationship is verified, the drone digital identity recognition module accesses the trusted digital identity management platform and establishes an HTTPS / MQTTS secure connection with the platform, and performs two-way authentication. Only legitimate drone digital identity recognition modules can upload data.
[0075] Step S3, Real-name Registration Stage: The Trusted Digital Identity Management Platform associates the basic information of the drone with the real-name registration code, generates a digital identity certificate for the drone, and creates a configuration management task.
[0076] Step S4: After the two-way authentication is successful, the drone digital identity recognition module obtains the configuration management task from the trusted digital identity management platform and installs the drone digital identity certificate into the drone digital identity recognition module.
[0077] Step S5: During the operation phase, the drone digital identity recognition module uploads the drone digital identity certificate to the platform for verifying the drone and real-name registration information.
[0078] Step S6: The UAV digital identity recognition module collects, stores, and reports the UAV flight trajectory information to the UAV Trusted Digital Identity Management Platform in real time. The UAV Trusted Digital Identity Management Platform records the flight trajectory information reported by the UAV digital identity recognition module.
[0079] This embodiment proposes a method for unmanned aerial vehicle (UAV) digital identity recognition, including a UAV digital identity recognition module and a UAV trusted digital identity management platform. Its operating principle is as follows: First, the UAV digital identity recognition module is installed on the UAV. Through online issuance of UAV digital identity certificates, the UAV digital identity recognition module is dynamically bound to the UAV flight control system, ensuring that the UAV digital identity recognition module can only function properly on the bound UAV. Second, each time the UAV is powered on, it requests the UAV trusted digital identity management platform through the UAV digital identity recognition module for identity authentication, ensuring that only authorized UAVs can access the platform. Third, during UAV operation, the UAV digital identity recognition module collects, stores, and reports UAV flight trajectory information to the network in real time. Fourth, the UAV trusted digital identity management platform issues digital certificates online for the UAV digital identity recognition module, performs two-way authentication with the UAV digital identity recognition module, and records the flight trajectory information reported by the UAV digital identity recognition module to the network, providing a trusted data source for low-altitude UAV air traffic management and flight auditing.
[0080] The above scheme provides a reliable method for digital identification of drones in low-altitude air traffic management. This method issues a digital identity certificate for each drone online, which is equivalent to issuing an electronic ID card for the drone and assigning it a reliable digital identity code. This can not only accurately identify each drone, but also promote the transformation of the safety management model for low-altitude drones towards pre-emptive prevention, achieving the safety control effects of "pre-emptive prevention", "in-process monitoring" and "post-event audit".
[0081] In this embodiment, after the drone is powered on, the drone's digital identity recognition module uses symmetric cryptography to verify with the flight control system whether the binding relationship has changed. Specifically, this includes:
[0082] If a change in the binding relationship is detected, a multi-verification mechanism is initiated, which is set with a predetermined number of verifications. If the consistency of the binding relationship cannot be verified within the number of verifications, the UAV digital identity recognition module automatically generates an exception log message and records the details of the verification failure. At the same time, it triggers the invalidation process of the UAV digital identity certificate, making the UAV digital identity certificate invalid.
[0083] In step S1 above, the method provided in this embodiment is to integrate a drone digital identity recognition module into the drone. After power-on, this module accesses the drone's trusted digital identity management platform, and through the platform, writes the drone's basic information (including but not limited to a unique product identification code and flight control serial number) into the drone digital identity recognition module, and activates the one-to-one binding relationship between the drone digital identity recognition module and the drone. The drone digital identity recognition module acts as the drone's "electronic ID card" to identify the drone's digital identity.
[0084] In step S3 above, the two-way authentication process includes:
[0085] The drone digital identity recognition module calls the two-way authentication interface of the trusted digital identity management platform and sends the device certificate chain, which includes at least the issuing authority root certificate, the device manufacturer certificate, and the device certificate, to the trusted digital identity management platform.
[0086] The trusted digital identity management platform queries whether the certificate system is supported based on the public key ID in the root certificate of the issuing authority. If it is supported, the platform will sequentially verify the legitimacy of the root certificate, the device manufacturer certificate, and the device certificate.
[0087] If the root certificate, device manufacturer certificate, and device certificate are all valid, the trusted digital identity management platform considers the drone to be issued by a legitimate organization.
[0088] Once the drone is deemed to be issued by a legitimate organization, the trusted digital identity management platform will send a platform certificate chain, including at least the issuing organization's root certificate and the platform certificate, to the drone's digital identity recognition module.
[0089] The drone digital identity recognition module verifies the legitimacy of the received platform certificate chain; among them, the drone digital identity authentication module first verifies whether the issuing authority root certificate is the same as the root certificate stored locally. If they are the same, the public key of the root certificate is used to verify the legitimacy of the platform certificate.
[0090] If the platform certificate chain is valid, the drone digital identity recognition module considers the drone trusted digital identity management platform to be legitimate, thus completing the two-way authentication process between the drone and the drone trusted digital identity management platform.
[0091] Specifically, during identity authentication, the drone digital identity recognition module calls the two-way authentication interface of the drone trusted digital identity management platform, sending the device certificate chain to the platform. The device certificate chain includes, but is not limited to, the issuing authority root certificate, the device manufacturer certificate, and the device certificate. The drone trusted digital identity management platform first checks whether it supports the certificate system based on the public key ID in the issuing authority root certificate. If supported, it verifies whether the root certificate is the same as its own stored root certificate. If they are the same, it uses the public key of the root certificate to verify the legitimacy of the device manufacturer certificate. If legitimate, it verifies the legitimacy of the device certificate. If legitimate, the platform considers the drone to be issued by a legitimate organization, and then sends its own platform certificate chain to the drone digital identity recognition module. The platform certificate chain includes, but is not limited to, the issuing authority root certificate and the platform certificate. The drone digital identity authentication module first verifies whether the issuing authority root certificate is the same as the locally stored root certificate. If they are the same, it uses the public key of the root certificate to verify the legitimacy of the platform certificate. If legitimate, the drone trusted digital identity management platform is considered legitimate, and the two-way authentication process is completed.
[0092] In step S4 above, after mutual authentication is successful, the following steps are also included:
[0093] The drone digital identity recognition module synchronizes device anomaly information and drone digital identity certificate to the drone trusted digital identity management platform; the drone trusted digital identity management platform synchronizes the received device anomaly information and drone digital identity certificate to the air traffic management platform; the air traffic management platform verifies the legality of the synchronized drone digital identity certificate; if the drone digital identity certificate is legal, the air traffic management platform identifies the drone's identity information and the associated operational identification information based on the information in the drone digital identity certificate. The drone's identity information includes at least the drone manufacturer, the drone's unique product identification code, the drone flight control serial number, the drone digital identity recognition module, and real-name registration information.
[0094] In this embodiment, when the UAV digital identity recognition module detects an inconsistency in its binding relationship with the flight control system, it initiates a multiple verification mechanism. The UAV digital identity recognition module performs the verification operation according to the following steps:
[0095] Initial verification: The current binding relationship is verified for the first time using AES symmetric cryptography, generating an encrypted binding relationship verification code. This verification code is a unique value calculated based on the AES algorithm and the binding relationship information of both parties. The generated verification code is compared with a pre-stored verification code or a verification code provided by the flight control system to verify the consistency of the binding relationship.
[0096] Repeated verification: If the initial verification fails, indicating an inconsistency in the binding relationship verification, a repeated verification mechanism is initiated. Repeated verification employs the same AES symmetric cryptography as the initial verification, but may use different encryption parameters or initialization vectors (IVs). Following a predetermined algorithm or rules, the binding relationship information is encrypted multiple times, generating corresponding checksums. The checksums generated in each repeated verification are compared with the expected value. If a checksum matches, the binding relationship is determined to be consistent in that verification, and repeated verification can be stopped. The predetermined algorithm or rules include at least adjusting encryption parameters, changing the encryption order, and introducing random factors.
[0097] Verification count control: After each verification, the number of verifications is recorded. If the number of verifications reaches a preset threshold, verification is stopped.
[0098] Anomaly Handling: If all verifications fail to confirm the consistency of the binding relationship within the verification count threshold, the drone digital identity recognition module determines that the binding relationship is abnormal and automatically triggers the anomaly log generation logic.
[0099] Anomaly Log Generation: Based on the predefined log format and content, record detailed information about failed binding relationship verifications, including verification time, number of verifications, binding relationship status, etc., generate anomaly log information, and store it in the system-specified log file for subsequent analysis and troubleshooting.
[0100] Based on the above implementation principle, the multiple verification mechanism can leverage the security and reliability of AES symmetric cryptography to accurately and repeatedly verify the binding relationship between the UAV's digital identity recognition module and flight control system, ensuring the correctness and security of the binding relationship.
[0101] In summary, this embodiment proposes a trusted digital identity recognition method for drones, which constructs a secure and reliable digital identity certificate system for drones and their real-name registration information.
[0102] This embodiment ensures the uniqueness and traceability of the drone's identity by writing key information such as the drone's unique product identification code, flight control serial number, unique identification code of the drone's digital identity recognition module, equipment manufacturer ID, and real-name registration code into the drone's digital identity certificate. The digital identity certificate uses advanced cryptographic technology for encryption, effectively preventing information from being tampered with or forged, thus enhancing the credibility of the drone's identity.
[0103] This embodiment integrates digital identity recognition technology into all aspects of drone manufacturing, real-name registration, flight control, and drone deregistration, forming a complete and trustworthy chain. This ensures that the identity information and real-name registration information of drones can be accurately traced throughout their entire lifecycle, providing strong support for the safety management and supervision of drones.
[0104] The introduction of digital identity certificates for drones enables air traffic management departments to quickly and accurately identify the identity and flight status of each drone, which helps them to more effectively schedule flight plans, plan flight routes, and avoid flight conflicts, thereby improving the efficiency and safety of air traffic management.
[0105] This embodiment provides a secure and reliable identification and management solution for the drone industry, helping to regulate the drone market order. By ensuring the legal identity and flight behavior of drones, this invention promotes the healthy development of the drone industry and lays a solid foundation for the widespread application of drones.
[0106] An embodiment of a trusted digital identity recognition system for unmanned aerial vehicles (UAVs)
[0107] like Figure 3 and Figure 4 As shown, this embodiment provides a trusted digital identity recognition system for unmanned aerial vehicles (UAVs), comprising:
[0108] The drone digital identity recognition module is used to perform the steps of the above-described drone trusted digital identity recognition method;
[0109] The trusted digital identity management platform is used to establish a secure connection with the drone digital identity recognition module, perform two-way identity authentication, and receive and store information synchronized by the drone digital identity recognition module.
[0110] The air traffic management platform is used to verify the legitimacy of drone digital identity certificates and to monitor and manage flight activities based on the identified drone information.
[0111] This embodiment implements drone digital identity recognition through a drone digital identity recognition module and a drone trusted digital identity management platform. The issuance and management process of the drone digital identity recognition module includes:
[0112] (1) Manufacturing of the UAV Digital Identity Recognition Module: A nationally designated institution authorizes UAV digital identity recognition module manufacturers to issue equipment manufacturer certificates. Based on these certificates, the equipment manufacturers issue equipment certificates for their UAV digital identity recognition modules. During the manufacturing phase of the UAV digital identity recognition module, the equipment certificate is installed into the security chip within the module. The information in the equipment certificate includes, but is not limited to, the unique identifier of the UAV digital identity recognition module, the equipment manufacturer ID, and the root certificate public key ID. The equipment certificate for the UAV digital identity recognition module is used for end-to-end identity authentication with the UAV trusted digital identity management platform.
[0113] (2) Integration and binding of the UAV digital identity recognition module with the UAV: During the UAV production and assembly stage, UAV manufacturers purchase UAV digital identity recognition modules from nationally designated institutions and integrate them with the UAV's flight control system in both software and hardware. Before the UAV leaves the factory, the UAV digital identity recognition module is powered on and first performs two-way authentication with the trusted digital identity management platform using the device certificate. After successful authentication, the trusted digital identity management platform writes the UAV's basic information (including but not limited to the UAV's unique product identification code and flight control serial number) into the UAV digital identity recognition module and activates the one-to-one binding relationship between the UAV digital identity recognition module and the UAV flight control system.
[0114] Issuance and Installation of Drone Digital Identity Certificates: After the drone leaves the factory, each time it is powered on, the drone's digital identity recognition module will access the Trusted Digital Identity Management Platform for identity authentication and synchronize the drone's basic information to the platform. The Trusted Digital Identity Management Platform then accesses the Air Traffic Management Platform, using the drone's unique product identification code to check if the drone has real-name registration information. If so, it retrieves the real-name registration code from the Air Traffic Management Platform. The Air Traffic Management Platform associates the drone's basic information and the real-name registration code to generate a drone digital identity certificate (certificate information includes, but is not limited to, the unique product identification code, flight control serial number, unique identification code of the drone's digital identity recognition module, equipment manufacturer ID, and real-name registration code). The drone digital identity certificate is then installed into the drone's digital identity recognition module.
[0115] In this embodiment, the UAV digital identity recognition module includes an application processor, a baseband processor, a GNSS positioning processor, and an eSIM. It is evident that the UAV digital identity recognition module is a module comprised of multiple core processors. These core processors include, but are not limited to, an application processor (AP), a baseband processor (BP), a GNSS positioning processor, and an eSIM. The UAV digital identity recognition module can exist as a communication module chip or as an independent terminal device, and this module possesses the following functions:
[0116] Mobile communication capabilities: Through the collaborative work of the baseband processor and eSIM, it enables connection and data transmission with mobile communication networks, supports access and authentication of mobile communication services, and ensures that the drone can conduct stable data communication during flight.
[0117] Flight trajectory acquisition capability: Utilizing the multi-constellation GNSS receiver function supported by the GNSS positioning processor, the flight trajectory information of the UAV is acquired in real time, including parameters such as position, speed, and altitude, providing accurate data support for the flight control and safety monitoring of the UAV.
[0118] Sensitive information secure storage capability: The eSIM has a secure storage area for storing the drone's basic information, digital identity certificate, and other sensitive data related to drone identity authentication and safe flight. This ensures the confidentiality, integrity, and availability of this data during storage and transmission, preventing unauthorized access and tampering.
[0119] With the above-mentioned functional configuration, the UAV digital identity recognition module can fully meet the communication, positioning and secure storage needs of UAVs during flight, providing strong technical support for the safe flight and remote management of UAVs.
[0120] In this embodiment, the application processor serves as a scheduling and management function module, specifically including:
[0121] The digital identity management component is configured to connect to a trusted digital identity management platform to query and execute digital identity management tasks issued by the platform, parse and install received UAV digital identity certificates, and collect UAV GNSS location information and report it to relevant platforms or systems via the network.
[0122] The Profile management component is configured to connect to a trusted digital identity management platform to query and execute profile management tasks issued by the platform, parse and install received profiles, and assist in remote profile management, including but not limited to profile updates, deletions, or configuration adjustments.
[0123] In this embodiment, the baseband processor is configured as follows:
[0124] It encodes and decodes wireless signals to enable data transmission and reception, thereby providing mobile communication services; it communicates with the eSIM via the ISO7816 protocol to realize the authentication process of the mobile communication network; and it transmits CSIM AT commands sent by the application processor to the eSIM to facilitate the implementation of digital identity management functions for drones.
[0125] In this embodiment, eSIM is configured as follows:
[0126] Upon receiving a CSIM AT command from the baseband processor, it performs the corresponding mobile communication authentication operation according to the command content; it supports dynamically loading and switching profiles of different operators to select the optimal mobile communication service based on the drone's current location or preset policies; it provides a secure storage area for storing the drone's basic information, device certificate, drone digital identity certificate, and sensitive data related to mobile communication, and supports the installation of certificates such as device certificate and drone digital identity certificate; it works in conjunction with the application processor to respond to the application processor's requests for drone digital identity management functions.
[0127] In this embodiment, the GNSS positioning processor is configured as follows:
[0128] It supports multi-constellation GNSS receiver functionality, enabling compatibility and processing of signals from various positioning systems such as GPS, BDS, GLONASS, and Galileo; it provides fast and accurate positioning services, offering real-time position, speed, and time information for drones to meet their flight control, navigation, and safety monitoring needs.
[0129] In addition, in this embodiment, the drone digital identity recognition module can be in the form of a communication module, a chip, or a terminal.
[0130] In this embodiment, the UAV digital identity recognition module is integrated with the UAV flight control system to achieve one-to-one binding with the UAV. However, it can be configured not to be integrated with the UAV flight control system as needed, and the binding function can be disabled.
[0131] In this embodiment, the drone digital identity recognition module can be integrated into the drone cabin or mounted on the outside of the drone fuselage through other fastening structures;
[0132] In this embodiment, the UAV digital identity recognition module can be used to identify the digital identity of UAVs, and can also be used for the digital identity recognition of other low-altitude unmanned equipment, including but not limited to: unmanned boats, unmanned vehicles, unmanned vessels, and humanoid robots.
[0133] In this embodiment, the trusted computing function of the UAV digital identity recognition module can be implemented based on international asymmetric ECC and AES algorithms, or it can be implemented based on SM2, SM3, and SM4 algorithms.
[0134] In summary, the drone digital identity recognition module in this embodiment serves as a trusted source of digital identity for the drone, issued and managed uniformly by a nationally designated agency, ensuring the authority and credibility of the identity information. This module operates independently, without relying on other drone attachments, guaranteeing the stability and reliability of identity recognition.
[0135] This embodiment utilizes a drone digital identity recognition module to achieve online tracking and management of the entire drone lifecycle, including manufacturing, registration, flight control, and deregistration. This facilitates the establishment of complete drone management files, improves management efficiency, and ensures the legal and compliant use of drones. The drone digital identity recognition module can independently perform functions such as identity authentication with a trusted digital identity management platform, online digital certificate issuance, real-name registration, flight information recording, and online reporting. This provides a reliable data source for air traffic management or air law enforcement, ensuring the accuracy and effectiveness of management decisions.
[0136] The drone digital identity module features secure storage, ensuring that the digital certificates stored within cannot be illegally tampered with. Flight information records are authentic, complete, and non-repudiable, providing reliable data support for the air traffic management platform. Based on the trusted link established by the drone digital identity module, the air traffic management platform can acquire drone flight information in real time, making timely management decisions, thus improving the efficiency and accuracy of air traffic management and ensuring air traffic safety and order.
[0137] Therefore, the method and system of this embodiment provide a unified and standardized identity recognition and management solution for the drone industry, which helps to promote the healthy development of the industry and provides a strong guarantee for the widespread application of drones by ensuring the legal identity and flight behavior of drones.
[0138] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0139] The above embodiments are merely preferred embodiments of the present invention and should not be construed as limiting the scope of protection of the present invention. Any non-substantial changes and substitutions made by those skilled in the art based on the present invention shall fall within the scope of protection claimed by the present invention.
Claims
1. A method for trusted digital identity recognition of unmanned aerial vehicles (UAVs), characterized in that, include: The drone integrates a drone digital identity recognition module to bind the drone and the drone digital identity recognition module. Each time it is powered on, the binding relationship with the drone flight control system is verified to see if it has changed, and the binding relationship verification result is recorded. Once the binding relationship is verified, the drone digital identity recognition module accesses the trusted digital identity management platform and establishes an HTTPS / MQTTS secure connection with the platform, and performs two-way authentication. Only legitimate drone digital identity recognition modules can upload data. During the real-name registration phase, the trusted digital identity management platform associates the drone's basic information with the real-name registration code, generates a drone digital identity certificate, and creates a configuration management task. After two-way authentication is successful, the drone digital identity recognition module obtains the configuration management task from the trusted digital identity management platform and installs the drone digital identity certificate into the drone digital identity recognition module. During operation, the drone digital identity recognition module uploads the drone's digital identity certificate to the platform for verifying the drone and real-name registration information; The drone digital identity recognition module collects, stores, and reports drone flight trajectory information to the drone trusted digital identity management platform in real time. The drone trusted digital identity management platform records the flight trajectory information reported by the drone digital identity recognition module. When the UAV digital identity recognition module detects an inconsistency in its binding relationship with the flight control system, it initiates a multi-verification mechanism. The UAV digital identity recognition module performs the verification operation according to the following steps: Initial verification: The current binding relationship is verified for the first time using AES symmetric cryptography, generating an encrypted binding relationship verification code. This verification code is a unique value calculated based on the AES algorithm and the binding relationship information of both parties. The generated verification code is compared with a pre-stored verification code or a verification code provided by the flight control system to verify the consistency of the binding relationship. Repeated verification: If the initial verification fails, indicating an inconsistency in the binding relationship verification, a repeated verification mechanism is initiated. Repeated verification employs the same AES symmetric cryptography as the initial verification, but may use different encryption parameters or initialization vectors (IVs). Following a predetermined algorithm or rules, the binding relationship information is encrypted multiple times, generating corresponding checksums. The checksums generated in each repeated verification are compared with the expected value. If a checksum matches, the binding relationship is determined to be consistent in that verification, and repeated verification can be stopped. The predetermined algorithm or rules include at least adjusting encryption parameters, changing the encryption order, and introducing a random factor. Verification count control: After each verification, the number of verifications is recorded. If the number of verifications reaches a preset threshold, verification is stopped. Anomaly Handling: If all verifications fail to confirm the consistency of the binding relationship within the verification count threshold, the drone digital identity recognition module determines that the binding relationship is abnormal and automatically triggers the anomaly log generation logic.
2. The method according to claim 1, characterized in that, The two-way authentication process includes: The drone digital identity recognition module calls the two-way authentication interface of the trusted digital identity management platform and sends the device certificate chain, which includes at least the issuing authority root certificate, the device manufacturer certificate, and the device certificate, to the trusted digital identity management platform. The trusted digital identity management platform checks whether the certificate belongs to the system based on the public key ID in the root certificate of the issuing authority. If it does, it verifies the legitimacy of the root certificate, the device manufacturer certificate, and the device certificate in sequence. If the root certificate, device manufacturer certificate, and device certificate are all valid, the trusted digital identity management platform considers the drone to be issued by a legitimate organization.
3. The method according to claim 2, characterized in that, After considering the drones to be issued by legitimate entities, this also includes: The trusted digital identity management platform will send a platform certificate chain, including at least the issuing authority root certificate and the platform certificate, to the drone digital identity recognition module; The drone digital identity recognition module verifies the legitimacy of the received platform certificate chain; among them, the drone digital identity authentication module first verifies whether the issuing authority root certificate is the same as the root certificate stored locally. If they are the same, the public key of the root certificate is used to verify the legitimacy of the platform certificate. If the platform certificate chain is valid, the drone digital identity recognition module considers the drone trusted digital identity management platform to be legitimate, thus completing the two-way authentication process between the drone and the drone trusted digital identity management platform.
4. The method according to claim 3, characterized in that, After mutual authentication is successful, the following steps are also included: The drone digital identity recognition module synchronizes device anomaly information and drone digital identity certificates to the drone trusted digital identity management platform; The drone trusted digital identity management platform synchronizes the received device anomaly information and drone digital identity certificates to the air traffic management platform; The air traffic management platform verifies the legality of the synchronized drone digital identity certificates; If the drone's digital identity certificate is valid, the air traffic management platform will identify the drone's identity information and the operational identification information associated with the drone based on the information in the drone's digital identity certificate. The drone's identity information includes at least the drone manufacturer, the drone's unique product identification code, the drone's flight control serial number, the drone's digital identity recognition module, and real-name registration information.
5. A trusted digital identity recognition system for unmanned aerial vehicles (UAVs), characterized in that, include: A drone digital identity recognition module is used to perform the steps of the drone trusted digital identity recognition method according to any one of claims 1 to 4; The trusted digital identity management platform is used to establish a secure connection with the drone digital identity recognition module, perform two-way identity authentication, and receive and store information synchronized by the drone digital identity recognition module. The air traffic management platform is used to verify the legitimacy of drone digital identity certificates and to monitor and manage flight activities based on the identified drone information.
6. The system according to claim 5, characterized in that: The UAV digital identity recognition module includes an application processor, a baseband processor, a GNSS positioning processor, and an eSIM. This module has the following functions: Mobile communication capabilities: Through the collaborative work of the baseband processor and eSIM, it enables connection and data transmission with mobile communication networks, supports access and authentication of mobile communication services, and ensures that the drone can conduct stable data communication during flight; Flight trajectory acquisition capability: Utilizing the multi-constellation GNSS receiver function supported by the GNSS positioning processor, the flight trajectory information of the UAV is acquired in real time; Sensitive information secure storage capability: The eSIM has a secure storage area for storing basic information about the drone, digital identity certificates, and other sensitive data related to drone identity authentication and safe flight.
7. The system according to claim 6, characterized in that, The application processor, as a scheduling and management function module, specifically includes: The digital identity management component is configured to connect to a trusted digital identity management platform to query and execute digital identity management tasks issued by the platform, parse and install received UAV digital identity certificates, and collect UAV GNSS location information and report it to relevant platforms or systems via the network. The Profile Management Component is configured to connect to a trusted digital identity management platform to query and execute Profile management tasks issued by the platform, parse and install received Profiles, and assist in remote Profile management.
8. The system according to claim 6, characterized in that: The baseband processor is configured to: It encodes and decodes wireless signals to enable data transmission and reception, thereby providing mobile communication services; it communicates with the eSIM via the ISO7816 protocol to realize the authentication process of the mobile communication network; and it transmits the CSIMAT command sent by the application processor to the eSIM to facilitate the implementation of the digital identity management function of the drone. The eSIM is configured as follows: Upon receiving a CSIM AT command from the baseband processor, the corresponding mobile communication authentication operation is performed according to the command content; it supports dynamically loading and switching profiles of different operators to select the optimal mobile communication service based on the current location of the drone or a preset strategy. Provides a secure storage area for storing basic information about the drone, device certificates, drone digital identity certificates, and sensitive data related to mobile communications; Works in conjunction with the application processor to respond to the application processor's requests for drone digital identity management functionality.