Unmanned aerial vehicle group access authentication system and method for power system
Through the device compatibility adaptation and batch authentication modules, combined with edge computing and cloud authentication centers, the compatibility and security issues of the drone access authentication system are solved, and the efficient and safe access of drone swarms to the power system is achieved.
Patent Information
- Application Number
- CN202510805241.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-17
- Publication Date
- 2025-09-05
AI Technical Summary
The existing drone access authentication system has compatibility issues, large computational complexity, and low security in the power system, making it difficult to support unified authentication and effective security management of multiple drone devices.
The device compatibility adaptation module is used to convert the drone identity information into a standard format. Combined with the batch authentication module and the authentication and authorization module, batch access of drone swarms is achieved through the edge computing authentication gateway and the cloud authentication center. The anomaly detection and security protection module is used to monitor drone behavior in real time to ensure safety.
The applicability of the authentication system is improved, the computational complexity is reduced, and the security and reliability of drone swarm access are improved through real-time monitoring and safety protection measures.
Smart Images

Figure CN120602939A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of power systems, and in particular to a drone swarm access authentication system and method for a power system. Background Art
[0002] With the development of unmanned aerial vehicle (UAV) technology, its application in power systems is becoming more and more extensive, such as transmission line inspection, troubleshooting, and equipment maintenance. However, to ensure the security of the power grid and prevent unauthorized drones from accessing power facilities, effective access authentication for drone swarms is crucial. The existing drone access authentication system is a security mechanism for managing and verifying the identity of drone swarms entering the power system, ensuring that only authorized drones can access related networks and control commands. However, the existing drone access authentication system has the following shortcomings during use:
[0003] 1. Compatibility issues: Existing authentication solutions are difficult to support all devices. The main reasons include inconsistent protocol standards, significant differences in authentication methods, and different software and hardware interfaces.
[0004] 2. Due to the large number of drones in a drone swarm, the existing technology of authenticating each drone access to the swarm requires a lot of computation.
[0005] 3. The security of drone access is low; based on the above situation, this application proposes a drone group access authentication system and authentication method for power systems. Summary of the Invention
[0006] Based on the technical problems existing in the background technology, the present invention proposes a drone swarm access authentication system and an authentication method for the power system. The drone identity information is converted into a standard format through the equipment compatibility adaptation module to improve the scope of application. The batch authentication module and the authentication and authorization module are coordinated to realize batch access of the drone swarm and reduce the amount of calculation. In addition, during the authentication process, the anomaly detection and security protection module is used to monitor the behavior of the drone in real time, detect potential security threats, and take necessary security protection measures to improve security.
[0007] The UAV swarm access authentication system for a power system proposed in the present invention includes a UAV terminal, a cloud authentication center, and an edge computing authentication gateway. The edge computing authentication gateway is connected to the UAV terminal and the cloud authentication center.
[0008] The drone terminal includes a digital certificate module, an encryption communication module, and a log storage and audit module;
[0009] The cloud authentication center includes an identity management module, an authentication and authorization module, a communication security module, and an anomaly detection and security protection module;
[0010] The edge computing authentication gateway includes a batch authentication module, a device compatibility adaptation module, and a task scheduling and policy management module.
[0011] Preferably, the digital certificate module is used to generate, manage and use digital certificates for identity authentication and signature verification, ensuring that the identity of the drone is trusted and authenticated when accessing the authentication system;
[0012] The logical steps of its operation are as follows:
[0013] S101: The drone submits a digital certificate application to the authentication and authorization module through the certificate request protocol, and submits the public key and identity information. The identity management module issues a PKI certificate.
[0014] S102: The drone stores the private key and public key in the log storage and audit module. The private key is used for signature authentication, and the public key is used for identity authentication.
[0015] S103: The drone uses the private key to sign the identity authentication request to prove the authenticity of the identity;
[0016] S104: The authentication system verifies the digital signature and PKI certificate sent by the drone using the public key of the certificate to ensure that the drone’s identity has not been tampered with;
[0017] The encryption communication module is used to ensure the communication and security between the UAV and the power system, and uses encryption algorithms to encrypt and decrypt the communication content to prevent the data from being intercepted or tampered during transmission;
[0018] The encryption communication module includes a key management unit, an encryption engine unit, a hash and authentication unit, a protocol adaptation layer, and a log and audit interface. The key management unit is used to manage the public and private key pairs, session keys, and pre-shared keys of the drone. The encryption engine unit is used to implement data encryption and digital signatures.
[0019] The log storage and audit module is used to log the activities and communications of the drone, and audit each operation in the authentication system for subsequent traceability and security review. The logs are stored in the blockchain to ensure that the log data cannot be tampered with.
[0020] Preferably, the identity management module is responsible for generating and managing the drone's DID identifier and issuing a PKI certificate for it. The DID identifier generated by the identity management module will be registered on the blockchain. When the drone initiates an identity authentication request, the identity management module will extract and verify the DID identifier and PKI certificate to check whether they are valid. After successful authentication, the identity management module will store the drone's identity data in the cloud database.
[0021] During the identity revocation process, the identity management module will trigger the revocation operation and mark the drone's DID identifier and PKI certificate as invalid;
[0022] The identity management module supports the registration and authentication of drones from different manufacturers through a unified DID standard and PKI certificate format.
[0023] Preferably, the authentication and authorization module is used to authenticate the drone's DID identifier and PKI certificate to ensure that only legitimate drones can access the power system;
[0024] The formula used in authentication is as follows:
[0025] PKI certificate authentication: , (e, N) is the public key, M′ is the decrypted message, and M is the message to be signed. If M′=M, the signature is valid;
[0026] DID identifier authentication: H(M)=hash(M), where H(M) is the hash value of the message M, which can be used to verify the uniqueness of the identity;
[0027] The authentication and authorization module is also used to determine the resources that the drone can access and the tasks that it can perform based on the authenticated identity information. The authentication and authorization module performs permission checks based on the drone's identity information and role to ensure that the drone is qualified to access the requested resources, and the permission check is performed according to the role-based access control or attribute-based access control policy. After verifying the identity and performing the permission check, the authentication and authorization module decides whether to grant the drone permission to access specific resources. After successful authorization, the authentication and authorization module creates a session token for the drone as an identifier of the current operation session, and the authentication and authorization module records the detailed information of each identity authentication and authorization decision in the log storage and audit module. After the drone completes the task, the authentication and authorization module will actively terminate the current session;
[0028] Role-based access control determines the permissions of the drone based on its role, and its permission allocation can be expressed as P(U) = , where U is the drone, R(U) is the set of roles the user has, and P(r) is the permissions that role r has;
[0029] Attribute-based access control is based on the attributes of the drone to determine whether it has the right to perform a specific task. The authorization rules are usually based on a set of attributes A and policy S. Decision = f(A, S), where A includes identity, task, location, and time, and S is the access policy defined by the system;
[0030] The authentication and authorization module works in conjunction with the anomaly detection and security protection module to monitor the drone's behavior and session status in real time and identify possible anomalies. When abnormal behavior is detected, the authentication and authorization module will automatically initiate security protection measures to ensure that the drone's identity has not been forged. Its security protection measures include temporarily freezing the session, preventing further resource access, and initiating a re-authentication review.
[0031] When the drone mission ends or its identity is revoked, the authentication and authorization module will proactively revoke all access rights of the drone. After revoking the rights, the authentication and authorization module will terminate the drone's session token and update the relevant session status.
[0032] Preferably, the anomaly detection and safety protection module is used to monitor the behavior of the drone in real time, detect potential security threats, and take necessary safety protection measures. Its operating logic steps are as follows:
[0033] S201: Collect drone activity data and communication data from the drone terminal, cloud authentication center, and other related systems;
[0034] S202: Analyze the data collected in S201 in real time using a machine learning algorithm and compare it with normal behavior patterns to identify possible abnormal behaviors, including but not limited to: ①, identity forgery; ②, authority abuse; ③, communication anomalies; ④, abnormal flight trajectory;
[0035] When identifying abnormal behavior, the formula used is: min ;
[0036] in is the i-th cluster, is the center of the cluster, It is a data point. If the data point is too far away from the center of a cluster, it will be considered an outlier.
[0037] S203: For the detected abnormal behavior, the anomaly detection and security protection module analyzes its potential threat and determines whether it is a malicious attack, system failure or misoperation;
[0038] S204: After detecting abnormal behavior, the anomaly detection and security protection module will automatically trigger security protection measures according to the set security policy. Its security policy includes but is not limited to: ① If the drone is found to have identity forgery or authority abuse, immediately terminate communication with the drone; ② If the drone's operation exceeds the authorized scope, the anomaly detection and security protection module will proactively revoke the drone's permissions; ③ If the drone's behavior poses a security threat, the anomaly detection and security protection module can isolate it and stop it from executing its mission to prevent further damage; ④ For abnormal events with high threat levels, automatically notify the administrator for manual intervention;
[0039] S205: The anomaly detection module will record all abnormal events, security responses and protective measures to provide a basis for subsequent audits and analysis.
[0040] Preferably, the batch authentication module is used to verify the legitimacy of the identities of the drone group and to establish a secure communication link with the drones. Its operating logic steps are as follows:
[0041] S301: Preload the whitelist, root certificate, and authentication policy of the drone swarm, and establish a secure communication channel with the edge computing node;
[0042] S302: Receive access request from the drone group and extract device identification and authentication credentials;
[0043] S303: Use the lightweight authentication protocol to verify the legitimacy of the identities of multiple drones. The formula used is:
[0044] HMAC , )=SHA256(( ⊕opad)∥SHA256(( ⊕ipad)∥ ));
[0045] The gateway compares the calculated result with the authentication tag attached to the drone. If they match, the identity is legitimate. The HMAC gateway ( , ) HMAC device , ); where i is a drone, For the submitted message, is the pre-shared key;
[0046] S304: Generate a session key through a key exchange protocol to ensure encryption of subsequent communications;
[0047] S305: Send the authentication result and encryption policy to the drone, and record the authentication log for auditing and anomaly detection.
[0048] Preferably, the device compatibility adaptation module supports interoperability of multiple communication protocols and is compatible with drone hardware from different manufacturers;
[0049] The specific operation logic steps are as follows:
[0050] S401: Parse the drone communication message, identify the protocol type, and dynamically call the protocol conversion plug-in;
[0051] S402: Detect the hardware capabilities of the drone, adapt the computing task allocation strategy of the edge node, and enable the lightweight encryption algorithm for low-performance devices. The formula used by the lightweight encryption algorithm is:
[0052] Encryption process: Cipher=ChaCha20(K,Nonce,Plaintext);
[0053] Where K is the session key, Nonce is a one-time random number to prevent replay attacks, Plaintext is the plaintext data to be encrypted, and Cipher is the ciphertext. ChaCha20 is a stream cipher that generates a pseudo-random key stream using the key K and Nonce, and then generates the ciphertext by byte-by-byte cross-scrambling the plaintext.
[0054] Authentication tag: Tag=Poly1305(K,Cipher|AdditionalData);
[0055] Where K is the same session key as the encryption key, Cipher is the ciphertext encrypted by ChaCha20, AdditionalData is the additional authentication data, Tag is the 128-bit authentication tag used to verify data integrity and authenticity, Poly1305 is a polynomial hash MAC algorithm based on modular arithmetic −5, convert the ciphertext and additional data into a polynomial, and finally generate an unforgeable label;
[0056] S403: Compare the drone firmware version with the compatibility matrix of the system requirements and trigger the automatic upgrade process;
[0057] S404: Generate an alarm for the incompatible device, push a suggestion, and enable a fallback mechanism.
[0058] Preferably, the task scheduling and policy management module is used to optimize the computing, storage and bandwidth resources of the edge nodes and dynamically adjust the execution order according to the urgency of the tasks. The formula used for adjusting the execution order is:
[0059] + , where i is the task, For the comprehensive urgency level, For resource requirements, 、 and are all weight coefficients.
[0060] The present invention also proposes a UAV swarm access authentication method applied to a power system, comprising the following steps:
[0061] S1: The drone manufacturer assigns a unique public-private key pair (PK, SK) to each drone. The drone submits manufacturer information, hardware identification, and public key to the identity management module of the cloud authentication center and the device compatibility adaptation module of the edge computing authentication gateway. The identity management module generates a unique decentralized identifier (DID) in the following format:
[0062] DID=did:powergrid:+Hash(manufacturer ID∥hardware serial number);
[0063] And register the DID identifier to the blockchain to ensure that it cannot be tampered with;
[0064] S2: The device compatibility adapter module parses the manufacturer's protocol and converts the drone's identity information into a standard format. =Convert( ), the drone submits the public key and DID to the authentication and authorization module through a certificate signing request (CSR), requesting the issuance of a PKI certificate. After the cloud authentication center verifies the validity of the DID, the identity management module issues a PKI certificate in X.509 format:
[0065] The format is: Cert drone = SignCA private key (DID | public key | validity period);
[0066] The certificate is stored in the blockchain to complete the registration;
[0067] S3: The drone group simultaneously initiates an authentication request: Req={DID, ,T, (T)}n;
[0068] S4: The batch authentication module uses batch signatures to verify the requests sent by the drone group. At the same time, the authentication and authorization module queries the validity of the DID and PKI certificates through the blockchain.
[0069] S5: Batch authentication passed, token generated:
[0070] =Encrypt(SessionKey, );
[0071] S6: Drone submits access request:
[0072] ={DID, ,Access_Request, }, to the edge authentication gateway;
[0073] S7: The task scheduling and strategy management module analyzes the task type (inspection, emergency, monitoring) and schedules the drone to execute the optimal strategy;
[0074] S8: The authentication and authorization module uses role-based access control to determine the permissions based on the role of the drone. Its permission allocation can be expressed as P(U) = , the smart contract determines the authority and returns the access result; the drone negotiates the session key with the power system through the encrypted communication module, K= modp, and establish a TLS secure channel to encrypt data output. At the same time, the communication security module detects abnormal communication behavior and triggers a security response;
[0075] S9: The log storage and audit module generates access logs: log = {DID, Access_Time, Access_Resource, Result}, which are used to record access history and support post-event tracing;
[0076] S10: The anomaly detection and security protection module detects abnormal behavior of drones based on machine learning and triggers a security response when an anomaly is detected. The formula used is: R= If R>ThresholdR, trigger security response
[0077] Compared with the existing technology, the beneficial effects of the present invention are:
[0078] The present invention converts drone identity information into a standard format through a device compatibility adapter module, enabling the authentication system to support multiple drone types and improve its scope of application. In addition, by cooperating with a batch authentication module and an authentication and authorization module, batch access of drone groups can be achieved, reducing the amount of calculation. In addition, during the authentication process, the anomaly detection and security protection modules are used to monitor the behavior of drones in real time, detect potential security threats, and take necessary security protection measures to improve security. BRIEF DESCRIPTION OF THE DRAWINGS
[0079] Figure 1 This is a block diagram of the UAV swarm access authentication system for power systems proposed by the present invention;
[0080] Figure 2 This is a flow chart of a drone swarm access authentication method applied to a power system proposed by the present invention. DETAILED DESCRIPTION
[0081] The present invention will be further explained below with reference to specific embodiments.
[0082] Example
[0083] Reference Figure 1-2,This embodiment proposes a drone group access authentication system for a power system, including a drone end, a cloud authentication center, and an edge computing authentication gateway, where the edge computing authentication gateway is connected to the drone end and the cloud authentication center;
[0084] The drone side includes a digital certificate module, an encrypted communication module, and a log storage and audit module;
[0085] The digital certificate module is used to generate, manage and use digital certificates for identity authentication and signature verification, ensuring that the drone's identity is trusted when it accesses the authentication system.
[0086] The logical steps of its operation are as follows:
[0087] S101: The drone submits a digital certificate application to the authentication and authorization module through the Certificate Request Protocol (CSR), and submits the public key and identity information. The identity management module then issues a PKI certificate.
[0088] S102: The drone stores the private key and public key in the log storage and audit module. The private key is used for signature authentication, and the public key is used for identity authentication.
[0089] S103: The drone uses the private key to sign the identity authentication request to prove the authenticity of the identity;
[0090] S104: The authentication system verifies the digital signature and PKI certificate sent by the drone using the public key of the certificate to ensure that the drone’s identity has not been tampered with;
[0091] The encryption communication module is used to ensure the communication and security between the UAV and the power system. It uses encryption algorithms to encrypt and decrypt the communication content to prevent the data from being intercepted or tampered during transmission.
[0092] The log storage and audit module is used to log the activities and communications of drones, and audit each operation in the authentication system for subsequent traceability and security review. The logs are stored in the blockchain to ensure that the log data cannot be tampered with.
[0093] The cloud authentication center includes identity management module, authentication and authorization module, communication security module, and anomaly detection and security protection module;
[0094] The identity management module is responsible for generating and managing the drone's DID identifier and issuing a PKI certificate for it. The DID identifier generated by the identity management module will be registered on the blockchain. In addition, when the drone initiates an authentication request, the identity management module will extract and verify the DID identifier and PKI certificate to check whether they are valid. After successful authentication, the identity management module will store the drone's identity data (DID, PKI certificate, permissions) in the cloud database.
[0095] During the identity revocation process, the identity management module will trigger the revocation operation and mark the drone's DID identifier and PKI certificate as invalid;
[0096] The identity management module supports the registration and authentication of drones from different manufacturers through a unified DID standard and PKI certificate format, ensuring the compatibility of devices across manufacturers.
[0097] The authentication and authorization module is used to authenticate the drone's DID identifier and PKI certificate to ensure that only legitimate drones can access the power system;
[0098] The formula used in authentication is as follows:
[0099] PKI certificate authentication: , (e, N) is the public key, M′ is the decrypted message, and M is the message to be signed. If M′=M, the signature is valid;
[0100] DID identifier authentication: H(M)=hash(M), where H(M) is the hash value of the message M, which can be used to verify the uniqueness of the identity;
[0101] The authentication and authorization module is also used to determine the resources that the drone can access and the tasks that it can perform based on the authenticated identity information. The authentication and authorization module performs permission checks based on the drone's identity information and role to ensure that the drone is qualified to access the requested resources. Permission checks are usually performed based on role-based access control (RBAC) or attribute-based access control (ABAC) policies. After verifying the identity and performing permission checks, the authentication and authorization module decides whether to grant the drone permission to access specific resources. After successful authorization, the authentication and authorization module creates a session token for the drone as an identifier for the current operation session. The authentication and authorization module records detailed information on each identity authentication and authorization decision in the log storage and audit module. After the drone completes its mission, the authentication and authorization module will actively terminate the current session.
[0102] Role-based access control (RBAC) determines the permissions of drones based on their roles (drones that perform patrol and inspection tasks). The permission allocation can be expressed as P(U) = , where U is the drone, R(U) is the set of roles the user has, and P(r) is the permissions that role r has;
[0103] Attribute-based access control (ABAC) determines whether a drone has the right to perform a specific task based on its attributes (task type, location, time). Authorization rules are usually based on a set of attributes A and policies S. Decision = f(A, S), where A includes identity, task, location, and time, and S is the access policy defined by the system.
[0104] The authentication and authorization module works in conjunction with the anomaly detection and security protection module to monitor the drone's behavior and session status in real time and identify possible anomalies. When abnormal behavior is detected, the authentication and authorization module will automatically initiate security protection measures to ensure that the drone's identity has not been forged. Its security protection measures include temporarily freezing the session, preventing further resource access, and initiating a re-authentication review.
[0105] When the drone's mission ends or its identity is revoked, the authentication and authorization module will proactively revoke all access rights of the drone. After revoking the rights, the authentication and authorization module will terminate the drone's session token and update the relevant session status.
[0106] The anomaly detection and security protection module is used to monitor the behavior of drones in real time, detect potential security threats, and take necessary security protection measures. Its operation logic steps are as follows:
[0107] S201: Collect drone activity data and communication data from the drone terminal, cloud authentication center, and other related systems;
[0108] S202: Analyze the data collected in S201 in real time using a machine learning algorithm and compare it with normal behavior patterns to identify possible abnormal behaviors, including but not limited to: ①, identity forgery; ②, authority abuse; ③, communication anomalies; ④, abnormal flight trajectory;
[0109] When identifying abnormal behavior, the formula used is: min ;
[0110] in is the i-th cluster, is the center of the cluster, It is a data point. If the data point is too far away from the center of a cluster, it will be considered an outlier.
[0111] S203: For the detected abnormal behavior, the anomaly detection and security protection module analyzes its potential threat and determines whether it is a malicious attack, system failure or misoperation;
[0112] S204: After detecting abnormal behavior, the anomaly detection and security protection module will automatically trigger security protection measures according to the set security policy. Its security policy includes but is not limited to: ① If the drone is found to have identity forgery or authority abuse, immediately terminate communication with the drone; ② If the drone's operation exceeds the authorized scope, the anomaly detection and security protection module will proactively revoke the drone's permissions; ③ If the drone's behavior poses a security threat, the anomaly detection and security protection module can isolate it and stop it from executing its mission to prevent further damage; ④ For abnormal events with high threat levels, automatically notify the administrator for manual intervention;
[0113] S205: The anomaly detection module records all abnormal events, security responses, and protective measures, providing a basis for subsequent audits and analysis;
[0114] The edge computing authentication gateway includes a batch authentication module, a device compatibility adaptation module, and a task scheduling and policy management module;
[0115] The batch authentication module is used to verify the legitimacy of the drone swarm and to establish a secure communication link with the drones. Its operation logic steps are as follows:
[0116] S301: Preload the whitelist, root certificate, and authentication policy of the drone swarm, and establish a secure communication channel with the edge computing node;
[0117] S302: Receive access request from the drone swarm and extract device identification (MAC address, IMEI) and authentication credentials (digital signature, dynamic token);
[0118] S303: Use the lightweight authentication protocol to verify the legitimacy of the identities of multiple drones. The formula used is:
[0119] HMAC , )=SHA256(( ⊕opad)∥SHA256(( ⊕ipad)∥ ));
[0120] The gateway compares the calculated result with the authentication tag attached to the drone. If they match, the identity is legitimate. The HMAC gateway ( , ) HMAC device , ); where i is a drone, For the submitted message, is the pre-shared key;
[0121] S304: Generate a session key through a key exchange protocol to ensure encryption of subsequent communications;
[0122] S305: Send the authentication result (success / failure) and encryption policy to the drone, and record the authentication log (timestamp, device ID, authentication result) for auditing and anomaly detection;
[0123] The device compatibility adapter module supports interoperability of multiple communication protocols (MQTT, CoAP, LoRaWAN) and is compatible with drone hardware from different manufacturers;
[0124] The specific operation logic steps are as follows:
[0125] S401: Parse the drone communication message, identify the protocol type, and dynamically call the protocol conversion plug-in;
[0126] S402: Detect the hardware capabilities of the drone (CPU, memory, battery), adapt the computing task allocation strategy of the edge node, and enable lightweight encryption algorithms for low-performance devices. The formula used is:
[0127] Encryption process: Cipher=ChaCha20(K,Nonce,Plaintext);
[0128] Authentication tag: Tag=Poly1305(K,Cipher|AdditionalData);
[0129] S403: Compare the drone firmware version with the compatibility matrix of the system requirements and trigger the automatic upgrade process;
[0130] S404: Generate an alert for the incompatible device, push a suggestion, and enable a fallback mechanism;
[0131] The task scheduling and policy management module is used to optimize the computing, storage, and bandwidth resources of edge nodes and dynamically adjust the execution order according to the urgency of the task. The formula used for adjusting the execution order is:
[0132] + , where i is the task, For the comprehensive urgency level, For resource requirements, 、 and are all weight coefficients.
[0133] This embodiment also proposes a drone swarm access authentication method applied to a power system, comprising the following steps:
[0134] S1: The drone manufacturer assigns a unique public-private key pair (PK, SK) to each drone. The drone submits manufacturer information, hardware identification, and public key to the identity management module of the cloud authentication center and the device compatibility adaptation module of the edge computing authentication gateway. The identity management module generates a unique decentralized identifier (DID) in the following format:
[0135] DID=did:powergrid:+Hash(manufacturer ID∥hardware serial number);
[0136] And register the DID identifier to the blockchain to ensure that it cannot be tampered with;
[0137] S2: The device compatibility adapter module parses the manufacturer's protocol and converts the drone's identity information into a standard format. =Convert( ), the drone submits the public key and DID to the authentication and authorization module through a certificate signing request (CSR), requesting the issuance of a PKI certificate. After the cloud authentication center verifies the validity of the DID, the identity management module issues a PKI certificate in X.509 format:
[0138] The format is: Cert drone = SignCA private key (DID | public key | validity period);
[0139] The certificate is stored in the blockchain to complete the registration;
[0140] S3: The drone group simultaneously initiates an authentication request: Req={DID, ,T, (T)}n;
[0141] S4: The batch authentication module uses batch signatures to verify the requests sent by the drone group. At the same time, the authentication and authorization module queries the validity of the DID and PKI certificates through the blockchain.
[0142] S5: Batch authentication passed, token generated:
[0143] =Encrypt(SessionKey, );
[0144] S6: Drone submits access request:
[0145] ={DID, ,Access_Request, }, to the edge authentication gateway;
[0146] S7: The task scheduling and strategy management module analyzes the task type (inspection, emergency, monitoring) and schedules the drone to execute the optimal strategy;
[0147] S8: The authentication and authorization module uses role-based access control (RBAC) to determine the permissions of drones based on their roles (drones that perform patrol and inspection tasks). The permission allocation can be expressed as P(U) = , the smart contract determines the permissions and returns the access result;
[0148] The UAV negotiates the session key with the power system through the encrypted communication module, K= modp, and establish a TLS secure channel to encrypt data output. At the same time, the communication security module detects abnormal communication behavior and triggers a security response;
[0149] S9: Log storage and audit module generates access logs:
[0150] log={DID,Access_Time,Access_Resource,Result}, used to record access history and support post-event tracing;
[0151] S10: The anomaly detection and security protection module detects abnormal behavior of drones based on machine learning and triggers a security response when an anomaly is detected. The formula used is: R= , if R>ThresholdR, trigger security response;
[0152] This embodiment converts drone identity information into a standard format through the device compatibility adaptation module, so that the authentication system can support multiple drone types, improving the scope of application. In addition, through the cooperation of the batch authentication module and the authentication and authorization module, batch access of drone groups can be achieved, reducing the amount of calculation. In addition, during the authentication process, the anomaly detection and security protection module monitors the behavior of drones in real time, detects potential security threats, and takes necessary security protection measures to improve security.
[0153] The above description is only a preferred specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any technician familiar with the technical field, within the technical scope disclosed by the present invention, who makes equivalent replacements or changes based on the technical solution and inventive concept of the present invention, should be covered by the scope of protection of the present invention.
Claims
1. A drone swarm access authentication system for power systems, characterized in that: It includes a drone end, a cloud authentication center and an edge computing authentication gateway, wherein the edge computing authentication gateway is connected to the drone end and the cloud authentication center; The drone terminal includes a digital certificate module, an encryption communication module, and a log storage and audit module; The cloud authentication center includes an identity management module, an authentication and authorization module, a communication security module, and an anomaly detection and security protection module; The edge computing authentication gateway includes a batch authentication module, a device compatibility adaptation module, and a task scheduling and policy management module.
2. The UAV swarm access authentication system for power system according to claim 1, characterized in that: The digital certificate module is used to generate, manage and use digital certificates for identity authentication and signature verification, ensuring that the identity of the drone is trusted when it accesses the authentication system; The logical steps of its operation are as follows: S101: The drone submits a digital certificate application to the authentication and authorization module through the certificate request protocol, and submits the public key and identity information. The identity management module issues a PKI certificate. S102: The drone stores the private key and public key in the log storage and audit module. The private key is used for signature authentication, and the public key is used for identity authentication. S103: The drone uses the private key to sign the identity authentication request to prove the authenticity of the identity; S104: The authentication system verifies the digital signature and PKI certificate sent by the drone using the public key of the certificate to ensure that the drone’s identity has not been tampered with; The encryption communication module is used to ensure the communication and security between the UAV and the power system, and uses encryption algorithms to encrypt and decrypt the communication content to prevent the data from being intercepted or tampered during transmission; The encryption communication module includes a key management unit, an encryption engine unit, a hash and authentication unit, a protocol adaptation layer, and a log and audit interface. The key management unit is used to manage the public and private key pairs, session keys, and pre-shared keys of the drone. The encryption engine unit is used to implement data encryption and digital signatures. The log storage and audit module is used to log the activities and communications of the drone, and audit each operation in the authentication system for subsequent traceability and security review. The logs are stored in the blockchain to ensure that the log data cannot be tampered with.
3. The UAV swarm access authentication system for power system according to claim 2, characterized in that: The identity management module is responsible for generating and managing the drone's DID identifier and issuing a PKI certificate for it. The DID identifier generated by the identity management module will be registered on the blockchain. When the drone initiates an authentication request, the identity management module will extract and verify the DID identifier and PKI certificate to check whether they are valid. After successful authentication, the identity management module will store the drone's identity data in the cloud database. During the identity revocation process, the identity management module will trigger the revocation operation and mark the drone's DID identifier and PKI certificate as invalid; The identity management module supports the registration and authentication of drones from different manufacturers through a unified DID standard and PKI certificate format.
4. The UAV swarm access authentication system for power system according to claim 3, characterized in that: The authentication and authorization module is used to authenticate the drone’s DID identifier and PKI certificate to ensure that only legitimate drones can access the power system; The formula used in authentication is as follows: PKI certificate authentication: , (e, N) is the public key, M′ is the decrypted message, and M is the message to be signed. If M′=M, the signature is valid; DID identifier authentication: H(M)=hash(M), where H(M) is the hash value of the message M, which can be used to verify the uniqueness of the identity; The authentication and authorization module is also used to determine the resources that the drone can access and the tasks that it can perform based on the authenticated identity information. The authentication and authorization module performs permission checks based on the drone's identity information and role to ensure that the drone is qualified to access the requested resources, and the permission check is performed according to the role-based access control or attribute-based access control policy. After verifying the identity and performing the permission check, the authentication and authorization module decides whether to grant the drone permission to access specific resources. After successful authorization, the authentication and authorization module creates a session token for the drone as an identifier of the current operation session, and the authentication and authorization module records the detailed information of each identity authentication and authorization decision in the log storage and audit module. After the drone completes the task, the authentication and authorization module will actively terminate the current session; Role-based access control determines the permissions of the drone based on its role, and its permission allocation can be expressed as P(U) = , where U is the drone, R(U) is the set of roles the user has, and P(r) is the permissions that role r has; Attribute-based access control is based on the attributes of the drone to determine whether it has the right to perform a specific task. The authorization rules are usually based on a set of attributes A and policies S. Decision = f(A, S), where A includes identity, task, location, and time, and S is the access policy defined by the system; The authentication and authorization module works in conjunction with the anomaly detection and security protection module to monitor the drone's behavior and session status in real time and identify possible anomalies. When abnormal behavior is detected, the authentication and authorization module will automatically initiate security protection measures to ensure that the drone's identity has not been forged. Its security protection measures include temporarily freezing the session, preventing further resource access, and initiating a re-authentication review. When the drone mission ends or its identity is revoked, the authentication and authorization module will proactively revoke all access rights of the drone. After revoking the rights, the authentication and authorization module will terminate the drone's session token and update the relevant session status.
5. The UAV swarm access authentication system for a power system according to any one of claims 1 to 4, characterized in that: The anomaly detection and security protection module is used to monitor the behavior of drones in real time, detect potential security threats, and take necessary security protection measures. Its operation logic steps are as follows: S201: Collect drone activity data and communication data from the drone terminal, cloud authentication center, and other related systems; S202: Analyze the data collected in S201 in real time using a machine learning algorithm and compare it with normal behavior patterns to identify possible abnormal behaviors, including but not limited to: ①, identity forgery; ②, authority abuse; ③, communication anomalies; ④ Abnormal flight trajectory; When identifying abnormal behavior, the formula used is: min ; in is the i-th cluster, is the center of the cluster, It is a data point. If the data point is too far away from the center of a cluster, it will be considered an outlier. S203: For the detected abnormal behavior, the anomaly detection and security protection module analyzes its potential threat and determines whether it is a malicious attack, system failure or misoperation; S204: After detecting abnormal behavior, the anomaly detection and security protection module will automatically trigger security protection measures according to the set security policy. Its security policy includes but is not limited to: ① If the drone is found to have identity forgery or authority abuse, immediately terminate communication with the drone; ② If the drone's operation exceeds the authorized scope, the anomaly detection and security protection module will proactively revoke the drone's permissions; ③ If a drone's behavior poses a security threat, the anomaly detection and security protection module can isolate it, halt its mission, and prevent further damage. ④ For high-threat-level anomalies, the administrator is automatically notified for manual intervention. S205: The anomaly detection module will record all abnormal events, security responses and protective measures to provide a basis for subsequent audits and analysis.
6. The UAV swarm access authentication system for power system according to claim 5, characterized in that: The batch authentication module is used to verify the legitimacy of the identities of the drone group and to establish a secure communication link with the drones. Its operating logic steps are as follows: S301: Preload the whitelist, root certificate, and authentication policy of the drone swarm, and establish a secure communication channel with the edge computing node; S302: Receive access request from the drone group and extract device identification and authentication credentials; S303: Use the lightweight authentication protocol to verify the legitimacy of the identities of multiple drones. The formula used is: HMAC( , )=SHA256(( ⊕opad)∥SHA256(( ⊕ipad)∥ )); The gateway compares the calculated result with the authentication tag attached to the drone. If they match, the identity is legitimate. The HMAC gateway ( , ) HMAC device , ); where i is a drone, For the submitted message, is the pre-shared key; S304: Generate a session key through a key exchange protocol to ensure encryption of subsequent communications; S305: Send the authentication result and encryption policy to the drone, and record the authentication log for auditing and anomaly detection.
7. The UAV swarm access authentication system for power system according to claim 6, characterized in that: The device compatibility adaptation module supports the interoperability of multiple communication protocols and is compatible with drone hardware from different manufacturers; The specific operation logic steps are as follows: S401: Parse the drone communication message, identify the protocol type, and dynamically call the protocol conversion plug-in; S402: Detect the hardware capabilities of the drone, adapt the computing task allocation strategy of the edge node, and enable the lightweight encryption algorithm for low-performance devices. The formula used by the lightweight encryption algorithm is: Encryption process: Cipher=ChaCha20(K,Nonce,Plaintext); Where K is the session key, Nonce is a one-time random number to prevent replay attacks, Plaintext is the plaintext data to be encrypted, and Cipher is the ciphertext. ChaCha20 is a stream cipher that generates a pseudo-random key stream using the key K and Nonce, and then generates the ciphertext by byte-by-byte cross-scrambling the plaintext. Authentication tag: Tag=Poly1305(K,Cipher|AdditionalData); Where K is the same session key as the encryption key, Cipher is the ciphertext encrypted by ChaCha20, AdditionalData is the additional authentication data, Tag is the 128-bit authentication tag used to verify data integrity and authenticity, Poly1305 is a polynomial hash MAC algorithm based on modular arithmetic −5, convert the ciphertext and additional data into a polynomial, and finally generate an unforgeable label; S403: Compare the drone firmware version with the compatibility matrix of the system requirements and trigger the automatic upgrade process; S404: Generate an alarm for the incompatible device, push a suggestion, and enable a fallback mechanism.
8. The UAV swarm access authentication system for power system according to claim 7, characterized in that: The task scheduling and policy management module is used to optimize the computing, storage, and bandwidth resources of edge nodes and dynamically adjust the execution order according to the urgency of the tasks. The formula used for adjusting the execution order is: + , where i is the task, For the comprehensive urgency level, For resource requirements, 、 and are all weight coefficients.
9. A drone group access authentication method applied to a power system, characterized in that: The drone swarm access authentication system for a power system according to any one of claims 1 to 8 includes the following steps: S1: The drone manufacturer assigns a unique public-private key pair (PK, SK) to each drone. The drone submits manufacturer information, hardware identification, and public key to the identity management module of the cloud authentication center and the device compatibility adaptation module of the edge computing authentication gateway. The identity management module generates a unique decentralized identifier (DID) in the following format: DID=did:powergrid:+Hash(manufacturer ID∥hardware serial number); And register the DID identifier to the blockchain to ensure that it cannot be tampered with; S2: The device compatibility adapter module parses the manufacturer's protocol and converts the drone's identity information into a standard format. =Convert( ), the drone submits the public key and DID to the authentication and authorization module through a certificate signing request (CSR), requesting the issuance of a PKI certificate. After the cloud authentication center verifies the validity of the DID, the identity management module issues a PKI certificate in X.509 format: The format is: Cert drone = SignCA private key (DID | public key | validity period); The certificate is stored in the blockchain to complete the registration; S3: The drone group simultaneously initiates an authentication request: Req={DID, ,T, (T)}n; S4: The batch authentication module uses batch signatures to verify the requests sent by the drone group. At the same time, the authentication and authorization module queries the validity of the DID and PKI certificates through the blockchain. S5: Batch authentication passed, token generated: =Encrypt(SessionKey, ); S6: Drone submits access request: ={DID, ,Access_Request, }, to the edge authentication gateway; S7: The task scheduling and strategy management module analyzes the task type (inspection, emergency, monitoring) and schedules the drone to execute the optimal strategy; S8: The authentication and authorization module uses role-based access control to determine the permissions based on the role of the drone. Its permission allocation can be expressed as P(U) = , the smart contract determines the authority and returns the access result; the drone negotiates the session key with the power system through the encrypted communication module, K= modp, and establish a TLS secure channel to encrypt data output. At the same time, the communication security module detects abnormal communication behavior and triggers a security response; S9: The log storage and audit module generates access logs: log = {DID, Access_Time, Access_Resource, Result}, which are used to record access history and support post-event tracing; S10: The anomaly detection and security protection module detects abnormal behavior of drones based on machine learning and triggers a security response when an anomaly is detected. The formula used is: R= , if R>ThresholdR, trigger the security response.