Unmanned aerial vehicle electronic identity card identification and management method based on 4G / 5G cloud control
Through challenge-responsive dynamic identity authentication and multi-source location comparison, the problems of identity forgery and location deception in the drone cloud control management system are solved, a high-trust channel is established, precise and intelligent management of drones is achieved, and airspace safety and management efficiency are improved.
Patent Information
- Application Number
- CN202511242809.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-02
- Publication Date
- 2025-10-10
AI Technical Summary
In the existing drone cloud control and management system, the identity authentication method based on static identification codes is not secure enough and can be easily counterfeited. It also relies on the drone's GPS location information, which is susceptible to interference or deception, leading to airspace safety risks.
It adopts a combination of challenge-responsive dynamic identity authentication and cross-comparison of multi-source location information, ensures the authenticity of identity authentication through asymmetric encryption technology, verifies the location of the drone through cellular network base station positioning information, builds a high-trust management channel, and evaluates the comprehensive trust status of the drone in real time.
It improves the security and reliability of drone traffic control, prevents identity forgery and location spoofing, enables precise and intelligent management of drones, and ensures airspace safety.
Smart Images

Figure CN120768564A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of drone traffic control systems, and in particular to a method for identifying and managing drone electronic ID cards based on 4G / 5G cloud control. Background Art
[0002] In recent years, with the rapid development of civilian drone technology, drones have become increasingly popular in aerial photography, logistics, agriculture, and inspection, leading to an increase in low-altitude flight activity. To ensure public safety and airspace order, effectively regulating these massive numbers of drones has become a critical issue in traffic management. Leveraging the widespread coverage of 4G / 5G cellular networks to connect drones to cloud-based monitoring platforms for remote monitoring and management—known as cloud-controlled drones—has become the mainstream technology for future drone traffic management.
[0003] Currently, drone identification in cloud-based drone management systems typically relies on a static identifier reported by the drone when it connects to the network, such as the drone's factory serial number or the International Mobile Equipment Identity (IMEI) code of its built-in communication module. The monitoring platform uses this identifier to register and distinguish drones. During flight, the drone obtains its position coordinates via its onboard GPS module and periodically reports these coordinates to the cloud-based monitoring platform via the cellular network. The platform then monitors the drone's flight trajectory.
[0004] However, identity authentication methods based on static identification codes lack security. Once intercepted, such identification codes can be used by illegal drones to impersonate legitimate drones and access the regulatory network, making it difficult for the regulatory platform to confirm the true physical identity of the communicating party. Secondly, the regulatory platform relies entirely on the GPS location information unilaterally reported by the drone. GPS signals are susceptible to interference or spoofing. Malicious attackers can use technical means to inject false location data into the drone, resulting in distorted location information received by the cloud platform. This makes it impossible to truly reflect the drone's flight trajectory, posing a significant risk to airspace security. Summary of the Invention
[0005] To solve the above problems, the present invention provides a drone electronic ID card identification and management method based on 4G / 5G cloud control. It adopts a combination of challenge-responsive dynamic identity authentication and multi-source location information cross-comparison to establish a high-trust management and control channel between the drone and the cloud platform, and evaluate the comprehensive trust status of the drone in real time, thereby improving the safety and reliability of drone traffic control.
[0006] The above objectives can be achieved through the following solutions: A method for identifying and managing an electronic ID card for a drone based on 4G / 5G cloud control includes obtaining an initial connection request sent by a drone, the initial connection request including an identity code representing the drone's physical hardware, and establishing an initial communication link based on the identity code; generating a challenge code including one-time data, encapsulating the challenge code into an identity query instruction, and sending the identity query instruction to the drone via the initial communication link; the drone receiving the identity query instruction and digitally signing the challenge code using a private key within the drone to generate a response signature; receiving the response signature returned by the drone, and calling a public key pre-bound to the identity code to decrypt and verify the response signature, confirming the authenticity of the identity of the other end of the initial communication link, and generating an identity confirmation credential; based on the identity confirmation credential, upgrading the attributes of the initial communication link to a highly trusted management channel, performing location credibility assessment and comprehensive decision-making based on the highly trusted management channel, and generating remote control instructions to manage the drone.
[0007] Optionally, establishing the initial communication link includes: after the drone is turned on, the cellular communication module of the drone actively initiates a network connection to the cloud-based supervision platform and sends the initial connection request; the cloud-based supervision platform verifies the identity identification code, generates a session identifier and returns it to the drone; and establishes an encrypted, point-to-point initial communication link based on the session identifier.
[0008] Optionally, the calling of the public key pre-bound to the identity code includes: during the drone registration stage, obtaining the user's real-name information and binding it with the drone's identity code and the paired public key; encrypting and storing the binding result to form an authorized digital file; and when the response signature is received, retrieving and extracting the corresponding public key from the authorized digital file based on the identity code.
[0009] Optionally, the location credibility assessment based on the high-trust management channel includes: receiving the terminal-reported location information containing GPS module coordinates reported by the drone through the high-trust management channel; retrieving the network base station positioning information associated with the cellular network session carrying the high-trust management channel through the data interface with the cellular network operator; performing a spatial consistency comparison between the terminal-reported location information and the network base station positioning information to generate a location credibility assessment result.
[0010] Optionally, generating a location credibility assessment result includes: using the network base station positioning information as a benchmark and combining the positioning error characteristics of the cellular network to delineate a dynamic, credible geographic fence; determining whether the coordinate point indicated by the location information reported by the terminal falls within the credible geographic fence, and obtaining a location match based on the determination result; and generating a location credibility assessment result indicating whether the location is credible or abnormal based on the level of the location match.
[0011] Optionally, before generating a remote control instruction to manage the drone, it also includes: generating a dynamically changing challenge code at a preset time interval and generating a new identity challenge instruction through the high-trust management channel; receiving a response signature generated based on the new identity challenge instruction and verifying a trusted status monitoring stream containing multiple identity confirmation credentials; generating a real-time identity authentication status based on the validity and timeliness of the multiple identity confirmation credentials in the trusted status monitoring stream.
[0012] Optionally, generating remote control instructions to manage the drone includes: combining the real-time identity authentication status and the location credibility assessment result to generate a comprehensive credibility status for characterizing the reliability of the current flight status of the drone; based on the comprehensive credibility status, determining the flight mode of the drone, the flight mode including a credibility mode, a location abnormality mode and an identity abnormality mode; and generating remote control instructions based on the flight mode to manage the drone.
[0013] Optionally, the method further includes: obtaining an electronic no-fly zone range set by an airspace management agency, which defines geographic coordinates and altitude restrictions; determining whether an area intrusion has occurred based on the geographic location indicated by the location information reported by the terminal and the electronic no-fly zone range; when an area intrusion occurs and the comprehensive trust status is trustworthy, generating a compliance handling instruction including forced return or on-site landing.
[0014] Optionally, the method further includes: using a preset digital certificate private key to sign the remote control instruction to generate an encrypted control data packet; and sending the encrypted control data packet to the drone through the high-trust management channel.
[0015] Based on the same inventive concept, the present invention also provides a drone electronic ID card identification and management system based on 4G / 5G cloud control. The system includes: a communication and information receiving module, configured to obtain an initial connection request sent by a drone, the initial connection request including an identity identification code representing the drone's physical hardware, and establish an initial communication link based on the identity identification code; an identity challenge module, configured to generate a challenge code including one-time data, encapsulate the challenge code into an identity challenge instruction, and send the identity challenge instruction to the drone via the initial communication link; wherein the drone receives the identity challenge instruction and digitally signs the challenge code using a private key within the drone to generate a response signature; an identity authentication module, configured to receive the response signature returned by the drone and decrypt and verify the response signature using a public key pre-bound to the identity identification code, confirm the authenticity of the identity of the other end of the initial communication link, and generate an identity confirmation credential; and a control and management module, configured to upgrade the attributes of the initial communication link to a highly trusted management channel based on the identity confirmation credential, perform location credibility assessment and comprehensive decision-making based on the highly trusted management channel, and generate remote control instructions to manage the drone.
[0016] Compared with the prior art, the present invention has the following advantages: 1. This invention establishes an end-to-end, highly trusted communication link between drones and a cloud-based monitoring platform through a challenge-response dynamic identity authentication mechanism. This mechanism utilizes asymmetric encryption technology to ensure that each connected drone must undergo signature verification using its unique hardware private key, fundamentally eliminating the risk of identity codes being counterfeited or replayed. Furthermore, signature protection for downlink control commands ensures the uniqueness and tamper-proof nature of the command source, significantly enhancing the security and anti-attack capabilities of the entire drone traffic control system. 2. This invention achieves real-time assessment of the credibility of a drone's location by cross-comparing the drone's reported location information with the positioning information of cellular network base stations. This dual-source verification mechanism effectively addresses the drawback of existing technologies that rely solely on the drone's own GPS and are unable to prevent location spoofing attacks. By establishing a dynamic and trusted geo-fence, the system can accurately identify abnormal location behavior, ensuring that all control decisions are based on authentic and reliable drone location data, providing a key position credibility guarantee for safe and orderly operation in low-altitude airspace. 3. The application establishes a dynamic and differentiated management and control strategy based on comprehensive trusted state; the system continuously monitors and comprehensively evaluates the dual trustworthiness of identity and location, divides the unmanned aerial vehicle into different states such as trusted mode, location abnormal mode and identity abnormal mode, and based on this, the system can automatically execute a series of hierarchical control instructions from normal flight, early warning observation to forced return or landing, realize the accurate, intelligent and automatic management of unmanned aerial vehicles of different risk levels, and improve the efficiency and fine level of traffic control.
[0017] Other features and advantages of the present application will be set forth in the following description, and in part will become apparent to those skilled in the art from the description, or can be learned by practice of the application. The objects and other advantages of the present application can be realized and obtained by the structure indicated in the specification, claims and drawings. BRIEF DESCRIPTION OF DRAWINGS
[0018] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the drawings needed to be used in the embodiments or the prior art description will be briefly introduced below. Obviously, the drawings in the following description are some embodiments of the present application, and those skilled in the art can also obtain other drawings according to these drawings without creative labor.
[0019] Figure 1 is a flowchart of the unmanned aerial vehicle electronic identity card recognition and management method based on 4G / 5G cloud control according to an embodiment of the present application.
[0020] Figure 2 is a structural schematic diagram of the unmanned aerial vehicle electronic identity card recognition and management system based on 4G / 5G cloud control according to an embodiment of the present application. DETAILED DESCRIPTION
[0021] In order to make the objects, technical solutions and advantages of the embodiments of the present application more clear, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are some embodiments of the present application, not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.
[0022] With reference to Figure 1 , one embodiment of the present application proposes an unmanned aerial vehicle electronic identity card recognition and management method based on 4G / 5G cloud control, which adopts a combination of challenge-response dynamic identity authentication and multi-source location information cross comparison, can establish a high-trust management and control channel between the unmanned aerial vehicle and the cloud platform, and evaluate the comprehensive trusted state of the unmanned aerial vehicle in real time, thereby improving the safety and reliability of unmanned aerial vehicle traffic control.
[0023] The method of this embodiment specifically includes: Obtaining an initial connection request sent by the drone, the initial connection request including an identification code representing the physical hardware of the drone, and establishing an initial communication link based on the identification code; generating a challenge code including one-time data, encapsulating the challenge code into an identity challenge instruction, and sending the identity challenge instruction to the drone via the initial communication link; The drone receives the identity challenge instruction and uses the private key inside the drone to digitally sign the challenge code to generate a response signature; Specifically, first, the identity challenge module of the cloud-based supervision platform uses the built-in cryptographically secure pseudo-random number generator to generate an unpredictable string with high entropy as a challenge code. The challenge code is one-time data, which ensures the uniqueness of each identity challenge, thereby effectively resisting replay attacks. Subsequently, the platform encapsulates this challenge code into a standardized identity challenge instruction data packet, which is sent to the drone through the previously established initial communication link. After the drone receives the identity challenge instruction, its onboard security firmware will parse the instruction and extract the challenge code. Next, the drone calls the device's unique private key stored in its internal hardware security module or trusted execution environment, performs a digital signature operation on the received challenge code, and generates a response signature. Digital signature is an application of asymmetric encryption technology that can prove that the signer holds a private key paired with the public key and that the signed content has not been tampered with. The process can be expressed as follows: , in, Represents the final generated response signature, which is the data returned by the drone to the cloud monitoring platform. Represents a certain digital signature algorithm, such as the Elliptic Curve Digital Signature Algorithm ECDSA. It is a private key stored inside the drone hardware. This key is securely embedded during the drone manufacturing or registration stage and cannot be read externally. Represents a cryptographic hash function, such as SHA-256, which is used to generate a fixed-length digest of the input data. Hashing the challenge code before signing is a standard security practice. This is a one-time challenge code received from the cloud-based monitoring platform. After the drone completes the calculation of the response signature, it sends this signature data back to the cloud-based monitoring platform for subsequent verification steps.
[0024] Receive the response signature returned by the drone, and call the public key pre-bound to the identity identification code to decrypt and verify the response signature, confirm the authenticity of the identity of the peer end of the initial communication link, and generate an identity confirmation certificate; Based on the identity confirmation credentials, the attributes of the initial communication link are upgraded to a high-trust management channel, and location credibility assessment and comprehensive decision-making are performed based on the high-trust management channel to generate remote control instructions to manage the drone.
[0025] Specifically, the present invention solves the security risk of easy identity forgery caused by reliance on static identification codes in traditional drone supervision. By introducing a dynamic challenge-response mechanism and digital signature verification, it ensures that each identity confirmation is strongly bound to the private key in the drone's physical hardware, so that any unauthorized device cannot pass the authentication even if it steals the identity identification code, thereby greatly improving the accuracy of drone identity recognition and anti-attack capabilities. Secondly, the present invention conducts strict identity verification before management and control, and upgrades the communication link to a high-trust management channel based on this, thus building a safe and reliable foundation for all subsequent complex management behaviors, such as location assessment and command issuance. This model of establishing a trust foundation before operating ensures the authenticity and integrity of the interactive information between the cloud platform and the drone from the source.
[0026] Optionally, establishing an initial communication link includes: After the drone is powered on, the cellular communication module of the drone actively initiates a network connection to the cloud monitoring platform and sends the initial connection request; The cloud-based monitoring platform verifies the identity code, generates a session identifier, and returns it to the drone; An encrypted, point-to-point initial communication link is established based on the session identifier.
[0027] Specifically, establishing an initial communication link is the starting point of the entire drone electronic ID recognition and management process. Its core purpose is to establish a secure channel for subsequent identity challenge and verification. This process is automatically triggered by the drone upon powering on. First, the drone's built-in cellular communication module, the hardware foundation for connecting to 4G or 5G mobile networks, initiates a network connection to the cloud-based monitoring platform's network address preset in its firmware. During this step, the drone sends an initial connection request. This request must include a key piece of data: an identification code. This identification code is an identifier uniquely tied to the drone's physical hardware, such as the cellular module's International Mobile Equipment Identity (IMEI) or a unique serial number assigned by the manufacturer. This code serves as a preliminary declaration of its physical identity on the network. Upon receiving this initial connection request, the cloud-based monitoring platform extracts the identification code and queries it against its backend authorized digital archive database to verify its legitimacy and registration status. After verification, the cloud-based monitoring platform will generate a session identifier specifically for this communication. This is a temporary, unique string used to mark and identify this specific connection session in subsequent communications. The platform will then return this session identifier to the drone. When the drone successfully receives the session log returned by the cloud-based monitoring platform, the communicating parties will use this session identifier as a basis, follow the standard transport layer security protocol TLS or similar security mechanisms, and conduct an encrypted handshake, thereby successfully establishing an encrypted, point-to-point initial communication link. This link is logically a direct channel between the drone and the cloud-based monitoring platform, ensuring the secure transmission of subsequent identity query instructions and response signatures, laying the foundation for more stringent identity authentication in the next step.
[0028] Optionally, calling a public key pre-bound to the identity code includes: During the drone registration phase, the user's real-name information is obtained and bound to the drone's identification code and paired public key; Encrypt and store the binding results to form an authorized digital file; When the response signature is received, the corresponding public key is retrieved and extracted from the authorized digital archive according to the identity identification code.
[0029] Specifically, when the cloud supervision platform receives the response signature returned by the UAV, the identity verification module immediately starts the verification procedure to confirm the authenticity of the communication peer. The core of this procedure is to verify whether the response signature is generated by the unique private key bound to the UAV identity code using the principle of asymmetric cryptography. First, the UAV identity code obtained during the initial connection is used to search in the authorized digital archive in the background. The authorized digital archive is established during the UAV registration phase, which securely binds the physical identity code of the UAV, the public key matched therewith, and the real name information of the owner, and stores them in an encrypted manner. Through this search, the system can accurately extract the pre-stored public key uniquely corresponding to the current UAV identity code. After obtaining the public key, the identity verification module performs the digital signature verification operation. This verification process can be expressed in the following logic: , wherein, represents the final Boolean result of the verification, true or false. is a digital signature verification algorithm, which matches the digital signature algorithm used by the UAV side, such as the verification part of the elliptic curve digital signature algorithm. is the public key bound to the UAV identity code called by the cloud supervision platform from the authorized digital archive. is the same cryptographic hash function used when signing with the UAV, is the one-time data challenge code originally sent by the cloud supervision platform to the UAV, and the platform will take out the original challenge code from the session record and calculate its hash value for comparison. is the response signature received from the UAV. If the verification result is true, it is irrefutably proved that the response signature is signed by the UAV holding the corresponding private key, thereby verifying the authenticity of the identity of the initial communication link peer. After successful verification, the system generates a digital identity confirmation certificate, which serves as an internal marker that the UAV identity has passed strict verification, triggering the subsequent procedure to upgrade the properties of the initial communication link to a high-trust management channel.
[0030] Optionally, the location trustworthiness assessment based on the high-trust management channel comprises: receiving the terminal reported location information containing the GPS module coordinates reported by the UAV through the high-trust management channel; through the data interface with the cellular network operator, calling the network base station positioning information associated with the cellular network session carrying the high-trust management channel; performing spatial consistency comparison on the terminal reported location information and the network base station positioning information to generate a location trustworthiness assessment result.
[0031] Optionally, generating a location credibility assessment result includes: Delineating a dynamic, credible geographic fence based on the network base station positioning information and in combination with the positioning error characteristics of the cellular network; Determining whether the coordinate point indicated by the location information reported by the terminal falls within the trusted geographic fence, and obtaining a location matching degree according to the determination result; A location credibility evaluation result is generated based on the degree of location matching, indicating whether the location is credible or abnormal.
[0032] Specifically, in order to effectively verify the authenticity of the reported location of the drone, this method introduces an evaluation mechanism based on the cross-comparison of dual-source location information. Based on the established high-trust management channel, this evaluation process first obtains the drone's location data from two independent sources. The first is the terminal-reported location information received through the high-trust management channel. This information comes from the global positioning system GPS module on the drone, providing high-precision coordinate points, which are recorded as The cloud monitoring platform then retrieves a key reference information, namely the network base station location information, through the secure data interface established with the cellular network operator and records it as This information is the approximate location of the drone calculated by the operator based on the cellular network session that carries the high-trust management channel, using its network infrastructure such as the location and signal characteristics of the service base station. The acquisition method is independent of the drone's own positioning system. Next, a dynamic trusted geographic fence is constructed. This fence is not a static preset, but is based on the real-time network base station positioning information. is the geographic center. The size of the fence, i.e. its radius or boundary range, is determined based on the positioning error characteristics of the cellular network. This error characteristic is a parameter related to network technology, base station density and signal environment, representing The maximum possible deviation range is denoted as This parameter can be provided by the operator or modeled based on historical statistical data. Therefore, a trusted geofence is a As the center, The system then performs spatial consistency judgment, i.e., determines the location information reported by the terminal. Whether it falls within this dynamically defined trusted geographic fence. This judgment can be made by calculating the geographic distance between the two coordinate points. And the positioning error radius The comparison is completed. The position matching degree can be generated based on the judgment result. For example, when the following conditions are met, the position matching degree is high: , in, Indicates the spherical or planar distance between the GPS coordinates of the drone and the positioning coordinates of the network base station. The coordinates reported by the drone, The coordinates provided by the network side, is the positioning error radius under the current network environment. When the above conditions are not met, the location match is low. Finally, the system outputs the final location credibility assessment result based on the level of location match. A high match corresponds to a "reliable location," indicating that the GPS coordinates reported by the drone are corroborated by the cellular network location and their authenticity has been confirmed. Conversely, a low match generates a "location anomaly" assessment result, indicating that the drone may be at risk of GPS location spoofing or positioning system failure, triggering further control decisions.
[0033] Optionally, before generating a remote control instruction to manage the drone, the method further includes: Generate a dynamically changing challenge code and a new identity challenge instruction at preset time intervals through the highly trusted management channel; Receive and verify the response signature generated based on the new identity challenge instruction, including the trusted status monitoring flow of multiple identity confirmation credentials; Based on the validity and timeliness of multiple identity confirmation credentials in the trusted state monitoring flow, a real-time identity authentication status is generated.
[0034] Specifically, before generating any remote control commands, the cloud-based monitoring platform continuously executes the identity challenge process at preset intervals, such as a few seconds, through an established high-trust management channel. At the beginning of each interval, the system automatically generates a new, dynamically changing challenge code that is different from all previous challenge codes. This challenge code is encapsulated into a new identity challenge command and sent to the drone. Upon receiving this command, the drone must immediately digitally sign the new challenge code using its unique internal private key, generate a corresponding response signature, and return it to the cloud-based monitoring platform. Upon receiving the response signature, the platform immediately verifies it. Each successful verification generates a timestamped identity confirmation credential. These identity confirmation credentials, generated continuously over time, constitute a trusted status monitoring stream. This is a critical data structure that records the historical trajectory of the drone's identity verification over time. Finally, the system generates real-time authentication status based on this trusted status monitoring stream. This generation process comprehensively considers two core metrics: validity and timeliness. To be considered valid and timely, an identity confirmation credential must meet the following conditions: , in, Represents the result status of a single challenge verification. A Boolean value of true indicates success. Represents validity, that is, the received response signature must be verified by public key decryption to confirm that it is signed by a legitimate private key. Represents timeliness, which refers to the time from when the identity query instruction is sent By the time a valid response signature is received The time difference between the two must be less than a preset timeout threshold ,Right now The real-time authentication status is a series of The comprehensive evaluation result of the values is based on the real-time identity verification status. If the verification results of multiple consecutive queries are true, the real-time identity verification status is assessed as trustworthy. Conversely, if the verification fails or the response times out, the status will be assessed as abnormal.
[0035] Optionally, generating a remote control instruction to manage the drone includes: Combining the real-time identity authentication status with the location credibility assessment result to generate a comprehensive credibility status for characterizing the reliability of the current flight status of the UAV; Determining the flight mode of the drone based on the comprehensive trustworthy status, the flight mode including a trustworthy mode, a location abnormality mode, and an identity abnormality mode; Generate remote control instructions based on the flight mode to manage the drone.
[0036] Specifically, the system first integrates two key input data streams: the real-time identity verification status, which is continuously updated at preset intervals, and the latest location credibility assessment result generated based on dual-source location comparison. Based on these two independent assessment results, a comprehensive credibility status is generated. This generation process follows a clear logical judgment matrix to ensure decision-making certainty and consistency. The logic can be described as follows: The comprehensive credibility status is determined by first examining the real-time identity verification status. If the status is determined to be an identity anomaly, meaning multiple consecutive identity challenges have failed or the response has timed out, this is considered the highest priority anomaly, and the comprehensive credibility status is directly assessed as untrustworthy. The location credibility assessment result is no longer considered, as the security of the communication link itself is no longer guaranteed. If the real-time identity verification status is trustworthy, the location credibility assessment result is further examined. If the location credibility assessment result is trustworthy, the comprehensive credibility status is assessed as trustworthy. Conversely, if the location credibility assessment result is an anomaly, the comprehensive credibility status is assessed as risky. Based on this comprehensive trust status, the system further determines the drone's current state as a preset flight mode. The specific mapping rules are as follows: If the comprehensive trust status is trustworthy, the drone is placed in trustworthy mode. If the comprehensive trust status indicates risk, meaning the identity is trustworthy but the location is abnormal, the drone is placed in abnormal location mode. If the comprehensive trust status is untrustworthy, meaning the identity is abnormal, the drone is placed in abnormal identity mode. Finally, based on the determined flight mode, the system automatically triggers and generates corresponding remote control instructions. For example, a drone in trustworthy mode will receive instructions to perform normal tasks; a drone in abnormal location mode may receive warnings, hover observation, or instructions to limit its flight range; and a drone in abnormal identity mode will receive the highest priority control instructions, such as forced return or immediate on-site landing, aimed at eliminating potential threats.
[0037] Optionally, the method further includes: Obtain the scope of the electronic no-fly zone set by the airspace management agency, which defines the geographical coordinates and altitude restrictions; Determining whether an area intrusion occurs based on the geographical location indicated by the location information reported by the terminal and the range of the electronic no-fly zone; When an area intrusion occurs and the comprehensive trust status is trustworthy, a compliance handling instruction including forced return or on-site landing is generated.
[0038] Specifically, this operation integrates automated airspace compliance enforcement into drone management. Building on the existing comprehensive trust state assessment, it adds geospatial rule assessment and response capabilities. First, the cloud-based monitoring platform must pre-establish a data interface with official airspace management agencies to obtain and synchronize authoritative data on the electronic no-fly zone (ELFZ) boundaries in real time. These ELFZ boundaries are not simple two-dimensional areas, but rather three-dimensional volumes with precisely defined geographic coordinate boundaries and vertical height limits, designed to protect sensitive airspace such as critical infrastructure and airports. During drone flight, the system continuously identifies intrusions. This identification relies on a continuous geometric comparison of the drone's terminal-reported location information (including real-time 3D coordinates, including latitude, longitude, and altitude) transmitted via the highly trusted management channel with the ELFZ boundaries stored in the system. This comparison involves a point-to-polygon and altitude range containment test. If a drone's coordinates fall within any of the defined 3D ELFZ volumes, the system determines an intrusion has occurred. However, simply detecting an intrusion does not directly trigger a response; the system performs a critical, complex logic check. This judgment is intended to distinguish unintentional violations from malicious intrusions. The system simultaneously checks the drone's comprehensive trust status, which is a product of real-time authentication status and location trustworthiness assessment results. Specific compliance handling instructions are only generated when the following two conditions are simultaneously met: the area intrusion behavior has been confirmed and the drone's comprehensive trust status is determined to be trustworthy. "Trustworthy" here means that the system is confident that the drone's identity is authentic and the GPS location information it reports is accurate. In this specific scenario, the system will generate clear compliance handling instructions, such as forced return or on-site landing, and issue them to the drone through a high-trust management channel, guiding it to safely exit the restricted area.
[0039] Optionally, the method further includes: Use the preset digital certificate private key to sign the remote control instruction and generate an encrypted control data packet; The encrypted control data packet is sent to the drone through the highly trusted management channel.
[0040] Specifically, after the system generates a specific remote control instruction based on the comprehensive trust status and airspace compliance judgment, the instruction will not be sent directly. Instead, the system will call a digital certificate private key preset in the cloud-based supervision platform. This private key is unique to the platform and is associated with a public digital certificate to prove the platform's own identity. Using this private key, the platform will perform a digital signature operation on the content of the remote control instruction. The process can be described as the following steps. First, a cryptographic hash operation is performed on the original remote control instruction to generate a fixed-length summary, and then the summary is encrypted using the platform's private key to obtain a unique digital signature: , in, Represents the final generated digital signature. is the digital signature algorithm used, such as RSA or elliptic curve digital signature algorithm. Refers to the preset digital certificate private key that is held and kept only by the cloud-based monitoring platform. It is a cryptographic hash function, such as SHA-256, which is used to convert instruction content of arbitrary length into a hash value of fixed length. This represents the original content of the remote control command to be sent. After signing, the system packages the original remote control command with the generated digital signature to form a complete encrypted control data packet. Finally, this encrypted control data packet is sent to the target drone through the previously established high-trust management channel. Upon receiving this data packet, the drone verifies the signature using the pre-stored cloud platform public key. Only when verification confirms the command's authenticity and integrity will it execute the command. This establishes a closed-loop chain of trust for the drone's remote management system. Digitally signing each issued remote control command fundamentally ensures its authenticity and integrity. This effectively prevents command forgery or tampering attacks within the control chain, eliminating the risk of unauthorized third parties impersonating the monitoring platform and sending malicious commands to drones. This ensures the non-repudiation of commands, ensuring that all control actions can be traced back to the legitimate issuing source, and providing a solid technical basis for post-audit and accountability. This mechanism adds an additional layer of application-layer security on top of the existing high-trust management channel, achieving the separation and dual reinforcement of communication security and command security, greatly enhancing the security and robustness of the entire cloud control management system. It is a key link in achieving highly reliable and secure remote management of drones.
[0041] Based on the same inventive concept, Figure 2 As shown, the present invention also provides a drone electronic ID card recognition and management system based on 4G / 5G cloud control, the system comprising: A communication and information receiving module is configured to obtain an initial connection request sent by the drone, the initial connection request including an identification code representing the drone's physical hardware, and establish an initial communication link based on the identification code; an identity challenge module, configured to generate a challenge code containing one-time data, encapsulate the challenge code into an identity challenge instruction, and send the identity challenge instruction to the drone via the initial communication link; wherein the drone receives the identity challenge instruction and digitally signs the challenge code using a private key within the drone to generate a response signature; An identity verification module is configured to receive the response signature returned by the drone, and to decrypt and verify the response signature by calling a public key pre-bound to the identity identification code, thereby confirming the authenticity of the identity of the peer end of the initial communication link and generating an identity confirmation credential; A control and management module is used to upgrade the attributes of the initial communication link to a high-trust management channel based on the identity confirmation credentials, and perform location credibility assessment and comprehensive decision-making based on the high-trust management channel to generate remote control instructions to manage the drone.
[0042] To verify the feasibility of this invention, it was applied to a municipal-level integrated drone monitoring platform. This platform aims to effectively and securely monitor drones flying over the city, particularly in key areas such as airports, government buildings, and large event venues. To ensure that every drone connected to the platform has a trusted "electronic ID" and to verify the authenticity of its flight location in real time, the present invention was applied to the platform's cloud-based control system. This system utilizes the drone's built-in 4G / 5G cellular communication module to achieve continuous online monitoring and management of the drone.
[0043] To verify the effectiveness of the invention, the system was tested for several months in simulated and real environments, recording data under various flight scenarios, including normal inspections, flights at the edge of restricted areas, and simulated identity forgery and location spoofing attacks.
[0044] In the embodiment, the application realizes the initial authentication and continuous verification of the identity of the UAV through the challenge-response mechanism. When a registered inspection UAV (ID: UAV-SN-8848) starts, its 4G module will immediately initiate an initial connection request to the supervision platform, and the request contains the unique identity code of the UAV. After receiving the request, the supervision platform immediately generates a one-time random string as a challenge code and sends it to the UAV through the initial link. The UAV uses the private key stored in its hardware security module to sign the challenge code, generates a response signature and returns it. The platform immediately calls the public key bound with UAV-SN-8848 in advance for verification. In the test at 09:30:15 on November 15, 2024, the entire process from the UAV initiating connection to the platform completing identity confirmation and establishing a highly trusted management channel took only 480 milliseconds.
[0045] To deal with potential risks during flight, the application realizes dynamic monitoring of the trusted state of the UAV through continuous identity challenge and double-source location cross comparison. In a simulated attack test, an unauthorized device tried to fake the identity code of UAV-SN-8848 to access the system. At 09:45:20, although the illegal device successfully initiated an initial connection request, it failed the identity challenge in the subsequent identity challenge process because it could not provide a response signature generated by the correct private key. The system immediately marked the connection as "identity abnormal mode" and sent an alarm to nearby security units according to the location of the base station it accessed. In another test against location fraud, a UAV (ID: UAV-FPV-9527) reported false GPS coordinates during flight through technical means, trying to show that it was flying in a city park, while its actual location was close to a high-speed rail forbidden flight area. Through the highly trusted management channel, the system receives the GPS location reported by the UAV, i.e. the terminal reported location information, and through the data interface with the cellular network operator, it obtains the network base station positioning information of the communication link. At 10:10:05, the system detected that the spatial deviation between the GPS coordinates reported by the UAV and the network base station positioning information exceeded the preset threshold of 800 meters, and determined that a location anomaly occurred. The system immediately switched its flight mode to "location abnormal mode" and issued an instruction to hover and accept manual verification, effectively preventing a potential violation of flight.
[0046] By integrating the trusted status of identity and location, this invention achieves precise, hierarchical control of drones. At 2:00 PM on November 20, 2024, a drone (ID: UAV-LG-007), whose identity and location were confirmed as "trusted," was about to enter a temporarily established no-fly zone due to a deviation in its route planning while performing a delivery mission. When the system predicted that its trajectory would enter the no-fly zone in 30 seconds, it determined that an "area intrusion" had occurred. Because the drone's overall trusted status was "trusted," the system determined this behavior to be an unintentional violation and automatically generated a "forced return" compliance instruction. This instruction was encapsulated and signed with the platform's private key and issued to the drone through a highly trusted management channel. After verifying the validity of the instruction signature, the drone immediately executed the return operation, avoiding the security incident.
[0047] Comparative data demonstrates that the proposed drone identification and management method offers significant advantages in response speed, anomaly detection accuracy, and closed-loop control efficiency. End-to-end authentication takes an average of less than 500 milliseconds. For abnormal behaviors such as identity forgery or location spoofing, the system's detection and pattern determination response time is less than 2 seconds. In scenarios such as no-fly zone intrusions, the entire automated closed-loop processing time, from detecting an intrusion risk to issuing a compliance action, is controlled within 5 seconds, significantly enhancing the system's proactive defense capabilities for low-altitude urban safety.
[0048] Table 1 Drone identity and location monitoring data Table 2 Data table of drone abnormal behavior detection and pattern determination Table 3 Remote control command generation and response processing data table It can be seen from the data in Tables 1-3 above that the method of the present invention has demonstrated efficient and reliable performance in drone supervision applications. Table 1 clearly records the system's identification process for normal and abnormal connections. Table 2 shows the system's ability to quickly detect and accurately determine different types of abnormal behaviors. For example, the response time to identity forgery is 1.2 seconds, and the response time to location deception is 1.8 seconds, which wins valuable time for subsequent disposal. Table 3 proves the effectiveness of closed-loop control. Whether it is "hovering for investigation" for position anomalies or "forced return" for no-fly zone intrusion, the system can deliver the securely signed instructions in less than half a second and verify and execute them by the drone, ensuring the immediacy and authority of the control measures. These data results fully demonstrate the technical advantages and practical value of the present invention in building a safe, reliable and efficient drone cloud supervision system.
[0049] It should be noted that the formulas appearing above can translate physical quantities of different properties into unitless standard values or superimposable parameters of the same dimension through the principle of dimensional consistency and mathematical standardization means (such as normalization, dimensionless parameter conversion or unit system unification), thereby eliminating the interference of different dimensions on the operation logic, so that the formulas have mathematical operation rationality and objective law adaptability while retaining the distribution characteristics of the original data. It is a conventional technical means and will not be elaborated here. The electrical connection between the above-mentioned units does not necessarily mean a direct connection of the circuit. The indirect connection method can be applied to the embodiments of the present invention as long as the purpose of the present invention is achieved. The above is only an exemplary embodiment of the present invention and the scope of the present invention cannot be limited thereto.
[0050] That is, any equivalent changes and modifications made according to the teachings of the present invention are still within the scope of the present invention. Those skilled in the art will readily conceive of other embodiments of the present invention after considering the disclosure of the specification and practical truths. This application is intended to cover any variations, uses, or adaptations of the present invention that follow the general principles of the present invention and include common knowledge or customary technical means in the art not described herein.
Claims
1. A method for identifying and managing drone electronic ID cards based on 4G / 5G cloud control, characterized in that: The method comprises: Obtaining an initial connection request sent by the drone, the initial connection request including an identification code representing the physical hardware of the drone, and establishing an initial communication link based on the identification code; generating a challenge code including one-time data, encapsulating the challenge code into an identity challenge instruction, and sending the identity challenge instruction to the drone via the initial communication link; The drone receives the identity challenge instruction and uses the private key inside the drone to digitally sign the challenge code to generate a response signature; Receive the response signature returned by the drone, and call the public key pre-bound to the identity identification code to decrypt and verify the response signature, confirm the authenticity of the identity of the peer end of the initial communication link, and generate an identity confirmation certificate; Based on the identity confirmation credentials, the attributes of the initial communication link are upgraded to a high-trust management channel, and location credibility assessment and comprehensive decision-making are performed based on the high-trust management channel to generate remote control instructions to manage the drone.
2. The method for identifying and managing drone electronic ID cards based on 4G / 5G cloud control according to claim 1 is characterized in that: The establishing of the initial communication link comprises: After the drone is powered on, the cellular communication module of the drone actively initiates a network connection to the cloud monitoring platform and sends the initial connection request; The cloud-based monitoring platform verifies the identity code, generates a session identifier, and returns it to the drone; An encrypted, point-to-point initial communication link is established based on the session identifier.
3. The method for identifying and managing drone electronic ID cards based on 4G / 5G cloud control according to claim 1 is characterized in that: The calling of the public key pre-bound to the identity code includes: During the drone registration phase, the user's real-name information is obtained and bound to the drone's identification code and paired public key; Encrypt and store the binding results to form an authorized digital file; When the response signature is received, the corresponding public key is retrieved and extracted from the authorized digital archive according to the identity identification code.
4. The method for identifying and managing drone electronic ID cards based on 4G / 5G cloud control according to claim 1, characterized in that: The performing of location credibility assessment based on the high-credibility management channel includes: Receiving terminal-reported location information including GPS module coordinates reported by the drone through the highly trusted management channel; Retrieving, through a data interface with a cellular network operator, network base station location information associated with a cellular network session carrying the highly trusted management channel; Perform spatial consistency comparison on the location information reported by the terminal and the positioning information of the network base station to generate a location credibility assessment result.
5. The method for identifying and managing drone electronic ID cards based on 4G / 5G cloud control according to claim 4 is characterized in that: Generating the location credibility evaluation result includes: Delineating a dynamic, credible geographic fence based on the network base station positioning information and in combination with the positioning error characteristics of the cellular network; Determining whether the coordinate point indicated by the location information reported by the terminal falls within the trusted geographic fence, and obtaining a location matching degree according to the determination result; A location credibility evaluation result is generated based on the degree of location matching, indicating whether the location is credible or abnormal.
6. The method for identifying and managing drone electronic ID cards based on 4G / 5G cloud control according to claim 4, characterized in that: Before generating remote control instructions to manage the drone, the method further includes: Generate a dynamically changing challenge code and a new identity challenge instruction at preset time intervals through the highly trusted management channel; Receive and verify the response signature generated based on the new identity challenge instruction, including the trusted status monitoring flow of multiple identity confirmation credentials; Based on the validity and timeliness of multiple identity confirmation credentials in the trusted state monitoring flow, a real-time identity authentication status is generated.
7. The method for identifying and managing drone electronic ID cards based on 4G / 5G cloud control according to claim 6, characterized in that: Generating a remote control instruction to manage the drone includes: Combining the real-time identity authentication status with the location credibility assessment result to generate a comprehensive credibility status for characterizing the reliability of the current flight status of the UAV; Determining the flight mode of the drone based on the comprehensive trustworthy status, the flight mode including a trustworthy mode, a location abnormality mode, and an identity abnormality mode; Generate remote control instructions based on the flight mode to manage the drone.
8. The method for identifying and managing drone electronic ID cards based on 4G / 5G cloud control according to claim 7, characterized in that: The method further comprises: Obtain the scope of the electronic no-fly zone set by the airspace management agency, which defines the geographical coordinates and altitude restrictions; Determining whether an area intrusion occurs based on the geographical location indicated by the location information reported by the terminal and the range of the electronic no-fly zone; When an area intrusion occurs and the comprehensive trust status is trustworthy, a compliance handling instruction including forced return or on-site landing is generated.
9. The method for identifying and managing drone electronic ID cards based on 4G / 5G cloud control according to claim 1, characterized in that: The method further comprises: Use the preset digital certificate private key to sign the remote control instruction and generate an encrypted control data packet; The encrypted control data packet is sent to the drone through the highly trusted management channel.
10. A 4G / 5G cloud-controlled drone electronic ID card identification and management system, applied to a 4G / 5G cloud-controlled drone electronic ID card identification and management method as claimed in any one of claims 1 to 9, characterized in that: The system comprises: A communication and information receiving module is configured to obtain an initial connection request sent by the drone, the initial connection request including an identification code representing the drone's physical hardware, and establish an initial communication link based on the identification code; an identity challenge module, configured to generate a challenge code containing one-time data, encapsulate the challenge code into an identity challenge instruction, and send the identity challenge instruction to the drone via the initial communication link; wherein the drone receives the identity challenge instruction and digitally signs the challenge code using a private key within the drone to generate a response signature; An identity verification module is configured to receive the response signature returned by the drone, and to decrypt and verify the response signature by calling a public key pre-bound to the identity identification code, thereby confirming the authenticity of the identity of the peer end of the initial communication link and generating an identity confirmation credential; A control and management module is used to upgrade the attributes of the initial communication link to a high-trust management channel based on the identity confirmation credentials, and perform location credibility assessment and comprehensive decision-making based on the high-trust management channel to generate remote control instructions to manage the drone.
Citation Information
Patent Citations
Electronic fence and unmanned aerial vehicle control method based on electronic fence
CN107424442A
Method and system for controlling flight of unmanned aerial vehicle, and unmanned aerial vehicle
CN110209188A
Identity verification method, system and device based on challenge-response mechanism cryptography and medium
CN116827556A
Unmanned aerial vehicle control method, terminal and system
CN118212811A
Unmanned aerial vehicle access authentication method based on LORA communication
CN120358500A
Cited By
Unmanned aerial vehicle leasing service identity verification system of low-altitude shared economic platform
CN121125118A
Identity verification system for low-altitude sharing economy platform unmanned aerial vehicle rental service
CN121125118B
Unmanned aircraft unique product identification code credit granting and verification system fused with password technology
CN121568104A