A data processing method and device for user authentication of a drone, and a medium

By employing a multi-dimensional authentication method, combining initial authentication via SIM card and 5G core network with secondary authentication via target backend, an encrypted transmission channel is established, solving the drone identity security problem and achieving reliability and security for drone data interaction.

CN120857119BActive Publication Date: 2025-12-12THE THIRD RES INST OF MIN OF PUBLIC SECURITY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511333638.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-18
Publication Date
2025-12-12
Estimated Expiration
2045-09-18

AI Technical Summary

Technical Problem

Unmanned aerial vehicle (UAV) identity security has become a key bottleneck restricting the industry's development. Attackers can illegally access private networks by forging identity identifiers, leading to false intelligence and fabricated evidence, which seriously threatens public and national security. Existing authentication schemes for UAV access to private networks are easily cracked or subjected to replay attacks.

Method used

A multi-dimensional authentication method is adopted, including the drone establishing a wireless connection with the 5G core network through a SIM card, using SMF and DN-AAA for initial authentication, the target SDK and the target backend performing secondary authentication, and generating dynamic access policies through the target authentication platform to establish an encrypted transmission channel for data interaction.

Benefits of technology

It improves the security of drone identity authentication, ensures the reliability and legitimacy of data interaction, resists man-in-the-middle attacks and data tampering, and enhances the verification legitimacy on the network side and the device identity verification of the target backend.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120857119B_ABST
    Figure CN120857119B_ABST
Patent Text Reader

Abstract

The application provides a data processing method and device for user authentication of a UAV, and a medium, and relates to the technical field of data processing.The method comprises the following steps: the UAV sends an access request to a target backend in a 5G wireless manner through a SIM card installed by the UAV; the UAV performs first identity authentication on an intermediate backend corresponding to the 5G wireless manner; if the first identity authentication is passed, the UAV performs second identity authentication on the target backend through a target SDK installed by the UAV; and based on an encrypted transmission channel, the UAV transmits encrypted target task data to the target backend, thereby improving the security of identity authentication.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data processing, in particular to a data processing method for user authentication of a UAV, a device and a medium. BACKGROUND

[0002] The security of UAV identity has become a key bottleneck restricting the development of the industry: attackers can access the private network and send malicious data by forging the MAC address, serial number, certificate and other identity identifiers of the UAV, leading to false information, false scene information or fake evidence received by the background, which seriously threatens public safety and national security.

[0003] In the prior art, the authentication scheme for UAV access to the private network relies on single network side authentication (such as initial authentication of the operator 5G network side), which is easy to be cracked or replay attacked. Therefore, there is an urgent need for a secure authentication method combining multi-dimensional authentication, dynamic permission control and national encryption to ensure the legality of UAV identity and the reliability of data interaction. SUMMARY

[0004] To solve the above technical problems, the technical solution adopted by the present application is as follows:

[0005] According to the first aspect of the present application, a data processing method for user authentication of a UAV is provided. When the UAV sends an access request to a target backend through a SIM card installed in a 5G wireless manner, the following steps are performed:

[0006] S001, the UAV performs first identity authentication to the intermediate backend corresponding to the 5G wireless manner through the SIM card installed, and performs S002 if the first identity authentication is passed;

[0007] In which, the UAV establishes a wireless connection with the 5G core network of the intermediate backend through the SIM card, and the session management device SMF of the 5G core network initiates a first authentication request to the data network authentication and authorization device DN-AAA, the first authentication request at least carrying the ID of the UAV SIM card;

[0008] The data network authentication and authorization device DN-AAA verifies the legality of the first authentication request and generates an authentication response containing 5G network access permission;

[0009] The session management device SMF receives the authentication response, and the first identity authentication is passed;

[0010] S002, the UAV performs second identity authentication to the target backend through the target SDK installed, and performs S003 if the second identity authentication is passed;

[0011] The target SDK initiates a single package authorization (SPA) authentication request to a target gateway of a target backend, and the SPA authentication request carries a UAV ID, a SIM card public key hash value, a current timestamp, and a random number;

[0012] The target gateway receives the SPA authentication request, verifies whether the current timestamp is within a valid window based on the current time, and determines that the random number has not been tampered with;

[0013] The target gateway initiates a platform authentication request to a target authentication platform, and the platform authentication request carries digest information of the SPA authentication request and a UAV device certificate, wherein the digest information of the SPA authentication request is determined based on the UAV ID, the SIM card public key hash value, the current timestamp, and the random number;

[0014] The target authentication platform performs authentication based on the digest information of the SPA authentication request and the UAV device certificate, and generates an SPA authentication result and a dynamic access policy;

[0015] The target gateway receives the SPA authentication result, and returns an encrypted session token and a dynamic permission policy to the target SDK;

[0016] The target SDK installed on the UAV receives the encrypted session token and the dynamic permission policy, and secondary identity authentication is passed, and the UAV and the target backend establish an encrypted transmission channel based on the encrypted session token and the dynamic permission policy;

[0017] S003, based on the encrypted transmission channel, the UAV transmits encrypted target task data to the target backend.

[0018] According to a second aspect of the present application, a non-transitory computer readable storage medium is provided, and the storage medium stores a computer program, and the computer program is loaded and executed by a processor to implement the method described above.

[0019] According to a third aspect of the present application, an electronic device is provided, comprising a processor, a memory, and a computer program stored on the memory and executable on the processor, and the processor implements the method described above when executing the computer program.

[0020] The present application has at least the following beneficial effects: the unmanned aerial vehicle sends an access request to the target backend in a 5G wireless manner through the installed SIM card, the unmanned aerial vehicle performs first identity authentication through the corresponding intermediate backend in a 5G wireless manner, the first identity authentication is passed, the unmanned aerial vehicle performs second identity authentication through the installed target SDK to the target backend, the encrypted target task data is transmitted to the target backend based on an encrypted transmission channel, the second identity authentication is passed, the secure data interaction is established with the target backend, and the encrypted transmission is performed. BRIEF DESCRIPTION OF DRAWINGS

[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiment description. Obviously, the drawings in the following description are only some embodiments of the present application, and for those skilled in the art, other drawings can also be obtained without creative labor.

[0022] Figure 1 A flowchart of a data processing method for user authentication of an unmanned aerial vehicle is provided. DETAILED DESCRIPTION

[0023] The technical solutions in the embodiments of the present application will be described clearly and completely in the following with reference to the drawings of the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, not all. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.

[0024] It should be noted that the terms "first", "second" and the like in the specification and claims of the present application and the above drawings are used to distinguish similar objects, and do not necessarily indicate a specific order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or server including a series of steps or units does not necessarily have to include those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to the process, method, product or device.

[0025] It should be noted that the acquisition, storage, use, processing and the like of data in the technical solutions of the present application comply with the relevant provisions of national laws and regulations.

[0026] The embodiment of the application provides a data processing method for user authentication of a UAV, as shown in the following Figure 1 When the UAV sends an access request to a target backend in a 5G wireless mode through an installed SIM card, the following steps are performed:

[0027] S001, the UAV performs first identity authentication to an intermediate backend corresponding to the 5G wireless mode through the installed SIM card, and performs S002 when the first identity authentication is passed.

[0028] S001 specifically includes the following steps:

[0029] S010, the UAV establishes a wireless connection with a 5G core network of the intermediate backend through the SIM card, and a session management device SMF of the 5G core network initiates a first authentication request to a data network authentication and authorization device DN-AAA, wherein the first authentication request at least carries an ID of the UAV SIM card; specifically, the ID of the SIM card is a unique identifier of the SIM card, and in an embodiment of the application, the ID of the SIM card is an international mobile subscriber identity IMSI. Further, the authentication request also carries a globally unique temporary identifier GUTI and a temporary session ID allocated by the 5G core network.

[0030] S011, the data network authentication and authorization device DN-AAA verifies the legality of the first authentication request and generates an authentication response containing 5G network access permission; specifically, the data network authentication and authorization device DA-AAA queries a database according to the IMSI to verify the legality of the SIM card.

[0031] S012, the session management device SMF receives the authentication response, and the first identity authentication is passed. In an embodiment of the application, the intermediate backend is a supplier corresponding to the SIM card.

[0032] Specifically, after obtaining the unpassing factor of the first identity authentication of the UAV, the following steps are further included:

[0033] The intermediate backend sends the UAV related information and the unpassing factor of the first identity authentication of the UAV to the target backend, and the UAV related information at least includes a UAV ID. Specifically, the intermediate backend sends the UAV related information and the unpassing factor of the first identity authentication of the UAV to the target backend, so that the target backend stores the information, avoids the situation that the UAV directly authenticates the target backend without passing through the intermediate backend, and thus improves the correctness of the authentication.

[0034] S002, the UAV performs second identity authentication to the target backend through the installed target SDK, and performs S003 when the second identity authentication is passed.

[0035] S002 specifically includes the following steps:

[0036] S020, the target SDK initiates a single package authorization (SPA) authentication request to a target gateway of a target backend, and the SPA authentication request carries a UAV ID, a SIM card public key hash value, a current timestamp, and a random number.

[0037] S021, after the target gateway receives the SPA authentication request, it verifies whether the current timestamp is within a valid window based on the current time, and determines that the random number has not been tampered with.

[0038] S022, the target gateway initiates a platform authentication request to the target authentication platform, and the platform authentication request carries digest information of the SPA authentication request and a UAV device certificate, wherein the digest information of the SPA authentication request is determined based on the UAV ID, the SIM card public key hash value, the current timestamp, and the random number.

[0039] S023, the target authentication platform authenticates based on the digest information of the SPA authentication request and the UAV device certificate to generate a SPA authentication result and a dynamic access policy; specifically, the target authentication platform generates a dynamic access policy based on the single package authorization (SPA) authentication request, allowing the UAV to access only specified business resources, minimizing the attack surface.

[0040] Specifically, the target authentication platform uses a national cryptographic algorithm to implement authentication and signature verification, which meets the national cryptographic security standard and resists threats such as man-in-the-middle attacks and data tampering.

[0041] S024, after the target gateway receives the SPA authentication result, it returns an encrypted session token and a dynamic permission policy to the target SDK.

[0042] S025, the target SDK installed on the UAV receives the encrypted session token and the dynamic permission policy, the secondary identity authentication is passed, and based on the encrypted session token and the dynamic permission policy, the UAV and the target backend establish an encrypted transmission channel.

[0043] Specifically, S002 further comprises: when the secondary identity authentication fails, the target backend sends the relevant information of the UAV to the intermediate backend. When the secondary identity authentication fails, the target backend sends the relevant information of the UAV and the failure factors of the secondary identity authentication to the intermediate backend, so as to synchronize the data of the UAV and the target backend.

[0044] S003, based on the encrypted transmission channel, the UAV transmits encrypted target task data to the target backend.

[0045] In summary, the unmanned aerial vehicle sends an access request to the target backend through the installed SIM card in a 5G wireless manner, the unmanned aerial vehicle performs first identity authentication through the corresponding intermediate backend in a 5G wireless manner, the first identity authentication is passed, the unmanned aerial vehicle performs second identity authentication through the installed target SDK to the target backend, the encrypted target task data is transmitted to the target backend based on an encrypted transmission channel, the second identity authentication is passed, and the secure data interaction is established with the target backend for encrypted transmission. The application verifies the legality of the SIM card through the intermediate backend network side and verifies the identity of the unmanned aerial vehicle device through the target backend, solves the security problem that the traditional single authentication is easy to be forged, and improves the security of identity authentication.

[0046] Specifically, the first authentication request further includes target task information transmitted by the unmanned aerial vehicle to the target backend, and the target task information at least includes a flight path of the unmanned aerial vehicle for executing a target task.

[0047] Further, when the first identity authentication is not passed, the following steps are performed.

[0048] S0011, obtaining an unpassed factor of first identity authentication of the unmanned aerial vehicle.

[0049] S0012, if the unpassed factor of the first identity authentication is that the ID of the SIM card of the unmanned aerial vehicle is not legal, ending.

[0050] S0013, if the unpassed factor of the first identity authentication belongs to a preset factor list, giving the unmanned aerial vehicle a temporary first identity authentication pass and obtaining a preset temporary pass scheme corresponding to the unpassed factor, the preset factor list includes a plurality of preset factors, and the preset factors at least include an unreasonable flight path of the unmanned aerial vehicle; the preset temporary pass scheme at least includes a time length of the first identity authentication pass.

[0051] S0014, sending the preset temporary pass scheme of the unmanned aerial vehicle to the target backend.

[0052] In summary, when the first identity authentication is not passed, the unpassed factor of the first identity authentication of the unmanned aerial vehicle is obtained, if the unpassed factor of the first identity authentication is that the ID of the SIM card of the unmanned aerial vehicle is not legal, ending, if the unpassed factor of the first identity authentication belongs to a preset factor list, giving the unmanned aerial vehicle a temporary first identity authentication pass and obtaining a preset temporary pass scheme corresponding to the preset factor, and sending the preset temporary pass scheme of the unmanned aerial vehicle to the target backend, the application analyzes the factor that the unmanned aerial vehicle does not pass the first identity authentication, sets a temporary first identity authentication for the unmanned aerial vehicle that meets the preset factor, and accurately controls the risk.

[0053] Specifically, in S003, based on the encrypted transmission channel, the unmanned aerial vehicle transmits the encrypted target task data to the target backend, and the method further includes:

[0054] S100, in response to the received target task instruction, in the process that the unmanned aerial vehicle executes the target task, every interval preset time length, the encryption module mounted on the unmanned aerial vehicle obtains intermediate subtask data by reducing the resolution of the video data in the original subtask data collected in the corresponding preset time length; wherein the data collected by the unmanned aerial vehicle in one preset time length is the original subtask data corresponding to the preset time length.

[0055] Specifically, the mounting mode of the encryption module on the unmanned aerial vehicle includes: the encryption module is accessed to the unmanned aerial vehicle through the interface of the unmanned aerial vehicle in the form of an external box; or the encryption module is installed to the running environment of the unmanned aerial vehicle in the form of software. The encryption module is accessed to the unmanned aerial vehicle through the interface of the unmanned aerial vehicle in the form of an external box, and the form of the external box is used, which is suitable for various unmanned aerial vehicles, and improves the convenience of target task data processing and intermediate subtask data encryption.

[0056] In an embodiment of the application, the encryption module is embedded in the unmanned aerial vehicle in the form of a chip.

[0057] Specifically, on the one hand, the resolution of the video data of the target task data collected by the unmanned aerial vehicle when executing the target task may be high, for example, 4k, and the video data with high resolution occupies a large space, affecting the transmission efficiency; on the other hand, when the unmanned aerial vehicle executes the target task, the target backend may urgently need the target task data, and the target task data needs to be transmitted in real time by means of interval preset time length, and the real-time requirement of the target task data is high. Therefore, the unmanned aerial vehicle collects the target task data, reduces the resolution of the video data in the target task data to obtain the intermediate subtask data for transmission.

[0058] Those skilled in the art know that any method for reducing the resolution of video data in the prior art belongs to the protection scope of the present application, which will not be described here.

[0059] S200, after the encryption module encrypts the intermediate subtask data, the unmanned aerial vehicle transmits the encrypted intermediate subtask data to the target backend through the encryption transmission channel using 4G / 5G.

[0060] When the intermediate subtask data meets the first preset encryption condition, the intermediate subtask data is encrypted using a symmetric encryption algorithm; when the intermediate subtask data meets the second preset encryption condition, the intermediate subtask data is encrypted using an asymmetric encryption algorithm, and the first preset encryption condition is different from the second preset encryption condition.

[0061] Specifically, the first preset encryption condition is that the data amount of the intermediate sub-task data is greater than a preset data amount threshold, or the real-time level in the transmission requirement of the intermediate sub-task data is greater than a preset real-time level threshold. In an embodiment of the present application, when the intermediate sub-task data satisfies the first preset encryption condition, SM4 symmetric encryption is used.

[0062] Specifically, the second preset encryption condition is that the data amount of the intermediate sub-task data is not greater than a preset data amount threshold, or the security level in the transmission requirement of the intermediate sub-task data is greater than a preset security level threshold. In an embodiment of the present application, when the intermediate sub-task data satisfies the second preset encryption condition, SM2 public key encryption is used. In another embodiment of the present application, when the intermediate sub-task data satisfies the second preset encryption condition, SM9 encryption is used.

[0063] S300, the target backend receives the encrypted intermediate sub-task data, decrypts the encrypted intermediate sub-task data, obtains the intermediate sub-task data, processes the intermediate sub-task data, and obtains a processing result.

[0064] Specifically, when the intermediate sub-task data satisfies the second preset encryption condition, asymmetric encryption is used, the key generation center generates a public key and a private key of the target backend based on the ID of the target backend; the unmanned aerial vehicle encrypts the intermediate sub-task data using the public key of the target backend, and the target backend decrypts the encrypted intermediate sub-task data using the private key of the target backend to obtain the intermediate sub-task data.

[0065] The key generation center updates the public key and the private key periodically.

[0066] Specifically, when the intermediate sub-task data satisfies the first preset encryption condition, symmetric encryption is used, the key generation center generates a key and binds the key with the ID of the unmanned aerial vehicle; the key generation center securely sends the key to the unmanned aerial vehicle and the target backend; the unmanned aerial vehicle encrypts the intermediate sub-task data using the key, and the target backend decrypts the encrypted intermediate sub-task data using the key. The key generation center updates the key periodically.

[0067] Specifically, the target backend processes the intermediate sub-task data to obtain a processing result, for example, the target backend performs face recognition of a preset face on the intermediate sub-task data to determine whether the video information of the intermediate sub-task data contains information of the preset face.

[0068] S400, the unmanned aerial vehicle returns to the unmanned aerial vehicle nest after completing the target task, and sends the target task data to the unmanned aerial vehicle nest; wherein the target task data is composed of all original sub-task data collected by the unmanned aerial vehicle during the execution of the target task. Specifically, after the unmanned aerial vehicle returns to the unmanned aerial vehicle nest, the target task data is sent to the unmanned aerial vehicle nest in various ways, for example, the target task data stored in the storage card of the unmanned aerial vehicle is directly transmitted to the unmanned aerial vehicle nest using a wired method, which is more efficient and easier to transmit high-resolution and large-data target task data. Therefore, the target task data is directly sent to the unmanned aerial vehicle nest.

[0069] S500, the unmanned aerial vehicle nest sends the target task data to the target backend.

[0070] S600, the target backend receives the target task data and verifies the processing result based on the target task data.

[0071] Specifically, when the target backend receives the target task data, the target backend simultaneously stores the target task data and the intermediate sub-task data, compares the intermediate sub-task data and the target task data, and verifies the processing result of the intermediate sub-task data by the target task data.

[0072] In summary, in response to the received target task instruction, during the execution of the target task by the unmanned aerial vehicle, every interval of a preset time length, the encryption module mounted on the unmanned aerial vehicle reduces the resolution of the video data in the original sub-task data collected within the corresponding preset time length to obtain intermediate sub-task data, the unmanned aerial vehicle uses the encryption module mounted on the unmanned aerial vehicle to encrypt the intermediate sub-task data, after the encryption module encrypts the intermediate sub-task data, the unmanned aerial vehicle transmits the encrypted intermediate sub-task data to the target backend through the encryption transmission channel using 4G / 5G, the target backend receives the encrypted intermediate sub-task data, decrypts the encrypted intermediate sub-task data, obtains the intermediate sub-task data, processes the intermediate sub-task data, obtains the processing result, the unmanned aerial vehicle returns to the unmanned aerial vehicle nest after completing the target task, and sends the target task data to the unmanned aerial vehicle nest, the unmanned aerial vehicle nest sends the target task data to the target backend, the target backend receives the target task data, and verifies the processing result based on the target task data. In the present application, the unmanned aerial vehicle executes the target task to collect the target task data, uses the encryption module to encrypt and then transmits, and the target backend decrypts and then uses, to ensure the security, authenticity and timeliness of data transmission.

[0073] Further, the unmanned aerial vehicle remote controller sends the target task instruction to the unmanned aerial vehicle through a radio station.

[0074] Specifically, the unmanned aerial vehicle remote controller sends the target task instruction to the unmanned aerial vehicle through a radio station, and further comprises:

[0075] S110, the unmanned aerial vehicle remote controller and the unmanned aerial vehicle perform key exchange using an SM2 algorithm to generate a session key.

[0076] S120, the unmanned aerial vehicle remote controller encrypts the target task instruction and the related information of the target task instruction using an SM4 algorithm through the session key to generate instruction ciphertext.

[0077] S130, the unmanned aerial vehicle remote controller sends the instruction ciphertext to the unmanned aerial vehicle.

[0078] S140, the unmanned aerial vehicle receives the instruction ciphertext and decrypts the instruction ciphertext using the SM4 algorithm through the session key to obtain the target task instruction.

[0079] In summary, the unmanned aerial vehicle remote controller and the unmanned aerial vehicle perform key exchange using an SM2 algorithm to generate a session key, the unmanned aerial vehicle remote controller encrypts the target task instruction and the related information of the target task instruction using an SM4 algorithm through the session key to generate instruction ciphertext, the unmanned aerial vehicle remote controller sends the instruction ciphertext to the unmanned aerial vehicle, and the unmanned aerial vehicle receives the instruction ciphertext and decrypts the instruction ciphertext using the SM4 algorithm through the session key to obtain the target task instruction, thereby performing encrypted transmission of the signaling.

[0080] Further, in S200, the encryption module encrypts the intermediate subtask data, and the method further includes:

[0081] S210, obtaining a symmetric encryption algorithm ID list and an asymmetric encryption algorithm ID list, the symmetric encryption algorithm ID list including IDs of a plurality of symmetric encryption algorithms, and the asymmetric encryption algorithm ID list including IDs of a plurality of asymmetric encryption algorithms; the symmetric encryption algorithm and the asymmetric encryption algorithm are marked with a low priority label or a high priority label.

[0082] Specifically, all symmetric encryption algorithms and all asymmetric encryption algorithms are given a high priority label or a low priority label based on a preset evaluation standard. In an embodiment of the present application, for a plurality of key lengths of the same category algorithm, the algorithm with the longest key length is marked as a high priority label, and the algorithms with the key lengths other than the longest key length are marked as low priority labels. The same category algorithm is a symmetric encryption algorithm with different key lengths.

[0083] S220, determining the processing efficiency of the symmetric encryption algorithm with a low priority label based on the first preset encryption condition and the video data in the intermediate subtask data, and determining the symmetric encryption algorithm as a target symmetric encryption algorithm based on the processing efficiency.

[0084] When the intermediate subtask data meets the first preset encryption condition, the target symmetric encryption algorithm is used to encrypt the intermediate subtask data.

[0085] Specifically, the processing efficiency of the symmetric encryption algorithm of the low-priority label is obtained by the following steps:

[0086] S221, obtaining a list of applicable characteristic values of each symmetric encryption algorithm of the same category, the list of applicable characteristic values including preset characteristic values of several applicable characteristics, the applicable characteristics including real-time characteristics and security characteristics. In an embodiment of the present application, experts divide the real-time characteristics of the symmetric encryption algorithms of the same category into grades.

[0087] S222, obtaining a list of target characteristic values based on the first preset encryption condition and the video data in the intermediate subtask data, the list of target characteristic values including target characteristic values of several applicable characteristics, matching the list of target characteristic values and the list of preset characteristic values, and taking the matching degree as the processing efficiency of the symmetric encryption algorithm of the low-priority label. In an embodiment of the present application, the requirements for the real-time characteristics of the first preset encryption condition and the video data in the intermediate subtask data are divided into grades.

[0088] Further, the symmetric encryption algorithm is determined as a target symmetric encryption algorithm based on the processing efficiency, including:

[0089] The symmetric encryption algorithm of the same category with a matching degree greater than a preset threshold is obtained as an intermediate symmetric encryption algorithm, the symmetric encryption algorithm of the same category with the highest ranking in the intermediate symmetric encryption algorithm is obtained as a target symmetric encryption algorithm, and one of the symmetric encryption algorithms of the same category is randomly selected from the target symmetric encryption algorithm as the target encryption algorithm. In an embodiment of the present application, the symmetric encryption algorithms of the same category are ranked from complex to simple based on the round operation step of the symmetric encryption algorithm, and in an embodiment of the present application, the ranking structure is AES>3DES>IDEA, the symmetric encryption algorithm of the same category being a kind of symmetric encryption algorithm with different key lengths. The more in front of the ranking, the higher the complexity of the symmetric encryption algorithm of the same category.

[0090] S230, determining the processing efficiency of the asymmetric encryption algorithm of the low-priority label based on the second preset encryption condition and the video data in the intermediate subtask data, and determining the asymmetric encryption algorithm as a target asymmetric encryption algorithm based on the processing efficiency.

[0091] When the intermediate subtask data meets the second preset encryption condition, the target asymmetric encryption algorithm is used to encrypt the intermediate subtask data.

[0092] Specifically, the target asymmetric encryption algorithm is determined by the same method as S220.

[0093] Further, the target task data is sent to the target back end by the drone nest in S500, further including:

[0094] S510, determine the processing efficiency of the symmetric encryption algorithm of the high-priority label based on the encryption condition of the target task data and the video data in the target task data, and determine the symmetric encryption algorithm of the high-priority label as the final symmetric encryption algorithm based on the processing efficiency.

[0095] Specifically, the final symmetric encryption algorithm is determined using the same method as S220.

[0096] S520, determine the processing efficiency of the asymmetric encryption algorithm of the high-priority label based on the encryption condition of the target task data and the video data in the target task data, and determine the asymmetric encryption algorithm of the high-priority label as the final asymmetric encryption algorithm based on the processing efficiency.

[0097] Specifically, the final asymmetric encryption algorithm is determined using the same method as S220.

[0098] S530, the drone nest encrypts the target task data based on the final symmetric encryption algorithm and the final asymmetric encryption algorithm, and sends the encrypted target task data to the target backend.

[0099] Specifically, in an embodiment of the present application, when the target task data meets the first preset encryption condition, the final symmetric encryption algorithm is used to encrypt the target task data; when the target task data meets the second preset encryption condition, the final asymmetric encryption algorithm is used to encrypt the target task data.

[0100] In summary, the symmetric encryption algorithm ID list and the asymmetric encryption algorithm ID list are obtained, the processing efficiency of the symmetric encryption algorithm of the low-priority label is determined based on the first preset encryption condition and the video data, and the symmetric encryption algorithm is determined as the target symmetric encryption algorithm based on the processing efficiency; when the intermediate sub-task data meets the first preset encryption condition, the target symmetric encryption algorithm is used to encrypt the intermediate sub-task data, the processing efficiency of the asymmetric encryption algorithm of the low-priority label is determined based on the second preset encryption condition and the video data, and the asymmetric encryption algorithm is determined as the target asymmetric encryption algorithm based on the processing efficiency; when the intermediate sub-task data meets the second preset encryption condition, the target asymmetric encryption algorithm is used to encrypt the intermediate sub-task data, the processing efficiency of the symmetric encryption algorithm of the high-priority label is determined based on the encryption condition of the target task data and the video data in the target task data, and the symmetric encryption algorithm of the high-priority label is determined as the final symmetric encryption algorithm based on the processing efficiency; the processing efficiency of the asymmetric encryption algorithm of the high-priority label is determined based on the encryption condition of the target task data and the video data in the target task data, and the asymmetric encryption algorithm of the high-priority label is determined as the final asymmetric encryption algorithm based on the processing efficiency; the drone nest encrypts the target task data based on the final symmetric encryption algorithm and the final asymmetric encryption algorithm, and sends the encrypted target task data to the target backend.

[0101] It can be understood that the intermediate subtask data is encrypted by using the symmetric encryption algorithm with the low priority label or the asymmetric encryption algorithm with the low priority, and the target task data is encrypted by using the symmetric encryption algorithm with the high priority label or the asymmetric encryption algorithm with the high priority, the intermediate subtask data is processed target task data, and the importance of the intermediate subtask data is lower than that of the target task data; therefore, the low priority label symmetric encryption algorithm and the low priority label asymmetric encryption algorithm are used for the intermediate subtask data, and the high priority label symmetric encryption algorithm and the high priority label asymmetric encryption algorithm are used for the non-intermediate subtask data, so that the computing resources are optimized and the efficiency is improved.

[0102] In an embodiment of the present application, S100 further comprises determining the preset time length by the following steps:

[0103] Based on the target task, determining the required total execution time length of the target task and a key time node A3 in the target task in the execution process.

[0104] Taking A3 as a starting point, the first preset time length after A3 is a first fixed value B1, the i-th preset time length after A3 is an i-th fixed value Bi, Bi=B1+ (i-1) d, d is greater than 0 and d is a preset fixed value, the value range of i is 1 to m, and m is the number of preset time lengths from the starting point to the target task completion execution time point.

[0105] Taking A3 as a starting point, the first preset time length before A3 is a first fixed value C1, the j-th preset time length before A3 is a j-th fixed value Cj, Cj=C1+ (j-1) d, the value range of j is 1 to n, and n is the number of preset time lengths from the target task start execution time point to the starting point. It can be understood that the key time node A3 in the target task is a time node that is more concerned in the execution process of the target task, and the key time node is more important than other time nodes, so the preset time length corresponding to the time node closest to the key time node is set to be the smallest, and the preset time length corresponding to the time node farthest from the key time node is set to be the largest. Preferably, B1=C1.

[0106] In another embodiment of the present application, S100 further comprises determining the preset time length by the following steps:

[0107] Based on the target task, determining the required total execution time length of the target task and a key part execution completion time node A4 in the target task.

[0108] The preset time length from the start of the target task to A4 is a first fixed value D1, the first preset time length after A4 is the first fixed value D1, the rth preset time length after A4 is an rth fixed value Br, Br=B1+(r-1)d, d is greater than 0 and is a preset fixed value, the value range of r is 1 to s, and s is the number of preset time lengths from A4 to the execution time point of the target task.

[0109] It can be understood that when the key part of the target task is executed, the remaining part can be a task of returning to the nest, at this time, the video of the remaining part can be directly sent to the target backend by the nest after the unmanned aerial vehicle returns to the nest, so as to save resources.

[0110] The embodiment of the application further provides a non-transitory computer readable storage medium, which can be arranged in an electronic device to save a computer program related to a method in the method embodiment, the computer program is loaded and executed by the processor to realize the method provided by the above embodiment.

[0111] The embodiment of the application further provides an electronic device, which comprises a processor, a memory and a computer program stored in the memory and executable on the processor, and the processor realizes the method provided by the above embodiment when executing the computer program.

[0112] The embodiment of the application further provides a computer program product, which comprises program code, and the program code is used for making the electronic device execute the steps in the method according to various exemplary embodiments of the application described in the specification when the program product is executed on the electronic device.

[0113] Although some specific embodiments of the application have been described in detail by examples, those skilled in the art should understand that the above examples are only for illustration, and are not intended to limit the scope of the application. Those skilled in the art should also understand that various modifications can be made to the embodiments without departing from the scope and spirit of the application.

Claims

1. A data processing method for user authentication of unmanned aerial vehicles (UAVs), characterized in that, When the drone sends an access request to the target backend via 5G wireless communication using the installed SIM card, the following steps are performed: S001, the drone performs initial identity authentication with the intermediate backend corresponding to the 5G wireless method through the installed SIM card. If the initial identity authentication is successful, proceed to S002. Among them, the drone establishes a wireless connection with the 5G core network in the middle and back end through the SIM card. The session management device SMF of the 5G core network initiates the first authentication request to the data network authentication and authorization device DN-AAA. The first authentication request carries at least the ID of the drone's SIM card. The data network authentication and authorization device DN-AAA verifies the legitimacy of the initial authentication request and generates an authentication response containing 5G network access rights; The session management device (SMF) receives the authentication response, and the initial authentication is successful. S002, the drone performs secondary authentication with the target backend through the installed target SDK. If the secondary authentication is successful, proceed to S003. The target SDK initiates a single-packet authorization SPA authentication request to the target gateway of the target backend. The SPA authentication request carries the drone ID, SIM card public key hash value, current timestamp and random number. After receiving the SPA authentication request, the target gateway verifies whether the current timestamp is within the valid window based on the current time, and determines that the random number has not been tampered with; The target gateway initiates a platform authentication request to the target authentication platform. The platform authentication request carries the digest information of the SPA authentication request and the drone device certificate. The digest information of the SPA authentication request is determined based on the drone ID, the hash value of the SIM card public key, the current timestamp, and a random number. The target authentication platform performs authentication based on the summary information of the SPA authentication request and the drone equipment certificate, and generates SPA authentication results and dynamic access policies; After receiving the SPA authentication result, the target gateway returns an encrypted session token and dynamic permission policy to the target SDK; The target SDK installed on the drone receives the encrypted session token and dynamic permission policy. After the secondary authentication is successful, the drone and the target backend establish an encrypted transmission channel based on the encrypted session token and dynamic permission policy. S003, based on an encrypted transmission channel, the UAV transmits encrypted target mission data to the target backend.

2. The data processing method for user authentication of unmanned aerial vehicles according to claim 1, characterized in that, The initial authentication request also includes: target mission information transmitted by the UAV to the target backend, the target mission information including at least: the flight path of the UAV to perform the target mission.

3. The data processing method for user authentication of unmanned aerial vehicles according to claim 2, characterized in that, If the initial authentication fails, proceed with the following steps: S0011, Factors that prevented the initial identification of the drone; S0012, If the reason for the initial identity verification failure is that the drone SIM card ID is invalid, the process ends; S0013, if the reason for the failure of the initial identity authentication belongs to the preset factor list, grant the drone a temporary initial identity authentication pass and obtain the preset temporary pass plan corresponding to the failure factor. The preset factor list includes several preset factors, and the preset factors include at least: the drone's flight path is unreasonable; the preset temporary pass plan includes at least: the duration of the initial identity authentication pass. S0014, send the drone's preset temporary access plan to the target backend.

4. The data processing method for user authentication of unmanned aerial vehicles according to claim 3, characterized in that, After identifying the factors that caused the drone's initial identity verification to fail, the following are also included: Send drone-related information and the reasons for the drone's initial identity authentication failure to the target backend. The drone-related information includes at least the drone ID.

5. The data processing method for user authentication of unmanned aerial vehicles according to claim 4, characterized in that, S002 also includes: If the secondary authentication fails, the target backend will send the drone's relevant information to the intermediate backend.

6. The data processing method for user authentication of unmanned aerial vehicles according to claim 1, characterized in that, In S003, based on the encrypted transmission channel, the UAV transmits the encrypted target mission data to the target backend, and also includes: S100, in response to the received target task instruction, during the execution of the target task by the UAV, at preset time intervals, the encryption module mounted on the UAV reduces the resolution of the video data in the original sub-task data collected within the corresponding preset time interval to obtain intermediate sub-task data; wherein, the data collected by the UAV within a preset time interval is the original sub-task data corresponding to that preset time interval; the target task data consists of all the original sub-task data collected by the UAV during the execution of the target task; S200: After the encryption module encrypts the intermediate subtask data, the drone transmits the encrypted intermediate subtask data to the target backend via 4G / 5G through an encrypted transmission channel. Specifically, when the intermediate subtask data meets the first preset encryption condition, a symmetric encryption algorithm is used to encrypt the intermediate subtask data; when the intermediate subtask data meets the second preset encryption condition, an asymmetric encryption algorithm is used to encrypt the intermediate subtask data. The first preset encryption condition is different from the second preset encryption condition. S300: The target backend receives the encrypted intermediate subtask data, decrypts the encrypted intermediate subtask data, obtains the intermediate subtask data, processes the intermediate subtask data, and obtains the processing result. S400: After completing the target mission, the UAV returns to its nest and sends the target mission data to the nest; the target mission data consists of all the raw sub-task data collected by the UAV during the execution of the target mission. The S500 drone's pod transmits target mission data to the target backend. S600: The target backend receives the target task data and verifies the processing results based on the target task data.

7. The data processing method for user authentication of unmanned aerial vehicles according to claim 6, characterized in that, In S200, the encryption module encrypts intermediate subtask data and also includes: S210, obtain a list of symmetric encryption algorithm IDs and a list of asymmetric encryption algorithm IDs. The list of symmetric encryption algorithm IDs includes IDs of several symmetric encryption algorithms, and the list of asymmetric encryption algorithm IDs includes IDs of several asymmetric encryption algorithms. Both the symmetric encryption algorithms and the asymmetric encryption algorithms are marked with low-priority tags or high-priority tags. S220, Based on the first preset encryption conditions and the video data in the intermediate subtask data, determine the processing efficiency of the symmetric encryption algorithm for low-priority tags, and determine the symmetric encryption algorithm as the target symmetric encryption algorithm based on the processing efficiency. When the intermediate subtask data meets the first preset encryption condition, the target symmetric encryption algorithm is used to encrypt the intermediate subtask data. S230, Based on the second preset encryption conditions and the video data in the intermediate subtask data, determine the processing efficiency of the asymmetric encryption algorithm for low-priority tags, and determine the asymmetric encryption algorithm as the target asymmetric encryption algorithm based on the processing efficiency. When the intermediate subtask data meets the second preset encryption condition, the target asymmetric encryption algorithm is used to encrypt the intermediate subtask data.

8. The data processing method for user authentication of unmanned aerial vehicles according to claim 6, characterized in that, The S500 drone pod transmits target mission data to the target backend, and also includes: S510, Based on the encryption conditions of the target task data and the video data in the target task data, determine the processing efficiency of the symmetric encryption algorithm for high-priority tags, and based on the processing efficiency, determine the symmetric encryption algorithm for high-priority tags as the final symmetric encryption algorithm. S520, based on the encryption conditions of the target task data and the video data in the target task data, determine the processing efficiency of the asymmetric encryption algorithm for high-priority tags, and based on the processing efficiency, determine the asymmetric encryption algorithm for high-priority tags as the final asymmetric encryption algorithm; The S530 drone's nest encrypts target mission data based on a final symmetric encryption algorithm and a final asymmetric encryption algorithm, and then sends the encrypted target mission data to the target backend.

9. A non-transitory computer-readable storage medium, characterized in that, The storage medium stores a computer program, which is loaded and executed by a processor to implement the data processing method for user authentication of the UAV as described in any one of claims 1-8.

10. An electronic device, comprising: A processor, a memory, and a computer program stored in the memory and executable on the processor, characterized in that, when the processor executes the computer program, it implements the data processing method for user authentication of a UAV as described in any one of claims 1-8.

Citation Information

Patent Citations

  • Unmanned aerial vehicle queue identity authentication method

    CN110972132A

  • Verification information sending method and device

    CN116233832A