Unmanned aerial vehicle flight control and data transmission integrated safety protection system
By constructing an integrated security protection system for UAV flight control and data transmission, and combining dynamic trust assessment and fuzzy logic fusion algorithms, the problem of collaborative attacks by UAVs in complex environments has been solved, achieving proactive intelligent defense and integrated security assurance for the system.
Patent Information
- Application Number
- CN202511559264.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-29
- Publication Date
- 2026-01-23
- Estimated Expiration
- 2045-10-29
AI Technical Summary
When facing coordinated attacks in complex environments, existing unmanned aerial vehicle (UAV) systems struggle to provide unified protection for flight control and data transmission security, and are unable to proactively counter attacks such as radio jamming and GPS spoofing, resulting in systemic security vulnerabilities.
An integrated security protection system for UAV flight control and data transmission is adopted, including a secure flight control module, a multi-link encrypted communication module, an environmental perception module, a hardware trust module, a ground-based decryption module, and a dynamic trust assessment module. Through a dynamic trust assessment model and a fuzzy logic fusion algorithm, the system security status is assessed in real time, and encryption algorithms and flight control strategies are dynamically switched to achieve collaborative protection of each security unit.
It enables real-time assessment of system security status and proactive intelligent defense, improving the overall security of drones in complex combat environments and providing integrated security from hardware to data.
Smart Images

Figure CN121386871A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of unmanned aerial vehicle safety protection, and particularly relates to an unmanned aerial vehicle flight control and data transmission integrated safety protection system. BACKGROUND
[0002] Unmanned aerial vehicle technology has been widely used in military reconnaissance, logistics transportation, remote sensing and mapping, etc. Its flight safety and data safety are the core of ensuring task success. The safety protection of traditional unmanned aerial vehicles is mostly designed in a separate manner. The flight control system focuses on flight attitude, route planning and obstacle avoidance, while data transmission safety relies on an independent encryption communication module. This independent architecture leads to the division of unmanned aerial vehicle safety strategies and cannot cope with increasingly complex coordinated attacks, resulting in systematic safety shortfalls.
[0003] Existing technologies attempt to improve safety from different aspects, but still have limitations. For example, the known authorized patent CN119937432A discloses a multi-source signal fusion distributed unmanned aerial vehicle remote control method and system. This invention solves the technical problems of insufficient positioning accuracy, weak anti-interference ability and poor communication link stability in existing technologies, and achieves the technical effect of high-precision positioning and anti-interference remote control of unmanned aerial vehicles in complex environments through multi-source signal fusion, deception interference, distributed adaptive transmission and encryption communication technology.
[0004] However, this invention improves positioning accuracy and anti-interference ability through multi-source signal fusion, but its optimization target does not involve dynamic assessment of overall safety status and feedback control of the control system. In response to coordinated attacks on flight control and data transmission, such as cutting off communication through radio suppression and then hijacking through GPS deception, it can only passively improve communication redundancy or switch links, and cannot solve safety threats by actively adjusting flight strategies, resulting in single protection means.
[0005] Therefore, an unmanned aerial vehicle flight control and data transmission integrated safety protection system is proposed. SUMMARY
[0006] Therefore, the present application provides an unmanned aerial vehicle flight control and data transmission integrated safety protection system to solve or alleviate one of the technical problems in the prior art, at least providing a beneficial choice.
[0007] The technical solution of the embodiment of the present application is as follows: An unmanned aerial vehicle flight control and data transmission integrated safety protection system includes an unmanned aerial vehicle terminal and a ground terminal. The unmanned aerial vehicle terminal includes:
[0008] A safety flight control module is used to control unmanned aerial vehicle flight and execute safety flight instructions.
[0009] A multi-link encrypted communication module is configured to establish encrypted data transmission with a ground terminal through multiple communication links;
[0010] An environment perception module is configured to acquire flight state, environment state and electromagnetic spectrum state data of the UAV;
[0011] A hardware trust module is configured to provide hardware-level secure storage and cryptographic operation, and verify integrity of the UAV terminal system;
[0012] The ground terminal comprises:
[0013] A decryption module is configured to decrypt received UAV terminal data and encrypt control instructions to be sent;
[0014] A dynamic trust evaluation module is configured to receive and fuse decrypted UAV flight state, environment state and electromagnetic spectrum state data, and calculate real-time trust values through an evaluation algorithm model;
[0015] A key management module is configured to manage system keys;
[0016] An integrated monitoring module is configured to monitor system state and interact with a human;
[0017] An output end of the dynamic trust evaluation module is connected to control ends of the key management module and the decryption module; the real-time trust values are used to dynamically trigger a key update strategy of the key management module, an encryption algorithm switching strategy of the decryption module, and flight control strategy instructions sent to the secure flight control module.
[0018] Further preferably, the links of the multi-link encrypted communication module comprise radio links, 4G / 5G cellular network links and satellite communication links, the multi-link encrypted communication module further comprises a link management unit configured to monitor signal quality, delay and bandwidth of each link in real time, and execute a link switching strategy based on the real-time trust values output by the dynamic trust evaluation module; when it is monitored that a signal-to-noise ratio of a currently used link is lower than a preset threshold or the real-time trust value decreases, the link management unit automatically switches data transmission to a backup link. The multi-link encrypted communication module is built-in with a hardware cryptographic acceleration chip configured to offload encryption and decryption operation, and provide high-performance symmetric and asymmetric cryptographic operation support for multiple links.
[0019] The multi-link encrypted communication module supports a data fragmentation transmission mode, can split the data to be transmitted into a plurality of fragments, and transmit the fragments in parallel to the ground terminal through different communication links for recombination and decryption by a decryption module. The radio link adopts an anti-interference communication system, including but not limited to frequency hopping, direct sequence spread spectrum or channel adaptive technology, to enhance the robustness in a complex electromagnetic environment. The satellite communication link adopts a maritime satellite, Iridium or Tianhong satellite system as an emergency backup communication means in areas without ground network coverage. The 4G / 5G cellular network link supports APN private network access or VPN tunnel encryption, which is logically isolated from the public network to ensure the privacy and security of data transmission.
[0020] Further preferably, the secure flight control module includes a main flight controller, a coprocessor, an inertial measurement unit, a monitoring timer, and a data transmission interface. The main flight controller is a high-performance microcontroller (MCU), and the main flight controller runs a real-time operating system (RTOS) and is responsible for executing flight control core algorithms, including sensor data fusion, attitude calculation and control, navigation and waypoint tracking, and analyzing safety instructions from the ground. The coprocessor is a cryptographic chip dedicated to safety functions. The inertial measurement unit includes a gyroscope, an accelerometer, and a magnetometer. The monitoring timer is an independent timer circuit for monitoring the running state of the main flight control MCU. If the MCU program execution is incorrect or dead due to failure or attack, the monitoring timer cannot be refreshed within the timeout period, and the monitoring timer will automatically trigger a system forced restart to restore to a known safe state. The transmission interface includes a sensor interface, an actuator interface, and a communication interface.
[0021] Further preferably, the dynamic trust evaluation module adopts a fuzzy logic-based fusion algorithm, and the real-time trust value is a continuous quantitative value between 0 and 100%. The input variables of the fuzzy logic fusion algorithm include the spectrum anomaly degree from the environment perception module, the GPS positioning reliability, the link quality from the multi-link encrypted communication module, and the flight attitude deviation degree from the secure flight control module. The spectrum anomaly degree is determined by fuzzification based on the deviation of the signal-to-noise ratio in the monitored frequency band from the preset threshold. The GPS positioning reliability is determined by fuzzification based on the difference between the positioning information output by the GPS module and the position calculated by the inertial navigation system. The evaluation algorithm has a built-in rule base containing a plurality of preset IF-THEN fuzzy rules for mapping the fuzzy sets of the input variables to the fuzzy sets of the output variables, and the rule base is introduced into machine learning for auxiliary optimization.
[0022] Typical rules in the rule base are as follows:
[0023] IF the spectrum anomaly degree is high AND the GPS positioning reliability is low THEN the trust value is low.
[0024] IF spectrum anomaly degree low AND GPS positioning credibility high THEN trust value high;
[0025] IF link quality poor AND flight attitude deviation degree high THEN trust value low;
[0026] IF link quality good AND flight attitude deviation degree low THEN trust value high;
[0027] IF spectrum anomaly degree low AND GPS positioning credibility high AND link quality good THEN trust value high;
[0028] IF spectrum anomaly degree high AND GPS positioning credibility low AND link quality good THEN trust value low.
[0029] The evaluation algorithm execution steps include:
[0030] Defining 2-5 fuzzy sets for each input variable, designing membership functions for each fuzzy set, and converting input variable values into membership degrees of corresponding fuzzy language variables, which are between 0 and 1;
[0031] According to the rule base, the activation strength of each fuzzy set of the output variable is determined, the inference process determines the influence degree of each rule on the output, and a minimum operator is used to calculate the overall activation strength of the rule, and the calculated rule activation strength acts on the output fuzzy set of the THEN back of the rule;
[0032] The barycenter method is used to convert the fuzzy set output by the inference into a real-time trust value;
[0033] The multiple possible overlapping output fuzzy subsets obtained after fuzzy inference are aggregated into a single accurate numerical output, i.e., a real-time trust value T, and the calculation formula of the output trust value T is:
[0034]
[0035] Wherein, N is the number of activated rules, α i is the activation strength of the ith rule, c i is the center value of the output fuzzy set of the ith rule.
[0036] Further preferably, the flight control strategy instruction includes at least one of the following: triggering automatic return, switching to an offline waypoint tracking mode, executing a preset emergency avoidance action, and limiting flight speed and height.
[0037] Further preferably, the encryption algorithm switching strategy of the decryption module refers to dynamically selecting encryption strength among AES-128, AES-256 and SM4 national encryption algorithm according to the real-time trust value, and a preset encryption algorithm strategy table corresponding to the real-time trust value interval is stored in the decryption module, and the encryption algorithm is switched and the key is updated each time to prevent the risk of cryptanalysis caused by long-term use of the same key.
[0038] Further preferably, the hardware trust module is a trusted platform module or an embedded secure element, and the hardware trust module internally stores the identity certificate, asymmetric encryption private key and symmetric encryption root key of the UAV terminal. The hardware trust module internally contains a physically independent non-volatile memory, which is isolated from the main processor system and cannot be directly accessed through an external debugging interface to prevent illegal extraction of the key. The hardware trust module stores an X.509 digital certificate issued by a private CA of the system, which is used for bidirectional authentication with the server when accessing the network to prevent access of illegal nodes.
[0039] Further preferably, when the periodic integrity measurement of the hardware trust module discovers that the firmware of the safety flight control module is tampered with or a remote recovery instruction is received from the ground end based on a low trust value, the hardware trust module can control the safety flight control module to start from a preset safety backup partition to realize system-level fault isolation and recovery.
[0040] Further preferably, the environment perception module includes a GNSS receiver, a barometer, an airspeed meter, a vision sensor, a laser radar, an ultrasonic sensor, a millimeter wave radar and a spectrum analysis unit. The GNSS receiver is used to receive global navigation satellite system signals, solve and provide the absolute geographic position, altitude, speed and precise time information of the UAV. The barometer is used to measure the atmospheric pressure at the height to assist in calculating and calibrating the relative altitude of the UAV. The airspeed meter is used to measure the relative speed of the UAV and the air through a pitot tube or a differential pressure sensor. The vision sensor is used to capture visible light or infrared image sequences. The laser radar is used to obtain high-precision three-dimensional point cloud data of the surrounding environment by emitting a laser beam and receiving its reflection. The ultrasonic sensor is used for short-range ranging by emitting and receiving ultrasonic waves. The millimeter wave radar is used to emit millimeter wave radio waves and analyze the echoes. The spectrum analysis unit is composed of a software-defined radio front end and a special spectrum analysis chip, which is used to scan and monitor the electromagnetic spectrum of the frequency bands used by the UAV for remote control, image transmission and navigation in real time. Its functions include detecting radio pressure, detecting abnormal signals and evaluating link quality.
[0041] Further preferably, the human-computer interaction interface of the integrated monitoring module integrates the display of the real-time trust value, the state of each link and the triggered safety strategy, and provides a port for manual confirmation or veto of the automatic decision of the system.
[0042] The embodiments of the present application have the following advantages due to the above technical solutions:
[0043] Firstly, the present application realizes real-time evaluation of system security condition by constructing a dynamic trust evaluation model and combining multi-dimensional state information such as flight control, data transmission and environment perception, and changes passive protection to active intelligent defense.
[0044] Secondly, the present application makes dynamic linkage control of key management, encryption algorithm switching and flight control strategy based on the same real-time trust value, so that each security unit in the system realizes collaborative protection and improves the overall security of the unmanned aerial vehicle in a complex counter-environment.
[0045] Thirdly, the present application introduces a hardware trust module as a security root and links with the ground end, realizes the measurement and recovery of terminal system integrity, and provides integrated security protection from hardware and software to data.
[0046] The above summary is only for the purpose of the description and is not intended to limit in any way. In addition to the above described illustrative aspects, embodiments and features, further aspects, embodiments and features will be readily apparent to those skilled in the art by reference to the drawings and the following detailed description. BRIEF DESCRIPTION OF DRAWINGS
[0047] In order to more clearly illustrate the technical solutions of the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings in the following description are only some embodiments of the present application, and those skilled in the art can obtain other drawings according to these drawings without any creative effort.
[0048] Figure 1 is a system structure diagram of the present application;
[0049] Figure 2 is a security protection flowchart of the present application. DETAILED DESCRIPTION
[0050] The embodiments of the present disclosure will be described in detail below with reference to the drawings.
[0051] It should be apparent that the following description illustrates by way of example only a full implementation of the disclosure. Based on the description given herein, a person of ordinary skill in the art will be aware of a variety of alternatives, adaptations and modifications of the specific implementational embodiments described that are within the scope of the present disclosure. Also, it is apparent that the described implementation is only a part of the implementation of the disclosure, and the disclosure can be implemented or applied by other different specific implementation. The details in the description can be modified based on different views and applications without departing from the spirit of the disclosure. It should be noted that the following embodiments and features in the embodiments can be combined with each other without conflict. Based on the embodiments in the disclosure, all other embodiments obtained by a person of ordinary skill in the art without creative labor are within the scope of protection of the disclosure.
[0052] It should be apparent that the following description illustrates by way of example only a full implementation of the disclosure. Based on the description given herein, a person of ordinary skill in the art will be aware of a variety of alternatives, adaptations and modifications of the specific implementational embodiments described that are within the scope of the present disclosure. Also, it is apparent that the described implementation is only a part of the implementation of the disclosure, and the disclosure can be implemented or applied by other different specific implementation. The details in the description can be modified based on different views and applications without departing from the spirit of the disclosure. It should be noted that the following embodiments and features in the embodiments can be combined with each other without conflict. Based on the embodiments in the disclosure, all other embodiments obtained by a person of ordinary skill in the art without creative labor are within the scope of protection of the disclosure.
[0053] In addition, in the following description, specific details are provided to facilitate a thorough understanding of the examples. However, one skilled in the art will understand that the described aspects can be practiced without these specific details.
[0054] Embodiment 1
[0055] As Figure 1 shown, the embodiment of the present application provides a UAV flight control and data transmission integrated security protection system, which comprises a UAV terminal and a ground terminal. The UAV terminal comprises:
[0056] a secure flight control module for controlling the flight of the UAV and executing a safe flight instruction;
[0057] a multi-link encrypted communication module for establishing encrypted data transmission with the ground terminal through multiple communication links;
[0058] an environment perception module for acquiring flight state, environment state and electromagnetic spectrum state data of the UAV;
[0059] a hardware trust module for providing hardware-level secure storage and cryptographic operation, and verifying the integrity of the terminal system;
[0060] The ground terminal comprises:
[0061] a decryption module for decrypting the received unmanned aerial vehicle terminal data and encrypting the control instructions to be sent;
[0062] a dynamic trust evaluation module for receiving and fusing the decrypted unmanned aerial vehicle flight state, environment state and electromagnetic spectrum state data, and calculating a real-time trust value through an evaluation algorithm model;
[0063] a key management module for managing system keys;
[0064] an integrated monitoring module for system state monitoring and man-machine interaction;
[0065] an output end of the dynamic trust evaluation module is connected with control ends of the key management module and the decryption module; the real-time trust value is used for dynamically triggering a key update strategy of the key management module, an encryption algorithm switching strategy of the decryption module, and sending flight control strategy instructions to the secure flight control module.
[0066] In this embodiment, the dynamic trust evaluation module is taken as the core to construct a cooperative security protection system for unmanned aerial vehicles. The environment perception, secure flight control, multi-link communication and hardware trust module of the unmanned aerial vehicle terminal continuously collect flight state, environment information and electromagnetic spectrum data, and encrypt and transmit the data to the ground terminal. After decryption by the ground terminal, the dynamic trust evaluation module combines the multi-source data, calculates a quantitative trust value in real time through a fuzzy inference algorithm, and uses the trust value as a unified command signal to dynamically trigger the key management module to update the keys, the decryption module to switch the encryption algorithm, and the secure flight control module of the unmanned aerial vehicle to send hierarchical flight instructions.
[0067] In this embodiment, specifically, the links of the multi-link encryption communication module include a radio link, a 4G / 5G cellular network link and a satellite communication link. The multi-link encryption communication module further comprises a link management unit for monitoring the signal quality, delay and bandwidth of each link in real time, and executing a link switching strategy based on the real-time trust value output by the dynamic trust evaluation module. The switching strategy is that when it is monitored that the signal-to-noise ratio of the current primary link is lower than a preset threshold or the real-time trust value decreases, the link management unit automatically switches the data transmission to a backup link. The multi-link encryption communication module is built-in with a hardware password acceleration chip for offloading encryption and decryption operations, and provides high-performance symmetric and asymmetric password operation support for multiple links. For different links, a differentiated bidirectional identity authentication mechanism can be used. In this embodiment, the satellite link uses a strong authentication based on a certificate, and the local radio link can use a lightweight symmetric key authentication to adapt to the resource constraints and security requirements of different links.
[0068] The multi-link encrypted communication module supports a data fragmentation transmission mode, can split the data to be transmitted into a plurality of fragments, and transmits the plurality of fragments to the ground end in parallel through different communication links, and the decrypted module recombines and decrypts. Under normal circumstances, the system allocates different data streams to appropriate links, for example, control instructions are sent through a low-delay radio link, high-definition video streams are transmitted through a high-bandwidth 4G / 5G link, and health status information is backed up through a satellite link, when the system is attacked, stop using the link identified as untrusted, and migrate the tasks originally undertaken by the faulty link to other healthy links.
[0069] The radio link design follows the unmanned aerial vehicle communication standard protocol such as MAVLink, ensures compatibility with existing ground control stations and infrastructure, and at the same time adopts anti-interference communication systems including but not limited to frequency hopping, direct sequence spread spectrum or channel adaptive technology to enhance robustness in complex electromagnetic environments. The satellite communication link adopts the maritime satellite, Iridium or Tianhong satellite system as an emergency backup communication means in areas without ground network coverage. The 4G / 5G cellular network link supports APN private network access or VPN tunnel encryption, which is logically isolated from the public network to ensure the privacy and security of data transmission.
[0070] In the embodiment, specifically, the secure flight control module includes a main flight controller, a coprocessor, an inertial measurement unit, a monitoring timer, and a data transmission interface. The main flight controller is a high-performance microcontroller (MCU), the main flight controller runs a real-time operating system (RTOS), is responsible for executing flight control core algorithms, including sensor data fusion, attitude calculation and control, navigation and waypoint tracking, and analyzing safety instructions from the ground. The coprocessor is an encryption chip dedicated to security functions. The inertial measurement unit includes a gyroscope, an accelerometer, and a magnetometer. The monitoring timer is an independent timer circuit for monitoring the running state of the main flight control MCU. If the MCU program execution is incorrect or dead due to failure or attack, the monitoring timer cannot be refreshed within the timeout period, and the monitoring timer will automatically trigger a system forced restart to restore to a known safe state. The data transmission interface includes a sensor interface, an actuator interface, and a communication interface. Other modules also have transmission interfaces according to requirements.
[0071] The main flight control MCU and the coprocessor are connected through an SPI bus and comply with a secure communication protocol. After receiving a flight control command from the ground, the main MCU does not execute the command immediately, but sends the command and its digital signature to the coprocessor. The coprocessor verifies the legality of the command signature using the certificates and keys stored in it, and returns an execution permission signal to the main MCU after confirming that it is a legal command. After receiving the execution permission, the main MCU writes the command into the flight control execution queue. For commands with high security levels such as switching to offline mode and executing emergency maneuvers, the coprocessor additionally requires the main MCU to read the corresponding code segment in the flight control memory and perform real-time hash calculation to ensure that the flight control code has not been tampered with, thereby achieving double verification of the command and code.
[0072] In this embodiment, specifically: the evaluation algorithm adopted by the dynamic trust evaluation module is a fuzzy logic fusion algorithm, and the real-time trust value is a continuous quantitative value between 0 and 100%. The input variables of the fuzzy logic fusion algorithm include the spectrum anomaly degree from the environment perception module, the GPS positioning reliability, the link quality from the multi-link encrypted communication module, and the flight attitude deviation degree from the secure flight control module. The spectrum anomaly degree is determined by fuzzification based on the deviation of the signal-to-noise ratio in the monitored frequency band from the preset threshold, and the GPS positioning reliability is determined by fuzzification based on the difference between the positioning information output by the GPS module and the position calculated by the inertial navigation system. The evaluation algorithm has a built-in rule base, which contains a number of preset IF-THEN fuzzy rules for mapping the fuzzy sets of input variables to the fuzzy sets of output variables, and the rule base is assisted by machine learning for optimization.
[0073] Typical rules in the rule base are, for example:
[0074] IF spectrum anomaly degree is high AND GPS positioning reliability is low THEN trust value is low;
[0075] IF spectrum anomaly degree is low AND GPS positioning reliability is high THEN trust value is high;
[0076] IF link quality is poor AND flight attitude deviation degree is high THEN trust value is low;
[0077] IF link quality is good AND flight attitude deviation degree is low THEN trust value is high;
[0078] IF spectrum anomaly degree is low AND GPS positioning reliability is high AND link quality is good THEN trust value is high;
[0079] IF spectrum anomaly degree is high AND GPS positioning reliability is low AND link quality is good THEN trust value is low.
[0080] The execution steps of the evaluation algorithm include:
[0081] 2-5 fuzzy sets are defined for each input variable, membership functions are designed for each fuzzy set, and the input variable value is converted into the membership of the corresponding fuzzy language variable, whose value is between 0 and 1;
[0082] According to the rule base, the activation strength of each fuzzy set of the output variable is determined, the inference process determines the influence degree of each rule on the output, a minimum operator is used to calculate the overall activation strength of the rule, and the calculated rule activation strength acts on the output fuzzy set of the THEN back of the rule;
[0083] The fuzzy set output by the inference is converted into a real-time trust value by using the barycenter method;
[0084] The multiple possible overlapping output fuzzy subsets obtained after fuzzy inference are aggregated into a single accurate numerical output, i.e., a real-time trust value T, and the calculation formula of the output trust value T is:
[0085]
[0086] wherein N is the number of activated rules, a i is the activation strength of the i th rule, c i is the center value of the output fuzzy set of the i th rule, for example, the center value of the low set of trust value is defined as 25%, the trust value is 50%, and the high trust value is 85%.
[0087] In this embodiment, specifically, the flight control strategy instruction includes at least one of the following: triggering automatic return, switching to an offline waypoint tracking mode, executing a preset emergency avoidance action, and limiting flight speed and height. All flight control strategy instructions are verified by a coprocessor in the safety flight control module through digital signature, to ensure that the instruction source is real and has not been tampered with. After the instruction is executed, the new state data of the unmanned aerial vehicle will be transmitted back to the ground end dynamic trust evaluation module as feedback information, to evaluate the strategy execution effect and calculate a new trust value.
[0088] In this embodiment, specifically: the encryption algorithm switching strategy of the decryption module dynamically selects the encryption strength between AES-128, AES-256 and SM4 national encryption algorithm according to the real-time trust value, and the decryption module is preconfigured with an encryption algorithm strategy table mapped with the real-time trust value interval. The key is updated each time the algorithm is switched, to prevent the risk of password analysis caused by long-term use of the same key.
[0089] During the algorithm switching process, the ground terminal key management module generates a new key, encrypts the new algorithm identifier and the new key using the old algorithm and the old key, and sends them to the UAV through the current link. The communication parties synchronize to use the new encryption algorithm and key at the agreed next data packet sequence number or system clock cycle. The first data packet after switching contains an encrypted confirmation information. After the parties verify the information, the switching is completed. If the verification fails, the system returns to the previous security state and issues an alarm. To cope with potential proactive attacks, the system supports an algorithm agility framework. The encryption algorithm type and its parameters in the policy table can be remotely configured and updated by the ground terminal integrated monitoring module.
[0090] In this embodiment, specifically, the hardware trust module is a trusted platform module or an embedded secure element. The hardware trust module internally stores the identity certificate of the UAV terminal, the asymmetric encryption private key, and the symmetric encryption root key. The hardware trust module internally contains a physically independent non-volatile memory that is isolated from the main processor system and cannot be directly accessed through an external debugging interface, thereby preventing the keys from being illegally extracted. The hardware trust module stores an X.509 digital certificate issued by a system private CA, which is used for bidirectional authentication with the server when accessing the network to prevent the access of illegal nodes. The hardware trust module is the starting point of all security functions of the system and provides an unalterable hardware basis for the three core functions of secure storage, cryptographic operation, and trust measurement.
[0091] In this embodiment, specifically, when the periodic integrity measurement of the hardware trust module discovers that the firmware of the secure flight control module is tampered with or a remote recovery instruction is received from the ground terminal based on a low trust value, the hardware trust module can control the secure flight control module to start from a preset secure backup partition, thereby realizing system-level fault isolation and recovery.
[0092] In this embodiment, specifically: the environment perception module includes a GNSS (Global Navigation Satellite System) receiver, a barometer, an airspeed indicator, a vision sensor, a laser radar, an ultrasonic sensor, a millimeter wave radar, and a spectrum analysis unit. The GNSS receiver is used to receive global navigation satellite system signals, calculate and provide the absolute geographic position, altitude, speed, and precise time information of the unmanned aerial vehicle. The barometer is used to measure the atmospheric pressure at the height to assist in calculating and calibrating the relative altitude of the unmanned aerial vehicle. The airspeed indicator is used to measure the relative speed of the unmanned aerial vehicle and the air through a pitot tube or a differential pressure sensor. The vision sensor is used to capture visible light or infrared image sequences. The laser radar is used to obtain high-precision three-dimensional point cloud data of the surrounding environment by emitting a laser beam and receiving its reflection. The ultrasonic sensor is used for short-range ranging by emitting and receiving ultrasonic waves. The millimeter wave radar is used to emit millimeter wave radio waves and analyze the echoes. The spectrum analysis unit is composed of a software-defined radio front end and a dedicated spectrum analysis chip, which is used to scan and monitor the electromagnetic spectrum of the remote control, image transmission, navigation, and other frequency bands used by the unmanned aerial vehicle in real time. Its functions include detecting radio interference, detecting abnormal signals, and evaluating link quality.
[0093] In this embodiment, specifically: the man-machine interface of the integrated monitoring module integrates the display of real-time trust values, link states, and triggered safety strategies, and provides a port for manual confirmation or veto of system automatic decisions. The man-machine interface specifically includes a global situation view that graphically displays real-time trust values in the form of a speedometer, a three-dimensional geographic view that displays the position of the unmanned aerial vehicle and the trust value change curve, and a subsystem detail view that displays the communication link state and safety event list. The system has intelligent alarm and decision support functions, providing hierarchical alarm and disposal suggestions.
[0094] As shown in Figure 2 In this embodiment, the system receives four core input parameters:
[0095] Spectrum anomaly degree of the environment perception module: calculated by monitoring the deviation of the signal-to-noise ratio in the frequency band from the preset threshold;
[0096] GPS positioning reliability of the environment perception module: determined by comparing the difference between the GPS output and the position calculated by the inertial navigation system;
[0097] Link quality of the multi-link encrypted communication module: calculated based on signal strength, bit error rate, and delay;
[0098] Flight attitude deviation of the safety flight control module: quantified by the difference between the actual attitude and the expected attitude;
[0099] Each input parameter is converted into the membership degree of the fuzzy language variable by the membership function μ(x), with a value between 0 and 1. Taking the spectrum anomaly degree as an example, its membership function can be defined as:
[0100]
[0101] wherein d1, d2 are preset threshold values, for example, preset d1 = 3dB, d2 = 6dB.
[0102] The system is built-in with a rule base containing multiple IF-THEN rules, for example:
[0103] IF spectrum abnormality degree is high AND GPS positioning credibility is low THEN trust value is low;
[0104] IF link quality is poor AND flight attitude deviation degree is high THEN trust value is low;
[0105] IF spectrum abnormality degree is low AND GPS positioning credibility is high AND link quality is good THEN trust value is high,
[0106] The minimum operator is used to calculate the activation strength α of each rule i :
[0107]
[0108] The barycenter method is used to calculate the accurate real-time trust value T:
[0109]
[0110] In the embodiment, when T≥80%, the normal flight state of the unmanned aerial vehicle is maintained, the standard encryption algorithm AES-128 is used, and the current communication link is maintained;
[0111] When 80%>T≥65%, the encryption algorithm strength is enhanced, the encryption algorithm is upgraded to AES-256, the operator is prompted to pay attention and confirm, and periodic security detection is started;
[0112] When 65%>T≥50%, the flight speed and height are limited, the offline waypoint tracking mode is switched to, the standby communication link is switched to, and the session key is updated;
[0113] When 50%>T≥30%, automatic return is triggered, and the strongest encryption algorithm is enabled;
[0114] When T<30%, the preset emergency avoidance action is executed, the non-critical data transmission is cut off, the final state is tried to be sent through the most reliable link, and the system recovery program is prepared to be started.
[0115] Embodiment 2
[0116] As shown in Figure 1 The embodiment of the application provides a flight control and data transmission integrated security protection system of an unmanned aerial vehicle, which comprises an unmanned aerial vehicle terminal and a ground terminal, and the unmanned aerial vehicle terminal comprises:
[0117] A safety flight control module for controlling the flight of the UAV and executing safety flight instructions;
[0118] A multi-link encrypted communication module for establishing encrypted data transmission with the ground terminal through multiple communication links;
[0119] An environment perception module for acquiring flight state, environment state and electromagnetic spectrum state data of the UAV;
[0120] A hardware trust module for providing hardware-level secure storage and cryptographic operations, and verifying the integrity of the terminal system;
[0121] The ground terminal comprises:
[0122] A decryption module for decrypting received UAV terminal data and encrypting control instructions to be sent;
[0123] A dynamic trust evaluation module for receiving and fusing the decrypted UAV flight state, environment state and electromagnetic spectrum state data, and calculating real-time trust values through an evaluation algorithm model;
[0124] A key management module for managing system keys;
[0125] An integrated monitoring module for system state monitoring and human-computer interaction.
[0126] In this embodiment, when an attacker first implements radio suppression on the UAV, cuts off the normal communication link between the UAV and the ground control station, and then transmits a high-power GPS spoofing signal to try to navigate the UAV to a pre-set malicious location for hijacking, the spectrum analysis unit in the environment perception module monitors the background noise power of the remote control and image transmission frequency band in real time, which abnormally rises and exceeds the normal threshold, and determines that the UAV is subjected to radio suppression, and sets the spectrum anomaly degree index to high. At the same time, the GNSS receiver outputs that the UAV is moving towards an unplanned waypoint, and the inertial measurement unit in the safety flight control module detects that the actual acceleration and attitude change do not match the speed and position change reported by the GPS in terms of physical logic. The above multi-source data is encrypted and transmitted to the ground terminal through the backup link of the multi-link encrypted communication module. After the ground terminal decryption module decrypts the data, it is sent to the dynamic trust evaluation module. The fusion algorithm of the module calculates the input:
[0127] Spectrum anomaly degree = high (membership degree 0.9);
[0128] GPS positioning credibility = low (membership degree 0.95 by comparing IMU data);
[0129] Link quality = poor (membership degree 0.8);
[0130] Flight attitude deviation = high (membership degree 0.7);
[0131] According to the preset fuzzy rule base, the rules "IF high degree of spectrum anomaly AND low credibility of GPS positioning THEN low trust value" and "IF poor link quality AND high degree of flight attitude deviation THEN low trust value" are activated.
[0132] The activation strength of rule 1 is a1 = min (0.9, 0.95) = 0.9;
[0133] The activation strength of rule 2 is a2 = min (0.8, 0.7) = 0.7;
[0134] The center value c1 of the low trust value fuzzy set output by rule 1 is 15%, and the center value c2 of the low trust value fuzzy set output by rule 2 is 25%, so:
[0135]
[0136] After the dynamic trust evaluation module is comprehensively calculated, the real-time trust value T is output to decrease, and the system automatically triggers the pre-set cooperative protection strategy according to the trust value.
[0137] Embodiment 3
[0138] As shown in Figure 1 The embodiment of the application provides a UAV flight control and data transmission integrated security protection system, which comprises a UAV terminal and a ground terminal.
[0139] A secure flight control module is used for controlling the flight of the UAV and executing a secure flight instruction.
[0140] A multi-link encrypted communication module is used for establishing encrypted data transmission with the ground terminal through multiple communication links.
[0141] An environment perception module is used for acquiring flight state, environment state and electromagnetic spectrum state data of the UAV.
[0142] A hardware trust module is used for providing hardware-level secure storage and cryptographic operation, and verifying the integrity of the terminal system.
[0143] The ground terminal comprises:
[0144] A decryption module is used for decrypting the received UAV terminal data and encrypting the control instruction to be sent.
[0145] A dynamic trust evaluation module is used for receiving and fusing the decrypted flight state, environment state and electromagnetic spectrum state data of the UAV, and calculating a real-time trust value through an evaluation algorithm model.
[0146] A key management module is used for managing system keys.
[0147] An integrated monitoring module is used for system state monitoring and human-computer interaction.
[0148] When the UAV is attacked and the real-time trust value continuously decreases, the cooperative protection strategy is gradually triggered, the decryption module and the key management module are linked, the encryption algorithm switching strategy is triggered, the encryption algorithm is switched from AES-128 to SM4 national encryption algorithm, and the session key is updated, so that the attacker cannot eavesdrop or inject through the suppression gap. The multi-link encryption communication module executes the link switching strategy, gives up the suppressed radio main link, switches the communication to the satellite communication backup link, and attempts to restore the secure connection with the ground. The ground end sends a high-priority switching to the offline waypoint tracking mode instruction to the safe flight control module of the UAV through the newly established link. After the safe flight control module receives the instruction, the positioning information from the GPS receiver is rejected, the inertial navigation is switched to, the terrain reference navigation is combined with the visual sensor and the laser radar, the original flight route is flown, the current spoofed airspace is escaped, and the integrated monitoring module interface is alarmed and displays the encountered attack, the real-time trust value and the protection measures taken by the UAV. The operator can monitor the UAV in real time to attempt the return path, if the attacker tampers with the UAV flight control software, so that the UAV behaves abnormally, for example, refuses to execute the switching instruction of the ground, the hardware trust module detects the tampering during operation, and triggers the recovery process. When the UAV flies away from the suppression and spoofing area, the GPS signal is restored to normal, the communication link quality is restored, the dynamic trust value is restored, the system is released from the emergency state, and the normal control is restored.
[0149] The application constructs a dynamic trust evaluation model, combines real-time state information from multiple dimensions such as flight control, data transmission and environment perception, adopts a fusion algorithm based on fuzzy logic to quantitatively analyze multi-source parameters such as spectrum abnormality, GPS positioning reliability, link quality and flight attitude deviation, generates a continuous real-time trust value of 0-100%, realizes accurate evaluation of the system safety state, changes the traditional single passive protection mode, and realizes early prediction and active intelligent defense of potential threats.
[0150] The application dynamically links and controls the key management, encryption algorithm switching and flight control strategy based on the same real-time trust value, establishes a cooperative protection mechanism. When the trust value changes, the system automatically triggers key update, algorithm upgrade and flight strategy adjustment, so that the independent security units in the system form a whole, realizes the deep cooperation of communication security, data security and flight safety, and improves the overall survivability and task reliability of the UAV in the complex electromagnetic interference and cooperative attack environment.
[0151] The application provides hardware-based key storage, secure encryption and trusted measurement capabilities in the UAV terminal by introducing a hardware trust module as a security root, and realizes continuous verification of the integrity of the flight control system during startup and operation by linking with the ground terminal evaluation system. After finding tampering or receiving ground recovery instructions, the UAV terminal can be remotely authorized to start from a secure backup partition, realizing self-repair and fault isolation of the UAV terminal, and building a hardware and software integrated security protection system.
[0152] It should be noted that each of the embodiments in the specification adopts a progressive manner for description, and each embodiment focuses on the difference from other embodiments, and the same and similar parts between each embodiment can be referred to each other.
[0153] The block diagrams of the devices, apparatuses, equipment, systems involved in the present disclosure are only exemplary examples and are not intended to require or imply the connection, arrangement, configuration as shown in the block diagram. As those skilled in the art will recognize, these devices, apparatuses, equipment, systems can be connected, arranged, configured in any manner. Words such as "include", "contain", "have" and the like are open-ended words, which mean "including but not limited to", and can be used interchangeably. The words "or" and "and" used herein mean the word "and / or", and can be used interchangeably unless the context clearly indicates otherwise. The word "such as" used herein means the phrase "such as but not limited to", and can be used interchangeably.
[0154] It should also be noted that in the system of the present disclosure, each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be considered as equivalent solutions of the present disclosure.
[0155] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto, and any skilled person in the art can easily think of various changes or replacements within the technical range disclosed by the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. An unmanned aerial vehicle flight control and data transmission integrated security protection system, characterized in that, The unmanned aerial vehicle terminal and the ground terminal are included, and the unmanned aerial vehicle terminal comprises: a secure flight control module for controlling the flight of the unmanned aerial vehicle and executing safe flight instructions; a multi-link encrypted communication module for establishing encrypted data transmission with the ground terminal through multiple communication links; an environment perception module for obtaining flight state, environment state and electromagnetic spectrum state data of the unmanned aerial vehicle; a hardware trust module for providing hardware-level secure storage and cryptographic operations, and verifying the integrity of the unmanned aerial vehicle terminal system; The ground terminal comprises: a decryption module for decrypting received unmanned aerial vehicle terminal data and encrypting control instructions to be sent; a dynamic trust evaluation module for receiving and fusing decrypted unmanned aerial vehicle flight state, environment state and electromagnetic spectrum state data, and calculating real-time trust values through an evaluation algorithm model; a key management module for managing system keys; an integrated monitoring module for system state monitoring and human-computer interaction; The output end of the dynamic trust evaluation module is connected to the control end of the key management module and the decryption module, and the real-time trust values are used to dynamically trigger security protection strategies.
2. The unmanned aerial vehicle flight control and data transmission integrated security protection system according to claim 1, wherein, The links of the multi-link encrypted communication module include radio links, 4G / 5G cellular network links and satellite communication links, and the multi-link encrypted communication module comprises a link management unit for real-time monitoring of signal quality, delay and bandwidth of each link, and executing link switching strategies based on real-time trust values output by the dynamic trust evaluation module.
3. The unmanned aerial vehicle flight control and data transmission integrated security protection system of claim 1, wherein, The secure flight control module comprises a main flight controller, a coprocessor, an inertial measurement unit and a monitoring timer.
4. The unmanned aerial vehicle flight control and data transmission integrated security protection system of claim 1, wherein, The evaluation algorithm used by the dynamic trust evaluation module is a fuzzy logic fusion algorithm, the real-time trust values are continuous quantitative values between 0 and 100%, the input variables of the fuzzy logic fusion algorithm include spectrum anomaly degree from the environment perception module, GPS positioning reliability, link quality from the multi-link encrypted communication module, and flight attitude deviation degree from the secure flight control module, the evaluation algorithm has a built-in rule base, and the rule base contains a plurality of preset IF-THEN fuzzy rules for mapping fuzzy sets of input variables to fuzzy sets of output variables.
5. The unmanned aerial vehicle flight control and data transmission integrated security protection system according to claim 4, characterized in that, The evaluation algorithm execution steps include: Converting input variable values to membership degrees of corresponding fuzzy language variables; Reasoning according to the rule base to determine the activation strength of each fuzzy set of the output variable; Using the barycentric method to convert the fuzzy set output by reasoning into a real-time trust value; The calculation formula of the output trust value T is: where N is the number of activated rules, a i is the activation strength of the ith rule, c i is the center value of the output fuzzy set of the ith rule.
6. The unmanned aerial vehicle flight control and data transmission integrated security protection system of claim 1, wherein, The flight control strategy instructions include at least one of the following: triggering automatic return, switching to offline waypoint tracking mode, executing preset emergency avoidance actions, and limiting flight speed and height.
7. The unmanned aerial vehicle flight control and data transmission integrated security protection system of claim 1, wherein, The encryption algorithm switching strategy of the decryption module dynamically selects encryption strength between AES-128, AES-256 and SM4 national encryption algorithms according to the real-time trust values, and the decryption module has a preset encryption algorithm strategy table mapped with the real-time trust value interval. 8.The UAV flight control and data transmission integrated security protection system of claim 1, wherein, The hardware trust module is a trusted platform module or an embedded secure element, and the hardware trust module internally stores an identity certificate of the UAV terminal, an asymmetric encryption private key, and a symmetric encryption root key.
9. The unmanned aerial vehicle flight control and data transmission integrated security protection system of claim 1, wherein, The environment perception module includes a GNSS receiver, a barometer, an air speed meter, a visual sensor, a laser radar, an ultrasonic sensor, a millimeter wave radar, and a spectrum analysis unit.
10. The unmanned aerial vehicle flight control and data transmission integrated security protection system of claim 1, wherein, The human-computer interaction interface of the integrated monitoring module integrates to display the real-time trust value, the state of each link, and the triggered security policy, and provides a port for manual confirmation or rejection of automatic decision of the system.
Citation Information
Patent Citations
Distributed unmanned aerial vehicle remote control method and system based on multi-source signal fusion
CN119937432A
Lightweight and privacy-protected trust evaluation method and system in unmanned aerial vehicle network
CN114125728A
Flight communication system of unmanned aerial vehicle with single Beidou module and flight control method thereof
CN119727876A
Unmanned control system dynamic key trust chain construction method based on Feiteng E2000TCM
CN120378874A
Anti-interference method, system and device for rotor unmanned aerial vehicle, and medium
CN120567535A