An unmanned aerial vehicle flight control and data transmission integrated security protection system

By constructing an integrated security protection system for UAV flight control and data transmission, and utilizing a dynamic trust assessment model and fuzzy logic fusion algorithm, the problem of collaborative attacks by UAVs in complex environments was solved, achieving proactive intelligent defense and integrated security assurance for the system.

CN121386871BActive Publication Date: 2026-05-08CIVIL AVIATION FLIGHT UNIV OF CHINA +1
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CIVIL AVIATION FLIGHT UNIV OF CHINA
Filing Date
2025-10-29
Publication Date
2026-05-08

AI Technical Summary

Technical Problem

When facing coordinated attacks in complex environments, existing unmanned aerial vehicle (UAV) systems struggle to provide unified protection for flight control and data transmission security, and are unable to proactively respond to attacks such as radio jamming and GPS spoofing, resulting in systemic security vulnerabilities.

Method used

An integrated security protection system for UAV flight control and data transmission is adopted, including a secure flight control module, a multi-link encrypted communication module, an environmental perception module, a hardware trust module, a ground-based decryption module, and a dynamic trust assessment module. Through a dynamic trust assessment model and a fuzzy logic fusion algorithm, the system security status is assessed in real time, and encryption algorithms and flight control strategies are dynamically switched to achieve multi-dimensional collaborative protection.

Benefits of technology

It enables real-time assessment of system security status and proactive intelligent defense, improving the overall security of drones in complex combat environments and providing integrated security protection from hardware to data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121386871B_ABST
    Figure CN121386871B_ABST
Patent Text Reader

Abstract

The application provides a UAV flight control and data transmission integrated security protection system, comprising a UAV terminal and a ground terminal, wherein the UAV terminal comprises: a secure flight control module for controlling UAV flight and executing safe flight instructions; a multi-link encrypted communication module for establishing encrypted data transmission with the ground terminal through multiple communication links; and an environment perception module for acquiring flight state, environment state and electromagnetic spectrum state data of the UAV. The application realizes real-time evaluation of the system security condition by constructing a dynamic trust evaluation model and combining multi-dimensional state information such as flight control, data transmission and environment perception, and changes passive protection to active intelligent defense. Through dynamic linkage regulation and control of key management, encryption algorithm switching and flight control strategy based on the same real-time trust value, the security units in the system realize collaborative protection, and the overall security of the UAV in a complex counter-environment is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of unmanned aerial vehicle (UAV) safety protection technology, and in particular to an integrated safety protection system for UAV flight control and data transmission. Background Technology

[0002] Unmanned aerial vehicle (UAV) technology has been widely used in military reconnaissance, logistics transportation, remote sensing and mapping, and its flight safety and data security are the core of ensuring mission success. Traditional UAV security protection often adopts a discrete design, with the flight control system focusing on flight attitude, route planning and obstacle avoidance, while data transmission security relies on independent encrypted communication modules. This independent architecture leads to fragmented UAV security strategies, making it unable to cope with increasingly complex coordinated attacks and resulting in systemic security shortcomings.

[0003] Existing technologies attempt to improve security at different levels, but limitations still exist. For example, the known authorized patent CN119937432A discloses a distributed remote control method and system for UAVs based on multi-source signal fusion. This invention solves the technical problems of insufficient positioning accuracy, weak anti-interference capability, and poor communication link stability of UAVs in existing technologies. It achieves the technical effect of high-precision positioning and anti-interference remote control of UAVs in complex environments through multi-source signal fusion, deception interference, distributed adaptive transmission, and encrypted communication technologies.

[0004] However, while this invention improves positioning accuracy and anti-interference capabilities through multi-source signal fusion, its optimization goals do not involve dynamic assessment of the overall security situation or feedback control of the control system. When dealing with coordinated attacks on flight control and data transmission, such as first cutting off communication through radio suppression and then hijacking GPS spoofing, it can only passively increase communication redundancy or switch links, and cannot solve security threats by actively adjusting flight strategies, resulting in a single protection method.

[0005] To address this, an integrated security protection system for UAV flight control and data transmission is proposed. Summary of the Invention

[0006] In view of this, the present invention provides an integrated security protection system for unmanned aerial vehicle (UAV) flight control and data transmission, in order to solve or alleviate one of the technical problems existing in the prior art, and at least provide a beneficial alternative.

[0007] The technical solution of this invention is implemented as follows: An integrated security protection system for UAV flight control and data transmission, comprising a UAV terminal and a ground terminal, wherein the UAV terminal includes:

[0008] The safety flight control module is used to control the drone's flight and execute safe flight commands;

[0009] A multi-link encrypted communication module is used to establish encrypted data transmission with the ground terminal through multiple communication links;

[0010] The environmental perception module is used to acquire data on the UAV's flight status, environmental status, and electromagnetic spectrum status.

[0011] The hardware trust module provides hardware-level secure storage and cryptographic operations, and verifies the integrity of the drone terminal system.

[0012] The ground end includes:

[0013] The decryption module is used to decrypt the received drone terminal data and encrypt the control commands to be sent.

[0014] The dynamic trust assessment module is used to receive and integrate decrypted UAV flight status, environmental status and electromagnetic spectrum status data, and calculate the real-time trust value through the assessment algorithm model.

[0015] The key management module is used to manage system keys;

[0016] An integrated monitoring module is used for system status monitoring and human-computer interaction;

[0017] The output of the dynamic trust evaluation module is connected to the control terminals of the key management module and the decryption module; the real-time trust value is used to dynamically trigger the key update strategy of the key management module, the encryption algorithm switching strategy of the decryption module, and send flight control strategy commands to the secure flight control module.

[0018] Further preferably, the multi-link encrypted communication module includes radio links, 4G / 5G cellular network links, and satellite communication links. The module also includes a link management unit for real-time monitoring of the signal quality, latency, and bandwidth of each link. Based on the real-time trust value output by the dynamic trust evaluation module, the unit executes a link switching strategy. This strategy involves automatically switching data transmission to a backup link when the signal-to-noise ratio of the current primary link falls below a preset threshold or the real-time trust value decreases. The multi-link encrypted communication module incorporates a hardware cryptographic acceleration chip to offload encryption and decryption operations, providing high-performance symmetric and asymmetric cryptographic support for various links.

[0019] The multi-link encrypted communication module supports data fragmentation transmission, dividing the data to be transmitted into several fragments and transmitting them in parallel to the ground terminal through different communication links, where the decryption module reassembles and decrypts them. The radio link employs anti-interference communication mechanisms, including but not limited to frequency hopping, direct sequence spread spectrum, or channel adaptive technology, to enhance robustness in complex electromagnetic environments. The satellite communication link uses Inmarsat, Iridium, or Tiantong satellite systems as an emergency backup communication method in areas without terrestrial network coverage. The 4G / 5G cellular network link supports APN private network access or VPN tunnel encryption, logically isolating it from public networks to ensure the privacy and security of data transmission.

[0020] Further preferred configuration: The safety flight control module includes a main flight controller, a coprocessor, an inertial measurement unit, a monitoring timer, and a data transmission interface. The main flight controller is a high-performance microcontroller (MCU) running a real-time operating system (RTOS), responsible for executing core flight control algorithms, including sensor data fusion, attitude calculation and control, navigation and waypoint tracking, and parsing safety commands from the ground. The coprocessor is an encryption chip dedicated to safety functions. The inertial measurement unit includes a gyroscope, an accelerometer, and a magnetometer. The monitoring timer is an independent timer circuit used to monitor the operating status of the main flight control MCU. If the MCU malfunctions or is attacked, causing program execution errors or a system crash, resulting in the monitoring timer not being refreshed within the timeout period, the monitoring timer will automatically trigger a forced system restart to restore the system to a known safe state. The transmission interface includes a sensor interface, an actuator interface, and a communication interface.

[0021] Further preferred: The evaluation algorithm used by the dynamic trust evaluation module is a fuzzy logic-based fusion algorithm. The real-time trust value is a continuously quantized value between 0 and 100%. The input variables of the fuzzy logic fusion algorithm include the spectrum anomaly degree and GPS positioning reliability from the environmental perception module, the link quality from the multi-link encrypted communication module, and the flight attitude deviation degree from the safety flight control module. The spectrum anomaly degree is determined by fuzzification by calculating the deviation between the signal-to-noise ratio in the monitoring frequency band and a preset threshold. The GPS positioning reliability is determined by fuzzification by comparing the difference between the positioning information output by the GPS module and the position calculated by the inertial navigation system. The evaluation algorithm has a built-in rule base containing several preset IF-THEN fuzzy rules, which are used to map the fuzzy set of input variables to the fuzzy set of output variables. The rule base introduces machine learning to assist in optimization.

[0022] Typical rules in the rule base include:

[0023] IF high spectrum anomaly AND low GPS positioning reliability THEN low trust value;

[0024] IF Low spectral anomaly AND High GPS positioning reliability THEN High confidence value;

[0025] IF poor link quality AND high flight attitude deviation THEN low trust value;

[0026] IF Good link quality AND low flight attitude deviation THEN High trust value;

[0027] IF Low spectrum anomaly AND High GPS positioning reliability AND Good link quality THEN High trust value;

[0028] IF high spectrum anomaly AND low GPS positioning reliability AND good link quality THEN low trust value.

[0029] The evaluation algorithm execution steps include:

[0030] Define 2-5 fuzzy sets for each input variable, and design a membership function for each fuzzy set to convert the input variable value into the membership degree of the corresponding fuzzy linguistic variable, with the value between 0 and 1;

[0031] Inference is performed based on the rule base to determine the activation intensity of each fuzzy set of the output variable. The inference process determines the degree of influence of each rule on the output, and the minimum operator is used to calculate the overall activation intensity of the rule. The calculated rule activation intensity is then used. It applies to the output fuzzy set of the THEN consequent of this rule;

[0032] The centroid method is used to convert the fuzzy set of inference output into real-time trust values;

[0033] Multiple potentially overlapping fuzzy subsets of output obtained after fuzzy inference are aggregated into a single precise numerical output, namely the real-time trust value T. The formula for calculating the output trust value T is as follows:

[0034]

[0035] Where N is the number of rules activated, α i c is the activation strength of the i-th rule. i It is the center value of the fuzzy set output by the i-th rule.

[0036] Further preferred: the flight control strategy commands include at least one of the following: triggering automatic return to home, switching to offline waypoint tracking mode, executing preset emergency evasive maneuvers, and limiting flight speed and altitude.

[0037] A further preferred embodiment: The encryption algorithm switching strategy of the decryption module refers to dynamically selecting the encryption strength among AES-128, AES-256 and SM4 national cryptographic algorithms based on the real-time trust value. The decryption module has a preset encryption algorithm strategy table that maps to the real-time trust value range. The key is updated at the same time as each algorithm switch to prevent the risk of cryptanalysis caused by the long-term use of the same key.

[0038] Further preferred: The hardware trust module is a trusted platform module or an embedded security element. The hardware trust module internally stores the identity certificate, asymmetric encryption private key, and symmetric encryption root key of the UAV terminal. The hardware trust module contains physically independent non-volatile memory, which is isolated from the main processor system and cannot be directly accessed through an external debugging interface to prevent the keys from being illegally extracted. The hardware trust module stores an X.509 digital certificate issued by the system's private CA, which is used for two-way authentication with the server when accessing the network to prevent the access of unauthorized nodes.

[0039] Further preferred: When the periodic integrity measurement of the hardware trust module detects that the firmware of the safety flight control module has been tampered with, or receives a remote recovery command from the ground based on a low trust value, the hardware trust module can control the safety flight control module to start from a preset safety backup partition to achieve system-level fault isolation and recovery.

[0040] Further preferred configuration: The environmental perception module includes a GNSS receiver, a barometer, an airspeed indicator, a visual sensor, a lidar, an ultrasonic sensor, a millimeter-wave radar, and a spectrum analysis unit. The GNSS receiver receives signals from the Global Navigation Satellite System, calculates and provides the UAV's absolute geographical location, altitude, ground velocity, and precise time information. The barometer measures the atmospheric pressure at its altitude, assisting in calculating and calibrating the UAV's relative altitude. The airspeed indicator measures the relative velocity of the UAV to the air using a pitot tube or differential pressure sensor. The visual sensor captures visible light or infrared image sequences. The lidar acquires high-precision three-dimensional point cloud data of the surrounding environment by emitting laser beams and receiving their reflections. The ultrasonic sensor performs short-range ranging by emitting and receiving ultrasonic waves. The millimeter-wave radar emits millimeter-wave radio waves and analyzes the echoes. The spectrum analysis unit consists of a software-defined radio front-end and a dedicated spectrum analysis chip, used to scan and monitor the electromagnetic spectrum of the frequency bands used by the UAV for remote control, image transmission, and navigation in real time. Its functions include detecting radio suppression, detecting abnormal signals, and evaluating link quality.

[0041] Further preferred: The human-machine interface of the integrated monitoring module integrates and displays the real-time trust value, the status of each link and the triggered security policies, and provides a port for manual confirmation or rejection of the system's automatic decision.

[0042] The embodiments of the present invention have the following advantages due to the adoption of the above technical solutions:

[0043] I. This invention constructs a dynamic trust assessment model, combining multi-dimensional state information such as flight control, data transmission, and environmental perception, to achieve real-time assessment of system security status, transforming passive protection into proactive intelligent defense.

[0044] Second, this invention enables collaborative protection among various security units in the system by dynamically linking and controlling key management, encryption algorithm switching, and flight control strategies based on the same real-time trust value, thereby improving the overall security of UAVs in complex adversarial environments.

[0045] Third, by introducing a hardware trust module as a security root and linking it with the ground terminal, this invention realizes the measurement and recovery of the integrity of the terminal system, and provides integrated security protection from hardware and software to data.

[0046] The above overview is for illustrative purposes only and is not intended to be limiting in any way. In addition to the illustrative aspects, embodiments, and features described above, further aspects, embodiments, and features of the invention will become readily apparent from the accompanying drawings and the following detailed description. Attached Figure Description

[0047] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0048] Figure 1 This is a system structure diagram of the present invention;

[0049] Figure 2 This is a flowchart illustrating the safety protection process of the present invention. Detailed Implementation

[0050] The embodiments of this disclosure will now be described in detail with reference to the accompanying drawings.

[0051] It should be understood that the following specific examples illustrate the implementation of this disclosure, and those skilled in the art can easily understand other advantages and effects of this disclosure from the content disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of this disclosure, and not all of them. This disclosure can also be implemented or applied through other different specific implementation methods, and the details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of this disclosure. It should be noted that, in the absence of conflict, the following embodiments and features in the embodiments can be combined with each other. Based on the embodiments in this disclosure, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this disclosure.

[0052] It should be noted that various aspects of embodiments within the scope of the appended claims are described below. It will be apparent that the aspects described herein can be embodied in a wide variety of forms, and any particular structure and / or function described herein is merely illustrative. Based on this disclosure, those skilled in the art will understand that one aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number of aspects set forth herein can be used to implement the device and / or practice the method. Additionally, this device and / or method can be implemented using structures and / or functionalities other than one or more of the aspects set forth herein.

[0053] Furthermore, specific details are provided in the following description to facilitate a thorough understanding of the examples. However, those skilled in the art will understand that the described aspects can be practiced without these specific details.

[0054] Example 1

[0055] like Figure 1 As shown, this embodiment of the invention provides an integrated security protection system for unmanned aerial vehicle (UAV) flight control and data transmission, including a UAV terminal and a ground terminal. The UAV terminal includes:

[0056] The safety flight control module is used to control the drone's flight and execute safe flight commands;

[0057] A multi-link encrypted communication module is used to establish encrypted data transmission with the ground terminal through multiple communication links;

[0058] The environmental perception module is used to acquire data on the UAV's flight status, environmental status, and electromagnetic spectrum status.

[0059] The hardware trust module provides hardware-level secure storage and cryptographic operations, and verifies the integrity of the terminal system.

[0060] The ground end includes:

[0061] The decryption module is used to decrypt the received drone terminal data and encrypt the control commands to be sent.

[0062] The dynamic trust assessment module is used to receive and integrate decrypted UAV flight status, environmental status and electromagnetic spectrum status data, and calculate the real-time trust value through the assessment algorithm model.

[0063] The key management module is used to manage system keys;

[0064] An integrated monitoring module is used for system status monitoring and human-computer interaction;

[0065] The output of the dynamic trust evaluation module is connected to the control terminals of the key management module and the decryption module; the real-time trust value is used to dynamically trigger the key update strategy of the key management module, the encryption algorithm switching strategy of the decryption module, and to send flight control strategy commands to the safe flight control module.

[0066] In this embodiment, a collaborative security protection system for unmanned aerial vehicles (UAVs) is constructed with a dynamic trust assessment module at its core. The UAV terminal's environmental perception, safe flight control, multi-link communication, and hardware trust modules continuously collect flight status, environmental information, and electromagnetic spectrum data, and transmit them to the ground terminal in encrypted form. After decryption at the ground terminal, the dynamic trust assessment module combines the multi-source data and calculates a quantified trust value in real time using a fuzzy inference algorithm. This value serves as a unified command signal, dynamically triggering the key management module to update the key, the decryption module to switch encryption algorithms, and sending tiered flight commands to the UAV safe flight control module.

[0067] In this embodiment, specifically: the multi-link encrypted communication module includes radio links, 4G / 5G cellular network links, and satellite communication links. The multi-link encrypted communication module also includes a link management unit for real-time monitoring of the signal quality, latency, and bandwidth of each link. Based on the real-time trust value output by the dynamic trust evaluation module, it executes a link switching strategy. The switching strategy is that when the signal-to-noise ratio of the current primary link is detected to be lower than a preset threshold or the real-time trust value decreases, the link management unit automatically switches data transmission to a backup link. The multi-link encrypted communication module has a built-in hardware cryptographic acceleration chip to offload encryption and decryption operations, providing high-performance symmetric and asymmetric cryptographic operation support for various links. Differentiated two-way authentication mechanisms can be adopted for different links. In this embodiment, the satellite link uses certificate-based strong authentication, while the local radio link can use lightweight symmetric key authentication to adapt to the resource constraints and security requirements of different links.

[0068] The multi-link encrypted communication module supports data fragmentation transmission mode, which can divide the data to be transmitted into several fragments and transmit them in parallel to the ground end through different communication links, where the decryption module reassembles and decrypts them. Under normal conditions, the system assigns different data streams to appropriate links. For example, control commands are sent through low-latency radio links, high-definition video streams are transmitted through high-bandwidth 4G / 5G links, and health status information is backed up through satellite links. When the system is attacked, the link identified as untrusted is discontinued, and the tasks originally performed by the failed link are migrated to other healthy links.

[0069] The radio link design adheres to UAV communication standard protocols such as MAVLink, ensuring compatibility with existing ground control stations and infrastructure. It also employs anti-jamming communication mechanisms, including but not limited to frequency hopping, direct sequence spread spectrum, or channel adaptive techniques, to enhance robustness in complex electromagnetic environments. The satellite communication link utilizes Inmarsat, Iridium, or Tiantong satellite systems as an emergency backup communication method in areas without terrestrial network coverage. The 4G / 5G cellular network link supports APN private network access or VPN tunnel encryption, logically isolating it from public networks to ensure the privacy and security of data transmission.

[0070] In this embodiment, specifically: the safety flight control module includes a main flight controller, a coprocessor, an inertial measurement unit, a monitoring timer, and a data transmission interface. The main flight controller is a high-performance microcontroller (MCU) running a real-time operating system (RTOS), responsible for executing core flight control algorithms, including sensor data fusion, attitude calculation and control, navigation and waypoint tracking, and parsing safety commands from the ground. The coprocessor is an encryption chip dedicated to safety functions. The inertial measurement unit includes a gyroscope, an accelerometer, and a magnetometer. The monitoring timer is an independent timer circuit used to monitor the operating status of the main flight control MCU. If the MCU malfunctions or is attacked, causing program execution errors or a system crash, resulting in the monitoring timer not being refreshed within the timeout period, the monitoring timer will automatically trigger a forced system restart to restore the system to a known safe state. The data transmission interface includes a sensor interface, an actuator interface, and a communication interface. Other modules are also equipped with transmission interfaces as needed.

[0071] The main flight control MCU and the coprocessor are connected via an SPI bus and follow a secure communication protocol. Upon receiving flight control commands from the ground, the main MCU does not execute them immediately. Instead, it sends the command and its digital signature to the coprocessor. The coprocessor uses its internally stored certificate and key to verify the legitimacy of the command signature. If the command is deemed legitimate, the coprocessor returns an execution permission signal to the main MCU. Upon receiving the permission, the main MCU writes the command into the flight control execution queue. For commands requiring high security levels, such as switching to offline mode or performing emergency maneuvers, the coprocessor additionally requests the main MCU to read the corresponding code segment from the flight control memory and perform real-time hash calculations to ensure the flight control code has not been tampered with, thus achieving dual verification of the command and the code.

[0072] In this embodiment, specifically: the dynamic trust evaluation module uses a fuzzy logic-based fusion algorithm. The real-time trust value is a continuously quantized value between 0 and 100%. The input variables of the fuzzy logic fusion algorithm include the spectrum anomaly and GPS positioning reliability from the environmental perception module, the link quality from the multi-link encrypted communication module, and the flight attitude deviation from the safety flight control module. The spectrum anomaly is determined by fuzzifying the deviation between the signal-to-noise ratio in the monitoring frequency band and a preset threshold. The GPS positioning reliability is determined by fuzzifying the difference between the positioning information output by the GPS module and the position calculated by the inertial navigation system. The evaluation algorithm has a built-in rule base containing several preset IF-THEN fuzzy rules, which are used to map the fuzzy set of input variables to the fuzzy set of output variables. The rule base introduces machine learning to assist in optimization.

[0073] Typical rules in the rule base include:

[0074] IF high spectrum anomaly AND low GPS positioning reliability THEN low trust value;

[0075] IF Low spectral anomaly AND High GPS positioning reliability THEN High confidence value;

[0076] IF poor link quality AND high flight attitude deviation THEN low trust value;

[0077] IF Good link quality AND low flight attitude deviation THEN High trust value;

[0078] IF Low spectrum anomaly AND High GPS positioning reliability AND Good link quality THEN High trust value;

[0079] IF high spectrum anomaly AND low GPS positioning reliability AND good link quality THEN low trust value.

[0080] The evaluation algorithm execution steps include:

[0081] Define 2-5 fuzzy sets for each input variable, and design a membership function for each fuzzy set to convert the input variable value into the membership degree of the corresponding fuzzy linguistic variable, with the value between 0 and 1;

[0082] Inference is performed based on the rule base to determine the activation intensity of each fuzzy set of the output variable. The inference process determines the degree of influence of each rule on the output, and the minimum operator is used to calculate the overall activation intensity of the rule. The calculated rule activation intensity is then used. It applies to the output fuzzy set of the THEN consequent of this rule;

[0083] The centroid method is used to convert the fuzzy set of inference output into real-time trust values;

[0084] Multiple potentially overlapping fuzzy subsets of output obtained after fuzzy inference are aggregated into a single precise numerical output, namely the real-time trust value T. The formula for calculating the output trust value T is as follows:

[0085]

[0086] Where N is the number of rules activated, α i c is the activation strength of the i-th rule. i It is the center value of the fuzzy set output by the i-th rule. For example, the center value of the low trust value set is defined as 25%, the center value of the medium trust value set is 50%, and the center value of the high trust value set is 85%.

[0087] In this embodiment, the specific flight control strategy commands include at least one of the following: triggering automatic return to home, switching to offline waypoint tracking mode, executing preset emergency evasive maneuvers, and limiting flight speed and altitude. All flight control strategy commands are digitally signed and verified by the coprocessor in the secure flight control module to ensure the authenticity and tamper-proof nature of the commands. After the commands are executed, the new status data of the UAV will be transmitted back to the ground-based dynamic trust assessment module as feedback information to evaluate the effectiveness of the strategy execution and calculate a new trust value.

[0088] In this embodiment, specifically: the encryption algorithm switching strategy of the decryption module refers to dynamically selecting the encryption strength among AES-128, AES-256 and SM4 national cryptographic algorithms based on the real-time trust value. The decryption module has a preset encryption algorithm strategy table that maps to the real-time trust value range. The key is updated at the same time as each algorithm switch to prevent the risk of cryptanalysis caused by the long-term use of the same key.

[0089] During algorithm switching, the ground-based key management module generates a new key and encrypts the new algorithm identifier and key using the old algorithm and key. This encrypted key is then sent to the UAV via the current link. Both communicating parties synchronously activate the new encryption algorithm and key at the agreed-upon next data packet sequence number or system clock cycle. The first data packet after the switch contains an encrypted confirmation message. Once both parties verify the message, the switch is officially completed. If confirmation fails, the system returns to the previous security state and issues an alarm. To address potential proactive attacks, the system supports an algorithm agility framework. The encryption algorithm types and their parameters in the policy table can be remotely configured and updated via the integrated ground-based monitoring module.

[0090] In this embodiment, specifically: the hardware trust module is a trusted platform module or an embedded security element. The hardware trust module internally stores the UAV terminal's identity certificate, asymmetric encryption private key, and symmetric encryption root key. The hardware trust module contains physically independent non-volatile memory, isolated from the main processor system, and cannot be directly accessed through external debugging interfaces, thereby preventing the keys from being illegally extracted. The hardware trust module stores the X.509 digital certificate issued by the system's private CA, which is used for two-way authentication with the server when accessing the network to prevent the access of unauthorized nodes. The hardware trust module is the starting point for all security functions of the system, providing an immutable hardware foundation for the three core functions of secure storage, cryptographic operations, and trusted measurement.

[0091] In this embodiment, specifically: when the periodic integrity measurement of the hardware trust module detects that the firmware of the safety flight control module has been tampered with, or when it receives a remote recovery command from the ground based on a low trust value, the hardware trust module can control the safety flight control module to start from a preset safety backup partition, thereby achieving system-level fault isolation and recovery.

[0092] In this embodiment, specifically: the environmental perception module includes a GNSS (Global Navigation Satellite System) receiver, a barometer, an airspeed meter, a visual sensor, a lidar, an ultrasonic sensor, a millimeter-wave radar, and a spectrum analysis unit. The GNSS receiver receives global navigation satellite system signals, calculates and provides the UAV's absolute geographical location, altitude, ground velocity, and precise time information. The barometer measures the atmospheric pressure at the current altitude to assist in calculating and calibrating the UAV's relative altitude. The airspeed meter measures the relative velocity of the UAV to the air using a pitot tube or differential pressure sensor. The visual sensor captures visible light or infrared image sequences. The lidar acquires high-precision three-dimensional point cloud data of the surrounding environment by emitting laser beams and receiving their reflections. The ultrasonic sensor performs short-range ranging by emitting and receiving ultrasonic waves. The millimeter-wave radar emits millimeter-wave radio waves and analyzes the echoes. The spectrum analysis unit consists of a software-defined radio front-end and a dedicated spectrum analysis chip, used to scan and monitor the electromagnetic spectrum of the remote control, image transmission, and navigation frequency bands used by the UAV in real time. Its functions include detecting radio suppression, detecting abnormal signals, and evaluating link quality.

[0093] In this embodiment, specifically: the human-machine interface of the integrated monitoring module integrates and displays real-time trust values, the status of each link, and the triggered security policies, and provides a port for manual confirmation or rejection of the system's automatic decision. The human-machine interface specifically includes a global situational view that graphically displays real-time trust values ​​in the form of a speedometer, a three-dimensional geographic view that displays the curve of the change in UAV position and trust value, and a subsystem details view of communication link status and security event list. The system has intelligent alarm and decision support functions, providing hierarchical alarms and handling suggestions.

[0094] like Figure 2 As shown, in this embodiment, the system receives four core input parameters:

[0095] Spectral anomaly of the environmental perception module: calculated by the deviation between the signal-to-noise ratio and the preset threshold within the monitored frequency band;

[0096] Reliability of GPS positioning in the environmental perception module: determined by comparing the difference between the GPS output and the position calculated by the inertial navigation system;

[0097] Multi-link encrypted communication module link quality: calculated based on signal strength, bit error rate, and latency;

[0098] Flight attitude deviation of the safety flight control module: quantified by the difference between the actual attitude and the expected attitude;

[0099] Each input parameter is converted into a membership degree of a fuzzy linguistic variable through a membership function μ(x), with a value between 0 and 1. Taking spectral anomaly as an example, its membership function can be defined as:

[0100]

[0101] Where d1 and d2 are preset thresholds, for example, preset d1=3dB, d2=6dB.

[0102] The system has a built-in rule base containing multiple IF-THEN rules, for example:

[0103] IF high spectrum anomaly AND low GPS positioning reliability THEN low trust value;

[0104] IF poor link quality AND high flight attitude deviation THEN low trust value;

[0105] IF low spectrum anomaly AND high GPS positioning reliability AND good link quality THEN high trust value

[0106] The activation strength α of each rule is calculated using the minimum operator. i :

[0107]

[0108] The accurate real-time trust value T is calculated using the centroid method:

[0109]

[0110] In this embodiment, when T≥80%, the drone maintains normal flight status and uses the standard encryption algorithm AES-128 to maintain the current communication link;

[0111] When 80% > T ≥ 65%, the encryption algorithm strength is increased, the encryption algorithm is upgraded to AES-256, the operator is prompted to pay attention and confirm, and periodic security checks are initiated.

[0112] When 65%>T≥50%, limit flight speed and altitude, switch to offline waypoint tracking mode, switch to backup communication link, and update session key;

[0113] When 50% > T ≥ 30%, automatic return to home is triggered, and the strongest encryption algorithm is activated;

[0114] When T < 30%, execute the preset emergency avoidance action, cut off non-critical data transmission, attempt to send the final status through the most reliable link, and prepare to start the system recovery procedure.

[0115] Example 2

[0116] like Figure 1 As shown, this embodiment of the invention provides an integrated security protection system for unmanned aerial vehicle (UAV) flight control and data transmission, including a UAV terminal and a ground terminal. The UAV terminal includes:

[0117] The safety flight control module is used to control the drone's flight and execute safe flight commands;

[0118] A multi-link encrypted communication module is used to establish encrypted data transmission with the ground terminal through multiple communication links;

[0119] The environmental perception module is used to acquire data on the UAV's flight status, environmental status, and electromagnetic spectrum status.

[0120] The hardware trust module provides hardware-level secure storage and cryptographic operations, and verifies the integrity of the terminal system.

[0121] The ground end includes:

[0122] The decryption module is used to decrypt the received drone terminal data and encrypt the control commands to be sent.

[0123] The dynamic trust assessment module is used to receive and integrate decrypted UAV flight status, environmental status and electromagnetic spectrum status data, and calculate the real-time trust value through the assessment algorithm model.

[0124] The key management module is used to manage system keys;

[0125] An integrated monitoring module is used for system status monitoring and human-computer interaction.

[0126] In this embodiment, at a certain moment, when the attacker first suppresses the drone's radio signal, cutting off its normal communication link with the ground control station, and then transmits a high-power GPS spoofing signal in an attempt to navigate the drone to a preset malicious location for hijacking, the spectrum analysis unit in the environmental perception module detects an abnormal spike in background noise power in the remote control and image transmission frequency bands, exceeding the normal threshold. This is determined to be radio suppression, and the spectrum anomaly index is set to a high level. Simultaneously, the GNSS receiver output shows the drone moving towards an unplanned waypoint. The inertial measurement unit in the safety flight control module detects actual acceleration and attitude changes that are physically inconsistent with the speed and position changes reported by GPS. The aforementioned multi-source data is encrypted and transmitted to the ground end via a backup link of the multi-link encrypted communication module. After the ground-end decryption module decrypts the data, it is sent to the dynamic trust assessment module. The fusion algorithm of this module calculates the input:

[0127] Spectral anomaly = High (Membership degree 0.9);

[0128] GPS positioning reliability = low (membership 0.95 based on IMU data comparison);

[0129] Link quality = poor (membership degree 0.8);

[0130] Flight attitude deviation = High (Membership degree 0.7);

[0131] According to the preset fuzzy rule base, the rules "IF high spectrum anomaly AND low GPS positioning reliability THEN low trust value" and "IF poor link quality AND high flight attitude deviation THEN low trust value" are activated.

[0132] Rule 1 activation intensity α1 = min(0.9, 0.95) = 0.9;

[0133] Rule 2: Activation intensity α2 = min(0.8, 0.7) = 0.7;

[0134] Rule 1 outputs a low-trust-value fuzzy set with a center value c1 of 15%, and Rule 2 outputs a low-trust-value fuzzy set with a center value c2 of 25%. Therefore:

[0135]

[0136] After comprehensive calculation by the dynamic trust assessment module, the output trust value T decreases in real time. Based on the trust value, the system automatically triggers the pre-set collaborative protection strategy.

[0137] Example 3

[0138] like Figure 1 As shown, this embodiment of the invention provides an integrated security protection system for unmanned aerial vehicle (UAV) flight control and data transmission, including a UAV terminal and a ground terminal. The UAV terminal includes:

[0139] The safety flight control module is used to control the drone's flight and execute safe flight commands;

[0140] A multi-link encrypted communication module is used to establish encrypted data transmission with the ground terminal through multiple communication links;

[0141] The environmental perception module is used to acquire data on the UAV's flight status, environmental status, and electromagnetic spectrum status.

[0142] The hardware trust module provides hardware-level secure storage and cryptographic operations, and verifies the integrity of the terminal system.

[0143] The ground end includes:

[0144] The decryption module is used to decrypt the received drone terminal data and encrypt the control commands to be sent.

[0145] The dynamic trust assessment module is used to receive and integrate decrypted UAV flight status, environmental status and electromagnetic spectrum status data, and calculate the real-time trust value through the assessment algorithm model.

[0146] The key management module is used to manage system keys;

[0147] An integrated monitoring module is used for system status monitoring and human-computer interaction.

[0148] When the drone is attacked, causing its real-time trust value to continuously decline, the collaborative protection strategy is gradually triggered. The decryption module and key management module work together to trigger an encryption algorithm switching strategy, switching from AES-128 to the SM4 national cryptographic algorithm and updating the session key to prevent attackers from exploiting the suppression gap for eavesdropping or injection. The multi-link encrypted communication module executes a link switching strategy, abandoning the suppressed main radio link and switching communication to the satellite communication backup link to attempt to restore a secure connection with the ground. The ground terminal sends a high-priority command to the drone's secure flight control module to switch to offline waypoint tracking mode through the newly established link. Upon receiving the command, the safety flight control module rejects the positioning information from the GPS receiver, switches to inertial navigation, and uses terrain reference navigation in conjunction with visual sensors and lidar. It then flies along the original route, leaving the currently deceived airspace. The integrated monitoring module interface issues an alarm and displays the attack, real-time trust value, and the protective measures taken by the drone. The operator can monitor the drone's attempted return path in real time. If the attacker tampers with the drone's flight control software, causing abnormal behavior, such as refusing to execute ground switching commands, the hardware trust module will detect the tampering and trigger a recovery process. Once the drone flies away from the suppression and deception area, the GPS signal returns to normal, the communication link quality recovers, the dynamic trust value is restored, the system deactivates the emergency state, and normal operation is resumed.

[0149] This invention constructs a dynamic trust assessment model, combining real-time status information from multiple dimensions such as flight control, data transmission, and environmental perception. It employs a fuzzy logic-based fusion algorithm to quantitatively analyze multi-source parameters such as spectrum anomaly, GPS positioning reliability, link quality, and flight attitude deviation, generating a continuous real-time trust value from 0 to 100%. This enables accurate assessment of the system's security status, changing the traditional single and passive protection mode and achieving early prediction and proactive intelligent defense against potential threats.

[0150] This invention establishes a collaborative protection mechanism by dynamically linking and controlling key management, encryption algorithm switching, and flight control strategies based on the same real-time trust value. When the trust value changes, the system automatically triggers response actions such as key updates, algorithm upgrades, and flight strategy adjustments, enabling independent security units in the system to form a whole. This achieves deep synergy between communication security, data security, and flight security, improving the overall survivability and mission reliability of UAVs in complex electromagnetic interference and coordinated attack environments.

[0151] This invention introduces a hardware trust module as a security root, providing hardware-based key storage, secure encryption, and trust measurement capabilities at the UAV terminal. It also integrates with a ground-based evaluation system to continuously verify the integrity of the flight control system during startup and operation. Upon detection of tampering or receipt of a ground recovery command, remote authorization can be granted to boot from the secure backup partition, enabling self-repair and fault isolation of the UAV terminal and constructing an integrated hardware and software security system.

[0152] It should be noted that the various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.

[0153] The block diagrams of devices, apparatuses, devices, and systems disclosed herein are merely illustrative examples and are not intended to require or imply that they must be connected, arranged, or configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, devices, and systems can be connected, arranged, and configured in any manner. Words such as “comprising,” “including,” “having,” etc., are open-ended terms meaning “including but not limited to,” and are used interchangeably with them. The terms “or” and “and” as used herein refer to the terms “and / or,” and are used interchangeably with them unless the context clearly indicates otherwise. The term “such as” as used herein refers to the phrase “such as but not limited to,” and is used interchangeably with it.

[0154] It should also be noted that in the system disclosed herein, the components or steps can be decomposed and / or recombined. These decompositions and / or recombinations should be considered as equivalent solutions to this disclosure.

[0155] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any person skilled in the art can easily conceive of various variations or substitutions within the technical scope disclosed in the present invention, and these should all be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.

Claims

1. An integrated security protection system for unmanned aerial vehicle (UAV) flight control and data transmission, characterized in that, Includes a drone terminal and a ground terminal, wherein the drone terminal includes: The safety flight control module is used to control the drone's flight and execute safe flight commands; A multi-link encrypted communication module is used to establish encrypted data transmission with the ground terminal through multiple communication links; The environmental perception module is used to acquire data on the UAV's flight status, environmental status, and electromagnetic spectrum status. The hardware trust module provides hardware-level secure storage and cryptographic operations, and verifies the integrity of the drone terminal system. The ground end includes: The decryption module is used to decrypt the received drone terminal data and encrypt the control commands to be sent. The dynamic trust assessment module is used to receive and integrate decrypted UAV flight status, environmental status and electromagnetic spectrum status data, and calculate the real-time trust value through the assessment algorithm model. The key management module is used to manage system keys; An integrated monitoring module is used for system status monitoring and human-computer interaction; The output of the dynamic trust evaluation module is connected to the control terminals of the key management module and the decryption module, and the real-time trust value is used to dynamically trigger security protection strategies. The dynamic trust assessment module uses a fuzzy logic-based fusion algorithm. The real-time trust value is a continuously quantized value between 0 and 100%. The input variables of the fuzzy logic fusion algorithm include the spectrum anomaly degree and GPS positioning reliability from the environmental perception module, the link quality from the multi-link encrypted communication module, and the flight attitude deviation from the safety flight control module. The assessment algorithm has a built-in rule base containing several preset IF-THEN fuzzy rules, which are used to map the fuzzy set of input variables to the fuzzy set of output variables.

2. The integrated security protection system for UAV flight control and data transmission according to claim 1, characterized in that, The links of the multi-link encrypted communication module include radio links, 4G / 5G cellular network links and satellite communication links. The multi-link encrypted communication module includes a link management unit, which is used to monitor the signal quality, latency and bandwidth of each link in real time, and execute link switching strategies based on the real-time trust value output by the dynamic trust evaluation module.

3. The integrated security protection system for UAV flight control and data transmission according to claim 1, characterized in that, The safety flight control module includes a main flight controller, a coprocessor, an inertial measurement unit, and a monitoring timer.

4. The integrated security protection system for UAV flight control and data transmission according to claim 1, characterized in that, The evaluation algorithm execution steps include: Convert the input variable values ​​into the membership degrees of the corresponding fuzzy linguistic variables; Reasoning is performed based on the rule base to determine the activation strength of each fuzzy set of the output variable; The centroid method is used to convert the fuzzy set of inference output into real-time trust values; The formula for calculating the output trust value T is: Where N is the number of rules activated, α i c is the activation strength of the i-th rule. i It is the center value of the fuzzy set output by the i-th rule.

5. The integrated security protection system for UAV flight control and data transmission according to claim 1, characterized in that, Flight control strategy commands include at least one of the following: triggering automatic return to home, switching to offline waypoint tracking mode, executing preset emergency evasive maneuvers, and limiting flight speed and altitude.

6. The integrated security protection system for UAV flight control and data transmission according to claim 1, characterized in that, The encryption algorithm switching strategy of the decryption module refers to dynamically selecting the encryption strength among AES-128, AES-256 and SM4 national cryptographic algorithms based on the real-time trust value. The decryption module has a preset encryption algorithm strategy table that maps to the real-time trust value range.

7. The integrated security protection system for UAV flight control and data transmission according to claim 1, characterized in that, The hardware trust module is a trusted platform module or an embedded security element. The hardware trust module internally stores the identity certificate, asymmetric encryption private key, and symmetric encryption root key of the drone terminal.

8. The integrated security protection system for UAV flight control and data transmission according to claim 1, characterized in that, The environmental perception module includes a GNSS receiver, barometer, airspeed meter, visual sensor, lidar, ultrasonic sensor, millimeter-wave radar, and spectrum analysis unit.

9. The integrated security protection system for UAV flight control and data transmission according to claim 1, characterized in that, The integrated monitoring module's human-machine interface displays the real-time trust value, the status of each link, and the triggered security policies, and provides a port for manual confirmation or rejection of the system's automatic decision.

Citation Information

Patent Citations

  • Distributed unmanned aerial vehicle remote control method and system based on multi-source signal fusion

    CN119937432A

  • Lightweight and privacy-protected trust evaluation method and system in unmanned aerial vehicle network

    CN114125728A

  • Unmanned aerial vehicle safety protection system and method, electronic equipment and storage medium

    CN120639444A