Low-altitude airspace authority authentication and management method and system based on block chain

By using blockchain technology for distributed data storage and authentication in the low-altitude airspace management system, the bottlenecks and security issues of centralized management are resolved, and efficient and reliable airspace access control is achieved.

CN121640771APending Publication Date: 2026-03-10JSTI GRP CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511813251.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-04
Publication Date
2026-03-10

AI Technical Summary

Technical Problem

Traditional centralized airspace management systems are prone to performance bottlenecks and single-point failure risks when dealing with massive, high-frequency, and multi-entity drone operations, and they also suffer from insufficient data security and management efficiency.

Method used

Using blockchain technology for low-altitude airspace access authentication and management, the system prevents data tampering, identifies plan conflicts, and tracks flight operations in real time by storing flight plan data stubs on different nodes of the blockchain, thus forming a distributed data processing and storage system.

Benefits of technology

It improves the efficiency and stability of low-altitude airspace management, avoids the problems of large data volume and security in centralized management, and ensures the integrity and reliability of data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121640771A_ABST
    Figure CN121640771A_ABST
Patent Text Reader

Abstract

The invention provides a block chain-based low-altitude airspace authority authentication and management method and system, and relates to the technical field of block chains. The method comprises the steps of collecting public shared data corresponding to different nodes, and performing clustering data storage to form block chain node shared stub data; obtaining plan application information, and performing authentication analysis in combination with block chain node sharing stub data to form authentication analysis result information; acquiring real-time flight data according to the authentication analysis result information, and performing monitoring analysis in combination with the plan application information to form real-time monitoring data; the real-time monitoring data are managed, information is managed, data records are extracted, and flight real-time record data are formed. According to the method, the high-efficiency management of the low-altitude airspace is realized by utilizing the advantages of the block chain, and the management capability is optimized.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of block chain, in particular to a low-altitude airspace permission authentication and management method and system based on block chain. BACKGROUND

[0002] With the gradual opening of low-altitude airspace, the number of low-altitude operations gradually increases, which also gradually brings pressure to the management of low-altitude airspace. The traditional centralized airspace management system is prone to performance bottlenecks and single-point failure risks when facing massive, high-frequency, multi-agent unmanned aerial vehicle operations.

[0003] The block chain technology is a block chain storage, tamper-proof, secure and trusted decentralized distributed ledger, which combines distributed storage, peer-to-peer transmission, consensus mechanism, cryptography and other technologies, records transactions and information through a growing data block chain, and ensures the security and transparency of data. If the block chain technology can be applied to the management of low-altitude airspace, the management capability and efficiency can be further optimized. However, how to establish a reasonable management system based on block chain is an important problem to be considered at present.

[0004] Therefore, it is an urgent problem to be solved to design a low-altitude airspace permission authentication and management method and system based on block chain, which uses the advantages of block chain to realize efficient management of low-altitude airspace and optimize the management capability. SUMMARY

[0005] The purpose of the present application is to provide a low-altitude airspace permission authentication and management method based on block chain, through the flight plan data disclosed by different nodes on the block chain, each node can stub the flight plan information on the entire block chain to avoid tampering with the plan data. Of course, different nodes manage the corresponding plan application information, and judge whether the applied plan conflicts with the existing plan based on the shared stub, and then ensure that the approved plan has no conflict. According to the time of plan execution, the discrete record data uploaded in real time by the flight operation is obtained to track whether the flight plan conforms to the real time, and to avoid the situation of deviating from the plan. After completing the aircraft operation, the data is stored on the corresponding node, and the shared data is provided to other nodes as a stub, which facilitates the tracing of record data on all nodes. The low-altitude airspace permission is authenticated and managed by using the block chain method, which can avoid the large amount of data, low data security and other situations caused by centralized management, on the one hand, and greatly improve the management efficiency and management capability, on the other hand, so that the data is more stable and reliable.

[0006] The application also aims to provide a low-altitude airspace permission authentication and management system based on a blockchain, which realizes distributed data processing and storage through different functional units on each node in the blockchain, the data acquisition unit completes the acquisition of flight data and corresponding application data and real-time flight data, the data storage unit stores shared data and monitoring data, the authentication analysis unit realizes authentication analysis on the proposed flight plan application, and the monitoring analysis unit is responsible for real-time data acquisition and monitoring of the authenticated flight plan, so that the different functional units form a complete data processing system of the node, which is a necessary material basis for realizing low-altitude airspace permission authentication and management, and the different nodes form a complete blockchain system, which ensures the integrity of the data and improves the management ability and efficiency, greatly improving the form of authentication and management.

[0007] In the first aspect, the application provides a low-altitude airspace permission authentication and management method based on a blockchain, which comprises the following steps: collecting public shared data corresponding to different nodes, performing cluster data storage, and forming shared stub data of the blockchain node; obtaining plan application information, combining the shared stub data of the blockchain node for authentication analysis, and forming authentication analysis result information; according to the authentication analysis result information, collecting real-time flight data, combining the plan application information for monitoring analysis, and forming real-time monitoring data; extracting and processing the management information of the real-time monitoring data for data recording, and forming flight real-time recording data.

[0008] In the application, the flight plan data disclosed by different nodes on the blockchain can be stored by each node to avoid tampering with the plan data. Of course, different nodes manage corresponding plan application information, and judge whether the applied plan conflicts with the existing plan based on the shared stub, so as to ensure that the approved plan has no conflict. According to the time of plan execution, the discrete recording data uploaded in real time by the flight operation is acquired to track whether the flight plan is consistent in real time, so as to avoid deviation from the plan. After completing the aircraft operation, the data is stored on the corresponding node, and shared data is provided to other nodes as a stub, so that the recording data can be traced on all nodes. The low-altitude airspace permission is authenticated and managed by using the blockchain, which can avoid the problems of large data volume and low data security caused by centralized management, and greatly improve the management efficiency and ability, so that the data is more stable and reliable.

[0009] As a possible implementation manner, the public sharing data corresponding to different nodes is collected, and cluster data storage is performed to form the blockchain node shared stub data, including: extracting public sharing authentication plans from the public sharing data to form a public sharing authentication plan set; extracting public sharing application plans from the public sharing data to form a public sharing application plan set; performing sequential clustering processing on the public sharing authentication plan set and the public sharing application plan set respectively to form the blockchain node shared stub data.

[0010] In the application, the aircraft plan data shared by different nodes in the blockchain needs to be stored on each node to provide comprehensive data reference for the corresponding flight plan authentication and management of the nodes. Of course, considering that these stored data are mainly used for flight plan authentication and management, it is necessary to consider the parameter information involved in authentication and management, so two data sets are distinguished, one is the aircraft plan that has completed the audit authentication, and the other is the flight plan that is being applied for authentication. It can be understood that for the aircraft plan that has completed the audit authentication, it is mainly used to provide authentication services for whether the flight plan being applied has plan content conflict, and the flight plan being applied for authentication not only needs to consider the conflict of plan content, but also needs to consider the time of application to apply first and authenticate first in order to perform authentication work, so as to avoid the confusion of application and authentication work. Therefore, the two different data sets need to be separated to avoid the confusion of the two data sets when referring to the two data sets later, which leads to the failure to carry out the application and authentication work.

[0011] As a possible implementation manner, the public sharing data corresponding to different nodes is collected, and cluster data storage is performed to form the blockchain node shared stub data, including: extracting public sharing authentication plans from the public sharing data to form a public sharing authentication plan set; extracting public sharing application plans from the public sharing data to form a public sharing application plan set; performing sequential clustering processing on the public sharing authentication plan set and the public sharing application plan set respectively to form the blockchain node shared stub data.

[0012] In the present application, the stub data of each node on the blockchain contains the flight plan data on the entire blockchain. Since the review and certification of whether the flight plan is complete has an impact on subsequent applications for new flight plans, it is necessary to cluster the stub data that has been certified and that has not been certified. At the same time, in order to facilitate efficient processing and analysis of the two types of flight plan data, it is necessary to reasonably and orderly cluster them. For certified flight plans, the important information is the time of occurrence and the corresponding involved area. For uncertified flight plans, the important information is the application time, followed by the plan time and the area involved in the application. Therefore, the two different types of flight plan data are sequentially clustered according to different important information points to form sequentially clustered data that can be efficiently referenced subsequently. It should be noted that the stub data mainly contains object identity information, application time, plan time, and involved area. On the one hand, these pieces of information can provide a complete reference for the targeted query of all nodes on the stub data, facilitating quick locking to data record nodes containing more rich information. At the same time, the simplicity of the stub data can avoid the increase in resource demand caused by the excessive storage of data by the nodes, thereby reducing unnecessary cost overhead.

[0013] As a possible implementation manner, the plan application information is acquired, the stub data shared by the blockchain nodes are combined for certification analysis, and certification analysis result information is formed, including: acquiring plan application information, extracting object encryption segments and flight plan encryption segments respectively; decrypting the extracted object encryption segments and flight plan encryption segments to form application object information and object flight plan information respectively; according to the stub data shared by the blockchain nodes, the object flight plan information is combined for certification analysis to form certification analysis result data.

[0014] In the present application, different nodes in the blockchain can handle flight plan applications filed by objects in different ranges, which can alleviate the pressure of centralized management and certification processing. In order to ensure the security of data uploading and information on the blockchain, the data is transmitted in an encrypted form. Therefore, it is necessary to first decrypt the filed flight plan application, extract the object and the corresponding flight plan application data, and then combine the node stub data to analyze whether the flight plan meets the requirements.

[0015] As a possible implementation, the encrypted segment of the extraction object and the encrypted segment of the flight plan are decrypted to form the application object information and the object flight plan information, respectively, including: obtaining the identity order decoding of the node public decryption function corresponding to the node, and performing the following identity decoding on the object encrypted segment: removing the order decoding from the object encrypted segment to form the application object code information; performing the identification information conversion on the application object code information to form the application object information; determining the object decoding function on the corresponding node according to the application object information, and obtaining the object application order decoding according to the object decoding function; and performing the following application content decoding on the flight plan encrypted segment: removing the object application order decoding from the flight plan encrypted segment to form the object application content code information; and performing the identification information conversion on the object application content code information to form the object flight plan information.

[0016] In the application, the information transmitted for ensuring the safety of data transmission of the flight plan application data transmitted by the object to the corresponding node is encrypted, so that the node needs to decrypt the transmitted information to obtain the detailed flight plan application information, and then provide data reference for subsequent application authentication and management. The decryption method adopted in the application is divided into two parts, one part is for the decryption of the object's identity information, and the other part is for the decryption of the object's flight plan information. Of course, in order to further improve the security of data, the decryption of the object's identity information and the decryption of the object's flight plan information are associated, and only the object's identity information is correctly and completely decrypted can the decryption of the object's flight plan information be continued. The application provides a decryption method, which is based on the flight object as the management range for different nodes, each node manages a corresponding number of specific objects, of course, the object range can also be adjusted regularly to improve the security of data, each node will provide a random function for decrypting the identity information of the object applying for the decryption method, when obtaining an application request, the random function will randomly generate a function value, of course, the function value randomly generated by the random function has regularity in the number of times, that is, if the number of operations of two identical random functions is consistent, the function value randomly generated is equal, using this rule for decryption and encryption can ensure that the password information can only be obtained by the applicant object and the node, and how to realize the function value generated by the random function of the node to match the function value formed by the corresponding random function on the applicant object can be considered in two ways, the node uses a counter to record the number of operations of the random function, when the applicant object needs to apply for the application, the node's number information is first obtained, then the random function on the applicant object is operated according to the number information, and then the function value generated by the next operation of the random function on the node is obtained, and the function value is used to encrypt the information of the applicant object, so that the encrypted object identity information can be decrypted by the node after the node obtains the information, and the random function on the node is operated again to obtain the function value matching the encryption. Another way is that the node and the applicant object agree on a time period and a time interval, which can be a function form of management, so that the random function on the node and the random function on the applicant object are operated according to the specified time interval within the agreed time period, when the applicant object needs to apply for the application, the latest random function operation result is obtained to encrypt and assist the time information, so that the node can extract the function value generated by the operation of the random function on the node at the corresponding time point according to the time information to decrypt. Of course, the decryption method is also various, first, the encryption and decryption method between the node and the applicant object is agreed, then the node uses the agreed decryption method to exclude the function value of the random function and finally converts the applicant object information.When the object identity information is decrypted, the node determines the object decoding function set on the node according to the object identity information matching the object identity, and decrypts the encrypted flight plan application information by using the object decoding function. Of course, the encryption and decryption of the flight plan application information are the same as the encryption and decryption of the object identity information, and only the random function value set on different application objects for the encryption of the flight plan data information is different.

[0017] As a possible implementation, according to the blockchain node sharing stub data, combined with object flight plan information for authentication analysis, forming authentication analysis result data, including: according to the object flight plan information, extracting the application time point, application plan time period and application plan space range, forming the application data group; according to the blockchain node sharing stub data, extracting the authentication plan time period and authentication plan space range corresponding to different flight plans in the publicly shared ordered authentication plan set, forming the authentication data group corresponding to different flight plans; according to the blockchain node sharing stub data, extracting the application ordered time point, application ordered plan time period and application ordered plan space range corresponding to different flight plans in the publicly shared ordered application plan set, forming the application ordered data group corresponding to different flight plans; the application data group is compared with different authentication data groups in the time period and space range as follows: if there is no authentication plan time period coinciding with the application plan time period, and the authentication plan space range coincides with the application plan space range, authentication comparison normal information is formed; if there is an authentication data group, the authentication plan time period coincides with the application plan time period, but the authentication plan space range does not coincide with the application plan space range, authentication comparison space coincidence information is formed; if there is an authentication data group, the authentication plan time period does not coincide with the application plan time period, but the authentication plan space range coincides with the application plan space range, authentication comparison time coincidence information is formed; if there is an authentication data group, the authentication plan time period coincides with the application plan time period, and the authentication plan space range coincides with the application plan space range, authentication comparison coincidence information is formed; when the comparison analysis forms authentication comparison normal information, the application data group is compared with different application ordered data groups as follows: all application ordered data groups with application ordered time point earlier than the application time point are determined as previous application ordered data groups; if there is no authentication plan time period coinciding with the application plan time period, and the authentication plan space range coincides with the application plan space range for any previous application ordered data group, authentication pass information is formed, otherwise authentication fail information is formed.

[0018] In the present application, the authentication analysis is mainly to determine whether the flight plan to be applied conflicts with the existing flight plan content in the time range of the plan implementation and the spatial range of the plan implementation. Since the existing flight plan includes the plans that have been approved for implementation and the plans that are being applied for authentication, the comparison analysis of the two types of plan data is different. For the plans that have been approved for implementation, the comparison of the plan implementation time and the plan implementation spatial range can be directly performed. Of course, if different nodes apply for authentication approval according to the application area, the comparison analysis can be performed only on the authentication plan data obtained locally, which can greatly reduce the data amount of the comparison analysis. For the plans that are being applied for authentication, in order to avoid conflicts, the plans are reviewed according to the principle of first application and first authentication. Therefore, when performing the comparison analysis, it is necessary to first determine the application in the submitted application plan, and then compare the plan time and the plan spatial range of the plans that are being authenticated and reviewed. Of course, the comparison analysis of the two types of plan data is a progressive relationship. Only when the data comparison of the existing flight plan is passed, the comparison of the plan data being applied is performed. In this way, the efficiency of the authentication comparison analysis can be improved, and the data amount of the data analysis processing can be reduced.

[0019] As a possible implementation manner, according to the authentication analysis result information, real-time flight data is collected, and monitoring analysis is performed in combination with the plan application information to form real-time monitoring data, including: when the authentication analysis result information is authentication pass information, different real-time discrete record time points and corresponding real-time discrete position coordinates are extracted according to the real-time flight data; the real-time flight time interval is determined according to the real-time discrete record time points, and is compared with the application plan time period. If the real-time flight time interval belongs to the application plan time period, real-time time monitoring normal information is formed, otherwise, real-time time overrun information is formed; path trajectory analysis is performed based on the time dimension according to the real-time discrete position coordinates to form a real-time flight trajectory curve ; range monitoring analysis based on the minimum turning radius is performed according to the real-time flight trajectory curve in combination with the application plan spatial range to form range monitoring result data.

[0020] In the present application, the monitoring analysis is mainly to track the aircraft operation in real time, and to supervise whether the operation is carried out according to the time period and the spatial range reported in the plan. The data required for real-time monitoring of flight operation comes from the discrete acquisition data uploaded by the aircraft. Considering that real-time monitoring mainly covers time and space monitoring, it is necessary to use the acquired discrete data for comparative analysis with the plan data respectively. The time data only needs to combine the acquired discrete time points to determine the time period of the corresponding operation to judge whether it is within the planned time period. For the spatial data, the trajectory data is formed by using the discrete position coordinate data to judge whether the trajectory exceeds the planned spatial range.

[0021] As a possible implementation manner, according to the real-time flight trajectory curve , and combined with the application plan spatial range, the range monitoring analysis based on the minimum turning radius is carried out to form the range monitoring result data, including: according to the real-time flight trajectory curve , the corresponding trajectory curvature radius is determined. According to the real-time flight trajectory curve , the trajectory curvature radius and the application plan spatial range, the range monitoring analysis is carried out in the following manner: for the real-time flight trajectory curve , if it exceeds the application plan spatial range, the operation range over-limit information is formed; for the real-time flight trajectory curve , if it does not exceed the application plan spatial range, and there is no shortest distance between the trajectory point and the boundary of the application plan spatial range not greater than the trajectory checking distance , the operation range normal information is formed; for the real-time flight trajectory curve , if it does not exceed the application plan spatial range, but there is a shortest distance between the trajectory point and the boundary of the application plan spatial range not greater than the trajectory checking distance : the trajectory segment with the shortest distance not greater than the trajectory checking distance to the boundary of the application plan spatial range is determined, which is marked as a risk trajectory segment, and the risk trajectory segment curvature radius corresponding to the risk trajectory segment is extracted, n represents the number of different risk trajectory segments; for each risk trajectory segment, if ≤ , the operation range normal information is formed, wherein, is the minimum turning radius of the aircraft, is the turning environment influence factor; for each risk trajectory segment, if there is any risk trajectory segment that does not satisfy ≤ ≤ , the operation range over-limit information is formed.

[0022] In the present application, whether the flight trajectory exceeds the planned space range is mainly to determine whether the flight trajectory is in the planned space range or whether there is a risk of exceeding the planned space range. For whether it is in the planned space range, the trajectory curve can be directly compared and judged, and for whether there is a risk of exceeding the planned space range, mainly because the node collects discrete position coordinate data, and the trajectory fitting is only a simple continuity fitting analysis, and cannot completely represent the real trajectory. In order to be safe, for the trajectory position close to the boundary of the planned space range, it is necessary to determine whether it is possible to exceed the limit for a short time because the turning radius is not small enough. Therefore, the analysis of the exceeding risk is determined by taking the trajectory checking distance as the reference, if there is a minimum distance reaching the trajectory checking distance, it is necessary to judge whether the minimum turning radius meets the condition of being less than the trajectory checking distance, of course, the environmental factors and the minimum turning radius capability that the aircraft can make are also considered. Environmental factors also have an impact on the minimum turning radius that the aircraft can make. Therefore, it is necessary to determine whether the curvature radius of the risk trajectory segment can be realized by the aircraft under the influence of the environment, and whether the trajectory checking distance can be reached. For environmental factors, i.e. turning environmental influence factor, it can be obtained based on big data analysis of the turning radius of the working aircraft under different environmental conditions, and the minimum turning radius of the aircraft can be obtained from the design parameters of the aircraft. Of course, this parameter needs to be reported to the node when applying for the plan.

[0023] As a possible implementation manner, the management information of the real-time monitoring data is recorded and extracted, forming flight real-time record data, including: storing the real-time monitoring data on the corresponding node, and extracting the application object and flight plan information in the real-time monitoring data; the application object and flight plan information are sent to all nodes as public shared data for storage.

[0024] In the present application, after the flight operation is completed, whether it is terminated because it exceeds the planned content or it is successfully completed, the real-time monitoring data needs to be stored. The storage method is to store the real-time monitoring data on the corresponding node. The real-time monitoring data contains the application plan data, the real-time collected data and the analysis data made for the real-time collected data. Of course, in order to ensure that other nodes can have traceability or contact to the real-time monitoring data, the application object and flight plan information are provided to other nodes as public shared data, and other nodes store the corresponding node shared stub data after obtaining the data. In this way, it can be ensured that all nodes of the entire block chain have traceability and contact to any flight data. While reducing the consumption of data storage resources, the safety and reliability of the data can also be improved.

[0025] In a second aspect, the application provides a low-altitude airspace permission authentication and management system based on a blockchain, comprising: a data acquisition unit arranged on each node of the blockchain, configured to acquire public shared data from different nodes, plan application information for the corresponding node, and real-time flight data; a data storage unit arranged on each node of the blockchain, configured to cluster and store the public shared data from different nodes acquired by the data acquisition unit, to form shared stub data of the blockchain node, and to store real-time monitoring data formed by the corresponding node; an authentication analysis unit arranged on each node of the blockchain, configured to perform authentication analysis on the plan application information of the corresponding node, to form authentication analysis result information; and a monitoring analysis unit arranged on each node of the blockchain, configured to acquire real-time flight data collected by the data acquisition unit on the basis of the analysis result of the authentication analysis unit, to perform monitoring analysis, and to form real-time monitoring data.

[0026] In the application, the system realizes distributed data processing and storage through different functional units on each node in the blockchain, the data acquisition unit completes the acquisition of flight data and corresponding application data and real-time flight data, the data storage unit stores shared data and monitoring data, the authentication analysis unit realizes authentication analysis on the proposed flight plan application, and the monitoring analysis unit is configured to collect and monitor the data of the real-time operation of the authenticated flight plan. The different functional units form a complete data processing system of the node, which is a necessary material basis for realizing low-altitude airspace permission authentication and management. Different nodes form a complete blockchain system, which ensures the integrity of the data and improves the management ability and efficiency, greatly improving the form of authentication and management.

[0027] The application provides a low-altitude airspace permission authentication and management method and system based on a blockchain, which has the following advantages:

[0028] The method can avoid tampering of the plan data by each node on the blockchain stubbing the flight plan information on the entire blockchain. Of course, different nodes manage the corresponding plan application information and determine whether the applied plan conflicts with the existing plan based on the shared stub to ensure that the approved plan has no conflict. The discrete record data uploaded in real time by the flight operation is obtained according to the execution time of the plan to track whether the flight plan conforms to the real time, so as to avoid deviation from the plan. After the completion of the aircraft operation, the data is stored on the corresponding node, and the shared data is provided to other nodes as a stub to facilitate the tracing of the record data on all nodes. The low-altitude airspace permission is authenticated and managed by using the blockchain, which can avoid the problems of large data volume and low data security caused by centralized management, and greatly improve the management efficiency and management ability, so that the data is more stable and reliable.

[0029] The system realizes distributed data processing and storage through different functional units on each node in the blockchain. The data acquisition unit completes the acquisition of flight data, corresponding application data and real-time flight data. The data storage unit stores shared data and monitors data. The authentication analysis unit realizes authentication analysis of the proposed flight plan application. The monitoring analysis unit realizes real-time operation data acquisition and monitoring of the authenticated flight plan. Different functional units form a complete data processing system of the node, which is a necessary material basis for realizing low-altitude airspace permission authentication and management. Different nodes form a complete blockchain system, which can ensure the integrity of the data and improve the management ability and efficiency, and greatly improve the form of authentication and management. BRIEF DESCRIPTION OF DRAWINGS

[0030] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiments of the present application. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as a limitation on the scope. For those skilled in the art, other related drawings can also be obtained without creative labor on the basis of these drawings.

[0031] Fig. 1 A step diagram of a low-altitude airspace permission authentication and management method based on a blockchain provided by the embodiments of the present application;

[0032] Fig. 2 A structure schematic diagram of a low-altitude airspace permission authentication and management system based on a blockchain provided by the embodiments of the present application. DETAILED DESCRIPTION

[0033] The technical solutions in the embodiments of the present application will be described below with reference to the drawings in the embodiments of the present application.

[0034] With the gradual opening of low-altitude airspace, the number of low-altitude operations gradually increases, which gradually brings pressure to the management of low-altitude airspace. The traditional centralized airspace management system is prone to performance bottlenecks and single-point failure risks when facing massive, high-frequency, and multi-agent unmanned aerial vehicle operations.

[0035] Blockchain technology is a block chain storage, tamper-proof, secure and trusted decentralized distributed ledger, which combines distributed storage, peer-to-peer transmission, consensus mechanism, cryptography and other technologies, records transactions and information through a growing data block chain, and ensures the security and transparency of data. If the blockchain technology can be applied to the management of low-altitude airspace, the management capability and efficiency can be further optimized. However, how to establish a reasonable management system based on blockchain is an important problem to be considered at present.

[0036] Reference Figs. 1-2 The embodiments of the present application provide a low-altitude airspace permission authentication and management method based on blockchain. The method uses flight plan data disclosed by different nodes on the blockchain, and each node can stub the flight plan information on the entire blockchain to avoid tampering with the plan data. Of course, different nodes manage the corresponding plan application information, and judge whether the applied plan conflicts with the existing plan based on the shared stub, and then ensure that the approved plan has no conflict. According to the time of plan execution, the discrete record data uploaded in real time by the flight operation is obtained to track whether the flight plan conforms to the real time, and to avoid the situation of deviating from the plan. After completing the aircraft operation, the data is stored on the corresponding node, and shared data is provided to other nodes as a stub, which facilitates the tracing of record data on all nodes. The low-altitude airspace permission is authenticated and managed by using the blockchain method, which can avoid the large amount of data, low data security and other situations caused by centralized management, and greatly improve the management efficiency and management capability, so that the data is more stable and reliable.

[0037] A low-altitude airspace permission authentication and management method based on blockchain specifically includes the following steps:

[0038] S1: Collecting public shared data corresponding to different nodes, clustering data storage, and forming blockchain node shared stub data.

[0039] Collecting the public sharing data corresponding to different nodes, performing cluster data storage, and forming blockchain node shared stub data, including: extracting public sharing authentication plans from the public sharing data to form a public sharing authentication plan set; extracting public sharing application plans from the public sharing data to form a public sharing application plan set; performing sequential clustering processing on the public sharing authentication plan set and the public sharing application plan set respectively to form the blockchain node shared stub data.

[0040] The aircraft plan data shared by different nodes in the blockchain needs to be stored on each node to provide comprehensive data reference for the corresponding flight plan authentication and management of the nodes. Of course, considering that these stored data are mainly used for flight plan authentication and management, it is necessary to consider the parameter information involved in authentication and management, so two data sets are distinguished, one is the aircraft plan that has completed the audit authentication, and the other is the flight plan that is being applied for authentication. It can be understood that for the aircraft plan that has completed the audit authentication, it is mainly used to provide authentication services for the conflict of the plan content of the flight plan being applied for, while the flight plan being applied for authentication not only needs to consider the conflict of the plan content but also needs to consider the time of the application to apply for authentication in the order of first application first authentication to avoid confusion in the application and authentication work, so the two different data sets need to be separated to avoid confusion in the subsequent reference of the two data sets, which leads to the inability to carry out the application and authentication work.

[0041] Respectively performing sequential clustering processing on the public sharing authentication plan set and the public sharing application plan set to form the blockchain node shared stub data, including: numbering and sorting the different flight plans in the public sharing authentication plan set according to the operation start time of the aircraft plan in the time dimension to form a public sharing ordered authentication plan set; numbering and sorting the different flight plans in the public sharing application plan set according to the application time of the flight plan in the time dimension to form a public sharing ordered application plan set; collecting the public sharing ordered authentication plan set and the public sharing ordered application plan set to form the blockchain node shared stub data.

[0042] The stub data of each node on the blockchain contains flight plan data on the entire blockchain. Since the review and certification of whether the flight plan is complete has an impact on subsequent applications for new flight plans, it is necessary to cluster the stub data that has been certified and that has not been certified. At the same time, in order to facilitate efficient processing and analysis of the two types of flight plan data, it is necessary to perform reasonable and orderly clustering. For certified flight plans, the important information is the time of occurrence and the corresponding involved area. For uncertified flight plans, the important information is the application time, followed by the plan time and the area involved in the application. Therefore, the two different types of flight plan data are sequentially clustered according to different important information points to form sequentially clustered data that can be efficiently referenced later. It should be noted that the stub data mainly contains object identity information, flight plan application time, plan time, and involved area. On the one hand, these pieces of information can provide a complete reference for all nodes to perform targeted queries on stub data, facilitating quick locking to data record nodes containing more rich information. At the same time, the simplicity of stub data can avoid the increase in resource demand caused by excessive data storage on nodes, thereby reducing unnecessary cost overhead.

[0043] S2: Obtain plan application information, perform authentication analysis based on the shared stub data of the blockchain nodes, and form authentication analysis result information.

[0044] Obtain plan application information, perform authentication analysis based on the shared stub data of the blockchain nodes, and form authentication analysis result information, including: obtaining plan application information, extracting object encryption segments and flight plan encryption segments; decrypting the extracted object encryption segments and flight plan encryption segments to form application object information and object flight plan information; performing authentication analysis based on the shared stub data of the blockchain nodes and the object flight plan information to form authentication analysis result data.

[0045] Different nodes in the blockchain can handle flight plan applications initiated by objects within different ranges, which can alleviate the authentication processing pressure of centralized management. In order to ensure the security of data upload and information on the blockchain, the data is transmitted in an encrypted form. Therefore, it is necessary to first decrypt the initiated flight plan application, extract the object and corresponding flight plan application data, and then perform authentication analysis on whether the flight plan meets the requirements based on the node stub data.

[0046] The encrypted segment of the extraction object and the encrypted segment of the flight plan are decrypted to form the application object information and the object flight plan information, respectively, including: obtaining the identity order decoding of the node public decryption function corresponding to the node, and decoding the object encrypted segment in the following manner: removing the order decoding from the object encrypted segment to form the application object code information; transforming the identification information of the application object code information to form the application object information; determining the object decoding function on the corresponding node according to the application object information, and obtaining the object application order decoding according to the object decoding function; and decoding the flight plan encrypted segment in the following manner: removing the object application order decoding from the flight plan encrypted segment to form the object application content code information; and transforming the identification information of the object application content code information to form the object flight plan information.

[0047] For the flight plan application data sent by the object to the corresponding node, in order to ensure the security of data transmission, the transmitted information is encrypted, so that the node needs to be decrypted after obtaining the transmitted information to obtain the detailed flight plan application information, and then provide data reference for subsequent application authentication and management. The decryption method adopted in this application is divided into two parts, one part is for the decryption of the object's identity information, and the other part is for the decryption of the object's flight plan information. Of course, in order to further improve the security of data, the decryption of the object's identity information and the decryption of the object's flight plan information are associated. Only the object's identity information is correctly and completely decrypted can the decryption of the object's flight plan information be continued. This application provides a decryption method, which is based on the flight object as the management range for different nodes. Each node manages a corresponding number of specific objects. Of course, the object range can also be adjusted regularly to improve the security of data. Each node will provide a random function for decrypting the identity information of the object applying for it. When an application request is obtained, the random function will randomly generate a function value. Of course, the function value generated by the random function has regularity in the number of times. That is, if the number of operations of two identical random functions is consistent, the function value generated by the random function is equal. Using this rule for decryption and encryption can ensure that the password information can only be obtained by the applicant object and the node. How to realize the matching of the function value generated by the random function of the node with the function value formed by the corresponding random function of the applicant object can be considered in two ways. The node uses a counter to record the number of operations of the random function. When the applicant object needs to apply, it first obtains the number of times of the node, then performs the corresponding number of operations on the random function on the applicant object according to the number of times, and then obtains the function value generated by the next operation of the random function on the node. The function value is used to encrypt the information of the applicant object. In this way, after the encrypted object identity information is obtained by the node, the random function on the node performs a new operation to obtain the function value matching the encryption, which can realize decryption. The other way is that the node and the applicant object agree on a time period and a time interval. The time period and the time interval can be managed in the form of function. In this way, within the agreed time period, the random function on the node and the random function on the applicant object operate according to the specified time interval. When the applicant object needs to apply, the latest random function operation result is obtained to encrypt and assist the time information. In this way, the node obtains the data according to the time information to extract the function value generated by the operation of the random function on the node at the corresponding time point for decryption. Of course, the decryption method is also various. First, agree on the encryption and decryption method between the node and the applicant object, then use the agreed decryption method to exclude the function value of the random function when the node decrypts, and finally convert the applicant object information.When the object identity information is decrypted, the node determines the object decoding function set on the node according to the object identity information matching the object identity, and decrypts the encrypted flight plan application information using the object decoding function. Of course, the encryption and decryption of the flight plan application information is the same as the encryption and decryption of the object identity information, and only the random function value set on different application objects for the encryption of the flight plan data information is different.

[0048] According to the blockchain node sharing stub data, combined with the object flight plan information, the authentication analysis result data is formed, including: according to the object flight plan information, the application time point, the application plan time period and the application plan space range are extracted to form the application data group; according to the blockchain node sharing stub data, the authentication plan time period and the authentication plan space range corresponding to different flight plans in the publicly shared ordered authentication plan set are extracted to form the authentication data group corresponding to different flight plans; according to the blockchain node sharing stub data, the application ordered time point, the application ordered plan time period and the application ordered plan space range corresponding to different flight plans in the publicly shared ordered application plan set are extracted to form the application ordered data group corresponding to different flight plans; the application data group is compared with different authentication data groups in the time period and the space range as follows: if there is no authentication plan time period and application plan time period overlap, and the authentication plan space range and the application plan space range overlap for any authentication data group, authentication comparison normal information is formed; if there is an authentication data group, the authentication plan time period and the application plan time period overlap, but the authentication plan space range and the application plan space range do not overlap, authentication comparison space overlap information is formed; if there is an authentication data group, the authentication plan time period and the application plan time period do not overlap, but the authentication plan space range and the application plan space range overlap, authentication comparison time overlap information is formed; if there is an authentication data group, the authentication plan time period and the application plan time period overlap, and the authentication plan space range and the application plan space range overlap, authentication comparison overlap information is formed; when the comparison analysis forms authentication comparison normal information, the application data group is compared with different application ordered data groups as follows: all application ordered data groups with application ordered time point earlier than application time point are identified as previous application ordered data groups; if there is no authentication plan time period and application plan time period overlap, and the authentication plan space range and the application plan space range overlap for any previous application ordered data group, authentication pass information is formed, otherwise authentication fail information is formed.

[0049] The authentication analysis is mainly to determine whether the flight plan to be applied conflicts with the existing flight plan content in the time range of the plan implementation and the spatial range of the plan implementation. Since the existing flight plan includes plans that have been approved for implementation and plans that are currently being applied for authentication, the comparison analysis method of these two types of plan data is different. For plans that have been approved for implementation, the plan implementation time and the plan implementation spatial range can be directly compared. Of course, if different nodes apply for authentication approval according to the application area, only the authentication plan data in the local node needs to be compared and analyzed, which can greatly reduce the data volume of comparison and analysis. For plans that are currently being applied for authentication, to avoid conflicts, they are reviewed according to the principle of first application and first authentication. Therefore, when comparing and analyzing, it is necessary to first determine the application in the submitted application plan, and then compare the plan time and plan spatial range of these pre-existing plans under authentication review. Of course, the comparison and analysis of the two types of plan data is a progressive relationship. Only when the data comparison of the existing flight plan passes, the comparison of the plan data being applied is performed. This can also improve the efficiency of authentication comparison and analysis and reduce the data volume of data analysis processing.

[0050] S3: According to the authentication analysis result information, collect real-time flight data and combine the plan application information to perform monitoring analysis to form real-time monitoring data.

[0051] According to the authentication analysis result information, collect real-time flight data and combine the plan application information to perform monitoring analysis to form real-time monitoring data, including: when the authentication analysis result information is authentication pass information, according to the real-time flight data, extract different real-time discrete record time points and corresponding real-time discrete position coordinates; determine the real-time flight time interval according to the real-time discrete record time points, and compare it with the application plan time period. If the real-time flight time interval belongs to the application plan time period, real-time time monitoring normal information is formed, otherwise, real-time time overrun information is formed; perform path trajectory analysis based on the time dimension according to the real-time discrete position coordinates to form a real-time flight trajectory curve ; perform range monitoring analysis based on the minimum turning radius according to the real-time flight trajectory curve and in combination with the application plan spatial range to form range monitoring result data.

[0052] The monitoring analysis mainly tracks the aircraft operation in real time, supervises whether the operation is carried out according to the time period and spatial range reported in the plan. The data required for real-time monitoring of flight operation comes from the discrete acquisition data uploaded by the aircraft. Considering that real-time monitoring mainly covers time and space monitoring, it is necessary to use the acquired discrete data for comparative analysis with the plan data respectively. The time data only needs to combine the acquired discrete time points to determine the time period of the corresponding operation to judge whether it is within the planned time period. For spatial data, it is necessary to use discrete position coordinate data to form trajectory data to judge whether the trajectory exceeds the planned spatial range.

[0053] According to the real-time flight trajectory curve , and combined with the application plan spatial range, the range monitoring analysis based on the minimum turning radius is carried out to form the range monitoring result data, including: according to the real-time flight trajectory curve , the corresponding trajectory curvature radius is determined; according to the real-time flight trajectory curve , the trajectory curvature radius and the application plan spatial range, the range monitoring analysis in the following manner is carried out: for the real-time flight trajectory curve , if it exceeds the application plan spatial range, the operation range over-limit information is formed; for the real-time flight trajectory curve , if it does not exceed the application plan spatial range, and there is no shortest distance between the trajectory point and the boundary of the application plan spatial range is not greater than the trajectory checking distance , the operation range normal information is formed; for the real-time flight trajectory curve , if it does not exceed the application plan spatial range, but there is a shortest distance between the trajectory point and the boundary of the application plan spatial range is not greater than the trajectory checking distance , then: the trajectory segment with a shortest distance to the boundary of the application plan spatial range not greater than the trajectory checking distance is determined, which is marked as a risk trajectory segment, and the risk trajectory segment curvature radius corresponding to the risk trajectory segment is extracted, n represents the number of different risk trajectory segments; for each risk trajectory segment, if it satisfies ≤ ≤ , the operation range normal information is formed, wherein, is the minimum turning radius of the aircraft, is the turning environment influence factor; for each risk trajectory segment, if there is any risk trajectory segment that does not satisfy ≤ ≤ , the operation range over-limit information is formed.

[0054] The main purpose of determining whether the flight trajectory exceeds the planned space range is to determine whether the flight trajectory is within the planned space range or whether there is a risk of exceeding the planned space range. For whether it is within the planned space range, the trajectory curve can be directly compared and judged, and for whether there is a risk of exceeding the planned space range, mainly because the node collects discrete position coordinate data, and the trajectory fitting is only a simple continuity fitting analysis and cannot completely represent the real trajectory. In order to be safe, the trajectory position close to the boundary of the planned space range needs to be determined whether it is possible to exceed the limit for a short time due to insufficient turning radius. Therefore, the analysis of the risk of exceeding the limit is determined by the trajectory checking distance. If the minimum distance reaches the trajectory checking distance, it is necessary to determine whether the minimum turning radius meets the condition of being less than the trajectory checking distance. Of course, environmental factors and the minimum turning radius capability of the aircraft also need to be considered. Environmental factors also have an impact on the minimum turning radius of the aircraft. Therefore, it is necessary to determine whether the curvature radius of the risk trajectory segment can be achieved by the aircraft under the influence of the environment and whether it will reach the trajectory checking distance. For environmental factors, i.e. turning environmental impact factor, it can be obtained based on big data analysis of the turning radius of the working aircraft under different environmental conditions. The minimum turning radius of the aircraft can be obtained from the design parameters of the aircraft. Of course, this parameter needs to be reported to the node when applying for the plan.

[0055] S4: Extracting and processing the data recording of the management information of the real-time monitoring data to form flight real-time recording data.

[0056] The extracting and processing of the data recording of the management information of the real-time monitoring data to form flight real-time recording data includes: storing the real-time monitoring data on the corresponding node, and extracting the application object and flight plan information in the real-time monitoring data; sending the application object and flight plan information as public shared data to all nodes for storage.

[0057] After the completion of the flight operation, whether it is terminated due to exceeding the planned content or successfully completed, the real-time monitoring data needs to be stored. The storage method is to store the real-time monitoring data on the corresponding node. The real-time monitoring data includes the application plan data, the real-time collected data and the analysis data made for the real-time collected data. Of course, in order to ensure that other nodes can have traceability or contact to the real-time monitoring data, the application object and flight plan information are provided as public shared data to other nodes, which are stored by other nodes to form corresponding node shared stub data after being obtained. This can ensure that all nodes of the entire block chain have traceability and contact to any flight data. While reducing the consumption of data storage resources, it also improves the security and reliability of the data.

[0058] The application also provides a low-altitude airspace permission authentication and management system based on a blockchain, which comprises: a data acquisition unit arranged on each node of the blockchain and used for acquiring public shared data from different nodes, plan application information of the corresponding node and real-time flight data; a data storage unit arranged on each node of the blockchain and used for clustering and storing the public shared data from different nodes acquired by the data acquisition unit to form shared stub data of the blockchain node, and storing real-time monitoring data formed by the corresponding node; an authentication analysis unit arranged on each node of the blockchain and used for performing authentication analysis on the plan application information of the corresponding node to form authentication analysis result information; and a monitoring analysis unit arranged on each node of the blockchain and used for acquiring the real-time flight data collected by the data acquisition unit on the basis of the analysis result of the authentication analysis unit, performing monitoring analysis and forming real-time monitoring data.

[0059] The system realizes distributed data processing and storage through different functional units on each node in the blockchain, the data acquisition unit completes the collection of flight data and corresponding application data and real-time flight data, the data storage unit stores shared data and monitoring data, the authentication analysis unit realizes authentication analysis on the proposed flight plan application, and the monitoring analysis unit is used for collecting and monitoring the data of the real-time operation of the authenticated flight plan, so that a complete data processing system of the node is formed between different functional units, which is a necessary material basis for realizing low-altitude airspace permission authentication and management, different nodes form a complete blockchain system, which can ensure the integrity of data and improve the management ability and efficiency, and greatly improves the form of authentication and management.

[0060] In conclusion, the low-altitude airspace permission authentication and management method and system based on the blockchain have the following advantages:

[0061] The method can avoid tampering of the plan data by each node on the blockchain stubbing the flight plan information on the entire blockchain. Of course, different nodes manage the corresponding plan application information, and determine whether the applied plan conflicts with the existing plan based on the shared stub, thereby ensuring that the approved plan has no conflict. According to the time of the plan execution, the discrete record data uploaded by the flight operation in real time is acquired to track whether the flight plan conforms to the real time, thereby avoiding deviation from the plan. After the completion of the aircraft operation, the data is stored on the corresponding node, and shared data is provided to other nodes as a stub, so that the record data can be traced on all nodes. The low-altitude airspace permission is authenticated and managed by using the blockchain, which can avoid the problems of large data volume and low data security caused by centralized management, and greatly improve the management efficiency and management ability, so that the data is more stable and reliable.

[0062] The system realizes distributed data processing and storage through different functional units on each node in the blockchain. The data acquisition unit completes the acquisition of flight data and corresponding application data and real-time flight data. The data storage unit stores shared data and monitors data. The authentication analysis unit realizes authentication analysis of the proposed flight plan application. The monitoring analysis unit is responsible for real-time data acquisition and monitoring of the authenticated flight plan. Different functional units form a complete data processing system of the node, which is a necessary material basis for realizing low-altitude airspace permission authentication and management. Different nodes form a complete blockchain system, which ensures the integrity of the data and improves the management ability and efficiency, greatly improving the form of authentication and management.

[0063] In the embodiments of the present application, the indication can include direct indication and indirect indication, and can also include explicit indication and implicit indication. The information indicated by a certain information is referred to as to-be-indicated information. In the specific implementation process, there are many ways to indicate the to-be-indicated information, for example, but not limited to, the to-be-indicated information can be directly indicated, such as the to-be-indicated information itself or the index of the to-be-indicated information. The to-be-indicated information can also be indirectly indicated by indicating other information, where the other information and the to-be-indicated information have an association relationship. The to-be-indicated information can also be indicated only by a part of the to-be-indicated information, and the other part of the to-be-indicated information is known or agreed in advance. For example, the indication of a specific information can also be realized by means of the arrangement order of each information agreed in advance (for example, a protocol stipulates), thereby reducing the indication overhead to a certain extent. At the same time, the common part of each information can be identified and uniformly indicated, so as to reduce the indication overhead caused by separately indicating the same information.

[0064] In addition, the specific indication manner can also be various existing indication manners, for example but not limited to the indication manners described above and various combinations thereof. The specific details of various indication manners can refer to the prior art, and will not be described herein. As can be known from the above, for example, when multiple information of the same type needs to be indicated, the indication manners of different information can be different. In the specific implementation process, the required indication manner can be selected according to the specific needs, and the selected indication manner is not limited by the embodiments of the application. In this way, the indication manners involved in the embodiments of the application should be understood as covering various methods that can enable the indicating party to know the information to be indicated.

[0065] It should be understood that the information to be indicated can be sent as a whole or divided into multiple sub-information and sent separately, and the sending period and / or sending occasion of the sub-information can be the same or different. The specific sending method is not limited by the embodiments of the application. The sending period and / or sending occasion of the sub-information can be predefined, for example, predefined according to a protocol, or configured by the sending end device by sending configuration information to the receiving end device.

[0066] The "predefined" or "preconfigured" can be implemented by pre-storing corresponding codes, tables or other methods that can be used to indicate related information in the device, and the specific implementation manner is not limited by the embodiments of the application. The "storage" can mean storage in one or more memories. The one or more memories can be separately arranged or integrated in the encoder or decoder, processor or communication device. The one or more memories can be partially separately arranged and partially integrated in the decoder, processor or communication device. The type of memory can be any form of storage medium, and the embodiments of the application do not limit this.

[0067] The "protocol" involved in the embodiments of the application can refer to a protocol family in the communication field, a standard protocol similar to the protocol family frame structure, or a related protocol applied to a future communication system, and the embodiments of the application do not make specific limitations.

[0068] In the embodiments of the application, "when", "in the case of", "if" and "if" and the like all refer to the device making corresponding processing under certain objective conditions, and are not limited by time, and do not require the device to have a judgment action when implemented, nor does it mean that there are other limitations.

[0069] In the description of the embodiments of the present application, unless otherwise specified, " / " represents that the objects before and after the " / " are in an "or" relationship, for example, A / B can represent A or B; "and / or" in the embodiments of the present application is only a description of the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone, wherein A and B can be singular or plural. In addition, in the description of the embodiments of the present application, unless otherwise specified, "multiple" means two or more than two. "At least one of the following" or the like means any combination of the items, including any combination of single item or multiple items. For example, at least one of a, b or c can represent: a, b, c, a-b, a-c, b-c, or a-b-c, wherein a, b, and c can be single or multiple. In addition, in order to clearly describe the technical solutions of the embodiments of the present application, in the embodiments of the present application, "first", "second", and the like are used to distinguish the same items or similar items with basically the same function and role. Those skilled in the art can understand that "first", "second", and the like do not limit the quantity and execution order, and "first", "second", and the like do not necessarily mean different. At the same time, in the embodiments of the present application, "exemplary" or "for example" means to serve as an example, illustration or description. Any embodiment or design scheme described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as more preferred or more advantageous than other embodiments or design schemes. Rather, "exemplary" or "for example" is used to present the relevant concept in a specific manner, for understanding.

[0070] It should be understood that the processor in the embodiments of the present application can be a central processing unit (CPU), and the processor can also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor.

[0071] It should also be understood that the memory in the embodiments of the present application can be a volatile memory or a nonvolatile memory, or can include both volatile and nonvolatile memory. Among them, the nonvolatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically EPROM (EEPROM), or a flash memory. The volatile memory can be a random access memory (RAM) used as an external cache. By way of example, and not limitation, many forms of random access memory (RAM) can be used, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM).

[0072] The above-described embodiments can be implemented in whole or in part by software, hardware (such as a circuit), firmware, or any combination thereof. When implemented in software, the above-described embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions described in the embodiments of the present application are wholly or partially generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another computer-readable storage medium, for example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center through a wired (for example, infrared, wireless, microwave, etc.) manner. The computer-readable storage medium can be any available medium accessible by a computer or a data storage device such as a server, data center, etc. containing one or more available medium collections. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state disk.

[0073] It should be understood that the term "and / or" herein merely describes an association relationship of associated objects, which means that there can be three relationships, for example, A and / or B can represent three cases of A alone, A and B together, and B alone, where A and B can be singular or plural. In addition, the character " / " herein generally represents an "or" relationship between the front and rear associated objects, but can also represent an "and / or" relationship, which can be understood in the context before and after.

[0074] In this application, "at least one" means one or more, and "multiple" means two or more. "At least one of the following" or similar expressions means any combination of these items, including any combination of single or multiple items. For example, at least one of a, b, or c can mean a, b, c, a-b, a-c, b-c, or a-b-c, where a, b, and c can be single or multiple.

[0075] It should be understood that in various embodiments of the present application, the size of the sequence number of the above-described processes does not mean the order of execution, and the execution order of the processes should be determined by their functions and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0076] Those skilled in the art can clearly understand that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be realized by electronic hardware or a combination of computer software and electronic hardware. Whether the functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.

[0077] Those skilled in the art can clearly understand that, for the convenience and brevity of the description, the specific working processes of the above-described system, device and unit can refer to the corresponding processes in the foregoing method embodiments, which will not be repeated here.

[0078] In several embodiments provided in the present application, it should be understood that the disclosed system, device and method can be implemented in other ways. For example, the above-described device embodiments are only schematic, for example, the division of the units is only a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some interface, device or unit, and can be electrical, mechanical or other forms.

[0079] The units described as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, that is, they can be located in one place, or can be distributed on a plurality of network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment.

[0080] In addition, each functional unit in each embodiment of the present application can be integrated into a processing unit, or each unit can exist physically, or two or more units can be integrated into one unit.

[0081] If the functions are implemented in the form of software function units and sold or used as independent products, they can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application essentially or the parts that contribute to the prior art or parts of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various media that can store program codes.

[0082] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1.A method for low-altitude airspace permission authentication and management based on a blockchain, characterized in that, The application comprises the following steps: Collecting public shared data corresponding to different nodes, performing clustering data storage, and forming blockchain node shared stub data; Obtaining plan application information, combining the blockchain node shared stub data for authentication analysis, and forming authentication analysis result information; According to the authentication analysis result information, collecting real-time flight data, and combining the plan application information for monitoring analysis, forming real-time monitoring data; Performing extraction processing on the real-time monitoring data management information for data recording, forming flight real-time recording data. 2.The blockchain-based low-altitude airspace permission authentication and management method of claim 1, wherein, The collection of public shared data corresponding to different nodes, the clustering data storage, and the formation of the blockchain node shared stub data comprise the following steps: According to the public shared data, extracting public shared authentication plans to form a public shared authentication plan set; According to the public shared data, extracting public shared application plans to form a public shared application plan set; Respectively performing sequential clustering processing on the public shared authentication plan set and the public shared application plan set to form the blockchain node shared stub data. 3.The blockchain-based low-altitude airspace permission authentication and management method of claim 2, wherein, The sequential clustering processing on the public shared authentication plan set and the public shared application plan set to form the blockchain node shared stub data comprises the following steps: According to the operation start time of the aircraft plan, the different flight plans in the public shared authentication plan set are numbered and sorted in time dimension to form a public shared ordered authentication plan set; According to the application time of the flight plan, the different flight plans in the public shared application plan set are numbered and sorted in time dimension to form a public shared ordered application plan set; The public shared ordered authentication plan set and the public shared ordered application plan set are combined to form the blockchain node shared stub data. 4.The blockchain-based low-altitude airspace permission authentication and management method of claim 3, wherein, The acquisition of plan application information, the combination of the blockchain node shared stub data for authentication analysis, and the formation of authentication analysis result information comprise the following steps: Obtaining the plan application information, respectively extracting the object encryption segment and the flight plan encryption segment; Decrypting the extracted object encryption segment and the flight plan encryption segment to form application object information and object flight plan information, respectively; According to the blockchain node shared stub data, combining the object flight plan information for authentication analysis to form the authentication analysis result data. 5.The blockchain-based low-altitude airspace permission authentication and management method of claim 4, wherein, The decryption processing of the extracted object encryption segment and the flight plan encryption segment to form the application object information and the object flight plan information, respectively, comprises the following steps: Obtaining the identity order decoding of the node corresponding to the node public decryption function, and performing the following identity decoding on the object encryption segment: Removing the order decoding from the object encryption segment to form application object code information; Performing recognition information conversion on the application object code information to form the application object information; According to the application object information, determining the object decoding function on the corresponding node, and according to the object decoding function, obtaining the object application order decoding to perform the following application content decoding on the flight plan encryption segment: Removing the object application order decoding from the flight plan encryption segment to form object application content code information; The object application content code information is subjected to identification information conversion to form the object flight plan information. 6.The blockchain-based low-altitude airspace permission authentication and management method of claim 5, wherein, The authentication analysis result data is formed by authenticating analysis according to the object flight plan information and the blockchain node shared stub data, including: According to the object flight plan information, the application time point, the application plan time period, and the application plan space range are extracted to form an application data group; According to the blockchain node shared stub data, the authentication plan time period and the authentication plan space range corresponding to different flight plans in the publicly shared ordered authentication plan set are extracted to form an authentication data group corresponding to different flight plans; According to the blockchain node shared stub data, the application ordered time point, the application ordered plan time period, and the application ordered plan space range corresponding to different flight plans in the publicly shared ordered application plan set are extracted to form an application ordered data group corresponding to different flight plans; The application data group is compared with different authentication data groups in the time period and the space range, including: If the authentication plan time period and the application plan time period do not coincide, and the authentication plan space range and the application plan space range do not coincide, authentication comparison time coincidence information is formed; If the authentication plan time period and the application plan time period coincide, but the authentication plan space range and the application plan space range do not coincide, authentication comparison space coincidence information is formed; If the authentication plan time period and the application plan time period do not coincide, but the authentication plan space range and the application plan space range coincide, authentication comparison time coincidence information is formed; If the authentication plan time period and the application plan time period coincide, and the authentication plan space range and the application plan space range coincide, authentication comparison coincidence information is formed; When the authentication comparison normal information is formed, the application data group is compared with different application ordered data groups, including: All application ordered data groups in which the application ordered time point is earlier than the application time point are designated as previous application ordered data groups; If the authentication plan time period and the application plan time period do not coincide, and the authentication plan space range and the application plan space range do not coincide, authentication pass information is formed, otherwise authentication fail information is formed. 7.The blockchain-based low-altitude airspace permission authentication and management method of claim 6, wherein, According to the authentication analysis result information, real-time flight data is collected, and monitoring analysis is performed in combination with the plan application information to form real-time monitoring data, including: When the authentication analysis result information is the authentication pass information, different real-time discrete record time points and corresponding real-time discrete position coordinates are extracted from the real-time flight data; According to the real-time discrete recording time point, a real-time flight time interval is determined and compared with the application plan time period. If the real-time flight time interval belongs to the application plan time period, real-time time monitoring normal information is formed, otherwise, real-time time overrun information is formed; performing time-dimension based path trajectory analysis according to the real-time discrete position coordinates to form a real-time flight trajectory curve ; According to the real-time flight trajectory curve And combined with the application plan space range, the range monitoring analysis based on the minimum turning radius is carried out, and the range monitoring result data is formed. 8.The blockchain-based low-altitude airspace permission authentication and management method of claim 7, wherein, The real-time flight trajectory curve is determined according to the flight trajectory curve The range monitoring analysis based on the minimum turning radius is performed in combination with the application plan space range, and a range monitoring result data is formed, including: According to the real-time flight trajectory curve , a corresponding trajectory curvature radius is determined According to the real-time flight trajectory curve the trajectory curvature radius and the application plan space range, the following range monitoring analysis is performed: for the real-time flight trajectory curve forms job range overrun information if the application plan space range is exceeded; For the real-time flight trajectory curve If the application plan space range is not exceeded, and there is no trajectory point with a shortest distance to the boundary of the application plan space range not greater than the trajectory checking distance Form a job range normal information: for the real-time flight trajectory curve if the shortest distance between the trajectory point and the boundary of the application plan space range is not greater than the trajectory check distance then: determining that a shortest distance from a boundary of the application plan space range is not greater than a trajectory checking distance a trajectory segment of the trajectory segment set is labeled as a risk trajectory segment, and a risk trajectory segment curvature radius corresponding to the risk trajectory segment is extracted n represents a number of different risk trajectory segments For each of the risk trajectory segments, if the following conditions are met ≤ ≤ , the operation range normal information is formed, wherein, is the minimum turning radius of the aircraft, is the turning environmental impact factor; For each of the risk trajectory segments, if any of the risk trajectory segments does not satisfy ≤ ≤ , forming an operation range overrun information. 9.The blockchain-based low-altitude airspace permission authentication and management method of claim 8, wherein, The extraction processing of the management information of the real-time monitoring data for data recording forms flight real-time recording data, including: The real-time monitoring data is stored on the corresponding node, and the application object and flight plan information in the real-time monitoring data are extracted; The application object and the flight plan information are sent to all nodes as public shared data for storage. 10.A low-altitude airspace permission authentication and management system based on blockchain, adopting the low-altitude airspace permission authentication and management method based on blockchain in any one of claims 1-9, characterized in that, Including: A data acquisition unit is arranged on each node of the blockchain, which is used to acquire public shared data from different nodes, plan application information for the corresponding node, and real-time flight data; A data storage unit is arranged on each node of the blockchain, which is used to cluster and store the public shared data from different nodes acquired by the data acquisition unit to form blockchain node shared stub data, and store the real-time monitoring data formed by the corresponding node; An authentication analysis unit is arranged on each node of the blockchain, which is used to authenticate and analyze the plan application information of the corresponding node to form authentication analysis result information; A monitoring analysis unit is arranged on each node of the blockchain, which is used to acquire the real-time flight data collected by the data acquisition unit on the basis of the analysis result of the authentication analysis unit, and perform monitoring analysis to form real-time monitoring data.