A low-altitude airspace permission authentication and management method and system based on a blockchain
By using blockchain technology to share stub data and perform authentication analysis in low-altitude airspace management, the performance bottlenecks and data security issues of centralized management systems have been resolved, enabling efficient and reliable airspace access authentication and management.
Patent Information
- Application Number
- CN202511813251.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-04
- Publication Date
- 2026-08-25
- Estimated Expiration
- 2045-12-04
AI Technical Summary
Traditional centralized airspace management systems are prone to performance bottlenecks and single-point failure risks when dealing with massive, high-frequency, and multi-entity drone operations, and they also suffer from insufficient data security and management efficiency.
Using blockchain technology for low-altitude airspace access authentication and management, the system avoids tampering with planned data, tracks the compliance of flight plans in real time, and forms a distributed data processing system among nodes by sharing and analyzing stub data from different nodes on the blockchain.
It improves the efficiency and stability of low-altitude airspace management, avoids the problems of large data volume and security in centralized management, and ensures the integrity and reliability of data.
Smart Images

Figure CN121640771B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of blockchain technology, and more specifically, to a blockchain-based method and system for low-altitude airspace access authentication and management. Background Technology
[0002] With the gradual opening of low-altitude airspace, the number of low-altitude operations is increasing, which is also putting pressure on the management of low-altitude airspace. Traditional centralized airspace management systems are prone to performance bottlenecks and single-point failure risks when dealing with massive, high-frequency, and multi-entity drone operations.
[0003] Blockchain technology is a decentralized distributed ledger that is block-based, immutable, secure, and reliable. It combines distributed storage, peer-to-peer transmission, consensus mechanisms, and cryptography to record transactions and information through a continuously growing chain of data blocks, ensuring data security and transparency. Applying blockchain technology to low-altitude airspace management could further optimize management capabilities and efficiency. However, establishing a sound blockchain-based management system is a crucial issue that needs to be considered.
[0004] Therefore, designing a blockchain-based method and system for low-altitude airspace access authentication and management, and leveraging the advantages of blockchain to achieve efficient management and optimize management capabilities for low-altitude airspace, is an urgent problem to be solved. Summary of the Invention
[0005] The purpose of this invention is to provide a blockchain-based method for low-altitude airspace access authentication and management. By utilizing flight plan data publicly available on different nodes of the blockchain, each node can maintain a stub of the flight plan information across the entire blockchain to prevent tampering with the plan data. Different nodes manage their respective plan application information and, based on the shared stub, determine whether the applied plan conflicts with existing plans, thus ensuring that the approved plans are conflict-free. Real-time tracking of discrete record data uploaded during flight operations is performed based on the plan execution time to ensure compliance with the flight plan and prevent deviations. After aircraft operations are completed, the data is stored on the corresponding node and shared with other nodes as a stub, facilitating traceability of the recorded data across all nodes. Using blockchain for low-altitude airspace access authentication and management avoids the problems of large data volumes and low data security associated with centralized management, while significantly improving management efficiency and capabilities, resulting in more stable and reliable data.
[0006] The present invention also aims to provide a blockchain-based low-altitude airspace access authorization and management system. This system achieves distributed data processing and storage through different functional units on each node of the blockchain. The data acquisition unit completes the collection of flight data, corresponding application data, and real-time flight data. The data storage unit stores shared data and monitoring data. The authentication and analysis unit performs authentication and analysis on the submitted flight plan applications. The monitoring and analysis unit collects and monitors real-time operational data of the certified flight plans. The different functional units form a complete data processing system, which is the necessary material basis for realizing low-altitude airspace access authorization and management. The different nodes form a complete blockchain system, which ensures data integrity while improving management capabilities and efficiency, and greatly improves the form of authentication and management.
[0007] In a first aspect, the present invention provides a blockchain-based method for low-altitude airspace access authentication and management, comprising: collecting publicly shared data corresponding to different nodes, performing clustered data storage to form blockchain node shared stub data; obtaining plan application information, combining it with the blockchain node shared stub data for authentication analysis to form authentication analysis result information; collecting real-time flight data based on the authentication analysis result information, and combining it with plan application information for monitoring and analysis to form real-time monitoring data; and extracting and processing the real-time monitoring data to form real-time flight record data.
[0008] In this invention, the method utilizes flight plan data publicly available on different nodes of a blockchain. Each node can maintain a stub of the flight plan information across the entire blockchain to prevent tampering with the plan data. Different nodes manage their respective plan application information and, based on the shared stub, determine whether the applied plan conflicts with existing plans, thus ensuring that the approved plans are conflict-free. Real-time tracking of discrete record data uploaded during flight operations is performed based on the plan execution time to ensure consistency with the flight plan and prevent deviations. After aircraft operations are completed, the data is stored on the corresponding node and shared with other nodes as a stub, facilitating traceability of the recorded data across all nodes. Using blockchain for low-altitude airspace permission authentication and management avoids the problems of large data volumes and low data security associated with centralized management, while significantly improving management efficiency and capabilities, resulting in more stable and reliable data.
[0009] One possible implementation involves collecting publicly shared data from different nodes, performing clustered data storage, and forming shared stub data for blockchain nodes. This includes: extracting publicly shared authentication plans from the publicly shared data to form a set of publicly shared authentication plans; extracting publicly shared application plans from the publicly shared data to form a set of publicly shared application plans; and performing sequential clustering on the publicly shared authentication plan set and the publicly shared application plan set to form shared stub data for blockchain nodes.
[0010] In this invention, the aircraft plan data shared by different nodes in the blockchain needs to be stored on each node to provide comprehensive data reference for the corresponding flight plan authentication and management. Since this stored data is primarily used for flight plan authentication and management, the parameters involved in authentication and management need to be considered. Therefore, two datasets are distinguished: one for aircraft plans that have completed review and authentication, and the other for flight plans currently applying for authentication. It can be understood that the reviewed and authenticated flight plans are mainly used to provide authentication services for flight plans currently applying for authentication to determine if there are any conflicts in the plan content. For flight plans currently applying for authentication, not only conflicts in plan content need to be considered, but also the application time, with authentication proceeding in a first-come, first-served order to avoid confusion in the authentication process. Therefore, the two different datasets need to be stored separately to prevent data confusion from hindering the authentication process when referring to these two datasets later.
[0011] As one possible implementation, sequential clustering is performed on the publicly shared authentication plan set and the publicly shared application plan set to form shared stub data for blockchain nodes. This includes: numbering and sorting different flight plans in the publicly shared authentication plan set according to the start time of the flight plan in chronological order to form a publicly shared ordered authentication plan set; numbering and sorting different flight plans in the publicly shared application plan set according to the application time of the flight plan in chronological order to form a publicly shared ordered application plan set; and combining the publicly shared ordered authentication plan set and the publicly shared ordered application plan set to form shared stub data for blockchain nodes.
[0012] In this invention, the stub data of each node on the blockchain contains flight plan data from the entire blockchain. Since the completeness and certification of flight plans affect subsequent applications for new flight plans, the stub data needs to be clustered into certified and uncertified categories. Furthermore, to facilitate efficient processing and analysis of these two types of flight plan data, reasonable ordered clustering is necessary. For certified flight plans, the timing and corresponding region are crucial; for uncertified flight plans, the application date is paramount, followed by the application content, the plan date, and the region. Therefore, the two different types of flight plan data are sequentially clustered according to different key information points, forming sequentially clustered data that can be efficiently referenced later. It should also be noted that the stub data mainly includes object identity information, flight plan application date, plan date, and the region involved. This information provides a relatively complete reference for all nodes to perform targeted queries on the stub data, facilitating quick location of data record nodes containing richer information. Simultaneously, the simplification of the stub data avoids excessively large data storage by nodes, which would increase resource demands and unnecessary costs.
[0013] One possible implementation involves obtaining plan application information and performing authentication analysis using shared stub data from blockchain nodes to generate authentication analysis results. This includes: obtaining plan application information and extracting the encrypted segment of the object and the encrypted segment of the flight plan; decrypting the extracted encrypted segment of the object and the encrypted segment of the flight plan to generate application object information and object flight plan information, respectively; and performing authentication analysis based on shared stub data from blockchain nodes and the object flight plan information to generate authentication analysis results.
[0014] In this invention, different nodes in the blockchain can handle flight plan applications submitted by objects within different ranges, thus alleviating the authentication processing pressure of centralized management. For plan applications obtained from nodes, to ensure the security of data uploads and information on the blockchain, data is transmitted in encrypted form. Therefore, it is necessary to first decrypt the submitted flight plan application to extract the object and the corresponding flight plan application data, and then combine this with the node stub data to perform authentication analysis to determine whether the flight plan meets the requirements.
[0015] As one possible implementation, the encrypted segments of the extracted object and the encrypted segments of the flight plan are decrypted to form application object information and object flight plan information, respectively. This includes: obtaining the identity sequence decoding of the public decryption function of the corresponding node; performing identity decoding on the encrypted segment of the object in the following manner: removing the sequence decoding from the encrypted segment of the object to form application object coded information; performing identification information conversion on the coded information of the application object to form application object information; determining the object decoding function on the corresponding node based on the application object information, and obtaining the object application sequence decoding based on the object decoding function; performing application content decoding on the encrypted segment of the flight plan in the following manner: removing the object application sequence decoding from the encrypted segment of the flight plan to form object application content coded information; performing identification information conversion on the coded information of the object application content to form object flight plan information.
[0016] In this invention, the flight plan application data sent by an object to the corresponding node is encrypted to ensure data transmission security. Therefore, after receiving the transmitted information, the node needs to decrypt it to obtain detailed flight plan application information, thus providing data reference for subsequent application authentication and management. The decryption method used in this application is divided into two parts: one part decrypts the object's identity information, and the other part decrypts the object's flight plan information. To further improve data confidentiality, the decryption of the object's identity information and the decryption of the object's flight plan information are linked; only after the object's identity information is correctly and completely decrypted can the decryption of the object's flight plan information be completed. This application provides a decryption method where different nodes are configured with the flying objects as the management scope. Each node manages a specific number of objects. The object scope can be adjusted periodically to improve data security. Each node provides a random function to decrypt the identity information of the requesting object. The decryption method involves the random function generating a value upon receiving a request. This generated value exhibits a regularity in terms of the number of operations performed; if two identical random functions are executed the same number of times, their generated values will be equal. Utilizing this regularity for decryption and encryption ensures that only the requesting object and the node can access the password information. To ensure that the randomly generated value of the node matches the value of the corresponding random function on the requesting object, two methods can be considered: the node uses a counter to record the number of operations performed by the random function, and when the requesting object needs to submit a request... When applying, the node first obtains the node's count information. Then, based on this count information, a random function on the application object is executed a corresponding number of times. This yields the function value generated by the next execution of the random function on the node. This function value is used to encrypt the application object's information. The encrypted object's identity information is then decrypted by the node performing a new operation on its random function to obtain the function value that matches the encryption value. Alternatively, the node and the application object agree on a time period and time interval, which can be managed as a function. Within the agreed time period, both the node's and the application object's random functions execute at the specified time intervals. When the application object needs to submit an application, it obtains the result of the random function operation closest to the application submission time, encrypts it, and adds time information. After obtaining the data, the node extracts the function value generated by the random function operation at the corresponding time point based on the time information and decrypts it. Of course, decryption methods are also diverse. First, the encryption and decryption methods between the node and the application object are agreed upon. Then, when decrypting, the node uses the agreed decryption method to exclude the function value of the random function and finally converts it into the application object information.After decrypting the object's identity information, the node needs to determine the object decoding function set on the node that matches the object's identity, and then use the object decoding function to decrypt the encrypted flight plan application information. Of course, the encryption and decryption methods for flight plan application information are the same as those for object identity information; only the random function value set for encrypting flight plan data differs for different application objects.
[0017] As one possible implementation, authentication analysis is performed based on shared stub data from blockchain nodes, combined with object flight plan information, to form authentication analysis result data. This includes: extracting the application time point, application plan time period, and application plan spatial range from the object flight plan information to form an application data group; extracting the authentication plan time period and authentication plan spatial range corresponding to different flight plans in the publicly shared ordered authentication plan set from the shared stub data from blockchain nodes to form authentication data groups corresponding to different flight plans; and extracting the application ordered time point, application ordered plan time period, and application ordered plan spatial range corresponding to different flight plans in the publicly shared ordered application plan set from the shared stub data from blockchain nodes to form application ordered data groups corresponding to different flight plans. The application data groups are then compared with different authentication data groups in terms of time period and spatial range as follows: if for any authentication data group, there is no overlap between the authentication plan time period and the application plan time period, and no overlap between the authentication plan spatial range and the application plan spatial range, then an authentication pair is formed. The comparison process is as follows: If a certification data set exists, and the planned certification time period overlaps with the planned application time period, but the planned certification spatial range does not overlap with the planned application spatial range, then a certification comparison time overlap is formed. If a certification data set exists, and the planned certification time period does not overlap with the planned application time period, but the planned certification spatial range overlaps with the planned application spatial range, then a certification comparison spatial overlap is formed. If a certification data set exists, and the planned certification time period overlaps with the planned application time period, and the planned certification spatial range overlaps with the planned application spatial range, then a certification comparison overlap is formed. When the comparison analysis results in a normal certification comparison, the application data set is compared with different ordered application data sets as follows: All ordered application data sets whose ordered application time points are earlier than the application time points are identified and marked as the earlier ordered application data sets. If, for any earlier ordered application data set, there is no overlap between the planned certification time period and the planned application time period, and the planned certification spatial range overlaps with the planned application spatial range, then certification pass information is formed; otherwise, certification fail information is formed.
[0018] In this invention, the certification analysis primarily determines whether the proposed flight plan conflicts with existing flight plans in terms of both time and spatial scope. Since existing flight plans include those already certified and approved, as well as those currently undergoing certification, the methods for comparing and analyzing this data differ. For certified plans, the implementation time and spatial scope can be directly compared. If different nodes process certification requests according to application regions, then only the local certification plan data at the node needs to be compared, significantly reducing the amount of data required. However, for plans currently undergoing certification, to avoid conflicts, they are reviewed on a first-come, first-served basis. Therefore, the comparison analysis requires first identifying the submitted applications and then comparing the time and spatial scope of these previously submitted applications. The comparison analysis of these two types of plan data follows a progressive relationship; only after the data comparison of existing flight plans passes is the comparison of the application data performed. This also improves the efficiency of the certification comparison analysis and reduces the amount of data processed.
[0019] As one possible implementation, based on the certification analysis results, real-time flight data is collected and combined with the plan application information for monitoring and analysis to form real-time monitoring data. This includes: when the certification analysis result is "certification passed," extracting different real-time discrete recording time points and corresponding real-time discrete position coordinates from the real-time flight data; determining the real-time flight time interval based on the real-time discrete recording time points and comparing it with the applied plan time period; if the real-time flight time interval falls within the applied plan time period, generating "real-time time monitoring normal" information; otherwise, generating "real-time time exceeding limit" information; and performing time-dimensional path trajectory analysis based on the real-time discrete position coordinates to generate a real-time flight trajectory curve. According to the real-time flight trajectory curve Furthermore, based on the spatial range of the application plan, range monitoring analysis was conducted to generate range monitoring result data.
[0020] In this invention, monitoring and analysis primarily involves real-time tracking of aircraft operations to monitor whether they are conducted within the planned timeframe and spatial scope. The data required for real-time monitoring of flight operations comes from discretely collected data uploaded by the aircraft. Considering that real-time monitoring mainly covers both time and space aspects, it is necessary to compare and analyze the collected discrete data with the planned data separately. For time data, it is only necessary to combine the collected discrete time points to determine the corresponding time period of the operation to judge whether it is within the planned timeframe. For spatial data, discrete position coordinate data is used to form trajectory data to determine whether the trajectory exceeds the planned spatial scope.
[0021] As one possible implementation method, based on real-time flight trajectory curves In conjunction with the proposed spatial range, range monitoring analysis based on the minimum turning radius is conducted to generate range monitoring results data, including: data based on real-time flight trajectory curves. Determine the corresponding trajectory radius of curvature. According to the real-time flight trajectory curve Trajectory curvature radius In addition to the planned spatial range, the following range monitoring and analysis methods will be used for the real-time flight trajectory curve. If the space exceeds the planned area, it will generate an "operational scope exceeding limit" message; for real-time flight trajectory curves If it does not exceed the application plan space range, and the shortest distance between the trajectory point and the boundary of the application plan space range is not greater than the trajectory verification distance. This generates normal information about the operational range: for real-time flight trajectory curves. If the application does not exceed the planned spatial range, but the shortest distance between the trajectory point and the boundary of the planned spatial range is not greater than the trajectory verification distance. Then: the shortest distance from the boundary of the application plan's spatial range is determined to be no greater than the trajectory verification distance. The trajectory segments are labeled as risk trajectory segments, and the radius of curvature of the corresponding risk trajectory segments is extracted. , where n represents the number of different risk trajectory segments; for each risk trajectory segment, if all satisfy... ≤ ≤ This will generate normal information for the work scope, among which, The minimum turning radius of the aircraft. The turning environment is an influencing factor; for each risk trajectory segment, if any risk trajectory segment does not satisfy... ≤ ≤ This generates information indicating that the work scope has exceeded the limit.
[0022] In this invention, determining whether a flight trajectory exceeds the planned spatial range primarily involves identifying whether the trajectory is within the planned spatial range or if there is a risk of exceeding it. Whether it's within the planned range can be directly judged by comparing the trajectory curves. However, the risk of exceeding the planned range arises because the nodes collect discrete position coordinate data, and trajectory fitting is merely a simple continuous fitting analysis, which doesn't fully represent the actual trajectory. For safety, trajectory positions close to the planned spatial range boundary need to be analyzed to determine if a short-term exceedance might occur due to an insufficient turning radius. Therefore, the exceedance risk analysis uses the trajectory verification distance as a reference. If a minimum distance meets the trajectory verification distance requirement, it's necessary to determine whether the minimum turning radius is less than the trajectory verification distance. Of course, environmental factors and the aircraft's minimum turning radius capability also need to be considered, as environmental factors also affect the aircraft's minimum turning radius capability. Therefore, it is necessary to determine whether the radius of curvature of the risk trajectory segment is achievable by the aircraft under environmental influence conditions, and whether it will not reach the trajectory verification distance. For environmental factors, namely the turning environment impact factor, it can be obtained based on big data analysis of the turning radius of the operational aircraft under different environmental conditions. The minimum turning radius of the aircraft can be obtained from the aircraft's design parameters. Of course, this parameter needs to be reported to the node when applying for the plan.
[0023] As one possible implementation, the real-time monitoring data is extracted and processed to form real-time flight record data, including: storing the real-time monitoring data on the corresponding nodes and extracting the application object and flight plan information from the real-time monitoring data; and sending the application object and flight plan information as publicly shared data to all nodes for storage.
[0024] In this invention, after a flight operation is completed, whether it is terminated due to exceeding the planned scope or successfully completed, the real-time monitoring data needs to be stored. This storage method involves storing the real-time monitoring data under the corresponding node. The real-time monitoring data includes the requested plan data, the data collected in real-time, and the analysis data based on the collected data. To ensure that other nodes can trace or connect to the real-time monitoring data, the application object and flight plan information are provided to other nodes as publicly shared data. Other nodes then obtain and store this data to form corresponding node-shared stub data. This ensures that all nodes in the entire blockchain have traceability and connection to any flight data. This reduces data storage resource consumption while also improving data security and reliability.
[0025] Secondly, this invention provides a blockchain-based low-altitude airspace access authorization and management system, comprising: a data acquisition unit, deployed on each node of the blockchain, for acquiring publicly shared data from different nodes, plan application information for the corresponding nodes, and real-time flight data; a data storage unit, deployed on each node of the blockchain, for clustering and storing the publicly shared data acquired by the data acquisition unit from different nodes to form shared stub data of the blockchain nodes, and storing the real-time monitoring data generated by the corresponding nodes; an authentication analysis unit, deployed on each node of the blockchain, for performing authentication analysis on the plan application information of the corresponding nodes to generate authentication analysis result information; and a monitoring analysis unit, deployed on each node of the blockchain, for acquiring the real-time flight data acquired by the data acquisition unit based on the analysis results of the authentication analysis unit, performing monitoring analysis, and generating real-time monitoring data.
[0026] In this invention, the system achieves distributed data processing and storage through different functional units on each node of the blockchain. The data acquisition unit completes the collection of flight data, corresponding application data, and real-time flight data. The data storage unit stores shared data and monitoring data. The authentication and analysis unit performs authentication and analysis on the submitted flight plan applications. The monitoring and analysis unit collects and monitors real-time operational data of the certified flight plans. The different functional units form a complete data processing system, which is the necessary material basis for realizing low-altitude airspace permission authentication and management. The different nodes form a complete blockchain system, which ensures data integrity while improving management capabilities and efficiency, and greatly improves the form of authentication and management.
[0027] The beneficial effects of the blockchain-based low-altitude airspace access authentication and management method and system provided by this invention are as follows:
[0028] This method utilizes publicly available flight plan data from different nodes on a blockchain. Each node can maintain a stub of the flight plan information across the entire blockchain to prevent data tampering. Different nodes manage their respective plan application information and use the shared stub to determine if any applied plans conflict with existing plans, thus ensuring that approved plans are conflict-free. Real-time tracking of flight operation data uploaded during plan execution is performed to ensure consistency with the flight plan and prevent deviations. After aircraft operations are completed, the data is stored on the corresponding node and shared with other nodes as a stub, facilitating data traceability across all nodes. Using blockchain for low-altitude airspace access authentication and management avoids the problems of large data volumes and low data security associated with centralized management, while significantly improving management efficiency and capabilities, resulting in more stable and reliable data.
[0029] This system achieves distributed data processing and storage through different functional units on each node of the blockchain. The data acquisition unit collects flight data, corresponding application data, and real-time flight data. The data storage unit stores shared data and monitoring data. The authentication and analysis unit performs authentication and analysis on the submitted flight plan applications. The monitoring and analysis unit collects and monitors real-time operational data for the authenticated flight plans. The different functional units form a complete data processing system, which is the necessary material basis for realizing low-altitude airspace permission authentication and management. The different nodes form a complete blockchain system, which ensures data integrity while improving management capabilities and efficiency, and greatly improves the form of authentication and management. Attached Figure Description
[0030] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the embodiments of the present invention will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as a limitation on the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0031] Figure 1 A flowchart illustrating the steps of a blockchain-based low-altitude airspace access authentication and management method provided in this embodiment of the invention;
[0032] Figure 2 This is a schematic diagram of a blockchain-based low-altitude airspace access authentication and management system provided in an embodiment of the present invention. Detailed Implementation
[0033] The technical solutions of the present invention will now be described with reference to the accompanying drawings in the embodiments of the present invention.
[0034] With the gradual opening of low-altitude airspace, the number of low-altitude operations is increasing, which is also putting pressure on the management of low-altitude airspace. Traditional centralized airspace management systems are prone to performance bottlenecks and single-point failure risks when dealing with massive, high-frequency, and multi-entity drone operations.
[0035] Blockchain technology is a decentralized distributed ledger that is block-based, immutable, secure, and reliable. It combines distributed storage, peer-to-peer transmission, consensus mechanisms, and cryptography to record transactions and information through a continuously growing chain of data blocks, ensuring data security and transparency. Applying blockchain technology to low-altitude airspace management could further optimize management capabilities and efficiency. However, establishing a sound blockchain-based management system is a crucial issue that needs to be considered.
[0036] refer to Figures 1-2 This invention provides a blockchain-based method for low-altitude airspace access authentication and management. This method utilizes flight plan data publicly available on different nodes of the blockchain. Each node can maintain a stub of the flight plan information across the entire blockchain to prevent tampering with the plan data. Different nodes manage their respective plan application information and use the shared stub to determine if the applied plan conflicts with existing plans, thus ensuring that approved plans are conflict-free. Real-time tracking of discrete record data uploaded during flight operations is performed based on the plan execution time to ensure consistency with the flight plan and prevent deviations. After aircraft operations are completed, the data is stored on the corresponding node and shared with other nodes as a stub, facilitating traceability of the recorded data across all nodes. Using blockchain for low-altitude airspace access authentication and management avoids the problems of large data volumes and low data security associated with centralized management, while significantly improving management efficiency and capabilities, resulting in more stable and reliable data.
[0037] A blockchain-based method for low-altitude airspace access authentication and management specifically includes the following steps:
[0038] S1: Collect publicly shared data from different nodes, perform clustered data storage, and form shared stub data for blockchain nodes.
[0039] Collect publicly shared data from different nodes, perform clustered data storage, and form blockchain node shared stub data. This includes: extracting publicly shared certification plans from the publicly shared data to form a publicly shared certification plan set; extracting publicly shared application plans from the publicly shared data to form a publicly shared application plan set; and performing sequential clustering processing on the publicly shared certification plan set and the publicly shared application plan set to form blockchain node shared stub data.
[0040] The aircraft plan data shared by different nodes in the blockchain needs to be stored on each node to provide comprehensive data reference for the corresponding flight plan certification and management. Since this stored data is primarily used for flight plan certification and management, the parameters involved in certification and management need to be considered. Therefore, two datasets are distinguished: one for flight plans that have completed review and certification, and the other for flight plans currently applying for certification. The review and certification of flight plans is mainly used to verify whether there are any conflicts in the content of the flight plans currently applying for certification. For flight plans currently applying for certification, not only conflicts in the content of the plans need to be considered, but also the application time, with certification proceeding in a first-come, first-served order to avoid confusion in the certification process. Therefore, the two different datasets need to be stored separately to prevent data confusion from hindering the certification process later.
[0041] Sequential clustering is performed on the publicly shared certification plan set and the publicly shared application plan set to form shared stub data for blockchain nodes. This includes: for different flight plans in the publicly shared certification plan set, numbering and sorting them according to the start time of the flight plan operation in chronological order to form a publicly shared ordered certification plan set; for different flight plans in the publicly shared application plan set, numbering and sorting them according to the application time of the flight plan in chronological order to form a publicly shared ordered application plan set; and combining the publicly shared ordered certification plan set and the publicly shared ordered application plan set to form shared stub data for blockchain nodes.
[0042] The stub data of each node on the blockchain contains flight plan data from the entire blockchain. Since the completeness and certification of flight plans affect subsequent applications for new flight plans, the stub data needs to be clustered into certified and uncertified categories. Furthermore, to facilitate efficient processing and analysis of both types of flight plan data, reasonable ordered clustering is necessary. For certified flight plans, the timing and corresponding region are crucial; for uncertified flight plans, the application date is paramount, followed by the application content, the plan date, and the region. Therefore, the two types of flight plan data are clustered sequentially according to different key information points, forming sequential clustered data that can be efficiently referenced later. It should also be noted that the stub data mainly includes object identity information, flight plan application date, plan date, and the region involved. This information provides a relatively complete reference for all nodes to perform targeted queries on the stub data, facilitating quick identification of data record nodes containing richer information. Simultaneously, the simplification of the stub data avoids excessively large data storage by nodes, which would increase resource demands and unnecessary costs.
[0043] S2: Obtain the application information for the plan, combine it with the shared stub data of the blockchain nodes to perform authentication analysis, and generate authentication analysis result information.
[0044] The process involves obtaining application information, combining it with shared stub data from blockchain nodes for authentication analysis, and generating authentication analysis results. This includes: obtaining application information and extracting the encrypted segment of the object and the encrypted segment of the flight plan; decrypting the extracted encrypted segment of the object and the encrypted segment of the flight plan to generate application object information and object flight plan information, respectively; and conducting authentication analysis based on shared stub data from blockchain nodes and the object flight plan information to generate authentication analysis results.
[0045] In a blockchain, different nodes can handle flight plan applications from objects within different scopes, thus alleviating the authentication processing pressure of centralized management. To ensure the security of data uploads and information on the blockchain, flight plan applications obtained from nodes are transmitted in encrypted form. Therefore, it is necessary to first decrypt the submitted flight plan application to extract the object and the corresponding flight plan application data, and then combine this data with the node's stub data to perform authentication analysis to determine whether the flight plan meets the requirements.
[0046] The extracted encrypted object segment and flight plan encrypted segment are decrypted to form application object information and object flight plan information, respectively. This includes: obtaining the identity sequence decoding of the public decryption function corresponding to the node; performing identity decoding on the encrypted object segment in the following ways: removing the sequence decoding from the encrypted object segment to form application object encoded information; performing identification information conversion on the encoded application object information to form application object information; determining the object decoding function on the corresponding node based on the application object information, and obtaining the object application sequence decoding based on the object decoding function; performing application content decoding on the encrypted flight plan segment in the following ways: removing the object application sequence decoding from the encrypted flight plan segment to form object application content encoded information; performing identification information conversion on the encoded object application content information to form object flight plan information.
[0047] For flight plan application data sent by an object to the corresponding node, the transmitted information is encrypted to ensure data security. Therefore, after receiving the transmitted information, the node needs to decrypt it to obtain detailed flight plan application information, thus providing data reference for subsequent application authentication and management. The decryption method adopted in this application is divided into two parts: one part decrypts the object's identity information, and the other part decrypts the object's flight plan information. Of course, to further improve data confidentiality, the decryption of the object's identity information and the decryption of the object's flight plan information are linked. Only after the object's identity information is correctly and completely decrypted can the decryption of the object's flight plan information be completed. This application provides a decryption method where different nodes are configured with the flying objects as the management scope. Each node manages a specific number of objects. The object scope can be adjusted periodically to improve data security. Each node provides a random function to decrypt the identity information of the requesting object. The decryption method involves the random function generating a value upon receiving a request. This generated value exhibits a regularity in terms of the number of operations performed; if two identical random functions are executed the same number of times, their generated values will be equal. Utilizing this regularity for decryption and encryption ensures that only the requesting object and the node can access the password information. To ensure that the randomly generated value of the node matches the value of the corresponding random function on the requesting object, two methods can be considered: the node uses a counter to record the number of operations performed by the random function, and when the requesting object needs to submit a request... When applying, the node first obtains the node's count information. Then, based on this count information, a random function on the application object is executed a corresponding number of times. This yields the function value generated by the next execution of the random function on the node. This function value is used to encrypt the application object's information. The encrypted object's identity information is then decrypted by the node performing a new operation on its random function to obtain the function value that matches the encryption value. Alternatively, the node and the application object agree on a time period and time interval, which can be managed as a function. Within the agreed time period, both the node's and the application object's random functions execute at the specified time intervals. When the application object needs to submit an application, it obtains the result of the random function operation closest to the application submission time, encrypts it, and adds time information. After obtaining the data, the node extracts the function value generated by the random function operation at the corresponding time point based on the time information and decrypts it. Of course, decryption methods are also diverse. First, the encryption and decryption methods between the node and the application object are agreed upon. Then, when decrypting, the node uses the agreed decryption method to exclude the function value of the random function and finally converts it into the application object information.After decrypting the object's identity information, the node needs to determine the object decoding function set on the node that matches the object's identity, and then use the object decoding function to decrypt the encrypted flight plan application information. Of course, the encryption and decryption methods for flight plan application information are the same as those for object identity information; only the random function value set for encrypting flight plan data differs for different application objects.
[0048] Based on the shared stub data of blockchain nodes, and combined with the object's flight plan information, authentication analysis is performed to form authentication analysis result data, including: extracting the application time point, application plan time period, and application plan spatial range from the object's flight plan information to form an application data group; extracting the authentication plan time period and authentication plan spatial range corresponding to different flight plans in the publicly shared ordered authentication plan set from the shared stub data of blockchain nodes to form authentication data groups corresponding to different flight plans; extracting the application order time point, application order plan time period, and application order plan spatial range corresponding to different flight plans in the publicly shared ordered application plan set from the shared stub data of blockchain nodes to form application order data groups corresponding to different flight plans; and comparing the application data groups with different authentication data groups in terms of time period and spatial range as follows: if for any authentication data group, there is no overlap between the authentication plan time period and the application plan time period, and no overlap between the authentication plan spatial range and the application plan spatial range, then the authentication comparison is considered normal. If a certification data set exists, and the planned certification time period overlaps with the planned application time period, but the planned certification spatial range does not overlap with the planned application spatial range, then certification comparison time overlap information is formed. If a certification data set exists, and the planned certification time period does not overlap with the planned application time period, but the planned certification spatial range overlaps with the planned application spatial range, then certification comparison spatial overlap information is formed. If a certification data set exists, and the planned certification time period overlaps with the planned application time period, and the planned certification spatial range overlaps with the planned application spatial range, then certification comparison overlap information is formed. When the comparison analysis results in normal certification comparison information, the application data set is compared with different ordered application data sets as follows: all ordered application data sets whose ordered application time points are earlier than the application time points are identified and marked as earlier ordered application data sets. If for any earlier ordered application data set, there is no overlap between the planned certification time period and the planned application time period, and the planned certification spatial range overlaps with the planned application spatial range, then certification pass information is formed; otherwise, certification fail information is formed.
[0049] Certification analysis primarily determines whether the proposed flight plan conflicts with existing flight plans in terms of implementation time and spatial scope. Since existing flight plans include those already certified and approved, as well as those currently undergoing certification, the methods for comparing and analyzing this data differ. For certified and approved plans, the implementation time and spatial scope can be directly compared. If different nodes process certification requests according to application regions, then only the local certification plan data at the receiving node needs to be compared, significantly reducing the data volume. For plans currently undergoing certification, to avoid conflicts, they are reviewed on a first-come, first-served basis. Therefore, the comparison analysis must first identify the submitted applications and then compare the implementation time and spatial scope of these previously submitted applications. The comparison analysis of these two types of plan data follows a progressive relationship; only after the data comparison of existing flight plans passes is the data of the applying plans compared. This improves the efficiency of certification comparison analysis and reduces the amount of data processed.
[0050] S3: Based on the certification analysis results, collect real-time flight data and combine it with the plan application information for monitoring and analysis to form real-time monitoring data.
[0051] Based on the certification analysis results, real-time flight data is collected and combined with the plan application information for monitoring and analysis, forming real-time monitoring data. This includes: when the certification analysis result is "certification passed," extracting different real-time discrete recording time points and corresponding real-time discrete position coordinates from the real-time flight data; determining the real-time flight time interval based on the real-time discrete recording time points and comparing it with the applied plan time period; if the real-time flight time interval falls within the applied plan time period, generating "real-time time monitoring normal" information; otherwise, generating "real-time time exceeding limit" information; and performing time-dimensional path trajectory analysis based on the real-time discrete position coordinates to generate a real-time flight trajectory curve. According to the real-time flight trajectory curve Furthermore, based on the spatial range of the application plan, range monitoring analysis was conducted to generate range monitoring result data.
[0052] Monitoring and analysis primarily involves real-time tracking of aircraft operations to monitor whether they are conducted within the planned timeframes and spatial ranges. The data required for real-time monitoring of flight operations comes from discretely collected data uploaded by the aircraft. Considering that real-time monitoring encompasses both time and spatial aspects, it is necessary to compare and analyze the collected discrete data with the planned data separately. For time data, it is only necessary to combine the collected discrete time points to determine the corresponding time period of the operation to judge whether it falls within the planned timeframe. For spatial data, discrete position coordinate data is used to form trajectory data to determine whether the trajectory exceeds the planned spatial range.
[0053] According to the real-time flight trajectory curve In conjunction with the proposed spatial range, range monitoring analysis based on the minimum turning radius is conducted to generate range monitoring results data, including: data based on real-time flight trajectory curves. Determine the corresponding trajectory radius of curvature. According to the real-time flight trajectory curve Trajectory curvature radius In addition to the planned spatial range, the following range monitoring and analysis methods will be used for the real-time flight trajectory curve. If the space exceeds the planned area, it will generate an "operational scope exceeding limit" message; for real-time flight trajectory curves If it does not exceed the application plan space range, and the shortest distance between the trajectory point and the boundary of the application plan space range is not greater than the trajectory verification distance. This generates normal information about the operational range: for real-time flight trajectory curves. If the application does not exceed the planned spatial range, but the shortest distance between the trajectory point and the boundary of the planned spatial range is not greater than the trajectory verification distance. Then: the shortest distance from the boundary of the application plan's spatial range is determined to be no greater than the trajectory verification distance. The trajectory segments are labeled as risk trajectory segments, and the radius of curvature of the corresponding risk trajectory segments is extracted. , where n represents the number of different risk trajectory segments; for each risk trajectory segment, if all satisfy... ≤ ≤ This will generate normal information for the work scope, among which, The minimum turning radius of the aircraft. The turning environment is an influencing factor; for each risk trajectory segment, if any risk trajectory segment does not satisfy... ≤ ≤ This generates information indicating that the work scope has exceeded the limit.
[0054] Determining whether a flight trajectory exceeds the planned spatial range primarily involves identifying whether the trajectory falls within the planned spatial range or if there is a risk of exceeding it. Whether it falls within the planned range can be directly judged by comparing the trajectory curves. However, regarding the risk of exceeding the planned range, since the nodes collect discrete position coordinate data, trajectory fitting is merely a simple continuous fitting analysis and cannot fully represent the actual trajectory. For safety, for trajectory positions close to the planned spatial range boundary, it is necessary to assess whether a short-term exceedance might occur due to an insufficient turning radius. Therefore, the exceedance risk analysis uses the trajectory verification distance as a reference. If a minimum distance meets the trajectory verification distance condition, it is necessary to determine whether the minimum turning radius is less than the trajectory verification distance. Of course, environmental factors and the aircraft's minimum turning radius capability also need to be considered, as environmental factors also affect the aircraft's minimum turning radius capability. Therefore, it is necessary to determine whether the radius of curvature of the risk trajectory segment is achievable by the aircraft under environmental influence conditions, and whether it will not reach the trajectory verification distance. For environmental factors, namely the turning environment impact factor, it can be obtained based on big data analysis of the turning radius of the operational aircraft under different environmental conditions. The minimum turning radius of the aircraft can be obtained from the aircraft's design parameters. Of course, this parameter needs to be reported to the node when applying for the plan.
[0055] S4: Extract and process real-time monitoring data to form real-time flight record data.
[0056] The real-time monitoring data is extracted and processed to form real-time flight record data, including: storing the real-time monitoring data on the corresponding nodes and extracting the application object and flight plan information from the real-time monitoring data; and sending the application object and flight plan information as publicly shared data to all nodes for storage.
[0057] After a flight operation is completed, whether terminated due to exceeding the planned scope or successfully completed, the real-time monitoring data needs to be stored. This storage method involves storing the real-time monitoring data under the corresponding nodes. The real-time monitoring data includes the requested plan data, the data collected in real-time, and the analysis data based on the collected data. To ensure that other nodes can trace and connect to the real-time monitoring data, the application object and flight plan information are provided to other nodes as publicly shared data. Other nodes then obtain and store this data to form corresponding node-shared stub data. This ensures that all nodes on the entire blockchain have traceability and connection to any flight data. This reduces data storage resource consumption while also improving data security and reliability.
[0058] This invention also provides a blockchain-based low-altitude airspace access authentication and management system. The system includes: a data acquisition unit, deployed on each node of the blockchain, for collecting publicly shared data from different nodes, plan application information for corresponding nodes, and real-time flight data; a data storage unit, deployed on each node of the blockchain, for clustering and storing the publicly shared data collected by the data acquisition unit from different nodes to form shared stub data for blockchain nodes, and storing the real-time monitoring data generated by the corresponding nodes; an authentication analysis unit, deployed on each node of the blockchain, for performing authentication analysis on the plan application information of the corresponding nodes to generate authentication analysis results; and a monitoring analysis unit, deployed on each node of the blockchain, for combining the analysis results of the authentication analysis unit with the real-time flight data collected by the data acquisition unit, performing monitoring analysis, and generating real-time monitoring data.
[0059] This system achieves distributed data processing and storage through different functional units on each node of the blockchain. The data acquisition unit collects flight data, corresponding application data, and real-time flight data. The data storage unit stores shared data and monitoring data. The authentication and analysis unit performs authentication and analysis on the submitted flight plan applications. The monitoring and analysis unit collects and monitors real-time operational data for the authenticated flight plans. The different functional units form a complete data processing system, which is the necessary material basis for realizing low-altitude airspace permission authentication and management. The different nodes form a complete blockchain system, which ensures data integrity while improving management capabilities and efficiency, and greatly improves the form of authentication and management.
[0060] In summary, the beneficial effects of the blockchain-based low-altitude airspace access authentication and management method and system provided by the embodiments of the present invention are as follows:
[0061] This method utilizes publicly available flight plan data from different nodes on a blockchain. Each node can maintain a stub of the flight plan information across the entire blockchain to prevent data tampering. Different nodes manage their respective plan application information and use the shared stub to determine if any applied plans conflict with existing plans, thus ensuring that approved plans are conflict-free. Real-time tracking of flight operation data uploaded during plan execution is performed to ensure consistency with the flight plan and prevent deviations. After aircraft operations are completed, the data is stored on the corresponding node and shared with other nodes as a stub, facilitating data traceability across all nodes. Using blockchain for low-altitude airspace access authentication and management avoids the problems of large data volumes and low data security associated with centralized management, while significantly improving management efficiency and capabilities, resulting in more stable and reliable data.
[0062] This system achieves distributed data processing and storage through different functional units on each node of the blockchain. The data acquisition unit collects flight data, corresponding application data, and real-time flight data. The data storage unit stores shared data and monitoring data. The authentication and analysis unit performs authentication and analysis on the submitted flight plan applications. The monitoring and analysis unit collects and monitors real-time operational data for the authenticated flight plans. The different functional units form a complete data processing system, which is the necessary material basis for realizing low-altitude airspace permission authentication and management. The different nodes form a complete blockchain system, which ensures data integrity while improving management capabilities and efficiency, and greatly improves the form of authentication and management.
[0063] In the embodiments of this application, "instruction" can include direct and indirect instructions, as well as explicit and implicit instructions. The information indicated by a certain piece of information is called the information to be instructed. In the specific implementation process, there are many ways to instruct the information to be instructed, such as, but not limited to, directly instructing the information to be instructed, such as the information to be instructed itself or its index. It can also indirectly instruct the information to be instructed by instructing other information, where there is a relationship between the other information and the information to be instructed. It can also instruct only a part of the information to be instructed, while the other parts are known or pre-agreed upon. For example, the instruction of specific information can be achieved by using a pre-agreed (e.g., protocol-defined) arrangement of various pieces of information, thereby reducing instruction overhead to some extent. At the same time, common parts of various pieces of information can be identified and uniformly indicated to reduce the instruction overhead caused by individually indicating the same information.
[0064] Furthermore, the specific indication method can also be any existing indication method, such as, but not limited to, the above-mentioned indication methods and their various combinations. Specific details of various indication methods can be found in existing technologies, and will not be repeated here. As described above, for example, when multiple pieces of information of the same type need to be indicated, the indication methods for different pieces of information may differ. In the specific implementation process, the required indication method can be selected according to specific needs. This application embodiment does not limit the selected indication method; therefore, the indication methods involved in this application embodiment should be understood to cover various methods that enable the party to be indicated to obtain the information to be indicated.
[0065] It should be understood that the information to be indicated can be sent as a whole or divided into multiple sub-information messages sent separately, and the sending period and / or timing of these sub-information messages can be the same or different. The specific sending method is not limited in this application embodiment. The sending period and / or timing of these sub-information messages can be predefined, for example, according to a protocol, or configured by the sending device by sending configuration information to the receiving device.
[0066] "Predefined" or "pre-configured" can be achieved by pre-saving corresponding codes, tables, or other means that can be used to indicate relevant information in the device. This application does not limit the specific implementation method. "Saving" can refer to saving in one or more memories. These memories can be separate installations or integrated into the encoder, decoder, processor, or communication device. Alternatively, some memories can be separately installed, while others are integrated into the decoder, processor, or communication device. The type of memory can be any form of storage medium, and this application does not limit this.
[0067] The “protocol” mentioned in the embodiments of this application may refer to a protocol family in the field of communication, a standard protocol with a similar protocol family frame structure, or a related protocol applied to future communication systems. The embodiments of this application do not specifically limit this.
[0068] In the embodiments of this application, descriptions such as "when," "under the circumstances," "if," and "if" all refer to the device making corresponding processing under certain objective circumstances, and are not limited to a specific time. They do not require the device to make a judgment action during implementation, nor do they imply any other limitations.
[0069] In the description of the embodiments of this application, unless otherwise stated, " / " indicates that the objects before and after are in an "or" relationship. For example, A / B can represent A or B. "And / or" in the embodiments of this application is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, and B alone, where A and B can be singular or plural. Furthermore, in the description of the embodiments of this application, unless otherwise stated, "multiple" refers to two or more. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or multiple. Additionally, to facilitate a clear description of the technical solutions of the embodiments of this application, the terms "first" and "second" are used in the embodiments of this application to distinguish identical or similar items with essentially the same function and effect. Those skilled in the art will understand that the terms "first," "second," etc., do not limit the quantity or order of execution, and that "first," "second," etc., are not necessarily different. Furthermore, in the embodiments of this application, words such as "exemplary" or "for example" are used to indicate that something is being used as an example, illustration, or description. Any embodiment or design scheme described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design schemes. Specifically, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner for ease of understanding.
[0070] It should be understood that the processor in the embodiments of this application can be a central processing unit (CPU), or it can be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor, etc.
[0071] It should also be understood that the memory in the embodiments of this application can be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of random access memory (RAM) are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate synchronous DRAM (DDR SDRAM), enhanced synchronous DRAM (ESDRAM), synchronous linked DRAM (SLDRAM), and direct rambus RAM (DR RAM).
[0072] The above embodiments can be implemented, in whole or in part, by software, hardware (such as circuits), firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more sets of available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium. A semiconductor medium can be a solid-state drive.
[0073] It should be understood that the term "and / or" in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. A and B can be singular or plural. Additionally, the character " / " in this article generally indicates an "or" relationship between the preceding and following related objects, but it can also represent an "and / or" relationship. Please refer to the context for a more accurate understanding.
[0074] In this application, "at least one" means one or more, and "more than one" means two or more. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of a single item or a plurality of items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be a single item or multiple items.
[0075] It should be understood that in the various embodiments of this application, the order of the above-mentioned processes does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0076] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0077] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0078] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0079] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0080] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0081] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0082] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A blockchain-based method for low-altitude airspace access authentication and management, characterized in that, include: Collect publicly shared data from different nodes, cluster and store the data to form shared stub data for blockchain nodes, including: Based on the publicly shared data, extract publicly shared authentication plans to form a set of publicly shared authentication plans; Based on the publicly shared data, extract the publicly shared application plan to form a publicly shared application plan set; Sequential clustering is performed on the publicly shared authentication plan set and the publicly shared application plan set to form the shared stub data of the blockchain nodes, including: For the different flight plans in the publicly shared authentication plan set, they are numbered and sorted according to the time dimension based on the start time of the aircraft plan's operation, forming a publicly shared ordered authentication plan set; For the different flight plans in the publicly shared application plan set, they are numbered and sorted according to the application time of the flight plans in chronological order to form an ordered publicly shared application plan set; The publicly shared ordered authentication plan set and the publicly shared ordered application plan set are combined to form the shared stub data of the blockchain nodes; Obtain the application information, combine it with the shared stub data of the blockchain nodes for authentication analysis, and generate authentication analysis result information, including: Obtain the plan application information and extract the object encryption segment and the flight plan encryption segment respectively; The encrypted segment of the extracted object and the encrypted segment of the flight plan are decrypted to form application object information and object flight plan information, respectively. Based on the shared stub data of the blockchain nodes, and combined with the object's flight plan information, authentication analysis is performed to form the authentication analysis result information, including: Based on the flight plan information of the object, the application time point, the application plan time period, and the application plan spatial range are extracted to form an application data group; Based on the shared stub data of the blockchain nodes, the time period and spatial range of the authentication plan corresponding to different flight plans in the publicly shared ordered authentication plan set are extracted to form authentication data groups corresponding to different flight plans. Based on the shared stub data of the blockchain nodes, the application order time point, application order time period and application order spatial range corresponding to different flight plans in the publicly shared orderly application plan set are extracted to form application order data groups corresponding to different flight plans. The application data set will be compared and analyzed with different authentication data sets in terms of time period and spatial range, including: If for any of the authentication data groups, there is no overlap between the authentication plan time period and the application plan time period, and the authentication plan spatial range overlaps with the application plan spatial range, then normal authentication comparison information is formed. If the authentication data group exists, and the authentication plan time period overlaps with the application plan time period, but the authentication plan spatial range does not overlap with the application plan spatial range, then authentication comparison time overlap information is formed; If the authentication data group exists, and the authentication plan time period does not overlap with the application plan time period, but the authentication plan spatial range overlaps with the application plan spatial range, then authentication comparison spatial overlap information is formed. If the authentication data group exists, and the authentication plan time period overlaps with the application plan time period, and the authentication plan spatial range overlaps with the application plan spatial range, then authentication comparison overlap information is formed; When the comparative analysis results in the authentication comparison being normal, the application data group is compared with different ordered application data groups as follows: All ordered data groups of applications whose ordered application time points are earlier than the application time point are identified and marked as the earlier ordered data groups of applications. If for any of the preceding ordered data groups, there is no overlap between the authentication plan time period and the application plan time period, and the authentication plan spatial range overlaps with the application plan spatial range, then authentication pass information is generated; otherwise, authentication fail information is generated. If the certification analysis result is a certification pass, real-time flight data is collected and combined with the aforementioned plan application information for monitoring and analysis to form real-time monitoring data; The real-time monitoring data is extracted and processed to form real-time flight record data.
2. The blockchain-based low-altitude airspace access authentication and management method according to claim 1, characterized in that, The process of decrypting the encrypted segment of the extracted object and the encrypted segment of the flight plan to form application object information and object flight plan information respectively includes: Obtain the identity sequence decoding of the node's public decryption function, and perform identity decoding on the encrypted segment of the object in the following manner: Remove the identity sequence from the encrypted segment of the object to form the encrypted information of the application object; The information of the applicant is transformed into identification information to form the applicant information; Based on the application object information, determine the object decoding function on the corresponding node, and decode the application content of the flight plan encrypted segment in the following manner according to the object decoding function to obtain the object application order decoding: Remove the object application sequence decoding from the encrypted segment of the flight plan to form the object application content encoded information; The information in the application content of the object is enhanced with identification information and transformed to form the flight plan information of the object.
3. The blockchain-based low-altitude airspace access authentication and management method according to claim 2, characterized in that, The step involves collecting real-time flight data based on the authentication analysis results and combining it with the plan application information for monitoring and analysis to form real-time monitoring data, including: When the authentication analysis result information is the authentication passed information, then based on the real-time flight data, different real-time discrete recording time points and corresponding real-time discrete position coordinates are extracted; The real-time flight time interval is determined based on the real-time discrete recording time points and compared with the application plan time period. If the real-time flight time interval belongs to the application plan time period, real-time time monitoring normal information is generated; otherwise, real-time time exceeding limit information is generated. Based on the real-time discrete position coordinates, a time-dimensional path trajectory analysis is performed to generate a real-time flight trajectory curve. ; According to the real-time flight trajectory curve Furthermore, based on the spatial range of the application plan, range monitoring analysis is conducted to generate range monitoring result data.
4. The blockchain-based low-altitude airspace access authentication and management method according to claim 3, characterized in that, The real-time flight trajectory curve In conjunction with the proposed spatial range, range monitoring analysis based on the minimum turning radius is performed to generate range monitoring result data, including: According to the real-time flight trajectory curve Determine the corresponding trajectory radius of curvature. ; According to the real-time flight trajectory curve The radius of curvature of the trajectory And the spatial scope of the application plan, the following range monitoring and analysis methods will be used: For the real-time flight trajectory curve If the scope exceeds the planned application space, an operation scope over-limit information will be generated; For the real-time flight trajectory curve If it does not exceed the application plan space range, and there is no trajectory point whose shortest distance to the boundary of the application plan space range is not greater than the trajectory verification distance. This will generate normal information for the work area: For the real-time flight trajectory curve If the application plan space is not exceeded, but the shortest distance between a trajectory point and the boundary of the application plan space is not greater than the trajectory verification distance. ,but: The shortest distance to the boundary of the proposed spatial range is determined to be no greater than the trajectory verification distance. The trajectory segments are labeled as risk trajectory segments, and the radius of curvature of the corresponding risk trajectory segments is extracted. , where n represents the number of the different risk trajectory segments; For each of the aforementioned risk trajectory segments, if all satisfy... ≤ ≤ This will generate normal information for the work scope, among which, The minimum turning radius of the aircraft. Environmental factors affecting the turning environment; For each of the aforementioned risk trajectory segments, if any of the aforementioned risk trajectory segments does not satisfy... ≤ ≤ This generates information indicating that the work scope has exceeded the limit.
5. The blockchain-based low-altitude airspace access authentication and management method according to claim 4, characterized in that, The step of extracting and processing the real-time monitoring data to form real-time flight recording data includes: The real-time monitoring data is stored on the corresponding node, and the application object and flight plan information in the real-time monitoring data are extracted. The application object and the flight plan information are sent to all nodes as publicly shared data for storage.
6. A blockchain-based low-altitude airspace access authentication and management system, employing the blockchain-based low-altitude airspace access authentication and management method described in any one of claims 1-5, characterized in that, include: The data acquisition unit is deployed on each node of the blockchain to collect publicly shared data from different nodes, plan application information for the corresponding node, and real-time flight data. The data storage unit is located on each node of the blockchain and is used to cluster and store the publicly shared data collected by the data acquisition unit from different nodes to form shared stub data of blockchain nodes, and to store the real-time monitoring data formed by the corresponding nodes. The authentication analysis unit is deployed on each node of the blockchain and is used to perform authentication analysis on the plan application information of the corresponding node to generate authentication analysis result information. The monitoring and analysis unit is deployed on each node of the blockchain. It is used to combine the analysis results of the authentication analysis unit with the real-time flight data collected by the data acquisition unit, perform monitoring and analysis, and form real-time monitoring data.
Citation Information
Patent Citations
Block chain-based low-altitude Internet of Things trusted data sharing system and method
CN120179731A
Urban low-altitude AI collaborative management and control method and system based on Beidou grid code and block chain
CN120452258A