Zero-trust command and control system and method for unmanned vehicle session risk budget
By introducing session risk budgeting and joint risk upper bound mapping into the unmanned vehicle system, the problem of insufficient risk management at the session level in the command and control system of unmanned vehicles is solved, and effective protection and security arbitration against multi-session collaborative attacks are achieved, thereby improving the system's security and mission efficiency.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-24
- Publication Date
- 2026-03-27
AI Technical Summary
Existing command and control systems for unmanned vehicles lack session-level risk budgeting and multi-dimensional constraints, making it impossible to manage control commands in a fine-grained manner under a zero-trust framework, unable to cope with multi-session collaborative attacks, and lacking an effective security arbitration mechanism in multi-control terminal scenarios.
By introducing a session risk budget field and a joint risk upper bound mapping, identity authentication, session management, and adversarial session joint risk budget adjudication are performed through the security agent modules on the ground station and unmanned vehicle side. Combined with trajectory prediction and multi-dimensional constraint verification, fine-grained control and safety adjudication of control commands are achieved.
It significantly improves the security of the command and control link of unmanned vehicles, and can provide clear risk constraints and protection under multi-session collaborative attacks, ensuring that emergency safety instructions take priority while balancing mission efficiency and system security.
Smart Images

Figure CN121750679A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of unmanned system safety control, and particularly relates to an unmanned vehicle session risk budget zero trust command and control system and method. BACKGROUND
[0002] With the large deployment of unmanned platforms such as unmanned aerial vehicles, unmanned vehicles, unmanned ships, etc. in police and civilian fields, remote command and control (C2) based on wireless data link becomes a key link for task execution. The existing unmanned vehicle command and control system generally relies on fixed ground station software to issue flight path planning, attitude control, load control and other instructions to unmanned vehicles through special or public network links.
[0003] On the one hand, in order to cope with complex network attack threats, the industry has gradually introduced a zero trust (Zero Trust) security architecture to enhance security in access control, identity authentication, access authorization, etc. However, a large number of zero trust solutions mainly focus on the scenario of user terminal accessing enterprise applications, and lack of fine-grained risk constraint mechanisms for session level for the command and control link of high-risk control objects such as unmanned vehicles.
[0004] On the other hand, the fields of aviation, aerospace, navigation, etc. have proposed a risk budget-based security evaluation method, which allocates the overall risk of a task according to functions and scenarios to meet a certain level of safety target. However, most of these risk budgets are at the task or system level and are used in the design or verification phase, and are not refined to each control instruction and each control session in runtime, nor are they closely integrated with the zero trust access control system.
[0005] In addition, in the scenario where multiple control terminals and multiple ground stations jointly control the same unmanned vehicle, the common practice is to solve the command conflict through static priority, role permission or simple "primary and backup switching" strategy, and the situation where an attacker may control multiple sessions simultaneously and collaboratively initiate malicious instructions is not considered. Once the attacker obtains the legal credentials of multiple control terminals, even if a single session acts within its authorized range, it may push the unmanned vehicle into a dangerous state through "combined consumption".
[0006] In the prior art, there is still a lack of a system that can simultaneously achieve:
[0007] 1. Assigning a clear session risk budget and multi-dimensional constraints to each control session under the zero trust framework;
[0008] 2. Implementing fine-grained instruction risk measurement and trajectory prediction verification on the unmanned vehicle side;
[0009] 3. For the attack model of "at most k sessions are compromised", a clear joint risk upper bound estimation is given, and an adversarial decision is made for each instruction at runtime;
[0010] 4. In the multi-control terminal concurrent scene, considering the session risk budget, dynamic trust score and security priority, the security arbitration of conflict control instructions is completed.
[0011] Therefore, it is necessary to propose a new unmanned vehicle zero-trust safe command and control system and method, which significantly improves the ability of the system to resist multi-session coordinated attacks by maintaining low invasiveness to the existing ground station software and vehicle control system, through algorithm-level session risk budget management and adversarial decision mechanism. SUMMARY
[0012] The purpose of the present application is to overcome the shortcomings of the existing unmanned vehicle command and control system in the following aspects:
[0013] 1. Lack of risk budget and multi-dimensional constraints at the session level, making it difficult to limit the maximum damage that a single session can cause when compromised;
[0014] 2. Unable to make joint decisions on control instructions based on task constraints, space-time constraints and risk budgets on the unmanned vehicle side, lacking a "last security gate";
[0015] 3. No clear joint risk upper bound estimation and runtime adversarial decision method for the threat model of "at most k control sessions are compromised and coordinated attacks";
[0016] 4. When multiple control terminals are concurrently controlled, only relying on static priority or simple role control, it is impossible to consider security instruction priority, residual risk budget and session dynamic trust degree comprehensively.
[0017] The present application provides an unmanned vehicle zero-trust safe command and control system and method based on session risk budget, which realizes provable risk constraints for single session and multi-session coordinated attacks by introducing session risk budget fields, joint risk upper bound mapping and adversarial session joint risk budget decision methods on the ground side and the unmanned vehicle side, thereby significantly improving the intrinsic safety level of the unmanned vehicle command and control link.
[0018] To achieve the above object, the technical scheme adopted by the present application is: an unmanned vehicle zero-trust security command and control system based on a session risk budget, comprising: a control terminal, a zero-trust access control gateway, a ground station security agent module, a command and control communication link, an unmanned vehicle side security agent module, an unmanned vehicle control module, an operation monitoring and digital twin simulation module, wherein the zero-trust access control gateway, the ground station security agent module and the unmanned vehicle side security agent module jointly constitute a session-level risk budget management and decision system.
[0019] The control terminal is configured to run ground command and control software and generate control instructions for the unmanned vehicle.
[0020] The zero-trust access control gateway is configured to perform identity authentication, fine-grained permission control and session management on the control terminal, and issue a task credential to the control terminal when a control session is established, wherein the task credential at least includes a session identifier field, a control capability field, a space constraint field, a time constraint field and a session risk budget field.
[0021] The ground station security agent module is deployed in a transparent or low-intrusion manner between the control terminal and the command and control communication link, is decoupled from the original ground station software, is configured to intercept the control instructions, analyze the task credential, calculate a risk consumption value of the control instructions according to the control instruction type and the current state of the unmanned vehicle, and encapsulate the control instructions and the risk consumption value into a control-type security message carrying a session identifier and a task credential digest.
[0022] The command and control communication link is configured to transmit control-type security messages and telemetry-type security messages between the ground side and the unmanned vehicle, and includes a wired network, a wireless private network, a public network VPN or a combination thereof.
[0023] The unmanned vehicle side security agent module is deployed in a transparent or low-intrusion manner between the command and control communication link and the unmanned vehicle control module, is configured to perform integrity and session binding verification on the received control-type security messages, make a local decision based on the session risk budget and a predicted trajectory, and execute an adversarial session joint risk budget decision method. Square
[0024] The unmanned vehicle side security agent module performs integrity and session binding verification on the received control-type security messages, makes a local decision based on the session risk budget and a predicted trajectory, and executes an adversarial session joint risk budget decision method, and the specific process is as follows:
[0025] Perform integrity verification and session binding verification on the received control-type security messages.
[0026] obtaining a session risk budget field, a space constraint field and a time constraint field from the bound task credential;
[0027] discretely predicting a trajectory of the unmanned vehicle after execution of the control instruction within a preset prediction time window, and comparing the predicted trajectory with the space constraint and the time constraint point by point;
[0028] continuing risk budget checking and joint risk decision-making of the adversarial session on the premise that the trajectory prediction does not enter the dangerous area and does not violate the time constraint;
[0029] if the trajectory prediction indicates that the instruction will guide the unmanned vehicle to enter a dangerous area or violate the task time constraint, the instruction is directly rejected.
[0030] The unmanned vehicle control module includes a flight control system, a drive control unit, a task load control unit, etc., and is used to execute the control instruction released by the unmanned vehicle side security agent module;
[0031] The running monitoring and digital twin simulation module is used to collect unmanned vehicle state and environment information, build an unmanned vehicle motion model and a task environment model, and simulate multi-session collaborative control under a set attack scenario, build a joint risk upper bound mapping, and provide support for the adversarial decision-making method on the unmanned vehicle side.
[0032] The unmanned vehicle side security agent module is configured to:
[0033] maintain a session risk budget, a consumed risk and a remaining risk budget corresponding to each control session;
[0034] In the case where the trajectory prediction and the space constraint and the time constraint checking are satisfied, first, according to the session risk budget field and the consumed risk of the corresponding session, the risk consumption value carried by the control type security message is subjected to single-session risk budget checking;
[0035] When the single-session risk budget checking is passed, based on the current unmanned vehicle state, the task environment, the remaining risk budget of all control sessions and the preset maximum number of controlled sessions k, the worst joint risk upper bound that may occur within the prediction time window is determined from the joint risk upper bound mapping, the worst joint risk upper bound is compared with the system-level safety limit, and only when the worst joint risk upper bound does not exceed the system-level safety limit, the control instruction is issued to the unmanned vehicle control module for execution, otherwise the control instruction is rejected and a security event is recorded;
[0036] Thus, under the assumption that at most k control sessions are compromised and jointly initiate an attack, the joint risk that the unmanned vehicle may bear within the prediction time window is upper bounded.
[0037] Further, the configuration of the session risk budget field is determined by the zero trust access control gateway according to at least one of:
[0038] a task type, including at least one of patrol, reconnaissance, strike, emergency rescue, and training;
[0039] a security level of a task area, including at least one of a normal area, a sensitive area, and a no-fly / no-go area;
[0040] a role of the control terminal, including at least one of a combat command seat, an intelligence seat, a training seat, and a maintenance seat;
[0041] a type of an unmanned vehicle platform capability and a carried load, and a value corresponding to the session risk budget field is configured between a preset lower limit and an upper limit, wherein the preset upper limit is preferably less than or equal to 50% of a system-level safety limit.
[0042] Further, when the ground station security agent module calculates the risk consumption value of the control instruction, at least two factors are considered:
[0043] a type of the control instruction and an influence intensity of the control instruction on a posture, a speed, a trajectory, and a load state of the unmanned vehicle;
[0044] a distance between an action area of the control instruction and a boundary of the no-fly / no-go area;
[0045] a current remaining power, a height, a speed, and a posture stability of the unmanned vehicle;
[0046] a task phase and a time window defined by the time constraint field;
[0047] and based on a preset risk assessment model, the above factors are quantified into a normalized risk consumption value in the interval of 0-1 or 0-100.
[0048] Further, the security agent module on the unmanned vehicle side, when performing trajectory prediction:
[0049] uses a prediction time window with a length of 1-10 seconds, and discretizes the prediction time window according to a time step length of 50-500 milliseconds;
[0050] based on a current state of the unmanned vehicle and the control instruction, calculates a predicted position of the unmanned vehicle at each time step, and compares it with a safety area, a buffer area, and a no-fly / no-go area corresponding to the space constraint field point by point;
[0051] when any position point of the predicted trajectory enters the no-fly / no-go area or violates the task time window defined by the time constraint field, directly rejects to execute the control instruction.
[0052] Further, the process of constructing the joint risk upper bound mapping by the operation monitoring and digital twin simulation module comprises:
[0053] Defining unmanned vehicle state variables, including at least two of position, speed, attitude, power level and load state;
[0054] Establishing a set of task environment scenarios, including different terrains, obstacle distributions and no-fly / no-go area configurations;
[0055] For different combinations of session number, session risk budget and maximum number of controlled sessions k, set the attack scenario in which the attacker can arbitrarily select control instructions and their time series within the session risk budget range within the prediction time window;
[0056] Simulate a large number of state, environment and session budget combinations, evaluate the risk level that the unmanned vehicle can reach within the prediction time window under each attack scenario, and take the maximum risk that the attacker can achieve in each scenario as the corresponding joint risk upper bound value;
[0057] Map the unmanned vehicle state, task environment, session budget combination and maximum number of controlled sessions k to the joint risk upper bound value to form the joint risk upper bound mapping.
[0058] Further, the joint risk upper bound mapping is implemented in at least one of the following ways:
[0059] A lookup table based on a multi-dimensional discrete grid, each grid cell stores the joint risk upper bound value under the corresponding state, environment and session budget combination;
[0060] A function approximation model based on decision tree, gradient boosting tree or lightweight neural network, the input of the function approximation model includes unmanned vehicle state features, environment features, session budget features and maximum number of controlled sessions k, and the output is the joint risk upper bound estimate
[0061] Further, the unmanned vehicle side security agent module is also configured to maintain a dynamic trust score for each control session and adjust the effective risk budget of the session based on the dynamic trust score, wherein:
[0062] The dynamic trust score is updated according to the session history control instruction behavior, triggered security events and audit results;
[0063] When a control session repeatedly issues control instructions that cause the joint risk upper bound to approach the system-level security limit, the upper limit of its effective risk budget is reduced;
[0064] When a control session continuously issues control instructions in compliance with the security policy for a long time without triggering a security event, the effective risk budget upper limit is moderately increased, but does not exceed the maximum value configured in the session risk budget field.
[0065] Further, there are more than one control terminal, and when multiple sessions issue mutually exclusive control instructions to the same unmanned vehicle in the same time period, the unmanned vehicle side security agent module comprehensively considers the safety priority of the instruction type, the proportion of the remaining risk budget of the session to the session risk budget field, and the session dynamic trust score, determines a priority instruction according to a preset sorting rule, and after trajectory prediction and joint risk budget decision of the confrontation session, the instruction is issued for execution, and the remaining conflicting instructions are rejected or delayed processing. Specifically, it includes:
[0066] Detect whether the control instructions received in the preset time window have mutually exclusive relationships in control direction, control amount or control mode;
[0067] According to the instruction type, determine the safety priority of each control instruction, so that the emergency obstacle avoidance, fault handling and safe landing type instructions have higher priority than the general task control instructions;
[0068] Read the remaining risk budget of each session, and calculate the proportion of the remaining risk budget to the session risk budget field configuration value;
[0069] Obtain the dynamic trust score of each session;
[0070] According to the comprehensive sorting results of the safety priority, the proportion of the remaining risk budget, and the dynamic trust score, select a target control instruction from the mutually exclusive control instructions, perform trajectory prediction, multi-dimensional constraint verification and joint risk budget decision of the confrontation session on the target control instruction, and only when the above decisions are passed, the target control instruction is issued to the unmanned vehicle control module for execution.
[0071] Further, when the zero-trust access control gateway establishes a control session for a control terminal, it generates a task credential containing the following fields for the session according to the task type, control terminal role, unmanned vehicle platform capability and task area security level:
[0072] Session identification field, used to uniquely identify the current control session;
[0073] Control capability field, used to describe the allowed instruction type and parameter range;
[0074] Space constraint field, used to describe the geographical range allowed for task execution, including safe area, buffer area and forbidden flying / running area;
[0075] Time constraint field, used to describe the time window allowed for task execution and the safety requirements of each stage;
[0076] a session risk budget field for describing a maximum risk amount allowed to be consumed by the session within a preset prediction time window;
[0077] a session security level field for describing the importance of the session and the security responsibility that can be carried;
[0078] an optional session dynamic trust initial value field for initializing subsequent dynamic trust evaluation.
[0079] The task credential is integrity-protected by digital signature or the like, and is carried in or bound to the control-type security message.
[0080] Further, a ground station security agent module is deployed between the control terminal and the command and control communication link, and is decoupled from the original ground station software through transparent proxy, network driver layer plug-in or virtual serial port or the like. The ground station security agent module is used for:
[0081] intercepting the control instruction generated by the ground station software;
[0082] obtaining the session identifier, the control capability, the space constraint, the time constraint and the session risk budget field from the task credential;
[0083] calculating the risk consumption value of the control instruction according to the control instruction type, the target area, the current state of the unmanned vehicle and the like;
[0084] encapsulating the control instruction and the risk consumption value into the control-type security message, and carrying or binding the session identifier and the task credential digest;
[0085] locally intercepting or downgrading the instruction with significantly high risk or violating the constraint.
[0086] Further, the security agent module on the unmanned vehicle side is deployed between the communication link and the unmanned vehicle control module through the bypass network gateway, serial port relay or bus middleware, and is used for:
[0087] performing integrity verification and session binding verification on the received control-type security message;
[0088] obtaining the session risk budget field, the space constraint field and the time constraint field from the bound task credential;
[0089] discretely predicting the trajectory of the unmanned vehicle after execution of the control instruction within a preset prediction time window, and point-by-point comparing the predicted trajectory with the space constraint and the time constraint;
[0090] on the premise that the trajectory prediction does not enter the dangerous area and does not violate the time constraint, continuing to perform risk budget verification and joint risk decision of the confrontation session.
[0091] If trajectory prediction indicates that the instruction will guide the unmanned vehicle into a dangerous area or violate the task time constraint, the execution of the instruction is directly rejected.
[0092] Further, the unmanned vehicle is at least one of a fixed-wing unmanned aerial vehicle, a multi-rotor unmanned aerial vehicle, a vertical take-off and landing unmanned aerial vehicle, an unmanned vehicle, an unmanned ship, or an unmanned cluster.
[0093] The application also provides an unmanned vehicle zero-trust security command and control method based on session risk budget, which is used to jointly evaluate the upper bound of risk of control instructions and make adversarial decisions for the threat model of "at most k control sessions being compromised and cooperatively attacked" on the basis of considering a single session risk budget on the unmanned vehicle side, the method comprising an offline stage and an online stage:
[0094] (1) Offline stage:
[0095] Before deployment or operation, the motion characteristics, control response and task environment of the unmanned vehicle are modeled by running the monitoring and digital twin simulation module, different vehicle states, environmental scenarios and session risk budget configurations are simulated, and a joint risk upper bound mapping is constructed to describe the worst risk level that the unmanned vehicle can reach within a predetermined prediction time window, under the condition that at most k control sessions are compromised and cooperatively maliciously utilized their remaining risk budget.
[0096] (2) Online stage:
[0097] When the security agent on the unmanned vehicle side receives a control-type security message from any session, in addition to single-session risk budget verification, it also obtains the worst joint risk upper bound from the joint risk upper bound mapping based on the current remaining risk budget of each session, vehicle state and environmental context, compares it with the system-level security limit, and only releases the control instruction when the worst joint risk upper bound does not exceed the system-level security limit, otherwise it is rejected.
[0098] Through the above adversarial session joint risk budget decision method, the application can provide explicit joint risk upper bound constraints for the unmanned vehicle under the assumption that the attacker can control at most k sessions, thereby significantly enhancing the ability of the system to resist multi-session cooperative attacks.
[0099] Specifically, the following steps are included:
[0100] Step 1, the zero-trust access control gateway performs identity authentication and fine-grained authorization on the control terminal, and issues a task credential containing a session risk budget field for the control session;
[0101] Step 2, the ground station security agent module intercepts the control instruction generated by the control terminal, parses the task voucher, calculates the risk consumption value according to the control instruction type and the current state of the unmanned vehicle, and sends the control instruction and the risk consumption value to the unmanned vehicle as a control type security message through the command control communication link after encapsulation.
[0102] Step 3, the security agent module on the unmanned vehicle side receives the control type security message, completes the integrity check and session binding check, performs trajectory prediction within a preset prediction time window based on the current state of the unmanned vehicle, and compares the predicted trajectory with the space constraint field and the time constraint field in the task voucher.
[0103] Step 4, in the case that the trajectory prediction and multi-dimensional constraint check are passed, the security agent module on the unmanned vehicle side performs single-session risk budget check according to the session risk budget field in the task voucher and the maintained consumed risk record, and if the consumed risk after executing the control instruction exceeds the corresponding session risk budget, the control instruction is rejected.
[0104] Step 5, in the case that the single-session risk budget check is passed, the security agent module on the unmanned vehicle side obtains the remaining risk budget of all current control sessions, the current state of the unmanned vehicle and the task environment characteristics, and determines the worst-case joint risk upper bound within the prediction time window from the joint risk upper bound mapping combined with the preset maximum number of controlled sessions k.
[0105] Step 6, compare the worst-case joint risk upper bound with the system-level safety limit, only when the worst-case joint risk upper bound does not exceed the system-level safety limit, the control instruction is issued to the unmanned vehicle control module for execution, and the consumed risk record and dynamic trust score of the corresponding session are updated, otherwise the control instruction is rejected and a security event is recorded.
[0106] Compared with the prior art, the present application has the following beneficial effects:
[0107] 1. The present application explicitly allocates a session risk budget field and multi-dimensional task constraints for each control session under a zero trust access control framework, refines the traditional task-level risk budget to the session level and instruction level, so that the maximum damage that each session can cause when compromised is strictly upper bounded.
[0108] 2. The present application introduces trajectory prediction within a prediction time window and multi-dimensional constraint check by deploying a security agent module on the unmanned vehicle side, moves the judgment of the legality of the instruction to the unmanned vehicle body, realizes a "last safety gate" decoupled from the ground station software, and even if the ground station software is attacked, independent safety decision can still be made at the vehicle end.
[0109] 3. The application first introduces an adversarial session joint risk budget decision method in the unmanned vehicle command control scene, constructs a joint risk upper bound mapping offline, and performs worst joint risk evaluation in the online stage, gives a clear technical response to the threat model of "at most k sessions are attacked and cooperatively attacked", so that the system is no longer dependent on the local security of a single session, but has the essential protection ability against multi-session cooperative attack.
[0110] 4. In the multi-control terminal concurrent scene, the application realizes multi-factor decision of conflict instructions by comprehensively considering instruction safety priority, session residual risk budget proportion and dynamic trust score, ensures that emergency safety instructions have priority, sessions with more sufficient risk budget and more reliable historical behavior have higher control right, so as to balance task efficiency and system security.
[0111] 5. The application adopts the deployment mode of ground station security agent and unmanned vehicle side security agent, can be integrated with existing ground station software and vehicle control module through transparent agent, virtual serial port or bus middleware, has low invasiveness and good engineering feasibility, and is conducive to gradual deployment and promotion in existing unmanned systems. BRIEF DESCRIPTION OF DRAWINGS
[0112] Figure 1 is a schematic diagram of the overall structure of the system of the application.
[0113] Figure 2 is a schematic diagram of the working process of the ground station security agent module of the application.
[0114] Figure 3 is a schematic diagram of the working process of the unmanned vehicle side security agent module of the application.
[0115] Figure 4 is a schematic diagram of the process of the adversarial session joint risk budget decision method of the application.
[0116] Figure 5 is a schematic diagram of the process of constructing a joint risk upper bound mapping of the application.
[0117] Figure 6 is a schematic diagram of the process of multi-control terminal conflict decision of the application. DETAILED DESCRIPTION
[0118] Embodiment one: overall architecture of the system
[0119] Referring to Figure 1 The unmanned vehicle zero-trust security command control system based on session risk budget provided by the embodiment comprises:
[0120] A control terminal runs ground command control software and is used to generate control instructions such as flight path planning, attitude adjustment and load operation.
[0121] A zero-trust access control gateway is used to authenticate the control terminal, perform fine-grained authorization, and manage the session, and issue a task credential for the control terminal;
[0122] A ground station security agent module is deployed in a transparent proxy manner between the control terminal and the command and control communication link;
[0123] The command and control communication link can be a wired network, a private network, a public network VPN, or a combination thereof;
[0124] An unmanned vehicle side security agent module is deployed in a bypass network gateway or bus relay manner between the communication link and the unmanned vehicle control module;
[0125] The unmanned vehicle control module includes a flight control system, a drive control module, a load control module, etc.;
[0126] An operation monitoring and digital twin simulation module obtains unmanned vehicle state information and environmental information through a telemetry channel, simulates different attack scenarios, and constructs a joint risk upper bound mapping.
[0127] During task execution, the control terminal completes authentication and authorization through the zero-trust access control gateway and obtains a task credential carrying a session risk budget field. The ground station security agent module parses the task credential, calculates a risk consumption value according to the control instruction, and encapsulates it as a control-type security message, which is sent to the unmanned vehicle side security agent module through the command and control communication link. The unmanned vehicle side security agent module performs integrity verification, trajectory prediction, multi-dimensional constraint verification, and countermeasures session joint risk budget decision on the control-type security message. Instructions that meet the conditions are issued to the unmanned vehicle control module for execution, and instructions that do not meet the conditions are rejected and security events are recorded according to the strategy.
[0128] Embodiment Two: Task Credential and Session Risk Budget Configuration
[0129] In this embodiment, the zero-trust access control gateway generates a task credential for each session when creating a control session. The configuration of the session risk budget field in the task credential can refer to the following principles:
[0130] 1. According to the task type (reconnaissance, patrol, strike, emergency rescue, etc.) and the sensitivity of the task area, determine the basic risk budget of the session;
[0131] 2. Adjust the basic risk budget according to the role of the control terminal (combat command seat, intelligence seat, training seat, etc.) and historical behavior performance;
[0132] 3. According to the unmanned vehicle platform capability and load type, the platform is adapted to the basic risk budget, for example, the upper limit of the session risk budget of the unmanned vehicle carrying high-risk load can be appropriately reduced;
[0133] 4. Write the above results into the session risk budget field as the maximum risk amount allowed to be consumed by the session within the preset prediction time window.
[0134] The task credential is protected by asymmetric encryption, digital signature, etc. The zero-trust access control gateway and the unmanned vehicle side security agent module can verify the source and integrity of the task credential according to the signature of the task credential.
[0135] Embodiment three: risk consumption calculation and encapsulation process of ground station security agent
[0136] Referring to Figure 2 The workflow of the ground station security agent module of the embodiment includes:
[0137] 1. Agent initialization: load the ground station security agent module on the control terminal, so that it can intercept the control instructions issued by the ground station software and receive the unmanned vehicle telemetry data;
[0138] 2. Credential analysis: in the session initialization stage, receive the task credential from the zero-trust access control gateway, and analyze the session identifier, control capability, spatial constraint, time constraint, and session risk budget field;
[0139] 3. Instruction interception and analysis: when the ground station software generates control instructions such as waypoint update, speed adjustment, attitude control, load switch operation, etc., the ground station security agent module analyzes the instructions and extracts the operation type and key parameters;
[0140] 4. Risk consumption calculation: according to the pre-set risk assessment model, assign a reference risk value to different types of instructions, and combine the sensitivity of the instruction action area, the current unmanned vehicle state (such as remaining power, current height, distance from the forbidden area), etc. Calculate the risk consumption value of the instruction;
[0141] 5. Security message encapsulation: encapsulate the control instruction and the calculated risk consumption value into a control type security message, and carry or bind the session identifier and the task credential digest in the message;
[0142] 6. Local interception strategy: when the risk consumption value is obviously abnormal or violates the spatial constraint, time constraint, etc. Configuration, the ground station security agent module can directly reject to send the instruction on the ground side, and send an alarm to the operator.
[0143] Through the above steps, the embodiment can perform first-layer risk constraint and legality verification on the control instruction on the ground side, and provide information basis for further decision of the unmanned vehicle side.
[0144] Embodiment Four: Unmanned Vehicle Side Security Agent and Adversarial Session Joint Risk Budget Decision Method
[0145] Referring to Figure 3 In the embodiment, the basic workflow of the unmanned vehicle side security agent module includes:
[0146] 1. Receiving and parsing: receiving control type security messages from the command control communication link, parsing session identification, instruction content, risk consumption value and task voucher digest;
[0147] 2. Integrity and session binding verification: verifying the integrity of the control type security message and the binding relationship with the task voucher, to prevent message tampering or session hijacking;
[0148] 3. Trajectory prediction and constraint verification: based on the current state of the unmanned vehicle and the control instruction, discrete trajectory prediction is performed within a preset prediction time window, and the predicted trajectory is compared point by point with the space constraint and time constraint;
[0149] 4. Single-session risk budget check: obtain the risk budget field and consumed risk record of the session, compare the risk consumption value of the instruction with the session budget;
[0150] 5. Adversarial session joint risk budget decision: after the foregoing checks pass, the adversarial session joint risk budget decision method is executed to evaluate the joint risk upper bound in the worst case that at most k sessions are compromised;
[0151] 6. Instruction release and execution: if the joint risk upper bound does not exceed the system-level safety limit, the instruction is issued to the unmanned vehicle control module for execution, and the risk consumption record and dynamic trust data of the session are updated;
[0152] 7. Exception handling: when any step check fails, the instruction is rejected, and security events and necessary telemetry information are recorded for subsequent analysis and policy adjustment.
[0153] Referring to Figure 4 and Figure 5 In the embodiment, the adversarial session joint risk budget decision method is divided into two stages of offline construction and online decision.
[0154] (1) Offline construction of joint risk upper bound mapping
[0155] In the system deployment or upgrade phase, the monitoring and digital twin simulation module is run to model the unmanned vehicle, including the following steps:
[0156] a) Vehicle state space definition: Define unmanned vehicle state variables, including position, speed, attitude, power, load state, etc.
[0157] b) Environment scenario modeling: According to the task area, terrain, no-fly zone distribution, etc., build an environment scenario set;
[0158] c) Session configuration and budget combination: Set different numbers and types of control sessions, configure different session risk budget combinations for each group of sessions, including high risk budget, medium budget and low budget, etc.
[0159] d) Attack scenario setting: Under the assumption that at most k control sessions are compromised, the attacker can choose any instruction combination and time sequence within the budget range of these sessions, the goal is to make the unmanned vehicle enter the dangerous state set within the prediction time window;
[0160] e) Simulation and worst-case risk assessment: Simulate a large number of vehicle states, environment scenarios and session budget combinations, evaluate the worst-case risk level that the attacker can achieve by coordinating the control of compromised sessions for each scenario, and obtain the joint risk upper bound value;
[0161] f) Mapping construction: Establish a mapping relationship between vehicle state, environment scenario, session budget combination, and the corresponding joint risk upper bound value, which can be realized by table lookup or using a lightweight function approximation model, forming a joint risk upper bound mapping.
[0162] (2) Online confrontation decision-making process
[0163] During task execution, when the unmanned vehicle side security agent module receives a control type security message from session i, the online confrontation decision-making process includes:
[0164] a) Single session budget verification: Read the session risk budget field and consumed risk value of the session, judge whether the consumed risk after executing this instruction exceeds the budget, if it exceeds, directly refuse to execute;
[0165] b) Residual budget calculation: Without changing the state of other sessions, calculate the residual risk budget combination after executing this instruction, including the updated residual budget of session i and the current residual budget of other sessions;
[0166] c) Current state and environment acquisition: Obtain the current unmanned vehicle state and environment scenario information through telemetry data;
[0167] d) Joint risk upper bound query: input the current vehicle state, environment scenario, updated session budget combination, and the maximum number of compromised sessions k, query or calculate the corresponding joint risk upper bound value from the joint risk upper bound mapping;
[0168] e) System-level security limit comparison: compare the above-mentioned joint risk upper bound value with the pre-configured system-level security limit;
[0169] f) Decision and execution: if the joint risk upper bound does not exceed the system-level security limit, the control command is issued to the unmanned vehicle control module after trajectory prediction and multi-dimensional constraint verification, and the session consumed risk value and dynamic trust score are updated; if the joint risk upper bound exceeds the system-level security limit, the command is rejected, and the relevant security event is recorded.
[0170] Through the above online confrontation decision-making process, the embodiment can evaluate whether the system is still within an acceptable risk range under the worst-case scenario of multi-session coordinated attacks from the perspective of the system as a whole each time a control command is received, thereby achieving essential protection against multi-session coordinated attacks.
[0171] Embodiment five: multi-control terminal conflict resolution
[0172] Referring to Figure 6 , the multi-control terminal conflict resolution process in the embodiment includes:
[0173] 1. Conflict detection: when the unmanned vehicle side security agent module receives mutually exclusive control commands from different sessions within a preset time window, it identifies that these commands have mutually exclusive relationships with the control state of the unmanned vehicle, for example, one command requires acceleration, and another command requires emergency braking;
[0174] 2. Safety priority determination: determine the safety priority of each command according to the command type, for example, emergency obstacle avoidance and high-risk alarm handling commands have the highest priority, and general task commands have lower priority;
[0175] 3. Risk budget evaluation: read the session risk budget field and the remaining risk budget of each session, calculate the remaining risk budget ratio to reflect the "space" of the session in the overall risk allocation of the system;
[0176] 4. Dynamic trust evaluation: maintain the session dynamic trust score based on historical command behavior, security event records, and other information, and sessions with higher trustworthiness can obtain higher weights in conflict resolution;
[0177] 5. Comprehensive sorting: according to the command safety priority, the session remaining risk budget ratio, and the dynamic trust score, the conflict commands are comprehensively sorted according to the preset rules, and the command with the optimal sorting result is selected as the candidate command;
[0178] 6. Counter decision and execution: joint risk budget decision of candidate instruction execution trajectory prediction, multi-dimensional constraint check and counter session, and execution by the following, the rest of the conflict instructions are rejected or delayed processing;
[0179] 7. Feedback and adjustment: report the conflict decision result to the ground in a telemetry manner for the commander to refer to, and adjust the subsequent session risk budget configuration and trust management strategy accordingly.
[0180] Through the above-mentioned multi-control terminal conflict decision mechanism, the embodiment can prioritize the execution of safety-related instructions while avoiding risk budget depletion or excessive control of low-trust sessions in the presence of multiple control sessions.
[0181] Embodiment six: system deployment and application scenarios
[0182] The system of the present application can be deployed on various unmanned vehicle platforms, including but not limited to fixed-wing unmanned aerial vehicles, multi-rotor unmanned aerial vehicles, vertical take-off and landing unmanned aerial vehicles, unmanned vehicles, unmanned ships, and unmanned cluster systems. According to the communication interface and control bus type of different platforms, the unmanned vehicle side safety agent module can be integrated with the control module in the form of network gateway, serial relay, CAN bus middleware, etc.
[0183] In typical application scenarios, the present application can be used for:
[0184] Safety command and control of police unmanned aerial vehicles in complex electromagnetic and network countermeasures environment;
[0185] Safety constraints on high-risk payload unmanned vehicles in law enforcement supervision;
[0186] Risk control of urban low-altitude logistics unmanned aerial vehicles under multi-control center collaborative scheduling;
[0187] Multi-session safety control of unmanned cluster cooperative combat or cooperative operation.
[0188] Those skilled in the art should understand that the above embodiments of the present application are only used to illustrate the present application, and are not used to limit the present application. For those skilled in the art, various modifications and changes can be made to the above embodiments without departing from the spirit and essence of the present application, and these modifications and changes should fall within the protection scope of the claims of the present application.
Claims
1. A zero-trust safety command and control system for unmanned vehicles based on session risk budgeting, characterized in that, include: The control terminal is used to run ground command and control software and generate control commands for unmanned vehicles. The zero-trust access control gateway is used to perform identity authentication, fine-grained access control and session management on the control terminal, and to issue task credentials to the control terminal when a control session is established. The task credentials include at least a session identifier field, a control capability field, a spatial constraint field, a time constraint field and a session risk budget field. The ground station security agent module is deployed between the control terminal and the command and control communication link in a transparent proxy or low-intrusion manner. It is used to intercept the control command, parse the mission credentials, calculate the risk consumption value of the control command based on the control command type and the current state of the unmanned vehicle, and encapsulate the control command and the risk consumption value into a control-type security message carrying a session identifier and a mission credential digest. A command and control communication link is used to transmit the control-type safety messages and telemetry-type safety messages between the ground side and the unmanned vehicle; The unmanned vehicle side safety agent module is deployed in a transparent or low-intrusion manner between the command and control communication link and the unmanned vehicle control module. It is used to perform integrity verification and session binding verification on the received control-type safety messages, make local decisions based on session risk budget and predicted trajectory, and execute adversarial session joint risk budget decision-making methods. The unmanned vehicle control module includes a flight control system, a drive control unit, a mission payload control unit, etc., and is used to execute control commands released by the unmanned vehicle-side safety agent module. The operation monitoring and digital twin simulation module is used to collect unmanned vehicle status and environmental data, construct unmanned vehicle motion models and task environment models, and simulate multi-session cooperative control under set attack scenarios to construct a joint risk upper bound mapping. The unmanned vehicle-side security agent module includes: Maintain the session risk budget, consumed risk, and remaining risk budget corresponding to each control session; If the predicted trajectory satisfies the spatial and temporal constraints, then firstly, based on the session risk budget field and consumed risk of the corresponding session, the risk consumption value carried by the control-type security message is checked for single session risk budget. When the single-session risk budget verification passes, based on the current unmanned vehicle status, mission environment, remaining risk budget of all control sessions, and the preset maximum number of controlled sessions k, the worst-case joint risk upper bound that may occur within the prediction time window is determined from the joint risk upper bound mapping. The worst-case joint risk upper bound is compared with the system-level safety limit. Only when the worst-case joint risk upper bound does not exceed the system-level safety limit is the control command issued to the unmanned vehicle control module for execution; otherwise, the control command is rejected and a safety event is recorded.
2. The system according to claim 1, characterized in that, The unmanned vehicle-side safety agent module performs integrity and session binding verification on received control-type safety messages, makes local decisions based on session risk budget and predicted trajectory, and executes an adversarial session joint risk budget decision-making method. The specific process is as follows: Perform integrity verification and session binding verification on received control-type security messages; Retrieve the session risk budget field, spatial constraint field, and time constraint field from the bound task credentials; Within a preset prediction time window, the trajectory of the unmanned vehicle after the execution of the control command is discretely predicted, and the predicted trajectory is compared point by point with the spatial and temporal constraints. Provided that the trajectory prediction does not enter the danger zone and does not violate the time constraint, continue to perform risk budget verification and joint risk adjudication of the adversarial session; If trajectory prediction indicates that the instruction will lead the unmanned vehicle into a dangerous area or violate the mission time constraint, then the instruction will be rejected directly.
3. The system according to claim 1, characterized in that, The configuration of the session risk budget field is determined by the zero-trust access control gateway based on at least one of the following: Mission types include at least one of patrol, reconnaissance, strike, emergency response, and training; The security level of the mission area includes at least one of the following: general area, sensitive area, and no-fly / no-access area; The role to which the control terminal belongs includes at least one of the following: combat command, intelligence, training, and maintenance. The unmanned vehicle platform capabilities and payload types, the value corresponding to the session risk budget field is configured between a preset lower limit and an upper limit, wherein the preset upper limit is preferably less than or equal to 50% of the system-level safety limit.
4. The system according to claim 1, characterized in that, The unmanned vehicle-side safety agent module includes the following when performing trajectory prediction: A prediction time window with a length of 1 to 10 seconds is used, and the prediction time window is discretized according to a time step of 50 to 500 milliseconds; Based on the current unmanned vehicle status and control commands, the predicted position of the unmanned vehicle is calculated at each time step, and compared point by point with the safe area, buffer area and no-fly / no-drive area corresponding to the spatial constraint field. If the target enters a no-fly / no-access zone or violates the task time window defined by the time constraint field at any point on the predicted trajectory, the control command will be rejected immediately.
5. The system according to claim 1, characterized in that, The process of constructing the joint risk upper bound mapping by the operation monitoring and digital twin simulation module includes: Define the state variables of the unmanned vehicle, including at least two of the following: position, speed, attitude, battery level, and load status; Establish a set of mission environment scenarios, including different terrains, obstacle distributions, and no-fly / no-access zone configurations; For different numbers of sessions, combinations of session risk budgets, and a maximum number of controlled sessions k, an attack scenario is set in which an attacker can arbitrarily select control commands and their time sequences within the predicted time window, within the range of the session risk budget. Simulations were performed on a large number of state, environment and session budget combinations to evaluate the risk level that the unmanned vehicle may reach within the prediction time window under each attack scenario, and the maximum risk that the attacker can achieve in each scenario was taken as the corresponding joint risk upper bound. A mapping relationship is established between the unmanned vehicle state, mission environment, session budget combination, and the maximum number of controlled sessions k and the joint risk upper bound value to form the joint risk upper bound mapping.
6. The system according to claim 5, characterized in that, The joint risk upper bound mapping is implemented using at least one of the following methods: Based on a multidimensional discrete grid lookup table, each grid cell stores the joint risk upper bound value under the corresponding combination of state, environment and session budget; A function approximation model based on decision trees, gradient boosting trees, or lightweight neural networks is used. The input of the function approximation model includes unmanned vehicle state features, environmental features, session budget features, and the maximum number of controlled sessions k. The output is a joint risk upper bound estimate.
7. The system according to claim 1, characterized in that, The unmanned vehicle-side safety agent module is also used to maintain the dynamic trust score of each control session and adjust the effective risk budget of the session based on the dynamic trust score. Specifically, the dynamic trust score is updated according to the session's historical control command behavior, triggered security events, and audit results. When a control session repeatedly issues control commands that cause the joint risk upper bound to approach the system-level security limit, its effective risk budget upper limit is reduced. When a control session continuously issues control commands that comply with the security policy for a long period of time without triggering security events, its effective risk budget upper limit is appropriately increased, but not exceeding the maximum value configured in the session risk budget field.
8. The system according to claim 1, characterized in that, There is one or more control terminals. The unmanned vehicle-side safety agent module performs conflict resolution when multiple control sessions issue mutually exclusive control commands to the same unmanned vehicle, including the following process: Detect whether there is a mutual exclusion relationship between the control commands received within a preset time window in terms of control direction, control quantity, or control mode; The safety priority of each control command is determined according to the command type, so that emergency obstacle avoidance, fault handling and safe landing commands have higher priority than general mission control commands. Read the remaining risk budget for each session and calculate the proportion of the remaining risk budget to the configured value of the session risk budget field; Obtain dynamic trust scores for each session; Based on the comprehensive ranking results of safety priority, remaining risk budget ratio and dynamic trust score, a target control command is selected from the mutually exclusive control commands. The target control command is then subjected to trajectory prediction, multi-dimensional constraint verification and adversarial session joint risk budget adjudication. The target control command is only sent to the unmanned vehicle control module for execution when the above adjudication is passed.
9. The system according to claim 1, characterized in that, The unmanned vehicle is at least one of the following: fixed-wing UAV, multi-rotor UAV, vertical take-off and landing UAV, unmanned vehicle, unmanned boat, or unmanned swarm.
10. A zero-trust safety command and control method for unmanned vehicles based on session risk budgeting, characterized in that, Includes the following steps: Step 1: The zero-trust access control gateway performs identity authentication and fine-grained authorization on the control terminal, and issues task credentials containing a session risk budget field for the control session. Step 2: The ground station security agent module intercepts the control commands generated by the control terminal, parses the mission credentials, calculates the risk consumption value based on the control command type and the current state of the unmanned vehicle, and encapsulates the control commands and risk consumption value into a control-type security message before sending it to the unmanned vehicle through the command and control communication link. Step 3: The unmanned vehicle side safety agent module receives control-type safety messages, completes integrity verification and session binding verification, performs trajectory prediction within a preset prediction time window based on the current unmanned vehicle status, and compares the predicted trajectory with the spatial constraint field and time constraint field in the task certificate. Step 4: If the trajectory prediction and multidimensional constraint verification pass, the unmanned vehicle side safety agent module performs single session risk budget verification based on the session risk budget field in the task certificate and the maintained consumed risk record. If the consumed risk exceeds the corresponding session risk budget after executing the control command, the control command is rejected. Step 5: If the single-session risk budget verification passes, the unmanned vehicle-side safety agent module obtains the remaining risk budget, current unmanned vehicle status and task environment characteristics of all current control sessions, and determines the worst joint risk upper bound within the prediction time window from the joint risk upper bound mapping based on the preset maximum number of controlled sessions k. Step 6: Compare the worst-case joint risk upper bound with the system-level safety limit. Only when the worst-case joint risk upper bound does not exceed the system-level safety limit will the control command be sent to the unmanned vehicle control module for execution, and the consumed risk record and dynamic trust score of the corresponding session will be updated. Otherwise, the control command will be rejected and the safety event will be recorded.