Low-altitude agent interconnection system and method based on mobile SIM (Subscriber Identity Module) card
By constructing a low-altitude intelligent agent interconnection system based on a mobile SIM card-based TEE, the key management and protocol compatibility issues in low-altitude intelligent agent interconnection security technology are resolved, achieving efficient security protection and business processing, and ensuring the reliability and integrity of data transmission.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-30
- Publication Date
- 2026-03-27
AI Technical Summary
Existing low-altitude intelligent agent interconnection security technologies suffer from problems such as high key management complexity, insufficient protocol compatibility, and centralized authentication architecture's inability to cope with distributed attack threats in dynamic networking scenarios, which affect task execution efficiency.
A Trusted Execution Environment (TEE) is constructed using an embedded security chip based on a mobile SIM card to achieve full lifecycle management of keys. A globally unique identity is generated through multi-dimensional composite authentication, a quantum encrypted transmission channel is established, and a lightweight BFT consensus protocol and an off-chain and on-chain collaborative evidence storage mechanism are adopted to dynamically adjust encryption algorithm parameters and authentication processes to balance security protection strength and business processing efficiency.
It ensures distributed and trusted storage of behavioral data across the entire chain, improves the integrity rate of storage and the efficiency of traceability and location, and enhances business processing efficiency and security protection capabilities.
Smart Images

Figure CN121751174A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application relates to the technical field of artificial intelligence, in particular to a low-altitude intelligent body interconnection system and method based on a mobile SIM card. BACKGROUND
[0002] Under the background of continuous breakthroughs in artificial intelligence technology, the development of general-purpose AI intelligent bodies has entered a critical point of large-scale application. Intelligent body products represented by Manus exhibit the transformation potential of AI from "dialogue interaction" to "productivity tools" through characteristics such as autonomous task decomposition and multi-tool calling. Such products can realize cross-platform collaboration through natural language instructions, such as automatically generating travel guides and analyzing stock data, and the technical controversy and market heat caused by their release reflect the industry's high attention to the value of intelligent body technology.
[0003] The low-altitude field will most likely become the first breakthrough point for large-scale commercial use of intelligent bodies; this trend is driven by three core drivers: first, the maturity of technology has broken through, the fusion of 5G private networks and edge computing enables millisecond-level collaborative response of unmanned vehicle clusters, and lightweight AI models enable individual intelligent bodies to have local decision-making capabilities; second, the demand for scenes has exploded, the successful application of low-altitude vehicles in low-altitude transportation, agricultural plant protection, emergency rescue, smart cities and other fields has verified that the low-altitude economy has the basic conditions for large-scale commercial use, for example, the "unmanned vehicle + robot" three-dimensional distribution network in Shenzhen has realized efficient operation of 3000 orders per day, and the formal operation of multiple civilian manned unmanned vehicle routes in Shanghai has effectively verified the commercial feasibility and technical completeness of intelligent low-altitude economy; finally, the policy dividend is released, more than 20 countries around the world have opened up low-altitude digital airspace management systems, providing a compliant operation framework for multi-intelligent body collaboration.
[0004] In the process of accelerating the landing of the low-altitude economy, intelligent body interconnection security technology has become a key technical bottleneck restricting the large-scale development of the industry. The current mainstream solution mainly relies on traditional PKI certificate systems, lightweight encryption protocols, and identity verification based on blockchains, but these technologies have exposed three core contradictions in dynamic networking scenarios: the exponential key management complexity generated by multi-intelligent body collaboration leads to communication delay exceeding the standard, the lack of protocol compatibility in heterogeneous network environments causes system-level risks, and the centralized authentication architecture is difficult to cope with distributed attack threats. More seriously, the existing security framework cannot adapt to the high dynamicity requirements specific to the low-altitude scene, directly affecting the efficiency of task execution.
[0005] In view of the defects of the prior art, the application provides a low-altitude intelligent body interconnection system and method based on a mobile SIM card. SUMMARY
[0006] To achieve the above purpose, the application adopts the following technical solutions: In one aspect of the present application, a method for low-altitude intelligent entity interconnection based on mobile SIM card is provided, comprising the following steps: An embedded secure chip based on mobile SIM card is used to build a trusted execution environment (TEE), and the TEE is used to implement key lifecycle management; User behavior characteristics, terminal hardware identification and digital certificate information of the intelligent entity are collected, and multi-dimensional composite authentication is performed to generate a globally unique identity; Heterogeneous network protocol conversion is performed through a unified security gateway layer, and a quantum encryption transmission channel is established; According to a preset C1-C4 data sensitivity grading strategy, authentication security strength is dynamically matched with business scenario requirements; A lightweight BFT consensus protocol and an off-chain and on-chain collaborative evidence storage mechanism are used to realize distributed and trusted storage of all-link behavior data; Based on a reinforcement learning algorithm, security situation is evaluated in real time, and encryption algorithm parameters and authentication processes are dynamically adjusted to balance security protection strength and business processing efficiency.
[0007] In an optional implementation, the dynamic matching of authentication security strength and business scenario requirements comprises: C1 invention data, C2 internal data, C3 sensitive data and C4 core data are classified according to four levels of sensitivity of the transmission data; Single-factor authentication is used for C1-level data, two-factor authentication is used for C2-level data, three-factor authentication is used for C3-level data, and quantum encryption + multi-factor authentication is used for C4-level data.
[0008] In an optional implementation, the multi-dimensional composite authentication comprises: The terminal hardware identification is verified through an SM2 elliptic curve algorithm; User operation behavior characteristics are collected for behavior authentication; An STK pop-up box instruction of the mobile SIM card is called to trigger secondary user confirmation, so as to complete strong reach authentication.
[0009] In an optional implementation, the embedded secure chip is EAL4+, and the TEE is built through the following steps: An independent execution area is divided in the SIM card security chip, and key storage and business logic are isolated; A random mask technology of an SM4 algorithm is used to resist side channel attacks on data in the TEE; A quantum resistance migration protocol is integrated to support post-quantum cryptographic algorithm upgrade.
[0010] In an optional implementation, the key lifecycle management comprises: Generate an initial key pair within the TEE and obtain the session key through a quantum key distribution network; The root key is stored using hardware binding, and key rotation is achieved through an OTA remote update mechanism. The key usage process is audited and logged, and then uploaded to the dynamic consensus and evidence storage module.
[0011] In one optional implementation, the protocol conversion of the unified security gateway layer includes: Analyze the frame structure and encapsulation format of heterogeneous networks; The intelligent protocol conversion engine maps data from different protocols to a unified secure transmission frame format. Data integrity checks are performed during the conversion process.
[0012] In one alternative implementation, the quantum encryption channel is established in the following manner: Quantum keys are generated by a quantum key distribution network and injected through the security chip of a mobile SIM card. A quantum random number generator is used to generate session keys, and an end-to-end encrypted channel is constructed by combining the AES-GCM algorithm. A quantum bit commitment protocol is used in the key negotiation process to prevent man-in-the-middle attacks.
[0013] In one optional implementation, the lightweight BFT consensus protocol includes: The agent nodes are divided into a verification node group and a consensus node group, and the verification node group performs data preprocessing. A group consensus mechanism is adopted, and the number of nodes in each group is dynamically adjusted to reduce communication overhead; The consensus result is stored in a lightweight manner using a combination of off-chain storage and on-chain hash anchoring.
[0014] In one optional implementation, the reinforcement learning algorithm includes a combined model of Monte Carlo tree search and federated learning, wherein the input parameters of the model include: Current network topology change frequency, data transmission latency threshold, remaining device battery power, and types of historical attack events; The output parameters include the encryption algorithm type, the number of authentication steps, and the key update cycle.
[0015] In one optional implementation, the STK pop-up command interaction process includes: The terminal sends a pop-up request command in the BIP protocol to the SIM card; The SIM card generates a random challenge code via TEE and returns a pop-up response command; After the user enters the challenge code and the verification is successful, the SIM card outputs the "Authentication Successful" command and releases the session key.
[0016] In one optional implementation, the dynamic adjustment of encryption algorithm parameters includes: When a DoS attack is detected, it automatically switches to a lightweight encryption algorithm; Low-power encryption mode is enabled when the device battery level is below 20%. When transmitting C4 level data, the automatic key rotation mechanism is forced to be enabled every 30 seconds.
[0017] In one optional implementation, the multidimensional composite authentication further includes: Collect the physical environment parameters of the intelligent agent as auxiliary authentication factors; When the deviation of physical environment parameters from the historical baseline exceeds a preset threshold, secondary authentication is triggered.
[0018] In one optional implementation, the quantum-resistant transfer protocol includes: Pre-defined adaptation interface for quantum cryptography algorithm; When a quantum computing threat is detected, the existing RSA / ECC key pair is automatically migrated to a lattice-based cryptosystem.
[0019] In one optional implementation, the unified security gateway layer further includes: Protocol conversion rule base, storing the mapping relationship between LoRaWAN, ZigBee, and 5GNR protocols; The intelligent routing engine dynamically selects the optimal transmission path based on network bandwidth and latency.
[0020] Another aspect of the present invention provides a low-altitude intelligent agent interconnection system based on a mobile SIM card, comprising: The multi-dimensional authentication module is configured to integrate user behavior authentication, terminal identity authentication, and digital certificate authentication to generate a globally unique identity identifier. The hardware security enhancement module, integrated into the EAL4+ level security chip of the mobile SIM card, is used to build an in-memory computing TEE and provide key lifecycle protection. An adaptive secure transmission module includes a unified security gateway and a quantum encryption channel, wherein the unified security gateway is configured to perform heterogeneous protocol conversion; The security efficiency collaborative optimization module is configured to dynamically adjust encryption algorithm parameters and authentication processes based on threat perception results. The dynamic consensus notarization module is configured to notarize behavioral data through a lightweight BFT consensus protocol and an off-chain / on-chain collaborative mechanism.
[0021] In one optional implementation, the hardware security enhancement module further includes: The cryptographic acceleration submodule is configured to optimize the computational efficiency of the SM2 algorithm through elliptic curve pre-computation. The anti-side-channel attack submodule is configured to apply a random mask and time perturbation to the SM4 encryption process.
[0022] In one optional implementation, the security efficiency collaborative optimization module includes: The threat perception submodule is configured to use an improved isolated forest algorithm to detect abnormal behavior and to identify attack patterns using a lightweight CNN model. The dynamic adjustment submodule is configured to automatically switch predefined security policy templates based on the threat level.
[0023] In one optional implementation, the cryptographic acceleration submodule optimizes the SM2 algorithm in the following way: Pre-compile a table of multiples of the base points of the elliptic curve, reducing the complexity of scalar multiplication operations from O(n) to O(logn); By employing a parallel computing architecture to process multiple key pair generation requests simultaneously, the computational efficiency is improved by ≥30%.
[0024] In an optional implementation, the dynamic consensus evidence storage module is further configured as follows: The evidence storage data is segmented, and each segment generates a unique Merkle tree hash value; The Merkle tree root hash is stored on-chain, while the complete shard data is stored off-chain, supporting verification of data integrity through the root hash.
[0025] In one optional implementation, the multidimensional authentication module includes: The user behavior authentication submodule is configured to identify user operation features through an LSTM neural network model. The terminal identity authentication submodule is configured to read the eSIM embedded identifier and perform hardware binding verification. The digital certificate submodule is configured to interface with a CA server to implement certificate chain verification.
[0026] In one optional implementation, the detection process of the threat perception submodule includes: Network traffic characteristics are collected, and anomaly scores are calculated using an improved isolated forest algorithm. When the score exceeds a threshold, a lightweight CNN model is triggered to classify the attack type.
[0027] In one optional implementation, the hardware security enhancement module further includes: The anti-physical attack submodule is configured to automatically trigger a key erasure command when an abnormal voltage or physical disassembly is detected. The cryptographic resource service interface supports third-party applications in calling the SM2 / SM3 / SM4 national cryptographic algorithms and the FIDO2 biometric authentication protocol.
[0028] In another aspect, the present invention provides an electronic device comprising: At least one memory stores computer-executable instructions non-transiently; At least one processor, configured to run the computer-executable instructions, The computer-executable instructions are executed by the processor to implement the aforementioned low-altitude intelligent agent interconnection method based on a mobile SIM card.
[0029] In another aspect, the present invention provides a computer-readable storage medium storing computer-executable instructions that, when executed by at least one processor, implement the aforementioned method for low-altitude intelligent agent interconnection based on a mobile SIM card.
[0030] Effects of the invention: A Trusted Execution Environment (TEE) is constructed using an embedded security chip based on a mobile SIM card, enabling full lifecycle management of keys. User behavior characteristics, terminal hardware identifiers, and digital certificate information of intelligent agents are collected, and multi-dimensional composite authentication is performed to generate a globally unique identity. A unified security gateway layer is used to convert heterogeneous network protocols and establish a quantum-encrypted transmission channel. Based on a preset C1-C4 data sensitivity grading strategy, the authentication security strength is dynamically matched to business scenario requirements. A lightweight BFT consensus protocol and an off-chain / on-chain collaborative evidence storage mechanism are adopted to achieve distributed trusted evidence storage of the entire chain of behavioral data. A reinforcement learning algorithm is used to evaluate the security situation in real time and dynamically adjust encryption algorithm parameters and authentication processes to balance security protection strength and business processing efficiency. This invention ensures evidence integrity and improves traceability and location efficiency, and uses a cryptographic acceleration module and a dynamic strategy model to improve business efficiency under the same security strength. Attached Figure Description
[0031] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used in conjunction with embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings: Figure 1 This is a flowchart of a low-altitude intelligent agent interconnection method based on a mobile SIM card provided in Embodiment 1 of the present invention; Figure 2 This is a framework diagram of a low-altitude intelligent agent interconnection system based on a mobile SIM card provided in Embodiment 3 of the present invention; Figure 3 This is a block diagram of the electronic device provided in Embodiment 4 of the present invention; Figure 4 This is a block diagram of a computer-readable storage medium provided in Embodiment 4 of the present invention. Detailed Implementation
[0032] The technical solutions of the present invention will now be described with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments.
[0033] Hereinafter, the terms "first," "second," etc., are used for descriptive convenience only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Thus, a feature defined with "first," "second," etc., may explicitly or implicitly include one or more of that feature. In the description of this invention, unless otherwise stated, "a plurality of" means two or more.
[0034] In this invention, unless otherwise explicitly specified and limited, the term "connection" should be interpreted broadly. For example, "connection" can be a fixed mechanical connection, a detachable mechanical connection, or an integral part; or, "connection" can be a direct connection or an indirect connection through an intermediate medium. Furthermore, unless otherwise explicitly specified and limited, the term "coupling" should be interpreted broadly. For example, "coupling" can be a direct electrical connection, such as physical contact and electrical conduction between two components; it can also be understood as an electrical connection between different components in a circuit structure through physical lines capable of transmitting electrical signals, such as copper foil or wires on a printed circuit board (PCB), to transmit electrical signals; or, "coupling" can be an indirect electrical connection between two components through an intermediate medium; or, "coupling" can be an electrical connection between two components in a non-contact manner, such as an electrical connection between two components using capacitive coupling to transmit electrical signals.
[0035] In this embodiment of the invention, directional terms such as "up," "down," "left," and "right" may be defined relative to the orientation of the components shown in the accompanying drawings. It should be understood that these directional terms can be relative concepts, used for relative description and clarification, and can change accordingly depending on the orientation of the components in the accompanying drawings.
[0036] Example 1: like Figure 1 As shown, this embodiment of the invention provides a method for low-altitude intelligent agent interconnection based on a mobile SIM card, comprising the following steps: S100: An embedded security chip based on a mobile SIM card constructs a Trusted Execution Environment (TEE), through which key lifecycle management is achieved; S200: Collects user behavior characteristics, terminal hardware identification and digital certificate information of intelligent agents, and performs multi-dimensional composite authentication to generate a globally unique identity identifier; S300: It performs heterogeneous network protocol conversion through a unified security gateway layer and establishes a quantum-encrypted transmission channel; S400: Dynamically matches authentication security strength with business scenario requirements based on the preset C1-C4 data sensitivity classification strategy; S500: It adopts a lightweight BFT consensus protocol and an off-chain and on-chain collaborative evidence storage mechanism to achieve distributed and trusted evidence storage of behavior data across the entire chain. S600: Based on reinforcement learning algorithms, it assesses the security situation in real time and dynamically adjusts encryption algorithm parameters and authentication processes to balance security protection strength and business processing efficiency.
[0037] In the above embodiments, a dynamic hierarchical authentication strategy ensures the security of route command (C4 level) transmission and last-mile delivery security: SIM card binding technology prevents delivery terminals from being hijacked, and biometric authentication enables "face-scanning signature" for valuable items. The drone inspection system utilizes a SIM card-based TEE (Transmission Equipment for Storage and Computation) to encrypt sensitive data (such as power line inspection images), and dynamic consensus-based evidence storage technology ensures the non-repudiation of inspection results. Digital airspace governance uses a threat perception model to monitor abnormal drone behavior in real time, improving the security level of the low-altitude air defense system. Resilient communication is ensured: in extreme environments such as earthquake-stricken areas, a temporary key distribution center is built using a SIM card security chip to ensure reliable transmission of emergency rescue commands through a quantum encryption channel. Personnel location tracking is achieved using SIM card number retrieval capabilities and base station positioning technology, enabling trapped personnel to "call for help with precise location." Precision agricultural protection: During plant protection drone spraying operations, a data sensitivity grading mechanism is used to protect farmland geographic information (C3 level) and prevent agricultural data leakage; Collaborative operation of agricultural machinery: An improved BFT consensus protocol is adopted to achieve secure networking of multiple harvesters and ensure the accuracy of synchronized operation instructions.
[0038] Example 2: like Figure 1 As shown, based on Example 1, the steps provided in this embodiment of the invention include the dynamic matching of authentication security strength and business scenario requirements, including: Transmitted data is classified into four levels of sensitivity: C1 Invention Data, C2 Internal Data, C3 Sensitive Data, and C4 Core Data. Single-factor authentication is used for C1 level data, two-factor authentication for C2 level data, three-factor authentication for C3 level data, and a combination strategy of quantum encryption and multi-factor authentication for C4 level data.
[0039] In one optional implementation, the multidimensional composite authentication includes: Verify the terminal hardware identifier using the SM2 elliptic curve algorithm; Collect user operation behavior characteristics for behavior authentication; The STK pop-up command of the mobile SIM card is invoked to trigger the user's secondary confirmation in order to complete the strong reach authentication.
[0040] In one optional implementation, the embedded security chip is EAL4+ level, and the TEE is constructed through the following steps: Within the SIM card security chip, an independent execution area is defined to isolate key storage and business logic; Random masking technology based on the SM4 algorithm is used to strengthen the data within the TEE against side-channel attacks; Integrate quantum-resistant transfer protocols to support post-quantum cryptography algorithm upgrades.
[0041] In one optional implementation, the key lifecycle management includes: Generate an initial key pair within the TEE and obtain the session key through a quantum key distribution network; The root key is stored using hardware binding, and key rotation is achieved through an OTA remote update mechanism. The key usage process is audited and logged, and then uploaded to the dynamic consensus and evidence storage module.
[0042] In one optional implementation, the protocol conversion of the unified security gateway layer includes: Analyze the frame structure and encapsulation format of heterogeneous networks; The intelligent protocol conversion engine maps data from different protocols to a unified secure transmission frame format. Data integrity checks are performed during the conversion process.
[0043] In one alternative implementation, the quantum encryption channel is established in the following manner: Quantum keys are generated by a quantum key distribution network and injected through the security chip of a mobile SIM card. A quantum random number generator is used to generate session keys, and an end-to-end encrypted channel is constructed by combining the AES-GCM algorithm. A quantum bit commitment protocol is used in the key negotiation process to prevent man-in-the-middle attacks.
[0044] In one optional implementation, the lightweight BFT consensus protocol includes: The agent nodes are divided into a verification node group and a consensus node group, and the verification node group performs data preprocessing. A group consensus mechanism is adopted, and the number of nodes in each group is dynamically adjusted to reduce communication overhead; The consensus result is stored in a lightweight manner using a combination of off-chain storage and on-chain hash anchoring.
[0045] In one optional implementation, the reinforcement learning algorithm includes a combined model of Monte Carlo tree search and federated learning, wherein the input parameters of the model include: Current network topology change frequency, data transmission latency threshold, remaining device battery power, and types of historical attack events; The output parameters include the encryption algorithm type, the number of authentication steps, and the key update cycle.
[0046] In one optional implementation, the STK pop-up command interaction process includes: The terminal sends a pop-up request command in the BIP protocol to the SIM card; The SIM card generates a random challenge code via TEE and returns a pop-up response command; After the user enters the challenge code and the verification is successful, the SIM card outputs the "Authentication Successful" command and releases the session key.
[0047] In one optional implementation, the dynamic adjustment of encryption algorithm parameters includes: When a DoS attack is detected, it automatically switches to a lightweight encryption algorithm; Low-power encryption mode is enabled when the device battery level is below 20%. When transmitting C4 level data, the automatic key rotation mechanism is forced to be enabled every 30 seconds.
[0048] In one optional implementation, the multidimensional composite authentication further includes: Collect the physical environment parameters of the intelligent agent as auxiliary authentication factors; When the deviation of physical environment parameters from the historical baseline exceeds a preset threshold, secondary authentication is triggered.
[0049] In one optional implementation, the quantum-resistant transfer protocol includes: Pre-defined adaptation interface for quantum cryptography algorithm; When a quantum computing threat is detected, the existing RSA / ECC key pair is automatically migrated to a lattice-based cryptosystem.
[0050] In one optional implementation, the unified security gateway layer further includes: Protocol conversion rule base, storing the mapping relationship between LoRaWAN, ZigBee, and 5GNR protocols; The intelligent routing engine dynamically selects the optimal transmission path based on network bandwidth and latency.
[0051] In the above embodiments, a "four-dimensional collaborative" intelligent security architecture is constructed, achieving a technological breakthrough with the mobile SIM card as the core security carrier. The system integrates terminal identification, network characteristics, and behavioral data to construct a multi-dimensional composite authentication mechanism, relies on the SIM card chip-level security capabilities to create a trusted computing environment, and achieves full lifecycle protection of keys and lightweight cryptographic services. An adaptive secure transmission architecture is built based on a unified gateway layer, connecting quantum encryption channels and dynamic consensus storage mechanisms to eliminate differences in heterogeneous network transmission. Simultaneously, we innovatively developed a cryptographic acceleration module and a threat perception model, achieving an autonomous balance between security strength and business efficiency through dynamic policy adjustment and intelligent algorithm-driven approaches.
[0052] This architecture integrates embedded security and distributed intelligence to form a closed-loop protection system covering identity authentication, data transmission, environment adaptation, and resource scheduling, providing a highly secure, low-latency, and highly compatible interconnected infrastructure for low-altitude intelligent agents.
[0053] Multidimensional authentication system construction technology; User behavior authentication technology; Integrate the SIM card security module with the mobile communication protocol to build an authentication mechanism: Strong user reach: Real-time interactive technology based on BIP protocol to trigger STK pop-ups The BIP protocol is used to realize encrypted command interaction between the terminal and the SIM card. The STK application pop-up forces the user to complete the PIN code confirmation or biometric input to ensure the authenticity and real-time operation.
[0054] Security process: Issue encryption command → SIM card decryption → Trigger pop-up window → User confirmation → Generate signature receipt.
[0055] Real-name authentication: Dynamic binding of SIM card number acquisition with data from the Ministry of Public Security; By embedding a number retrieval function in the SIM card, the system links the operator's real-name database with the Ministry of Industry and Information Technology's real-name database to achieve two-factor verification of users.
[0056] Dynamic verification of aircraft terminals: a linkage mechanism between flight trajectory deviation and secondary authentication; When the drone's flight path deviates from the threshold (e.g., horizontal displacement > 50m or altitude error > 10m), the STK pop-up window is forcibly activated via the BIP protocol to require the operator to perform secondary authentication.
[0057] Cross-validation: The data reported by the SIM card is compared with the data sensed by the base station. If the IMSI does not match the device fingerprint hash value, the certificate is revoked.
[0058] End-user authentication technology: This forms a three-stage authentication closed loop, from certificate issuance to SIM card identity authentication and then to SIM card binding; Trusted certificate issuance: based on SIM card encryption chip and collaborative signature technology; Process: Generate certificate request in the cloud → The security chip in the SIM card signs using the SM2 algorithm → Return the signing result to the cloud to issue the certificate.
[0059] Security features: The certificate is bound to the user's identity (real-name data) and device information (IMEI / chip serial number), supporting non-repudiation.
[0060] SIM card authentication: Improved AKA protocol and random number challenge response mechanism; Two-way authentication process: The network side sends a random number RAND → the SIM card generates an SRES response using the Ki key → the matching is verified.
[0061] Anti-attack design: Dynamic key generation resists replay attacks, and the SIM card security module isolates the key calculation process.
[0062] Device-SIM card binding: A multi-factor hash chain model combining device fingerprint hash and SIM card identifier; Binding process: Terminal hardware feature (IMEI) hash value → transmitted to the cloud via SIM card secure channel → construct a multi-factor composite key hash with IMSI / ICCID.
[0063] Anti-porting design: The binding relationship is permanently stored in the SIM card's secure storage area; unauthorized removal will trigger authentication failure.
[0064] Dynamic authentication strategy: Data sensitivity grading model: C1-C4 four-level classification standard and security strategy design: C4 Level (Flight Command Data): Superimposed Quantum-resistant Certificate + Biometric Authentication; C3 Level (Location Trajectory Data): SIM card binding + base station positioning verification; C2 Level (Device Status Data): Lightweight Dynamic Key Authentication; C1 Level (Task Metadata): Basic SIM Card Authentication.
[0065] Risk mapping mechanism: AI-driven abnormal behavior detection and homomorphic authentication strategy. Anomaly detection: The AI model is trained using historical flight patterns (cruising speed, altitude curve) to detect behaviors such as hovering and frequent changes of direction; Policy upgrade: Abnormal operations trigger multi-factor authentication (such as biometrics + dynamic token).
[0066] Dynamic switching logic: security policy driven by environment parameters; For example: Battery sensitive mode: Biometric identification is turned off when the battery is less than 20%, and only the SIM card dynamic token is retained; Latency sensitive mode: When the communication delay is greater than 50ms, it switches to the lightweight SM4 algorithm.
[0067] In-memory computing trusted execution environment: Secure computing engine: closed-loop processing of the entire SM2 / SM4 national cryptographic algorithm; Hardware architecture: The SIM card integrates a programmable computing unit, supporting parallel computation of SM2 signature and SM4 encryption; Data isolation: Key generation and signing operations are completed in a physically isolated environment, avoiding the risk of data leakage between the TEE and the main processor.
[0068] Lightweight protocol stack: Encrypted command interaction channel based on BIP protocol; Communication mechanism: The APDU instruction format is defined using the BIP protocol to achieve encrypted data transmission between the SIM card and the terminal; Code verification: The SIM card has a pre-installed certificate chain to verify the signature of the execution code and prevent malicious code injection.
[0069] Cross-platform SIM card channel and certificate application compatibility technology: It enables secure communication between SIM cards and terminal devices across intelligent systems through a standardized SIM card interface, supports certificate access from PCs, mobile devices and IoT devices, and pre-configures certificate lifecycle management functions within the SIM card to achieve secure authentication management that is independent of the environment.
[0070] Cryptographic acceleration technology and hardware circuit optimization: Elliptic curve pre-computation and modular inverse accelerator design; The hardware circuit pre-calculates the multiple point table of the elliptic curve base point G and stores it in the secure storage area of the SIM card. During signature generation, the dedicated instruction EC_MULT is called to compute k·G=(x1,y1) in parallel, where k is a random number; The modulo inverse accelerator is used to calculate r = (e + x1) mod n, where e is the message hash value; Output the signature pair (r, s), and complete the entire process in a physically isolated area.
[0071] Side-channel hardening: randomization masking and compensation key techniques Before the S-box lookup in the SM4 algorithm, a random mask m is injected into the input byte x: x'=x⊕m; Use a pre-computed mask S-box S'(x')=S(x)⊕m', where m' is the output mask; During the round key addition phase, a mask compensation is applied to the key k: k'=k⊕(m⊕m'); The mask is removed during the final output to ensure that the power consumption trace is not related to sensitive data.
[0072] High-security scenario adaptation and quantum computing protection technology For highly sensitive scenarios, a layered anti-quantum attack scheme is designed, which uses the SM series of national cryptographic algorithms and quantum key distribution technology to resist the risk of quantum computing cracking.
[0073] Adaptive secure transport architecture: Threat perception model: Multi-source feature acquisition and correlation analysis: Perform the following data processing flow: Extract the timestamp t, operation type op, and key usage count c from the SIM card's encrypted log; Analyze network traffic to obtain the five-tuple characteristics (source IP, destination IP, port, protocol, packet length distribution); Construct a spatiotemporal feature matrix X∈R^(N×5), with each row corresponding to [t,op,c,packet_rate,entropy]; Anomaly detection using an improved isolated forest algorithm: Randomly select ψ sample subsets to construct T isolation trees; for each sample x_i in the feature matrix X, calculate the anomaly score: s(x_i,T)=2^(-E(h(x_i)) / c(T)) Where h(x_i) is the path length of x_i in the tree, and c(T) is the average path length of the tree; If s(x_i) > threshold θ, it is marked as abnormal behavior.
[0074] Lightweight threat inference engine: The optimization steps for the CNN model are as follows: Model compression: Channel pruning is performed on the pre-trained ResNet-18 to remove convolutional kernels with weight norms lower than γ; Quantization deployment: Convert 32-bit floating-point parameters to 8-bit fixed-point numbers, and use piecewise linear approximation for the activation function; When deployed at the gateway edge, the input traffic feature map F∈R^(32×32×3) is used to output the probability distribution of threat categories.
[0075] Dynamic defense strategy linkage: When a SIM card key leak is detected, the following dynamic security policy will be implemented; The trusted execution environment generates a temporary key pair (SK_temp, PK_temp). APDU commands are issued via the BIP protocol; After the SIM card security chip is decrypted, the original key is replaced, and the plaintext SK_temp is destroyed.
[0076] Dynamic consensus notarization: Lightweight BFT protocol: a group voting mechanism based on SIM card identifiers; Consensus process: Master node group pre-signs proposal → Verification node group performs batch signature verification → Group voting reaches consensus, latency can be controlled within 200ms.
[0077] Implementation examples of dynamic consensus notarization: Node credibility score; Each agent node collects its own and its neighboring nodes' operational data in real time through the built-in trust measurement module of the TEE, including: Hardware health (CPU / memory usage, remaining battery power); Historical behavior records (data transmission success rate, consensus response speed, number of malicious acts); Network status (latency, packet loss rate, link quality with the gateway).
[0078] Based on the above data, the real-time credibility score (range 0-100) of the node is calculated using a preset weighted algorithm (e.g., credibility score = 0.4 × hardware health + 0.3 × historical behavior records + 0.3 × network status).
[0079] Dynamic node group generation; The unified security gateway acts as the "consensus coordinator," dynamically selecting consensus node groups according to the following rules: When the data sensitivity is C3 / C4 (highly sensitive, such as flight control commands and encrypted sensor data), select nodes with a credibility score ≥80 to form a consensus group of 4-6 nodes (satisfying the fault tolerance threshold of lightweight BFT: n=3f+1, when f=1 n=4, tolerating 1 malicious node). When the data sensitivity is C1 / C2 (low sensitivity, such as environmental temperature and humidity data), select nodes with a credibility score ≥60 to form a simplified consensus group of 2-3 nodes (fault tolerance of 0-1 nodes, reducing consensus rounds). If the current number of trusted nodes is insufficient (e.g., below the minimum consensus size), the ground control center or highly trusted fixed nodes (e.g., base station edge nodes) will be temporarily added to the consensus group to supplement node resources.
[0080] To address the challenges of high network latency fluctuations and high agent mobility in low-altitude environments, this solution dynamically adjusts the core parameters of a lightweight BFT based on real-time network conditions. Consensus timeout (T): The average latency (Lat_avg) between nodes is collected through the network monitoring module built into the TEE, and T is set to 2 × Lat_avg + 50ms (reserve buffer time). When the network latency exceeds the threshold (e.g., Lat_avg > 200ms), T is automatically extended to 3 × Lat_avg to avoid consensus interruption due to network fluctuations; Consensus Rounds (R): High-sensitivity data (C3 / C4 level) uses 3 rounds of consensus (pre-preparation → preparation → commit) to ensure immutability; low-sensitivity data (C1 / C2 level) uses 2 rounds of simplified consensus (pre-preparation → commit) to reduce computational resource consumption; Signature verification strategy: When the node's battery level is below 20%, it automatically switches to "batch signature verification" mode (verifying a signature by merging every 5 data entries), reducing the computational overhead of a single verification.
[0081] Dynamic switching between on-chain and off-chain collaboration: To address the conflict between the high-frequency data generation of low-altitude intelligent agents and the limited bandwidth of on-chain evidence storage, this solution designs a dynamic collaborative mechanism of "off-chain caching - on-chain anchoring": Off-chain caching layer: In the local TEE secure storage area of each agent node (or the distributed cache of the edge gateway), high-frequency, low-sensitivity data (such as C1 level environmental data, sampling frequency 10Hz) is temporarily stored, and data digests (such as hash values, maximum / minimum values) are aggregated by time windows (such as 5 minutes / window) using a time series database (such as InfluxDB). On-chain evidence storage layer: Based on blockchain (such as consortium blockchain, nodes include trusted intelligent agents, ground control centers, and regulatory nodes), it stores key data, including: Complete record of C3 / C4 level data (such as UAV flight path coordinates and control commands); Window digest hash of off-chain cached data (aggregated digests are uploaded to the chain every 5 minutes to achieve "local storage of high-frequency data and on-chain anchoring of key evidence"); The consensus node group's dynamic adjustment record (node selection log, credibility score changes).
[0082] Dynamically switch trigger conditions: When the network bandwidth is ≥1Mbps (monitored in real time via TEE), the window summary of the off-chain cached data is uploaded to the chain in real time; When the network bandwidth is less than 1Mbps, the on-chain real-time anchoring is paused, and the off-chain cached data is temporarily stored locally. After the network is restored (bandwidth ≥ 1Mbps for 30 seconds), the data is uploaded to the chain in batches. When the risk of off-chain cached data being tampered with is detected (such as a digest hash that does not match the local record), an emergency on-chain process is immediately triggered to prioritize the on-chain storage of suspicious data and evidence of tampering.
[0083] Off-chain-on-chain collaboration: Two-layer notarization of SIM card signature hash and blockchain digest; Data storage: The original data hash value is signed by the SIM card security chip and stored locally, while the digest information is uploaded to the blockchain; Verification mechanism: The on-chain digest is compared with the off-chain hash value to verify the integrity of the data.
[0084] Quantum-resistant transfer: A seamless switching protocol between lattice-based signatures and the SM2 algorithm; Migration Trigger: Upon detection of a quantum attack, the post-quantum cryptography (PQC) migration protocol is initiated; A safety / efficiency collaborative optimization model algorithm is developed to address the need for balancing safety and efficiency in low-altitude intelligent agent interconnection. This algorithm employs a multi-objective optimization approach, employing a reinforcement learning-driven dynamic decision-making model to achieve optimal policy matching under resource constraints. Its core functionalities include: Multi-dimensional performance evaluation model: Defines three core indicators: security strength, authentication latency, and energy consumption. Employs the Analytic Hierarchy Process (AHP) to quantify the weights and trains a deep Q-network (DQN) based on historical data to establish nonlinear relationships between the indicators. Real-time strategy optimization mechanism: A candidate strategy set is generated through online Monte Carlo Tree Search (MCTS), and combined with the pre-set constraint rule base in the SIM card trusted execution environment, the optimal authentication and encryption combination strategy that meets the current network status (such as remaining battery power and signal strength) is selected. Incremental model update technology: Utilizes the secure storage area of the SIM card to cache the energy efficiency optimization data locally on the terminal, and periodically uploads it to the cloud through a quantum-encrypted channel for federated learning aggregation, continuously improving the model's generalization ability in complex spatial environments.
[0085] The intelligent agent interconnection process, specifically the mobile SIM card low-altitude intelligent agent interconnection system, is based on a three-stage closed-loop process of "authentication-transmission-proof storage." The detailed process steps are as follows: SIM card initialization and activation triggers the STK pop-up through the BIP protocol to complete user real-name authentication. The SIM card security chip generates the device fingerprint hash and binds it to the terminal IMEI. Dynamic identity authentication: The security gateway calls collaborative signature technology to issue digital certificates and completes two-way authentication of SIMKEY based on the improved AKA protocol; Data sensitivity classification, threat perception model analyzes flight data characteristics in real time, and dynamic authentication strategy engine generates graded protection strategies; Trusted execution environment processing, in-memory computing TEE performs SM2 / SM4 encrypted operations.
[0086] The cryptographic acceleration module implements side-channel hardening. Quantum encrypted transmission: Security gateway builds adaptive quantum channel Implementing protocol conversion eliminates differences in heterogeneous networks Dynamic consensus notarization involves signing the off-chain notarization hash using the SIM card security chip, and then completing the on-chain notarization using grouped BFT consensus.
[0087] The performance is optimized in real time, and the security / efficiency model is dynamically adjusted to adjust the algorithm parameters. Federated learning updates the threat perception model.
[0088] Example 3: like Figure 2 As shown, based on Embodiment 1, this embodiment of the invention provides a low-altitude intelligent agent interconnection system based on a mobile SIM card, comprising: The multi-dimensional authentication module is configured to integrate user behavior authentication, terminal identity authentication, and digital certificate authentication to generate a globally unique identity identifier. The hardware security enhancement module, integrated into the EAL4+ level security chip of the mobile SIM card, is used to build an in-memory computing TEE and provide key lifecycle protection. An adaptive secure transmission module includes a unified security gateway and a quantum encryption channel, wherein the unified security gateway is configured to perform heterogeneous protocol conversion; The security efficiency collaborative optimization module is configured to dynamically adjust encryption algorithm parameters and authentication processes based on threat perception results. The dynamic consensus notarization module is configured to notarize behavioral data through a lightweight BFT consensus protocol and an off-chain / on-chain collaborative mechanism.
[0089] The hardware security enhancement module also includes: The cryptographic acceleration submodule is configured to optimize the computational efficiency of the SM2 algorithm through elliptic curve pre-computation. The anti-side-channel attack submodule is configured to apply a random mask and time perturbation to the SM4 encryption process.
[0090] In one optional implementation, the security efficiency collaborative optimization module includes: The threat perception submodule is configured to use an improved isolated forest algorithm to detect abnormal behavior and to identify attack patterns using a lightweight CNN model. The dynamic adjustment submodule is configured to automatically switch predefined security policy templates based on the threat level.
[0091] In one optional implementation, the cryptographic acceleration submodule optimizes the SM2 algorithm in the following way: Pre-compile a table of multiples of the base points of the elliptic curve, reducing the complexity of scalar multiplication operations from O(n) to O(logn); By employing a parallel computing architecture to process multiple key pair generation requests simultaneously, the computational efficiency is improved by ≥30%.
[0092] In an optional implementation, the dynamic consensus evidence storage module is further configured as follows: The evidence storage data is segmented, and each segment generates a unique Merkle tree hash value; The Merkle tree root hash is stored on-chain, while the complete shard data is stored off-chain, supporting verification of data integrity through the root hash.
[0093] In one optional implementation, the multidimensional authentication module includes: The user behavior authentication submodule is configured to identify user operation features through an LSTM neural network model. The terminal identity authentication submodule is configured to read the eSIM embedded identifier and perform hardware binding verification. The digital certificate submodule is configured to interface with a CA server to implement certificate chain verification.
[0094] In one optional implementation, the detection process of the threat perception submodule includes: Network traffic characteristics are collected, and anomaly scores are calculated using an improved isolated forest algorithm. When the score exceeds a threshold, a lightweight CNN model is triggered to classify the attack type.
[0095] In one optional implementation, the hardware security enhancement module further includes: The anti-physical attack submodule is configured to automatically trigger a key erasure command when an abnormal voltage or physical disassembly is detected. The cryptographic resource service interface supports third-party applications in calling the SM2 / SM3 / SM4 national cryptographic algorithms and the FIDO2 biometric authentication protocol.
[0096] Example 4: Figure 3 A block diagram of an exemplary electronic device suitable for implementing embodiments of the present invention is shown.
[0097] The electronic device may include a central processing unit / microprocessor / main control chip, etc. 4; and a storage medium 5, coupled to the central processing unit / microprocessor / main control chip, etc. 4, and storing computer-executable instructions therein for performing the steps of various methods of embodiments of the present invention when executed by the processor.
[0098] The central processing unit / microprocessor / main control chip, etc., can include, but are not limited to, one or more processors or microprocessors.
[0099] Storage medium 5 may include, but is not limited to, random access memory (RAM), read-only memory (ROM), flash memory, EPROM memory, EEPROM memory, registers, computer storage media (e.g., hard disk, floppy disk, solid-state drive, removable disk, CD-ROM, DVD-ROM, Blu-ray disc, etc.).
[0100] In addition, the electronic device may also include (but is not limited to) a data bus 6, an input / output bus / external bus / device bus 7, a display 8, and input / output devices 9 (e.g., keyboard, mouse, speaker, etc.).
[0101] The central processing unit / microprocessor / main control chip, etc. 4 can communicate with external devices (8, 9, etc.) via I / O bus 7 through wired or wireless network (not shown).
[0102] The storage medium 5 may also store at least one computer-executable instruction for performing the steps of various functions and / or methods in the embodiments described herein when the central processing unit / microprocessor / main control chip, etc., 4 is running.
[0103] In one embodiment, the at least one computer-executable instruction may also be compiled into or comprise a software product, wherein one or more computer-executable instructions are executed by a processor to perform the steps of the various functions and / or methods in the embodiments described herein.
[0104] Figure 4 A schematic diagram of a computer-readable storage medium according to an embodiment of the present invention is shown.
[0105] like Figure 4 As shown, the non-transitory computer-readable storage medium 11 stores instructions, such as computer-readable instructions 10. When the computer-readable instructions 10 are executed by a processor, the various methods described above can be performed. The non-transitory computer-readable storage medium includes, but is not limited to, volatile memory and / or non-volatile memory. Volatile memory may include, for example, random access memory (RAM) and / or cache memory. Non-transitory non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc. For example, the non-transitory computer-readable storage medium 11 can be connected to a computing device such as a computer, and then, when the computing device executes the computer-readable instructions 10 stored on the computer-readable storage medium 11, the various methods described above can be performed.
[0106] In the several embodiments provided by this invention, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0107] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0108] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0109] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for executing all or part of the steps of the methods of the various embodiments of this invention through a computer device (which may be a personal computer, server, or network device, etc.). The aforementioned storage medium includes: USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, optical disks, and other media capable of storing program code.
[0110] The above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for low-altitude intelligent agent interconnection based on a mobile SIM card, characterized in that, Includes the following steps: A Trusted Execution Environment (TEE) is constructed based on an embedded security chip of a mobile SIM card, and the entire lifecycle management of keys is achieved through the TEE; Collect user behavior characteristics, terminal hardware identification and digital certificate information of intelligent agents, and perform multi-dimensional composite authentication to generate a globally unique identity identifier; A quantum-encrypted transmission channel is established by converting heterogeneous network protocols through a unified security gateway layer; Based on the preset C1-C4 data sensitivity classification strategy, the authentication security strength is dynamically matched with the business scenario requirements; A lightweight BFT consensus protocol and an off-chain and on-chain collaborative evidence storage mechanism are adopted to achieve distributed and trusted evidence storage of behavioral data across the entire chain. The system uses reinforcement learning algorithms to assess the security situation in real time and dynamically adjusts encryption algorithm parameters and authentication processes to balance security protection strength and business processing efficiency.
2. The low-altitude intelligent agent interconnection method as described in claim 1, characterized in that, The dynamic matching authentication security strength and business scenario requirements include: Transmitted data is classified into four levels of sensitivity: C1 Invention Data, C2 Internal Data, C3 Sensitive Data, and C4 Core Data. Single-factor authentication is used for C1 level data, two-factor authentication for C2 level data, three-factor authentication for C3 level data, and a combination strategy of quantum encryption and multi-factor authentication for C4 level data.
3. The low-altitude intelligent agent interconnection method as described in claim 1, characterized in that, The multidimensional composite certification includes: Verify the terminal hardware identifier using the SM2 elliptic curve algorithm; Collect user operation behavior characteristics for behavior authentication; The STK pop-up command of the mobile SIM card is invoked to trigger the user's secondary confirmation in order to complete the strong reach authentication.
4. The low-altitude intelligent agent interconnection method as described in claim 1, characterized in that, The embedded security chip is of EAL4+ level, and the TEE is constructed through the following steps: Within the SIM card security chip, an independent execution area is defined to isolate key storage and business logic; Random masking technology based on the SM4 algorithm is used to strengthen the data within the TEE against side-channel attacks; Integrate quantum-resistant transfer protocols to support post-quantum cryptography algorithm upgrades.
5. The low-altitude intelligent agent interconnection method as described in claim 1, characterized in that, The key lifecycle management includes: Generate an initial key pair within the TEE and obtain the session key through a quantum key distribution network; The root key is stored using hardware binding, and key rotation is achieved through an OTA remote update mechanism. The key usage process is audited and logged, and then uploaded to the dynamic consensus and evidence storage module.
6. The low-altitude intelligent agent interconnection method as described in claim 1, characterized in that, The protocol conversion of the unified security gateway layer includes: Analyze the frame structure and encapsulation format of heterogeneous networks; The intelligent protocol conversion engine maps data from different protocols to a unified secure transmission frame format. Data integrity checks are performed during the conversion process.
7. The low-altitude intelligent agent interconnection method as described in claim 1, characterized in that, The quantum encryption channel is established in the following way: Quantum keys are generated by a quantum key distribution network and injected through the security chip of a mobile SIM card. A quantum random number generator is used to generate session keys, and an end-to-end encrypted channel is constructed by combining the AES-GCM algorithm. A quantum bit commitment protocol is used in the key negotiation process to prevent man-in-the-middle attacks.
8. The low-altitude intelligent agent interconnection method as described in claim 1, characterized in that, The lightweight BFT consensus protocol includes: The agent nodes are divided into a verification node group and a consensus node group, and the verification node group performs data preprocessing. A group consensus mechanism is adopted, and the number of nodes in each group is dynamically adjusted to reduce communication overhead; The consensus result is stored in a lightweight manner using a combination of off-chain storage and on-chain hash anchoring.
9. The low-altitude intelligent agent interconnection method as described in claim 1, characterized in that, The reinforcement learning algorithm includes a combined model of Monte Carlo tree search and federated learning, and the input parameters of the model include: Current network topology change frequency, data transmission latency threshold, remaining device battery power, and types of historical attack events; The output parameters include the encryption algorithm type, the number of authentication steps, and the key update cycle.
10. The low-altitude intelligent agent interconnection method as described in claim 1, characterized in that, The STK pop-up command interaction process includes: The terminal sends a pop-up request command in the BIP protocol to the SIM card; The SIM card generates a random challenge code via TEE and returns a pop-up response command; After the user enters the challenge code and the verification is successful, the SIM card outputs the "Authentication Successful" command and releases the session key.
11. The low-altitude intelligent agent interconnection method as described in claim 2, characterized in that, The dynamically adjustable encryption algorithm parameters include: When a DoS attack is detected, it automatically switches to a lightweight encryption algorithm; Low-power encryption mode is enabled when the device battery level is below 20%. When transmitting C4 level data, the automatic key rotation mechanism is forced to be enabled every 30 seconds.
12. The low-altitude intelligent agent interconnection method as described in claim 1, characterized in that, The multidimensional composite certification also includes: Collect the physical environment parameters of the intelligent agent as auxiliary authentication factors; When the deviation of physical environment parameters from the historical baseline exceeds a preset threshold, secondary authentication is triggered.
13. The low-altitude intelligent agent interconnection method as described in claim 1, characterized in that, The quantum-resistant transfer protocol includes: An adapter interface for a pre-defined quantum cryptography algorithm; When a quantum computing threat is detected, the existing RSA / ECC key pair is automatically migrated to a lattice-based cryptosystem.
14. The low-altitude intelligent agent interconnection method as described in claim 1, characterized in that, The unified security gateway layer also includes: Protocol conversion rule base, storing the mapping relationship between LoRaWAN, ZigBee, and 5GNR protocols; The intelligent routing engine dynamically selects the optimal transmission path based on network bandwidth and latency.
15. A low-altitude intelligent agent interconnection system based on a mobile SIM card, characterized in that, include: The multi-dimensional authentication module is configured to integrate user behavior authentication, terminal identity authentication, and digital certificate authentication to generate a globally unique identity identifier. The hardware security enhancement module, integrated into the EAL4+ level security chip of the mobile SIM card, is used to build an in-memory computing TEE and provide key lifecycle protection. An adaptive secure transmission module includes a unified security gateway and a quantum encryption channel, wherein the unified security gateway is configured to perform heterogeneous protocol conversion; The security efficiency collaborative optimization module is configured to dynamically adjust encryption algorithm parameters and authentication processes based on threat perception results. The dynamic consensus notarization module is configured to notarize behavioral data through a lightweight BFT consensus protocol and an off-chain / on-chain collaborative mechanism.
16. The low-altitude intelligent agent interconnection system as described in claim 15, characterized in that, The hardware security enhancement module also includes: The cryptographic acceleration submodule is configured to optimize the computational efficiency of the SM2 algorithm through elliptic curve pre-computation. The anti-side-channel attack submodule is configured to apply a random mask and time perturbation to the SM4 encryption process.
17. The low-altitude intelligent agent interconnection system as described in claim 15, characterized in that, The security efficiency collaborative optimization module includes: The threat perception submodule is configured to use an improved isolated forest algorithm to detect abnormal behavior and to identify attack patterns using a lightweight CNN model. The dynamic adjustment submodule is configured to automatically switch predefined security policy templates based on the threat level.
18. The low-altitude intelligent agent interconnection system as described in claim 15, characterized in that, The cryptographic acceleration submodule optimizes the SM2 algorithm in the following ways: Pre-compile a table of multiples of the base points of the elliptic curve, reducing the complexity of scalar multiplication operations from O(n) to O(logn); By employing a parallel computing architecture to process multiple key pair generation requests simultaneously, the computational efficiency is improved by ≥30%.
19. The low-altitude intelligent agent interconnection system as described in claim 15, characterized in that, The dynamic consensus evidence storage module is also configured to: The evidence storage data is segmented, and each segment generates a unique Merkle tree hash value; The Merkle tree root hash is stored on-chain, while the complete shard data is stored off-chain, supporting verification of data integrity through the root hash.
20. The low-altitude intelligent agent interconnection system as described in claim 15, characterized in that, The multidimensional authentication module includes: The user behavior authentication submodule is configured to identify user operation features through an LSTM neural network model. The terminal identity authentication submodule is configured to read the eSIM embedded identifier and perform hardware binding verification. The digital certificate submodule is configured to interface with a CA server to implement certificate chain verification.
21. The low-altitude intelligent agent interconnection system as described in claim 15, characterized in that, The detection process of the threat perception submodule includes: Network traffic characteristics are collected, and anomaly scores are calculated using an improved isolated forest algorithm. When the score exceeds a threshold, a lightweight CNN model is triggered to classify the attack type.
22. The low-altitude intelligent agent interconnection system as described in claim 15, characterized in that, The hardware security enhancement module also includes: The anti-physical attack submodule is configured to automatically trigger a key erasure command when an abnormal voltage or physical disassembly is detected. The cryptographic resource service interface supports third-party applications in calling the SM2 / SM3 / SM4 national cryptographic algorithms and the FIDO2 biometric authentication protocol.
23. An electronic device, comprising: At least one memory stores computer-executable instructions non-transiently; At least one processor, configured to run the computer-executable instructions, The computer-executable instructions are executed by the processor to implement the low-altitude intelligent agent interconnection method according to any one of claims 1-14.
24. A computer-readable storage medium, wherein, The computer-readable storage medium stores computer-executable instructions that, when executed by at least one processor, implement the low-altitude intelligent agent interconnection method according to any one of claims 1-14.