An Access Control-Based Unmanned Aerial Vehicle (UAV) Communication Link Encryption System

By using the improved UCON+ model for access control and continuous authorization assessment, the problem of unclear binding between the validity period of key authorization credentials and the evidence of obligation execution in UAV communication links is solved, achieving high consistency, dynamic adaptability and controllable encryption protection for UAV communication links.

CN122093801APending Publication Date: 2026-05-26BEIJING XIONGFENG TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BEIJING XIONGFENG TECHNOLOGY CO LTD
Filing Date
2026-03-10
Publication Date
2026-05-26

Smart Images

  • Figure CN122093801A_ABST
    Figure CN122093801A_ABST
Patent Text Reader

Abstract

This invention discloses an access control-based encryption system for UAV communication links, comprising: a link establishment request module for initiating a communication link establishment request; an identity authentication module for performing identity authentication; an access decision module for performing pre-access authorization assessment using an improved UCON+ model; a key authorization module for outputting session key authorization credentials and session key materials to establish the communication link; a link encryption module for performing control operations based on the session key authorization credentials and performing encryption and integrity protection; a status verification module for collecting link status and environmental status and generating obligation execution evidence; a continuous control module for performing continuous authorization assessment during use; and a post-use audit module for performing post-use processing. This invention employs access control-driven link encryption to achieve encryption of UAV communication links.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of unmanned aerial vehicle (UAV) wireless communication security technology, and in particular to an UAV communication link encryption system based on access control. Background Technology

[0002] In scenarios involving formation coordination, mission payload transmission, and relay forwarding, UAVs typically rely on air-to-air or air-to-ground wireless data links to transmit control commands, telemetry information, and payload data.

[0003] In existing technologies, to ensure link security, protected communication is often established by means of identity authentication, session key negotiation, link encryption and integrity verification, and key updates are triggered by preset periods or data volume thresholds. Some solutions introduce access control policies at the system level to restrict the scope of access to business functions or data types by different nodes.

[0004] Existing solutions generally implement access control and key authorization, encryption level selection, key domain range, and key lifecycle management in a decentralized manner, resulting in inconsistent mechanisms for continuous evaluation of link status and environmental changes after link establishment. For scenarios involving link switching, relay changes, platoon member additions or removals, and security alarm triggers, there is a lack of clear binding between the validity period and renewal date of key authorization credentials and the evidence of obligation execution. This makes it difficult to establish consistent linkage between continuous authorization evaluation and actions such as renewal, demotion, key re-keying, re-authentication, and link termination during the usage phase, potentially leading to inconsistencies between policy execution and link encryption control.

[0005] Therefore, how to provide an access control-based encryption system for UAV communication links is a problem that urgently needs to be solved by those skilled in the art. Summary of the Invention

[0006] One objective of this invention is to propose an access control-based encryption system for UAV communication links. This invention fully utilizes identity authentication, access control decisions based on the improved UCON+ model, session key authorization, and link encryption protection. During the link establishment phase, based on the authentication context and subject attributes, resource attributes, environmental attributes, and session attributes, a pre-access authorization assessment is performed. This generates an access control decision output containing the admission result, the set of allowed actions, session constraint information, key domain authorization range, encryption policy level, key rotation policy, and link session state transition instructions. Based on this, session key authorization credentials and session key materials are generated to establish the communication link. During the link maintenance phase, combined with the link state, environmental state, and obligation execution evidence, continuous authorization assessment is performed to drive control actions such as renewal, demotion, key re-authentication, re-authentication, and link termination. This achieves control over the sending and receiving of different service data streams and encryption and integrity protection of link data, possessing advantages such as high policy consistency, strong dynamic adaptability, strong controllability of key lifecycle, and high link security.

[0007] An access control-based encryption system for unmanned aerial vehicle (UAV) communication links according to an embodiment of the present invention includes:

[0008] The link establishment request module is used to initiate a communication link establishment request from the first UAV node to the second UAV node and generate a link establishment request message.

[0009] The identity authentication module is used to perform identity authentication based on the link establishment request message, generate authentication context information, and create a link session object;

[0010] The access decision module is used to perform pre-access authorization assessment based on authentication context information and link session objects, and generate access control decision outputs through the improved UCON+ model.

[0011] The key authorization module is used to generate session key authorization credentials and session key materials based on access control decision output, update the link session state of the link session object, and establish a communication link.

[0012] The link encryption module is used to perform control operations based on session key authorization credentials, obtain business flow control results, and perform encryption and integrity protection to obtain encrypted link data;

[0013] The status verification module is used to collect link status and environmental status during the communication link maintenance period and generate evidence of obligation execution.

[0014] The continuous control module is used to perform continuous authorization assessment during the usage phase based on link status and environment status, obligation execution evidence, authentication context information, and link session object, and to obtain the communication link to be terminated.

[0015] The post-event audit module is used to perform post-use processing based on terminated communication links, generate session summaries, and record audit logs.

[0016] Optionally, the chain establishment request module specifically includes:

[0017] The communication entities involved in establishing the communication link are identified, resulting in the first UAV node and the second UAV node;

[0018] The first UAV node collects the request parameters used to establish a communication link, obtains the request parameters, and generates a link session identifier based on the request parameters;

[0019] Based on the request parameters, construct the link to establish the message body of the request message, perform integrity calculation on the message body, and obtain the integrity verification value;

[0020] The message body and integrity check value are encapsulated and sent as a link establishment request message, and the link session identifier is used as the session association identifier.

[0021] Optionally, the identity authentication module specifically includes:

[0022] The second UAV node receives the link establishment request message, parses the link establishment request message, and obtains the message body and integrity verification value;

[0023] The second drone node recalculates the message authentication code based on the message body and the authentication key preset by the first drone node, and obtains the recalculated verification value.

[0024] The recalculated check value is compared with the integrity check value. When the recalculated check value is consistent with the integrity check value, the integrity verification of the link establishment request message is determined to be successful. After the integrity verification is successful, the extraction result is obtained from the message body.

[0025] The second drone node retrieves the node credentials corresponding to the identity identifier from the identity credential database based on the identity identifier, generates a random authentication challenge value based on the node credentials, and sends the random authentication challenge value to the first drone node.

[0026] After receiving the random authentication challenge value, the first drone node performs a signature calculation on the random authentication challenge value based on the authentication key to obtain the challenge response value.

[0027] After receiving the challenge response value, the second drone node calculates the verification value based on the authentication key and the random authentication challenge value to obtain the verification value.

[0028] The verification value is compared with the challenge response value. When the verification value and the challenge response value are consistent, the identity authentication of the first drone node is determined to be successful, and authentication context information is generated.

[0029] The second drone node creates a link session object based on the authentication context information.

[0030] Optionally, the access decision module specifically includes:

[0031] Receive authentication context information and link session object, and extract identity identifier, role information, task identifier, link type and link session identifier from the authentication context information to form a set of main attributes;

[0032] Extract the link session state, key domain authorization range, encryption policy level, key rotation policy, re-evaluation cycle, and obligation tag from the link session object, and combine them with the link session identifier to form a set of session attributes;

[0033] Based on the link type and task identifier, the resource policy information is retrieved from the policy resource library. The link type and task identifier are combined to form a resource attribute set, and the current communication environment information is collected to form an environment attribute set.

[0034] The subject attribute set, resource attribute set, environment attribute set, and session attribute set are fused to construct the authorization evaluation input vector;

[0035] An improved UCON+ model is constructed by using the set of link session states, the set of link session state transition relationships, the set of authorization rules, the set of obligation rules, the set of condition rules, the obligation label mapping relationship, the key policy mapping relationship, and the set of triggering rules.

[0036] Based on the improved UCON+ model, a joint evaluation is performed on the authorization evaluation input vector in the pre-access phase to obtain the admission evaluation value and session constraint information;

[0037] The admission evaluation value is compared with the preset admission threshold to obtain the admission result. When the admission result allows the establishment of a communication link, the policy is calculated based on the key policy mapping relationship and the authorization evaluation input vector to obtain the set of allowed actions, the key domain authorization range, the encryption policy level and the key rotation policy.

[0038] The access control decision output is generated by combining and encapsulating the access result, the set of allowed actions, session constraint information, key domain authorization range, encryption policy level, key rotation policy, and link session state transition instructions.

[0039] Optionally, the key authorization module specifically includes:

[0040] Receive access control decision output, form an authorization parameter set, and generate session key authorization credentials based on the authorization parameter set;

[0041] Integrity protection is performed on the session key authorization credentials to obtain protected session key authorization credentials;

[0042] Determine the session random number, and generate the initial session master key based on the link session identifier and the session random number;

[0043] Generate a set of domain keys based on the initial session master key, key domain authorization range, and encryption policy profile;

[0044] A key rotation parameter set is generated based on the key rotation strategy, thus obtaining the key rotation parameter set;

[0045] The protected session key authorization credentials are bound and encapsulated with the domain key set and the key rotation parameter set to generate session key material;

[0046] The session key material is distributed to the first UAV node and the second UAV node to obtain the distribution result. The link session state of the link session object is updated according to the link session state migration instruction to establish a communication link.

[0047] Optionally, the link encryption module specifically includes:

[0048] Receive service data on the communication link and determine the service data stream type for the service data;

[0049] Parse the session key authorization credentials to obtain the set of allowed actions, the key domain authorization range, the encryption policy level, and the link session identifier;

[0050] Based on the allowed action set and the business data flow type, a business flow control judgment result is generated.

[0051] When the service flow control determination result is an allowed value, the corresponding send and receive operations are performed for the service data flow type, and a service flow control result is generated.

[0052] The corresponding key domain identifier is determined based on the business data flow type, and a matching judgment is made between the key domain identifier and the key domain authorization range to generate a key domain authorization judgment result.

[0053] When the key domain authorization determination result is an allowed value, the domain key corresponding to the key domain identifier is extracted from the session key material, and the encryption algorithm level and integrity algorithm level are selected according to the encryption policy level to form the encryption input;

[0054] The business data is encrypted based on the domain key and the encryption algorithm settings to obtain ciphertext.

[0055] Based on the domain key and integrity algorithm settings, integrity protection operations are performed on the ciphertext and encrypted input to obtain the integrity check value;

[0056] Encapsulate the ciphertext and integrity check value to form encrypted link data, thus obtaining encrypted link data.

[0057] Optionally, the status verification module specifically includes:

[0058] During the communication link maintenance period, a periodic trigger signal is generated according to the reassessment cycle, and the current system timestamp is recorded to form a periodic trigger event;

[0059] During the communication link maintenance period, the status of the communication network is monitored, and the link event type is obtained based on the monitoring results to identify whether a link event has occurred.

[0060] When a link event type is detected, a link event record is generated, and link operation status parameters and communication environment parameters are collected to obtain the link status and environment status.

[0061] The oblig rule set corresponding to the oblig tag is read from the oblig tag in the session key authorization credential, and the oblig execution status is obtained by performing oblig execution detection on the current communication behavior based on the oblig rule set.

[0062] Evidence of obligation execution is generated based on the link session identifier, obligation tag, obligation execution status, and current timestamp.

[0063] Optionally, the continuous control module specifically includes:

[0064] Receive link status and environment status, obligation execution evidence, authentication context information, and link session object, and construct a continuous authorization evaluation input vector;

[0065] The improved UCON+ model is invoked to perform in-use phase authorization assessment calculations on the continuous authorization assessment input vector to obtain the continuous authorization assessment value.

[0066] The continuous authorization evaluation value is compared with a preset set of evaluation thresholds to generate continuous control action results;

[0067] Based on the results of continuous control actions, the access control decision output is updated to generate an updated access control decision output.

[0068] When the result of continuous control actions is renewal, verification is performed based on the execution status of the obligation execution evidence to obtain the verification result;

[0069] If the verification result is successful, generate updated session key authorization credentials and updated session key materials;

[0070] When the result of continuous control actions is a reduction in weight, the updated key domain authorization range, the updated encryption policy level, and the updated business flow control result are obtained.

[0071] When the result of continuous control actions is a duplicate key, a new session random number is generated according to the key rotation strategy, resulting in a new initial session master key, a new set of domain keys, and updated session key materials.

[0072] When the result of continuous control actions is re-authentication, the identity authentication process is re-triggered to perform identity authentication on the first drone node and the second drone node and generate a new authentication result.

[0073] The authentication context information is updated based on the new authentication result to obtain the updated authentication context information;

[0074] When the result of continuous control actions is a broken link, the session key authorization credentials are invalidated and the communication link is terminated. The link session state of the link session object is updated to the terminated state, and the terminated communication link is obtained.

[0075] Optionally, the post-audit module specifically includes:

[0076] When a communication link is terminated or a communication link ends normally, the session information corresponding to the communication link is obtained, and a session information set is obtained.

[0077] The statistical communication link generates service flow control results, link status and environment status, and obligation execution evidence during operation, forming a set of session statistics information.

[0078] Based on the link session identifier, communication link establishment timestamp, communication link termination timestamp, continuous control action results, and session summary, an audit log is generated.

[0079] The audit log entries are written to the audit log storage module to obtain the audit log.

[0080] The beneficial effects of this invention are:

[0081] This invention employs an improved UCON+ model for pre-access authorization assessment during the communication link establishment phase. It incorporates authentication context information generated from identity authentication, along with subject attributes, resource attributes, environmental attributes, and session attributes of the link session object, into the assessment input. This generates an access control decision output that includes the admission result, the set of allowed actions, session constraint information, key domain authorization range, encryption policy level, key rotation policy, and link session state transition instructions. Based on this, it generates session key authorization credentials and session key materials, enabling link admission, service action authorization, and key authorization to be configured under the same decision result. This reduces the risk of inconsistency caused by the decentralized implementation of access control policies and link encryption configurations.

[0082] This invention further employs an improved UCON+ model to perform continuous authorization assessment during the communication link maintenance phase. It collects link status and environment status through reassessment cycle triggering and link event triggering, and generates obligation execution evidence corresponding to the obligation tag. It updates the access control decision output and forms continuous control actions such as renewal, demotion, key re-keying, re-authentication, and link disconnection. This allows the validity period and renewal time of the session key authorization credential to be associated with the obligation execution status and link status changes, realizing the linkage control of session-level authorization and key lifecycle management.

[0083] This invention controls the sending and receiving of different service data streams based on session key authorization credentials during the link data transmission phase. It also selects keys from the session key material according to the key domain authorization range to encrypt and protect the link data, creating a secure, isolated boundary at the key domain level for control data streams, telemetry data streams, payload data streams, and management data streams. Combined with a session digest generation and audit log recording mechanism after communication link termination, it enables traceable recording of link session state transitions, authorization updates, and key management actions, facilitating verification of the security control process. Attached Figure Description

[0084] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used in conjunction with embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings:

[0085] Figure 1 This is a schematic diagram of the structure of an access control-based UAV communication link encryption system proposed in this invention;

[0086] Figure 2 This invention presents a flowchart of the pre-access authorization process in an access control-based UAV communication link encryption system.

[0087] Figure 3 This is a flowchart illustrating the key authorization process in an access control-based UAV communication link encryption system proposed in this invention. Detailed Implementation

[0088] The present invention will now be described in further detail with reference to the accompanying drawings. These drawings are simplified schematic diagrams, illustrating only the basic structure of the invention, and therefore only show the components relevant to the invention.

[0089] refer to Figures 1-3 An access control-based encryption system for unmanned aerial vehicle (UAV) communication links includes:

[0090] The link establishment request module is used to initiate a communication link establishment request from the first UAV node to the second UAV node and generate a link establishment request message.

[0091] The identity authentication module is used to perform identity authentication based on the link establishment request message, generate authentication context information, and create a link session object;

[0092] The access decision module is used to perform pre-access authorization assessment based on authentication context information and link session objects, and generate access control decision outputs through the improved UCON+ model.

[0093] The key authorization module is used to generate session key authorization credentials and session key materials based on access control decision output, update the link session state of the link session object, and establish a communication link.

[0094] The link encryption module is used to perform control operations based on session key authorization credentials, obtain business flow control results, and perform encryption and integrity protection to obtain encrypted link data;

[0095] The status verification module is used to collect link status and environmental status during the communication link maintenance period and generate evidence of obligation execution.

[0096] The continuous control module is used to perform continuous authorization assessment during the usage phase based on link status and environment status, obligation execution evidence, authentication context information, and link session object, and to obtain the communication link to be terminated.

[0097] The post-event audit module is used to perform post-use processing based on terminated communication links, generate session summaries, and record audit logs.

[0098] In this embodiment, the chain establishment request module specifically includes:

[0099] The communication entities participating in establishing the communication link are determined, and the first UAV node and the second UAV node are obtained, wherein the first UAV node is the link initiator and the second UAV node is the link receiver.

[0100] The first UAV node collects the request parameters used to establish the communication link, and obtains the request parameters. The request parameters include at least the identity identifier, role information, task identifier, link type, and set of requested business actions of the first UAV node.

[0101] The link session identifier is generated based on the request parameters. The link session identifier is obtained by concatenating the identity identifier, task identifier, link type, timestamp of the generation time and random number in a preset order to form a string to be calculated, and then performing a hash operation on the string to be calculated.

[0102] The timestamp is used to represent the current time when the link session identifier is generated, and the random number is used to increase the randomness of the link session identifier, thereby obtaining a unique link session identifier.

[0103] Based on the request parameters, a message body for establishing a link is constructed. The message body includes at least the following in a preset order: link session identifier, identity identifier, role information, task identifier, link type, and the set of requested business actions. All of the above fields are encapsulated into the same message body data structure to form the message body.

[0104] Integrity calculation is performed on the message body to obtain an integrity verification value. The integrity calculation adopts a message authentication code calculation rule based on hashing, which specifically includes: normalizing the authentication key of the first UAV node according to the preset group length; when the authentication key length exceeds the preset group length, hashing the authentication key is performed to obtain an equal-length key; when the authentication key length is less than the preset group length, padding is performed on the authentication key to obtain an equal-length key.

[0105] An inner computing key and an outer computing key are generated based on an equal-length key. The inner computing key is concatenated with the message body to form the first data to be hashed. A hash operation is then performed on the first data to be hashed to obtain an intermediate verification value.

[0106] The outer computing key is concatenated with the intermediate verification value to form the second data to be hashed, and a hash operation is performed on the second data to be hashed. The output result is used as the integrity verification value.

[0107] The message body and integrity check value are encapsulated and sent as a link establishment request message, and the link session identifier is used as the session association identifier.

[0108] In this embodiment, the identity authentication module specifically includes:

[0109] The second UAV node receives the link establishment request message, parses the link establishment request message, and obtains the message body and integrity verification value;

[0110] The second drone node recalculates the message authentication code based on the message body and the authentication key preset by the first drone node to obtain the recalculated verification value. The recalculation of the message authentication code adopts a hash-based message authentication code calculation rule.

[0111] The recalculated check value is compared with the integrity check value. When the recalculated check value is consistent with the integrity check value, the integrity verification of the link establishment request message is determined to be successful. After the integrity verification is successful, the link session identifier, identity identifier, role information, task identifier, link type and the set of requested business actions are extracted from the message body to obtain the extraction results.

[0112] The second drone node retrieves the node credentials corresponding to the identity identifier from the identity credential database based on the identity identifier, generates a random authentication challenge value based on the node credentials, and sends the random authentication challenge value to the first drone node.

[0113] After receiving the random authentication challenge value, the first drone node performs a signature calculation on the random authentication challenge value based on the authentication key to obtain the challenge response value. The signature calculation specifically includes: concatenating the authentication key and the random authentication challenge value to form a string to be calculated, and performing a hash operation on the string to be calculated. The output of the hash operation is used as the challenge response value.

[0114] After receiving the challenge response value, the second drone node calculates the verification value based on the authentication key and the random authentication challenge value. The verification value is calculated by concatenating the authentication key and the random authentication challenge value to form a verification calculation string, and then performing a hash operation on the verification calculation string to obtain the verification value.

[0115] The verification value is compared with the challenge response value. When the verification value and the challenge response value are consistent, the identity authentication of the first drone node is determined to be successful.

[0116] After successful identity authentication, authentication context information is generated, which includes at least identity identifier, role information, task identifier, link type, link session identifier, and timestamp of the successful authentication.

[0117] The second UAV node creates a link session object based on the authentication context information. The link session object includes a link session identifier, a link session status, a key domain authorization range, an encryption policy level, a key rotation policy, a re-evaluation cycle, and an obligation label.

[0118] Specifically, the process involves: using the link session identifier as the unique identifier field of the link session object; initializing the link session state to the pending authorization state; setting the key domain authorization range to the key usage range determined by the role information and task identifier; setting the encryption policy level to the encryption policy level corresponding to the link type; setting the key rotation policy to the key update rule corresponding to the link type and task identifier; setting the re-evaluation cycle to the preset security evaluation time interval; and generating an obligation tag corresponding to the task identifier, thereby obtaining the link session object.

[0119] In this embodiment, the access decision module specifically includes:

[0120] The access control decision module receives authentication context information and link session object, and extracts identity identifier, role information, task identifier, link type and link session identifier from the authentication context information, and combines identity identifier, role information and task identifier to form a set of subject attributes;

[0121] Extract the link session state, key domain authorization range, encryption policy level, key rotation policy, re-evaluation cycle, and obligation tag from the link session object, and combine them with the link session identifier to form a set of session attributes;

[0122] Based on the link type and task identifier, retrieve resource policy information that matches the link type and task identifier in the policy resource library to obtain resource policy information, and combine the link type and task identifier to form a set of resource attributes.

[0123] Collect current communication environment information to form an environmental attribute set, which includes at least the current system time, link quality parameters, and current security level;

[0124] The subject attribute set, resource attribute set, environmental attribute set, and session attribute set are subjected to attribute fusion processing to construct the authorization assessment input vector. Specifically, the subject attribute set, resource attribute set, environmental attribute set, and session attribute set are sequentially concatenated to form a set of ordered data items for authorization assessment, and the ordered data items are encapsulated as the authorization assessment input vector.

[0125] An improved UCON+ model is constructed by using the set of link session states, the set of link session state transition relationships, the set of authorization rules, the set of obligation rules, the set of condition rules, the obligation label mapping relationship, the key policy mapping relationship, and the set of triggering rules.

[0126] The link session state set includes at least the initialization state, the pre-access authorization state, the key authorized state, the link activity state, the degraded state, the re-key state, the re-authentication state, and the termination state.

[0127] The set of link session state transition relationships is used to limit the transition from the link session state to the target link session state;

[0128] The authorization rule set is used to calculate the admission evaluation value based on the authorization evaluation input vector; the obligation rule set is used to generate obligation constraint items and form session constraint information based on obligation labels; the condition rule set is used to generate condition constraint items and form session constraint information based on the environmental attribute set; the obligation label mapping relationship is used to map obligation labels to corresponding subsets of obligation rules;

[0129] The key policy mapping relationship is used to map the subject attribute set, resource attribute set, and session attribute set to the key domain authorization range, encryption policy level, and key rotation policy; the trigger rule set is used to map the re-evaluation cycle and link event type to the re-evaluation trigger condition.

[0130] Based on the improved UCON+ model, a joint evaluation is performed on the authorization evaluation input vector in the pre-access stage to obtain the admission evaluation value and session constraint information. The joint evaluation includes: performing authorization evaluation calculation on the authorization evaluation input vector based on the authorization rule set and outputting the admission evaluation value.

[0131] Based on the obligation label mapping relationship, the obligation labels are mapped to the corresponding subsets of obligation rules, and the obligation constraint generation calculation is performed on the authorization evaluation input vector based on the set of obligation rules, and the obligation constraint terms are output.

[0132] Based on the set of conditional rules, the authorization assessment input vector is used to generate conditional constraints, output conditional constraint terms, and the obligation constraint terms and conditional constraint terms are combined to form session constraint information. The admission assessment value is the assessment result obtained by the authorization assessment input vector through the set of authorization rules, and the session constraint information includes obligation constraint terms and conditional constraint terms.

[0133] The admission assessment value is compared with the preset admission threshold to obtain the admission result. When the admission assessment value is greater than or equal to the preset admission threshold, the admission result is set to allow the establishment of a communication link; when the admission assessment value is less than the preset admission threshold, the admission result is set to refuse the establishment of a communication link.

[0134] When the admission result allows the establishment of a communication link, policy calculation is performed based on the key policy mapping relationship and the authorization evaluation input vector to obtain the set of allowed actions, the key domain authorization range, the encryption policy level, and the key rotation policy. Among them, the key policy mapping relationship is used to perform policy mapping calculation on the subject attribute set, resource attribute set, environment attribute set, and session attribute set, thereby determining the key domain authorization range, encryption policy level, and key rotation policy. Based on the link session state transition relationship set and the admission result, a link session state transition instruction is generated to obtain the target link session state, which is used to instruct the link session object to transition from the current link session state to the target link session state.

[0135] The access control decision output is generated by combining and encapsulating the access result, the set of allowed actions, session constraint information, key domain authorization range, encryption policy level, key rotation policy, and link session state transition instructions.

[0136] In this embodiment, the key authorization module specifically includes:

[0137] Receive access control decision output, and extract the admission result, allowed action set, session constraint information, key domain authorization range, encryption policy level, key rotation policy, link session state transition instruction and obligation label from the access control decision output to form an authorization parameter set;

[0138] The session key authorization credential is generated based on the set of authorization parameters. The session key authorization credential includes at least the link session identifier, credential effective timestamp, credential expiration timestamp, renewal time point, obligation label, key domain authorization range, and encryption policy level.

[0139] Among them, the credential effective timestamp is used to indicate the time when the session key authorization credential becomes effective, the credential expiration timestamp is used to indicate the time when the session key authorization credential expires, the renewal time point is a preset time point located between the credential effective timestamp and the credential expiration timestamp, and the obligation label is the obligation label corresponding to the obligation rule set.

[0140] Integrity protection is performed on the session key authorization credential to obtain a protected session key authorization credential. The integrity protection includes: invoking the message authentication code calculation rule, generating a credential verification value, and combining and encapsulating the credential verification value with the session key authorization credential to form a protected session key authorization credential.

[0141] Determine the session random number, and generate the initial session master key based on the link session identifier and the session random number. The initial session master key is obtained by concatenating the link session identifier and the session random number to form a string to be calculated, and then performing a hash operation on the string to be calculated.

[0142] A domain key set is generated based on the initial session master key, the key domain authorization range, and the encryption policy profile. The domain key set includes multiple domain keys that correspond one-to-one with each key domain indicated by the key domain authorization range. Specifically, each key domain identifier within the key domain authorization range is determined, and for each key domain identifier, the initial session master key, the key domain identifier, and the encryption policy profile are concatenated to form the string to be derived corresponding to the key domain. A hash operation is performed on the string to be derived to obtain the domain key corresponding to the key domain. The domain keys corresponding to each key domain are then collected to form the domain key set.

[0143] A key rotation parameter set is generated based on the key rotation strategy, wherein the key rotation parameter set includes at least the rotation period, the data volume trigger threshold, and the maximum number of rotations;

[0144] The protected session key authorization credentials are bound and encapsulated with the domain key set and the key rotation parameter set to generate session key material;

[0145] The session key material is distributed to the first UAV node and the second UAV node to obtain the distribution result. The link session state of the link session object is updated according to the link session state migration instruction to establish a communication link.

[0146] In this embodiment, the link encryption module specifically includes:

[0147] The first UAV node and the second UAV node receive service data to be sent and received on the communication link, and determine the service data stream type for the service data. The service data stream type belongs to one of the following: control data stream, telemetry data stream, payload data stream, and management data stream.

[0148] Parse the session key authorization credentials to obtain the set of allowed actions, the key domain authorization range, the encryption policy level, and the link session identifier;

[0149] The system matches the allowed action set with the business data flow type to generate a business flow control decision result. When the business data flow type belongs to the allowed action set, the business flow control decision result is set to an allowed value; when the business data flow type does not belong to the allowed action set, the business flow control decision result is set to a rejected value.

[0150] When the service flow control determination result is an allowed value, the first UAV node and the second UAV node perform the corresponding sending and receiving operations for the service data flow type, record the service flow control information, and generate the service flow control result.

[0151] The service flow control result includes a record item containing the link session identifier, service data flow type, and service flow control judgment result;

[0152] The corresponding key domain identifier is determined based on the business data flow type, and a matching judgment is made between the key domain identifier and the key domain authorization range to generate a key domain authorization judgment result. Specifically, when the key domain identifier belongs to the key domain authorization range, the key domain authorization judgment result is set to the allowed value; when the key domain identifier does not belong to the key domain authorization range, the key domain authorization judgment result is set to the rejected value.

[0153] When the key domain authorization determination result is an allowed value, the domain key corresponding to the key domain identifier is extracted from the session key material, and the encryption algorithm level used for encryption operation and the integrity algorithm level used for integrity protection operation are selected according to the encryption policy level; the link session identifier, business data flow type and business data are combined and encapsulated to form encrypted input;

[0154] The business data is encrypted using the domain key and the encryption algorithm profile to obtain ciphertext. The encryption operation involves using the domain key as the encryption key, the business data as the data to be encrypted, and encrypting the business data according to the encryption algorithm parameters indicated by the encryption algorithm profile to generate ciphertext.

[0155] Based on the domain key and integrity algorithm settings, integrity protection operations are performed on the ciphertext and encrypted input to obtain the integrity check value;

[0156] The integrity protection operation adopts a hash-based message authentication code calculation rule;

[0157] Encapsulate the ciphertext and integrity check value to form encrypted link data, thus obtaining encrypted link data.

[0158] In this embodiment, the status verification module specifically includes:

[0159] During the communication link maintenance period, a periodic trigger signal is generated according to the reassessment cycle, and the current system timestamp is recorded to form a periodic trigger event;

[0160] During the communication link maintenance period, the status of the communication network is monitored, and the link event type is obtained based on the monitoring results to identify whether a link event has occurred.

[0161] Among them, the link event type is one or more of the following: link switching event, relay change event, platoon member join event, platoon member leave event, and security alarm event;

[0162] When a change in the connection path of a communication link is detected, the link event type is determined to be a link switching event;

[0163] When a change is detected in the relay node used for communication link forwarding, the link event type is determined to be a relay change event;

[0164] When a new member is detected joining the formation and participating in communication link communication, the link event type is determined to be a formation member joining event;

[0165] When it is detected that an existing member in the formation has left and no longer participates in communication link communication, the link event type is determined as a formation member exit event;

[0166] When a security alarm is detected, the link event type is determined to be a security alarm event;

[0167] When a link event type is detected, a link event record is generated. The link event record includes the link session identifier, the link event type, and the timestamp of when the link event occurred.

[0168] Collect link operation status parameters and communication environment parameters to obtain link status and environment status. The link operation status parameters include at least link quality indicators, link bandwidth, link latency and packet loss rate. The communication environment parameters include at least the current security level and record the current system timestamp.

[0169] The oblig rule set corresponding to the oblig tag is read from the oblig tag in the session key authorization credential, and the oblig execution status is obtained by performing oblig execution detection on the current communication behavior based on the oblig rule set.

[0170] The obligation execution status is a status value used to indicate the result of the obligation rule execution. When the current communication behavior satisfies all the obligation rules in the obligation rule set, the obligation execution status is set to a success status value; when the current communication behavior does not satisfy at least one obligation rule in the obligation rule set, the obligation execution status is set to a failure status value.

[0171] Evidence of obligation execution is generated based on the link session identifier, obligation tag, obligation execution status, and current timestamp.

[0172] In this embodiment, the continuous control module specifically includes:

[0173] Receive link status and environment status, obligation execution evidence, authentication context information, and link session object, and construct a continuous authorization evaluation input vector;

[0174] Among them, the continuous authorization assessment input vector is a data vector formed by the combination of link state and environment state, obligation execution evidence, authentication context information and link session object;

[0175] The improved UCON+ model is invoked to perform in-use phase authorization assessment calculations on the continuous authorization assessment input vector to obtain the continuous authorization assessment value.

[0176] Among them, the authorization assessment calculation in the middle stage is based on the authorization rules, obligation rules and condition rules of the improved UCON+ model. The continuous authorization assessment input vector is jointly evaluated, and the output result of the joint evaluation is determined as the continuous authorization assessment value.

[0177] The continuous authorization evaluation value is compared with a preset set of evaluation thresholds to generate continuous control action results; wherein, the preset set of evaluation thresholds is a set of thresholds used to distinguish different control action trigger intervals, and the continuous control action results are one or more of the following: renewal, demotion, key re-key, re-authentication, and chain break;

[0178] When the continuous authorization assessment value falls within the threshold range corresponding to the renewal, the result of the continuous control action will be determined as a renewal.

[0179] When the continuous authorization evaluation value falls into the threshold range corresponding to the deweighting, the result of the continuous control action will be determined as deweighting;

[0180] When the continuous authorization evaluation value falls into the threshold range corresponding to the rekey, the result of the continuous control action is determined as the rekey;

[0181] When the continuous authorization evaluation value falls within the threshold range corresponding to recertification, the result of the continuous control action will be determined as recertification;

[0182] When the continuous authorization evaluation value falls into the threshold range corresponding to the chain break, the result of the continuous control action is determined as a chain break;

[0183] Based on the results of continuous control actions, the access control decision output is updated to generate an updated access control decision output. The updated access control decision output is a decision data structure formed by the combination of the updated admission result, the updated set of allowed actions, the updated session constraint information, the updated key domain authorization range, the updated encryption policy level, the updated key rotation policy, and the updated link session state transition instructions.

[0184] When the result of continuous control actions is renewal, the obligation execution status corresponding to the obligation label is verified based on the obligation execution evidence to obtain the verification result;

[0185] If the verification result is successful, update the credential expiration timestamp and renewal date in the session key authorization credential, and generate an updated session key authorization credential.

[0186] Update the session key material based on the updated session key authorization credentials to obtain the updated session key material;

[0187] When the result of continuous control actions is a reduction in weight, update the key domain authorization range and encryption policy level in the link session object to obtain the updated key domain authorization range and updated encryption policy level;

[0188] Based on the updated key domain authorization range and the updated encryption policy level, the transmission and reception control of different service data streams running on the communication link are re-executed, the service flow control results are updated, and the updated service flow control results are obtained.

[0189] When the result of continuous control actions is a duplicate key, a new session random number is generated according to the key rotation strategy;

[0190] A new initial session master key is generated based on the link session identifier and the new session random number.

[0191] A new set of domain keys is generated based on the new initial session master key. The new set of domain keys is then used to replace the set of domain keys in the session key material to update the session key material, resulting in the updated session key material.

[0192] When the result of continuous control actions is re-authentication, the identity authentication process is re-triggered to perform identity authentication on the first drone node and the second drone node and generate a new authentication result.

[0193] The authentication context information is updated based on the new authentication result to obtain the updated authentication context information;

[0194] When the result of continuous control actions is a broken link, the session key authorization credentials are invalidated and the communication link is terminated. The link session state of the link session object is updated to the terminated state, and the terminated communication link is obtained.

[0195] Invalidating the session key authorization credential includes marking the session key authorization credential as invalid and stopping the invocation of session key materials based on the session key authorization credential.

[0196] In this embodiment, the post-audit module specifically includes:

[0197] When a communication link is terminated or a communication link ends normally, the session information corresponding to the communication link is obtained, and a session information set is obtained.

[0198] The session information set is a data set composed of link session identifier, authentication context information, link session object, key domain authorization range, encryption policy level, and key rotation policy combination.

[0199] The statistical communication link generates service flow control results, link status and environment status, and obligation execution evidence during operation, forming a set of session statistics information.

[0200] The session information set and the session statistics set are concatenated to form the data to be summarized, and a hash operation is performed on the data to be summarized to obtain the session summary;

[0201] Based on the link session identifier, communication link establishment timestamp, communication link termination timestamp, continuous control action results, and session summary, an audit record is generated and written to the audit log storage module to obtain the audit log.

[0202] Example 1: To verify the feasibility of this invention in practice, it was applied to a UAV swarm collaborative communication test scenario. This scenario involves multiple UAV nodes forming a swarm network, with air-to-air communication links and relay forwarding links within the swarm. Service data simultaneously includes control data streams, telemetry data streams, and payload data streams. During the test, link switching, relay changes, swarm member additions and removals, and security alarm triggers were artificially set as operating conditions to reproduce the problems that existing technologies easily encounter under dynamic topology and risk state changes, such as separation of access control and encryption policies, delayed key rotation, offline nodes still holding keys, and inconsistent policy execution. The comparative scheme uses a traditional approach: after link establishment, static policy configuration is the primary method, with keys rotated according to a fixed period or data volume threshold, lacking renewal and demotion linkage based on evidence of obligation execution.

[0203] In this scenario, during the link establishment phase, the link establishment request module generates a link establishment request message, the identity authentication module completes the identity authentication of both parties and generates authentication context information, and simultaneously creates a link session object. The access decision module performs an authorization assessment based on the improved UCON+ model for the pre-access phase, outputting the admission result, the set of allowed actions, session constraint information, key domain authorization range, encryption policy level, key rotation policy, and link session state migration instructions. The key authorization module generates a session key authorization credential and performs integrity protection accordingly, then generates and distributes session key materials. The communication link is established after the link session state is updated with the migration instructions. The link encryption module performs send and receive control on the business data stream based on the session key authorization credential and selects a domain key based on the key domain authorization range to encrypt and protect the integrity of the link data. During link maintenance, the state evidence collection module triggers according to the reassessment cycle and collects the link status and environment status when the link switches, relays change, members join or leave, or security alarms are triggered, and generates obligation execution evidence corresponding to the obligation tag. The continuous control module inputs the link status and environment status, obligation execution evidence, authentication context information, and link session object into the continuous authorization evaluation during the usage phase, obtains the continuous control action results, and updates the access control decision output. When the obligation execution evidence verification is successful, renewal is performed to update the session key authorization credential and session key material. When the risk state increases or the link quality deteriorates, a demotion is triggered to narrow the key domain authorization scope and adjust the encryption policy level. When the rotation policy is reached or an alarm is triggered, key re-keying is performed to update the domain key set. When the identity trust level changes, re-authentication is triggered. When continuous violations or high risks are detected, the link is disconnected, invalidating the session key authorization credential and terminating the communication link. After the link ends, the post-event audit module generates a session summary and records an audit log, realizing traceable recording of link session state migration and key management actions.

[0204] The test was based on continuous flight and network operation, comprehensively analyzing link establishment latency, key authorization and distribution overhead, response latency after event triggering, service availability, encryption overhead, and audit integrity. Results show that, under the same link conditions, this invention can complete authorization updates and key domain contraction faster when link switching, relay changes, and member exits occur. After an exiting node is determined to have exited, the subsequent message decryption success rate drops to zero, reducing the risk of retaining keys while offline. After a security alarm is triggered, this invention can complete de-weighting or link disconnection within a reassessment cycle, ensuring stricter key domain isolation for control data flows during alarm periods, while payload data flows can be downgraded according to a strategy to maintain controllable bandwidth usage. When the obligation execution evidence is continuously satisfied, session key authorization credential renewal is smoothly updated, avoiding service interruptions caused by frequent full renegotiation. The comparative scheme, lacking an obligation evidence-driven renewal and de-weighting mechanism, exhibits key domain contraction lag and inconsistent policy execution in member exit and alarm scenarios, leading to situations where service traffic that does not conform to the current authorization can still be encrypted and forwarded within a short time window.

[0205] Table 1 Comparison of Key Indicators in On-site Testing and Event Response Records

[0206] Indicator Categories Test conditions / events Indicator Name Results of the Invention Comparison of results unit Chain building phase Normal chain building Median delay in link establishment completion. 0.21 0.34 s Chain building phase Normal chain building Median delay in pre-access authorization assessment 0.038 0.015 s Chain building phase Normal chain building Median delay in distribution of session key materials 0.062 0.090 s Operational phase steady state operation End-to-end delay (average) 0.047 0.045 s Operational phase steady state operation Average packet loss rate 0.8 0.8 % Operational phase steady state operation Encryption processing overhead (incremental CPU usage) 7.6 6.9 % Operational phase steady state operation Audit record completeness rate (event coverage should be recorded) 100 82 % Event Response Link switching Median delay between continuous evaluation trigger and policy update completion. 0.19 0.92 s Event Response Link switching Control data flow availability during handover 99.2 96.1 % Event Response Relay change Median delay in rekey completion 0.11 0.48 s Event Response Members join Median delay in group enrollment authorization completion 0.27 0.63 s Event Response Member Exit Success rate of message decryption after exit 0 7.4 % Security Alert Alarm triggered Median delay between alert and weight reduction taking effect 0.23 1.05 s Security Alert Alarm triggered During the alarm period, control the data flow and deny unauthorized actions. Hit rate. 100 91 % Renewal Mechanism The obligation to provide evidence continues to be satisfied Certificate renewal success rate 99.6 not applicable % Renewal Mechanism Lack of evidence of obligation Percentage of Certificate Renewal Denied 100 not applicable % Energy consumption impact steady state operation Additional power consumption for communication and encryption 3.1 2.8 % Post-event stage End of session Median delay in session summary generation 0.012 0.004 s

[0207] As can be seen from the table above, this invention demonstrates more consistent policy execution performance and faster event response capabilities compared to the comparative scheme in key indicators related to UAV communication link security control. During the link establishment phase, although the pre-access authorization assessment introduces a more complete policy calculation process, the median link establishment completion latency remains at 0.21 seconds, lower than the comparative scheme's 0.34 seconds. The session key material distribution latency also decreased from 0.090 seconds to 0.062 seconds, indicating that the structured connection between access control decision output and key authorization process reduces the additional time consumed by repeated interactions. In steady-state operation, the end-to-end latency is 0.047 seconds and 0.045 seconds, respectively, with a packet loss rate of 0.8% for both. This indicates that under the same link conditions, the encryption and control logic of this invention does not significantly change the basic link latency and packet loss level. Meanwhile, the CPU usage increase for encryption processing is 7.6%, which is only slightly different from the comparative scheme's 6.9%, while the audit log integrity rate reaches 100%, compared to 82% for the comparative scheme, demonstrating that the session digest and audit log mechanisms provide more comprehensive coverage of key process records.

[0208] In dynamic event-triggered scenarios, the advantages of this invention are more concentrated. During link switching, the median latency from continuous evaluation triggering to policy update completion is 0.19 seconds, compared to 0.92 seconds for the comparative scheme. Furthermore, the availability of control data flow remains at 99.2% during the switching period, higher than the comparative scheme's 96.1%, indicating that continuous authorization updates based on re-evaluation cycles and link event triggering can converge to the new authorization and encryption configuration more quickly. In relay change scenarios, the re-key completion latency is 0.11 seconds, compared to 0.48 seconds for the comparative scheme, and the member joining authorization completion latency is 0.27 seconds, compared to 0.63 seconds for the comparative scheme. This reflects that the linked update of session key authorization credentials and session key materials has higher processing efficiency for topology changes. The message decryption success rate after a member leaves is 0% in this invention, while it is 7.4% in the comparative scheme. Combined with the 0.23-second delay from alarm triggering to the reduction of privileges taking effect (1.05 seconds in the comparative scheme) and the 100% hit rate of the control data flow rejecting unauthorized actions during the alarm period (91% in the comparative scheme), it can be seen that this invention, through the combination of obligatory execution evidence and continuous control actions, makes the reduction of privileges and key domain control more thorough and timely within the exit and alarm window.

[0209] Furthermore, the credential renewal mechanism reflects the differences in session-level key lifecycle management: when the obligation evidence is continuously satisfied, the renewal success rate reaches 99.6%; when the obligation evidence is missing, the renewal rejection rate is 100%, giving key authorization a clear and continuous constraint. In terms of energy consumption increment, this invention is 3.1%, while the comparative scheme is 2.8%, showing a limited difference; the session digest generation latency is 0.012 seconds, while the comparative scheme is 0.004 seconds, still at a low level. Overall, this invention, while maintaining controllable basic link performance, achieves faster response and higher consistency in authorization updates, key updates, and action execution for link events and security alarm triggering scenarios.

[0210] The above are merely preferred embodiments of the present invention, but the scope of protection of the present invention is not limited thereto. Any equivalent substitutions or modifications made by those skilled in the art within the scope of the technology disclosed in the present invention, based on the technical solution and inventive concept of the present invention, should be covered within the scope of protection of the present invention.

Claims

1. An access control based drone communication link encryption system, characterized in that, The method comprises the following steps: A link establishment request module is configured to initiate a communication link establishment request from a first UAV node to a second UAV node, and generate a link establishment request message; An identity authentication module is configured to perform identity authentication based on the link establishment request message, generate authentication context information, and create a link session object; An access decision module is configured to perform pre-access authorization evaluation based on the authentication context information and the link session object, generate an access control decision output, and perform in-process authorization evaluation based on an improved UCON+ model; A key authorization module is configured to generate session key authorization credentials and session key material based on the access control decision output, update the link session state of the link session object, and establish a communication link; A link encryption module is configured to perform control operations based on the session key authorization credentials to obtain a traffic flow control result, and perform encryption and integrity protection to obtain encrypted link data; A state evidence collection module is configured to collect link state and environment state during communication link maintenance, and generate obligation execution evidence; A continuous control module is configured to perform in-process continuous authorization evaluation based on the link state and environment state, the obligation execution evidence, the authentication context information, and the link session object, and obtain a terminated communication link; An after-the-fact audit module is configured to perform post-use phase processing based on the terminated communication link, generate a session digest, and record an audit log.

2. The UAV communication link encryption system based on access control according to claim 1, wherein, The link establishment request module specifically comprises: Determining a communication entity participating in establishing a communication link to obtain a first UAV node and a second UAV node; Collecting request parameters for establishing a communication link from the first UAV node to obtain request parameters, and generating a link session identifier based on the request parameters; Constructing a message body of the link establishment request message according to the request parameters, performing integrity calculation on the message body, and obtaining an integrity check value; Encapsulating the message body and the integrity check value and sending them as the link establishment request message, and taking the link session identifier as a session association identifier.

3. The UAV communication link encryption system based on access control according to claim 1, wherein, The identity authentication module specifically comprises: The second UAV node receives the link establishment request message, parses the link establishment request message to obtain the message body and the integrity check value; The second UAV node recalculates a message authentication code based on the message body and the authentication key pre-stored by the first UAV node to obtain a recalculated check value; The recalculated check value and the integrity check value are compared for consistency. When the recalculated check value and the integrity check value are consistent, it is determined that the integrity verification of the link establishment request message is passed. After the integrity verification is passed, an extraction result is obtained from the message body; The second UAV node retrieves the node credentials corresponding to the identity identifier in the identity credential database based on the identity identifier, generates a random authentication challenge value based on the node credentials, and sends the random authentication challenge value to the first UAV node; After receiving the random authentication challenge value, the first UAV node performs signature calculation on the random authentication challenge value based on the authentication key to obtain a challenge response value; After receiving the challenge response value, the second UAV node calculates a verification value based on the authentication key and the random authentication challenge value to obtain the verification value; The verification value is compared with the challenge response value. When the verification value and the challenge response value are consistent, the identity authentication of the first drone node is determined to be successful, and authentication context information is generated. The second drone node creates a link session object based on the authentication context information.

4. The UAV communication link encryption system based on access control according to claim 1, wherein, The access decision module specifically includes: Receive authentication context information and link session object, and extract identity identifier, role information, task identifier, link type and link session identifier from the authentication context information to form a set of main attributes; Extract the link session state, key domain authorization range, encryption policy level, key rotation policy, re-evaluation cycle, and obligation tag from the link session object, and combine them with the link session identifier to form a set of session attributes; Based on the link type and task identifier, the resource policy information is retrieved from the policy resource library. The link type and task identifier are combined to form a resource attribute set, and the current communication environment information is collected to form an environment attribute set. The subject attribute set, resource attribute set, environment attribute set, and session attribute set are fused to construct the authorization evaluation input vector; An improved UCON+ model is constructed by using the set of link session states, the set of link session state transition relationships, the set of authorization rules, the set of obligation rules, the set of condition rules, the obligation label mapping relationship, the key policy mapping relationship, and the set of triggering rules. Based on the improved UCON+ model, a joint evaluation is performed on the authorization evaluation input vector in the pre-access phase to obtain the admission evaluation value and session constraint information; The admission evaluation value is compared with the preset admission threshold to obtain the admission result. When the admission result allows the establishment of a communication link, the policy is calculated based on the key policy mapping relationship and the authorization evaluation input vector to obtain the set of allowed actions, the key domain authorization range, the encryption policy level and the key rotation policy. The access control decision output is generated by combining and encapsulating the access result, the set of allowed actions, session constraint information, key domain authorization range, encryption policy level, key rotation policy, and link session state transition instructions.

5. The UAV communication link encryption system based on access control according to claim 1, wherein, The key authorization module specifically includes: Receive access control decision output, form an authorization parameter set, and generate session key authorization credentials based on the authorization parameter set; Integrity protection is performed on the session key authorization credentials to obtain protected session key authorization credentials; Determine the session random number, and generate the initial session master key based on the link session identifier and the session random number; Generate a set of domain keys based on the initial session master key, key domain authorization range, and encryption policy profile; A key rotation parameter set is generated based on the key rotation strategy, thus obtaining the key rotation parameter set; The protected session key authorization credentials are bound and encapsulated with the domain key set and the key rotation parameter set to generate session key material; The session key material is distributed to the first UAV node and the second UAV node to obtain the distribution result. The link session state of the link session object is updated according to the link session state migration instruction to establish a communication link.

6. The UAV communication link encryption system based on access control according to claim 1, wherein, The link encryption module specifically includes: Receive service data on the communication link and determine the service data stream type for the service data; Parse the session key authorization credentials to obtain the set of allowed actions, the key domain authorization range, the encryption policy level, and the link session identifier; Based on the allowed action set and the business data flow type, a business flow control judgment result is generated. When the service flow control determination result is an allowed value, the corresponding send and receive operations are performed for the service data flow type, and a service flow control result is generated. The corresponding key domain identifier is determined based on the business data flow type, and a matching judgment is made between the key domain identifier and the key domain authorization range to generate a key domain authorization judgment result. When the key domain authorization determination result is an allowed value, the domain key corresponding to the key domain identifier is extracted from the session key material, and the encryption algorithm level and integrity algorithm level are selected according to the encryption policy level to form the encryption input; The business data is encrypted based on the domain key and the encryption algorithm settings to obtain ciphertext. Based on the domain key and integrity algorithm settings, integrity protection operations are performed on the ciphertext and encrypted input to obtain the integrity check value; Encapsulate the ciphertext and integrity check value to form encrypted link data, thus obtaining encrypted link data.

7. The UAV communication link encryption system based on access control according to claim 1, wherein, The status verification module specifically includes: During the communication link maintenance period, a periodic trigger signal is generated according to the reassessment cycle, and the current system timestamp is recorded to form a periodic trigger event; During the communication link maintenance period, the status of the communication network is monitored, and the link event type is obtained based on the monitoring results to identify whether a link event has occurred. When a link event type is detected, a link event record is generated, and link operation status parameters and communication environment parameters are collected to obtain the link status and environment status. The oblig rule set corresponding to the oblig tag is read from the oblig tag in the session key authorization credential, and the oblig execution status is obtained by performing oblig execution detection on the current communication behavior based on the oblig rule set. Evidence of obligation execution is generated based on the link session identifier, obligation tag, obligation execution status, and current timestamp.

8. The UAV communication link encryption system based on access control according to claim 1, wherein, The continuous control module specifically includes: Receive link status and environment status, obligation execution evidence, authentication context information, and link session object, and construct a continuous authorization evaluation input vector; The improved UCON+ model is invoked to perform in-use phase authorization assessment calculations on the continuous authorization assessment input vector to obtain the continuous authorization assessment value. The continuous authorization evaluation value is compared with a preset set of evaluation thresholds to generate continuous control action results; Based on the results of continuous control actions, the access control decision output is updated to generate an updated access control decision output. When the result of continuous control actions is renewal, verification is performed based on the execution status of the obligation execution evidence to obtain the verification result; If the verification result is successful, generate updated session key authorization credentials and updated session key materials; When the result of continuous control actions is a reduction in weight, the updated key domain authorization range, the updated encryption policy level, and the updated business flow control result are obtained. When the result of continuous control actions is a duplicate key, a new session random number is generated according to the key rotation strategy, resulting in a new initial session master key, a new set of domain keys, and updated session key materials. When the result of continuous control actions is re-authentication, the identity authentication process is re-triggered to perform identity authentication on the first drone node and the second drone node and generate a new authentication result. The authentication context information is updated based on the new authentication result to obtain the updated authentication context information; When the result of continuous control actions is a broken link, the session key authorization credentials are invalidated and the communication link is terminated. The link session state of the link session object is updated to the terminated state, and the terminated communication link is obtained.

9. The UAV communication link encryption system based on access control according to claim 1, wherein, The post-audit module specifically includes: When a communication link is terminated or a communication link ends normally, the session information corresponding to the communication link is obtained, and a session information set is obtained. The statistical communication link generates service flow control results, link status and environment status, and obligation execution evidence during operation, forming a set of session statistics information. Based on the link session identifier, communication link establishment timestamp, communication link termination timestamp, continuous control action results, and session summary, an audit log is generated. The audit log entries are written to the audit log storage module to obtain the audit log.