A drone lifecycle traceability method based on digital identity credentials

By generating and updating digital identity credentials within the drone, combined with secure hardware storage and a decentralized traceability server, the problem of easy tampering with the central database is solved, enabling trusted traceability and authenticity verification throughout the drone's lifecycle.

CN122133123APending Publication Date: 2026-06-02SHANDONG SIJI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SHANDONG SIJI TECH CO LTD
Filing Date
2026-05-08
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

Existing drone traceability methods rely on a central database, historical records are easily tampered with, static identification cannot reflect the drone's state change history, and the reliability of traceability results is difficult to guarantee.

Method used

A drone lifecycle traceability method based on digital identity credentials is adopted. An initial digital identity credential is generated inside the drone, and behavioral feature data is collected in real time during lifecycle events to generate a new generation of digital identity credentials. This is then combined with secure hardware storage and a decentralized traceability monitoring server for traceability verification.

Benefits of technology

It enhances the tamper resistance of traceability information, enables reliable traceability of drone lifecycle events, and binds digital identity credentials with physical behavior to ensure the authenticity and integrity of traceability results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122133123A_ABST
    Figure CN122133123A_ABST
Patent Text Reader

Abstract

This invention discloses a method for tracing the entire lifecycle of a drone based on digital identity credentials, relating to the field of drone regulatory technology. The method includes: obtaining the drone's initial digital identity credential; obtaining the drone's lifecycle event trigger signal; determining an event type identifier based on the lifecycle event trigger signal; collecting behavioral feature data from the drone's current operating state based on the event type identifier and determining a behavioral feature snapshot; obtaining the drone's current valid digital identity credential; determining a new generation digital identity credential; replacing the valid digital identity credential with the new generation digital identity credential; associating the behavioral feature snapshot with the event type identifier and sending it to a traceability monitoring server for storage; obtaining a traceability verification request; performing a reverse verification operation based on the behavioral feature snapshot; and determining the traceability verification result. By generating a new credential through hybrid generation, the tamper-resistance of traceability information is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of drone regulatory technology, specifically a drone lifecycle tracing method based on digital identity credentials. Background Technology

[0002] The whole life cycle traceability of drones refers to the ability to record and track the entire process of drones from manufacturing, sales, flight mission execution, firmware upgrades, maintenance and repair to scrapping. An effective traceability mechanism is of great significance for drone flight safety supervision, accident liability determination and investigation of illegal modifications. Existing drone traceability methods usually rely on a centralized database to record the drone's identity and operation logs. After each critical event, the drone reports the event information to the central server, and the regulator traces the drone's historical behavior by querying the central database.

[0003] However, the integrity and authenticity of the traceability data in existing methods are highly dependent on the security management of the central database. Once the central database is attacked or tampered with by internal personnel, the historical records can be arbitrarily modified, and the reliability of the traceability results is difficult to guarantee. Moreover, the drone identification in existing methods is usually a fixed static identifier, which cannot reflect the drone's status change history, and it is difficult for regulators to directly obtain the drone's historical information from the current identification. Summary of the Invention

[0004] (a) Technical problems to be solved Existing traceability methods rely on a central database and static identity identifiers. The historical records of the central database method are easily tampered with, and the static identity identifiers cannot reflect the complete historical status of the UAV from the current identifier. In order to address the shortcomings of the existing technology, this invention provides a UAV full lifecycle traceability method based on digital identity credentials.

[0005] (II) Technical Solution To achieve the above objectives, the present invention provides the following technical solution: a method for tracing the entire lifecycle of unmanned aerial vehicles (UAVs) based on digital identity credentials, specifically including the following steps: S1. Obtain the initial digital identity credential of the drone, which is stored in the drone's hardware secure storage area; S2. Obtain the drone lifecycle event trigger signal, determine the event type identifier based on the lifecycle event trigger signal, collect behavioral feature data from the drone's current operating state based on the event type identifier, and determine a behavioral feature snapshot; S3. Obtain the current valid digital identity credential of the drone, and based on the valid digital identity credential and the behavioral feature snapshot, perform a credential evolution operation to determine the next generation of digital identity credential; S4. Write the new generation digital identity credential into the hardware secure storage area to replace the valid digital identity credential, and send the behavioral feature snapshot to the traceability and supervision server for storage after associating it with the event type identifier. S5. Obtain a traceability verification request, wherein the traceability verification request carries the current digital identity credential of the drone to be verified and the lifecycle event sequence to be verified; S6. Based on the behavioral feature snapshots corresponding to each event node in the lifecycle event sequence to be verified, perform reverse verification operations on the current digital identity credential from back to front to determine the source verification result.

[0006] Preferably, in step S1, during the initialization phase of the UAV, a random byte sequence of fixed length is generated by a hardware security element installed inside the UAV. The random byte sequence is used as the initial seed value, and a one-way derivation operation is performed on the initial seed value to obtain the initial digital identity credential. The one-way derivation operation includes the process of inputting the initial seed value into a one-way transformation function and outputting a fixed-length byte sequence. The initial digital identity credential is written into the first credential storage partition of the hardware secure storage area, the initial seed value is associated with the hardware serial number of the drone, and then transferred to the traceability and supervision server for filing and storage through an offline secure channel. The specific steps for filing and storing the records are as follows: During the drone manufacturing process, the initial seed value and the drone hardware serial number are written into the same data record line and stored in a removable storage medium. The removable storage medium is then delivered to the management location of the traceability and supervision server, where the seed registration terminal of the traceability and supervision server reads the data record line in the removable storage medium and extracts the initial seed value and hardware serial number. The seed registration terminal performs a one-way derivation operation on the extracted initial seed value to generate an initial digital identity certificate. The generated initial digital identity certificate is associated with the hardware serial number and stored in the seed registration storage unit as a base certificate for traceability verification.

[0007] Preferably, in step S2, an event monitoring unit installed inside the UAV continuously monitors flight state switching signals, firmware version change signals, maintenance port access signals, and geographical location crossing signals. When the state of any of the monitored signals changes from a first state value to a second state value, a lifecycle event is determined to have occurred, and the event monitoring unit generates a lifecycle event trigger signal. Based on the actual signal type that triggers the lifecycle event, the corresponding event type identifier is determined. When the trigger signal is a flight state switching signal and the state is switched to landing, the event type identifier is determined to be the flight mission end identifier. When the trigger signal is a firmware version change signal, the event type identifier is determined to be a firmware upgrade identifier; When the trigger signal is a maintenance port access signal, the event type identifier is determined to be a maintenance identifier; When the trigger signal is a geographic location crossing signal that crosses a preset airspace boundary, the event type identifier is determined to be an airspace switching identifier; Based on the event type identifier, the collection item set corresponding to the event type identifier is read from the collection item configuration information pre-stored inside the UAV. The collection item set specifies the category identifier of the operating parameters to be collected and the collection order of each parameter. Based on the category identifier in the collection item set, the flight attitude angle and flight altitude values ​​are read sequentially from the UAV's flight control unit, the latitude and longitude coordinate values ​​and ambient temperature values ​​are read from the sensor unit, and the remaining battery capacity value and cumulative flight time value are read from the power management unit. The read operating parameter values ​​are sequentially converted into binary representations of fixed byte length. The converted binary representations are then concatenated end to end according to the acquisition order to obtain a behavior feature concatenation sequence. A one-way compression transformation operation is performed on the behavior feature concatenation sequence to obtain a fixed-length output byte sequence. The output byte sequence is then determined as the behavior feature snapshot.

[0008] Preferably, in step S3, the complete byte sequence of the valid digital identity credential currently stored by the UAV is read from the hardware secure storage area, the byte length value of the valid digital identity credential and the byte length value of the behavioral feature snapshot are obtained, and the two are compared. If the byte length of the valid digital identity credential is equal to the byte length of the behavioral feature snapshot, then each byte of the valid digital identity credential is XORed with the corresponding byte in the behavioral feature snapshot to obtain a mixed byte sequence. If the byte length of the valid digital identity credential is not equal to the byte length of the behavioral feature snapshot, the shorter byte sequence is extended to the same length as the longer byte sequence using a cyclic expansion method, and then a byte-by-byte XOR mixing operation is performed to obtain a mixed byte sequence. A one-way transformation operation is performed on the mixed byte sequence to obtain a new generation of digital identity credential with the same length as the valid digital identity credential.

[0009] Preferably, in step S4, a credential integrity protection field is added to the new generation digital identity credential. The credential integrity protection field is obtained by performing a cyclic redundancy check operation on all bytes of the new generation digital identity credential. The new generation digital identity credential with the credential integrity protection field added is written into the hardware secure storage area, overwriting the storage location occupied by the original valid digital identity credential. Obtain the credential version number of the digital identity credential currently held by the drone, where the credential version number represents the number of credential evolutions that have been performed since the initial digital identity credential was generated; The new credential version number is obtained by incrementing the credential version number by one. The credential version number, event type identifier, behavior feature snapshot, and current timestamp are combined into an event record. The event record is protected and encapsulated using the public protection key of the traceability and supervision server to generate an event record protection package. The event log protection package is sent to the traceability and monitoring server via the communication link between the drone and the ground station. After receiving the event log protection package, the traceability and monitoring server uses the private decryption key corresponding to the public protection key to perform the decryption verification operation. After successful verification, the event log is stored in the event log storage unit.

[0010] Preferably, in step S5, a traceability verification request message initiated by the traceability supervisor through the supervisory terminal is received, a format verification operation is performed on the traceability verification request message, and after the verification is passed, the platform identifier of the drone to be verified is extracted from the header area of ​​the message. Based on the platform identifier, the latest current digital identity credential of the drone to be verified is obtained from the status information periodically reported by the drone through the telemetry link. Extract the lifecycle event sequence to be verified from the payload area of ​​the traceability verification request message. The lifecycle event sequence to be verified contains at least one event node, and each event node consists of an event type identifier field and an event timestamp range field.

[0011] Preferably, in step S6, the total number of event nodes is determined from the lifecycle event sequence to be verified, the total number of event nodes is recorded as a first quantity value, the current digital identity credential is used as a level zero verification credential, and the current processing sequence number is set as the first quantity value. The penultimate event node is extracted from the lifecycle event sequence to be verified. Based on the event type identifier and event timestamp range of the event node, the matching event record is retrieved from the event record storage unit of the traceability and supervision server, and a behavioral feature snapshot is extracted from the matching event record as a first behavioral feature snapshot. The zero-level verification credential and the first line feature snapshot are mixed by performing a byte-by-byte operation, and a one-way transformation operation is performed on the mixed result to obtain the first-level verification credential. Decrement the current processing sequence number by one, and determine whether the current processing sequence number after decrementing by one is greater than zero. If it is greater than zero, extract the event node with the corresponding sequence number from the lifecycle event sequence to be verified, retrieve the corresponding behavioral feature snapshot, and perform byte mixing and one-way transformation operations on the previous level verification credential and the behavioral feature snapshot again to obtain the next level verification credential. Repeat the above steps until the current processing sequence number is reduced to zero, and then determine the final verification credential as the last-level verification credential. The initial digital identity credential corresponding to the drone to be verified is read from the seed registration storage unit of the traceability and supervision server as the base credential; The final verification certificate is compared byte by byte with the base certificate. If they are completely consistent, the traceability verification result is determined to be passed. If any byte is inconsistent, the traceability verification result is determined to be failed.

[0012] (III) Beneficial Effects This invention provides a method for tracing the entire lifecycle of unmanned aerial vehicles (UAVs) based on digital identity credentials, which has the following beneficial effects: This invention generates a new credential by mixing the behavioral characteristics of each lifecycle event of a drone with the current digital identity credential, and the old credential is then erased, effectively improving the anti-tampering capability of traceability information. The behavioral characteristic snapshots in this invention are directly collected in real time from the drone's flight control unit and sensor unit, and are correlated in real time with the physical operating state of the drone at the moment the event occurs. This establishes a binding relationship between the evolution of the digital identity credential and the physical behavior of the drone. The drone holds a constantly evolving digital identity credential at any time. The digital identity credential contains the accumulated information of all lifecycle events since the drone left the factory, realizing decentralized and trustworthy traceability. Attached Figure Description

[0013] Figure 1 This is a flowchart of the method of the present invention. Detailed Implementation

[0014] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0015] Please see Figure 1 This invention provides a method for tracing the entire lifecycle of a drone based on digital identity credentials, comprising the following steps: S1. Obtain the initial digital identity credential of the drone, which is stored in the drone's hardware secure storage area; Furthermore, in S1, during the initialization phase of the UAV, a random byte sequence of fixed length is generated by a hardware security element installed inside the UAV. The random byte sequence is used as the initial seed value, and a one-way derivation operation is performed on the initial seed value to obtain the initial digital identity credential. The one-way derivation operation includes the process of inputting the initial seed value into a one-way transformation function and outputting a fixed-length byte sequence. The initial digital identity credential is written into the first credential storage partition of the hardware secure storage area, the initial seed value is associated with the hardware serial number of the drone, and then transferred to the traceability and supervision server for filing and storage through an offline secure channel. The specific steps for filing and storing the records are as follows: During the drone manufacturing process, the initial seed value and the drone hardware serial number are written into the same data record line and stored in a removable storage medium. The removable storage medium is then delivered to the management location of the traceability and supervision server, where the seed registration terminal of the traceability and supervision server reads the data record line in the removable storage medium and extracts the initial seed value and hardware serial number. The seed registration terminal performs a one-way derivation operation on the extracted initial seed value to generate an initial digital identity certificate. The generated initial digital identity certificate is associated with the hardware serial number and stored in the seed registration storage unit as a base certificate for traceability verification.

[0016] It should be noted that the specific steps of the one-way derivation operation are as follows: The hardware security element inputs all bytes of the initial seed value into the one-way transformation function in order from the most significant bit to the least significant bit. The one-way transformation function is a deterministic byte processing flow that is fixed inside the hardware security element. Its processing includes multiple rounds of byte replacement, position permutation and XOR mixing operations. The input byte sequence is first divided into several fixed-length groups. Each group goes through the first round of byte replacement in turn. According to a fixed replacement table, the value of each byte in the group is replaced with the value of another byte at the corresponding position in the table. Then, after position permutation, each byte in the group is moved to a new position according to a fixed position mapping sequence. Finally, a byte-by-byte XOR operation is performed with a fixed round constant. After multiple rounds of iterative processing, the one-way transformation function outputs an output byte sequence with the same length as the input. There is only a one-way derivation relationship between the output byte sequence and the initial seed value. The hardware security element determines the output byte sequence as the initial digital identity credential. The initial digital identity credential and the initial seed value are completely different in value, but there is a verifiable correspondence between the two. After generating the initial digital identity credential, the hardware security element writes the initial digital identity credential into the first credential storage partition of the hardware security storage area. The hardware security storage area is a non-volatile storage space inside or coupled to the hardware security element. The first credential storage partition is used to store the initial digital identity credential. After the write operation is completed, the initial digital identity credential will be stored as the first generation of valid digital identity credential of the drone from the moment it leaves the factory. Unless it is replaced by a new generation of credential in a subsequent life cycle event, its content will not be modified by any external or internal program. The hardware security element associates the initial seed value with the drone's hardware serial number. The drone's hardware serial number is a unique string of characters in the drone's main control chip during the production process. The hardware security element reads the hardware serial number from the main control chip and concatenates the initial seed value and the hardware serial number into the same data record line. The data record line is then exported to the production terminal. After obtaining the initial seed value, the seed registration storage unit performs the same one-way derivation operation as the hardware security element on the initial seed value. The seed registration storage unit inputs all the bytes of the extracted initial seed value into the same one-way transformation function as the hardware security element. After the same number of rounds of byte replacement, position permutation and XOR mixing processing, an output byte sequence is obtained. The seed filing storage unit determines the output byte sequence as a filing copy of the initial digital identity credential and associates it with the hardware serial number extracted from the data record line. The association method is to add a new record in the seed filing storage unit, fill in the extracted hardware serial number in the hardware serial number field of the record, and fill in the generated initial digital identity credential in the credential field.

[0017] S2. Obtain the drone lifecycle event trigger signal, determine the event type identifier based on the lifecycle event trigger signal, collect behavioral feature data from the drone's current operating state based on the event type identifier, and determine a behavioral feature snapshot; Furthermore, in S2, an event monitoring unit installed inside the UAV continuously monitors flight state switching signals, firmware version change signals, maintenance port access signals, and geographical location crossing signals. When the state of any of the monitored signals changes from a first state value to a second state value, a lifecycle event is determined to have occurred, and the event monitoring unit generates a lifecycle event trigger signal. Based on the actual signal type that triggers the lifecycle event, the corresponding event type identifier is determined. When the trigger signal is a flight state switching signal and the state is switched to landing, the event type identifier is determined to be the flight mission end identifier. When the trigger signal is a firmware version change signal, the event type identifier is determined to be a firmware upgrade identifier; When the trigger signal is a maintenance port access signal, the event type identifier is determined to be a maintenance identifier; When the trigger signal is a geographic location crossing signal that crosses a preset airspace boundary, the event type identifier is determined to be an airspace switching identifier; Based on the event type identifier, the collection item set corresponding to the event type identifier is read from the collection item configuration information pre-stored inside the UAV. The collection item set specifies the category identifier of the operating parameters to be collected and the collection order of each parameter. Based on the category identifier in the collection item set, the flight attitude angle and flight altitude values ​​are read sequentially from the UAV's flight control unit, the latitude and longitude coordinate values ​​and ambient temperature values ​​are read from the sensor unit, and the remaining battery capacity value and cumulative flight time value are read from the power management unit. The read operating parameter values ​​are sequentially converted into binary representations of fixed byte length. The converted binary representations are then concatenated end to end according to the acquisition order to obtain a behavior feature concatenation sequence. A one-way compression transformation operation is performed on the behavior feature concatenation sequence to obtain a fixed-length output byte sequence. The output byte sequence is then determined as the behavior feature snapshot.

[0018] It should be noted that the preset airspace boundary refers to the data of the closed polygon boundary, which includes the area identifier, area type identifier, and a number of latitude and longitude coordinates connected sequentially, which is pre-written into the non-volatile storage area of ​​the UAV during the initialization stage of the UAV or before the execution of the flight mission. This is done through the production terminal parameter configuration interface or the ground station software encrypted communication link. The event monitoring unit obtains the real-time latitude and longitude coordinates of the UAV and determines whether it is inside or outside the preset airspace boundary by the spatial position relationship of the real-time coordinates relative to the spatial position relationship. When the spatial position relationship result changes from inside to outside or from outside to inside in two consecutive judgments, the event monitoring unit determines that a geographical location crossing event has occurred and generates a corresponding life cycle event trigger signal. This then drives the event type identifier to be determined as an airspace switching identifier and subsequent behavior feature snapshot collection and credential evolution operations, recording each airspace crossing behavior of the UAV in the evolution chain of the digital identity credential.

[0019] It should be noted that the event monitoring unit obtains the flight status switching signal by reading the status register of the UAV flight control system. The flight status switching signal is automatically set by the flight control system when the UAV's flight status changes. The event monitoring unit detects the firmware version change signal by comparing the current firmware version number in the firmware storage partition with the previously recorded historical firmware version number. When the two are inconsistent, it is determined that a change has occurred. The event monitoring unit detects the maintenance port access signal by monitoring the level status of the UAV's external maintenance port. When the level of the maintenance port changes from high impedance to low or from low to high, it indicates that an external debugging or maintenance device has been connected. The event monitoring unit reads the real-time latitude and longitude coordinates output and compares them with the airspace boundary geofence data pre-stored inside the UAV to detect geographical location crossing signals. When the real-time coordinates move from the inside area of ​​the fence to the outside area of ​​the fence or vice versa, it is determined that an airspace crossing has occurred. When the event monitoring unit detects that the state of any signal changes from the first state value to the second state value, the event monitoring unit determines that a life cycle event has occurred and immediately generates a life cycle event trigger signal, which is an internal interrupt signal. After generating a lifecycle event trigger signal, the event monitoring unit determines the corresponding event type identifier based on the signal type of the actual trigger event. The event type identifier is used to distinguish different categories of lifecycle events. When the lifecycle event trigger signal is caused by a flight state switching signal, and the current flight state read by the event monitoring unit from the flight control system status register is the landing state, the event monitoring unit determines the event type identifier as a flight mission end identifier. When the lifecycle event trigger signal is caused by a firmware version change signal, the event monitoring unit determines the event type identifier as a firmware upgrade identifier. When the lifecycle event trigger signal is caused by a maintenance port access signal, the event monitoring unit determines the event type identifier as a maintenance identifier. When the lifecycle event trigger signal is caused by a geographical location crossing signal, and the comparison result between the real-time coordinates and the geofence data of the airspace boundary shows that the UAV has crossed the preset airspace boundary, the event monitoring unit will identify the event type as an airspace switching identifier. After receiving the event type identifier, the corresponding set of collection items is read from the collection item configuration information pre-stored inside the drone based on the event type identifier. The collection item configuration information is structured data written into the internal storage area of ​​the drone before it leaves the factory. The structured data is organized into a corresponding relationship table with the event type identifier as the index. Each event type identifier corresponds to a set of collection items in the corresponding relationship table. The collection item set specifies the category identifier of the operating parameters that should be collected when a type lifecycle event occurs, as well as the collection order of each parameter. For example, for the flight mission end identifier, its corresponding collection item set may include the flight attitude angle category identifier, flight altitude value category identifier, latitude and longitude coordinate value category identifier, ambient temperature value category identifier, battery remaining capacity value category identifier, and cumulative flight time value category identifier in sequence. For the maintenance identifier, its corresponding collection item set may focus on parameters such as ambient temperature value, battery remaining capacity value, and flight control unit operating status code. According to the category identifier and collection order in the read collection item set, parameter reading requests are sent to each functional unit of the UAV in sequence. Based on the category identifier in the collection item set, the instantaneous values ​​of the corresponding operating parameters are read from the flight control unit, sensor unit and power management unit of the UAV. After all the specified operating parameter values ​​are read, the snapshot acquisition module performs standardization conversion and stitching operations on these values. The minimum byte length required is determined according to the value range of each parameter value. For example, the flight attitude angle is in degrees and accurate to one decimal place, which can be converted into a two-byte binary two's complement representation. For values ​​that are less than the fixed byte length, zeros are padded in the high-order byte. For values ​​that exceed the fixed byte length, the low-order byte is truncated. After the conversion is completed, the binary representations of each parameter are concatenated strictly according to the collection order specified in the collection item set. During concatenation, the binary representation of the first parameter occupies the first few bytes of the output buffer, and the binary representation of the second parameter follows immediately after it. The above steps are repeated until the binary representations of all parameters are concatenated. The continuous byte sequence obtained after concatenation is the behavior feature concatenation sequence. Subsequently, a one-way compression transformation operation is performed on the behavioral feature concatenation sequence. All bytes of the behavioral feature concatenation sequence are sequentially input into a one-way compression transformation function. The one-way compression transformation function first divides the input byte sequence into several fixed-length groups. For each group, byte substitution, position permutation, and round constant XOR operations are sequentially performed. After several rounds of iteration, the outputs of each group are merged. The length of the merged byte sequence is fixed. The fixed length is determined by the output specification of the one-way compression transformation function and is independent of the length of the input sequence. The fixed-length output byte sequence obtained by the one-way compression transformation operation is determined as the behavioral feature snapshot.

[0020] S3. Obtain the current valid digital identity credential of the drone, and based on the valid digital identity credential and the behavioral feature snapshot, perform a credential evolution operation to determine the next generation of digital identity credential; Furthermore, in S3, the complete byte sequence of the valid digital identity credential currently stored by the UAV is read from the hardware secure storage area, the byte length value of the valid digital identity credential and the byte length value of the behavioral feature snapshot are obtained, and the two are compared. If the byte length of the valid digital identity credential is equal to the byte length of the behavioral feature snapshot, then each byte of the valid digital identity credential is XORed with the corresponding byte in the behavioral feature snapshot to obtain a mixed byte sequence. If the byte length of the valid digital identity credential is not equal to the byte length of the behavioral feature snapshot, the shorter byte sequence is extended to the same length as the longer byte sequence using a cyclic expansion method, and then a byte-by-byte XOR mixing operation is performed to obtain a mixed byte sequence. A one-way transformation operation is performed on the mixed byte sequence to obtain a new generation of digital identity credential with the same length as the valid digital identity credential.

[0021] It should be noted that the specific steps for the byte-by-byte XOR operation are as follows: Allocate a mixed buffer in memory with a length equal to that of the valid digital identity credential in bytes. Set a loop sequence number variable and initialize it to zero. Read the first byte value of the valid digital identity credential at the offset position indicated by the sequence number variable, and at the same time read the first byte value of the behavioral feature snapshot at the same offset position. Perform a bitwise XOR operation on the two byte values. For each binary bit at the same position in two bytes, if the values ​​of the two binary bits are the same, the result of the operation is zero; if the values ​​of the two binary bits are different, the result of the operation is one. After the operation is completed, an output byte value is obtained and written into the mixed buffer at the position corresponding to the current offset position. Increment the value of the loop number variable by one unit, read the byte value of the two byte sequences at the next offset position, perform the bitwise XOR operation again, and write the result to the corresponding position in the mixed buffer. Repeat the above steps until the loop number variable reaches the byte length value minus one. After the loop has traversed all the bytes of the two byte sequences, the continuous byte sequence stored in the mixed buffer is the mixed byte sequence. If the comparison results show that the byte length of the valid digital identity credential is not equal to the byte length of the behavioral feature snapshot, then the shorter byte sequence is first extended to the same length as the longer byte sequence using a cyclic expansion method, and then a byte-by-byte XOR mixing operation is performed. The specific steps of the cyclic expansion method are as follows: determine which is larger, the byte length of the valid digital identity credential or the byte length of the behavioral feature snapshot, take the larger one as the target length, take the smaller one as the sequence to be expanded, allocate a temporary buffer in memory with a length equal to the byte length of the sequence to be expanded, and copy all bytes of the sequence to be expanded to the temporary buffer. Calculate the difference between the target length and the length of the sequence to be expanded to determine the number of additional bytes needed. Read the bytes in the temporary buffer in the original order, and append each byte to the end of the expansion buffer as it is read, until the total number of bytes in the expansion buffer reaches the target length. The specific steps of the loop reading are as follows: Set a read pointer and read bytes sequentially from the beginning of the temporary buffer. When the read pointer moves to the end of the temporary buffer, set the read pointer back to the beginning of the temporary buffer and continue reading sequentially. After the expansion is completed, the byte sequence stored in the expanded buffer is the byte sequence after loop expansion. Perform a byte-by-byte XOR operation on the longer byte sequence and the byte sequence after loop expansion to obtain the mixed byte sequence. After obtaining the mixed byte sequence, a one-way transformation operation is performed on the mixed byte sequence. The specific steps of the one-way transformation operation are as follows: All bytes of the mixed byte sequence are taken as input and fed into the one-way transformation function fixed inside the UAV. The mixed byte sequence is divided into several fixed-length groups, and the length of each group is consistent with the group length specified inside the one-way transformation function. For each group, the one-way transformation function performs the first round of transformation in sequence. Based on a fixed replacement table, it replaces the value of each byte in the group with the byte value at the corresponding offset position in the replacement table. Based on a fixed position mapping sequence, it rearranges the positions of each byte in the group. Finally, the group is XORed byte by byte with the constant of the first round. After the first round of transformation is completed, the output result is used as the input of the second round of transformation. The replacement, permutation and XOR process is repeated until all preset rounds of transformation are completed. After all rounds of transformation are completed, the output results of each group are concatenated in the order of group processing to obtain a continuous output byte sequence. The length of the output byte sequence is the same as the length of the mixed byte sequence of the input one-way transformation function. The output byte sequence is then identified as the new generation digital identity credential.

[0022] S4. Write the new generation digital identity credential into the hardware secure storage area to replace the valid digital identity credential, and send the behavioral feature snapshot to the traceability and supervision server for storage after associating it with the event type identifier. Furthermore, in S4, a certificate integrity protection field is added to the new generation digital identity certificate. The certificate integrity protection field is obtained by performing a cyclic redundancy check operation on all bytes of the new generation digital identity certificate. The new generation digital identity certificate with the certificate integrity protection field added is written into the hardware secure storage area, covering the storage location occupied by the original valid digital identity certificate. Obtain the credential version number of the digital identity credential currently held by the drone, where the credential version number represents the number of credential evolutions that have been performed since the initial digital identity credential was generated; The new credential version number is obtained by incrementing the credential version number by one. The credential version number, event type identifier, behavior feature snapshot, and current timestamp are combined into an event record. The event record is protected and encapsulated using the public protection key of the traceability and supervision server to generate an event record protection package. The event log protection package is sent to the traceability and monitoring server via the communication link between the drone and the ground station. After receiving the event log protection package, the traceability and monitoring server uses the private decryption key corresponding to the public protection key to perform the decryption verification operation. After successful verification, the event log is stored in the event log storage unit.

[0023] It should be noted that for each byte of input, the Cyclic Redundancy Check (CRBC) performs an XOR operation with the value at a specific position in the shift register. Then, it performs a left shift operation on the shift register and determines whether to perform an XOR operation with a preset generator polynomial value based on the least significant bit of the XOR result. After all bytes of the new generation digital identity credential have been input and processed, the final value retained in the shift register is the result of the CRBC operation, and the result of the CRBC operation is used as the credential integrity protection field. After generating the credential integrity protection field, the credential integrity protection field is appended to the end of the new generation digital identity credential, forming a composite data structure composed of the digital identity credential body and the credential integrity protection field. The new generation digital identity credential with the credential integrity protection field is written to the hardware secure storage area. The writing location is the credential storage partition occupied by the original valid digital identity credential. The writing operation is performed in an overwrite mode, that is, the new data is written byte by byte starting from the starting address of the credential storage partition, completely overwriting the entire contents of the original old credential. After the write operation is complete, only the newly generated next-generation digital identity credential and its integrity protection field are retained in the hardware secure storage area, and all traces of the old credential are completely erased; Any read operation on the currently valid digital identity credential must extract the credential integrity protection field and perform the same cyclic redundancy check operation on the main part of the read digital identity credential. The operation result is compared with the stored credential integrity protection field. If the two are consistent, it means that the credential is complete and has not been tampered with. If they are inconsistent, a credential invalidation alarm is triggered immediately and the subsequent processing is terminated. After the secure storage of the digital identity credential is completed, the credential version number of the digital identity credential currently held by the drone is obtained. The credential version number is used to represent the number of credential evolutions since the initial digital identity credential was generated. The credential version number is set to zero when the initial digital identity credential is generated and stored in an independent version counting partition in the hardware secure storage area. After each credential evolution operation is completed and the new generation credential is successfully written, the current credential version number is read from the version counting partition, the current credential version number is incremented by one, the incremented value is used as the new credential version number, and it is written back to the version counting partition to overwrite the original value. The credential version number currently read is the number of evolutions before this credential evolution occurred. Incrementing it by one gives the credential version number corresponding to this evolution. The updated credential version number, the event type identifier of this lifecycle event, the previously generated behavioral feature snapshot, and the current timestamp read are combined to form an event record. The specific combination method is as follows: allocate an event record buffer in memory, write the voucher version number into the first field position of the buffer, write the event type identifier into the second field position, write all the bytes of the behavior feature snapshot into the third field position, and write the current timestamp into the fourth field position. After the combination is completed, the continuous byte sequence in the event record buffer is a complete event record. After generating the event log, a protection encapsulation operation is performed to generate an event log protection packet. The UAV first generates a one-time session protection key, which is a fixed-length random byte sequence generated by a random number generator. The session protection key is used to perform a symmetric protection transformation operation on the continuous byte sequence of the event log. That is, the session protection key is used as the transformation driving parameter to perform byte replacement and position mixing processing on all bytes of the event log in sequence to generate the event log ciphertext. Using the pre-stored public protection key of the traceability and monitoring server, an asymmetric encapsulation operation is performed on the session protection key. That is, the byte sequence of the session protection key is taken as input and encrypted and transformed using the public protection key to obtain an encapsulated session protection key. The event record ciphertext and the encapsulated session protection key are concatenated according to a preset format. A protection packet header identifier is appended to the front of the concatenated data. The protection packet header identifier contains the algorithm identifier and version information used in this encapsulation operation to form a complete event record protection packet. After generating the event log protection package, the UAV sends the event log protection package to the traceability and supervision server through the communication link between the UAV and the ground station. The communication link between the UAV and the ground station is a two-way wireless data transmission channel provided by the UAV data link. The UAV encapsulates the event log protection package as payload data into the data link transmission frame and sends it to the ground data link terminal in the form of wireless radio frequency signal through the airborne data link terminal. The ground data link terminal then forwards the data to the ground station computer connected to the traceability and supervision server. Upon receiving the event log protection packet, the traceability and monitoring server first reads the header identifier to determine the encapsulation algorithm and version. Then, it uses the private decryption key corresponding to the public protection key to perform the decryption verification operation. The specific steps of the decryption verification operation are as follows: The encapsulated session protection key is extracted from the event log protection package. An asymmetric decryption transformation is performed on the encapsulated session protection key using the private decryption key securely stored inside the traceability and monitoring server to recover the original session protection key. The event log ciphertext is extracted from the event log protection package. A symmetric decryption transformation operation is performed on the event log ciphertext using the recovered session protection key to recover the original byte sequence of the event log. After recovery, the traceability and monitoring server verifies the format and length of each field in the event log to confirm the integrity and legality of the event log. After verification, the event record is stored in the event record storage unit. The event record storage unit is a dedicated storage area inside the traceability and supervision server used to persistently store all event records reported by drones. It uses the drone's hardware serial number and certificate version number as a combined index to append the event records one by one in the order of reporting time, and returns a storage confirmation response to the drone after storage is completed.

[0024] S5. Obtain a traceability verification request, wherein the traceability verification request carries the current digital identity credential of the drone to be verified and the lifecycle event sequence to be verified; Furthermore, in S5, the traceability verification request message initiated by the traceability supervisor through the supervisory terminal is received, a format verification operation is performed on the traceability verification request message, and after the verification is passed, the platform identifier of the drone to be verified is extracted from the header area of ​​the message. Based on the platform identifier, the latest current digital identity credential of the drone to be verified is obtained from the status information periodically reported by the drone through the telemetry link. Extract the lifecycle event sequence to be verified from the payload area of ​​the traceability verification request message. The lifecycle event sequence to be verified contains at least one event node, and each event node consists of an event type identifier field and an event timestamp range field.

[0025] It should be noted that the specific steps for format validation are as follows: The traceability monitoring server reads the beginning part of the traceability verification request message and checks whether it contains a preset request start identifier sequence. The request start identifier sequence is used to mark the start boundary of a valid request message. If the start identifier sequence does not exist or is inconsistent with the preset pattern, the format verification is determined to fail. The traceability monitoring server directly discards the valid request message and returns a format error response to the monitoring terminal. If the start identifier sequence verification passes, the traceability monitoring server continues to read the end of the message and checks whether it contains a preset request end identifier sequence. The request end identifier sequence is used to mark the end boundary of the message. If the end identifier sequence does not exist or is inconsistent with the preset mode, the format verification is also determined to have failed. The traceability monitoring server will also read the message length field specified in the middle of the message and compare the value indicated by the message length field with the total number of bytes actually received in the message. If the two do not match, it is determined that the message has lost or increased bytes during transmission, and the format verification fails. Only when the request start identifier sequence, request end identifier sequence and message length field are all verified successfully will the traceability monitoring server determine that the traceability verification request message has passed the format verification operation.

[0026] S6. Based on the behavioral feature snapshots corresponding to each event node in the lifecycle event sequence to be verified, perform reverse verification operations on the current digital identity credential from back to front to determine the source verification result.

[0027] Furthermore, in S6, the total number of event nodes is determined from the lifecycle event sequence to be verified, the total number of event nodes is recorded as the first quantity value, the current digital identity credential is used as the zero-level verification credential, and the current processing sequence number is set as the first quantity value. The penultimate event node is extracted from the lifecycle event sequence to be verified. Based on the event type identifier and event timestamp range of the event node, the matching event record is retrieved from the event record storage unit of the traceability and supervision server, and a behavioral feature snapshot is extracted from the matching event record as the first behavioral feature snapshot. The zero-level verification credential and the first line feature snapshot are mixed by performing a byte-by-byte operation, and a one-way transformation operation is performed on the mixed result to obtain the first-level verification credential. Decrement the current processing sequence number by one, and determine whether the current processing sequence number after decrementing by one is greater than zero. If it is greater than zero, extract the event node with the corresponding sequence number from the lifecycle event sequence to be verified, retrieve the corresponding behavioral feature snapshot, and perform byte mixing and one-way transformation operations on the previous level verification credential and the behavioral feature snapshot again to obtain the next level verification credential. Repeat the above steps until the current processing sequence number is reduced to zero, and then determine the final verification credential as the last-level verification credential. The initial digital identity credential corresponding to the drone to be verified is read from the seed registration storage unit of the traceability and supervision server as the base credential; The final verification certificate is compared byte by byte with the base certificate. If they are completely consistent, the traceability verification result is determined to be passed. If any byte is inconsistent, the traceability verification result is determined to be failed.

[0028] It should be noted that the Level 0 verification credential represents the digital identity credential state held by the drone after experiencing all the lifecycle events to be verified. The specific steps of the byte mixing operation are as follows: First, obtain the byte length of the Level 0 verification credential and the byte length of the first row of feature snapshots. If the two are equal, perform a byte-by-byte XOR mixing operation. If the two lengths are not equal, use a cyclic expansion method to expand the shorter sequence to the same length as the longer sequence before performing a byte-by-byte XOR mixing operation. After mixing, a mixed byte sequence is obtained. Then, perform a one-way transformation operation on the mixed byte sequence that is exactly the same as the credential evolution stage. The one-way transformation operation also includes dividing the mixed byte sequence into fixed-length groups, performing multiple rounds of byte replacement, position permutation, and round constant XOR processing on each group. After the one-way transformation operation is completed, output a byte sequence with the same length as the Level 0 verification credential. The output byte sequence is the Level 1 verification credential. The Level 1 verification credential is equal to the digital identity credential held by the drone before completing the last lifecycle event, that is, before experiencing the evolution of that event. After obtaining the first-level verification certificate, the traceability monitoring server subtracts one unit from the value of the current processing sequence number. Then, the traceability monitoring server determines whether the current processing sequence number after subtraction is greater than zero. If the current processing sequence number is greater than zero, it indicates that there are still unprocessed event nodes in the lifecycle event sequence to be verified, and the reverse verification operation needs to continue. The traceability monitoring server extracts the event node with the corresponding sequence number from the lifecycle event sequence to be verified based on the value of the current processing sequence number. The same byte mixing and one-way transformation operations are performed again on the previous level verification certificate (i.e., the first level verification certificate) and the behavioral feature snapshot to obtain the next level verification certificate, i.e., the second level verification certificate. After completion, the traceability and supervision server decrements the current processing sequence number by one again and repeats the above judgment, extraction, mixing and transformation process. In each loop, the current processing sequence number is decremented by one unit and one event node is advanced from the event sequence. At the same time, the verification certificate held by the current server is deduced one level further in the historical direction. The loop continues until the value of the current processing sequence number becomes zero after a certain decrement operation. At this time, it indicates that all event nodes in the life cycle event sequence to be verified have been processed. The traceability and supervision server obtains the final level verification certificate, i.e., the last level verification certificate. The last level verification certificate is equal to the digital identity certificate held by the drone before experiencing all life cycle events to be verified, i.e., in the initial state. Subsequently, the traceability monitoring server performs a byte-by-byte consistency comparison between the final verification credential and the read baseline credential. The byte-by-byte consistency comparison operation is as follows: starting from the first byte of both credentials, the byte values ​​at the same offset positions are read sequentially and compared. If the byte value of the final verification credential is different from the byte value of the baseline credential at any offset position, they are determined to be inconsistent, and the comparison process is terminated immediately. If, after traversing all bytes of both credentials, the byte values ​​at all corresponding positions are completely identical, they are determined to be consistent. According to the comparison results, if the final verification credential and the baseline credential are completely consistent, the traceability monitoring server determines that the traceability verification result is passed, indicating that the digital identity credential currently held by the drone to be verified was indeed generated by the initial digital identity credential according to the event sequence described by the life cycle event sequence to be verified through a legitimate credential evolution operation, and the drone's full life cycle behavior trajectory is real, complete, and has not been tampered with. If they are inconsistent, the traceability monitoring server determines that the traceability verification result is failed, indicating that there is a deviation between the life cycle event sequence to be verified and the actual evolution process experienced by the drone, and there may be abnormal situations such as missing event records, incorrect event sequence, or forged digital identity credential.

[0029] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0030] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0031] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0032] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0033] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of protection of the described technical solution.

Claims

1. A method for tracing the entire lifecycle of unmanned aerial vehicles (UAVs) based on digital identity credentials, characterized in that: Includes the following steps: S1. Obtain the initial digital identity credential of the drone, which is stored in the drone's hardware secure storage area; S2. Obtain the drone lifecycle event trigger signal, determine the event type identifier based on the lifecycle event trigger signal, collect behavioral feature data from the drone's current operating state based on the event type identifier, and determine a behavioral feature snapshot; S3. Obtain the current valid digital identity credential of the drone, and based on the valid digital identity credential and the behavioral feature snapshot, perform a credential evolution operation to determine the next generation of digital identity credential; S4. Write the new generation digital identity credential into the hardware secure storage area to replace the valid digital identity credential, and send the behavioral feature snapshot to the traceability and supervision server for storage after associating it with the event type identifier. S5. Obtain a traceability verification request, wherein the traceability verification request carries the current digital identity credential of the drone to be verified and the lifecycle event sequence to be verified; S6. Based on the behavioral feature snapshots corresponding to each event node in the lifecycle event sequence to be verified, perform reverse verification operations on the current digital identity credential from back to front to determine the source verification result.

2. The method for tracing the entire lifecycle of a drone based on digital identity credentials according to claim 1, characterized in that, In S1, during the initialization phase of the UAV, a random byte sequence of fixed length is generated by a hardware security element installed inside the UAV. The random byte sequence is used as the initial seed value, and a one-way derivation operation is performed on the initial seed value to obtain the initial digital identity credential. The one-way derivation operation includes the process of inputting the initial seed value into a one-way transformation function and outputting a fixed-length byte sequence. The initial digital identity credential is written into the first credential storage partition of the hardware secure storage area. The initial seed value is associated with the hardware serial number of the drone and recorded. The record is then transferred to the traceability and supervision server for filing and storage via an offline secure channel.

3. The method for tracing the entire lifecycle of a drone based on digital identity credentials according to claim 2, characterized in that, The specific steps for filing and storing the records are as follows: During the drone manufacturing process, the initial seed value and the drone hardware serial number are written into the same data record line and stored in a removable storage medium. The removable storage medium is then delivered to the management location of the traceability and supervision server, where the seed registration terminal of the traceability and supervision server reads the data record line in the removable storage medium and extracts the initial seed value and hardware serial number. The seed registration terminal performs a one-way derivation operation on the extracted initial seed value to generate an initial digital identity certificate. The generated initial digital identity certificate is associated with the hardware serial number and stored in the seed registration storage unit as a base certificate for traceability verification.

4. The method for tracing the entire lifecycle of a drone based on digital identity credentials according to claim 1, characterized in that, In S2, an event monitoring unit installed inside the UAV continuously monitors flight state switching signals, firmware version change signals, maintenance port access signals, and geographical location crossing signals. When the state of any of the monitored signals changes from a first state value to a second state value, a lifecycle event is determined to have occurred, and the event monitoring unit generates a lifecycle event trigger signal. Based on the actual signal type that triggers the lifecycle event, the corresponding event type identifier is determined. When the trigger signal is a flight state switching signal and the state is switched to landing, the event type identifier is determined to be the flight mission end identifier. When the trigger signal is a firmware version change signal, the event type identifier is determined to be a firmware upgrade identifier; When the trigger signal is a maintenance port access signal, the event type identifier is determined to be a maintenance identifier; When the trigger signal is a geographic location crossing signal that crosses a preset airspace boundary, the event type identifier is determined to be an airspace switching identifier; Based on the event type identifier, the collection item set corresponding to the event type identifier is read from the collection item configuration information pre-stored inside the UAV. The collection item set specifies the category identifier of the operating parameters to be collected and the collection order of each parameter. Based on the category identifier in the collection item set, the flight attitude angle and flight altitude values ​​are read sequentially from the UAV's flight control unit, the latitude and longitude coordinate values ​​and ambient temperature values ​​are read from the sensor unit, and the remaining battery capacity value and cumulative flight time value are read from the power management unit. The read operating parameter values ​​are sequentially converted into binary representations of fixed byte length. The converted binary representations are then concatenated end to end according to the acquisition order to obtain a behavior feature concatenation sequence. A one-way compression transformation operation is performed on the behavior feature concatenation sequence to obtain a fixed-length output byte sequence. The output byte sequence is then determined as the behavior feature snapshot.

5. The method for tracing the entire lifecycle of a drone based on digital identity credentials according to claim 1, characterized in that, In step S3, the complete byte sequence of the valid digital identity credential currently stored by the UAV is read from the hardware secure storage area, the byte length value of the valid digital identity credential and the byte length value of the behavioral feature snapshot are obtained, and the two are compared. If the byte length of the valid digital identity credential is equal to the byte length of the behavioral feature snapshot, then each byte of the valid digital identity credential is XORed with the corresponding byte in the behavioral feature snapshot to obtain a mixed byte sequence. If the byte length of the valid digital identity credential is not equal to the byte length of the behavioral feature snapshot, the shorter byte sequence is extended to the same length as the longer byte sequence using a cyclic expansion method, and then a byte-by-byte XOR mixing operation is performed to obtain a mixed byte sequence. A one-way transformation operation is performed on the mixed byte sequence to obtain a new generation of digital identity credential with the same length as the valid digital identity credential.

6. The method for tracing the entire lifecycle of a drone based on digital identity credentials according to claim 1, characterized in that, In step S4, a credential integrity protection field is added to the new generation digital identity credential. The credential integrity protection field is obtained by performing a cyclic redundancy check operation on all bytes of the new generation digital identity credential. The new generation digital identity credential with the credential integrity protection field added is written to the hardware secure storage area, overwriting the storage location occupied by the original valid digital identity credential. Obtain the credential version number of the digital identity credential currently held by the drone, where the credential version number represents the number of credential evolutions that have been performed since the initial digital identity credential was generated; The new credential version number is obtained by incrementing the credential version number by one. The credential version number, event type identifier, behavior feature snapshot, and current timestamp are combined into an event record. The event record is then protected and encapsulated using the public protection key of the traceability and supervision server to generate an event record protection package.

7. The method for tracing the entire lifecycle of a drone based on digital identity credentials according to claim 6, characterized in that, The event log protection package is sent to the traceability and monitoring server via the communication link between the drone and the ground station. After receiving the event log protection package, the traceability and monitoring server uses the private decryption key corresponding to the public protection key to perform the decryption verification operation. After successful verification, the event log is stored in the event log storage unit.

8. The method for tracing the entire lifecycle of a drone based on digital identity credentials according to claim 1, characterized in that, In step S5, a traceability verification request message initiated by the traceability supervisor through the supervisory terminal is received, a format verification operation is performed on the traceability verification request message, and after the verification is passed, the platform identifier of the drone to be verified is extracted from the header area of ​​the message. Based on the platform identifier, the latest current digital identity credential of the drone to be verified is obtained from the status information periodically reported by the drone through the telemetry link. Extract the lifecycle event sequence to be verified from the payload area of ​​the traceability verification request message. The lifecycle event sequence to be verified contains at least one event node, and each event node consists of an event type identifier field and an event timestamp range field.

9. The method for tracing the entire lifecycle of a drone based on digital identity credentials according to claim 1, characterized in that, In step S6, the total number of event nodes is determined from the lifecycle event sequence to be verified, and the total number of event nodes is recorded as the first quantity value. The current digital identity credential is used as the level zero verification credential, and the current processing sequence number is set as the first quantity value. The penultimate event node is extracted from the lifecycle event sequence to be verified. Based on the event type identifier and event timestamp range of the event node, the matching event record is retrieved from the event record storage unit of the traceability and supervision server, and a behavioral feature snapshot is extracted from the matching event record as the first behavioral feature snapshot.

10. The method for tracing the entire lifecycle of a drone based on digital identity credentials according to claim 9, characterized in that, The zero-level verification credential and the first line feature snapshot are mixed by performing a byte-by-byte operation, and a one-way transformation operation is performed on the mixed result to obtain the first-level verification credential. Decrement the current processing sequence number by one, and determine whether the current processing sequence number after decrementing by one is greater than zero. If it is greater than zero, extract the event node with the corresponding sequence number from the lifecycle event sequence to be verified, retrieve the corresponding behavioral feature snapshot, and perform byte mixing and one-way transformation operations on the previous level verification credential and the behavioral feature snapshot again to obtain the next level verification credential. Repeat the above steps until the current processing sequence number is reduced to zero, and then determine the final verification credential as the last-level verification credential. The initial digital identity credential corresponding to the drone to be verified is read from the seed registration storage unit of the traceability and supervision server as the base credential; The final verification certificate is compared byte by byte with the base certificate. If they are completely consistent, the traceability verification result is determined to be passed. If any byte is inconsistent, the traceability verification result is determined to be failed.

Citation Information

Patent Citations

  • Dynamic traceability identifier generation and verification method based on multi-node environment data fusion

    CN121390112A

  • Autonomous devices

    US10158480B1