A judicial expertise evidence system and method for illegal flight of a drone
The judicial identification and evidence collection system for illegal drone flights, which integrates multi-source data fusion and blockchain technology, solves the problems of single monitoring methods and weak traceability in existing technologies. It achieves high-precision trajectory restoration and electromagnetic link traceability, generates judicially credible evidence reports, and improves the automation and standardization of low-altitude safety governance.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIJING RONGGEN INTERNET TECH CO LTD
- Filing Date
- 2026-03-30
- Publication Date
- 2026-07-10
AI Technical Summary
Existing drone monitoring technologies in low-altitude airspace suffer from several problems, including limited monitoring methods, lack of electromagnetic link tracing technology, weak trajectory reconstruction capabilities, lack of evidence solidification and judicial linkage, and absence of standardized behavioral analysis models. These issues make it difficult to quickly identify and trace illegal flight incidents, affecting the accuracy of low-altitude safety governance and judicial credibility.
A closed-loop system consisting of a low-altitude monitoring unit, a trajectory fusion and recovery unit, an electromagnetic feature acquisition unit, a link tracing module, and an evidence solidification module is adopted. Combined with low-altitude detection radar, photoelectric imaging, electromagnetic detection, and 5G-A integrated sensor, the system achieves real-time detection, trajectory reconstruction, electromagnetic link tracing, and evidence solidification of UAVs through multi-source data fusion, signal fingerprint comparison, and blockchain technology, generating a credible judicial evidence report.
It significantly improves the ability to identify illegal drone flights and enhances judicial credibility, increases target capture rate and source tracing accuracy, reduces judicial disputes caused by flawed evidence, improves law enforcement efficiency and standardization, and enables rapid response to illegal flight incidents in high-risk scenarios.
Smart Images

Figure CN122362533A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a forensic identification and evidence collection system and method for illegal drone flights, belonging to the field of low-altitude safety governance technology. Background Technology
[0002] In recent years, with the rapid popularization of civilian drones in aerial surveying, logistics, emergency rescue, and entertainment, the number of aircraft in low-altitude airspace has exploded. Drones, with their small size, high speed, strong stealth, ease of acquisition, and ease of operation, are widely used in people's lives, but this has also led to frequent incidents of illegal flights, incursions into no-fly zones, interference with public safety facilities, and threats to public safety. For example, in key areas such as airport perimeters, government agencies, and nuclear power plants, illegal drone flights can cause major safety accidents. Traditional regulatory methods (such as manual patrols or single-sensor monitoring) are insufficient for real-time monitoring, rapid identification, and traceability in complex low-altitude environments. The dynamic nature of low-altitude airspace and the heterogeneity of drones (such as different models and flight attitudes) further exacerbate the difficulty of governance, exposing the shortcomings of current technological systems in terms of accuracy, stability, and judicial credibility.
[0003] Existing drone regulatory technologies suffer from five key problems that hinder their ability to collect evidence in court:
[0004] The monitoring methods are limited and the detection stability is insufficient: existing low-altitude surveillance relies mainly on optoelectronic equipment or simple radar. However, under complex backgrounds (such as urban buildings blocking the view), multipath effects, or severe weather, the detection accuracy and detection range decrease significantly, making it impossible to form a stable acquisition capability for small, high-speed, or low-altitude hovering UAVs, resulting in a high target miss rate.
[0005] The lack of electromagnetic link tracing technology and incomplete evidence chain: Drone control signals often use 2.4GHz, 5.8GHz or customized protocols. Existing systems can only detect frequency band activities and it is difficult to extract information such as "signal fingerprints" and "protocol features" that can be used to uniquely identify the remote control terminal or image transmission device. This cannot meet the requirements of judicial appraisal for the relevance and verifiability of evidence.
[0006] Weak trajectory recovery capability and unreliable flight path reconstruction: Although some monitoring systems can capture discrete location points, they lack time synchronization mechanisms, noise compensation algorithms and multi-source data fusion capabilities, resulting in many broken points and large errors in the reconstructed trajectory. They cannot accurately restore the flight path of the drone (such as entering a no-fly zone or performing dangerous actions), making it difficult to use for the identification of illegal flight behavior and post-event auditing.
[0007] The lack of evidence consolidation and judicial links, and insufficient anti-tampering mechanisms: The evidence data in the existing system is mostly stored in ordinary platform-level databases, lacking anti-tampering mechanisms such as credible timestamps and hash verification. Moreover, the collection process does not comply with the norms recognized by judicial appraisal institutions, resulting in insufficient authenticity, completeness and verifiability of evidence, which cannot directly support administrative penalties or legal proceedings.
[0008] The lack of standardized behavioral analysis models and inconsistent liability determination: The determination of the operator's identity, flight purpose and behavior of drones needs to be based on comprehensive evidence such as trajectory and electromagnetic signals. However, the existing technology has not built a unified "rule set for determining illegal flight events", which makes law enforcement determination highly subjective, inefficient and unclear in the attribution of responsibility, thus affecting the impartiality of the judiciary.
[0009] The aforementioned deficiencies reveal a significant technological gap in the field of low-altitude safety governance: existing systems cannot achieve a closed loop of multi-source detection fusion, high-precision trajectory reconstruction, electromagnetic link tracing, and judicial-grade evidence solidification. This results in a lack of standardized and verifiable technical support for regulatory enforcement and judicial proceedings, particularly in high-risk scenarios such as airports and key infrastructure, making it difficult to respond quickly and trace responsibility for unauthorized drone flights. Therefore, there is an urgent need for a judicial identification and evidence collection system and method integrating multimodal sensing, intelligent algorithms, and blockchain technology to fill the gaps in the evidence collection system and improve the automation, standardization, and credibility of low-altitude safety governance.
[0010] Therefore, a judicial identification and evidence collection system and method for illegal drone flights is proposed. Summary of the Invention
[0011] In view of this, the present invention provides a forensic identification and evidence collection system and method for illegal drone flights, in order to solve or alleviate the technical problems existing in the prior art, and at least provide a beneficial option.
[0012] The technical solution of the present invention is implemented as follows: a judicial identification and evidence collection system for illegal drone flights, the system consists of a low-altitude monitoring unit, a flight path fusion and trajectory restoration unit, an electromagnetic feature acquisition unit, a link tracing module, an evidence solidification module, and a judicial identification analysis platform connected in a closed loop via a data bus or network link;
[0013] The low-altitude monitoring unit employs several types of sensors, including low-altitude detection radar, photoelectric imaging, 5G-A, and electromagnetic detection. It achieves unified time synchronization (GPS / BeiDou clock source) through a data synchronization device, which is used for real-time detection, identification, and three-dimensional positioning of suspicious drones.
[0014] The trajectory fusion and restoration unit, based on extended Kalman filtering or particle filtering algorithms, performs multi-source heterogeneous fusion of radar spot data, visual angle data, and electromagnetic coarse positioning data, outputting a continuous, smooth, and legally reproducible three-dimensional flight trajectory. The state vector is defined as x=(x,y,z, , , );
[0015] The electromagnetic feature acquisition unit includes a spectrum scanning module, a protocol identification module, and an RF fingerprint extraction module, used to extract RF feature parameters of the UAV control link (such as I / Q imbalance and power spectrum shape) and generate a device fingerprint vector F=( , ,…, );
[0016] The link tracing module compares signal fingerprints and locates the transmitter (using the TOA / TDOA algorithm, with the location function being...). =c( - By analyzing the correlation between the remote control terminal and historical behavior, the location of the remote control terminal can be retrieved and the identity can be inferred.
[0017] The evidence solidification module uses a blockchain-style hash chain, trusted timestamps, and SHA-256 / SM3 algorithm to generate an immutable evidence package, ensuring that the data conforms to the judicial appraisal format.
[0018] The judicial appraisal analysis platform integrates an event judgment engine, a behavior rule base, and a correlation analysis engine, and automatically outputs a "Judicial Appraisal Report on Illegal Drone Flight".
[0019] More preferably, the low-altitude monitoring unit specifically includes:
[0020] The low-altitude detection radar module operates in the X / Ku band and outputs target point sequence, Doppler information, and timestamps. It can be used for real-time detection, tracking, and situational analysis of low-altitude targets and supports data fusion with other sensors.
[0021] The optoelectronic imaging module integrates a high-definition visible light camera and an infrared camera, and uses YOLO or CenterNet target detection algorithms to achieve UAV shape recognition.
[0022] The electromagnetic detection module scans the frequency band from 300MHz to 6GHz and can identify WiFi, 2.4GHz, 5.8GHz, and custom protocol signals.
[0023] The data synchronization and fusion interface ensures the time consistency of sensor data through GPS / BeiDou clock sources.
[0024] More preferably, the track fusion and trajectory restoration unit further includes:
[0025] The data preprocessing module is used for radar point filtering (spherical clustering and noise removal) and visual target box angle transformation;
[0026] The time synchronization module calibrates the latency of multi-source data based on a unified clock source;
[0027] The sensor registration module calibrates extrinsic parameters using a coordinate transformation matrix (WGS84 or ENU coordinate system) and a Levenberg-Marquardt optimizer.
[0028] The multi-source fusion algorithm module uses EKF or PF algorithm to achieve trajectory smoothing and outputs track in KML, GeoJSON or PDF format.
[0029] The trajectory visualization and storage module supports trajectory playback and speed change graph generation.
[0030] More preferably, in the electromagnetic feature acquisition unit:
[0031] The spectrum scanning module detects the signal frequency hopping mode and duty cycle;
[0032] The protocol identification module supports the identification of DJI, Autel, WiFi-FPV and open source protocols;
[0033] The features extracted by the radio frequency fingerprint extraction module include frequency offset, time offset, and packet waveform differences;
[0034] It also includes a feature database comparison module, which matches fingerprint vectors with historical signal databases and returns device brand, model, and the time, location, and behavior that occurred.
[0035] More preferably, the link tracing module includes:
[0036] The fingerprint comparison engine dynamically adjusts the similarity threshold through a machine learning model.
[0037] The transmitter positioning module uses RSSI or AOA coarse positioning combined with TOA / TDOA precise positioning;
[0038] The device signature database stores manufacturer fingerprints, historical case data, and registration information of suspicious persons.
[0039] The behavioral correlation analysis module generates manipulator inference results based on trajectory features, regional risk labels, and historical activities.
[0040] More preferably, the evidence solidification module is specifically implemented in the following ways:
[0041] The data standardization module generates metadata (collection time, device number, and verification value).
[0042] The hash generation module uses SHA-256 or the national cryptographic SM3 algorithm to generate data fingerprints;
[0043] The trusted timestamp module generates legally-grade timestamps from an authoritative time source;
[0044] Blockchain-style evidence chain storage uses a chain structure to solidify evidence packages and prevent tampering.
[0045] A forensic evidence collection method for illegal drone flights includes the following steps:
[0046] Step S1: When an illegal flight incident is triggered, the system automatically activates based on suspicious signals within the no-fly zone or restricted flight area;
[0047] Step S2: Multimodal detection and target recognition, integrating radar spot data, visual target bounding boxes, and electromagnetic spectrum activity to achieve UAV 3D positioning and model identification;
[0048] Step S3: Track reconstruction, unifying the time series of multi-source data through the time synchronization module, and using the EKF / PF algorithm for track fitting and smoothing;
[0049] Step S4: Electromagnetic link acquisition and signal fingerprint extraction, perform spectrum sampling on the control link and image transmission link, analyze protocol features and generate radio frequency fingerprints;
[0050] Step S5: Link tracing and operator location: The location of the remote control terminal is determined by matching fingerprint comparison engine and device feature library, combined with TOA / TDOA inversion.
[0051] Step S6: Evidence consolidation, converting flight tracks, images, and electromagnetic data into a judicially acceptable format to generate an evidence package with timestamps and hash values;
[0052] Step S7: Judicial analysis and report output, automatically generating opinions on the determination of the responsible party and an analysis report on illegal flights based on the behavior determination model.
[0053] More preferably, the multimodal detection in step S2 includes:
[0054] Radar spot filtering generates range-velocity information;
[0055] Visual target detection outputs bounding boxes and spatial angles;
[0056] Electromagnetic spectrum activity identification signal center frequency and bandwidth.
[0057] More preferably, the link tracing in step S5 further includes:
[0058] By correlating historical behavior data, it can be determined whether the remote control terminal has been involved in illegal flight incidents;
[0059] The probability of manipulators is calculated by combining regional risk labels (such as airports and government agencies).
[0060] More preferably, its application scenarios include key target areas such as airport perimeters, nuclear power plants, sports venues and urban management centers. When deployed, it covers low-altitude high-risk areas and automatically outputs standardized evidence collection reports through the judicial appraisal analysis platform.
[0061] The embodiments of the present invention have the following advantages due to the adoption of the above technical solutions:
[0062] I. This invention significantly improves the identification capability and judicial credibility of unauthorized drones through multimodal fusion monitoring and high-precision trajectory reconstruction. Specifically, the low-altitude monitoring unit employs multi-source sensing methods such as low-altitude detection radar, photoelectric imaging, electromagnetic detection, and 5G-A integrated sensing, working collaboratively. A unified time synchronization device (GPS / BeiDou clock source) is used to overcome the limitations of single sensors in complex environments (such as urban multipath effects or severe weather). The low-altitude detection radar module operates in the X / Ku band and can output target point sequences and Doppler information; the photoelectric imaging module integrates visible light and infrared cameras, achieving drone morphology recognition based on YOLO or CenterNet algorithms; the electromagnetic detection module scans the 300MHz~6GHz frequency band, identifying WiFi, 2.4G / 5.8G, and other custom frequency band signals. This multimodal fusion increases the target acquisition rate to over 95% and can meet the low-altitude monitoring needs of high-risk areas such as airports and city centers.
[0063] Meanwhile, the trajectory fusion and recovery unit, based on extended Kalman filter or particle filter algorithms, cleans, registers, and fuses multi-source heterogeneous data. The state vector is defined as x=(x,y,z, , , The system eliminates time delay differences through a time synchronization module and unifies the data to the WGS84 coordinate system using a sensor registration module, ultimately generating a continuous and smooth 3D trajectory. The output is in KML or PDF format for judicial auditing. The trajectory reconstruction accuracy can reach the meter level, accurately reconstructing key behaviors such as drone intrusion into no-fly zones, hovering, or escape, providing verifiable evidence for the identification of illegal flights.
[0064] II. This invention achieves judicial-grade reliability in electromagnetic link tracing and evidence solidification, filling a gap in traditional evidence collection techniques. The electromagnetic feature acquisition unit detects signal frequency hopping patterns through a spectrum scanning module, the protocol identification module parses customized protocols such as DJI and Autel, and the radio frequency fingerprint extraction module generates a unique device fingerprint vector F=( , ,…, Features include I / Q imbalance and power spectrum shape. The link tracing module further integrates the fingerprint comparison engine and the transmitter location module, employing the TOA / TDOA algorithm (Taiwanese Transmission Address Allocation Function). =c( - By reversing the location of the remote control terminal and matching it with historical case data through a device feature database, the system can accurately infer the identity of the operator and the device model, achieving a tracing accuracy rate of over 90%.
[0065] The evidence solidification module uses blockchain technology to ensure the immutability of the evidence chain. The data standardization module converts flight tracks, images, and electromagnetic data into a legally recognized format; the hash generation module uses SHA-256 or SM3 algorithms to generate data fingerprints; and the trusted timestamp module attaches an authoritative time source. Finally, the evidence package is stored in a chain structure. This design complies with the requirements of the "Standards for Forensic Identification of Electronic Evidence," possesses verifiability, and can be directly used for administrative penalties or criminal proceedings, avoiding judicial disputes caused by flawed evidence.
[0066] Third, the automated analysis capabilities and multi-scenario adaptability of this invention significantly improve law enforcement efficiency and standardization. The judicial appraisal analysis platform integrates an event judgment engine and a correlation analysis engine, automatically completes the determination of the level of illegal flight (such as intrusion into a no-fly zone or dangerous approach) based on a behavioral feature rule model, and performs path comparison by linking the no-fly zone dataset to generate a "Judicial Appraisal Report on Illegal Drone Flight". This method reduces the time spent on traditional manual evidence collection from several hours to minutes, improves case processing efficiency by more than 80%, and ensures that law enforcement determination is scientific and standardized through a unified rule set, reducing subjective bias.
[0067] Meanwhile, the system supports deployment in multiple scenarios. The low-altitude monitoring unit can be flexibly configured with sensor arrays, and the forensic analysis platform can dynamically adjust the judgment threshold based on regional risk labels. It is highly practical and can be scaled up. For example, in airport applications, the system can monitor drone intrusions in real time and, combined with historical behavior data correlation analysis, quickly identify the responsible parties, providing standardized technical support for low-altitude safety governance.
[0068] The above overview is for illustrative purposes only and is not intended to be limiting in any way. In addition to the illustrative aspects, embodiments, and features described above, further aspects, embodiments, and features of the invention will become readily apparent from the accompanying drawings and the following detailed description. Attached Figure Description
[0069] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0070] Figure 1 This is a schematic diagram of the overall structure of the present invention;
[0071] Figure 2 This is a structural block diagram of the multimodal monitoring unit of the present invention;
[0072] Figure 3 This is a flowchart of the UAV trajectory fusion and trajectory restoration process of the present invention;
[0073] Figure 4 This is a flowchart of the electromagnetic feature acquisition and signal fingerprint extraction process of the present invention;
[0074] Figure 5 This is a schematic diagram of the implementation structure of the link tracing module of the present invention;
[0075] Figure 6 This is a flowchart of the judicial evidence solidification module of the present invention;
[0076] Figure 7 This is an overall flowchart of the judicial identification method for illegal drone flights according to the present invention;
[0077] Figure 8 This is a schematic diagram illustrating a typical application scenario of the present invention. Detailed Implementation
[0078] In the following description, only certain exemplary embodiments are briefly described. As those skilled in the art will recognize, the described embodiments can be modified in various ways without departing from the spirit or scope of the invention. Therefore, the drawings and description are considered to be exemplary in nature and not restrictive.
[0079] The embodiments of the present invention will now be described in detail with reference to the accompanying drawings.
[0080] Example
[0081] like Figure 1-8As shown, this embodiment of the invention provides a forensic evidence collection system for illegal drone flights. The system consists of a low-altitude monitoring unit, a flight path fusion and trajectory restoration unit, an electromagnetic feature acquisition unit, a link tracing module, an evidence solidification module, and a forensic analysis platform connected in a closed loop via a data bus or network link.
[0082] The low-altitude monitoring unit employs multi-source sensing methods such as low-altitude detection radar, photoelectric imaging, electromagnetic detection, and 5G-A integrated sensing. It achieves unified time synchronization (GPS / BeiDou clock source) through a data synchronization device, which is used for real-time detection, identification, and three-dimensional positioning of suspicious drones.
[0083] The trajectory fusion and recovery unit, based on extended Kalman filter or particle filter algorithms, performs multi-source heterogeneous fusion of radar spot data, visual angle data, and electromagnetic coarse positioning data, outputting a continuous, smooth, and legally reproducible three-dimensional flight trajectory. The state vector is defined as x=(x,y,z, , , );
[0084] The electromagnetic feature acquisition unit includes a spectrum scanning module, a protocol identification module, and an RF fingerprint extraction module. It is used to extract RF feature parameters (such as I / Q imbalance and power spectrum shape) of the UAV control link and generate a device fingerprint vector F=( , ,…, );
[0085] The link tracing module compares signal fingerprints and locates the transmitter (using the TOA / TDOA algorithm, with the location function being...). =c( - By analyzing the correlation between the remote control terminal and historical behavior, the location of the remote control terminal can be retrieved and the identity can be inferred.
[0086] The evidence solidification module uses a blockchain-style hash chain, trusted timestamps, and SHA-256 / SM3 algorithms to generate an immutable evidence package, ensuring that the data conforms to the format for forensic identification.
[0087] The judicial appraisal analysis platform integrates an event determination engine, a behavior rule base, and a correlation analysis engine to automatically output a "Judicial Appraisal Report on Illegal Drone Flight".
[0088] Furthermore, the low-altitude monitoring unit specifically includes:
[0089] The low-altitude detection radar module operates in the X / Ku band and outputs target point sequence, Doppler information, and timestamps. It can be used for real-time detection, tracking, and situational analysis of low-altitude targets and supports data fusion with other sensors.
[0090] The optoelectronic imaging module integrates a high-definition visible light camera and an infrared camera, and uses YOLO or CenterNet target detection algorithms to achieve UAV shape recognition.
[0091] The electromagnetic detection module scans the frequency band from 300MHz to 6GHz and can identify WiFi, 2.4GHz, 5.8GHz, and custom protocol signals.
[0092] 5G-A integrated sensing capability enables the perception, analysis, and data retention of drone communication links, achieving flight trajectory reconstruction and evidence tracing.
[0093] The data synchronization and fusion interface ensures the time consistency of sensor data through GPS / BeiDou clock sources.
[0094] Furthermore, the track fusion and trajectory restoration unit further includes:
[0095] The data preprocessing module is used for radar point filtering (spherical clustering and noise removal) and visual target box angle transformation;
[0096] The time synchronization module calibrates the latency of multi-source data based on a unified clock source;
[0097] The sensor registration module calibrates extrinsic parameters using a coordinate transformation matrix (WGS84 or ENU coordinate system) and a Levenberg-Marquardt optimizer.
[0098] The multi-source fusion algorithm module uses EKF or PF algorithm to achieve trajectory smoothing and outputs track in KML, GeoJSON or PDF format.
[0099] The trajectory visualization and storage module supports trajectory playback and speed change graph generation.
[0100] Furthermore, in the electromagnetic feature acquisition unit:
[0101] The spectrum scanning module detects the frequency hopping mode and duty cycle of the signal;
[0102] The protocol identification module supports the identification of DJI, Autel, WiFi-FPV, and open-source protocols;
[0103] The features extracted by the radio frequency fingerprint extraction module include frequency offset, time offset, and packet header waveform differences;
[0104] It also includes a feature database comparison module, which matches fingerprint vectors with historical signal databases and returns the device brand, model and locations where it has appeared.
[0105] Furthermore, the link tracing module includes:
[0106] The fingerprint comparison engine dynamically adjusts the similarity threshold through a machine learning model.
[0107] The transmitter positioning module uses RSSI or AOA coarse positioning combined with TOA / TDOA precise positioning;
[0108] The device signature database stores manufacturer fingerprints, historical case data, and registration information of suspicious persons.
[0109] The behavioral correlation analysis module generates manipulator inference results based on trajectory features, regional risk labels, and historical activities.
[0110] Furthermore, the specific implementation methods of the evidence solidification module include:
[0111] The data standardization module generates metadata (collection time, device number, and verification value).
[0112] The hash generation module uses SHA-256 or the national cryptographic SM3 algorithm to generate data fingerprints;
[0113] The trusted timestamp module generates legally-grade timestamps from an authoritative time source;
[0114] Blockchain-style evidence chain storage uses a chain structure to solidify evidence packages and prevent tampering.
[0115] A forensic evidence collection method for illegal drone flights includes the following steps:
[0116] Step S1: When an illegal flight incident is triggered, the system automatically activates based on suspicious signals within the no-fly zone or restricted flight area;
[0117] Step S2: Multimodal detection and target recognition, integrating radar spot data, visual target bounding boxes, and electromagnetic spectrum activity to achieve UAV 3D positioning and model identification;
[0118] Step S3: Track reconstruction, unifying the time series of multi-source data through the time synchronization module, and using the EKF / PF algorithm for track fitting and smoothing;
[0119] Step S4: Electromagnetic link acquisition and signal fingerprint extraction, perform spectrum sampling on the control link and image transmission link, analyze protocol features and generate radio frequency fingerprints;
[0120] Step S5: Link tracing and operator location: The location of the remote control terminal is determined by matching fingerprint comparison engine and device feature library, combined with TOA / TDOA inversion.
[0121] Step S6: Evidence consolidation, converting flight tracks, images, and electromagnetic data into a judicially acceptable format to generate an evidence package with timestamps and hash values;
[0122] Step S7: Judicial analysis and report output, automatically generating opinions on the determination of the responsible party and an analysis report on illegal flights based on the behavior determination model.
[0123] Furthermore, the multimodal detection in step S2 includes:
[0124] Radar spot filtering generates range-velocity information;
[0125] Visual target detection outputs bounding boxes and spatial angles;
[0126] Electromagnetic spectrum activity identification signal center frequency and bandwidth.
[0127] Furthermore, the link tracing in step S5 further includes:
[0128] By correlating historical behavior data, it can be determined whether the remote control terminal has been involved in illegal flight incidents;
[0129] The probability of manipulators is calculated by combining regional risk labels (such as airports and government agencies).
[0130] Furthermore, its application scenarios include key target areas such as airport perimeters, nuclear power plants, sports venues, and urban management centers. When deployed, it covers low-altitude high-risk areas and automatically outputs standardized evidence collection reports through the judicial appraisal analysis platform.
[0131] This invention significantly improves the identification capability and judicial credibility of unauthorized drones through multimodal fusion monitoring and high-precision trajectory reconstruction. Specifically, the low-altitude monitoring unit employs multi-source sensing methods such as low-altitude detection radar, photoelectric imaging, electromagnetic detection, and 5G-A integrated sensing to work collaboratively. A unified time synchronization device (GPS / BeiDou clock source) is used to overcome the limitations of single sensors in complex environments (such as urban multipath effects or severe weather). The low-altitude detection radar module operates in the X / Ku band and can output target point sequences and Doppler information; the photoelectric imaging module integrates visible light and infrared cameras and uses YOLO or CenterNet algorithms to achieve drone morphology recognition; the electromagnetic detection module scans the 300MHz~6GHz frequency band and identifies WiFi, 2.4G / 5.8G signals; and the 5G-A integrated sensing capability senses, analyzes, and stores data on the drone's communication link. This multimodal fusion improves the target acquisition rate to over 95% and can adapt to the low-altitude monitoring needs of high-risk areas such as airports and city centers. Simultaneously, the trajectory fusion and recovery unit, based on extended Kalman filtering or particle filtering algorithms, cleans, registers, and fuses multi-source heterogeneous data. The state vector is defined as x=(x,y,z, , , This invention eliminates time delay differences through a time synchronization module and unifies the data to the WGS84 coordinate system using a sensor registration module, ultimately generating a continuous and smooth 3D trajectory, outputting it in KML or PDF format for judicial auditing. The trajectory reconstruction accuracy reaches the meter level, accurately reconstructing key behaviors such as drone intrusion into no-fly zones, hovering, or escape, providing verifiable evidence for illegal flight identification. This invention achieves judicial-grade reliability in electromagnetic link tracing and evidence solidification, filling a gap in traditional evidence collection techniques. The electromagnetic feature acquisition unit detects signal frequency hopping modes through a spectrum scanning module, parses customized protocols such as DJI and Autel through a protocol identification module, and generates a unique device fingerprint vector F=( , ,…, Features include I / Q imbalance and power spectrum shape. The link tracing module further integrates the fingerprint comparison engine and the transmitter location module, employing the TOA / TDOA algorithm (Taiwanese Transmission Address Allocation Function). =c( - The system retrieves the location of the remote control terminal and matches it with historical case data using a device feature database to accurately infer the operator's identity and device model, achieving a traceability accuracy rate of over 90%. The evidence solidification module uses blockchain technology to ensure the immutability of the evidence chain. The data standardization module converts flight tracks, images, and electromagnetic data into a judicially acceptable format, the hash generation module uses SHA-256 or SM3 algorithms to generate data fingerprints, and the trusted timestamp module attaches an authoritative time source, ultimately storing the evidence package in a chain structure. This design complies with the requirements of the "Electronic Evidence Judicial Appraisal Standard," possesses verifiability, and can be directly used for administrative penalties or criminal proceedings, avoiding judicial disputes caused by flawed evidence. The automated analysis capabilities and multi-scenario adaptability of this invention significantly improve law enforcement efficiency and standardization. The forensic identification and analysis platform integrates an event judgment engine and a correlation analysis engine. Based on a behavioral feature rule base, it automatically determines the level of illegal flight (such as intrusion into a no-fly zone or dangerous approach), and compares paths using a no-fly zone dataset to generate a "Forensic Identification Report on Illegal Drone Flight." This method reduces the time required for traditional manual evidence collection from several hours to minutes, improving case processing efficiency by over 80%. Furthermore, the unified rule set ensures scientific and standardized law enforcement determinations, reducing subjective bias. The system supports multi-scenario deployment; the low-altitude monitoring unit can flexibly configure sensor arrays, and the forensic identification and analysis platform can dynamically adjust judgment thresholds based on regional risk labels. It is highly practical and scalable. For example, in airport applications, the system can monitor drone intrusions in real time, and through correlation analysis of historical behavioral data, quickly identify the responsible party, providing standardized technical support for low-altitude safety governance.
[0132] I. Interconnection and Data Flow Refinement of the Overall System Architecture
[0133] Data flow collaboration mechanism: The low-altitude monitoring unit outputs target point traces, images and spectrum data in real time. After ensuring time synchronization through unified time synchronization (GPS / BeiDou clock source), the data is input to the track fusion unit for trajectory reconstruction. The reconstructed track and the signal fingerprint extracted by the electromagnetic feature unit are transmitted in parallel to the link tracing module for correlation analysis. Finally, all data are stored on the blockchain through the evidence solidification module and the forensic identification analysis platform automatically generates an identification report.
[0134] Hardware deployment requirements: Each unit can be deployed in a distributed manner. For example, the sensor array of the low-altitude monitoring unit needs to cover key areas (such as antenna towers around the airport perimeter), while the analysis platform can be placed on a cloud server to support access from multiple terminals.
[0135] II. Implementation Details of Sub-modules of the Low-Altitude Monitoring Unit
[0136] The hardware selection and data processing flow for its three sub-modules are detailed below:
[0137] Low-altitude detection radar module:
[0138] Hardware configuration: It adopts FMCW frequency modulated continuous wave radar, with the preferred operating frequency band being X / Ku, a detection range of 0.1-5km, and an angle accuracy of ±0.1°.
[0139] Data processing: Output target point sequence (including distance, velocity, and azimuth), filter out clutter using the CFAR constant false alarm rate algorithm, and remove noise points using spherical clustering (DBSCAN algorithm).
[0140] Output interface: The dot data, accompanied by a microsecond-level timestamp, is transmitted to the fusion interface via Ethernet.
[0141] Photoelectric imaging module:
[0142] Hardware configuration: A high-definition visible light camera (resolution 3840×2160) and an infrared camera (thermal sensitivity ≤50mK) work together, with an optical zoom of 20×.
[0143] Recognition Algorithm: Target detection is performed based on YOLOv8 or CenterNet models. The model training data includes common drone models such as multi-rotor and fixed-wing drones, with a recognition accuracy of >98%.
[0144] Data output: Generates target bounding box and geographic coordinates (converted via WGS84), frame rate 25fps, synchronized with radar data.
[0145] Electromagnetic detection module:
[0146] Hardware configuration: Software-defined radio (SDR) equipment (such as USRP B210), scanned frequency band 300MHz-6GHz, instantaneous bandwidth 56MHz.
[0147] Signal processing: Generates spectrograms in real time, extracts signal center frequency, bandwidth and frequency hopping period through short-time Fourier transform (STFT), and identifies protocols such as DJI OcuSync and Wi-Fi.
[0148] Synchronization mechanism: The data synchronization device adopts the PTP precision clock protocol, with a delay error of <1ms.
[0149] 5G-A module: characterized by supporting access to operator 5G-A network data and realizing data synchronization and correlation processing, used for drone target information collection, behavior analysis and evidence collection support.
[0150] III. Detailed Algorithm and Process for Track Fusion and Trajectory Restoration Unit
[0151] Its module functions are detailed as follows:
[0152] Data preprocessing module:
[0153] Radar spot filtering: Density-based clustering algorithms (such as OPTICS) are used to remove isolated noise points.
[0154] Visual data conversion: The image bounding box is mapped to the ENU coordinate system through perspective transformation, with elevation angle error compensation ≤0.5°.
[0155] Coarse electromagnetic positioning: The distance to the signal source is estimated using the RSSI path loss model (Log-distance model).
[0156] Time synchronization module:
[0157] Aligning timestamps of multi-source data based on the PTP protocol, interpolating and resampling radar, vision, and electromagnetic data to address inherent sensor delays (such as camera exposure time).
[0158] Sensor registration module:
[0159] Coordinate unification: The sensor's local coordinates are transformed to the WGS84 coordinate system using a rotation-translation matrix, and the extrinsic parameters are optimized using the Levenberg-Marquardt algorithm (calibration error <0.1m).
[0160] Multi-source fusion algorithm module (20-4):
[0161] EKF algorithm parameters: State vector x=(x,y,z, , , The process noise covariance Q is taken as a diagonal matrix (diagonal value 1e-4), and the observation model integrates radar ranging and visual angle measurement.
[0162] Particle filter (PF) alternatives: 1000-5000 particles, resampling strategy is system resampling, suitable for non-Gaussian noise scenarios.
[0163] Output: Generate a smooth 3D trajectory with a position error of <3m and a velocity error of <0.5m / s.
[0164] Track visualization and storage module:
[0165] It supports KML format for Google Earth playback, GeoJSON for WebGIS integration, and PDF reports include time-velocity graphs.
[0166] IV. Refinement of the signal processing chain in the electromagnetic feature acquisition unit
[0167] The workflow for this unit is detailed as follows:
[0168] Spectrum scanning module:
[0169] The scanning step is 10kHz, the dwell time is 100ms, the detection threshold is -90dBm, and the output signal activity heatmap is generated.
[0170] Protocol identification module:
[0171] Based on the decision tree model, protocol features (such as packet length and preamble of DJI protocol) are analyzed, and the recognition library includes more than 20 protocol templates such as Autel and OpenTX.
[0172] Radio frequency fingerprint extraction module:
[0173] Extract I / Q imbalance (amplitude error <0.1dB, phase error <0.5°) and power spectral ripple features (1024 FFT points) to generate a 128-dimensional fingerprint vector F=( , ,…, ).
[0174] Feature library comparison module:
[0175] The fingerprint matching degree is calculated using cosine similarity, with a threshold set to 0.85. The device model (such as "DJI Mavic 3 remote controller") and the historical location (latitude and longitude) are returned.
[0176] V. Refinement of Location and Identity Inference in the Link Tracing Module
[0177] The implementation details of the key components are as follows:
[0178] Fingerprint matching engine:
[0179] The similarity threshold was dynamically adjusted using SVM (Support Vector Machine), and the training data contained 1000+ historical signal samples.
[0180] Transmitter positioning module:
[0181] TOA / TDOA algorithm: Number of base stations ≥ 3, time difference measurement accuracy 10ns, positioning equation =c( - In this case, the speed of light c is taken as 3e8 m / s, and the inversion position error is <50m.
[0182] RSSI-assisted: Use a logarithmic path loss model (path loss exponent n=2.5) for coarse localization.
[0183] Equipment Feature Library:
[0184] The database fields include vendor ID, RFID fingerprint, and historical case number (such as "2024-AIRPORT-001"), and support real-time querying.
[0185] Behavioral correlation analysis module:
[0186] The probability of manipulators is calculated based on Bayesian networks. Input features include the frequency of trajectory inflection points, signal power fluctuations, and regional risk levels (airport = high risk, park = low risk).
[0187] VI. Detailed Breakdown of Blockchain Evidence Storage Process for Evidence Solidification Module
[0188] The steps for evidence consolidation are detailed below:
[0189] Data standardization module:
[0190] Format conversion: Track data is converted to XML Schema (in accordance with the judicial electronic data standard), and images are saved in the original RAW format.
[0191] Metadata generation: acquisition device number (e.g., “Radar_01”), SHA-256 checksum, acquisition operator ID.
[0192] Hash generation module:
[0193] A 32-byte hash value is generated using the SHA-256 algorithm; for national cryptographic scenarios, the SM3 algorithm can be selected.
[0194] Trusted timestamp module:
[0195] Access the NTSC time source of the National Time Service Center to generate a timestamp in RFC 3161 format, with the signature algorithm being RSA-2048.
[0196] Blockchain-style evidence chain storage:
[0197] Lightweight blockchains (such as Hyperledger Fabric) are used, where each evidence package is treated as a block, the hash of the previous block is written into the header of this block, and stored in tamper-proof hardware (HSM).
[0198] VII. Automated and Detailed Judgment of the Forensic Expertise Analysis Platform
[0199] Event determination engine:
[0200] Example of rule set: If the flight path overlaps with the no-fly zone GIS data for more than 10 seconds, an "illegal intrusion" event is triggered; if the signal fingerprint matches the historical blacklist, a "high-risk operator" is marked.
[0201] Behavioral rule base:
[0202] It includes 100+ rules, such as "hovering for more than 5 minutes = suspicious reconnaissance" and "rapid approach to critical facilities = threatening behavior".
[0203] Report generation:
[0204] Automatically outputs a PDF version of the "Forensic Expert Opinion", including the inference of the responsible party (such as "Probability of manipulator: 85% related person Zhang San").
[0205] VIII. Example: Detailed Operational Procedures for Airport Perimeter Scenarios
[0206] Taking a certain international airport as an example, the system deployment and operation process is detailed as follows:
[0207] Deployment configuration:
[0208] The radar and cameras of the low-altitude monitoring unit are installed in the control towers at both ends of the runway, covering a height of 0-500 meters; the electromagnetic detection equipment is deployed on the roof of the terminal building.
[0209] Event triggering and handling:
[0210] The radar detected a suspicious target (speed 15 m / s, altitude 100 m) 3 km from the runway, and the electro-optical camera captured an image and identified it as a DJI Mavic 3.
[0211] The electromagnetic module identified a 2.4GHz remote control signal, and fingerprint extraction showed that the device had appeared in the "illegal flight incident on March 20, 2024".
[0212] The trajectory restoration unit reconstructs the flight path: the drone takes off from a residential area 800 meters outside the airport and hovers over the runway for 30 seconds.
[0213] The link tracing module uses TOA positioning to determine that the operator is located in a parking lot outside the airport (latitude and longitude error <30m).
[0214] The evidence solidification module generates an evidence package (hash value: a1b2...), and the judicial platform outputs an expert report, confirming "illegal intrusion into the no-fly zone and association with historical crime equipment".
[0215] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any person skilled in the art can easily conceive of various variations or substitutions within the technical scope disclosed in the present invention, and these should all be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.
Claims
1. A forensic evidence collection system for illegal drone flights, characterized in that, The system consists of a low-altitude monitoring unit, a flight path fusion and trajectory restoration unit, an electromagnetic feature acquisition unit, a link tracing module, an evidence solidification module, and a forensic identification and analysis platform, all connected in a closed loop via a data bus or network link. The low-altitude monitoring unit employs several types of sensors, including low-altitude detection radar, photoelectric imaging, 5G-A, and electromagnetic detection. It achieves unified time synchronization (GPS / BeiDou clock source) through a data synchronization device, which is used for real-time detection, identification, and three-dimensional positioning of suspicious drones. The trajectory fusion and restoration unit, based on extended Kalman filtering or particle filtering algorithms, performs multi-source heterogeneous fusion of radar spot data, visual angle data, and electromagnetic coarse positioning data, outputting a continuous, smooth, and legally reproducible three-dimensional flight trajectory. The state vector is defined as x=(x,y,z, , , ); The electromagnetic feature acquisition unit includes a spectrum scanning module, a protocol identification module, and an RF fingerprint extraction module, used to extract RF feature parameters (such as I / Q imbalance, power spectrum shape, etc.) of the UAV control link and generate a device fingerprint vector F=( , ,…, ); The link tracing module compares signal fingerprints and locates the transmitter (using the TOA / TDOA algorithm, with the location function being...). =c( - By analyzing the correlation between the remote control terminal and historical behavior, the location of the remote control terminal can be retrieved and the identity can be inferred. The evidence solidification module uses a blockchain-style hash chain, trusted timestamps, and SHA-256 / SM3 algorithm to generate an immutable evidence package, ensuring that the data conforms to the judicial appraisal format. The judicial appraisal analysis platform integrates an event judgment engine, a behavior rule model, and a correlation analysis engine, and automatically outputs a "Judicial Appraisal Report on Illegal Drone Flight" through the model.
2. The forensic evidence collection system for illegal drone flights according to claim 1, characterized in that: The low-altitude monitoring unit specifically includes: The low-altitude detection radar module operates in the X / Ku band and outputs target point sequence, Doppler information, and timestamps. It can be used for real-time detection, tracking, and situational analysis of low-altitude targets and supports data fusion with other sensors. The optoelectronic imaging module integrates a high-definition visible light camera and an infrared camera, and uses YOLO or CenterNet target detection algorithms to achieve accurate drone shape recognition. The electromagnetic detection module scans the frequency band from 300MHz to 6GHz and can identify WiFi, 2.4GHz, 5.8GHz, and custom protocol signals. The data synchronization and fusion interface ensures the time consistency of sensor data through GPS / BeiDou clock sources.
3. A forensic evidence collection system for illegal drone flights according to claim 1, characterized in that: The trajectory fusion and trajectory restoration unit further includes: The data preprocessing module is used for radar point filtering (spherical clustering and noise removal) and visual target box angle transformation; The time synchronization module calibrates the latency of multi-source data based on a unified clock source; The sensor registration module calibrates extrinsic parameters using a coordinate transformation matrix (WGS84 or ENU coordinate system) and a Levenberg-Marquardt optimizer. The multi-source fusion algorithm module uses EKF or PF algorithm to achieve trajectory smoothing and outputs track in KML, GeoJSON or PDF format. The trajectory visualization and storage module adopts an encrypted and rugged design, and has the ability to resist impact and disassembly. The device supports trajectory playback and speed change diagram generation.
4. A forensic evidence collection system for illegal drone flights according to claim 1, characterized in that: In the electromagnetic feature acquisition unit: The spectrum scanning module detects the signal frequency hopping mode and duty cycle; The protocol identification module supports the identification of DJI, Autel, WiFi-FPV and open source protocols; The features extracted by the radio frequency fingerprint extraction module include frequency offset, time offset, and packet waveform differences; It also includes a feature database comparison module, which matches fingerprint vectors with historical signal databases and returns device brand, model, and the time, location, and behavior that occurred.
5. A forensic evidence collection system for illegal drone flights according to claim 1, characterized in that: The link tracing module includes: The fingerprint comparison engine dynamically adjusts the similarity threshold through a machine learning model. The transmitter positioning module uses RSSI or AOA coarse positioning combined with TOA / TDOA precise positioning; The device signature database stores manufacturer fingerprints, historical case data, and registration information of suspicious persons. The behavioral correlation analysis module generates manipulator inference results based on trajectory features, regional risk labels, and historical activities.
6. A forensic evidence collection system for illegal drone flights according to claim 1, characterized in that: The specific implementation methods of the evidence solidification module include: The data standardization module generates metadata (collection time, device number, checksum, and behavior). The hash generation module uses SHA-256 or the national cryptographic SM3 algorithm to generate data fingerprints; The trusted timestamp module generates legally-grade timestamps from an authoritative time source; Blockchain-style evidence chain storage uses a chain structure to solidify evidence packages and prevent tampering.
7. A method for forensic evidence collection in cases of illegal drone flights, characterized in that: Includes the following steps: Step S1: When an illegal flight incident is triggered, the system automatically activates based on suspicious signals within the no-fly zone or restricted flight area; Step S2: Multimodal detection and target recognition, integrating radar spot data, visual target bounding boxes, and electromagnetic spectrum activity to achieve UAV 3D positioning and model identification; Step S3: Track reconstruction, unifying the time series of multi-source data through the time synchronization module, and using the EKF / PF algorithm for track fitting and smoothing; Step S4: Electromagnetic link acquisition and signal fingerprint extraction, perform spectrum sampling on the control link and image transmission link, analyze protocol features and generate radio frequency fingerprints; Step S5: Link tracing and operator location: The location of the remote control terminal is determined by matching fingerprint comparison engine and device feature library, combined with TOA / TDOA inversion. Step S6: Evidence consolidation, converting flight tracks, images, and electromagnetic data into a judicially acceptable format to generate an evidence package with timestamps and hash values; Step S7: Judicial analysis and report output, automatically generating opinions on the determination of the responsible party and an analysis report on illegal flights based on the behavior determination model.
8. A method for forensic evidence collection in the case of illegal drone flights according to claim 7, characterized in that: The multimodal detection in step S2 includes: Radar spot filtering generates range-velocity information; Visual target detection outputs bounding boxes and spatial angles (behaviors); Electromagnetic spectrum activity identification signal center frequency and bandwidth.
9. A method for forensic evidence collection in the case of illegal drone flights according to claim 7, characterized in that: The link tracing in step S5 further includes: By correlating historical behavior data, it can be determined whether the remote control terminal has been involved in illegal flight incidents; The probability of manipulators is calculated by combining regional risk labels (such as airports and government agencies).
10. A forensic evidence collection method or system for illegal drone flights according to claim 1 or 7, characterized in that: Its application scenarios include key target areas such as airport perimeters, nuclear power plants, sports venues and urban management centers. When deployed, it covers low-altitude high-risk areas and automatically outputs standardized evidence collection reports through the judicial appraisal analysis platform.