Low-altitude unmanned aerial vehicle operation situation streaming management and evidence-based supervision method and device
By implementing identity authentication, standardized conversion, sliding window governance, and comprehensive credibility scoring on the low-altitude drone supervision platform, combined with equipment ledgers and airspace rules, the platform has solved the problems of trajectory bounce and entity identification in low-altitude drone supervision, enabling real-time compliance judgment and evidence-based supervision, and improving the credibility and traceability of supervision.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- GUANGZHOU INST OF SOFTWARE APPL TECH
- Filing Date
- 2026-07-02
- Publication Date
- 2026-07-31
AI Technical Summary
Existing low-altitude drone monitoring platforms lack effective sliding window management, disordered ordering, delay detection, and abnormal jump point suppression under high-frequency streaming data conditions, leading to trajectory bounces and false alarms. Furthermore, they lack reliable quantification mechanisms, making it impossible to accurately identify the operating entity. They also lack sufficient airspace rule support, and the granularity of monitoring event records makes it difficult to form an auditable and verifiable chain of evidence, posing security risks.
By performing identity authentication, integrity verification, and anti-replay verification on access messages, the messages are parsed into standardized situation points. A sliding time window is established for governance, and the overall credibility is calculated. Multi-factor correlation verification is performed by combining equipment ledgers, real-name registration, task authorization, and operator information. Four-dimensional airspace compliance judgment is executed, and a traceable evidence chain is generated.
It effectively reduces false alarms and missed alarms caused by weak networks, out-of-order transmissions, and retransmissions, clarifies the responsible parties for flight operations, enables real-time online compliance assessment and early warning, improves the credibility and traceability of regulatory decisions, and forms a tamper-proof evidence hash chain.
Smart Images

Figure CN122496535A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of low-altitude unmanned aerial vehicle (UAV) operation supervision technology, and in particular to a method and apparatus for streamlining and evidence-based supervision of low-altitude UAV operation status. Background Technology
[0002] With the rapid development of the low-altitude economy, drones are increasingly used in fields such as inspection, logistics, surveying, and emergency rescue. Monitoring platforms need to continuously monitor drone operations, including information such as device identity, time, location, altitude, speed, heading, and mission context. Drone operational status data is typically reported at frequencies of 1Hz to 10Hz or even higher, characterized by streaming, real-time nature, susceptibility to cellular network jitter, and significant format differences across device manufacturers. Achieving accurate, reliable, and traceable drone operation monitoring under complex conditions such as high-frequency reporting, weak network environments, and message out-of-order transmission and retransmission has become a pressing technical problem in this field.
[0003] Currently, some low-altitude airspace monitoring platforms adopt a network interface-based situational reporting and trajectory display solution. Terminals periodically report situational data via protocols such as HTTP, MQTT, or WebSocket, and the platform handles data storage, real-time location display, and historical trajectory playback. Other solutions use electronic fences or no-fly zone models to determine the spatial relationship between the drone's current location and no-fly zones, restricted flight zones, or authorized airspace, triggering alarms when the location enters or approaches a specific area. Furthermore, some platforms can correlate equipment, operators, flight plans, airspace applications, and dynamic trajectories to achieve compliance process and flight monitoring. However, these solutions typically focus on access, display, or simple alarms as core functions, lacking a complete solution for the systematic governance of high-frequency streaming data and the construction of a closed-loop regulatory evidence system.
[0004] The shortcomings of existing technologies are as follows: First, raw situational data is directly used for display or alarms, lacking features such as sliding window management, out-of-order reordering, delay discrimination, and abnormal jump point suppression for high-frequency messages. This easily leads to trajectory reversals and false alarm triggers, and lacks a reliable quantification mechanism, making it impossible to distinguish between high-reliability real-time points and weak network retransmission points. Second, the identification of operating entities mostly relies on device number matching, failing to fully link real-name registration numbers, Ubox binding relationships, task authorization, pilot identity, and operator information, resulting in unclear entity consistency conclusions. Third, airspace rules are mostly based on two-dimensional fence judgments, with insufficient support for altitude, time, rule version, and trend warnings. Fourth, the granularity of regulatory event records is relatively coarse, lacking structured binding between events and raw messages, reliable situational points, entity identification results, rule versions, and handling results, making it difficult to form an auditable and verifiable chain of evidence. This also poses security risks such as message forgery, device impersonation, and evidence tampering. Summary of the Invention
[0005] Based on the above problems, this application provides a streaming governance and evidence-based supervision method and apparatus for low-altitude UAV operation status. By performing trusted governance of access messages, subject consistency identification, four-dimensional airspace compliance determination, and event evidence chain retention, it can effectively reduce false alarms and missed alarms caused by weak networks, out-of-order signals, and jumps, clarify the responsible parties for flight operations, and achieve auditable traceability of regulatory events.
[0006] In a first aspect, embodiments of this application provide a streaming governance and evidence-based supervision method for the operational status of low-altitude unmanned aerial vehicles (UAVs). The method includes: receiving raw status messages reported by UAV terminals, performing identity authentication, integrity verification, and anti-replay verification on the raw status messages, and taking the raw status messages that pass the verification as valid raw messages.
[0007] The valid raw messages are parsed into standardized situation points with a unified data structure. The standardized situation points include device identification, acquisition time, platform reception time, spatial coordinates, altitude, speed and heading.
[0008] For standardized situation point sequences with the same device identifier, a sliding time window is established, and governance operations are performed within the window. Situation points that have undergone governance and carry comprehensive credibility and governance tags are defined as credible situation points. Governance operations include: deduplication based on message fingerprints or sequence numbers, reordering by collection time or sequence number, identifying and marking delay points based on the difference between collection time and platform reception time, suppressing abnormal jump points by comparing the velocity and altitude change rates between adjacent points with preset thresholds, and calculating the comprehensive credibility of each situation point. The comprehensive credibility is calculated based on a weighted average of multiple dimensions, including time credibility, location credibility, signal credibility, and sequence credibility.
[0009] The system acquires trusted situational awareness points and performs multi-element correlation verification with the device ledger, real-name registration identifiers, terminal binding relationships, task authorization information, and operator information pre-stored on the platform to generate entity identification results. The entity identification results include device legality status, task authorization status, operator matching status, and reasons for anomalies.
[0010] Acquire credible situation points and subject identification results, and perform online compliance determination in combination with predefined four-dimensional airspace rules; the four-dimensional airspace rules include spatial geometric constraints, altitude range constraints, time range constraints and rule version information; compliance determination includes: determining whether the current credible situation point is located within the authorized mission airspace or has entered a restricted or prohibited flight zone, and predicting the future position based on the current speed and heading and judging the trend risk of crossing the boundary or entering a restricted or prohibited flight zone in advance;
[0011] When a compliance determination triggers a risk or an anomaly is found in the entity identification result, a regulatory event is generated. The regulatory event is bound to the following information: the original message identifier of the triggering event, the trusted status point of the triggering event, the entity identification result, the applicable airspace rule version, the handling status, and the evidence hash value of the preceding event. The regulatory event and the corresponding evidence package are stored in a structured manner to form a traceable evidence chain.
[0012] In one possible implementation, the governance operation further includes:
[0013] When a standardized situation point carries a retransmission identifier or the difference between the acquisition time and the platform reception time exceeds a preset real-time threshold, the situation point is marked as a retransmission point or a delay point. The retransmission point or delay point does not participate in real-time compliance determination and is only used for historical trajectory completion.
[0014] In one possible implementation, the regulatory event is also bound to the hash value of the original message that triggered the event and the overall credibility of the trusted status point of the triggering event;
[0015] The overall credibility is calculated as follows:
[0016] C=w1*C time +w2*C location +w3*C signal +w4*C sequence +w5*C identity
[0017] Among them, C time To calculate the time reliability based on the delay between the acquisition time and the platform reception time, C location To calculate the position reliability based on the velocity and height continuity between adjacent points, C signal C is the link reliability calculated based on signal strength or packet loss rate. sequence C is a sequence reliability calculated based on the continuity and disorder of message fingerprints or sequence numbers. identity This is the identity credibility calculated based on the consistency verification results between the device identifier and the operating entity information. Weights w1 to w5 are preset weights and their sum is 1.
[0018] When the overall credibility is greater than or equal to the first threshold, the trusted status point directly participates in the real-time compliance determination; when the overall credibility is less than the second threshold, the trusted status point does not trigger a high-level alarm.
[0019] In one possible implementation, multi-factor association verification includes:
[0020] Verify that the device identifier exists in the platform's device ledger and that the real-name registration status is valid;
[0021] Verify whether there is a valid binding relationship between the reported terminal identifier and the device identifier;
[0022] Verify whether the flight plan corresponding to the mission identifier in the trusted situation point is within the valid time window;
[0023] Verify that the operator information matches the task authorization record;
[0024] When any verification rule fails, the corresponding reason for the anomaly is recorded in the subject identification result.
[0025] In one possible implementation, the spatial geometric constraints in the four-dimensional airspace rules are expressed using at least one of the following geometric forms: polygon, circle, sector, flight path buffer, and three-dimensional cylinder.
[0026] When multiple airspace rules overlap in space or time, conflict resolution is carried out according to the priority of the rules, the release time, the task authorization status or the temporary control status, and compliance determination is performed based on the resolution results.
[0027] In one possible implementation, predicting future position based on current speed and heading, and assessing the potential risk of crossing boundaries or entering restricted flight zones in advance, includes:
[0028] The future position is predicted using a uniform linear motion model, and the specific formula is as follows:
[0029] P′=P+V·τ
[0030] Where P is the spatial coordinate of the current credible situation point, V is the velocity vector, and τ is the preset prediction duration; the same spatial rule judgment is applied to the future position P′ as to the current credible situation point, and a trend warning event is generated when P′ enters a restricted flight zone or crosses the authorized mission airspace.
[0031] In one possible implementation, the evidence package includes the original data associated with the triggering event, governance process records, judgment basis, and handling results; the evidence hash values of the preceding event and the evidence hash value of the current event are used to form a verifiable chain of evidence.
[0032] Secondly, embodiments of this application provide a streaming governance and evidence-based monitoring device for the operational status of low-altitude unmanned aerial vehicles (UAVs). This device includes: a receiving module, a parsing module, an establishing module, an acquiring module, a judging module, and a generating module, wherein:
[0033] The receiving module is used to receive raw situational information reported by the UAV terminal, perform identity authentication, integrity verification and anti-replay verification on the raw situational information, and take the raw situational information that passes the verification as valid raw information.
[0034] The parsing module is used to parse valid raw messages into standardized situation points with a unified data structure. The standardized situation points include device identifier, acquisition time, platform reception time, spatial coordinates, altitude, speed and heading.
[0035] A module is established to create a sliding time window for standardized situation point sequences with the same device identifier, and to perform governance operations within the window. Situation points that have undergone governance and carry a comprehensive credibility score and governance tag are defined as credible situation points. Governance operations include: deduplication based on message fingerprints or sequence numbers; reordering based on acquisition time or sequence number; identifying and marking delay points based on the difference between acquisition time and platform reception time; suppressing abnormal jump points by comparing the velocity and altitude change rates between adjacent points with preset thresholds; and calculating the comprehensive credibility score for each situation point. The comprehensive credibility score is calculated based on a weighted average of multiple dimensions, including time credibility, location credibility, signal credibility, and sequence credibility.
[0036] The acquisition module is used to acquire trusted situation points and perform multi-element correlation verification with the device ledger, real-name registration identifier, terminal binding relationship, task authorization information and operator information pre-stored on the platform to generate subject identification results; the subject identification results include device legality status, task authorization status, operator matching status and abnormal reasons;
[0037] The judgment module is used to acquire credible situation points and subject identification results, and perform online compliance judgment in combination with predefined four-dimensional airspace rules. The four-dimensional airspace rules include spatial geometric constraints, altitude range constraints, time range constraints and rule version information. The compliance judgment includes: determining whether the current credible situation point is located within the authorized mission airspace or has entered a restricted flight zone, and predicting the future position based on the current speed and heading and judging the trend risk of crossing the boundary or entering a restricted flight zone in advance.
[0038] The generation module is used to generate regulatory events when compliance judgments trigger risks or when there are anomalies in the entity identification results. The regulatory event is bound to the following information: the original message identifier of the triggering event, the trusted status point of the triggering event, the entity identification result, the applicable airspace rule version, the handling status, and the evidence hash value of the preceding event. The regulatory event and the corresponding evidence package are stored in a structured manner to form a traceable evidence chain.
[0039] Thirdly, embodiments of this application provide a computer storage medium storing multiple instructions adapted for loading by a processor and executing the steps of the above-described method.
[0040] Fourthly, embodiments of this application provide an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, the computer program being adapted to be loaded by the processor and to execute the steps of the above-described method.
[0041] The beneficial effects of the technical solutions provided in some embodiments of this application include at least the following: by performing security verification, standardization conversion, and deduplication, reordering, delay identification, and abnormal jump point suppression within a sliding window on the original situation messages, and introducing a multi-dimensional weighted comprehensive credibility score, the problems of trajectory bounce and false alarms caused by weak networks, out-of-order transmission, and retransmission are effectively solved; by identifying the consistency of multiple elements such as equipment ledgers, real-name registration, Ubox binding, task authorization, and operators, the flight responsibility subject is clarified; by supporting four-dimensional airspace rules that support various geometric expressions such as polygons, circles, sectors, route buffer zones, and three-dimensional cylinders and conflict resolution, combined with the trend prediction of uniform linear motion models, real-time online compliance judgment and early warning are realized; finally, by structurally binding regulatory events with original message hashes, credible situation points, subject identification results, rule versions, handling status, and hash values of evidence before and after, a tamper-proof evidence hash chain is formed, which improves the credibility, traceability, and auditing capabilities of regulatory decisions. Moreover, this method is compatible with multiple communication protocols and terminal types, and has good scalability and engineering practicality. Attached Figure Description
[0042] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0043] Figure 1 An exemplary system architecture diagram for the streaming governance and evidence-based supervision method of low-altitude unmanned aerial vehicle (UAV) operation status provided in the embodiments of this application;
[0044] Figure 2 A flowchart illustrating the streaming governance and evidence-based supervision method for the operational status of low-altitude unmanned aerial vehicles provided in this application embodiment;
[0045] Figure 3 A flowchart for generating trusted situation points provided in this application embodiment;
[0046] Figure 4 This is a schematic diagram illustrating the operational entity identification relationship provided in the embodiments of this application;
[0047] Figure 5 A schematic diagram illustrating the airspace compliance determination provided for this application;
[0048] Figure 6 A structural block diagram of the low-altitude unmanned aerial vehicle (UAV) operation status monitoring and evidence-based supervision device provided in this application embodiment;
[0049] Figure 7This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0050] To make the features and advantages of this application more apparent and understandable, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0051] In the following description, when referring to the accompanying drawings, the same numbers in different drawings denote the same or similar elements unless otherwise indicated. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0052] In the description of this application, it should be understood that the terms "first," "second," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance. Those skilled in the art can understand the specific meaning of the above terms in this application based on the specific circumstances. Furthermore, in the description of this application, unless otherwise stated, "multiple" refers to two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship.
[0053] As mentioned earlier, in existing low-altitude drone monitoring technologies, the original situational data is difficult to use directly for accurate judgment due to issues such as weak networks, out-of-order data, and retransmission. The weak connection between the operating entity and the data makes it difficult to trace responsibility. Airspace rule judgments are mostly limited to two-dimensional fences and lack real-time online compliance judgments. The granularity of regulatory event records is coarse and does not form an auditable chain of evidence with the original messages, governance results, and rule versions. At the same time, there are security risks such as message forgery, device misuse, and evidence tampering.
[0054] In view of this, this application provides a streaming governance and evidence-based supervision of low-altitude unmanned aerial vehicle (UAV) operational status. It aims to generate credible status points by performing access verification, standardization conversion, sliding window governance, and comprehensive credibility scoring on raw status messages. This is combined with equipment ledgers, real-name registration, task authorization, and operator information to achieve multi-element subject consistency identification. Based on four-dimensional airspace rules, online compliance judgment and trend risk prediction are executed. Furthermore, regulatory events are bound to the original message identifier, credible status point, subject identification result, rule version, handling status, and hash value of preceding event evidence, forming a traceable evidence chain with structured evidence packages. This reduces false alarms and missed alarms, clarifies responsible parties, enables real-time compliance judgment, and constructs a tamper-proof closed-loop regulatory evidence system.
[0055] Please see Figure 1 , Figure 1 An exemplary system architecture diagram of the streaming governance and evidence-based supervision method for low-altitude unmanned aerial vehicle (UAV) operation status provided in this application embodiment.
[0056] like Figure 1 As shown, the system architecture consists of a data resource layer, a platform core service layer, a support and interaction layer, and an external interface layer. The data resource layer stores original information, standard information, trust and risk, entity identification, airspace rules, regulatory events, evidence, handling records, and log auditing, providing core data support for upper-layer business operations. The platform's core service layer processes data collaboratively along three main lines: The access and preprocessing link receives raw situational data reported by sensing devices such as drones, Ubox communication terminals, ground stations, drone nests, and remote controllers in batches via communication protocols such as MQTT, HTTPS, WebSocket, 5G / 4G, and Wi-Fi. After load balancing and gateway processing, the situational data processing service performs parsing, standardization, and credibility scoring; the operating entity identification service performs entity consistency identification on equipment, real-name registration, task authorization, and operator information; the rules and compliance judgment service performs four-dimensional airspace calculation and trend prediction based on the airspace rule base; when violations or anomalies are detected, the event and evidence service automatically generates regulatory events and electronic evidence, associates video evidence storage and task playback, and triggers joint analysis and notification; the display and command service provides real-time situational display, three-dimensional trajectory playback, data statistical analysis, and report export. The support and interaction layer has built-in modules for user permissions, task management, device management, rule management, and notifications to ensure the platform's own operation. Finally, the regulatory results are output to external regulatory platforms, emergency command centers, and higher-level systems through external interfaces, forming a complete closed-loop regulatory system for low-altitude operations. The following section, in conjunction with the above system architecture, provides a detailed description of the specific implementation methods for the streaming governance and evidence-based supervision of low-altitude unmanned aerial vehicle (UAV) operational status provided by this invention.
[0057] Please see Figure 2 , Figure 2This is a flowchart illustrating the streaming governance and evidence-based supervision method for the operational status of low-altitude unmanned aerial vehicles (UAVs) provided in an embodiment of this application. Figure 2 As shown, the streaming governance and evidence-based supervision methods for the operational status of low-altitude drones can include at least:
[0058] S201. Receive the raw situation message reported by the UAV terminal, perform identity authentication, integrity verification and anti-replay verification on the raw situation message, and take the raw situation message that passes the verification as the valid raw message.
[0059] Specifically, the platform receives raw situational information reported by terminals such as drones, Uboxes, ground stations, drone nests, or remote controllers through communication protocols such as MQTT (default port 1883 / 8883), HTTPS (port 443), WebSocket (port 8080), or 5G private networks. Taking MQTT as an example, the terminal publishes a JSON format message to a specified Topic (such as / drone / status / {sn}). The message structure includes a message header (sn device serial number, uasID, uboxId, msgId message unique identifier, seq serial number, timestamp device-side collection time, topic, version), business data payload (longitude, latitude, altitude, height, ground speed GS, vertical speed VS, course, roll, pitch, yaw, signal strength), task context (orderID order number, taskId task identifier, flightStatus flight status, pilotId pilot identifier, operatorId operator identifier, missionType task type), and security fields (certId certificate identifier, token token, signature signature, nonce random number, rawMsgHash raw message hash). The platform's authentication module first verifies that the device certificate or token exists in the valid whitelist and has not expired. Then, it verifies the signature using a pre-shared key or the device's public key, recalculating the hash value of the message body (excluding the signature fields) and comparing it with the signature to ensure integrity. Next, it checks whether the difference between the timestamp and the platform's current timestamp is within a preset time window (e.g., ±60 seconds), and simultaneously verifies whether the nonce has been used by the device (recording the most recent 1000 nonces in Redis). If it has, it is considered a replay attack. Finally, it verifies whether the msgId or seq conforms to the basic format and is not duplicated in the current device session (duplicate removal within a sliding window). Messages that pass all verifications are assigned a globally unique platform-side ID, rawMsgId, and its hash value, rawMsgHash, is calculated. The complete original message is then stored in the original information database. Messages that fail verification are discarded and an anomaly log is recorded for security auditing.
[0060] S202. Parse the valid raw messages into standardized situation points with a unified data structure. The standardized situation points include device identifier, acquisition time, platform reception time, spatial coordinates, altitude, speed and heading.
[0061] Specifically, the platform message parsing and standardization module extracts or calculates the following fields from valid raw messages based on a preset vendor mapping table or dynamic configuration rules: DeviceId (generated by mapping from sn or uasID), device-side acquisition time T (Unix millisecond timestamp, taken as timestamp), platform reception time arrivalTime (system current millisecond timestamp), spatial coordinates (longitude Lon, latitude Lat; if the original coordinate system is GCJ-02 or BD-09, the coordinate transformation interface is called to uniformly convert it to WGS-84), and altitude. Alt (if the original report is relative height, it is converted to altitude by combining the equipment's takeoff point elevation or terrain data), relative ground height (direct mapping or calculation), ground speed GS (m / s), vertical speed VS (m / s), course (degrees, 0-360), roll, pitch, yaw (degrees), signal strength (normalized 0-100 or level 0-4), source (identifier such as "Ubox", "nest", "ground station"), and raw message identifier RawMsgId. For messages with missing or incorrect types of required fields (such as sn, timestamp, latitude and longitude), they are discarded or marked as abnormal and the reason is recorded according to the importance of the field; for messages with missing optional fields, the location is retained but the corresponding weight is reduced in the subsequent credibility scoring. The standardized status quo point P structure is: {pointId, T, arrivalTime, Lon, Lat, Alt, Height, DeviceId, UboxId, UasId, TaskId, PilotId, GS, VS, Course, Roll, Pitch, Yaw, Signal, Source, RawMsgId}, and stored in a standard information database. Here, T represents the device-side acquisition time, arrivalTime represents the platform reception time, Lon / Lat represents the spatial coordinates, Alt / Height represents the altitude information, DeviceId can be mapped by a serial number (SN) or other unique identifier, and TaskId can be mapped by orderID or flight plan number. This unified data model eliminates the need for subsequent governance, identification, and judgment algorithms to adapt to varying upstream protocols, improving system scalability and compatibility. Optionally, the platform allows users to dynamically add field mapping rules for new vendors via XML or JSON configuration files, enabling access to new types of terminals without modifying the core code.
[0062] S203. For a standardized sequence of situation points with the same device identifier, establish a sliding time window and perform governance operations within the window; define the situation point that has been governed and carries a comprehensive credibility and governance label as a credible situation point.
[0063] Specifically, the platform maintains a sliding time window W in memory, categorized by DeviceId (or a combination of DeviceId and TaskId). The window length is 10 seconds by default, but can be dynamically adjusted based on the device reporting frequency, typically ranging from 5 to 30 seconds. Within this window is a bounded buffer queue B (with a default capacity of 100 points, implemented as a circular queue). Please refer to [link to relevant documentation]. Figure 3 , Figure 3 A flowchart illustrating the trusted situation point generation process provided in this application embodiment. Figure 3 As shown, each standardized situation point P performs the following operations upon entry: First, construct the message fingerprint f. p =Hash(sn+msgId+TaskId+T+Lon+Lat+Alt), for unique points, write them to bounded buffer queue B. Out-of-order and reordering: Due to network jitter, the order of arrival at the platform may differ from the acquisition time T. Queue B is periodically (triggered every time a new point is received or timed every 100ms) sorted in ascending order by acquisition time T. If T is less than the minimum T of existing points in the queue, a reordering is triggered to ensure the output sequence satisfies T(i)≤T(i+1). For points exceeding the window time ΔT... buf Lag points (arriving after a default 2 seconds) are treated as delayed points but not fed back into the real-time situational master sequence. Delay point identification: If arrivalTime-T > T max (A real-time judgment threshold, generally set to 30 seconds), is then marked as a "delay point"; if the terminal carries a retransmission identifier in the message, it is marked as a "retransmission point". Delay points and retransmission points do not participate in subsequent real-time compliance judgments, but are stored in the historical trajectory database for replay completion. Abnormal jump point suppression: Calculate the planar distance d (meters) and time difference Δt (seconds) between the adjacent output reliable points and the current point to obtain the instantaneous velocity V=d / Δt; at the same time, calculate the altitude change rate Va=ΔAlt / Δt. If V > Vmax or |Va| > Vhmax (Vmax is the maximum level flight speed of this aircraft type, which can be 100m / s for fixed-wing UAVs and 20m / s for multi-rotor aircraft; Vhmax is the maximum rate of climb, which can be 5m / s for multi-rotor aircraft), or if the position change contradicts the heading and speed logic (e.g., heading due north but latitude decreasing), it is marked as an "abnormal jump point." Depending on the configuration, it is removed (not output as a reliable point), downweighted (reduced in reliability), or smoothed (e.g., using Kalman filtering for correction), and a "positioning anomaly" event is generated. A reliability score is calculated for each post-processing situation point, with a comprehensive reliability C. This embodiment uses a weighted summation method, with the specific formula as follows:
[0064] C=w1*C time +w2*C location +w3*C signal +w4*C sequence +w5*C identity
[0065] Among them, Ctime is the time reliability calculated based on the delay between the acquisition time and the platform reception time; Clocation is the location reliability calculated based on the speed continuity and height continuity between adjacent points; Csignal is the link reliability calculated based on signal strength or packet loss rate; Csequence is the sequence reliability calculated based on the continuity and disorder of message fingerprints or sequence numbers; and Cidentity is the identity reliability calculated based on the consistency verification results of device identifier and operating entity information. Weights w1 to w5 are preset weights and sum to 1. After calculation, the reliable situation point P*={P,C,tags,qualityLevel} is obtained, where tags is a list of strings containing governance action markers such as "deduplication," "order reordering," "delay," and "abnormal jump point." qualityLevel is divided into three levels based on the C value: high (C≥0.8), medium (0.5≤C<0.8), and low (C<0.5). This step effectively suppresses trajectory jitter and false alarms caused by weak networks, retransmissions, and positioning drift through multi-dimensional governance.
[0066] In one possible implementation, when a standardized situation point carries a retransmission identifier or the difference between its acquisition time and the platform's reception time exceeds a preset real-time threshold (e.g., 5 seconds), the situation point is marked as a retransmission point or a delay point. Such points do not participate in real-time compliance determination and are only used for historical trajectory completion. This mechanism avoids false real-time alarms caused by historical data backfeeding while ensuring the integrity of historical trajectories.
[0067] S204. Obtain trusted situation points and perform multi-element correlation verification with the device ledger, real-name registration identifier, terminal binding relationship, task authorization information and operator information pre-stored on the platform to generate subject identification results.
[0068] Specifically, please refer to Figure 4 , Figure 4 This is a schematic diagram illustrating the operational entity identification relationship provided for the embodiments of this application, such as... Figure 4As shown, the platform's main entity identification module extracts fields such as DeviceId, UboxId, TaskId, PilotId, and OperatorId from the trusted situation point P*, and queries the following data tables in the pre-maintained relational database (such as MySQL) or graph database (such as Neo4j) on the platform side: Device Ledger Table (Device sn, Activation Status, Real-name Registration Number, Registration Validity Period, Device Certificate Serial Number), Real-name Registration Table (Registrant ID Card / Organization Code, Bound Device sn, Registration Status), Ubox Binding Relationship Table (Ubox Hardware Unique Code, Bound Device sn, Binding Time, Validity Period, Certificate certId), Task Authorization Table (TaskId, Flight Plan ID, Authorized Airspace Geometry WKT, Authorized Altitude Range, Valid Start Time, End Time, Approval Status, Associated Pilot ID, Associated Operator ID, Affiliated Unit), and Operator Information Table (Pilot ID, License Number, Qualification Level, Validity Period, Operator ID, Unit Name).
[0069] Furthermore, this step performs the following verifications in parallel: Device registration verification – checks if the DeviceId exists in the device ledger and if the real-name registration status is “effective” and not expired; Ubox binding verification – checks if the reported UboxId has a valid binding relationship with the device (binding time ≤ current ≤ validity period) and if the associated certificate has not expired; Task authorization verification – checks if the flight plan corresponding to the TaskId is currently within the [start time, end time] range, the approval status is “approved”, and the task has not been suspended or canceled; Operator verification – checks if the PilotId or OperatorId is consistent with the pilot / operator ID in the task authorization record, and if the corresponding license / qualification status is valid (e.g., the license is within the validity period and has not been revoked). After all mandatory verification items pass, `identityStatus = "Legal"` and `identityConfidence = 1.0` are output. If any item fails, `identityStatus = "Abnormal"`, and the specific reason is recorded in the `abnormalReasons` array (e.g., "Device not registered", "Device real-name status abnormal", "Ubox binding expired", "Task expired", "Task unauthorized flight", "Pilot mismatch", "Operator qualification invalid"). For cases where all mandatory verifications pass but there are non-mandatory warnings (e.g., certificate about to expire), `identityStatus = "Partially Trusted"` can be output and the warning recorded. The `IdentityResult` structure is: `{identityStatus, deviceStatus, uboxStatus, taskStatus, pilotStatus, operatorStatus, abnormalReasons, identityConfidence}`, which is associated with the trusted status point and then sent to the airspace rule determination module. This step, through multi-source identity fusion, enables each regulatory event to be traced back to a specific legal person or natural person, meeting the post-event accountability requirements of low-altitude airspace regulations.
[0070] S205. Obtain credible situation points and subject identification results, and perform online compliance judgment in conjunction with predefined four-dimensional airspace rules.
[0071] Specifically, the platform's airspace rule engine pre-stores an airspace rule library. Each rule object, Airspace, is defined as follows: Airspace={airspaceId,type,geometry,heightRange,timeRange,ruleVersion,priority,effectiveStatus}, where airspaceId is a unique identifier, type is an enumeration type, including authorized mission airspace, no-fly zone, restricted flight zone, temporary control zone, route buffer zone, key protection zone, and geometry is the spatial geometry, using GeoJSON format, supporting Polygon and Point+radius circles. The system includes: Sector, LineString+buffer (flight path buffer), Polygon+height (3D cylinder), heightRange({minAlt meters, maxAlt meters}, null indicates full height), timeRange({startTime, endTime}, supports periodic time expressions, null indicates full time period), ruleVersion (semantic version number, such as "2025-03-01-v2"), priority (integer, larger values indicate higher priority), effectiveStatus (boolean, whether it is effective), creator, createTime, etc.
[0072] Spatial geometric constraints employ at least one of the following geometric expressions: polygon (a closed region defined by a set of latitude and longitude coordinates), circle (defined by the center coordinates and radius), sector (defined by the center, starting angle, ending angle, and radius), route buffer zone (a strip-shaped region extending outwards from the centerline of the route with a preset width), or 3D cylinder (adding a vertical height range to the 2D geometry). For route buffer zones, the platform generates linear geometry based on the waypoint sequence in the mission plan and buffers outwards with a preset width (e.g., 100 meters); for 3D cylinders, it combines the base of a polygon and a height range. Height range constraints use minimum and maximum altitudes (in meters); if not specified, they are considered to apply across the entire altitude range. Time range constraints use start and end times (supporting absolute and periodic time expressions, such as "every Saturday 09:00-17:00"); if not specified, they are considered to apply across the entire time period. Rule versions use semantic version numbers (e.g., "2025-03-01-v2"), used for retrospective review of the rule definitions in effect at the time of the rule's implementation. Priority is represented by integer values; the larger the value, the higher the priority.
[0073] Please see Figure 5 , Figure 5 The diagram provided for airspace compliance determination in this application is as follows: Figure 5As shown, for each input reliable situation point P* (including time T, coordinates (Lon, Lat), and altitude Alt), the following five-step decision process is performed:
[0074] The first step is to determine the authorized task airspace. Based on the TaskId in the subject identification result, obtain the set of authorized task airspaces associated with this task (type=TASK_AIRSPACE). Call the spatial calculation module (based on JTS or GEOS library) to determine whether the coordinates of P* fall within the geometry of any authorized airspace, and simultaneously determine whether Alt is within the height range of that airspace and whether T is within the time range. If all conditions are met, the task airspace is deemed compliant; otherwise, a "deviation from task airspace" or "out of bounds" event is generated, recording the specific information of the deviation (horizontal distance exceeding the limit, height exceeding the limit, time exceeding the limit).
[0075] The second step is to determine no-fly or restricted-fly zones. Query all airspace rules currently in effect with a type of no-fly zone, restricted-fly zone, or temporary control zone (timeRange contains T and effectiveStatus=true). For each rule, check if P* satisfies the following conditions: coordinates are within the geometry and Alt is within the heightRange. If any no-fly zone or temporary control zone is hit, immediately generate an "Entering No-Fly Zone" event, push a high-level alarm, and record the ID and version of the hit rule. If a restricted-fly zone is hit, generate an alarm of the corresponding level based on the restriction type (e.g., altitude restriction, speed restriction, no entry).
[0076] The third step is proximity risk assessment. Calculate the minimum distance d from P* to each airspace boundary (using the spherical distance formula to calculate the shortest distance between a latitude / longitude point and the polygon boundary, or the distance from a point to the center of a circle minus the radius). When d ≤ the first proximity threshold Dwarn (default 200 meters), a "proximity risk" event is generated, with a medium level event; when d ≤ the second proximity threshold Dcritical (default 50 meters), it is upgraded to a high-level alarm, and the coordinates of the nearest point on the boundary are recorded. Dwarn and Dcritical can be configured individually for different airspace types (e.g., the proximity threshold for a no-fly zone can be set to 500 meters to provide earlier warnings).
[0077] The fourth step is rule conflict resolution. When multiple airspace rules overlap spatially or temporally (e.g., the authorized mission airspace overlaps with a temporary control area, or the boundaries of two no-fly zones are adjacent), they are resolved according to the following priority order: no-fly zones have the highest priority, followed by temporary control areas, then restricted flight zones, and authorized mission airspace has the lowest priority. If priorities are the same, the rules are compared by their publication time, with the later-published rule taking precedence. If a mission has already obtained a temporary exemption from a rule (marked in the exemption rule list of the mission authorization table), the priority of that mission's airspace relative to the exempted rule is temporarily raised to higher than that rule. The result of conflict resolution is determined by the rule with the highest (or strictest) priority, and a detailed log of the resolution process (including the rule IDs involved in the conflict, their respective priorities, and the final rule adopted) is saved in the generated event log.
[0078] Step 5, Trend Risk Prediction. Based on the ground speed GS (vector direction determined by the heading course, unit m / s) of the current point P* and the preset prediction time τ (default 5 seconds, configurable to 2~10 seconds; for high-speed fixed-wing UAVs, it can be appropriately shortened to 2 seconds; for low-speed multi-rotor UAVs, it can be extended to 10 seconds), the future position P′=P+V·τ is predicted using a uniform linear motion model, where the velocity vector V=(GS·cosθ,GS·sinθ), θ=course·π / 180. During the prediction process, if altitude changes need to be considered, the vertical velocity VS can be used to extrapolate the altitude simultaneously: Alt′=Alt+VS·τ. The same spatial rule judgments (including authorized airspace inclusion judgment, no-fly zone hit judgment, and approach distance calculation) are performed on the predicted position P′ as on the current point. If P′ will enter a no-fly zone or cross the authorized mission airspace, or the distance to a certain airspace boundary is less than D, the prediction will be made accordingly. warn If a trend warning event is generated, a "trend warning" event will be created. The event level of the trend warning is set according to the predicted risk level: if it is predicted that the aircraft will enter a no-fly zone, it will be at a high level; if it is predicted that the aircraft will cross the mission airspace or approach the boundary, it will be at a medium or low level depending on the distance. The warning information must include the prediction duration τ, the predicted location coordinates, and the associated risk airspace ID.
[0079] Through the specific implementation described above, this step not only completes the online compliance assessment of four-dimensional airspace, but also adapts to the complex airspace management needs through various geometric expressions and conflict resolution rules. Furthermore, by using a uniform linear motion model, it enables early perception of short-term risks with low computational overhead, thus buying time for regulatory personnel to take action.
[0080] S206. When a compliance determination triggers a risk or an anomaly is found in the entity identification result, a regulatory event is generated.
[0081] Specifically, when the compliance assessment outputs any risk (entering a no-fly zone, deviating from the mission airspace, approaching risk, trend warning) or the entity identification result is abnormal, the system event and evidence service module immediately generates a regulatory event (Event), assigning it a globally unique event identifier (eventId). The specific structure of the Event is Event={eventId, eventType, eventLevel, triggerTime, triggerPointId, rawMsgId, rawMsgHash, deviceId, uasId, uboxId, taskId, pilotId, operatorId, ruleId, ruleVersion, identityResult, confidence, disposalStatus, evidenceHash, previousEvidenceHash}. Here, eventId is the globally unique identifier for the regulatory event, used to distinguish different events and for subsequent retrieval and association. eventType is the event type, such as "entering a no-fly zone," "deviating from the mission airspace," "abnormal entity identification," "trend warning," etc., used for classification and management. `eventLevel` indicates the event level, categorized into high, medium, and low, to indicate the severity of the risk and the priority of its handling. `triggerTime` is the event trigger time, taken as the platform system's current timestamp (milliseconds), used to record the precise moment the event occurred. `triggerPointId` is the unique identifier of the trusted situation point that triggered the event, used to trace which specific managed situation point caused the event. `rawMsgId` is the original message identifier that triggered the event, pointing to the number assigned to the original situation message when the platform connected, facilitating the tracing of the original reported data. `rawMsgHash` is the hash value (e.g., SHA-256) of the original message that triggered the event, used to verify whether the original message has been tampered with after storage. `deviceId` is the unified identifier of the UAV device, mapped from the `sn` or `uasID` in the reported message, used to associate with the device ledger. `uasId` is the identifier of the unmanned aerial vehicle system (e.g., the UAS ID registered with the Civil Aviation Administration), used for cross-system tracing. `uboxId` is the hardware identifier of the communication terminal (Ubox) carried or associated with the UAV, used to verify the binding relationship between the terminal and the device. `taskId` is the flight mission identifier, corresponding to the mission authorization record in the platform, used to associate flight plans, airspace authorization, and operator information. `pilotId` is the pilot identifier, used to associate pilot licenses, qualifications, and identity information. `operatorId` is the operator identifier, used to associate operating units, legal entity information, and responsible entities. `ruleId` is the airspace rule identifier applicable to triggering the judgment, pointing to the specific rule in the airspace rule base.`ruleVersion` is the version number of the applicable airspace rule, used for post-event review to determine the outcome based on the rule version in effect at the time, avoiding inconsistencies due to rule updates. `identityResult` is a snapshot of the subject identification results (usually in JSON format), including device legitimacy status, task authorization status, operator matching status, and anomaly reasons, used to record the subject identification conclusion at the time the event occurred. `confidence` is the comprehensive credibility score (range 0-1) of the trusted situation point that triggered the event, used to indicate the quality of the situation point on which the event is based, distinguishing between high-confidence points, low-confidence points, or supplementary transmission points. `disposalStatus` is the disposal status, including "pending disposal," "in progress," "disposed," and "closed," used for regulatory closed-loop tracking. `evidenceHash` is the hash value (e.g., SHA-256) of the evidence package corresponding to this event. The evidence package contains original data, governance records, judgment basis, and disposal results; this hash value is used to verify the integrity of the evidence package. previousEvidenceHash is the evidence hash value of the preceding event (the evidenceHash of the previous event under the same device dimension). This field is set to empty or all 0 for the first event, and is used to form an evidence hash chain with the preceding event. Any intermediate evidence that has been tampered with can be detected.
[0082] Furthermore, the system synchronously constructs a structured evidence package (Evidence). This evidence package includes at least the full text of the original message triggering the event (or the original message hash and key fields), standardized situation points, trusted situation points and their overall trustworthiness, governance operation records (including operation logs for deduplication, reordering, delay, and anomaly suppression, recorded as a JSON array for each governance action), subject identification inputs and outputs (including snapshots of device ledgers, Ubox binding relationships, task authorization, and operator information used during queries, stored in read-only format), snapshots of the applicable four-dimensional spatial rules (the complete definition of the rule at the trigger time, including geometric WKT, altitude range, time range, priority, and version number), spatial calculation results (including distance values, boundary intersections, and intermediate results of the judgment logic used during calculation), disposal push records (including notification recipients, notification time, notification channel, and success status), and an entry timestamp. The evidence package can be stored in a BLOB field of a relational database, an object storage system (such as MinIO), or a distributed file system. Each evidence package has a unique storage path, and its SHA-256 hash value is calculated and stored in the evidenceHash field of the event table. The previousEvidenceHash and current evidenceHash are linked sequentially by device and time: For the same device, each time a new event is generated, the evidenceHash of the current event is stored at the end of the device's event chain, and the hash value of the previous event is recorded in the previousEvidenceHash field of the current event. Any subsequent modification to the evidence package will cause its hash value to change, resulting in a mismatch with the next hash recorded for the previous event, thus detecting tampering. The disposal status can be updated through the platform's disposal interface. Supervisors can set disposal actions (such as issuing a return instruction, sending an SMS notification, or pushing to the emergency command system). After disposal is completed, disposalStatus will be updated to "Disposaled," and the disposal result and disposal timestamp will be recorded.
[0083] By binding the hash value of the original message triggering the regulatory event with the combined credibility of the trusted state point of the triggering event, the integrity and quality transparency of the evidence are further enhanced, facilitating a quick determination during subsequent review whether the event was triggered by a high-credibility point or a low-credibility point. In one possible implementation, the evidence package includes the original data associated with the triggering event, governance process records, judgment criteria, and handling results, with the evidence hash values of the preceding event and the current event forming a verifiable evidence chain. This implementation provides a higher-level overview of the evidence package content and clarifies the verifiable function of the hash chain, retaining flexibility while ensuring the core security mechanism. Through the above specific settings, this step not only meets the traceability requirements of regulatory events but also further realizes a tamper-proof evidence chain closed loop, solving the technical problems of coarse-grained regulatory event records, lack of structured binding, and difficulty in post-event evidence collection in existing technologies, and possessing outstanding advantages of auditability, verifiability, and anti-forgery.
[0084] This application provides a streaming governance and evidence-based supervision method for the operational status of low-altitude unmanned aerial vehicles (UAVs). By performing security verification, standardization conversion, and deduplication, reordering, delay identification, and abnormal jump point suppression within a sliding window on the original status messages, and by introducing a multi-dimensional weighted comprehensive credibility score, it effectively solves the problems of trajectory bounce and false alarms caused by weak networks, out-of-order transmissions, and retransmissions. Through the consistency identification of multiple elements such as equipment ledgers, real-name registration, Ubox binding, task authorization, and operators, the responsible parties for flight are clearly identified. By supporting four-dimensional airspace rules with various geometric expressions such as polygons, circles, sectors, flight path buffer zones, and three-dimensional cylinders, and conflict resolution, combined with trend prediction from a uniform linear motion model, real-time online compliance judgment and early warning are achieved. Finally, by structurally binding regulatory events with the hash of the original message, credible status points, subject identification results, rule versions, handling status, and hash values of the preceding and following evidence, a tamper-proof evidence hash chain is formed, improving the credibility, traceability, and auditing capabilities of regulatory decisions. Furthermore, this method is compatible with multiple communication protocols and terminal types, possessing good scalability and engineering practicality.
[0085] Please see Figure 6 , Figure 6 This is a structural block diagram of a flow-based governance and evidence-based monitoring device for the operational status of low-altitude unmanned aerial vehicles (UAVs) provided in an embodiment of this application. Figure 6 As shown: The streaming governance and evidence-based monitoring device 600 for low-altitude unmanned aerial vehicle (UAV) operation includes: a receiving module 610, a parsing module 620, an establishing module 630, an acquiring module 640, a judging module 650, and a generating module 660, wherein:
[0086] The receiving module 610 is used to receive the raw situation message reported by the UAV terminal, perform identity authentication, integrity verification and anti-replay verification on the raw situation message, and take the raw situation message that passes the verification as the valid raw message.
[0087] The parsing module 620 is used to parse valid raw messages into standardized situation points with a unified data structure. The standardized situation points include device identifier, acquisition time, platform reception time, spatial coordinates, altitude, speed and heading.
[0088] Module 630 is established to create a sliding time window for a standardized sequence of situation points identified by the same device, and to perform governance operations within the window. Situation points that have undergone governance and carry a comprehensive credibility score and governance tag are defined as credible situation points. Governance operations include: deduplication based on message fingerprints or sequence numbers; reordering based on acquisition time or sequence number; identifying and marking delay points based on the difference between acquisition time and platform reception time; suppressing abnormal jump points by comparing the velocity and altitude change rates between adjacent points with preset thresholds; and calculating the comprehensive credibility score of each situation point. The comprehensive credibility score is calculated based on a weighted average of multiple dimensions, including time credibility, location credibility, signal credibility, and sequence credibility.
[0089] The acquisition module 640 is used to acquire trusted situation points and perform multi-element correlation verification with the device ledger, real-name registration identifier, terminal binding relationship, task authorization information and operator information pre-stored on the platform to generate subject identification results; the subject identification results include device legality status, task authorization status, operator matching status and abnormal reasons.
[0090] The judgment module 650 is used to acquire credible situation points and subject identification results, and to perform online compliance judgment in combination with predefined four-dimensional airspace rules. The four-dimensional airspace rules include spatial geometric constraints, altitude range constraints, time range constraints and rule version information. The compliance judgment includes: determining whether the current credible situation point is located within the authorized mission airspace or has entered a restricted or prohibited flight zone, and predicting the future position based on the current speed and heading and judging the trend risk of crossing the boundary or entering a restricted or prohibited flight zone in advance.
[0091] The generation module 660 is used to generate a regulatory event when a compliance judgment triggers a risk or when the subject identification result is abnormal. The regulatory event is bound to the following information: the original message identifier of the triggering event, the trusted status point of the triggering event, the subject identification result, the applicable airspace rule version, the handling status, and the evidence hash value of the preceding event. The regulatory event and the corresponding evidence package are stored in a structured manner to form a traceable evidence chain.
[0092] It should be noted that the flow management and evidence-based monitoring device for low-altitude UAV operation status provided in the above embodiments is only illustrated by the division of the above functional modules when executing the flow management and evidence-based monitoring method for low-altitude UAV operation status. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the flow management and evidence-based monitoring device for low-altitude UAV operation status provided in the above embodiments and the flow management and evidence-based monitoring method embodiments for low-altitude UAV operation status belong to the same concept, and the implementation process is detailed in the method embodiments, which will not be repeated here.
[0093] The sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0094] Please see Figure 7 , Figure 7 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Figure 7 As shown, the electronic device 700 may include: at least one processor 701, at least one network interface 704, a user interface 703, a memory 705, and at least one communication bus 702.
[0095] The communication bus 702 is used to enable communication between these components.
[0096] The user interface 703 may include a display screen and a camera. Optional user interfaces 703 may include standard wired interfaces and wireless interfaces.
[0097] The network interface 704 may optionally include a standard wired interface or a wireless interface (such as a Wi-Fi interface).
[0098] The processor 701 may include one or more processing cores. The processor 701 connects to various parts within the electronic device 700 using various interfaces and lines, and performs various functions and processes data by running or executing instructions, programs, code sets, or instruction sets stored in the memory 705, and by calling data stored in the memory 705. Optionally, the processor 701 may be implemented using at least one hardware form of Digital Signal Processing (DSP), Field-Programmable Gate Array (FPGA), or Programmable Logic Array (PLA). The processor 701 may integrate one or a combination of several of the following: Central Processing Unit (CPU), Graphics Processing Unit (GPU), and modem. The CPU primarily handles the operating system, user interface, and applications; the GPU is responsible for rendering and drawing the content required for display; and the modem handles wireless communication. It is understood that the modem may also not be integrated into the processor 701 and may be implemented as a separate chip.
[0099] The memory 705 may include random access memory (RAM) or read-only memory. Optionally, the memory 705 may include a non-transitory computer-readable storage medium. The memory 705 can be used to store instructions, programs, code, code sets, or instruction sets. The memory 705 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for at least one function (such as touch function, sound playback function, image playback function, etc.), instructions for implementing the above-described method embodiments, etc.; the data storage area may store data involved in the above-described method embodiments, etc. Optionally, the memory 705 may also be at least one storage device located remotely from the aforementioned processor 701. Figure 7 As shown, the memory 705, which serves as a computer storage medium, may include an operating system, a network communication module, a user interface module, and a streaming governance and evidence-based monitoring application for the operational status of low-altitude unmanned aerial vehicles.
[0100] exist Figure 7In the illustrated electronic device 700, the user interface 703 is mainly used to provide an input interface for the user and acquire user input data; while the processor 701 can be used to call the streaming governance and evidence-based supervision application for low-altitude UAV operation status stored in the memory 705, and specifically perform the following operations: receive raw status messages reported by the UAV terminal, perform identity authentication, integrity verification, and anti-replay verification on the raw status messages, and take the raw status messages that pass the verification as valid raw messages; parse the valid raw messages into standardized status points with a unified data structure, the standardized status points including device identification, acquisition... The system includes time, platform reception time, spatial coordinates, altitude, speed, and heading; for standardized situation point sequences with the same device identifier, a sliding time window is established, and governance operations are performed within the window; situation points that have undergone governance and carry comprehensive credibility and governance tags are defined as credible situation points; governance operations include: deduplication based on message fingerprints or sequence numbers, reordering by collection time or sequence number, identifying and marking delay points based on the difference between collection time and platform reception time, suppressing abnormal jump points by comparing the speed and altitude change rates between adjacent points with preset thresholds, and calculating the comprehensive credibility of each situation point; the comprehensive credibility... Reliability is calculated based on a weighted average of multiple dimensions, including time reliability, location reliability, signal reliability, and sequence reliability. Reliable situation points are obtained and cross-validated with pre-stored equipment ledgers, real-name registration identifiers, terminal binding relationships, task authorization information, and operator information on the platform to generate entity identification results. These results include equipment legality status, task authorization status, operator matching status, and reasons for anomalies. The obtained reliable situation points and entity identification results are then combined with predefined four-dimensional airspace rules for online compliance determination. These rules include spatial geometric constraints, altitude range constraints, time range constraints, and other constraints. Version information; compliance determination includes: determining whether the current credible situation point is within the authorized mission airspace or has entered a restricted flight zone, and predicting the future position based on the current speed and heading, and pre-judging the trend risk of crossing the boundary or entering a restricted flight zone; when the compliance determination triggers a risk or the subject identification result is abnormal, a regulatory event is generated; the regulatory event is bound to the following information: the original message identifier of the triggering event, the credible situation point of the triggering event, the subject identification result, the applicable airspace rule version, the handling status, and the evidence hash value of the preceding event; the regulatory event and the corresponding evidence package are stored in a structured manner to form a traceable evidence chain.
[0101] In some possible embodiments, the governance operation further includes:
[0102] When a standardized situation point carries a retransmission identifier or the difference between the acquisition time and the platform reception time exceeds a preset real-time threshold, the situation point is marked as a retransmission point or a delay point. The retransmission point or delay point does not participate in real-time compliance determination and is only used for historical trajectory completion.
[0103] In some possible embodiments, the regulatory event is also bound to the hash value of the original message that triggered the event and the overall credibility of the trusted status point of the triggering event;
[0104] The overall credibility is calculated as follows:
[0105] C=w1*C time +w2*C location +w3*C signal +w4*C sequence +w5*C identity
[0106] Among them, C time To calculate the time reliability based on the delay between the acquisition time and the platform reception time, C location To calculate the position reliability based on the velocity and height continuity between adjacent points, C signal C is the link reliability calculated based on signal strength or packet loss rate. sequence C is a sequence reliability calculated based on the continuity and disorder of message fingerprints or sequence numbers. identity This is the identity credibility calculated based on the consistency verification results between the device identifier and the operating entity information. Weights w1 to w5 are preset weights and their sum is 1.
[0107] When the overall credibility is greater than or equal to the first threshold, the trusted status point directly participates in the real-time compliance determination; when the overall credibility is less than the second threshold, the trusted status point does not trigger a high-level alarm.
[0108] In some possible embodiments, multi-feature association verification includes:
[0109] Verify that the device identifier exists in the platform's device ledger and that the real-name registration status is valid;
[0110] Verify whether there is a valid binding relationship between the reported terminal identifier and the device identifier;
[0111] Verify whether the flight plan corresponding to the mission identifier in the trusted situation point is within the valid time window;
[0112] Verify that the operator information matches the task authorization record;
[0113] When any verification rule fails, the corresponding reason for the anomaly is recorded in the subject identification result.
[0114] In some possible embodiments, the spatial geometric constraints in the four-dimensional airspace rules are expressed using at least one of the following geometric forms: polygon, circle, sector, flight path buffer, three-dimensional cylinder;
[0115] When multiple airspace rules overlap in space or time, conflict resolution is carried out according to the priority of the rules, the release time, the task authorization status or the temporary control status, and compliance determination is performed based on the resolution results.
[0116] In some possible embodiments, the processor 701 performs actions such as predicting future position based on current speed and heading, and pre-judging the trend risk of crossing boundaries or entering restricted flight zones, specifically for the following purposes:
[0117] The future position is predicted using a uniform linear motion model, and the specific formula is as follows:
[0118] P′=P+V·τ
[0119] Where P is the spatial coordinate of the current credible situation point, V is the velocity vector, and τ is the preset prediction duration; the same spatial rule judgment is applied to the future position P′ as to the current credible situation point, and a trend warning event is generated when P′ enters a restricted flight zone or crosses the authorized mission airspace.
[0120] In some possible embodiments, the evidence package includes the original data associated with the triggering event, governance process records, judgment basis, and handling results; the evidence hash value of the preceding event and the evidence hash value of the current event are used to form a verifiable chain of evidence.
[0121] This application also provides a computer-readable storage medium storing instructions that, when executed on a computer or processor, cause the computer or processor to perform the above-described instructions. Figure 2 One or more steps in the illustrated embodiment. If the constituent modules of the above-described low-altitude UAV operational status flow management and evidence-based monitoring device are implemented as software functional units and sold or used as independent products, they can be stored in the computer-readable storage medium.
[0122] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted through the computer-readable storage medium. The computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, Digital Subscriber Line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device such as a server or data center that integrates one or more available media. The available media may be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., digital versatile discs (DVDs)), or semiconductor media (e.g., solid state disks (SSDs)).
[0123] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. This program can be stored in a computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. The aforementioned storage medium includes various media capable of storing program code, such as read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks. Unless otherwise specified, the technical features of this embodiment and its implementation schemes can be combined arbitrarily.
[0124] The above description of the disclosed embodiments enables those skilled in the art to make or use this application. It will be apparent to those skilled in the art that various modifications can be made to these embodiments, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A method for stream-based governance and evidence-based supervision of the operational status of low-altitude unmanned aerial vehicles (UAVs), characterized in that, The method includes: Receive raw situational information reported by the UAV terminal, perform identity authentication, integrity verification and anti-replay verification on the raw situational information, and take the raw situational information that passes the verification as valid raw information; The valid original message is parsed into standardized situation points with a unified data structure. The standardized situation points include device identifier, acquisition time, platform reception time, spatial coordinates, altitude, speed and heading. For a standardized sequence of situation points with the same device identifier, a sliding time window is established, and governance operations are performed within the window. Situation points that have undergone governance and carry a comprehensive credibility score and governance tag are defined as credible situation points. The governance operations include: deduplication based on message fingerprints or sequence numbers; reordering based on acquisition time or sequence number; identifying and marking delay points based on the difference between acquisition time and platform reception time; suppressing abnormal jump points by comparing the velocity and altitude change rates between adjacent points with preset thresholds; and calculating the comprehensive credibility score of each situation point. The comprehensive credibility score is calculated based on a weighted average of multiple dimensions, including time credibility, location credibility, signal credibility, and sequence credibility. The trusted situation points are obtained and multi-element correlation verification is performed with the device ledger, real-name registration identifier, terminal binding relationship, task authorization information and operator information pre-stored on the platform to generate subject identification results; the subject identification results include device legality status, task authorization status, operator matching status and abnormal reasons; The trusted situation point and the subject identification result are obtained, and online compliance determination is performed in combination with predefined four-dimensional airspace rules. The four-dimensional airspace rules include spatial geometric constraints, altitude range constraints, time range constraints, and rule version information. The compliance determination includes: determining whether the current trusted situation point is located within the authorized mission airspace or has entered a restricted flight zone, and predicting the future position based on the current speed and heading and judging the trend risk of crossing the boundary or entering a restricted flight zone in advance. When the compliance determination triggers a risk or the subject identification result is abnormal, a regulatory event is generated; the regulatory event is bound to the following information: the original message identifier of the triggering event, the trusted status point of the triggering event, the subject identification result, the applicable airspace rule version, the handling status, and the evidence hash value of the preceding event; the regulatory event and the corresponding evidence package are stored in a structured manner to form a traceable evidence chain.
2. The method for stream-based governance and evidence-based supervision of low-altitude unmanned aerial vehicle (UAV) operation status according to claim 1, characterized in that, The governance operations also include: When the standardized situation point carries a retransmission identifier or the difference between the acquisition time and the platform reception time exceeds a preset real-time threshold, the situation point is marked as a retransmission point or a delay point. The retransmission point or delay point does not participate in real-time compliance determination and is only used for historical trajectory completion.
3. The method for stream-based governance and evidence-based supervision of low-altitude unmanned aerial vehicle (UAV) operation status according to claim 1, characterized in that, The regulatory event is also bound to the hash value of the original message that triggered the event and the comprehensive credibility of the trusted status point of the triggering event; The calculation method for the overall credibility is as follows: C=w1*C time +w2*C location +w3*C signal +w4*C sequence +w5*C identity Among them, C time C is the time reliability calculated based on the delay between the acquisition time and the platform reception time. location To calculate the position reliability based on the velocity and height continuity between adjacent points, C signal C is the link reliability calculated based on signal strength or packet loss rate. sequence C is a sequence reliability calculated based on the continuity and disorder of message fingerprints or sequence numbers. identity The identity credibility is calculated based on the consistency verification results between the device identifier and the operating entity information. The weights w1 to w5 are preset weights and their sum is 1. When the overall credibility is greater than or equal to the first threshold, the credibility status point directly participates in the real-time compliance determination; when the overall credibility is less than the second threshold, the credibility status point does not trigger a high-level alarm.
4. The method for stream-based governance and evidence-based supervision of low-altitude unmanned aerial vehicle (UAV) operation status according to claim 1, characterized in that, The multi-factor association verification includes: Verify that the device identifier exists in the platform's device ledger and that the real-name registration status is valid; Verify whether a valid binding relationship exists between the reporting terminal identifier and the device identifier; Verify whether the flight plan corresponding to the mission identifier in the trusted situation point is within a valid time window; Verify whether the operator information matches the task authorization record; When any verification rule fails, the subject identification result records the corresponding reason for the anomaly.
5. The method for stream-based governance and evidence-based supervision of low-altitude unmanned aerial vehicle (UAV) operation status according to claim 1, characterized in that, The spatial geometric constraints in the four-dimensional airspace rules adopt at least one of the following geometric expressions: polygon, circle, sector, flight path buffer, three-dimensional cylinder; When multiple airspace rules overlap in space or time, conflict resolution is performed according to the rule priority, release time, task authorization status, or temporary control status, and the compliance determination is executed based on the resolution result.
6. The method for stream-based governance and evidence-based supervision of low-altitude unmanned aerial vehicle (UAV) operation status according to claim 1, characterized in that, The method of predicting future position based on current speed and heading and assessing the risk of crossing boundaries or entering restricted or prohibited flight zones in advance includes: The future position is predicted using a uniform linear motion model, and the specific formula is as follows: P′=P+V·τ Where P is the spatial coordinate of the current credible situation point, V is the velocity vector, and τ is the preset prediction duration; the same spatial rule judgment as the current credible situation point is performed on P′, and a trend warning event is generated when P′ enters the restricted flight zone or crosses the authorized mission airspace.
7. The method for stream-based governance and evidence-based supervision of low-altitude unmanned aerial vehicle (UAV) operation status according to claim 1, characterized in that, The evidence package includes the original data associated with the triggering event, governance process records, judgment basis, and handling results; the evidence hash value of the preceding event and the evidence hash value of the current event are used to form a verifiable evidence chain.
8. A flow-based governance and evidence-based monitoring device for the operational status of low-altitude unmanned aerial vehicles (UAVs), characterized in that, The device includes: The receiving module is used to receive raw situational information reported by the UAV terminal, perform identity authentication, integrity verification and anti-replay verification on the raw situational information, and take the raw situational information that passes the verification as valid raw information. The parsing module is used to parse the valid raw message into standardized situation points with a unified data structure. The standardized situation points include device identifier, acquisition time, platform reception time, spatial coordinates, altitude, speed and heading. A module is established to create a sliding time window for a standardized sequence of situation points identified by the same device, and to perform governance operations within the window. Situation points that have undergone governance and carry a comprehensive credibility score and governance tag are defined as credible situation points. The governance operations include: deduplication based on message fingerprints or sequence numbers; reordering based on acquisition time or sequence number; identifying and marking delay points based on the difference between acquisition time and platform reception time; suppressing abnormal jump points by comparing the velocity and altitude change rates between adjacent points with preset thresholds; and calculating the comprehensive credibility score of each situation point. The comprehensive credibility score is calculated based on a weighted average of multiple dimensions, including time credibility, location credibility, signal credibility, and sequence credibility. The acquisition module is used to acquire the trusted situation points and perform multi-element association verification with the device ledger, real-name registration identifier, terminal binding relationship, task authorization information and operator information pre-stored on the platform to generate the subject identification result; the subject identification result includes the device legality status, task authorization status, operator matching status and abnormal reasons. The determination module is used to acquire the trusted situation point and the subject identification result, and to perform online compliance determination in combination with predefined four-dimensional airspace rules. The four-dimensional airspace rules include spatial geometric constraints, altitude range constraints, time range constraints and rule version information. The compliance determination includes: determining whether the current trusted situation point is located within the authorized mission airspace or has entered a restricted flight zone, and predicting the future position based on the current speed and heading and judging the trend risk of crossing the boundary or entering the restricted flight zone in advance. The generation module is used to generate a regulatory event when the compliance determination triggers a risk or the subject identification result is abnormal. The regulatory event is bound to the following information: the original message identifier of the triggering event, the trusted status point of the triggering event, the subject identification result, the applicable airspace rule version, the handling status, and the evidence hash value of the preceding event. The regulatory event and the corresponding evidence package are stored in a structured manner to form a traceable evidence chain.
9. A computer storage medium, characterized in that, The computer storage medium stores a plurality of instructions adapted for loading by a processor and executing the steps of the method as described in any one of claims 1 to 7.
10. An electronic device, characterized in that, It includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the steps of the method as described in any one of claims 1 to 7.