Dual-mode friend-or-foe identification system and method based on trusted identification and task parameters
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- NANJING XUNSHI DATA TECH CO LTD
- Filing Date
- 2026-05-13
- Publication Date
- 2026-08-07
AI Technical Summary
然而在实战场景中,随着各类无人装备在外形设计、材料结构和雷达特征等方面趋于高度相似,依赖物理特征的识别手段越来越难以准确区分敌我
(1)基于标识密钥对构建身份,结合数字签名机制,能够有效防止伪装、欺骗和重放攻击;
Smart Images

Figure CN122534397A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of intelligent equipment identification, and particularly relates to the identification of small unmanned equipment, and to a dual-mode friend-or-foe identification system and method based on trusted identifiers and task parameters. Background Technology
[0002] With the development of intelligent and unmanned combat equipment, unmanned platforms, represented by drones and unmanned ground vehicles, have gradually become the core combat force on the modern battlefield. Compared with manned equipment, unmanned equipment has the characteristics of low cost, strong survivability, and strong adaptability to complex environments. It can perform missions in high-risk areas, significantly improving combat effectiveness and personnel safety.
[0003] In collaborative operations and cross-domain joint missions, a rapid, accurate, and secure friend-or-foe identification mechanism must be established among unmanned equipment, personnel, and supplies on the battlefield. This mechanism not only affects the efficiency of equipment coordination but also directly impacts the correctness of operational decisions and the safety of their execution.
[0004] Currently, traditional friend-or-foe identification (FF) technologies primarily rely on photoelectric identification methods, combining target shape features, visual markers, or spectral characteristics with image recognition algorithms for identification. However, in real-world combat scenarios, as various unmanned equipment become increasingly similar in shape, material structure, and radar characteristics, identification methods relying on physical features are finding it increasingly difficult to accurately distinguish friend from foe. Especially when the enemy acquires and modifies friendly equipment for re-deployment, traditional identification methods often fail.
[0005] Furthermore, photoelectric identification methods heavily rely on the visual environment, and their reliability drops significantly in harsh weather, at night, or under strong interference, failing to meet the requirements for high-reliability all-weather operations. Meanwhile, most current friend-or-foe identification schemes employ a centralized control architecture, requiring a command center to initiate identification requests. This approach is unsustainable in situations of communication disruptions, link interruptions, or extremely wide battlefield distribution, severely impacting system stability and battlefield adaptability.
[0006] In summary, existing IFF (Identification Friend or Foe) technologies still have significant shortcomings in terms of accuracy, environmental robustness, mission adaptability, and response timeliness. There is an urgent need for an IFF system with high security, dual-mode operation capabilities, low communication dependence, and rapid response. Especially for small unmanned equipment operating in modern, highly dynamic, and highly contested unmanned combat environments, building a trusted identity recognition system based on digital identity, supporting mission customization, and adaptable to both centralized and distributed scenarios is crucial for improving operational security and decision-making efficiency. Summary of the Invention
[0007] In view of this, the purpose of this invention is to provide a dual-mode friend-or-foe identification system and method based on trusted identifiers and task parameters, which uses digital identity to replace physical appearance features for friend-or-foe judgment, thereby improving identification accuracy; supports two operating modes, centralized control and distributed identification, thereby improving battlefield adaptability; and combines task parameters and digital signatures to achieve customized, secure, and low-latency friend-or-foe identification response.
[0008] To achieve the above objectives, the present invention provides the following technical solution: A dual-mode friend-or-foe identification system based on trusted identifiers and task parameters, comprising: The Identification and Recognition Management System (IRMS) is used to generate, issue, cancel, update, and audit trusted identification parameters. TIME With execution task parameters TP ; At least one Identification and Recognition Module (IRM) is integrated with or worn by an identifiable object to perform identification and judgment of friend or foe attributes; in, The trusted identifier parameter TIME Including publicly available parameters TIME pub With privacy parameters TIME pri , TIME pri Stored in IRM, TIME pub The equipment identification ID is calculated and generated in real time within the IRM. The execution task parameters TP Securely injected into the IRM via IRMS or the mission parameter injection device TP-IN; The system supports the following two working modes: Centralized mode: The broadcast IRM actively initiates identification, and the receiving IRM responds to the identification request; Decentralized mode: Any IRM initiates an identification request autonomously, and the receiving IRM verifies the friend or foe attribute.
[0009] Furthermore, the IRM includes: The microprocessor module (MPU) is used to execute enemy-foe identification algorithms and real-time computing. TIME pub ; The communication module is used to broadcast or receive identification information; Storage module, used for storage TIMEpri and TP ; Power module: Provides an independent continuous power supply for the module, and also supports 5V power supply input; The interface module is used to interact with the positioning device, clock module, and business processing module of unmanned equipment.
[0010] Furthermore, the IRMS generates trusted identifier parameters. TIME At that time, an identification key pair is generated based on the equipment identification ID: TIME ={ TIME pub , TIME pri} in: TIME pub Indicates the public key; TIME pri Indicates the identifier private key; The TIME pub It can be generated using any of the following encryption algorithms: SM2, SM4, RSA, ECC, or other symmetric or asymmetric algorithms.
[0011] Furthermore, the aforementioned TP The parameters are generated by IRMS based on the task identifier before each task is executed and are unique; The TP Parameters are written remotely to the IRM via IRMS, or manually injected via the TP parameter injection device TP-IN; Before injecting parameters, the TP-IN needs to receive a corresponding certificate issued by IRMS. TIME parameter.
[0012] A dual-mode friend-or-foe identification method based on trusted identifiers and task parameters includes the following steps: S1: IRMS generates an identification key pair for each piece of equipment. TIME pub , TIME pri},Will TIME pri Write the corresponding IRM and configure it for computation. TIME pub The algorithm; S2: IRMS generates execution task parameters TP And inject it into the IRM remotely or via TP-IN; S3: IRM performs friend-or-foe identification operations, specifically including: In centralized mode, the broadcast IRM periodically sends data packets: Pack treq ={Rand, TIME pub , TP , Say} The signature field Say Generated by the following function:
[0013] in, Rim It is a random number; A function for performing digital signatures; This represents a string concatenation operation; TP These represent the parameters for executing the task and are unique to each task. TIME pub This indicates the public key.
[0014] After receiving the broadcast packet, the receiving IRM uses the following verification function to determine friend or foe attributes:
[0015] in, For verification functions; If the verification passes, it is considered "our side"; otherwise, it is considered "the enemy side". In the decentralized mode, any IRM can send an identification data packet as the initiator and send it to the target IRM through the business data link. The target IRM then completes the same verification process.
[0016] Furthermore, the identification data packet Package res The total length shall not exceed 110 bytes; The receiving end returns a response data packet after successful verification: Package res ={ ID recv , Say recv} in, ID recv Indicates the receiver identifier; Say recv This indicates the response data signed by the receiving end in response to the request packet; the total length of the data packet does not exceed 94 bytes.
[0017] Furthermore, the signature function and verification function Supports SM2, RSA and ECC algorithm implementations.
[0018] Furthermore, during the identification process, the end-to-end response from the initiating IRM to the receiving IRM has a total latency of less than 70 to 200 milliseconds, depending on the communication distance of 1 to 5 km, in order to meet the real-time identification requirements in highly dynamic battlefields.
[0019] The beneficial effects of this invention are as follows: (1) Identity is constructed based on the identifier key pair, and combined with the digital signature mechanism, which can effectively prevent spoofing, deception and replay attacks; (2) It supports both centralized control and distributed identification modes, adapting to various battlefield environments; (3) Through local computing and lightweight data packet structure, the entire identification process can be completed in 70-200 milliseconds, depending on the communication distance of 1-5km; (4) Introducing a task parameter mechanism allows for dynamic configuration of the recognition logic based on the task, thereby improving the context awareness of recognition decisions; (5) The enemy-foe identification device has a compact structure and low power consumption, and can be flexibly deployed in various unmanned equipment, materials or combat personnel equipment.
[0020] (6) The identification friend or foe device is lightweight, with a weight of less than 80g (excluding independent power supply), and provides 5V power supply access.
[0021] Other advantages, objectives, and features of the invention will be set forth in part in the description which follows, and in part will be apparent to those skilled in the art from the following examination, or may be learned from practice of the invention. The objectives and other advantages of the invention can be realized and obtained through the following description. Attached Figure Description
[0022] To make the objectives, technical solutions, and advantages of the present invention clearer, the preferred embodiments of the present invention will be described in detail below with reference to the accompanying drawings, wherein: Figure 1 This is a schematic diagram of the overall architecture of the enemy-foe identification system of the present invention; Figure 2 A schematic diagram of the functional structure of an IFF (Identification Friend or Foe) device; Figure 3 This is a flowchart of the interaction process for friend-or-foe identification under a centralized mode; Figure 4 This is a flowchart of the end-to-end identification process in a decentralized mode; Figure 5 Inject a flowchart into the task parameters. Detailed Implementation
[0023] The following specific examples illustrate the implementation of the present invention. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments, and various details in this specification can be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. It should be noted that the illustrations provided in the following embodiments are only schematic representations of the basic concept of the present invention. Unless otherwise specified, the following embodiments and features can be combined with each other.
[0024] The accompanying drawings are for illustrative purposes only and are schematic diagrams, not actual pictures. They should not be construed as limiting the invention. To better illustrate the embodiments of the invention, some parts in the drawings may be omitted, enlarged, or reduced, and do not represent the actual product dimensions. It is understandable to those skilled in the art that some well-known structures and their descriptions may be omitted in the drawings.
[0025] In the accompanying drawings of the embodiments of the present invention, the same or similar reference numerals correspond to the same or similar components. In the description of the present invention, it should be understood that if terms such as "upper," "lower," "left," "right," "front," and "rear" indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings, they are only for the convenience of describing the present invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, the terms used to describe positional relationships in the drawings are only for illustrative purposes and should not be construed as limiting the present invention. For those skilled in the art, the specific meaning of the above terms can be understood according to the specific circumstances.
[0026] Figure 1 This is a schematic diagram of the overall architecture of the enemy-foe identification system of the present invention, illustrating the relationship between the enemy-foe identification management system and multiple enemy-foe identification devices; Figure 2 This is a functional structure diagram of an IRM (Identification Friend or Foe) device, illustrating the composition of its internal modules and the relationship between data flow. Figure 3 This is a flowchart of the interaction process for friend-or-foe identification in a centralized mode, illustrating the identification process between the broadcasting end and the receiving end; Figure 4 This is a flowchart of the end-to-end identification process in a decentralized mode, illustrating the interaction logic between two IRMs. Figure 5 The flowchart for injecting task parameters illustrates the process of writing task parameters to the IRM via the TP-IN device.
[0027] This invention provides a dual-mode friend-or-foe identification system and method based on trusted identifiers and mission parameters, which is applicable to real-time identification of unmanned equipment, ground supplies and combat personnel in multi-domain combat scenarios, improving identification security and battlefield adaptability.
[0028] I. System Structure The system includes: Identification and Recognition Management System (IRMS) Identification and Recognition Module (IRM) is a device used for identifying friend or foe. An optional task parameter injection device, TP-IN, is available for manually injecting task parameters.
[0029] 1. IRMS Function Description IRMS is deployed in backend command and control systems or secure and trusted network nodes to perform the following functions: Generate an identification key pair based on the equipment identification ID, including the identification public parameters. TIME pub and identifying privacy parameters TIME pri ; Generate mission parameters for each combat mission TP ; Will TIME pri , TP The parameters are written to the corresponding IRM, or a signature credential for TP-IN injection is issued; Record and audit every identity issuance, cancellation, and update operation.
[0030] IRMS supports multiple algorithm generation mechanisms, including mainstream symmetric and asymmetric algorithms such as SM2, SM4, RSA, and ECC, to adapt to different security strategies.
[0031] 2. IRM Module Structure IRM is integrated into unmanned equipment or personnel gear, including: The MPU processor is used for identity signing, verification, and TID calculation. Storage module, secure storage TIME pri and TP ; The communication module, in centralized mode, is used to send and receive broadcast data packets; The interface module shares location information, time information, and friend-or-foe identification status with the main device. Optional RTC time module and BeiDou positioning module are available for independent identification support in offline operation scenarios.
[0032] IRM internal implementation TIME pub Its real-time computing logic enables verification to be completed without a pre-set public key, enhancing security and flexibility.
[0033] II. Working Mode The system of this invention supports dual-mode recognition, which is applicable to centralized recognition and end-to-end collaborative scenarios respectively.
[0034] 1. Centralized model It is suitable for centralized control scenarios, such as target identification, material receiving, and personnel protection against accidental injury.
[0035] The broadcast IRM periodically initiates identification requests and constructs identification data packets: Pack treq ={Rand, TIME pub , TP , Say} in, Rim This indicates that it is used for generating random numbers only once to prevent replay attacks; TIME pub It is an identifier public key generated locally and in real time by the IRM; TP These are the current task parameters injected by IRMS; Say For the signature field, the calculation method is as follows:
[0036] After receiving the broadcast packet, the receiving IRM executes the verification logic:
[0037] If the verification passes, it is judged as "our side"; otherwise, it is judged as "the enemy side". After successful verification, the receiving end returns a response data packet: Package res ={ ID recv , Say recv} The response packet is used to provide feedback on the identification results or to confirm the attribution status by the central system.
[0038] 2. Decentralized Model It is suitable for scenarios such as distributed collaboration and cross-domain data chain interconnection.
[0039] Any IRM can act as the initiator, construct a data packet identical to the broadcast method, and send it to the receiving end through the data link; The receiving end completes authentication without relying on a central node, making it suitable for units with broken command chains or independent combat units. The overall verification response process latency is controlled within 70 to 200 milliseconds, depending on the specific communication distance of 1 to 5 km, to ensure rapid identification under high dynamic conditions.
[0040] III. Task Parameter Injection Mechanism TP parameters can be injected offline via a TP-IN device. The injection process is as follows: 1. IRMS issues temporary TIDs and task TPs based on TP-IN identity; 2. The operator connects the TP-IN to the IRM; 3. The IRM receives the TP through the physical interface and verifies whether the IRMS signature is valid; 4. After successful injection, the IRM enters the task execution phase.
[0041] TP parameters are one-time task credentials that are strongly bound to the context of the task time window and execution region to prevent them from being reused or copied.
[0042] Example 1: Identification of Foe and Friend Based on Central Control This embodiment is applicable to centralized combat scenarios where air-ground cooperation or unmanned platforms have a stable communication link with the command center, and demonstrates the workflow of friend-or-foe identification in a centralized mode.
[0043] First, the IFF (Identification Friend or Foe) management system generates an identification key pair based on the identification number of each unmanned equipment. This key pair includes an identification public key and an identification private key. The identification private key is written into the corresponding IFF device through a secure channel. The algorithm for generating the identification public key is configured in the device for real-time calculation during runtime.
[0044] Before a mission is issued, the IFF (Identification Friend or Foe) management system generates mission parameters based on the mission type and writes these parameters into the IFF device on the unmanned equipment remotely.
[0045] Once the operation begins, the IFF (Identification Friend or Foe) device at the central broadcast position actively broadcasts identification data packets to equipment within a certain range at fixed intervals. These data packets contain a random number field, an identification public key, mission parameters, and a digital signature field generated based on the local identification private key for the first three items.
[0046] After receiving the identification data packet, the IFF (Identification Friend or Foe) device on the receiving end uses a local algorithm to calculate the broadcaster's public key, then verifies the signature field, and simultaneously checks the validity and timeliness of the task parameters. If the verification is successful, the broadcaster is identified as a friendly target, and a response message is returned. If the verification fails, it is determined to be a non-friendly unit, and no response is given or evasion measures are taken.
[0047] This process features high security, unified control, and rapid response, making it suitable for performing high-density identification tasks under conditions with a communication master control.
[0048] Example 2: Decentralized Distributed Process Based on End-to-End Identification This embodiment is applicable to distributed collaborative combat scenarios where friend or foe identification is performed between unmanned platforms or between unmanned platforms and command and control terminals without centralized control.
[0049] First, the IFF (Identification Friend or Foe) management system generates an identification key pair for each unmanned platform and securely writes the private key into its respective IFF device, while simultaneously issuing corresponding task parameters. The identification public key generation logic is pre-configured within the identification device, supporting real-time generation based on local identification numbers.
[0050] In actual combat, when any unmanned platform needs to determine whether a nearby platform is friendly, it can proactively construct an identification data packet and send it to the target platform via the operational communication link. The data packet includes a random number, a real-time generated identifier public key, current mission parameters, and a signature generated based on the identifier private key.
[0051] After receiving the data packet, the receiving identification device uses the same algorithm as the sending end to calculate the identification public key and verify the validity of the signature. It also verifies the consistency of the task parameters with the current context. If all verifications pass, the sender is marked as a friendly platform; if verification fails, it is identified as a non-friendly force or an abnormal target.
[0052] This mode does not rely on a command center or star-shaped communication architecture, and has a high degree of autonomy and flexibility. It is suitable for dynamic battlefield environments such as cross-domain collaboration, tactical disconnection, and autonomous units.
[0053] Example 3: Offline Task Parameter Loading Process Based on Injection Device This embodiment is applicable to application scenarios where task parameters need to be written to the identification device in an offline or closed environment.
[0054] During the pre-battle deployment phase, the IFF (Identification Friend or Foe) management system authorizes the task parameter injection device, issues it an identification key, and configures its injection permissions. Subsequently, the management system generates task parameters corresponding to specific tasks and writes them into the task injection device.
[0055] Users connect the task injection device to the IFF (Identification Friend or Foe) device to be deployed. The IFF device reads the task parameters and digital signature stored in the injection device through an interface, and verifies the validity of the signature using the identifier's public key. Upon successful verification, the IFF device stores the task parameters locally and completes the loading process.
[0056] This method is suitable for scenarios where equipment is deployed in batches under network-free conditions, effectively ensuring the security of task parameter transmission and improving the efficiency and flexibility of task preparation.
[0057] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.
Claims
1. A dual-mode friend-or-foe identification system based on trusted identifiers and task parameters, characterized in that: include: Identification Friend or Foe Management System (IRMS) is used to generate, issue, cancel, update, and audit trusted identifier parameters. TID With execution task parameters TP ; At least one IFF (Identification Friend or Foe) device, integrated with or worn by an identifiable object, is used to complete the identification and judgment of friend or foe attributes; in, The trusted identifier parameter TID Including publicly available parameters TID pub With privacy parameters TID pri , TID pri Stored in IRM, TID pub The equipment identification ID is calculated and generated in real time in the IRM or generated using a pre-made method. The execution task parameters TP Securely injected into the IRM via IRMS or the mission parameter injection device TP-IN; The system supports the following two working modes: Centralized mode: The broadcast IRM actively initiates identification, and the receiving IRM responds to the identification request; Decentralized mode: Any IRM initiates an identification request autonomously, and the receiving IRM verifies the friend or foe attribute.
2. The dual-mode friend-or-foe identification system based on trusted identifiers and task parameters according to claim 1, characterized in that: The IRM includes: The microprocessor module (MPU) is used to execute enemy-foe identification algorithms and real-time computing. TID pub ; The communication module is used to broadcast or receive identification information; Storage module, used for storage TID pri and TP ; The interface module is used to interact with the positioning device, clock module, and business processing module of the unmanned equipment. Power module: Provides an independent continuous power supply for the IRM module, and also supports 5V power supply input.
3. The dual-mode friend-or-foe identification system based on trusted identifiers and task parameters according to claim 1, characterized in that: The IRMS generates trusted identifier parameters. TID At that time, an identification key pair is generated based on the equipment identification ID: TID ={ TID pub , TID pri} in: TID pub Indicates the public key; TID pri Indicates the identifier private key; The TID pub It can be generated using any of the following encryption algorithms: SM2, SM4, RSA, ECC, or other symmetric or asymmetric algorithms.
4. The dual-mode friend-or-foe identification system based on trusted identifiers and task parameters according to claim 1, characterized in that: The TP The parameters are generated by IRMS based on the task identifier before each task is executed and are unique; The TP Parameters are written remotely to the IRM via IRMS, or manually injected via the TP parameter injection device TP-IN; Before injecting parameters, the TP-IN needs to receive a corresponding certificate issued by IRMS. TID parameter.
5. A dual-mode friend-or-foe identification method based on trusted identifiers and task parameters, characterized in that: Includes the following steps: S1: IRMS generates an identification key pair for each piece of equipment. TID pub , TID pri },Will TID pri Write the corresponding IRM and configure it for computation. TID pub The algorithm; S2: IRMS generates execution task parameters TP And inject it into the IRM remotely or via TP-IN; S3: IRM performs friend-or-foe identification operations, specifically including: In centralized mode, the broadcast IRM periodically sends data packets: Packe treq ={Rand, TID pub , TP , Sig } The signature field Sig Generated by the following function: in, Rand It is a random number; A function for performing digital signatures; This represents a string concatenation operation; TP These represent the parameters for executing the task and are unique to each task. TID pub This indicates the public key. After receiving the broadcast packet, the receiving IRM uses the following verification function to determine friend or foe attributes: in, For verification functions; If the verification passes, it is considered "our side"; otherwise, it is considered "the enemy side". In the decentralized mode, any IRM can send an identification data packet as the initiator and send it to the target IRM through the business data link. The target IRM then completes the same verification process.
6. The dual-mode friend-or-foe identification method based on trusted identifiers and task parameters according to claim 5, characterized in that: The identification data packet Packet res The total length shall not exceed 110 bytes; The receiving end returns a response data packet after successful verification: Packet res ={ ID recv , Sig recv} in, ID recv Indicates the receiver identifier; Sig recv This indicates the response data signed by the receiving end in response to the request packet; the total length of the data packet does not exceed 94 bytes.
7. The dual-mode friend-or-foe identification method based on trusted identifiers and task parameters according to claim 5, characterized in that: The signature function and verification function Supports SM2, RSA and ECC algorithm implementations.
8. The dual-mode friend-or-foe identification method based on trusted identifiers and task parameters according to claim 5, characterized in that: During the identification process, the total end-to-end response latency from the initiating IRM to the receiving IRM is less than 70-200 milliseconds, thus meeting the real-time identification requirements in highly dynamic battlefields.