Unmanned aerial vehicle data flow processing method and system with instantaneous safety perception capability
Patent Information
- Application Number
- CN202611096054.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-23
- Publication Date
- 2026-09-29
- Estimated Expiration
- 2046-07-23
AI Technical Summary
[0007]本发明的一个目的在于提出一种具备瞬时安全感知能力的无人机数据流处理方法及系统,针对现有技术普遍在数据生成之后才进行哈希计算或数字签名处理而难以提供采样瞬间固化证据、批处理机制缺乏跨批连续性约束且对丢帧断流缺失区间难以形成可验证承诺的问题,提出了基于流式哈希与微批量默克尔累积并结合周期数字签名的数据流安全处理技术方案:在传感器触发时刻获取采样数据帧并生成包含设备标识、高精度时间戳及帧序号的元数据,经规范化编码后与采样数据帧构造叶子输入并执行流式哈希得到叶子指纹;基于帧序号连续性判断在不连续时生成缺口元数据并哈希得到缺口叶子指纹;将叶子指纹及缺口叶子指纹按到达顺序写入当前微批量默克尔树生成批根并记录默克尔证明路径;在满足周期条件时对包含当前微批量批根与上一微批量批根的签名数据进行数字签名,并在当前微批量第一帧的叶子输入中写入上一微批量批根以实现交叠叶子绑定
1、实现采样瞬间固化与源头可信证明:通过在传感器触发时刻获取采样数据帧并同步生成包含设备标识、高精度时间戳及帧序号的元数据,随后对组合形成的叶子输入执行流式哈希生成叶子指纹,使得采样数据在产生瞬间即被指纹化固化,可有效降低数据注入、篡改或重放后再形成摘要或签名的风险,从而提升采集数据的真实性与完整性可信度。
Smart Images

Figure CN122595382B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of unmanned aerial vehicle (UAV) data processing, and in particular to a UAV data stream processing method and system with instantaneous safety perception capabilities. Background Technology
[0002] With the development of the low-altitude economy and the widespread application of drones in fields such as inspection, surveying, security evidence collection, and emergency rescue, drones typically need to continuously collect sensor outputs such as video, images, radar point clouds, and inertial measurement data, and transmit them wirelessly to ground stations or the cloud for storage, analysis, and sharing. To improve the credibility and traceability of the collected data, existing technologies generally employ methods such as hash digest verification, digital signatures, message authentication codes, trusted timestamps, and trusted logs to protect data integrity. Meanwhile, to balance real-time performance and resource consumption, some solutions aggregate continuous data in batches according to time windows or quantity thresholds, calculate hash summaries for data within a batch, or use Merkle trees to aggregate multiple data entries within a batch before signing the batch root, thereby reducing the number of signatures and facilitating subsequent verification.
[0003] However, in complex low-altitude environments and under open communication link conditions, existing technologies still have the following shortcomings: 1) Delayed solidification time: Many schemes perform hash calculations or digital signatures only after the data is generated, stored on disk, or uploaded. It is difficult to prove that the data is solidified at the moment of sampling triggering, and there is a risk that the data may be injected, tampered with, or replayed before the digest or signature is formed.
[0004] 2) Insufficient evidence of continuity: Existing batch processing security mechanisms often only provide integrity proof for a single batch of data and lack root value links across batches, making it difficult to detect when attackers replace or splice data at batch boundaries.
[0005] 3) Missing intervals are difficult to prove: In cases of frame loss, interruption, etc., many solutions only show that the data is missing, lacking verifiable commitment information about the missing intervals, making it difficult to distinguish between natural loss and human deletion, thus affecting the credibility of evidence collection and auditing.
[0006] Therefore, there is a need for a method and system for processing UAV data streams that can overcome the shortcomings of the existing technologies. Summary of the Invention
[0007] One objective of this invention is to propose a UAV data stream processing method and system with instantaneous security awareness capabilities. Addressing the problems of existing technologies that generally perform hash calculations or digital signatures only after data generation, making it difficult to provide evidence solidified at the moment of sampling, and the lack of cross-batch continuity constraints in batch processing mechanisms, making it difficult to form verifiable commitments for missing frames and interruptions, this invention proposes a data stream security processing technology based on streaming hashing and micro-batch Merkle accumulation combined with periodic digital signatures: At the sensor trigger moment, sampled data frames are acquired and metadata containing device identifiers, high-precision timestamps, and frame sequence numbers is generated. After normalization and encoding, leaf inputs are constructed with the sampled data frames, and streaming hashing is performed to obtain leaf fingerprints. Based on the continuity judgment of frame sequence numbers, gap metadata is generated when there is discontinuity, and gap leaf fingerprints are hashed to obtain gap leaf fingerprints. The leaf fingerprints and gap leaf fingerprints are written into the current micro-batch Merkle tree in arrival order to generate batch roots and record the Merkle proof path. When the periodic condition is met, the signature data containing the current micro-batch batch root and the previous micro-batch batch root is digitally signed, and the previous micro-batch batch root is written into the leaf input of the first frame of the current micro-batch to achieve overlapping leaf binding. This invention has the technical effects of instantaneous solidification of samples, traceability across batches, verifiability of missing intervals, and enhanced data authenticity, integrity, and non-repudiation.
[0008] On one hand, the present invention provides a method for processing UAV data streams with instantaneous safety awareness capabilities, comprising: S1. Obtain the digital certificate and corresponding private key bound to the drone, and set the preset constant to the initial value of the previous micro-batch root. S2. Obtain the sampling data frame at the trigger moment when the sensor generates the sampling data frame. S3. Generate metadata for the sampling data frame, including device identifier, high-precision timestamp, and frame sequence number. S4. Standardize and encode the metadata, and combine it with the sampling data frame according to the preset field order to generate leaf input. When the sampling data frame is the first frame of the current micro-batch, write the previous micro-batch root into the leaf input. S5. Perform streaming hash calculation on the leaf input to obtain the leaf fingerprint. S6. Based on the frame sequence number of the current frame and the previous frame... Frame sequence number is used to determine continuity. When it is not continuous, gap metadata representing the missing interval is generated, and after normalization encoding, streaming hash calculation is performed to obtain the gap leaf fingerprint; S7, the leaf fingerprint and the gap leaf fingerprint when they exist are written into the Merkle tree of the current micro-batch in the order of arrival to generate the current micro-batch root, and Merkle proof path is generated for the leaf fingerprint corresponding to the sampled data frame; S8, when the preset period condition is met, signature data including the current micro-batch root and the previous micro-batch root is constructed, the signature data is digitally signed using the private key, the current micro-batch root is updated to the new previous micro-batch root, and verification data associated with the sampled data frame is generated.
[0009] Optionally, S1 includes: Obtain the digital certificate bound to the drone and the private key corresponding to the digital certificate; Perform a certificate chain verification on the digital certificate to determine if the digital certificate is valid; When the digital certificate is in a valid state, a preset constant is written into the memory as the initial batch root, and the initial batch root is assigned the initial value of the previous micro-batch root. This value is used in subsequent steps to write the previous micro-batch root in the leaf input construction step and to reference the previous micro-batch root when constructing signature data in the periodic signature and inter-batch root linking steps.
[0010] Optionally, S2 includes: At the trigger moment when the sensor outputs a sampling data frame, the data acquisition module of the UAV reads the sampling data frame from the output interface of the sensor; Record the corresponding frame number for the sampled data frame and associate the frame number with the sampled data frame for storage; The sampled data frame that has been read and associated with the storage is output.
[0011] Optionally, S3 includes: Obtain the pre-set device identifier of the drone; At the trigger time of acquiring the sampled data frame, a high-precision timestamp corresponding to the sampled data frame is obtained from the time source; At the triggering time, the location information corresponding to the sampled data frame is obtained from the positioning module; Obtain the frame number associated with the sampled data frame; The device identifier, the high-precision timestamp, the location information, and the frame sequence number are combined according to a preset field format to generate the metadata, and the metadata is associated with the sampled data frame. Output the sampled data frame and the metadata.
[0012] Optionally, S4 includes: The device identifier, high-precision timestamp, location information, and frame sequence number of the metadata are respectively normalized and encoded. The normalization and encoding includes writing field identifier, field length, and field content for each field. The leaf input is generated by combining the normalized encoded metadata with the sampled data frame according to the preset field order. When the sampled data frame is the first frame of the current micro-batch, the root of the previous micro-batch is written into the leaf input and the writing position is the preset position of the leaf input to achieve overlapping leaf binding. Output the leaf input.
[0013] Optionally, S5 includes: The leaf input is input into the streaming hash calculation unit in byte order, and the hash calculation of the leaf input is performed using an incremental update method. After all data processing of the leaf input is completed, the leaf fingerprint is output. The leaf fingerprint is associated with the sampled data frame that generated the leaf input and then cached. Output the leaf fingerprint.
[0014] Optionally, S6 includes: Get the frame number of the current frame and the frame number of the previous frame, and determine whether the frame number of the current frame is equal to the frame number of the previous frame plus one. When the judgment result is not equal, determine the start and end frame numbers of the gap, where the start frame number of the gap is the frame number of the previous frame plus one, and the end frame number of the gap is the frame number of the current frame minus one. Obtain the high-precision timestamp corresponding to the previous frame and the high-precision timestamp corresponding to the current frame, and determine the corresponding time range from the high-precision timestamp corresponding to the previous frame to the high-precision timestamp corresponding to the current frame. The gap start and end frame numbers and the time range are combined to generate gap metadata. After normalizing and encoding the gap metadata, streaming hash calculation is performed to obtain the gap leaf fingerprint. Output the notched leaf fingerprint and the leaf fingerprint corresponding to the current frame. If the judgment result is equal, only output the leaf fingerprint corresponding to the current frame.
[0015] Optionally, S7 includes: Write the leaf fingerprints and the notched leaf fingerprints into the current micro-batch of Merkel leaf sub-layers in the order of arrival and assign the corresponding leaf indices. After each leaf fingerprint or notched leaf fingerprint is written, an incremental update is performed based on the node level of the Merkle tree. The incremental update includes hashing two adjacent node values at the same node level according to a preset splicing order to generate a parent node value, and then using the generated parent node value to continue hashing at the next node level until the current micro-batch root is obtained. During the incremental update process, the Merkel proof path corresponding to the sampled data frame is generated by taking the leaf fingerprint record corresponding to the sampled data frame and the sibling node value and sibling node position corresponding to the leaf fingerprint when participating in hash calculation at each node level. Output the current micro-batch root and the Merkel proof path.
[0016] Optionally, S8 includes: When the current micro-batch reaches a preset leaf quantity threshold or a preset time length threshold, it is determined that the preset cycle condition is met. When the preset periodic conditions are met, the batch number of the current micro-batch and the start and end timestamps of the current micro-batch are obtained, and the current micro-batch root, the previous micro-batch root, the batch number, and the start and end timestamps are combined in the order of preset fields to generate signature data. Perform a digital signature on the signature data using the private key; Write the current micro-batch root to memory to update the previous micro-batch root; The digital signature is associated with the signature data and stored, and the sampled data frame, the metadata, the leaf fingerprint, the Merkel proof path, the current micro-batch root, and the digital signature are output as the result data.
[0017] On the other hand, the present invention also provides a UAV data stream processing system with instantaneous safety awareness capability, comprising: The key management module is used to acquire the digital certificate bound to the drone and its corresponding private key, and initialize the root of the previous micro-batch with preset constants. The sampling and leaf generation module is used to acquire sampling data frames at the sensor trigger moment and generate metadata including device identifier, high-precision timestamp, and frame sequence number. After normalizing and encoding the metadata, it is combined with the sampling data frame to generate leaf input. The root of the previous micro-batch is written into the leaf input of the first frame of the current micro-batch, and streaming hashing is performed on the leaf input to obtain the leaf fingerprint. The gap processing module is used to generate gap metadata based on the continuity of frame sequence number and perform hashing. The module obtains the gapped leaf fingerprint; the Merkel accumulation and proof module is used to write the leaf fingerprint and the gapped leaf fingerprint when they exist into the Merkel tree of the current micro-batch to obtain the current micro-batch root, and generate the Merkel proof path corresponding to the sampled data frame; the periodic signature and output module is used to digitally sign the signature data including at least the current micro-batch root and the previous micro-batch root when a preset periodic condition is met, update the previous micro-batch root, and generate verification data associated with the sampled data frame. The verification data includes metadata, leaf fingerprint, Merkel proof path, current micro-batch root, and digital signature.
[0018] The beneficial effects of this invention are: 1. Achieve instantaneous data solidification and source-based credible proof: By acquiring the sampled data frame at the moment of sensor triggering and simultaneously generating metadata containing device identifier, high-precision timestamp and frame sequence number, and then performing streaming hashing on the combined leaf input to generate leaf fingerprint, the sampled data is fingerprinted and solidified at the moment of generation. This can effectively reduce the risk of data injection, tampering or replay before forming digest or signature, thereby improving the authenticity and integrity of the collected data.
[0019] 2. Enhance cross-micro-batch continuity and anti-spoofing / tampering capabilities: Write the previous micro-batch root into the leaf input of the first frame of the current micro-batch to achieve overlapping leaf binding, and include the current micro-batch root and the previous micro-batch root into the signature data during periodic signing to form an inter-batch root link. This establishes dual constraints at the batch boundary, which can effectively prevent attackers from replacing, truncating or splicing between batches, and improve the traceability and non-repudiation of the data link.
[0020] 3. Improve the provability and auditability in scenarios of interruption and frame loss: Generate missing metadata based on the continuity detection of frame sequence number and calculate the missing leaf fingerprint. Incorporate the missing interval into the Merkel accumulation process in the form of missing leaves, so that the missing data is no longer just "no data", but forms verifiable missing commitment evidence, which is convenient for distinguishing between natural loss and human deletion during subsequent audits and improves the credibility of evidence collection. Attached Figure Description
[0021] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used in conjunction with embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings: Figure 1 This is a flowchart of the UAV data stream processing method with instantaneous safety perception capability proposed in this invention. Detailed Implementation
[0022] The present invention will now be described in further detail with reference to the accompanying drawings. These drawings are simplified schematic diagrams, illustrating only the basic structure of the invention, and therefore only show the components relevant to the invention.
[0023] refer to Figure 1 A method for processing UAV data streams with instantaneous safety awareness capabilities, comprising: S1. Obtain the digital certificate and corresponding private key bound to the drone, and set the preset constant to the initial value of the previous micro-batch root. S2. Obtain the sampling data frame at the trigger moment when the sensor generates the sampling data frame. S3. Generate metadata for the sampling data frame, including device identifier, high-precision timestamp, and frame sequence number. S4. Standardize and encode the metadata, and combine it with the sampling data frame according to the preset field order to generate leaf input. When the sampling data frame is the first frame of the current micro-batch, write the previous micro-batch root into the leaf input. S5. Perform streaming hash calculation on the leaf input to obtain the leaf fingerprint. S6. Based on the frame sequence number of the current frame and the previous frame... Frame sequence number is used to determine continuity. When it is not continuous, gap metadata representing the missing interval is generated, and after normalization encoding, streaming hash calculation is performed to obtain the gap leaf fingerprint; S7, the leaf fingerprint and the gap leaf fingerprint when they exist are written into the Merkle tree of the current micro-batch in the order of arrival to generate the current micro-batch root, and Merkle proof path is generated for the leaf fingerprint corresponding to the sampled data frame; S8, when the preset period condition is met, signature data including the current micro-batch root and the previous micro-batch root is constructed, the signature data is digitally signed using the private key, the current micro-batch root is updated to the new previous micro-batch root, and verification data associated with the sampled data frame is generated.
[0024] In this specific embodiment, S1 includes: The key management module reads the digital certificate bound to the drone and the private key corresponding to the digital certificate from the secure storage area. The digital certificate adopts the X.509 certificate format with DER encoding and is stored in the drone's non-volatile memory in the form of a byte array. The private key is stored in the key slot of the hardware security unit and is obtained in the form of a key handle to ensure that the plaintext of the private key does not leave the security boundary. At the same time, the key management module reads the root certificate from the drone's read-only storage area as a trust anchor and reads the drone's preset device identifier for binding relationship verification. Subsequently, a certificate chain verification is performed on the digital certificate to determine that the digital certificate is in a valid state. The certificate chain verification establishes a parent-child relationship between the leaf certificate, the intermediate certificate, and the root certificate in a bottom-up chain construction manner, and performs signature verification and constraint checks at each level. The signature verification uses the public key of each level certificate issuer to verify the signature value of the next level certificate, and calculates the data to be verified using the signature algorithm and hash algorithm declared in the certificate to ensure that the chain cannot be forged. The constraint checks include determining the time interval of the certificate validity period fields NotBefore and NotAfter, determining the consistency of the usage of BasicConstraints and KeyUsage, and determining the consistency between the device identifier declared in the leaf certificate and the device identifier preset in the drone. The current time used for time determination is provided by the drone time source and supplied to the verification logic in the form of a microsecond-level timestamp. After the certificate chain verification is successful, a preset constant is written into the memory as the initial batch root and assigned the initial value of the previous micro-batch batch root. The preset constant is fixed as a sequence of all zeros with a length of 32 bytes, and its length is consistent with the batch root byte length output by the subsequent Merkle accumulation and streaming hash of this invention. The assignment relationship is expressed by the formula: ; in This represents the value of the variable in runtime memory of the previous micro-batch root. This indicates the initial batch root to be written to memory. The symbol ← represents the preset constant, and the symbol ← indicates an assignment operation that writes the value on the right and overwrites the value on the left. The initial batch root is written into the batch root storage area of the UAV's non-volatile memory and a mirror cache is established in the running memory. This allows the previous micro-batch batch root to be read and written when constructing leaf input in subsequent steps, and the same previous micro-batch batch root to be referenced when constructing periodic signatures and inter-batch root links to complete the signature data construction. At the same time, when the certificate chain verification fails, the key management module outputs a failure status and terminates the current data stream processing task to avoid generating batch root chains and digital signatures under untrusted identities.
[0025] In this specific embodiment, S2 includes: The UAV's data acquisition module acquires the sampled data frame at the trigger moment when the sensor generates the sampled data frame. The sensor is an image sensor and its output interface is a MIPI SI-2 interface. The trigger moment is triggered by the frame start synchronization signal output by the image sensor and the interrupt controller generates an acquisition interrupt. During the system initialization phase, the data acquisition module configures the DMA ring buffer of the MIPI receiver controller to receive continuously arriving frame data and configures it to generate a DMA completion interrupt each time the frame start synchronization signal arrives, so that there is a definite correspondence between the interruption and the frame data being written to the buffer. When an acquisition interruption occurs, the data acquisition module reads the completed buffer segment pointed to by the DMA write pointer and writes all the bytes in the buffer segment as the current sampled data frame into the acquisition buffer area. The acquisition buffer area is a pre-allocated contiguous memory area and each frame corresponds to a record item. The record item contains a sampled data frame field and a frame sequence number field and is appended to form a first-in-first-out queue for subsequent steps to read. Simultaneously, the data acquisition module assigns and records a frame sequence number for the current sampled data frame. This frame sequence number is generated by a monotonically increasing counter maintained by the data acquisition module, and its data type is an unsigned 64-bit integer. When the current data stream processing task starts, the counter initializes the frame sequence number variable of the previous frame to 0 and performs an incrementing assignment once after each successfully acquired sampled data frame. The assignment relationship is expressed by the formula: ; in This indicates the frame number corresponding to the currently sampled data frame. Indicates the frame number corresponding to the previous sampled data frame, symbol This indicates an assignment operation; the plus sign represents integer addition, and after the assignment is completed, it will... Write the frame number field of the record item and Write-back overwrite For use in incremental generation of the next frame; After the frame sequence number is written, the data acquisition module marks the record item as "ready" in memory and outputs the handle of the record item to the subsequent processing pipeline, and outputs the sampled data frame that has been read and whose frame sequence number has been associated and stored.
[0026] In this specific embodiment, S3 includes: After receiving a ready record item, the metadata generation module uses the trigger time of the sampling data frame corresponding to the record item as a unified sampling benchmark. The metadata generation module first reads the device identifier preset by the UAV from the UAV's read-only storage area and uses it as an immutable field to participate in subsequent association. The device identifier is a 16-byte binary identifier that is written at the factory of the UAV and remains unchanged during the operation of this data stream processing task. The metadata generation module obtains a high-precision timestamp corresponding to the sampled data frame from a time source. The time source consists of a hardware timer and a time synchronization module, and the hardware timer uses... To achieve continuous counting at the counting resolution, when the sampling data frame triggers an interrupt, the interrupt service routine latches the hardware timer count value as the original timestamp value of the frame and writes it into the record item, so that the high-precision timestamp and the sampling data frame are bound at the same trigger time and do not depend on the scheduling delay of subsequent processing threads. The metadata generation module obtains the location information corresponding to the sampled data frame from the positioning module at the trigger time. The positioning module is a GNSS positioning module that continuously outputs positioning solutions and maintains the latest positioning solution record in shared memory. The location information adopts the WGS-84 coordinate system and includes three items: latitude, longitude, and altitude. The latitude and longitude adopt a coordinate system with latitude and longitude of 10 ... The location is represented by a signed 32-bit fixed-point number in degrees and the height is represented by a signed 32-bit integer in millimeters. The metadata generation module reads the latest location solution record and aligns its timestamp with the high-precision timestamp before writing it into the record item to complete the binding of location and trigger time. The metadata generation module reads the frame sequence number written in step S2 from the record item and uses this frame sequence number as the sequential identifier of the sampled data frame. The frame sequence number is consistent with that in step S2, using a monotonically increasing unsigned 64-bit integer, and is denoted as in this paragraph. ; After completing the above field collection, the metadata generation module combines the device identifier, high-precision timestamp, location information, and frame sequence number according to a preset field format to generate metadata and establishes a one-to-one association with the sampled data frame. The metadata handle is then filled back into the record item, enabling subsequent steps to simultaneously index the sampled data frame and metadata through the same record item. The combination relationship is expressed by the formula: ; in This represents the metadata structure corresponding to the currently sampled data frame. This indicates the device identifier. This refers to the high-precision timestamp. This indicates the location information, and its internal structure includes latitude, longitude, and altitude in sequence. The symbol represents the frame number, and the left arrow (←) indicates assignment and write operations. This indicates an ordered combination constructed according to the field order, and the sampled data frame and the metadata are output after the metadata structure is written.
[0027] In this specific embodiment, S4 includes: After receiving the sampled data frame and metadata, the sampling and leaf generation module performs normalized encoding on the metadata and combines it with the sampled data frame according to a preset field order to generate leaf input. The normalized encoding adopts a deterministic TLV format and encodes each field in the metadata separately. The field identifier occupies 1 byte and is used to uniquely indicate the field semantics. The field length occupies 4 bytes and uses big-endian byte order of unsigned integers to represent the number of bytes of the field content. The field content is the binary value of the corresponding field and the encoding byte order of the same field remains consistent in different frames. The field identifier value is fixedly set to the device identifier field. The high-precision timestamp field is The location information field is The frame sequence number field is The device identifier field contains the device identifier. Furthermore, the length is fixed at 16 bytes, and the high-precision timestamp field contains a high-precision timestamp. Furthermore, the length is fixed at 8 bytes and uses big-endian byte order encoding for unsigned integers. The position information field contains position information. Furthermore, the latitude, longitude, and altitude are concatenated sequentially, with latitude and longitude encoded using big-endian byte order (signed 32-bit fixed-point numbers) and altitude encoded using big-endian byte order (signed 32-bit integers). This ensures that the location information field has a fixed length of 12 bytes, and the frame sequence number field contains the frame sequence number. Furthermore, the length is fixed at 8 bytes and it uses big-endian byte order encoding for unsigned integers; The sampling and leaf generation modules simultaneously maintain the current micro-batch leaf counter. The It is set to 0 when this data stream processing task starts, incremented by one after each leaf fingerprint is written to the current micro-batch Merkle tree, and set to 0 again after the periodic signature and batch root update are completed. The system determines that the current sampled data frame is the first frame of the current micro-batch and writes the previous micro-batch root into the leaf input to achieve overlapping leaf binding. The previous micro-batch root takes the previous micro-batch root variable. Furthermore, the length is fixed at 32 bytes and written in the form of the original byte sequence. Its writing position is set after the beginning of the leaf input and before all normalized encoded metadata, thereby ensuring that the verification end can extract and recalculate the binding value at a definite position. To ensure the deterministic nature of the overall parsing of the leaf input, the sampling and leaf generation module writes a fixed-length header at the beginning of the leaf input. The head It consists of a version number field and a flag field, with the version number field occupying 1 byte and taking the value of 1. The flag field occupies 1 byte and is used to indicate whether the previous micro-batch root is included. The bit is set to 1 if the condition is met, and 0 otherwise. Then, the normalized encoded metadata is concatenated sequentially according to the field identifiers in ascending order, followed by the sampled data frame payload. The sampled data frame payload consists of a frame length prefix and a frame byte sequence. The frame length prefix occupies 4 bytes and uses unsigned big-endian byte order encoding to determine the number of bytes in the sampled data frame. Finally, the leaf input is obtained, and its combination relationship is expressed by the formula: ; in This represents the leaf input corresponding to the current sampled data frame. This indicates an operation that concatenates bytes without separators in a given order. This refers to the fixed-length head. Indicates in The value is taken as the root of the previous micro-batch. And in The batch root write segment takes the value of an empty byte sequence. Indicates the current metadata The normalized encoding result completed according to the TLV rules The sampled data frame payload contains the frame length prefix and the sampled data frame byte sequence. The symbol ← indicates an assignment operation that writes the result on the right and outputs it as a leaf input.
[0028] In this specific embodiment, S5 includes: The streaming hash computation unit receives leaf input. The streaming hash calculation unit performs a streaming hash calculation to obtain the leaf fingerprint without changing the byte order of the leaf input. The streaming hash calculation unit uses the SHA-256 hash algorithm and the output length is fixed at 32 bytes. When processing each frame of leaf input, the streaming hash calculation unit creates a hash context, initializes the hash context to the initial link value of SHA-256, and clears the cumulative message length counter. The streaming hash calculation unit reads data sequentially from the starting byte of the leaf input, using a fixed input block of 4096 bytes, and calls the incremental update interface to send the block data into the hash context. During each incremental update, the input block is cached and compressed according to the 64-byte message group boundary of SHA-256, and the cumulative message length counter is accumulated synchronously, thereby ensuring that even if the leaf input length exceeds the single memory copy limit, the hash processing can be completed with constant memory usage. After completing the incremental update of all bytes of the leaf input, the streaming hash calculation unit executes the end interface to perform standard SHA-256 padding on the hash context and outputs the final digest as the leaf fingerprint. The padding process includes appending a single bit "1" to the end of the message, appending several bits "0" until the length satisfies the modulo 512 bits remainder 448 bits, and writing the bit length representation of the cumulative message length counter as a 64-bit unsigned integer to ensure that the digest is sensitive to the input length and reproducible. The generation relationship of the leaf fingerprint is expressed by the formula: ; in This represents the leaf fingerprint corresponding to the current sampled data frame. SHA256(•) represents a function that performs a hash operation on the input byte sequence using the SHA-256 algorithm and outputs a 32-byte digest. This indicates the current leaf input, and the symbol ← indicates an assignment operation that writes the calculation result on the right to the output. After obtaining the leaf fingerprint, the sampling and leaf generation module writes the leaf fingerprint into the leaf fingerprint buffer and associates it with the sampling data frame that generated the leaf input and its metadata. The association is based on the frame sequence number. The leaf fingerprint is used as the primary key to create an index entry in the cache and store the index entry. The record handle enables subsequent gap processing and Merkel accumulation steps to locate the corresponding leaf fingerprint using the same frame number and perform consistency processing, finally outputting the leaf fingerprint. .
[0029] In this specific embodiment, S6 includes: The gap processing module receives the leaf fingerprint corresponding to the current sampled data frame. and current metadata Then, from the current metadata Read the frame number of the current frame. With high-precision timestamps It also reads the frame number of the previous frame from the status register of the gap processing module. High-precision timestamp of the previous frame , wherein and The values are initialized to 0 and 0 respectively when this data stream processing task starts, and are updated to the values of that frame after each frame is processed. and The gap processing module makes a judgment. Is it equal to To determine the continuity of frame numbers, if the determination result is continuous, no gap metadata is generated and only the leaf fingerprint is used. This step outputs and synchronously performs a state update. and When the judgment result is discontinuous, gap metadata is generated based on the missing interval between the previous frame and the current frame. The gap metadata It consists of the start and end frame numbers of the gap and the time range, and the start frame number of the gap is defined as follows: and take the value The gap termination frame number is defined as and take the value The start timestamp of the time range is defined as follows: and take the value The end timestamp of the time range is defined as and take the value The relationship between the aforementioned gap boundary and the time range can be expressed by the following formula: ; in Indicates the starting frame number of the gap. Indicates the gap termination frame number. Indicates the start timestamp of the time range of the gap. Indicates the end timestamp of the gap time range. Indicates the previous frame number. Indicates the current frame sequence number. This represents the high-precision timestamp of the previous frame. This represents the high-precision timestamp of the current frame; the ← symbol indicates an assignment operation. The notch processing module will... and Encode into a byte sequence according to the TLV normalization encoding rules consistent with step S4. The field identifier occupies 1 byte and is fixed as the gap start frame sequence number field. Gap Termination Frame Sequence Number Field Time range start timestamp field Time range end timestamp field The field length occupies 4 bytes and is represented in big-endian byte order as an unsigned integer. The content length of all four fields is fixed at 8 bytes. and Uses big-endian byte order encoding for unsigned 64-bit integers and and The big-endian byte order encoding of unsigned 64-bit integers is adopted to ensure that synonymous inputs of missing metadata produce consistent encoding results in different operating environments; Then the above The notched leaf fingerprint is calculated by inputting the data into the same streaming hash calculation unit as in step S5 and using the same SHA-256 incremental update and output termination process. The fingerprints of the notched leaves are output first according to the arrival order. Then output the current leaf fingerprint. This allows step S7 to sequentially write the current microbatch Merkle tree, and simultaneously performs a state update after output is complete. and To ensure continuity of the next frame, the judgment is based on the latest processed frame.
[0030] In this specific embodiment, S7 includes: The Merkel accumulation and proof module receives leaf fingerprints and gap leaf fingerprints when they exist, and writes them sequentially into the Merkel leaf layer of the current microbatch in the order of arrival to generate the current microbatch root and form the Merkel proof path corresponding to the sampled data frame. The Merkle tree is a binary Merkle tree, and the node hash algorithm is the same as in step S5, using SHA-256. The length of each node value is fixed at 32 bytes, and the maximum leaf number threshold for the current micro-batch is fixed at [value missing]. And the Merkel tree height is fixed at [value]. To meet The Merkel accumulation and proof module establishes a node value storage table in memory. Node valid flag table ,in Indicates the level as And the index is The node values and satisfy It is a leaf layer and For the root layer, Indicates and Is the corresponding node valid and Indicates that it is valid. Indicates invalid; When a leaf fingerprint arrives, the module reads the current micro-batch leaf counter. And use its current value as the leaf index of that leaf in the leaf layer. Write the fingerprint of the leaf And set bit Then Increment one to ensure that the leaves arriving later obtain unique indices in order, and that the gap leaf fingerprint and the leaf fingerprint share the index space, so that the leaf order of the Merkle tree is consistent with the output order of step S6; After each leaf is written, an incremental update at the node level is performed, with the incremental update based on the leaf index. Starting from the first level, check upwards layer by layer whether adjacent sibling node pairs are formed, where when When the index is even, the index of the adjacent sibling node is And when When the index is odd, the index of the adjacent sibling node is At the same level If and only if And when the valid flag of its adjacent sibling node is 1, the parent node is calculated and written to the upper level. Parent node index The parent node calculation uses a fixed concatenation order and takes the child node with the smaller index as the left child node to ensure consistent results across different implementations. The parent node calculation relationship is expressed by the formula: ; in Indicates the level as And the index is The value of the parent node. Represents the node level and its value ranges from 0 to... , Indicates the parent node in the hierarchy An index that satisfies the condition that its left child index is And the index of the right child node is , This function represents the operation of performing a SHA-256 hash on an input byte sequence and outputting a 32-byte node value. This represents a concatenation operation that directly concatenates the byte sequence of the left child node value with the byte sequence of the right child node value in order without introducing a separator. The symbol ← indicates an assignment / write operation. Write the valid flag corresponding to the last bit in the parent node. And Add one and will Updated to The same adjacent merge check is performed upwards until no adjacent sibling node pairs can be formed at that level, thus completing the layer-by-layer accumulation of the Merkle tree as the leaves are reached one by one; Leaf fingerprints corresponding to the sampled data frames The module will assign the frame number of the sampled data frame when writing to the leaf layer. Its leaf index Establish the association and create the proof path record corresponding to the sampled data frame. The proof path record From length of The sequence of entries is constituted, and each entry contains the value of its sibling node. Position of sibling nodes ,in Taken from the same level as the current node The values of adjacent sibling nodes and by reading Obtain and store in byte sequence form. For position bits and when the current node index Set to 1 when the index is even to indicate that the sibling node is to the right of the current node and when the index of the current node is even. When the value is odd, it is set to 0 to indicate that the sibling node is to the left of the current node, and Depend on And it is deduced hierarchically as follows This ensures that the proof path entries correspond one-to-one with the Merkle tree levels; When the number of leaves in the current micro-batch reaches At that time, the root node Set as valid and identified as the current micro-batch root Merkel's accumulation and proof module is based on the stated Recorded in and The Merkel proof path for forming the sampled data frame is then output, along with the current micro-batch root. and the Merkel proof path
[0031] In this specific embodiment, S8 includes: The periodic signature and output module continuously receives the current micro-batch root. Merkel proof path corresponding to the sampled data frame Simultaneously, based on preset periodic conditions, it is determined whether to perform batch sealing and digital signature on the current micro-batch. The preset periodic conditions are jointly constrained by a leaf quantity threshold and a time length threshold, and the leaf quantity threshold is taken from the value defined in step S7. The time length threshold is fixed. The unit is microseconds, and the periodic signature and output module maintains the current micro-batch leaf counter. Using the same counter instance as steps S4 and S7, the periodic signature and output module also maintains the current microbatch start timestamp. Compared to the current micro-batch termination timestamp ,in exist And receive the high-precision timestamp from the current frame metadata. When written as Each time a frame is received Updated to be overwritten This ensures that the start and end timestamps of the batch are consistent with the timestamps of the frames that actually enter the Merkel accumulation process; When the periodic signature and output module detects achieve Or detected achieve At that time, mark the current micro-batch status as "pending signature" and freeze the current micro-batch root. Previous micro-batch root and batch number ,in The previous micro-batch root is initialized for step S1 and persisted after each batch signing is completed, with a fixed length of 32 bytes. It is an unsigned 64-bit integer, which is read from non-volatile memory when the current data stream processing task starts and incremented by one after each batch signature is completed and written back to ensure the batch sequence number is continuous; Then construct the signature data. The signature data It is obtained by deterministic byte sequence encoding and concatenation in a fixed field order. The field order is as follows: signature data version number, batch number, current microbatch start timestamp, current microbatch end timestamp, previous microbatch root, and current microbatch root. The signature data version number field is 1 byte long and has a value of The batch serial number field is 8 bytes long and encoded in unsigned big-endian byte order. The start timestamp field and the end timestamp field are both 8 bytes long and are encoded in unsigned big-endian byte order. and The previous micro-batch root field and the current micro-batch root field are both 32 bytes long and are written separately. and The original byte sequence allows the verifier to reconstruct the signature data in the same field order and perform signature verification. The signature calculation is performed by the hardware security unit corresponding to the private key, which is denoted as [private key name] in this paragraph. The hardware security unit uses the Elliptic Curve Digital Signature Algorithm (ECDSA) with the curve parameter secp256r1. It first performs SHA-256 hashing on the signature data before signing, and the signature output is a digital signature. And the length is fixed at 64 bytes and consists of 32 bytes. With 32 bytes The digital signature is constructed by concatenating elements in sequence, and the generation relationship of the digital signature is expressed by the formula: ; in This indicates the digital signature corresponding to the current micro-batch, ECDSA_P256_SHA256_Sign. This indicates that the input data is pre-hashed using SHA-256 on curve secp256r1 and then ECDSA signed. Signature function for byte sequences, This represents the private key corresponding to the digital certificate described in step S1. This represents the byte sequence of the signature data; the left arrow (←) indicates an assignment / write operation. In obtaining Afterwards, the periodic signature and output module will Write to the batch root memory area of non-volatile memory to overwrite the update. An atomic commit process of "writing new values to spare slots, verifying write integrity, and switching valid flags" is adopted to ensure that batch roots do not generate inconsistent states in the event of a power outage. and Perform associated storage and use Write it as an index key into the batch signature index table to support subsequent batch retrieval; Finally, the periodic signature and output module encapsulates each cached result record within this micro-batch into verification data and outputs it. The verification data includes the sampled data frame and metadata for each sampled data frame. Leaf fingerprints Merkel's proof path Current micro-batch root Signature data and digital signatures And after the output is complete Clear and and Clear to begin the next micro-batch accumulation and signing process.
[0032] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any equivalent substitutions or modifications made by those skilled in the art within the scope of the technology disclosed in the present invention, based on the technical solution and inventive concept of the present invention, should be covered within the scope of protection of the present invention.
[0033] This invention employs a combined structure of streaming hashing, micro-batch Merkle accumulation, and periodic digital signatures to form a verifiable, continuous chain of evidence for UAV sensor data throughout its entire lifecycle, from generation to transmission, storage, and processing. Specifically, at the moment of sensor triggering, sampled data frames are acquired, and metadata containing device identifiers, high-precision timestamps, and frame sequence numbers is generated simultaneously. After normalization and encoding, this metadata, along with the sampled data frames, forms leaf inputs, and streaming hashing is immediately performed to obtain leaf fingerprints, establishing a fingerprint commitment that is "fixed instantly upon sampling" from the source. Subsequently, the leaf fingerprints are written into a micro-batch Merkle tree in arrival order and incrementally updated to obtain micro-batch root data, simultaneously forming a Merkle proof path corresponding to the sampled data frames. This achieves frame-by-frame verifiable integrity proof without requiring high-cost signing of each frame. When preset periodic conditions are met, the signed data is digitally signed, providing a non-repudiable anchor for the root data, allowing any subsequent frame of data to be verified through the leaf fingerprints and proof paths to determine if it belongs to the signed and confirmed data set, thus suppressing the risks of data injection, data tampering, and data replay.
[0034] To address the shortcomings of existing technologies, such as susceptibility to replacement and splicing at batch boundaries and difficulty in proving missing intervals in frame loss and interruption, this invention further introduces three improvements to the algorithm structure: inter-batch root linking, overlapping leaf binding, and gap leaf mechanism. First, the signature data of the periodic signature simultaneously includes the root of the current micro-batch and the root of the previous micro-batch, creating a chain constraint between the root values of adjacent batches, improving cross-batch continuity and resistance to splicing and tampering. Second, the root of the previous micro-batch is written into the leaf input of the first frame of the current micro-batch, allowing the root of the previous batch to participate in the first leaf hash of the next batch, achieving overlapping binding of batch boundaries. This strengthens inter-batch correlation at the leaf level, reducing the possibility of attackers maintaining superficial consistency by replacing data in a single batch. Third, when frame sequence numbers are discontinuous, gap metadata representing the missing interval is generated and a gap leaf fingerprint is calculated. The missing interval is incorporated into the Merkle accumulation process in the form of a verifiable commitment, thus ensuring that frame loss and interruption are not merely manifested as missing data, but as verifiable and auditable evidence of missing data, further enhancing the credibility of evidence collection and the overall security of the system.
Claims
1. A method for processing UAV data streams with instantaneous safety awareness capabilities, characterized in that, include: S1. Obtain the digital certificate and corresponding private key bound to the drone, and set the preset constant to the initial value of the previous micro-batch root. S2. Acquire the sampling data frame at the trigger moment when the sensor generates the sampling data frame; S3. Generate metadata for the sampled data frame. The metadata includes device identifier, high-precision timestamp, and frame sequence number. S4. Standardize and encode the metadata, and combine it with the sampled data frame according to the preset field order to generate the leaf input. When the sampled data frame is the first frame of the current micro-batch, write the root of the previous micro-batch into the leaf input. S5. Perform streaming hash calculation on the leaf input to obtain the leaf fingerprint; S6. Determine the continuity based on the frame number of the current frame and the frame number of the previous frame. If they are not continuous, generate gap metadata representing the missing interval, and perform normalized encoding and streaming hash calculation to obtain the gap leaf fingerprint. S7. Write the leaf fingerprints and the gap leaf fingerprints when they exist into the Merkle tree of the current micro-batch in the order of arrival to generate the current micro-batch root, and generate the Merkle proof path for the leaf fingerprints corresponding to the sampled data frames. S8. When the preset periodic conditions are met, construct signature data including the current micro-batch root and the previous micro-batch root, digitally sign the signature data using the private key, update the current micro-batch root to the new previous micro-batch root, and generate verification data associated with the sampled data frame.
2. The UAV data stream processing method with instantaneous safety perception capability according to claim 1, characterized in that, S1 includes: Obtain the digital certificate bound to the drone and the private key corresponding to the digital certificate; Perform a certificate chain verification on the digital certificate to determine if the digital certificate is valid; When the digital certificate is in a valid state, a preset constant is written into the memory as the initial batch root, and the initial batch root is assigned the initial value of the previous micro-batch root. This value is used in subsequent steps to write the previous micro-batch root in the leaf input construction step and to reference the previous micro-batch root when constructing signature data in the periodic signature and inter-batch root linking steps.
3. The UAV data stream processing method with instantaneous safety perception capability according to claim 1, characterized in that, S2 include: At the trigger moment when the sensor outputs a sampling data frame, the data acquisition module of the UAV reads the sampling data frame from the output interface of the sensor; Record the corresponding frame number for the sampled data frame and associate the frame number with the sampled data frame for storage; The sampled data frame that has been read and associated with the storage is output.
4. The UAV data stream processing method with instantaneous safety perception capability according to claim 1, characterized in that, S3 include: Obtain the pre-set device identifier of the drone; At the trigger time of acquiring the sampled data frame, a high-precision timestamp corresponding to the sampled data frame is obtained from the time source; At the triggering time, the location information corresponding to the sampled data frame is obtained from the positioning module; Obtain the frame number associated with the sampled data frame; The device identifier, the high-precision timestamp, the location information, and the frame sequence number are combined according to a preset field format to generate the metadata, and the metadata is associated with the sampled data frame. Output the sampled data frame and the metadata.
5. The UAV data stream processing method with instantaneous safety perception capability according to claim 1, characterized in that, S4 include: The device identifier, high-precision timestamp, location information, and frame sequence number of the metadata are respectively normalized and encoded. The normalization and encoding includes writing field identifier, field length, and field content for each field. The leaf input is generated by combining the normalized encoded metadata with the sampled data frame according to the preset field order. When the sampled data frame is the first frame of the current micro-batch, the root of the previous micro-batch is written into the leaf input and the writing position is the preset position of the leaf input to achieve overlapping leaf binding. Output the leaf input.
6. The UAV data stream processing method with instantaneous safety perception capability according to claim 1, characterized in that, S5 include: The leaf input is input into the streaming hash calculation unit in byte order, and the hash calculation of the leaf input is performed using an incremental update method. After all data processing of the leaf input is completed, the leaf fingerprint is output. The leaf fingerprint is associated with the sampled data frame that generated the leaf input and then cached. Output the leaf fingerprint.
7. The UAV data stream processing method with instantaneous safety perception capability according to claim 1, characterized in that, S6 include: Get the frame number of the current frame and the frame number of the previous frame, and determine whether the frame number of the current frame is equal to the frame number of the previous frame plus one. When the judgment result is not equal, determine the start and end frame numbers of the gap, where the start frame number of the gap is the frame number of the previous frame plus one, and the end frame number of the gap is the frame number of the current frame minus one. Obtain the high-precision timestamp corresponding to the previous frame and the high-precision timestamp corresponding to the current frame, and determine the corresponding time range from the high-precision timestamp corresponding to the previous frame to the high-precision timestamp corresponding to the current frame. The gap start and end frame numbers and the time range are combined to generate gap metadata. After the gap metadata is normalized and encoded, streaming hash calculation is performed to obtain the gap leaf fingerprint. Output the notched leaf fingerprint and the leaf fingerprint corresponding to the current frame. If the judgment result is equal, only output the leaf fingerprint corresponding to the current frame.
8. The UAV data stream processing method with instantaneous safety perception capability according to claim 1, characterized in that, S7 includes: Write the leaf fingerprints and the notched leaf fingerprints into the current micro-batch of Merkel leaf sub-layers in the order of arrival and assign the corresponding leaf indices. After each leaf fingerprint or notched leaf fingerprint is written, an incremental update is performed based on the node level of the Merkle tree. The incremental update includes hashing two adjacent node values at the same node level according to a preset splicing order to generate a parent node value, and then using the generated parent node value to continue hashing at the next node level until the current micro-batch root is obtained. During the incremental update process, the Merkel proof path corresponding to the sampled data frame is generated by taking the leaf fingerprint record corresponding to the sampled data frame and the sibling node value and sibling node position corresponding to the leaf fingerprint when participating in hash calculation at each node level. Output the current micro-batch root and the Merkel proof path.
9. The UAV data stream processing method with instantaneous safety perception capability according to claim 1, characterized in that, S8 includes: When the current micro-batch reaches a preset leaf quantity threshold or a preset time length threshold, it is determined that the preset cycle condition is met. When the preset periodic conditions are met, the batch number of the current micro-batch and the start and end timestamps of the current micro-batch are obtained, and the current micro-batch root, the previous micro-batch root, the batch number, and the start and end timestamps are combined in the order of preset fields to generate signature data. Perform a digital signature on the signature data using the private key; Write the current micro-batch root to memory to update the previous micro-batch root; The digital signature is associated with the signature data and stored, and the sampled data frame, the metadata, the leaf fingerprint, the Merkel proof path, the current micro-batch root, and the digital signature are output as result data.
10. A UAV data stream processing system with instantaneous safety awareness capability, used to execute the UAV data stream processing method with instantaneous safety awareness capability as described in any one of claims 1 to 9, characterized in that, include: The key management module is used to obtain the digital certificate and its corresponding private key bound to the drone, and initialize the root of the previous micro-batch with preset constants; The sampling and leaf generation module is used to acquire sampling data frames at the moment of sensor triggering and generate metadata including device identifier, high-precision timestamp and frame sequence number. After normalizing and encoding the metadata, it is combined with the sampling data frame to generate leaf input. The root of the previous micro-batch is written into the leaf input of the first frame of the current micro-batch, and streaming hash is performed on the leaf input to obtain the leaf fingerprint. The gap processing module is used to generate gap metadata based on frame sequence number continuity and hash the gap leaf fingerprint. The Merkel accumulation and proof module is used to write the leaf fingerprint and the gap leaf fingerprint when they exist into the Merkel tree of the current micro-batch to obtain the current micro-batch root and generate the Merkel proof path corresponding to the sampled data frame. The periodic signature and output module is used to digitally sign signature data including at least the current micro-batch root and the previous micro-batch root when a preset periodic condition is met, update the previous micro-batch root, and generate verification data associated with the sampled data frame. The verification data includes metadata, leaf fingerprint, Merkel proof path, current micro-batch root, and digital signature.
Citation Information
Patent Citations
Unmanned aerial vehicle bus data security record and credible evidence storage method and security record storage system
CN122179236A
Vehicle data storage and verification method and system based on lightweight block chain
CN122420314A