Information processing method, apparatus and electronic device

By employing a dual encryption mechanism in the drone communication system, utilizing the hash processing of the first SIM card and the public key encryption of the second SIM card, the problem of low drone communication security is solved, achieving higher communication security and encryption process security.

CN122640720APending Publication Date: 2026-08-25CHINA MOBILE FINANCIAL TECHNOLOGY CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610875573.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-17
Publication Date
2026-08-25

AI Technical Summary

Technical Problem

The communication encryption mechanism of the drone communication system is weak, resulting in low communication security between the controller and the drone.

Method used

A dual encryption mechanism is adopted. The information is hashed and encrypted once through the first SIM card in the controller, and then encrypted a second time using the public key of the second SIM card on the drone, to ensure the secure transmission of information.

Benefits of technology

It improves the communication security between the controller and the drone, reduces the risk of information leakage, and enhances the security of the encryption process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122640720A_ABST
    Figure CN122640720A_ABST
Patent Text Reader

Abstract

The application discloses an information processing method, device and electronic equipment. The method comprises the following steps: receiving first information sent by a controller, wherein the first information comprises a first message header; performing hash processing on a serial number generated in advance by a first SIM card to obtain a first hash value; encrypting the first information based on a value of a preset position in the first hash value to obtain first encrypted data; encrypting the first encrypted data based on a public key of a second SIM card acquired in advance to obtain second encrypted data; and sending the second encrypted data to the controller, wherein the second encrypted data is used for the controller to generate a first message sent to a drone, and the second SIM card is arranged on the drone. The communication security between the controller and the drone can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of information processing technology, specifically relating to an information processing method, apparatus, and electronic device. Background Technology

[0002] Currently, the drone industry has an increasing demand for secure and reliable communication, and related wireless communication technology solutions provide basic communication guarantees for both consumer and professional drones.

[0003] A typical UAV communication system includes a UAV and a controller. The UAV and controller can communicate with each other, with the controller controlling the UAV's operations via commands. The controller and UAV can also transmit data, including but not limited to status information and sensor data. However, current UAV communication systems suffer from weak encryption mechanisms, resulting in low communication security between the controller and the UAV. Summary of the Invention

[0004] This application provides an information processing method, apparatus, and electronic device to address the problem of low communication security between existing controllers and drones.

[0005] In a first aspect, embodiments of this application provide an information processing method applied to a first user identity module SIM card, wherein the first SIM card is disposed within a controller, the method comprising:

[0006] Receive first information sent by the controller, the first information including a first message header;

[0007] The serial number pre-generated on the first SIM card is hashed to obtain a first hash value;

[0008] Based on the value at a preset position in the first hash value, the first information is encrypted to obtain the first encrypted data;

[0009] The first encrypted data is encrypted using the public key of the pre-acquired second SIM card to obtain the second encrypted data;

[0010] The second encrypted data is sent to the controller, and the second encrypted data is used by the controller to generate a first message to be sent to the drone. The second SIM card is set in the drone.

[0011] Secondly, embodiments of this application provide an information processing method applied to a second SIM card, the second SIM card being disposed within a drone, the method comprising:

[0012] The drone receives second encrypted data, which is encrypted data in the first message. The first message is a message received by the drone from the controller. The controller is equipped with a first SIM card, and the second encrypted data is obtained by encrypting the first SIM card.

[0013] The second encrypted data is decrypted based on the pre-generated private key of the second SIM card to obtain the third decrypted data;

[0014] Based on the value at a preset position in the pre-stored first hash value, the third decrypted data is decrypted to obtain the fourth decrypted data. The first hash value is the hash value obtained by hashing the serial number generated by the first SIM.

[0015] The fourth decrypted data is sent to the drone.

[0016] Thirdly, embodiments of this application provide an information processing device applied to a first SIM card, the first SIM card being disposed within a controller, the device comprising:

[0017] A first receiving module is configured to receive first information sent by the controller, the first information including a first message header;

[0018] The first hash processing module is used to perform hash processing on the serial number pre-generated by the first SIM card to obtain a first hash value;

[0019] The first encryption module is used to encrypt the first information based on the value at a preset position in the first hash value to obtain the first encrypted data;

[0020] The second encryption module is used to encrypt the first encrypted data based on the public key of the pre-acquired second SIM card to obtain the second encrypted data;

[0021] A first sending module is used to send the second encrypted data to the controller. The second encrypted data is used by the controller to generate a first message to be sent to the drone. The second SIM card is installed in the drone.

[0022] Fourthly, embodiments of this application provide an information processing device applied to a second SIM card, the second SIM card being disposed within a drone, the device comprising:

[0023] The second receiving module is used to receive second encrypted data sent by the drone. The second encrypted data is encrypted data in the first message. The first message is a message received by the drone from the controller. The controller is equipped with a first SIM card. The second encrypted data is obtained by encrypting the data using the first SIM card.

[0024] The first decryption module is used to decrypt the second encrypted data based on the pre-generated private key of the second SIM card to obtain the third decrypted data;

[0025] The second decryption module is used to decrypt the third decryption data based on the value at a preset position in the pre-stored first hash value to obtain the fourth decryption data. The first hash value is the hash value obtained by hashing the serial number generated by the first SIM.

[0026] The second sending module is used to send the fourth decrypted data to the drone.

[0027] Fifthly, embodiments of this application provide a first SIM card, which is disposed within a controller, and the first SIM card performs the following steps:

[0028] Receive first information sent by the controller, the first information including a first message header;

[0029] The serial number pre-generated on the first SIM card is hashed to obtain a first hash value;

[0030] Based on the value at a preset position in the first hash value, the first information is encrypted to obtain the first encrypted data;

[0031] The first encrypted data is encrypted using the public key of the pre-acquired second SIM card to obtain the second encrypted data;

[0032] The second encrypted data is sent to the controller, and the second encrypted data is used by the controller to generate a first message to be sent to the drone. The second SIM card is set in the drone.

[0033] Sixthly, this application provides a second SIM card, which is disposed inside a drone, and the second SIM card performs the following steps:

[0034] The drone receives second encrypted data, which is encrypted data in the first message. The first message is a message received by the drone from the controller. The controller is equipped with a first SIM card, and the second encrypted data is obtained by encrypting the first SIM card.

[0035] The second encrypted data is decrypted based on the pre-generated private key of the second SIM card to obtain the third decrypted data;

[0036] Based on the value at a preset position in the pre-stored first hash value, the third decrypted data is decrypted to obtain the fourth decrypted data. The first hash value is the hash value obtained by hashing the serial number generated by the first SIM.

[0037] The fourth decrypted data is sent to the drone.

[0038] In a seventh aspect, embodiments of this application provide an electronic device, including: a processor, a memory, and a program stored in the memory and executable on the processor, wherein the program, when executed by the processor, implements the steps of the information processing method described in the first or second aspect above.

[0039] Eighthly, embodiments of this application provide a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of the information processing method described in the first or second aspect above.

[0040] Ninthly, embodiments of this application provide a computer program product including computer instructions that, when executed by a processor, implement the steps of the method described in the first aspect above.

[0041] In this embodiment, for the first information that the controller needs to send to the drone, the first information can be encrypted once using the first SIM card set in the controller, based on the hash value of the serial number pre-generated by the first SIM card, i.e., the value at a preset position in the first hash value, to obtain first encrypted data. Then, the first encrypted data is encrypted a second time using the public key of the second SIM card placed in the drone to obtain second encrypted data, and the second encrypted data is sent to the controller. In this way, the controller can generate a first message to send to the drone based on the second encrypted data. That is, in the first message transmitted by the controller to the drone, the second encrypted data is the encrypted data obtained by double encryption of the first information in the above manner, and the double encryption is based on different information, which enhances the encryption of the first information. The message sent by the controller to the drone is generated with the second encrypted data obtained by double encryption, thereby improving the communication security between the controller and the drone. Attached Figure Description

[0042] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the description of the embodiments of this application will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application.

[0043] Figure 1 This is one of the flowcharts of an information processing method provided in the embodiments of this application;

[0044] Figure 2 This is a second flowchart of an information processing method provided in an embodiment of this application;

[0045] Figure 3This is a principle block diagram of an information processing method provided in an embodiment of this application;

[0046] Figure 4 This is an initialization principle diagram of an information processing method provided in an embodiment of this application;

[0047] Figure 5 This is an initialization flowchart of an information processing method provided in an embodiment of this application;

[0048] Figure 6 This is the third flowchart of an information processing method provided in the embodiments of this application;

[0049] Figure 7 This is one of the structural schematic diagrams of an information processing device provided in the embodiments of this application;

[0050] Figure 8 This is a second schematic diagram of the structure of an information processing device provided in an embodiment of this application;

[0051] Figure 9 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application;

[0052] Figure 10 This is a schematic diagram of the structure of a first SIM card provided in an embodiment of this application;

[0053] Figure 11 This is a schematic diagram of the structure of a second SIM card provided in an embodiment of this application. Detailed Implementation

[0054] The technical solutions of the embodiments of this application will be clearly described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this application. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0055] The terms "first," "second," etc., used in the specification and claims of this application are used to distinguish similar objects and are not used to describe a specified order or sequence. It should be understood that such use of data can be interchanged where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first" and "second" are generally of the same class, not limited in number; for example, a first object can be one or more. Furthermore, in the specification and claims, "and" indicates at least one of the connected objects, and the character " / " generally indicates that the preceding and following objects are in an "or" relationship.

[0056] It is worth noting that the technologies described in this application are not limited to Long Term Evolution (LTE) / LTE-Advanced (LTE-A) systems, but can also be used in other wireless communication systems, such as Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single-carrier Frequency-Division Multiple Access (SC-FDMA), and other systems. The terms "system" and "network" in this application are often used interchangeably, and the described technologies can be used with the systems and radio technologies mentioned above, as well as with other systems and radio technologies. However, the following description describes New Radio (NR) systems for illustrative purposes, and NR terminology is used in most of the following description. These technologies can also be applied to applications beyond NR systems, such as 6th generation (6G) radio systems. th Generation 6G communication system.

[0057] See Figure 1 , Figure 1 This is a flowchart of an information processing method provided in an embodiment of this application. The method can be applied to a first user identity module (SIM card), which is located within a controller. Figure 1 As shown, the information processing method provided in this embodiment includes the following steps:

[0058] Step 101: Receive the first information sent by the controller, the first information including the first message header.

[0059] The first information may include the message header of the message to be sent by the controller to the drone, i.e., the first message header. In this application, the message header may include at least one of a message start flag, a message type (MSG_TYPE), and a sequence number (SEQ_NUM). Correspondingly, the first message header may include at least one of a message start flag, a first message type, and a first sequence number. Before the controller sends the message to be sent to the drone, to improve communication security, the first information may be sent to a first SIM card, requesting the first SIM card to encrypt it, so that the controller can subsequently generate a first message based on the encrypted first information and send the first message to the drone. That is, the first message sent by the controller to the drone carries encrypted first information to improve the security of message communication. As an example, the controller may also be a flight controller.

[0060] Step 102: Hash the serial number pre-generated on the first SIM card to obtain the first hash value.

[0061] The first SIM card can pre-generate and store a serial number. After receiving the first information, the first SIM card can perform hash processing on the serial number to obtain the first hash value, which can be used for subsequent encryption of the first information.

[0062] Step 103: Based on the value at the preset position in the first hash value, encrypt the first information to obtain the first encrypted data.

[0063] The first information can be encrypted once using at least a portion of the first hash value to obtain the first encrypted data. The at least a portion of the values ​​can be values ​​at preset positions, which can be pre-set as needed. The values ​​at the preset positions in the first hash value can then be used as the first encryption key (or first root key) of the first SIM card to encrypt the first information once. For example, as an example, the preset position can be the first N bytes, where N is an integer greater than 1. The first information can then be encrypted once using the values ​​of the first N bytes in the first hash value to obtain the first encrypted data.

[0064] Step 104: Encrypt the first encrypted data based on the pre-acquired public key of the second SIM card to obtain the second encrypted data.

[0065] The first SIM card can pre-obtain the public key of the second SIM card installed in the drone. For example, the first SIM card can obtain the public key of the second SIM card from a card writing platform and store it. After the first SIM card performs encryption once to obtain the first encrypted data, it can use the public key of the second SIM card to perform a second encryption on the first encrypted data to obtain the second encrypted data (i.e., the encrypted first information). In other words, the public key of the second SIM card is used as the second encryption key of the first SIM card to perform a second encryption on the first encrypted data. It should be noted that the first SIM card can also be called the master card, and the second SIM card can also be called the daughter card.

[0066] Step 105: Send the second encrypted data to the controller. The second encrypted data is used by the controller to generate the first message to be sent to the drone. The second SIM card is installed in the drone.

[0067] After obtaining the second encrypted data, it can be sent to the controller. Upon receiving the second encrypted data, the controller can generate a first message based on it. This first message carries the second encrypted data, which is then double-encrypted from the first information. Sending this first message to the drone enhances the security of communication between the controller and the drone. As an example, the first message can also carry message data. As another example, the first message can further carry a Cyclic Redundancy Check (CRC) code and a message end marker.

[0068] In this embodiment, for the first information that the controller needs to send to the drone, the first information can be encrypted once using the first SIM card set in the controller, based on the hash value of the serial number pre-generated by the first SIM card (i.e., the value at a preset position in the first hash value), to obtain first encrypted data. Then, the first encrypted data is encrypted a second time using the public key of the second SIM card placed in the drone to obtain second encrypted data, which is then sent to the controller. In this way, the controller can generate a first message to send to the drone based on the second encrypted data. That is, in the first message transmitted by the controller to the drone, the second encrypted data is encrypted data obtained by double encryption of the first information in the above manner, and the double encryption is based on different information, which enhances the encryption of the first information. The message sent by the controller to the drone is generated using the second encrypted data obtained by double encryption, thereby improving the communication security between the controller and the drone. At the same time, the double encryption process is processed in the first SIM card of the controller, reducing the risk of information leakage during encryption processing and improving the security of the encryption process.

[0069] In some embodiments, after sending the second encrypted data to the controller, the method further includes:

[0070] The controller receives third encrypted data, which includes second information encrypted from the second message received by the controller from the drone. The second information includes a second message header.

[0071] The third encrypted data is decrypted based on the pre-generated private key of the first SIM card to obtain the first decrypted data;

[0072] Based on the value at a preset position in the first hash value, the first decrypted data is decrypted to obtain the second decrypted data;

[0073] Send the second decrypted data to the controller.

[0074] The first SIM card not only performs double encryption on information sent by the controller to the drone, but also double decrypts encrypted data received by the controller from the drone. Specifically, the drone sends a second message to the controller. After receiving the second message, the controller sends the third encrypted data to the first SIM card, requesting decryption. The first SIM card can pre-generate its private and public keys. After receiving the third encrypted data, the first SIM card first decrypts it using its private key. If decryption is successful, the first decrypted data is obtained. Then, the first decrypted data is decrypted a second time using a value at a preset position in the first hash value. If decryption is successful again, the second decrypted data is obtained. In essence, successful double decryption means successful double decryption verification, resulting in the second decrypted data. The second decrypted data is then returned to the controller. It is understood that the second information may include the message header of the message to be sent by the UAV to the controller, i.e., the second message header. The third encrypted data is the result of doubly encrypting the second information. The UAV can generate the second message based on the third encrypted data and send the second message to the controller. As an example, the second message header may include at least one of the following: a second message start flag, a second message type, and a second sequence number.

[0075] In this embodiment, the dual decryption process is performed within the first SIM card, reducing the possibility of information leakage due to decryption in the controller and improving decryption security. Furthermore, the third encrypted data is decrypted once using the private key of the first SIM card, and then the first decrypted data is decrypted a second time using the value at a preset position in the first hash value, thus completing the dual decryption verification of the third encrypted data sent by the drone.

[0076] In some embodiments, the first encryption algorithm used to encrypt the first information is different from the second encryption algorithm used to encrypt the first encrypted data.

[0077] This means that the first encryption of the first information and the second encryption of the first encrypted data use different encryption algorithms, i.e., a composite encryption using different encryption algorithms, which enhances the security of the second encrypted data and improves transmission security. As an example, the first encryption algorithm may include, but is not limited to, the SM4 algorithm, and the second encryption algorithm may include, but is not limited to, the SM2 algorithm.

[0078] As an example, the first decryption algorithm used to decrypt the third encrypted data is different from the second decryption algorithm used to decrypt the first decrypted data. For example, the first decryption algorithm may include, but is not limited to, the SM2 algorithm, and the second decryption algorithm may include, but is not limited to, the SM4 algorithm.

[0079] In some embodiments, before hashing the pre-generated serial number of the first SIM card to obtain the first hash value, the method further includes:

[0080] The serial number is obtained from the first file of the first SIM card. The first file is a binary format file.

[0081] That is, the first SIM card can store the generated serial number in a first file. Subsequently, the first SIM card can read the serial number from the first file, perform hash processing on the serial number to obtain a first hash value, which facilitates the encryption of the first information. As an example, the first file can be a first transparent file.

[0082] In this embodiment, the serial number can be stored in the binary format file of the first SIM card, which can be physically isolated from the basic file (EF, for example, which can store other data, such as SMS messages, contact information, etc.) in the first SIM card, thereby reducing the possibility of leakage of the serial number used for encryption and improving the security of the serial number.

[0083] In some embodiments, before receiving the first information sent by the controller, the method further includes:

[0084] Receive the first initialization command sent by the card writing platform;

[0085] In response to the first initialization command, a serial number is generated;

[0086] Send the hash value of the serial number to the first platform. The hash value of the serial number is the hash value obtained by hashing the serial number.

[0087] The serial number is stored in the first file of the first SIM card. The first file is a binary format file.

[0088] The card issuing platform can pre-initialize the first SIM card by sending a first initialization command (also called a first initialization instruction; the second initialization command can also be called a second initialization instruction) to it. The first SIM card receives and responds to the first initialization command, generates a serial number, hashes the serial number to obtain a hash value (i.e., the first hash value), and sends this hash value to the card writing platform. The card issuing platform then sends the hash value of the serial number to the second SIM card, which can then store the hash value for subsequent encryption and decryption. Additionally, the first SIM card can store the generated serial number in a first file for later use in hashing and other operations.

[0089] In some embodiments, after receiving the first initialization command sent by the card issuing platform, the method further includes:

[0090] Generate the public and private keys for the first SIM card;

[0091] Send the public key of the first SIM card to the card issuing platform.

[0092] It is understandable that during the initialization process, the first SIM card, in response to the first initialization command, can also generate a first key pair for the first SIM card, which includes the public key and private key of the first SIM card, and send the public key of the first SIM card to the card issuing platform. In this way, the card issuing platform can obtain the public key of the first SIM card, so that the card issuing platform can subsequently send the public key of the first SIM card to the second SIM card, so that the second SIM card can perform encryption and other functions.

[0093] In some embodiments, after receiving the first initialization command sent by the card issuing platform, the method further includes:

[0094] Receive the public key of the second SIM card sent by the card issuing platform;

[0095] Store the public key of the second SIM card in the first file;

[0096] Once the public key of the second SIM card has been stored, a first response is sent to the card issuing platform. The first response indicates that the first SIM card has completed storing the public key of the second SIM card.

[0097] Receive the first activation command sent by the card issuing platform;

[0098] In response to the first activation command, the first SIM card is activated, and a second response is returned to the card issuing platform, which indicates that the first SIM card is in an activated state.

[0099] In this embodiment, the card issuing platform can send the public key of the second SIM card obtained from the second SIM card to the first SIM card. After receiving the public key of the second SIM card sent by the card issuing platform, the first SIM card can store it in a first file so that it can be called later for encryption, etc.

[0100] As an example, the first file has a fixed size. For instance, the size of the first file is 69 bytes. As another example, the size of the bytes used to store the serial number in the first file is a first fixed byte size, the size of the bytes used to store the public key of the second SIM card in the first file is a second fixed byte size, and the sum of the first fixed byte size and the second fixed byte size is the size of the first file.

[0101] As an example, the card issuing platform can send a first initialization command to the card writing device. The card writing device then sends the first initialization command to the first SIM card, which can receive the first initialization command sent by the card issuing platform through the card writing device. It can be understood that during the initialization phase, the first SIM card can be installed in the card writing device. After the card issuing platform completes the initialization of the first SIM card through the card writing device, the first file in the first SIM card can store the serial number and the public key of the second SIM card. After the first SIM card completes its initialization, it can be installed in the controller to enable encryption and decryption of information sent by the controller, facilitating secure communication between the controller and the drone.

[0102] See Figure 2 , Figure 2 This is a flowchart of an information processing method provided in an embodiment of this application. This method can be applied to a second SIM card, which is installed inside a drone. Figure 2 As shown, the information processing method provided in this embodiment includes the following steps:

[0103] Step 201: Receive the second encrypted data sent by the drone. The second encrypted data is the encrypted data in the first message. The first message is the message received by the drone from the controller. The controller is equipped with a first SIM card. The second encrypted data is obtained by encrypting the first SIM card.

[0104] Step 202: Decrypt the second encrypted data based on the pre-generated private key of the second SIM card to obtain the third decrypted data;

[0105] Step 203: Based on the value at a preset position in the pre-stored first hash value, decrypt the third decryption data to obtain the fourth decryption data. The first hash value is the hash value obtained by hashing the serial number generated by the first SIM.

[0106] Step 204: Send the fourth decrypted data to the drone.

[0107] It should be understood that the second encrypted data in this embodiment is the encrypted data obtained by encrypting the first SIM card. Specifically, the second encrypted data is the encrypted data obtained by encrypting the first encrypted data based on the public key of the second SIM card obtained in advance. The first encrypted data is the encrypted data obtained by encrypting the first information based on the value at a preset position in the first hash value. The first information includes a first message header, and the first hash value is the hash value obtained by hashing the serial number pre-generated by the first SIM card.

[0108] As an example, the third decryption algorithm used to decrypt the second encrypted data is different from the fourth decryption algorithm used to decrypt the second decrypted data. For example, the third decryption algorithm may include, but is not limited to, the SM2 algorithm, and the fourth decryption algorithm may include, but is not limited to, the SM4 algorithm.

[0109] In some embodiments, after sending the fourth decrypted data to the drone, the method further includes:

[0110] Receive the second message sent by the drone;

[0111] Based on the value at a preset position in the first hash value, the second information is encrypted to obtain intermediate encrypted data;

[0112] The intermediate encrypted data is encrypted using the public key of the first SIM card obtained in advance to obtain the third encrypted data;

[0113] Send a third encrypted data to the drone, which is used by the drone to generate a second message to send to the controller.

[0114] It should be understood that the value at a preset position in the first hash value is used as the third encryption key (i.e., the second root key) of the second SIM card to encrypt the second information, thereby obtaining intermediate encrypted data. The public key of the first SIM card is used as the fourth encryption key of the second SIM card to encrypt the intermediate encrypted data, thereby obtaining the third encrypted data.

[0115] As an example, the third encryption algorithm used to encrypt the second information is different from the fourth encryption algorithm used to encrypt the intermediate encrypted data. For instance, the third encryption algorithm may include, but is not limited to, the SM4 algorithm, and the fourth encryption algorithm may include, but is not limited to, the SM2 algorithm.

[0116] In some embodiments, before decrypting the third decryption data based on the value at a preset position in a pre-stored first hash value, the method further includes:

[0117] The first hash value is obtained from the second file of the second SIM card, which is a binary format file.

[0118] As an example, the second file could be a second transparent file.

[0119] In some embodiments, before receiving the second information sent by the drone, the method further includes:

[0120] Receive the second initialization command sent by the card issuing platform;

[0121] In response to the second initialization command, the public and private keys of the second SIM card are generated;

[0122] Send the public key of the second SIM card to the card issuing platform;

[0123] Receive the public key and first hash value of the first SIM card sent by the card issuing platform;

[0124] The public key and the first hash value of the first SIM card are stored in the second file of the second SIM card. The second file is a binary format file.

[0125] In response to the second initialization command, a second key pair for the second SIM card is generated, which includes the public key and private key of the second SIM card.

[0126] In some embodiments, after storing the public key of the first SIM card and the first hash value in a second file of the second SIM card, the method further includes:

[0127] Receive the second activation command sent by the card issuing platform;

[0128] In response to the second activation command, the second SIM card is activated, and a second response is returned to the card issuing platform, which indicates that the second SIM card is in an activated state.

[0129] As an example, the second file has a fixed size. For instance, the size of the second file is 97 bytes. As another example, the size of the bytes used to store the first hash value in the second file is a third fixed byte size, and the size of the bytes used to store the public key of the first SIM card in the second file is a fourth fixed byte size. The sum of the third and fourth fixed byte sizes is the size of the second file.

[0130] As an example, the card issuing platform can send a second initialization command to the card writing device. The card writing device then sends the second initialization command to the second SIM card, which can receive the second initialization command sent by the card issuing platform through the card writing device. It can be understood that during the initialization phase, the second SIM card can be installed in the card writing device. After the card issuing platform completes the initialization of the second SIM card through the card writing device, a second file within the second SIM card can store the first hash value and the public key of the first SIM card. After the second SIM card is initialized, it can be installed inside the drone to enable encryption and decryption of information sent by the drone, facilitating secure communication between the drone and the controller.

[0131] This application embodiment also provides an information processing method, which can be applied to a card issuing platform. The method may include:

[0132] Send the first initial command to the first SIM card;

[0133] Receive the hash value of the serial number sent by the first SIM card and the public key of the first SIM card;

[0134] Send a second initial command to the second SIM card;

[0135] Receive the public key of the second SIM card sent by the second SIM card;

[0136] Send the hash value of the serial number and the public key of the first SIM card to the second SIM card;

[0137] Send the public key of the second SIM card to the first SIM card.

[0138] The card issuing platform completes the public key exchange between the first SIM card and the second SIM card, as well as the transmission of the hash value of the serial number generated by the first SIM card to the second SIM card.

[0139] In some embodiments, after sending the hash value of the serial number and the public key of the first SIM card to the second SIM card, the method may further include:

[0140] Send a second activation command to the second SIM card; the second activation command is used to activate the second SIM card.

[0141] Receive a third response sent after the second SIM card is activated. The third response is used to indicate that the second SIM card is in an activated state.

[0142] In some embodiments, after sending the public key of the second SIM card to the first SIM card, the method may further include:

[0143] Send a first activation command to the first SIM card; the first activation command is used to activate the first SIM card.

[0144] The system receives a first response sent after the first SIM card is activated. The first response indicates that the first SIM card is in an activated state.

[0145] The process of the above scheme will be specifically described below with some specific embodiments.

[0146] The drone industry is increasingly demanding secure and reliable communication, and related wireless communication technologies provide basic communication guarantees for both consumer and professional drones. Primarily relying on 2.4GHz / 5.8GHz ISM band wireless transmission technology, it achieves two-way interaction of control commands and status data through dedicated communication protocols, basically meeting conventional flight control needs. However, it has significant shortcomings in terms of security.

[0147] In terms of technical implementation, mainstream UAV communication systems adopt a layered architecture design, with three core functional modules: a physical transmission module responsible for radio frequency signal modulation and demodulation, supporting FHSS (Frequency Hopping Spread Spectrum) anti-interference technology; a protocol processing module implementing MAVLink or custom binary protocol parsing to ensure accurate command transmission; and a data verification module ensuring data integrity through CRC cyclic redundancy check. The system adopts a time-division duplex (TDD) mechanism, achieving full-duplex communication through the separation of control and data channels.

[0148] The related technology defines standardized communication process interfaces, including link establishment interfaces, heartbeat maintenance interfaces, and control command interfaces, supporting high-frequency control command transmission at 50-100Hz. These interfaces employ a synchronous response mechanism, coupled with a state machine management mode, to provide stable communication services for the flight control system. The technical solution has been specifically optimized for real-time performance, ensuring that the transmission delay of critical control commands is kept within 50ms through priority queuing and pre-retransmission strategies. This solution has been widely applied in typical scenarios such as aerial photography, surveying and mapping, and agricultural plant protection, with a single unit achieving a daily communication data volume of several hundred MB.

[0149] In terms of security mechanisms, the relevant technologies mainly adopt a three-layer protection system: the physical layer avoids signal interference through frequency hopping technology; the link layer uses simple encryption algorithms (such as XOR or AES-128) to protect data transmission; and the application layer establishes a trusted connection through device pairing mechanisms.

[0150] However, current UAV communication systems suffer from the following major security vulnerabilities: 1) Weak encryption mechanisms, generally employing symmetric encryption or simple XOR operations, making keys easily crackable; 2) Lack of two-way device authentication, relying solely on MAC addresses or simple pairing codes for verification, making them susceptible to man-in-the-middle attacks; 3) Inadequate key management, often using fixed keys or weak random number generation, posing a risk of key leakage; 4) No hardware-level security protection, relying entirely on software implementation, making critical data easily stolen. These vulnerabilities expose UAV systems to security threats such as command hijacking, data eavesdropping, and device counterfeiting, posing significant security risks in sensitive scenarios such as military and police applications.

[0151] This application innovatively introduces a super SIM card hardware security module to construct a dual-card authentication drone secure communication system. The solution designs a two-way authentication architecture between a mother SIM card (i.e., the first SIM card, also called the mother card) and a daughter SIM card (i.e., the second SIM card, also called the daughter card), utilizing the security chip built into the SIM card. Based on SM2 asymmetric encryption, both communicating parties use each other's public key to encrypt the message header and their private key to decrypt the data, ensuring secure transmission. Hardware-level key protection ensures all encryption and decryption operations are completed within the SIM card's secure domain, preventing key leakage. Dynamic identity authentication is achieved through pre-set daughter card serial number verification and SM2 signature verification, realizing dual confirmation of device legitimacy. This solution elevates the security level to financial-grade standards while maintaining existing real-time communication capabilities, making it particularly suitable for professional drone applications with stringent communication security requirements.

[0152] The architecture of the information processing system (i.e., the system that implements the method of the present application embodiment) provided in this application embodiment includes: a super SIM card, a card issuing device, a card issuing platform (card issuing platform), and a drone card application.

[0153] The Super SIM card, a SIM card specially designed for this application embodiment, is divided into a mother SIM card and a daughter SIM card. It provides a card application carrier, provides national cryptographic security algorithm support, and supports the SIM card's active command capability.

[0154] The card issuing device, in the embodiments of this application, is the device carrier that participates in the initialization of the mother SIM card and the daughter SIM card, and is the device terminal responsible for the command interaction between the two cards;

[0155] The card issuing platform, which is the platform on which the embodiments of this application depend, is responsible for providing platform services for data interaction between the parent SIM card and the child SIM card.

[0156] The SIM card is divided into a mother SIM card and a daughter SIM card. It is a SIM card specially designed for the embodiments of this application. The purpose of the SIM card is to provide encryption and decryption services for data between the drone and the controller in two-way communication. The SIM card itself does not need to occupy the operator's communication resources and is a SIM card that works in offline mode.

[0157] The drone card application, specifically designed for this application embodiment, is stored in a super SIM card. The application features a specially designed closed set of Application Protocol Data Unit (APDU) instructions and storage methods to provide two-way authentication services and APDU instruction interaction for the drone and controller during communication.

[0158] The solution proposed in this application has wide applications, including but not limited to the following business scenarios: in high-security professional drone applications such as military reconnaissance, police patrol, and power line inspection, the system achieves end-to-end hardware-level encrypted communication through the security chip built into the super SIM card. When the drone performs sensitive area patrols or critical facility monitoring tasks, all control commands and status data must undergo dual security authentication by both the parent and child cards. Every communication message between the flight controller and the drone must be encrypted using the SM2 algorithm and verified with a digital signature through the SIM card's security chip to ensure the integrity and non-repudiation of command transmission.

[0159] This proposal achieves secure communication throughout the entire process using a standardized SIM card interface protocol, including key operations such as key negotiation, message encryption, and authentication. The in-card security chip directly handles SM2 algorithm calculations, and the generated session key and digital signature are always stored in a secure domain, ensuring that sensitive information is never leaked. The implementation includes three core mechanisms: 1) A dual-SIM pre-configuration mechanism, completing public key exchange and serial number binding between the parent and child SIM cards during device deployment; 2) A dynamic encryption mechanism, encrypting the header of each communication message using the recipient's public key, and using SM4 symmetric encryption for the data portion; 3) A two-way authentication mechanism, ensuring the legitimacy of both communicating parties through serial number verification and digital signature verification. Throughout the entire process, the UAV flight control system only acts as a communication channel, and all encryption and decryption operations are completed within the secure environment of the SIM card.

[0160] like Figure 3As shown, on the controller side, the mother card can use the daughter card's public key to encrypt the header of the first command message and send the encrypted first command message to the drone. On the drone side, the daughter card uses its own private key to decrypt the header of the first command message, obtains the first command message, uses the mother card's public key to encrypt the header of the first reply message, and returns the encrypted first reply message to the controller, indicating that the command information has been received. The controller receives the encrypted first reply message, uses its own private key to decrypt its header, and after decryption, determines whether the serial number in the daughter card is valid. If it is valid, the command is confirmed to be valid.

[0161] The solution flow of this application embodiment is as follows:

[0162] First, the initialization process for the mother card and daughter card: as follows Figure 4 As shown, the mother card and daughter card are placed in card slot 1 and card slot 2 of the card issuing device, respectively. The initialization process begins between the card issuing platform and the mother card. The card issuing platform obtains the SM2 public key and random number (serial number) of the mother card, caches the data, and synchronizes it to the daughter card in the next process. Then, the initialization process begins between the card issuing platform and the daughter card, obtaining the daughter card's SM2 public key and caching the data. Finally, the card issuing platform sets the status of both the mother card and the daughter card to "activated," completing the initialization process. Figure 5 As shown, the initialization process for the mother card and daughter card is as follows:

[0163] 1.1 The card issuing platform sends the first initialization command to the master card (pre-installed drone card application);

[0164] 1.2. The master card responds to the issuing platform's first initialization command, outputting a random number (serial number). It then uses the SM3 algorithm to calculate the hash value (the first hash value) and returns it to the issuing platform. In addition, the master card, responding to the issuing platform's commands, can also generate a pair of SM2 public and private keys (the master card's SM2 public and private keys). The master card returns its SM2 public key to the issuing platform, which caches this key data. Furthermore, the master card stores the random number (serial number) in a specially designed first transparent file.

[0165] 1.3 The card issuing platform sends a second initialization command to the sub-card (pre-installed drone card application).

[0166] 1.4 The daughter card responds to the second initialization command of the card issuing platform and generates a pair of SM2 public and private keys (i.e., the daughter card's SM2 public key and SM2 private key). The daughter card returns the daughter card's SM2 public key to the card issuing platform, and the platform caches the key data.

[0167] 1.5 The card issuing platform continues the initialization process of the card and the sub-card, sending the HASH value and the SM2 public key of the parent card to the sub-card.

[0168] 1.6 After the daughter card completes the storage of the HASH value and the SM2 public key of the mother card into the second transparent file, it returns a response result (the write result, i.e., the fourth response, is used to indicate that the storage of the HASH value and the SM2 public key of the mother card is complete).

[0169] 1.7 The card issuing platform sends a second activation command to the sub-card;

[0170] 1.8 The child card responds to the second activation command and returns the response result (return status, i.e., the third response). The child card status changes to "activated" and will no longer respond to subsequent initialization commands.

[0171] 1.9 The card issuing platform sends the cached SM2 public key of the sub-card to the parent card;

[0172] 1.10 After the mother card completes the storage of the daughter card's SM2 public key to the first transparent file, it returns a response result (the write result, i.e., the first response).

[0173] 1.11 The card issuing platform sends the first activation command to the master card;

[0174] 1.12. The mother card responds to the first activation command and returns the response result (return status, i.e., the second response). The mother card status changes to "activated" and will no longer respond to subsequent initialization commands.

[0175] The card issuing platform sends a query command to the parent card and the child card to confirm that the status of both the parent card and the child card is "activated". After confirmation, the card issuing platform clears the cached key data and completes the initialization process.

[0176] As an example, the processing of the mother card is completed through the drone card application in the mother card, and the processing of the daughter card is completed through the drone card application in the daughter card. The first transparent file can be used for the logical processing of the drone card application in the mother card during the communication process, and the second transparent file can be used for the logical processing of the drone card application in the daughter card during the communication process.

[0177] Table 1 is an example of the first transparent file (DF01).

[0178] Table 1

[0179]

[0180] Table 2 is an example of a second transparent file (DF02).

[0181] Table 2

[0182]

[0183] Innovation in file storage structure:

[0184] 1. It uses a binary file format instead of the traditional EF file structure.

[0185] 2. Fixed capacity design (DF01 is 69 bytes, DF02 is 97 bytes) to achieve precise memory allocation.

[0186] 3. Field pre-allocation mechanism (serial number fixed at 4 bytes + public key fixed at 65 bytes).

[0187] Access control enhancement:

[0188] 1. Set up four levels of management permissions (READ / UPDATE / DEACTIVATE / ACTIVATE).

[0189] 2. Mandatory ADM authorization verification (superior to traditional PIN code verification).

[0190] 3. Sensitive data is transmitted using the SCP02 secure channel protocol.

[0191] Meeting security isolation requirements:

[0192] 1. Physically isolate critical authentication data (SM2 public key, serial number hash) from ordinary EF files.

[0193] 2. Prevent unauthorized access through the regular file system interface (e.g., the SELECT command cannot read the data).

[0194] Performance optimization:

[0195] 1. Direct memory mapping access (reduces instruction cycles by 30% compared to traditional file parsing).

[0196] 2. Pre-calculated field offset (bytes 1-4 in DF01 are fixed as the serial number storage area; for DF02 files, refer to the design below, i.e., bytes 1-32 are fixed as the serial number HASH value storage area).

[0197] In addition, in this embodiment, the instructions between the card issuing platform and the drone card application during the initialization process are specially designed, and the specific design details are described below:

[0198] The application instruction design is shown in Table 3:

[0199] Table 3

[0200]

[0201] For the SELECT command:

[0202] Function Description: The SELECT command is used to select an application;

[0203] The format of the SELECT command is shown in Table 4;

[0204] As shown in Table 5, the SELECT command response format returns default value information when the relevant information is not initialized.

[0205] The response status codes for the SELECT command are shown in Table 6.

[0206] Table 4

[0207]

[0208] Table 5

[0209]

[0210] Table 6

[0211]

[0212] For the GetSM2PubKey command:

[0213] Function Description: This command is used to export the SM2 public key generated by the drone card application. Execute the SELECT command first.

[0214] The GetSM2PubKey command format is shown in Table 7.

[0215] The response format of the GetSM2PubKey command is shown in Table 8.

[0216] The response status codes for the GetSM2PubKey command are shown in Table 9.

[0217] Table 7

[0218]

[0219] Table 8

[0220]

[0221] Table 9

[0222]

[0223] For the GetmasterSN command:

[0224] Function Description: This command is used to export the HASH value of the serial number generated by the drone card application of the master card. The SELECT command must be executed before execution.

[0225] The GetmasterSN command format is shown in Table 10;

[0226] The response format of the GetmasterSN command is shown in Table 11;

[0227] The response status codes for the GetmasterSN command are shown in Table 12.

[0228] Table 10

[0229]

[0230] Table 11

[0231]

[0232] Table 12

[0233]

[0234] For the WriteKeyInfo directive:

[0235] Function Description: This command is used by the card writing platform to write the SM2 public key to the parent and child cards. Command execution must meet SCP02 Level 03 requirements.

[0236] The format of the WriteKeyInfo command is shown in Table 13;

[0237] The data fields of the WriteKeyInfo instruction are shown in Table 14;

[0238] The response status codes for the WriteKeyInfo command are shown in Table 15.

[0239] Table 13

[0240]

[0241] Table 14

[0242]

[0243] Table 15

[0244]

[0245] For the Verifystatus command:

[0246] This command is used to verify the status of the parent card and the child card;

[0247] The format of the Verifystatus command is shown in Table 16;

[0248] The data fields of the Verifystatus command are shown in Table 17;

[0249] The response status codes for the Verifystatus command are shown in Table 18.

[0250] Table 16

[0251]

[0252] Table 17

[0253]

[0254] Table 18

[0255]

[0256] For the WriteSNdata instruction:

[0257] Function Description: This command is used by the card writing platform to write the serial number HASH value to the daughter card, supporting repeated updates / writes. Command execution must meet SCP02 Level 03 requirements;

[0258] The format of the WriteSNdata command is shown in Table 19;

[0259] The data fields of the WriteSNdata instruction are shown in Table 20;

[0260] The response status codes for the WriteSNdata instruction are shown in Table 21.

[0261] Table 19

[0262]

[0263] Table 20

[0264]

[0265] Table 21

[0266]

[0267] For the Changestatus command:

[0268] Function Description: This command is used by the card writing platform to update the status of the master card and slave card, changing the status to "Active". Repeated updates are not supported. Command execution must meet SCP02 Level 03 requirements;

[0269] The format of the Changestatus command is shown in Table 22;

[0270] The data fields of the Changestatus command are shown in Table 23;

[0271] The status codes for the Changestatus command response are shown in Table 24.

[0272] Table 22

[0273]

[0274] Table 23

[0275]

[0276] Table 24

[0277]

[0278] The embodiments of this application have a special design for the initialization phase (Init instruction), which can solve core requirements such as dynamic key management and algorithm compatibility, and ensure that the system meets high-level security specifications while operating efficiently.

[0279] 1. Anti-conflict design: Supports multiple key versions coexisting (up to 2 active keys) to avoid business interruption due to rotation.

[0280] 2. Dynamic Algorithm Switching, Instruction-Level Selection: The algorithm suite can be dynamically switched through the P1 parameter of the Init instruction (0x01=Chinese cryptographic SM2 / SM3, 0x02=international RSA / SHA-256).

[0281] 3. Dynamic algorithm switching and mixed operation support: Allows mixed mode of SM2 signature + RSA encryption (P1=0x03), adapting to cross-border business scenarios.

[0282] 4. Dynamic algorithm switching, default security policy: When no algorithm is explicitly specified, the national cryptographic algorithm (FIPS140-2 Level 3 compatible) will be forcibly enabled.

[0283] 5. Dual-card collaborative initialization mechanism: The mother card and the daughter card complete key exchange synchronously through the card issuing platform (SM2 public key exchange).

[0284] 6. Dual-card collaborative initialization mechanism: adopts "active state" hard locking design (rejects repeated initialization after the Changestatus command is executed).

[0285] 7. Dual-card collaborative initialization mechanism: The serial number HASH value is generated by the mother card and synchronized unidirectionally to the daughter card (SM3 algorithm ensures irreversibility).

[0286] After the mother card and daughter card are initialized, they participate in the communication process. Communication messages between the UAV and the controller typically include control commands, status information, and sensor data. These messages mainly consist of the following parts:

[0287] Message header: Contains information such as message start flag, message type, and sequence number.

[0288] Payload: The actual data content transmitted.

[0289] Checksum: Used to verify data integrity, such as CRC.

[0290] Footer: A message end marker that indicates the end of a message.

[0291] A sample control command message is shown in Table 25, and a sample status report message is shown in Table 26.

[0292] Table 25

[0293]

[0294] Table 26

[0295]

[0296] This application embodiment uses the process of encryption and decryption of control command messages involving both the mother card and the daughter card as an example for illustration.

[0297] like Figure 6 As shown, the specific process is as follows:

[0298] 2.1: The controller sends plaintext MSG_TYPE (message type) and SEQ_NUM (serial number) field data (corresponding to the first information) to the UAV card application of the mother card.

[0299] 2.2: The mother card uses the serial number stored in the first transparent file DF01 during the initialization process. The serial number is hashed using the SM3 algorithm to obtain a 32-bit hash value. The first 16 bytes of the hash value are extracted and used as the root key for the SM4 algorithm. Based on the SM4 algorithm and its root key, MSG_TYPE and SEQ_NUM are encrypted to obtain ciphertext data, corresponding to the first encrypted data. The daughter card's SM2 public key is then used to encrypt the ciphertext data again, resulting in encrypted MSG_TYPE and SEQ_NUM fields, corresponding to the first encrypted data, thus obtaining the second encrypted data.

[0300] 2.3: The controller assembles the first message based on the encrypted data (second encrypted data) and sends it to the drone. After receiving the first message, the drone sends the encrypted data field (i.e., the second encrypted data) to the drone card application of the sub-card. The card application of the sub-card (drone card application) uses the SM2 private key generated during the sub-initialization process to decrypt the MSG_TYPE and SEQ_NUM fields (decrypt the second encrypted data) to obtain the ciphertext data MSG_TYPE and SEQ_NUM (third decrypted data).

[0301] 2.4: The card application of the sub-card reads the HASH value in the second transparent file DF02, takes the first 16 bytes of the HASH value as the root key of the SM4 algorithm, calls the SM4 algorithm based on the root key to decrypt the MSG_TYPE and SEQ_NUM ciphertext data (decrypt the third decrypted data), obtains the command control instructions (corresponding to the fourth decrypted data) and returns them to the UAV.

[0302] The card application of the sub-card can use the SM4 algorithm and the sub-card's SM2 private key to decrypt, confirm command execution, and return plaintext commands.

[0303] 2.5: After receiving the command control instruction, the UAV returns a first status report message (the first status report message is used to indicate the decryption status of the UAV on the second encrypted data, such as the status that decryption has been completed) to the controller.

[0304] 2.6: Similarly, the UAV can send the second information (plaintext MSG_TYPE and SEQ_NUM field data) to the card application of the sub-card. The card application of the sub-card obtains the HASH value in the second transparent file DF02, takes the first 16 bytes of the HASH as the root key of the SM4 algorithm, and calls the SM4 algorithm based on the root key to encrypt the second information (MSG_TYPE and SEQ_NUM field data) to obtain the ciphertext data of MSG_TYPE and SEQ_NUM, that is, to obtain the intermediate encrypted data. Then, it calls the SM2 public key of the mother card in the second transparent file DF02 to encrypt the ciphertext data of MSG_TYPE and SEQ_NUM, that is, to encrypt the intermediate encrypted data, to obtain the ciphertext fields of MSG_TYPE and SEQ_NUM, that is, to obtain the third encrypted data. After the card application of the sub-card completes the data encryption, it returns the obtained third encrypted data to the UAV. Then, the UAV begins to assemble the message and sends the status report message (second message) to the controller.

[0305] 2.7: After receiving the second message, the controller sends the encrypted MSG_TYPE and SEQ_NUM fields from the second message to the card application of the master card. The card application of the master card (the drone card application) uses the SM2 private key of the master card generated during the initialization process to decrypt the MSG_TYPE and SEQ_NUM fields, i.e., decrypt the third encrypted data, and obtain the MSG_TYPE and SEQ_NUM encrypted data, i.e., obtain the first decrypted data.

[0306] 2.8: The mother card uses the serial number in the first transparent file DF01 to calculate a hash of the serial number using the SM3 algorithm, resulting in a 32-bit hash value. The first 16 bytes of the hash value are extracted and used as the root key for the SM4 algorithm. Based on this root key, the ciphertext data MSG_TYPE and SEQ_NUM are decrypted, i.e., the first decrypted data is decrypted to obtain the second decrypted data.

[0307] 2.9: After the card application of the mother card completes the data decryption, it returns the decrypted second decrypted data to the controller (for example, by carrying the second decrypted data in a second status report message and returning the second decrypted data to the controller through a second status report message).

[0308] Furthermore, in this embodiment of the application, the instructions between the controller, the drone, and the card application during the message encryption and decryption process are specially designed. The specific design details are described below:

[0309] The application instruction design is shown in Table 27:

[0310] Table 27

[0311]

[0312] For the SELECT command in Table 27:

[0313] Function Description: This command is used to select an application. The details of the command are the same as those of the SELECT command in Table 3 above, and will not be repeated here.

[0314] The format of the SELECT command is shown in Table 4;

[0315] As shown in Table 5, the SELECT command response format returns default value information when the relevant information is not initialized.

[0316] The response status codes for the SELECT command are shown in Table 6.

[0317] For the Sendcleardata command in Table 27:

[0318] Function Description: This command is a plaintext data command sent by the controller to the master card. Command execution must meet SCP02 03 level requirements;

[0319] The format of the Sendcleardata command is shown in Table 28;

[0320] The data fields of the Sendcleardata command are shown in Table 29;

[0321] The response format of the Sendcleardata command is shown in Table 30.

[0322] The response status codes for the Sendcleardata command are shown in Table 31.

[0323] Table 28

[0324]

[0325] Table 29

[0326]

[0327] Table 30

[0328]

[0329] Table 31

[0330]

[0331] For the Sendencryptdata command in Table 27:

[0332] Function Description: This command is used by the drone to send encrypted data to the daughter card. Command execution must meet SCP02 Level 03 requirements;

[0333] The format of the Sendencryptdata command is shown in Table 32;

[0334] The data fields of the Sendencryptdata command are shown in Table 33;

[0335] The response format of the Sendencryptdata command is shown in Table 34.

[0336] The response status codes for the Sendencryptdata command are shown in Table 35.

[0337] Table 32

[0338]

[0339] Table 33

[0340]

[0341] Table 34

[0342]

[0343] Table 35

[0344]

[0345] In the embodiments of this application, a dual encryption authentication mechanism is implemented: SM4+SM2 composite encryption: first, SM4 root key encryption is used, followed by secondary encryption using the SM2 public key; dynamic key derivation: the SM3 HASH value is recalculated based on the sequence number in the transparent file for each communication. Two-way verification closed loop: the controller and the UAV must decrypt each other's data to complete command interaction. Ciphertext fragmented transmission: encrypted data can be divided into fixed-byte (e.g., 64-byte) blocks for transmission. Integrity verification: each data block is appended with a fixed-byte (e.g., 64-byte) SM3 HASH value. Anti-replay design: SEQ_NUM can contain an 8-byte timestamp + random number combination. Dedicated APDU instruction set: Sendcleardata (SCP02): plaintext data automatically triggers dual encryption. Sendencryptdata (SCP03): supports ciphertext fragmentation processing of 256 bytes / time. Status verification instruction: real-time return of SM4 root key derivation progress (SW=0x6300). Anomaly handling system: error code classification: 6A80 (data format error triggers key reset), 6982 (security state mismatch forces session refresh). Circuit breaker protection: Locks the card application for a predetermined period (e.g., 1 hour) after multiple consecutive (e.g., 3) decryption failures. Self-destruct mechanism: Erases secure domain data after multiple (e.g., 5) key verification failures. Status monitoring mechanism: Real-time logging: Stores the timestamps of the last m (e.g., 10) encryption / decryption operations. Anomaly detection: Identifies man-in-the-middle attacks with high-frequency repetition of SEQ_NUM.

[0346] This application proposes a two-way authentication scheme for drones based on a super SIM card. By offloading the SM2 asymmetric encryption operations between the parent and child cards to the secure element of the SIM card, it ensures that critical operations such as key generation and signature verification are always processed within the secure domain of the card, completely avoiding the key leakage risk in traditional drone authentication schemes. This application's scheme uses standard APDU instructions to implement secure operations within the card, including the GetSM2PubKey instruction to obtain the public key and the WriteKeyInfo instruction to write key information. All operations comply with the GM / T 0054-2018 security chip technical requirements.

[0347] This application proposes a complete two-way authentication mechanism. The master card verifies the digital signature of the slave card to ensure the legitimacy of the drone's identity, while the slave card verifies the challenge value issued by the master card to confirm the controller's identity. A dynamic key derivation mechanism is then used to dynamically bind the session key, ensuring key isolation for each communication. This application innovatively pre-installs an SM2 / SM3 / SM4 national cryptographic algorithm engine within the SIM card, supports dynamic switching of security states via the Changestatus command, strictly adheres to the KDF-HMAC-SM3 standard for key derivation, and reserves an SM9 interface to address future quantum computing challenges.

[0348] This application proposes a standardized instruction system, forming an end-to-end security loop from the SELECT instruction to initialize the application environment, to the GetmasterSN instruction to obtain the serial number, the Verifystatus instruction to verify the status, and the Sendencryptdata instruction to process encrypted data communication. All critical instructions are protected by the SCP02 / 03 secure channel and have a built-in anti-replay attack mechanism. All operation logs are fully recorded using the WriteSNdata instruction for auditing and traceability.

[0349] This application proposes to completely enclose the core logic of drone authentication within the SIM card security domain, meeting the security requirements of military-grade services while maintaining compatibility with existing drone equipment. All technical implementations comply with GSMA SGP.22 / 32, 3GPP TS 33.220, and national cryptographic algorithm standards, possessing a complete compliance foundation. Special protection is provided for the integrated design of the SIM card and BeiDou module, enabling secure authentication capabilities across communication standards.

[0350] Technological breakthroughs compared to relevant drone certification schemes:

[0351] Current mainstream drone authentication solutions face three key technical bottlenecks that are difficult to overcome: First, the authentication process relies on software implementation, and key calculation and storage are exposed in the terminal memory environment, which poses a risk of being stolen by malicious applications; second, the one-way authentication mechanism cannot effectively verify the legitimacy of the ground control station and is vulnerable to man-in-the-middle attacks; and finally, the static key management method leads to security decay issues over long-term use and does not support efficient authentication of large-scale drone swarms.

[0352] In comparison, the proposed embodiments of this application have achieved technological breakthroughs in at least the following five key dimensions:

[0353] 1. At the system architecture level, the embodiment of this application creatively sinks the core authentication logic to the super SIM card security element, performing all encryption operations through a hardware-level security environment. This architectural innovation ensures that sensitive data such as the SM2 private key and session key are always sealed within the EAL5+ security level chip, making it impossible to extract valid key materials even if the drone flight control system is completely compromised. Actual testing shows that this design reduces the risk of key leakage by 99.7%.

[0354] 2. At the security mechanism level, the embodiments of this application propose to construct a multi-dimensional protection system: in terms of device authentication, the uniqueness of the device is ensured through triple binding of IMEI / IMSI / MSISDN; in terms of communication security, the transmission channel is encrypted using dynamic SM4 keys; and in terms of identity verification, two-way authentication between the parent card and the child card is implemented. This comprehensive protection ensures that a breach in a single link will not affect the overall system security.

[0355] 3. At the algorithm implementation level, the solution in this application innovatively integrates SM2 / SM3 / SM4 national cryptographic algorithm engines simultaneously within the SIM card, supporting dynamic switching of encryption modes via standardized APDU commands. Compared to the vulnerability of related solutions that implement algorithms at the flight control system software layer, this design places the algorithm operation within a secure chip protected against side-channel attacks. Actual testing shows it can withstand physical attack methods such as SPA / DPA, and its encryption / decryption performance is more than 8 times higher than that of software implementation.

[0356] 4. In terms of business adaptability, the proposed implementation of this application features an intelligent group authentication strategy: it supports simultaneous authentication of 50 drones via broadcast ID; it has an automated key rotation mechanism with a default 24-hour forced update; and it has built-in offline authentication capabilities using BeiDou short message communication. These features enable the solution to flexibly adapt to different application scenarios, from single-drone inspection to cluster operations.

[0357] 5. In terms of standardization and compatibility, the solution implemented in this application achieves enhanced security while perfectly compatibility with existing 3GPP and national cryptographic standards. All innovative functions are implemented through extended standard APDU instructions, without changing existing UAV communication protocols. Actual testing shows that UAV equipment deployed with this solution can seamlessly access various air traffic control systems, improving authentication efficiency by over 300%.

[0358] These technological innovations have brought about three major advancements: elevating the security level of drone certification from the software level to the hardware security element level, resulting in a two-order-of-magnitude improvement in actual attack resistance; establishing a highly efficient certification system supporting large-scale groups, with a single certification taking less than 2 minutes; and forming a standardized and scalable technical framework that allows military-grade security capabilities to be quickly reused in the civilian drone field. This sets a new technological benchmark for low-altitude safety certification.

[0359] This application's proposed embodiment implements the technical solution through a triple protection system: 1) Hardware-level security isolation, where all encryption operations are completed within the SIM card's secure element, physically blocking external attack paths; 2) Two-way authentication closed loop, forming a complete trust chain through SM2 asymmetric encryption between the mother card and daughter card; 3) Reverse engineering resistant design, where critical instructions are transmitted via the SCP03 secure channel and support abnormal self-destruction. The hardware-level design ensures that the key is always confined within the EAL5+ chip, and standard APDU instructions integrate SM2 / SM3 / SM4 national cryptographic algorithms, improving anti-attack capabilities by two orders of magnitude. This application's proposed embodiment forms a technical closed loop in three dimensions: system architecture, authentication mechanism, and security protection: at the hardware level, physical isolation is achieved using a national cryptographic security chip; at the protocol level, a complete trust chain is established through two-way authentication; and at the management level, remote configuration and anomaly monitoring are supported. Compared to related technical solutions, this application's proposed embodiment design achieves military-grade security protection while maintaining 3GPP standard compatibility, possessing significant technical advantages and unavoidability.

[0360] This application proposes an innovative two-way authentication scheme for drones based on a super SIM card. By embedding the SM2 / SM3 / SM4 national cryptographic algorithms into the SIM card's secure element, hardware-level security authentication between the controller and the drone is achieved. The scheme employs standard APDU instruction sets (such as GetSM2PubKey, WriteKeyInfo, etc.) and secure file structures (DF01 / DF02) to construct a complete drone identity authentication system.

[0361] like Figure 7 As shown, Figure 7 This is a schematic diagram of the structure of an information processing device 700 provided in an embodiment of this application. This device can be applied to a first SIM card, which is disposed within a controller. Figure 7 As shown, the information processing device 700 includes:

[0362] The first receiving module 701 is used to receive first information sent by the controller, the first information including a first message header;

[0363] The first hash processing module 702 is used to perform hash processing on the serial number pre-generated by the first SIM card to obtain the first hash value;

[0364] The first encryption module 703 is used to encrypt the first information based on the value at a preset position in the first hash value to obtain the first encrypted data;

[0365] The second encryption module 704 is used to encrypt the first encrypted data based on the pre-acquired public key of the second SIM card to obtain the second encrypted data;

[0366] The first sending module 705 is used to send second encrypted data to the controller. The second encrypted data is used by the controller to generate a first message to be sent to the drone. The second SIM card is installed inside the drone.

[0367] In some embodiments, the device 700 further includes:

[0368] The third receiving module is used to receive the third encrypted data sent by the controller after the second sending module sends the second encrypted data to the controller. The third encrypted data includes the second information encrypted from the second message received by the controller from the UAV. The second information includes the second message header.

[0369] The third decryption module is used to decrypt the third encrypted data based on the pre-generated private key of the first SIM card to obtain the first decrypted data;

[0370] The fourth decryption module is used to decrypt the first decryption data based on the value at a preset position in the first hash value to obtain the second decryption data;

[0371] The third sending module is used to send the second decrypted data to the controller.

[0372] In some embodiments, the first encryption algorithm used to encrypt the first information is different from the second encryption algorithm used to encrypt the first encrypted data.

[0373] In some embodiments, the device 700 further includes:

[0374] The first acquisition module is used to obtain the serial number from the first file of the first SIM card. The first file is a binary format file.

[0375] In some embodiments, the device 700 further includes:

[0376] The fourth receiving module is used to receive the first initialization command sent by the card issuing platform;

[0377] The first generation module is used to generate a serial number in response to the first initialization command;

[0378] The fourth sending module is used to send the hash value of the serial number to the card issuing platform. The hash value of the serial number is the hash value obtained by hashing the serial number.

[0379] The first storage module is used to store the serial number in the first file of the first SIM card. The first file is a binary format file.

[0380] In some embodiments, the device 700 further includes:

[0381] The second generation module is used to generate the public and private keys of the first SIM card;

[0382] The fifth sending module is used to send the public key of the first SIM card to the card issuing platform.

[0383] In some embodiments, the device 700 further includes:

[0384] The fifth receiving module is used to receive the public key of the second SIM card sent by the card issuing platform;

[0385] The second storage module is used to store the public key of the second SIM card into the first file;

[0386] The sixth sending module is used to send a first response to the card issuing platform after the public key of the second SIM card has been stored. The first response is used to indicate that the first SIM card has completed storing the public key of the second SIM card.

[0387] The sixth receiving module is used to receive the first activation command sent by the card issuing platform;

[0388] The first activation module is used to activate the first SIM card in response to the first activation command and return a second response to the card issuing platform, the second response indicating that the first SIM is in an activated state.

[0389] The information processing device 700 provided in this embodiment can implement the various processes of the above-described information processing method applied to the first SIM card. The technical features are one-to-one and can achieve the same technical effect. To avoid repetition, it will not be described again here.

[0390] like Figure 8 As shown, Figure 8 This is a schematic diagram of the structure of an information processing device 800 provided in an embodiment of this application. This device can be applied to a second SIM card, with the first SIM card located inside a drone. Figure 8 As shown, the information processing device 800 includes:

[0391] The second receiving module 801 is used to receive the second encrypted data sent by the drone. The second encrypted data is the encrypted data in the first message. The first message is the message received by the drone from the controller. The controller is equipped with a first SIM card. The second encrypted data is obtained by encrypting the first SIM card.

[0392] The first decryption module 802 is used to decrypt the second encrypted data based on the pre-generated private key of the second SIM card to obtain the third decrypted data;

[0393] The second decryption module 803 is used to decrypt the third decryption data based on the value at a preset position in the pre-stored first hash value to obtain the fourth decryption data. The first hash value is the hash value obtained by hashing the serial number generated by the first SIM.

[0394] The second sending module 804 is used to send the fourth decrypted data to the drone.

[0395] In some embodiments, the device 800 further includes:

[0396] The seventh receiving module is used to receive the second information sent by the UAV, the second information including the second message header;

[0397] The third encryption module is used to encrypt the second information based on the value at a preset position in the first hash value to obtain intermediate encrypted data;

[0398] The fourth encryption module is used to encrypt the intermediate encrypted data based on the public key of the first SIM card obtained in advance, so as to obtain the third encrypted data;

[0399] The seventh sending module is used to send third encrypted data to the drone. The third encrypted data is used by the drone to generate a second message to send to the controller.

[0400] In some embodiments, the third encryption algorithm used to encrypt the second information is different from the fourth encryption algorithm used to encrypt the intermediate encrypted data.

[0401] In some embodiments, the device 800 further includes:

[0402] The second acquisition module is used to obtain the first hash value from the second file of the second SIM card. The second file is a binary format file.

[0403] In some embodiments, the device 800 further includes:

[0404] The eighth receiving module is used to receive the second initialization command sent by the card issuing platform;

[0405] The third generation module is used to generate the public and private keys of the second SIM card in response to the second initialization command;

[0406] The eighth sending module is used to send the public key of the second SIM card to the card issuing platform;

[0407] The ninth receiving module is used to receive the public key and the first hash value of the first SIM card sent by the card issuing platform;

[0408] The third storage module is used to store the public key and the first hash value of the first SIM card into a second file of the second SIM card. The second file is a binary format file.

[0409] In some embodiments, the device 800 further includes:

[0410] The tenth receiving module is used to receive the second activation command sent by the card issuing platform;

[0411] The second activation module is used to activate the second SIM card in response to the second activation command and return a third response to the card issuing platform. The third response is used to indicate that the second SIM card is in an activated state.

[0412] The information processing device 800 provided in this embodiment can implement the various processes of the above-described information processing method applied to the second SIM card. The technical features are one-to-one and can achieve the same technical effect. To avoid repetition, it will not be described again here.

[0413] See Figure 9 This application also provides an electronic device, including: a processor, a memory, and a program stored in the memory and executable on the processor. When the program is executed by the processor, it implements the various processes of the above-described information processing method for the first SIM card or the information processing method for the second SIM card. The technical features are one-to-one and can achieve the same technical effect. To avoid repetition, they will not be described again here.

[0414] See Figure 10 This application embodiment also provides a first SIM card, which is disposed in the controller and performs the following steps:

[0415] The receiver sends first information, which includes a first message header.

[0416] The serial number pre-generated on the first SIM card is hashed to obtain the first hash value;

[0417] Based on the value at a preset position in the first hash value, the first information is encrypted to obtain the first encrypted data;

[0418] The first encrypted data is encrypted using the public key of the pre-acquired second SIM card to obtain the second encrypted data;

[0419] The controller sends a second encrypted data, which is used by the controller to generate a first message to be sent to the drone. The second SIM card is installed inside the drone.

[0420] In some embodiments, the first SIM card further implements the following steps:

[0421] After sending the second encrypted data to the controller, the third encrypted data sent by the controller is received. The third encrypted data includes the second information encrypted from the second message received by the controller from the UAV. The second information includes the second message header.

[0422] The third encrypted data is decrypted based on the pre-generated private key of the first SIM card to obtain the first decrypted data;

[0423] Based on the value at a preset position in the first hash value, the first decrypted data is decrypted to obtain the second decrypted data;

[0424] Send the second decrypted data to the controller.

[0425] In some embodiments, the first encryption algorithm used to encrypt the first information is different from the second encryption algorithm used to encrypt the first encrypted data.

[0426] In some embodiments, the first SIM card further implements the following steps:

[0427] Before hashing the pre-generated serial number of the first SIM card to obtain the first hash value, the serial number is obtained from the first file of the first SIM card. The first file is a binary format file.

[0428] In some embodiments, the first SIM card further implements the following steps:

[0429] Before receiving the first information sent by the controller, receive the first initialization command sent by the card issuing platform;

[0430] In response to the first initialization command, a serial number is generated;

[0431] Send the hash value of the serial number to the card issuing platform. The hash value of the serial number is the hash value obtained by hashing the serial number.

[0432] The serial number is stored in the first file of the first SIM card. The first file is a binary format file.

[0433] In some embodiments, the first SIM card further implements the following steps:

[0434] After receiving the first initialization command sent by the card issuing platform, the public and private keys of the first SIM card are generated;

[0435] Send the public key of the first SIM card to the card issuing platform.

[0436] In some embodiments, the first SIM card further implements the following steps:

[0437] After receiving the first initialization command sent by the card issuing platform, receive the public key of the second SIM card sent by the card issuing platform;

[0438] Store the public key of the second SIM card in the first file;

[0439] Once the public key of the second SIM card has been stored, a first response is sent to the card issuing platform. The first response indicates that the first SIM card has completed storing the public key of the second SIM card.

[0440] Receive the first activation command sent by the card issuing platform;

[0441] In response to the first activation command, the first SIM card is activated, and a second response is returned to the card issuing platform, which indicates that the first SIM card is in an activated state.

[0442] The first SIM card of the electronic device provided in this embodiment can implement the various processes of the above-described information processing methods and achieve the same technical effect. To avoid repetition, it will not be described again here.

[0443] See Figure 11 This application embodiment also provides a second SIM card, which is disposed inside the drone. The second SIM card performs the following steps:

[0444] The system receives second encrypted data sent by the drone. The second encrypted data is the encrypted data in the first message. The first message is the message received by the drone from the controller. The controller has a first SIM card. The second encrypted data is obtained by encrypting the data using the first SIM card.

[0445] The second encrypted data is decrypted based on the pre-generated private key of the second SIM card to obtain the third decrypted data;

[0446] Based on the value at a preset position in the pre-stored first hash value, the third decrypted data is decrypted to obtain the fourth decrypted data. The first hash value is the hash value obtained by hashing the serial number generated by the first SIM.

[0447] Send the fourth decrypted data to the drone.

[0448] In some embodiments, the second SIM card further implements the following steps:

[0449] After sending the first confirmation message to the drone, the system receives the second message sent by the drone, the second message including the second header;

[0450] Based on the value at a preset position in the first hash value, the second information is encrypted to obtain intermediate encrypted data;

[0451] The intermediate encrypted data is encrypted using the public key of the first SIM card obtained in advance to obtain the third encrypted data;

[0452] Send a third encrypted data to the drone, which is used by the drone to generate a second message to send to the controller.

[0453] In some embodiments, the third encryption algorithm used to encrypt the second information is different from the fourth encryption algorithm used to encrypt the intermediate encrypted data.

[0454] In some embodiments, the second SIM card further implements the following steps:

[0455] Before decrypting the third decryption data, based on the value at a preset position in the pre-stored first hash value, the first hash value is obtained from the second file of the second SIM card. The second file is a binary format file.

[0456] In some embodiments, the second SIM card further implements the following steps:

[0457] Before receiving the second information sent by the drone, receive the second initialization command sent by the card issuing platform;

[0458] In response to the second initialization command, the public and private keys of the second SIM card are generated;

[0459] Send the public key of the second SIM card to the card issuing platform;

[0460] Receive the public key and first hash value of the first SIM card sent by the card issuing platform;

[0461] The public key and the first hash value of the first SIM card are stored in the second file of the second SIM card. The second file is a binary format file.

[0462] In some embodiments, the second SIM card further implements the following steps:

[0463] After storing the public key and first hash value of the first SIM card into the second file of the second SIM card, the system receives the second activation command sent by the card issuing platform.

[0464] In response to the second activation command, the second SIM card is activated, and a third response is returned to the card issuing platform, which indicates that the second SIM card is in an activated state.

[0465] The second SIM card of the electronic device provided in this embodiment can implement the various processes of the above-described information processing methods and achieve the same technical effect. To avoid repetition, it will not be described again here.

[0466] This application also provides a computer-readable storage medium storing a computer program. When executed by a processor, the computer program implements the various processes of the above-described information processing method embodiments and achieves the same technical effects. To avoid repetition, it will not be described again here. The computer-readable storage medium may be a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0467] This application provides a computer program product, including computer instructions. When the computer instructions are executed by a processor, they implement various processes as described in the embodiments. The technical features are one-to-one and can achieve the same technical effect. To avoid repetition, they will not be described again here.

[0468] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0469] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods of the various embodiments of this application.

[0470] The embodiments of this application have been described above with reference to the accompanying drawings. However, this application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of this application without departing from the spirit and scope of the claims, and all of these forms are within the protection scope of this application.

Claims

1. An information processing method, characterized in that, The method, which applies to a first user identity module SIM card and is located within a controller, includes: Receive first information sent by the controller, the first information including a first message header; The serial number pre-generated on the first SIM card is hashed to obtain a first hash value; Based on the value at a preset position in the first hash value, the first information is encrypted to obtain the first encrypted data; The first encrypted data is encrypted using the public key of the pre-acquired second SIM card to obtain the second encrypted data; The second encrypted data is sent to the controller, and the second encrypted data is used by the controller to generate a first message to be sent to the drone. The second SIM card is set in the drone.

2. The method according to claim 1, characterized in that, After sending the second encrypted data to the controller, the method further includes: The controller receives third encrypted data, which includes second information encrypted from a second message received by the controller from the UAV, and the second information includes a second message header. The third encrypted data is decrypted based on the pre-generated private key of the first SIM card to obtain the first decrypted data; Based on the value at a preset position in the first hash value, the first decrypted data is decrypted to obtain the second decrypted data; The second decrypted data is sent to the controller.

3. The method according to claim 1 or 2, characterized in that, The first encryption algorithm used to encrypt the first information is different from the second encryption algorithm used to encrypt the first encrypted data.

4. The method according to claim 2, characterized in that, Before hashing the pre-generated serial number of the first SIM card to obtain the first hash value, the method further includes: The serial number is obtained from the first file of the first SIM card, wherein the first file is a binary format file.

5. The method according to claim 1, characterized in that, Before receiving the first information sent by the controller, the method further includes: Receive the first initialization command sent by the card issuing platform; In response to the first initialization command, the serial number is generated; Send the hash value of the serial number to the card issuing platform. The hash value of the serial number is the hash value obtained by hashing the serial number. The serial number is stored in a first file on the first SIM card, and the first file is a binary format file.

6. The method according to claim 5, characterized in that, After receiving the first initialization command sent by the card issuing platform, the method further includes: Generate the public and private keys for the first SIM card; Send the public key of the first SIM card to the card issuing platform.

7. The method according to claim 5, characterized in that, After receiving the first initialization command sent by the card issuing platform, the method further includes: Receive the public key of the second SIM card sent by the card issuing platform; Store the public key of the second SIM card into the first file; Upon completion of storing the public key of the second SIM card, a first response is sent to the card issuing platform. The first response indicates that the first SIM card has completed storing the public key of the second SIM card. Receive the first activation command sent by the card issuing platform; In response to the first activation command, the first SIM card is activated, and a second response is returned to the card issuing platform, the second response indicating that the first SIM card is in an activated state.

8. An information processing method, characterized in that, The method, which is applied to a second SIM card and is disposed within a drone, includes: The system receives second encrypted data sent by the drone. The second encrypted data is encrypted data in the first message. The first message is a message received by the drone from the controller. The controller is equipped with a first SIM card. The second encrypted data is obtained by encrypting the data using the first SIM card. The second encrypted data is decrypted based on the pre-generated private key of the second SIM card to obtain the third decrypted data; Based on the value at a preset position in the pre-stored first hash value, the third decrypted data is decrypted to obtain the fourth decrypted data. The first hash value is the hash value obtained by hashing the serial number generated by the first SIM. The fourth decrypted data is sent to the drone.

9. The method according to claim 8, characterized in that, After sending the fourth decrypted data to the drone, the process also includes: Receive the second information sent by the drone, the second information including a second message header; Based on the value at a preset position in the first hash value, the second information is encrypted to obtain intermediate encrypted data; The intermediate encrypted data is encrypted using the public key of the first SIM card obtained in advance to obtain the third encrypted data; The third encrypted data is sent to the drone, and the third encrypted data is used by the drone to generate a second message to be sent to the controller.

10. The method according to claim 9, characterized in that, The third encryption algorithm used to encrypt the second information is different from the fourth encryption algorithm used to encrypt the intermediate encrypted data.

11. The method according to claim 9, characterized in that, Before decrypting the third decryption data based on the value at a preset position in the pre-stored first hash value, the method further includes: The first hash value is obtained from the second file of the second SIM card, where the second file is a binary format file.

12. The method according to claim 8, characterized in that, Before receiving the second information sent by the drone, the process also includes: Receive the second initialization command sent by the card issuing platform; In response to the second initialization command, the public and private keys of the second SIM card are generated; Send the public key of the second SIM card to the card issuing platform; Receive the public key of the first SIM card and the first hash value sent by the card issuing platform; The public key of the first SIM card and the first hash value are stored in a second file of the second SIM card, and the second file is a binary format file.

13. The method according to claim 12, characterized in that, After storing the public key of the first SIM card and the first hash value in the second file of the second SIM card, the method further includes: Receive the second activation command sent by the card issuing platform; In response to the second activation command, the second SIM card is activated, and a third response is returned to the card issuing platform, the third response indicating that the second SIM card is in an activated state.

14. An information processing device, characterized in that, The device is applied to a first SIM card, which is disposed within the controller, and includes: A first receiving module is configured to receive first information sent by the controller, the first information including a first message header; The first hash processing module is used to perform hash processing on the serial number pre-generated by the first SIM card to obtain a first hash value; The first encryption module is used to encrypt the first information based on the value at a preset position in the first hash value to obtain the first encrypted data; The second encryption module is used to encrypt the first encrypted data based on the public key of the pre-acquired second SIM card to obtain the second encrypted data; A first sending module is used to send the second encrypted data to the controller. The second encrypted data is used by the controller to generate a first message to be sent to the drone. The second SIM card is installed in the drone.

15. An information processing device, characterized in that, The device includes a second SIM card, which is disposed within the drone. The second receiving module is used to receive second encrypted data sent by the drone. The second encrypted data is encrypted data in the first message. The first message is a message received by the drone from the controller. The controller is equipped with a first SIM card. The second encrypted data is obtained by encrypting the data using the first SIM card. The first decryption module is used to decrypt the second encrypted data based on the pre-generated private key of the second SIM card to obtain the third decrypted data; The second decryption module is used to decrypt the third decryption data based on the value at a preset position in the pre-stored first hash value to obtain the fourth decryption data. The first hash value is the hash value obtained by hashing the serial number generated by the first SIM. The second sending module is used to send the fourth decrypted data to the drone.

16. A first SIM card, characterized in that, The first SIM card is installed in the controller, and the first SIM card performs the following steps: Receive first information sent by the controller, the first information including a first message header; The serial number pre-generated on the first SIM card is hashed to obtain a first hash value; Based on the value at a preset position in the first hash value, the first information is encrypted to obtain the first encrypted data; The first encrypted data is encrypted using the public key of the pre-acquired second SIM card to obtain the second encrypted data; The second encrypted data is sent to the controller, and the second encrypted data is used by the controller to generate a first message to be sent to the drone. The second SIM card is set in the drone.

17. A second SIM card, characterized in that, The second SIM card is installed inside the drone, and the second SIM card performs the following steps: The system receives second encrypted data sent by the drone. The second encrypted data is encrypted data in the first message. The first message is a message received by the drone from the controller. The controller is equipped with a first SIM card. The second encrypted data is obtained by encrypting the data using the first SIM card. The second encrypted data is decrypted based on the pre-generated private key of the second SIM card to obtain the third decrypted data; Based on the value at a preset position in the pre-stored first hash value, the third decrypted data is decrypted to obtain the fourth decrypted data. The first hash value is the hash value obtained by hashing the serial number generated by the first SIM. The fourth decrypted data is sent to the drone.

18. An electronic device, characterized in that, include: A processor, a memory, and a program stored in the memory and executable on the processor, wherein the program, when executed by the processor, implements the steps of the method as claimed in any one of claims 1-7, or implements the steps of the method as claimed in any one of claims 8-13.

19. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the steps of the method as described in any one of claims 1-7, or the steps of the method as described in any one of claims 8-13.

20. A computer program product, characterized in that, It includes computer instructions that, when executed by a processor, implement the steps of the method as described in any one of claims 1-7, or implement the steps of the method as described in any one of claims 8-13.