Detection of a remotely controlled aircraft through a managed network

The method and system address the inefficacy of IMSI catchers by detecting and controlling RCAVs within managed networks, ensuring network security and preventing unauthorized operations.

JP2025522325APending Publication Date: 2025-07-15D FEND SOLUTIONS AD LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2024570623
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-05-30
Filing Date
2023-05-30
Publication Date
2025-07-15

AI Technical Summary

Technical Problem

Existing methods for detecting and mitigating unauthorized remotely controlled aerial vehicles (RCAVs) using LTE networks are ineffective, particularly when IMSI catchers are not practical or applicable, and can affect unrelated users and lose track of RCAVs in wide areas.

Method used

A method and system for detecting RCAV-related communication units in managed networks through privileged access, utilizing communication-related information to identify and mitigate threats by monitoring, warning, and controlling RCAVs within these networks.

Benefits of technology

Effectively detects and mitigates unauthorized RCAVs by identifying and managing their communication within managed networks, preventing unauthorized operations and ensuring network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025522325000001_ABST
    Figure 2025522325000001_ABST
Patent Text Reader

Abstract

A computerized method for detecting remotely-controlled aerial vehicle (RCAV)-related communication units in one or more managed networks. The method can include obtaining communication-related information regarding one or more members of one or more managed networks using privileged access, or searching for RCAV-related communication units. The search corresponds to the detection of RCAV-related communication units, at least in part based on the communication-related information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Remotely controlled aerial vehicles (RCAVs) (including unmanned aerial vehicles (UAVs), drones, etc.) have evolved over the past two decades and have become a common tool for various applications such as surveillance, aerial photography, remote delivery, and entertainment, and are even used in military scenarios such as visual information collection or direct attacks. Many applications are generally considered beneficial, and many users act responsibly, but there are also many cases where such aircraft are used irresponsibly or maliciously. In response to the development and more general use of RCAVs, technologies have emerged that can monitor their use, warn when their use is unauthorized or risky, and sometimes mitigate such risks. Many RCAVs use direct wireless communication (RF) for control channels, and some detection, identification, and mitigation methods counter threats by addressing this type of communication.

Background Art

[0002] Recently, some remotely controlled aerial vehicles utilize the LTE network to connect to a remote controller. Since such communication has several unique features and characteristics different from direct wireless communication, such RCAV communication will not be detected in the way of detecting RF communication. Some of the differences relate to the fact that by using LTE, drone communication appears like any other call over the same LTE network, i.e., like a wireless conversation. Therefore, it is very difficult to identify RCAV communication. Even if it is identified, this communication is protected in the same way as voice communication in the same network, and due to the nature of cellular communication, it is even more difficult to track the communication. And ultimately, interfering with the communication between the RCAV and the remote controller or hijacking its communication channel poses a great challenge to systems trying to protect against misused RCAVs.

[0003] One common technique that can be thought of when dealing with such threats is the use of techniques such as IMSI grabbers / catchers and SUPI grabbers / catchers.

[0004] An International Mobile Subscriber Identity (IMSI) catcher is a phone tapping device that is used to intercept mobile phone traffic and track the location data of mobile phone users. Basically, a "fake" mobile tower operates between the target mobile phone and the actual tower of the service provider, which is considered a man-in-the-middle (MITM) attack. The 3G wireless standard provides some risk mitigation through mutual authentication required from both the handset and the network. However, sophisticated attacks may be able to downgrade 3G and LTE to non-LTE network services that do not require mutual authentication. IMSI catchers are used by law enforcement and intelligence agencies in many countries (WWW.WIKIPEDIA.ORG).

[0005] This is not a complete solution to the threat, but an RCAV that uses LTE as a communication channel can be detected or monitored using an IMSI catcher. However, in the near future, various RCAVs will use a managed network with security means, and it is expected that IMSI catchers will be rendered obsolete.

[0006] Furthermore, even when the use of an IMSI catcher is applicable, there are scenarios where it is not practical. The use of an IMSI catcher requires being physically close to the RCAV, and it is not practical to monitor a wide area without prior knowledge that such an RCAV might appear.

[0007] The use of technologies such as IMSI catchers can affect unrelated users on the same network and there is also a possibility of losing some RCAVs using the network.

[0008] In addition, there are other types of managed networks that do not use cellular - type connections through which RCAVs can communicate.

Prior Art Documents

Patent Documents

[0009]

Patent Document 1

Patent Document 2

Patent Document 3

Patent Document 4

Summary of the Invention

Problems to be Solved by the Invention

[0010] There is an increasing need to provide an efficient method for detecting and / or locating and / or mitigating unauthorized RCAVs that use a managed network where such IMSI catchers are ineffective.

Means for Solving the Problems

[0011] A system, method, and computer - readable medium as exemplified herein may be provided.

[0012] A method for RCAV detection may be provided.

[0013] Embodiments of the present disclosure will be more fully understood and recognized from the following detailed description together with the drawings.

Brief Description of the Drawings

[0014]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

DETAILED DESCRIPTION OF THE INVENTION

[0015] To provide a thorough understanding of the present invention, many specific details are set forth in the following detailed description. However, those skilled in the art will understand that the present invention may be practiced without these specific details. In other instances, well-known methods, procedures, and components have not been described in detail so as not to obscure the present invention.

[0016] The subject matter regarded as the present invention is particularly shown and distinctly claimed in the appended claims. However, the present invention, both as to its construction and method of operation, together with its objects, features, and advantages, will be best understood from the following detailed description read in conjunction with the accompanying drawings.

[0017] It will be recognized that, for the sake of brevity and clarity of illustration, the elements shown in the figures are not necessarily drawn to scale. For example, the dimensions of some elements may be exaggerated relative to other elements for clarity. Further, reference numbers may be repeated among the figures where appropriate to refer to corresponding or similar elements.

[0018] The illustrated embodiments of the present invention can be implemented using electronic components and circuits that are well known to those of ordinary skill in the art in many parts. Therefore, for the understanding and recognition of the concepts underlying the present invention, and in order not to obscure or deviate from the teachings of the present invention, as illustrated above, the details are not described more than is considered necessary.

[0019] Any reference to a method herein should be applied with the necessary modifications to a device or system capable of performing the method and / or to a non-transitory computer-readable medium storing instructions for performing the method.

[0020] Any reference to a system or device herein should be applied with the necessary modifications to a method that can be performed by the system and / or to a non-transitory computer-readable medium storing instructions executable by the system.

[0021] Any reference to a non-transitory computer-readable medium herein should be applied with the necessary modifications to a device or system capable of executing instructions stored on the non-transitory computer-readable medium and / or to a method for executing the instructions.

[0022] Any combination of any modules or units listed in any drawing, any combination of any parts of this specification and / or any claims can be provided.

[0023] This specification and / or the drawings may refer to a processor. The processor may be a processing circuit configuration. The processing circuit configuration may be implemented as a central processing unit (CPU), and / or as one or more other integrated circuits such as an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), a full-custom integrated circuit, or a combination of such integrated circuits.

[0024] Any combination of any steps of any method as exemplified in this specification and / or the drawings may be provided.

[0025] Any combination of any subject matters of any claims may be provided.

[0026] Any combination of a system, a unit, a component, a processor, and a sensor as exemplified in this specification and / or the drawings may be provided.

[0027] Methods, systems, and computer-readable media for RCAV detection and / or positioning and / or mitigation may be provided.

[0028] The RCAV can be programmed and / or otherwise configured to perform a task and / or mission. This can include arriving at a destination and / or performing an operation when arriving at the destination. Even when the destination is within the range of the RCAV, the RCAV can be considered to have arrived at the destination. When the RCAV is placed in a position that enables the RCAV to perform a task related to the destination, assume that the destination is within the range of the RCAV. Operations can include photographing a target, blasting a target associated with the destination, delivering a payload (which may or may not be a damaging payload) to the target, executing electronic countermeasures, obtaining information about the target, directing high-precision ammunition at the target, etc. The relaxation of the RCAV can include preventing the RCAV from performing a task and / or mission.

[0029] When referring to a "remote controller", in addition to a remote controller device, it includes any other control device such as a ground station, virtual reality goggles, smartphone or tablet, control stick, telemetry module, secondary remote controller (e.g., gimbal controller), smart controller (a controller that includes a screen and is often programmable), etc.

[0030] The RCAV can communicate with one or more other devices such as a remote controller having a communication unit using the RCAV communication unit. The RCAV communication unit and any communication unit that communicates with the RCAV communication unit are called RCAV-related communication units. An RCAV-related communication unit is a communication unit that participates in the communication between the RCAV and one or more other devices.

[0031] A managed network is a network that includes and can transfer RCAV-related communication between the RCAV and others, where neither the RCAV nor others manage the network.

[0032] For example, in many cases, the RCAV connects to a remote controller or other device directly through radio frequency (RF) communication. In other cases, such communication can be made through a separate network that is managed by an entity not related to the RCAV, where both the RCAV and the remote controller are members of that network. Each communicates with the network, and the network forwards that communication to the other. This example is an LTE network, and each of the RCAV and the remote controller can be a member of that network (and can have a SIM card, eSIM, IMSI / SUPI, etc.). Such a managed network will generally have some level of privileged access (or managed privilege) to the network administrator and infrastructure that can enable, for example, monitoring of communication, packet inspection, denial of access to members, member management, access to member identity databases, etc.

[0033] A method can be provided for accessing one or more managed networks through managed privileges to monitor (within the boundaries where available and permitted) some or all of the members of one or more managed networks and extract the presence of one or more members (RCAV-related communication units) that are part of the RCAV connection in the managed network.

[0034] The connection to a command and control system used by a method that can receive data from multiple systems can use the same managed network for communication or communicate externally from the network through other means.

[0035] Some air traffic can include a managed fleet, which may or may not use the same managed network for communication.

[0036] The method can interface with a UAV fleet management method (e.g., Amazon Prime Air) to verify the identity of a UAV that is part of the fleet, or to warn the UAV fleet management method from a threat posed by a UAV that is part of the fleet, or against a threat posed to a UAV that is part of the fleet.

[0037] The method can receive information from the UAV fleet management method and synthesize it with information received from a managed network to create a synthesized aviation status.

[0038] For similar purposes, the method can interface with other management methods (e.g., U-Space, UTM).

[0039] For similar purposes, the method can interface with other systems that contain information about manned or unmanned aerial objects.

[0040] Several such managed networks that are not connected to each other or are sparsely connected may be used for communication with various UAVs in the same air vicinity. In such cases, the aviation status received from these networks may be aggregated by one or more aggregation or command and control methods.

[0041] Note that these managed networks may include non-public communications. Therefore, privileges for some actions may include receiving confirmation from an authorizer (e.g., legal, administrative, network administrator) to use these actions. A request for such confirmation may be automatically initiated by the method, or may be executed following a confirmation received in the manner described, through automatic or manual means.

[0042] A method for detecting RCAV-related communication units in a managed network may be provided.

[0043] FIG. 1 illustrates a computerized method 100 for detecting RCAV related communication units in one or more managed networks. Since the method can be executed by a computerized system, it is referred to as a computerized method.

[0044] Method 100 can be initiated by step 110, which uses privileged access to obtain communication related information about one or more members of a managed network.

[0045] Obtaining can include receiving, generating, calculating, determining, searching, fetching, monitoring, processing, etc.

[0046] One or more managed networks can include networks such as cellular networks, fifth generation (5G) cellular networks, privately owned managed networks (e.g., Amazon Prime Air network), U-Space networks, UTM, etc.

[0047] Obtaining may be initiated manually, may be initiated based on an event, or may be automatically initiated without human intervention.

[0048] Obtaining can be done during an exhaustive search process or during a targeted search process. A targeted search process is intended to detect specific members of one or more managed networks and / or members exhibiting specific characteristics.

[0049] Step 120 can follow step 110, where step 120 searches for RCAV related communication units. The search can be at least partially based on the communication related information.

[0050] Thus, step 120 may be based on only the communication related information. Alternatively, step 120 may be based on the communication related information and additional information.

[0051] Additional information may be obtained, for example, using privileged access, without using privileged access, from one or more managed networks, or from one or more sources other than one or more managed networks.

[0052] Step 120 may not be necessary for a particular application. One example is when a list of suspicious network members is obtained externally and step 130 is triggered in accordance with such members being active within the network.

[0053] Both steps 110 and 120 may not be necessary for a particular application. One example is when a current list of RCAVs is provided to the system along with their network identifiers and step 130 is triggered without the system obtaining any additional information associated with that action.

[0054] The discovery can include at least one of the following. · Execution by a network carrier / operator, through a network identifier, of an identification as an RCAV-related device, or an identification as related to a subscriber or member of a managed network that can be identified by the network administrator as being associated with RCAV operations. · Execution of the following identifications through cooperation with an administrator privileged in network connection parameters. For example, (i) others in a closed connection (e.g., P2P, telephone connection). (ii) Accessed data or network addresses (e.g., accessed web address, IP address) · Creating a fingerprint of data transferred in communication (e.g., through data inspection). · Utilizing data (or a combination of privileged and non-privileged data) available through privileged access that is typical of RCAV operations (e.g., location data typical of an RCAV flight). ·Identify and record communication parameters, which may be used later to perform additional actions, either through a managed network or through additional means related to RCAV or its operator. ·In some managed networks, such as cellular networks (e.g., 3G, 4G, 5G), there are also device identifiers for the communication units used to connect to the network, which enable law enforcement agencies (LEAs) to have privileged access (regardless of whether additional authorization for access is required, such as a court order). Such identifiers (e.g., IMEI in cellular communication) can be used to identify those who use RCAV communication units, and the carrier can directly alert them to it, or the LEA can identify and alert the system through LI privileges. The connection may be associated with another subscriber already known to be an RCAV remote controller. The access may be to a known RCAV-related network (e.g., one operated by an RCAV manufacturer). Fingerprint data can be data packets typical of the RCAV application protocol. Location data in some cellular networks (especially 5G) can include altitude data or movement data typical of RCAV flights, and other cellular networks without altitude data (e.g., 3G, 4G) can still show trajectories that can typically only be made by flying objects. When the identification of the relevant IMSI / SUPI or IMEI and such details are available through privileged access to a managed network, details about the owner or operator of the relevant device can be shared with the LEA to apprehend the RCAV pilot or address threats in another way. ·Receive information related to RCAV or its users (e.g., location / altitude data in a 5G network, personal information of subscribers available to network carriers / operators) through privileged access or other data available within the network, and synthesize it with the data extracted from RCAV communications. ·When an RCAV connection is identified by a method, the method automatically, or through initiation by a system operator, extracts data transferred between the RCAV and a remote controller, or between the RCAV and other destinations (e.g., an RCAV manufacturer server or cloud server, a repository connected to the RCAV manufacturer's network, an agent connected to a network that collects communications related to the command and control of RCAV data and RCAV fleets). According to the data, the method can determine whether the RCAV is of interest to the method operator (e.g., located within a protected area), and the method can use additional data received through other sensors, or received through prior knowledge, or received through additional tests conducted following a received warning, to determine whether the RCAV is of interest to the method operator. ·Search for members who have accessed RCAV-related information resources of one or more managed networks. ·Search for members who use RCAV-related communication protocols of one or more managed networks. ·Search for members that may include RCAV-related types of communication units of one or more managed networks. ·Search for RCAV-related communication content. ·Search for members identified by RCAV-related identifiers of one or more managed networks. ·Search for connections with characteristics typical of RCAV-related communications. ·Search at least partially based on the movement information of members of one or more managed networks. ·Search at least partially based on the location information of members of one or more managed networks. ·Search at least in part based on personal information about one or more persons associated with members of one or more managed networks. ·Search for RCAV-related connections and analyze the content carried through the RCAV-related connections.

[0055] Step 130 can follow step 120, and in step 130, it corresponds to the detection of an RCAV-related communication unit.

[0056] Step 120 may be redundant, and in these cases, step 130 can follow step 110.

[0057] Step 130 can include at least one of the following steps. ·Following identification, further analyze the content or characteristics of the communication to extract information related to the monitoring of air traffic and the possible mitigation of threats that this traffic may cause. In a managed network, access to that level of data and the ability to manipulate or block / filter the transferred data can be allowed through the privileges of the network administrator or through APIs provided by the network operator. ·The method can filter the received information by additional parameters (e.g., the location of the end customer of the method, the scope of interest for the method operator, the altitude, size, operating range of the UAV), and present the information based on the filtering to the customer or the method operator. ·Generate warnings sent to various entities such as carriers, or the LEA can identify the system through LI privileges and warn the system. The connection may be associated with another subscriber already known to be an RCAV remote controller. ·The identification of the relevant IMSI / SUPI or IMEI and additional information that can be obtained through privileged access can be shared with the LEA to capture the RCAV pilot or otherwise address the threat. ·Integrate information related to one or more positions to generate a global or overall warning that synthesizes the warnings given for each position. The method can use the position information to predict the future route of the RCAV or to complement the available partial routes. ·Use the prediction of the future route to warn the method operator of predicted threats or to determine the need for additional actions (e.g., hijacking the UAV's communication). ·Store a repository of the detection of the UAV and the history of the actions taken for purposes such as forensic investigations, statistical data collection, bookkeeping, trials, etc. ·If the method determines that the threat to the RCAV should be mitigated (either through an automated command or through initiation by the method operator), the method can address that threat through one or more means. ·After such mitigation, track and follow the RCAV.

[0058] Step 130 can include at least one of the following. ·Generate and send an RCAV label. ·Stop the progress of the RCAV, which may include an RCAV-related communication unit. ·Stop the progress of the RCAV that communicates with an RCAV-related communication unit. ·Disconnect the RCAV-related communication. ·Use privileged access to disconnect the RCAV-related communication. ·Modify the RCAV-related communication. ·Gain control of the RCAV, which may include an RCAV-related communication unit. ·Gain control of the RCAV that communicates with an RCAV-related communication unit. ·Request that one or more managed networks change the communication mode of the RCAV. ·Execute a response based at least in part on the position of the RCAV related to the RCAV-related communication unit. ·Facilitate one or more countermeasures by affecting the communication of the RCAV-related communication unit. Transfer information regarding the RCAV-related communication unit to another computerized entity. Use privileged access to obtain additional information different from communication-related information. Obtain additional information. Monitor one or more members. Disconnect communication between the RCAV and a controller (e.g., a remote controller / command and control / ground station) through a command given to a carrier / administrator connected to a managed network. Eavesdrop on and / or filter and / or modify communication data between the RCAV and the controller, or insert other commands into the communication, so as to prevent the RCAV from receiving commands, or to interfere with the operation of the RCAV or the control of the RCAV by the controller. This can include interfering packets that cause malfunctions or behavioral modifications in one or more elements of the UAV or the remote controller. See, for example, U.S. Patent No. 10,728,906, U.S. Patent Application No. 17 / 444,907, U.S. Patent Application No. 17 / 456,798, and U.S. Patent Application No. 17 / 129,629, all of which are incorporated herein by reference in their entirety. Disconnect other communication channels that the RCAV was available to use (e.g., direct wireless communication with a remote controller), force the RCAV to use the managed network as the sole communication channel, and then potentially proceed to some form of interference through the ability to modify or control information passing through the network. Change communication parameters so that the RCAV can be stopped from responding to commands sent by a remote controller. Communicate directly with and control the RCAV (e.g., send it to a base, send it along a safe route to a safe landing, land it at a fixed location). ·Warn the end user about problems caused by the RCAV through communication with the end user via a managed network (and possibly through an application used to control the RCAV), for example, through a warning sent to a remote controller by a network operator or to a mobile phone connected to the remote controller. ·Warn the method operator about the existence of the RCAV and other data related to the RCAV. ·Accept commands from the method operator. ·Automatically activate pre-programmed commands. ·Verify the identity of the operator of the RCAV related to the RCAV-related communication unit. ·Verify the identity of the operator of the RCAV related to the RCAV-related communication unit and then act according to the result of the verification. ·Verify the identity of the RCAV related to the RCAV-related communication unit. ·Verify the identity of the RCAV related to the RCAV-related communication unit and then act according to the result of the verification. For example, ignore unproven identities and execute some other example of step 130 above. ·Jump to step 120. ·Jump to step 110.

[0059] Figures 2 to 5 illustrate a computerized system 400 and various environments 300. The computerized system 400 may be located in other environments. In any of these figures, the RCAV and the remote controller may communicate directly with each other and / or communicate indirectly with each other, for example, through a managed network.

[0060] In FIG. 2, the environment 300 includes (i) a managed network 210 managed by a managed network control unit 220, (ii) one or more additional information resources 240 such as a database, an administrator of another network, a managed network member data structure, an aviation communication unit and / or a communication unit and / or a communication unit data structure for information provided by a user and / or a purchaser of an aviation component, (iii) an RCAV such as a drone 121, and (iv) a remote controller 111.

[0061] In FIG. 3, the environment 300 includes (i) a managed network 210 managed by a managed network control unit 220, (ii) one or more additional information resources 240 such as a database, an administrator of another network, a managed network member data structure, an aviation communication unit and / or a communication unit and / or a communication unit data structure for information provided by a user and / or a purchaser of an aviation component, (iii) an RCAV such as a drone 121, (iv) a remote controller 111, and (v) an external air traffic management system 501.

[0062] In FIG. 4, the environment 300 includes (i) a plurality of managed networks (only one managed network 210 is shown for simplicity of explanation) each of which is managed by a managed network control unit such as a managed network control unit 220, (ii) one or more additional information resources 240 such as a database, an administrator of another network, a managed network member data structure, an aviation communication unit and / or a communication unit and / or a communication unit data structure for information provided by a user and / or a purchaser of an aviation component, (iii) an RCAV such as a drone 121, and (iv) a remote controller 111.

[0063] In FIG. 5, the environment 300 includes: (i) a managed network 210 managed by a managed network control unit 220, (ii) one or more additional information resources 240 such as a database, an administrator of another network, a managed network member data structure, an aviation communication unit and / or a communication unit and / or a communication unit data structure for information provided by a user and / or a purchaser of an aviation component, (iii) an RCAV such as a drone 121, (iv) a remote controller 111, and (v) a jamming system 131.

[0064] The jamming system 131 is illustrated as including an antenna 132, a transmitter 133, a signal generator 134, a receiver 135, a signal analyzer 136, and a controller / processor unit 137.

[0065] The antenna 132 can be used to receive signals transmitted from the UAV 121 and / or the remote controller 111. These signals are sent to the receiver 135, and the receiver 135 provides the detected signals to the signal analyzer 136, which can analyze the signals. The analysis can be spectrum analysis, timing analysis, demodulation, descrambling, error correction, decoding, etc. The signal generator 134 can generate a jamming signal, which will be transmitted by the transmitter 133 via the antenna 132.

[0066] Note that the jamming system may have one or more transmitting antennas separate from the one or more receiving antennas.

[0067] The jamming system 131 may include only some of the units illustrated in the figure and / or may include more or other units.

[0068] The controller / processor can be a controller and / or a processor. The controller can control the operation of the interference system, and the processor can analyze the received signals received from the signal analyzer 136 and determine which interference command to send and when to send it.

[0069] The controller / processor can perform the functionality of the signal analyzer and / or the signal generator 134.

[0070] The computerized system 400 includes one or more processors 402 (including one or more processing circuits), one or more memory units 404 for storing instructions and / or information, and one or more communication units 408. The computerized system 400 may communicate with the interference system 131.

[0071] The one or more communication units can include one or more wireless receivers and / or one or more wireless transmitters, and / or one or more communication elements for communicating wired, and / or one or more communication elements for facilitating communication between elements of the computerized system, and / or one or more communication elements for facilitating communication between the computerized system and entities external to the computerized system.

[0072] A computerized system may be, for example, part of a relaxation system, part of a monitoring system, part of a stand-alone computer, part of a cloud computing environment, or not part of a relaxation system, not part of a monitoring system, not part of a stand-alone computer, and not part of a cloud computing environment. The computerized system may have a centralized architecture or a distributed architecture. The computerized system can be a server, a desktop computer, a mobile device, a smartphone, a hardware accelerator, etc.

[0073] Figure 6 illustrates a computerized system 400 and its environment 300. The computerized system 400 may be located in other environments. In Figure 6, the computerized system 400 is included in the interference system 131. Note that one or more components of the computerized system may be implemented, at least in part, in the components of the interference system 131. For example, the controller / processor 137 may execute at least a part of the tasks executed by one or more processors 402 of the computerized system in Figure 2.

[0074] Figure 7 illustrates an example of communication between a computerized system 400 and a managed network control unit of a managed network, such as a 5G cellular network including a 5G core 310 (including an AMF 311, an SMF 312, and a UPS 313) and a 5G radio access network 308, using privileged access. Figure 7 also illustrates various types of links and standard protocols such as X1, X2, X3, etc.

[0075] The above description of the present invention enables those skilled in the art to make and use what is considered to be the best mode at present. However, those skilled in the art will understand and recognize the existence of modifications, combinations, and equivalents of the specific examples, methods, and examples described herein. Therefore, the present invention is not limited by the above examples, methods, and examples, but should be limited by all examples and methods within the scope and spirit of the present invention as claimed.

[0076] In the above specification, the present invention has been described with reference to specific examples of embodiments of the present invention. However, it will be apparent that various modifications and changes can be made without departing from the broader spirit and scope of the present invention as set forth in the appended claims.

[0077] Those skilled in the art will recognize that the boundaries between logic blocks are merely exemplary, and that in alternative embodiments, logic blocks or circuit elements can be combined, or alternative decompositions of functionality can be imposed on various logic blocks or circuit elements. Therefore, it should be understood that the architecture shown herein is merely exemplary, and that in practice, many other architectures that achieve the same functionality can be implemented.

[0078] Any configuration of components that achieves the same functionality is effectively "associated" so that the desired functionality is achieved. Therefore, any two components combined to achieve a specific functionality herein can be regarded as "associated" with each other so that the desired functionality is achieved, regardless of the architecture or intermediate components. Similarly, any two such associated components can be regarded as "operably connected" or "operably coupled" to each other to achieve the desired functionality.

[0079] Furthermore, those skilled in the art will recognize that the boundaries between the above operations are merely exemplary. Multiple operations may be combined into a single operation, a single operation may be distributed over additional operations, and the operations may be performed at least partially in temporal overlap. Further, alternative embodiments may include multiple executions of a particular operation, and in various other embodiments, the order of the operations may be modified.

[0080] Also, for example, in one embodiment, the illustrated examples may be implemented as a single integrated circuit or a circuit configuration disposed within the same device. Alternatively, the examples may be implemented as any number of separate integrated circuits or separate devices appropriately interconnected with each other.

[0081] However, other changes, variations, and modifications are possible. Accordingly, the specification and drawings are to be regarded in an illustrative rather than a limiting sense.

[0082] In the claims, any reference signs placed between parentheses shall not be construed as limiting the claim. The word "comprising" does not exclude the presence of other elements or steps than those listed in a claim. Further, the term "a" or "an" as used herein is defined as one or more than one. Also, the use of introductory phrases such as "at least one" and "one or more" in the claims shall not be construed to imply that another claim element introduced by the indefinite article "a" or "an" limits any particular claim containing such introduced claim element to inventions containing only one such element, even when the same claim includes introductory phrases such as "one or more" or "at least one" and indefinite articles such as "a" or "an". The same holds true for the use of definite articles. Unless stated otherwise, terms such as "first" and "second" are used for arbitrarily distinguishing between elements described by such terms. Thus, these terms are not necessarily intended to indicate any temporal or other precedence of such elements. Just because certain means are described in different claims does not indicate that a combination of these means cannot be used advantageously.

[0083] Although specific features of the present invention have been illustrated and described herein, many modifications, substitutions, changes, and equivalents will occur to those skilled in the art. It is, therefore, to be understood that the appended claims are intended to cover all such modifications and changes as fall within the true spirit of the invention.

[0084] It is recognized that various features of the embodiments of the present disclosure, which are described in the context of separate embodiments for clarity, may be provided in combination in a single embodiment. Conversely, various features of the embodiments of the present disclosure, which are described in the context of a single embodiment for brevity, may be provided separately or in any suitable sub-combination.

[0085] Those skilled in the art will recognize that the embodiments of the present disclosure are not limited by what is particularly shown and described above. Rather, the scope of the embodiments of the present disclosure is defined by the appended claims and their equivalents.

Claims

**Claim 1** A computerized method for detecting a remotely-controlled aerial vehicle (RCAV) related communication unit in one or more managed networks, comprising: Using privileged access to obtain communication-related information about one or more members of the one or more managed networks; Searching for the RCAV related communication unit, the searching being at least partially based on the communication-related information; Corresponding steps for detecting the RCAV related communication unit; and A computerized method including the above steps. **Claim 2** The computerized method according to claim 1, wherein the searching includes searching for members of the one or more managed networks that have accessed RCAV related information resources. **Claim 3** The computerized method according to claim 1, wherein the searching includes searching for members of the one or more managed networks that use RCAV related communication protocols. **Claim 4** The computerized method according to claim 1, wherein the searching includes searching for members of the one or more managed networks that include RCAV related types of communication units. **Claim 5** The computerized method according to claim 1, wherein the searching includes searching for RCAV related communication content. **Claim 6** The computerized method according to claim 1, wherein the searching includes searching for members of the one or more managed networks that are identified by RCAV related identifiers. **Claim 7** The computerized method according to claim 1, wherein the searching is also based on additional information not obtained using the privileged access. **Claim 8** The computerized method according to claim 1, wherein the searching includes searching for connections having characteristics typical of RCAV related communication. **Claim 9** The computerized method according to claim 1, wherein the searching is at least partially based on movement information of members of the one or more managed networks. **Claim 10** The computerized method according to claim 1, wherein the searching is at least partially based on location information of members of the one or more managed networks. **Claim 11** The computerized method according to claim 1, wherein the discovery is at least partially based on personal information about one or more persons associated with members of the one or more managed networks.

12. The computerized method according to claim 1, wherein the response includes generating and sending an RCAV indication.

13. The computerized method according to claim 1, wherein the response includes stopping the progress of the RCAV including the RCAV-related communication unit.

14. The computerized method according to claim 1, wherein the response includes stopping the progress of the RCAV communicating with the RCAV-related communication unit.

15. The computerized method according to claim 1, wherein the response includes disconnecting the RCAV-related communication.

16. The computerized method according to claim 1, wherein the response includes disconnecting the RCAV-related communication using the privileged access.

17. The computerized method according to claim 1, wherein the response includes modifying the RCAV-related communication.

18. The computerized method according to claim 1, wherein the response includes obtaining control of the RCAV including the RCAV-related communication unit.

19. The computerized method according to claim 1, wherein the response includes obtaining control of the RCAV communicating with the RCAV-related communication unit.

20. The computerized method according to claim 1, wherein the response includes verifying the identity of the RCAV associated with the RCAV-related communication unit.

21. The computerized method according to claim 20, wherein after the verification, an action is taken according to the result of the verification.

22. The computerized method according to claim 20, wherein the one or more managed networks are a plurality of managed networks.

23. The computerized method according to claim 22, wherein the obtaining includes obtaining the communication-related information during roaming between managed networks within the plurality of managed networks.

24. The computerized method according to claim 1, wherein the response includes requesting the one or more managed networks to change the communication mode of the RCAV.

25. The computerized method according to claim 1, wherein the one or more managed networks include a cellular network. **Claim 26** The computerized method according to claim 1, wherein the one or more managed networks include a fifth generation (5G) cellular network. **Claim 27** The computerized method according to claim 1, wherein the correspondence is at least partially based on the position of the RCAV related to the RACV related communication unit. **Claim 28** The computerized method according to claim 1, wherein the correspondence includes facilitating one or more countermeasures by affecting the communication of the RACV related communication unit. **Claim 29** The computerized method according to claim 1, wherein the correspondence includes verifying the identity of the operator of the RACV related to the RACV related communication unit. **Claim 30** The computerized method according to claim 1, wherein at least a part of the computerized network belongs to the managed network. **Claim 31** The computerized method according to claim 1, wherein the correspondence is also in response to information obtained outside the one or more managed networks. **Claim 32** The computerized method according to claim 1, wherein the correspondence includes transferring information about the RACV related communication unit to another computerized entity. **Claim 33** The computerized method according to claim 1, wherein the acquisition is manually initiated. **Claim 34** The computerized method according to claim 1, wherein the acquisition is the result of searching for a member presenting one or more parameters. **Claim 35** The computerized method according to claim 1, including the step of using the privileged access to obtain additional information different from the communication related information. **Claim 36** The computerized method according to claim 1, wherein the correspondence includes obtaining additional information. **Claim 37** The computerized method according to claim 1, wherein the correspondence includes monitoring the one or more members. **Claim 38** The computerized method according to claim 1, wherein the one or more managed networks include a privately owned managed network. **Claim 39** The computerized method of claim 1, wherein the one or more managed networks include the Amazon Prime Air network.

40. The computerized method of claim 1, wherein the one or more managed networks include the U-Space network.

41. The computerized method of claim 1, wherein the one or more managed networks include UTM.

42. The computerized method of claim 1, wherein the discovery includes discovering RCAV-related connections and analyzing the content carried through the RCAV-related connections.

43. A non-transitory computer-readable medium for detecting a remotely-controlled aerial vehicle (RCAV)-related communication unit in one or more managed networks, using privileged access to obtain communication-related information regarding one or more members of the one or more managed networks, discovering the RCAV-related communication unit, the discovery being at least partially based on the communication-related information, and responding to the detection of the RCAV-related communication unit and storing instructions for doing so.

44. A computerized system for detecting a remotely-controlled aerial vehicle (RCAV)-related communication unit in one or more managed networks, one or more communication units configured to use privileged access to obtain communication-related information regarding one or more members of the one or more managed networks, discovering the RCAV-related communication unit, the discovery being at least partially based on the communication-related information, and responding to the detection of the RCAV-related communication unit one or more processors configured to perform and comprising a computerized system.

Citation Information

Patent Citations

  • US10,728,906

  • Battery module and battery pack

    US20210111458A1

  • Processing information related to one or more monitored areas

    US20220329346A1

  • Disruption to an operation of an unmanned aerial vehicle

    US20240356669A1