System for verifying the integrity of unmanned aerial vehicles

The system ensures the integrity and security of UAVs by authenticating their hardware and software components, addressing the risk of unauthorized operations and enhancing safety in shared airspace through cryptographic verification.

JP7762190B2Active Publication Date: 2025-10-29RHOMBUS SYST GRP INC
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2023194197
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-11-15
Publication Date
2025-10-29
Estimated Expiration
2037-06-07

AI Technical Summary

Technical Problem

Unmanned aerial vehicles (UAVs) operating autonomously pose a risk due to potential tampering with their flight systems or software, which can lead to unauthorized operations, posing threats to life and property, and there is a need for a system to ensure the integrity and security of UAVs in shared airspace.

Method used

A system for verifying the integrity of UAVs through cryptographic verification mechanisms, using cryptographic keys and algorithms to authenticate hardware and software components, ensuring that the UAV's status is validated and authorized before operations, with a certification authority managing the licensing and ensuring compliance with regulatory requirements.

Benefits of technology

The system provides secure authorization and integrity verification of UAVs, preventing unauthorized modifications and ensuring safe operation in shared airspace by validating the UAV's hardware and software, thus reducing the risk of adverse events.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007762190000002
    Figure 0007762190000002
  • Figure 0007762190000003
    Figure 0007762190000003
  • Figure 0007762190000004
    Figure 0007762190000004
Patent Text Reader

Abstract

To provide a control system for regulating an operation of one or a plurality of UAVs by verifying integrity of unmanned aircraft.SOLUTION: An UAV 1 acquires a serial number or a unique identifier of hardware and software of UAVs, creates a combination of hash codes of the unique identifiers, encrypts the hash code, and transmits the encrypted hash code to another computer that holds an authentication code table for each UAV through a wired or a wireless communication system. As a result, the computer executes firmware that authenticates the specific UAV. A system also can determine whether the specific UAV hardware or software has been changed since the UAV was last authenticated.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Background technology]

[0001] The present invention relates to unmanned aerial vehicles (UAVs), and more particularly to a system for verifying the integrity of UAVs and coordinating the operation of UAVs.

[0002] Unmanned aerial vehicles (UAVs) are expected to become widespread in society in the coming years, performing functions such as package delivery, remote sensing inspection, and supporting other activities in everyday commerce, industry, and consumer life. Unlike manned aircraft, UAVs are expected to operate in much closer proximity to people, animals, property, buildings, and equipment. In addition, UAVs are expected to be automated and perform functions far beyond the line of sight of an operator or trusted officer.

[0003] Because UAVs often operate alongside other manned aircraft carrying passengers and in the airspace around other objects and people, they can pose a threat to life and property if operated with uncertified, incompatible, or untested software or hardware, and can pose an additional threat if the UAV is hacked or taken over by an unauthorized person for nefarious purposes. Manned aircraft can pose similar threats, but are under the control of a trusted person - the pilot. The trusted person's function is to ensure the safety of the flight and that the aircraft is under their control and flying safely.

[0004] Flight plans are typically required for aircraft using national airspace. Air traffic control is important for the safety of individuals, property, and animals at ground locations over which aircraft fly, as well as those navigating and / or operating aircraft. Since the early days of flight, the United States has provided systems for both collecting and distributing flight information from and to pilots. Pilots are typically required to file or request a flight plan, which provides an intended direction to a destination location. A flight plan typically must include aircraft identification, specialized equipment, departure and arrival points, and the route flown. Services, often referred to as flight services, are offered to pilots and are provided by commercial or governmental organizations (or commercial organizations that may be under government contract). Flight services are designed to provide information to pilots at the time a flight plan is filed, as well as updates on activities or events that may affect the intended flight plan. Aircraft are managed to allow several aircraft to be located closely together within the same general airspace, while remaining sufficiently separated so as not to interfere with or pose a safety risk to each other.

[0005] With the increasing use of UAVs for both commercial and recreational purposes, airspace previously reserved exclusively for conventional aircraft is now shared with a variety of UAVs. In addition to the activities and alerts that pilots need to be aware of, another variable must be taken into account: the potential presence of UAVs. Flight services that alert pilots to adverse conditions, such as closed runways or threatening weather, can also collect and provide information about nearby aircraft and UAVs. There is growing demand for UAV operators to not only register aircraft but, in some cases, also provide information about planned UAV operations, such as flight plans. The goal is to enable UAVs to reduce interference and cooperate in the same airspace as other aircraft. The hope is to reduce or eliminate the possibility of mid-air collisions between UAVs and other aircraft. For example, the systems typically used by aircraft pilots to obtain information and alerts about impending flights, known as flight services, are being updated to include a category of alerts related to UAVs (sometimes referred to as unmanned aerial systems, or UAS). Thus, the pilot of the aircraft may be provided with information identifying the likely presence of a UAV in the vicinity of the aircraft based on the aircraft's flight plan and information provided by the UAV operator. For example, the UAV or drone operator may register and provide details such as the operator's name, contact information, UAV identification, date and time of the flight, maximum altitude, and a flight boundary, e.g., a radius based on geographic coordinates.

[0006] The importance of integrating UAV operations with traditional airspace use and aircraft is designed to provide the benefits of UAV use while promoting safety by reducing the risk of adverse events such as collisions.

[0007] However, as with any device, even extensive precautions cannot eliminate all potential hazards. Given the precautions taken and the potential risks, there is also the possibility of injury to persons and property, including passengers on nearby aircraft, as well as people, animals, and structures on the ground. There is also the possibility of unauthorized manipulation of a UAV, including, for example, attempts to hijack its operation, divert its route, or operate it in a manner not intended by the original operator. Summary of the Invention [Problem to be solved by the invention]

[0008] Because unmanned, beyond-line-of-sight UAVs may operate in fully autonomous mode without direct human involvement, a system is needed to ensure that the UAV's flight systems, software, and hardware cannot be tampered with, so that the UAV can be trusted to operate within airspace. [Means for solving the problem]

[0009] A system for controlling UAVs, particularly for regulating the operation of one or more UAVs by verifying the integrity of the UAVs, is provided. According to a preferred embodiment, the system verifies the UAVs via a verification mechanism. According to a preferred embodiment, the verification mechanism may be provided in association with one or more UAV components (e.g., hardware), software, or a combination thereof. Also provided are methods for verifying UAVs and UAVs configured with the UAV verification system.

[0010] According to preferred embodiments, the system implements security features to ensure control of the UAV as intended. An authentication mechanism is implemented to provide a validation status for the UAV. The validation status of the UAV is preferably based on one or more modalities of the UAV's hardware, software, or a combination of hardware and software. According to preferred embodiments, the validation status may be implemented by a cryptographic system in which a cryptographic key and / or cryptographic algorithm is used to provide the UAV's status. The UAV's status is preferably assigned based on one or more unique properties that identify the particular UAV. Preferred embodiments may provide cryptographic hash values ​​(combined hashes of hardware component identification and software) of essential hardware components (e.g., serial numbers and model numbers of drive motors and control motors, and / or installation dates), essential software (e.g., navigation software), or both. Hardware components may be uniquely identified (or preferably identified by a combination of these), for example, by hardware serial number, model number, installation date, or some other identifier, while software may be identified by a unique property (e.g., hash value, checksum hash, etc.).

[0011] According to a preferred embodiment, a UAV may be authorized and assigned an authorization state, such that the UAV is authenticated, whereby an authorization state or authorization hash value may be generated and preferably stored for that particular UAV.

[0012] According to some preferred embodiments, authentication of a UAV can be performed without the owner or operator of the UAV knowing the verification policy or without an authority knowing what properties or characteristics are being verified, for example, if the policy is not revealed except implicitly (such as to a computer assigned to identify and authenticate the UAV). For example, the UAV may be provided with an authentication instruction or chip that provides the verification. The verification may then be transmitted or retrieved from the UAV for storage and stored for reference and further use by the authentication authority.

[0013] According to some embodiments, validation is performed using one or more electronic components and / or software of the UAV designed to represent the state of the UAV and identify deviations therefrom, for example, if specific hardware and / or software are used in conjunction with a validation hash deviation, then validation results in identification of deviations in these specific hardware and / or software.

[0014] Certification may be performed by a certification authority. The certification authority may define its own set of parameters for performing certification of the UAV. According to some preferred embodiments, the certification authority may be given the ability to manage the licensing of the UAV by verifying and certifying the UAV before the UAV performs any activity or operation. The certification authority may have secured communications with the UAV, which may be encrypted communications or transmission of encrypted verification data or other encrypted transmissions. According to some embodiments, the system may include one or more certification management operations, which may be implemented in hardware, such as computers and communications hardware, to perform certification of the UAV and may perform verification of the UAV before or during flight.

[0015] The system may be configured to reside within a UAV and interface with both the UAV's communications system and the UAV's software and hardware resources. The UAV may be configured to obtain the UAV's hardware and software serial numbers or unique identifiers, create a hash code combination of such unique identifiers, encrypt the hash code, and transmit the encrypted hash code via a wired or wireless communication system to another computer that maintains a table of authorized codes for each UAV, so that the computer implements firmware that authorizes (or disauthorizes) the particular UAV. The system may also determine whether the particular UAV hardware or software has been modified since the UAV was last authorized.

[0016] Features described herein in connection with one embodiment may be used in other embodiments, and features may be combined to provide an embodiment with one, two, or several combinations of features. [Brief explanation of the drawings]

[0017] [Figure 1] 1 depicts an exemplary embodiment of a system and is a flow chart showing steps of an embodiment of a method for licensing a UAV.

[0018] [Figure 2] 10 is a flow diagram depicting another embodiment of a system for indicating a UAV requesting to be verified.

[0019] [Figure 3] 1 is a perspective view of an exemplary embodiment of an unmanned aerial vehicle (UAV) implementing the system of the present invention;

[0020] [Figure 4] FIG. 2 is a front view of another exemplary embodiment of an unmanned aerial vehicle (UAV) implementing the system of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0021] The system can be implemented by providing a UAV with a chip and software that includes instructions to generate a verification hash and provide a hash code.

[0022] For example, according to some embodiments, the present invention may provide a cryptographic system as part of a UAV equipment circuit, which may include a storage component, microcircuit, microcontroller, or processor along with instructions for generating and / or storing keys. For example, according to one embodiment, an integrated circuit component is provided that includes a storage element that internally stores a certification authority's public key that is used to encrypt a unique verification status code generated from the UAV (e.g., component, software, or a combination thereof) and / or decrypt a digital signature from the certification authority. This public / private key may be implemented as a further way to provide security by encrypting a unique hash code (e.g., of the UAV's verification code request by the certification authority's computer). Public or private key embodiments may include a time or location element that further encrypts the hash code.

[0023] According to embodiments, the system validates the UAV to verify that the hardware and / or software of the UAV has not been modified. According to some preferred embodiments, if the system identifies a hardware or software change, the system may be configured to identify one or more components (hardware items or software) that have been modified. Additionally, the certification authority may implement a protocol for recertification in the event of, for example, a motor replacement or an upgrade of, for example, a navigation component or navigation software. Recertification may be performed to ensure that any changes made are approved, authorized, and / or regulatory requirements are met and are recognized by the authorization or authentication hash value.

[0024] According to a preferred embodiment, a system may be implemented to secure the operation of an unmanned aerial vehicle (UAV). The UAV preferably includes multiple hardware components and software. An authorization hash code corresponding to the UAV is generated. This is preferably done by obtaining unique identifiers from at least one of the UAV's hardware components and the UAV's software, and according to a preferred embodiment, both unique identifiers, such as serial numbers or checksums of the hardware and software, respectively. The authorization hash code is created for either the hardware or the software, or a combination of the hardware and software identifiers. The system is used in conjunction with a remote computing component, preferably remote from the UAV and configured to exchange communications with the UAV over a network. The UAV preferably includes a computing component, which may be provided separately or as part of the UAV circuitry. The authorization hash code for the UAV is preferably stored (e.g., once the UAV is authenticated) and available to the remote computing component via an accessible database, table, or other access means. To verify the UAV, the remote computing component receives the encrypted verification code from the UAV, then decrypts the verification code and compares it to the authorization code for the UAV. If a match occurs, the UAV is authorized; if no match occurs, the UAV is not authorized.

[0025] According to some embodiments, the UAV can issue a request to the authentication authority by contacting an authorization computer over a network. According to some embodiments, the authentication authority or computer (e.g., a remote computing component) can request the UAV to provide verification information. The UAV can receive the request and generate a verification code, such as a hash value. According to some embodiments, the UAV is configured with instructions that provide a protocol for generating a verification hash value from UAV components. The instructions and protocol can be implemented via a TPM chip or system, or fTPM, according to some embodiments. According to system embodiments, the UAV can be configured with a protocol that is a zero-knowledge proof protocol, whereby verification of UAV authorization parameters remains unknown to the UAV (even if the UAV has knowledge of the hardware and software components from which the verification hash is generated). For example, according to some embodiments, the UAV can generate the verification hash without being specifically provided with knowledge. According to some other embodiments, communication exchanges between the UAV and the authentication authority computer can be secured by keys and through implementation of a zero-knowledge proof protocol.

[0026] Once a verification code is generated based on existing UAV hardware and software information, the verification code is then communicated to an authentication computer, which, according to some embodiments, is remotely located from the UAV. The verification code is preferably encrypted during transmission and can be decrypted by the authentication computer. According to some embodiments, the UAV may connect to the authentication computer via a wired connection, while according to other embodiments, the UAV may connect via a wireless connection.

[0027] Verification of the UAV may provide an indication of whether software changes, hardware changes, or both have been made (including whether any unauthorized software changes have occurred), for example.

[0028] According to a preferred embodiment, a database is provided having a plurality of stored authorization hash codes corresponding to a respective plurality of UAVs, such that each particular UAV can be authorized by its respective authorization hash. For example, a remote computing component may maintain and access a table of authentication codes for a plurality of UAVs. The authentication codes (e.g., authorization hash codes) may be stored in encrypted form.

[0029] The present invention may also provide cryptographic equipment that may include storing an element that internally stores the regulatory agency's public key as an integrated circuit component within the UAV, which is used to decrypt digital signatures from the regulatory agency (such as a certification authority), thereby verifying that any commands received by the UAV (e.g., to generate and / or provide a verification code) have been authorized by the regulatory agency.

[0030] The present invention further provides a cryptographic device as an integrated circuit component having the capability to generate a unique public / private key pair that may be used to perform encryption / decryption operations, to store and use the public / private key pair securely within the integrated circuit component in a manner that substantially prevents detection of the key pair via reverse engineering, and to provide a modifiable cryptographic device as a unique integrated circuit component to which guaranteed, authorized modifications can be performed remotely.

[0031] According to an exemplary embodiment, in accordance with a preferred embodiment of the system, each UAV that is to be authorized for flight in a particular airspace based on regulatory or other legal restrictions is first certified. Certification is preferably performed by a certification or regulatory body. Certification preferably includes certification of the UAV's hardware and / or software, and according to a preferred embodiment, preferably includes certification of the UAV's primary flight and navigation systems (which may preferably include hardware components and software). According to a preferred embodiment, certification is performed by an inspection or certification body that may subsequently verify the UAV.

[0032] Preferably, a UAV is inspected or otherwise determined to have acceptable hardware, software, and preferably both. For example, within a certified UAV, specific software and hardware authorized as airworthy for that particular UAV are then connected to either hardware or software, or a combined hardware / software system, that calculates a hash code representing the state of the hardware and software on certain predetermined portions of the UAV's command and control and navigation system. According to some preferred embodiments, the hash code may be created from a combination of electronically readable serial numbers, model numbers, and installation dates of hardware (e.g., computers or drive motors), and checksums or hash codes of each critical piece of software within the UAV's computing system. The number of hardware and software elements may be determined by, but not limited to, regulations or best practices. A hash, the certification or authorization hash, is created at the time of certification. The certification or authorization hash is preferably stored in a secure location associated with a computer that verifies the hash code for the UAV at the time the UAV desires to use airspace for operational (or other regulated) operations.

[0033] Authorization hash codes that may be implemented to authenticate a UAV are depicted in the exemplary table below. The table shows the hardware component identification and authorization hash value associated with each exemplary listed hardware component (although there may be additional hardware components on a UAV other than those listed and that may also be used to determine authorization values). A table is presented for the UAV's software, listing some examples of essential operational software. Examples of hardware and software combinations are depicted in the table showing hash values ​​for the hardware and software combination. In this depiction, the hash value is generated from a combination of hardware indicia (e.g., serial number, model number, and installation date) and software indicia. Furthermore, according to some other embodiments, values ​​may be combined (hardware value string | software value string) and a hash value may be calculated. According to other embodiments, values ​​may be authenticated for each hardware component and software so that, if the UAV fails validation, individual hardware and software components may be identified as the cause of a fault or malfunction. A table showing exemplary descriptions of authentication or authorization values ​​is set forth below. [Table 1]

[0034] Reference is now made to FIG. 1 , which illustrates an exemplary embodiment of the present system in the context of an unmanned aerial vehicle, here UAV1. Aircraft UAV1 preferably undergoes an authentication procedure, preferably performed in an authentication authority computer, CA1, shown here as such. An authentication hash code (or authorization hash code) is generated in block 115 and stored in block 116 for later reference when UAV1 is verified by an authentication authority, such as a command and control computer (CA, e.g., CA1, CA2, CA3). In block 120, aircraft UAV1 receives a request from a requesting component in block 121, which may be a computer configured as a command and control authority authenticating the UAV. In the description of FIG. 1 , references to CA1, CA2, and CA3 may refer to a single authentication authority computer or to one or more separate computers. Alternatively, the request received by UAV1 in block 120 may originate from an unauthorized component, such as a rogue computer, a hacker computer, or other malicious transmission. In block 121, the request is preferably transmitted with an authentication or signature and provided encrypted. At block 120, UAV1 receives the request and determines at block 122 whether the request meets the requirements of an authorized signature, authentication, or other security feature. If the request is determined to be from a trusted certification authority (CA1), UAV1 passes the request through at block 123, decrypts the request, and processes the request at block 124. If the request cannot be determined to be trusted at block 125, and therefore fails, no further processing of the request occurs, or alternatively or additionally, an alarm may be generated and communicated, for example, to an authentication computing component at block 126. If the request is passed through at block 123, UAV1 decrypts the request at block 124 and generates a verification hash code (VHC) at block 127. The VHC is then encrypted at block 128, and the encrypted authentication hash code (EVHC) is sent at block 130 to an authentication computer, shown in FIG. 1 as CA2.

[0035] The authenticating computer CA2 receives the EVHC from UAVl in block 131, decrypts the EVHC in block 132, and compares the decrypted verification hash code (DVHC) to the UAVl's stored hash code in block 116. If the comparison fails in block 134, an alert may be issued to a component or personnel via a device such as a computer, tablet, or other notification device in block 135. Alternatively, if the UAVl fails to be verified, further certification of the UAVl may be prevented or a specific operation may be performed. The UAVl may no longer be authorized to enter the protected airspace or zone. According to some embodiments, the authenticating computer, CA2 in this example, may issue a command to disable the UAVl or one or more functions of the UAVl in block 136.

[0036] If the comparison of the DVHC matches the hash value of UAVl stored in block 116 at block 133, then verification of UAVl passes at block 137 and UAVl is verified at block 138. According to some alternative embodiments, UAVl requests a remote computer, such as a certification authority computer (e.g., CA1, CA2, CA3), to verify UAVl. This may occur when UAVl wishes to take some action, such as entering designated or controlled airspace, operating a camera, or delivering a payload.

[0037] The UAV can initiate a verification request to the certification authority. This request can be issued from the UAV to the certification authority computer. The certification authority computer can receive the request, process it, and perform verification of the UAV. For example, the UAV can request verification to perform an operation, such as entering controlled airspace, executing a specific flight plan or route, taking images, deploying a payload, or other function. In accordance with this embodiment, FIG. 2 shows an example procedure illustrating a UAV, UAV1, issuing a request to the certification authority CA. The illustration in FIG. 2 may be in addition to or instead of the authenticating computer CA1 of FIG. 1 issuing the verification request (see block 121 in FIG. 1). As shown in FIG. 2, UAV1 preferably makes the request by encrypting the request in block 140 and then sending the request to the certification authority computer (such as single or multiple computers CA1, CA2, CA3, and the CAs shown in FIGS. 1 and 2) in block 141. The certification authority computer CA depicted in FIG. 2 (which may be any one or more of the certification authority computers represented by CA1, CA2, and CA3 in FIG. 1) receives a verification request from UAV1 in block 142. The request (see, e.g., blocks 141 and 142) may be transmitted or received over a network (wired or wireless). The certification authority computer decrypts the request in block 143. If the request is decrypted and determined to be an authentic request from UAV1, verification of UAV1 occurs as requested. Verification may be performed as described herein, including the verification shown in the representative example of FIG. 1. The certification authority computer requests UAV1 to generate a verification hash value. This is represented by block 121′ in FIG. 2, which may proceed essentially as shown in block 121 in FIG. 1.

[0038] According to an embodiment of the present invention, a UAV Management (UTM) system is provided to facilitate management of UAVs that may operate within a particular airspace. The UTM system can regulate the airspace, preferably by verifying each UAV that is within or desires to enter the airspace.

[0039] At a later point in time, the UAV may generate and transmit a request to be verified. Alternatively, the request may be generated autonomously in association with the UAV performing a particular activity, instruction, flight plan, or procedure. For example, the UAV may obtain verification if the UAV flight plan includes passage through a zone of restricted airspace. Once authenticated, the authenticated UAV may proceed to operate in conjunction with an authentication system and management function. For example, when a UAV makes a request to a UAV traffic management (UTM) system, such as for flight plan submission or permission to fly within controlled airspace, the UTM system may be configured to query the UAV for its specific hash code using any number of available encrypted communication methods, which is generated at the time of the query via a common encryption of a key or time code provided by the UTM system, which may require the UAV system to actually generate a new hash code rather than simply parroting a separately stored hash code that may not reflect the actual hardware and software at the time of the request.

[0040] The verification hash code is then transmitted to a UTM computer verification system, which then decodes messages received from the UAV in response to the query and determines whether it matches the same hash code stored after authentication (i.e., the authentication or authorization hash). If there is a match, the UAV is considered verified as authorized; if there is no match, it is not considered verified as authorized, and appropriate action may be taken depending on the nature of the UTM system, the nature of the UAV, regulations, or other factors. For example, according to some embodiments, a failure to pass verification may disable the UAV, command it to land in a specific location, or return it to manual control (or the UTM system itself, or in conjunction with other systems, may control the operation of the UAV). Additionally or alternatively, if the UAV fails verification, the system may issue an alert to appropriate individuals, systems, or other components. Alternatively, a verification failure may cause some, but not all, of the UAV's functionality (e.g., the ability to release cargo or payload) to be inoperable.

[0041] The UAV's hash code can be generated by the UAV's hardware or software, or a combination thereof. The UAV's hash code can be created by hardware such as a dedicated TPM chip, software similar to or including an fTPM, or some combination thereof.

[0042] According to a preferred embodiment, the hash code may be generated based on one or more policies corresponding to the state of the UAV hardware, the UAV software, both, or a combination. The system may be configured to perform the verification based on, for example, a particular component or components of the UAV or the UAV software, such as a hash value, a checksum, or both.

[0043] According to some preferred embodiments, the UAV may be configured with a dedicated Trusted Platform Module (TPM) chip, or software similar to or including an fTPM, or a combination of one or more of these features. For example, a traditional TPM, such as a hardware device or “chip,” may be provided, and according to some embodiments, may include its own secure cryptographic processor. The TPM chip or software may be provided as part of or in combination with the UAV's circuitry. The TPM chip or software may securely generate cryptographic keys, as well as restrict their use. The TPM chip may also include hardware pseudorandom number generator functionality. The system is preferably configured to generate a hash value based on the UAV's specific hardware and / or software configuration, thereby providing remote attestation of the UAV in conjunction with authentication. For example, if the UAV software is tampered with, for example, to hijack operation or remove certain functionality, the hash value provided by the TPM may identify and detect the modification to the UAV. Preferred embodiments may provide a certification authority (such as a regulatory body) with the ability to identify unauthorized modifications (e.g., software or hardware components of a UAV), including potential tampering with UAV software (e.g., to accomplish undesirable or even illegal purposes). According to preferred embodiments, a hash value is obtained by creating an authentication that preferably identifies the currently running software, the hardware profile of one or more hardware components of the UAV, or a combination thereof. For example, the serial number of a hardware component such as a drive motor, its model number, installation date, and the identification or serial number of a navigation chip may be used to generate an authentication or authorization hash for the UAV. An authentication system can be used by having the certification authority identify the hash value and comparing it to an expected, known, accepted, or trusted value. According to some embodiments, the certification authority may generate an authentication hash (or authorization hash) associated with the UAV and store it for reference for future verification.For example, the trusted value may be a hash value that indicates proper installation, operation, and / or other properties of the UAV software and hardware. The UAV is preferably configured with instructions that may be provided in a TPM or fTPM component or chip (e.g., a chip) utilizing parameters of existing hardware and software components at the time of the authorization request, for example, to generate a hash value that is sent to a certification authority to validate the UAV.

[0044] According to preferred embodiments, the system is preferably configured to function with a variety of UAVs, and according to preferred embodiments, a specially configured UAV may be provided for use in connection with the authentication system. For example, preferably, the UAV is configured so that a certifying organization can remotely communicate with the UAV and exchange communications, preferably including authentication or hash verification. The communications are preferably secure and preferably encrypted. A remotely located computing component is preferably configured to communicate with the UAV. According to preferred embodiments of the system, the computing component is configured with software including instructions for verifying the authorization status of the UAV and validating the UAV. According to some embodiments, the computing component may receive a request from the UAV for authentication. According to some embodiments, the computing component may also issue a request to the UAV and authenticate the UAV even if the UAV has not requested it. Verification may preferably be provided as an operational requirement. For example, according to some embodiments, a UAV is required to pass verification in order to perform one or more functions, such as being able to fly, being admitted into controlled airspace, or being able to perform one or more operational functions (e.g., delivering a payload, operating a camera, transmitting video, etc.).

[0045] The system may be configured to further protect communications between the UAV and a remote component, such as an authentication authority, by preferably enforcing encryption of information exchanged between the UAV and the remote computing component. For example, remote attestation may preferably be combined with public key encryption to prevent the information from being exploited if communications are intercepted (e.g., by an eavesdropper).

[0046] According to some alternative embodiments, the system may implement Direct Anonymous Authentication (DAA) security. A DAA signature system may be implemented in conjunction with a TPM chip or system to provide secure interactions between the UAV and a certificate authority.

[0047] According to some preferred embodiments, a certificate authority can control the TPM chip or fTPM software. For example, a unique, private RSA key in the TPM chip can provide another level of authorization by verifying that a regulated computer attempting to query the UAV (e.g., a calculated hash value) is a genuine certificate authority expected to request information.

[0048] According to some embodiments, the UAV circuitry may be configured with a separate hardware TPM integrated into the system board or circuitry of a UAV hardware component, such as a UAV computing component or system. For example, according to some embodiments, the UAV may be configured with suitable interconnects or other suitable hardware components capable of supporting a TPM.

[0049] The system preferably provides safeguards to minimize or eliminate the possibility of intrusion into the UAV's hardware and software operating systems. The system is designed to provide appropriate integrity protection and defense against malicious modification of the UAV's hardware and software.

[0050] According to some preferred embodiments, a "firmware-based TPM" or "fTPM" may be implemented in combination with a system that provides authentication and validation of a UAV. A "firmware TPM" or fTPM may be implemented to provide software with an interface to security extensions that are integral to a processor, preferably as an alternative to requiring a hardware TPM module. The fTPM may be utilized to perform trusted computations in conjunction with the authentication system. For example, the fTPM may be implemented within the UAV, such as within the UAV circuitry, to provide a trusted execution environment. According to some preferred embodiments, the UAV may be modified with FTPM software and provided with instructions to generate authentication or authorization hashes in conjunction with the authentication system.

[0051] According to some embodiments, a separately provided processor may be used by the UAV to perform the authentication operations, or software may be located in protected memory of the UAV (or in storage that cannot be read or modified by untrusted components).

[0052] 3 and 4, examples of UAVs 110, 210 operable with the present system are depicted. The UAV 110 is configured as a drone, and the UAV 210 is configured as a quadcopter. The UAVs 110, 210 are preferably configured with power and communication hardware. The UAVs 110, 210 preferably include one or more processors, which may include a microcircuit, microcontroller, or microprocessor according to some preferred embodiments. The UAV or its computer also includes a memory component (which may be part of the circuit or processing component or be provided separately). Preferably, the UAV circuit or computing component is provided with software including instructions for monitoring control signals and flight properties (e.g., acceleration, direction, pitch, and yaw). The software also includes instructions for controlling rotor operation and may include stabilization algorithms for stabilizing the intended flight (to smooth operational control and flight properties of the unmanned aerial vehicle as the instructions are executed and the aircraft carries out commands from a control, program, or other source). The UAV may also be configured with navigation components or circuitry, which may include, for example, a compass and a GPS, which may be provided alone or together on a chip or circuit, and may optionally have one or more other components (e.g., an IMU). The UAV may also be configured with electronic speed control, which may be implemented in software, hardware, aircraft circuitry, or a combination thereof. The speed control mechanism may preferably be provided to manage the operation of the motor driving the rotor and changing the orientation of the rotor (e.g., by changing the direction of the motor shaft), and may function by receiving remote signals or in combination with programming that directs the flight path, direction, and other operations of the unmanned aerial vehicle. According to some embodiments, a certification authority acting as a command and control computer for validating the UAV may have the ability to control one or more operations or functions of the UAV.According to some embodiments, the UAV 110, 210 may preferably include a TPM chip or system and may include fTPM firmware for managing the verification operations of the UAV.

[0053] While an exemplary embodiment of a UAV is shown, the system may be used in conjunction with other unmanned aerial vehicles. One or more functions described with respect to one or more embodiments may be provided individually or in combination with one or more other functions of the aircraft and / or system. Additionally, while the system is described with reference to aircraft 110, 210, the system may alternatively be deployed on an existing UAV or provided as a module that may be integrated with or electronically coupled to the computing and electronic components of the UAV to perform authentication and subsequent validation of the UAV. Also, references to one or more computers depicted as CA1, CA2, CA3, and CA may collectively represent a single computer configured to perform the depicted functions, or may represent two or three computers. In addition to the depicted computer or computers (e.g., CA, CA1, CA2, CA3), many other computers may be provided, including a computer network, that perform command and control operations. These and other advantages may be provided by the present invention. For example, a TPM chip and fTPM firmware can be used, but alternative embodiments implemented or provided by a computing standards organization, such as the Trusted Computing Group, for secure cryptographic communications or exchanges, such as integrated security provided in a particular chip (e.g., a communications chip), can also be implemented. The following is the invention as originally described in the present application. <Claim 1> resides within a UAV and interfaces with both the communication system of the UAV and the software and hardware resources of the UAV; a. Obtain serial numbers or unique identifiers for the hardware and software on the UAV; b. Create a hash code combination of such unique identifiers; c. further encrypting said hash code; d. Executable firmware that transmits the encrypted hash code via a wired or wireless communication system to another computer that maintains a table of authentication codes for each UAV, thereby causing the computer to verify the authorization (or disauthorization) of the particular UAV; e. The computer then determines whether the hardware and software of the particular UAV has changed since the UAV was last authenticated. <Claim 2> The system of claim 1 , wherein the UAV has a TPM standard-compliant chip / system to verify the integrity of the UAV's hardware. <Claim 3> The system of claim 1 , wherein the UAV includes software or firmware that comprises an fTPM system. <Claim 4> The system of claim 2 , wherein the verification of the TPM chip is also used to encrypt communications between the UAV and a central command and control system. <Claim 5> The system of claim 4 , wherein the central command and control system is automated. <Claim 6> The system of claim 4 , wherein the central command and control system is operated by a human. <Claim 7> 4. The system of claim 3, wherein fTPM (firmware TPM) functionality resides in a computer located on the UAV to perform the functions described in paragraphs a.-d. <Claim 8> The system of claim 1 , further comprising a public or private key system configured to further encrypt the hash code generated in b. <Claim 9> 9. The system of claim 8, wherein the public or private key system includes one or both of a time element and a location element for further encrypting the hash code. <Claim 10> 1. A method for securing the operation of a wireless airborne vehicle (UAV) including a plurality of hardware components and software, comprising: generating an authorization hash code corresponding to at least one UAV and storing the authorization hash code; providing at least one computing component electronically coupled to one or more of the plurality of hardware components or the software of the UAV; obtaining a unique identifier for at least one of (i) a hardware component of the plurality of hardware components or (ii) the software; generating a verification hash code of the at least one hardware component or software from the unique identifier; encrypting the verification hash code; transmitting the encrypted verification hash code to a remotely located computing component over a communications network; decrypting the encrypted verification hash code; comparing the verification hash code with the stored authorization hash code; and authorizing the UAV if the verification hash code matches the stored authorization hash code. <Claim 11> The method of claim 10 , wherein the stored authorization hash code is stored in a database. <Claim 12> The method of claim 11 , comprising providing a database having a plurality of stored authorization hash codes, each of the plurality of stored authorization hash codes corresponding to a particular UAV. <Claim 13> The method of claim 10 , comprising determining whether the hardware or software of the UAV has been modified. <Claim 14> The method of claim 10 , wherein authenticating the UAV includes generating the authorization hash code corresponding to the UAV and storing the authorization hash code. <Claim 15> 15. The method of claim 14, wherein the computing component at the remote location maintains a table of the authentication codes of a plurality of UAVs, and the computing component is configured with software including instructions to generate the verification hash code, compare the generated verification hash code with the authentication codes in the table, and authorize the UAV if the authorization hash code of the UAV matches the verification hash code. <Claim 16> 15. The method of claim 14, wherein the computing component at the remote location maintains a table of the authentication codes for a plurality of UAVs, and the computing component is configured with software including instructions to generate the verification hash code, compare the generated verification hash code with the authentication hash codes in the table, and determine whether the UAV hardware components or the UAV software have been modified since the last time the UAV was authenticated. <Claim 17> The method of claim 10 , wherein the unique identifier comprises a serial number. <Claim 18> 11. The method of claim 10, wherein the step of obtaining a unique identifier is performed for one hardware component of the plurality of hardware components and software, and the verification hash code is generated from a combination of the at least one hardware unique identifier obtained for the hardware and the unique identifier obtained for the software. <Claim 19> 20. The method of claim 18, wherein the computing component at the remote location maintains a table of the authentication codes for a plurality of UAVs, and the computing component is configured with software including instructions to generate the verification hash code, compare the generated verification hash code with the authentication codes in the table, and authorize the UAV if the UAV authorization hash code matches the verification hash code. <Claim 20> The method of claim 19, further comprising operating the UAV if the UAV is authorized by the UAV verification hash code. <Claim 21> The method of claim 10 , wherein the transmitting of the encrypted verification hash code occurs over a wireless communication network. <Claim 22> The method of claim 10 , wherein the transmission of the encrypted verification hash code occurs over a wired communications network. <Claim 23> 11. The method of claim 10, wherein the UAV is provided with a TPM standard-compliant chip / system to generate an authorization hash code, obtain a unique identifier for at least one of (i) a hardware component among the plurality of hardware components, or (ii) the software, and generate a validation hash code for the at least one hardware component or software from the unique identifier. <Claim 24> The method of claim 23 , wherein the UAV includes firmware or software that includes an fTPM system. <Claim 25> The method of claim 23 , wherein the TPM standard-compliant chip / system encrypts communications between the UAV and the remotely located computing component. <Claim 26> The method of claim 10 , wherein the remotely located computing component comprises a central command and control system. <Claim 27> 11. The method of claim 10, wherein a firmware TPM (fTPM) function resides within the at least one computing component electronically coupled to one or more of the plurality of hardware components or the software of the UAV to generate the authorization hash code, obtain a unique identifier for at least one of (i) a hardware component of the plurality of hardware components, or (ii) the software, and generate a validation hash code for the at least one hardware component or software from the unique identifier. <Claim 28> The method of claim 10 , wherein encrypting the verification hash code comprises implementing a public key system or a private key system. <Claim 29> 20. The method of claim 18, wherein the public or private key system includes one or both of a time element and a location element for further encrypting the hash code. <Claim 30> An unmanned aerial vehicle, a plurality of hardware components including at least one processing component, at least one storage component, at least one rotor, and an associated drive component connected to said rotor for driving said rotor; software stored on said storage component; Power supply and a control mechanism for controlling the speed and direction of the aircraft; communications hardware for sending and receiving communications; a system interfacing with the communications hardware of the UAV, the software of the UAV, and at least one of the plurality of hardware components; The UAV is generating an authorization hash code corresponding to the UAV; obtaining a unique identifier for at least one of (i) a hardware component of the plurality of hardware components or (ii) the software; generating a verification hash code for the at least one hardware component or software from the unique identifier; encrypting the verification hash code; an unmanned aerial vehicle configured to execute software that transmits the encrypted verification hash code via the communications hardware over a communications network to a computing component at a remote location. <Claim 31> 31. The aircraft of claim 30, wherein the UAV is configured to communicate via the communications hardware with a remote computing component that can access the authorization hash code, and that is configured to decrypt the encrypted verification hash code, compare the verification hash code with the stored authorization hash code, and verify authorization of the UAV if the verification hash code matches the UAV's stored authorization hash code. <Claim 32> 32. The aircraft of claim 31, wherein the aircraft is configured to receive an operation code upon validation. <Claim 33> 32. The aircraft of claim 31, wherein the UAV is configured to execute software including instructions provided as part of a TPM standard compliant chip / system. <Claim 34> A firmware TPM (fTPM) function is present in at least one of the plurality of hardware components, and the fTPM includes: generating an authorization hash code corresponding to the UAV; obtaining a unique identifier for at least one of (i) a hardware component of the plurality of hardware components or (ii) the software; generating a verification hash code for the at least one hardware component or software from the unique identifier; 34. The aircraft of claim 33, including instructions for encrypting the verification hash code. <Claim 35> 35. The aircraft of claim 34, wherein the fTPM includes instructions for transmitting the encrypted verification hash code via the communications hardware over a communications network to a computing component at the remote location.

Claims

1. residing within an unmanned aerial vehicle (UAV) and interfacing with a communication system of the UAV and with both software and hardware resources of the UAV; Obtaining serial numbers or unique identifiers for the hardware and software on the UAV; b. Creating a hash code combination of the serial number or the unique identifier; c. encrypting the hash code using a cryptographic algorithm having a verification protocol; d. transmitting the encrypted hash code via a wired or wireless communication system to a computer maintaining a table of authentication codes for a plurality of UAVs, thereby causing verification of the UAV by the computer; Capable of executing firmware, e. After performing steps a through d, the computer determines whether the hardware and software of the UAV have been modified since the UAV was last authenticated, f. the verification protocol is a zero-knowledge proof protocol, and the system performs verification of the UAV while the UAV is in flight using the cryptographic algorithm with the zero-knowledge proof protocol; g. If the verification fails during flight of the UAV, the system operates the UAV to land the UAV at a specified location or return control of the UAV to manual control; h) The system wherein the hash code and the encryption algorithm are unknown to the owner or operator of the UAV, and verification of UAV certification parameters remains unknown to the UAV.

2. The system of claim 1 , wherein the UAV includes a Trusted Platform Module (TPM) standard-compliant chip / system to verify the integrity of the UAV's hardware.

3. The system of claim 1 , wherein the UAV includes software or firmware that comprises a firmware trusted platform module (fTPM) system.

4. 3. The system of claim 2, further comprising an automated central command and control system.

5. The system of claim 4 wherein the central command and control system is human operated.

6. 4. The system of claim 3, wherein firmware TPM (fTPM) functionality resides in a computer located on the UAV for performing the functions described in a. through d.

7. 2. The system of claim 1, further comprising a public or private key system configured to further encrypt the hash code generated in step b.

8. The system of claim 7 , wherein the public or private key system includes a time and / or location component that can be used to further encrypt the hash code.

9. 1. A method for securing operation of a wireless air vehicle (UAV), including during flight of the UAV, the UAV comprising a plurality of hardware components and software, the method comprising: generating an authorization hash code corresponding to at least one UAV and storing the authorization hash code; providing at least one computing component electronically coupled to one or more of the plurality of hardware components or the software of the at least one UAV; obtaining a unique identifier for at least one of (i) the plurality of hardware components or (ii) the software; generating a verification hash code of the at least one hardware component or software from the unique identifier; encrypting the verification hash code using a cryptographic algorithm having a verification protocol; transmitting the encrypted verification hash code to a remotely located computing component over a communications network; decrypting the encrypted verification hash code; comparing the verification hash code with the stored authorization hash code; authorizing the UAV if the verification hash code matches the stored authorization hash code; the verification protocol is a zero-knowledge proof protocol, and securing the operation of the UAV includes performing verification of the UAV during flight of the UAV using the cryptographic algorithm having the zero-knowledge proof protocol, and if the verification during flight of the UAV fails, operating the UAV to land the UAV at a specific location or return control of the UAV to manual control; The method wherein the verification hash code and the encryption algorithm are unknown to the owner or operator of the UAV, and verification of UAV certification parameters remains unknown to the UAV.

10. The method of claim 9 , wherein the stored authorization hash code is stored in a database.

11. The method of claim 10 , further comprising providing a database having a plurality of stored authorization hash codes, each of the plurality of stored authorization hash codes corresponding to a particular UAV.

12. The method of claim 9 , further comprising determining whether one of the hardware components or the software of the UAV has been modified.

13. The method of claim 9 , further comprising authenticating the UAV by generating the authorization hash code corresponding to the UAV and storing the authorization hash code.

14. The method of claim 13, wherein the computing component at the remote location maintains a table of the authorization hash codes of a plurality of UAVs, and the computing component at the remote location is configured with software including instructions to generate the verification hash code, compare the generated verification hash code with the authorization hash codes in the table, and authorize the UAV if the authorization hash code matches the verification hash code.

15. The method of claim 13, wherein the remotely located computing component maintains a table of the authorization hash codes for a plurality of UAVs, and the remotely located computing component is configured with software including instructions to generate the verification hash code, compare the generated verification hash code with the authorization hash codes in the table, and determine whether the hardware components or the software have been modified since the last time the UAV was authenticated.

16. The method of claim 9 , wherein the unique identifier comprises a serial number.

17. 10. The method of claim 9, wherein the step of obtaining a unique identifier is performed for at least one hardware component of the plurality of hardware components and for software, and the verification hash code is generated from a combination of the at least one hardware component unique identifier obtained for the hardware component and the unique identifier obtained for the software.

18. The method of claim 17, wherein the computing component at the remote location maintains a table of the authorization hash codes for a plurality of UAVs, and the computing component is configured with software including instructions to generate the verification hash code, compare the generated verification hash code with the authorization hash codes in the table, and authorize the UAV if the authorization hash code matches the verification hash code.

19. The method of claim 18, including operating the UAV if the UAV is authorized by the verification hash code.

20. 10. The method of claim 9, wherein the transmission of the encrypted verification hash code occurs over a wireless communication network.

21. 10. The method of claim 9, wherein the transmission of the encrypted verification hash code occurs over a wired communications network.

22. 10. The method of claim 9, wherein the UAV is provided with a Trusted Platform Module (TPM) standard compliant chip / system to generate an authorization hash code, obtain a unique identifier for at least one hardware component of the plurality of hardware components, or (ii) the software, and generate a validation hash code for the at least one hardware component or software from the unique identifier.

23. 23. The method of claim 22, wherein the UAV includes firmware or software that includes a firmware trusted platform module (fTPM) system.

24. The method of claim 22 , wherein the TPM standard compliant chip / system encrypts communications between the UAV and a computing component at the remote location.

25. The method of claim 9 , wherein the remotely located computing component comprises a central command and control system.

26. 10. The method of claim 9, wherein a firmware TPM (fTPM) function resides within at least one computing component electronically coupled with one or more of the plurality of hardware components or the software of the UAV to generate the authorization hash code, obtain a unique identifier for at least one of (i) the plurality of hardware components, or (ii) the software, and generate a verification hash code for the at least one hardware component or software from the unique identifier.

27. The method of claim 9 , wherein encrypting the verification hash code comprises implementing a public key system or a private key system.

28. 28. The method of claim 27, wherein the public or private key system includes one or both of a time element and / or a location element that may be used to further encrypt the verification hash code.

29. An unmanned aerial vehicle (UAV), a plurality of hardware components including at least one processing component, at least one storage component, at least one rotor, and an associated drive component connected to said rotor for driving said rotor; software stored on said storage component; Power supply and a control mechanism for controlling the speed and direction of the UAV; communications hardware for sending and receiving communications; a system interfacing with at least one of the communications hardware, software, and hardware components of the UAV; The UAV is generating an authorization hash code corresponding to the UAV; Obtaining a unique identifier for at least one of (i) the plurality of hardware components or (ii) the software; generating a verification hash code for the at least one hardware component or software from the unique identifier using a cryptographic algorithm having a verification protocol; encrypting the verification hash code; transmitting the encrypted verification hash code via the communications hardware over a communications network to a remote computing component; performing verification of the UAV while the UAV is in flight; The unmanned aerial vehicle is configured to execute software that operates the UAV to land the UAV at a specific location or return control of the UAV to manual control if the verification protocol is a zero-knowledge proof protocol, the verification hash code and the cryptographic algorithm are unknown to the owner or operator of the UAV, and verification of UAV certification parameters remains unknown to the UAV, and if the verification fails during flight of the UAV.

30. 30. The unmanned aerial vehicle of claim 29, wherein the UAV is configured to communicate via the communications hardware with a remote computing component that can access the authorization hash code, decrypt the encrypted verification hash code, compare the verification hash code with the stored authorization hash code, and verify authorization of the UAV if the verification hash code matches the UAV's stored authorization hash code.

31. The unmanned aerial vehicle of claim 30 , wherein the UAV is configured to receive an operation code once verified.

32. The unmanned aerial vehicle of claim 30 , wherein the UAV is configured to execute software including instructions provided as part of a Trusted Platform Module (TPM) standard compliant chip / system.

33. a firmware TPM (fTPM) function residing within at least one of the plurality of hardware components, the firmware TPM (fTPM) function comprising: generating an authorization hash code corresponding to the UAV; Obtaining a unique identifier for at least one of (i) the plurality of hardware components or (ii) the software; generating a verification hash code for the at least one hardware component or software from the unique identifier using a cryptographic algorithm having a verification protocol; The unmanned aerial vehicle of claim 32 , including instructions for encrypting the verification hash code.

34. 34. The unmanned aerial vehicle of claim 33, wherein the firmware TPM (fTPM) functionality includes instructions for transmitting the encrypted verification hash code via the communications hardware over a communications network to a computing component at the remote location.

Citation Information

Patent Citations

  • Systems and methods for identity-based encryption and related cryptographic methods

    JP2005500740A

  • Platform validation and management of wireless devices

    JP2014075841A

  • Method and system for verifying software platform of vehicle

    US20110138188A1

  • Controlled range and payload for unmanned vehicles, and associated systems and methods

    US20140379173A1

  • Management of Authenticated Variables

    US20150379306A1