UAV User-Plane Authentication via Third-Party UTM Authorization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems lack efficient methods for unmanned aerial vehicle (UAV) authentication and authorization by third-party service providers using the user plane, which is crucial for secure communication and traffic management.
Innovation Solution
UAVs and network devices communicate with a third-party service provider using security information such as tokens or keys, including UAV IDs and subscription identifiers, to establish secure connections for communication sessions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If UAVs use traditional authentication methods with ground control stations, then communication security is maintained, but traffic management efficiency and scalability are reduced
Solution Approach 1:
The patent introduces a third-party service provider as an intermediary authentication server that mediates between UAVs and ground control stations. This intermediary handles authentication and authorization using security information (tokens/keys) exchanged through the network, enabling scalable traffic management while maintaining security through centralized credential verification without requiring direct secure channels between every UAV and ground station.
Solution Approach 2:
The authentication system is segmented into separate functional components: UAV clients, network devices, third-party service providers, and ground control stations. Each entity has specific authentication responsibilities, allowing parallel processing of multiple authentication requests and improving overall traffic management efficiency while maintaining security through distributed authentication operations.
2Adaptability or versatility
If centralized authentication is implemented through ground control stations, then security is maintained, but system complexity and deployment difficulty increase
Solution Approach 1:
The third-party service provider implements a universal authentication mechanism that serves multiple functions: authentication, authorization, token distribution, and security verification. This multi-functional approach consolidates what would otherwise require separate systems, reducing overall deployment complexity while maintaining security and enabling flexible adaptation to different UAV and ground control station configurations.
3Loss of time
If security information is exchanged directly between UAVs and ground control stations, then communication security is ensured, but network overhead and authentication time increase
Solution Approach 1:
Authentication credentials (tokens and keys) are preliminarily established and cached by network devices during initial UAV registration. When authentication is needed, these pre-established credentials are quickly verified without requiring real-time direct communication between UAVs and ground control stations, significantly reducing authentication time while maintaining security through the pre-validated credential verification process.
Data Source
AI summary
An unmanned aerial vehicle (UAV) authentication and authorization may be performed by a third-party service provider (e.g., an unmanned aerial system traffic management (UTM) over a user plane (UP). An UAV may be configured to send an UAV ID to a network. The UAV may receive, from the network, security information that indicates an authorization of a connection to a third-party service provider. The UAV may establish, based on the security information, the connection to the third-party service provider for communications with the third-party service provider. The security information may include signature information of the third-party service provider, and one or more of a subscription identifier (ID) associated with the UAV, the UAV ID, or an ID of the third-party service provider.


