UAV Security Credentials via Cellular Network Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Unmanned aerial vehicles (UAVs) face security breaches due to falsified remote IDs, leading to potential denial of service attacks and inefficient operations, as existing remote identification systems lack robust security measures to authenticate and verify UAV identities.
Innovation Solution
A method and system for providing security credentials to UAVs through a terrestrial cellular network, where a user equipment (UE) associated with a UAV registers with network entities like UDM and AMF, receives a security configuration, and communicates securely with service suppliers using generated or provided security credentials, including certificates and keys, to authenticate and verify identities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing remote identification systems are used for UAVs, then basic identification functionality is provided, but security against falsified IDs and denial of service attacks is insufficient
Solution Approach 1:
A network entity acts as an intermediary between the UAV and the remote identification system. The network entity receives security credentials from a unified data management entity and provides them to the UAV through structured signaling messages. This intermediary approach enhances security by introducing authenticated credential distribution while managing system complexity through standardized communication protocols.
Solution Approach 2:
Security credentials are generated and distributed to the UAV in advance through the network entity before the UAV operates. The unified data management entity creates security credentials and the network entity delivers them to the UAV through registration procedures. This preliminary action ensures that security measures are in place before potential threats occur, improving reliability without adding operational complexity.
2Reliability
If security credentials are distributed through network signaling, then authentication capability is enhanced, but signaling overhead and network resource usage increase
Solution Approach 1:
The network entity performs multiple functions using the same signaling infrastructure: it manages registration procedures, distributes security credentials, and maintains communication with both the UAV and the unified data management entity. This multi-functionality enhances authentication capability while minimizing additional signaling overhead by reusing existing network resources.
Solution Approach 2:
The system changes the state of security credentials from absent to present through controlled parameter updates in signaling messages. The network entity manages the transition of credential parameters (generation, distribution, activation) through standardized message exchanges, enhancing authentication capability while keeping signaling overhead manageable through efficient parameter management.
Data Source
AI summary
Methods, systems, and devices for wireless communications are described. A user equipment (UE) associated with an unmanned aerial vehicle (UAV) in a cellular terrestrial network may establish a connection with a unified data management (UDM) entity for communications with an unmanned aerial system service supplier (USS). The UE, or an access and mobility management function (AMF), may receive a security configuration from the UDM entity in a non-access stratum transport message. The security configuration may include one or more security credentials that enable communications between the UE and the USS. The AMF may transmit an acknowledgement message indicating the UE successfully received the indication of the security configuration. The UDM may transmit a message to the USS based on receiving the acknowledgment message. The UE may transmit a registration request to the USS. The UE and the USS may communicate according to the security credentials of the security configuration.


