WO2021134712A1 - Load authentication method and system, mobile platform, load, and transfer device - Google Patents

Load authentication method and system, mobile platform, load, and transfer device Download PDF

Info

Publication number
WO2021134712A1
WO2021134712A1 PCT/CN2019/130967 CN2019130967W WO2021134712A1 WO 2021134712 A1 WO2021134712 A1 WO 2021134712A1 CN 2019130967 W CN2019130967 W CN 2019130967W WO 2021134712 A1 WO2021134712 A1 WO 2021134712A1
Authority
WO
WIPO (PCT)
Prior art keywords
load
movable platform
switching device
function
authentication information
Prior art date
Application number
PCT/CN2019/130967
Other languages
French (fr)
Chinese (zh)
Inventor
王钧玉
Original Assignee
深圳市大疆创新科技有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 深圳市大疆创新科技有限公司 filed Critical 深圳市大疆创新科技有限公司
Priority to PCT/CN2019/130967 priority Critical patent/WO2021134712A1/en
Priority to CN201980095977.7A priority patent/CN113767605A/en
Publication of WO2021134712A1 publication Critical patent/WO2021134712A1/en

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/40Network security protocols
    • BPERFORMING OPERATIONS; TRANSPORTING
    • B64AIRCRAFT; AVIATION; COSMONAUTICS
    • B64UUNMANNED AERIAL VEHICLES [UAV]; EQUIPMENT THEREFOR
    • B64U20/00Constructional aspects of UAVs
    • B64U20/80Arrangement of on-board electronics, e.g. avionics systems or wiring
    • B64U20/87Mounting of imaging devices, e.g. mounting of gimbals

Definitions

  • the present invention relates to the field of communication technology, in particular to a load authentication method and system, a movable platform, a load, and a switching device.
  • the load mounted on the mobile platform can be an SDK product developed based on the SDK (Software Development Kit, software development kit).
  • the SDK is generally provided to users in the form of open source or in the form of library files.
  • illegal users can steal the user information of legitimate users by monitoring the communication data when the mobile platform communicates with the load.
  • Illegal users can use the user information of legitimate users, impersonate legitimate users, or even The movable platform may be illegally controlled, and the security risk is relatively high.
  • the embodiment of the present invention provides a load authentication method and system, a movable platform, a load, and a switching device, which can set the functional authority of the load according to the load authentication information, improve the reliability of the load authentication, and ensure the safety of the movable platform Sex.
  • an embodiment of the present invention provides a load authentication system, where the load authentication system includes a movable platform and a load;
  • the movable platform is configured to send a load authentication request to the load when it is detected that the load is connected to the movable platform;
  • the load is used to receive the load authentication request sent by the movable platform, and based on the load authentication request, send load authentication information of the load to the movable platform;
  • the mobile platform is further configured to receive the load authentication information sent by the load, and determine the functional authority of the load according to the load authentication information;
  • the movable platform is also used to determine the open function between the load and the movable platform according to the functional authority of the load.
  • an embodiment of the present invention provides a load authentication method, which is applied to a mobile platform, and the method includes:
  • an open function between the load and the movable platform is determined.
  • an embodiment of the present invention provides a load authentication method, which is applied to a switching device, and the method includes:
  • an embodiment of the present invention provides a load authentication method, which is applied to a load, and the method includes:
  • the load authentication information of the load is sent to the mobile platform, so that the mobile platform determines the load and the function authority of the load determined by the load authentication information Open functions between the movable platforms.
  • an embodiment of the present invention provides a movable platform, the movable platform includes a memory and a processor, and the memory and the processor are connected to each other, wherein:
  • the memory is used to store a computer program, and the computer program includes program instructions
  • the processor calls the program instructions for:
  • an open function between the load and the movable platform is determined.
  • an embodiment of the present invention provides a switching device, the switching device includes a memory and a processor, the memory and the processor are connected to each other, wherein:
  • the memory is used to store a computer program, and the computer program includes program instructions
  • the processor calls the program instructions for:
  • an embodiment of the present invention provides a load, the load includes a memory and a processor, and the memory and the processor are connected to each other, wherein:
  • the memory is used to store a computer program, and the computer program includes program instructions
  • the processor calls the program instructions for:
  • the load authentication information of the load is sent to the movable platform, so that the movable platform determines the functional authority of the load according to the load authentication information, and determines the relationship between the load and the load. Describes the open functions between the movable platforms.
  • an embodiment of the present invention provides a carrier assembly, including a carrier and the adapter device according to the sixth aspect of the embodiment of the invention, the adapter device being provided on the carrier.
  • an embodiment of the present invention provides a movable platform assembly, including the movable platform described in the fifth aspect of the embodiments of the present invention and the carrier assembly described in the eighth aspect of the embodiments of the present invention, the carrier assembly and The movable platform is connected.
  • an embodiment of the present invention provides a computer-readable storage medium having a computer program stored on the computer-readable storage medium, and when the computer program is executed, it achieves the same as described in the second aspect of the embodiment of the present invention.
  • an embodiment of the present invention provides a computer-readable storage medium having a computer program stored on the computer-readable storage medium, and the computer program, when executed, realizes the same as the third aspect of the embodiment of the present invention The load authentication method.
  • an embodiment of the present invention provides a computer-readable storage medium, and a computer program is stored on the computer-readable storage medium.
  • the computer program When executed, it implements the fourth aspect of the embodiment of the present invention.
  • the load authentication method When the computer program is executed, it implements the fourth aspect of the embodiment of the present invention.
  • the mobile platform when the mobile platform detects that the load is connected to the mobile platform, it sends a load authentication request to the load. After the load receives the load authentication request sent by the mobile platform, it sends the load authentication information of the load to the mobile platform. The mobile platform, after receiving the load authentication information sent by the load, the mobile platform determines the functional authority of the load according to the load authentication information, and the mobile platform further determines the open functions between the load and the mobile platform according to the functional authority of the load.
  • the functional authority of the load can be set according to the load authentication information, and the reliability of the load authentication is improved, thereby ensuring the safety of the movable platform.
  • FIG. 1 is a schematic diagram of a link of a load authentication system provided by an embodiment of the present invention
  • FIG. 2 is a schematic flowchart of a load authentication method provided by an embodiment of the present invention.
  • FIG. 3 is a schematic flowchart of a method for authenticating a load according to an embodiment of the present invention
  • FIG. 4 is a schematic diagram of a successful flow of load authentication provided by an embodiment of the present invention.
  • FIG. 5 is a schematic flowchart of a method for authenticating a switching device according to an embodiment of the present invention
  • FIG. 6 is a schematic flowchart of an exemplary load authentication method provided by an embodiment of the present invention.
  • Figure 7 is a schematic structural diagram of a movable platform provided by an embodiment of the present invention.
  • FIG. 8 is a schematic structural diagram of a switching device provided by an embodiment of the present invention.
  • Fig. 9 is a schematic structural diagram of a load provided by an embodiment of the present invention.
  • the movable platform can expand the functions of the movable platform by mounting a load such as a shooting device (such as a video camera, a camera, a camera, etc.) or a loudspeaking device (such as a megaphone, etc.).
  • a load such as a shooting device (such as a video camera, a camera, a camera, etc.) or a loudspeaking device (such as a megaphone, etc.).
  • the load mounted on the mobile platform can be authenticated before use.
  • the mobile platform can authenticate the load by verifying the relevant information of the load, but in this process, user information is easy to leak, and illegal users can use the illegally obtained information to perform all the functions of the load, and then can illegally steal The data or control of the mobile platform poses a greater security risk.
  • the embodiment of the present invention provides a load authentication method and a load authentication system.
  • a functional filtering firewall is constructed between the load and the mobile platform.
  • the mobile platform can determine the functional authority of the load according to the firewall level certificate of the load, and then The open functions between the load and the movable platform can be determined, and the reliability of the authentication of the load by the movable platform is improved, thereby ensuring the safety of the movable platform.
  • the movable platform mentioned in the embodiment of the present invention may be provided by a supplier (ie, the first party), and the load may be provided by a developer (ie, the second party).
  • the load can be mounted on a carrier, such as a pan/tilt.
  • the load can communicate with the carrier and the movable platform through a transfer device set on the carrier, and form a corresponding communication link, carrier and transfer
  • the device can also be provided by the supplier.
  • the movable platform may include unmanned aerial vehicles, unmanned vehicles, unmanned ships, handheld devices, and so on.
  • FIG. 1 is a schematic diagram of a link of a load authentication system provided by an embodiment of the present invention.
  • the load authentication system includes: a load 101, a switching device 102, a movable platform 103, a terminal device installed with an application 104, and Server 105.
  • the load 101 is mounted on a carrier (not shown in the figure) through an adapter device 102, and the adapter device 102 is installed on the carrier (not shown in the figure), and the carrier is used to connect with the movable platform 103.
  • the mobile platform 103 can be connected to the terminal device installed with the application program 104 in a wired manner, or can be connected to the terminal device installed with the application program 104 in a wireless manner, and the terminal device 104 can be connected to the server 105.
  • the mobile platform 103 when the mobile platform 103 is wirelessly connected to the terminal device installed with the application 104, it can be directly connected to the terminal device installed with the application 104, or it can be connected to the terminal device installed with the application 104 through the remote control device of the movable platform 103 and the installation.
  • the terminal device with the application 104 is connected.
  • the load can be authenticated.
  • the mobile platform 103 and the server 105 can be connected in different ways, and the terminal device installed with the application 104 can also be used. Different, and the functions that can be opened by the application 104 may also be different. For details, please refer to the subsequent description.
  • the developer when the developer develops the load based on the carrier provided by the supplier, he can register enterprise user information on the website provided by the supplier. After the registration is successful, the developer side can obtain the corresponding application information, which can include the product name (the product includes a combination device consisting of a load and a carrier, and the carrier is equipped with a switching device), an identity mark and an authentication secret key.
  • the corresponding product name can be different, and the corresponding authentication key and identity can be the same; for different products of different developers, the corresponding product name, authentication key and identity can be Both can be different.
  • the developer can write the corresponding application information into the load during the development of the load. Further, after the user purchases the product provided by the developer, the corresponding firewall level certificate can be downloaded to limit the open function between the load and the mobile platform.
  • the encryption chip of the switching device 102 stores the SN (Serial Number) of the load 101, and the SN can uniquely identify the load 101; the encryption chip can also store supplier information, such as the anti-counterfeiting identification of the supplier’s product, It is used to authenticate the switching device, for example; the encryption chip may also store a first key, and the first key is used to assist the authentication of the switching device.
  • SN Serial Number
  • supplier information such as the anti-counterfeiting identification of the supplier’s product
  • the mobile platform 103 includes a certification center and a server.
  • the certification center is an application established based on the server 105 and runs on the mobile platform.
  • the certification center stores a second key obtained from the server 105.
  • the second key can be
  • the only authentication load is 101.
  • the firewall of the mobile platform 103 is an application program running on the mobile platform. The firewall can determine the open functions between the load 101 and the mobile platform 103, thereby allowing commands to execute related open functions between the load 101 and the mobile platform 103. Passed between.
  • the application 104 can run in a terminal device, and the user can interact with the movable platform 103 and the switching device 102 through the application 104 to start the load authentication process.
  • the terminal device may be a mobile terminal, a personal computer (PC) end or a portable computer (Tablet Personal Computer, Tablet PC) end, etc., and may also be a remote control device of a movable platform.
  • the server 105 stores the application information registered by the developer on the development website provided by the supplier.
  • the application information may include the product name (the product includes a combination device consisting of a load and a carrier, and the carrier is provided with a switching device), Identification (such as the supplier's registration ID) and authentication key.
  • the server 105 may also store related information about the switching device 102, the load 101, etc., such as SN.
  • FIG. 2 is a schematic flowchart of a load authentication method provided by an embodiment of the present invention.
  • the load authentication method includes but is not limited to the following steps:
  • Step S201 The mobile platform sends a load authentication request to the load.
  • the authentication of the load includes the authentication of the functional authority of the load, that is, the open function between the load and the movable platform is specified.
  • the mobile platform in the actual authentication process, it can be divided into online mode and offline mode. That is, when the mobile platform is in communication with the server, either online mode or offline mode can be used to authenticate the load; and when the mobile platform is not in communication with the server, the offline mode can be used to authenticate the load.
  • Perform authentication Specifically, in order to be able to authenticate the load in offline mode, the mobile platform may store corresponding information for authenticating the functional authority of the load, such as a key, and the key (such as the second key described above) can be It is used to decrypt the obtained firewall certificate.
  • the functional authority of the load such as a key
  • the key such as the second key described above
  • the mobile platform may send a load authentication request to the load to obtain load authentication information for authenticating the load.
  • the load can be authenticated so that it can be authenticated every time the load is used, preventing the risk of load being replaced, thereby ensuring the load It has always been a payload, which improves the security of the application.
  • the load can be initially authenticated once, or it can be authenticated multiple times continuously or at intervals during the use process, which is not specifically limited here.
  • Step S202 The load may send load authentication information of the load to the mobile platform based on the load authentication request.
  • the load After the load receives the load authentication request sent by the mobile platform, the load can send the load authentication information of the load to the mobile platform based on the load authentication request, and the mobile platform can receive the load authentication information sent by the load.
  • the legality of the load can be checked. And the legitimacy of the transfer device is verified, for example: if the transfer device passes the load authentication, the transfer device receives the load authentication information sent by the load; if the mobile platform passes the authentication of the transfer device, the mobile platform receives the transfer Load authentication information sent by the receiving device.
  • the timing between steps is not limited to this.
  • the transfer device receives the load authentication request sent by the mobile platform; if the transfer device If the load authentication is passed, the load receives the load authentication request sent by the switching device; the authentication process of the mobile platform for authenticating the switching device and the authentication process of the switching device for authenticating the load can also be performed at the same time.
  • FIG. 3 is a schematic flowchart of a method for authenticating the load provided by an embodiment of the present invention; the movable platform performs the authentication on the transfer device.
  • FIG. 5 for the authentication process of legality authentication.
  • FIG. 5 is a schematic flowchart of a method for authenticating a switching device according to an embodiment of the present invention, and details are not described herein again.
  • Step S203 The mobile platform determines the functional authority of the load according to the load authentication information.
  • the load authentication information may include the firewall grade certificate of the load, and the mobile platform may determine the functional authority of the load according to the firewall grade certificate of the load.
  • the form of load authentication information is not limited to the firewall level certificate.
  • the firewall is set on the mobile platform, so that the open function between the load and the mobile platform can be limited through the firewall.
  • It can also be embodied in other forms, which can indicate the open function between the load and the movable platform, for example, encrypted identification information, which is used to indicate the open function between the load and the movable platform.
  • the firewall level certificate of the payload in order to prevent the firewall level of the payload from being tampered with, can be encrypted information, and the mobile platform can use the second key as described above to decrypt the encrypted firewall level certificate to obtain
  • the decrypted firewall level certificate, and the decrypted firewall level certificate may include the firewall level of the load. If the certification center of the mobile platform determines that the decrypted firewall level certificate is a valid firewall level certificate based on the certificate number and validity period of the decrypted firewall level certificate, the mobile platform can determine the firewall level of the load according to the firewall level of the load.
  • the functional authority corresponding to the level if the certification center of the mobile platform determines that the decrypted firewall level certificate is an invalid firewall level certificate according to the certificate number and validity period of the decrypted firewall level certificate, the mobile platform can change the received load
  • the firewall level certificate of the mobile platform is deleted from the storage space of the mobile platform, and the open function between the load and the mobile platform can be closed, and the user can be prompted accordingly.
  • the mobile platform can send out a photoelectric prompt, or The remote control side of the platform gives a prompt.
  • the firewall level can include ordinary service level and value-added service level.
  • the ordinary service level means that the firewall can allow some basic commands to pass, such as commands that allow the control of PTZ and image transmission.
  • the value-added service level means that the firewall can allow some Advanced commands are passed, such as allowing control of movable platforms. If the firewall level of the load is a normal service level, the mobile platform can determine that the function authority of the load corresponding to the normal service level is the normal service function authority; if the firewall level of the load is a value-added service level, the mobile platform can determine the value-added service level The function authority of the corresponding load is the value-added service function authority. Among them, the value-added service function authority may include the normal service function authority.
  • the firewall of the mobile platform can send a policy file acquisition request to the certification center of the mobile platform, and the firewall of the mobile platform receives After the policy file acquisition request, the policy file can be returned to the certification center of the mobile platform based on the policy file acquisition request.
  • the policy file may include a preset correspondence relationship between the firewall level and the function authority.
  • the firewall level may include a normal service level and a value-added service level; the function authority may include a normal service function authority and a value-added service function authority.
  • the preset correspondence between the firewall level and the function authority may include the correspondence between the ordinary service level and the ordinary service function authority, and the correspondence between the value-added service level and the value-added service function authority.
  • the mobile platform can determine the current firewall level of the load according to the firewall level certificate of the load, so that the mobile platform can determine the functional authority of the load according to the preset correspondence between the firewall level and the functional authority and the current firewall level of the load.
  • the mobile platform can determine that the functional authority of the load is a normal service function authority; if the current firewall level of the load is a value-added service level, the mobile platform can determine that the functional authority of the load is a value-added service function Permissions.
  • the classification of firewall levels may not be limited to the ordinary service levels and value-added service levels described above, but may also include multiple levels.
  • the corresponding function permissions between each level may be different or partly different. The number of function permissions is also different. Different settings can be made accordingly.
  • the firewall level certificate of the load can be updated. After the firewall level certificate of the load is updated, the mobile platform can obtain the updated firewall level certificate of the load, so that the mobile platform can update the firewall level according to the load. The certificate determines the functional authority corresponding to the updated firewall level certificate.
  • the policy file in the certification center of the mobile platform can be updated.
  • the updated policy file may include the updated preset correspondence between the firewall level and the function authority, and the updated policy file can also be updated. It can include the updated preset corresponding relationship between the function authority and the function level of the open function.
  • the mobile platform can determine the updated function authority of the load according to the updated policy file and the firewall level certificate of the load, so that the mobile platform can be based on The updated functional authority of the load determines the updated open functions between the load and the mobile platform.
  • Step S204 The movable platform determines the open function between the load and the movable platform according to the functional authority of the load.
  • the open function may include at least one of a data transmission function that allows a movable platform to the load or a carrier of the load, and a data transmission function that allows the load or a carrier of the load to the movable platform.
  • the data transmission function that allows the movable platform to the load or the carrier of the load may include, but is not limited to, the transmission function of the control command of the movable platform to the carrier of the load, the transmission function of the positioning data of the movable platform, and the acquisition of the movable platform from the ground terminal.
  • the data transmission function that allows the load or the load carrier to the movable platform may include, but is not limited to, at least one of the transmission function of the collected data of the load and the transmission function of the control command of the load to the movable platform.
  • the transmission function of the control command of the movable platform to the carrier of the load and the transmission function of the control command of the load to the movable platform are functions related to control.
  • the transmission function of the positioning data of the movable platform is a function related to positioning. If the multimedia data acquired by the mobile platform from the ground side and the data collected by the load are image data, the transmission function of the multimedia data acquired by the mobile platform from the ground side and the transmission function of the collected data on the load are image-related Function; if the multimedia data acquired by the mobile platform from the ground side and the data of the collected data of the load are audio data, the transmission function of the multimedia data acquired by the mobile platform from the ground side and the transmission function of the collected data of the load are audio data Related functions. That is, the open function may include, but is not limited to, at least one of a control-related function, an image-related function, an audio-related function, and a positioning-related function.
  • the carrier of the load is a gimbal.
  • the control-related functions can be to control the rotation of the PTZ through the load and the flight of the unmanned aerial vehicle through the load;
  • the image-related functions can be the unmanned aerial vehicle to transmit the image data taken by the unmanned aerial vehicle to the load, among which, the image data
  • the bit stream bandwidth required for transmission can be different according to the firewall level;
  • audio-related functions can be for users to upload voice to the load through terminal equipment, for example, through the load for playback;
  • positioning-related functions can be obtained by the load RTK (Real-time Kinematic) data on the unmanned aerial vehicle.
  • the RTK data is combined with the image data collected by the load to construct a three-dimensional model.
  • the same open function may include different function levels
  • the policy file obtained by the mobile platform may also include the preset correspondence between the function authority and the function level of the open function
  • the mobile platform may determine according to The obtained function authority of the load, the preset correspondence between the function authority and the function level of the open function, determine the open function between the load and the movable platform, and determine the function of the open function between the obtained load and the movable platform
  • the level is adapted to the determined functional authority of the load.
  • the function authority may include ordinary service function authority and value-added service function authority;
  • the function level of the open function may include ordinary service function level 1, ordinary service function level 2, and value-added service function Level 1, value-added service function level 2;
  • the preset correspondence between function authority and open function function level may include the correspondence between ordinary service function authority and ordinary service function level, value-added service function authority and value-added service function level The corresponding relationship between is used to limit the openness of all functions in the same category.
  • the mobile platform can determine the normal service function level of the open function between the load and the mobile platform according to the normal service function authority; if it is determined that the function authority of the load obtained is Value-added service function authority, the mobile platform can determine the value-added service function level of the open function between the load and the mobile platform according to the value-added service function authority.
  • the unmanned aerial vehicle can determine the ordinary service function of the open function between the payload and the unmanned aerial vehicle according to the ordinary service function authority.
  • Level which can determine the open function between the load and the UAV; if the function authority of the obtained load is determined to be the value-added service function authority, the UAV can determine the open function between the load and the UAV according to the value-added service function authority.
  • the value-added service function level of the function so that the open function between the load and the UAV can be determined. For example, suppose the open function between the load and the UAV is a value-added service function.
  • the value-added service function includes not only the control of the PTZ through the load, but also the control of the UAV through the load.
  • the value-added service function level is 1 When the user can control the rotation of the PTZ through the load and control the drone through the load within a predetermined period of time, when the value-added service function level is 2, the user can control the rotation of the PTZ through the load and control the unmanned aircraft through the load.
  • the control of the machine is not limited within a predetermined period of time.
  • the same open function is the function with the same functional attribute, the image-related function, the image-related function can be divided into level 1, level 2, and the preset correspondence between the function authority and the function level of the open function
  • the relationship may include the corresponding relationship between the image-related functions and their function levels. If it is determined that the function authority of the load is an image-related function, the movable platform can determine the image-related function between the load and the movable platform according to the correspondence between the image-related function and its function level. Function level.
  • the unmanned aerial vehicle can determine the load and the ability according to the correspondence between the image-related function and its function level.
  • the function level of image-related functions between mobile platforms For example, assuming that the open function between the payload and the UAV is an image-related function, the bit stream bandwidth corresponding to level 1 is smaller than the bit stream bandwidth corresponding to level 2 during image transmission.
  • the mobile platform can determine the functional authority of the load according to the obtained authentication information of the load, that is, the firewall level certificate of the load, and the mobile platform can determine the functional authority of the load according to the functional authority of the load.
  • the level of the firewall level certificate is different, and the function authority of the determined load is also different, and the open function between the determined load and the movable platform may be different.
  • a functional filtering firewall is constructed between the load and the mobile platform, so that the open function between the load and the mobile platform corresponds to the level of the load’s firewall level certificate, and the load cannot be executed with the load’s firewall level certificate level.
  • Uncorresponding open functions can improve the reliability and security of load applications, and can also prevent the load from being used illegally.
  • FIG. 3 is a schematic flowchart of a method for authenticating a load according to an embodiment of the present invention.
  • the method for authenticating a load includes but is not limited to the following steps:
  • Step S301 The switching device sends preset data to the load.
  • the authentication of the load includes the authentication of the legitimacy of the load.
  • the authentication process of the load by the switching device mentioned in the embodiment of the present invention may be performed before the embodiment shown in FIG. 2.
  • the embodiment shown in FIG. 2 is executed to determine the open function between the movable platform and the load.
  • the authentication process of the load by the switching device mentioned in the embodiment of the present invention may also be executed when the switching device detects that the load is connected to the switching device.
  • the authentication process for the load by the switching device shown in FIG. 3 and the open function determination process shown in FIG. 2 may be executed simultaneously when the load is connected to the switching device.
  • the switching device may store corresponding information for authenticating the legitimacy of the load, such as a key (such as the authentication key described above).
  • the switching device may send preset data to the load, and the preset data may be a random string for verifying the legitimacy of the load.
  • Step S302 The load generates first verification data based on the preset data and the preset key.
  • the load After the load receives the preset data from the switching device, the load can calculate the preset key (such as the authentication key mentioned above) and the preset data of the load according to the preset verification algorithm to generate the first Check the data.
  • the load application information including authentication keys and other load stored in the load can be provided by the supplier and obtained by the developer after registering on the website provided by the supplier. After the developer obtains the application information, the application information can be written into it Under load.
  • the preset verification algorithm may include the MD5 algorithm, the CMAC algorithm, the SHA256 algorithm, the SHA512 algorithm, and so on.
  • Step S303 The load sends the first verification data to the switching device.
  • the load may send the generated first verification data to the switching device, and the switching device may perform legality authentication on the load through the first verification data.
  • Step S304 The switching device verifies the first verification data.
  • the switching device can establish a communication connection with the server, and the switching device can verify the first verification data through the server, that is, the switching device can verify the first verification data in an online mode. For example, after the switching device receives the first verification data from the load, the switching device sends the first verification data and the preset data to the server, and the server can check the data from the switching device according to the preset verification algorithm. The preset data and the preset key stored in the server are calculated to generate the third verification data.
  • the server may send a verification success notification to the switching device, and the switching device may determine that the first verification data from the load is authenticated based on the verification success notification, Therefore, the switching device confirms that the load is authenticated, and the switching device can allow the load to establish a communication connection with the movable platform through the switching device; if the first verification data is different from the third verification data, the server can send to the switching device In the verification failure notification, the switching device may determine that the authentication of the first verification data from the load has failed based on the verification failure notification, so that the switching device confirms that the authentication of the load has failed, and the switching device may prohibit the load from passing through the switching device and The mobile platform establishes a communication connection, and the switching device can delete the first verification data from the load from the storage space of the switching device.
  • a user can log in to an application with a user account, and send a verification start notification to the switching device through the application.
  • the switching device may respond to the start verification notification and send an application information acquisition request to the load to start the load authentication process.
  • the load can be based on the application information acquisition request, and the application information (including the identity or product name during transmission, but not the authentication key) can be sent to the switching device.
  • the switching device After the switching device receives the identity or product name sent by the load , Can send preset data to the load.
  • the load can calculate the preset key and preset data of the load according to the preset verification algorithm to generate the first calibration.
  • the switching device may send the first verification data, preset data, and application information to the server, so that the server verifies the first verification data from the load .
  • the server can obtain the preset key stored in the server corresponding to the application information according to the application information, and the server can perform a check on the preset key stored in the server and the preset data from the switching device according to the preset verification algorithm. Calculate and generate the third verification data.
  • the server may send a verification success notification, the first verification data, and application information to the switching device; the switching device may send the verification success notification returned by the server to the application Program, the user can know that the transfer device has passed the load authentication through the application program.
  • the switching device may also store the configuration information returned by the server in the storage space of the switching device. If the first verification data is not the same as the third verification data, the switching device can determine that the authentication of the first verification data from the load has failed, so that the switching device confirms that the authentication of the load has failed, and the switching device can prohibit the load from passing the transfer.
  • the connection device establishes a communication connection with the movable platform, and the switching device can also delete the first verification data from the load from the storage space of the switching device.
  • the configuration information includes first verification data and application information.
  • the product name and identity identifier in the application information can be used to record the authentication information of the combined device.
  • the first verification data and the preset data can be sent to the server asynchronously; the application information and the first verification data can also be sent to the switching device synchronously; the application information acquisition request and the sending preset data can be sent synchronously, or The application information acquisition request may not be sent.
  • the load can send the corresponding application information and the first verification data to the switching device.
  • the switching device may verify the first verification data in an offline mode. After the switching device receives the first verification data from the load, the switching device can check the preset data and the preset key obtained by the switching device (such as the authentication secret mentioned above) according to the preset verification algorithm. Key) to perform calculations to generate second verification data.
  • the preset key acquired by the switching device may be obtained by decrypting the acquired encrypted preset key by the switching device.
  • the switching device can determine that the authentication of the first verification data from the load is passed, so that the switching device confirms that the load is authenticated, and the switching device can allow the load to pass the transfer
  • the device establishes a communication connection with the movable platform; if the first verification data and the second verification data are not the same, the switching device can determine that the authentication of the first verification data from the load has failed, so that the switching device confirms that the authentication of the load has failed ,
  • the switching device can prohibit the load from establishing a communication connection with the movable platform through the switching device, and the switching device can also delete the first verification data from the load from the storage space of the switching device.
  • the load and the carrier may be bound, so as to store corresponding binding information at the switching device, so as to obtain the preset key.
  • the switching device in order to prevent the payload from transmitting the preset key to the switching device and causing information leakage, the switching device can send a random character string to the carrier and the movable platform, and the payload can use
  • the preset key and the received random character string calculate the check value, and the check value can be sent to the server through the switching device, and the server can also calculate the check value based on the preset key and the received random character string , And the calculated check value can be compared with the check value sent by the load. If they are the same, the load is considered to be authenticated, the load can be bound to the carrier, and the binding configuration information can be issued to the transfer ⁇ Connecting device.
  • the binding configuration information may include a preset key and may be encrypted.
  • the switching device can authenticate the load multiple times at intervals of a preset period. If the authentication fails, the load can be immediately prohibited from continuing to establish a communication connection with the mobile platform through the switching device, which is beneficial to avoid The user illegally controls the movable platform through the load.
  • the switching device can authenticate the legitimacy of the load. If the transfer device confirms that the load authentication is passed, the transfer device can allow the load to establish a communication connection with the mobile platform through the transfer device to further determine the open function between the load and the mobile platform, thereby improving the reliability of the load authentication. If the transfer device confirms that the load authentication has not passed, the transfer device can immediately prohibit the load from establishing a communication connection with the mobile platform through the transfer device, so as to prevent the user from illegally controlling the mobile platform through the load, which is beneficial to protect the mobile platform. safety.
  • FIG. 5 is a schematic flowchart of a method for authenticating a switching device according to an embodiment of the present invention.
  • the method for authenticating a switching device includes but is not limited to the following steps:
  • Step S501 The movable platform sends a switching device authentication request to the switching device.
  • a switching device is provided on the carrier, and the load communicates with the carrier and the movable platform through the switching device.
  • the authentication process of the transfer device by the movable platform mentioned in the embodiment of the present invention may be executed before the embodiment shown in FIG. 2 or executed when the movable platform detects that the load is connected to the movable platform.
  • the authentication process of the transfer device by the movable platform mentioned in the embodiment of the present invention may be performed at the same time as the authentication process of the load by the transfer device shown in FIG. 3, or may not be performed at the same time.
  • the authentication process of the legitimacy of the transfer device by the movable platform mentioned in the embodiment of the present invention may be performed before the authentication process of the load by the transfer device shown in FIG. 3.
  • the authentication process of the transfer device by the movable platform mentioned in the embodiment of the present invention and the authentication process of the load by the transfer device shown in FIG. 3 can be performed at the same time when the load is connected to the transfer device.
  • the movable platform detects that the load is connected to the movable platform, and the movable platform can send the adapter device authentication request to the adapter device to obtain the adapter used to authenticate the adapter device. Device authentication information.
  • the switching device and the carrier can be integrated into the same device, or they can be independent of each other, the switching device can be integrated with the carrier into the same device, and the authentication of the switching device can be equivalent to the authentication including the carrier.
  • the adapter device when the movable platform detects that the adapter device is connected to the movable platform, the adapter device can be authenticated, so that every time the adapter device is used, it can be authenticated, preventing the adapter device The risk of being replaced ensures that the switching device is always an effective switching device, which improves the safety of the application.
  • the switching device can be authenticated once, or it can be repeatedly authenticated continuously or at intervals during the use process, which is not specifically limited here.
  • Step S502 The mobile platform receives the adapter device authentication information sent by the adapter device.
  • the adapter device After the adapter device receives the adapter device certification request sent by the movable platform, the adapter device can send the adapter device certification information of the adapter device to the movable platform based on the adapter device certification request, and the movable platform can receive The switching device authentication information sent by the switching device, and the switching device is authenticated according to the switching device authentication information.
  • Step S503 The mobile platform authenticates the switching device according to the authentication information of the switching device.
  • the adapter device is authenticated as a valid adapter device or an invalid adapter device.
  • the movable platform can authenticate the adapter device according to the adapter device authentication information to determine whether the adapter device is a valid adapter device.
  • the authentication information of the switching device may include the anti-counterfeiting identification of the switching device (such as the aforementioned supplier information), and the movable platform can determine whether the switching device is a valid switching device according to the anti-counterfeiting identification of the switching device. That is, whether it is a switching device provided by the supplier.
  • the switching device authentication information may include a certificate of the switching device, and the certificate contains the anti-counterfeiting identification of the switching device.
  • the certification center of the mobile platform can certify the certificate of the switching device. If the certification center of the mobile platform determines that the certificate of the switching device is a valid certificate according to the information in the certificate of the switching device, the mobile platform can determine that the switching device is a valid switching device; if the certification center of the mobile platform determines The certificate of the transfer device fails the authentication, the certification center of the mobile platform can determine that the certificate authentication of the transfer device has failed, and the mobile platform can delete the received certificate of the transfer device from the storage space of the mobile platform, and The communication function between the switching device and the movable platform can be turned off, and the user can be prompted accordingly. For example, the movable platform can send out a photoelectric prompt, or send out a prompt on the remote control side of the movable platform.
  • the switching device authentication information may include the certificate of the switching device and the SN of the load, and the certificate contains the anti-counterfeiting identification of the switching device.
  • the authentication center of the mobile platform can authenticate the certificate of the switching device and the SN of the load.
  • the certification center of the mobile platform can refer to the above description for certification of the certificate of the switching device, which will not be repeated here.
  • the SN of the load included in the authentication information of the switching device can be sent to the server by the mobile platform when a communication connection is established between the mobile platform and the server, and stored in the server, so that the server can record the load of the load according to the SN.
  • Authentication information so that the developer can learn the relevant authentication information of the product based on the relevant authentication information recorded by the server.
  • the switching device authentication information may include the certificate of the switching device, the SN of the load, and response information.
  • the certificate contains the anti-counterfeiting identification of the switching device and the first key described above, and the response information is the use of
  • the first key is obtained by verifying the character string carried in the authentication request of the switching device.
  • the authentication center of the mobile platform can authenticate the legitimacy of the switching device through Challenge/Response (Challenge/Response) authentication.
  • the transfer device authentication request sent by the mobile platform to the transfer device can carry the challenge character string "Challenge".
  • the transfer device After the transfer device receives the transfer device authentication request sent by the mobile platform, the transfer device can use the preset calibration
  • the verification algorithm calculates the first key and the challenge string "Challenge” to generate the first response string "Response".
  • the switching device can send the first response string "Response", the certificate of the switching device, and the SN of the load to the mobile platform, and the certification center of the mobile platform can obtain the first key from the certificate of the switching device, and According to the preset verification algorithm, the first response string "Response" is calculated to generate the second response string "Response".
  • the mobile platform can determine that the transfer device is a valid transfer device. If the challenge string "Challenge” and the second response string "Response" are not the same, or the certification center of the mobile platform can determine that the certificate of the transfer device is an invalid certificate, the mobile platform can determine the transfer device It is an invalid adapter.
  • the specific execution content when the switching device is a valid or invalid switching device can refer to the foregoing description; the reason for sending the SN can also refer to the foregoing description, which will not be repeated here. It is understandable that by authenticating the character string in the switching device authentication request, the risk of replacement or fraudulent use of the switching device can be further prevented, and the application security of the switching device can be improved.
  • the transfer device is a device that connects the load and the mobile platform.
  • the communication interaction between the load and the mobile platform is transmitted via the transfer device.
  • the mobile platform passes the certificate of the transfer device, the SN of the load, etc.
  • the switching device authentication information authenticates the switching device, and the mobile platform confirms that the switching device is authenticated, that is, after the switching device is a valid switching device, the load and the mobile platform can transmit communication interaction through the switching device. data.
  • the mobile platform can further improve the reliability and safety of load authentication through the authentication of the switching device.
  • the authentication center of the mobile platform detects that the load is connected to the mobile platform, the authentication center of the mobile platform A load authentication request may be sent to the load, and the load may obtain load authentication information based on the load authentication request (load authentication information may be stored in the load).
  • the firewall of the mobile platform can send a policy file acquisition request to the certification center of the mobile platform, and the certification center of the mobile platform can return the policy file to the firewall of the mobile platform based on the policy file acquisition request.
  • the firewall of the mobile platform After the firewall of the mobile platform receives the policy file returned by the certification center of the mobile platform, the firewall of the mobile platform can send the transfer device certification notification to the certification center of the mobile platform, and the certification center of the mobile platform can respond to the transfer Device authentication notification, and sending a transfer device authentication request carrying a challenge string to the transfer device.
  • the switching device can calculate the first key and the challenge string in the certificate of the switching device according to a preset verification algorithm to generate a first response string.
  • the switching device can convert the first response string to the challenge string.
  • the certificate of the connected device and the product serial number of the load are sent to the certification center of the mobile platform.
  • the certification center of the mobile platform can obtain the first key from the received certificate of the switching device, and calculate the first response string according to the preset verification algorithm to generate the second response string. If the challenge string is the same as the second response string, and the certification center of the mobile platform determines that the certificate of the adapter device is a valid certificate, the certification center of the mobile platform confirms that the adapter device is authenticated (if the adapter device is integrated in The carrier, that is, the authentication of the carrier is passed; if the transfer transposition is not integrated into the carrier, the legality of the carrier can be further authenticated), the authentication center of the mobile platform can receive the load authentication information sent by the transfer device. The authentication center of the mobile platform can determine the functional authority of the load according to the load authentication information, and the firewall of the mobile platform can determine the open function between the load and the mobile platform according to the functional authority of the load.
  • the firewall of the mobile platform After the firewall of the mobile platform determines the open functions between the load and the mobile platform according to the functional authority of the load, the firewall of the mobile platform can also send configuration information to the switching device, and the switching device can store the configuration information to the switching device. In the storage space of the device.
  • the configuration information is used to indicate the open function between the load and the movable platform determined by the movable platform according to the functional authority of the load.
  • the communication interaction between the load and the mobile platform can be authenticated in multiple ways, ensuring that if the communication protocol between them is cracked by other users, the user information will not be leaked during the security authentication process.
  • the risk of illegal replacement of the load or the carrier including the switching device is reduced.
  • the mobile platform may first send a load authentication request to the load, and then authenticate the switching device. If the mobile platform passes the authentication of the switching device, the switching device returns the load The load authentication information of the mobile platform is sent to the mobile platform; the mobile platform can also authenticate the transfer device first, if the mobile platform passes the authentication of the transfer device, the transfer device sends the load authentication request of the mobile platform to the load.
  • FIG. 7 is a schematic structural diagram of a movable platform according to an embodiment of the present invention.
  • the movable platform 70 in the embodiment of the present invention includes a memory 701 and a processor 702.
  • the memory 701 and the processor 702 are connected by one or more communication buses.
  • the memory 701 may include volatile memory (Volatile Memory), such as random access memory (Random-Access Memory, RAM); the memory 701 may also include non-volatile memory (Non-Volatile Memory), such as flash memory (Flash Memory), Solid-State Drive (SSD), etc.; the memory 701 may also include a combination of the foregoing types of memories.
  • volatile memory such as random access memory (Random-Access Memory, RAM
  • non-Volatile Memory such as flash memory (Flash Memory), Solid-State Drive (SSD), etc.
  • flash Memory Flash Memory
  • SSD Solid-State Drive
  • the processor 702 may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (Digital Signal Processors, DSPs), and application specific integrated circuits (Application Specific Integrated Circuits). , ASIC), ready-made programmable gate array (Field-Programmable Gate Array, FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc.
  • the general-purpose processor may be a microprocessor or the processor may also be any conventional processor or the like.
  • the movable platform 70 of the embodiment of the present invention can be used to implement the method implemented by each embodiment of the present invention shown in FIG. 2 or FIG. 5 through the processor 702.
  • the embodiments of the present invention shown in FIG. 2 or FIG. 5 for implementation.
  • program instructions are stored in the memory 701, and the processor 702 calls the program instructions in the memory 701.
  • the processor 702 is configured to: When the platform is moved, the load authentication information of the load is obtained; the function authority of the load is determined according to the load authentication information; the function authority of the load is determined according to the load and the movable platform 70 Open function.
  • the load authentication information includes a firewall grade certificate; when the processor 702 determines the functional authority of the load according to the load authentication information, it is specifically configured to: according to the firewall grade certificate, Determine the functional authority of the load.
  • the firewall level certificate is encrypted information; when the processor 702 determines the functional authority of the load according to the load authentication information, it is specifically configured to: perform a check on the firewall level certificate. Decryption; when the decrypted firewall level certificate is valid, the functional authority of the load is determined according to the decrypted firewall level certificate.
  • the processor 702 before determining the functional authority of the load according to the firewall level certificate, the processor 702 is further configured to: obtain a policy file, the policy file including the firewall level and the open function
  • the processor 702 is specifically configured to: determine the current firewall level according to the firewall level certificate; according to the policy The file and the current firewall level determine the functional authority of the load.
  • the step of obtaining the policy file by the processor 702 is performed when it is detected that the load is connected to the movable platform.
  • the policy file is updatable.
  • the firewall level certificate is updatable.
  • the open function includes at least one of the following: allowing the mobile platform 70 to transmit data to the load or the load carrier, allowing the load or the load The data transmission function of the carrier to the movable platform 70.
  • the data transmission function allowing the movable platform 70 to the load or the carrier of the load includes at least one of the following: the carrier of the movable platform 70 to the load The transmission function of the control command; the transmission function of the positioning data of the movable platform 70; the transmission function of the multimedia data obtained by the movable platform 70 from the ground terminal.
  • the data transmission function that allows the load or the carrier of the load to the movable platform 70 includes at least one of the following: a transmission function of the collected data of the load; The transmission function of the load to the control command of the movable platform 70.
  • the open function includes at least one of the following: a control-related function, an image-related function, an audio-related function, and a positioning-related function.
  • the same open function includes different function levels, and the function levels are adapted to the determined function permissions.
  • the load is communicatively connected to the movable platform 70 through a switching device
  • the processor 702 is further configured to perform the following steps: according to the functional authority of the load, send a message to the switching device Sending configuration information, the configuration information being used to indicate the open function between the load and the movable platform 70.
  • the load is communicatively connected to the movable platform 70 through a switching device; the processor 702 is further configured to perform the following steps before acquiring the load authentication information of the load: The switching device authentication information of the switching device; when it is determined that the switching device is a valid switching device according to the switching device authentication information, the execution of the step of obtaining the load authentication information of the load is triggered.
  • the authentication information of the switching device includes an anti-counterfeiting identifier.
  • the processor 702 obtains the adapter device authentication information of the adapter device when it is detected that the adapter device is connected to the movable platform 70.
  • the movable platform 70 is provided by a first party, and the load is provided by a second party.
  • the movable platform 70 provided in this embodiment can execute the steps executed by the movable platform in the foregoing embodiment, and the execution mode and beneficial effects are similar, and will not be repeated here.
  • FIG. 8 is a schematic structural diagram of a switching device according to an embodiment of the present invention.
  • the switching device 80 in the embodiment of the present invention includes a memory 801 and a processor 802.
  • the memory 801 and the processor 802 are connected through one or more communication buses.
  • the memory 801 may include a volatile memory (Volatile Memory), such as a random access memory (Random-Access Memory, RAM); the memory 801 may also include a non-volatile memory (Non-Volatile Memory), such as a flash memory (Flash Memory), Solid-State Drive (SSD), etc.; the memory 801 may also include a combination of the foregoing types of memories.
  • volatile memory such as a random access memory (Random-Access Memory, RAM
  • non-Volatile Memory such as a flash memory (Flash Memory), Solid-State Drive (SSD), etc.
  • flash Memory Flash Memory
  • SSD Solid-State Drive
  • the processor 802 may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (Digital Signal Processors, DSPs), and application specific integrated circuits (Application Specific Integrated Circuits). , ASIC), ready-made programmable gate array (Field-Programmable Gate Array, FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc.
  • the general-purpose processor may be a microprocessor or the processor may also be any conventional processor or the like.
  • embodiments of the present invention may also provide a movable platform component, including the movable platform described above and the adapter device described below, wherein the adapter device is connected to the movable platform through a pan-tilt.
  • the switching device 80 of the embodiment of the present invention can be used to implement the method implemented by each embodiment of the present invention shown in FIG. 3 or FIG. 5 through the processor 802.
  • the embodiments of the present invention shown in FIG. 3 or FIG. 5 for implementation.
  • program instructions are stored in the memory 801, and the processor 802 calls the program instructions in the memory 801.
  • the processor 802 is configured to: send the load authentication information of the load To the mobile platform, so that the mobile platform determines the functional authority of the load according to the load authentication information; receives and stores the configuration information returned by the mobile platform, and the configuration information is used to indicate The open function between the load and the movable platform determined by the function authority of the load.
  • the load authentication information includes a firewall level certificate.
  • the firewall level certificate is updatable.
  • the open function includes at least one of the following: a data transmission function that allows the movable platform to the load or a carrier of the load, and a carrier that allows the load or the load Data transmission function to the mobile platform.
  • the data transmission function allowing the movable platform to the load or the carrier of the load includes at least one of the following: control of the carrier of the load by the movable platform Command transmission function; transmission function of positioning data of the movable platform; transmission function of multimedia data obtained by the movable platform from the ground terminal.
  • the data transmission function that allows the load or the carrier of the load to the movable platform includes at least one of the following: a transmission function of collected data of the load; the load The transmission function of the control command to the movable platform.
  • the open function includes at least one of the following: a control-related function, an image-related function, an audio-related function, and a positioning-related function.
  • the same open function includes different function levels, and the function levels are adapted to the determined function permissions.
  • the processor 802 sending the load authentication information of the load to the movable platform is executed when it is detected that the load is connected to the switching device 80.
  • the processor 802 before sending the load authentication information of the load to the movable platform, the processor 802 is further configured to perform the following steps: send the transfer device authentication information of the transfer device 80 Sent to the movable platform; when the movable platform determines that the switching device 80 is a valid switching device according to the authentication information of the switching device, triggering the execution of the sending of the authentication information of the load to The steps of the movable platform.
  • the authentication information of the switching device includes an anti-counterfeiting identifier.
  • the processor 802 sends the adapter device authentication information of the adapter device 80 to the movable platform when it is detected that the adapter device 80 is connected to the movable platform. implemented.
  • the processor 802 before the processor 802 sends the load authentication information of the load to the movable platform, the processor is further configured to perform the following step: receiving the first calibration sent by the load Verification data; if the first verification data is verified, the load is allowed to communicate with the movable platform through the switching device 80.
  • the processor 802 is further configured to perform the following steps: if the first verification data fails the verification, prohibit the load from communicating with the movable platform through the switching device 80 connection.
  • the processor 802 is further configured to perform the following step: sending preset data to the load, so that the load generates the first calibration based on the preset data and the preset key. Test data.
  • the processor 802 is further configured to perform the following steps: obtain an encrypted preset key, decrypt the encrypted preset key to obtain the preset key; Set the key and preset data to generate second verification data; compare the first verification data with the second verification data; if the first verification data and the second verification data are the same , It is determined that the first verification data has passed the verification; if the first verification data and the second verification data are not the same, it is determined that the first verification data has not passed the verification.
  • the adapter device 80 is installed on a carrier of the load, and the carrier of the load is used to connect with the movable platform.
  • the switching device 80 and the movable platform are provided by the first party, and the load is provided by the second party.
  • the switching device 80 provided in this embodiment can execute the steps performed by the switching device in the foregoing embodiments, and the execution method and beneficial effects thereof are similar, and details are not described herein again.
  • the embodiment of the present invention may also provide a carrier assembly, including the adapter device and the carrier described above.
  • the adapter device is mounted on the carrier, specifically, it can be set on the carrier. It is used to connect with the load, and as an intermediate adapter.
  • the adapter device here can also be a device including the carrier, that is, the pan-tilt is a part of the adapter device.
  • the switching device is provided with an interface for connecting the load to realize the communication connection between the load, the carrier, and the movable platform.
  • FIG. 9 is a schematic structural diagram of a load provided by an embodiment of the present invention.
  • the load 90 in the embodiment of the present invention includes a memory 901 and a processor 902.
  • the memory 901 and the processor 902 are connected by one or more communication buses.
  • the memory 901 may include a volatile memory (Volatile Memory), such as a random access memory (Random-Access Memory, RAM); the memory 901 may also include a non-volatile memory (Non-Volatile Memory), such as a flash memory (Flash Memory), Solid-State Drive (SSD), etc.; the memory 901 may also include a combination of the foregoing types of memories.
  • volatile memory such as a random access memory (Random-Access Memory, RAM
  • non-Volatile Memory such as a flash memory (Flash Memory), Solid-State Drive (SSD), etc.
  • flash Memory Flash Memory
  • SSD Solid-State Drive
  • the processor 902 may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (Digital Signal Processors, DSPs), and application specific integrated circuits (Application Specific Integrated Circuits). , ASIC), ready-made programmable gate array (Field-Programmable Gate Array, FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc.
  • the general-purpose processor may be a microprocessor or the processor may also be any conventional processor or the like.
  • the load 90 of the embodiment of the present invention can be used by the processor 902 to implement the method implemented by each embodiment of the present invention shown in FIG. 2 or FIG.
  • the processor 902 can be used by the processor 902 to implement the method implemented by each embodiment of the present invention shown in FIG. 2 or FIG.
  • For related parts please refer to the embodiments of the present invention shown in FIG. 2 or FIG. 3 for implementation.
  • the memory 901 stores program instructions
  • the processor 902 calls the program instructions in the memory 901.
  • the processor 902 is configured to: receive a load authentication request sent by a mobile platform Based on the load authentication request, the load authentication information of the load 90 is sent to the movable platform, so that the movable platform determines the function authority of the load 90 determined by the load authentication information The open function between the load 90 and the movable platform.
  • the load authentication information includes a firewall level certificate
  • the firewall level certificate is used to indicate the firewall level corresponding to the open function.
  • the firewall level certificate is encrypted information.
  • the firewall level certificate is updatable.
  • the open function includes at least one of the following: allowing the mobile platform to transfer data to the load 90 or the carrier of the load 90, allowing the load 90 or the load The data transmission function of the carrier of the load 90 to the movable platform.
  • the data transmission function allowing the movable platform to the load 90 or the carrier of the load 90 includes at least one of the following: The transmission function of the control command of the carrier; the transmission function of the positioning data of the movable platform; the transmission function of the multimedia data obtained by the movable platform from the ground terminal.
  • the data transmission function that allows the load 90 or the carrier of the load 90 to the movable platform includes at least one of the following: a transmission function of collected data of the load 90; The transmission function of the load 90 to the control command of the movable platform.
  • the open function includes at least one of the following: a control-related function, an image-related function, an audio-related function, and a positioning-related function.
  • the same open function includes different function levels, and the function levels are adapted to the determined function permissions.
  • the load 90 is communicatively connected with the movable platform through a switching device, and the communication interaction between the load 90 and the movable platform is transmitted via the switching device.
  • the movable platform is provided by a first party, and the load 90 is provided by a second party.
  • the load 90 provided in this embodiment can execute the steps executed by the load in the foregoing embodiment, and its execution manner and beneficial effects are similar, and will not be repeated here.
  • the embodiment of the present invention also provides a computer-readable storage medium, the computer-readable storage medium stores computer program instructions, and when the computer program instructions are executed by a processor, they are used to execute the Functions implemented by mobile platforms.
  • the embodiment of the present invention also provides a computer-readable storage medium, the computer-readable storage medium stores computer program instructions, and when the computer program instructions are executed by a processor, they are used to execute the implementation described in FIG. 3 or FIG. 5 The function realized by the switching device in the example.
  • the embodiment of the present invention also provides a computer-readable storage medium, the computer-readable storage medium stores computer program instructions, and when the computer program instructions are executed by a processor, they are used to execute the Functions implemented by the load.
  • the program can be stored in a readable storage medium, and the program can be stored in a readable storage medium. During execution, it may include the procedures of the above-mentioned method embodiments.
  • the storage medium may be a magnetic disk, an optical disc, a read-only memory (Read-Only Memory, ROM), or a random access memory (Random Access Memory, RAM), etc.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Telephonic Communication Services (AREA)

Abstract

A load authentication method and system, a mobile platform, a load, and a transfer device. The load authentication system comprises a mobile platform and a load. The load authentication method comprises: when a mobile platform detects that a load is connected thereto, the mobile platform sending a load authentication request to the load; the load receiving the load authentication request sent by the mobile platform, and sending, on the basis of the load authentication request, load authentication information thereof to the mobile platform; the mobile platform receiving the load authentication information sent by the load, and determining, according to the load authentication information, a function permission of the load; and the mobile platform determining an exposure function between the load and the mobile platform according to the function permission. In an embodiment of the present invention, function permissions of a load can be set according to load authentication information, thereby enhancing the reliability of the load, and accordingly ensuring security of a mobile platform.

Description

一种负载认证方法及系统、可移动平台、负载、转接装置Load authentication method and system, movable platform, load, and switching device 技术领域Technical field
本发明涉及通信技术领域,尤其涉及一种负载认证方法及系统、可移动平台、负载、转接装置。The present invention relates to the field of communication technology, in particular to a load authentication method and system, a movable platform, a load, and a switching device.
背景技术Background technique
目前,挂载于可移动平台的负载可以是基于SDK(Software Development Kit,软件开发工具包)开发的SDK产品,SDK一般以开源的形式,或者以库文件的形式的提供给用户。At present, the load mounted on the mobile platform can be an SDK product developed based on the SDK (Software Development Kit, software development kit). The SDK is generally provided to users in the form of open source or in the form of library files.
在可移动平台对负载的应用过程中,非法用户可以通过监听可移动平台与负载进行通信时的通信数据,窃取合法用户的用户信息,非法用户可以使用合法用户的用户信息,冒充合法用户,甚至可能对可移动平台进行非法控制,安全风险较大。During the application of the load to the mobile platform, illegal users can steal the user information of legitimate users by monitoring the communication data when the mobile platform communicates with the load. Illegal users can use the user information of legitimate users, impersonate legitimate users, or even The movable platform may be illegally controlled, and the security risk is relatively high.
发明内容Summary of the invention
本发明实施例提供了一种负载认证方法及系统、可移动平台、负载、转接装置,能够根据负载认证信息设置负载的功能权限,提高负载认证的可靠性,从而保证了可移动平台的安全性。The embodiment of the present invention provides a load authentication method and system, a movable platform, a load, and a switching device, which can set the functional authority of the load according to the load authentication information, improve the reliability of the load authentication, and ensure the safety of the movable platform Sex.
第一方面,本发明实施例提供了一种负载认证系统,所述负载认证系统包括可移动平台和负载;In the first aspect, an embodiment of the present invention provides a load authentication system, where the load authentication system includes a movable platform and a load;
所述可移动平台用于在检测到所述负载连接于所述可移动平台时,向所述负载发送负载认证请求;The movable platform is configured to send a load authentication request to the load when it is detected that the load is connected to the movable platform;
所述负载用于接收所述可移动平台发送的所述负载认证请求,并基于所述负载认证请求,将所述负载的负载认证信息发送至所述可移动平台;The load is used to receive the load authentication request sent by the movable platform, and based on the load authentication request, send load authentication information of the load to the movable platform;
所述可移动平台还用于接收所述负载发送的所述负载认证信息,并根据所述负载认证信息,确定所述负载的功能权限;The mobile platform is further configured to receive the load authentication information sent by the load, and determine the functional authority of the load according to the load authentication information;
所述可移动平台还用于根据所述负载的功能权限,确定所述负载与所述可移动平台之间的开放功能。The movable platform is also used to determine the open function between the load and the movable platform according to the functional authority of the load.
第二方面,本发明实施例提供了一种负载认证方法,应用于可移动平台,所述方法包括:In the second aspect, an embodiment of the present invention provides a load authentication method, which is applied to a mobile platform, and the method includes:
在检测到负载连接于所述可移动平台时,获取所述负载的负载认证信息;When it is detected that the load is connected to the movable platform, acquiring load authentication information of the load;
根据所述负载认证信息,确定所述负载的功能权限;Determine the functional authority of the load according to the load authentication information;
根据所述负载的功能权限,确定所述负载与所述可移动平台之间的开放功能。According to the functional authority of the load, an open function between the load and the movable platform is determined.
第三方面,本发明实施例提供了一种负载认证方法,应用于转接装置,所述方法包括:In a third aspect, an embodiment of the present invention provides a load authentication method, which is applied to a switching device, and the method includes:
将所述负载的负载认证信息发送至所述可移动平台,以使所述可移动平台根据所述负载认证信息,确定所述负载的功能权限;Sending load authentication information of the load to the movable platform, so that the movable platform determines the functional authority of the load according to the load authentication information;
接收并存储所述可移动平台返回的配置信息,所述配置信息用于指示基于所述负载的功能权限确定的所述负载与所述可移动平台之间的开放功能。Receiving and storing configuration information returned by the movable platform, where the configuration information is used to indicate an open function between the load and the movable platform determined based on the functional authority of the load.
第四方面,本发明实施例提供了一种负载认证方法,应用于负载,所述方法包括:In a fourth aspect, an embodiment of the present invention provides a load authentication method, which is applied to a load, and the method includes:
接收可移动平台发送的负载认证请求;Receive load authentication request sent by the mobile platform;
基于所述负载认证请求,将所述负载的负载认证信息发送至所述可移动平台,以使所述可移动平台根据所述负载认证信息确定的所述负载的功能权限,确定所述负载与所述可移动平台之间的开放功能。Based on the load authentication request, the load authentication information of the load is sent to the mobile platform, so that the mobile platform determines the load and the function authority of the load determined by the load authentication information Open functions between the movable platforms.
第五方面,本发明实施例提供了一种可移动平台,所述可移动平台包括存储器和处理器,所述存储器和所述处理器相互连接,其中:In a fifth aspect, an embodiment of the present invention provides a movable platform, the movable platform includes a memory and a processor, and the memory and the processor are connected to each other, wherein:
所述存储器,用于存储计算机程序,所述计算机程序包括程序指令;The memory is used to store a computer program, and the computer program includes program instructions;
所述处理器,调用所述程序指令,用于:The processor calls the program instructions for:
在检测到负载连接于所述可移动平台时,获取所述负载的负载认证信息;When it is detected that the load is connected to the movable platform, acquiring load authentication information of the load;
根据所述负载认证信息,确定所述负载的功能权限;Determine the functional authority of the load according to the load authentication information;
根据所述负载的功能权限,确定所述负载与所述可移动平台之间的开放功能。According to the functional authority of the load, an open function between the load and the movable platform is determined.
第六方面,本发明实施例提供了一种转接装置,所述转接装置包括存储器和处理器,所述存储器和所述处理器相互连接,其中:In a sixth aspect, an embodiment of the present invention provides a switching device, the switching device includes a memory and a processor, the memory and the processor are connected to each other, wherein:
所述存储器,用于存储计算机程序,所述计算机程序包括程序指令;The memory is used to store a computer program, and the computer program includes program instructions;
所述处理器,调用所述程序指令,用于:The processor calls the program instructions for:
将所述负载的负载认证信息发送至所述可移动平台,以使所述可移动平台根据所述负载认证信息,确定所述负载的功能权限;Sending load authentication information of the load to the movable platform, so that the movable platform determines the functional authority of the load according to the load authentication information;
接收并存储所述可移动平台返回的配置信息,所述配置信息用于指示基于所述负载的功能权限确定的所述负载与所述可移动平台之间的开放功能。Receiving and storing configuration information returned by the movable platform, where the configuration information is used to indicate an open function between the load and the movable platform determined based on the functional authority of the load.
第七方面,本发明实施例提供了一种负载,所述负载包括存储器和处理器,所述存储器和所述处理器相互连接,其中:In a seventh aspect, an embodiment of the present invention provides a load, the load includes a memory and a processor, and the memory and the processor are connected to each other, wherein:
所述存储器,用于存储计算机程序,所述计算机程序包括程序指令;The memory is used to store a computer program, and the computer program includes program instructions;
所述处理器,调用所述程序指令,用于:The processor calls the program instructions for:
接收可移动平台发送的负载认证请求;Receive load authentication request sent by the mobile platform;
基于所述负载认证请求,将所述负载的负载认证信息发送至所述可移动平台,以使所述可移动平台根据所述负载认证信息确定所述负载的功能权限,确定所述负载与所述可移动平台之间的开放功能。Based on the load authentication request, the load authentication information of the load is sent to the movable platform, so that the movable platform determines the functional authority of the load according to the load authentication information, and determines the relationship between the load and the load. Describes the open functions between the movable platforms.
第八方面,本发明实施例提供了一种载体组件,包括载体和本发明实施例第六方面所述的转接装置,所述转接装置设于所述载体上。In an eighth aspect, an embodiment of the present invention provides a carrier assembly, including a carrier and the adapter device according to the sixth aspect of the embodiment of the invention, the adapter device being provided on the carrier.
第九方面,本发明实施例提供了一种可移动平台组件,包括本发明实施例第五方面所述的可移动平台和本发明实施例第八方面所述的载体组件,所述载体组件与所述可移动平台连接。In a ninth aspect, an embodiment of the present invention provides a movable platform assembly, including the movable platform described in the fifth aspect of the embodiments of the present invention and the carrier assembly described in the eighth aspect of the embodiments of the present invention, the carrier assembly and The movable platform is connected.
第十方面,本发明实施例提供了一种计算机可读存储介质,所述计算机可读存储介质上存储有计算机程序,所述计算机程序在被执行时,实现如本发明实施例第二方面所述的负载认证方法。In a tenth aspect, an embodiment of the present invention provides a computer-readable storage medium having a computer program stored on the computer-readable storage medium, and when the computer program is executed, it achieves the same as described in the second aspect of the embodiment of the present invention. The load authentication method described.
第十一方面,本发明实施例提供了一种计算机可读存储介质,所述计算机可读存储介质上存储有计算机程序,所述计算机程序在被执行时,实现如本发明实施例第三方面所述的负载认证方法。In an eleventh aspect, an embodiment of the present invention provides a computer-readable storage medium having a computer program stored on the computer-readable storage medium, and the computer program, when executed, realizes the same as the third aspect of the embodiment of the present invention The load authentication method.
第十二方面,本发明实施例提供了一种计算机可读存储介质,所述计算机可读存储介质上存储有计算机程序,所述计算机程序在被执行时,实现如本发明实施例第四方面所述的负载认证方法。In a twelfth aspect, an embodiment of the present invention provides a computer-readable storage medium, and a computer program is stored on the computer-readable storage medium. When the computer program is executed, it implements the fourth aspect of the embodiment of the present invention. The load authentication method.
在本发明实施例中,可移动平台在检测到负载连接于可移动平台时,向负载发送负载认证请求,负载接收到可移动平台发送的负载认证请求后,将负载 的负载认证信息发送至可移动平台,可移动平台接收到负载发送的负载认证信息后,根据负载认证信息确定负载的功能权限,可移动平台还根据负载的功能权限进一步确定负载与可移动平台之间的开放功能。通过本发明实施例,能够根据负载认证信息设置负载的功能权限,提高负载认证的可靠性,从而保证了可移动平台的安全性。In the embodiment of the present invention, when the mobile platform detects that the load is connected to the mobile platform, it sends a load authentication request to the load. After the load receives the load authentication request sent by the mobile platform, it sends the load authentication information of the load to the mobile platform. The mobile platform, after receiving the load authentication information sent by the load, the mobile platform determines the functional authority of the load according to the load authentication information, and the mobile platform further determines the open functions between the load and the mobile platform according to the functional authority of the load. Through the embodiment of the present invention, the functional authority of the load can be set according to the load authentication information, and the reliability of the load authentication is improved, thereby ensuring the safety of the movable platform.
附图说明Description of the drawings
为了更清楚地说明本发明实施例中的技术方案,下面将对实施例中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本发明的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动性的前提下,还可以根据这些附图获得其他的附图。In order to explain the technical solutions in the embodiments of the present invention more clearly, the following will briefly introduce the drawings that need to be used in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative labor, other drawings can be obtained from these drawings.
图1是本发明实施例提供的一种负载认证系统的链路示意图;FIG. 1 is a schematic diagram of a link of a load authentication system provided by an embodiment of the present invention;
图2是本发明实施例提供的一种负载认证方法的流程示意图;2 is a schematic flowchart of a load authentication method provided by an embodiment of the present invention;
图3是本发明实施例提供的一种对负载进行认证的方法流程示意图;FIG. 3 is a schematic flowchart of a method for authenticating a load according to an embodiment of the present invention;
图4是本发明实施例提供的一种负载认证成功的流程示意图;4 is a schematic diagram of a successful flow of load authentication provided by an embodiment of the present invention;
图5是本发明实施例提供的一种对转接装置进行认证的方法流程示意图;FIG. 5 is a schematic flowchart of a method for authenticating a switching device according to an embodiment of the present invention;
图6是本发明实施例提供的一种示例性的负载认证方法的流程示意图;6 is a schematic flowchart of an exemplary load authentication method provided by an embodiment of the present invention;
图7是本发明实施例提供的一种可移动平台的结构示意图;Figure 7 is a schematic structural diagram of a movable platform provided by an embodiment of the present invention;
图8是本发明实施例提供的一种转接装置的结构示意图;FIG. 8 is a schematic structural diagram of a switching device provided by an embodiment of the present invention;
图9是本发明实施例提供的一种负载的结构示意图。Fig. 9 is a schematic structural diagram of a load provided by an embodiment of the present invention.
具体实施方式Detailed ways
下面将结合本发明实施例中的附图对本发明实施例中进行描述。The embodiments of the present invention will be described below in conjunction with the drawings in the embodiments of the present invention.
可移动平台可以通过挂载拍摄装置(例如摄像机、摄影机、照相机等)或扬声装置(例如喊话器等)等负载,扩展可移动平台的功能。为了防止负载的非法冒用,挂载于可移动平台的负载在使用前可以经过认证。其中,可移动平台可以通过验证负载的相关信息以实现对负载的认证,但在这一过程中,用户信息容易泄露,非法用户可以使用该非法获得的信息执行负载的全部功能,进而可以非法窃取数据或控制可移动平台,安全风险较大。The movable platform can expand the functions of the movable platform by mounting a load such as a shooting device (such as a video camera, a camera, a camera, etc.) or a loudspeaking device (such as a megaphone, etc.). In order to prevent illegal use of the load, the load mounted on the mobile platform can be authenticated before use. Among them, the mobile platform can authenticate the load by verifying the relevant information of the load, but in this process, user information is easy to leak, and illegal users can use the illegally obtained information to perform all the functions of the load, and then can illegally steal The data or control of the mobile platform poses a greater security risk.
本发明实施例提供了一种负载认证方法及负载认证系统,在负载和可移动平台之间构建了一道功能过滤型防火墙,可移动平台可以根据负载的防火墙等级证书,确定负载的功能权限,进而可以确定负载与可移动平台之间开放的功能,提高了可移动平台对负载进行认证的可靠性,从而保证了可移动平台的安全性。The embodiment of the present invention provides a load authentication method and a load authentication system. A functional filtering firewall is constructed between the load and the mobile platform. The mobile platform can determine the functional authority of the load according to the firewall level certificate of the load, and then The open functions between the load and the movable platform can be determined, and the reliability of the authentication of the load by the movable platform is improved, thereby ensuring the safety of the movable platform.
本发明实施例提及的可移动平台可以由供应商(即第一方)提供,负载可以由开发商(即第二方)提供。其中,负载可以挂载在载体上,例如云台,负载可以通过设置于载体上的转接装置实现与载体、可移动平台之间的通信连接,并形成相应的通信链路,载体以及转接装置也可以由供应商提供。其中,可移动平台可以包括无人飞行器、无人车、无人船、手持装置等等。The movable platform mentioned in the embodiment of the present invention may be provided by a supplier (ie, the first party), and the load may be provided by a developer (ie, the second party). Among them, the load can be mounted on a carrier, such as a pan/tilt. The load can communicate with the carrier and the movable platform through a transfer device set on the carrier, and form a corresponding communication link, carrier and transfer The device can also be provided by the supplier. Among them, the movable platform may include unmanned aerial vehicles, unmanned vehicles, unmanned ships, handheld devices, and so on.
请参见图1,是本发明实施例提供的一种负载认证系统的链路示意图,该负载认证系统包括:负载101、转接装置102、可移动平台103、安装有应用程序104的终端设备和服务器105。负载101通过转接装置102挂载于载体(图未示)上,转接装置102安装在载体(图未示)上,载体用于与可移动平台103连接。其中,可移动平台103可以通过有线的方式与安装有应用程序104的终端设备连接,也可以通过无线的方式与安装有应用程序104的终端设备连接,该终端设备104可以与服务器105连接。其中,可移动平台103在通过无线的方式与安装有应用程序104的终端设备连接时,可以是直接与安装有应用程序104的终端设备连接,也可以是通过可移动平台103的遥控设备与安装有应用程序104的终端设备连接。Please refer to FIG. 1, which is a schematic diagram of a link of a load authentication system provided by an embodiment of the present invention. The load authentication system includes: a load 101, a switching device 102, a movable platform 103, a terminal device installed with an application 104, and Server 105. The load 101 is mounted on a carrier (not shown in the figure) through an adapter device 102, and the adapter device 102 is installed on the carrier (not shown in the figure), and the carrier is used to connect with the movable platform 103. The mobile platform 103 can be connected to the terminal device installed with the application program 104 in a wired manner, or can be connected to the terminal device installed with the application program 104 in a wireless manner, and the terminal device 104 can be connected to the server 105. Among them, when the mobile platform 103 is wirelessly connected to the terminal device installed with the application 104, it can be directly connected to the terminal device installed with the application 104, or it can be connected to the terminal device installed with the application 104 through the remote control device of the movable platform 103 and the installation. The terminal device with the application 104 is connected.
其中,对于开发商侧和用户侧,均可以对负载进行认证,在对负载进行认证的对象不同时,可移动平台103与服务器105连接的方式可以不同,安装有应用程序104的终端设备也可以不同,且应用程序104可开放的功能也可以不同,具体请参见后续说明。Among them, for both the developer side and the user side, the load can be authenticated. When the objects to be authenticated for the load are different, the mobile platform 103 and the server 105 can be connected in different ways, and the terminal device installed with the application 104 can also be used. Different, and the functions that can be opened by the application 104 may also be different. For details, please refer to the subsequent description.
具体的,开发商在基于供应商提供的载体对负载进行开发时,可以在供应商提供的网站上注册企业用户信息。在注册成功后,开发商侧可以获取相应的应用信息,该应用信息可以包括产品名称(产品包括由负载、载体组成的组合设备,其中,载体上设有转接装置)、身份标识和认证密钥。其中,针对同一开发商的不同产品,其对应的产品名称可以不同,其对应的认证密钥和身份标 识可以相同;针对不同开发商的不同产品,其对应的产品名称、认证密钥和身份标识均可以不同。开发商在对负载的开发过程中,可以将对应的应用信息写入负载中。进一步的,在用户购买开发商提供的产品后,可以下载相应的防火墙等级证书,以限定负载与可移动平台之间的开放功能。Specifically, when the developer develops the load based on the carrier provided by the supplier, he can register enterprise user information on the website provided by the supplier. After the registration is successful, the developer side can obtain the corresponding application information, which can include the product name (the product includes a combination device consisting of a load and a carrier, and the carrier is equipped with a switching device), an identity mark and an authentication secret key. Among them, for different products of the same developer, the corresponding product name can be different, and the corresponding authentication key and identity can be the same; for different products of different developers, the corresponding product name, authentication key and identity can be Both can be different. The developer can write the corresponding application information into the load during the development of the load. Further, after the user purchases the product provided by the developer, the corresponding firewall level certificate can be downloaded to limit the open function between the load and the mobile platform.
转接装置102的加密芯片中存储有负载101的SN(Serial Number,产品序列号),SN可以唯一标识负载101;加密芯片中还可以存储有供应商信息,例如属于供应商产品的防伪标识,用于对诸如转接装置进行认证;加密芯片中还可以存储有第一密钥,该第一密钥用于辅助对转接装置进行认证。The encryption chip of the switching device 102 stores the SN (Serial Number) of the load 101, and the SN can uniquely identify the load 101; the encryption chip can also store supplier information, such as the anti-counterfeiting identification of the supplier’s product, It is used to authenticate the switching device, for example; the encryption chip may also store a first key, and the first key is used to assist the authentication of the switching device.
可移动平台103包括认证中心和服务器,认证中心是基于服务器105建立的应用程序,运行于可移动平台中,认证中心中存储有从服务器105获取到的第二密钥,该第二密钥可以唯一认证负载101。可移动平台103的防火墙是运行于可移动平台中的应用程序,防火墙可以确定负载101与可移动平台103之间开放的功能,从而允许执行相关开放功能的命令在负载101与可移动平台103之间通过。The mobile platform 103 includes a certification center and a server. The certification center is an application established based on the server 105 and runs on the mobile platform. The certification center stores a second key obtained from the server 105. The second key can be The only authentication load is 101. The firewall of the mobile platform 103 is an application program running on the mobile platform. The firewall can determine the open functions between the load 101 and the mobile platform 103, thereby allowing commands to execute related open functions between the load 101 and the mobile platform 103. Passed between.
应用程序104可以运行在终端设备中,用户可以通过应用程序104与可移动平台103、转接装置102实现交互,开启负载认证流程。其中,终端设备可以为移动终端、个人计算机(Personal Computer,PC)端或者便携式电脑(Tablet Personal Computer,Tablet PC)端等等,也可以为可移动平台的遥控设备。The application 104 can run in a terminal device, and the user can interact with the movable platform 103 and the switching device 102 through the application 104 to start the load authentication process. Among them, the terminal device may be a mobile terminal, a personal computer (PC) end or a portable computer (Tablet Personal Computer, Tablet PC) end, etc., and may also be a remote control device of a movable platform.
服务器105中存储有开发商在供应商提供的开发网站上注册的应用信息,该应用信息可以包括产品名称(产品包括由负载、载体组成的组合设备,其中,载体上设有转接装置)、身份标识(如为供应商的注册ID)和认证密钥。服务器105中还可以存储有转接装置102、负载101等的相关信息,例如SN。The server 105 stores the application information registered by the developer on the development website provided by the supplier. The application information may include the product name (the product includes a combination device consisting of a load and a carrier, and the carrier is provided with a switching device), Identification (such as the supplier's registration ID) and authentication key. The server 105 may also store related information about the switching device 102, the load 101, etc., such as SN.
可以理解的是,本发明实施例描述的负载认证系统是为了更加清楚的说明本发明实施例的技术方案,并不构成对于本发明实施例提供的技术方案的限定,本领域普通技术人员可知,随着系统架构的演变和新业务场景的出现,本发明实施例提供的技术方案对于类似的技术问题,同样适用。It is understandable that the load authentication system described in the embodiment of the present invention is to explain the technical solution of the embodiment of the present invention more clearly, and does not constitute a limitation to the technical solution provided by the embodiment of the present invention. Those of ordinary skill in the art will know that, With the evolution of the system architecture and the emergence of new business scenarios, the technical solutions provided by the embodiments of the present invention are equally applicable to similar technical problems.
基于图1所示的一种负载认证系统的链路示意图,请参见图2,是本发明实施例提供的一种负载认证方法的流程示意图,该负载认证方法包括但不限于如下步骤:Based on the link schematic diagram of a load authentication system shown in FIG. 1, please refer to FIG. 2, which is a schematic flowchart of a load authentication method provided by an embodiment of the present invention. The load authentication method includes but is not limited to the following steps:
步骤S201、可移动平台向负载发送负载认证请求。Step S201: The mobile platform sends a load authentication request to the load.
本实施例中,负载的认证包括负载的功能权限的认证,即明确负载与可移动平台之间的开放功能。In this embodiment, the authentication of the load includes the authentication of the functional authority of the load, that is, the open function between the load and the movable platform is specified.
可选的,在实际的认证过程中,可以分为在线模式和离线模式。即在可移动平台与服务器通信连接的情况下,可以利用在线模式或离线模式中的任一种,对负载进行认证;而在可移动平台与服务器未通信连接的情况下,利用离线模式对负载进行认证。具体的,为了能够在离线模式下,对负载进行认证,可移动平台处可以存储有用于认证负载的功能权限的相应信息,如密钥,该密钥(如前述说明的第二密钥)可以用于对诸如获取的防火墙证书进行解密,具体请参见后文。Optionally, in the actual authentication process, it can be divided into online mode and offline mode. That is, when the mobile platform is in communication with the server, either online mode or offline mode can be used to authenticate the load; and when the mobile platform is not in communication with the server, the offline mode can be used to authenticate the load. Perform authentication. Specifically, in order to be able to authenticate the load in offline mode, the mobile platform may store corresponding information for authenticating the functional authority of the load, such as a key, and the key (such as the second key described above) can be It is used to decrypt the obtained firewall certificate. For details, please refer to the following text.
具体的,在可移动平台检测到负载连接于可移动平台,可移动平台可以向负载发送负载认证请求,以获取用于对负载进行认证的负载认证信息。其中,在可移动平台检测到负载连接于可移动平台时,即可对负载进行认证,以在负载每次开始被使用时,都能够被进行认证,防止了负载被替换的风险,从而保证负载一直为有效负载,提升了应用的安全性。其中,在负载的一次使用过程中,可以对负载进行一次初始认证,也可以在使用过程中,持续地或间隔地进行多次认证,此处不做具体限定。Specifically, when the mobile platform detects that the load is connected to the mobile platform, the mobile platform may send a load authentication request to the load to obtain load authentication information for authenticating the load. Among them, when the mobile platform detects that the load is connected to the mobile platform, the load can be authenticated so that it can be authenticated every time the load is used, preventing the risk of load being replaced, thereby ensuring the load It has always been a payload, which improves the security of the application. Among them, during one use of the load, the load can be initially authenticated once, or it can be authenticated multiple times continuously or at intervals during the use process, which is not specifically limited here.
步骤S202、负载可以基于该负载认证请求,将负载的负载认证信息发送至可移动平台。Step S202: The load may send load authentication information of the load to the mobile platform based on the load authentication request.
负载接收到可移动平台发送的负载认证请求后,负载可以基于该负载认证请求,将负载的负载认证信息发送至可移动平台,可移动平台可以接收负载发送的负载认证信息。After the load receives the load authentication request sent by the mobile platform, the load can send the load authentication information of the load to the mobile platform based on the load authentication request, and the mobile platform can receive the load authentication information sent by the load.
在一种实现方式中,为了进一步提高认证的可靠性,在负载经由转接装置连接至载体再至可移动平台时,在可移动平台接收负载发送的负载认证信息之前,可以对负载的合法性以及转接装置的合法性进行认证,例如:若转接装置对负载认证通过,则转接装置接收负载发送的负载认证信息;若可移动平台对转接装置认证通过,则可移动平台接收转接装置发送的负载认证信息。当然,在实际应用中,步骤之间的时序不限于此,例如,可以是:若可移动平台对转接装置认证通过,则转接装置接收可移动平台发送的负载认证请求;若转接装 置对负载认证通过,则负载接收转接装置发送的负载认证请求;可移动平台对转接装置进行合法性认证的认证过程与转接装置对负载进行认证的认证过程还可以同时进行。In one implementation, in order to further improve the reliability of authentication, when the load is connected to the carrier via the switching device and then to the mobile platform, before the mobile platform receives the load authentication information sent by the load, the legality of the load can be checked. And the legitimacy of the transfer device is verified, for example: if the transfer device passes the load authentication, the transfer device receives the load authentication information sent by the load; if the mobile platform passes the authentication of the transfer device, the mobile platform receives the transfer Load authentication information sent by the receiving device. Of course, in practical applications, the timing between steps is not limited to this. For example, it can be: if the mobile platform authenticates the transfer device, the transfer device receives the load authentication request sent by the mobile platform; if the transfer device If the load authentication is passed, the load receives the load authentication request sent by the switching device; the authentication process of the mobile platform for authenticating the switching device and the authentication process of the switching device for authenticating the load can also be performed at the same time.
其中,转接装置对负载进行合法性认证的认证过程请参见图3的具体描述,图3是本发明实施例提供的一种对负载进行认证的方法流程示意图;可移动平台对转接装置进行合法性认证的认证过程请参见图5,图5是本发明实施例提供的一种对转接装置进行认证的方法流程示意图,在此不再赘述。Please refer to the detailed description of FIG. 3 for the authentication process of the transfer device for authenticating the load. FIG. 3 is a schematic flowchart of a method for authenticating the load provided by an embodiment of the present invention; the movable platform performs the authentication on the transfer device. Please refer to FIG. 5 for the authentication process of legality authentication. FIG. 5 is a schematic flowchart of a method for authenticating a switching device according to an embodiment of the present invention, and details are not described herein again.
步骤S203、可移动平台根据负载认证信息,确定负载的功能权限。Step S203: The mobile platform determines the functional authority of the load according to the load authentication information.
负载认证信息可以包括负载的防火墙等级证书,可移动平台可以根据负载的防火墙等级证书,确定负载的功能权限。可以理解,负载认证信息的形式不限于防火墙等级证书,本实施例中,通过在可移动平台处设置防火墙,因而可以经由防火墙来限定负载与可移动平台之间的开放功能,在实际应用中,也可以以其它形式体现,能够指示负载与可移动平台之间的开放功能即可,例如,经加密的标识信息,该加密的标识信息用于指示负载与可移动平台之间的开放功能。The load authentication information may include the firewall grade certificate of the load, and the mobile platform may determine the functional authority of the load according to the firewall grade certificate of the load. It can be understood that the form of load authentication information is not limited to the firewall level certificate. In this embodiment, the firewall is set on the mobile platform, so that the open function between the load and the mobile platform can be limited through the firewall. In practical applications, It can also be embodied in other forms, which can indicate the open function between the load and the movable platform, for example, encrypted identification information, which is used to indicate the open function between the load and the movable platform.
在一种实现方式中,为了防止负载的防火墙等级被篡改,负载的防火墙等级证书可以为加密的信息,可移动平台可以使用如前述说明的第二密钥对加密的防火墙等级证书进行解密,获得解密后的防火墙等级证书,解密后的防火墙等级证书可以包括负载的防火墙等级。若可移动平台的认证中心根据解密后的防火墙等级证书的证书编号、有效期等信息确定解密后的防火墙等级证书为有效的防火墙等级证书,可移动平台可以根据负载的防火墙等级,确定与负载的防火墙等级对应的功能权限;若可移动平台的认证中心根据解密后的防火墙等级证书的证书编号、有效期等信息确定解密后的防火墙等级证书为无效的防火墙等级证书,可移动平台可以将接收到的负载的防火墙等级证书从可移动平台的存储空间中删除,并可以关闭负载与可移动平台之间的开放功能,还可以对用户进行相应提示,例如,可移动平台可以发出光电提示,或在可移动平台的遥控器侧发出提示。In one implementation, in order to prevent the firewall level of the payload from being tampered with, the firewall level certificate of the payload can be encrypted information, and the mobile platform can use the second key as described above to decrypt the encrypted firewall level certificate to obtain The decrypted firewall level certificate, and the decrypted firewall level certificate may include the firewall level of the load. If the certification center of the mobile platform determines that the decrypted firewall level certificate is a valid firewall level certificate based on the certificate number and validity period of the decrypted firewall level certificate, the mobile platform can determine the firewall level of the load according to the firewall level of the load. The functional authority corresponding to the level; if the certification center of the mobile platform determines that the decrypted firewall level certificate is an invalid firewall level certificate according to the certificate number and validity period of the decrypted firewall level certificate, the mobile platform can change the received load The firewall level certificate of the mobile platform is deleted from the storage space of the mobile platform, and the open function between the load and the mobile platform can be closed, and the user can be prompted accordingly. For example, the mobile platform can send out a photoelectric prompt, or The remote control side of the platform gives a prompt.
防火墙等级可以包括普通服务等级和增值服务等级,其中普通服务等级,意味着防火墙可以允许一些较为基础的命令通过,如允许控制云台和图像传输 的命令,增值服务等级,意味着防火墙可以允许一些高级的命令通过,如允许控制可移动平台。若负载的防火墙等级为普通服务等级,可移动平台可以确定与普通服务等级对应的负载的功能权限为普通服务功能权限;若负载的防火墙等级为增值服务等级,可移动平台可以确定与增值服务等级对应的负载的功能权限为增值服务功能权限。其中,增值服务功能权限可以包括普通服务功能权限。The firewall level can include ordinary service level and value-added service level. The ordinary service level means that the firewall can allow some basic commands to pass, such as commands that allow the control of PTZ and image transmission. The value-added service level means that the firewall can allow some Advanced commands are passed, such as allowing control of movable platforms. If the firewall level of the load is a normal service level, the mobile platform can determine that the function authority of the load corresponding to the normal service level is the normal service function authority; if the firewall level of the load is a value-added service level, the mobile platform can determine the value-added service level The function authority of the corresponding load is the value-added service function authority. Among them, the value-added service function authority may include the normal service function authority.
在一种实现方式中,在可移动平台根据负载的防火墙等级证书确定负载的功能权限之前,可移动平台的防火墙可以向可移动平台的认证中心发送策略文件获取请求,可移动平台的防火墙接收到策略文件获取请求后,可以基于该策略文件获取请求,将策略文件返回至可移动平台的认证中心。策略文件可以包括防火墙等级与功能权限之间的预设对应关系。防火墙等级可以包括普通服务等级和增值服务等级;功能权限可以包括普通服务功能权限和增值服务功能权限。防火墙等级与功能权限之间的预设对应关系可以包括普通服务等级与普通服务功能权限之间的对应关系、增值服务等级与增值服务功能权限之间的对应关系。可移动平台可以根据负载的防火墙等级证书,确定负载当前的防火墙等级,从而可移动平台可以根据防火墙等级与功能权限之间的预设对应关系以及负载当前的防火墙等级,确定负载的功能权限。In one implementation, before the mobile platform determines the functional authority of the load according to the firewall level certificate of the load, the firewall of the mobile platform can send a policy file acquisition request to the certification center of the mobile platform, and the firewall of the mobile platform receives After the policy file acquisition request, the policy file can be returned to the certification center of the mobile platform based on the policy file acquisition request. The policy file may include a preset correspondence relationship between the firewall level and the function authority. The firewall level may include a normal service level and a value-added service level; the function authority may include a normal service function authority and a value-added service function authority. The preset correspondence between the firewall level and the function authority may include the correspondence between the ordinary service level and the ordinary service function authority, and the correspondence between the value-added service level and the value-added service function authority. The mobile platform can determine the current firewall level of the load according to the firewall level certificate of the load, so that the mobile platform can determine the functional authority of the load according to the preset correspondence between the firewall level and the functional authority and the current firewall level of the load.
若负载当前的防火墙等级为普通服务等级,可移动平台可以确定负载的功能权限为普通服务功能权限;若负载当前的防火墙等级为增值服务等级,可移动平台可以确定负载的功能权限为增值服务功能权限。可以理解,防火墙等级的分类也可以不限于上述说明的普通服务等级和增值服务等级,还可以包括多个等级,各个等级之间对应的功能权限可以不同,也可以部分不同,功能权限数量方面也可以相应进行不同的设定。If the current firewall level of the load is a normal service level, the mobile platform can determine that the functional authority of the load is a normal service function authority; if the current firewall level of the load is a value-added service level, the mobile platform can determine that the functional authority of the load is a value-added service function Permissions. It can be understood that the classification of firewall levels may not be limited to the ordinary service levels and value-added service levels described above, but may also include multiple levels. The corresponding function permissions between each level may be different or partly different. The number of function permissions is also different. Different settings can be made accordingly.
在一种实现方式中,负载的防火墙等级证书是可以更新的,负载的防火墙等级证书更新后,可移动平台可以获取负载更新后的防火墙等级证书,从而可移动平台可以根据负载更新后的防火墙等级证书,确定与更新后的防火墙等级证书对应的功能权限。In one implementation, the firewall level certificate of the load can be updated. After the firewall level certificate of the load is updated, the mobile platform can obtain the updated firewall level certificate of the load, so that the mobile platform can update the firewall level according to the load. The certificate determines the functional authority corresponding to the updated firewall level certificate.
在一种实现方式中,可移动平台的认证中心中的策略文件是可以更新的,更新后的策略文件可以包括防火墙等级与功能权限之间更新后的预设对应关 系,更新后的策略文件还可以包括功能权限与开放功能的功能等级之间更新后的预设对应关系,可移动平台可以根据更新后的策略文件和负载的防火墙等级证书确定负载更新后的功能权限,从而可移动平台可以根据负载更新后的功能权限确定负载和可移动平台之间更新后的开放功能。In one implementation, the policy file in the certification center of the mobile platform can be updated. The updated policy file may include the updated preset correspondence between the firewall level and the function authority, and the updated policy file can also be updated. It can include the updated preset corresponding relationship between the function authority and the function level of the open function. The mobile platform can determine the updated function authority of the load according to the updated policy file and the firewall level certificate of the load, so that the mobile platform can be based on The updated functional authority of the load determines the updated open functions between the load and the mobile platform.
步骤S204、可移动平台根据负载的功能权限,确定负载与可移动平台之间的开放功能。Step S204: The movable platform determines the open function between the load and the movable platform according to the functional authority of the load.
其中,开放功能可以包括允许可移动平台至负载或负载的载体的数据传输功能、允许负载或负载的载体至可移动平台的数据传输功能中的至少一种。允许可移动平台至负载或负载的载体的数据传输功能可以包括但不限于可移动平台对负载的载体的控制命令的传输功能、可移动平台的定位数据的传输功能、可移动平台从地面端获取的多媒体数据的传输功能中的至少一种。允许负载或负载的载体至可移动平台的数据传输功能可以包括但不限于负载的采集数据的传输功能、负载对所述可移动平台的控制命令的传输功能中的至少一种。Wherein, the open function may include at least one of a data transmission function that allows a movable platform to the load or a carrier of the load, and a data transmission function that allows the load or a carrier of the load to the movable platform. The data transmission function that allows the movable platform to the load or the carrier of the load may include, but is not limited to, the transmission function of the control command of the movable platform to the carrier of the load, the transmission function of the positioning data of the movable platform, and the acquisition of the movable platform from the ground terminal. At least one of the multimedia data transmission functions. The data transmission function that allows the load or the load carrier to the movable platform may include, but is not limited to, at least one of the transmission function of the collected data of the load and the transmission function of the control command of the load to the movable platform.
在一种实现方式中,可移动平台对负载的载体的控制命令的传输功能,和负载对所述可移动平台的控制命令的传输功能为与控制相关的功能。可移动平台的定位数据的传输功能为与定位相关的功能。若可移动平台从地面端获取的多媒体数据和负载的采集数据的数据为图像数据,则可移动平台从地面端获取的多媒体数据的传输功能,和负载的采集数据的传输功能为与图像相关的功能;若可移动平台从地面端获取的多媒体数据和负载的采集数据的数据为音频数据,则可移动平台从地面端获取的多媒体数据的传输功能,和负载的采集数据的传输功能为与音频相关的功能。也即,开放功能可以包括但不限于与控制相关的功能、与图像相关的功能、与音频相关的功能、与定位相关的功能中的至少一种。In an implementation manner, the transmission function of the control command of the movable platform to the carrier of the load and the transmission function of the control command of the load to the movable platform are functions related to control. The transmission function of the positioning data of the movable platform is a function related to positioning. If the multimedia data acquired by the mobile platform from the ground side and the data collected by the load are image data, the transmission function of the multimedia data acquired by the mobile platform from the ground side and the transmission function of the collected data on the load are image-related Function; if the multimedia data acquired by the mobile platform from the ground side and the data of the collected data of the load are audio data, the transmission function of the multimedia data acquired by the mobile platform from the ground side and the transmission function of the collected data of the load are audio data Related functions. That is, the open function may include, but is not limited to, at least one of a control-related function, an image-related function, an audio-related function, and a positioning-related function.
以可移动平台为无人飞行器为例,相应的,负载的载体为云台。与控制相关的功能可以为通过负载控制云台的转动、通过负载控制无人飞行器的飞行;与图像相关的功能可以为无人飞行器向负载传输无人飞行器拍摄到的图像数据,其中,图像数据传输时所需要的码流带宽可根据防火墙等级而不同;与音频相关的功能可以为用户通过终端设备将语音上传至负载,例如,通过负载进行播放;与定位相关的功能可以为负载可以获取到无人飞行器上的RTK (Real-time Kinematic,实时动态)数据,该RTK数据结合负载采集的诸如图像数据进行结合,以构建三维模型。Taking the mobile platform as an unmanned aerial vehicle as an example, correspondingly, the carrier of the load is a gimbal. The control-related functions can be to control the rotation of the PTZ through the load and the flight of the unmanned aerial vehicle through the load; the image-related functions can be the unmanned aerial vehicle to transmit the image data taken by the unmanned aerial vehicle to the load, among which, the image data The bit stream bandwidth required for transmission can be different according to the firewall level; audio-related functions can be for users to upload voice to the load through terminal equipment, for example, through the load for playback; positioning-related functions can be obtained by the load RTK (Real-time Kinematic) data on the unmanned aerial vehicle. The RTK data is combined with the image data collected by the load to construct a three-dimensional model.
在一种实现方式中,同一开放功能可以包括不同的功能等级,可移动平台获取到的策略文件还可以包括功能权限与开放功能的功能等级之间的预设对应关系,可移动平台可以根据确定得到的负载的功能权限,功能权限与开放功能的功能等级之间的预设对应关系,确定负载与可移动平台之间的开放功能,确定得到的负载与可移动平台之间的开放功能的功能等级与确定得到的负载的功能权限相适配。In an implementation manner, the same open function may include different function levels, the policy file obtained by the mobile platform may also include the preset correspondence between the function authority and the function level of the open function, and the mobile platform may determine according to The obtained function authority of the load, the preset correspondence between the function authority and the function level of the open function, determine the open function between the load and the movable platform, and determine the function of the open function between the obtained load and the movable platform The level is adapted to the determined functional authority of the load.
示例性的,以同一开放功能为同一类别的功能,功能权限可以包括普通服务功能权限和增值服务功能权限;开放功能的功能等级可以包括普通服务功能等级1、普通服务功能等级2、增值服务功能等级1、增值服务功能等级2;功能权限与开放功能的功能等级之间的预设对应关系可以包括普通服务功能权限与普通服务功能等级之间的对应关系、增值服务功能权限与增值服务功能等级之间的对应关系,用于限定同一类别中所有功能的开放程度。若确定得到的负载的功能权限为普通服务功能权限,可移动平台可以根据普通服务功能权限,确定负载与可移动平台之间的开放功能的普通服务功能等级;若确定得到的负载的功能权限为增值服务功能权限,可移动平台可以根据增值服务功能权限,确定负载与可移动平台之间的开放功能的增值服务功能等级。Exemplarily, taking the same open function as the same type of function, the function authority may include ordinary service function authority and value-added service function authority; the function level of the open function may include ordinary service function level 1, ordinary service function level 2, and value-added service function Level 1, value-added service function level 2; the preset correspondence between function authority and open function function level may include the correspondence between ordinary service function authority and ordinary service function level, value-added service function authority and value-added service function level The corresponding relationship between is used to limit the openness of all functions in the same category. If it is determined that the function authority of the load obtained is the normal service function authority, the mobile platform can determine the normal service function level of the open function between the load and the mobile platform according to the normal service function authority; if it is determined that the function authority of the load obtained is Value-added service function authority, the mobile platform can determine the value-added service function level of the open function between the load and the mobile platform according to the value-added service function authority.
以可移动平台为无人飞行器为例,若确定得到的负载的功能权限为普通服务功能权限,无人飞行器可以根据普通服务功能权限,确定负载与无人飞行器之间的开放功能的普通服务功能等级,从而可以确定负载与无人飞行器之间的开放功能;若确定得到的负载的功能权限为增值服务功能权限,无人飞行器可以根据增值服务功能权限,确定负载与无人飞行器之间的开放功能的增值服务功能等级,从而可以确定负载与无人飞行器之间的开放功能。例如,假设负载与无人飞行器之间的开放功能为增值服务功能,该增值服务功能不仅包括通过负载对云台的控制,也包括通过负载对无人飞行器的控制,在增值服务功能等级为1时,用户可以通过负载控制云台的转动以及通过负载对无人机的控制在预定时段内,而在增值服务功能等级为2时,用户可以通过负载控制云台的转动以及通过负载对无人机的控制在预定时段内没有限制。Taking the mobile platform as an unmanned aerial vehicle as an example, if it is determined that the function authority of the load obtained is the ordinary service function authority, the unmanned aerial vehicle can determine the ordinary service function of the open function between the payload and the unmanned aerial vehicle according to the ordinary service function authority. Level, which can determine the open function between the load and the UAV; if the function authority of the obtained load is determined to be the value-added service function authority, the UAV can determine the open function between the load and the UAV according to the value-added service function authority The value-added service function level of the function, so that the open function between the load and the UAV can be determined. For example, suppose the open function between the load and the UAV is a value-added service function. The value-added service function includes not only the control of the PTZ through the load, but also the control of the UAV through the load. The value-added service function level is 1 When the user can control the rotation of the PTZ through the load and control the drone through the load within a predetermined period of time, when the value-added service function level is 2, the user can control the rotation of the PTZ through the load and control the unmanned aircraft through the load. The control of the machine is not limited within a predetermined period of time.
示例性的,以同一开放功能为相同功能属性的功能,与图像相关的功能,该与图像相关的功能可以分为等级1、等级2,功能权限与开放功能的功能等级之间的预设对应关系可以包括与图像相关的功能及其功能等级之间的对应关系。若确定得到的负载的功能权限为与图像相关的功能,可移动平台可以根据与图像相关的功能及其功能等级之间的对应关系,确定负载与可移动平台之间的与图像相关的功能的功能等级。Exemplarily, the same open function is the function with the same functional attribute, the image-related function, the image-related function can be divided into level 1, level 2, and the preset correspondence between the function authority and the function level of the open function The relationship may include the corresponding relationship between the image-related functions and their function levels. If it is determined that the function authority of the load is an image-related function, the movable platform can determine the image-related function between the load and the movable platform according to the correspondence between the image-related function and its function level. Function level.
以可移动平台为无人飞行器为例,若确定得到的负载的功能权限为与图像相关的功能,无人飞行器可以根据与图像相关的功能及其功能等级之间的对应关系,确定负载与可移动平台之间的与图像相关的功能的功能等级。例如,假设负载与无人飞行器之间的开放功能为与图像相关的功能,在图像的传输过程中,等级1对应的码流带宽小于等级2对应的码流带宽。Taking the mobile platform as an unmanned aerial vehicle as an example, if it is determined that the function authority of the obtained load is an image-related function, the unmanned aerial vehicle can determine the load and the ability according to the correspondence between the image-related function and its function level. The function level of image-related functions between mobile platforms. For example, assuming that the open function between the payload and the UAV is an image-related function, the bit stream bandwidth corresponding to level 1 is smaller than the bit stream bandwidth corresponding to level 2 during image transmission.
在本发明实施例中,可移动平台可以根据获取到的负载的认证信息,即负载的防火墙等级证书,确定负载的功能权限,进而可移动平台可以根据负载的功能权限确定可移动平台与负载之间的开放功能。防火墙等级证书的等级不同,确定得到的负载的功能权限也不同,进而确定得到的负载与可移动平台之间的开放功能可以不同。如此,在负载与可移动平台之间构建了一道功能过滤型防火墙,使得负载与可移动平台之间的开放功能与负载的防火墙等级证书的等级对应,负载不能执行与负载的防火墙等级证书的等级不对应的开放功能,提高负载应用的可靠性和安全性,也可以防止负载被非法冒用的问题。In the embodiment of the present invention, the mobile platform can determine the functional authority of the load according to the obtained authentication information of the load, that is, the firewall level certificate of the load, and the mobile platform can determine the functional authority of the load according to the functional authority of the load. The open function of the room. The level of the firewall level certificate is different, and the function authority of the determined load is also different, and the open function between the determined load and the movable platform may be different. In this way, a functional filtering firewall is constructed between the load and the mobile platform, so that the open function between the load and the mobile platform corresponds to the level of the load’s firewall level certificate, and the load cannot be executed with the load’s firewall level certificate level. Uncorresponding open functions can improve the reliability and security of load applications, and can also prevent the load from being used illegally.
请参见图3,是本发明实施例提供的一种对负载进行认证的方法流程示意图,该对负载进行认证的方法包括但不限于如下步骤:Refer to FIG. 3, which is a schematic flowchart of a method for authenticating a load according to an embodiment of the present invention. The method for authenticating a load includes but is not limited to the following steps:
步骤S301、转接装置发送预设数据至负载。Step S301: The switching device sends preset data to the load.
本实施例中,负载的认证包括负载的合法性的认证。In this embodiment, the authentication of the load includes the authentication of the legitimacy of the load.
本发明实施例提及的转接装置对负载的认证过程可以在图2所示实施例之前执行。例如,转接装置对负载认证通过之后,再执行图2所示的实施例,以确定可移动平台与负载之间的开放功能。The authentication process of the load by the switching device mentioned in the embodiment of the present invention may be performed before the embodiment shown in FIG. 2. For example, after the switching device passes the load authentication, the embodiment shown in FIG. 2 is executed to determine the open function between the movable platform and the load.
本发明实施例提及的转接装置对负载的认证过程还可以在转接装置检测到负载连接于转接装置时执行。例如,图3所示的转接装置对负载的认证过程以及图2所示的开放功能确定过程可以在负载连接于转接装置时,同时执行。The authentication process of the load by the switching device mentioned in the embodiment of the present invention may also be executed when the switching device detects that the load is connected to the switching device. For example, the authentication process for the load by the switching device shown in FIG. 3 and the open function determination process shown in FIG. 2 may be executed simultaneously when the load is connected to the switching device.
可以理解,本实施例中的应用程序与上一实施例中提到的应用程序可以不同,也可以相同。It can be understood that the application program in this embodiment and the application program mentioned in the previous embodiment may be different or the same.
在实际的认证过程中,可以分为在线模式和离线模式。即在可移动平台与服务器通信连接的情况下,可以利用在线模式或离线模式中的任一种,对负载进行认证;而在可移动平台与服务器未通信连接的情况下,利用离线模式对负载进行认证。具体的,为了能够在离线模式下,对负载进行认证,转接装置处可以存储有用于认证负载的合法性的相应信息,如密钥(如前述说明的认证密钥)。In the actual authentication process, it can be divided into online mode and offline mode. That is, when the mobile platform is in communication with the server, either online mode or offline mode can be used to authenticate the load; and when the mobile platform is not in communication with the server, the offline mode can be used to authenticate the load. Perform authentication. Specifically, in order to be able to authenticate the load in offline mode, the switching device may store corresponding information for authenticating the legitimacy of the load, such as a key (such as the authentication key described above).
具体的,在转接装置检测到负载连接于转接装置时,转接装置可以向负载发送预设数据,预设数据可以为一段随机字符串,用于对负载的合法性进行验证。Specifically, when the switching device detects that the load is connected to the switching device, the switching device may send preset data to the load, and the preset data may be a random string for verifying the legitimacy of the load.
步骤S302、负载基于预设数据和预设密钥生成第一校验数据。Step S302: The load generates first verification data based on the preset data and the preset key.
负载接收到来自转接装置的预设数据后,负载可以根据预设的校验算法,对负载的预设密钥(如前述提到的认证密钥)和预设数据进行计算,生成第一校验数据。负载中存储的包括认证密钥等负载的应用信息可以是供应商提供,并由开发商在供应商提供的网站上进行注册后获取,开发商获取到应用信息后,可将该应用信息写入负载中。After the load receives the preset data from the switching device, the load can calculate the preset key (such as the authentication key mentioned above) and the preset data of the load according to the preset verification algorithm to generate the first Check the data. The load application information including authentication keys and other load stored in the load can be provided by the supplier and obtained by the developer after registering on the website provided by the supplier. After the developer obtains the application information, the application information can be written into it Under load.
其中,预设的校验算法可以包括MD5算法、CMAC算法、SHA256算法、SHA512算法等等。Among them, the preset verification algorithm may include the MD5 algorithm, the CMAC algorithm, the SHA256 algorithm, the SHA512 algorithm, and so on.
步骤S303、负载发送第一校验数据至转接装置。Step S303: The load sends the first verification data to the switching device.
负载可以将生成的第一校验数据发送至转接装置,转接装置可以通过第一校验数据对负载进行合法性认证。The load may send the generated first verification data to the switching device, and the switching device may perform legality authentication on the load through the first verification data.
步骤S304、转接装置对第一校验数据进行验证。Step S304: The switching device verifies the first verification data.
在一种实现方式中,转接装置与服务器可以建立通信连接,转接装置可以通过服务器对第一校验数据进行验证,即转接装置可以通过在线模式对第一校验数据进行验证。例如,转接装置接收到来自负载的第一校验数据后,转接装置将第一校验数据和预设数据发送至服务器,服务器可以根据预设的校验算法,对来自转接装置的预设数据和服务器中存储的预设密钥进行计算,生成第三校验数据。若第一校验数据与第三校验数据相同,服务器可以向转接装置发送校 验成功通知,转接装置可以基于该校验成功通知,确定对来自负载的第一校验数据认证通过,从而转接装置确认对负载认证通过,转接装置可以允许负载通过转接装置与可移动平台建立通信连接;若第一校验数据与第三校验数据不相同,服务器可以向转接装置发送校验失败通知,转接装置可以基于该校验失败通知,确定对来自负载的第一校验数据认证失败,从而转接装置确认对负载认证失败,转接装置可以禁止负载通过转接装置与可移动平台建立通信连接,转接装置可以将来自负载的第一校验数据从转接装置的存储空间中删除。In an implementation manner, the switching device can establish a communication connection with the server, and the switching device can verify the first verification data through the server, that is, the switching device can verify the first verification data in an online mode. For example, after the switching device receives the first verification data from the load, the switching device sends the first verification data and the preset data to the server, and the server can check the data from the switching device according to the preset verification algorithm. The preset data and the preset key stored in the server are calculated to generate the third verification data. If the first verification data is the same as the third verification data, the server may send a verification success notification to the switching device, and the switching device may determine that the first verification data from the load is authenticated based on the verification success notification, Therefore, the switching device confirms that the load is authenticated, and the switching device can allow the load to establish a communication connection with the movable platform through the switching device; if the first verification data is different from the third verification data, the server can send to the switching device In the verification failure notification, the switching device may determine that the authentication of the first verification data from the load has failed based on the verification failure notification, so that the switching device confirms that the authentication of the load has failed, and the switching device may prohibit the load from passing through the switching device and The mobile platform establishes a communication connection, and the switching device can delete the first verification data from the load from the storage space of the switching device.
以图4所示的一种负载认证成功的流程示意图为例,用户可以使用用户账号登录一应用程序,并通过该应用程序向转接装置发送开始校验通知。转接装置可以响应该开始校验通知,并向负载发送应用信息获取请求,开启负载认证流程。负载可以基于该应用信息获取请求,可以将应用信息(传输时包括身份标识或产品名称,但不包括认证密钥)发送至转接装置,转接装置接收到负载发送的身份标识或产品名称后,可以向负载发送预设数据,负载接收到来自转接装置的预设数据后,负载可以根据预设的校验算法,对负载的预设密钥和预设数据进行计算,生成第一校验数据,并将第一校验数据返回至转接装置。转接装置接收到负载返回的第一校验数据后,转接装置可以将第一校验数据、预设数据、应用信息发送至服务器,以使服务器对来自负载的第一校验数据进行验证。服务器可以根据应用信息,获取服务器中存储的与应用信息对应的预设密钥,服务器可以根据预设的校验算法,对服务器中存储的预设密钥和来自转接装置的预设数据进行计算,生成第三校验数据。若第一校验数据与第三校验数据相同,服务器可以向转接装置发送校验成功通知、第一校验数据、应用信息;转接装置可以将服务器返回的校验成功通知发送至应用程序,用户可以通过应用程序获知转接装置对负载认证通过。转接装置还可以将服务器返回的配置信息存储在转接装置的存储空间中。若第一校验数据与第三校验数据不相同,转接装置可以确定对来自负载的第一校验数据认证失败,从而转接装置确认对负载认证失败,转接装置可以禁止负载通过转接装置与可移动平台建立通信连接,转接装置还可以将来自负载的第一校验数据从转接装置的存储空间中删除。其中,配置信息包括第一校验数据、应用信息。Taking a schematic diagram of a successful load authentication process shown in FIG. 4 as an example, a user can log in to an application with a user account, and send a verification start notification to the switching device through the application. The switching device may respond to the start verification notification and send an application information acquisition request to the load to start the load authentication process. The load can be based on the application information acquisition request, and the application information (including the identity or product name during transmission, but not the authentication key) can be sent to the switching device. After the switching device receives the identity or product name sent by the load , Can send preset data to the load. After the load receives the preset data from the switching device, the load can calculate the preset key and preset data of the load according to the preset verification algorithm to generate the first calibration. Verify the data, and return the first verification data to the switching device. After the switching device receives the first verification data returned by the load, the switching device may send the first verification data, preset data, and application information to the server, so that the server verifies the first verification data from the load . The server can obtain the preset key stored in the server corresponding to the application information according to the application information, and the server can perform a check on the preset key stored in the server and the preset data from the switching device according to the preset verification algorithm. Calculate and generate the third verification data. If the first verification data is the same as the third verification data, the server may send a verification success notification, the first verification data, and application information to the switching device; the switching device may send the verification success notification returned by the server to the application Program, the user can know that the transfer device has passed the load authentication through the application program. The switching device may also store the configuration information returned by the server in the storage space of the switching device. If the first verification data is not the same as the third verification data, the switching device can determine that the authentication of the first verification data from the load has failed, so that the switching device confirms that the authentication of the load has failed, and the switching device can prohibit the load from passing the transfer. The connection device establishes a communication connection with the movable platform, and the switching device can also delete the first verification data from the load from the storage space of the switching device. Wherein, the configuration information includes first verification data and application information.
其中,应用信息中的产品名称和身份标识可以用于记录组合设备的认证信 息。可以理解,第一校验数据与预设数据可以不同步发送至服务器;应用信息与第一校验数据也可以同步发送至转接装置;应用信息获取请求与发送预设数据可以同步发送,或者应用信息获取请求也可以不发送,在实际应用中,负载能够发送相应的应用信息与第一校验数据给转接装置即可。Among them, the product name and identity identifier in the application information can be used to record the authentication information of the combined device. It can be understood that the first verification data and the preset data can be sent to the server asynchronously; the application information and the first verification data can also be sent to the switching device synchronously; the application information acquisition request and the sending preset data can be sent synchronously, or The application information acquisition request may not be sent. In actual applications, the load can send the corresponding application information and the first verification data to the switching device.
在一种实现方式中,转接装置可以通过离线模式对第一校验数据进行验证。转接装置接收到来自负载的第一校验数据后,转接装置可以根据预设的校验算法,对预设数据和转接装置获取到的预设密钥(如前述提到的认证密钥)进行计算,生成第二校验数据。转接装置获取到的预设密钥可以是转接装置对获取到的加密的预设密钥进行解密获得的。若第一校验数据与第二校验数据相同,转接装置可以确定对来自负载的第一校验数据认证通过,从而转接装置确认对负载认证通过,转接装置可以允许负载通过转接装置与可移动平台建立通信连接;若第一校验数据与第二校验数据不相同,转接装置可以确定对来自负载的第一校验数据认证失败,从而转接装置确认对负载认证失败,转接装置可以禁止负载通过转接装置与可移动平台建立通信连接,转接装置还可以将来自负载的第一校验数据从转接装置的存储空间中删除。In an implementation manner, the switching device may verify the first verification data in an offline mode. After the switching device receives the first verification data from the load, the switching device can check the preset data and the preset key obtained by the switching device (such as the authentication secret mentioned above) according to the preset verification algorithm. Key) to perform calculations to generate second verification data. The preset key acquired by the switching device may be obtained by decrypting the acquired encrypted preset key by the switching device. If the first verification data is the same as the second verification data, the switching device can determine that the authentication of the first verification data from the load is passed, so that the switching device confirms that the load is authenticated, and the switching device can allow the load to pass the transfer The device establishes a communication connection with the movable platform; if the first verification data and the second verification data are not the same, the switching device can determine that the authentication of the first verification data from the load has failed, so that the switching device confirms that the authentication of the load has failed , The switching device can prohibit the load from establishing a communication connection with the movable platform through the switching device, and the switching device can also delete the first verification data from the load from the storage space of the switching device.
其中,为了能够在离线模式下对第一校验数据进行验证时,可以对负载和载体进行绑定,以在转接装置处存储相应的绑定信息,从而获取预设密钥。具体的,在整个认证绑定过程中,为了负载不会向转接装置传输预设密钥而导致信息的泄露,可以通过转接装置发送随机字符串至载体和可移动平台,负载端可以采用预设密钥和接收到的随机字符串计算校验值,并可以将该校验值通过转接装置发送至服务器,服务器也可以通过预设密钥和接收到的随机字符串计算校验值,并可以将计算得到的校验值与由负载发送的校验值进行对比,若相同,则认为负载通过认证,可以将负载与载体进行绑定,并可以将下发绑定配置信息至转接装置。其中,绑定配置信息中可以包括预设密钥,并可以被加密。Wherein, in order to be able to verify the first verification data in the offline mode, the load and the carrier may be bound, so as to store corresponding binding information at the switching device, so as to obtain the preset key. Specifically, in the entire authentication and binding process, in order to prevent the payload from transmitting the preset key to the switching device and causing information leakage, the switching device can send a random character string to the carrier and the movable platform, and the payload can use The preset key and the received random character string calculate the check value, and the check value can be sent to the server through the switching device, and the server can also calculate the check value based on the preset key and the received random character string , And the calculated check value can be compared with the check value sent by the load. If they are the same, the load is considered to be authenticated, the load can be bound to the carrier, and the binding configuration information can be issued to the transfer接装置。 Connecting device. Among them, the binding configuration information may include a preset key and may be encrypted.
其中,在负载运行的过程中,转接装置可以间隔预设周期对负载进行多次认证,若认证未通过,则可以立即禁止负载通过转接装置与可移动平台继续建立通信连接,有利于避免用户通过负载对可移动平台进行非法控制。Among them, in the process of load operation, the switching device can authenticate the load multiple times at intervals of a preset period. If the authentication fails, the load can be immediately prohibited from continuing to establish a communication connection with the mobile platform through the switching device, which is beneficial to avoid The user illegally controls the movable platform through the load.
在本发明实施例中,转接装置可以对负载的合法性进行认证。若转接装置确认负载认证通过,转接装置可以允许负载通过转接装置与可移动平台建立通 信连接,以进一步确定负载与可移动平台之间的开放功能,从而提高负载认证的可靠性。若转接装置确认负载认证未通过,转接装置可以立即禁止负载通过转接装置与可移动平台建立通信连接,以避免用户通过负载对可移动平台进行非法控制,从而有利于保护可以移动平台的安全性。In the embodiment of the present invention, the switching device can authenticate the legitimacy of the load. If the transfer device confirms that the load authentication is passed, the transfer device can allow the load to establish a communication connection with the mobile platform through the transfer device to further determine the open function between the load and the mobile platform, thereby improving the reliability of the load authentication. If the transfer device confirms that the load authentication has not passed, the transfer device can immediately prohibit the load from establishing a communication connection with the mobile platform through the transfer device, so as to prevent the user from illegally controlling the mobile platform through the load, which is beneficial to protect the mobile platform. safety.
请参见图5,是本发明实施例提供的一种对转接装置进行认证的方法流程示意图,该对转接装置进行认证的方法包括但不限于如下步骤:Refer to FIG. 5, which is a schematic flowchart of a method for authenticating a switching device according to an embodiment of the present invention. The method for authenticating a switching device includes but is not limited to the following steps:
步骤S501、可移动平台向转接装置发送转接装置认证请求。Step S501: The movable platform sends a switching device authentication request to the switching device.
本实施例中,载体上设有转接装置,负载通过转接装置与载体、可移动平台进行通信连接。In this embodiment, a switching device is provided on the carrier, and the load communicates with the carrier and the movable platform through the switching device.
本发明实施例提及的可移动平台对转接装置的认证过程可以在图2所示实施例之前执行,或者在可移动平台检测到负载连接于可移动平台时执行。The authentication process of the transfer device by the movable platform mentioned in the embodiment of the present invention may be executed before the embodiment shown in FIG. 2 or executed when the movable platform detects that the load is connected to the movable platform.
本发明实施例提及的可移动平台对转接装置的认证过程可以与图3所示的转接装置对负载的认证过程同时执行,也可以不同时执行。例如,本发明实施例提及的可移动平台对转接装置的合法性的认证过程可在图3所示的转接装置对负载的认证过程之前执行。再例如,本发明实施例提及的可移动平台对转接装置的认证过程与图3所示的转接装置对负载的认证过程,可以在负载连接于转接装置时同时执行。The authentication process of the transfer device by the movable platform mentioned in the embodiment of the present invention may be performed at the same time as the authentication process of the load by the transfer device shown in FIG. 3, or may not be performed at the same time. For example, the authentication process of the legitimacy of the transfer device by the movable platform mentioned in the embodiment of the present invention may be performed before the authentication process of the load by the transfer device shown in FIG. 3. For another example, the authentication process of the transfer device by the movable platform mentioned in the embodiment of the present invention and the authentication process of the load by the transfer device shown in FIG. 3 can be performed at the same time when the load is connected to the transfer device.
为了进一步提高组合设备的应用安全性,可移动平台检测到负载连接于可移动平台,可移动平台可以向转接装置发送转接装置认证请求,以获取用于对转接装置进行认证的转接装置认证信息。In order to further improve the application security of the combined equipment, the movable platform detects that the load is connected to the movable platform, and the movable platform can send the adapter device authentication request to the adapter device to obtain the adapter used to authenticate the adapter device. Device authentication information.
其中,转接装置可以与载体集成为同一设备,也可以相互独立,转接装置可以与载体集成为同一设备,转接装置的认证可以等同为包括载体的认证。其中,在可移动平台检测到转接装置连接于可移动平台时,即可对转接装置进行认证,以在转接装置每次开始被使用时,都能够被进行认证,防止了转接装置被替换的风险,从而保证转接装置一直为有效转接装置,提升了应用的安全性。其中,在转接装置的一次使用过程中,可以对转接装置进行一次初始认证,也可以在使用过程中,持续地或间隔地进行多次认证,此处不做具体限定。Wherein, the switching device and the carrier can be integrated into the same device, or they can be independent of each other, the switching device can be integrated with the carrier into the same device, and the authentication of the switching device can be equivalent to the authentication including the carrier. Among them, when the movable platform detects that the adapter device is connected to the movable platform, the adapter device can be authenticated, so that every time the adapter device is used, it can be authenticated, preventing the adapter device The risk of being replaced ensures that the switching device is always an effective switching device, which improves the safety of the application. Among them, during a single use of the switching device, the switching device can be authenticated once, or it can be repeatedly authenticated continuously or at intervals during the use process, which is not specifically limited here.
步骤S502、可移动平台接收转接装置发送的转接装置认证信息。Step S502: The mobile platform receives the adapter device authentication information sent by the adapter device.
转接装置接收到可移动平台发送的转接装置认证请求后,转接装置可以基 于该转接装置认证请求,将转接装置的转接装置认证信息发送至可移动平台,可移动平台可以接收转接装置发送的转接装置认证信息,并根据该转接装置认证信息对转接装置进行认证。After the adapter device receives the adapter device certification request sent by the movable platform, the adapter device can send the adapter device certification information of the adapter device to the movable platform based on the adapter device certification request, and the movable platform can receive The switching device authentication information sent by the switching device, and the switching device is authenticated according to the switching device authentication information.
步骤S503、可移动平台根据转接装置认证信息对转接装置进行认证。如此,认证该转接装置为有效的转接装置或无效的转接装置。Step S503: The mobile platform authenticates the switching device according to the authentication information of the switching device. In this way, the adapter device is authenticated as a valid adapter device or an invalid adapter device.
可移动平台接收到转接装置发送的转接装置认证信息后,可移动平台可以根据转接装置认证信息对转接装置进行认证,以判断转接装置是否为有效的转接装置。其中,转接装置认证信息可以包括转接装置的防伪标识(如前述提到的供应商信息),可移动平台可以根据转接装置的防伪标识判断转接装置是否为有效的转接装置,也即是否为供应商提供的转接装置。After the mobile platform receives the adapter device authentication information sent by the adapter device, the movable platform can authenticate the adapter device according to the adapter device authentication information to determine whether the adapter device is a valid adapter device. Wherein, the authentication information of the switching device may include the anti-counterfeiting identification of the switching device (such as the aforementioned supplier information), and the movable platform can determine whether the switching device is a valid switching device according to the anti-counterfeiting identification of the switching device. That is, whether it is a switching device provided by the supplier.
在一种实现方式中,转接装置认证信息可以包括转接装置的证书,该证书中有转接装置的防伪标识。可移动平台的认证中心可以对转接装置的证书进行认证。若可移动平台的认证中心根据转接装置的证书中的信息确定转接装置的证书为有效的证书,可移动平台可以确定转接装置为有效的转接装置;若可移动平台的认证中心确定转接装置的证书未通过认证,可移动平台的认证中心可以确定对转接装置的证书认证失败,可移动平台可以将接收到的转接装置的证书从可移动平台的存储空间中删除,并可以关闭转接装置与可移动平台之间的通信功能,还可以对用户进行相应提示,例如,可移动平台可以发出光电提示,或在可移动平台的遥控器侧发出提示。In an implementation manner, the switching device authentication information may include a certificate of the switching device, and the certificate contains the anti-counterfeiting identification of the switching device. The certification center of the mobile platform can certify the certificate of the switching device. If the certification center of the mobile platform determines that the certificate of the switching device is a valid certificate according to the information in the certificate of the switching device, the mobile platform can determine that the switching device is a valid switching device; if the certification center of the mobile platform determines The certificate of the transfer device fails the authentication, the certification center of the mobile platform can determine that the certificate authentication of the transfer device has failed, and the mobile platform can delete the received certificate of the transfer device from the storage space of the mobile platform, and The communication function between the switching device and the movable platform can be turned off, and the user can be prompted accordingly. For example, the movable platform can send out a photoelectric prompt, or send out a prompt on the remote control side of the movable platform.
在一种实现方式中,转接装置认证信息可以包括转接装置的证书和负载的SN,该证书中有转接装置的防伪标识。可移动平台的认证中心可以对转接装置的证书和负载的SN进行认证。可移动平台的认证中心可以对转接装置的证书的认证可以参照上述说明,此处不再赘述。其中,转接装置认证信息包括的负载的SN,可以在可移动平台与服务器建立通信连接时,由可移动平台发送至服务器,并存储于服务器中,以使得服务器可以根据该SN记录负载的负载认证信息,以使得开发商可以根据服务器记录的相关认证信息获悉产品的相关认证信息。In an implementation manner, the switching device authentication information may include the certificate of the switching device and the SN of the load, and the certificate contains the anti-counterfeiting identification of the switching device. The authentication center of the mobile platform can authenticate the certificate of the switching device and the SN of the load. The certification center of the mobile platform can refer to the above description for certification of the certificate of the switching device, which will not be repeated here. Wherein, the SN of the load included in the authentication information of the switching device can be sent to the server by the mobile platform when a communication connection is established between the mobile platform and the server, and stored in the server, so that the server can record the load of the load according to the SN. Authentication information, so that the developer can learn the relevant authentication information of the product based on the relevant authentication information recorded by the server.
在一种实现方式中,转接装置认证信息可以包括转接装置的证书、负载的SN和响应信息,该证书中有转接装置的防伪标识和前述说明的第一密钥,响 应信息为利用第一密钥对转接装置认证请求中携带的字符串进行校验得到。例如,可移动平台的认证中心可以通过Challenge/Response(挑战/回应)认证的方式对转接装置的合法性进行认证。可移动平台向转接装置发送的转接装置认证请求中可以携带挑战字符串“Challenge”,转接装置接收到可移动平台发送的转接装置认证请求后,转接装置可以根据预设的校验算法对第一密钥和挑战字符串“Challenge”进行计算,生成第一回应字符串“Response”。转接装置可以将第一回应字符串“Response”、转接装置的证书、负载的SN发送至可移动平台,可移动平台的认证中心可以从转接装置的证书中获取第一密钥,并根据预设的校验算法,对第一回应字符串“Response”进行计算,生成第二回应字符串“Response”。若挑战字符串“Challenge”与第二回应字符串“Response”相同,且可移动平台的认证中心可以确定转接装置的证书为有效的证书,则可移动平台可以确定转接装置为有效的转接装置;若挑战字符串“Challenge”与第二回应字符串“Response”不相同,或可移动平台的认证中心可以确定转接装置的证书为无效的证书,则可移动平台可以确定转接装置为无效的转接装置。其中,在转接装置为有效或无效的转接装置时的具体执行内容可以参照前述说明;SN的发送理由也可以参照前述说明,此处不再赘述。可以理解的是,通过对转接装置认证请求中的字符串进行认证,可以进一步防止转接装置被替换或冒用的风险,并提高转接装置的应用安全性。In an implementation manner, the switching device authentication information may include the certificate of the switching device, the SN of the load, and response information. The certificate contains the anti-counterfeiting identification of the switching device and the first key described above, and the response information is the use of The first key is obtained by verifying the character string carried in the authentication request of the switching device. For example, the authentication center of the mobile platform can authenticate the legitimacy of the switching device through Challenge/Response (Challenge/Response) authentication. The transfer device authentication request sent by the mobile platform to the transfer device can carry the challenge character string "Challenge". After the transfer device receives the transfer device authentication request sent by the mobile platform, the transfer device can use the preset calibration The verification algorithm calculates the first key and the challenge string "Challenge" to generate the first response string "Response". The switching device can send the first response string "Response", the certificate of the switching device, and the SN of the load to the mobile platform, and the certification center of the mobile platform can obtain the first key from the certificate of the switching device, and According to the preset verification algorithm, the first response string "Response" is calculated to generate the second response string "Response". If the challenge string "Challenge" is the same as the second response string "Response", and the certification center of the mobile platform can determine that the certificate of the transfer device is a valid certificate, the mobile platform can determine that the transfer device is a valid transfer device. If the challenge string "Challenge" and the second response string "Response" are not the same, or the certification center of the mobile platform can determine that the certificate of the transfer device is an invalid certificate, the mobile platform can determine the transfer device It is an invalid adapter. Among them, the specific execution content when the switching device is a valid or invalid switching device can refer to the foregoing description; the reason for sending the SN can also refer to the foregoing description, which will not be repeated here. It is understandable that by authenticating the character string in the switching device authentication request, the risk of replacement or fraudulent use of the switching device can be further prevented, and the application security of the switching device can be improved.
转接装置是连接负载与可移动平台的设备,负载与可移动平台之间的通信交互经由转接装置传输,在本发明实施例中,可移动平台通过转接装置的证书、负载的SN等转接装置认证信息对转接装置进行认证,可移动平台确认转接装置认证通过,即转接装置为有效的转接装置之后,负载与可移动平台之间可以通过转接装置传输通信交互的数据。可移动平台通过对转接装置的认证,可以进一步提高负载认证的可靠性和安全性。The transfer device is a device that connects the load and the mobile platform. The communication interaction between the load and the mobile platform is transmitted via the transfer device. In the embodiment of the present invention, the mobile platform passes the certificate of the transfer device, the SN of the load, etc. The switching device authentication information authenticates the switching device, and the mobile platform confirms that the switching device is authenticated, that is, after the switching device is a valid switching device, the load and the mobile platform can transmit communication interaction through the switching device. data. The mobile platform can further improve the reliability and safety of load authentication through the authentication of the switching device.
结合图3至图5,以图6所示的一种示例性的负载认证方法的流程示意图为例,在可移动平台的认证中心检测到负载连接于可移动平台时,可移动平台的认证中心可以向负载发送负载认证请求,负载可以基于该负载认证请求获取负载认证信息(负载内可以存储有负载认证信息)。可移动平台的防火墙可以向可移动平台的认证中心发送策略文件获取请求,可移动平台的认证中心可以 基于该策略文件获取请求,将策略文件返回至可移动平台的防火墙。可移动平台的防火墙接收到可移动平台的认证中心返回的策略文件后,可移动平台的防火墙可以向可移动平台的认证中心发送转接装置认证通知,可移动平台的认证中心可以响应该转接装置认证通知,并发送携带挑战字符串的转接装置认证请求至转接装置。转接装置可以根据预设的校验算法,对转接装置的证书中的第一密钥和挑战字符串进行计算,生成第一回应字符串,转接装置可以将第一回应字符串、转接装置的证书、负载的产品序列号发送至可移动平台的认证中心。可移动平台的认证中心可以从接收到的转接装置的证书中获取第一密钥,并根据预设的校验算法,对第一回应字符串进行计算,生成第二回应字符串。若挑战字符串与第二回应字符串相同,且可移动平台的认证中心确定转接装置的证书为有效的证书,可移动平台的认证中心确认对转接装置认证通过(若转接装置集成于载体,即载体的认证通过;若转接转置不集成于载体,可以进一步在载体的合法性进行认证),可移动平台的认证中心可以接收负载经由转接装置发送的负载认证信息。可移动平台的认证中心可以根据负载认证信息确定负载的功能权限,可移动平台的防火墙可以根据负载的功能权限确定负载与可移动平台之间的开放功能。With reference to Figures 3 to 5, taking the flow diagram of an exemplary load authentication method shown in Figure 6 as an example, when the authentication center of the mobile platform detects that the load is connected to the mobile platform, the authentication center of the mobile platform A load authentication request may be sent to the load, and the load may obtain load authentication information based on the load authentication request (load authentication information may be stored in the load). The firewall of the mobile platform can send a policy file acquisition request to the certification center of the mobile platform, and the certification center of the mobile platform can return the policy file to the firewall of the mobile platform based on the policy file acquisition request. After the firewall of the mobile platform receives the policy file returned by the certification center of the mobile platform, the firewall of the mobile platform can send the transfer device certification notification to the certification center of the mobile platform, and the certification center of the mobile platform can respond to the transfer Device authentication notification, and sending a transfer device authentication request carrying a challenge string to the transfer device. The switching device can calculate the first key and the challenge string in the certificate of the switching device according to a preset verification algorithm to generate a first response string. The switching device can convert the first response string to the challenge string. The certificate of the connected device and the product serial number of the load are sent to the certification center of the mobile platform. The certification center of the mobile platform can obtain the first key from the received certificate of the switching device, and calculate the first response string according to the preset verification algorithm to generate the second response string. If the challenge string is the same as the second response string, and the certification center of the mobile platform determines that the certificate of the adapter device is a valid certificate, the certification center of the mobile platform confirms that the adapter device is authenticated (if the adapter device is integrated in The carrier, that is, the authentication of the carrier is passed; if the transfer transposition is not integrated into the carrier, the legality of the carrier can be further authenticated), the authentication center of the mobile platform can receive the load authentication information sent by the transfer device. The authentication center of the mobile platform can determine the functional authority of the load according to the load authentication information, and the firewall of the mobile platform can determine the open function between the load and the mobile platform according to the functional authority of the load.
可移动平台的防火墙根据负载的功能权限确定负载与可移动平台之间的开放功能之后,可移动平台的防火墙还可以将配置信息发送至转接装置,转接装置可以将配置信息存储至转接装置的存储空间中。其中,该配置信息用于指示可移动平台根据负载的功能权限确定的负载与可移动平台之间的开放功能的。After the firewall of the mobile platform determines the open functions between the load and the mobile platform according to the functional authority of the load, the firewall of the mobile platform can also send configuration information to the switching device, and the switching device can store the configuration information to the switching device. In the storage space of the device. Wherein, the configuration information is used to indicate the open function between the load and the movable platform determined by the movable platform according to the functional authority of the load.
如此,可以多方位对负载与可移动平台之间的通信交互进行安全认证,保证了在其之间的通讯协议被其它用户破解的情况下,在安全认证的过程中不会泄露用户信息,也降低了负载或包括转接装置的载体被非法替换的风险。In this way, the communication interaction between the load and the mobile platform can be authenticated in multiple ways, ensuring that if the communication protocol between them is cracked by other users, the user information will not be leaked during the security authentication process. The risk of illegal replacement of the load or the carrier including the switching device is reduced.
可选的,图6所示的实施例中,可移动平台可以先向负载发送负载认证请求,再对转接装置进行认证,若可移动平台对转接装置认证通过,转接装置将负载返回的负载认证信息发送至可移动平台;可移动平台也可以先对转接装置进行认证,若可移动平台对转接装置认证通过,转接装置将可移动平台的负载认证请求发送至负载。Optionally, in the embodiment shown in FIG. 6, the mobile platform may first send a load authentication request to the load, and then authenticate the switching device. If the mobile platform passes the authentication of the switching device, the switching device returns the load The load authentication information of the mobile platform is sent to the mobile platform; the mobile platform can also authenticate the transfer device first, if the mobile platform passes the authentication of the transfer device, the transfer device sends the load authentication request of the mobile platform to the load.
请参见图7,图7是本发明实施例提供的一种可移动平台的结构示意图,本发明实施例的所述可移动平台70包括:存储器701、处理器702。存储器701、处理器702通过一条或多条通信总线连接。Please refer to FIG. 7. FIG. 7 is a schematic structural diagram of a movable platform according to an embodiment of the present invention. The movable platform 70 in the embodiment of the present invention includes a memory 701 and a processor 702. The memory 701 and the processor 702 are connected by one or more communication buses.
所述存储器701可以包括易失性存储器(Volatile Memory),例如随机存取存储器(Random-Access Memory,RAM);存储器701也可以包括非易失性存储器(Non-Volatile Memory),例如快闪存储器(Flash Memory),固态硬盘(Solid-State Drive,SSD)等;存储器701还可以包括上述种类的存储器的组合。The memory 701 may include volatile memory (Volatile Memory), such as random access memory (Random-Access Memory, RAM); the memory 701 may also include non-volatile memory (Non-Volatile Memory), such as flash memory (Flash Memory), Solid-State Drive (SSD), etc.; the memory 701 may also include a combination of the foregoing types of memories.
所述处理器702可以是中央处理器(central processing unit,CPU),所述处理器还可以是其他通用处理器、数字信号处理器(Digital Signal Processor,DSP)、专用集成电路(Application Specific Integrated Circuit,ASIC)、现成可编程门阵列(Field-Programmable Gate Array,FPGA)或者其他可编程逻辑器件、分立门或者晶体管逻辑器件、分立硬件组件等。通用处理器可以是微处理器或者该处理器也可以是任何常规的处理器等。The processor 702 may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (Digital Signal Processors, DSPs), and application specific integrated circuits (Application Specific Integrated Circuits). , ASIC), ready-made programmable gate array (Field-Programmable Gate Array, FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor or the like.
本发明实施例的所述可移动平台70通过所述处理器702可以用于实施上述图2或图5所示的本发明各实施例实现的方法,为了便于说明,仅示出了与本发明实施例相关的部分,实现请参照图2或图5所示的本发明各实施例。The movable platform 70 of the embodiment of the present invention can be used to implement the method implemented by each embodiment of the present invention shown in FIG. 2 or FIG. 5 through the processor 702. For related parts of the embodiment, please refer to the embodiments of the present invention shown in FIG. 2 or FIG. 5 for implementation.
在一种实现方式中,存储器701中存储有程序指令,处理器702调用存储器701中的程序指令,当程序指令被执行时,所述处理器702用于:在检测到负载连接于所述可移动平台时,获取所述负载的负载认证信息;根据所述负载认证信息,确定所述负载的功能权限;根据所述负载的功能权限,确定所述负载与所述可移动平台70之间的开放功能。In one implementation, program instructions are stored in the memory 701, and the processor 702 calls the program instructions in the memory 701. When the program instructions are executed, the processor 702 is configured to: When the platform is moved, the load authentication information of the load is obtained; the function authority of the load is determined according to the load authentication information; the function authority of the load is determined according to the load and the movable platform 70 Open function.
在一种实现方式中,所述负载认证信息包括防火墙等级证书;所述处理器702在根据所述负载认证信息,确定所述负载的功能权限时,具体用于:根据所述防火墙等级证书,确定所述负载的功能权限。In an implementation manner, the load authentication information includes a firewall grade certificate; when the processor 702 determines the functional authority of the load according to the load authentication information, it is specifically configured to: according to the firewall grade certificate, Determine the functional authority of the load.
在一种实现方式中,所述防火墙等级证书为加密的信息;所述处理器702在根据所述负载认证信息,确定所述负载的功能权限时,具体用于:对所述防火墙等级证书进行解密;在解密后的防火墙等级证书有效时,根据所述解密后的防火墙等级证书,确定所述负载的功能权限。In an implementation manner, the firewall level certificate is encrypted information; when the processor 702 determines the functional authority of the load according to the load authentication information, it is specifically configured to: perform a check on the firewall level certificate. Decryption; when the decrypted firewall level certificate is valid, the functional authority of the load is determined according to the decrypted firewall level certificate.
在一种实现方式中,所述处理器702在根据所述防火墙等级证书,确定所述负载的功能权限之前,还用于:获取策略文件,所述策略文件包括防火墙等级与所述开放功能之间的预设对应关系;所述处理器702在根据所述防火墙等级证书,确定所述负载的功能权限时,具体用于:根据所述防火墙等级证书,确定当前的防火墙等级;根据所述策略文件与所述当前的防火墙等级,确定所述负载的功能权限。In an implementation manner, before determining the functional authority of the load according to the firewall level certificate, the processor 702 is further configured to: obtain a policy file, the policy file including the firewall level and the open function When determining the functional authority of the load according to the firewall level certificate, the processor 702 is specifically configured to: determine the current firewall level according to the firewall level certificate; according to the policy The file and the current firewall level determine the functional authority of the load.
在一种实现方式中,所述处理器702获取策略文件的步骤是在检测到所述负载连接于所述可移动平台时执行的。In an implementation manner, the step of obtaining the policy file by the processor 702 is performed when it is detected that the load is connected to the movable platform.
在一种实现方式中,所述策略文件是可更新的。In one implementation, the policy file is updatable.
在一种实现方式中,所述防火墙等级证书是可更新的。In one implementation, the firewall level certificate is updatable.
在一种实现方式中,所述开放功能包括以下中的至少一种:允许所述可移动平台70至所述负载或所述负载的载体的数据传输功能、允许所述负载或所述负载的载体至所述可移动平台70的数据传输功能。In an implementation manner, the open function includes at least one of the following: allowing the mobile platform 70 to transmit data to the load or the load carrier, allowing the load or the load The data transmission function of the carrier to the movable platform 70.
在一种实现方式中,所述允许所述可移动平台70至所述负载或所述负载的载体的数据传输功能包括以下中的至少一种:所述可移动平台70对所述负载的载体的控制命令的传输功能;所述可移动平台70的定位数据的传输功能;所述可移动平台70从地面端获取的多媒体数据的传输功能。In an implementation manner, the data transmission function allowing the movable platform 70 to the load or the carrier of the load includes at least one of the following: the carrier of the movable platform 70 to the load The transmission function of the control command; the transmission function of the positioning data of the movable platform 70; the transmission function of the multimedia data obtained by the movable platform 70 from the ground terminal.
在一种实现方式中,所述允许所述负载或所述负载的载体至所述可移动平台70的数据传输功能包括以下中的至少一种:所述负载的采集数据的传输功能;所述负载对所述可移动平台70的控制命令的传输功能。In an implementation manner, the data transmission function that allows the load or the carrier of the load to the movable platform 70 includes at least one of the following: a transmission function of the collected data of the load; The transmission function of the load to the control command of the movable platform 70.
在一种实现方式中,所述开放功能包括以下中的至少一种:与控制相关的功能、与图像相关的功能、与音频相关的功能、与定位相关的功能。In an implementation manner, the open function includes at least one of the following: a control-related function, an image-related function, an audio-related function, and a positioning-related function.
在一种实现方式中,同一所述开放功能包括不同的功能等级,所述功能等级与确定的所述功能权限相适配。In an implementation manner, the same open function includes different function levels, and the function levels are adapted to the determined function permissions.
在一种实现方式中,所述负载通过转接装置通信连接于所述可移动平台70,所述处理器702还用于执行如下步骤:根据所述负载的功能权限,向所述转接装置发送配置信息,所述配置信息用于指示所述负载与所述可移动平台70之间的开放功能。In an implementation manner, the load is communicatively connected to the movable platform 70 through a switching device, and the processor 702 is further configured to perform the following steps: according to the functional authority of the load, send a message to the switching device Sending configuration information, the configuration information being used to indicate the open function between the load and the movable platform 70.
在一种实现方式中,所述负载通过转接装置通信连接于所述可移动平台 70;所述处理器702在获取所述负载的负载认证信息之前,还用于执行如下步骤:获取所述转接装置的转接装置认证信息;在根据所述转接装置认证信息判断所述转接装置为有效的转接装置时,触发执行所述获取所述负载的负载认证信息的步骤。In an implementation manner, the load is communicatively connected to the movable platform 70 through a switching device; the processor 702 is further configured to perform the following steps before acquiring the load authentication information of the load: The switching device authentication information of the switching device; when it is determined that the switching device is a valid switching device according to the switching device authentication information, the execution of the step of obtaining the load authentication information of the load is triggered.
在一种实现方式中,所述转接装置认证信息包括防伪标识。In an implementation manner, the authentication information of the switching device includes an anti-counterfeiting identifier.
在一种实现方式中,所述处理器702获取转接装置的转接装置认证信息是在检测到所述转接装置连接于所述可移动平台70时执行的。In an implementation manner, the processor 702 obtains the adapter device authentication information of the adapter device when it is detected that the adapter device is connected to the movable platform 70.
在一种实现方式中,所述可移动平台70为第一方提供,所述负载为第二方提供。In an implementation manner, the movable platform 70 is provided by a first party, and the load is provided by a second party.
本实施例提供的可移动平台70能够执行前述实施例中可移动平台所执行的步骤,其执行方式和有益效果类似,在这里不再赘述。The movable platform 70 provided in this embodiment can execute the steps executed by the movable platform in the foregoing embodiment, and the execution mode and beneficial effects are similar, and will not be repeated here.
请参见图8,图8是本发明实施例提供的一种转接装置的结构示意图,本发明实施例的所述转接装置80包括:存储器801、处理器802。存储器801、处理器802通过一条或多条通信总线连接。Please refer to FIG. 8. FIG. 8 is a schematic structural diagram of a switching device according to an embodiment of the present invention. The switching device 80 in the embodiment of the present invention includes a memory 801 and a processor 802. The memory 801 and the processor 802 are connected through one or more communication buses.
所述存储器801可以包括易失性存储器(Volatile Memory),例如随机存取存储器(Random-Access Memory,RAM);存储器801也可以包括非易失性存储器(Non-Volatile Memory),例如快闪存储器(Flash Memory),固态硬盘(Solid-State Drive,SSD)等;存储器801还可以包括上述种类的存储器的组合。The memory 801 may include a volatile memory (Volatile Memory), such as a random access memory (Random-Access Memory, RAM); the memory 801 may also include a non-volatile memory (Non-Volatile Memory), such as a flash memory (Flash Memory), Solid-State Drive (SSD), etc.; the memory 801 may also include a combination of the foregoing types of memories.
所述处理器802可以是中央处理器(central processing unit,CPU),所述处理器还可以是其他通用处理器、数字信号处理器(Digital Signal Processor,DSP)、专用集成电路(Application Specific Integrated Circuit,ASIC)、现成可编程门阵列(Field-Programmable Gate Array,FPGA)或者其他可编程逻辑器件、分立门或者晶体管逻辑器件、分立硬件组件等。通用处理器可以是微处理器或者该处理器也可以是任何常规的处理器等。The processor 802 may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (Digital Signal Processors, DSPs), and application specific integrated circuits (Application Specific Integrated Circuits). , ASIC), ready-made programmable gate array (Field-Programmable Gate Array, FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor or the like.
可以理解,本发明实施例还可以提供一种可移动平台组件,包括上述说明的可移动平台和下述说明的转接装置,其中,转接装置通过云台连接于可移动平台。It can be understood that embodiments of the present invention may also provide a movable platform component, including the movable platform described above and the adapter device described below, wherein the adapter device is connected to the movable platform through a pan-tilt.
本发明实施例的所述转接装置80通过所述处理器802可以用于实施上述 图3或图5所示的本发明各实施例实现的方法,为了便于说明,仅示出了与本发明实施例相关的部分,实现请参照图3或图5所示的本发明各实施例。The switching device 80 of the embodiment of the present invention can be used to implement the method implemented by each embodiment of the present invention shown in FIG. 3 or FIG. 5 through the processor 802. For related parts of the embodiment, please refer to the embodiments of the present invention shown in FIG. 3 or FIG. 5 for implementation.
在一种实现方式中,存储器801中存储有程序指令,处理器802调用存储器801中的程序指令,当程序指令被执行时,所述处理器802用于:将所述负载的负载认证信息发送至所述可移动平台,以使所述可移动平台根据所述负载认证信息,确定所述负载的功能权限;接收并存储所述可移动平台返回的配置信息,所述配置信息用于指示基于所述负载的功能权限确定的所述负载与所述可移动平台之间的开放功能。In one implementation, program instructions are stored in the memory 801, and the processor 802 calls the program instructions in the memory 801. When the program instructions are executed, the processor 802 is configured to: send the load authentication information of the load To the mobile platform, so that the mobile platform determines the functional authority of the load according to the load authentication information; receives and stores the configuration information returned by the mobile platform, and the configuration information is used to indicate The open function between the load and the movable platform determined by the function authority of the load.
在一种实现方式中,所述负载认证信息包括防火墙等级证书。In an implementation manner, the load authentication information includes a firewall level certificate.
在一种实现方式中,所述防火墙等级证书是可更新的。In one implementation, the firewall level certificate is updatable.
在一种实现方式中,所述开放功能包括以下中的至少一种:允许所述可移动平台至所述负载或所述负载的载体的数据传输功能、允许所述负载或所述负载的载体至所述可移动平台的数据传输功能。In an implementation manner, the open function includes at least one of the following: a data transmission function that allows the movable platform to the load or a carrier of the load, and a carrier that allows the load or the load Data transmission function to the mobile platform.
在一种实现方式中,所述允许所述可移动平台至所述负载或所述负载的载体的数据传输功能包括以下中的至少一种:所述可移动平台对所述负载的载体的控制命令的传输功能;所述可移动平台的定位数据的传输功能;所述可移动平台从地面端获取的多媒体数据的传输功能。In an implementation manner, the data transmission function allowing the movable platform to the load or the carrier of the load includes at least one of the following: control of the carrier of the load by the movable platform Command transmission function; transmission function of positioning data of the movable platform; transmission function of multimedia data obtained by the movable platform from the ground terminal.
在一种实现方式中,所述允许所述负载或所述负载的载体至所述可移动平台的数据传输功能包括以下中的至少一种:所述负载的采集数据的传输功能;所述负载对所述可移动平台的控制命令的传输功能。In an implementation manner, the data transmission function that allows the load or the carrier of the load to the movable platform includes at least one of the following: a transmission function of collected data of the load; the load The transmission function of the control command to the movable platform.
在一种实现方式中,所述开放功能包括以下中的至少一种:与控制相关的功能、与图像相关的功能、与音频相关的功能、与定位相关的功能。In an implementation manner, the open function includes at least one of the following: a control-related function, an image-related function, an audio-related function, and a positioning-related function.
在一种实现方式中,同一所述开放功能包括不同的功能等级,所述功能等级与确定的所述功能权限相适配。In an implementation manner, the same open function includes different function levels, and the function levels are adapted to the determined function permissions.
在一种实现方式中,所述处理器802将所述负载的负载认证信息发送至所述可移动平台是在检测到所述负载连接于所述转接装置80时执行的。In an implementation manner, the processor 802 sending the load authentication information of the load to the movable platform is executed when it is detected that the load is connected to the switching device 80.
在一种实现方式中,所述处理器802在将所述负载的负载认证信息发送至所述可移动平台之前,还用于执行如下步骤:将所述转接装置80的转接装置认证信息发送至所述可移动平台;在所述可移动平台根据所述转接装置认证信 息判断所述转接装置80为有效的转接装置时,触发执行所述将所述负载的认证信息发送至所述可移动平台的步骤。In an implementation manner, before sending the load authentication information of the load to the movable platform, the processor 802 is further configured to perform the following steps: send the transfer device authentication information of the transfer device 80 Sent to the movable platform; when the movable platform determines that the switching device 80 is a valid switching device according to the authentication information of the switching device, triggering the execution of the sending of the authentication information of the load to The steps of the movable platform.
在一种实现方式中,所述转接装置认证信息包括防伪标识。In an implementation manner, the authentication information of the switching device includes an anti-counterfeiting identifier.
在一种实现方式中,所述处理器802将所述转接装置80的转接装置认证信息发送至所述可移动平台是在检测到所述转接装置80连接于所述可移动平台时执行的。In one implementation, the processor 802 sends the adapter device authentication information of the adapter device 80 to the movable platform when it is detected that the adapter device 80 is connected to the movable platform. implemented.
在一种实现方式中,所述处理器802在将所述负载的负载认证信息发送至所述可移动平台之前,所述处理器还用于执行如下步骤:接收所述负载发送的第一校验数据;若所述第一校验数据通过验证,则允许所述负载通过所述转接装置80与所述可移动平台通信连接。In an implementation manner, before the processor 802 sends the load authentication information of the load to the movable platform, the processor is further configured to perform the following step: receiving the first calibration sent by the load Verification data; if the first verification data is verified, the load is allowed to communicate with the movable platform through the switching device 80.
在一种实现方式中,所述处理器802还用于执行如下步骤:若所述第一校验数据未通过验证,则禁止所述负载通过所述转接装置80与所述可移动平台通信连接。In an implementation manner, the processor 802 is further configured to perform the following steps: if the first verification data fails the verification, prohibit the load from communicating with the movable platform through the switching device 80 connection.
在一种实现方式中,所述处理器802还用于执行如下步骤:发送预设数据至所述负载,以使得所述负载基于所述预设数据和预设密钥生成所述第一校验数据。In an implementation manner, the processor 802 is further configured to perform the following step: sending preset data to the load, so that the load generates the first calibration based on the preset data and the preset key. Test data.
在一种实现方式中,所述处理器802还用于执行如下步骤:获取加密后的预设密钥,并对所述加密的预设密钥解密,得到预设密钥;根据所述预设密钥和预设数据生成第二校验数据;将所述第一校验数据和所述第二校验数据进行对比;若所述第一校验数据和所述第二校验数据相同,则确定所述第一校验数据通过验证;若所述第一校验数据和所述第二校验数据不相同,则确定所述第一校验数据未通过验证。In an implementation manner, the processor 802 is further configured to perform the following steps: obtain an encrypted preset key, decrypt the encrypted preset key to obtain the preset key; Set the key and preset data to generate second verification data; compare the first verification data with the second verification data; if the first verification data and the second verification data are the same , It is determined that the first verification data has passed the verification; if the first verification data and the second verification data are not the same, it is determined that the first verification data has not passed the verification.
在一种实现方式中,所述转接装置80安装在所述负载的载体上,所述负载的载体用于与所述可移动平台连接。In an implementation manner, the adapter device 80 is installed on a carrier of the load, and the carrier of the load is used to connect with the movable platform.
在一种实现方式中,所述转接装置80以及所述可移动平台为第一方提供,所述负载为第二方提供。In an implementation manner, the switching device 80 and the movable platform are provided by the first party, and the load is provided by the second party.
本实施例提供的转接装置80能够执行前述实施例中转接装置所执行的步骤,其执行方式和有益效果类似,在这里不再赘述。The switching device 80 provided in this embodiment can execute the steps performed by the switching device in the foregoing embodiments, and the execution method and beneficial effects thereof are similar, and details are not described herein again.
可以理解,在转接装置与载体可分离时,本发明实施例还可以提供一种载 体组件,包括上述说明的转接装置以及载体,转接装置安装于载体上,具体的,可设于载体中用于与负载连接的位置,而作为中间转接件。在转接装置与载体不可分离时,这里的转接装置亦可以为包括载体的设备,即云台为转接装置的一部分。其中,转接装置设有用于连接负载的接口,以实现负载、载体、可移动平台之间的通信连接。It can be understood that when the adapter device and the carrier are separable, the embodiment of the present invention may also provide a carrier assembly, including the adapter device and the carrier described above. The adapter device is mounted on the carrier, specifically, it can be set on the carrier. It is used to connect with the load, and as an intermediate adapter. When the adapter device and the carrier are inseparable, the adapter device here can also be a device including the carrier, that is, the pan-tilt is a part of the adapter device. Among them, the switching device is provided with an interface for connecting the load to realize the communication connection between the load, the carrier, and the movable platform.
请参见图9,图9是本发明实施例提供的一种负载的结构示意图,本发明实施例的所述负载90包括:存储器901、处理器902。存储器901、处理器902通过一条或多条通信总线连接。Please refer to FIG. 9. FIG. 9 is a schematic structural diagram of a load provided by an embodiment of the present invention. The load 90 in the embodiment of the present invention includes a memory 901 and a processor 902. The memory 901 and the processor 902 are connected by one or more communication buses.
所述存储器901可以包括易失性存储器(Volatile Memory),例如随机存取存储器(Random-Access Memory,RAM);存储器901也可以包括非易失性存储器(Non-Volatile Memory),例如快闪存储器(Flash Memory),固态硬盘(Solid-State Drive,SSD)等;存储器901还可以包括上述种类的存储器的组合。The memory 901 may include a volatile memory (Volatile Memory), such as a random access memory (Random-Access Memory, RAM); the memory 901 may also include a non-volatile memory (Non-Volatile Memory), such as a flash memory (Flash Memory), Solid-State Drive (SSD), etc.; the memory 901 may also include a combination of the foregoing types of memories.
所述处理器902可以是中央处理器(central processing unit,CPU),所述处理器还可以是其他通用处理器、数字信号处理器(Digital Signal Processor,DSP)、专用集成电路(Application Specific Integrated Circuit,ASIC)、现成可编程门阵列(Field-Programmable Gate Array,FPGA)或者其他可编程逻辑器件、分立门或者晶体管逻辑器件、分立硬件组件等。通用处理器可以是微处理器或者该处理器也可以是任何常规的处理器等。The processor 902 may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (Digital Signal Processors, DSPs), and application specific integrated circuits (Application Specific Integrated Circuits). , ASIC), ready-made programmable gate array (Field-Programmable Gate Array, FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor or the like.
本发明实施例的所述负载90通过所述处理器902可以用于实施上述图2或图3所示的本发明各实施例实现的方法,为了便于说明,仅示出了与本发明实施例相关的部分,实现请参照图2或图3所示的本发明各实施例。The load 90 of the embodiment of the present invention can be used by the processor 902 to implement the method implemented by each embodiment of the present invention shown in FIG. 2 or FIG. For related parts, please refer to the embodiments of the present invention shown in FIG. 2 or FIG. 3 for implementation.
在一种实现方式中,存储器901中存储有程序指令,处理器902调用存储器901中的程序指令,当程序指令被执行时,所述处理器902用于:接收可移动平台发送的负载认证请求;基于所述负载认证请求,将所述负载90的负载认证信息发送至所述可移动平台,以使所述可移动平台根据所述负载认证信息确定的所述负载90的功能权限,确定所述负载90与所述可移动平台之间的开放功能。In an implementation manner, the memory 901 stores program instructions, and the processor 902 calls the program instructions in the memory 901. When the program instructions are executed, the processor 902 is configured to: receive a load authentication request sent by a mobile platform Based on the load authentication request, the load authentication information of the load 90 is sent to the movable platform, so that the movable platform determines the function authority of the load 90 determined by the load authentication information The open function between the load 90 and the movable platform.
在一种实现方式中,所述负载认证信息包括防火墙等级证书,所述防火墙 等级证书用于指示与所述开放功能对应的防火墙等级。In an implementation manner, the load authentication information includes a firewall level certificate, and the firewall level certificate is used to indicate the firewall level corresponding to the open function.
在一种实现方式中,所述防火墙等级证书为加密的信息。In an implementation manner, the firewall level certificate is encrypted information.
在一种实现方式中,所述防火墙等级证书是可更新的。In one implementation, the firewall level certificate is updatable.
在一种实现方式中,所述开放功能包括以下中的至少一种:允许所述可移动平台至所述负载90或所述负载90的载体的数据传输功能、允许所述负载90或所述负载90的载体至所述可移动平台的数据传输功能。In an implementation manner, the open function includes at least one of the following: allowing the mobile platform to transfer data to the load 90 or the carrier of the load 90, allowing the load 90 or the load The data transmission function of the carrier of the load 90 to the movable platform.
在一种实现方式中,所述允许所述可移动平台至所述负载90或所述负载90的载体的数据传输功能包括以下中的至少一种:所述可移动平台对所述负载90的载体的控制命令的传输功能;所述可移动平台的定位数据的传输功能;所述可移动平台从地面端获取的多媒体数据的传输功能。In an implementation manner, the data transmission function allowing the movable platform to the load 90 or the carrier of the load 90 includes at least one of the following: The transmission function of the control command of the carrier; the transmission function of the positioning data of the movable platform; the transmission function of the multimedia data obtained by the movable platform from the ground terminal.
在一种实现方式中,所述允许所述负载90或所述负载90的载体至所述可移动平台的数据传输功能包括以下中的至少一种:所述负载90的采集数据的传输功能;所述负载90对所述可移动平台的控制命令的传输功能。In an implementation manner, the data transmission function that allows the load 90 or the carrier of the load 90 to the movable platform includes at least one of the following: a transmission function of collected data of the load 90; The transmission function of the load 90 to the control command of the movable platform.
在一种实现方式中,所述开放功能包括以下中的至少一种:与控制相关的功能、与图像相关的功能、与音频相关的功能、与定位相关的功能。In an implementation manner, the open function includes at least one of the following: a control-related function, an image-related function, an audio-related function, and a positioning-related function.
在一种实现方式中,同一所述开放功能包括不同的功能等级,所述功能等级与确定的所述功能权限相适配。In an implementation manner, the same open function includes different function levels, and the function levels are adapted to the determined function permissions.
在一种实现方式中,所述负载90通过转接装置与所述可移动平台通信连接,所述负载90与所述可移动平台之间的通信交互经由所述转接装置传输。In an implementation manner, the load 90 is communicatively connected with the movable platform through a switching device, and the communication interaction between the load 90 and the movable platform is transmitted via the switching device.
在一种实现方式中,所述可移动平台由第一方提供,所述负载90由第二方提供。In one implementation, the movable platform is provided by a first party, and the load 90 is provided by a second party.
本实施例提供的负载90能够执行前述实施例中负载所执行的步骤,其执行方式和有益效果类似,在这里不再赘述。The load 90 provided in this embodiment can execute the steps executed by the load in the foregoing embodiment, and its execution manner and beneficial effects are similar, and will not be repeated here.
本发明实施例还提供一种计算机可读存储介质,所述计算机可读存储介质中存储有计算机程序指令,计算机程序指令被处理器执行时,用于执行图2或图5所述实施例中可移动平台实现的功能。The embodiment of the present invention also provides a computer-readable storage medium, the computer-readable storage medium stores computer program instructions, and when the computer program instructions are executed by a processor, they are used to execute the Functions implemented by mobile platforms.
本发明实施例还提供一种计算机可读存储介质,所述计算机可读存储介质中存储有计算机程序指令,计算机程序指令被处理器执行时,用于执行图3或图5所述所述实施例中转接装置实现的功能。The embodiment of the present invention also provides a computer-readable storage medium, the computer-readable storage medium stores computer program instructions, and when the computer program instructions are executed by a processor, they are used to execute the implementation described in FIG. 3 or FIG. 5 The function realized by the switching device in the example.
本发明实施例还提供一种计算机可读存储介质,所述计算机可读存储介质中存储有计算机程序指令,计算机程序指令被处理器执行时,用于执行图2或图3所述实施例中负载实现的功能。The embodiment of the present invention also provides a computer-readable storage medium, the computer-readable storage medium stores computer program instructions, and when the computer program instructions are executed by a processor, they are used to execute the Functions implemented by the load.
本领域普通技术人员可以理解实现上述实施例方法中的全部或部分流程,是可以通过计算机程序来指令相关的硬件来完成,所述的程序可存储于一可读取存储介质中,所述程序在执行时,可包括如上述各方法的实施例的流程。其中,所述的存储介质可为磁碟、光盘、只读存储记忆体(Read-Only Memory,ROM)或随机存储记忆体(Random Access Memory,RAM)等。A person of ordinary skill in the art can understand that all or part of the processes in the method of the above-mentioned embodiments can be implemented by instructing relevant hardware through a computer program. The program can be stored in a readable storage medium, and the program can be stored in a readable storage medium. During execution, it may include the procedures of the above-mentioned method embodiments. Wherein, the storage medium may be a magnetic disk, an optical disc, a read-only memory (Read-Only Memory, ROM), or a random access memory (Random Access Memory, RAM), etc.
最后应说明的是:以上各实施例仅用以说明本发明的技术方案,而非对其限制;尽管参照前述各实施例对本发明进行了详细的说明,本领域的普通技术人员应当理解:其依然可以对前述各实施例所记载的技术方案进行修改,或者对其中部分或者全部技术特征进行等同替换;而这些修改或者替换,并不使相应技术方案的本质脱离本发明各实施例技术方案的范围。Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: The technical solutions recorded in the foregoing embodiments can still be modified, or some or all of the technical features can be equivalently replaced; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the technical solutions of the embodiments of the present invention. range.

Claims (119)

  1. 一种负载认证系统,其特征在于,所述负载认证系统包括可移动平台和负载;A load authentication system, characterized in that the load authentication system includes a movable platform and a load;
    所述可移动平台用于在检测到所述负载连接于所述可移动平台时,向所述负载发送负载认证请求;The movable platform is configured to send a load authentication request to the load when it is detected that the load is connected to the movable platform;
    所述负载用于接收所述可移动平台发送的所述负载认证请求,并基于所述负载认证请求,将所述负载的负载认证信息发送至所述可移动平台;The load is used to receive the load authentication request sent by the movable platform, and based on the load authentication request, send load authentication information of the load to the movable platform;
    所述可移动平台还用于接收所述负载发送的所述负载认证信息,并根据所述负载认证信息,确定所述负载的功能权限;The mobile platform is further configured to receive the load authentication information sent by the load, and determine the functional authority of the load according to the load authentication information;
    所述可移动平台还用于根据所述负载的功能权限,确定所述负载与所述可移动平台之间的开放功能。The movable platform is also used to determine the open function between the load and the movable platform according to the functional authority of the load.
  2. 根据权利要求1所述的负载认证系统,其特征在于,所述负载认证信息包括防火墙等级证书;The load authentication system according to claim 1, wherein the load authentication information includes a firewall grade certificate;
    所述可移动平台用于根据所述负载认证信息,确定所述负载的功能权限,包括:The mobile platform is configured to determine the functional authority of the load according to the load authentication information, including:
    根据所述防火墙等级证书,确定所述负载的功能权限。Determine the functional authority of the load according to the firewall level certificate.
  3. 根据权利要求2所述的负载认证系统,其特征在于,所述防火墙等级证书为加密的信息;The load authentication system according to claim 2, wherein the firewall level certificate is encrypted information;
    所述可移动平台用于根据所述防火墙等级证书,确定所述负载的功能权限,包括:The mobile platform is configured to determine the functional authority of the load according to the firewall level certificate, including:
    对所述防火墙等级证书进行解密;Decrypt the firewall level certificate;
    在解密后的防火墙等级证书有效时,根据所述解密后的防火墙等级证书,确定所述负载的功能权限。When the decrypted firewall level certificate is valid, the functional authority of the load is determined according to the decrypted firewall level certificate.
  4. 根据权利要求2所述的负载认证系统,其特征在于,所述可移动平台在用于根据所述防火墙等级证书,确定所述负载的功能权限之前,还用于:The load authentication system according to claim 2, characterized in that, before the mobile platform is used to determine the functional authority of the load according to the firewall level certificate, it is also used to:
    获取策略文件,所述策略文件包括防火墙等级与所述开放功能之间的预设对应关系;Acquiring a policy file, where the policy file includes a preset correspondence between the firewall level and the open function;
    所述可移动平台用于根据所述防火墙等级证书,确定所述负载的功能权限,包括:The mobile platform is configured to determine the functional authority of the load according to the firewall level certificate, including:
    根据所述防火墙等级证书,确定当前的防火墙等级;Determine the current firewall level according to the firewall level certificate;
    根据所述策略文件与所述当前的防火墙等级,确定所述负载的功能权限。Determine the functional authority of the load according to the policy file and the current firewall level.
  5. 根据权利要求4所述的负载认证系统,其特征在于,所述可移动平台获取策略文件的步骤是所述可移动平台在检测到所述负载连接于所述可移动平台时执行的。The load authentication system according to claim 4, wherein the step of acquiring the policy file by the movable platform is executed when the movable platform detects that the load is connected to the movable platform.
  6. 根据权利要求4所述的负载认证系统,其特征在于,所述策略文件是可更新的。The load authentication system according to claim 4, wherein the policy file is updatable.
  7. 根据权利要求2所述的负载认证系统,其特征在于,所述防火墙等级证书是可更新的。The load authentication system according to claim 2, wherein the firewall level certificate is renewable.
  8. 根据权利要求1所述的负载认证系统,其特征在于,所述开放功能包括以下中的至少一种:The load authentication system according to claim 1, wherein the open function includes at least one of the following:
    允许所述可移动平台至所述负载或所述负载的载体的数据传输功能、允许所述负载或所述负载的载体至所述可移动平台的数据传输功能。Allow the data transmission function of the movable platform to the load or the carrier of the load, and allow the data transmission function of the load or the carrier of the load to the movable platform.
  9. 根据权利要求8所述的负载认证系统,其特征在于,所述允许所述可移动平台至所述负载或所述负载的载体的数据传输功能包括以下中的至少一种:The load authentication system according to claim 8, wherein the data transmission function allowing the movable platform to the load or the load carrier comprises at least one of the following:
    所述可移动平台对所述负载的载体的控制命令的传输功能;The transmission function of the control command of the mobile platform to the carrier of the load;
    所述可移动平台的定位数据的传输功能;The transmission function of the positioning data of the movable platform;
    所述可移动平台从地面端获取的多媒体数据的传输功能。The mobile platform has a transmission function of multimedia data obtained from the ground terminal.
  10. 根据权利要求8所述的负载认证系统,其特征在于,允许所述负载或所述负载的载体至所述可移动平台的数据传输功能包括以下中的至少一种:The load authentication system according to claim 8, wherein the data transmission function allowing the load or the carrier of the load to the movable platform comprises at least one of the following:
    所述负载的采集数据的传输功能;The transmission function of the collected data of the load;
    所述负载对所述可移动平台的控制命令的传输功能。The transmission function of the control command of the load to the movable platform.
  11. 根据权利要求1所述的负载认证系统,其特征在于,所述开放功能包括以下中的至少一种:The load authentication system according to claim 1, wherein the open function includes at least one of the following:
    与控制相关的功能、与图像相关的功能、与音频相关的功能、与定位相关的功能。Control-related functions, image-related functions, audio-related functions, and positioning-related functions.
  12. 根据权利要求1所述的负载认证系统,其特征在于,同一所述开放功能包括不同的功能等级,所述功能等级与确定的所述功能权限相适配。The load authentication system according to claim 1, wherein the same open function includes different function levels, and the function levels are adapted to the determined function authority.
  13. 根据权利要求1所述的负载认证系统,其特征在于,所述负载认证系统还包括转接装置,所述负载通过所述转接装置通信连接于所述可移动平台;The load authentication system according to claim 1, wherein the load authentication system further comprises a switching device, and the load is communicatively connected to the movable platform through the switching device;
    所述可移动平台在用于接收所述负载发送的所述负载认证信息之前,还用于:Before the mobile platform is used to receive the load authentication information sent by the load, it is also used to:
    在检测到所述负载连接于所述可移动平台时,获取所述转接装置的转接装置认证信息;When it is detected that the load is connected to the movable platform, acquiring the switching device authentication information of the switching device;
    在根据所述转接装置认证信息判断所述转接装置为有效的转接装置时,触发执行所述向所述负载发送负载认证请求的步骤。When it is determined that the switching device is a valid switching device according to the switching device authentication information, the execution of the step of sending a load authentication request to the load is triggered.
  14. 根据权利要求13所述的负载认证系统,其特征在于,所述转接装置认证信息包括防伪标识。The load authentication system according to claim 13, wherein the authentication information of the switching device includes an anti-counterfeiting identification.
  15. 根据权利要求1所述的负载认证系统,其特征在于,所述负载认证系统还包括转接装置,所述转接装置安装在所述负载的载体上,所述负载的载体用于与所述可移动平台连接;The load authentication system according to claim 1, wherein the load authentication system further comprises a switching device installed on a carrier of the load, and the carrier of the load is used to communicate with the load carrier. Mobile platform connection;
    所述转接装置用于将所述负载的负载认证信息发送至所述可移动平台。The switching device is used to send the load authentication information of the load to the movable platform.
  16. 根据权利要求15所述的负载认证系统,其特征在于,所述转接装置将所述负载的负载认证信息发送至所述可移动平台是在所述转接装置检测到所述负载连接于所述转接装置时执行的。The load authentication system according to claim 15, wherein the transfer device sends the load authentication information of the load to the movable platform when the transfer device detects that the load is connected to the mobile platform. Executed when the switch device is described.
  17. 根据权利要求1所述的负载认证系统,其特征在于,所述负载认证系统还包括转接装置,所述转接装置安装在所述负载的载体上,所述负载的载体用于与所述可移动平台连接;The load authentication system according to claim 1, wherein the load authentication system further comprises a switching device installed on a carrier of the load, and the carrier of the load is used to communicate with the load carrier. Mobile platform connection;
    所述可移动平台在用于根据所述负载的功能权限,确定所述负载与所述可移动平台之间的开放功能之后,还用于向所述转接装置发送配置信息,所述配置信息用于指示基于所述负载的功能权限确定的所述负载与所述可移动平台之间的开放功能;After the mobile platform is used to determine the open function between the load and the mobile platform according to the functional authority of the load, it is also used to send configuration information to the switching device, the configuration information Used to indicate an open function between the load and the movable platform determined based on the function authority of the load;
    所述转接装置还用于接收并存储所述可移动平台发送的配置信息。The switching device is also used for receiving and storing configuration information sent by the movable platform.
  18. 根据权利要求15所述的负载认证系统,其特征在于,所述转接装置在用于将所述负载的负载认证信息发送至所述可移动平台之前,还用于:The load authentication system according to claim 15, wherein before the switching device is used to send the load authentication information of the load to the movable platform, it is further used for:
    接收所述负载发送的第一校验数据;Receiving the first check data sent by the load;
    若所述第一校验数据通过验证,则允许所述负载通过所述转接装置与所述 可移动平台进行通信连接;If the first verification data is verified, allowing the load to communicate with the movable platform through the switching device;
    若所述第一校验数据未通过验证,则禁止所述负载通过所述转接装置与所述可移动平台进行通信连接。If the first verification data fails the verification, the load is prohibited from communicating with the movable platform through the switching device.
  19. 根据权利要求18所述的负载认证系统,其特征在于,所述转接装置还用于发送预设数据至所述负载,以使得所述负载基于所述预设数据和预设密钥生成所述第一校验数据。The load authentication system according to claim 18, wherein the switching device is further configured to send preset data to the load, so that the load generates the data based on the preset data and the preset key. The first check data.
  20. 根据权利要求18所述的负载认证系统,其特征在于,所述转接装置还用于:The load authentication system according to claim 18, wherein the switching device is further used for:
    获取加密后的预设密钥,并对所述加密后的预设密钥进行解密,得到预设密钥;Obtaining the encrypted preset key, and decrypting the encrypted preset key to obtain the preset key;
    根据所述预设密钥和预设数据生成第二校验数据;Generating second verification data according to the preset key and preset data;
    将所述第一校验数据和所述第二校验数据进行对比;Comparing the first verification data with the second verification data;
    若所述第一校验数据和所述第二校验数据相同,则确定所述第一校验数据通过验证;If the first verification data and the second verification data are the same, determining that the first verification data passes verification;
    若所述第一校验数据和所述第二校验数据不相同,则确定所述第一校验数据未通过验证。If the first verification data and the second verification data are not the same, it is determined that the first verification data has not passed verification.
  21. 根据权利要求1所述的负载认证系统,其特征在于,所述可移动平台为第一方提供,所述负载为第二方提供。The load authentication system according to claim 1, wherein the movable platform is provided by a first party, and the load is provided by a second party.
  22. 根据权利要求13所述的负载认证系统,其特征在于,所述转接装置为第一方提供。The load authentication system according to claim 13, wherein the switching device is provided by the first party.
  23. 一种负载认证方法,其特征在于,应用于可移动平台,所述方法包括:A load authentication method, characterized in that it is applied to a movable platform, and the method includes:
    在检测到负载连接于所述可移动平台时,获取所述负载的负载认证信息;When it is detected that the load is connected to the movable platform, acquiring load authentication information of the load;
    根据所述负载认证信息,确定所述负载的功能权限;Determine the functional authority of the load according to the load authentication information;
    根据所述负载的功能权限,确定所述负载与所述可移动平台之间的开放功能。According to the functional authority of the load, an open function between the load and the movable platform is determined.
  24. 根据权利要求23所述的方法,其特征在于,所述负载认证信息包括防火墙等级证书;The method according to claim 23, wherein the load authentication information includes a firewall level certificate;
    所述根据所述负载认证信息,确定所述负载的功能权限,包括:The determining the functional authority of the load according to the load authentication information includes:
    根据所述防火墙等级证书,确定所述负载的功能权限。Determine the functional authority of the load according to the firewall level certificate.
  25. 根据权利要求24所述的方法,其特征在于,所述防火墙等级证书为加密的信息;The method according to claim 24, wherein the firewall level certificate is encrypted information;
    所述根据所述防火墙等级证书,确定所述负载的功能权限,包括:The determining the functional authority of the load according to the firewall level certificate includes:
    对所述防火墙等级证书进行解密;Decrypt the firewall level certificate;
    在解密后的防火墙等级证书有效时,根据所述解密后的防火墙等级证书,确定所述负载的功能权限。When the decrypted firewall level certificate is valid, the functional authority of the load is determined according to the decrypted firewall level certificate.
  26. 根据权利要求24所述的方法,其特征在于,所述根据所述防火墙等级证书,确定所述负载的功能权限之前,所述方法还包括:The method according to claim 24, characterized in that, before determining the functional authority of the load according to the firewall level certificate, the method further comprises:
    获取策略文件,所述策略文件包括防火墙等级与所述开放功能之间的预设对应关系;Acquiring a policy file, where the policy file includes a preset correspondence between the firewall level and the open function;
    所述根据所述防火墙等级证书,确定所述负载的功能权限,包括:The determining the functional authority of the load according to the firewall level certificate includes:
    根据所述防火墙等级证书,确定当前的防火墙等级;Determine the current firewall level according to the firewall level certificate;
    根据所述策略文件与所述当前的防火墙等级,确定所述负载的功能权限。Determine the functional authority of the load according to the policy file and the current firewall level.
  27. 根据权利要求26所述的方法,其特征在于,所述获取策略文件的步骤是在检测到所述负载连接于所述可移动平台时执行的。The method according to claim 26, wherein the step of obtaining the policy file is performed when it is detected that the load is connected to the movable platform.
  28. 根据权利要求26所述的方法,其特征在于,所述策略文件是可更新的。The method according to claim 26, wherein the policy file is updatable.
  29. 根据权利要求24所述的方法,其特征在于,所述防火墙等级证书是可更新的。The method according to claim 24, wherein the firewall level certificate is renewable.
  30. 根据权利要求23所述的方法,其特征在于,所述开放功能包括以下中的至少一种:The method according to claim 23, wherein the open function comprises at least one of the following:
    允许所述可移动平台至所述负载或所述负载的载体的数据传输功能、允许所述负载或所述负载的载体至所述可移动平台的数据传输功能。Allow the data transmission function of the movable platform to the load or the carrier of the load, and allow the data transmission function of the load or the carrier of the load to the movable platform.
  31. 根据权利要求30所述的方法,其特征在于,所述允许所述可移动平台至所述负载或所述负载的载体的数据传输功能包括以下中的至少一种:The method according to claim 30, wherein the data transmission function allowing the movable platform to the load or the carrier of the load comprises at least one of the following:
    所述可移动平台对所述负载的载体的控制命令的传输功能;The transmission function of the control command of the mobile platform to the carrier of the load;
    所述可移动平台的定位数据的传输功能;The transmission function of the positioning data of the movable platform;
    所述可移动平台从地面端获取的多媒体数据的传输功能。The mobile platform has a transmission function of multimedia data obtained from the ground terminal.
  32. 根据权利要求30所述的方法,其特征在于,所述允许所述负载或所 述负载的载体至所述可移动平台的数据传输功能包括以下中的至少一种:The method according to claim 30, wherein the data transmission function that allows the load or the carrier of the load to the movable platform comprises at least one of the following:
    所述负载的采集数据的传输功能;The transmission function of the collected data of the load;
    所述负载对所述可移动平台的控制命令的传输功能。The transmission function of the control command of the load to the movable platform.
  33. 根据权利要求23所述的方法,其特征在于,所述开放功能包括以下中的至少一种:The method according to claim 23, wherein the open function comprises at least one of the following:
    与控制相关的功能、与图像相关的功能、与音频相关的功能、与定位相关的功能。Control-related functions, image-related functions, audio-related functions, and positioning-related functions.
  34. 根据权利要求23所述的方法,其特征在于,同一所述开放功能包括不同的功能等级,所述功能等级与确定的所述功能权限相适配。The method according to claim 23, wherein the same open function includes different function levels, and the function levels are adapted to the determined function permissions.
  35. 根据权利要求23所述的方法,其特征在于,所述负载通过转接装置通信连接于所述可移动平台;The method of claim 23, wherein the load is communicatively connected to the movable platform through a switching device;
    所述根据所述负载的功能权限,确定所述负载与所述可移动平台之间的开放功能之后,所述方法还包括:After determining the open function between the load and the movable platform according to the function authority of the load, the method further includes:
    向所述转接装置发送配置信息,所述配置信息用于指示所述负载与所述可移动平台之间的开放功能。Sending configuration information to the switching device, where the configuration information is used to indicate an open function between the load and the movable platform.
  36. 根据权利要求23所述的方法,其特征在于,所述负载通过转接装置通信连接于所述可移动平台;The method of claim 23, wherein the load is communicatively connected to the movable platform through a switching device;
    所述获取所述负载的负载认证信息之前,所述方法还包括:Before the obtaining the load authentication information of the load, the method further includes:
    获取所述转接装置的转接装置认证信息;Acquiring the switching device authentication information of the switching device;
    在根据所述转接装置认证信息判断所述转接装置为有效的转接装置时,触发执行所述获取所述负载的负载认证信息的步骤。When it is determined that the switching device is a valid switching device according to the switching device authentication information, the execution of the step of obtaining the load authentication information of the load is triggered.
  37. 根据权利要求36所述的方法,其特征在于,所述转接装置认证信息包括防伪标识。The method according to claim 36, wherein the authentication information of the switching device includes an anti-counterfeiting identifier.
  38. 根据权利要求36所述的方法,其特征在于,所述获取所述转接装置的转接装置认证信息是在检测到所述转接装置连接于所述可移动平台时执行的。36. The method according to claim 36, wherein said acquiring the switching device authentication information of the switching device is performed when it is detected that the switching device is connected to the movable platform.
  39. 根据权利要求23所述的方法,其特征在于,所述可移动平台为第一方提供,所述负载为第二方提供。The method according to claim 23, wherein the movable platform is provided by a first party, and the load is provided by a second party.
  40. 一种负载认证方法,其特征在于,应用于转接装置,所述转接装置用 于连接负载与可移动平台,所述方法包括:A load authentication method, characterized in that it is applied to a switching device, the switching device is used to connect a load and a movable platform, and the method includes:
    将所述负载的负载认证信息发送至所述可移动平台,以使所述可移动平台根据所述负载认证信息,确定所述负载的功能权限;Sending load authentication information of the load to the movable platform, so that the movable platform determines the functional authority of the load according to the load authentication information;
    接收并存储所述可移动平台返回的配置信息,所述配置信息用于指示基于所述负载的功能权限确定的所述负载与所述可移动平台之间的开放功能。Receiving and storing configuration information returned by the movable platform, where the configuration information is used to indicate an open function between the load and the movable platform determined based on the functional authority of the load.
  41. 根据权利要求40所述的方法,其特征在于,所述负载认证信息包括防火墙等级证书。The method according to claim 40, wherein the load authentication information includes a firewall level certificate.
  42. 根据权利要求41所述的方法,其特征在于,所述防火墙等级证书是可更新的。The method according to claim 41, wherein the firewall level certificate is renewable.
  43. 根据权利要求40所述的方法,其特征在于,所述开放功能包括以下中的至少一种:The method according to claim 40, wherein the open function comprises at least one of the following:
    允许所述可移动平台至所述负载或所述负载的载体的数据传输功能、允许所述负载或所述负载的载体至所述可移动平台的数据传输功能。Allow the data transmission function of the movable platform to the load or the carrier of the load, and allow the data transmission function of the load or the carrier of the load to the movable platform.
  44. 根据权利要求43所述的方法,其特征在于,所述允许所述可移动平台至所述负载或所述负载的载体的数据传输功能包括以下中的至少一种:The method according to claim 43, wherein the data transmission function allowing the movable platform to the load or the carrier of the load comprises at least one of the following:
    所述可移动平台对所述负载的载体的控制命令的传输功能;The transmission function of the control command of the mobile platform to the carrier of the load;
    所述可移动平台的定位数据的传输功能;The transmission function of the positioning data of the movable platform;
    所述可移动平台从地面端获取的多媒体数据的传输功能。The mobile platform has a transmission function of multimedia data obtained from the ground terminal.
  45. 根据权利要求43所述的方法,其特征在于,所述允许所述负载或所述负载的载体至所述可移动平台的数据传输功能包括以下中的至少一种:The method according to claim 43, wherein the data transmission function that allows the load or the carrier of the load to the movable platform comprises at least one of the following:
    所述负载的采集数据的传输功能;The transmission function of the collected data of the load;
    所述负载对所述可移动平台的控制命令的传输功能。The transmission function of the control command of the load to the movable platform.
  46. 根据权利要求40所述的方法,其特征在于,所述开放功能包括以下中的至少一种:The method according to claim 40, wherein the open function comprises at least one of the following:
    与控制相关的功能、与图像相关的功能、与音频相关的功能、与定位相关的功能。Control-related functions, image-related functions, audio-related functions, and positioning-related functions.
  47. 根据权利要求40所述的方法,其特征在于,同一所述开放功能包括不同的功能等级,所述功能等级与确定的所述功能权限相适配。The method according to claim 40, wherein the same open function includes different function levels, and the function levels are adapted to the determined function permissions.
  48. 根据权利要求40所述的方法,其特征在于,所述将所述负载的负载 认证信息发送至所述可移动平台是在检测到所述负载连接于所述转接装置时执行的。The method of claim 40, wherein the sending the load authentication information of the load to the movable platform is performed when it is detected that the load is connected to the switching device.
  49. 根据权利要求40所述的方法,其特征在于,所述将所述负载的负载认证信息发送至所述可移动平台之前,所述方法还包括:The method according to claim 40, characterized in that, before the sending the load authentication information of the load to the movable platform, the method further comprises:
    将所述转接装置的转接装置认证信息发送至所述可移动平台;Sending the switching device authentication information of the switching device to the movable platform;
    在所述可移动平台根据所述转接装置认证信息判断所述转接装置为有效的转接装置时,触发执行所述将所述负载的认证信息发送至所述可移动平台的步骤。When the movable platform determines that the switching device is a valid switching device according to the authentication information of the switching device, trigger execution of the step of sending the authentication information of the load to the movable platform.
  50. 根据权利要求49述的方法,其特征在于,所述转接装置认证信息包括防伪标识。The method according to claim 49, wherein said switching device authentication information includes an anti-counterfeiting identification.
  51. 根据权利要求40所述的方法,其特征在于,所述将所述转接装置的转接装置认证信息发送至所述可移动平台是在检测到所述转接装置连接于所述可移动平台时执行的。The method according to claim 40, wherein the sending the switching device authentication information of the switching device to the movable platform is when it is detected that the switching device is connected to the movable platform Executed at the time.
  52. 根据权利要求40所述的方法,其特征在于,所述将所述负载的负载认证信息发送至所述可移动平台之前,所述方法还包括:The method according to claim 40, characterized in that, before the sending the load authentication information of the load to the movable platform, the method further comprises:
    接收所述负载发送的第一校验数据;Receiving the first check data sent by the load;
    若所述第一校验数据通过验证,则允许所述负载通过所述转接装置与所述可移动平台通信连接。If the first verification data passes the verification, the load is allowed to communicate with the movable platform through the switching device.
  53. 根据权利要求52所述的方法,其特征在于,所述方法还包括:The method of claim 52, wherein the method further comprises:
    若所述第一校验数据未通过验证,则禁止所述负载通过所述转接装置与所述可移动平台通信连接。If the first verification data fails the verification, the load is prohibited from communicating with the movable platform through the switching device.
  54. 根据权利要求52或53所述的方法,其特征在于,所述方法还包括:The method according to claim 52 or 53, wherein the method further comprises:
    发送预设数据至所述负载,以使得所述负载基于所述预设数据和预设密钥生成所述第一校验数据。Sending preset data to the load, so that the load generates the first verification data based on the preset data and a preset key.
  55. 根据权利要求52或53所述的方法,其特征在于,所述方法还包括:The method according to claim 52 or 53, wherein the method further comprises:
    获取加密后的预设密钥,并对所述加密的预设密钥解密,得到预设密钥;Obtaining the encrypted preset key, and decrypting the encrypted preset key to obtain the preset key;
    根据所述预设密钥和预设数据生成第二校验数据;Generating second verification data according to the preset key and preset data;
    将所述第一校验数据和所述第二校验数据进行对比;Comparing the first verification data with the second verification data;
    若所述第一校验数据和所述第二校验数据相同,则确定所述第一校验数据 通过验证;If the first verification data and the second verification data are the same, it is determined that the first verification data passes verification;
    若所述第一校验数据和所述第二校验数据不相同,则确定所述第一校验数据未通过验证。If the first verification data and the second verification data are not the same, it is determined that the first verification data has not passed verification.
  56. 根据权利要求40所述的方法,其特征在于,所述转接装置安装在所述负载的载体上,所述负载的载体用于与所述可移动平台连接。The method of claim 40, wherein the adapter device is installed on a carrier of the load, and the carrier of the load is used to connect with the movable platform.
  57. 根据权利要求40所述的方法,其特征在于,所述转接装置以及所述可移动平台为第一方提供,所述负载为第二方提供。The method of claim 40, wherein the switching device and the movable platform are provided by a first party, and the load is provided by a second party.
  58. 一种负载认证方法,其特征在于,应用于负载,所述负载存储有所述负载的负载认证信息,所述方法包括:A load authentication method, characterized in that it is applied to a load, the load stores load authentication information of the load, and the method includes:
    接收可移动平台发送的负载认证请求;Receive load authentication request sent by the mobile platform;
    基于所述负载认证请求,将所述负载的负载认证信息发送至所述可移动平台,以使所述可移动平台根据所述负载认证信息确定所述负载的功能权限,确定所述负载与所述可移动平台之间的开放功能。Based on the load authentication request, the load authentication information of the load is sent to the movable platform, so that the movable platform determines the functional authority of the load according to the load authentication information, and determines the relationship between the load and the load. Describes the open functions between the movable platforms.
  59. 根据权利要求58所述的方法,其特征在于,所述负载认证信息包括防火墙等级证书,所述防火墙等级证书用于指示与所述开放功能对应的防火墙等级。The method according to claim 58, wherein the load authentication information includes a firewall level certificate, and the firewall level certificate is used to indicate a firewall level corresponding to the open function.
  60. 根据权利要求59所述的方法,其特征在于,所述防火墙等级证书为加密的信息。The method according to claim 59, wherein the firewall level certificate is encrypted information.
  61. 根据权利要求59或60所述的方法,其特征在于,所述防火墙等级证书是可更新的。The method according to claim 59 or 60, wherein the firewall level certificate is renewable.
  62. 根据权利要求58所述的方法,其特征在于,所述开放功能包括以下中的至少一种:The method according to claim 58, wherein the open function comprises at least one of the following:
    允许所述可移动平台至所述负载或所述负载的载体的数据传输功能、允许所述负载或所述负载的载体至所述可移动平台的数据传输功能。Allow the data transmission function of the movable platform to the load or the carrier of the load, and allow the data transmission function of the load or the carrier of the load to the movable platform.
  63. 根据权利要求62所述的方法,其特征在于,所述允许所述可移动平台至所述负载或所述负载的载体的数据传输功能包括以下中的至少一种:The method according to claim 62, wherein the data transmission function allowing the movable platform to the load or the carrier of the load comprises at least one of the following:
    所述可移动平台对所述负载的载体的控制命令的传输功能;The transmission function of the control command of the mobile platform to the carrier of the load;
    所述可移动平台的定位数据的传输功能;The transmission function of the positioning data of the movable platform;
    所述可移动平台从地面端获取的多媒体数据的传输功能。The mobile platform has a transmission function of multimedia data obtained from the ground terminal.
  64. 根据权利要求62所述的方法,其特征在于,所述允许所述负载或所述负载的载体至所述可移动平台的数据传输功能包括以下中的至少一种:The method according to claim 62, wherein the data transmission function that allows the load or the carrier of the load to the movable platform comprises at least one of the following:
    所述负载的采集数据的传输功能;The transmission function of the collected data of the load;
    所述负载对所述可移动平台的控制命令的传输功能。The transmission function of the control command of the load to the movable platform.
  65. 根据权利要求58所述的方法,其特征在于,所述开放功能包括以下中的至少一种:The method according to claim 58, wherein the open function comprises at least one of the following:
    与控制相关的功能、与图像相关的功能、与音频相关的功能、与定位相关的功能。Control-related functions, image-related functions, audio-related functions, and positioning-related functions.
  66. 根据权利要求58所述的方法,其特征在于,同一所述开放功能包括不同的功能等级,所述功能等级与确定的所述功能权限相适配。The method according to claim 58, wherein the same open function includes different function levels, and the function levels are adapted to the determined function permissions.
  67. 根据权利要求58所述的方法,其特征在于,所述负载通过转接装置与所述可移动平台通信连接,所述负载与所述可移动平台之间的通信交互经由所述转接装置传输。The method according to claim 58, wherein the load is communicatively connected with the movable platform through a switching device, and the communication interaction between the load and the movable platform is transmitted through the switching device .
  68. 根据权利要求58所述的方法,其特征在于,所述可移动平台由第一方提供,所述负载由第二方提供。The method of claim 58, wherein the movable platform is provided by a first party, and the load is provided by a second party.
  69. 一种可移动平台,其特征在于,所述可移动平台包括存储器和处理器,所述存储器和所述处理器相互连接,其中:A movable platform, characterized in that, the movable platform includes a memory and a processor, and the memory and the processor are connected to each other, wherein:
    所述存储器,用于存储计算机程序,所述计算机程序包括程序指令;The memory is used to store a computer program, and the computer program includes program instructions;
    所述处理器调用所述程序指令,用于执行如下步骤:The processor calls the program instructions to execute the following steps:
    在检测到负载连接于所述可移动平台时,获取所述负载的负载认证信息;When it is detected that the load is connected to the movable platform, acquiring load authentication information of the load;
    根据所述负载认证信息,确定所述负载的功能权限;Determine the functional authority of the load according to the load authentication information;
    根据所述负载的功能权限,确定所述负载与所述可移动平台之间的开放功能。According to the functional authority of the load, an open function between the load and the movable platform is determined.
  70. 根据权利要求69所述的可移动平台,其特征在于,所述负载认证信息包括防火墙等级证书;The mobile platform according to claim 69, wherein the load authentication information includes a firewall level certificate;
    所述处理器在根据所述负载认证信息,确定所述负载的功能权限时,具体用于执行如下步骤:When the processor determines the functional authority of the load according to the load authentication information, it is specifically configured to execute the following steps:
    根据所述防火墙等级证书,确定所述负载的功能权限。Determine the functional authority of the load according to the firewall level certificate.
  71. 根据权利要求70所述的可移动平台,其特征在于,所述防火墙等级 证书为加密的信息;The mobile platform of claim 70, wherein the firewall level certificate is encrypted information;
    所述处理器在根据所述负载认证信息,确定所述负载的功能权限时,具体用于执行如下步骤:When the processor determines the functional authority of the load according to the load authentication information, it is specifically configured to execute the following steps:
    对所述防火墙等级证书进行解密;Decrypt the firewall level certificate;
    在解密后的防火墙等级证书有效时,根据所述解密后的防火墙等级证书,确定所述负载的功能权限。When the decrypted firewall level certificate is valid, the functional authority of the load is determined according to the decrypted firewall level certificate.
  72. 根据权利要求70所述的可移动平台,其特征在于,所述处理器在根据所述防火墙等级证书,确定所述负载的功能权限之前,还用于执行如下步骤:The mobile platform according to claim 70, wherein the processor is further configured to perform the following steps before determining the functional authority of the load according to the firewall level certificate:
    获取策略文件,所述策略文件包括防火墙等级与所述开放功能之间的预设对应关系;Acquiring a policy file, where the policy file includes a preset correspondence between the firewall level and the open function;
    所述处理器在根据所述防火墙等级证书,确定所述负载的功能权限时,所述处理器还具体用于执行如下步骤:When the processor determines the functional authority of the load according to the firewall level certificate, the processor is further specifically configured to perform the following steps:
    根据所述防火墙等级证书,确定当前的防火墙等级;Determine the current firewall level according to the firewall level certificate;
    根据所述策略文件与所述当前的防火墙等级,确定所述负载的功能权限。Determine the functional authority of the load according to the policy file and the current firewall level.
  73. 根据权利要求72所述的可移动平台,其特征在于,所述处理器获取策略文件的步骤是在检测到所述负载连接于所述可移动平台时执行的。The movable platform according to claim 72, wherein the step of obtaining the policy file by the processor is executed when it is detected that the load is connected to the movable platform.
  74. 根据权利要求72所述的可移动平台,其特征在于,所述策略文件是可更新的。The mobile platform according to claim 72, wherein the policy file is updatable.
  75. 根据权利要求70所述的可移动平台,其特征在于,所述防火墙等级证书是可更新的。The mobile platform according to claim 70, wherein the firewall level certificate is renewable.
  76. 根据权利要求69所述的可移动平台,其特征在于,所述开放功能包括以下中的至少一种:The mobile platform according to claim 69, wherein the open function comprises at least one of the following:
    允许所述可移动平台至所述负载或所述负载的载体的数据传输功能、允许所述负载或所述负载的载体至所述可移动平台的数据传输功能。Allow the data transmission function of the movable platform to the load or the carrier of the load, and allow the data transmission function of the load or the carrier of the load to the movable platform.
  77. 根据权利要求76所述的可移动平台,其特征在于,所述允许所述可移动平台至所述负载或所述负载的载体的数据传输功能包括以下中的至少一种:The movable platform according to claim 76, wherein the data transmission function allowing the movable platform to the load or the carrier of the load comprises at least one of the following:
    所述可移动平台对所述负载的载体的控制命令的传输功能;The transmission function of the control command of the mobile platform to the carrier of the load;
    所述可移动平台的定位数据的传输功能;The transmission function of the positioning data of the movable platform;
    所述可移动平台从地面端获取的多媒体数据的传输功能。The mobile platform has a transmission function of multimedia data obtained from the ground terminal.
  78. 根据权利要求76所述的可移动平台,其特征在于,所述允许所述负载或所述负载的载体至所述可移动平台的数据传输功能包括以下中的至少一种:The movable platform according to claim 76, wherein the data transmission function that allows the load or the carrier of the load to the movable platform comprises at least one of the following:
    所述负载的采集数据的传输功能;The transmission function of the collected data of the load;
    所述负载对所述可移动平台的控制命令的传输功能。The transmission function of the control command of the load to the movable platform.
  79. 根据权利要求69所述的可移动平台,其特征在于,所述开放功能包括以下中的至少一种:The mobile platform according to claim 69, wherein the open function comprises at least one of the following:
    与控制相关的功能、与图像相关的功能、与音频相关的功能、与定位相关的功能。Control-related functions, image-related functions, audio-related functions, and positioning-related functions.
  80. 根据权利要求69所述的可移动平台,其特征在于,同一所述开放功能包括不同的功能等级,所述功能等级与确定的所述功能权限相适配。The mobile platform according to claim 69, wherein the same open function includes different function levels, and the function levels are adapted to the determined function permissions.
  81. 根据权利要求69所述的可移动平台,其特征在于,所述负载通过转接装置通信连接于所述可移动平台,所述处理器还用于执行如下步骤:The movable platform according to claim 69, wherein the load is communicatively connected to the movable platform through a switching device, and the processor is further configured to perform the following steps:
    向所述转接装置发送配置信息,所述配置信息用于指示所述负载与所述可移动平台之间的开放功能。Sending configuration information to the switching device, where the configuration information is used to indicate an open function between the load and the movable platform.
  82. 根据权利要求69所述的可移动平台,其特征在于,所述负载通过转接装置通信连接于所述可移动平台;The movable platform of claim 69, wherein the load is communicatively connected to the movable platform through a switching device;
    所述处理器在获取所述负载的负载认证信息之前,还用于执行如下步骤:Before acquiring the load authentication information of the load, the processor is further configured to perform the following steps:
    获取所述转接装置的转接装置认证信息;Acquiring the switching device authentication information of the switching device;
    在根据所述转接装置认证信息判断所述转接装置为有效的转接装置时,触发执行所述获取所述负载的负载认证信息的步骤。When it is determined that the switching device is a valid switching device according to the switching device authentication information, the execution of the step of obtaining the load authentication information of the load is triggered.
  83. 根据权利要求82所述的可移动平台,其特征在于,所述转接装置认证信息包括防伪标识。The movable platform according to claim 82, wherein the authentication information of the switching device includes an anti-counterfeiting identifier.
  84. 根据权利要求82所述的可移动平台,其特征在于,所述处理器获取转接装置的转接装置认证信息是在检测到所述转接装置连接于所述可移动平台时执行的。The movable platform of claim 82, wherein the processor obtains the switching device authentication information of the switching device when it is detected that the switching device is connected to the movable platform.
  85. 根据权利要求69所述的可移动平台,其特征在于,所述可移动平台为第一方提供,所述负载为第二方提供。The movable platform of claim 69, wherein the movable platform is provided by a first party, and the load is provided by a second party.
  86. 一种转接装置,其特征在于,所述转接装置包括存储器和处理器,所述存储器和所述处理器相互连接,其中:A switching device, characterized in that the switching device includes a memory and a processor, the memory and the processor are connected to each other, wherein:
    所述存储器,用于存储计算机程序,所述计算机程序包括程序指令;The memory is used to store a computer program, and the computer program includes program instructions;
    所述处理器调用所述程序指令,用于执行如下步骤:The processor calls the program instructions to execute the following steps:
    将所述负载的负载认证信息发送至所述可移动平台,以使所述可移动平台根据所述负载认证信息,确定所述负载的功能权限;Sending load authentication information of the load to the movable platform, so that the movable platform determines the functional authority of the load according to the load authentication information;
    接收并存储所述可移动平台返回的配置信息,所述配置信息用于指示基于所述负载的功能权限确定的所述负载与所述可移动平台之间的开放功能。Receiving and storing configuration information returned by the movable platform, where the configuration information is used to indicate an open function between the load and the movable platform determined based on the functional authority of the load.
  87. 根据权利要求86所述的转接装置,其特征在于,所述负载认证信息包括防火墙等级证书。The switching device according to claim 86, wherein the load authentication information includes a firewall level certificate.
  88. 根据权利要求87所述的转接装置,其特征在于,所述防火墙等级证书是可更新的。The switching device according to claim 87, wherein the firewall level certificate is renewable.
  89. 根据权利要求86所述的转接装置,其特征在于,所述开放功能包括以下中的至少一种:The switching device according to claim 86, wherein the open function comprises at least one of the following:
    允许所述可移动平台至所述负载或所述负载的载体的数据传输功能、允许所述负载或所述负载的载体至所述可移动平台的数据传输功能。Allow the data transmission function of the movable platform to the load or the carrier of the load, and allow the data transmission function of the load or the carrier of the load to the movable platform.
  90. 根据权利要求89所述的转接装置,其特征在于,所述允许所述可移动平台至所述负载或所述负载的载体的数据传输功能包括以下中的至少一种:The switching device according to claim 89, wherein the data transmission function allowing the movable platform to the load or the carrier of the load comprises at least one of the following:
    所述可移动平台对所述负载的载体的控制命令的传输功能;The transmission function of the control command of the mobile platform to the carrier of the load;
    所述可移动平台的定位数据的传输功能;The transmission function of the positioning data of the movable platform;
    所述可移动平台从地面端获取的多媒体数据的传输功能。The mobile platform has a transmission function of multimedia data obtained from the ground terminal.
  91. 根据权利要求89所述的转接装置,其特征在于,所述允许所述负载或所述负载的载体至所述可移动平台的数据传输功能包括以下中的至少一种:The switching device according to claim 89, wherein the data transmission function that allows the load or the carrier of the load to the movable platform comprises at least one of the following:
    所述负载的采集数据的传输功能;The transmission function of the collected data of the load;
    所述负载对所述可移动平台的控制命令的传输功能。The transmission function of the control command of the load to the movable platform.
  92. 根据权利要求86所述的转接装置,其特征在于,所述开放功能包括以下中的至少一种:The switching device according to claim 86, wherein the open function comprises at least one of the following:
    与控制相关的功能、与图像相关的功能、与音频相关的功能、与定位相关的功能。Control-related functions, image-related functions, audio-related functions, and positioning-related functions.
  93. 根据权利要求86所述的转接装置,其特征在于,同一所述开放功能包括不同的功能等级,所述功能等级与确定的所述功能权限相适配。The switching device according to claim 86, wherein the same open function includes different function levels, and the function levels are adapted to the determined function permissions.
  94. 根据权利要求86所述的转接装置,其特征在于,所述处理器将所述负载的负载认证信息发送至所述可移动平台是在检测到所述负载连接于所述转接装置时执行的。The switching device according to claim 86, wherein the processor sending the load authentication information of the load to the movable platform is executed when it is detected that the load is connected to the switching device of.
  95. 根据权利要求86所述的转接装置,其特征在于,所述处理器在将所述负载的负载认证信息发送至所述可移动平台之前,还用于执行如下步骤:The switching device according to claim 86, wherein the processor is further configured to perform the following steps before sending the load authentication information of the load to the movable platform:
    将所述转接装置的转接装置认证信息发送至所述可移动平台;Sending the switching device authentication information of the switching device to the movable platform;
    在所述可移动平台根据所述转接装置认证信息判断所述转接装置为有效的转接装置时,触发执行所述将所述负载的认证信息发送至所述可移动平台的步骤。When the movable platform determines that the switching device is a valid switching device according to the authentication information of the switching device, trigger execution of the step of sending the authentication information of the load to the movable platform.
  96. 根据权利要求95所述的转接装置,其特征在于,所述转接装置认证信息包括防伪标识。The switching device of claim 95, wherein the authentication information of the switching device includes an anti-counterfeiting identifier.
  97. 根据权利要求86所述的转接装置,其特征在于,所述处理器将所述转接装置的转接装置认证信息发送至所述可移动平台是在检测到所述转接装置连接于所述可移动平台时执行的。The adapter device of claim 86, wherein the processor sends the adapter device authentication information of the adapter device to the movable platform when it detects that the adapter device is connected to the adapter device. Executed when the mobile platform is described.
  98. 根据权利要求86所述的转接装置,其特征在于,所述处理器在将所述负载的负载认证信息发送至所述可移动平台之前,所述处理器还用于执行如下步骤:The switching device according to claim 86, wherein before the processor sends the load authentication information of the load to the movable platform, the processor is further configured to perform the following steps:
    接收所述负载发送的第一校验数据;Receiving the first check data sent by the load;
    若所述第一校验数据通过验证,则允许所述负载通过所述转接装置与所述可移动平台通信连接。If the first verification data passes the verification, the load is allowed to communicate with the movable platform through the switching device.
  99. 根据权利要求98所述的转接装置,其特征在于,所述处理器还用于执行如下步骤:The switching device according to claim 98, wherein the processor is further configured to execute the following steps:
    若所述第一校验数据未通过验证,则禁止所述负载通过所述转接装置与所述可移动平台通信连接。If the first verification data fails the verification, the load is prohibited from communicating with the movable platform through the switching device.
  100. 根据权利要求98或99所述的转接装置,其特征在于,所述处理器还用于执行如下步骤:The switching device according to claim 98 or 99, wherein the processor is further configured to execute the following steps:
    发送预设数据至所述负载,以使得所述负载基于所述预设数据和预设密钥 生成所述第一校验数据。Sending preset data to the load, so that the load generates the first verification data based on the preset data and a preset key.
  101. 根据权利要求98或99所述的转接装置,其特征在于,所述处理器还用于执行如下步骤:The switching device according to claim 98 or 99, wherein the processor is further configured to execute the following steps:
    获取加密后的预设密钥,并对所述加密的预设密钥解密,得到预设密钥;Obtaining the encrypted preset key, and decrypting the encrypted preset key to obtain the preset key;
    根据所述预设密钥和预设数据生成第二校验数据;Generating second verification data according to the preset key and preset data;
    将所述第一校验数据和所述第二校验数据进行对比;Comparing the first verification data with the second verification data;
    若所述第一校验数据和所述第二校验数据相同,则确定所述第一校验数据通过验证;If the first verification data and the second verification data are the same, determining that the first verification data passes verification;
    若所述第一校验数据和所述第二校验数据不相同,则确定所述第一校验数据未通过验证。If the first verification data and the second verification data are not the same, it is determined that the first verification data has not passed verification.
  102. 根据权利要求86所述的转接装置,其特征在于,所述转接装置安装在所述负载的载体上,所述负载的载体用于与所述可移动平台连接。The adapter device of claim 86, wherein the adapter device is installed on a carrier of the load, and the carrier of the load is used to connect with the movable platform.
  103. 根据权利要求86所述的转接装置,其特征在于,所述转接装置以及所述可移动平台为第一方提供,所述负载为第二方提供。The switching device of claim 86, wherein the switching device and the movable platform are provided by a first party, and the load is provided by a second party.
  104. 一种负载,其特征在于,所述负载包括存储器和处理器,所述存储器和所述处理器相互连接,其中:A load, characterized in that the load includes a memory and a processor, and the memory and the processor are connected to each other, wherein:
    所述存储器,用于存储计算机程序,所述计算机程序包括程序指令;The memory is used to store a computer program, and the computer program includes program instructions;
    所述处理器调用所述程序指令,用于执行如下步骤:The processor calls the program instructions to execute the following steps:
    接收可移动平台发送的负载认证请求;Receive load authentication request sent by the mobile platform;
    基于所述负载认证请求,将所述负载的负载认证信息发送至所述可移动平台,以使所述可移动平台根据所述负载认证信息确定所述负载的功能权限,确定所述负载与所述可移动平台之间的开放功能。Based on the load authentication request, the load authentication information of the load is sent to the movable platform, so that the movable platform determines the functional authority of the load according to the load authentication information, and determines the relationship between the load and the load. Describes the open functions between the movable platforms.
  105. 根据权利要求104所述的负载,其特征在于,所述负载认证信息包括防火墙等级证书,所述防火墙等级证书用于指示与所述开放功能对应的防火墙等级。The load according to claim 104, wherein the load authentication information includes a firewall level certificate, and the firewall level certificate is used to indicate a firewall level corresponding to the open function.
  106. 根据权利要求104所述的负载,其特征在于,所述防火墙等级证书为加密的信息。The load according to claim 104, wherein the firewall level certificate is encrypted information.
  107. 根据权利要求105或106所述的负载,其特征在于,所述防火墙等级证书是可更新的。The load according to claim 105 or 106, wherein the firewall level certificate is updatable.
  108. 根据权利要求104所述的负载,其特征在于,所述开放功能包括以下中的至少一种:The load according to claim 104, wherein the open function comprises at least one of the following:
    允许所述可移动平台至所述负载或所述负载的载体的数据传输功能、允许所述负载或所述负载的载体至所述可移动平台的数据传输功能。Allow the data transmission function of the movable platform to the load or the carrier of the load, and allow the data transmission function of the load or the carrier of the load to the movable platform.
  109. 根据权利要求108所述的负载,其特征在于,所述允许所述可移动平台至所述负载或所述负载的载体的数据传输功能包括以下中的至少一种:The load according to claim 108, wherein the data transmission function that allows the movable platform to the load or the carrier of the load comprises at least one of the following:
    所述可移动平台对所述负载的载体的控制命令的传输功能;The transmission function of the control command of the mobile platform to the carrier of the load;
    所述可移动平台的定位数据的传输功能;The transmission function of the positioning data of the movable platform;
    所述可移动平台从地面端获取的多媒体数据的传输功能。The mobile platform has a transmission function of multimedia data obtained from the ground terminal.
  110. 根据权利要求108所述的负载,其特征在于,所述允许所述负载或所述负载的载体至所述可移动平台的数据传输功能包括以下中的至少一种:The load according to claim 108, wherein the data transmission function that allows the load or the carrier of the load to the movable platform comprises at least one of the following:
    所述负载的采集数据的传输功能;The transmission function of the collected data of the load;
    所述负载对所述可移动平台的控制命令的传输功能。The transmission function of the control command of the load to the movable platform.
  111. 根据权利要求104所述的负载,其特征在于,所述开放功能包括以下中的至少一种:The load according to claim 104, wherein the open function comprises at least one of the following:
    与控制相关的功能、与图像相关的功能、与音频相关的功能、与定位相关的功能。Control-related functions, image-related functions, audio-related functions, and positioning-related functions.
  112. 根据权利要求104所述的负载,其特征在于,同一所述开放功能包括不同的功能等级,所述功能等级与确定的所述功能权限相适配。The load according to claim 104, wherein the same open function includes different function levels, and the function levels are adapted to the determined function permissions.
  113. 根据权利要求204所述的负载,其特征在于,所述负载通过转接装置与所述可移动平台通信连接,所述负载与所述可移动平台之间的通信交互经由所述转接装置传输。The load according to claim 204, wherein the load is communicatively connected with the movable platform through a switching device, and the communication interaction between the load and the movable platform is transmitted through the switching device .
  114. 根据权利要求104所述的负载,其特征在于,所述可移动平台由第一方提供,所述负载由第二方提供。The load according to claim 104, wherein the movable platform is provided by a first party, and the load is provided by a second party.
  115. 一种载体组件,其特征在于,包括载体和权利要求86至103中任一项所述的转接装置,所述转接装置设于所述载体上。A carrier assembly, characterized in that it comprises a carrier and the adapter device according to any one of claims 86 to 103, and the adapter device is provided on the carrier.
  116. 一种可移动平台组件,其特征在于,包括69至85中任一项所述的可移动平台和权利要求115所述的载体组件,所述载体组件与所述可移动平台连接。A movable platform assembly, characterized by comprising the movable platform according to any one of 69 to 85 and the carrier assembly according to claim 115, and the carrier assembly is connected with the movable platform.
  117. 一种计算机可读存储介质,其特征在于,所述计算机可读存储介质上存储有计算机程序,所述计算机程序在被执行时,实现如权利要求23至39任一项所述的负载认证方法。A computer-readable storage medium, wherein a computer program is stored on the computer-readable storage medium, and the computer program, when executed, implements the load authentication method according to any one of claims 23 to 39 .
  118. 一种计算机可读存储介质,其特征在于,所述计算机可读存储介质上存储有计算机程序,所述计算机程序在被执行时,实现如权利要求40至57任一项所述的负载认证方法。A computer-readable storage medium, characterized in that a computer program is stored on the computer-readable storage medium, and the computer program, when executed, implements the load authentication method according to any one of claims 40 to 57 .
  119. 一种计算机可读存储介质,其特征在于,所述计算机可读存储介质上存储有计算机程序,所述计算机程序在被执行时,实现如权利要求58至68任一项所述的负载认证方法。A computer-readable storage medium, characterized in that a computer program is stored on the computer-readable storage medium, and the computer program, when executed, implements the load authentication method according to any one of claims 58 to 68 .
PCT/CN2019/130967 2019-12-31 2019-12-31 Load authentication method and system, mobile platform, load, and transfer device WO2021134712A1 (en)

Priority Applications (2)

Application Number Priority Date Filing Date Title
PCT/CN2019/130967 WO2021134712A1 (en) 2019-12-31 2019-12-31 Load authentication method and system, mobile platform, load, and transfer device
CN201980095977.7A CN113767605A (en) 2019-12-31 2019-12-31 Load authentication method and system, movable platform, load and switching device

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2019/130967 WO2021134712A1 (en) 2019-12-31 2019-12-31 Load authentication method and system, mobile platform, load, and transfer device

Publications (1)

Publication Number Publication Date
WO2021134712A1 true WO2021134712A1 (en) 2021-07-08

Family

ID=76686322

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2019/130967 WO2021134712A1 (en) 2019-12-31 2019-12-31 Load authentication method and system, mobile platform, load, and transfer device

Country Status (2)

Country Link
CN (1) CN113767605A (en)
WO (1) WO2021134712A1 (en)

Citations (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104936180A (en) * 2015-06-26 2015-09-23 陈昊 Authentication system and method for providing authentication service specific to unmanned aerial vehicle and ground station
CN107040560A (en) * 2016-02-04 2017-08-11 阿里巴巴集团控股有限公司 A kind of method for processing business and device based on business platform
CN107054677A (en) * 2015-12-24 2017-08-18 松下电器(美国)知识产权公司 Unmanned vehicle and its control method
CN107409174A (en) * 2015-03-31 2017-11-28 深圳市大疆创新科技有限公司 System and method for the operation of control unmanned vehicle
US9875592B1 (en) * 2016-08-30 2018-01-23 International Business Machines Corporation Drone used for authentication and authorization for restricted access via an electronic lock
CN109064599A (en) * 2018-07-27 2018-12-21 新华三技术有限公司 Purview certification method and device
US20190199534A1 (en) * 2017-12-27 2019-06-27 International Business Machines Corporation Managing in-flight transfer of parcels using blockchain authentication
CN109995719A (en) * 2017-12-29 2019-07-09 中移(杭州)信息技术有限公司 A kind of unmanned plane authentication method, system, unmanned plane supervising platform and the first equipment
CN110326033A (en) * 2017-02-20 2019-10-11 三星电子株式会社 For controlling the electronic device of unmanned vehicle and operating the method for the electronic device

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US9651944B2 (en) * 2015-03-22 2017-05-16 Microsoft Technology Licensing, Llc Unmanned aerial vehicle piloting authorization
WO2019178828A1 (en) * 2018-03-23 2019-09-26 深圳市大疆创新科技有限公司 Control method, apparatus, and system

Patent Citations (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107409174A (en) * 2015-03-31 2017-11-28 深圳市大疆创新科技有限公司 System and method for the operation of control unmanned vehicle
CN104936180A (en) * 2015-06-26 2015-09-23 陈昊 Authentication system and method for providing authentication service specific to unmanned aerial vehicle and ground station
CN107054677A (en) * 2015-12-24 2017-08-18 松下电器(美国)知识产权公司 Unmanned vehicle and its control method
CN107040560A (en) * 2016-02-04 2017-08-11 阿里巴巴集团控股有限公司 A kind of method for processing business and device based on business platform
US9875592B1 (en) * 2016-08-30 2018-01-23 International Business Machines Corporation Drone used for authentication and authorization for restricted access via an electronic lock
CN110326033A (en) * 2017-02-20 2019-10-11 三星电子株式会社 For controlling the electronic device of unmanned vehicle and operating the method for the electronic device
US20190199534A1 (en) * 2017-12-27 2019-06-27 International Business Machines Corporation Managing in-flight transfer of parcels using blockchain authentication
CN109995719A (en) * 2017-12-29 2019-07-09 中移(杭州)信息技术有限公司 A kind of unmanned plane authentication method, system, unmanned plane supervising platform and the first equipment
CN109064599A (en) * 2018-07-27 2018-12-21 新华三技术有限公司 Purview certification method and device

Also Published As

Publication number Publication date
CN113767605A (en) 2021-12-07

Similar Documents

Publication Publication Date Title
JP7018109B2 (en) Secure provisioning and management of equipment
JP6262278B2 (en) Method and apparatus for storage and computation of access control client
US9032493B2 (en) Connecting mobile devices, internet-connected vehicles, and cloud services
CN112260995B (en) Access authentication method, device and server
US9268545B2 (en) Connecting mobile devices, internet-connected hosts, and cloud services
EP2973188B1 (en) Secondary device as key for authorizing access to resources
KR102540090B1 (en) Electronic device and method for managing electronic key thereof
US20150113259A1 (en) Computer with Flexible Operating System
KR20160121775A (en) THIRD PARTY'S SECURITY AUTHENTICATION SYSTEM BETWEEN MOBILE DEVICE AND IoT DEVICES AND METHOD THEREOF
KR20190033380A (en) Authenticating a networked camera using a certificate having device binding information
CN104994503B (en) A kind of mobile application access method
WO2021134712A1 (en) Load authentication method and system, mobile platform, load, and transfer device
CN110247877A (en) A kind of management method and terminal of outline management instruction
CN111143832A (en) Mobile terminal SDK (software development kit) suitable for multiple scenes and hybrid authorization method thereof
CN112995717A (en) Video transmission control method and device, electronic equipment and intelligent glasses
KR20200101053A (en) Electronic device and certification method in electronic device
US20220350586A1 (en) Methods of Distributing Software/Firmware Updates
WO2020177116A1 (en) Counterfeit app identification method and apparatus
CN117354001A (en) Access method of Internet of vehicles system, cloud server, controlled terminal and Internet of vehicles system
CN117499918A (en) Method and device for upgrading equipment to access cloud, electronic equipment and storage medium
KR20220050702A (en) Software application license management of camera device through mediation device
CN117479152A (en) Vehicle machine debugging method, server, vehicle machine equipment and computer readable storage medium
CN115292673A (en) Container application authorization method and device, readable storage medium and electronic equipment
KR20180085499A (en) Mobile control

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 19958286

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 19958286

Country of ref document: EP

Kind code of ref document: A1