WO2021134712A1 - Procédé et système d'authentification de charge, plateforme mobile, charge et dispositif de transfert - Google Patents

Procédé et système d'authentification de charge, plateforme mobile, charge et dispositif de transfert Download PDF

Info

Publication number
WO2021134712A1
WO2021134712A1 PCT/CN2019/130967 CN2019130967W WO2021134712A1 WO 2021134712 A1 WO2021134712 A1 WO 2021134712A1 CN 2019130967 W CN2019130967 W CN 2019130967W WO 2021134712 A1 WO2021134712 A1 WO 2021134712A1
Authority
WO
WIPO (PCT)
Prior art keywords
load
movable platform
switching device
function
authentication information
Prior art date
Application number
PCT/CN2019/130967
Other languages
English (en)
Chinese (zh)
Inventor
王钧玉
Original Assignee
深圳市大疆创新科技有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 深圳市大疆创新科技有限公司 filed Critical 深圳市大疆创新科技有限公司
Priority to CN201980095977.7A priority Critical patent/CN113767605A/zh
Priority to PCT/CN2019/130967 priority patent/WO2021134712A1/fr
Publication of WO2021134712A1 publication Critical patent/WO2021134712A1/fr

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/40Network security protocols
    • BPERFORMING OPERATIONS; TRANSPORTING
    • B64AIRCRAFT; AVIATION; COSMONAUTICS
    • B64UUNMANNED AERIAL VEHICLES [UAV]; EQUIPMENT THEREFOR
    • B64U20/00Constructional aspects of UAVs
    • B64U20/80Arrangement of on-board electronics, e.g. avionics systems or wiring
    • B64U20/87Mounting of imaging devices, e.g. mounting of gimbals

Definitions

  • the present invention relates to the field of communication technology, in particular to a load authentication method and system, a movable platform, a load, and a switching device.
  • the load mounted on the mobile platform can be an SDK product developed based on the SDK (Software Development Kit, software development kit).
  • the SDK is generally provided to users in the form of open source or in the form of library files.
  • illegal users can steal the user information of legitimate users by monitoring the communication data when the mobile platform communicates with the load.
  • Illegal users can use the user information of legitimate users, impersonate legitimate users, or even The movable platform may be illegally controlled, and the security risk is relatively high.
  • the embodiment of the present invention provides a load authentication method and system, a movable platform, a load, and a switching device, which can set the functional authority of the load according to the load authentication information, improve the reliability of the load authentication, and ensure the safety of the movable platform Sex.
  • an embodiment of the present invention provides a load authentication system, where the load authentication system includes a movable platform and a load;
  • the movable platform is configured to send a load authentication request to the load when it is detected that the load is connected to the movable platform;
  • the load is used to receive the load authentication request sent by the movable platform, and based on the load authentication request, send load authentication information of the load to the movable platform;
  • the mobile platform is further configured to receive the load authentication information sent by the load, and determine the functional authority of the load according to the load authentication information;
  • the movable platform is also used to determine the open function between the load and the movable platform according to the functional authority of the load.
  • an embodiment of the present invention provides a load authentication method, which is applied to a mobile platform, and the method includes:
  • an open function between the load and the movable platform is determined.
  • an embodiment of the present invention provides a load authentication method, which is applied to a switching device, and the method includes:
  • an embodiment of the present invention provides a load authentication method, which is applied to a load, and the method includes:
  • the load authentication information of the load is sent to the mobile platform, so that the mobile platform determines the load and the function authority of the load determined by the load authentication information Open functions between the movable platforms.
  • an embodiment of the present invention provides a movable platform, the movable platform includes a memory and a processor, and the memory and the processor are connected to each other, wherein:
  • the memory is used to store a computer program, and the computer program includes program instructions
  • the processor calls the program instructions for:
  • an open function between the load and the movable platform is determined.
  • an embodiment of the present invention provides a switching device, the switching device includes a memory and a processor, the memory and the processor are connected to each other, wherein:
  • the memory is used to store a computer program, and the computer program includes program instructions
  • the processor calls the program instructions for:
  • an embodiment of the present invention provides a load, the load includes a memory and a processor, and the memory and the processor are connected to each other, wherein:
  • the memory is used to store a computer program, and the computer program includes program instructions
  • the processor calls the program instructions for:
  • the load authentication information of the load is sent to the movable platform, so that the movable platform determines the functional authority of the load according to the load authentication information, and determines the relationship between the load and the load. Describes the open functions between the movable platforms.
  • an embodiment of the present invention provides a carrier assembly, including a carrier and the adapter device according to the sixth aspect of the embodiment of the invention, the adapter device being provided on the carrier.
  • an embodiment of the present invention provides a movable platform assembly, including the movable platform described in the fifth aspect of the embodiments of the present invention and the carrier assembly described in the eighth aspect of the embodiments of the present invention, the carrier assembly and The movable platform is connected.
  • an embodiment of the present invention provides a computer-readable storage medium having a computer program stored on the computer-readable storage medium, and when the computer program is executed, it achieves the same as described in the second aspect of the embodiment of the present invention.
  • an embodiment of the present invention provides a computer-readable storage medium having a computer program stored on the computer-readable storage medium, and the computer program, when executed, realizes the same as the third aspect of the embodiment of the present invention The load authentication method.
  • an embodiment of the present invention provides a computer-readable storage medium, and a computer program is stored on the computer-readable storage medium.
  • the computer program When executed, it implements the fourth aspect of the embodiment of the present invention.
  • the load authentication method When the computer program is executed, it implements the fourth aspect of the embodiment of the present invention.
  • the mobile platform when the mobile platform detects that the load is connected to the mobile platform, it sends a load authentication request to the load. After the load receives the load authentication request sent by the mobile platform, it sends the load authentication information of the load to the mobile platform. The mobile platform, after receiving the load authentication information sent by the load, the mobile platform determines the functional authority of the load according to the load authentication information, and the mobile platform further determines the open functions between the load and the mobile platform according to the functional authority of the load.
  • the functional authority of the load can be set according to the load authentication information, and the reliability of the load authentication is improved, thereby ensuring the safety of the movable platform.
  • FIG. 1 is a schematic diagram of a link of a load authentication system provided by an embodiment of the present invention
  • FIG. 2 is a schematic flowchart of a load authentication method provided by an embodiment of the present invention.
  • FIG. 3 is a schematic flowchart of a method for authenticating a load according to an embodiment of the present invention
  • FIG. 4 is a schematic diagram of a successful flow of load authentication provided by an embodiment of the present invention.
  • FIG. 5 is a schematic flowchart of a method for authenticating a switching device according to an embodiment of the present invention
  • FIG. 6 is a schematic flowchart of an exemplary load authentication method provided by an embodiment of the present invention.
  • Figure 7 is a schematic structural diagram of a movable platform provided by an embodiment of the present invention.
  • FIG. 8 is a schematic structural diagram of a switching device provided by an embodiment of the present invention.
  • Fig. 9 is a schematic structural diagram of a load provided by an embodiment of the present invention.
  • the movable platform can expand the functions of the movable platform by mounting a load such as a shooting device (such as a video camera, a camera, a camera, etc.) or a loudspeaking device (such as a megaphone, etc.).
  • a load such as a shooting device (such as a video camera, a camera, a camera, etc.) or a loudspeaking device (such as a megaphone, etc.).
  • the load mounted on the mobile platform can be authenticated before use.
  • the mobile platform can authenticate the load by verifying the relevant information of the load, but in this process, user information is easy to leak, and illegal users can use the illegally obtained information to perform all the functions of the load, and then can illegally steal The data or control of the mobile platform poses a greater security risk.
  • the embodiment of the present invention provides a load authentication method and a load authentication system.
  • a functional filtering firewall is constructed between the load and the mobile platform.
  • the mobile platform can determine the functional authority of the load according to the firewall level certificate of the load, and then The open functions between the load and the movable platform can be determined, and the reliability of the authentication of the load by the movable platform is improved, thereby ensuring the safety of the movable platform.
  • the movable platform mentioned in the embodiment of the present invention may be provided by a supplier (ie, the first party), and the load may be provided by a developer (ie, the second party).
  • the load can be mounted on a carrier, such as a pan/tilt.
  • the load can communicate with the carrier and the movable platform through a transfer device set on the carrier, and form a corresponding communication link, carrier and transfer
  • the device can also be provided by the supplier.
  • the movable platform may include unmanned aerial vehicles, unmanned vehicles, unmanned ships, handheld devices, and so on.
  • FIG. 1 is a schematic diagram of a link of a load authentication system provided by an embodiment of the present invention.
  • the load authentication system includes: a load 101, a switching device 102, a movable platform 103, a terminal device installed with an application 104, and Server 105.
  • the load 101 is mounted on a carrier (not shown in the figure) through an adapter device 102, and the adapter device 102 is installed on the carrier (not shown in the figure), and the carrier is used to connect with the movable platform 103.
  • the mobile platform 103 can be connected to the terminal device installed with the application program 104 in a wired manner, or can be connected to the terminal device installed with the application program 104 in a wireless manner, and the terminal device 104 can be connected to the server 105.
  • the mobile platform 103 when the mobile platform 103 is wirelessly connected to the terminal device installed with the application 104, it can be directly connected to the terminal device installed with the application 104, or it can be connected to the terminal device installed with the application 104 through the remote control device of the movable platform 103 and the installation.
  • the terminal device with the application 104 is connected.
  • the load can be authenticated.
  • the mobile platform 103 and the server 105 can be connected in different ways, and the terminal device installed with the application 104 can also be used. Different, and the functions that can be opened by the application 104 may also be different. For details, please refer to the subsequent description.
  • the developer when the developer develops the load based on the carrier provided by the supplier, he can register enterprise user information on the website provided by the supplier. After the registration is successful, the developer side can obtain the corresponding application information, which can include the product name (the product includes a combination device consisting of a load and a carrier, and the carrier is equipped with a switching device), an identity mark and an authentication secret key.
  • the corresponding product name can be different, and the corresponding authentication key and identity can be the same; for different products of different developers, the corresponding product name, authentication key and identity can be Both can be different.
  • the developer can write the corresponding application information into the load during the development of the load. Further, after the user purchases the product provided by the developer, the corresponding firewall level certificate can be downloaded to limit the open function between the load and the mobile platform.
  • the encryption chip of the switching device 102 stores the SN (Serial Number) of the load 101, and the SN can uniquely identify the load 101; the encryption chip can also store supplier information, such as the anti-counterfeiting identification of the supplier’s product, It is used to authenticate the switching device, for example; the encryption chip may also store a first key, and the first key is used to assist the authentication of the switching device.
  • SN Serial Number
  • supplier information such as the anti-counterfeiting identification of the supplier’s product
  • the mobile platform 103 includes a certification center and a server.
  • the certification center is an application established based on the server 105 and runs on the mobile platform.
  • the certification center stores a second key obtained from the server 105.
  • the second key can be
  • the only authentication load is 101.
  • the firewall of the mobile platform 103 is an application program running on the mobile platform. The firewall can determine the open functions between the load 101 and the mobile platform 103, thereby allowing commands to execute related open functions between the load 101 and the mobile platform 103. Passed between.
  • the application 104 can run in a terminal device, and the user can interact with the movable platform 103 and the switching device 102 through the application 104 to start the load authentication process.
  • the terminal device may be a mobile terminal, a personal computer (PC) end or a portable computer (Tablet Personal Computer, Tablet PC) end, etc., and may also be a remote control device of a movable platform.
  • the server 105 stores the application information registered by the developer on the development website provided by the supplier.
  • the application information may include the product name (the product includes a combination device consisting of a load and a carrier, and the carrier is provided with a switching device), Identification (such as the supplier's registration ID) and authentication key.
  • the server 105 may also store related information about the switching device 102, the load 101, etc., such as SN.
  • FIG. 2 is a schematic flowchart of a load authentication method provided by an embodiment of the present invention.
  • the load authentication method includes but is not limited to the following steps:
  • Step S201 The mobile platform sends a load authentication request to the load.
  • the authentication of the load includes the authentication of the functional authority of the load, that is, the open function between the load and the movable platform is specified.
  • the mobile platform in the actual authentication process, it can be divided into online mode and offline mode. That is, when the mobile platform is in communication with the server, either online mode or offline mode can be used to authenticate the load; and when the mobile platform is not in communication with the server, the offline mode can be used to authenticate the load.
  • Perform authentication Specifically, in order to be able to authenticate the load in offline mode, the mobile platform may store corresponding information for authenticating the functional authority of the load, such as a key, and the key (such as the second key described above) can be It is used to decrypt the obtained firewall certificate.
  • the functional authority of the load such as a key
  • the key such as the second key described above
  • the mobile platform may send a load authentication request to the load to obtain load authentication information for authenticating the load.
  • the load can be authenticated so that it can be authenticated every time the load is used, preventing the risk of load being replaced, thereby ensuring the load It has always been a payload, which improves the security of the application.
  • the load can be initially authenticated once, or it can be authenticated multiple times continuously or at intervals during the use process, which is not specifically limited here.
  • Step S202 The load may send load authentication information of the load to the mobile platform based on the load authentication request.
  • the load After the load receives the load authentication request sent by the mobile platform, the load can send the load authentication information of the load to the mobile platform based on the load authentication request, and the mobile platform can receive the load authentication information sent by the load.
  • the legality of the load can be checked. And the legitimacy of the transfer device is verified, for example: if the transfer device passes the load authentication, the transfer device receives the load authentication information sent by the load; if the mobile platform passes the authentication of the transfer device, the mobile platform receives the transfer Load authentication information sent by the receiving device.
  • the timing between steps is not limited to this.
  • the transfer device receives the load authentication request sent by the mobile platform; if the transfer device If the load authentication is passed, the load receives the load authentication request sent by the switching device; the authentication process of the mobile platform for authenticating the switching device and the authentication process of the switching device for authenticating the load can also be performed at the same time.
  • FIG. 3 is a schematic flowchart of a method for authenticating the load provided by an embodiment of the present invention; the movable platform performs the authentication on the transfer device.
  • FIG. 5 for the authentication process of legality authentication.
  • FIG. 5 is a schematic flowchart of a method for authenticating a switching device according to an embodiment of the present invention, and details are not described herein again.
  • Step S203 The mobile platform determines the functional authority of the load according to the load authentication information.
  • the load authentication information may include the firewall grade certificate of the load, and the mobile platform may determine the functional authority of the load according to the firewall grade certificate of the load.
  • the form of load authentication information is not limited to the firewall level certificate.
  • the firewall is set on the mobile platform, so that the open function between the load and the mobile platform can be limited through the firewall.
  • It can also be embodied in other forms, which can indicate the open function between the load and the movable platform, for example, encrypted identification information, which is used to indicate the open function between the load and the movable platform.
  • the firewall level certificate of the payload in order to prevent the firewall level of the payload from being tampered with, can be encrypted information, and the mobile platform can use the second key as described above to decrypt the encrypted firewall level certificate to obtain
  • the decrypted firewall level certificate, and the decrypted firewall level certificate may include the firewall level of the load. If the certification center of the mobile platform determines that the decrypted firewall level certificate is a valid firewall level certificate based on the certificate number and validity period of the decrypted firewall level certificate, the mobile platform can determine the firewall level of the load according to the firewall level of the load.
  • the functional authority corresponding to the level if the certification center of the mobile platform determines that the decrypted firewall level certificate is an invalid firewall level certificate according to the certificate number and validity period of the decrypted firewall level certificate, the mobile platform can change the received load
  • the firewall level certificate of the mobile platform is deleted from the storage space of the mobile platform, and the open function between the load and the mobile platform can be closed, and the user can be prompted accordingly.
  • the mobile platform can send out a photoelectric prompt, or The remote control side of the platform gives a prompt.
  • the firewall level can include ordinary service level and value-added service level.
  • the ordinary service level means that the firewall can allow some basic commands to pass, such as commands that allow the control of PTZ and image transmission.
  • the value-added service level means that the firewall can allow some Advanced commands are passed, such as allowing control of movable platforms. If the firewall level of the load is a normal service level, the mobile platform can determine that the function authority of the load corresponding to the normal service level is the normal service function authority; if the firewall level of the load is a value-added service level, the mobile platform can determine the value-added service level The function authority of the corresponding load is the value-added service function authority. Among them, the value-added service function authority may include the normal service function authority.
  • the firewall of the mobile platform can send a policy file acquisition request to the certification center of the mobile platform, and the firewall of the mobile platform receives After the policy file acquisition request, the policy file can be returned to the certification center of the mobile platform based on the policy file acquisition request.
  • the policy file may include a preset correspondence relationship between the firewall level and the function authority.
  • the firewall level may include a normal service level and a value-added service level; the function authority may include a normal service function authority and a value-added service function authority.
  • the preset correspondence between the firewall level and the function authority may include the correspondence between the ordinary service level and the ordinary service function authority, and the correspondence between the value-added service level and the value-added service function authority.
  • the mobile platform can determine the current firewall level of the load according to the firewall level certificate of the load, so that the mobile platform can determine the functional authority of the load according to the preset correspondence between the firewall level and the functional authority and the current firewall level of the load.
  • the mobile platform can determine that the functional authority of the load is a normal service function authority; if the current firewall level of the load is a value-added service level, the mobile platform can determine that the functional authority of the load is a value-added service function Permissions.
  • the classification of firewall levels may not be limited to the ordinary service levels and value-added service levels described above, but may also include multiple levels.
  • the corresponding function permissions between each level may be different or partly different. The number of function permissions is also different. Different settings can be made accordingly.
  • the firewall level certificate of the load can be updated. After the firewall level certificate of the load is updated, the mobile platform can obtain the updated firewall level certificate of the load, so that the mobile platform can update the firewall level according to the load. The certificate determines the functional authority corresponding to the updated firewall level certificate.
  • the policy file in the certification center of the mobile platform can be updated.
  • the updated policy file may include the updated preset correspondence between the firewall level and the function authority, and the updated policy file can also be updated. It can include the updated preset corresponding relationship between the function authority and the function level of the open function.
  • the mobile platform can determine the updated function authority of the load according to the updated policy file and the firewall level certificate of the load, so that the mobile platform can be based on The updated functional authority of the load determines the updated open functions between the load and the mobile platform.
  • Step S204 The movable platform determines the open function between the load and the movable platform according to the functional authority of the load.
  • the open function may include at least one of a data transmission function that allows a movable platform to the load or a carrier of the load, and a data transmission function that allows the load or a carrier of the load to the movable platform.
  • the data transmission function that allows the movable platform to the load or the carrier of the load may include, but is not limited to, the transmission function of the control command of the movable platform to the carrier of the load, the transmission function of the positioning data of the movable platform, and the acquisition of the movable platform from the ground terminal.
  • the data transmission function that allows the load or the load carrier to the movable platform may include, but is not limited to, at least one of the transmission function of the collected data of the load and the transmission function of the control command of the load to the movable platform.
  • the transmission function of the control command of the movable platform to the carrier of the load and the transmission function of the control command of the load to the movable platform are functions related to control.
  • the transmission function of the positioning data of the movable platform is a function related to positioning. If the multimedia data acquired by the mobile platform from the ground side and the data collected by the load are image data, the transmission function of the multimedia data acquired by the mobile platform from the ground side and the transmission function of the collected data on the load are image-related Function; if the multimedia data acquired by the mobile platform from the ground side and the data of the collected data of the load are audio data, the transmission function of the multimedia data acquired by the mobile platform from the ground side and the transmission function of the collected data of the load are audio data Related functions. That is, the open function may include, but is not limited to, at least one of a control-related function, an image-related function, an audio-related function, and a positioning-related function.
  • the carrier of the load is a gimbal.
  • the control-related functions can be to control the rotation of the PTZ through the load and the flight of the unmanned aerial vehicle through the load;
  • the image-related functions can be the unmanned aerial vehicle to transmit the image data taken by the unmanned aerial vehicle to the load, among which, the image data
  • the bit stream bandwidth required for transmission can be different according to the firewall level;
  • audio-related functions can be for users to upload voice to the load through terminal equipment, for example, through the load for playback;
  • positioning-related functions can be obtained by the load RTK (Real-time Kinematic) data on the unmanned aerial vehicle.
  • the RTK data is combined with the image data collected by the load to construct a three-dimensional model.
  • the same open function may include different function levels
  • the policy file obtained by the mobile platform may also include the preset correspondence between the function authority and the function level of the open function
  • the mobile platform may determine according to The obtained function authority of the load, the preset correspondence between the function authority and the function level of the open function, determine the open function between the load and the movable platform, and determine the function of the open function between the obtained load and the movable platform
  • the level is adapted to the determined functional authority of the load.
  • the function authority may include ordinary service function authority and value-added service function authority;
  • the function level of the open function may include ordinary service function level 1, ordinary service function level 2, and value-added service function Level 1, value-added service function level 2;
  • the preset correspondence between function authority and open function function level may include the correspondence between ordinary service function authority and ordinary service function level, value-added service function authority and value-added service function level The corresponding relationship between is used to limit the openness of all functions in the same category.
  • the mobile platform can determine the normal service function level of the open function between the load and the mobile platform according to the normal service function authority; if it is determined that the function authority of the load obtained is Value-added service function authority, the mobile platform can determine the value-added service function level of the open function between the load and the mobile platform according to the value-added service function authority.
  • the unmanned aerial vehicle can determine the ordinary service function of the open function between the payload and the unmanned aerial vehicle according to the ordinary service function authority.
  • Level which can determine the open function between the load and the UAV; if the function authority of the obtained load is determined to be the value-added service function authority, the UAV can determine the open function between the load and the UAV according to the value-added service function authority.
  • the value-added service function level of the function so that the open function between the load and the UAV can be determined. For example, suppose the open function between the load and the UAV is a value-added service function.
  • the value-added service function includes not only the control of the PTZ through the load, but also the control of the UAV through the load.
  • the value-added service function level is 1 When the user can control the rotation of the PTZ through the load and control the drone through the load within a predetermined period of time, when the value-added service function level is 2, the user can control the rotation of the PTZ through the load and control the unmanned aircraft through the load.
  • the control of the machine is not limited within a predetermined period of time.
  • the same open function is the function with the same functional attribute, the image-related function, the image-related function can be divided into level 1, level 2, and the preset correspondence between the function authority and the function level of the open function
  • the relationship may include the corresponding relationship between the image-related functions and their function levels. If it is determined that the function authority of the load is an image-related function, the movable platform can determine the image-related function between the load and the movable platform according to the correspondence between the image-related function and its function level. Function level.
  • the unmanned aerial vehicle can determine the load and the ability according to the correspondence between the image-related function and its function level.
  • the function level of image-related functions between mobile platforms For example, assuming that the open function between the payload and the UAV is an image-related function, the bit stream bandwidth corresponding to level 1 is smaller than the bit stream bandwidth corresponding to level 2 during image transmission.
  • the mobile platform can determine the functional authority of the load according to the obtained authentication information of the load, that is, the firewall level certificate of the load, and the mobile platform can determine the functional authority of the load according to the functional authority of the load.
  • the level of the firewall level certificate is different, and the function authority of the determined load is also different, and the open function between the determined load and the movable platform may be different.
  • a functional filtering firewall is constructed between the load and the mobile platform, so that the open function between the load and the mobile platform corresponds to the level of the load’s firewall level certificate, and the load cannot be executed with the load’s firewall level certificate level.
  • Uncorresponding open functions can improve the reliability and security of load applications, and can also prevent the load from being used illegally.
  • FIG. 3 is a schematic flowchart of a method for authenticating a load according to an embodiment of the present invention.
  • the method for authenticating a load includes but is not limited to the following steps:
  • Step S301 The switching device sends preset data to the load.
  • the authentication of the load includes the authentication of the legitimacy of the load.
  • the authentication process of the load by the switching device mentioned in the embodiment of the present invention may be performed before the embodiment shown in FIG. 2.
  • the embodiment shown in FIG. 2 is executed to determine the open function between the movable platform and the load.
  • the authentication process of the load by the switching device mentioned in the embodiment of the present invention may also be executed when the switching device detects that the load is connected to the switching device.
  • the authentication process for the load by the switching device shown in FIG. 3 and the open function determination process shown in FIG. 2 may be executed simultaneously when the load is connected to the switching device.
  • the switching device may store corresponding information for authenticating the legitimacy of the load, such as a key (such as the authentication key described above).
  • the switching device may send preset data to the load, and the preset data may be a random string for verifying the legitimacy of the load.
  • Step S302 The load generates first verification data based on the preset data and the preset key.
  • the load After the load receives the preset data from the switching device, the load can calculate the preset key (such as the authentication key mentioned above) and the preset data of the load according to the preset verification algorithm to generate the first Check the data.
  • the load application information including authentication keys and other load stored in the load can be provided by the supplier and obtained by the developer after registering on the website provided by the supplier. After the developer obtains the application information, the application information can be written into it Under load.
  • the preset verification algorithm may include the MD5 algorithm, the CMAC algorithm, the SHA256 algorithm, the SHA512 algorithm, and so on.
  • Step S303 The load sends the first verification data to the switching device.
  • the load may send the generated first verification data to the switching device, and the switching device may perform legality authentication on the load through the first verification data.
  • Step S304 The switching device verifies the first verification data.
  • the switching device can establish a communication connection with the server, and the switching device can verify the first verification data through the server, that is, the switching device can verify the first verification data in an online mode. For example, after the switching device receives the first verification data from the load, the switching device sends the first verification data and the preset data to the server, and the server can check the data from the switching device according to the preset verification algorithm. The preset data and the preset key stored in the server are calculated to generate the third verification data.
  • the server may send a verification success notification to the switching device, and the switching device may determine that the first verification data from the load is authenticated based on the verification success notification, Therefore, the switching device confirms that the load is authenticated, and the switching device can allow the load to establish a communication connection with the movable platform through the switching device; if the first verification data is different from the third verification data, the server can send to the switching device In the verification failure notification, the switching device may determine that the authentication of the first verification data from the load has failed based on the verification failure notification, so that the switching device confirms that the authentication of the load has failed, and the switching device may prohibit the load from passing through the switching device and The mobile platform establishes a communication connection, and the switching device can delete the first verification data from the load from the storage space of the switching device.
  • a user can log in to an application with a user account, and send a verification start notification to the switching device through the application.
  • the switching device may respond to the start verification notification and send an application information acquisition request to the load to start the load authentication process.
  • the load can be based on the application information acquisition request, and the application information (including the identity or product name during transmission, but not the authentication key) can be sent to the switching device.
  • the switching device After the switching device receives the identity or product name sent by the load , Can send preset data to the load.
  • the load can calculate the preset key and preset data of the load according to the preset verification algorithm to generate the first calibration.
  • the switching device may send the first verification data, preset data, and application information to the server, so that the server verifies the first verification data from the load .
  • the server can obtain the preset key stored in the server corresponding to the application information according to the application information, and the server can perform a check on the preset key stored in the server and the preset data from the switching device according to the preset verification algorithm. Calculate and generate the third verification data.
  • the server may send a verification success notification, the first verification data, and application information to the switching device; the switching device may send the verification success notification returned by the server to the application Program, the user can know that the transfer device has passed the load authentication through the application program.
  • the switching device may also store the configuration information returned by the server in the storage space of the switching device. If the first verification data is not the same as the third verification data, the switching device can determine that the authentication of the first verification data from the load has failed, so that the switching device confirms that the authentication of the load has failed, and the switching device can prohibit the load from passing the transfer.
  • the connection device establishes a communication connection with the movable platform, and the switching device can also delete the first verification data from the load from the storage space of the switching device.
  • the configuration information includes first verification data and application information.
  • the product name and identity identifier in the application information can be used to record the authentication information of the combined device.
  • the first verification data and the preset data can be sent to the server asynchronously; the application information and the first verification data can also be sent to the switching device synchronously; the application information acquisition request and the sending preset data can be sent synchronously, or The application information acquisition request may not be sent.
  • the load can send the corresponding application information and the first verification data to the switching device.
  • the switching device may verify the first verification data in an offline mode. After the switching device receives the first verification data from the load, the switching device can check the preset data and the preset key obtained by the switching device (such as the authentication secret mentioned above) according to the preset verification algorithm. Key) to perform calculations to generate second verification data.
  • the preset key acquired by the switching device may be obtained by decrypting the acquired encrypted preset key by the switching device.
  • the switching device can determine that the authentication of the first verification data from the load is passed, so that the switching device confirms that the load is authenticated, and the switching device can allow the load to pass the transfer
  • the device establishes a communication connection with the movable platform; if the first verification data and the second verification data are not the same, the switching device can determine that the authentication of the first verification data from the load has failed, so that the switching device confirms that the authentication of the load has failed ,
  • the switching device can prohibit the load from establishing a communication connection with the movable platform through the switching device, and the switching device can also delete the first verification data from the load from the storage space of the switching device.
  • the load and the carrier may be bound, so as to store corresponding binding information at the switching device, so as to obtain the preset key.
  • the switching device in order to prevent the payload from transmitting the preset key to the switching device and causing information leakage, the switching device can send a random character string to the carrier and the movable platform, and the payload can use
  • the preset key and the received random character string calculate the check value, and the check value can be sent to the server through the switching device, and the server can also calculate the check value based on the preset key and the received random character string , And the calculated check value can be compared with the check value sent by the load. If they are the same, the load is considered to be authenticated, the load can be bound to the carrier, and the binding configuration information can be issued to the transfer ⁇ Connecting device.
  • the binding configuration information may include a preset key and may be encrypted.
  • the switching device can authenticate the load multiple times at intervals of a preset period. If the authentication fails, the load can be immediately prohibited from continuing to establish a communication connection with the mobile platform through the switching device, which is beneficial to avoid The user illegally controls the movable platform through the load.
  • the switching device can authenticate the legitimacy of the load. If the transfer device confirms that the load authentication is passed, the transfer device can allow the load to establish a communication connection with the mobile platform through the transfer device to further determine the open function between the load and the mobile platform, thereby improving the reliability of the load authentication. If the transfer device confirms that the load authentication has not passed, the transfer device can immediately prohibit the load from establishing a communication connection with the mobile platform through the transfer device, so as to prevent the user from illegally controlling the mobile platform through the load, which is beneficial to protect the mobile platform. safety.
  • FIG. 5 is a schematic flowchart of a method for authenticating a switching device according to an embodiment of the present invention.
  • the method for authenticating a switching device includes but is not limited to the following steps:
  • Step S501 The movable platform sends a switching device authentication request to the switching device.
  • a switching device is provided on the carrier, and the load communicates with the carrier and the movable platform through the switching device.
  • the authentication process of the transfer device by the movable platform mentioned in the embodiment of the present invention may be executed before the embodiment shown in FIG. 2 or executed when the movable platform detects that the load is connected to the movable platform.
  • the authentication process of the transfer device by the movable platform mentioned in the embodiment of the present invention may be performed at the same time as the authentication process of the load by the transfer device shown in FIG. 3, or may not be performed at the same time.
  • the authentication process of the legitimacy of the transfer device by the movable platform mentioned in the embodiment of the present invention may be performed before the authentication process of the load by the transfer device shown in FIG. 3.
  • the authentication process of the transfer device by the movable platform mentioned in the embodiment of the present invention and the authentication process of the load by the transfer device shown in FIG. 3 can be performed at the same time when the load is connected to the transfer device.
  • the movable platform detects that the load is connected to the movable platform, and the movable platform can send the adapter device authentication request to the adapter device to obtain the adapter used to authenticate the adapter device. Device authentication information.
  • the switching device and the carrier can be integrated into the same device, or they can be independent of each other, the switching device can be integrated with the carrier into the same device, and the authentication of the switching device can be equivalent to the authentication including the carrier.
  • the adapter device when the movable platform detects that the adapter device is connected to the movable platform, the adapter device can be authenticated, so that every time the adapter device is used, it can be authenticated, preventing the adapter device The risk of being replaced ensures that the switching device is always an effective switching device, which improves the safety of the application.
  • the switching device can be authenticated once, or it can be repeatedly authenticated continuously or at intervals during the use process, which is not specifically limited here.
  • Step S502 The mobile platform receives the adapter device authentication information sent by the adapter device.
  • the adapter device After the adapter device receives the adapter device certification request sent by the movable platform, the adapter device can send the adapter device certification information of the adapter device to the movable platform based on the adapter device certification request, and the movable platform can receive The switching device authentication information sent by the switching device, and the switching device is authenticated according to the switching device authentication information.
  • Step S503 The mobile platform authenticates the switching device according to the authentication information of the switching device.
  • the adapter device is authenticated as a valid adapter device or an invalid adapter device.
  • the movable platform can authenticate the adapter device according to the adapter device authentication information to determine whether the adapter device is a valid adapter device.
  • the authentication information of the switching device may include the anti-counterfeiting identification of the switching device (such as the aforementioned supplier information), and the movable platform can determine whether the switching device is a valid switching device according to the anti-counterfeiting identification of the switching device. That is, whether it is a switching device provided by the supplier.
  • the switching device authentication information may include a certificate of the switching device, and the certificate contains the anti-counterfeiting identification of the switching device.
  • the certification center of the mobile platform can certify the certificate of the switching device. If the certification center of the mobile platform determines that the certificate of the switching device is a valid certificate according to the information in the certificate of the switching device, the mobile platform can determine that the switching device is a valid switching device; if the certification center of the mobile platform determines The certificate of the transfer device fails the authentication, the certification center of the mobile platform can determine that the certificate authentication of the transfer device has failed, and the mobile platform can delete the received certificate of the transfer device from the storage space of the mobile platform, and The communication function between the switching device and the movable platform can be turned off, and the user can be prompted accordingly. For example, the movable platform can send out a photoelectric prompt, or send out a prompt on the remote control side of the movable platform.
  • the switching device authentication information may include the certificate of the switching device and the SN of the load, and the certificate contains the anti-counterfeiting identification of the switching device.
  • the authentication center of the mobile platform can authenticate the certificate of the switching device and the SN of the load.
  • the certification center of the mobile platform can refer to the above description for certification of the certificate of the switching device, which will not be repeated here.
  • the SN of the load included in the authentication information of the switching device can be sent to the server by the mobile platform when a communication connection is established between the mobile platform and the server, and stored in the server, so that the server can record the load of the load according to the SN.
  • Authentication information so that the developer can learn the relevant authentication information of the product based on the relevant authentication information recorded by the server.
  • the switching device authentication information may include the certificate of the switching device, the SN of the load, and response information.
  • the certificate contains the anti-counterfeiting identification of the switching device and the first key described above, and the response information is the use of
  • the first key is obtained by verifying the character string carried in the authentication request of the switching device.
  • the authentication center of the mobile platform can authenticate the legitimacy of the switching device through Challenge/Response (Challenge/Response) authentication.
  • the transfer device authentication request sent by the mobile platform to the transfer device can carry the challenge character string "Challenge".
  • the transfer device After the transfer device receives the transfer device authentication request sent by the mobile platform, the transfer device can use the preset calibration
  • the verification algorithm calculates the first key and the challenge string "Challenge” to generate the first response string "Response".
  • the switching device can send the first response string "Response", the certificate of the switching device, and the SN of the load to the mobile platform, and the certification center of the mobile platform can obtain the first key from the certificate of the switching device, and According to the preset verification algorithm, the first response string "Response" is calculated to generate the second response string "Response".
  • the mobile platform can determine that the transfer device is a valid transfer device. If the challenge string "Challenge” and the second response string "Response" are not the same, or the certification center of the mobile platform can determine that the certificate of the transfer device is an invalid certificate, the mobile platform can determine the transfer device It is an invalid adapter.
  • the specific execution content when the switching device is a valid or invalid switching device can refer to the foregoing description; the reason for sending the SN can also refer to the foregoing description, which will not be repeated here. It is understandable that by authenticating the character string in the switching device authentication request, the risk of replacement or fraudulent use of the switching device can be further prevented, and the application security of the switching device can be improved.
  • the transfer device is a device that connects the load and the mobile platform.
  • the communication interaction between the load and the mobile platform is transmitted via the transfer device.
  • the mobile platform passes the certificate of the transfer device, the SN of the load, etc.
  • the switching device authentication information authenticates the switching device, and the mobile platform confirms that the switching device is authenticated, that is, after the switching device is a valid switching device, the load and the mobile platform can transmit communication interaction through the switching device. data.
  • the mobile platform can further improve the reliability and safety of load authentication through the authentication of the switching device.
  • the authentication center of the mobile platform detects that the load is connected to the mobile platform, the authentication center of the mobile platform A load authentication request may be sent to the load, and the load may obtain load authentication information based on the load authentication request (load authentication information may be stored in the load).
  • the firewall of the mobile platform can send a policy file acquisition request to the certification center of the mobile platform, and the certification center of the mobile platform can return the policy file to the firewall of the mobile platform based on the policy file acquisition request.
  • the firewall of the mobile platform After the firewall of the mobile platform receives the policy file returned by the certification center of the mobile platform, the firewall of the mobile platform can send the transfer device certification notification to the certification center of the mobile platform, and the certification center of the mobile platform can respond to the transfer Device authentication notification, and sending a transfer device authentication request carrying a challenge string to the transfer device.
  • the switching device can calculate the first key and the challenge string in the certificate of the switching device according to a preset verification algorithm to generate a first response string.
  • the switching device can convert the first response string to the challenge string.
  • the certificate of the connected device and the product serial number of the load are sent to the certification center of the mobile platform.
  • the certification center of the mobile platform can obtain the first key from the received certificate of the switching device, and calculate the first response string according to the preset verification algorithm to generate the second response string. If the challenge string is the same as the second response string, and the certification center of the mobile platform determines that the certificate of the adapter device is a valid certificate, the certification center of the mobile platform confirms that the adapter device is authenticated (if the adapter device is integrated in The carrier, that is, the authentication of the carrier is passed; if the transfer transposition is not integrated into the carrier, the legality of the carrier can be further authenticated), the authentication center of the mobile platform can receive the load authentication information sent by the transfer device. The authentication center of the mobile platform can determine the functional authority of the load according to the load authentication information, and the firewall of the mobile platform can determine the open function between the load and the mobile platform according to the functional authority of the load.
  • the firewall of the mobile platform After the firewall of the mobile platform determines the open functions between the load and the mobile platform according to the functional authority of the load, the firewall of the mobile platform can also send configuration information to the switching device, and the switching device can store the configuration information to the switching device. In the storage space of the device.
  • the configuration information is used to indicate the open function between the load and the movable platform determined by the movable platform according to the functional authority of the load.
  • the communication interaction between the load and the mobile platform can be authenticated in multiple ways, ensuring that if the communication protocol between them is cracked by other users, the user information will not be leaked during the security authentication process.
  • the risk of illegal replacement of the load or the carrier including the switching device is reduced.
  • the mobile platform may first send a load authentication request to the load, and then authenticate the switching device. If the mobile platform passes the authentication of the switching device, the switching device returns the load The load authentication information of the mobile platform is sent to the mobile platform; the mobile platform can also authenticate the transfer device first, if the mobile platform passes the authentication of the transfer device, the transfer device sends the load authentication request of the mobile platform to the load.
  • FIG. 7 is a schematic structural diagram of a movable platform according to an embodiment of the present invention.
  • the movable platform 70 in the embodiment of the present invention includes a memory 701 and a processor 702.
  • the memory 701 and the processor 702 are connected by one or more communication buses.
  • the memory 701 may include volatile memory (Volatile Memory), such as random access memory (Random-Access Memory, RAM); the memory 701 may also include non-volatile memory (Non-Volatile Memory), such as flash memory (Flash Memory), Solid-State Drive (SSD), etc.; the memory 701 may also include a combination of the foregoing types of memories.
  • volatile memory such as random access memory (Random-Access Memory, RAM
  • non-Volatile Memory such as flash memory (Flash Memory), Solid-State Drive (SSD), etc.
  • flash Memory Flash Memory
  • SSD Solid-State Drive
  • the processor 702 may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (Digital Signal Processors, DSPs), and application specific integrated circuits (Application Specific Integrated Circuits). , ASIC), ready-made programmable gate array (Field-Programmable Gate Array, FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc.
  • the general-purpose processor may be a microprocessor or the processor may also be any conventional processor or the like.
  • the movable platform 70 of the embodiment of the present invention can be used to implement the method implemented by each embodiment of the present invention shown in FIG. 2 or FIG. 5 through the processor 702.
  • the embodiments of the present invention shown in FIG. 2 or FIG. 5 for implementation.
  • program instructions are stored in the memory 701, and the processor 702 calls the program instructions in the memory 701.
  • the processor 702 is configured to: When the platform is moved, the load authentication information of the load is obtained; the function authority of the load is determined according to the load authentication information; the function authority of the load is determined according to the load and the movable platform 70 Open function.
  • the load authentication information includes a firewall grade certificate; when the processor 702 determines the functional authority of the load according to the load authentication information, it is specifically configured to: according to the firewall grade certificate, Determine the functional authority of the load.
  • the firewall level certificate is encrypted information; when the processor 702 determines the functional authority of the load according to the load authentication information, it is specifically configured to: perform a check on the firewall level certificate. Decryption; when the decrypted firewall level certificate is valid, the functional authority of the load is determined according to the decrypted firewall level certificate.
  • the processor 702 before determining the functional authority of the load according to the firewall level certificate, the processor 702 is further configured to: obtain a policy file, the policy file including the firewall level and the open function
  • the processor 702 is specifically configured to: determine the current firewall level according to the firewall level certificate; according to the policy The file and the current firewall level determine the functional authority of the load.
  • the step of obtaining the policy file by the processor 702 is performed when it is detected that the load is connected to the movable platform.
  • the policy file is updatable.
  • the firewall level certificate is updatable.
  • the open function includes at least one of the following: allowing the mobile platform 70 to transmit data to the load or the load carrier, allowing the load or the load The data transmission function of the carrier to the movable platform 70.
  • the data transmission function allowing the movable platform 70 to the load or the carrier of the load includes at least one of the following: the carrier of the movable platform 70 to the load The transmission function of the control command; the transmission function of the positioning data of the movable platform 70; the transmission function of the multimedia data obtained by the movable platform 70 from the ground terminal.
  • the data transmission function that allows the load or the carrier of the load to the movable platform 70 includes at least one of the following: a transmission function of the collected data of the load; The transmission function of the load to the control command of the movable platform 70.
  • the open function includes at least one of the following: a control-related function, an image-related function, an audio-related function, and a positioning-related function.
  • the same open function includes different function levels, and the function levels are adapted to the determined function permissions.
  • the load is communicatively connected to the movable platform 70 through a switching device
  • the processor 702 is further configured to perform the following steps: according to the functional authority of the load, send a message to the switching device Sending configuration information, the configuration information being used to indicate the open function between the load and the movable platform 70.
  • the load is communicatively connected to the movable platform 70 through a switching device; the processor 702 is further configured to perform the following steps before acquiring the load authentication information of the load: The switching device authentication information of the switching device; when it is determined that the switching device is a valid switching device according to the switching device authentication information, the execution of the step of obtaining the load authentication information of the load is triggered.
  • the authentication information of the switching device includes an anti-counterfeiting identifier.
  • the processor 702 obtains the adapter device authentication information of the adapter device when it is detected that the adapter device is connected to the movable platform 70.
  • the movable platform 70 is provided by a first party, and the load is provided by a second party.
  • the movable platform 70 provided in this embodiment can execute the steps executed by the movable platform in the foregoing embodiment, and the execution mode and beneficial effects are similar, and will not be repeated here.
  • FIG. 8 is a schematic structural diagram of a switching device according to an embodiment of the present invention.
  • the switching device 80 in the embodiment of the present invention includes a memory 801 and a processor 802.
  • the memory 801 and the processor 802 are connected through one or more communication buses.
  • the memory 801 may include a volatile memory (Volatile Memory), such as a random access memory (Random-Access Memory, RAM); the memory 801 may also include a non-volatile memory (Non-Volatile Memory), such as a flash memory (Flash Memory), Solid-State Drive (SSD), etc.; the memory 801 may also include a combination of the foregoing types of memories.
  • volatile memory such as a random access memory (Random-Access Memory, RAM
  • non-Volatile Memory such as a flash memory (Flash Memory), Solid-State Drive (SSD), etc.
  • flash Memory Flash Memory
  • SSD Solid-State Drive
  • the processor 802 may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (Digital Signal Processors, DSPs), and application specific integrated circuits (Application Specific Integrated Circuits). , ASIC), ready-made programmable gate array (Field-Programmable Gate Array, FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc.
  • the general-purpose processor may be a microprocessor or the processor may also be any conventional processor or the like.
  • embodiments of the present invention may also provide a movable platform component, including the movable platform described above and the adapter device described below, wherein the adapter device is connected to the movable platform through a pan-tilt.
  • the switching device 80 of the embodiment of the present invention can be used to implement the method implemented by each embodiment of the present invention shown in FIG. 3 or FIG. 5 through the processor 802.
  • the embodiments of the present invention shown in FIG. 3 or FIG. 5 for implementation.
  • program instructions are stored in the memory 801, and the processor 802 calls the program instructions in the memory 801.
  • the processor 802 is configured to: send the load authentication information of the load To the mobile platform, so that the mobile platform determines the functional authority of the load according to the load authentication information; receives and stores the configuration information returned by the mobile platform, and the configuration information is used to indicate The open function between the load and the movable platform determined by the function authority of the load.
  • the load authentication information includes a firewall level certificate.
  • the firewall level certificate is updatable.
  • the open function includes at least one of the following: a data transmission function that allows the movable platform to the load or a carrier of the load, and a carrier that allows the load or the load Data transmission function to the mobile platform.
  • the data transmission function allowing the movable platform to the load or the carrier of the load includes at least one of the following: control of the carrier of the load by the movable platform Command transmission function; transmission function of positioning data of the movable platform; transmission function of multimedia data obtained by the movable platform from the ground terminal.
  • the data transmission function that allows the load or the carrier of the load to the movable platform includes at least one of the following: a transmission function of collected data of the load; the load The transmission function of the control command to the movable platform.
  • the open function includes at least one of the following: a control-related function, an image-related function, an audio-related function, and a positioning-related function.
  • the same open function includes different function levels, and the function levels are adapted to the determined function permissions.
  • the processor 802 sending the load authentication information of the load to the movable platform is executed when it is detected that the load is connected to the switching device 80.
  • the processor 802 before sending the load authentication information of the load to the movable platform, the processor 802 is further configured to perform the following steps: send the transfer device authentication information of the transfer device 80 Sent to the movable platform; when the movable platform determines that the switching device 80 is a valid switching device according to the authentication information of the switching device, triggering the execution of the sending of the authentication information of the load to The steps of the movable platform.
  • the authentication information of the switching device includes an anti-counterfeiting identifier.
  • the processor 802 sends the adapter device authentication information of the adapter device 80 to the movable platform when it is detected that the adapter device 80 is connected to the movable platform. implemented.
  • the processor 802 before the processor 802 sends the load authentication information of the load to the movable platform, the processor is further configured to perform the following step: receiving the first calibration sent by the load Verification data; if the first verification data is verified, the load is allowed to communicate with the movable platform through the switching device 80.
  • the processor 802 is further configured to perform the following steps: if the first verification data fails the verification, prohibit the load from communicating with the movable platform through the switching device 80 connection.
  • the processor 802 is further configured to perform the following step: sending preset data to the load, so that the load generates the first calibration based on the preset data and the preset key. Test data.
  • the processor 802 is further configured to perform the following steps: obtain an encrypted preset key, decrypt the encrypted preset key to obtain the preset key; Set the key and preset data to generate second verification data; compare the first verification data with the second verification data; if the first verification data and the second verification data are the same , It is determined that the first verification data has passed the verification; if the first verification data and the second verification data are not the same, it is determined that the first verification data has not passed the verification.
  • the adapter device 80 is installed on a carrier of the load, and the carrier of the load is used to connect with the movable platform.
  • the switching device 80 and the movable platform are provided by the first party, and the load is provided by the second party.
  • the switching device 80 provided in this embodiment can execute the steps performed by the switching device in the foregoing embodiments, and the execution method and beneficial effects thereof are similar, and details are not described herein again.
  • the embodiment of the present invention may also provide a carrier assembly, including the adapter device and the carrier described above.
  • the adapter device is mounted on the carrier, specifically, it can be set on the carrier. It is used to connect with the load, and as an intermediate adapter.
  • the adapter device here can also be a device including the carrier, that is, the pan-tilt is a part of the adapter device.
  • the switching device is provided with an interface for connecting the load to realize the communication connection between the load, the carrier, and the movable platform.
  • FIG. 9 is a schematic structural diagram of a load provided by an embodiment of the present invention.
  • the load 90 in the embodiment of the present invention includes a memory 901 and a processor 902.
  • the memory 901 and the processor 902 are connected by one or more communication buses.
  • the memory 901 may include a volatile memory (Volatile Memory), such as a random access memory (Random-Access Memory, RAM); the memory 901 may also include a non-volatile memory (Non-Volatile Memory), such as a flash memory (Flash Memory), Solid-State Drive (SSD), etc.; the memory 901 may also include a combination of the foregoing types of memories.
  • volatile memory such as a random access memory (Random-Access Memory, RAM
  • non-Volatile Memory such as a flash memory (Flash Memory), Solid-State Drive (SSD), etc.
  • flash Memory Flash Memory
  • SSD Solid-State Drive
  • the processor 902 may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (Digital Signal Processors, DSPs), and application specific integrated circuits (Application Specific Integrated Circuits). , ASIC), ready-made programmable gate array (Field-Programmable Gate Array, FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc.
  • the general-purpose processor may be a microprocessor or the processor may also be any conventional processor or the like.
  • the load 90 of the embodiment of the present invention can be used by the processor 902 to implement the method implemented by each embodiment of the present invention shown in FIG. 2 or FIG.
  • the processor 902 can be used by the processor 902 to implement the method implemented by each embodiment of the present invention shown in FIG. 2 or FIG.
  • For related parts please refer to the embodiments of the present invention shown in FIG. 2 or FIG. 3 for implementation.
  • the memory 901 stores program instructions
  • the processor 902 calls the program instructions in the memory 901.
  • the processor 902 is configured to: receive a load authentication request sent by a mobile platform Based on the load authentication request, the load authentication information of the load 90 is sent to the movable platform, so that the movable platform determines the function authority of the load 90 determined by the load authentication information The open function between the load 90 and the movable platform.
  • the load authentication information includes a firewall level certificate
  • the firewall level certificate is used to indicate the firewall level corresponding to the open function.
  • the firewall level certificate is encrypted information.
  • the firewall level certificate is updatable.
  • the open function includes at least one of the following: allowing the mobile platform to transfer data to the load 90 or the carrier of the load 90, allowing the load 90 or the load The data transmission function of the carrier of the load 90 to the movable platform.
  • the data transmission function allowing the movable platform to the load 90 or the carrier of the load 90 includes at least one of the following: The transmission function of the control command of the carrier; the transmission function of the positioning data of the movable platform; the transmission function of the multimedia data obtained by the movable platform from the ground terminal.
  • the data transmission function that allows the load 90 or the carrier of the load 90 to the movable platform includes at least one of the following: a transmission function of collected data of the load 90; The transmission function of the load 90 to the control command of the movable platform.
  • the open function includes at least one of the following: a control-related function, an image-related function, an audio-related function, and a positioning-related function.
  • the same open function includes different function levels, and the function levels are adapted to the determined function permissions.
  • the load 90 is communicatively connected with the movable platform through a switching device, and the communication interaction between the load 90 and the movable platform is transmitted via the switching device.
  • the movable platform is provided by a first party, and the load 90 is provided by a second party.
  • the load 90 provided in this embodiment can execute the steps executed by the load in the foregoing embodiment, and its execution manner and beneficial effects are similar, and will not be repeated here.
  • the embodiment of the present invention also provides a computer-readable storage medium, the computer-readable storage medium stores computer program instructions, and when the computer program instructions are executed by a processor, they are used to execute the Functions implemented by mobile platforms.
  • the embodiment of the present invention also provides a computer-readable storage medium, the computer-readable storage medium stores computer program instructions, and when the computer program instructions are executed by a processor, they are used to execute the implementation described in FIG. 3 or FIG. 5 The function realized by the switching device in the example.
  • the embodiment of the present invention also provides a computer-readable storage medium, the computer-readable storage medium stores computer program instructions, and when the computer program instructions are executed by a processor, they are used to execute the Functions implemented by the load.
  • the program can be stored in a readable storage medium, and the program can be stored in a readable storage medium. During execution, it may include the procedures of the above-mentioned method embodiments.
  • the storage medium may be a magnetic disk, an optical disc, a read-only memory (Read-Only Memory, ROM), or a random access memory (Random Access Memory, RAM), etc.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Telephonic Communication Services (AREA)

Abstract

L'invention concerne un procédé et un système d'authentification de charge, une plateforme mobile, une charge et un dispositif de transfert. Le système d'authentification de charge comprend une plateforme mobile et une charge. Le procédé d'authentification de charge comprend les étapes suivantes : lorsqu'une plateforme mobile détecte qu'une charge est connectée à celle-ci, la plateforme mobile envoie une demande d'authentification de charge à la charge ; la charge reçoit la demande d'authentification de charge envoyée par la plateforme mobile, et envoie, en fonction de la demande d'authentification de charge, des informations d'authentification de charge de celle-ci à la plateforme mobile ; la plateforme mobile reçoit les informations d'authentification de charge envoyées par la charge, et détermine, selon les informations d'authentification de charge, une autorisation de fonction de la charge ; et la plateforme mobile détermine une fonction d'exposition entre la charge et la plateforme mobile selon l'autorisation de fonction. Dans un mode de réalisation de la présente invention, des autorisations de fonction d'une charge peuvent être définies en fonction d'informations d'authentification de charge, ce qui améliore la fiabilité de la charge et, en conséquence, assure la sécurité d'une plateforme mobile.
PCT/CN2019/130967 2019-12-31 2019-12-31 Procédé et système d'authentification de charge, plateforme mobile, charge et dispositif de transfert WO2021134712A1 (fr)

Priority Applications (2)

Application Number Priority Date Filing Date Title
CN201980095977.7A CN113767605A (zh) 2019-12-31 2019-12-31 一种负载认证方法及系统、可移动平台、负载、转接装置
PCT/CN2019/130967 WO2021134712A1 (fr) 2019-12-31 2019-12-31 Procédé et système d'authentification de charge, plateforme mobile, charge et dispositif de transfert

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2019/130967 WO2021134712A1 (fr) 2019-12-31 2019-12-31 Procédé et système d'authentification de charge, plateforme mobile, charge et dispositif de transfert

Publications (1)

Publication Number Publication Date
WO2021134712A1 true WO2021134712A1 (fr) 2021-07-08

Family

ID=76686322

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2019/130967 WO2021134712A1 (fr) 2019-12-31 2019-12-31 Procédé et système d'authentification de charge, plateforme mobile, charge et dispositif de transfert

Country Status (2)

Country Link
CN (1) CN113767605A (fr)
WO (1) WO2021134712A1 (fr)

Citations (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104936180A (zh) * 2015-06-26 2015-09-23 陈昊 一种针对无人机和地面站提供鉴权服务的鉴权系统及方法
CN107040560A (zh) * 2016-02-04 2017-08-11 阿里巴巴集团控股有限公司 一种基于业务平台的业务处理方法及装置
CN107054677A (zh) * 2015-12-24 2017-08-18 松下电器(美国)知识产权公司 无人飞行器及其控制方法
CN107409174A (zh) * 2015-03-31 2017-11-28 深圳市大疆创新科技有限公司 用于管制无人飞行器操作的系统和方法
US9875592B1 (en) * 2016-08-30 2018-01-23 International Business Machines Corporation Drone used for authentication and authorization for restricted access via an electronic lock
CN109064599A (zh) * 2018-07-27 2018-12-21 新华三技术有限公司 权限认证方法及装置
US20190199534A1 (en) * 2017-12-27 2019-06-27 International Business Machines Corporation Managing in-flight transfer of parcels using blockchain authentication
CN109995719A (zh) * 2017-12-29 2019-07-09 中移(杭州)信息技术有限公司 一种无人机认证方法、系统、无人机监管平台和第一设备
CN110326033A (zh) * 2017-02-20 2019-10-11 三星电子株式会社 用于控制无人驾驶飞行器的电子装置及操作该电子装置的方法

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US9651944B2 (en) * 2015-03-22 2017-05-16 Microsoft Technology Licensing, Llc Unmanned aerial vehicle piloting authorization
WO2019178828A1 (fr) * 2018-03-23 2019-09-26 深圳市大疆创新科技有限公司 Procédé, appareil et système de commande

Patent Citations (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107409174A (zh) * 2015-03-31 2017-11-28 深圳市大疆创新科技有限公司 用于管制无人飞行器操作的系统和方法
CN104936180A (zh) * 2015-06-26 2015-09-23 陈昊 一种针对无人机和地面站提供鉴权服务的鉴权系统及方法
CN107054677A (zh) * 2015-12-24 2017-08-18 松下电器(美国)知识产权公司 无人飞行器及其控制方法
CN107040560A (zh) * 2016-02-04 2017-08-11 阿里巴巴集团控股有限公司 一种基于业务平台的业务处理方法及装置
US9875592B1 (en) * 2016-08-30 2018-01-23 International Business Machines Corporation Drone used for authentication and authorization for restricted access via an electronic lock
CN110326033A (zh) * 2017-02-20 2019-10-11 三星电子株式会社 用于控制无人驾驶飞行器的电子装置及操作该电子装置的方法
US20190199534A1 (en) * 2017-12-27 2019-06-27 International Business Machines Corporation Managing in-flight transfer of parcels using blockchain authentication
CN109995719A (zh) * 2017-12-29 2019-07-09 中移(杭州)信息技术有限公司 一种无人机认证方法、系统、无人机监管平台和第一设备
CN109064599A (zh) * 2018-07-27 2018-12-21 新华三技术有限公司 权限认证方法及装置

Also Published As

Publication number Publication date
CN113767605A (zh) 2021-12-07

Similar Documents

Publication Publication Date Title
JP7018109B2 (ja) 機器の安全なプロビジョニングと管理
JP6262278B2 (ja) アクセス制御クライアントの記憶及び演算に関する方法及び装置
US9032493B2 (en) Connecting mobile devices, internet-connected vehicles, and cloud services
CN112260995B (zh) 接入认证方法、装置及服务器
WO2018050081A1 (fr) Procédé et appareil d'authentification d'identité de dispositif, et support de stockage
EP2973188B1 (fr) Dispositif secondaire comme clé d'autorisation d'accès aux ressources
KR102540090B1 (ko) 전자 장치 및 그의 전자 키 관리 방법
KR20160121775A (ko) 모바일 단말과 IoT기기간 제3자 보안인증 시스템 및 방법
CN113572728B (zh) 认证物联网设备的方法、装置、设备及介质
KR102402705B1 (ko) 망분리 환경에서의 모바일 원격 관제를 위한, 제로 트러스트 모델 기반 멀티팩터 보안인증 방법 및 서버
CN111431840A (zh) 安全处理方法和装置
CN104994503B (zh) 一种移动应用访问方法
WO2021134712A1 (fr) Procédé et système d'authentification de charge, plateforme mobile, charge et dispositif de transfert
CN110247877A (zh) 一种离线管理指令的管理方法和终端
CN111143832A (zh) 适用于多场景的移动端sdk及其混合授权方法
CN112995717A (zh) 视频传输控制方法、装置、电子设备与智能眼镜
US20220350586A1 (en) Methods of Distributing Software/Firmware Updates
US20220124245A1 (en) Software application license management of camera device through mediation device
CN117354001A (zh) 车联网系统的访问方法、云服务器、被控端和车联网系统
CN117499918A (zh) 升级设备接入云端的方法、装置、电子设备及存储介质
CN115292673A (zh) 容器应用授权方法、装置、可读存储介质及电子设备
CN112805702A (zh) 仿冒app识别方法及装置
CN114884963A (zh) 数字证书的管理方法和管理装置

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 19958286

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 19958286

Country of ref document: EP

Kind code of ref document: A1