Physical layer authentication method for bidirectional privacy protection unmanned aerial vehicle assisted MIMO (Multiple Input Multiple Output) system

By adopting a bidirectional authentication framework based on CFO and ECC in the UAV-assisted MIMO system, the challenges of high dynamics and privacy protection in the UAV system are solved, efficient identity authentication and privacy protection are achieved, and the robustness and security of the system are enhanced.

CN120751379APending Publication Date: 2025-10-03NANJING UNIV OF POSTS & TELECOMM
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510942456.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-09
Publication Date
2025-10-03

AI Technical Summary

Technical Problem

UAV-assisted MIMO communication systems face the challenges of high dynamics and limited computing resources. Existing privacy protection strategies have high computational overhead and are vulnerable to co-location identity spoofing attacks, leading to privacy data leakage. Traditional upper-layer authentication methods have high latency and communication overhead in UAV systems.

Method used

A two-way authentication framework based on the carrier frequency offset (CFO) statistical model and elliptic curve cryptography (ECC) is adopted. The data frame is encrypted through the CFO session key negotiation algorithm. The MOOSE algorithm is used to track CFO and an identity authentication framework is designed to enhance the privacy protection and robustness of the system.

Benefits of technology

The authentication accuracy and privacy protection capability of the UAV-assisted MIMO system are improved, the computational overhead is reduced, the ability to resist eavesdropping and location tracking attacks is enhanced, and greater robustness and privacy are provided.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120751379A_ABST
    Figure CN120751379A_ABST
Patent Text Reader

Abstract

The invention belongs to the field of unmanned aerial vehicle auxiliary MIMO system physical layer authentication, and discloses a bidirectional privacy protection unmanned aerial vehicle auxiliary MIMO system physical layer authentication method, which comprises the following steps: step 1, considering a frame consisting of a pilot frequency and a data symbol, and establishing a carrier frequency offset statistical model representing the identity of an unmanned aerial vehicle; step 2, establishing a CFO session key negotiation algorithm based on the carrier frequency offset statistical model and the elliptic curve cryptography; 3, designing an unmanned aerial vehicle identity bidirectional authentication framework to complete identity authentication based on a carrier frequency offset statistical model and a CFO session key negotiation algorithm; and 4, based on the carrier-free frequency offset statistical model, performing authentication performance analysis, and quantifying the authentication effect. Compared with the prior art, the method has the advantages that the robustness and the accuracy of attacking identity-based impersonation attacks are better.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of physical layer authentication of drone-assisted MIMO systems, and specifically relates to a physical layer authentication method for drone-assisted MIMO systems with bidirectional privacy protection. Background Art

[0002] Unmanned aerial vehicles (UAVs) have seen rapid growth in many fields thanks to their high mobility and low deployment costs. Drone-assisted communications have become an effective solution for providing wide-area coverage and dynamic capacity. Multiple-input, multiple-output (MIMO) technology has been widely adopted in terrestrial networks due to its excellent diversity performance and spectral efficiency. However, due to the inherent openness of wireless networks and the highly dynamic nature of network topologies, UAV-assisted communication systems are vulnerable to spoofing and eavesdropping attacks.

[0003] One of the core security requirements for drone deployment is the design of appropriate authentication schemes to ensure that only legitimate devices can participate in wireless communications. Traditionally, authentication methods based on upper-layer protocols have been widely used for device authentication and have been proven to be effective and feasible. However, due to the inherent characteristics of drones, such as high dynamics and limited computing resources, these upper-layer authentication methods face significant challenges in drone-assisted communication systems. As a supplement or enhancement to traditional methods, physical layer (PHY layer) authentication is considered a potential solution to the drone identity authentication problem due to its lower authentication latency and communication overhead.

[0004] Prior art proposes a framework for mobile drone authentication based on PHY-layer channel characteristics and transmitter location, and extends it to dual-drone scenarios. Prior art also proposes a PHY-layer authentication scheme for heterogeneous coexisting MIMO systems, leveraging location-dependent channel gain and phase noise caused by transmitter oscillator imperfections to enable transmitter identification. The scheme's stealth, robustness, and security are evaluated.

[0005] While existing research has made significant contributions to the design of PHY-layer authentication schemes, privacy protection remains a topic worthy of further exploration due to security concerns and concerns about eavesdropping attacks. Current mainstream privacy protection strategies often come with high computational overhead, posing a challenge for resource-constrained drone-assisted MIMO communication systems. Furthermore, the high maneuverability of drones can lead to rapid channel changes, allowing attackers to launch co-location identity spoofing attacks, resulting in privacy breaches. If an illegal drone approaches a legitimate drone, its channel characteristics, such as signal strength, latency, and multipath propagation, may be highly similar to those of the legitimate drone, making it difficult to distinguish. Existing research often assumes the trustworthiness of the ground control station (GCS), guaranteeing only the security of communications between the GCS and drones. However, if the GCS is compromised or maliciously manipulated, such as by sending malicious commands to alter the route or disable security protocols, it poses a serious threat. Summary of the Invention

[0006] To address the above technical issues, this application provides a bidirectional privacy-preserving physical layer authentication method for drone-assisted MIMO systems. This method encrypts data frames by utilizing the carrier frequency offset (CFO) that characterizes the drone's identity and a CFO session key constructed based on elliptic curve cryptography (ECC). The framework proposed in this application outperforms state-of-the-art methods in both robustness and accuracy against identity-based impersonation attacks, demonstrating its superiority in identity authentication and privacy protection. Compared with existing solutions, this framework has greater robustness and privacy.

[0007] In order to achieve the above objectives, this application is implemented through the following technical solutions:

[0008] The present application discloses a physical layer authentication method for a bidirectional privacy-preserving drone-assisted MIMO system. The physical layer authentication method is implemented through an enhanced bidirectional privacy-preserving drone-assisted MIMO system physical layer authentication framework. The enhanced bidirectional privacy-preserving drone-assisted MIMO system physical layer authentication framework utilizes a carrier frequency offset (CFO) statistical model that characterizes drone identity and a CFO session key agreement algorithm based on elliptic curve cryptography (ECC) to encrypt data frames. The method specifically includes the following steps:

[0009] Step 1: Consider a frame consisting of pilot and data symbols and establish a carrier frequency offset (CFO) statistical model to characterize the identity of the drone.

[0010] Step 2: Based on the carrier frequency offset (CFO) statistical model and elliptic curve cryptography (ECC) that characterizes the identity of the drone, a CFO session key negotiation algorithm is established, i.e., the negotiation key K ses ;

[0011] Step 3: Based on the carrier frequency offset (CFO) statistical model of the drone identity and the CFO session key negotiation algorithm, a two-way authentication framework for the drone identity is designed to complete the identity authentication;

[0012] Step 4: Based on the carrier frequency offset (CFO) statistical model of the drone identity, perform authentication performance analysis and quantify the authentication effect.

[0013] The further improvement of this application is that: Step 1 establishes a carrier frequency offset (CFO) statistical model to characterize the identity of the drone, which specifically includes the following steps:

[0014] Step 1.1, in the UAV-assisted dynamic MIMO communication system, the carrier frequency offset (CFO) statistical model of the nth transmit-receive antenna pair in the kth transmission frame at the transmitter and receiver is modeled as;

[0015]

[0016] in, is the carrier frequency offset (CFO) caused by constant oscillator mismatch for the nth transmit-receive antenna pair in the kth frame, is the carrier frequency offset (CFO) caused by the Doppler effect in the kth frame for the nth transmit-receive antenna pair, n=1,2,…,N,N=N t ×N r , N is the number of transmit-receive antenna pairs, N t is the number of transmitting antennas in the transmitting-receiving antenna pair; N r The number of receiving antennas in a transmit-receive antenna pair; is the time coefficient of the carrier frequency offset (CFO) between two consecutive frames, ξ n (k) is the random change of the carrier frequency offset (CFO) of the nth frame on the kth frame, and ε n (k) is uncorrelated and obeys a Gaussian distribution, i.e. Follow Jakes model every m frames is the variance of the carrier frequency offset (CFO) caused by the Doppler effect, J0(·) is the zero-order Bessel function, f D is the carrier frequency offset (CFO) caused by the maximum normalized Doppler effect;

[0017] Step 1.2: The pilot tracks the carrier frequency offset (CFO) based on the MOOSE algorithm and estimates the carrier frequency offset (CFO). In the kth frame, the received signal y of the nth transmit-receive antenna pair is n (i,k) is:

[0018]

[0019] Among them, ε n (k) is the carrier frequency offset (CFO) of the nth transmit-receive antenna pair in the kth frame, h n (k) is the quasi-static unknown channel coefficient of the nth transmit-receive antenna pair in the kth frame, s(i,k) is the i-th transmitted symbol in the kth frame, and w n (i,k) is a variable with variance The complex additive Gaussian white noise is

[0020] A further improvement of the present application is that the step 2 specifically includes the following steps:

[0021] Step 2.1: The transmitter sends a request frame. The receiver uses the MOOSE algorithm to estimate the carrier frequency offset (CFO) from the received request frame. The receiver verifies the identity of the transmitter using the upper-layer protocol method. If the transmitter is in the list of legal drones, the receiver accepts the request frame and stores the estimated carrier frequency offset (CFO) value. If the transmitter is not in the list of legal drones, the receiver rejects the request frame.

[0022] Step 2.2, the receiving end sends an ACK frame (acknowledgement frame) to the transmitting end. If the value of ACK is equal to 1, the transmitting end receives the signal y n (i, k) Estimate the carrier frequency offset (CFO) value and perform identity authentication. Otherwise, the transmitter rebroadcasts the request frame. If the receiver is confirmed to be a legitimate communication party, the transmitter stores the estimated carrier frequency offset (CFO) value and prepares for key negotiation. Otherwise, the transmitter rebroadcasts the request frame and notifies the receiver at the same time.

[0023] Step 2.3, the transmitter and receiver negotiate the session key: introduce the elliptic curve cryptography (ECC) algorithm, based on the received signal y n The estimated carrier frequency offset (CFO) value in (i, k) is used. The transmitter and receiver negotiate a key based on the legitimacy of each other's identities. After the key negotiation, the transmitter and receiver obtain the same session key and use the session key to encrypt the data frame to protect the privacy of subsequent communications.

[0024] Step 2.4: Encrypt and transmit data frames. The transmitter sends data frames encrypted with the session key to the receiver. The receiver receives the data frame based on the received signal y. n (i, k) Estimate the carrier frequency offset (CFO) value and perform physical layer authentication. If the identity of the transmitter is confirmed to be legitimate, the receiver uses the session key to decrypt the data frame and uses the information in it for subsequent authentication analysis. At the same time, it updates the stored estimated carrier frequency offset (CFO) value. If the identity of the transmitter is confirmed to be illegal, the receiver directly rejects the data frame without decrypting it.

[0025] Step 2.5: Encrypt and transmit instructions. The receiving end sends the encrypted instructions to the transmitting end. Similarly, the transmitting end receives the signal y. n (i, k) Estimate the carrier frequency offset (CFO) value and perform physical layer identity authentication. The transmitter verifies the legitimacy of the sender's identity. If the detection passes, the transmitter uses the session key to decrypt and execute the instruction, while updating the stored estimated carrier frequency offset (CFO) value. If the detection fails, the transmitter directly refuses to execute the instruction and sends an encrypted frame to the receiver, indicating that there is an illegal transmitter in the communication environment and requesting the correct instruction;

[0026] Step 2.6: Establish a privacy protection strategy that utilizes the physical layer hardware characteristics CFO, that is, establish a CFO session key negotiation algorithm to achieve privacy data protection in communication and effectively resist eavesdropping and location tracking attacks.

[0027] A further improvement of the present application is that in step 2.6, the specific method for establishing the CFO session key agreement algorithm is:

[0028] Step 2.6.1. Construct a secure base point based on elliptic curve cryptography (ECC): The elliptic curve on is described as a plane algebraic curve:

[0029] Y={(x,y)|y 2 =x 3 +ax+b}

[0030] Where a and b are finite fields The constant in , and satisfy 4a 3 +27b 2 ≠0 ensures the non-singularity of the elliptic curve;

[0031] Step 2.6.2, the transmitter receives the signal y n Extract the estimated value of carrier frequency offset (CFO) from (i,k) Variance of carrier frequency offset (CFO) Used as the private key of the transmitter Among them, A is the legal transmitter and B is the receiver;

[0032] Step 2.6.3. The private key obtained in step 2.6.1 Based on the data, the transmitter obtains the base point G of the elliptic curve from the transmitter memory and calculates the public key of the transmitter The transmitter uses upper-layer cryptography to encrypt the public key and timestamp and send to the receiving end;

[0033] Step 2.6.4, the receiving end receives the signal y n Extract the estimated value of carrier frequency offset (CFO) from (i,k) Calculate the variance of the carrier frequency offset (CFO) and will Serves as the receiving end's private key

[0034] Step 2.6.5. The private key obtained in step 2.6.4 Based on the data, the receiver obtains the base point G from the drone's memory and calculates the public key of the receiver. The receiving end uses upper-level cryptography methods to encrypt the public key and timestamp and send it to the transmitter; so far, Alice and Bob have obtained the data basis for independently calculating the negotiated key required for subsequent encryption and decryption.

[0035] Step 2.6.6. Calculate the session key based on the public key and private key of the transmitter and the public key and private key of the receiver obtained in steps 2.6.1-2.6.4:

[0036] For the transmitter, the session key is calculated as follows

[0037]

[0038] For the receiving end, the session key is calculated as follows

[0039]

[0040] The transmitter and receiver share the negotiated key K through the key negotiation process. ses , encrypt and decrypt data frames.

[0041] The further improvement of the present application is that: the estimation of the carrier frequency offset (CFO) value is specifically as follows: for the estimation of the carrier frequency offset (CFO), the preamble code transmitted in the communication channel between the transmitting end and the receiving end is given by an M-point complex modulation sequence, the sequence is composed of 2G+1 complex sine waves orthogonal in the symbol interval, and the preamble code is

[0042]

[0043] After transmission through the communication channel, the complex envelope of the received sequence is:

[0044]

[0045] Among them, h g (k) is the channel transfer function at the g-th carrier frequency, ε(k) is the relative frequency offset of the channel, that is, the ratio of the actual frequency offset to the carrier spacing, is the complex envelope of additive white Gaussian noise (AWGN);

[0046] During demodulation via discrete Fourier transform, the transmitted signal is subject to a frequency offset expressed as

[0047]

[0048] The elements in the discrete Fourier transform sequence consist of three parts, defined as

[0049]

[0050] in, is the channel transfer function h g (k) Modified modulation value X g , The inter-carrier interference (ICI) caused by the frequency offset is is additive white Gaussian noise;

[0051] nth carrier frequency offset (CFO) statistical model ε n Maximum Likelihood Estimation (MLE) of (k) for

[0052]

[0053] Among them, Y 1g (k) represents the received signal composed of the first M point sequence, Y 2g (k) represents the received signal composed of the last M point sequence, Re(·) and Im(·) are used to extract the real part and imaginary part respectively.

[0054] Maximum Likelihood Estimation of Carrier Frequency Offset (CFO) Expressed as the sum of its true value and estimated error, that is,

[0055]

[0056] in, Is a variance The Gaussian estimation error of

[0057] A further improvement of the present application is that: in step 3, identity authentication includes the following steps:

[0058] Step 3.1: Consider identity authentication as a binary hypothesis test, expressed as:

[0059]

[0060] Among them, the null hypothesis H0 indicates that the currently received signal comes from a legal communication link, that is, X=A, and the hypothesis H1 indicates that the signal comes from an illegal communication link, that is, X=E, A is the legal transmitter, and E is the illegal transmitter. is the estimated carrier frequency offset (CFO) of the device to be authenticated, is the estimated carrier frequency offset (CFO) of the legitimate device;

[0061] Step 3.2: Add the estimated values ​​of the carrier frequency offset (CFO) of the N transmit-receive antenna pairs to obtain a variable, let Define the test statistic Z(ε) for the difference in carrier frequency offset (CFO) between the kth frame and the k-1th frame for the nth transmit-receive antenna pair:

[0062]

[0063] Step 3.3, the signal receiver calculates the difference between the carrier frequency offset (CFO) estimate extracted from the received signal of the kth frame and the carrier frequency offset (CFO) estimate stored in the (k-1)th frame, as well as the difference in the carrier frequency offset (CFO) between each channel, and calculates the sum of the squares of the carrier frequency offset (CFO) as the test statistic for binary detection. The signal receiver will perform identity detection by comparing the test statistic Z(ε) with the threshold δ:

[0064]

[0065] If Z(ε)<δ, the receiver makes the H0 judgment, indicating that the current received signal is consistent with the signal transmitter of the previous frame and comes from a legitimate transmitter. The receiver will use the carrier frequency offset (CFO) measurement value obtained at this time to update the stored carrier frequency offset (CFO) and perform subsequent decryption processing on the received signal. If Z(ε)>δ, the receiver makes the H1 judgment, indicating that the sender of the current signal is different from the sender of the previous frame, and the communication has been illegally attacked. The receiver will reject the second frame at time k to complete the identity authentication.

[0066] A further improvement of the present application is that: in step 4, the false alarm probability P is used f and detection probability P d Perform authentication performance analysis, specifically: given a threshold δ, derive the false alarm probability P f The theoretical expression of:

[0067]

[0068] According to the mathematical definition, the false alarm probability P is expressed by the regularized incomplete gamma function. f :

[0069]

[0070] where Q(s,x) is the regularized incomplete gamma function:

[0071]

[0072] Under H1, the test statistic Z(ε) is greater than the threshold δ, that is, Z(ε)>δ,

[0073] Correct detection probability P d Defined as:

[0074]

[0075] Correct detection probability P d Detailed expression:

[0076]

[0077] Therefore, the probability of correct detection is given by the Marcum-Q function:

[0078]

[0079] Among them, μ c is the noncentral parameter, and I is the modified Bessel function.

[0080] The beneficial effects of this application are:

[0081] This application uses the MOOSE algorithm to extract hardware fingerprint features related to drones. Based on the extracted CFO feature parameters, an ECC-based session key negotiation algorithm is designed to achieve identity authentication of network participants.

[0082] This application establishes a two-way authentication framework based on CFO characteristic parameters and applies CFO session keys to encrypt data frames to prevent privacy data leakage.

[0083] This application derives closed-form analytical expressions for detection probability and false alarm probability for rigorous performance analysis.

[0084] This paper verifies the effectiveness of the proposed theoretical model through a large number of numerical experiments and demonstrates its superiority in identity authentication and privacy protection. Compared with existing solutions, the proposed framework has stronger robustness and privacy. BRIEF DESCRIPTION OF THE DRAWINGS

[0085] Figure 1 This is a flowchart of the application authentication method.

[0086] Figure 2 It is a display diagram of the simulation and theoretical results of the false alarm probability and detection probability in the embodiment of the present application.

[0087] Figure 3 This is a drone motion diagram for this application.

[0088] Figure 4 This is a comparison chart of the encryption and decryption effects of this application and the existing solution.

[0089] Figure 5 This is a comparison chart of the effects of this application and the existing solution

[0090] Figure 6 This is a comparison chart of the encryption and decryption effects of this application and the existing solution. DETAILED DESCRIPTION

[0091] The following diagrams illustrate embodiments of the present invention. For clarity, many practical details are included in the following description. However, it should be understood that these practical details are not intended to limit the present invention. In other words, in some embodiments of the present invention, these practical details are not essential.

[0092] like Figure 1 As shown, the present application is a two-way privacy protection UAV-assisted MIMO system physical layer authentication method, which is implemented by an enhanced two-way privacy protection UAV-assisted MIMO system physical layer authentication framework. The enhanced two-way privacy protection UAV-assisted MIMO system physical layer authentication framework utilizes a carrier frequency offset (CFO) statistical model that characterizes the identity of the drone and a CFO session key negotiation algorithm based on elliptic curve cryptography (ECC) to encrypt data frames, specifically including the following steps:

[0093] Step 1: Consider a frame consisting of pilot and data symbols and establish a statistical model of carrier frequency offset (CFO) that characterizes the identity of the drone. The specific steps include:

[0094] Step 1.1, in the UAV-assisted dynamic MIMO communication system, the carrier frequency offset (CFO) statistical model of the nth transmit-receive antenna pair in the kth transmission frame at the transmitter and receiver is modeled as;

[0095]

[0096] in, is the carrier frequency offset (CFO) caused by constant oscillator mismatch for the nth transmit-receive antenna pair in the kth frame, is the carrier frequency offset (CFO) caused by the Doppler effect in the kth frame for the nth transmit-receive antenna pair, n=1,2,…,N,N=N t ×N r , N is the number of transmit-receive antenna pairs, N t is the number of transmitting antennas in the transmitting-receiving antenna pair; N r The number of receiving antennas in a transmit-receive antenna pair; is the time coefficient of the carrier frequency offset (CFO) between two consecutive frames, ξ n (k) is the random change of the carrier frequency offset (CFO) of the nth frame on the kth frame, and ε n (k) is uncorrelated and obeys a Gaussian distribution, i.e. With εn (k) The temporal correlation between them, m frames apart, follows the Jakes model is the variance of the carrier frequency offset (CFO) caused by the Doppler effect, J0(·) is the zero-order Bessel function, f D is the carrier frequency offset (CFO) caused by the maximum normalized Doppler effect;

[0097] Step 1.2: The pilot tracks the carrier frequency offset (CFO) based on the MOOSE algorithm and estimates the carrier frequency offset (CFO). In the kth frame, the received signal y of the nth transmit-receive antenna pair is n (i,k) is:

[0098]

[0099] Among them, ε n (k) is the carrier frequency offset (CFO) of the nth transmit-receive antenna pair in the kth frame, h n (k) is the quasi-static unknown channel coefficient of the nth transmit-receive antenna pair in the kth frame, which is assumed to remain unchanged during the length of the frame; s(i,k) is the i-th transmitted symbol in the kth frame, w n (i,k) is a variable with variance The complex additive Gaussian white noise is

[0100] Step 2: Based on the carrier frequency offset (CFO) statistical model and elliptic curve cryptography (ECC) that characterizes the identity of the drone, a CFO session key negotiation algorithm is established, i.e., the negotiation key K ses The specific steps include:

[0101] Step 2.1: The transmitter sends a request frame. The receiver uses the MOOSE algorithm to estimate the carrier frequency offset (CFO) from the received request frame. The receiver verifies the identity of the transmitter using the upper-layer protocol method. If the transmitter is in the list of legal drones, the receiver accepts the request frame and stores the estimated carrier frequency offset (CFO) value. If the transmitter is not in the list of legal drones, the receiver rejects the request frame.

[0102] Step 2.2, the receiving end sends an ACK frame to the transmitting end, which is a confirmation frame. If the value of ACK is equal to 1, the transmitting end n (i, k) Estimate the carrier frequency offset (CFO) value and perform identity authentication. Otherwise, the transmitter rebroadcasts the request frame. When the receiver is confirmed to be a legitimate communication party, the transmitter stores the estimated carrier frequency offset (CFO) value and prepares for key negotiation. Otherwise, the transmitter rebroadcasts the request frame and notifies the receiver of this situation at the same time.

[0103] Step 2.3, the transmitter and receiver negotiate the session key: introduce the elliptic curve cryptography (ECC) algorithm, based on the received signal y n The estimated carrier frequency offset (CFO) value in (i, k) is used. The transmitter and receiver negotiate a key based on the legitimacy of each other's identities. After the key negotiation, the transmitter and receiver obtain the same session key and use the session key to encrypt the data frame to protect the privacy of subsequent communications.

[0104] Step 2.4: Encrypt and transmit data frames. The transmitter sends data frames encrypted with the session key to the receiver. The receiver receives the data frame based on the received signal y. n (i, k) Estimate the carrier frequency offset (CFO) value and perform physical layer authentication. If the identity of the transmitter is confirmed to be legitimate, the receiver uses the session key to decrypt the data frame and uses the information in it for subsequent authentication analysis. At the same time, it updates the stored estimated carrier frequency offset (CFO) value. If the identity of the transmitter is confirmed to be illegal, the receiver directly rejects the data frame without decrypting it.

[0105] Step 2.5: Encrypt and transmit instructions. The receiving end sends the encrypted instructions to the transmitting end. Similarly, the transmitting end receives the signal y. n (i, k) Estimate the carrier frequency offset (CFO) value and perform physical layer identity authentication. The transmitter verifies the legitimacy of the sender's identity. If the detection passes, the transmitter uses the session key to decrypt and execute the instruction, while updating the stored estimated carrier frequency offset (CFO) value. If the detection fails, the transmitter directly refuses to execute the instruction and sends an encrypted frame to the receiver, indicating that there is an illegal transmitter in the communication environment and requesting the correct instruction;

[0106] Step 2.6: Establish a privacy protection strategy that utilizes the physical layer hardware feature CFO. This involves establishing a CFO session key negotiation algorithm to protect private data during communications and effectively resist eavesdropping and location tracking attacks. The specific method for establishing the CFO session key negotiation algorithm is as follows:

[0107] Step 2.6.1. Construct a secure base point based on elliptic curve cryptography (ECC): The elliptic curve on is described as a plane algebraic curve:

[0108] Y={(x,y)|y 2 =x 3 +ax+b}

[0109] Where a and b are finite fields The constant in , and satisfy 4a 3 +27b 2 ≠0 ensures the non-singularity of the elliptic curve. The key generation process includes defining a and b of the elliptic curve and selecting the base point G. The private key is the variance of the carrier frequency offset (CFO), the public key It is calculated The result, given G and K pub , solving the private key in polynomial time It is not feasible, ensuring the security of the key;

[0110] Step 2.6.2, the transmitter receives the signal y n Extract the estimated value of carrier frequency offset (CFO) from (i,k) Variance of carrier frequency offset (CFO) Used as the private key of the transmitter Among them, A is the legal transmitter and B is the receiver;

[0111] Step 2.6.3. The private key obtained in step 2.6.1 Based on this, the transmitter obtains the base point G of the elliptic curve from the memory and calculates the public key of the transmitter The transmitter uses upper-layer cryptography to encrypt the public key and timestamp and send to the receiving end;

[0112] Step 2.6.4, the receiving end receives the signal y n Extract the estimated value of carrier frequency offset (CFO) from (i,k) Calculate the variance of the carrier frequency offset (CFO) and will Serves as the receiving end's private key

[0113] Step 2.6.5. The private key obtained in step 2.6.4 Based on the data, the receiver obtains the base point G from the drone's memory and calculates the public key of the receiver. The receiving end uses upper-level cryptography methods to encrypt the public key and timestamp and send it to the transmitter; so far, both the transmitter Alice and the receiver Bob have obtained the data basis for independently calculating the negotiated key required for subsequent encryption and decryption.

[0114] Step 2.6.6. Calculate the session key based on the public key and private key of the transmitter and the public key and private key of the receiver obtained in steps 2.6.1-2.6.4:

[0115] For the transmitter, the session key is calculated as follows

[0116]

[0117] For the receiving end, the session key is calculated as follows

[0118]

[0119] The transmitter and receiver share the negotiated key K through the key negotiation process. ses , encrypt and decrypt data frames.

[0120] The estimated carrier frequency offset (CFO) value is specifically as follows: For the estimation of the carrier frequency offset (CFO), the preamble code transmitted in the communication channel between the transmitter and the receiver is given by an M-point complex modulation sequence, and the sequence is composed of 2G+1 complex sine waves orthogonal in the symbol interval. The preamble code is

[0121]

[0122] After transmission through the communication channel, the complex envelope of the received sequence is:

[0123]

[0124] Among them, h g (k) is the channel transfer function at the g-th carrier frequency, ε(k) is the relative frequency offset of the channel, that is, the ratio of the actual frequency offset to the carrier spacing, is the complex envelope of additive white Gaussian noise (AWGN);

[0125] During demodulation via discrete Fourier transform, the transmitted signal is susceptible to frequency offset, expressed as

[0126]

[0127] The elements in the discrete Fourier transform sequence consist of three parts, defined as

[0128]

[0129] in, Channel transfer function h g (k) Modified modulation value X g , which experiences amplitude attenuation and phase shift due to frequency shift, The inter-carrier interference (ICI) caused by the frequency offset is is additive white Gaussian noise;

[0130] If the transmitted symbols are repeated, a 2M-point sequence will be received without noise, and the nth carrier frequency offset (CFO) statistical model ε n Maximum Likelihood Estimation (MLE) of (k) for

[0131]

[0132] Among them, Y 1g (k) represents the received signal composed of the first M point sequence, Y 2g (k) represents the received signal composed of the last M point sequence, Re(·) and Im(·) are used to extract the real part and imaginary part respectively.

[0133] Estimated value of carrier frequency offset (CFO) Expressed as the sum of its true value and estimated error, that is,

[0134]

[0135] in, Is a variance The Gaussian estimation error of

[0136] Step 3: Based on the carrier frequency offset (CFO) statistical model of the drone identity and the CFO session key negotiation algorithm, a two-way drone identity authentication framework is designed to complete identity authentication; identity authentication includes the following steps:

[0137] Step 3.1: Consider identity authentication as a binary hypothesis test, expressed as:

[0138]

[0139] Among them, the null hypothesis H0 indicates that the currently received signal comes from a legal communication link, that is, X=A, and the hypothesis H1 indicates that the signal comes from an illegal communication link, that is, X=E, A is the legal transmitter, and E is the illegal transmitter. is the estimated carrier frequency offset (CFO) of the device to be authenticated, is the estimated carrier frequency offset (CFO) of the legitimate device;

[0140] Step 3.2: Add the estimated values ​​of the carrier frequency offset (CFO) of the N transmit-receive antenna pairs to obtain a variable, let Define the test statistic Z(ε) for the difference in carrier frequency offset (CFO) between the kth frame and the k-1th frame for the nth transmit-receive antenna pair:

[0141]

[0142] Step 3.3, the signal receiver calculates the difference between the carrier frequency offset (CFO) estimate extracted from the received signal of the kth frame and the carrier frequency offset (CFO) estimate stored in the (k-1)th frame, as well as the difference in the carrier frequency offset (CFO) between each channel, and calculates the sum of the squares of the carrier frequency offset (CFO) as the test statistic for binary detection. The signal receiver will perform identity detection by comparing the test statistic Z(ε) with the threshold δ:

[0143]

[0144] If Z(ε)<δ, the receiver makes the H0 judgment, indicating that the current received signal is consistent with the signal transmitter of the previous frame and comes from a legitimate transmitter. The receiver will use the carrier frequency offset (CFO) measurement value obtained at this time to update the stored carrier frequency offset (CFO) and perform subsequent decryption processing on the received signal. If Z(ε)>δ, the receiver makes the H1 judgment, indicating that the sender of the current signal is different from the sender of the previous frame, and the communication has been illegally attacked. The receiver will reject the second frame at time k to complete the identity authentication.

[0145] Step 4: Based on the carrier frequency offset (CFO) statistical model of the drone identity, perform authentication performance analysis and quantify the authentication effect. In this step, the false alarm probability P is used. f and detection probability P d Perform authentication performance analysis, specifically:

[0146] Under H0, the test statistic Z(ε) is greater than the threshold δ, that is, Z(ε)>δ, which causes the signal receiver to make an incorrect identity judgment. Given the threshold δ, the false alarm probability P is derived f The theoretical expression of:

[0147]

[0148] According to the mathematical definition, the false alarm probability P is expressed by the regularized incomplete gamma function. f :

[0149]

[0150] where Q(s,x) is the regularized incomplete gamma function:

[0151]

[0152] The detection probability refers to the probability that the signal sent by the illegal device Eve is successfully authenticated as an illegal signal. In other words, under H1, the test statistic Z(ε) is greater than the threshold δ, that is, Z(ε)>δ,

[0153] Correct detection probability P dDefined as:

[0154]

[0155] Correct detection probability P d Detailed expression:

[0156]

[0157] This integral is identified as the complementary cumulative distribution function (CCDF) of the noncentral chi-squared distribution, which is equivalent to the Marcum-Q function:

[0158] Therefore, the probability of correct detection is given by the Marcum-Q function:

[0159]

[0160] Among them, μ c is the non-central parameter.

[0161] This application conducted a simulation experiment in which the air-to-ground system operated at a 2.4 GHz radio carrier frequency, with the flight speed of the legal drone Alice and the illegal drone Eve at 100 km / h. This application set the actual CFO value between the legal communication link Alice and Bob to 0.1 rad, and the actual CFO value between the illegal communication link Eve and Bob to 0.2 rad. The number of transmitting and receiving antennas was set to N t =N r =2. The transmission symbol uses OFDM modulation, the fast Fourier transform size is M=128, and the sampling frequency is 10kHz. This application can simulate different communication scenarios by adjusting the above parameters. For the convenience of the experiment, this application assumes that the encryption and decryption process has no effect on the extraction of CFO. This application conducts 10 4 A simulation experiment was conducted to verify this application.

[0162] This application focuses on verifying P f and P d Theoretical model. Figure 2 As shown, the close alignment of simulation and theoretical results demonstrates the effectiveness of the proposed method in simulating false alarms and detection probabilities. Figure 2 As shown, it can be observed that when the SNR is in [0,8]dB and the threshold δ is high, the detection probability P d There is a slight discrepancy between the theoretical value and the simulation results. This discrepancy stems from CFO estimation errors. However, as the SNR increases, the CFO can be estimated more accurately, resulting in a seamless match between the theoretical and simulation curves. Therefore, this application can be used to characterize the authentication performance of the proposed scheme.

[0163] from Figure 2It can be seen that as the SNR increases, the false alarm probability P f Significantly reduced, the detection probability P d This is attributed to the reduced effect of noise interference at higher SNR, which promotes more accurate CFO estimation. In addition, at a constant SNR, the increase in threshold leads to a decrease in P f and P d This is because for P f , a higher threshold enhances the fault tolerance, resulting in a lower false alarm probability. Similarly, for P d ,A higher threshold brings a higher authentication threshold, resulting in a lower detection probability.,It is important to choose an appropriate threshold so that both the detection probability and the false alarm probability can,show good results.

[0164] This application compares the performance of existing solutions with the authentication method of this application. Existing solutions implement device identity authentication and privacy data protection solutions based on channel characteristics. However, channel-based methods are actually location-based authentication methods.

[0165] When the position of the drone changes, the channel characteristics will also change accordingly. This application assumes that the initial positions of the legal drone Alice, the illegal drone Eve and the ground control station Bob are as follows: Figure 3 shown.

[0166] from Figure 4 As can be seen, even slight changes in the drone's position can alter the channel characteristics. Furthermore, due to the drone's high-speed movement and numerous position changes in a short period of time, the channel characteristics vary significantly. Therefore, existing device authentication schemes that protect private data are not suitable for high-speed mobile drone communication systems.

[0167] This application further compares the performance of the existing scheme and the authentication scheme of this application. Figure 5 As shown in Figure 2, when the position of the drone changes, the channel gain variance between the drone and the GCS fluctuates significantly. This variance is a key parameter of the authentication scheme proposed in the existing scheme. In contrast, the CFO variance between the same drone and the base station remains basically unchanged, providing strong support for drone identity authentication in high-speed mobile scenarios. This application uses the detection probability P d The performance of the existing solution of this application is compared. When the position of the drone changes, the P d dropped sharply, while the P d This shows that although the authentication performance of the existing schemes decreases as the location of the drone changes, the scheme proposed in this application maintains superior identity authentication performance.

[0168] This application verifies the privacy protection capability of the proposed authentication scheme. Assume that an unauthorized attacker can obtain the encryption and decryption scheme, and the data is initially encrypted using the legitimate session key SKey. A Encryption. Figure 6 As shown, when using the legal session key SKey A When decrypted, the decrypted data exactly matches the data before encryption. This shows that the authentication method of this application ensures the integrity of the data. However, when an unauthorized session key SKey is used E During decryption, the decrypted data does not correspond to the original data and introduces a large amount of interference data. This is because the CFO variances between the legal and illegal communication links are different, expressed as and In addition, the base point G in the elliptic curve is protected by the upper layer protocol, making it inaccessible to unauthorized attackers. This results in unauthorized session key SKey E and the valid session key SKey A The difference between the two makes it impossible to accurately decrypt the encrypted data. It demonstrates the effectiveness of this application and ensures data security.

[0169] The foregoing is merely an embodiment of the present invention and is not intended to limit the present invention. It will be apparent to those skilled in the art that various modifications and variations of the present invention are possible. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention are intended to be included within the scope of the claims of the present invention.

Claims

1. A physical layer authentication method for a bidirectional privacy-preserving drone-assisted MIMO system, characterized by: The two-way privacy-preserving UAV-assisted MIMO system physical layer authentication method is implemented through an enhanced two-way privacy-preserving UAV-assisted MIMO system physical layer authentication framework. The enhanced two-way privacy-preserving UAV-assisted MIMO system physical layer authentication framework utilizes a carrier frequency offset (CFO) statistical model that characterizes the identity of the UAV and a CFO session key negotiation algorithm based on elliptic curve cryptography (ECC) to encrypt data frames. The method specifically includes the following steps: Step 1: Consider a frame consisting of pilot and data symbols and establish a carrier frequency offset (CFO) statistical model to characterize the identity of the drone. Step 2: Based on the carrier frequency offset (CFO) statistical model and elliptic curve cryptography (ECC) that characterizes the identity of the drone, a CFO session key negotiation algorithm is established, i.e., the negotiation key K ses ; Step 3: Based on the carrier frequency offset (CFO) statistical model of the drone identity and the CFO session key negotiation algorithm, a two-way authentication framework for the drone identity is designed to complete the identity authentication; Step 4: Based on the carrier frequency offset (CFO) statistical model of the drone identity, perform authentication performance analysis and quantify the authentication effect.

2. The physical layer authentication method for a two-way privacy-preserving drone-assisted MIMO system according to claim 1, characterized in that: Step 1: Establish a carrier frequency offset (CFO) statistical model to characterize the drone's identity. The specific steps include: Step 1.1, in the UAV-assisted dynamic MIMO communication system, the carrier frequency offset (CFO) statistical model of the nth transmit-receive antenna pair in the kth transmission frame at the transmitter and receiver is modeled as; in, is the carrier frequency offset (CFO) caused by constant oscillator mismatch for the nth transmit-receive antenna pair in the kth frame, is the carrier frequency offset (CFO) caused by the Doppler effect in the kth frame for the nth transmit-receive antenna pair, n=1,2,…,N,N=N t ×N r , N is the number of transmit-receive antenna pairs, N t is the number of transmitting antennas in the transmitting-receiving antenna pair, N r The number of receiving antennas in a transmit-receive antenna pair, is the time coefficient of the carrier frequency offset (CFO) between two consecutive frames, ξ n (k) is the random change of the carrier frequency offset (CFO) of the nth frame on the kth frame, and ε n (k) is uncorrelated and obeys a Gaussian distribution, i.e. Follow Jakes model every m frames is the variance of the carrier frequency offset (CFO) caused by the Doppler effect, J0(·) is the zero-order Bessel function, f D is the carrier frequency offset (CFO) caused by the maximum normalized Doppler effect; Step 1.2: The pilot tracks the carrier frequency offset (CFO) based on the MOOSE algorithm and estimates the carrier frequency offset (CFO). In the kth frame, the received signal y of the nth transmit-receive antenna pair is n (i,k) is: Among them, ε n (k) is the carrier frequency offset (CFO) of the nth transmit-receive antenna pair in the kth frame, h n (k) is the quasi-static unknown channel coefficient of the nth transmit-receive antenna pair in the kth frame, s(i,k) is the i-th transmitted symbol in the kth frame, and w n (i,k) is a variable with variance The complex additive Gaussian white noise is 3. The physical layer authentication method for a two-way privacy-preserving drone-assisted MIMO system according to claim 2, characterized in that: The step 2 specifically includes the following steps: Step 2.1: The transmitter sends a request frame. The receiver estimates the carrier frequency offset (CFO) from the received request frame and verifies the identity of the transmitter. If the transmitter is in the list of legal drones, the receiver accepts the request frame and stores the estimated carrier frequency offset (CFO) value. If the transmitter is not in the list of legal drones, the receiver rejects the request frame. Step 2.2, the receiving end sends an ACK frame to the transmitting end, which is a confirmation frame. If the value of ACK is equal to 1, the transmitting end n (i, k) Estimate the carrier frequency offset (CFO) value and perform identity authentication. Otherwise, the transmitter rebroadcasts the request frame. If the receiver is confirmed to be a legitimate communication party, the transmitter stores the estimated carrier frequency offset (CFO) value and prepares for key negotiation. Otherwise, the transmitter rebroadcasts the request frame and notifies the receiver at the same time. Step 2.3, the transmitter and receiver negotiate the session key: introduce the elliptic curve cryptography (ECC) algorithm, based on the received signal y n The estimated carrier frequency offset (CFO) value in (i, k) is used. The transmitter and receiver negotiate a key based on the legitimacy of each other's identities. After the key negotiation, the transmitter and receiver obtain the same session key and use the session key to encrypt the data frame to protect the privacy of subsequent communications. Step 2.4: The transmitter sends a data frame encrypted with the session key to the receiver. The receiver receives the signal y n (i, k) Estimate the carrier frequency offset (CFO) value and perform physical layer authentication. If the identity of the transmitter is confirmed to be legitimate, the receiver uses the session key to decrypt the data frame and uses the information in it for subsequent authentication analysis. At the same time, it updates the stored estimated carrier frequency offset (CFO) value. If the identity of the transmitter is confirmed to be illegal, the receiver directly rejects the data frame without decrypting it. Step 2.5: The receiving end sends an encrypted command to the transmitting end. Similarly, the transmitting end receives the signal y n (i, k) Estimate the carrier frequency offset (CFO) value and perform physical layer identity authentication. The transmitter verifies the legitimacy of the sender's identity. If the detection passes, the transmitter uses the session key to decrypt and execute the instruction, while updating the stored estimated carrier frequency offset (CFO) value. If the detection fails, the transmitter directly refuses to execute the instruction and sends an encrypted frame to the receiver, indicating that there is an illegal transmitter in the communication environment and requesting the correct instruction; Step 2.6: Establish a privacy protection strategy that utilizes the physical layer hardware characteristics CFO, that is, establish a CFO session key negotiation algorithm to achieve privacy data protection in communication and effectively resist eavesdropping and location tracking attacks.

4. The physical layer authentication method for a two-way privacy-preserving drone-assisted MIMO system according to claim 3, characterized in that: In step 2.6, the specific method for establishing the CFO session key agreement algorithm is as follows: Step 2.6.

1. Construct a secure base point based on elliptic curve cryptography (ECC): The elliptic curve on is described as a plane algebraic curve: Y={(x,y)|y 2 =x 3 +ax+b} Where a and b are finite fields The constant in , and satisfy 4a 3 +27b 2 ≠0 ensures the non-singularity of the elliptic curve; Step 2.6.2, the transmitter receives the signal y n Extract the estimated value of carrier frequency offset (CFO) from (i,k) Variance of carrier frequency offset (CFO) Used as the private key of the transmitter Among them, A is the legal transmitter and B is the receiver; Step 2.6.

3. The private key obtained in step 2.6.1 Based on this, the transmitter obtains the base point G of the elliptic curve from the memory and calculates the public key of the transmitter Transmitter encryption public key and timestamp and send to the receiving end; Step 2.6.4, the receiving end receives the signal y n Extract the estimated value of carrier frequency offset (CFO) from (i,k) Calculate the variance of the carrier frequency offset (CFO) and will Serves as the receiving end's private key Step 2.6.

5. The private key obtained in step 2.6.4 Based on the data, the receiver obtains the base point G from the drone's memory and calculates the public key of the receiver. Receiver encryption public key and timestamp and send to the transmitter; Step 2.6.

6. Calculate the session key based on the public key and private key of the transmitter and the public key and private key of the receiver obtained in steps 2.6.1-2.6.4: For the transmitter, the session key is calculated as follows For the receiving end, the session key is calculated as follows The transmitter and receiver share the negotiated key K through the key negotiation process. ses , encrypt and decrypt data frames.

5. The physical layer authentication method for a two-way privacy-preserving drone-assisted MIMO system according to claim 4, characterized in that: The estimated carrier frequency offset (CFO) value is specifically as follows: For the estimation of the carrier frequency offset (CFO), the preamble code transmitted in the communication channel between the transmitter and the receiver is given by an M-point complex modulation sequence, which is composed of 2G+1 complex sine waves orthogonal in the symbol interval. The preamble code is After transmission through the communication channel, the complex envelope of the received sequence is: Among them, h g (k) is the channel transfer function at the g-th carrier frequency, ε(k) is the relative frequency offset of the channel, that is, the ratio of the actual frequency offset to the carrier spacing, is the complex envelope of additive white Gaussian noise (AWGN); During demodulation via discrete Fourier transform, the transmitted signal is subject to a frequency offset expressed as The elements in the discrete Fourier transform sequence consist of three parts, defined as in, is the channel transfer function h g (k) Modified modulation value X g , I Pg (k) is the inter-carrier interference (ICI) caused by the frequency offset, is additive white Gaussian noise; nth carrier frequency offset (CFO) statistical model ε n Maximum Likelihood Estimation (MLE) of (k) for Among them, Y 1g (k) represents the received signal composed of the first M point sequence, Y 2g (k) represents the received signal composed of the last M point sequence, Re(·) and Im(·) are used to extract the real part and imaginary part respectively. Maximum Likelihood Estimation of Carrier Frequency Offset (CFO) Expressed as the sum of its true value and estimated error, that is, in, Is a variance The Gaussian estimation error of 6. The physical layer authentication method for a two-way privacy-preserving drone-assisted MIMO system according to claim 1, characterized in that: In step 3, identity authentication includes the following steps: Step 3.1: Consider identity authentication as a binary hypothesis test, expressed as: Among them, the null hypothesis H0 indicates that the currently received signal comes from a legal communication link, that is, X=A, and the hypothesis H1 indicates that the signal comes from an illegal communication link, that is, X=E, A is the legal transmitter, and E is the illegal transmitter. is the estimated carrier frequency offset (CFO) of the device to be authenticated, is the estimated carrier frequency offset (CFO) of the legitimate device; Step 3.2: Add the estimated values ​​of the carrier frequency offset (CFO) of the N transmit-receive antenna pairs to obtain a variable, let Define the test statistic Z(ε) for the difference in carrier frequency offset (CFO) between the kth frame and the k-1th frame for the nth transmit-receive antenna pair: Step 3.3, the signal receiver calculates the difference between the carrier frequency offset (CFO) estimate extracted from the received signal of the kth frame and the carrier frequency offset (CFO) estimate stored in the (k-1)th frame, as well as the difference in the carrier frequency offset (CFO) between each channel, and calculates the sum of the squares of the carrier frequency offset (CFO) as the test statistic for binary detection. The signal receiver will perform identity detection by comparing the test statistic Z(ε) with the threshold δ: If Z(ε)<δ, the receiver makes the H0 judgment, indicating that the current received signal is consistent with the signal transmitter of the previous frame and comes from a legitimate transmitter. The receiver will use the carrier frequency offset (CFO) measurement value obtained at this time to update the stored carrier frequency offset (CFO) and perform subsequent decryption processing on the received signal. If Z(ε)>δ, the receiver makes the H1 judgment, indicating that the sender of the current signal is different from the sender of the previous frame, and the communication has been illegally attacked. The receiver will reject the second frame at time k to complete the identity authentication.

7. The physical layer authentication method for a two-way privacy-preserving UAV-assisted MIMO system according to claim 6, characterized in that: In step 4, the false alarm probability P is used f and detection probability P d Perform authentication performance analysis, specifically: Given a threshold δ, the false alarm probability P is derived f The theoretical expression of: According to the mathematical definition, the false alarm probability P is expressed by the regularized incomplete gamma function. f : where Q(s,x) is the regularized incomplete gamma function: Under H1, the test statistic Z(ε) is greater than the threshold δ, that is, Z(ε)>δ; Correct detection probability P d Defined as: Correct detection probability P d Detailed expression: The probability of correct detection is given by the Marcum-Q function: Among them, μ c is the noncentral parameter, and I is the modified Bessel function.

Citation Information

Cited By

  • A dynamic key-based intercom communication method

    CN122513765B