Pilot fraud attack detection methods, devices, electronic equipment and storage media
By constructing a geographic location fingerprint map and a Bernoulli random finite set, pilot fraud attacks are detected, solving the problems of high complexity and reception uncertainty in dynamic scenarios in existing methods, and achieving fast and accurate attack detection and improved system security.
Patent Information
- Application Number
- CN202210126800.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-02-10
- Publication Date
- 2025-10-31
- Estimated Expiration
- 2042-02-10
AI Technical Summary
Existing pilot fraud attack detection methods require assistance from other end users or multiple uplink and downlink pilot training sessions, resulting in high time and computational complexity, making them unsuitable for rapid detection. Furthermore, the uncertainty of received information in dynamic scenarios poses a significant challenge.
By constructing a geographic location fingerprint map, establishing a Bernoulli random finite set, obtaining historical states and current pilot signals, calculating posterior probabilities, determining the current state of being eavesdropped on, and adjusting antenna weights to resist pilot fraud attacks.
It achieves rapid and accurate detection of pilot fraud attacks, improves the physical layer security and confidentiality capacity of communication systems, and can effectively locate illegal eavesdropping users in dynamic scenarios.
Smart Images

Figure CN114786180B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of communication technology, and in particular to a method, apparatus, electronic device, and storage medium for detecting pilot fraud attacks. Background Technology
[0002] Physical Layer Security (PLS) aims to ensure the security of transmitted information by utilizing the characteristics of physical layer channels (such as their distinctness). In practical engineering applications, PLS is threatened by various factors. Due to the inherent wide-area propagation characteristics of physical layer channels, in wireless cellular networks, unauthorized eavesdropping users can exploit this characteristic to launch pilot spoofing attacks (PSA) against the base station, significantly impacting physical layer information security. Specifically, unauthorized eavesdropping users send pilot signals to the base station simultaneously with legitimate users, interfering with the base station's channel estimation. Under this influence, the base station's channel estimation for legitimate users becomes biased. During the downlink beamforming stage based on the estimated channel state information, the base station adjusts its antenna weights based on the biased channel state information, causing the antennas to point towards the unauthorized eavesdropping user, resulting in information leakage. Therefore, addressing pilot spoofing attacks by unauthorized eavesdropping users is of paramount importance in cellular network scenarios.
[0003] Existing methods for detecting pilot spoofing attacks include trusted user-based methods and bidirectional detection methods. However, trusted user-based methods require the assistance of other end users to detect pilot spoofing attacks, while existing bidirectional detection methods require multiple uplink and downlink pilot training sessions to complete attack detection. This introduces additional time and computational complexity during the pilot training phase, hindering fast pilot spoofing attack detection. Summary of the Invention
[0004] In view of this, the purpose of this disclosure is to propose a pilot fraud attack detection method, device, electronic device and storage medium to solve the physical layer security problem of communication system caused by the pilot fraud attack that may be launched by the illegal eavesdropping user.
[0005] To achieve the above objectives, this disclosure provides a method for detecting pilot fraud attacks, comprising:
[0006] Obtain historical states and predict the current state based on the historical states to determine the first Bernoulli random finite set;
[0007] Obtain the pilot signal at the current moment, and update the first Bernoulli random finite set according to the pilot signal to obtain the second Bernoulli random finite set;
[0008] The posterior probability is calculated based on the second Bernoulli random finite set, and the current state of being eavesdropped is determined based on the posterior probability.
[0009] Optionally, the step of obtaining historical states and predicting the current state based on the historical states to determine the first Bernoulli random finite set includes:
[0010] Obtain a pre-created geographic location fingerprint map;
[0011] The historical state is determined based on the geographic location fingerprint map;
[0012] Based on the historical state, the first Bernoulli random finite set is determined; wherein the historical state includes: geographical location information and attack status.
[0013] Optionally, the creation of the geographic location fingerprint map includes:
[0014] A coverage area is determined, and based on the coverage area, several reference areas are determined; wherein, each reference area is provided with a reference point;
[0015] Obtain the user's historical channel state vector at the reference point, and create the geographic location fingerprint map based on the historical channel state vector.
[0016] Optionally, the step of obtaining the pilot signal at the current moment and updating the first Bernoulli random finite set according to the pilot signal to obtain the second Bernoulli random finite set includes:
[0017] The pilot signal is acquired, and channel estimation is performed on the pilot signal to determine the channel state value;
[0018] Based on the channel state value, the first Bernoulli random finite set is updated to obtain the second Bernoulli random finite set.
[0019] Optionally, the step of calculating the posterior probability based on the second Bernoulli random finite set and determining the current eavesdropping state based on the posterior probability includes:
[0020] The posterior probability is calculated according to the formula shown below, and the posterior probability is compared with a preset threshold to determine the current eavesdropping state:
[0021]
[0022] Where, q t|t-1 Predicted value of the probability of launching pilot fraud attacks for unauthorized eavesdropping on users; The double integral of the likelihood function for launching a pilot fraud attack on an unauthorized eavesdropping user at the current moment; The probability density distribution of the geographic locations of legitimate users; The probability density distribution of the geographic locations of legitimate users; Let t be the derivative of the legitimate user's geographical location in the fingerprint map at time t; Let t be the differential of the illegal user's geographical location in the fingerprint map; It is a normalization constant.
[0023] Optionally, comparing the posterior probability with a preset threshold to determine the current eavesdropping state includes:
[0024] If, in response to the determination, the posterior probability is less than a preset threshold, then there is currently no pilot fraud attack.
[0025] If, in response to the determination that the posterior probability is not less than a preset threshold, then a pilot fraud attack exists.
[0026] Optionally, in response to determining that the posterior probability is not less than a preset threshold, a pilot spoofing attack currently exists, including:
[0027] Based on the posterior probability, determine the posterior probability density distribution;
[0028] The location information of the eavesdropping user is determined based on the posterior probability density distribution.
[0029] Based on the same inventive concept, one or more embodiments of this disclosure also provide a pilot fraud attack detection device, including:
[0030] The prediction module is configured to acquire historical states and predict the current state based on the historical states to determine the first Bernoulli random finite set.
[0031] The update module is configured to acquire the pilot signal at the current time and update the first Bernoulli random finite set according to the pilot signal to obtain the second Bernoulli random finite set.
[0032] The detection module is configured to calculate the posterior probability based on the second Bernoulli random finite set and determine the current eavesdropping state based on the posterior probability.
[0033] Based on the same inventive concept, one or more embodiments of this disclosure also provide an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the method described in any of the above.
[0034] Based on the same inventive concept, one or more embodiments of this disclosure also provide a non-transitory computer-readable storage medium storing computer instructions for causing a computer to perform any of the methods described above.
[0035] As described above, the pilot spoofing attack detection method, apparatus, electronic device, and storage medium provided in this disclosure, wherein the pilot spoofing attack detection method first acquires historical states and predicts the current state based on the historical states to determine a first Bernoulli random finite set; acquires the pilot signal at the current moment and updates the first Bernoulli random finite set based on the pilot signal to obtain a second Bernoulli random finite set; calculates the posterior probability based on the second Bernoulli random finite set, and determines the current eavesdropping state based on the posterior probability. It can be seen from the above that, compared with traditional solutions, this scheme determines location information based on pilot spoofing attack detection, thereby solving the physical layer security problem of the communication system caused by the possibility of illegal eavesdropping users launching pilot spoofing attacks. Attached Figure Description
[0036] To more clearly illustrate the technical solutions in this disclosure or related technologies, the accompanying drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the accompanying drawings described below are only embodiments of this disclosure. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0037] Figure 1 This is a schematic diagram of a pilot fraud attack detection method according to an embodiment of the present disclosure;
[0038] Figure 2 This is a schematic diagram of a scenario for a pilot fraud attack detection method according to an embodiment of this disclosure;
[0039] Figure 3 This is a schematic diagram illustrating the variation of the pilot fraud attack detection probability with the length of the pilot sequence sent by the user, according to an embodiment of this disclosure.
[0040] Figure 4 This is a schematic diagram showing the variation of the positioning error between the legitimate user and the illegal eavesdropping user as a function of the illegal eavesdropping user's transmission power, according to an embodiment of this disclosure.
[0041] Figure 5 This is a schematic diagram showing the trend of confidentiality capacity as a function of signal-to-noise ratio in an embodiment of this disclosure.
[0042] Figure 6 This is a schematic diagram of a pilot fraud attack detection device according to an embodiment of the present disclosure;
[0043] Figure 7This is a schematic diagram of the electronic device structure according to an embodiment of the present disclosure. Detailed Implementation
[0044] To make the objectives, technical solutions, and advantages of this disclosure clearer, the following detailed description is provided in conjunction with specific embodiments and the accompanying drawings.
[0045] It should be noted that, unless otherwise defined, the technical or scientific terms used in the embodiments of this disclosure should have the ordinary meaning understood by one of ordinary skill in the art to which this disclosure pertains. The terms "first," "second," and similar words used in the embodiments of this disclosure do not indicate any order, quantity, or importance, but are merely used to distinguish different components. Words such as "comprising" or "including" mean that the element or object preceding the word encompasses the elements or objects listed following the word and their equivalents, but do not exclude other elements or objects.
[0046] As described in the background section, during transmission, due to the inherent wide-area propagation characteristics of the physical layer channel, such as... Figure 2 The (scene diagram) shows a wireless cellular network, which includes: a multi-antenna base station, legitimate users, and unauthorized eavesdropping users; the multi-antenna base station includes, for example: Figure 2 The (1, 2, ..., M) antennas shown are used for transmitting and receiving pilot sequences. (Reference) Figure 2 Given the wide-area propagation characteristics of physical layer channels, it is known that while legitimate users communicate with the base station, illicit eavesdropping users also communicate with the base station, interfering with the base station's channel estimation and affecting normal communication between the base station and legitimate users. Furthermore, the base station lacks the ability to distinguish between legitimate and illicit eavesdropping users, thus significantly impacting physical layer information security. However, existing detection methods introduce additional time and computational complexity during the pilot training phase, hindering rapid detection of pilot fraud attacks. Moreover, in scenarios where both legitimate and illicit users exhibit a degree of dynamism (i.e., movement speed), traditional methods face the challenge of uncertainty in received information caused by user dynamism.
[0047] Existing methods for detecting pilot spoofing attacks targeting unauthorized eavesdroppers can be categorized into two types. One type requires the assistance of other end-users for pilot spoofing detection, such as trusted user-based detection schemes. Trusted user-based schemes introduce another trusted user node to assist in uplink pilot training, thereby mitigating the influence of unauthorized eavesdroppers. The other type of method does not require the assistance of other end-users but requires multiple uplink and downlink pilot training sessions to complete attack detection, such as bidirectional detection methods. Bidirectional detection methods train by having legitimate users send uplink pilots, and then have the base station resend pilots downlink for further training, achieving pilot spoofing attack detection through user collaboration. It is important to note that existing traditional methods, whether requiring assistance from other end-users or multiple uplink and downlink training sessions for joint detection, introduce additional time and computational complexity during the pilot training phase, hindering rapid pilot spoofing attack detection. Furthermore, in scenarios where both legitimate and illegitimate users exhibit a degree of dynamism (i.e., movement speed), traditional methods face challenges due to the uncertainty of received information caused by user dynamism.
[0048] In view of this, the present disclosure provides a pilot spoofing attack detection method, apparatus, electronic device, and storage medium. The pilot spoofing attack detection method includes:
[0049] First, a geographic location fingerprint map is constructed for the base station and the scenario where legitimate users are located. Then, based on the constructed geographic location fingerprint map, the geographic locations of legitimate users and illegal eavesdropping users, as well as the pilot fraud attack detection status of illegal eavesdropping users, are jointly considered. The above system states are uniformly described by establishing a Bernoulli random finite set.
[0050] refer to Figure 1 The pilot spoofing attack detection method includes the following steps:
[0051] Step 101: Obtain the historical state and predict the current state based on the historical state to determine the first Bernoulli random finite set.
[0052] In this implementation, firstly, the coverage area of the base station and the specific locations of legitimate users within the base station's coverage area are determined. Then, a geographic location fingerprint map is created based on the base station's coverage area and the specific locations of legitimate users within the base station's coverage area. Specifically, this includes considering a square area covered by the base station, with a side length of l. It should be noted that this is only a special case of a square; the shapes of other areas can be adjusted accordingly. This square area is divided into N equal smaller square areas, where the side length of each smaller square area is... Each small square is named a reference region. Within each reference region, its center point is selected as the reference point, resulting in a total of N reference points across the entire square region. For example, the coordinates of each reference point can be represented as: (x1, y1), (x2, y2), ..., (x...). N ,y N ).
[0053] Based on the defined reference area and reference point, the geographical location of a legitimate user at time t can be represented as l. t B ∈R N×1 Here, B represents a legitimate user, and R represents the set of real numbers. Each element in this N-dimensional vector can take the value 0 or 1. t B (i) = 0 means that at time t, the legitimate user is not in the i-th reference region; t B (i) = 1 represents the legitimate user being in the i-th reference area at time t. Similarly, the geographical location of the unauthorized eavesdropping user at time t is represented as l. t E ∈R N×1 Where E represents the unauthorized eavesdropping user. After completing the construction of the geographic location fingerprint map, based on the geographic location fingerprint map, the geographic locations of legitimate users and unauthorized eavesdropping users, as well as the pilot fraud attack detection status of unauthorized eavesdropping users, are further considered to establish a Bernoulli random finite set to uniformly describe the above system state.
[0054] In some embodiments, the simulation sets up a multi-antenna base station segment covering a square area, which is divided into 256 reference areas when constructing the fingerprint map, i.e., reference area N=256, and each reference area is a square with a side length of 1m. The state transition probability when an unauthorized eavesdropping user launches a pilot spoofing attack is set to p. b =p s =0.8. The power budget for legitimate users is 10dB. The received noise variance is assumed to be equal at the base station, legitimate terminal users, and illegal eavesdropping users. Then, the following is obtained: Figure 3 The graph shows how the detection probability of pilot spoofing attacks varies with the length of the pilot sequence sent by the user. Figure 3 As shown, the present invention can accurately detect pilot spoofing attacks launched by unauthorized eavesdroppers. The detection performance improves with increasing pilot length because increasing the pilot length improves the accuracy of channel estimation, thereby enhancing spoofing detection performance. Furthermore, the detection performance also improves with increasing antenna element count. When the number of antenna elements is 30, a pilot length of only 20 is sufficient to achieve a detection accuracy of over 98%.
[0055] In some implementations, an unauthorized eavesdropping user may perform pilot spoofing attacks in certain time slots, while remaining silent and not transmitting signals in other time slots. In this scenario, the multi-antenna base station can only receive the unauthorized user's signal when the user launches a pilot spoofing attack; when the user is silent, the base station can only receive signals from legitimate users. Therefore, let X be a Bernoulli random finite set. t The set can take the value {l} t B , l t E} and {l t B}, where {l t B , l t E} indicates that an unauthorized user launched a pilot spoofing attack, and the base station received signals from both the legitimate user and the unauthorized user; {l t B The '}' indicates that the unauthorized eavesdropping user is in a silent state, and the base station can only receive signals from the legitimate user. Therefore, at time t, X... t The probability density distribution can be expressed as:
[0056]
[0057] Where q represents the probability that the base station receives the signal of an illegally eavesdropping user, which is also the probability that the illegally eavesdropping user launches a pilot fraud attack.
[0058] In some implementations, the base station acquires historical information from a geographic location fingerprint map, including the base station's state value at a previous time. Based on the Chapman-Komogorov equation, the state of the Bernoulli random finite set is predicted, and the following formula is determined:
[0059] f t|t-1 (X t |h 1:t-1 )=∫φ t|t-1 (X t |X t-1 )f t-1|t-1 (X t-1 |h 1:t-1 )δX t-1
[0060] Formula (2)
[0061] Among them, f t-1|t-1 (X t-1 |h 1:t-1 Let φ denote the posterior probability density distribution of the Bernoulli random finite set at the previous time step. t|t-1 (X t |Xt-1 Let φ denote the one-step state transition probability density of a Bernoulli random finite set. For the above probability density function φ... t|t-1 (X t |X t-1 If we consider the Bernoulli random finite set, then we need to consider each of the possible states that the set can take.
[0062] First, calculate the probability that the unauthorized eavesdropping user is silent at the current moment, given that the user was silent at the previous moment, including:
[0063] (1) The probability density function of the user who was illegally eavesdropping in the previous moment being in a silent state, and who is also silent at the current moment (time t), that is, when X t-1 ={l t-1 B}, X t ={l t B When}, then we have:
[0064]
[0065] Where, p b φ represents the empirical probability of an unauthorized user transitioning from a silent state to a pilot spoofing attack state; B (l t B |l t-1 B ) represents the one-step migration probability density function of the geographic location status of a legitimate user.
[0066] (2) The probability density function of the current time (time t) when the illegal eavesdropping user was silent (i.e., the non-eavesdropping user launched the attack), that is, when X t-1 ={l t-1 B}, X t ={l t B ,l t E When}, then we have:
[0067]
[0068] Where, p b φ represents the empirical probability of an unauthorized user transitioning from a silent state to a pilot spoofing attack state; B (l t B |l t-1 B ) represents the one-step migration probability density function of the geographic location status of a legitimate user; The birth probability distribution function is used to illegally eavesdrop on users' geographical location status.
[0069] Then, calculate the probability that the unauthorized eavesdropping user was in a non-silent state at the previous moment, and is currently in a non-silent state, including:
[0070] (1) When the illegal eavesdropping user was not silent at the previous moment, the probability density function of being not silent at the current moment (time t) (i.e., the non-eavesdropping user launching the attack), that is, when X t-1 ={l t-1 B ,l t-1 E}, X t ={l t B When:
[0071]
[0072] Where, p s Based on experience, this represents the probability that an unauthorized eavesdropping user will continue to maintain a pilot spoofing attack state; φ B (l t B |l t-1 B () is the one-step migration probability density function for the geographic location status of a legitimate user; The birth probability distribution function is used to illegally eavesdrop on users' geographical location status.
[0073] (2) When the illegal eavesdropping user was not silent at the previous moment, the probability density function of being not silent at the current moment (time t) (i.e., the non-eavesdropping user launching the attack), that is, when X t-1 ={l t-1 B ,l t-1 E}, X t ={l t B ,l t E When:
[0074]
[0075] Where, p s Based on experience, this represents the probability that an unauthorized eavesdropping user will continue to maintain a pilot spoofing attack state; φ B (l t B |l t-1 B φ is the one-step migration probability density function for the geographic location status of a legitimate user; E (l tE |l t-1 E ) is the one-step migration probability density function for illegally eavesdropping on the user's geographical location status.
[0076] In some implementations, by further substituting equation (1) into equation (2), the probability of an illegal eavesdropping user performing a pilot fraud attack at time t and the predicted values of the geographical location status of each user can be derived.
[0077] Specifically, the probability of a pilot spoofing attack is as follows:
[0078] q t|t-1 =p b (1-q t-1|t-1 )+p s q t-1|t-1
[0079] Formula (7)
[0080] Where, p b p represents the empirical probability of an unauthorized user transitioning from a silent state to a pilot spoofing attack state; s Based on experience, the probability that an unauthorized eavesdropping user will continue to maintain a pilot spoofing attack state; q t-1|t-1 The posterior probability of a pilot fraud attack carried out by an unauthorized eavesdropper on a user at the previous moment.
[0081] The probability density distribution prediction of the geographic location of legitimate users is shown below:
[0082]
[0083] Where, f(l) t-1 B ) represents the probability density distribution estimate of the geographic location of the legitimate user at the previous time step; φ is the derivative of the legitimate user's geographical location on the fingerprint map at the previous moment; B (l t B |l t-1 B ) is the one-step migration probability density function for the geographic location status of a legitimate user.
[0084] The probability density distribution prediction of the geographic location of unauthorized eavesdropping users is shown below:
[0085]
[0086] Where, p b p represents the empirical probability of an unauthorized user transitioning from a silent state to a pilot spoofing attack state; s Based on experience, the probability that an unauthorized eavesdropping user will continue to maintain a pilot spoofing attack state; qt-1|t-1 The posterior probability of a pilot fraud attack carried out by an unauthorized eavesdropper on a user at the previous moment; φ is the birth probability distribution function for illegally eavesdropping on users' geographical location status; E (l t E |l t-1 E () represents the one-step transition probability density function for illegally eavesdropping on the user's geographic location status; This is an estimate of the probability density distribution of the location of the user illegally eavesdropping at the previous moment; The derivative of the unauthorized user's geographical location in the fingerprint map at the previous moment; q t|t-1 The predicted value of the probability of launching a pilot fraud attack for illegally eavesdropping on users.
[0087] Step 102: Obtain the pilot signal at the current time, and update the first Bernoulli random finite set according to the pilot signal to obtain the second Bernoulli random finite set.
[0088] In this embodiment, the pilot signal is first acquired, and channel estimation is performed on the pilot signal to determine the channel state value. Then, based on the channel state value, the first Bernoulli random finite set is updated to obtain the second Bernoulli random finite set. Specifically, this includes:
[0089] After receiving pilot signals from legitimate users (who may be illegally eavesdropping), the multi-antenna receiver needs to perform a channel estimation mechanism based on the Linear Minimum Mean Square Error (LMMSE matrix).
[0090] First, establish the channel model, where the signal received by the multi-antenna receiver can be represented as:
[0091]
[0092] Among them, P B P E h represents the transmission power of legitimate users and illegitimate eavesdropping users. t B Let h be the channel state vector of a legitimate user, where h t B ∈C M×1 h t E Let h be the channel state vector of the unauthorized eavesdropping user. t E ∈C M×1 ;x up Let x be a pilot sequence, where x up ∈C1×L L is the pilot length; N represents the received noise matrix, where N∈C M×L .
[0093] Then, based on the channel model, LMMSE channel estimation is performed on the received signal, which is represented as follows:
[0094] h t =Y t U
[0095] Formula (11)
[0096] Where U is the LMMSE matrix.
[0097] In some implementations, U (LMMSE matrix) is specifically represented as:
[0098]
[0099] in, For vector x up The conjugate transpose of P; B Transmit power for legitimate users; x up For pilot sequences; σ 2 This represents the variance of the noise received at the base station.
[0100] In some implementations, due to the presence of unauthorized eavesdropping users, when these users launch pilot spoofing attacks (i.e., emit spoofing signals), the aforementioned LMMSE estimation results are further expressed as follows:
[0101]
[0102] Among them, h t B P is the channel state vector of a legitimate user; E For illegally eavesdropping on users' transmission power; P B For legitimate users' transmission power; h t E The channel state vector of the unauthorized eavesdropping user; n t This represents the noise vector after LMMSE estimation.
[0103] Furthermore, the channel state values obtained from the LMMSE matrix estimation are used to update the Bernoulli random finite set state prediction values obtained in the state prediction step, resulting in a second Bernoulli random finite set. The specific calculation is as follows:
[0104]
[0105] Wherein, ψ(h) t |X t) is the likelihood function; It is a normalization constant.
[0106] In some implementations, the likelihood functions are considered for the current time when the unauthorized eavesdropping user is silent and when the unauthorized eavesdropping user launches a pilot fraud attack, respectively.
[0107] In response to confirmation, the current moment is a time of silence for the unauthorized eavesdropping user, i.e., when X... t ={l t B When}, the likelihood function is expressed as follows:
[0108]
[0109] Where, σ 2 h' is the variance of the received noise at the base station. B This indicates the location corresponding to the fingerprint map. t B Channel state measurement values.
[0110] In some implementations, wherein, To substitute the vector h t The i-th element and h b The exponent e is obtained by dividing the square of the modulus of the i-th element by the noise variance. The intermediate variables have no specific physical meaning.
[0111] In response to the determination, a pilot fraud attack is launched for the unauthorized eavesdropping user at the current moment, that is, when X... t ={l t B ,l t E When}, the likelihood function is expressed as follows:
[0112]
[0113] Where, σ 2 h' is the variance of the received noise at the base station. B with h' E These represent the fingerprint maps corresponding to geographical locations l t B With l t E Channel state measurement value; P B P E These represent the transmission power of legitimate users and illegitimate eavesdropping users, respectively.
[0114] In some implementations, the normalization constant (h) in formula (14) t |h 1:t-1 Specifically, it is expressed as:
[0115]
[0116] Where, q t|t-1 The probability of a pilot spoofing attack; Let ψ(h) be the likelihood function. t |X t ) fell for X t ={l t B The value at time}; The probability density distribution of the geographic locations of legitimate users; The double integral of the likelihood function for launching a pilot fraud attack on an unauthorized eavesdropping user at the current moment; The probability density distribution of the geographic locations of legitimate users; The probability density distribution of the geographic location of users illegally eavesdropping; Let t be the derivative of the legitimate user's geographical location in the fingerprint map at time t; Let t be the differential of the illegal user's geographical location in the fingerprint map at time t.
[0117] Step 103: Calculate the posterior probability based on the second Bernoulli random finite set, and determine the current eavesdropping state based on the posterior probability.
[0118] In this embodiment, firstly, the posterior probability is calculated and compared with a preset threshold. If the posterior probability is less than the preset threshold, then no pilot spoofing attack exists; if the posterior probability is not less than the preset threshold, then a pilot spoofing attack exists. Then, based on the posterior probability, a posterior probability density distribution is determined; based on the posterior probability density distribution, the location information of the eavesdropping user is determined.
[0119] In some implementations, substituting equation (1) into equation (14) yields the probability that an unauthorized eavesdropping user will perform a pilot spoofing attack at time t, as well as the posterior estimate of the geographical location status of each user. The posterior probability is the probability of occurrence inferred from the observed values. Specifically, the posterior probability of a pilot spoofing attack is derived as follows:
[0120]
[0121] Where, q t|t-1 Predicted value of the probability of launching pilot fraud attacks for unauthorized eavesdropping on users; The double integral of the likelihood function for launching a pilot fraud attack on an unauthorized eavesdropping user at the current moment; The probability density distribution of the geographic locations of legitimate users; The probability density distribution of the geographic locations of unauthorized users; Let t be the derivative of the legitimate user's geographical location in the fingerprint map at time t; Let t be the differential of the illegal user's geographical location in the fingerprint map; It is a normalization constant.
[0122] (1) The posterior probability density distribution of the geographic location of a legitimate user is:
[0123]
[0124] in, Let ψ(h) be the likelihood function. t |X t ) fell for X t ={l t B The value at time}; This represents the probability density distribution of the geographic locations of legitimate users in the previous time step. Let t be the derivative of the legitimate user's geographical location in the fingerprint map at time t.
[0125] (2) The posterior probability density distribution of the geographic location of the illegally eavesdropping user is:
[0126]
[0127] in, Let ψ(h) be the likelihood function. t |X t ) fell for X t ={l t B ,l t E The value at time}; Let ψ(h) be the likelihood function. t |X t ) fell for X t ={l t B The value at time}; The probability density distribution of the geographic locations of unauthorized users; The double integral of the likelihood function for launching a pilot fraud attack on an unauthorized eavesdropping user at the current moment; The probability density distribution of the geographic locations of legitimate users; for; Let t be the derivative of the legitimate user's geographical location in the fingerprint map at time t; Let t be the differential of the illegal user's geographical location in the fingerprint map at time t.
[0128] By calculating the expectation of the posterior probability density distribution of the geographic locations of legitimate users and illegitimate eavesdropping users, the specific geographic location estimates of legitimate users and illegitimate eavesdropping users can be obtained.
[0129] In some implementations, such as Figure 4 The figure shows the variation of the positioning error for legitimate users and illegitimate eavesdropping users with the transmission power of the illegitimate eavesdropping user. As shown in the figure, the solution of the present invention can achieve relatively ideal positioning accuracy for both legitimate users and illegitimate eavesdropping users. The positioning performance for legitimate users remains constant at all eavesdropping user transmission powers, indicating that the solution of the present invention can effectively resist the influence of pilot spoofing attacks. The positioning performance for illegitimate eavesdropping users improves with increasing transmission power, because eavesdropping users are relatively easier to detect and locate when their transmission power increases.
[0130] In some implementations, based on the obtained posterior probability density distribution of the system state, a decision threshold is set for the posterior probability of pilot spoofing attacks to determine whether an unauthorized eavesdropping user is conducting a pilot spoofing attack. The decision threshold can be set according to actual conditions; for example, it can be 0.5 or 0.6, or it can be set to 1 or any value that meets actual needs. When the calculated posterior probability exceeds the preset threshold, a pilot spoofing attack is currently present; if it is less than the preset threshold, a pilot spoofing attack is currently not present.
[0131] In some implementations, after determining the location information based on pilot spoofing attack detection, the antenna weights can be adjusted according to the location information to minimize the channel used to eavesdrop on users. Specifically, this includes:
[0132] Antenna weights are adjusted based on the estimated pilot spoofing attack status and the geographical location of each user to maximize the channel capacity of legitimate users and minimize the channel capacity of illicit eavesdropping users. For example, if the current channel capacity for both legitimate and illicit users is set to 60%, the antenna weights are adjusted based on the estimated pilot spoofing attack status and the geographical location of each user to adjust the channel capacity of legitimate users to 90%-100% and the channel capacity of illicit users to 10% or less or 0, thus restricting the communication of illicit users. The channel capacity for both legitimate and illicit users can be set according to the actual situation, and other numerical settings are also within the protection scope of this disclosure.
[0133] Specifically, this invention employs a zero-forcing beamforming method to maximize channel security capacity (i.e., maximize the communication capacity of legitimate users and minimize the channel security capacity of unauthorized eavesdropping users). The specific optimization formula is shown in formula (21) below:
[0134]
[0135]
[0136] Among them, w t This is the antenna weight vector at the base station. For vector w t The conjugate transpose of the above formula (21) yields the specific adjustment method for antenna weights as shown in formula (22):
[0137]
[0138] Where I is the identity matrix; l t B With l t E Both H(l) represent estimated geographical locations of legitimate and illegitimate users in the fingerprint map at time t. t B ) and H(l t E ) represent the geographical locations of legitimate users in the fingerprint map at time t. t B Geographic location of unauthorized users t E The channel state value.
[0139] In some embodiments, the method of the present invention can significantly improve the security capacity of the system compared to direct location and signal transmission without employing pilot fraud attack detection. For further persuasion, see references... Figure 5 As can be seen, this disclosure introduces a current method for detecting pilot fraud attacks, namely the random pilot method. For example, Figure 5 As shown, the method disclosed herein demonstrates superior security capabilities compared to both random pilot methods and existing methods that directly perform location and signal transmission without pilot fraud attack detection. Therefore, the method of this invention offers significant advantages in enhancing the security of communication systems.
[0140] As described above, the pilot spoofing attack detection method, apparatus, electronic device, and storage medium provided in this disclosure, wherein the pilot spoofing attack detection method first acquires historical states and predicts the current state based on the historical states to determine a first Bernoulli random finite set; acquires the pilot signal at the current moment and updates the first Bernoulli random finite set based on the pilot signal to obtain a second Bernoulli random finite set; calculates the posterior probability based on the second Bernoulli random finite set and determines the current eavesdropping state based on the posterior probability, thereby solving the physical layer security problem of the communication system caused by the possibility of illegal eavesdropping users launching pilot spoofing attacks. It can be seen from the above that, compared with traditional solutions, this scheme, while determining the location information based on pilot spoofing attack detection, can also adjust the antenna weights based on the location information to minimize the channel of the eavesdropping user, thereby greatly improving the system's confidentiality capacity and ensuring the security of wireless communication.
[0141] It should be noted that the method of this disclosure embodiment can be executed by a single device, such as a computer or server. The method of this embodiment can also be applied to a distributed scenario, where multiple devices cooperate to complete the task. In such a distributed scenario, one of these devices may execute only one or more steps of the method of this disclosure embodiment, and the multiple devices will interact with each other to complete the method described.
[0142] It should be noted that the above description describes some embodiments of this disclosure. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in a different order than that shown in the above embodiments and still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0143] Based on the same inventive concept, corresponding to any of the above-described embodiments, this disclosure also provides a pilot fraud attack detection device.
[0144] refer to Figure 6 The pilot spoofing attack detection device includes:
[0145] The prediction module is configured to acquire historical states and predict the current state based on the historical states to determine the first Bernoulli random finite set.
[0146] The update module is configured to acquire the pilot signal at the current time and update the first Bernoulli random finite set according to the pilot signal to obtain the second Bernoulli random finite set.
[0147] The detection module is configured to calculate the posterior probability based on the second Bernoulli random finite set and determine the current eavesdropping state based on the posterior probability.
[0148] For ease of description, the above apparatus is described in terms of its functions, divided into various modules. Of course, in implementing this disclosure, the functions of each module can be implemented in one or more software and / or hardware.
[0149] The apparatus described above is used to implement the corresponding pilot fraud attack detection method in any of the foregoing embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be repeated here.
[0150] Based on the same inventive concept, corresponding to the methods of any of the above embodiments, this disclosure also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the pilot fraud attack detection method described in any of the above embodiments.
[0151] Figure 7 This embodiment illustrates a more specific hardware structure of an electronic device, which may include a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. The processor 1010, memory 1020, input / output interface 1030, and communication interface 1040 are interconnected internally via the bus 1050.
[0152] The processor 1010 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this specification.
[0153] The memory 1020 can be implemented in the form of ROM (Read Only Memory), RAM (Random Access Memory), static storage device, dynamic storage device, etc. The memory 1020 can store the operating system and other applications. When the technical solutions provided in the embodiments of this specification are implemented by software or firmware, the relevant program code is stored in the memory 1020 and is called and executed by the processor 1010.
[0154] The input / output interface 1030 is used to connect input / output modules to realize information input and output. Input / output modules can be configured as components within the device (not shown in the figure) or externally connected to the device to provide corresponding functions. Input devices may include keyboards, mice, touchscreens, microphones, various sensors, etc., while output devices may include displays, speakers, vibrators, indicator lights, etc.
[0155] The communication interface 1040 is used to connect a communication module (not shown in the figure) to enable communication between this device and other devices. The communication module can communicate via wired means (such as USB, Ethernet cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.).
[0156] Bus 1050 includes a pathway for transmitting information between various components of the device, such as processor 1010, memory 1020, input / output interface 1030, and communication interface 1040.
[0157] It should be noted that although the above-described device only shows the processor 1010, memory 1020, input / output interface 1030, communication interface 1040, and bus 1050, in specific implementations, the device may also include other components necessary for normal operation. Furthermore, those skilled in the art will understand that the above-described device may only include the components necessary for implementing the embodiments of this specification, and not necessarily all the components shown in the figures.
[0158] The electronic devices described above are used to implement the corresponding pilot fraud attack detection methods in any of the foregoing embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.
[0159] Based on the same inventive concept, corresponding to the methods of any of the above embodiments, this disclosure also provides a non-transitory computer-readable storage medium storing computer instructions for causing the computer to execute the pilot fraud attack detection method as described in any of the above embodiments.
[0160] The computer-readable medium of this embodiment includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transfer medium that can be used to store information accessible by a computing device.
[0161] The computer instructions stored in the storage medium of the above embodiments are used to cause the computer to execute the pilot fraud attack detection method as described in any of the above embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.
[0162] Those skilled in the art should understand that the discussion of any of the above embodiments is merely exemplary and is not intended to imply that the scope of this disclosure (including the claims) is limited to these examples; within the framework of this disclosure, the technical features of the above embodiments or different embodiments can also be combined, the steps can be implemented in any order, and there are many other variations of different aspects of the embodiments of this disclosure as described above, which are not provided in detail for the sake of brevity.
[0163] Additionally, to simplify the description and discussion, and to avoid obscuring the embodiments of this disclosure, the provided drawings may or may not show well-known power / ground connections to integrated circuit (IC) chips and other components. Furthermore, the apparatus may be shown in block diagram form to avoid obscuring the embodiments of this disclosure, and this also takes into account the fact that the details of implementation of these block diagram apparatuses are highly dependent on the platform on which the embodiments of this disclosure will be implemented (i.e., these details should be fully understood by those skilled in the art). While specific details (e.g., circuitry) have been set forth to describe exemplary embodiments of this disclosure, it will be apparent to those skilled in the art that the embodiments of this disclosure may be implemented without these specific details or with variations thereof. Therefore, these descriptions should be considered illustrative rather than restrictive.
[0164] Although this disclosure has been described in conjunction with specific embodiments thereof, many substitutions, modifications, and variations of these embodiments will be apparent to those skilled in the art from the foregoing description. For example, other memory architectures (e.g., dynamic RAM (DRAM)) may be used with the embodiments discussed.
[0165] This disclosure is intended to cover all such substitutions, modifications, and variations that fall within the broad scope of the appended claims. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.
Claims
1. A method for detecting pilot spoofing attacks, comprising: Obtain historical states and predict the current state based on these historical states to determine the first Bernoulli random finite set; wherein, the Bernoulli random finite set is X. t The set takes values of and This indicates that an unauthorized user has launched a pilot spoofing attack, and the base station has received signals from both the legitimate user and the unauthorized user. This indicates that the illegal eavesdropping user is in a silent state, and the base station can only receive signals from the legitimate user. Obtain the pilot signal at the current moment, and update the first Bernoulli random finite set according to the pilot signal to obtain the second Bernoulli random finite set; The posterior probability is calculated based on the second Bernoulli random finite set, and the current state of being eavesdropped is determined based on the posterior probability.
2. The detection method according to claim 1, wherein, The step of acquiring historical states and predicting the current state based on those historical states to determine the first Bernoulli random finite set includes: Obtain a pre-created geographic location fingerprint map; The historical state is determined based on the geographic location fingerprint map; Based on the historical state, the first Bernoulli random finite set is determined; wherein the historical state includes: geographical location information and attack status.
3. The detection method according to claim 2, wherein, The creation of the geographic location fingerprint map includes: A coverage area is determined, and based on the coverage area, several reference areas are determined; wherein, each reference area is provided with a reference point; Obtain the user's historical channel state vector at the reference point, and create the geographic location fingerprint map based on the historical channel state vector.
4. The detection method according to claim 1, wherein, The step of acquiring the pilot signal at the current moment and updating the first Bernoulli random finite set according to the pilot signal to obtain the second Bernoulli random finite set includes: The pilot signal is acquired, and channel estimation is performed on the pilot signal to determine the channel state value; Based on the channel state value, the first Bernoulli random finite set is updated to obtain the second Bernoulli random finite set.
5. The detection method according to claim 1, wherein, The step of calculating the posterior probability based on the second Bernoulli random finite set and determining the current eavesdropping state based on the posterior probability includes: The posterior probability is calculated according to the formula shown below, and the posterior probability is compared with a preset threshold to determine the current eavesdropping state: Where, q t|t-1 Predicted value of the probability of launching pilot fraud attacks for unauthorized eavesdropping on users; The double integral of the likelihood function for launching a pilot fraud attack on an unauthorized eavesdropping user at the current moment; Let ψ(h) be the likelihood function. t |X t ) fell into the trap The value at time; The probability density distribution of the geographic locations of legitimate users; The probability density distribution of the geographic locations of illegitimate users; Let t be the derivative of the legitimate user's geographical location in the fingerprint map at time t; Let t be the differential of the illegal user's geographical location in the fingerprint map; It is a normalization constant.
6. The detection method according to claim 5, wherein, The step of comparing the posterior probability with a preset threshold to determine the current eavesdropping state includes: If, in response to the determination, the posterior probability is less than a preset threshold, then there is currently no pilot fraud attack. If, in response to the determination that the posterior probability is not less than a preset threshold, then a pilot fraud attack exists.
7. The detection method according to claim 6, wherein, If, in response to a determination, the posterior probability is not less than a preset threshold, then a pilot spoofing attack exists, including: Based on the posterior probability, determine the posterior probability density distribution; The location information of the eavesdropping user is determined based on the posterior probability density distribution.
8. A pilot spoofing attack detection device, comprising: The prediction module is configured to acquire historical states and predict the current state based on the historical states to determine a first Bernoulli random finite set; wherein, the Bernoulli random finite set is X. t The set takes values of and This indicates that an unauthorized user has launched a pilot spoofing attack, and the base station has received signals from both the legitimate user and the unauthorized user. This indicates that the illegal eavesdropping user is in a silent state, and the base station can only receive signals from the legitimate user. The update module is configured to acquire the pilot signal at the current time and update the first Bernoulli random finite set according to the pilot signal to obtain the second Bernoulli random finite set. The detection module is configured to calculate the posterior probability based on the second Bernoulli random finite set and determine the current eavesdropping state based on the posterior probability.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the program, implements the method as described in any one of claims 1 to 7.
10. A non-transitory computer-readable storage medium storing computer instructions for causing a computer to perform the method of any one of claims 1 to 7.
Citation Information
Patent Citations
Combined authorized user perception and link state estimation method and device
CN103916969A
Method, system and device for detecting wiretapping pilot signal sent by illegal user
CN108768901A