Positioning method for active eavesdropper in MIMO system
By analyzing the channel sparsity and beam domain channel of the Cell-free massive MIMO system, an AP selection strategy and fingerprint database were designed, which solved the problem of locating active eavesdroppers and improved the system's security and the reliability of information transmission.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-15
- Publication Date
- 2026-03-31
AI Technical Summary
In cell-free massive MIMO systems, active eavesdroppers can obtain legitimate user information through pilot attacks, leading to information leakage. Existing technologies fail to effectively consider the impact of eavesdropper location on security and lack effective security enhancement solutions.
By analyzing the spatial sparsity of the channel, a beam domain channel is established using a spatial basis extension model. An AP selection strategy is designed to remove the influence of noise, recover the effective beam domain channel information of the eavesdropper, and a fingerprint database is established with the help of auxiliary sensors. A low-complexity positioning method is then used to determine the location of the eavesdropper.
It enables accurate location of active eavesdroppers, improves system security, reduces information leakage, and enhances network security.
Smart Images

Figure CN115834299B_ABST
Abstract
Description
Technical Field
[0001] This invention pertains to information security technology in the field of wireless communication, specifically physical layer security technology, and is a method for locating active attackers. Background Technology
[0002] Cell-free massive MIMO systems can significantly improve spectral efficiency by leveraging spatial multiplexing, and additional interference can be controlled through AP cooperation. However, the high openness of Cell-free massive MIMO links inevitably exposes such networks to more security challenges, particularly active eavesdropping. Intelligent, unauthorized users can use pilot attacks to obtain information from legitimate users, posing a security threat to legitimate transmissions. Unlike passive eavesdropping, the impact of active eavesdropping is more severe in Cell-free massive MIMO systems. Active eavesdroppers send deceptive pilot sequences, causing pilot pollution, which can lead to the leakage of higher data rates, severely impacting system performance. Therefore, significant security challenges remain to be addressed in this type of network.
[0003] While active eavesdroppers pose a far greater threat to system security than passive eavesdroppers, their proactive pilot attacks, aimed at acquiring more useful information, increase their risk of exposure. Compared to the stealth of passive eavesdroppers, active eavesdroppers offer an opportunity to detect them through their proactive behavior, laying the foundation for further research and countermeasures. Obtaining the location of active eavesdroppers is crucial for improving system security. The flexible architecture of cell-free massive MIMO systems allows for AP scheduling based on user needs. Once the location of the eavesdropper is known, information leakage at the eavesdropper's location can be reduced by designing a serving AP set and beamforming scheme, thereby improving system security.
[0004] Currently, there is a lot of research on the security of cell-free massive MIMO systems against active pilot attacks. Researchers have studied security enhancement schemes using artificial noise, cooperative jamming techniques, beamforming techniques, and resource allocation techniques. However, few studies have considered the impact of the location of the active eavesdropper on security, while the location of the eavesdropper can help improve the performance of security enhancement schemes. Summary of the Invention
[0005] The problem to be solved by the present invention is as follows: For a cell-free (CF) massive multiple-input multiple-output (MIMO) network with an active eavesdropper, a positioning scheme for the active eavesdropper based on spatial sparsity is proposed. According to the low-rank property of the spatially correlated channel, a beam-domain channel is established through a spatial basis expansion model. For the case where some access points (APs) cannot distinguish between eavesdroppers and legitimate users, an AP selection strategy is proposed, and based on this, the effective beam-domain channel of the eavesdropper is recovered. On this basis, a low-complexity initial positioning method is proposed to determine the approximate range of the eavesdropper. In the precise positioning stage, a fingerprint similarity criterion is proposed to estimate the position of the eavesdropper.
[0006] The technical solution of the present invention is as follows: In a network with active pilot attacks, the channel received in the uplink channel estimation stage is projected onto a spatial orthogonal basis. Utilizing the spatial sparsity of multiple antennas, by removing the active beam set of legitimate users, the effective beam-domain channel information of the eavesdropping channel is obtained. On this basis, with the aid of auxiliary sensors, by establishing fingerprint information in the angle domain and power domain, the position of the active eavesdropper is obtained.
[0007] Specifically, the present invention considers a CF massive MIMO network with M APs, each AP equipped with N antennas, simultaneously serving K legitimate single-antenna users in the same frequency band. There is an active attacking eavesdropper in the network, which obtains the information of legitimate users by sending the same pilot as the eavesdropped user in the uplink channel estimation stage. Therefore, when a user sends a unit orthogonal pilot for uplink channel estimation, the eavesdropper sends to eavesdrop on the information of user k. Where τ P is the pilot length, and τ P <T, where T represents the coherence time. In the channel estimation stage, using the least squares estimation, it can be known that
[0008]
[0009] When the eavesdropper sends the same pilot as user k, user k is the eavesdropped user.
[0010]
[0011] The eavesdropper makes the channel estimation information contain the channel information of the eavesdropper by sending the same pilot as the eavesdropped user, resulting in errors in the CPU when performing downlink precoding, so that information is leaked to the eavesdropper in the downlink information transmission stage. P p represents the user pilot transmission power, P e represents the power of the eavesdropper's interfering pilot is expressed as a noise vector, Its elements satisfy an independent and identically distributed complex Gaussian distribution. σ 2 This represents noise power.
[0012] Projecting the channel onto a set of basis vectors yields the beam domain channel. Where matrix F is the normalized DFT matrix, F = [f1,...,f n ,...,f N ], where f n Let n be the basis vector. Since the beam domain channel between the AP and the user is low-rank and related to the user's angle of arrival, this invention utilizes this spatial sparsity characteristic to extract the eavesdropper's effective channel based on the difference in the angle of arrival between the eavesdropper and the legitimate user, and to locate the eavesdropper. First, to remove noise and the influence of eavesdroppers and users with the same angle of arrival on the channel sparsity, effective APs are selected, removing those with significant noise impact. APs whose active beam sets, after removing legitimate users, do not affect the channel gain of the eavesdropper's channel are retained, thus obtaining the AP set participating in the location. The basis vector indices representing the channel gain as a percentage of the total channel gain η are defined as the active beam set, i.e.
[0013]
[0014] Here, card(·) is the cardinality of the vector.
[0015] Furthermore, with the aid of auxiliary sensors, a location fingerprint database is established using the maximum beam set and channel beam domain matrix.
[0016] The basis vector index with the largest channel gain is defined as the maximum beam set, i.e.
[0017]
[0018] User k's beam domain channels on all APs are written as follows
[0019]
[0020] Initial localization is performed using the maximum beam set, reducing the dimensionality of fingerprint matching and narrowing down the range of the eavesdropper. After the CPU receives the estimated channel from each AP, it first selects the APs to participate in the localization according to the AP selection scheme in Part 3. Then, it extracts the eavesdropper's beam domain channel information and calculates the maximum beam set on that group of APs. The coverage area is then evenly divided into C... D The fingerprint of the reference point at the center of each region is selected as the initial centroid. The remaining points are then assigned to region C based on their distance from the centroid. D Within each cluster, a new C is generated based on the generated clusters.D Using a centroid, continue selecting cluster members based on Euclidean distance. Repeat the selection of centroids and cluster members until the cluster assignment converges. The centroid is the average angular domain fingerprint A of the cluster members. c According to the formula Calculate the Jaccard similarity between the centroid and the eavesdropper's maximum beam set. Select the top ν centroids with the highest similarity and find their cluster members as reference points to be activated for precise localization. Obtain the power domain fingerprint of the activated reference points and calculate the similarity coefficient. in After obtaining the similarity of offline fingerprints between the eavesdropper's channel and each reference point, we use the Weighted K-Nearest Neighbors (WKNN) algorithm to calculate the eavesdropper's location. First, we adaptively select the top R... K If there are 3 adjacent reference points, then the location of the eavesdropper is 1.
[0021]
[0022] in, It is the weight coefficient of the i-th reference point, and
[0023] This invention proposes a method for locating active eavesdroppers. Utilizing the characteristic of active eavesdroppers transmitting interference pilots during the channel estimation phase, and through analysis of the sparsity of the estimated channel, a high-resolution access point (AP) is selected to extract the effective beam domain channel information of the eavesdropper's channel. Based on this, an auxiliary sensor is used to design a low-complexity maximum beam set fingerprint to reduce matching dimensionality, and further, beam domain power fingerprinting is used to achieve the location of the eavesdropper.
[0024] This invention analyzes the sparsity of the estimated signal during the uplink estimation stage, designs an AP selection scheme, and extracts the effective beam domain channel of the eavesdropper; it also designs a low-complexity algorithm to locate the eavesdropper. Attached Figure Description
[0025] Figure 1 This is a flowchart illustrating the present invention;
[0026] Figure 2 This is a model diagram of the active eavesdropper localization method in the cell-free massive MIMO system of the present invention.
[0027] Figure 3 This is a schematic diagram illustrating the acquisition and extraction error of the eavesdropping channel under different AP numbers and eavesdropper pilot power.
[0028] Figure 4 This is a schematic diagram illustrating the probability distribution of positioning errors under different distances between eavesdroppers and legitimate users according to the present invention.
[0029] Figure 5 It is a schematic diagram of the positioning error of the present invention under different numbers of antennas and pilot powers of eavesdroppers. Specific embodiments
[0030] In a network of CF massive MIMO, the number of APs is M, each AP is equipped with N antennas, and simultaneously serves K legitimate single-antenna users in the same frequency. There is an actively attacking eavesdropper in the network, as Figure 2 shown, using the narrowband multipath model to model the channel between the AP and the user as
[0031]
[0032] where u ∈ {k, e} represents the user k and the eavesdropper e respectively. Formula (1) shows that the modeling method of the eavesdropping user is the same as that of the legitimate user. P is the total number of paths, and β m,u represents the large-scale fading related to the distance, is the small-scale fading, and its elements follow a complex Gaussian distribution with a mean of 0 and a variance of 1; the AP antennas adopt linear array antennas, and the response of the nth antenna array between the mth AP and the kth user is where d represents the antenna spacing, λ represents the signal wavelength, and j is the imaginary unit; represents the angle of arrival of the pth path, where θ m,u represents the central angle from the mth AP to the uth user, and δ m,u represents the angle spread caused by rich scattering; the path loss comes from the three-slope model
[0033]
[0034] where d0 and d1 are reference distances, and d m,u is the distance from APm to user u, and the shadow fading its elements follow a Gaussian distribution with a mean of 0 and a variance of 8 2 and only exists when d m,u > d1.
[0035] As Figure 1 shown, a positioning method for an active eavesdropper in a MIMO system according to the present invention is as follows:
[0036] First, user k sends a unit orthogonal pilot for uplink channel estimation, where τ P is the pilot length, and τ P < T, T represents the coherence time. In the channel estimation stage, using the least square (Least Square) estimation, it can be known that the estimated channel m between user k and AP
[0037]
[0038] in
[0039]
[0040] in, Indicates user k pilot signal s k The conjugate transpose, k = k e This indicates that the eavesdropper sends the same pilot signal as user k, and user k is the user being eavesdropped on; P p P represents the user pilot transmit power. e Indicates the power of the eavesdropper's interference pilot. Represented as a noise vector, Its elements satisfy an independent and identically distributed complex Gaussian distribution, σ 2 This represents noise power.
[0041] Projecting the channel onto a set of basis vectors yields the beam domain channel. Where matrix F is the normalized DFT matrix, F = [f1,...,f n ,...,f N ], where f n Let n be the basis vector. Antennas and basis vectors have a one-to-one correspondence; neglecting the effects of multipath, the channel for user k is...
[0042]
[0043] Then, user k is in the q-th orthogonal basis f q The projection on the beam domain channel is
[0044]
[0045] in As N→∞,
[0046]
[0047] Where δ(·) represents the impulse response, and according to the above formula, only when... In this case, the channel has gain, and the gain of its beam domain channel is related to the user's angle of arrival. Under no scattering and infinite antenna conditions, the beam domain channel gain decreases from N dimensions to one dimension. Due to the effects of rich scattering, the actual channel will experience power leakage, causing the channel gain to concentrate on a small number of orthogonal bases rather than a single orthogonal base. To simplify the following study, we define two beam sets: the maximum beam set and the active beam set.
[0048] We define the index of the basis vector with the largest channel gain as the maximum beam set A.m,k ,Right now
[0049] The basis vector index of the channel gain as a percentage of the total channel gain η is defined as the active beam set B. m,k ,Right now
[0050]
[0051] Where card(·) is the potential of the basis vectors, and the beam domain channel of user k on all APs is written as
[0052]
[0053] Based on the above analysis, it can be seen that the beam domain of a channel can spatially distinguish different users. The ability to distinguish them depends on the spatial resolution of the antenna. Therefore, this invention uses AP selection to remove APs with low spatial resolution, thereby improving positioning accuracy. We use a method of judging active beam sets for AP selection. Then, the AP coefficient I... m The following conditions must be met
[0054]
[0055] Among them, B m,e This represents the active beam set of the eavesdropper's channel. User k estimates the active beam set of the channel, ε N The threshold is used; the above AP selection scheme removes APs that are significantly affected by noise; it retains APs whose removal of active beamsets of legitimate users does not affect the channel gain of the eavesdropper's channel, thus obtaining the set of APs participating in the localization. Then the effective beam domain channel of the eavesdropper is: Where I represents an M×1 unit vector, and ⊙ represents the Hadamard product. User k was being eavesdropped on. e Estimate the beam domain of the channel.
[0056] This invention uses an auxiliary sensor to determine the location of an eavesdropper. First, it acquires two-dimensional fingerprint information through C samplings.
[0057] (1) Spatial domain fingerprint information
[0058]
[0059] in, This represents the maximum beam set sampled by APm and sensor i at the c-th sampling point; Let Pm be the maximum beam set sampled by sensor i for C, and [ ]. T Let the transpose of the vector be represented as follows: The maximum beam set database between APm and sensor i is then expressed as...
[0060]
[0061] The above formula means that the sample value that appears most frequently is taken as the sample value, where card represents the cardinality of the vector.
[0062] (2) Power domain fingerprint
[0063]
[0064] in, and These are sample values of power on the nth basis vector. Since the small-scale fading of the channel follows a complex Gaussian distribution, the channel magnitude follows a Rayleigh distribution.
[0065]
[0066] in, Let APm and sensor i represent the power domain fingerprints, and
[0067]
[0068] After the CPU receives the estimated channels from each AP, it first selects the APs to participate in the localization process according to the AP selection scheme. Then, it extracts the channel information in the eavesdropper's beam domain and calculates the maximum beam set A on that group of APs. e =I⊙[1,...,A m,e ,...,A M,e ], where A m,e Indicates AP m The maximum beam set between the receiver and the eavesdropper; dividing the coverage area evenly into C D The fingerprint of the reference point at the center of each region is selected as the initial centroid; the remaining points are then assigned to region C based on their distance from the centroid. D Within each cluster; new C is generated based on the generated clusters. D Given a centroid, continue selecting cluster members based on Euclidean distance; repeat the selection of centroids and cluster members until the cluster assignment converges. The centroid is the average angular domain fingerprint A of the cluster members. c According to the formula Calculate the Jaccard similarity between the centroid and the maximum beam set of the eavesdropper, select the top ν centroids with the highest similarity, find their cluster members as reference points to be activated for precise localization, obtain the power domain fingerprint of the activated reference points, and calculate the similarity coefficient of the i-th similar point. in After obtaining the similarity of offline fingerprints between the eavesdropper's channel and each reference point, the WKNN algorithm is used to calculate the eavesdropper's location. First, the top R values are adaptively selected. KIf there are 3 adjacent reference points, then the location of the eavesdropper is 1.
[0069]
[0070] Where, ψ i Let i be the position of the i-th reference point. It is the weight coefficient of the i-th reference point, and
[0071] Simulation Analysis
[0072] Consider active eavesdropper localization in a multi-antenna AP CF massive MIMO system, where the network coverage area is a 1 km wide and long region, the antenna height is 15 m, the user height is 1.65 m, and the noise power σ 2 = -96dBm, system bandwidth B = 20MHz, operating frequency B = 2.4GHz.
[0073] Experiment 1: Simulated the impact of AP density on channel extraction by eavesdroppers, such as... Figure 3 Where λ represents the number of APs per 10,000 square meters, N represents the number of antennas per AP, and the x-axis represents P. p / P e P represents the ratio of pilot transmission power between legitimate users and eavesdroppers. p =200mW. (Vertical axis) The normalized beam domain channel error is denoted by g. e The channel representing the eavesdropper, To estimate the channel for the eavesdropper, the following conclusions are drawn:
[0074] (1) As the eavesdropper’s eavesdropping power decreases, the mse value increases. This is because when the eavesdropping power is low, the presence of noise reduces the impact of the eavesdropping channel on the legitimate user’s channel estimation, and the error of the eavesdropping channel extraction increases.
[0075] (2) Increasing the density of APs can improve the accuracy of eavesdropping channel extraction. This is because increasing the density of APs increases the effective dimension of the eavesdropping channel and reduces the error.
[0076] Experiment 2: Simulated the positioning error at different distances between the eavesdropper and the eavesdropped user, such as... Figure 4 , where P p / P e P represents the ratio of pilot transmission power between legitimate users and eavesdroppers. p =200mW, d e This represents the distance between the user being eavesdropped on and the eavesdropper. The following conclusions are drawn:
[0077] When the two are far apart, their positioning error is small. This is because when the distance is close, the resolution of each AP decreases, and the similarity weakens with distance.
[0078] Experiment 3: This experiment simulates the effect of varying location capability on the eavesdropper's power when the number of access points (APs) and antennas differs. The antenna density λ represents the number of APs per 10,000 square meters, and P... p =200mW, N=24, P p / P e P represents the ratio of pilot transmission power between legitimate users and eavesdroppers. p =200mW, the lines and legend in the figure correspond to the following conclusion:
[0079] (1) As the eavesdropper’s eavesdropping power decreases, the positioning error increases. This is because when the eavesdropping power is too low, there is an error in the extraction of the eavesdropping channel. Positioning is based on channel extraction, and the smaller the channel extraction error, the better the positioning performance.
[0080] (2) Increasing the number of antennas per AP can further reduce positioning error, but the number of antennas is all for enhancing fingerprint resolution. When it increases to a certain extent, it has little impact on eavesdropping performance, because the fingerprint resolution is already sufficient for positioning.
Claims
1. A method for positioning an active eavesdropper in a MIMO system, characterized in that In the spatially correlated fading channel, there exists an active eavesdropper who can steal useful information by sending the same pilot as the target user in the uplink estimation phase; By exploiting the spatial sparsity of the channel, we develop an AP selection scheme to obtain the effective beam domain channel of the eavesdropper and design a low complexity algorithm to determine the location of the active eavesdropper with the help of auxiliary sensors; In the AP selection scheme and eavesdropper beam domain effective channel extraction of the uplink channel estimation stage, the user k sends a unit orthogonal pilot to the AP The uplink channel estimation is performed, where τ P is the pilot length, and τ P <T, T represents the coherence time, and in the channel estimation stage, the estimated channel between the user k and the AP m can be known by using the least square estimation Wherein where, denotes the conjugate transpose of the user k pilot signal s k , k = k e denotes that the eavesdropper transmits the same pilot as user k, user k is the eavesdropped user; P p denotes the user pilot transmit power, P e denotes the power with which the eavesdropper interferes with the pilot denotes a noise vector, whose elements satisfy an independent and identically distributed complex Gaussian distribution, σ 2 is the noise power; Using the way of judging the active beam set to make AP selection, AP coefficient I m Satisfies the following conditions where B m,e denotes the active beam set of the eavesdropper channel, user k estimates the active beam set of the channel, ε N is a threshold; the above AP selection scheme removes the APs whose impact on the channel is very large due to the noise; it retains the APs whose removal of the active beam set of the legitimate user does not affect the channel gain of the eavesdropper channel, obtaining the AP set participating in positioning Then the effective beam-domain channel of the eavesdropper is where I denotes an Mx1 unit vector, and denotes Hadamard product, denotes the eavesdropped user k e estimates the beam-domain channel of the channel.
2. The method of claim 1, wherein: In a CF massive MIMO network, there are M APs, each equipped with N antennas, serving K legitimate single-antenna users simultaneously, and there exists an active eavesdropper. We model the channel between APs and users as where u ∈ {k, e} denotes user k and eavesdropper e, respectively, formula (1) shows that the modeling of eavesdropping users is consistent with the legal users, P is the total path number, β m,u represents the distance-related large-scale fading, is the small-scale fading, and the elements thereof obey a complex Gaussian distribution with a mean of 0 and a variance of 1; the AP antenna adopts a linear array antenna, and the nth antenna array response between the mth AP and the kth user is where d represents the antenna spacing, λ represents the signal wavelength, and j is the imaginary unit; represents the angle of arrival of the pth path, where θ m,u represents the central angle from the AP m to the user u, δ m,u represents the angle spread caused by rich scattering; the path loss comes from a three-slope model where d0, d1are reference distances, d m,u is the distance from the AP m to the user u, shadowing whose elements are drawn from a Gaussian distribution with mean 0 and variance 8 2 and only exists when d m,u > d1.
3. The method for positioning active eavesdroppers in a MIMO system according to claim 2, wherein spatial sparsity of the channel; projecting the channel onto a set of basis vectors to obtain the beam domain channel of the channel where matrix F is a normalized DFT matrix, F = [f1,..., fn,..., fN], where fnis the nth basis vector, n ,...,f N ], where fnis the nth basis vector, n antenna and basis vector are one-to-one correspondence; without considering the influence of multipath, the channel of user k is So, the projection of user k on the qth orthogonal basis f q is the beam domain channel wherein when N→∞, Wherein, δ(·) represents an impulse response, according to the above formula, only when The channel has a gain, and the gain of the beam domain channel of the channel is related to the angle of arrival of the user, and in the case of no scattering and infinite antenna, the beam domain channel gain is reduced from N dimensions to one dimension.
4. The method for positioning active eavesdroppers in MIMO systems according to claim 3, characterized in that The beam characteristics of the channel are measured by the channel beam domain matrix, the maximum beam set A, and the active beam set B. The index of the beam vector with the maximum channel gain is defined as the maximum beam set A m,k i.e. The base vector order of the channel gain that occupies the total channel gain η is defined as the active beam set B m,k i.e. Where, card(·) is the potential of the basis vector, and the beam domain channel of user k at all APs is written as 5. The method for positioning active eavesdroppers in MIMO systems according to claim 4, characterized in that The creation of the fingerprint database; first, through C times sampling, two-dimensional fingerprint information is obtained (1) Spatial domain fingerprint information where, represents the AP m and the maximum set of beams sampled by sensor i at c; is the AP m and the maximum set of beams sampled by sensor i at c, T represents the transpose of a vector, then the maximum set of beams database between the APmand sensor i is represented as The above formula indicates that the sampling value with the highest occurrence frequency is taken as the sample value, where card represents the potential of the vector; (2) Power domain fingerprint wherein and is the sample value of the power on the nth basis vector, since the small-scale fading of the channel obeys a complex Gaussian distribution, the modulus of the channel obeys a Rayleigh distribution, wherein, represents the power domain fingerprint of APmand sensor i, and 6. The method for positioning active eavesdroppers in MIMO systems according to claim 5, characterized in that The eavesdropper is located by using the fingerprint database; when the CPU receives the estimated channel feedback from each AP, the APs participating in the location are selected according to the AP selection scheme, then the beam domain channel information of the eavesdropper is extracted, and the maximum beam set A e = I o [1,...,A m,e ,...,A M,e ] where A m,e represents the maximum beam set between the APm and the eavesdropper; the coverage is evenly divided into C D regions, and the fingerprint of the center reference point of each region is selected as the initial centroid point; according to the distance from the centroid, the remaining points are divided into C D clusters; based on the generated clusters, new C D centroids are generated, and the cluster members are continuously selected according to the Euclidean distance; the selection of the centroid and the cluster member is repeated until the cluster assignment converges, and the centroid is the average value A c of the angle domain fingerprint of the cluster member; the Jaccard similarity between the centroid and the maximum beam set of the eavesdropper is calculated according to the formula , the first v centroids with the largest similarity are selected, the cluster members thereof are searched as the reference points needed to be activated for accurate positioning, the power domain fingerprint of the activated reference point is obtained, and the similarity coefficient of the i-th similar point is calculated where After the similarity between the offline fingerprint of each reference point and the channel of the eavesdropper is obtained, the WKNN algorithm is used to calculate the position of the eavesdropper; first, the first R K adjacent reference points are adaptively selected, and then the position of the eavesdropper is wherein ψ i is the position of the i-th reference point, is the weight coefficient of the i-th reference point, and