Network Time Synchronization Message Transmission Method and Device Applied to Arbitrary Channel Environments
The network time synchronization packets are processed through Polar encoding and OFDM-IM modulation technology, which solves the problems of security and application scenario limitations in the prior art, and achieves high security and high-precision time synchronization in any channel environment.
Patent Information
- Application Number
- CN202211656673.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-22
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2042-12-22
AI Technical Summary
The existing network time synchronization message transmission method has significant flaws in terms of security and application scenario limitations, especially in terms of time-delay attacks, the timestamp is susceptible to tampering, and the identity authentication mechanism cannot take into account the security and accuracy of time synchronization.
Polar encoding and OFDM-IM modulation technology are used to classify the data bits of time synchronization messages, generate the first coding sequence and perform constellation modulation, and IM modulation is performed according to the number of molecular blocks of the legal receiving end, and interleaved using the total frequency domain channel matrix features of the preset channel simulation system. Finally, OFDM-IM signal processing is performed on the legal receiving end to improve security.
In any channel environment, by controlling the frequency selectivity of the transmission channel, the security of network time synchronization messages is enhanced, the limitations of application scenarios are solved, and the security of timestamps and the accuracy of time synchronization is improved.
Smart Images

Figure CN115967463B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication technologies, and particularly to a method and apparatus for secure transmission of network time synchronization messages applicable to any channel environment. Background Art
[0002] Network time synchronization technology refers to a technology that uses a network as a medium and enables computers or instrument devices connected to the network to achieve time synchronization through message interaction. Network time synchronization protocols include the Network Time Protocol (NTP) and the Precision Time Protocol (PTP, IEEE 1588). Currently, the standardization work on NTP and PTP security mechanisms is still ongoing. From the latest standardized results of NTP and PTP security mechanisms, these mechanisms can provide basic security functions such as identity authentication, data integrity protection, replay attack suppression, etc., but there are still significant defects. For example, there are large limitations in delay attacks. The timestamps in network time synchronization messages are transmitted publicly in the network and are vulnerable to tampering attacks; it is impossible to balance the security of time synchronization and the accuracy of time synchronization; and the current methods cannot fully apply to the identity authentication mechanism of network time synchronization.
[0003] It can be seen that the application scope of the current network time synchronization message transmission method is limited and there are certain security vulnerabilities. Summary of the Invention
[0004] In view of the above problems, the present invention provides a method and apparatus for transmitting network time synchronization messages applicable to any channel environment, which can be applied to any channel environment and solves the problem of limited application scenarios in the secure transmission of network time synchronization messages.
[0005] To achieve the above object, the present invention provides the following technical solutions:
[0006] A method for transmitting network time synchronization messages applicable to any channel environment, the method comprising:
[0007] Classify the data bits of the time synchronization message to be transmitted to obtain public information bits and secret information bits;
[0008] Based on the public information bits and the secret information bits, perform Polar coding on the data bits of the time synchronization message to obtain a first coding sequence;
[0009] Perform constellation modulation on the first coding sequence to obtain a symbol vector;
[0010] Divide all data subcarriers within the transmission bandwidth into several sub - blocks according to the number of legitimate receivers, and divide each sub - block to obtain several clusters. Perform IM modulation on each cluster to determine the active sub - carrier indices of each cluster;
[0011] Based on the characteristics of the total frequency - domain channel matrix of the preset channel simulation system, interleave the symbol vector and determine the active sub - carrier indices carrying the symbol vector;
[0012] Modulate the interleaved symbol vector onto the active sub - carriers selected for each sub - block to complete OFDM - IM modulation and obtain an OFDM - IM signal;
[0013] Transmit the OFDM - IM signal to each of the legitimate receivers.
[0014] Optionally, the method further includes:
[0015] Determine the information - bit channels, where the information - bit channels include a secret - bit channel and a public - bit channel. The secret - bit channel is used to transmit the secret information bits, the public - bit channel is used to transmit the public information bits, and the sum of the information - bit channels and the frozen - bit channels is the total bit channel;
[0016] Based on the Bhattacharyya parameters of each bit channel in the total bit channel, determine the information - bit channel index set, the public - bit channel index set, the secret - bit channel index set, and the frozen - bit channel index set.
[0017] Optionally, the Polar - encoding the data bits of the time - synchronization message based on the public information bits and the secret information bits to obtain a first encoded sequence includes:
[0018] Generate a Polar - code generation matrix;
[0019] According to each index set, extract the corresponding rows of the generation matrix to obtain each sub - matrix. Each index set includes the information - bit channel index set, the public - bit channel index set, the secret - bit channel index set, and the frozen - bit channel index set;
[0020] Based on the secret information bits and the secret - information - bit vector corresponding to the message - forwarding indication vector, the public - information - bit vector corresponding to the public information bits, the frozen vector, and each sub - matrix, perform Polar encoding on the data bits of the time - synchronization message to obtain a first encoded sequence.
[0021] Optionally, the dividing each sub - block to obtain several clusters includes:
[0022] Obtain the number of sub-links included in the actual transmission link from the sender to the legitimate receiver in the network;
[0023] Determine the number of clusters based on the number of sub-links;
[0024] Divide each sub-block according to the number of clusters to obtain a number of clusters, where a specific number of clusters are reserved for link security information transmission, and the remaining clusters are used to transmit time synchronization message data.
[0025] Optionally, perform IM modulation on each cluster to determine the active subcarrier indices of each cluster, including:
[0026] Number the several clusters of each sub-block respectively, so that the IM data of each numbered cluster carries different information. Among them, the IM data of the first 3 clusters carry the sender identification code, the receiver identification code, and the numbers of all sub-links included in the predetermined route respectively, and the IM data of the remaining clusters carry the channel simulation system indication data of each sub-link. The channel simulation system indication data of the sub-link is used to indicate the number and passing order of the channel simulation system that the time synchronization message needs to go through on this sub-link;
[0027] Perform IM modulation on each cluster according to the information to be carried by each cluster to determine the active subcarrier indices of each cluster.
[0028] Optionally, the method of interleaving the symbol vector based on the total frequency domain channel matrix characteristics of the preset channel simulation system and determining the active subcarrier indices carrying the symbol vector includes:
[0029] Determine the total frequency domain channel matrix of the channel simulation system based on the transfer functions of the preset channel simulation systems;
[0030] Calculate the channel gains added by the channel simulation system for each active subcarrier within each sub-block based on the total frequency domain channel matrix of the channel simulation system;
[0031] Interleave the symbol vector based on the channel gains and determine the active subcarrier indices carrying the symbol vector.
[0032] Optionally, the method of modulating the interleaved symbol vector onto the selected active subcarriers of each sub-block to complete OFDM-IM modulation and obtain an OFDM-IM signal includes:
[0033] Determine the length of the noise vector for each sub-block based on the symbol vector length and the number of active subcarriers of each sub-block, and generate a noise vector;
[0034] Generate a frequency domain vector based on the link security information vector, the message data symbol vector, and the noise vector;
[0035] Generate a time-domain vector based on the frequency-domain vector;
[0036] Perform OFDM-IM modulation based on the frequency-domain vector and the time-domain vector to obtain an OFDM-IM signal.
[0037] Optionally, the method further includes:
[0038] During the signal transmission process, each of the channel simulation systems and each switching device during the transmission process processes the OFDM-IM signal based on the dedicated link working mechanism.
[0039] Optionally, the method further includes:
[0040] In response to the legitimate receiver receiving the OFDM-IM signal, process the OFDM-IM signal based on a reverse processing mode that matches the generation processing mode of the OFDM-IM signal to obtain the time synchronization message, where the reverse processing mode at least includes OFDM demodulation, IM demodulation, generation of the total frequency-domain channel matrix of the channel simulation system, deinterleaving, constellation demodulation, Polar decoding, and determination of the transmission security of the message according to the bit error rate of the message forwarding indication vector.
[0041] A network time synchronization message transmission device applied to any channel environment, the device includes:
[0042] A classification unit, configured to classify the data bits of the time synchronization message to be transmitted to obtain public information bits and secret information bits;
[0043] A Polar coding unit, configured to perform Polar coding on the data bits of the time synchronization message based on the public information bits and the secret information bits to obtain a first coding sequence;
[0044] A constellation modulation unit, configured to perform constellation modulation on the first coding sequence to obtain a symbol vector;
[0045] A first determination unit, configured to divide all data subcarriers within the transmission bandwidth into several sub-blocks according to the number of legitimate receivers, and divide each sub-block to obtain several clusters, perform IM modulation on each cluster, and determine the active subcarrier indexes of each cluster;
[0046] A second determination unit, configured to interleave the symbol vector based on the characteristics of the total frequency-domain channel matrix of the preset channel simulation system, and determine the active subcarrier indexes carrying the symbol vector;
[0047] An OFDM modulation unit, configured to modulate the interleaved symbol vector onto the active subcarriers selected for each sub-block to complete OFDM-IM modulation and obtain an OFDM-IM signal;
[0048] A signal transmitting unit, configured to transmit the OFDM-IM signal to each of the legitimate receivers
[0049] Compared with the prior art, the present invention provides a method and apparatus for transmitting network time synchronization messages applicable to any channel environment and applied to a sending end, including: classifying data bits of the time synchronization message to be transmitted to obtain public information bits and secret information bits; performing Polar coding on the data of the time synchronization message based on the public information bits and the secret information bits to obtain a first coding sequence; performing constellation modulation on the first coding sequence to obtain a symbol vector; dividing all data subcarriers within the transmission bandwidth into several sub-blocks according to the number of legitimate receivers, and dividing each sub-block to obtain several clusters, performing IM modulation on each cluster to determine the active subcarrier indices of each cluster; performing interleaving on the symbol vector based on the total frequency-domain channel matrix characteristics of a preset channel simulation system, and determining the active subcarrier indices carrying the symbol vector; modulating the interleaved symbol vector onto the active subcarriers selected for each sub-block to complete OFDM-IM modulation, and transmitting the modulated OFDM-IM signal to each legitimate receiver; during the signal transmission process, each channel simulation system and each switching device process the OFDM-IM signal according to the dedicated link working mechanism. The legitimate receiver performs OFDM demodulation, IM demodulation, generation of the total frequency-domain channel matrix of the channel simulation system, deinterleaving, constellation demodulation, and Polar decoding on the received OFDM-IM signal. The security of the message transmission is determined according to the bit error rate of the message forwarding indication vector. The present invention can control the frequency selectivity of the transmission channel through the channel simulation system and its supporting dedicated link working mechanism, and can be applied to any channel environment, solving the problems of poor security of network time synchronization message transmission and limited application scenarios. BRIEF DESCRIPTION OF THE DRAWINGS
[0050] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.
[0051] Figure 1 Schematic diagram of a principle block diagram for implementing OFDM modulation through IFFT provided by an embodiment of the present invention
[0052] Figure 2 Principle block diagram for implementing OFDM demodulation through FFT provided by an embodiment of the present invention
[0053] Figure 3Schematic diagram of a frequency-domain model for OFDM transmission and reception provided by an embodiment of the present invention;
[0054] Figure 4 Schematic diagram of a first-order tap frequency-domain equalizer provided by an embodiment of the present invention;
[0055] Figure 5 Schematic flowchart of a network time synchronization message transmission method applicable to any channel environment provided by an embodiment of the present invention;
[0056] Figure 6 Schematic diagram of an NTPv4 data packet format protected by NTS provided by an embodiment of the present invention;
[0057] Figure 7 Schematic diagram of a security algorithm link provided by an embodiment of the present invention;
[0058] Figure 8 Schematic diagram of a dedicated link communication frame structure provided by an embodiment of the present invention;
[0059] Figure 9 Schematic diagram of a structure of a network time synchronization message transmission device applicable to any channel environment provided by an embodiment of the present invention. Detailed implementation manners
[0060] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0061] The terms "first" and "second" etc. in the specification and claims of the present invention and the above accompanying drawings are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but may include steps or units not listed.
[0062] In an embodiment of the present invention, a network time synchronization message transmission method applicable to any channel environment is provided. Based on Polar coding, OFDM-IM modulation is introduced, and by controlling the frequency selectivity of the transmission channel, the channel quality difference between the legal main channel and the illegal tap channel is constructed. It solves the security problem caused by the close channel quality between the illegal tap channel and the legal main channel, where the secret bit channel cannot be constructed or the quantity cannot meet the actual requirements.
[0063] In order to facilitate the description of the technical features in the embodiments of the present invention, the relevant technologies applied by the present invention are now described.
[0064] Polar code technology:
[0065] Polar code is a channel coding method proposed by Erdal Arikan, a professor at Bilkent University in Turkey in 2007. By performing Polar coding on the original information bits, N consecutive applications of a given binary-input discrete memoryless channels (B-DMCs) W (serial transmission of an N-bit vector) can be combined and split into N bit channels with polarization effects.
[0066] Polar code is a special form of block code (also called group code). The data block length N is limited to N = 2 n (n≥0), for any N-bit original data block Its Polar coded data block is shown in formula (1).
[0067]
[0068]
[0069]
[0070] Among them, G N Generates a matrix of order N; I N is the N-order unit matrix; R N Represents a permutation operation; represents the Kronecker product Kronecker power Defined as (for all n ≥ 1). By convention,
[0071] For any subset A of {1,…,N}, formula (1) can be written as:
[0072]
[0073] Among them, G N (A) is G N The corresponding row index is determined by A; Represents modulo 2 addition.
[0074] If \(A\) and \(u\) are fixed A , let \(u\) A be a free variable, and a mapping from the source data block \(u\) A to the coded data block can be obtained. This mapping is called coset coding: the coset coding generating matrix is \(G\) N (\(A\)), and the coset is determined by the given vector \(u\) A \(G\) N (\(A\)). Codes of this type are collectively called \(G\) N -coset codes. \(G\) N -coset codes can be uniquely determined by the parameter vector \((N, K, A, u\) A ), where \(K\) is the dimension of the code, which determines the size of \(A\); \(K / N\) is called the code rate \(R\); \(A\) is the set of information bit indices; \(u\) A is the \(N - K\) bit frozen vector.
[0075] Based on the above coding method, Polar codes give specific rules for the selection of the information set \(A\): Given the B-DMC channel \(W\), when the information bit index set \(A\) is selected from all \(K\)-element subsets of \(\{1, \ldots, N\}\), such that for all \(i\in A\), \(j\in A\) c , the Bhattacharyya parameter is satisfied, then the \(G\) A -coset code with the parameter vector \((N, K, A, u\) N ) is called the Polar code of the channel \(W\).
[0076] Polar coding realizes channel polarization. After coding, any bit \(x\) of the codeword will reach the receiving end via the bit channel \(W\) i (i) N . The bit channel has the polarization property: when \(N\) is large, the capacity of some channels will tend to 1, while the capacity of the remaining channels will tend to 0, and the proportion of channels with a capacity of 1 in the total number of channels is exactly the capacity \(I(W)\) of the original binary input discrete channel. This means that among the \(N\) bit channels, there are bit channels that can achieve error-free transmission of information bits. The actual number of information bits in the original data block
[0077] OFDM modulation technology:
[0078] Orthogonal Frequency Division Multiplexing (OFDM) technology, simply referred to as OFDM technology, is a multi-carrier baseband modulation technology with the following basic characteristics:
[0079] (1) A large number of narrow subcarriers are adopted. The OFDM modulation technology divides the effective transmission bandwidth into multiple mutually orthogonal narrow subcarriers, and each such subcarrier can carry an independent information stream. On the same transmission link, thousands of subcarriers are allowed to transmit simultaneously.
[0080] (2) High spectrum utilization rate. The subcarriers in the frequency domain are arranged closely, and the subcarrier spacing is Δf = 1 / T u , where T u is the duration of the modulation symbol carried in each subcarrier.
[0081] (3) Low implementation complexity. OFDM can achieve low-complexity modulation and demodulation through efficient Inverse Fast Fourier Transform (IFFT) and Fast Fourier Transform (FFT) operations.
[0082] In the time domain, OFDM is a modulation based on fast. Within each OFDM symbol interval, a total of N c modulation symbols are transmitted in parallel, which is also the reason why OFDM modulation can obtain a high data transmission efficiency. The modulation symbols can adopt any constellation modulation method, such as Binary Phase Shift Keying (BPSK) modulation, Quadrature Phase Shift Keying (QPSK) modulation, etc.
[0083] In the frequency domain, OFDM divides the effective transmission bandwidth into a series of orthogonal and overlapping narrow subcarriers. The spectrum of each subcarrier is a sine-squared spectrum and can be described by the sinc function (sinc(x) = sin(x) / x). The characteristics of the subcarrier spectrum are that the main lobe is narrow, while the side lobes extend infinitely in the +∞ and -∞ directions. To avoid carrier leakage, the center frequencies of each subcarrier are usually distributed on both sides of the signal center frequency (the baseband signal is zero frequency). Since the bandwidth of each subcarrier (the main lobe width of the sinc function) is very narrow, even if there is channel distortion within the entire transmission bandwidth, for each subcarrier, within the main lobe range of its spectrum, the channel can be considered flat.
[0084] The reason why the OFDM modulation method is called orthogonal frequency division multiplexing is that its orthogonality is mainly reflected in that any two OFDM modulated subcarriers have a time interval of mT u≤t≤(m + 1)T u are all mutually orthogonal, that is:
[0085]
[0086] Therefore, OFDM can be regarded as modulation carried out by a series of orthogonal functions φ k (t), where:
[0087]
[0088] OFDM can achieve low - complexity modulation through an efficient IFFT operation. Assume a time - discrete (sampled) OFDM signal, whose sampling rate fs is an integer multiple of the sub - carrier spacing Δf, that is: f s = 1 / T s = N·Δf. The parameter N should be selected considering fully satisfying the sampling theorem. Since N s ·Δf can be regarded as the nominal bandwidth of the OFDM signal, this means that the value of N should be greater than N c and ensure sufficient margin. c
[0089] According to the above assumptions, the time - discrete OFDM signal can be described as:
[0090]
[0091] where,
[0092] Therefore, the sequence x n , that is, the sampled OFDM signal, is obtained by padding the original modulation symbol block a0, a1, …, a Nc-1 with zeros to extend the length to N and then performing an N - point Inverse Discrete Fourier Transform (IDFT). Therefore, OFDM modulation can be realized through an inverse Fourier transform followed by a digital - to - analog conversion, as shown in Figure 1 . In particular, when the number of points of the IDFT is selected as 2 m (m is an arbitrary integer), OFDM modulation can be realized through an efficient radix - 2 - IFFT.
[0093] Similar to OFDM modulation, OFDM demodulation can also be realized through an efficient FFT, that is, the analog signal becomes a discrete signal after sampling (f s = 1 / T s ), and then is realized through a DFT / FFT with N points, as shown in Figure 2 .
[0094] Under the influence of an actual complex channel, the orthogonality between subcarriers will be, at least partially, lost. In the time domain, it is manifested as that within an integration period of the demodulator, it includes not only the integer periods of the complex exponential corresponding to a certain subcarrier, but also the fractional periods, thus affecting the orthogonality between subcarriers; in the frequency domain, considering that each subcarrier has a special spectral structure. Even if the frequency-domain impulse response of the channel is constant within the main lobe bandwidth of each OFDM subcarrier, the distortion of the channel only damages the side lobes of that subcarrier, but since the side lobe range of each OFDM subcarrier is much larger than the main lobe, the distortion of the side lobes inevitably causes the loss of orthogonality between subcarriers, thereby causing interference between subcarriers.
[0095] To ensure the orthogonality between OFDM signal subcarriers in an actual channel environment, the OFDM technology adopts a simple method, that is, inserting a cyclic prefix. This method means copying the last part of the OFDM symbol and inserting it at the front end of the OFDM symbol. Therefore, inserting the cyclic prefix increases the length of the OFDM symbol from Tu to T u +T CP , where T CP is the cyclic prefix length. Therefore, after inserting the cyclic prefix, the symbol rate of OFDM will be correspondingly reduced.
[0096] Actually, the cyclic prefix insertion is performed after the IFFT. Therefore, the cyclic prefix insertion can be understood as copying the last N CP samples of the IFFT output block of length N and inserting them at the front of the block, increasing the block length from N to N+N CP . At the receiving end, the samples of the cyclic prefix part will be removed before OFDM demodulation (DFT / FFT processing).
[0097] Assuming that the cyclic prefix is long enough, within an integration period T u of the demodulator, the linear convolution of the channel can be regarded as a cyclic convolution. The OFDM modulation (IFFT processing), the channel, and the OFDM demodulation (FFT processing) can be combined and regarded as a frequency-domain channel, as Figure 3 shown, where the frequency-domain channel taps H0,…,H NC-1 can be directly generated from the channel impulse response.
[0098] Figure 3 In k , the output b k of the demodulator is the weighted sum and phase rotation of the transmitted modulation signal a k through the complex frequency-domain channel tap H kIn order to further process the received signal to correctly recover the original data bits, that is, to perform constellation demodulation, the receiver needs to compensate for the distortion of the received signal amplitude and phase caused by the channel. This operation is called equalization, such as Figure 4 A schematic diagram of a first-order tap frequency domain equalizer is given.
[0099] After inserting the cyclic prefix, from the receiver's perspective, the received symbol can be viewed as a circular convolution of the transmitted symbol and the channel, so no overlap-and-discard processing is required at the receiver. The taps of the frequency domain equalizer can be directly calculated by estimating the sample values of the channel frequency response. Taking the MMSE equalizer as an example, its frequency domain filter taps can be calculated using Equation (9).
[0100]
[0101] Where N0 is the noise power; H k is the discrete channel frequency response.
[0102] Through equalization, the impact of non-ideal channel characteristics on the received signal can be effectively suppressed, ensuring the orthogonality between subcarriers.
[0103] OFDM-IM modulation technology:
[0104] OFDM-IM (OFDM with index modulation) modulation technology is developed based on OFDM technology. Compared with traditional OFDM technology, this technology mainly expands the subcarrier index as a new way to carry information.
[0105] In OFDM-IM modulation, N c The subcarriers are divided into N g clusters, each cluster has n subcarriers, that is, N c =n·N g Different from the traditional OFDM technology (N c All subcarriers are used to carry data symbols). Of the n subcarriers in each cluster, only k subcarriers are selected for data transmission at a time, which are called active subcarriers, and k≤n. The combination of active subcarriers in each cluster is called an IM symbol. Different combinations of active subcarriers in a cluster constitute different IM symbols. The number of IM symbols that can be expressed by the index of active subcarriers in each cluster is This is equivalent to the number of bits that can be carried by the active subcarrier index of each cluster being ( The index set of active subcarriers of the βth cluster can be expressed as:
[0106] I β ={i β,0 ,…,i β,k-1} (10)
[0107] Among them, i β,u ∈{1,2,…,n}, and u=0,1,…,k-1.
[0108] Once the active subcarriers are determined, as in traditional OFDM modulation, each active subcarrier can carry one data symbol. Assuming the constellation modulation order of the data symbol is l (for example, l = 1 for BPSK and l = 2 for QPSK), the number of bits carried by the active subcarriers in each cluster is B2 = k·l. Therefore, the total number of bits transmitted in each cluster is B1 + B2.
[0109] The OFDM-IM symbol vector is denoted as where x β =[x β (0),…,x β (n-1)] T Refers to the transmission symbol vector of the βth cluster. β (i), if i∈I β , then x β (i) is a data symbol; otherwise, x β (i)=0.
[0110] The modulation and demodulation processes of OFDM-IM technology are similar to those of OFDM, except that clustering and active subcarrier selection are added before the IFFT in the modulation phase, and IM demodulation is added after the FFT in the demodulation phase. IM demodulation, or active subcarrier index detection, essentially checks all subcarriers one by one to determine whether they carry non-zero data symbols. If so, the subcarrier is considered active. Currently, mainstream detectors include the Maximum Likelihood (ML) detector, the Log-Likelihood Ratio (LLR) detector, and the Coherent OOK (On-Offkeying) detector.
[0111] For details, see Figure 5 , which is a flow chart of a method for transmitting a network time synchronization message in an arbitrary channel environment provided by an embodiment of the present invention. The method may include the following steps:
[0112] S101. Classify data bits of a time synchronization message to be transmitted to obtain public information bits and secret information bits.
[0113] S102. Perform Polar coding on the data bits of the time synchronization message based on the public information bits and the secret information bits to obtain a first coding sequence.
[0114] S103. Perform constellation modulation on the first coding sequence to obtain a symbol vector.
[0115] S104. Divide all data subcarriers within the transmission bandwidth into several sub-blocks according to the number of legitimate receivers, and further divide each sub-block to obtain several clusters. Perform IM modulation on each cluster to determine the active subcarrier indices of each cluster.
[0116] S105. Interleave the symbol vector based on the characteristics of the total frequency-domain channel matrix of the preset channel simulation system, and determine the active subcarrier indices carrying the symbol vector.
[0117] S106. Modulate the interleaved symbol vector onto the active subcarriers selected for each sub-block to complete OFDM-IM modulation and obtain an OFDM-IM signal.
[0118] S107. Send the OFDM-IM signal to each of the legitimate receivers.
[0119] It should be noted that during the signal transmission process, each channel simulation system and each switching device process the OFDM-IM signal according to the dedicated link working mechanism. Correspondingly, the legitimate receiver performs OFDM demodulation, IM demodulation, generation of the total frequency-domain channel matrix of the channel simulation system, deinterleaving, constellation demodulation, and Ploar decoding on the received OFDM-IM signal. Determine the security of the message transmission according to the bit error rate of the message forwarding indication vector. The specific implementation of this part will be described in detail in the subsequent embodiments of the present invention.
[0120] In this embodiment, the OFDM-IM modulation technology is introduced into the network time synchronization data packet based on Polar codes. Utilize the special time and frequency domain structures and orthogonality characteristics of OFDM signals to achieve the degradation of illegal tapping channels and improve the system security rate.
[0121] First, in step S101, classify the data bits of the time synchronization message to be transmitted, so as to further improve the security of the information bits that need to be protected during transmission. Divide the information bits that need to be protected during transmission into secret information bits, and the other bits are divided into public information bits. Taking NTP (Network Time Protocol) as an example, its data packet format is as Figure 6 shown.
[0122] Figure 6Among them, LI: Leap Second Indicator, a 2-bit unsigned integer, indicating whether a positive or negative leap second will be implemented in the last minute of the current month; VN: Version Number, a 3-bit unsigned integer, currently 4; Mode: Working Mode, a 3-bit unsigned integer; Stratum: Stratum Number, an 8-bit unsigned integer, indicating levels 1 - 15; Poll: an 8-bit signed integer, indicating the maximum time interval between consecutive time synchronization messages, calculated as log2(x) seconds; Precision: an 8-bit signed integer, indicating the precision of the system clock, calculated as log2(x) seconds; Root Delay: the total round-trip delay to the reference clock; Root Dispersion: the total time deviation from the reference clock; Reference ID: a 32-bit coded sequence used to indicate a specific server or reference clock; Reference Timestamp: the reference timestamp indicating the time when the system clock was last calibrated; Origin Timestamp: the timestamp of the time synchronization request message, indicating the moment when the request message leaves the client and is sent to the server, with the client time as the reference; Receive Timestamp: the timestamp of the time synchronization request message reception, indicating the moment when the request message arrives at the server, with the server time as the reference; Transmit Timestamp: the timestamp of the time synchronization response message transmission, indicating the moment when the response message leaves the server and is sent to the client, with the server time as the reference; Destination Timestamp: the timestamp of the time synchronization response message reception, indicating the moment when the response message arrives at the client, with the client time as the reference. It should be noted that the Destination Timestamp field is not included in the response packet, but is determined by the client and written into the corresponding data structure in the client packet buffer. The above fields are the regular part of the NTP packet, totaling 12 × 32 bits.
[0123] This is followed by the extended portion of the NTP data packet (optional), which contains four new extended fields of NTS. The purpose of this portion is to provide NTS protection for the NTP data packet. Starting from the Nonce Length field is the format of the NTS authentication and encryption extended field. Nonce Length: A 16-bit unsigned integer used to indicate the length of the Nonce field; Ciphertext Length: A 16-bit unsigned integer used to indicate the length of the ciphertext field; Nonce: Provides the nonce required by the AEAD algorithm. If the nonce is less than 32 bits, it is padded with zeros; Ciphertext: The output of the AEAD algorithm. The structure of this field is determined by the actual algorithm used, but it usually contains an authentication tag and the actual ciphertext. If it is less than 32 bits, it is padded with zeros; Additional Padding: If the nonce length used by the client is less than the maximum length allowed by the AEAD algorithm used, the extended portion of the data packet may require the inclusion of this field.
[0124] The current NTP data packet format, except for the NTS authentication and encryption extension fields, is plain text, that is, the message content is not encrypted and is only protected by authentication. From the perspective of suppressing timestamp tampering attacks and being compatible with current security mechanisms, Figure 5 The four timestamp fields in the message—Reference Timestamp, Origin Timestamp, Receive Timestamp, and Transmit Timestamp—should be classified as secret information bits, while the other message fields should be classified as public information bits. It is worth noting that after Polar encoding, the public information bits are transmitted via a public bit channel, which is essentially no different from the current transmission mechanism. This means that the fields included in the public information bit set are still protected by the current security mechanism. The network time synchronization security algorithm based on Polar codes proposed in this invention focuses on enhancing the security of timestamp data, which is the weak link in the current security mechanism.
[0125] In step S102, after obtaining the public information bits and the secret information bits, combined with the bit channel parameters, that is, first determining the information bit channel, which includes a secret bit channel and a public bit channel. Among them, the secret bit channel is used to transmit the secret information bits, the public bit channel is used to transmit the public information bits, and the sum of the information bit channel and the frozen bit channel is the total bit channel. Then, based on the Bhattacharyya parameters of each bit channel in the total bit channel, an information bit channel index set, a public bit channel index set, a secret bit channel index set, and a frozen bit channel index set can be determined. Then, based on various types of information bits, the frozen vector, and the corresponding index sets, Polar coding is performed on the bit data of the time synchronization message to obtain a first coding sequence. For example, in one implementation, the information bit channel is determined, and the information bit channel includes a secret bit channel and a public bit channel. The secret bit channel is used to transmit the secret information bits, and the public bit channel is used to transmit the public bit channel. The sum of the information bit channel and the frozen bit channel is the total bit channel; based on the Bhattacharyya parameters of each bit channel in the total bit channel, an information bit channel index set, a public bit channel index set, a secret bit channel index set, and a frozen bit channel index set are determined.
[0126] In the process of performing Polar coding in step S103, the above information can be utilized. In one implementation, based on the public information bits and the secret information bits, Polar coding is performed on the data bits of the time synchronization message to obtain a first coding sequence, including: generating a Polar code generation matrix; according to each index set, extracting the corresponding rows of the generation matrix to obtain each sub-matrix, and each index set includes an information bit channel index set, a public bit channel index set, a secret bit channel index set, and a frozen bit channel index set; based on the secret information bits and the secret information bit vector corresponding to the message forwarding indication vector, the public information bit vector corresponding to the public information bits, the frozen vector, and each sub-matrix, Polar coding is performed on the data bits of the time synchronization message to obtain a first coding sequence.
[0127] Specifically, after determining the public information bits and the secret information bits, determine the number of secret bit channels K s , the number of public bit channels K p , the number of information bit channels K, and the total number of bit channels N.
[0128] Taking NTP as an example, the number of secret bit channels K sIt is determined by the total number of timestamp data bits (64×4) and the length of the message forwarding indicator vector. The message forwarding indicator vector is designed as a random sequence, and the sequence length is determined by the actual physical channel bandwidth resources, channel quality, and the performance requirements for suppressing delay attacks and timestamp tampering attacks. In order to avoid the introduction of large additional complexity, delay uncertainty, and new security risks by sharing the message forwarding indicator vector between the client and the server, the client key or its truncated sequence can be used as the message forwarding indicator vector in combination with the NTS protocol. The client key length is 256 bits. If it is used as the message forwarding indicator vector, the number of secret bit channels K can be determined. s 512 bits.
[0129] Number of public bit channels K p Determined by the total number of bits in all fields except the timestamp field in the NTP packet.
[0130] The number of channel bit channels K should satisfy K ≥ K s +K p , from the perspective of transmission efficiency, it can be equal to , and from the perspective of security, it can be appropriately larger than the number of information bits actually transmitted.
[0131] The total number of bit channels, N, is also the code length of the Polar code and must satisfy the following constraints:
[0132]
[0133] Where W is the given channel, where N = 2 n ; I(W) is the symmetric capacity of channel W; Indicates rounding down.
[0134] Furthermore, the Polar code generation matrix G can be calculated based on equations (2) and (3) in the relevant information of the aforementioned Polar technical features. N .
[0135] Calculate the Bhattacharya parameter for each bit channel If W is a BEC channel (with an erasure probability of ε), the parameter It can be obtained by recursive calculation, that is,
[0136]
[0137]
[0138] in, parameter Equal to channel The probability of deletion.
[0139] Among the Bhattacharyya parameters of N bit channels, select the K smallest ones The corresponding indexes form the information bit channel index set Among select K p the smallest ones The corresponding indexes form the public information bit channel index set Select K s the largest ones The corresponding indexes form the secret information bit channel index set The bit channels corresponding to the remaining indexes can be reserved for the transmission of other necessary information bits not mentioned in the present invention; The complement of is denoted as
[0140] According to the index sets and extract the corresponding rows of the generating matrix G N to generate the submatrices and
[0141] The secret information bit vector is composed of the timestamp data bits and the message forwarding indication vector, denoted as u s ; Other message fields form the public information bit vector, denoted as u p ; The frozen vector is set to the zero vector, denoted as Then the codeword after Polar coding of the original time synchronization data packet is
[0142]
[0143] After obtaining the first coding sequence in step S103, the bits in the first coding sequence can be subjected to constellation modulation to obtain a symbol vector.
[0144] Perform constellation modulation on the codeword to obtain the symbol vector where N c is the number of OFDM data subcarriers required to transmit a time synchronization message.
[0145]
[0146] In the formula, k is the index of the modulation symbol vector ; x k,m refers to the l codeword bits mapped to the kth modulation symbol, and m is its index; Refers to the constellation modulation function; l is the modulation order. If BPSK modulation is used, l = 1. If QPSK modulation is used, l = 2.
[0147] In step S104, all data subcarriers within the transmission bandwidth are divided into several subblocks according to the number of legal receiving terminals, and each subblock is divided into several clusters. IM modulation is performed on each cluster to determine the active subcarrier index of each cluster.
[0148] The method of dividing each sub-block into several clusters includes: obtaining the number of sub-links contained in the actual transmission link from the transmitter to the receiver in the network; determining the number of clusters based on the number of sub-links; dividing each sub-block into several clusters based on the number of clusters, wherein a specific number of clusters are reserved for link security information transmission, and the remaining clusters are used to transmit time synchronization message data. Correspondingly, IM modulation is performed on each cluster to determine the active subcarrier index of each cluster, including: numbering the several clusters of each sub-block, wherein the IM data of each numbered cluster carries different information, wherein the IM data of the first three clusters respectively carries the transmitter identification code, the receiver identification code, and the numbers of all sub-links contained in the predetermined route, and the IM data of the subsequent remaining clusters respectively carries the channel simulation system indication data of each sub-link, wherein the sub-link information simulation system indication data is used to indicate the number and order of the channel simulation systems that the time synchronization message needs to traverse on the sub-link; IM modulation is performed on each cluster based on the information that each cluster needs to carry, and the active subcarrier index of each cluster is determined.
[0149] Specifically, considering all the operating modes defined by the NTP and PTP protocols, from the perspective of message transmission, there are two basic modes: unicast and broadcast, namely one-to-one and one-to-many. The difference between the two is whether there is a single legitimate receiver or multiple legitimate receivers.
[0150] The present invention regards unicast as a special form of broadcast. Without loss of generality, consider a transmitter and n receivers. If it is unicast, then n=1; if it is broadcast, then n>1. In step S103, the time synchronization message sent to each receiver needs to occupy N c data subcarriers.
[0151] All data subcarriers N contained in an OFDM-IM symbol D Divided into n sub-blocks, one sub-block is used to transmit a time synchronization message to a legal receiving end R i (1≤i≤η). Each sub-block is divided into N g,j clusters, each containing n i data subcarriers (1≤i≤η). g,j Equal to the distance from the sender to the receiver in the network R iThe number of sub-links included in the actual transmission link (with the route determined in advance) (considering switching devices such as switches, routers, and repeaters in the network, the links from the sending end to the switching device, from the switching device to the switching device, and from the switching device to the receiving end are all sub-links) plus 3. N g,j Among the N g,j (N i - 3)·n c (1 ≤ i ≤ η).
[0152] For each of the N g,j clusters in each sub-block, they are numbered 1, 2,..., N g,j respectively. The IM data carried by the cluster numbered 1 bears the sending end identification code (pre-allocated and unique in the system), the IM data carried by the cluster numbered 2 bears the receiving end identification code (pre-allocated and unique in the system), the IM data carried by the cluster numbered 3 bears the routing information, that is, the sub-link numbers of the first to the N g,j - 3 sub-links (pre-allocated and uniquely identifying each sub-link in the network). The N g,j clusters numbered from 4 to N g,j correspond to the first, second,..., jth until the N g,j - 3 sub-links of the actual transmission link respectively. Their IM data bears the sub-link channel simulation system indication data. The sub-link channel simulation system indication data is used to indicate the number (pre-allocated, with different transfer functions corresponding to different channel simulation system numbers) and the traversal order (traversing in the order of the numbers) of the channel simulation system that the time synchronization message needs to go through on this sub-link. According to the above design, the active subcarrier indices of each cluster are determined (1 ≤ j ≤ N g,j , 1 ≤ p j,i < n i ).
[0153] In this embodiment, it is required that a number of frequency-selective Rayleigh channel simulation systems are pre-deployed on all physical sub-links in the network. Its transfer function H j,v (4 ≤ j ≤ N g,i , 1 ≤ v ≤ r) is as shown in Equation (17), where r is the number of channel simulation systems deployed on a certain sub-link. The channel simulation system on the sub-link corresponding to sub-block i and cluster j only acts on the n i data subcarriers of this cluster. The first 3 clusters of each sub-block do not go through any channel simulation systems.
[0154]
[0155] In step S105, the total frequency-domain channel matrix characteristics of the preset channel simulation system can be used to interleave the symbol vector, determine the active subcarrier indices carrying the symbol vector, and then perform OFDM-IM modulation based on step S106. In step S107, the obtained OFDM-IM signal is sent to each legitimate receiver.
[0156] In one implementation, the method of interleaving the symbol vector and determining the active subcarrier indices carrying the symbol vector based on the total frequency-domain channel matrix characteristics of the preset channel simulation system includes: determining the total frequency-domain channel matrix of the channel simulation system based on the transfer function of each preset channel simulation system; calculating the channel gains added by the channel simulation system for each active subcarrier within each sub-block based on the total frequency-domain channel matrix of the channel simulation system; interleaving the symbol vector based on the channel gains of the active subcarriers, and determining the active subcarrier indices carrying the symbol vector. Further, modulating the interleaved symbol vector onto the selected active subcarriers of each sub-block to complete OFDM-IM modulation and obtain an OFDM-IM signal includes: determining the length of the noise vector for each sub-block based on the length of the symbol vector and the number of active subcarriers in each sub-block, and generating the noise vector; generating a frequency-domain vector based on the link security information vector, the message data symbol vector, and the noise vector; generating a time-domain vector based on the frequency-domain vector, and performing OFDM-IM modulation based on the frequency-domain vector and the time-domain vector to obtain an OFDM-IM signal.
[0157] During signal transmission, each channel simulation system and each switching device process the OFDM-IM signal according to the dedicated link working mechanism. The legitimate receiver performs OFDM demodulation, IM demodulation, generation of the total frequency-domain channel matrix of the channel simulation system, deinterleaving, constellation demodulation, and Polar decoding on the received OFDM-IM signal. The security of message transmission is determined according to the bit error rate of the message forwarding indication vector.
[0158] Specifically, before each transmission of the time synchronization message, the sender pre-determines the routes to each receiver and the channel simulation systems that the message needs to go through on each sub-link and the order of passage. The link schematic diagram is as Figure 7 shown.
[0159] In the embodiment of the present invention, it is assumed that the channel simulation systems and intermediate devices on all sub-links are trusted, and they are connected through dedicated links to form an independent security network, which is shielded from all terminals. The channel simulation systems deployed on each link and between the channel simulation system and the switching device can communicate through dedicated links. The frame structure of the dedicated link communication is as Figure 8As shown. Each legal receiving end corresponds to a dedicated link communication frame. The first two fields of each frame carry the identification codes of the sending end and the legal receiving end respectively, followed by each subframe. Each subframe corresponds to a sublink, subframe 1 corresponds to the first sublink, subframe 2 corresponds to the second sublink, and so on. The subframe consists of 4 fields. The first field carries the sublink number, which specifies the mapping relationship between each sublink and the actual sublink; the second and third fields carry the current sending device number and destination device number of the frame respectively, which may be a channel simulation system or a switching device; the fourth field carries the number and order of the channel simulation system that the time synchronization message needs to pass through on the sublink.
[0160] The transmitter first sends a time synchronization message to the first channel simulation system. After receiving the OFDM-IM signal, the first channel simulation system performs channel equalization on the signal based on the previous channel estimation results (channel estimation between each device and its neighbors can be performed periodically). It then demodulates the IM data of the corresponding sub-block to obtain the transmitter identification code, receiver identification code, sublink numbers, and the sublink channel simulation system numbers and sequence that each sub-link must traverse. Based on this information, the first channel simulation system generates a dedicated link communication frame while applying frequency-selective fading to the OFDM-IM signal. After processing, the dedicated link communication frame (fields 2 and 3 of subframe 1) is updated based on the IM information and transmitted along with the OFDM-IM signal to the second channel simulation system.
[0161] The second channel simulation system receives the dedicated link communication frame and OFDM-IM signal, recording their arrival times. Based on the previous channel estimation results, it performs channel equalization on the OFDM-IM signal, demodulates the IM data of the first two clusters of the corresponding sub-block, and compares it with the transmitter identification code and receiver identification code of the dedicated link communication frame. If they match, and the arrival time difference between the dedicated link communication frame and the OFDM-IM signal is within the limit, the signal is deemed normal and frequency selective fading is applied to the OFDM-IM signal. After processing, the dedicated link communication frame is updated based on the IM information and sent to the third channel simulation system along with the OFDM-IM signal. The processing of the third and subsequent channel simulation systems is identical to that of the second until transmission reaches the switching equipment at the end of sub-link 1. On the contrary, if the identification codes are inconsistent, the transmission of the OFDM-IM signal and the dedicated link communication frame will be terminated; if the dedicated link communication frame is not received, the system will remain in a silent state and the OFDM-IM signal will continue to be transmitted on the sub-link; if the OFDM-IM signal is not received, the transmission of the dedicated link communication frame will be terminated; if the arrival time difference exceeds the limit, it will be judged as abnormal, and the channel simulation system will not apply frequency selective fading to the OFDM-IM signal, and will update the dedicated link communication frame and send it and the OFDM-IM signal directly to the switching device at the end of sub-link 1.
[0162] After the switching device at the end of sub-link 1 receives the dedicated link communication frame and the OFDM-IM signal (if the dedicated link communication frame is not received, the transmission of the OFDM-IM signal is terminated; if the OFDM-IM signal is not received, the transmission of the dedicated link communication frame is terminated), it performs channel equalization on the OFDM-IM signal according to the previous channel estimation result, and compares the source and destination identification codes carried by the OFDM-IM signal and the dedicated link communication frame. If they are inconsistent, the signal transmission is terminated; if they are consistent, according to the 4th field of sub-frame 1 of the dedicated link communication frame, frequency selective fading imposed by all channel simulation systems of this sub-link is equalized. Under normal circumstances, the OFDM-IM signal has gone through all the preset channel simulation systems of this sub-link. At the switching device at the end, the influence of frequency selective fading introduced by the channel simulation system can be completely equalized. Under abnormal circumstances, the OFDM-IM signal is directly transmitted to the switching device at the end without going through all the channel simulation systems. Then, during the equalization process at the switching device, new frequency selective fading will be introduced. After the switching device at the end of sub-link 1 finishes processing, it updates the dedicated link communication frame (the 2nd and 3rd fields of sub-frame 2) according to the 1st and 4th fields of sub-frame 2 of the dedicated link communication frame, and sends it together with the OFDM-IM signal to the first channel simulation system of sub-link 2. The processing procedures of sub-link 2 and subsequent sub-links are the same as those of sub-link 1 until the last channel simulation system before the legal receiver.
[0163] The processing procedure of the last channel simulation system before the legal receiver is the same as that of the switching device. After receiving the dedicated link communication frame and the OFDM-IM signal, it performs channel equalization on the OFDM-IM signal according to the previous channel estimation result, and compares the source and destination identification codes carried by the OFDM-IM signal and the dedicated link communication frame. If they are inconsistent, the signal transmission is terminated; if they are consistent, according to the 4th field of sub-frame N g,i -3 of the dedicated link communication frame, frequency selective fading imposed by all channel simulation systems of this sub-link is equalized. After finishing the processing, the OFDM-IM signal is sent to the legal receiver according to the destination identification code.
[0164] In the above security mechanism, except for the first and the last channel simulation systems, the processing procedures of the remaining channel simulation systems are the same; the processing procedures of all switching devices are the same.
[0165] The deployment of the channel simulation system and the design of its working mechanism in the embodiments of the present invention aim to control the frequency selectivity between the OFDM-IM signals (legal signals) transmitted on the legal main channel and the OFDM-IM signals (illegal signals) transmitted on the illegal tap channel, so as to control the equivalent signal-to-noise ratio. On the premise of not affecting the capacity of the legal main channel, the capacity of the illegal tap channel is reasonably degraded.
[0166] During the OFDM-IM modulation process, according to the pre-determined routing and channel simulation system scheme, calculate the data sub-carrier channel gains determined by the channel simulation system within each sub-block (it should be noted that in the embodiments of the present invention, the actual physical channel is not considered, and the influence of the actual physical channel has been removed in the channel equalization performed by each level of equipment), as shown in Equations (18) and (19).
[0167]
[0168] In the formula, H Ri refers to the total frequency-domain channel matrix of the channel simulation system corresponding to the sub-block of the legal receiver R i , and H n,Ri is the nth diagonal element of H Ri ; r j is the number of channel simulation systems experienced by the jth cluster of this sub-block; the meanings of other symbols are the same as above. refers to the total transfer function of the channel simulation systems experienced by the OFDM-IM symbol on N i -3 sub-chains during the process of transmitting from the transmitter to the receiver R g,i .
[0169]
[0170] In the formula, is the channel gain (only determined by the channel simulation system) of the active sub-carrier with index q i in the jth cluster of the sub-block corresponding to the legal receiver R j ; Q j,i is the set of active sub-carrier indices of the jth cluster of this sub-block, which is determined in step S104.
[0171] Taking the sub-block as a unit, the active sub-carriers of the first 3 clusters are dedicated to carrying link security information, and the channel gains of all the active sub-carriers of the remaining clusters are sorted from high to low, and the first N c active sub-carriers with the highest gains are used to modulate the constellation symbol vector in step S103 This process is equivalent to interleaving. Here, in order to distinguish different sub-blocks, the above constellation symbol vector is denoted as and there is The remaining The active subcarriers can be modulated with noise according to actual needs; or pseudo-constellation symbols can be modulated. These symbols do not carry any information and can confuse illegal receivers, making it impossible for them to determine which are normal message data symbols and which are pseudo-data symbols.
[0172] Take the modulated noise vector as an example. The Gaussian white noise vector modulated in the remaining active subcarriers of each subblock is denoted as Its unilateral power spectrum density is N0, and the one-dimensional probability density function is shown in Equation (20). After the noise vector is modulated, from the perspective of the time domain, the normal message data symbols are mixed with white noise and even submerged in white noise. It will be difficult for attackers to identify and intercept the time synchronization messages processed in this way.
[0173]
[0174] Where μ n is the mean, usually μ n =0;σ n 2 is the variance, when the mean μ n When it is 0, the average power of the noise is equal to the variance σ n 2 .
[0175] The frequency domain vector generated by the above algorithm is shown in formula (21).
[0176]
[0177]
[0178] In the formula, It includes the link security information vector, the message data symbol vector, the Gaussian white noise vector and the zero vector (the inactive subcarrier does not modulate the data vector, which is reflected as the zero vector).
[0179] Determine the number of IFFT points N for OFDM modulation IFFT , generating a complete frequency domain vector. In order to be able to use efficient 2-IFFT, N IFFT It must be an integer power of 2. At the same time, considering the suppression of out-of-band scattering,
[0180] N IFFT >N D . Define N IFFT In addition to the above N subcarriers D The subcarriers other than the data subcarriers are virtual subcarriers. The number of virtual subcarriers is N. x =N IFFT -N D, the data carried is zero, and it is distributed on both sides of the data subcarrier. After considering the virtual subcarrier, the complete frequency domain vector As shown in formula (22).
[0181]
[0182] The frequency domain vector Perform serial-to-parallel conversion, then perform IFFT transformation and parallel-to-serial conversion to obtain N IFFT Time domain vector of a point
[0183] For time domain vector Insert N cp The cyclic prefix of the point is obtained OFDM =(N OFDM +N IFFT +N cp ) point OFDM-IM modulation vector N cp The value of can be set according to the total frequency domain channel matrix (taking into account the actual physical channel and each channel simulation system).
[0184] OFDM-IM signal Through each main channel W R Sent to each legal receiving end R i (1≤i≤η), and during the transmission process, it will go through several levels of channel simulation systems on each sub-link according to the pre-designed system.
[0185] The main channel W R The output vector is recorded as In the time attack scenario, It may also be attacked by the attacker E k (The number of attackers is unknown, k may be equal to 1 or greater than 1) intercept, tamper and forward, the transmission channel it passes through is the wired channel The channel output vector on the attacker side is recorded as The Gaussian white noise vector in the [ ] reduces the probability of the time synchronization message being identified and intercepted by the attacker to a certain extent. Even if the signal is successfully intercepted and forwarded, under the security mechanism designed by this algorithm, the forwarding will most likely cause the OFDM-IM signal transmission to be terminated, and the illegal signal cannot reach the legitimate receiving end, or the time difference between the OFDM-IM signal and the dedicated link communication frame reaching the next level channel simulation system exceeds the limit, thereby introducing additional frequency selective fading at the sub-link switching device; or in the absence of a dedicated link communication frame, it passes through each channel simulation system and switching device, and is terminated by the switching device and cannot reach the legitimate receiving end. For the legitimate receiving end R i , the illegal wiring channel output vector is recorded as
[0186]
[0187] Receiving end R i After performing CP removal, serial-to-parallel conversion, and FFT transformation on the received signal ( or ), perform IM demodulation on sub-block i, and then determine the analog system of each sub-link channel through which the signal has passed according to the IM data. According to the transfer function of the analog system of each sub-link channel through which the signal has passed, calculate the total frequency-domain channel matrix H of the channel analog system of this sub-block Ri , as shown in Equation (18).
[0188] If the received signal is a normal signal During the signal transmission process, each channel analog system and switching device have equalized the frequency-selective fading introduced by the actual physical channel and the channel analog system. Therefore, the receiving end R i After the FFT transformation, IM demodulation can be directly performed by detecting the energy of the subcarrier signal to obtain the correct frequency-domain channel matrix H Ri . Then, according to H Ri Calculate the active subcarrier channel gain (as shown in Equation (19)). After sorting the gains, the correct positions and orders of the message data symbols can be obtained (deinterleaving).
[0189] If the received signal is an illegal signal According to the security mechanism designed by the present invention There must be one or several clusters with frequency-selective fading, and the frequency-selective fading will cause the receiving end R i to make misjudgments during IM demodulation, resulting in incorrect IM data. The incorrect IM data will indicate the incorrect channel analog system number, thus causing R i to be unable to obtain the correct frequency-domain channel matrix H Ri , and thus unable to perform correct deinterleaving.
[0190] After deinterleaving, perform parallel-to-serial conversion, message data symbol extraction, and constellation demodulation on the frequency-domain vector of this sub-block to obtain the corresponding Polar codeword sequence or
[0191] When the legitimate receiving end R i After receiving the OFDM-IM signal modulated by the sending end through Polar coding, the target channel analog system, and OFDM-IM modulation, it is necessary to perform demodulation and decoding on this signal to obtain the data of the time synchronization message. It should be noted that the process of the receiving end processing the received OFDM-IM signal of the sending end is the reverse process of the sending end generating this OFDM-IM signal.
[0192] Specifically, the legitimate receiver R i employs an SC decoder to decode the received vector ( or ). Based on the polarization characteristics of the Polar code and the performance difference between the artificially constructed legitimate main channel and the illegal wiretapping channel, after decoding, the secret information bits have a low bit error rate; if the data packet is maliciously forwarded by an attacker (corresponding to the codeword sequence ), then the message forwarding indication vector will have a high bit error rate. Therefore, an appropriate bit error rate threshold can be set according to the quality of the actual legitimate main channel, and the bit error rate of the message forwarding indication vector is detected packet by packet. When the bit error rate of the indication vector is greater than or equal to the threshold, it is considered that the data packet is forwarded by an attacker, and the data packet is discarded; otherwise, it is considered that the data packet has not been attacked by forwarding, and the data packet is accepted, as shown in Equation (23).
[0193]
[0194] In the formula, u d refers to the message forwarding indication vector; u di refers to the i-th bit of the message forwarding indication vector, and is its estimated value; refers to the number of bits with bit errors in the message forwarding indication vector; num(u d ) refers to the total number of bits of the message forwarding indication vector; E is the set bit error rate threshold.
[0195] The above security policy, by introducing Polar coding, OFDM-IM modulation, a sub-link channel simulation system, and message data symbol interleaving based on the transfer function of the channel simulation system, makes the quality of the polarized bit channels corresponding to the legitimate main channel (binary symmetric capacity or Bhattacharyya parameter) basically unaffected, while a considerable part of the originally higher-quality bit channels corresponding to the illegal wiretapping channel will deteriorate into lower-quality bit channels, thus greatly improving the security rate, solving the limitations in terms of the channel quality difference between the legitimate main channel and the illegal wiretapping channel, and expanding the application scope of this method to any channel scenario.
[0196] It should be noted that in the embodiment of the present invention, based on Polar encoding and decoding, at the sending end and the legitimate receiver R iOFDM-IM modulation and demodulation are introduced separately, and a channel simulation system chain, a safety net consisting of dedicated links, and a security working mechanism are deployed on the legitimate main channel link. If the transmitted OFDM-IM signal is intercepted and forwarded by an attacker and cannot pass through the subsequent sub-link channel simulation system chain, the equalization function on the switching device side will not match the transfer function of the channel simulation system that the signal actually passes through. This will introduce additional frequency selective fading in the corresponding cluster, causing errors in IM demodulation and deinterleaving at the receiving end. The constellation demodulation bit error rate is greatly increased, which is equivalent to reducing the signal-to-noise ratio of each physical channel application in a pure Polar coding system. As a result, the channel quality of a considerable number of polarization bit channels with good channel quality will be degraded, improving the system security ratio.
[0197] In this embodiment of the present invention, polar coding is channel-dependent. After OFDM-IM modulation and demodulation, the polar codeword is equivalent to traversing a binary input and binary output physical channel, which can be modeled as a BSC channel. Its transition probability is determined by the bit error rate of constellation demodulation. This bit error rate can be determined in advance through experiments, and polar codes can be constructed based on this bit error rate.
[0198] When the physical channel environment is harsh and the channel state response changes rapidly over time, to ensure the transmission quality of time-synchronized data messages, pilots can be inserted at specific locations in the OFDM-IM sub-block (the pilot pattern is pre-agreed upon). OFDM-IM modulation of the message data symbols continues as described above. Each channel simulation system and switching equipment uses the pilots to perform channel estimation, interpolation, and physical channel equalization, mitigating any increase in the demodulation bit error rate of the time-synchronized message data symbols caused by physical channel distortion. Each channel simulation system does not act on the pilot symbols, ensuring that they reflect the actual physical channel conditions.
[0199] The embodiment of the present invention provides a network time synchronization message transmission method for any channel, which can effectively suppress message delay attacks and timestamp tampering attacks; it is oriented to unicast and broadcast transmission modes; it can effectively suppress single or multiple attackers, external and internal attackers in the network, and ensure the security of time message transmission from the physical layer; Polar encoding and decoding, OFDM-IM modulation and demodulation, channel simulation system and switching equipment signal processing, and dedicated link working mechanism all have low complexity and small processing delay, and the physical layer of the switching equipment directly controls routing, avoiding the storage of routing tables and upper-layer table lookups, with little impact on time synchronization accuracy; it is not dependent on system time synchronization and is compatible with current NTP and PTP security mechanisms. At the same time, it breaks through the working scenario limitations of the "network time synchronization message security transmission method", that is, it can work in wired and wireless network environments, and does not require the difference in channel quality between legitimate main channels and illegal access channels.
[0200] Correspondingly, an embodiment of the present invention further provides a schematic diagram of a network time synchronization message transmission device applied to any channel environment of a sending end, see Figure 9 , the apparatus may include:
[0201] A classification unit 901 is configured to classify data bits of a time synchronization message to be transmitted to obtain public information bits and secret information bits;
[0202] A Polar encoding unit 902 is configured to perform Polar encoding on the data bits of the time synchronization message based on the public information bits and the secret information bits to obtain a first encoding sequence;
[0203] a constellation modulation unit 903, configured to perform constellation modulation on the first coding sequence to obtain a symbol vector;
[0204] A first determining unit 904 is configured to divide all data subcarriers within the transmission bandwidth into a plurality of subblocks according to the number of legal receiving terminals, divide each subblock into a plurality of clusters, perform IM modulation on each cluster, and determine an active subcarrier index for each cluster;
[0205] A second determining unit 905 is configured to interleave the symbol vector based on a total frequency domain channel matrix characteristic of a preset channel simulation system, and determine an active subcarrier index carrying the symbol vector;
[0206] An OFDM modulation unit 906 is configured to modulate the interleaved symbol vector onto active subcarriers selected by each subblock to complete OFDM-IM modulation and obtain an OFDM-IM signal;
[0207] The signal sending unit 907 is configured to send the OFDM-IM signal to each of the legal receiving ends.
[0208] Optionally, the device further comprises:
[0209] a third determining unit, configured to determine an information bit channel, wherein the information bit channel includes a secret bit channel and a public bit channel, wherein the secret bit channel is used to transmit the secret information bits, the public bit channel is used to transmit the public information bits, and the sum of the information bit channel and the frozen bit channel is a total bit channel;
[0210] The fourth determining unit is configured to determine an information bit channel index set, a public bit channel index set, a secret bit channel index set, and a frozen bit channel index set based on the Bhattacharya parameter of each bit channel in the total bit channels.
[0211] Optionally, the Polar encoding unit includes:
[0212] A first generating subunit, configured to generate a Polar code generating matrix;
[0213] an extraction subunit, configured to extract corresponding rows of the generator matrix according to respective index sets to obtain respective submatrices, wherein the respective index sets include an information bit channel index set, a public bit channel index set, a secret bit channel index set, and a frozen bit channel index set;
[0214] The encoding subunit is configured to perform Polar encoding on the data bits of the time synchronization message based on the secret information bit and the secret information bit vector corresponding to the message forwarding indication vector, the public information bit vector corresponding to the public information bit, the frozen vector, and the sub-matrices to obtain a first encoding sequence.
[0215] Optionally, the first determining unit includes a sub-block division sub-unit, configured to divide each sub-block into a plurality of clusters, wherein the sub-block division sub-unit is specifically configured to:
[0216] Obtain the number of sub-links contained in the actual transmission link from the sender to the legal receiver in the network;
[0217] determining the number of clusters based on the number of sub-links;
[0218] Each sub-block is divided according to the number of clusters to obtain a number of clusters, wherein a specific number of clusters are reserved for link security information transmission, and the remaining clusters are used to transmit time synchronization message data.
[0219] Correspondingly, the first determination unit further includes an IM modulation subunit, configured to perform IM modulation on each cluster to determine an active subcarrier index of each cluster, wherein the IM modulation subunit is specifically configured to:
[0220] The clusters of each sub-block are numbered so that the IM data of each numbered cluster carries different information. The IM data of the first three clusters respectively carries the sender identification code, the receiver identification code, and the numbers of all sub-links included in the predetermined route. The IM data of the remaining clusters respectively carries the channel simulation system indication data of each sub-link. The channel simulation system indication data of each sub-link is used to indicate the number and order of the channel simulation systems that the time synchronization message needs to traverse on the sub-link.
[0221] IM modulation is performed on each cluster according to the information that each cluster needs to carry, and the active subcarrier index of each cluster is determined.
[0222] Optionally, the second determining subunit is specifically configured to:
[0223] Determining a total frequency domain channel matrix of the channel simulation system based on a preset transfer function of each channel simulation system;
[0224] Based on the total frequency domain channel matrix of the channel simulation system, calculating the channel gain added by the channel simulation system to each active subcarrier in each subblock;
[0225] The symbol vector is interleaved based on the channel gain, and an active subcarrier index carrying the symbol vector is determined.
[0226] Optionally, the OFDM modulation unit is specifically configured to:
[0227] Determine the length of the noise vector for each subblock based on the length of the symbol vector and the number of active subcarriers in each subblock, and generate a noise vector;
[0228] Generate a frequency domain vector based on the link security information vector, the message data symbol vector and the noise vector;
[0229] Based on the frequency domain vector, generate a time domain vector;
[0230] OFDM-IM modulation is performed based on the frequency domain vector and the time domain vector to obtain an OFDM-IM signal.
[0231] Optionally, the device further comprises:
[0232] The first processing unit is configured to process the OFDM-IM signal based on a dedicated link working mechanism during signal transmission by each of the channel simulation systems and each switching device during transmission.
[0233] Optionally, the device further comprises:
[0234] The second processing unit is used to process the OFDM-IM signal in response to the legitimate receiving end receiving the OFDM-IM signal based on a reverse processing mode that matches the generation and processing mode of the OFDM-IM signal to obtain the time synchronization message, wherein the reverse processing mode at least includes OFDM demodulation, IM demodulation, generation of the total frequency domain channel matrix of the channel simulation system, deinterleaving, constellation demodulation, Ploar decoding, and message transmission security determination based on the bit error rate of the message forwarding indication vector.
[0235] Based on the above embodiments, an embodiment of the present invention further provides a storage medium storing executable instructions, which, when executed by a processor, implements the network time synchronization message transmission method applied to any channel environment as described in any one of the above.
[0236] An embodiment of the present invention further provides an electronic device, including:
[0237] A memory for storing programs;
[0238] A processor for executing the program, where the program is specifically used to implement the network time synchronization message transmission method applied to any channel environment as described in any one of the above.
[0239] The various embodiments in this specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same or similar parts among the various embodiments, reference can be made to each other. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple. For the relevant parts, reference can be made to the description in the method part.
[0240] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present invention. Various modifications to these embodiments will be obvious to those skilled in the art. The general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but will be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A method for transmitting network time synchronization messages applicable to any channel environment, characterized in that, The method includes: Classifying the data bits of the time synchronization message to be transmitted to obtain public information bits and secret information bits; Based on the public information bits and the secret information bits, performing Polar coding on the data bits of the time synchronization message to obtain a first coding sequence; Performing constellation modulation on the first coding sequence to obtain a symbol vector; Dividing all data subcarriers within the transmission bandwidth into several sub-blocks according to the number of legitimate receivers, and dividing each sub-block to obtain several clusters, and performing IM modulation on each cluster to determine the active subcarrier indices of each cluster; Based on the total frequency-domain channel matrix characteristics of the preset channel simulation system, interleaving the symbol vector and determining the active subcarrier indices carrying the symbol vector; Modulating the interleaved symbol vector onto the active subcarriers selected for each sub-block to complete OFDM-IM modulation and obtain an OFDM-IM signal; Sending the OFDM-IM signal to each of the legitimate receivers.
2. The method according to claim 1, characterized in that, The method further includes: Determining information bit channels, where the information bit channels include a secret bit channel and a public bit channel. Among them, the secret bit channel is used to transmit the secret information bits, the public bit channel is used to transmit the public information bits, and the sum of the information bit channels and the frozen bit channels is the total bit channel; Based on the Bhattacharyya parameters of each bit channel in the total bit channel, determining an information bit channel index set, a public bit channel index set, a secret bit channel index set, and a frozen bit channel index set.
3. The method according to claim 2, wherein The performing Polar coding on the data bits of the time synchronization message based on the public information bits and the secret information bits to obtain a first coding sequence includes: Generating a Polar code generation matrix; According to each index set, extracting the corresponding rows of the generation matrix to obtain each sub-matrix, and each index set includes an information bit channel index set, a public bit channel index set, a secret bit channel index set, and a frozen bit channel index set; Performing Polar coding on the data bits of the time synchronization message based on the secret information bits and the secret information bit vector corresponding to the message forwarding indication vector, the public information bit vector corresponding to the public information bits, the frozen vector, and each sub-matrix to obtain a first coding sequence.
4. The method according to claim 1, wherein The dividing each sub-block to obtain several clusters includes: Obtaining the number of sub-links included in the actual transmission link from the sender to the legitimate receiver in the network; Determining the number of clusters based on the number of sub-links; Dividing each sub-block according to the number of clusters to obtain several clusters, where a specific number of clusters are reserved for link security information transmission, and the remaining clusters are used to transmit time synchronization message data.
5. The method according to claim 4, wherein The performing IM modulation on each cluster to determine the active subcarrier indices of each cluster includes: Numbers are respectively assigned to several clusters of each sub-block, such that the IM data of each numbered cluster carries different information. Among them, the IM data of the first three clusters respectively carry the sending end identification code, the receiving end identification code, and the numbers of all sub-links included in the predetermined route. The IM data of the remaining clusters respectively carry the channel simulation system indication data of each sub-link, and the channel simulation system indication data of the sub-link is used to indicate the numbers and passing orders of the channel simulation systems that the time synchronization message needs to pass through on this sub-link; Perform IM modulation on each cluster according to the information to be carried by each cluster, and determine the active subcarrier indices of each cluster.
6. The method according to claim 5, characterized in that, The interleaving of the symbol vector based on the total frequency domain channel matrix characteristics of the preset channel simulation system and the determination of the active subcarrier indices carrying the symbol vector include: Determine the total frequency domain channel matrix of the channel simulation system based on the transfer functions of the preset channel simulation systems; Calculate the channel gains added by the channel simulation system for each active subcarrier within each sub-block based on the total frequency domain channel matrix of the channel simulation system; Interleave the symbol vector based on the channel gains, and determine the active subcarrier indices carrying the symbol vector.
7. The method according to claim 6, wherein The modulation of the interleaved symbol vector onto the selected active subcarriers of each sub-block to complete OFDM-IM modulation and obtain an OFDM-IM signal includes: Determine the noise vector lengths of each sub-block based on the symbol vector length and the number of active subcarriers of each sub-block, and generate noise vectors; Generate a frequency domain vector based on the link security information vector, the message data symbol vector, and the noise vectors; Generate a time domain vector based on the frequency domain vector; Perform OFDM-IM modulation based on the frequency domain vector and the time domain vector to obtain an OFDM-IM signal.
8. The method according to claim 1, characterized in that, The method further includes: During the signal transmission process, each of the channel simulation systems and each switching device during the transmission process processes the OFDM-IM signal based on the dedicated link working mechanism.
9. The method according to claim 1, wherein The method further includes: In response to the legal receiving end receiving the OFDM-IM signal, process the OFDM-IM signal based on a reverse processing mode matching the generation processing mode of the OFDM-IM signal to obtain the time synchronization message, where the reverse processing mode at least includes OFDM demodulation, IM demodulation, generation of the total frequency domain channel matrix of the channel simulation system, deinterleaving, constellation demodulation, Polar decoding, and determination of the message transmission security based on the bit error rate of the message forwarding indication vector.
10. A network time synchronization message transmission device applicable to any channel environment, characterized in that The device includes: A classification unit, configured to classify the data bits of the time synchronization message to be transmitted to obtain public information bits and secret information bits; A Polar coding unit, configured to perform Polar coding on the data bits of the time synchronization message based on the public information bits and the secret information bits to obtain a first coding sequence; A constellation modulation unit, configured to perform constellation modulation on the first coding sequence to obtain a symbol vector; The first determination unit is configured to divide all data subcarriers within the transmission bandwidth into several sub-blocks according to the number of legitimate receivers, and divide each sub-block to obtain several clusters, perform IM modulation on each cluster, and determine the active subcarrier indices of each cluster; The second determination unit is configured to interleave the symbol vector based on the total frequency-domain channel matrix characteristics of the preset channel simulation system, and determine the active subcarrier indices carrying the symbol vector; The OFDM modulation unit is configured to modulate the interleaved symbol vector onto the active subcarriers selected for each sub-block to complete OFDM-IM modulation and obtain an OFDM-IM signal; The signal transmission unit is configured to transmit the OFDM-IM signal to each of the legitimate receivers.
Citation Information
Patent Citations
Network time synchronization message security transmission method and device
CN108964910A
Method and apparatus for clock source management
WO2021238377A1
Cited By
Physical layer identity authentication method and device of network time synchronization system
CN118041593A
A physical layer identity authentication method and device of a network time synchronization system
CN118041593B
Network time synchronization system and method
CN118041594A
A network time synchronization system and method
CN118041594B