A machine learning-based OFDM-PON physical layer authentication method
By using neural network and principal component analysis algorithm in the OFDM-PON system, the hardware fingerprint features of the OFDM transmitter are extracted from the OFDM spectrum, which solves the problem of illegal user detection difficulties caused by incomplete extraction of hardware fingerprint features and small differences, and achieves more efficient illegal user detection capabilities.
Patent Information
- Application Number
- CN202211455446.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-21
- Publication Date
- 2025-05-02
- Estimated Expiration
- 2042-11-21
AI Technical Summary
In the current OFDM-PON physical layer authentication, the hardware fingerprint feature extraction is incomplete and the difference in the hardware fingerprint feature of the OFDM transmitter is too small, which makes it difficult to detect illegal users.
Using a machine learning-based method, the neural network is used to directly learn the hardware features of the OFDM transmitter from the OFDM spectrum, and the neural network's ability to detect illegal users is enhanced through a combination of principal component analysis algorithms and one-dimensional convolutional neural networks.
It realizes the extraction of complete hardware fingerprint features from the OFDM spectrum, and improves the detection ability of illegal users, especially when the hardware fingerprint differences are small.
Smart Images

Figure CN116208337B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of optical fiber communication security and relates to an OFDM-PON physical layer authentication method based on machine learning. Background Art
[0002] In order to meet the development of various high-bandwidth services such as 5G communication, Internet of Everything, and cloud services, PON technology has become one of the most widely used optical access network solutions with its advantages of high bandwidth, large capacity, and low cost. Passive optical network technology based on orthogonal frequency division multiplexing has the advantages of high spectrum resource utilization, strong anti-dispersion ability, easy digital signal processing, and flexible adjustment of the number of subcarriers, which better meets people's needs for high speed, low cost, and dynamic bandwidth allocation of PON technology. However, since the downlink of OFDM-PON adopts a point-to-multipoint topology and broadcast communication, there are many security risks, such as eavesdropping, interference attacks, camouflage attacks, and interception attacks. Among them, camouflage attacks refer to attacks on the physical layer of the OFDM-PON system. Specifically, illegal users reprogram some reconfigurable optical network unit devices (ONUs), and then disguise themselves as legitimate ONUs and join the optical network. This type of illegal ONU can continuously transmit signals to the uplink to interfere with the normal communication of legitimate ONUs. Even, they can directly replace the legitimate ONU identity and then communicate with the optical line terminal (OLT), thus threatening the security of the optical network. Therefore, it is particularly necessary to study an identity authentication scheme suitable for OFDM-PON.
[0003] There are three main authentication methods for traditional PON authentication technology, namely, authentication based on registration value (Registration_ID), authentication based on ONU management and control interface (OMCI) message exchange, and authentication based on IEEE 802.1X message exchange. In general, the security of traditional PON authentication technology is mainly guaranteed by the complexity of the encryption algorithm. However, the development of quantum computers makes it possible to crack complex encryption algorithms, thus threatening the security of traditional PON authentication technology. In addition, complex encryption algorithms will add additional overhead to the underlying communication of OFDM-PON, which is not conducive to the efficient transmission characteristics of the underlying OFDM-PON.
[0004] Hardware fingerprint technology is a physical layer authentication technology. Compared with traditional PON authentication technology, it has the advantages of being lightweight and non-clonable. In the production process of equipment, there are often various subtle differences in the same batch of equipment due to factors such as technical processes, raw materials, production environment, and operating environment. Like human fingerprints, these differences have non-clonable and unique physical layer characteristics, which meet the conditions required for identity authentication. The existing physical layer authentication method of OFDM-PON shows that the hardware fingerprint characteristics of the transmitting device are extracted from the OFDM pilot signal by using a photodetector and a digital sampling oscilloscope at the receiving end, and then the legal ONU identity and illegal ONU detection can be identified by combining a two-dimensional convolutional neural network and a wavelet transform algorithm. However, the OFDM pilot signal has a very short duration, so the hardware fingerprint characteristics it carries are limited, and it may not even contain the hardware fingerprint characteristics of the transmitter. In order to solve this problem, a spectral feature analysis method is proposed to identify authorized and unauthorized signals, and the complete hardware fingerprint characteristics are obtained through machine learning. When using this method to detect unauthorized signals, the loss value of the neural network is used as the threshold for judging authorized and unauthorized signals. However, this method of detecting unauthorized ONUs is no longer applicable when the hardware fingerprints are slightly different, such as the same batch of OFDM transmitters. In addition to extracting hardware fingerprints through the spectrum, the hardware fingerprint of the transmitter can also be extracted from the eye diagram of the signal. However, in order to obtain the eye diagram, the collected signal needs to be processed by a series of DSP algorithms, which is a cumbersome and complicated process.
[0005] Therefore, a new method is urgently needed to solve the current problems of incomplete hardware fingerprint features extracted by OFDM-PON physical layer authentication and the difficulty in detecting illegal users due to the small differences in OFDM transmitter hardware fingerprint features. Summary of the invention
[0006] In view of this, the purpose of the present invention is to provide an OFDM-PON physical layer authentication method based on machine learning, which is used to solve and improve the current problems of incomplete hardware fingerprint features extracted by OFDM-PON physical layer authentication and difficulty in detecting illegal users due to small differences in OFDM transmitter hardware fingerprint features.
[0007] In order to achieve the above object, the present invention provides the following technical solutions:
[0008] A machine learning-based OFDM-PON physical layer authentication method uses a neural network to learn the OFDM transmitter hardware characteristics directly from the OFDM spectrum, and then adds negative samples in the process of training the neural network to enhance the ability of the neural network to detect illegal users; and proposes an OFDM-PON physical layer authentication method that combines a principal component analysis algorithm with a one-dimensional convolutional neural network.
[0009] The method specifically comprises the following steps:
[0010] S1: Authentication negotiation: The optical line terminal (OLT) notifies each legitimate optical network unit (ONU) of the authentication data that needs to be sent during the next round of authentication;
[0011] S2: Data collection: The receiving end of the OLT uses an optical spectrum analyzer (OSA) and an optical amplifier (AMP) to collect OFDM spectrum samples of the authentication data and create training sets, validation sets, and test sets;
[0012] S3: Data dimensionality reduction: The spectral sample data is preprocessed using the principal component analysis (PCA) algorithm to reduce the redundancy of the data;
[0013] S4: Establish and train a one-dimensional convolutional neural network (1D-CNN), and input the dataset after dimension reduction preprocessing into the neural network for training and testing;
[0014] S5: Identity authentication. The OLT randomly initiates authentication to the downstream connected ONU, and then the ONU immediately sends authentication data to respond to the authentication.
[0015] Further, step S1 specifically includes the following steps:
[0016] S11: At regular intervals, the OFDM-PON communication system updates the authentication data required for the next round of authentication, including:
[0017] The OLT encrypts the authentication data required during the authentication period through the encryption algorithm in the PON standard protocol, and then transmits it to each legitimate user;
[0018] For legitimate ONU devices newly added to the OFDM-PON network, their authentication information can be directly input into the ONU on-site by the operator's staff;
[0019] S12: When the ONU receives the authentication data about the next round of authentication from the OLT, it immediately replaces the authentication data in the memory, and then sends the new authentication data to the OLT for training and authentication.
[0020] Further, step S2 specifically includes the following steps:
[0021] S21: The receiving module of OLT consists of AMP and OSA, which is used to receive and collect the spectrum data of OFDM transmitter;
[0022] S22: According to the uploaded time slot interval, the OFDM spectrum data is labeled with a label corresponding to a legitimate user; for example, ONU1 is labeled 0, ONU2 is labeled 1, and so on.
[0023] In an actual communication environment, we have little chance to collect OFDM spectrum data of illegal users. If the data set of illegal users is not added in the training phase, the neural network will only learn the hardware fingerprints of legitimate users, which will make it difficult for the neural network to distinguish the OFDM transmitters of illegal users with very small differences in hardware fingerprints based on the loss threshold. For samples that are more difficult to classify, machine learning methods usually add some negative samples in the training phase to enhance the classification ability of the neural network. Therefore, the present invention selects several virtual illegal ONU users from the same batch of generated OFDM transmitters, transmits them over the same long transmission distance, and then uses the same receiving module to collect this part of the data; this part of the data will be labeled as an illegal user, and allowed to participate in the training process of the one-dimensional neural network, but not in the testing process;
[0024] S23: Divide the labeled data set in step S22 into a training set and a test set in a ratio of 8:2; in order to observe whether overfitting occurs during the training process, 10% of the samples in the training set are divided as a validation set.
[0025] Further, step S3 specifically includes the following steps:
[0026] S31: The data set collected in step S2 is recorded as X = {x1, x2, ..., x m}, represents m OFDM spectrum data, and the number of sampling points of each sample is n;
[0027] S32: Perform standardization processing on the spectral data set of step S31 to obtain a standardized data set X'={x'1, x'2, x'3, ..., x' m}, and the expression for each sample in the standardized data set is:
[0028]
[0029] Among them, {u j ,j=1,2...,n} and {δ j ,j=1,2,...,n} respectively represent the mean and variance of the j-th dimension data, as shown below:
[0030]
[0031]
[0032] S33: Multiply the standardized data set with its transposed matrix to obtain the covariance matrix C, which is expressed as:
[0033] C=X'X' T
[0034] S34: Calculate the eigenvalue λ and eigenvector a of the covariance matrix C. The calculation formula is as follows:
[0035] Ca=λa
[0036] S35: Sort the eigenvalues in descending order to obtain λ={λ1,λ2,λ3,...,λ n}. Similarly, the eigenvectors are adjusted in the order of the eigenvalues to obtain a={a1,a2,a3,...,a n}. Calculate the cumulative contribution τ of the principal component as shown below:
[0037]
[0038] The numerator of this formula represents the eigenvalues λ={λ1,λ2,λ3,...,λ n}, select the first r eigenvalues and add them. The denominator represents the sum of all eigenvalues. The cumulative contribution indicates how much information of the original data can be contained in the number of principal components selected.
[0039] S36: Select the eigenvectors whose cumulative contribution τ is close to 95% to form the matrix P = {a1, a2, ..., a r}; after transposing it and multiplying it with the original standardized data set, we can get the data set Y={y1,y2,...,y m}, expression we: Y = P T ×X'.
[0040] Further, step S4 specifically includes the following steps:
[0041] S41: Use Tensorflow2.0 framework to build a one-dimensional convolutional neural network (1D-CNN), including an input layer, two convolutional layers, two Relu function activation layers, two maximum pooling layers, a global average pooling layer, a Softmax function activation layer and an output layer;
[0042] S42: Input the training set and validation set preprocessed by the PCA algorithm into 1D-CNN to obtain the prediction results; calculate the value of the cross entropy loss function based on the prediction results and the actual target results, and feed it back to 1D-CNN to adjust the parameters of the neural network; then repeat the above process until the training accuracy curve stabilizes.
[0043] Further, step S5 specifically includes the following steps:
[0044] S51: After the OLT initiates authentication to the ONU, the ONU sends the previously negotiated authentication data to the OLT;
[0045] S52: The OLT first uses an AMP to amplify the received OFDM optical signal, and then uses an OSA to collect OFDM spectrum data and convert it into a sequence form;
[0046] S53: The sequence data is then subjected to the PCA algorithm to reduce the dimension of the data and extract the main features;
[0047] S54: Input the reduced-dimensional data into the pre-trained 1D-CNN. Since different OFDM transmitters have different hardware fingerprints, the 1D-CNN network will automatically identify the user's identity. If the authentication result is a legitimate user, the user will be provided with the corresponding service; on the contrary, if the authentication result is an illegal user, the service will be refused.
[0048] The beneficial effects of the present invention are:
[0049] 1) The receiving end of the present invention uses OSA to collect the transmission signal of the OFDM transmitter, thereby avoiding the problem that the complete OFDM transmitter hardware fingerprint information cannot be collected due to the short duration of the OFDM pilot signal;
[0050] 2) In order to solve the problem that the hardware fingerprint features of the same batch of OFDM transmitters are too different, making it difficult to detect illegal users, the present invention proposes to add virtual illegal OFDM transmitter samples during the training of the 1D-CNN neural network to enhance the ability of the neural network to detect illegal users.
[0051] 3) The principal component analysis method used in the present invention can reduce data redundancy.
[0052] Other advantages, objectives and features of the present invention will be described in the following description to some extent, and to some extent, will be obvious to those skilled in the art based on the following examination and study, or can be taught from the practice of the present invention. The objectives and other advantages of the present invention can be realized and obtained through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0053] In order to make the purpose, technical solutions and advantages of the present invention more clear, the present invention will be described in detail below in conjunction with the accompanying drawings, wherein:
[0054] Figure 1 It is an OFDM simulation system;
[0055] Figure 2 Certify the system model for OFDM-PON physical layer;
[0056] Figure 3 It is a one-dimensional convolutional neural network model structure;
[0057] Figure 4 The following is a comparison chart of 16 groups of OFDM transmitter spectra collected at the receiving end;
[0058] Figure 5 It is the cumulative contribution curve after dimension reduction processing of the data set of 16 groups of OFDM transmitters;
[0059] Figure 6 The training accuracy curve (a) and loss function curve (b) of the one-dimensional convolutional neural network;
[0060] Figure 7 Results of one-dimensional convolutional neural network for identifying legitimate users. DETAILED DESCRIPTION
[0061] The following describes the embodiments of the present invention by specific examples, and those skilled in the art can easily understand other advantages and effects of the present invention from the contents disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments, and the details in this specification can also be modified or changed in various ways based on different viewpoints and applications without departing from the spirit of the present invention. It should be noted that the illustrations provided in the following embodiments only illustrate the basic concept of the present invention in a schematic manner, and the following embodiments and features in the embodiments can be combined with each other without conflict.
[0062] See also Figure 1 to Figure 7 The present invention provides an OFDM-PON physical layer authentication method based on machine learning. First, the mathematical professional software matlab2019a and the commercial optical simulation software VPI TransmissionMaker V.9.5 are used to jointly build an OFDM system based on intensity modulation, such as Figure 1 shown.
[0063] At the transmitter, the input bit data stream is first converted from serial to parallel (S / P) to generate multiple parallel data. Then, each data channel is modulated with hexadecimal quadrature amplitude modulation (16 Multiple Quadrature Amplitude Modulation, 16QAM) and pilot data is inserted. Then, the data with the pilot inserted is transformed by inverse fast Fourier transform (IFFT) to obtain OFDM symbols. The length of the IFFT transform is the same as the number of subcarriers, which is set to 512 here. Then, a cyclic prefix is inserted before each OFDM symbol, where the length of the cyclic prefix is 1 / 8 of the number of IFFT points. Finally, the data with the cyclic prefix is converted from parallel to serial (P / S) and digital to analog (DAC) in turn to generate a baseband OFDM signal. For the VPI TransmissionMaker V.9.5 optical simulation platform, the laser drive power module can generate the corresponding RF bias voltage according to the input baseband OFDM signal to drive the differential Mach-Zehnder modulator (DMZM) to operate. The DC power module generates a DC bias voltage to control the working state of the DMZM. Here, the DC voltage difference between the upper and lower channels of the DC power module is set to half of the DMZM half-wave voltage, so that the DMZM works in intensity modulation mode. The DMZM working in intensity modulation mode will modulate the intensity of the laser emitted by the continuous laser source according to the input baseband OFDM signal. At the receiving end, the received OFDM optical signal is first amplified by an optical amplifier (AMP), and then the OFDM spectrum data is collected by OSA. Table 1 gives some parameter setting information of the VPI device:
[0064] Table 1 Device parameter information
[0065]
[0066] according to Figure 1 The OFDM simulation system built can derive the optical field E of the output signal of DMZM out for:
[0067]
[0068] Among them, E in Represents the light field of the output signal of the continuous laser source, V RF1 and V RF2 They are the output voltages of laser drive power module 1 and laser drive power module 2, respectively. They are related to the OFDM baseband signal and the DriveAmplitude parameter set by the laser drive power module itself.DC1 and V DC2 This is the Amplitude parameter set for DC power module 1 and DC power module 2, V π is the half-wave voltage of DMZM. Therefore, the power of the OFDM optical signal output by DMZM is:
[0069]
[0070] It can be seen from the above formula that OFDM optical power is greatly affected by the device itself, including continuous laser source, DMZM, laser drive power module, DC power module, etc. Therefore, in order to quickly simulate OFDM transmitters produced in the same batch, the present invention only fine-tunes two parameters of the OFDM system during the simulation process to generate OFDM transmitters with different hardware fingerprints. The first modified parameter is Figure 1 The DriveAmplitude of the laser drive power module 1 is denoted as V_drive, and its value is set in {0.18, 0.19, 0.2, 0.21}; the second parameter is Figure 1 The Amplitude of the DC_Source1 module is denoted as V_dc, and is set to be in the range of {-3.1, -3.05, -3, -2.95}. Finally, a total of 16 groups of OFDM transmitters were produced. In order to more intuitively show the differences in hardware fingerprints of different OFDM transmitters, the OFDM transmitter group with V_drive = 0.2V, V_dc = -3.0V was selected as the reference ONU. Then other groups of OFDM transmitters were compared with it, such as Figure 4 shown.
[0071] Depend on Figure 4 It can be seen that there are indeed differences in the OFDM spectra between the other 15 groups of OFDM transmitters and the reference OFDM transmitter. However, these differences are too small to be classified by the naked human eye. Therefore, the present invention proposes an OFDM-PON physical layer authentication system based on machine learning. The neural network learns the hardware fingerprint features of the OFDM transmitter from the OFDM spectrum data, and then uses it to identify the identity of the legitimate ONU user and detect the illegal ONU user.
[0072] After the OFDM communication system is built, two application scenarios of the present invention are further elaborated below:
[0073] Scenario 1: Identifying legitimate users:
[0074] In this scenario, all 16 OFDM transmitters are marked as legitimate ONUs, in order to verify the ability of this method to identify legitimate users.
[0075] S1: Authentication negotiation: Figure 2 As shown, the OLT notifies each legitimate ONU of the authentication information that needs to be sent during the next round of authentication. The steps include:
[0076] S11: At regular intervals, the OFDM-PON communication system will update the authentication information required for the next round of authentication. Here, the authentication data in the authentication negotiation process is simulated by modifying the random number seed for generating OFDM signals in the Matlab program. Since the 16 groups of ONUs use the same random number seed, the generated OFDM optical signal will only be related to the hardware parameters of the OFDM transmitter itself, which will help the neural network learn the hardware fingerprint of the transmitter.
[0077] S12: After the 16 groups of ONUs receive the authentication data about the next round of authentication from the OLT, they immediately replace the authentication data in the memory, and then send the authentication data to the OLT for training and authentication.
[0078] S2: Data collection: OLT receives and collects OFDM spectrum samples, and creates training sets, validation sets, and test sets. This includes the following steps:
[0079] S21: OLT receiving end Figure 2 The module is composed of an optical amplifier (AMP) and an OSA, which is used to receive and collect the spectrum of the OFDM transmitter;
[0080] S22: according to the uploaded time slot interval, the 16 groups of OFDM spectrum data are marked with corresponding labels (including labels of legal users and illegal users), such as ONU1 is marked with label 0, ONU2 is marked with label 1, and so on;
[0081] S23: The above data set is divided into a training set and a test set in an 8:2 ratio, and in order to observe whether overfitting occurs during the training process, 10% of the samples in the training set are divided as a validation set. Therefore, the final training set size is 4839, the test set size is 537, and the validation set size is 1344.
[0082] S3: Data dimensionality reduction: Use PCA algorithm to preprocess the spectral data to reduce the redundancy of the data. It includes the following steps:
[0083] S31: Call the sklearn library in the general open source machine learning library to implement the PCA algorithm.
[0084] S32: The OFDM spectrum data of the 16 groups of ONUs are reduced in dimension using the PCA algorithm, and the cumulative contribution of the principal component number (r) with different values is counted, such as Figure 5As shown in the figure. As the number of principal components selected increases, that is, the r value increases, the corresponding contribution increases. When 90 principal components are selected, the upward trend of contribution has hardly changed, because the current principal components can already contain 99% of the information of the original data. Figure 5 The intersection of the middle dashed lines is the closest to the contribution of 95%, so this scenario ultimately reduces the original OFDM spectrum data to 25 dimensions.
[0085] S4: Build and train 1D-CNN, and input the previously preprocessed dataset into the neural network for training and testing:
[0086] S41: Built with Tensorflow2.0 framework Figure 3 The one-dimensional convolutional neural network shown in Figure 2 contains an input layer, two convolutional layers, two Relu function activation layers, two maximum pooling layers, a global average pooling layer, a Softmax function activation layer, and an output layer. The parameters of each layer are shown in Table 2 below:
[0087] Table 2 Parameters of one-dimensional convolutional neural network (1D-CNN)
[0088]
[0089]
[0090] S42: Input the training set and the validation set into the 1D-CNN for training the 1D-CNN. Figure 6 (a) and Figure 6 (b) are the training accuracy curve and loss function curve of the 1D-CNN neural network, respectively. Figure 6 It can be seen that the training accuracy and loss value of the 1D-CNN neural network change very quickly at the beginning of training. After 90 iterations, the curves of the two figures gradually stabilize until convergence. In addition, the training accuracy curves and loss function curves of the training set and the validation set gradually fit in the later training process, without overfitting or underfitting, indicating that the neural network has good stability.
[0091] S5: Identity authentication: OLT randomly initiates authentication to the downstream connected ONU, and then the ONU immediately sends authentication data to respond to the authentication. It includes the following steps:
[0092] S51: Input the test set into the well-trained one-dimensional convolutional neural network and observe the output results of the neural network.
[0093] S52: Figure 7As shown, the present invention uses a confusion matrix to represent the recognition result of the one-dimensional convolutional neural network. Each row of the matrix represents the actual category of a certain type of ONU, and each column represents the authentication result of the authentication system. It is worth noting that the number of correctly identified ONUs can be counted by directly observing the values located on the main diagonal of the matrix. After statistics, it can be seen that in the authentication scenario of 16 legitimate users, the accuracy of the one-dimensional convolutional neural network can reach 99.18%.
[0094] Scenario 2: Test the system's ability to resist spoofing attacks:
[0095] In this scenario, the 16 groups of ONUs previously created are set as illegal users. The training phase does not include samples of such illegal users, and only such samples appear in the test set to test the ability of the present invention to resist spoofing attacks. The specific process will be described in detail below:
[0096] The difference between scenario 2 and scenario 1 is only in step S2, that is, the way of making data sets is different. In this scenario, ONU1-8 is set as legal ONU, ONU13-16 is set as illegal ONU, and ONU9-12 is set as irrelevant ONU. 336 samples are collected from ONU1-8 and marked with corresponding labels, and then 84 samples are collected from ONU9-12 and marked with illegal user labels to make training sets.
[0097] In order to test the system's ability to resist spoofing attacks, four test sets are created, as shown in Table 3. Each test set contains data from legitimate ONUs 1 to 8, and data from an illegal ONU is added to each of the four test sets. For example, test set 1 contains data samples from legitimate ONUs 1 to 8 and samples from illegal ONU 13.
[0098] Table 3 Test set
[0099]
[0100] The test results are shown in Table 4. The results of test set 1 show that the method proposed by the present invention has a probability of identifying the identities of legal ONUs 1 to 8 of 99.85% and a probability of detecting illegal ONU 13 of 100%. It can be seen that the method can effectively detect illegal users whose spectral characteristics are very different from those of legal users, and the detection probability is as high as 100%.
[0101] Table 4. Probability of identifying legitimate users and detecting illegal users
[0102]
[0103] Finally, it should be noted that the above embodiments are only used to illustrate the technical solution of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solution of the present invention can be modified or replaced by equivalents without departing from the purpose and scope of the technical solution, which should be included in the scope of the claims of the present invention.
Claims
1. A machine learning-based OFDM-PON physical layer authentication method, characterized in that: The method specifically comprises the following steps: S1: Authentication negotiation: The optical line terminal OLT notifies each legal optical network unit device ONU of the authentication data that needs to be sent during the next round of authentication; S2: Data collection: The receiving end of the OLT collects OFDM spectrum samples of the authentication data and creates training sets, validation sets, and test sets; S3: Data dimensionality reduction: Use principal component analysis algorithm to preprocess the spectral sample data; S4: Establish and train a one-dimensional convolutional neural network, and input the dataset after dimension reduction preprocessing into the neural network for training and testing, which specifically includes the following steps: S41: Build a one-dimensional convolutional neural network, including an input layer, two convolutional layers, two Relu function activation layers, two maximum pooling layers, a global average pooling layer, a Softmax function activation layer and an output layer; S42: Input the training set and the validation set preprocessed by the principal component analysis algorithm into the one-dimensional convolutional neural network to obtain the prediction result; calculate the value of the cross entropy loss function according to the prediction result and the actual target result, and feed it back to the one-dimensional convolutional neural network to adjust the parameters of the neural network; then repeat the above process until the training accuracy curve tends to be stable; S5: Identity authentication: The OLT randomly initiates authentication to the downstream connected ONU, and then the ONU immediately sends authentication data to respond to the authentication.
2. The OFDM-PON physical layer authentication method according to claim 1, characterized in that: Step S1 specifically includes the following steps: S11: At regular intervals, the OFDM-PON communication system updates the authentication data required for the next round of authentication, including: The OLT encrypts the authentication data required during the authentication period through the encryption algorithm in the PON standard protocol, and then transmits it to each legitimate user; For legitimate ONU devices newly added to the OFDM-PON network, their authentication information can be directly input into the ONU on-site by the operator's staff; S12: When the ONU receives the authentication data about the next round of authentication from the OLT, it immediately replaces the authentication data in the memory, and then sends the new authentication data to the OLT for training and authentication.
3. The OFDM-PON physical layer authentication method according to claim 1, characterized in that: Step S2 specifically includes the following steps: S21: The receiving module of OLT consists of an optical amplifier AMP and an optical spectrum analyzer OSA. This module is used to receive and collect the spectrum data of the OFDM transmitter. S22: according to the uploaded time slot interval, the OFDM spectrum data is labeled with the corresponding legal user; and a number of virtual illegal ONU users are selected from the same batch of generated OFDM transmitters, and they are transmitted over the same long distance, and then the same receiving module is used to collect this part of the data; this part of the data will be labeled with the illegal user and allowed to participate in the training process of the one-dimensional neural network, but not in the testing process; S23: Divide the labeled data set in step S22 into a training set and a test set in an 8:2 ratio; and then divide 10% of the samples from the training set as a validation set.
4. The OFDM-PON physical layer authentication method according to claim 1, characterized in that: Step S3 specifically includes the following steps: S31: Record the data set collected in step S2 as ,express m OFDM spectrum data, and the number of sampling points for each sample is n ; S32: Performing standardization processing on the spectral data set of step S31 to obtain a standardized data set , and the expression for each sample in the standardized data set is: in, and Respectively represent j The mean and variance of the dimensional data are as follows: S33: Multiply the standardized data set with its transposed matrix to obtain the covariance matrix C, which is expressed as: S34: Calculate the eigenvalues of the covariance matrix C and the eigenvector , the calculation formula is as follows: S35: Sort the eigenvalues in descending order and get Similarly, the eigenvectors are also adjusted in the order of the eigenvalues to obtain ; Calculate the cumulative contribution of the principal components , as shown below: The numerator of the above formula represents the eigenvalues calculated from Before the selection r The denominator represents the sum of all eigenvalues; the cumulative contribution Indicates how much information about the original data the selected principal components can contain; S36: Select cumulative contribution Close to 95% of the eigenvectors form the matrix ; Transpose it and multiply it with the original standardized data set to get the dimension reduction to r Dimensioned dataset , the expression is: 。 5. The OFDM-PON physical layer authentication method according to claim 1, characterized in that: Step S5 specifically includes the following steps: S51: After the OLT initiates authentication to the ONU, the ONU sends the previously negotiated authentication data to the OLT; S52: The OLT first uses an AMP to amplify the received OFDM optical signal, and then uses an OSA to collect OFDM spectrum data and convert it into a sequence form; S53: The sequence data is then subjected to principal component analysis algorithm to reduce the data dimension and extract the main features; S54: Input the reduced-dimensional data into a pre-trained one-dimensional convolutional neural network; if the authentication result is a legitimate user, the corresponding service will be provided to the user; on the contrary, if the authentication result is an illegal user, the service will be refused.
Citation Information
Patent Citations
Physical layer authentication method based on principal component analysis and residual network
CN111541632A
System and method for smart device control using radar
US20210231775A1