A terminal radio frequency fingerprint extraction method based on LTE DMRS signal processing

By processing LTE DMRS signals, including frame synchronization, carrier frequency offset correction, and wavelet decomposition, the problems of large channel variation impact and low recognition accuracy in existing technologies are solved, and highly robust radio frequency fingerprint recognition for terminal devices is achieved.

CN116419239BActive Publication Date: 2025-11-28SOUTHEAST UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202310202285.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-02
Publication Date
2025-11-28
Estimated Expiration
2043-03-02

AI Technical Summary

Technical Problem

Existing LTE radio frequency fingerprint extraction methods mainly extract from LTE PRACH signals, which cannot achieve periodic authentication of devices, and have low identification accuracy under channel change conditions, failing to effectively separate the influence of the channel.

Method used

By sampling, synchronizing frames, estimating and correcting carrier frequency offset, decomposing and reconstructing wavelet decomposition, and training neural networks on LTE DMRS signals, the terminal's radio frequency fingerprint is extracted, mitigating the impact of channel variations and preserving the radio frequency fingerprint information.

Benefits of technology

It improves the channel robustness of LTE terminal equipment radio frequency fingerprint recognition, enabling it to maintain high recognition accuracy under channel changes and achieve periodic recognition of the equipment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116419239B_ABST
    Figure CN116419239B_ABST
Patent Text Reader

Abstract

The present application relates to a terminal radio frequency fingerprint extraction method based on LTE DMRS signal processing, comprising: (1) sampling the LTE DMRS signal, signal detection is carried out to obtain a rough starting point; (2) frame synchronization is carried out on the signal to obtain a more fine-grained starting point; (3) carrier frequency offset estimation and correction are carried out on the signal to obtain the amplitude of the subcarrier occupied by the DMRS; (4) the amplitude is subjected to 6-layer db6 wavelet decomposition, single-branch reconstruction and superposition are carried out on D1-D6 to obtain a signal containing a radio frequency fingerprint; (5) the signal after reconstruction and superposition is input, the unoccupied subcarriers in the effective 1200 subcarriers are zero-filled to obtain a training sample; (6) the training sample is used to train a neural network to obtain model parameters; (7) the test set is input into the trained neural network model to obtain a device classification result. The present application can suppress the adverse effects of time-varying channel fading on radio frequency fingerprint, and realize reliable extraction and identification of LTE terminal radio frequency fingerprint.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of information security, and particularly relates to a terminal radio frequency fingerprint extraction method based on LTE DMRS signal processing. BACKGROUND

[0002] Due to the natural hardware differences in the manufacturing process of wireless devices, the radio frequency signals sent by the wireless devices are affected. The effects mainly include IQ DC bias, IQ imbalance and power amplifier nonlinearity. Different hardware has different effects on signals, and these hardware defects will affect the communication performance of the system, but due to the physical unclonable feature, it is beneficial to realize the physical layer security identification of the device.

[0003] The existing LTE system has security risks at the protocol layer, so the system performance can be improved by means of physical layer radio frequency fingerprint identification. However, the existing LTE radio frequency fingerprint extraction method mainly extracts the radio frequency fingerprint from the LTE PRACH signal, which only appears in the random access stage of the device, and cannot be used for periodic authentication of the device. At the same time, the existing radio frequency fingerprint extraction method under the system does not effectively separate the channel influence, so that the system identification accuracy is low under the condition of channel change. Therefore, there is an urgent need for a new solution to solve the above technical problems. SUMMARY

[0004] The present application is aimed at solving the problems in the prior art, and provides a terminal radio frequency fingerprint extraction method based on LTE DMRS signal processing, which can effectively reduce the influence of channel change on device radio frequency fingerprint extraction and identification.

[0005] The terminal radio frequency fingerprint extraction method based on LTE DMRS signal processing provided by the present application comprises the following steps:

[0006] Step 1: sampling the LTE PUSCH signal and obtaining the baseband signal through frequency conversion, and performing signal detection to obtain a rough starting point.

[0007] Step 2: frame synchronization of the signal to obtain a finer starting point;

[0008] Step 3: carrier frequency offset estimation and correction of the signal to obtain the amplitude of the subcarriers occupied by the DMRS;

[0009] Step 4: 6-layer db6 wavelet decomposition of the amplitude of the subcarriers occupied by the DMRS to obtain detail coefficients D1-D6 and approximation coefficients A6, setting the approximation coefficients A6 to zero, and performing single-branch reconstruction and superposition on the detail coefficients D1-D6 to obtain a signal containing the radio frequency fingerprint, which is less affected by the channel;

[0010] Step 5: The unoccupied subcarriers in the effective 1200 subcarriers are zero-padded to obtain the training sample after the superposition of the reconstructed signals;

[0011] Step 6: The neural network is trained using the training sample to obtain the model parameters;

[0012] Step 7: The test set is input into the trained neural network model to obtain the device classification result.

[0013] In step 1, the starting point is detected based on a sliding window and a threshold value. The received baseband signal at the nth sampling point is denoted as y(n), n = 1, 2,..., N, and the signal is detected from n = 1. The window length is denoted as W, the step length is denoted as S, and the threshold value is denoted as T. If the following conditions are met in the kth detection, it is indicated that the starting point is near :

[0014]

[0015] In step 2, one subframe of PUSCH contains 14 symbols, and the beginning part of each symbol is a cyclic prefix, which is completely the same as the end part of the symbol. The coarse synchronization starting point is taken as the center, and the fine synchronization starting point is searched

[0016]

[0017] where M is the number of symbols contained in one subframe, K m represents the length of the cyclic prefix of the mth symbol, N m-1 represents the total length of the 0th symbol to the (m-1)th symbol, where N -1 = 0, L FFT represents the length of FFT operation, and (·)* represents complex conjugate operation.

[0018] In step 3, the modulated transmitted signal at time t can be represented as

[0019]

[0020] where x(t) is the transmitted baseband signal at time t, e (·) is an exponential operation, j is a complex symbol, and f1 is the carrier frequency of the transmitting end. In the case of not considering the channel and noise, the received baseband signal at time t can be represented as

[0021]

[0022] where f2 is the receiving end carrier frequency, and Δf = f1-f2 is the carrier frequency offset. After analog-digital conversion, the receiving baseband signal at the nth sampling point is

[0023]

[0024] where x(n) is the transmitting baseband signal at the nth sampling point, T s is the sampling frequency. Within one subframe, the carrier frequency offset estimation value can be expressed as

[0025]

[0026] where T s is the sampling frequency, ∠· represents the angle of a complex number, and n0 is the fine synchronization starting point. After frequency offset compensation, the receiving baseband signal at the nth sampling point can be expressed as

[0027]

[0028] Assuming that n = 0 represents the starting position of DMRS FFT operation in one subframe, the receiving baseband signal y1 is subjected to half-carrier offset to obtain the signal after half-carrier offset at the nth sampling point

[0029]

[0030] L s represents the position of the starting point of the signal segment subjected to FFT operation within the symbol corresponding to DMRS, and L cp represents the length of the cyclic prefix within the symbol corresponding to DMRS. FFT operation is performed on y2 to obtain the frequency domain signal Y2 corresponding to y2. Phase compensation is performed on Y2 to obtain the signal after phase compensation at the nth subcarrier

[0031]

[0032] At this time, the DMRS symbol Y3 is obtained, and the amplitude of DMRS on the occupied subcarrier can also be obtained.

[0033] where step 4 is specifically as follows: db6 wavelet is adopted to perform 6-layer wavelet decomposition on Y3 to obtain an approximate component A6 and detail components D1-D6. The signal frequency corresponding to the approximate component A6 is the lowest, and the signal frequency corresponding to the detail components D1-D6 gradually decreases. Since the channel mainly affects the value of the approximate component A6, the approximate component A6 is set to zero, and the detail components D1-D6 are subjected to single-branch reconstruction and superposition to obtain a signal containing a radio frequency fingerprint, which is less affected by the channel.

[0034] Wherein, step 5 is specifically as follows: under the condition that the LTE uplink bandwidth is 20MHz, in 2048 subcarriers, only the 1200th subcarrier from the 427th to the 1626th is an effective subcarrier. The zero-padded subcarriers in the 1200 effective subcarriers are filled in the reconstructed superimposed signal to obtain a training sample.

[0035] Wherein, step 6 is specifically as follows: on the basis of the neural network InceptionTime, the sample label is smoothed to obtain a label value

[0036] y'=(1-alpha)y+alphaN y (10)

[0037] Wherein, alpha is a label smoothing coefficient, y is a label after One-Hot encoding, N y is the number of terminals. In the application, alpha is 0.1, L2 regularization is added, the parameter is set to 0.1, the learning rate is set to 0.003. The training sample is used to train the neural network to obtain a model parameter.

[0038] Wherein, step 7 is specifically as follows: the test set data is input into the trained neural network model to obtain a device classification result.

[0039] Compared with the prior art, the application has the following advantages: according to the above method, the terminal LTE DMRS signal can be processed, the influence of the channel on the DMRS is reduced through wavelet decomposition and reconstruction, the radio frequency fingerprint information in the signal is retained, the channel robustness of the LTE terminal device radio frequency fingerprint recognition is effectively improved, the recognition performance is less affected by the position change, and the device can be periodically identified. BRIEF DESCRIPTION OF DRAWINGS

[0040] Figure 1 is the amplitude of the DMRS signal on each subcarrier;

[0041] Figure 2 is the signal after the single-branch reconstruction and superposition of the approximation coefficients D1-D6. DETAILED DESCRIPTION

[0042] In order to deepen the understanding of the application, the embodiment will be described in detail below with reference to the drawings.

[0043] Embodiment 1: the application provides a terminal radio frequency fingerprint extraction method based on LTE DMRS signal processing, and the specific technical steps are as follows.

[0044] 1. The LTE PUSCH signal is sampled, and the baseband signal is obtained through frequency conversion, starting point detection and frame synchronization.

[0045] (1) Start point detection

[0046] The start point is detected by using a method based on sliding window and threshold. Let y(n) be the received baseband discrete signal in a period of time, n = 1, 2,..., N. Starting from n = 1, the signal is detected. Let W be the window length, S be the step length, and T be the threshold. In the kth detection, if the following conditions are met, it is considered that the start point is in the vicinity of

[0047]

[0048] (2) Frame synchronization

[0049] Taking the coarse synchronization start point as the center, the start point of fine synchronization is searched in the range of

[0050]

[0051] where M is the number of symbols contained in a subframe, K m represents the length of the mth symbol cyclic prefix, N m-1 represents the total length from the 0th symbol to the m-1th symbol, where N -1 = 0, L FFT represents the length of FFT operation, and (·)* represents complex conjugate operation.

[0052] (3) Carrier frequency offset estimation and compensation

[0053] The modulated transmitted signal at time t can be represented as

[0054]

[0055] x(t) is the transmitted baseband signal at time t, e (·) is the exponential operation, j is the complex symbol, and f1 is the transmitted carrier frequency. Without considering the channel and noise, the received baseband signal at time t can be represented as

[0056]

[0057] where f2 is the received carrier frequency, and Δf = f1-f2 is the carrier frequency offset. After analog-to-digital conversion, the received baseband signal at the nth sampling point is

[0058]

[0059] where x(n) is the transmitted baseband signal at the nth sampling point, and T s is the sampling frequency. In a subframe, the carrier frequency offset estimation value can be represented as​​​

[0060]

[0061] where T s is the sampling frequency, ∠· represents the angle of complex number, after frequency offset compensation, the received baseband signal of the nth sampling point can be expressed as

[0062]

[0063] (4) DMRS acquisition

[0064] Suppose n = 0 represents the starting position of DMRS FFT operation in a subframe, the received baseband signal y1 is subjected to half-carrier offset to obtain the signal after half-carrier offset at the nth sampling point

[0065]

[0066] L s represents the position of the starting point of the signal segment subjected to FFT operation in the symbol corresponding to the DMRS, L cp represents the length of the cyclic prefix in the symbol corresponding to the DMRS. The FFT operation is performed on y2 to obtain the frequency domain signal Y2 corresponding to y2. The phase compensation is performed on Y2 to obtain the signal after phase compensation at the nth subcarrier

[0067]

[0068] At this time, the DMRS symbol Y3 is obtained, and the amplitude of the DMRS on the occupied subcarrier can also be obtained. As shown in Figure 1 shows the amplitude of the received DMRS signal on each subcarrier.

[0069] 2. Device radio frequency fingerprint extraction based on DMRS

[0070] (1) Wavelet decomposition and reconstruction

[0071] The db6 wavelet is adopted to perform 6-layer wavelet decomposition on Y3 to obtain the approximation component A6 and the detail components D1-D6. The signal frequency corresponding to the approximation coefficient A6 is the lowest, and the signal frequency corresponding to the detail coefficients D1-D6 gradually decreases. Since the channel mainly affects the value of the approximation coefficient A6, the approximation coefficient A6 is set to zero, and the detail coefficients D1-D6 are reconstructed and superimposed to obtain a signal containing a radio frequency fingerprint, which is less affected by the channel. As shown in Figure 2 shows the signal after single-branch reconstruction and superposition of the detail components D1-D6.

[0072] (2) Sample length normalization

[0073] Under the condition of 20MHz of the LTE uplink bandwidth, in 2048 subcarriers, only the 427th to the 1626th subcarriers of a total of 1200 subcarriers are effective subcarriers. The unoccupied subcarriers in the effective 1200 subcarriers are zero-padded to obtain the training sample after the superposition of the reconstructed signal.

[0074] 3. Neural network training and classification

[0075] On the basis of the InceptionTime neural network, label smoothing processing is performed on the sample label to obtain

[0076] y' = (1 - a) y + aN y (10)

[0077] where a is a label smoothing coefficient, y is a One-Hot encoded label, N y is the number of terminals. In the present application, a is 0.1, L2 regularization is added, the parameter is set to 0.1, the learning rate is set to 0.003, the training sample is used to train the neural network, and the model parameter is obtained.

[0078] The trained neural network is tested by using the test set to realize terminal physical layer radio frequency fingerprint identification.

[0079] Table 1 Performance comparison on different data sets

[0080]

[0081] As shown in Table 1, the performance comparison of the present application on different data sets under the condition of 10 mobile phone devices is shown. Compared with directly using the original DMRS IQ signal as the training sample, the method of the present application can effectively reduce the influence of channel change on device radio frequency fingerprint identification, and the classification accuracy is improved under different data sets and under different mobile phone motion states.

[0082] As shown in Table 2, it is the confusion matrix under the condition that the training set is DS3 and the test set is DS4. As can be seen from Table 2, the classification accuracy of other devices is relatively high except for device UE6.

[0083] Table 2 Confusion matrix under the condition that the training set is DS3 and the test set is DS4

[0084]

[0085] It should be noted that the above embodiments are not intended to limit the protection scope of the present application, and equivalent transformations or substitutions made on the basis of the above technical solutions all fall within the scope of protection of the claims of the present application.

Claims

1. A terminal radio frequency fingerprint extraction method based on LTE DMRS signal processing, characterized in that, The method comprises the following steps: Step 1: sampling the LTE PUSCH signal and obtaining a baseband signal through frequency down-conversion, and performing signal detection to obtain a rough starting point; Step 2: performing frame synchronization on the signal to obtain a more fine-grained starting point; Step 3: performing carrier frequency offset estimation and correction on the signal to obtain the amplitude of the subcarriers occupied by the DMRS; Step 4: performing 6-layer db6 wavelet decomposition on the amplitude of the subcarriers occupied by the DMRS to obtain detail coefficients D1-D6 and approximation coefficients A6, setting the approximation coefficients A6 to zero, and performing single-branch reconstruction and superposition on the detail coefficients D1-D6 to obtain a signal containing a radio frequency fingerprint, which is less affected by the channel; Step 5: zero-padded the unoccupied subcarriers in the effective 1200 subcarriers to obtain a training sample; Step 6: training the neural network using the training sample to obtain model parameters; Step 7: inputting the test set into the trained neural network model to obtain the device classification result. 2.The terminal radio frequency fingerprint extraction method based on LTE DMRS signal processing of claim 1, wherein, Step 1 is as follows: the received baseband signal at the nth sampling point is denoted as y(n), n = 1, 2,..., N, starting from n = 1, the signal is detected, the window length is denoted as W, the step length is denoted as S, and the threshold value is denoted as T, in the kth detection, if The starting point is indicated in the vicinity. 3.The terminal RF fingerprint extraction method based on LTE DMRS signal processing of claim 1, wherein, Step 2 is specified as follows: Find the fine synchronization start point in the range centered at the coarse synchronization start point with a range of​ where M is the number of symbols contained in one subframe, K m denotes the length of the mth symbol cyclic prefix, N m-1 denotes the total length of the 0th symbol to the m-1th symbol, where N -1 = 0, L FFT denotes the length of FFT operation, (·)* denotes complex conjugate operation. 4.The terminal RF fingerprint extraction method based on LTE DMRS signal processing of claim 1, wherein, Step 3 is as follows: within a subframe, the carrier frequency offset estimation value is denoted as where T s is the sampling frequency, and ∠· denotes the angle of a complex number. After the frequency offset compensation, the nth received baseband signal can be expressed as where e (·) is an exponential operation, j is a complex symbol, x(n) represents a transmitted baseband signal at the nth sample point, and n=0 represents the starting position of DMRS FFT operation in a subframe. The received baseband signal y1 is subjected to half-carrier offset to obtain a signal subjected to half-carrier offset at the nth sample point L s denotes the position of the starting point of the signal segment corresponding to the FFT operation within the symbol corresponding to the DMRS, L cp denotes the length of the cyclic prefix within the symbol corresponding to the DMRS, the FFT operation is performed on y2 to obtain the frequency domain signal Y2 corresponding to y2, and phase compensation is performed on Y2 to obtain the signal after phase compensation at the nth subcarrier At this time, the DMRS symbol Y3 is obtained, and the amplitude of the subcarriers occupied by the DMRS can also be obtained.

5. The terminal radio frequency fingerprint extraction method based on LTE DMRS signal processing according to claim 1, characterized in that, Step 4: performing 6-layer db6 wavelet decomposition on Y3 to obtain detail coefficients D1-D6 and approximation coefficients A6, setting the approximation coefficients A6 to zero, and performing single-branch reconstruction and superposition on the detail coefficients D1-D6 to obtain a signal containing a radio frequency fingerprint, which is less affected by the channel. 6.The terminal RF fingerprint extraction method based on LTE DMRS signal processing of claim 1, wherein, Step 5: under the condition that the LTE uplink bandwidth is 20MHz, in the 2048 subcarriers, only the first 427 to the 1626th, a total of 1200 subcarriers are effective subcarriers, the reconstructed and superimposed signal is zero-padded in the unoccupied subcarriers in the effective 1200 subcarriers to obtain a training sample.

7. The terminal radio frequency fingerprint extraction method based on LTE DMRS signal processing according to claim 1, characterized in that, Step 6: on the basis of the neural network InceptionTime, the sample labels are processed by label smoothing, and an L2 regularization term is added, the neural network is trained using the training sample to obtain model parameters. 8.The terminal RF fingerprint extraction method based on LTE DMRS signal processing of claim 1, wherein, Step 7: inputting the test set into the trained neural network model to obtain the device classification result.