A cognitive radio anti-pue attack solution based on authentication center

By introducing an authentication center into cognitive radio networks and using hash function clusters and public-key cryptography to verify the identity of the primary user, the PUEA problem is solved, spectrum resource utilization and network security are improved, and the access threshold for cognitive users is lowered.

CN116684871BActive Publication Date: 2025-12-23GUANGDONG POLYTECHNIC NORMAL UNIV
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202310648780.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-06-01
Publication Date
2025-12-23
Estimated Expiration
2043-06-01

AI Technical Summary

Technical Problem

Cognitive radio networks are vulnerable to Pullover Attacks (PUEAs) during spectrum sensing, which can lead to misjudgments of sensing results and affect spectrum resource utilization and network reputation.

Method used

A cognitive radio anti-PUE attack method based on an authentication center is adopted. The main user and cognitive user register with the authentication center, and hash function clusters and public key encryption technology are used. The authentication center verifies the identity of the main user to prevent malicious users from impersonating them.

Benefits of technology

It improves spectrum resource utilization and network security, reduces transmission channel overhead, lowers the access threshold for cognitive users, and enhances the security and efficiency of cognitive users.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116684871B_ABST
    Figure CN116684871B_ABST
Patent Text Reader

Abstract

The present application relates to the security application field of cognitive radio spectrum sensing, and discloses a cognitive radio anti-PUE attack solution method based on an authentication center, which comprises two steps of registration and authentication processes, and the participating roles of the protocol process are a primary user network, a cognitive user, a malicious user and a third-party trusted authentication center; in the cognitive network, the number of base stations of the primary user network is far less than that of the cognitive user; the cognitive user is a user of spectrum holes, needs to access the cognitive network conveniently and quickly, and its main function should be placed on spectrum sensing and channel switching, so that the whole authentication process has the minimum modification on the function of the cognitive user and has high feasibility.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the security application field of cognitive radio spectrum sensing, in particular to a cognitive radio PUE attack prevention solution based on an authentication center. BACKGROUND

[0002] With the continuous development of communication technology, people's requirements for wireless communication services are also getting higher and higher. The current spectrum allocation policy is not reasonable enough, resulting in low utilization of spectrum. In order to improve the utilization of spectrum resources, cognitive radio is widely used in industrial and military fields. In the implementation process of cognitive radio, the cognitive user has the function of sensing the surrounding spectrum resources, and uses the spectrum resources under the premise of not interfering with the primary user to improve the utilization of spectrum resources.

[0003] With the further development of cognitive radio technology, the security problem of cognitive radio network is increasingly prominent. Network security is essential for the normal operation of wired and wireless communication networks. If the communication is not secure, the application range of the network will be greatly limited, especially in military communication, the sensitivity of information requires high security in the communication process. As a kind of wireless network, cognitive wireless network first faces many security threats of traditional wireless network, secondly, due to the characteristics of cognitive wireless network itself, such as no fixed available spectrum, end-to-end reconfigurable, etc., new security threats are brought, and these security risks and attack behaviors make the security problem of cognitive radio more complex. Therefore, whether the process of communication using cognitive radio technology is safe or not has become an important factor for its wide application prospect.

[0004] The spectrum sensing function is the basis for the implementation of other processes of cognitive radio, but it is also the most vulnerable to attack stage. Cognitive radio technology fully utilizes the channel resources not used by the primary user through the optimization design strategy. Although this working method improves the utilization of spectrum resources, it also provides a gap for malicious users to attack. In the spectrum sensing process, the primary user emulation attack (PUEA) is the most vulnerable, that is, a malicious attacker sends a signal simulating the characteristics of the primary user on the channel, which interferes with the sensing of the cognitive user to the primary user signal, misjudges whether the frequency band where the primary user is located is active, and causes the sensing result to be wrong, affecting the use of the primary user spectrum resource by the secondary user. The malicious user interferes with the primary user and prevents the legitimate secondary user from using the idle resource opportunity, which causes the cognitive user to have a low reputation evaluation of the cognitive network, resulting in low utilization of the entire cognitive network, which is the biggest security risk of cognitive radio. Therefore, we propose a cognitive radio PUE attack prevention solution based on an authentication center. SUMMARY

[0005] (I) Technical problems solved

[0006] In view of the deficiencies of the prior art, the present application provides a cognitive radio anti-PUE attack solution method based on an authentication center, which solves the above problems.

[0007] (II) Technical solutions

[0008] To achieve the above purposes, the present application provides the following technical solutions: a cognitive radio anti-PUE attack solution method based on an authentication center, which includes two steps of registration and authentication process, and the participating roles of the protocol process are a primary user network, a cognitive user, a malicious user, and a third-party trusted authentication center.

[0009] Preferably, the registration includes the following steps:

[0010] The primary user and the cognitive user register to show the legitimacy of their own identity;

[0011] When the primary user PMU i enters the primary user network, it needs to provide the initial identity information PUID i to the authentication center;

[0012] At this time, the authentication center provides the primary user with a shared key

[0013] Hash function cluster {H0(x),1(), H2(x),3(x),…, H i (x),…, n ()};

[0014] The cognitive user SEU j also needs to provide the authentication center with identity information SUID j , and the authentication center provides the cognitive user with a shared key Sy j ;

[0015] In a cognitive network environment where multiple primary users coexist, the authentication center needs to store the following information:

[0016] Hash function cluster matrix:

[0017]

[0018] Primary user identity information vector:

[0019] {PUID1PUID2…PUID i …PUID n};

[0020] Cognitive user identity information vector:

[0021] {SUID1SUID2…SUID i …SUIDn}。

[0022] Preferably, the authentication process comprises the following steps:

[0023] Step 1: the cognitive user is aware of the data packet in the f1 band, and the content is

[0024] Step 2: the cognitive user is aware of the spectrum information f i whether it is the currently occupied spectrum resource, if not, discard the broadcast data packet, end. If yes, judge the time T p whether it is the latest message time of the frequency band, if yes, continue step (3), otherwise discard the data packet.

[0025] Step 3: get the hash value of the current primary user identity information and send {E(PUcenter,(PUID i ,k)),T s ,N2,SUID j} to the authentication center to verify whether the primary user is legal.

[0026] Step 4: after receiving the request of the cognitive user, the authentication center judges whether T s is the latest time using the frequency band, otherwise discard the request data packet.

[0027] Step 5: the authentication center decrypts the encrypted information using its own private key, D(PRcenter,E(PUcenter,(PUID i ,k))), to obtain the primary user identity PUID i and the kth hash function used, determine the hash function H ik (x) in the function cluster matrix through i and k, and obtain i do hash calculation,

[0028] Step 6: get i from SUID return

[0029] Step 7: the cognitive user compares h with if the two are equal, suspend the use of the spectrum resource, and give the use right back to the primary user i, otherwise, regard it as a malicious user, refuse the request, and report to the authentication center.

[0030] ​The eighth step: after receiving the report, the authentication center records the user information and adds it to the blacklist, and if the malicious user initiates a request again next time, the cognitive user is directly fed back to reject the request.

[0031] The ninth step: when the number of times of using each Hash function of the Hash function cluster reaches a certain number, the authentication center replaces the Hash function cluster for the primary user again and notifies the primary user.

[0032] Preferably, the pseudo code of the authentication workflow is as follows:

[0033] 1) PMU->SEU: E(PUcenter, (PUID i , k))||Tp||H k (PUID i ||Sx i )||f i ||N1;

[0034] 2) SEU->TCC: E(PUcenter, (PUID i , k))||SUID j ||Ts||N2||Ts;

[0035] 3) TCC->SEU: h'||Tc||N2+1;

[0036] 4) SEU->PMU: h==h'XOR Sy j .

[0037] The cognitive radio security spectrum sensing system comprises a Sora station, a PC and a cloud server.

[0038] (Three) beneficial effects

[0039] Compared with the prior art, the application provides a cognitive radio PUE attack prevention solution based on an authentication center, which has the following beneficial effects:

[0040] 1. The application combines Hash algorithm and public key encryption technology to ensure information security and save transmission channels, and improves the security of the entire interaction process through the role of the authentication center.

[0041] 2. In the scheme, the cognitive user does not need additional space and time overhead, improves security while ensuring efficiency.

[0042] 3. Due to the highly dispersed nature of cognitive users and the diverse range of access terminals, the protocol design of this invention requires minimal functional modifications to cognitive users, thus lowering the barrier to entry for cognitive users to access spectrum resources. Furthermore, the authentication center and primary user network are centrally managed devices by operators, making this approach highly feasible.

[0043] 4. In cognitive networks, the number of base stations in the primary user network is far less than that of cognitive users. As users of spectrum holes, cognitive users need convenient and quick access to the cognitive network, and their main functions should be spectrum sensing and channel switching. Therefore, the entire authentication process requires minimal modification to the cognitive user's own functions, making it highly feasible. Attached Figure Description

[0044] Fig. 1 This is a diagram illustrating the working mode of the present invention;

[0045] Fig. 2 This is a diagram illustrating the secure data transmission of this invention;

[0046] Fig. 3 This is the system architecture diagram of the present invention. Detailed Implementation

[0047] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0048] Please see Figs. 1-3 This paper presents a cognitive radio solution for preventing impersonation attacks based on an authentication center. After a cognitive user connects to the network, when a primary user needs to use authorized spectrum, the cognitive user uses the authentication center to verify the primary user's identity, confirming its authenticity and preventing malicious impersonation. This solution combines hash algorithms and public-key encryption to ensure information security, improve efficiency, and save transmission channel space. The authentication center enhances the security of the entire interaction process. A communication platform is built using Microsoft's Sora software radio platform. This platform is then further developed using its SDK to achieve spectrum awareness of the surrounding environment and statistical analysis of spectrum resource usage.

[0049] In the working model of cognitive radio network, there are two network models: primary user network and cognitive user network. The primary user network is an existing network, in which the primary user is the authorized user, who has the right to use the spectrum resource. The primary user network is composed of primary users and primary user base stations. The primary users communicate in the licensed frequency band and are not affected by the cognitive users, nor do they change their network structure because of the cognitive users. The cognitive user network is a non-licensed user network built by the cognitive users, which waits for the spectrum hole in the primary user network and accesses opportunistically.

[0050] Currently, there are two commonly used network architectures: distributed network and centralized network. However, for most primary user networks, the centralized network architecture is mainly used, such as mobile communication network, broadcast television network, etc. Therefore, the present application is directed to a cognitive wireless network based on centralized structure.

[0051] The cognitive wireless network based on centralized structure has two identities and one base station. The primary user network is an existing network that has the licensed frequency band. The primary user base station is a fixed infrastructure and the core of the entire network, which can use the licensed frequency band of the primary user and is mainly responsible for providing services to the primary user. When the primary user needs to use the spectrum resource, the primary user communicates with the base station to transmit the data content to the base station and authorizes the base station to use the frequency band for communication. If the primary user does not use the spectrum resource temporarily, the communication between the primary user and the base station will be terminated, and the base station will also stop using the frequency band. At this time, the spectrum resource is idle. At this time, the cognitive user perceives that there is a spectrum hole in this segment, and uses the frequency band for data transmission without interfering with the use of the primary user.

[0052] The attacker can attack the gap in two places. One is that the primary user applies to the base station for spectrum use, and the malicious user node imitates the identity of the primary user to obtain and use the spectrum resource from the base station. The other is that the cognitive user perceives whether the primary user base station is working, and the malicious user pretends to be the primary user base station to communicate and prevent other cognitive users from using the spectrum resource. Although the attack points of the malicious users are different, they have similarities, which are the authentication of the identity of the primary user. Because the base station itself only manages and controls the spectrum resource and does not need to communicate with the cognitive user, the final communication is between the cognitive user and the primary user. The authentication of the primary user attack is also the authentication of the identity of the primary user by the cognitive user, and the primary user and the cognitive user do not need to make any modifications to adapt to this process. Based on this idea, the present application proposes an authentication scheme based on an authentication center.

[0053] The participants of the protocol process include the primary user network, the cognitive user, the malicious user and the third party trust authentication center (Trust Authentication Centre). The primary user network includes the primary user equipment and the transmitting base station. The authentication of the primary user identity is mainly for the primary user equipment rather than for the base station equipment. The malicious user is a user who has learned part of the primary user information and initiates a request to the cognitive user by imitating the identity of the primary user, thereby disturbing the cognitive user from the spectrum sensing result. The authentication center is an authentication server. The scheme assumes that the primary user network and the authentication center belong to a same secure network environment.

[0054] The scheme mainly includes two stages: the registration and the authentication process.

[0055] (1) Registration

[0056] The primary user and the cognitive user need to register with the authentication center before entering the cognitive network, so as to show the legitimacy of their identities. When the primary user PMU i enters the primary user network, it needs to provide the initial identity information PUID i to the authentication center, and the authentication center provides the primary user with the shared key and the hash function cluster {H0(x),1(), H2(x),3(x),…,H i (x),…, n ()}. The cognitive user SEU j also needs to provide the identity information SUID j to the authentication center, and the authentication center provides the cognitive user with the shared key Sy j . In the cognitive network environment where multiple primary users coexist, the authentication center needs to store the following information.

[0057] Hash function cluster matrix:

[0058]

[0059] Primary user identity information vector:

[0060] {PUID1 PUID2…PUID i …PUID n}(2)

[0061] Cognitive user identity information vector:

[0062] {SUID1 SUID2…SUID i …SUID n}(3)

[0063] (2) Authentication process

[0064] At a certain moment, the primary user needs to use the licensed frequency band to work, at this time the authentication user needs to authenticate the identity of the primary user, if the authentication is successful, the frequency band usage right is released, otherwise the primary user is judged as a malicious user, the authentication process is as shown in Fig. 2

[0065] Step one, the cognitive user perceives the data packet of f1 frequency band, the content is

[0066] Step two, the cognitive user judges whether it is the currently occupied frequency spectrum resource according to the spectrum information f i , if not, the broadcast data packet is discarded, and the process is ended. If yes, whether the time T p sent by the primary user is the latest message time of the frequency band is judged, if yes, the step (3) is continued, otherwise the data packet is discarded.

[0067] Step three, the hash value of the current primary user identity information is obtained , and {E(PUcenter,(PUID i ,k)),T s ,N2,SUID j} is sent to the authentication center to verify whether the primary user is legal.

[0068] Step four, after the authentication center receives the request of the cognitive user, whether T s is the latest time of using the frequency band is judged, otherwise the request data packet is discarded.

[0069] Step five, the authentication center decrypts the encrypted information by using the private key of itself, D(PRcenter,E(PUcenter,(PUID i ,k))), the primary user identity PUID i is obtained, and the kth hash function is used, the hash function H ik (x) in the function cluster matrix is determined through i and k, and the hash value h i is obtained through PUID i .

[0070] Step six, the cognitive user returns h to the cognitive user.

[0071] Step seven, the cognitive user compares h with h , if both are equal, the use of the frequency spectrum resource is suspended, and the use right is returned to the primary user i, otherwise the primary user is regarded as a malicious user, the request is refused, and the authentication center is reported.

[0072] ​​Step eight, after receiving the report, the authentication center records the user information and adds it to the blacklist.

[0073] Step nine, when the number of times of using each Hash function of the Hash function cluster reaches a certain number, the authentication center replaces the Hash function cluster for the main user again and notifies the main user.

[0074] The pseudo code of the workflow is as follows:

[0075] 1) PMU->SEU: E(PUcenter, (PUID i , k))||Tp||H k (PUID i ||Sx i )||f i ||N1

[0076] 2) SEU->TCC: E(PUcenter, (PUID i , k))||SUID j ||Ts||N2||Ts

[0077] 3) TCC->SEU: h'||Tc||N2+1

[0078] 4) SEU->PMU: h==h'XOR Sy j .

[0079] The present application is based on the sora platform, and the original data obtained from the Sora platform is preprocessed to obtain processed data by clipping and removing header information. Then, FFT transformation is written to process the data, obtain the frequency domain graph of the signal, and obtain the phase spectrum and power spectrum through analysis of the spectrum graph.

[0080] The specific process of data transmission of the present application is as follows:

[0081] Step one, the main user broadcasts a message to the wireless environment, stating that the authorized frequency band is to be reclaimed. The data carried by the broadcast message includes the identity of the main user, the authorized frequency band information, etc.

[0082] Step two, after receiving the broadcast message, the cognitive user matches the information of the authorized frequency band carried in the message with the frequency band information occupied by itself, and if the information matches, initiates authentication of the identity of the main user to the authentication center.

[0083] Step three, the authentication center accepts processing, authenticates the identity of the main user, and returns the authentication information.

[0084] Step four, the cognitive user compares the returned authentication information with the main user identity information, returns the authentication result, and performs channel switching and other processes: gives up the channel or continues to occupy it.

[0085] While the embodiments of the application have been illustrated and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made therein without departing from the spirit and scope of the application, which is defined by the appended claims and their equivalents.

Claims

1. A method for preventing PUE attack in cognitive radio based on authentication center, characterized in that, The protocol process includes two steps of registration and authentication process, and the participating roles of the protocol process are a main user network, a cognitive user, a malicious user and a third-party trusted authentication center; The registration comprises the following steps: the cognitive user SEU j It is also necessary to provide the identity information SUID to the authentication center j The authentication center then provides the cognitive user with a shared key Sy j ; The authentication process includes the following steps: First step: the user perceives the data packet of f1 band, the content is Second step: the cognitive user judges according to the spectrum information f i whether the spectrum resource is currently occupied, if not, discarding the data packet and ending; if yes, judging the time T p of the primary user sending, if yes, continuing the third step, otherwise discarding the data packet; Third step: get the hash value of the current main user identity information and send {E(PUcenter, (PUID i ,k)), T s ,N2, SUID j} to the authentication center to verify whether the main user is legal; Step 4: After receiving the request from the cognitive user, the authentication center judges whether the time is the latest time of using the frequency band. If yes, it continues to step 5, otherwise, it discards the data packet. s Step 4: After receiving the request from the cognitive user, the authentication center judges whether the time is the latest time of using the frequency band. If yes, it continues to step 5, otherwise, it discards the data packet. Step 5: The authentication center decrypts the encrypted information using its own private key, D(PRcenter, E(PUcenter, (PUID i , k))) to obtain the primary user identity PUID i and the kth hash function used, and determines the hash function H ik (x) in the function cluster matrix through i and k to obtain i Hash calculation, ​ Step 6: By SUID i Obtain Return to the cognitive user Step 7: The cognitive user compares h with If they are equal, then the use of the spectrum resource is suspended and the use right is returned to the primary user PMU i Otherwise, it is considered as a malicious user and the request is rejected and reported to the certification center. In the eighth step, after receiving the report, the authentication center records the information of the user and adds the user to a blacklist; if the malicious user initiates a request again next time, the authentication center directly feeds back to the cognitive user to notify the cognitive user to reject the request; In the ninth step, when the use times of the Hash functions in the Hash function cluster reach a certain value, the authentication center replaces the Hash function cluster for the main user again and notifies the main user.

2. The method of claim 1, wherein the method is based on a certification center. The registration includes the following steps: The main user and the cognitive user register to show the legitimacy of their identities; When the primary user PMU i enters the primary user network, it needs to provide initial identity information PUID to the authentication center i ; At this time, the authentication center provides the shared key to the main user and a hash function cluster {H0(x), H1(x), H2(x), H3(x),..., H i (x),..., H n (x)}; cognitive user SEU j Identity information SUID is also required to be provided to the authentication center j The authentication center then provides the cognitive user with a shared key Sy j ; In the cognitive network environment where multiple main users coexist, the authentication center needs to store the following information: Hash function cluster matrix: Main user identity information vector: {PUID1 PUID2 … PUID i … PUID n} Cognitive user identity information vector: {SUID1 SUID2 … SUID i … SUID n}

Citation Information

Patent Citations

  • Primary user emulation attack-based interference estimation method for cognitive radio network

    CN103746756A