Wireless optical communication physical layer authentication system and method
By using a multi-receiver and master control authentication method in a wireless optical communication system, the authentication threshold is calculated using the pilot signal strength and channel parameters to identify imitation and replay attacks, solving the problem of synchronous identification in existing technologies and improving the security and reliability of the system.
Patent Information
- Application Number
- CN202411416481.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-11
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2044-10-11
AI Technical Summary
Existing physical layer authentication methods for wireless optical communications cannot simultaneously identify imitation attacks and replay attacks, affecting the security and reliability of the system.
A wireless optical communication physical layer authentication system with at least three receivers and a master control is adopted. Through photoelectric detection, ranging, data processing and authentication modules, the pilot signal strength is used to calculate the distance and channel parameters, generate the authentication threshold and expected watermark, and integrate the receiver's authentication parameters to determine the legitimacy of the signal transmitter.
It achieves synchronous identification of imitation attacks and replay attacks, improves the security and reliability of wireless optical communication systems, and ensures the legitimacy of both communicating parties.
Smart Images

Figure CN119299175B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of wireless optical communication, in particular to a wireless optical communication physical layer authentication system and method. BACKGROUND
[0002] Wireless optical communication is a secure data access method for next-generation data access and Internet of Things, but its open transmission medium makes it vulnerable to attacks such as spoofing. Specifically, an attacker can access the network by impersonating a user to obtain further illegal benefits, leading to privacy leakage and data injection, and even causing the entire wireless optical communication system to be destroyed. Therefore, when performing wireless optical communication, it is necessary to verify whether the received message is sent by a legal device to ensure the legality of both parties. Unlike upper-layer authentication which relies on encryption algorithms, physical layer authentication utilizes the unique physical layer characteristics of wireless signals, making it difficult for attackers to observe and imitate, providing higher security for wireless optical systems.
[0003] Physical layer authentication methods can be divided into two categories: active physical layer authentication methods and passive physical layer authentication methods. Passive physical layer authentication methods are based on inherent physical layer characteristics, and the transmitting end does not need to perform additional processing on the transmitted signal or generate additional related identity information, but a large amount of data is required in the early stage of authentication and a certain amount of time is spent to pre-establish a radio fingerprint database of legal transmitting ends or to train a model of the characteristics, and the authentication accuracy depends on the number of features used. Active physical layer authentication superimposes watermark information in the transmitted signal by human intervention, and the receiving end verifies the identity of the transmitting end by checking whether the watermark exists in the received signal, which has a relatively more accurate authentication result and stronger robustness.
[0004] In existing active physical layer authentication methods, the legal transmitting end superimposes watermark information in the transmitted signal, and the receiving end can effectively identify the impersonation attack by checking whether the watermark information in the received signal is consistent with the estimated watermark generated by the receiver, i.e., whether the information is sent by the legal transmitting end. However, for a replay attack, i.e., an attacker only forwards the signal with superimposed watermark information after eavesdropping, since the attacker does not modify the signal, it is impossible to determine whether the signal is sent by the legal transmitting end based on the received signal.
[0005] However, imitation attacks and replay attacks are interrelated. For example, an attacker may first perform a replay attack to obtain the identity information or signal of the legitimate transmitter, and then use this information to launch an imitation attack. If the replay attack occurs before the imitation attack is identified, the attacker may complete the disguise without the system noticing, resulting in data leakage. In addition, the identification of each attack method requires a certain amount of time. The attacker may perform a replay attack during the identification process of the imitation attack, or perform an imitation attack during the identification process of the replay attack. Therefore, in addition to being able to identify imitation attacks and replay attacks, it is also necessary to be able to simultaneously identify imitation attacks and replay attacks to fully ensure the security and reliability of wireless optical communication systems.
[0006] In summary, how to design a wireless optical communication physical layer authentication system and method that can simultaneously identify imitation attacks and replay attacks, thereby improving the security and reliability of wireless optical communication systems, is an urgent problem that needs to be solved. Summary of the Invention
[0007] Therefore, the technical problem to be solved by the present invention is to overcome the problem that the physical layer authentication method in the prior art cannot simultaneously identify the attacker's replay attack and imitation attack, thereby affecting the security of the wireless communication system.
[0008] To solve the above technical problems, the present invention provides a wireless optical communication physical layer authentication system, comprising:
[0009] At least three receivers, each receiver comprising:
[0010] The photoelectric detection module is used to receive a message transmission request sent by the transmitting end during the handshake phase, convert the message transmission request into a first electrical signal and send it to the master control; receive a watermark superimposed signal during the message transmission phase, and convert the watermark superimposed signal into a second electrical signal;
[0011] a ranging module, configured to calculate a first distance between a receiver and a transmitting end and a first channel parameter based on the pilot signal strength in the first electrical signal; and calculate a second distance between the receiver and a transmitting end of a watermark superimposed signal and a second channel parameter based on the pilot signal strength in the second electrical signal;
[0012] a data processing module, configured to obtain a restored watermark-superimposed signal based on the second electrical signal and the second estimated channel, obtain a source signal based on the restored watermark-superimposed signal, and obtain a residual signal based on the restored watermark-superimposed signal, the source signal, and a power allocation factor;
[0013] authentication threshold upper and lower limits of the receiver based on the theoretical authentication test statistic standard Gaussian cumulative distribution function of the receiver, noise standard deviation of the receiver, the first channel parameter and the first distance; generating an expected watermark based on the total control transmitted key, encryption function for generating watermark and the source signal, and calculating the actual authentication test statistic of the receiver based on the expected watermark, the residual signal, the second channel parameter and the second distance;
[0014] The total control is in communication connection with each receiver and the transmitting end, and comprises:
[0015] The key update storage and watermark superposition setting module is used for generating a key and an encryption function for generating watermark based on the first electric signal, and transmitting the key and the encryption function for generating watermark to each receiver and the transmitting end.
[0016] The decision module is used for calculating the authentication parameter of each receiver based on the actual authentication test statistic and the authentication threshold upper and lower limits of the receiver, and determining whether the watermark superposition signal transmitting end is legal based on the authentication parameters of all receivers.
[0017] Preferably, the calculation formula of the actual authentication test statistic of the receiver is:
[0018]
[0019]
[0020] wherein, represents the actual authentication test statistic of the i-th receiver; D i ′ represents the second distance between the i-th receiver and the watermark superposition signal transmitting end; h i ′ represents the second channel parameter between the i-th receiver and the watermark superposition signal transmitting end; represents the expected watermark generated by the i-th receiver; (·) H represents conjugate transpose; ρ t represents the power allocation factor of the watermark superposition signal power on the watermark signal; ρ s represents the power allocation factor of the watermark superposition signal power on the message signal; ρ t ≤1, ρ s ≥0, ρ t 2 +ρ s 2 =1; represents the recovered watermark superposition signal of the i-th receiver; represents the source signal obtained by the i-th receiver; r irepresents the residual signal obtained by the ith receiver; i∈[1, m], m represents the number of receivers.
[0021] Preferably, the calculation formula of the upper limit of the authentication threshold of the receiver is:
[0022]
[0023] wherein, represents the upper limit of the authentication threshold of the ith receiver; θ i represents the theoretical authentication test statistic of the ith receiver; represents the standard Gaussian cumulative distribution function of the theoretical authentication test statistic of the ith receiver; D i represents the first distance between the ith receiver and the transmitting end; h i represents the first channel parameter of the ith receiver; L represents the length of the watermark superimposed signal; represents the upper limit of the false alarm probability of the ith receiver; σ wi represents the noise standard deviation of the ith receiver; ρ t represents the power allocation factor of the watermark superimposed signal power on the watermark signal; i∈[1, m], m represents the number of receivers.
[0024] The calculation formula of the lower limit of the authentication threshold of the receiver is:
[0025]
[0026] wherein, represents the lower limit of the authentication threshold of the ith receiver.
[0027] Preferably, the authentication parameter of the receiver is represented as:
[0028]
[0029] wherein, δ i represents the authentication parameter of the ith receiver; represents the actual authentication test statistic of the ith receiver; represents the upper limit of the authentication threshold of the ith receiver; represents the lower limit of the authentication threshold of the ith receiver; i∈[1, m], m represents the number of receivers.
[0030] Preferably, determining whether the transmitting end of the watermark superimposed signal is legal based on the authentication parameters of all receivers comprises:
[0031] If the product of the authentication parameters of all receivers is 1, it is determined that the transmitting end of the watermark superimposed signal is a legal transmitting end.
[0032] If the product of the authentication parameters of all receivers is 0, it is determined that the watermark superposition signal transmitting end is an illegal transmitting end.
[0033] Preferably, when the number of receivers is greater than 3, the total control further comprises:
[0034] An authentication receiver selection module is configured to select n receivers closest to the transmitting end as authentication receivers based on the first distances between the receivers and the transmitting end, wherein 3≤n≤m, and m represents the number of receivers.
[0035] An authentication enabling module is configured to control the n authentication receivers to receive the watermark superposition signal.
[0036] Preferably, the key updating storage and watermark superposition setting module updates the key and the encryption function for generating the watermark every preset time, and sends the updated key and the encryption function for generating the watermark to each receiver and the transmitting end.
[0037] Preferably, the total control further comprises a sink configured to control each receiver to reject the signal sent by the transmitting end when it is determined that the transmitting end is an illegal transmitting end.
[0038] Preferably, each receiver further comprises a ranging compensation calibration module configured to calibrate the first distance and the second distance between the receiver and the transmitting end by using a ranging compensation algorithm.
[0039] The application further provides a wireless optical communication physical layer authentication method applied to the wireless optical communication physical layer authentication system, and comprising the following steps:
[0040] In the handshake stage, each receiver receives the message transmission request sent by the transmitting end, converts the message transmission request into a first electric signal and sends the first electric signal to the total control; and each receiver calculates the first distance and the first channel parameter between the receiver and the transmitting end based on the pilot signal strength in the first electric signal.
[0041] The total control generates a key and an encryption function for generating a watermark based on the first electric signal, and sends the key and the encryption function for generating the watermark to each receiver and the transmitting end.
[0042] In the message transmission stage, each receiver receives the watermark superposition signal, converts the watermark superposition signal into a second electric signal, and calculates the second distance and the second channel parameter between the receiver and the watermark superposition signal transmitting end based on the pilot signal strength in the second electric signal.
[0043] Each receiver obtains a recovered watermark superposition signal based on the second electric signal and the second estimated channel, obtains a source signal based on the recovered watermark superposition signal, and obtains a residual signal based on the recovered watermark superposition signal, the source signal and the power allocation factor.
[0044] Each receiver calculates the authentication threshold upper and lower limits of the receiver based on the theoretical authentication test statistic standard Gaussian cumulative distribution function, noise standard deviation, the first channel parameter and the first distance; generates the expected watermark based on the total control transmitted key, the encryption function for generating the watermark and the source signal, and calculates the actual authentication test statistic of the receiver based on the expected watermark, the residual signal, the second channel parameter and the second distance;
[0045] The total control calculates the authentication parameter of each receiver based on the actual authentication test statistic and the authentication threshold upper and lower limits of the receiver, and determines whether the watermark superimposed signal transmitting end is legal based on the authentication parameters of all receivers.
[0046] The wireless optical communication physical layer authentication system provided in the application includes at least three receivers and a total control; in the handshake stage, the receiver converts the message transmission request sent by the transmitting end into a first electrical signal, and obtains the first distance and the first channel parameter between the current transmitting end and the receiver by using a ranging module; in the signal transmission stage, the receiver converts the received watermark superimposed signal into a second electrical signal, and obtains the second distance and the second channel parameter between the receiver and the watermark superimposed signal transmitting end; at the same time, the receiver obtains the recovered watermark superimposed signal, the source signal and the residual signal based on the received watermark superimposed signal and the second estimated channel, generates the expected watermark based on the key, the encryption function for generating the watermark and the source signal, and calculates the actual authentication test statistic of the receiver based on the expected watermark, the residual signal, the second channel parameter and the second distance, and finally calculates the authentication threshold upper and lower limits of the receiver based on the theoretical authentication test statistic standard Gaussian cumulative distribution function, the noise standard deviation of the receiver, the first channel parameter and the first distance; since the actual authentication test statistic of the receiver contains the distance information between the watermark superimposed signal transmitting end and the receiver, and also fuses the residual signal and the expected watermark, and the authentication threshold upper and lower limits contain the distance information between the receiver and the transmitting end, finally, the total control obtains the authentication parameter of the receiver for the transmitting end by judging whether the actual authentication test statistic of each receiver is within the authentication threshold range, so as to determine whether the distance between the watermark superimposed signal transmitting end and the receiver is changed, and whether the watermark information in the transmitted watermark superimposed signal is changed; since at least three reference points are needed in the optical wireless positioning system to determine the position of the transmitting end in the two-dimensional plane, therefore, the total control fuses the authentication parameters of at least three receivers, checks the authentication test statistic of the fused position information and the watermark information, so as to accurately identify the simulation attack of the tampered signal and the replay attack of not tampering the signal, and fully ensure the safety and reliability of the wireless optical communication system. BRIEF DESCRIPTION OF DRAWINGS
[0047] In order to make the content of the present application more easily understood, the present application is further described in detail below according to specific embodiments of the present application and in conjunction with the accompanying drawings, in which:
[0048] Figure 1 A wireless optical communication physical layer authentication system model provided by the present application is shown in the figure.
[0049] Figure 2 A wireless optical communication physical layer authentication system structure provided by the present application is shown in the figure.
[0050] Figure 3 A wireless optical communication physical layer authentication method provided by the present application is shown in the figure.
[0051] Figure 4 The influence of the position distance between a replay attacker and a legal transmitting end on the authentication verification statistical quantity distribution of a receiver when the power allocation factor is different is shown in the figure. Wherein, Figure 4 (a) in the figure is the authentication verification statistical quantity distribution of a receiver when the position distance between an attacker and a legal transmitting end is 0.05. Figure 4 (b) in the figure is the authentication verification statistical quantity distribution of a receiver when the position distance between an attacker and a legal transmitting end is 0.1.
[0052] Figure 5 The false detection probability of the wireless optical communication physical layer authentication method provided by the present application against a replay attack is shown in the figure.
[0053] Figure 6 The false detection probability of the first receiver, the second receiver, the third receiver and the overall control obtained by using the method provided by the present application against a replay attacker is shown in the figure. Wherein, Figure 6 (a) in the figure is the authentication false detection probability of the first receiver against a replay attack, Figure 6 (b) in the figure is the authentication false detection probability of the second receiver against a replay attack, Figure 6 (c) in the figure is the authentication false detection probability of the third receiver against a replay attack, Figure 6 (d) in the figure is the authentication false detection probability of the overall control against a replay attack. DETAILED DESCRIPTION
[0054] The present application is further described below in conjunction with the accompanying drawings and specific embodiments, so that those skilled in the art can better understand the present application and implement it. However, the embodiments are not intended to limit the present application.
[0055] Please refer to Figure 1 , Figure 1 A wireless optical communication physical layer authentication system model provided by the present application is shown in the figure.Figure 2 A wireless optical communication physical layer authentication system structure diagram is shown; the wireless optical communication physical layer authentication system comprises:
[0056] At least three receivers, each receiver comprising:
[0057] A photodetection module for receiving a message transmission request sent by the transmitting end in the handshake phase, converting the message transmission request into a first electrical signal and sending it to the general control; receiving a watermark superimposed signal in the message transmission phase, and converting the watermark superimposed signal into a second electrical signal;
[0058] A ranging module for calculating the first distance and the first channel parameter between the receiver and the transmitting end based on the pilot signal strength in the first electrical signal; calculating the second distance and the second channel parameter between the receiver and the watermark superimposed signal transmitting end based on the pilot signal strength in the second electrical signal;
[0059] A data processing module for obtaining a recovered watermark superimposed signal based on the second electrical signal and the second estimated channel, and obtaining a source signal based on the recovered watermark superimposed signal, and obtaining a residual signal based on the recovered watermark superimposed signal, the source signal and the power allocation factor;
[0060] An authentication module for calculating the upper and lower limits of the authentication threshold of the receiver based on the theoretical authentication test statistic standard Gaussian cumulative distribution function of the receiver, the noise standard deviation of the receiver, the first channel parameter and the first distance; generating an expected watermark based on the key sent by the general control, the encryption function for generating the watermark and the source signal, and calculating the actual authentication test statistic of the receiver based on the expected watermark, the residual signal, the second channel parameter and the second distance;
[0061] A general control in communication connection with each receiver and the transmitting end, comprising:
[0062] A key update storage and watermark superimposition setting module for generating a key and an encryption function for generating a watermark based on the first electrical signal, and sending the key and the encryption function for generating the watermark to each receiver and the transmitting end;
[0063] A decision module for calculating the authentication parameter of each receiver based on the actual authentication test statistic and the upper and lower limits of the authentication threshold of the receiver, and determining whether the watermark superimposed signal transmitting end is legal based on the authentication parameters of all receivers.
[0064] The wireless optical communication physical layer authentication system provided in the application, in a handshake stage, converts a message transmission request sent by a transmitting end into a first electrical signal by a receiver, and obtains a first distance between the current transmitting end and the receiver and a first channel parameter by using a ranging module; in a signal transmission stage, the receiver converts a received watermark superimposed signal into a second electrical signal, and obtains a second distance between the receiver and a watermark superimposed signal transmitting end and a second channel parameter; at the same time, the receiver obtains a recovered watermark superimposed signal, a source signal and a residual signal based on the received watermark superimposed signal and a second estimated channel, generates an expected watermark based on a key, an encryption function for generating a watermark and the source signal, and calculates an actual authentication test statistic of the receiver based on the expected watermark, the residual signal, the second channel parameter and the second distance, and finally calculates an upper and lower limit of an authentication threshold of the receiver based on a theoretical authentication test statistic standard Gaussian cumulative distribution function of the receiver, a noise standard deviation of the receiver, the first channel parameter and the first distance; since the actual authentication test statistic of the receiver contains not only distance information between the watermark superimposed signal transmitting end and the receiver, but also the residual signal and the expected watermark, and the upper and lower limits of the authentication threshold contain distance information between the receiver and the transmitting end, finally, the total control obtains the authentication parameter of the receiver for the transmitting end by judging whether the actual authentication test statistic of each receiver is within the authentication threshold range, since at least three reference points are needed in the optical wireless positioning system to determine the position of the transmitting end in a two-dimensional plane, therefore, the total control can accurately identify the mimic attack of the tampered signal and the replay attack of the signal without tampering by fusing the authentication parameters of at least three receivers and checking the authentication test statistic of the fused position information and watermark information.
[0065] For example, when the number of receivers is less than 3, if the watermark superimposed signal transmitting end and the transmitting end are located on the circumference of a circle with the receiver as the center, the calculated first distance and second distance are the same, which causes the receiver to be unable to determine whether the position of the transmitting end has changed, and thus unable to determine whether the watermark superimposed signal transmitting end is a legal transmitting end, therefore, at least three receivers are needed to fuse the calculated position information to determine the specific position of the transmitting end; in addition, each receiver restores the received signal to obtain the expected watermark to determine whether there is a mimic attack, and the more the number of receivers, the more accurate the identification result of the mimic attack.
[0066] Specifically, the transmitting end comprises:
[0067] A source for generating a source signal;
[0068] An encoding and modulation module for processing the source signal;
[0069] A key update storage and watermark superimposition setting module for obtaining a key generated by a receiver total control and an encryption function for generating a watermark.
[0070] a watermark generation module configured to generate a watermark signal based on a key and a processed source signal by using an encryption function for generating a watermark, and make the watermark signal consistent with the length of the processed source signal;
[0071] a watermark superposition module configured to superimpose the watermark signal on the processed source signal according to a power allocation factor to obtain a watermark superposition signal;
[0072] a light source driving module configured to convert the modulation signal into an electrical signal that can drive the light source to work;
[0073] a light source configured to convert the electrical signal into a light signal for emission.
[0074] Specifically, the calculation formula of the actual authentication verification statistic of the receiver is:
[0075]
[0076]
[0077] wherein, represents the actual authentication verification statistic of the i th receiver; D i ′ represents the second distance between the i th receiver and the watermark superposition signal emission end; h i ′ represents the second channel parameter between the i th receiver and the watermark superposition signal emission end; represents the expected watermark generated by the i th receiver; (·) H represents the conjugate transpose; ρ t represents the power allocation factor of the watermark superposition signal power on the watermark signal; ρ s represents the power allocation factor of the watermark superposition signal power on the message signal; ρ t ≤ 1, ρ s ≥ 0, ρ t 2 + ρ s 2 = 1; represents the watermark superposition signal recovered by the i th receiver; represents the source signal obtained by the i th receiver; r i represents the residual signal obtained by the i th receiver; i ∈ [1, m], and m represents the number of receivers.
[0078] The calculation formula of the upper limit of the authentication threshold of the receiver is:
[0079]
[0080] wherein, represents the upper bound of authentication threshold of the i-th receiver; θ i represents the theoretical authentication test statistic of the i-th receiver; represents the standard Gaussian cumulative distribution function of the theoretical authentication test statistic of the i-th receiver; D i represents the first distance of the i-th receiver to the transmitter; h i represents the first channel parameter of the i-th receiver to the transmitter; L represents the length of the watermark superimposed signal; represents the upper bound of false alarm probability of the i-th receiver; σ wi represents the noise standard deviation of the i-th receiver; ρ t represents the power allocation factor of the watermark superimposed signal power on the watermark signal; i∈[1,m], m represents the number of receivers;
[0081] The calculation formula of the lower bound of the authentication threshold of the receiver is:
[0082]
[0083] wherein, represents the lower bound of the authentication threshold of the i-th receiver.
[0084] The authentication parameter of the receiver is represented as:
[0085]
[0086] wherein, δ i represents the authentication parameter of the i-th receiver; represents the actual authentication test statistic of the i-th receiver; represents the upper bound of the authentication threshold of the i-th receiver; represents the lower bound of the authentication threshold of the i-th receiver; i∈[1,m], m represents the number of receivers.
[0087] Further, the total control determines whether the watermark superimposed signal transmitter is legal based on the authentication parameters of all receivers, which includes:
[0088] If the product of the authentication parameters of all receivers is 1, it is determined that the watermark superimposed signal transmitter is a legal transmitter;
[0089] If the product of the authentication parameters of all receivers is 0, it is determined that the watermark superimposed signal transmitter is an illegal transmitter.
[0090] The calculation formula of the product of the authentication parameters of all receivers is:
[0091]
[0092] wherein, δ represents the product of the authentication parameters of all receivers.
[0093] Specifically, as the number of receivers increases, since each receiver processes and restores the received signal, it can be more accurately determined whether the signal is tampered with, increasing the accuracy of the authentication result, but also increasing the complexity of the authentication process, reducing the authentication efficiency, therefore, when the number of receivers is greater than 3, the total control can also select the energy saving mode or the security mode, specifically, the energy saving mode is to control only 3 receivers to participate in authentication, and the security mode is to control all receivers to participate in authentication, in order to increase the accuracy of the authentication result.
[0094] Optionally, in some embodiments of the present application, the total control further comprises:
[0095] The authentication receiver selection module is configured to select n receivers closest to the transmitter as authentication receivers based on the first distances of the receivers to the transmitter; wherein 3≤n≤m, m represents the number of receivers.
[0096] The authentication enabling module is configured to control the n authentication receivers to receive the watermark superimposed signal.
[0097] Since the distance between the transmitter and the receiver will affect the accuracy of signal transmission, in the embodiments of the present application, the 3 receivers closest to the transmitter are selected to participate in authentication, which can save resources and improve authentication efficiency, while also taking into account the accuracy of the authentication result.
[0098] Optionally, in order to further improve the security of wireless optical communication, the key update storage and watermark superposition setting module in the total control updates the key and the encryption function for generating the watermark every preset time, and sends the updated key and the encryption function for generating the watermark to each receiver and the transmitter, so that the transmitter generates the watermark superimposed signal based on the updated key and the encryption function for generating the watermark.
[0099] In some embodiments of the present application, the encryption function for generating the watermark can select to use a hash function, and at the same time set a power allocation factor of the watermark superposition according to security, concealment and robustness, to ensure the effectiveness of the authentication watermark in the wireless optical communication environment, while not causing too much impact on the signal quality.
[0100] For example, according to the update interval of the key and the encryption function for generating the watermark, the key update storage and watermark superimposition module can be divided into a saving type, a regular type and an enhanced type; the saving type key update storage and watermark superimposition module updates the key and the encryption function for generating the watermark once every week, the watermark superimposition power allocation factor is set to 0.05, the regular type key update storage and watermark superimposition module updates the key and the encryption function for generating the watermark once every day, the watermark superimposition power allocation factor is set to 0.1, and the enhanced type key update storage and watermark superimposition module updates the key and the encryption function for generating the watermark once every hour, the watermark superimposition power allocation factor is set to 0.2.
[0101] Optionally, the total control further comprises a signal sink, configured to control each receiver to reject the signal sent by the transmitter when it is determined that the transmitter is an illegal transmitter.
[0102] Optionally, in some embodiments of the present application, each receiver further comprises a ranging compensation calibration module, configured to calibrate the first distance and the second distance between the receiver and the transmitter by using a ranging compensation algorithm.
[0103] By using the algorithm to compensate the ranging error caused by environmental factors, and using the mean smoothing method to process the signal strength indicator, the measurement fluctuation is reduced, and considering that the attacker may not use the standard transmission power, but modify the transmission power to fake the position information, therefore, using the ranging compensation algorithm to use the time difference of arrival to check the position information can further improve the accuracy of the measured position information.
[0104] Based on the above wireless optical communication physical layer authentication system, the embodiments of the present application further provide a wireless optical communication physical layer authentication method, as shown in Figure 3 The authentication method specifically includes:
[0105] S10: In the handshake phase, each receiver receives the message transmission request sent by the transmitter, converts the message transmission request into a first electrical signal and sends it to the total control; each receiver calculates the first distance and the first channel parameter between the receiver and the transmitter based on the pilot signal strength in the first electrical signal.
[0106] Specifically, the handshake phase is considered as a safe communication phase.
[0107] S20: The total control generates a key and an encryption function for generating a watermark based on the first electrical signal, and sends the key and the encryption function for generating the watermark to each receiver and the transmitter.
[0108] Specifically, the receiving end total control uses the existing upper layer protocol authentication scheme to authenticate the message transmission request from the transmitting end, and if the authentication is successful, sends a message transmission permission Acknowledge (ACK) to the transmitting end, and generates a key and an encryption function for generating a watermark;
[0109] The specific process of the transmitting end obtaining the watermark superimposed signal based on the key and the encryption function for generating a watermark includes:
[0110] The source of the transmitting end generates a source signal m and performs corresponding encoding and modulation to obtain a signal s, obtains a hash value S = f(m, k) of the source signal and the key k, converts the hash value S from a string to data of the same standard as the message, and performs corresponding modulation to obtain a watermark signal t;
[0111] The watermark superimposed power is set according to the watermark superimposed power distribution factor negotiated in the handshake phase, and the watermark superimposed signal x is generated based on the signal s, the watermark signal t, and the watermark superimposed power distribution factor, x = p s s + p t t, wherein p t represents the power distribution factor of the watermark superimposed signal power on the watermark signal; p s represents the power distribution factor of the watermark superimposed signal power on the message signal; p t ≤ 1, p s ≥ 0, p t 2 s 2 = 1.
[0112] The light source driving module converts the watermark superimposed signal x into an electrical signal that can make the light source work, and converts the electrical signal into a light signal through the light source for transmission.
[0113] S30: In the message transmission phase, each receiver receives the watermark superimposed signal, converts the watermark superimposed signal into a second electrical signal, and calculates a second distance and a second channel parameter between the receiver and the transmitting end of the watermark superimposed signal based on the pilot signal strength in the second electrical signal.
[0114] S40: Each receiver obtains a recovered watermark superimposed signal based on the second electrical signal and the second estimated channel, and obtains a source signal based on the recovered watermark superimposed signal, obtains a residual signal based on the recovered watermark superimposed signal, the source signal, and the power distribution factor.
[0115] Specifically, the receiver can obtain the second channel parameter by the pilot signal in the transmitted signal and the pilot signal in the received signal, and then obtain the recovered watermark superimposed signal based on the second channel parameter and the watermark superimposed signal part in the received signal, and finally obtain the source signal based on the recovered watermark superimposed signal and the corresponding decoding and demodulation mode, which is the signal without watermark transmitted by the transmitter and recovered by the receiver based on the received signal.
[0116]
[0117] wherein, represents the watermark superimposed signal recovered by the i th receiver; y i represents the watermark superimposed signal received by the i th receiver; h i ′ represents the second channel parameter obtained by the i th receiver.
[0118] S50: Each receiver calculates the authentication threshold upper and lower limits of the receiver based on the theoretical authentication test statistic standard Gaussian cumulative distribution function, noise standard deviation, first channel parameter and first distance; generates the expected watermark based on the key transmitted by the total controller, encryption function for generating watermark and source signal, and calculates the actual authentication test statistic of the receiver based on the expected watermark, residual signal, second channel parameter and second distance.
[0119] S60: The total controller calculates the authentication parameter of each receiver based on the actual authentication test statistic and authentication threshold upper and lower limits of the receiver, and determines whether the watermark superimposed signal transmitter is legal based on the authentication parameters of all receivers.
[0120] In order to evaluate the performance of the receiving end and the authentication method of the wireless optical communication physical layer authentication system provided in the present application, the present application considers a specific two-way indoor wireless optical scene physical layer authentication system, data is transmitted through infrared light in the uplink channel, and visible light is used for illumination and communication in the downlink channel. The room size is 5m x 5m x 3m, there are 3 receivers at the receiving end, receiver-1 is located at (1, 2, 3), receiver-2 is located at (4, 2, 3), and receiver-3 is located at (2, 4, 3). The light source output power of the transmitter is 1W, the message length is 1024, the SHA-256 encryption function is used, the authentication mode is selected as the security mode, it is assumed that the position of the legal transmitter is located at (3, 1, 0.85), the illegal transmitter is located at any position in the same plane as the legal transmitter, the illegal transmitter (i.e. attacker) will launch an impersonation attack and a replay attack, and the upper limit of the acceptable false alarm probability of each receiver is set to 0.01.
[0121] The calculation formula of the theoretical false detection probability of the final impersonation attack and replay attack is:
[0122]
[0123] wherein, denotes the theoretical false alarm probability of an impersonation attack; denotes the theoretical false alarm probability of an impersonation attack for the i-th receiver; denotes the second distance of the impersonation attacker from the i-th receiver; denotes the theoretical false alarm probability of a replay attack; denotes the theoretical false alarm probability of a replay attack for the i-th receiver; denotes the second distance of the replay attacker from the i-th receiver; denotes the second channel parameter of the i-th receiver from the replay attacker.
[0124] To compare the effects of different power allocation and the distance between the replay attacker and the legitimate transmitter on the distribution of the authentication test statistic, the upper limit of the acceptable false alarm probability on the receiver is set to 0.01, and the corresponding threshold is obtained. Figure 4 The figure shows the effect of the distance between the replay attacker and the legitimate transmitter on the distribution of the authentication test statistic of the receiver when the power allocation factor is different; wherein, Figure 4 (a) in the figure shows the effect of the distance between the attacker and the legitimate transmitter on the distribution of the authentication test statistic of the receiver when the power allocation factor is 0.05, Figure 4 (b) in the figure shows the effect of the distance between the attacker and the legitimate transmitter on the distribution of the authentication test statistic of the receiver when the power allocation factor is 0.1. t When ρ = 0.05, the impersonation attacker is located at (3, 1, 0.85), and the replay attacker is located at (3, 4, 0.85); ρ t When ρ = 0.1, the impersonation attacker is located at (3, 1, 0.85), and the replay attacker is located at (3, 1.5, 0.85). It can be seen that the authentication test statistic distribution obtained by 100,000 times of Monte Carlo simulation is consistent with the theoretical distribution, showing a Gaussian distribution, the mean of the test statistic of the impersonation attacker is 0, and the closer the position of the replay attacker to Alice, the closer the statistic distribution of the two.
[0125] The authentication performance of the method provided in the application against impersonation attacks and replay attacks is tested: the position of the illegal transmitter is (x, 1, 0.85), and as x changes, the false alarm probability is as shown in Figure 5 When ρ t When ρ = 0.05, when the distance between the replay attacker and the legitimate transmitter is greater than 0.5 m, the false alarm probability can be close to 0%. When ρ t=0.1, when the distance between the replay attacker and the legitimate transmitter is greater than 0.3m, the false detection probability can reach nearly 0%. In addition, for imitation attacks, the method provided by this application can achieve 100% authentication accuracy.
[0126] Setting ρ t = 0.1, the verification is performed within the plane where the legitimate transmitter is located. The authentication performance of the method provided by this application against replay attacks is: the illegal transmitter position is (x, y, 0.85), as x and y change, the false detection probability is as follows: Figure 6 As shown. Figure 6 As shown in (a), (b), and (c), when the replay attacker is located on a concentric circle centered on the projection of receiver-i in the plane, receiver-i cannot identify the replay attack. However, when the receiver's authentication results are jointly executed by the decision module provided by the present application through the master control, when the distance between the legitimate transmitter and the replay attacker exceeds 0.2m, the false detection probability is less than 5%, as shown in Figure 1. Figure 6 As shown in (d) in .
[0127] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0128] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0129] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1the function specified in the one or more blocks.
[0130] These computer program instructions can also be loaded into computer or other programmable data processing devices, so that a series of operation steps are performed on the computer or other programmable data processing devices to generate computer-implemented processes, thus the instructions executed on the computer or other programmable data processing devices provide processes for implementing the flow Figure 1 the flow or flows and / or blocks Figure 1 the steps of the function specified in the one or more blocks.
[0131] Obviously, the above embodiments are only examples for clearly illustrating the present application, and are not intended to limit the implementation. Based on the above description, other different forms of changes or variations can also be made by those skilled in the art. Here, all the implementations are not required to be exhausted, and the obvious changes or variations derived therefrom are still within the protection scope of the present application.
Claims
1. A wireless optical communication physical layer authentication system, characterized in that: include: At least three receivers, each receiver comprising: The photoelectric detection module is used to receive a message transmission request sent by the transmitting end during the handshake phase, convert the message transmission request into a first electrical signal and send it to the master control; receive a watermark superimposed signal during the message transmission phase, and convert the watermark superimposed signal into a second electrical signal; a ranging module, configured to calculate a first distance between a receiver and a transmitting end and a first channel parameter based on the pilot signal strength in the first electrical signal; and calculate a second distance between the receiver and a transmitting end of a watermark superimposed signal and a second channel parameter based on the pilot signal strength in the second electrical signal; a data processing module, configured to obtain a restored watermark superimposed signal based on the second electrical signal and the second channel parameter, obtain a source signal based on the restored watermark superimposed signal, and obtain a residual signal based on the restored watermark superimposed signal, the source signal, and a power allocation factor; an authentication module, configured to calculate upper and lower limits of the authentication threshold of the receiver based on a standard Gaussian cumulative distribution function of a theoretical authentication test statistic of the receiver, a noise standard deviation of the receiver, the first channel parameter, and the first distance; generate an expected watermark based on a key sent by the master control, an encryption function for generating a watermark, and the source signal; and calculate an actual authentication test statistic of the receiver based on the expected watermark, the residual signal, the second channel parameter, and the second distance; The master control communicates with each receiver and transmitter, including: a key update storage and watermark superposition setting module, configured to generate a key and an encryption function for generating a watermark based on the first electrical signal, and to send the key and the encryption function for generating the watermark to each receiver and transmitter; The decision module is used to calculate the authentication parameters of each receiver based on the actual authentication test statistics and the upper and lower limits of the authentication threshold, and to determine whether the watermark superimposed signal transmitter is legal based on the authentication parameters of all receivers.
2. The wireless optical communication physical layer authentication system according to claim 1, characterized in that: The actual authentication test statistic for the receiver is calculated as: , , in, Indicates the The actual certification test statistic for each receiver; Indicates the a second distance between a receiver and a transmitting end of a watermark superimposed signal; Indicates the The second channel parameters of the receiver and the watermark superposition signal transmitter; Indicates the The expected watermark generated by each receiver; represents the conjugate transpose; The power allocation factor of the watermark superimposed signal power on the watermark signal; The power allocation factor of the watermark superimposed signal power on the message signal; , , ; Indicates the The watermark superimposed signal recovered by a receiver; Indicates the The source signal is obtained by the receiver; Indicates the The residual signal obtained by the receiver; , Indicates the number of receivers.
3. The wireless optical communication physical layer authentication system according to claim 1, wherein: The calculation formula for the upper authentication threshold of the receiver is: , , in, Indicates the The upper limit of the authentication threshold for each receiver; Indicates the Theoretical validation test statistics for receivers; Indicates the Theoretical validation test statistic for each receiver is the standard Gaussian cumulative distribution function; Indicates the A first distance between a receiver and a transmitter; Indicates the First channel parameters of a receiver and a transmitter; Indicates the length of the watermark superimposed signal; Indicates the The upper limit of the false alarm probability of each receiver; Indicates the The standard deviation of the noise of each receiver; The power allocation factor of the watermark superimposed signal power on the watermark signal; , Indicates the number of receivers; The calculation formula for the receiver's authentication lower threshold is: , in, Indicates the The lower authentication threshold for each receiver.
4. The wireless optical communication physical layer authentication system according to claim 1, wherein: The authentication parameters of the receiver are expressed as: , in, Indicates the authentication parameters for each receiver; Indicates the The actual certification test statistic for each receiver; Indicates the The upper limit of the authentication threshold for each receiver; Indicates the The lower authentication threshold for each receiver; , Indicates the number of receivers.
5. The wireless optical communication physical layer authentication system according to claim 1, wherein: The authentication parameters of all receivers are used to determine whether the transmitter of the watermark superimposed signal is legitimate, including: If the cumulative product of the authentication parameters of all receivers is 1, the transmitter of the watermark superimposed signal is determined to be a legitimate transmitter; If the cumulative product of the authentication parameters of all receivers is 0, the watermark superimposed signal transmitter is determined to be an illegal transmitter.
6. The wireless optical communication physical layer authentication system according to claim 1, characterized in that: When the number of receivers is greater than 3, the master control further includes: The authentication receiver selection module is used to select n receivers closest to the transmitter as authentication receivers based on the first distance between each receiver and the transmitter; wherein, , Indicates the number of receivers; The authentication enabling module is used to control n authentication receivers to receive the watermark superimposed signal.
7. The wireless optical communication physical layer authentication system according to claim 1, characterized in that: The key update storage and watermark superposition setting module updates the key and the encryption function for generating the watermark at preset intervals, and sends the updated key and the encryption function for generating the watermark to each receiver and transmitter.
8. The wireless optical communication physical layer authentication system according to claim 1, wherein: The master control also includes a sink, which is used to control each receiver to refuse to receive the watermark superimposed signal when it is determined that the watermark superimposed signal transmitting end is an illegal transmitting end.
9. The wireless optical communication physical layer authentication system according to claim 1, wherein: Each receiver further includes a distance compensation calibration module, configured to calibrate the first distance and the second distance using a distance compensation algorithm.
10. A wireless optical communication physical layer authentication method, characterized in that: The wireless optical communication physical layer authentication system according to any one of claims 1 to 9 comprises: During the handshake phase, each receiver receives a message transmission request sent by the transmitter, converts the message transmission request into a first electrical signal, and sends the signal to the master control; each receiver calculates a first distance and a first channel parameter between the receiver and the transmitter based on the pilot signal strength in the first electrical signal; The master control generates a key and an encryption function for generating a watermark based on the first electrical signal, and sends the key and the encryption function for generating the watermark to each receiver and transmitter; During the message transmission phase, each receiver receives the watermark superimposed signal and converts the watermark superimposed signal into a second electrical signal; and calculates a second distance and a second channel parameter between the receiver and the transmitter of the watermark superimposed signal based on the pilot signal strength in the second electrical signal; Each receiver obtains a restored watermark superimposed signal based on the second electrical signal and the second channel parameter, obtains a source signal based on the restored watermark superimposed signal, and obtains a residual signal based on the restored watermark superimposed signal, the source signal, and a power allocation factor; Each receiver calculates an upper and lower limit of an authentication threshold of the receiver based on its theoretical authentication test statistic standard Gaussian cumulative distribution function, noise standard deviation, first channel parameter, and first distance; generates an expected watermark based on a key sent by the master control, an encryption function for generating a watermark, and a source signal, and calculates an actual authentication test statistic of the receiver based on the expected watermark, a residual signal, a second channel parameter, and a second distance; The master control calculates the authentication parameters of each receiver based on the actual authentication test statistics and the upper and lower limits of the authentication threshold, and determines whether the watermark superimposed signal transmitter is legal based on the authentication parameters of all receivers.
Citation Information
Patent Citations
Optical feedback for visual recognition authentication
CN110036391A
Optical communication device, optical communication system and method
CN114223155A