Reference signal fraud attack detection method, device and electronic equipment

By utilizing the null space projection technology of the channel covariance matrix in the 5G NR communication environment to calculate signal characteristics and set detection thresholds, the problems of insufficient accuracy and robustness in fraud attack detection in existing technologies are solved, and efficient and accurate fraud attack identification is achieved.

CN119521225BActive Publication Date: 2025-09-30XIDIAN UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411531381.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-30
Publication Date
2025-09-30
Estimated Expiration
2044-10-30

AI Technical Summary

Technical Problem

Existing reference signal spoofing attack detection methods have deficiencies in detection accuracy and robustness, making it difficult to effectively identify spoofing attacks in 5G NR communication environments. Furthermore, they have high implementation costs and long training times.

Method used

By using the channel covariance matrix stored in the base station to obtain the null space, multiple consecutive instantaneous channel characteristics of the received signal are calculated, and the projection of these characteristics in the null space is obtained. The detection threshold is determined using the residual noise energy and false alarm probability to determine whether there is a fraudulent attack signal in the received signal.

Benefits of technology

The separation accuracy of the signal subspaces of legitimate users and fraud attackers is improved, achieving more accurate and robust fraud attack detection without modifying the communication protocol and high startup costs, making it easy to implement in engineering.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119521225B_ABST
    Figure CN119521225B_ABST
Patent Text Reader

Abstract

The present invention discloses a reference signal fraud attack detection method, device and electronic device. The method includes obtaining the null space using the channel covariance matrix stored in the base station; the channel covariance matrix is ​​the channel covariance matrix of the SRS signal; calculating multiple consecutive instantaneous channel characteristics of the received signal, and obtaining the projections of the multiple instantaneous channel characteristics in the null space; if the residual noise energy existing in the multiple projections is greater than a predetermined detection threshold, it is determined that an SRS attack signal exists in the received signal; the detection threshold is determined according to a set false alarm probability. By introducing the null space of the channel covariance matrix with a low-rank structure, the separation accuracy of the user and attacker signal subspaces can be effectively improved, and attack detection is performed based on a sequential approach focusing on the energy mutation after the null space projection, so that the detection results are more accurate and robust.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of signal processing technology, and in particular relates to a reference signal fraud attack detection method, device and electronic equipment. Background Art

[0002] Reference signal spoofing attacks targeting communication protocols pose a serious threat to user privacy, network security, and even national security. Effective reference signal spoofing attack detection methods are crucial for maintaining the stable operation and information security of communication systems. Reference signal spoofing attack detection methods can promptly defend against attacks such as man-in-the-middle and denial-of-service, protecting communication content from eavesdropping, tampering, or forgery, ensuring the reliability of location data and maintaining the integrity and confidentiality of network data. Therefore, researching effective reference signal spoofing attack detection methods is of great application value in building a more secure and reliable fifth-generation (5G) new wireless (NR) communication environment, protecting user privacy, and national security.

[0003] Currently, reference signal fraud attack detection methods are mainly divided into two categories: methods based on randomness and auxiliary transmission, and methods based on statistical characteristics.

[0004] Methods based on randomness and assisted transmission are inherently based on proprietary communication protocols. The technical specifications for physical layer channels and signals in 5G NR have already been standardized by the 3rd Generation Partnership Project (3GPP) committee, making them difficult to adopt in practice. Furthermore, assisted transmission methods have high startup costs and training time, making them difficult to implement in practice. For example, methods based on dual-channel training and bidirectional training require the base station to make decisions based on all observations generated by the introduction of assisted transmission.

[0005] Current statistical feature-based methods are not robust in distinguishing fraudulent attacks from other causes, such as fluctuations caused by legitimate communications. Furthermore, these methods rely on prior information about the attacker to select decision thresholds to distinguish between attacks and normal states. However, potential malicious attackers often deliberately disguise information to deceive and confuse users, making it difficult to accurately identify and obtain such statistical data. Furthermore, methods for detecting abnormal traffic based on upper-layer statistical features track the percentage of transmission collisions at the upper layer and detect attacks when the percentage exceeds a certain threshold. However, this approach results in unacceptable detection delays.

[0006] Therefore, how to provide a reference signal fraud attack detection method that is more accurate, more robust, and easier to implement has become an important issue. Summary of the Invention

[0007] In order to solve the above problems existing in the prior art, the present invention provides a reference signal fraud attack detection method, device and electronic equipment.

[0008] The technical problem to be solved by the present invention is achieved through the following technical solutions:

[0009] In a first aspect, the present invention provides a reference signal fraud attack detection method, the reference signal fraud attack detection method comprising:

[0010] Utilizing the channel covariance matrix stored in the base station to obtain the null space; the channel covariance matrix is ​​the channel covariance matrix of the SRS signal;

[0011] Calculating a plurality of continuous instantaneous channel features of the received signal, and obtaining projections of the plurality of instantaneous channel features in the null space;

[0012] If the residual noise energy in the multiple projections is greater than a predetermined detection threshold, it is determined that an SRS attack signal exists in the received signal; the detection threshold is determined according to a set false alarm probability.

[0013] Optionally, the detection threshold is predetermined by:

[0014] Acquire SRS residual noise energy of the SRS signal in the null space;

[0015] A test statistic is obtained using the central limit theorem and multiple sample signals; the sample signals include an SRS sample signal and an SRS attack sample signal;

[0016] determining a normal distribution of the SRS signal according to the SRS residual noise energy and the test statistic;

[0017] The detection threshold is determined according to the definition of the right-tail Q function of the normal distribution and the false alarm probability.

[0018] Optionally, determining the detection threshold according to the definition of the right-tail Q function of the normal distribution and the false alarm probability includes:

[0019]

[0020] Wherein, η represents the detection threshold; Q represents the right tail Q function of the normal distribution; P fa represents the false alarm probability; σ 2 represents the Gaussian white noise variance of the base station; τ p represents the length of the sample signal; represents the SRS transmission power of the kth user; L represents the number of sample signals; and M represents the number of antennas of the base station.

[0021] Optionally, the test statistic is:

[0022]

[0023] Wherein, l=1, 2, ..., L, L represents the number of sample signals; y np represents the projection of the instantaneous channel characteristics into the null space.

[0024] Optionally, obtaining projections of the multiple instantaneous channel features in the null space includes:

[0025]

[0026] in, An assumption that no SRS attack exists in the received signal; represents the assumption that there is an SRS attack in the received signal; np represents the projection of the instantaneous channel characteristics in the null space; VV H Represents instantaneous channel characteristics; N represents the number of attackers transmitting SRS attack signals; θ n,k represents the power allocation coefficient of the nth attacker attacking the kth user; represents the attack power of the nth attacker; represents the SRS transmission power of the kth user; h A,n represents the channel model between the base station and the nth attacker; w B,k represents the equivalent noise vector; np-detector represents the detector after the null space projection.

[0027] In a second aspect, the present invention provides a reference signal fraud attack detection device, the reference signal fraud attack detection device comprising:

[0028] A null space obtaining module, configured to obtain the null space using a channel covariance matrix stored in the base station; the channel covariance matrix is ​​the channel covariance matrix of the SRS signal;

[0029] A projection acquisition module, configured to calculate a plurality of continuous instantaneous channel features of a received signal and obtain projections of the plurality of instantaneous channel features in the null space;

[0030] The SRS attack judgment module is used to determine that an SRS attack signal exists in the received signal if the residual noise energy in the multiple projections is greater than a predetermined detection threshold; the detection threshold is determined according to a set false alarm probability.

[0031] Optionally, the detection threshold is predetermined by:

[0032] Acquire SRS residual noise energy of the SRS signal in the null space;

[0033] A test statistic is obtained using the central limit theorem and multiple sample signals; the sample signals include an SRS sample signal and an SRS attack sample signal;

[0034] determining a normal distribution of the SRS signal according to the SRS residual noise energy and the test statistic;

[0035] The detection threshold is determined according to the definition of the right-tail Q function of the normal distribution and the false alarm probability.

[0036] Optionally, determining the detection threshold according to a definition of the right-tail Q function of the normal distribution and a false alarm probability includes:

[0037]

[0038] Wherein, η represents the detection threshold; Q represents the right tail Q function of the normal distribution; P fa represents the false alarm probability; σ 2 represents the Gaussian white noise variance of the base station; τ p represents the length of the sample signal; represents the SRS transmission power of the kth user; L represents the number of sample signals; and M represents the number of antennas of the base station.

[0039] Optionally, the test statistic is:

[0040]

[0041] Wherein, l=1, 2, ..., L, L represents the number of sample signals; y np represents the projection of the instantaneous channel characteristics into the null space.

[0042] Optionally, a projection acquisition module obtains projections of multiple instantaneous channel features in the null space, including:

[0043]

[0044] in, An assumption that no SRS attack exists in the received signal; represents the assumption that there is an SRS attack in the received signal; np represents the projection of the instantaneous channel characteristics in the null space; VV H Represents instantaneous channel characteristics; N represents the number of attackers transmitting SRS attack signals; θ n,k represents the power allocation coefficient of the nth attacker attacking the kth user; represents the attack power of the nth attacker; represents the SRS transmission power of the kth user; h A,n represents the channel model between the base station and the nth attacker; w B,k represents the equivalent noise vector; np-detector represents the detector after the null space projection.

[0045] In a third aspect, the present invention provides an electronic device comprising a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other via the communication bus;

[0046] Memory for storing computer programs;

[0047] The processor is configured to implement the method steps described in any one of the above-mentioned reference signal fraud attack detection methods when executing the program stored in the memory.

[0048] In a fourth aspect, the present invention provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method steps described in any of the above-mentioned reference signal fraud attack detection methods are implemented.

[0049] The present invention provides a reference signal fraud attack detection method that can effectively improve the separation accuracy of the signal subspaces of legitimate users and fraud attackers by introducing the null space of the channel covariance matrix with a low-rank structure, thereby obtaining multiple continuous instantaneous channel characteristics of the received signal and obtaining the projections of multiple instantaneous channel characteristics in the null space. In addition, in the present invention, attack detection is performed based on a sequential approach focusing on the energy mutation after the null space projection. By calculating multiple continuous instantaneous channel characteristics of the received signal and obtaining the projections of multiple instantaneous channel characteristics in the null space, when the residual noise energy present in the multiple projections is greater than a predetermined detection threshold, it is determined that an SRS attack signal exists in the received signal, making the detection result more accurate and robust.

[0050] Compared with existing fraud attack detection methods, the reference signal fraud attack detection method provided by the present invention does not require modification of the communication protocol and does not require high startup costs and training time, and is easier to implement in engineering.

[0051] The present invention will be further described in detail below with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0052] Figure 11 is a flow chart of a reference signal fraud attack detection method provided by an embodiment of the present invention;

[0053] Figure 2 Schematic diagram of a communication scenario in which an SRS fraud attack occurs, provided by an embodiment of the present invention;

[0054] Figure 3 This is a schematic diagram comparing the changes in residual noise energy under different spatial feature overlaps;

[0055] Figure 4 2 is a schematic diagram of visualization results of detection performance of the reference signal fraud attack detection method provided by an embodiment of the present invention;

[0056] Figure 5 1 is a schematic structural diagram of a reference signal fraud attack detection device provided by an embodiment of the present invention;

[0057] Figure 6 It is a structural diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0058] The present invention will be further described in detail below with reference to specific examples, but the embodiments of the present invention are not limited thereto.

[0059] In order to solve the problems of high implementation cost and poor robustness of the existing SRS signal fraud attack detection method, the embodiment of the present invention provides a reference signal fraud attack detection method. Figure 1 , Figure 1 This is a flow chart of a reference signal fraud attack detection method provided by an embodiment of the present invention, which specifically includes the following steps:

[0060] Step S101 : Calculate the null space using the channel covariance matrix stored in the base station; the channel covariance matrix is ​​the channel covariance matrix of the SRS signal.

[0061] In an embodiment of the present invention, under normal circumstances, an SRS (Sounding Reference Signal) fraud attack does not exist at the beginning. For example, when an attacker exists at the beginning and then stops, the base station uses the stored channel covariance matrix to perform null space projection. Once the energy of the projection drops suddenly, it also indicates that an SRS fraud attack has occurred before. In order to ensure the efficiency of the attack, the attacker often attacks after the legal transmission begins. Therefore, when the collaborative SRS fraud does not exist at the beginning, the channel covariance matrix of the SRS signal in the non-attack state stored by the base station can be used to obtain the null space of the projection. Among them, the channel covariance matrix can be used to describe the statistical characteristics of the channel.

[0062] In the embodiment of the present invention, the channel covariance matrix C of the SRS signal in the non-SRS attack state stored at the base station is decomposed to obtain orthogonal matrices U and V:

[0063]

[0064] Where, the superscript H represents the conjugate transpose; λ r represents the rth channel feature in the channel covariance matrix; r represents the rank of the channel covariance matrix; diag(·) represents the diagonal matrix formed by the main eigenvalues ​​of the channel covariance matrix.

[0065] When the rank of the channel covariance matrix is ​​determined, the null space of the channel covariance matrix of the SRS signal can be obtained.

[0066] Step S102: Calculate a plurality of consecutive instantaneous channel features of the received signal, and obtain projections of the plurality of instantaneous channel features in the null space.

[0067] In the embodiment of the present invention, the received signal includes an SRS signal and / or an SRS attack signal, wherein the SRS signal refers to a legitimate signal sent by a user, and the SRS attack signal refers to a fraudulent signal sent by an attacker.

[0068] See also Figure 2 , Figure 2 This is a schematic diagram of a communication scenario in which an SRS spoofing attack exists, provided by an embodiment of the present invention. In the embodiment of the present invention, a single-cell multi-user communication scenario in time division duplex mode is adopted, which includes a base station configured with M antennas and K legitimate users configured with single antennas.

[0069] Explain the SRS signal. The base station completes channel estimation through the SRS signal transmitted by the user. The SRS signal of the kth user is satisfy Among them, τ p represents the length of the SRS signal, the superscript T represents the transpose operation of the matrix, and the superscript * represents the conjugate operation of the matrix.

[0070] To illustrate the SRS attack signal, N single-antenna attackers coordinate to transmit multi-user SRS signals to interfere with uplink channel estimation training. Because the SRS signal transmission protocol is public, each attacker can synchronize with the base station, obtain system information, and send the same SRS signal to confuse the base station.

[0071] In the embodiment of the present invention, represents the channel model between the base station and the kth user, represents the channel model between the base station and the nth attacker. Specifically, it can be generated by a channel model based on a clustered delay line (CDL-D) model that complies with the 3GPP standard.

[0072] In SRS fraud, each attacker targets all users in the system, so the attack signal is constructed as a linear combination of the SRS signals of all users. Taking the nth attacker as an example, the SRS attack signal It can be expressed as:

[0073]

[0074] Among them, θ n,k represents the power allocation coefficient of the nth attacker attacking the kth user; represents the attack power of the nth attacker; p k represents the SRS signal of the kth user; n=1,2,…,N, N represents the total number of attackers; k=1,2,…,K, K represents the total number of users.

[0075] During the uplink channel training phase, the base station will receive SRS signal combinations from the user and the attacker. The SRS signal combination Y B It can be expressed as:

[0076]

[0077] in, represents the SRS transmission power of the kth user; U represents the power received by the base station that follows the distribution Noise; σ 2 represents the Gaussian white noise variance of the base station.

[0078] In order to obtain the channel estimation result of the kth user, the base station can complete the following preprocessing process based on the existing prior information:

[0079]

[0080] Among them, y B,k represents the SRS signal of the kth user; z B,k Indicates that the kth user follows the distribution The equivalent noise vector of M represents a matrix of all ones.

[0081] Taking the channel quality estimation of the kth user as an example, at the base station, according to y B,k Construct the following binary hypothesis test question about whether or not SRS is fraudulent:

[0082]

[0083] in, It indicates the assumption that there is no SRS fraud attack; Indicates the assumption that there is an SRS spoofing attack. Is subject to distribution The equivalent noise vector of

[0084] In the actually deployed large-scale antenna system, the corresponding channel covariance matrix will extend to a limited space, that is, the channel covariance matrix will exhibit a low-rank property, so the signal subspaces sent by legitimate users and fraudulent attackers can be separated in the angle domain.

[0085] Through the above binary hypothesis test problem, it can be seen that after the null space projection, the projection of the instantaneous channel characteristics of the SRS attack signal into the null space will have more residual noise energy than the projection of the instantaneous channel characteristics of the SRS signal into the null space. That is, the residual noise energy after filtering the null space projection of the instantaneous channel characteristics of the SRS attack signal is higher than the residual noise energy after filtering the null space projection of the instantaneous channel characteristics of the SRS signal.

[0086] In this embodiment of the present invention, obtaining projections of multiple instantaneous channel features in the null space includes:

[0087]

[0088] in, represents the assumption that there is no SRS attack in the received signal; represents the assumption that there is an SRS attack in the received signal; np represents the projection of instantaneous channel characteristics in the null space; VV H Represents instantaneous channel characteristics; N represents the number of attackers transmitting SRS attack signals; θ n,k represents the power allocation coefficient of the nth attacker attacking the kth user; represents the attack power of the nth attacker; represents the SRS transmission power of the kth user; h A,n represents the channel model between the base station and the nth attacker; w B,k represents the equivalent noise vector; np-detector represents the detector after null space projection.

[0089] Step S103: If the residual noise energy in the plurality of projections is greater than a predetermined detection threshold, it is determined that an SRS attack signal exists in the received signal; the detection threshold is determined according to a set false alarm probability.

[0090] In the embodiments of the present invention, the false alarm probability refers to the acceptable false alarm probability of the system. The specific false alarm probability can be set by technical personnel according to needs and is not limited here. The predetermined detection threshold can be determined based on the set false alarm probability.

[0091] In this embodiment of the present invention, the detection threshold is derived based on a signal in a non-attack state, namely, an SRS signal. Therefore, by determining the residual noise energy of the projections, if the residual noise energy in multiple projections is greater than a predetermined detection threshold, it can be determined that an SRS attack signal is present in the received signal. Conversely, if the residual noise energy in multiple projections is not greater than the predetermined detection threshold, it is determined that no SRS attack signal is present in the received signal, i.e., no SRS spoofing attack has occurred.

[0092] In an embodiment of the present invention, by introducing the null space of the channel covariance matrix with a low-rank structure, the separation accuracy of the signal subspaces of legitimate users and fraudulent attackers can be effectively improved, thereby obtaining multiple continuous instantaneous channel characteristics of the received signal and obtaining the projections of multiple instantaneous channel characteristics in the null space. In addition, in an embodiment of the present invention, attack detection is performed based on a sequential approach focusing on the energy mutation after the null space projection. By calculating multiple continuous instantaneous channel characteristics of the received signal and obtaining the projections of multiple instantaneous channel characteristics in the null space, when the residual noise energy present in the multiple projections is greater than a predetermined detection threshold, it is determined that an SRS attack signal exists in the received signal, making the detection result more accurate and robust.

[0093] Compared with existing fraud attack detection methods, the reference signal fraud attack detection method provided by the embodiment of the present invention does not require modification of the communication protocol and does not require high startup costs and training time, and is easier to implement in engineering.

[0094] In one implementation, the detection threshold is predetermined by:

[0095] Obtain the SRS residual noise energy of the SRS signal in the null space;

[0096] The test statistic is obtained by using the central limit theorem and multiple sample signals; the sample signals include SRS sample signals and SRS attack sample signals;

[0097] Determine the normal distribution of the SRS signal based on the SRS residual noise energy and the test statistic;

[0098] The detection threshold is determined based on the right-tail Q function of the normal distribution and the definition of the false alarm probability.

[0099] In the embodiment of the present invention, the SRS residual noise energy of the SRS signal in the null space is expressed as VV H w B,k express.

[0100] In the embodiment of the present invention, VV represents the residual noise energy after the SRS signal is projected in the null space H w B,k The variance of Set up the test questions.

[0101] When the variance of the decision sample signal composed of the collected L sample signals is Not present The confidence interval is within the range of , that is, the probability is high and the SRS signal The characteristics do not match, so it can be considered that there is an SRS attack sample signal in the sample signal. As can be seen from the test statistics, it is essentially detected by comparing the distribution characteristics when there is an attack and when there is no attack.

[0102] In one implementation, when the number of sample signals is large enough, based on the central limit theorem, the test statistic obtained from the variance of the decision sample signal composed of L sample signals can be approximated as a Gaussian random variable. for:

[0103]

[0104] Wherein, l=1, 2, ..., L, and L represents the number of sample signals.

[0105] Based on this, the sample signal without SRS attack can be expressed as the following normal distribution:

[0106]

[0107] The normal distribution of the sample signal without SRS attack is converted into a standard normal distribution using the general normal distribution to standard normal distribution method. The general normal distribution to standard normal distribution method is:

[0108]

[0109] Where X represents a general normally distributed random variable; μ represents the mean; σ represents the standard deviation; and Y represents a standard normally distributed random variable.

[0110] In one implementation, the false alarm probability is defined as:

[0111]

[0112] Among them, P fa represents the false alarm probability; η represents the detection threshold; H0 represents the assumption that there is no SRS attack signal.

[0113] In the embodiment of the present invention, the relationship between the false alarm probability and the detection threshold can be determined according to the right-tail Q function of the normal distribution:

[0114]

[0115] Where Φ(·) represents the distribution function of the standard normal distribution. The relationship between the detection threshold and the false alarm probability can be derived from the right-tail Q function of the standard normal distribution: Q(·) = 1-Φ(·). Furthermore, the detection threshold can be determined using the inverse function of the false alarm probability relationship. Since more sample signals result in smaller fluctuations, the sample signal without an SRS attack is closer to a distribution with a known variance. Therefore, the detection threshold can be calculated as:

[0116]

[0117] When the number of samples is large enough, the detection threshold will be maintained near the residual noise variance after projection. The Q function is x represents the lower limit of integration; +∞ is positive infinity, representing the upper limit of integration; t represents the integral variable.

[0118] The inverse of the Q function can be found by storing the right-tail Q function table of the standard normal distribution, as shown in Table 1. The detection threshold can be obtained by looking up the table. For example, when the false alarm probability is 0.20, Q -1 (0.20) can be determined to be around 0.84 by looking up the table.

[0119] Table 1

[0120]

[0121]

[0122] In the embodiment of the present invention, according to a given false alarm probability requirement, the detection threshold can be determined by looking up a table using the Q function. In addition, the detection recognition rate can be calculated based on this.

[0123] In the embodiment of the present invention, the residual noise after projection has little impact, and the impact caused by fluctuations of legitimate users can also be eliminated, thereby effectively controlling the false alarm probability and improving the robustness of detection.

[0124] The following describes a simulation experiment using the reference signal fraud attack detection method provided by an embodiment of the present invention:

[0125] 1. Example scene setting.

[0126] The experiment constructs a circular area with a base station at the center and an inner radius of 50m, in which users and attackers are evenly and randomly distributed. The maximum distances between users and attackers are 400m and 300m respectively. The channel bandwidth and noise power are set to 20MHz and -90dBm respectively. During the uplink channel training phase, the SRS transmission power of each user is set to be the same, that is, The interference power of each attacker is the same, that is, Specifically, the number of base station antennas M is set to 64, the number of users K is set to 24, the number of attackers N is set to 4, and the attackers' attack distribution coefficient follows a uniform distribution from 0 to 1. The signal-to-noise ratio (SNR) is considered to be 5dB and -5dB, respectively, and the jamming-to-signal ratio (JSR) range is considered to be -15dB to 10dB.

[0127] The method provided by this embodiment of the present invention primarily leverages the fact that the channel covariance matrix extends over a limited space, separating the signal subspace from the interference subspace in the angular domain. Ideally, the angular extension ranges of the attacker and legitimate user signals will not overlap, resulting in superior detection performance.

[0128] In order to conduct a more comprehensive analysis of the detection method proposed in the embodiment of the present invention, and considering that there may be an overlap in the angle extension range of the attacker's SRS fraud attack and the legitimate user's non-attack signal, the spatial feature overlap index is introduced, such as Figure 3 The simulation results show that Figure 3 This is a schematic diagram comparing the changes in residual noise energy under different spatial feature overlaps, where the horizontal axis represents the channel implementation index and the vertical axis represents the null space projection residual value. Figure (3)a shows the case where the spatial features do not overlap, Figure (3)b shows the case where the spatial feature overlap is 50%, Figure (3)c shows the case where the spatial feature overlap is 70%, and Figure (3d) shows the case where the spatial feature overlap is 90%. The legitimate user's transmission signal will have a certain angle range when it reaches the base station antenna through the channel. The spatial feature overlap refers to the overlap of the attacker and legitimate user angle ranges from a statistical perspective. The specific overlap setting can be determined by the position swing and angle expansion scaling of the attacker and legitimate user in the CDL-D model.

[0129] 2. Experimental details.

[0130] 1) The null space projection based on the spatial characteristics of the channel is used to depict the changes in the residual energy after projection filtering when there is no attack and when there is an attack, demonstrating the process of determining the detection threshold of the proposed scheme;

[0131] 2) The changes in the detection probability of the proposed scheme and the energy signature-based scheme under different SRS transmission signal-to-noise ratios as the attacker's power increases.

[0132] Figure 3 The figure depicts the variation in residual noise energy after null space projection filtering for different degrees of overlap in the angular spread ranges of the attacker and legitimate user signals. Simulation results show that when the angular spread ranges of the attacker and legitimate user signals do not overlap, the demarcation between residual energy levels is very clear when there is an attack and when there is no attack. Even when the angular spread ranges of the attacker and legitimate user signals overlap by half, an effective detection threshold can be achieved. When the angular spread ranges of the attacker and legitimate user signals overlap more, for example, reaching 70% and 90%, although the demarcation between residual energy levels converges, detection and identification can still be achieved within a certain false alarm range. Furthermore, in practice, because transmission environments are more complex and variable, transmitters at different locations have significantly different spatial characteristics and do not have a high degree of spatial feature overlap. Therefore, the detection method proposed in this embodiment of the present invention still has considerable application potential.

[0133] Figure 4 : is a schematic diagram of the detection performance visualization results of the reference signal fraud attack detection method provided by an embodiment of the present invention, wherein the horizontal axis represents JSR (Jamming to Signal Ration, interference signal ratio): P A / P U , the unit is dB, the vertical axis represents the detection probability, Figure 4 (a) represents the detection probability under different JSRs, where SNR (Signal-to-Noise Ratio): P U / σ 2 =5dB, Figure 4 (b) represents the detection probability under different JSRs, where SNR: P U / σ 2 =-5dB. Figure 4The proposed method and energy signature-based scheme demonstrate how the detection probability changes with increasing attacker power and at different SRS transmission signal-to-noise ratios. Simulation results show that the detection probability of both schemes increases with increasing attacker power. When the angular spread ranges of the attacker and legitimate user signals do not overlap, the overall detection performance of the detection method proposed in this embodiment of the present invention significantly outperforms the energy signature-based scheme. This is because the proposed method detects only the presence of residual SRS spoofing attacks, regardless of the magnitude of energy fluctuations. Therefore, it is more robust than the baseline energy detection method. Furthermore, the proposed method achieves good detection performance even when the angular spread ranges of the attacker and legitimate user signals overlap by half, particularly at high attacker power, approaching the optimal detection performance for incomplete overlap. It should also be noted that when the angular spread ranges of the attacker and legitimate user signals overlap significantly, such as 70% and 90%, the method provided by this embodiment of the present invention also rapidly improves detection performance even at higher attack power. In practice, it is difficult for an attacker to achieve an overlap of more than 50% with the legitimate user signal spread range due to the complex and variable transmission environment, where transmitters at different locations have significantly different spatial characteristics.

[0134] The reference signal spoofing attack detection method based on null space projection of the spatial low-rank structure of the channel, proposed in embodiments of the present invention, is more robust in terms of detection and false alarm performance. It also requires no protocol modifications and is easier to implement. Taking the SRS spoofing attack as an example, when an attack occurs, the proposed null space projection detection essentially relies on spatial statistical features. It exploits the fact that the channel covariance matrix extends into a limited space, separating the signal subspace from the interference subspace in the angular domain. Detection is performed solely based on the presence or absence of residual SRS spoofing attack influence, regardless of the magnitude of energy fluctuation. When there is no SRS spoofing attack, the proposed detection algorithm is more robust to legitimate users and noise. Because the null space projection method minimizes the residual noise influence, the noise effect, which exists regardless of the attack, can be canceled out. Furthermore, after null space projection, the legitimate user's portion is eliminated, eliminating the impact caused by legitimate user fluctuations.

[0135] Based on the same inventive concept, the embodiment of the present invention further provides a reference signal fraud attack detection device, see Figure 5 , Figure 5 : is a schematic diagram of the structure of a reference signal fraud attack detection device provided by an embodiment of the present invention, the reference signal fraud attack detection device comprising:

[0136] The null space obtaining module 501 is configured to obtain the null space using the channel covariance matrix stored in the base station; the channel covariance matrix is ​​the channel covariance matrix of the SRS signal;

[0137] The projection acquisition module 502 is used to calculate a plurality of consecutive instantaneous channel characteristics of the received signal and obtain projections of the plurality of instantaneous channel characteristics in the null space;

[0138] The SRS attack judgment module 503 is configured to determine that an SRS attack signal exists in the received signal if the residual noise energy in the plurality of projections is greater than a predetermined detection threshold; the detection threshold is determined according to a set false alarm probability.

[0139] In an embodiment of the present invention, by introducing the null space of the channel covariance matrix with a low-rank structure, the separation accuracy of the signal subspaces of legitimate users and fraudulent attackers can be effectively improved, thereby obtaining multiple continuous instantaneous channel characteristics of the received signal and obtaining the projections of multiple instantaneous channel characteristics in the null space. In addition, in an embodiment of the present invention, attack detection is performed based on a sequential approach focusing on the energy mutation after the null space projection. By calculating multiple continuous instantaneous channel characteristics of the received signal and obtaining the projections of multiple instantaneous channel characteristics in the null space, when the residual noise energy present in the multiple projections is greater than a predetermined detection threshold, it is determined that an SRS attack signal exists in the received signal, making the detection result more accurate and robust.

[0140] Compared with existing fraud attack detection methods, the reference signal fraud attack detection method provided by the embodiment of the present invention does not require modification of the communication protocol and does not require high startup costs and training time, and is easier to implement in engineering.

[0141] Optionally, the detection threshold is predetermined by:

[0142] Acquire SRS residual noise energy of the SRS signal in the null space;

[0143] A test statistic is obtained using the central limit theorem and multiple sample signals; the sample signals include an SRS sample signal and an SRS attack sample signal;

[0144] determining a normal distribution of the SRS signal according to the SRS residual noise energy and the test statistic;

[0145] The detection threshold is determined according to the definition of the right-tail Q function of the normal distribution and the false alarm probability.

[0146] Optionally, determining the detection threshold according to the definition of the right-tail Q function of the normal distribution and the false alarm probability includes:

[0147]

[0148] Wherein, η represents the detection threshold; Q represents the right tail Q function of the normal distribution; P fa represents the false alarm probability; σ 2represents the Gaussian white noise variance of the base station; τ p represents the length of the sample signal; represents the SRS transmission power of the kth user; L represents the number of sample signals; and M represents the number of antennas of the base station.

[0149] Optionally, the test statistic is:

[0150]

[0151] Wherein, l=1, 2, ..., L, L represents the number of sample signals; y np represents the projection of the instantaneous channel characteristics into the null space.

[0152] Optionally, a projection acquisition module obtains projections of multiple instantaneous channel features in the null space, including:

[0153]

[0154] in, An assumption that no SRS attack exists in the received signal; represents the assumption that there is an SRS attack in the received signal; np represents the projection of the instantaneous channel characteristics in the null space; VV H Represents instantaneous channel characteristics; N represents the number of attackers transmitting SRS attack signals; θ n,k represents the power allocation coefficient of the nth attacker attacking the kth user; represents the attack power of the nth attacker; represents the SRS transmission power of the kth user; h A,n represents the channel model between the base station and the nth attacker; w B,k represents the equivalent noise vector; np-detector represents the detector after the null space projection.

[0155] The embodiment of the present invention further provides an electronic device, such as Figure 6 As shown, it includes a processor 601, a communication interface 602, a memory 603 and a communication bus 604, wherein the processor 601, the communication interface 602, and the memory 603 communicate with each other through the communication bus 604.

[0156] Memory 603, used for storing computer programs;

[0157] The processor 601 is configured to implement the method steps described in any of the above-mentioned reference signal fraud attack detection methods when executing the program stored in the memory 603 .

[0158] The communication bus mentioned in the electronic device mentioned above may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus. This communication bus can be divided into an address bus, a data bus, a control bus, etc. For ease of illustration, only one thick line is used in the figure, but this does not mean that there is only one bus or only one type of bus.

[0159] The communication interface is used for communication between the above electronic device and other devices.

[0160] The memory may include random access memory (RAM) or non-volatile memory (NVM), such as at least one disk storage. Alternatively, the memory may be at least one storage device located away from the processor.

[0161] The above-mentioned processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, and discrete hardware components.

[0162] The present invention also provides a computer-readable storage medium having a computer program stored therein, which, when executed by a processor, implements the method steps described in any of the above-mentioned reference signal fraud attack detection methods.

[0163] Optionally, the computer-readable storage medium may be a non-volatile memory (NVM), such as at least one disk memory.

[0164] Optionally, the computer-readable memory may also be at least one storage device located away from the aforementioned processor.

[0165] It should be noted that the terms "first," "second," and the like are used to distinguish similar objects and are not necessarily used to describe a particular order or precedence. It should be understood that the terms used in this manner are interchangeable where appropriate, so that the embodiments of the present invention described herein can be implemented in sequences other than those illustrated or described herein. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present invention. Instead, they are merely examples of devices and methods consistent with some aspects of the present invention.

[0166] In the description of this specification, the reference terms "one embodiment," "some embodiments," "example," "specific example," or "some examples" mean that the specific features or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features or characteristics described can be combined in any suitable manner in any one or more embodiments or examples. In addition, those skilled in the art can combine and combine different embodiments or examples described in this specification.

[0167] Although the present invention is described herein in conjunction with various embodiments, in the process of implementing the claimed invention, those skilled in the art can understand and implement other variations of the disclosed embodiments by viewing the drawings and the disclosed content. In the description of the present invention, the word "comprising" does not exclude other components or steps, "one" or "a" does not exclude multiple situations, and "multiple" means two or more, unless otherwise clearly and specifically defined. In addition, certain measures are recorded in different embodiments, but this does not mean that these measures cannot be combined to produce good results.

[0168] The method provided in the embodiments of the present invention can be applied to electronic devices. Specifically, the electronic devices can be desktop computers, portable computers, smart mobile terminals, servers, etc. This is not limited here; any electronic device that can implement the present invention falls within the scope of protection of the present invention.

[0169] As for the device / electronic device / storage medium embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0170] It should be noted that the device, electronic device and storage medium of the embodiments of the present invention are respectively the device, electronic device and storage medium that apply the above-mentioned reference signal fraud attack detection method. All embodiments of the above-mentioned reference signal fraud attack detection method are applicable to the device, electronic device and storage medium, and can achieve the same or similar beneficial effects.

[0171] The above is a further detailed description of the present invention in conjunction with specific preferred embodiments, and the specific implementation of the present invention should not be considered to be limited to these descriptions. For those skilled in the art of the present invention, without departing from the concept of the present invention, several simple deductions or substitutions can be made, which should be considered to fall within the scope of protection of the present invention.

Claims

1. A reference signal fraud attack detection method, characterized in that: The reference signal fraud attack detection method includes: Utilizing the channel covariance matrix stored in the base station to obtain the null space; the channel covariance matrix is ​​the channel covariance matrix of the SRS signal; Calculating a plurality of continuous instantaneous channel features of the received signal, and obtaining projections of the plurality of instantaneous channel features in the null space; If the residual noise energy present in the plurality of projections is greater than a predetermined detection threshold, it is determined that an SRS attack signal exists in the received signal; the detection threshold is determined according to a set false alarm probability; The obtaining projections of the plurality of instantaneous channel features in the null space includes: ; in, An assumption that no SRS attack exists in the received signal; Indicates a hypothesis that an SRS attack exists in the received signal; represents the projection of the instantaneous channel feature on the null space; Represents instantaneous channel characteristics; , , Indicates the number of attackers transmitting SRS attack signals; Indicates the The attacker attacks Power allocation coefficient for each user; Indicates the The attack power of each attacker; Indicates the SRS transmission power of each user; Indicates the base station and the Channel model between attackers; represents the equivalent noise vector; represents the detector after the null space projection.

2. The reference signal fraud attack detection method according to claim 1, characterized in that: The detection threshold is predetermined in the following manner: Acquire SRS residual noise energy of the SRS signal in the null space; A test statistic is obtained using the central limit theorem and multiple sample signals; the sample signals include an SRS sample signal and an SRS attack sample signal; determining a normal distribution of the SRS signal according to the SRS residual noise energy and the test statistic; The detection threshold is determined according to the definition of the right-tail Q function of the normal distribution and the false alarm probability.

3. The reference signal fraud attack detection method according to claim 2, characterized in that: Determining the detection threshold according to the definition of the right-tail Q function of the normal distribution and the false alarm probability includes: ; in, represents the detection threshold; represents the right-tailed Q function of the normal distribution; represents the false alarm probability; ; represents the Gaussian white noise variance of the base station; represents the length of the sample signal; Indicates the SRS transmission power of each user; represents the number of the sample signals; Indicates the number of antennas of the base station.

4. The reference signal fraud attack detection method according to claim 2, characterized in that: The test statistic is: ; in, , represents the number of the sample signals; represents the projection of the instantaneous channel characteristics into the null space.

5. A reference signal fraud attack detection device, characterized in that: The reference signal fraud attack detection device includes: A null space obtaining module, configured to obtain the null space using a channel covariance matrix stored in the base station; the channel covariance matrix is ​​the channel covariance matrix of the SRS signal; A projection acquisition module, configured to calculate a plurality of continuous instantaneous channel features of a received signal and obtain projections of the plurality of instantaneous channel features in the null space; An SRS attack judgment module is configured to determine that an SRS attack signal exists in the received signal if the residual noise energy present in the plurality of projections is greater than a predetermined detection threshold; the detection threshold is determined based on a set false alarm probability; The projection acquisition module acquires the projections of the multiple instantaneous channel features in the null space, including: ; in, An assumption that no SRS attack exists in the received signal; Indicates a hypothesis that an SRS attack exists in the received signal; represents the projection of the instantaneous channel feature on the null space; Represents instantaneous channel characteristics; , , Indicates the number of attackers transmitting SRS attack signals; Indicates the The attacker attacks Power allocation coefficient for each user; Indicates the The attack power of each attacker; Indicates the SRS transmission power of each user; Indicates the base station and the Channel model between attackers; represents the equivalent noise vector; represents the detector after the null space projection.

6. The reference signal fraud attack detection device according to claim 5, characterized in that: The detection threshold is predetermined in the following manner: Acquire SRS residual noise energy of the SRS signal in the null space; A test statistic is obtained using the central limit theorem and multiple sample signals; the sample signals include an SRS sample signal and an SRS attack sample signal; determining a normal distribution of the SRS signal according to the SRS residual noise energy and the test statistic; The detection threshold is determined according to the definition of the right-tail Q function of the normal distribution and the false alarm probability.

7. The reference signal fraud attack detection device according to claim 6, characterized in that: Determining the detection threshold according to the definition of the right-tail Q function of the normal distribution and the false alarm probability includes: ; in, represents the detection threshold; represents the right-tailed Q function of the normal distribution; represents the false alarm probability; ; represents the Gaussian white noise variance of the base station; represents the length of the sample signal; Indicates the SRS transmission power of each user; represents the number of the sample signals; Indicates the number of antennas of the base station.

8. An electronic device, characterized in that: It includes a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other via the communication bus; Memory for storing computer programs; The processor is configured to implement the reference signal fraud attack detection method according to any one of claims 1 to 4 when executing a program stored in the memory.

9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the reference signal fraud attack detection method according to any one of claims 1 to 4 is implemented.

Citation Information

Patent Citations

  • SAR deception jamming method with jammers and receivers jointly networked

    CN103760532A

  • Interference control method and device

    CN116195214A