A method and system for reverse analysis of physical layer characteristics of radio frequency chips
By configuring the software environment on the RF chip development board and performing forward and reverse data processing, the physical layer characteristics of the RF chip are systematically analyzed, solving the problems of low efficiency and low accuracy in existing technologies and achieving efficient and economical RF chip analysis.
Patent Information
- Application Number
- CN202510193034.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-21
- Publication Date
- 2025-09-19
- Estimated Expiration
- 2045-02-21
AI Technical Summary
Existing technologies are inefficient and inaccurate when analyzing the physical layer characteristics of RF chips, especially when dealing with unknown or proprietary chips that lack official documentation support. Traditional methods are costly and complex to operate, and software simulation tools are not accurate enough.
By configuring the software environment, code is burned into two development boards. One board is used as the transmitter for forward operation, and the other board is used as the receiver for reverse operation. The forward and reverse functions in the data processing flow are used to analyze the physical layer characteristics of the RF chip, including error detection, channel encoding and decoding, signal shaping, time domain dispersion, and independent control of carrier modulation links.
It realizes the automatic and precise analysis of the physical layer characteristics of RF chips, reduces the dependence on dedicated test equipment, improves the analysis efficiency and accuracy, is applicable to various types of RF chips, enhances interoperability and security assessment capabilities, and reduces R&D costs.
Smart Images

Figure CN119668928B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of radio frequency communication technology, and in particular to a method and system for reversely analyzing the physical layer characteristics of a radio frequency chip. Background Art
[0002] With the rapid development of the Internet of Things, 5G networks, and dedicated wireless communication systems, understanding and analyzing the physical layer characteristics of these RF chips is becoming increasingly important. Accurately capturing the internal data processing flow and physical layer configuration of RF chips is a key technical requirement for applications such as security assessments, compatibility testing, fault diagnosis, and reverse engineering.
[0003] Currently, traditional methods for analyzing the physical layer characteristics of RF chips typically rely on manufacturer-provided datasheets and technical documentation, or on chip disassembly and analysis using specialized hardware testing equipment. In addition, some software-based simulation tools exist for simulating the behavior of RF chips to infer their physical layer characteristics.
[0004] Existing approaches to analyzing the physical layer characteristics of RF chips face several major drawbacks. First, when dealing with unknown or proprietary RF chips, a lack of official documentation prevents access to necessary information, rendering traditional document-based analysis methods ineffective. Second, using specialized test equipment for physical-level reverse engineering is not only costly and complex, but also unsuitable for large-scale or rapid analysis. Finally, while existing software simulation tools can provide some assistance, they often fail to fully simulate actual behavior, resulting in inaccurate results. Summary of the Invention
[0005] The embodiments of the present application provide a method and system for reverse analysis of the physical layer characteristics of a radio frequency chip, to solve the problems of low efficiency and low accuracy in the prior art.
[0006] In a first aspect, an embodiment of the present application provides a method for reversely analyzing physical layer characteristics of a radio frequency chip, comprising:
[0007] Configure the software environment for the RF chip with unknown physical layer configuration characteristics. After the software environment configuration is complete, burn the code to two development boards carrying the RF chip. Use one development board with the burned code as the transmitter and the other development board with the burned code as the receiver.
[0008] Controlling the transmitting end to perform forward operation in the data processing flow, and controlling the receiving end to perform reverse operation in the data processing flow;
[0009] Reverse analysis is performed on all data generated by the transmitting end and the receiving end in the data processing flow to obtain physical layer characteristic information of the radio frequency chip.
[0010] Optionally, the data processing flow includes at least one of the following data processing links: an error detection link, a channel encoding and decoding link, a signal shaping link, a time domain dispersion link, and a carrier modulation link;
[0011] The controlling the transmitting end to perform a forward operation in the data processing flow and the controlling the receiving end to perform a reverse operation in the data processing flow comprises at least one of the following steps:
[0012] For the error detection link, enable the cyclic redundancy check bit generation function corresponding to the error detection link at the transmitting end, disable the encoding function, whitening function, interleaving function and modulation function, enable the cyclic redundancy check function corresponding to the error detection link at the receiving end, and disable the decoding function, dewhitening function, deinterleaving function and demodulation function;
[0013] For the channel coding and decoding link, the encoding function corresponding to the transmitting end and the channel coding and decoding link is enabled, and the cyclic redundancy check bit generation function, whitening function, interleaving function and modulation function are not enabled; the decoding function corresponding to the receiving end and the channel coding and decoding link is enabled, and the cyclic redundancy check function, dewhitening function, deinterleaving function and demodulation function are not enabled;
[0014] For the signal shaping link, enable the whitening function corresponding to the transmitting end and the signal shaping link, do not enable the cyclic redundancy check bit generation function, encoding function, interleaving function and modulation function, enable the dewhitening function corresponding to the receiving end and the signal shaping link, do not enable the cyclic redundancy check function, decoding function, deinterleaving function and demodulation function;
[0015] For the time domain dispersion link, enable the interleaving function corresponding to the transmitting end and the time domain dispersion link, do not enable the cyclic redundancy check bit generation function, encoding function, whitening function and modulation function, enable the deinterleaving function corresponding to the receiving end and the time domain dispersion link, do not enable the cyclic redundancy check function, decoding function, dewhitening function and demodulation function;
[0016] For the carrier modulation link, the modulation function corresponding to the transmitting end and the carrier modulation link is enabled, and the cyclic redundancy check bit generation function, encoding function, whitening function and interleaving function are not enabled. The demodulation function corresponding to the receiving end and the carrier modulation link is enabled, and the cyclic redundancy check function, decoding function, dewhitening function and deinterleaving function are not enabled.
[0017] Optionally, performing reverse parsing on all data generated by the transmitting end and the receiving end in a data processing flow to obtain physical layer characteristic information of the radio frequency chip includes:
[0018] When the data processing flow includes a time domain dispersion link, reverse analysis is performed based on the data generated by the transmitting end in the time domain dispersion link and the data generated by the receiving end in the time domain dispersion link to obtain physical layer characteristic information of the RF chip, where the physical layer characteristic information includes interleaving block size and interleaving block data position change information.
[0019] Optionally, the reverse parsing is performed based on the data generated by the transmitting end in the time domain dispersion link and the data generated by the receiving end in the time domain dispersion link to obtain physical layer characteristic information of the RF chip, where the physical layer characteristic information includes interleaving block size and interleaving block data position change information, including:
[0020] Step 11, initialize two parameters n and k1, n is the number of bytes, n is an integer greater than or equal to 1, k1 is the coefficient, k1=1;
[0021] Step 12: generating first repetitive data in units of n bytes at the transmitting end as test data, wherein the test data is interleaved when the interleaving function is enabled, and the receiving end obtains the first interleaved data;
[0022] Step 13, determining whether the first interleaved data is in units of n bytes; if the first interleaved data is not in units of n bytes, executing step 14; or, if the first interleaved data is in units of n bytes, executing step 15;
[0023] Step 14, update n by accumulating, and repeat steps 12 to 13;
[0024] Step 15: generating, at the transmitting end, multiple sets of second repeated data in units of n bytes as multiple sets of verification data, wherein the multiple sets of verification data are interleaved when the interleaving function is enabled, and the receiving end obtains multiple sets of second interleaved data, wherein each set of second repeated data is not equal to the first repeated data;
[0025] Step 16, determining whether the multiple sets of second interleaved data are all in units of n bytes; if the multiple sets of second interleaved data are not in units of n bytes, executing step 17; or if the multiple sets of second interleaved data are all in units of n bytes, executing step 18;
[0026] Step 17: Update k1 by accumulation, and update n by multiplying k1 by n, and repeat steps 15 to 16.
[0027] Step 18: Determine that the interleaved block size is n, and trigger the interleaved block data position change process to obtain interleaved block data position change information.
[0028] Optionally, triggering an interleaved block data position change process to obtain interleaved block data position change information includes:
[0029] Step 21, initialize the interleaving block size to n, parameter k2=1, indicating the first byte, a=1, indicating the first bit;
[0030] Step 22: at the transmitting end, setting the ath bit of the k2th byte to 1 and the remaining bits to 0 to generate non-repeating data in units of an interleaving block size n, and performing an interleaving process when the interleaving function is enabled;
[0031] Step 23, determining position change information of the value 1 according to the third interleaved data received by the receiving end;
[0032] Step 24, determine whether k2 is equal to n and whether a is equal to 8; if not, proceed to step 25; or, if both are satisfied, proceed to step 28;
[0033] Step 25, determine whether a is less than 8. If a is less than 8, execute step 26; if a is equal to 8, execute step 27;
[0034] Step 26, update a by accumulating, and repeat steps 22 to 24;
[0035] Step 27: Update k2 by accumulating, reset a to 1, and execute steps 22 to 24;
[0036] Step 28: Generate interleaved block data position change information based on the position change information of all values 1.
[0037] Optionally, performing reverse parsing on all data generated by the transmitting end and the receiving end in a data processing flow to obtain physical layer characteristic information of the radio frequency chip includes:
[0038] In the case where the data processing flow includes a channel encoding and decoding link, reverse parsing is performed based on all data generated by the transmitting end and the receiving end in the channel encoding and decoding link to obtain physical layer characteristic information of the RF chip. The physical layer characteristic information includes the encoding method adopted by the encoding function. When the encoding method includes a convolutional code, the convolutional code includes a generating polynomial and a code rate.
[0039] Optionally, reverse parsing is performed based on all data generated by the transmitting end and the receiving end in the data processing flow to obtain physical layer characteristic information of the radio frequency chip, including:
[0040] In the case where the data processing flow includes a signal shaping step, the maximum length is determined according to a preset RF chip manual, all-zero data of the maximum length is sent at the transmitting end, and reverse analysis is performed by comparing the all-zero data with the data received at the receiving end to obtain a whitening sequence of the RF chip;
[0041] In the case where the data processing flow includes an error detection link, a preset standard length is obtained through a preset RF chip manual, a cyclic redundancy check bit is generated at the transmitting end according to the preset standard length, data with the cyclic redundancy check bit is sent to the receiving end, and the cyclic redundancy check bit of the data sent by the transmitting end is compared with the cyclic redundancy check bit of the data received by the receiving end. If the comparison result is inconsistent, multiple initial values are obtained through an exhaustive method, and the cyclic redundancy check bit generated based on each initial value is compared with the cyclic redundancy check bit of the data sent by the transmitting end to perform reverse analysis to obtain the cyclic redundancy check parameters of the RF chip, wherein the cyclic redundancy check parameters include: the initial value corresponding to the cyclic redundancy check bit when the comparison is consistent.
[0042] In a second aspect, an embodiment of the present application provides a system for reverse engineering the physical layer characteristics of a radio frequency chip, including:
[0043] The configuration and programming module is used to configure the software environment of the RF chip with unknown physical layer configuration characteristics. After the software environment configuration is completed, the code is programmed into two development boards carrying the RF chip. One development board with the programmed code is used as the transmitter, and the other development board with the programmed code is used as the receiver.
[0044] A control module, configured to control the transmitting end to perform a forward operation in the data processing flow, and control the receiving end to perform a reverse operation in the data processing flow;
[0045] The reverse parsing module is used to perform reverse parsing based on all data generated by the transmitting end and the receiving end in the data processing flow to obtain physical layer characteristic information of the radio frequency chip.
[0046] In a third aspect, an embodiment of the present application provides a computing device comprising a processing component and a storage component; the storage component stores one or more computer instructions; the one or more computer instructions are used to be called and executed by the processing component to implement a method for reverse analysis of the physical layer characteristics of a radio frequency chip as described in any one of the first aspects.
[0047] In a fourth aspect, an embodiment of the present application provides a computer storage medium storing a computer program. When the computer program is executed by a computer, it implements a method for reverse analysis of the physical layer characteristics of a radio frequency chip as described in any one of the first aspects.
[0048] In an embodiment of the present application, a software environment for a radio frequency chip with unknown physical layer configuration characteristic information is configured. After the software environment configuration is completed, code is burned into two development boards carrying the radio frequency chip, and one development board after the code is burned is used as a transmitter, and the other development board after the code is burned is used as a receiver; the transmitter is controlled to perform forward operations in the data processing flow, and the receiver is controlled to perform reverse operations in the data processing flow; reverse analysis is performed based on all data generated by the transmitter and the receiver in the data processing flow to obtain the physical layer characteristic information of the radio frequency chip.
[0049] The technical solution of this application has the following beneficial effects:
[0050] This method provides a systematic approach to automatically analyze the unknown physical layer characteristics of RF chips, reducing the complexity and time required for manual analysis. By controlling the data processing flow at both the transmitter and receiver ends and performing reverse engineering based on all generated data, the physical layer configuration information of the RF chip can be more accurately obtained. This method is applicable to a wide range of RF chip types and different data processing steps (such as error detection, channel encoding and decoding, and signal shaping), making it widely applicable. Understanding the specific physical layer characteristics of RF chips helps improve interoperability and compatibility between different devices, which is invaluable for product development and troubleshooting. Compared to traditional physical layer characteristic analysis methods, this method reduces reliance on specialized test equipment and lowers R&D costs. It helps security researchers assess the security of RF communications and identify potential security vulnerabilities or unexpected behavior. It provides new tools and methods for the study of RF technology and communication protocols, promoting technological innovation and development.
[0051] Furthermore, the data processing process is specified to encompass five key steps: error detection, channel encoding and decoding, signal shaping, time-domain dispersion, and carrier modulation. For each step, the transmitter and receiver perform the forward or reverse operations of a specific function: in the error detection step, only the cyclic redundancy check bit generation and verification functions are enabled; in the channel encoding and decoding step, encoding and decoding functions are enabled separately; in the signal shaping step, only the whitening and de-whitening functions are activated; in the time-domain dispersion step, only the interleaving and de-interleaving functions are enabled; and in the carrier modulation step, only the modulation and demodulation functions are enabled. Other unrelated functions are deactivated in each step to ensure the independence and accuracy of each data processing step.
[0052] This method separates different data processing steps—error detection, channel encoding and decoding, signal shaping, time-domain dispersion, and carrier modulation—and activates only the relevant forward or reverse operations within each step, avoiding interference from other non-relevant functions. This significantly improves the accuracy and reliability of reverse engineering. This approach allows researchers to focus on each individual data processing step without having to consider the impact of multiple parallel processes. This not only simplifies the analysis process but also accelerates the understanding of the physical layer characteristics of RF chips, improving work efficiency. Compared to traditional methods that rely on expensive specialized test equipment, this method utilizes software environment configuration and code flashing onto development boards for reverse engineering, reducing hardware requirements and technical barriers, making RF chip analysis more economical and feasible. The detailed information obtained through this method can enhance understanding of RF communication protocols and technologies, help improve interoperability between different systems, and provide a valuable basis for security assessments. For existing RF systems, this method can help identify potential issues, such as the effectiveness of error detection mechanisms, the rationality of channel coding strategies, and the optimal settings of signal processing parameters, thereby guiding system improvements and optimization. This method provides a new tool for research in the field of wireless communications, promoting the research and development of new RF technologies and protocols, especially for proprietary or unknown RF chips that lack public documentation support.
[0053] In summary, this method not only solves the defects of existing solutions, but also brings higher accuracy, efficiency and economy to the analysis of the physical layer characteristics of RF chips, which is of great significance for promoting the development of wireless communication technology.
[0054] These and other aspects of the present application will become more readily apparent from the description of the following embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0055] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, a brief introduction will be given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0056] Figure 1 A flowchart of a method for reverse-engineering the physical layer characteristics of a radio frequency chip provided in an embodiment of the present application;
[0057] Figure 2 A schematic diagram of the structure of a device (or system) for reversely analyzing the physical layer characteristics of a radio frequency chip provided in an embodiment of the present application;
[0058] Figure 3A schematic diagram of the structure of a computing device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0059] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application.
[0060] In some of the processes described in the specification and claims of this application and the above-mentioned figures, multiple operations that appear in a specific order are included, but it should be clearly understood that these operations may not be executed in the order in which they appear in this document or may be executed in parallel. The serial numbers of the operations, such as 11, 12, etc., are only used to distinguish between different operations, and the serial numbers themselves do not represent any order of execution. In addition, these processes may include more or fewer operations, and these operations may be executed in sequence or in parallel. It should be noted that the descriptions of "first", "second", etc. in this document are used to distinguish different messages, devices, modules, etc., and do not represent a sequential order, nor do they limit "first" and "second" to being different types.
[0061] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without making creative efforts are within the scope of protection of this application.
[0062] Figure 1 A flowchart of a method for reversely analyzing the physical layer characteristics of a radio frequency chip provided in an embodiment of the present application is shown in FIG. Figure 1 As shown, the method includes:
[0063] 101. Configure a software environment for the radio frequency chip with unknown physical layer configuration characteristic information. After the software environment configuration is completed, program code on two development boards carrying the radio frequency chip, and use one program-programmed development board as a transmitter and the other program-programmed development board as a receiver.
[0064] Unknown physical layer configuration characteristics refer to the specific parameters used within the radio frequency (RF) chip to process signal transmission and reception. These parameters include, but are not limited to, modulation mode, coding scheme, and error detection mechanism. In the absence of technical documentation or official support from the manufacturer, this information is considered "unknown."
[0065] A radio frequency chip is an integrated circuit that is responsible for high-frequency signal processing tasks in wireless communication systems, such as signal transmission, reception, and related processing;
[0066] The software environment refers to a set of operating systems and application software frameworks built for the operation of RF chips, including necessary drivers, library files, and development tool chains to ensure that they can correctly interact with the hardware and perform the intended functions;
[0067] Code burning means writing the prepared control program into the non-volatile memory on the development board so that the program can be directly loaded and executed during subsequent operations;
[0068] The transmitter is the party responsible for sending data in a communication system, which transmits information to the other end by modulating the signal.
[0069] The receiving end is the party responsible for receiving and decoding the signal and extracting the original data from the received signal.
[0070] In practice, to begin the reverse engineering process, a software environment suitable for the RF chip must be set up. This involves installing a specific operating system and programming interfaces to ensure the chip can be programmed and monitored. Once the software environment is set up, the next step is to flash the code onto the two development boards carrying the RF chip. This involves writing pre-written test programs onto the boards. One development board is designated as the transmitter, serving as the signal source; the other as the receiver, capturing and analyzing the transmitted data packets.
[0071] For example, a typical wireless sensor network might be faced with RF chips from different vendors whose detailed physical layer characteristics are not publicly available. To understand and optimize the behavior of these chips, we configured a Linux embedded operating system according to the aforementioned steps and used an open-source platform such as GNU Radio as the foundation for the software environment. We then selected two development boards based on different models of RF chips from the same series and burned customized firmware into each board. One board served as the transmitter and the other as the receiver, preparing for the next step in the data processing process.
[0072] 102. Control the transmitting end to perform a forward operation in the data processing flow, and control the receiving end to perform a reverse operation in the data processing flow;
[0073] The data processing process covers all stages from raw data generation to final transmission or reception, including key links such as error detection, channel encoding and decoding, signal shaping, time domain dispersion, and carrier modulation.
[0074] Forward operation means that the transmitter processes the data according to preset rules, such as adding redundant check bits, encoding the data stream, whitening the signal, etc., to make it ready for transmission;
[0075] The reverse operation refers to the receiving end performing the opposite process, such as removing redundant check bits, decoding data streams, and de-whitening signals, to restore the original data.
[0076] In practice, the data processing logic on both the transmitter and receiver sides needs to be configured separately. On the transmitter side, this means activating a series of functions required to prepare data for transmission, such as cyclic redundancy check (CRC) generation, channel coding, and whitening. The receiver side, on the other hand, needs to be configured to understand and process the results of these operations, enabling the appropriate CRC checking, decoding, and de-whitening functions. Furthermore, irrelevant functions must be disabled to avoid interfering with the intended data processing.
[0077] For example, continuing with the embodiment of step 101, in the application scenario of a wireless sensor network, the CRC generation function is enabled on the transmitting end, while unnecessary coding, interleaving, and modulation options are disabled. This is done to focus on studying the error detection mechanism. At the same time, only the CRC check function is enabled on the receiving end, and the other functions remain disabled. Next, the transmitting end generates a series of data packets with CRC check bits, and observes how the receiving end processes these data packets, thereby inferring the specific behavior pattern of the RF chip in error detection. The same method can also be applied to the study of other data processing links.
[0078] 103. Perform reverse analysis on all data generated by the transmitting end and the receiving end in the data processing flow to obtain physical layer characteristic information of the radio frequency chip.
[0079] Reverse engineering refers to the process of analyzing known outputs (in this case, the communication data between the transmitter and receiver) to infer the internal algorithms or configuration parameters that produce these outputs.
[0080] Physical layer characteristic information refers to the specific details about how the RF chip processes and transmits data at the lowest level, such as the modulation technology used, coding strategy, error control method, etc.
[0081] In practice, the data collected in the previous steps is used to conduct detailed reverse engineering analysis. This involves comparing the data sent by the transmitter with the data received by the receiver, identifying which changes are caused by the data processing mechanisms within the RF chip. This method can gradually restore the RF chip's physical layer configuration information, including but not limited to the encoding method, error detection mechanism, and signal shaping parameters.
[0082] For example, continuing with the above example, by comparing the data packets generated by the transmitter with those received by the receiver, it is possible to determine how the RF chip performs during error detection, such as which CRC algorithm it uses and the length of the CRC check bits. Furthermore, this approach can be extended to channel encoding and decoding, signal shaping, and other data processing steps, analyzing the behavioral characteristics of the RF chip in each step.
[0083] Through the implementation of steps 101 to 103, this method provides a systematic means to automatically and accurately analyze the physical layer characteristics of RF chips. This approach not only improves analysis efficiency and reduces reliance on specialized test equipment, but also enhances the accuracy of the results by separating the various data processing steps. Furthermore, it promotes transparency and technological advancement in the field of RF technology, providing strong support for fault diagnosis, safety assessments, and innovative research. Examples demonstrate the high flexibility and adaptability of this method in practical applications, enabling effective analysis of different types of RF chips, providing valuable information for subsequent product development and optimization.
[0084] In order to solve the problem of mutual interference among various data processing links during the analysis of the physical layer characteristics of the radio frequency chip and further improve the accuracy and efficiency of the analysis, in some embodiments, the data processing flow in step 102 includes at least one of the following data processing links: an error detection link, a channel encoding and decoding link, a signal shaping link, a time domain dispersion link, and a carrier modulation link;
[0085] The controlling the transmitting end to perform a forward operation in the data processing flow and the controlling the receiving end to perform a reverse operation in the data processing flow comprises at least one of the following steps:
[0086] For the error detection link, the cyclic redundancy check bit generation function corresponding to the transmitting end and the error detection link is enabled, and the encoding function, whitening function, interleaving function and modulation function are not enabled; the cyclic redundancy check function corresponding to the receiving end and the error detection link is enabled, and the decoding function, dewhitening function, deinterleaving function and demodulation function are not enabled; for the channel coding and decoding link, the encoding function corresponding to the transmitting end and the channel coding and decoding link is enabled, and the cyclic redundancy check bit generation function, whitening function, interleaving function and modulation function are not enabled; the decoding function corresponding to the receiving end and the channel coding and decoding link is enabled, and the cyclic redundancy check function, dewhitening function, deinterleaving function and demodulation function are not enabled; for the signal shaping link, the whitening function corresponding to the transmitting end and the signal shaping link is enabled, and the cyclic redundancy check bit generation function, encoding function, interleaving function and modulation function are not enabled. The interleaving function and modulation function are enabled, the de-whitening function corresponding to the receiving end and the signal shaping link is enabled, and the cyclic redundancy check function, decoding function, de-interleaving function and demodulation function are not enabled; for the time domain dispersion link, the interleaving function corresponding to the transmitting end and the time domain dispersion link is enabled, the cyclic redundancy check bit generation function, encoding function, whitening function and modulation function are not enabled, the de-interleaving function corresponding to the receiving end and the time domain dispersion link is enabled, and the cyclic redundancy check function, decoding function, de-whitening function and demodulation function are not enabled; for the carrier modulation link, the modulation function corresponding to the transmitting end and the carrier modulation link is enabled, the cyclic redundancy check bit generation function, encoding function, whitening function and interleaving function are not enabled, the demodulation function corresponding to the receiving end and the carrier modulation link is enabled, and the cyclic redundancy check function, decoding function, de-whitening function and de-interleaving function are not enabled.
[0087] In this embodiment, the error detection step aims to ensure the integrity of data transmission by adding additional data (such as cyclic redundancy check bits (CRC)) at the transmitting end and verifying this data at the receiving end to detect errors that may occur during the transmission process. CRC is a common error detection method that calculates the remainder of a polynomial division and appends it to the data packet as a check value.
[0088] Channel encoding and decoding: This involves converting raw data into a form suitable for transmission over a communication channel (encoding), and restoring the received data to its original form at the receiving end (decoding). This includes, but is not limited to, encoding methods such as convolutional codes and turbo codes. The primary purpose of encoding is to improve the reliability and efficiency of data transmission, while decoding refers to the process of extracting the original information from the received modulated signal.
[0089] Signal shaping: This involves processing a signal to improve its transmission characteristics, such as reducing interference or improving noise immunity. Whitening is a technique used in this process to make the signal spectrum more uniform. This randomizes the data sequence to reduce the likelihood of long strings of identical bits, thereby eliminating DC and low-frequency components in the signal, making the signal more suitable for certain types of transmission channels.
[0090] Time-domain dispersion: Also known as interleaving, it improves error correction by rearranging the data sequence to disperse the effects of burst errors. Interleaving prevents consecutive errors from affecting large amounts of data because previously adjacent data is now dispersed. Deinterleaving is the process of restoring the original data order at the receiver, typically matching the interleaving pattern used at the transmitter.
[0091] Carrier modulation: This is responsible for loading information onto a high-frequency carrier for wireless transmission. Common modulation methods include ASK (amplitude shift keying), FSK (frequency shift keying), and PSK (phase shift keying). Demodulation, on the other hand, involves extracting the original information from the received modulated signal. Modulation and demodulation are fundamental processes for wireless communication, determining how signals are transmitted over the physical medium.
[0092] Cyclic redundancy check (CRC) bit generation: This is part of the error detection process. The transmitter uses a specific algorithm to generate a check value (usually a polynomial division result based on the input data) and appends it to the packet. This check value is used by the receiver to verify whether the packet has been altered during transmission.
[0093] Decoding: During the channel encoding and decoding phase, the receiver uses the inverse algorithm of the transmitter to decode the received data stream and recover the original information content. For convolutional codes, the receiver will perform maximum likelihood estimation using the Viterbi algorithm or other appropriate decoding algorithms to reconstruct the original data as accurately as possible.
[0094] Whitening: During signal shaping, whitening is applied at the transmitter to eliminate or reduce signal redundancy and flatten the signal spectrum. Whitening can be achieved using mechanisms such as linear feedback shift registers (LFSRs), which disrupt the data sequence according to specific rules while preserving the meaning of the data.
[0095] Interleaving: In the time-domain dispersion phase, the transmitter reorders data blocks according to a predetermined rule to increase the data's resistance to sudden errors. The interleaver disperses consecutive data fragments into different time positions, so that even if strong interference occurs for a short period of time, it will not cause a large amount of data corruption.
[0096] Modulation: In the carrier modulation phase, the transmitter maps binary data into an analog signal suitable for wireless transmission based on the selected modulation scheme. For example, in QPSK modulation, each symbol carries two bits of information and is represented by four different phase angles.
[0097] De-whitening function: During the signal shaping process, the receiver performs the opposite operation of the transmitter, namely, canceling the whitening effect and restoring the original data sequence. This process must be completely synchronized with the whitening algorithm used by the transmitter to accurately restore the data.
[0098] Deinterleaving: During time-domain dispersion, the receiver rearranges the data using the same rules as the transmitter to restore the original data order. The deinterleaver needs to know the interleaving pattern used by the transmitter to accurately reverse the interleaving process.
[0099] Demodulation: During carrier modulation, the receiver extracts the original information from the modulated signal, reversing the modulation performed by the transmitter. The demodulator selects an appropriate algorithm based on the specific modulation type to interpret the signal. For example, for QPSK modulation, the demodulator determines the bit combination represented by each symbol based on the received phase information.
[0100] In the embodiment of the present application, the operating modes of the transmitter and receiver are configured respectively for the five key links in the data processing flow of the RF chip - error detection, channel coding and decoding, signal shaping, time domain dispersion and carrier modulation; for each link, the transmitter performs a forward operation, that is, enables the specific function related to the link (such as the CRC generation function in the error detection link) and disables other irrelevant functions (such as encoding, whitening, interleaving and modulation); at the same time, the receiver is set to a reverse operation mode, only activating the inspection or decoding function corresponding to the transmitter, and turning off all other irrelevant options; such a design ensures that the data processing of each link can be analyzed independently and accurately, avoiding mutual interference between different functions.
[0101] Here's a specific example:
[0102] In a real-world wireless sensor network scenario, the goal is to analyze the physical layer characteristics of an unknown RF chip. First, the cyclic redundancy check (CRC) generation function is enabled on the transmitter side during error detection, while encoding, whitening, interleaving, and modulation functions are disabled to focus solely on the CRC generation mechanism. The receiver then enables the CRC check function, while all other functions remain disabled.
[0103] Next, during the channel encoding and decoding phase, encoding functions (such as convolutional coding) were activated on the transmitter side, while decoding functions were correspondingly enabled on the receiver side, with all other non-relevant functions remaining disabled. To study the signal shaping phase, the transmitter was configured to process the signal using only whitening, while the receiver was dedicated to de-whitening, again eliminating other factors that could affect the results. When it came to time-domain dispersion, the transmitter applied only interleaving to alter the temporal distribution of the data stream, while the receiver focused on de-interleaving to restore the original data order.
[0104] Finally, during the carrier modulation phase, the transmitter is configured to execute a specific modulation scheme (such as QPSK), while the receiver is responsible for the corresponding demodulation operation. By implementing this fine-grained control strategy for each phase in turn, not only can the behavioral characteristics of the RF chip at each data processing stage be analyzed individually, but mutual interference between different functions can also be effectively avoided, improving the accuracy and reliability of the analysis results. The entire process demonstrates how to systematically isolate and analyze each data processing step, thereby fully understanding the operating principles of the RF chip.
[0105] In order to solve the problem of inaccurate acquisition of physical layer characteristic information of the RF chip and further improve the accuracy and depth of the analysis, in some embodiments, the reverse analysis is performed based on all data generated by the transmitting end and the receiving end in the data processing flow to obtain the physical layer characteristic information of the RF chip, including:
[0106] When the data processing flow includes a time domain dispersion link, reverse analysis is performed based on the data generated by the transmitting end in the time domain dispersion link and the data generated by the receiving end in the time domain dispersion link to obtain physical layer characteristic information of the RF chip, where the physical layer characteristic information includes interleaving block size and interleaving block data position change information.
[0107] In this embodiment, the time domain dispersion step, also known as interleaving, disperses the impact of burst errors by rearranging the data sequence, thereby improving error correction capabilities. Interleaving can prevent consecutive errors from affecting a large amount of data because previously adjacent data is now dispersed. Deinterleaving refers to the process of restoring the original data sequence at the receiving end, which usually matches the interleaving pattern at the transmitting end.
[0108] Interleaving block size: This refers to the size of the units or "blocks" into which data is processed during the interleaving process. The data in each interleaving block is reordered according to a specific algorithm to achieve temporal dispersion. Understanding the interleaving block size is crucial for analyzing the physical layer characteristics of RF chips, as it directly affects the reliability and efficiency of data transmission.
[0109] Interleaved block data position change information: This refers to how the specific position of the original data in the new sequence changes after the interleaving process. This change information reveals the specific details of the interleaving algorithm and is very important for reverse engineering and understanding the internal working principles of RF chips.
[0110] In an embodiment of the present application, in the process of analyzing the physical layer characteristics of the radio frequency chip, when it comes to the time domain dispersion (interleaving) link, reverse analysis is performed using the data generated by the transmitting end and the data received by the receiving end.
[0111] Specifically, the transmitter interleaves the data before transmission, reordering it according to specific rules. The receiver performs the reverse operation—deinterleaving—to restore the original data. By comparing the data sent by the transmitter with the data received by the receiver, the exact parameters used by the RF chip during interleaving, such as the interleaving block size and the positional changes of the data within the block, can be inferred. This approach allows for detailed analysis and understanding of the RF chip's behavior during this critical data processing step, providing a foundation for subsequent technical optimization.
[0112] Here's a specific example:
[0113] Continuing with the implementation steps from the previous wireless sensor network case study, after analyzing error detection, channel coding and decoding, signal shaping, and carrier modulation, we now turn to time-domain interleaving. To precisely analyze the interleaving mechanism of the RF chip, a test program was configured on the transmitter side. This program generates a series of packets with a known structure and transmits them with interleaving enabled. The receiver also enabled the corresponding deinterleaving function and recorded the received data.
[0114] Next, they compared the data packets sent by the transmitter with those received by the receiver, focusing specifically on the data position changes caused by the interleaving process. This method not only determined the interleaving block size used by the RF chip, but also revealed the specific patterns of data position changes within the interleaved blocks.
[0115] For example, they discovered that certain data bits appeared in new positions after interleaving, indicating the existence of a characteristic of the interleaving algorithm. Further experiments and data analysis gradually built a complete picture of the interleaving characteristics of RF chips, including key parameters such as the interleaving pattern and interleaving depth. This series of analytical work provides valuable insights into the working mechanisms of RF chips and lays a solid foundation for further optimization of wireless communication systems.
[0116] In order to solve the problem of difficulty in accurately obtaining the interleaving block size and data position change information of the RF chip and further improve the accuracy and reliability of the analysis, in some embodiments, reverse analysis is performed based on the data generated by the transmitting end in the time domain dispersion link and the data generated by the receiving end in the time domain dispersion link to obtain the physical layer characteristic information of the RF chip, where the physical layer characteristic information includes the interleaving block size and the interleaving block data position change information, including:
[0117] Step 11, initialize two parameters n and k1, where n is the number of bytes, n is an integer greater than or equal to 1, and k1 is a coefficient, k1=1; Step 12, generate first repeated data in units of n bytes at the transmitting end as test data, the test data is interleaved when the interleaving function is enabled, and the receiving end obtains the first interleaved data; Step 13, determine whether the first interleaved data is in units of n bytes; if the first interleaved data is not in units of n bytes, execute Step 14; or, if the first interleaved data is in units of n bytes, execute Step 15; Step 14, update n by accumulating, and repeat Steps 12 to 13; Step 15, generate multiple groups of second repeated data in units of n bytes at the transmitting end data, as multiple groups of verification data, the multiple groups of verification data are interleaved when the interleaving function is enabled, and the receiving end obtains multiple groups of second interleaved data, and each group of second repeated data is not equal to the first repeated data; step 16, judging whether the multiple groups of second interleaved data are all in units of n bytes; if the multiple groups of second interleaved data are not in units of n bytes, executing step 17; or, if the multiple groups of second interleaved data are all in units of n bytes, executing step 18; step 17, updating k1 by accumulation, updating n by using the product result of k1 and n, and repeating steps 15 to 16; step 18, determining that the interleaved block size is n, and triggering the interleaved block data position change process to obtain interleaved block data position change information.
[0118] In this embodiment, the number of bytes (n) refers to the basic unit of data, that is, the number of bytes. In radio frequency communications, data is usually processed and transmitted in bytes. Here, n represents the assumed interleaving block size, which is the basic unit used to test the interleaving effect.
[0119] Coefficient (k1): This is a parameter used to adjust the interleaving block size and is initially set to 1. As the parsing process progresses, if the currently assumed interleaving block size is found to be incorrect, k1 is updated cumulatively and the new interleaving block size is redefined using the product of k1 and n.
[0120] First repeated data: This refers to a set of data with a specific pattern generated by the transmitter, usually consisting of identical or similar data units. This data is sent to the receiver after interleaving to initially verify the assumption of the interleaving block size.
[0121] Multiple sets of verification data: To further confirm the interleaving block size and ensure the reliability of the results, the transmitter also generates multiple sets of repeated data as verification data. These data are also interleaved and compared with the previous results.
[0122] Interleaved data: refers to the data stream after the interleaving process. Since interleaving changes the location distribution of the original data, it is necessary to conduct a detailed analysis of the interleaved data to determine the specific interleaving algorithm and parameters.
[0123] Interleaved block data position change information: describes how the specific position of the original data in the new sequence changes after the interleaving process; this is crucial for understanding the interleaving mechanism and its impact.
[0124] In the embodiment of the present application, in order to accurately analyze the behavioral characteristics of the RF chip in the time domain dispersion (interleaving) link, a systematic reverse analysis process is designed.
[0125] First, two key parameters n (number of bytes) and k1 (coefficient) are initialized, where n represents the assumed interleaving block size and k1 is used as a tool to adjust n.
[0126] Next, the transmitter generates a series of first repeated data in units of n bytes as test data and enables the interleaving function to process the data. After receiving the interleaved data, the receiver checks whether the data still maintains the structure in units of n bytes.
[0127] If the conditions are not met, the value of n is increased and the above steps are repeated. Otherwise, the process proceeds to the next stage, using multiple sets of different verification data for more in-depth testing. If all verification data meets expectations, the final interleaving block size is determined to be n, and further steps are triggered to obtain detailed information about the changes in data positions within the interleaving block. This series of operations accurately restores the workings of the RF chip during the interleaving process.
[0128] Here's a specific example:
[0129] Continuing with the implementation steps in the wireless sensor network case, we will now focus on analyzing the time-domain dispersion (interleaving) characteristics of the RF chip. Following the aforementioned scheme, we first initialized two parameters: n = 1 (number of bytes) and k1 = 1 (coefficient). Then, the transmitter generated a set of first-order repeating data in units of n bytes as test data. This data was then transmitted after enabling interleaving. Upon receiving the interleaved data, the receiver immediately checked whether the data still maintained the n-byte structure. The results showed that the data from the first attempt did not meet expectations, so the value of n was updated through cumulative calculations, and the above steps were repeated until an appropriate interleaving block size was found.
[0130] Once the initial interleaving block size is determined, multiple different sets of verification data are generated. Each set is also based on the assumed n-byte unit, but the content differs from the initial first-repeated data. These verification data are interleaved again and sent to the receiver. All second-interleaved data received by the receiver is carefully compared to ensure that they all maintain the n-byte unit structure. If any set of data does not meet the expected structure, the verification process is repeated by accumulating k1 and updating n using the product of k1 and n. Finally, when all verification data are confirmed to meet the expected structure, the actual interleaving block size of the RF chip can be determined to be n.
[0131] This triggers the next step: the interleaved block data position change process. This step aims to record the position change of each bit before and after the interleaving process in detail, thereby fully understanding the specific implementation of the interleaving algorithm.
[0132] For example, the observation that certain bits appeared in new positions after interleaving provided important clues about the interleaving pattern. This method not only successfully determined the interleaving block size of the RF chip, but also provided a deep understanding of the positional variations of data within the interleaved block, laying a solid foundation for further optimizing the performance of wireless communication systems. The entire analysis process demonstrates how scientific methodologies and technical means can gradually reveal the complex data processing mechanisms within RF chips.
[0133] To address the difficulty in accurately capturing interleaved block data position change information of the RF chip and further improve the accuracy and completeness of analysis, in some embodiments, triggering an interleaved block data position change process to obtain interleaved block data position change information includes:
[0134] Step 21, initialize the interleaving block size to n, parameter k2=1, indicating the first byte, a=1, indicating the first bit; Step 22, at the transmitting end, set the a-th bit of the k2-th byte to 1 and the remaining bits to 0 to generate non-repeating data in units of the interleaving block size n, and perform interleaving processing when the interleaving function is enabled; Step 23, determine the position change information of the value 1 based on the third interleaved data received by the receiving end; Step 24, determine whether k2 is equal to n and whether a is equal to 8; if If the conditions are not met simultaneously, execute step 25; or, if the conditions are met simultaneously, execute step 28; in step 25, determine whether a is less than 8. If a is less than 8, execute step 26; if a is equal to 8, execute step 27; in step 26, update a by accumulation and repeat steps 22 to 24; in step 27, update k2 by accumulation, reset a to 1, and execute steps 22 to 24; in step 28, generate interleaved block data position change information based on the position change information of all values 1.
[0135] In this embodiment, parameters k2 and a are used: k2 represents the number of the byte currently being processed, counting from 1; a represents the bit position within the current byte, ranging from 1 to 8. These two parameters are used to activate bits at different positions within the interleaved block one by one, so as to accurately track their changes after interleaving.
[0136] Third, interleaved data refers to the data received by the receiving end. This data has been interleaved by the transmitting end. By analyzing this data, the specific movement path of the original bits during the interleaving process can be determined.
[0137] Position changes of the value 1: When the transmitter sets a specific bit to 1 and sends it, the new position of that bit in the data received by the receiver reflects the effect of the interleaving process. Recording these position changes helps understand how the interleaving algorithm works.
[0138] Non-repeating data: This type of data means that the data content generated by the transmitter during each test is different from any previous test; in this way, it can be ensured that each round of testing is independent and verifiable, thereby improving the accuracy of the analysis results.
[0139] In this embodiment, a detailed reverse engineering process was designed to deeply analyze the position changes of interleaved block data in the RF chip. First, the interleaved block size was initialized to the known value n, and two parameters were set: k2 = 1 (indicating the first byte) and a = 1 (indicating the first bit).
[0140] Next, the transmitter performs the following operation for each bit position in each interleaved block: The ath bit of the k2th byte is set to 1, and all other bits are set to 0, generating a unique, non-repeating set of data, and enabling the interleaving function to process it. Upon receiving this interleaved data, the receiver records the specific position of the value 1. By gradually increasing the values of k2 and a, every bit position in the interleaved block is traversed until all bits have been tested.
[0141] Finally, based on the collected position change information of all the value 1s, a complete interleaved block data position change map can be constructed, which provides detailed insights into the interleaving characteristics of the RF chip.
[0142] Here's a specific example:
[0143] Continuing with the above example, after successfully determining the interleaving block size of the RF chip, we now turn to analyzing the changes in the interleaving block data position. According to the aforementioned scheme, we first initialize the interleaving block size to the previously determined n, and set the parameter k2 to 1 (indicating the first byte) and a to 1 (indicating the first bit).
[0144] Then, at the transmitter, bit a of the k2th byte is set to 1, while all other bits are set to 0, generating a unique, non-repeating data set. This data set is transmitted after interleaving is enabled. The data received by the receiver is the data after the third interleaving. This data is carefully analyzed, and the specific positions of the value 1 after interleaving are recorded.
[0145] As the test progresses, the values of k2 and a are continuously updated to cover every bit position within the interleaved block. Whenever a is less than 8, a is updated incrementally and the above steps are repeated. Once a reaches 8, indicating that all bits within a byte have been tested, k2 is incremented by 1, a is reset to 1, and testing continues with the next byte. This process continues until k2 equals the interleaved block size n and a reaches 8, indicating that all bit positions within the entire interleaved block have been exhaustively tested and recorded.
[0146] Finally, a complete map of the interleaved block data position changes is generated based on the position changes of all 1 bits. This map not only shows the specific movement path of each bit before and after the interleaving process, but also reveals the internal workings of the interleaving algorithm.
[0147] For example, they discovered that certain bits exhibited regular position shifts after interleaving, providing important clues about the interleaving pattern. This approach not only provided a deep understanding of the interleaving characteristics of RF chips but also laid a solid foundation for optimizing the performance of wireless communication systems. The entire analysis process demonstrated how systematic experiments and technical approaches can gradually reveal the complex data processing mechanisms within RF chips, further promoting the research and development of previously unknown RF chips.
[0148] In order to solve the problem that it is difficult to directly obtain the physical layer characteristic information of the RF chip and further improve the understanding and optimization capabilities of the internal mechanism of the RF chip, in some embodiments, the physical layer characteristic information of the RF chip is obtained by reverse parsing all the data generated by the transmitting end and the receiving end in the data processing flow, including:
[0149] In the case where the data processing flow includes a channel encoding and decoding link, reverse parsing is performed based on all data generated by the transmitting end and the receiving end in the channel encoding and decoding link to obtain physical layer characteristic information of the RF chip. The physical layer characteristic information includes the encoding method adopted by the encoding function. When the encoding method includes a convolutional code, the convolutional code includes a generating polynomial and a code rate.
[0150] In this embodiment, the channel encoding and decoding process involves converting original data into a form suitable for transmission over a communication channel (encoding), and restoring the received data to its original form at the receiving end (decoding). This includes, but is not limited to, encoding schemes such as convolutional codes and turbo codes. The main purpose of encoding is to improve the reliability and efficiency of data transmission, while decoding refers to the process of extracting the original information from the received modulated signal.
[0151] Coding method: This refers to the specific algorithm or method used to process data to enhance its transmission performance. Different coding methods have their own advantages and disadvantages and are suitable for different communication scenarios. For example, convolutional codes are widely used in many wireless communication systems due to their strong error correction capabilities.
[0152] Convolutional code: A linear block code that depends not only on the current input bit but also on a series of previous input bits to generate the output bit sequence. Convolutional codes provide good error detection and correction capabilities and are particularly well-suited for channels with bursty errors.
[0153] Generator polynomial: This is a mathematical expression used in the convolutional code encoding process to define how the encoder generates redundant bits based on the input bit stream. The specific form of the generator polynomial determines the structure of the encoded data and its error correction properties.
[0154] Bit rate: Indicates the proportional relationship between the amount of data before and after encoding, usually expressed as R=k / n, where k is the number of original information bits and n is the total number of bits after encoding (including redundant bits). A lower bit rate means more redundant information is added, thereby improving error correction capabilities but reducing transmission efficiency; vice versa.
[0155] In the embodiment of the present application, a reverse engineering method is used to accurately analyze the behavioral characteristics of the radio frequency chip in the channel encoding and decoding link. First, all data generated by the transmitting end and the receiving end in this link need to be collected.
[0156] Detailed analysis of this data then allows the inference of the specific encoding scheme used by the RF chip. If a convolutional code is confirmed, further investigation is conducted into key parameters such as the generator polynomial and bit rate. This process not only helps understand the data processing mechanisms within the RF chip but also provides valuable insights for optimizing communication system performance. This approach accurately demonstrates the operating principles of the RF chip at the physical layer, laying a solid foundation for further technological improvements.
[0157] Here's a specific example:
[0158] Continuing with the above example, after a detailed analysis of the time-domain interleaving phase, we now turn to the channel encoding and decoding phase. To reveal the physical layer characteristics of the RF chip in this phase, we first ensure that both the transmitter and receiver are configured to enable only functions related to channel encoding and decoding. Specifically, the transmitter activates only encoding, while the receiver is dedicated to decoding. This eliminates interference from other functions and allows for a focused analysis of the encoding scheme.
[0159] Next, a series of tests were designed to collect data packets sent by the transmitter and received by the receiver. These packets contained encoded information, providing key material for reverse engineering. Comparing and analyzing this data revealed certain patterns and regularities, suggesting that the RF chip may have employed convolutional coding as its encoding method. To verify this hypothesis, further investigation was conducted into the structure of the encoded data, focusing specifically on the distribution of redundant bits.
[0160] Based on the analysis of the redundant bit positions, the convolutional code's generator polynomial was successfully identified. Furthermore, the ratio of the amount of data before and after encoding was calculated to determine the code rate of the convolutional code. For example, it was found that each original information bit was expanded into multiple coded bits, and that these coded bits had a fixed mathematical relationship, which is a reflection of the convolutional code's generator polynomial. Furthermore, the code rate reflects the degree of redundant information added. A lower code rate means stronger error correction capabilities, but also sacrifices a certain degree of transmission efficiency.
[0161] Ultimately, this method not only confirmed that the RF chip used a convolutional code, but also accurately analyzed its generator polynomial and code rate, two key parameters. This information is crucial for understanding and optimizing the working mechanisms of RF chips and provides important technical support for the subsequent development of more efficient and reliable wireless communication systems. The entire analysis process demonstrates how, through systematic experiments and technical means, the complex data processing mechanisms within RF chips can be gradually revealed, further promoting the research and development of unknown RF chips.
[0162] In order to solve the problem of difficulty in accurately obtaining the physical layer characteristic information of the RF chip (such as the whitening sequence and cyclic redundancy check parameters) and further improve the accuracy and reliability of the analysis, in some embodiments, reverse analysis is performed based on all data generated by the transmitting end and the receiving end in the data processing flow to obtain the physical layer characteristic information of the RF chip, including:
[0163] In the case where the data processing flow includes a signal shaping link, the maximum length is determined according to a preset RF chip manual, all-zero data of the maximum length is sent at the transmitting end, and reverse analysis is performed by comparing the all-zero data with the data received at the receiving end to obtain a whitening sequence of the RF chip; in the case where the data processing flow includes an error detection link, the preset standard length is obtained through the preset RF chip manual, cyclic redundancy check bits are generated at the transmitting end according to the preset standard length, data with cyclic redundancy check bits are sent to the receiving end, the cyclic redundancy check bits of the data sent by the transmitting end and the cyclic redundancy check bits of the data received by the receiving end are compared, if the comparison result is inconsistent, multiple initial values are obtained by an exhaustive method, the cyclic redundancy check bits generated based on each initial value are compared with the cyclic redundancy check bits of the data sent by the transmitting end, so as to perform reverse analysis and obtain the cyclic redundancy check parameters of the RF chip, the cyclic redundancy check parameters including: the initial value corresponding to the cyclic redundancy check bit when the comparison is consistent.
[0164] In this embodiment, the signal shaping step refers to processing the signal to improve its transmission characteristics, such as reducing interference or improving noise immunity. Whitening is a technique in this step used to make the signal spectrum more uniform. This technique randomizes the data sequence to reduce the possibility of long strings of identical bits, thereby avoiding DC components and low-frequency components in the signal, making the signal more suitable for certain types of transmission channels.
[0165] Whitening sequence: This refers to a series of pseudo-random bit patterns applied during signal shaping to disrupt the structure of the original data sequence and ensure the flatness of the signal spectrum. Understanding the whitening sequence is crucial for analyzing the physical layer characteristics of RF chips, as it directly affects signal transmission quality.
[0166] All-zero data: refers to a bit stream consisting of a series of consecutive zeros; this data pattern is often used to test system behavior, especially when specific functions (such as whitening) need to be verified, because of its simplicity and predictability;
[0167] Maximum length: The maximum size of a data block determined by the preset RF chip manual; sending all-zero data of the maximum length ensures that the entire possible data range is covered, thus providing the most comprehensive test results;
[0168] Error detection: This step aims to ensure the integrity of data transmission by adding additional data (such as cyclic redundancy check bits (CRC)) at the transmitting end and verifying this data at the receiving end to detect errors that may occur during the transmission process;
[0169] Cyclic Redundancy Check (CRC): A commonly used error detection method that calculates the remainder of a polynomial division as a check value and appends it to the data packet. The receiver recalculates the check value using the same algorithm and compares it with the received check value to verify data integrity.
[0170] Preset standard length: Determine the fixed size of the input data block required to generate the CRC based on the information provided in the RF chip manual; this helps ensure that all tests are performed on a consistent basis, facilitating comparison and analysis of results;
[0171] Initial value: The starting value used when generating CRC, usually a fixed binary number. Different initial values will result in different CRC check bits. Therefore, parsing the correct initial value is crucial for accurately understanding how the RF chip works.
[0172] Exhaustive search: When it is not feasible to directly obtain the correct initial value, you can search by trying all possible initial values; although this method is computationally expensive, it is very effective when other methods cannot reach a conclusion.
[0173] In the embodiment of the present application, a reverse engineering method is designed to accurately analyze the physical layer characteristics of the radio frequency chip in the signal shaping and error detection links.
[0174] First, during the signal shaping phase, the transmitter sends all-zero data of the maximum length specified in the RF chip manual. This data is then whitened and sent to the receiver. By comparing the received data with the original all-zero data, the whitening sequence used by the RF chip can be reverse-engineered.
[0175] Then, in the error detection phase, data with a cyclic redundancy check (CRC) bit is generated according to the preset standard length and sent to the receiving end.
[0176] The CRC generated by the transmitter is then compared with the decoded CRC at the receiver. If the two do not match, an exhaustive search is performed to try multiple initial values until one is found that results in a CRC match. This approach not only helps understand how the RF chip handles error detection but also reveals the specific CRC parameters used internally, providing valuable insights for further optimizing communication system performance.
[0177] Here's a specific example:
[0178] Continuing with the above embodiment, after completing the study of the channel encoding and decoding link, we now turn to the analysis of the signal shaping and error detection links. In order to gain a deeper understanding of the behavioral characteristics of the RF chip in these two key links, we first focus on the signal shaping link. According to the information provided in the RF chip manual, the maximum length is determined to be 128 bytes, and the transmitter is configured to send all-zero data of the maximum length. These data are sent out after being whitened at the transmitter, and the receiving end records the actual data received. By comparing the two sets of data in detail, some regular changes were found, which are the result of the action of the whitening sequence. After further analysis, the whitening sequence used by the RF chip was successfully reverse-analyzed, which is of great significance for understanding and optimizing the quality of signal transmission.
[0179] Next, we turn to the study of error detection. According to the preset standard length provided in the manual, the transmitter is configured to generate data containing cyclic redundancy check bits (CRC) according to this length and send it to the receiver. At the receiver, the CRC in the received data packet is extracted and recorded. By comparing the CRC generated by the transmitter with the CRC decoded by the receiver, it was found that the two were not completely consistent. To find out the reason, an exhaustive method was used, trying multiple possible initial values until an initial value that could make the CRC match was found. This process not only helped confirm the CRC generating polynomial used by the RF chip, but also revealed its specific parameters such as the code rate. For example, it was found that using a specific initial value can ensure the accuracy of the CRC check bit, which provides important guidance for the subsequent development of more reliable data transmission mechanisms.
[0180] This approach not only provides a deep understanding of the physical layer characteristics of RF chips in signal shaping and error detection, but also lays a solid foundation for optimizing the performance of wireless communication systems. The entire analysis process demonstrates how systematic experiments and technical means can gradually reveal the complex data processing mechanisms within RF chips, further promoting the research and development of unknown RF chips.
[0181] Figure 2 A schematic diagram of the structure of a device (or system) for reversely analyzing the physical layer characteristics of a radio frequency chip provided in an embodiment of the present application is shown in FIG. Figure 2As shown, the device includes:
[0182] Configuration and programming module 21, used to configure the software environment of the RF chip with unknown physical layer configuration characteristics. After the software environment configuration is completed, code is programmed into two development boards carrying the RF chip, and one development board with the code programmed is used as the transmitter, and the other development board with the code programmed is used as the receiver.
[0183] A control module 22, configured to control the transmitting end to perform forward operations in the data processing flow, and control the receiving end to perform reverse operations in the data processing flow;
[0184] The reverse analysis module 23 is used to perform reverse analysis on all data generated by the transmitting end and the receiving end in the data processing flow to obtain the physical layer characteristic information of the radio frequency chip.
[0185] Figure 2 The device for reverse analysis of the physical layer characteristics of a radio frequency chip can perform Figure 1 The implementation principle and technical effects of the method for reverse parsing the physical layer characteristics of a radio frequency chip described in the illustrated embodiment will not be elaborated on here. The specific manner in which each module and unit performs operations in the device for reverse parsing the physical layer characteristics of a radio frequency chip in the above embodiment has been described in detail in the embodiments of the method and will not be elaborated on here.
[0186] In one possible design, Figure 2 The device for reversely analyzing the physical layer characteristics of a radio frequency chip in the embodiment shown can be implemented as a computing device, such as Figure 3 As shown, the computing device may include a storage component 31 and a processing component 32 .
[0187] The storage component 31 stores one or more computer instructions, wherein the one or more computer instructions are called and executed by the processing component 32 .
[0188] The processing component 32 is used to: configure the software environment of the RF chip with unknown physical layer configuration characteristic information; after the software environment configuration is completed, burn the code to two development boards carrying the RF chip, and use one development board with the code burned as the transmitter and the other development board with the code burned as the receiver; control the transmitter to perform forward operations in the data processing flow, and control the receiver to perform reverse operations in the data processing flow; perform reverse analysis based on all data generated by the transmitter and the receiver in the data processing flow to obtain the physical layer characteristic information of the RF chip.
[0189] The processing component 32 may include one or more processors to execute computer instructions to complete all or part of the steps in the above method. Of course, the processing component may also be implemented as one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to perform the above method.
[0190] The storage component 31 is configured to store various types of data to support operations on the terminal. The storage component can be implemented by any type of volatile or non-volatile memory device, or a combination thereof, such as random access memory (RAM), static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk.
[0191] Of course, a computing device may also include other components, such as input / output interfaces, display components, communication components, etc.
[0192] The input / output interface provides an interface between the processing component and the peripheral interface module, which can be an output device, an input device, etc.
[0193] The communication component is configured to facilitate, among other things, wired or wireless communications between the computing device and other devices.
[0194] Among them, the computing device can be a physical device or an elastic computing host provided by a cloud computing platform, etc. In this case, the computing device can refer to a cloud server, and the above-mentioned processing components, storage components, etc. can be basic server resources rented or purchased from the cloud computing platform.
[0195] The present application also provides a computer storage medium storing a computer program, wherein the computer program can achieve the above-mentioned Figure 1 The embodiment shown is a method for reverse engineering the physical layer characteristics of a radio frequency chip.
[0196] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0197] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e., they may be located in one location or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.
[0198] Through the above description of the embodiments, those skilled in the art will clearly understand that each embodiment can be implemented using software plus a necessary general-purpose hardware platform, or of course, hardware. Based on this understanding, the essence of the above technical solution, or the portion that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, or an optical disk, and includes a number of instructions for causing a computer device (such as a personal computer, server, or network device) to execute the methods described in each embodiment or certain portions of the embodiments.
[0199] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A method for reverse analysis of the physical layer characteristics of a radio frequency chip, characterized in that: Applications in embedded platforms, including: Configure the software environment for the RF chip with unknown physical layer configuration characteristics. After the software environment configuration is complete, burn the code to two development boards carrying the RF chip. Use one development board with the burned code as the transmitter and the other development board with the burned code as the receiver. Controlling the transmitting end to perform a forward operation in the data processing flow, and controlling the receiving end to perform a reverse operation in the data processing flow; Perform reverse analysis on all data generated by the transmitting end and the receiving end in the data processing flow to obtain physical layer characteristic information of the radio frequency chip; The data processing flow includes at least one of the following data processing links: error detection link, channel encoding and decoding link, signal shaping link, time domain dispersion link and carrier modulation link; The controlling the transmitting end to perform a forward operation in the data processing flow and the controlling the receiving end to perform a reverse operation in the data processing flow comprises at least one of the following steps: For the error detection link, enable the cyclic redundancy check bit generation function corresponding to the error detection link at the transmitting end, disable the encoding function, whitening function, interleaving function and modulation function, enable the cyclic redundancy check function corresponding to the error detection link at the receiving end, and disable the decoding function, dewhitening function, deinterleaving function and demodulation function; For the channel coding and decoding link, the encoding function corresponding to the transmitting end and the channel coding and decoding link is enabled, and the cyclic redundancy check bit generation function, whitening function, interleaving function and modulation function are not enabled; the decoding function corresponding to the receiving end and the channel coding and decoding link is enabled, and the cyclic redundancy check function, dewhitening function, deinterleaving function and demodulation function are not enabled; For the signal shaping link, enable the whitening function corresponding to the transmitting end and the signal shaping link, do not enable the cyclic redundancy check bit generation function, encoding function, interleaving function and modulation function, enable the dewhitening function corresponding to the receiving end and the signal shaping link, do not enable the cyclic redundancy check function, decoding function, deinterleaving function and demodulation function; For the time domain dispersion link, enable the interleaving function corresponding to the transmitting end and the time domain dispersion link, do not enable the cyclic redundancy check bit generation function, encoding function, whitening function and modulation function, enable the deinterleaving function corresponding to the receiving end and the time domain dispersion link, do not enable the cyclic redundancy check function, decoding function, dewhitening function and demodulation function; For the carrier modulation link, the modulation function corresponding to the transmitting end and the carrier modulation link is enabled, and the cyclic redundancy check bit generation function, encoding function, whitening function and interleaving function are not enabled. The demodulation function corresponding to the receiving end and the carrier modulation link is enabled, and the cyclic redundancy check function, decoding function, dewhitening function and deinterleaving function are not enabled.
2. The method according to claim 1, characterized in that The reverse parsing of all data generated by the transmitting end and the receiving end in the data processing flow to obtain the physical layer characteristic information of the radio frequency chip includes: When the data processing flow includes a time domain dispersion link, reverse analysis is performed based on the data generated by the transmitting end in the time domain dispersion link and the data generated by the receiving end in the time domain dispersion link to obtain physical layer characteristic information of the RF chip, where the physical layer characteristic information includes interleaving block size and interleaving block data position change information.
3. The method according to claim 2, characterized in that The method further comprises: performing reverse parsing on the data generated by the transmitting end in the time domain dispersion link and the data generated by the receiving end in the time domain dispersion link to obtain physical layer characteristic information of the radio frequency chip, wherein the physical layer characteristic information includes interleaving block size and interleaving block data position change information, including: Step 11, initialize two parameters n and k1, n is the number of bytes, n is an integer greater than or equal to 1, k1 is the coefficient, k1=1; Step 12: generating first repetitive data in units of n bytes at the transmitting end as test data, wherein the test data is interleaved when the interleaving function is enabled, and the receiving end obtains the first interleaved data; Step 13, determining whether the first interleaved data is in units of n bytes; if the first interleaved data is not in units of n bytes, executing step 14; or, if the first interleaved data is in units of n bytes, executing step 15; Step 14, updating n by accumulating, and repeating steps 12 to 13 until the first interleaved data is in units of n bytes; Step 15: generating, at the transmitting end, multiple sets of second repeated data in units of n bytes as multiple sets of verification data, wherein the multiple sets of verification data are interleaved when the interleaving function is enabled, and the receiving end obtains multiple sets of second interleaved data, wherein each set of second repeated data is not equal to the first repeated data; Step 16, determining whether the multiple sets of second interleaved data are all in units of n bytes; if the multiple sets of second interleaved data are not in units of n bytes, executing step 17; or if the multiple sets of second interleaved data are all in units of n bytes, executing step 18; Step 17, updating k1 by accumulation, and updating n by the product of k1 and n, and repeating steps 15 to 16 until the multiple sets of second interleaved data are all in units of n bytes; Step 18: Determine that the interleaved block size is n, and trigger the interleaved block data position change process to obtain interleaved block data position change information.
4. The method according to claim 3, characterized in that Triggering the interleaved block data position change process to obtain interleaved block data position change information includes: Step 21, initialize the interleaving block size to n, parameter k2=1, indicating the first byte, a=1, indicating the first bit; Step 22: at the transmitting end, setting the ath bit of the k2th byte to 1 and the remaining bits to 0 to generate non-repeating data in units of an interleaving block size n, and performing an interleaving process when the interleaving function is enabled; Step 23, determining position change information of the value 1 according to the third interleaved data received by the receiving end; Step 24, determine whether k2 is equal to n and whether a is equal to 8; if not, proceed to step 25; or, if both are satisfied, proceed to step 28; Step 25, determine whether a is less than 8. If a is less than 8, execute step 26; if a is equal to 8, execute step 27; Step 26: Update a by accumulating, and repeat steps 22 to 24 until a is equal to 8; Step 27: Update k2 by cumulative means, reset a to 1, and execute steps 22 to 24 until k2 equals n and a equals 8. Step 28: Generate interleaved block data position change information based on the position change information of all values 1.
5. The method according to claim 1, wherein The reverse parsing of all data generated by the transmitting end and the receiving end in the data processing flow to obtain the physical layer characteristic information of the radio frequency chip includes: In the case where the data processing flow includes a channel encoding and decoding link, reverse parsing is performed based on all data generated by the transmitting end and the receiving end in the channel encoding and decoding link to obtain physical layer characteristic information of the RF chip. The physical layer characteristic information includes the encoding method adopted by the encoding function. When the encoding method includes a convolutional code, the convolutional code includes a generating polynomial and a code rate.
6. The method according to claim 1, characterized in that Reverse analysis is performed on all data generated by the transmitter and the receiver in the data processing flow to obtain physical layer characteristic information of the RF chip, including: In the case where the data processing flow includes a signal shaping step, the maximum length is determined according to a preset RF chip manual, all-zero data of the maximum length is sent at the transmitting end, and reverse analysis is performed by comparing the all-zero data with the data received at the receiving end to obtain a whitening sequence of the RF chip; In the case where the data processing flow includes an error detection link, a preset standard length is obtained through a preset RF chip manual, a cyclic redundancy check bit is generated at the transmitting end according to the preset standard length, data with the cyclic redundancy check bit is sent to the receiving end, and the cyclic redundancy check bit of the data sent by the transmitting end is compared with the cyclic redundancy check bit of the data received by the receiving end. If the comparison result is inconsistent, multiple initial values are obtained through an exhaustive method, and the cyclic redundancy check bit generated based on each initial value is compared with the cyclic redundancy check bit of the data sent by the transmitting end for reverse analysis to obtain the cyclic redundancy check parameters of the RF chip. The cyclic redundancy check parameters include: an initial value corresponding to the cyclic redundancy check bit when the comparison is consistent; the initial value is a starting value used when generating the cyclic redundancy check bit, and different initial values will result in the generation of different cyclic redundancy check bits.
7. A reverse analysis system for the physical layer characteristics of a radio frequency chip, characterized in that: Applications in embedded platforms, including: The configuration and programming module is used to configure the software environment of the RF chip with unknown physical layer configuration characteristics. After the software environment configuration is completed, the code is programmed into two development boards carrying the RF chip. One development board with the programmed code is used as the transmitter, and the other development board with the programmed code is used as the receiver. A control module, configured to control the transmitting end to perform a forward operation in the data processing flow, and control the receiving end to perform a reverse operation in the data processing flow; A reverse parsing module, configured to perform reverse parsing on all data generated by the transmitting end and the receiving end in the data processing flow to obtain physical layer characteristic information of the radio frequency chip; The data processing flow includes at least one of the following data processing links: error detection link, channel encoding and decoding link, signal shaping link, time domain dispersion link and carrier modulation link; The controlling the transmitting end to perform a forward operation in the data processing flow and the controlling the receiving end to perform a reverse operation in the data processing flow comprises at least one of the following steps: For the error detection link, enable the cyclic redundancy check bit generation function corresponding to the error detection link at the transmitting end, disable the encoding function, whitening function, interleaving function and modulation function, enable the cyclic redundancy check function corresponding to the error detection link at the receiving end, and disable the decoding function, dewhitening function, deinterleaving function and demodulation function; For the channel coding and decoding link, the encoding function corresponding to the transmitting end and the channel coding and decoding link is enabled, and the cyclic redundancy check bit generation function, whitening function, interleaving function and modulation function are not enabled; the decoding function corresponding to the receiving end and the channel coding and decoding link is enabled, and the cyclic redundancy check function, dewhitening function, deinterleaving function and demodulation function are not enabled; For the signal shaping link, enable the whitening function corresponding to the transmitting end and the signal shaping link, do not enable the cyclic redundancy check bit generation function, encoding function, interleaving function and modulation function, enable the dewhitening function corresponding to the receiving end and the signal shaping link, do not enable the cyclic redundancy check function, decoding function, deinterleaving function and demodulation function; For the time domain dispersion link, enable the interleaving function corresponding to the transmitting end and the time domain dispersion link, do not enable the cyclic redundancy check bit generation function, encoding function, whitening function and modulation function, enable the deinterleaving function corresponding to the receiving end and the time domain dispersion link, do not enable the cyclic redundancy check function, decoding function, dewhitening function and demodulation function; For the carrier modulation link, the modulation function corresponding to the transmitting end and the carrier modulation link is enabled, and the cyclic redundancy check bit generation function, encoding function, whitening function and interleaving function are not enabled. The demodulation function corresponding to the receiving end and the carrier modulation link is enabled, and the cyclic redundancy check function, decoding function, dewhitening function and deinterleaving function are not enabled.
8. A computing device, characterized in that It includes a processing component and a storage component; the storage component stores one or more computer instructions; the one or more computer instructions are used to be called and executed by the processing component to implement a method for reverse parsing the physical layer characteristics of a radio frequency chip as described in any one of claims 1 to 6.
9. A computer storage medium, characterized in that A computer program is stored, and when the computer program is executed by a computer, the method for reverse analysis of the physical layer characteristics of a radio frequency chip according to any one of claims 1 to 6 is implemented.
Citation Information
Patent Citations
IEEE802.15.4g-protocol-standard-based 433MHz wireless communication module
CN105207694A
OFDMA physical layer uplink and downlink processing method based on private network
CN105721380A