Data processing system, method and electronic device

By working together with a wireless signal monitor and a gateway, and utilizing LoRa transmission and hash processing technology, the high cost caused by the need for a SIM card in wireless signal monitors is solved, thus achieving low-cost and secure indoor distributed system signal monitoring.

CN119767342BActive Publication Date: 2025-11-18CHINA TELECOM CORP LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411795223.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-06
Publication Date
2025-11-18
Estimated Expiration
2044-12-06

AI Technical Summary

Technical Problem

Existing wireless signal monitoring solutions require each wireless signal monitor to be equipped with an independent SIM card, which makes large-scale deployment impossible. In addition, the monitoring process incurs high data traffic costs, resulting in high costs for signal monitoring in indoor distributed systems.

Method used

A wireless signal monitor receives and encrypts radio frequency signals, which are then transmitted to the gateway via a long-distance radio LORA transmission module. The gateway decrypts and hashes the radio frequency signals before forwarding them to the intelligent management system through a secure tunnel link, thereby enabling the monitoring of radio frequency signals.

Benefits of technology

It enables low-cost monitoring of signal quality in indoor distributed systems, reducing monitoring costs and improving the security and reliability of signal monitoring.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119767342B_ABST
    Figure CN119767342B_ABST
Patent Text Reader

Abstract

The application discloses a data processing system, method and electronic equipment. The system comprises a wireless signal monitor, a gateway and an intelligent management system. The wireless signal monitor is used for receiving radio frequency signals transmitted by a room distribution antenna, encrypting the radio frequency signals, and transmitting the encrypted radio frequency signals to the gateway through a long-range radio LORA transmission module in the wireless signal monitor. The gateway is used for decrypting the received encrypted radio frequency signals, performing hash processing on the decrypted radio frequency signals, and forwarding the hash-processed radio frequency signals to the intelligent management system through a secure tunnel link. The intelligent management system is used for monitoring the radio frequency signals forwarded by the gateway. The application solves the technical problem of high cost in related art for monitoring signals of an indoor distribution system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of wireless communication, and more specifically, to a data processing system, method, and electronic device. Background Technology

[0002] In related technologies, 4G / 5G indoor distribution systems primarily employ traditional passive distributed antenna systems (DAS). This system has been widely used as an indoor distribution solution since the 2G era. Its low cost and ability to meet the needs of most scenarios have ensured its continued use in the 3G, 4G, and even 5G eras. The base station signal source built by the operator is split through a series of passive devices such as power dividers and couplers, and then the signal is rationally distributed to low-power antennas installed in different areas of the building via feeders. For multi-system signals, combiners or POI (Point of Interface) technology are used to merge signals from different systems into a single indoor distribution system, achieving resource sharing and co-construction.

[0003] However, while existing wireless signal monitoring solutions can effectively monitor, automatically monitor, locate faults, and intelligently analyze faults in passive indoor distributed antennas, they require each wireless signal monitor to be equipped with an independent SIM card, making it impossible to deploy intelligent monitors on a large scale. Furthermore, wireless signal monitors consume high data traffic during daily monitoring, resulting in high monitoring costs.

[0004] There is currently no effective solution to the above problems. Summary of the Invention

[0005] This application provides a data processing system, method, and electronic device to at least solve the technical problem of high cost in indoor distributed system signal monitoring in related technologies.

[0006] According to one aspect of the embodiments of this application, a data processing system is provided, including: a wireless signal monitor, a gateway, and an intelligent management system. The wireless signal monitor receives radio frequency (RF) signals transmitted by an indoor distributed antenna, encrypts the RF signals, and transmits the encrypted RF signals to the gateway via a long-range radio (LORA) transmission module in the wireless signal monitor. The gateway decrypts the received encrypted RF signals, hashes the decrypted RF signals, and forwards the hashed RF signals to the intelligent management system via a secure tunnel link. The intelligent management system monitors the RF signals forwarded by the gateway.

[0007] Optionally, the wireless signal monitor includes a signal receiver, a signal decision unit, a LoRa transmission module, a security control module, and a power supply unit. The signal receiver receives the radio frequency (RF) signal transmitted by the indoor distributed antenna and sends it to the signal decision unit. The signal decision unit extracts key parameters of the received RF signal, evaluates the signal quality based on these parameters, and obtains a decision result. These key parameters include received signal strength indication, signal-to-noise ratio (SNR), reference signal received power, and physical cell identifier. The security control module encrypts and checks the integrity of the decision result and the RF signal. After the integrity check is passed, the encrypted decision result and RF signal are sent to the gateway via the LoRa transmission module. The power supply unit provides power to the signal receiver, signal decision unit, LoRa transmission module, and security control module.

[0008] Optionally, the gateway includes: a LORA module, an encryption / decryption module, and a security module. The LORA module is used to establish a wireless connection with the wireless signal monitor and receive the encrypted radio frequency signal transmitted by the wireless signal monitor. The encryption / decryption module is used to decrypt the encrypted radio frequency signal. The security module is used to hash the decrypted radio frequency signal and forward the hashed radio frequency signal to the intelligent management system through a secure tunnel link.

[0009] Optionally, before forwarding the radio frequency signal to the intelligent management system via the secure tunnel link, the process includes: the gateway receiving an encrypted temporary user identity identifier (SUCI) sent by the wireless signal monitor, wherein the encrypted user identity identifier is obtained by encrypting the permanent user identity identifier (SUPI); the gateway sending the temporary user identity identifier (SUCI) and the gateway identifier (SNID) to the intelligent management system, wherein the intelligent management system parses the SUCI into a SUPI and generates an authentication vector, wherein the authentication vector is determined by an authentication random number, an authentication token, an encryption key, an integrity key, and the expected value of the wireless signal monitor's response; the gateway forwarding the received authentication random number, authentication token, and gateway identifier sent by the intelligent management system to the wireless signal monitor; after the wireless signal monitor verifies the authentication token, the gateway forwards the received actual authentication response value sent by the wireless signal monitor to the intelligent management system for verification, obtaining a verification result, wherein the intelligent management system obtains the verification result by comparing the actual authentication response value with the expected value; if the verification result is successful, the gateway receives the SUPI sent by the intelligent management system and sends a successful authentication message to the wireless signal monitor.

[0010] Optionally, the security module is used to perform hash processing on the decrypted radio frequency signal, including: filling the radio frequency signal according to a preset rule to obtain a first radio frequency signal; dividing the first radio frequency signal into blocks to obtain multiple blocks; decomposing each block to obtain multiple words; generating a temporary value based on the multiple words and a preset working variable; updating the working variable based on the temporary value; performing an addition operation on the updated working variable and the corresponding initial security hash value to obtain multiple hash value components; and connecting the multiple hash value components corresponding to each block to obtain a security hash value.

[0011] Optionally, a tunnel mode is used between the gateway and the intelligent management system, and an IPSec channel transmission mode is used between the gateway and the wireless signal monitor.

[0012] Optionally, the intelligent management system is also used to trigger a fault management process when the radio frequency signal does not meet the preset security policy.

[0013] According to another aspect of the embodiments of this application, a data processing method is also provided, comprising: acquiring an encrypted radio frequency signal transmitted by a wireless signal monitor through a long-range radio (LORA) transmission module, wherein the LORA transmission module is a component in the wireless signal monitor, and the radio frequency signal is a radio frequency signal transmitted by an indoor distributed antenna; decrypting the encrypted radio frequency signal and performing hash processing on the decrypted radio frequency signal; and forwarding the hash-processed radio frequency signal to an intelligent management system through a secure tunnel link, wherein the intelligent management system is used to monitor the radio frequency signal.

[0014] According to another aspect of the embodiments of this application, an electronic device is also provided, including: a memory and a processor, wherein the memory is used to store program instructions; and the processor is connected to the memory and used to execute the above-described data processing method.

[0015] According to another aspect of the embodiments of this application, a non-volatile storage medium is also provided, the non-volatile storage medium including a stored computer program, wherein the device where the non-volatile storage medium is located executes the above-described data processing method by running the computer program.

[0016] According to another aspect of the embodiments of this application, a computer program product is also provided, including computer instructions that, when executed by a processor, implement the above-described data processing method.

[0017] In this embodiment, a wireless signal monitor, a gateway, and an intelligent management system are used in the data processing system. The wireless signal monitor receives radio frequency (RF) signals transmitted by the indoor distributed antenna, encrypts the RF signals, and transmits the encrypted RF signals to the gateway through a long-range radio (LORA) transmission module in the wireless signal monitor. The gateway decrypts the received encrypted RF signals, hashes the decrypted RF signals, and forwards the hashed RF signals to the intelligent management system through a secure tunnel link. The intelligent management system monitors the RF signals forwarded by the gateway, achieving the goal of low-cost monitoring of the signal quality of the indoor distributed system. This achieves the technical effect of secure wireless signal monitoring and solves the technical problem of high cost in monitoring indoor distributed system signals in related technologies. Attached Figure Description

[0018] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:

[0019] Figure 1 This is a hardware structure block diagram of a computer terminal for implementing a data processing method according to an embodiment of this application;

[0020] Figure 2 This is a structural diagram of a data processing system according to an embodiment of this application;

[0021] Figure 3 This is a schematic diagram of the internal connection structure of a wireless signal monitor according to an embodiment of this application;

[0022] Figure 4 This is a schematic diagram of the internal components and connection structure of a gateway according to an embodiment of this application;

[0023] Figure 5 This is a flowchart of a data processing method according to an embodiment of this application. Detailed Implementation

[0024] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.

[0025] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0026] First, some nouns or terms that appear in the explanation of the embodiments of this application shall be interpreted as follows:

[0027] RFID: Radio Frequency Identification. It is a non-contact automatic identification technology that uses radio frequency signals to automatically identify target objects and acquire relevant data. It mainly consists of electronic tags, readers, and antennas. The electronic tag consists of a coupling element and a chip; each tag has a unique electronic code and is attached to an object to identify the target. The reader is used to read (and sometimes write) information from the electronic tag. It emits radio frequency signals at a specific frequency and receives reflected signals from the electronic tag, thereby acquiring the data from the tag. The antenna transmits the radio frequency signals between the reader and the electronic tag.

[0028] SIM Card: Subscriber Identity Module. It is a smart card that stores digital mobile phone customer information, primarily used to identify users in mobile communication networks and store user-related data. The SIM card contains the following main information and functions: User identity information, storing the International Mobile Subscriber Identity (IMSI), used to uniquely identify a mobile phone user. The IMSI is crucial information for identifying mobile users globally; Security information, including authentication keys, used for network authentication of the user and encrypted communication to ensure communication security; Phone number, associated with the user's mobile phone number, through which the network communicates with the user; Communication records, which can store a certain number of SMS messages and call records; Network access parameters, storing relevant parameters of the mobile network so that the mobile phone can access a specific mobile communication network.

[0029] LoRa: Long Range Radio. LoRa is a Low Power Wide Area Network (LPWAN) technology with the following characteristics: Long-range communication: LoRa technology can achieve communication over distances of several kilometers or even tens of kilometers, making it particularly suitable for applications with wide coverage and high requirements for communication distance; Low power consumption: Devices using LoRa technology consume very little power, allowing battery-powered devices to operate for extended periods, reducing the need for frequent battery replacements or charging; Strong anti-interference capability: LoRa uses spread spectrum technology to resist interference in complex wireless environments, ensuring reliable communication; Flexible deployment: LoRa networks can be flexibly deployed according to actual needs, ranging from public networks built by operators to private networks built by enterprises or individuals. LoRa technology is mainly used in the Internet of Things (IoT) field, such as smart metering, smart agriculture, environmental monitoring, and logistics tracking, providing a reliable long-range communication solution for various IoT devices.

[0030] Intrinsic Security Convergence Gateway: The intrinsic security convergence gateway connects to the intelligent management system through a specific "secure tunnel link" mode, primarily using wireless transmission to enhance system deployment flexibility and adapt to more application scenarios unsuitable for "wired transmission deployment." It consists of a LoRa module, an encryption / decryption module, and an intrinsic security module.

[0031] IPsec: Internet Protocol Security. IPsec is an open standard set of network layer security protocols primarily used to provide security services such as encryption, authentication, and integrity protection for IP packets. Its main functions include: encryption, ensuring the confidentiality of data during network transmission and preventing eavesdropping by encrypting IP packets; authentication, authenticating the origin of IP packets to ensure data comes from a legitimate sender and prevent forgery; and integrity protection, using mechanisms such as checksums to ensure that IP packets have not been tampered with during transmission, guaranteeing data integrity. IPsec is widely used in Virtual Private Networks (VPNs), enterprise network security, and other fields, providing reliable security for network communications.

[0032] PSK: Pre-Shared Key, is a pre-shared password or key. In network communication and encryption technologies, shared keys are commonly used for the following: Encrypted communication: Both parties pre-determine a shared key and then use this key to encrypt and decrypt data. For example, in some wireless local area networks (WLANs), users and access points can use PSKs for encrypted communication to protect the security of data transmission over the wireless network; Authentication: Shared keys can be used as a method of authentication. Both parties verify each other's identity by confirming the correctness of the shared key; Security protocols: In some security protocols, shared keys are used as the basis for establishing secure connections. For example, the IPsec protocol can use PSKs for authentication and establishing secure associations.

[0033] EAP-AKA: Extensible Authentication Protocol - Authentication and Key Agreement. EAP-AKA is an authentication protocol used in wireless and mobile networks, primarily for secure authentication and key agreement between user equipment (UE) and the network. It is commonly used in 3G, 4G, and 5G mobile communication networks, as well as some wireless local area networks (WLANs) for secure access. Its main features and functions include: two-way authentication: EAP-AKA provides authentication from the network to the UE and from the UE to the network, ensuring the legitimacy of both parties; key agreement: key agreement is performed simultaneously during authentication to generate session keys for encrypted communication; high security: advanced encryption algorithms and security mechanisms are used to protect user identity information and communication data; suitability for mobile networks, especially for authentication and key agreement in mobile environments, meeting the security and convenience requirements of mobile devices.

[0034] RAND: RandomNumber, is a random value used in the authentication process of a communication network. In mobile communication networks, a RAND is generated when authenticating user identity. It plays several important roles: Security Challenge: RAND is provided to the user equipment (such as a mobile phone) as a randomly generated challenge value. The user equipment and the authentication center in the network (usually the Home Location Register (HLR) or Authentication Center (AuC)) use this random number, along with information such as the SIM card stored in the user equipment and the key stored on the network side, to perform a series of calculations; Participation in Authentication Calculation: RAND, together with the key stored in the SIM card and a specific algorithm, is used to calculate important parameters such as the authentication response value (RES) and the encryption key. The network determines the user's legitimacy by comparing the authentication response value returned by the user equipment with the expected value calculated by the network side; Enhanced Security: Because RAND is randomly generated, its value is different in each authentication process, which increases the security of authentication and prevents security threats such as replay attacks.

[0035] SHA-256 (Secure Hash Algorithm 256-bit) is a cryptographic hash function with the following characteristics: determinism (for the same input data, it always produces the same output result); irreversibility (it is difficult to deduce the original input data from the output hash value); and collision resistance (it is difficult to find two different input data that produce the same hash value). The SHA-256 algorithm takes an input message of arbitrary length, divides it into fixed-size blocks, and then processes these data blocks step by step through a series of complex mathematical operations, including bitwise operations, logical operations, and circular shifts, ultimately generating a 256-bit hash value.

[0036] RSSI: Received Signal Strength Indication. RSSI is an indication of the strength of the wireless signal received by a receiving device. It reflects the power of the received signal and is usually measured in decibels per milliwatt (dBm). The main functions of RSSI include: Signal Strength Assessment: Evaluating the strength of the wireless signal to help users understand the quality of the currently received signal. A stronger signal usually corresponds to a higher RSSI value, and vice versa; Distance Estimation: The RSSI value can be used to estimate the distance between the transmitting and receiving devices. Signal strength decreases with distance, so changes in RSSI can be used to roughly determine the distance; Network Optimization: In wireless network deployment and optimization, RSSI serves as an important parameter. By monitoring the RSSI value, parameters such as the location of wireless access points and transmit power can be adjusted to improve network coverage and performance.

[0037] SINR stands for Signal to Interference plus Noise Ratio. SINR is the ratio of the received useful signal power to the sum of the interference signal power (including interference from other signal sources and internal system noise). It is an important indicator of signal quality in wireless communication systems. Specifically, the formula for calculating SINR is: SINR = Useful Signal Power / (Interference Signal Power + Noise Power).

[0038] RSRP stands for Reference Signal Receiving Power. RSRP is the linear average of the signal power received on resource particles (REs) carrying a cell-specific reference signal (CRS) within a specific measurement frequency bandwidth, measured in dBm. Simply put, it reflects the strength of the reference signal received by the terminal from the base station.

[0039] PCI: Physical Cell Identifier. PCI is a physical layer identifier used to distinguish different cells. In mobile communication networks, especially in LTE (Long Term Evolution) and 5G networks, PCI plays a crucial role.

[0040] Traditional indoor passive antenna systems are complex in structure, with numerous components distributed across different areas. This makes direct signal monitoring difficult, leading to delayed fault detection, reactive maintenance, high inspection costs, and a lack of user satisfaction. Furthermore, they fail to provide comprehensive, visualized management of all nodes and cannot meet operators' demands for intelligent network maintenance. While wireless signal monitoring solutions can effectively monitor, automatically detect, locate faults, and intelligently analyze them in passive indoor antenna systems, each monitor requires an independent SIM card, hindering large-scale deployment. Additionally, daily monitoring incurs significant data charges, resulting in high monitoring costs.

[0041] To address the problems existing in related technologies, embodiments of this application provide a data processing method that can be run on... Figure 1 The computer terminal shown is explained below.

[0042] The data processing method embodiments provided in this application can be executed on a mobile terminal, computer terminal, or similar computing device. Figure 1 A hardware structure block diagram of a computer terminal for implementing a data processing method is shown. Figure 1As shown, the computer terminal 10 may include one or more processors (shown as 102a, 102b, ..., 102n in the figure) (the processor may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.), a memory 104 for storing data, and a transmission module 106 for communication functions connected via wired and / or wireless networks. In addition, it may also include: a display, a keyboard, a cursor control device, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the I / O interface), a network interface, and a BUS bus. Those skilled in the art will understand that... Figure 1 The structure shown is for illustrative purposes only and does not limit the structure of the aforementioned electronic device. For example, computer terminal 10 may also include... Figure 1 The more or fewer components shown, or having the same Figure 1 The different configurations shown.

[0043] It should be noted that the aforementioned one or more processors and / or other data processing circuits are generally referred to herein as "data processing circuits". These data processing circuits may be implemented wholly or partially as software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuits may be a single, independent processing module, or may be wholly or partially integrated into any other element in the computer terminal 10. As involved in the embodiments of this application, the data processing circuits serve as processor control (e.g., selection of a variable resistor termination path connected to an interface).

[0044] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the data processing method in this embodiment. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory 104, thereby implementing the aforementioned data processing method. The memory 104 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor, and these remote memories can be connected to the computer terminal 10 via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0045] The transmission module 106 is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by the communication provider of the computer terminal 10. In one example, the transmission module 106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission module 106 may be a Radio Frequency (RF) module, used for wireless communication with the Internet.

[0046] The display may be, for example, a touchscreen liquid crystal display (LCD) that allows the user to interact with the user interface of the computer terminal 10.

[0047] It should be noted here that, in some optional embodiments, the above... Figure 1 The computer terminal shown may include hardware elements (including circuitry), software elements (including computer code stored on a computer-readable medium), or a combination of both hardware and software elements. It should be noted that... Figure 1 This is only one instance of a specific particular instance, and is intended to illustrate the types of components that may exist in the aforementioned computer terminal.

[0048] In the above operating environment, this application provides a data processing method embodiment. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Also, although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than that shown here.

[0049] Figure 2 This is a structural diagram of a data processing system according to an embodiment of this application, such as... Figure 2 As shown, the system includes: a wireless signal monitor 20, a gateway 22, and an intelligent management system 24. The wireless signal monitor receives radio frequency signals transmitted by the indoor distributed antenna, encrypts the radio frequency signals, and transmits the encrypted radio frequency signals to the gateway through the long-range radio LoRa transmission module in the wireless signal monitor. The gateway decrypts the received encrypted radio frequency signals, hashes the decrypted radio frequency signals, and forwards the hashed radio frequency signals to the intelligent management system through a secure tunnel link. The intelligent management system monitors the radio frequency signals forwarded by the gateway.

[0050] In this embodiment, the wireless signal monitor (hereinafter referred to as the monitor) is the front-end device in the entire system. Its main function is to receive and monitor the radio frequency signals (RF signals) transmitted from the indoor distributed antenna. Indoor distributed antennas typically refer to antennas used for indoor signal coverage, such as those in a distributed antenna system (DAS). The monitor contains a signal receiver to capture these RF signals and then analyzes the signal quality, such as key indicators like RSSI, SINR, and RSRP, using a signal decision unit. The analyzed signal data, combined with the built-in security control module, is encrypted using a pre-set encryption algorithm to protect the confidentiality and integrity of the data. After encryption, the encrypted signal data is sent to the gateway via the built-in LoRa transmission module.

[0051] LoRa communication technology is a low-power wide-area network (LPWAN) based wireless communication technology with several significant features and advantages, including:

[0052] 1. Long-distance communication: LoRa can achieve communication distances of several kilometers or even tens of kilometers, making it an ideal choice for long-distance communication. For example, LoRa's link budget is as high as 157dB, enabling its communication distance to reach more than 15 kilometers.

[0053] 2. Low power consumption: LoRa is designed for low-power operation, making it suitable for battery-powered sensors and devices. Its receive current is only 10mA, and its sleep current is 200nA, which significantly extends battery life.

[0054] 3. High anti-interference capability: Due to the use of spread spectrum modulation technology, LoRa has a strong anti-interference capability and can work stably in complex environments.

[0055] 4. Multi-node support: LoRa can support a large number of node connections, making it suitable for large-scale IoT application scenarios.

[0056] 5. Low cost: LoRa technology has a low cost and is suitable for large-scale deployment, especially in IoT applications that require coverage of a wide area.

[0057] 6. Easy to deploy and standardized: LoRa technology is easy to deploy and has standardized protocols such as LoRaWAN, which further simplifies network construction and management.

[0058] 7. Flexible network topology: LoRa supports flexible network topology, which can adapt to different application needs.

[0059] 8. Adaptive Data Rate Strategy: LoRa uses an Adaptive Data Rate (ADR) strategy to automatically adjust the data transmission rate according to environmental conditions in order to balance transmission distance and data rate.

[0060] 9. Good penetration: LoRa can also penetrate buildings and other obstacles, making it suitable for both indoor and outdoor environments.

[0061] Therefore, LoRa, with its advantages of long range, low power consumption, high anti-interference capability, low cost, and good penetration, is perfectly suited for indoor signal monitoring and detection, providing a perfect backhaul path for wireless signal monitors. LoRa can achieve long-distance coverage of several kilometers or even tens of kilometers, which greatly reduces the number of built-in security aggregation gateways required, further reducing the cost of deploying the entire indoor signal monitoring system. Moreover, the deployment method is more flexible; it can be deployed outdoors or near the building where the signal monitor is installed. Outdoor installation is more suitable for better utilizing the built-in security aggregation gateway.

[0062] The gateway (intrinsically secure aggregation gateway) acts as a relay and aggregation point in the data processing flow. It receives encrypted RF signal data from the wireless signal monitor. The intrinsically secure aggregation gateway first decrypts the data using the same key as the monitor, then hashes the decrypted data using a self-developed intrinsically secure hash algorithm, SeSHA-256. This algorithm converts the data into a fixed-length hash value to ensure data integrity and prevent tampering. After processing, the gateway forwards the hashed data to the intelligent management system via a secure tunnel link built with IPsec. IPsec provides a secure data transmission method that ensures the confidentiality and integrity of data during transmission, preventing eavesdropping or tampering.

[0063] The intelligent management system is the core of the entire system's control and management, receiving data forwarded from the intrinsically secure aggregation gateway. By receiving and processing this data, the intelligent management system can monitor and analyze the signal quality of the indoor distributed antennas in real time. The system compares the decrypted data with its stored reference data to monitor signal quality changes and determine whether the antennas are functioning correctly or have malfunctioned. Simultaneously, the intelligent management system is also responsible for configuration management, task management, fault management, log management, and system management, ensuring the normal operation and efficiency of the entire signal monitoring system. Through the intelligent management system, operators can achieve remote monitoring and maintenance of the indoor distributed system, improving operational efficiency and reducing inspection costs. The functional modules and corresponding functional classifications and descriptions of the intelligent management system are shown in the table below:

[0064]

[0065]

[0066] Through the coordinated operation of the wireless signal monitor 20, gateway 22, and intelligent management system 24, real-time, secure, and low-cost monitoring of indoor distributed antenna signals can be achieved. The monitor is responsible for signal acquisition and preliminary processing, the gateway is responsible for secure data transmission and aggregation, and the intelligent management system is responsible for the final analysis and management of the data. Together, they construct an efficient and secure signal monitoring system, effectively solving the problems of high cost and insufficient security in traditional indoor distributed antenna systems. The following is a detailed explanation.

[0067] In the aforementioned data processing system, the wireless signal monitor includes a signal receiver, a signal decision unit, a LoRa transmission module, a security control module, and a power supply unit. The signal receiver receives the radio frequency (RF) signal transmitted by the indoor distributed antenna and sends it to the signal decision unit. The signal decision unit extracts key parameters of the received RF signal, evaluates its signal quality based on these parameters, and obtains a decision result. These key parameters include received signal strength indication, signal-to-noise ratio (SNR), reference signal received power, and physical cell identifier. The security control module encrypts and performs integrity checks on the decision result and the RF signal. After the integrity check is passed, the encrypted decision result and RF signal are sent to the gateway via the LoRa transmission module. The power supply unit provides power to the signal receiver, signal decision unit, LoRa transmission module, and security control module.

[0068] In this embodiment of the application, the internal connection structure of the wireless signal monitor is as follows: Figure 3 As shown, it includes: a signal receiver, a signal decision unit, a LoRa transmission module, an (intrinsic) safety control module, and a power supply unit. The signal receiver, signal decision unit, LoRa transmission module, and safety control module are connected to each other in sequence, while the power supply module is connected to all of the above modules to provide them with the necessary power support.

[0069] Specifically, the signal receiver is responsible for capturing radio frequency (RF) signals transmitted by indoor distributed antennas (such as mushroom-shaped antennas or panel antennas). It needs to have full-band reception capability, be able to process signals in the bandwidth range of 200MHz to 7000MHz, and perform appropriate filtering operations to eliminate signal interference from outside the band. The received RF signals are then sent to the signal decision unit for further analysis.

[0070] The main function of a signal decision unit (or simply decision unit) is to perform the following steps after receiving a radio frequency (RF) signal: 1. RF down-conversion: converting the high-frequency RF signal into a lower-frequency signal for subsequent processing; 2. Analog-to-digital conversion: converting the analog signal into a digital signal, providing a foundation for digital signal processing; 3. Digital down-conversion: further down-converting the signal to the baseband frequency range; 4. Baseband signal processing: demodulating the baseband signal to obtain its key parameters. By extracting these key parameters, signal quality is assessed to determine whether the signal is normal and whether its quality meets application standards. Key parameters include Received Signal Strength Indication (RSSI), Signal-to-Noise Ratio (SINR), Received Reference Signal Power (RSRP), and Physical Cell Identifier (PCI).

[0071] Based on these parameters, the decision-maker employs multi-dimensional analysis methods, such as RSSI-based decision criteria, RSRP-based decision criteria, and SINR-based signal interference and noise ratio assessment, to comprehensively analyze the radio frequency signal and ultimately determine whether the signal quality is normal. Some of the decision criteria are explained below:

[0072] 1. Decision criteria based on RSSI:

[0073] Given the differences in Received Signal Strength Indication (RSSI) among antennas in different frequency bands, an adaptive decision threshold processing mechanism is used to ensure accurate determination of the normality of each antenna signal. Specifically, during normal daily operation of the antenna, this mechanism determines a reference value through repeated adaptive learning, and sets an adjustment value above this reference value to set a reasonable decision threshold, thereby avoiding erroneous decisions.

[0074] Under normal system operation, self-learning is first performed to determine the normal average RSSI strength. Typically, self-learning involves three test cycles. For example, if signal reporting is performed once a day, one test cycle is one day, denoted as RSSI_Ref. The data acquisition test cycle can be customized, ranging from 1 minute to 144 hours. This value corresponds to the decision threshold range for a specific frequency band and antenna, calculated as: RSSI_Th = RSSI_Ref - RSSI_Delta (where RSSI_Delta ranges from 5 to 10, with a typical value of 8).

[0075] The signal decision unit compares the currently received Signal Strength Indication (RSSI) with a preset threshold (RSSI_Th). If the RSSI value is greater than or equal to RSSI_Th, the antenna signal is considered normal; if the RSSI value is lower than RSSI_Th, the antenna signal is considered abnormal. After traversing all frequency bands, the unit performs the determination according to the Received Signal Strength Indication (RSSI) standard and displays the determination results sequentially.

[0076] 2. RSRP-based decision criteria: To further improve the accuracy of detection, RSRP can be used for decision-making and analysis.

[0077] Given the differences in RSRP (Signal Strength Receivable) received by each antenna across different frequency bands, the system needs to perform self-learning during normal operation to determine a normal average RSRP strength. Typically, the self-learning process lasts for three test cycles; for example, if the system reports a signal once a day, each test cycle is one day. The data acquisition test cycle can be customized, ranging from 1 minute to 144 hours. This average value is denoted as RSRP_Ref, which corresponds to the decision threshold range for a specific frequency band and antenna, i.e., RSRP_Th = RSSI_Ref - RSRP_Delta. The value of RSRP_Delta ranges from 5 to 15, with a typical value set to 10.

[0078] The signal decision unit compares the reference signal received power (RSRP) of the currently received signal with a preset threshold (RSRP_Th). If RSRP is greater than or equal to RSRP_Th, the antenna signal is determined to be in a normal state; if RSRP is less than RSRP_Th, the antenna signal is determined to be abnormal. After traversing all frequency bands, the decision is made sequentially according to the RSRP standard, and the decision results are output sequentially.

[0079] 3. Multi-parameter integrated decision method: In order to improve the accuracy and reliability of the decision, a comprehensive decision based on multiple parameters such as RSSI, SINR, and RSRP is introduced.

[0080] First, independent judgments are made according to the decision criteria based on RSSI and RSRP, respectively, to obtain preliminary judgment results on the signal state. For the SINR parameter, a minimum acceptable threshold SINR_Min is set (for example, 3dB depending on system requirements and actual application scenarios). When the signal's SINR is greater than or equal to SINR_Min, the signal state is judged as normal; if the SINR is less than SINR_Min, the signal is judged to have an abnormal risk in terms of interference and noise.

[0081] The judgment results of RSSI, RSRP, and SINR are considered comprehensively. If at least one of the RSSI and RSRP judgments is normal, and the SINR is also normal, then the signal is ultimately judged to be in a normal state. If both RSSI and RSRP are judged to be abnormal, or if the SINR is judged to be abnormal, then the signal is judged to be abnormal. This multi-parameter comprehensive judgment method can more comprehensively evaluate signal quality, avoid misjudgments that may be caused by single-parameter judgment, and thus improve the accuracy and reliability of signal judgment.

[0082] The LoRa transmission module is the communication unit in a wireless signal monitor. It uses LoRa (Long Range Radio) technology to communicate with the built-in secure aggregation gateway, thereby building a secure intranet transmission network. The low power consumption of LoRa technology makes it ideal for long-term operation of the monitor, while its long-distance communication capability ensures stable data transmission from the monitor to the gateway. After the signal decision unit makes its decision, the LoRa transmission module sends the decision result and related radio frequency signal data to the gateway via LoRa wireless transmission technology, eliminating the need for traditional cellular networks or SIM cards and significantly reducing communication costs.

[0083] The security control module is responsible for encrypting and performing integrity checks on the judgment results and radio frequency signal data to ensure data security during transmission. The encryption and hash algorithms used (such as SeSHA-256) prevent data tampering and theft; only data that passes the integrity check is sent to the gateway via the LoRa transmission module. This security control mechanism enhances the overall security capabilities of the system and is particularly suitable for applications with high security requirements. The core function of the security control module is to implement intrinsic security-related encryption and decryption algorithms, IPsec protocol, intrinsic security control policies, and adjust security levels. For cost-sensitive applications, some functions of the security control module can be reduced or bypassed to lower system costs and deployment complexity, thereby reducing overall application costs.

[0084] The power supply unit is the energy supply component of the monitor, responsible for providing the necessary power to the signal receiver, signal decision unit, LORA transmission module, and security control module. Since the entire monitor needs to operate for extended periods without maintenance, the power supply unit is typically designed with low power consumption and long-term power supply in mind. This may involve using battery power combined with a low-power mode to ensure the monitor can operate continuously in indoor distributed environments without frequent battery replacements.

[0085] In the aforementioned data processing system, the gateway includes a LoRa module, an encryption / decryption module, and a security module. The LoRa module is used to establish a wireless connection with the wireless signal monitor and receive the encrypted radio frequency signal transmitted by the wireless signal monitor. The encryption / decryption module is used to decrypt the encrypted radio frequency signal. The security module is used to hash the decrypted radio frequency signal and forward the hashed radio frequency signal to the intelligent management system through a secure tunnel link.

[0086] In the embodiments of this application, the internal components and connection structure of the gateway are as follows: Figure 4 As shown, it includes: LORA module, (A-end) encryption / decryption module and (B-end) built-in security module.

[0087] Specifically, the LoRa module is primarily responsible for establishing a wireless communication connection with the wireless signal monitor. It receives encrypted radio frequency signals transmitted from the wireless signal monitor via LoRa (Long Range Radio) technology. LoRa technology was chosen because of its unique long range, low power consumption, and interference resistance, allowing communication between the monitor and the gateway to proceed without relying on carrier networks or SIM cards, thereby reducing deployment and operating costs.

[0088] The encryption / decryption module is used to decrypt the received encrypted radio frequency signals. Before transmitting data, the wireless signal monitor uses a preset encryption algorithm to encrypt the signal judgment results and key parameters of the radio frequency signal to protect data privacy and security. The encryption / decryption module uses the same or compatible encryption algorithm as the wireless signal monitor to restore the encrypted data to the original signal judgment results and key parameter information.

[0089] The security module performs hash processing on the received and decrypted RF signal data using a self-developed intrinsically secure hash algorithm, SeSHA-256. This hash processing ensures data integrity and tamper-proof nature; even if the data is intercepted during transmission, it cannot be easily deciphered or altered. Furthermore, the security module is responsible for constructing a secure tunnel link, encrypting the hashed RF signal data via the IPsec protocol and forwarding it to the intelligent management system. The use of the IPsec protocol not only guarantees the confidentiality and integrity of the data during transmission but also provides authentication and anti-replay protection, ensuring the data source is reliable and that it has not been retransmitted.

[0090] In this embodiment, the security module may be optionally equipped with a security module that has IPsec (Internet Protocol Security) functionality, and a dedicated secure VLAN tunnel may be constructed. Furthermore, the system supports multiple IPsec tunnel establishment methods, including but not limited to the following: 1. IPsec tunnel establishment based on pre-shared key (PSK) authentication; 2. IPsec tunnel establishment based on digital certificate authentication; 3. IPsec tunnel establishment based on EAP-SIM authentication; 4. IPsec tunnel establishment based on "Secure Intrinsic EAP-AKA" authentication.

[0091] In the aforementioned data processing system, before forwarding the radio frequency signal to the intelligent management system via a secure tunnel link, the process includes: the gateway receiving an encrypted temporary user identity identifier (SUCI) sent by a wireless signal monitor, wherein the encrypted user identity identifier is obtained by encrypting the permanent user identity identifier (SUPI); the gateway sending the SUCI and its gateway identifier (SNID) to the intelligent management system, wherein the intelligent management system parses the SUCI into a SUPI and generates an authentication vector, wherein the authentication vector is determined by an authentication random number, an authentication token, an encryption key, an integrity key, and the expected value of the wireless signal monitor's response; the gateway forwarding the received authentication random number, authentication token, and gateway identifier from the intelligent management system to the wireless signal monitor; after the wireless signal monitor verifies the authentication token, the gateway forwards the received actual authentication response value from the wireless signal monitor to the intelligent management system for verification, obtaining a verification result, wherein the intelligent management system obtains the verification result by comparing the actual authentication response value with the expected value; if the verification result is successful, the gateway receives the SUPI sent by the intelligent management system and sends a successful authentication message to the wireless signal monitor.

[0092] In this embodiment, the "Secure Intrinsic EAP-AKA" authentication protocol process is as follows: The gateway first receives the encrypted temporary user identity identifier (SUCI) sent by the wireless signal monitor. The SUCI is obtained by encrypting the permanent user identity identifier (SUPI), and its purpose is to protect the user's identity information from being stolen or misused during transmission. The gateway then sends the SUCI and its own gateway identifier (SNID) to the intelligent management system. After receiving the SUCI and SNID, the intelligent management system parses the SUCI back to the SUPI. Next, the intelligent management system generates an authentication vector (AV) based on the SUPI, SNID, and the generated authentication random number (RAND) and authentication token (AUTN). The authentication vector AV contains key information such as XRES (expected value of the wireless signal monitor's response), CK (encryption key), IK (integrity key), and AK (anonymity key), which are used for subsequent authentication and secure communication. The intelligent management system uses RAND, AUTN, and SN... The ID is sent back to the gateway, which then forwards it to the wireless signal monitor. Upon receiving this information, the wireless signal monitor uses its built-in security control module to calculate the XAUTN ​​(Extended Authentication Token) and compares it with the received AUTN. If they match, the authentication token is considered valid, and the monitor calculates the actual authentication response value RES, which is then sent back to the gateway. The gateway, upon receiving the RES, forwards it to the intelligent management system. The intelligent management system compares the previously generated expected RES value (XRES) with the actual RES sent by the wireless signal monitor to verify the monitor's identity. If the intelligent management system verifies that the RES matches the expected value, it confirms the monitor's identity and sends a SUPI to the gateway. Upon receiving the SUPI from the intelligent management system, the gateway sends an authentication success message to the wireless signal monitor, marking the completion of the authentication process. This process ensures the security of communication between the wireless signal monitor and the intelligent management system, preventing identity information leakage and unauthorized access.

[0093] The calculation formulas involved in the above certification process are as follows:

[0094] AV = RAND||XRES||CK||IK||AUTN

[0095] MAC = f1(K, SQN||RAND)

[0096] XRES = f2(K,RAND)

[0097] CK = f3(K,RAND)

[0098] IK = f4(K,RAND)

[0099] AK = f5(K,RAND)

[0100] AUTN = SQN modulo 2 plus AK || MAC

[0101] XMAC = f1(K, sqn||RAND)

[0102] XAUTN ​​= sqn modulo 2 plus AK||MAC

[0103] RES = f2(K,RAND)

[0104] In this system, RAND is the authentication random number, used as a parameter for calculating XRES and serving as a seed for generating different authentication sets. It is generated at the intelligent management system. The root sequence number sqn is generated during the initialization of the wireless signal monitor, maintaining the same root sequence number as the intelligent management system and generating a sequence number SQN according to the rules. K is the shared long-term key, also generated during the initialization of the wireless signal monitor and stored together with the intelligent management system. f1-f5 are one-way functions to ensure that the key cannot be obtained from the calculation result. AV (Authentication Vector) is the intermediately generated authentication vector; XRES is the expected value of the wireless signal monitor's response, used as a parameter for the wireless signal monitor's legitimacy check; CK is the confidentiality encryption key, used as an encryption parameter for the wireless signal monitor's information; IK is the integrity key, used as an integrity protection parameter for network and terminal signaling, used for signaling encryption; AK is the anonymity key, used to hide the sequence number SQN value; AUTN is the authentication token, a parameter used by the wireless signal monitor to confirm the legitimacy of the intelligent management system; MAC is used to verify the correctness of the message to achieve the wireless signal monitor's authentication of the intelligent management system, and XMAC is the extended message authentication code. SUPI is the user's permanent identity identifier. SUPI and K can be used to encrypt SUPI to obtain the user's temporary identity identifier SUCI; SNID is the gateway identifier of the intrinsic security aggregation gateway.

[0105] Through the above process, a secure connection based on the intrinsically secure "EAP-AKA" authentication protocol is established between the gateway and the wireless signal monitor. After successful authentication, the gateway can forward the radio frequency signal data collected by the wireless signal monitor to the intelligent management system through a secure tunnel link. This secure tunnel link is typically built using the IPsec protocol, further ensuring the security and integrity of data transmission. The entire authentication and data transmission process enables secure communication between the wireless signal monitor and the intelligent management system during signal monitoring, effectively protecting the security of user identity information and monitoring data, while reducing the costs incurred by using traditional SIM cards and public network data backhaul.

[0106] In the aforementioned data processing system, the security module is used to perform hash processing on the decrypted radio frequency signal, including: filling the radio frequency signal according to a preset rule to obtain a first radio frequency signal; dividing the first radio frequency signal into blocks to obtain multiple blocks; decomposing each block to obtain multiple words; generating a temporary value based on the multiple words and a preset working variable; updating the working variable based on the temporary value; performing an addition operation on the updated working variable and the corresponding initial security hash value to obtain multiple hash value components; and connecting the multiple hash value components corresponding to each block to obtain a security hash value.

[0107] In this embodiment, the "Secure Intrinsic EAP-AKA" authentication protocol employs the intrinsic secure hash algorithm SeSHA-256, a function that maps data of arbitrary length to a fixed-length string (secure hash value). SeSHA-256 possesses important characteristics such as irreversibility and collision resistance. The SeSHA-256 algorithm processes the input message and ultimately generates a 256-bit (32-byte) secure hash value. The algorithm calculation steps are as follows:

[0108] The security module pads the decrypted RF signal data (L bits in length) to conform to the SeSHA-256 algorithm. During padding, a "1" is added after the RF signal data, followed by multiple "0"s, until the data length reaches 448 bits plus a multiple of 512 bits, i.e., the padded data length M equals 448 (mod 512). Finally, a 64-bit block is added to store the original RF signal data length L to ensure data integrity; the padded data is called the first RF signal. The padded first RF signal (now a fixed-length string) is divided into 512-bit blocks, each denoted as Mi, where i is the block number. Each 512-bit block Mi is further decomposed into 16 32-bit words Wj, where j ranges from 0 to 15. These words are then expanded according to preset rules, generating 48 additional words from the 16th to the 63rd, ensuring both algorithm complexity and security. The preset rules are as follows:

[0109] W j =σ(1W j-2 )+W j-7 +σ0(W j-15 )+W j-16

[0110]

[0111] For each block Mi, 64 rounds of calculation are performed using 8 working variables (a, b, c, d, e, f, g, h) and the corresponding 8 32-bit initial security hash values ​​(SeH0 to SeH7).

[0112] The initial values ​​of the initial security hash are as follows: SeH0 = 0x6a09e667, SeH1 = 0xbb67ae85, SeH2 = 0x3c6ef372, SeH3 = 0xa54ff53a, SeH4 = 0x510e527f, SeH5 = 0x9605688c, SeH6 = 0x1f83d9ab, SeH7 = 0x5be0cd19.

[0113] The calculations for each round are as follows:

[0114]

[0115] In each round of calculation, two temporary values, T1 and T2, are generated based on the words in the block and the working variable. Then, the working variable is updated using Kj (a series of predefined constants with different values ​​for different j values) and other mathematical operations (such as addition, circular shift, etc.). This step ensures the unpredictability and tamper-proof nature of the final secure hash value. The update of the working variable can satisfy, for example, the following formula: h = g, g = f, f = e, e = d + T1, d = c, c = b, b = a, a = T1 + T2.

[0116] After calculating all blocks, the updated working variables are added to the corresponding initial secure hash values ​​to generate eight new 32-bit values, which are called hash value components. Specifically: SeH0 = SeH0 + a, SeH1 = SeH1 + b, SeH2 = SeH2 + c, SeH3 = SeH3 + d, SeH4 = SeH4 + e, SeH5 = SeH5 + f, SeH6 = SeH6 + g, SeH7 = SeH7 + h.

[0117] Finally, the eight hash value components corresponding to each block are concatenated together to form the final 256-bit secure hash value. That is, all the calculated hash value components SeH0||SeH1||SeH2||SeH3||SeH4||SeH5||SeH6||SeH7 are concatenated to obtain the secure hash value of the entire radio frequency signal data.

[0118] In the aforementioned data processing system, a tunnel mode is used between the gateway and the intelligent management system, while the IPSec channel transmission mode is used between the gateway and the wireless signal monitor.

[0119] In this embodiment, the gateway and the wireless signal monitor use an IPSec tunnel transmission mode to transmit IP data packets; communication between the gateway and the intelligent management system uses a tunnel mode to ensure the transmission of IP data packets. The tunnel mode is primarily used for end-to-end connections between hosts, utilizing the address information in the original IP packet header for location. The tunnel mode is mainly used for communication between two security gateways (e.g., routers), achieving IP-in-IP encapsulation by appending a new IP header to the original IP packet header. During tunnel transmission, the original IP packet header is retained until it reaches the tunnel endpoint and the appended header is removed before use.

[0120] There are three main types of backhaul links between the gateway and the intelligent management system: a dedicated transmission link with the highest security level, a third-party backhaul link with a relatively high security level, and a public network transmission link with a lower security level. Using an IPsec transmission channel in tunnel mode can significantly enhance the security of the backhaul link between the intrinsically secure aggregation gateway and the intelligent management system, making it suitable for application scenarios with various security requirements.

[0121] The built-in IPSec security module enables the following four functions: First, data confidentiality, where IPSec encrypts data packets before transmission, ensuring data confidentiality during transmission; second, data integrity, where IPSec verifies the sender's data packets, ensuring data has not been tampered with during transmission; third, data authentication, where the IPSec receiver can verify the source of the data packets; and finally, anti-replay functionality, where the IPSec receiver can detect and reject duplicate packets. Therefore, the built-in IPSec security module further enhances system security and supports various IPSec tunnel establishment methods to meet a wider range of application needs.

[0122] In the aforementioned data processing system, the intelligent management system is also used to trigger a fault management process when the radio frequency signal does not meet the preset security policy.

[0123] In this embodiment, the intelligent management system pre-sets a series of security policies, which cover various security requirements and parameter thresholds in signal monitoring. For example, these policies may include, but are not limited to, the strength of the radio frequency signal, signal quality indicators (such as SINR and RSRP), signal integrity, the security level of data transmission, and the validity of authentication results. These policies are set based on the signal parameter range and security requirements during normal system operation. The intelligent management system receives radio frequency signal data and related judgment results forwarded by the intrinsically secure aggregation gateway through a secure tunnel link or dedicated transmission link. Upon receiving the data, the system first verifies the integrity and correctness of the data, such as by checking whether the data transmitted via LoRa has been tampered with, and whether the data in the IPsec tunnel has passed the verification of the security control module. Once the data verification is successful, the intelligent management system analyzes the signal data, compares it with the pre-set security policies, and checks whether the data is within the expected normal range and whether the signal transmission process meets security requirements. For example, if the radio frequency signal strength (RSSI) is lower than a pre-set threshold, or the signal quality (such as SINR and RSRP) is lower than the minimum requirement, the intelligent management system will determine that the signal does not meet the security policy. When the signal data does not meet the pre-set security policy, the intelligent management system will trigger a fault management process.

[0124] Figure 5 This is a flowchart of a data processing method according to an embodiment of this application, such as... Figure 5 As shown, the method includes:

[0125] Step S502: Obtain the encrypted radio frequency signal transmitted by the wireless signal monitor through the long-range radio LORA transmission module, wherein the LORA transmission module is a component in the wireless signal monitor, and the radio frequency signal is the radio frequency signal transmitted by the indoor distributed antenna.

[0126] Step S504: Decrypt the encrypted radio frequency signal and perform hash processing on the decrypted radio frequency signal;

[0127] Step S506: The hash-processed radio frequency signal is forwarded to the intelligent management system through a secure tunnel link, wherein the intelligent management system is used to monitor the radio frequency signal.

[0128] It should be noted that, Figure 5 The data processing method shown can be run on Figure 2 The data processing system shown above is an example of a data processing method, and therefore the relevant explanations and descriptions in the above data processing system also apply to this data processing method, which will not be repeated here.

[0129] This application also provides an electronic device, which includes a memory and a processor, wherein the memory is used to store program instructions; the processor is connected to the memory and is used to execute the above-described data processing method.

[0130] This application also provides a non-volatile storage medium that includes a stored computer program, wherein the device containing the non-volatile storage medium executes the above-described data processing method by running the computer program.

[0131] This application also provides a computer program product, including computer instructions that, when executed by a processor, implement the steps of the data processing methods in various embodiments of this application.

[0132] This application also provides a computer program that, when executed by a processor, implements the steps of the data processing methods in various embodiments of this application.

[0133] The sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0134] In the above embodiments of this application, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0135] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For instance, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection may be through some interfaces; the indirect coupling or communication connection between units or modules may be electrical or other forms.

[0136] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0137] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0138] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.

[0139] The above description is only a preferred embodiment of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications should also be considered within the scope of protection of this application.

Claims

1. A data processing system, characterized in that, include: Wireless signal monitors, gateways, and intelligent management systems, among which, The wireless signal monitor is used to receive radio frequency signals transmitted by indoor distributed antennas, encrypt the radio frequency signals, and transmit the encrypted radio frequency signals to the gateway through the long-range radio LORA transmission module in the wireless signal monitor. The gateway is used to decrypt the received encrypted radio frequency signal, perform hash processing on the decrypted radio frequency signal, and forward the hash-processed radio frequency signal to the intelligent management system through a secure tunnel link. The intelligent management system is used to monitor the radio frequency signals forwarded by the gateway; The system also includes: the gateway receiving an encrypted temporary user identity identifier (SUCI) sent by the wireless signal monitor, wherein the encrypted user identity identifier is obtained by encrypting the permanent user identity identifier (SUPI); the gateway sending the temporary user identity identifier (SUCI) and the gateway identifier (SNID) to the intelligent management system, wherein the intelligent management system parses the SUCI into the SUPI and generates an authentication vector, wherein the authentication vector is generated using an authentication random number, an authentication token, the SUPI, and the SNID, and the generated authentication vector includes an encryption key, an integrity key, and the expected response from the wireless signal monitor. The gateway forwards the authentication random number, authentication token, and gateway identifier received from the intelligent management system to the wireless signal monitor. After the wireless signal monitor verifies the authentication token, the gateway forwards the actual authentication response value received from the wireless signal monitor to the intelligent management system for verification, obtaining a verification result. The intelligent management system obtains the verification result by comparing the actual authentication response value with the expected value. If the verification result is successful, the gateway receives the SUPI sent by the intelligent management system and sends an authentication success message to the wireless signal monitor.

2. The system according to claim 1, characterized in that, The wireless signal monitor includes a signal receiver, a signal decision unit, a LoRa transmission module, a security control module, and a power supply unit. The signal receiver is used to receive the radio frequency signal transmitted by the indoor distributed antenna and send the radio frequency signal to the signal decision device; The signal decision unit is used to extract key parameters of the radio frequency signal after receiving the radio frequency signal, and to evaluate the signal quality of the radio frequency signal based on the key parameters to obtain a decision result. The key parameters include received signal strength indication, signal-to-noise ratio, reference signal received power, and physical cell identifier. The security control module is used to encrypt and perform integrity checks on the judgment result and the radio frequency signal. After the integrity check is passed, the encrypted judgment result and radio frequency signal are sent to the gateway through the LORA transmission module. The power supply unit is used to supply power to the signal receiver, the signal decision unit, the LORA transmission module, and the security control module.

3. The system according to claim 1, characterized in that, The gateway includes: a LoRa module, an encryption / decryption module, and a security module, wherein, The LORA module is used to establish a wireless connection with the wireless signal monitor and to receive encrypted radio frequency signals transmitted by the wireless signal monitor. The encryption / decryption module is used to decrypt the encrypted radio frequency signal; The security module is used to perform hash processing on the decrypted radio frequency signal and forward the hash-processed radio frequency signal to the intelligent management system through the secure tunnel link.

4. The system according to claim 3, characterized in that, The security module is used to perform hash processing on the decrypted radio frequency signal, including: The radio frequency signal is filled according to a preset rule to obtain a first radio frequency signal; The first radio frequency signal is divided into blocks to obtain multiple blocks; Each block is decomposed to obtain multiple words; Based on the multiple words and preset working variables, generate temporary values; Update the working variable based on the temporary value; The updated working variable and its corresponding initial security hash value are added together to obtain multiple hash value components. By connecting the multiple hash value components corresponding to each block, a secure hash value is obtained.

5. The system according to claim 1, characterized in that, The gateway and the intelligent management system communicate using a tunnel mode, while the gateway and the wireless signal monitor communicate using an IPSec channel transmission mode.

6. The system according to claim 1, characterized in that, The intelligent management system is also used to trigger a fault management process when the radio frequency signal does not meet the preset security policy.

7. A data processing method, characterized in that, include: The encrypted radio frequency signal transmitted by the wireless signal monitor through the long-range radio LORA transmission module is acquired, wherein the LORA transmission module is a component in the wireless signal monitor, and the radio frequency signal is a radio frequency signal transmitted by the indoor distributed antenna. The encrypted radio frequency signal is decrypted, and the decrypted radio frequency signal is hashed. The hash-processed radio frequency signal is forwarded to the intelligent management system via a secure tunnel link, wherein the intelligent management system is used to monitor the radio frequency signal; The method further includes: receiving an encrypted temporary user identity identifier (SUCI) sent by the wireless signal monitor, wherein the encrypted user identity identifier is obtained by encrypting a permanent user identity identifier (SUPI); sending the temporary user identity identifier (SUCI) and the gateway identifier (SNID) of the gateway to the intelligent management system, wherein the intelligent management system parses the SUCI into the SUPI and generates an authentication vector, wherein the authentication vector is generated using an authentication random number, an authentication token, the SUPI, and the SNID, and the generated authentication vector includes an encryption key, an integrity key, and the expected value of the response from the wireless signal monitor; forwarding the received authentication random number, the authentication token, and the gateway identifier sent by the intelligent management system to the wireless signal monitor; after the wireless signal monitor verifies the authentication token, forwarding the received actual authentication response value sent by the wireless signal monitor to the intelligent management system for verification, and obtaining a verification result, wherein the intelligent management system obtains the verification result by comparing the actual authentication response value and the expected value; if the verification result is successful, receiving the SUPI sent by the intelligent management system and sending an authentication success message to the wireless signal monitor.

8. An electronic device, characterized in that, include: A memory and a processor, wherein the memory is used to store program instructions; the processor is connected to the memory and is used to execute the data processing method of claim 7.

9. A non-volatile storage medium, characterized in that, The non-volatile storage medium includes a stored computer program, wherein the device containing the non-volatile storage medium executes the data processing method of claim 7 by running the computer program.

10. A computer program product comprising computer instructions, characterized in that, When the computer instructions are executed by the processor, they implement the data processing method described in claim 7.

Citation Information

Patent Citations

  • Security monitoring big data processing method and device based on cloud computing

    CN111931194A

  • Indoor area network optimization method and device and storage medium

    CN117956500A