A method for information security in wireless communication

Through the radio frequency fingerprint disassembly of wireless devices and the construction of environmental feature library, steady-state and dynamic environment hashing are generated for matching judgment, which solves the problems of abnormal changes and illegal device identification in the wireless communication environment, and realizes dynamic evaluation of device security and real-time security monitoring of communication systems.

CN119815350BActive Publication Date: 2025-07-01BEIJING TIANHONG TONGXIN TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510293617.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-13
Publication Date
2025-07-01
Estimated Expiration
2045-03-13

AI Technical Summary

Technical Problem

The prior art is difficult to monitor abnormal changes in the wireless communication environment in real time, it is impossible to promptly warn and identify illegal equipment, and there is a lack of a dynamic equipment risk monitoring mechanism, which affects the security of the communication system.

Method used

By extracting the radio frequency fingerprint of wireless devices, disassembly as a basis and disturbance fingerprint, a steady-state environment feature library is built, steady-state and dynamic environment hashes are generated, matching judgments are made, communication correction signals are generated, transmission keys are calculated, device matching is verified, device security is dynamically evaluated, and device security is calculated by calculating device limit values ​​for real-time monitoring and communication are restricted.

Benefits of technology

Real-time monitoring of wireless communication environment and timely warning of abnormal changes, accurately identify illegal devices, dynamically evaluate equipment security, and improve the security and stability of the communication system through real-time monitoring and restriction of communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119815350B_ABST
    Figure CN119815350B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for information security in wireless communication, which relates to the technical field of information security and includes: extracting the radio frequency fingerprint of a wireless device to disassemble it into a basic fingerprint and a perturbation fingerprint, and at the same time extracting the characteristics of the wireless communication environment to construct a steady-state environment feature library; obtaining a steady-state environment hash based on the steady-state environment feature library, comparing it with the dynamic environment hash generated by the current environment characteristics, and generating a communication correction signal when they do not match; using the communication correction signal to calculate the transmission key and correct the device, and performing hierarchical fingerprint verification on the device to be tested with a mismatched correction; if the device is completely mismatched, analyze the verification behavior to determine an untrusted device; finally, analyze the dynamic environment hashes of multiple monitoring periods, and replace the dissimilar dynamic environment hashes with lagged environment hashes. The present invention can detect abnormal communication environments, identify illegal devices, ensure the security of communication information, and improve the balance between verification efficiency and security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and particularly to a method for information security in wireless communication. Background Art

[0002] In today's digital age, wireless communication technology is widely used in various fields. However, with the popularization of wireless communication, information security issues have become increasingly prominent.

[0003] In the prior art, it is difficult to monitor the communication environment in real time. When new interference signals or malicious interferences appear in the environment, timely warnings cannot be given. If a steady-state environment feature library is constructed and the matching judgment of the steady-state environment hash and the dynamic environment hash is combined, abnormal changes in the communication environment can be monitored, and potential safety hazards such as interference sources can be discovered in a timely manner.

[0004] In the prior art, in detecting illegal devices, it often relies on a single detection method and cannot perform multi-level verification, or consumes too many resources during the detection process, affecting communication efficiency. If a hierarchical fingerprint verification strategy is adopted and progressive in-depth verification is carried out according to the risk level of the device, illegal devices can be identified, and at the same time, the security of the device can be dynamically evaluated. However, some illegally devices with ingenious disguises may be missed by the existing methods, achieving a balance between verification efficiency and security.

[0005] In the prior art, there is a lack of a dynamic monitoring mechanism for device risks, and the device risks are not tracked and evaluated in real time. If the device limit value is calculated to continuously monitor the device risk status and restrict the communication of untrusted devices in a timely manner, and effective preventive measures are taken in the face of potentially threatening devices, the security of the communication system can be guaranteed.

[0006] Therefore, the present invention provides a method for information security in wireless communication. Summary of the Invention

[0007] The purpose of the present invention is to provide a method for information security in wireless communication to solve at least one of the above-mentioned prior art problems.

[0008] In a first aspect, the present invention provides a method for information security in wireless communication, including the following steps:

[0009] Step 1: Extract the radio frequency fingerprint of the wireless device, perform fingerprint decomposition to obtain the basic and perturbed fingerprints, extract the environmental features of the wireless communication, and construct a steady-state environment feature library;

[0010] Step 2: Based on the steady-state environment feature library, extract the steady-state environment hash, analyze the features of the current environment to obtain the dynamic environment hash, and perform a matching judgment on the steady-state environment hash and the dynamic environment hash. If they do not match, generate a communication correction signal;

[0011] Step 3: Based on the communication correction signal, perform numerical analysis on the dynamic environment hash, calculate the transmission key, and use the transmission key to correct the sending device and the receiving device. If the correction does not match, obtain the device to be inspected, and verify whether the device to be inspected matches the registered device;

[0012] Step 4: If there is a complete mismatch, analyze the verification behavior of the device to obtain the device limit value, and perform restricted communication determination on the device based on the device limit value to obtain an untrusted device;

[0013] Step 5: Perform numerical analysis on the dynamic environment hashes of multiple monitoring cycles to obtain the lagged environment hash, perform similarity analysis with the dynamic environment hash. If they are not similar, the lagged environment hash replaces the dynamic environment hash.

[0014] In a second aspect, the present invention provides a system for information security in wireless communication, including the following modules:

[0015] Feature construction module: used to extract the radio frequency fingerprint of the wireless device, perform fingerprint decomposition to obtain the basic and perturbed fingerprints, extract the environmental features of the wireless communication, and construct a steady-state environmental feature library;

[0016] Environmental matching module: Based on the steady-state environmental feature library, extract the steady-state environment hash, analyze the features of the current environment to obtain the dynamic environment hash, and perform a matching judgment on the steady-state environment hash and the dynamic environment hash. If they do not match, generate a communication correction signal;

[0017] Device matching module: Based on the communication correction signal, used to perform numerical analysis on the dynamic environment hash, calculate the transmission key, and use the transmission key to correct the sending device and the receiving device. If the correction does not match, obtain the device to be inspected, and verify whether the device to be inspected matches the registered device;

[0018] Trusted analysis module: If there is a complete mismatch, used to analyze the verification behavior of the device to obtain the device limit value, and perform restricted communication determination on the device based on the device limit value to obtain an untrusted device;

[0019] Dynamic update module: used to perform numerical analysis on the dynamic environment hashes of multiple monitoring cycles to obtain the lagged environment hash, perform similarity analysis with the dynamic environment hash. If they are not similar, the lagged environment hash replaces the dynamic environment hash.

[0020] Advantages of the present invention:

[0021] 1. By taking advantage of the uniqueness of radio frequency fingerprints and decomposing them into basic fingerprints and perturbation fingerprints, it is possible to accurately identify devices in a communication network. Also, when communication fails, security authentication can be performed through basic fingerprint matching verification to check the legitimacy of communication devices, effectively preventing illegal devices from accessing and ensuring the security of communication data. A steady-state environment feature library is constructed, and based on this, a steady-state environment hash is generated. By judging the match with the dynamic environment hash and combining the calculation and analysis of transmission outliers, abnormal changes in the communication environment can be detected in a timely manner. This is conducive to providing a reliable early warning for ensuring the security of wireless communication information and reducing the possibility of information transmission in an insecure environment.

[0022] 2. Generate an initial key from wireless channel state information, and then calculate the transmission key in combination with the dynamic environment hash to encrypt and correct communication transmissions. The encryption system enhances the confidentiality and integrity of communication data, reduces the risk of data being stolen or tampered with during transmission, and improves the security of communication content. A hierarchical fingerprint verification strategy is adopted, and different levels of verification are carried out according to the risk level of the device. It can dynamically evaluate the security of the device, accurately identify illegal devices through gradually in-depth verification, and at the same time improve the verification efficiency, achieving a balance between verification efficiency and security, and effectively ensuring the normal operation of the communication system.

[0023] 3. By calculating the device limit value and comparing it with a preset threshold, the trustworthiness of the device can be accurately determined. For untrusted devices, their communication is restricted in a timely manner, and devices with lower device limit values are continuously monitored to dynamically grasp the device risk situation. Analyze the dynamic environment hashes of multiple monitoring cycles, and replace dissimilar dynamic environment hashes with lagged environment hashes, enabling the system to better adapt to environmental changes, ensuring the accuracy and timeliness of environmental features, and further enhancing the security and stability of the communication system. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0025] Figure 1 is a flowchart of an information security method for a wireless communication of the present invention;

[0026] Figure 2 is a flowchart for judging untrusted devices provided in the second embodiment of the present invention;

[0027] Figure 3 is a module diagram of a system for information security of a wireless communication provided in the fourth embodiment of the present invention;

[0028] Figure 4 It is a schematic structural diagram of the computer device provided in the fifth embodiment of the present invention. Specific implementation manners

[0029] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0030] Embodiment 1

[0031] As Figure 1 shown, a method for information security of wireless communication provided in the embodiment of the present invention specifically includes the following steps:

[0032] Step 1: Extract the radio frequency fingerprint of the wireless device, perform fingerprint decomposition to obtain the basic and perturbation fingerprints, extract the environmental characteristics of the wireless communication, and construct a steady-state environmental characteristic library;

[0033] In some embodiments, the radio frequency fingerprint of the wireless device is divided into a basic fingerprint and a perturbation fingerprint. By collecting the carrier frequency offset of the wireless device in a steady state within multiple monitoring periods and performing binary encoding on the carrier frequency offset, it is used as the basic fingerprint of the wireless communication device;

[0034] By intercepting the carrier frequency offset of the wireless device in a transient oscillation state during the power amplifier startup stage when the wireless device is in a steady state and performing binary encoding on the carrier frequency offset, it is used as the perturbation fingerprint of the wireless communication device;

[0035] It should be noted that the radio frequency fingerprint originates from the manufacturing tolerance and drift tolerance of the hardware components of the wireless device. The wireless device being in a steady state refers to a specific state in which the working state of the wireless device is relatively stable and the various parameters fluctuate less;

[0036] Store the basic fingerprint and perturbation fingerprint of the wireless device in the database, and at the same time mark the wireless device as a registered device;

[0037] In some embodiments, by obtaining the MAC address of the wireless device and performing AES-128 algorithm processing, the initial key of the wireless communication device is obtained;

[0038] It should be noted that the wireless sending device and the receiving device use the initial key to encrypt and transmit data packets;

[0039] The role of collecting the radio frequency fingerprint is: Role 1, used to accurately identify devices in the communication network;

[0040] Function 2: Used for security authentication and verification. When wireless communication fails, the system will perform matching verification on the collected basic fingerprints;

[0041] Function 3: Used for encrypted communication transmission;

[0042] In some embodiments, when the wireless device is in a steady state, signals are received through multiple spatially distributed antennas, and the angle of arrival of the signals is calculated using the phase difference of the signals arriving at different array elements. The variance of the angle of arrival of the signals of multiple antennas is calculated through the variance formula;

[0043] In some embodiments, when the wireless device is in a steady state, multipath components are separated from the channel impulse response, the delay and power of each path are recorded, and the distribution of signal power over time delay is obtained;

[0044] The obtained power delay distribution is normalized to obtain a normalized power delay distribution , denotes the time delay;

[0045] Normalized power delay distribution , and the delay spread entropy is calculated through the information entropy formula;

[0046] Based on the angle of arrival variance and the delay spread entropy, the dimension is removed, they are concatenated into a high-dimensional vector, and the high-dimensional vector is Min-Max normalized to obtain a normalized high-dimensional vector;

[0047] The normalized high-dimensional vectors in different environments are obtained to construct a steady-state environment feature library;

[0048] It should be noted that if the number of dominant paths is less than 3, the delay spread entropy is 0, where the environments include: home environment, office environment, commercial environment, etc.;

[0049] Among them, the functions of constructing the steady-state environment feature library are: Function 1, combined with the collected radio frequency fingerprints, can be used to detect abnormal behaviors in the communication environment;

[0050] Function 2, for interference identification. Information such as the delay spread entropy and the angle of arrival variance in the environmental feature vector can reflect the signal interference situation.

[0051] Step 2: Based on the steady-state environment feature library, the steady-state environment hash is extracted, the features of the current environment are analyzed to obtain the dynamic environment hash, and the steady-state environment hash and the dynamic environment hash are matched and judged. If they do not match, a communication correction signal is generated;

[0052] Based on the steady-state environment feature library, through the SHA-256 hash function, the hash value of the normalized high-dimensional vector of each scenario is calculated to obtain the steady-state environment hash;

[0053] Collect the angle of arrival variance and delay spread entropy of the signals of wireless devices in real time, splice and calculate to obtain a normalized high-dimensional vector, and perform a hash calculation on the normalized high-dimensional vector to obtain a dynamic environment hash;

[0054] It should be noted that since the same hash function is used, the lengths of the dynamic environment hash and the steady-state environment hash are the same;

[0055] Through the Hamming distance formula: , obtain the Hamming distance D between the dynamic environment hash and the steady-state environment hash hm , where X and Y are the binary string sequences of the dynamic environment hash and the steady-state environment hash respectively, is the exclusive OR operator;

[0056] If the Hamming distance between the dynamic environment hash and the steady-state environment hash is 0, it means that the characteristics of the dynamic environment and the steady-state environment are exactly the same;

[0057] It should be noted that the Hamming distance measures the number of different characters in the same position of two equal-length binary strings, reflecting the difference degree between the dynamic environment hash and the steady-state environment hash;

[0058] Since the hash value is calculated based on the normalized high-dimensional vector of the environmental characteristics, the larger the Hamming distance, the greater the difference between the dynamic environment where the wireless device is collected in real time and the scenarios in the steady-state environment feature library; the smaller the Hamming distance, the more similar the dynamic environment and the steady-state environment;

[0059] If the Hamming distance between the dynamic environment hash and the steady-state environment hash is not 0, obtain the sum of the characters of the hash values of the dynamic environment hash and the steady-state environment hash to obtain the hash character sum;

[0060] Perform a ratio process on the Hamming distance and the hash character sum to obtain the Hamming distance ratio;

[0061] Obtain the number of unmatched data packets and the number of sent packets of the wireless device after communication encryption using the initial key;

[0062] It should be noted that the wireless device includes a wireless transmitting device and a wireless receiving device. Those skilled in the art classify the data packets by performing matching verification on the data packets to obtain unmatched data packets. The matching verification includes hash verification and CRC verification;

[0063] Perform a difference process on the number of unmatched data packets and the number of sent packets, and then perform a ratio process on the obtained result and the number of sent packets to obtain the matching weight value;

[0064] Based on the matching weight value and the Hamming distance ratio, the transmission outlier is calculated through a weighted formula, and the weights of the matching weight value and the Hamming distance ratio are taken as 0.65 and 0.43 respectively;

[0065] Compare the transmission outlier with a preset transmission outlier threshold. If the transmission outlier is higher than the preset transmission outlier threshold, it is considered that the dynamic environment where the wireless device is collected in real time does not match the scenario in the steady-state environment feature library, and the number of transmission mismatch data packets exceeds the expectation. Generate a communication correction signal and record the current communication signal;

[0066] If the transmission outlier is lower than the preset transmission outlier threshold, it is considered that the matching difference between the dynamic environment where the wireless device is collected in real time and the scenario in the steady-state environment feature library is within the expected range, and no processing is performed;

[0067] It should be noted that the preset transmission outlier threshold is set by professionals in this field. The role of obtaining the transmission outlier is as follows:

[0068] Detect communication environment anomalies: The transmission outlier is calculated based on the matching of the steady-state environment hash and the dynamic environment hash. By monitoring the transmission outlier, anomalies in the communication environment can be detected in a timely manner, providing an early warning for ensuring the security of wireless communication information;

[0069] The technical solution of this embodiment is: Extract the radio frequency fingerprint of the wireless device, perform fingerprint decomposition to obtain the basic and perturbed fingerprints, extract the environmental features of the wireless communication, construct a steady-state environment feature library, based on the steady-state environment feature library, extract the steady-state environment hash, analyze the features of the current environment to obtain the dynamic environment hash, and perform a matching judgment on the steady-state environment hash and the dynamic environment hash. If they do not match, generate a communication correction signal, which can monitor anomalies in the communication environment and discover potential safety hazards such as interference sources in a timely manner.

[0070] Embodiment 2

[0071] As Figure 1 shown, a method for information security of wireless communication further includes the following steps:

[0072] Step 3: Based on the communication correction signal, perform numerical analysis on the dynamic environment hash, calculate the transmission key, use the transmission key to correct the sending device and the receiving device. If the correction does not match, obtain the device to be tested and verify whether the device to be tested matches the registered device;

[0073] Take the absolute value of the difference between the Hamming distance ratio of the wireless device and the preset Hamming distance ratio threshold to obtain the ratio threshold difference;

[0074] The dynamic environment hash of the wireless device is multiplied by the proportional threshold difference, and the result is rounded up to obtain a dynamic key number;

[0075] The dynamic environment is hashed and processed according to the dynamic key number to obtain a dynamic verification code;

[0076] It should be noted that the code fetching process refers to: intercepting from the starting point of the dynamic environment hash according to the dynamic key number;

[0077] The initial key and the dynamic verification code are concatenated to obtain the transmission key;

[0078] In some embodiments, the wireless device utilizes a transmission key, and the wireless device converts data into ciphertext using an encryption algorithm and the transmission key, and only a recipient holding the correct key can decrypt and restore the original data to encrypt and modify the communication transmission;

[0079] Obtain the number of unmatched data packets after encryption correction, and calculate the matching weight value after encryption correction;

[0080] Based on the encrypted matching weight value, the encrypted transmission anomaly value is calculated again;

[0081] If the encrypted and corrected transmission anomaly value is still higher than the preset transmission anomaly threshold, the wireless device is marked as a device to be inspected;

[0082] Start time domain signal backtracking to obtain the matching weight value of the device to be tested within the signal transmission period;

[0083] The matching weight values ​​are divided into three levels from small to large, and the verification fingerprint in the radio frequency fingerprint of the device to be verified is extracted to perform hierarchical fingerprint verification;

[0084] A1. Simple fingerprint verification: The basic fingerprint of the device to be verified is intercepted as the verification fingerprint for matching verification;

[0085] A2, Intermediate fingerprint verification: All basic fingerprints of the device to be verified and the intercepted part of the perturbation fingerprint are used as the verification fingerprint for matching verification;

[0086] A3. Complex fingerprint verification: Treat all basic fingerprints and all disturbance fingerprints of the verification device as verification fingerprints and perform matching verification;

[0087] It should be noted that professionals in this field intercept the basic fingerprint or disturbance fingerprint of the wireless device according to a fixed ratio, wherein the hierarchical fingerprint verification is performed to:

[0088] Function 1: Dynamically evaluate device security: Hierarchical fingerprint verification can dynamically evaluate the security of the device based on the verification results of the device at different stages, such as the change of matching weight value;

[0089] Function 2. Identify illegal devices: Through a step-by-step in-depth verification method, illegal devices can be identified to ensure the confidentiality and integrity of communication content;

[0090] Function 3. Improve the balance between verification efficiency and security: Hierarchical fingerprint verification targets different levels of verification based on the risk level of the device. While ensuring information security, it optimizes the verification process and improves the overall performance of the communication system;

[0091] Specifically, based on different levels of fingerprint verification, obtain the verification fingerprint of the device to be verified and the radio frequency fingerprint of the registered device in the database;

[0092] Calculate the Hamming distance between the verification fingerprint of the device to be verified and the radio frequency fingerprint of the registered device;

[0093] If the Hamming distance between the verification fingerprint of the device to be verified and the radio frequency fingerprint of the registered device is 0, it indicates that the device to be verified is a registered device;

[0094] If the Hamming distance between the verification fingerprint of the device to be verified and the radio frequency fingerprint of the registered device is not 0, store the radio frequency fingerprint of the device to be verified in the database and calculate the Hamming distance ratio between the device to be verified and the radio frequency fingerprint of the registered device;

[0095] It should be noted that by obtaining the sum of the hash characters of the radio frequency fingerprints of the device to be verified and the registered device, the Hamming distance ratio between the device to be verified and the registered device is further calculated;

[0096] If the Hamming distance ratio between the verification fingerprint of the device to be verified and the radio frequency fingerprint of the registered device is higher than the preset Hamming distance threshold, it is considered that the device to be verified and the registered device do not match at all;

[0097] If the Hamming distance ratio between the verification fingerprint of the device to be verified and the radio frequency fingerprint of the registered device is lower than the preset Hamming distance threshold, it is considered that the device to be verified and the registered device do not match completely, and a matching analysis signal is generated;

[0098] It should be noted that when the device to be verified and the registered device do not match completely, the Hamming distance between the verification fingerprint of the device to be verified and the radio frequency fingerprint of the registered device is not 0;

[0099] After multiple signal transmission cycles, by collecting the disturbance fingerprints of the registered device, segment the disturbance fingerprints according to the Poisson distribution, and update the disturbance fingerprint segments of the segmented part of the registered device;

[0100] Step 4. If there is no match at all, analyze the verification behavior of the device to obtain a device limit value, and based on the device limit value, determine the restricted communication of the device to obtain an untrusted device;

[0101] Based on the matching analysis signal, during multiple signal transmission cycles, re-verify the device to be verified, calculate the matching weight value of the device to be verified within the signal transmission cycle, and determine whether the grading of the fingerprint verification of the device to be verified shows an increasing trend;

[0102] Exemplarily, if the grading of the fingerprint verification of the device to be verified changes from A1 to A2, A3, or from A2 to A3, it is considered that the grading of the fingerprint verification of the device to be verified shows an increasing trend;

[0103] If the grading of the fingerprint verification of the device to be verified shows an increasing trend, obtain the difference between the Hamming distance ratios of the device to be verified in two adjacent times in the time dimension to get the distance ratio difference;

[0104] Obtain the historical verification times and the historical number of times of generating matching analysis signals of the device to be verified from the database;

[0105] Perform a ratio process on the historical number of times of generating matching analysis signals and the historical verification times to get the analysis verification ratio;

[0106] Based on the sum of the analysis verification ratio and the distance ratio difference, obtain the device limit value;

[0107] As Figure 2 shown, compare the device limit value with the preset device limit threshold. If the device limit value is higher than the preset device limit threshold, mark the device to be verified as an untrusted device;

[0108] If the device limit value is lower than the preset device limit threshold, it is still necessary to continuously monitor the device limit value of the device to be verified;

[0109] It should be noted that the function of the device limit value is as follows: Function 1, determining the trustworthiness of the device: It can judge whether the device to be verified is trustworthy, which helps to timely identify devices that may threaten information security, prevent them from accessing the communication network, and prevent illegal devices from stealing and tampering with communication data, ensuring the confidentiality and integrity of communication information;

[0110] Function 2, dynamically monitoring device risks: If the device limit value is lower than the preset threshold, still continuously monitor this value to grasp the device risk status in real time.

[0111] The technical solution of this embodiment is: Based on the communication correction signal, perform numerical analysis on the dynamic environment hash, calculate the transmission key, use the transmission key to correct the sending device and the receiving device. If the correction does not match, obtain the device to be verified, verify whether the device to be verified matches the registered device. If it does not match completely, analyze the verification behavior of the device to obtain the device limit value, and perform restricted communication determination on the device based on the device limit value to obtain an untrusted device, which is beneficial to improving the security and stability of the communication system.

[0112] Example Three

[0113] As Figure 1 shown, a method for information security in wireless communication further includes the following steps:

[0114] Step Five: Perform numerical analysis on the dynamic environment hashes of multiple monitoring cycles to obtain a lagged environment hash, perform similarity analysis with the dynamic environment hashes. If they are not similar, the lagged environment hash replaces the dynamic environment hash;

[0115] Based on untrusted devices, send marker signals to other communication devices through a database. Other wireless devices restrict communication with untrusted devices based on radio frequency fingerprints;

[0116] Obtain the dynamic environment hashes within multiple signal transmission cycles to obtain a lagged environment hash;

[0117] It should be noted that the lengths of the lagged environment hash and the dynamic environment hash are kept consistent;

[0118] Calculate the Hamming distance between the dynamic environment hash and the lagged environment hash;

[0119] If the Hamming distance between the dynamic environment hash and the lagged environment hash is 0, it indicates that the characteristics of the dynamic environment and the steady-state environment are completely consistent within multiple transmission cycles, and no processing is performed;

[0120] If the Hamming distance between the dynamic environment hash and the lagged environment hash is not 0, split the dynamic environment hash and the lagged environment hash into multiple sub-sections, and calculate the Hamming distance ratio of each sub-section;

[0121] It should be noted that the positions of splitting the sub-sections of the dynamic environment hash and the lagged environment hash are kept consistent, that is, the sub-sections of the dynamic environment hash and the lagged environment hash are in one-to-one correspondence;

[0122] Compare the Hamming distance ratio of each sub-section with a preset Hamming distance ratio threshold. If the Hamming distance ratio of each sub-section is higher than the preset Hamming distance ratio threshold, mark the sub-section as a characteristic sub-section;

[0123] In some embodiments, through the run test method, obtain the number of continuously occurring characteristic sub-sections and the number of all sub-sections;

[0124] It should be noted that the run test method sequentially checks the sub-sections. Starting from the starting position of the sub-section, scan in order to check whether a characteristic sub-section appears. When a continuously occurring characteristic sub-section is detected, it is regarded as a run. During the scanning process, continuously record the number of runs, and finally obtain the number of continuously occurring characteristic sub-sections;

[0125] Ratio processing is performed on the number of continuously occurring characteristic sub-sections and the number of all sub-sections to obtain a continuous section ratio;

[0126] The mean value of the Hamming distance ratios of all characteristic sub-sections is calculated, and deviation calculation is performed with a preset Hamming distance ratio threshold to obtain a distance difference ratio;

[0127] The continuous section ratio and the distance difference ratio are summed to obtain a section similarity;

[0128] It should be noted that the larger the continuous section ratio, the more similar, and the smaller the distance difference ratio, the more similar. Therefore, when performing the summation process, the reciprocal of the distance difference ratio is taken and then summed with the continuous section ratio;

[0129] The section similarity is compared with a preset similarity definition value. If the section similarity is lower than the preset similarity definition value, it is considered that the dynamic environment hash and the lag environment hash are not similar. Otherwise, the change of the similarity definition value is continuously monitored;

[0130] If the dynamic environment hash and the lag environment hash are not similar, the lag environment hash is used to replace the dynamic environment hash.

[0131] Embodiment 4

[0132] As Figure 3 shown, a system for information security in wireless communication, used to implement a method for information security in wireless communication, includes the following modules:

[0133] Feature construction module: used to extract the radio frequency fingerprint of the wireless device, perform fingerprint decomposition to obtain the basic and perturbed fingerprints, extract the environmental features of the wireless communication, and construct a steady-state environmental feature library;

[0134] Environmental matching module: Based on the steady-state environmental feature library, extract the steady-state environmental hash, analyze the features of the current environment to obtain the dynamic environmental hash, and perform matching judgment on the steady-state environmental hash and the dynamic environmental hash. If they do not match, generate a communication correction signal;

[0135] Device matching module: Based on the communication correction signal, used to perform numerical analysis on the dynamic environmental hash, calculate the transmission key, and correct the sending device and the receiving device using the transmission key. If the correction does not match, obtain the device to be tested and verify whether the device to be tested matches the registered device;

[0136] Trusted analysis module: If there is a complete mismatch, used to analyze the verification behavior of the device to obtain a device limit value, and perform restricted communication determination on the device based on the device limit value to obtain an untrusted device;

[0137] Dynamic update module: used to perform numerical analysis on the dynamic environment hashes of multiple monitoring cycles to obtain a lagged environment hash, perform similarity analysis with the dynamic environment hash, and if they are not similar, the lagged environment hash replaces the dynamic environment hash.

[0138] Embodiment 5

[0139] Refer to Figure 4 , the embodiment of the present invention also provides a computer device 3, including: a memory 302, a processor 301, and a computer program 303 stored on the memory 302. When the computer program 303 is executed on the processor 301, it implements a method for information security of wireless communication as described in any one of the above methods.

[0140] The computer device 3 may be a computing device such as a desktop computer, a notebook, a palm computer, and a cloud server. The computer device 3 may include, but is not limited to, a processor 301 and a memory 302. Those skilled in the art can understand;

[0141] Figure 4 This is only an example of the computer device 3 and does not limit the computer device 3. It may include more or fewer components than shown in the figure, or combine some components, or different components. For example, it may also include input / output devices, network access devices, etc.

[0142] The so-called processor 301 may be a central processing unit (CPU), and the processor 301 may also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0143] The memory 302 may be an internal storage unit of the computer device 3 in some embodiments, such as the hard disk or memory of the computer device 3. The memory 302 may also be an external storage device of the computer device 3 in other embodiments, such as a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, etc. equipped on the computer device 3. Further, the memory 302 may also include both the internal storage unit and the external storage device of the computer device 3. The memory 302 is used to store an operating system, application programs, a boot loader, data, and other programs, such as the program code of the computer program. The memory 302 may also be used to temporarily store the data that has been output or will be output.

[0144] Embodiment Six

[0145] The embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is run by a processor, it implements a method for information security of wireless communication as described in any one of the above methods.

[0146] In this embodiment, if the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, to implement all or part of the processes in the above embodiment methods of the present application, a computer program can be used to instruct the relevant hardware to complete. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, it can implement the steps of the above various method embodiments. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, an executable file, or some intermediate form, etc. The computer-readable medium may at least include: any entity or device, a recording medium, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunication signal, and a software distribution medium that can carry the computer program code to the photographing device / terminal device. For example, a USB flash drive, a mobile hard disk, a magnetic disk, or an optical disc, etc. In some jurisdictions, according to legislation and patent practice, the computer-readable medium may not be an electrical carrier signal and a telecommunication signal.

[0147] In the above embodiments, the descriptions of the various embodiments have their own focuses. For the parts not detailed or recorded in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.

[0148] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0149] In the embodiments disclosed in this application, it should be understood that the disclosed devices / terminal devices and methods can be implemented in other ways. For example, the device / terminal device embodiments described above are merely illustrative. For example, the division of the modules or units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of the devices or units can be in electrical, mechanical or other forms.

[0150] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place, or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0151] The above formulas are all dimensionless and take their numerical calculations. The formulas are obtained by collecting a large amount of data for software simulation to obtain a formula that is closest to the actual situation. The preset parameters in the formulas are set by technicians in this field according to the actual situation.

[0152] The above has described a detailed description of an embodiment of the present invention, but the content described is only a preferred embodiment of the present invention and cannot be considered to be used to limit the scope of implementation of the present invention. All equivalent changes and improvements made within the scope of the application of the present invention should still fall within the scope covered by the patent of the present invention.

Claims

1. A method for information security of wireless communication, characterized in that: The following steps are involved: Perform numerical analysis on the dynamic environment hash to calculate the transmission key, use the transmission key to modify the sending device and the receiving device. If the modifications do not match, the device to be tested is obtained. Obtain the matching weight value of the device to be tested within the signal transmission period; The matching weight values ​​are divided into grades according to the numerical values, and the verification fingerprint in the radio frequency fingerprint of the device to be verified is extracted to perform hierarchical fingerprint verification; By calculating the Hamming distance ratio between the verification fingerprint of the device to be verified and the radio frequency fingerprint of the registered device, and performing a matching judgment, it is verified whether the device to be verified matches the registered device; If there is no match at all, the verification behavior of the device is analyzed to obtain the device restriction value, and based on the device restriction value, the device is restricted from communication and determined to be an untrusted device; Perform numerical analysis on the dynamic environment hash of multiple monitoring cycles to obtain the lagged environment hash, and perform similarity analysis with the dynamic environment hash. If they are not similar, the lagged environment hash replaces the dynamic environment hash. Split the dynamic environment hash and the delayed environment hash into multiple sub-segments, and if the Hamming distance ratio of each sub-segment is higher than a preset Hamming distance ratio threshold, mark the sub-segment as a characteristic sub-segment; Calculate the proportion of the number of consecutive characteristic sub-segments to obtain the continuous segment ratio; Calculate the deviation ratio between the mean of the Hamming distance ratio of all feature sub-segments and the preset Hamming distance ratio threshold to obtain the distance difference ratio; The continuous segment ratio and the distance difference ratio are summed to obtain the segment similarity; If the segment similarity is lower than the preset similarity threshold, the dynamic environment hash and the delayed environment hash are considered to be dissimilar.

2. The method for ensuring information security of wireless communication according to claim 1, characterized in that: The dynamic environment hash is obtained as follows: Extract the environmental characteristics of wireless communications and build a steady-state environmental characteristics library; Based on the steady-state environment feature library, the steady-state environment hash is extracted, the characteristics of the current environment are analyzed to obtain the dynamic environment hash, and the steady-state environment hash and the dynamic environment hash are matched and judged.

3. The method for ensuring information security of wireless communication according to claim 2, characterized in that: The matching judgment method for the steady-state environment hash and the dynamic environment hash is: Obtain the Hamming distance between dynamic environment hash and steady-state environment hash through the Hamming distance formula; If the Hamming distance between the dynamic environment hash and the steady-state environment hash is not 0, the dynamic environment hash is analyzed to obtain the Hamming distance ratio; Obtain the number of unmatched data packets and the number of sent data packets after communication encryption; Calculate the deviation ratio between the number of unmatched data packets and the number of sent data packets to obtain the matching weight value; The transmission anomaly value is obtained by weighted calculation of the matching weight value and the Hamming distance; If the transmission anomaly value is higher than the preset transmission anomaly threshold, the dynamic environment of the wireless device collected in real time does not match the scene in the steady-state environment feature library.

4. The method for ensuring information security of wireless communication according to claim 1, characterized in that: The transmission key is obtained in the following manner: Subtract the Hamming distance ratio of the wireless device from the preset Hamming distance ratio threshold and take the absolute value to obtain a proportional threshold difference; The dynamic environment hash of the wireless device is multiplied and rounded by the ratio threshold difference to obtain a dynamic key number, and the dynamic environment hash is coded to obtain a dynamic check code; Get the initial key, concatenate the initial key and the dynamic verification code to get the transmission key.

5. The method for ensuring information security of wireless communication according to claim 1, characterized in that: The classification method is as follows: By intercepting the basic fingerprint of the device to be verified as the verification fingerprint, matching verification is performed; All basic fingerprints of the device to be verified and the intercepted part of the disturbance fingerprint are used as verification fingerprints for matching verification; All basic fingerprints and all disturbance fingerprints of the device to be verified are used as verification fingerprints for matching verification.

6. The method for ensuring information security of wireless communication according to claim 1, characterized in that: The method for obtaining the untrusted device is as follows: Re-verify the device to be verified, calculate the matching weight value of the device to be verified within the signal transmission period, and if the fingerprint verification level of the device to be verified shows an increasing trend, perform quantitative analysis on the verification behavior of the device to be verified to obtain the device limit value; If the device limit value is higher than the preset device limit threshold, the device to be inspected will be marked as an untrusted device.

7. The method for ensuring information security of wireless communications according to claim 6, characterized in that: The method for quantitatively analyzing the calibration behavior of the device to be calibrated is: Obtain the difference between the Hamming distance ratios of two adjacent devices to be verified, and obtain the distance ratio difference; The number of times of historically generated matching analysis signals is processed with the number of historical tests to obtain the analysis test ratio; The equipment limit value is obtained based on the sum of the analysis inspection ratio and the distance ratio difference.

Citation Information

Patent Citations

  • Terminal security credible state monitoring method and system based on device fingerprint

    CN117896074A