A wireless data transmission security detection method for intelligent buildings

Through the combination of multi-band RF front-end and multi-source interference model, the time-frequency joint entropy characteristics are extracted and the detection threshold is dynamically adjusted, and the detection threshold is dynamically validated, combined with the generation of adversarial networks, the problem of wireless communication security detection in intelligent buildings is solved, and the signal detection and defense capabilities in complex electromagnetic environments are improved.

CN119907004BActive Publication Date: 2025-06-06SICHUAN ELECTRONIC PROD SUPERVISION & INSPECTION INST
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510405400.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-02
Publication Date
2025-06-06
Estimated Expiration
2045-04-02

AI Technical Summary

Technical Problem

The intensive deployment of wireless communication technology in smart buildings leads to congestion of spectrum resources, and traditional security detection methods are difficult to accurately distinguish between legal signals and attack signals, and fail to effectively defend against unknown attack modes.

Method used

The multi-band RF front-end is used to synchronously acquire mixed signals, and frequency domain distortion compensation is performed through the multi-source interference superposition model, time-frequency joint entropy characteristics are extracted, abnormal detection thresholds are dynamically adjusted, and adversarial verification is performed by generating an adversarial network.

Benefits of technology

Effectively improve signal quality, accurately quantify the interference superposition effect, improve the distinction and generalization ability of abnormal signal detection, and can deal with multiple attack modes in complex electromagnetic environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119907004B_ABST
    Figure CN119907004B_ABST
Patent Text Reader

Abstract

The present invention provides a radio data transmission security detection method for intelligent buildings, which relates to the field of data security technology. The method includes the following steps: synchronously collecting mixed signals within a preset frequency band through a multi-band radio frequency front end, and performing denoising preprocessing on the signal; constructing a multi-source interference superposition model to compensate for the frequency domain distortion of the received signal; extracting time-frequency joint entropy features; dynamically adjusting the anomaly detection threshold based on historical data Mahalanobis distance statistics and real-time bit error rate; and performing adversarial verification on suspicious signals through a generative adversarial network. The method of the present invention can effectively solve the three major problems of abnormal signal detection in complex electromagnetic environments of intelligent buildings through the deep integration of multi-band signal processing, physical environment modeling, dynamic feature extraction, adaptive decision-making and adversarial verification: signal distortion caused by interference superposition, insufficient discrimination of traditional features, and weak generalization ability of unknown attack modes.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention relates to the technical field of data security, and in particular to a radio data transmission security detection method for intelligent buildings. Background Art

[0002] At present, the dense deployment of wireless communication technologies (such as Wi-Fi, Bluetooth, Zigbee, NB-IoT, etc.) in smart buildings has led to high congestion of spectrum resources in the 2.4GHz ISM band and adjacent bands. The co-channel interference between multi-standard devices, adjacent channel leakage, and multipath effects caused by building structures will cause signal waveform distortion, increased bit error rate, and packet timing confusion.

[0003] The coupling effect of such physical environment and spectrum competition causes the following problems in traditional security detection methods based on fixed thresholds or single-dimensional features:

[0004] First, the dynamics of interference causes uncontrollable signal distortion, making it impossible to accurately restore the original signal spectrum.

[0005] Second, the anomaly detection features lack discrimination, making it difficult to accurately distinguish between legitimate signals and attack signals.

[0006] Third, the defense capability against unknown attack modes is weak. Summary of the invention

[0007] In order to solve the technical problems in the related art, the present invention provides a radio data transmission security detection method for intelligent buildings.

[0008] In order to achieve the above object, the technical solution adopted by the present invention is:

[0009] A wireless data transmission security detection method for intelligent buildings comprises the following steps:

[0010] Step S1: synchronously collect mixed signals within a preset frequency band through a multi-band RF front end, and perform denoising preprocessing on the signals;

[0011] Step S2: construct a multi-source interference superposition model based on the interference source type, spatial location and building material attenuation parameters to compensate for the frequency domain distortion of the received signal;

[0012] Step S3: extracting a time-frequency joint entropy feature from the preprocessed signal, the feature integrating the time-frequency distribution matrix of the short-time Fourier transform and its gradient correlation;

[0013] Step S4: dynamically adjusting the anomaly detection threshold based on the historical data Mahalanobis distance statistics and the real-time bit error rate to identify forged data packets and illegal instructions;

[0014] Step S5: Perform adversarial verification on suspicious signals through a generative adversarial network, where the generator simulates potential attack signals and the discriminator combines a gradient penalty mechanism to enhance generalization detection capabilities.

[0015] Optionally, in step S1, the multi-band RF front end includes at least three parallel receiving channels, which are respectively configured as 20 MHz, 40 MHz and 80 MHz instantaneous bandwidth modes, and cover a preset frequency band range through a time division multiplexing mechanism.

[0016] Optionally, the denoising preprocessing of the signal in step S1 specifically includes:

[0017] The adaptive wavelet threshold algorithm is used to pre-process the signal for denoising, where the threshold value is dynamically adjusted according to the real-time signal-to-interference-noise ratio. The threshold calculation formula is:

[0018]

[0019] In the formula, is the threshold value, For the The standard deviation of the layer wavelet coefficients, is the signal length, is the signal-to-dryness ratio estimated in real time.

[0020] Optionally, in step S2, the multi-source interference superposition model is expressed as:

[0021]

[0022] In the formula, For the frequency and time The total interference field strength function on For the The time-varying amplitude of an interference source, is the attenuation coefficient of building materials, is the spatial distance between the interference source and the detection point, , For the The center frequency of the interference source, For the The signal bandwidth of the interference source is is Gaussian white noise.

[0023] Optionally, in step S3, the time-frequency joint entropy feature is extracted according to the following formula:

[0024]

[0025] In the formula, is the time-frequency joint entropy, is the number of time frames, is the number of frequency points, For the time frame, The time-frequency matrix corresponding to the frequency points is: is the weight coefficient, is the correlation function between the time domain gradient and the frequency domain gradient, is the time domain gradient operator, which calculates the difference along the time axis. is the frequency domain gradient operator, which calculates the difference along the frequency axis. is a time-frequency matrix.

[0026] Optionally, in step S4, the anomaly detection threshold satisfies:

[0027]

[0028] In the formula, For in time The adaptive anomaly detection threshold set below, is the mean of the Mahalanobis distance in historical data, is the standard deviation of the Mahalanobis distance in the historical data, is the average bit error rate in the sliding time window.

[0029] Optionally, the length of the sliding time window is configured to be between 30 seconds and 5 minutes, and when the average bit error rate exceeds a set threshold, the interference source location subroutine is automatically triggered.

[0030] Optionally, in step S5, performing adversarial verification on the suspicious signal by generating an adversarial network specifically includes:

[0031] Design Generator Simulate attack signal, discriminator The optimization is based on the following formula:

[0032]

[0033] In the formula, is the discriminator function, that is, the expected value of the logarithmic probability of the real data after passing through the discriminator, is the discriminator, used to output input data is the true probability, For real data, is the generator function, i.e., the logarithmic expected value of the probability of misjudging the generated data by the discriminator, is a generator that inputs noise and outputs fake data, is the latent spatial noise, To control the gradient penalty coefficient, For input data The gradient operation of For input data.

[0034] Optionally, the generator Potential spatial noise of the input It obeys a Gaussian distribution with a mean of 0 and a variance of 1, and the dimension of the latent space is set to 1 / 4 of the number of signal sampling points.

[0035] Optionally, the method is applied to the security verification of NB-IoT meter data in smart buildings, and when an abnormal high-frequency component signal is detected in the elevator shaft, the billing system isolation mechanism is automatically triggered; or,

[0036] The method is applied to a wireless access controller using the Bluetooth protocol in an intelligent building. When the frequency-combined entropy exceeds a preset threshold, the face recognition secondary verification is automatically triggered and an alarm log is uploaded; or,

[0037] The method is applied to the Zigbee wireless node of the fire broadcast system in the intelligent building. When the asymmetric double-peak frequency domain characteristics are detected in the fire alarm command signal, the method immediately switches to the wired redundant channel and marks the contaminated wireless channel as isolated; or,

[0038] The method is applied to the LoRa-modulated air conditioning group control system in the intelligent building. When the discriminator output probability is lower than 0.5, the instruction hash value blockchain verification is started to prevent forged overload cooling instruction attacks.

[0039] Beneficial effects:

[0040] 1. Through the above technical solution, first, in the step S1, the method of the present invention can achieve full coverage acquisition of the corresponding frequency band by synchronously collecting mixed signals within the preset frequency band range through the multi-band RF front end, and can effectively avoid the signal omission problem caused by bandwidth limitation of traditional single-channel equipment. By combining denoising preprocessing, it can effectively suppress non-stationary noise and effectively improve signal quality.

[0041] Second, in step S2, the method of the present invention can more accurately quantify the interference superposition effect by modeling the time-varying amplitude, spatial attenuation and frequency domain characteristics of multi-source interference.

[0042] Third, in the existing related technologies, generally only frequency domain or time domain features are used, while in step S3 of the present invention, the time-frequency joint entropy captures the dynamic characteristics of the signal through short-time Fourier transform, and combines the time-frequency gradient correlation to enhance the abnormal state recognition.

[0043] Fourthly, in step S4 of the present invention, the abnormality detection threshold is dynamically adjusted based on the historical Mahalanobis distance and the real-time bit error rate, which can effectively avoid the problem that the traditional fixed threshold fails when the environment changes suddenly.

[0044] Fifth, in step S5 of the present invention, the generator simulates potential attack signals, and the discriminator can enhance the generalization detection capability through the gradient penalty mechanism to avoid overfitting known attack patterns.

[0045] In summary, the steps of the method of the present invention form a closed-loop detection chain, wherein steps S1 to S2 can ensure the reliability of the physical level of signal acquisition and interference compensation, step S3 extracts high-discrimination features, step S4 dynamically optimizes the decision boundary according to environmental changes, and step S5 covers unknown attack types through adversarial learning. In this way, through the deep integration of multi-band signal processing, physical environment modeling, dynamic feature extraction, adaptive decision-making and adversarial verification through the method of the present invention, the three major problems of abnormal signal detection in the complex electromagnetic environment of intelligent buildings can be effectively solved: interference superposition leads to signal distortion, insufficient discrimination of traditional features, and weak generalization ability of unknown attack modes.

[0046] 2. Other beneficial effects or advantages of the present invention will be described in detail in the specific implementation manner. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without paying any creative labor.

[0048] in:

[0049] Figure 1 It is a schematic flow chart of the steps of a radio data transmission security detection method for intelligent buildings provided by an exemplary embodiment of the present invention. DETAILED DESCRIPTION

[0050] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments.

[0051] Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the invention claimed for protection, but merely represents selected embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0052] In addition, the terms "including" and "having" and any variations thereof mentioned in the description of the present invention are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but optionally includes other steps or units that are not listed, or optionally includes other steps or units that are inherent to these processes, methods, products or devices. It should also be noted that in the embodiments of the present invention, words such as "exemplary" or "for example" are used to indicate examples, illustrations or explanations. Any embodiment or design described as "exemplary" or "for example" in the embodiments of the present invention should not be interpreted as being more preferred or more advantageous than other embodiments or design. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a specific way.

[0053] To facilitate understanding by relevant technical personnel, the problems existing in the existing related technologies are described in more detail below.

[0054] In smart building environments, the dense deployment of wireless communication technologies has led to highly crowded spectrum resources in the 2.4GHz ISM band and adjacent bands. Co-channel interference between multi-standard devices, adjacent-channel leakage, and multipath effects caused by building structures can cause signal waveform distortion, increased bit error rates, and packet timing confusion.

[0055] Especially in closed environments with a lot of metal, such as elevator shafts and underground parking lots, electromagnetic wave propagation is affected by both the Faraday cage effect and the attenuation of concrete material (typical attenuation coefficient β=3-5dB / m), and the signal power may drop by more than 20dB.

[0056] The coupling effect of such physical environment and spectrum competition causes the following problems in traditional security detection methods based on fixed thresholds or single-dimensional features:

[0057] First, the dynamic nature of interference causes uncontrollable signal distortion. In the prior art, static interference suppression algorithms are generally used. However, they do not take into account the time-varying amplitude (such as Wi-Fi burst traffic) and spatial distribution (such as random position changes of mobile devices) of the interference source, resulting in the accumulation of frequency domain compensation deviations.

[0058] For example, when the NB-IoT meter signal in the elevator shaft overlaps with the existing channel of the neighboring AP, the traditional method cannot accurately restore the original signal spectrum because it ignores the combined impact of the interference signal bandwidth and center frequency offset.

[0059] Second, the anomaly detection feature has insufficient differentiation. The current mainstream solutions rely on time domain bit error rate or frequency domain power spectrum entropy as detection indicators, but in multi-device concurrent scenarios, the short-term burst packet loss of legitimate signals and the disguised packet loss of attack signals are highly similar in a single domain feature.

[0060] For example, when the bit error rate of the elevator access control Bluetooth signal and the forged command is 10^-3, the classification accuracy of the traditional method is very low.

[0061] Third, the defense capability against unknown attack patterns is weak. In existing technologies, detection systems based on rule bases or supervised learning are difficult to deal with new data injection attacks.

[0062] For example, the LoRa spread spectrum feature can be used to forge NB-IoT MAC frames. Attackers can use software-defined radio to dynamically adjust the time-frequency characteristics of the attack signal, causing traditional detectors to miss detection due to feature mismatch.

[0063] This is explained below using a typical scenario.

[0064] The NB-IoT meter in the elevator shaft needs to work under a certain weak field strength, but the shaft containing a lot of metal will reflect the signal of the ZigBee temperature sensor, causing the signal-to-noise ratio of the meter receiving end to be lower than a certain value. At this time, the attacker can bypass the primary detection based on bit error rate and signal strength and tamper with the energy metering data by injecting forged instructions similar to the time-frequency characteristics of the meter heartbeat packet (for example, period 1s, bandwidth 180kHz). Existing technologies cannot achieve reliable security protection in such complex electromagnetic environments due to the lack of dynamic modeling of joint time-frequency characteristics and quantitative analysis of interference physical mechanisms.

[0065] The technical solution of the present invention is described in detail below with reference to the accompanying drawings.

[0066] Example 1

[0067] like Figure 1 As shown, this embodiment provides a wireless data transmission security detection method for intelligent buildings, comprising the following steps:

[0068] Step S1: synchronously collect mixed signals within a preset frequency band through a multi-band RF front end, and perform denoising preprocessing on the signals;

[0069] Step S2: construct a multi-source interference superposition model based on the interference source type, spatial location and building material attenuation parameters to compensate for the frequency domain distortion of the received signal;

[0070] Step S3: extracting a time-frequency joint entropy feature from the preprocessed signal, the feature integrating the time-frequency distribution matrix of the short-time Fourier transform and its gradient correlation;

[0071] Step S4: dynamically adjusting the anomaly detection threshold based on the historical data Mahalanobis distance statistics and the real-time bit error rate to identify forged data packets and illegal instructions;

[0072] Step S5: Perform adversarial verification on suspicious signals through a generative adversarial network, where the generator simulates potential attack signals and the discriminator combines a gradient penalty mechanism to enhance generalization detection capabilities.

[0073] Through the above technical solution, first, in the step S1, the method of the present invention can achieve full coverage acquisition of the corresponding frequency band (for example, it can ensure the synchronous capture of Wi-Fi, Bluetooth, Zigbee and other signals) by synchronously collecting mixed signals within the preset frequency band through a multi-band RF front end (for example, the 20MHz, 40MHz and 80MHz parallel channels described below), and can effectively avoid the signal omission problem caused by bandwidth limitation of traditional single-channel devices. By combining denoising preprocessing, it can effectively suppress non-stationary noise (for example, elevator motor pulse interference noise), and can effectively improve signal quality. For example, through this step, the weak high-frequency component of the NB-IoT meter signal in the elevator shaft can be captured, and the burst noise of the elevator access control Bluetooth signal can be filtered out, providing high-fidelity data for subsequent analysis.

[0074] Second, in step S2, the method of the present invention can more accurately quantify the interference superposition effect by modeling the time-varying amplitude, spatial attenuation (e.g., signal penetration loss of building materials) and frequency domain characteristics of multi-source interference (e.g., Wi-Fi, Bluetooth, Zigbee). For example, when the NB-IoT meter signal in the elevator shaft is superimposed with the interference of the adjacent Wi-Fi router due to the attenuation of the building wall, the multi-source interference superposition model can calculate the total interference field strength and restore the original signal spectrum through frequency domain inverse compensation, so that the subsequent feature extraction is free from the frequency deviation caused by the coexistence of multiple devices.

[0075] Third, in the existing related technologies, only frequency domain or time domain features are generally used, while in step S3 of the present invention, the time-frequency joint entropy captures the dynamic characteristics of the signal through short-time Fourier transform, and combines the time-frequency gradient correlation to enhance the abnormal state recognition. For example, forged data packets often have abnormal time-frequency energy distribution (for example, asymmetric bimodal features) due to the unstable clock of the attacking device, while the time-frequency gradient changes of the legitimate signal are consistent. In this way, the detection sensitivity of forged meter instructions in the elevator shaft can be improved through the time-frequency joint entropy feature.

[0076] Fourth, in step S4 of the present invention, the abnormal detection threshold is dynamically adjusted based on the historical Mahalanobis distance and the real-time bit error rate, which can effectively avoid the problem that the traditional fixed threshold fails when the environment changes suddenly. For example, when the bit error rate of the elevator shaft access control system suddenly increases due to metal shielding, the abnormal detection threshold can be automatically relaxed to avoid false alarms; and when the bit error rate is normal, the abnormal detection threshold can be tightened to detect hidden attacks.

[0077] Fifth, in step S5 of the present invention, the generator simulates potential attack signals (e.g., replay attacks, protocol vulnerability injection, etc.), and the discriminator can enhance the generalization detection capability through the gradient penalty mechanism to avoid overfitting known attack patterns. For example, for the forged "meter reset" instruction in the elevator shaft (simulating the NB-IoT protocol format), the discriminator can identify the subtle differences in the joint time-frequency entropy (e.g., the lack of harmonic components) between it and the legitimate instruction, which can effectively improve the detection accuracy.

[0078] In summary, the steps of the method of the present invention form a closed-loop detection chain, wherein steps S1 to S2 can ensure the reliability of the physical level of signal acquisition and interference compensation, step S3 extracts high-discrimination features, step S4 dynamically optimizes the decision boundary according to environmental changes, and step S5 covers unknown attack types through adversarial learning. In this way, through the deep integration of multi-band signal processing, physical environment modeling, dynamic feature extraction, adaptive decision-making and adversarial verification through the method of the present invention, the three major problems of abnormal signal detection in the complex electromagnetic environment of intelligent buildings can be effectively solved: interference superposition leads to signal distortion, insufficient discrimination of traditional features, and weak generalization ability of unknown attack modes.

[0079] The implementation process of the method of the present invention is described below in conjunction with two exemplary implementations.

[0080] In the first exemplary implementation, taking the NB-IoT electric meter in the elevator shaft as an example, when the attacker injects a forged "high energy consumption pulse" signal, step S2 can be used to compensate for the frequency deviation caused by the metal shaft, and step S3 can be used to identify its time-frequency entropy anomaly (energy concentrated in the unauthorized frequency band). In step S5, GAN can be used to identify it as a malicious instruction, and the system can immediately isolate the electric meter and switch to a redundant communication channel.

[0081] The second exemplary implementation method takes the Bluetooth access control system as an example. For Bluetooth relay attacks, through step S4, the threshold can be dynamically relaxed according to the increase in the bit error rate to avoid false locking of the access control system. At the same time, the discriminator in step S5 identifies the timestamp anomaly of the replayed signal, which can trigger secondary facial verification and block illegal intrusion.

[0082] In one embodiment of the present invention, in step S1, the multi-band RF front end includes at least three parallel receiving channels, which are respectively configured as 20MHz, 40MHz and 80MHz instantaneous bandwidth modes, and cover a preset frequency band range through a time division multiplexing mechanism.

[0083] In this implementation, first, by configuring parallel receiving channels with three instantaneous bandwidths of 20MHz, 40MHz and 80MHz, the spectrum characteristics of different wireless standards (e.g., Wi-Fi, Bluetooth, Zigbee, etc.) in smart buildings can be flexibly adapted. For example, the 80MHz bandwidth is suitable for full-band capture of high-speed Wi-Fi signals, while the 20MHz bandwidth is suitable for high-resolution analysis of narrowband signals (e.g., Bluetooth), which can effectively improve the compatibility of the RF front end with complex spectrum environments.

[0084] Second, through the time division multiplexing (TDM) mechanism, the three receiving channels work in turns according to time slices, covering a wider range of preset frequency bands (such as the 2.4GHz ISM band and adjacent bands). Compared with a single broadband receiver, this can reduce the requirements for hardware sampling rate, reduce costs and power consumption, and effectively avoid mutual interference when multiple channels work simultaneously.

[0085] Third, in addition, in scenarios where the spectrum is highly crowded, the combination of different bandwidth modes enables the system to quickly switch scanning strategies. For example, when sudden interference is detected, the 80MHz channel can quickly locate the approximate frequency band of the interference source, while the 40MHz or 20MHz channel then performs refined feature extraction. In this way, this hierarchical monitoring mechanism can effectively enhance the real-time response capability to dynamic interference.

[0086] In this implementation, it should be noted that for a multi-channel parallel reception architecture, at least three independent RF links (e.g., 20MHz, 40MHz, and 80MHz) can be used, each of which is equipped with a corresponding ADC and digital down-conversion module to achieve physical layer isolation. For example, a 20MHz channel can be used for high-sensitivity reception of narrowband signals (e.g., ZigBee), and an 80MHz channel can be used for OFDMA wideband resolution of Wi-Fi6.

[0087] Second, for the preset frequency band range, it can be set to 2.4-2.484GHz ISM to cover most of the current multi-standard devices.

[0088] In one embodiment of the present invention, the denoising preprocessing of the signal in step S1 specifically includes:

[0089] The adaptive wavelet threshold algorithm is used to pre-process the signal for denoising, where the threshold value is dynamically adjusted according to the real-time signal-to-interference-noise ratio. The threshold calculation formula is:

[0090]

[0091] In the formula, is the threshold value, For the The standard deviation of the layer wavelet coefficients, is the signal length, is the signal-to-dryness ratio estimated in real time.

[0092] In this embodiment, first, the adaptive wavelet threshold algorithm of the present invention dynamically adjusts the denoising threshold through the real-time estimated signal-to-noise ratio (SINR), which can effectively deal with the noise fluctuation caused by multi-source interference (e.g., co-frequency devices, building material attenuation, etc.) of wireless signals in smart buildings. For example, in low signal-to-noise ratio scenarios, the threshold is automatically increased to filter out strong background noise; in high signal-to-noise ratio scenarios, the threshold is reduced to retain signal details.

[0093] Second, the multi-resolution characteristics of wavelet transform (e.g., the number of decomposition levels) ) can support hierarchical processing of noise in different frequency bands to preserve multi-scale signal features. For example, high-frequency wavelet coefficients (corresponding to pulse interference) can be truncated by hard threshold, and low-frequency coefficients (corresponding to multipath effect) can be smoothed by soft threshold, thus avoiding signal distortion or detail loss caused by traditional fixed threshold algorithms.

[0094] Third, for the threshold calculation formula, first, by pre-calculating and sliding window , which can control the computational complexity at the O(N) level to meet the processing requirements of real-time signals in smart buildings. Real-time feedback of environmental interference intensity, its reciprocal Make sure you can increase the threshold to suppress noise when interference is high, and decrease the threshold to preserve signal details when interference is low.

[0095] For example, in a smart building, when multiple Bluetooth devices (20MHz bandwidth) and Wi-Fi routers (80MHz bandwidth) coexist, the adaptive wavelet threshold algorithm of the present invention can dynamically distinguish the narrowband noise of the Bluetooth signal from the broadband interference of Wi-Fi, thereby avoiding the loss of Bluetooth data packets that may be caused by traditional fixed thresholds.

[0096] In one embodiment of the present invention, in step S2, the multi-source interference superposition model is expressed as:

[0097]

[0098] In the formula, For the frequency and time The total interference field strength function on For the The time-varying amplitude of an interference source, is the attenuation coefficient of building materials, is the spatial distance between the interference source and the detection point, , For the The center frequency of the interference source, For the The signal bandwidth of the interference source is is Gaussian white noise.

[0099] In this embodiment, first, the multi-source interference superposition model of the present invention can comprehensively simulate the time-varying amplitude interference (for example, Wi-Fi burst traffic), spatial attenuation (for example, distance and material attenuation) and spectrum leakage (adjacent channel interference) in intelligent buildings, thereby effectively improving the accuracy of interference compensation.

[0100] Second, the multi-source interference superposition model of the present invention uses time-varying amplitude , can monitor the power fluctuation of the interference source in real time and dynamically update the interference intensity. , combined with building structure data (building material attenuation coefficient ) and the interference source location data (the spatial distance between the interference source and the detection point ), which can more accurately evaluate the signal penetration loss.

[0101] Third, the multi-source interference superposition model of the present invention Function term ( ) can accurately describe the interference source The shape of the spectrum (i.e., the center frequency ,bandwidth ), which can effectively solve the problem of spectrum aliasing that may be caused by the traditional rectangular window model.

[0102] In this embodiment, it should be noted that, in this embodiment, each interference source The influence of is decomposed into three parts: the amplitude term ( , used to reflect the time-varying nature of interference power), spatial attenuation term ( , used to quantify the attenuation effect of building materials and distance) and the spectral leakage term ( , used to describe the spectrum energy distribution of the interference source, The function is the Fourier transform of a rectangular pulse). In this way, by linearly superimposing all interference source components and adding Gaussian white noise, the complex electromagnetic environment can be characterized more accurately.

[0103] For example, in an exemplary embodiment, the metal structure of the elevator shaft causes severe attenuation of the NB-IoT signal, which can be compensated by the multi-source interference superposition model. term and multipath interference components to improve the sensitivity of signal reception.

[0104] In one embodiment of the present invention, in step S3, the time-frequency joint entropy feature is extracted according to the following formula:

[0105]

[0106] In the formula, is the time-frequency joint entropy, is the number of time frames, is the number of frequency points, For the time frame, The time-frequency matrix corresponding to the frequency points is: is the weight coefficient, is the correlation function between the time domain gradient and the frequency domain gradient, is the time domain gradient operator, which calculates the difference along the time axis. is the frequency domain gradient operator, which calculates the difference along the frequency axis. is a time-frequency matrix.

[0107] In this embodiment, first, this embodiment uses the time-frequency joint entropy The fusion design (entropy term and gradient correlation term) can simultaneously characterize the energy distribution complexity and time-frequency structure mutation characteristics of the signal, thereby effectively improving the ability to distinguish between legitimate signals and attack signals. For example, in a scenario where Wi-Fi and Zigbee coexist, the time-frequency energy distribution of legitimate signals is more uniform (high entropy value), while malicious interference (for example, pulse injection attack) may cause local gradient mutation (low correlation). In this way, the false detection rate can be effectively reduced through the joint judgment of the two.

[0108] Second, for the time-frequency gradient correlation term In general, by analyzing the consistency of the time-domain and frequency-domain changes of the time-frequency matrix, it is possible to effectively distinguish the multipath distortion caused by the building structure (continuous gradient changes) from the sudden distortion of the attack signal (unrelated gradient mutations). This can effectively improve the bit error rate compensation effect in metal-dense environments (for example, elevator shafts).

[0109] Third, the weight coefficient Can be adjusted according to the signal type (for example, for narrowband signals, Set to 0.3, for broadband signals can be Set to 0.7) to balance entropy sensitivity and gradient sensitivity. For example, for NB-IoT narrowband signals, focusing on entropy detection is conducive to suppressing out-of-band noise; for Wi-Fi broadband signals, increasing the weight of the gradient term is conducive to capturing attack tampering between OFDM symbols.

[0110] In this implementation, for the extraction formula of the time-frequency joint entropy feature, it should be noted that, first, for the entropy value term ( ), which is based on the short-time Fourier transform (STFT) time-frequency matrix , quantifies the randomness of the signal energy distribution. Among them, the time-frequency energy of legitimate signals is concentrated and regular (for example, the fixed frame interval of Wi-Fi), and the entropy value is low; while the energy distribution of attack signals (for example, spectrum sniffing attacks) is dispersed, and the entropy value is significantly higher.

[0111] Second, for the gradient correlation term ( ), calculate the time domain gradient of the time-frequency matrix (Difference along the time axis) and frequency domain gradient The Pearson correlation coefficient (differential along the frequency axis) reflects the synchronous change characteristics of the signal's time-frequency structure. Among them, the time-frequency changes of legitimate signals are causal (for example, the continuous phase change of QPSK modulation) and the gradient correlation is high; while the time-frequency mutations of forged signals (for example, replay attacks) are irregular and the correlation is close to zero.

[0112] Take an exemplary implementation as an example. When an attacker forges a Zigbee command (center frequency 2.4GHz), the signal time-frequency entropy value increases abnormally (due to random filling data), and the time-frequency gradient correlation is lower than that of a legitimate device (due to frequency hopping timing errors). In this way, the system can quickly trigger an alarm and block the attack.

[0113] In one embodiment of the present invention, in step S4, the anomaly detection threshold satisfies:

[0114]

[0115] In the formula, For in time The adaptive anomaly detection threshold set below, is the mean of the Mahalanobis distance in historical data, is the standard deviation of the Mahalanobis distance in the historical data, is the average bit error rate in the sliding time window.

[0116] In this embodiment, first, by introducing a bit error rate feedback factor ( ), which enables the abnormal detection threshold to automatically increase as the quality of the wireless channel deteriorates. For example, when the average bit error rate exceeds 10% (i.e., When the anomaly detection threshold is 0.1, the magnitude of , which can effectively deal with the problem of signal feature ambiguity in high interference scenarios. Compared with the fixed threshold solution, it can effectively improve the anomaly detection recall rate.

[0117] Second, the present invention adopts the Mahalanobis distance ( ) replaces the Euclidean distance to take into account the covariance relationship between the dimensions of the feature vector. For example, in the scenario where Zigbee and Wi-Fi signals are mixed, the Mahalanobis distance can distinguish legitimate / attack signals more accurately than the Euclidean distance, and accordingly, the misjudgment rate can be smaller.

[0118] In this implementation mode, it should be noted that, first, based on Criteria for setting initial thresholds , can cover most of the normal data distribution, among which, It can be obtained through historical data training to include the statistical laws of signal characteristics under typical scenarios (for example, concurrent communication of multiple devices, reflection of building materials, etc.).

[0119] Second, through the bit error rate feedback factor ( ) can establish a mapping relationship between physical layer damage and application layer security. When increased, this factor can amplify the adjustment of the anomaly detection threshold to effectively compensate for the feature distribution dispersion effect caused by the degradation of channel quality.

[0120] In one embodiment of the present invention, the length of the sliding time window is configured to be between 30 seconds and 5 minutes, and when the average bit error rate exceeds a set threshold, the interference source location subroutine is automatically triggered.

[0121] In this implementation, the sliding time window mechanism (30 seconds to 5 minutes) can achieve differentiated processing of short-term burst interference and long-term attacks. For example, when When the threshold is exceeded, the increase in the anomaly detection threshold will present a nonlinear response characteristic, which is beneficial to avoid false triggering due to instantaneous interference. At the same time, it can also effectively ensure a rapid response to continuous attacks.

[0122] It is understandable that the length of the sliding time window can be selected according to the actual situation (building space characteristics). For example, in large space scenes (such as large atriums in smart buildings), a 5-minute sliding time window can be used to ensure statistical stability. In smaller confined spaces (such as computer rooms, local office areas or leisure areas), a 30-second sliding time window can be used to improve sensitivity.

[0123] In addition, for the data within the window, exponentially weighted moving average processing can be used to give higher weight to recent data.

[0124] In one embodiment of the present invention, in step S5, performing adversarial verification on the suspicious signal by generating an adversarial network specifically includes:

[0125] Design Generator Simulate attack signal, discriminator The optimization is based on the following formula:

[0126]

[0127] In the formula, is the discriminator function, that is, the expected value of the logarithmic probability of the real data after passing through the discriminator, is the discriminator, used to output input data is the true probability, For real data, is the generator function, i.e., the logarithmic expected value of the probability of misjudging the generated data by the discriminator, is a generator that inputs noise and outputs fake data, is the latent spatial noise, To control the gradient penalty coefficient, For input data The gradient operation of For input data.

[0128] Through this implementation, first, the ability to generate adversarial samples can be effectively enhanced. Specifically, the generator By simulating potential attack signals (for example, physical layer attack features such as waveform distortion and timing disorder), it is possible to generate covert adversarial samples in a dynamic interference environment. In this way, the similarity between the time-frequency features of the attack signal and the legitimate signal can be further reduced, resulting in a lower misjudgment rate than traditional static attack libraries.

[0129] Second, it can effectively improve the generalization performance of the discriminator. A gradient penalty term is introduced ( ), by constraining the Lipschitz continuity of the discriminant function in the real data neighborhood, the overfitting of the model to the training data can be effectively suppressed. For example, in a mixed Wi-Fi and Zigbee signal scenario, the discriminator's recognition accuracy of unknown attack patterns can be greatly improved (compared to the non-gradient penalty scheme, its accuracy has a considerable advantage).

[0130] Third, it can form a dynamic defense closed loop. Specifically, the adversarial optimization (min-max game) between the generator and the discriminator can build an adaptive defense feedback mechanism. When the characteristics of the attack signal change, the generator can quickly generate new variant samples, thereby driving the discriminator to update parameters, forming a continuous evolution chain of "attack simulation → feature learning → defense upgrade". Compared with traditional solutions, the present invention can significantly shorten the response time to new attacks.

[0131] In this embodiment, it can be understood that for the generator architecture, a deep convolutional neural network (DCNN) can be used as the main structure of the generator, and the input is a noise vector containing channel state information (CSI) and bit error rate characteristics. ,The output layer configures an Orthogonal Frequency Division Multiplexing (OFDM) modulation module to ensure that the generated ,signal complies with the physical layer constraints of wireless ,communication.

[0132] For discriminator optimization, the discriminator loss function of the present invention includes three items: real data discriminant item ( ), generate data discriminant items ( ) and the gradient penalty term ( ), where the gradient penalty term prevents the discriminator from falling into a local optimal solution by forcing the discriminant function to be smoothed, thereby enhancing the adaptability to changes in the channel environment.

[0133] In general, this implementation can solve the problem that traditional static feature libraries are difficult to cope with new attacks in complex electromagnetic environments by generating a dynamic game mechanism of adversarial networks, and provides an innovative solution for the wireless communication security of smart buildings.

[0134] In one embodiment of the present invention, the generator Potential spatial noise of the input It obeys a Gaussian distribution with a mean of 0 and a variance of 1, and the dimension of the latent space is set to 1 / 4 of the number of signal sampling points.

[0135] In this embodiment, first, by making the latent spatial noise Following a Gaussian distribution with a mean of 0 and a variance of 1, the generator can cover a wider probability space, thereby generating more diverse attack signal samples. This distribution characteristic makes the noise vector evenly dispersed in the latent space, avoiding the problem of generating a single signal pattern, which is conducive to enhancing the coverage of attack signals in adversarial training.

[0136] Second, the standardized noise distribution (mean is 0, variance is 1) can also make the input data of the generator have a consistent scale, which can reduce the fluctuation during gradient update, thus avoiding the gradient explosion or vanishing problem caused by input range differences. This is conducive to improving the convergence speed and training stability of the Generative Adversarial Network (GAN).

[0137] Third, setting the dimension of the latent space to 1 / 4 of the number of signal sampling points can not only retain enough degrees of freedom to encode the time-frequency characteristics of the attack signal, but also avoid introducing redundant parameters due to excessively high dimensions. In this way, the dimension compression of such a setting can force the generator to learn a more compact representation, thereby effectively reducing the consumption of computing resources on the basis of improving the generalization ability of the model.

[0138] In an exemplary implementation, for example, in the smart building NB-IoT meter data security verification scenario, assuming that the number of meter signal sampling points is 400 (corresponding to a 100μs time domain signal and a sampling rate of 4MHz), the potential space dimension is 100. After the generator receives a 100-dimensional Gaussian noise vector, it can map it to a 400-dimensional attack signal through a neural network. Due to the synergistic effect of noise distribution and dimensionality compression, the generator can simulate a variety of attack waveforms including high-frequency interference, pulse injection, etc. At the same time, the discriminator can learn to identify these attacks through adversarial training, and ultimately accurately block forged billing instructions in real scenarios.

[0139] The method of the present invention is further described below in combination with four typical application scenarios.

[0140] The first typical application scenario is that the NB-loT electricity meters deployed in smart buildings report electricity consumption data through wireless networks. Attackers may amplify high-frequency interference signals (such as 2.4GHz pulse injection) through the reflection of metal structures in the elevator shaft to forge tampered billing data packets.

[0141] In this application scenario, the multi-band RF front end (e.g., 80MHz instantaneous bandwidth channel) in step S1 is used to capture abnormal high-frequency components (e.g., burst signals above 2.6GHz) in the elevator shaft. At the same time, the time-frequency joint entropy feature ( ) can quantify the energy distribution anomaly of the signal in the time-frequency domain. For example, the The value is stable in the range of 4.2 to 4.6, while when high-frequency interference is injected The value suddenly increased to above 5.8.

[0142] At this time, when the abnormality detection threshold value ( ) When an abnormality is determined, the system immediately triggers the billing system isolation mechanism, temporarily stores the current meter data in the local encrypted cache, and switches to the backup communication frequency band (such as 900MHz). At the same time, after the adversarial verification in step S5, if the discriminator confirms that the attack probability is >90%, it automatically submits the data hash value to the blockchain audit node to prevent tampered data from entering the billing system.

[0143] The second typical application scenario is that the attacker forges Bluetooth access control commands through replay attacks (such as copying the MAC address of a legitimate user) and attempts to illegally break into the controlled area.

[0144] In this application scenario, the time-frequency joint entropy extracted in step S3 can capture the time domain jitter characteristics of the replayed signal. Since the fixed frequency hopping sequence exhibits periodic fluctuations (standard deviation is less than 0.15), the replay attack is caused by clock offset. The standard deviation of fluctuation is greater than 0.3.

[0145] At this time, when When a preset threshold is exceeded (e.g. ), the system triggers the face recognition secondary verification, and can require the user to perform liveness detection on site, and upload the time-frequency matrix features of the attack signal (including MAC address forgery traces) to the security log (alarm log). At the same time, the average bit error rate ( ) can further distinguish signal degradation (such as multipath interference) from malicious attacks and reduce the misjudgment rate.

[0146] In the third typical application scenario, i.e., in a fire scenario, an attacker may forge the dual-peak frequency domain characteristic signal of the Zigbee protocol (for example, injecting 119MHz and 121MHz carriers at the same time) to interfere with the emergency command transmission of the fire broadcast.

[0147] In this application scenario, the multi-source interference superposition model in step S2 can resolve the bimodal frequency domain characteristics (for example, the center frequency difference is greater than 2MHz, the amplitude difference is greater than 3dB), combined with the gradient correlation in step S3 ( ) Determine whether it is a maliciously constructed unnatural interference.

[0148] At this time, when the asymmetric double-peak feature is detected, the system can switch to the wired redundant channel (such as RS-485 bus) within a preset time (for example, 50ms) to ensure the continuous transmission of fire fighting instructions. At the same time, the contaminated wireless channel can be marked as isolated, and the clean frequency band can be reallocated to other key equipment (such as smoke exhaust fan controller) through the time division multiplexing mechanism of step S1.

[0149] The fourth typical application scenario is that the attacker forges the overload cooling command modulated by LoRa (such as tampering with the hash value of the temperature control parameter) in an attempt to cause an overload failure of the air-conditioning unit.

[0150] In this application scenario, in the generative adversarial network of step S5, when the discriminator output probability is lower than 0.5 (for example, ), it indicates that the current LoRa signal is likely to be a forged command (a legitimate command Usually greater than 0.5).

[0151] At this point, the system can immediately start the instruction hash value blockchain verification and compare the hash value of the received instruction with the pre-stored on-chain data. If the hash value does not match, the execution is rejected and the attack source MAC address is marked. At the same time, combined with the Mahalanobis distance statistic in step S4, the occasional bit error is distinguished (generally, the Mahalanobis distance is less than ) and deliberate attack (generally, the Mahalanobis distance is greater than ), to prevent normal signals from being mistakenly intercepted due to instantaneous interference.

[0152] From the above four typical application scenarios, it can be seen that the present invention can achieve scenario-customized detection (designing differentiated detection thresholds and response strategies according to the physical layer characteristics of different communication standards) and defense-isolation-traceability integration (able to seamlessly connect anomaly detection, channel isolation, redundant switching, blockchain auditing and other links to form a closed-loop security protection system) through the linkage of multi-scenario adaptation and response mechanism.

[0153] The above are only specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions within the technical scope disclosed by the present invention should be included in the protection scope of the present invention. Therefore, the protection scope of the present invention should be based on the protection scope of the claims.

Claims

1. A radio data transmission security detection method for intelligent buildings, characterized in that: The steps include: Step S1: synchronously collect mixed signals within a preset frequency band through a multi-band RF front end, and perform denoising preprocessing on the signals; Step S2: construct a multi-source interference superposition model based on the interference source type, spatial position and building material attenuation parameters to compensate for the frequency domain distortion of the received signal. The multi-source interference superposition model is expressed as: In the formula, For the frequency and time The total interference field strength function on For the The time-varying amplitude of an interference source, is the attenuation coefficient of building materials, is the spatial distance between the interference source and the detection point, , For the The center frequency of the interference source, For the The signal bandwidth of the interference source is is Gaussian white noise; Step S3: extracting a time-frequency joint entropy feature from the preprocessed signal, the feature integrating the time-frequency distribution matrix of the short-time Fourier transform and its gradient correlation; Step S4: dynamically adjusting the anomaly detection threshold based on the historical data Mahalanobis distance statistics and the real-time bit error rate to identify forged data packets and illegal instructions; Step S5: performing adversarial verification on suspicious signals by generating adversarial networks, wherein the generator simulates potential attack signals and the discriminator combines a gradient penalty mechanism to enhance generalization detection capabilities; the adversarial verification on suspicious signals by generating adversarial networks specifically includes: Design Generator Simulate attack signal, discriminator The optimization is based on the following formula: In the formula, is the discriminator function, that is, the expected value of the logarithmic probability of the real data after passing through the discriminator, is the discriminator, used to output input data is the true probability, For real data, is the generator function, i.e., the logarithmic expected value of the probability of misjudging the generated data by the discriminator, is a generator that inputs noise and outputs fake data, is the latent spatial noise, To control the gradient penalty coefficient, For input data The gradient operation of For input data.

2. The wireless data transmission security detection method for intelligent buildings according to claim 1 is characterized in that: In the step S1, the multi-band RF front end includes at least three parallel receiving channels, which are respectively configured as 20 MHz, 40 MHz and 80 MHz instantaneous bandwidth modes, and cover a preset frequency band range through a time division multiplexing mechanism.

3. The wireless data transmission security detection method for intelligent buildings according to claim 1, characterized in that: The denoising preprocessing of the signal in step S1 specifically includes: The adaptive wavelet threshold algorithm is used to pre-process the signal for denoising, where the threshold value is dynamically adjusted according to the real-time signal-to-interference-noise ratio. The threshold calculation formula is: In the formula, is the threshold value, For the The standard deviation of the layer wavelet coefficients, is the signal length, is the signal-to-dryness ratio estimated in real time.

4. The wireless data transmission security detection method for intelligent buildings according to claim 1, characterized in that: In step S3, the time-frequency joint entropy feature is extracted according to the following formula: In the formula, is the time-frequency joint entropy, is the number of time frames, is the number of frequency points, For the time frame, The time-frequency matrix corresponding to the frequency points is: is the weight coefficient, is the correlation function between the time domain gradient and the frequency domain gradient, is the time domain gradient operator, which calculates the difference along the time axis. is the frequency domain gradient operator, which calculates the difference along the frequency axis. is a time-frequency matrix.

5. The wireless data transmission security detection method for intelligent buildings according to claim 1, characterized in that: In step S4, the anomaly detection threshold satisfies: In the formula, For in time The adaptive anomaly detection threshold set below, is the mean of the Mahalanobis distance in the historical data, is the standard deviation of the Mahalanobis distance in the historical data, is the average bit error rate in the sliding time window.

6. The wireless data transmission security detection method for intelligent buildings according to claim 5, characterized in that: The length of the sliding time window is configured to be between 30 seconds and 5 minutes, and when the average bit error rate exceeds a set threshold, the interference source location subroutine is automatically triggered.

7. The wireless data transmission security detection method for intelligent buildings according to claim 1, characterized in that: The generator Potential spatial noise of the input It obeys a Gaussian distribution with a mean of 0 and a variance of 1, and the dimension of the latent space is set to 1 / 4 of the number of signal sampling points.

8. The wireless data transmission security detection method for intelligent buildings according to claim 1, characterized in that: The method is applied to the security verification of NB-IoT meter data in smart buildings. When an abnormal high-frequency component signal is detected in the elevator shaft, the billing system isolation mechanism is automatically triggered; or, The method is applied to a wireless access controller using the Bluetooth protocol in an intelligent building. When the frequency-combined entropy exceeds a preset threshold, the face recognition secondary verification is automatically triggered and an alarm log is uploaded; or, The method is applied to the Zigbee wireless node of the fire broadcast system in the intelligent building. When the asymmetric double-peak frequency domain characteristics are detected in the fire alarm command signal, the method immediately switches to the wired redundant channel and marks the contaminated wireless channel as isolated; or, The method is applied to the LoRa-modulated air conditioning group control system in the intelligent building. When the discriminator output probability is lower than 0.5, the instruction hash value blockchain verification is started to prevent forged overload cooling instruction attacks.

Citation Information

Patent Citations

  • Interference identification method and device

    CN118075801A

  • Positioning method and system based on electric power communication radio interference source

    CN118337308A