A mobile phone geolocation detection system based on mobile communication signals
By dynamically adjusting classification weights and thresholds, and utilizing a random forest classifier and protocol layer anomaly statistics, the problem of mobile phone positioning coordinate offset caused by fake base station signal pollution was solved. This enabled high-precision geographic coordinate calculation and fake base station risk assessment, thereby improving the accuracy and security of mobile phone positioning.
Patent Information
- Application Number
- CN202510533985.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-27
- Publication Date
- 2025-12-02
- Estimated Expiration
- 2045-04-27
AI Technical Summary
Existing technologies struggle to accurately model time-varying correlations in dynamic mobile scenarios, resulting in ineffective suppression of fake base station signal pollution and continuous shifts in mobile phone positioning coordinates due to dynamic parameter distortion.
By dynamically adjusting classification weights and thresholds, the spatiotemporal continuity of channel labels is optimized. A random forest classifier is used to identify fake base stations. Combined with protocol layer anomaly statistics, the distortion of multipath delay parameters by fake base station signals is corrected, thereby achieving high-precision geographic coordinate calculation.
It achieves high-precision calculation of geographic coordinates on mobile devices, improves the accuracy and security of location detection, can accurately generate geographic coordinates and provide fake base station risk values, and ensures user communication security.
Smart Images

Figure CN120075808B_ABST
Abstract
Description
Technical Field
[0001] This disclosure belongs to the field of mobile communication and mobile phone positioning technology, and specifically relates to a mobile phone geographic location detection system based on mobile communication signals. Background Technology
[0002] Spatial propagation characteristics analysis based on multipath delay or frequency domain energy features of channel impulse response waveforms is often used to estimate the geographical location of signal sources.
[0003] In dynamic mobile scenarios, the relative motion between the terminal and the base station causes Doppler frequency offset and environmental time-varying characteristics, resulting in nonlinear distortion of physical layer signal characteristics. Such distortions mask the inherent differences between fake base stations and legitimate base stations in terms of hardware or deployment, such as abnormal propagation delay and frequency domain energy shift. Traditional technologies rely on static feature weights and fixed classification thresholds, making it difficult to dynamically model the correlation between frequency offset characteristics and interference signals in time-varying channels. This leads to inaccurate quantification of environmental interference intensity, making it difficult for positioning algorithms to correct the dynamic pollution of propagation parameters by fake base stations. Consequently, the deviation in the calculation of geographical coordinates on the mobile phone continues to accumulate with interference, easily resulting in offset phenomena. Summary of the Invention
[0004] This disclosure provides a mobile phone geolocation detection system based on mobile communication signals, effectively solving the problem in existing technologies where static processing of dynamic channel interference makes it impossible to accurately model time-varying correlations, resulting in ineffective suppression of fake base station signal pollution and continuous shifts in mobile phone positioning coordinates due to dynamic parameter distortion. This disclosure optimizes the spatiotemporal continuity of channel labels by dynamically adjusting classification weights and thresholds, enabling accurate quantification of fake base station interference intensity through credibility scoring. Finally, it integrates protocol layer anomaly statistics to correct the distortion of multipath delay parameters caused by fake base station signals, achieving high-precision calculation of mobile phone geolocation coordinates.
[0005] To achieve the above objectives, the present disclosure adopts the following technical solution:
[0006] In a first aspect, this disclosure provides a mobile phone geolocation detection system based on mobile communication signals, comprising:
[0007] The system comprises the following modules: a data receiving module, which receives physical layer channel impulse response waveform data and protocol layer signaling data from the mobile device; a data processing module, which performs dynamic feature correction and filtering on the physical layer channel impulse response waveform data to generate frequency offset compensation waveforms; and analyzes the protocol layer signaling data to generate protocol layer signaling anomaly statistics; a frequency domain feature extraction module, which performs wavelet packet decomposition on the frequency offset compensation waveform to generate an effective frequency band energy matrix; a fake base station identification module, which inputs the generated effective frequency band energy matrix into a fake base station identification model, which uses a random forest classifier as its basic architecture and adjusts the Doppler frequency offset feature weights and classification thresholds according to the effective correlation time period to output channel environment classification labels; a comprehensive analysis module, which performs a sliding window weighted average on the channel environment classification labels to generate an environment credibility score; and a risk assessment and location module, which generates fake base station risk values and mobile device geographic coordinates based on the environment credibility score and protocol layer signaling anomaly statistics.
[0008] Furthermore, dynamic feature correction and filtering are performed on the physical layer channel impulse response waveform data to generate a frequency offset compensation waveform, including: calculating the dynamic parameters of the physical layer channel impulse response waveform to obtain multipath delay spread and Doppler frequency offset; dynamically truncating the main path portion of the physical layer channel impulse response waveform based on the multipath delay spread to generate a delay correction waveform; and performing phase compensation on the waveform based on the Doppler frequency offset to generate a frequency offset compensation waveform.
[0009] Furthermore, the time-varying correlation coefficient sequence of the delay correction waveform and the frequency offset compensation waveform is calculated; a correlation threshold and a time threshold are set; in the time-varying correlation coefficient sequence, time periods with absolute values of correlation coefficients greater than the correlation threshold and durations greater than the time threshold are selected to generate valid correlation time period markers; within the interval of the valid correlation time period, wavelet packet decomposition is performed on the frequency offset compensation waveform.
[0010] Furthermore, wavelet packet decomposition is performed on the frequency offset compensation waveform to generate an effective frequency band energy matrix, including: performing wavelet packet decomposition on the frequency offset compensation waveform to obtain the sub-frequency band coefficients of each layer; using a smooth soft threshold function to denoise the sub-frequency band coefficients; calculating the sub-frequency band energy by weighting according to the importance of the sub-frequency band in the mobile communication signal; and extracting a specified number of sub-frequency band energies to generate an effective frequency band energy matrix.
[0011] Furthermore, the protocol layer signaling anomaly statistics include IMSI request frequency; adjusting the Doppler frequency offset feature weights according to the effective correlation period includes: setting a frequency threshold and a first proportion value; obtaining the IMSI request frequency surge increment; when the IMSI request frequency surge increment is greater than the frequency threshold, the split gain weight of the Doppler frequency offset related sub-band is increased to the first proportion value.
[0012] Furthermore, the protocol layer signaling anomaly statistics include the number of TA value transitions; the classification threshold is adjusted according to the effective correlation period, including: setting a transition threshold and a second proportional value; when the number of TA value transitions is greater than the transition threshold, the split gain weight of the multipath delay spread related sub-band is attenuated to the second proportional value.
[0013] Furthermore, the channel environment classification label includes at least label one and label two; in the wavelet packet decomposition of the frequency offset compensation waveform, the wavelet packet decomposition level is a first specified level; a second specified level is set, which is greater than the first specified level; after outputting the channel environment classification label: if the channel environment classification label is label one, the wavelet packet decomposition level of the next cycle is increased from the first specified level to the second specified level; if the channel environment classification label is label two, the sliding window length is shortened to the specified window length.
[0014] Furthermore, the node splitting rules of the random forest classifier in the fake base station identification model include: calculating the protocol anomaly score; setting an anomaly threshold and a mean threshold; if the protocol anomaly score is greater than the anomaly threshold, then selecting the Doppler frequency offset correlation feature for node splitting; if the protocol anomaly score is less than or equal to the anomaly threshold, then selecting the multipath delay spread correlation feature for node splitting; wherein, the selected correlation feature satisfies that its historical splitting gain mean is greater than the mean threshold under the current protocol anomaly score.
[0015] Further, based on the environmental credibility score and protocol layer signaling anomaly statistics, a fake base station risk value and mobile phone geographic coordinates are generated, including: inputting the environmental credibility score and protocol layer signaling anomaly statistics into a spatiotemporal gating decision network, and outputting the fake base station risk value and geographic coordinates; performing distance compensation and secondary correction on the geographic coordinates to generate mobile phone coordinates; wherein, the spatiotemporal gating decision network includes:
[0016] Physical branch: The first fully connected layer extracts signal stability features from the environmental credibility score, and the slope of the negative interval of the activation function is set to a specified proportion of the effective association time period to generate a physical feature vector; Protocol branch: The gated recurrent unit network extracts temporal features from the number of TA transitions and the frequency of IMSI anomalies to generate a protocol feature vector; Fusion layer: The weights of the physical branch and the protocol branch are dynamically adjusted according to the proportion of the effective association time period to generate fused features; Second fully connected layer: The fused features are used to output the fake base station risk value and the geographical coordinates of the mobile phone.
[0017] Furthermore, distance compensation and secondary correction are performed on the geographic coordinates to generate mobile phone coordinates, including: calculating the initial distance between the base station and the terminal based on the geographic coordinates; calculating the compensated distance based on the Doppler frequency offset and the initial distance; setting a percentage threshold; if the percentage of the effective association period is greater than or equal to the percentage threshold, the coordinates after compensation are used as the mobile phone coordinates; if the percentage of the effective association period is less than the percentage threshold, secondary correction is performed based on the Doppler frequency offset and the compensated distance, and the secondary corrected geographic coordinates are used as the mobile phone coordinates.
[0018] Secondly, this disclosure provides a mobile phone geolocation detection device based on mobile communication signals, comprising:
[0019] The radio frequency front-end module is configured to receive physical layer radio frequency signals from the mobile phone and generate physical layer channel impulse response waveform data through down-conversion and analog-to-digital conversion.
[0020] The protocol parsing chip is connected to the radio frequency front-end module and is configured to demodulate protocol layer signaling data from physical layer channel impulse response waveform data and to statistically analyze protocol layer signaling anomaly indicators.
[0021] The FPGA chip, connected to the radio frequency front-end module, is configured to: perform dynamic feature correction and filtering on the physical layer channel impulse response waveform data to generate a frequency offset compensation waveform; and perform wavelet packet decomposition on the frequency offset compensation waveform to generate an effective frequency band energy matrix.
[0022] The main control unit, connected to the FPGA chip and the protocol parsing chip, is configured to: input the effective frequency band energy matrix into the fake base station identification model, which is based on a random forest classifier and dynamically adjusts the Doppler frequency offset feature weights and classification thresholds according to the effective correlation time period, and outputs channel environment classification labels; generate an environment credibility score by performing a sliding window weighted average on the channel environment classification labels; and generate a fake base station risk value and mobile phone geographical coordinates based on the environment credibility score and protocol layer signaling anomaly statistics.
[0023] The beneficial effects of this disclosure are:
[0024] This disclosure optimizes the spatiotemporal continuity of channel labels by dynamically adjusting classification weights and thresholds, enabling the credibility score to accurately quantify the interference intensity of fake base stations. Finally, it integrates protocol layer anomaly statistics to correct the distortion of multipath delay parameters by fake base station signals, achieving high-precision calculation of mobile phone geographic coordinates. This effectively solves the problem in existing technologies where static processing of dynamic channel interference cannot accurately model time-varying correlations, resulting in the failure to effectively suppress fake base station signal pollution and the continuous shift of mobile phone positioning coordinates due to dynamic parameter distortion. It can not only accurately generate mobile phone geographic coordinates but also provide fake base station risk values, improving the security of mobile phone use and the accuracy of location detection, effectively ensuring user communication security and the reliability of location information acquisition.
[0025] Other features and advantages of this disclosure will be set forth in the following description and will be apparent in part from the description or may be learned by practicing the disclosure. The objects and other advantages of this disclosure may be realized and obtained by means of the structures pointed out in the description and the accompanying drawings. Attached Figure Description
[0026] To more clearly illustrate the technical solutions in the embodiments of this disclosure or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this disclosure. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0027] Figure 1 A schematic diagram of a mobile phone geolocation detection system based on mobile communication signals disclosed herein is shown;
[0028] Figure 2 A schematic diagram of a mobile phone geolocation detection device based on mobile communication signals disclosed herein is shown. Detailed Implementation
[0029] To address the problems raised in the background technology, this disclosure optimizes the spatiotemporal continuity of channel labels by dynamically adjusting classification weights and thresholds, enabling the credibility score to accurately quantify the interference intensity of fake base stations. Finally, it integrates protocol layer anomaly statistics to correct the distortion of multipath delay parameters by fake base station signals, thereby achieving high-precision calculation of geographical coordinates on mobile devices.
[0030] To make the objectives, technical solutions, and advantages of the embodiments of this disclosure clearer, the technical solutions of the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this disclosure, and not all embodiments. Based on the embodiments of this disclosure, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this disclosure.
[0031] In some embodiments, such as Figure 1 As shown, this disclosure provides a mobile phone geolocation detection system based on mobile communication signals, including: a data receiving module, a data processing module, a frequency domain feature extraction module, a fake base station identification module, a comprehensive analysis module, and a risk assessment and positioning module.
[0032] The data receiving module is used to receive physical layer channel impulse response waveform data and protocol layer signaling data from the mobile phone.
[0033] The data processing module is used to perform dynamic feature correction and filtering on the physical layer channel impulse response waveform data to generate frequency offset compensation waveforms; and to parse the protocol layer signaling data to generate protocol layer signaling anomaly statistics.
[0034] The frequency domain feature extraction module is used to perform wavelet packet decomposition on the frequency offset compensation waveform to generate an effective frequency band energy matrix.
[0035] The fake base station identification module is used to input the generated effective frequency band energy matrix into the fake base station identification model. The fake base station identification model is based on a random forest classifier and adjusts the Doppler frequency offset feature weights and classification thresholds according to the effective correlation time period, and outputs channel environment classification labels.
[0036] The comprehensive analysis module is used to perform a sliding window weighted average of the channel environment classification labels to generate an environment credibility score.
[0037] The risk assessment and location module is used to generate fake base station risk values and mobile phone geographic coordinates based on environmental credibility scores and protocol layer signaling anomaly statistics.
[0038] In some embodiments, dynamic feature correction and filtering are performed on the physical layer channel impulse response waveform data to generate a frequency offset compensation waveform, including: calculating the dynamic parameters of the physical layer channel impulse response waveform to obtain multipath delay spread and Doppler frequency offset; dynamically truncating the main path portion of the physical layer channel impulse response waveform according to the multipath delay spread to generate a delay correction waveform; and performing phase compensation on the waveform according to the Doppler frequency offset to generate a frequency offset compensation waveform.
[0039] Multipath delay spread is calculated using the root mean square delay spread formula based on physical layer channel impulse response waveform data. The specific steps include: extracting the time delay and corresponding power of each path in the waveform; and calculating the multipath time delay spread using the root mean square time delay spread formula. .
[0040] For example, in an LTE signal, if the detected delays of three paths are 0.2μs, 0.8μs, and 1.5μs, respectively, with corresponding powers of 0.3, 0.5, and 0.2, the multipath delay spread can be calculated. It is 0.63 μs.
[0041] Doppler frequency offset calculated using the phase difference method The specific steps include: calculating the phase difference between adjacent signal sampling points; and estimating the Doppler frequency offset based on the phase difference sequence. .
[0042] For example, in a 5G NR system, if the sampling interval is 0.1μs, the Doppler frequency offset is calculated. The frequency is 450Hz, which corresponds to a terminal speed of approximately 80km / h.
[0043] Based on multipath delay spread Dynamically extract the principal path portion of the physical layer channel impulse response waveform. The principal path determination rule can be: principal path delay. The window range is the path delay with the highest power. , where m is a dynamic adjustment coefficient, with a value ranging from 0.2 to 0.5.
[0044] For example, if multipath delay spread =0.63μs, m=0.3, then the truncation window is the principal path delay. ±0.19μs.
[0045] Multipath Delay Spread Adaptive adjustment of the cut-off range ensures the accuracy of the main diameter selection.
[0046] Phase compensation is performed on the time delay correction waveform to eliminate the influence of Doppler frequency offset. The phase compensation method can be based on the Doppler frequency offset. Apply phase compensation to each sampling point of the time delay correction waveform. , where n is the sampling point number and T is the sampling interval.
[0047] For example, if the Doppler frequency shift for The sampling interval T is Then the phase compensation amount for each sampling point is ≈-0.028 radians.
[0048] Real-time frequency offset compensation using the phase difference method can reduce compensation delay.
[0049] In some embodiments, the time-varying correlation coefficient sequence of the delay correction waveform and the frequency offset compensation waveform is calculated; a correlation threshold and a time threshold are set; time periods with absolute values of correlation coefficients greater than the correlation threshold and durations greater than the time threshold are selected from the time-varying correlation coefficient sequence to generate valid correlation time period markers; within the interval of the valid correlation time period, wavelet packet decomposition is performed on the frequency offset compensation waveform.
[0050] The time delay correction waveform and frequency offset compensation waveform are segmented with a fixed window length and step size, for example, the window length is 10ms and the step size is 1ms.
[0051] The correlation coefficient is calculated for the two waveform data segments within each window to generate a time-varying correlation coefficient sequence.
[0052] For example, in a 5G NR signal, if the window length is 10ms and contains 1000 sampling points, the calculated correlation coefficient sequence is [-0.2, 0.85, 0.92, -0.1, 0.88].
[0053] The relevant threshold can be set to an absolute value of 0.8 to filter for periods of high relevance.
[0054] The time threshold can be set to 5ms, which can be used to avoid misjudgments caused by momentary interference.
[0055] For example, if the correlation coefficient sequence is [0.85, 0.92, 0.88], lasting for 3 windows (3ms), it does not meet the time threshold; if the sequence is [0.85, 0.92, 0.88, 0.91, 0.89], lasting for 5ms, it is marked as a valid correlation period.
[0056] Wavelet packet decomposition is performed on the frequency offset compensation waveform only within the interval corresponding to the valid correlation time period; data from non-valid time periods are temporarily stored or discarded to reduce invalid calculations.
[0057] In some embodiments, wavelet packet decomposition is performed on the frequency offset compensation waveform to generate an effective frequency band energy matrix, including: performing wavelet packet decomposition on the frequency offset compensation waveform to obtain sub-band coefficients of each layer; using a smooth soft threshold function to denoise the sub-band coefficients; calculating the sub-band energy by weighting according to the importance of the sub-band in the mobile communication signal; and extracting a specified number of sub-band energies to generate an effective frequency band energy matrix.
[0058] The wavelet basis function can be the Daubechies wavelet; the initial number of layers is the first specified number of layers, such as 4 layers.
[0059] The frequency offset compensation waveform is decomposed into a full tree to obtain the sub-band coefficients of each layer.
[0060] For example, in a 5G NR signal, the frequency offset compensation waveform is decomposed into 4-layer wavelet packets to generate 16 sub-band coefficients, with the band numbers being 1 to 16.
[0061] The sub-band coefficients are denoised using a smooth soft thresholding function, the specific formula of which is: ;in, Represents the original sub-band coefficients. Represents the denoised coefficients. Represents the threshold parameter. This represents the estimated standard deviation of noise.
[0062] Threshold parameter It can be dynamically adjusted according to the sub-band number, such as in the case of high-frequency sub-bands. Low frequency sub-band The noise standard deviation σ is estimated by the absolute deviation of the median of the sub-band coefficients.
[0063] For example, for high-frequency sub-bands, such as numbered 13~16, λ=0.3, the noise power filtering ratio is ≥80%.
[0064] By preserving effective signal details through a nonlinear threshold function, the noise suppression rate can be improved.
[0065] The weights of sub-bands are predefined according to their importance in mobile communication signals. For example, the weight value of bands 1-4 can be 0.5, the weight value of bands 5-8 can be 0.8, the weight value of bands 9-12 can be 1.0, and the weight value of bands 13-16 can be 0.3.
[0066] Calculate and weight the energy of the denoised sub-band coefficients, referring to the formula: ;in, Represents energy. represents the weight value of the k-th sub-band, and N represents the number of coefficients.
[0067] For example, the energy contribution of frequency bands 9-12 accounts for 60% of the total, while frequency bands 13-16 account for 5%.
[0068] By weighting frequencies differently based on their importance, the energy contribution of the primary carrier frequency band can be increased.
[0069] Extract a specified number of sub-bands with the highest energy from all sub-bands, for example, 8. If multiple sub-bands have the same energy, prioritize retaining the lower frequency bands.
[0070] The selected sub-band energies are sorted by band number to generate an effective band energy matrix.
[0071] For example, the energy values of frequency band numbers 7, 8, 9, 10, 11, 12, 5, and 6 form a matrix [45, 52, 68, 75, 82, 89, 38, 41].
[0072] Extracting key sub-bands through energy sorting can reduce the computational load of subsequent models.
[0073] In some embodiments, protocol layer signaling anomaly statistics include IMSI request frequency; adjusting the Doppler frequency offset feature weights according to the effective correlation period includes: setting a frequency threshold and a first proportional value; obtaining the IMSI request frequency surge increment; when the IMSI request frequency surge increment is greater than the frequency threshold, increasing the split gain weight of the Doppler frequency offset correlated subband to the first proportional value.
[0074] Within the effective correlation period, the frequency of IMSI requests is counted, and the sudden increase in IMSI requests compared to the previous period is calculated.
[0075] The frequency threshold can be determined based on the lowest frequency of typical IMSI sniffing behavior in fake base station attacks, such as setting it to 30 times. The first proportion value can be determined by cross-validation, such as setting it to 1.5.
[0076] If the sudden increase in the frequency of IMSI requests exceeds the frequency threshold, the split gain weight will be increased to 1.5 times the original value.
[0077] The weights are increased only for the Doppler frequency offset correlated sub-bands, such as bands numbered 9 to 12, while the weights of other sub-bands remain unchanged, such as the multipath delay spread correlated sub-bands.
[0078] Dynamically adjusting weights based on sudden increases in IMSI request frequency can improve sensitivity to transient attacks.
[0079] Combining the frequency threshold with the first proportion value can reduce false positives for low-speed crawling attacks.
[0080] Adjusting only the weights of the Doppler frequency offset correlation subband can effectively avoid the performance degradation caused by global weight perturbation.
[0081] In some embodiments, protocol layer signaling anomaly statistics include the number of TA value transitions; adjusting the classification threshold according to the effective correlation period includes: setting a transition threshold and a second proportional value; when the number of TA value transitions is greater than the transition threshold, the split gain weight of the multipath delay spread related sub-band is attenuated to the second proportional value.
[0082] Within the effective correlation period, count the number of TA value jumps. A jump is defined as the absolute difference between adjacent TA values exceeding a preset threshold, such as 3 time units.
[0083] For example, the TA value sequence is [10,13,15,18,22], and the adjacent difference sequence is [3,2,3,4]. If the threshold is 3, then the number of transitions is 3, and the difference is 3, 3, 4.
[0084] The jump threshold can be determined based on historical statistics, such as setting it to 5 times, and the second ratio value can be set to 0.7.
[0085] By dynamically decaying the weights based on the number of TA value jumps, the impact of multipath interference on the model can be reduced.
[0086] If the number of TA value jumps exceeds the jump threshold, weight decay is performed, which only applies to the weight decay of sub-bands related to multipath delay extension, such as bands 1 to 4; the weights of other sub-bands remain unchanged.
[0087] Combining the jump threshold with the second proportional value can reduce false positives.
[0088] Adjusting only the weights of the multipath delay spread correlated subbands can effectively avoid signal feature loss caused by global weight adjustments.
[0089] In some embodiments, the channel environment classification label includes at least label one and label two; in the wavelet packet decomposition of the frequency offset compensation waveform, the wavelet packet decomposition layer number is a first specified layer number; a second specified layer number is set, which is greater than the first specified layer number.
[0090] After outputting the channel environment classification label: if the channel environment classification label is label one, then the wavelet packet decomposition layer number in the next cycle is increased from the first specified layer number to the second specified layer number; if the channel environment classification label is label two, then the sliding window length is shortened to the specified window length.
[0091] Tag 1 indicates a stable base station signal environment, such as a normal base station; Tag 2 indicates an abnormal base station signal, such as a fake base station.
[0092] The first specified layer number is the initial wavelet packet decomposition layer number, such as 4 layers. The second specified layer number can be set to 6 layers. The specified window length can be 5ms. For example, when label two is triggered, the sliding window length is shortened from the default 10ms to 5ms.
[0093] If the fake base station identification module outputs a channel environment classification label of label one, it determines that the current environment is stable and increases the wavelet packet decomposition layer number for the next cycle from the first specified layer number to the second specified layer number.
[0094] The number of decomposition layers is increased to 6, generating 64 sub-band coefficients (up from 16), which can improve the frequency domain resolution.
[0095] If the output label is label two, it is determined that there is a risk of fake base stations, and the sliding window length is shortened to the specified window length.
[0096] With the window shortened, the update frequency of the environmental credibility score increases from 100 times per second to 200 times per second, which improves real-time performance.
[0097] In some embodiments, the node splitting rules of the random forest classifier in the fake base station identification model include: calculating the protocol anomaly score; setting an anomaly threshold and a mean threshold; if the protocol anomaly score is greater than the anomaly threshold, then selecting the Doppler frequency offset correlation feature for node splitting; if the protocol anomaly score is less than or equal to the anomaly threshold, then selecting the multipath delay spread correlation feature for node splitting; wherein, the selected correlation feature satisfies that its historical splitting gain mean is greater than the mean threshold under the current protocol anomaly score.
[0098] The protocol anomaly score S is calculated as follows: ;in, This indicates a sudden increase in the frequency of IMSI requests. This represents the number of TA value jumps. α and β represent weighting coefficients, with the default values being α=0.6 and β=0.4.
[0099] The abnormal threshold is determined based on historical data statistics. Exceeding this value is considered a high-risk protocol abnormality. For example, it can be set to 25 points. The mean threshold represents the boundary value of the historical split gain mean. For example, it can be set to 0.2.
[0100] If the protocol anomaly score is greater than the anomaly threshold, select the Doppler frequency offset correlation feature, such as frequency bands 9-12, for node splitting; if the protocol anomaly score is less than the anomaly threshold, select the multipath delay spread correlation feature, such as frequency bands 1-4, for node splitting.
[0101] By leveraging the dynamic switching characteristics of weighted scoring based on sudden increases in IMSI request frequency and TA jumps, the model's sensitivity to fake base station attacks is enhanced.
[0102] The selected feature must satisfy the condition that its historical split gain average value under the current protocol anomaly score is greater than the average value threshold. For example, if the Doppler frequency offset correlation feature has a split gain average value of 0.25 in a scenario where the historical protocol anomaly score is greater than 25, then splitting is allowed; if the average value is 0.15, then splitting is prohibited.
[0103] Calculate the information gain for candidate features and select the feature with the largest gain for splitting.
[0104] Verification using both anomaly thresholds and mean thresholds ensures the effectiveness of the splitting features.
[0105] In some embodiments, Doppler frequency offset correlation sub-bands and multipath delay spread correlation sub-bands are selected based on the historical split gain average. During the training process of each decision tree, the protocol anomaly score is calculated in real time, the split features are dynamically switched, and the optimal parameter combination is determined through grid search.
[0106] In some embodiments, a fake base station risk value and mobile phone geographic coordinates are generated based on environmental credibility score and protocol layer signaling anomaly statistics, including: inputting the environmental credibility score and protocol layer signaling anomaly statistics into a spatiotemporal gating decision network, outputting the fake base station risk value and geographic coordinates; performing distance compensation and secondary correction on the geographic coordinates to generate mobile phone coordinates.
[0107] The spatiotemporal gating decision network includes:
[0108] Physical branch: The signal stability features are extracted from the environmental credibility score through the first fully connected layer. The slope of the negative interval of the activation function is set to a specified proportion of the effective correlation period to generate a physical feature vector.
[0109] Protocol branch: Temporal features are extracted from the number of TA transitions and the frequency of IMSI anomalies through a gated recurrent unit network to generate a protocol feature vector.
[0110] Fusion Layer: Dynamically adjusts the weights of physical branches and protocol branches based on the proportion of effective association time periods to generate fusion features.
[0111] The second fully connected layer outputs the risk value of fake base stations and the geographical coordinates of the mobile phone based on the fusion characteristics.
[0112] The first fully connected layer can contain three fully connected layers with 64, 32, and 16 neurons respectively. The activation function can be LeakyReLU, with the slope of the negative interval set to 50% of the effective association time period. The output is a physical feature vector, which represents the signal stability.
[0113] The Gated Recurrent Unit (GRU) network structure can be a single-layer GRU with 32 hidden units. The input is a time series of TA transition counts and IMSI anomaly frequencies, with a window length of 10ms and a step size of 1ms. The output is a protocol feature vector that represents the protocol anomaly time series pattern.
[0114] The physical branch weight is calculated based on the proportion of effective associated time periods, and the protocol branch weight is 1 minus the physical branch weight.
[0115] The fusion formula can be: ;in, Representing the characteristics of integration, Represents the weight of the physical branch. Represents physical feature vectors. Represents the protocol branch weight. This represents the protocol feature vector.
[0116] The fused features are input to the second fully connected layer, which outputs the fake base station risk value and geographical coordinates. The fake base station risk value can be a scalar from 0 to 1.
[0117] In some embodiments, when training the spatiotemporal gating decision network, the risk value of fake base stations is measured by binary cross-entropy loss to measure the prediction difference, and the geographic coordinates are measured by mean square error to measure the coordinate deviation, which helps the model to make accurate predictions.
[0118] The Adam optimizer can be used with an initial learning rate of 0.001 and a batch size of 128. The learning rate is reduced when the validation loss stagnates. The L2 regularization coefficient is 0.001 to prevent overfitting. Forward propagation dynamically calculates branch weights based on the proportion of effective association periods of the samples. For example, when 70% of the time is spent, the physical branch weight is 0.7 and the protocol branch weight is 0.3.
[0119] In some embodiments, distance compensation and secondary correction are performed on the geographic coordinates to generate mobile phone coordinates, including: calculating the preliminary distance between the base station and the terminal based on the geographic coordinates; calculating the compensated distance based on the Doppler frequency offset and the preliminary distance; setting a proportion threshold; if the proportion of the effective association time period is greater than or equal to the proportion threshold, then the geographic coordinates after the compensation distance are used as the mobile phone coordinates; if the proportion of the effective association time period is less than the proportion threshold, then secondary correction is performed based on the Doppler frequency offset and the compensated distance, and the secondary corrected geographic coordinates are used as the mobile phone coordinates.
[0120] Obtain the coordinates of known base stations from the operator's database, calculate the Euclidean distance between the known base station coordinates and the mobile phone, and calculate the compensation amount based on the Doppler frequency offset, referring to the following formula: ;in, Represents the amount of compensation. The distance between the legitimate base station coordinates and the mobile device is represented in Euclidean form, where c represents the speed of light. Represents Doppler frequency shift, Represents the carrier frequency.
[0121] The percentage of effective associated time periods is the proportion of effective time periods to the total signal duration, which can be set to 60%.
[0122] If the effective associated time period accounts for more than or equal to 60%, the geographical coordinates after compensation will be used directly as the coordinates on the mobile device.
[0123] If the effective correlation period accounts for less than 60%, the distance after compensation is further adjusted based on the Doppler frequency offset, referring to the following formula: Then, using the base station coordinates as the center, Using the radius as the coordinate, the final mobile phone coordinates are determined by combining multi-base station triangulation.
[0124] The initial compensation is based on Doppler frequency offset, while the secondary correction combines the proportion of effectively correlated time periods, with enhanced compensation for low-quality time periods, which can reduce errors. A dynamic switching correction strategy using the proportion threshold balances accuracy and real-time performance.
[0125] In some embodiments, such as Figure 2As shown, this disclosure provides a mobile phone geolocation detection device based on mobile communication signals, comprising:
[0126] The radio frequency front-end module is configured to receive physical layer radio frequency signals from the mobile phone and generate physical layer channel impulse response waveform data through down-conversion and analog-to-digital conversion.
[0127] The protocol parsing chip is connected to the radio frequency front-end module and is configured to demodulate protocol layer signaling data from physical layer channel impulse response waveform data and to statistically analyze protocol layer signaling anomaly indicators.
[0128] The FPGA chip, connected to the radio frequency front-end module, is configured to: perform dynamic feature correction and filtering on the physical layer channel impulse response waveform data to generate a frequency offset compensation waveform; and perform wavelet packet decomposition on the frequency offset compensation waveform to generate an effective frequency band energy matrix.
[0129] The main control unit, connected to the FPGA chip and the protocol parsing chip, is configured to: input the effective frequency band energy matrix into the fake base station identification model, which is based on a random forest classifier and dynamically adjusts the Doppler frequency offset feature weights and classification thresholds according to the effective correlation time period, and outputs channel environment classification labels; generate an environment credibility score by performing a sliding window weighted average on the channel environment classification labels; and generate a fake base station risk value and mobile phone geographical coordinates based on the environment credibility score and protocol layer signaling anomaly statistics.
[0130] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes the element.
[0131] Although the present disclosure has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present disclosure.
Claims
1. A mobile phone geographic location detection system based on mobile communication signals, characterized in that, include: Data receiving module: Receives physical layer channel impulse response waveform data and protocol layer signaling data from the mobile terminal; Data processing module: performs dynamic feature correction and filtering on physical layer channel impulse response waveform data to generate frequency offset compensation waveform; parses protocol layer signaling data to generate protocol layer signaling anomaly statistics; Frequency domain feature extraction module: Performs wavelet packet decomposition on the frequency offset compensation waveform to generate an effective frequency band energy matrix; The fake base station identification module generates an effective frequency band energy matrix and inputs it into the fake base station identification model. The fake base station identification model is based on a random forest classifier and adjusts the Doppler frequency offset feature weights and classification thresholds according to the effective correlation time period, and outputs channel environment classification labels. Comprehensive analysis module: Performs sliding window weighted averaging on channel environment classification labels to generate an environment credibility score; Risk assessment and location module: Based on environmental credibility score and protocol layer signaling anomaly statistics, it generates fake base station risk value and mobile phone geographical coordinates; Based on environmental credibility scores and protocol layer signaling anomaly statistics, fake base station risk values and mobile phone geographic coordinates are generated, including: The environmental credibility score and protocol layer signaling anomaly statistics are input into the spatiotemporal gating decision network, and the fake base station risk value and geographical coordinates are output. Distance compensation and secondary correction are performed on the geographic coordinates to generate mobile coordinates; The spatiotemporal gating decision network includes: Physical branch: The signal stability features are extracted from the environmental credibility score through the first fully connected layer. The slope of the negative interval of the activation function is set to a specified proportion of the effective correlation period to generate a physical feature vector. Protocol branch: Temporal features are extracted from the number of TA transitions and the frequency of IMSI anomalies through a gated recurrent unit network to generate a protocol feature vector; The weights of physical and protocol branches are dynamically adjusted based on the proportion of effective correlation periods to generate fusion features; The fused features are input to the second fully connected layer, which outputs the fake base station risk value and geographical coordinates. Calculate the preliminary distance between the base station and the terminal based on geographical coordinates; Calculate the compensated distance based on Doppler frequency shift and preliminary distance; Set a percentage threshold; if the percentage of effective associated time periods is greater than or equal to the percentage threshold, then the coordinates after compensation distance are used as the coordinates on the mobile phone; if the percentage of effective associated time periods is less than the percentage threshold, then a second correction is performed based on Doppler frequency offset and compensation distance, and the geographical coordinates after the second correction are used as the coordinates on the mobile phone. The percentage of effective associated time periods is the proportion of the effective time periods to the total signal duration.
2. The mobile phone geographic location detection system based on mobile communication signals according to claim 1, characterized in that, Dynamic feature correction and filtering are performed on the physical layer channel impulse response waveform data to generate frequency offset compensation waveforms, including: Calculate the dynamic parameters of the physical layer channel impulse response waveform to obtain the multipath delay spread and Doppler frequency offset; Based on the multipath delay spread, the main path portion of the physical layer channel impulse response waveform is dynamically extracted to generate a delay correction waveform; Phase compensation is performed on the waveform based on the Doppler frequency offset to generate a frequency offset compensated waveform.
3. The mobile phone geographic location detection system based on mobile communication signals according to claim 2, characterized in that, Calculate the time-varying correlation coefficient sequence between the delay-corrected waveform and the frequency offset-compensated waveform; Set correlation thresholds and time thresholds; filter time periods in the time-varying correlation coefficient sequence where the absolute value of the correlation coefficient is greater than the correlation threshold and the duration is greater than the time threshold, and generate valid correlation time period markers; Within the effective correlation time interval, wavelet packet decomposition is performed on the frequency offset compensation waveform.
4. The mobile phone geographic location detection system based on mobile communication signals according to claim 1, characterized in that, Wavelet packet decomposition is performed on the frequency offset compensation waveform to generate an effective frequency band energy matrix, including: Wavelet packet decomposition is performed on the frequency offset compensation waveform to obtain the sub-band coefficients of each layer; A smooth soft threshold function is used to denoise the sub-band coefficients, and the sub-band energy is calculated by weighting the sub-bands according to their importance in the mobile communication signal. Extract a specified number of sub-band energies to generate an effective frequency band energy matrix.
5. The mobile phone geographic location detection system based on mobile communication signals according to claim 3, characterized in that, Protocol layer signaling anomaly statistics include IMSI request frequency; Adjust the weights of the Doppler frequency offset features based on the effective correlation period, including: Set the frequency threshold and the first proportion value; obtain the IMSI request frequency surge increment; When the sudden increase in the frequency of IMSI requests exceeds the frequency threshold, the split gain weight of the Doppler frequency offset correlated subband is increased to the first proportional value.
6. The mobile phone geographic location detection system based on mobile communication signals according to claim 3, characterized in that, Protocol layer signaling anomaly statistics include the number of TA value transitions; Adjusting classification thresholds based on the effective association period, including: Set the jump threshold and the second ratio value; When the number of TA value jumps exceeds the jump threshold, the split gain weight of the multipath delay spread correlated subband is attenuated to the second proportional value.
7. The mobile phone geographic location detection system based on mobile communication signals according to claim 4, characterized in that, The channel environment classification label includes at least label one and label two; in the wavelet packet decomposition of the frequency offset compensation waveform, the wavelet packet decomposition layer number is the first specified layer number; a second specified layer number is set, which is greater than the first specified layer number; After outputting the channel environment classification label: if the channel environment classification label is label one, then the wavelet packet decomposition layer number in the next cycle is increased from the first specified layer number to the second specified layer number; if the channel environment classification label is label two, then the sliding window length is shortened to the specified window length.
8. The mobile phone geographic location detection system based on mobile communication signals according to claim 1, characterized in that, The node splitting rules of the random forest classifier in the fake base station identification model include: Calculate protocol anomaly scores; set anomaly thresholds and mean thresholds; If the protocol anomaly score is greater than the anomaly threshold, the Doppler frequency offset correlation feature is selected for node splitting; if the protocol anomaly score is less than or equal to the anomaly threshold, the multipath delay spread correlation feature is selected for node splitting. Among them, the selected relevant features satisfy the condition that the mean of their historical split gain under the current protocol anomaly score is greater than the mean threshold.
Citation Information
Patent Citations
Orthogonal matching pursuit channel estimation method for underwater acoustic OFDM system
CN113055317A
Bit timing synchronization method and device for DSSS-TDMA system
CN119182417A