WiFi equipment radio frequency fingerprint extraction method based on reference equipment receiver robustness
By processing WiFi signals, the receiver's robust RF fingerprint features are extracted and the neural network is used for identification, the security risks existing in WiFi devices and the impact of receiver changes on identification are solved, and efficient security authentication and simplified system deployment are achieved.
Patent Information
- Application Number
- CN202510306608.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-14
- Publication Date
- 2025-06-06
AI Technical Summary
Existing WiFi devices have security risks during the authentication process, and the changes in the receiver have a great impact on the extraction and identification of RF fingerprints, resulting in cumbersome and difficult system deployment.
The radio frequency fingerprint extraction method of WiFi device based on the reference device receiver is adopted. By sampling, downconversion, starting point detection, frame synchronization, carrier frequency deviation estimation and compensation of the WiFi signal, the robust radio frequency fingerprint characteristics of the receiver are obtained, and neural network is used for training to achieve recognition.
It effectively reduces the impact of receiver changes on RF fingerprint extraction and identification, improves the system's security authentication performance, simplifies system deployment, and is suitable for IoT devices with limited computing resources.
Smart Images

Figure CN120111501A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security, and in particular to a method for extracting radio frequency fingerprints of WiFi devices based on a robust reference device receiver. Background Art
[0002] During the manufacturing process of RF equipment, due to process limitations, the hardware may have imperfect characteristics, such as IQ DC bias, IQ imbalance, imperfect low-pass filter, nonlinear power amplifier, etc. These hardware damages will affect the transmitted wireless signals, which will affect the performance of the communication system on the one hand, but on the other hand, due to the physical non-cloning characteristics of the hardware, device security identification based on physical layer signals can be achieved.
[0003] With the improvement of computer computing power, existing WiFi devices have security risks in the authentication process. Therefore, the physical layer radio frequency fingerprint recognition can be used to improve the security authentication performance of the system. In radio frequency fingerprint recognition, changes in the receiver will have a great adverse effect on the recognition accuracy. The existing receiver-robust radio frequency fingerprint recognition method requires multiple receivers to receive signals to train the receiver-independent radio frequency fingerprint extractor, or under the condition of a new receiver, it is necessary to receive a small number of signals from the devices to be classified to calibrate the model, but these steps make the system deployment more cumbersome and difficult. Therefore, a new solution is urgently needed to solve the above technical problems. Summary of the invention
[0004] The present invention aims at the problems existing in the prior art and provides a method for extracting radio frequency fingerprints of WiFi devices based on a robust reference device receiver, which can effectively reduce the impact of receiver changes on the extraction and identification of radio frequency fingerprints of devices.
[0005] The present invention provides a method for extracting radio frequency fingerprints of WiFi devices based on a robust reference device receiver, comprising the following steps:
[0006] Step 1: Sample the WiFi signal of the reference device, down-convert it to obtain a baseband signal, detect the starting point of the baseband signal, and obtain a rough starting point;
[0007] Step 2: Perform frame synchronization on the baseband signal to obtain a more accurate starting point;
[0008] Step 3: Estimating and compensating the carrier frequency offset of the baseband signal;
[0009] Step 4: transform the short and long preamble parts of the baseband signal after carrier frequency offset compensation into the frequency domain to obtain the frequency domain signals corresponding to the two parts;
[0010] Step 5: Repeat the above operation for the device to be classified to obtain the frequency domain signal of the device to be classified;
[0011] Step 6: Divide the frequency domain signal of the device to be classified by the frequency domain signal of the reference device to obtain the robust RF fingerprint feature of the receiver; Step 7: Use the RF fingerprint feature samples to train the neural network to obtain model parameters;
[0012] Step 8: Input the test set into the trained neural network model to obtain the classification results.
[0013] Step 1 is as follows: Detect the coarse starting point of the signal based on the threshold value method. j Samples received from reference device T M The discrete baseband signal is recorded as n=1,...,N, N is the signal length, starting from n=1, Perform detection. Let the window length be W, the threshold value be T, in the kth detection, if
[0014]
[0015] Indicates the starting point is n 0 =near (k-1)W.
[0016] Step 2 is as follows: Generate a long guide signal L(n) locally, where n=1,...,L L , where L L is the length of the long guide code. With the help of L(n), we can get The starting point of the long preamble part is
[0017]
[0018] in(·) * represents the conjugate operation, and K represents the search range. Under the condition of sampling rate of 20Msps, The exact starting point position is n 1 =k 0 -160.
[0019] Among them, step 3 is as follows: In a signal frame, the carrier frequency offset estimation is performed using the short preamble part, and the following can be obtained:
[0020]
[0021] in(·) * represents the conjugate operation, D is the short guide code symbol length, ∠· represents the complex angle, T S is the sampling frequency, n S It is the starting point for carrier frequency offset estimation, where 0≤n S ≤D, After frequency offset compensation, it can be expressed as
[0022]
[0023] Where x(n) is the reference device T M Transmitted baseband signal.
[0024] Among them, step 4 is as follows: The short and long preamble parts are transformed into the frequency domain to obtain the frequency domain signals corresponding to the two parts. and
[0025] Among them, step 5 is as follows: the device to be classified T i Repeat the above operation to obtain the device to be classified T i Frequency domain signals of short and long preamble parts and
[0026] Step 6 is as follows: Divide the frequency domain signal of the device to be classified by the frequency domain signal of the reference device to obtain the robust RF fingerprint features of the receiver of the short and long guide codes.
[0027]
[0028]
[0029] in and The reference device T M Frequency domain signals in the short and long preamble parts, and They are the equipment to be classified T i Frequency domain signals in the short and long preamble parts.
[0030] Step 7 is as follows: Design based on the InceptionTime neural network model. Smooth the sample labels to obtain
[0031] y'=(1-α)y+αN y (13)
[0032] Where α is the label smoothing coefficient, y is the label after One-Hot encoding, and N yis the number of terminals. In the present invention, α is taken as 0.1, and L2 regularization is added to prevent overfitting of the model, and the parameter is set to 0.1, and the learning rate is set to 0.001. The two neural networks are trained respectively using the RF fingerprint feature samples of the short and long guide codes to obtain model parameters, and then the RF fingerprint feature samples of the short and long guide codes in the test set are input into the two trained neural network models respectively, and the results after the output of the softmax layer of the two neural network models are added, and the class corresponding to the maximum value is taken as the prediction result.
[0033] An electronic device comprises a memory, a processor and a computer program stored in the memory and executable on the processor. When the processor executes the program, a method for extracting radio frequency fingerprints of a WiFi device based on the robustness of a reference device receiver is implemented.
[0034] A computer-readable storage medium stores computer instructions, which, when executed by a processor, implement a method for extracting a radio frequency fingerprint of a WiFi device based on a robust reference device receiver.
[0035] Compared with the prior art, the present invention has the following advantages: the technical solution can process WiFi signals according to the above method, and by dividing the preamble code of the device to be classified with the preamble code of the reference device in the frequency domain, the influence of the receiver on the extraction of radio frequency fingerprint features is reduced. When the method is used to train the neural network with only one receiver, a higher classification accuracy can be achieved on the test set obtained by another receiver, and the robustness of the receiver for radio frequency fingerprint identification of WiFi devices is effectively improved. The method has the advantages of low algorithm complexity, easy deployment, and lightweight, and is suitable for IoT devices with limited computing resources. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] Figure 1 The radio frequency fingerprint characteristics of the WiFi device Dev2 obtained by the receiver Rx3;
[0037] Figure 2 The radio frequency fingerprint feature of the WiFi device Dev2 obtained by the receiver Rx5. DETAILED DESCRIPTION
[0038] In order to deepen the understanding of the present invention, the present embodiment is described in detail below with reference to the accompanying drawings.
[0039] Embodiment 1: The present invention proposes a method for extracting radio frequency fingerprints of WiFi devices based on a robust reference device receiver. The specific technical steps are as follows.
[0040] 1. Sample the WiFi signal, then down-convert it to obtain the baseband signal, perform starting point detection, frame synchronization, and carrier frequency offset estimation and compensation on the baseband signal.
[0041] (1) Starting point detection
[0042] The receiver R j Samples received from reference device T M The discrete baseband signal is recorded as n=1,...,N, N is the signal length. Starting from n=1, Perform detection. Let the window length be W, the threshold value be T, in the kth detection, if
[0043]
[0044] Indicates the starting point is n 0 =near (k-1)W.
[0045] (2) Frame synchronization
[0046] Generate a long preamble signal L(n) locally, n=1,...,L L , where L L is the length of the long guide code. With the help of L(n), we can get The starting point of the long preamble part is
[0047]
[0048] in(·) * represents the conjugate operation, and K represents the search range. Under the condition of sampling rate of 20Msps, The exact starting point position is n 1 =k 0 -160.
[0049] (3) Carrier frequency offset estimation and compensation
[0050] In a signal frame, using The short guide code part performs carrier frequency offset estimation, and we can get
[0051]
[0052] in(·) * represents the conjugate operation, D is the short guide code symbol length, ∠· represents the complex angle, T S is the sampling frequency, n S It is the starting point for carrier frequency offset estimation, where 0≤n S ≤D. After frequency offset compensation, it can be expressed as
[0053]
[0054] Where x(n) is the reference device T M Transmitted baseband signal.
[0055] 2. Robust RF fingerprint extraction based on reference device receiver
[0056] (1) Obtain the frequency domain preamble signal of the reference device
[0057] The corresponding short guide code can be expressed as
[0058]
[0059] in, is the reference device T M and receiver R j The influence of the flat fading channel, is the receiver R j The RF fingerprint in the short guide part, is the reference device T M The RF fingerprint in the short guide part, represents the convolution operation, x LSTF is a short guide code. Transformed to the frequency domain, we can get
[0060]
[0061] in, and X LSTF Respectively and x LSTF The result after fast Fourier transform.
[0062] The corresponding long guide code can be expressed as
[0063]
[0064] in, is the receiver R j The RF fingerprint in the long preamble part, is the reference device T M The RF fingerprint in the long preamble part, represents the convolution operation, x LLTF is a long guide code. Transformed to the frequency domain, we can get
[0065]
[0066] in, and XLLTF Respectively and x LLTF The result after fast Fourier transform.
[0067] (2) Obtaining the frequency domain preamble signal of the device to be classified
[0068] Through the signal processing process similar to the above, the device to be classified T can be obtained. i The frequency domain forms of the short preamble signal and the long preamble signal are
[0069]
[0070]
[0071] in Is the equipment to be classified T i and receiver R j The influence of the flat fading channel, and The receiver R j RF fingerprint of short and long preamble parts and The result after fast Fourier transform is and They are the equipment to be classified T i RF fingerprint of short and long preamble parts and The result after fast Fourier transform.
[0072] (3) Obtaining a robust RF fingerprint of the receiver of the device to be classified
[0073] Dividing equations (22) and (23) by equations (20) and (21) respectively, we can get the device T to be classified: i The robust RF fingerprints of the receiver in the short and long preamble parts are:
[0074]
[0075]
[0076] like Figure 1 and Figure 2 The following are the RF fingerprints of the same device to be classified, extracted by two different receivers. Figure 1 and Figure 2 It can be seen that when the receiver is changed, the RF fingerprint of the same device to be classified is still similar.
[0077] 3. Neural network training and classification
[0078] The two InceptionTime neural networks are trained separately using the RF fingerprint feature samples of the short and long lead codes of the equipment to be classified. The sample smoothing parameter α is set to 0.1, and L2 regularization is added to prevent the model from overfitting. The parameters are set to 0.1, and the learning rate is set to 0.001 to obtain the model parameters. Then, the RF fingerprint feature samples of the short and long lead codes of the equipment to be tested in the test set are input into the two trained neural network models respectively, and the output results of the softmax layers of the two neural network models are added, and the class corresponding to the largest value is taken as the prediction result.
[0079] As shown in Table 1, the performance comparison of the method of the present invention on different data sets is shown under the condition of 10 WiFi devices to be classified.
[0080] Table 1 Comparison of classification accuracy on different datasets
[0081]
[0082] Compared with the method of directly dividing the short guide code and the long guide code in the frequency domain, the method of the present invention can effectively reduce the impact of the receiver change on the RF fingerprint recognition of the device to be classified, and the classification accuracy is improved under different data sets. Table 2 shows the confusion matrix obtained by using the samples obtained by the receiver Rx4 as the training set and the samples obtained by Rx3 as the test set. It can be seen from Table 2 that the classification accuracy of each device reaches 90% or above using the method of the present invention.
[0083] Table 2 shows the confusion matrix obtained by using the samples obtained by the receiver Rx4 as the training set and the samples obtained by Rx3 as the test set.
[0084] Table 2 Confusion matrix when the training set is Rx4 and the test set is Rx3.
[0085]
[0086] It should be noted that the above embodiments are not intended to limit the protection scope of the present invention, and equivalent changes or substitutions made on the basis of the above technical solutions all fall within the protection scope of the claims of the present invention.
Claims
1. A method for extracting radio frequency fingerprints of WiFi devices based on the robustness of reference device receivers, characterized in that: The method comprises the following steps: Step 1: Sample the WiFi signal of the reference device, down-convert it to obtain a baseband signal, detect the starting point of the baseband signal, and obtain a rough starting point; Step 2: Perform frame synchronization on the baseband signal to obtain a more accurate starting point; Step 3: Estimating and compensating the carrier frequency offset of the baseband signal; Step 4: transform the short and long preamble parts of the baseband signal after carrier frequency offset compensation into the frequency domain to obtain the frequency domain signals corresponding to the two parts; Step 5: Repeat the above operation for the device to be classified to obtain the frequency domain signal of the device to be classified; Step 6: Divide the frequency domain signal of the device to be classified by the frequency domain signal of the reference device to obtain a robust RF fingerprint feature of the receiver; Step 7: Use the RF fingerprint feature samples to train the neural network and obtain model parameters; Step 8: Input the test set into the trained neural network model to obtain the classification results.
2. According to claim 1, a method for extracting radio frequency fingerprints of WiFi devices based on robust reference device receivers is characterized in that: Step 1 is as follows: Set the receiver R j The samples are received from the reference device T M The discrete baseband signal is recorded as N is the signal length, starting from n=1, Perform starting point detection, record the window length as W, the threshold value as T, in the kth detection, if This indicates that the starting point is near n0=(k-1)W.
3. According to claim 1, a method for extracting radio frequency fingerprint of a WiFi device based on a robust reference device receiver is characterized in that: Step 2 is as follows: Generate a long guide signal L(n) locally, where n=1,...,L L , where L L is the length of the long preamble. With the help of L(n), the received signal is obtained. The starting point of the long preamble part is in(·) * represents the conjugate operation, K represents the search range, and under the condition of a sampling rate of 20Msps, The exact starting point position is n1=k0-160.
4. According to claim 1, a method for extracting radio frequency fingerprints of WiFi devices based on robust reference device receivers is characterized in that: Step 3 is as follows: In a signal frame, the short preamble part is used to estimate the carrier frequency offset, and the result is Where D is the short guide symbol length, ∠· represents the complex angle, T S is the sampling frequency, n S It is the starting point for carrier frequency offset estimation, where 0≤n S ≤D, After frequency offset compensation, it is expressed as Where x(n) is the reference device T M Transmitted baseband signal.
5. The method for extracting radio frequency fingerprint of a WiFi device based on a robust reference device receiver according to claim 1, characterized in that: Step 4: Transform the short and long lead codes of the signal into the frequency domain, and obtain the frequency domain signals corresponding to the two parts respectively: and 6. The method for extracting radio frequency fingerprint of a WiFi device based on a robust reference device receiver according to claim 1, characterized in that: Step 5: Equipment T to be classified i Repeat the above operation to obtain the device to be classified T i Frequency domain signals of short and long preamble parts and 7. The method for extracting radio frequency fingerprint of a WiFi device based on a robust reference device receiver according to claim 1, characterized in that: Step 6: T i The frequency domain signal of the reference device T M The frequency domain signal of is divided by the short and long preambles to obtain the robust RF fingerprint features of the receiver respectively. in, and The reference device T M In the frequency domain signal of the short and long preamble parts, and They are the equipment to be classified T i Frequency domain signals in the short and long preamble parts.
8. The method for extracting radio frequency fingerprint of a WiFi device based on a robust reference device receiver according to claim 1, characterized in that: Step 7: Use the device to be classified T i The RF fingerprint feature samples of the short guide code and the long guide code parts are used to train the two InceptionTime neural network models respectively to obtain the model parameters. Then, the RF fingerprint feature samples of the short guide code and the long guide code parts of the equipment to be classified in the test set are input into the two trained neural network models respectively, and the results output by the softmax layers in the two neural network models are added, and the class corresponding to the largest value is taken as the prediction result. Among them, on the basis of the InceptionTime neural network, it is necessary to perform label smoothing on the sample labels and add the L2 regularization term to prevent overfitting.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the method for extracting a WiFi device radio frequency fingerprint based on a robust reference device receiver as described in any one of claims 1 to 8 above is implemented.
10. A computer-readable storage medium having computer instructions stored thereon, characterized in that: When the computer instruction is executed by the processor, a robust WiFi device radio frequency fingerprint extraction method based on a reference device receiver is implemented as described in any one of claims 1-8.