Unmanned aerial vehicle real-time countering method for LoRa communication protocol
Through software-defined radio technology, LoRa signal parameters are monitored and analyzed in real time and matched interference signals are sent, which solves the problems of insufficient reaction speed, power consumption and targeting in LoRa drone countermeasures, and achieves fast and low-power precise interference.
Patent Information
- Application Number
- CN202510518463.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-24
- Publication Date
- 2025-07-04
AI Technical Summary
The existing drone counter technology has shortcomings in response speed, signal power and targeting, especially in the LoRa communication protocol, the drone counter system is difficult to achieve fast response, low power consumption and precise interference.
Software-defined radio technology is adopted to continuously monitor electromagnetic signals, analyze LoRa signal parameters, and use preamble detection based on energy thresholds and LoRa Sniffer to identify the target signal and send interference signals matching the target signal parameters to achieve real-time countermeasures for LoRa drones.
It improves reaction speed and real-time performance, reduces energy consumption, reduces the probability of interference being detected, and ensures accurate interference to LoRa drones without affecting other communication equipment.
Smart Images

Figure CN120263336A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of wireless communication interference in the fields of wireless communication security and drone security, and specifically relates to a real-time countermeasure method for drones against the LoRa communication protocol. Background Art
[0002] With the progress of drone technology, in the field of low-altitude drone racing, the use of racing drones is becoming increasingly popular. Common self-made racing drones are usually widely used in competitions and entertainment activities due to their high speed and flexible control performance. However, with the expansion of their application scenarios, the flight of racing drones may pose potential threats to public safety, privacy, and the security management of specific areas. For example, unauthorized racing drones may operate in no-fly zones and even be used for illegal reconnaissance and other malicious purposes.
[0003] As a major long-range communication means, LoRa technology is often used for the remote control and data transmission of racing drones due to its strong long-distance transmission ability and low power consumption advantages.
[0004] Therefore, it is particularly important to develop a real-time countermeasure system for drones against the LoRa communication protocol. The goal of this system is to be able to monitor drones illegally using the LoRa protocol in real time and, when necessary, take measures to interfere with the target drone to make it land safely or return, effectively preventing the illegal intrusion and potential threats of drones to sensitive areas.
[0005] The countermeasure means for drones mainly include two core processes: detection and countermeasure.
[0006] The current drone detection methods mainly include: (1) Radar systems: using radio waves to detect the position and speed of drones; (2) Optical cameras: capturing images of drones through visible light or infrared cameras for visual recognition; (3) RF detectors: detecting the radio frequency signals of drones to determine their activities and control sources, etc. The interference methods include: (1) Electromagnetic interference: disrupting the communication and navigation systems of drones by sending interference signals to make them lose control or force them to land; (2) Physical interception: physically capturing drones using net guns or other capture devices; (3) GPS interference / spoofing: misleading the positioning and navigation systems of drones by interfering with or sending false GPS signals, etc.
[0007] In the existing literature technology:
[0008] Reference [1]: "Nguyen D, Sahin C, Shishkin B, et al. A real-time and protocol-aware reactive jamming framework built on software-defined radios[C] / / Proceedings of the 2014 ACM workshop on Software radio implementation forum. 2014:15-22.": Designed a real-time reactive jamming system based on software-defined radio (SDR). The system utilizes FPGA hardware and the GNU Radio software library, enabling rapid response within 80 nanoseconds after signal detection to achieve real-time jamming. The jamming signals include White Gaussian Noise (WGN), Replay Attack, and custom waveforms as required, and experimental verification was carried out in Wi-Fi (802.11g) and WiMAX (802.16e) network environments.
[0009] Reference [2]: "Tapparel J, Afisiadis O, Mayoraz P, et al. An open-source LoRa physical layer prototype on GNU radio[C] / / 2020 IEEE 21st International Workshop on Signal Processing Advances in Wireless Communications (SPAWC). IEEE, 2020:1-5.": Designed an open-source LoRa physical layer prototype based on GNU Radio. The research team revealed many details of the LoRa physical layer through reverse engineering and implemented a complete LoRa transceiver based on this.
[0010] Literature [3]: "Mikhaylov K, Fujdiak R, Pouttu A, et al. Energy attack in LoRaWAN: Experimental validation[C] / / Proceedings of the 14th International Conference on Availability, Reliability and Security. 2019:1-6.": It discusses the energy attack in the LoRaWAN network. The researchers studied the feasibility of the energy attack under real conditions and its impact on LoRa communication. The experimental results show that an attacker can significantly increase the energy consumption of LoRaWAN devices through specific methods, specifically, the energy consumption increased by 36% to 576% in a single communication event.
[0011] Literature [4]: "Aras E, Ramachandran G S, Lawrence P, et al. Exploring the security vulnerabilities of LoRa[C] / / 2017 3rd IEEE international conference on cybernetics (CYBCONF). IEEE, 2017:1-6.": It discusses the security vulnerabilities of LoRa communication technology. The research shows that although the spread spectrum technology of LoRa can provide certain anti-interference capabilities, in actual applications, LoRa signals are still vulnerable to interference. The research points out that there are multiple security weaknesses in the LoRa physical layer and network layer. First, there are vulnerabilities in the long-distance communication of the LoRa network. LoRa devices perform long-term signal transmission, which increases the possibility of signal interception or destruction. Second, the impact of interference attacks on LoRa communication. The LoRa network can be successfully interfered with through commercial LoRa devices, especially when using the same frequency and spreading factor. Finally, there is a lack of security protection. Although the LoRaWAN protocol provides encryption protection based on symmetric keys, there are still various potential attack methods that can affect the LoRa network, including replay attacks and network wormhole attacks.
[0012] Literature [5]: "Ingham M, Marchang J, Bhowmik D. IoT security vulnerabilities and predictive signal jamming attack analysis in LoRaWAN[J]. IET information security, 2020, 14(4): 368-379.": It analyzed in detail the IoT security vulnerabilities and predictive signal jamming attacks in LoRaWAN. The research highlighted the predictive patterns of LoRaWAN devices when sending data, which may lead to the vulnerability of the communication process to jamming attacks.
[0013] Literature [6]: "Hou N, Xia X, Zheng Y. Jamming of LoRa PHY and countermeasure[J]. ACM Transactions on Sensor Networks, 2023, 19(4): 1-27.": It explored in detail the vulnerability of the LoRa physical layer in the face of synchronous jamming signals. The authors pointed out through experimental research that in practical applications of LoRa systems, when encountering high-power synchronous jamming signals, existing conflict recovery methods and decoding strategies often fail. In addition, the authors also proposed that sending continuous standard basic upchirp signals or continuous basic downchirp signals with the same center frequency, center frequency point, bandwidth, and spreading factor as the target signal can interfere with LoRa signals, and the theoretical power of the interfering signal can be equal to the strength of the remote control signal. Compared with the interference method of random noise, the signal strength of the latter needs to reach more than 100 times that of the remote control signal.
[0014] Literature [7]: "Kang J M. LoRa preamble detection with optimized thresholds[J]. IEEE Internet of Things Journal, 2022, 10(7): 6525-6526.": It studied the preamble detection technology in LoRa communication systems and made improvements to the existing threshold-based preamble detection methods. The article proposed an optimized threshold method to maximize the preamble detection probability while satisfying the false alarm rate constraint conditions. It provided a more effective technical means for the preamble detection of LoRa systems.
[0015] Reference [8]: "Ruotsalainen H, Shen G, Zhang J, et al. LoRaWAN physical layer-based attacks and countermeasures, a review[J]. Sensors, 2022, 22(9): 3127.": This paper reviews the attack methods and defense measures against the LoRaWAN physical layer, mainly covering several interference methods such as reactive radio frequency interference, trigger-based and reactive interference attacks, and wormhole attacks. Through the analysis of these interference methods, it emphasizes the security threats that LoRaWAN may face at the physical level, and also discusses how to enhance key update and device authentication through physical layer technologies to improve the security and robustness of LoRaWAN nodes.
[0016] Reference [9]: "Li Xuzhu. Research on USRP interference experiment and listening mechanism throughput in LoRa network[D]. Xiamen University, 2021.": This paper studies the interference experiment using USRP and explores the impact of the listening mechanism on the system throughput in the LoRa network at the network layer. The article analyzes the random transmission interference caused by the ALOHA protocol and the interference caused by the fixity of the physical layer.
[0017] Reference
[10] : "Hua Min, Wei Jianan, Zhao Wei, et al. Analysis and performance research of LoRa signal interference[J / OL]. Journal of Computer Applications, 1 - 9[2024 - 08 - 08].": This paper analyzes the performance of LoRa signals under different interference conditions, especially explores the impact on the demodulation performance of the transmitted signal when the spreading factor (SF) of the interference signal is the same as or different from that of the transmitted signal. The article points out that when the interference signal and the transmitted signal have the same SF, the impact of the interference on the transmitted signal is relatively large. The experimental results show that in this case, a very high signal-to-interference ratio (SIR) is required to ensure that the transmitted signal can be correctly demodulated. When the SF of the interference signal is different from that of the transmitted signal, the impact of the interference is relatively small.
[0018] Document
[11] : "Boquet G, Tuset-Peiró P, Adelantado F, et al. LR-FHSS: Overview and performance analysis[J]. IEEE Communications Magazine, 2021, 59(3): 30-36." It introduced the LoRa frequency hopping mechanism (LR-FHSS) technology, focusing on the operation mode, performance and its limitations of LR-FHSS, including how to handle the saturated frequency hopping strategy. In addition, it also explored the strategies of LR-FHSS in frequency selection, hopping sequence optimization and coexistence with traditional LoRa systems.
[0019] Document
[12] : "Tang X, Zhang Y, Wang Y, et al. Performance analysis of preamble detection of lora system[C] / / 2019 International Conference on Electronic Engineering and Informatics(EEI). IEEE, 2019: 175-180." It analyzed in detail the performance of preamble detection in the LoRa system, focusing on the detection probability, missed detection probability and false detection probability under different signal-to-noise ratios and detection thresholds. In the article, the discrete Fourier transform (DFT) and non-coherent accumulation algorithm were used to detect preamble symbols. In addition, the article also explored the influence of different configuration parameters on the detection performance.
[0020] Literature
[13] : "Aras E, Small N, Ramachandran G S, et al. Selective jamming of LoRaWAN using commodity hardware [C] / / Proceedings of the 14th EAI International Conference on Mobile and Ubiquitous Systems: Computing, Networking and Services. 2017: 363-372.": It deeply explores the method of realizing selective jamming of LoRaWAN using commodity hardware. It focuses on analyzing the possible security vulnerabilities in LoRaWAN communication, especially the defects introduced by the LoRa modulation method, such as the long signal transmission time and the sensitivity to interference. Three interference-based attack methods are proposed and evaluated in the article: (1) Triggered Jamming: Start jamming immediately when detecting LoRa transmission activities to block information transmission; (2) Selective Jamming: During the transmission of data packets, decide whether to perform jamming according to the specific content of the data packet, such as device address or message type; (3) Wormhole attack combined with selective jamming: Use two devices to perform jamming and data replay. One device is responsible for jamming, and the other device replays the previously recorded data packet at an appropriate time to mislead the receiving device. The article verifies the effectiveness of these attacks through an actual LoRaWAN test environment and discusses their application scenarios and potential limitations in the real world.
[0021] Reference
[14] : "Gvozdenovic S, Becker J K, Mikulskis J, et al. Truncate after preamble: PHY-based starvation attacks on IoT networks[C] / / Proceedings of the 13th ACM Conference on Security and Privacy in Wireless and Mobile Networks. 2020:89-98.": Introduced and evaluated a specific type of denial-of-service (DoS) attack called Truncate-after-Preamble (TaP). In this attack, the attacker sends a signal with a standard preamble and packet length field to indicate that a large payload will be transmitted, but then omits the transmission of the payload. This causes the receiver to wait for data that never arrives, effectively blocking the channel on a false premise. The article demonstrated the effectiveness of this strategy against various Zigbee and Wi-Fi devices, where Zigbee devices showed widespread vulnerability while Wi-Fi devices exhibited different susceptibilities. The article emphasized the efficiency of the TaP attack, which uses far less energy compared to continuous jamming strategies, making it difficult to detect while still severely affecting network communication.
[0022] Reference
[15] : "Zhang Cong, Han Ziqiang, Yue Mingkai, et al. Research on infrared detection method for anti-‘low, slow, and small’ drones[J]. Journal of Ordnance Equipment Engineering, 2023, 44(07):203-208.": Studied the infrared detection method for "low, slow, and small" drones. The article proposed a new single-frame infrared detection method based on density-distance space, using the relatively high gray value of drones in infrared images for detection. By establishing a density-distance space and converting irregular target areas into regular geometric shapes, the algorithm can achieve efficient infrared target detection in complex backgrounds.
[0023] Reference
[16] : "Qiu Baohua. Review of anti-drone technologies: The integration of communication technologies and artificial intelligence[J]. Zhongxing Telecommunication Technology, 2024, 30(02):89-99.": Discussed in detail the current development of anti-drone technologies, especially in the application of communication technologies and artificial intelligence. The article reviewed the active jamming technologies and passive detection technologies of anti-drone systems from multiple perspectives, covering methods such as electromagnetic interference, laser systems, radio frequency interference, radar, optics, and thermal imaging. In addition, it also delved into the role of communication technologies such as dynamic frequency switching, broadband technology, and multiple-input multiple-output (MIMO) technology in enhancing anti-drone effectiveness.
[0024] The control, positioning, etc. of drones need to be realized based on wireless communication. The traditional method of interfering with drones for wireless communication refers to an attack method that covers or disrupts legal communication in the wireless frequency band by sending high-power signals, making the original signals unable to be correctly received by the receiver.
[0025] There are certain deficiencies in existing common drone countermeasure technologies:
[0026] (1) Response speed and real-time performance: Most interference solutions in the existing technologies cannot achieve extremely fast signal detection and response times. For application scenarios such as the fast response and dynamic communication environment of drones, it is required that wireless communication monitoring and interference devices respond within a short time, and traditional radio interference methods may not meet the requirements.
[0027] (2) Signal power: The implementation of traditional wireless communication interference methods, such as the continuous interference method in interference attacks, often requires a large amount of energy consumption due to the large power of the interference signals sent, and the detection efficiency is also relatively high.
[0028] (3) Wide interference: Traditional wireless communication usually adopts a broadcast interference method, that is, interference signals are widely sent within a specific frequency band. The disadvantage of this method is the lack of pertinence. While interfering with the target communication, it will also affect all other communication devices within the same frequency band, including the wireless communication devices of one's own side.
[0029] Therefore, the present invention proposes a real-time countermeasure method for drones against the LoRa communication protocol. Summary of the Invention
[0030] The purpose of the present invention is to provide a real-time countermeasure method for drones against the LoRa communication protocol. Based on software-defined radio (SDR), a real-time countermeasure system for drones against the LoRa communication protocol is designed, providing an effective countermeasure solution for drones against the LoRa communication protocol. The solution includes two parts: detection and interference, and is used to protect critical infrastructure, important activities, and sensitive areas from potential threats that drones using the LoRa communication protocol may bring.
[0031] The technical solutions adopted by the present invention are specifically as follows:
[0032] A real-time countermeasure method for drones against the LoRa communication protocol, comprising the following steps:
[0033] Step 1: Continuously monitor electromagnetic signals and detect the target LoRa signals therein;
[0034] Step 2: Analyze signal parameters: Analyze the captured remote control signal to obtain the center frequency (Freq), bandwidth (BW), preamble length (Preamble Length), and spreading factor (SF) required to send the interference signal;
[0035] Step 3: Send an interference signal; send an interference signal based on the signal parameters analyzed in step 2 to interfere with the communication between the remote controller and the drone.
[0036] Preferably, in step 1, a preamble detection method based on energy threshold is used to monitor electromagnetic signals; the basic method of threshold-based preamble detection is that if a certain number of basic signal units are detected within several consecutive symbol periods, it is proved that there is a preamble; each basic unit in the preamble of the FTV signal can be detected based on the dechirp process;
[0037] In the Channel Activity Detection (CAD) working mode of the LoRa chip, the LoRa device will scan the channel to detect the presence of the preamble code; if the preamble code is detected, it means that the channel is occupied, and the LoRa device will stop sending data and wait for the channel to be idle; finally, the detection of the LoRa signal is achieved through the above mechanism.
[0038] Preferably, in step 2, the target signal spectrum is first recorded and analyzed in GNU Radio. The spectrum analysis method is first introduced. In the software radio platform, the period T of the unit symbol of the LoRa signal is analyzed. s , Maximum frequency and minimum frequency On this basis, we can get the bandwidth BW and the center frequency f RF , after calculation, we get the spreading factor SF
[0039] Then use the LoRa Sniffer detection method. The implementation of LoRa Sniffer is related to the CAD mode in the LoRa chip. CAD mode is a working mode of the LoRa chip, which is used to detect whether there is an ongoing LoRa transmission on the channel. In CAD mode, the LoRa device will listen for activities on a specific channel. If activity is detected, the device will delay sending data until the channel is idle.
[0040] Based on the CAD mode, the LoRa Sniffer can actually capture and analyze the data passing through the channel; through the CAD mode of the LoRa chip, it first detects the channel occupied by the target signal by scanning the frequency band, and then cyclically scans different spreading factors SF and bandwidths BW of LoRa communication. When the spreading factor SF, bandwidth BW, and center frequency f of the LoRa Sniffer are the same as those of the target signal, the LoRa Sniffer will return the various parameters of the target signal, preparing for the transmission of the interference signal in step 2. RF When they are the same, the LoRa Sniffer will return the various parameters of the target signal, preparing for the transmission of the interference signal in step 2.
[0041] Preferably, in step 3, the transmission of the interference signal is implemented on the software radio platform GNU Radio;
[0042] The interference of the target signal on a single frequency band is simulated for the communication between two SX1276 chips. The center frequency of the target signal is 915 MHz, the bandwidth is set to 125 kHz, the spreading factor is 7, and the preamble length is 8. The interference signal is a continuous upchirp signal with the same center frequency, bandwidth, and spreading factor parameters as the target signal, and the signal intensity is adjusted by adjusting the constant value of the Constant Source.
[0043] The technical effects achieved by the present invention are as follows:
[0044] In the present invention, reaction speed and real-time performance: By using software-defined radio technology, the present invention realizes a fast time response from signal detection to interference emission, greatly improving the adaptability and effect of the system to the rapidly changing wireless communication environment.
[0045] In the present invention, signal power and energy efficiency: The interference strategy adopted by the present invention is a reactive interference strategy. Compared with the traditional continuous interference method, interference is only initiated at specific moments, which not only significantly reduces energy consumption but also reduces the probability of being detected by the other party. This method is not only highly efficient but also more concealed in actual operation.
[0046] In the present invention, interference targeting: Different from the traditional broadcast interference method that causes large-scale communication interruption due to lack of targeting, the interference method adopted by the present invention can accurately target the interference range to a specific protocol, and can accurately interfere with specific drone signals without affecting other communication devices using other communication protocols in the same frequency band.
[0047] The present invention is designed based on SDR, and the system can achieve a rapid response from detection to interference. By detecting the signal preamble to analyze the signal characteristics, the present invention can accurately identify LoRa drone signals. On this basis, it can perform directional interference on specific targets to avoid affecting its own equipment and other communication signals. Through the parameter analysis of the target signal, the present invention can flexibly adjust the working frequency band according to the target communication protocol. The reactive interference strategy adopted by the present invention only starts interference when a threat is detected. While reducing energy consumption, more importantly, it reduces the probability of the interference signal being detected and can achieve more concealed interference.
[0048] The present invention can quickly identify LoRa drone signals and respond within a very short time. The interference signal power of the present invention is low, and the lower interference signal power reduces the probability of the interference signal being detected.
[0049] The present invention has good adaptability to LoRa drones communicating on multiple frequency bands and can perform interference on multiple frequency bands. The present invention can respond to LoRa drones and avoid interfering with the wireless communications of other protocols of its own side. Description of the Drawings
[0050] Figure 1 is a flowchart of a method for real-time countermeasure of drones against LoRa communication protocol according to the present invention;
[0051] Figure 2 is a schematic diagram of the spectrum of the basic upchirp signal in the present invention;
[0052] Figure 3 is a schematic diagram of the spectrum of a non-standard upchirp signal in the present invention;
[0053] Figure 4 is a schematic diagram of the actual LoRa signal spectrum and spectrum analysis in the present invention;
[0054] Figure 5 is a spectrum diagram of LoRa communication between SX1276 chips in the present invention;
[0055] Figure 6 is a GNU Radio block diagram for transmitting continuous upchirp signals in the present invention;
[0056] Figure 7 is a spectrum diagram of continuous upchirp signals on a single frequency band in the present invention;
[0057] Figure 8 is a GNU Radio block diagram for transmitting random Gaussian noise signals in the present invention;
[0058] Figure 9is the physical layer frame structure of the LoRa signal in the present invention;
[0059] Figure 10 is the preamble frame structure of the LoRa signal in the present invention;
[0060] Figure 11 is the schematic diagram of the preamble spectrum in the present invention;
[0061] Figure 12 is the schematic diagram of different interfering chirps and the same interfering chirps and their demodulation results in the present invention;
[0062] Figure 13 is the spectrum diagram of the LoRa drone remote control signal in the present invention;
[0063] Figure 14 is the spectrum diagram of the frequency hopping communication process between SX1276 chips in the present invention;
[0064] Figure 15 is the GNU Radio block diagram for simultaneously transmitting interference signals on multiple frequency bands in the present invention;
[0065] Figure 16 is the spectrum diagram of the multi - band interference signal in the present invention. Specific embodiments
[0066] In order to make the objectives and advantages of the present invention clearer, the present invention will be specifically described below in conjunction with embodiments. It should be understood that the following text only describes one or several specific implementation manners of the present invention, and does not strictly limit the scope of protection specifically claimed by the present invention.
[0067] As Figures 1 - 16 shown, a real - time counter - measure method for drones against the LoRa communication protocol includes the following steps:
[0068] Step 1: Continuously monitor electromagnetic signals and detect the target LoRa signals therein.
[0069] LoRa uses the modulation method of linear spread spectrum (Chirp Spread Spectrum, CSS). The basic unit of the physical layer of the LoRa signal is the basic upchirp signal. A standard basic signal unit on the baseband is shown in the following spectrum diagram. The linear frequency increases linearly with time within a period T s inside.
[0070] As Figure 2 shown, the center frequency of the LoRa signal is f RF , and the center frequency f RF on the baseband is 0. The maximum frequency of the signal within a basic unit period is The minimum frequency is The spreading factor SF in the LoRa signal represents the number of information bits contained in each symbol, that is, each symbol is spread to 2 SF The transmission is performed on chips, where the symbol period is T s The relationship between the signal bandwidth BW and the spreading factor SF is:
[0071]
[0072] Non-standard upchirp symbols such as Figure 3 As shown, the frequency of the non-standard upchirp sweeps across the entire bandwidth in one cycle, increases linearly from a certain initial frequency point, jumps to the lowest frequency after reaching the maximum frequency, and then increases linearly to the initial frequency, ending one symbol cycle.
[0073] Different initial frequency values f init Represents different coding values. According to the signal transmission bandwidth and spreading factor, the initial frequency value corresponding to different symbol coding values S is:
[0074]
[0075] The demodulation process of the LoRa signal requires multiplying the unit symbol in each period Ts of the signal with the basic downchirp signal. This process can obtain the initial frequency value of each unit symbol. Based on this process, a preamble detection method based on energy threshold can be adopted. The basic method of threshold-based preamble detection is that if a certain number of basic signal units are detected within several consecutive symbol periods, it proves that there is a preamble. For each basic unit in the preamble of the Flying Machine signal, detection can be performed based on the dechirp process.
[0076] In the Channel Activity Detection (CAD) working mode of the LoRa chip, the LoRa device will scan the channel to detect the presence of the preamble. If the preamble is detected, it means that the channel is occupied, and the LoRa device will stop sending data and wait for the channel to be idle. This mechanism can be used to detect LoRa signals.
[0077] Step 2: Analyze signal parameters. Analyze the captured remote control signal to obtain the parameters required for sending interference signals, such as center frequency (Freq), bandwidth (BW), preamble length (Preamble Length), and spreading factor (SF).
[0078] The second stage of parameter analysis of the target LoRa signal can be achieved through spectrum analysis or LoRa Sniffer.
[0079] Software Defined Radio (SDR) is a wireless communication technology that can implement various communication modules on a general hardware platform and complete most radio functions through software. Before SDR, most functions of radio systems, such as modulation and demodulation, frequency selection, etc., needed to be completed through fixed hardware. Compared with traditional hardware methods, SDR devices can change their frequencies, modulation methods, and other radio parameters through software updates, thus achieving extensive flexibility and versatility. SDR devices usually consist of a radio frequency front end and a digital backend. The radio frequency front end is responsible for receiving and transmitting radio signals, while the digital backend processes these signals in software.
[0080] GNU Radio is an open-source software development kit that is widely used to create software-defined radio systems. GNU Radio provides a rich set of signal processing modules for building various wireless communication systems, and its features include: modular design, graphical interface, flexibility, and scalability, etc.
[0081] The present invention realizes the recording and analysis of the spectrum of the target signal in GNU Radio.
[0082] First, the method of spectrum analysis is introduced. The actual spectrum diagram of LoRa communication signals is as Figure 4 shown. In the software radio platform, the period T of a single symbol of the LoRa signal can be analyzed, s the maximum frequency and the minimum frequency Based on this, the bandwidth BW and the center frequency f RF can be obtained. According to formula (1), the spreading factor SF can be obtained.
[0083] Next, the detection method of LoRa Sniffer is introduced.
[0084] LoRa Sniffer is a tool for capturing and analyzing wireless communications in LoRa networks. This device can listen to LoRa transmissions on specific frequency bands and help developers or network administrators monitor and diagnose the performance and security issues of LoRa networks. LoRa Sniffer usually includes one or more receiving modules that can receive and demodulate signals within the LoRa frequency band. These devices are usually equipped with software tools that can display the captured data packets and detailed communication parameters, including frequency, spreading factor, and signal strength, etc.
[0085] The implementation of the LoRa Sniffer is closely related to the CAD mode in the LoRa chip. The CAD mode is a working mode of the LoRa chip used to detect whether there is an ongoing LoRa transmission on the channel. In the CAD mode, the LoRa device listens for activities on a specific channel. If an activity is detected, the device will delay sending data until the channel is idle. This mode can effectively reduce packet collisions and retransmissions in the network, thereby improving the network efficiency.
[0086] Based on the CAD mode, the LoRa Sniffer can actually capture and parse the data passing through the channel. Through the CAD mode of the LoRa chip, it can first detect the channel occupied by the target signal by scanning the frequency band, and then cyclically scan different spreading factors SF and bandwidths BW of LoRa communication. When the spreading factor SF, bandwidth BW, and center frequency f of the LoRa Sniffer are the same as those of the target signal RF the LoRa Sniffer will return the various parameters of the target signal to prepare for the transmission of the interference signal in the third stage.
[0087] Step 3: Transmit the interference signal. Transmit the interference signal according to the signal parameters obtained from the analysis in Step 2 to interfere with the communication between the remote control and the drone.
[0088] The transmission of the interference signal is implemented on the software-defined radio platform GNU Radio.
[0089] The interference of the target signal on a single frequency band is simulated for the communication between two SX1276 chips. The center frequency of the target signal is 915 MHz, the bandwidth is set to 125 kHz, the spreading factor is 7, and the preamble length is 8. The spectrogram of the target signal is as Figure 5 shown:
[0090] The interference signal is a continuous upchirp signal with the same parameters as the center frequency, bandwidth, spreading factor, etc. of the target signal. The block diagram in GNU Radio is as Figure 6 shown, and the signal strength is adjusted by adjusting the constant value of the Constant Source:
[0091] The spectrogram of the signal on a single frequency band is as Figure 7 shown:
[0092] In the actual test, random Gaussian noise is used as a comparison to evaluate the interference effect and signal strength, etc. The GNU Radio block diagram for transmitting random Gaussian noise is as Figure 8 shown, and the signal strength of the random Gaussian noise is adjusted by adjusting the constant value of the Constant Source:
[0093] Actual test data shows that to achieve the same interference effect, the signal strength of the random Gaussian noise signal needs to be more than 30 dBm greater than that of the continuous upchirp signal.
[0094] There are two perspectives to explain the interference of the continuous upchirp signal on LoRa communication.
[0095] The first perspective is the interference of the interfering signal on the recognition of the preamble of the target LoRa signal.
[0096] The physical layer frame structure of the LoRa signal is as Figure 9 shown. The LoRa signal consists of four parts: preamble, optional header, payload, and cyclic redundancy check (CRC). Among them, the preamble is an important part of the LoRa communication protocol. It is located at the beginning of the LoRa data packet and is mainly used for synchronization and signal detection.
[0097] The preamble of the LoRa signal data packet mainly consists of three parts: variable preamble, sync word, and start frame delimiter (SFD), as Figure 10 shown.
[0098] The variable preamble part consists of upchirp symbols with a length of 4 to 65535, mainly providing functions such as signal detection, receiver gain setting, frequency and sampling time synchronization, as Figure 11 shown.
[0099] The continuous upchirp signal is the same as the variable preamble part of the target LoRa signal. When sending a continuous upchirp signal, the receiving party will keep waiting for the reception of the sync word, thus unable to receive the complete preamble and the subsequent content of the optional header, payload, and cyclic redundancy check (CRC), resulting in abnormal communication between the meter devices.
[0100] The second perspective is the disruption of the demodulation process of the target signal.
[0101] Suppose there are multiple LoRa communication devices in the same frequency band communicating through LoRa signals at the same time. Due to the existence of the synchronization mechanism, multiple LoRa signals will not interfere with each other. Therefore, if you want to interfere with the communication between LoRa devices through a complete LoRa signal without synchronization, the demodulation window of the interfering chirp symbols is likely to be inconsistent with the demodulation window of the legal data packet chirp symbols, which will directly cause the target interfering device to ignore the interfering signal.
[0102] Consider a demodulation window that is aligned with a legitimate chirp but not with an interfering chirp. As shown in Figure 12 (a), since the demodulation window spans two adjacent interfering chirps, the interfering signal will have a sudden frequency change at the chirp boundary because the demodulation window spans two adjacent interfering chirps. Therefore, after demodulation, two FFT spikes will appear in the frequency domain, as shown in Figure 12 (b). However, if the starting frequencies f of two adjacent interfering chirps init are the same, their frequencies will not have a sudden change at the interfering chirp boundary, as shown in Figure 12 (c). Therefore, both the interfering chirp and the legitimate chirp exhibit frequency continuity within the demodulation window, which means that the power of the continuous interfering chirp will be concentrated in the demodulation window, and a complete peak will appear in the frequency domain after demodulation, as shown in Figure 12 (d). Therefore, it is possible to interfere with the communication between target devices without synchronizing with the legitimate chirp by transmitting the same continuous upchirp signal, resulting in false alarms when the target device receives legitimate messages.
[0103] In practical applications, in order to improve the anti-interference ability to a certain extent, the frequency bands occupied by LoRa communication are not unique but occupy multiple frequency bands. LoRa FHSS (Frequency Hopping Spread Spectrum) is a communication technology that extends the capabilities of traditional LoRa technology, especially for improving network capacity and enhancing anti-interference. LoRaFHSS incorporates the characteristics of frequency hopping (FHSS) and transmits data by rapidly hopping between different frequencies, thereby reducing interference and improving transmission security.
[0104] The spectrum diagram of the actually captured LoRa drone remote control signal is as shown in Figure 13 :
[0105] The SX1276 chip supports a communication frequency band range of 137 - 1020 MHz. Modify the communication frequency band settings between SX1276 chips to perform pseudo-random frequency hopping on 6 frequency bands with a bandwidth of 200 kHz and center frequencies of 915 MHz, 915.2 MHz, 915.4 MHz, 915.6 MHz, 915.8 MHz, and 916.0 MHz respectively, so as to simulate the frequency hopping process of the remote control signal. The spectrum diagram of the frequency hopping communication process between SX1276 chips is as shown in Figure 14 :
[0106] Transmit interference simultaneously on multiple frequency bands. The block diagram of transmitting interference signals simultaneously on multiple frequency bands through GNU Radio is shown in the figure; the spectrogram of the interference signal is as Figure 16 shown.
[0107] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention. The structures, devices, and operation methods not specifically described and explained in the present invention are implemented according to the conventional means in the art without special instructions and limitations.
Claims
1. A real-time countermeasure method for drones against the LoRa communication protocol, characterized in that: The following steps are involved: Step 1: Continuously monitor electromagnetic signals and find the target LoRa signal; Step 2: Analyze signal parameters: Analyze the captured remote control signal to obtain the center frequency (Freq), bandwidth (BW), preamble length (Preamble Length), and spreading factor (SF) required to send the interference signal; Step 3: Send an interference signal; send an interference signal based on the signal parameters analyzed in step 2 to interfere with the communication between the remote controller and the drone.
2. The real-time countermeasure method for drones against the LoRa communication protocol according to claim 1, characterized in that: In step 1, an energy threshold-based preamble detection method is used to monitor electromagnetic signals. The basic method of threshold-based preamble detection is that if a certain number of basic signal units are detected within several consecutive symbol periods, it proves that a preamble exists. Each basic unit in the preamble of the FTV signal can be detected based on the dechirp process.
3. The real-time countermeasure method for drones against the LoRa communication protocol according to claim 2, characterized in that: In step 1, in the channel occupancy detection CAD working mode of the LoRa chip, the LoRa device will scan the channel to detect the presence of the preamble; if the preamble is detected, it means that the channel is occupied, and the LoRa device will stop sending data and wait for the channel to be idle; finally, the detection of the LoRa signal is realized through the above mechanism.
4. A real-time countermeasure method for drones against the LoRa communication protocol according to claim 1, characterized in that: In step 2, first record and analyze the spectrum of the target signal in GNU Radio. First, introduce the method of spectrum analysis; in the software-defined radio platform, analyze the period T of each LoRa signal symbol, s the maximum frequency and the minimum frequency Based on this, the bandwidth BW and the center frequency f RF can be obtained. After calculation, the spreading factor SF is obtained.
5. The real-time countermeasure method for drones against the LoRa communication protocol according to claim 1, characterized in that: In step 2, the detection method of LoRa Sniffer is then used. The implementation of LoRa Sniffer is related to the CAD mode in the LoRa chip; CAD mode is a working mode of the LoRa chip, which is used to detect whether there is an ongoing LoRa transmission on the channel. In CAD mode, the LoRa device will monitor the activity of a specific channel; if activity is detected, the device will delay sending data until the channel is idle. Based on the CAD mode, the LoRa Sniffer can actually capture and analyze the data passing through the channel; in the CAD mode of the LoRa chip, it first scans the frequency band to detect the channel occupied by the target signal, and then cyclically scans different spreading factors SF and bandwidths BW of LoRa communication. When the spreading factor SF, bandwidth BW, and center frequency f of the LoRa Sniffer are the same as those of the target signal, the LoRa Sniffer will return the various parameters of the target signal to prepare for the transmission of the interfering signal in step 2. RF are the same, the LoRa Sniffer will return the various parameters of the target signal to prepare for the transmission of the interfering signal in step 2.
6. The real-time countermeasure method for drones against the LoRa communication protocol according to claim 1, characterized in that: In the step 3, the sending of the interference signal is implemented on the software radio platform GNU Radio; The target signal interference on a single frequency band is simulated for the communication between two SX1276 chips. The target signal center frequency is 915MHz, the bandwidth is set to 125kHz, the spreading factor is 7, and the preamble length is 8.
7. A real-time countermeasure method for drones against the LoRa communication protocol according to claim 6, characterized in that: In step 3, the interference signal is a continuous upchirp signal having the same center frequency, bandwidth, and spreading factor parameters as the target signal, and the signal strength is adjusted by adjusting the constant value of Constant Source.
Citation Information
Cited By
METHOD FOR RADIO SUPPRESSION OF DATA TRANSMISSION CHANNELS WITH MODULATION USING LoRa TECHNOLOGY
RU2864006C1