Method, device and system for downlink PSA detection
By introducing third-party trusted nodes in the Cell-free large-scale MIMO system, using the likelihood ratio detection principle to analyze the backhaul signal of the user equipment, the downlink PSA detection inaccuracy caused by the user channel estimation error is solved, and the accurate identification of malicious access points and the improvement of system security is achieved.
Patent Information
- Application Number
- CN202510730745.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-03
- Publication Date
- 2025-07-25
AI Technical Summary
In the prior art, the channel estimation and noise statistical characteristics design judgment measurements may have large errors in complex environments, affecting the accuracy of downlink PSA detection.
A third-party trusted node is introduced to analyze the backhaul signals of the user equipment, and by recording and re-stitching of the downlink equivalent channel estimates of the target user, it analyzes based on the likelihood ratio detection principle to identify the downlink PSA attack behavior of the malicious access point.
It improves the accuracy of downlink PSA detection, can accurately identify attack behaviors of malicious access points, and improves the security and attack resistance of the system.
Smart Images

Figure CN120378885A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security technology, and for example, relates to a method, device and system for downlink PSA detection. Background Art
[0002] With the rapid growth of data traffic and the continuous improvement of confidentiality requirements, physical layer security technology has gradually become a research hotspot, and it is crucial to ensure the security performance of wireless communication systems. In the application process of downlink channel estimation for Cell-free massive MIMO (Multiple-Input Multiple-Output) systems, due to the openness of the channel, malicious attackers can take the opportunity to launch a downlink PSA (Pilot Spoofing Attack). This attack will affect the downlink transmission rate of the system, thereby reducing the system performance. Therefore, the research on downlink PSA detection is particularly important and urgently needs to be explored in depth.
[0003] In the related art, a PSA detection method for a massive MIMO system is provided, using the classical Alice BobEve model to describe the transmission process; a PSA method for a MassiveMIMO system based on the feedback method is proposed, enabling it to cope with the situation when the prior message is unknown, including feedback strategies, prior information acquisition, decision metric design, and analysis of key parameters for PSA detection. The decision execution is carried out separately at each user, and the decision metric is constructed using the feedback signal, and each user only needs to know the noise variance in advance.
[0004] In the process of implementing the embodiments of the present disclosure, it is found that there are at least the following problems in the related art:
[0005] In the related art, the decision metric is designed based on the channel estimation and noise statistical characteristics at the user end, but the decision metric determined in a complex environment may have a large error, affecting the accuracy of PSA detection.
[0006] It should be noted that the information disclosed in the above background art section is only used to enhance the understanding of the background of this application, and therefore may include information that does not constitute the prior art known to those of ordinary skill in the art. Summary of the Invention
[0007] To have a basic understanding of some aspects of the disclosed embodiments, a simple summary is given below. The summary is not a general review, nor is it intended to identify key / important elements or delineate the scope of protection of these embodiments, but rather serves as a preface to the following detailed description.
[0008] Embodiments of the present disclosure provide a method, apparatus, and system for downlink PSA detection to improve the accuracy of downlink PSA detection.
[0009] In some embodiments, the method for downlink PSA detection is applied to a third-party trusted node. The method includes: after the user equipment receives a downlink training sequence initiated by a malicious access point and performs downlink equivalent channel estimation, receiving feedback signals from all users; determining the downlink equivalent channel estimation value of the target user according to the feedback signals; recording and re-splicing the downlink equivalent channel estimation value of the target user to obtain a target column vector; and analyzing the target column vector based on the likelihood ratio detection principle to determine whether the malicious access point has launched a downlink PSA against the target user.
[0010] Optionally, receiving feedback signals from all users includes: receiving first feedback signals from each user; the first feedback signals being pilot signals; receiving second feedback signals from each user; the second feedback signals including downlink equivalent channel estimation characteristic signals in the case where it is assumed that the user has not been subjected to downlink PSA and in the case where it is assumed that the user has been subjected to downlink PSA.
[0011] Optionally, determining the downlink equivalent channel estimation value of the target user according to the feedback signals includes: performing LS channel estimation according to the first feedback signals to obtain the channel response from the third-party trusted node to the target user; after projecting the second feedback signals onto the target user, combining the channel response from the third-party trusted node to the target user to obtain the downlink equivalent channel estimation values in the case where it is assumed that the target user has not been subjected to downlink PSA and in the case where it is assumed that the target user has been subjected to downlink PSA, and determining the distribution of the downlink equivalent channel estimation values.
[0012] Optionally, recording and re-splicing the downlink equivalent channel estimation value of the target user to obtain a target column vector includes: recording and re-splicing the downlink equivalent channel estimation value of the target user to obtain a first column vector; defining a second column vector according to the first column vector; and taking out and re-splicing the imaginary part and the real part of the second column vector to obtain the target column vector.
[0013] Optionally, analyzing the target column vector based on the likelihood ratio detection principle includes: defining an observation value according to the target column vector; determining a detector expression according to the distributions of the observation value in the case where it is assumed that the user has not been subjected to downlink PSA and in the case where it is assumed that the user has been subjected to downlink PSA; and determining whether the malicious access point has launched a downlink PSA according to the decision metric and the decision threshold in the detector expression.
[0014] Optionally, determine the detector expression according to the distributions of the observation values under the assumptions that the user is not subject to downlink PSA and that the user is subject to downlink PSA, including: determining the likelihood function according to the distributions of the observation values under the assumptions that the user is not subject to downlink PSA and that the user is subject to downlink PSA; simplifying the likelihood function according to the expectations and variances of the observation values under the assumptions that the user is not subject to downlink PSA and that the user is subject to downlink PSA to obtain the detector expression.
[0015] Optionally, determine the decision metric and the decision threshold in the following manner: construct the decision metric according to the observation values; determine the false alarm probability that the target user is determined to be subject to PSA when the target user is not subject to downlink PSA; calculate the decision threshold using the false alarm probability according to the distributions of the decision metric under the assumptions that the target user is not subject to downlink PSA and that the target user is subject to downlink PSA.
[0016] Optionally, determine whether the malicious access point launches downlink PSA against the target user according to the decision metric and the decision threshold in the detector expression, including: when the decision threshold is greater than the decision metric, determine that the malicious access point does not launch downlink PSA; or, when the decision threshold is less than the decision metric, determine that the malicious access point launches downlink PSA.
[0017] In some embodiments, the apparatus for downlink PSA detection includes a processor and a memory storing program instructions, and the processor is configured to execute the method for downlink PSA detection as described above when running the program instructions.
[0018] In some embodiments, the system for downlink PSA detection includes: a third-party trusted node provided with the apparatus for downlink PSA detection as described above; a user equipment configured to send a feedback signal to the third-party trusted node after receiving a downlink training sequence initiated by a malicious access point and performing downlink equivalent channel estimation.
[0019] The method, apparatus, and system for downlink PSA detection provided by the embodiments of the present disclosure can achieve the following technical effects:
[0020] In the embodiments of the present disclosure, during the downlink training phase of the user equipment, a third-party node is introduced to analyze the feedback signal of the user equipment. By recording and re-splicing the downlink equivalent channel estimation values of the target user to form a target column vector and analyzing based on the likelihood ratio detection principle, the downlink PSA attack behavior of the malicious access point can be accurately identified, improving the accuracy of downlink PSA detection.
[0021] The above general description and the following description are only exemplary and explanatory, and are not used to limit this application. Description of the Drawings
[0022] One or more embodiments are exemplarily illustrated by corresponding accompanying drawings. These exemplary illustrations and the accompanying drawings do not constitute a limitation on the embodiments. Elements with the same reference numerals in the accompanying drawings are shown as similar elements. The accompanying drawings do not constitute a scale limitation, and wherein:
[0023] Figure 1 is a schematic diagram of data transmission of a PSA detection model provided by an embodiment of the present disclosure in the uplink training phase;
[0024] Figure 2 is a schematic diagram of data transmission of a PSA detection model provided by an embodiment of the present disclosure in the downlink training phase;
[0025] Figure 3 is a schematic diagram of data transmission of a PSA detection model provided by an embodiment of the present disclosure in the PSA detection phase;
[0026] Figure 4 is a TDD protocol structure of a PSA detection model provided by an embodiment of the present disclosure;
[0027] Figure 5 is a schematic diagram of a method for downlink PSA detection provided by an embodiment of the present disclosure;
[0028] Figure 6 is a schematic diagram of a device for downlink PSA detection provided by an embodiment of the present disclosure. Detailed Embodiments
[0029] In order to be able to understand the features and technical content of the embodiments of the present disclosure in more detail, the implementation of the embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings. The accompanying drawings are for reference and illustration only and are not used to limit the embodiments of the present disclosure. In the following technical description, for the sake of explanation, numerous details are provided to give a thorough understanding of the disclosed embodiments. However, one or more embodiments may still be implemented without these details. In other cases, well-known structures and devices may be shown in a simplified manner.
[0030] The terms "first", "second", etc. in the technical solutions described in this application are used to distinguish similar objects and do not necessarily have to be used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so as to implement the embodiments of the present disclosure described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion.
[0031] Unless otherwise specified, the term "plurality" means two or more.
[0032] In the embodiments of the present disclosure, the character " / " indicates an "or" relationship between the preceding and following objects. For example, A / B means: A or B.
[0033] The term "and / or" is an associative relationship describing an object, indicating that there can be three relationships. For example, A and / or B means: A or B, or, the three relationships of A and B.
[0034] The term "corresponds to" can refer to an associative relationship or a binding relationship. A corresponding to B means that there is an associative relationship or a binding relationship between A and B.
[0035] The embodiments of the present disclosure provide a PSA detection model, including a user device, a CPU, malicious access points (AccessPoints, APs), legitimate APs, and third-party trusted access points. The legitimate APs are connected to the CPU, and the user device can communicate with the legitimate APs and malicious APs. In the uplink training phase, since the malicious APs have obtained the pilot sequences of each user in advance, the malicious APs will perform uplink channel estimation synchronously with the legitimate APs, and use the estimated channel response information to precode the downlink pilot sequences in the downlink training phase to correctly initiate the downlink PSA.
[0036] Combined Figure 1 As shown, during the uplink training, since the malicious APs have obtained the pilot information of the users in advance, the malicious APs (malicious AP1, malicious AP2) will synchronously receive the uplink pilot signals sent by the users with the legitimate APs (legitimate AP1, legitimate AP2, legitimate AP3), and estimate the channel state information between the users and themselves. That is, at the nth malicious AP node, the received pilot signal sent by the user will be:
[0037]
[0038] Among them, k′ is an accumulative variable between 1 and K, k represents any value between 1 and K, f nk is the channel between the kth user and the nth malicious AP, and p nk is the small-scale fading factor between the malicious AP and the user, θ nk is the large-scale fading coefficient, is the downlink pilot vector, w up,n is the noise, τ up is the length of the uplink pilot, ρ up is the uplink normalized signal-to-noise ratio. The nth malicious AP uses the MMSE (Minimum Mean Square Error) criterion to estimate the channel characteristic coefficient of the kth user, and the estimation result is:
[0039]
[0040] Similar to the channel estimation with a legitimate AP, the uplink channel estimation error of the malicious AP is defined as which is uncorrelated with In addition, the channel estimation value and the estimation error respectively satisfy and where κ nk is the variance of, denoted as:
[0041]
[0042] Combined with Figure 2 As shown, after entering the downlink training phase, the malicious AP uses conjugate beamforming to precode and transmit the downlink pilot signal, that is, the malicious AP and the legitimate AP synchronously send the downlink pilot signal to the user equipment. Since using a beamforming system different from that of the legitimate AP will complicate the analysis process, conjugate beamforming is used. The downlink pilot vector of the nth malicious AP is:
[0043]
[0044] where τ dp is the length of the downlink pilot, μ dp is the normalized transmission signal-to-noise ratio of the downlink pilot of the malicious AP, ζ nk′ is the power allocation factor for transmitting the downlink pilot ψ k′ of the nth malicious access point, is the conjugate of. Since the legitimate AP and the malicious AP simultaneously and synchronously send the beamformed pilot sequences, the received signal of the kth user is:
[0045]
[0046] where ρ dp is the downlink normalized signal-to-noise ratio, a kk′ is the equivalent channel gain between the downlink user k and the downlink user k′, w dp,k is the noise signal, is y when there is an attack dp,k , The second term in the formula represents the pilot contamination from the malicious AP.
[0047] Since the kth user is unaware of the existence of the downlink PSA, after projecting the received downlink pilot vector onto the known downlink pilot sequence in the presence of the downlink PSA, it is expressed as:
[0048]
[0049] Among them,
[0050] is the one when there is an attack is the signal after the k-th user projects the received downlink pilot signal onto . After the k-th user performs linear minimum mean square error estimation on a kk , the estimation result can be obtained as:
[0051]
[0052]
[0053] Among them, E{a kk} is the expected value of the downlink equivalent channel of the k-th user, is the covariance of a kk and , a kk is the downlink equivalent channel of the k-th user, is 's variance, is 's expectation, η mk is the power control coefficient from the m-th AP to the k-th user, γ mk is the mean square value of the uplink channel estimation result, β mk is the large-scale fading coefficient between the k-th user and the m-th AP.
[0054] In the presence of downlink PSA, except for , other parameters still exist and remain unchanged because the user does not know whether the received signal contains pilots sent by malicious APs. Since contains the channel estimation result includes not only the desired channel a kk , but also the interference channel b kk from malicious APs. It can be seen that simply increasing the transmission power of legitimate access points cannot eliminate interference. If the user uses the channel estimation value affected by pilot attacks for data decoding, the achievable downlink rate may suffer a significant loss. In addition, malicious APs may cooperate to launch attacks and optimize the power allocation coefficient ζ nk , thus further reducing the downlink rate. Therefore, downlink PSA poses a serious threat to the security of the de-cellularized massive MIMO system.
[0055] Combined with Figure 3As shown, the PSA detection model provided by the embodiments of the present disclosure introduces an authorized and trusted third-party trusted node HELPER on the basis of the Alice-Bob-Eve model. Its functions include but are not limited to assisting in detecting the downlink pilot spoofing attack of malicious APs, assisting in detecting the uplink pilot spoofing attack of malicious users, and countering pilot spoofing attacks. In a cell-free massive MIMO system operating in the TDD mode, there are M legitimate APs, N malicious APs, and K users. Both the legitimate APs and the malicious APs are single-antenna transmissions, and the channel model conforms to the standard block fading model. The downlink PSA detection model adds an authorized and trusted single-antenna third-party trusted node HELPER, and this node is connected to the CPU in the same way as the legitimate APs. The channel response from the trusted node HELPER to the k-th user can be expressed as where β Tk is the large-scale fading coefficient from the k-th user to the detection node, and h Tk is the small-scale fading coefficient from the k-th user to the detection node, satisfying The large-scale fading includes two parts, namely path loss and shadow fading, and the coefficient β Tk is constant over multiple coherence intervals.
[0056] In the embodiments of the present disclosure, for a system with a downlink PSA detection module, the coherence interval spacing is different from that of a conventional cell-free massive MIMO system. The coherence interval of the conventional cell-free massive MIMO system model TDD (Time Division Duplex) is τ C sample length, which includes four stages, namely uplink training τ up , uplink data transmission τ ud , downlink training τ dp , and downlink data transmission τ dd . In the PSA detection model provided by the embodiments of the present disclosure, as shown in combination with Figure 4 , the coherence interval includes five components. In addition to the four stages mentioned above, a PSA detection stage is added after the downlink training stage to detect whether there is a downlink PSA for malicious APs, denoted by τ T . Therefore, the coherence interval length τ c of the system model = τ up + τ ud + τ dp + τ dd + τ TThe work content is different in different stages. In the uplink training stage, the legitimate AP performs channel estimation based on the received user pilot sequence. Since the malicious AP knows the user pilot information in advance, it will also receive the pilot information and perform channel estimation, but it will not initiate an attack in this stage. Then, in the third stage of downlink training, the legitimate AP precodes the downlink pilot signal and sends it to the user, and the user performs downlink channel estimation. In this stage, the malicious AP will precode the pilot signal and launch a pilot attack on the user. After the user performs downlink channel estimation, in the fourth stage, the user device will send a signal with the characteristics of downlink channel estimation to the third-party trusted node, and the PSA detection process is completed on the trusted node side. In addition, the third-party trusted node does not participate in the communication in other stages except the PSA detection stage.
[0057] It is assumed that the malicious AP has pre-obtained the complete information of the downlink training sequence. On this premise, when entering the downlink training stage, the malicious AP will synchronously send the training sequence to the user together with the legitimate AP. At this time, the k-th user performs a linear minimum mean square error estimation on the downlink equivalent channel a kk which is expressed as:
[0058]
[0059] where, it is assumed that H0 is the case where the user is not affected by the downlink PSA, and H1 is the case where the user is affected by the downlink PSA. After sorting out this formula, we can get:
[0060]
[0061] where,
[0062]
[0063]
[0064] After each user performs downlink equivalent channel estimation, signal feedback will be carried out and sent back to the third-party trusted node. Therefore, as shown in Figure 5 the embodiments of the present disclosure provide a method for downlink PSA detection applied to a third-party trusted node. The execution subject of this method can be a processor set in the third-party trusted node. The method includes:
[0065] S501, after the user equipment receives the downlink training sequence initiated by the malicious access point and the user equipment performs downlink equivalent channel estimation, the processor receives the feedback signals from all users.
[0066] S502, the processor determines the downlink equivalent channel estimation value of the target user according to the feedback signals.
[0067] S503. The processor records and re - splices the downlink equivalent channel estimation values of the target user to obtain a target column vector.
[0068] S504. The processor analyzes the target column vector based on the likelihood - ratio detection principle to determine whether the malicious access point has launched a downlink PSA against the target user.
[0069] In the embodiments of the present disclosure, during the downlink training phase of the user equipment, a third - party node is introduced to analyze the feedback signal of the user equipment. By recording and re - splicing the downlink equivalent channel estimation values of the target user to form a target column vector and analyzing it based on the likelihood - ratio detection principle, the downlink PSA attack behavior of the malicious access point can be accurately identified, improving the accuracy of downlink PSA detection.
[0070] Optionally, receive the feedback signals from all users, including: receiving the first feedback signals from each user; the first feedback signals are pilot signals; receiving the second feedback signals from each user; the second feedback signals include the downlink equivalent channel estimation characteristic signals in the case where it is assumed that the user is not affected by the downlink PSA and in the case where it is assumed that the user is affected by the downlink PSA.
[0071] In this embodiment, as Figure 3 shown, the feedback signal of the user is divided into two parts. Among them, the first feedback signal is x1, and the second feedback signal is x2. The first feedback signal is intended to estimate the channel response from the trusted node to the user, and the second feedback signal is intended to construct a decision statistic. The first feedback signal and the second feedback signal can be expressed as:
[0072] x1 = f k
[0073]
[0074] where f k is a pilot signal, satisfying and there is k≠k′, k = k′, and ||f k || 2 = 1, and are the downlink equivalent channel estimation values under the hypotheses H0 and H1 respectively.
[0075] When the user equipment sends the first feedback signal, for the hypotheses H0 and H1, the first feedback signals are the same, which are pilot signals. Therefore, the signals received by the trusted node are also the same. Then, the feedback signal y1 from each user received by the trusted node is:
[0076]
[0077] where ρT is the normalized signal-to-noise ratio of the signal in the feedback phase, and τ T is the length of the pilot signal in the feedback, and w is the noise.
[0078] When the user sends the second feedback signal, the feedback signals y2 received by the optional nodes from each user under different assumptions are different, and at this time:
[0079]
[0080] Optionally, determining the downlink equivalent channel estimation value of the target user according to the feedback signal includes: performing LS channel estimation according to the first feedback signal to obtain the channel response from the third-party trusted node to the target user; after projecting the second feedback signal to the target user, combining the channel response from the third-party trusted node to the target user, obtaining the downlink equivalent channel estimation values under the assumption that the target user is not affected by the downlink PSA and the assumption that the target user is affected by the downlink PSA, and determining the distribution of the downlink equivalent channel estimation value.
[0081] In this embodiment, the trusted node uses the received feedback signal y1 to perform LS signal estimation, and the channel response from the trusted node to the k-th user is obtained and expressed as:
[0082]
[0083] Then, after the trusted node linearly projects the received feedback signal y2 to the k-th user for processing, it obtains:
[0084]
[0085] Within a coherence interval, it can be considered that the channel response remains unchanged. Therefore, the trusted node can use the LS channel estimation value in the feedback signal x1 stage to obtain the downlink equivalent channel estimation value of the user, expressed as:
[0086]
[0087] After simplifying and arranging this formula, it can be known that the downlink equivalent channel estimation value obtained at the trusted node satisfies the following distribution:
[0088]
[0089] Among them, β Tk is the large-scale fading coefficient from the k-th user to the trusted node. ε k , υ k , The expressions of are respectively:
[0090]
[0091] Optionally, record and re - splice the downlink equivalent channel estimation values of the target user to obtain a target column vector, including: record and re - splice the downlink equivalent channel estimation values of the target user to obtain a first column vector; define a second column vector according to the first column vector; take out and re - splice the imaginary part and real part of the second column vector to obtain the target column vector.
[0092] In this embodiment, since a malicious AP may not necessarily be able to master the pilot sequences of all users in actual situations, it is particularly necessary to consider detecting pilot attacks for a single user. This embodiment takes the PSA detection of the k - th user as an example, and uses the downlink equivalent channel estimation values obtained at the trusted node to carry out attack detection. Collect and save the information about the k - th user received by the detection node, record it once in each coherence interval, record it continuously for H times, and then re - splice the recorded data to form a new set of first column vectors Denoted as:
[0093]
[0094] Each element b in the first column vector b i is an independent and identically - distributed random variable. According to the Khinchin's law of large numbers, when the recording times H of the detection node is large enough, use the sample mean to approximately replace the population mean Ε{b i}, define a new second column vector d, and its element d i is Then d i approximately follows the following distribution:
[0095]
[0096] Then take out and re - splice the real part and imaginary part of the elements in the second column vector d to form a new set of target column vectors c, and satisfy Denoted as:
[0097]
[0098] The elements c in the target column vector c i satisfy:
[0099]
[0100] Among them,
[0101]
[0102] Optionally, analyze the target column vector based on the likelihood ratio detection principle, including: defining an observation value according to the target column vector; determining a detector expression according to the distributions of the observation value under the assumption that the user is not affected by the downlink PSA and the assumption that the user is affected by the downlink PSA; and determining whether the malicious access point has launched the downlink PSA according to the decision metric and decision threshold in the detector expression.
[0103] In this embodiment, based on the likelihood ratio detection principle, a binary likelihood ratio detector for Gaussian distribution can be obtained. According to the target column vector c, an observation value q can be defined i , expressed as:
[0104] q i = c i , i = 1, 2,..., 2H
[0105] At the trusted node, H independent and identically distributed observation values are obtained according to c i . Under the assumptions H0 and H1, the distributions of q i are respectively:
[0106]
[0107] Optionally, determining the detector expression according to the distributions of the observation value under the assumption that the user is not affected by the downlink PSA and the assumption that the user is affected by the downlink PSA includes: determining the likelihood function according to the distributions of the observation value under the assumption that the user is not affected by the downlink PSA and the assumption that the user is affected by the downlink PSA; and simplifying the likelihood function according to the expectations and variances of the observation value under the assumption that the user is not affected by the downlink PSA and the assumption that the user is affected by the downlink PSA to obtain the detector expression.
[0108] In this embodiment, first assume that there are now N independent and identically distributed observation values S = {S1, S2,..., S N}, and the distributions of S n under the binary hypotheses H A and H B are:
[0109]
[0110] According to the Neyman-Pearson theorem, it can be determined which of H A and H B is true and which is false through the likelihood ratio test. The corresponding likelihood function is:
[0111]
[0112] where p(S; H A ) and p(S; HB ) represent a joint distribution under two assumptions respectively. γ is the decision threshold. Simplify and organize the above formula, and take the logarithm to get:
[0113]
[0114] According to the distribution of q i , the expected value μ i of the distribution of q A under hypothesis H0 and hypothesis H1 can be determined as μ B = μ and Then, substituting the expected value and variance of q i into the above formula and simplifying, we can get
[0115] The detector expression is:
[0116]
[0117] where φ2 is the decision metric of the detector expression, and γ2 is the decision threshold of the detector expression.
[0118] Optionally, the decision metric and decision threshold are determined as follows: construct the decision metric according to the observation value; determine the false alarm probability that the target user is judged to be affected by the downlink PSA when it is not actually affected by the downlink PSA; calculate the decision threshold using the false alarm probability according to the distributions of the decision metric under the assumption that the target user is not affected by the downlink PSA and the assumption that the target user is affected by the downlink PSA.
[0119] In this embodiment, the decision metric can be constructed from the observation value, specifically expressed as:
[0120]
[0121] For a random variable satisfying c i ~ N(0, β c ), then there is:
[0122]
[0123] In addition, assume that a random variable D follows a chi-square distribution with degree of freedom v, and c is a constant greater than 0. Then its product cD follows a Gamma distribution with shape parameter and scale parameter 2c, denoted as where k is the shape parameter of the Gamma distribution and θ is the scale parameter. Therefore, the distributions of φ2 under hypothesis H0 and hypothesis H1 can be obtained as:
[0124]
[0125] Assume that the probability density function of φ2 under the hypothesis H0 is denoted by f b,0 (.), then the false alarm probability P fa is given by:
[0126]
[0127] where Γ(.) is the Gamma function, γ(a, b) is the lower incomplete Gamma function, Γ(a, b) represents the upper incomplete Gamma function, and η2 represents the actual decision threshold. The false alarm probability P fa represents the probability that a PSA is judged to exist during the downlink training phase when there is no PSA. In the entire detection process, first, a false alarm probability P fa is given, and then the given false alarm probability P fa is substituted into the above formula to calculate the actual threshold η2. Finally, by comparing the magnitudes of the decision threshold η2 and the decision metric φ2, it is determined whether there is a downlink PSA.
[0128] Optionally, according to the decision metric and the decision threshold in the detector expression, it is determined whether a malicious access point has launched a downlink PSA, including: when the decision threshold is greater than the decision metric, it is determined that the malicious access point has not launched a downlink PSA; or, when the decision threshold is less than the decision metric, it is determined that the malicious access point has launched a downlink PSA.
[0129] In this embodiment, when the decision threshold η2 is greater than the decision metric φ2, the hypothesis H0 is judged to be true, and when the decision threshold η2 is less than the decision metric φ2, the hypothesis H1 is judged to be true.
[0130] Optionally, for the method for downlink PSA detection provided by the embodiments of the present disclosure, its theoretical detection probability P d is given by:
[0131]
[0132] where f b,1 (.) is the probability density function of the decision metric φ2 under the hypothesis H1.
[0133] The method for downlink PSA detection provided by the embodiments of the present disclosure can effectively detect downlink PSA by introducing a third-party trusted node in a Cell-free massive MIMO system and using this node to receive and analyze the feedback signals from user equipment. Moreover, based on the likelihood ratio detection principle, by constructing a decision metric and setting a decision threshold, accurate identification of malicious AP attack behaviors is achieved, thereby significantly enhancing the security and anti-attack capabilities of the system and ensuring the reliability of wireless communication and the integrity of data transmission. In addition, this method has a low false positive rate and high adaptability for the detection of downlink PSA, and is applicable to various communication scenarios, including automotive, mobile phone, and satellite communications, etc.
[0134] As shown in combination Figure 6 shown, the embodiments of the present disclosure provide a device 600 for downlink PSA detection, including a processor 700 and a memory 701, and may further include a communication interface 702 and a bus 703. Among them, the processor 700, the communication interface 702, and the memory 701 can communicate with each other through the bus 703. The communication interface 702 can be used for information transmission. The processor 700 can call the logical instructions in the memory 701 to execute the method for downlink PSA detection in the above embodiments.
[0135] In addition, when the logical instructions in the above memory 701 are implemented in the form of a software functional unit and sold or used as an independent product, they can be stored in a computer-readable storage medium.
[0136] The memory 701, as a computer-readable storage medium, can be used to store software programs and computer-executable programs, such as the program instructions / modules corresponding to the method in the embodiments of the present disclosure. The processor 700 executes functional applications and data processing by running the program instructions / modules stored in the memory 701, that is, implements the method for downlink PSA detection in the above method embodiments.
[0137] The memory 701 may include a program storage area and a data storage area. Among them, the program storage area can store an operating system and application programs required for at least one function; the data storage area can store data created according to the use of the terminal device, etc. In addition, the memory 701 may include a high-speed random access memory and may also include a non-volatile memory.
[0138] An embodiment of the present disclosure provides a system for downlink PSA detection, including: a third-party trusted node and a user equipment. The third-party trusted node is provided with the above-mentioned device for downlink PSA detection. The user equipment is configured to send a feedback signal to the third-party trusted node after receiving a downlink training sequence initiated by a malicious access point and performing downlink equivalent channel estimation.
[0139] An embodiment of the present disclosure provides a computer-readable storage medium storing computer-executable instructions, and the computer-executable instructions are configured to execute the above-mentioned method for downlink PSA detection.
[0140] An embodiment of the present disclosure provides a computer program product, the computer program product includes a computer program stored on a computer-readable storage medium, the computer program includes program instructions, and when the program instructions are executed by a computer, the computer is caused to execute the above-mentioned method for downlink PSA detection.
[0141] The above-mentioned computer-readable storage medium may be a transient computer-readable storage medium or a non-transient computer-readable storage medium.
[0142] The technical solution of the embodiment of the present disclosure may be embodied in the form of a software product. The computer software product is stored in a storage medium and includes one or more instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in the embodiment of the present disclosure. The foregoing storage medium may be a non-transient storage medium, including: a USB flash drive, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk, or an optical disc and other media that can store program codes, or may also be a transient storage medium.
[0143] The above description and the accompanying drawings fully illustrate the embodiments of the present disclosure, enabling those skilled in the art to practice them. Other embodiments may include structural, logical, electrical, process, and other changes. Embodiments merely represent possible variations. Unless explicitly required, individual components and functions are optional, and the order of operations may vary. Parts and features of some embodiments may be included in or replace parts and features of other embodiments. The scope of the embodiments of the present disclosure includes the entire scope of the claims and all available equivalents of the claims. When used in this application, although terms such as "first", "second", etc. may be used in this application to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, without changing the meaning of the description, the first element may be called the second element, and similarly, the second element may be called the first element, as long as all occurrences of the "first element" are consistently renamed and all occurrences of the "second element" are consistently renamed. The first element and the second element are both elements, but they may not be the same element. Moreover, the terms used in this application are only used to describe the embodiments and do not limit the claims. As used in the description of the embodiments and the claims, unless the context clearly indicates otherwise, the singular forms "a", "an", and "the" are intended to also include the plural forms. Similarly, as used in this application, the term "and / or" refers to any and all possible combinations including one or more of the associated listed items. Additionally, when used in this application, the term "comprise" and its variants "comprises" and / or "comprising" etc. mean the presence of the stated features, wholes, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or groups of these. Without further limitation, an element defined by the statement "comprising one..." does not exclude the presence of additional identical elements in the process, method, or device comprising the element. Herein, each embodiment may focus on the differences from other embodiments, and the same or similar parts between various embodiments may be referred to each other. For the methods, products, etc. disclosed in the embodiments, if they correspond to the method part disclosed in the embodiments, the relevant parts may refer to the description of the method part.
[0144] Those skilled in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner may depend on the specific application and design constraints of the technical solution. The skilled person can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of the embodiments of the present disclosure. The skilled person can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.
[0145] In the embodiments disclosed herein, the disclosed methods, products (including but not limited to devices, equipment, etc.) can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units can be merely a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the devices or units can be in an electrical, mechanical or other forms. The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to implement this embodiment. In addition, in the embodiments of the present disclosure, the functional units can be integrated in one processing unit, or each unit can exist physically separately, or two or more units can be integrated in one unit.
[0146] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a segment of code, or a portion thereof, which contains one or more executable instructions for implementing the specified logical function. In some alternative implementations, the functions noted in the blocks may occur in a different order than noted in the accompanying drawings. For example, two consecutive blocks may in fact be executed substantially in parallel, or they may sometimes be executed in the reverse order, depending on the functions involved. In the description corresponding to the flowcharts and block diagrams in the accompanying drawings, the operations or steps corresponding to different blocks may also occur in a different order than disclosed in the description, and sometimes there is no specific order between different operations or steps. For example, two consecutive operations or steps may in fact be executed substantially in parallel, or they may sometimes be executed in the reverse order, depending on the functions involved. Each block in the block diagram and / or flowchart, and combinations of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based system that performs the specified functions or actions, or may be implemented by a combination of dedicated hardware and computer instructions.
Claims
1. A method for detecting PSA in the downlink, characterized in that, Applied to a third-party trusted node, the method includes: After the user equipment receives the downlink training sequence initiated by the malicious access point and performs downlink equivalent channel estimation, receive the feedback signals from all users; Determine the downlink equivalent channel estimation value of the target user according to the feedback signals; Record and re-stitch the downlink equivalent channel estimation value of the target user to obtain the target column vector; Analyze the target column vector based on the likelihood ratio detection principle to determine whether the malicious access point has launched a downlink PSA against the target user.
2. The method according to claim 1, wherein Receive the feedback signals from all users, including: Receive the first feedback signals from each user; the first feedback signals are pilot signals; Receive the second feedback signals from each user; the second feedback signals include the downlink equivalent channel estimation characteristic signals in the case where it is assumed that the user has not been affected by the downlink PSA and in the case where it is assumed that the user has been affected by the downlink PSA.
3. The method according to claim 2, wherein Determine the downlink equivalent channel estimation value of the target user according to the feedback signals, including: Perform LS channel estimation according to the first feedback signals to obtain the channel response from the third-party trusted node to the target user; After projecting the second feedback signals to the target user, combine the channel response from the third-party trusted node to the target user to obtain the downlink equivalent channel estimation values in the case where it is assumed that the target user has not been affected by the downlink PSA and in the case where it is assumed that the target user has been affected by the downlink PSA, and determine the distribution of the downlink equivalent channel estimation values.
4. The method according to claim 1, wherein Record and re-stitch the downlink equivalent channel estimation value of the target user to obtain the target column vector, including: Record and re-stitch the downlink equivalent channel estimation value of the target user to obtain the first column vector; Define the second column vector according to the first column vector; Extract and re-stitch the imaginary part and the real part of the second column vector to obtain the target column vector.
5. The method according to any one of claims 1 to 4, characterized in that, Analyze the target column vector based on the likelihood ratio detection principle, including: Define the observation value according to the target column vector; Determine the detector expression according to the distributions of the observation value in the case where it is assumed that the user has not been affected by the downlink PSA and in the case where it is assumed that the user has been affected by the downlink PSA; Determine whether the malicious access point has launched a downlink PSA according to the decision metric and the decision threshold in the detector expression.
6. The method according to claim 5, wherein Determine the detector expression according to the distributions of the observation value in the case where it is assumed that the user has not been affected by the downlink PSA and in the case where it is assumed that the user has been affected by the downlink PSA, including: Determine the likelihood function according to the distributions of the observation value in the case where it is assumed that the user has not been affected by the downlink PSA and in the case where it is assumed that the user has been affected by the downlink PSA; Simplify the likelihood function according to the expectations and variances of the observation value in the case where it is assumed that the user has not been affected by the downlink PSA and in the case where it is assumed that the user has been affected by the downlink PSA to obtain the detector expression.
7. The method according to claim 5, characterized in that Determine the decision metric and the decision threshold in the following manner: Construct the decision metric according to the observation value; Determine the false alarm probability that the target user is determined to be affected by the PSA when it has not been affected by the downlink PSA; Calculate the decision threshold using the false alarm probability according to the distributions of the decision metric in the case where it is assumed that the target user has not been affected by the downlink PSA and in the case where it is assumed that the target user has been affected by the downlink PSA.
8. The method according to claim 5, characterized in that Determine whether a malicious access point has launched a downlink PSA according to the decision metric and decision threshold in the detector expression, including: In the case where the decision threshold is greater than the decision metric, determine that the malicious access point has not launched a downlink PSA; or, In the case where the decision threshold is less than the decision metric, determine that the malicious access point has launched a downlink PSA.
9. A device for downlink PSA detection, comprising a processor and a memory storing program instructions, characterized in that, The processor is configured to execute the method for downlink PSA detection according to any one of claims 1 to 8 when running the program instructions.
10. A system for downlink PSA detection, characterized in that, Including: A third-party trusted node provided with the device for downlink PSA detection according to claim 9; A user equipment configured to send a feedback signal to the third-party trusted node after receiving a downlink training sequence initiated by a malicious access point and performing downlink equivalent channel estimation.