A data security transmission method and system
By acquiring and monitoring the inherent radio frequency response fingerprint information and real-time response information of the antenna element, deviations are analyzed to identify tampering, solving the problem of tampering that cannot be detected in the prior art, and ensuring the security and integrity of data transmission.
Patent Information
- Application Number
- CN202511208176.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-27
- Publication Date
- 2025-11-25
- Estimated Expiration
- 2045-08-27
AI Technical Summary
Existing technologies cannot effectively detect tampered antenna elements in multi-antenna industrial control networks, potentially compromising the confidentiality and integrity of data transmission.
By acquiring the inherent radio frequency response fingerprint information of each antenna element and monitoring its radio frequency response information in real time during operation, the deviation can be analyzed to determine whether it has been tampered with, and appropriate security measures can be taken.
It enables timely detection of physical tampering, ensuring the confidentiality and integrity of data transmission in multi-antenna industrial control networks and preventing further damage to data security.
Smart Images

Figure CN120786372B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of antenna transmission, in particular to a data secure transmission method and system. BACKGROUND
[0002] In the industrial control network of remotely operating critical infrastructure, multi-antenna communication systems have become a core supporting technology. Through large-scale antenna arrays combined with beamforming and spatial multiplexing, the system provides high-reliability, low-latency data transmission services for multiple industrial control terminals within a wide area. By dynamically adjusting the antenna weighting vector, it optimizes signal quality, suppresses interference and maximizes throughput, demonstrating strong channel adaptive capability, ensuring data transmission confidentiality and integrity to meet the growing demand for industrial automation.
[0003] However, in the high-security industrial control environment, there is a hidden and extremely threatening attack method. Unauthorized entities may secretly invade and tamper with part of the antenna units in the multi-antenna system through physical means. This tampering does not cause the antenna units to completely fail, but rather makes minor and difficult-to-detect modifications to their internal radio frequency characteristics or digital control logic. These tampered antenna units can still pass the basic function test in the conventional system health check and exhibit similar external behavior to normal units, thereby evading preliminary security audits.
[0004] During data transmission, when the system performs beamforming or spatial multiplexing, the tampered antenna units will introduce preset minor nonlinear errors or deviations. The system adaptive algorithm will mistakenly consider these deviations as real channel changes or noise and compensate by adjusting the weighting coefficients of other non-tampered antenna units, inadvertently absorbing these deviations. This causes a subtle difference between the actual transmitted wireless signal and the ideal secure signal generated by the system, which may subtly change the channel fingerprint or distort the precoding matrix, thereby weakening the physical layer security mechanism or making the signal leakage path more predictable, ultimately causing potential damage to the confidentiality or integrity of data transmission.
[0005] Existing security mechanisms, including conventional system health checks and channel estimation, cannot effectively detect this coordinated minor tampering originating from internal physical components, which is absorbed by the adaptive algorithm. Therefore, it is impossible to timely discover and prevent potential damage to the confidentiality or integrity of data transmission caused by this, which poses a serious security risk in the highly secure industrial control network.
[0006] To address the above problems, there is currently no effective technical solution. SUMMARY
[0007] The purpose of the present application is to provide a data security transmission method and system to overcome the limitations of existing adaptive algorithms in absorbing tampering-induced errors, detect physical tampering, and ensure the confidentiality and integrity of data transmission in multi-antenna industrial control networks.
[0008] In a first aspect, the present application provides a data security transmission method applied to a multi-antenna industrial control network, wherein the multi-antenna industrial control network comprises a plurality of antenna units, and the method comprises the following steps:
[0009] S1, obtaining inherent radio frequency response fingerprint information of each antenna unit, wherein the inherent radio frequency response fingerprint information is obtained by stimulating and testing each antenna unit before deployment of the multi-antenna industrial control network or in a security calibration phase;
[0010] S2, obtaining real-time radio frequency response information of each antenna unit during operation of the multi-antenna industrial control network;
[0011] S3, analyzing the deviation of the response parameters of each antenna unit according to the inherent radio frequency response fingerprint information and the real-time radio frequency response information to determine whether each antenna unit is tampered with;
[0012] S4, triggering a security warning message for the tampered antenna unit and taking security processing.
[0013] The data security transmission method, wherein the step of stimulating and testing each antenna unit before deployment of the multi-antenna industrial control network or in the security calibration phase comprises:
[0014] A1, measuring the radio frequency response parameters of each antenna unit under different excitation conditions before deployment of the multi-antenna industrial control network or in the security calibration phase as the inherent radio frequency response fingerprint information of the corresponding antenna unit, and storing it in the security storage module of the multi-antenna industrial control network.
[0015] The data security transmission method, wherein the step of measuring the radio frequency response parameters of each antenna unit under different excitation conditions before deployment of the multi-antenna industrial control network or in the security calibration phase comprises:
[0016] A11, performing multiple rounds of radio frequency response parameter measurement on each antenna unit based on a preset test excitation signal sequence representing different excitation conditions before deployment of the multi-antenna industrial control network or in the security calibration phase, obtaining multiple groups of original radio frequency response parameters, and simultaneously measuring and obtaining environmental parameters;
[0017] A12, compensating the original radio frequency response parameters for environmental impact and performing consistency verification based on the environmental parameters to obtain the radio frequency response parameters of each antenna unit under different excitation conditions.
[0018] The data secure transmission method, wherein step A12 comprises:
[0019] A121, according to the environmental parameters, using a preset compensation relationship, each group of the original radio frequency response parameters is compensated for environmental impact to obtain a plurality of groups of environmental calibrated radio frequency response parameters;
[0020] A122, the consistency of the plurality of groups of environmental calibrated radio frequency response parameters is verified, and the consistency verification comprises:
[0021] The statistical analysis is performed on the plurality of groups of environmental calibrated radio frequency response parameters, the statistical characteristics of each group of parameters are calculated, and according to the statistical characteristics and a preset deviation threshold, abnormal data deviating from the deviation threshold is identified and removed from each group of radio frequency response parameters;
[0022] The remaining radio frequency response parameters after removing the abnormal data are aggregated to obtain the radio frequency response parameters of each antenna unit under different excitation conditions.
[0023] The data secure transmission method, wherein step S2 comprises:
[0024] S21, during the operation of the multi-antenna industrial control network, the real-time radio frequency response information of each antenna unit is periodically collected, and the collection process comprises:
[0025] Based on the preset test excitation signal, the radio frequency response parameter measurement of each antenna unit is performed, and the radio frequency response data of each antenna unit under the corresponding excitation condition is collected;
[0026] Based on the preset test excitation signal sequence representing different excitation conditions, a plurality of rounds of real-time radio frequency response parameter measurement of each antenna unit is performed, a plurality of groups of original real-time radio frequency response parameters are obtained, and real-time environmental parameters are synchronously obtained, then the original real-time radio frequency response parameters are compensated for environmental impact and consistency verification based on the real-time environmental parameters, to obtain the real-time radio frequency response parameters of each antenna unit under different excitation conditions,
[0027] Or,
[0028] The latest communication signal of each antenna unit is obtained, and then the real-time radio frequency response information of each antenna unit is extracted according to the latest communication signal.
[0029] The data secure transmission method, wherein the radio frequency response parameters include amplitude response, phase response, harmonic component and intermodulation distortion.
[0030] The data secure transmission method, wherein step S3 comprises:
[0031] S31, calculating multi-dimension parameter deviations of each antenna unit under different excitation conditions according to the intrinsic radio frequency response fingerprint information and the real-time radio frequency response information;
[0032] S32, generating a comparison result according to the multi-dimension parameter deviations and a preset security threshold;
[0033] S33, judging whether the corresponding antenna unit is tampered according to the comparison result.
[0034] The data security transmission method, wherein step S32 comprises:
[0035] S321, calculating a comprehensive deviation index according to the multi-dimension parameter deviations and combining preset dimension parameter weights;
[0036] S322, obtaining aging information of each antenna unit, compensating the preset security threshold according to the aging information, and generating a comprehensive security threshold;
[0037] S323, comparing the comprehensive deviation index with the comprehensive security threshold to generate the comparison result.
[0038] The data security transmission method, wherein in step S4, the step of taking security processing comprises:
[0039] S41, obtaining identification information of the tampered antenna unit and multi-dimension parameter deviations determined based on the intrinsic radio frequency response fingerprint information and the real-time radio frequency response information;
[0040] S42, analyzing the multi-dimension parameter deviations to obtain a tampering type;
[0041] S43, generating an impact evaluation result based on the identification information, the tampering type, and a preset service priority;
[0042] S44, selecting a security response strategy from a preset security response strategy set according to the impact evaluation result, the security response strategy comprising one or more of complete isolation, weight reduction, switching to a backup antenna unit, and starting a redundant communication mechanism.
[0043] In a second aspect, the application further provides a data security transmission system applied to a multi-antenna industrial control network, the multi-antenna industrial control network comprising a plurality of antenna units, and the system comprising:
[0044] A first obtaining module is configured to obtain intrinsic radio frequency response fingerprint information of each antenna unit, the intrinsic radio frequency response fingerprint information being obtained by excitation testing of each antenna unit before deployment of the multi-antenna industrial control network or in a security calibration phase;
[0045] a second obtaining module, configured to obtain real-time radio frequency response information of each antenna unit during operation of the multi-antenna industrial control network;
[0046] a tampering analysis module, configured to analyze deviation of response parameters of each antenna unit according to the inherent radio frequency response fingerprint information and the real-time radio frequency response information, so as to determine whether each antenna unit is tampered with;
[0047] a tampering processing module, configured to trigger a security warning for the tampered antenna unit, and take isolation or degradation processing.
[0048] As can be seen from the above, the data security transmission method and system provided by the present application, wherein the method of the present application establishes the inherent radio frequency characteristics of the antenna unit as a benchmark, and continuously monitors the real-time response thereof, analyzes the deviation between the two, thereby identifying the slight radio frequency characteristic changes caused by tampering, overcoming the limitations of the existing adaptive algorithm that absorbs tampering-induced errors, achieving detection of physical tampering, and ensuring the confidentiality and integrity of data transmission in the multi-antenna industrial control network. BRIEF DESCRIPTION OF DRAWINGS
[0049] Figure 1 The flowchart of the data security transmission method provided by the embodiment of the present application.
[0050] Figure 2 The structural schematic diagram of the data security transmission system provided by the embodiment of the present application.
[0051] The accompanying drawings: 201, first obtaining module; 202, second obtaining module; 203, tampering analysis module; 204, tampering processing module. DETAILED DESCRIPTION
[0052] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the accompanying drawings of the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all the embodiments. The components of the embodiments of the present application described and shown in the accompanying drawings can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the accompanying drawings is not intended to limit the scope of the claimed present application, but only represents selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present application.
[0053] It should be noted that like reference numerals and characters refer to like elements throughout the following description with like reference numerals and characters referring to like elements throughout the following description and across different drawings indicated to be reference numerals and characters in the drawings and like elements have legal effect only within the context of that drawing and throughout the description so that once a elements is defined in one drawing it does not need to be further defined and explained in subsequent drawings. Also, in the description of the application, the terms "first", "second", and so on merely identify different stages of the process and are not to be interpreted as indicating or implying relative importance.
[0054] In a first aspect, referring to Figure 1 Some embodiments of the present application provide a data security transmission method applied to a multi-antenna industrial control network, the multi-antenna industrial control network comprising a plurality of antenna units, the method comprising the following steps:
[0055] S1, obtaining inherent radio frequency response fingerprint information of each antenna unit, the inherent radio frequency response fingerprint information being obtained by stimulating and testing each antenna unit before deployment of the multi-antenna industrial control network or in a security calibration phase;
[0056] S2, obtaining real-time radio frequency response information of each antenna unit during operation of the multi-antenna industrial control network;
[0057] S3, analyzing deviation of response parameters of each antenna unit according to the inherent radio frequency response fingerprint information and the real-time radio frequency response information, to determine whether each antenna unit is tampered with;
[0058] S4, triggering a security warning information for the tampered antenna unit, and taking a security processing.
[0059] Specifically, the inherent radio frequency response fingerprint information refers to the radio frequency characteristics of the antenna unit under a known safe state, which can be obtained by stimulating and testing each antenna unit before deployment of the multi-antenna industrial control network or in a security calibration phase, to establish a benchmark for each antenna unit, for subsequent identification of physical tampering by comparing current operation data.
[0060] More specifically, the real-time radio frequency response information refers to the current radio frequency characteristics of each antenna unit during operation of the multi-antenna industrial control network, which can be obtained by active detection, i.e. injecting a test signal and measuring the response, or by analyzing the characteristics extracted from the ongoing communication signals, to reflect the operating state of the antenna unit, thereby realizing continuous monitoring and anomaly detection.
[0061] Specifically, the method of the present application first establishes a baseline for each antenna unit by obtaining the inherent radio frequency response fingerprint information of each antenna unit during a pre-deployment or security calibration phase of the multi-antenna industrial control network. The inherent radio frequency response fingerprint information represents the inherent, unaltered radio frequency characteristics of the antenna unit and is stored in a secure storage module of the network. During network operation, the system continuously obtains real-time radio frequency response information of each antenna unit. Subsequently, the system analyzes the deviation of the response parameters related to the radio frequency characteristics of each antenna unit based on the inherent radio frequency response fingerprint information and the real-time radio frequency response information. This analysis aims to identify any differences between the real-time response and the baseline fingerprint, which can employ statistical methods, pattern recognition algorithms, or direct comparison of radio frequency parameters to identify deviations indicative of tampering, thereby overcoming the limitations of existing adaptive algorithms that can absorb such changes without detection. Then, the system determines whether each antenna unit is tampered with based on the analysis results, which can be completed by comparing the calculated deviation with a preset threshold, evaluating statistical significance, or applying a rule-based reasoning engine. Once it is determined that the antenna unit is tampered with, the system triggers a security warning message and takes security handling measures to prevent further damage to data security and maintain the operational integrity of the industrial control network; wherein the security handling refers to implementing countermeasures to mitigate the impact of the detected tampering event, which can include isolating the affected antenna unit from the network, reconfiguring network parameters to bypass the affected unit, or starting a redundant communication system.
[0062] Through the above design, the method of the present application effectively solves the problem that after the antenna unit in the multi-antenna industrial control network is physically tampered with, its internal radio frequency characteristics or digital control logic change slightly and are difficult to detect, causing existing security mechanisms to be ineffective in detection, thereby affecting the confidentiality and integrity of data transmission. The method can detect even slight deviations caused by tampering by establishing a baseline of the inherent radio frequency characteristics of the antenna unit, overcoming the limitations of existing adaptive algorithms that can absorb such changes, thereby ensuring the identification of hidden threats to data transmission security; timely detection and subsequent security handling in the method prevent further damage to sensitive industrial control data, maintaining the reliability and integrity of network operation.
[0063] In summary, the method of the present application establishes a baseline of the inherent radio frequency characteristics of the antenna unit and continuously monitors its real-time response to analyze the deviation between the two, thereby identifying slight changes in radio frequency characteristics caused by tampering, overcoming the limitations of existing adaptive algorithms that absorb errors introduced by tampering, achieving detection of physical tampering, and ensuring the confidentiality and integrity of data transmission in the multi-antenna industrial control network.
[0064] In some preferred embodiments, the step of performing excitation test on each antenna unit during the pre-deployment or security calibration phase of the multi-antenna industrial control network comprises:
[0065] A1. During the pre-deployment or security calibration phase of the multi-antenna industrial control network, measure the radio frequency response parameters of each antenna unit under different excitation conditions as the inherent radio frequency response fingerprint information of the corresponding antenna unit, and store it in the secure storage module of the multi-antenna industrial control network.
[0066] Specifically, the excitation condition refers to the external signal applied to the antenna unit, which can include frequency, power level, modulation mode, polarization mode, or incident angle, etc. The radio frequency response parameter refers to the electromagnetic characteristic index exhibited by the antenna unit under a specific excitation condition, which can include amplitude response, phase response, harmonic component, intermodulation distortion, return loss, or voltage standing wave ratio, etc.
[0067] Specifically, during the pre-deployment or security calibration phase of the multi-antenna industrial control network, the system performs excitation test on each antenna unit. The key of this test is that it is not limited to a single or limited excitation condition, but systematically measures the radio frequency response parameters of the antenna unit under multiple excitation conditions. For example, the frequency, power level, or modulation mode of the excitation signal can be changed to fully stimulate the radio frequency characteristics of the antenna unit. Through such multi-condition measurement, the system can capture the subtle radio frequency behavior of the antenna unit under various potential working states, including nonlinear response or deviation that may only appear under certain conditions. These multi-dimensional radio frequency response parameters are collected and serve as the inherent radio frequency response fingerprint information of the antenna unit. Subsequently, these fingerprint information is securely stored in the secure storage module of the multi-antenna industrial control network to prevent it from being tampered with or stolen. During the operation of the multi-antenna industrial control network, the system periodically obtains the real-time radio frequency response information of each antenna unit. These real-time information are then compared with the pre-stored inherent radio frequency response fingerprint information. Since the inherent fingerprint information is obtained under multiple excitation conditions, it contains more abundant and detailed original radio frequency characteristics of the antenna unit. Therefore, during the comparison process, even a small nonlinear error or deviation introduced by physical tampering can be effectively identified and distinguished from normal system fluctuations, environmental influences, or compensation behavior of adaptive algorithms. This fingerprint information obtained based on multi-condition excitation test enables the system to establish a high-resolution benchmark, thereby improving the detection capability of hidden tampering and reducing the occurrence of false negatives and false positives.
[0068] Through the above design, the method of the application can obtain the radio frequency characteristics of the antenna unit under multiple working conditions. The measurement under multiple conditions enables the obtained intrinsic radio frequency response fingerprint information to capture the radio frequency characteristics of the antenna unit, form a high-resolution reference, thereby improving the accuracy of tamper detection, avoiding missed reports (failure to find actual tampering) or false reports (mistaking normal changes as tampering), and thereby enhancing the overall protection capability of data security transmission.
[0069] In some preferred embodiments, before the deployment of the multi-antenna industrial control network or in the security calibration phase, the step of measuring the radio frequency response parameters of each antenna unit under different excitation conditions includes:
[0070] A11. Before the deployment of the multi-antenna industrial control network or in the security calibration phase, multiple rounds of radio frequency response parameter measurements are performed on each antenna unit based on a preset test excitation signal sequence representing different excitation conditions, and multiple sets of original radio frequency response parameters are obtained, and environmental parameters are measured and obtained at the same time;
[0071] A12. Based on the environmental parameters, the original radio frequency response parameters are compensated for environmental impact and consistency verification to obtain the radio frequency response parameters of each antenna unit under different excitation conditions.
[0072] Specifically, the multiple-round measurement of step A11 is used to capture random fluctuations and transient noise in the measurement process, providing a statistical basis for subsequent data processing, thereby improving the reliability of the raw data. The multiple sets of raw radio frequency response parameters refer to the unprocessed radio frequency response data sets containing raw measurement values and potential errors obtained through multiple-round measurement. The test excitation signal sequence includes excitation signals covering multiple discrete frequency points in the working frequency band of the multi-antenna industrial control network and multiple power levels corresponding to each frequency point, which is a preset signal set for exciting the antenna unit and obtaining its radio frequency response. It can be achieved by using a vector network analyzer or a signal generator to generate a series of radio frequency signals with specific frequencies and powers, and applying them to the antenna unit in a predetermined order. The purpose is to fully characterize the radio frequency characteristics of the antenna unit under different working conditions and form a multi-dimensional, high-resolution radio frequency fingerprint. The environmental influence compensation can be achieved by correcting the raw data based on a pre-established environmental-radio frequency characteristic relationship model (for example, through regression analysis, lookup table or neural network model), which is used to ensure that the obtained radio frequency response parameters reflect the inherent characteristics of the antenna unit, rather than the deviation caused by environmental fluctuations. The consistency check refers to analyzing the multiple sets of radio frequency response parameters after environmental compensation to identify and process abnormal values or inconsistencies in the data. It can be achieved by using statistical methods (for example, calculating mean, standard deviation, median, quartile range, etc., and setting threshold to identify outliers), or machine learning-based anomaly detection algorithms to identify and exclude abnormal data, and then aggregate the remaining data (for example, taking average, weighted average or median) for processing, which is used to improve the accuracy and reliability of the final radio frequency response parameters.
[0073] Specifically, step A11 lays the foundation for obtaining high-quality original radio frequency response data through multiple rounds of multi-dimensional and simultaneous environmental parameter measurement. Based on the preset test excitation signal sequence representing different excitation conditions, multiple rounds of radio frequency response parameter measurement are performed on each antenna unit, and multiple sets of original radio frequency response parameters are obtained, which overcomes the random errors and transient fluctuations that may exist in single measurement. Through multiple rounds of measurement, more abundant data samples can be collected, providing a statistical basis for subsequent data processing and verification, thereby improving the reliability of the original data. Since the radio frequency characteristics of the antenna unit can be slightly affected by environmental factors such as temperature and humidity, synchronous recording of environmental parameters enables subsequent targeted environmental impact compensation, ensuring that the obtained fingerprint information is the inherent characteristics of the antenna unit itself, rather than deviations caused by environmental factors. The test excitation signal sequence includes multiple discrete frequency points covering the working frequency band of the multi-antenna industrial control network and multiple power levels corresponding to each frequency point, ensuring comprehensive characterization of the radio frequency characteristics of the antenna unit. By performing excitation testing at a wide frequency band and multiple power levels, subtle responses of the antenna under different working conditions can be captured, forming a multi-dimensional, high-resolution radio frequency fingerprint. Step A12 refines the original data obtained in step A11, eliminates environmental impact, and ensures data consistency, ultimately obtaining highly reliable inherent radio frequency response fingerprint information. Based on the environmental parameters, the original radio frequency response parameters are compensated for environmental impact, adjusting the original radio frequency response parameters to equivalent values under a standard environmental condition, thereby effectively eliminating the impact of environmental fluctuations on radio frequency characteristics during measurement, ensuring that the obtained radio frequency response parameters truly reflect the inherent properties of the antenna unit, rather than the transient state of the measurement environment, making the fingerprint information more stable and accurate. Consistency verification can identify and eliminate abnormal data points or inconsistent measurement results by statistically analyzing and verifying the multiple sets of radio frequency response parameters after environmental compensation. For example, statistical characteristics (such as mean and variance) of the data can be calculated, and based on a pre-set deviation threshold, it can be determined which data points deviate too much, thereby eliminating them. The remaining radio frequency response parameters after eliminating abnormal data are aggregated (such as averaging, weighted averaging, etc.), and the radio frequency response parameters of each antenna unit under different excitation conditions are finally obtained. This series of processing ensures that the final obtained radio frequency response parameters are highly reliable, accurate, and representative, which serve as the inherent radio frequency response fingerprint information of the antenna unit, providing a solid and unbiased benchmark for subsequent real-time monitoring and tamper judgment.
[0074] The method of the present application ensures that the obtained intrinsic radio frequency response fingerprint information accurately reflects the real intrinsic characteristics of the antenna unit, and eliminates the interference of environmental factors and measurement noise, by multiple rounds of measurement, environmental impact compensation and consistency verification. Through multiple discrete frequency points covering the working frequency band and multiple power level excitation signals, the radio frequency characteristics of the antenna unit under different working conditions are comprehensively characterized, forming a high-resolution, multi-dimensional radio frequency fingerprint. Thus, when real-time radio frequency response information is obtained during system operation and compared with this high-precision reference, subtle radio frequency characteristic changes caused by physical tampering can be more reliably identified, thereby effectively improving the ability of the entire data security transmission method to detect hidden tampering.
[0075] In some preferred embodiments, step A12 comprises:
[0076] A121, according to the environmental parameters, using a preset compensation relationship, compensating each of the multiple groups of original radio frequency response parameters for environmental impact to obtain multiple groups of environmentally calibrated radio frequency response parameters;
[0077] A122, consistency verification is performed on the multiple groups of environmentally calibrated radio frequency response parameters, and the consistency verification comprises:
[0078] statistical analysis is performed on the multiple groups of environmentally calibrated radio frequency response parameters, the statistical characteristics of each group of parameters are calculated, and according to the statistical characteristics and a preset deviation threshold, abnormal data in each group of radio frequency response parameters that deviates beyond the deviation threshold is identified and removed;
[0079] the remaining radio frequency response parameters after removing the abnormal data are aggregated to obtain the radio frequency response parameters of each antenna unit under different excitation conditions.
[0080] Specifically, the compensation relationship refers to a mathematical model or mapping rule previously established between environmental parameters (such as temperature, humidity) and radio frequency response parameters, which can be implemented using a lookup table, a polynomial regression model, a neural network model, or a correction formula based on a physical model. The statistical characteristics refer to quantitative indicators for describing the trend and dispersion degree of the data set, which can be implemented using mean, median, standard deviation, variance, quartile, or skewness coefficient. The deviation threshold refers to a preset limit for judging whether a data point is an outlier, which can be implemented using a multiple of standard deviation (such as the 3σ principle), a multiple of interquartile range (IQR), a percentile, or an empirical value. The deviation degree refers to the deviation degree of a single data point relative to the overall distribution of its data set, which can be implemented using the difference between the data point and the mean, the difference between the data point and the median, Z-score, or Mahalanobis distance. The aggregation processing refers to the process of combining multiple data points into a representative data point, which can be implemented using arithmetic mean, weighted mean, median, or mode.
[0081] Specifically, since the radio frequency response parameters are susceptible to environmental factors, directly using the raw data can introduce errors. Therefore, step A121 applies a pre-established compensation relationship to each set of raw radio frequency response parameters based on the measured environmental parameters for independent calibration. This compensation relationship is pre-trained and determined based on a large amount of experimental data or theoretical models, and can quantify the specific influence of environmental factors on radio frequency response parameters. In this way, the raw data under different measurement batches or different environmental conditions are calibrated to a consistent environmental reference, eliminating the interference of environmental factors, thereby obtaining multiple sets of environmentally calibrated radio frequency response parameters. This process ensures the environmental adaptability and comparability of the data, laying the foundation for subsequent accurate analysis. Then, step A122 performs consistency checking on these environmentally calibrated radio frequency response parameters. Although the data has been compensated for the environment, inconsistencies caused by measurement device errors, transient interference or occasional abnormalities may still exist in the data. Consistency checking first performs statistical analysis on each set of environmentally calibrated radio frequency response parameters, calculates the statistical characteristics of each set of data, such as mean and standard deviation, and then uses these statistical characteristics and combines with the pre-set deviation threshold to intelligently identify and eliminate abnormal data points whose deviation exceeds the threshold. By accurately identifying and eliminating these abnormal data, the purity and reliability of the data set are significantly improved. Finally, the remaining radio frequency response parameters after eliminating abnormal data are aggregated. This aggregation process, such as calculating the average, can further smooth the random noise in the data and integrate the results of multiple measurements, thereby obtaining highly accurate and representative radio frequency response parameters of each antenna unit under different excitation conditions. These parameters constitute the inherent radio frequency response fingerprint information of the antenna unit.
[0082] The present scheme solves the problem of original radio frequency response parameters being affected by environmental interference and abnormal data through the combination of environmental influence compensation and consistency checking. Environmental compensation ensures the comparability of data under different environments, while consistency checking further purifies the data and eliminates noise and outliers. This two-stage processing flow makes the final obtained inherent radio frequency response fingerprint information have high precision and high reliability. These accurate fingerprint information as a reference can significantly improve the accuracy of subsequent judgment of whether the antenna unit is tampered with during network operation, thereby effectively dealing with the hidden tampering attacks mentioned in the background technology and ensuring the secure transmission of data in the multi-antenna industrial control network.
[0083] In some preferred embodiments, step S2 comprises:
[0084] S21, during the operation of the multi-antenna industrial control network, periodically collecting real-time radio frequency response information of each antenna unit, the collection process comprising:
[0085] measure radio frequency response parameters of each antenna unit based on preset test excitation signals, and collect radio frequency response data of each antenna unit under corresponding excitation conditions;
[0086] measure radio frequency response parameters of each antenna unit based on preset test excitation signals, and collect radio frequency response data of each antenna unit under corresponding excitation conditions;
[0087] Alternatively, the latest communication signals of each antenna unit are obtained, and real-time radio frequency response information of each antenna unit is extracted according to the latest communication signals.
[0088] Specifically, during the operation of the multi-antenna industrial control network, the acquisition of real-time radio frequency response information can adopt two main paths. The first path is periodic acquisition based on active excitation testing. The system periodically sends preset test excitation signals to each antenna unit and measures the response of the antenna unit to these signals. In order to improve the accuracy and robustness of the data, further, the system measures the radio frequency response parameters of each antenna unit based on a preset test excitation signal sequence representing different excitation conditions, thereby obtaining multiple sets of original real-time radio frequency response parameters. During the measurement process, the system synchronously acquires real-time environmental parameters. This is because environmental factors can affect radio frequency characteristics. Subsequently, the system compensates for the environmental impact on the original real-time radio frequency response parameters based on these real-time environmental parameters, to eliminate the interference of environmental factors on the measurement results and ensure that the data reflects the characteristics of the antenna unit itself. Then, the consistency of the data after environmental compensation is verified to identify and eliminate abnormal data or noise in the measurement process, thereby ensuring that the real-time radio frequency response parameters used for judgment are reliable and uniform. This active testing method can accurately obtain antenna characteristics under controllable conditions, which helps to identify small deviations, so that the real-time radio frequency response parameters obtained after environmental impact compensation and consistency verification can be compared and analyzed with the inherent radio frequency response fingerprint information. The second path is real-time extraction based on passive communication signals. The system obtains the latest communication signals of each antenna unit, and then extracts the real-time radio frequency response information of each antenna unit according to these communication signals. This method uses the signals generated by the antenna unit in the normal business communication process, without additional excitation testing, and has the advantages of not interfering with normal operation and being able to be performed in real time. By extracting radio frequency response information from actual communication signals, the performance of the antenna under actual working load can be reflected, which can be used as a supplement or replacement for active excitation testing, and is especially suitable for scenarios where it is inconvenient to interrupt normal communication for testing.
[0089] The real-time radio frequency response information acquisition mechanism of the scheme is closely combined with the overall data security transmission method. In the overall method, the inherent radio frequency response fingerprint information is obtained before deployment or in the security calibration phase, and is also subjected to environmental influence compensation and consistency verification. Therefore, in the scheme, the real-time radio frequency response information is subjected to the same environmental influence compensation and consistency verification, ensuring the consistency of the real-time data and the inherent fingerprint information at the data processing level, so that the subsequent deviation analysis and tampering judgment can be based on standardized and comparable data, thereby significantly improving the accuracy and sensitivity of the judgment. The periodic acquisition setting ensures uninterrupted monitoring of the antenna state, enabling the system to timely discover possible tampering behavior. The selection of the two acquisition paths provides flexibility for the system, enabling it to continuously acquire high-quality real-time data under different operating conditions, thereby enhancing the robustness of the overall tampering detection scheme. This real-time, accurate and adaptive data acquisition method is the key to solving the problem of difficult detection of small and difficult-to-detect tampering behavior in the prior art.
[0090] In some preferred embodiments, the radio frequency response parameters include multiple types of amplitude response, phase response, harmonic component, and intermodulation distortion.
[0091] Specifically, the amplitude response refers to the change in the output signal amplitude caused by the change in the input radio frequency signal amplitude of the antenna unit, which can be realized by measuring the antenna gain, insertion loss or return loss, etc. The amplitude response can reflect the linear characteristics of the antenna in terms of signal transmission efficiency.
[0092] More specifically, the phase response refers to the change in the output signal phase caused by the change in the input radio frequency signal phase of the antenna unit, which can be realized by measuring the phase shift or group delay when the signal passes through the antenna, etc. The phase response can reflect the linear characteristics of the antenna in terms of signal transmission delay.
[0093] More specifically, the harmonic component refers to the signal with a frequency that is an integer multiple of the base frequency generated when the radio frequency signal passes through the nonlinear circuit inside the antenna unit, in addition to the original base frequency signal. It can be realized by measuring the frequency spectrum of the output signal using a spectrum analyzer, identifying and quantifying the energy at the integer multiple frequencies of the base frequency signal. The harmonic component can serve as an important basis for detecting changes in the nonlinear characteristics of the antenna unit.
[0094] More specifically, the intermodulation distortion refers to the new frequency component generated due to the interaction between two or more radio frequency signals of different frequencies when they are simultaneously input into the nonlinear circuit inside the antenna unit. It can be realized by inputting a multi-tone signal into the antenna unit and then measuring the non-input frequency combination frequency components in the output signal using a spectrum analyzer. The intermodulation distortion can reflect the nonlinear behavior of the antenna unit in a multi-signal environment, and is helpful in identifying subtle changes in radio frequency characteristics caused by tampering.
[0095] By combining linear parameters such as amplitude response, phase response, etc. with nonlinear parameters such as harmonic components, intermodulation distortion, etc., the method of the present application can construct a multi-dimensional RF characteristic fingerprint. This multi-dimensional dataset enables the system to sensitively capture hidden tampering behaviors that are difficult to be discovered by traditional detection means, such as those that only introduce minor nonlinear errors or deviations.
[0096] In some preferred embodiments, step S3 comprises:
[0097] S31, calculating multi-dimensional parameter deviations of each antenna unit under different excitation conditions according to the inherent RF response fingerprint information and the real-time RF response information;
[0098] S32, generating a comparison result according to the multi-dimensional parameter deviations and a preset security threshold;
[0099] S33, judging whether the corresponding antenna unit is tampered with according to the comparison result.
[0100] Specifically, the multi-dimensional parameter deviation refers to the difference between the real-time RF response information and the inherent RF response fingerprint information of the antenna unit in multiple RF characteristic parameter dimensions, which can be realized by combining multiple parameters such as amplitude response deviation, phase response deviation, harmonic component deviation, and intermodulation distortion deviation, etc. to capture subtle tampering signs that may not be obvious in a single dimension. The preset security threshold refers to a quantitative standard for distinguishing between normal fluctuations and malicious tampering, which can be realized by a fixed value or a dynamically adjusted range based on historical data analysis, statistical methods or expert experience. This threshold can tolerate minor deviations caused by normal environmental changes or device aging, while identifying abnormal deviations beyond the normal range.
[0101] Specifically, first, step S31 can capture any deviation of the antenna unit's radio frequency characteristics by comparing the real-time information with the reference fingerprint. Calculating multi-dimensional parameter deviations means that the detection is not limited to a single radio frequency parameter, but considers multiple dimensions such as amplitude, phase, harmonics, and intermodulation distortion, which allows even non-linear errors or deviations introduced in a specific dimension to be discovered. In addition, deviation calculation under different excitation conditions ensures the comprehensiveness of the detection and avoids missing detection caused by tampering behavior only appearing at a specific operating frequency or power level. Second, step S32 compares the calculated multi-dimensional parameter deviations with the preset safety threshold to generate a comparison result. This preset safety threshold is a quantitative standard for distinguishing normal fluctuations from malicious tampering. It allows the system to filter out small, acceptable deviations caused by environmental changes, device aging, or normal operation, thereby avoiding false positives. At the same time, the system can identify abnormal deviations that exceed the safety range. Generating a comparison result provides a quantitative basis for subsequent judgment, making the tampering judgment process more objective and automated. Finally, step S33 judges whether the corresponding antenna unit has been tampered with according to the generated comparison result. This judgment is based on multi-dimensional, multi-excitation condition deviation calculation and strict comparison with the preset safety threshold. In this way, the present scheme can make accurate and reliable tampering judgments, effectively distinguishing between small fluctuations in normal operation and subtle but critical deviations introduced by malicious tampering. Through this detailed detection, the system can timely discover potential damage to data transmission confidentiality or integrity, ensuring the data security of industrial control networks. This combination allows the system to identify hidden physical tampering earlier and more accurately, avoiding the missed detection caused by the compensation of traditional methods through adaptive algorithms, thereby improving the security protection capability of the entire multi-antenna industrial control network.
[0102] In some preferred embodiments, step S32 includes:
[0103] S321, calculating a comprehensive deviation index according to the multi-dimensional parameter deviations and combining the preset weights of each dimension parameter;
[0104] S322, obtaining the aging information of each antenna unit, compensating the preset safety threshold according to the aging information, and generating a comprehensive safety threshold;
[0105] S323, comparing the comprehensive deviation index with the comprehensive safety threshold to generate a comparison result.
[0106] Specifically, the preset dimension parameter weight refers to the relative importance value given to the deviation of different radio frequency characteristic parameters, which can be determined by expert experience setting, historical data analysis or machine learning algorithm training, etc. The comprehensive deviation index refers to a single value that quantifies the degree of coordinated deviation of multiple dimension parameters, which can be calculated by weighted summation, multivariate statistical distance or machine learning-based anomaly score, etc. The aging information refers to the data reflecting the trend or state of the natural change of the antenna unit's radio frequency characteristics in the long-term running process, which can be obtained by running time, cumulative usage time, environmental exposure history or periodic performance test data, etc. The comprehensive security threshold refers to the judgment benchmark dynamically adjusted according to the aging information of the antenna unit, which can be generated by compensation based on aging model, lookup table method or adaptive algorithm adjustment, etc.
[0107] Specifically, step S321 calculates a comprehensive deviation index according to the multi-dimensional parameter deviation, combined with the preset dimension parameter weight. This comprehensive deviation index can represent the coordinated deviation degree of multiple dimension parameters, which means it not only considers the deviation of a single parameter, but also considers the overall pattern produced by the interaction between different parameters, so as to capture the subtle deviation caused by the tampering behavior mentioned in the background technology that is difficult to detect. Then, step S322 obtains the aging information of each antenna unit, and compensates the preset security threshold according to these aging information, to generate a comprehensive security threshold. This comprehensive security threshold is dynamically adjusted, which can adapt to the change of radio frequency characteristics of the antenna unit over time, avoid judging aging as tampering, thereby reducing false positives, while maintaining the detection ability of real tampering behavior, ensuring that the system can still judge the tampering state of the antenna unit in the long-term running. Finally, step S323 compares the calculated comprehensive deviation index with the comprehensive security threshold, to generate a comparison result. This comparison result can indicate the radio frequency characteristic deviation state of the antenna unit. In this way, the present scheme combines the evaluation of multi-dimensional coordinated deviation with the dynamic adaptation to the natural aging of the antenna unit, so that the final judgment result is reliable. This dynamic and comprehensive comparison method can identify whether the antenna unit is tampered with and indicate its radio frequency characteristic deviation state, thereby providing a basis for subsequent security processing. This judgment mechanism combining multi-dimensional coordinated deviation evaluation and aging compensation improves the system's ability to judge the tampering behavior of the antenna unit in the industrial environment, solves the limitations of the simple comparison method in the prior art and the problem of not adapting to the natural aging of the antenna unit, thereby enhancing the data security transmission capability of the multi-antenna industrial control network.
[0108] In some preferred embodiments, in step S4, the security processing step includes:
[0109] S41, obtaining identification information of the tampered antenna unit and a multi-dimensional parameter deviation determined based on the inherent radio frequency response fingerprint information and the real-time radio frequency response information;
[0110] S42, analyzing the multi-dimensional parameter deviation to obtain a tampering type;
[0111] S43, generating an impact assessment result based on the identification information, the tampering type, and a preset service priority;
[0112] S44, selecting a security response strategy from a preset security response strategy set according to the impact assessment result, the security response strategy including one or more of complete isolation, weight reduction, switching to a backup antenna unit, and starting a redundant communication mechanism.
[0113] Specifically, the multi-dimensional parameter deviation can be obtained by step S31.
[0114] More specifically, the tampering type refers to the specific classification of unauthorized modification behavior on the antenna unit. It can be represented by specific types such as "signal injection", "parameter drift", "function hijacking", and "physical damage" identified based on the multi-dimensional parameter deviation mode. Identifying the tampering type helps to judge the potential harm and is the key to selecting the appropriate response strategy. The service priority refers to the importance ranking of different service processes or data transmission tasks for network operation stability and security in a multi-antenna industrial control network. It can be divided into preset levels, such as "critical service", "important service", "general service", etc., or represented by numerical weights. The introduction of service priority ensures that the system can prioritize the protection of services critical to the operation of the industrial control network when responding to security. The impact assessment result refers to the quantitative or categorical description of the potential risks and impact levels that the tampering behavior may cause to the multi-antenna industrial control network after considering the identification information of the tampered antenna unit, the tampering type, and the preset service priority. It can be represented in the form of risk level (e.g., "high risk", "medium risk", "low risk"), impact range (e.g., "local impact", "systematic impact"), or specific loss estimate (e.g., "communication interruption risk", "data leakage risk"). The security response strategy set refers to a series of pre-defined combinations of measures to respond to antenna unit tampering events.
[0115] Specifically, when the system determines that a certain antenna unit is tampered according to the inherent radio frequency response fingerprint information and the real-time radio frequency response information, a security warning is triggered. Subsequently, the system obtains the identification information of the tampered antenna unit, which enables the system to determine which specific antenna unit has a problem, and obtains multi-dimensional parameter deviations, and then identifies the specific tampering type by in-depth analysis of these multi-dimensional parameter deviations. Different tampering behaviors will exhibit different characteristic patterns on the radio frequency response parameters. By analyzing these deviation patterns, the system can convert the abstract parameter deviation into an understandable tampering type. On this basis, the system evaluates the influence degree of the tampered antenna unit on the multi-antenna industrial control network based on the identification information of the tampered antenna unit, the identified tampering type, and the preset business priority, and generates an influence evaluation result. The identification information helps to determine the topological position of the antenna unit in the network and the type of key services it carries; the tampering type determines the specific harm that may be caused; and the business priority ensures that the system prioritizes the protection of services that are essential to the operation of the industrial control network. By comprehensively considering these three aspects of information, the system can generate a comprehensive influence evaluation result, quantifying or classifying the potential risks posed by tampering to network security and business continuity. Finally, the system selects the most appropriate security response strategy from a preset set of security response strategies based on the generated influence evaluation result. This strategy set includes a variety of flexible response measures, such as complete isolation, weight reduction, switching to a backup antenna unit, or starting a redundant communication mechanism. For example, for tampering with a high-risk influence evaluation result and involving key services, the system may choose complete isolation or switching to a backup antenna unit to quickly limit losses; while for tampering with a low-risk influence evaluation result and having a minor impact on non-critical services, the system may choose to reduce the weight or start a redundant communication mechanism to minimize the impact on normal services while ensuring safety. This dynamic strategy selection based on the influence evaluation result ensures the accuracy, efficiency, and flexibility of the security response, thereby maximizing the availability and business continuity of the system while ensuring the security of the industrial control network, effectively avoiding the problems of over-response or insufficient response, achieving fine, efficient, and appropriate security response, and significantly improving the security and stability of the industrial control network.
[0116] In some preferred embodiments, step S43 comprises:
[0117] S431, according to the identification information, obtaining the network topological position information of the tampered antenna unit in the multi-antenna industrial control network and the associated key service type;
[0118] S432, according to the tampering type, querying a preset tampering influence weight table to obtain the influence weight of the tampering type on different key services;
[0119] S433, combine network topology location information, associated key service type, tampering influence weight and preset service priority, calculate the influence degree of the tampered antenna unit on the multi-antenna industrial control network, and generate an influence evaluation result.
[0120] Specifically, the network topology location information refers to a specific position description of the antenna unit in the multi-antenna industrial control network structure, which can be realized by physical coordinates, logical levels, connection ports or regional identifiers. The associated key service type refers to the industrial control service category directly related to or affected by the normal operation of the antenna unit. The tampering influence weight table refers to a pre-configured data structure for storing the quantitative values of the influence degree of different tampering types on various key services, which can be realized by a two-dimensional lookup table, a database or a rule set.
[0121] Specifically, through the identification information, the system can obtain the specific topological position of the tampered antenna unit in the network and its associated key service types. By obtaining the network topological position information, the importance of the antenna unit in the network structure can be determined; by obtaining the associated key service types, it can directly identify which core services may be affected. Secondly, according to the identified tampering type, the system queries the preset tampering influence weight table to obtain the influence weight of the tampering type on different key services, realizing the quantitative evaluation of the influence degree of different tampering types. Not all tampering has the same harmfulness, for example, a slight radio frequency characteristic deviation and a serious signal leakage may cause different degrees of damage to the service. This mechanism of querying the influence weight according to the tampering type enables the evaluation process to distinguish the harm level of different tampering behaviors, avoiding the "one-size-fits-all" evaluation method, thereby improving the accuracy and fineness of the evaluation. Finally, the system combines the network topological position information, the associated key service types, the tampering influence weight, and the preset service priority to calculate the influence degree of the tampered antenna unit on the multi-antenna industrial control network and generate the influence evaluation result. This step comprehensively considers the key information obtained in the foregoing steps to form a comprehensive influence evaluation model. By combining the network position of the antenna unit and the associated key service types, the affected range and importance can be determined; by combining the tampering influence weight, the harm degree of the specific tampering behavior can be quantified; and by combining the preset service priority, the importance difference of different services in the industrial control network can be reflected. This multi-dimensional information fusion mechanism enables the finally generated influence evaluation result to comprehensively and accurately reflect the actual harm that the tampered antenna unit may cause to the entire industrial control network, thereby providing solid data support for the system to adopt targeted and efficient security response strategies. Through this refined influence evaluation, the overall data security transmission method can more accurately judge the actual influence of the tampered antenna unit on the network operation and key services after discovering that the antenna unit is tampered, and then select a more appropriate security response strategy, significantly improving the effectiveness and robustness of the system in response to covert tampering attacks.
[0122] In a second aspect, referring to Figure 2 Some embodiments of the present application also provide a data security transmission system applied to a multi-antenna industrial control network, the multi-antenna industrial control network comprising a plurality of antenna units, the system comprising:
[0123] A first acquisition module 201 is configured to acquire inherent radio frequency response fingerprint information of each antenna unit, the inherent radio frequency response fingerprint information being obtained by exciting and testing each antenna unit before deployment of the multi-antenna industrial control network or in a security calibration phase;
[0124] The second acquisition module 202 is configured to acquire real-time radio frequency response information of each antenna unit during operation of the multi-antenna industrial control network.
[0125] The tampering analysis module 203 is configured to analyze deviation of response parameters of each antenna unit according to the inherent radio frequency response fingerprint information and the real-time radio frequency response information, so as to determine whether each antenna unit is tampered with.
[0126] The tampering processing module 204 is configured to trigger a security warning for the tampered antenna unit, and take isolation or degradation processing.
[0127] The system of the present application establishes the inherent radio frequency characteristic benchmark of the antenna unit, and continuously monitors the real-time response, analyzes the deviation between the two, thereby identifying the slight radio frequency characteristic change caused by tampering, overcoming the limitation of absorbing tampering-induced errors by the existing adaptive algorithm, realizing detection of physical tampering, and ensuring the confidentiality and integrity of data transmission in the multi-antenna industrial control network.
[0128] In addition, the units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, i.e., they can be located in one place, or distributed to multiple network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the present embodiment.
[0129] Furthermore, the functional modules in each embodiment of the present application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.
[0130] In this paper, the relationship terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between the entities or operations.
[0131] The above is only an embodiment of the present application and is not used to limit the protection scope of the present application. For those skilled in the art, the present application can have various modifications and changes. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.
Claims
1. A data security transmission method applied to a multi-antenna industrial control network, wherein the multi-antenna industrial control network comprises multiple antenna elements, characterized in that, The method includes the following steps: S1. Obtain the inherent radio frequency response fingerprint information of each antenna element. The inherent radio frequency response fingerprint information is obtained by performing excitation tests on each antenna element before the deployment of the multi-antenna industrial control network or during the security calibration phase. S2. During the operation of the multi-antenna industrial control network, acquire the real-time radio frequency response information of each antenna unit; S3. Based on the inherent radio frequency response fingerprint information and the real-time radio frequency response information, analyze the deviation of the response parameters of each antenna element to determine whether each antenna element has been tampered with. S4. Trigger a security warning message for the tampered antenna unit and take security measures. The step of performing excitation testing on each antenna element before deployment of the multi-antenna industrial control network or during the safety calibration phase includes: A1. Before the deployment of the multi-antenna industrial control network or during the security calibration phase, measure the radio frequency response parameters of each antenna unit under different excitation conditions, use them as the inherent radio frequency response fingerprint information of the corresponding antenna unit, and store them in the secure storage module of the multi-antenna industrial control network; The step of measuring the radio frequency response parameters of each antenna element under different excitation conditions before the deployment of the multi-antenna industrial control network or during the security calibration phase includes: A11. Before the deployment of the multi-antenna industrial control network or during the safety calibration phase, multiple rounds of radio frequency response parameter measurements are performed on each antenna unit based on a preset test excitation signal sequence representing different excitation conditions to obtain multiple sets of original radio frequency response parameters, while simultaneously measuring and acquiring environmental parameters. A12. Based on the environmental parameters, perform environmental impact compensation and consistency verification on the original radio frequency response parameters to obtain the radio frequency response parameters of each antenna element under different excitation conditions. Step A12 includes: A121. Based on the environmental parameters, using a preset compensation relationship, environmental impact compensation is performed on each of the multiple sets of original radio frequency response parameters to obtain multiple sets of environmentally calibrated radio frequency response parameters. A122. Perform a consistency check on the multiple sets of environmentally calibrated RF response parameters, the consistency check including: Statistical analysis is performed on the multiple sets of environmentally calibrated radio frequency response parameters to calculate the statistical characteristics of each set of parameters. Based on the statistical characteristics and a preset deviation threshold, abnormal data in each set of radio frequency response parameters that deviate from the deviation threshold are identified and removed. The remaining RF response parameters after removing outlier data are aggregated to obtain the RF response parameters of each antenna element under different excitation conditions.
2. The data secure transmission method according to claim 1, characterized in that, Step S2 includes: S21. During the operation of the multi-antenna industrial control network, real-time radio frequency response information of each antenna element is periodically collected. The collection process includes: Based on the preset test excitation signal, the radio frequency response parameters of each antenna element are measured, and the radio frequency response data of each antenna element under the corresponding excitation conditions are collected. Based on a preset test excitation signal sequence representing different excitation conditions, multiple rounds of real-time RF response parameter measurements are performed on each antenna element to obtain multiple sets of raw real-time RF response parameters. Simultaneously, real-time environmental parameters are acquired. Then, based on the real-time environmental parameters, environmental impact compensation and consistency verification are performed on the raw real-time RF response parameters to obtain the real-time RF response parameters of each antenna element under different excitation conditions. or, The latest communication signal of each antenna element is acquired, and then the real-time radio frequency response information of each antenna element is extracted based on the latest communication signal.
3. The data secure transmission method according to claim 1, characterized in that, The radio frequency response parameters include multiple parameters such as amplitude response, phase response, harmonic components, and intermodulation distortion.
4. The data secure transmission method according to claim 1, characterized in that, Step S3 includes: S31. Calculate the multi-dimensional parameter deviation of each antenna element under different excitation conditions based on the inherent radio frequency response fingerprint information and the real-time radio frequency response information. S32. Generate comparison results based on the multi-dimensional parameter deviations and preset safety thresholds; S33. Determine whether the corresponding antenna element has been tampered with based on the comparison results.
5. The data secure transmission method according to claim 4, characterized in that, Step S32 includes: S321. Calculate the comprehensive deviation index based on the multi-dimensional parameter deviations and the preset weights of each dimension parameter. S322. Obtain aging information of each antenna element, compensate for the preset safety threshold based on the aging information, and generate a comprehensive safety threshold. S323. Compare the comprehensive deviation index with the comprehensive safety threshold to generate the comparison result.
6. The data secure transmission method according to claim 1, characterized in that, In step S4, the step of taking security measures includes: S41. Obtain the identification information of the tampered antenna unit and the multi-dimensional parameter deviation calculated and determined based on the inherent radio frequency response fingerprint information and the real-time radio frequency response information; S42. Analyze the deviation of the multi-dimensional parameters to obtain the tampering type; S43. Generate an impact assessment result based on the identification information, tampering type, and preset business priority; S44. Based on the impact assessment results, select a security response strategy from a preset set of security response strategies. The security response strategy includes one or more of the following: complete isolation, weight reduction, switching to a backup antenna unit, and activating a redundant communication mechanism.
7. A data security transmission system applied to a multi-antenna industrial control network, wherein the multi-antenna industrial control network comprises multiple antenna elements, characterized in that, The system includes: The first acquisition module is used to acquire the inherent radio frequency response fingerprint information of each antenna element. The inherent radio frequency response fingerprint information is obtained by performing excitation tests on each antenna element before the deployment of the multi-antenna industrial control network or during the security calibration phase. The second acquisition module is used to acquire real-time radio frequency response information of each antenna unit during the operation of the multi-antenna industrial control network. The tampering analysis module is used to analyze the deviation of the response parameters of each antenna element based on the inherent radio frequency response fingerprint information and the real-time radio frequency response information, so as to determine whether each antenna element has been tampered with. The tampering handling module is used to trigger security warnings for tampered antenna units and take isolation or downgrade actions. The step of performing excitation testing on each antenna element before deployment of the multi-antenna industrial control network or during the safety calibration phase includes: A1. Before the deployment of the multi-antenna industrial control network or during the security calibration phase, measure the radio frequency response parameters of each antenna unit under different excitation conditions, use them as the inherent radio frequency response fingerprint information of the corresponding antenna unit, and store them in the secure storage module of the multi-antenna industrial control network; The step of measuring the radio frequency response parameters of each antenna element under different excitation conditions before the deployment of the multi-antenna industrial control network or during the security calibration phase includes: A11. Before the deployment of the multi-antenna industrial control network or during the safety calibration phase, multiple rounds of radio frequency response parameter measurements are performed on each antenna unit based on a preset test excitation signal sequence representing different excitation conditions to obtain multiple sets of original radio frequency response parameters, while simultaneously measuring and acquiring environmental parameters. A12. Based on the environmental parameters, perform environmental impact compensation and consistency verification on the original radio frequency response parameters to obtain the radio frequency response parameters of each antenna element under different excitation conditions. Step A12 includes: A121. Based on the environmental parameters, using a preset compensation relationship, environmental impact compensation is performed on each of the multiple sets of original radio frequency response parameters to obtain multiple sets of environmentally calibrated radio frequency response parameters. A122. Perform a consistency check on the multiple sets of environmentally calibrated RF response parameters, the consistency check including: Statistical analysis is performed on the multiple sets of environmentally calibrated radio frequency response parameters to calculate the statistical characteristics of each set of parameters. Based on the statistical characteristics and a preset deviation threshold, abnormal data in each set of radio frequency response parameters that deviate from the deviation threshold are identified and removed. The remaining RF response parameters after removing outlier data are aggregated to obtain the RF response parameters of each antenna element under different excitation conditions.
Citation Information
Patent Citations
Network information security monitoring system
CN120455091A
Method and apparatus for removing coupling between antennas in multi-antenna based wireless communication system
US20150036763A1