Bluetooth equipment illegal access hardware identification and dynamic blocking method and device

By collecting the steady-state current response waveform and RF IQ baseband signal of Bluetooth devices, multi-source training data is constructed, and cyclic-stable, highly stable, highly stable, highly stable, highly stable, highly stable features are extracted. Combined with attention and convolution modules, an adaptive neural network is constructed, which solves the problem of hardware clone identification of Bluetooth devices and realizes dynamic blocking.

CN121751176AActive Publication Date: 2026-03-27深圳市乾海芯联科技有限公司 +1
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-03-02
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

Existing Bluetooth security mechanisms rely on a single signal source, lack cross-physical domain hardware feature fusion, making it difficult to identify hardware clones and counterfeit devices, and lacking dynamic defense capabilities.

Method used

By acquiring steady-state current response waveforms and RF IQ baseband signals, a multi-source training dataset is constructed. Cyclic stationary features and joint time-frequency-cyclic features are extracted. Combined with channel attention, spatial attention, bi-branch convolution modules, and protocol-aware feature modulators, an adaptive neural network is constructed to perform hardware recognition and dynamic blocking.

Benefits of technology

It enables multi-dimensional hardware fingerprint recognition of Bluetooth devices, enhances the ability to identify hardware clones and counterfeit devices, and forms an end-to-end proactive defense system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121751176A_ABST
    Figure CN121751176A_ABST
Patent Text Reader

Abstract

The invention discloses a Bluetooth device illegal access hardware identification and dynamic blocking method and device, and relates to the technical field of artificial intelligence, and the method comprises the steps: synchronously collecting a steady-state current response waveform and a radio frequency IQ baseband signal of a Bluetooth device; the signals are preprocessed, and cyclostationary features and combined time frequency-cycle features are extracted respectively; a self-adaptive multi-source feature fusion network fusing channels and space attention is constructed, and classification is carried out in combination with double-branch convolution, a protocol perception feature modulator and a multi-scale cavity convolution pyramid. According to the method, multi-dimensional perception and cross-domain feature fusion of hardware fingerprints are realized, the anomaly discrimination is enhanced through protocol perception modulation, feature normalization of different working modes of the same hardware and feature anomaly amplification of illegal equipment are realized, and an end-to-end active defense system from feature extraction to dynamic blocking is formed.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of artificial intelligence, and in particular to a Bluetooth device illegal access hardware identification and dynamic blocking method and device. BACKGROUND

[0002] With the rapid development of Internet of Things and mobile communication, Bluetooth technology has become one of the mainstream standards for short-distance communication of various devices, and is widely used in consumer electronics, smart home, industrial control and medical devices, etc. However, the Bluetooth protocol is more focused on ease of use and interoperability at the initial design stage, and has inherent weaknesses in identity authentication and hardware security. The traditional Bluetooth security mechanism mainly relies on the pairing key and encryption algorithm of the link layer, but these methods often only verify the correctness of the protocol logic, rather than the uniqueness of the physical hardware. Therefore, a large number of hardware clones, software imitations and unauthorized production of Bluetooth devices have emerged in the market, which can easily access the protected network through protocol-level imitation, steal sensitive data, launch man-in-the-middle attacks or cause service interruption, posing a serious threat to personal privacy, enterprise assets and even critical infrastructure.

[0003] The main defects of the prior art are as follows: usually relying on a single signal source (such as only radio frequency or only power consumption), lacking of hardware feature fusion across physical domains, resulting in insufficient discrimination features for high-imitation hardware; feature extraction mostly uses conventional time-frequency transform (such as short-time Fourier transform), ignoring the cyclostationary statistical characteristics in the signal, making it difficult to capture the periodic modulation patterns of hardware circuit and radio frequency; the recognition model is mostly a general neural network architecture, without considering the dynamic influence of Bluetooth protocol state on hardware response, and lacking of special convolution design for the space-frequency space structure of hardware fingerprint; the security mechanism mostly stays in the offline identification stage, failing to form a closed loop with real-time blocking control, lacking of active interference and dynamic defense capability for illegal access. SUMMARY

[0004] In order to solve the technical problems in the prior art, the present application provides a Bluetooth device illegal access hardware identification and dynamic blocking method and device.

[0005] The present application is realized by the following technical solutions: A Bluetooth device illegal access hardware identification and dynamic blocking method, comprising: S1, multi-source waveform data acquisition and training data set construction: including acquiring steady-state current response waveform and radio frequency IQ baseband signal data and constructing data set in proportion; S2, signal preprocessing and feature extraction: including preprocessing alignment and denoising of the original steady-state current response waveform and radio frequency IQ baseband signal data, and extracting the cyclostationary features of the steady-state current response waveform and the joint time-frequency-cyclostationary features of the radio frequency IQ baseband signal to form a preliminary joint feature tensor; S3, Bluetooth device illegal access hardware identification model construction: including adaptive multi-source feature fusion based on channel attention and spatial attention mechanism; and based on the neural network composed of double-branch convolution module, protocol perception feature modulator and multi-scale hollow convolution pyramid, the model construction and training of Bluetooth device legality classification discrimination; S4, Bluetooth device illegal access hardware identification: including when a Bluetooth device tries to access the network or communicate with the monitoring device, based on the trained Bluetooth device illegal access hardware identification model for identification, if it is determined that it is an illegal device, the blocking decision engine generates a blocking instruction immediately according to the preset security policy.

[0006] Further, the cyclic stationary feature of the waveform is determined by the steady-state current response waveform.

[0007] Further, the joint time-frequency-cyclic feature of the radio frequency IQ baseband signal is analyzed by the cyclic spectrum analysis of the complex time-frequency matrix of the signal, the cyclic spectrum feature tensor is extracted, the three-dimensional complex feature tensor is obtained, the three-dimensional complex feature tensor is separated into real part tensor and imaginary part tensor, and is spliced along the channel dimension to form the IQ joint real number feature tensor.

[0008] Further, the adaptive multi-source feature fusion based on channel attention and spatial attention mechanism includes channel attention weight map generation, spatial attention weight map generation, and broadcasting the channel attention weight map and the spatial attention weight map to the same dimension as the preliminary joint feature tensor, then performing element-wise multiplication to obtain the enhanced feature tensor, which is expressed as follows: In the formula, Enhanced feature tensor, Channel attention weight map, Spatial attention weight map, Element-wise multiplication.

[0009] Further, the channel attention weight map is obtained by global average pooling of the preliminary joint feature tensor to obtain a channel descriptor vector, then the inter-channel dependency is learned through two fully connected layers and ReLU activation function, and finally Sigmoid activation function is used to generate; The spatial attention weight map is obtained by respectively performing average pooling and maximum pooling along the channel dimension on the preliminary joint feature tensor to obtain two spatial feature maps, then the two spatial feature maps are spliced and the spatial information is fused through a convolution layer, and finally Sigmoid activation function is used to generate.

[0010] Furthermore, the dual-branch convolutional module uses temporal strip convolutional kernels, frequency-shifted strip convolutional kernels, and square convolutional kernels respectively for parallel feature extraction, as shown below: In the formula, Indicates the first The output feature map of each dual-branch convolutional module; Indicates the layer index of the dual-branch convolutional module; Indicates batch standardized operations; This represents a square convolution operation with a kernel height of . Width is ; This represents a temporal strip convolution operation; This represents a frequency-shifted strip convolution operation; This represents an element-wise addition operation; Indicates input to the first The feature maps of each convolutional module; for the first convolutional module, its input... To enhance the feature tensor .

[0011] Furthermore, the protocol-aware feature modulator encodes the protocol state parsed from the synchronously captured data packets into a protocol state vector, and uses it as a modulation signal to generate channel scaling factors and bias vectors through a lightweight modulation network to perform adaptive channel modulation on the convolutional features.

[0012] Furthermore, the multi-scale dilated convolutional pyramid uses multiple convolutional layers with different dilation rates in parallel to process the protocol-aware modulated features, and then concatenates the outputs along the channel dimension and fuses them through convolution, as shown below: In the formula, Indicates the first Output feature map of multi-scale fusion; express Convolution operation; This indicates a splicing operation along the channel dimension; This represents a dilated convolution operation with a kernel height of . Width is void ratio ; This represents the void ratio parameter; Indicates the first after protocol-sensing modulation Layer feature map.

[0013] The present invention also provides a device for identifying and dynamically blocking unauthorized access to Bluetooth devices, based on the method for identifying and dynamically blocking unauthorized access to Bluetooth devices as described above, comprising: A multi-source waveform data acquisition and training data set construction module is used to acquire steady-state current response waveforms and radio frequency IQ baseband signal data and divide them into training sets, validation sets and test sets in proportion; A signal preprocessing and feature extraction module is used to extract the cyclic stationary features of the steady-state current response waveforms, construct joint time-frequency-cyclic features of the radio frequency IQ baseband signals, and form a preliminary joint feature tensor; A Bluetooth device illegal access hardware identification model construction module is used to adaptively fuse and enhance multi-source features, and construct a Bluetooth device illegal access hardware identification model based on a neural network model composed of a double-branch convolution module, a protocol-aware feature modulator and a multi-scale hollow convolution pyramid, and train the model; A Bluetooth device illegal access hardware identification module is used to identify the illegal access of Bluetooth devices based on the trained model, and output the legality discrimination result of the hardware identity of the device.

[0014] In addition, to achieve the above-mentioned purpose, the application also provides a computer readable storage medium, which stores the program instructions of the Bluetooth device illegal access hardware identification and dynamic blocking method, and the program instructions of the Bluetooth device illegal access hardware identification and dynamic blocking method can be executed by one or more processors to realize the steps of the Bluetooth device illegal access hardware identification and dynamic blocking method as described above.

[0015] Compared with the prior art, the application has the following beneficial effects: 1) By synchronously acquiring the circuit domain steady-state current response and the radio frequency domain IQ baseband signal of the Bluetooth device, a multi-source training data set across physical domains is constructed, and multi-dimensional perception of hardware fingerprints is realized; 2) According to the physical characteristics of the two signals, cyclic stationary feature extraction and complex time-frequency-cyclic spectrum joint feature construction methods are respectively designed, which breaks through the limitation of traditional time-frequency analysis on the discrimination ability of hardware subtle defects; 3) A protocol-aware dynamic feature modulation mechanism is proposed, which integrates the Bluetooth protocol stack state vector as context information into the neural network, realizes feature normalization of the same hardware in different working modes and abnormal amplification of illegal device features; 4) An adaptive neural network is constructed by fusing double-branch convolution, multi-scale hollow convolution and attention mechanism, which is specially designed to optimize the cross-domain correlation, multi-scale characteristics and noise sensitivity of hardware fingerprints, forming an end-to-end active defense system from feature extraction to dynamic blocking. BRIEF DESCRIPTION OF DRAWINGS

[0016] The accompanying drawings, which are included to provide a further understanding of the application and are incorporated in and constitute a part of this application, illustrate embodiments of the application and together with the description serve to explain the application. In the drawings: Figure 1 is a flowchart of a method for identifying illegal access hardware of a Bluetooth device and dynamically blocking according to an embodiment of the application; Figure 2 is a flowchart of a method for pre-processing multi-source waveform data and extracting joint time-frequency-cyclic stationary features according to an embodiment of the application; Figure 3 is a scatter plot of feature space distribution of legal devices and illegal devices according to an embodiment of the application; Figure 4 is a kernel density plot of feature space distribution of legal devices and illegal devices according to an embodiment of the application; Figure 5 is a flowchart of a method for identifying illegal access hardware of a Bluetooth device according to an embodiment of the application. DETAILED DESCRIPTION

[0017] Embodiments of the present application will be described in detail below with reference to the drawings.

[0018] The above examples are merely illustrative of the present application. Numerous modifications and adaptations will be apparent to those skilled in the art without departing from the spirit and scope of the present application. Therefore, the scope of the present application is not limited to the above examples, but is defined by the appended claims.

[0019] It should be noted that the drawings provided in the following embodiments are merely schematic and do not show the components in the actual number, shape and size. The actual implementation of each component may be randomly changed, and the layout of the components may be more complex.

[0020] Referring to Figure 1 A method for identifying illegal access hardware of a Bluetooth device and dynamically blocking includes the following steps: S1, multi-source waveform data acquisition and training data set construction The differences in steady-state current response waveform and radio frequency IQ baseband signal between legal devices and illegal devices (fake / cloned devices) are fundamentally rooted in the physical and non-ideal differences in the hardware manufacturing process (i.e., "hardware fingerprint" or "physical unclonable feature"). Differences in software and protocol are secondary and can be circumvented, but hardware physical differences are inherent and difficult to completely replicate. Due to physical characteristics, semiconductor process deviations, passive component tolerances, PCB layout and parasitic parameters, and antenna characteristics at the hardware manufacturing level, these physical differences are random, unique, and relatively stable throughout the device's life cycle. They are directly and inevitably mapped to the two types of signals during device runtime: 1) Steady-state current response waveform: When performing different operations (scanning, connecting, encrypting), digital circuits (such as Bluetooth baseband processors) have different internal transistor switch state combinations, resulting in a unique dynamic "power consumption fingerprint" synchronized with the clock and protocol frame from the power supply. Hardware clones cannot replicate the original device's transistor-level switching characteristics.

[0021] 2) Radio frequency IQ baseband signal: Physical defects in radio frequency front-end circuits (such as voltage-controlled oscillators, mixers, and power amplifiers) can introduce unique nonlinear distortion, phase noise, I / Q imbalance (inconsistent amplitude and phase between two signals of quadrature modulation), and carrier leakage. These are the "radio frequency fingerprints" of hardware, and it is difficult for high-imitation hardware to be completely consistent.

[0022] It is important to note that a "high-imitation" illegal device aims to be completely consistent with legal devices at the protocol and behavior level to pass authentication, so the innovation and value of the invention lies in its independence from software / protocol layer features that are easily cloned or simulated, and its deep dive into physical layer hardware features that are difficult to counterfeit. That is, even if illegal devices are well disguised in software and behavior, their unique hardware features are difficult to disguise, and they can be accurately identified by the system.

[0023] In a controlled laboratory environment, the multi-source waveform data of a variety of Bluetooth devices with known identity and source are synchronously collected. Specifically, the collection system is composed of a high-precision current probe and a software-defined radio platform, which are used to capture the steady-state current response waveform and the radio frequency IQ baseband signal transmitted in the air, respectively, when the target Bluetooth device is working. During the collection process, the Bluetooth device to be tested (including legal devices from authorized manufacturers and illegal hardware such as counterfeit and cloned devices obtained from the market) is placed in a standard working state and is required to perform a series of communication tasks covering different protocol stack states (such as scanning, connection establishment, encrypted data transmission, etc.). The current probe is connected in series to the power supply circuit of the device at a high sampling rate to capture the dynamic current consumption of the circuit board during the communication process, forming the steady-state current response waveform raw data. At the same time, the software-defined radio platform is configured in the Bluetooth operating frequency band to capture the Bluetooth radio frequency signal in the air with a synchronous clock reference, and after down-conversion and demodulation, the radio frequency IQ baseband signal raw data in the same time period is obtained. Ensuring that the collection of the two signals is strictly synchronized in time is the basis for subsequent joint analysis.

[0024] After completing the raw data collection, it needs to be labeled. The labeling work is based on the known source and identity of the device: all devices from authorized manufacturers and certified devices are labeled as “legal device” category; and all devices from unauthorized channels, hardware cloning or software emulation are labeled as “illegal device” category.

[0025] In addition, in order to enrich the context awareness ability of the model, the Bluetooth protocol stack state information (such as connection state, encryption, data packet type, etc.) corresponding to each piece of data needs to be parsed from the captured data packet and encoded as a protocol state vector, which is stored as auxiliary information associated with the waveform data.

[0026] All synchronously collected steady-state current response waveform and radio frequency IQ baseband signal data pairs with explicit device legality labels and protocol state vectors are proportionally divided into training set, validation set and test set, thereby constructing a complete multi-source waveform training data set that can be used for supervised learning.

[0027] S2, multi-source waveform data preprocessing and joint time-frequency-cyclostationary feature extraction The training data is composed of synchronously collected steady-state current response waveform and radio frequency IQ baseband signal, which come from the circuit current domain and the radio frequency complex baseband domain respectively, have the characteristics of cross-physical domain, high dimension and are affected by environmental noise and hardware nonlinear distortion. Conventional techniques simply concatenate the two signals after performing short-time Fourier transform on each of them, which fails to effectively exploit the cyclostationary characteristics in the steady-state current response waveform determined by hardware circuit nonlinearity, and also destroys the joint structure information of the radio frequency IQ baseband signal complex domain, resulting in insufficient discrimination of subtle waveform differences produced by high-emulation hardware.

[0028] This invention preprocesses, aligns, and denoises the raw dual-stream waveform data, and simultaneously extracts the cyclostationary characteristics of the steady-state current response waveform and the joint time-frequency-cyclic characteristics of the RF IQ baseband signal to fully exploit the hardware fingerprint information contained in different physical domains. Specific steps are as follows: Figure 2 As shown, it includes: S201. Extraction of cyclic stationary features of steady-state current response waveform; The statistical characteristics inherent in the steady-state current response waveform exhibit cyclostationarity due to the periodic frame structure of Bluetooth communication. This is a unique modulation feature of the hardware circuit. By calculating its cyclic spectrum to extract the cyclostationar features, robust extraction of the periodic modulation mode of the hardware circuit can be achieved, enhancing the ability to distinguish subtle waveform differences in high-quality counterfeit hardware. This can be represented as: In the formula, The cyclostationary characteristic spectrum of the steady-state current response waveform In time index and cycle frequency The value at that location represents a specific time delay. The second-order cyclic autocorrelation intensity can keenly capture the periodic modulation patterns of hardware circuits. It is a three-dimensional tensor with dimensions of . ; This represents a time index, with a value range of [value range missing]. ; The cycle frequency represents the frequency of periodic modulation components in the signal (such as the periodicity caused by the Bluetooth frame structure), and its value is selected from a first preset discrete set. , This represents the maximum cyclic frequency value in a first preset discrete set. The example value is 32; This represents the pre-processed steady-state current response waveform. In the The complex values ​​at each sampling point are obtained from the original current signal after DC removal, alignment and noise reduction; This represents a local time index within the sliding window, with values ​​ranging from... arrive ; This indicates the length of the sliding window, used to control the smoothness of time; an example value is 64. This represents the pre-processed steady-state current response waveform. In the Complex values ​​at each sampling point; represents a pre-processed steady-state current response waveform, which is a complex-valued sequence obtained by removing DC component, time alignment based on reference signal, and wavelet denoising from the original steady-state current response waveform, in an implementation, the pre-processing includes: DC component removal, time alignment based on reference signal, and wavelet denoising, and the analytic signal is obtained by Hilbert transform; represents a complex conjugate operator; represents the complex conjugate of ; represents a natural constant; represents an imaginary unit, satisfying ; represents a time delay parameter, used to define the time difference between two sampling points when calculating correlation, and its value is selected from a second preset discrete set , represents the maximum time delay value in the second preset discrete set , and the value example is 8; represents the total number of sampling points of the pre-processed steady-state current response waveform, which is determined by the sampling rate and signal duration, that is ; represents the number of feature frames obtained by sliding calculation along the time axis , and the calculation method is represented as ; represents the maximum value in the second preset discrete set .

[0029] In an implementation, the value set of is usually set in a range expected to contain the main cycle frequency according to prior knowledge (such as Bluetooth protocol frame period, symbol rate), and is uniformly or logarithmically discretized.

[0030] It should be noted that the cycle frequency is not the frequency of the signal itself in the frequency spectrum, but represents the frequency at which the statistical characteristics (such as mean value, autocorrelation function) of the signal show periodic changes. In communication signals, such periodicity is usually introduced by periodic processes such as frame structure, symbol rate, carrier modulation, for example, the frame repetition period of a Bluetooth device will make its current waveform autocorrelation function show the same periodicity, and the reciprocal of this period corresponds to the cycle frequency Extracting the cyclostationary feature can capture the unique correspondence of the periodic modulation mode of the hardware circuit, thereby distinguishing different hardware.

[0031] S202, joint time-frequency-cyclo feature construction of radio frequency IQ baseband signal The radio frequency IQ baseband signal is essentially a complex baseband signal, and a joint representation that can simultaneously retain its time-frequency characteristics and cyclostationarity needs to be constructed. A complex time-frequency matrix of the analytic signal is calculated to obtain a better time-frequency resolution, and a cyclostationary density sensitive to hardware defects is extracted for the complex time-frequency matrix. The steps are as follows: 1) Time-frequency analysis of the preprocessed radio frequency IQ baseband signal is performed by S transform to obtain a complex time-frequency matrix, wherein the S transform is based on a Gaussian window function, the window width of which is adaptively adjusted according to the absolute value of the frequency, and the time-frequency transform is realized by convolution integration of the signal and the Gaussian window function, so as to obtain variable time-frequency resolution with high frequency resolution in the low frequency area and high time resolution in the high frequency area, effectively capturing the transient characteristics in the radio frequency IQ baseband signal caused by hardware defects, which is expressed as: In the formula, The complex time-frequency matrix of the radio frequency IQ baseband signal is expressed as The value of the radio frequency IQ baseband signal at time and frequency is The dimension of is , which is adaptively changed by the Gaussian window to provide variable time-frequency resolution on the time-frequency plane, with high frequency resolution in the low frequency area and high time resolution in the high frequency area; The time variable is expressed as The frequency variable is expressed as The absolute value of the frequency is expressed as The preprocessed radio frequency IQ baseband signal is expressed as The value of the preprocessed radio frequency IQ baseband signal at time is expressed as The preprocessed radio frequency IQ baseband signal is expressed as In one implementation, the complex signal obtained by normalizing, bandpass filtering and synchronously preprocessing the original radio frequency IQ baseband signal is expressed as The integral variable is expressed as , which represents the time of the signal; The integral operation of the variable from negative infinity to positive infinity is expressed as

[0032] It should be noted that Item represents a Gaussian window function in S-transform, whose width varies with frequency Adaptive variation, thus providing variable time-frequency resolution on the time-frequency plane, improving the ability to capture transient hardware defects.

[0033] 2) By performing cyclic spectrum analysis on the complex time-frequency matrix of the radio frequency IQ baseband signal, the cyclic spectrum feature tensor is extracted, and sensitive detection of radio frequency hardware defects such as carrier leakage and I / Q imbalance is realized, represented as: In the formula, represents the cyclic spectrum feature tensor of the radio frequency IQ baseband signal At the center frequency And the spectral frequency shift The value at the value represents the spectral correlation of the signal in the cyclic frequency, center frequency and spectral frequency shift dimensions, which is extremely sensitive to radio frequency hardware defects such as carrier leakage and I / Q imbalance, is a three-dimensional complex tensor with dimensions ; represents the spectral frequency shift parameter, which is used to define the offset between two frequency components, and its value is selected from a preset discrete set , represents the maximum spectral frequency shift value in the third preset discrete set, and the size of the third preset discrete set is The value example is 16; represents the length of the complex time-frequency matrix on the time axis, that is, the number of time sampling points; represents the value of the complex time-frequency matrix At time And frequency ; represents the value of the complex time-frequency matrix At time And frequency ; represents The complex conjugate of As a complex exponential function, it is used to convert time To the cyclic frequency Domain; represents the length of the frequency dimension, which is determined by the frequency sampling points of the S-transform; represents the number of cyclic frequency parameters, and the value example is 16.

[0034] 3) cyclic spectral density tensor construction and real numberization to the complex time-frequency matrix slice along the time axis and calculate the cyclic spectral correlation (i.e. cyclic spectrum), obtaining a three-dimensional complex feature tensor , that is, is a tensor composed of all values, denoted as , with dimensions , representing the strength of spectral correlation of the signal in the frequency, spectral frequency shift and cyclic frequency dimensions; Further, in order to facilitate neural network processing, the three-dimensional complex feature tensor is separated into real part tensor and imaginary part tensor , and concatenated along the channel dimension to form the IQ joint real feature tensor , with dimensions ; S203, forming a preliminary joint feature tensor The steady-state current response waveform cyclic stationary feature spectrum and the spatial dimension of the IQ joint real feature tensor are uniformly adjusted to (by interpolation or pooling operation), and then concatenated in the channel dimension to form a preliminary joint feature tensor , with dimensions , representing a collection of hardware fingerprint information mined from different angles.

[0035] wherein represents the height of the feature map, corresponding to the number of time frames or frequency points, the width of the feature map, corresponding to the time delay or spectral frequency shift dimension, represents the initial number of channels, defined as , represents the number of channels of the steady-state current response waveform cyclic stationary feature spectrum .

[0036] S3, constructing a Bluetooth device illegal access hardware identification model S301, adaptive multi-source feature fusion and noise robustness enhancement In the prior art, simple concatenation or fixed weight fusion is usually used in multi-source feature fusion, without considering the importance difference of different feature channels and spatial positions, and being sensitive to environmental noise and hardware nonlinear distortion, resulting in insufficient discrimination of the fused features.

[0037] The present application adaptively weights important feature channels and spatial positions through channel attention and spatial attention mechanisms, suppresses noise interference, and improves feature robustness and identification performance, with the following specific steps: 1) Channel attention weight map generation The global average pooling is performed on the preliminary joint feature tensor to obtain a channel descriptor vector, and then the inter-channel dependency is learned through two fully connected layers and a ReLU activation function, and a channel attention weight map is generated using a Sigmoid activation function, denoted as: In the formula, represents the channel attention weight map, and the dimension is , which is used to weight the importance of each channel of the preliminary joint feature tensor ; the greater the value, the more important the corresponding channel feature is; represents the Sigmoid activation function, which normalizes the output value to the interval ; represents the weight matrix of the first fully connected layer, which is a trainable parameter, and the dimension is ; represents the weight matrix of the second fully connected layer, which is a trainable parameter, and the dimension is ; represents the global average pooling operation, the item is used to compress the spatial dimension of the preliminary joint feature tensor to , and the output dimension is the channel descriptor vector with dimensions, which contains the global statistical information of each channel; represents the channel compression ratio, which is an integer hyperparameter greater than 1, used to reduce the computational complexity of the attention module, and the value example is 16; represents the ReLU activation function, which introduces nonlinearity to enhance the expression ability of the network.

[0038] 2) Spatial attention weight map generation The average pooling and maximum pooling along the channel dimension are performed on the preliminary joint feature tensor to obtain two spatial feature maps, then the two spatial feature maps are spliced and the spatial information is fused through a convolution layer, and a spatial attention weight map is generated using a Sigmoid activation function, denoted as: In the formula, represents the spatial attention weight map, and the dimension is , which is used to weight the importance of each spatial position of the preliminary joint feature tensor ; denotes a convolution layer with kernel size , which is used to perform convolution operation on the concatenated feature map to fuse spatial information; denotes an average pooling operation along the channel dimension, the output dimension of the feature map is , which captures the average response of all channels at each spatial position; denotes a max pooling operation along the channel dimension, the output dimension of the feature map is , which captures the most salient response of all channels at each spatial position; denotes a concatenation operation along the channel dimension, which is used to concatenate the two feature maps output by the average pooling and max pooling into a feature map with dimension .

[0039] 3) Adaptive feature weighting The channel attention weight map and the spatial attention weight map are broadcast to the same dimension as the preliminary joint feature tensor, and then element-wise multiplication is performed to obtain the enhanced feature tensor, denoted as: In the formula, denotes the enhanced feature tensor, which is the feature tensor after channel and spatial attention weighting, with dimension . denotes element-wise multiplication.

[0040] In specific implementation, broadcast along the spatial dimension, broadcast along the channel dimension, that is, from to , from to , realizing adaptive weighting for each channel and each spatial position.

[0041] S302, Bluetooth device illegal access hardware identification The conventional method usually uses a general neural network architecture to process the concatenated features, which fails to optimize for the characteristics of high-dimensional, cross-domain and noise-sensitive Bluetooth hardware fingerprints, and ignores the key contextual information of Bluetooth communication protocol stack state, resulting in blurred boundaries in identifying high-simulation illegal hardware.

[0042] The application constructs a neural network model composed of a double-branch convolution module, a protocol-aware feature modulator and a multi-scale hollow convolution pyramid, deeply fuses physical layer hardware defect features and link layer protocol state information, fully mines cross-domain correlations contained in the enhanced feature tensor, and dynamically modulates the features by using the protocol state vector, so as to increase the distance between legal and illegal hardware device features in the feature space, and the specific steps are as follows: 1) Spatio-temporal-frequency-space convolution feature extraction based on a double-branch convolution module Considering that the spatial dimensions of the enhanced feature tensor correspond to time or frequency and time delay or spectral frequency shift respectively, the local patterns have different correlation structures in the spatio-temporal subspace and the frequency-space subspace, a double-branch convolution module is adopted, a time sequence strip convolution kernel, a frequency shift strip convolution kernel and a square convolution kernel are used for parallel feature extraction, so as to finely capture the local dependence relationship of the hardware fingerprint in different physical domain subspaces, and the expression is as follows: In the formula, represents the output feature map of the i-th double-branch convolution module, the dimension of which is consistent with the input , and the dimension is , the local features of the spatio-temporal and frequency-space subspaces are fused, and the representation ability of the hardware fingerprint is effectively enhanced; represents the layer index of the double-branch convolution module, and the value range is ; represents the total number of double-branch convolution modules, i.e. the number of stacked module layers, and the value example is 4; represents a batch normalization operation, which is used to accelerate model training convergence and improve generalization ability; represents a square convolution operation, the height of the convolution kernel is , the width is , and is preferably defined to capture the local correlation pattern in the joint subspace of time and time delay or frequency and spectral frequency shift; represents a time sequence strip convolution operation, the convolution kernel size is , and it focuses on the dependence relationship along the time or frequency axis direction, and is used to capture the time sequence pattern of the hardware response; represents a frequency shift strip convolution operation, the convolution kernel size is , and it focuses on the dependence relationship along the time delay or spectral frequency shift axis direction, and is used to capture the structure of the features in the shift dimension; ​This indicates an element-wise addition operation, used to fuse temporal and frequency-shift features extracted by the strip convolution branches; Indicates input to the first The feature maps of each convolutional module; for the first convolutional module, its input... To enhance the feature tensor .

[0043] In its implementation, the dual-branch convolution module consists of two branches. Branch 1 uses a 3×3 square convolution kernel to perform standard convolution, capturing local correlations within the spatiotemporal or frequency-spatial joint subspace. Branch 2 uses two strip convolution kernels in parallel: a 1×3 temporal strip convolution kernel (focusing on feature dependencies along the time or frequency axis) and a 3×1 frequency-shifted strip convolution kernel (focusing on feature dependencies along the time delay or spectral frequency shift axis). The outputs of these two strip convolutions are summed element-wise. The outputs of the two branches are batch-normalized and then summed element-wise to form the output of the dual-branch convolution module.

[0044] It should be noted that the square convolution operation is a standard convolution using a 3×3 square convolution kernel, which is an existing technology used to capture local spatial patterns. The temporal strip convolution operation uses a 1×3 strip convolution kernel and focuses on dependencies along the time or frequency axis. The frequency shift strip convolution operation uses a 3×1 strip convolution kernel and focuses on dependencies along the time delay or spectral frequency shift axis.

[0045] 2) Protocol-aware dynamic feature modulation The circuit and RF response characteristics of Bluetooth devices are affected by their current protocol stack state. Utilizing this prior knowledge, the protocol state parsed from the synchronously captured data packets is encoded into a protocol state vector, which is then used as a modulation signal. A lightweight modulation network generates channel scaling factors and bias vectors, adaptively modulating the convolutional features. This enables the model to distinguish feature changes of the same hardware under different protocol states and amplifies the feature anomalies caused by differences in protocol stack implementations in illegitimate devices, represented as: In the formula, Indicates the first after protocol-sensing modulation Layer feature map, dimension is Based on the protocol state vector, the features are channel scaled and biased to highlight the abnormal features of illegal devices under specific protocol states. This indicates a channel-by-channel multiplication broadcast operation; Indicates the first The layer's channel scaling factor vector is derived from the protocol state vector. Generated through a modulation network for use with feature maps importance scaling for each channel of the feature map, which is calculated as ; denotes the channel bias vector of the first full connection layer, which is generated by the protocol state vector is generated by the modulation network, which is used to adjust the bias for each channel of the feature map ; denotes the protocol state vector, which is obtained by protocol parsing of the captured data packet, and encodes the current connection state, encryption mode and data packet type of the encoding device, etc. In an implementation, the protocol state vector encodes the current protocol stack state information of the Bluetooth device, including the connection state (such as standby, scanning, connection, encryption), the encryption mode (such as no encryption, AES encryption), and the data packet type (such as broadcast packet, ACL data packet, SCO voice packet); denotes the weight matrix of the first full connection layer, which is a trainable parameter, and is used to map the protocol state vector to the hidden layer to learn the abstract representation of the protocol state; denotes the weight matrix of the second full connection layer, which is a trainable parameter, and is used to map the hidden layer to the scaling factor vector and the bias vector to realize channel modulation; denotes the weight matrix of the third full connection layer, which is a trainable parameter, and is used to map the protocol state vector to the hidden layer to learn the abstract representation of the protocol state; denotes the weight matrix of the fourth full connection layer, which is a trainable parameter, and is used to map the hidden layer to the scaling factor vector and the bias vector to realize channel modulation; denotes the LeakyReLU activation function, which is used to introduce nonlinearity in the modulation network.

[0046] It should be noted that in the calculation process of , the +1 ensures that the scaling factor changes around 1 to avoid excessive distortion of the features, while allowing adaptive fine-tuning based on the protocol state to enhance the model's ability to distinguish feature changes of the same hardware under different protocol states.

[0047] It should also be noted that in the calculation process of , the bias vector is directly generated to compensate for the feature offset caused by the protocol state, thereby strengthening the feature abnormalities caused by the implementation differences of the protocol stack of illegal devices.

[0048] 3) Multi-scale dilated convolution pyramid fusion ​​Hardware defects may manifest as transient features at different time or frequency scales in signals. To expand the receptive field and capture multi-scale contextual information without significantly increasing parameters, a multi-scale dilated convolutional pyramid is constructed. This pyramid uses multiple convolutional layers with different dilation rates in parallel to process features modulated by protocol awareness, and the outputs are concatenated along the channel dimension and then fused through convolution. This enhances the model's ability to perceive hardware fingerprint patterns at various scales, from subtle transients to macroscopic distortions, and is represented as follows: In the formula, Indicates the first The output feature map of multi-scale fusion has a dimension of 1. By integrating multi-scale contextual information captured by convolutions with different dilation rates, the ability to perceive hardware fingerprint patterns at various scales, from subtle transients to macroscopic distortions, is enhanced. express Convolutional operations are used to perform channel fusion and dimensionality reduction on the spliced ​​multi-scale features; This indicates a splicing operation along the channel dimension; This represents a dilated convolution operation with a kernel height of . Width is void ratio ,when This is the standard convolution, while dilated convolution can expand the receptive field while keeping the number of parameters constant; This represents the hole rate parameter, which controls the spacing between weights within the convolution kernel. Examples of values ​​are 1, 2, and 4, corresponding to standard convolution, moderate receptive field expansion, and large receptive field expansion, respectively.

[0049] 4) Global feature aggregation and legality classification judgment go through After stacking the above modules, we get the first... Output feature map of multi-scale fusion ,right Global average pooling is used to obtain the global feature vector. Then The input is fed into a fully connected classifier to determine the legality of the hardware identity, and the output is the legality category of the hardware identity, including two categories: "legal device" and "illegal device".

[0050] In one embodiment, the ability of the features extracted by the method of the present invention to distinguish between legitimate and illegitimate devices is analyzed through feature space visualization. In the experimental configuration, the method of the present invention is used to extract high-dimensional features of 200 legitimate devices and 200 illegitimate devices, where illegitimate devices include both high-imitation and low-imitation devices. To visualize the high-dimensional features, a feature reduction technique (t-SNE algorithm) is used to project them onto a two-dimensional plane, preserving the main structural information of the original feature space.

[0051] like Figure 3 As shown, the scatter plot illustrates the distribution of devices in the feature space: legitimate devices (blue dots) are densely clustered in a relatively compact area, forming a clear cluster structure; illegitimate devices (red dots) are distributed in a relatively dispersed area. It can be inferred that low-imitation devices are far from the legitimate device cluster, while high-imitation devices are close to but not completely mixed into the legitimate device area; where feature dimension 1 represents the first feature dimension after t-SNE dimensionality reduction, and feature dimension 2 represents the second feature dimension after t-SNE dimensionality reduction.

[0052] like Figure 4 As shown, the kernel density map further illustrates the density of device distribution in the feature space using contour lines and color fills. The density difference map uses color gradients to represent the difference between the density of legal and illegal devices; blue areas indicate regions where the density of legal devices is significantly higher than that of illegal devices, while red areas indicate the opposite. Feature dimension 1 represents the first feature dimension after t-SNE dimensionality reduction, and feature dimension 2 represents the second feature dimension after t-SNE dimensionality reduction. The color represents the density difference. The figure shows that the overlap area between the density distributions of the two types of devices is small, indicating that the features extracted by the method of this invention can effectively increase the distance between legal and illegal devices in the feature space, reducing the classification difficulty. This demonstrates that the feature space obtained by the method of this invention has a large inter-class distance and a small intra-class dispersion.

[0053] S303, Loss Function Calculation and Trainable Parameter Update During model training, after each forward propagation to obtain the legality category prediction result of the hardware identity, a loss function needs to be calculated to measure the gap between the prediction and the true label.

[0054] This invention employs the cross-entropy loss function, which is suitable for binary classification tasks involving "legitimate devices" and "illegitimate devices." This function effectively measures the difference between the probability distribution predicted by the model and the one-hot encoding of the true labels. The calculated loss value reflects the performance of the recognition system under the current model parameters.

[0055] Then, the gradients of the loss function with respect to all trainable parameters in the model are computed using the backpropagation algorithm, which indicate the direction and magnitude of adjustment for each parameter to reduce the loss and improve the discriminative ability of the model. The gradients are used to iteratively update all trainable parameters in the model using stochastic gradient descent or its variants, such as the Adam optimizer. The optimizer adaptively adjusts the learning rate of each parameter based on the first and second moment estimates of the gradients, achieving more stable and efficient parameter updates. The entire training process periodically evaluates the model performance on the validation set, monitoring the loss and accuracy indicators.

[0056] Training will continue until the preset stopping iteration condition is met. The stopping condition is set as follows: the loss function value on the validation set no longer significantly decreases for multiple training cycles (rounds) in a row, or the accuracy indicator enters a plateau, indicating that the model may have learned sufficiently and is starting to overfit, or the maximum number of training rounds is reached.

[0057] After training is complete, the model parameter snapshot with the best performance on the validation set is saved as the final trained Bluetooth device illegal access hardware identification model, which is used for subsequent identification and blocking tasks.

[0058] S4, Bluetooth device illegal access hardware identification As shown in Figure 5 When the Bluetooth device illegal access hardware identification model is trained, it can be deployed in actual network access points or security monitoring devices to perform online or offline illegal hardware identification tasks. The identification process starts with signal capture of the target Bluetooth device. When a Bluetooth device attempts to access the network or communicate with the monitoring device, the system synchronously collects the steady-state current response waveform and the air RF IQ baseband signal generated during communication.

[0059] Then, strictly following the process defined in the training phase, the two original waveform data are preprocessed, aligned, and joint time-frequency-cyclostationary feature extraction is performed to generate a preliminary joint feature tensor consistent with the training data format. This feature tensor is fed into the identification model with the above trained parameters. The model performs forward inference, sequentially passing through feature enhancement, spatio-temporal-frequency-space feature extraction, protocol state dynamic modulation, multi-scale context information fusion, and finally outputs the legality judgment result of the device hardware identity, i.e., whether it is a "legal device" or an "illegal device". Based on the Bluetooth device illegal access hardware identification result, the system can start a dynamic blocking mechanism to actively prevent the access and communication of illegal hardware.

[0060] Specifically, the dynamic blocking of illegal access of the Bluetooth device is a closed-loop control process. When the identification model determines that a Bluetooth device in communication or attempting to access is an illegal device, a blocking decision engine generates a blocking instruction according to a preset security policy, and the instruction is sent to a network access control entity or a dedicated signal interference unit.

[0061] Specific blocking actions can include various forms: for illegal devices in the connection establishment phase, the access point can reject the connection request and immediately disconnect any established link layer connection; for illegal devices that have accessed the network, the network firewall can discard all data packets of the illegal device and add the media access control address of the illegal device to a blacklist to prohibit all access attempts of the illegal device in the future for a period of time; at a more active radio frequency layer, the system can control the radio frequency front end to transmit a friendly jamming signal at a specific channel to interfere with the communication of the illegal device and force the illegal device to back off or fail to connect. Meanwhile, all identification events of illegal devices, blocking actions, and related protocol states and feature fingerprint information are recorded in a security log for auditing and subsequent analysis.

[0062] The dynamic blocking mechanism is not a one-time operation. The system continuously monitors the channel state, performs real-time feature extraction and identification on any newly appearing or repeatedly attempted communication, and realizes the cycle of “identification-blocking-monitoring”.

[0063] Through the real-time identification and rapid response of the dynamic blocking, the active defense capability of the Bluetooth network against illegal access behavior at the hardware level is effectively improved.

[0064] In the embodiment, by synchronously collecting the circuit domain steady-state current response and the radio frequency domain IQ baseband signal of the Bluetooth device, a multi-source training data set across physical domains is constructed, and multi-dimensional perception of the hardware fingerprint is realized; in view of the physical characteristics of the two signals, a cyclostationary feature extraction method and a complex time-frequency-cyclostationary spectrum joint feature construction method are respectively designed, thereby breaking through the limitation of the traditional time-frequency analysis on the discrimination of subtle defects of hardware; a protocol-aware dynamic feature modulation mechanism is proposed, the Bluetooth protocol stack state vector is taken as context information and integrated into a neural network, feature normalization and illegal device feature abnormal amplification in different working modes of the same hardware are realized; an adaptive neural network that fuses a double-branch convolution, a multi-scale hollow convolution, and an attention mechanism is constructed, and is specially optimized for the cross-domain correlation, multi-scale characteristics, and noise sensitivity of the hardware fingerprint, thereby forming an end-to-end active defense system from feature extraction to dynamic blocking.

[0065] The embodiment of the present application also proposes a Bluetooth device illegal access hardware identification and dynamic blocking device based on the Bluetooth device illegal access hardware identification and dynamic blocking method as described above, and includes: A multi-source waveform data and training data set construction module is used to collect steady-state current response waveforms and radio frequency IQ baseband signal data and divide them into training sets, validation sets and test sets in proportion; A signal preprocessing and feature extraction module is used to extract the cyclic stationary features of the steady-state current response waveforms, construct the joint time-frequency-cyclic features of the radio frequency IQ baseband signals, and finally form a preliminary joint feature tensor; A Bluetooth device illegal access hardware identification model construction module is used to adaptively fuse and enhance multi-source features, and construct a Bluetooth device illegal access hardware identification model based on a neural network model composed of a double-branch convolution module, a protocol-aware feature modulator and a multi-scale hollow convolution pyramid, and train the model; A Bluetooth device illegal access hardware identification module is used to identify the illegal access of Bluetooth devices to hardware based on the trained model, and output the legality discrimination result of the hardware identity of the device.

[0066] In addition, an embodiment of the present application also proposes a computer readable storage medium, and the computer readable storage medium stores program instructions of a Bluetooth device illegal access hardware identification and dynamic blocking method. The program instructions of the Bluetooth device illegal access hardware identification and dynamic blocking method can be executed by one or more processors to implement the steps of the Bluetooth device illegal access hardware identification and dynamic blocking method as described above.

[0067] The above-described embodiments only describe the preferred embodiments of the present application, and do not limit the scope of the present application. Without departing from the design spirit of the present application, various modifications and improvements to the technical solutions of the present application made by those skilled in the art shall fall within the protection scope determined by the claims of the present application.

Claims

1. A method for identifying and dynamically blocking unauthorized access to Bluetooth devices, characterized in that, include: S1. Multi-source waveform data acquisition and training dataset construction: This includes acquiring steady-state current response waveforms and RF IQ baseband signal data and constructing a dataset proportionally. S2. Signal preprocessing and feature extraction: This includes preprocessing, aligning, and denoising the original steady-state current response waveform and RF IQ baseband signal data, and extracting the cyclostationary features of the steady-state current response waveform and the joint time-frequency-cyclostationary features of the RF IQ baseband signal to form a preliminary joint feature tensor. S3. Construction of a hardware identification model for illegal access to Bluetooth devices: This includes adaptive multi-source feature fusion based on channel attention and spatial attention mechanisms; and the construction and training of a model for Bluetooth device legality classification based on a neural network composed of a dual-branch convolutional module, a protocol-aware feature modulator, and a multi-scale dilated convolutional pyramid. S4. Illegal Bluetooth Device Access Hardware Identification: This includes identifying Bluetooth devices attempting to access the network or communicate with monitoring devices based on a trained Bluetooth device illegal access hardware identification model. If the device is determined to be illegal, the blocking decision engine immediately generates a blocking command according to the preset security policy.

2. The method for identifying and dynamically blocking unauthorized access to Bluetooth devices according to claim 1, characterized in that, The cyclic stationary characteristics of the waveform are determined by the cyclic stationary characteristic spectrum of the steady-state current response waveform.

3. The method for identifying and dynamically blocking unauthorized access to Bluetooth devices according to claim 2, characterized in that, The joint time-frequency-cyclic features of the radio frequency IQ baseband signal are obtained by performing cyclic spectrum analysis on the complex time-frequency matrix of the signal, extracting the cyclic spectrum feature tensor, obtaining a three-dimensional complex feature tensor, separating the three-dimensional complex feature tensor into real part tensor and imaginary part tensor, and splicing them along the channel dimension to form the IQ joint real feature tensor.

4. The method for identifying and dynamically blocking unauthorized access to Bluetooth devices according to claim 1, characterized in that, The adaptive multi-source feature fusion based on channel attention and spatial attention mechanisms includes generating a channel attention weight map, generating a spatial attention weight map, and broadcasting the channel attention weight map and the spatial attention weight map to the same dimension as the initial joint feature tensor, and then performing element-wise multiplication to obtain the enhanced feature tensor, as expressed below: In the formula, Represents the augmented feature tensor. This represents the channel attention weight map. Represents the spatial attention weight map. This represents element-wise multiplication; This represents the initial joint feature tensor.

5. The method for identifying and dynamically blocking unauthorized access to Bluetooth devices according to claim 4, characterized in that, The channel attention weight map is obtained by global average pooling of the preliminary joint feature tensor to obtain the channel descriptor vector, and then the channel dependencies are learned through two fully connected layers and the ReLU activation function. Finally, the Sigmoid activation function is used to generate the channel attention weight map. The spatial attention weight map is obtained by performing average pooling and max pooling along the channel dimension on the preliminary joint feature tensor, respectively, to obtain two spatial feature maps. These two spatial feature maps are then concatenated and spatial information is fused through a convolutional layer. Finally, the Sigmoid activation function is used to generate the weight map.

6. The method for identifying and dynamically blocking unauthorized access to Bluetooth devices according to claim 1, characterized in that, The dual-branch convolutional module uses temporal strip convolution kernels, frequency-shifted strip convolution kernels, and square convolution kernels respectively for parallel feature extraction, as follows: In the formula, Indicates the first The output feature map of each dual-branch convolutional module; Indicates the layer index of the bi-branch convolutional module; This indicates a batch of standardized operations; This represents a square convolution operation with a kernel height of . Width is ,in, This represents a temporal strip convolution operation. This represents a frequency-shifted strip convolution operation; This represents an element-wise addition operation; Indicates input to the first The feature maps of each convolutional module; for the first convolutional module, its input... To enhance the feature tensor .

7. The method for identifying and dynamically blocking unauthorized access to Bluetooth devices according to claim 6, characterized in that, The protocol-aware feature modulator encodes the protocol state parsed from the synchronously captured data packets into a protocol state vector, and uses it as a modulation signal to generate channel scaling factors and bias vectors through a lightweight modulation network to perform adaptive channel modulation on the convolutional features.

8. The method for identifying and dynamically blocking unauthorized access to Bluetooth devices according to claim 7, characterized in that, The multi-scale dilated convolutional pyramid uses multiple convolutional layers with different dilation rates in parallel to process the protocol-aware modulated features, and then concatenates the outputs along the channel dimension and fuses them through convolution, as shown below: In the formula, Indicates the first Output feature map of multi-scale fusion; express Convolution operation; This indicates a splicing operation along the channel dimension; This represents a dilated convolution operation with a kernel height of . Width is void ratio ; This represents the void ratio parameter; Indicates the first after protocol-sensing modulation Layer feature map.

9. A Bluetooth device unauthorized access hardware identification and dynamic blocking device, based on the Bluetooth device unauthorized access hardware identification and dynamic blocking method as described in any one of claims 1 to 8, comprising: A multi-source waveform data acquisition and training dataset construction module is used to acquire steady-state current response waveforms and RF IQ baseband signal data and divide them into training set, validation set and test set according to the proportions. The signal preprocessing and feature extraction module is used for cyclic stationary feature extraction of steady-state current response waveform and joint time-frequency-cyclic feature construction of RF IQ baseband signal to form a preliminary joint feature tensor. The module for constructing a Bluetooth device illegal access hardware identification model is used for adaptive multi-source feature fusion and enhancement. It constructs and trains a Bluetooth device illegal access hardware identification model based on a neural network model composed of a dual-branch convolution module, a protocol-aware feature modulator, and a multi-scale dilated convolution pyramid. The Bluetooth device unauthorized access hardware identification module is used to identify unauthorized access hardware of Bluetooth devices based on a trained model, and outputs the result of the judgment on the legality of the hardware identity of the device.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores program instructions for a method of identifying and dynamically blocking unauthorized access to Bluetooth devices, which can be executed by one or more processors to implement the steps of the method of identifying and dynamically blocking unauthorized access to Bluetooth devices as described in any one of claims 1 to 8.

Citation Information

Patent Citations

  • Multi-feature fusion wireless device radio frequency fingerprint extraction method based on attention mechanism

    CN114118131A

  • Wireless communication test method and system based on portable frequency spectrograph, and medium

    CN121194188A

  • Birdsong classification method based on harmonic enhancement and time-frequency semantic joint modeling

    CN121281529A

  • Wireless device classification apparatus and method

    US20220116130A1