A pilot spoofing attack defense method based on master channel null-spatial joint precoding

By employing non-standard cyclic shifting for private pilot allocation and eavesdropping channel detection, combined with zero-space precoding and directional artificial noise, the channel separation problem of TDD MIMO systems under pilot spoofing attacks was solved, thereby improving secure transmission performance and effectively utilizing spectrum resources.

CN122496825APending Publication Date: 2026-07-31HENAN UNIV OF SCI & TECH
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
HENAN UNIV OF SCI & TECH
Filing Date
2026-05-21
Publication Date
2026-07-31

AI Technical Summary

Technical Problem

Existing TDD MIMO systems cannot effectively separate legitimate channels from eavesdropping channels when facing pilot spoofing attacks, resulting in a decline in secure transmission performance and a waste of spectrum resources. Traditional defense solutions lack the ability to actively extract and utilize the characteristics of eavesdropping channels.

Method used

A non-standard cyclic shift private pilot allocation mechanism is adopted. A private pilot sequence is generated by pre-shared private key. The decision threshold is set by combining constant false alarm rate criterion and Bonferroni correction to achieve active detection and extraction of eavesdropping channels. A secure transmission architecture combining null space precoding and directional artificial noise is constructed.

Benefits of technology

It achieves uncontaminated extraction of legitimate channels and proactive sensing of eavesdropping channels, realizing a triple security effect of no data leakage, no noise interference to friendly forces, and precise energy strikes against the enemy. It is compatible with existing standards and has strong robustness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122496825A_ABST
    Figure CN122496825A_ABST
Patent Text Reader

Abstract

This invention discloses a pilot deception attack defense method based on joint null-space precoding of the master eavesdropping channel, belonging to the field of wireless communication and physical layer security technology. This invention utilizes a non-standard orthogonal cyclic shift allocation of the Zadoff-Chu root sequence and an active sensing mechanism using decoy traps. It physically isolates legitimate pilots in the code domain to obtain uncontaminated downlink channel state information while actively capturing attack signals and reconstructing the multi-dimensional channel matrix of the intelligent eavesdropper. Furthermore, based on bidirectional physical domain isolation, a joint null-space precoding architecture is constructed. This physically constrains confidential data signals to the intelligent eavesdropper's null space and injects directional artificial noise into the legitimate user's null space, aligning it to the intelligent eavesdropper's main receiving direction. This achieves a paradigm shift from passive interruption avoidance to proactive trap detection, completely blocking pilot contamination at its source and achieving absolute physical suppression of Eve.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of wireless communication and physical layer security technology, specifically relating to a pilot spoofing attack defense method based on master channel null joint precoding. Background Technology

[0002] With the rapid deployment of fifth-generation (5G) and sixth-generation (6G) mobile communication technologies, Multiple-Input Multiple-Output (MIMO) technology has become a core physical layer technology in modern wireless communication networks due to its significant advantages in improving spectral efficiency and system throughput. However, the inherent openness and broadcast characteristics of wireless communication media make communication links highly vulnerable to malicious eavesdropping and interference. Traditional network security architectures mainly rely on upper-layer cryptographic encryption mechanisms, whose security is based on the assumption of high computational complexity. Therefore, when facing demanding scenarios such as massive machine-type communication and ultra-reliable low-latency communication, they introduce significant computational power consumption and processing latency, and cannot prevent eavesdropping at the physical source.

[0003] To address this, Physical Layer Security (PLS) has emerged as an intrinsic security paradigm. It leverages physical properties such as multipath fading, spatial degrees of freedom, and channel reciprocity to build a security defense at the link's underlying layer. Specifically, in Time Division Duplex (TDD) MIMO systems, the system utilizes channel reciprocity to estimate downlink Channel State Information (CSI) by having a legitimate user (Bob) send uplink pilot sequences, effectively avoiding the feedback overhead that increases linearly with the number of antennas. However, the uplink channel estimation process in TDD systems is completely exposed to an open environment; the pilot sequences are sent in plaintext, lacking effective authentication and anti-interference mechanisms, thus providing opportunities for proactive attacks.

[0004] Currently, in TDD MIMO systems, pilot spoofing attacks (PSA) are a highly destructive active physical layer threat. The standard uplink channel estimation process requires Bob to send orthogonal pilot sequences with good autocorrelation and cross-correlation properties to ensure the base station (Alice) can accurately extract channel features. Under this mechanism, a full-duplex intelligent eavesdropper (Eve) can accurately intercept and parse the standard pilot pattern assigned by Bob through long-term channel monitoring. Subsequently, during the uplink pilot training phase, Eve synchronously sends the exact same spoofed pilot signal as Bob within the same time-frequency resource block. Based on the principle of linear superposition of electromagnetic waves in free space, the mixed signal received by Alice appears as an in-phase superposition of the legitimate pilot signal and the malicious spoofed pilot signal. When Alice employs traditional channel estimation algorithms such as Least Squares (LS) or Minimum Mean Square Error (MMSE), the deception pilot signal completely overlaps with the legitimate pilot signal, making effective separation impossible. Consequently, the CSI extracted by Alice inevitably becomes a linear combination of Bob's and Eve's channels. During downlink data transmission, if Alice constructs a spatial precoding matrix and performs beamforming based on this corrupted CSI, the radiated energy of the TDD MIMO system cannot be fully focused on Bob's multi-antenna subspace. Instead, this precoding matrix, based on the superimposed channel characteristics, generates significant high-gain sidelobes in Eve's physical space. This not only leads to a substantial decrease in the signal-to-interference-plus-noise ratio (SINR) at the legitimate receiver but also causes confidential data streams, which should be protected, to be directly transmitted to the Eve node in the underlying physical space, fundamentally undermining the physical layer security defenses of the TDD MIMO system.

[0005] Under the active threat of PSA, the secure transmission model of traditional TDD MIMO systems faces severe challenges. Eve, by synchronously sending the same pilot signals, not only pollutes legitimate channel estimation but also directionally steals beam energy that should serve Bob, completely reversing the favorable "weak offense, strong defense" situation. In this new situation of shifting offense and defense, existing research has carried out extensive work on PSA detection and defense, including: PSA verification methods based on energy detection or Minimum Description Length (MDL) to determine whether an attack has occurred; and the introduction of multi-stage bidirectional training schemes or random pilot mechanisms to obtain Bob's CSI.

[0006] Despite significant progress in PSA detection and defense, existing research still has limitations. First, PSA detection methods can only determine whether an attack has occurred, but cannot effectively separate Bob's true CSI from the contaminated received signal after an attack is detected. This forces TDD MIMO systems to discard all resources in the current transmission block and interrupt the communication link upon confirming an attack, resulting in wasted spectrum resources and loss of service continuity. Second, introducing a multi-stage bidirectional training scheme consumes additional time-frequency resources and modifies the physical layer frame structure, conflicting with existing 3GPP standards. Third, random pilot mechanisms can disrupt pilot orthogonality, leading to pilot contamination between users; neither of these approaches is feasible for large-scale deployment in real-world networks.

[0007] Furthermore, traditional defense schemes generally ignore the usable signal traces left by Eve during active attacks and fail to actively extract Eve's CSI from the received signals. As a result, when designing beamforming and artificial noise, artificial noise can only be blindly projected into Bob's null space. Although this method avoids interfering with Bob, it cannot suppress Eve in a targeted manner due to the lack of Eve's channel information, resulting in a large amount of transmit power being wasted in invalid spatial dimensions.

[0008] Based on this, the present invention proposes a pilot spoofing attack defense method with null-space joint precoding of the master-spy channel, which can fully unleash the potential of TDD MIMO system in physical layer secure transmission, break the paradigm limitation of passive defense in traditional schemes, fundamentally realize the precise separation of legitimate channels and eavesdropping channels, and ensure the secure communication performance of TDD MIMO system under PSA. Summary of the Invention

[0009] The purpose of this invention is to provide a pilot spoofing attack defense method based on master channel null space joint precoding, which can effectively overcome the technical defects of existing TDD MIMO systems when dealing with PSA, which can only passively interrupt communication or destroy pilot orthogonality and lack the ability to actively extract and utilize Eve space channel characteristics.

[0010] To achieve the above objectives, the technical solution adopted by this invention is: a pilot spoofing attack defense method based on master-stealing channel null-space joint precoding, comprising the following steps: Step S1: Private pilot allocation based on non-standard cyclic shift: The base station and the legitimate user generate a set of non-standard shift amounts through a pre-shared private key. The legitimate user uses the non-standard shift amounts to cyclically shift the Zadoff-Chu root sequence to generate private pilot sequences corresponding to each antenna, and stacks them row by row to form a private pilot signal matrix, which is then transmitted in the uplink channel. Step S2, Uncontaminated extraction of downlink channel state information of legitimate users: After receiving the pilot signal of the uplink channel, the base station projects the received signal using the locally known private pilot sequence to obtain an uncontaminated channel estimation result containing only the real legitimate channel and the equivalent noise matrix; Step S3: Active detection and extraction of downlink channel state information of the intelligent eavesdropper: First, the base station uses the standard pilot sequence as a trap to perform a full-domain energy scan on all idle standard pilot shift positions that are not occupied by the private pilots of legitimate users; then, it calculates the projected energy statistics of the received signal at each candidate position on the corresponding standard pilot; finally, it uses the constant false alarm rate criterion combined with Bonferroni correction to set a decision threshold, constructs a binary hypothesis test to determine whether there is an attack signal at each position, and when the detected energy exceeds the threshold, it determines that there is a pilot spoofing attack, and uses the pilot sequence at that position to reconstruct the multi-dimensional spatial channel matrix of the intelligent eavesdropper, thereby realizing the active perception of the eavesdropping channel characteristics; Step S4: The base station uses the downlink channel state information of the legitimate user obtained in step S2 and the downlink channel state information of the intelligent eavesdropper obtained in step S3 to design a data precoding matrix and an artificial noise precoding matrix. First, singular value decomposition is performed on the equivalent channel matrix of the intelligent eavesdropper to extract its null-space basis matrix, and the confidential data signal is mapped into this null space to obtain the data precoding matrix. Then, the artificial noise signal and the channel matrix of the intelligent eavesdropper are mapped into the null space of the legitimate user's channel, and the main feature direction with the strongest receiving capability of the intelligent eavesdropper is extracted to generate a directional attack matrix, so that the artificial noise energy is accurately focused on the main receiving direction of the intelligent eavesdropper to achieve directional active suppression. Finally, the confidential data signal and the artificial noise signal are superimposed to generate a downlink transmission signal and transmitted through a multi-antenna array.

[0011] Furthermore, the specific process of generating the private pilot sequence in step S1 includes: The base station and the authorized user share a private key K in advance. The authorized user uses the pre-shared private key to generate a set of private shift values. ,in The number of antennas for legitimate users; The private shift amount satisfy: In the formula, Indicates the pilot length. Indicates the basic cyclic shift step size. Indicates a standard shift index. Indicates the maximum multipath duration; Based on this, the first private pilot sequence of legitimate users Each element is represented as: In the formula, This indicates taking the modulus.

[0012] Furthermore, the basic cyclic shift step size satisfies: .

[0013] Furthermore, the downlink channel state information of the legitimate user mentioned in step S2 is represented as follows: In the formula: Indicates a genuine and legitimate channel. This represents the equivalent noise matrix.

[0014] Furthermore, the specific steps of step S3 include: Step S31: The base station uses standard pilot sequences not used by legitimate users as decoy traps, and defines the scanning space as the set of standard shift indices occupied by all private shift amounts not used by legitimate users. The base station performs a full-domain energy scan on all time-domain sampling points of the standard shift index set; Step S32: For each candidate shift index The base station calculates the pilot sequence corresponding to the shift index in the Y direction of the received signal matrix. Projected energy statistics: In the formula, This represents the average transmit power of legitimate users; Step S33: Construct a binary hypothesis test to determine whether there are attack signals at each location; Define the null hypothesis For any position There is no attack signal at this location; at this point, the location only contains additive white Gaussian noise. It follows a central chi-square distribution with 2M degrees of freedom: Alternative Hypothesis For any position An attack signal exists at this location; the statistics at this time... It follows a non-central chi-square distribution with 2M degrees of freedom: in, For non-central parameters, For the first Power of the bar diameter; This represents Eve's average transmit power; The decision threshold is set using a constant false alarm rate combined with Bonferroni correction. in, Let P be the inverse cumulative distribution function of a chi-square distribution with 2M degrees of freedom. FA The preset global false alarm probability; when At that time, determine the position of the shift. A pilot spoofing attack exists. Record the location of the attack and reconstruct Eve's channel estimate using the corresponding pilot sequence: If multiple attack locations are detected, all estimated results will be... Stacking them column-wise yields the complete multi-dimensional channel matrix of the intelligent eavesdropper: .

[0015] Furthermore, in step S4, the data precoding matrix for: in, For power allocation factor, The total power transmitted by the base station. For the null-space basis matrix of the intelligent eavesdropper, The main subspace matrix, For the pre-equilibrium operation matrix, This is the original data vector.

[0016] Furthermore, the artificial noise signal in step S4 for: In the formula, The null basis matrix representing legitimate users, Represents a targeted strike matrix. This represents the complex Gaussian interference vector.

[0017] The beneficial effects of the above technical solution are as follows: 1. This invention enables the uncontaminated extraction of legitimate channels and proactive detection of eavesdropping channels. Specifically, this invention utilizes a non-standard cyclic shift private pilot allocation mechanism, enabling base stations and legitimate users to generate private pilot sequences orthogonal to standard pilots using pre-shared private keys. This proactively avoids pilot spoofing attacks in the code domain and obtains clean legitimate downlink channel state information without modifying the physical layer frame structure. Simultaneously, this invention transforms the standard pilot sequence into a decoy trap, employing a constant false alarm rate criterion combined with Bonferroni correction to set a decision threshold. It performs a full-domain energy scan on idle pilot shift positions, achieving proactive detection and systematic extraction of the eavesdropper's multi-dimensional spatial channel matrix. This overcomes the shortcomings of traditional schemes, which can only passively detect attacks and cannot separate the channel.

[0018] 2. This invention achieves a triple security effect of "no data leakage, no noise interference to friendly forces, and precise energy strikes to the enemy" by constructing a joint null space bidirectional isolation mechanism. Specifically, based on the precise channel state information of both the legitimate channel and the eavesdropping channel, this invention constructs a secure transmission architecture of joint null space precoding and directional artificial noise. On the one hand, confidential data signals are mapped into the null space of the eavesdropper's channel, causing the precoded signal to generate deep nulls in all receiving directions of the eavesdropper, completely cutting off the eavesdropping path at the physical layer. On the other hand, artificial noise signals are constrained to the null space of the legitimate user's channel to avoid interfering with the legitimate user. At the same time, the main feature direction is extracted after projecting the eavesdropper's channel onto the legitimate user's null space, so that the artificial noise energy is precisely focused on the eavesdropper's main receiving direction.

[0019] 3. This invention offers superior security performance and is fully compatible with existing standards, exhibiting strong robustness and engineering deployment feasibility. Specifically, this invention requires no modification to the physical layer frame structure, does not disrupt pilot orthogonality, and is fully compatible with existing 3GPP standards. Furthermore, compared to traditional artificial noise schemes that blindly project noise into the null space of legitimate users and cannot target and suppress eavesdroppers, this invention achieves bidirectional isolation and coordination between data and interference in the spatial domain. Under the same power consumption, it significantly degrades the received signal-to-interference-plus-noise ratio (SNR) for eavesdroppers, achieving secure transmission in the information theory sense. Attached Figure Description

[0020] Figure 1 This is a schematic diagram of a PSA system model for a TDD MIMO system provided in an embodiment of the present invention; Figure 2 This is a performance curve of Bob in the PSA scenario of this invention embodiment; Figure 3 This is a performance curve of Eve in the PSA scenario of this invention embodiment; Figure 4 This is a performance curve of Bob under the active defense scheme in an embodiment of the present invention; Figure 5 This is a performance curve of Eve under the active defense scheme in an embodiment of the present invention; Figure 6 This is a performance comparison curve of the present invention's solution and the traditional artificial noise solution under different antenna configurations in the embodiments of the present invention; Figure 7 This is a performance comparison chart of Bob in the present invention and the traditional artificial noise scheme under different power allocation factors in the embodiments of the present invention; Figure 8 This is a performance comparison chart of Eve in the present invention and the traditional artificial noise scheme under different power allocation factors in the embodiments of the present invention. Detailed Implementation

[0021] The present invention will now be described in further detail with reference to the accompanying drawings and specific embodiments.

[0022] It should be noted that, unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application pertains.

[0023] like Figure 1 As shown, in this embodiment, the TDD MIMO communication system model mainly includes three communication nodes: Alice equipped with M antennas, and... Bob with the root antenna, and equipped with The antenna's Eve. The TDD MIMO communication system adopts a quasi-static block fading channel model with multipath delay spread. The channel coefficients remain constant during the coherence time, but vary independently between different blocks, with a maximum multipath delay of [value missing]. Both Bob and Eve operate in half-duplex mode, with Eve implementing synchronous PSA during the uplink pilot training phase and eavesdropping during the downlink data transmission phase. This embodiment assumes Alice has global channel statistics to verify the theoretical performance of the proposed active defense scheme. Based on the above multipath channel model and system configuration, this embodiment proposes a pilot spoofing attack defense method using master-spoofing channel null-space joint precoding, the specific steps of which are as follows: Step S1: Private Pilot Allocation Based on Non-Standard Cyclic Shift: The base station and the authorized user generate a set of non-standard shift values ​​using a pre-shared private key. The authorized user uses these non-standard shift values ​​to cyclically shift the Zadoff-Chu root sequence, generating private pilot sequences corresponding to each antenna. These sequences are then stacked row-wise to form a private pilot signal matrix, which is transmitted in the uplink channel. Specifically: Step S11: Define the standard pilot sequence In this embodiment, the Zadoff-Chu (ZC) sequence is used as a pilot signal for uplink channel estimation.

[0024] Define the pilot length as Define the ZC root sequence with physical root index r. Its nth element is defined as: ;make For a standard logical shift index set, where , Based on the cyclic shift step size and satisfying .

[0025] For any standard shift index Its corresponding standard pilot sequence Defined as: (1) Step S12: Define Bob's private pilot sequence To defend against PSA, Alice and Bob share a private key K beforehand. Bob uses the pre-shared private key to generate a set of private shift values. ,in This refers to the number of antennas for Bob. To achieve absolute physical isolation, the privacy shift amount... The following constraints must be met: (2) Based on this, Bob's private pilot sequence Defined as: (3) Bob's Private Pilot Signal Matrix for: .

[0026] Since Eve cannot know the private key, she can only initiate PSA against the standard shift set or randomly guess the shift amount. Therefore, the spoof pilot sent by Eve and Bob's private pilot are orthogonal in the code domain, thus achieving physical isolation between the legitimate signal and the spoof signal and eliminating pilot pollution at the source.

[0027] Step S2, Uncontaminated Extraction of Downlink Channel State Information for Legitimate Users: After receiving the pilot signal of the uplink channel, the base station projects the received signal using locally known private pilot sequences to obtain an uncontaminated channel estimation result containing only the real legitimate channel and the equivalent noise matrix. Specifically: Step S21: Base station Alice receives signals during the uplink pilot training phase.

[0028] Considering a multipath propagation environment, let the maximum multipath time delay be... Then the received signal matrix This can be represented as a linear superposition of Bob's private pilot signal, Eve's spoof pilot signal, and additive white Gaussian noise: (4) Among them, P B P E These represent the average transmit power of Bob and Eve, respectively. and These represent Bob and Eve at the [number]th [year]. Channel matrix of each path, and These represent Bob and Eve at the [number]th [year]. Pilot sequences transmitted along the path, The matrix is ​​an additive white Gaussian noise matrix whose elements follow the order of... distributed.

[0029] Step S22: In order to estimate Bob's first... For the channel of the path, Alice uses the locally known private pilot sequence corresponding to that path to perform a projection operation on the received signal. Specifically, the received signal is right-multiplied... And normalize it: (5) Step S23: Substitute the received signal matrix Y from step 21 into equation (5) and expand to get: (6) in, The processed equivalent noise matrix has elements that follow a complex Gaussian distribution. Utilizing the orthogonality of the cyclic shifts of the ZC sequence, for sufficiently large... Suitable cyclic shift intervals include: (7) Step S24: Substitute equation (7) into equation (6) to eliminate all interference terms, resulting in: (8) Alice obtained only channels containing genuine and legitimate information. and equivalent noise matrix The interference contribution from Eve is completely zero, and there is no mutual interference between different paths. This process does not require modification of the existing pilot frame structure or interruption of the communication link. Compared to existing solutions that can only discard resources or modify the frame structure after detecting an attack, this step enables the base station to accurately obtain Bob's CSI even when PSA is present, providing a reliable foundation for subsequent secure downlink transmission.

[0030] For all Repeat the above steps for each stripe to obtain the complete Bob channel matrix: (9) Step S3: Active detection and extraction of downlink channel state information of the intelligent eavesdropper: First, the base station uses the standard pilot sequence as a decoy trap to perform a full-domain energy scan on all idle standard pilot shift positions not occupied by the private pilots of legitimate users; then, it calculates the projected energy statistics of the received signal at each candidate position on the corresponding standard pilot; finally, it uses the constant false alarm rate criterion combined with Bonferroni correction to set a decision threshold, constructs a binary hypothesis test to determine whether there is an attack signal at each position, and when the detected energy exceeds the threshold, it determines that there is a pilot spoofing attack, and uses the pilot sequence at that position to reconstruct the multi-dimensional spatial channel matrix of the intelligent eavesdropper, thereby realizing the active perception of the eavesdropping channel characteristics.

[0031] Step 31: Alice uses the standard pilot sequence that Bob did not use as a trap, and defines the scan space as the set of all standard shift indices that were not occupied by Bob's private shifts. Alice performs a full-domain energy scan on all time-domain sampling points of the standard shift index set. This has a linear complexity and can be implemented in real time.

[0032] Step S32: For each candidate shift index Alice calculates the pilot sequence corresponding to the shift index in the Y direction of the received signal matrix. The projected energy statistics. First, the received signal matrix is ​​right-multiplied. The conjugate transpose of the frobenius norm is then calculated to obtain the candidate shift index. Corresponding projected energy statistics: (10) This statistic reflects the position of displacement. The total energy of the signal received.

[0033] Step S33: Construct a binary hypothesis test to determine whether there are attack signals at each location.

[0034] Define the null hypothesis For any position There is no attack signal at this location; at this point, the location only contains additive white Gaussian noise. Under the assumption that, due to the private pilot and Orthogonal, and Eve did not send a signal at this location, statistic It contains only noise contributions and follows a central chi-square distribution with 2M degrees of freedom: (11) Alternative Hypothesis For any position An attack signal exists at this location, indicating that Eve is using a shift index. Send pilot signal. Statistics at this time... It follows a non-central chi-square distribution with 2M degrees of freedom: (12) in, This is a non-central parameter that reflects the energy contribution of Eve's attack signal and is proportional to the attacker's received signal-to-noise ratio (SNR). For the first Power of bar diameter, note the index. Here, it represents both the shift position and the corresponding time delay path.

[0035] To distinguish noise peaks from attack signals, the decision threshold is set using the Constant False Alarm Rate (CFAR) criterion.

[0036] Because simultaneous scanning is required To prevent the accumulation of false alarms due to multiple hypothesis testing, Bonferroni correction is used to adjust the significance level at each position. Let the required global false alarm probability of the system be... Then the threshold for a single position should satisfy: (13) Using the cumulative distribution function (CDF) of the chi-square distribution, the threshold The closed-form solution is: (14) in, It is the inverse cumulative distribution function of a chi-square distribution with 2M degrees of freedom.

[0037] For each Comparative statistics With threshold .like Then determine the shift position. Given a PSA, record the attack location and reconstruct Eve's channel estimate using the corresponding pilot sequence. The reconstruction method is as follows: (15) The channel estimation for Eve only includes Eve's real channel and noise, without any other interference.

[0038] If multiple attack locations are detected, all estimated results will be... Stacked column-wise, they form the complete Eve multidimensional spatial channel matrix: (16) If no location in the scanned space exceeds the threshold, it is determined that there is no PSA in the current time slot, and the system can use only the legal channel obtained in step S2 for regular downlink transmission.

[0039] Detection probability in this step It can be represented as: (17) in, Indicates that the non-central parameter is The chi-square distribution and cumulative distribution function.

[0040] This step transforms the standard pilot sequence into an active trap, utilizing the energy traces inevitably left by Eve during the attack to actively extract the characteristics of the eavesdropping channel. Compared to existing schemes that can only determine whether an attack has occurred but cannot obtain Eve's CSI, this step provides a precise channel information foundation for subsequent directional artificial noise design.

[0041] Step S4: The base station uses the downlink channel state information of the legitimate user obtained in step S2 and the downlink channel state information of the intelligent eavesdropper obtained in step S3 to design a data precoding matrix and an artificial noise precoding matrix. First, singular value decomposition is performed on the equivalent channel matrix of the intelligent eavesdropper to extract its null-space basis matrix, and the confidential data signal is mapped into this null space to obtain the data precoding matrix. Then, the artificial noise signal and the channel matrix of the intelligent eavesdropper are mapped into the null space of the legitimate user's channel, and the main feature direction with the strongest receiving capability of the intelligent eavesdropper is extracted to generate a directional attack matrix, so that the artificial noise energy is accurately focused on the main receiving direction of the intelligent eavesdropper to achieve directional active suppression. Finally, the confidential data signal and the artificial noise signal are superimposed to generate a downlink transmission signal and transmitted through a multi-antenna array.

[0042] Step S41: Construct the equivalent channel matrices for legitimate users and intelligent eavesdroppers respectively.

[0043] In a TDD system, the downlink channel is the transpose of the uplink channel, i.e. , For Bob and Eve, the equivalent channel matrix contains all multipath spatial features. and They are respectively: , (18) If multiple attack paths are detected, the equivalent channel matrices reconstructed from each attack location are arranged column-wise to obtain the column union of all attack path channel matrices. .

[0044] Step S42: Construct the data precoding matrix.

[0045] To completely sever Eve's reception path at the physical layer, the confidential data signal must be completely hidden within Eve's channel. Specifically, firstly, the equivalent channel matrix of Eve... Perform Singular Value Decomposition (SVD) to obtain the column union of all attack path channel matrices for Eve. : (19) in, Represents a unitary left singular matrix. Represents a singular value diagonal matrix. Describes a unitary right singular matrix. This indicates the conjugate transpose.

[0046] set up The number of non-zero singular values ​​is a scalar .extract The end Columns, construct Eve's null basis matrix .

[0047] Then, the confidential data signal is mapped into Eve's null space. Let the initial data precoding vector be of the form: (20) in, Let be the dimensionality-reduced precoding vector to be determined. Substitute it into Bob's receiver and define Bob's secure equivalent channel matrix in the secure subspace. : (twenty one) Subsequently, the dimensionality reduction Perform SVD to obtain Bob's equivalent spatial channel: (twenty two) Let the effective rank of this matrix be a scalar r. Extract The first r columns constitute the principal subspace matrix Extract the first r non-zero singular values ​​to form a square matrix. Introducing a pre-equalization operation matrix Active compensation for channel fading, original data vector The dimensionality reduction precoding vector design is as follows: (twenty three) in, .

[0048] Ultimately, the complete base station antenna transmits a confidential data vector, i.e., a private data signal. for: (twenty four) in, For power allocation factor, This represents the total power transmitted by the base station.

[0049] Step S43: Construct the artificial noise precoding matrix.

[0050] The design goal of artificial noise (AN) is to maximize the interference with Eve without disturbing Bob and all his multipath components. Specifically, Equivalent spatial channel for Bob Perform SVD, and let its effective rank be . Directly extract the last part of its right singular matrix. Columns, construct Bob's null basis matrix The null space basis matrix satisfies: .

[0051] In order to concentrate the noise energy on Eve's effective receiving direction, Eve's equivalent channel is... Projecting this onto Bob's null space yields the equivalent interference channel matrix for Eve. : (25) right Perform SVD. To maximize interference efficiency, pre-equalization inverse calculation is not performed here; instead, the pre-equalization inverse is directly extracted. The right singular vectors corresponding to the maximal singular values, i.e., the principal feature directions where Eve's reception capability is strongest, constitute the directional attack matrix. The base station generates complex Gaussian interference vectors that are independent and identically distributed. ,satisfy: .

[0052] Based on this, the final artificial noise emission vector, i.e., the artificial noise signal, is: (26) In summary, downlink transmission signal .

[0053] To further verify the effectiveness and superiority of the method described in this invention, a simulation experiment was conducted in this embodiment. The specific system simulation parameter settings and performance verification results are as follows.

[0054] In the simulation evaluation, the system adopts a quasi-static block fading channel model with multipath delay spread. The channel coefficients remain constant during the coherence time and vary independently between different blocks. The maximum multipath delay is set to L=2, and the pilot sequence length is... Basic cyclic shift step size Bob uses a pre-shared private key to randomly select a private shift value from the non-standard shift space, ensuring that it does not intersect with the standard shift set. The global false alarm probability under the constant false alarm rate criterion is set as follows: After Bonferoni correction, the single-point decision threshold is adjusted accordingly. An LLR receiver is used in the simulation to demodulate the received signal, obtaining the bit error rate (BER) performance curves for Bob and Eve under different SNR conditions. The method described in this invention is then compared with traditional artificial noise schemes.

[0055] In a specific embodiment, the core default parameters of the system are configured as follows: the number of antennas of the transmitting end Alice. Total transmit power of the base station To highlight the effectiveness of the proposed joint null space precoding and directional artificial noise scheme, three comparative scenarios were designed in the simulation experiments: Scenario 1 shows the performance curves of Bob and Eve's BER versus SNR when PSA occurs without any defense measures; Scenario 2 shows the performance curves of Bob and Eve's BER versus SNR under the proposed active defense scheme; Scenario 3 shows the comparison curves of the BER performance of the proposed scheme and the traditional artificial noise scheme (which only projects artificial noise into Bob's null space without using Eve's channel information for directional suppression) on Eve. All simulation results were statistically averaged using Monte Carlo independent channel implementation.

[0056] Figure 2 and Figure 3 The graphs showing the relationship between BER and SNR for Bob and Eve during a PSA event, assuming Alice takes no defensive measures, are presented. The antennas for Bob and Eve are configured as follows: During the uplink pilot training phase, Bob's transmit power was set to... Eve's transmit power is set to... , , and At the same SNR, as Eve's pilot transmit power increases, Eve's BER decreases significantly, while Bob's BER increases significantly. For example, at SNR=5dB, when Eve's power increases from 5dB to 20dB, Bob's BER increases from 0.4 to 0.7, while Eve's BER decreases from 1.2% to 0.7%. This trend indicates that by increasing the power of the spoofing pilot, Eve severely pollutes the uplink channel estimation, causing the base station beamforming energy to be biased towards Eve, resulting in a sharp deterioration in Bob's communication quality. On the other hand, the stronger spoofing signal allows Eve to obtain more accurate channel information, thereby enhancing its eavesdropping capability. The above results fully reveal the dual harm of PSA: high-power spoofing pilots both destroy legitimate links and empower Eve, and this damage intensifies rapidly with increasing Eve power, thus highlighting the urgency of implementing proactive defense.

[0057] Figure 4 and Figure 5 The comparison curves of BER versus SNR for the proposed active defense scheme and Bob and Eve in an undefended scenario are presented under different pilot spoofing powers. Bob's transmit power is set to... Eve's transmit power is set to... , , and At the same signal-to-noise ratio, in the undefended scenario, as Eve's pilot transmit power increases, Eve's bit error rate decreases significantly, while Bob's bit error rate increases sharply; however, under the proposed active defense scheme, regardless of... Regardless of the changes, Eve's BER remains consistently high, while Bob's BER curves largely overlap and both decrease significantly with increasing SNR. For example, at SNR=11dB, in an undefended scenario... When Bob's BER increased from 5dB to 20dB, it changed from... Seriously deteriorated to Eve's BER is Significantly reduced Scale. In contrast, under the method described in this invention, regardless of Regardless of the value, Eve's BER remains around 0.5. For Bob, under the same signal-to-noise ratio conditions, his BER consistently remains at... The method described in this invention demonstrates a superior level of performance. This trend indicates that, without defensive measures, Eve severely pollutes the uplink channel estimation of the base station through high-power pilot spoofing, successfully stealing downlink beamforming gain, destroying not only legitimate links but also significantly enhancing its own eavesdropping capabilities. However, the method described in this invention, by introducing an effective active spatial defense mechanism, completely cuts off Eve's eavesdropping path, rendering the high-power spoofing attack completely ineffective, leaving Eve in a state of complete blind guessing. This mechanism effectively eliminates beam interference from spoofing signals on legitimate links, making Bob perfectly immune to attacks of varying intensities. The above results comprehensively reveal the dual harm of pilot spoofing attacks and powerfully demonstrate the strong robustness and excellent security defense performance of this invention in dealing with high-intensity malicious attacks.

[0058] Figure 6 The comparison curves of BER versus SNR for Bob and Eve under the proposed active defense scheme and the traditional artificial noise scheme are presented. Bob's transmit power is set to... Eve's transmit power is set to... Bob and Eve's antenna configurations respectively include , and , Two scenarios. With the same antenna configuration, as the SNR increases, Eve's BER decreases significantly in the traditional approach, while Eve's BER remains stable at a high level in the method described in this invention; simultaneously, Bob's BER decreases significantly with increasing SNR in both approaches. For example, in... , With this configuration, when SNR=11dB, Eve's BER drops to [a lower value] in the traditional scheme. The BER of Eve under the active defense scheme proposed in this invention remains around 0.5. For Bob, under the same conditions, the BER of the traditional scheme is approximately... The BER of this invention is approximately This trend indicates that traditional solutions have serious security vulnerabilities under favorable channel conditions, allowing Eve to obtain more accurate signals and significantly enhance her eavesdropping capabilities. In contrast, the proactive defense scheme proposed in this invention introduces an effective spatial defense mechanism. On the one hand, it severely interferes with the eavesdropping channel, causing Eve's BER to remain consistently around 0.5, making it impossible to demodulate any useful information. On the other hand, this defense mechanism only causes a minimal compromise impact on Bob's communication quality. These results comprehensively reveal the significant advantages of the proactive defense scheme proposed in this invention: it can completely block Eve's eavesdropping link across the entire SNR range while fully ensuring the high reliability of legitimate links, thus highlighting the effectiveness and necessity of this invention in implementing physical layer security proactive defense.

[0059] Figure 7 and Figure 8 Different power allocation factors are given respectively. The simulation compares the BER of Bob and Eve in the proposed active defense scheme with the SNR in a traditional artificial noise scheme. The power allocation factors were set as follows: , and To evaluate the impact of the power allocation ratio of useful signal to artificial noise on system performance. As shown in the figure, with the increase of SNR, Eve's BER in the traditional scheme decreases significantly, and with... With the increase of AN power, meaning more power is allocated to the useful signal and less AN power, Eve's eavesdropping ability is further enhanced; and regardless of Regardless of changes in SNR, Eve's BER remains consistently around 0.5 under the active defense scheme proposed in this invention. For example, in and At that time, Eve's BER under the traditional solution had dropped to The magnitude of the problem poses a serious risk of security leakage, while Eve remains in a completely blind guess state with a BER of 0.5 under the proactive defense scheme proposed in this invention. Regarding legitimate links, Bob's BER increases with SNR and... The increase significantly decreased, in and At that point, Bob's BER under the proposed active defense scheme reached approximately The performance is extremely close to that of traditional schemes. This trend profoundly demonstrates that when traditional AN schemes suffer from channel estimation pollution caused by PSA, the generated AN fails to accurately cover the eavesdropping channel, resulting in a complete loss of security under high SNR. In contrast, the active defense scheme proposed in this invention, through a more robust spatial precoding design and accurate AN orthogonal projection, not only completely blocks Eve's information interception path but also minimizes the self-interference of the AN on legitimate channels. The above results comprehensively confirm that the proposed active defense scheme achieves absolute physical layer security suppression of Eve by introducing only a negligible trade-off in legitimate link performance, effectively overcoming the vulnerability of traditional schemes.

[0060] In summary, the pilot deception attack defense method proposed in this invention, which uses joint precoding of null space for master-spy channel, has the characteristics of unpolluted extraction of legitimate channels, active perception of eavesdropping channels, joint null space bidirectional isolation, full compatibility with existing standard systems, and significant defense effectiveness.

[0061] Finally, it should be noted that any parts of this invention not described in detail are prior art. Those skilled in the art will understand that the above descriptions are merely preferred embodiments of the invention and are not intended to limit the invention. Although the invention has been described in detail with reference to the foregoing examples, those skilled in the art can still modify the technical solutions described in the foregoing examples or make equivalent substitutions for some of the technical features. All modifications and equivalent substitutions made within the spirit and principles of the invention should be included within the scope of protection of the invention.

Claims

1. A method for defending against pilot spoofing attacks using master-stealing channel null-spatial joint precoding, characterized in that, Includes the following steps: Step S1: Private pilot allocation based on non-standard cyclic shift: The base station and the legitimate user generate a set of non-standard shift amounts through a pre-shared private key. The legitimate user uses the non-standard shift amounts to cyclically shift the Zadoff-Chu root sequence to generate private pilot sequences corresponding to each antenna, and stacks them row by row to form a private pilot signal matrix, which is then transmitted in the uplink channel. Step S2, Uncontaminated extraction of downlink channel state information of legitimate users: After receiving the pilot signal of the uplink channel, the base station projects the received signal using the locally known private pilot sequence to obtain an uncontaminated channel estimation result containing only the real legitimate channel and the equivalent noise matrix; Step S3, Active detection and extraction of downlink channel state information of intelligent eavesdroppers: First, the base station uses the standard pilot sequence as a trap to perform a full-domain energy scan on all idle standard pilot shift positions that are not occupied by the private pilots of legitimate users; Then, the projected energy statistics of the received signal at each candidate location on the corresponding standard pilot are calculated; Finally, the constant false alarm rate criterion combined with Bonferroni correction is used to set the decision threshold. A binary hypothesis test is constructed to determine whether there is an attack signal at each position. When the detected energy exceeds the threshold, it is determined that there is a pilot spoofing attack. The pilot sequence at that position is used to reconstruct the multi-dimensional spatial channel matrix of the intelligent eavesdropper, so as to realize the active perception of the eavesdropping channel characteristics. Step S4: The base station uses the downlink channel state information of the legitimate user obtained in step S2 and the downlink channel state information of the intelligent eavesdropper obtained in step S3 to design the data precoding matrix and the artificial noise precoding matrix: First, singular value decomposition is performed on the equivalent channel matrix of the intelligent eavesdropper to extract its null space basis matrix, and the confidential data signal is mapped into the null space to obtain the data precoding matrix. Subsequently, the artificial noise signal and the channel matrix of the intelligent eavesdropper are mapped onto the null space of the legitimate user channel, and the main feature direction with the strongest receiving capability of the intelligent eavesdropper is extracted to generate a directional attack matrix, so that the artificial noise energy is precisely focused on the main receiving direction of the intelligent eavesdropper, thereby achieving directional active suppression; finally, the confidential data signal is superimposed with the artificial noise signal to generate a downlink transmission signal and transmit it through a multi-antenna array.

2. The pilot spoofing attack defense method based on master channel null joint precoding according to claim 1, characterized in that, The specific process of generating the private pilot sequence in step S1 includes: The base station and the authorized user share a private key K in advance. The authorized user uses the pre-shared private key to generate a set of private shift values. ,in The number of antennas for legitimate users; The private shift amount satisfies: In the formula, denotes the pilot length, denotes the base cyclic shift step size, denotes the standard shift index, denotes the maximum multipath delay length; Based on this, the first element of the private pilot sequence of the legitimate user is expressed as: ​ In the formulae, denotes a modulo operation.

3. The pilot spoofing attack defense method of primary wiretapper channel null space joint precoding according to claim 2, characterized in that, The base cyclic shift step size satisfies: .

4. The pilot spoofing attack defense method of primary wiretapper channel null space joint precoding according to claim 1, characterized in that, The downlink channel state information of the legitimate user in step S2 is represented as follows: wherein: denotes the real legitimate channel, denotes the equivalent noise matrix.

5. The pilot spoofing attack defense method based on master channel null joint precoding according to claim 1, characterized in that, The specific steps of step S3 include: Step S31, the base station defines a scanning space as a set of standard shift indexes occupied by all standard pilot sequences not used by legal users , the base station performs full-energy scanning on all time-domain sampling points of the set of standard shift indexes; Step S32: For each candidate shift index The base station calculates the pilot sequence corresponding to the shift index in the Y direction of the received signal matrix. Projected energy statistics: In the formula, denotes the average transmit power of a legitimate user; Step S33: Construct a binary hypothesis test to determine whether there are attack signals at each location; Define the null hypothesis For any position There is no attack signal at this location; at this point, the location only contains additive white Gaussian noise. It follows a central chi-square distribution with 2M degrees of freedom: alternative hypothesis for any position presence of an attack signal, the statistic obeys a non-central chi-square distribution with 2M degrees of freedom: wherein is a non-central parameter, is the power of the bin; denotes the average transmit power of Eve. The decision threshold is set using a constant false alarm rate combined with Bonferroni correction. wherein, is the inverse cumulative distribution function of the chi-squared distribution of degrees of freedom 2M, P FA is a preset global false alarm probability; When the shift position There is a pilot spoofing attack, record the attack position and use the corresponding pilot sequence to reconstruct Eve's channel estimate: If multiple attack locations are detected, all estimates are combined Stacked by column, resulting in the full smart eavesdropper multi-dimensional space channel matrix: .

6. The pilot spoofing attack defense method of primary wiretapper channel null space joint precoding according to claim 1, characterized in that, The data precoding matrix in step S4 for: wherein is a power allocation factor, is the total power transmitted by the base station, is a null space basis matrix for the intelligent eavesdropper, is a main subspace matrix, is a pre-equalization operation matrix, is an original data vector.

7. The pilot spoofing attack defense method of primary wiretapper channel null space joint precoding according to claim 1, characterized in that, The artificial noise signal in the step S4 is: wherein denotes a zero space basis matrix of legitimate users, denotes a directional strike matrix, denotes a complex Gaussian interference vector.