A Real-Time Source Tracing Method and System for Spectrum Occupation Signals Based on Modulation Fingerprinting

CN122554953APending Publication Date: 2026-08-11UNIT 75841 OF THE PEOPLES LIBERATION ARMY OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-05-14
Publication Date
2026-08-11

AI Technical Summary

Technical Problem

[0006]针对现有技术的以上缺陷或改进需求,本发明提供了基于调制指纹的频谱占用信号实时溯源方法及系统,解决了现有技术中通常采用能量检测或常规频谱监测进行非法信号定位,导致定位精度容易受多径效应与地形遮蔽影响,进而影响频谱执法效率与现场处置准确性的问题

Benefits of technology

[0026]本发明实施例提供的方案中,通过在监测区域部署包含中心处理站和P个机动监测站的协同监测网络,并依托无线通信专网建立网络协同机制,实现了边缘节点与中心节点的紧密联动,有效降低了中心站对海量无关数据的处理负担。随后,中心处理站接收第一机动监测站回传的首发事件告警,立即触发对剩余P-1个机动监测站的边缘级同步监测,通过统一模板驱动的信号关联性验证,精准获取Q个通过同源性确认的伴随事件告警,从而确保了后续定位输入信号的信号同源性与可靠性。基于首发与伴随事件告警中的时域信号进行TDOA时延估计,不仅获得了高精度的初始信号源位置,还通过联合信号分析提取了包含调制指纹在内的信号特征摘要,为身份溯源提供了唯一性凭据。进一步结合监测区域的数字高程地图数据,对初始信号源位置实施基于射线追踪的地形遮蔽校正,有效消除了多径与非视距传播造成的定位偏差,显著提升了复杂地形下的定位精度,同时输出对应的置信度评估值,量化了校正结果的可信程度。以校正后的信号源大地经纬度坐标为中心,依据置信度评估值动态构建频谱执法地理围栏,置信度高时围栏半径精确聚焦,置信度低时适当扩大覆盖范围,从而在保证执法针对性的同时避免漏检,优化了现场执法资源的空间分配效率。最终,将动态频谱执法地理围栏、信号特征摘要、信号源大地经纬度坐标及置信度评估值融合封装为完整的溯源结果,发送至上级指挥云端,实现了从信号发现、身份识别、精准定位到执法边界划定的全链路闭环,使上级指挥云端可直接据此下达执法决策,大幅提升了频谱占用信号实时溯源的响应速度与监管效能。达到了提升定位精度和执法响应速度的同时,保障执法资源空间分配合理性的效果。当然,实施本发明的任一产品或方法并不一定需要同时达到以上所述的所有优点。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122554953A_ABST
    Figure CN122554953A_ABST
Patent Text Reader

Abstract

This invention provides a method and system for real-time tracing of spectrum occupancy signals based on modulation fingerprinting, relating to the field of radio spectrum monitoring technology. The method includes: within a collaborative network, a central processing station receives the initial event alarm and triggers edge monitoring of P-1 stations, acquiring Q accompanying event alarms. Based on the alarms, TDOA delay estimation is performed to obtain the initial signal source location and signal feature summary. Ray-tracing terrain occupancy correction is performed using a digital elevation map to obtain the signal source coordinates and confidence level assessment. A dynamic spectrum enforcement geofence is constructed using these coordinates as the center and based on the confidence level. The geofence, signal feature summary, coordinates, and confidence level assessment are fused and sent to the upper-level command cloud as the tracing result. This solves the problem in existing technologies where energy detection or conventional spectrum monitoring is typically used for illegal signal location, leading to positioning accuracy being easily affected by multipath effects and terrain occupancy, thus impacting spectrum enforcement efficiency and on-site handling accuracy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of radio spectrum monitoring technology, and in particular to a method and system for real-time tracing of spectrum occupancy signals based on modulation fingerprints. Background Technology

[0002] Currently, the source tracing of civilian spectrum occupancy signals mainly relies on energy detection and conventional spectrum monitoring. Energy detection only determines the presence of a signal based on a power threshold and cannot identify the identity of the transmitting source. In complex electromagnetic environments with overlapping signals, it is easy to misidentify legitimate signals as illegitimate sources, resulting in a high false alarm rate. While conventional monitoring can provide coarse-grained information such as center frequency, its positioning capability is limited by the distance between stations and lacks compensation mechanisms for multipath propagation and terrain masking. In scenarios such as urban canyons, non-line-of-sight propagation can severely reduce the accuracy of time delay estimation, leading to large-scale deviations in positioning results.

[0003] Furthermore, the lack of correlation verification based on the inherent characteristics of signals between different monitoring stations makes it difficult to accurately match signals from the same source, further amplifying the positioning error.

[0004] The aforementioned problems ultimately lead to a high risk of identity misjudgment, positioning accuracy being easily affected by multipath and terrain, and difficulty in accurately correlating signals from the same source, which seriously restricts the efficiency of law enforcement and the accuracy of on-site handling.

[0005] It should be noted that the information disclosed in this background section is intended only to enhance the understanding of the overall background of the invention and should not be construed as an admission or in any way implying that the information constitutes prior art known to those skilled in the art. Summary of the Invention

[0006] To address the aforementioned deficiencies or improvement needs of existing technologies, this invention provides a method and system for real-time tracing of spectrum occupancy signals based on modulation fingerprints. This solves the problem that existing technologies typically employ energy detection or conventional spectrum monitoring for illegal signal location, leading to positioning accuracy being easily affected by multipath effects and terrain obstruction, thus impacting the efficiency of spectrum-based law enforcement and the accuracy of on-site handling. It achieves the effect of improving positioning accuracy and law enforcement response speed while ensuring the rational allocation of law enforcement resources. The specific technical solution is as follows:

[0007] According to a first aspect of the present invention, a real-time source tracing method for spectral occupancy signals based on modulation fingerprints is provided, the method comprising:

[0008] A collaborative monitoring network is deployed in the monitoring area, comprising a central processing station and P mobile monitoring stations. The central processing station establishes a network collaboration mechanism with the P mobile monitoring stations via a dedicated wireless communication network. The central processing station receives the initial event alarm transmitted from the first mobile monitoring station, triggering edge-level synchronous monitoring of P-1 mobile monitoring stations to obtain Q accompanying event alarms transmitted from Q mobile monitoring stations, where Q ≥ 2 and Q ≤ P. Based on the initial event alarm and the Q accompanying event alarms, TDOA delay estimation is performed to obtain the initial signal source location and signal feature summary. Combining the digital elevation map data of the monitoring area, terrain masking correction based on ray tracing is performed on the initial signal source location to obtain the geodetic latitude and longitude coordinates of the signal source and the corresponding confidence assessment value. A dynamic spectrum law enforcement geofence is constructed centered on the geodetic latitude and longitude coordinates of the signal source and based on the confidence assessment value. The dynamic spectrum law enforcement geofence, signal feature summary, geodetic latitude and longitude coordinates of the signal source, and confidence assessment value are fused and sent to the upper-level command cloud as the source tracing result.

[0009] In one implementation, based on the initial event alarm and Q accompanying event alarms, TDOA delay estimation is performed to obtain the initial signal source location and signal feature summary, and the following processing is also performed:

[0010] The initial time-domain signal and Q accompanying time-domain signals are extracted from the initial event alarm and Q accompanying event alarms, respectively. After time-domain alignment of the initial time-domain signal and the Q accompanying time-domain signals, the first mobile monitoring station is used as a reference station. The initial time-domain signal is cross-correlated with the Q accompanying time-domain signals to obtain Q cross-correlation functions. The Q cross-correlation functions are then used for peak detection-based time delay estimation to locate Q TDOA values. Using the Q TDOA values ​​as observation inputs, and combined with the Q three-dimensional coordinates of the Q mobile monitoring stations, a hyperbolic positioning equation is constructed and solved to obtain the initial signal source location. A high-dimensional modulation fingerprint feature vector is extracted from the initial event alarm. Combined with the time-aligned initial time-domain signal and Q accompanying time-domain signals, joint signal analysis is performed to extract global signal feature parameters and generate the signal feature summary.

[0011] In one implementation, using the Q TDOA values ​​as observation inputs and combining them with the Q three-dimensional coordinates of the Q mobile monitoring stations, a hyperbolic positioning equation is constructed and solved to obtain the initial signal source location. The following processing is then performed:

[0012] The Q TDOA values ​​are converted into Q distance difference observations; taking the first mobile monitoring station as the reference station and the Q distance difference observations as constants, a nonlinear hyperbolic equation system is constructed by combining the Q three-dimensional coordinates and the first three-dimensional coordinates of the first mobile monitoring station; the nonlinear hyperbolic equation system is linearized to generate a linear observation equation system; the linear observation equation system is iteratively solved using the weighted least squares estimation method until convergence, and the initial signal source position is output.

[0013] In one embodiment, the mobile monitoring station is equipped with a multi-channel parallel acquisition architecture, which includes a multi-channel radio frequency receiver and a high-speed ADC.

[0014] In one implementation, the following processing is also performed:

[0015] After receiving signals from the preset target frequency band via the multi-channel radio frequency receiver, the first mobile monitoring station uses the high-speed ADC to perform bandpass sampling and digital quadrature demodulation on the received signals to obtain a first baseband I / Q data stream. The first baseband I / Q data stream is then subjected to local two-stage filtering to obtain the signal segment to be analyzed. A deep analysis of the cyclostationary characteristics of the signal segment to be analyzed is performed to extract subtle modulation features and construct a high-dimensional modulation fingerprint feature vector. If the result of local comparison of the high-dimensional modulation fingerprint feature vector with the modulation fingerprint database indicates an unregistered signal, then the high-dimensional modulation fingerprint feature vector and the initial time-domain signal of the signal segment to be analyzed are packaged together as the initial event alarm and uploaded to the central processing station.

[0016] In one implementation, the central processing station receives the initial event alarm transmitted back from the first mobile monitoring station, triggers edge-level synchronous monitoring of P-1 mobile monitoring stations, acquires Q accompanying event alarms transmitted back from Q mobile monitoring stations, and further performs the following processing:

[0017] The central processing station receives and parses the initial event alarm to obtain the high-dimensional modulation fingerprint feature vector and the initial time-domain signal. Based on the first start time and first duration contained in the initial time-domain signal, a collaborative backtracking time window is constructed. The central processing station sends the collaborative backtracking time window and the high-dimensional modulation fingerprint feature vector to the P-1 mobile monitoring stations. The P-1 mobile monitoring stations perform deep analysis of the cyclostationary characteristics based on signal data backtracking retrieval according to the collaborative backtracking time window, obtain P-1 node modulation fingerprint feature vectors, compare them with the high-dimensional modulation fingerprint feature vectors, and perform signal correlation verification to obtain Q accompanying time-domain signals of Q mobile monitoring stations. The Q mobile monitoring stations use the Q accompanying time-domain signals as the payload of the Q accompanying event alarms and transmit them back to the central processing station.

[0018] In one implementation, the first baseband I / Q data stream is subjected to local two-stage filtering to obtain the signal segment to be analyzed, and the following processing is also performed:

[0019] Based on a preset time window length and sliding step size, the first baseband I / Q data stream is segmented by a sliding window to obtain multiple continuous signal segments; multiple segment kurtosis values ​​of the multiple continuous signal segments are calculated, and a first-level filter is performed by comparing them with a preset kurtosis threshold to select and retain H potential useful signal segments; H power spectral entropies of the H potential useful signal segments are calculated, and a second-level filter is performed by comparing them with a preset spectral entropy threshold to select and retain the signal segments to be analyzed.

[0020] In one implementation, the signal segment to be analyzed undergoes in-depth analysis of its cyclostationary characteristics to extract subtle modulation features, constructs a high-dimensional modulation fingerprint feature vector, and further performs the following processing:

[0021] Calculate the cyclic autocorrelation function and spectral correlation density function of the signal segment to be analyzed; extract multiple cyclic frequency domain statistical features and multiple spectral correlation structural features from the cyclic autocorrelation function and spectral correlation density function respectively; perform cross-source feature-level fusion on the multiple cyclic frequency domain statistical features and multiple spectral correlation structural features, construct feature vectors, and output the high-dimensional modulation fingerprint feature vector.

[0022] According to a second aspect of the present invention, a real-time source tracing system for spectrum occupancy signals based on modulation fingerprints is provided, the system comprising:

[0023] A collaborative network deployment module is used to deploy a collaborative monitoring network in the monitoring area. The collaborative monitoring network includes a central processing station and P mobile monitoring stations. The central processing station establishes a network collaboration mechanism with the P mobile monitoring stations via a dedicated wireless communication network. A collaborative monitoring triggering module is used by the central processing station to receive the initial event alarm transmitted from the first mobile monitoring station, triggering edge-level synchronous monitoring of P-1 mobile monitoring stations, and acquiring Q accompanying event alarms transmitted from Q mobile monitoring stations, where Q ≥ 2 and Q ≤ P. A TDOA delay estimation module is used to perform TDOA based on the initial event alarm and the Q accompanying event alarms. The system includes a time delay estimation module to obtain the initial signal source location and signal feature summary; a terrain masking correction module to perform ray tracing-based terrain masking correction on the initial signal source location using digital elevation map data of the monitoring area, obtaining the geodetic latitude and longitude coordinates of the signal source and the corresponding confidence assessment value; a dynamic geofencing module to construct a dynamic spectrum enforcement geofencing centered on the geodetic latitude and longitude coordinates of the signal source and based on the confidence assessment value; and a source tracing result fusion module to fuse the dynamic spectrum enforcement geofencing, signal feature summary, geodetic latitude and longitude coordinates of the signal source, and confidence assessment value, sending the result to the upper-level command cloud.

[0024] According to a third aspect of the present invention, an electronic device is provided, the electronic device comprising: a memory for storing executable instructions; and a processor for implementing the real-time tracing method of spectrum occupancy signal based on modulation fingerprint in the first aspect when executing the executable instructions stored in the memory.

[0025] Beneficial effects of the embodiments of the present invention:

[0026] In the solution provided by this invention, a collaborative monitoring network comprising a central processing station and P mobile monitoring stations is deployed in the monitoring area. A network collaboration mechanism is established based on a dedicated wireless communication network, enabling close linkage between edge nodes and the central node. This effectively reduces the processing burden on the central station for massive amounts of irrelevant data. Subsequently, the central processing station receives the initial event alarm transmitted from the first mobile monitoring station and immediately triggers edge-level synchronous monitoring of the remaining P-1 mobile monitoring stations. Through signal correlation verification driven by a unified template, Q accompanying event alarms confirmed by homology are accurately obtained, thus ensuring the signal homology and reliability of subsequent positioning input signals. Based on the time-domain signals in the initial and accompanying event alarms, TDOA delay estimation is performed, not only obtaining a high-precision initial signal source location but also extracting a signal feature summary, including modulation fingerprints, through joint signal analysis, providing unique credentials for identity tracing. By further integrating digital elevation map data of the monitored area, terrain masking correction based on ray tracing was applied to the initial signal source location. This effectively eliminated positioning deviations caused by multipath and non-line-of-sight propagation, significantly improving positioning accuracy in complex terrain. Simultaneously, a corresponding confidence assessment value was output, quantifying the reliability of the correction results. Using the corrected geodetic coordinates of the signal source as the center, a spectrum enforcement geofence was dynamically constructed based on the confidence assessment value. When the confidence level was high, the fence radius was precisely focused; when the confidence level was low, the coverage area was appropriately expanded. This ensured targeted enforcement while avoiding missed detections, optimizing the spatial allocation efficiency of on-site enforcement resources. Finally, the dynamic spectrum enforcement geofence, signal feature summary, signal source geodetic coordinates, and confidence assessment value were integrated and packaged into a complete source tracing result, which was sent to the higher-level command cloud. This achieved a closed-loop process from signal discovery, identification, precise positioning to enforcement boundary delineation, enabling the higher-level command cloud to directly issue enforcement decisions based on this information, significantly improving the response speed and regulatory efficiency of real-time spectrum occupancy signal source tracing. This achieves the effect of improving positioning accuracy and law enforcement response speed while ensuring the rational allocation of law enforcement resources. Of course, implementing any product or method of this invention does not necessarily require achieving all of the advantages described above simultaneously. Attached Figure Description

[0027] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0028] Figure 1 The flowchart of the real-time source tracing method for spectrum occupancy signals based on modulation fingerprints provided by the present invention is shown.

[0029] Figure 2 This invention provides a schematic diagram of the structure of a real-time spectrum occupancy signal tracing system based on modulation fingerprinting.

[0030] Figure 3 A schematic diagram of the structure of an exemplary electronic device provided by the present invention is shown.

[0031] Figure labeling: 1. Collaborative network deployment module; 2. Collaborative monitoring triggering module; 3. TDOA latency estimation module; 4. Terrain occlusion correction module; 5. Dynamic geofencing module; 6. Source tracing result fusion module; 7. Bus 500; 8. Receiver 501; 9. Processor 502; 10. Transmitter 503; 11. Memory 504; 12. Bus interface 505. Detailed Implementation

[0032] To facilitate understanding of the present invention, a more complete description of the invention will be given below with reference to the accompanying drawings, which illustrate preferred embodiments of the invention. However, the invention can be implemented in many different forms and is not limited to the embodiments described herein; rather, these embodiments are provided to enable a more thorough and complete understanding of the disclosure of the invention.

[0033] Furthermore, the technical features involved in the various embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.

[0034] In the description of this invention, it should be understood that the terms "center," "longitudinal," "lateral," "length," "width," "thickness," "upper," "lower," "front," "rear," "left," "right," "vertical," "horizontal," "top," "bottom," "inner," "outer," "clockwise," and "counterclockwise," etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are only for the convenience of describing this invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on this invention.

[0035] Unless otherwise expressly stated, throughout the specification and claims, the term "comprising" or its variations such as "including" or "comprises" shall be understood to include the stated elements or components without excluding other elements or other components.

[0036] The present invention provides a method and system for real-time tracing of spectrum occupancy signals based on modulation fingerprints, which is used to solve the problem that the existing technology usually uses energy detection or conventional spectrum monitoring to locate illegal signals, which makes the positioning accuracy easily affected by multipath effects and terrain masking, thus affecting the efficiency of spectrum law enforcement and the accuracy of on-site handling.

[0037] Example 1: See Figure 1 The flowchart of the real-time source tracing method for spectrum occupancy signals based on modulation fingerprints provided in this embodiment of the invention includes:

[0038] Step S100: Deploy a collaborative monitoring network in the monitoring area, wherein the collaborative monitoring network includes a central processing station and P mobile monitoring stations, wherein the central processing station establishes a network collaboration mechanism with the P mobile monitoring stations through a private wireless communication network.

[0039] In one implementation, the mobile monitoring station is equipped with a multi-channel parallel acquisition architecture, which includes a multi-channel radio frequency receiver and a high-speed ADC.

[0040] Specifically, in this embodiment, a collaborative monitoring network is constructed within a specific geographical area of ​​the monitoring region. The monitoring network consists of two core nodes: a central processing station that plays the role of command and data processing, and P mobile monitoring stations. P is a positive integer variable with a minimum of 3, representing the number of mobile monitoring stations that may exist in the monitoring network. The dispersed mobile monitoring stations and the central processing station are connected through a dedicated wireless communication network.

[0041] This embodiment establishes an independent wireless data link with specific quality of service guarantees for the monitoring network, so as to ensure that the central processing station can establish a network coordination mechanism with all mobile monitoring stations, and ensure that the command issuance and data transmission between the central processing station and all mobile monitoring stations can be carried out in an orderly and reliable manner.

[0042] It should also be understood that the central processing station and the P mobile monitoring stations in this embodiment are essentially a specific implementation of cloud-edge fusion technology. The mobile monitoring stations function as edge nodes, responsible for locally receiving and processing signals in the preset target frequency band and making preliminary judgments on unregistered signals. The central processing station functions as a central cloud node, responsible for aggregating collaborative data from the mobile monitoring stations, performing multi-point positioning calculations, and generating the final source tracing results. The collaborative workflow and internal processing mechanisms of the central processing station and the P mobile monitoring stations will be described in detail in the subsequent description.

[0043] The mobile monitoring station's signal receiving front-end is designed with a multi-channel parallel acquisition architecture, capable of simultaneously processing multiple signals of different frequencies, and possessing wide-band, high-efficiency signal acquisition capabilities. This multi-channel parallel acquisition architecture comprises two key components: first, a multi-channel RF receiver that receives weak radio signals from a preset target frequency band in space and performs front-end processing such as amplification and filtering; and second, a high-speed ADC (analog-to-digital converter), used to sample and quantize the analog signals processed by the multi-channel RF receiver at extremely high rates, converting them into digital signals that can be processed by a computer or digital processor.

[0044] The specific application details of the multi-channel RF receiver and high-speed ADC in the signal processing flow will be described in detail in the following description.

[0045] In one implementation, the method step S200 provided by the present invention further includes:

[0046] Step S201: After the first mobile monitoring station receives the signal from the preset target frequency band through the multi-channel radio frequency receiver, it uses the high-speed ADC to perform bandpass sampling and digital quadrature demodulation on the received signal to obtain the first baseband I / Q data stream.

[0047] Step S202: Perform local two-stage filtering on the first baseband I / Q data stream to obtain the signal segment to be analyzed.

[0048] Step S203: Perform in-depth analysis of the cyclic stationary characteristics of the signal segment to be analyzed, extract subtle modulation features, and construct a high-dimensional modulation fingerprint feature vector.

[0049] Step S204: If the result of identity verification by comparing the high-dimensional modulated fingerprint feature vector locally with the modulated fingerprint database is an unregistered signal, then the high-dimensional modulated fingerprint feature vector and the first time domain signal of the signal segment to be analyzed are packaged as the first event alarm and uploaded to the central processing station.

[0050] Specifically, in this embodiment, the first mobile monitoring station is any one of the P mobile monitoring stations, and in the current real-time spectrum monitoring scenario, the first mobile monitoring station is the first monitoring station to identify the unregistered signal.

[0051] The multi-channel radio frequency receiver inside the first mobile monitoring station continuously receives radio signals from a pre-set target frequency band. The pre-set target frequency band is determined based on spectrum regulatory requirements or mission planning strategies, for example, focusing on frequency ranges suspected of containing illegal signals.

[0052] The radio frequency signal received by the multi-channel radio frequency receiver is a weak analog signal, which needs to pass through low-noise amplification, bandpass filtering and other front-end processing stages in sequence to suppress out-of-band interference and improve the signal-to-noise ratio. The analog signal after front-end processing is fed to a high-speed ADC, i.e., an analog-to-digital converter, to perform bandpass sampling.

[0053] The bandpass sampling operation allows for the direct digitization of front-end processed analog signals at intermediate frequency or radio frequency at a sampling rate less than twice the highest frequency of the signal. This significantly reduces the data throughput requirements of subsequent digital processors without losing effective information. After the sampling process is completed, a discrete digital signal stream is obtained.

[0054] The discrete digital signal stream then enters the digital quadrature demodulation stage, where two mutually orthogonal baseband components are separated from the digitized sinusoidal modulation signal. These are called the in-phase component and the quadrature component, i.e., the I component and the Q component, respectively. In this embodiment, the two component data together constitute the first baseband I / Q data stream. The first baseband I / Q data stream completely preserves the amplitude and phase information of the original signal, serving as the basic input for all subsequent digital signal processing procedures.

[0055] It should be understood that the cyclostationary characteristic refers to the inherent property of the statistics of artificially modulated signals to change periodically over time. Its periodicity originates from the modulation format itself and the combined effects of non-ideal hardware at the transmitter front end, such as nonlinear distortion of the power amplifier, phase noise of the local oscillator signal, and quantization error of the digital-to-analog converter.

[0056] This embodiment first calculates the cyclic autocorrelation function and spectral correlation density function of the signal segment to be analyzed. The cyclic autocorrelation function reveals the dual-periodic correlation of the signal segment to be analyzed in the time delay domain and the cyclic frequency domain, and can capture the time-domain statistical periodicity caused by modulation period and hardware defects. The spectral correlation density function, by performing a Fourier transform on the cyclic autocorrelation function, presents the cyclic coupling relationship between the signal spectral components, and shows the unique pattern of modulation fingerprint from the frequency domain perspective.

[0057] Multiple cyclic frequency domain statistical features are extracted from the cyclic autocorrelation function, such as the cyclic spectral line intensity at the symbol rate and its overtones, the cyclic frequency spectral peak sharpness, and the spectral line symmetry; multiple spectral correlation structural features are extracted from the spectral correlation density function, such as the peak distribution pattern, peak morphology, and contour line density on the spectral correlation plane.

[0058] The two types of feature parameters from different transform domains are fused at the cross-source feature level, that is, integrated into a unified feature set according to a preset strategy, and then vectorized according to a fixed dimension order to output the high-dimensional modulation fingerprint feature vector.

[0059] Due to its high dimensionality and multi-source information fusion characteristics, the high-dimensional modulated fingerprint feature vector has extremely high device distinguishability, which is sufficient to identify subtle hardware differences between different individuals of the same model, providing a unique basis for subsequent identity determination.

[0060] It should be understood that each mobile monitoring station has a local pre-stored modulation fingerprint database of registered and legitimate transmission equipment. This modulation fingerprint database is constructed through prior collection and matching training and contains feature vectors of all approved spectrum-using equipment.

[0061] The high-dimensional modulated fingerprint feature vector output in step S203 is compared with all the registered fingerprints in the modulated fingerprint database one by one to measure the similarity. For example, algorithms such as cosine similarity or Euclidean distance are used to calculate the degree of matching between the vectors.

[0062] If the similarity between the high-dimensional modulated fingerprint feature vector and any known fingerprint in the database is lower than the preset identity discrimination threshold, then the transmitting device corresponding to the signal is determined to be an unregistered signal source, i.e. a potential illegal or unknown interference source.

[0063] Once the identity verification result is an unregistered signal, the first mobile monitoring station immediately initiates the packaging and uploading process. Specifically, the high-dimensional modulated fingerprint feature vector is used as the identity verification credential, and together with the first time domain signal in the signal segment to be analyzed (i.e., the original waveform data retained after double-level filtering), they are packaged into the first event alarm.

[0064] The initial event alarm message is uploaded to the central processing station in real time via a private wireless communication network, thereby triggering the network-level collaborative monitoring and positioning process initiated by the central processing station in subsequent steps.

[0065] The local discrimination mechanism in this embodiment effectively reduces the data processing pressure on the central processing station, realizes the efficient combination of edge computing and collaborative positioning, and ensures that the system can respond quickly and accurately trace illegal signals in complex electromagnetic environments.

[0066] Step S200: The central processing station receives the first event alarm returned by the first mobile monitoring station, triggers edge-level synchronous monitoring of P-1 mobile monitoring stations, and obtains Q accompanying event alarms returned by Q mobile monitoring stations, where Q≥2 and Q≤P.

[0067] In one implementation, the central processing station receives the initial event alarm transmitted back from the first mobile monitoring station, triggers edge-level synchronous monitoring of P-1 mobile monitoring stations, and acquires Q accompanying event alarms transmitted back from Q mobile monitoring stations. Step S200 of the method provided by this invention further includes:

[0068] Step S210: The central processing station receives and parses the first event alarm to obtain the high-dimensional modulated fingerprint feature vector and the first time domain signal.

[0069] Step S220: Construct a collaborative backtracking time window based on the first start time and the first duration contained in the initial time domain signal.

[0070] Step S230: The central processing station sends the collaborative backtracking time window and the high-dimensional modulated fingerprint feature vector to the P-1 mobile monitoring stations.

[0071] Step S240: The P-1 mobile monitoring stations perform deep analysis of cyclic stationarity characteristics based on signal data backtracking retrieval according to the collaborative backtracking time window, and obtain P-1 node modulation fingerprint feature vectors. Then, they compare the high-dimensional modulation fingerprint feature vectors to perform signal correlation verification, and obtain Q accompanying time-domain signals of Q mobile monitoring stations.

[0072] Step S250: The Q mobile monitoring stations transmit the Q accompanying time-domain signals as the payloads of the Q accompanying event alarms back to the central processing station.

[0073] Specifically, in this embodiment, after the central processing station receives the first event alarm transmitted back by the first mobile monitoring station through the wireless communication private network, it immediately performs protocol-level parsing on the data packet of the first event alarm to separate two core information elements.

[0074] The first element is a high-dimensional modulated fingerprint feature vector that carries the hardware fingerprint recognition function of the signal transmitting equipment. This vector is calculated locally at the first mobile monitoring station through in-depth analysis of cyclic stationary characteristics and constructed in a cross-source feature-level fusion manner, and has the ability to uniquely identify the signal source.

[0075] The second element is the initial time-domain signal, which is the original waveform data of the unregistered signal selected after local two-stage filtering in the aforementioned steps. This signal segment records the complete amplitude and phase information of the target signal in the time domain. The extraction of the high-dimensional modulation fingerprint feature vector and the initial time-domain signal provides an accurate basis for the central processing station to subsequently initiate network-level collaborative timing scheduling and signal source identification.

[0076] The central processing station reads two embedded metadata fields from the initial time-domain signal extracted in step S210: the first start time of the signal when it was captured locally and the first duration of the signal's continuous waveform. The first start time and the first duration precisely define the start and end positions of the target signal on the absolute time axis.

[0077] Based on the first start time and the first duration, the central processing station constructs a collaborative backtracking time window. The starting point of the collaborative backtracking time window is equal to the first start time minus a preset allowable delay margin, and the ending point is equal to the first start time plus the first duration plus the preset allowable delay margin, thereby ensuring that the arrival time offset of the target signal may be caused by the distance difference between each station during the spatial propagation process.

[0078] The construction of the collaborative backtracking time window provides a unified spatiotemporal coordinate for each mobile monitoring station to retrieve signal data for a specific time period from its local continuous signal buffer.

[0079] The central processing station encapsulates the collaborative backtracking time window constructed in step S220 and the high-dimensional modulated fingerprint feature vector extracted in step S210 as a comparison template into a downlink control command according to a preset network communication protocol, and sends it in real time to all P-1 mobile monitoring stations except the first alarm station via the wireless communication private network.

[0080] After receiving and parsing the instruction, P-1 mobile monitoring stations can obtain two key pieces of information. The first is the time range from which the signal data needs to be retrieved from the local cache, that is, the precise time period specified by the collaborative backtracking time window; the second is the target fingerprint feature used for signal homology verification, that is, the high-dimensional modulation fingerprint feature vector issued by the central station.

[0081] Based on the received collaborative backtracking time window, P-1 mobile monitoring stations accurately retrieve the original intermediate frequency or radio frequency signal data within the corresponding time range from their local continuous signal buffers. Subsequently, each P-1 mobile monitoring station independently performs the same signal processing chain as the first alarm station on the backtracked signal data, including in-depth analysis of cyclostationary characteristics, i.e., calculating the cyclic autocorrelation function and spectral correlation density function of the signal, extracting subtle modulation features, and finally constructing the node modulation fingerprint feature vector of each station.

[0082] After feature extraction, P-1 mobile monitoring stations perform similarity measurements between their calculated modulation fingerprint feature vectors and the high-dimensional modulation fingerprint feature vectors sent by the central processing station as comparison templates. This measurement process is achieved through mathematical operations such as calculating the cosine distance or Euclidean distance between the two vectors. This comparison operation is the signal correlation verification. Only stations whose modulation fingerprint feature vectors and template vectors have a similarity exceeding a preset correlation threshold are considered to have successfully captured a signal originating from the same source as the first alarm signal.

[0083] After independent verification by all P-1 mobile monitoring stations, it was finally determined that the signals of Q mobile monitoring stations passed the correlation verification. Each of these stations obtained a time-domain signal that was strictly homologous to the initial event alarm signal.

[0084] This embodiment adopts a unified template-driven edge-level verification mode, which fundamentally ensures the consistency of signals from each station participating in the subsequent positioning calculation at the cyclic stationarity feature level, and avoids erroneous or missed associations introduced by each station independently setting its decision criteria.

[0085] The Q mobile monitoring stations that have passed the signal correlation verification use their respective acquired time-domain signals as the core payload for accompanying event alarms. At the same time, they attach accurate local capture timestamps and station 3D coordinates and other auxiliary metadata to the alarm data packet and encapsulate it into an accompanying event alarm frame that conforms to the network communication protocol.

[0086] Subsequently, the Q mobile monitoring stations transmit the accompanying event alarm frames back to the central processing station via a dedicated wireless communication network through a network collaboration mechanism.

[0087] The central processing station ultimately gathers Q accompanying event alarms, which carry waveform data of the same source signal from different spatial locations and location information of each station. These data constitute all the observation inputs required for high-precision TDOA time delay estimation and signal source localization, providing multi-station signal data support with strict source correlation for subsequent calculation of the initial signal source location through hyperbolic positioning equation.

[0088] Step S300: Based on the initial event alarm and Q accompanying event alarms, perform TDOA delay estimation to obtain the initial signal source location and signal feature summary.

[0089] In one implementation, TDOA delay estimation is performed based on the initial event alarm and Q accompanying event alarms to obtain the initial signal source location and signal feature summary. Step S300 of the method provided by this invention further includes:

[0090] Step S310: Extract the initial time-domain signal and the Q accompanying time-domain signals from the initial event alarm and the Q accompanying event alarms, respectively.

[0091] Step S320: After aligning the initial time-domain signal and the Q accompanying time-domain signals in the time domain, using the first mobile monitoring station as the reference station, perform cross-correlation calculations on the initial time-domain signal and the Q accompanying time-domain signals respectively to obtain Q cross-correlation functions.

[0092] Step S330: Perform time delay estimation based on peak detection on the Q cross-correlation functions to locate the Q TDOA values.

[0093] Step S340: Using the Q TDOA values ​​as observation inputs, and combining them with the Q three-dimensional coordinates of the Q mobile monitoring stations, construct and solve the hyperbolic positioning equation to obtain the initial signal source position.

[0094] Step S350: Extract the high-dimensional modulation fingerprint feature vector from the first event alarm, combine it with the time-aligned first time-domain signal and Q accompanying time-domain signals, perform joint signal analysis, extract global signal feature parameters, and generate the signal feature summary.

[0095] In one implementation, the Q TDOA values ​​are used as observation inputs, and the hyperbolic positioning equation is constructed and solved using the Q three-dimensional coordinates of the Q mobile monitoring stations to obtain the initial signal source position. Step S340 of the method provided by this invention further includes:

[0096] Step S341: Convert the Q TDOA values ​​into Q distance difference observations.

[0097] Step S342: Using the first mobile monitoring station as the reference station, and Q distance difference observations as constant terms, construct a nonlinear hyperbolic equation system by combining the Q three-dimensional coordinates and the first three-dimensional coordinates of the first mobile monitoring station.

[0098] Step S343: Linearize the nonlinear hyperbolic equation system to generate a linear observation equation system.

[0099] Step S344: Iteratively solve the linear observation equations using the weighted least squares estimation method until convergence, and output the initial signal source location.

[0100] This embodiment extracts time-domain signal data containing the original waveform information of the target signal from the initial event alarm and Q accompanying event alarms collected in step S200. The data extracted from the initial event alarm is called the initial time-domain signal, which originates from the first baseband I / Q data stream retained by the first mobile monitoring station after local two-stage filtering and cyclic stationarity analysis. The data extracted from each accompanying event alarm is called the accompanying time-domain signal, which originates from the results retrieved and verified from the local buffers of the Q mobile monitoring stations that have passed signal correlation verification. This yields a total of Q+1 time-domain signal segments from different spatial locations, providing a unified signal observation set for subsequent time difference measurement and positioning calculation.

[0101] By utilizing the high-precision capture timestamps attached to each alarm data packet, Q+1 time-domain signal segments are shifted and aligned on a unified time axis, eliminating the sampling start deviation introduced by the differences in independent clock references of each site.

[0102] After completing time-domain alignment, the first mobile monitoring station is set as the reference station. Subsequently, cross-correlation calculations are performed between the initial time-domain signal of the reference station and the accompanying time-domain signal of each accompanying station. Cross-correlation calculation is a mathematical operation that measures the similarity between two signals in the time domain at different relative delays. Its output is a function curve with relative delay as the independent variable, called the cross-correlation function. Q cross-correlation functions are obtained, and each function curve reflects the distribution of the correlation strength between the reference station signal and the corresponding accompanying station signal at various time offsets.

[0103] An extremum search is performed on the curves of the Q cross-correlation functions to locate the Q horizontal coordinate positions corresponding to their maximum amplitudes. The independent variable value corresponding to this position represents the relative time delay offset between the reference station signal and the corresponding accompanying station signal. Since the peak point of the cross-correlation function corresponds to the moment when the two signals are most aligned in the time domain, this offset represents the arrival time difference between the same signal propagating from the signal source to the reference station and to the accompanying station. Finally, Q TDOA values ​​are obtained, each corresponding to a participating accompanying mobile monitoring station. These observations are the core inputs for subsequent spatial positioning calculations.

[0104] The Q TDOA values ​​are multiplied by the speed of light, the propagation speed of electromagnetic waves in free space, to convert them into the corresponding Q distance difference observation values.

[0105] Using the first mobile monitoring station as the reference station for the entire positioning geometric model, and taking the Q distance difference observations as known constants in each equation, a nonlinear hyperbolic equation system is constructed by combining the Q three-dimensional coordinates of the Q mobile monitoring stations and the first three-dimensional coordinates of the first mobile monitoring station.

[0106] In the nonlinear hyperbolic equation system, each equation describes the difference between the spatial distance from the signal source to the corresponding i-th companion station and the spatial distance from the signal source to the reference station. This difference is strictly equal to the i-th distance difference observation value calculated in step S341. These equations together form a nonlinear system with the unknown three-dimensional coordinates of the signal source as the independent variable. Its geometric essence is the intersection point of multiple hyperboloids in space, and this intersection point is the spatial location of the signal source to be solved.

[0107] Since the hyperbola equation is a nonlinear equation in mathematics and cannot be solved directly with a closed-form solution, this embodiment uses the Taylor series expansion method to make a first-order approximation at the initial estimation point of the signal source location.

[0108] Specifically, the partial derivatives of each nonlinear equation with respect to the three coordinate components of the signal source are expanded at the initial estimation point, and only the linear terms are retained, thereby approximately transforming the original set of nonlinear equations into a set of linear observation equations concerning the signal source position correction.

[0109] The linearization process in this embodiment allows for iterative approximation using a mature linear least squares solution framework, significantly reducing computational complexity while ensuring controllable solution accuracy.

[0110] Each linear observation equation is assigned a weighting coefficient, which is usually determined based on the measurement signal-to-noise ratio or time delay estimation variance of the corresponding TDOA observation. Observations with high signal-to-noise ratios or small variances are given higher weights to reduce the negative impact of noisy observations on the solution results.

[0111] The weighted linear observation equations are subjected to least squares estimation to obtain the position correction for the current iteration step. This correction is then added to the current estimated position to obtain the updated signal source position.

[0112] Using the updated position as the new initial estimated point, the linearization process in step S343 and the weighted least squares solution process in step S344 are repeated until the position correction obtained by the two iterations is less than the preset convergence threshold or the preset maximum number of iterations is reached. The three-dimensional coordinates finally converged are the initial signal source position, which is essentially the initial coordinate estimate of the unregistered signal source in three-dimensional space.

[0113] The high-dimensional modulation fingerprint feature vector is extracted from the first event alarm and input together with the first time-domain signal and Q accompanying time-domain signals that have been aligned in the time domain into the joint signal analysis module.

[0114] The joint signal analysis module utilizes the differences in amplitude, phase, and channel fading between copies of the same source signal received from multiple stations. It extracts global signal feature parameters with higher signal-to-noise ratio and smaller estimation variance through multi-channel parameter estimation technology. These parameters include center frequency, occupied bandwidth, modulation type identification result, symbol rate, and average power level. The extracted global signal feature parameters and high-dimensional modulation fingerprint feature vector are organized and encapsulated according to a preset data structure to generate a structured signal feature summary, which serves as the information carrier for subsequent source tracing results.

[0115] Step S400: Combining the digital elevation map data of the monitoring area, perform terrain occlusion correction based on ray tracing on the initial signal source location to obtain the geodetic latitude and longitude coordinates of the signal source and the corresponding confidence assessment value.

[0116] Specifically, digital elevation maps are rasterized elevation datasets that describe the undulating shape of the earth's surface. They store the elevation of each location as regular grid points, providing terrain contours for electromagnetic wave propagation path analysis.

[0117] Ray tracing is an electromagnetic wave propagation prediction algorithm based on the principles of geometric optics. It simulates the path of rays emitted from a signal source to various receiving stations and calculates the reflection, diffraction, and transmission effects that occur when rays encounter terrain obstacles during propagation.

[0118] This embodiment utilizes digital elevation map data, taking the initial signal source location as the transmission point and the locations of each mobile monitoring station as the receiving points, to perform ray tracing simulation, focusing on evaluating the impact of terrain occlusion on signal arrival time and path loss. Ray tracing simulation simulates the propagation path of electromagnetic waves in realistic 3D terrain, outputting the actual geometric length of each path, propagation delay, and signal attributes such as whether it belongs to line-of-sight propagation. It then extracts the additional propagation delay deviation caused by reflection, diffraction, or occlusion due to terrain obstacles. Terrain occlusion correction, based on the aforementioned delay deviation, reverses the pseudo-delay introduced by non-line-of-sight propagation in the initial TDOA positioning results, correcting the signal propagation delay error caused by obstacles such as mountains and buildings, thereby eliminating the systematic bias introduced by multipath and non-line-of-sight propagation in the initial TDOA positioning results.

[0119] The geodetic latitude and longitude coordinates of the output signal source after correction are the final geographic coordinates after terrain compensation of the initial three-dimensional position of the signal source.

[0120] Meanwhile, based on the degree of signal path obstruction, signal strength attenuation, and positioning residual in the multipath environment during ray tracing simulation, a confidence assessment value is calculated. This confidence assessment value quantifies the reliability of the correction result. A high confidence value indicates that the terrain has little impact and the positioning accuracy is reliable, while a low confidence value indicates that the location is greatly affected by complex terrain and there is a certain degree of uncertainty.

[0121] Step S500: Using the latitude and longitude coordinates of the signal source as the center, construct a dynamic spectrum law enforcement geofence based on the confidence assessment value.

[0122] The geofence is a virtual boundary based on geographical location, used to delineate specific areas on an electronic map to trigger subsequent monitoring actions. In this embodiment, the geofence is centered on the latitude and longitude coordinates of the signal source, and its shape is circular or elliptical. The radius of the geofence is dynamically determined by the confidence level assessment value.

[0123] Specifically, the higher the confidence level, the smaller the fence radius, indicating a more precise location of the signal source and allowing for accurate focusing of the enforcement area; conversely, the lower the confidence level, the larger the fence radius should be to cover areas with potential location uncertainties and avoid missed detections.

[0124] This embodiment uses a dynamic radius adjustment mechanism based on confidence level assessment values ​​to ensure the rational allocation of law enforcement resources. This avoids both over-expanding the enforcement scope leading to inefficiency and overconfidence causing the loss of genuine signal sources. The resulting dynamic spectrum enforcement geofence provides spatial support for subsequent on-site verification, signal suppression, and evidence collection.

[0125] Step S600: The dynamic spectrum law enforcement geofence, signal feature summary, signal source geodetic coordinates and confidence assessment value are fused and sent to the superior command cloud as the source tracing result.

[0126] In this embodiment, the dynamic spectrum law enforcement geofence, signal feature summary, signal source geodetic coordinates and confidence assessment value obtained in the aforementioned steps are integrated into a complete source tracing data package according to a preset data encapsulation format, and then sent to the upper-level command cloud via a network communication link.

[0127] The higher-level decision-making center in the cloud-based command and control system is responsible for receiving traceability results from multiple monitoring systems, conducting overall situation analysis, assigning law enforcement tasks, and managing spectrum resources.

[0128] The fusion reporting mechanism in this embodiment transmits the location results, identity fingerprints, confidence assessments, and law enforcement boundaries together, enabling the superior command cloud to directly execute subsequent spectrum law enforcement decisions based on the results without the need for secondary analysis and verification, thus significantly improving the closed-loop efficiency from signal detection to law enforcement response.

[0129] This embodiment constructs an edge-level local discrimination and centrally triggered multi-station collaborative monitoring network based on modulation fingerprints. Compared with existing centralized spectrum monitoring schemes, it significantly reduces the data processing pressure on the central processing station. At the same time, it utilizes cyclostationary fingerprint characteristics to achieve accurate identification of illegal transmission devices and multi-station source verification. Combined with ray tracing terrain occlusion correction of digital elevation maps, it effectively improves the positioning accuracy in complex terrain. Finally, the confidence-driven dynamic law enforcement fence mechanism optimizes the spatial allocation efficiency of on-site law enforcement resources and comprehensively improves the closed-loop response capability from signal detection to accurate source tracing.

[0130] In one implementation, the first baseband I / Q data stream is subjected to local two-stage filtering to obtain the signal segment to be analyzed. Step S202 of the method provided by this invention further includes:

[0131] Step S2021: Based on the preset time window length and sliding step size, the first baseband I / Q data stream is divided into multiple continuous signal segments by sliding window segmentation.

[0132] Step S2022: Calculate the kurtosis values ​​of the multiple continuous signal segments, compare them with the preset kurtosis threshold for first-level filtering, and select and retain H potential useful signal segments.

[0133] Step S2023: Calculate the H power spectral entropies of the H potential useful signal segments, compare them with the preset spectral entropy threshold for secondary filtering, and select and retain the signal segments to be analyzed.

[0134] Specifically, the preset time window length defines the fixed duration of each signal segment, while the sliding step size controls the displacement between adjacent windows. Together, they determine the granularity and degree of overlap of the segmentation.

[0135] By using a sliding window to divide the continuous high-sampling-rate baseband data stream into a series of short-time signal units, multiple continuous signal segments are obtained, allowing subsequent processing to be performed on an independent segment basis, providing structured input data for local two-stage filtering.

[0136] Kurtosis is a fourth-order statistic reflecting the degree to which the amplitude distribution of a signal deviates from a Gaussian distribution. When there is sudden communication activity or pulse components in a signal segment, the tail of its amplitude distribution thickens, and the kurtosis value increases significantly. Based on this, this embodiment calculates multiple segmental kurtosis values ​​of the multiple continuous signal segments, compares them with a preset kurtosis threshold for primary filtering, quickly eliminates a large number of redundant segments containing only background noise or no active components, and retains only those signal segments whose kurtosis values ​​exceed the threshold, thus obtaining the H potentially useful signal segments. This significantly compresses the amount of data to be processed and filters out invalid interference for subsequent detailed analysis.

[0137] The power spectral entropy is the Shannon entropy calculated after normalizing the power spectral density of the signal. It is used to quantify the uniformity of the spectral distribution. Artificially modulated signals usually have a concentrated spectral line structure or a regular spectral shape, and their power spectral entropy is low. In contrast, the spectral distribution of broadband noise or unmodulated interference is relatively flat, and the entropy value is high.

[0138] In this embodiment, the power spectral entropy is compared with a preset spectral entropy threshold. Only signal segments with power spectral entropy lower than the threshold are determined to have modulation signal characteristics and are thus retained as signal segments to be analyzed.

[0139] Thus, through two-stage filtering using kurtosis and power spectral entropy, this embodiment accurately extracts the segment most likely to contain unregistered modulation signals from the original baseband data stream, providing high-quality input for subsequent in-depth analysis of cyclostationary characteristics and fingerprint extraction.

[0140] In one implementation, a deep analysis of the cyclostationary characteristics of the signal segment to be analyzed is performed to extract subtle modulation features and construct a high-dimensional modulation fingerprint feature vector. Step S203 of the method provided by this invention further includes:

[0141] Step S2031: Calculate the cyclic autocorrelation function and spectral correlation density function of the signal segment to be analyzed.

[0142] Step S2032: Extract multiple cyclic frequency domain statistical features and multiple spectral correlation structural features from the cyclic autocorrelation function and the spectral correlation density function, respectively.

[0143] Step S2033: After performing cross-source feature-level fusion on the multiple cyclic frequency domain statistical features and multiple spectral correlation structural features, feature vectors are constructed and the high-dimensional modulation fingerprint feature vector is output.

[0144] It should be understood that the cyclic autocorrelation function is a two-dimensional function that describes the bi-periodic correlation between a signal in the time delay domain and the cyclic frequency domain. It is obtained by performing correlation operations on the signal and its cyclic frequency offset copy, and can reveal the periodic statistical regularities introduced by the modulation format and the non-ideal characteristics of the transmitter hardware.

[0145] The spectral correlation density function is obtained by performing a Fourier transform on the cyclic autocorrelation function along the time delay axis. It presents the distribution of cyclic coupling strength between different spectral components of the signal from the frequency domain perspective and is the core tool for cyclic stationarity analysis.

[0146] This embodiment calculates the cyclic autocorrelation function and spectral correlation density function of the signal segment to be analyzed, providing a multi-dimensional feature space basis for subsequent extraction of subtle modulation features.

[0147] Multiple cyclic frequency domain statistical features and multiple spectral correlation structural features are extracted from the cyclic autocorrelation function and the spectral correlation density function, respectively. The cyclic frequency domain statistical features include parameters such as symbol rate and cyclic spectral line intensity at its harmonics, cyclic peak sharpness, and spectral line symmetry, which reflect the statistical characteristics of the signal over the baseband modulation period. The spectral correlation structural features include geometric and topological properties such as peak distribution patterns, peak morphology, and contour density on the spectral correlation plane, which characterize the nonlinear coupling relationships between the signal's spectral components.

[0148] By extracting the features of these two different transform domains separately, we obtain multiple cyclic frequency domain statistical features and multiple spectral correlation structural features. This not only preserves the independent identification information of each domain, but also provides rich and complementary original materials for subsequent fusion.

[0149] The cross-source feature-level fusion refers to integrating different types of feature parameters (multiple cyclic frequency domain statistical features and multiple spectral correlation structural features) from the cyclic frequency domain and the spectral correlation domain into a unified feature set according to a preset weight or sorting strategy, eliminating the differences in feature dimensions and dynamic range, so that the fused feature set carries triple information from the time delay domain, the cyclic frequency domain, and the frequency domain.

[0150] After feature fusion is complete, the fused features are vectorized and arranged in a fixed dimensional order to form a high-dimensional modulation fingerprint feature vector with a defined length. Due to its high dimensionality and multi-source information fusion characteristics, this high-dimensional modulation fingerprint feature vector can uniquely characterize subtle modulation defects at the hardware level of the signal emission source, possessing extremely high device distinguishability and can be directly used for fingerprint recognition and signal source verification.

[0151] Example 2: Based on the same inventive concept as the real-time spectral occupancy signal tracing method based on modulation fingerprints in the foregoing examples, this invention provides a real-time spectral occupancy signal tracing system based on modulation fingerprints. See [link to example]. Figure 2 As shown, the system includes:

[0152] The collaborative network deployment module 1 is used to deploy a collaborative monitoring network in the monitoring area, wherein the collaborative monitoring network includes a central processing station and P mobile monitoring stations, wherein the central processing station establishes a network collaboration mechanism with the P mobile monitoring stations through a wireless communication private network;

[0153] The collaborative monitoring trigger module 2 is used to receive the first event alarm returned by the first mobile monitoring station from the central processing station, trigger edge-level synchronous monitoring of P-1 mobile monitoring stations, and obtain Q accompanying event alarms returned by Q mobile monitoring stations, where Q≥2 and Q≤P;

[0154] TDOA delay estimation module 3 is used to perform TDOA delay estimation based on the first event alarm and Q accompanying event alarms to obtain the initial signal source location and signal feature summary;

[0155] The terrain occlusion correction module 4 is used to combine the digital elevation map data of the monitoring area to perform terrain occlusion correction on the initial signal source location based on ray tracing, so as to obtain the geodetic latitude and longitude coordinates of the signal source and the corresponding confidence evaluation value.

[0156] The dynamic geofencing module 5 is used to construct a dynamic spectrum law enforcement geofencing centered on the latitude and longitude coordinates of the signal source and based on the confidence assessment value.

[0157] The source tracing result fusion module 6 is used to fuse the dynamic spectrum law enforcement geofence, signal feature summary, signal source geodetic coordinates and confidence assessment value, and send them as source tracing results to the superior command cloud.

[0158] In one implementation, the TDOA delay estimation module 3 is further configured to:

[0159] The initial time-domain signal and Q accompanying time-domain signals are extracted from the initial event alarm and Q accompanying event alarms, respectively. After time-domain alignment of the initial time-domain signal and the Q accompanying time-domain signals, the first mobile monitoring station is used as a reference station. The initial time-domain signal is cross-correlated with the Q accompanying time-domain signals to obtain Q cross-correlation functions. The Q cross-correlation functions are then used for peak detection-based time delay estimation to locate Q TDOA values. Using the Q TDOA values ​​as observation inputs, and combined with the Q three-dimensional coordinates of the Q mobile monitoring stations, a hyperbolic positioning equation is constructed and solved to obtain the initial signal source location. A high-dimensional modulation fingerprint feature vector is extracted from the initial event alarm. Combined with the time-aligned initial time-domain signal and Q accompanying time-domain signals, joint signal analysis is performed to extract global signal feature parameters and generate the signal feature summary.

[0160] In one implementation, the TDOA delay estimation module 3 is further configured to:

[0161] The Q TDOA values ​​are converted into Q distance difference observations; taking the first mobile monitoring station as the reference station and the Q distance difference observations as constants, a nonlinear hyperbolic equation system is constructed by combining the Q three-dimensional coordinates and the first three-dimensional coordinates of the first mobile monitoring station; the nonlinear hyperbolic equation system is linearized to generate a linear observation equation system; the linear observation equation system is iteratively solved using the weighted least squares estimation method until convergence, and the initial signal source position is output.

[0162] In one implementation, the collaborative monitoring triggering module 2 is further configured to:

[0163] The mobile monitoring station is equipped with a multi-channel parallel acquisition architecture, which includes a multi-channel radio frequency receiver and a high-speed ADC.

[0164] In one implementation, the collaborative monitoring triggering module 2 is further configured to:

[0165] After receiving signals from the preset target frequency band via the multi-channel radio frequency receiver, the first mobile monitoring station uses the high-speed ADC to perform bandpass sampling and digital quadrature demodulation on the received signals to obtain a first baseband I / Q data stream. The first baseband I / Q data stream is then subjected to local two-stage filtering to obtain the signal segment to be analyzed. A deep analysis of the cyclostationary characteristics of the signal segment to be analyzed is performed to extract subtle modulation features and construct a high-dimensional modulation fingerprint feature vector. If the result of local comparison of the high-dimensional modulation fingerprint feature vector with the modulation fingerprint database indicates an unregistered signal, then the high-dimensional modulation fingerprint feature vector and the initial time-domain signal of the signal segment to be analyzed are packaged together as the initial event alarm and uploaded to the central processing station.

[0166] In one implementation, the collaborative monitoring triggering module 2 is further configured to:

[0167] The central processing station receives and parses the initial event alarm to obtain the high-dimensional modulation fingerprint feature vector and the initial time-domain signal. Based on the first start time and first duration contained in the initial time-domain signal, a collaborative backtracking time window is constructed. The central processing station sends the collaborative backtracking time window and the high-dimensional modulation fingerprint feature vector to the P-1 mobile monitoring stations. The P-1 mobile monitoring stations perform deep analysis of the cyclostationary characteristics based on signal data backtracking retrieval according to the collaborative backtracking time window, obtain P-1 node modulation fingerprint feature vectors, compare them with the high-dimensional modulation fingerprint feature vectors, and perform signal correlation verification to obtain Q accompanying time-domain signals of Q mobile monitoring stations. The Q mobile monitoring stations use the Q accompanying time-domain signals as the payload of the Q accompanying event alarms and transmit them back to the central processing station.

[0168] In one implementation, the collaborative monitoring triggering module 2 is further configured to:

[0169] Based on a preset time window length and sliding step size, the first baseband I / Q data stream is segmented by a sliding window to obtain multiple continuous signal segments; multiple segment kurtosis values ​​of the multiple continuous signal segments are calculated, and a first-level filter is performed by comparing them with a preset kurtosis threshold to select and retain H potential useful signal segments; H power spectral entropies of the H potential useful signal segments are calculated, and a second-level filter is performed by comparing them with a preset spectral entropy threshold to select and retain the signal segments to be analyzed.

[0170] In one implementation, the collaborative monitoring triggering module 2 is further configured to:

[0171] Calculate the cyclic autocorrelation function and spectral correlation density function of the signal segment to be analyzed; extract multiple cyclic frequency domain statistical features and multiple spectral correlation structural features from the cyclic autocorrelation function and spectral correlation density function respectively; perform cross-source feature-level fusion on the multiple cyclic frequency domain statistical features and multiple spectral correlation structural features, construct feature vectors, and output the high-dimensional modulation fingerprint feature vector.

[0172] Example 3: Figure 3 The diagram shown is a schematic representation of the structure of an exemplary electronic device of the present invention. Figure 3 In this document, the bus architecture is represented by bus 500. Bus 500 may include any number of interconnected buses and bridges, and bus 500 connects various circuits including one or more processors represented by processor 502 and memory represented by memory 504. Bus 500 may also connect various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. Bus interface 505 provides an interface between bus 500 and receiver 501 and transmitter 503. Receiver 501 and transmitter 503 may be the same element, i.e., a transceiver, providing a unit for communicating with various other devices over a transmission medium.

[0173] The memory 504, as a computer-readable storage medium, can be used to store software programs, computer-executable programs, and modules, such as the program instructions / modules corresponding to the real-time spectral occupancy signal tracing method based on modulation fingerprints in this embodiment of the invention. The processor 502 executes various functional applications and data processing of the computer device by running the software programs, instructions, and modules stored in the memory 504, thereby realizing the aforementioned real-time spectral occupancy signal tracing method based on modulation fingerprints.

[0174] The above description is merely a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.

[0175] The foregoing description of specific exemplary embodiments of the invention is for illustrative and explanatory purposes. These descriptions are not intended to limit the invention to the precise forms disclosed, and it will be apparent that many changes and variations can be made in accordance with the foregoing teachings. The exemplary embodiments were chosen and described in order to explain the specific principles of the invention and its practical application, thereby enabling those skilled in the art to implement and utilize various different exemplary embodiments of the invention, as well as various different choices and variations. The scope of the invention is intended to be defined by the claims and their equivalents.

Claims

1. A real-time modulation fingerprint based spectrum occupancy signal provenance method, characterized in that, include: A collaborative monitoring network is deployed in the monitoring area, wherein the collaborative monitoring network includes a central processing station and P mobile monitoring stations, wherein the central processing station establishes a network collaboration mechanism with the P mobile monitoring stations through a private wireless communication network; The central processing station receives the first event alarm returned by the first mobile monitoring station, triggers edge-level synchronous monitoring of P-1 mobile monitoring stations, and obtains Q accompanying event alarms returned by Q mobile monitoring stations, where Q≥2 and Q≤P; Based on the initial event alarm and Q accompanying event alarms, TDOA delay estimation is performed to obtain the initial signal source location and signal feature summary; By combining the digital elevation map data of the monitoring area, terrain occlusion correction based on ray tracing is performed on the initial signal source location to obtain the geodetic latitude and longitude coordinates of the signal source and the corresponding confidence assessment value; A dynamic spectrum enforcement geofence is constructed based on the ground latitude and longitude coordinates of the signal source and the confidence level assessment value. The dynamic spectrum law enforcement geofence, signal feature summary, signal source geolocation coordinates and confidence assessment value are integrated and sent to the higher-level command cloud as the source tracing result.

2. The real-time source tracing method for spectrum occupancy signals based on modulation fingerprints as described in claim 1, characterized in that, Based on the initial event alarm and Q accompanying event alarms, TDOA delay estimation is performed to obtain the initial signal source location and signal feature summary, including: The initial time-domain signal and the Q accompanying time-domain signals are extracted from the initial event alarm and the Q accompanying event alarms, respectively. After aligning the initial time-domain signal and the Q accompanying time-domain signals in the time domain, using the first mobile monitoring station as a reference station, the initial time-domain signal is cross-correlated with the Q accompanying time-domain signals respectively to obtain Q cross-correlation functions; Delay estimation based on peak detection is performed on the Q cross-correlation functions to locate the Q TDOA values; Using the Q TDOA values ​​as observation inputs, and combining them with the Q three-dimensional coordinates of the Q mobile monitoring stations, the hyperbolic positioning equation is constructed and solved to obtain the initial signal source position; A high-dimensional modulation fingerprint feature vector is extracted from the initial event alarm. Combined with the time-aligned initial time-domain signal and Q accompanying time-domain signals, joint signal analysis is performed to extract global signal feature parameters and generate the signal feature summary.

3. The real-time source tracing method for spectrum occupancy signals based on modulation fingerprints as described in claim 2, characterized in that, Using the Q TDOA values ​​as observation inputs, and combining them with the Q three-dimensional coordinates of the Q mobile monitoring stations, a hyperbolic positioning equation is constructed and solved to obtain the initial signal source location, including: Convert the Q TDOA values ​​into Q distance difference observations; Using the first mobile monitoring station as a reference station, and Q distance difference observations as constants, a nonlinear hyperbolic equation system is constructed by combining the Q three-dimensional coordinates and the first three-dimensional coordinates of the first mobile monitoring station. The nonlinear hyperbolic equation system is linearized to generate a linear observation equation system; The initial signal source location is output by iteratively solving the linear observation equations using the weighted least squares estimation method until convergence.

4. The real-time source tracing method for spectrum occupancy signals based on modulation fingerprints as described in claim 1, characterized in that, The mobile monitoring station is equipped with a multi-channel parallel acquisition architecture, which includes a multi-channel radio frequency receiver and a high-speed ADC.

5. The real-time source tracing method for spectrum occupancy signals based on modulation fingerprints as described in claim 4, characterized in that, Also includes: After receiving signals from the preset target frequency band through the multi-channel radio frequency receiver, the first mobile monitoring station uses the high-speed ADC to perform bandpass sampling and digital quadrature demodulation on the received signals to obtain the first baseband I / Q data stream. The first baseband I / Q data stream is subjected to local two-stage filtering to obtain the signal segment to be analyzed; Deep analysis of the cyclostationary characteristics of the signal segment to be analyzed is performed to extract subtle modulation features and construct a high-dimensional modulation fingerprint feature vector. If the result of the identity determination using the high-dimensional modulated fingerprint feature vector for local comparison with the modulated fingerprint database is an unregistered signal, then the high-dimensional modulated fingerprint feature vector and the first time-domain signal of the signal segment to be analyzed are packaged as the first event alarm and uploaded to the central processing station.

6. The real-time source tracing method for spectrum occupancy signals based on modulation fingerprints as described in claim 5, characterized in that, The central processing station receives the initial event alarm from the first mobile monitoring station, triggers edge-level synchronous monitoring of P-1 mobile monitoring stations, and acquires Q accompanying event alarms from Q mobile monitoring stations, including: The central processing station receives and parses the first event alarm to obtain the high-dimensional modulated fingerprint feature vector and the first time-domain signal. Based on the first start time and first duration contained in the first time domain signal, a collaborative backtracking time window is constructed; The central processing station sends the collaborative backtracking time window and the high-dimensional modulated fingerprint feature vector to the P-1 mobile monitoring stations; The P-1 mobile monitoring stations perform deep analysis of cyclic stationarity characteristics based on signal data backtracking retrieval according to the collaborative backtracking time window, and obtain P-1 node modulation fingerprint feature vectors. Then, they compare the high-dimensional modulation fingerprint feature vectors to perform signal correlation verification, and obtain Q accompanying time-domain signals of Q mobile monitoring stations. The Q mobile monitoring stations transmit the Q accompanying time-domain signals as the payloads for the Q accompanying event alarms back to the central processing station.

7. The real-time source tracing method for spectrum occupancy signals based on modulation fingerprints as described in claim 5, characterized in that, The first baseband I / Q data stream is subjected to local two-stage filtering to obtain the signal segment to be analyzed, including: Based on a preset time window length and sliding step size, the first baseband I / Q data stream is divided by a sliding window to obtain multiple continuous signal segments; Calculate multiple segment kurtosis values ​​of the multiple continuous signal segments, compare them with a preset kurtosis threshold for first-level filtering, and select and retain H potential useful signal segments; Calculate the H power spectral entropies of the H potential useful signal segments, compare them with a preset spectral entropy threshold for secondary filtering, and select and retain the signal segments to be analyzed.

8. The real-time source tracing method for spectrum occupancy signals based on modulation fingerprints as described in claim 5, characterized in that, A deep analysis of the cyclostationary characteristics of the signal segment to be analyzed is performed to extract subtle modulation features and construct a high-dimensional modulation fingerprint feature vector, including: Calculate the cyclic autocorrelation function and spectral correlation density function of the signal segment to be analyzed; Multiple cyclic frequency domain statistical features and multiple spectral correlation structural features are extracted from the cyclic autocorrelation function and the spectral correlation density function, respectively. After performing cross-source feature-level fusion on the multiple cyclic frequency domain statistical features and multiple spectral correlation structural features, feature vectors are constructed, and the high-dimensional modulation fingerprint feature vector is output.

9. A real-time source tracing system for spectrum occupancy signals based on modulation fingerprints, characterized in that, For implementing the method steps of any one of claims 1 to 8, comprising: A collaborative network deployment module is used to deploy a collaborative monitoring network in a monitoring area. The collaborative monitoring network includes a central processing station and P mobile monitoring stations. The central processing station establishes a network collaboration mechanism with the P mobile monitoring stations through a private wireless communication network. The collaborative monitoring triggering module is used by the central processing station to receive the first event alarm returned by the first mobile monitoring station, trigger edge-level synchronous monitoring of P-1 mobile monitoring stations, and obtain Q accompanying event alarms returned by Q mobile monitoring stations, where Q≥2 and Q≤P; The TDOA delay estimation module is used to estimate the TDOA delay based on the initial event alarm and Q accompanying event alarms, and to obtain the initial signal source location and signal feature summary. The terrain occlusion correction module is used to combine the digital elevation map data of the monitoring area to perform terrain occlusion correction on the initial signal source location based on ray tracing, so as to obtain the geodetic latitude and longitude coordinates of the signal source and the corresponding confidence evaluation value. The dynamic geofencing module is used to construct a dynamic spectrum law enforcement geofencing centered on the latitude and longitude coordinates of the signal source and based on the confidence assessment value. The source tracing result fusion module is used to fuse the dynamic spectrum law enforcement geofence, signal feature summary, signal source geodetic coordinates and confidence assessment value, and send them as source tracing results to the superior command cloud.

10. An electronic device, characterized in that, The electronic device includes: Memory, used to store executable instructions; The processor, when executing executable instructions stored in the memory, implements the real-time tracing method for spectrum occupancy signals based on modulation fingerprints as described in any one of claims 1-8.