An optical wireless physical layer security enhancement method based on dynamic chaotic encryption driving constellation reconstruction
Patent Information
- Application Number
- CN202610804297.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-05
- Publication Date
- 2026-08-18
AI Technical Summary
[0005]为了解决现有光纤无线接入网络中,光纤链路易遭光纤窃听、无线通信易被截获篡改的问题,本发明提供了一种基于动态混沌加密驱动星座重构的光载无线物理层安全增强方法,该方法实现了数字混沌加密与光域调制、无线空口传输的深度融合,可有效增强光纤无线接入网络全链路的安全性,确保信息传输的保密性与完整性
[0029] This invention mainly designs an encryption module for optical communication transmitters, focusing on a dynamic key mechanism. In each transmission process, the encryption key is transmitted to the authorized user along with the encryption key. The information is encrypted using a multi-layer encryption method based on chaotic XOR encryption, DNA encryption, constellation reconstruction, and probabilistic integer encryption to achieve high-security transmission of information and prevent important data from being stolen or directly tampered with.
Smart Images

Figure CN122601165A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of optical communication technology, specifically to a method for enhancing the physical layer security of optical wireless communication based on dynamic chaotic encryption-driven constellation reconstruction. It aims to leverage the high initial value sensitivity, strong randomness, and large key space characteristics of hyperchaotic systems to achieve physical layer encryption and secure transmission of communication signals across the entire link, resisting malicious attacks such as signal eavesdropping and illegal tampering. This system is suitable for high-security fiber optic wireless converged communication scenarios, including secure communications for government and enterprises, military access network communications, industrial internet edge access communications, and other critical communication fields requiring resistance to eavesdropping and hacking. Background Technology
[0002] With the large-scale deployment and rapid development of various industries worldwide, fiber optic wireless access networks not only integrate the ultra-high bandwidth, low transmission loss, and high resistance to electromagnetic interference of fiber optic communication, but also the core advantages of wireless communication, such as flexible access, wide coverage, and strong mobility, making them a key component of the next-generation information infrastructure. Therefore, the communication security performance of this system is directly related to the stable operation of the national information infrastructure, and high-reliability security protection across the entire link has become a core requirement for fiber optic wireless access networks.
[0003] Many security solutions for fiber optic wireless access networks employ high-level encryption algorithms, primarily deployed at the network and application layers. These algorithms typically utilize symmetric cryptography such as Advanced Encryption Standard (AES) and asymmetric cryptography such as Rivest-Shamir-Adleman (RSA) and Elliptic Curve Cryptography (ECC). While these solutions can achieve a certain level of encryption for service data, they are ill-equipped to handle physical layer signal leakage and native eavesdropping, and are vulnerable to feature extraction, cracking, and reconstruction of the underlying modulation signals. Therefore, physical layer encryption plays a crucial role in secure communication.
[0004] In recent years, various physical layer security technologies have been proposed and developed, such as quantum key distribution and optical chaotic encryption. While quantum key distribution possesses unconditional security based on quantum mechanics, its limited transmission distance and extremely low key generation rate make it unsuitable for existing communication networks. Optical chaotic encryption relies on externally fed back semiconductor lasers to generate optical chaos to encrypt signals; the complexity of its generation process severely restricts feasible application scenarios. In contrast, digital chaotic encryption, due to its flexible implementation, excellent compatibility with existing fiber optic digital communication systems, ample key space, and outstanding anti-cracking capabilities, has become the most mature chaotic encryption scheme in the current communication field. This solution makes the following improvements to the currently mainstream digital chaotic encryption technology: First, the key can be dynamically changed and transmitted to the authorized user along with the encryption key during each transmission; second, it not only achieves passive anti-eavesdropping protection but also identifies active tampering attacks; finally, it not only adapts to different signal modulation formats but also performs constellation reconstruction and probability shaping during transmission, enhancing its security and universal compatibility. Summary of the Invention
[0005] To address the issues of fiber optic links being vulnerable to eavesdropping and wireless communication being easily intercepted and tampered with in existing fiber optic wireless access networks, this invention provides a method for enhancing the physical layer security of optical wireless networks based on dynamic chaotic encryption-driven constellation reconstruction. This method achieves deep integration of digital chaotic encryption with optical domain modulation and wireless air interface transmission, effectively enhancing the security of the entire fiber optic wireless access network and ensuring the confidentiality and integrity of information transmission.
[0006] The optical wireless physical layer security enhancement method based on dynamic chaotic encryption-driven constellation reconstruction includes a transmitter, an optical fiber transmission link, a remote radio frequency unit, and a receiver. The transmitter employs digital multiple chaotic encryption technology to modulate the encrypted signal onto an optical carrier, which is then transmitted via single-mode fiber to the remote radio frequency unit. A millimeter-wave signal is generated through photoelectric beat frequency conversion and wireless air interface transmission is completed. The receiver performs down-conversion using an envelope detector and recovers the original signal through digital signal processing.
[0007] To achieve the above objectives, the link devices used include a transmitting laser, a remote local oscillator laser, an arbitrary waveform generator, a TX-DSP module, an RX-DSP module, a variable optical power attenuator, a Mach-Zehnder modulator, a polarization modulator, an optical coupler, an electrical amplifier, a high-pass filter, a low-pass filter, a single-mode fiber, a photodetector, a transmitting antenna, a receiving antenna, and an envelope detector.
[0008] The optical wireless physical layer security enhancement method based on dynamic chaotic encryption-driven constellation reconstruction described in this invention is implemented as follows:
[0009] Step 1: In the TX-DSP module, a matrix of original plaintext pseudo-random binary sequences is generated. From this matrix, a fixed binary sequence with pre-agreed terms and bidirectional known location information between the sender and receiver is extracted. After passing through a hash function (SecureHash Algorithm-256, SHA-256), groups of four hexadecimal symbols are formed. The first two symbols are converted to the integer part of the initial chaotic value using decimal, and the last two symbols are mapped to the fractional part of the initial chaotic value, until all initial chaotic values are generated. The generated initial chaotic values are then substituted into the chaotic system to generate a unique chaotic key for the transmitted signal, enabling dynamic key changes and obtaining the corresponding chaotic sequence. .
[0010] The chaotic system is described by a set of ordinary differential equations:
[0011]
[0012] Among them, There are five chaotic state variables. These are pre-set constant system parameters.
[0013] Step 2: Process the chaotic sequence Perform pseudo-random number generation (PRNG) processing to obtain the sequence.
[0014] The PRNG processing procedure is as follows:
[0015]
[0016] in This represents the modulo operation. This indicates rounding down, applying a function to the chaotic sequence. When scaled up by a certain magnitude, tiny perturbations in the control parameters or initial iteration values are amplified dramatically, causing the output sequence to produce completely unrelated nonlinear jumps.
[0017] Step 3: Compare the remaining pseudo-random binary sequence after extraction with the generated chaotic sequence. An XOR operation is performed to achieve the first layer of bit-level chaotic encryption. Then, a DNA encryption method based on base computation is used to encrypt the signal, achieving the second layer of chaotic encryption on the signal after the first layer of encryption.
[0018] The specific process of DNA encryption is as follows:
[0019] First, in chaotic sequences Under the control of [the system], the XOR-encrypted data is mapped using DNA encoding, primarily through eight prescribed DNA encoding rules, while chaotic sequences [are also involved]. The mapping yields exactly 8 possible values, corresponding to 8 DNA coding rules, thereby controlling the data to be mapped under the corresponding rules.
[0020] Secondly, the chaotic sequence Another chaotic DNA mapping sequence is generated using DNA coding mapping rules.
[0021] Finally, three DNA computation rules are defined, using chaotic sequences. This controls the DNA computation rules to be used, performing DNA computations on the two types of mapped sequences generated. Chaotic sequences. There are three possible values in the design, corresponding to three defined DNA calculation rules.
[0022] Step 4: Design new DNA decoding rules to decode the computed DNA mapping symbols and directly map them to constellation points corresponding to the modulation scheme. This adapts the rules to different signal modulation schemes and achieves constellation reconstruction and probability shaping, generated through a chaotic system. and The sequence is used to select the corresponding decoding rule to complete the third layer of encryption of the signal.
[0023] The specific process of DNA decoding rules is as follows:
[0024] First, based on the corresponding modulation method, the constellation points are divided into high-energy and low-energy constellation points. A base mapping table with 4 rows and 8 columns is defined, where the 4 rows correspond to 4 low-energy or high-energy modulation constellation points respectively, and the 8 columns correspond to 8 DNA coding sub-rules respectively. Each base mapping table contains 4 constellation points, and multiple base mapping tables are generated until the constellation points of the corresponding modulation method are traversed once.
[0025] Secondly, according to the chaotic sequence The base mapping table is selected based on the interval in which the signal is located, thereby artificially increasing the probability of low-energy constellation points appearing, thus achieving probability shaping of the encrypted signal.
[0026] Finally, based on the chaotic sequence The eight seed rules of the current base mapping table are selected so that the DNA encryption mapping sequence becomes the chaotic constellation point of the current modulation mode after passing through.
[0027] Step 5: During modulation, the sequence extracted from the original pseudo-random binary sequence matrix in Step 1 is mapped to a normal constellation and placed in front of the chaotic encrypted constellation matrix to form a new constellation matrix for radio frequency signal modulation. The encrypted radio frequency signal is then transmitted to the receiving end via a fiber optic wireless access network, while the hash value from Step 1 is simultaneously sent to the receiving end through a secure channel.
[0028] Step Six: At the receiving end, demodulate the normal constellation mapping points in the constellation matrix to obtain the extracted original pseudo-random binary sequence. After applying the SHA-256 hash function, obtain the hash value and compare it with the hash value received through the secure channel. If, after eliminating noise and low received optical power, the results do not match, it proves that the data has been subjected to an active tampering attack, resulting in a mismatch between the extracted constellation points and the original data. If the comparison is correct, generate the corresponding chaotic initial value using the hash value and decrypt the remaining chaotic constellation points.
[0029] This invention mainly designs an encryption module for optical communication transmitters, focusing on a dynamic key mechanism. In each transmission process, the encryption key is transmitted to the authorized user along with the encryption key. The information is encrypted using a multi-layer encryption method based on chaotic XOR encryption, DNA encryption, constellation reconstruction, and probabilistic integer encryption to achieve high-security transmission of information and prevent important data from being stolen or directly tampered with. Attached Figure Description
[0030] Figure 1 This is a schematic diagram of a method for enhancing the security of optical wireless physical layer based on dynamic chaotic encryption-driven constellation reconstruction proposed in this invention.
[0031] Figure 2 DNA decoding mapping rule diagram designed for this invention;
[0032] Figure 3 This is a schematic diagram of the optical link of the fiber optic wireless access network described in this invention; Detailed Implementation
[0033] The invention will be further described below with reference to the accompanying drawings, using an OFDM-16QAM modulated signal as an example:
[0034] Figure 1 This is a schematic diagram of a method for enhancing the security of optical wireless physical layer based on dynamic chaotic encryption-driven constellation reconstruction proposed in this invention, which specifically includes the following steps:
[0035] Step 1, such as Figure 1As shown, a pseudo-random binary sequence matrix of the original plaintext is generated. Since it is an OFDM-16QAM modulated signal, four rows of fixed binary sequences with pre-agreed terms and bidirectional known location information between the transmitter and receiver are extracted from this matrix. After passing through the SHA-256 hash function, each group consists of four hexadecimal symbols. The first two symbols are converted to the integer part of the chaotic initial value through decimal conversion, and the last two symbols are mapped to the fractional part of the chaotic initial value, until all chaotic initial values are generated. The generated chaotic initial values are substituted into a five-dimensional hyperchaotic system to generate a chaotic key unique to the transmitted signal, enabling dynamic key changes and obtaining the corresponding chaotic sequence. .
[0036] The chaotic system is described by a set of ordinary differential equations:
[0037]
[0038] Among them, There are five chaotic state variables. These are pre-set constant system parameters.
[0039] Step 2: Process the chaotic sequence Perform PRNG processing to obtain the sequence.
[0040] The PRNG processing procedure is as follows:
[0041]
[0042] in This represents the modulo operation. This indicates rounding down, applying a function to the chaotic sequence. When scaled up by a certain magnitude, tiny perturbations in the control parameters or initial iteration values are amplified dramatically, causing the output sequence to produce completely unrelated nonlinear jumps.
[0043] Step 3, as follows Figure 1 As shown, the remaining pseudo-random binary sequence after extraction and the generated chaotic sequence are compared. An XOR operation is performed to achieve the first layer of bit-level chaotic encryption. Then, a DNA encryption method based on base computation is used to encrypt the signal, achieving the second layer of chaotic encryption on the signal after the first layer of encryption. First, in the chaotic sequence... Under the control of [the system / mechanism], the XOR-encrypted data is mapped using DNA encoding. Secondly, the chaotic sequence [is then processed / mapped]. Another chaotic DNA mapping sequence is generated using DNA coding mapping rules. Finally, three DNA computation rules are defined, using the chaotic sequence... This controls the DNA computation rules to be used, resulting in a chaotic DNA mapping sequence.
[0044] Step 4, Design as follows Figure 2 The new DNA decoding rule shown decodes the chaotic DNA mapping sequence, directly mapping it to the constellation points of the corresponding modulation scheme. Since OFDM-16QAM modulation is used in this case, it directly corresponds to its constellation points. Based on the chaotic sequence... To select 8 seed rules for the current base mapping table, based on the chaotic sequence. The four constellation mappings corresponding to the base mapping table are selected based on the interval where the base is located. The probability of low-energy constellation points appearing is artificially increased, thereby realizing the probability shaping of the encrypted signal and completing the chaotic scrambling and expansion of the constellation.
[0045] Step 5: During modulation, the four rows of sequence extracted from the original pseudo-random binary sequence matrix in Step 1 are mapped to a normal 16QAM constellation and placed before the chaotic encrypted constellation matrix to form a new constellation matrix. OFDM radio frequency signal modulation is then performed. The encrypted radio frequency signal is transmitted to the receiving end through a fiber optic wireless access network. A schematic diagram of this link is shown below. Figure 3 As shown. Simultaneously, the dynamic key from step one is sent to the receiving end via a secure channel.
[0046] Step Six: At the receiving end, demodulate the normal constellation mapping points in the constellation matrix to obtain the extracted original pseudo-random binary sequence. After applying the SHA-256 hash function, obtain the hash value and compare it with the hash value received through the secure channel. If, after eliminating noise and low received optical power, the results do not match, it proves that the data has been subjected to an active tampering attack, resulting in a mismatch between the extracted constellation points and the original data. If the comparison is correct, generate the corresponding chaotic initial value using the hash value and decrypt the remaining chaotic constellation points.
[0047] In summary, this invention exhibits the following features: 1) It employs a dynamic key mechanism, transmitting the encryption key along with the data to the authorized user during each transmission. This strategy effectively reduces the risk of quantum computing cracking long-term keys, providing strong protection for secure information transmission. 2) It encrypts information using a multi-layered encryption method combining chaotic XOR encryption, DNA encryption, constellation reconstruction, and probabilistic integer encryption to prevent theft of important data. 3) While ensuring secure transmission, by comparing the signal hash value extracted at the receiving end with the baseline hash value of the original secure signal at the sending end, it can identify active tampering during signal transmission, simultaneously completing signal integrity verification and attack detection.
Claims
1. A method for enhancing the security of optical over-the-air (OT) wireless physical layer based on dynamic chaotic encryption-driven constellation reconstruction, characterized in that: Includes the following steps: Step 1: Generate a dynamic chaotic key based on the output of the hash function-driven chaotic system. Step 2: Perform XOR encryption based on the chaotic key obtained in Step 1; Step 3: Perform DNA encryption based on the chaotic key obtained in Step 1; Step 4: Perform constellation reconstruction and probabilistic integer encryption based on the chaotic key obtained in Step 1 and the designed DNA decoding rules; Step 5: The receiving end compares the hash value extracted from the received signal with the baseline hash value of the original security signal to determine whether it has been actively tampered with or attacked.
2. The hash function-driven chaotic system according to claim 1 comprises the following specific steps: A matrix of pseudo-random binary sequences of original plaintext is generated. From this matrix, fixed binary sequences with pre-agreed terms and bidirectionally known location information between the sender and receiver are extracted. After passing through a hash function, each group consists of four hexadecimal symbols. The first two symbols are converted to the integer part of the initial chaotic value using decimal conversion, and the last two symbols are converted to the fractional part of the initial chaotic value using decimal conversion. This process continues until all initial chaotic values are generated. A five-dimensional hyperchaotic system is used, and the chaotic iterative equation is as follows: ; Substitute the generated chaotic initial values into the iterative equation until five chaotic sequences are obtained. If the sequence length meets the requirements for subsequent encryption, the iteration stops.
3. The XOR encryption of the chaotic key according to claim 1 comprises the following steps: The remaining pseudo-random binary sequence after extraction and the generated chaotic sequence Perform an XOR operation to achieve the first level of bit-level chaotic encryption.
4. The specific steps for DNA encryption using the chaotic key according to claim 1 are as follows: First, in chaotic sequences Under the control of [the system], DNA encoding mapping is performed on the XOR-encrypted data; Secondly, the chaotic sequence Another chaotic DNA mapping sequence is generated using DNA coding mapping rules; Finally, based on the DNA computation rules, through chaotic sequences This controls the DNA computation rules to be used, and performs DNA computation on the two generated mapping sequences.
5. The constellation reconstruction and probabilistic integer encryption are performed using the chaotic key and the designed DNA decoding rules according to claim 1, with the following specific steps: A new DNA decoding rule is designed to decode the computed DNA mapping symbols and directly map them to constellation points corresponding to the modulation scheme. This adapts the rules to different signal modulation schemes and enables chaotic constellation scrambling and expansion. This is achieved through a chaotic system. and The sequence is used to select the corresponding decoding constellation point, artificially increasing the probability of low-energy constellation points appearing, thereby achieving probability shaping of the encrypted signal. The sequence extracted from the original pseudo-random binary sequence matrix is normally mapped and placed in front of the chaotic constellation matrix, and the two form a new constellation matrix.
6. The specific steps for determining whether an active tampering attack has occurred according to claim 1 are as follows: The sending end sends the hash value generated by the hash function to the receiving end through a secure channel. The receiving end extracts the normally mapped, unencrypted sequence, processes it through the hash function, and compares it with the hash value obtained through the secure channel. If the results are inconsistent after excluding noise factors and low received optical power, it proves that the data has been subjected to an active tampering attack.