A method and system for monitoring and multi-scene linkage of abnormal electromagnetic signals in a secret-involved place
By employing nonlinear modeling and radio frequency fingerprinting methods, the problems of false alarms and identification reliability in electromagnetic signal monitoring systems under strong interference are solved, achieving low false alarm and reliable linkage decision-making. This method is suitable for electromagnetic signal monitoring and multi-scenario linkage in classified locations.
Patent Information
- Application Number
- CN202611122724.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-28
- Publication Date
- 2026-08-25
AI Technical Summary
Existing electromagnetic signal monitoring systems in classified locations suffer from nonlinear distortion components that cause false alarms and low identification reliability due to strong self-emission interference. Furthermore, the lack of uncertainty quantification and fusion in linkage decision-making leads to delayed response or frequent jumps.
By modeling the interference transmission link as a nonlinear model, extracting coherent reference signals for interference reconstruction, and combining radio frequency fingerprinting and Bayesian filtering to update the belief probability distribution, low false alarm detection and optimal linkage decision-making are achieved.
It achieves low false alarm detection of weak abnormal electromagnetic signals under strong interference background, improves the reliability of identification, and reduces false actions through probability-driven linkage decision-making, accurately matching security risks and business impact.
Smart Images

Figure CN122631964A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of electromagnetic information security protection, and discloses a method for monitoring abnormal electromagnetic signals in classified locations and for multi-scenario linkage. Background Technology
[0002] Active electromagnetic interference systems are typically deployed in classified locations to suppress electromagnetic leakage emissions. However, the strong self-emission interference makes the monitoring of abnormal signals within the location still inadequate. For example, existing interference cancellation schemes often simplify the spatial coupling channel into a linear multipath model, without taking into account the harmonic distortion and intermodulation distortion components introduced by the interference power amplifier under high power output conditions. These nonlinear distortions, after spatial coupling, are superimposed on the received signal. Reconstructing the interference using only a linear model will result in waveform mismatch. The nonlinear residuals after cancellation simulate the characteristics of real burst signals in the time domain, easily triggering false alarms or drowning out weak abnormal signals. RF fingerprint extraction relies on the headroom signal after interference cancellation. The nonlinear components, background noise fluctuations, and multipath fading in the cancellation residue will act as additive perturbations on the shape details of the AM-AM and AM-PM distortion curves of the power amplifier, leading to an increase in the intraclass distance of the extracted real-time fingerprint relative to the registered fingerprint of a legitimate device of the same model. This blurs the boundary between individual device differences and channel random bias, reducing identification reliability. Existing linkage solutions mostly rely on rules or thresholds to simply switch between abnormal alarms and scene states, failing to use the anomaly likelihood as a continuous observation for temporal probability fusion. They cannot recursively update the belief in the electromagnetic threat state, resulting in frequent jumps in linkage actions under transient interference or delayed responses when real threats occur. It is difficult to achieve a trade-off between security risks and business impact with accurate matching of scene states. Summary of the Invention
[0003] The purpose of this section is to outline some aspects of the embodiments of this application and to briefly describe some preferred embodiments. Simplifications or omissions may be made in this section, as well as in the abstract and title of this application, to avoid obscuring the purpose of these documents, and such simplifications or omissions should not be construed as limiting the scope of this application.
[0004] The specific inventive objective of this application is as follows:
[0005] To overcome the technical defects in existing solutions, such as insufficient nonlinear modeling for interference reconstruction leading to fingerprint extraction of contaminated residuals and lack of uncertainty quantification fusion in linkage decision-making, this solution enables low false alarm detection of weak abnormal electromagnetic signals under strong self-emission interference, and makes optimal linkage decisions that balance security risks and business impact based on the scenario status.
[0006] While achieving the above improvements, ensure that the spatial resolution and gain level of the device are no lower than those of existing technical solutions.
[0007] To address the aforementioned technical issues, this application provides a method for monitoring abnormal electromagnetic signals in classified locations and for multi-scenario linkage.
[0008] On the one hand, this application provides a method for monitoring abnormal electromagnetic signals in classified locations and for multi-scenario linkage, including:
[0009] Acquire the mixed received signal contaminated by interference, and extract a reference signal coherent with the currently transmitted interference signal from the interference transmission link;
[0010] The spatial coupling channel from the interference transmission link to the monitoring antenna is modeled as a nonlinear model. The kernel parameters of the nonlinear model are estimated using the reference signal and the mixed received signal to generate the interference reconstruction signal.
[0011] The interference-cancelled clearance signal is obtained from the mixed received signal and the interference reconstruction signal. The clearance signal is then subjected to signal detection and time-domain segmentation to extract nonlinear intrinsic feature parameters as a real-time radio frequency fingerprint.
[0012] The anomaly likelihood is calculated by comparing the radio frequency fingerprint with the device radio frequency fingerprint. The anomaly likelihood and the scene state observation information are used as real-time observation inputs to the linkage decision unit. The belief probability distribution of the electromagnetic threat state is recursively updated according to the time series observation.
[0013] By using the updated belief probability distribution and cost function, the linked decision unit is solved to obtain the linked action with the minimum long-term expected cumulative cost.
[0014] As a preferred embodiment of the method for monitoring abnormal electromagnetic signals in classified locations and for multi-scenario linkage in this application, wherein:
[0015] Acquire mixed received signals that are contaminated by interference from the monitoring antenna;
[0016] A broadband monitoring antenna array is deployed in the protected area of a classified location so that the spatial receiving range of the broadband monitoring antenna array covers all electromagnetic leakage paths that need to be protected. Each monitoring antenna unit in the broadband monitoring antenna array receives electromagnetic signals in the space. The electromagnetic signals are formed by the superposition of electromagnetic signals generated in the protected area and interference signals output by the interference transmission link through spatial propagation and multipath reflection.
[0017] The electromagnetic signals received by each monitoring antenna unit are sequentially amplified with low noise and bandpass filtered to suppress the saturation of the receiving link caused by strong out-of-band signals. The amplified and filtered signals are then subjected to analog-to-digital conversion and down-conversion to obtain the digital baseband signals of each channel, which serve as the mixed received signals contaminated by interference.
[0018] As a preferred embodiment of the method for monitoring abnormal electromagnetic signals in classified locations and for multi-scenario linkage in this application, wherein:
[0019] A directional coupler is connected in series between the output of the interference signal power amplifier and the interference transmitting antenna. The main path of the directional coupler transmits the interference signal output by the power amplifier to the interference transmitting antenna with low loss.
[0020] The coupling port of the directional coupler extracts part of the energy of the power amplifier output signal according to a preset coupling degree that does not degrade the transmission performance of the main path, and generates a coupling signal; after the coupling signal is attenuated and filtered, it is sent to the interference cancellation processing unit through an equal time delay transmission link as a reference signal coherent with the currently transmitted interference signal.
[0021] The reference signal includes the nonlinear distortion characteristics introduced by the power amplifier, and the equal-delay transmission link ensures that the sum of the transmission delay of the reference signal to the interference cancellation processing unit and the air delay of the interference signal from the interference transmitting antenna through space to the monitoring antenna array maintains a fixed and calibrable relative delay difference between the reference signal and the air-propagating interference component.
[0022] As a preferred embodiment of the method for monitoring abnormal electromagnetic signals in classified locations and for multi-scenario linkage in this application, wherein:
[0023] The spatially coupled channel is decomposed into a system structure in which the nonlinear distortion part of the transmission link and the multipath part of wireless propagation are cascaded;
[0024] The nonlinear distortion part of the transmission link characterizes the harmonic distortion and intermodulation distortion characteristics introduced by the power amplifier of the interference signal, and the wireless propagation multipath part characterizes the differential attenuation and time delay characteristics introduced by the direct path, reflection path and scattering path that the interference signal traverses from the interference transmitting antenna through space to the monitoring antenna.
[0025] The nonlinear distortion of the transmission link and the multipath propagation of wireless propagation are cascaded and coupled to construct a joint nonlinear model. The nonlinear model takes the reference signal as input and the interference component in the mixed received signal as output. It is characterized by a set of kernel parameters. The set of kernel parameters is used to describe the entire nonlinear distortion transmission characteristics and multipath propagation characteristics of the interference signal from the output of the final stage power amplifier of the transmission link to the monitoring and receiving front end.
[0026] As a preferred embodiment of the method for monitoring abnormal electromagnetic signals in classified locations and for multi-scenario linkage in this application, wherein:
[0027] Using the reference signal as the input excitation of the nonlinear model and the hybrid received signal as the desired output of the nonlinear model, a closed-loop adaptive identification architecture is constructed.
[0028] In the adaptive identification architecture, the reference signal generates an intermediate output signal through a nonlinear model under the current kernel parameters. The intermediate output signal is compared with the mixed received signal to generate an error signal. The error signal drives the adaptive parameter update algorithm to iteratively adjust the kernel parameters, so that the intermediate output signal gradually approaches the interference signal component contributed by the interference transmission link in the mixed received signal.
[0029] When the error signal power drops below the preset convergence threshold and the convergence condition is met for multiple consecutive frames with stable and no significant fluctuations, the current intermediate output signal is used as the interference reconstruction signal. The interference reconstruction signal matches the actual interference component in the mixed received signal in terms of time domain waveform, phase characteristics, and nonlinear distortion components.
[0030] As a preferred embodiment of the method for monitoring abnormal electromagnetic signals in classified locations and for multi-scenario linkage in this application, wherein:
[0031] The mixed received signal and the interference reconstruction signal are subjected to a sample-by-sample-point alignment and subtraction operation in the time domain. The alignment and subtraction operation is based on the determined relative time delay relationship between the reference signal guaranteed by the equal-delay transmission link and the interference component in the mixed received signal, so that each sampling point of the interference reconstruction signal corresponds in time to the corresponding sampling point of the interference component in the mixed received signal.
[0032] After the alignment and subtraction operation, the interference signal component contributed by the interference transmission link in the mixed received signal is canceled out. The residual signal contains the original electromagnetic signal in the protected area and the background noise introduced by the monitoring and receiving link. The residual signal is the clear signal after the interference cancellation.
[0033] As a preferred embodiment of the method for monitoring abnormal electromagnetic signals in classified locations and for multi-scenario linkage in this application, wherein:
[0034] The clearance signal is subjected to signal detection. Based on the start and end changes of the energy of the electromagnetic signal in the clearance signal in the time domain, the continuous clearance signal is divided into signal segments containing signal bursts and silent segments without signal bursts. Each signal segment has a definite start time and end time in the time domain.
[0035] For each of the said signal segments, distortion characteristic parameters generated when the transmitter power amplifier of the leakage device to be measured operates in the non-linear range within the signal segment are extracted. The distortion characteristic parameters include a first type of parameter describing the non-linear mapping relationship between the envelope amplitude of the input signal and the envelope amplitude of the output signal, and a second type of parameter describing the non-linear mapping relationship between the envelope amplitude of the input signal and the phase offset of the output signal. The first type of parameter and the second type of parameter together constitute the real-time radio frequency fingerprint of the transmitter corresponding to the signal segment.
[0036] As a preferred solution of a method for monitoring abnormal electromagnetic signals and multi-scenario linkage in a classified场所, where:
[0037] The real-time radio frequency fingerprint is successively subjected to similarity measurement with each registered radio frequency fingerprint of legal devices in the legal device radio frequency fingerprint library to obtain the degree of deviation of the real-time radio frequency fingerprint relative to each legal device radio frequency fingerprint.
[0038] Based on the degree of deviation of the real-time radio frequency fingerprint relative to all legal device radio frequency fingerprints, the abnormal likelihood is generated. The abnormal likelihood is used to characterize the possibility that the intercepted signal originates from an unknown or abnormal device.
[0039] As a preferred solution of a method for monitoring abnormal electromagnetic signals and multi-scenario linkage in a classified场所, where:
[0040] The scene state observation information is obtained from the security management system of the classified场所.
[0041] The abnormal likelihood and the scene state observation information are jointly used as the real-time observation quantity at the current moment.
[0042] In the partially observable Markov decision process, based on the belief probability distribution at the previous moment and the real-time observation quantity at the current moment, the posterior belief probability distribution of the electromagnetic threat state at the current moment is calculated using Bayesian filtering, realizing the sequential recursive update of the belief probability distribution.
[0043] A system for monitoring abnormal electromagnetic signals and multi-scenario linkage in a classified场所 according to the present application includes:
[0044] An acquisition unit, a processing unit, and a linkage decision unit, with each unit being synchronized in time sequence and interacting and transmitting data.
[0045] The signal acquisition unit includes a broadband monitoring antenna array and a directional coupler. The broadband monitoring antenna array is deployed within the protected area to acquire mixed received signals. The directional coupler is connected in series between the output of the interference signal power amplifier and the interference transmitting antenna to extract a reference signal that includes power amplifier nonlinear distortion and is coherent with the transmitted interference. The signal acquisition unit is also configured with an equal-delay transmission link to maintain a fixed and calibrable relative delay difference between the reference signal and the interference components in the mixed received signal.
[0046] The processing unit is signal-connected to the signal acquisition unit and is used to generate an interference reconstruction signal by taking the reference signal and the mixed received signal as inputs and using a kernel parameter identification algorithm of a joint nonlinear channel model. After time-domain alignment and subtraction, the clearance signal is output. The clearance signal is then divided into time domains and nonlinear distortion features are extracted to generate a real-time radio frequency fingerprint, which is then compared with the legitimate device radio frequency fingerprint database to output anomaly likelihood.
[0047] The linkage decision-making unit communicates bidirectionally with the processing unit and the security management system for classified locations. It receives the anomaly likelihood and multi-dimensional scene state observation information as real-time observations. Based on a partially observable Markov decision process, it recursively updates the belief probability distribution of the electromagnetic threat state through Bayesian filtering. Combined with a cost function that includes security risk costs and business impact costs, it outputs the linkage control action with the minimum long-term expected cumulative cost.
[0048] The beneficial effects of this application are as follows:
[0049] This application extracts a coherent reference signal containing nonlinear distortion features from the power amplifier output and performs joint nonlinear modeling of the nonlinear distortion of the transmission link and wireless propagation multipath. This enables the reconstructed interference signal to accurately match the real interference components in terms of nonlinear distortion components. The residual nonlinear components after cancellation are reduced to the level of background noise, eliminating false candidate signals caused by modeling errors. Instead of passively filtering out false alarms by raising the threshold in the detection stage, this application can achieve a substantial reduction in the false alarm rate without sacrificing detection sensitivity.
[0050] This application places radio frequency fingerprint extraction after nonlinear interference depth cancellation, which significantly improves the signal-to-interference ratio of the input signal for fingerprint extraction, effectively suppresses residual disturbances on AM-AM and AM-PM curves, significantly narrows the intra-class distance of fingerprints from legitimate devices of the same model, and clarifies the boundary between individual device differences and channel random deviations. By improving the signal source quality for fingerprint extraction, the problem of identification reliability is solved from the upstream stage of feature generation.
[0051] This application uses anomaly likelihood as a continuous uncertainty observation, and inputs it together with scene state observation information into a partially observable Markov decision process. It uses Bayesian filtering to recursively update the belief probability distribution of electromagnetic threat state, and solves the problem with a strategy jointly driven by security risk cost and business impact cost. The triggering of linkage decision no longer depends on the binary judgment at a single moment, but is based on the gradual convergence process of threat belief, so that linkage action changes from rule jump to probability convergence drive, eliminating erroneous actions caused by instantaneous abnormal fluctuations; the dual cost function enables the linkage response intensity under different scenarios to be accurately matched with business tolerance. Attached Figure Description
[0052] To more clearly illustrate the technical solutions of the embodiments of this application, the drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained through these drawings without creative effort. Wherein:
[0053] Figure 1 The flowchart of signal acquisition and preprocessing for a method for monitoring abnormal electromagnetic signals in classified locations and for multi-scene linkage provided in this application;
[0054] Figure 2 This application provides a flowchart of nonlinear modeling and interference reconstruction for a method of monitoring abnormal electromagnetic signals in classified locations and multi-scene linkage.
[0055] Figure 3 The flowchart of the time-domain cancellation and clearance signal acquisition method for monitoring abnormal electromagnetic signals in classified locations and multi-scene linkage provided in this application is as follows:
[0056] Figure 4 The flowchart of radio frequency fingerprint extraction and anomaly likelihood generation is provided for the method of monitoring abnormal electromagnetic signals in classified locations and multi-scene linkage in this application. Detailed Implementation
[0057] To make the above-mentioned objectives, features and advantages of this application more apparent and understandable, the specific embodiments of this application will be described in detail below with reference to the accompanying drawings.
[0058] Many specific details are set forth in the following description in order to provide a full understanding of this application. However, this application may also be implemented in other ways different from those described herein. Those skilled in the art can make similar extensions without departing from the spirit of this application. Therefore, this application is not limited to the specific embodiments disclosed below.
[0059] Secondly, the term "an embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of this application. The phrase "in one embodiment" appearing in different places in this specification does not necessarily refer to the same embodiment, nor is it a single embodiment or an embodiment selectively excluded from other embodiments.
[0060] Example 1
[0061] This embodiment provides a method for monitoring abnormal electromagnetic signals in classified locations and for multi-scenario linkage, including:
[0062] The system acquires the mixed received signal contaminated by interference from the monitoring antenna and extracts a reference signal coherent with the current transmitted interference signal from the interference transmission link through directional coupling.
[0063] The acquisition of the interference-contaminated mixed received signal from the monitoring antenna includes:
[0064] A broadband monitoring antenna array is deployed within the protected area of a classified location, so that the spatial receiving range of the broadband monitoring antenna array covers all electromagnetic leakage paths that need to be protected.
[0065] Each monitoring antenna unit in the broadband monitoring antenna array receives electromagnetic signals in the space. The electromagnetic signals include signals formed by the superposition of the original electromagnetic signals in the protected area and the interference signals emitted by the interference transmission link after spatial propagation and multipath reflection.
[0066] The electromagnetic signals received by each monitoring antenna unit are amplified with low noise and bandpass filtered to suppress receiver link saturation caused by strong out-of-band signals.
[0067] A preferred example of the low-noise amplification and bandpass filtering includes:
[0068] The electromagnetic signals received by each monitoring antenna unit are first sent to a low-noise amplifier. The noise figure of the low-noise amplifier is set to be less than a preset value, and the gain is set to make the total noise figure of the receiving link dominated by the low-noise amplifier while compensating for the insertion loss of the subsequent bandpass filter.
[0069] The low-noise amplified signal is input to a bandpass filter. The passband range of the bandpass filter covers all target frequency bands to be monitored, and its stopband attenuation is configured to suppress strong interference signals outside the operating frequency band to within the linear range of the receiving link, so as to avoid nonlinear distortion caused by the overload of strong out-of-band signals in the subsequent analog-to-digital converter.
[0070] The amplified and filtered signals are subjected to analog-to-digital conversion and down-conversion to obtain the digital baseband signals of each channel, which serve as the mixed received signals affected by interference.
[0071] An example of a preferred analog-to-digital conversion and down-conversion process to obtain the digital baseband signal for each channel includes:
[0072] Synchronous analog-to-digital conversion is performed on the amplified and filtered signals of each channel. The sampling clock is provided by a shared reference clock source for multiple channels to ensure phase consistency between the sampled signals of each channel.
[0073] The digital signal after analog-to-digital conversion is mixed with the quadrature local oscillator signal generated by the digitally controlled oscillator to obtain a complex signal containing in-phase and quadrature components, thereby shifting the spectrum from the radio frequency band to zero intermediate frequency or low intermediate frequency.
[0074] The mixed complex signal is sequentially subjected to digital low-pass filtering and decimation processing to filter out the image frequency component generated by mixing and reduce the sampling rate to a rate that matches the bandwidth of the target monitoring signal, thereby obtaining the digital baseband signal of each channel.
[0075] The extraction of a reference signal coherent with the currently transmitted jamming signal from the jamming transmission link via directional coupling includes:
[0076] A directional coupler is connected in series between the output of the interference signal power amplifier and the interference transmitting antenna. The main path of the directional coupler transmits the interference signal output by the power amplifier to the interference transmitting antenna with low loss.
[0077] The coupling port of the directional coupler extracts a portion of the energy of the power amplifier output signal according to a preset coupling degree that does not degrade the transmission performance of the main path, and generates a coupling signal.
[0078] After being attenuated and filtered, the coupled signal is sent to the interference cancellation processing unit through an equal-delay transmission link as a reference signal coherent with the currently transmitted interference signal. The reference signal includes the nonlinear distortion characteristics introduced by the power amplifier and is coherent in the time domain with the signal actually radiated into space by the interference transmitting antenna.
[0079] The equal-delay transmission link is constructed using a radio frequency transmission cable of the same length or with the same delay as the signal transmission cable from the monitoring antenna array to the interference cancellation processing unit, so that the transmission delay of the reference signal to the interference cancellation processing unit and the sum of the air delay of the interference signal from the interference transmitting antenna through space to the monitoring antenna array maintain a definite and stable relative delay relationship.
[0080] In this application, a preferred example of constructing an equal-delay transmission link includes:
[0081] In the interference signal transmission link, a directional coupler is connected in series between the output of the power amplifier and the interference transmitting antenna. The coupling port of the directional coupler extracts a portion of the power amplifier's output signal. The coupled signal is then attenuated to adjust the signal level to a suitable amplitude range for subsequent processing. After passing through a filter to remove any out-of-band spurious signals that may have coupled in, it is sent to the reference signal input of the interference cancellation processing unit through a radio frequency transmission cable, which is the reference signal transmission cable.
[0082] Furthermore, the interference signal radiates into space from the interference transmitting antenna, propagates in free space, and undergoes multipath reflections caused by indoor walls and facilities before reaching each antenna element of the monitoring antenna array. The signals received by each antenna element are then amplified by their respective low-noise amplifiers and bandpass filters, and finally transmitted to the signal input of the interference cancellation processing unit via another section of radio frequency transmission cable. This section of radio frequency transmission cable is the monitoring signal transmission cable.
[0083] The total delay of the two paths can be expressed as follows: The total delay of the reference signal path is equal to the sum of the device delay introduced by the directional coupler, attenuator, and filter, and the cable delay introduced by the reference signal transmission cable.
[0084] The total delay of the interference air interface path is equal to the sum of the feeder delay from the output of the power amplifier to the radiating surface of the interference transmitting antenna, the air interface propagation delay from the interference transmitting antenna to the monitoring antenna unit, the feeder delay from the monitoring antenna unit to the low noise amplifier, the device delay of the low noise amplifier and the bandpass filter, and the cable delay introduced by the monitoring signal transmission cable.
[0085] To ensure that the arrival time of the reference signal at the interference cancellation processing unit and the arrival time of the interference component in the mixed received signal at the cancellation processing unit maintain a definite and stable time delay relationship.
[0086] Specifically, the time delay difference between the two paths is determined by measuring or calculating the time delay introduced by each device and the time delay corresponding to the propagation distance of each feeder segment and the air interface. Then, the total time delay of the two paths is made equal by adjusting the physical lengths of the reference signal transmission cable and the monitoring signal transmission cable, or the time delay difference between the two is fixed at a known value that does not drift over time. Specifically, the time delay introduced by each device can be obtained by measuring the S-parameters of a single device using a vector network analyzer to obtain the group time delay characteristics, or the nominal time delay parameters can be obtained from the device datasheet. The time delay of each feeder segment is calculated based on the physical length of the feeder and the signal propagation speed per unit length of the feeder, where the propagation speed per unit length of the feeder is determined by the dielectric constant of the feeder. The air interface propagation time delay is calculated by dividing the straight-line distance between the interference transmitting antenna and the monitoring antenna element by the free space propagation speed of electromagnetic waves.
[0087] In one embodiment, if the two cables cannot be made physically equal in length due to space layout limitations, a fixed delay line can be connected in series in the shorter cable. The fixed delay line can be a surface acoustic wave delay line or an optical fiber delay line, and its delay amount is selected according to the measured value of the time delay difference between the two cables to achieve matching of the total time delay.
[0088] The reference signal and the interference components in the mixed received signal maintain a high degree of temporal coherence upon reaching the interference cancellation processing unit. This coherence is unaffected by micro-delay drift caused by slow changes in ambient temperature or device aging, because the delays of the two transmission cables change synchronously with environmental factors, and their relative delay relationship remains stable.
[0089] Total delay of reference signal path Total delay of interference air interface path They are represented as follows:
[0090]
[0091]
[0092] in, This is the group delay of the directional coupler from the input port to the coupling port, in nanoseconds. It can be obtained from the device datasheet or by measuring the group delay of parameters using a vector network analyzer.
[0093] The group delay introduced by the attenuator is in nanoseconds, which can be obtained from the datasheet or actual measurement.
[0094] The group delay introduced by the filter, in nanoseconds, is the nominal or measured average value of the group delay within the filter's passband.
[0095] The propagation delay introduced by the reference signal transmission cable, in nanoseconds, is obtained by dividing the physical length of the cable by the speed of signal propagation in the cable.
[0096] The propagation delay from the output of the power amplifier to the radiating surface of the interfering transmitting antenna via the feeder is measured in nanoseconds and is calculated from the physical length and propagation speed of the feeder segment.
[0097] The propagation delay of the interference signal from the radiating surface of the interference transmitting antenna through free space to each monitoring antenna element is given in nanoseconds and is calculated by dividing the propagation distance by the speed of light in free space.
[0098] The feeder delay from the antenna unit to the input of the low-noise amplifier, measured in nanoseconds, is calculated from the physical length and propagation speed of the feeder segment.
[0099] This is the group delay of the low-noise amplifier, measured in nanoseconds, obtained from the device datasheet or by actual measurement.
[0100] The group delay introduced by the bandpass filter of the monitoring link is measured in nanoseconds, and is taken as the nominal value or the measured average value of the group delay in the passband.
[0101] The propagation delay introduced by the signal transmission cable is measured in nanoseconds and is calculated by dividing the physical length of the cable by the signal propagation speed in the cable.
[0102] The latency matching conditions for the two paths mentioned above are:
[0103] in, This is the latency alignment accuracy threshold, measured in nanoseconds, and is an integer fraction of the analog-to-digital converter's sampling period.
[0104] Furthermore, during the deployment and calibration phase, the jamming transmission link sends a known training sequence, and a reference signal is simultaneously acquired at the jamming cancellation processing unit. and mixed received signals Perform cross-correlation operation on the two signals:
[0105]
[0106] in: The time-domain waveform of the reference signal acquired at the interference cancellation processing unit;
[0107] The time-domain waveform of the mixed received signal acquired at the interference cancellation processing unit;
[0108] The time delay search variable is used for cross-correlation calculation, with the unit being nanoseconds. The search range covers the ± margin range of the estimated time delay difference between the two paths.
[0109] For the two signals with a time delay difference of The cross-correlation function value at that time delay is used to measure the waveform similarity of two signals at that time delay offset.
[0110] Extract the time delay difference corresponding to the peak position of the cross-correlation:
[0111]
[0112] in: The time delay difference corresponding to the maximum value of the cross-correlation function is expressed in nanoseconds, representing the actual relative time delay difference between the two signals.
[0113] For the cross-correlation function in time delay difference The amplitude at that point is taken as an absolute value to eliminate the effect of phase reversal.
[0114] according to Fine-tune the cable length or the delay of a fixed delay line in one of the paths until the delay alignment accuracy threshold condition is met. |≤ After calibration, the time delay difference is recorded as the prior time delay compensation parameter for the interference cancellation algorithm.
[0115] like Figure 2 The spatial coupling channel from the interference transmission link to the monitoring antenna is modeled as a nonlinear model. The kernel parameters of the nonlinear model are estimated by using the reference signal and the mixed received signal through a nonlinear model identification algorithm to generate the interference reconstruction signal.
[0116] The step of modeling the spatial coupling channel from the interference transmission link to the monitoring antenna as a nonlinear model includes:
[0117] The spatially coupled channel is decomposed into a structure in which the nonlinear distortion part of the transmission link and the multipath part of wireless propagation are cascaded. It should be noted that the interference signal, from its generation in the digital baseband to its final reception by the monitoring antenna, undergoes nonlinear distortion introduced by the power amplifier and multipath effect introduced by spatial propagation. In the physical link, they are in series. Therefore, the entire coupled channel can be modeled as a cascade of two subsystems.
[0118] The nonlinear distortion of the transmission link refers to the nonlinear characteristics introduced by the power amplifier of the interfering signal, including harmonic distortion and intermodulation distortion. The nonlinear characteristics cause the interfering signal to generate in-band distortion components and out-of-band spectral spread components after passing through the power amplifier.
[0119] Specifically, when the power amplifier operates in the region close to the saturation output power, the relationship between the input signal envelope amplitude and the output signal envelope amplitude deviates from a linear proportional relationship. At the same time, the phase of the output signal changes with the change of the input signal envelope amplitude, resulting in an additional phase shift. The nonlinear characteristics cause the interference signal to generate not only in-band distortion components with the same frequency as the input signal after passing through the power amplifier, but also out-of-band spectral spread components that fall into adjacent frequency bands.
[0120] In this embodiment, a memory polynomial model is used to model the nonlinear distortion part of the transmit link, with the reference signal x(n) as input and the signal after nonlinear distortion by the power amplifier as input. For output, its mathematical expression is:
[0121]
[0122] Where: x(n) is the complex baseband sampled value of the reference signal at the nth sampling time, that is, the digital baseband reference signal extracted from the directional coupler and processed by downconversion;
[0123] The complex baseband sample value of the signal output by the nonlinear distortion model of the power amplifier at the nth sampling time;
[0124] K is the nonlinear order, which takes an odd value. The maximum nonlinear order is selected according to the strength of the nonlinear characteristics of the power amplifier, and the typical value range is 5 to 9.
[0125] Q is the memory depth, which represents the degree to which the current output depends on the input signal at the past Q sampling times. It reflects the memory effect of the power amplifier and typically ranges from 2 to 5.
[0126] The kernel parameters are complex numbers that contain amplitude and phase information for the memory polynomial model. The subscript k corresponds to the nonlinear order and the subscript q corresponds to the memory depth. This set of kernel parameters is the parameterized representation of the nonlinear distortion characteristics of the power amplifier.
[0127] Let be the envelope amplitude of the reference signal at the nq-th sampling time.
[0128] The above model simultaneously characterizes the AM-AM and AM-PM distortion characteristics of the power amplifier. AM-AM distortion is manifested as the nonlinear change in output signal amplitude with input signal amplitude, while AM-PM distortion is manifested as the change in the additional phase of the output signal with input signal amplitude. The memory term q>0 allows the model to describe the memory effect of the power amplifier's bias circuit and thermal effects on the signal; that is, the current output depends not only on the current input but also on the input signal from several previous moments.
[0129] The wireless propagation multipath component characterizes the propagation path characteristics of the interference signal from the interference transmitting antenna through space to the monitoring antenna, including the different attenuation and time delay introduced by the direct path, reflection path and scattering path, so that the interference signal exhibits a multipath superposition effect in the time domain.
[0130] Specifically, the multipath propagation component of wireless signals characterizes the propagation path of interference signals from the interfering transmitting antenna through space to the monitoring antenna. In the indoor environment of a classified location, the electromagnetic signals radiated by the interfering transmitting antenna, in addition to the direct path of line-of-sight propagation, also undergo reflection paths formed by reflections from objects such as walls, floors, ceilings, and metal cabinets, as well as scattering paths formed by diffraction from the edges of indoor objects. The signal components from different propagation paths attenuate at different amplitudes and superimpose with different time delays at the monitoring antenna, causing the interference signal to exhibit a multipath superposition effect in the time domain and frequency-selective fading in the frequency domain.
[0131] In this embodiment, the multipath component of wireless propagation is modeled as a finite impulse response filter, the mathematical expression of which is:
[0132]
[0133] in: This is the sampled value of the signal that arrives at the front end of the monitoring antenna after multipath propagation at the nth sampling time, i.e., the interference component in the mixed received signal;
[0134] L is the number of taps in the multipath channel, which is the number of resolvable multipath components. It is determined by the maximum multipath delay spread of the channel and the system sampling period.
[0135] For the complex channel coefficients of the l-th multipath component, which include the amplitude attenuation and phase rotation information of that path;
[0136] l is the multipath tap index, and l=0 corresponds to the direct path or the first multipath component reached.
[0137] complex channel coefficients of taps The amplitude depends on the propagation distance and reflection loss of the corresponding path, while the phase depends on the propagation delay of the corresponding path and the phase flip introduced by reflection.
[0138] The nonlinear distortion part of the transmission link and the multipath part of wireless propagation are jointly modeled into a nonlinear model with memory effect. This nonlinear model takes the reference signal as input and the interference component in the mixed received signal as output. Its system characteristics are characterized by a set of kernel parameters, which describe all the linear and nonlinear transmission characteristics of the interference signal from the end of the transmission link to the monitoring and receiving front end.
[0139] The nonlinear distortion component of the transmit link is cascaded with the multipath component of wireless propagation to establish a joint nonlinear model with a memory effect. This joint nonlinear model takes a reference signal x(n) as input and incorporates interference components from the mixed received signal. For the output. Substituting the expression for the nonlinear distortion part of the transmit link into the expression for the multipath part of wireless propagation, we obtain the mathematical expression for the joint nonlinear model as follows:
[0140]
[0141] The system characteristics of this joint nonlinear model are determined by the kernel parameter set { , } Complete representation, where:
[0142] (l=0,1,...,L-1) describes the linear transfer characteristics of the multipath component of wireless propagation;
[0143] (k=1,3,...,K; q=0,1,...,Q) describes the nonlinear distortion characteristics of the transmit link power amplifier.
[0144] The two sets of kernel parameters together describe the entire linear and nonlinear transmission characteristics of the interference signal from the output of the final stage power amplifier in the transmit link to the monitoring receiver front end. The joint nonlinear model includes the nonlinear distortion effect of the power amplifier, the memory effect of the power amplifier, and the multipath propagation effect of the wireless channel, which can more accurately reconstruct the actual interference components in the mixed received signal.
[0145] The step of estimating the kernel parameters of the nonlinear model using the reference signal and the mixed received signal through an adaptive nonlinear system identification algorithm, and generating an interference reconstruction signal, includes:
[0146] Using the reference signal as the input excitation of the nonlinear model and the mixed received signal as the desired output of the nonlinear model, an adaptive identification loop is constructed.
[0147] In the adaptive identification loop, the reference signal is used to generate an intermediate output signal through a nonlinear model under the current kernel parameters. The error signal between the intermediate output signal and the mixed received signal is calculated. The error signal is used to drive an adaptive update algorithm to iteratively adjust the kernel parameters so that the intermediate output signal gradually approaches the interference components in the mixed received signal.
[0148] When the power of the error signal converges to less than a preset threshold, the kernel parameter is the estimated value of the spatial coupling channel. At this time, the intermediate output signal is the interference reconstruction signal. The interference reconstruction signal matches the actual interference component in the mixed received signal in terms of time-domain waveform, phase, and nonlinear distortion characteristics.
[0149] As a preferred implementation, the adaptive identification loop uses a memory polynomial adaptive filter to achieve recursive parameter estimation.
[0150] Let the estimated value of the nonlinear parameters of the power amplifier after the t-th iteration be denoted as... The estimated value of the multipath channel coefficient is denoted as... Let x(n) be the complex baseband sample value of the reference signal, where n is the sampling time number.
[0151] The reference signal x(n) is input into the nonlinear model under the current kernel parameters, and the intermediate output signal is generated. The results were obtained from the following joint nonlinear model:
[0152]
[0153] In the above formula:
[0154] L is the number of taps in the wireless propagation multipath channel, which is the number of resolvable multipath components.
[0155] K is the highest order of the nonlinear model of the power amplifier, and it takes an odd number, with a typical value range of 5 to 9.
[0156] Q is the memory depth, which represents the degree to which the current output depends on the input signal at the past Q time points. The typical value range is 2 to 5.
[0157] |x(nlq)| represents the envelope amplitude of the reference signal at the corresponding sampling time.
[0158] The complex baseband sample value of the mixed received signal is denoted as... The intermediate output signal With mixed received signals Subtracting the values at each sample point, we obtain the instantaneous error signal e(n;t):
[0159] e(n;t)= -
[0160] Using either iterative least squares or normalized least mean squares algorithms, with the optimization objective of minimizing the power of the error signal e(n;t), the kernel parameters are recursively adjusted. and Taking the iterative least squares algorithm as an example, the kernel parameter update direction always makes the sum of squares of the error signal e(n;t) gradually decrease along the gradient descent direction.
[0161] instantaneous power of the error signal Defined as the average power within a time-domain window:
[0162] =
[0163] in, The number of sampling points in the time-domain window used to calculate the error power.
[0164] Preset convergence threshold Based on the background noise power of the monitoring receiving link The settings are as follows:
[0165] = +ΔP
[0166] Where ΔP is the design margin, ranging from 3dB to 6dB. (Batch noise power) During the system deployment and calibration phase, power was measured on the monitoring and receiving channel after the interference transmission link was turned off.
[0167] Convergence criteria include both of the following:
[0168] The first condition is that the instantaneous power of the error signal is less than the preset convergence threshold, i.e. < ;
[0169] The second condition is that all M consecutive frames satisfy the above condition, that is, for frame number t' = t - M + 1 to t;
[0170] The third item has < Where M is the preset stable frame rate, ranging from 10 to 50 frames, with each frame corresponding to... One sampling point.
[0171] When both of the above conditions are met, the adaptive identification loop is considered to have converged.
[0172]
[0173] After convergence, the current kernel parameter estimates are... and The final estimated values of the spatially coupled channel are denoted as follows: and The current intermediate output signal As the final interference reconstruction signal Its calculation expression is:
[0174]
[0175] At this time, the obtained interference reconstruction signal It achieves substantial matching with the actual interference components in the mixed received signal in the following three dimensions:
[0176] First, in the time-domain waveform, the instantaneous envelope amplitude of the interference reconstruction signal | |Approximates the instantaneous envelope amplitude of the actual interference component;
[0177] Second, regarding phase characteristics, the instantaneous phase of the interference reconstruction signal... The instantaneous phase approximates the actual interference component;
[0178] Third, in terms of nonlinear distortion characteristics, the harmonic distortion components and intermodulation distortion components contained in the interference reconstruction signal are consistent with the nonlinear distortion components of the actual interference components in terms of frequency domain distribution and relative intensity.
[0179] This application combines a convergence threshold set by correlating the error signal power with the background noise power, and introduces a stability criterion for consecutive multi-frames. This effectively avoids false convergence caused by instantaneous noise spikes, ensuring that the kernel parameter estimates reach global optimum in a statistical sense. This allows the kernel parameters of the nonlinear model to continuously track the slow time-varying characteristics of the spatial coupling channel introduced by factors such as ambient temperature changes and device aging during system operation, thereby maintaining a long-term and stable match between the interference reconstruction signal and the actual interference components.
[0180] The adaptive identification loop is implemented using a nonlinear adaptive filter. The structure of the nonlinear adaptive filter is determined by the order and memory depth of the kernel parameter set. The adaptive update algorithm adjusts the filter coefficients iteratively according to the statistical characteristics of the error signal, so that the nonlinear adaptive filter tracks the slow changes in the characteristics of the spatial coupling channel during operation and maintains the continuous effectiveness of interference cancellation.
[0181] In a preferred embodiment, the adaptive identification loop is implemented using a nonlinear adaptive filter. The structure of this filter is determined by the order K, memory depth Q, and number of multipath taps L of the aforementioned kernel parameter set, specifically a polynomial nonlinear filter with memory effect.
[0182] Let the complex baseband sampling value of the reference signal be x(n), and the kernel parameters of the filter in the current t-th iteration include the power amplifier nonlinear coefficient. and multipath channel coefficients The output of the filter at time n is the interference reconstruction signal.
[0183] The mixed received signal is denoted as Then the instantaneous error of the filter The adaptive update algorithm uses the statistical characteristics of the error signal (such as mean square error) as the cost function, and employs iterative least squares or normalized least mean squares algorithms to adjust the filter coefficients according to the following general recursive form:
[0184] θ(t+1) = θ(t) + μ·Δ(t)
[0185] Where θ(t) is the vector composed of all kernel parameters at the t-th iteration, μ is the iteration step size, and Δ(t) is the correction direction calculated from the regression vector of the error signal and the reference signal. The regression vector is derived from... Its composition is determined based on the filter structure.
[0186] During the iteration process, the power of the error signal gradually decreases. When the error power remains below the preset convergence threshold, the filter is considered to have converged, and the current coefficients are the estimated values of the spatially coupled channel. At this point, the filter output... This is the final interference reconstruction signal.
[0187] Since the filter coefficients are continuously updated through error feedback, when the spatial coupling channel changes slowly due to factors such as ambient temperature and device aging, the error signal will increase again and drive the update algorithm to automatically adjust the coefficients, so that the filter output always tracks the changes in the actual interference components, thereby maintaining the effectiveness of interference cancellation in the long term.
[0188] In this embodiment, the order and memory depth of the nonlinear adaptive filter are pre-selected based on the nonlinear strength of the power amplifier and the channel delay spread, and are fixed during system operation, while the filter coefficients are updated online in real time. This ensures the model's fitting accuracy to the real physical channel and overcomes the defect of the fixed model being unable to adapt to environmental changes through the adaptive mechanism, ensuring that the interference reconstruction signal continuously matches the real interference components under strong interference background.
[0189] like Figure 3 As shown, the interference-cancelled clearance signal is obtained from the mixed received signal and the interference reconstruction signal. The clearance signal is then subjected to signal detection and time-domain segmentation, and intrinsic characteristic parameters reflecting the nonlinearity of the transmitter power amplifier are extracted as real-time radio frequency fingerprints.
[0190] The mixed received signal and the interference reconstruction signal are subjected to a sample-by-sample-point alignment and subtraction operation in the time domain. The alignment and subtraction operation is based on the determined relative time delay relationship between the reference signal guaranteed by the equal-delay transmission link and the interference component in the mixed received signal, so that each sampling point of the interference reconstruction signal corresponds in time to the corresponding sampling point of the interference component in the mixed received signal.
[0191] After the alignment and subtraction operation, the interference signal component contributed by the interference transmission link in the mixed received signal is canceled out. The residual signal contains the original electromagnetic signal in the protected area and the background noise introduced by the monitoring and receiving link. The residual signal is the clear signal after the interference cancellation.
[0192] In a preferred embodiment, after obtaining the interference reconstruction signal through the adaptive identification loop, the mixed received signal and the interference reconstruction signal are subjected to a sample-by-sample-point aligned subtraction operation in the time domain.
[0193] Let the complex baseband sample value sequence of the hybrid received signal be... The complex baseband sample value sequence of the interference reconstruction signal is as follows: Where n is the sampling time number (n=0,1,2,...). Since the equal-delay transmission link has been fixed and known during the system deployment and calibration phase through cross-correlation delay measurement or physical cable length equalization, the relative delay difference between the reference signal and the interference component in the mixed received signal is fixed and known, and this delay difference has been used as a priori delay compensation parameter. The unit is the number of sampling periods, and the integer value is recorded in the system.
[0194] Before the operation is executed, the prior delay compensation parameter is first used. The interference reconstruction signal is time-domain registered to obtain the registered interference reconstruction signal. :
[0195] =
[0196] when When the value is positive, it indicates that the interference reconstruction signal leads the interference component in the mixed received signal and needs to be delayed. Each sampling point; when A negative value indicates that the interference reconstruction signal is lagging, and the corresponding number of sampling points need to be advanced. The registration operation aligns each sampling point in the interference reconstruction signal with the corresponding sampling point of the interference component in the mixed received signal in terms of time index.
[0197] After time-domain registration is completed, the mixed received signal is subtracted from the registered interference reconstruction signal point by point to obtain the cancellation output signal. :
[0198] = -
[0199] The sample-by-sample subtraction operation is performed in the complex domain, that is, the subtraction operation is performed on the corresponding sample points of the in-phase component and the quadrature component respectively, so as to maintain the integrity of the signal amplitude and phase information.
[0200] After the above alignment and subtraction operation, the mixed received signal The interference signal components contributed by the interference transmission link are reconstructed from the interference signal. The interference is canceled out. Under ideal convergence conditions, the residual power of the interference in the canceled output signal is lower than the background noise power. It includes the original electromagnetic signals within the protected area and the background noise introduced by the monitoring and receiving link, while the interference component contributed by the interference transmission link is substantially suppressed.
[0201] The above cancel output signal The clearance signal after interference cancellation is used for subsequent signal detection, time-domain segmentation, and radio frequency fingerprint extraction.
[0202] In this embodiment, the prior delay compensation parameters upon which the time-domain registration is based During the system deployment and calibration phase, the following method is used to determine the prior delay compensation parameter: The interference transmission link sends a known training sequence; the reference signal and the mixed received signal are simultaneously acquired at the interference cancellation processing unit; cross-correlation is performed on the two signals; and the delay difference corresponding to the cross-correlation peak position is extracted as the prior delay compensation parameter. Once calibrated, this parameter remains unchanged during system operation because the delays of the reference signal path and the monitoring signal path of the equal-delay transmission link drift synchronously with changes in ambient temperature, and the relative delay difference between them remains stable.
[0203] The alignment and subtraction operation is based on a pre-calibrated and fixed relative time delay relationship, eliminating the need for real-time time delay search in each cancellation operation, thus reducing computational complexity and processing latency. The alignment and subtraction in the complex domain, performed point-by-sampling, fully utilizes the precise matching characteristics of the interference reconstruction signal in the three dimensions of waveform, phase, and nonlinear distortion, enabling substantial cancellation of interference components while preserving useful electromagnetic signals and background noise. The quality of this clearance signal directly determines the accuracy of subsequent RF fingerprint extraction. The deep suppression of interference components ensures that the nonlinear distortion characteristics of the device under test in the clearance signal are not contaminated by interference residuals, thereby guaranteeing the reliability of fingerprint recognition.
[0204] The sample-point aligned subtraction operation is specifically performed in the digital signal processing domain as follows: For each sampling time number n, the complex baseband sample values of the mixed received signal are... The complex baseband sampled values of the registered interference reconstruction signal Perform complex number subtraction. Let the real part of the complex number be the in-phase component (I) and the imaginary part be the quadrature component (Q). Then the specific subtraction formula is:
[0205]
[0206]
[0207] in, and These are the in-phase and quadrature components of the mixed received signal, respectively. and These are the in-phase and quadrature components of the interference reconstruction signal after registration, respectively. and This is to cancel out the in-phase and quadrature components of the output signal.
[0208] It should be noted that the cancellation is based on vector cancellation according to the principle of coherent wave destructive interference.
[0209] Since the adaptive identification loop has converged, the interference reconstruction signal after registration numerically approximates the true interference component in the mixed received signal, that is, it satisfies ≈ yinter(n), where yinter(n) represents the interference signal component contributed by the interference transmission link in the mixed received signal.
[0210] Since the equal-delay transmission link ensures that the relative time-delay difference between the reference signal and the interference component is fixed, and precise alignment of sampling points is achieved after time-domain registration, the instantaneous phase of the interference reconstruction signal < is the same as the instantaneous phase <yinter(n) of the interference component in the mixed received signal.
[0211] Based on the above two conditions, in the complex plane, the interference reconstruction signal vector and the true interference component vector have equal magnitudes and the same phase directions. When performing complex subtraction = - the true interference component vector in the mixed received signal and the subtracted interference reconstruction signal vector undergo destructive interference (i.e., the vector difference approaches zero), so that the contribution of this component in the composite vector is substantially set to zero. At this time, the cancellation output can be expanded as:
[0212] = -
[0213] Since ≈ substituting it into the above formula gives:
[0214] ≈ +
[0215] When there is a small estimation error, the magnitude of the residual interference power depends on | - |², and the residual amount is controlled below the preset convergence threshold, that is, lower than the background noise power.
[0216] The clear-air signal refers to the residual time-domain signal after the above coherent cancellation processing, in which the strong signal component contributed by the interference transmission link has been substantially removed. The residual signal no longer exhibits the power spectrum characteristics of the interference transmission link in the frequency spectrum, and its background noise floor is restored to a state close to the thermal noise floor of the monitoring receiving link, thus obtaining a clear-air, that is, interference-free, frequency spectrum environment. The clear-air signal has the only component: the original electromagnetic signal component generated by legal or abnormal devices within the protected area And the background noise component introduced by the thermal noise and quantization noise of the monitoring receiver link itself. .
[0217] Among them, the first type of parameter characterizes the instantaneous envelope amplitude of the burst signal in the airspace signal. The nonlinear mapping relationship between the current signal and the normalized envelope reference value after phase alignment; the second type of parameter characterizes the instantaneous envelope amplitude and the instantaneous phase offset ∠ of the headroom signal. Nonlinear mapping relationship between
[0218] The clearance signal is subjected to signal detection. Based on the start and end changes of the energy of the electromagnetic signal in the clearance signal in the time domain, the continuous clearance signal is divided into signal segments containing signal bursts and silent segments without signal bursts. Each signal segment has a definite start time and end time in the time domain.
[0219] For each signal segment, the distortion characteristic parameters generated by the power amplifier of the transmitter of the leaking device under test operating in the nonlinear range are extracted. The distortion characteristic parameters include a first type of parameter describing the nonlinear mapping relationship between the input signal envelope amplitude and the output signal envelope amplitude, and a second type of parameter describing the nonlinear mapping relationship between the input signal envelope amplitude and the output signal phase offset. The first type of parameter and the second type of parameter together constitute the real-time radio frequency fingerprint of the transmitter corresponding to the signal segment.
[0220] In a preferred embodiment, the clearance signal is subjected to signal detection to identify whether it contains sudden signals emitted by electromagnetic leakage devices within the protected area. The signal detection employs an energy detection method, dividing the signal into segments based on the start and end changes in the energy of the electromagnetic signal in the clearance signal over the time domain.
[0221] Let the complex baseband sample value sequence of the clearance signal be... First, calculate the instantaneous power P(n) of the headroom signal:
[0222] P(n) = | |²= +
[0223] in, and These are the in-phase and quadrature components of the clearance signal at the nth sampling time, respectively.
[0224] To suppress random power fluctuations caused by noise, a sliding window average is applied to the instantaneous power P(n) to obtain a smoothed power. :
[0225]
[0226] Where w is the sliding window length, expressed in units of sampling points. Its value is determined based on the system sampling rate and the minimum duration of the signal to be detected. The typical range is 1 / 10 to 1 / 5 of the shortest duration of the signal so that the window time length covers the shortest duration of the signal.
[0227] Detection threshold The settings are adaptively configured based on the statistical characteristics of noise power during silent periods in the airspace signal. During system operation, noise power samples are continuously recorded during signal-free periods, and their mean is calculated. and standard deviation The detection threshold is set as follows:
[0228] = +
[0229] in, This is the threshold coefficient, ranging from 3 to 8, determined based on the expected false alarm probability. The higher the value, the lower the probability of a false alarm, but at the same time, it may miss weak signals.
[0230] The smoothing power With detection threshold Compare point by point. When From below Become higher than When, mark that moment as the start time tstart of a signal burst; when From higher Become lower than When the signal burst ends, mark that moment as the end time (tend).
[0231] After the initial marking time, the signal power must remain above the detection threshold for a duration exceeding a preset minimum signal duration Tmin, with a value ranging from 50 microseconds to 1 millisecond. Otherwise, the event exceeding the threshold will be considered a false alarm caused by a noise spike and will not be marked. Similarly, before the end marking time, the signal power must remain below the detection threshold for a duration exceeding a preset minimum silence time Tsilent, with a value ranging from 50 microseconds to 1 millisecond, to confirm that the signal has indeed terminated.
[0232] Based on the above judgment results, the continuous airspace signal will be... The segments are divided into two categories: signal segments containing signal bursts. And silent segments without any sudden signal bursts. Each signal segment In the time domain, it has a definite start time tstart(i) and end time tent(i), and tent(i) - tstart(i) > Tmin. Silence segments are marked as the remaining portion of the continuous headroom signal excluding all other signal segments.
[0233] For each detected signal segment The distortion characteristic parameters generated by the corresponding transmitter power amplifier operating in the nonlinear range within the signal segment are extracted and used as the real-time RF fingerprint of the transmitter corresponding to the signal segment.
[0234] The distortion characteristic parameters include two types of parameters. The first type of parameter describes the nonlinear mapping relationship between the input signal envelope amplitude and the output signal envelope amplitude, i.e., the AM-AM distortion characteristic. Let the input envelope amplitude at each sampling time within the signal segment be Ain(n), and the output envelope amplitude be Aout(n). The mapping relationship between the two is represented by a polynomial model:
[0235]
[0236] Where M is the polynomial order, typically ranging from 3 to 7; Let be the m-th order fitting coefficient (m=0,1,...,M) in the first type of parameters, where is a real number representing the shape characteristics of the AM-AM distortion curve. A set of fitting coefficients is obtained by performing polynomial fitting using the least squares method on all sampled data {Ain(n),Aout(n)} within the signal segment. , ,..., , as the first type of parameter.
[0237] The second type of parameter describes the nonlinear mapping relationship between the input signal envelope amplitude and the output signal phase shift, i.e., the AM-PM distortion characteristic. Let the additional phase shift of the output signal relative to the input signal at each sampling time within the signal segment be... The mapping relationship between it and the input envelope amplitude Ain(n) is also represented by a multinomial model:
[0238]
[0239] Where P is the polynomial order, typically ranging from 3 to 5; Let {Ain(n)} be the p-th order fitting coefficient (p=0,1,...,P) in the second type of parameters, a real number representing the shape characteristics of the AM-PM distortion curve. The least squares method is used for polynomial fitting to obtain a set of fitting coefficients. , ,..., , as the second type of parameter.
[0240] Among the two types of parameters mentioned above, Ain(n) and Aout(n) and The specific methods for obtaining it are as follows:
[0241] For signal segments For each sampling time n, the input envelope amplitude Ain(n) is taken as the positive envelope value of the baseband signal at the current time, i.e., Ain(n) = |xin(n)|, where xin(n) is the complex baseband sample value of the signal segment at sampling time n; the output envelope amplitude Aout(n) is taken as the envelope value of the output signal after the nonlinear effect of the power amplifier. In the headspace signal, Aout(n) is obtained by measuring the instantaneous amplitude of the signal at the corresponding time, i.e., Aout(n) = | |; Phase shift By comparing the instantaneous phase of the output signal The difference between the instantaneous phase xin(n) of the input signal and the input signal is obtained, i.e. = -xin(n).
[0242] If the range of the envelope amplitude variation of the input signal within a signal segment does not fully cover the nonlinear range of the power amplifier, that is, if Ain(n) of all sampling points is lower than the input amplitude corresponding to the 1dB compression point of the power amplifier, then the segment does not meet the conditions for extracting a valid RF fingerprint, and the system discards the segment without performing fingerprint extraction and subsequent comparison operations.
[0243] When a signal segment satisfies the condition that its envelope amplitude covers the nonlinear interval, the two sets of fitting coefficients mentioned above are combined, i.e., { , ,..., , ,..., Together, they constitute the real-time radio frequency fingerprint vector Freal of the transmitter corresponding to the signal segment:
[0244] Freal=[ , ,..., , ,..., ]
[0245] In subsequent steps, the real-time radio frequency fingerprint vector Freal is compared with each registered fingerprint in the legitimate device radio frequency fingerprint database to generate anomaly likelihood.
[0246] In this application, an adaptive threshold segmentation method based on energy detection, combined with dual criteria of shortest duration and shortest silence time, effectively distinguishes between real burst signals and noise spikes. This avoids misjudging random noise spikes as signal initiation, reduces the amount of ineffective computation in fingerprint extraction, improves the accuracy of signal segmentation, and eliminates the influence of power random fluctuations caused by residual background noise in the headroom signal on the threshold comparison results. This makes the determination of start and end times more stable and reliable, effectively avoiding false triggering caused by power mutations at a single sampling point. This application uses a polynomial model to parametrically fit the AM-AM and AM-PM nonlinear distortion characteristics, and combines the two sets of fitting coefficients into a fingerprint vector. This vector comprehensively characterizes the individual nonlinear features of the transmitter power amplifier from two orthogonal dimensions: amplitude and phase. Different transmitters exhibit different AM-AM and AM-PM curve shapes due to variations in power amplifier device manufacturing tolerances, bias circuit differences, and aging levels. This fingerprint vector can effectively distinguish between different devices of the same model.
[0247] The anomaly likelihood is calculated by comparing the radio frequency fingerprint with the device radio frequency fingerprint, and the anomaly likelihood characterizes the source of the intercepted signal;
[0248] The real-time radio frequency fingerprint is compared with each of the registered legitimate device radio frequency fingerprints in the legitimate device radio frequency fingerprint database to measure the similarity of the real-time radio frequency fingerprint with each of the legitimate device radio frequency fingerprints, thereby obtaining the degree of deviation of the real-time radio frequency fingerprint from each legitimate device radio frequency fingerprint.
[0249] The anomaly likelihood is generated by combining the deviation of the real-time RF fingerprint from the RF fingerprints of all legitimate devices. This anomaly likelihood characterizes the probability that the intercepted signal originates from an unknown or abnormal device. Figure 4 As shown.
[0250] As a preferred embodiment, after extracting the real-time radio frequency fingerprint vector Freal from the signal segment, the real-time radio frequency fingerprint is compared with each of the registered legitimate device radio frequency fingerprints in the legitimate device radio frequency fingerprint database to obtain the degree of deviation of the real-time radio frequency fingerprint from each legitimate device radio frequency fingerprint.
[0251] Let Ndev be the total number of registered legitimate devices in the legitimate device RF fingerprint database. Let Freg(j) be the registered fingerprint vector of the j-th legitimate device (j=1,2,...,Ndev). Its dimension is the same as that of the real-time RF fingerprint vector Freal, which is D=(M+1)+(P+1), that is, the sum of the number of fitting coefficients of the first type of parameter and the number of fitting coefficients of the second type of parameter.
[0252] The similarity metric uses weighted Euclidean distance as a quantitative indicator of the degree of deviation. The deviation of the real-time RF fingerprint Freal from the registered fingerprint Freg(j) of the j-th legitimate device is calculated. Calculate as follows:
[0253]
[0254] Where: r is the dimension index of the fingerprint vector, r=1,2,...,D;
[0255] Freal(r) is the value of the real-time radio frequency fingerprint vector in the r-th dimension;
[0256] Freg(j,r) is the value of the r-th dimension of the fingerprint vector registered by the j-th legitimate device;
[0257] is the weighting coefficient for the r-th dimension, and is a preset positive real number used to adjust the contribution ratio of each dimension in the distance metric.
[0258] The weighting coefficients The value of is determined during the system registration phase based on the statistical dispersion of each dimension's characteristics within the group of legitimate devices. Specifically, for the r-th dimension, the sample standard deviation of all registered legitimate devices on that dimension is calculated, and the weighting coefficient for the dimension is taken as . =1 / squared standard deviation, which gives greater weight to features with smaller dispersion across different dimensions, and vice versa, thereby optimizing the fingerprint's discriminative ability.
[0259] When the dimensional feature types and number of real-time RF fingerprints are completely consistent with those of legitimate device registration fingerprints, the aforementioned distance metric can effectively reflect the degree of comprehensive difference between the two in each dimension. The smaller the value, the more similar the real-time RF fingerprint is to the registered fingerprint of the j-th legitimate device, and the higher the probability that the signal segment originates from the j-th legitimate device; The larger the value, the greater the deviation and the lower the probability that it originated from the legitimate device.
[0260] The deviation of the real-time radio frequency fingerprint from the registered fingerprints of all Ndev legitimate devices is obtained. , ,..., Then, the anomaly likelihood Lab is generated by summing all deviations.
[0261] Specifically, first, the minimum value among all deviations is taken. :
[0262] =min{ , ,..., }
[0263] The The corresponding legitimate device is the device in the fingerprint database that best matches the current real-time radio frequency fingerprint. This minimum value reflects the best matching degree between the real-time radio frequency fingerprint and the entire set of legitimate devices.
[0264] Then, the mean of all deviations is calculated. and standard deviation :
[0265]
[0266]
[0267] The outlier likelihood Lab is generated by combining minimum deviation with global statistical features:
[0268]
[0269] in: This is a preset proportionality coefficient, a positive real number, ranging from 2 to 8, used to adjust the sensitivity of the outlier likelihood to the degree of relative deviation;
[0270] It is a preset small positive real number used to prevent the denominator from being zero. Its value is less than the lowest effective order of magnitude of the system's distance calculation accuracy, and its typical value is 10^(-6).
[0271] e is an exponential function with the natural constant e as its base.
[0272] When the real-time RFID fingerprint is highly similar to at least one device in the set of legitimate devices Less than ,ratio When the value approaches zero, Lab approaches 0, indicating a high probability that the signal originates from a legitimate device and a low probability of being abnormal. When the real-time RF fingerprint deviates from the fingerprints of all legitimate devices... and When the values are close, the ratio approaches 1, and at this point, Lab approaches... When α is large enough, Lab approaches 1, indicating that the signal is more likely to originate from an unknown or abnormal device.
[0273] As an alternative calculation method, anomaly likelihood can also be directly based on the minimum deviation. The ratio to the preset anomaly threshold λab is generated as follows:
[0274] Lab=min( / λab,1)
[0275] Wherein, λab is a preset anomaly detection threshold, the value of which is determined during the system deployment phase by repeatedly collecting fingerprints of known legitimate devices and statistically analyzing the intra-class distance distribution. A typical value is 2 to 4 times the average intra-class distance of legitimate devices. When this threshold is exceeded, Lab saturates to 1, indicating a high degree of certainty that it is an anomaly; when When the value is well below this threshold, Lab approaches 0, indicating a high degree of confidence that the device is legitimate.
[0276] The final generated anomaly likelihood Lab is a continuous real scalar with a value range of [0,1], where 0 indicates that the signal is certain to come from a legitimate device, 1 indicates that the signal is certain to come from an unknown or abnormal device, and the intermediate value represents the degree of uncertainty. This continuous value characteristic allows the anomaly likelihood to serve as an observation for uncertainty quantification, providing information input that meets the requirements of Bayesian filtering for subsequent observable Markov decision processes.
[0277] This application employs weighted Euclidean distance for similarity measurement. The weighting coefficients for each dimension are adaptively determined based on the statistical dispersion of the legitimate device group in that dimension. This allows feature dimensions with strong discriminative power to receive greater weight contributions, while feature dimensions with weak discriminative power are effectively suppressed, thereby improving the inter-class discrimination of fingerprint recognition. This ensures that anomaly determination considers both the absolute deviation from the best-matching legitimate device and the relative position of the deviation within the entire set of legitimate devices, avoiding misjudgments caused by the large dispersion of the legitimate device group itself. The anomaly likelihood output is a continuous value in the [0,1] interval rather than a discrete binary decision result, preserving the uncertainty information in the recognition process. This continuous uncertainty measure can be directly utilized by some observable Markov decision processes downstream. Through Bayesian filtering, time-series recursive updates are achieved, making the final linkage decision based on the belief probability fused from multiple time points rather than the instantaneous value at a single time point. This fundamentally overcomes the defect of frequent false alarms under noise fluctuations in traditional threshold decision methods.
[0278] Obtain the scene status observation information from the security management system of the classified location;
[0279] The anomaly likelihood and the scene state observation information are used together as the real-time observation at the current moment;
[0280] In partially observable Markov decision-making, the posterior belief probability distribution of the electromagnetic threat state at the current moment is calculated by Bayesian filtering using the belief probability distribution of the previous moment and the real-time observations at the current moment, thus realizing the temporal recursive update of the belief probability distribution.
[0281] As a preferred implementation method, the scene status observation information is obtained from the security management system of the classified location. The security management system of the classified location is a centralized management platform that collects data from various sensors deployed within the classified location and personnel management information in real time.
[0282] The scene status observation information includes personnel activity status information, door and window opening and closing status information, security alarm status information, time and environmental information;
[0283] Personnel activity status information includes the number of personnel currently on duty in the protected area, personnel density distribution, personnel movement trajectory, and personnel entry and exit records. The above information is collected in real time through infrared sensors, access control systems, and personnel positioning tags deployed in the venue.
[0284] The door and window opening and closing status information includes the opening or closing status of each entrance and window in the protected area, as well as the opening angle and duration of continuous opening. The above information is collected in real time through magnetic reed switches or angle sensors installed on the door and window frames.
[0285] Security alarm status information includes intrusion alarm signs triggered by the perimeter intrusion detection system, fire alarm signs triggered by the fire protection system, and alarm statuses of other security subsystems. This information is obtained from each subsystem of the security management system through standardized interface protocols.
[0286] Time and environmental information includes the current system time, weekday or holiday identification, and the electromagnetic background noise level of the protected area. The electromagnetic background noise level is obtained by power measurement of the overhead signal by the monitoring receiving link during periods without signal.
[0287] The joint decision-making unit maintains a two-way communication connection with the security management system for classified locations. The security management system pushes the above-mentioned scenario status observation information to the joint decision-making unit at a fixed data refresh cycle, or the joint decision-making unit actively queries the data interface of the security management system at the same cycle to obtain the latest status.
[0288] The anomaly likelihood is combined with the scene state observation information obtained from the security management system as the real-time observation at the current moment.
[0289] Let the current time be t, the anomaly likelihood be L(t), and the scene state observation information contain S independent observation dimensions, denoted as... , ,..., The anomaly likelihood is extended to the first dimension of the multidimensional observation vector and merged with the scene state observation information to form a complete real-time observation vector O(t):
[0290]
[0291] When the abnormal likelihood is invalid at a certain moment (e.g., no signal burst is detected in the headspace signal and no valid fingerprint can be extracted), L(t) is set to the preset default value of 0.5, indicating a completely uncertain state, that is, the observation at this moment does not provide any valid information about the electromagnetic threat state.
[0292] Recursive updates of the probability distribution of beliefs based on partially observable Markov decision processes:
[0293] The electromagnetic threat state of classified locations is modeled as a partially observable Markov decision process. A finite set of states X = { , , } includes three threat states: safe state This indicates that there are no abnormal electromagnetic leakage devices present in the currently protected area; a suspicious state. This indicates the presence of an unidentified signal source, but not yet sufficient to confirm a threat; Threat status. This indicates that an abnormal electromagnetic leakage device has been confirmed and an immediate response is required.
[0294] Define the system's belief probability distribution b(t) as the confidence probability vector for each of the above threat states at time t:
[0295] b(t) = [P( ),P( ),P( )]
[0296] The sum of the three probability values mentioned above is always equal to 1. The essence of this belief distribution is that the system does not give a single, definitive judgment of the threat, but maintains a probability distribution for all possible states, thereby quantifying the degree of certainty about each possible state.
[0297] At the initial time t=0, the belief probability distribution b(0) is set as the prior probability distribution, usually b(0)=[0.8,0.1,0.1], that is, the system is in a safe state by default when there is no observation information, and the probability of suspicious state and threat state is very low.
[0298] From the initial moment onwards, the system performs the following recursive update process:
[0299] Before obtaining new observations at the current moment, the system first infers the most likely state at the current moment based on the beliefs from the previous moment and the natural laws governing the change of the electromagnetic threat state over time. This inference is achieved by multiplying the probabilities of each state from the previous moment by the state transition matrix:
[0300]
[0301] Where T is the state transition probability matrix, and its element T(i,j) represents the state from the previous time step. Transition to the current state The probability is calculated using a matrix of pre-defined fixed parameters, whose values reflect the a priori laws governing the evolution of electromagnetic threat states over time. In this embodiment, the probability of a safe state evolving into a suspicious state within a short period is low and can be set to 0.02; the probability of a suspicious state evolving into a threat state is moderate and can be set to 0.2; the probability of a threat state remaining a threat state is high and can be set to 0.8; and the probability of a threat state automatically reverting to a safe state is extremely low and can be set to 0.05.
[0302] In this application, some key elements of the transition matrix T are set as functions of the scene state observation information Z(t). Specifically, the transition probability from a safe state to a suspicious state... With doors and windows open and frequency of personnel entry and exit Positive correlation, its expression is: = +α +β in, =0.02 is the base transition probability, α=0.03 is the influence coefficient of doors and windows, and β=0.01 is the influence coefficient of personnel flow. When doors and windows are open and people frequently enter and exit, the transition probability dynamically increases to 0.08-0.12, accelerating the shift of belief to a doubtful state; when the place is completely closed and unoccupied, the transition probability falls back to the base value.
[0303] Even if no new observations are made, the threat status will still evolve naturally according to prior laws. There is a small probability that a suspicious signal will appear in the safe state. If the suspicious state persists, there is a moderate probability that it will be confirmed as a threat. Once it is confirmed as a threat, it is difficult to automatically resolve it in a short period of time.
[0304] After obtaining the real-time observation O(t) at the current moment, the posterior belief probability distribution at the current moment is calculated using Bayesian filtering:
[0305] b(t)=[P(O(t)| )·bpred( )] / [
[0306] In the above formula, bpred( () represents the state in the prior beliefs at the current moment obtained from the prediction step. The corresponding probability value; P(O(t)| Let be the observation likelihood function, representing the likelihood under threat state . The conditional probability density of O(t) is observed under the given conditions.
[0307] The observation likelihood function is modeled based on the anomaly likelihood and the physical characteristics of each scene state observation dimension, and it is assumed that each observation dimension is conditionally independent under a given threat state. Therefore:
[0308] P(O(t)| )=P(L(t)| )·
[0309] For the abnormal likelihood L(t), under the threat state The conditional probability density P(L(t)| The model is based on a Gaussian distribution. For the safe state... The expected value of the anomaly likelihood is low, with a mean of 0.1 and a standard deviation of 0.15, indicating that occasional fluctuations in the anomaly likelihood under safe conditions are usually small; for threat conditions... The expected value of the anomaly likelihood is high, with a mean of 0.85 and a standard deviation of 0.15, indicating that the anomaly likelihood remains at a high level under threat conditions. The mean of the suspicious state is in the middle, with a slightly larger standard deviation, reflecting the higher uncertainty of the state.
[0310] For scene state observation dimensions The conditional distribution is determined based on the type of sensor: for binary sensors, such as the opening and closing state of doors and windows of magnetic door switches, a Bernoulli distribution is used for modeling; for continuous sensors, such as personnel density and electromagnetic background noise levels, a Gaussian distribution is used for modeling.
[0311] For example, the probability of observing suspicious signals is higher during peak hours than during off-peak hours, and the likelihood of a threat is higher when doors and windows are open than when they are closed.
[0312] The posterior probability of a state is proportional to its prior probability multiplied by the likelihood of observing current evidence in that state. If a state has a high prior probability and the current observation is also likely to occur in that state, the posterior probability of that state is strengthened; conversely, if the prior probability is high but the current observation is almost impossible in that state, the posterior probability of that state is significantly weakened.
[0313] The denominator term in the Bayesian filter update formula This is a normalization constant, ensuring that the sum of all elements in the updated belief probability distribution equals 1, so that the system maintains a complete and consistent probability distribution for all possibilities.
[0314] The updated belief probability distribution b(t) is used as the posterior belief probability distribution of the electromagnetic threat state at the current moment for subsequent coordinated decision-making steps. At the next moment t+1, this posterior belief distribution is re-inputted into the prediction step as the belief b(t) of the previous moment, realizing the temporal recursive update of the belief probability distribution.
[0315] Recursive belief updates require the gradual accumulation of consistent evidence from observations over multiple consecutive moments. Beliefs slowly shift from a safe state to a suspicious state and then to a threatening state, with coordinated actions triggered only after the belief probability fully converges to a certain threatening state. Instantaneous abnormal fluctuations do not cause drastic jumps in beliefs, while the accumulation of persistent threat evidence enables beliefs to gradually converge to a threatening state, achieving timely responses.
[0316] This application employs a recursive belief update mechanism based on a partially observable Markov decision process. Abnormal likelihood fluctuations at a single moment or instantaneous false alarms from individual sensors do not lead to drastic jumps in threat state estimation. The system only gradually converges to a definite threat judgment after obtaining consistent evidence over multiple consecutive moments, effectively suppressing erroneous actions caused by instantaneous interference. The introduction of the state transition probability matrix enables the system to utilize the prior temporal patterns of electromagnetic threat state evolution. The observation likelihood function is independently modeled for abnormal likelihood and various scenario states, allowing the contribution of different types of observation information to threat belief updates to be adaptively weighted according to their information reliability and discriminativeness: abnormal likelihood receives a larger update weight when it has high discriminativeness in the threat state, and a larger weight when the correlation between scenario state information and threat state is strong; otherwise, it is automatically suppressed. This gives the belief estimation process adaptive multi-source information fusion characteristics.
[0317] Obtain scene status observation information of classified locations, and use the anomaly likelihood and scene status observation information as real-time observation inputs to the linkage decision unit to recursively update the belief probability distribution of electromagnetic threat status based on time-series observations.
[0318] By using the updated belief probability distribution and the cost function consisting of security risk cost and business impact cost, the linkage decision unit is solved to obtain the linkage action that minimizes the long-term expected cumulative cost.
[0319] The objective function of the coordinated decision-making unit consists of two parts: security risk cost and business impact cost. Security risk cost This represents the security risk cost incurred in executing coordinated action 'a' under threat state 'x'; the business impact cost. This indicates the cost of disruption to the normal business operations of the protected area caused by executing the linkage action 'a'.
[0320] A preferred security risk cost Cost of business impact Examples of the numerical setting method include: pairwise comparing and scoring the security risks of each action in each threat state, constructing a judgment matrix, calculating the eigenvector corresponding to the maximum eigenvalue and performing consistency verification, and finally normalizing to obtain the relative cost weights. The business impact cost is calibrated by scoring the interruption degree of different actions on business continuity, and the calibration results are stored in the system configuration file in the form of a parameter table. Users can call different preset parameter templates according to the security levels (top secret, secret, confidential) of different classified venues without modifying the system core algorithm.
[0321] Define the set of executable linkage actions A = { , , , }, which includes the following four linkage actions: No action , indicating that no linkage operation is performed; Acoustic and optical alarm , indicating that the acoustic and optical alarm devices in the protected area are triggered; Signal blocking , indicating that the electromagnetic interference device is activated to actively block abnormal signals; Personnel verification , indicating that a field verification instruction is sent to security personnel. The security risk costs and business impact costs of different actions are different, and the specific values are pre-calibrated according to the security level of the protected area and the requirements of business continuity during the system deployment phase.
[0322] Security risk cost is set following the following principles: The security risk cost of performing no action in a threat state is the highest, the security risk costs of performing signal blocking and personnel verification are relatively low, and the security risk cost of performing an acoustic and optical alarm is in the middle; In a safe state, regardless of the action performed, the security risk cost is zero or extremely low. Business impact cost is set following the following principles: The business impact cost of no action is the lowest, the acoustic and optical alarm is the second, the personnel verification is higher, and the signal blocking is the highest.
[0323] An optimal linkage action solving method for a preferred belief probability distribution:
[0324] After obtaining the updated belief probability distribution b(t) at each moment t, the system does not make a greedy decision based on the instantaneous belief at the current moment, but solves the linkage action that minimizes the long-term expected cumulative cost.
[0325] Define the value function V(b) as the negative value (i.e., the long-term return) of the future expected cumulative cost obtained by executing according to the optimal strategy starting from the current belief state b. This value function satisfies the Bellman optimality equation:
[0326]
[0327] Among them, =-[ + The negative sign represents the immediate reward obtained by performing action a in the current belief state b, and it indicates that the cost minimization problem has been transformed into a reward maximization problem. This is a discount factor (ranging from 0.90 to 0.99), used to adjust the relative importance of future returns to immediate returns. The closer the value is to 1, the more the system prioritizes long-term benefits; The belief state at the next moment is updated after performing action a and observing a new observation u; Let u be the probability of observing u after performing action a under the current belief b.
[0328] The optimal linkage strategy is obtained by solving the Bellman optimality equation offline. Specifically, a value iteration algorithm or a strategy iteration algorithm is used to pre-calculate the optimal action mapping table for all reachable belief states. During the online operation of the system, the linkage decision unit queries the mapping table based on the belief probability distribution b(t) at the current moment to obtain the linkage action a*(t) that minimizes the long-term expected cumulative cost.
[0329] a*(t)= V(b(t))
[0330] When the updated belief probability distribution b(t) shows the probability P(t) of a threat state When the value is below the first decision threshold, no action is output. The system continues to monitor; when the threat probability falls between the first and second decision thresholds, it outputs an audible and visual alarm. The system alerts security personnel to the situation but does not interrupt operations; when the probability of a threat exceeds the second decision threshold, the system blocks signals based on the specific details in the scenario status observation information. and personnel verification Choose between the following options: If the classified area is currently in an unoccupied period or the personnel density is below the preset value, select signal blocking to quickly suppress the risk of electromagnetic leakage; if the classified area is currently in a densely populated period, select personnel verification to avoid signal blocking from interfering with normal business activities.
[0331] Real-time observations at each moment drive the belief probability distribution to evolve towards more accurate threat estimation through Bayesian filtering. The updated belief probability distribution, combined with a pre-calculated long-term cost minimization strategy, outputs the optimal coordinated action. After executing the coordinated action, new observations at the next moment drive belief updates again. The design logic of this closed loop is as follows: the triggering of coordinated actions no longer depends on the binary decision of whether the anomaly likelihood exceeds a fixed threshold at a single moment, but is based on the convergence of belief probabilities after the accumulation of observational evidence over multiple consecutive moments. The belief probability gradually shifts from the initial safe state to the suspicious state and then to the threat state. Instantaneous anomaly fluctuations do not lead to drastic jumps in belief, while the accumulation of persistent threat evidence enables belief to gradually converge, thereby achieving a balance between response sensitivity and false alarm resistance at the decision-making level.
[0332] This application incorporates the continuous uncertainty measure of abnormal likelihood with multi-dimensional scene state observation information into a unified Bayesian filtering framework, enabling the estimation of electromagnetic threat status to simultaneously integrate radio frequency fingerprinting results from the signal domain and multi-source information from the physical domain, such as personnel, environment, and security. By adopting a belief recursive update mechanism based on a partially observable Markov decision process, fluctuations in abnormal likelihood at a single moment or instantaneous false alarms from individual sensors will not cause drastic changes in threat status estimation. The system only gradually converges to a definite threat judgment after obtaining consistent evidence over multiple consecutive moments, effectively suppressing erroneous actions caused by instantaneous interference.
[0333] The cost function incorporates both security risk costs and business impact costs, and uses Bellman optimization to find the action that minimizes the cumulative cost in the long term, rather than greedily choosing the action with the lowest cost at the current moment. This proactive decision-making mechanism enables the system to take low-impact early warning actions before security risks are fully confirmed, exchanging lower immediate business costs for potentially higher security benefits, thereby achieving an optimal long-term balance between security and availability.
[0334] Example 2
[0335] A system for monitoring abnormal electromagnetic signals in classified locations and for multi-scenario linkage includes: an acquisition unit, a processing unit, and a linkage decision-making unit, with each unit being time-synchronized and capable of data interaction and transmission;
[0336] The signal acquisition unit includes a broadband monitoring antenna array and a directional coupler. The broadband monitoring antenna array is deployed within the protected area to acquire mixed received signals. The directional coupler is connected in series between the output of the interference signal power amplifier and the interference transmitting antenna to extract a reference signal that includes power amplifier nonlinear distortion and is coherent with the transmitted interference. The signal acquisition unit is also configured with an equal-delay transmission link to maintain a fixed and calibrable relative delay difference between the reference signal and the interference components in the mixed received signal.
[0337] The processing unit is signal-connected to the signal acquisition unit and is used to generate an interference reconstruction signal by taking the reference signal and the mixed received signal as inputs and using a kernel parameter identification algorithm of a joint nonlinear channel model. After time-domain alignment and subtraction, the clearance signal is output. The clearance signal is then divided into time domains and nonlinear distortion features are extracted to generate a real-time radio frequency fingerprint, which is then compared with the legitimate device radio frequency fingerprint database to output anomaly likelihood.
[0338] The linkage decision-making unit communicates bidirectionally with the processing unit and the security management system for classified locations. It receives the anomaly likelihood and multi-dimensional scene state observation information as real-time observations. Based on a partially observable Markov decision process, it recursively updates the belief probability distribution of the electromagnetic threat state through Bayesian filtering. Combined with a cost function that includes security risk costs and business impact costs, it outputs the linkage control action with the minimum long-term expected cumulative cost.
[0339] Example 3
[0340] This embodiment is applied to the core R&D area of a classified research unit. The area is a rectangular enclosed space measuring 30 meters long, 20 meters wide, and 3.5 meters high, containing office workstations, a conference table, metal filing cabinets, and several classified information processing devices. The electromagnetic leakage paths within the protected area mainly include: video signal radiation leakage from classified computer monitors, conduction leakage of control signals and data from classified printers during operation, and local oscillator leakage from various classified terminal devices.
[0341] Broadband monitoring antennas were deployed at the four corners of the ceiling in this area, forming a 2×2 monitoring antenna array. Each monitoring antenna is a log-periodic broadband antenna, operating at frequencies from 30MHz to 6GHz, with an antenna gain of 5dBi. The spatial reception range of each monitoring antenna element was verified through field strength simulation to ensure coverage of all electromagnetic leakage paths requiring protection.
[0342] The electromagnetic signals received by each monitoring antenna unit are first fed into a low-noise amplifier. The noise figure of the low-noise amplifier is set to 1.5dB, and the gain is set to 28dB. This gain value, after compensating for the approximately 3dB insertion loss of the subsequent bandpass filter, ensures that the overall noise figure of the receiving link is dominated by the low-noise amplifier, with an overall noise figure of approximately 2.0dB. The signal after low-noise amplification is then fed into a bandpass filter. The passband range of the bandpass filter is 30MHz to 6GHz, and the stopband attenuation is configured to 40dB to ensure that strong interference signals outside the operating frequency band are suppressed to within the linear range of the receiving link. The filtered signal is then fed into an analog-to-digital converter (ADC) with a sampling rate of 200 mega-samples per second and a sampling precision of 14 bits. The digital signal after ADC is mixed with the quadrature local oscillator signal generated by a digitally controlled oscillator, achieving a frequency spectrum shift from the radio frequency band to zero intermediate frequency, resulting in a complex baseband signal containing in-phase and quadrature components.
[0343] The jamming transmission link is deployed in the southwest corner of the protected area. The jamming signal power amplifier has an output power of 20 watts and operates near its saturation output power. A directional coupler is connected in series between the power amplifier output and the jamming transmission antenna. The coupling degree of the directional coupler is set to 20 dB, and the insertion loss of the main path is less than 0.5 dB. The coupling port of the directional coupler extracts 1% of the energy of the power amplifier output signal to generate a coupled signal. The coupled signal is attenuated to a suitable amplitude range for subsequent processing by an attenuator set to 10 dB, then filtered to remove out-of-band spurious signals, and finally sent to the jamming cancellation processing unit through a 15-meter-long low-loss RF coaxial cable with a loss of 0.3 dB / m, a dielectric constant of 2.1, and a signal propagation speed of approximately 69% of the speed of light in a vacuum, as a reference signal coherent with the currently transmitted jamming signal.
[0344] The signals received by each unit of the monitoring antenna array are then sent to the signal input terminal of the interference cancellation processing unit through another 12-meter-long radio frequency coaxial cable of the same specification after passing through their respective low-noise amplifiers and bandpass filters.
[0345] During the deployment and calibration phase, the group delay characteristics of each device are measured using a vector network analyzer, and the total delay of each path is calculated by combining the physical length of the cables and the propagation speed, with the total delay of the reference signal path also considered.
[0346] = (1.2ns)+ (0.5ns)+ (3.0ns)+ (15m / (0.69×3× m / s)≈72.5ns)≈77.2ns.
[0347] Total delay of interference air interface path: = (0.3ns)+ (15m / 3× m / s≈50ns)+ (0.3ns)+ (1.5ns)+ (3.0ns)+ (12m / (0.69×3× m / s)≈58.0ns)≈113.1ns.
[0348] The time delay difference between the two paths is approximately 35.9 ns, exceeding the alignment accuracy threshold corresponding to an integer fraction of the analog-to-digital converter's sampling period. By connecting a fixed delay line in series with the shorter path and setting the delay to 36 ns, the total time delay of the two paths is matched to an error of less than 1 ns, satisfying the time delay alignment accuracy threshold condition.
[0349] The spatially coupled channel is decomposed into a structure where the nonlinear distortion component of the transmit link and the multipath component of wireless propagation are cascaded. The nonlinear distortion component of the transmit link is characterized using a memory polynomial model, with the nonlinear order K set to 7 and the memory depth Q set to 3. This parameter combination is based on the following considerations: the power amplifier operates near saturation and exhibits strong nonlinearity, requiring a high nonlinear order to accurately characterize the curvature of the AM-AM and AM-PM distortion curves; simultaneously, the memory effect introduced by the bias circuit and thermal effects of the power amplifier manifests as the dependence of the current output on the input signal at the past three sampling times, and Q=3 is sufficient to cover the time span of the main memory effect. The multipath component of wireless propagation is modeled as a finite impulse response filter, with the number of multipath taps L set to 5, corresponding to five resolvable multipath components in the indoor environment: direct path, primary wall reflection path, secondary wall reflection path, ground reflection path, and ceiling reflection path.
[0350] The adaptive identification loop uses an iterative least squares algorithm for kernel parameter estimation. The instantaneous power of the error signal... Defined as the average power within a time-domain window of Nw = 1024 sampling points. Preset convergence threshold. Based on the background noise power of the monitoring receiving link Setup. During the system deployment and calibration phase, the background noise power was measured after the interference transmission link was turned off. =-115dBm (corresponding to a normalized power of approximately 3.16×) (milliwatts). The design margin ΔP is set to 3dB, then =P_noise + 3dB ≈ -112dBm. The convergence criterion is: < Furthermore, for M=20 consecutive frames, each frame corresponding to N_w=1024 sampling points satisfies the above conditions. When both conditions are satisfied simultaneously, the adaptive identification loop is considered to have converged, the current kernel parameter estimate is used as the final estimate of the spatially coupled channel, and the current intermediate output signal is used as the final interference reconstruction signal.
[0351] In this application, a preferred method for initializing core parameters is as follows: during initial startup or channel reset, the power amplifier nonlinear core parameters are initialized. The initial value is set to =1, and the initial values of all other higher-order terms and memory terms are set to 0. This initial value corresponds to the initial assumption that the power amplifier operates in the ideal linear region; multipath channel kernel parameters The initial value is set to 1, and the rest of the multipath taps (l≥1) The initial value is set to 0, which corresponds to the initial assumption of a direct path in ideal free space. To ensure convergence to the global optimum, in the first iteration... Within 200 sampling points, the recursive least squares algorithm is used for pre-convergence (forgetting factor λ=0.99). After the error power drops to less than 30% of the initial power, the algorithm is switched to the normalized least mean square algorithm with lower computational complexity and a step size factor μ=0.1 for tracking.
[0352] After obtaining the interference reconstruction signal, the mixed received signal and the interference reconstruction signal are subtracted in the time domain, sample-by-sample alignment. Prior delay compensation parameters. The value was determined to be 0 during the calibration phase. Interference reconstruction signal after time-domain registration. = The canceled output signal is obtained by subtracting the samples one by one. = Subtraction is performed on the in-phase and quadrature components in the complex domain, respectively. After cancellation, the interference signal components in the mixed received signal are canceled out, and the residual signal is the clearance signal. The power spectrum characteristics of the interfering transmission link are substantially removed from its power spectrum, and the background noise floor is restored to a noise floor level close to -112dBm.
[0353] Energy detection was performed on the clearance signal. The sliding window length W was set to 256 sampling points, corresponding to 1.28 microseconds, covering approximately 1 / 40 of the shortest signal duration of 50 microseconds. During system operation, noise power samples were continuously recorded during signal-free periods, and their mean and standard deviation were calculated. The detection threshold coefficient β was set to 5, the shortest signal duration Tmin was set to 50 microseconds, and the shortest silence time Tsilent was set to 50 microseconds. Based on the above detection parameters, the continuous clearance signal was divided into signal segments containing signal bursts and silent segments without signal bursts.
[0354] For each detected signal segment, AM-AM and AM-PM distortion characteristic parameters are extracted. The order M of the AM-AM polynomial is set to 5, and the order P of the AM-PM polynomial is set to 4. The input envelope amplitude A_in(n) and output envelope amplitude Aout(n) data of all sampling points within the signal segment are subjected to polynomial fitting using the least squares method to obtain the fitting coefficients. , , , , Polynomial fitting is performed on the input envelope amplitude Ain(n) and phase offset Δφ(n) data to obtain the fitting coefficients. , , , The two types of coefficients are merged into a real-time radio frequency fingerprint vector Freal=[ , , , , , , , , ], dimension D=11.
[0355] If Ain(n) of all sampling points within a signal segment is lower than the input amplitude corresponding to the 1dB compression point of the power amplifier, i.e., the transmitter is operating in the linear region within the signal segment, then the segment is discarded and fingerprint extraction is not performed.
[0356] The total number of registered legitimate devices in the legitimate device RF fingerprint database is Ndev=15, covering all authorized classified information processing devices within the protected area.
[0357] The similarity measure uses weighted Euclidean distance. The weighting coefficients for each dimension are as follows. During the system registration phase, it was determined that: the standard deviation of the samples from 15 legitimate devices in each of the 11 dimensions would be calculated, and the results would be taken as follows: =1 / square of the standard deviation.
[0358] The deviation of the real-time RF fingerprint Freal from the registered fingerprint Freg(j) of the j-th legitimate device is calculated for j=1 to 15 respectively. Value, take the minimum value Calculate the mean of all deviations. and standard deviation The proportionality coefficient α is set to 5, and the anomaly likelihood is... The anomaly likelihood Lab is a continuous value in the interval [0,1].
[0359] The linkage decision-making unit obtains scene status observation information from the security management system of classified locations every 100 milliseconds. At the current time t=10 seconds, the scene status is as follows: Personnel activity status: There are currently 3 people on duty in the protected area, and the personnel density is low; Door and window opening status: All entrances and windows are closed; Security alarm status: No intrusion alarms, no fire alarms; Time and environmental information: The current time is 14:30 on a weekday afternoon, not a holiday, and the electromagnetic background noise level is -110dBm.
[0360] The anomaly likelihood L(t) = 0.78. The anomaly likelihood and scene state observation information are combined into a real-time observation vector O(t) = [0.78, 3 people, all doors and windows closed, no alarm, 14:30, -110dBm]ᵀ, and the initial belief probability distribution b(0) = [0.8, 0.1, 0.1].
[0361] In the observation likelihood function, the conditional probability density of the anomaly likelihood L(t) = 0.78 under each state is: P(0.78| =0.08 (Gaussian distribution, mean 0.1, standard deviation 0.15), P(0.78| =0.52 (mean 0.5, standard deviation 0.25), P(0.78| =0.91 (mean 0.85, standard deviation 0.15). In the scenario state information, under conditions of low personnel density and all doors and windows closed, the conditional probability of a threat state is slightly higher than that of a safe state. After synthesizing the likelihood values of each observation dimension, the posterior belief probability distribution b(t) is calculated using the Bayesian filtering formula.
[0362] After recursive updates, the current belief probability distribution is approximately b(t) = [0.35, 0.42, 0.23], representing a 35% safe state, a 42% suspicious state, and a 23% threat state. The system has not yet fully confirmed the threat, but the probability of the suspicious state is already higher than that of the safe state.
[0363] Linked action set A={ No action Audible and visual alarms Signal blocking Personnel verification. Safety risk costs. The settings are as follows: Under threat status, =100, =60, =10, =15; Under safe conditions, all actions All are 0. Business impact cost The settings are as follows: ( )=0, ( )=5, ( )=30, ( =80.
[0364] The discount factor η is set to 0.95. The value function V(b) satisfies the Bellman optimality equation, which is solved in advance using an offline value iteration algorithm. With the current belief b(t) = [0.35, 0.42, 0.23], the optimal action mapping table is queried, and the threat state probability P(t) is calculated. The value of 0.23 is lower than the first decision threshold of 0.3, so the system outputs no action. Continue to maintain monitoring status.
[0365] If the anomalous likelihood continues to rise to 0.92 in the next time step, after belief update, P( If the value rises to 0.55, falling between the first threshold of 0.3 and the second threshold of 0.6, the system will output an audible and visual alarm. This alerts security personnel to pay attention. If the anomaly likelihood remains high for several consecutive moments and the scene status information further supports the threat assessment, P( The value rises to 0.75, and the system makes a secondary decision based on the personnel density information in the scene: if the current personnel density is lower than the preset value, signal blocking is selected. To quickly suppress the risk of electromagnetic leakage; if it is a period of high population density, then personnel verification should be selected. To avoid signal disruptions that could interfere with normal business operations.
[0366] It is important to note that the constructions and arrangements of this application shown in several different exemplary embodiments are merely illustrative. Although only two embodiments are described in detail in this disclosure, those who consult this disclosure will readily understand that many modifications are possible without substantially departing from the novel teachings and advantages of the subject matter described in this application. These modifications may include, for example, changes in the size, dimensions, structure, shape, and proportions of various elements, as well as parameter values (e.g., temperature, pressure, etc.), installation arrangements, the use of materials, colors, orientations, etc. For example, an element shown as integrally formed may be composed of multiple parts or elements, the position of elements may be inverted or otherwise altered, and the nature or number or position of discrete elements may be changed or altered. Therefore, all such modifications are intended to be included within the scope of this application. The order or sequence of any process or method may be changed or reordered by alternative embodiments. Any "apparatus plus function" clause is intended to cover, and not only structurally equivalent but also equivalent structures, the structures performing the functions described herein. Other substitutions, modifications, alterations, and omissions may be made in the design, operation, and arrangement of the exemplary embodiments without departing from the scope of this application. Therefore, this application is not limited to a particular embodiment, but extends to various modifications that still fall within the scope of the appended claims.
[0367] Furthermore, in order to provide a concise description of exemplary embodiments, not all features of actual embodiments (i.e., those features that are not relevant to the best mode of performing this application as currently considered, or those features that are not relevant to implementing this application) may be omitted.
[0368] It should be understood that numerous specific implementation decisions can be made during the development of any practical implementation, such as in any engineering or design project. Such development efforts may be complex and time-consuming, but for those of ordinary skill in the art who benefit from this disclosure, the development effort will be a routine task in design, manufacturing, and production without requiring extensive experimentation.
[0369] It should be noted that the above embodiments are only used to illustrate the technical solutions of this application and are not intended to limit it. Although this application has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of this application without departing from the spirit and scope of the technical solutions of this application, and all such modifications and substitutions should be covered within the scope of the claims of this application.
Claims
1. A method for monitoring abnormal electromagnetic signals in classified locations and for multi-scenario linkage, characterized in that, include: Acquire the mixed received signal contaminated by interference, and extract a reference signal coherent with the currently transmitted interference signal from the interference transmission link; The spatial coupling channel from the interference transmission link to the monitoring antenna is modeled as a nonlinear model. The kernel parameters of the nonlinear model are estimated using the reference signal and the mixed received signal to generate the interference reconstruction signal. The interference-cancelled clearance signal is obtained from the mixed received signal and the interference reconstruction signal. The clearance signal is then subjected to signal detection and time-domain segmentation to extract nonlinear intrinsic feature parameters as a real-time radio frequency fingerprint. The anomaly likelihood is calculated by comparing the radio frequency fingerprint with the device radio frequency fingerprint. The anomaly likelihood and the scene state observation information are used as real-time observation inputs to the linkage decision unit. The belief probability distribution of the electromagnetic threat state is recursively updated according to the time series observation. By using the updated belief probability distribution and cost function, the linked decision unit is solved to obtain the linked action with the minimum long-term expected cumulative cost.
2. The method for monitoring abnormal electromagnetic signals in classified locations and coordinating multiple scenarios as described in claim 1, characterized in that: Acquire mixed received signals that are contaminated by interference from the monitoring antenna; A broadband monitoring antenna array is deployed in the protected area of a classified location so that the spatial receiving range of the broadband monitoring antenna array covers all electromagnetic leakage paths that need to be protected. Each monitoring antenna unit in the broadband monitoring antenna array receives electromagnetic signals in the space. The electromagnetic signals are formed by the superposition of electromagnetic signals generated in the protected area and interference signals output by the interference transmission link through spatial propagation and multipath reflection. The electromagnetic signals received by each monitoring antenna unit are sequentially amplified with low noise and bandpass filtered to suppress the saturation of the receiving link caused by strong out-of-band signals. The amplified and filtered signals are then subjected to analog-to-digital conversion and down-conversion to obtain the digital baseband signals of each channel, which serve as the mixed received signals contaminated by interference.
3. The method for monitoring abnormal electromagnetic signals in classified locations and coordinating multiple scenarios as described in claim 1, characterized in that: A directional coupler is connected in series between the output of the interference signal power amplifier and the interference transmitting antenna. The main path of the directional coupler transmits the interference signal output by the power amplifier to the interference transmitting antenna with low loss. The coupling port of the directional coupler extracts a portion of the energy of the power amplifier output signal according to a preset coupling degree that does not degrade the transmission performance of the main path, and generates a coupling signal. After the coupled signal is attenuated and filtered, it is sent to the interference cancellation processing unit through an equal-delay transmission link as a reference signal coherent with the currently transmitted interference signal. The reference signal includes the nonlinear distortion characteristics introduced by the power amplifier, and the equal-delay transmission link ensures that the sum of the transmission delay of the reference signal to the interference cancellation processing unit and the air delay of the interference signal from the interference transmitting antenna through space to the monitoring antenna array maintains a fixed and calibrable relative delay difference between the reference signal and the air-propagating interference component.
4. The method for monitoring abnormal electromagnetic signals in classified locations and coordinating multiple scenarios as described in claim 1, characterized in that: The spatially coupled channel is decomposed into a system structure in which the nonlinear distortion part of the transmission link and the multipath part of wireless propagation are cascaded; The nonlinear distortion part of the transmission link characterizes the harmonic distortion and intermodulation distortion characteristics introduced by the power amplifier of the interference signal, and the wireless propagation multipath part characterizes the differential attenuation and time delay characteristics introduced by the direct path, reflection path and scattering path that the interference signal traverses from the interference transmitting antenna through space to the monitoring antenna. The nonlinear distortion of the transmission link and the multipath propagation of wireless propagation are cascaded and coupled to construct a joint nonlinear model. The nonlinear model takes the reference signal as input and the interference component in the mixed received signal as output. It is characterized by a set of kernel parameters. The set of kernel parameters is used to describe the entire nonlinear distortion transmission characteristics and multipath propagation characteristics of the interference signal from the output of the final stage power amplifier of the transmission link to the monitoring and receiving front end.
5. The method for monitoring abnormal electromagnetic signals in classified locations and coordinating multiple scenarios as described in claim 1, characterized in that: Using the reference signal as the input excitation of the nonlinear model and the hybrid received signal as the desired output of the nonlinear model, a closed-loop adaptive identification architecture is constructed. In the adaptive identification architecture, the reference signal generates an intermediate output signal through a nonlinear model under the current kernel parameters. The intermediate output signal is compared with the mixed received signal to generate an error signal. The error signal drives the adaptive parameter update algorithm to iteratively adjust the kernel parameters, so that the intermediate output signal gradually approaches the interference signal component contributed by the interference transmission link in the mixed received signal. When the error signal power drops below the preset convergence threshold and the convergence condition is met for multiple consecutive frames with stable and no significant fluctuations, the current intermediate output signal is used as the interference reconstruction signal. The interference reconstruction signal matches the actual interference component in the mixed received signal in terms of time domain waveform, phase characteristics, and nonlinear distortion components.
6. The method for monitoring abnormal electromagnetic signals in classified locations and coordinating multiple scenarios as described in claim 1, characterized in that: The mixed received signal and the interference reconstruction signal are subjected to a sample-by-sample-point aligned subtraction operation in the time domain. The aligned subtraction operation is based on the determined relative time delay relationship between the reference signal guaranteed by the equal-delay transmission link and the interference component in the mixed received signal, so that each sampling point of the interference reconstruction signal corresponds in time to the corresponding sampling point of the interference component in the mixed received signal. After the alignment and subtraction operation, the interference signal component contributed by the interference transmission link in the mixed received signal is canceled out. The residual signal contains the original electromagnetic signal in the protected area and the background noise introduced by the monitoring and receiving link. The residual signal is the clear signal after the interference cancellation.
7. The method for monitoring abnormal electromagnetic signals in classified locations and coordinating multiple scenarios as described in claim 1, characterized in that: The clearance signal is subjected to signal detection. Based on the start and end changes of the energy of the electromagnetic signal in the clearance signal in the time domain, the continuous clearance signal is divided into signal segments containing signal bursts and silent segments without signal bursts. Each signal segment has a definite start time and end time in the time domain. For each signal segment, the distortion characteristic parameters generated by the power amplifier of the transmitter of the leaking device under test operating in the nonlinear range are extracted. The distortion characteristic parameters include a first type of parameter describing the nonlinear mapping relationship between the input signal envelope amplitude and the output signal envelope amplitude, and a second type of parameter describing the nonlinear mapping relationship between the input signal envelope amplitude and the output signal phase offset. The first type of parameter and the second type of parameter together constitute the real-time radio frequency fingerprint of the transmitter corresponding to the signal segment.
8. The method for monitoring abnormal electromagnetic signals in classified locations and coordinating multiple scenarios as described in claim 1, characterized in that: The similarity between the real-time radio frequency fingerprint and each registered legitimate device radio frequency fingerprint in the legitimate device radio frequency fingerprint database is measured one by one to obtain the degree of deviation of the real-time radio frequency fingerprint relative to each legitimate device radio frequency fingerprint. The anomaly likelihood is generated by combining the deviation of the real-time radio frequency fingerprint from the radio frequency fingerprints of all legitimate devices. The anomaly likelihood is used to characterize the possibility that the intercepted signal originates from an unknown or abnormal device.
9. The method for monitoring abnormal electromagnetic signals in classified locations and coordinating multiple scenarios as described in claim 1, characterized in that: Obtain the scene status observation information from the security management system of the classified location; The anomaly likelihood and the scene state observation information are used together as the real-time observation at the current moment; In partially observable Markov decision-making, the posterior belief probability distribution of the electromagnetic threat state at the current moment is calculated by Bayesian filtering using the belief probability distribution of the previous moment and the real-time observations at the current moment, thus realizing the temporal recursive update of the belief probability distribution.
10. A system for monitoring abnormal electromagnetic signals in classified locations and for multi-scenario linkage, characterized in that, The method for monitoring abnormal electromagnetic signals in classified locations and linking multiple scenarios as described in any one of claims 1 to 9 includes: an acquisition unit, a processing unit, and a linkage decision-making unit, wherein each unit is time-synchronized and data is interactively transmitted. The signal acquisition unit includes a broadband monitoring antenna array and a directional coupler. The broadband monitoring antenna array is deployed within the protected area to acquire mixed received signals. The directional coupler is connected in series between the output of the interference signal power amplifier and the interference transmitting antenna to extract a reference signal that includes power amplifier nonlinear distortion and is coherent with the transmitted interference. The signal acquisition unit is also configured with an equal-delay transmission link to maintain a fixed and calibrable relative delay difference between the reference signal and the interference components in the mixed received signal. The processing unit is signal-connected to the signal acquisition unit and is used to generate an interference reconstruction signal by taking the reference signal and the mixed received signal as inputs and using a kernel parameter identification algorithm of a joint nonlinear channel model. After time-domain alignment and subtraction, the clearance signal is output. The clearance signal is then divided into time domains and nonlinear distortion features are extracted to generate a real-time radio frequency fingerprint, which is then compared with the legitimate device radio frequency fingerprint database to output anomaly likelihood. The linkage decision-making unit communicates bidirectionally with the processing unit and the security management system for classified locations. It receives the anomaly likelihood and multi-dimensional scene state observation information as real-time observations. Based on a partially observable Markov decision process, it recursively updates the belief probability distribution of the electromagnetic threat state through Bayesian filtering. Combined with a cost function that includes security risk costs and business impact costs, it outputs the linkage control action with the minimum long-term expected cumulative cost.