Apparatus for enhancing signal integrity in a signaling network
The apparatus and system enhance signal integrity in signaling networks by detecting and correcting signal element changes and reordering operations to counteract overshadowing and undershadowing attacks, ensuring reliable communication and sensing.
Patent Information
- Application Number
- JP2025515379
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-04-19
- Filing Date
- 2023-09-11
- Publication Date
- 2025-10-28
AI Technical Summary
Signal integrity in signaling networks is compromised by overshadowing and undershadowing attacks, where a third-party transmitter injects interfering signals, leading to distorted communication or sensing functionality.
An apparatus and system that utilize an identification unit to detect signal element changes in magnitude and reordering operations, employing AI/ML models to identify injection attacks, and a processing unit to process and correct received signals, along with reordering operations to prevent such attacks.
Enhances signal integrity by accurately detecting and mitigating overshadowing and undershadowing attacks, ensuring reliable communication and sensing functionality.
Smart Images

Figure 2025535651000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to an apparatus, system, method and computer program for enhancing signal integrity in a signaling or sensing network. [Background technology]
[0002] If a transmitter transmits an original signal and a third-party transmitter transmits a stronger interfering signal, a receiver receiving the combination of the two signals may obtain only the interfering signal after demodulation or decoding. This is due to the capture effect; whenever a combination of signals is received, only the strongest signal in the combination is actually selected for demodulation or decoding. More generally, the receiver obtains a distorted signal containing any combination of the desired original signal and the unwanted interfering signal. For simplicity, we refer to such any combination as being due to the capture effect.
[0003] When a third party intentionally transmits, or "injects," a strong interfering signal, this is called an overshadowing attack. Overshadowing attacks can occur in various wireless communication networks, such as LTE, 5G, and WiFi, as well as in wired communication networks, such as those based on optical fiber. These and other injection attacks can also occur in wired or wireless sensing networks, such as wireless sensing networks based on radar signals. In wireless sensing networks, wireless sensing signals are transmitted and reflected by surrounding objects before being received. Additionally, integrated sensing and communication (ISAC) networks can also be subject to overshadowing and other injection attacks.
[0004] A variation of the over-shadow attack is the under-shadow attack, which uses the same capture effect as the over-shadow attack, but the interfering signal matches the original signal only in distinct signal components. Under-shadow attacks are more difficult to detect than over-shadow attacks.
[0005] There is a need to enhance signal integrity within signaling networks where injection attacks, such as overshadowing and undershadowing attacks, can occur for malicious or non-malicious reasons. Interfering signals can affect the communication or sensing functionality of a particular device or the overall communication / system, e.g., modulating received signals or enabling private data extraction. Summary of the Invention
[0006] An object of the present invention is to improve signal integrity in signaling networks.
[0007] An apparatus for enhancing signal integrity in a signaling network is presented, where each signal includes a sequence of one or more signal elements, and the apparatus includes an identification unit that identifies injection of a signal element into a received signal based on at least one of a) a change in magnitude of the signal element and b) a reversal of a reordering operation that was applied to the received signal at the time of transmission.
[0008] Because a successful injection of a signal element into a target signal requires a relatively large magnitude of the signal element, we found that changes in the magnitude of a signal element are a good criterion for identifying the injection of a signal element into a received signal and thereby enhancing signal integrity in a signaling network. We also recognized that the injection of signal elements depends on the expected ordering of the target signal. This expected ordering can be reliably detected by applying a reordering operation to the signal at transmission and reversing the reordering operation after the signal is received. Therefore, we found that this method can also enhance signal integrity in a signaling network. In particular, we found that over-shadowing attacks, as well as under-shadowing attacks, can be identified based on either a) changes in the magnitude of signal elements and / or b) the reversal of the reordering operation applied to the received signal at transmission.
[0009] A signaling network may include one or more nodes that act as transmitters and / or receivers of signals whose integrity is to be enhanced. Exemplary signaling networks include communication networks, sensing networks, and integrated sensing and communication networks. Signals, particularly in communication networks and integrated sensing and communication networks, may be interpreted as corresponding to messages communicated within the network. For example, if a signal carries a message, the signal may be understood as an information-bearing medium, and a message may be understood as the information being carried. Signals within a signaling network may be considered to be switched, i.e., exchanged between one or more nodes of the network. However, signals may also be sent and received by the same node. This may be particularly the case for sensing networks and integrated sensing and communication networks. As used herein, signals within a signaling network, or simply signals within a "network," should be understood to mean signals that are switched or otherwise transmitted over the network, i.e., propagating within the network.
[0010] A signal element may refer to, for example, a symbol of a signal, and a bit is understood herein as a specific example of a symbol. The sequence of signal elements in a signal may also be referred to as the sequence of slots in the signal and the content of each signal in the slot. The sequence of signal elements does not necessarily have to be a time sequence, but may also be a sequence in, for example, a spectral domain. In other words, the slots of a signal may be individualized, i.e., separated from one another, for example, in time and / or frequency. A signal element may refer to characteristics of a modulation scheme or multiple access scheme, such as the carrier of the signal, the modulation of the carrier, the polarization of the signal, the angular momentum of the signal, etc.
[0011] The magnitude of a signal element may, for example, indicate the energy of the signal element. In particular, the magnitude of a signal element may refer to the energy of the signal element. However, more generally, the magnitude of a signal element may be any quantity that can be considered as the magnitude of a signal element. For example, the magnitude of a signal element may be the strength, polarization, intensity, phase, frequency shift, or power of the signal element. Exemplary quantities of the above type that are frequently used in practice in related applications include received signal strength indicator (RSSI), signal-to-noise ratio (SNR), and error vector magnitude (EVM), etc.
[0012] The apparatus may include a measurement unit configured to measure, for each signal element of the received signal, a signal element magnitude, whereafter changes in the signal element magnitude may be detected in the measured signal element magnitude.
[0013] The variation in magnitude of the signal elements may be a variation in magnitude of the signal elements between signals and / or within a signal, i.e., a variation in magnitude of the signal elements may be a variation in magnitude of corresponding signal elements in a plurality of different received signals and / or a variation in magnitude of a sequence of signal elements in a single signal.
[0014] The identification unit, which may also be referred to as an identification part, may be configured to detect a change in the magnitude of a signal element or to consider a change to be significant only if the change exceeds a predetermined threshold. For example, a uniform distribution of the magnitudes of signal elements across the signal and / or within the signal may be assumed, and the injection of a signal element may be identified based on a significant deviation from the uniform distribution. The presence of a significant deviation may be determined, for example, based on a p-test, i.e., a statistical test that gives a p-value.
[0015] The identification unit may use an artificial intelligence (AI) model, in particular a machine learning (ML) model, to detect an attack or interference signal. That is, the identification unit is configured to identify the injection of a signal element into a received signal based on a trained AI or ML model. The model is trained to receive the signal as an input and provide a corresponding output indicative of the injection of the signal element into the signal received as an input. The ML / AI model may be configured to identify the injection of the signal element into the signal based on a change in the magnitude of the signal element, for example by being trained accordingly. If detected, the ML / AI model may be configured to enable extraction of the received signal (e.g., the actual signal and the interference signal).
[0016] The ML / AI model may be trained centrally and deployed to multiple receivers in a network so that the model can be used for inference, i.e., to infer whether a signal is subject to an overshadowing or undershadowing attack. The ML / AI model may be trained locally based on locally received and decoded / demodulated signals. The ML / AI model may be based on supervised or unsupervised learning. The ML / AI model may be distributed, for example, in a federated learning approach.
[0017] The injection of the identified signal element may in particular be performed by a third party into the received signal after transmission of the received signal: injection of signal elements throughout the entire signal corresponds to an over-shadowing attack, while an under-shadowing attack corresponds to injecting signal elements only into selected positions of the signal.
[0018] Identifying the injection of a signal element into the received signal may include, inter alia, locating the injected signal element within the received signal. The injected signal element within the received signal can be identified by detecting where within the sequence of signal elements of the received signal the magnitude of the signal element changes, i.e., by more than a predetermined amount, for example.
[0019] The device may be configured to discard or drop the received signal if an injected signal element is identified within the received signal. Additionally or alternatively, the device may be configured to trigger an alarm upon detecting the injection of the signal element. However, it may be preferable for the device to further include a processing unit, or "processor," configured to process the received signal. In particular, the processing unit may be configured to process the received signal based on the injection of the identified signal element. As will be described in further detail below, this may allow the received signal to be modified with respect to the injection of the signal element.
[0020] More generally, the action to be taken upon identifying the injection of one or more signal elements may be determined by a policy configured by a management entity, such as a base station or a network function within the core network. For example, the policy may determine that upon detecting an attack, a receiver in the network issues an alarm to a base station or management entity in the network. However, any signal processing, particularly any signal modification, implemented as a countermeasure against an attack may equally be performed by the processing unit regardless of the injection of the identified signal element. Thus, the policy may determine to apply a predefined modification procedure to a predefined percentage of received signals, only received signals identified as containing injected signal elements (i.e., identified as being under attack), or all received signals. Even if injection is detected, the signal may be successfully extracted / demodulated / acquired and provided for further processing or presentation. In the case of sensing signals, the sensing signals identified as injected may be processed, presented, or displayed with an injected status, e.g., to allow a user to perform further evaluation.
[0021] Preferably, any of the measurement unit, the identification unit, and the processing unit may be included in the receiver of the network. Thus, the device may be specifically a receiver or include a receiver. However, the device may be separate from the receiver, in which case the receiver can forward the received signal to the device. Furthermore, the measurement unit, the identification unit, and the processing unit may be distributed, for example, across a network, in which case the device may be understood as a distributed device or system.
[0022] The terms "receiver" and "transmitter" may refer to different functions of the same device, also called a "transceiver," and such a device may perform "receive" and "transmit" functions at different times. However, for certain services or predefined signal types of a network, there may be a fixed allocation between a) receive and transmit functions and b) devices in the network. This means that a device may provide receive functionality for some services or signals of the network, but transmit functionality for other services or signals.
[0023] Optionally, a configuration of or for a device, which may be thought of as a policy, may be transmitted to a receiver or transmitter of the network. For example, if the device is separate from the receivers or transmitters of the network that are receiving or transmitting signals that are the subject of the device's configuration, the device's configuration may be transmitted to these receivers or transmitters. On the other hand, if the device is or includes a receiver or transmitter, the configuration may be forwarded to other receivers or transmitters in the network and / or the device may receive the configuration from a management entity of the network.
[0024] As mentioned above, the change in magnitude of the signal element may be a change in magnitude of the signal element between signals and / or within a signal. In particular, to identify the injection of a signal element into the received signal based on the change in magnitude of the signal element, the identification unit may detect a change in magnitude of the signal element in at least one of: a) a sequence of signal elements of the received signal; and b) a signal element sequence comprising the signal element of the received signal and one or more corresponding signal elements of a previous repetition of the received signal.
[0025] If the received signal corresponds to a current repetition of a repeatedly received signal, the magnitude of the signal element may refer, in particular, to an average of the magnitudes of the signal element calculated from the current repetition and a predetermined number of previous repetitions of the received signal. Identifying the injection of a signal element based on the average magnitude of the signal element improves reliability by reducing the likelihood of false positives due to random fluctuations in the magnitude of the signal element.
[0026] For example, if the last N repetitions of a signal S are denoted by S[n], S[n-1], . . . , S[n-N+1], then a set of averages of the magnitudes of the corresponding signal elements, A = [A[0], A[1], . . . , A[L-1]], may be calculated, where L is the number of signal elements in S, i.e., the number of signal elements contained in each of its repetitions, A[j] = (1 / N)(S[n,j] + S[n-1,j] + . . . + S[n-N+1,j]), and S[m,j] refers to the jth signal element in the sequence of signal elements in the mth repetition of S. N can be any natural number, including 1; if N = 1, no average is calculated and only the magnitudes of the signal elements in S[n] are used.
[0027] Known examples of repeatedly received signals are periodically transmitted signals such as signals forming a master information block (MIB) or a system information block (SIB1), or sensing signals such as radar signals or preambles used to measure channel state information, etc. Periodic signals are to be understood here as repetitive signals that are repeated, for example at regular time intervals.
[0028] As noted above, the assumed uniform distribution of signal element magnitudes for identifying signal element injection may refer to uniform distribution within a signal and / or between signals. It should be understood that uniform distribution within a signal refers to uniformity of signal elements in any given signal, and not necessarily uniformity of signal elements in multiple different signals. It should be understood that uniform distribution between signals refers to uniformity of corresponding signal elements in multiple different signals, and not necessarily uniformity of signal elements in only a given signal. Correspondence of signal elements between multiple different signals may refer, for example, to correspondence of positions within each signal.
[0029] The concept of assuming a uniform distribution within and / or across signals can be translated to the above example of using the average magnitude of a signal element to identify an injection, i.e., an attack, rather than the magnitude of the signal element itself. Then, referring to the notation above, a uniform distribution can be assumed for each of the N average values A[j] for any j measured repeatedly over time, and / or for the L average values A measured for a particular received signal at any point in time.
[0030] The identification unit and / or the processing unit may preferably be configured to invert a transmission transformation applied to the received signal upon transmission. A transmission transformation is to be distinguished from a reordering operation, which may for example correspond to modulation or encoding, while the inversion of the transformation may correspond to demodulation or decoding, respectively. Thus, if a transmitter in a network transmits a signal by modulating or encoding the information to be transmitted on a carrier signal, the device, when operating as or together with a receiver, may demodulate or decode the received signal, respectively.
[0031] The identification unit and / or the processing unit may be configured to apply an inverted transmission transformation to the received signal regardless of whether the received signal has been identified by the identification unit as containing the injected signal element. In practice, attacks such as overshadow attacks and undershadow attacks that exploit the capture effect rely on the transmitter and receiver encoding / modulating and decoding / demodulating the signal, respectively. In particular, these types of transmission transformations, i.e., the transmission transformations on which the attacks rely and which may therefore also be considered "normal" transmission transformations, may be performed independently of the injection of the identified signal element. However, as described in more detail below, further or subsequent application of a transmission transformation and / or its inversion may be beneficial, especially at the receiver side. These further applications of a transmission transformation and / or its inversion may also be performed independently of the injection of the identified signal element.
[0032] Furthermore, the processing of the received signal, i.e., processing performed by the processing unit depending on or independent of the injection of the identified signal element, may preferably include scaling the signal element of the received signal depending on whether it was identified as an injected signal element. Scaling of the signal element may refer to scaling the magnitude of the signal element. Furthermore, scaling may be applied after applying an inverted transmission transform to the received signal, specifically after applying a "normal" inverted transmission transform or a first inverted transmission transform. In particular, the processing unit may be configured to duplicate the received signal, apply the inverted transmission transform to a first of the duplicates, and scale the signal element of the transformed first duplicate. In this way, an unprocessed version of the received signal, i.e., a second duplicate, remains. Therefore, both the processed first duplicate and the unprocessed second duplicate can be used in further processing.
[0033] Preferably, the processing of the received signal comprises thresholding signal elements to predefined signal element levels, the predefined signal element levels including at least an injection level indicating the magnitude of the injected signal element and a non-injection level indicating the magnitude of the non-injected signal element, the signal elements being scaled according to their respective signal element levels. In particular, the processing unit may be configured to apply thresholding to the received signal before applying the "normal" or first inverted transmission transformation and / or before replicating the received signal. Thus, for example, the processing unit may be configured to apply thresholding as an initial processing step. Alternatively, thresholding may be applied before the received signal is passed to the processing unit, i.e., before it reaches, for example, the identification unit or, in some cases, the measurement unit.
[0034] Thresholding signal elements may refer to determining which of a set of predefined magnitude intervals each signal element falls into and then replacing the magnitude of the signal element with a magnitude level. The magnitude level represents the determined magnitude interval in which the signal element falls. The magnitude level may be predefined as a multiple of the smallest signal element magnitude measured for each signal. The magnitude level may also be normalized relative to the lowest or highest level. For example, in the case of binary thresholding, i.e., thresholding into only injection and non-injection levels, the magnitude level of a signal element for a given signal will be either 1 or k, where k>1 is a thresholding parameter. The non-injection level is preferably predefined to be the lowest signal element level. The non-injection level is preferably predefined to correspond to a magnitude interval in which intact or untampered signal elements are expected to fall, and the injection level is preferably predefined to correspond to a magnitude interval in which signal element magnitudes in which an attacker is expected to attempt to inject signal elements are included. For example, if untampered signal elements are expected to have magnitudes between I and I + ΔI, and all potentially injected signal elements are expected to have magnitudes between kI and (k + Δk)I, where k>1, then the corresponding (binary) thresholding magnitude levels may be the lower limits of the respective intervals, i.e., I and kI. After normalizing with respect to the lower of the two (i.e., I), we obtain the above-mentioned examples of possible magnitude levels 1 and k (k>1) for all signal elements in the received signal.
[0035] Although thresholding can be extended to signals where symbols are received at multiple magnitude levels, it may be preferable to binary threshold the signal elements into low and high signal element levels. In the case of binary thresholding, the thresholding parameter k may be selected such that all attacking signals are at the full high signal element level and all non-attacking signals are at the full low signal element level.
[0036] Preferably, the processing comprises forming a difference signal based on an unprocessed version of the received signal (i.e., the second replica) and a processed version of the received signal (i.e., the first replica) corresponding to the received signal, resulting from thresholding and scaling, where the scaling comprises scaling the signal components of the injected level higher than a level difference, the level difference indicating the difference in magnitude between the injected level and the non-injected level. It has been found that doing so facilitates recovering an untampered signal from a received signal that may contain signal components injected by an attacker.
[0037] In particular, when low signal element levels, i.e., signal elements at the non-injected level, are scaled by a factor a (preferably 0≦a<1) and high signal element levels, i.e., signal elements at the injected level, are scaled by a factor b, the factor b may be selected to satisfy b>k−1. As mentioned above, k may indicate the ratio of the signal element magnitude between the injected signal element and the signal element from the original signal, more specifically, the ratio of the magnitude of the signal element at the injected level to the magnitude of the signal element at the non-injected level. Therefore, the scaling factor b is selected to be higher than the level difference k−1 (which in this case is the normalized level difference).
[0038] The above condition on the scaling factor b corresponds to the insight that it is preferable to scale the signal elements of the first replica of the received signal such that when the scaled first replica is subtracted from the second replica of the received signal, the magnitude of the signal elements of the original signal portion in the superposition corresponding to the second replica is greater than the difference between a) the magnitude of the signal elements of the injection / attack signal portion in the superposition corresponding to the second replica and b) the magnitude of the scaled signal elements of the injection / attack portion of the first replica of the received signal.
[0039] The processing unit is preferably configured to apply an inverted transmission transform to the difference signal. As described above, if the inverted transmission transform has already been applied before forming the difference signal, e.g., as an initial processing step, the processing unit is configured to apply the inverted transmission transform a second time. Applying the inverted transmission transform to the difference signal allows signal elements replaced by injected signal elements to be restored, and allows the received signal to be corrected against third-party injection attacks such as undershadowing.
[0040] Between the application of the inverted transmission transform to the received signal, i.e., the application of the first inverted transmission transform, and the application of the inverted transmission transform to the difference signal, the processing unit may be configured to apply a non-inverted transmission transform, i.e., the transmission transform that was applied to the received signal during transmission. For example, a first copy of the received signal, i.e., a version of the received signal that is processed until a difference signal is formed based on it and an unprocessed version of the received signal, may be processed in the following order: 1) apply the inverted transmission transform, 2) apply the non-inverted transmission transform, 3) apply scaling. An alternative order is as follows: 1) apply the inverted transmission transform, 2) apply scaling, 3) apply the non-inverted transmission transform. Regardless of the order, it is preferable to apply the inverted transmission transform to the difference signal formed from the resulting version of the first and second “saved” copies. As noted above, the transmission transform may particularly correspond to modulation or encoding, while the inverted transmission transform may particularly correspond to demodulation or decoding.
[0041] In practice, it has been found that reversing a transformation applied to a signal during transmission can also be useful for identifying injected signal elements. For this purpose, the transformation may correspond, in particular, to a reordering of the signal elements in the received signal, since this allows for creating a mismatch between the order of the signal elements assumed by an attacker and the actual order of the signal elements temporarily present during transmission and reception. In particular, to identify the injection of signal elements into a received signal based on the reversal of the reordering operation applied to the received signal during transmission, the identification unit may preferably reorder the received signal according to the inverted reordering operation and perform an integrity check on the reordered received signal. The integrity check may be a known integrity check, particularly one known to return a negative result for signals containing signal elements in the wrong order due to interference or noise, or for signals containing randomly distributed erroneous signal elements. For example, the identification unit may be configured to perform a cyclic redundancy check (CRC).
[0042] The permutation operation may in particular be a random permutation operation, where "randomness" is understood to also include "pseudorandomness." For example, a secure pseudorandom sequence of signal elements can be obtained by first determining a random seed and then applying a secure pseudorandom function to it (e.g., a key derivation function or SHAKE).
[0043] Similar to the approach of identifying injected signal elements based on changes in their magnitude, the approach of using integrity checking in combination with signal reordering is based in part on the insight that current wireless communication standards, such as LTE or 5G, lack integrity protection at lower communication layers. Possible implementations of integrity protection are currently being investigated. For example, a solution addressing KI#2 (second key issue) titled "Study on 5G security enhancements against False Base Stations (FBS)" in 3GPP (3rd Generation Partnership Project) Technical Report (TR) 33.809 discusses how to protect broadcast 5G system information. Similarly, adding a message integrity code (MIC) to messages (e.g., between a UE and a base station) could potentially enable integrity protection for unicast messages. However, applying integrity protection to each message can be costly.
[0044] Fortunately, performing an integrity check on all received signals may not be necessary to identify the injected signal element with sufficient probability. Therefore, the identification unit may perform an integrity check on a predetermined percentage of signals in the network, and for a given signal to be transmitted, whether or not to perform an integrity check on that signal is determined randomly based on the predetermined percentage. This reduces computational effort. In other words, efficiency can be improved by integrity protecting only certain messages, for example, only a percentage f of messages (e.g., f = 50% or less). If certain messages are (randomly) selected and protected with probability f, the messages include a digital signature or a message integrity check (MIC), or more generally, any integrity check. If an integrity check is included, the receiver must check the integrity of the received message. Then, even if an attacker attempts to manipulate the signal, the attacker will not necessarily be successful, and the attack can be detected. The probability f may correspond to the predetermined percentage. In one example, performing an integrity check may include checking whether a signal structure possibly given for a signal element conforms to a standard structure. The standard structure may correspond to, for example, a communication protocol.
[0045] For signals for which an integrity check is to be performed, an integrity indication signal portion may be transmitted in combination with the signal, and the identification unit may be configured to check the integrity of the signal upon reception based on the integrity indication signal portion. For example, the transmitted combination of the integrity indication signal portion and the signal may be formed by including the integrity indication signal portion in the corresponding signal, and if upon reception of the signal, it is determined that the magnitude of one or more signal elements of the integrity indication signal portion exceeds a predetermined threshold, a lack of integrity is concluded. The integrity indication signal portion may in particular correspond to a digital signature or MIC. The signal elements of the integrity indication signal portion may be of the same type as the signal elements of the signal itself. Thus, for example, the signal elements of the integrity indication signal portion may correspond to bits or other symbols.
[0046] An integrity indication signal portion can be included in a signal, for example, by appending a signal portion indicating integrity (check) to the end of the signal or by inserting a signal portion indicating integrity (check) at the beginning of the signal. However, if the integrity check is appended to the end of the message, an attacker may attempt to overshadow the end of the message. To address this issue, the integrity check may be placed at the beginning of the message so that the transmission of the remainder of the message is shifted when the integrity check is transmitted. Alternatively, the integrity check can be appended to the end of the message, but a negative integrity check result will be returned if the energy of the symbol occupied by the integrity check is too high, especially compared to the rest of the message.
[0047] In other words, it may be preferable that a) the transmitted combination of the integrity indication signal portion and the signal is formed by inserting the integrity indication signal portion before the signal, or b) the transmitted combination of the integrity indication signal portion and the signal is formed by appending the integrity indication signal portion to the end of the signal, and if the magnitude of one or more signal elements of the integrity indication signal portion is determined to be above a predetermined threshold, it is concluded that integrity is lacking upon receipt of the signal.
[0048] In practice, it may also be preferable that a) only a predetermined percentage of signals in the network are reordered according to the reordering operation before transmission, and for a given signal to be transmitted, a random decision is made based on the predetermined percentage whether to reorder the signal or not, and / or b) the transmitted combination of reordering indication signal portion and reordered signal is formed by inserting the reordering indication signal portion before the reordered signal and / or is indicated by another message (e.g., a configuration message).
[0049] It should be noted that such integrity checks can be implemented independently of whether the signals are reordered or not. Simply including an integrity check in the signals may allow more attacks to be detected, thereby improving the integrity of the signals within the signaling network. This is particularly true for networks operating according to wireless communication standards such as LTE or 5G, which, as noted above, lack integrity protection at lower communication layers.
[0050] While we have discussed above the aspects of attack detection by identifying the injection of signal elements and processing received signals accordingly to increase signal integrity in the signaling network, it should be noted that these aspects can be implemented individually or in combination.
[0051] In a further aspect, it has been found that, for example, processing a received signal in which injected signal elements have been identified to modify it by restoring signal elements that have been replaced by the injected signal elements provides an efficient way of increasing the overall integrity of signals in signaling networks that are subject to third-party injection attacks such as undershadowing, but that these attacks may instead be completely avoided by attack avoidance measures.
[0052] As with attack detection, for attack avoidance, at least some of the signals in the network may be reordered according to a reordering operation, e.g., before transmission, and the reordering operation may be reversed after reception of the signals. Thus, the processing unit may be configured to reverse, for at least some received signals, the reordering operation that reordered the signals before or during transmission. In this way, third-party attacks, such as undershadow attacks, can be prevented unless the attacker has knowledge of the reordering operation.
[0053] Because it is not always possible to completely avoid attacks, signal modification and attack avoidance may be implemented in parallel, i.e., both may be implemented in the same network. Also, either or both of these two may be implemented regardless of whether an attack has been previously detected, for example, by identifying the injection of signal elements in the received signal. Such an implementation, although possibly requiring additional computational effort, can be considered to be preventative in nature.
[0054] Therefore, the present disclosure also relates to a system for enhancing the integrity of signals in a signaling network, each signal comprising a sequence of one or more signal elements, the system comprising: a) an apparatus as described above as a receiving device or receiver of signals in the network, and / or b) a transmitting device or transmitter of signals in the network, the transmitting device comprising a reordering unit configured to reorder the transmitted signals according to a reordering operation.
[0055] Thus, an apparatus for increasing signal integrity in a signaling network is also presented, wherein each signal comprises a sequence of one or more signal elements, the apparatus not necessarily including means for identifying injection of a signal element into a received signal based on at least one of a change in the magnitude of the signal element and an inversion of a reordering operation applied to the received signal at transmission, and in particular including: a) means for measuring, for each of the signal elements of the received signal, a magnitude of the signal element, the magnitude of the signal element indicating the energy of the signal element; b) means for identifying injection of a signal element into the received signal by detecting a change in the magnitude of the signal element based on the measured magnitude of the signal element; and / or c) means for processing the received signal based on the injection of the identified signal element, but including reordering means, such as a reordering unit or "reordering section" configured to reorder at least some signals in the network according to a reordering operation before transmission, the reordering operation may be inverted after reception of the signals, for example by a processing unit of a further device in the system. If the apparatus implements only option d), the apparatus may in particular be a transmitter.
[0056] It should be understood that while the aspect of modifying the received signal in response to an identified attack may be achieved solely by the receiver, i.e. the receiving device implementing the apparatus described at the beginning, the avoidance of the attack (e.g. by reordering the signal) is preferably achieved in cooperation between the transmitter and receiver, i.e. the transmitting device implementing the apparatus for realizing option d) above, and also the receiver, i.e. the receiving device implementing the apparatus described at the beginning.
[0057] For example, an attack mitigation measure, such as reordering signal elements in a signal according to some reordering operation, may be initiated by the receiver as well as the transmitter. In one example, the receiver may request the transmitter to implement the attack mitigation measure, specifically, to begin reordering signal elements of a signal transmitted from the transmitter to the receiver according to some reordering operation. Such a request may be sent when the receiver identifies that one or more signal elements have been injected into the received signal, i.e., when an attack is detected.
[0058] In either case, i.e., whether implemented for attack detection or attack avoidance purposes, or for other purposes or signal modification purposes without implementing the same or other means, for each reordered transmitted signal, it may be preferable that the reordering operation be encoded in a reordering indication signal portion and the reordered signal be transmitted in combination with the reordering indication signal portion. The reordering signal may be received in combination with the reordering indication signal portion, and the reordering may be reversed after reception of the signal based on the reordering indication signal portion. The transmitted combination of the reordering indication signal portion and the reordered signal may preferably be formed by a) appending the reordering indication signal portion to the end of the reordered signal, or b) inserting the reordering indication signal portion before the reordered signal. Additionally or alternatively, the signal portion indicating reordering may be transmitted in a separate configuration message or signal.
[0059] In another embodiment, the reordering operation may be encoded into a particular physical parameter of the signal. For example, an initiator and a responder, which may correspond to a transmitter and a receiver or a receiver and a transmitter, respectively, may exchange data, particularly an encryption key, encoded into the phase of a carrier signal. Instead of exchanging keys, the responder may encode the reordering operation used to reorder the transmitted data.
[0060] In a variation, the reordering operation for the transmitted first signal may be encoded in the reordering indication signal portion transmitted in combination with the second reordered signal. The transmitted combination of the reordering indication signal portion and the second reordered signal may be formed by a) appending the reordering indication signal portion to the end of the second reordered signal or b) inserting the reordering indication signal portion before the second reordered signal. The second reordered signal may have been reordered according to a different reordering operation than the first signal. The first and second signals may have any predefined relationship to each other. For example, both signals may be transmitted consecutively, i.e., the second signal may be transmitted immediately after the first signal.
[0061] In another embodiment, the reordering operation may not be encoded in the signal portion that is combined with the reordered signal and transmitted. Instead, the reordering operation may be defined, for example, according to one or more communication parameters accessible to or known by transmitters and receivers in the network. The communication parameters that define the reordering operation may be understood as global parameters of the network. The communication parameters are preferably selected to be difficult or substantially impossible for a potential attacker to guess.
[0062] The above embodiments are particularly applicable to, but not limited to, signals transmitted by a transmitter (e.g., a base station or access point transmitter) before a receiver (e.g., user equipment) establishes a connection with the transmitter. For example, the signal may be a master information block (MIB) or system information block (SIB1) initially transmitted by a 5G base station to enable user equipment to perform an initial random access procedure in a 5G network. When a connection is already available, permutations may also be securely exchanged or agreed upon, for example, by securely exchanging secret permutations to be applied to subsequently exchanged signals using a secure channel between the transmitter and receiver / responder. Here, a "secure channel" may refer to a confidentiality-protected channel, an integrity-protected channel, and / or a replay-protected channel, etc.
[0063] The above embodiments can also be applied to signals that encode configuration parameters and that are normally unprotected (e.g., DCI, UCI, or SCI messages). The permutation applied to these messages can be securely configured, for example, by a protected RRC message, after which the transmitter and receiver can apply the protected secret permutation. The receiver can undo the secret permutation and verify the message by verifying the integrity check (e.g., CRC).
[0064] While it may be sufficient to combine an avoidance strategy with a correction strategy, or even to implement the avoidance strategy alone in some cases, the additional effort required for this, even if relatively small, may not be necessary if it is known that no ongoing attack exists. Therefore, it may be beneficial to first identify the injection of a signal element into the received signal by detecting, for at least a portion of the received signal, a change in the magnitude of the signal element based on, for example, previously measured signal element magnitudes. In other words, it may be preferable to reorder signals in the network according to a reordering operation before transmission only if an injected signal element is identified in the received signal. In particular, the reordering unit may reorder transmitted signals only if an injected signal element is identified in the received signal based on a change in the signal element magnitude. The reordering can then be used to more accurately detect attacks. According to another aspect, which can be used independently of the same objective of increasing signal integrity in a signaling network, a node engaged in a procedural dialogue with a peer may measure several physical (layer) parameters of each transmitted signal from the peer received by the node. The measurements may be combined into a “fingerprint” representing the signal transmitted from the peer node as observed / sensed by the first node. The signals to be measured and the information to be measured may be provided to the receiving node via a configuration message, a pre-configuration. If the dialogue is interrupted / altered / etc. by a transmission from a third node, whether intentionally (e.g., an overshadowing attack) or unintentionally, the measurements made by the first node may combine to form a fingerprint that is significantly different from the expected one. The first node may then use that information to take appropriate action. For example, it may simply discard the signal without attempting to read it; it may resend the last signal it sent to its peer; or it may instruct its peer to abort or resume a procedure in progress.
[0065] In one embodiment, the physical parameters include one or more measurements related to location, such as an estimate of the distance between two nodes. For example, a measurement of the angle of arrival of an incoming signal from a peer node. The first node may use multiple antennas to gather more detailed information. In another example, the physical parameters may include a measure of a characteristic of the signal itself, such as received signal strength or a measure of the quality of the signal or a component of the signal, such as a measure of the frequency of the carrier wave.
[0066] In a related embodiment, the use of multiple antennas at different locations allows differentiation between the wanted signal S and the unwanted interfering signal I based on the fact that their transmitters are at different locations and the signals arrive at each receiving antenna location at different rates.
[0067] In a related embodiment, a measure of distance is calculated between the fingerprint of the most recently received signal and a weighted average of the preceding fingerprints. If the calculated distance exceeds a threshold, the first node can assume that the signal is not arriving from the peer node, i.e., that a malicious device is interfering with communication. The weighting used may take into account operational conditions. For example, if both nodes are relatively stationary, a weighted average may be used to smooth out measurement noise. In this case, each signal may be weighted equally. As another example, if one or both nodes are moving, the weighting may favor more recent signals. Alternatively, if there is movement or other systematic change, previous fingerprints may be used to predict the expected fingerprint of the next signal.
[0068] A fingerprint containing multiple parameters may be represented as a multidimensional object. The representation may additionally define a distance measure that can be used to compare fingerprints. Alternatively, the number of dimensions may be reduced by manipulating some or all of the parameters. In extreme cases, a fingerprint may be represented as a single number.
[0069] In further embodiments, multiple thresholds may be used to determine the appropriate response. For example, if the distance exceeds a first threshold, the signal may be discarded without further action. If the distance exceeds a second threshold, the first node may abort or resume an ongoing procedure.
[0070] In a further embodiment, a first node can initiate a transaction by first determining whether the peer node is within a "validity zone" for the transaction by first identifying some physical characteristics of the peer node, such as the peer node's exact location. For example, if the first node is a point-of-sale terminal, the peer node should be located within a small coverage zone corresponding to the owner being in front of the terminal. At least some of the location information can then form part of the fingerprint. Subsequent signals can then be checked to ensure that a) the peer device remains within the zone for the duration of the transaction and b) all signals are transmitted from the peer device.
[0071] In further embodiments, the fingerprint is alternatively or additionally used to determine whether the peer device is moving relative to the first device, and detected changes in movement can be used to trigger mitigation mechanisms, such as changes in antenna beam configuration or handover procedures.
[0072] In further embodiment variations, the fingerprint may be determined by using a ranging procedure between the two UEs, or by using a positioning procedure, or by using a wireless sensing procedure.
[0073] An example benefiting from this technique is the reception of a rejection message, e.g., a rejection message sent by a UE upon detecting a potential cause for rejection. This can occur, for example, in the context of a UE-to-network relay, when the relay receives a direct communication request message whose integrity cannot be verified or contains parameters that cannot be verified. In such a situation, it may be beneficial for the relay to send a rejection message to inform the remote UE that it was not accepted. Generally, if this rejection message is integrity protected, such as with a MIC, this is beneficial to prevent an attacker from injecting a false rejection message to interfere with normal communications. However, if the rejection message is not integrity protected, the remote UE can apply the technique of the previous embodiment to check whether the received rejection message is associated with a fingerprint similar to that of a message previously exchanged with the UE-to-network relay. In this way, the remote UE can achieve some assurance regarding the source of the received rejection message. This principle can also be applied in other environments where a first device verifies that it is still communicating with a second device by comparing the fingerprints of received messages. Similar techniques may also be applicable to other communication / sensing procedures involving other devices. For example, the user equipment rejects a message received from the base station.
[0074] Exemplary procedures that may benefit from the above procedures may include, but are not limited to, random access procedures, (conditional) handover procedures (e.g., where a gNB or UE wants to determine if the other party has an appropriate signal / fingerprint).
[0075] Generally, the above embodiments describe an apparatus (Rx) for enhancing the integrity of signals (S) in a signaling network, each signal (S) comprising a sequence of one or more signal elements, the apparatus (Rx) comprising an identification unit configured to identify injection (kI) of or interference with a signal element into a received signal based on at least one of a) a change in magnitude of the signal element, b) a signal fingerprint, c) a transmitter location, and d) an inversion of a permutation operation (P) applied to the received signal at the time of transmission.
[0076] According to another aspect of the same objective of improving signal integrity in signaling networks, it has been recognized that an attacker may attempt to attack a wireless system, such as a wireless sensing system. Such a wireless sensing system can also be considered a network and may be based on radar signals or on measurements of pilot sensing signals. Wireless sensing signals may be attacked by overshadowing or undershadowing attacks or by signal injection. The radar signal may, for example, consist of periodically transmitted chirps. A chirp may be a periodic signal whose frequency increases or decreases over time. For example, a radar signal may be transmitted every Tt seconds, and the radar signal itself may have a duration of Ts seconds, including N chirps with a duration of Tc = Ts / N. Here, during the duration of each chirp, the frequency increases linearly between frequencies fa and fb. For example, the frequency of the transmitted signal is fa + (k*t mod(fb-fa)), where fa is the initial frequency, k is the rate of increase, t is time, and mod is the modulo operation. If an attacker knows the parameters of a radar signal, they can find ways to inject new signals that resemble reflected radar signals to create new objects that do not exist or to hide the object's actual measured characteristics. To address this issue, the chirps in the radar signal may follow a permuted "pattern" or "signature," as described in the above embodiment. Additionally, or instead, the chirps may follow a "pattern" that appears random, e.g., N chirps may be of the increasing / decreasing frequency type. Therefore, in addition to or instead of permuting signal elements based on a permutation operation as described above, the signal elements may be modified in the frequency domain in a predetermined, possibly random, manner. It may also be preferable for how the signal is modified—in this case, the modification of signal elements in the frequency domain—to be known to the corresponding transmitter and the corresponding receiver but not to a potential attacker. Again, the term "random" as used herein should be understood to include "pseudo-random."As detailed above, a secure pseudo-random sequence of signal elements can be obtained by first determining a random seed and then applying a secure pseudo-random function to it (e.g., a key derivation function or SHAKE).
[0077] The permutation described above may be random permutation applied to a standard wireless sensing signal (e.g., a known chirp pattern), or the permutation may be applied to the wireless sensing signal before transmission. Similarly, the permutation may be random permutation applied to a standard wireless sensing signal upon reception. Also, the permutation operation may be applied to only a portion of the wireless sensing signal. For example, a chirp signal may be transmitted normally at a rate of f and transmitted using random permutation at a rate of 1-f. This has the advantage of reducing the computational overhead during transmission and reception.
[0078] In practice, to enhance the integrity of wireless (sensing) signals within a signaling network, wireless sensing signals may be characterized or made identifiable by a “signature” or “pattern,” which may be, for example, (i) a specific randomized / permuted arrangement of chirps as described above, and / or (ii)) a specific modulation (e.g., amplitude, phase, frequency) of one or more chirps. In this second case, the modulation may consist of modulating the amplitude (or other feature) of a chirp of duration Tc, for example, where Tc is divided into M intervals of duration Tc / M, each modulated by a different amplitude (or other feature). As another example of this second case, the frequency may be modulated; for example, instead of a chirp in which the frequency of each chirp increases linearly between frequencies f and fb, a chirp may be used whose frequency varies continuously (i.e., does not jump between f and fb) but which still follows a non-constant pattern that is difficult for an attacker to guess. For example, the frequency of the transmitted signal may be fa+(k(t)*t mod(fb-fa)), where k(t) refers to the rate of increase which may be time-varying and not constant, e.g., k(t) may be k*sin(fm*t), where fm is the frequency that determines the rate of change.
[0079] The "signatures" or "patterns" may be updated according to a particular schedule (eg, every T_up seconds).
[0080] In one embodiment, the wireless sensing signals may be characterized / identifiable by a "signature" or "pattern," as defined above, that is location-specific or direction-specific, i.e., specific to a particular direction DIR relative to the transmitter, for example. This limits the range of potential injection attacks, as an attacker must be able to monitor the "signature" or "pattern" contained in the wireless sensing signals in the particular direction DIR. A malicious attacker injecting false wireless sensing signals will only be successful if the attacker injects signals from the direction DIR and contains the appropriate "signature," "pattern," or "fingerprint."
[0081] In one embodiment, when a first signal (e.g., a communication signal) is received next to a second signal (e.g., a ranging signal or a wireless sensing signal such as a radar chirp), the receiver can verify the integrity of the first signal, and the receiver can verify the location of the transmitter via the second signal.
[0082] To implement any of the above countermeasures, one or more wireless sensing transmitters in the network may be configured to transmit wireless (sensing) signals as described above.
[0083] In a further embodiment, if the wireless sensing receiver detects an object at distance d as the nearest object, or if the wireless sensing receiver wishes to limit the distance at which an attack can be carried out to d or less (i.e., an attacker located beyond distance d cannot carry out an injection attack), the wireless sensing receiver may request (or the wireless sensing transmitter may be configured to) the wireless sensing transmitter to adjust the period of the wireless sensing signal to at least d / c, and in particular may request that a "pattern" or "signature" be used whose duration is at least d / c (where c is the speed of light).
[0084] The wireless (sensing) receiver may also receive the wireless (sensing) signal as described above and compare (or integrity check) the received wireless (sensing) signal with a pattern (e.g., a permuted pattern, a random pattern, etc.) of the transmitted wireless (sensing) signal. This comparison may require that the received wireless (sensing) signal follow the same "signature" / "pattern" as the transmitted wireless (sensing) signal. Furthermore, the comparison (integrity check) step may require, for example, detection of a change in the magnitude of a signal element and / or reversal of the (permutation) operation (P) applied to the received signal during transmission. The comparison (integrity check) step may also be direction-dependent.
[0085] In a further embodiment, if a manipulation (e.g., reordering) is applied to the sensing signal during transmission, the receiver must be synchronized when the sensing signal arrives before applying the inverse of the reordering manipulation. For example, a wireless sensing system that receives a reordered chirp, e.g., an FMWC chirp, before transmission requires a synchronization module capable of detecting the reordered chirp sequence. The synchronization module triggers a detection event upon detection of the reordered chirp sequence, which triggers a second module responsible for performing the inverse of the reordering manipulation on the received signal. This is necessary because, because the distance to the target is unknown and therefore the time at which the reflected wireless sensing signal will arrive is unknown, it is necessary to first determine when to initiate the inversion manipulation before reversing the manipulation based on the sensing signal. The synchronization module can detect the signal, for example, by analyzing the correlation between the received signal and the transmitted reordered sensing signal or a matching filter. Once a correlation peak is identified, the inverse manipulation can be applied to the received sensing signal, which is then sent to a wireless sensing receiver, e.g., a radar receiver.
[0086] Note that the above synchronization procedure is also necessary if the sensing (chirp) signals are not all exactly equal, or if some characteristics of the chirps are mixed or altered depending on the operations applied to the transmitted sensing signals, such as the slope or rate of linear frequency increase between frequencies fa and fb, or the distance between chirps.
[0087] Note that in the above embodiment, where the "signature" or "pattern" may be a specific modulation, the above synchronization step may not be necessary, and thus this embodiment may provide a simpler sensing receiver. For example, in the case of a receiver with a time-varying frequency rate, the sensing receiver may need to mix the received signal with a transmitted signal having a variable frequency between fa and fb and modulated according to k(t). When the signals are mixed, a main peak appears in the frequency domain at a frequency that depends on the distance, and smaller peaks appear next to it, the specific location of which depends on the modulation frequency of k(t). The sensing receiver can determine the presence of the injected signal by monitoring the correct or incorrect location of these smaller peaks, which depend on k(t).
[0088] If operations are not necessarily applied to the transmitted sensing signal, the pipeline is not necessarily executed, reducing the required resources.
[0089] In a further embodiment, if manipulation is not necessarily applied to the transmitted sensing signal, an attacker may attempt to attack the system if the sensing signal is predictable. Thus, the receiver needs to verify that the reading r1[n] of the received sensing (radar) signal when the manipulation is applied to the transmitted sensing signal is consistent with the reading r2[n] of the received sensing (radar) signal when the manipulation is not applied, e.g., that no new targets are detected when no manipulation is applied to the transmitted sensing signal, or that the reading r1[n] is equal to r2[n] (where n is discrete time n).
[0090] In a further embodiment, the proportion of the transmitted sensing signals that undergo the (reordering) operation is context-dependent. If the environment is friendly (e.g., no attacker is detected when comparing readings of the received sensing (radar) signals with and without the operation applied to the transmitted sensing signals), the (reordering) operation is applied to a small portion of the transmitted sensing signals. If the readings do not match, the operation is applied to a larger portion / percentage f′ of the transmitted sensing signals. This embodiment provides a trade-off between resource requirements and robustness. In particular, f at time n may depend on the consistency between readings obtained from the transmitted sensing signals with and without the (reordering) operation. For example, if r1[n-1] == r2[n-1], f[n] tends to a lower value f0, but if r1[n-1] != r2[n-1], f[n] tends to a higher value f1.
[0091] Configuration parameters, including the use of "patterns" or "signatures" to limit the injection of false sensing signals, timing functions, whether the "patterns" or "signatures" are direction-specific, update times, etc., may be set in the wireless sensing transmitter or wireless sensing receiver by a management entity such as a core network, a network function responsible for wireless sensing, or an (external) application function. Also, it should be noted that the wireless sensing transmitter and / or wireless sensing receiver could be a base station or a user equipment.
[0092] In certain circumstances, an attacker may exploit wireless sensing signals to passively monitor a target device (e.g., a person). This may be done, for example, when an attacker monitors a transmitter's (e.g., a base station's) wireless sensing signal (e.g., a radar-based sensing signal) and receives the sensing signal reflected by an object (e.g., a person). This may be done when the attacker himself can transmit wireless sensing signals to monitor an object, such as a person. Characteristics an attacker may attempt to monitor include, but are not limited to, location, velocity, health information, number, etc. Therefore, a further objective of the present invention is to address this privacy issue. This is achieved by embodiments that monitor the integrity of received signals and prevent unwanted / unauthorized parties from injecting signals, such as sensing signals.
[0093] In further embodiments, a personal sensing firewall (PSF) intended to prevent sensing by unwanted / unauthorized parties may be used within a region of interest (ROI) or by a person or object. For example, the ROI may be a house. For example, the object may be a UE. For example, a person may carry a PSF. The PSF processes the received signal to ensure its integrity, i.e., as in other embodiments, removes injected signals / interference to ensure that only signals received from trusted senders are processed. Additionally or alternatively, the PSF may modify the received signal to prevent information leakage. This is illustrated by FIG. 10, in which a transmitting device 1000 transmits a signal 1003. The signal is received by a user equipment 1002, which may include a PSF function 1007. The user equipment / PSF may reflect / generate / return a signal 1004 to the receiving device 1001. A (malicious) sender / receiver 1005 may transmit a signal 1006 with the intent or effect of disrupting the operation of user equipment 1002, the reception of signal 1003, and / or the reflection / transmission of signal 1004.
[0094] In further embodiments, the PSF may be incorporated into the UE. Alternatively, the PSF may be associated with the UE in another manner. For example, it may be incorporated into a phone case used to hold the UE and further linked to the UE by a proximity mechanism such as NFC so that the PSF can act according to instructions received from the UE or the network. For example, the PSF may be incorporated into a home (e.g., a home base station providing coverage to the home) and may be activated when the UE is within range of the home. The PSF may also be incorporated into a router, such as a wireless router used in a Wi-Fi network.
[0095] The PSF monitors incoming signals and determines whether an authorized incoming signal is being received. For example, the PSF may monitor whether an incoming wireless sensing signal (1003 or 1006), which can be used for wireless sensing, is being received. The PSF may monitor whether a signal is authorized. For example, signal 1003 may be authorized, and the access device (typically a transmitter) may have notified the UE / PSF (1002, 1007) about it. For example, signal 1006 may not be authorized, and the UE / PSF may not be aware of it. Thus, when signal 1003 or 1006 is detected, the UE / PSF may have a policy or configuration that applies a related embodiment of the present invention to prevent leakage.
[0096] In further embodiments, the PSF may be based on or include one or more backscattering devices configured to modulate the backscattered wireless (sensing) signal. The PSF may also refer to a smart repeater that can modify certain parameters of the retransmitted signal, such as phase, delay, amplitude, etc., to simulate a perceived wireless channel or distortion in the received signal.
[0097] In further embodiments, the PSF may rely on or include one or more radios and / or receiving / transmitting units (e.g., backscatter radios) that can, for example, reflect and / or modulate (the modulation can be at least one of FSP, PSK, or ASK) a received radio (sensing) signal. The radios may be capable of generating a wireless sensing signal; for example, when the PSF receives / senses the wireless sensing signal, the PSF may be able to determine parameters of the wireless sensing signal and regenerate / retransmit the wireless sensing signal, for example, after a predetermined delay.
[0098] In a further embodiment, the PSF modulates the (reflected / backscattered) wireless sensing signal according to a pattern, which may be generated by the PSF, for example, if the PSF wishes to prevent or make difficult monitoring of an object / person / ROI (which may be performed by wireless sensing).
[0099] In a further embodiment, the pattern is a randomized pattern.
[0100] In a further embodiment, the randomized pattern is difficult to predict, in that an attacker observing the pattern over a period of time cannot guess the pattern value at the next moment. In particular, if the pattern is a sequence of symbols where each symbol can take two possible values (1 and 0) with equal probability, an attacker cannot guess whether the next symbol will be a 1 or a 0 (between 0 and 1) with a probability better than 0.5.
[0101] In a further embodiment, the PSF FSK-modulates the (reflected / backscattered / received) wireless sensing signals according to a pattern, so that the (reflected / backscattered) signals mask smaller / weaker reflections from passive objects, thereby preventing a receiver (e.g., an attacker's receiver) from identifying the object's position / movement / acceleration. For example, the PSF may use a random pattern to determine a random frequency fs used to FSK-modulate the backscattered / reflected wireless sensing signals (creating a fake object at a different location). For example, the PSF may use the random pattern to determine a set of frequencies fsi, and then use different sets of frequencies fsi to modulate the backscattered / reflected wireless sensing signals (creating different fake objects at multiple different locations).
[0102] In a further embodiment, the PSF modulates the (reflected / backscattered) wireless sensing signal according to a pattern (PSK / ASK) such that the (reflected / backscattered) signal masks smaller / weaker reflections from passive objects, making the wireless communication channel appear randomized and preventing a receiver (e.g., an attacker's receiver) from determining the object's velocity (e.g., related to heart rate, breathing rate).
[0103] In a further embodiment, the PSF and the trusted (sensing) device (e.g., gNB or receiver) agree on a pattern (e.g., a randomized pattern). This allows the trusted (sensing) device to access information in the received (reflected) wireless sensing signal even when the PSF applies a pattern. Considering FIG. 10, this trusted (sensing) device may refer to the transmitting device 1000 and the receiving device 1001, which may be co-located or located at different locations.
[0104] In a further embodiment, the PSF securely receives the pattern (or parameters for generating the pattern) from an access device (e.g., a gNB) or a wireless sensing transmitter or a wireless sensing receiver.
[0105] In further embodiments, the PSF generates a random pattern of a specified length from a seed using a cryptographically secure pseudo-random number generator, for example by applying a deterministic random bit generator or a function such as SHAKE256, part of the SHA-3 family of hash functions.
[0106] In another embodiment, the PSF is configured to optimize the propagation path between the transmitter of the sensing signal and one or more authorized sensing receivers.
[0107] The PSF not only provides gain to the sensing receiver (and in some cases allows for lower transmit power), but also directs energy away from the attacker's receiver.
[0108] In further embodiments, multiple adjacent PSFs may cooperate with each other or be coordinated by a network to monitor different portions of the spectrum. This is beneficial when the PSFs are narrowband and can use wireless sensing signals in different (wide) frequency bands. If one of the PSFs detects a potentially malicious wireless sensing signal, the PSF may report this to the network and / or the other PSFs. Each PSF may then monitor / configure (or be configured) itself to operate in that particular frequency band.
[0109] In further embodiments, if the PSF recognizes that an input signal (e.g., signal 1006) is received from a different location than a previously received signal (e.g., signal 1003), typically if the fingerprint of the input signal (e.g., signal 1006) differs from the fingerprint of the previously received signal (e.g., signal 1003), it may apply one of the protection measures, for example a random pattern to modulate the signal.
[0110] In further embodiments, the PSF may apply the protection measures described in the present invention. For example, the PSF may apply AI / ML mechanisms to reduce or address interfering signals. The PSF may also coordinate the application of countermeasures with management entities, such as RAN entities (e.g., base stations), network functions, applications, etc., based on control commands or configurations.
[0111] Another potential threat to sensing protection is undershadowing, which occurs when an attacker transmits a signal that interferes with the sensing signal at the receiver, causing symbol errors or signal quality degradation. In a variation of the embodiment, this type of attack may be detectable (and correctable) at the symbol or block level by an error coding system used at a layer higher than the physical layer. For example, the receiver may use a cyclic redundancy check (CRC) code, a forward error correction (FEC) code, or other form of integrity check to identify and correct errors in the received signal. Alternatively, or in addition, the receiver may use artificial intelligence (AI) or machine learning (ML) techniques to analyze error patterns and / or to assist in detecting and correcting errors. For example, the receiver may use an error-correcting neural network to learn a mapping between tampered and original signals, or a classifier to distinguish between legitimate and malicious signals based on signal characteristics.
[0112] In another embodiment variation, the device may employ one or more of the following techniques to uncover interference or attacks on the sensing signal. One technique is to transmit null symbols or known dummy symbols where interference is expected in the presence of noise, jamming, spoof signals, etc. By comparing the received symbols with the expected symbols, the device can detect discrepancies that indicate interference or attacks. Another technique is to change the modulation of the sensing signal, particularly to a different symbol rate or carrier spacing, which may also uncover interference or attacks. For example, the device may switch from quadrature phase shift keying (QPSK) modulation to amplitude shift keying (ASK) modulation, or from narrowband modulation to wideband modulation. By doing so, the device may change the spectral characteristics of the sensing signal, making it more difficult for an attacker to match or jam the sensing signal. The device may also reveal anomalies caused by interference or attacks by observing the effect of modulation changes on the quality or error rate of the received signal. The device may apply these techniques periodically, randomly, or adaptively depending on network conditions and sensing requirements. The different embodiments can be combined with each other as appropriate.
[0113] In a general definition of this embodiment, a sensing protection method is proposed that may be implemented in a device configured to: - (sensing) receiving a signal or determining the presence of a signal; - receiving configuration of measures to enhance the integrity of the received signal and policies (e.g., pattern configuration) that determine when the measures should be applied; - applying the measures, e.g. obtaining or generating patterns; - when modulating the backscattered or reflected received sensing signal, or - using the above pattern in at least one of the following cases when transmitting a time-delayed / scaled / modulated copy of the received sensing signal.
[0114] The present invention also relates to a method for enhancing signal integrity in a signaling network, each signal including a sequence of one or more signal elements, the method including identifying injection of a signal element into a received signal based on at least one of a) a change in the magnitude of the signal element or b) a reversal of a reordering operation applied to the received signal at transmission. As described above with respect to the corresponding apparatus, the method may include identifying injection of a signal element into the received signal by, for example, detecting a change in the magnitude of the signal element, e.g., by measuring, for each signal element of the received signal, a signal element magnitude that may indicate the energy of the signal element and detecting a change in the signal element magnitude based on the measured signal element magnitude, and possibly processing the received signal based on the identified injection of the signal element. As detailed above, the processing may include, inter alia, modifying the received signal in response to the detected attack.
[0115] Furthermore, the invention relates to a computer program for increasing the integrity of signals in a signaling network, the program comprising instructions for causing a device, in particular the device first mentioned above, to carry out the method described above.
[0116] Similarly, a method and corresponding computer program are provided in which: a) at least a portion of the signals in the network are modulated before transmission in accordance with the reordering and / or frequency modulation operations determined as above in order to avoid successful attacks; and / or b) an integrity check is performed on a predetermined percentage of the signals in the network, wherein, for a particular transmitted signal, whether or not to perform an integrity check on the signal is decided randomly based on said predetermined percentage, and the integrity check may be performed as detailed above and / or may be of the type detailed above.
[0117] It is to be understood that the apparatus of claim 1, the system of claim 13, the method of claim 14 and the computer program of claim 15 have similar and / or identical preferred embodiments, in particular as set out in the dependent claims.
[0118] It is to be understood that a preferred embodiment of the invention can also be any combination of the dependent claims or the above embodiments with the independent claims.
[0119] These and other aspects of the invention will be apparent from and elucidated with reference to the embodiments described hereinafter. [Brief explanation of the drawings]
[0120] [Figure 1] FIG. 1 shows a schematic and exemplary communication network. [Figure 2] FIG. 2 illustrates a schematic and exemplary overshadowing attack. [Figure 3] FIG. 3 illustrates schematically and exemplarily the use of successive interference cancellation to remove interfering signals, for example against overshadowing attacks. [Figure 4] FIG. 4 illustrates a schematic and exemplary undershadow attack. [Figure 5] FIG. 5 shows, schematically and exemplarily, an apparatus for increasing the integrity of signals exchanged in a signaling network. [Figure 6] FIG. 6 shows, in a schematic and exemplary manner, the processing of a received signal to correct for an undershadow attack. [Figure 7] FIG. 7 shows schematically and exemplarily the processing of a received signal to remove interfering signals, for example to avoid successful undershadowing attacks. [Figure 8] FIG. 8 illustrates schematically an exemplary reordering operation that can be applied to signals to avoid interfering signals, for example to avoid successful undershadowing attacks. [Figure 9] FIG. 9 shows a schematic diagram of the AI / ML procedure for removing the interfering signal. [Figure 10] FIG. 10 shows a schematic diagram of a use case of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0121] FIG. 1 illustrates, in a schematic and exemplary manner, a communication network in which embodiments disclosed herein may be implemented. The illustrated exemplary network is a cellular communication network, such as a 4G or 5G network, in which terminals / end devices (referred to as user equipment, or UE for short, in 5G) of the network implement apparatus according to the disclosed embodiments. In FIG. 1, the terminals / end devices are depicted as receivers Rx because the following detailed description will primarily refer to this function of the terminals / end devices. It should be understood that they also function as transmitters in the network. Similarly, base stations (referred to as gNodeBs, or gNBs for short, in 5G) of the network are depicted as transmitters Tx in FIG. 1 because the following detailed description will primarily refer to this function of the base stations. It should be understood that they also function as receivers in the network. For example, the terminals / end devices can access various types of services, such as voice services and data services, through the exchange of signals with base stations of the network.
[0122] Each base station serves or communicates with terminals / end devices located within a given area, also called a cell. Two adjacent cells are shown in Figure 1 by dotted lines. The base stations are connected to a core network (CN) managed by a network operator or management entity. The core network controls the delivery of services. Each cell is served by one base station, which serves as an interface between the terminals / end devices and the core network 120. As shown in Figure 1, the terminals / end devices are mobile devices that may move from one network cell to another. Therefore, the interface used by a particular terminal / end device may change over time. The terminals / end devices may communicate with the base station via various uplink (from the device to its corresponding base station) and downlink (from its corresponding base station to the device) wireless channels. Other wireless channels may exist, for example, between terminals / end devices (e.g., sidelink channels) and between base stations (e.g., X2 interface), but are not shown in Figure 1 for simplicity. Each terminal / end device may perform its function along any channel. However, the primary interest may be in the channel connecting the terminal / end device with its corresponding base station. In particular, the downlink channel may be important, in which case the terminal / end device may implement an apparatus according to the present disclosure in the form of a receiver Rx, and the base station may implement a further apparatus according to the present disclosure in the form of a transmitter Tx.
[0123] Cellular communication networks have evolved to include wireless sensing capabilities, and the resulting systems are capable of both wireless communication and sensing. In such systems, base stations may be capable of transmitting and / or receiving wireless sensing signals. Similarly, terminals / end devices may be capable of transmitting and / or receiving wireless signals.
[0124] Figure 2 illustrates a schematic of an overshadowing attack in which a transmitter (Tx) transmits a message / signal (S), an attacker transmits a stronger interfering signal (kI), and a receiver (Rx) receives a signal (S+kI). The interfering signal is assumed to be k times stronger (k>1) than signal (S). Therefore, the magnitudes of S and I are assumed to be the same. Furthermore, a characteristic of an overshadowing attack is that the interfering signal has the same length, i.e., the same number of signal elements, as the original signal (S), and is timed to be received by receiver (Rx) at the same time as signal (S). The signal (S+kI) received by receiver (Rx) is a superposition of signals (S) and (kI). While there is no "before" or "after" in the superposition, in Figure 2 signal (S) is depicted as being in front of signal (kI).
[0125] The signal S shown in Figure 2 is a modulated or coded signal. Therefore, as is typical for transmitting information via a signal, the transmitter Tx applies a transmission transformation in the form of a modulation or coding operation to the corresponding carrier or base signal. As shown in Figure 2, to extract the information conveyed via the signal S, the receiver Rx applies a demodulation or coding operation, respectively, to the received signal. In this case, the received signal is a superposed signal S+kI. A receiver that receives and demodulates / decodes the signal S+kI typically obtains a signal that differs in phase and amplitude from signal S depending on the relative proportions of S and I at the receiver. In extreme cases where S is a phase- or frequency-modulated signal and the magnitude of kI is sufficiently larger than S, the receiver tends to obtain signal I due to the capture effect. The obtained signal I corresponds to a demodulated or decoded version of the attacker-sent signal kI, reduced in level to the magnitude of the signal S transmitted by the transmitter Tx.
[0126] In a typical overshadowing attack, an attacker modifies a broadcast message sent from an LTE base station (Tx) by injecting a strong signal, which can be denoted as kI as described above. As a result, all user equipment (UE) devices receiving such a broadcast as a receiver (Rx) decode the incorrect signal and are affected by the attack. In this case, an overshadowing attack can be used to modify specific fields in messages broadcast in LTE or 5G, particularly fields in the lower signaling layers that are not integrity protected or during initial communication. In LTE systems, it has been shown that any downlink traffic can be overshadowed. Conversely, an attacker can also attack a base station receiving a message sent from a UE. In this case, the UE can be the transmitter (Tx) and the base station can be the receiver (Rx).
[0127] It turns out that signals attacked by overshadowing attacks can be recovered using a technique called successive interference cancellation (SIC). SIC is the basis for non-orthogonal multiple access, which is being considered for use in 5G. The original SIC concept is shown in Figure 3.
[0128] FIG. 3 corresponds to FIG. 2 in that it extracts signal I from superimposed signal S+kI. However, in this case, receiver Rx is configured to re-modulate or re-encode signal I and subtract the resulting signal from the original received signal S+kI. For example, as shown in FIG. 3, two signal processing chains may be formed within the receiver. Signal S+kI is demodulated / decoded along the first signal processing chain and then re-modulated / re-encoded along the second signal processing chain. The two signal processing chains may be combined by subtracting the signal resulting from the first signal processing chain from the signal resulting from the second processing chain, where the latter signal is simply the received signal S+kI. The resulting signal is the signal S originally transmitted by transmitter Tx, i.e., the undisturbed signal. As shown in FIG. 3, a demodulation or decoding operation may be applied to this signal to extract the information to be conveyed.
[0129] The division of the signal processing chain into first and second signal processing chains shown in Figure 3 is an example of what was described above as replicating a received signal into first and second replicas. Furthermore, as shown in Figure 3 and repeated correspondingly in Figure 6, it will be appreciated that signal subtraction can be accomplished by first inverting, i.e., making negative versions of, the signals to be subtracted and then adding the signals together.
[0130] As mentioned in the introduction, like the over-shadow attack, the under-shadow attack also exploits the capture effect, but the interfering signal in an under-shadow attack matches the original signal only in separate signal elements. Figure 4 shows a schematic and exemplary under-shadow attack, and it can be seen that in contrast to the over-shadow attack, in the under-shadow attack the injected signal kI only affects certain bits / symbols of S, i.e., only a given signal element in the sequence of signal elements that make up the signal S.
[0131] It has been found that under-shadowing attacks are more difficult to detect than over-shadowing attacks because the total energy of the interfering signal is relatively low, especially lower than the total energy of the original signal. Therefore, in contrast to over-shadowing attacks, a tampered signal cannot be distinguished from an untampered signal from a total energy perspective. Furthermore, applying SIC as shown in FIG. 3 is unsuccessful because the subtraction results in the loss of original signal components. Therefore, the use of digital signatures to avoid under-shadowing attacks in master information blocks (MIBs) such as those used in LTE and / or modifying SIC to correct under-shadowing attacks have been proposed. However, there remains a need to enhance signal integrity in networks subject to attacks such as over-shadowing and, in particular, under-shadowing attacks. Specific embodiments that address this need are described with reference to FIGS. 5-8. It should be noted, however, that an apparatus for processing signals with SIC to correct an identified over-shadowing attack, as described with reference to FIG. 3, can already enhance signal integrity in a signaling network, e.g., as shown in FIG. 1. Therefore, such an apparatus forms a further embodiment and, in fact, can be considered a "base" embodiment.
[0132] FIG. 5 illustrates, in a schematic and exemplary manner, an apparatus for enhancing signal integrity in a signaling network. While the following three units may not be necessary in other embodiments, the illustrated specific apparatus, which may be a receiver of or part of the network, includes a measurement unit, an identification unit, and a processing unit. The measurement unit, which may include a sensor, is configured to measure the magnitude of signal elements in the received signal and forward the measurement results to or provide access by the identification unit. The identification unit is configured to identify the injection of a signal element into the received signal based on, in this case, a change in the magnitude of the signal element, i.e., a change in the magnitude of the signal element measured by the measurement unit. The processing unit is configured to process the received signal based on the injection of the identified signal element, i.e., in this case, based on whether the injected signal element was identified by the identification unit. If identified, the processing unit processes the received signal based on the injected signal element, e.g., based on the magnitude and / or position of those elements in the sequence of signal elements.
[0133] FIG. 6 illustrates, in a schematic and exemplary manner, an apparatus for enhancing signal integrity in a signaling network in the form of a receiver Rx, where each signal includes a sequence of one or more signal elements, and includes a processing unit configured to process the received signal. The processing unit, which may also be referred to as a processor, is not shown in FIG. 6, but the processing steps performed by the processing unit are illustrated. FIG. 6 can be understood as a more contextual description of the type of apparatus shown in FIG. 5. FIG. 6 focuses on processing steps that can be performed by the processing unit, which can also be understood and implemented independently of the measurement and identification steps performed by the measurement and identification units, respectively. While FIGS. 5 and 6 illustrate the receiver as an exemplary apparatus, instead of being located within the receiver Rx, the processing unit may be partially or completely located elsewhere. In that case, the receiver may forward the received signal to the processing unit, possibly after some initial processing steps, including demodulation or decoding.
[0134] The processing unit is configured to process the received signal based on the injection of the identified signal element. Notably, while the processing steps illustrated in FIG. 6 are depicted as if they were fixed, i.e., always performed for all received signals, this is not necessarily the case. Instead, the processing unit may be configured to perform the illustrated processing steps only upon request, such as a request from a central management entity within the transmitter Tx or core network CN, and / or only upon identification of one or more signal elements being injected into a signal previously transmitted over the network, particularly a signal previously received by the receiver Rx. Furthermore, to identify signal element injection, such as due to an over-shadowing or under-shadowing attack, the receiver Rx may (although as noted above, this need not necessarily be the case) include, as shown in FIG. 5, a measurement unit configured to measure a signal element magnitude (the signal element magnitude indicating the energy or related quantity of the signal element) for each signal element in the received signal, and an identification unit configured to identify the injection of the signal element into the received signal by detecting a change in the signal element magnitude based on the measured signal element magnitude. The magnitude of the signal element used as a reference may refer to the magnitude of the signal element within a single received signal or between multiple signals. Thus, for example, significant magnitude changes can be detected by comparing the magnitudes of signal elements of a) a sequence of signal elements of a particular received signal and b) at least one sequence of signal element sequences that includes signal elements of the received signal and one or more corresponding signal elements of a previous repetition of the received signal. Although not shown in Figures 3 and 6, the measurement unit and identification unit may be located before the elements shown for the receiver in the signal processing chain.For example, the identification unit may be configured to identify the presence of an over-shadow attack if the magnitudes of all measured signal elements of the received signal measured by the measurement unit deviate from the magnitudes of the expected signal elements by at least a predetermined amount, and to identify the presence of an under-shadow attack if the magnitudes of one or more measured signal elements of the received signal measured by the measurement unit deviate from the magnitudes of the expected signal elements by at least a predetermined amount.
[0135] To identify undershadow attacks on a repetitive signal S, the measurement unit may be configured to measure the magnitude of signal elements over several repetitions of the signal S. In that case, the identification unit may be configured to calculate the average magnitude of each signal element over several repetitions of the signal S and identify the injection of signal elements based on the variation in the average magnitude of the signal elements, where the variation may be detected based on a statistical test of whether the average magnitude of the signal elements corresponds to an assumed uniform distribution. If the signal is a non-repetitive signal, only the magnitude of the signal elements of each signal itself may be used, i.e., the average value is not used. The identification unit may also be based on an AI / ML model embedded in the signal receiver, which may be designed to classify whether the received signal / signal element is subject to interference.
[0136] Figure 6 corresponds to Figure 3 in that the original signal transmitted by the transmitter Tx is again denoted by S, and the interfering signal (e.g., transmitted by an attacker) is again denoted by kI. In Figure 6, the combination of the two signals S and kI received by the receiver Rx, i.e., the superimposed signal S+kI, is denoted by S2, i.e., S2 = S+kI. As in Figure 3, the receiver Rx is configured in the illustrated embodiment to optionally subtract a processed version of the signal S2 from the signal S2 itself if the presence of an attack (here an undershadow attack) is identified.
[0137] Subsequent processing is implemented by two separate signal processing chains, again similar to FIG. 3. The first signal processing chain actually processes signal S2, while the second signal processing chain stores signal S2, and the two signal processing chains are combined by subtracting the processed version of signal S2 from the stored, unprocessed version of signal S2. However, according to the embodiment of FIG. 6, the processing applied along the first signal processing chain is different, except for the first demodulation / decoding step, which is the same as that shown in FIG. 3. Subsequent processing may be based on an AI / ML model that can process the input signal and perform demodulation / decoding such that interfering signals are ignored.
[0138] The exemplary embodiment shown in FIG. 9 is an apparatus that may be used within a wireless transceiver. In FIG. 9, 905 represents an antenna for receiving / transmitting information, 902 represents a modulation / demodulation block, 903 represents a MIMO block enabling transmission / reception via multiple antennas, 904 represents a receive / transmit processor, 906 represents a data source / sink, and 901 represents one or more AI / ML models used to control 902, 903, and 904, with control managed by block 900. This apparatus may be applicable to wireless communication devices, such as 3GPP wireless communication devices. A first AI / ML model may be trained to distinguish / infer whether a received raw signal contains two or more overlapping signals, for example, based on the output of block 902. A second AI / ML model may be trained to distinguish whether each signal is received from a different direction, for example, based on the output of block 903. A third AI / ML model may be trained to separate two or more signals based on information inferred from the first model and / or the second model.
[0139] In a variation of this embodiment, the first AI / ML model may be able to distinguish whether one, two, or more signals are received by analyzing the modulation constellation (e.g., 16-QAM) and whether there are one, two, or more overlapping modulation constellations. These analyses may also return the relative strength of the received signals, thereby allowing one signal to be extracted from another.
[0140] In a further embodiment variation, the second AI / ML model may be able to distinguish between different signal receiving directions.
[0141] In a further embodiment variation, the third AI / ML model may be capable of extracting one or more signals from the raw received signal.
[0142] In further embodiment variations, the AI / ML model may be able to determine whether one or more signals included in the raw received signal are multipath signals that arrive with different phases / delays / signal strengths based on the corresponding path channels, and the AI / ML model may be able to indicate relative signal strengths, phases, delays, etc. so that block 904 can perform signal alignment.
[0143] In a further embodiment variation, the AI / ML model may be able to distinguish between types of interference, e.g., injection attacks such as overshadow or undershadow attacks, or multipath, and return an indication of the cause.
[0144] In a further embodiment variation, the AI / ML model may have been trained using a dataset representative of the situation to be inferred, e.g., a dataset including over-shadow attacks, under-shadow attacks, multi-path, etc.
[0145] In a further embodiment variation, the apparatus may receive instructions to apply one or more AI / ML models from an access device (e.g., a base station such as a 5G gNB) or a network function in the core network, or a management entity such as an Operational, Administration, and Maintenance function, and the instructions may include an identifier indicating the AI / ML model to apply.
[0146] In a further embodiment variation, the device may be capable of receiving the AI / ML model from the management entity described above.
[0147] In a further embodiment variation, the AI / ML model may be a neural network, such as a convolutional neural network (CNN) or a recurrent neural network (RNN). A convolutional neural network may be able to identify symbols received within a modulation. Even if interference occurs and a symbol is obscured by the interference, the CNN may be able to recover the symbol because it has been trained or tuned to recognize symbols of a particular size / strength. Similarly, the RNN maintains a memory of previously calculated outputs. The RNN may also record the received signal strength of a signal so that it can take it into account in inferring the next processed symbol to remove and / or provide an indication of the interfering signal.
[0148] In further embodiments, devices implementing the techniques described in the present invention that allow for identifying potential injection of interfering signals or the impact of interference, and techniques that allow for removal of interference, may be applied upon configuration by a management entity (e.g., a RAN device such as an access device, an NF in a core network, OAM, etc.), which application may include: - Upon request based on measurements provided by the device, and / or - The configured policies may be implemented in determining the conditions under which the techniques are applied upon analysis by the device as to whether the conditions are met.
[0149] In further embodiments, measurements / conditions sent to a management entity or that trigger execution of a configured policy may include one or more of the following: - Deterioration of communication quality, - Increased communication errors, - detection of changes in the fingerprint of the received signal, - Unexpected signal detection.
[0150] In the exemplary embodiment shown schematically in FIG. 6, the demodulated / decoded signal is S3=d (-1) It is written as S+dI, where d is a binary signal with length S, and d is 1 in the slots (e.g., time / frequency) that affect S (if I has a non-zero value), and 0 otherwise. (-1) is the inverse of d, and therefore explicitly sets the values of S that are affected by I to 0, and the values that are not affected by I to S. The term "inverse" refers to the binary inversion, or complement, so if d is 1, then d (-1) is 0 and vice versa.
[0151] The signal elements (which may be symbols in particular) of the signal S3 are scaled depending on whether they are identified by the identification unit as injected signal elements, for example, based on a change in the magnitude of the signal elements (which may be symbol energy in particular). If the injected signal elements are identified based on the magnitude of the signal elements, the signal elements can also be said to be scaled based on the magnitude of the signal elements. In this way, it can be considered that the identification of the injected signal elements remains implicit.
[0152] The result of the scaling operation is S4=ad in Figure 6. (-1)S+bdI. Thus, signal elements identified as originating from the transmitter Tx are scaled by a predefined factor a, and signal elements identified as originating from the attacker are scaled by another predefined factor b. The factors a and b are preferably selected such that 0≦a<1 and b>k−1.
[0153] To find a and b, signal S2 must be normalized by dividing the magnitude of each signal element in signal S2 by the magnitude of the signal element with the lowest signal element magnitude. If each symbol in S2 can be received at two energy levels, as would be the case if binary thresholding of the received signal were performed, then after normalization, each symbol in S2 will have an energy level of either 1 or k. The above description, particularly FIG. 6, assumes and illustrates signal S2 that has already been binary thresholded and normalized. This assumption is justified because the processing unit may be configured such that processing the received signal includes thresholding signal elements to predefined signal element levels, where the predefined signal element levels include at least an injection level indicating the magnitude of injected signal elements and a non-injection level indicating the magnitude of non-injected signal elements, and the signal elements are scaled according to their respective signal element levels. The injection level may be selected to include all reasonable signal element magnitudes that an attacker might apply, and the non-injection level may be selected to include all signal element magnitudes of normal signal traffic in the network. Normalization may be performed to a relatively low uninjected level, resulting in a factor k that indicates the ratio of the typical magnitudes of the injected and uninjected levels.
[0154] According to the embodiment of FIG. 6, before the second demodulation / decoding, a scaled version of S3 is added, i.e., S4=ad (-1) S+bdI is subtracted from S2, and S5=S+kI-(ad (-1) S+bdI)=(1-ad (-1))S+(k-bd)I is obtained. Therefore, a difference signal S5 is formed based on the unprocessed version S2 of the received signal and the processed version S4 of the received signal corresponding to the received signal, obtained as a result of thresholding and scaling. If S3 is scaled according to the condition b>k-1, the signal elements at the injected level are scaled higher than the level difference k-1, which indicates the difference in magnitude between the injected and non-injected levels. This results in that, in the difference signal S5, at positions in the signal element sequence where the attacker has injected a signal element, the portion of the original signal S has a higher magnitude than the injected portion. In this way, again as in SIC, the original signal S can be obtained in a second and final demodulation / decoding step. In FIG. 6, the result of this final demodulation / decoding corresponding to the original signal S is denoted S6, i.e., S6=S. It should be noted that if a valid signal S6 is recovered, this also indicates a detection indication, i.e., an indication of an ongoing attack. This illustrates that the processing unit and the identification unit can actually be a single unit.
[0155] In order to counter attacks such as overshadowing and undershadowing attacks, it is also possible to pursue evasion strategies in addition to, or instead of, processing the received signals as described above with reference to Figures 3 and 6. For this purpose, an apparatus in the form of a receiver Rx may again be used, in particular in combination with a corresponding apparatus which may have the form of a transmitter Tx including a reordering unit for reordering the signals to be transmitted. A particular way to evade attacks is to reorder the signals according to a reordering operation known to the sender and receiver but unknown to the attacker.
[0156] 7 and 8 schematically and exemplarily show the case where the permutation operation is encoded in a permutation indication signal portion. In this case, the permutation indication signal portion corresponds to a permutation mask M having a length of at least one bit and determining the bit placement in the signal S. The permuted version of the signal S can be represented as P(S,M), i.e., as a function P of the original signal S and the permutation mask M. In other words, according to the illustrated embodiment, the physical (e.g., time / frequency) placement of signal elements such as symbols / bits in the transmitted signal / message S is based on the mask M, and the signal S is transmitted in permuted form and combined with the mask M. The permutation mask may be based on a codebook, in which case the permutation mask field includes an identifier indicating the permutation used.
[0157] Preferably, the mask M is added to the end of the signal. In this case, as shown, the combined transmitted signal can be expressed as S1 = P(S,M)|M. In a variation, the mask M is included at the beginning of the signal, which offers the advantage that the receiver does not need to buffer the entire signal before processing it. In another variation, one or more masks M may be added to the signal, each mask indicating a permutation to be performed only on a corresponding portion of the signal. For example, if a signal containing N symbols is transmitted, the first (not necessarily consecutive) N / 2 symbols (set) are subject to a permutation determined by a first mask, and the second (not necessarily consecutive) N / 2 symbols (set) are subject to a second permutation determined by a second mask.
[0158] Preferably, the mask M is set randomly, and preferably set separately for each signal. However, the mask M may also be set according to a predefined rule that is accessible to the transmitter and receiver but not disclosed to an attacker. The random mask M may also be stored for a predetermined period of time, and only after this period has elapsed is a new mask M randomly selected and used.
[0159] If M is sent at the end of S1 and M is set randomly, the attacker injecting the signal will not know when and how to change the bits and will have to guess how to undershadow the signal S. If M is 1 bit long, the success rate is 50%. If this is applied to multiple messages, the communication will become unstable and the receiver (Rx) will drop the communication. The attacker must overshadow the entire signal, especially including the mask M, because the receiver may notice that it failed to decode 50% of the messages. These overshadowing attacks can again be detected, for example, by analyzing measurements of the transmitted power, i.e., the overall magnitude of the received signal.
[0160] 7 shows how a transceiver Tx transmits a combined signal S1, where an attacker wants to inject an interfering signal kI into S1. As a result, a signal S2 = P(S,M)|M + kI is generated, where the interfering signal kI affects, for example, a specific symbol of S1.
[0161] By demodulation / decoding, the receiver (Rx) receives the signal S3=d from S2. (-1) P(S,M)|M+dI is then permuted by the receiver according to the received mask M, or undone by permutation, to obtain signal S4=P (-1) (S3',M) is obtained, where S3' is equal to S3 up to the last permutation mask to be removed, and P (-1) refers to the inverse function of P. As in Figure 7, S3' is d (-1) It can also be expressed as P(S,M)+dI.
[0162] S4 shows how the injected signal I is permuted or reversed based on M. This transforms the injected signal I into a simple interference signal. That is, without knowledge of the permutation mask M, an attacker cannot inject bits into the intended positions. Instead, the injected bits are permuted, which, like a normal jamming signal, can disrupt signal reception by destroying the meaning / correctness of the attacked signal. For example, a receiver may be configured to perform an integrity test, such as a cyclic redundancy check (CRC), on the received signal and drop signals that do not pass the integrity test. Due to the (reverse) permutation, signal S4 fails the CRC or other check.
[0163] The mask M may affect the signal S at different steps in the modulation / coding process. For example, it could refer to a permutation of the input bit string corresponding to the signal at the physical layer, or a permutation at a different layer in the communications stack. For example, it could refer to a permutation in the mapping of orthogonal frequency division multiplexing (OFDM) carriers or quadrature amplitude modulation (QAM) symbols used to transmit S.
[0164] At the top of Figure 8, an exemplary message S containing 8 bits is shown. The message S has been transformed by the transmitter by adding a mask bit M to the end of the message. In the example shown, if M=1 (corresponding to the middle case in Figure 8), then S1=Rotate(S)|M, where Rotate() rotates S in a circular fashion. If M=0 (corresponding to the bottom case in Figure 8), then in this example S1=S|M. Thus, in this specific example:
number
[0165] Also, as mentioned above, the reordering operation need not necessarily be encoded only in the reordering indication signal portion, such as the mask M, in which the reordered signal is transmitted in combination with the reordering indication signal portion. Additionally or alternatively, the reordering operation may be encoded in the physical parameters of the corresponding signal and / or defined according to one or more communication parameters of the network. Furthermore, the reordering operation for reordering a first transmitted signal may be encoded in the reordering indication signal portion that is transmitted in combination with a second reordered signal. Thus, for example, if a transmitter Tx transmits a first signal S to a receiver Rx and then subsequently transmits a second signal S', the mask M of S may be transmitted in combination with S', or vice versa.
[0166] In another embodiment, the transmitted signal may be transmitted on default known frequency / time resources but with a specific frequency / time shift known only to the transmitter and the responder. For example, if the allocated resources for transmitting the signal are in frequency resource blocks f0 to f1 and time resource blocks t0 to t1, the frequency resources actually used may be f0+df to f1+df. Similarly, the time resources actually used may be t0+dt to t1+dt. In this case, dt and df may be securely exchanged or agreed upon between the transmitter and the receiver, or may be securely assigned to the transmitter and the receiver. Similarly, dt and df may be variable parameters, i.e., they may change each time a signal is exchanged between the transmitter and the receiver. Here, "secure" refers to confidentiality protection, integrity protection, and / or replay protection, etc.
[0167] In another embodiment related to the above embodiment, the frequency and / or time resources (e.g., frequency resource blocks f0-f1 and frequency resource blocks t0-t1) used for signal exchange between the transmitter and receiver may be securely exchanged or agreed upon between the transmitter and receiver, or securely assigned to the transmitter and receiver.
[0168] Also, time and / or frequency shifts of signal elements may be performed by the reordering unit of the transmitter Tx and then reversed by the receiver Rx, in particular by the identification unit. These shifts can be considered as special cases of reordering. Furthermore, it should be noted that signal reordering measures are not necessarily performed all the time. Instead, it may be more efficient to configure the reordering unit to reorder the transmitted signal only if an injected signal element is identified in the received signal based on a change in the magnitude of the signal element. A corresponding notification or request may be sent from the receiver Rx to the transmitter Tx.
[0169] Specific methods of signal reordering have been described with reference to FIGS. 7 and 8. It has been recognized that, in practice, any of these methods can be applied not only to avoid attacks but also to detect them. Therefore, in addition to determining a change in the magnitude of a signal element as a basis for identifying the injection of a signal element I into the received signal, the identification unit may also be configured to determine, as a basis for doing so, the inversion of the reordering operation applied to the received signal at the time of transmission. In that case, the identification unit is preferably configured to reorder the received signal according to the inverted reordering operation and to perform an integrity check on the reordered received signal. A positive or negative result of the integrity check can be used as an indicator of an attack on the received signal, in particular an attack carried out on selected signal elements in the signal element sequence of the signal without knowledge that the signal has been reordered.
[0170] While the integrity check can be used in combination with signal reordering, particularly to detect attacks, it may also be beneficial to perform the integrity check alone. Whether or not it is performed in combination with signal reordering, the identification unit may be configured to perform the integrity check on a predetermined percentage of signals S in the network, and for a given signal S to be transmitted, whether or not to perform the integrity check on that signal may be randomly determined based on the predetermined percentage. The receiver Rx and the transmitter Tx may jointly agree on whether or not to perform the integrity check on a given signal. In that case, for a signal S on which an integrity check should be performed, an integrity indication signal portion may be transmitted in combination with the signal S, and the identification unit may be configured to check the integrity of the signal S upon reception of the signal based on the integrity indication signal portion. Similar to the reordering indication signal portion exemplified by the mask M in FIG. 8 , the integrity indication signal portion may be formed from additional signal elements, for example, bits or symbols included in the signal in addition to bits or symbols encoding the actual message conveyed by the signal. In one specific example, a transmitted combination of an integrity indication signal portion and a signal S may be formed by including the integrity indication signal portion within a corresponding signal, and upon receipt of the signal, a conclusion may be made that integrity is lacking if the magnitude of one or more signal elements of the integrity indication signal portion is determined to exceed a predetermined threshold.
[0171] The embodiments disclosed herein were discovered based on the recognition that the prior art lacked an adequate solution for 1) detecting, 2) avoiding, or 3) dealing with / recovering from interfering signals, e.g., interfering signals injected by an attacker via overshadowing and / or undershadowing attacks. Signal injection-based attacks, such as overshadowing and undershadowing attacks, in which an attacker injects signals that overshadow / undershadow a message transmitted by a transmitter so that a receiver decodes the tampered message, are gaining importance in wireless communication systems such as LTE and 5G. It is anticipated that such injection attacks may also be applicable to wireless sensing systems. These techniques may also be applicable to dealing with other interfering signals, such as those resulting from multipath or interference.
[0172] Detecting an attack may refer, for example, to detecting an attack in progress; avoiding an attack may refer, for example, to preventing an attacker from carrying out an attack; and responding to an attack may refer, for example, to being able to receive the actual message, i.e., original signal, if an attack occurs. According to disclosed embodiments, 1) the presence of an attack can be detected by monitoring traffic for persistent signals with higher signal magnitudes (higher “received signals”) across the entire signal (message) or specific elements (portions) of the signal, or by using AI / ML models; 2) the attack can be prevented from occurring (i.e., avoided) or its effects can be limited by including a mask in the signal that determines the arrangement of bits / symbols within the signal (the mask may indicate reordering); and / or 3) the desired signal can be restored (and thereby the attack can be countered) by performing successive interference cancellation (SIC) on the received signal and further using the main signal, i.e., the received signal, to remove the attacker's signal (which may be, in particular, an over-shadowed / under-shadowed signal) by scaling per signal element, or by using an AI / ML model trained to recover the interfering signal. It has been found that any one or a combination of techniques 1) to 3) can improve the security of wired and wireless communications, especially when subjected to overshadow and / or undershadow attacks.
[0173] When the above embodiments are implemented in a receiver, the receiver can perform tests to determine whether symbols or other signal elements in one or more received signals follow an expected distribution and / or whether the raw received signals contain multiple signal components. If the test results in a negative result, the receiver may trigger an action based on a configured policy. The receiver may be configured to receive a configured policy transmitted by a management entity, such as a 5G core network or a radio access network. Furthermore, the receiver may be configured to enable the policy upon receiving the policy or to enable a policy or a portion thereof (e.g., a specific rule) when a specific condition is detected. The action may be to apply an AI / ML model to remove interfering signals and / or SIC when decoding at least one of the received signals, where the decoded signal is previously scaled element-by-element. The scaling coefficients used for scaling may vary element-by-element depending on a normalized version of the received signal. If the test results in a negative result, the action triggered may be to request the transmitter to reorder the transmitted signal based on a reordering indicator, which can be thought of as a mask. For example, the mask may be attached to the transmitted signal. Alternatively, the action triggered by a negative test result could be to apply a reordering indicator (mask) that reorders the signal that the receiver itself transmits when operating as a transmitter. Also, for example, a reordering indicator that the receiver uses when operating as a transmitter could be attached to the signal. As yet another option, the action triggered by a negative test result could be to reject the received signal or to trigger an alert.
[0174] Countermeasures against attacks such as overshadowing and / or undershadowing attacks may be implemented globally or only when the presence of such an attack is actually detected. Thus, an objective of some of the above embodiments is to detect overshadowing / undershadowing attacks, for example, by monitoring changes in the received SNR between multiple different messages S. If an attacker injects signal I or several signals I,...,IM to modify (certain symbols of) S or several signals S,...,SM, the receiver receives messages affected by signal I (or I,...,IM) at higher energy levels compared to (signal elements, i.e., symbols, within) signals S (or S,...,SM) that are not affected by I. Thus, one specific approach to implementing these embodiments is to a) track the energy for each symbol from multiple received signals S, and b) calculate whether the energy levels of the signal symbols follow a uniform distribution, for example, by a statistical test (e.g., p-test). These embodiments may be performed by a receiving device if the receiving device performs the above checks / tests itself.
[0175] It will be appreciated that the techniques described in any of the above embodiments may be combined. For example, according to a first combination option, a) a receiver may be configured to measure the magnitude of signal elements of a received signal and test whether the magnitudes or time averages of the measured signal elements within and / or between received signals satisfy an expected distribution to detect the presence of an attacker. This input may also be used as input to an AI / ML model used to determine the presence of an interfering signal. If an attacker is detected in this manner, the receiver may be configured to apply successive interference cancellation or an AI / ML model, particularly in the adapted form described in FIG. 6, to recover the desired signal that has been modified by the attacker or contains a lot of noise when received. Furthermore, upon detecting an attacker, the receiver may be configured to process the received signal itself based on a predefined reordering operation and / or request the transmitter (which may be user equipment (UE)) to utilize the same reordering operation when transmitting signals to prevent the attacker from jamming signals exchanged with the transmitter.
[0176] According to a second exemplary combination option, the receiver may be configured to apply successive interference cancellation and / or an AI / ML model, particularly in the adapted form described in FIG. 6, to recover a signal of interest that has been altered by an attacker. If one or more potential signals of interest are subsequently detected, i.e., one or more signals that appear not to have been tampered with, the receiver may test whether the magnitudes of the measured signal elements of the one or more potential signals of interest, or their time averages, within and / or across the one or more received signals satisfy an expected distribution to confirm whether the received signals have indeed not been tampered with or are in fact under attack. Furthermore, upon detecting an attacker, the receiver may be configured to process the received signals itself based on a predefined reordering operation and / or request the transmitter (which may be user equipment (UE)) to utilize the same reordering operation when transmitting signals to prevent the attacker from jamming signals exchanged with the transmitter.
[0177] In certain embodiments, a system is presented in the form of one or more UEs, where the device acting as a receiver is configured to collect information or statistics about the received signal S and transmit them to an administrative authority, e.g., a base station or network function within the core network, thereby enabling the system to determine the presence of an attacker. The collected relevant information may include any raw or processed parameters relevant to the embodiments disclosed herein, such as per-symbol signal strength or results of statistical tests related to the uniformity of energy of received signal symbols. The received information may be used by the network / core network to provide the UE with a specific configuration that determines the type of technique to apply to address the interfering signal (e.g., apply a specific permutation or use a specific AI / ML model tailored to a specific type of interference).
[0178] Again, it should be noted that any of the above actions that the receiver may take in response to a negative test result, testing whether signal elements in one or more received signals follow an expected distribution, can be performed independently of the test. In other words, an action may instead always be performed. Tests that may correspond to the identification of injected signal elements may only be added optionally. The choice of whether to perform an action independently or in response to a test, i.e., whether an attack is detected or not, can be seen as a trade-off between security and efficiency. This required trade-off may be specified in a policy that may be configured for the respective device. This test may also refer to a test of whether the received signal contains an interfering signal (not necessarily malicious).
[0179] Additionally, although the above embodiments are described with a focus on overshadow and undershadow attacks, these embodiments are equally applicable as a countermeasure against any other attack that functions similarly to overshadow and undershadow attacks, particularly in the context of wireless communication or sensing, for example, based on the injection of signal elements using the capture effect.
[0180] The above embodiments may be applicable to various types of multiple access, such as Orthogonal Frequency Division Multiple Access (OFDMA), Rate Division Multiple Access (RSMA), or Orthogonal Angular Momentum (OAM) systems.
[0181] The above embodiments may be applicable to various types of networks, such as cellular systems, Wi-Fi networks, ultra-wideband systems, etc. The above embodiments may also be applicable to various kinds of network infrastructures, such as terrestrial and non-terrestrial based networks that use, for example, smart repeaters or reflective intelligent surfaces for range extension.
[0182] Other variations of the disclosed embodiments can be understood and effected by those skilled in the art in practicing the claimed invention, from a study of the drawings, the disclosure, and the appended claims.
[0183] In the claims, the terms "comprise" and "include" do not exclude other elements or steps, and the singular form of an element does not exclude a plurality. Also, the phrase "at least one" followed by a phrase including one or more elements or features is to be understood in its inclusive disjunction sense. For example, the phrase "at least one of A, B, and C" is to be understood as "A and / or B and / or C."
[0184] A single unit or device may fulfill the functions of several items recited in the claims. The mere fact that several means are recited in mutually different dependent claims does not indicate that a combination of these means cannot be advantageously used. The steps performed by one or more units or devices, such as measuring the magnitude of a signal element, identifying the injection of a signal element, further processing the received signal, or sorting the transmitted signal, may also be performed by any number of other units or devices. These steps may be implemented as program code means of a computer program and / or as dedicated hardware. However, these steps, and any methods resulting from any combination thereof, are also disclosed herein, regardless of how they are implemented.
[0185] The computer program may be stored and / or distributed on a suitable medium, such as an optical storage medium or a solid-state medium supplied together with or as part of other hardware, or may be distributed in other forms, such as via the Internet or other wired or wireless telecommunications systems.
[0186] Any reference signs in the claims should not be construed as limiting the scope.
[0187] The present invention relates to an apparatus for enhancing signal integrity in a signaling network, where each signal includes a sequence of one or more signal elements. The apparatus includes an identification unit configured to identify injection of a signal element into a received signal based on at least one of a) a change in the magnitude of the signal element and b) an inversion of a reordering operation applied to the received signal at the time of transmission. This allows reliable identification of injection of a signal element due to the capture effect. In particular, it is possible to identify not only overshadowing attacks but also undershadowing attacks or other injection attacks or interference. By processing the received signal based on the injection / interference of the identified signal element, signal integrity in the network can be enhanced.
Claims
1. 1. An apparatus for increasing signal integrity in a signaling network, each signal comprising a sequence of one or more signal elements, the apparatus comprising: an identification unit for identifying injection or interference of a signal element into the received signal based on at least one of: a) a change in magnitude of the signal elements; b) a reversal of a reordering operation applied to the received signal at the time of transmission; c) a fingerprint of the signal; d) a location of the transmitter; and e) an AI / ML (artificial intelligence / machine learning) model.
2. The apparatus of claim 1 , further comprising a processing unit for processing the received signal based on the injection or interference of the identified signal element.
3. 3. The apparatus of claim 2, wherein the processing of the received signal includes scaling the signal element of the received signal depending on whether the signal element is identified as an injected signal element.
4. 4. The apparatus of claim 2 or 3, wherein the processing of the received signal includes recovering the interfered signal using an AI / ML model.
5. 4. The apparatus of claim 2, wherein the processing of the received signal comprises thresholding the signal elements to predefined signal element levels, the predefined signal element levels including at least an injected level indicating a magnitude of an injected signal element and a non-injected level indicating a magnitude of a non-injected signal element, and the signal elements are scaled according to their respective signal element levels.
6. 6. The apparatus of claim 5, wherein the processing includes forming a difference signal based on an unprocessed version of the received signal and a processed version of the received signal corresponding to the received signal resulting from the thresholding and the scaling, and the scaling includes scaling the signal component of the injection level to be higher than a level difference, the level difference indicating a difference in magnitude between the injection level and the non-injection level.
7. 7. The apparatus of claim 1, wherein the identification unit detects changes in the magnitude of signal elements in at least one of: a) a sequence of signal elements of the received signal; and b) a signal element sequence comprising signal elements of the received signal and one or more corresponding signal elements of a previous repetition of the received signal, in order to identify injection or interference of signal elements into the received signal based on changes in the magnitude of the signal elements.
8. 8. The apparatus of claim 1, wherein the identification unit reorders the received signal according to the inverted reordering operation and performs an integrity check on the reordered received signal to identify injection or interference of signal elements into the received signal based on an inversion of the reordering operation applied to the received signal at the time of transmission.
9. 9. The apparatus of claim 1, wherein the identification unit performs an integrity check on a predetermined percentage of signals in the network, and for a given signal to be transmitted, it is randomly decided based on the predetermined percentage whether to perform an integrity check on the given signal.
10. 10. The apparatus of claim 9, wherein for any signal on which an integrity check is to be performed, an integrity indication signal portion is transmitted in combination with the signal, and the identification unit checks the integrity of the signal upon receipt based on the integrity indication signal portion.
11. 11. The apparatus of claim 10, wherein the transmitted combination of the integrity indication signal portion and the signal is formed by including the integrity indication signal portion within the corresponding signal, and wherein, upon receipt of the signal, a lack of integrity is concluded if the magnitude of one or more signal elements of the integrity indication signal portion is determined to exceed a predetermined threshold.
12. 1. A system for enhancing signal integrity in a signaling network, the system comprising: a) a device according to any one of claims 1 to 11 as a receiving device for the signals in the network, and / or b) A system comprising a transmitting device for the signals in the network, the transmitting device including a reordering unit for reordering the signals to be transmitted according to a reordering operation.
13. a) the reordering operation is encoded into a reordering indication signal portion, and the reordered signal is transmitted in combination with the reordering indication signal portion; b) the permutation operations are encoded into corresponding physical parameters of the signals; c) the reordering operation of the first signal to be transmitted is encoded in a reordering indicator signal portion that is transmitted in combination with the second reordered signal; and / or 13. The system of claim 12, wherein d) the reordering operation is defined as a function of one or more communication parameters of the network.
14. 14. The system of claim 12 or 13, wherein the reordering unit reorders the signal to be transmitted only if an injected signal element is identified in the received signal based on a change in the magnitude of the signal element.
15. 1. A method for increasing signal integrity in a signaling network, each signal comprising a sequence of one or more signal elements, the method comprising identifying injection of a signal element into a received signal based on at least one of: a) a change in magnitude of the signal element; b) a reversal of a reordering operation applied to the received signal at the time of transmission; c) a fingerprint of the signal; d) a location of the transmitter; and e) an AI / ML (artificial intelligence / machine learning) model.
16. A computer program for increasing signal integrity in a signaling network, said computer program comprising instructions for causing an apparatus according to any one of claims 1 to 13 to perform the method according to claim 15.