Systems and methods for providing security during digital communication

By encrypting modulation symbols into an orthogonal transform space to create white noise-like waveforms, the method addresses the challenge of on-the-fly attacks in dynamic channels, ensuring secure communication with low computational costs and high security in environments like underwater acoustic channels.

WO2025222270A1PCT designated stage Publication Date: 2025-10-30MARECOMMS INC
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/CA2024/050546
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-04-25
Publication Date
2025-10-30

AI Technical Summary

Technical Problem

Existing data encryption methods fail to provide effective physical layer security against on-the-fly attacks in dynamic communication channels, particularly in triply-dispersive environments like underwater acoustic channels, where time-varying propagation introduces Doppler shift and multipath propagation, rendering channel steering-based encryption ineffective.

Method used

A method and system that encrypts modulation symbols by transforming them to an orthogonal transform space, disguising phase and amplitude information, and generating a transmit waveform that appears as white noise, making spectral analysis unintelligible to interceptors, using look-up tables or algorithms defined by the modulation scheme.

Benefits of technology

Provides robust physical layer security by disguising the modulation format and spectral content, preventing unauthorized access even in highly dynamic channels, with computational costs lower than key-based obfuscation methods, and achieving near-zero bit error rates in challenging environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CA2024050546_30102025_PF_FP_ABST
    Figure CA2024050546_30102025_PF_FP_ABST
Patent Text Reader

Abstract

A system and a method for physical layer security during digital communication are provided. The method comprises: assigning, by a modulator, received source data to a block of modulation symbols carrying the source data according to a modulation scheme, the block of modulation symbols including multiple discrete modulation symbols; mapping the block of modulation symbols to a block of encryption symbols including multiple encryption symbols, the mapping including encryption of at least a phase and / or an amplitude information associated with the modulation symbols by transforming the modulation symbols to an orthogonal transform space; generating a transmit waveform for the block of encryption symbols, the transmit waveform including a sequence of transmit samples corresponding to the multiple encryption symbols; and transmitting the generated transmit waveform.
Need to check novelty before this filing date? Find Prior Art

Description

TITLE: SYSTEMS AND METHODS FOR PROVIDING SECURITY DURING DIGITAL COMMUNICATIONFIELD

[0001] Various embodiments are described herein that generally relate to systems and methods for providing security during digital communication, and in particular to systems and methods for providing physical layer security during digital communication.BACKGROUND

[0002] Digital communication includes transmitting and receiving over any suitable digital communication channel. The communication channel may include, for example, an underwater communication channel, a terrestrial channel, a wired channel, a wireless channel or a satellite channel. The transmitted data may include confidential or sensitive data that must be protected from potential attacks or interception during communication. For example, a third party may attempt to intercept confidential data being communicated between a transmitter and an intended receiver. Therefore, there is a need for data encryption / security systems and methods during digital communication.

[0003] Systems and methods may be needed to provide data encryption / security for both “at-rest” and “on-the-fly” scenarios. “At-rest” data encryption / security systems and methods may protect the content of a transmitted message source but may not protect the transmitted waveform against potential attacks / interception. In some applications, data encryption / security systems and methods may be needed to provide encryption / security against “on-the-fly” attacks against the transmitted waveform during the course of transmission (e.g., by encrypting / disguising the power spectral density, modulation constellation of the transmitted waveform etc.).SUMMARY OF VARIOUS EMBODIMENTS

[0004] In a broad aspect, in accordance with the teachings herein, there is provided at least one embodiment of a method of providing physical layer security during digital communication. The method comprises: assigning, by a modulator,received source data to a block of modulation symbols carrying the source data according to a modulation scheme, the block of modulation symbols including multiple discrete modulation symbols; mapping the block of modulation symbols to a block of encryption symbols including multiple encryption symbols, the mapping including encryption of at least a phase and / or an amplitude information associated with the modulation symbols by transforming the modulation symbols to an orthogonal transform space; generating a transmit waveform for the block of encryption symbols, the transmit waveform including a sequence of transmit samples corresponding to the multiple encryption symbols; and transmitting the generated transmit waveform.

[0005] In at least one embodiment, the mapping may further include encrypting a relative position information of each of the modulation symbols with reference to other modulation symbols in the block of modulation symbols.

[0006] In at least one embodiment, the block of modulation symbols may be mapped to the block of encryption symbols using a transmit look-up table or a transmit mapping algorithm.

[0007] In at least one embodiment, the transmit look-up table or the transmit mapping algorithm may be defined for the modulation scheme used by the modulator.

[0008] In at least one embodiment, the modulation scheme may include, but is not limited, to phase shift keying (PSK), quadrature amplitude modulation (QAM), Continuous Phase Modulation (CPM), Continuous Phase Shift Keying (CPSK), Minimum Shift Keying (MSK), Gaussian Minimum Shift Keying (GMSK) or frequency shift keying (FSK) modulation.

[0009] In at least one embodiment, the mapping may include pre-equalizing non-uniform amplitude levels associated with the multiple modulation symbols.

[0010] In at least one embodiment, generating the transmit waveform may include passing the block of encryption symbols through an interpolation filter during digital-to-analog conversion.

[0011] In at least one embodiment, generating the transmit waveform may include passing the block of encryption symbols through a single-carrier interface, a multi-carrier interface, or a spread-spectrum interface.

[0012] In at least one embodiment, the method may further comprise: receiving the transmitted waveform at a receiving unit; recovering the block of encryption symbols from the received waveform; reverse-mapping the recovered block of encryption symbols to recover the block of modulation symbols; and demodulating the recovered block of modulation symbols to recover the source data.

[0013] In at least one embodiment, the reverse-mapping may be performed using a receive look-up table or a receive mapping algorithm that is defined for the modulation scheme used by the modulator.

[0014] In at least one embodiment, the generated transmit waveform may be transmitted using acoustic waves, electromagnetic waves or optical waves.

[0015] In at least one embodiment, the generated transmit waveform may be transmitted via an underwater communication channel, a terrestrial channel, a wired channel, a wireless channel or a satellite channel.

[0016] In another broad aspect, in accordance with the teachings herein, there is provided a system. The system provides physical layer security during digital communication. The system comprises a modulator, an encryptor, and a transmitter. The modulator is configured to assign received source data to a block of modulation symbols carrying the source data according to a modulation scheme, the block of modulation symbols including multiple discrete modulation symbols. The encryptor is configured to map the block of modulation symbols to a block of encryption symbols to encrypt at least a phase and / or an amplitude information associated with the modulation symbols by transforming the modulation symbols to an orthogonal transform space, the block of encryption symbols including multiple encryption symbols. The transmitter is configured to generate a transmit waveform for the block of encryption symbols, the transmit waveform including a sequence of transmit samples corresponding to the multiple encryption symbols; and transmit the generated transmit waveform.

[0017] In at least one embodiment, the encryptor may be further configured to map the block of modulation symbols to the block of encryption symbols to encrypt a relative position information of each of the modulation symbols with reference to other modulation symbols in the block of modulation symbols.

[0018] In at least one embodiment, the encryptor may be configured to map the block of modulation symbols to the block of encryption symbols using a transmit look-up table or a transmit mapping algorithm.

[0019] In at least one embodiment, the transmit look-up table or the transmit mapping algorithm may be defined for the modulation scheme used by the modulator.

[0020] In at least one embodiment, the modulation scheme used by the system may include phase shift keying (PSK), quadrature amplitude modulation (QAM), Continuous Phase Modulation (CPM), Continuous Phase Shift Keying (CPSK), Minimum Shift Keying (MSK), Gaussian Minimum Shift Keying (GMSK) or frequency shift keying (FSK) modulation.

[0021] In at least one embodiment, the encryptor may be configured to preequalize non-uniform amplitude levels associated with the multiple modulation symbols while mapping the block of modulation symbols to the block of encryption symbols.

[0022] In at least one embodiment, the transmitter may be configured to generate the transmit waveform by passing the block of encryption symbols through an interpolation filter for digital-to-analog conversion.

[0023] In at least one embodiment, the transmitter may be configured to generate the transmit waveform by passing the block of encryption symbols through a single-carrier interface, a multi-carrier interface, or a spread-spectrum interface.

[0024] In at least one embodiment, the system may further comprise a receiver, a decryptor, and a demodulator. The receiver may be configured to receive the transmitted waveform; and recover the block of encryption symbols from the received waveform. The decryptor may be configured to reverse-map the block of recovered encryption symbols to recover the block of modulation symbols. Thedemodulator may be configured to demodulate the recovered block of modulation symbols to recover the source data.

[0025] In at least one embodiment, the decryptor may be configured to reversemap the block of recovered encryption symbols using a receive look-up table or a receive mapping algorithm that is defined for the modulation scheme used by the modulator.

[0026] In at least one embodiment, the transmitter may be configured to transmit the generated transmit waveform using acoustic waves, electromagnetic waves or optical waves.

[0027] In at least one embodiment, the transmitter may be configured to transmit the generated transmit waveform via an underwater communication channel, a terrestrial channel, a wired channel, a wireless channel or a satellite channel.

[0028] Other features and advantages of the present application will become apparent from the following detailed description taken together with the accompanying drawings. It should be understood, however, that the detailed description and the specific examples, while indicating preferred embodiments of the application, are given by way of illustration only, since various changes and modifications within the spirit and scope of the application will become apparent to those skilled in the art from this detailed description.BRIEF DESCRIPTION OF THE DRAWINGS

[0029] For a better understanding of the various embodiments described herein, and to show more clearly how these various embodiments may be carried into effect, reference will be made, by way of example, to the accompanying drawings which show at least one example embodiment, and which are now described. The drawings are not intended to limit the scope of the teachings described herein.

[0030] FIG. 1 is a graph that provides an instantaneous snapshot of the timevarying Channel Frequency Response (CFR) measured for an example underwater acoustic channel in Halifax Harbor, Canada.

[0031] FIGS. 2A and 2B are graphs showing a Time-Delay profile and a Doppler- Delay profile respectively for the example underwater acoustic channel of FIG. 1 .

[0032] FIG. 3 is a block diagram showing a system for providing physical layer security during digital communication, according to at least one example embodiment of this disclosure.

[0033] FIG. 4A is a graph showing an example transmit signal constellation for modulation symbols without encryption.

[0034] FIG. 4B is a graph showing an example transmit signal constellation for encryption symbols generated by the system of FIG. 3.

[0035] FIG. 5 is a graph showing the normalized power spectral density for an example transmitted waveform by the system of FIG. 3.

[0036] FIG. 6 is a graph showing the normalized phase spectrum for an example transmitted waveform by the system of FIG. 3.

[0037] FIG. 7 is a graph showing example spectral efficiency performance of the system of FIG. 3 using an underwater acoustic communication channel in Halifax Harbor.

[0038] FIG. 8 is a flowchart showing a method of providing physical layer security during digital communication, in accordance with at least one example embodiment of this disclosure.

[0039] Further aspects and features of the example embodiments described herein will appear from the following description taken together with the accompanying drawings.DETAILED DESCRIPTION OF THE EMBODIMENTS

[0040] Various embodiments in accordance with the teachings herein will be described below to provide an example of at least one embodiment of the claimed subject matter. No embodiment described herein limits any claimed subject matter. The claimed subject matter is not limited to devices, systems or methods having all of the features of any one of the devices, systems or methods described below or to features common to multiple or all of the devices, systems or methods described herein. It is possible that there may be a device, system or method described herein that is not an embodiment of any claimed subject matter. Any subject matter that is described herein that is not claimed in this document may be the subject matter ofanother protective instrument, for example, a continuing patent application, and the applicants, inventors or owners do not intend to abandon, disclaim or dedicate to the public any such subject matter by its disclosure in this document.

[0041] It will be appreciated that for simplicity and clarity of illustration, where considered appropriate, reference numerals may be repeated among the figures to indicate corresponding or analogous elements. In addition, numerous specific details are set forth in order to provide a thorough understanding of the embodiments described herein. However, it will be understood by those of ordinary skill in the art that the embodiments described herein may be practiced without these specific details. In other instances, well-known methods, procedures and components have not been described in detail so as not to obscure the embodiments described herein. Also, the description is not to be considered as limiting the scope of the embodiments described herein.

[0042] It should also be noted that the terms “coupled” or “coupling” as used herein can have several different meanings depending in the context in which these terms are used. For example, the terms coupled or coupling can have a mechanical or electrical connotation. For example, as used herein, the terms coupled or coupling can indicate that two elements or devices can be directly connected to one another or connected to one another through one or more intermediate elements or devices via an electrical signal, electrical connection, or a mechanical element, depending on the particular context.

[0043] It should also be noted that, as used herein, the wording “and / or” is intended to represent an inclusive-or. That is, “X and / or Y” is intended to mean X orY or both, for example. As a further example, “X, Y, and / or Z” is intended to mean X or Y or Z or any operative combination thereof.

[0044] It should be noted that terms of degree such as “substantially”, “about” and “approximately” as used herein mean a reasonable amount of deviation of the modified term such that the end result is not significantly changed. These terms of degree may also be construed as including a deviation of the modified term, such as by 1 %, 2%, 5% or 10%, for example, if this deviation does not negate the meaning of the term it modifies.

[0045] Furthermore, the recitation of numerical ranges by endpoints herein includes all numbers and fractions subsumed within that range (e.g., 1 to 5 includes 1 , 1.5, 2, 2.75, 3, 3.90, 4, and 5). It is also to be understood that all numbers and fractions thereof are presumed to be modified by the term “about” which means a variation of up to a certain amount of the number to which reference is being made if the end result is not significantly changed, such as 1 %, 2%, 5%, or 10%, for example.

[0046] At least a portion of the example embodiments of the systems or methods described in accordance with the teachings herein may be implemented as a combination of hardware or software. For example, a portion of the embodiments described herein may be implemented, at least in part, by using one or more computer programs, executing on one or more programmable devices comprising at least one processing element, and at least one data storage element (including volatile and non-volatile memory). These devices may also have at least one input device (e.g., a touchscreen, and the like) and at least one output device (e.g., a display screen, a printer, a wireless radio, and the like) depending on the nature of the device.

[0047] It should also be noted that some elements that are used to implement at least part of the embodiments described herein may be implemented via software that is written in a high-level procedural language such as object-oriented programming. The program code may be written in JAVA, PYTHON, C, C++, MATLAB, JavaScript or any other suitable programming language and may comprise modules or classes, as is known to those skilled in object-oriented programming. Alternatively, or in addition thereto, some of these elements implemented via software may be written in assembly language, machine language, or firmware as needed.

[0048] At least some of the software programs used to implement at least one of the embodiments described herein may be stored on a storage medium (e.g., a computer readable medium such as, but not limited to, ROM, flash memory, magnetic disk, optical disc) or a device that is readable by a programmable device. The software program code, when read by the programmable device, configuresthe programmable device to operate in a new, specific and predefined manner in order to perform at least one of the methods described herein.

[0049] Furthermore, at least some of the programs associated with the systems and methods of the embodiments described herein may be capable of being distributed in a computer program product comprising a computer readable medium that bears computer usable instructions, such as program code, for one or more processors. The program code may be preinstalled and embedded during manufacture and / or may be later installed as an update for an already deployed computing system. The medium may be provided in various forms, including non- transitory forms such as, but not limited to, one or more diskettes, compact disks, DVD, tapes, chips, and magnetic, optical and electronic storage. In alternative embodiments, the medium may be transitory in nature such as, but not limited to, wire-line transmissions, satellite transmissions, internet transmissions (e.g., downloads), media, digital and analog signals, and the like. The computer useable instructions may also be in various formats, including compiled and non-compiled code.

[0050] Some data encryption methods may protect the content of a message source but may not protect the transmitted waveform against potential attacks on- the-fly. The disclosed systems and methods can protect both - the message content at rest and the transmitted waveform against potential attacks on-the-fly. The disclosed systems and methods can achieve this by ensuring that the transmitted waveforms do not reveal useful information to facilitate a potential attack on the modulation format, constellation, or the spectral content of communication, thereby providing physical layer security.

[0051] Some data encryption methods may focus on the exploitation of channel information to steer transmissions toward an authorized receiver and to leave all unauthorized locations in null or shadow zones. However, this requires the channel to exhibit a stable, time-invariant behavior, which is often not the case in highly dynamic propagation environments that render the time-invariance assumption invalid.

[0052] Time-varying propagation channels introduce Doppler shift, Doppler spread or a combination of both to a transmitted signal. A wireless communication channel may also exhibit multipath propagation, which leads to frequencyselectivity in addition to time-selectivity. Additionally, spatial selectivity may present itself in highly dynamic channels, which means that the signal quality may vastly differ at various measured locations in space. Such communication media that exhibit time, frequency and spatial selectivity are termed “triply-dispersive”. Examples of triply-dispersive communication media include underwater acoustic communication channels, and especially, shallow-water, horizontal transmission environments.

[0053] An acoustic signal transmitted under the water, especially in a shallowwater environment, may bounce off from the ocean surface and / or bottom, leading to multipath propagation, which can result in distortions due to frequency-selectivity. The speed of sound is nearly 200,000 smallerthan the speed of light, and the ocean propagation environment is dynamic, introducing random time variations, even if the transmit and receive platforms are fixed. This introduces Doppler spread. If one or both of the transmit and receive platforms are moving, then Doppler shift is also present, in addition to the Doppler spread. Such Doppler spread and / or shift cannot be modeled as a simple carrier frequency offset and such channels cannot be assumed time-invariant. Water column inhomogeneities result in spatial selectivity.

[0054] Reference is now made to FIG. 1 showing the frequency-selectivity displayed by an example communication channel. FIG. 1 is a graph 100 that provides an example instantaneous snapshot of the time-varying Channel Frequency Response (CFR) measured during underwater acoustic data transmissions in Halifax Harbor, Canada. Halifax Harbor can be considered to be an extreme shallow-water environment where the water depth changes between 8- 20 m between transmit and receive locations, and the communication range is 2 Km from one shore of the harbor to the other. The transmitted signal bounces off from the bottom and the surface of the ocean, pertaining to the multipath response, which manifests itself in terms of severe frequency-selectivity as exemplified in FIG. 1 . As shown in FIG. 1 , fades greater than 30 dB can be common in the CFR.

[0055] Reference is now made to FIGS. 2A and 2B showing a Time-Delay profile 200 and a Doppler-Delay profile 250 respectively for the example Halifax Harbor underwater acoustic channel described herein above with reference to FIG. 1. FIGS. 2A and 2B illustrate the time-varying nature of the multipath for the example communication channel. As shown in FIG. 2A, multipath arrivals can have significant time-variations (indicated by the grey-scale variations) due to timevarying amplitude and a clear drift from left to the right, indicating mobility. The Doppler-Delay profile 250 quantifies the Doppler spectrum at each signal arrival path. A random Doppler spectrum is observed, which is different for each arrival. In the illustrated example, the Doppler drift is caused simply by the surface variations, and not due to platform mobility.

[0056] FIGS. 1 , 2A and 2B illustrate that the analyzed example channel is timevarying with a significant frequency-selectivity even in the absence of platform mobility. The data plotted in FIGS. 1 , 2A and 2B are obtained from to a single sensor. Substantially different plots (not shown here for conciseness) are obtained for other sensors that are placed in various water depths in the same example channel, indicating spatial variability.

[0057] As shown in FIGS. 1 , 2A and 2B, it can be challenging to achieve reliable, broadband and secure communications in time, frequency and spatially dispersive channels. Steering signals towards an authorized receiver to achieve physical layer security in such dispersive channels can be ineffective as the channel undergoes substantial time variability. Consequently, the channel information that the transmitter would exploit for steering-based encryption would have already been obsolete by the time the signal is received at the receiver. From a practical standpoint, in many subsea use cases, a mobile platform (e.g., an Autonomous Underwater Vehicle (AUV)) may be used for inspection or reconnaissance tasks. AUVs can move at velocities ranging from 0.5 knots to 7 or 10 knots. Therefore, the channel steering based physical layer encryption may not be useful for an AUV attempting secure communication with other AUV(s), a support vessel, a fixed node and / or a submarine.

[0058] Some digital communication systems and methods use data obfuscation based on a secret key to enable secure communication and provide physical layer security. However, key-based obfuscation systems and methods may exhibit shortcomings including, for example, potential weaknesses that may occur during key exchange. The key-based obfuscation systems and methods may also be unable to protect the spectral content of a transmitted waveform, because simple spectral analysis can reveal useful information about the nature of modulation used, thereby facilitating potential attack / interception.

[0059] At least one of the disclosed systems and methods herein can enable powerful physical layer security by providing transmitted waveforms that are resilient towards potential jamming or obstruction attacks, by efficiently and non- trivially disguising the spectral content, the modulation format and the underlying constellation used. At least one of the disclosed systems and methods can enable physical layer security in all digital communication channels (e.g., terrestrial, underwater, wired, wireless, satellite channels etc.) including time, frequency, and / or spatially selective channels.

[0060] Reference is now made to FIG. 3. FIG. 3 is a block diagram showing a system 300 for providing physical layer security during digital communication. System 300 includes a transmitting unit 304 and a receiving unit 312. Transmitting unit 304 and receiving unit 312 can communicate using a channel 308.

[0061] Channel 308 can be any suitable communication channel. For example, channel 308 may be an underwater communication channel, a terrestrial channel, a wired channel, a wireless channel or a satellite channel.

[0062] Transmitting unit 304 may include any suitable combination of subcomponents. In the illustrated embodiment, transmitting unit 304 includes a data source 316, a channel encoder 320, an interleaver 324, a modulator 328, an encryptor 332, and a transmitter 336. In other embodiments, transmitting unit 304 may include a different combination of sub-components. For example, transmitting unit 304 may not include an interleaver.

[0063] Data source 316 may have any suitable design that provides the data to be communicated. For example, data source 316 may include a communicationinterface to an external device or channel to receive input data for transmission. In some examples, data source 316 may include a memory device that is configured to store data that can be transmitted by transmitting unit 304. In some embodiments, data source 316 may provide compressed data for transmission. In other embodiments, data source 316 may provide uncompressed data.

[0064] Channel encoder 320 may have any suitable design for encoding data provided by data source 316. Channel encoder 320 may include any combination of circuits / hardware and program instructions to encode the source data to add redundancy for protection against uniformly distributed errors on channel 308.

[0065] Interleaver 324 may have any suitable design for interleaving encoded data from channel encoder 320. Interleaver 324 may include any combination of circuits / hardware and program instructions to rearrange or spread out data bits / symbols in the encoded data for protection against burst errors.

[0066] Modulator 328 may have any suitable design for assigning received data to a block of modulation symbols carrying the received data according to a modulation scheme. In the illustrated example, the data received by modulator 328 includes source data that has been encoded by channel encoder 320 and interleaved by interleaver 324. In other examples, the data received by modulator 328 may be different based on the particular combination of sub-components of transmitting unit 304.

[0067] Modulator 328 may assign a received data bit / symbol or a group of received data bit / symbols to a block of modulation symbols. The block of modulation symbols may include multiple discrete modulation symbols. The modulation symbols may be based on the modulation scheme used by modulator 328. Modulator 328 may use any suitable modulation scheme. For example, the modulation scheme may include phase shift keying (PSK), quadrature amplitude modulation (QAM), Continuous Phase Modulation (CPM), Continuous Phase Shift Keying (CPSK), Minimum Shift Keying (MSK), Gaussian Minimum Shift Keying (GMSK) or frequency shift keying (FSK) modulation. Any suitable modulation order may be used for the modulation scheme. For example, the modulation order may be binary, quaternary, 8-ary, or any higher order.

[0068] Encryptor 332 may have any suitable design for mapping the block of modulation symbols to a block of encryption symbols. The block of encryption symbols may include multiple encryption symbols. For example, encryptor 332 may map a block of N discrete modulation symbols received from modulator 328 (e.g., s = ...,s„_w+1]) onto a block of N discrete encryption symbols (e.g., a =[an,a„_i, ...,an-jv+i]) where N is an integer where N may vary from about 10 to several hundreds of thousands.

[0069] The mapping can transform the modulation symbols to an orthogonal transform space which is a space that is spanned by set of basis functions that form an orthonormal set. The basis functions of the transform space can be orthogonal to the basis functions of the Fourier Transform (FT) space resulting in a non-trivial transform space that does not overlap with the FT space. The Fourier Transform is given as one example and the orthogonal transform space can be other spaces that are spanned by basis functions that are orthogonal to each other. Therefore, a spectral analysis of a transmitted waveform for the block of encryption symbols may display a white noise-like spectral content and not provide any intelligible information (e.g., to a third-party attempting to attack / intercept the transmitted waveform).

[0070] Encryptor 332 may use any suitable method for mapping the block of modulation symbols to the block of encryption symbols. In some embodiments, encryptor 332 may include a transmit look-up table. Encryptor 332 may use the transmit look-up table to look up an encryption symbol corresponding to each modulation symbol. In other embodiments, encryptor 332 may not include a transmit look-up table. For example, encryptor 332 may include any suitable processor that implements a transmit mapping algorithm to map the block of modulation symbols to the block of encryption symbols. In either case, the look-up table or transmit mapping algorithm are reversible in that the decryptor 360 may apply an inverse look-up table or inverse mapping algorithm to recover the modulation symbols at the receiver 312.

[0071] Encryptor 332 may change at least phase and / or amplitude information associated with the modulation symbols during the mapping. For example,encryptor 332 may encrypt the modulation symbols by changing the phase and / or amplitude of each of the samples generated by modulator 328. In some embodiments, encryptor 332 may further change a relative position information of each of the modulation symbols (e.g., sn) with reference to other modulation symbols (e.g.,... , s„_w+1) in the block of modulation symbols s.

[0072] In some embodiments, the mapping may be based on the modulation scheme used by modulator 328 and / or a carrier scheme used by transmitter 336. For example, the transmit look-up table or the transmit mapping algorithm may be defined for the specific modulation scheme used by modulator 328. Modulator 328 may use, for example, a QAM scheme where the samples generated by modulator 328 have non-uniform amplitude levels. The mapping implemented by encryptor 332 can include pre-equalizing the amplitude levels of the samples from modulator 328 to enable uniform transmit amplitude levels associated with the encryption symbols. The uniform transmit amplitude levels can enable transmitting unit 304 to encrypt / disguise constellation information associated with modulator 328 in the transmitted waveform.

[0073] As another example, the transmit look-up table or the transmit mapping algorithm may be defined for the specific carrier scheme used by transmitter 336. Transmitter 336 may use, for example, a single-carrier or a multi-carrier scheme and the mapping implemented by encryptor 332 may include changing relative position information of the modulation symbols. For a single-carrier scheme, the mapping can change the order in which the samples from modulator 328 are transmitted in the time-domain, rendering a time series analysis ineffective for a potential interceptor / eavesdropper. In a multi-carrier scheme, the carrier carries the transmitted symbols in discrete frequency bins. The mapping can change the relative position of the frequency bins, rendering a spectral analysis of the frequency bins unintelligible to a potential interceptor / eavesdropper.

[0074] Transmitter 336 may have any suitable design for generating a transmit waveform for the block of encryption symbols generated by encryptor 332. The transmit waveform may include a sequence of transmit samples corresponding to the multiple encryption symbols included in the block of encryption symbols. In theillustrated embodiment, transmitter 336 includes carrier interface & digital-to-analog converter (DAC) 340, and up-converter & amplifier 344.

[0075] Carrier interface & DAC 340 may generate a baseband transmit waveform z(t, a) based on encryption symbols anreceived from encryptor 332. Carrier interface & DAC 340 may include any suitable carrier interface and digital- to-analog converter to generate the baseband transmit waveform. For example, carrier interface & DAC 340 may include a single-carrier interface, a multi-carrier interface or a spread-spectrum interface. This can enable any suitable carrier scheme to be implemented for the transmitted waveform. For example, the carrier scheme may be selected based on application or use case requirements and the disclosed system / encryption is not limited to any specific carrier scheme. In some embodiments, carrier interface & DAC 340 may include an interpolation filter for digital-to-analog conversion.

[0076] Up-converter & amplifier 344 may have any suitable design to up-convert and amplify the baseband transmit waveform generated by carrier interface & DAC 340. The up-converted and amplified waveform may be transmitted via channel 308. The waveform may be transmitted using, for example, acoustic waves, electromagnetic waves or optical waves.

[0077] The transmitted waveform can be received at receiving unit 312. Receiving unit 312 can have any suitable design to receive the transmitted waveform and recover the source data. The specific design of receiving unit 312 may be based on the encoding scheme, modulation scheme, encryption scheme, and / or carrier scheme implemented at transmitting unit 304.

[0078] Receiving unit 312 may include any suitable combination of subcomponents. In the illustrated example embodiment, receiving unit 312 includes a receiver 348, a decryptor 360, a demodulator 364, a de-interleaver 368, a channel decoder 372, and a sink 376. In other embodiments, receiving unit 312 may include a different combination of sub-components. The combination of sub-components may correspond to the combination of sub-components of transmitting unit 304. For example, receiving unit 312 may not include a de-interleaver if transmitting unit 304 does not include an interleaver.

[0079] Receiver 348 may have any suitable design for recovering the block of encryption symbols from the received waveform. In the illustrated example embodiment, receiver 348 includes amplifier s down-converter 352, and analog-to- digital converter (ADC) 356. Amplifiers down-converter 352 may have any suitable design to amplify the received waveform and down-convert the received waveform to a baseband waveform r(t, a). ADC 356 may include any suitable analog-to- digital converter to recover the encryption symbols (e.g., a =... , a„_w+i]) from the baseband received waveform r(t, a).

[0080] Decryptor 360 may have any suitable design for reverse-mapping the block of recovered encryption symbols (e.g., a = [an,an_i, ...,a„_w+1]) to recover the block of modulation symbols (e.g., s =... ,s„_w+i]). Decryptor 360 may use any suitable method for reverse-mapping the block of recovered encryption symbols to the block of modulation symbols. In some embodiments, decryptor 360 may include a receive look-up table. Decryptor 360 may use the receive look-up table to look up a modulation symbol corresponding to each encryption symbol. In other embodiments, decryptor 360 may not include a receive look-up table. For example, decryptor 360 may include any suitable processor that implements a reverse-mapping algorithm (e.g., a receive mapping algorithm) to map the block of recovered encryption symbols to the block of modulation symbols.

[0081] The reverse-mapping can be complementary to the transmit mapping performed at transmitting unit 304. For a transmit look-up table or transmit mapping algorithm being defined for the specific modulation scheme used by modulator 328, the receive look-up table or the receive mapping algorithm may also be defined for the specific modulation scheme used by modulator 328.

[0082] Demodulator 364 may have any suitable design for demodulating a recovered block of modulation symbols (e.g., s =...,s„_w+i] received from decryptor 360) to recover the encoded source data. Demodulator 364 may demodulate the recovered block of modulation symbols according to a demodulation scheme that is complementary to the modulation scheme used by modulator 328.

[0083] Deinterleaver 368 and channel decoder 372 may have any suitable design (e.g., any combination of circuits / hardware and program instructions) for deinterleaving and decoding demodulated data received from demodulator 364. The deinterleaving and decoding can be complementary to the interleaving at interleaver 324 and the encoding at 320 respectively to recover the source data. The recovered source data may be provided to data sink 376. Data sink 376 may provide a communication interface to an external device or channel. In some examples, data sink 376 may include a memory device that is configured to store the recovered source data.

[0084] As described herein above, transmitting unit 304 can provide encryption of the modulation symbols and the underlying modulation scheme / constellation at the physical layer. The transmitted waveforms can provide protection / encryption against spectral or time series analysis methods. Consequently, decrypting the transmitted waveform without the knowledge of the underlying mapping table / algorithm can be an arbitrarily difficult task. To that end, a potential interceptor / eavesdropper would need to test all potential combinations of symbol streams and hope that one of the outcomes of those combinations would match the transmitted baseband waveform, z(t, a). It can be shown mathematically and experimentally that there exists a lower bound on the number of all possible combinations of encrypted symbols (i.e., a = [an,a„-i, ..., a„_w+i]), constituting z(t, a).

[0085] To specify this lower bound, assuming that a total of N symbols is transmitted in a burst or a block, the number of all possible combinations of the encrypted symbols may be denoted as C. The mentioned lower bound can be presented as:where N\ denotes N factorial and log(IT) is the natural logarithm of N. The number of encrypted symbol combinations, C , can quickly reach a prohibitively large number for an eavesdropper to test, as the number of symbols, N grows. For example, if TV = 10 samples are transmitted, the number of all possiblecombinations that need to be tested to decrypt z(t, a) is greater than one trillion, more specifically, C > 1.4606F + 12. When N = 100 samples are transmitted, equation (1) yields C > 1.3572F + 163. When N = 175 samples are transmitted, equation (1) indicates that C can become an almost infinitely large number. Therefore, the disclosed system can efficiently create encrypted transmit sample blocks that are virtually impossible to decrypt with a brute force approach without the knowledge of the underlying mapping table / algorithm, even at relatively short block lengths (as illustrated by the above examples).

[0086] Reference is now additionally made to FIGS. 4A and 4B. FIG. 4A is a graph showing an example transmit signal constellation 400 for modulation symbols without encryption and FIG. 4B is a graph showing an example transmit signal constellation 450 for encryption symbols generated by encryptor 332. The illustrated example constellations 400 and 450 are for a total of 2,000 blocks, each carrying 150 samples from a QPSK (Quadrature Phase Shift Keying) modulation scheme. As shown in FIGS. 4A and 4B, the disclosed system can convert an easily recognizable QPSK constellation 400 into an encrypted form 450 that exhibits a random appearance, presenting almost an infinitely many possible combinations for a potential interceptor / eavesdropper to test.

[0087] Reference is now additionally made to FIG. 5. FIG. 5 is a graph 500 showing the normalized power spectral density (PSD) for an example transmitted waveform by transmitting unit 304. Graph 500 shows the normalized power spectral density for 150 transmit samples averaged over 2,000 transmitted blocks. As shown in FIG. 5, the example transmitted waveform has a flat spectrum, appearing as a white noise source to a potential interceptor / eavesdropper device, thereby disguising the actual spectral shape of the waveform.

[0088] Reference is now additionally made to FIG. 6. FIG. 6 is a graph 600 showing the normalized phase spectrum for an example transmitted waveform by transmitting unit 304. Graph 600 shows the normalized phase spectrum for 150 transmit samples, averaged over 2,000 transmitted blocks. As shown in FIG. 6, the phase spectrum does not follow a particular pattern, instead presenting a randomand arbitrary appearance, thereby not revealing any information on the underlying modulation format or modulation cardinality of the transmitted waveform.

[0089] As shown in FIGS. 5 and 6, the disclosed system can prevent unauthorized receivers or detectors from gaining any useful information related to the modulation format and / or the type of signal constellation of a transmitted waveform, even in cases where the unauthorized receivers / detectors are arbitrarily close to the transmitting unit (and have an arbitrarily high signal-to-noise ratio and no channel distortions). Consequently, the disclosed systems and methods can provide a high level of physical layer security without relying on directional transmission or key-based obfuscation.

[0090] At least one embodiment of the disclosed systems and methods can enable secure communication at low computational costs. For example, the computational cost associated with encryption and decryption using corresponding transmit and receive look-up tables can be significantly lower compared with the computation cost associated with key-based obfuscation. The computational cost associated with the disclosed systems and methods may grow linearly with N, the number of samples to be transmitted and received in each data block. In other systems and methods, the computational cost may grow non-linearly / exponentially with N.

[0091] Reference is now additionally made to FIG. 7. FIG. 7 is a graph showing example spectral efficiency performance of the disclosed system using an underwater acoustic communication channel in Halifax Harbor. The underwater acoustic communication channel used for the example measurements can present significant communication challenges including extremely shallow waters in the presence of large amounts and variety of ambient noise, Doppler spread and shift, and significant multipath up to several Kilometers of shallow-water, horizontal range.

[0092] At least one embodiment of the disclosed system can provide zero Bit Error Rate communication for the challenging communication environment, even in the presence of extreme multipath and random and deterministic Doppler spread and shift, which leads to a Doppler spectrum between -5 knots and +5 knots. Duringthe example measurements, high amounts of random and narrowband noise were introduced into the test environments by placing the transmitting unit and receiving unit in close proximity to large commercial and shipping vessels. The example measurements were repeated in conditions leading to a sea state of 6.

[0093] As shown in FIG. 7, the spectral efficiency performance of the disclosed system can be evaluated based on the practical limits on error-free communication (e.g., channel capacity). FIG. 7 shows that the average capacity of a shallow-water acoustic communication channel, exemplified by Halifax Harbor channel, can be considerably smaller than the capacity of well-known terrestrial channels. Further, FIG. 7 shows that an example embodiment of the disclosed system can provide communication throughputs that corresponds to 0.6 / 0.7, i.e., approximately 86% of the channel capacity in combination with a high level of physical layer security.

[0094] Reference is now made to FIG. 8. FIG. 8 is a flowchart showing an example embodiment of method 800 of providing physical layer security during digital communication. Any suitable system may be used for implementing method 800. For example, method 800 may be implemented using transmitting unit 304 and receiving unit 312 shown in FIG. 3 and concurrent reference is made to FIG. 3 in the following description. Method 800 may start automatically (e.g., periodically), manually undera user’s command, or when data to be transmitted is received (e.g., at source 316).

[0095] After method 800 starts, at act 810, modulator 328 assigns received source data to a block of modulation symbols carrying the source data according to a modulation scheme. The block of modulation symbols includes multiple discrete modulation symbols. In some embodiments, source data from source 316 may be encoded and interleaved before being assigned to the block of modulation symbols.

[0096] At act 820, encryptor 332 maps the block of modulation symbols to a block of encryption symbols including multiple encryption symbols. The mapping may include encryption of at least phase and / or an amplitude information associated with the modulation symbols by transforming the modulation symbols to an orthogonal transform space.

[0097] At act 830, transmitter 336 generates a transmit waveform for the block of encryption symbols. The transmit waveform may include a sequence of transmit samples corresponding to the multiple encryption symbols generated by encryptor 332 at act 820.

[0098] At act 840, transmitter 336 transmits the transmit waveform generated at act 830. The waveform may be transmitted via any suitable communication channel, e.g., channel 308.

[0099] At act 850, receiving unit 312 receives the transmitted waveform. For example, receiver 348 amplifies and down-converts the received waveform to generate a baseband received waveform.

[0100] At act 860, ADC 356 of receiver 348 performs analog to digital conversion of the baseband received waveform to recover the block of encryption symbols.

[0101] At act 870, decryptor 360 decrypts the block of encryption symbols recovered at act 860 to recover the block of modulation symbols. The decryption by decryptor 360 at act 870 is the complementary and inverse process of the encryption by encryptor 332 at act 820.

[0102] At act 880, demodulator 364 demodulates the block of modulation symbols recovered at act 870 to recover the source data. The demodulation by demodulator 364 at act 880 is complementary to the modulation process by modulator 328 at act 810. If received source data was encrypted and interleaved by transmitting unit 304, de-interleaver 368 and channel decoder 372 perform complementary deinterleaving and decoding to recover the source data.

[0103] Method 800 may continue recursively until a stop condition is satisfied. For example, method 800 may stop in response to a user input or when all the available data is transmitted and received.

[0104] While the applicant's teachings described herein are in conjunction with various embodiments for illustrative purposes, it is not intended that the applicant's teachings be limited to such embodiments as the embodiments described herein are intended to be examples. On the contrary, those of skill in the art will appreciate that the applicant's teachings described and illustrated herein encompass variousalternatives, modifications, and equivalents, without departing from the embodiments described herein, the general scope of which is defined in the appended claims.

Claims

CLAIMS:

1. A method of providing physical layer security during digital communication, the method comprising: assigning, by a modulator, received source data to a block of modulation symbols carrying the source data according to a modulation scheme, the block of modulation symbols including multiple discrete modulation symbols; mapping the block of modulation symbols to a block of encryption symbols including multiple encryption symbols, the mapping including encryption of at least a phase and / or an amplitude information associated with the modulation symbols by transforming the modulation symbols to an orthogonal transform space; generating a transmit waveform for the block of encryption symbols, the transmit waveform including a sequence of transmit samples corresponding to the multiple encryption symbols; and transmitting the generated transmit waveform.

2. The method of claim 1 , wherein the mapping further includes encrypting a relative position information of each of the modulation symbols with reference to other modulation symbols in the block of modulation symbols.

3. The method of claim 1 or claim 2, wherein the block of modulation symbols is mapped to the block of encryption symbols using a transmit look-up table or a transmit mapping algorithm.

4. The method of claim 3, wherein the transmit look-up table or the transmit mapping algorithm is defined for the modulation scheme used by the modulator.

5. The method of any one of claims 1 to 4, wherein the modulation scheme includes phase shift keying (PSK), quadrature amplitude modulation (QAM), Continuous Phase Modulation (CPM), Continuous Phase Shift Keying (CPSK), Minimum Shift Keying (MSK), Gaussian Minimum Shift Keying (GMSK) or frequency shift keying (FSK) modulation.

6. The method of any one of claims 1 to 5, wherein the mapping includes preequalizing non-uniform amplitude levels associated with the multiple modulation symbols.

7. The method of any one of claims 1 to 6, wherein generating the transmit waveform includes passing the block of encryption symbols through an interpolation filter for digital-to-analog conversion.

8. The method of any one of claims 1 to 7, wherein generating the transmit waveform includes passing the block of encryption symbols through a single-carrier interface, a multi-carrier interface, or a spread-spectrum interface.

9. The method of any one of claims 1 to 8, wherein the method further comprises: receiving the transmitted waveform at a receiving unit; recovering the block of encryption symbols from the received waveform; reverse-mapping the recovered block of encryption symbols to recover the block of modulation symbols; and demodulating the recovered block of modulation symbols to recover the source data.

10. The method of claim 9, wherein the reverse-mapping is performed using a receive look-up table or a receive mapping algorithm that is defined for the modulation scheme used by the modulator.

11. The method of any one of claims 1 to 10, wherein the generated transmit waveform is transmitted using acoustic waves, electromagnetic waves or optical waves.

12. The method of any one of claims 1 to 11 , wherein the generated transmit waveform is transmitted via an underwater communication channel, a terrestrial channel, a wired channel, a wireless channel or a satellite channel.

13. A system for providing physical layer security during digital communication, the system comprising:a modulator configured to assign received source data to a block of modulation symbols carrying the source data according to a modulation scheme, the block of modulation symbols including multiple discrete modulation symbols; an encryptor configured to map the block of modulation symbols to a block of encryption symbols to encrypt at least a phase and / or an amplitude information associated with the modulation symbols by transforming the modulation symbols to an orthogonal transform space, the block of encryption symbols including multiple encryption symbols; and a transmitter configured to: generate a transmit waveform for the block of encryption symbols, the transmit waveform including a sequence of transmit samples corresponding to the multiple encryption symbols; and transmit the generated transmit waveform.

14. The system of claim 13, wherein the encryptor is further configured to map the block of modulation symbols to the block of encryption symbols to encrypt a relative position information of each of the modulation symbols with reference to other modulation symbols in the block of modulation symbols.

15. The system of claim 13 or claim 14, wherein the encryptor is configured to map the block of modulation symbols to the block of encryption symbols using a transmit look-up table or a transmit mapping algorithm.

16. The system of claim 15, wherein the transmit look-up table or the transmit mapping algorithm is defined for the modulation scheme used by the modulator.

17. The system of any one of claims 13 to 16, wherein the modulation scheme includes phase shift keying (PSK), quadrature amplitude modulation (QAM), Continuous Phase Modulation (CPM), Continuous Phase Shift Keying (CPSK), Minimum Shift Keying (MSK), Gaussian Minimum Shift Keying (GMSK) or frequency shift keying (FSK) modulation.

18. The system of any one of claims 13 to 17, wherein the encryptor is configured to pre-equalize non-uniform amplitude levels associated with the multiplemodulation symbols while mapping the block of modulation symbols to the block of encryption symbols.

19. The system of any one of claims 13 to 18, wherein the transmitter is configured to generate the transmit waveform by passing the block of encryption symbols through an interpolation filter for digital-to-analog conversion.

20. The system of any one of claims 13 to 19, wherein the transmitter is configured to generate the transmit waveform by passing the block of encryption symbols through a single-carrier interface, a multi-carrier interface, or a spreadspectrum interface.

21. The system of any one of claims 13 to 20, wherein the system further comprises: a receiver configured to: receive the transmitted waveform; and recover the block of encryption symbols from the received waveform; a decryptor configured to reverse-map the block of recovered encryption symbols to recover the block of modulation symbols; and a demodulator configured to demodulate the recovered block of modulation symbols to recover the source data.

22. The system of claim 21 , wherein the decryptor is configured to reverse-map the block of recovered encryption symbols using a receive look-up table ora receive mapping algorithm that is defined for the modulation scheme used by the modulator.

23. The system of any one of claims 13 to 22, wherein the transmitter is configured to transmit the generated transmit waveform using acoustic waves, electromagnetic waves or optical waves.

24. The system of any one of claims 13 to 23, wherein the transmitter is configured to transmit the generated transmit waveform via an underwater communication channel, a terrestrial channel, a wired channel, a wireless channel or a satellite channel.

Citation Information

Patent Citations

  • Wireless security communication method based on physical layer

    CN107920351A

  • Method and apparatus for low complexity transmission and reception of constant or quasi-constant envelope continuous phase modulation waveforms

    US10374853B2

  • Computer system with privileged-mode modem driver

    US6842803B2

  • Method and apparatus for encryption of over-the-air communications in a wireless communication system

    US7804912B2

  • A harmonic based encryption and decryption system for waveform signals

    WO2015097312A1