System and methods for real time identification of transmission protocols

The method and system efficiently identify unknown transmission protocols in real-time by processing a single burst transmission, overcoming the limitations of prior systems through brute-force search and autocorrelation, ensuring rapid and accurate protocol detection.

WO2026154479A1PCT designated stage Publication Date: 2026-07-23
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Filing Date
2026-01-19
Publication Date
2026-07-23

Smart Images

  • Figure IL2026050058_23072026_PF_FP_ABST
    Figure IL2026050058_23072026_PF_FP_ABST
Patent Text Reader

Abstract

A method and system are presented for real-time identification of an unknown transmission protocol. Recorded RF data is provided comprising sampled RF waves being indicative of one or more burst transmissions being detected. Data indicative of a single burst transmission, BTi, is provided, having a burst duration and a bandwidth. The BTi is processed and analyzed in accordance with at least one selected transmission protocol type out of a plurality of predetermined transmission protocol types. Data about unique parameters characterizing the selected transmission protocol type is utilized to recover characteristic parameter(s) from the BTi, and optimize value(s) of characteristic parameter(s) of the selected transmission protocol type, by utilizing predetermined fit criterion to perform at least one of a brute-force search of best-fit value(s) of said characteristic parameter(s) and autocorrelation of the single burst transmission BTi, thereby obtaining a set of recovered and optimized values of the characteristic parameters. At least one of the following is then performed: utilizing said set of parameters to demodulate a sequence of transmitted symbols from said BTi and determine a quality score for said sequence of transmitted symbols; and determine a quality score for said characteristic parameter(s). A predetermined thresholding analysis is applied to said quality score to determine a probability of correctness of the identification of said selected transmission protocol.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] SYSTEM AND METHODS FOR REAL TIME IDENTIFICATION OF TRANSMISSION PROTOCOLS

[0002] TECHNOLOGICAL FIELD

[0003] The present disclosure is in the field of telecommunication and particularly relates to systems and methods of detection and identification of wireless signals.

[0004] BACKGROUND AND BACKGROUND ART

[0005] Drones of various types are widely used in various military and civilian fields. They are finding new applications in areas such as surveillance, military reconnaissance, rescue missions, infrastructure inspection, package delivery and many other applications. However, there are security and privacy issues associated with the ubiquity of the drones of UAV and DIY types. For example, drones may be used to transport illegal drugs across prison walls or carrying out espionage attacks which pose serious risk to public safety. Moreover, drones are becoming tools for cyberattack and terrorism. Therefore, effective regulation of drones will become an important task in addressing the above risks. In particular, accurate detection and classification of these vehicles are vital to public safety and national security.

[0006] LoRa (Long Range) protocol is employed in drone communications for its long-range and low-power capabilities. Specifically, it is advantageous in scenarios where extended communication distances are necessary, such as remote monitoring and control.

[0007] FSK (Frequency Shift Keying) is a modulation technique where digital information is transmitted through discrete frequency changes of a carrier wave. Due to its simplicity and robustness, FSK is utilized in certain telemetry and control systems, e.g., in non-line-of-sight atmospheric optical communication in UAVs / DIYs.

[0008] OFDM is a digital modulation technique that divides a signal into multiple closely spaced subcarrier frequencies, allowing for efficient and robust data transmission.OFDM's resilience to multipath interference and efficient spectrum usage make it suitable for the high data rates required in drone operations.

[0009] GENERAL DESCRIPTION

[0010] There is a need in the art for a novel approach for real-time identification of an unknown transmission protocol embedded in a signal being detected.

[0011] It should be noted that known in the art generic detectors and parameter estimators typically assume some prior knowledge of the FSK / LoRa transmissions. The technique of the present disclosure utilizes assumptions solely on the ranges of parameter values, but otherwise treats all parameters as unknown, including the time-frequency location of transmissions within a given sample of the signal being detected.

[0012] The present disclosure provides a novel solution for real-time identification of unknown transmission protocols from single burst transmissions being detected and recorded. More specifically, according to the technique of the present disclosure, identification is made of which communication protocol is being used by a transmitter, by processing a signal being detected and recorded, i.e., by processing a single burst transmission. By this, a need for accumulation of data over extended periods of time is eliminated. The processing of the single burst transmission includes using a predetermined fit criterion to perform a brute-force search within one or more assumed ranges of parameter values and / or autocorrelation of the single burst transmission BTi, and quality score based protocol probability assessment, i.e., determining a score quantifying correctness and determining a probability of correctness of the identification of the selected transmission protocol.

[0013] Thus, according to one broad aspect of the present disclosure it provides a method for real-time identification of an unknown transmission protocol, comprising:

[0014] providing recorded RF data comprising sampled RF waves being indicative of one or more burst transmissions being detected;

[0015] providing data indicative of a single burst transmission, BTi, out of one or more burst transmissions being recorded, the single burst transmission having a burst duration and a bandwidth;

[0016] processing and analyzing said single burst transmission BTi, in accordance with at least one selected transmission protocol type out of a plurality of predetermined transmission protocol types,wherein said processing and analyzing according to the selected transmission protocol type comprises:

[0017] (i) based on data about unique characteristic parameters characterizing the selected transmission protocol type, recovering from said single burst transmission, one or more of said unique characteristic parameters, and optimizing one or more values of said one or more unique characteristic parameters of the selected transmission protocol type, said optimizing comprising utilizing a predetermined fit criterion to perform at least one of a brute-force search within one or more assumed ranges of parameter values of the selected transmission protocol type and autocorrelation of the single burst transmission BTi, to thereby identify best-fit correlation for each of said one or more values of said one or more unique characteristic parameters and the single burst transmission BTi, thereby obtaining a set of one or more recovered and optimized values of the one or more unique characteristic parameters of the selected transmission protocol type;

[0018] (ii) utilizing said one or more recovered and optimized values of the one or more unique characteristic parameters to carry out at least one of the following:

[0019] demodulate a sequence of transmitted symbols from said single burst transmission BTi and determine a quality score for said sequence of transmitted symbols, the quality score being indicative of correctness of symbol demodulation; and

[0020] determine a quality score for at least one of said one or more unique characteristic parameters, the quality score being indicative of correctness of correctness of parameter recovery;

[0021] (iii) applying a predetermined thresholding analysis to said quality score and determining a probability of correctness of the identification of said selected transmission protocol.

[0022] Thus, the technique of the present disclosure provides a blind recovery of the unique characteristic parameter(s) of the selected transmission protocol type; and provides for determining the quality score which is indicative of correctness of at least one of the parameter recovery and symbol demodulation. The thresholding analysis of the quality score and determination of the probability of correctness is based on successful recovery of characteristic protocol parameters and / or demodulation of the transmitted symbols. Hence, the technique of the present disclosure ties the verification todemodulation / parameter recovery success, and protocol identification is confirmed through actual data determination (protocol parameters and / or transmitted symbols).

[0023] It should also be noted that in the technique of the present disclosure, recovering and optimizing of the unique characteristic parameter(s) is performed without use of pretrained machine learning models or classifiers, and relies solely on correlation-based analysis of the single burst transmission structure.

[0024] The provision of the data indicative of the single burst transmission, BTi, having the burst duration and the bandwidth can be implemented by processing the recorded RF data being detected to identify in said recorded RF data the single burst transmission.

[0025] In some embodiments, the processing and analyzing of said single burst transmission BTi comprises parallel performance of a set of steps (i) - (iii) in accordance with at least two selected transmission protocol types out of said plurality of predetermined transmission protocol types.

[0026] In some embodiments, the processing and analyzing of said single burst transmission BTi further comprises: upon determining that the probability of correctness of the identification of the selected transmission protocol is below a predetermined threshold, performing a set of steps (i) - (iii) in accordance with another selected transmission protocol type out of said plurality of predetermined transmission protocol types.

[0027] As noted above, the provision of the data indicative of the single burst transmission, BTi, may be implemented by processing the recorded RF data being detected to identify in said recorded RF data the single burst transmission. In some embodiments, the processing of the recorded RF data to identify the single burst transmission, BTi, comprises:

[0028] (a) applying to said recorded RF data a filter bank with chosen parameters and obtaining filter bank’s outputs;

[0029] (b) averaging and normalizing absolute values of the filter bank’s outputs;

[0030] (c) applying threshold and contour detection to find time ( / ) and frequency ( / ) start and end values, (tstart, tend) and ( start, fend), of the single burst transmission, BTi, defining burst duration, Tburst, and estimated bandwidth, BWest, of the single burst transmission BTi;

[0031] (d) based on the defined burst duration, Tburst, and estimated bandwidth, BWest, validating the single burst transmission BTi, to either accept said single bursttransmission BTi for further processing or disregard said single burst transmission BTi.

[0032] The validating of the single burst transmission BTi may comprise: analyzing the burst duration, Tburst , and the estimated bandwidth, BWest, with respect to predetermined normal ranges, and applying a constant amplitude (CA) score test using a CA criterion to the absolute values of validated samples of the burst transmission BTi.

[0033] For example, the validating of the single burst transmission BTi comprises: assigning “valid” value to the single burst transmission BTi upon identifying that the burst duration, Tburst , the estimated bandwidth, BW, and the CA score satisfy conditions that the burst duration, Tburst, and the estimated bandwidth, BW, are within said predetermined normal ranges, and the CA score is above threshold; and disregarding the single burst transmission BTi upon identifying that at least one of said conditions is not satisfied.

[0034] In some embodiments, at least one of the above steps (a) to (d) of the processing of the recorded RF data utilizes an iterative data processing.

[0035] In some embodiments, the filter bank being used is a Short-Time Fourier Transform (STFT).

[0036] In some embodiments, the CA score test used in the validating of the single burst transmission BTi comprises the following:

[0037] calculating a constant amplitude score, CA SCORE defined as CA SCORE = mean(abs(BTi_samples)) / std(abs(BTi_samples)); and applying threshold to the CA SCORE.

[0038] In some embodiments, the selected transmission protocol type is based on Long Range (LoRa) modulation technique. In these embodiments, the at least one unique characteristic parameter comprises a symbol time, TM, a spreading factor, SF, a chirp type, a number N of repetitions of a basic preamble symbol within a preamble portion of the BTi, and two additional middle symbols of the preamble portion of the BTi.

[0039] For example, the recovering of the at least one characteristic parameter from said single burst transmission comprises:

[0040] applying autocorrelation to recover the symbol time, TM, from the preamble portion of the BTi;

[0041] utilizing the symbol time, TM, being recovered and an estimated value of the bandwidth, BWest, of the BTi , and recovering the spreading factor, SF from a relation:

[0042] SF = roimd(log2 , BWest• TM )recovering the bandwidth, BWacc, using a relation:

[0043] ?SF

[0044] BWacc= — ;

[0045] 1M

[0046] recovering the chirp type as being of up-chirp type or down-chirp type by analyzing correlation between the BTi and generated up-chirp and down-chirp burst transmissions;

[0047] recovering the number N of the repetitions of the basic preamble symbol, by analyzing correlation of the BTi with a generated preamble portion of the recovered chirp type.

[0048] The method may further include the step of optimizing a time start value, to, and a center frequency, fco, of the BTi using a brute force search and a max score criterion. This may, for example, be implemented as follows:

[0049] performing initial estimations of the time start value, to and the center frequency, / co, by applying threshold and contour detection on the recorded data indicative of the BTi;

[0050] creating corresponding first and second vectors of test timings around the time start value to and test frequencies around the center frequency fco , respectively; iterating through every permutation of values of the first and second vectors, wherein in each iteration:

[0051] creating a corrected BTi by applying a corresponding shift in time and frequency domains to the preamble portion of the BTi;

[0052] generating a reference preamble using recovered values of the characteristic parameters: symbol time, TM, spreading factor, SF, chirp type, and number N of repetitions of a basic preamble symbol within the preamble portion of the BTi;

[0053] multiplying data indicative of the corrected BTi and the reference preamble and obtaining a multiplication result;

[0054] applying FFT to the multiplication result and recording FFT maximum value;

[0055] determining an optimized time start value, to, being a time start value from the first vector that corresponds to a maximum value out of all recorded FFT maximum values; and determining an optimized center frequency, fco, being acenter frequency from the second vector corresponding to the maximum value out of all the recorded FFT maximum values.

[0056] In the above example, the extracting of the sequence of the transmitted LoRa symbols from the single burst transmission BTi may include:

[0057] resampling the BTi using the recovered value of the bandwidth, BWaCc, and spreading factor, SF, parameters; de-chirping a resampled BTi; and applying FFT thereto;

[0058] performing said calculation of the score for said sequence of the transmitted symbols by carrying out the following:

[0059] for each FFT of the extracted transmitted LoRa symbol, searching for a maximum value index corresponding to the symbol number, and calculating and recording a corresponding score defined as a ratio of maximum energy and a noise level;

[0060] calculating a final mean score of all recorded scores;

[0061] applying the predetermined thresholding analysis to the final mean score, and determining whether or not all LoRa recovered parameters and extracted symbols are correct.

[0062] The predetermined thresholding analysis may be configured to determine the probability of correctness, and upon identifying that said probability of correctness is indicative of that all the LoRa recovered parameters and the extracted symbols are incorrect, performing said processing and analyzing of the single burst transmission BTi for the selected transmission protocol type being Frequency -shift keying (FSK) communication protocol.

[0063] The method may further include preprocessing the single burst transmission BTi to obtain data indicative of a phase derivative of BTi. The preprocessing may include: obtaining the phase derivative of BTi followed by normalization and smoothing thereby obtaining said data indicative of the phase derivative of BTi.

[0064] The at least one characteristic parameter may comprise baud rate, BRo. In this case, the recovering of the baud rate, BRo from the data indicative of the phase derivative of BTi may comprise finding a minimum distance between extrema points of said data and determining an initial value of the baud rate as a reciprocal of the minimum distance between extrema points. The optimizing of the initial value of the baud rate, BRo, may comprise the brute force search of the best-fit with a bin-width criterion, wherein the brute force search comprises:creating a vector of narrowly-spaced test baud rates, {BRtest}, around BRo ; for each tested baud rate BRtest, performing the following:

[0065] recording all extrema points in the data indicative of the phase derivative of BTi, wherein the extrema points are identified at constant intervals;

[0066] applying absolute value to all the extrema points;

[0067] calculating and recording an average of the absolute values of all extrema points;

[0068] determining the optimized value of the baud rate, BR, as the tested baud rate, BRtest, corresponding to a maximum value of all averages of the absolute values of all the extrema points.

[0069] The extraction of the sequence of the transmitted symbols from the single burst transmission BTi may utilize the optimized value of the baud rate, BR, and comprises: determining all the extrema points in the data indicative of phase derivative of BTi for the optimized value of the baud rate, BR; and converting each maximum value to ‘ 1’ and each minimum value to ‘O’. The process may further include: detecting and recovering a standard preamble portion of an FSK-type signal within the single burst transmission BTi, using correlation, by carrying out the following:

[0070] generating a “1,0, 1,0,...” bit sequence corresponding to the standard preamble portion of an FSK-type signal, and correlating said sequence being generated with the extracted sequence of the transmitted symbols;

[0071] applying a predetermined threshold to determine whether the preamble portion of the BTi corresponds to the standard preamble of the FSK-type or not.

[0072] The method may further include recovering of the preamble portion of the single burst transmission BTi comprising repetitions of a certain base bit sequences, where such recovering is based on a brute force search and comprises:

[0073] generating a vector of preamble bit sequence lengths, PLi;

[0074] generating a vector of preamble starting points, SPi ;

[0075] generating a vector of base bit sequence lengths, BBLi;

[0076] iterating through each triplet of tested values, (PLi, SPi, BBLi) and performing the autocorrelations of the single burst transmission BTi, each autocorrelation ACi being calculated per the triplet of the tested values PLi, SPi, BBLi;

[0077] recording a maximum score, defined as a maximum autocorrelation value, Max{ACi}, out of all autocorrelations;applying the predetermined thresholding analysis to said maximum score, Max{ACi}, and determining the probability of correctness of the identification of said unknown transmission protocol as FSK transmission protocol.

[0078] In some embodiments, the selected transmission protocol type is Orthogonal Frequency Division Multiplexing (OFDM) communication protocol. In this case, the data indicative of the single burst transmission, BTi, having the burst duration and the bandwidth, is provided by processing the recorded data being detected to identify in said recorded data the single burst transmission. The identifying of the single burst transmission, BTi, in the recorded data being detected may be performed by utilizing an energy detector in the time domain, followed by an energy detector in the frequency domain.

[0079] The recovering step may comprise: recovering values of the following OFDM characteristic parameters from said single burst transmission BTi: (1) width, Nfft, of an FFT window corresponding to each OFDM symbol, (2) chip rate defined as a sample rate enabling Nfft OFDM subcarriers, (3) subcarrier spacing (scs), (4) number of active subcarriers, Nactive, (5) average cyclic prefix (CP) size, Nep, and (6) number of symbols, Nsym, within the single burst transmission BTi. For example, recovering the width, Nfft, of the FFT window corresponding to each OFDM symbol comprises a first brute force search in a range of test FFT windows, {Nffttest}, for maximum autocorrelations between the single burst transmission BTi and its shifted versions by Nffttest, where the brute force search comprises:

[0080] for each tested value, Nffttest, performing a brute force search over a range of correlation lengths represented by a range of test lengths of the cyclic prefix, {Neptest}, by carrying out the following:

[0081] calculating the autocorrelation values for all correlation lengths in {Neptest}; and

[0082] recording the maximum autocorrelation value out of all correlation lengths in {Neptest};

[0083] locating and recording Nffto defined as the Nffttest for which the maximum of all the maximum autocorrelation values is found in (a);

[0084] determining an optimized value of Nfft defined as the closest value, being a power of 2, which meets the requirement: n_fft_vec= [64, 128, 256, 512, 1024, 2048, 4096, ...], such that (Nfft)Opt= n_fft_vec[argmin(abs (NfftO -n_fft_vec))].For example, recovering the chip rate comprises an iterative initial chip rate, chip_rateinit, estimation, update of the value of (Nfft)opt, and an optimization of the initial chip rate, chip rateinit, estimation using brute force searches.

[0085] The iterative initial chip rate estimation comprises:

[0086] setting chip rateinit as the input sampling rate;

[0087] performing an iterative process using the bandwidth BW as follows:

[0088] while (chip_rateinit / 2) > BW and Nfft >64:

[0089] chip_rateinit = chip_rateinit / 2

[0090] update Nfft value: Nfft = Nfft / 2.

[0091] The optimization using brute force searches comprises running first and second brute force searches by performing the following:

[0092] defining a range {chip ratetest} of tested chip rate values for the first brute force search, and performing the first brute force search comprising: for each tested chip rate value, chip ratetest, resampling the single burst transmission BTi from its sample rate to chip_ratetest; and

[0093] performing the second brute force search over a range of correlation lengths represented by a range of test lengths of the cyclic prefix, {Neptest}, using the updated value of Nfft, said second brute force search comprising: calculating the autocorrelation values for all correlation lengths in {Neptest}; and recording the maximum autocorrelation value of all correlation lengths in {Neptest};

[0094] locating and saving an optimized chip rate, chip rateo, defined as the chip ratetest for which the maximum of all the maximum autocorrelation values is found.

[0095] For example, recovering the value of the subcarrier spacing (scs) comprises: using the recovered values of the chip rate and Nfft to define subcarrier spacing (scs) as: scs = chip_rateo / Nfft. Recovering the value of the number of active subcarriers, Nactive, may utilize the estimated bandwidth BW and the subcarrier spacing (scs) to define the value of the number of active subcarriers, Nactive as: Nactive= round(BW / scs). Recovering the value of the average cyclic prefix (CP) size, Nep, may comprise optimization using a brute force search over a range, {Neptest}, of test lengths of the cyclic prefix, and CPbased autocorrelation, wherein the brute force search comprises:

[0096] resampling the single burst transmission BTi from its sample rate to chip rateo ; for each tested value, Neptest, performing the following:calculating the autocorrelation values for all the cyclic prefixes of length Neptest within the single burst transmission BTi, wherein the shift of BTi for each tested value Neptest is defined by the updated Nfft value;

[0097] saving the maximum autocorrelation value per Neptest value;

[0098] identifying and recording an optimized Nep value defined as the Neptest for which the maximum of all the maximum autocorrelation values.

[0099] Recovering the value of the number of symbols, Nsym, within the single transmission burst BTi may utilize the burst duration, and the recovered parameters Nfft, Nep, and the chip rate to calculate an integer value of Nsym using a relation:

[0100] Nsym= round( (burst duration * chip rate) / (Nfft+Ncp)).

[0101] The method can further include: calculating a final score using the recovered parameters, by carrying out the following:

[0102] resampling the single burst transmission BTi from its sample rate to chip_rateo;

[0103] using Nfft and Nep to calculate the autocorrelation value obtained between the single burst transmission BTi and its version which was shifted by Nfft; defining the final score as the autocorrelation value ;

[0104] applying a threshold to the final score to determine whether all OFDM parameters are correct.

[0105] According to another broad aspect of the present disclosure, there is provided a computerized system configured and operable to implement the above-described method for real-time identification of an unknown transmission protocol.

[0106] According to yet another broad aspect of the present disclosure, it provides a system for real-time identification of an unknown transmission protocol, the system comprising a computerized system which comprises a processing and memory circuitry comprising at least one analyzer configured and operable to identify whether one or more burst transmissions of RF data relate to one of K (K>1) predetermined transmission protocols; the analyzer comprising:

[0107] a recovery utility configured and operable to carry out the following: recover, from recorded RF data being detected, data indicative of a single burst transmission, BTi, having a burst duration and a bandwidth; and utilize data about unique characteristic parameters of a selected transmission protocol type to recover, from said single burst transmission, one or more of said unique characteristic parameters and optimize one ormore values of said one or more unique characteristic parameters of the selected transmission protocol type, said optimizing comprising using a predetermined fit criterion to perform at least one of a brute-force search within one or more assumed ranges of parameter values of the selected transmission protocol type and autocorrelation of the single burst transmission BTI; to thereby identify best-fit correlation for each of said one or more values of said one or more unique characteristic parameters and the single burst transmission BTi; thereby obtaining a set of one or more recovered and optimized values of the one or more unique characteristic parameters of the selected transmission protocol type;

[0108] a demodulation utility configured and operable to analyze said one or more values of the one or more recovered and optimized unique characteristic parameters to carry out at least one of the following: demodulate a sequence of transmitted symbols from said single burst transmission and determine a quality score for said sequence of transmitted symbols, the quality score being indicative of correctness of symbol demodulation; and determine a quality score for at least one of said one or more unique characteristic parameters, the quality score being indicative of correctness of parameter recovery; a verification utility configured and operable to apply a predetermined thresholding analysis to said quality score and determine a probability of correctness of the identification of said selected transmission protocol.

[0109] BRIEF DESCRIPTION OF THE DRAWINGS

[0110] In order to better understand the subject matter that is disclosed herein and to exemplify how it may be carried out in practice, embodiments will now be described, by way of non-limiting examples only, with reference to the accompanying drawings, in which:

[0111] Figs. 1A and IB exemplify, by way of a flow diagram (Fig. 1A) and a block diagram (Fig. IB), the method and system of the present disclosure for real-time identification of an unknown transmission protocol;

[0112] Fig- 2 is a flow diagram illustrating more specifically an exemplary procedure of the burst detection according to the present disclosure;

[0113] Figs.3A-3E exemplify analysis of the signal being detected to identify whether it corresponds to LoRa transmission protocol;Figs. 4A-4F exemplify analysis of the detected burst to identify whether it corresponds to FSK transmission protocol; and

[0114] Figs. 5A-5H exemplify analysis of the signal being detected to identify whether it corresponds to OFDM transmission protocol.

[0115] DETAILED DESCRIPTION OF EMBODIMENTS

[0116] Reference is made to Figs. 1A and IB illustrating schematically the principles of the technique of the present disclosure for real-time identification of an unknown transmission protocol embedded in an RF signal being detected from an external device, such as a drone.

[0117] As shown in Fig. 1A, the technique of the present disclosure is implemented by a system 10, which includes a control unit 12 configured as a computerized system associated with a signal detection system 14. The detection system 14 includes one or more detectors of any known suitable type capable of receiving external signals, e.g., in the form of RF waves. The detection system 14 may comprise a number of RF detectors configured and operable to intercept communication data traffic between a drone and its remote controller. The detection system 14 further includes a burst identifier utility 18.

[0118] The control unit 12 may be a stand-alone unit connectable to the detection system 14 via wires or wireless signal communication, or can be integral with the detection system, or functionalities of the control unit 12 may be distributed between the detection system and a stand-alone controller.

[0119] The control unit 12, being a computerized system, includes inter alia data input and output utilities 12A, 12B; memory 12C; and processing and memory circuitry 12D.

[0120] The processing and memory circuitry 12D is configured and operable to be responsive to data indicative of the signal being detected by the detection system 14 and apply to this data predetermined processing and analyzing to identify whether the signal being detected relates to one of K (K>1) predetermined transmission protocols. To this end, the processing and memory circuitry 12D may be configured to apply sequential processing and analyzing procedures in accordance with a list of predetermined transmission protocols, i.e., start from the first protocol, and if it appears that the signal is not related to the first protocol, start analyzing the signal with respect to the second protocol, and so on. Alternatively (or additionally) the processing and memory circuitry may beconfigured to concurrently analyze the same signal with respect to two or more different transmission protocols.

[0121] Thus, the processing and memory circuitry 12D includes at least one analyzer 16 configured and operable to analyze an i-th burst transmission (sample) BTi in accordance with at least one of K predetermined protocols. Each of the at least one analyzer 16 includes a protocol parameters recovery utility 20, a symbol demodulation utility 22, and a verification utility 24. In some embodiments, the processing and memory circuitry 12D also includes a pre-processor 26, the operation of which will be described further below.

[0122] As shown in Fig. 1A and IB, the detection system 14, which includes at least one detector operating with a certain sampling rate, is configured and operable to provide recorded RF data (raw input data) corresponding to sampled RF waves, which are indicative of one or more burst transmissions. More specifically, such raw input data may be the power recorded by an analog-to-digital converter (ADC) of the at least one detector.

[0123] The detection system 14 includes a processing circuitry 18 configured and operable as a burst identifier to identify in the input data a single burst transmission, BTi, out of the one or more burst transmissions. The single burst transmission BTi has a burst duration and a bandwidth. It should be noted that, generally, such a burst identifier circuitry can be part of the control unit 12, or the functionalities of the processing circuitry 18 can be distributed between the detection system 14 and the control unit 12.

[0124] The processing and memory circuitry 12D receives at least one burst transmission, BTi, from the detection system 14 (or internal circuitry of the control unit 12), and operates to process and analyze the single burst transmission BTi, in accordance with at least one selected transmission protocol type out of a plurality of predetermined transmission protocol types.

[0125] The processing and analyzing according to the selected transmission protocol type is implemented as follows:

[0126] The recovery utility utilizes unique characteristic parameters characterizing the selected transmission protocol type to recover from the single burst transmission one or more of the unique characteristic parameters, and optimizing one or more values of the one or more characteristic parameters of the selected transmission protocol type, and thus optimize initial recovery data. This is implemented by performing a brute-force search within one or more assumed ranges of parameter values of the selected transmissionprotocol type and / or autocorrelation using a predetermined fit criterion, to identify best-fit correlation for each of the one or more values of the one or more unique characteristic parameters with the detected data of the single burst transmission, BTi. The so-obtained optimized recovery data includes a set of one or more recovered and optimized values of the one or more unique characteristic parameters of the selected transmission protocol type.

[0127] The demodulation utility uses the so-obtained set of the one or more recovered and optimized values of the one or more unique characteristic parameters to extract (demodulate) a sequence of transmitted symbols from the single burst transmission BTi. Then, the demodulation utility calculates a quality score for the sequence of transmitted symbols and / or for at least one of the one or more unique characteristic parameters. The quality score is indicative of correctness of parameter recovery and / or symbol demodulation / extraction.

[0128] The so-obtained quality score then undergoes a verification by applying a predetermined thresholding analysis thereto to determine a probability of correctness of the identification of the selected transmission protocol.

[0129] Reference is made to Fig. 2 exemplifying a method 200 of burst detection which may be employed during detection of, e.g., LoRa and FSK transmission protocols. The method 200 is used to identify a single burst transmission z, BTi, in the recorded RF data. Thus, the at least one detector of the detection system 14 operates to provide the recorded RF data (step 202) which corresponds to the raw input sample / recording at a known sampling rate.

[0130] The detection system 14 may include one or more detectors. It should be noted that the detector may utilize any known in the art RF receiving circuitry, but which is configured (i.e., has a corresponding response function) to detect burst transmissions of a specific modulation type. In case the detection system includes multiple detectors, they may include detectors configured for detection of burst transmissions of different modulation types. Thus, the detection system may be configured to detect either one specific modulation type or more than one modulation type. Specifically for the example of LoRa / FSK transmission protocols, the detector can be designed to detect FSK and LoRa, and can potentially be broken into 2 different detectors - one for FSK and another one for LoRa.As noted above, the detector preferably further includes the burst identifier circuitry 18. The burst identifier circuitry 18 operates as follows:

[0131] In step 204, a filter bank with chosen parameters is applied to the input data and filter bank’s outputs are obtained. A filter bank generally includes an array of bandpass filters that separate the input signal into multiple components, each one carrying a sub-band of the original signal.

[0132] A specific but not-limiting example of such a filter bank is a short-time Fourier Transform (STFT) which is a Fourier transform of a short part of a signal. STFT can be viewed as filtering the detected data through a bank of analysis filters, in which the k-th filter is a bandpass filter centered at cok. It should be noted that many other known techniques can be used to implement a filter bank, of which STFT is just a non-limiting example.

[0133] The parameters of the filter bank are chosen based on statistical bandwidth and channel separation analysis of many types and instances of FSK / LoRa transmissions, with the goal to choose parameters that ensure a favorable detection and false alarm rates. The parameters are configurable and changing them affects the system performance, creating a tradeoff between correct detection and false alarm rate.

[0134] In step 206, the absolute values of the filter bank’s outputs are averaged and normalized.

[0135] In step 208, threshold and contour detection are applied to find time (7) and frequency (f) start and end values, (tstart, tend) and (fstart, fend , of the single burst transmission, BTi, defining burst duration, Tburst= tend - tstart, and estimated bandwidth, B W est—fend ~ fstart, of the BTi.

[0136] In step 210, the single burst transmission BTi is validated, to either accept the single burst transmission BTi for further processing or disregard BTi. The validation may include the following steps: (i) analyzing the burst duration, Tburst, and the estimated bandwidth, BWest, with respect to predetermined normal ranges, and (ii) applying a constant amplitude (CA) score test using a CA criterion applied to the absolute values of the validated burst transmission BTi samples.

[0137] The normal ranges of burst duration Tburst and bandwidth BW are determined based on burst duration and bandwidth analysis of many types and instances of FSK / LoRa transmissions with the goal to choose parameters that ensure a favorable detection andfalse alarm rates. The ranges are configurable and changing them affects the system performance, creating a tradeoff between correct detection and false alarm rate.

[0138] The constant amplitude (CA) score test is the first threshold-based test of the detection module. In the embodiment of LoRa / FSK detection, the CA test relies on the fact that both FSK and LoRa bursts have a constant amplitude. For given BTi samples of detected data, the CA score, CA SCORE, is defined as:

[0139] CA SCORE = mean(abs(BTi_samples)) / std(abs(BTi_samples)) For an ideal BTi, i.e., not including noise, the standard deviation (std) of abs(Bti_samples) goes to zero, resulting in a very high CA SCORE.

[0140] The CA criterion includes applying a threshold to CA SCORE. The threshold applicable to CA SCORE is determined statistically using many types and instances of FSK and LoRa bursts.

[0141] In step 212, if the burst duration, Tburst, and the estimated bandwidth, BWest. are within the predetermined normal ranges, and the CA score is above the threshold, the single burst transmission BTi is assigned as “valid”, otherwise it is disregarded.

[0142] It is noted that in some embodiments, at least one of steps 204 to 210 described above may utilize an iterative data processing. For example, an iterative step may be added, where (BTi)s that almost pass the conditions (with respect to burst duration, Tburst, bandwidth, BWest. and thresholding of the CA score) go through further processing. Such further processing may, for example, utilize another filter bank with different parameters, and is used to determine whether more criteria can be formulated in a way that supports changing the 'failed (BTi)s' (i.e., to be disregarded) to 'valid (BTi)s' (i.e., (BTi)s passing the conditions of step 212). The iterative step can also be triggered by an input from any following processing steps / modules.

[0143] Reference is made to Fig. 3A showing an exemplary flow diagram 300 of a method of real-time identification of LoRa transmission protocol. In LoRa, each symbol is represented by a cyclic shifted chirp over the frequency interval ( / o-BW / 2, / o+BW / 2) where fo is the center frequency and BW is the bandwidth.

[0144] Fig.3B shows an example of a LoRa burst transmission showing that the symbol value is defined by the frequency -time profile. Specifically, in LoRa the data is carried in the phase component of the burst transmission and the amplitude carries no data. The following unique characteristic parameters of LoRa transmission protocol need to be recovered from the single burst transmission BTi if it was successfully validated duringthe process of burst detection described above with reference to in Fig. 2: a symbol time, TM, a spreading factor, SF, a chirp type, and a number N of repetitions of a basic preamble symbol within a preamble portion of the BTi.

[0145] In step 302 the symbol time, TM, is recovered from the preamble of BTi using autocorrelation. It should be noted that at this stage it is not known whether the burst transmission is LoRa and the duration of the preamble is not known either. It is known, however, that if the burst transmission BTi is LoRa, there should be a preamble portion consisting of N repetitions of a basic preamble symbol, as shown in Fig. 3C. The autocorrelation is performed between a portion of BTi against itself, exposing thereby the repetitions in the preamble portion as demonstrated in Fig. 3D. In the figure, the maximum peak is the signal correlated with itself, with no offset. The next peak is at an offset of a single symbol and the time difference between the peaks equals to TM.

[0146] In step 304, the recovered symbol time, TM, and the estimated value of the bandwidth, BWest, of the burst transmission BTi, are utilized to recover the spreading factor, SF from a relation:

[0147] SF = roimd(log2, BWest• TM)

[0148] It is noted that the estimated bandwidth, BWest, was obtained during the burst detection stage, and although it is not yet accurate, it is accurate enough for recovering the spread factor, SF, since SF is an integer value between 5 and 12.

[0149] In step 306 the approximate spread factor SF and recovered symbol time TM are used to recover accurate bandwidth, BWaCc, using the formula:

[0150]

[0151] The frequency shift (chirp) of LoRa modulation can be performed increasingly (up-chirp) or decreasingly (down-chirp). The chirp type may be identified based on the first part of the preamble. Therefore, in step 308, the chirp type is recovered as being of up-chirp type or down-chirp type by analyzing correlation between the BTi and generated synthetic up-chirp and down-chirp burst transmissions. The option (up-chirp or downchirp) that results in a higher value of the correlation determines the chirp type.

[0152] In step 310, the number N of the repetitions of the basic preamble symbol is recovered by analyzing correlation of the burst transmission BTi with a generated preamble portion of the recovered chirp type. Typically, LoRa transmission preambleincludes N up-chirp or down-chirp symbols, followed by two middle predetermined symbols, and ending with 2.25 symbols whose chirp is opposite to that of the first N symbols, as shown in FIG 3C.

[0153] It should be noted that the LoRa preamble structure shown in Fig. 3C corresponds to a specific digital spread spectrum (or chirp spread spectrum) modulation protocol used by LoRa protocols. This is described in US Patent No. 8,406,275, which is incorporated herein by reference with respect to the LoRa structure.

[0154] In the non-limiting example shown in Fig. 3C, there are 6 repetitions of the basic preamble symbol (i.e., N=6). Once the chirp type has been recovered in step 308, it may be concluded that the last part of the preamble (containing 2.25 symbols) uses the other remaining chirp type.

[0155] Thus, the last portion of the preamble (the part in Fig.3C containing 2.25 symbols) can be generated with the assumed chirp type (i.e., opposite of the recovered chirp type in step 308) and correlated with the actual burst transmission BTi. The result of the correlation is expected to give 2 peaks. The first peak index, divided by the samples_per_symbol (defined by the sampling rate of the correlated BTi) minus 2 symbols (to account for the two symbols in Fig. 3C, ending at 7Tm and 8Tm) gives N.

[0156] It should be noted that the samples_per_symbol value chosen above may be set to any value, depending on the sampling rate of the burst transmission BTi, which can be set to many values as well, as opposed to being dictated by the detector 14.

[0157] The two middle predetermined preamble symbols may be recovered by applying FFT to a de-chirped resampled burst transmission BTi and setting the demodulated signal as the index of the max(abs) value of the resulting FFT.

[0158] In step 312, a (fractional) time start value, to, and a center frequency, fco, of the burst transmission BTi (initially estimated during burst detection phase, e.g., of method 200 in Fig. 2) are optimized using a brute force search and a max score criterion. Initially, to, may be estimated from (tstart, tend) values obtained during burst detection phase, e.g., of method 200 described in Fig. 2 above. Similarly, a center frequency, fco, may be deduced from the ( start, fend) values obtained during burst detection phase, e.g., of method 200 described in Fig. 2 above. However, these initial values need to be refined, i.e., optimized, prior to demodulation. Initial estimations of the time start value, to, and the center frequency, fco, may be obtained by applying threshold and contour detection on data indicative of the burst transmission BTi.The optimization is achieved using a brute-force search which may include the following steps:

[0159] (i) creating corresponding first and second vectors of test timings around to and test frequencies around fco , respectively;

[0160] (ii) iterating through every permutation of the values of the first and second vectors wherein in each iteration:

[0161] (a) creating a corrected burst transmission BTi by applying a corresponding shift in time and frequency domains to the preamble portion of the burst transmission BTi;

[0162] (b) generating a reference preamble using recovered values of the unique characteristic parameters: symbol time, TM, spreading factor, SF, chirp type, and number N of repetitions of a basic preamble symbol within the preamble portion of the BTi;

[0163] (c) multiplying data indicative of the corrected burst transmission BTi and the reference preamble and obtaining a multiplication result;

[0164] (d) applying FFT to the multiplication result and recording the FFT maximum value, wherein for the best tested pair of values, the FFT results in a delta function around / = 0 Hz;

[0165] (iii) determining an optimized time start value, to, being a time start value from the first vector that corresponds to a maximum value out of all the recorded FFT maximum values; and determining an optimized center frequency, fco, being a center frequency from the second vector corresponding to the maximum value out of all the recorded FFT maximum values.

[0166] In step 314, after recovering all the required unique characteristic parameters of LoRa and refining (optimizing) the burst timing and center frequency, extraction (demodulation) of the transmitted LoRa from the single burst transmission BTi is performed.

[0167] A given LoRa symbol xm(t) may be defined as

[0168]

[0169] where B = BWacc. Resampling burst transmission BTi using the recovered values of the l C* bandwidth, BWacc, and spreading factor, SF, and defining: t = - , n = 0, 2^ — 1

[0170] B acc

[0171] results in:

[0172] . n2+2mn

[0173] xm[n] = eJ7T2SFNext, the resampled burst transmission BTi is de-chirped, which may be described as:

[0174] . n2+2mn . n2+2mn j2nmn

[0175] ejn2SF■ eJn2SF=e2SF

[0176] Demodulated symbols are obtained by applying FFT to the de-chirped resampled burst transmission BTi. For each FFT of the extracted (demodulated) symbol, a quality score is calculated, which is then used to determine the correctness of the LoRa identification.

[0177] The calculation of the quality score for the sequence of the (recovered / demodulated) transmitted symbols includes:

[0178] (i) for each FFT of the extracted transmitted LoRa symbol, searching for a maximum value index corresponding to the symbol number, which is actually the demodulated symbol;

[0179] (ii) calculating and recording a corresponding score, defined as a ratio of maximum energy (defined as the value corresponding to the maximum value index found in (i)) and a noise level.

[0180] Fig. 3E shows an example of FFT of de-chirped symbol with a maximum value obtained at index 49, which also corresponds to the demodulated symbol number.

[0181] In step 316, a final mean score of all the recorded scores in step 314 is calculated. This final mean score is used in a thresholding analysis of the quality score to determine a probability of correctness of the identification of the LoRa transmission protocol. A threshold is applied to the final mean score:

[0182] • If the final mean score > threshold, then all LoRa recovered parameters and demodulated symbols are correct;

[0183] • If the final mean score < threshold, then the single burst transmission BTi is not LoRa and all the parameters are discarded.

[0184] The next step includes testing whether the single burst transmission BTi is FSK.

[0185] Reference is made to Fig. 4A showing an exemplary flow diagram 400 of a method of real-time identification of the FSK transmission protocol. FSK encoding carries data only in the phase component. Fig. 4B shows a clean example (no noise) of FSK burst transmission. The repetitive portion (marked with a rectangle) is the preamble. The FSK transmissions dealt with in the present disclosure are of the continuous-phase frequency-shift-keying (CPFSK) type, guaranteeing that the process of switching to a differentfrequency at the beginning of each symbol period preserves the phase. However, for simplicity of presentation, the term “FSK” will be used throughout the description.

[0186] Method 400 starts (step 402) with preprocessing (e.g., by the preprocessor 26) of the single burst transmission BTi using phase derivative, normalization, and smoothing to extract FSK pulse shape. Specifically, initially, the single burst transmission BTi is preprocessed to obtain data indicative of a phase derivative of the burst transmission BTi. Then, the pulse shape is preprocessed by (i) normalization, which includes removing the average value and dividing by the standard deviation, and (ii) smoothing, which includes applying a low-pass filtering to remove noise.

[0187] Deriving the phase component of the burst in the form of (normalized and smoothed) phase derivative,

[0188]

[0189] , shown in Fig. 4C, allows to obtain a signal whose

[0190]

[0191] min / max points represent the 2 -bit values: max - corresponding to ‘1’, and min -corresponding to ‘O’. Also, in Fig. 4C, it can be seen that the max / min points are carried over a basic waveform - the pulse shape.

[0192] In step 404 an initial baud rate estimate, BRo, is extracted from the data indicative of the phase derivative of the burst transmission BTi, obtained in step 402. Specifically, this step includes finding a minimum distance between extrema points of the data and determining an initial value of the baud rate, BRo, as a reciprocal of the minimum distance between extrema points. It is noted that the minimum distance between the extrema points, as shown in Fig. 4D, is the symbol duration which is also the reciprocal of the baud rate.

[0193] In step 406, accurate baud estimation (i.e. optimization) is performed using bruteforce search with a goodness of fit bin-width criterion. This is needed before demodulation (i.e., bit extraction).

[0194] The optimization includes the following steps:

[0195] (i) creating a vector of narrowly-spaced test baud rates, {BRtest}, around BRo; (ii) for each tested baud rate, BRtest, performing the following:

[0196] (a) recording all extrema points in the data indicative of the phase derivative of burst transmission BTi, wherein the extrema points are identified at constant intervals (since a max / min should appear every 1 / baud such that 1 / baud determines the bin width);

[0197] (b) applying absolute value to all the extrema points;(c) calculating and recording an average of the absolute values of all extrema points - this represents the goodness-of-fit bin-width criterion The bin-width criterion relies on the fact that for the correct baud, the bin width is such that results in all bins, centered at extrema points, are being adjacent. This means that alignment on the extrema points is achieved, and thus summing their absolute values results in a high criterion score. For inaccurate / incorrect bauds, the bin width creates bins which do not align with extrema points, thus lowering the criterion score;

[0198] (iii) determining the optimized value of the baud rate, BR, as the tested baud rate, BRtest, corresponding to a maximum value of all the averages of the absolute values of all the extrema points.

[0199] In step 408, the sequence of transmitted symbols (bits) is extracted (demodulated) from the single burst transmission BTi utilizing the optimized value of the baud rate, BR. This demodulation is straightforward and includes repeating the step (refer to step (ii) (a) of the accurate baud estimation step 406 above) of determining and recording all the extrema points in the data indicative of the phase derivative of single burst transmission BTi for the optimized value of the baud rate, BR, and converting each maximum value to ‘ 1’ and each minimum value to ‘O’.

[0200] In step 410, the preamble portion of an FSK-type signal within the single burst transmission BTi, is detected and recovered using correlation. The purpose of the first stage of step 410 is to check whether single burst transmission BTi includes a known / common type of a preamble, called herein “a standard” preamble, since the specific preamble type being used is unknown at this stage.

[0201] The “standard” preamble is characterized by a constant length of “1, 0, 1, 0,...” bit sequence. The inventors have noted that such “standard” preamble is employed by a large number of communication protocols using different FSK types and transmissions. If the standard preamble is not found at this stage, the inventors rely on the fact that every FSK transmission begins with some form of a preamble bit sequence that includes repetitions of some base bit sequences which will be searched for in the next step. However, it is noted that the bits that were extracted in step 408 are not used to test for / confirm any other specific type of preamble.It should be noted that in a case where an FSK-type burst transmission with no preamble is being received (as the case might be), this burst will be ignored / disregarded, i.e., it will not be tagged as 'valid'.

[0202] The standard preamble is recovered using the following steps:

[0203] (i) generating a “1,0,1, 0, ...” bit sequence of a constant length, corresponding to the standard preamble portion of an FSK-type signal, and correlating it with the extracted sequence of transmitted bits;

[0204] (ii) applying a predetermined threshold to determine whether the preamble portion of the single burst transmission BTi corresponds to the standard preamble of the FSK-type or not.

[0205] Fig. 4E shows the correlation results when a standard preamble is present, whereas Fig. 4F shows the respective correlation results when a standard preamble is not present. The method 400 sets a Boolean variable to ‘YES’ or ‘NO’ when, respectively, a standard preamble is found or not.

[0206] In step 412, if the standard preamble is not found, analysis is applied to a preamble portion including repetitions of certain base bit sequences, as described below, and maximum score is calculated using repetition search over start of burst.

[0207] If the standard preamble is found, there is no need to iterate over the base bit sequences and the preamble bit sequence lengths, since they are known from step 410. In this case, only brute force search over preamble starting points is performed in order to calculate the maximum score, as described further below.

[0208] The recovering of the preamble portion of the single burst transmission BTi, wherein the preamble includes repetitions of a certain base bit sequences, is based on a brute force search and includes the following steps:

[0209] (i) generating a vector of preamble bit sequence lengths, PLi;

[0210] (ii) generating a vector of preamble starting points, SPi ;

[0211] (iii) generating a vector of base bit sequence lengths, BBLi;

[0212] (iv) iterating through each triplet of tested values, (PLi, SPi, BBLi) and performing autocorrelations of the single burst transmission BTi, each autocorrelation, ACi, being calculated per tested PLi, SPi, BBLi (noting that autocorrelations are performed only for the vector of preamble starting points, SPi in case the standard preamble was found); (v) recording a maximum score (quality score), defined as a maximum autocorrelation value, max{ACi}, out of all autocorrelations;In step 414, the maximum value of the quality score, max{ACi}, is used in a thresholding analysis to determine a probability of correctness of the identification of the FSK transmission protocol. To this end, a threshold is applied to the maximum score, max{ACi}:

[0213] • If the maximum score, max{ACi} > threshold, then all FSK recovered parameters and demodulated symbols are correct;

[0214] • If the maximum score, max{ACi} < threshold, then the single burst transmission BTi is not FSK, and all the parameters are discarded.

[0215] The technique of the present disclosure is not limited to testing for LoRa / FSK transmission protocols. The inventors found that other modulation techniques, e.g., OFDM may be identified using the technique of the present disclosure. In the following, a method of identifying OFDM modulation in a single burst transmission is exemplified.

[0216] OFDM symbols are inherently different from LoRa / FSK transmission, in that binary data is encoded on multiple carrier frequencies. Fig. 5B shows an example of an OFDM burst transmission as a frequency vs. time image. The demodulation of OFDM symbols is based on FFT. However, in order to determine whether a single burst transmission BTi is of OFDM type, there are many unique characteristic parameters that first need to be recovered. According to the technique of the present disclosure, these parameters are estimated assuming the burst transmission BTi is of OFDM type and then a score test is applied which determines whether the processing steps and recovered parameters are correct.

[0217] The method of the present disclosure includes recovering values of the following OFDM unique characteristic parameters from the single burst transmission BTi: (i) width (i.e., number of samples in a time / frequency window), Nfft, of an FFT window corresponding to each OFDM symbol, (ii) chip rate defined as a sample rate enabling Nfft OFDM subcarriers, (iii) subcarrier spacing (scs), (iv) number of active subcarriers, Nactive, (v) average cyclic prefix (CP) size, Nep, and (vi) number of symbols, Nsym, within the single burst transmission BTi.

[0218] Reference is made to Fig. 5A exemplifying a flow diagram 500 of a method of realtime identification of OFDM transmission protocol.

[0219] In step 502, a single burst transmission BTi is identified in the detected data using an energy detector in the time domain, followed by an energy detector in the frequency domain. It is noted that the method 200 of Fig.2 is only suitable for detecting LoRa / FSKburst transmissions. A different burst detector is required for identifying OFDM bursts. One such detector may be energy based, as indicated above, but other detectors may be found suitable to achieve OFDM burst detection.

[0220] In step 504, the width of the FFT window, Nfft, is recovered based on parameter space grid search for maximum autocorrelation. Fig. 5C shows schematically two transmitted OFDM symbols (OFDM symbol 0 and OFDM symbol 1) where the relative locations of the FFT windows (each having Nfft samples) and the cyclic prefixes (each having Nep samples) attached at the beginning of each symbol, are clearly indicated.

[0221] Thus, the autocorrelation method described below relies on the fact that the OFDM symbol structure has a built-in repetition, i.e., that the first part of each symbol, named ‘cyclic prefix’ (CP) is a copy from the last part of each symbol. The space grid search includes two nested brute force searches, a first brute force search in a range of test FFT windows, {Nffttest} and a second brute force search in a range of test lengths of the cyclic prefix, {Neptest}, as will be described in detail below.

[0222] Fig. 5D shows schematically an OFDM burst transmission and its shifted version by Nfft. The figure shows also the result of an autocorrelation between the two signals with expected maxima appearing every Nfft+Ncp samples.

[0223] Thus, the first brute force search in a range of test FFT windows, {Nffttest}, looks for maximum autocorrelations between the single burst transmission BTi and its shifted versions by Nffttest and includes the following steps:

[0224] (i) for each tested value, Nffttest, performing a second brute force search over a range of correlation lengths represented by a range of test lengths of the cyclic prefix, {Neptest}, and including the following steps:

[0225] (a) calculating the autocorrelation values for all correlation lengths in {Neptest};

[0226] and

[0227] (b) recording the maximum autocorrelation value out of all correlation lengths in {Neptest};

[0228] (ii) locating and recording Nffto defined as the Nffttest for which the maximum of all the maximum autocorrelation values is found in (i);

[0229] (iii) determining an optimized value of Nfft, defined as the closest value, being a power of 2, which meets the requirement: n_fft_vec= [64, 128, 256, 512, 1024, 2048, 4096, ...], such that the optimized value of Nfft, Nfftopt is defined by:

[0230] NfftOpt= n_fft_vec[argmin(abs (Nffto -n_fft_vec))].It is noted that Nfft is updated at the next step, after recovering the chip rate.

[0231] In step 506, the chip rate is recovered based on iterative division according to estimated BW and Nfft. In this connection, reference is made to Fig. 5E showing schematically the chip rate. The chip rate is the sample rate (shown in Fig. 5E as full bandwidth BW) which enables Nfft OFDM subcarriers. Recovering the chip rate includes an iterative initial chip rate, chip rateinit, estimation, updating of the value of Nfftopt, and an optimization of chip rateinit, using brute force searches.

[0232] The iterative chip rateinit estimation includes:

[0233] setting chip rateinit as the input sampling rate;

[0234] performing an iterative process using the bandwidth BW as follows:

[0235] while (chip_rateinit / 2) > BW and Nfft >64:

[0236] chip_rateinit = chip_rateinit / 2

[0237] update Nfft value: Nfft = Nfft / 2;

[0238] In step 508, an accurate chip rate estimate based on a fine grid-search and CP-based autocorrelation is performed. The initial chip rate estimation needs to be refined in order to correctly estimate the remaining parameters. The optimization of the chip rate uses two nested brute force searches and includes the following steps:

[0239] (i) defining a range {chip ratetest} of tested chip rate values for the first brute force search, and performing the first brute force search including:

[0240] (ii) for each tested chip rate value, chip ratetest:

[0241] (a) resampling the single burst transmission BTi from its sample rate to chip_ratetest;

[0242] (b) performing the second brute force search over a range of correlation lengths represented by a range of test lengths of the cyclic prefix, {Neptest}, using the updated value of Nfft, the second brute force search including:

[0243] 1. calculating the autocorrelation values for all correlation lengths in {Neptest};

[0244] 2. recording the maximum autocorrelation value of all correlation lengths in {Neptest};

[0245] (iii) locating and saving an optimized chip rate, chip rateo, defined as the chip ratetest for which the maximum of all the maximum autocorrelation values is found in (ii)(b)2.In step 510, the subcarrier spacing, scs, is recovered, using previously recovered chip rate and Nfft. The subcarrier spacing (scs) is defined as: scs = chip_rateo / Nfftopt. The subcarrier spacing, scs, is demonstrated in Fig. 5F.

[0246] In step 512, the value of the number of active subcarriers, Nactive, is recovered. The estimated bandwidth BW during burst detection and the subcarrier spacing (scs) recovered in step 510, are used to define the value of the number of active subcarriers, Nactive as:

[0247] Nactive= round(BW / scs).

[0248] Nactive is demonstrated in Fig. 5G.

[0249] In step 514, an average cyclic prefix (CP) size, Nep, is recovered using fine grid search and CP -based autocorrelation. Recovering the value of the average CP size includes optimization using a brute force search over a range, {Neptest}, of test lengths of the cyclic prefix, and CP-based autocorrelation, wherein the brute force search includes the following steps:

[0250] (i) resampling the single burst transmission BTi from its sample rate to chip rateo ; (ii) for each tested value, Neptest, performing the following:

[0251] (a) calculating the autocorrelation values for all the cyclic prefixes of length Neptest within the single burst transmission BTi, wherein the shift of BTi for each tested value Neptest is defined by the updated Nfft value; the autocorrelation value being actually an averaged autocorrelation vector given by "folding" and adding at a spacing of (Nfft + Neptest) the regular autocorrelation vector shown in Fig- 5D;

[0252] (b) saving the maximum autocorrelation value per Neptest value;

[0253] (iii) identifying and recording an optimized Nep value defined as the Neptest for which the maximum of all the maximum autocorrelation values found in (ii) is given.

[0254] In step 516, the number of symbols, Nsym, within BTi is recovered, using Nfft, Nep, chip rate and burst duration obtained during burst detection. The number of symbols, Nsym, within the single transmission burst TBi is an integer value defined by the relation:

[0255] Nsym= round( (burst duration * chip_rate) / (Nfft+Ncp)).

[0256] Nsym calculation is demonstrated in a self-explanatory manner in Fig. 5H.

[0257] In step 518, a final mean score is calculated using final parameters (no grid search), using the following steps:

[0258] (i) resampling the single burst transmission BTi from its sample rate to chip rateo;(ii) using Nfft and Nep to calculate the autocorrelation value (e.g., average of peaks in Fig. 5D) obtained between the single burst transmission BTi and its version which was shifted by Nfft;

[0259] (iii) defining the final score (quality score) as the autocorrelation value.

[0260] In step 520, a threshold is applied to the final score defined in step 518, to determine if all OFDM recovered parameters are correct:

[0261] • If final score > threshold, then all OFDM recovered parameters are correct and BTi is of OFDM type;

[0262] • If final score < threshold, then BTi is not of OFDM type and all the parameters are discarded.

[0263] Thus, the present disclosure provides a solution for real-time identification of an unknown transmission protocol embedded in a signal being detected. Moreover, the technique of the present disclosure utilizes assumptions solely on the ranges of parameter values, but otherwise treats all parameters as unknown.

Claims

CLAIMS:

1. A method for real-time identification of an unknown transmission protocol, comprising:providing recorded RF data comprising sampled RF waves being indicative of one or more burst transmissions being detected;providing data indicative of a single burst transmission, BTi, out of one or more burst transmissions being recorded, the single burst transmission having a burst duration and a bandwidth;processing and analyzing said single burst transmission BTi, in accordance with at least one selected transmission protocol type out of a plurality of predetermined transmission protocol types,wherein said processing and analyzing according to the selected transmission protocol type comprises:(i) based on data about unique characteristic parameters characterizing the selected transmission protocol type, recovering from said single burst transmission, one or more of said unique characteristic parameters, and optimizing one or more values of said one or more unique characteristic parameters of the selected transmission protocol type, said optimizing comprising using a predetermined fit criterion to perform at least one of a brute-force search within one or more assumed ranges of parameter values of the selected transmission protocol type and autocorrelation of the single burst transmission BTi; to thereby identify best-fit correlation for each of said one or more values of said one or more unique characteristic parameters and the single burst transmission BTi, thereby obtaining a set of one or more recovered and optimized values of the one or more unique characteristic parameters of the selected transmission protocol type;(ii) utilizing said one or more recovered and optimized values of the one or more unique characteristic parameters to carry out at least one of the following:demodulate a sequence of transmitted symbols from said single burst transmission BTi and determine a quality score for said sequence of transmitted symbols, the quality score being indicative of correctness of symbol demodulation; anddetermine a quality score for at least one of said one or more unique characteristic parameters, the quality score being indicative of correctness of parameter recovery;(iii) applying a predetermined thresholding analysis to said quality score and determining a probability of correctness of the identification of said selected transmission protocol.

2. The method of claim 1, wherein said providing of the data indicative of the single burst transmission, BTi, having the burst duration and the bandwidth, comprises processing the recorded RF data being detected to identify in said recorded RF data the single burst transmission.

3. The method of claim 1 or 2, wherein said processing and analyzing of said single burst transmission BTi, comprises parallel performance of a set of the steps (i) - (iii) in accordance with at least two selected transmission protocol types out of said plurality of predetermined transmission protocol types.

4. The method of any one of the preceding claims, wherein said processing and analyzing of said single burst transmission BTi, further comprises: upon determining that the probability of correctness of the identification of the selected transmission protocol is below a predetermined threshold, performing a set of the steps (i) - (iii) in accordance with another selected transmission protocol type out of said plurality of predetermined transmission protocol types.

5. The method of any one of claims 2 to 4, wherein said processing of the recorded RF data to identify the single burst transmission, BTi, comprises:(a) applying to said recorded RF data a filter bank with chosen parameters and obtaining filter bank’s outputs;(b) averaging and normalizing absolute values of the filter bank’s outputs; (c) applying threshold and contour detection to find time ( / ) and frequency (f) start and end values, (tstart, tend) and ( start, fend), of the single burst transmission, BTi, defining burst duration, Tburst, and estimated bandwidth, BWest, of the single burst transmission BTi;(d) based on the defined burst duration, Tburst, and estimated bandwidth, BWest, validating the single burst transmission BTi, to either accept said single burst transmission BTi for further processing or disregard said single burst transmission BTi.

6. The method of claim 5, wherein said validating of the single burst transmission BTi, comprises: analyzing the burst duration, Tburst, and the estimated bandwidth, BWest, with respect to predetermined normal ranges, and applying a constant amplitude (CA) score test using a CA criterion to the absolute values of validated samples of the single burst transmission BTi.

7. The method of claim 6, wherein said validating of the single burst transmission BTi comprises: assigning “valid” value to the single burst transmission BTi upon identifying that the burst duration, Tburst, the estimated bandwidth, BW, and the CA score satisfy conditions that (1) the burst duration, Tburst , and the estimated bandwidth, BW, are within said predetermined normal ranges, and (2) the CA score is above threshold; and disregarding the single burst transmission BTi upon identifying that at least one of the conditions (1) or (2) is not satisfied.

8. The method of any one of claims 5 to 7, wherein at least one of steps (a) to (d) of the processing of the recorded RF data utilizes an iterative data processing.

9. The method of claim 5, wherein said filter bank is a Short-Time Fourier Transform (STFT).

10. The method of claim 6, wherein said CA score test comprises the following: calculating a constant amplitude score, CA SCORE defined as CA SCORE = mean(abs(BTi_samples)) / std(abs(BTi_samples)); applying threshold to the CA SCORE.

11. The method of anyone of the preceding claims, wherein said selected transmission protocol type is based on Long Range (LoRa) modulation technique.

12. The method of claim 11, wherein said one or more unique characteristic parameters comprises a symbol time, TM, a spreading factor, SF, a chirp type, a number N of repetitions of a basic preamble symbol within a preamble portion of the single burst transmission BTi, and two additional middle symbols of the preamble portion of the single burst transmission BTi.

13. The method of claim 12, wherein said recovering of the one or more unique characteristic parameters from said single burst transmission BTi comprises:applying autocorrelation to recover the symbol time, TM, from the preamble portion of the single burst transmission BTi;utilizing the symbol time, TM, being recovered and an estimated value of the bandwidth, BWest, of the single burst transmission BTi , and recovering the spreading factor, SF from a relation:SF = roimd(log2 , BWest• TM )recovering the bandwidth, BWacc, using a relation:?SFBWacc= — ;1Mrecovering the chirp type as being of up-chirp type or down-chirp type by analyzing correlation between the single burst transmission BTi and generated up-chirp and downchirp burst transmissions;recovering the number N of the repetitions of the basic preamble symbol, by analyzing correlation of the single burst transmission BTi with a generated preamble portion of the recovered chirp type.

14. The method of claim 13, further comprising optimizing a time start value, to, and a center frequency, fco, of the BTi using a brute force search and a max score criterion.

15. The method of claim 14, wherein said optimizing comprises:performing initial estimations of the time start value, to and the center frequency, / co, by applying threshold and contour detection on the recorded data indicative of the single burst transmission BTi;creating corresponding first and second vectors of test timings around the time start value to and test frequencies around the center frequency fco , respectively; iterating through every permutation of values of the first and second vectors, wherein in each iteration:creating a corrected value of the single burst transmission BTi by applying a corresponding shift in time and frequency domains to the preamble portion of the single burst transmission BTi;generating a reference preamble using recovered values of the characteristic parameters: symbol time, TM, spreading factor, SF, chirp type, and number N of repetitions of a basic preamble symbol within the preamble portion of the single burst transmission BTi;multiplying data indicative of the corrected BTi and the reference preamble and obtaining a multiplication result;applying FFT to the multiplication result and recording FFT maximum value;determining an optimized time start value, to, being a time start value from the first vector that corresponds to a maximum value out of all recorded FFT maximum values; and determining an optimized center frequency, fco, being a center frequency from the second vector corresponding to the maximum value out of all the recorded FFT maximum values.

16. The method of claim 15, wherein:said extracting the sequence of the transmitted LoRa symbols from the single burst transmission BTi comprises:resampling the single burst transmission BTi using the recovered value of the bandwidth, BWaCc, and spreading factor, SF, parameters; de-chirping a resampled single burst transmission BTi; and applying FFT thereto;performing said calculation of the score for said sequence of the transmitted symbols by carrying out the following:for each FFT of the extracted transmitted LoRa symbol, searching for a maximum value index corresponding to the symbol number, and calculating and recording a corresponding score defined as a ratio of maximum energy and a noise level;calculating a final mean score of all recorded scores;applying the predetermined thresholding analysis to the final mean score, and determining whether or not all LoRa recovered parameters and extracted symbols are correct.

17. The method of claim 16, wherein said predetermined thresholding analysis is configured to determine the probability of correctness, and upon identifying that said probability of correctness is indicative of that all the LoRa recovered parameters and the extracted symbols are incorrect, performing said processing and analyzing of the single burst transmission BTi for the selected transmission protocol type being Frequency-shift keying (FSK) communication protocol.

18. The method of claim 17, further comprising preprocessing the single burst transmission BTi to obtain data indicative of a phase derivative of BTi.

19. The method of claim 18, wherein said preprocessing comprises: obtaining the phase derivative of the single burst transmission BTi followed by normalization and smoothing thereby obtaining said data indicative of the phase derivative of the single burst transmission BTi.

20. The method of any one of claims 17 to 19, wherein said one or more unique characteristic parameters comprises baud rate, BRo.

21. The method of claim 20, wherein said recovering of the baud rate, BRo from the data indicative of the phase derivative of the single burst transmission BTi comprises finding a minimum distance between extrema points of said data and determining an initial value of the baud rate as a reciprocal of the minimum distance between extrema points.

22. The method of claim 21, wherein the optimizing of the initial value of the baud rate, BRo, comprises the brute force search of the best-fit with a bin-width criterion, wherein the brute force search comprises:creating a vector of narrowly-spaced test baud rates, {BRtest}, around BRo ; for each tested baud rate BRtest, performing the following:recording all extrema points in the data indicative of the phase derivative of the single burst transmission BTi, wherein the extrema points are identified at constant intervals;applying absolute value to all the extrema points;calculating and recording an average of the absolute values of all extrema points;determining the optimized value of the baud rate, BR, as the tested baud rate, BRtest, corresponding to a maximum value of all averages of the absolute values of all the extrema points.

23. The method of claim 22, wherein said extracting of the sequence of the transmitted symbols from the single burst transmission BTi utilizes the optimized value of the baud rate, BR, and comprises: determining all the extrema points in the data indicative of phase derivative of the single burst transmission BTi for the optimized value of the baud rate, BR; and converting each maximum value to ‘ 1’ and each minimum value to ‘O’.

24. The method of claim 23, further comprising detecting and recovering a standard preamble portion of an FSK-type signal within the single burst transmission BTi, using correlation, said detecting and recovering comprising:generating a “1,0, 1,0,...” bit sequence corresponding to the standard preamble portion of an FSK-type signal, and correlating said sequence being generated with the extracted sequence of the transmitted symbols;applying a predetermined threshold to determine whether the preamble portion of the single burst transmission BTi corresponds to the standard preamble of the FSK-type or not.

25. The method of claim 24, further comprising recovering the preamble portion of the single burst transmission BTi comprising repetitions of a certain base bit sequences, said recovering being based on a brute force search and comprising:generating a vector of preamble bit sequence lengths, PLi;generating a vector of preamble starting points, SPi ;generating a vector of base bit sequence lengths, BBLi;iterating through each triplet of tested values, (PLi, SPi, BBLi) and performing the autocorrelations of the single burst transmission BTi, each autocorrelation ACi being calculated per the triplet of the tested values PLi, SPi, BBLi;recording a maximum score, defined as a maximum autocorrelation value, Max{ACi}, out of all autocorrelations;applying the predetermined thresholding analysis to said maximum score, Max{ACi}, and determining the probability of correctness of the identification of said unknown transmission protocol as FSK transmission protocol.

26. The method of claim 1, wherein said selected transmission protocol type is Orthogonal Frequency Division Multiplexing (OFDM) communication protocol.

27. The method of claim 26, wherein said providing of the data indicative of the single burst transmission, BTi, having the burst duration and the bandwidth comprises processing the recorded data being detected to identify in said recorded data the single burst transmission.

28. The method of claim 27, wherein said identifying of the single burst transmission, BTi, in the recorded data being detected comprises utilizing an energy detector in the time domain, followed by an energy detector in the frequency domain.

29. The method of claim 28, wherein said recovering comprises recovering values of the following OFDM characteristic parameters from said single burst transmission BTi: width, Nfft, of an FFT window corresponding to each OFDM symbol; chip rate defined as a sample rate enabling Nfft OFDM subcarriers; subcarrier spacing (scs); number ofactive subcarriers, Nactive; average cyclic prefix (CP) size, Nep; and number of symbols, Nsym, within the single burst transmission BTi.

30. The method of claim 29, wherein recovering the width, Nfft, of the FFT window corresponding to each OFDM symbol comprises a first brute force search in a range of test FFT windows, {Nffttest}, for maximum autocorrelations between the single burst transmission BTi and its shifted versions by Nffttest, said first brute force search comprising:for each tested value, Nffttest, performing a brute force search over a range of correlation lengths represented by a range of test lengths of the cyclic prefix, {Neptest}, by carrying out the following:calculating the autocorrelation values for all correlation lengths in {Neptest}; andrecording the maximum autocorrelation value out of all correlation lengths in {Neptest};locating and recording Nffto defined as the Nffttest for which the maximum of all the maximum autocorrelation values is found in (a);determining an optimized value of Nfft defined as the closest value, being a power of 2, which meets the requirement: n_fft_vec= [64, 128, 256, 512, 1024, 2048, 4096, ...], such that (Nfft)Opt= n_fft_vec[argmin(abs (NfftO -n_fft_vec))].

31. The method of claim 30, wherein recovering the chip rate comprises an iterative initial chip rate, chip rateinit, estimation, update of the value of (Nfft)opt, and an optimization of the initial chip rate, chip rateinit, estimation using brute force searches, 32. The method of claim 31, wherein:the iterative initial chip rate estimation comprises:setting chip rateinit as the input sampling rate;performing an iterative process using the bandwidth BW as follows:while (chip_rateinit / 2) > BW and Nfft >64:chip_rateinit = chip_rateinit / 2update Nfft value: Nfft = Nfft / 2;the optimization using brute force searches comprises running first and second brute force searches by performing the following:defining a range {chip ratetest} of tested chip rate values for the first brute force search, and performing the first brute force search comprising: for each tested chip ratevalue, chip ratetest: resampling the single burst transmission BTi from its sample rate to chip_ratetest; andperforming the second brute force search over a range of correlation lengths represented by a range of test lengths of the cyclic prefix, {Neptest}, using the updated value of Nfft, said second brute force search comprising: calculating the autocorrelation values for all correlation lengths in {Neptest}; and recording the maximum autocorrelation value of all correlation lengths in {Neptest};locating and saving an optimized chip rate, chip rateo, defined as the chip ratetest for which the maximum of all the maximum autocorrelation values is found.

33. The method of claim 32, wherein recovering the value of the subcarrier spacing (scs) comprises: using the recovered values of the chip rate and Nfft to define subcarrier spacing (scs) as: scs = chip_rateo / Nfft.

34. The method of claim 33, wherein recovering the value of the number of active subcarriers, Nactive, comprises using the estimated bandwidth BW and the subcarrier spacing (scs) to define the value of the number of active subcarriers, Nactive as: Nactive= round(BW / scs).

35. The method of claim 34, wherein recovering the value of the average cyclic prefix (CP) size, Nep, comprises optimization using a brute force search over a range, {Neptest}, of test lengths of the cyclic prefix, and CP -based autocorrelation, wherein the brute force search comprises:resampling the single burst transmission BTi from its sample rate to chip rateo ; for each tested value, Neptest, performing the following:calculating the autocorrelation values for all the cyclic prefixes of length Neptest within the single burst transmission BTi, wherein the shift of BTi for each tested value Neptest is defined by the updated Nfft value;saving the maximum autocorrelation value per Neptest value; identifying and recording an optimized Nep value defined as the Neptest for which the maximum of all the maximum autocorrelation values.

36. The method of claim 35, wherein recovering the value of the number of symbols, Nsym, within the single transmission burst BTi comprises using the burst duration, and the recovered parameters Nfft, Nep, and the chip rate to calculate an integer value of Nsym using a relation:Nsym= round( (burst duration * chip rate) / (Nfft+Ncp)).

37. The method of claim 36, further comprising:calculating a final score using the recovered parameters, wherein the calculating of the final score comprises:resampling the single burst transmission BTi from its sample rate to chip_rateo;using Nfft and Nep to calculate the autocorrelation value obtained between the single burst transmission BTi and its version which was shifted by Nfft; defining the final score as the autocorrelation value;applying a threshold to the final score to determine whether all OFDM parameters are correct.

38. A computerized system configured and operable to implement the method of any one of the preceding claims for real-time identification of an unknown transmission protocol.

39. A system for real-time identification of an unknown transmission protocol, the system comprising a computerized system which comprises a processing and memory circuitry comprising at least one analyzer configured and operable to identify whether one or more burst transmissions of RF data relate to one of K (K>1) predetermined transmission protocols; the analyzer comprising:a recovery utility configured and operable to carry out the following: recover, from recorded RF data being detected, data indicative of a single burst transmission, BTi, having a burst duration and a bandwidth; and utilize data about unique characteristic parameters of a selected transmission protocol type to recover, from said single burst transmission, one or more of said unique characteristic parameters and optimize one or more values of said one or more unique characteristic parameters of the selected transmission protocol type, said optimizing comprising using a predetermined fit criterion to perform at least one of a brute-force search within one or more assumed ranges of parameter values of the selected transmission protocol type and autocorrelation of the single burst transmission BTI; to thereby identify best-fit correlation for each of said one or more values of said one or more unique characteristic parameters and the single burst transmission BTi; thereby obtaining a set of one or more recovered and optimized values of the one or more unique characteristic parameters of the selected transmission protocol type;a demodulation utility configured and operable to analyze said one or more values of the one or more recovered and optimized unique characteristic parameters to carry out at least one of the following: demodulate a sequence of transmitted symbols from said single burst transmission and determine a quality score for said sequence of transmitted symbols, the quality score being indicative of correctness of symbol demodulation; and determine a quality score for at least one of said one or more unique characteristic parameters, the quality score being indicative of correctness of parameter recovery; a verification utility configured and operable to apply a predetermined thresholding analysis to said quality score and determine a probability of correctness of the identification of said selected transmission protocol.

40. The system of claim 39, comprising a burst identifier which is responsive to the recorded data indicative of one or more burst transmissions being detected with a sampling rate, to identify in the recorded data a single burst transmission, BTi, out of said one or more burst transmissions, the single burst transmission having the burst duration and the bandwidth.

41. The system of claim 39 or 40, wherein said analyzer is configured and operable for parallel performance of said recovering, extraction and thresholding analysis in accordance with at least two selected transmission protocol types out of said plurality of predetermined transmission protocol types.

42. The system of any one of claims 39 to 41, wherein said analyzer is further configured to operable to carry out the following: upon determining that the probability of correctness of the identification of the selected transmission protocol is below a predetermined threshold, performing said recovering, extraction and thresholding analysis in accordance with another selected transmission protocol type out of said plurality of predetermined transmission protocol types.

43. The system of any one of claims 40 to 42, wherein said burst identifier is configured and operable to carry out the following to identify the single burst transmission, BTi:applying to said recorded RF data a filter bank with chosen parameters and obtaining filter bank’s outputs;averaging and normalizing absolute values of the filter bank’s outputs;applying threshold and contour detection to find time (7) and frequency ( ) start and end values, (tsta t, tend) and ( start, fend), of the single burst transmission, BTi, defining burst duration, Tburst, and estimated bandwidth, BWest, of the single burst transmission BTi; based on the defined burst duration, Tburst, and estimated bandwidth, BWest, validating the single burst transmission BTi, to either accept said single burst transmission BTi for further processing or disregard said single burst transmission BTi.

44. The system of claim 43, wherein said burst identifier is configured and operable to perform said validating of the single burst transmission BTi, by analyzing the burst duration, Tburst, and the estimated bandwidth, BWest, with respect to predetermined normal ranges, and applying a constant amplitude (CA) score test using a CA criterion to the absolute values of validated samples of the burst transmission BTi.

45. The system of claim 44, wherein said burst identifier is configured and operable to carrying out the following: assigning “valid” value to the single burst transmission BTi upon identifying that the burst duration, Tburst , the estimated bandwidth, BW, and the C A score satisfy conditions that the burst duration, Tburst, and the estimated bandwidth, BW, are within said predetermined normal ranges, and the CA score is above threshold; and disregarding the single burst transmission BTi upon identifying that at least one of said conditions is not satisfied.

46. The system of any one of claims 43 to 45, wherein the burst identifier is configured and operable to perform an iterative data processing.

47. The system of claim 43, wherein said filter bank is a Short-Time Fourier Transform (STFT).

48. The system of claim 44, wherein said burst identifier is configured and operable to perform said CA score test by:calculating a constant amplitude score, CA SCORE defined as CA SCORE = mean(abs(BTi_samples)) / std(abs(BTi_samples)); applying threshold to the CA SCORE.

49. The system of anyone of claims 39 to 48, wherein said analyzer is configured and operable to identify the transmission protocol type based on Long Range (LoRa) modulation technique.

50. The system of claim 49, wherein said one or more unique characteristic parameters comprises a symbol time, TM, a spreading factor, SF, a chirp type, a numberN of repetitions of a basic preamble symbol within a preamble portion of the BTi, and two additional middle symbols of the preamble portion of the BTi.

51. The system of claim 50, wherein said recovery utility is configured and operable to recover the one or more unique characteristic parameters from said single burst transmission by carrying out the following:applying autocorrelation to recover the symbol time, TM, from the preamble portion of the BTi;utilizing the symbol time, TM, being recovered and an estimated value of the bandwidth, BWest, of the BTi , and recovering the spreading factor, SF from a relation:SF = roimd(log2 , BWest• TM )recovering the bandwidth, BWacc, using a relation:?SFBWacc= — ;1Mrecovering the chirp type as being of up-chirp type or down-chirp type by analyzing correlation between the BTi and generated up-chirp and down-chirp burst transmissions;recovering the number N of the repetitions of the basic preamble symbol, by analyzing correlation of the BTi with a generated preamble portion of the recovered chirp type.

52. The system of claim 51, wherein said recovery utility is configured and operable to utilize a brute force search and a max score criterion to optimize a time start value, to, and a center frequency, fco, of the BTi.

53. The system of claim 52, wherein said recovery utility is configured and operable to carry out the following:performing initial estimations of the time start value, to and the center frequency, / co, by applying threshold and contour detection on the recorded data indicative of the BTi;creating corresponding first and second vectors of test timings around the time start value to and test frequencies around the center frequency fco , respectively; iterating through every permutation of values of the first and second vectors, wherein in each iteration:creating a corrected BTi by applying a corresponding shift in time and frequency domains to the preamble portion of the BTi;generating a reference preamble using recovered values of the characteristic parameters: symbol time, TM, spreading factor, SF, chirp type, and number N of repetitions of a basic preamble symbol within the preamble portion of the BTi;multiplying data indicative of the corrected BTi and the reference preamble and obtaining a multiplication result;applying FFT to the multiplication result and recording FFT maximum value;determining an optimized time start value, to, being a time start value from the first vector that corresponds to a maximum value out of all recorded FFT maximum values; and determining an optimized center frequency, fco, being a center frequency from the second vector corresponding to the maximum value out of all the recorded FFT maximum values.

54. The system of claim 53, wherein said recovery utility is configured and operable to carry out the following:performing said extracting of the sequence of the transmitted LoRa symbols by resampling the BTi using the recovered value of the bandwidth, BWacc, and spreading factor, SF, parameters; de-chirping a resampled BTi; and applying FFT thereto; and performing said calculation of the score for said sequence of the transmitted symbols by carrying out the following:for each FFT of the extracted transmitted LoRa symbol, searching for a maximum value index corresponding to the symbol number, and calculating and recording a corresponding score defined as a ratio of maximum energy and a noise level;calculating a final mean score of all recorded scores;applying the predetermined thresholding analysis to the final mean score, and determining whether or not all LoRa recovered parameters and extracted symbols are correct.

55. The system of claim 54, wherein said verification utility is configured and operable to determine the probability of correctness, and upon identifying that said probability of correctness is indicative of that all the LoRa recovered parameters and the extracted symbols are incorrect, perform said processing and analyzing of the single bursttransmission BTi for the selected transmission protocol type being Frequency-shift keying (FSK) communication protocol.

56. The system of claim 55, wherein said analyzer further comprises a pre-processor configured and operable to preprocess the data indicative of the single burst transmission BTi to obtain data indicative of a phase derivative of the BTi.

57. The system of claim 56, wherein said pre-processor is configured and operable to obtain the phase derivative of BTi and perform normalization and smoothing thereof to thereby obtaining said data indicative of the phase derivative of BTi.

58. The system of any one of claims 55 to 57, wherein said one or more unique characteristic parameters comprises baud rate, BRo.

59. The system of claim 58, wherein said recovery utility is configured and operable for recovering the baud rate, BRo from the data indicative of the phase derivative of BTi by finding a minimum distance between extrema points of said data and determining an initial value of the baud rate as a reciprocal of the minimum distance between extrema points.

60. The system of claim 59, wherein said recovery utility is configured and operable for optimizing the initial value of the baud rate, BRo, by performing the brute force search of the best-fit with a bin-width criterion, the brute force search comprising:creating a vector of narrowly-spaced test baud rates, {BRtest}, around BRo ; for each tested baud rate BRtest, performing the following:recording all extrema points in the data indicative of the phase derivative of BTi, wherein the extrema points are identified at constant intervals;applying absolute value to all the extrema points;calculating and recording an average of the absolute values of all extrema points;determining the optimized value of the baud rate, BR, as the tested baud rate, BRtest, corresponding to a maximum value of all averages of the absolute values of all the extrema points.

61. The system of claim 60, wherein the recovery utility is configured and operable to perform said extracting of the sequence of the transmitted symbols from the single burst transmission BTi by utilizing the optimized value of the baud rate, BR, and determining all the extrema points in the data indicative of phase derivative of BTi forthe optimized value of the baud rate, BR; and converting each maximum value to ‘ 1’ and each minimum value to ‘O’.

62. The system of claim 61, wherein the recovery utility is configured and operable to detect and recover a standard preamble portion of an FSK-type signal within the single burst transmission BTi, using correlation and carrying out the following:generating a “1,0, 1,0,...” bit sequence corresponding to the standard preamble portion of an FSK-type signal, and correlating said sequence being generated with the extracted sequence of the transmitted symbols;applying a predetermined threshold to determine whether the preamble portion of the BTi corresponds to the standard preamble of the FSK-type or not.

63. The system of claim 62, wherein the recovery utility is configured and operable to recover the preamble portion of the single burst transmission BTi comprising repetitions of a certain base bit sequences, by utilizing a brute force search and performing the following:generating a vector of preamble bit sequence lengths, PLi;generating a vector of preamble starting points, SPi ;generating a vector of base bit sequence lengths, BBLi;iterating through each triplet of tested values, (PLi, SPi, BBLi) and performing autocorrelations of the single burst transmission BTi, each autocorrelation ACi being calculated per the triplet of the tested values PLi, SPi, BBLi;recording a maximum score, defined as a maximum autocorrelation value, Max{ACi}, out of all autocorrelations;applying the predetermined thresholding analysis to said maximum score, Max{ACi}, and determining the probability of correctness of the identification of said unknown transmission protocol as FSK transmission protocol.

64. The system of claim 39, wherein said selected transmission protocol type is Orthogonal Frequency Division Multiplexing (OFDM) communication protocol.

65. The system of claim 64, comprising a burst identifier configured and operable to process the recorded data being detected to identify in said recorded data the single burst transmission having the burst duration and the bandwidth.

66. The system of claim 65, wherein said burst identifier is configured and operable to utilize an energy detector in the time domain, followed by an energy detector in the frequency domain.

67. The system of claim 66, wherein said recover utility is configured and operable to recover values of the following OFDM characteristic parameters from said single burst transmission BTi: (i) width, Nfft, of an FFT window corresponding to each OFDM symbol, (ii) chip rate defined as a sample rate enabling Nfft OFDM subcarriers, (iii) subcarrier spacing (scs), (iv) number of active subcarriers, Nactive, (v) average cyclic prefix (CP) size, Nep, and (vi) number of symbols, Nsym, within the single burst transmission BTi.

68. The system of claim 67, wherein said recover utility is configured and operable to recover the width, Nfft, of the FFT window corresponding to each OFDM symbol by performing a first brute force search in a range of test FFT windows, {Nffttest}, for maximum autocorrelations between the single burst transmission BTi and its shifted versions by Nffttest, said first brute force search comprising:(a) for each tested value, Nffttest, performing a brute force search over a range of correlation lengths represented by a range of test lengths of the cyclic prefix, {Neptest}, by carrying out the following:calculating the autocorrelation values for all correlation lengths in {Neptest}; andrecording the maximum autocorrelation value out of all correlation lengths in {Neptest};(b) locating and recording Nffto defined as the Nffttest for which the maximum of all the maximum autocorrelation values is found in (a);(c) determining an optimized value of Nfft defined as the closest value, being a power of 2, which meets the requirement: n_fft_vec= [64, 128, 256, 512, 1024, 2048, 4096, ...], such that (Nfft)opt= n_fft_vec[argmin(abs (NfftO -n_fft_vec))].

69. The system of claim 68, wherein said recover utility is configured and operable to recover the chip rate by performing an iterative initial chip rate, chip rateinit, estimation, update of the value of (Nfft)opt, and an optimization of the initial chip rate, chip rateinit, estimation using brute force searches.

70. The system of claim 69, wherein:the iterative initial chip rate estimation comprises:setting chip rateinit as the input sampling rate;performing an iterative process using the bandwidth BW as follows:while (chip_rateinit / 2) > BW and Nfft >64:chip_rateinit = chip_rateinit / 2update Nfft value: Nfft = Nfft / 2;the optimization using brute force searches comprises running first and second brute force searches by performing the following :(a) defining a range {chip ratetest} of tested chip rate values for the first brute force search, and performing the first brute force search comprising: for each tested chip rate value, chip ratetest: resampling the single burst transmission BTi from its sample rate to chip ratetest; andperforming the second brute force search over a range of correlation lengths represented by a range of test lengths of the cyclic prefix, {Neptest}, using the updated value of Nfft, said second brute force search comprising: calculating the autocorrelation values for all correlation lengths in {Neptest}; and recording the maximum autocorrelation value of all correlation lengths in {Neptest};(b) locating and saving an optimized chip rate, chip rateo, defined as the chip ratetest for which the maximum of all the maximum autocorrelation values is found in (a).

71. The system of claim 70, wherein said recover utility is configured and operable to recover the value of the subcarrier spacing (scs) by using the recovered values of the chip rate and Nfft to define subcarrier spacing (scs) as: scs = chip_rateo / Nfft.

72. The system of claim 71, wherein said recover utility is configured and operable to recover the value of the number of active subcarriers, Nactive, by using the estimated bandwidth BW and the subcarrier spacing (scs) to define the value of the number of active subcarriers, Nactive as: Nactive= round(BW / scs).

73. The system of claim 72, wherein said recover utility is configured and operable to recover the value of the average cyclic prefix (CP) size, Nep, by optimization using a brute force search over a range, {Neptest}, of test lengths of the cyclic prefix, and CP-based autocorrelation, wherein the brute force search comprises:(a) resampling the single burst transmission BTi from its sample rate to chip_rateo ;(b) for each tested value, Neptest, performing the following:calculating the autocorrelation values for all the cyclic prefixes of length Neptest within the single burst transmission BTi, wherein the shift of BTi for each tested value Neptest is defined by the updated Nfft value;saving the maximum autocorrelation value per Neptest value;(c) identifying and recording an optimized Nep value defined as the Neptest for which the maximum of all the maximum autocorrelation values found in (b) is given.

74. The system of claim 73, wherein said recover utility is configured and operable to recover the value of the number of symbols, Nsym, within the single transmission burst BTi by using the burst duration, and the recovered parameters Nfft, Nep, and the chip rate to calculate an integer value of Nsym using a relation:Nsym= round( (burst duration * chip rate) / (Nfft+Ncp)).

75. The system of claim 74, wherein said analyzer is further configured and operable to carry out the following:calculating a final score using the recovered parameters, wherein the calculating of the final score comprises: resampling the single burst transmission BTi from its sample rate to chip rateo; using Nfft and Nep to calculate the autocorrelation value obtained between the single burst transmission BTi and its version which was shifted by Nfft; defining the final score as the autocorrelation value; andapplying a threshold to the final score to determine whether all OFDM parameters are correct.