Dynamic key-based underground UWB positioning system hybrid encryption method
By adopting a hybrid encryption method with dynamic keys in the underground UWB positioning system, combined with RSA and AES algorithms, the data security and real-time problems of the underground UWB positioning system in complex environments are solved, and full-process security reinforcement, end-to-end full-frame encryption and key lightweight expansion are achieved to adapt to the high-frequency additions, deletions and location changes of underground equipment.
Patent Information
- Application Number
- CN202511009212.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-22
- Publication Date
- 2025-09-12
AI Technical Summary
In tunnel environments with dense metal structures and complex electromagnetic interference, the UWB precise positioning system in underground coal mines faces the dual threats of positioning data being intercepted and tampered with, and signal synchronization failure. Existing encryption schemes have problems such as high latency, susceptibility to attacks, poor scalability, and weak anti-interference capabilities.
A hybrid encryption method with dynamic keys is adopted, combining RSA and AES encryption algorithms. The terminal generates an RSA key pair and encrypts the AES key using the RSA public key. The base station dynamically allocates the AES key to achieve full-frame encryption and timestamp protection, building a three-level defense system to ensure the security of key distribution and data transmission during the ranging phase.
It achieves full-process security reinforcement in underground environments, end-to-end full-frame encryption protection, lightweight dynamic expansion of keys, multi-dimensional attack defense, and temporal decoupling of security and performance, adapting to scenarios with high-frequency additions, deletions, and location changes of underground equipment.
Smart Images

Figure CN120640277A_ABST
Abstract
Description
Technical Field
[0001] The invention belongs to the technical field of UWB positioning, and relates to a hybrid encryption method of an underground UWB positioning system based on a dynamic key. Background Art
[0002] In underground coal mines, UWB precision positioning systems face the dual threats of intercepted and tampered positioning data and signal synchronization failure in tunnel environments with dense metal structures and complex electromagnetic interference. While UWB technology can achieve centimeter-level positioning accuracy, its open channel nature allows attackers to forge coordinates, triggering false locks or collisions. Existing encryption schemes suffer from fundamental contradictions: asymmetric encryption significantly exceeds the UWB frame synchronization window tolerance due to high computational latency, resulting in positioning trajectory fragmentation. While symmetric encryption meets real-time requirements, its reliance on unencrypted channels for key distribution makes it vulnerable to man-in-the-middle attacks. Furthermore, static encryption strategies struggle to adapt to the dynamic interference of tunnel multipath and electromagnetic noise. Signal distortion caused by metal obstacles directly leads to decryption failures and positioning drift.
[0003] Current technologies suffer from systemic flaws: centralized key management mechanisms are rigid, requiring rewiring to add new nodes and exhibiting poor scalability, while static key distribution can be easily cracked through brute force. The single-choice encryption algorithm leads to a balance between security and energy efficiency. Asymmetric encryption power consumption becomes a significant bottleneck for device battery life, while symmetric encryption poses security risks due to key management vulnerabilities. Fixed encryption modes exhibit weak interference resistance in complex areas such as lane turns, and insufficient environmental adaptability leads to frequent data packet loss. Therefore, a hybrid encryption mechanism combining low latency, interference resistance, and scalability is urgently needed to ensure the end-to-end security of UWB positioning data while meeting the mine's high-real-time, low-power communication requirements. Summary of the Invention
[0004] In view of this, the purpose of the present invention is to provide a hybrid encryption method for an underground UWB positioning system based on dynamic keys, aiming to solve core problems such as the risk of man-in-the-middle attacks in the key distribution process, the real-time bottleneck caused by the high latency of asymmetric encryption, and the difficulty of static key strategies to adapt to the dynamic interference environment of the tunnel.
[0005] In order to achieve the above object, the present invention provides the following technical solutions:
[0006] A hybrid encryption method for an underground UWB positioning system based on a dynamic key includes the following steps:
[0007] Phase 1: Key security distribution phase:
[0008] The positioning terminal randomly generates an RSA key pair before joining the network and sends the RSA public key to the positioning base station by broadcasting a network application frame;
[0009] After receiving the RSA public key, the base station randomly generates an AES key dedicated to the terminal, and RSA encrypts the AES key with the RSA public key provided by the terminal to form an encrypted AES key, and then embeds the encrypted AES key into the network access response frame and returns it to the terminal;
[0010] The terminal uses its own RSA private key to decrypt the encrypted field in the network access response frame and obtain the original AES key;
[0011] Phase 2: Ranging Phase:
[0012] Two-way time-of-flight (TW-TOF) measurement is performed, and all data is protected end-to-end using AES encryption and decryption mechanisms.
[0013] Furthermore, after receiving the RSA public key and randomly generating an AES key exclusive to the terminal, the base station binds the terminal ID, the RSA public key, and the AES key and stores the mapping relationship.
[0014] Furthermore, the RSA key pair includes an RSA private key and an RSA public key, wherein the RSA private key never leaves the terminal, and the RSA public key allows plain text broadcasting.
[0015] Furthermore, the RSA private key and the RSA public key are bound to the terminal until the terminal is disconnected from the network.
[0016] Furthermore, the AES key is forced to be updated each time the terminal rejoins the network, and the key is not rotated during a single ranging.
[0017] Furthermore, after the terminal exits the network, the base station erases the AES key of the terminal.
[0018] Furthermore, the ranging phase specifically includes the following steps:
[0019] The terminal generates a Poll frame, encrypts the entire frame using the AES key, sends the ciphertext to the base station via UWB, and records the sending timestamp T send1 ;
[0020] After receiving the Poll ciphertext, the base station uses the AES key to decrypt it to obtain the plaintext and records the receiving timestamp T recv1 ;
[0021] The base station generates a Response frame, encrypts the entire frame using the AES key, returns it to the terminal via UWB, and records the sending timestamp T send2 ;
[0022] After the terminal decrypts the Response frame using the AES key, it records the receiving timestamp T recv2 ;
[0023] The terminal generates a Final frame, encrypts the entire frame using the AES key, and sends it to the base station via UWB;
[0024] After the base station decrypts the Final frame using the AES key, it records the receiving timestamp T recv3 ;
[0025] The base station is based on the two-way time of flight principle and uses six time stamps T send1 、T recv1 、T send2 、T recv2 、T send3 、T recv3 Calculate the terminal position.
[0026] The beneficial effects of the present invention are:
[0027] [1] Security is reinforced throughout the entire process. This patent establishes a dual protection mechanism in the key distribution and ranging stages: the terminal locally generates and strictly isolates the RSA private key to eliminate the risk of core key leakage; the base station dynamically allocates exclusive AES keys and transmits them through RSA public key encryption, completely blocking man-in-the-middle attacks; the timestamp in the ranging stage is transmitted through AES encryption throughout the entire process to ensure that key data cannot be tampered with, forming a three-level in-depth defense system for terminals, transmission, and base stations;
[0028] [2] End-to-end full-frame encryption protection. This solution adopts a full-frame encryption strategy to fully encrypt the Poll, Response, and Final frames in the UWB ranging process (including frame headers, timestamps, and checksum fields). This design completely eliminates the risk of attackers launching protocol vulnerability attacks (such as frame type spoofing and timing tampering) by parsing the frame header structure. By combining dynamic AES keys (generated by the base station and distributed through RSA encryption) with hardware-level encryption acceleration modules, nanosecond encryption delays are achieved, ensuring that security and real-time performance are achieved simultaneously;
[0029] [3] Lightweight and dynamic key expansion. Relying on a hierarchical architecture of "static RSA + dynamic AES" to achieve resource optimization: the terminal only needs to generate an RSA key once and has a built-in lightweight AES module; the base station manages thousands of terminal keys through a terminal ID-public key-private key triple mapping table. When a new terminal joins the network, it automatically broadcasts the public key to trigger dynamic key distribution. The system does not require a centralized key controller, significantly reducing deployment costs and adapting to scenarios where underground equipment is frequently added, deleted, and relocated.
[0030] [4] Active defense against multi-dimensional attacks. Through the collaborative design of encryption process and key mechanism, multiple threats can be resisted: RSA-encrypted AES key distribution can resist middleman eavesdropping; dynamic timestamp binding and key session isolation can suppress replay attacks; terminal-specific keys and the instant destruction mechanism after network exit can block the spread of brute force attacks; three-factor binding verification can eliminate the risk of counterfeit terminals, and build a full-cycle defense network covering key distribution, data transmission, and identity authentication.
[0031] [5] Timing decoupling of security and performance. By separating the key distribution and ranging phases, the computationally demanding RSA encryption / decryption is confined to the non-real-time handshake phase, while only microsecond-level AES encryption and decryption operations are performed during real-time ranging. This design overcomes the traditional contradiction that high-intensity encryption inevitably sacrifices real-time performance.
[0032] Other advantages, objects, and features of the present invention will be described in part in the following description and, in part, will be apparent to those skilled in the art upon examination of the following description or may be learned from practice of the present invention. The objects and other advantages of the present invention may be realized and obtained through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] In order to make the purpose, technical solutions and advantages of the present invention more clear, the present invention will be described in detail below with reference to the accompanying drawings, in which:
[0034] Figure 1 Schematic diagram of the encryption process;
[0035] Figure 2 Figure 1 is a diagram of the key distribution process;
[0036] Figure 3 Diagram of the encrypted communication process in the ranging phase;
[0037] Figure 4 Schematic diagram of the key management mechanism. DETAILED DESCRIPTION
[0038] The following describes the embodiments of the present invention by means of specific examples, and those skilled in the art can easily understand other advantages and effects of the present invention from the contents disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments, and the details in this specification can also be modified or changed in various ways based on different viewpoints and applications without departing from the spirit of the present invention. It should be noted that the illustrations provided in the following embodiments are only schematic illustrations of the basic concept of the present invention, and the following embodiments and features in the embodiments can be combined with each other without conflict.
[0039] It should be noted that the illustrations provided in the following embodiments are merely schematic illustrations of the basic concept of the present invention. Therefore, the illustrations only show components related to the present invention and are not drawn according to the number, shape, and size of components in actual implementation. In actual implementation, the type, quantity, and proportion of each component may be changed arbitrarily, and the component layout may also be more complex.
[0040] In the following description, numerous details are discussed to provide a more thorough explanation of the embodiments of the present invention. However, it will be apparent to those skilled in the art that the embodiments of the present invention may be practiced without these specific details. In other embodiments, well-known structures and devices are shown in block diagram form rather than in detail to avoid obscuring the embodiments of the present invention.
[0041] Example 1:
[0042] The present invention provides a hybrid encryption method for an underground UWB positioning system based on a dynamic key, such as Figure 1 As shown, this method achieves secure communication through a dynamic key hierarchy mechanism: before joining the network, the positioning terminal first generates an RSA key pair, then sends its self-generated RSA public key to the positioning base station via an unencrypted broadcast network access application frame. After receiving the public key, the base station randomly generates an AES key unique to the terminal and encrypts this AES key with the RSA public key provided by the terminal to form an encrypted AES key. This encrypted key is then appended to the unencrypted network access response frame and returned to the terminal. The terminal uses its own RSA private key to decrypt and obtain the original AES key. After completing the secure key distribution, both parties enter the ranging phase: all two-way time-of-flight (TW-TOF) data is end-to-end protected using the AES encryption / decryption mechanism. The terminal's original positioning data is encrypted into ciphertext through AES and transmitted to the base station via the UWB channel for decryption and restoration. The plaintext feedback command from the base station is also encrypted and transmitted using AES. Upon receipt, the terminal synchronously decrypts and executes the operation. During this process, the data body of the network interaction frame remains in plain text (only the AES key embedded in the base station reply frame is RSA encrypted). During the ranging phase, AES is used throughout to ensure the dynamic conversion between plain text and ciphertext. This not only avoids the risk of man-in-the-middle attacks in the initial key distribution, but also meets the real-time requirements of UWB positioning through high-frequency symmetric encryption. At the same time, the independently rotated AES key enhances the anti-cracking capability, ultimately realizing the secure closed-loop transmission of precise positioning data underground.
[0043] The key security distribution process is as follows Figure 2 As shown in the figure, the hybrid encryption key distribution process of the underground UWB positioning system is shown in the left and right column structure, including the collaborative operation of the base station side and the terminal side, which is divided into three stages:
[0044] Phase 1: Terminal key initialization
[0045] Step R1: The positioning terminal randomly generates an RSA key pair (including public and private keys). The private key never leaves the terminal, laying the foundation for asymmetric encryption security.
[0046] Phase 2: Public key broadcast and base station response
[0047] Step R2→L1: The terminal sends the RSA public key to the base station by broadcasting a network access application frame (plain text).
[0048] Step L2: After receiving the RSA public key, the base station dynamically generates an AES key specific to the terminal.
[0049] Step L3: The base station binds the three elements: terminal ID + RSA public key + AES key, and stores the mapping relationship.
[0050] Step L4: The base station encrypts the AES key using the RSA public key of the terminal to generate an encrypted AES key, where the encrypted AES key = RSA_Encrypt (AES key, RSA public key).
[0051] Step L5: The base station embeds the encryption result into a network access response frame (plain text frame body, only the key field is encrypted) and sends it back to the terminal.
[0052] Figure 2 The arrows in the figure reflect the bidirectional data flow of the public key upstream (R2→L1) and the encryption key downstream (L5→R3).
[0053] Phase 3: Terminal Key Decryption
[0054] Step R3: The terminal uses its own RSA private key to decrypt the encrypted field in the network access response frame and obtain the original AES key: AES key = RSA_Decrypt(encrypted AES key, RSA private key). This completes the closed loop: the terminal securely holds the same exclusive AES key as the base station.
[0055] The encrypted communication process in the ranging phase is as follows: Figure 3 As shown, it is mainly completed through the following 4 steps.
[0056] Step 1: The terminal initiates an encrypted Poll frame (ranging start)
[0057] Terminal action: Generate a Poll frame, encrypt the entire frame using the AES key, send the ciphertext to the base station via UWB, and record the sending timestamp T send1 .
[0058] Base station action: After receiving the Poll ciphertext, decrypt it with the AES key to obtain the plaintext and record the receiving timestamp T recv1 .
[0059] Step 2: The base station replies with an encrypted Response frame (ranging response)
[0060] Base station action: Generates a Response frame, encrypts the entire frame using the AES key, returns it to the terminal via UWB, and records the sending timestamp T send2 .
[0061] Terminal action: After decrypting the Response frame, record the receiving timestamp T recv2 .
[0062] Step 3: The terminal sends an encrypted Final frame (ranging ends)
[0063] Terminal action: Generate Final frame (including three terminal timestamps: T send1 、T recv2 , The terminal finally sends the timestamp T send3 ), encrypt the entire frame using the AES key, and send it to the base station via UWB.
[0064] Base station action: After decrypting the Final frame, record the receiving timestamp T recv3 .
[0065] Step 4: The base station securely calculates the terminal location
[0066] Base station action: Based on the two-way time of flight principle, according to six time stamps T send1 、T recv1 、T send2 、T recv2 、T send3 、T recv3 Calculate the precise terminal location.
[0067] Key management mechanisms such as Figure 4 As shown in the figure, it is mainly divided into two parts: terminal RSA key pair management and base station AES key management.
[0068] Terminal RSA key pair management is as follows:
[0069] Generation method: The terminal generates an RSA key pair (private key Pri_Key + public key Pub_Key) locally before joining the network, without network dependency.
[0070] Storage policy: Pri_Key never leaves the terminal, and Pub_Key allows plaintext broadcasting.
[0071] Transmission rules: Pub_Key is sent to the base station through an unencrypted network access application frame. Pri_Key is offline throughout the process and is only used to decrypt the encrypted AES key returned by the base station.
[0072] Lifecycle: Bound to the terminal until it is disconnected from the network and does not rotate (single generation is valid for a long time).
[0073] Base station AES key management is as follows:
[0074] Generation strategy: After receiving the terminal public key, the base station dynamically and randomly generates a unique AES key, one key for each terminal.
[0075] Encrypted distribution: Use the terminal's Pub_Key RSA to encrypt the AES key → generate Enc(AES_Key), embed the Enc(AES_Key) into the unencrypted network access response frame, and send it back to the terminal.
[0076] Terminal decryption: The terminal uses Pri_Key to decrypt Enc(AES_Key) and obtain the original AES key.
[0077] Usage rules: Only used in the ranging phase, encrypting Poll / Response / Final frames.
[0078] Bidirectional encryption and decryption with the same key: The base station and the terminal use the same AES key.
[0079] Rotation mechanism: The AES key is forcibly updated each time the terminal rejoins the network, and the key is not rotated during a single ranging.
[0080] Destruction conditions: After the terminal is disconnected from the network, the base station immediately erases the AES key of the terminal.
[0081] This paper proposes a hierarchical dynamic key management mechanism. First, static keys: terminals generate and store RSA private keys locally, distributing only public keys. Second, dynamic keys: the base station independently generates and maintains AES keys for each terminal, distributing them via RSA public key encryption. Key isolation: key leakage from a single terminal does not affect the overall system, and RSA and AES keys are mathematically unrelated. AES keys are securely transmitted via RSA handshakes. End-to-end AES encryption is implemented for the three-way handshake frames (Poll / Response / Final) of the TW-TOF protocol. Decrypted timestamp data is integrated on the base station side to output the terminal location.
[0082] Example 2:
[0083] An electronic device comprising a memory and a processor;
[0084] The memory is used to store computer programs;
[0085] The processor is configured to implement the method described in Example 1 when executing the computer program.
[0086] Example 3:
[0087] A computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method described in Example 1 is implemented.
[0088] Example 4:
[0089] A computer program product includes a computer program, which implements the method described in embodiment 1 when executed by a processor.
[0090] In the above embodiments, references to "this embodiment" in the specification indicate that a particular feature, structure, or characteristic described in conjunction with the embodiment is included in at least some embodiments, but not necessarily all embodiments. Multiple occurrences of "this embodiment" do not necessarily refer to the same embodiment.
[0091] In the above embodiments, references to "this embodiment" in the specification indicate that a particular feature, structure, or characteristic described in conjunction with the embodiment is included in at least some embodiments, but not necessarily all embodiments. Multiple occurrences of "this embodiment" do not necessarily refer to the same embodiment.
[0092] In the above embodiments, although the invention has been described in conjunction with specific embodiments thereof, many alternatives, modifications, and variations of these embodiments will be apparent to those skilled in the art based on the foregoing description. For example, other memory structures (e.g., dynamic RAM (DRAM)) may be used with the embodiments discussed. The embodiments of the present invention are intended to encompass all such alternatives, modifications, and variations that fall within the broad scope of the appended claims.
[0093] Regarding the computer-readable storage medium in this embodiment, those skilled in the art will appreciate that all or part of the steps in the aforementioned method embodiments can be implemented using hardware associated with the computer program. The aforementioned computer program can be stored in a computer-readable storage medium. When executed, the program performs the steps in the aforementioned method embodiments. The aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.
[0094] The electronic terminal provided in this embodiment includes a processor, a memory, a transceiver and a communication interface. The memory and the communication interface are connected to the processor and the transceiver and complete communication with each other. The memory is used to store computer programs, the communication interface is used for communication, and the processor and the transceiver are used to run computer programs so that the electronic terminal executes the various steps of the above method.
[0095] In this embodiment, the memory may include a random access memory (RAM), and may also include a non-volatile memory (non-volatile memory), such as at least one disk storage.
[0096] The above-mentioned processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, and discrete hardware components.
[0097] The present invention can be used in a wide variety of general-purpose or special-purpose computing system environments or configurations, such as personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputers, mainframe computers, and distributed computing environments that include any of the above.
[0098] The present invention may be described in the general context of computer-executable instructions, such as program modules, executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, and the like that perform specific tasks or implement specific abstract data types. The present invention may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communications network. In a distributed computing environment, program modules may be located in both local and remote computer storage media, including storage devices.
[0099] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not limiting. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention can be modified or replaced by equivalents without departing from the purpose and scope of the technical solutions, which should all be included in the scope of the claims of the present invention.
Claims
1. A hybrid encryption method for an underground UWB positioning system based on a dynamic key, characterized by: The following steps are involved: Phase 1: Key security distribution phase: The positioning terminal randomly generates an RSA key pair before joining the network and sends the RSA public key to the positioning base station by broadcasting a network application frame; After receiving the RSA public key, the base station randomly generates an AES key dedicated to the terminal, and RSA encrypts the AES key with the RSA public key provided by the terminal to form an encrypted AES key, and then embeds the encrypted AES key into the network access response frame and returns it to the terminal; The terminal uses its own RSA private key to decrypt the encrypted field in the network access response frame and obtain the original AES key; Phase 2: Ranging Phase: Perform two-way time-of-flight ranging (TW-TOF), and all data is end-to-end protected using AES encryption and decryption mechanisms.
2. The hybrid encryption method for an underground UWB positioning system based on a dynamic key according to claim 1, characterized in that: After receiving the RSA public key and randomly generating an AES key exclusive to the terminal, the base station binds the terminal ID, the RSA public key and the AES key and stores the mapping relationship.
3. The hybrid encryption method for an underground UWB positioning system based on a dynamic key according to claim 1, characterized in that: The RSA key pair includes an RSA private key and an RSA public key, wherein the RSA private key never leaves the terminal, and the RSA public key allows plain text broadcasting.
4. The hybrid encryption method for an underground UWB positioning system based on a dynamic key according to claim 1, characterized in that: The RSA private key and RSA public key are bound to the terminal until the terminal is disconnected from the network.
5. The hybrid encryption method for an underground UWB positioning system based on a dynamic key according to claim 1, characterized in that: The AES key is forcibly updated each time the terminal rejoins the network, and the key is not rotated during a single ranging.
6. The hybrid encryption method for an underground UWB positioning system based on dynamic keys according to claim 1, characterized in that: After the terminal is disconnected from the network, the base station erases the AES key of the terminal.
7. The hybrid encryption method for an underground UWB positioning system based on a dynamic key according to claim 1, characterized in that: The ranging phase specifically includes the following steps: The terminal generates a Poll frame, encrypts the entire frame using the AES key, sends the ciphertext to the base station via UWB, and records the sending timestamp T send1 ; After receiving the Poll ciphertext, the base station uses the AES key to decrypt it to obtain the plaintext and records the receiving timestamp T recv1 ; The base station generates a Response frame, encrypts the entire frame using the AES key, returns it to the terminal via UWB, and records the sending timestamp T send2 ; After the terminal decrypts the Response frame using the AES key, it records the receiving timestamp T recv2 ; The terminal generates a Final frame, encrypts the entire frame using the AES key, and sends it to the base station via UWB; After the base station decrypts the Final frame using the AES key, it records the receiving timestamp T recv3 ; The base station is based on the two-way time of flight principle and uses six time stamps T send1 、T recv1 、T send2 、T recv2 、T send3 、T recv3 Calculate the terminal position.
8. An electronic device, characterized in that: including memory and processor; The memory is used to store computer programs; The processor is configured to implement the hybrid encryption method for an underground UWB positioning system based on a dynamic key as described in any one of claims 1 to 7 when executing the computer program.
9. A computer-readable storage medium, characterized in that The storage medium stores a computer program, and when the computer program is executed by the processor, the hybrid encryption method of the underground UWB positioning system based on dynamic keys as described in any one of claims 1 to 7 is implemented.
10. A computer program product, characterized in that: The invention comprises a computer program, which, when executed by a processor, implements the hybrid encryption method of the underground UWB positioning system based on dynamic keys as described in any one of claims 1 to 7.
Citation Information
Cited By
Transmission data encryption method for through-the-earth type wireless detonator controller
CN122028034A