UWB communication node and method of operation
By using a combination of common and responder-specific cryptographic session keys in ultra-wideband communication systems to encrypt and decrypt messages and responses, the problem of responder node emulation risk is solved, improving the security and reliability of the system. This method is suitable for applications such as payment transactions and public transportation ticket verification.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- NXP BV
- Filing Date
- 2021-04-07
- Publication Date
- 2026-05-19
AI Technical Summary
In existing ultra-wideband communication systems, key sharing between responder nodes poses a security risk, as it is easily simulated, resulting in insufficient system reliability and security.
A combination of a common cryptographic session key and a responder-specific cryptographic session key is used to encrypt and decrypt messages and responses, respectively. This ensures that each responder node communicates using a specific key, and these keys are stored and managed through secure elements. This is combined with authentication and ranging operations to enhance security.
It reduces the risk of responder nodes simulating each other, improves the security level and reliability of the system, and ensures the accuracy and security of transactions, especially in large-scale communication technologies.
Smart Images

Figure CN113691977B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to an ultra-wideband communication node. Furthermore, this disclosure relates to a corresponding method for operating the ultra-wideband communication node, and to a corresponding computer program. Background Technology
[0002] Ultra-wideband (UWB) is a technology that utilizes high signal bandwidth, particularly for transmitting digital data over a wide frequency spectrum with extremely low power. For example, UWB technology can use a spectrum from 3.1 to 10.6 GHz and can feature high-frequency bandwidths greater than 500 MHz and very short pulse signals, resulting in high data rates. UWB technology enables communication devices to achieve high data throughput and high-precision device positioning. Summary of the Invention
[0003] According to a first aspect of this disclosure, an ultra-wideband communication node is provided, comprising: an ultra-wideband communication unit configured to transmit one or more messages to a plurality of external responder nodes and to receive one or more responses from the responder nodes; a processing unit configured to encrypt the messages using a common cryptographic session key, wherein the common cryptographic session key is a key shared between the ultra-wideband communication node and all the external responder nodes; wherein the processing unit is further configured to decrypt the responses and / or encrypt additional messages destined for the responder nodes using responder-specific cryptographic session keys, and wherein each individual key in the responder-specific cryptographic session keys is a key shared between the ultra-wideband communication node and one of the external responder nodes.
[0004] In one or more embodiments, the communication node includes an additional communication unit configured to transmit the common cryptographic session key and the responder-specific cryptographic session key to a corresponding external responder node.
[0005] In one or more embodiments, the additional communication unit is a Bluetooth communication unit, a Wi-Fi communication unit, or a cellular communication unit.
[0006] In one or more embodiments, the communication node further includes a security element, wherein the common cryptographic session key and the responder-specific cryptographic session key are stored in the security element.
[0007] In one or more embodiments, the ultra-wideband communication unit is further configured to receive an identifier from the external responder node, wherein the identifier uniquely identifies the external responder node, and wherein the processing unit is further configured to use the identifier to retrieve a responder-specific cryptographic session key from the security element.
[0008] In one or more embodiments, the message is a multicast message or a broadcast message.
[0009] In one or more embodiments, the communication node further includes an authentication unit configured to perform a mutual authentication process with the external responder node.
[0010] In one or more embodiments, the message and the response include a scrambled timestamp sequence and a payload.
[0011] In one or more embodiments, the common cryptographic session key and the responder-specific cryptographic session key can be used for a single communication session or for a limited number of communication sessions.
[0012] In one or more embodiments, the processing unit is further configured to: generate a new common cryptographic session key and a new responder-specific cryptographic session key after the end of one or more communication sessions; and share the new common cryptographic session key and the new responder-specific cryptographic session key with the responder nodes, wherein the new common cryptographic session key is shared with all the responder nodes, and each new responder-specific cryptographic session key is shared with a specific responder node among the responder nodes.
[0013] In one or more embodiments, a communication system includes communication nodes of the described type and the plurality of responder nodes, wherein each of the responder nodes is configured to: decrypt a message received from the communication node using the shared cryptographic session key; encrypt a response to the message using the responder-specific cryptographic session key already shared with the corresponding responder node; and / or decrypt additional messages received from the communication node.
[0014] In one or more embodiments, the communication node is configured to perform ranging operations with the responder node, wherein the ranging operations include one or more of the messages and one or more of the responses.
[0015] According to a second aspect of this disclosure, a method for operating an ultra-wideband communication node is envisioned, comprising: transmitting one or more messages to a plurality of external responder nodes by an ultra-wideband communication unit included in the communication node and receiving one or more responses from the responder nodes by the communication unit; encrypting the messages by a processing unit included in the communication node using a common cryptographic session key, wherein the common cryptographic session key is a key shared between the ultra-wideband communication node and all the external responder nodes; and decrypting the responses and / or encrypting additional messages destined for the responder nodes by the processing unit using responder-specific cryptographic session keys, wherein each individual key in the responder-specific cryptographic session keys is a key shared between the ultra-wideband communication node and one of the external responder nodes.
[0016] In one or more embodiments, the method further includes transmitting the common cryptographic session key and the responder-specific cryptographic session key to the corresponding external responder node by an additional communication unit included in the communication node.
[0017] According to a third aspect of this disclosure, a computer program is provided, including executable instructions that, when executed by a processing unit, cause the processing unit to perform the steps of a method of the described type. Attached Figure Description
[0018] The embodiments will be described in more detail with reference to the accompanying drawings, in which:
[0019] Figure 1 A schematic embodiment of a UWB communication node is shown;
[0020] Figure 2 A schematic embodiment of a method for operating a UWB communication node is shown;
[0021] Figure 3 A schematic embodiment of the UWB device authentication and session key generation process is shown;
[0022] Figure 4 A schematic embodiment of a dynamic multicast two-way ranging session is shown;
[0023] Figure 5 A schematic embodiment of a sub-session with multiple responders within a common session is shown. Detailed Implementation
[0024] Ultra-wideband (UWB) is a technology that utilizes high signal bandwidth, particularly for transmitting digital data over a wide frequency spectrum with extremely low power. For example, UWB technology can use a spectrum from 3.1 to 10.6 GHz and can feature high-frequency bandwidths greater than 500 MHz and very short pulse signals, resulting in high data rates. UWB technology enables communication devices to achieve high data throughput and high-precision device positioning.
[0025] UWB technology can also be used to support applications typically performed by technologies such as Near Field Communication (NFC), for example, to support transactions with another communication device (e.g., a payment terminal). Examples of such transactions include payment transactions in various stores and ticket verification or fare payment in public transportation. This transaction typically involves the exchange of one or more commands (e.g., instructions) and responses (e.g., data) between two communication devices. In this context, if communication technologies such as Bluetooth Low Energy or Wi-Fi are used to perform transactions between communication counterparts, UWB communication devices can help locate the communication counterparts. These communication technologies have a much larger range than NFC, and therefore the location of the communication counterparts becomes crucial. Specifically, because NFC can only be implemented when the communication counterparts are extremely close to each other, when NFC is used to perform a transaction, it implies the user's intent. However, if a communication technology with a larger range is used, the user's intent may be ambiguous. For example, a user may be within the communication range of the payment terminal, and thus may initiate a transaction between his mobile phone and the terminal, but the user does not approach the terminal and instead leaves the store. In this case, the transaction may be executed unintentionally. Therefore, the system may not be reliable and secure enough. In this scenario, UWB can be used to track a user's movement, and if this movement suggests the user's intention to conduct a transaction (e.g., if the phone approaches the terminal in an expected manner), the transaction can be completed. Therefore, a UWB ranging session involving multiple ranging operations to track phone movement serves as a supplementary security feature to compensate for the security deficiencies caused by broader range technologies.
[0026] Therefore, a UWB communication device integrated in a mobile phone can perform a series of ranging operations with another UWB communication device integrated in a payment terminal or transit gate to increase the reliability and security of transactions (e.g., to verify whether the phone is being carried by a user approaching the terminal or gate). Transactions executed via out-of-band communication channels (i.e., not via UWB communication channels) may involve initial steps such as identification, authentication, and verification of phone access rights, as well as completion steps such as transaction completion and terminal confirmation that the transaction has been completed. The UWB ranging session is used to verify whether the phone is close to the terminal; the phone's proximity to the terminal implies that the user has the intention to conduct a transaction. In typical NFC applications, this intention is implied by the technology because the user needs to be extremely close to the terminal (10cm). In the case of BLE, transactions are typically initiated when the user is many meters away from the terminal. Therefore, a UWB ranging session is performed to verify whether the user is correctly approaching the terminal, and the transaction is completed depending on the result of the UWB ranging session. The transaction is then executed using an out-of-band communication channel (BLE). Alternatively, both ranging and the transaction itself can be performed within the band, i.e., via the UWB communication channel. Therefore, UWB devices can perform functions typically performed by NFC devices.
[0027] A typical UWB ranging session consists of one or more messages (i.e., commands) transmitted from a UWB communication node (also referred to herein as a "reader") to one or more external UWB responder nodes (i.e., communication nodes outside the communication node), and one or more responses to these commands, which are transmitted back to the communication node by the responder node. These messages and responses to these messages should be encrypted. For this purpose, a cryptographic session key is used. That is, the communication node uses such a session key to encrypt the messages, and the responder node uses the same or a corresponding session key to decrypt the messages (depending on whether symmetric or asymmetric cryptography is applied). Similarly, the responder node uses a session key to encrypt the responses, and the communication node uses the same or a corresponding session key to decrypt the responses. Typically, a single shared cryptographic session key is used, i.e., a key shared between the communication node and all responder nodes. However, this introduces a security risk, as each responder node with access to the shared key can impersonate any other responder node using the shared key.
[0028] The discussion now focuses on ultra-wideband (UWB) communication nodes and corresponding methods for operating them, which help improve the security level of UWB-based communication systems, particularly by reducing the probability of responder nodes simulating each other.
[0029] Figure 1A schematic embodiment of a UWB communication node 100 is shown. The UWB communication node 100 includes a UWB communication unit 102 and a processing unit 104. The UWB communication unit 102 is configured to transmit one or more messages to a plurality of external responder nodes and to receive one or more responses from the responder nodes. The processing unit 104 is configured to encrypt the messages using a common cryptographic session key, wherein the common cryptographic session key is a key shared between the UWB communication node and all external responder nodes. Furthermore, the processing unit is configured to decrypt responses and / or encrypt additional messages destined for responder nodes using responder-specific cryptographic session keys, wherein each individual key in the responder-specific session keys is a key shared between the UWB communication node and one of the external responder nodes. Therefore, each responder node can encrypt its responses using a responder-specific session key, and the communication node's processing unit can decrypt responses using a responder-specific session key. Thus, because each responder node encrypts its responses using a specific session key, the risk of other responder nodes impersonating the responder node is reduced. However, using a shared cryptographic session key to transmit messages to the responder node helps achieve acceptable performance in terms of computational cost. Alternatively, or additionally, a responder-specific session key can be used to protect specific messages (i.e., additional messages) from the ultra-wideband communication node to the corresponding responder node. In this way, the risk of other responder nodes simulating the responder node is similarly reduced, while using a shared cryptographic session key to transmit one or more first messages to the responder node still helps achieve acceptable performance in terms of computational cost. Therefore, a responder node can use a responder-specific session key to encrypt its responses and / or decrypt additional messages from the communication node. If a responder node does not use a responder-specific session key to encrypt its responses, it can use the shared cryptographic session key for this purpose.
[0030] Figure 2A schematic embodiment of a method 200 for operating a UWB communication node is shown. Method 200 includes the following steps. In step 202, an ultra-wideband communication unit included in the communication node transmits one or more messages to a plurality of external responder nodes and receives one or more responses from the responder nodes. In step 204, a processing unit included in the communication node encrypts the messages using a common cryptographic session key, wherein the common cryptographic session key is a key shared between the ultra-wideband communication node and all external responder nodes. Furthermore, in step 206, the processing unit decrypts the responses and / or encrypts additional messages destined for the responder nodes using responder-specific cryptographic session keys, wherein each individual key in the responder-specific session keys is a key shared between the ultra-wideband communication node and one of the external responder nodes. As explained above, in this way, the risk of responder nodes simulating each other is reduced, while still achieving acceptable performance in terms of computational cost. It should be noted that method 200 can be implemented at least in part as a computer program.
[0031] In one or more embodiments, the communication node includes an additional communication unit configured to transmit a common cryptographic session key and a responder-specific session key to a corresponding external responder node. In this way, sharing the cryptographic session key with the external responder node via an out-of-band communication channel reduces the burden on the ultra-wideband communication network. In practical implementations, the additional communication unit is a Bluetooth communication unit, a Wi-Fi communication unit, or a cellular communication unit. For example, to reduce power consumption of the communication node and the responder node, the additional communication unit may be a Bluetooth Low Energy (BLE) communication unit. Furthermore, in one or more embodiments, the communication node further includes a security element, and the common cryptographic session key and the responder-specific cryptographic session key are stored in the security element. It should be noted that the security element (SE) may be a tamper-proof integrated circuit with an installed or pre-installed smart card-level application (e.g., a payment application) having specified functions and a specified security level. Furthermore, the security element may implement security functions, such as cryptographic and authentication functions. The security level can be further enhanced by storing the common cryptographic session key and the responder-specific cryptographic session key in the security element. It should be noted that the processing unit can also be embedded in a security element to further enhance the security level.
[0032] In one or more embodiments, the ultra-wideband communication unit is further configured to receive an identifier from an external responder node, wherein the identifier uniquely identifies the external responder node, and wherein the processing unit is further configured to retrieve a responder-specific session key from a security element using the identifier. In this way, the correct responder-specific cryptographic session key can be easily retrieved from the security element. Furthermore, the coherence between the content of the response and the cryptographic session key used to encrypt the response can be easily verified. For example, when a responder responds with its identifier and uses a cryptographic session key assigned to another responder, a mismatch between the identifier and the key used will be easily detected. Furthermore, in one or more embodiments, the message is a multicast message or a broadcast message. In this way, the communication node can easily transmit a single message to multiple responder nodes. Moreover, according to this disclosure, the security level of a UWB-based multicast or broadcast message-response communication system is improved by using a common cryptographic session key to encrypt multicast or broadcast messages and by using diverse cryptographic session keys for multiple responses. It should be noted that the term "multicast" refers to the situation where a message is sent to a predetermined subset of the intended responders within a large group of potential responders, while the term "broadcast" refers to the situation where a message is sent to all potential responders. In both cases, the level of security can be improved by diversifying the cryptographic session keys used by the responders. This diversification can be easily implemented because multicast or broadcast communication nodes only share the diversified cryptographic session keys in advance with the specific responder nodes intended to use them. Furthermore, by storing the responder-specific session key in a secure element, it can be ensured that the specifically shared responder-specific session key is only available to multicast or broadcast communication nodes and legitimate responder nodes, i.e., responder nodes intended to use the specifically shared responder-specific session key.
[0033] In one or more embodiments, the communication node further includes an authentication unit configured to perform a mutual authentication process with the external responder node. In this way, the reliability of both the communication node and the responder node can be easily verified. Furthermore, the mutual authentication process can be performed before sharing the cryptographic key. Therefore, the probability of sharing, for example, a specific shared responder-specific session key only with legitimate responder nodes is further increased. Additionally, in one or more embodiments, the message and response include a scrambled timestamp sequence and a payload. Using the scrambled timestamp sequence facilitates secure ranging operations between the communication node and the responder node. This, in turn, can be used to locate the responder node and compare, for example, the estimated location of a particular responder node with a desired location. It should be noted that a mismatch between the estimated location and the desired location can also indicate an impersonation attempt. Therefore, by combining the scrambled timestamp sequence with diverse responder-specific cryptographic session keys, the risk that responder nodes can impersonate each other is further reduced.
[0034] In practical implementations, the common cryptographic session key and the responder-specific cryptographic session key can be used for a single communication session or for a limited number of communication sessions. Furthermore, in one or more embodiments, the processing unit is additionally configured to generate new common cryptographic session keys and new responder-specific cryptographic session keys after the end of one or more communication sessions, and to share these new common cryptographic session keys and new responder-specific cryptographic session keys with the responder nodes. Specifically, the new common cryptographic session key is shared with all responder nodes, and each new responder-specific cryptographic session key is shared only with one specific responder node. By periodically generating new session keys, the newly generated session keys used by the responders are diversified, and the responder-specific session keys are shared only with the corresponding legitimate responders, which further enhances the security level.
[0035] In a practical implementation, the communication system includes communication nodes of the types described and multiple responder nodes, each of which is configured to decrypt messages received from the communication nodes using a shared cryptographic session key and encrypt responses to the messages using a responder-specific session key already shared with the corresponding responder node. In one or more embodiments, the communication nodes are configured to perform ranging operations with the responder nodes, and the ranging operations include one or more of the messages and one or more of the responses. In this way, secure ranging operations can be performed in UWB-enabled communication systems. For example, the operations may include two-way ranging (TWR) operations.
[0036] According to this disclosure, cryptographic separation of responder nodes can be achieved. This can be implemented using either asymmetric or symmetric cryptographic protocols. Specifically, the authentication or service applet can create a unique, responder-specific cryptographic session key for each responder and provide it, along with a sub-session identifier, to the Secure UWB Service (SUS) applet. The sub-session identifier and session identifier are globally unique. Key data can be exchanged and session keys for the UWB session can be derived. It should be noted that a UWB session may involve one or more ranging operations. Furthermore, a UWB session may include the execution of predetermined transactions. Once a UWB session begins, the UWB subsystem can obtain the session key associated with the session identifier from the secure element. In this example, this can be applied to an access control use case. In this case, the reader acts as a communication node of the described type. The reader performs a mutual authentication process with the mobile phone and configures the mobile phone to act as a responder in a multicast session. This configuration can be performed via an out-of-band communication channel. The mobile phone acting as a responder can then begin encrypting / decrypting an STS (Scrambled Timestamp Sequence) index. Furthermore, the mobile phone can encrypt data (i.e., the payload). For example, in a two-way ranging session between a reader and a mobile phone, the mobile phone can decrypt the STS received from the reader and encrypt the reader's response, which includes the STS and a payload.
[0037] More specifically, the following can be performed: An authentication or service applet can create a session key and provide it to the SUS applet. Furthermore, the authentication or service applet can create a responder-specific session key for each responder and provide it to the SUS applet along with a sub-session identifier. The sub-session identifier and the session identifier are globally unique. For example, a three-byte session identifier can be used, while a short address in the fourth byte can be used to create the sub-session identifier. The session key can be shared out-of-band with all potential responders. Additionally, a unique responder-specific session key can be shared out-of-band with each individual responder. A list of all responders, including short addresses and session information such as session identifiers, can be generated by the host processor, and the same list can be configured for the UWB device via the UWB Command Interface (UCI) transport layer. When a multicast session begins on a reader device with a controller / initiator role, the UWB device can acquire the session key. Subsequently, when a new responder is added to the multicast list, the UWB device can be triggered to acquire a session key with a sub-session identifier corresponding to the new responder address in the multicast list. On the side of the responder (e.g., a telephone) with a controlled role, when the multicast session begins, a session key with a session identifier associated with the multicast session is obtained. Furthermore, the UWB device can retrieve a responder-specific session key for each responder from the secure element via a SUS applet by providing a sub-session identifier. The session key can be used to derive all keys required for encrypting / decrypting the STS and payload. Additionally, the session key can be used to derive all keys required for encrypting the STS and commands from the controller. Furthermore, the responder-specific session key can be used to decrypt the STS and payload from the responder.
[0038] Figure 3A schematic embodiment of the UWB device authentication and session key generation process 300 is shown. After mutual authentication between reader 302 (i.e., the communication node of the described type) and telephone 312 (i.e., the responder of the described type), a root session key and responder session key negotiation step is performed between key exchange applet 306 of reader 302 and key exchange applet 316 of telephone 312. For this purpose, key exchange applets 306, 316 interact with SUS applets 308, 318, which in turn retrieve the relevant keys from the memory (not shown) of the respective security elements 304, 314. SUS applets 306, 316 interact with key exchange applets 306, 316 using JavaCard Shared Interface Object (SIO). Furthermore, SUS applets 306, 316 can interact with UWB units 310, 320 using Global Platform Secure Channel Protocol 03 (GPSCP03). The latter interaction can support the execution of a UWB secure session after UWB device authentication and session key generation processes have been completed. In a typical function flow, a key exchange applet or service applet can trigger authentication between reader 302 and phone 312, and the result of this authentication is a session key mapped to a session identifier on phone 312 and a responder-specific session key mapped to a sub-session identifier on reader 302. When translating this into an access control use case, reader 302 should perform the authentication steps on phone 312 and configure phone 312 to act as a responder in the multicast session. This configuration can be performed out-of-band. Subsequently, phone 312, acting as a responder, can begin encrypting / decrypting the STS and payload.
[0039] Figure 4 A schematic embodiment of a dynamic multicast two-way ranging session 400 is illustrated. Specifically, a dual-sided two-way ranging (DS-TWR) multicast ranging session is shown, in which a first phone 404 (i.e., a responder) is discovered by a controller / initiator 402 (i.e., a reader) via an out-of-band communication channel (i.e., a Bluetooth Low Energy communication channel). Following this discovery, a DS-TWR multicast ranging session is initiated via the first phone 404. At a later point in time, a second phone 406 is discovered by the controller / initiator 402 via the out-of-band communication channel, and the multicast list is thus updated. In addition to the ranging operations between the first phone 404 and the controller / initiator 402, the active DS-TWR multicast ranging session may now also include ranging operations between the second phone 406 and the controller / initiator 402.
[0040] Figure 5A schematic embodiment of a sub-session with multiple responders within a common session 500 is shown. Specifically, controller 502 performs ranging operations with several responders, namely, a first device 504 (e.g., a first telephone) and a second device 506 (e.g., a second telephone), within a single multicast ranging session. For this purpose, multicast sub-sessions are created within the (common) multicast ranging session. Furthermore, sub-session identifiers (i.e., device 1 session ID and device 2 session ID) are used to retrieve the associated responder-specific cryptographic session key from the secure element of controller 502.
[0041] The systems and methods described herein can be implemented, at least in part, by one or more computer programs, which may exist in various forms, either active or inactive, within a single computer system or across multiple computer systems. For example, the computer program may exist as a software program consisting of program instructions for performing some of these steps, in the form of source code, object code, executable code, or other formats. Any of these formats may be implemented in compressed or uncompressed form on a computer-readable medium, which may include storage devices and signals.
[0042] As used herein, the term "computer" refers to any electronic device that includes a processor, such as a general-purpose central processing unit (CPU), a dedicated processor, or a microcontroller. A computer is capable of receiving data (input), performing a series of predetermined operations on the data, and thereby producing results (output) in the form of information or signals. Depending on the context, the term "computer" will specifically refer to a processor or more generally to a processor associated with a combination of related elements housed within a single housing or enclosure.
[0043] The term "processor" or "processing unit" refers to a data processing circuit, which can be a microprocessor, coprocessor, microcontroller, microcomputer, central processing unit, field-programmable gate array (FPGA), programmable logic circuit, and / or any circuit that controls signals (analog or digital signals) based on operation instructions stored in memory. The term "memory" refers to one or more storage circuits, such as read-only memory, random access memory, volatile memory, non-volatile memory, static memory, dynamic memory, flash memory, cache memory, and / or any circuit that stores digital information.
[0044] As used herein, "computer-readable medium" or "storage medium" can be any component capable of containing, storing, transmitting, propagating, or transmitting a computer program for use by or in conjunction with an instruction execution system, device, or apparatus. A computer-readable medium can be, for example, but not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, apparatus, or propagation media. More specific examples of computer-readable media (a non-exhaustive list) may include: electrical connections having one or more wires, portable computer disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable optical disc read-only memory (CDROM), digital versatile optical disc (DVD), Blu-ray disc (BD), and memory cards.
[0045] It should be noted that the above embodiments have been described with reference to different subjects. Specifically, some embodiments may have been described with reference to claims of the method class, while others may have been described with reference to claims of the device class. However, those skilled in the art will understand from the foregoing that, unless otherwise indicated, any combination of features related to different subjects, particularly combinations of features of claims of the method class and features of claims of the device class, is also considered to be disclosed with this document, except for any combination of features belonging to one type of subject matter.
[0046] Furthermore, it should be noted that the drawings are illustrative. Similar or identical elements are represented by the same reference numerals in different drawings. Additionally, it should be noted that, in order to provide a concise description of illustrative embodiments, details of implementations that are customary to those skilled in the art may not be described. It should be understood that in the development of any such implementation, as in any engineering or design project, numerous implementation-specific decisions must be made to achieve the developer's specific goals, such as complying with system-related and business-related constraints, which may differ in different implementations. Furthermore, it should be understood that such development work can be complex and time-consuming, but remains a routine task for those skilled in the art in designing, manufacturing, and producing.
[0047] Finally, it should be noted that those skilled in the art should be able to devise numerous alternative embodiments without departing from the scope of the appended claims. Any reference numerals placed between parentheses in the claims should not be construed as limiting the claims. The word "comprising" does not exclude the presence of elements or steps other than those listed in the claims. The words "a" or "an" preceding an element do not exclude the presence of a plurality of such elements. The measures recited in the claims can be implemented by means of hardware comprising several different elements and / or by means of a suitably programmed processor. In a device claim listing several components, several of these components may be embodied by the same object in the hardware. The mere fact that certain measures are recited in different dependent claims does not imply that combinations of these measures cannot be advantageously used.
[0048] List of reference numerals
[0049] 100 UWB communication nodes
[0050] 102 UWB communication units
[0051] 104 processing units
[0052] 200 Methods for operating UWB communication nodes
[0053] 202. One or more messages are transmitted to multiple external responder nodes by an ultra-wideband communication unit included in a communication node, and responses are received from the responder nodes by the communication unit.
[0054] 204 The message is encrypted by a processing unit included in the communication node using a common cryptographic session key, wherein the common cryptographic session key is a key shared between the ultra-wideband communication node and all external responder nodes.
[0055] 206 The processing unit decrypts the response and / or encrypts additional messages destined for the responder node using a responder-specific cryptographic session key, wherein each individual key in the responder-specific session key is a key shared between the ultra-wideband communication node and one of the external responder nodes.
[0056] 300 UWB Device Authentication and Session Key Generation Process
[0057] 302 Reader
[0058] 304 First Safety Element
[0059] 306 Key Exchange Mini Program
[0060] 308 Secure UWB Service (SUS) Mini Program
[0061] 310 UWB unit
[0062] 312 telephone
[0063] 314 Second Safety Element
[0064] 316 Key Exchange Mini Program
[0065] 318 Secure UWB Service (SUS) Mini Program
[0066] 320 UWB unit
[0067] 400 Dynamic Multicast Two-Way Ranging Session
[0068] 402 Controller / Starter
[0069] 404 First Call
[0070] 406 Second Phone Number
[0071] 500 Sub-sessions for multiple responders within a common session
[0072] 502 Controller
[0073] 504 First Device
[0074] 506 Second device.
Claims
1. A communication system comprising an ultra-wideband communication node and a plurality of responder nodes, characterized in that, The ultra-wideband communication node includes: An ultra-wideband communication unit is configured to transmit one or more messages to the plurality of responder nodes and receive one or more responses from the responder nodes; A processing unit configured to encrypt the message using a common cryptographic session key, wherein the common cryptographic session key is a key shared between the ultra-wideband communication node and all the responder nodes; The processing unit is further configured to decrypt the response and / or encrypt additional messages destined for the responder node using a responder-specific cryptographic session key, and each individual key in the responder-specific cryptographic session key is a key shared between the ultra-wideband communication node and one of the responder nodes. Each of the aforementioned responder nodes is configured to: The message received from the communication node is decrypted using the shared cryptographic session key; The response to the message is encrypted using the responder-specific cryptographic session key that has been shared with the corresponding responder node, and / or additional messages received from the communication node are decrypted.
2. The communication system according to claim 1, characterized in that, The communication node includes an additional communication unit configured to transmit the common cryptographic session key and the responder-specific cryptographic session key to the corresponding responder node.
3. The communication system according to claim 1, characterized in that, The communication node further includes a security element, wherein the common cryptographic session key and the responder-specific cryptographic session key are stored in the security element.
4. The communication system according to claim 3, characterized in that, The ultra-wideband communication unit is further configured to receive an identifier from the responder node, wherein the identifier uniquely identifies the responder node, and wherein the processing unit is further configured to use the identifier to retrieve a responder-specific cryptographic session key from the security element.
5. The communication system according to claim 1, characterized in that, The communication node further includes an authentication unit configured to perform a mutual authentication process with the responder node.
6. The communication system according to claim 1, characterized in that, The common cryptographic session key and the responder-specific cryptographic session key can be used for a single communication session or for a limited number of communication sessions.
7. The communication system according to claim 1, characterized in that, The processing unit is further configured to: After one or more communication sessions have ended, a new common cryptographic session key and a new responder-specific cryptographic session key are generated. The new common cryptographic session key and the new responder-specific cryptographic session key are shared with the responder nodes, wherein the new common cryptographic session key is shared with all the responder nodes, and each new responder-specific cryptographic session key is shared with a specific responder node among the responder nodes.
8. A method of operating a communication system, wherein the communication system comprises an ultra-wideband communication node and a plurality of responder nodes, characterized in that, The method includes: One or more messages are transmitted to the plurality of responder nodes by an ultra-wideband communication unit included in the communication node, and one or more responses are received from the responder nodes by the communication unit. The message is encrypted by a processing unit included in the communication node using a common cryptographic session key, wherein the common cryptographic session key is a key shared between the ultra-wideband communication node and all the responder nodes; The processing unit uses a responder-specific cryptographic session key to decrypt the response and / or encrypt additional messages destined for the responder node, wherein each individual key in the responder-specific cryptographic session key is a key shared between the ultra-wideband communication node and one of the responder nodes. Each of the aforementioned responder nodes is configured to: The message received from the communication node is decrypted using the shared cryptographic session key; The response to the message is encrypted using the responder-specific cryptographic session key that has been shared with the corresponding responder node, and / or additional messages received from the communication node are decrypted.
9. A computer-readable storage medium, characterized in that, It stores executable instructions that, when executed by a processing unit, cause the processing unit to perform the steps of the method according to claim 8.