A key generation method based on aligned edited sequences
Through the key generation method based on edited sequence alignment, the key mismatch problem caused by channel non-reciprocity in the prior art is solved, and efficient and accurate key generation is achieved, which is suitable for resource-constrained Internet of Things devices.
Patent Information
- Application Number
- CN202210410736.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-04-19
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2042-04-19
AI Technical Summary
The existing physical layer key generation method leads to non-reciprocity of the channel under the asynchronous channel detection and hardware damage and noise effects in the time division duplex system, thereby making the quantization results in key generation inconsistent, resulting in mismatch of key bits.
The key generation method based on edited sequence alignment is adopted, and the key is generated through the steps of channel sampling, entropy-based permutation and segmentation, edited sequence alignment, information mediation and privacy amplification. This method ensures the accuracy and efficiency of key generation through editing distance calculation and editing pattern recognition.
Reciprocal matching of channel measurement values under environmental noise interference is realized, which reduces the ambiguity and mismatch rate in key generation, ensures the high bit generation rate and error-free keys, and is suitable for IoT devices with resource-constrained.
Smart Images

Figure CN114885327B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of physical layer security, and in particular to a key generation method based on the alignment of edited sequences. Background Art
[0002] With the popularization of wireless networks, ensuring the communication security between devices on a wireless channel with broadcast characteristics has become an urgent need today. For example, the abuse of wireless devices for eavesdropping attacks, information theft, unauthorized access and other malicious attacks result in losses of approximately 84 million euros per year. To ensure secure wireless communication, traditional encryption schemes in symmetric or asymmetric cryptography mainly rely on generating keys based on pre-shared information to protect users' messages from illegal access by malicious devices. However, due to the lack of a key management infrastructure and the limited communication computing resources of mobile devices, most of these schemes are not suitable for device-to-device communication in wireless networks. To overcome the limitations of traditional encryption schemes, many studies have turned to using the inherent physical characteristics of the wireless channel to establish shared keys between a pair of wireless transceivers.
[0003] For most physical layer key generation methods, quantization is a key step in realizing key generation on a reciprocal wireless channel. However, the asynchronous channel probing, hardware impairments and noise effects in time division duplex systems will all destroy the reciprocity of the channel, making the quantization results in key generation inconsistent, and thus leading to a mismatch of key bits between two users. Most existing works process each channel measurement value independently during the quantization process, but the outliers caused by channel fading and the interference of unpredictable environmental noise make it difficult to ensure consistent quantization results between a pair of users in practice. Therefore, an effective and stable solution is needed to eliminate the non-reciprocity of channel measurement values and achieve an error-free key agreement. Summary of the Invention
[0004] The present invention provides a key generation method based on edited sequence alignment to address the deficiencies of the above-mentioned prior art, and includes steps such as channel sampling, entropy-based permutation and segmentation, key generation based on edited sequence alignment, information reconciliation, and privacy amplification. The entropy-based permutation step increases the complexity of the channel measurement sequence through permutation and retains channel reciprocity to facilitate reducing ambiguity and mismatch in key generation under environmental noise interference; the segmentation step improves the robustness of key generation in different scenarios by introducing multiple channel measurement values. The key generation step based on edited sequence alignment generates a key by matching the channel measurement values between a pair of users, and uses the calculation of the edit distance and recognition of the edit pattern of the channel measurement values to promote accurate and efficient key generation. The information reconciliation step is used to correct the occasional bit mismatches in key generation to achieve error-free key generation. The privacy amplification step further enhances the randomness of the key to meet the actual application requirements of the key, and has strong practicality.
[0005] To achieve the object of the present invention, the following techniques are proposed:
[0006] A key generation method based on edited sequence alignment, including steps:
[0007] Step 1: Channel sampling, where terminal A and terminal B sample the measurement values of the channel and respectively generate the channel measurement value sequences of terminal A and terminal B;
[0008] Step 2: Permutation, segmentation, and re-permutation of the channel measurement values. Terminal A performs an overall permutation on the channel measurement value sequence obtained in Step 1, terminal A performs segmentation of the overall permuted channel measurement value sequence with a fixed length to obtain the segmented sequence of the channel measurement values of terminal A, and terminal A performs partial re-permutation on the segmented sequence of the channel measurement values of terminal A to obtain the segmented sequence of the channel measurement values of terminal A after two permutations. Terminal A sends the segmented sequence of the channel measurement values of terminal A and the segmented sequence of the channel measurement values of terminal A after two permutations to terminal B; terminal B performs segmentation of the channel measurement value sequence of terminal B obtained in Step 1 with a fixed length to obtain the segmented sequence of the channel measurement values of terminal B, and terminal B performs overall permutation and partial re-permutation on the segmented sequence of the channel measurement values of terminal B to obtain the segmented sequence of the channel measurement values of terminal B after two permutations;
[0009] Step 3: key generation, terminal A edits the segmented sequence of channel measurement values after two permutations of terminal A obtained in step 2, and obtains the segmented sequence of channel measurement values edited by terminal A, and sends the segmented sequence of channel measurement values edited by terminal A to terminal B, and terminal B matches the segmented sequence of channel measurement values after two permutations of terminal B with the segmented sequence of channel measurement values edited by terminal A through the segmented matching algorithm of the edit distance, so that terminal B determines the editing mode of the segmented sequence of channel measurement values edited by terminal A;
[0010] Step 4: Information mediation and privacy amplification. According to the judgment result of the editing mode of the segmented sequence of channel measurement values edited by terminal A by terminal B in step 3, terminal A and terminal B perform information mediation and privacy amplification and obtain the key.
[0011] Furthermore, in step 1, the channel measurement value sampling of terminal A and terminal B is performed within the channel coherence time of terminal A and terminal B, and until terminal A and terminal B have collected a certain number of channel measurement values, and the channel measurement value sequences collected by terminal A and terminal B are respectively recorded as and Among them, V A is the channel measurement value sequence of terminal A, V B is the channel measurement value sequence of terminal B.
[0012] Furthermore, the steps of permuting, segmenting and re-permuting the channel measurement values in step 2 are:
[0013] Step 2.1: Terminal A to Terminal A channel measurement sequence Perform a random global permutation S h , and obtain the channel measurement value sequence of terminal A after overall permutation
[0014] Step 2.2: Terminal A calculates the channel measurement value sequence of terminal A after the overall permutation obtained in step 2.1 The sample entropy of To measure the complexity of the channel measurement value sequence of terminal A after the overall permutation;
[0015] Step 2.3: Terminal A replaces the entire channel measurement value sequence of terminal A Divide into M fixed-length segment sequences of the channel measurement values of terminal A in, Represents P A The mth segment in the channel, and terminal B sends the channel measurement value sequence V B Divide into M fixed-length segmented sequences of the channel measurement values of terminal B in Represents PB the m-th segment in
[0016] Step 2.4: Terminal A repeatedly performs a random partial re-permutation S on each segment in the sequence P of channel measurement values of Terminal A A until the sample entropy of each segment reaches a pre-set threshold, and obtains the sequence of segmented channel measurement values of Terminal A after two permutations f
[0017] Step 2.5: Terminal A combines the overall permutation S in Step 2.1 h and the partial re-permutation S in Step 2.4 f to obtain the permutation sequence [k1, k2, …, k N , where k n ∈ [1, N] represents the original index of in the channel measurement sequence V of Terminal A A
[0018] Step 2.6: Transmit the permutation sequence [k1, k2, …, k N obtained by Terminal A in Step 2.5 to Terminal B;
[0019] Step 2.7: After receiving the permutation sequence [k1, k2, …, k N from Terminal A, Terminal B permutes the sequence of channel measurement values V of Terminal B in the same order as Terminal A permutes the channel measurement sequence V of Terminal A A to obtain the sequence of segmented channel measurement values of Terminal B after two permutations B
[0020] Furthermore, in Step 3, Terminal A performs multiple insert or delete editing operations on the sequence of segmented channel measurement values of Terminal A obtained after two permutations in Step 2.5 and generates a sequence of segmented channel measurement values of Terminal A after editing with a segment length of M p where represents the i-th segmented channel measurement value after editing, where 1 ≤ i ≤ M p
[0021] Furthermore, the generation steps of the sequence of segmented channel measurement values of Terminal A after editing are as follows:
[0022] Step 3.10: Terminal A randomly and without repetition selects L i indices As the insertion position, or select L d indexes As the deletion position;
[0023] Step 3.11: Terminal A inserts or deletes segments randomly into the sequence When inserting or deleting segments from the segmented sequence of the channel measurement values of Terminal A after two permutations Insert a segment at position α we can obtain When inserting or deleting segments from the segmented sequence of the channel measurement values of Terminal A after two permutations Delete a segment at position β we can obtain
[0024] Step 3.12: When Terminal A has performed L i insertions or L d deletions, Terminal A obtains the segmented sequence of the channel measurement values edited by Terminal A
[0025] Terminal A obtains the segmented sequence of the channel measurement values edited by Terminal A The unedited segments in correspond to the indexes in the segmented sequence of the channel measurement values of Terminal A after two permutations where M represents the number of unedited segments; r and obtains the segmented sequence of the channel measurement values edited by Terminal A
[0026] The inserted segments in correspond to the indexes in the segmented sequence of the channel measurement values of Terminal A after two permutations where L is the number of insertion indexes; where L i is the number of insertion indexes;
[0027] Terminal A sends the segmented sequence of the channel measurement values edited by Terminal A to User B.
[0028] Furthermore, the L i indexes in Step 3.10 and the L d indexes each independently follow a uniform distribution in the range 0 to M.
[0029] Furthermore, when inserting a segment at position α in the segmented sequence of the channel measurement values of Terminal A after two permutations in Step 3.11 Insert a segment at position α the inserted segment is from the segmented sequence of the channel measurement values of Terminal A after two permutations in another round of key generation process randomly selected, and segmented independently follows the same distribution as the original segments.
[0030] Furthermore, in step 3, the steps for terminal B to match the segmented sequence of channel measurement values of terminal B with the segmented sequence of edited channel measurement values of terminal A through the segmented matching algorithm based on the edit distance are as follows:
[0031] Step 3.20: Let the segmented sequence of edited channel measurement values of terminal A and the segmented sequence of channel measurement values of terminal B after two permutations The edit distance between them is where i ∈ [0, M p , j ∈ [0, M], κ i represents the number of segments contained in the segmented sequence of the channel sequence of terminal A after editing M p represents the length of the segmented sequence of edited channel measurement values of terminal A M represents the length of the segmented sequence of channel measurement values of terminal B after two permutations ;
[0032] Step 3.21: Use the dynamic programming method to obtain The recurrence formula of:
[0033]
[0034] where i ∈ [1, M p , j ∈ [1, M], the boundary values are defined as C ins is the edit cost of the insertion operation and C ins = 1, C del is the edit cost of the deletion operation and C del = 1;
[0035] The dynamic programming method terminates at By backtracking a shortest path from to and inferring the edit operations corresponding to the edit distance ;
[0036] Step 3.22: Terminal B infers that the unedited segments in the segmented sequence of edited channel measurement values of terminal A correspond to the indices in the segmented sequence of channel measurement values of terminal B after two permutations and infers that the segments in the segmented sequence of edited channel measurement values of terminal A where insertion operations are performed correspond to the segmented sequence of channel measurement values of terminal B after two permutations The index in where M r represents the number of unedited segments, and L i represents the number of inserted segments;
[0037] Step 3.23: The index obtained by terminal B and the index obtained by terminal A As the only and confidential sequence between terminal A and terminal B, it can be used for subsequent key establishment.
[0038] Furthermore, the steps for terminal A and terminal B to perform information reconciliation are:
[0039] Step 4.10: Terminal A and terminal B perform a two-round challenge-response information exchange. The challenge-response information exchange is as follows:
[0040] B→A:X BA =(σ′) -1 (S B ⊕R)
[0041] A→B:X AB =σ(X BA ⊕S A )
[0042] where ⊕ represents the logical exclusive OR operation, R is a random vector of length M r +L i ; and are the respective average values of the subset of segments in the sequence of channel measurement value segments edited by terminal A ; σ(·) represents the permutation function with the index order as the permutation sequence; in addition, let σ′(·) represent the permutation function with the index order as the permutation sequence; (σ′) -1 (·) represents the inverse permutation of σ′(·) such that σ′[(σ′) -1 (S B )]=S B ;
[0043] Step 4.11: Terminal B calculates X B =S B ⊕R⊕σ′(S B ); Terminal B identifies the indices of the unequal elements between X BA and X B as Φ=[φ1,φ2,…,φ s , where each φ s ∈[1,M r +L i, terminal B repeatedly exchanges the mismatched elements several times until X is satisfied AB = X B ;
[0044] Step 4.12: An agreed permutation sequence σ = σ′ is reached between terminal A and terminal B.
[0045] Furthermore, the way for terminal A and terminal B to perform privacy amplification is: terminal A and terminal B calculate SK = σ(S A ) = σ′(S B ) using the permutation operation and use it as the final key.
[0046] The advantages of the above technical solution are as follows:
[0047] (1) By matching the segments after random editing in the channel measurement instead of the quantization process in the traditional key generation method, the present invention realizes a low bit mismatch rate and a high bit generation rate for generating keys;
[0048] (2) In the key generation process based on the alignment of the edited sequences, the search matching algorithm of the present invention can achieve fast and practical reciprocal matching of the channel measurement values, which is suitable for resource-constrained Internet of Things devices;
[0049] (3) The present invention uses an efficient information reconciliation and privacy amplification scheme to ensure a fast and error-free high-entropy key protocol;
[0050] (4) The search matching algorithm of the present invention has strong stability and can effectively achieve key consistency in various scenarios with environmental noise interference. Description of the Drawings
[0051] In order to make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the drawings.
[0052] Figure 1 is the algorithm flow chart of the present invention;
[0053] Figure 2 is the information reconciliation process diagram of the present invention. Detailed Embodiments
[0054] As Figures 1 to 2 shown, a key generation method based on the alignment of edited sequences includes the steps:
[0055] Step 1: Channel sampling, terminal A and terminal B sample the measurement values of the channel and respectively generate the channel measurement value sequences of terminal A and terminal B;
[0056] Step 2: Permutation, segmentation, and re - permutation of channel measurement values. Terminal A and Terminal B respectively perform an overall permutation on the sequence of channel measurement values obtained in Step 1. Terminal A segments the sequence of channel measurement values after the overall permutation into segments of a fixed length, obtaining the segmented sequence of channel measurement values of Terminal A. And Terminal A performs a partial re - permutation on the segmented sequence of channel measurement values of Terminal A, obtaining the segmented sequence of channel measurement values of Terminal A after two permutations. Terminal A sends the permutation sequences used in the overall permutation and the partial re - permutation operations to Terminal B. Terminal B segments the sequence of channel measurement values of Terminal B obtained in Step 1 into segments of a fixed length, obtaining the segmented sequence of channel measurement values of Terminal B. And Terminal B performs an overall permutation and a partial re - permutation on the segmented sequence of channel measurement values of Terminal B, obtaining the segmented sequence of channel measurement values of Terminal B after two permutations.
[0057] Step 3: Key generation. Terminal A edits the segmented sequence of channel measurement values of Terminal A after two permutations obtained in Step 2, obtaining the edited segmented sequence of channel measurement values of Terminal A, and sends the edited segmented sequence of channel measurement values of Terminal A to Terminal B. Terminal B uses the segmented matching algorithm of the edit distance to match the segmented sequence of channel measurement values of Terminal B after two permutations with the edited segmented sequence of channel measurement values of Terminal A, so that Terminal B judges the editing mode of the edited segmented sequence of channel measurement values of Terminal A.
[0058] Step 4: Information reconciliation and privacy amplification. According to the judgment result of the editing mode of the edited segmented sequence of channel measurement values of Terminal A by Terminal B in Step 3, Terminal A and Terminal B perform information reconciliation and privacy amplification and obtain a key.
[0059] Among them, in Step 1, the sampling of the channel measurement values by Terminal A and Terminal B is carried out within the channel coherence time of Terminal A and Terminal B, and it stops until Terminal A and Terminal B have collected a certain number of channel measurements. In implementation, Terminal A and Terminal B perform multiple rounds of probe packet exchanges within the coherence time of their mutual channels, collect a certain number of probe packets as the channel measurement values for channel sampling, and respectively denote the sequences of channel measurement values collected by Terminal A and Terminal B as and V A is the sequence of channel measurement values of Terminal A, and V B is the sequence of channel measurement values of Terminal B.
[0060] The steps of permutation, segmentation, and re - permutation of channel measurement values in Step 2 are as follows:
[0061] Step 2.1: Terminal A performs a random overall permutation S on the channel measurement sequence h of Terminal A, obtaining the sequence of channel measurement values of Terminal A after the overall permutation
[0062] Step 2.2: The terminal A calculates the sequence of channel measurement values of the terminal A after the overall permutation obtained in Step 2.1 for its sample entropy to measure the complexity of the sequence of channel measurement values of the terminal A after the overall permutation. A larger sample entropy result represents a higher complexity of the channel measurement values and a lower self-similarity.
[0063] Step 2.3: The terminal A divides the sequence of channel measurement values of the terminal A after the overall permutation into M segmented sequences of channel measurement values of the terminal A with a fixed length wherein represents the m-th segment in P A , and the terminal B divides the sequence of channel measurement values V B into M segmented sequences of channel measurement values of the terminal B with a fixed length wherein represents the m-th segment in P B ;
[0064] Step 2.4: The terminal A repeatedly performs a random partial re-permutation S A on each segment in the segmented sequence of channel measurement values P f of the terminal A until the sample entropy of each segment reaches a pre-set threshold, and obtains the segmented sequence of channel measurement values of the terminal A after two permutations Moreover, after the partial permutation, the segmented sequence of channel measurement values P A of the terminal A will be converted into a more irregular segmented sequence of channel measurement values of the terminal A after two permutations
[0065] Step 2.5: The terminal A combines the overall permutation S h in Step 2.1 and the partial re-permutation S f in Step 2.4, and obtains the permutation sequence [k1, k2,..., k N , where k n ∈ [1, N] represents the original index of in the channel measurement sequence V A of the terminal A, and this process will not disclose the actual channel measurement values of the terminal A.
[0066] Step 2.6: Transmit the permutation sequence [k1, k2,..., k N obtained by the terminal A in Step 2.5 to the terminal B;
[0067] Step 2.7: After receiving the permutation sequence [k1, k2, …, k N from terminal A, terminal B permutes the channel measurement value sequence V A of terminal B in the same order as terminal A permutes the channel measurement sequence V B of terminal A, and obtains the segmented sequence of channel measurement values after two permutations of terminal B
[0068] In step 3, terminal A performs multiple insert or delete editing operations on the segmented sequence of channel measurement values after two permutations of terminal A obtained in step 2.5, and generates M segment-length segmented sequences of edited channel measurement values of terminal A p where, represents the i-th segmented sequence of edited channel measurement values, where 1 ≤ i ≤ M p .
[0069] The generation steps of the segmented sequence of edited channel measurement values of terminal A are as follows:
[0070] Step 3.10: Terminal A randomly and without repetition selects L i indices as the insertion positions, or selects L d indices as the deletion positions, where each index independently follows a uniform distribution in the range 0 to M.
[0071] Step 3.11: Terminal A randomly inserts or deletes segments into the sequence according to the generated indices. When inserting a segment at position α in the segmented sequence of channel measurement values after two permutations of terminal A can be obtained When deleting a segment at position β in the segmented sequence of channel measurement values after two permutations of terminal A can be obtained where, when inserting a segment at position α in the segmented sequence of channel measurement values after two permutations of terminal Athe inserted segment is randomly selected from the segmented sequence of channel measurement values after two permutations of terminal A in another round of key generation process and the segment independently follows the same distribution as the original segment.
[0072] Step 3.12: When terminal A has performed L i insertions or L d After the second deletion, terminal A obtains the segmented sequence of the channel measurement values edited by terminal A Terminal A obtains the segmented sequence of the channel measurement values edited by terminal A The unedited segments in correspond to the segmented sequence of the channel measurement values after two permutations of terminal A The indexes in And obtain the segmented sequence of the channel measurement values edited by terminal A The segments for insertion operations in correspond to the segmented sequence of the channel measurement values after two permutations of terminal A The indexes in Terminal A sends the segmented sequence of the channel measurement values edited by terminal A To user B through the public channel
[0073] In step 3, the steps for terminal B to match the segmented sequence of the channel measurement values after two permutations of terminal B with the segmented sequence of the channel measurement values edited by terminal A through the segmented matching algorithm of the edit distance are as follows:
[0074] Terminal A constructs a minimum edit distance problem based on the segmented sequence of the channel measurement values edited by terminal A And the segmented sequence of the channel measurement values after two permutations of terminal B A minimum edit distance problem can be constructed: search for a series of edit operations that convert the segmented sequence of the channel measurement values edited by terminal A Into the segmented sequence of the channel measurement values after two permutations of terminal B Where the sum of the costs of the edit operations (That is, the edit distance from sequence To sequence ) is the smallest; in this embodiment, it is stipulated that the edit cost of the insertion operation is C ins = 1, and the edit cost of the deletion operation is C del = 1. And it is stipulated that each segment in the segmented sequence of the channel measurement values edited by terminal A And each segment in the segmented sequence of the channel measurement values after two permutations of terminal B The distance metric between them uses the absolute value To measure, where Is composed of L individual channel measurement values And Is composed of L individual channel measurement values Composed. If Δ (κ , m′) is less than a predefined threshold δ, then the two segments A,B (κ m , m′) can be regarded as the same edit pattern, and And Can be regarded as the same edit pattern, and Corresponds to The unedited segments in The specific implementation steps are as follows:
[0075] Step 3.20: Let the sequence of segmented channel measurement values after editing by terminal A and the sequence of segmented channel measurement values after two permutations by terminal B have an edit distance of where i ∈ [0, M p , j ∈ [0, M], κ i represents the number of segments contained in the sequence of segmented channel sequences after editing by terminal A M p represents the length of the sequence of segmented channel measurement values after editing by terminal A and M represents the length of the sequence of segmented channel measurement values after two permutations by terminal B .
[0076] Step 3.21: Use the dynamic programming method to obtain The recurrence formula of
[0077]
[0078] where, i ∈ [1, M p , j ∈ [1, M], and the boundary values are defined as C ins is the edit cost for the insertion operation and C ins = 1, C del is the edit cost for the deletion operation and C del = 1.
[0079] The dynamic programming method terminates at by backtracking a shortest path from to and inferring the edit operations corresponding to the edit distance .
[0080] Step 3.22: Terminal B infers the indices in the sequence of segmented channel measurement values after two permutations by terminal B corresponding to the unedited segments in the sequence of segmented channel measurement values after editing by terminal A and infers the indices in the sequence of segmented channel measurement values after two permutations by terminal B corresponding to the segments with insertion operations in the sequence of segmented channel measurement values after editing by terminal A where, M represents the number of unedited segments, and L represents the number of inserted segments. r i
[0081] Step 3.23: Index obtained by terminal B and the index obtained by terminal A can be used as the only and confidential sequence between terminal A and terminal B for subsequent key establishment.
[0082] Furthermore, the implementation manner in which terminal A and terminal B perform information reconciliation is as follows:
[0083] Terminal A and terminal B perform a two-round challenge-response information exchange, and the challenge-response information exchange is as follows:
[0084] B→A:X BA =(σ′) -1 (S B ⊕R)
[0085] A→B:X AB =σ(X BA ⊕S A )
[0086] where ⊕ represents the logical exclusive OR operation, R is a random vector of length M r +L i , and are the respective average values of the segmented subsets in the segmented sequence of the channel measurement values edited by terminal A , σ(·) represents the permutation function with the index order as the permutation sequence; in addition, let σ′(·) represent the permutation function with the index order as the permutation sequence; (σ′) -1 (·) represents the inverse permutation of σ′(·) such that σ′[(σ′) -1 (S B )]=S B .
[0087] Terminal B continues to calculate X B =S B ⊕R⊕σ′(S B ); in the case of an ideal error-free key, terminal A and terminal B can generate the same permutation function σ = σ′ and X AB =X B ; however, due to asynchronous channel sampling and environmental noise, there is an accidental mismatch between the original permutation σ and the actual permutation σ′; therefore, terminal B identifies the indices of the unequal elements between X BA and X B as Φ = [φ1, φ2, …, φ s , where each φ s ∈[1, M r +L i , and S is XBA The number of elements not equal to X B Consider in an M - th symmetric group, where σ is a permutation of order M as an element in the group. Since each permutation in the symmetric group can be written as a composition of several transpositions, and the number of mismatched indices is small, terminal B can repeatedly swap the mismatched elements several times until X AB = X B . Eventually, the agreed - upon permutation sequence σ = σ′ is reached between user A and user B.
[0088] The way for terminal A and terminal B to perform privacy amplification is as follows: Terminal A and terminal B use the permutation operation to calculate SK = σ(S A ) = σ′(S B ), and use it as the final key. Of course, as another implementation method, a universal hash function can be used for privacy amplification to reduce information leakage in information reconciliation.
[0089] The above - mentioned are only the preferred embodiments of the present invention and are not used to limit the present invention. Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention also intends to include these changes and modifications.
Claims
1. A key generation method based on edited sequence alignment, characterized in that Including the steps: Step 1: Channel sampling. Terminals A and B sample the measured values of the channel and respectively generate the channel measurement value sequences of terminals A and B. Step 2: Permutation, segmentation, and re-permutation of the channel measurement values. Terminals A and B respectively perform overall permutation on the channel measurement value sequences obtained in Step 1. Terminals A and B respectively perform segmentation of a fixed length on the overall permuted channel measurement value sequences and obtain the segmented channel measurement value sequences of terminals A and B. Moreover, terminal A performs partial re-permutation on the segmented channel measurement value sequence after overall permutation, and terminal A sends the obtained re-permuted segmented channel measurement value sequence to terminal B. Step 3: Key generation. Terminal A edits the segmented channel measurement value sequence of terminal A obtained in Step 2 and obtains the edited segmented channel measurement value sequence of terminal A, and sends the edited segmented channel measurement value sequence of terminal A to terminal B. Terminal B uses the segmented matching algorithm of the edit distance to match the segmented channel measurement value sequence of terminal B with the edited segmented channel measurement value sequence of terminal A, so as to enable terminal B to judge the editing mode of the edited segmented channel measurement value sequence of terminal A. In Step 3, the step in which terminal B uses the segmented matching algorithm of the edit distance to match the segmented channel measurement value sequence of terminal B with the edited segmented channel measurement value sequence of terminal A is: Step 3.20: Let the segmented sequence of the channel measurement values edited by terminal A and the segmented sequence of the channel measurement values after re-permutation by terminal B have an edit distance of where i ∈ [0, M p , j ∈ [0, M], κ i represents the number of segments contained in the segmented sequence of the channel sequence edited by terminal A M p represents the length of the segmented sequence of the channel measurement values edited by terminal A M represents the length of the segmented sequence of the channel measurement values after two permutations by terminal B ; Step 3.21: Use the dynamic programming method to obtain 's recurrence formula: where \(i\in[1,M p \), \(j\in[1,M]\), and the boundary values are defined as C ins is the edit cost of the insertion operation and \(C ins = 1\), \(C del is the edit cost of the deletion operation and \(C del = 1;\) The dynamic programming method terminates at by backtracking a shortest path from to and inferring the edit operations corresponding to the edit distance ; Step 3.22: Terminal B infers the segmented sequence of channel measurement values edited by terminal A The unedited segments in correspond to the channel measurement value segment sequence after the terminal B replaces Index in And infer the segmented sequence of channel measurement values edited by terminal A The segment to be inserted in corresponds to the segment sequence of the channel measurement value after the replacement by terminal B. Index in Among them, M r Indicates the number of unedited segments, L i Indicates the number of inserted segments; Step 3.23: Index obtained by terminal B and the index obtained by terminal A can be used as the only and confidential sequence between terminal A and terminal B for subsequent key establishment; Step 4: Information reconciliation and privacy amplification. According to the judgment result of the editing mode of the edited segmented channel measurement value sequence of terminal A by terminal B in Step 3, terminals A and B perform information reconciliation and privacy amplification and obtain the key. The steps for terminals A and B to perform information reconciliation are: Step 4.10: Terminals A and B perform a two-round challenge-response information exchange. The challenge-response information exchange is as follows: B→A:X BA =(σ') -1 (S B ⊕R) A→B:X AB = σ(X BA ⊕S A ) wherein, ⊕ represents a logical exclusive OR operation, and R is a random vector of length M r +L i , and is the average value of each segmented subset in the segmented sequence of the channel measurement values edited by terminal A, σ(·) represents a permutation function with the index order as the permutation sequence; in addition, let σ'(·) represent a permutation function with the index order as the permutation sequence; (σ') (·) represents the inverse permutation of σ'(·) that makes σ'[(σ') -1 (S -1 )] = S B ; B Step 4.11: Terminal B calculates X B = S B ⊕ R ⊕ σ'(S B ), Terminal B identifies the indices of the elements that are not equal between X BA and X B as Φ = [φ1, φ2,..., φ S , where each φ s ∈ [1, M r + L i , S is the number of elements that are not equal between X BA and X B , Terminal B repeatedly exchanges the mismatched elements several times until X AB = X B ; Step 4.12: Terminals A and B reach a consistent permutation sequence σ = σ'.
2. The key generation method based on the aligned edited sequences according to claim 1, wherein In step 1, the sampling of the channel measurement values by terminal A and terminal B is carried out within the channel coherence time of terminal A and terminal B, and continues until a certain number of channel measurements are collected at both terminal A and terminal B. The sequences of the channel measurement values collected by terminal A and terminal B are respectively denoted as and Among them, V A is the channel measurement value sequence of terminal A, and V B is the channel measurement value sequence of terminal B.
3. The key generation method based on the aligned edited sequences according to claim 2, wherein The steps for permutation, segmentation, and re-permutation of the channel measurement values in Step 2 are: Step 2.1: The terminal A performs a measurement on the channel measurement sequence of terminal A to perform a random overall permutation S h to obtain the permuted channel measurement value sequence of terminal A Step 2.2: The terminal A calculates the sample entropy of the sequence of the channel measurement values of the permuted terminal A obtained in Step 2.1 to measure the complexity of the sequence of the channel measurement values of the permuted terminal A; Step 2.3: The terminal A divides the sequence of the channel measurement values of the terminal A after permutation into M with a fixed length Segment sequence of channel measurement values of terminal A Among them, represents the m-th segment in P A , and terminal B divides the channel measurement value sequence V B into M segment sequences of channel measurement values of terminal B with a fixed length Among them represents the m-th segment in P B ; Step 2.4: Terminal A repeatedly performs a random partial re - permutation S on each segment in the sequence P of channel measurement values of Terminal A A until the sample entropy of each segment reaches a pre - set threshold, and obtains the sequence of segments of the channel measurement values of Terminal A after re - permutation f Step 2.5: The terminal A combines the permutation S in Step 2.1 h and the re - permutation S in Step 2.4 f , and obtains a permutation sequence [k1, k2, …, k N , where k n ∈[1, N] represents the original index in the channel measurement sequence of the terminal A A in the channel measurement sequence V of the terminal A; Step 2.6: Transmit the permutation sequence [k1, k2, …, k N obtained by terminal A in Step 2.5 to terminal B; Step 2.7: After receiving the permutation sequence [k1, k2, …, k N from terminal A, terminal B permutes the channel measurement value sequence V A of terminal B in the same order as terminal A permutes the channel measurement sequence V B of terminal A, and obtains the segmented sequence of the channel measurement values after re - permutation of terminal B 4. The key generation method based on the aligned edited sequences according to claim 3, wherein In step 3, the terminal A performs segmentation on the channel measurement value sequence after the second replacement of the terminal A obtained in step 2.5 Perform multiple insert or delete edit operations and generate M p segmented sequences of the edited channel measurement values of terminal A with the length of each segment where represents the i-th segmented sequence of the edited channel measurement values, where 1 ≤ i ≤ M p .
5. The key generation method based on the edited sequence alignment according to claim 4, characterized in that Segment sequence of channel measurement values edited by terminal A The generation steps are as follows: Step 3.10: Terminal A randomly and without repetition selects L i indexes as the insertion positions, or selects L d indexes as the deletion positions; Step 3.11: Terminal A inserts or deletes segments randomly into the sequence . When inserting a segment at position α in the segmented sequence of the channel measurement values after re-permuting Terminal A , we can obtain . Among them, the remaining segments are the original channel measurement value segments in . When deleting a segment at position β in the segmented sequence of the channel measurement values after re-permuting Terminal A , we can obtain . When deleting a segment at position β , we can obtain Step 3.12: After terminal A has performed L i insertions or L d deletions, terminal A obtains the segmented sequence of channel measurement values edited by terminal A wherein, represents the number of segments of the channel measurement values after performing L i insertions or L d deletions. Terminal A sends the segmented sequence of channel measurement values edited by terminal A to user B.
6. The key generation method based on the edited sequence alignment according to claim 5, wherein The L in step 3.10 i indexes and the L d indexes each independently follows a uniform distribution in the range from 0 to M.
7. The key generation method based on the edited sequence alignment according to claim 5, characterized in that In step 3.11, when inserting a segment into the segmented sequence of channel measurement values after re-permuting terminal A at position α the inserted segment is randomly selected from the segmented sequence of channel measurement values after re-permuting terminal A in another round of key generation process and the segments independently follow the same distribution as the original segments.
8. The key generation method based on the aligned edited sequences according to claim 1, characterized in that The way for terminal A and terminal B to perform privacy amplification is as follows: Terminal A and terminal B use a permutation operation to calculate SK = σ(S A ) = σ'(S B ), and use it as the final secret key.