An intelligent channel key extraction method based on code bit rearrangement in the Internet of Things

By adopting the intelligent channel key extraction method of code bit rearrangement in the Internet of Things, error correction code encoding and decoding are used to generate code bit rearrangement tables, the problem of poor key extraction performance under low signal-to-noise ratio is solved, and high consistency and security key generation is achieved.

CN115412910BActive Publication Date: 2025-08-05XI AN JIAOTONG UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210907929.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-29
Publication Date
2025-08-05
Estimated Expiration
2042-07-29

AI Technical Summary

Technical Problem

The existing physical layer key extraction technology based on channel characteristics is poor in performance under low signal-to-noise ratio conditions, and it is impossible to effectively generate keys with consistency and security.

Method used

The first node generates the coded codeword and generates a code bit rearrangement table. Combined with error correction code encoding and decoding, the channel state information is rearranged and the master-slave key is generated.

Benefits of technology

High consistency and security of keys are achieved under low signal-to-noise ratio conditions, and spatial uniqueness of wireless channels is used to ensure that eavesdroppers cannot obtain key information, which improves the key generation rate and consistency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115412910B_ABST
    Figure CN115412910B_ABST
Patent Text Reader

Abstract

The present application provides an intelligent channel key extraction method based on code position reordering in the Internet of Things. The method includes: a first node and a second node alternately send pilot information to each other; after receiving the pilot information, the receiving node estimates channel state information to obtain a first original channel sequence at the first node and a second original channel sequence at the second node; the receiving node can be the first node or the second node; the first node generates a first key and an encoded codeword; the first node generates a code position reordering table based on the encoded codeword and the first original channel sequence, and sends the code position reordering table to the second node; the second node generates a second key based on the code position reordering table; and a master key and a slave key are determined based on the first key and the second key. This scheme can achieve key extraction based on channel state information under low signal-to-noise ratio conditions.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of electronic information technology, and in particular relates to an intelligent channel key extraction method based on code bit rearrangement in the Internet of Things. Background Art

[0002] With the widespread adoption of 5G and the Internet of Things (IoT) and the Internet of Vehicles (IoV), wireless communications have become an integral part of social life. However, due to the inherent broadcast nature of wireless communications, these systems present significant security risks, primarily through eavesdropping, tampering, unauthorized access, and paralysis attacks. Asymmetric key systems in traditional cryptography can provide a unique key distribution method, but these key distribution processes rely on large number calculations (such as the RSA algorithm), a computational overhead that hardware devices often cannot meet. Furthermore, with the increase in computing power and breakthroughs in quantum computing research, both symmetric and asymmetric key systems face the risk of brute force attacks.

[0003] Secret Key Generation (SKG) technology based on wireless channels has attracted widespread attention due to their short-term reciprocity, randomness, and spatial-temporal uniqueness. In wireless channels, correlation beyond half a wavelength can be considered extremely low, providing strong security for SKG. The short-term reciprocity and randomness of wireless channels ensure the consistency and randomness of key extraction.

[0004] In the physical layer key extraction scheme based on channel characteristics, it generally consists of four stages: channel detection, key extraction, key negotiation, and confidentiality amplification.

[0005] 1) Channel sounding primarily involves both communicating parties detecting the same random signal source, or channel characteristics. Generally, both parties exchange pilot signals to obtain information about the wireless channel. Common channel characteristics include received signal strength (RSS), channel state information (CSI), and signal phase.

[0006] 2) Key extraction involves the communication parties using quantization and other methods to obtain a highly correlated random key based on channel characteristics. However, this key is affected by differences in channel conditions and the noise level of the receiver on both sides, making it difficult to guarantee key consistency.

[0007] 3) Key negotiation: By interactively extracting partial information from the initial key and performing screening or error correction, a key with a high consistency rate is obtained. Key negotiation must minimize the leakage of key information while achieving the effect of improving key consistency.

[0008] 4) Confidentiality amplification. During the channel negotiation phase, the eavesdropper will inevitably obtain partial information about the key. To ensure the final key has high security, linear mapping or hash mapping is often used to minimize the amount of key information obtained by the eavesdropper.

[0009] In the above-mentioned traditional SKG technology, several links with significant information loss are noted: the quantization process and the deletion process during key negotiation. Quantization is also a crucial step in traditional wireless communications, but it can cause partial loss of original information, thus affecting the performance of the entire system. During the key negotiation phase, keys with poor consistency are often directly deleted, which also reduces the utilization rate and generation rate of key information.

[0010] To achieve higher key extraction rates and key consistency, some SKG schemes often use multi-bit quantization. However, these methods often require good channel conditions (such as a signal-to-noise ratio (SNR) > 20dB). These SKG schemes perform poorly under low SNRs (SNR < 10dB).

[0011] In summary, the existing physical layer key extraction technology based on channel characteristics is only applicable to high signal-to-noise ratio conditions, and performs poorly under low signal-to-noise ratio (SNR<10dB). Summary of the Invention

[0012] The purpose of the embodiments of this specification is to provide an intelligent channel key extraction method based on code bit rearrangement in the Internet of Things, which can solve the problem of poor key extraction performance under low signal-to-noise ratio.

[0013] To solve the above technical problems, the embodiments of the present application are implemented in the following ways:

[0014] The present application provides an intelligent channel key extraction method based on code bit rearrangement in the Internet of Things, the method comprising:

[0015] A first node and a second node alternately send pilot information to each other, and after receiving the pilot information, a receiver estimates channel state information to obtain a first original channel sequence at the first node and a second original channel sequence at the second node; the receiver is the first node or the second node;

[0016] The first node generates a first key and an encoded codeword;

[0017] The first node generates a code bit rearrangement table according to the encoded codeword and the first original channel sequence, and sends the code bit rearrangement table to the second node;

[0018] The second node generates a second key according to the code position rearrangement table;

[0019] A master key and a slave key are determined according to the first key and the second key.

[0020] In one embodiment, the first node generates a first key and an encoded codeword, including:

[0021] The first node generates the first key according to a preset mechanism;

[0022] The first node encodes the first key using an error correction code encoder to obtain the encoded codeword.

[0023] In one embodiment, the first key is generated from a random source that obeys a 0 / 1 uniform distribution.

[0024] In one embodiment, the first node generates a code bit reordering table according to the encoded codeword and the first original channel sequence, including:

[0025] Sorting the first original channel sequence according to a preset method to obtain a first rearranged sequence;

[0026] The code point rearrangement table is generated according to the first rearrangement sequence and the encoded codeword.

[0027] In one embodiment, sorting the first original channel sequence according to a preset method to obtain a first rearranged sequence includes:

[0028] The first original channel sequence is sorted in descending order according to the magnitude of the true value, and the sorting result retains the original position and the sorted position of any channel to obtain the first rearranged sequence.

[0029] In one embodiment, generating the code point rearrangement table according to the first rearrangement sequence and the encoded codeword includes:

[0030] Initialize and mark all the position information of all channels in the first rearranged sequence as unused; wherein the position information includes the original position and the sorted position;

[0031] The encoded codewords are read in a front-to-back order, and for any of the read encoded codewords, a channel is extracted from the first rearranged sequence according to a specific extraction mechanism, original position information of the extracted channel is entered into a preset code position rearrangement table, and the position information of the extracted channel is marked as used;

[0032] When all the encoded codewords are retrieved or the position information of the channels in the first rearrangement sequence are all marked as used, the preset code point rearrangement table is used as the code point rearrangement table.

[0033] In one embodiment, the encoded codeword is 0 or 1;

[0034] The extraction mechanism is specifically as follows:

[0035] If the encoded codeword read is 0, the first unused channel in the first rearranged sequence is extracted; if the encoded codeword read is 1, the last unused channel in the first rearranged sequence is extracted.

[0036] In one embodiment, the second node generates the second key according to the code bit rearrangement table, including:

[0037] The second node sorts the second original channel sequence at the second node according to the code bit rearrangement table to obtain a second rearranged sequence;

[0038] The second rearranged sequence is input into a decoder to obtain the second key; the decoder and the encoder correspond to each other.

[0039] In one embodiment, determining a master key and a slave key based on the first key and the second key includes:

[0040] Any node determines a key length according to an implementation method and a signal-to-noise ratio, and sends the key length to another node; the any node includes the first node or the second node;

[0041] The first node truncates the tail of the first key according to the key length to obtain the master key or the slave key;

[0042] The second node truncates the tail of the second key according to the key length to obtain the slave key or the master key.

[0043] In one embodiment, if the signal-to-noise ratio, the encoding rate, and the encoding type are determined or known, the key length is determined based on the signal-to-noise ratio, the encoding rate, and the encoding type;

[0044] The first node generates a code bit rearrangement table according to the encoded codeword and the first original channel sequence, including:

[0045] The first node generates a code bit reordering table according to the encoded codeword, the first original channel sequence, and the key length;

[0046] The determining of a master key and a slave key according to the first key and the second key includes:

[0047] The first key determines the master key or the slave key according to the key length;

[0048] The second key is used as the slave key or the master key.

[0049] It can be seen from the technical solution provided in the above embodiments of this specification that this solution can realize key extraction based on channel state information under low signal-to-noise ratio, and can adjust the encoding rate according to channel conditions to obtain better performance; this solution is extremely secure, and the information such as the code bit reordering table exchanged by the communicating parties does not contain any information about the key itself. The spatial uniqueness of the wireless channel ensures that eavesdroppers cannot obtain the key. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] In order to more clearly illustrate the embodiments of this specification or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments recorded in this specification. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.

[0051] Figure 1 The system model provided for this application;

[0052] Figure 2 A flowchart of the key extraction method provided in this application;

[0053] FIG3 is a comparison curve of the performance of the present application and the comparative solution when the coding rate is 1 / 3 and the number of initial channel state information is 300, where: Figure 3a ), Figure 3b ), Figure 3c ) corresponds to signal-to-noise ratio SNR = 0, 5, 10dB respectively;

[0054] FIG4 is a comparison curve of the performance of the present application and the comparative solution when the coding rate is 1 / 5 and the number of initial channel state information is 300, where: Figure 4a ), Figure 4b ) corresponds to signal-to-noise ratio SNR = 0, 5dB respectively;

[0055] Figure 5 The impact of the amount of initial channel state information on the number of keys generated by this application when the signal-to-noise ratio is 0dB and the key inconsistency rate is 0.01. DETAILED DESCRIPTION

[0056] To help those skilled in the art better understand the technical solutions in this specification, the following will provide a clear and complete description of the technical solutions in the embodiments of this specification, in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of this specification, not all of them. All other embodiments derived by those skilled in the art based on the embodiments in this specification without creative effort shall fall within the scope of protection of this specification.

[0057] In the following description, specific details such as specific system structures and techniques are provided for purposes of illustration rather than limitation to facilitate a thorough understanding of the embodiments of the present application. However, it will be apparent to those skilled in the art that the present application may be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid obscuring the description of the present application with unnecessary detail.

[0058] It will be apparent to those skilled in the art that various modifications and variations may be made to the specific embodiments described herein without departing from the scope or spirit of the present application. Other embodiments will be apparent to those skilled in the art from the present description. The present description and examples are intended to be illustrative only.

[0059] The words “include,” “including,” “have,” “contain,” etc. used in this document are open-ended terms, meaning including but not limited to.

[0060] Unless otherwise specified, "parts" in this application are calculated by mass.

[0061] The present invention will be further described in detail below with reference to the accompanying drawings and embodiments.

[0062] In related technologies, some SKG schemes often employ multi-bit quantization to achieve higher key extraction rates and key consistency rates. However, these methods often require good channel conditions (e.g., signal-to-noise ratio (SNR) > 20dB). These SKG schemes perform poorly under low SNRs (SNR < 10dB). Existing physical layer key extraction techniques based on channel characteristics are only suitable for high SNRs and perform poorly under low SNRs (SNR < 10dB).

[0063] Based on the above defects, this application proposes an intelligent channel key extraction method based on code bit rearrangement in the Internet of Things. By generating a code bit rearrangement scheme through the encoded codeword generated by the first node, key extraction based on channel state information can be realized under low signal-to-noise ratio conditions.

[0064] Reference Figure 1, which shows a system model applicable to the intelligent channel key extraction method based on code bit rearrangement in the Internet of Things provided by the embodiment of the present application. Figure 1 As shown, the system consists of three nodes: Alice, a legitimate master user (also called master node Alice or Alice, or simply A), Bob, a legitimate slave user (also called slave node Bob or Bob, or simply B), and Eve, an eavesdropper (abbreviated E). Alice and Bob have a bidirectional wireless link, transmitting in time-division duplex mode on the same frequency band. Eve, the eavesdropper, only performs passive eavesdropping and does not send any information.

[0065] In this application, legitimate users have a master-slave relationship. Alice is the master device, and Bob is the slave device. In the following embodiments, the error correction coding rate is set to k / n. That is, during the encoding process, when there are k input bits, n output bits are generated. Let the encoding process be enc(·) and the decoding process be dec(·).

[0066] Reference Figure 2 , which shows a flow chart of the intelligent channel key extraction method based on code bit rearrangement in the Internet of Things provided in the embodiment of the present application.

[0067] like Figure 2 As shown, an intelligent channel key extraction method based on code bit rearrangement in the Internet of Things may include:

[0068] S210, the first node and the second node alternately send pilot information to each other. After receiving the pilot information, the receiver estimates the channel state information to obtain the first original channel sequence at the first node and the second original channel sequence at the second node; the receiver is the first node or the second node. The first node and the second node can use the same error correction code encoder and decoder to process the information, that is, the first node uses the error correction code encoder to encode, and the second node uses the error correction code decoder to decode. It is understandable that the first node and the second node can also use the error correction code encoder and decoder with the same parameter configuration to process the information, that is, the first node uses the first error correction code encoder to encode, and the second node uses the second error correction code decoder to decode, and the parameter settings of the first error correction code and the second error correction code are consistent.

[0069] Specifically, the first node can be the node of the primary legitimate user Alice or the node of the secondary legitimate user Bob. Correspondingly, the second node can be the node of the legitimate user Bob or the node of the primary legitimate user Alice, without limitation. In the following embodiments, the first node is the node of the primary legitimate user Alice and the second node is the node of the secondary legitimate user Bob.

[0070] Let h ij , i, j∈A, B, E is the channel state information (CSI) from i to j. CSI is generally assumed to be a cyclically symmetric complex Gaussian random variable, whose real and imaginary parts can be decomposed into two uncorrelated random Gaussian variables, so it can be assumed that h ij It obeys the zero-mean normal distribution, that is, Alice and Bob work in half-duplex mode and take turns sending pilot signals to each other. The receiver estimates the CSI and obtains:

[0071]

[0072] in Represent the channel estimation values at A, B, and E respectively; w A 、w B 、w E They represent the receiver noise at A, B, and E respectively, definition is the signal-to-noise ratio (SNR) at node i; w A 、w B 、w E There is no correlation between them; the received noise and the channel state information are uncorrelated. When the interval between the legitimate nodes Alice and Bob sending pilot information to each other is less than the coherence time, it can be considered that reciprocity is satisfied, that is, h BA =h AB ; When the minimum distance between the eavesdropping node Eve and Alice and Bob is greater than half the wavelength of the frequency band used for communication, it is considered that h AE With h AB 、h BA Not related to each other.

[0073] The legitimate users Alice and Bob repeat the above channel detection process until they obtain a CSI estimation sequence of length M. That is, they correspond to the first original channel sequence at the first node and the second original channel sequence at the second node, respectively, wherein the estimated values are also assumed to be independent of each other.

[0074] S220: The first node generates a first key and an encoded codeword, which may include:

[0075] The first node generates the first key locally according to a preset mechanism;

[0076] The first node encodes the first key using an error correction code encoder to obtain the encoded codeword.

[0077] Specifically, the preset mechanism is a mechanism set according to actual needs. The first node generates a random first key (also called a master key) with a similar number of 0s and 1s through a certain mechanism.

[0078] The first node inputs the first key into the encoder for encoding to obtain an encoded codeword, where the encoded codeword has a value of 0 or 1.

[0079] Optionally, the generation source of the first key is a random source that obeys a 0 / 1 uniform distribution and takes a value of 0 or 1.

[0080] Optionally, the random source is a first original channel sequence at the first node.

[0081] Specifically, the master key generation source (or key source) can be any random source, which can be specified by the user. For example, the first original channel sequence at the first node in S210 can be used as the random source. When the original channel sequence follows a zero-mean Gaussian distribution and is mutually uncorrelated, a portion of the channel state information can be selected and subjected to single-bit quantization with equal probability to obtain the master key.

[0082] The following shows a primary user Alice node from its first original channel sequence Extract the master key Method:

[0083]

[0084] It should be noted that the method for generating the master key is not limited to this, and any random source that obeys a 0 / 1 uniform distribution can be used as the key source of this application.

[0085] The master node Alice applies a specific error correction code to the master key K A Encode and get the encoded codeword C A =enc(K A ).

[0086] It is understandable that the type of error correction code may be a repetition code, a convolutional code, a polar code, an LDPC code, or the like.

[0087] S230: The first node generates a code bit rearrangement table according to the encoded codeword and the first original channel sequence, and sends the code bit rearrangement table to the second node.

[0088] The first node generating a code bit rearrangement table according to the encoded codeword and the first original channel sequence may include:

[0089] Sorting the first original channel sequence according to a preset method to obtain a first rearranged sequence;

[0090] The code point rearrangement table is generated according to the first rearrangement sequence and the encoded codeword.

[0091] Sorting the first original channel sequence according to a preset manner to obtain a first rearranged sequence may include:

[0092] The first original channel sequence is sorted in descending order of true value, and the sorting result retains the original position and sorted position of any channel (but the specific value is not of interest and does not need to be retained), to obtain the first rearranged sequence.

[0093] Generating the code point rearrangement table according to the first rearrangement sequence and the encoded codeword may include:

[0094] Initialize and mark all the position information of all channels in the first rearranged sequence as unused; wherein the position information includes the original position and the sorted position;

[0095] Reading the encoded codewords in order from front to back, extracting a channel from the first rearranged sequence according to a specific extraction mechanism for any of the read encoded codewords, entering the original position of the extracted channel into a preset code position rearrangement table, and marking the position information of the extracted channel as used;

[0096] When all the encoded codewords are retrieved or the position information of the channels in the first rearrangement sequence are all marked as used, the preset code point rearrangement table is used as the code point rearrangement table.

[0097] Wherein, the encoded codeword is 0 or 1, and the extraction mechanism can be: if the encoded codeword read is 0, then the unused channel at the front of the first rearranged sequence is extracted; if the encoded codeword read is 1, then the unused channel at the back of the first rearranged sequence is extracted. It can be understood that it can also be set as: if the encoded codeword read is 1, then the unused channel at the front of the first rearranged sequence is extracted; if the encoded codeword read is 0, then the unused channel at the back of the first rearranged sequence is extracted. The specific setting method is matched with the symbol rule setting of the decoder. The following is an example of extracting the unused channel at the front of the first rearranged sequence when the encoded codeword read is 0, and extracting the unused channel at the back of the first rearranged sequence when the encoded codeword read is 0.

[0098] Specifically, Sort in descending order of true value, and we get in is the sorted channel state information, T sort represent Elements in For example, when The element with the largest truth value is but T sort [1]=5.

[0099] For example, assuming that the first original channel sequence for:

[0100]

[0101] After sorting in descending order according to the true value, the sorted channel state information is obtained for:

[0102] Correspondingly, the first rearranged sequence T obtained by sorting sort for

[0103]

[0104] Since we are not interested in the specific value of the original CSI value, It is not necessary to retain it, so according to the correspondence between the original position and the original CSI value in the first original channel sequence and the correspondence between the sorted position and the original CSI value in the sorted channel state information, the correspondence between the sorted position and the original position can be obtained, that is, the first rearranged sequence T is obtained. sort .

[0105] Then, the original positions and sorted positions of all channels in the first rearranged sequence are all initially marked as unused.

[0106] Next, the encoded codewords are read in order from front to back, one bit at a time.

[0107] The preset code position rearrangement table refers to a table with a blank space set in advance for the encoded code words and original positions to be filled in.

[0108] Exemplary:

[0109] I. Assume that the total number of channels in the first rearranged sequence is M, and the initial encoded codeword C A The reading order is i=1 (it can be understood that i is also the writing order of the code position rearrangement table), the left pointer lp is initialized to 1, and the right pointer rp is initialized to M, wherein the left pointer lp points to the first unused channel in the first rearrangement sequence, and the right pointer rp points to the last unused channel in the first rearrangement sequence; initializing the left pointer to point to 1 (lp=1) and initializing the right pointer to point to M (rp=M) means that the position information of all channels in the first rearrangement sequence is initialized and marked as unused.

[0110] II. If CA [i]=0, then T map [i]=T sort [p], lp = lp + 1;

[0111] If C A [i]=1, then T map [i]=T sort [rp], rp = rp-1;

[0112] III. If T map Generation is completed; otherwise i=i+1, repeat II.

[0113] S240: The second node generates a second key according to the code position rearrangement table, which may include:

[0114] The second node sorts the second original channel sequence at the second node according to the code bit rearrangement table to obtain a second rearranged sequence;

[0115] The second rearranged sequence is input into a decoder to obtain the second key; the decoder and the encoder correspond to each other.

[0116] Specifically, the slave node Bob reorders the table T according to the received code position map , the second original channel sequence from the node Rearrange to obtain the second rearranged sequence in,

[0117] The second rearrangement sequence Input the decoder corresponding to the error correction code to obtain the second key in, The positive value of is considered as '0', and the negative value is considered as '1'. When the dec(·) algorithm is soft information decoding, the larger the value is, the closer it is to '0', and the smaller the value is, the closer it is to '1'. This setting is the same as the symbol definition of the BPSK modulation method, and is consistent with the above T map The generation method remains consistent.

[0118] The decoder used in this step corresponds to the encoder used to generate the encoded codeword in S220, that is, the decoder is a codec of the same error correction code or a codec in an error correction code with the same parameter setting.

[0119] The above process of sorting the first original channel sequence makes the second rearranged sequence (or channel state information) rearranged in this step It also has a certain order, that is, the absolute value of the channel state information at the top of the ranking is larger - this feature means that the information at the top of the ranking is closer to 0 / 1 and is less prone to errors.

[0120] S250: Determine a master key and a slave key according to the first key and the second key.

[0121] Specifically, the master and slave nodes can determine the length of the generated key through negotiation, and retain the key with high consistency by truncating the tail.

[0122] In one embodiment, determining a master key and a slave key based on the first key and the second key includes:

[0123] Any node determines a key length according to an implementation method and a signal-to-noise ratio, and sends the key length to another node; the any node includes the first node or the second node;

[0124] The first node truncates the tail of the first key according to the key length to obtain the master key or the slave key;

[0125] The second node truncates the tail of the second key according to the key length to obtain the slave key or the master key.

[0126] Specifically, the master node (or slave node) obtains the expected key length by looking up a table (generated by simulation results) based on the implementation mode and the channel quality (signal-to-noise ratio) it observes, and sends the key length to the slave node (or master node);

[0127] The master node and the slave node apply the key length to truncate the tails of the generated first key and the generated second key respectively to obtain the final master key and slave key.

[0128] Simulations show that the length of the tail truncation is related to key consistency requirements, signal-to-noise ratio, encoding rate, and encoding type. Therefore, if these factors are known or determined, the size of the code point reordering table that needs to be transmitted can be reduced by applying the tail truncation length to the code point reordering table generation phase.

[0129] In one embodiment, if the signal-to-noise ratio, the encoding rate, and the encoding type are determined or known, the key length is determined based on the signal-to-noise ratio, the encoding rate, and the encoding type;

[0130] The first node generates a code bit rearrangement table according to the encoded codeword and the first original channel sequence, including:

[0131] The first node generates a code bit reordering table according to the encoded codeword, the first original channel sequence, and the key length;

[0132] The determining of a master key and a slave key according to the first key and the second key includes:

[0133] The first key determines the master key or the slave key according to the key length;

[0134] The second key is used as the slave key or the master key.

[0135] Specifically, when the encoding type, encoding rate, and key consistency requirements are determined, simulation can determine that the key length that can be generated under a certain signal-to-noise ratio is L and the necessary encoding overhead is L. ECC , the generation termination condition in the above example III. can be replaced by i==n / k(L+L ECC ).

[0136] In the embodiments of this application, when the error correction code type is a convolutional code, the proposed scheme outperforms other key extraction schemes at low signal-to-noise ratios. For different code rates, low code rates perform better at lower signal-to-noise ratios, while high code rates perform better at relatively higher signal-to-noise ratios.

[0137] In the embodiments of the present application, the generated key maximizes randomness, and the key obtained by using channel state information as a true random source is extremely secure. This security stems from the spatial uniqueness of the wireless channel. That is, when the distance between an eavesdropper and the legitimate master and slave nodes is greater than half a wavelength, the channel state information observed by the eavesdropper is independent of the channel state information between the legitimate nodes.

[0138] In the embodiment of the present application, no information about the key will be leaked during the key generation and negotiation process, and confidentiality is extremely strong. The information exchanged between the master and slave nodes includes the code bit rearrangement table and the key length. The code bit rearrangement table only contains the position information of the original channel sequence, and does not include any information about the value size of the original channel sequence. The slave node can use the position information to recover the code bit rearrangement, but the observation channel of the eavesdropper is not related to the observation channel of the legitimate node. The code bit rearrangement table does not help the eavesdropper to recover the key; the key length negotiation process does not use key-related information such as the check code, but is based on empirical information and also does not contain any information about the key.

[0139] Simulation Verification

[0140] Since the traditional multi-bit quantization SKG scheme performs poorly under low signal-to-noise ratio, multi-bit quantization schemes represented by CQG (Channel Quantization with Guardband) and VQ (Vector Quantization) all degenerate into single-bit quantization methods under low signal-to-noise ratio conditions. Therefore, in this simulation process, a typical single-bit dual-threshold quantization method (Level-crossing Algorithm, LCA) is used as a comparison scheme to compare with the key extraction method based on code bit rearrangement proposed in this application.

[0141] In the simulation, the number of initial channel state information is set to M = 300; the receiver noise of all users is the same, that is, The code bit reordering table used in the negotiation can be transmitted from the master user to the slave user without error. In this example, a convolutional code is used as the error correction code, with a code rate ranging from 1 / 3 to 1 / 5 and a constraint length of 7.

[0142] The performance metrics include the following:

[0143] ① Bit Generation Rate (BGR) refers to the average number of keys that can be generated from a single channel state information. The consistency of the master and slave user keys is not considered.

[0144]

[0145] in Represents the average.

[0146] ② Key Disagreement Probability (KDP). When there is at least one bit of inconsistency between the key sequences generated by the master and slave users, the key pair is considered inconsistent. KDP is the average of multiple experiments.

[0147] The simulation results are shown in Figures 3, 4, Figure 5 shown.

[0148] Figure 3 compares the performance of LCA and the method of this application (corresponding to the code bit rearrangement algorithm mentioned in Figure 3) under the conditions of coding rate of 1 / 3 and signal-to-noise ratio of 0, 5, and 10dB. Figure 3b ), when KDP is less than 6×10 -3 When , the BGR of the proposed code bit rearrangement scheme is greater than that of the LCA algorithm; when SNR=0dB, Figure 3a), the proposed code position reordering algorithm can generate more keys; under the condition of KDP of 0.02, the BGR of the LCA algorithm is about 2%, while the BGR of the code position reordering algorithm is about 2.33%. The BGR of the code position reordering algorithm is improved by about 16.5% compared with the LCA algorithm. Figure 3c ), when SNR=10dB, the LCA algorithm is better than the code bit rearrangement algorithm as a whole.

[0149] It's worth noting that as the signal-to-noise ratio (SNR) increases, the intersection point between the proposed code permutation algorithm and the LCA algorithm shifts downward and to the right, and the code permutation algorithm's performance decreases more rapidly as the BGR decreases. Therefore, it's reasonable to speculate that at an SNR of 10dB, if the KDP is below a very low value, the code permutation algorithm can obtain more highly consistent keys than the LCA algorithm. The code permutation algorithm can be used to achieve ultra-high-precision key extraction in high-SNR scenarios.

[0150] Figure 4 compares the performance of LCA and the proposed method under the conditions of 1 / 5 coding rate and 0 and 5dB signal-to-noise ratio. In Figures 3 and 4, the LCA algorithm remains unchanged, so Figure 3a )and Figure 4a ), Figure 3b )and Figure 4b ) are exactly the same as the LCA algorithm curves in . Figure 3a )and Figure 4a ), it is found that when SNR = 0dB, the number of keys generated when the encoding rate is 1 / 5 is significantly higher than the number of keys when the encoding rate is 1 / 3. When BGR = 2%, the KDP of the code bit rearrangement scheme proposed in this application is less than 4×10 -2 , an order of magnitude higher than the KDP of the LCA scheme. When KDP = 0.02, the BGR of the LCA algorithm is about 2%, and the BGR of the 1 / 5 code rate code bit rearrangement scheme is about 3.11%, which is 55% higher than the LCA scheme under the same KDP, and 33.4% higher than the 1 / 3 code rate scheme. Figure 3b )and Figure 4b ) found that when SNR = 5dB, the performance of the 1 / 5 code rate code bit rearrangement scheme is worse than that of the 1 / 3 code rate code bit rearrangement scheme, but the KDP of the 1 / 5 code rate code bit rearrangement scheme decreases faster with BGR. For example, when KDP = 10 -3 When BGR=6%, the BGR of the 1 / 3 code rate code bit rearrangement scheme is greater than that of the LCA scheme, while the BGR of the 1 / 5 code bit rearrangement scheme is less than that of the LCA scheme. When BGR=6%, the KDP of the 1 / 3 code rate code bit rearrangement scheme is about 2×10 -5 , KDP4×10 solves the 1 / 5 code position rearrangement solution -5 , the slope of the 1 / 5 code position rearrangement scheme is larger.

[0151] Figure 5 Compared with KDP=10 -2 The effect of the initial channel state information quantity M on the BGR when SNR = 0dB. When M ranges from 300 to 1200, increasing M improves the BGR. In further experiments, regardless of bit rate, whether 1 / 3 or 1 / 5, the BGR stabilizes when M increases to above 1800, with almost no increase in BGR observed.

[0152] Simulation results analysis:

[0153] Conclusion 1: Under low signal-to-noise ratio conditions, the proposed code bit rearrangement scheme performs better than the comparative scheme LCA;

[0154] Conclusion 2: The performance of the proposed code bit reordering scheme is related to the coding rate and signal-to-noise ratio (SNR). Different coding rates have different applicable SNR ranges. Simulation results show that when the code rate is 1 / 3, the code bit reordering scheme performs best at SNR = 5dB; when the code rate is 1 / 5, the code bit reordering scheme performs best at SNR = 0dB.

[0155] Conclusion 3: The curve of the code bit rearrangement scheme proposed in this application is steeper, that is, as BGR decreases, KDP decreases faster; the higher the encoding bit rate, the steeper the curve. Although the performance of this application is inferior to the LCA scheme under relatively high signal-to-noise ratio conditions, as KDP decreases, the code bit rearrangement scheme will generate more keys compared to the LCA scheme. In summary, the code bit rearrangement scheme proposed in this application can be used to achieve ultra-high-precision key extraction in high signal-to-noise ratio scenarios.

[0156] Randomness analysis:

[0157] According to S220, the generation of the master key is solely dependent on the key generation mechanism of the primary user Alice; the slave key is generated based on the master key. When the master key generation process is completely random and there is no clear dependency between keys, the key is considered random. When the channel state information follows a zero-mean Gaussian distribution and the channel state information at different times is uncorrelated, the key generated according to formula (2) is random and uniformly distributed.

[0158] Security Analysis:

[0159] According to the characteristic that channels beyond half a wavelength are uncorrelated, when the distance between the eavesdropper and the master and slave users is greater than half a wavelength, it can be considered that the eavesdropper cannot obtain the original channel state information of the legitimate user.

[0160] Security analysis focuses on whether the negotiation process carries key information. In the proposed code bit reordering scheme, the code bit reordering table transmitted during the negotiation phase does not carry any information about the key being 0 or 1. In this proposed code bit reordering scheme, each channel state information is used only once, resulting in the highest security. An eavesdropper cannot obtain any key information. The tail truncation process also does not carry any key information.

[0161] Complexity analysis:

[0162] The complexity analysis of the physical layer key extraction scheme is mainly divided into computational complexity and negotiation complexity.

[0163] From a computational complexity perspective, the proposed solution is primarily divided into the primary user's sorting overhead, encoding overhead, and code point reordering overhead, as well as the secondary user's decoding overhead. The primary user's overhead is O(M log2M), O(M), and O(M), respectively. For the secondary user, the soft information decoding overhead is relatively high, but decoding modules are already widely used in wireless devices, so this part of the work can be completed using existing decoding modules.

[0164] Negotiation complexity mainly represents the amount of negotiation information, which is reflected in the bandwidth occupied by the negotiation process. The code position reordering table involved in the solution proposed in this application has a total size of When M=1024, LCA transmits 1024 bits, and the size of the code position reordering table is 10240 bits. However, by applying tail truncation to the reordering table generation, the size of the reordering table required for negotiation can be greatly reduced. Simulation results show that when the signal-to-noise ratio SNR=0dB, the generated bits do not exceed 5% bps (bits per sample), that is, no more than 50 bits. Considering the coding rate of 1 / 5 and a certain coding overhead, the amount of reordering table information that needs to be transmitted in the actual code position reordering scheme is about 3000 to 4000 bits. On the other hand, the performance improvement is very limited when M exceeds 1800, so the size of the code position reordering table is It won't grow indefinitely.

[0165] It should be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.

[0166] The various embodiments in this specification are described in a progressive manner. Similar parts between the various embodiments can be referred to in conjunction with each other. Each embodiment focuses on the differences between the other embodiments. In particular, the system embodiments are generally similar to the method embodiments, so the description is relatively simple. For relevant parts, refer to the description of the method embodiments.

Claims

1. An intelligent channel key extraction method based on code bit rearrangement in the Internet of Things, characterized in that: The method comprises: A first node and a second node alternately send pilot information to each other, and after receiving the pilot information, a receiver estimates channel state information to obtain a first original channel sequence at the first node and a second original channel sequence at the second node; the receiver is the first node or the second node; The first node generates a first key and an encoded codeword; The first node generates a code bit rearrangement table according to the encoded codeword and the first original channel sequence, including: Sorting the first original channel sequence according to a preset method to obtain a first rearranged sequence includes: sorting the first original channel sequence in descending order of true value, retaining the original position and sorted position of any channel in the sorting result, to obtain the first rearranged sequence; Generating the code point rearrangement table according to the first rearrangement sequence and the encoded codeword includes: Initialize and mark all the position information of all channels in the first rearranged sequence as unused; wherein the position information includes the original position and the sorted position; Reading the encoded codewords in order from front to back, extracting a channel from the first rearranged sequence according to a specific extraction mechanism for any of the read encoded codewords, entering the original position of the extracted channel into a preset code position rearrangement table, and marking the position information of the extracted channel as used; When all the encoded codewords are extracted or the channel position information in the first rearrangement sequence is all marked as used, the preset code position rearrangement table is used as the code position rearrangement table, and the code position rearrangement table is sent to the second node, wherein the encoded codeword is 0 or 1, and the extraction mechanism is specifically as follows: If the encoded codeword read is 0, extracting the first unused channel in the first rearranged sequence; if the encoded codeword read is 1, extracting the last unused channel in the first rearranged sequence; The second node generates a second key according to the code position rearrangement table; A master key and a slave key are determined according to the first key and the second key.

2. The method according to claim 1, characterized in that The first node generates a first key and an encoded codeword, including: The first node generates the first key according to a preset mechanism; The first node encodes the first key using an error correction code encoder to obtain the encoded codeword.

3. The method according to claim 2, characterized in that The first key is generated from a random source that obeys a 0 / 1 uniform distribution.

4. The method according to claim 2, characterized in that The second node generates a second key according to the code position rearrangement table, including: The second node sorts the second original channel sequence at the second node according to the code bit rearrangement table to obtain a second rearranged sequence; The second rearranged sequence is input into a decoder to obtain the second key; the decoder and the encoder correspond to each other.

5. The method according to claim 1, wherein The determining of a master key and a slave key according to the first key and the second key includes: Any node determines a key length according to an implementation method and a signal-to-noise ratio, and sends the key length to another node; the any node includes the first node or the second node; The first node truncates the tail of the first key according to the key length to obtain the master key or the slave key; The second node truncates the tail of the second key according to the key length to obtain the slave key or the master key.

6. The method according to claim 1, characterized in that If the signal-to-noise ratio, encoding rate, and encoding type are determined or known, determining the key length based on the signal-to-noise ratio, the encoding rate, and the encoding type; The first node generates a code bit rearrangement table according to the encoded codeword and the first original channel sequence, including: The first node generates a code bit reordering table according to the encoded codeword, the first original channel sequence, and the key length; The determining of a master key and a slave key according to the first key and the second key includes: The first key determines the master key or the slave key according to the key length; and the second key is used as the slave key or the master key.

Citation Information

Patent Citations

  • Method for protection of ProSe communication session and WTRU

    CN110149621A

  • Key sharing method based on artificial noise and security coding in edge computing

    CN111934863A