A method and apparatus for generating a secret key, a storage medium, and a computer device
The method generates secure session keys using TDD wireless channels for wireless communication, addressing the inefficiencies and vulnerabilities of traditional key encryption by ensuring consistent key generation and distribution, thereby enhancing communication security.
Patent Information
- Application Number
- CN202211346215.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-31
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2042-10-31
AI Technical Summary
Traditional wireless communication key encryption technology has problems such as high complexity, high cost and easy to crack in dynamic wireless networks, and it is impossible to achieve "one secret at a time" secure communication.
Using a wireless channel key generation method based on the TDD mode, a consistent target session key sequence is generated through channel estimation, channel feature extraction and single-gate limiting between legal communication nodes, and a consistent target session key sequence is achieved using space-time consistency.
It improves the security of information transmission, reduces the cost of key generation and cracking risks, and realizes efficient "one password at a time" encrypted communication.
Smart Images

Figure CN115883063B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication technologies, and in particular, to a method and apparatus for generating a key, a storage medium, and a computer device. Background Art
[0002] Currently, wireless communication has been widely applied in both military and civilian fields. However, the open characteristic unique to wireless communication results in low security of wireless information transmission. The traditional solution is to encrypt data through public and private key pairs at the network layer. However, in a dynamic wireless network, the symmetric encryption method needs to solve the problem of key distribution in wireless communication. On the one hand, key distribution introduces additional complexity and cost, and it is impossible to quickly update the key or use a one-time pad; on the other hand, the distribution process is prone to leakage. The asymmetric key algorithm requires high power and high computing costs that are difficult for mobile nodes to bear. The traditional key encryption technology cannot achieve "one-time pad", and there is a great possibility of being cracked, which is not conducive to the secure transmission of information. Generally speaking, the encryption method of a wireless communication system is basically cited and developed from the encryption mechanism of a wired communication system. If you want to ensure the security of this encryption method, then both legitimate parties must pre-distribute keys through a secure channel and require a sufficiently high encryption strength so that even if an eavesdropper understands the encryption algorithm, they cannot decrypt the information. This source encryption is based on an encryption method that is computationally infeasible. From the perspective of the transmission mechanism, the wireless channel is open, which makes it easy for wireless signals to be intercepted. When the intercepted key has not been cracked or intercepted, the information is also confidential. If the key remains unchanged within a certain time range, then the eavesdropping party can decrypt the key by using cryptanalysis techniques and high-speed computing techniques. Although increasing the key length and the number of key generation iterations can increase the difficulty of decryption for the eavesdropping party, it will also increase the difficulty of decryption and encryption for the terminal, and it cannot achieve "one-time pad" secure communication. Summary of the Invention
[0003] In view of the above problems, the present invention proposes a method and apparatus for generating a key, a storage medium, and a computer device, which is a method for generating a key based on a wireless channel in the TDD mode, and uses spatio-temporal consistency to achieve "one-time pad", solving the problem that the method of the traditional key encryption technology for improving information security by increasing the key length and the number of key generation iterations has too high costs and a great possibility of being cracked.
[0004] According to a first aspect of the present invention, there is provided a method for generating a key, which is applied to at least two legitimate communication nodes, and the legitimate communication nodes communicate through a preset wireless channel based on the TDD mode. The method includes:
[0005] A first legitimate communication node and a second legitimate communication node generate a common training sequence for channel estimation;
[0006] The first legitimate communication node and the second legitimate communication node send the common training sequences to each other, and respectively perform channel estimation by using the common training sequence and the received target training sequence to obtain the first channel parameter H A and the second channel parameter H B ;
[0007] Respectively perform channel feature extraction based on the first channel parameter H A and the second channel parameter H B to obtain the first characteristic channel sequence X corresponding to the first legitimate communication node n and the second characteristic channel sequence Y corresponding to the second legitimate communication node n ;
[0008] Use the single-threshold quantization method to respectively convert the first characteristic channel sequence X n into a first target bit sequence, and convert the second characteristic channel sequence Y n into a second target bit sequence;
[0009] Perform consistency processing on the first target bit sequence and the second target bit sequence to obtain a consistent target session key sequence.
[0010] Optionally, the first legitimate communication node and the second legitimate communication node generate a common training sequence for channel estimation, including:
[0011] The first legitimate communication node generates an orthogonal sub-carrier including a pilot signal; performs pilot arrangement on the orthogonal sub-carrier to generate an initial training sequence;
[0012] Performs an IFFT transform on the initial training sequence, and adds a cyclic prefix to the initial training sequence after the IFFT transform is completed;
[0013] The first legitimate communication node and the second legitimate communication node perform signal synchronization based on the initial training sequence after the cyclic prefix is added to obtain a common training sequence §.
[0014] Optionally, the first legitimate communication node and the second legitimate communication node send the common training sequence to each other, and respectively perform channel estimation based on the LS algorithm by using the common training sequence and the received target training sequence to obtain the first channel parameter H A and the second channel parameter H B , including:
[0015] The first legitimate communication node sends the common training sequence § to the second legitimate communication node, and the second legitimate communication node receives the first training sequence §A;
[0016] The second legitimate communication node sends a common training sequence § to the first legitimate communication node, and the first legitimate communication node receives the second training sequence §B;
[0017] The first legitimate communication node and the second legitimate communication node respectively perform channel estimation on the received second training sequence §B and the first training sequence §A based on the LS algorithm, specifically including solving channel parameters using the following formula:
[0018]
[0019]
[0020]
[0021] The channel parameters are:
[0022]
[0023] The channel parameters on each subcarrier are:
[0024]
[0025] Among them, is the cost function; X is the transmitted signal; Y is the received signal; H is the channel response vector; is the estimated value of H; is the noise parameter; is the channel parameter; is the K-th element in, K = 0, 1, 2,..., N - 1.
[0026] Optionally, before the first legitimate communication node and the second legitimate communication node respectively perform channel estimation on the received second training sequence §B and the first training sequence §A based on the LS algorithm, the method further includes:
[0027] The first legitimate communication node and the second legitimate communication node respectively perform clock synchronization and frequency synchronization on the received second training sequence §B and the first training sequence §A, and remove the cyclic prefix;
[0028] Perform fft transformation on the second training sequence §B and the first training sequence §A after removing the cyclic prefix respectively.
[0029] Optionally, based on the first channel parameter H A and the second channel parameter H B perform channel feature extraction to obtain the first feature channel sequence X corresponding to the first legitimate communication node nThe second characteristic channel sequence Y corresponding to the second legitimate communication node n , including:
[0030] The first legitimate communication node and the second legitimate communication node respectively use the channel parameters on each subcarrier to extract channel characteristic signals based on channel characteristic parameters; the first legitimate communication node obtains the first channel characteristic sequence X corresponding to the channel characteristic parameters n ; the second legitimate communication node obtains the second channel characteristic sequence Y corresponding to the channel characteristic parameters n ;
[0031] wherein, the channel characteristic parameters include at least one of amplitude, phase, multipath delay, received signal angle, OFDM subcarrier information, etc.
[0032] Optionally, the using the single-threshold quantization method to convert the first channel characteristic sequence into a first target bit sequence and the second channel characteristic sequence into a second target bit sequence respectively includes:
[0033] Calculate the single-threshold quantization threshold of the first legitimate communication node and the second legitimate communication node according to the following formula:
[0034] a n = E(U n ) ± α·σ(U n )
[0035] wherein, U is a representative symbol of the first legitimate communication node or the second legitimate communication node; U n is the channel characteristic sequence, U n ∈(X n , Y n ); α is the quantization factor; E(U n ) is the mean value of the channel characteristic sequence, σ(U n ) is the standard deviation of the channel characteristic sequence;
[0036] Quantify each eigenvalue in the channel characteristic sequence using the following formula to obtain the bit value corresponding to each eigenvalue;
[0037]
[0038] wherein, x is each eigenvalue in the channel characteristic sequence; ε(x) is the bit value corresponding to each eigenvalue; a n is the single-threshold quantization threshold of the channel characteristic sequence;
[0039] Generate a first target bit sequence X using the bit values corresponding to each eigenvalue in the first channel characteristic sequence X n n‘ , generating a second target bit sequence Y using the bit values corresponding to each eigenvalue in the second channel feature sequence Y n . n′ .
[0040] Optionally, the consistency processing of the first target bit sequence and the second target bit sequence to obtain a consistent target session key sequence includes:
[0041] Using an error control coding-based correction method to correct the first target bit sequence X n‘ and the second target bit sequence Y n′ for inconsistent correction to obtain a first session key sequence and a second session key sequence after completing the inconsistent correction;
[0042] Using a Hash function to determine whether the first session key sequence and the second session key sequence after completing the inconsistent correction are exactly the same, and using the exactly the same first session key sequence or the second session key sequence as the target session key sequence.
[0043] Optionally, the using an error control coding-based correction method to correct the first target bit sequence X n ‘ and the second target bit sequence Y n′ for inconsistent correction to obtain a first session key sequence and a second session key sequence after completing the inconsistent correction includes:
[0044] Step 1: The first legitimate communication node determines an error control coding c, and generates a codeword s according to the error control coding c and the first target bit sequence X n‘ ; s = XOR(X n‘ , c);
[0045] Performing RS coding on the codeword s, and sending the codeword s after completing RS coding to the second legitimate communication node through USRP;
[0046] Step 2: The second legitimate communication node decodes the received RS coding to obtain the codeword s;
[0047] Generating a codeword c″ according to the codeword s and the second target bit sequence Y n′ ; c″ = XOR(Y n′ , s); and performing decoding correction on the codeword c″ to obtain a codeword c′;
[0048] Step 3: Judging whether the Hamming distance between the codeword c″ and the codeword c is less than the error correction capacity t; if the Hamming distance between the codeword c″ and the codeword c is less than the error correction capacity t, then X n‘=XOR(c′, s)=Y n′ ;
[0049] If the Hamming distance between the codeword c″ and the codeword c is greater than or equal to the error correction capacity t, the first legitimate communication node and the first legitimate communication node re - execute steps 1 - 3 or re - perform channel estimation until X n‘ =Y n′ , and respectively use X n‘ and Y n′ as the first session key sequence and the second session key sequence.
[0050] Optionally, the using the Hash function to determine whether the first session key sequence and the second session key sequence after inconsistency correction are exactly the same includes:
[0051] The first legitimate communication node and the second legitimate communication node respectively generate Hash functions of the first session key sequence and the second session key sequence, obtaining the first Hash function corresponding to the first legitimate communication node and the second Hash function corresponding to the second legitimate communication node; and encrypt and send the first Hash function and the second Hash function to each other;
[0052] The first legitimate communication node and the second legitimate communication node respectively receive the second Hash function and the first Hash function and decrypt them;
[0053] Respectively determine whether the decrypted first Hash function is the same as the second Hash function. If the first Hash function is the same as the second Hash function, the first session key sequence and the second session key sequence are the same.
[0054] Optionally, the method further includes:
[0055] The first legitimate communication node and the second legitimate communication node perform secrecy enhancement on the target session key sequence based on the Hash function using the second - order Rayleigh entropy.
[0056] According to the second aspect of the present invention, there is provided a key generation device, including:
[0057] A sequence generation module, configured to generate a common training sequence for channel estimation by a first legitimate communication node and a second legitimate communication node;
[0058] A channel estimation module, configured to send the common training sequence to each other by the first legitimate communication node and the second legitimate communication node, and respectively perform channel estimation using the common training sequence and the received target training sequence to obtain a first channel parameter H A and a second channel parameter H B ;
[0059] A feature extraction module, which is configured to perform channel feature extraction based on the first channel parameter H A and the second channel parameter H B respectively, so as to obtain a first feature channel sequence X corresponding to the first legitimate communication node n and a second feature channel sequence Y corresponding to the second legitimate communication node n ;
[0060] A quantization processing module, which is configured to use a single-threshold quantization method to convert the first feature channel sequence X n into a first target bit sequence and the second feature channel sequence Y n into a second target bit sequence;
[0061] A key generation module, which is configured to perform consistency processing on the first target bit sequence and the second target bit sequence to obtain a consistent target session key sequence.
[0062] According to a third aspect of the present invention, there is provided a storage medium, on which a computer program is stored. When the computer program is executed by a processor, the processor is caused to execute the steps of the key generation method according to any one of the first aspects of the present invention.
[0063] According to a fourth aspect of the present invention, there is provided a computer device, which is characterized by including a memory and a processor. A computer program is stored in the memory. When the computer program is executed by the processor, the processor is caused to execute the steps of the key generation method according to any one of the first aspects of the present invention.
[0064] A key generation method, device, storage medium, and computer device provided by the present invention generate a common training sequence for channel estimation through a first legitimate communication node and a second legitimate communication node; the first legitimate communication node and the second legitimate communication node send the common training sequence to each other, and respectively perform channel estimation by using the common training sequence and the received target training sequence to obtain a first channel parameter H A and a second channel parameter H B ; perform channel feature extraction based on the first channel parameter H A and the second channel parameter H B respectively, so as to obtain a first feature channel sequence X corresponding to the first legitimate communication node n and a second feature channel sequence Y corresponding to the second legitimate communication node n ; use a single-threshold quantization method to convert the first feature channel sequence X n into a first target bit sequence and the second feature channel sequence Y nConvert it into a second target bit sequence; perform consistency processing on the first target bit sequence and the second target bit sequence to obtain a consistent target session key sequence. The present invention extracts channel characteristic signals using spatio-temporal consistency, realizes a "one-time one-key" key generation method, improves the security of information transmission, and solves the problem that the traditional key encryption technology has too high a cost by increasing the key length and the number of key generation iterations and has a high possibility of being cracked.
[0065] The above description is only an overview of the technical solution of the present invention. In order to be able to understand the technical means of the present invention more clearly, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features and advantages of the present invention more obvious and understandable, the following specifically describes the embodiments of the present invention.
[0066] According to the following detailed description of the specific embodiments of the present invention in conjunction with the drawings, those skilled in the art will more clearly understand the above and other purposes, advantages and features of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0067] By reading the following detailed description of the preferred embodiments, various other advantages and benefits will become clear to those of ordinary skill in the art. The drawings are only for the purpose of showing the preferred embodiments and are not considered to be a limitation of the present invention. And throughout the drawings, the same reference numerals are used to represent the same components. In the drawings:
[0068] Figure 1 Shows a schematic flow chart of a key generation method provided by an embodiment of the present invention;
[0069] Figure 2 Shows a communication model diagram of two legitimate communication nodes provided by an embodiment of the present invention;
[0070] Figure 3 Shows a schematic diagram of subcarrier lattice type pilot arrangement provided by an embodiment of the present invention;
[0071] Figure 4 Shows a schematic flow chart of adding a cyclic prefix provided by an embodiment of the present invention;
[0072] Figure 5 Shows a schematic diagram of the time period for channel estimation between both sides of legitimate communication nodes provided by an embodiment of the present invention;
[0073] Figure 6 Shows a schematic flow chart of key negotiation based on error correction coding provided by an embodiment of the present invention;
[0074] Figure 7 Shows a schematic structural diagram of a key generation device provided by an embodiment of the present invention;
[0075] Figure 8 Shows a schematic structural diagram of a key generation device provided by another embodiment of the present invention;
[0076] Figure 9 Shows a schematic physical structure diagram of a computer device provided by an embodiment of the present invention. Detailed implementation manners
[0077] Hereinafter, exemplary embodiments of the present disclosure will be described in more detail with reference to the accompanying drawings. Although the exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present disclosure can be more thoroughly understood and the scope of the present disclosure can be fully conveyed to those skilled in the art.
[0078] It should be noted that, in this document, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, such that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, the elements defined by the statement "including..." do not exclude the presence of additional identical elements in the process, method, article or device including the said elements.
[0079] To further enhance the understanding of the content of the present invention, the invention logic of the key generation method based on the TDD mode proposed by the present invention is briefly introduced as follows:
[0080] The open nature of wireless communication affects the security of information transmission in the channel. However, the uniqueness and distinctiveness of the wireless channel are also important resources for secure communication. The channels of wireless communication terminals at different locations have characteristics such as reciprocity, spatial variability, and temporal variability within the coherence time. Therefore, these characteristics can be used to find effective solutions for key distribution. The two legitimate parties can utilize the channel characteristics, extract characteristic signals for key generation, and use the generated keys for encrypted communication and access authentication. According to the channel reciprocity, when the two legitimate parties mutually send signals to estimate sequences within the coherence time for channel estimation, the estimated channel information of the two legitimate parties is reciprocal. The two legitimate parties independently extract channel characteristics and generate keys through processes such as quantization, information negotiation, and secrecy enhancement. The generated keys are securely transmitted as key information. According to the spatial variability and temporal variability of the wireless channel, the two legitimate parties only need to generate keys again outside the coherence time or at different locations, and then use the keys for secure transmission again. The eavesdropper cannot follow the channel changes of the two legitimate parties at different times and different locations, so it cannot steal any information about the generated keys. Thus, "one-time pad" secure communication can be achieved based on the characteristics of the wireless channel.
[0081] An embodiment of the present invention provides a key generation method, which is applied to at least two legitimate communication nodes. The legitimate communication nodes communicate through a preset wireless channel based on the TDD mode, such as Figure 1 shown. The method may at least include the following steps S101 to S105:
[0082] Step S101, the first legitimate communication node and the second legitimate communication node generate a common training sequence for channel estimation.
[0083] The key generation method provided by the embodiment of the present invention can be applied to multiple legitimate communication nodes. The legitimate communication nodes communicate pairwise through a preset wireless channel based on the TDD mode. The TDD mode means that the reception and transmission in a mobile communication system are in different time slots of the same frequency channel (i.e., carrier wave) to ensure time separation of the reception and transmission channels. The following content will be described by taking the first legitimate communication node A and the second legitimate communication node B as examples. The communication model diagram of the two legitimate communication nodes is as Figure 2 shown.
[0084] First, the first legitimate communication node and the second legitimate communication node generate a training sequence § for channel estimation. Specifically, the first legitimate communication node generates an orthogonal subcarrier including a pilot signal; arranges the pilot signals of the orthogonal subcarriers to generate an initial training sequence; performs an IFFT transform on the initial training sequence, and adds a cyclic prefix to the initial training sequence after the IFFT transform is completed; the first legitimate communication node and the second legitimate communication node perform signal synchronization based on the initial training sequence after adding the cyclic prefix to obtain a common training sequence §.
[0085] Specifically, the generation process of the training sequence can be divided into the following steps S101-1 to S101-4:
[0086] Step S101-1: The first legitimate communication node and the second legitimate communication node generate the required number of orthogonal subcarriers, that is, there is no ICI subcarrier interference. Generally, to reduce the DC component of the subcarrier channel estimation, a pilot signal is added to the subcarrier, and the mean value of the pilot signal is 0.
[0087] Step S101-2: As Figure 3 shown, the generated subcarriers are arranged in a lattice-type pilot to generate an initial training sequence. Since it is not necessary to consider the data transmission during the subsequent channel estimation, the generated training sequence is only used for channel estimation, and no data is inserted in the middle but filled with zeros. Both legitimate communication nodes must perform channel estimation within the coherence time, and there is also a time period for the transceiver of both legitimate communication nodes. Therefore, it is necessary to satisfy:
[0088]
[0089]
[0090] where t s represents the duration of the training sequence, S f is the pilot frequency domain period, σ max is the maximum delay spread; T f is the total duration of channel estimation; t d is the relative multipath delay in the wireless channel; t c is the transmission time for sending the training sequence; t RT is the transceiver conversion time of both legitimate communication nodes during channel estimation.
[0091] Step S101-3: Perform an ifft transform on the initial training sequence. The ifft transform is a process of transforming the generated training sequence into the time domain to facilitate the sending of the training sequence by both legitimate communication nodes.
[0092] Step S101-4: As Figure 4As shown in the figure, a cyclic prefix is added to the initial training sequence after the IFFT transformation. By copying a part of the points at the rear of a string of time-domain OFDM symbols after IFFT to the front of the string of OFDM symbols, the expansion of the OFDM symbols is completed. The length of the CP (Cyclic Prefix, CP) must be greater than or equal to the maximum delay of the multipath channel to ensure that the FFT transformation of OFDM is not affected by ISI. Taking the first legitimate communication node A or the second legitimate communication node B as the transmitting end, after adding the cyclic prefix to the initial training sequence, and then adding the synchronization training sequence for synchronization, the common training sequence § is obtained. The common training sequence § is sent to the second legitimate communication node B or the first legitimate communication node A as the receiving end through the USRP device over the real channel.
[0093] Step S102: The first legitimate communication node and the second legitimate communication node send the common training sequence to each other, and respectively perform channel estimation using the common training sequence and the received target training sequence to obtain the first channel parameter H A and the second channel parameter H B .
[0094] Before the two legitimate communication nodes perform channel estimation, the first legitimate communication node A and the second legitimate communication node B respectively receive the common training sequence § sent by the other party. That is, the first legitimate communication node A sends the common training sequence § to the second legitimate communication node B, and the second legitimate communication node B receives the first training sequence §A; the second legitimate communication node B sends the common training sequence § to the first legitimate communication node A, and the first legitimate communication node A receives the second training sequence §B; the target training sequence is the collective name of the first training sequence §A and the second training sequence §B. That is to say, the two legitimate communication nodes use the received signal as the second training sequence §B and the first training sequence §A.
[0095] Specifically, assume that the first legitimate communication node A first sends the common training sequence § to the second legitimate communication node B, and the second legitimate communication node B first performs channel estimation, and then the second legitimate communication node B sends the common training sequence § to the first legitimate communication node A for channel estimation. The sending process of channel estimation between the two legitimate communication nodes is as Figure 5 shown, including the following steps S102-1 to S102-4:
[0096] Step S102-1: First, determine the starting point t = 0. At this time, the first legitimate communication node A and the second legitimate communication node B are ready to send and receive the common training sequence §.
[0097] Step S102-2: First, the first legitimate communication node A sends the common training sequence § to the second legitimate communication node B, and the sending time is t s , and after the transmission time is t c, it reaches the second legitimate communication node B; since the second legitimate communication node B has been in a receiving state all the time, after t c later, the second legitimate communication node B immediately receives and stores the first training sequence §A. Due to the influence of the relative multipath delay t d in the wireless channel, the receiving time is greater than the sending time of the training sequence, and it is t s +t d . After the second legitimate communication node B finishes receiving, it uses the received first training sequence §A for channel estimation to generate the second channel parameter H B .
[0098] Step S102-3: After ensuring that the first legitimate communication node A has finished sending, the first legitimate communication node A changes from the sending end to the receiving end, and its duration is t TR ; similarly, after ensuring that the second legitimate communication node B has finished receiving, the second legitimate communication node B changes from the receiving end to the sending end, and its duration is t RT .
[0099] Step S102-4: The process of the second legitimate communication node B sending to the first legitimate communication node A is mirror to the process of the first legitimate communication node A sending a signal to the second legitimate communication node B. Therefore, the first legitimate communication node A can generate a second channel parameter H B . Thus, a complete channel estimation cycle is completed, and the total duration of the channel estimation cycle is T f . The parameters involved also include: t T is the duration of the transmitted signal, t R is the duration of the received signal, t p is the acquisition and storage period at the receiving end, T c is the coherence time. The estimation cycle must be less than the coherence time to ensure the reciprocity of channel estimation between the legitimate parties. Therefore, a complete channel estimation cycle T f needs to satisfy:
[0100] T f ≥2(t s +t c +t d )+t RT
[0101] T f ≤T c
[0102] Furthermore, channel estimation is performed using the common training sequence and the received target training sequence to obtain the first channel parameter H A and the second channel parameter H B .
[0103] It should be noted that after the first legitimate communication node A and the second legitimate communication node B respectively receive the second training sequence §B and the first training sequence §A, it is necessary to perform clock synchronization and frequency synchronization on the second training sequence §B and the first training sequence §A, remove the cyclic prefix, and perform fft transformation on the second training sequence §B and the first training sequence §A after removing the cyclic prefix respectively, so that the second training sequence §B and the first training sequence §A are converted to the frequency domain, which is convenient for subsequent calculation of channel parameters.
[0104] Specifically, the following formula can be used to solve the channel parameters:
[0105]
[0106] If the equation achieves a minimum value, then the partial derivative of should be equal to 0, then there is:
[0107]
[0108]
[0109] Therefore, the obtained channel parameters are:
[0110]
[0111] The channel parameters on each subcarrier are:
[0112]
[0113] Among them, is the cost function; X is the transmitted signal; Y is the received signal; H is the channel response vector; is the estimated value of H; is the noise parameter; is the channel parameter; is the K-th element in, K = 0, 1, 2,..., N - 1.
[0114] According to the above formula, the first legitimate communication node A and the second legitimate communication node B can respectively obtain the first channel parameter H A and the second channel parameter H B .
[0115] Step S103: Respectively perform channel feature extraction based on the first channel parameter H A and the second channel parameter H B to obtain the first characteristic channel sequence X n corresponding to the first legitimate communication node and the second characteristic channel sequence Y n corresponding to the second legitimate communication node.
[0116] Specifically, the first legitimate communication node and the second legitimate communication node can respectively use the channel parameters on each subcarrier to extract channel feature signals based on the channel feature parameters; the first legitimate communication node obtains the first channel feature sequence X corresponding to the channel feature parameters n ; the second legitimate communication node obtains the second channel feature sequence Y corresponding to the channel feature parameters n ; wherein, the channel feature parameters include at least one of amplitude, phase, multipath delay, received signal angle, and OFDM subcarrier information
[0117] According to the spatio-temporal consistency, these channel feature parameters are highly correlated between the two legitimate communication nodes. These channel feature parameters are extracted as the random sources of the two legitimate parties. The information obtained by the eavesdropper is uncorrelated with the information extracted by the two legitimate communication nodes, and the randomness is very large and even after quantization, a key that matches the two legitimate parties cannot be obtained. Since the above channel estimation method will obtain the information on the frequency-domain subcarriers, it is very convenient to extract the information of the subcarriers as features, and it is also the envelope of the channel estimation in the frequency domain
[0118] Exemplarily, for the convenience of implementation on the USRP platform, the embodiment of the present invention uses the subcarrier amplitude attenuation information as the channel feature parameter. USRP refers to the digital baseband and intermediate frequency parts of a radio communication system, and can implement functions such as transmitting signal modulation, receiving signal modulation, feature signal extraction, and information negotiation. The channel feature sequence can be calculated using the following formula
[0119]
[0120] where k = 0, 1, 2,..., N - 1
[0121] Due to the reciprocity of the channel, the channel estimations of the two legitimate communication nodes are highly correlated, which will inevitably make the extracted feature signals highly correlated. The strength of the correlation of the channel feature parameters determines whether the feature signal can be used as a feature factor. According to the correlation formula
[0122] ρ XY ∈COv(x,y) / σ x σ y
[0123] Generally speaking, the correlation factor ρ xY ∈[-1,1], σ x , σ y are the standard deviations of the first legitimate communication node A and the second legitimate communication node B respectively
[0124] Through the above formula, based on different channel characteristic parameters, the first legitimate communication node A and the second legitimate communication node B can respectively obtain the first channel characteristic sequence X corresponding to the channel characteristic parameter n and the second characteristic channel sequence Y n .
[0125] Step S104, use the single-threshold quantization method to respectively convert the first characteristic channel sequence X n into the first target bit sequence, and convert the second characteristic channel sequence Y n into the second target bit sequence.
[0126] Specifically, the single-threshold quantization thresholds of the first legitimate communication node and the second legitimate communication node can be calculated according to the following formula:
[0127] a n = E(U n ) ± α·σ(U n )
[0128] where U is a substitute symbol for the first legitimate communication node or the second legitimate communication node; U n is the channel characteristic sequence, U n ∈(X n , Y n ); α is the quantization factor; E(U n ) is the mean value of the channel characteristic sequence, and σ(U n ) is the standard deviation of the channel characteristic sequence;
[0129] And use the following formula to quantize each eigenvalue in the channel characteristic sequence to obtain the bit value corresponding to each eigenvalue;
[0130]
[0131] where x is each eigenvalue in the channel characteristic sequence; ε(x) is the bit value corresponding to each eigenvalue; a n is the single-threshold quantization threshold of the channel characteristic sequence; use the bit values corresponding to each eigenvalue in the first channel characteristic sequence X n to generate the first target bit sequence X n‘ , and use the bit values corresponding to each eigenvalue in the second channel characteristic sequence Y n to generate the second target bit sequence Y n′ .
[0132] Compared with the quantization method of traditional communication, the quantization method for key extraction focuses on the consistency of the initial key after quantization. Since in the feature extraction part, the extracted signals are highly correlated, the target bit sequences after quantization are also highly correlated. In the embodiment of the present invention, the single-threshold quantization method is used to reduce the inconsistency rate of the initial key, so as to inherit the correlation of the feature signals and prepare for the next information negotiation method. Taking the subcarrier amplitude attenuation information as the channel feature parameter as an example, the specific steps of the single-threshold quantization method for both legitimate communication nodes may include the following steps S104-1 to S104-2:
[0133] Step S104-1: Assume that the first legitimate communication node A and the second legitimate communication node B obtain the amplitudes on each subcarrier as X n =(X1,...,X n ) and Y n =(Y1,...,Y n ). The single-threshold quantization threshold for both legitimate communication nodes can be expressed as:
[0134] a n =E(U n )±α·σ(U n )
[0135] Suppose in the first legitimate communication node A, U = x, and the channel feature sequence U n =X n , a x is the single-threshold for quantization by the first legitimate communication node A. In the second legitimate communication node B, U = y, U n =Y n , a y is the threshold for quantization by the second legitimate communication node B. E(·) is the mean of the random sequence, σ(·) is the standard deviation of the random sequence, and the quantization factor α is the controller of the single-threshold quantization method.
[0136] Step S104-2: For the first channel feature sequence X n of the first legitimate communication node A and the second channel feature sequence Y n , the quantization method is as follows
[0137]
[0138] where n represents which node is being quantized. For example, on the side of the first legitimate communication node A, the quantization representation function is ε x (·); on the side of the second legitimate communication node B, the quantization representation function is ε y (·).
[0139] It should be noted that: for single-threshold quantization, if the error correction range is 10%, the quantization boundary is:
[0140]
[0141] Under a certain signal-to-noise ratio, according to the mean of the received signal Calculate the σ factor, ασ is the horizontal bit error length caused by noise, that is, the maximum amplitude of the noise.
[0142] Longitudinal distribution amplitude:
[0143] According to the formula Determines the range of the quantization factor.
[0144] When the quantization factor α is determined, the proportion of 0 and 1 in the target bit sequence is:
[0145]
[0146] P(0)=1-P(1)
[0147] If the quantization factor is too large, the ratio of 0 and 1 bits will be inconsistent, resulting in continuous 0 or continuous 1. The size of the quantization factor is seriously affected by noise, so when the signal-to-noise ratio is high, the single threshold quantization method can make 0 and 1 relatively coordinated. Therefore, the value range of the quantization factor can be determined by the 1-bit ratio allowable range and the bit error limit range.
[0148] According to the above method, the bit value corresponding to each bit characteristic value in the channel characteristic sequence can be obtained, and the corresponding target bit sequence is generated, which solves the problem that the sum of the areas of the inconsistent ranges on both sides of the protection interval in the double threshold quantization method may still be greater than the error correction capacity, and reduces the initial key inconsistency rate.
[0149] Step S105: Perform consistency processing on the first target bit sequence and the second target bit sequence to obtain a consistent target session key sequence.
[0150] Specifically, the correction method based on error control coding can be used to correct the first target bit sequence X n‘ and the second target bit sequence Y n′ Perform inconsistency correction to obtain a first session key sequence and a second session key sequence after inconsistency correction; then use a hash function to determine whether the first session key sequence and the second session key sequence after inconsistency correction are completely consistent, and use the completely consistent first session key sequence or second session key sequence as the target session key sequence.
[0151] Among them, Figure 6As shown, the inconsistent correction of the target bit sequence according to the error control coding-based correction method includes the following S105-1 to S105-3:
[0152] Step S105-1: The first legitimate communication node A determines the error control coding c. According to the error control coding c and the first target bit sequence X n‘ generate the codeword s; s = XOR(X n‘ , c); perform RS coding on the codeword s, and send the codeword s after completing RS coding to the second legitimate communication node B through USRP.
[0153] Assume that the first target bit sequence X of the first legitimate communication node A n‘ is regarded as the master key. The first legitimate communication node A selects an error control coding c. Regarding the key inconsistency between the first legitimate communication node A and the second legitimate communication node B as the error in the information after demodulating the received signal due to information transmission, then the codeword c of the channel coding can be used to correct the inconsistency of the initial keys of both legitimate parties. Take the codeword c as the common codeword of both legitimate communication nodes. Use the generated codeword c and the first target bit sequence X of the first legitimate communication node A n‘ to perform exclusive OR to generate the codeword s, that is, s = XOR(X n‘ , c). And perform RS coding on the generated codeword s. The purpose is to ensure that the codeword c″ received by the second legitimate communication node B has no errors and has a certain confidentiality. The information generated by RS coding can first be converted into binary bit data through base conversion, and then be sent to the second legitimate communication node B through MIMO-OFDM modulation via the USRP platform.
[0154] Step S105-2: The second legitimate communication node decodes the received RS coding to obtain the codeword s; according to the codeword s and the second target bit sequence Y n′ generate the codeword c″; c″ = XOR(Y n′ , s); and perform decoding and correction on the codeword c″ to obtain the codeword c′.
[0155] The second legitimate communication node B receives the signal, converts the received signal into a decimal number through signal demodulation to match the information generated after RS coding at the sending end. The second legitimate communication node B decodes the received RS code to eliminate the demodulation error caused by the noise in the transmission process, so as to obtain the codeword s. The second legitimate communication node B performs exclusive OR on its own obtained second target bit sequence Y n′ and the codeword s to obtain the codeword c″, that is, c″ = XOR(Y n′ , s). c″ is equivalent to the error caused by the information transmission between the first legitimate communication node A and the second legitimate communication node B. The second legitimate communication node B performs decoding and correction on c″ to obtain the codeword c′.
[0156] Step S105-3: Determine whether the Hamming distance between codeword c″ and codeword c is less than the error correction capacity t; if the Hamming distance between codeword c″ and codeword c is less than the error correction capacity t, then X n‘ = XOR(c′, s) = Y n′ ; if the Hamming distance between codeword c″ and codeword c is greater than or equal to the error correction capacity t, the first legitimate communication node and the first legitimate communication node repeat the above steps or perform channel estimation again until X n‘ = Y n′ , and take X n‘ and Y n′ as the first session key sequence and the second session key sequence respectively.
[0157] That is to say, if the Hamming distance between codeword c″ and codeword c is less than the error correction capacity t, then X n‘ = XOR(c′, s) = n′ ; if the Hamming distance between codeword c″ and codeword c is greater than the error correction capacity t, it means that the result of decoding codeword c″ is wrong, that is, c′≠c. At this time, the second legitimate communication node B will send a request signal to the first legitimate communication node A, asking the first legitimate communication node A to send information to the second legitimate communication node B again. If the first legitimate communication node A cannot successfully match the key after sending to the second legitimate communication node B multiple times, to prevent the leakage of key bit information, the first legitimate communication node A and the second legitimate communication node can re-perform channel estimation to generate a session key sequence and repeat the above steps.
[0158] Further, after the two legitimate communication nodes obtain the session key sequence, in order to determine whether the session key sequences generated by the two legitimate communication nodes are 100% consistent and prevent information leakage during the key consistency determination process, the first legitimate communication node and the second legitimate communication node can respectively generate the Hash functions of the first session key sequence and the second session key sequence to obtain the first Hash function corresponding to the first legitimate communication node and the second Hash function corresponding to the second legitimate communication node; and encrypt the first Hash function and the second Hash function and send them to each other; the first legitimate communication node and the second legitimate communication node respectively receive the second Hash function and the first Hash function and decrypt them; respectively determine whether the decrypted first Hash function and the second Hash function are consistent. If the first Hash function and the second Hash function are consistent, then the first session key sequence and the second session key sequence are consistent, and the completely consistent first session key sequence or second session key sequence is used as the target session key sequence.
[0159] After the above steps, the embodiment of the present invention uses an error correction algorithm based on error control coding for information negotiation, which is much more convenient than the concatenated protocol and reduces the additional communication overhead.
[0160] Optionally, the first legitimate communication node and the second legitimate communication node perform secrecy enhancement on the target session key sequence based on the Hash function using the second-order Rayleigh entropy.
[0161] To ensure the security of the generated final key, it is necessary to delete the key bits leaked during the information negotiation process. The purpose of secrecy enhancement is to compress the key after information negotiation through a compression function, so that the leaked information during the key generation process is minimized. For secrecy enhancement, the embodiment of the present invention analyzes through the Hash function and the second-order Rayleigh entropy. The first legitimate communication node and the second legitimate communication node use the Hash function to perform secrecy enhancement on the negotiated bit sequence and analyze it through the second-order Rayleigh entropy to obtain the final key sequence with high consistency, security, and reliability.
[0162] A key generation method provided by the present invention generates a common training sequence for channel estimation through a first legitimate communication node and a second legitimate communication node; the first legitimate communication node and the second legitimate communication node send the common training sequence to each other, and respectively perform channel estimation using the common training sequence and the received target training sequence to obtain a first channel parameter H A and a second channel parameter H B ; respectively perform channel feature extraction based on the first channel parameter H A and the second channel parameter H B to obtain a first feature channel sequence X corresponding to the first legitimate communication node n and a second feature channel sequence Y corresponding to the second legitimate communication node n ; respectively convert the first feature channel sequence X n into a first target bit sequence and the second feature channel sequence Y n into a second target bit sequence using a single-threshold quantization method; perform consistency processing on the first target bit sequence and the second target bit sequence to obtain a consistent target session key sequence. The present invention uses spatio-temporal consistency to extract channel feature signals, realizes a "one-time one-key" key generation method, improves the security of information transmission, and solves the problem that the traditional key encryption technology has too high costs and a high possibility of being cracked by increasing the key length and the number of key generation iterations.
[0163] Further, as Figure 1 a specific implementation of, the embodiment of the present invention further provides a key generation device, as Figure 7As shown in the figure, the device may include: a sequence generation module 710, a channel estimation module 720, a feature extraction module 730, a quantization processing module 740, and a key generation module 750.
[0164] The sequence generation module 710 may be configured to generate a common training sequence for channel estimation for the first legitimate communication node and the second legitimate communication node;
[0165] The channel estimation module 720 may be configured to enable the first legitimate communication node and the second legitimate communication node to mutually send the common training sequence, and respectively perform channel estimation by using the common training sequence and the received target training sequence to obtain a first channel parameter H A and a second channel parameter H B ;
[0166] The feature extraction module 730 may be configured to respectively perform channel feature extraction based on the first channel parameter H A and the second channel parameter H B to obtain a first feature channel sequence X corresponding to the first legitimate communication node n and a second feature channel sequence Y corresponding to the second legitimate communication node n ;
[0167] The quantization processing module 740 may be configured to respectively convert the first feature channel sequence X n into a first target bit sequence and the second feature channel sequence Y n into a second target bit sequence by using a single-threshold quantization method;
[0168] The key generation module 750 may be configured to perform consistency processing on the first target bit sequence and the second target bit sequence to obtain a consistent target session key sequence.
[0169] Furthermore, an embodiment of the present invention further provides a key generation device, as Figure 8 shown in the figure, the device may further include: a key enhancement module 760.
[0170] The key enhancement module 760 may be configured to perform secrecy enhancement on the target session key sequence for the first legitimate communication node and the second legitimate communication node based on the Hash function by using the second-order Rayleigh entropy.
[0171] Optionally, the sequence generation module 710 may further be configured to generate an orthogonal sub-carrier including a pilot signal for the first legitimate communication node; perform pilot arrangement on the orthogonal sub-carrier to generate an initial training sequence;
[0172] perform an IFFT transformation on the initial training sequence, and add a cyclic prefix to the initial training sequence after the IFFT transformation is completed;
[0173] The first legitimate communication node and the second legitimate communication node perform signal synchronization based on the initial training sequence after adding a cyclic prefix to obtain a common training sequence §.
[0174] Optionally, the channel estimation module 720 can also be used for the first legitimate communication node to send the common training sequence § to the second legitimate communication node, and the second legitimate communication node receives the first training sequence §A;
[0175] The second legitimate communication node sends the common training sequence § to the first legitimate communication node, and the first legitimate communication node receives the second training sequence §B;
[0176] The first legitimate communication node and the second legitimate communication node respectively perform channel estimation based on the LS algorithm on the received second training sequence §B and the first training sequence §A, specifically including solving for channel parameters using the following formula:
[0177]
[0178]
[0179]
[0180] The channel parameters are:
[0181]
[0182] The channel parameters on each subcarrier are:
[0183]
[0184] Among them, is the cost function; X is the transmitted signal; Y is the received signal; H is the channel response vector; is the estimated value of H; is the noise parameter; is the channel parameter; is the Kth element in, K = 0, 1, 2,..., N - 1.
[0185] Optionally, the channel estimation module 720 can also be used for the first legitimate communication node and the second legitimate communication node to respectively perform clock synchronization and frequency synchronization on the received second training sequence §B and the first training sequence §A, and remove the cyclic prefix;
[0186] Perform fft transformation on the second training sequence §B and the first training sequence §A after removing the cyclic prefix respectively.
[0187] Optionally, the feature extraction module 730 can also be used for the first legitimate communication node and the second legitimate communication node to respectively utilize the channel parameters on each subcarrier to extract channel feature signals based on the channel feature parameters; the first legitimate communication node obtains a first channel feature sequence X corresponding to the channel feature parameters n ; the second legitimate communication node obtains a second channel feature sequence Y corresponding to the channel feature parameters n ;
[0188] wherein, the channel feature parameters include at least one of amplitude, phase, multipath delay, received signal angle, and OFDM subcarrier information.
[0189] Optionally, the quantization processing module 740 can also be used to calculate the single-threshold quantization thresholds of the first legitimate communication node and the second legitimate communication node according to the following formula:
[0190] a n = E(U n ) ± α·σ(U n )
[0191] wherein, U is a proxy symbol for the first legitimate communication node or the second legitimate communication node; U n is the channel feature sequence, U n ∈(X n , Y n ); α is the quantization factor; E(U n ) is the mean value of the channel feature sequence, and σ(U n ) is the standard deviation of the channel feature sequence;
[0192] Quantize each eigenvalue in the channel feature sequence using the following formula to obtain the bit value corresponding to each eigenvalue;
[0193]
[0194] wherein, x is each eigenvalue in the channel feature sequence; ε(x) is the bit value corresponding to each eigenvalue; a n is the single-threshold quantization threshold of the channel feature sequence;
[0195] Generate a first target bit sequence X n using the bit values corresponding to each eigenvalue in the first channel feature sequence X n ‘ , and generate a second target bit sequence Y n using the bit values corresponding to each eigenvalue in the second channel feature sequence Y n′ .
[0196] Optionally, the key generation module 750 can also be used to correct the first target bit sequence X by using an error control coding-based correction method n‘ and the second target bit sequence Y n′ to perform inconsistency correction, and obtain a first session key sequence and a second session key sequence after completing the inconsistency correction;
[0197] Use a Hash function to determine whether the first session key sequence and the second session key sequence after completing the inconsistency correction are exactly the same, and use the exactly the same first session key sequence or the second session key sequence as the target session key sequence.
[0198] Optionally, the key generation module 750 can also be used for step 1: The first legitimate communication node determines the error control coding c, and generates a codeword s according to the error control coding c and the first target bit sequence X n‘ s = XOR(X n‘ , c);
[0199] Perform RS coding on the codeword s, and send the codeword s after completing the RS coding to the second legitimate communication node through USRP;
[0200] Step 2: The second legitimate communication node decodes the received RS coding to obtain the codeword s;
[0201] Generate a codeword c″ according to the codeword s and the second target bit sequence Y n′ c″ = XOR(Y n′ , s); and perform decoding correction on the codeword c″ to obtain the codeword c′;
[0202] Step 3: Determine whether the Hamming distance between the codeword c″ and the codeword c is less than the error correction capacity t; if the Hamming distance between the codeword c″ and the codeword c is less than the error correction capacity t, then X n‘ = XOR(c′, s) = Y n′ ;
[0203] If the Hamming distance between the codeword c″ and the codeword c is greater than or equal to the error correction capacity t, the first legitimate communication node and the first legitimate communication node re-perform steps 1 to 3 or re-perform channel estimation until X n‘ = Y n′ , and use X n‘ and Y n′ as the first session key sequence and the second session key sequence respectively.
[0204] Optionally, the key generation module 750 can also be used to generate the Hash functions of the first session key sequence and the second session key sequence for the first legitimate communication node and the second legitimate communication node respectively, to obtain the first Hash function corresponding to the first legitimate communication node and the second Hash function corresponding to the second legitimate communication node; and encrypt the first Hash function and the second Hash function and send them to each other;
[0205] The first legitimate communication node and the second legitimate communication node respectively receive the second Hash function and the first Hash function and decrypt them;
[0206] Respectively determine whether the decrypted first Hash function is the same as the second Hash function. If the first Hash function is the same as the second Hash function, the first session key sequence and the second session key sequence are the same.
[0207] It should be noted that for other corresponding descriptions of each functional module involved in the key generation device provided in the embodiments of the present invention, reference can be made to Figure 1 the corresponding description of the method shown, which will not be elaborated here.
[0208] Based on the method as described above Figure 1 shown, correspondingly, the embodiments of the present invention also provide a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the key generation method described in any of the above embodiments are implemented.
[0209] Based on the method and the embodiments of the system as described above Figure 1 shown and as shown in the figure, the embodiments of the present invention also provide a physical structure diagram of a computer device. As Figure 9 shown, the computer device may include a communication bus, a processor, a memory, and a communication interface, and may also include an input / output interface and a display device. Among them, each functional unit can complete mutual communication through the bus. The memory stores a computer program, and the processor is used to execute the program stored on the memory and execute the steps of the key generation method described in the above embodiments.
[0210] Those skilled in the art can clearly understand that the specific working processes of the above-described system, device, module, and unit can refer to the corresponding processes in the foregoing method embodiments. For the sake of brevity, they will not be elaborated here.
[0211] In addition, in each embodiment of the present invention, each functional unit may be physically independent of each other, or two or more functional units may be integrated together, or all functional units may be integrated in a processing unit. The above-mentioned integrated functional units may be implemented in the form of hardware, or in the form of software or firmware.
[0212] Those of ordinary skill in the art can understand that if the integrated functional units are implemented in software form and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such understanding, the technical solution of the present invention, in essence, or all or part of the technical solution can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computing device (such as a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the embodiments of the present invention when running the instructions. The foregoing storage medium includes: USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs, etc., various media that can store program codes.
[0213] Alternatively, all or part of the steps of implementing the foregoing method embodiments can be completed by hardware related to program instructions (such as a computing device such as a personal computer, a server, or a network device), and the program instructions can be stored in a computer-readable storage medium. When the program instructions are executed by the processor of the computing device, the computing device executes all or part of the steps of the methods described in the embodiments of the present invention.
[0214] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that within the spirit and principles of the present invention, they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some or all of the technical features; and these modifications or replacements do not cause the corresponding technical solutions to deviate from the protection scope of the present invention.
Claims
1. A key generation method, applied to at least two legitimate communication nodes, characterized in that, The legal communication nodes communicate through a preset wireless channel based on the TDD mode. The method includes: The first legal communication node and the second legal communication node generate a common training sequence for channel estimation. The first legitimate communication node and the second legitimate communication node send the common training sequences to each other, and respectively perform channel estimation by using the common training sequence and the received target training sequence to obtain the first channel parameter and the second channel parameter Based on the first channel parameter and the second channel parameter respectively for channel feature extraction, obtaining a first channel feature sequence corresponding to the first legitimate communication node and a second channel feature sequence corresponding to the second legitimate communication node ; ; Using a single-threshold quantization method, respectively convert the first channel feature sequence into a first target bit sequence, and convert the second channel feature sequence into a second target bit sequence; Perform consistency processing on the first target bit sequence and the second target bit sequence to obtain a consistent target session key sequence, including: using a correction method based on error control coding to correct the first target bit sequence and the second target bit sequence to perform inconsistency correction, obtaining a first session key sequence and a second session key sequence after completing the inconsistency correction; using a Hash function to determine whether the first session key sequence and the second session key sequence after completing the inconsistency correction are exactly the same, and taking the exactly the same first session key sequence or the second session key sequence as the target session key sequence; Using the correction method based on error control coding to correct the first target bit sequence and the second target bit sequence to perform inconsistency correction, and obtaining a first session key sequence and a second session key sequence after completing the inconsistency correction, including: Step 1: The first legitimate communication node determines an error control code , and generates a codeword according to the error control code and the first target bit sequence ; ; Perform RS encoding on the said codeword and send the codeword after completing RS encoding to the second legitimate communication node through USRP; Step 2: The second legitimate communication node decodes the received RS code to obtain the codeword ; According to the codeword and the second target bit sequence generate a codeword ; ; and perform decoding and correction on the codeword to obtain a codeword ; Step 3: Determine whether the Hamming distance between the codeword and the codeword is less than the error correction capacity t; if the Hamming distance between the codeword and the codeword is less than the error correction capacity t, then ; If the Hamming distance between the codeword and the codeword is greater than or equal to the error correction capacity t, the first legitimate communication node and the first legitimate communication node repeat steps 1 to 3 or repeat channel estimation until = . Then, and are respectively used as the first session key sequence and the second session key sequence.
2. The key generation method according to claim 1, wherein The first legal communication node and the second legal communication node generate a common training sequence for channel estimation, including: The first legal communication node generates an orthogonal sub-wave carrier including a pilot signal; arranges the orthogonal sub-wave carriers for pilots to generate an initial training sequence. Performs an IFFT transform on the initial training sequence, and adds a cyclic prefix to the initial training sequence after the IFFT transform is completed. The first legitimate communication node and the second legitimate communication node Perform signal synchronization on the initial training sequence after adding a cyclic prefix to obtain a common training sequence § .
3. The key generation method according to claim 2, characterized in that, The first legitimate communication node and the second legitimate communication node send the common training sequences to each other, and respectively perform channel estimation based on the LS algorithm by using the common training sequence and the received target training sequence to obtain a first channel parameter and a second channel parameter , including: The first legitimate communication node sends a common training sequence to the second legitimate communication node§ The second legitimate communication node receives the first training sequence §A ; The second legitimate communication node sends a common training sequence § to the first legitimate communication node, and the first legitimate communication node receives the second training sequence §B ; The first legitimate communication node and the second legitimate communication node respectively perform channel estimation on the received second training sequence §B and the first training sequence §A using the LS algorithm, specifically including solving channel parameters using the following formula: The channel parameters are: The channel parameters on each sub-carrier are: Among them, is the cost function; is the transmitted signal; is the received signal; is the channel response vector; is the estimated value of; is the noise parameter; is the channel parameter; is the th element in; .
4. The key generation method according to claim 3, characterized in that, The first legitimate communication node and the second legitimate communication node respectively perform channel estimation based on the LS algorithm on the received second training sequence §B and the first training sequence §A Before that, the method further includes: The first legitimate communication node and the second legitimate communication node respectively perform clock synchronization and frequency synchronization on the received second training sequence §B and the first training sequence §A and remove the cyclic prefix; Perform FFT transformation on the second training sequence after removing the cyclic prefix §B and the first training sequence §A respectively.
5. The key generation method according to claim 3, characterized in that respectively based on the first channel parameter and the second channel parameter perform channel feature extraction to obtain the first channel feature sequence corresponding to the first legitimate communication node and the second channel feature sequence corresponding to the second legitimate communication node , including: The first legitimate communication node and the second legitimate communication node respectively utilize the channel parameters on each subcarrier to extract channel feature signals based on channel feature parameters; the first legitimate communication node obtains a first channel feature sequence corresponding to the channel feature parameters ; the second legitimate communication node obtains a second channel feature sequence corresponding to the channel feature parameters ; Wherein, the channel characteristic parameters include at least one of amplitude, phase, multipath delay, received signal angle, and OFDM sub-carrier information.
6. The key generation method according to claim 5, wherein The method of using the single-threshold quantization method to convert the first channel characteristic sequence into a first target bit sequence and the second channel characteristic sequence into a second target bit sequence respectively includes: Calculating the single-threshold quantization threshold of the first legal communication node and the second legal communication node according to the following formula: Among them, is a proxy symbol for the first legitimate communication node or the second legitimate communication node; is the channel feature sequence, ; is the quantization factor; is the mean of the channel feature sequence, is the standard deviation of the channel feature sequence; Quantifying each eigenvalue in the channel characteristic sequence using the following formula to obtain the bit value corresponding to each eigenvalue. ; Among them, is each eigenvalue in the channel feature sequence; is the bit value corresponding to each eigenvalue; is the single-threshold quantization threshold of the channel feature sequence; Generate a first target bit sequence using the bit value corresponding to each eigenvalue in the first channel feature sequence , and generate a second target bit sequence using the bit value corresponding to each eigenvalue in the second channel feature sequence . . 7. The key generation method according to claim 1, wherein The method of using the Hash function to determine whether the first session key sequence and the second session key sequence are exactly the same after inconsistency correction includes: The first legal communication node and the second legal communication node respectively Apply the Hash function to the first session key sequence and the second session key sequence to obtain the first Hash function corresponding to the first legal communication node and the second Hash function corresponding to the second legal communication node; encrypt the first Hash function and the second Hash function and then send them to each other; The first legal communication node and the second legal communication node respectively receive the second Hash function and the first Hash function and perform decryption. Respectively determine whether the decrypted first Hash function is the same as the second Hash function. If the first Hash function is the same as the second Hash function, the first session key sequence and the second session key sequence are the same.
8. The key generation method according to any one of claims 1 to 7, characterized in that The method further includes: The first legal communication node and the second legal communication node perform secrecy enhancement on the target session key sequence based on the Hash function using the second-order Rayleigh entropy.
9. A key generation device, characterized in that, Including: A sequence generation module, configured to generate a common training sequence for channel estimation by the first legal communication node and the second legal communication node. A channel estimation module is used for the first legitimate communication node and the second legitimate communication node to send the common training sequences to each other, and respectively perform channel estimation by using the common training sequences and the received target training sequences to obtain the first channel parameter and the second channel parameter ; A feature extraction module, which is used to perform channel feature extraction respectively based on the first channel parameter and the second channel parameter to obtain a first channel feature sequence corresponding to the first legitimate communication node and a second channel feature sequence corresponding to the second legitimate communication node ; A quantization processing module, which is used to respectively convert the first channel feature sequence into a first target bit sequence and the second channel feature sequence into a second target bit sequence; The key generation module is used to perform consistency processing on the first target bit sequence and the second target bit sequence to obtain a consistent target session key sequence, including: correcting the first target bit sequence by using an error control coding-based correction method and the second target bit sequence to perform inconsistency correction, obtaining a first session key sequence and a second session key sequence after completing the inconsistency correction; using a Hash function to determine whether the first session key sequence and the second session key sequence after completing the inconsistency correction are exactly the same, and taking the exactly the same first session key sequence or second session key sequence as the target session key sequence; A key generation module, further configured to perform the following steps: Step 1: The first legitimate communication node determines an error control code , and generates a codeword according to the error control code and the first target bit sequence ; ; Perform RS encoding on the said codeword and send the codeword after RS encoding is completed to the said second legitimate communication node through USRP; Step 2: The second legitimate communication node decodes the received RS code to obtain the codeword ; According to the codeword and the second target bit sequence generate a codeword ; ; and perform decoding and correction on the codeword to obtain a codeword ; Step 3: Determine whether the Hamming distance between the codeword and the codeword is less than the error correction capacity t; if the Hamming distance between the codeword and the codeword is less than the error correction capacity t, then ; If the said codeword and the said codeword have a Hamming distance greater than or equal to the error correction capacity t, then the first legitimate communication node and the first legitimate communication node repeat steps 1 to 3 or repeat channel estimation until = . Respectively, take and as the first session key sequence and the second session key sequence.
10. A storage medium, on which a computer program is stored. When the computer program is executed by a processor, the processor executes the steps of the key generation method according to any one of claims 1 to 8.
11. A computer device, characterized in that, Including a memory and a processor. A computer program is stored in the memory. When the computer program is executed by the processor, the processor executes the steps of the key generation method according to any one of claims 1 to 8.
Citation Information
Patent Citations
OFDM channel physical key generation method and device based on USRP and computer equipment
CN112533199A