Wireless key generation method, device, apparatus and storage medium

By extracting wireless channel features from receiving and sending messages in a wireless communication system to generate keys, the problem of insufficient wireless key generation in existing technologies is solved, the reliability and compatibility of wireless key generation are achieved, and system security is improved.

CN116095677BActive Publication Date: 2026-05-19CHINA MOBILE COMM LTD RES INST +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA MOBILE COMM LTD RES INST
Filing Date
2021-11-08
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

In existing wireless communication systems, the encryption and integrity protection mechanisms between terminals and base stations are insufficient in terms of the security of signaling messages and user identification information. In particular, they cannot effectively generate a sufficient number of wireless keys before the establishment of an RRC connection. Furthermore, existing methods have excessively high requirements for access systems and channel resources and are incompatible with the wireless bearer establishment mechanisms of existing wireless access networks.

Method used

Wireless channel features are extracted by receiving and sending messages to generate keys. Multiple channel feature extractions are performed using existing wireless channel resources to ensure sufficient keys are generated. Channel detection and channel estimation techniques are used in conjunction with existing channel resources to generate wireless keys. Control plane signaling and user plane data encryption for point-to-point transmission are supported. Error correction codes and check codes are used to verify key consistency.

Benefits of technology

It improves the reliability and compatibility of wireless key generation, meets the key length requirements of encryption algorithms, protects user identification information, prevents leakage, and enhances system security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116095677B_ABST
    Figure CN116095677B_ABST
Patent Text Reader

Abstract

The application discloses a wireless key generation method, device, equipment and storage medium. Wherein, the method comprises: the second device receives the first message sent by the first device; based on the first message, the wireless channel characteristics are extracted, and the first key is generated; based on the length of the first key, the second message is sent to the first device, so that the wireless channel characteristics can be extracted multiple times for the wireless channel between the first device and the second device, and the first device and the second device can generate sufficient keys, thereby improving the reliability of the wireless key generation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication security, and in particular to a wireless key generation method, apparatus, device and storage medium. Background Technology

[0002] In general wireless communication systems, encryption mechanisms are used to ensure the security of user communication. However, the AS (Access Stratum) security mechanism between the terminal and the base station is established after the AS SMC (Security Mode Command) process is completed. After that, the terminal and the base station can use the AS key derived from the AKA (Authentication and Key Agreement) process to encrypt and / or protect the integrity of control plane signaling and user plane data at the air interface.

[0003] Taking the LTE (Long Term Evolution) system as an example, Figure 1 This illustrates the basic signaling interaction flow between the UE (User Equipment), eNodeB (base station), and MME (Mobility Management Entity). Figure 1 It can be concluded that before the SMC process is executed, security mechanisms such as AS layer encryption and integrity protection between the UE and eNodeB have not been enabled. The previously exchanged AS layer messages (such as RRC connection establishment request, RRC connection establishment, RRC connection establishment completion, etc.) and the NAS (Non-Access Stratum) information carried by the AS layer messages (such as attach request) will not be securely protected. Therefore, the signaling messages are at risk of being tampered with, forged, or eavesdropped on by attackers.

[0004] Furthermore, in some cases, during attach, the UE needs to send sensitive information such as its International Mobile Subscriber Identity (IMSI) to the MME via a NAS attach request message so that the MME can obtain the UE's context information (including security context) and perform an AKA operation. This exposes the user's unique identifier, the IMSI, in plaintext over the air interface, posing a risk of leaking the user's privacy information to the mobile network system. Once attackers obtain this user identifier information, they can use it to track the user's location or bind the user's terminal to account information obtained through other means, combining it with other attack methods to cause economic losses to the user.

[0005] Therefore, it is necessary to study the air interface security mechanism of mobile communication networks and seek more effective methods to establish and enable encryption and / or integrity protection mechanisms at the air interface as early as possible to protect messages and prevent terminal signaling messages from being attacked and user identity information from being leaked.

[0006] In related technologies, a shared key can be generated between the terminal and the base station based on wireless physical layer key generation technology before negotiating the key during AKA operation, and the subsequently transmitted AS messages and user identifiers can be encrypted and protected based on the generated key. However, this method has the following shortcomings:

[0007] (1) A dedicated key negotiation channel is used to extract channel features and generate wireless keys. At the same time, a dedicated service channel is used to transmit encrypted session information. This requires the wireless access network to allocate new logical and physical channel resources to meet the above-mentioned dedicated requirements. This has a great impact on the standard channel management system of the L1 physical layer and L2 data link layer of the access system and is difficult to implement.

[0008] (2) The added dedicated service channel is used to carry radio data, and it needs to be established before the RRC (Radio Resource Control) connection is established. However, in the existing system, the terminal's radio bearer (including signaling radio bearer and data radio bearer) is established by the L2 RRC sublayer during or after the RRC connection is established. Therefore, the proposed method contradicts the existing radio bearer establishment mechanism in terms of timing logic.

[0009] (3) The dedicated service channel allocated is only used for encrypted transmission of sensitive information such as user identity identifiers (such as IMSI). It is a different channel from the control channel (such as shared / dedicated control channel) and service channel (such as dedicated service channel) allocated by the base station to the terminal after the RRC connection is established. Therefore, the generated key cannot be used to encrypt and protect subsequent control plane signaling and user plane service data, and the key application efficiency is not high.

[0010] Furthermore, related technologies can also be improved by integrating the physical layer key generation process into the random access procedure of mobile communication systems, thereby generating paired physical layer keys at both the mobile terminal and the base station, and using these physical layer keys to protect IMSI privacy information. However, this method also has the following drawbacks:

[0011] (1) This method uses the signals generated by random access request and response messages as input excitation to measure the state characteristics of the wireless channel, and then quantizes them to form the original key. However, since the duration of random access request and response messages is very short (about 1ms) and the amount of information is limited, under good conditions, a single transmission can only generate a limited number of key bits, and under poor conditions, it may not be able to generate a key. Therefore, this scheme cannot effectively guarantee the generation of a sufficient number of keys for subsequent encryption.

[0012] (2) In order to identify and capture terminals and synchronize uplink and downlink clocks, existing systems typically use preamble sequences (such as Zadoff-Chu sequences) with good autocorrelation and cross-correlation and constant amplitude characteristics in random access request messages to meet the needs of random terminal access. However, key generation rate is the main technical indicator of wireless key generation. To improve this performance, it is necessary to use targeted pilot information (such as pilot coding with randomness and poor correlation) as input excitation to measure the state characteristics of the wireless channel according to the application environment. Therefore, this scheme cannot well meet the needs of wireless key generation technology.

[0013] (3) Taking the 4G LTE system as an example, random access request and response messages are carried by the RACH (Random Access Channel) and DL-SCH (Downlink-Shared Channel) logical channels, respectively, corresponding to the L1 physical layer PRACH (Physical Random Access Channel) and PDSCH (Physical Downlink Shared Channel). The physical time-frequency resource blocks corresponding to PRACH and PDSCH are different in the LTE system. Therefore, neither TDD (Time Division Duplex) nor FDD (Frequency Division Duplex) systems can guarantee the consistency of the frequencies of the terminal's uplink channel and the base station's downlink channel. This cannot adequately meet the channel reciprocity requirements of wireless key generation technology, ultimately negatively impacting the key generation rate and consistency rate. Summary of the Invention

[0014] In view of this, embodiments of this application provide a wireless key generation method, apparatus, device, and storage medium, aiming to improve the performance of wireless key generation and meet the security requirements of wireless communication systems.

[0015] The technical solution of this application embodiment is implemented as follows:

[0016] In a first aspect, embodiments of this application provide a wireless key generation method, the method comprising:

[0017] Receive the first message sent by the first device;

[0018] Based on the first message, extract wireless channel features and generate a first key;

[0019] Based on the length of the first key, a second message is sent to the first device.

[0020] In the above scheme, sending a second message to the first device based on the length of the first key includes:

[0021] If the length of the first key is determined to be less than a threshold, a second message is sent to the first device. The second message is used to indicate that the length of the first key is less than the threshold, or to indicate the length of the first key, or to instruct the first device to continue sending the first message.

[0022] In the above scheme, sending a second message to the first device based on the length of the first key includes:

[0023] If the length of the first key is determined to be greater than or equal to a threshold, a second message is sent to the first device. The second message is used to indicate that the length of the first key is greater than or equal to the threshold, or to indicate the length of the first key, or to indicate that the first device does not need to send the first message, or does not carry additional indication information.

[0024] In the above scheme, the step of extracting wireless channel features based on the first message and generating the first key includes:

[0025] Based on the first message itself and / or the channel detection information carried in the first message, channel detection and / or channel estimation are performed, wireless channel features are extracted, and a first key is generated.

[0026] In the above scheme, the channel detection information is at least one of a preamble, a pilot code, and a preset information code.

[0027] In the above scheme, the first message is a random access request message, and the second message is a random access response message; and / or,

[0028] The first message is a Radio Resource Control (RRC) Connection Request message, and the second message is an RRC Connection Establishment message.

[0029] The method in the above scheme further includes:

[0030] The system receives a third message sent by the first device, the third message carrying first verification information for key consistency verification.

[0031] In the above scheme, the first verification information is an error correction code or a verification code.

[0032] The method in the above scheme further includes:

[0033] Send a fourth message to the first device.

[0034] In the above scheme, the fourth message carries second verification information for key consistency verification.

[0035] In the above scheme, the second verification information is a verification code.

[0036] In the above scheme, the third message is a random access request message, and the fourth message is a random access response message; and / or,

[0037] The third message is an RRC connection request message, and the fourth message is an RRC connection establishment message.

[0038] Secondly, embodiments of this application provide a wireless key generation method, the method comprising:

[0039] Send the first message to the second device;

[0040] Receive the second message sent by the second device;

[0041] Based on the second message, wireless channel features are extracted to generate a second key;

[0042] Based on the length of the second key and / or the indication information of the second message, send a first message or a third message to the second device.

[0043] In the above scheme, the second message is used to indicate that the length of the first key is less than a threshold, or to indicate the length of the first key, or to instruct the first device to continue sending the first message.

[0044] In the above scheme, the second message is used to indicate that the length of the first key is greater than or equal to a threshold, or to indicate the length of the first key, or to indicate that the first device does not need to send the first message, or does not carry additional indication information.

[0045] In the above scheme, sending the first message to the second device based on the length of the second key and / or the indication information of the second message includes:

[0046] Once it is determined that the length of the second key is less than a threshold, a first message is sent to the second device;

[0047] Alternatively, if the length of the first key is determined to be less than a threshold, a first message is sent to the second device;

[0048] Alternatively, the second message may be used to instruct the first device to continue sending the first message to the second device.

[0049] In the above scheme, sending a third message to the second device based on the length of the second key and / or the indication information of the second message includes:

[0050] A third message is sent to the second device when the length of the second key is determined to be greater than or equal to a threshold and at least one of the following conditions is met:

[0051] Determine that the length of the first key is greater than or equal to the threshold.

[0052] The second message indicates that the first device does not need to send the first message;

[0053] The second message does not carry any additional instructions.

[0054] In the above scheme, the step of extracting wireless channel features based on the second message and generating a second key includes:

[0055] Based on the second message itself and / or the channel detection information carried in the second message, channel detection and / or channel estimation are performed, wireless channel features are extracted, and a second key is generated.

[0056] In the above scheme, the channel detection information is at least one of a preamble, a pilot code, and a preset information code.

[0057] In the above scheme, the first message is a random access request message, and the second message is a random access response message; and / or,

[0058] The first message is a Radio Resource Control (RRC) Connection Request message, and the second message is an RRC Connection Establishment message.

[0059] In the above scheme, the third message carries first verification information for password consistency verification.

[0060] In the above scheme, the first verification information is an error correction code or a verification code.

[0061] The method in the above scheme further includes:

[0062] Receive the fourth message sent by the second device.

[0063] In the above scheme, the fourth message carries second verification information for consistency verification.

[0064] In the above scheme, the second verification information is a verification code.

[0065] In the above scheme, the third message is a random access request message, and the fourth message is a random access response message; and / or,

[0066] The third message is an RRC connection request message, and the fourth message is an RRC connection establishment message.

[0067] Fifthly, embodiments of this application provide a second device, including: a processor and a memory for storing a computer program capable of running on the processor, wherein the processor, when running the computer program, executes the steps of the method described in the first aspect of embodiments of this application.

[0068] In a sixth aspect, embodiments of this application provide a first device, including: a processor and a memory for storing a computer program capable of running on the processor, wherein the processor, when running the computer program, performs the steps of the method described in the second aspect of embodiments of this application.

[0069] In a seventh aspect, embodiments of this application provide a storage medium storing a computer program, which, when executed by a processor, implements the steps of the method described in the first or second aspect of embodiments of this application.

[0070] The technical solution provided in this application embodiment involves a second device receiving a first message sent by a first device; extracting wireless channel features based on the first message to generate a first key; and sending a second message to the first device based on the length of the first key. In this way, multiple extractions of wireless channel features can be performed on the wireless channel between the first device and the second device, allowing the first device and the second device to generate a sufficient number of keys, thereby improving the reliability of wireless key generation. Attached Figure Description

[0071] Figure 1 This is a schematic diagram of the UE attachment access process in related technologies;

[0072] Figure 2 This is a flowchart illustrating the wireless key generation method applied to a second device according to an embodiment of this application;

[0073] Figure 3 This is a flowchart illustrating the wireless key generation method applied to the first device according to an embodiment of this application;

[0074] Figure 4 This is a flowchart illustrating the wireless key generation method according to Embodiment 1 of this application;

[0075] Figure 5 This is a flowchart illustrating the wireless key generation method according to Embodiment 2 of this application;

[0076] Figure 6This is a flowchart illustrating the wireless key generation method according to Embodiment 3 of this application;

[0077] Figure 7 This is a flowchart illustrating the wireless key generation method according to Embodiment 4 of this application;

[0078] Figure 8 This is a schematic diagram of the structure of the wireless key generation device applied to the second device according to an embodiment of this application;

[0079] Figure 9 This is a schematic diagram of the structure of the wireless key generation device applied to the first device in an embodiment of this application;

[0080] Figure 10 This is a schematic diagram of the structure of the second device according to an embodiment of this application;

[0081] Figure 11 This is a schematic diagram of the structure of the first device in the embodiment of this application. Detailed Implementation

[0082] The present application will now be described in further detail with reference to the accompanying drawings and embodiments.

[0083] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of the application.

[0084] To generate wireless keys based on existing wireless channel resources in a mobile communication system, embodiments of this application provide a wireless key generation method applied to a second device. For example... Figure 2 As shown, the method includes:

[0085] Step 201: Receive the first message sent by the first device;

[0086] Step 202: Extract wireless channel features based on the first message and generate a first key;

[0087] Step 203: Based on the length of the first key, send a second message to the first device.

[0088] It is understood that in this embodiment, the first device can be various terminal devices supporting wireless communication, such as 4G / 5G / 6G terminals, mobile phones, tablets, smart bracelets, Wi-Fi STAs, etc.; the second device can be network devices supporting wireless communication, such as 4G / 5G / 6G base stations, Wi-Fi APs, Wi-Fi STAs, network-side devices, etc. The second device receives a first message sent by the first device; extracts wireless channel features based on the first message to generate a first key; and sends a second message to the first device based on the length of the first key. The first device can determine whether to continue sending the first message based on the received second message. In this way, multiple extractions of wireless channel features can be performed on the wireless channel between the first device and the second device, allowing the first and second devices to generate sufficient keys, thereby improving the reliability of wireless key generation.

[0089] For example, based on the length of the first key, a second message is sent to the first device, including:

[0090] If the length of the first key is determined to be less than a threshold, a second message is sent to the first device. The second message is used to indicate that the length of the first key is less than the threshold, or to indicate the length of the first key, or to instruct the first device to continue sending the first message.

[0091] It is understood that the second message can carry the aforementioned information in the form of explicit or implicit instructions. Explicit instructions directly carry explicit information, allowing the first device to directly determine, based on the explicit second message, whether the length of the first key is less than a threshold, the length of the first key, or whether the first device should continue sending the first message. Explicit instructions can also be understood as "indicating" or "explaining." Implicit instructions, on the other hand, require the first device to perform relevant processing (e.g., arithmetic processing) based on the received second message to determine whether the length of the first key is less than a threshold, the length of the first key, or whether the first device should continue sending the first message.

[0092] For example, based on the length of the first key, a second message is sent to the first device, including:

[0093] If the length of the first key is determined to be greater than or equal to a threshold, a second message is sent to the first device. The second message is used to indicate that the length of the first key is greater than or equal to the threshold, or to indicate the length of the first key, or to indicate that the first device does not need to send the first message, or does not carry additional indication information.

[0094] It is understandable that when the second device determines that the length of the first key is greater than or equal to the threshold, the second message sent can also adopt the aforementioned explicit indication or implicit indication method, as described above, and will not be repeated here.

[0095] It should be noted that the second message may not indicate the status of the first key or related information. That is, the second device can reply with a second message without carrying additional information. Upon receiving the second message without indicating the status of the first key (i.e., the key on the second device's side), the first device assumes that the second device has already generated sufficient keys. This second message can be a new message or a reused existing message.

[0096] It is understandable that, in the case of the aforementioned second message indicating that the length of the first key is less than the threshold, or indicating the length of the first key, or indicating that the first device should continue to send the first message, the first device will continue to send the first message to the second device. In this way, even if the number of bits of the wireless key is insufficient (for example, less than 128 or 256 bits, which would not meet the key length requirements of the encryption algorithm), the first device and the second device can repeatedly extract wireless channel features from the wireless channel between them, thereby generating a sufficient number of wireless keys and improving the reliability of wireless key generation.

[0097] For example, when the second device is a base station, the first message is a random access request message and the second message is a random access response message; and / or, the first message is an RRC connection request message and the second message is an RRC connection establishment message. When the second device is a WLAN device, the first message can be an RTS (Request To Send) message or a Data message; the second message can be a CTS (Clear to Send) message or an ACK (Acknowledgement) message.

[0098] The above are merely illustrative examples. It should be noted that in actual implementation, the first and second messages can be configured according to the specific circumstances of the first and second devices (e.g., the type of device). Specifically, the first and / or second messages can be existing messages between the first and second devices, i.e., reusing existing messages between devices to implement the key negotiation method of this application; or they can be new messages, i.e., using new messages to implement the key negotiation method of this application. Furthermore, each message in the first and / or second messages can be a single message or can include multiple sub-messages. For example, the transmission of the first and / or second messages between the first and second devices can be carried out through an intermediate forwarding device, which is not specifically limited in this embodiment of the application.

[0099] Taking the second message as a random access response message as an example, if the second message needs to indicate that the length of the first key is less than a threshold, or indicates the length of the first key, or indicates that the first device continues to send the first message, or indicates that the length of the first key is greater than or equal to the threshold, then the random access response message is a random access response message carrying relevant information; if the second message does not carry additional indication information, then the random access response message can be an existing random access response message.

[0100] It is understandable that the first message and the second message carry channel detection information, which is used to perform channel detection and / or channel estimation on the wireless channel between the first device and the second device, and to extract wireless channel features.

[0101] Here, the wireless channel characteristics can be at least one of Channel State Information (CSI), Received Signal Strength Indication (RSSI), and Channel Frequency Response (CFR), and this application embodiment does not limit this.

[0102] In this way, existing wireless channel resources in mobile communication networks can be used to generate wireless keys without the need for dedicated key negotiation to extract channel features, thus ensuring compatibility with existing wireless access network wireless bearer establishment mechanisms. Furthermore, the method in this embodiment effectively guarantees the number of bits generated for the wireless key, thereby meeting the key length requirements of encryption algorithms.

[0103] For example, the process of extracting wireless channel features based on the first message and generating a first key includes:

[0104] Based on the first message itself and / or the channel detection information carried in the first message, channel detection and / or channel estimation are performed, wireless channel features are extracted, and a first key is generated.

[0105] Understandably, the second device receives the first message from the first device, performs channel detection and / or channel estimation based on the first message itself and / or the channel detection information carried in the first message, extracts wireless channel features, and generates the first key.

[0106] For example, the channel detection information can be at least one of a preamble, a pilot code, and a preset information code.

[0107] It is understandable that the preamble is the content actually sent by the first device in RACH, consisting of a cyclic prefix CP of length Tcp and a sequence of length Tseq, which enables channel feature extraction during the establishment of random access.

[0108] Preferably, in order to enhance the effect of channel feature extraction, the channel detection information can be a pilot code (such as an m-sequence) that is more conducive to detecting the wireless channel state or a preset information code, which can effectively improve performance indicators such as wireless key generation rate.

[0109] It should be noted that if the first message is a random access request message and the second message is a random access response message, then RACH and DL-SCH (corresponding to L1 physical layer PRACH and PDSCH) are used to perform channel sounding and / or channel estimation on the wireless channel state, and to extract wireless channel features. If the first message is an RRC connection request message and the second message is an RRC connection establishment message, then CCCH (Common Control Channel) is used to perform channel sounding and / or channel estimation on the wireless channel state, and to extract wireless channel features.

[0110] It is understandable that both the RRC connection request message and the RRC connection establishment message are carried by the CCCH logical channel, corresponding to the L1 physical layer UL-SCH (Uplink Shared Channel) and DL-SCH (Downlink Shared Channel), as well as PUSCH (Physical Uplink Shared Channel) and PDSCH (Physical Downlink Shared Channel). In TDD systems, the PUSCH and PDSCH channels use the same physical time-frequency resource blocks in a time-division manner. Compared to PRACH and PDSCH carrying channel probing information, the RRC connection request message and the RRC connection establishment message can perform channel state probing and / or channel estimation on uplink and downlink radio channels with the same frequency, extracting radio channel characteristics and ensuring better reciprocity of the radio channel. Therefore, it can better guarantee that the second device and the first device generate more consistent radio keys, improving the system's radio key generation performance.

[0111] For example, the method further includes:

[0112] Receive a third message sent by the first device, the third message carrying first verification information for key consistency verification.

[0113] Understandably, after the second device generates a sufficient amount of the first key, the first device can send a third message carrying the first verification information to the second device, so that the second device can perform key consistency verification on the first key based on the first verification information, that is, perform information reconciliation.

[0114] For example, key consistency verification of the first key can be performed using one of the following methods: information reconciliation methods based on the Caseade protocol, error correction codes, or secure sketches.

[0115] For example, the first verification information is an error correction code or a check code. For instance, the first verification information can be a forward error correction code, a linear block code, a CRC (Cyclic Redundancy Check) code, a check code based on the Caseade protocol, etc.

[0116] It should be noted that, for the verification code, after the second device verifies the first key, it also needs to send the verification code to the first device, so that the first device can reconcile the information of the wireless key based on the received verification code.

[0117] For example, the method further includes:

[0118] Send the fourth message to the first device.

[0119] For example, the second device sends a fourth message to the first device, which carries second verification information for key consistency verification. This second verification information can be a checksum. This allows the wireless keys of the first and second devices to be reconciled based on the checksum, thereby obtaining a consistent key between them.

[0120] For example, when the second device is a base station, the third message is a random access request message, and the fourth message is a random access response message; and / or, the third message is an RRC connection request message, and the fourth message is an RRC connection establishment message. When the second device is a WLAN device, the third message can be an RTS (Request To Send) message or a Data message; the fourth message can be a CTS (Clear to Send) message or an ACK message.

[0121] The above are merely illustrative examples. It should be noted that in actual implementation, the third and fourth messages can be configured according to the specific circumstances of the first and second devices (e.g., the specific type of device). Specifically, the third and / or fourth messages can be existing messages between the first and second devices, i.e., reusing existing messages between devices to implement the key verification method of this application; or they can be new messages, i.e., using new messages to implement the key verification method of this application. Furthermore, each message in the third and / or fourth messages can be a single message or can include multiple sub-messages. For example, the transmission of the third and / or fourth messages between the first and second devices can be carried out through an intermediate forwarding device, which is not specifically limited in this embodiment of the application.

[0122] It is understood that the key consistency verification information can be transmitted during the random access phase or during the RRC connection phase, and this application embodiment does not limit this.

[0123] It is understood that the method in this application embodiment organically combines wireless physical layer key generation technology with mobile communication network technology, utilizing existing channel resources to obtain wireless channel characteristics and generate keys without adding additional dedicated channels. Simultaneously, by supporting multiple channel measurements, specific pilot information carrying, and co-frequency wireless channel carrying, it better meets the conditions required for wireless key generation technology, improving the system's wireless key generation performance. Furthermore, the generated key is used to encrypt and / or protect the integrity of control plane signaling and / or user plane data transmitted point-to-point between the first and second devices, enhancing system security. In particular, protecting NAS layer messages containing sensitive information such as user identifiers (e.g., IMSI) prevents user identifier leakage, thus improving the security of existing systems.

[0124] This application also provides a wireless key generation method, applied to a first device, such as... Figure 3 As shown, the method includes:

[0125] Step 301: Send the first message to the second device;

[0126] Step 302: Receive the second message sent by the second device;

[0127] Step 303: Extract wireless channel features based on the second message and generate a second key;

[0128] Step 304: Based on the number of second keys and / or the indication information of the second message, send a first message or a third message to the second device.

[0129] Understandably, the first device sends a first message to the second device; receives a second message from the second device; extracts wireless channel features based on the second message and generates a second key; and sends a first message or a third message to the second device based on the number of second keys and / or the indication information in the second message. The first message can support the second device and the first device to continue extracting wireless channel features. In this way, multiple extractions of wireless channel features between the first device and the second device can be performed, allowing the terminal and the second device to generate a sufficient number of keys, thereby improving the reliability of wireless key generation.

[0130] For example, when the second device determines that the length of the first key is less than a threshold (e.g., the number of bits in the first key is less than 128 or 256 bits), the second message sent is used to indicate that the length of the first key is less than the threshold, or to indicate the length of the first key, or to instruct the first device to continue sending the first message.

[0131] For example, when the second device determines that the length of the first key is greater than or equal to a threshold, the second message sent is used to indicate that the length of the first key is greater than or equal to the threshold, or to indicate the length of the first key, or to indicate that the first device does not need to send the first message, or to not carry additional indication information.

[0132] For example, based on the length of the second key and / or the indication information of the second message, a first message is sent to the second device, including:

[0133] If the length of the second key is determined to be less than the threshold, a first message is sent to the second device;

[0134] Alternatively, if the length of the first key is determined to be less than a threshold, a first message is sent to the second device;

[0135] Alternatively, the second message may be used to instruct the first device to continue sending the first message to the second device.

[0136] It is understandable that if the first device determines that the number of bits of the second key is less than the threshold, or receives the aforementioned indication that the length of the first key is less than the threshold, or the second message indicating the length of the first key, or instructing the first device to continue sending the first message, then it will continue to send the first message to the second device. In this way, even if the number of bits of the wireless key is insufficient (for example, less than 128 or 256 bits, which would not meet the key length requirements of the encryption algorithm), the first device and the second device can repeatedly extract wireless channel features from the wireless channel between them, thereby generating a sufficient number of wireless keys and improving the reliability of wireless key generation.

[0137] It should be noted that if the second message carries an instruction to continue sending the first message, the first device will directly send the first message to the second device based on the second message; if the second message indicates the length of the first key, the first device needs to compare the length of the first key with a threshold and determine whether to send the first message based on the comparison result.

[0138] For example, based on the length of the second key and / or the indication information of the second message, a third message is sent to the second device, including:

[0139] A third message is sent to the second device when the length of the second key is greater than or equal to a threshold and at least one of the following conditions is met:

[0140] Determine that the length of the first key is greater than or equal to the threshold.

[0141] The second message indicates that the first device does not need to send the first message;

[0142] The second message does not carry any additional instructions.

[0143] For example, the first message is a random access request message and the second message is a random access response message; or, the first message is an RRC connection request message and the second message is an RRC connection establishment message.

[0144] It is understandable that the first message and the second message carry channel detection information, which is used to perform channel detection and / or channel estimation on the wireless channel between the first device and the second device, and to extract wireless channel features.

[0145] For example, the second key is generated by extracting wireless channel features based on the second message, including:

[0146] Based on the second message itself and / or the channel detection information carried in the second message, channel detection and / or channel estimation are performed, wireless channel features are extracted, and a second key is generated.

[0147] Understandably, the first device receives a second message from the second device, performs channel detection and / or channel estimation based on the second message itself and / or the channel detection information carried in the second message, extracts wireless channel features, and generates a second key.

[0148] Here, the wireless channel characteristics can be at least one of CSI, RSSI, and CFR, and this application embodiment does not limit this.

[0149] In this way, existing wireless channel resources in mobile communication networks can be used to generate wireless keys without the need for dedicated key negotiation to extract channel features, thus ensuring compatibility with existing wireless access network wireless bearer establishment mechanisms. Furthermore, the method in this embodiment effectively guarantees the number of bits generated for the wireless key, thereby meeting the key length requirements of encryption algorithms.

[0150] For example, the channel detection information can be at least one of a preamble, a pilot code, and a preset information code.

[0151] It is understandable that the preamble is the content actually sent by the first device in RACH, consisting of a cyclic prefix CP of length Tcp and a sequence of length Tseq, which enables channel feature extraction during the establishment of random access.

[0152] Preferably, in order to enhance the effect of channel feature extraction, the channel detection information can be a pilot code (such as an m-sequence) that is more conducive to detecting the wireless channel state or a preset information code, which can effectively improve performance indicators such as wireless key generation rate.

[0153] It should be noted that if the first message is a random access request message and the second message is a random access response message, then RACH and DL-SCH (corresponding to L1 physical layer PRACH and PDSCH) are used to perform channel sounding and / or channel estimation on the wireless channel state, and to extract wireless channel features. If the first message is an RRC connection request message and the second message is an RRC connection establishment message, then CCCH (Common Control Channel) is used to perform channel sounding and / or channel estimation on the wireless channel state, and to extract wireless channel features.

[0154] It is understandable that both the RRC connection request message and the RRC connection establishment message are carried by the CCCH logical channel, corresponding to the L1 physical layer UL-SCH (Uplink Shared Channel) and DL-SCH (Downlink Shared Channel), as well as PUSCH (Physical Uplink Shared Channel) and PDSCH (Physical Downlink Shared Channel). In TDD systems, the PUSCH and PDSCH channels use the same physical time-frequency resource blocks in a time-division manner. Compared to PRACH and PDSCH carrying channel probing information, the RRC connection request message and the RRC connection establishment message can perform channel state probing and / or channel estimation on uplink and downlink radio channels with the same frequency, extracting radio channel characteristics and ensuring better reciprocity of the radio channel. Therefore, it can better guarantee that the second device and the first device generate more consistent radio keys, improving the system's radio key generation performance.

[0155] For example, the third message carries first verification information for password consistency verification, enabling the second device to perform key consistency verification on the first key based on the first verification information, i.e., to perform information reconciliation.

[0156] For example, the first verification information is an error correction code or a check code. For instance, the first verification information can be a forward error correction code, a linear block code, a CRC (Cyclic Redundancy Check) code, a check code based on the Caseade protocol, etc.

[0157] It should be noted that, for the verification code, after the second device verifies the first key, it also needs to send the verification code to the first device, so that the first device can reconcile the information of the wireless key based on the received verification code.

[0158] For example, the method further includes:

[0159] Receive the fourth message sent by the second device.

[0160] For example, the fourth message carries second verification information for consistency verification. This second verification information can be a checksum. This allows the wireless keys of the first and second devices to be reconciled based on the checksum, thereby obtaining a consistent key between the two parties.

[0161] For example, the third message is a random access request message, and the fourth message is a random access response message; and / or, the third message is an RRC connection request message, and the fourth message is an RRC connection establishment message.

[0162] It is understood that the key consistency verification information can be transmitted during the random access phase or during the RRC connection phase, and this application embodiment does not limit this.

[0163] The present application will be further described in detail below with reference to application examples.

[0164] This application provides application schemes of the above method in mobile communication networks using a 4G LTE system as an example. The first device is a user equipment (UE), and the second device is an eNodeB. It should be noted that the terminal access process in a 5G system is basically similar to that in 4G; therefore, the above method is also applicable to other mobile communication systems with similar processing procedures.

[0165] Application Example 1

[0166] In this application embodiment, the terminal device and the base station generate a wireless key using random access request messages and random access response messages, referring to... Figure 4 Specifically, it includes:

[0167] Step 401: Send the first message (MSG1): Random Access Request Message.

[0168] The terminal device sends a random access request message, which includes a preamble, in the uplink RACH.

[0169] Step 402: Wireless channel state measurement, feature extraction, and key generation.

[0170] Based on the received uplink random access request message, the base station measures the wireless channel state, extracts channel features, and generates the first key after sampling and quantization.

[0171] Step 403: Send the second message (MSG2): Random Access Response Message.

[0172] The base station returns a random access response message on the DL-SCH channel.

[0173] Understandably, if the base station has not yet generated a sufficient number of initial keys, it can return an indication message requesting the terminal device to continue initiating random access request messages for uplink channel probing. If the base station has generated a sufficient number of keys, it can normally send back a random access response message, requesting the terminal to continue with subsequent operations.

[0174] Step 404: Wireless channel state measurement, feature extraction, and key generation.

[0175] Based on the received downlink random access response message, the terminal device measures the wireless channel state, extracts channel features, and generates a second key after sampling and quantization.

[0176] Step 405: Determine whether a sufficient number of keys have been generated. If yes, proceed to step 406; otherwise, return to step 401.

[0177] Here, if the terminal device determines that it has generated a sufficient number of keys, it proceeds with the subsequent operations. If it has not yet generated a sufficient number of keys, the terminal device resends the random access request message and repeats steps 401 to 404 to continue generating keys until a sufficient number are generated.

[0178] Step 406: Send the first message (MSG1): Random Access Request Message, which carries key consistency verification information.

[0179] The terminal device resends the random access request message, which includes the first verification information used to complete the key consistency verification.

[0180] Step 407: Send the second message (MSG2): Random Access Response Message, which carries key consistency verification information.

[0181] The base station returns a random access response message, which includes second verification information for completing key consistency verification.

[0182] Steps 408a and 408b: Key consistency verification and privacy amplification.

[0183] Based on the received key consistency verification information, the base station and terminal equipment perform key consistency verification and privacy amplification operations, ultimately forming a key that can be used by both parties.

[0184] Steps 409a and 409b enable encryption.

[0185] Using the generated key, the terminal device and the base station encrypt and / or protect the integrity of the subsequent wireless signaling and data exchanged.

[0186] In steps 410 to 413 and thereafter, AS layer signaling messages (including NAS layer messages carried by RRC signaling, such as registration requests) and user plane data exchanged between the terminal equipment and the base station will be transparently encrypted and / or protected for integrity using a radio key to ensure the security of all control plane signaling and user plane data.

[0187] Application Example 2

[0188] Based on the first application embodiment, the encoded signals sent in steps 401 and 403 can be replaced with signal encodings that are more suitable for detecting the wireless channel state of the system, such as pilot codes (e.g., m-sequences) to obtain better wireless key generation results.

[0189] Specifically, the wireless key generation method in Application Example 2 includes:

[0190] Step 501: Send the first message (MSG1): Random Access Request Message.

[0191] The terminal device transmits pilot codes, such as m-sequences, for channel sounding during uplink RACH.

[0192] Step 502: Wireless channel state measurement, feature extraction, and key generation.

[0193] Based on the received uplink random access request message, the base station measures the wireless channel state, extracts channel features, and generates the first key after sampling and quantization.

[0194] Step 503: Send the second message (MSG2): Random Access Response Message.

[0195] The base station returns a random access response message on the DL-SCH channel, which carries pilot codes for channel sounding.

[0196] Understandably, if the base station has not yet generated a sufficient number of initial keys, it can return an indication message requesting the terminal device to continue initiating random access request messages for uplink channel probing. If the base station has generated a sufficient number of keys, it can normally send back a random access response message, requesting the terminal to continue with subsequent operations.

[0197] Step 504: Wireless channel state measurement, feature extraction, and key generation.

[0198] Based on the received downlink random access response message, the terminal device measures the wireless channel state, extracts channel features, and generates a second key after sampling and quantization.

[0199] Step 505: Determine whether a sufficient number of keys have been generated. If yes, proceed to step 506; otherwise, return to step 501.

[0200] Here, if the terminal device determines that it has generated a sufficient number of keys, it proceeds with the subsequent operations. If it has not yet generated a sufficient number of keys, the terminal device resends the random access request message and repeats steps 501 to 504 to continue generating keys until a sufficient number are generated.

[0201] Step 506: Send the first message (MSG1): Random Access Request Message, which carries key consistency verification information.

[0202] The terminal device resends the random access request message, which includes the first verification information used to complete the key consistency verification.

[0203] Step 507: Send the second message (MSG2): Random Access Response Message, which carries key consistency verification information.

[0204] The base station returns a random access response message, which includes second verification information for completing key consistency verification.

[0205] Steps 508a and 508b: Key consistency verification and privacy amplification.

[0206] Based on the received key consistency verification information, the base station and terminal equipment perform key consistency verification and privacy amplification operations, ultimately forming a key that can be used by both parties.

[0207] Steps 509a and 509b enable encryption.

[0208] Using the generated key, the terminal device and the base station encrypt and / or protect the integrity of the subsequent wireless signaling and data exchanged.

[0209] In steps 510 to 513 and thereafter, AS layer signaling messages (including NAS layer messages carried by RRC signaling, such as registration requests) and user plane data exchanged between the terminal equipment and the base station will be transparently encrypted and / or protected for integrity using a radio key to ensure the security of all control plane signaling and user plane data.

[0210] Application Example 3

[0211] For Application Implementation Example 1 or Application Implementation Example 2 described above, the short duration and limited information capacity of random access request / response messages may make them unsuitable for carrying key consistency verification information. In this case, the consistency verification information can be carried through the RRC connection request message and the RRC connection establishment message. After key consistency verification and privacy amplification operations are completed, encryption is enabled to encrypt and / or protect the integrity of the RRC connection establishment completion message and subsequent messages. The RRC connection establishment completion message carries a NAS layer registration request message, thus preventing the leakage of the IMSI identifier.

[0212] Specifically, the wireless key generation method in Application Example 3 includes:

[0213] First execute steps 401 to 405, or steps 501 to 505.

[0214] It is understandable that the base station first executes steps 401 to 405, or steps 501 to 505, to ensure that the base station and terminal equipment generate sufficient keys.

[0215] Step 606: Send the first message (MSG1): Random Access Request Message.

[0216] Step 607: Send the second message (MSG2): Random Access Response Message.

[0217] Step 608: Send a third message (MSG3): an RRC connection request message, which carries key consistency verification information.

[0218] The terminal device sends an RRC connection request message, which contains the first verification information used to complete the key consistency verification.

[0219] Step 609: Send the fourth message (MSG4): RRC connection establishment message, which carries key consistency verification information.

[0220] The base station returns an RRC connection establishment message, which contains second verification information for completing key consistency verification.

[0221] Steps 610a and 610b: Key consistency verification and privacy amplification.

[0222] Based on the received key consistency verification information, the base station and terminal equipment perform key consistency verification and privacy amplification operations, ultimately forming a key that can be used by both parties.

[0223] Steps 611a and 611b enable encryption.

[0224] Using the generated key, the terminal device and the base station encrypt and / or protect the integrity of the subsequent wireless signaling and data exchanged.

[0225] In steps 612 to 613 and thereafter, AS layer signaling messages (including NAS layer messages carried by RRC signaling, such as registration requests) and user plane data exchanged between the terminal equipment and the base station will be transparently encrypted and / or protected for integrity using a radio key to ensure the security of all control plane signaling and user plane data.

[0226] Application Example 4

[0227] When random access request / response messages are unsuitable for carrying specific channel probe pilot codes, specific pilot codes can be carried in RRC connection request messages and RRC connection establishment messages to complete wireless channel state probing. Subsequently, the RRC connection request and RRC connection establishment messages are used again to complete the key consistency verification message exchange, negotiating a consistent key between the terminal and the base station to encrypt the point-to-point transmission channel between them.

[0228] For example, refer to Figure 7 The wireless key generation method in this application embodiment specifically includes:

[0229] Step 701: Send the first message (MSG1): Random Access Request Message.

[0230] The terminal device sends a random access request message on the uplink RACH.

[0231] Step 702: Send the second message (MSG2): Random Access Response Message.

[0232] The base station returns a random access response message on the DL-SCH channel.

[0233] Step 703: Send the third message (MSG3): RRC connection request message.

[0234] The terminal device sends an RRC connection request message in the CCCH, which contains a specially designed pilot code (e.g., an m-sequence) for channel state detection.

[0235] Step 704: Wireless channel state measurement, feature extraction, and key generation.

[0236] Based on the received uplink pilot signal, the base station measures the wireless channel state, extracts channel features, and generates the first key after sampling and quantization.

[0237] Step 705: Send the fourth message (MSG4): RRC connection establishment message.

[0238] The base station sends an RRC connection establishment message on the CCCH channel, which contains a specially designed pilot code for channel state detection.

[0239] Understandably, if the base station has not yet generated a sufficient number of first keys, it can return an indication message requesting the terminal device to continue initiating an RRC connection request message for uplink channel probing. If the base station has generated a sufficient number of keys, it can normally send back a random access response message, requesting the terminal device to continue with subsequent operations.

[0240] Step 706: Wireless channel state measurement, feature extraction, and key generation.

[0241] Based on the received downlink pilot signal, the terminal device measures the wireless channel state, extracts channel features, and generates a second key after sampling and quantization.

[0242] Step 707: Determine whether a sufficient number of keys have been generated. If yes, proceed to step 708; otherwise, return to step 703.

[0243] Here, if the terminal device determines that it has generated a sufficient number of keys, it proceeds with the subsequent operations. If it has not yet generated a sufficient number of keys, the terminal device resends the random access request message and repeats steps 703 to 706 to continue generating keys until a sufficient number are generated.

[0244] Step 708: Send a third message (MSG3): an RRC connection request message, which carries key consistency verification information.

[0245] The terminal device resends the RRC connection request message, which includes the first verification information used to complete the key consistency verification.

[0246] Step 709: Send the fourth message (MSG4): RRC connection establishment message, which carries key consistency verification information.

[0247] The base station returns an RRC connection establishment message, which contains second verification information for completing key consistency verification.

[0248] Steps 710a and 710b: Key consistency verification and privacy amplification.

[0249] Based on the received key consistency verification information, the base station and terminal equipment perform key consistency verification and privacy amplification operations, ultimately forming a key that can be used by both parties.

[0250] Steps 711a and 711b enable encryption.

[0251] Using the generated key, the terminal device and the base station encrypt and / or protect the integrity of the subsequent wireless signaling and data exchanged.

[0252] In steps 712 to 713 and thereafter, AS layer signaling messages (including NAS layer messages carried by RRC signaling, such as registration requests) and user plane data exchanged between the terminal equipment and the base station will be transparently encrypted and / or protected for integrity using a radio key to ensure the security of all control plane signaling and user plane data.

[0253] It should be noted that both the RRC connection request message and the RRC connection establishment message are carried by the CCCH logical channel, corresponding to the L1 physical layer UL-SCH and DL-SCH transmission channels and the PUSCH and PDSCH physical channels. In the TDD system, PUSCH and PDSCH use the same physical time-frequency resource block in time division. Therefore, compared with the schemes in application embodiments one to three that use PRACH and PDSCH to carry channel probing information, the method proposed in application embodiment four can perform channel state probing and feature extraction on uplink and downlink wireless channels with the same frequency, ensuring better reciprocity of the wireless channel. Thus, it can better guarantee that the base station and the terminal generate more consistent keys, improving the system key generation performance.

[0254] To implement the method of the embodiments of this application, the embodiments of this application also provide a wireless key generation device, which is applied to a second device. The wireless key generation device corresponds to the wireless key generation method applied to the second device described above, and the steps in the embodiments of the wireless key generation method described above are also fully applicable to the embodiments of this wireless key generation device.

[0255] like Figure 8 As shown, the wireless key generation device includes: a first receiving module 801, a first key generation module 802, and a first sending module 803. The first receiving module 801 is used to receive a first message sent by a first device; the first key generation module 802 is used to extract wireless channel features based on the first message and generate a first key; and the first sending module 803 is used to send a second message to the first device based on the length of the first key.

[0256] In some embodiments, the first sending module 803 is specifically used for:

[0257] If the length of the first key is determined to be less than a threshold, a second message is sent to the first device. The second message is used to indicate that the length of the first key is less than the threshold, or to indicate the length of the first key, or to instruct the first device to continue sending the first message.

[0258] In some embodiments, the first sending module 803 is specifically used for:

[0259] If the length of the first key is determined to be greater than or equal to a threshold, a second message is sent to the first device. The second message is used to indicate that the length of the first key is greater than or equal to the threshold, or to indicate the length of the first key, or to indicate that the first device does not need to send the first message, or does not carry additional indication information.

[0260] In some embodiments, the first key generation module 802 is specifically used for:

[0261] Based on the first message itself and / or the channel detection information carried in the first message, channel detection and / or channel estimation are performed, wireless channel features are extracted, and a first key is generated.

[0262] For example, the channel detection information is at least one of a preamble, a pilot code, or a preset information code.

[0263] For example, the first message is a random access request message and the second message is a random access response message; and / or, the first message is a Radio Resource Control (RRC) connection request message and the second message is an RRC connection establishment message.

[0264] In some embodiments, the first receiving module 801 is further configured to:

[0265] Receive a third message sent by the first device, the third message carrying first verification information for key consistency verification.

[0266] For example, the first verification information is an error correction code or a verification code.

[0267] In some embodiments, the first sending module 803 is further configured to:

[0268] Send the fourth message to the first device.

[0269] For example, the second verification information is a verification code.

[0270] For example, the third message is a random access request message, and the fourth message is a random access response message; and / or, the third message is an RRC connection request message, and the fourth message is an RRC connection establishment message.

[0271] In practical applications, the first receiving module 801, the first key generation module 802, and the first transmitting module 803 can be implemented by the processor in the wireless key generation device. Of course, the processor needs to run the computer program in the memory to implement its functions.

[0272] In order to implement the method of the embodiments of this application, the embodiments of this application also provide a wireless key generation device, which is applied to a first device. The wireless key generation device corresponds to the wireless key generation method applied to the first device described above, and the steps in the embodiments of the wireless key generation method described above are also fully applicable to the embodiments of this wireless key generation device.

[0273] like Figure 9 As shown, the wireless key generation device includes a second transmitting module 901, a second receiving module 902, and a second key generation module 903. The second transmitting module 901 is used to transmit a first message to a second device; the second receiving module 902 is used to receive a second message transmitted by the second device; the second key generation module 903 is used to extract wireless channel features based on the second message and generate a second key; the second transmitting module 901 is also used to transmit either a first message or a third message to the second device based on the length of the second key and / or the indication information of the second message.

[0274] For example, the second message is used to indicate that the length of the first key is less than a threshold, or to indicate the length of the first key, or to instruct the first device to continue sending the first message.

[0275] For example, the second message is used to indicate that the length of the first key is greater than or equal to a threshold, or to indicate the length of the first key, or to indicate that the first device does not need to send the first message, or does not carry additional indication information.

[0276] In some embodiments, the second sending module 901 sends a first message to the second device based on the length of the second key and / or the indication information of the second message, including:

[0277] If the length of the second key is determined to be less than the threshold, a first message is sent to the second device;

[0278] Alternatively, if the length of the first key is determined to be less than a threshold, a first message is sent to the second device;

[0279] Alternatively, the second message may be used to instruct the first device to continue sending the first message to the second device.

[0280] In some embodiments, the second sending module 901 sends a third message to the second device based on the length of the second key and / or the indication information of the second message, including:

[0281] A third message is sent to the second device when the length of the second key is greater than or equal to a threshold and at least one of the following conditions is met:

[0282] Determine that the length of the first key is greater than or equal to the threshold.

[0283] The second message indicates that the first device does not need to send the first message;

[0284] The second message does not carry any additional instructions.

[0285] In some embodiments, the second key generation module 903 is specifically used for:

[0286] Based on the second message itself and / or the channel detection information carried in the second message, channel detection and / or channel estimation are performed, wireless channel features are extracted, and a second key is generated.

[0287] For example, the channel detection information is at least one of a preamble, a pilot code, or a preset information code.

[0288] For example, the first message is a random access request message and the second message is a random access response message; and / or, the first message is a Radio Resource Control (RRC) connection request message and the second message is an RRC connection establishment message.

[0289] For example, the third message carries first verification information for password consistency verification.

[0290] For example, the first verification information is an error correction code or a verification code.

[0291] For example, the second receiving module 902 is further configured to: receive a fourth message sent by the second device.

[0292] For example, the second verification information is a verification code.

[0293] For example, the third message is a random access request message, and the fourth message is a random access response message; and / or, the third message is an RRC connection request message, and the fourth message is an RRC connection establishment message.

[0294] In practical applications, the second transmitting module 901, the second receiving module 902, and the second key generating module 903 can be implemented by the processor in the wireless key generating device. Of course, the processor needs to run the computer program in the memory to implement its functions.

[0295] It should be noted that the wireless key generation device provided in the above embodiments is only illustrated by the division of the above program modules when generating wireless keys. In practical applications, the above processing can be assigned to different program modules as needed, that is, the internal structure of the device can be divided into different program modules to complete all or part of the processing described above. In addition, the wireless key generation device and the wireless key generation method embodiments provided in the above embodiments belong to the same concept, and their specific implementation process can be found in the method embodiments, which will not be repeated here.

[0296] Based on the hardware implementation of the above program modules, and in order to implement the method of the embodiments of this application, the embodiments of this application also provide a second device. Figure 10 Only an exemplary structure of the second device is shown, not the entire structure; it can be implemented as needed. Figure 10 The structure shown may be part or all of the structure.

[0297] like Figure 10 As shown, the second device 1000 provided in this embodiment includes at least one processor 1001, a memory 1002, a user interface 1003, and at least one network interface 1004. The various components in the second device 1000 are coupled together via a bus system 1005. It can be understood that the bus system 1005 is used to implement communication between these components. In addition to a data bus, the bus system 1005 also includes a power bus, a control bus, and a status signal bus. However, for clarity, in… Figure 10 The general labeled all buses as Bus System 1005.

[0298] The user interface 1003 may include a monitor, keyboard, mouse, trackball, click wheel, buttons, touchpad, or touch screen.

[0299] The memory 1002 in this embodiment is used to store various types of data to support the operation of the second device. Examples of such data include any computer program used to operate on the second device.

[0300] The wireless key generation method disclosed in this application can be applied to or implemented by the processor 1001. The processor 1001 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the wireless key generation method can be completed by integrated logic circuits in the hardware of the processor 1001 or by instructions in software form. The processor 1001 can be a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The processor 1001 can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor, etc. The steps of the method disclosed in the embodiments of this application can be directly manifested as execution by a hardware decoding processor, or execution by a combination of hardware and software modules in the decoding processor. The software modules can be located in a storage medium, specifically memory 1002. The processor 1001 reads information from memory 1002 and, in conjunction with its hardware, completes the steps of the wireless key generation method provided in the embodiments of this application.

[0301] In an exemplary embodiment, the second device may be implemented by one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), FPGAs, general-purpose processors, controllers, microcontrollers (MCUs), microprocessors, or other electronic components to perform the aforementioned method.

[0302] Based on the hardware implementation of the above program modules, and in order to implement the method of the embodiments of this application, the embodiments of this application also provide a first device. Figure 11 Only an exemplary structure of the first device is shown, not the entire structure; it can be implemented as needed. Figure 11 The structure shown may be part or all of the structure.

[0303] like Figure 11As shown, the first device 1100 provided in this application embodiment includes: at least one processor 1101, a memory 1102, a user interface 1103, and at least one network interface 1104. The various components in the first device 1100 are coupled together via a bus system 1105. It can be understood that the bus system 1105 is used to implement communication between these components. In addition to a data bus, the bus system 1105 also includes a power bus, a control bus, and a status signal bus. However, for clarity, in... Figure 11 The general designated all buses as Bus System 1105.

[0304] The user interface 1103 may include a monitor, keyboard, mouse, trackball, click wheel, buttons, touchpad, or touch screen.

[0305] The memory 1102 in this embodiment is used to store various types of data to support the operation of the first device. Examples of such data include any computer program used to operate on the first device.

[0306] The wireless key generation method disclosed in this application can be applied to or implemented by the processor 1101. The processor 1101 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the wireless key generation method can be completed by the integrated logic circuitry in the hardware of the processor 1101 or by instructions in software form. The processor 1101 can be a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The processor 1101 can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor, etc. The steps of the method disclosed in the embodiments of this application can be directly manifested as execution by a hardware decoding processor, or execution by a combination of hardware and software modules in the decoding processor. The software modules can be located in a storage medium, specifically memory 1102. The processor 1101 reads information from memory 1102 and, in conjunction with its hardware, completes the steps of the wireless key generation method provided in the embodiments of this application.

[0307] In an exemplary embodiment, the first device 1100 may be implemented by one or more ASICs, DSPs, PLDs, CPLDs, FPGAs, general-purpose processors, controllers, MCUs, microprocessors, or other electronic components to perform the aforementioned method.

[0308] It is understood that memories 1002 and 1102 can be volatile or non-volatile memories, or both. Non-volatile memories can be read-only memories (ROM), programmable read-only memories (PROM), erasable programmable read-only memories (EPROM), electrically erasable programmable read-only memories (EEPROM), ferromagnetic random access memory (FRAM), flash memory, magnetic surface memory, optical discs, or compact disc read-only memories (CD-ROM); magnetic surface memory can be disk storage or magnetic tape storage. Volatile memories can be random access memory (RAM), used as external cache. By way of example, but not limitation, many forms of RAM are available, such as Static Random Access Memory (SRAM), Synchronous Static Random Access Memory (SSRAM), Dynamic Random Access Memory (DRAM), Synchronous Dynamic Random Access Memory (SDRAM), Double Data Rate Synchronous Dynamic Random Access Memory (DDRSDRAM), Enhanced Synchronous Dynamic Random Access Memory (ESDRAM), SyncLink Dynamic Random Access Memory (SLDRAM), and Direct Rambus Random Access Memory (DRRAM).The memories described in the embodiments of this invention are intended to include, but are not limited to, these and any other suitable types of memories.

[0309] In an exemplary embodiment, this application also provides a storage medium, namely a computer storage medium, specifically a computer-readable storage medium, such as a memory 1002 storing a computer program, which can be executed by the processor 1001 of the second device 1000 to complete the steps of the wireless key generation method on the second device side of this application embodiment; or a memory 1102 storing a computer program, which can be executed by the processor 1101 of the first device 1100 to complete the steps of the wireless key generation method on the first device side of this application embodiment. The computer-readable storage medium can be a ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disc, or CD-ROM, etc.

[0310] It should be noted that terms such as "first" and "second" are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.

[0311] Furthermore, the technical solutions described in the embodiments of this application can be combined arbitrarily without conflict.

[0312] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A method for generating a wireless key, characterized in that, The method includes: Receive the first message sent by the first device; Based on the first message, extract wireless channel features and generate a first key; Based on the length of the first key, a second message is sent to the first device; The step of sending a second message to the first device based on the length of the first key includes: If the length of the first key is determined to be less than a threshold, a second message is sent to the first device. The second message is used to indicate that the length of the first key is less than the threshold, or to indicate the length of the first key, or to instruct the first device to continue sending the first message.

2. The method according to claim 1, characterized in that, Sending the second message to the first device based on the length of the first key further includes: If the length of the first key is determined to be greater than or equal to a threshold, a second message is sent to the first device. The second message is used to indicate that the length of the first key is greater than or equal to the threshold, or to indicate the length of the first key, or to indicate that the first device does not need to send the first message, or does not carry additional indication information.

3. The method according to claim 1 or 2, characterized in that, The step of extracting wireless channel features based on the first message and generating the first key includes: Based on the first message itself and / or the channel detection information carried in the first message, channel detection and / or channel estimation are performed, wireless channel features are extracted, and a first key is generated.

4. The method according to claim 3, characterized in that, The channel detection information is at least one of the following: preamble, pilot code, and preset information encoding.

5. The method according to claim 1, characterized in that, The first message is a random access request message, and the second message is a random access response message; And / or, The first message is a Radio Resource Control (RRC) Connection Request message, and the second message is an RRC Connection Establishment message.

6. The method according to claim 1, characterized in that, The method further includes: The system receives a third message sent by the first device, the third message carrying first verification information for key consistency verification.

7. The method according to claim 6, characterized in that, The first verification information is an error correction code or a verification code.

8. The method according to claim 6, characterized in that, The method further includes: Send a fourth message to the first device.

9. The method according to claim 8, characterized in that, The fourth message carries second verification information for key consistency verification.

10. The method according to claim 9, characterized in that, The second verification information is a verification code.

11. The method according to claim 8, characterized in that, The third message is a random access request message, and the fourth message is a random access response message; and / or, The third message is an RRC connection request message, and the fourth message is an RRC connection establishment message.

12. A method for generating a wireless key, characterized in that, The method includes: Send the first message to the second device; Receive the second message sent by the second device; Based on the second message, wireless channel features are extracted to generate a second key; Based on the length of the second key and / or the indication information of the second message, send a first message or a third message to the second device; The second message is used to indicate that the length of the first key is less than a threshold, or to indicate the length of the first key, or to instruct the first device to continue sending the first message; the first key is generated by the second device after extracting wireless channel features based on the first message.

13. The method according to claim 12, characterized in that, The second message is also used to indicate that the length of the first key is greater than or equal to a threshold, or to indicate the length of the first key, or to indicate that the first device does not need to send the first message, or does not carry additional indication information.

14. The method according to claim 12, characterized in that, Sending a first message to the second device based on the length of the second key and / or the indication information of the second message includes: Once it is determined that the length of the second key is less than a threshold, a first message is sent to the second device; Alternatively, if the length of the first key is determined to be less than a threshold, a first message is sent to the second device; Alternatively, the second message may be used to instruct the first device to continue sending the first message to the second device.

15. The method according to claim 12, characterized in that, The sending of a third message to the second device based on the length of the second key and / or the indication information of the second message includes: A third message is sent to the second device when the length of the second key is determined to be greater than or equal to a threshold and at least one of the following conditions is met: Determine that the length of the first key is greater than or equal to a threshold. The second message indicates that the first device does not need to send the first message; The second message does not carry any additional instructions.

16. The method according to claim 12, characterized in that, The step of extracting wireless channel features based on the second message and generating a second key includes: Based on the second message itself and / or the channel detection information carried in the second message, channel detection and / or channel estimation are performed, wireless channel features are extracted, and a second key is generated.

17. The method according to claim 16, characterized in that, The channel detection information is at least one of the following: preamble, pilot code, and preset information encoding.

18. The method according to claim 12, characterized in that, The first message is a random access request message, and the second message is a random access response message; and / or, The first message is a Radio Resource Control (RRC) Connection Request message, and the second message is an RRC Connection Establishment message.

19. The method according to any one of claims 12-18, characterized in that, The third message carries first verification information for password consistency verification.

20. The method according to claim 19, characterized in that, The first verification information is an error correction code or a verification code.

21. The method according to claim 20, characterized in that, The method further includes: Receive the fourth message sent by the second device.

22. The method according to claim 21, characterized in that, The fourth message carries second verification information for consistency verification.

23. The method according to claim 22, characterized in that, The second verification information is a verification code.

24. The method according to claim 22, characterized in that, The third message is a random access request message, and the fourth message is a random access response message; and / or, The third message is an RRC connection request message, and the fourth message is an RRC connection establishment message.

25. A wireless key generation device, characterized in that, The device includes: The first receiving module is used to receive the first message sent by the first device; The first key generation module is used to extract wireless channel features based on the first message and generate a first key; The first sending module is used to send a second message to the first device based on the length of the first key; Specifically, the first sending module is used to determine that the length of the first key is less than a threshold, and send a second message to the first device. The second message is used to indicate that the length of the first key is less than the threshold, or to indicate the length of the first key, or to instruct the first device to continue sending the first message.

26. A wireless key generation device, characterized in that, The device includes: The second sending module is used to send the first message to the second device; The second receiving module is used to receive the second message sent by the second device; The second key generation module is used to extract wireless channel features based on the second message and generate a second key; The second sending module is further configured to send a first message or a third message to the second device based on the length of the second key and / or the indication information of the second message; The second message is used to indicate that the length of the first key is less than a threshold, or to indicate the length of the first key, or to instruct the first device to continue sending the first message; the first key is generated by the second device after extracting wireless channel features based on the first message.

27. A second device, characterized in that, include: A processor and memory for storing computer programs that can run on the processor, wherein, The processor, when running a computer program, performs the steps of the method according to any one of claims 1 to 11.

28. A first device, characterized in that, include: A processor and memory for storing computer programs that can run on the processor, wherein, The processor, when running a computer program, performs the steps of the method according to any one of claims 12 to 24.

29. A storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 24.