Physical layer key generation method based on radio frequency fingerprint recognition model
Through the physical layer key generation method based on the RF-DNA fingerprint identification model, the RF-DNA fingerprint feature extraction algorithm and linear core support vector machine generate the key matrix is solved, and the key generation in the prior art depends on third parties and excessive delay is achieved, and key generation with high security and low delay is achieved.
Patent Information
- Application Number
- CN202310139912.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-02-21
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2043-02-21
AI Technical Summary
The existing wireless communication key generation technology relies on third parties to participate in generation, distribution and management, resulting in high resource consumption and vulnerability to attacks, excessive delay and human factors, making it impossible to achieve rapid key updates and universal use across the entire device.
Using the physical layer key generation method based on the RF frequency fingerprint identification model, the wireless communication signals of the master and child machines are collected, and the physical layer features are extracted using the RF-DNA fingerprint feature extraction algorithm, and a linear core support vector machine is constructed to generate a key matrix, and the key is obtained through MD5 encoding.
It realizes lightweight key generation without third-party participation, low latency, no human factors, separation of encryption and application devices, and updating, improving the security and generation rate of keys, reducing communication delay and human attack risks.
Smart Images

Figure CN116321135B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of wireless communication physical layer security, and in particular relates to a physical layer key generation method based on a radio frequency fingerprint recognition model. Background Art
[0002] With the increasing popularity of wireless communication devices and the booming development of Internet of Things technology, wireless communication plays an irreplaceable role in both military and civilian applications. However, due to the openness of wireless communication, it is more vulnerable to attacks than traditional wired communication. Traditional wireless communication protection mechanisms based on the bit level usually have loopholes, such as the encryption protocol originally used in IEEE820.11 wireless LAN: Wired Equivalent Privacy (WEP) is extremely vulnerable to statistical analysis attacks. Therefore, a new security mechanism is urgently needed to effectively identify the access of authorized and unauthorized users, thereby reducing the potential threats from malicious users. Unlike traditional key generation technology, physical layer key generation technology (PKG) provides a lightweight and theoretically secure key generation scheme. It uses channel characteristics such as randomness, reciprocity and spatial uniqueness of wireless channels to enable legitimate users to automatically generate symmetric keys without the need for third parties to participate in key generation and management. Therefore, the research on physical layer key generation technology has become one of the important directions for the development of communication security today. For example, patent document CN113596826B discloses a method and system for generating a millimeter wave physical layer key with random beam switching, wherein the communicating parties A and B perform initial channel detection to obtain the status information of the millimeter wave channel; perform physical layer key generation with random beam switching, and perform physical layer key combination. Patent document CN114390519A discloses a method, device, equipment, and storage medium for generating a wireless channel key, wherein in response to a first detection signal sent by a first communication terminal, the first detection signal is received by a target antenna selected from a multi-antenna unit to obtain a first received signal; the first received signal is filtered to obtain a filtered first received signal; the filtered first received signal is channel estimated to obtain a first channel parameter; and an encryption key is determined based on the first channel parameter. However, there are the following disadvantages: (1) Existing key generation technology relies on third-party participation in generation, distribution and management, which results in more resources being consumed and the emergence of malicious third-party security issues; (2) The continuous development of Internet of Things technology has put forward lower latency requirements for wireless communication equipment. Existing key generation technology relies on highly complex algorithms and key encryption and decryption processes, which increases the amount of encrypted and decrypted data and leads to excessive latency; (3) Traditional key generation technology always has human factors and is vulnerable to attacks by hackers using social engineering methods, and there is also a risk of database collision; (4) Existing physical layer key generation technology relies on the physical layer characteristics of the two communication devices themselves. If they are lost or stolen at the same time, the generation process will be reproduced and the relevant devices will be cracked; (5) Existing key generation technology is complex to update or even impossible to update, and it is impossible to achieve rapid key update and confidential retention of old version keys; (6) Existing physical layer key generation is mostly only for certain devices and cannot be universal for all devices. Summary of the invention
[0003] In view of the problems existing in the prior art, the purpose of the present invention is to provide a lightweight key generation method that does not require a third party, has low latency, is free of human factors, separates encryption and application devices, and is updateable.
[0004] To achieve the above object, the present invention adopts the following technical solution: a physical layer key generation method based on a radio frequency fingerprint recognition model, the method is applied to a wireless communication network including a master machine and a slave machine group, and is characterized in that the method comprises the following steps:
[0005] Step 1: Signal processing
[0006] 1) Collect the wireless communication signal of the master machine when it is turned on, and number each slave in the slave group and collect the wireless communication signal of each slave when it is turned on;
[0007] 2) Use the fractal Bayesian change point detection algorithm and envelope method to segment the transient signal segment of the wireless communication signal;
[0008] 3) Use the RF-DNA fingerprint feature extraction algorithm to extract the radio frequency fingerprint and obtain the physical layer feature data set RFF of the main machine and each sub-machine. RFF i is the physical layer feature data set of machine i, is the feature vector generated by the collected wireless communication signal data of the sth machine when it is turned on, i=0,1,2,…,N, i=0 represents the master unit, i≠0 represents the i-th slave unit, is the variance of the instantaneous amplitude characteristic of machine i, γ a is the skewness value of the instantaneous amplitude characteristic of machine i, κ a is the kurtosis value of the instantaneous amplitude characteristic of machine i, is the variance of the instantaneous phase characteristic of machine i, γ p is the skewness value of the instantaneous phase characteristic of machine i, κ p is the kurtosis value of the instantaneous phase characteristic of machine i, is the variance of the instantaneous frequency characteristic of machine i, γ f is the skewness value of the instantaneous frequency characteristic of machine i, κ f is the kurtosis value of the instantaneous frequency characteristic of machine i, and N is the number of sub-machines;
[0009] Step 2: Generate the physical layer key of the slave
[0010] The physical layer feature data set of the master machine is combined with the physical layer feature data sets of each slave machine to form a key feature set, and a linear kernel support vector machine is constructed. The key feature set is used as a training set to establish a separation hyperplane. The normal vector and intercept of the separation hyperplane are obtained through binary classification of the linear kernel support vector machine to form the original key matrix C of slave machine i. i , is the normal vector of the separation hyperplane obtained by binary classification of child machine i and parent machine through linear kernel support vector machine, is the intercept of the separating hyperplane obtained by binary classification of the sub-machine i and the main machine through the linear kernel support vector machine. i Encode to obtain the key matrix of slave machine i, and store it in the slave machine, and obtain the key matrix of all slave machines in the same way;
[0011] Step 3: Key application
[0012] When the master and slave machines are ready to establish communication, all slave machine serial numbers and slave machine key matrices are stored in the master machine, and the master machine serial number and each slave machine's own key matrix are stored in each slave machine;
[0013] When slaves are to establish communication, each slave will store its own key matrix and the slave serial numbers and key matrices of the remaining slaves in the slave group with which it needs to establish communication.
[0014] The physical layer key generation method based on the radio frequency fingerprint recognition model is to apply the slave key matrix obtained in step 2 in the two scenarios of the master control mode of the master machine and the slave communication mode as follows:
[0015] The first scenario: Master machine master control mode
[0016] This mode stores all slave serial numbers and slave key matrices in the master, and stores the master serial number and each slave's own key matrix in each slave. The master can initiate communication requests to all slaves and communicate. The specific steps of communication are:
[0017] a) The master transmits its own number and the serial number of the target slave to the surroundings, and waits for the slave to respond;
[0018] b) The target slave responds to the master and transmits its own serial number;
[0019] c) After the master receives and receives only one slave's response, it confirms it as the target slave, transmits the key matrix of the corresponding slave, and waits for the slave's response;
[0020] d) After receiving the key matrix, the slave compares it with the master key matrix. If they are correct, it is confirmed to be the master and the master number is sent to respond to the master.
[0021] e) The master receives the response from the slave and establishes communication with the slave;
[0022] The second scenario: slave machine communication mode
[0023] In this mode, each slave will store its own key matrix and the slave serial number and key matrix of the other slaves in the slave group that needs to establish communication. Slave A initiates a communication request to slave B and communicates with each other. The specific steps of communication are as follows:
[0024] a) Slave A transmits its own serial number and the serial number of the target slave B to the surroundings, and waits for slave B to respond;
[0025] b) Handset B responds to Handset A and transmits back Handset B’s serial number;
[0026] c) After receiving only one response from slave B, slave A confirms it as the target slave, transmits the key matrix of slave B, and waits for slave B to respond;
[0027] d) After receiving the key matrix, slave B compares it with its own key matrix. If they are completely correct, it is confirmed to be slave A and the key matrix of slave A is transmitted to respond to slave A;
[0028] e) After receiving the sub-machine key matrix, slave A compares it with its own key matrix. If they are completely correct, it is confirmed to be slave B and communication is established with slave B.
[0029] As a preferred solution of the present invention, the RF-DNA fingerprint feature extraction algorithm adopts a time-domain RF-DNA fingerprint feature extraction algorithm.
[0030] As a preferred solution of the present invention, MD5 encoding is used for encoding.
[0031] Through the above design scheme, the present invention can bring the following beneficial effects: the present invention proposes a physical layer key generation method based on the radio frequency fingerprint recognition model, firstly collects the transient signals generated when the mother machine and each sub-machine in the sub-machine group are turned on, and performs radio frequency fingerprint extraction through the RF-DNA fingerprint feature extraction algorithm to obtain the physical layer features of the mother machine and the sub-machine with the wireless communication module, and respectively combines the feature data sets of each sub-machine in the mother machine and the sub-machine group to form a key feature set, constructs a linear kernel support vector machine, uses the key feature set as a training set to establish a separation hyperplane, obtains the normal vector and intercept of the separation hyperplane to form a key matrix, and encodes the key matrix to obtain the physical layer key of the corresponding sub-machine. The method provided by the present invention increases the key bit number to expand the key space and uniformly distributes the key through a physical random method to improve the key entropy to ensure the security of the key, improves the generation rate of the physical layer key in a fixed environment, reduces the communication delay caused by key authentication between devices, does not require a third party to participate in the establishment and distribution of the key, eliminates human factors, prevents the risk of sociological engineering cracking and database collision, ensures rapid key update, and realizes data encryption with one machine and one key. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] Figure 1The working principle diagram of the physical layer key generation method based on the radio frequency fingerprint recognition model;
[0033] Figure 2 It is the operation flow chart of the signal processing part;
[0034] Figure 3 A signal map for starting up wireless communication equipment;
[0035] Figure 4 This is the operation flow chart of the key generation part;
[0036] Figure 5 Schematic diagram of the separating hyperplane;
[0037] Figure 6 Implementing a diagram for the key generation process;
[0038] Figure 7 This is the principle block diagram of the master control mode of the mother machine;
[0039] Figure 8 This is the implementation diagram of the communication steps of the master control mode of the master machine;
[0040] Fig. 9 This is the principle block diagram of the slave machine communication mode;
[0041] Fig.10 It is the implementation diagram of the communication steps of the slave communication mode;
[0042] Fig.11 The present invention is a flowchart of a method for generating physical layer keys based on a radio frequency fingerprint recognition model. DETAILED DESCRIPTION
[0043] In order to make the purpose, features and advantages of the present invention more obvious and easy to understand, the present invention is further described in detail below in conjunction with the accompanying drawings and specific embodiments. It should be understood by those skilled in the art that the content described below is illustrative rather than restrictive and should not be used to limit the scope of protection of the present invention. Unless otherwise defined, the technical terms or scientific terms used herein should be the common meanings understood by people with ordinary skills in the field to which the present invention belongs. In order to avoid confusing the essence of the present invention, known methods, processes, flows, components and circuits are not described in detail.
[0044] like Figure 1As shown in the figure, the physical layer key generation method based on the radio frequency fingerprint recognition model is divided into three parts: a signal processing part, which is to collect and process the wireless communication signals (such as Bluetooth communication modules in mobile phones, transmitters in walkie-talkies, long-distance radio modules (LoRa) and ZigBee modules in Internet of Things systems) generated when the wireless communication modules of the mother machine and the slave machine are turned on to obtain the original physical layer characteristics; a key generation part is used to generate physical layer keys for the slave machine and the mother machine; a key application part is used to store the keys in the mother machine or the slave machine according to the needs;
[0045] 1. Signal processing part (the wireless communication devices not specially specified in this part are all target devices in a single experiment, and the target device is the main unit or a single sub-unit. All receivers are receivers provided in the experiment for receiving the power-on signal of the wireless communication module of the main unit or sub-unit, and have nothing to do with the main unit and the sub-unit.)
[0046] The signal processing part collects and processes the wireless communication signals (such signals can be Bluetooth signals, radio signals or Wifi signals, etc.) generated when the wireless communication modules of the main machine and the sub-machine are turned on, and obtains the original physical layer characteristics. The specific process is as follows: Figure 2 As shown;
[0047] (1) Collect the wireless communication signals of the wireless communication modules of the master and slave devices when they are turned on in a laboratory environment
[0048] In order to obtain accurate physical layer characteristics, wireless communication signals should be collected in an interference-free environment. Different wireless communication signals used by different wireless communication modules of different types of sub-machines should be shielded from different signal frequencies. For example, the 2.4GHz frequency band should be shielded when collecting Bluetooth signals. At the same time, to ensure the stability of the physical layer characteristics, the room temperature and humidity should be kept suitable and stable. If there are no special requirements, the standard laboratory environment should be maintained: room temperature 20°C, humidity 50% to 70%. After ensuring that the environment is stable, the signal is sampled at a sampling frequency at least 1.5 times higher than the Nyquist frequency to ensure the collection of signal details. The specific collection steps are as follows: a) Turn on the oscilloscope in advance, collect a noise signal, and observe the noise signal to ensure that there is no interference from other signals; b) Turn on the wireless communication module switch of the wireless communication device to start the wireless communication module of the wireless communication device; c) After turning on the power and collecting a steady-state signal, obtain the following Figure 3The wireless communication signal (the lower amplitude part at the beginning is the noise signal, the rising part in the middle is the transient signal, and the stable part at the end is the steady-state signal) is obtained. The wireless communication module of the oscilloscope and the wireless communication device is turned off and the timing diagram is saved. The process is repeated many times to obtain multiple groups of power-on signals for the main machine and each sub-machine. The timing data signal is stored in the upper computer and waits for the next step of processing.
[0049] (2) Use the fractal Bayesian change point detection algorithm and envelope method to segment the transient signal
[0050] The fractal Bayesian change point detection algorithm mainly uses the difference in fractal dimension between the noise signal segment and the transient signal segment of the received signal to determine the starting point of the transient signal through the maximum a posteriori probability criterion. Unlike variance trajectory detection, this method does not require prior knowledge and has high detection accuracy.
[0051] The fractal Bayesian change point detection algorithm needs to calculate the fractal dimension of the signal first. This process is generally calculated using the Higuchi equation. The specific calculation process belongs to the prior art and will not be described in detail here.
[0052] For a given signal sequence {X(1),…,X(i),…,X(N x )}, where X(i) is the amplitude of the ith discrete signal collected, where i∈[1,N x ],N x In order to collect the number of discrete signal amplitudes, the first step is to split the original sequence into several subsequences of equal length to construct a sample subset:
[0053] X(m,k):X(m),X(m+k),…,X(m+N L ×k) (1)
[0054] in, Indicates (N x -m) / k rounded down, N L Indicates the maximum number of sequence intervals that can be extracted between the index starting point and the sequence interval, m∈[1,k], m is the sample subset index starting point, k is the subsequence sample point interval, X(m,k) represents the sample subset constructed from the given signal sequence with m as the index starting point and k as the sequence interval, X(m) is the first sample extracted from the sample subset X(m,k), that is, extracting the mth item in the original given signal sequence, X(m+k) is the second sample extracted from the sample subset X(m,k), that is, extracting the m+kth item in the original given signal sequence, X(m+N L ×k) is the last sample extracted from the sample subset, that is, the sample m+Nth in the original given signal sequence is extracted. L ×k items.
[0055] The curve length of the signal sample subset X(m,k) is defined as:
[0056]
[0057]
[0058] where k∈[1, k max ], is an empirical value, generally k max =10, i is traversed from 1 to N L The calculated value of It is the sum of the absolute values of the differences between adjacent samples in the sample subset X(m,k).
[0059] When calculating the fractal dimension, we set a sliding window to traverse the entire signal area, and then calculate the fractal dimension values of different positions of the signal to obtain the vector d composed of the overall fractal dimension trajectory of the signal. Then, we calculate the fractal dimension d through the fractal Bayesian change point detection algorithm. m The maximum a posteriori probability within the range of ∈d is used to determine the position of the change point in the data sequence, which corresponds to the position of the transient starting point of the signal. For a given fractal dimension vector d and the starting position b of the transient signal, the sequence a posteriori probability density function is:
[0060]
[0061]
[0062] Among them, N F is the length of the fractal dimension vector d, is the mean of vector d, and d(i) is the value of the vector at position i. Then That’s what you want.
[0063] The original time series data is X(1,N x ), then after obtaining b, the noise signal can be removed from the time series data and the effective signal segment (including transient signal segment and steady-state signal segment) X(b,N) of the target host or slave can be obtained. x ), and then the transient signal segment and the steady-state signal segment need to be separated from the actual signal.
[0064] Hilbert transform is a commonly used method in signal processing, and using Hilbert transform to obtain the signal envelope is also a commonly used method in signal processing.
[0065] For a given signal X(t), the Hilbert transform is defined as:
[0066]
[0067] Where H|X(t)| is the Hilbert transform, x(t) is the real part of the given signal X(t), is the imaginary part of the given signal X(t), * is the convolution operation, t is the time independent variable, τ is the integral variable, then the analysis signal can be defined as:
[0068]
[0069] Where z(t) is the analysis signal after Hilbert transform, It is the transient amplitude, It is the instantaneous phase, j is the sign of the imaginary part, and exp[·] is the exponential function. Then the Hilbert envelope h(f) is:
[0070]
[0071] Where f is the transient frequency.
[0072] Since the amplitude of the steady-state signal is generally stable, its envelope should be approximately a stable straight line, and its slope can be obtained by the envelope derivative. When the slope is less than a certain value ε1, it can be judged that it transitions from a transient signal to a steady-state signal. The ε1 value is determined by the specific change form of the signal. For example, if the target signal in the present invention is a gradual rise, its value is selected to be between 30% and 10% of the maximum value of the envelope curve derivative. At the same time, in order to prevent the transient signal part from fluctuating, a threshold multiple ε2 should be set for it to ensure that it does not end the segmentation early. The threshold multiple is generally selected as 0.93-0.98 times the maximum signal amplitude to ensure the accuracy of signal segmentation. At the same time, by randomly selecting ε1 and ε2, its randomness can also be enhanced. In summary, the transient signal end point position e is:
[0073]
[0074] Where h'(e) is the derivative of the Hilbert envelope h(f) at point e, X[e] is the amplitude of the signal at point e, and X max is the maximum value of the signal amplitude, then the transient signal sequence is X(b,e).
[0075] (3) Using the RF-DNA fingerprint feature extraction algorithm to obtain the original physical layer statistical characteristics of the signal
[0076] Generally speaking, feature extraction methods can be divided into transient signal-based and steady-state signal-based feature extraction methods according to the type of target signal. The two extraction methods have their own advantages. Here, the feature extraction method based on transient signals is used to ensure that the extracted signal features do not contain data information and obtain features that are independent of software. Here, the time domain RF-DNA fingerprint feature extraction algorithm for transient signals is selected.
[0077] Assuming the received signal is r(n), n = 1, 2, ..., N, the analytical representation can be obtained through Hilbert transform:
[0078] r(n)=r I (n)+jr Q (n) (10)
[0079] Among them, r I (n) and r Q (n) represent the instantaneous in-phase and quadrature components of the signal, respectively, and j is the sign of the imaginary part. Three normalized time-domain instantaneous characteristics of the signal can be obtained through formula (10), namely: instantaneous amplitude a(n), instantaneous phase p(n) and instantaneous frequency f(n):
[0080]
[0081]
[0082]
[0083] In the actual signal processing process, the extracted instantaneous features of the signal need to be centralized to reduce the influence of the receiver's own bias on the final fingerprint features. For the instantaneous amplitude a(n) and instantaneous frequency f(n), centralization can be achieved by the following formula:
[0084] a c (n) = a(n) - μ a (n) (14)
[0085] f c (n) = f(n) - μ f (n) (15)
[0086] Among them, μ a is the instantaneous amplitude mean, μ f is the instantaneous frequency mean, a c (n) is the centered instantaneous amplitude, f c (n)Centered instantaneous frequency.
[0087] For the instantaneous phase p(n), since the inaccurate frequency estimation of the receiver used for experimental collection during the signal reception process will cause phase nonlinearity, it is necessary to remove the nonlinear component contained in the instantaneous phase response before centralization.
[0088] p nl (n)=p(n)-2πμ f (n)Δt (16)
[0089]
[0090] Among them, μ f (n) is expressed as the frequency mean as shown in formula (15), Δt represents the sampling time interval, is p in formula (16) nl The mean of (n), p nl (n) is the instantaneous phase after removing the nonlinear component, which is p c (n) is the centralized instantaneous phase. Three final features can be obtained:
[0091] a * (n) = lg(a c (n))-max(lg(a c (n))) (18)
[0092]
[0093]
[0094] Among them, a * (n) is the instantaneous amplitude characteristic, p * (n) is the instantaneous phase characteristic, f * (n) Instantaneous frequency characteristics.
[0095] For the three time-domain instantaneous features, if they are directly used for signal classification and recognition, the high complexity will lead to greater computational overhead and feature redundancy. Based on this, RF-DNA's fingerprint feature extraction algorithm constructs the fingerprint feature set of the mother or child machine by extracting statistical features such as variance, skewness and kurtosis of instantaneous amplitude, phase and frequency.
[0096] The general process of signal time domain RF-DNA fingerprint feature extraction is as follows:
[0097] (1) Perform Hilbert transform on the transient signal sequence obtained after segmentation to obtain the analytical expression shown in formula (10), and obtain the normalized and centered time domain transient feature a through formulas (11) to (20): * (n),p * (n) and f * (n);
[0098] (2) The three time-domain instantaneous features are partitioned, and for each data interval, three statistical parameters are calculated as features:
[0099]
[0100] in, γ x ,κ xRespectively represent the variance, skewness and kurtosis of the data sequence x(n), including the variance, skewness and kurtosis of three time domain instantaneous features:
[0101]
[0102]
[0103]
[0104] Among them, N l represents the length of the data sequence x(n), represents the mean of x(n).
[0105] Therefore, for the three normalized and centered time-domain instantaneous features obtained after the previous processing, substituting them into the formula can obtain a 1*9 feature vector for the input linear kernel support vector machine:
[0106]
[0107] Where i = 0, 1, 2, ..., N, i = 0 represents the master unit, and i ≠ 0 represents the i-th slave unit. is the variance of the instantaneous amplitude characteristic of machine i, γ a is the skewness value of the instantaneous amplitude characteristic of machine i, κ a is the kurtosis value of the instantaneous amplitude characteristic of machine i, is the variance of the instantaneous phase characteristic of machine i, γ p is the skewness value of the instantaneous phase characteristic of machine i, κ p is the kurtosis value of the instantaneous phase characteristic of machine i, is the variance of the instantaneous frequency characteristic of machine i, γ f is the skewness value of the instantaneous frequency characteristic of machine i, κ f is the kurtosis value of the instantaneous frequency characteristic of machine i, and N is the number of sub-machines;
[0108] Repeat the above process for multiple groups of power-on signals of the wireless communication module of the main machine or the sub-machine obtained in step (1) to obtain the physical layer feature data set RFF of the wireless communication module of the main machine or the sub-machine, where s is the number of power-on signals obtained in step (1).
[0109]
[0110] Among them, RFF i is the physical layer feature data set of machine i, The feature vector generated by the s-th power-on signal data of machine i collected in the experiment.
[0111] 2. Key Generation
[0112] The key generation part is to combine the multiple feature vectors obtained by the master machine and each slave machine to obtain a feature data set for binary classification, build a linear kernel support vector machine, classify the feature data set to obtain a separation hyperplane, and encode the parameters of the separation hyperplane to obtain the key matrix. The specific process is as follows Figure 4 shown.
[0113] (1) Constructing a linear kernel support vector machine
[0114] Assume that the linearly separable data set T = {(x1,y1),…,(x i ,y i ),…,(x N ,y N )}, where x i is the sub-machine or main machine feature data set for classification, y i For the slave or master machine and x i The corresponding dataset label, i∈[1,N x ].like Figure 5 As shown, assuming that the separating hyperplane is w * ·x+b * = 0, then the classification decision function is f(x) = sign(w * ·x+b * ), where (w * ,b * ) are the normal vector and intercept of the hyperplane respectively. Define the hyperplane (w * ,b * ) and the data sample point (x i ,y i ) is:
[0115]
[0116] Define the function interval of the data set T as a hyperplane (w * ,b * ) and all sample points (x i ,y i ), that is:
[0117]
[0118] It can be seen from equations (27) and (28) that if (w * ,b * ) changes proportionally to the value of the separating hyperplane w * ·x+b *= 0 will not change, but the corresponding function interval will change exponentially. In actual use, the value of the normal vector can be fixed, so that the interval corresponding to the fixed separating hyperplane is fixed. When ||w||=1, the function interval is also called the geometric interval. From this, we can get the geometric interval between the data set T and the separating hyperplane:
[0119]
[0120] The process of learning the training data set by the linear kernel support vector machine can be regarded as the process of finding the optimal separation hyperplane, which needs to simultaneously satisfy the requirements that different types of data samples can be correctly classified and the geometric interval is the largest. For a linearly separable data set, the separation hyperplane that satisfies both of the above requirements is usually unique. At this time, the interval maximization is also called hard interval maximization. The above linear kernel support vector machine learning process can be simplified to the constrained optimization problem in formula (29):
[0121]
[0122] Optimization purpose, It means finding w and b that maximize the y value.
[0123]
[0124] Then, by introducing Lagrangian duality, we can obtain the dual problem of formula (30):
[0125]
[0126] Among them, α i corresponds to y in formula (30) i >Lagrange multiplier of λ, α j corresponds to y in formula (30) i =Lagrange multiplier of λ, y j 、x j corresponds to the Lagrange multiplier α j of y i With x i Corresponding value.
[0127] Solving equation (31) yields the Lagrange multiplier Then by a * Get the solution of the original optimization problem (w * ,b * ):
[0128]
[0129]
[0130] (2) Using the linear kernel support vector machine to obtain the separation hyperplane that separates the combined features of the parent machine and the child machine
[0131] Combine the main machine extracted in the first step with each sub-machine RFF to obtain a feature data set for binary classification:
[0132] data i =[RFF mother ,RFF i ] (i=1,2,…,N) (34)
[0133] The feature dataset label is
[0134] Y i =[Y mother ,Y i ] (i=1,2,…,N) (35)
[0135] Among them, Y mother =0, Y i =1(i=1,2,…,N). Substituting the feature data set and its labels into step (1), we can get the separating hyperplane:
[0136]
[0137] in is the normal vector of the separation hyperplane obtained by binary classification of child machine i and parent machine through linear kernel support vector machine, is the intercept of the separating hyperplane obtained by binary classification of child machine i and parent machine through linear kernel support vector machine (i=1,2,…,N).
[0138] (3) Combine the separation hyperplane normal vector and intercept to form the original key matrix
[0139] is a 1*9 real number matrix, is a real number, then the two can be combined into the original key matrix C i :
[0140]
[0141] Among them C i is the 1*10 original key matrix of slave machine i.
[0142] (4) Encode the original key matrix to obtain the key matrix of the corresponding slave machine
[0143] The original key matrix is a pure data matrix and the length of each data in the matrix is different. Secondary encoding is required to comply with the key specification and improve security. Take MD5 encoding as an example:
[0144] MD5 (Message Digest Algorithm 5) is a hash function widely used in the field of computer security to provide message integrity protection. The algorithm steps are:
[0145] a. Filling
[0146] In the MD5 algorithm, the information needs to be padded so that the result of its bit length modulo 512 is equal to 448, and its bit length is extended to N*512+448, where N is a non-negative integer. The padding steps are as follows: ① Pad a 1 and countless 0s after the information, and stop padding the information with 0s until the above conditions are met. ② Add a 64-bit binary representation of the length of the information before padding to the result. If the length of the information before padding in binary exceeds 64 bits when expressed in binary, take the lower 64 bits of the binary representation.
[0147] b. Initialize variables
[0148] The initial 128-bit value is the initial link variable. These parameters are used for the first round of operations and are expressed in big-endian byte order. Finally, four 32-bit constants A, B, C, and D are initialized.
[0149] c. Processing packet data
[0150] The algorithm flow of each group is as follows: The first group needs to copy the above four linked variables to the other four variables: A to a, B to b, C to c, D to d. The variables starting from the second group are the operation results of the previous group, that is, A = a, B = b, C = c, D = d.
[0151] The main loop has four rounds, and the first round performs 16 operations. Each operation performs a nonlinear function operation on three of a, b, c, and d, and then adds the result to the fourth variable to obtain a subgroup of the text and a constant. The result is then bitwise shifted to the left by a random distance and added to one of a, b, c, or d. Finally, the result replaces one of a, b, c, or d. The four nonlinear functions used in each operation are as follows:
[0152] F(X,Y,Z)=(X&Y)|((~X)&Z) (38)
[0153] G(X,Y,Z)=(X&Z)|(Y&(~Z)) (39)
[0154] H(X,Y,Z)=X^Y^Z (40)
[0155] I(X,Y,Z)=Y^(X|(~Z)) (41)
[0156] Among them, F(X,Y,Z), G(X,Y,Z), H(X,Y,Z), and I(X,Y,Z) are four nonlinear transformation functions, & is the bitwise AND symbol, | is the bitwise OR symbol, ~ is the bitwise inversion symbol, and ^ is the bitwise XOR symbol.
[0157] After the above three steps, the basic MD5 output can be obtained:
[0158] y=MD5(x) (42)
[0159] Among them, x is the original input, MD5() is the MD5 conversion function, and y is the basic MD5 output obtained by converting the x input.
[0160] d. "Salt Addition" Operation
[0161] To prevent reverse decryption, a specific string of your choice should be inserted at any fixed position in the password. It is customary to use "salt" to make the hashed result inconsistent with the hashed result using the original password. This process is called "salting".
[0162] The final output password of MD5 encoding is:
[0163] y * =MD5(x+salt) (43)
[0164] Among them, "salt" is the specific string added. If there is no special description, it can be considered that the string "salt" is added. * It is the final output of MD5 encoding after "salting".
[0165] Encode each element in the original key matrix as:
[0166]
[0167] Then the key matrix of slave machine i is:
[0168]
[0169] Figure 6 The key generation process is shown, the keys of all slave machines are obtained and stored in the corresponding slave machines.
[0170] 3. Key application
[0171] The key application part is to apply the slave key matrix obtained in step 2, which has the following two forms:
[0172] (1) Master control mode
[0173] like Figure 7 It is the master control mode of the mother machine. Figure 8This is the communication procedure for the master machine in master control mode.
[0174] In this mode, all slave serial numbers and slave keys are stored in the master, and the master number is stored in each slave. The master can initiate communication requests to all slaves and communicate. The specific steps of communication are as follows:
[0175] a. The master transmits its own number and the serial number of the target slave to the surroundings, and waits for the slave to respond;
[0176] b. The target slave responds to the master and transmits its own serial number;
[0177] c. After the master receives and receives only one slave's response, it confirms it as the target slave, transmits the key matrix of the corresponding slave, and waits for the slave's response;
[0178] d. After receiving the key matrix, the slave compares it with the master key matrix. If they are correct, it is confirmed to be the master and the master number is sent to respond to the master.
[0179] e. The master receives the response from the slave and establishes communication with the slave.
[0180] In this mode, the mother machine is the main control object, which is suitable for environments such as smart homes or smart factories where various devices need to communicate and control with mother machines such as mobile phones and central control machines.
[0181] (2) Slave unit communication mode
[0182] like Fig. 9 For slave communication mode, Fig.10 This is the communication procedure for slave communication mode.
[0183] In this mode, each slave will store the slave serial number and key matrix of the remaining slaves in the slave group that needs to establish communication. The slaves can initiate communication requests with each other and communicate. For example, slave A initiates a communication request to slave B. The specific steps of communication are as follows:
[0184] a. Handset A transmits its own serial number and the serial number of the target handset B to the surroundings, and waits for handset B to respond;
[0185] b. Handset B responds to Handset A and transmits Handset B's serial number back;
[0186] c. After receiving only one response from slave B, slave A confirms it as the target slave, transmits the key matrix of slave B, and waits for slave B to respond;
[0187] d. After receiving the key matrix, slave B compares it with its own key matrix. If they are completely correct, it is confirmed to be slave A and the key matrix of slave A is sent to respond to slave A.
[0188] e. After receiving the sub-machine key matrix, slave A compares it with its own key matrix. If they are completely correct, it is confirmed to be slave B and communication is established with slave B.
[0189] In this mode, the slave is the main control object, and its internal storage only stores the slave key and the keys of other slaves to establish communication. It is suitable for mutual communication among components in smart homes or smart factories, or when multiple slaves need to communicate with each other under the control of the main machine, such as the communication system of the security system.
[0190] In summary, the method for generating the physical layer key of a wireless communication device based on the RF-DNA fingerprint feature extraction algorithm is as follows: Fig.11 As shown:
[0191] a. Select a mother machine and collect multiple wireless communication signal data segments when the mother machine is turned on;
[0192] b. Number each sub-unit in the sub-unit group and collect multiple wireless communication signal data segments when the sub-unit is turned on;
[0193] c. Match the master unit and slave unit in sequence, and perform signal preprocessing and feature extraction;
[0194] d. Use the linear kernel support vector machine to identify the matched features and obtain the separation hyperplane parameters;
[0195] e. Encode the obtained parameter matrix to obtain the key matrix;
[0196] f. The key matrix is combined with the serial number of the slave and stored in the slave as the physical layer key of the slave;
[0197] g. Store the physical layer keys of other slaves into the slave or master machine according to different needs.
[0198] In summary, when the RF-DNA fingerprint feature extraction algorithm used in the present invention is used for classification and identification, the parameters of the support vector machine separation hyperplane are used as passwords for key generation. It is proposed to use the physical layer features of the mother machine and the sub-machine group for key generation, rather than generating physical layer features for two independent machines. It is proposed to use wireless communication signals as key generation objects, which can be applied to various types of wireless communication devices.
[0199] Advantages of the present invention: (1) The present invention only uses the physical layer intrinsic characteristics of the wireless communication module of the device, does not rely on the participation of a third party in generation, distribution and management, reduces resource consumption, and avoids the emergence of malicious third parties. (2) The present invention pre-builds the password into the target device, and does not rely on highly complex algorithms and key encryption and decryption processes, reduces communication delays, and is more in line with the requirements of today's Internet of Things technology. (3) The present invention does not have human factors, realizes the separation of man and machine, and reduces the risk of hacker social engineering attacks and database collisions. (4) The parent-child key generation method proposed in the present invention does not rely on the physical layer characteristics of a single device. If the child machine is stolen, it is not easy to reproduce the key generation process. (5) The password update and generation of the key generation method proposed in the present invention are only related to the parent machine. Each parent machine can retain the old version of the password. At the same time, by replacing the parent machine, the password can be updated quickly and efficiently. (7) The present method uses the power-on signal of the wireless communication module of the device. The signal is universal and can be applied to various devices with wireless communication modules.
Claims
1. A physical layer key generation method based on a radio frequency fingerprint recognition model, the method is applied to a wireless communication network including a master machine and a slave machine group, and is characterized in that: The method comprises the following steps: Step 1: Signal processing 1) Collect the wireless communication signal of the master machine when it is turned on, and number each slave in the slave group and collect the wireless communication signal of each slave when it is turned on; 2) Use the fractal Bayesian change point detection algorithm and envelope method to segment the transient signal segment of the wireless communication signal; 3) Use the RF-DNA fingerprint feature extraction algorithm to extract the radio frequency fingerprint and obtain the physical layer feature data set RFF of the main machine and each sub-machine. RFF i is the physical layer feature data set of machine i, is the feature vector generated by the collected wireless communication signal data of the sth machine when it is turned on, When i≠0, it represents the i-th sub-machine. is the variance of the instantaneous amplitude characteristic of machine i, γ a is the skewness value of the instantaneous amplitude characteristic of machine i, κ a is the kurtosis value of the instantaneous amplitude characteristic of machine i, is the variance of the instantaneous phase characteristic of machine i, γ p is the skewness value of the instantaneous phase characteristic of machine i, κ p is the kurtosis value of the instantaneous phase characteristic of machine i, is the variance of the instantaneous frequency characteristic of machine i, γ f is the skewness value of the instantaneous frequency characteristic of machine i, κ f is the kurtosis value of the instantaneous frequency characteristic of machine i, and N is the number of sub-machines; Step 2: Generate the physical layer key of the slave The physical layer feature data set of the master machine and the physical layer feature data sets of each slave machine are combined to form a key feature set, and the key feature set is a feature data set that can be used for binary classification; a linear kernel support vector machine is constructed, and the key feature set is used as a training set to establish a separating hyperplane. The normal vector and intercept of the separating hyperplane are obtained through binary classification of the linear kernel support vector machine to form the original key matrix C of slave machine i. i , is the normal vector of the separation hyperplane obtained by binary classification of child machine i and parent machine through linear kernel support vector machine, is the intercept of the separating hyperplane obtained by binary classification of the sub-machine i and the main machine through the linear kernel support vector machine. i Encode to obtain the key matrix of slave machine i, and store it in the slave machine, and obtain the key matrix of all slave machines in the same way; Step 3: Key application When the master and slave machines are ready to establish communication, all slave machine serial numbers and slave machine key matrices are stored in the master machine, and the master machine serial number and each slave machine's own key matrix are stored in each slave machine; When slaves are to establish communication, each slave will store its own key matrix and the slave serial numbers and key matrices of the remaining slaves in the slave group with which it needs to establish communication.
2. The method for generating a physical layer key based on a radio frequency fingerprint recognition model according to claim 1, characterized in that: The process of applying the slave machine key matrix obtained in step 2 in the two scenarios of master machine master control mode and slave machine communication mode is as follows: The first scenario: Master machine master control mode This mode stores all slave serial numbers and slave key matrices in the master, and stores the master serial number and each slave's own key matrix in each slave. The master can initiate communication requests to all slaves and communicate. The specific steps of communication are: a) The master transmits its own number and the serial number of the target slave to the surroundings, and waits for the slave to respond; b) The target slave responds to the master and transmits its own serial number; c) After the master receives and receives only one slave's response, it confirms it as the target slave, transmits the key matrix of the corresponding slave, and waits for the slave's response; d) After receiving the key matrix, the slave compares it with the master key matrix. If they are correct, it is confirmed to be the master and the master number is sent to respond to the master. e) The master receives the response from the slave and establishes communication with the slave; The second scenario: slave machine communication mode In this mode, each slave will store its own key matrix and the slave serial number and key matrix of the other slaves in the slave group that needs to establish communication. Slave A initiates a communication request to slave B and communicates with each other. The specific steps of communication are as follows: a) Slave A transmits its own serial number and the serial number of the target slave B to the surroundings, and waits for slave B to respond; b) Handset B responds to Handset A and transmits back Handset B’s serial number; c) After receiving only one response from slave B, slave A confirms it as the target slave, transmits the key matrix of slave B, and waits for slave B to respond; d) After receiving the key matrix, slave B compares it with its own key matrix. If they are completely correct, it is confirmed to be slave A and the key matrix of slave A is transmitted to respond to slave A; e) After receiving the sub-machine key matrix, slave A compares it with its own key matrix. If they are completely correct, it is confirmed to be slave B and communication is established with slave B.
3. The method for generating a physical layer key based on a radio frequency fingerprint recognition model according to claim 1, characterized in that: The RF-DNA fingerprint feature extraction algorithm adopts the time domain RF-DNA fingerprint feature extraction algorithm.
4. The method for generating a physical layer key based on a radio frequency fingerprint recognition model according to claim 1, characterized in that: The encoding uses MD5 encoding.
Citation Information
Patent Citations
A method and system for generating millimeter-wave physical layer keys with random beam switching
CN113596826B
Wireless channel key generation method and device, equipment and storage medium
CN114390519A
Endogenous secure communication method based on wireless channel characteristics
CN111132153A
Physical layer label signal embedding authentication method and system based on WFRFT
CN112188483A