A new physical layer encryption and authentication cooperation security method
By using encrypted sequences and digital tags generated by hash functions for collaborative encryption and authentication at the physical layer, the problems of frequent key updates and reliance on high-precision instruments in existing technologies are solved, achieving efficient encryption and authentication collaboration and resisting differential attacks.
Patent Information
- Application Number
- CN202310366553.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-04-07
- Publication Date
- 2025-12-12
- Estimated Expiration
- 2043-04-07
AI Technical Summary
The existing physical layer encryption technology is separate from the authentication technology, which requires high key update and maintenance, and the authentication process relies on high-precision instruments and superimposed digital tag detection, making it unable to effectively resist differential attacks.
A hash function is used to generate encrypted sequences and digital tags. The encrypted sequences and digital tags are generated by phase features and key input, and embedded in the signal for encryption and authentication. The receiving end uses digital features to regenerate the tags for authentication, which is independent of signal detection.
It reduces the need for key updates, improves system efficiency, achieves better encryption and authentication collaboration, resists differential attacks, and achieves the theoretical maximum level of confidentiality.
Smart Images

Figure CN116367149B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of communication security, in particular to a new physical layer encryption and authentication cooperation security method, which prevents eavesdropping and attack at the physical layer, prevents illegal receiving end from obtaining information sent by the legal sending end, and prevents the false message sent by the illegal sending end from being received and processed by the legal receiving end. BACKGROUND
[0002] The existing physical layer encryption technology and authentication technology are separated. The encryption technology focuses on the generation and distribution of the key, and performs encryption through XOR, rotation and other operations of the key and information. Only in the case of "one-time key", can it effectively resist differential decryption. The existing technology includes key generation based on channel state information, key generation based on chaotic system, quantum key distribution, etc. This situation puts forward higher requirements for the update, generation and distribution of the key. The authentication technology is to analyze the received signal based on device characteristics, channel, superimposed digital tag, etc. by the signal receiving end, and analyze whether the signal is from the legal sending end. The method based on device characteristics and channel needs high-precision detection instruments. The method based on superimposed digital tag (the unique output cannot be denied by inputting information and key into hash function, and the tag is superimposed as a secondary signal on the message signal) needs to detect the signal and the tag at the same time, or detect the signal first and the tag as a residual signal. In addition, authentication is to compare the detected tag with the tag regenerated by the received signal and the key. If the difference is small enough, it is considered that the information comes from a legal source, otherwise, it is illegal. The process of detecting the signal first cannot be avoided. SUMMARY
[0003] In view of the technical problem that the ability of the existing encryption technology to resist differential attack relies on the rapid update of the key, the present application proposes a new physical layer encryption and authentication cooperation security method. Instead of directly using the key and the information itself, the method generates an encryption sequence by using the key and the digital characteristics of the information through a hash function, and uses the encryption sequence to act on the information. The encryption sequence will change greatly when the key remains unchanged and the information changes. The digital characteristics of the information remain unchanged before and after encryption. The receiving end can regenerate the encryption sequence by using the digital characteristics of the received information and the key before decryption, and use it for decryption. Illegal users cannot decrypt because they do not know the key. The encryption sequence changes with the information itself, which can resist differential decryption, greatly reducing the demand for key update, and reducing the speed requirement and overhead of key generation and distribution. The digital tag required for authentication uses the same generation method and input as the encryption sequence, and is embedded by power allocation instead of superimposition. In this way, the detection of the tag can be independent of the detection of the signal, improving the efficiency of the system and increasing the cooperation of authentication and encryption.
[0004] The technical scheme of the present application is implemented as follows:
[0005] A new physical layer encryption and authentication cooperation security method, the steps of which are as follows:
[0006] Step one: at the sending end, phase features f are extracted from the input signal, and the phase features f and a key k are taken as inputs of a hash function to generate a digital tag t a and an encryption sequence t e .
[0007] Step two: the signal is encrypted by using the encryption sequence t e , and the digital tag is embedded in the encrypted signal to obtain a signal x sent by the sending end;
[0008] Step three: the signal x sent by the sending end reaches the receiving end after transmission through a wireless channel, and the receiving end receives a signal y, wherein y=hx+n, h is a channel gain, and n is noise;
[0009] Step four: at the receiving end, an estimated value of the digital features and a detected detection tag
[0010] Step five: the estimated value and the key k are used to regenerate an authentication tag and a decryption sequence , and the authentication tag is compared with the detection tag , if the difference is large, the signal y is discarded, and the standby state is re-entered; otherwise, the signal y passes the authentication, and step six is performed;
[0011] Step six: the signal y is decrypted by using the decryption sequence to obtain plaintext.
[0012] Preferably, the input signal is a 0 / 1 bit stream m, and the length is 2T; the input signal m is modulated into a QPSK signal at the sending end, and is represented as a complex signal s=[s1, s2,..., s T ].
[0013] Preferably, the generation method of the digital tag t a and the encryption sequence t e is as follows:
[0014] t a =hash(f,k),
[0015] t e =hash(k,f).
[0016] Preferably, the signal x is represented as:
[0017] x=s·(2diag{t e}-I)·diag{ρ2t a +ρ1(1-t a )},
[0018] Where diag is the diagonalization function, ρ1 and ρ2 are coefficients for energy distribution, and I is the identity matrix;
[0019] Encrypted information without embedded tags x e Represented as: x e =s·(2diag{t e}-I).
[0020] Preferably, the estimated value of the digital features extracted from the signal y The method is as follows:
[0021] After removing the channel gain from the received signal y, the ciphertext is obtained: Then from the ciphertext Estimates of digital features extracted if In the first or third quadrant, Otherwise yes The i-th element.
[0022] Preferably, the authentication label and decryption sequence The generation method is as follows:
[0023]
[0024]
[0025] Preferably, the authentication label With detection label The comparison method is as follows:
[0026]
[0027] Where η is the tolerance error, To test the statistic, we need to represent the certification label. With detection label Different numbers of bits.
[0028] Preferably, the use of decryption sequence The method for decrypting signal y to obtain plaintext is as follows:
[0029] Ciphertext obtained through maximum likelihood estimation The detection is carried out, and the encrypted signal estimation value is obtained:
[0030]
[0031] wherein, represents the encrypted signal estimation value;
[0032] The decrypted sequence is utilized The encrypted signal estimation value is decrypted, and the decrypted signal estimation value is obtained:
[0033]
[0034] wherein, represents the QPSK signal estimation value;
[0035] The QPSK signal estimation value is demodulated, and the message estimation value is obtained
[0036] Compared with the prior art, the present application has the following beneficial effects:
[0037] 1) By only exchanging the key and the front and rear order of the information digital features, a digital label sequence pseudo-uncorrelated with the encrypted sequence can be obtained; the digital label sequence is embedded into the message as the energy distribution of the message time slots, and at the receiving end, only the digital features of the received signal need to be extracted, and the message itself does not need to be detected; at the receiving end, the energy change of the noisy signal can be directly detected, that is, the detected label is obtained, and then the digital features of the received signal and the key are used to regenerate the label; the detected label and the regenerated label are compared, and authentication is performed.
[0038] 2) The encryption and authentication of the present application use the same hash function, the same key and the same signal digital features, and better cooperation is achieved; the deep joint encryption and superimposed digital label authentication technology cooperates to realize the physical layer security and prevent eavesdropping and attacks.
[0039] 3) The security performance of the encryption scheme can reach the theoretical maximum value, that is, the bit error rate of the illegal eavesdropping end is the maximum value 1 / 2; the plaintext sensitivity is good, the same key is used, when the plaintext of the sent information changes, the average change rate of the ciphertext is the maximum value 1 / 2, that is, it has the optimal anti-differential attack ability. BRIEF DESCRIPTION OF DRAWINGS
[0040] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the drawings needed to be used in the embodiments or the prior art description will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0041] Figure 1 The flow chart of the present application.
[0042] Figure 2 The label detection principle diagram of the present application. DETAILED DESCRIPTION
[0043] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all the other embodiments obtained by those skilled in the art without creative effort belong to the scope of protection of the present application.
[0044] The embodiments of the present application provide a new physical layer encryption and authentication cooperation security method. A key and information digital features are used to generate an encryption sequence through a hash function. The information is encrypted by using the encryption sequence. The encryption sequence will greatly change (about 1 / 2 of the content changes) when the key is unchanged and the information changes. The digital features of the information before and after encryption are unchanged. The information receiving end can regenerate the encryption sequence by using the digital features of the received signal and the key before decryption, and decrypt by using the encryption sequence. An illegal user cannot decrypt because the key is unknown. The encryption sequence changes with the information itself, and can resist differential decryption. This encryption technology greatly reduces the demand for key update, and can reduce the rate requirement and overhead of key generation and distribution. Figure 1 As shown in the figure, the specific steps are as follows:
[0045] Step 1: At the sending end, the phase feature f is extracted from the input signal m, and the phase feature f and the key k are taken as the input of the hash function to generate the digital tag t a and the encryption sequence t e . The input signal is a 0 / 1 bit stream m, and the length is 2T. The information bit stream m is modulated into a 4-phase shift keying modulation constellation at the sending end, that is, every two bits are mapped into a complex transmission symbol. It is represented as a QPSK signal {-1-j, -1+j, 1-j, 1+j}, and the complex signal s = [s1, s2,..., s T ].
[0046] The phase feature f of the complex signal is extracted, and the length is T. If s i is in the 1st or 3rd quadrant, f i is 0, and if s i is in the 2nd or 4th quadrant, f i is 1.
[0047] The digital tag t a and the encryption sequence t e are both 0 / 1 sequences with a length of T, and t a= hash(f, k), t e = hash(k, f). By adjusting the front and back positions of the two inputs, two different sequences can be generated and security performance is improved.
[0048] Step two: use the encryption sequence t e Encrypt the complex signal s to get x e , x e = s·(2diag{t e}-I); Specifically: if t e,i = 1, x e,i = s i , if t e,i = 0, x e,i = -s i . And embed the digital tag in the encrypted signal x e Obtain the signal x sent by the sending end; Specifically: if t a,i = 1, x i = ρ1x e,i , if t a,i = 0, x i = ρ2x e,i .
[0049] If the bit of the encryption sequence is 0 in a time slot, the sending symbol is reversed, otherwise the bit of the encryption sequence is 1, and the sending symbol remains unchanged. At the same time, the digital tag is embedded in the sending symbol in different energy allocation ways, if the digital tag is 0, the energy of the sending symbol is ρ1 2 , if the digital tag is 1, the energy of the sending symbol is This process is represented by the formula: x = s·(2diag{t e}-I)·diag{ρ2t a + ρ1(1-t a )}, where diag is a diagonalization function that returns a matrix with the input vector as the diagonal, that is, diag{t e} ii = t e,i , ρ1, ρ2 are energy allocation coefficients, and the average of energy allocation is 1 (sum is 2), that is, I is the unit matrix.
[0050] Step three: the signal x sent by the sending end passes through the wireless channel and reaches the receiving end, and the receiving end receives the signal y, where y = hx + n, h is the channel gain, n is the noise, and the length is the same as the signal length.
[0051] Step four: in the receiving end, based on the maximum likelihood ratio criterion, the estimated value of the digital feature and the detected detection tag are extracted from the signal y Specifically: if y i In 1 or 3 quadrants, if y i In 2 or 4 quadrants, if Otherwise where is the i-th element of the input, Re and Im functions are the real and imaginary parts of the input, respectively.
[0052] If the received signal is removed from the channel gain h is the channel gain; as shown, if Figure 2 falls in the shadow area, its projection on the diagonal line is less than then the embedded label is judged to be 0, if falls outside the shadow area, its projection on the diagonal line is greater than then the embedded label is judged to be 1.
[0053] Step five: regenerate the authentication label and the decryption sequence using the estimated value and the key k. Compare the difference between the authentication label and the detected label , if the difference is large, consider that the information source is illegal and discard the information, discard the signal y, and wait for standby again; otherwise, consider that the information source is legal, the signal y passes the authentication, and execute step six. The physical layer authentication process is a binary hypothesis testing process: H1: the signal detects the expected label. H2: the signal does not detect the expected label. The test statistic is set as: Its meaning is the number of different bits between the detected label and the regenerated label. The test process can be described as: Where η is the allowable error, which determines the level of communication security.
[0054] Step six: use the decryption sequence to perform decryption operation on the signal y to obtain the plaintext. If the information source is legal, detect the ciphertext by maximum likelihood estimation to obtain and use to decrypt the detected ciphertext information to obtain Finally, demodulate to obtain
[0055] Specific examples:
[0056] The transmitted signal 512 is the bit data m:
[0057] 011010110101111110000011001111101001101111110110101000001110111001100101001110 000010011000011100010110100111101011101101110101001101110010011110000110101010110 1001010111011001100000000010100011111000011110110111100101110000111001011011111111 0011011101111010011101011100011111010011101100010110011110011101000100001100111101 0000000100111111100001001011110011111100011110110110110001101111001000101011010110 00001111010101011111001110110110110111100110000010000000000001010000000000111000100000101101111010011001111.
[0058] The transmitted symbol s after QPSK modulation is:
[0059]
[0060] where, divided by is to normalize the energy.
[0061] Assume the key k is 128 bits:
[0062] 01010110000010100001111000001110011111101000010100101100111001111101001011000100000000101100100101111010111000111101101001011111.
[0063] The signal digital feature f can be extracted as:
[0064] 111011001000000111100011110001011111001001110100111110110101011001001101011111 010110100000001101000000110001010100101000111010010011010001110110100000011010111 0110001100000111011001000110110010110111110001011110011011011000000100000011000010010011100100000.
[0065] The hash function is selected as SHA-256, and the generated encrypted sequence t e is: 11000010001011000101000110101111011101110010111101000101000010110010101100101 100101000010000001001000011100111011010100011101010010100110001000010101011101001 000011000011011000000011010111100001011001001010001011011000010101011011111110100 11101001110011010
[0067] The digital tag sequence t a is:
[0068] 001101011110100111001111010000001001110001000010011101111101111001100010111010 1111001111001101111010001111110001001011001111101011111100100111111000110101010100 000000110100101011001110010001100000000010000111110001110011000110000111100110001010100010011011.
[0069] The encrypted information x e is:
[0070]
[0071]
[0072] The transmitted signal x after embedding the tag is:
[0073] -0.6595+0.6595j, 0.6595-0.6595j, -0.7517+0.7517j, -0.7517-0.7517j, 0.6595-0.6595j, 0.7517-0.7517j, 0.6595+0.6595j, -0.7517-0.7517j, -0.7517+0.7517j, 0.7517+0.7517j, -0.7517-0.7517j, -0.6595-0.6595j, -0.7517-0.7517j, 0.6595+0.6595j, -0.6595-0.6595j, -0.7517+0.7517j, -0.7517+0.7517j, -0.7517+0.7517j, -0.6595+0.6595j, 0.6595+0.6595j, -0.7517-0.7517j, -0.7517-0.7517j, 0.7517-0.7517j, 0.7517-0.7517j, 0.6595-0.6595j, -0.7517+0.7517j, -0.6595-0.6595j, 0.6595+0.6595j, 0.6595+0.6595j, 0.6595-0.6595j, 0.6595+0.6595j, 0.6595-0.6595j, 0.7517-0.7517j, 0.6595-0.6595j, -0.6595+0.6595j, -0.7517+0.7517j, 0.7517+0.7517j, 0.7517+0.7517j, 0.6595-0.6595j, -0.6595-0.6595j, 0.6595+0.6595j, -0.7517+0.7517j, -0.6595+0.6595j, -0.6595+0.6595j, -0.6595-0.6595j, -0.6595+0.6595j, 0.7517+0.7517j, -0.6595-0.6595j, 0.6595-0.6595j, -0.7517+0.7517j, -0.7517+0.7517j, -0.7517+0.7517j, 0.6595-0.6595j, 0.7517+0.7517j, -0.7517+0.7517j, 0.7517-0.7517j, -0.7517-0.7517j, -0.7517+0.7517j, -0.6595-0.6595j, 0.7517-0.7517j, 0.7517+0.7517j, 0.7517-0.7517j, -0.7517+0.7517j, -0.6595-0.6595j, -6595-0.6595j, 0.7517-0.7517j, 0.7517+0.7517j, 0.6595+0.6595j, 0.6595-0.6595j, 0.6595-0.6595j, 0.7517+0.7517j, 0.6595-0.6595j, 0.7517+0.7517j, 0.7517-0.7517j, 0.7517-0.7517j, -0.6595+0.6595j, 0.7517-0.7517j, 0.6595-0.6595j, -0.7517-0.7517j, 0.7517-0.7517j, -0.7517-0.7517j, -0.7517+0.7517j, 0.6595-0.6595j, -0.6595-0.6595j, -0.7517+0.7517j, -0.7517-0.7517j, 0.7517+0.7517j, 0.7517+0.7517j, 0.6595+0.6595j, 0.6595+0.6595j, 0.7517+0.7517j, 0.7517+0.7517j, 0.6595-0.6595j, 0.7517-0.7517j, -0.7517-0.7517j, 0.7517-0.7517j, -0.7517-0.7517j, 0.6595+0.6595j, 0.7517+0.7517j, 0.6595+0.6595j, -0.6595-0.6595j, -0.6595-0.6595j, -0.7517+0.7517j, 0.7517-0.7517j, 0.7517+0.7517j, -0.7517-0.7517j, 0.7517+0.7517j, 0.7517-0.7517j, 0.6595+0.6595j, 0.6595-0.6595j, 0.6595+0.6595j, -0.7517+0.7517j, 0.6595+0.6595j, 0.6595+0.6595j, 0.7517-0.7517j, -0.6595-0.6595j, -0.7517+0.7517j, -0.7517-0.7517j, -0.6595-0.6595j, -0.6595-0.6595j, 0.7517-0.7517j, -0.7517+0.7517j, 0.7517-0.7517j, -0.7517-0.7517j, 0.7517-0.7517j, -0.6595-0.6595j, 0.7517+0.7517j, 0.6595-0.6595j, 0.7517+0.7517j, 0.7517+0.7517j,-0.7517+0.7517j,0.7517-0.7517j,-0.7517-0.7517j,-0.7517+0.7517j,-0.6595-0.6595j,0.6595+0.6595j,-0.7517-0.7517j,-0.6595+0.6595j,-0.6595+0.6595j,-0.7517+0.7517j,-0.7517-0.7517j,0.7517-0.7517j,-0.7517+0.7517j,0.7517+0.7517j,0.7517-0.7517j,-0.6595-0.6595j,-0.6595-0.6595j,-0.6595-0.6595j,0.7517+0.7517j,0.7517+0.7517j,0.6595+0.6595j,0.7517-0.7517j,0.6595-0.6595j,0.7517+0.7517j,0.6595-0.6595j,0.7517+0.7517j,0.6595-0.6595j,0.7517-0.7517j,0.6595-0.6595j,-0.6595-0.6595j,-0.6595+0.6595j,-0.6595+0.6595j,-0.6595-0.6595j,-0.6595-0.6595j,0.6595+0.6595j,-0.6595+0.6595j,0.7517-0.7517j,-0.7517-0.7517j,0.6595+0.6595j,0.7517+0.7517j,0.6595+0.6595j,-0.6595-0.6595j,0.7517-0.7517j,0.6595-0.6595j,0.7517-0.7517j,-0.6595-0.6595j,-0.7517+0.7517j,0.7517-0.7517j,-0.6595-0.6595j,-0.6595-0.6595j,0.7517-0.7517j,-0.7517-0.7517j,-0.7517-0.7517j,0.6595+0.6595j,0.6595-0.6595j,0.7517-0.7517j,0.6595+0.6595j,-0.6595+0.6595j,0.6595-0.6595j,0.7517+0.7517j,-0.7517-0.7517j,0.6595-0.6595j,-0.6595-0.6595j,0.6595-0.6595j, 0.6595 - 0.6595j, -0.6595 - 0.6595j, -0.6595 + 0.6595j, 0.6595 - 0.6595j, 0.6595 - 0.6595j, 0.6595 - 0.6595j, -0.7517 + 0.7517j, -0.6595 - 0.6595j, -0.6595 - 0.6595j, 0.6595 + 0.6595j, -0.6595 + 0.6595j, -0.7517 - 0.7517j, -0.7517 + 0.7517j, -0.7517 + 0.7517j, 0.7517 - 0.7517j, -0.7517 + 0.7517j, 0.6595 + 0.6595j, 0.6595 + 0.6595j, -0.6595 + 0.6595j, -0.7517 + 0.7517j, 0.7517 + 0.7517j, 0.7517 - 0.7517j, -0.6595 + 0.6595j, -0.6595 - 0.6595j, 0.7517 - 0.7517j, 0.7517 - 0.7517j, -0.6595 - 0.6595j, 0.6595 + 0.6595j, 0.6595 + 0.6595j, 0.7517 + 0.7517j, 0.7517 + 0.7517j, -0.6595 - 0.6595j, -0.6595 + 0.6595j, 0.6595 + 0.6595j, -0.6595 - 0.6595j, -0.7517 - 0.7517j, -0.7517 - 0.7517j, -0.7517 - 0.7517j, -0.7517 - 0.7517j, 0.6595 - 0.6595j, 0.6595 - 0.6595j, 0.7517 + 0.7517j, -0.7517 - 0.7517j, 0.6595 + 0.6595j, 0.6595 + 0.6595j, -0.6595 + 0.6595j, 0.7517 + 0.7517j, -0.6595 - 0.6595j, 0.7517 - 0.7517j, -0.6595 - 0.6595j, 0.7517 + 0.7517j, 0.6595 - 0.6595j, -0.6595 + 0.6595j, 0.6595 - 0.6595j, 0.7517 + 0.7517j, -0.6595 - 0.6595j, 0.6595 - 0.6595j, -0.7517 - 0.7517j, 0.7517 + 0.7517j, 0.6595 + 0.6595j, 0.7517 + 0.7517j, -0.7517 - 0.7517j.
[0074] Assume that the channel gain is 1 and the signal-to-noise ratio is 15 dB. Once noise is randomly generated, the received signal y is (because the channel gain is 1, ) :
[0075] -0.7519+0.6717j, 0.3917-0.7348j, -0.7635+0.8264j, -0.8965-0.7580j, 0.4484-0.4921j, 0.7510-0.6579j, 0.5857+0.6880j, -0.8019-0.5842j, -0.7360+0.8608j, 0.7723+0.7944j, -0.7957-0.8662j, -0.6954-0.4920j, -0.8017-0.7675j, 0.6273+0.6153j, -0.7772-0.6558j, -0.9161+0.8860j, -0.8932+0.7666j, -0.6853+0.6087j, -0.6589+0.6242j, 0.7727+0.5582j, -0.6033-0.7858j, -0.8477-0.9090j, 0.6188-0.7069j, 0.5177-0.7950j, 0.6330-0.7707j, -0.6647+0.6786j, -0.4712-0.4998j, 0.6691+0.5093j, 0.6011+0.7207j, 0.6872-0.6383j, 0.5562+0.5095j, 0.6709-0.6545j, 0.7415-0.8680j, 0.5038-0.5544j, -0.7018+0.7289j, -0.6935+0.7370j, 0.9308+0.6273j, 0.8209+0.6863j, 0.9038-0.7222j, -0.7468-0.6161j, 0.6828+0.8163j, -0.7726+0.8471j, -0.6410+0.6036j, -0.7949+0.4228j, -0.6725-0.7521j, -0.6992+0.7039j, 0.7047+0.6182j, -0.7053-0.6602j, 0.6271-0.4744j, -0.7506+0.9561j, -0.5887+0.7738j, -0.7993+0.9742j, 0.6589-0.5879j, 0.5446+0.8408j, -0.7283+0.8216j, 0.7618-0.8137j, -0.8330-0.7270j, -0.7051+0.8168j, -0.6956-0.5105j, 0.7175-1.075j, 0.6097+0.6443j, 0.8620-0.5773j, -0.8676+0.8336j, -0.6460-0.6322j, -6446 -0.5938j, 0.8420 -0.6029j, 0.8446 +0.6328j, 0.4891 +0.7112j, 0.8218 -0.8961j, 0.7316 -0.6429j, 0.6323 +0.7638j, 0.5351 -0.5011j, 0.7002 +0.6593j, 0.6843 -0.6831j, 0.8731 -0.6315j, -0.5315 +0.5707j, 0.7782 -0.7125j, 0.7886 -0.6534j, -0.7379 -0.7735j, 0.9185 -0.8143j, -0.5984 -0.8349j, -0.9112 +0.6048j, 0.7647 -0.7178j, -0.6133 -0.7765j, -0.7793 +0.7459j, -0.6459 -0.5549j, 0.6951 +0.7144j, 0.6805 +0.8738j, 0.7308 +0.7209j, 0.6462 +0.8294j, 0.7637 +0.7509j, 0.8959 +0.7392j, 0.5972 -0.6786j, 0.7821 -0.9048j, -0.6551 -0.4961j, 0.6051 -0.9311j, -0.7387 -0.7673j, 0.6382 +0.6135j, 0.8092 +0.7609j, 0.6925 +0.4796j, -0.6559 -0.5616j, -0.7628 -0.6650j, -0.6356 +0.7229j, 0.9394 -0.5729j, 0.8136 +0.8365j, -0.6454 -0.5355j, 0.7577 +0.9170j, 0.7021 -0.8205j, 0.6823 +0.6274j, 0.4643 -0.5027j, 0.8682 +0.6071j, -0.6347 +0.7422j, 0.4291 +0.6031j, 0.4945 +0.7120j, 0.8240 -0.6165j, -0.6798 -0.7361j, -0.7555 +0.6886j, -0.9531 -0.6317j, -0.6438 -0.4445j, -0.6368 -0.5398j, 0.8315 -0.9243j, -0.9368 +0.7431j, 0.8800 -0.7121j, -0.8852 -0.7425j, 0.7593 -0.8182j, -0.4693 -0.8803j, 0.9188 +0.9034j, 0.7084 -0.5261j, 0.8852 +0.8426j, 0.-0.8496+0.4598j, -0.5449+0.6434j, -0.5283-0.8498j, -0.6768-0.6933j, 0.5350+0.5438j, -0.5282+0.6779j, 0.9811-0.6293j, -0.6632-0.9629j, 0.5562+0.5654j, 0.6952+0.6575j, 0.7480+0.6016j, -0.6517-0.6839j, 0.8807-0.8685j, 0.5361-0.6918j, 0.9448-0.6268j, -0.6957-0.6414j, -0.8411+0.6889j, 0.6039-0.7133j, -0.5519-0.5912j, -0.7018-0.8829j, 0.7172-0.7737j, -0.7991-0.5018j, -0.8824-0.7445j, 0.5705+0.6815j, 0.6446-0.4613j, 1.02450000000000-0.9032j, 0.6122+0.7668j, -0.5591+0.6209j, 0.5411-0.6284j, 0.8615+0.8274j, -0.6390-0.7778j, 0.7495-0.7395j, -0.6128 -0.5788j, 0.4300-0.6750j, 0.6417-0.6459j, -0.5839-0.5845j, -0.8871+0.7729j, 0.6069-0.6908j, 0.8101-0.7819j, 0.6638-0.6060j, -0.5811+0.9165j, -0.7021-0.7375j, -0.5038-0.5967j, 0.6796+0.8374j, -0.5743+0.6504j, -0.9330-0.7101j, -0.9377+0.7378j, -0.6903+0.6354j, 0.7066-0.8524j, -0.9812+0.5969j, 0.6026+0.6384j, 0.6148+0.8862j, -0.7670+0.6889j, -0.9084+0.9564j, 0.7796+0.6387j, 0.7939-0.8145j, -0.7605+0.8776j, -0.4931-0.8304j, 0.6904-0.9156j, 0.5026-0.5006j, -0.6567-0.5357j, 0.7619+0.6891j, 0.4209+0.6675j, 0.9877+0.8919j, 0.7151+0.8334j, -0.7630-0.5650j, -0.6239+0.8401j, 0.5917+0.8212j, -0.5401-0.6294j, -0.5847-0.9213j, -0.6967-0.5794j, -0.7524-0.8776j, -0.9658-1.06520000000000j, 0.5635-0.6117j, 0.6623-0.6408j, 0.5004+0.6777j, -0.8842-0.7329j, 0.6783+0.8337j, 0.5046+0.7029j, -0.7565+0.6234j, 0.7895+0.7648j, -0.6357-0.8682j, 0.7666-0.9389j, -0.3526-0.7940j, 0.8360+0.6078j, 0.5741-0.3820j, -0.6534+0.7313j, 0.8055-0.5353j, 0.9791+0.7153j, -0.5735-0.7516j, 0.5617-0.5593j, -0.6655-0.7002j, 0.8231+0.6983j, 0.7256+0.4341j, 0.7449+1.0143j, -0.7791-0.4976j.
[0076] extracting a digital feature of the received signal is:
[0077] 111011001000000111100011110001011111001001110100111110110101011001001101011111 010110100000001101000000110001010100101000111010010011010001110110100000011010111 0110001100000111011001000110110010110111110001011110011011011000000100000011000010010011100100000.
[0078] detected tag is:
[0079] 10110000111010111000010000000000101111101100100001010011110101100110100000101 1111110100111110101101001011011001000111100111110101001110100011111100011101111100 1000000110000101010011010010001110000101011010110110111111010010110110101100011001110100010001010.
[0080] reproducing the tag at the receiving end is:
[0081] 001101011110100111001111010000001001110001000010011101111101111001100010111010 1111001111001101111010001111110001001011001111101011111100100111111000110101010100 000000110100101011001110010001100000000010000111110001110011000110000111100110001010100010011011.
[0082] Assuming the false alarm probability is 0.1%, the corresponding maximum allowed label error is 105 bits (if the illegal end randomly generates a label, the average number of error bits is 128 bits with the real label).
[0083] and 68 bits, which is less than the tolerance, so the information is received and further processed, and the regenerated encrypted sequence is
[0084] 11000010001011000101000110101111011101110010111101000101000010110010101100101100110010010001110011101101010001110101001010011000100001010101110100100001100001101100000001101011110000101100100101000101101100001010101101111111010011101001110011010.
[0085] Detecting the received signal obtains
[0086]
[0087] Using to decrypt to obtain the decrypted symbol
[0088]
[0089]
[0090] After demodulation, the signal is obtained
[0091] 01101011010111111000001100111110100110111111011010100000111011100110010100111000001001100001110001011010011110101110110111010100110111001001111000011010101011010010101110110011000000000101000111110000111101101111001011100001110010110111111110011011101111010011101011100011111010011101100010110011110011101000100001100111101000000010011111110000100101111001111110001111011011011000110111100100010101101011000001111010101011111001110110110110111100110000010000000000001010000000000111000100000101101111010011001111.
[0092] Performance analysis: under different signal-to-noise ratios, adjust the power allocation, can achieve the maximum signal transmission efficiency, that is, the probability P of information transmission correct and authentication success sd , record
[0093] Under different signal-to-noise ratios, the maximum value of P sd and ρ is shown in Table 1:
[0094] Table 1 Maximum value of P sd and ρ under different signal-to-noise ratios
[0095] SNR (dB) 8 9 10 11 12 13 14 15 p 1.2 1.19 1.18 1.17 1.16 1.15 1.14 1.13 P sd (%)]] 1.86 17.37 53.36 83.49 96.21 99.47 99.95 99.99
[0096] The above only describes the preferred embodiments of the present application and is not intended to limit the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.
Claims
1. A new physical layer encryption and authentication collaboration security method, characterized in that, The steps are as follows: Step one: At the sender side, extract the phase feature f from the input signal, and take the phase feature f and the key k as the input of the hash function, to generate the digital tag t a = hash(f, k) and the encrypted sequence t e = hash(k, f); Step two: using the encryption sequence t e The signal is encrypted, and the encrypted signal is embedded with a digital tag to obtain the signal x sent by the sending end. Step three: the signal x sent by the sending end reaches the receiving end after transmission through the wireless channel, and the receiving end receives the signal y, wherein y=hx+n, h is the channel gain, and n is noise; Step four: At the receiving end, extract the estimate of the digital feature from the signal y and the detected detection tag Step five: using the estimate and key k to regenerate the authentication tag and decrypt the sequence and compare the authentication tag to the detection tag If the difference is greater than the tolerance, discard the signal y and go back to standby. Otherwise, the signal y passes authentication and step six is executed. Step six: decrypting using the decryption sequence The signal y is decrypted to obtain the plaintext.
2. The new physical layer encryption and authentication cooperation security method according to claim 1, characterized in that, The input signal is a 0 / 1 bit stream m, with length 2T; the input signal m is modulated into a QPSK signal at the transmitting end, represented as a complex signal s = [s1, s2,..., s T ].
3. The new physical layer encryption and authentication cooperation security method according to claim 2, characterized in that, The signal x is expressed as: x = s - (2diag{t e}-I) - diag{p2t a + p1(1-t a )}, Wherein, diag is a diagonalization function, ρ1 and ρ2 are both energy distribution coefficients, and I is a unit matrix; x e x e = s · (2diag{t e}-I).
4. The new physical layer encryption and authentication cooperation security method according to claim 3, characterized in that, extracting the estimated value of the digital feature from the signal y The method is as follows: After removing the channel gain from the received signal y, the ciphertext is obtained: Then the estimate of the digital feature is extracted from the ciphertext If the is in the first or third quadrant, Otherwise, is is the i-th element of 5. The new physical layer encryption and authentication cooperation security method according to claim 1 or 4, characterized in that, The authentication tag And decryption sequence The generation method is:
6. The new physical layer encryption and authentication cooperation security method according to claim 5, characterized in that, The authentication tag The comparison method with the detection tag is: where η is the tolerance error, To test the statistic, the authentication tag is denoted and the detection tag is denoted by a different number of bits, H1 : the signal contains the expected tag, H2: the signal does not contain the expected tag.
7. The new physical layer encryption and authentication cooperation security method according to claim 4, characterized in that, The decryption sequence is used The method for decrypting the signal y to obtain the plaintext is: The ciphertext is detected by maximum likelihood estimation and the result is: wherein denotes the encrypted signal estimate; Using the decryption sequence Estimating values for encrypted signals Decrypting to obtain: wherein denotes the QPSK signal estimate; The message estimate is obtained by demodulating the QPSK signal estimate
Citation Information
Patent Citations
Physical layer authentication method and system based on group connection between internet of things devices
CN109068284A
Non-orthogonal multiple access authentication system based on shared physical layer authentication tag
CN110381511A
Cited By
Electronic device data security interaction control system and method
CN122419765A