Symmetric key generation methods, apparatus, devices, media and products

By using random number sequences to generate symmetric keys in wireless sensor networks, the problem of insufficient key randomness in wireless sensor networks is solved, thereby improving the security and stability of the network.

CN119545338BActive Publication Date: 2025-10-31YONGJIANG LAB
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411944209.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-27
Publication Date
2025-10-31
Estimated Expiration
2044-12-27

AI Technical Summary

Technical Problem

The symmetric keys used between wireless sensors and network devices in wireless sensor networks have poor randomness, resulting in poor security and making them vulnerable to being cracked by attackers.

Method used

Network devices and wireless sensors generate more random symmetric keys by sending and receiving signals carrying random number sequences, thereby enhancing the randomness of channel eigenvalues.

Benefits of technology

It improves the security performance of wireless sensor networks, enhances the security and stability of data transmission, and reduces the difficulty for attackers to crack the keys.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119545338B_ABST
    Figure CN119545338B_ABST
Patent Text Reader

Abstract

This application provides a symmetric key generation method, apparatus, device, medium, and product. In this method, a network device sends a first signal to a wireless sensor based on a target key generation sequence, and the wireless sensor sends a second signal to the network device based on the target key generation sequence. This causes the network device to generate a first symmetric key based on the first signal, and the wireless sensor to generate a second symmetric key based on the second signal. Since the target key generation sequence is a random number sequence with strong randomness, it further enhances the channel variation between the wireless sensor and the network device. This makes the randomness of the symmetric key generated by the wireless sensor and the network device based on channel characteristic values ​​even stronger, thereby enhancing the security performance of the data transmitted between the wireless sensor and the network device and ensuring the security and stability of the entire wireless sensor network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to a symmetric key generation method, apparatus, device, medium and product. Background Technology

[0002] Wireless sensor networks consist of varying numbers of wireless sensors and network devices. These network devices can also be referred to as ingress points or aggregation points. Wireless sensors connect to network devices via wireless communication. Wireless sensors can transmit data to network devices via wireless communication. Network devices can process the data or transmit it to higher-level devices. Network devices can also send commands to wireless sensors via wireless communication.

[0003] To ensure secure communication between wireless sensors and network devices, the two devices can encrypt and decrypt data transmitted between them using symmetric keys. In existing technologies, the wireless sensor and network device send pilot signals to each other and calculate the channel characteristic value of their communication connection based on the received pilot signals. Then, they generate keys for encrypting and decrypting data based on the channel characteristic value.

[0004] However, because pilot signals are relatively simple and wireless sensors have limited mobility, the channel characteristic values ​​determined by wireless sensors and network devices based on pilot signals vary little. This makes it relatively easy for other attackers to determine the same channel characteristic values ​​based on pilot signals, thereby cracking the symmetric keys between wireless sensors and network devices, resulting in poor security performance of wireless sensor networks. Summary of the Invention

[0005] This application provides a symmetric key generation method, apparatus, device, medium, and product to solve the technical problem of poor performance of wireless sensor networks caused by the poor randomness of the symmetric keys used between wireless sensors and network devices.

[0006] A first aspect of this application provides a symmetric key generation method applied to a network device, comprising: sending a first signal to a wireless sensor according to a target key generation sequence, causing the wireless sensor to generate a first symmetric key based on the first signal, wherein the target key generation sequence is a random number sequence; receiving a second signal from the wireless sensor; the second signal being sent by the wireless sensor according to the target key generation sequence; and generating a second symmetric key for the network device based on the second signal.

[0007] A second aspect of this application provides a symmetric key generation method for a wireless sensor, comprising: sending a second signal to a network device according to a target key generation sequence, causing the network device to generate a second symmetric key according to the second signal, wherein the target key generation sequence is a random number sequence; receiving a first signal from the network device, the first signal being sent by the network device according to the target key generation sequence; and generating a first symmetric key for the wireless sensor according to the first signal.

[0008] A third aspect of this application provides a symmetric key generation apparatus for performing the symmetric key generation method provided in the first aspect of this application. The symmetric key generation apparatus includes a transmitting module for transmitting a first signal to a wireless sensor according to a target key generation sequence, causing the wireless sensor to generate a first symmetric key based on the first signal, wherein the target key generation sequence is a random number sequence; a receiving module for receiving a second signal from the wireless sensor, the second signal being transmitted by the wireless sensor according to the target key generation sequence; and a processing module for generating a second symmetric key for the network device based on the second signal.

[0009] A fourth aspect of this application provides a symmetric key generation apparatus for performing the symmetric key generation method provided in the second aspect of this application. The symmetric key generation apparatus includes a transmitting module for transmitting a second signal to a network device according to a target key generation sequence, causing the network device to generate a second symmetric key according to the second signal, wherein the target key generation sequence is a random number sequence; a receiving module for receiving a first signal from the network device, the first signal being transmitted by the network device according to the target key generation sequence; and a processing module for generating a first symmetric key for the wireless sensor according to the first signal.

[0010] A fifth aspect of this application provides an electronic device, comprising: a memory and a processor; the memory storing computer-executable instructions; the processor executing the computer-executable instructions stored in the memory, causing the processor to perform a symmetric key generation method as described in the first or second aspect of this application.

[0011] The sixth aspect of this application provides a computer-readable storage medium storing computer-executable instructions, which, when executed, implement the symmetric key generation method as described in the first or second aspect of this application.

[0012] The seventh aspect of this application provides a computer program product, including a computer program that, when executed, implements the symmetric key generation method as described in the first or second aspect of this application.

[0013] In summary, the symmetric key generation method, apparatus, device, medium, and product provided in this application involve a network device sending a first signal to a wireless sensor based on a target key generation sequence, and the wireless sensor sending a second signal to the network device based on the target key generation sequence. This enables the network device to generate a first symmetric key based on the first signal, and the wireless sensor to generate a second symmetric key based on the second signal. Since the target key generation sequence is a random number sequence, and random number sequences have stronger randomness compared to pilot signals in existing technologies, their variations are greater. Even if the mobility of wireless sensors in a wireless sensor network is poor, the channel variations between the wireless sensor and the network device can be further enhanced and amplified through the changes in the target key generation sequence. This makes the randomness of the channel feature values ​​extracted by the wireless sensor and the network device based on the mutually transmitted first and second signals stronger, thereby enhancing the randomness of the symmetric key generated based on the channel feature values. This makes the symmetric key more effective and increases the difficulty for other attackers to determine the same channel feature values ​​based on the pilot signal and crack the symmetric key between the wireless sensor and the network device. Ultimately, this enhances the security performance of the data transmitted between the wireless sensor and the network device, ensuring the security and stability of the entire wireless sensor network. Attached Figure Description

[0014] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0015] Figure 1 This is a schematic diagram illustrating the application scenario of this application;

[0016] Figure 2 A flowchart illustrating an embodiment of the symmetric key generation method provided in this application;

[0017] Figure 3 A schematic diagram illustrating the process of generating a first symmetric key using a wireless sensor, as provided in this application;

[0018] Figure 4 A schematic diagram illustrating the process of generating a second symmetric key for a network device, as provided in this application;

[0019] Figure 5 A schematic diagram illustrating the communication process between the wireless sensor and the network device provided in this application;

[0020] Figure 6 A flowchart illustrating the process of determining the target key generation sequence provided in this application;

[0021] Figure 7 A schematic diagram illustrating the mapping relationship for determining the target key sequence provided in this application;

[0022] Figure 8 A schematic diagram of the channel characteristic values ​​provided in this application;

[0023] Figure 9 A schematic diagram of an embodiment of the AI ​​model provided in this application;

[0024] Figure 10 A schematic diagram of an embodiment of the symmetric key generation apparatus provided in this application;

[0025] Figure 11 This is a schematic diagram of the structure of an electronic device provided in this application. Detailed Implementation

[0026] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0027] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a particular order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented, for example, in orders other than those illustrated or described herein. Furthermore, the terms “comprising” and “having,” and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0028] Figure 1 This is a schematic diagram illustrating the application scenario of this application. Wireless sensor networks typically include wireless sensor nodes, aggregation nodes, and management nodes, such as... Figure 1 The network device 10 shown is specifically an aggregation node, also known as an aggregation point, data ingress point, etc. An aggregation point can be a base station or a server set up within a base station.

[0029] The wireless sensor 20 can specifically be a miniature node integrating functions such as a sensor, a data processing unit, and a communication module. When a specific function is achieved, multiple wireless sensors 20 are distributed in a specific or random manner, for example, such as... Figure 1 The system shown uses N wireless sensors 20 as an example, denoted as wireless sensor A, wireless sensor B, ..., wireless sensor N. Each wireless sensor 20 is connected to the network device 10 through a network and communicates with the network device 10 based on the communication connection established between the wireless sensor 20 and the network device 10.

[0030] The wireless sensor 20 and the network device 10 can communicate via 5G or 6G. In order to ensure the security of the data transmitted over the network when the wireless sensor 20 and the network device 10 communicate, the wireless sensor 20 and the network device 10 respectively obtain the channel feature values ​​between them and generate symmetric keys based on the channel feature values. The generated symmetric keys are then used to encrypt and decrypt the data.

[0031] For example, when the physical channel technology between the wireless sensor 20 and the network device 10 is Orthogonal Frequency Division Multiplexing (OFDM), the wireless sensor 20 extracts channel feature values ​​based on the pilot signal sent by the network device 10 and generates a first symmetric key. The network device 10 then extracts channel feature values ​​based on the pilot signal sent by the wireless sensor 20 and generates a second symmetric key. Subsequently, the network device 10 uses the second symmetric key to encrypt data before sending it to the wireless sensor 20, and the wireless sensor 20 uses the first symmetric key to decrypt the received data. Similarly, the wireless sensor 20 uses the first symmetric key to encrypt data before sending it to the network device 10, and the network device 10 uses the second symmetric key to decrypt the received data.

[0032] The method described above, which extracts channel feature values ​​from pilot signals to generate a symmetric key, ensures the security of data transmitted in the network to a certain extent. However, due to the poor mobility of the wireless sensor 20 in the wireless sensor network, the channel variation between the wireless sensor 20 and the network device 10 is small, resulting in minimal variation of the pilot signals transmitted in the channel. This leads to relatively fixed channel feature values ​​extracted by the wireless sensor 20 and the network device 10 based on the pilot signals, resulting in poor randomness of the symmetric key generated based on these relatively fixed channel feature values. This makes it relatively easy for other attackers to determine the same channel feature values ​​based on the pilot signals, thereby cracking the symmetric key between the wireless sensor 20 and the network device 10. This reduces the security of the data transmitted between the wireless sensor 20 and the network device 10, ultimately affecting the security and stability of the entire wireless sensor network.

[0033] Based on this, this application provides a symmetric key generation method applicable to wireless sensor networks to increase the randomness of the symmetric key generated by the wireless sensor 20 and network device 10 based on channel characteristic values, thereby improving the security performance of the wireless sensor network. The technical solution of this application will be described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments.

[0034] Figure 2 A flowchart illustrating an embodiment of the symmetric key generation method provided in this application is shown below. Figure 2 The method shown can be applied to, for example Figure 1 In the scenario shown, this is performed by network device 10 and wireless sensor 20. Specifically, as... Figure 2 The symmetric key generation methods shown include:

[0035] S100: Network device 10 and wireless sensor 20 respectively determine the target key generation sequence. In this embodiment, the target key generation sequence is a sequence of several bits, specifically a sequence of several bits of random numbers (payload).

[0036] In one embodiment, the target key generation sequence may be specified by the network device 10 or the wireless sensor 20, may be preset, or may be determined by the network device 10 or the wireless sensor 20 from a plurality of preset key generation sequences. This application also provides a method for the network device 10 to determine the target key generation sequence based on an AI model, as detailed below. Figure 7 The example shown.

[0037] S201: Network device 10 generates a sequence based on the target key determined in S100 and sends a first signal to wireless sensor 20.

[0038] In one embodiment, the network device 10 modulates the amplitude, phase, frequency and other parameters of the carrier signal according to the target key generation sequence to obtain a first signal carrying the target key generation sequence, and sends the first signal to the wireless sensor 20 through the communication connection between the network device 10 and the wireless sensor 20.

[0039] S202: Wireless sensor 20 generates a sequence based on the target key determined in S100 and sends a second signal to network device 10.

[0040] In one embodiment, the wireless sensor 20 modulates the amplitude, phase, frequency and other parameters of the carrier signal according to the target key generation sequence to obtain a second signal carrying the target key generation sequence, and sends the second signal to the network device 10 through the communication connection between the wireless sensor 20 and the network device 10.

[0041] S203: Wireless sensor 20 generates a first symmetric key based on the first signal received in S201.

[0042] Specifically, Figure 3 A flowchart illustrating the process of generating a first symmetric key using a wireless sensor, as provided in this application, is shown below. Figure 3 A specific implementation of S203 is shown, wherein after the wireless sensor 20 receives the first signal, it can analyze the first signal in S2031 to calculate the first channel feature value of the communication channel between the wireless sensor 20 and the network device 10. Then, in S2032, a first symmetric key is generated based on the first channel feature value. This application emphasizes that the channel feature value extracted from the signal generated based on the target key symmetric sequence has stronger randomness; therefore, the method of generating the first symmetric key based on the first channel feature value in S2032 is not limited, and reference can be made to the symmetric key generation methods in related technologies, which will not be elaborated here.

[0043] In one embodiment, the first channel feature value includes channel parameters of the communication channel between the wireless sensor 20 and the network device 10, signal parameters of the signal transmitted through the communication channel, etc. Since the network device 10 and the wireless sensor 20 need to determine the first channel feature value separately and generate symmetric keys based on the first channel feature value, the first channel feature value is specifically determined by both the network device 10 and the wireless sensor 20 and is identical. For example, the first channel feature value can be at least one of Received Signal Strength (RSS), Channel State Information (CSI), or Carrier Frequency Offset (CFO). The network device 10 can determine the first channel feature value based on the communication channel or the signal transmitted through the communication channel. Simultaneously, the wireless sensor 20 can also determine the first channel feature value based on the communication channel or the signal transmitted through the communication channel. Due to the symmetry of the channel between the wireless sensor 20 and the network device 10, the first channel feature values ​​determined by the network device 10 and the wireless sensor 20 are also identical.

[0044] S204: Network device 10 generates a second symmetric key based on the second signal received in S202.

[0045] Specifically, Figure 4 A flowchart illustrating the process of generating a second symmetric key for a network device provided in this application is shown below. Figure 4 A specific implementation of S204 is shown, wherein after the network device 10 receives the second signal, it can analyze the second signal in S2041 to calculate the first channel feature value of the communication channel between the network device 10 and the wireless sensor 20. Then, in S2042, a second symmetric key is generated based on the first channel feature value. This application emphasizes that the channel feature value extracted from the signal generated based on the target key symmetric sequence has stronger randomness; therefore, the method of generating the second symmetric key based on the first channel feature value in S2042 is not limited, and reference can be made to the symmetric key generation methods in related technologies, which will not be elaborated here.

[0046] In one embodiment, the network device 10 and the wireless sensor 20 provided in this application include a pilot channel and a data channel, etc. The pilot channel can be used to transmit pilot signals, and the data channel can be used to transmit data signals. The network device 10 and the wireless sensor 20 can then use the data signal testing capability provided on the data channel to test relevant parameters based on the data signals transmitted on the data channel, thereby obtaining the first channel characteristics. In other words, the data channel between the network device 10 and the wireless sensor 20 provided in this application provides the ability to test data signals, which can be specifically implemented through the design of the underlying devices between the network device 10 and the wireless sensor 20.

[0047] In summary, in the symmetric key generation method provided in this embodiment, network device 10 sends a first signal to wireless sensor 20 according to a target key generation sequence, and wireless sensor 20 sends a second signal to network device 10 according to the target key generation sequence, so that network device 10 generates a first symmetric key according to the first signal and wireless sensor 20 generates a second symmetric key according to the second signal. Notably, the target key generation sequence is a random number sequence, and random number sequences have stronger randomness and greater variation compared to pilot signals in existing technologies. Even if the mobility of the wireless sensor 20 in the wireless sensor network is poor, the channel changes between the wireless sensor 20 and the network device 10 can be further enhanced and amplified by the change of the target key generation sequence. This makes the randomness of the channel feature values ​​extracted by the wireless sensor 20 and the network device 10 based on the first and second signals they send to each other stronger, thereby enhancing the randomness of the symmetric key generated based on the channel feature values. This makes the symmetric key more effective and increases the difficulty for other attackers to determine the same channel feature values ​​based on the pilot signal and crack the symmetric key between the wireless sensor 20 and the network device 10. In this way, the security performance of the data transmitted between the wireless sensor 20 and the network device 10 is enhanced, ensuring the security and stability of the entire wireless sensor network.

[0048] Meanwhile, the symmetric key generation method provided in this application does not make significant changes to the communication method and encryption method of the wireless sensor 20 and the network device 10 in the prior art. It only adds related processing of random numbers, which makes the embodiments of this application have the characteristics of low cost and easy implementation, and is more conducive to the application and promotion of the embodiments of this application.

[0049] Furthermore, such as Figure 2 As shown, after the wireless sensor 20 generates the first symmetric key and the network device 10 generates the second symmetric key, in S300, the wireless sensor 20 and the network device 10 can communicate based on the first symmetric key and the second symmetric key.

[0050] In one embodiment, Figure 5 The schematic diagram illustrating the communication process between the wireless sensor and the network device provided in this application shows... Figure 2 The embodiment shown illustrates one specific implementation of S300.

[0051] Based on the symmetry of the channel between the wireless sensor 20 and the network device 10, the first channel feature determined by the wireless sensor 20 based on the first signal is the same as the first channel feature determined by the network device 10 based on the second signal. This ensures that the first symmetric key generated by the wireless sensor 20 is also the same as the second symmetric key generated by the network device 10. Only with the same symmetric key can encrypted communication be achieved between the wireless sensor 20 and the network device 10. Therefore, as... Figure 5 As shown, after the wireless sensor 20 generates a first symmetric key and the network device 10 generates a second symmetric key, they exchange symmetric keys for key verification. Specifically, in S301, the network device 10 sends the second symmetric key it generated in S204 to the wireless sensor 20, and in S302, the wireless sensor 20 sends the first symmetric key it generated in S203 to the network device 10.

[0052] Subsequently, network device 10 verifies the two symmetric keys in S303. When network device 10 determines that the second symmetric key is the same as the first symmetric key, the verification is successful, and network device 10 and wireless sensor 20 can communicate using the first and second symmetric keys. Specifically, network device 10 encrypts data using the second symmetric key and sends it to wireless sensor 20, while wireless sensor 20 decrypts the received data using the first symmetric key. Correspondingly, wireless sensor 20 encrypts data using the first symmetric key and sends it to network device 10, while network device 10 decrypts the received data using the second symmetric key.

[0053] When network device 10 determines that the second symmetric key is different from the first symmetric key, it indicates that the verification has failed. In this case, network device 10 and wireless sensor 20 need to regenerate the symmetric key. Network device 10 can then return to the previous state. Figure 2 As shown in S100, the target key generation sequence is redefined, and the following is re-executed: Figure 2 The method shown enables network device 10 to generate a new second symmetric key and wireless sensor 20 to generate a new first symmetric key.

[0054] It should be noted that, as Figure 5 In the example shown, the network device 10 performs the verification of the first symmetric key and the second symmetric key as an example. In other possible implementations, the wireless sensor 20 may also perform the verification of the first symmetric key and the second symmetric key to improve the flexibility of the settings of the embodiments of this application.

[0055] In summary, in the symmetric key generation method provided in this embodiment, after the wireless sensor 20 generates the first symmetric key and the network device 10 generates the second symmetric key, they exchange symmetric keys for key verification. Communication only occurs after successful verification. If verification fails, the symmetric key needs to be regenerated, thereby ensuring the validity of the generated symmetric key and preventing the wireless sensor 20 and network device 10 from being unable to communicate due to key issues. This, in turn, ensures the stability and reliability of the wireless sensor network.

[0056] Furthermore, this application also provides a method for determining a target key generation sequence by a network device 10. For example, Figure 6 A flowchart illustrating the process of determining the target key generation sequence provided in this application is shown below. Figure 6 It shows Figure 2 The embodiment shown is one specific implementation of S100.

[0057] Specifically, such as Figure 6 As shown, network device 10 first determines the second channel characteristic value of the communication channel between network device 10 and wireless sensor 20 through S101. Specifically, when the physical channel technology between network device 10 and wireless sensor 20 is OFDM, network device 10 receives the pilot signal sent by wireless sensor 20 and calculates and extracts the second channel characteristic value based on the pilot signal.

[0058] In one embodiment, the second channel characteristic value includes at least one of RSS, CSI, or CFO. The network device 10 can obtain the second channel characteristic based on the pilot signal transmitted on the pilot channel by utilizing the testing capability of the pilot signal provided on the pilot channel.

[0059] Subsequently, network device 10, through S102, determines the target key generation sequence corresponding to the second channel feature value from a preset set of multiple key generation sequences based on the second channel feature value determined in S101.

[0060] In one embodiment, Figure 7 This is a schematic diagram illustrating the mapping relationship for determining the target key sequence provided in this application. Network device 10 can store, for example... Figure 7 The mapping relationship shown includes multiple second channel feature values, denoted as second channel feature value-1, second channel feature value-2, ..., second channel feature value-N. Each second channel feature value corresponds to one of multiple key generation sequences. For example, second channel feature value-1 corresponds to key generation sequence-1, second channel feature value-2 corresponds to key generation sequence-2, ..., second channel feature value-N corresponds to key generation sequence-N.

[0061] Therefore, after determining the second channel characteristic value, network device 10 can combine the currently determined second channel characteristic value with... Figure 7The mapping relationship shown determines the key generation sequence corresponding to the current second channel feature value as the target key generation sequence. That is, when communicating with the wireless sensor 20, the network device 10 supports the use of multiple different key generation sequences, and each key generation sequence is a random number sequence. The network device 10 can store multiple different key generation sequences. In S102, the network device 10 determines one of the candidate key generation sequences as the target key generation sequence based on the current second channel feature value, and subsequently generates a symmetric key based only on this single target key generation sequence.

[0062] like Figure 6 As shown, once network device 10 determines the target key generation sequence, it can send the target key generation sequence to wireless sensor 20, enabling wireless sensor 20 to receive and determine the target key generation sequence. Alternatively, network device 10 can also send indication information to wireless sensor 20. After receiving the indication information, wireless sensor 20 determines the target key generation sequence from multiple key generation sequences based on the indication information. It is understood that wireless sensor 20 can also store multiple key generation sequences and perform subsequent key generation and other processing based on the target key generation sequence determined by network device 10.

[0063] It should be noted that, as Figure 6 In the example shown, network device 10 determines the target key generation sequence, a method that leverages the greater computing power of network device 10. In other possible implementations, the target key generation sequence can also be determined by wireless sensor 20, offering greater flexibility.

[0064] In summary, in the symmetric key generation method provided in this embodiment, the network device 10 can more flexibly determine the target key generation sequence from multiple different key generation sequences based on the current channel characteristic value, making the determined target key generation sequence more suitable for the current channel, ensuring the effectiveness of subsequent generation based on the target key generation sequence, and the network device 10 can automatically determine the target key generation sequence without user configuration, which also improves the intelligence level of the network device 10.

[0065] Furthermore, in the above embodiments, such as Figure 7The mapping relationship shown can be obtained through the following steps: First, acquire multiple second channel feature values, and then combine these multiple channel feature values ​​sequentially with each key generation sequence in a plurality of key generation sequences. Next, input all combinations sequentially into the AI ​​model, and obtain the key quality information of each second channel feature value output by the AI ​​model in combination with the multiple key generation sequences. Subsequently, the key generation sequence whose key quality information meets preset conditions among the multiple key generation sequences and is used as the target key generation sequence corresponding to the second feature value in the mapping relationship. The above steps can be performed by electronic devices with relevant data processing capabilities, such as computers, workstations, servers, etc., or by network device 10. The AI ​​model described above is further explained below with reference to the accompanying drawings.

[0066] Specifically, Figure 8 This is a schematic diagram of the channel characteristic value provided in this application. When the wireless sensor 20 sends a pilot signal to the network device 10, after transmission through the channel h(t), the pilot channel received by the network device 10 carries the channel characteristic value. The network device 10 can record the second channel characteristic value based on the extreme parameters such as RSS, CSI or CFO of the pilot signal, in accordance with the manner described in the aforementioned embodiments of this application.

[0067] Subsequently, it can be determined that... Figure 8 The different second channel feature values ​​shown are, for example, the first second channel feature value is denoted as RSS_1, CSI_1, CFO_1, the second second channel feature value is denoted as RSS_2, CSI_2, CFO_2, and so on, for a total of v second channel feature values.

[0068] Subsequently, each second channel feature value is combined with multiple different key generation sequences. For example, assuming that network device 10 supports n key generation sequences, denoted as n1, n2, ..., nn, the first second channel feature value is combined with each of the n key generation sequences to obtain RSS_1, CSI_1, CFO_1, n1, RSS_1, CSI_1, CFO_1, n2, ..., RSS_1, CSI_1, CFO_1, nn. The second second channel feature value is combined with each of the n key generation sequences to obtain RSS_2, CSI_2, CFO_2, n1, RSS_2, CSI_2, CFO_2, n2, ..., RSS_2, CSI_2, CFO_2, nn, and so on.

[0069] Then, each of the above combinations is input into the AI ​​model. Figure 9 A schematic diagram of an embodiment of the AI ​​model provided in this application, as shown below. Figure 9As shown, when all combinations are sequentially input into AI model C, AI model C can output the key quality information of each second channel feature value combined with different key generation sequences. For example, for the first second channel feature value, there are n key quality information X1-1, X1-2...X1-n combined with n key generation sequences respectively. Correspondingly, for the second second channel feature value, there are n key quality information X2-1, X2-2...X2-n combined with n key generation sequences respectively, and so on.

[0070] In one embodiment, the random number sequence can be generated according to a certain random number generation algorithm. For example, different random number sequences can be generated as key generation sequences by generating a bitstream file with maximum randomness. For example, the generated random number sequence can be a series of identical 1-n bits, where the length of the smallest data unit is k. This can be achieved by randomly changing the next k bits to either all 0 or all 1, thus generating a bit sequence of a certain length as the key generation sequence. Another example is that the generated random number sequence can be generated by flipping each data unit with a certain probability. The probability distribution function includes a Poisson distribution or a normal distribution. By changing the parameters of the probability distribution function, different random number sequences can be obtained as key generation sequences. The probability distribution function can be a log-normal distribution, a Bernoulli distribution, an alpha distribution, etc., and this application does not limit this.

[0071] Finally, based on the n key quality information X1-1, X1-2...X1-n output by AI model C, key quality is evaluated to determine a target key generation sequence that meets preset conditions from the n key generation sequences. For example, for the first second channel feature value and the n key generation sequences, the n key quality information X1-1, X1-2...X1-n represent the probability information of each key generation sequence. Then, the key generation sequence with the highest probability information can be determined as the target key generation sequence. For example, if the first key generation sequence determined by the first second channel feature value has the highest probability information X1-1, then the target key generation sequence with the first second channel feature value RSS_1, CSI_1, and CFO_1 is determined as the first among the n key generation sequences, and the correspondence between the first second channel feature value and the first key generation sequence is added to the mapping relationship. Following the same method, the correspondence between each of the n second channel feature values ​​and one target key generation sequence among the n key generation sequences can be obtained, ultimately resulting in... Figure 7 The mapping relationship is shown.

[0072] The quality of the key generation sequence is judged based on its randomness; that is, the higher the randomness of a key generation sequence under a channel characteristic value, the higher its quality; conversely, the lower the randomness of a key generation sequence under a channel characteristic value, the lower its quality. In one embodiment, supervised training can be used during the training of the AI ​​model. For example, if the AI ​​model outputs the probability information of each key generation sequence, the quality of the probability information of each key generation sequence can be labeled, and the labeled content can be fed back into the AI ​​model. This allows the AI ​​model to obtain more accurate output results through feedback training, thereby more effectively determining the best-quality key generation sequence under each different channel environment as the target key generation sequence.

[0073] In summary, the symmetric key generation method provided in this embodiment obtains the target key generation sequence used under different second channel feature values ​​through AI model training, thereby ensuring that the target key generation sequence determined based on the mapping relationship is more suitable for the current channel and has higher randomness in the current channel environment, thus ensuring the effectiveness of subsequent target key generation sequences.

[0074] In the foregoing embodiments of this application, the symmetric key generation method provided by the embodiments of this application has been described. To implement the symmetric key generation method provided by the embodiments of this application, the source network device 10 and the wireless sensor 20, as the executing entities, may include hardware structures and / or software modules, implementing the above-mentioned symmetric key generation methods in the form of hardware structures, software modules, or a combination of hardware structures and software modules. Whether a method or step in the above-mentioned symmetric key generation method is executed in the form of hardware structures, software modules, or a combination of hardware structures and software modules depends on the specific application and design constraints of the technical solution.

[0075] For example, Figure 10 A schematic diagram of an embodiment of the symmetric key generation apparatus provided in this application is shown below. Figure 10 The symmetric key generation apparatus 100 shown can be used to execute the symmetric key generation method provided in any of the foregoing embodiments of this application. Specifically, the symmetric key generation apparatus 100 provided in this embodiment includes: a receiving module 101, a processing module 102, and a sending module 103.

[0076] When Figure 10When the symmetric key generation apparatus 100 shown executes the symmetric key generation method performed by the network device 10, the sending module 103 is used to send a first signal to the wireless sensor according to the target key generation sequence, so that the wireless sensor generates a first symmetric key based on the first signal. The receiving module 101 is used to receive a second signal from the wireless sensor; the processing module 102 is used to generate a second symmetric key for the network device based on the second signal.

[0077] When Figure 10 When the symmetric key generation device 100 shown executes the symmetric key generation method performed by the wireless sensor 20, the sending module 103 is used to send a second signal to the network device according to the target key generation sequence, so that the network device generates a second symmetric key according to the second signal. The receiving module 101 is used to receive a first signal from the network device. The processing module 102 is used to generate a first symmetric key for the wireless sensor according to the first signal.

[0078] The specific implementation method and principle of the symmetric key generation device 100 of the above database are described in the aforementioned symmetric key generation method, and will not be repeated here.

[0079] It should be noted that the division of the various modules in the above device is merely a logical functional division. In actual implementation, they can be fully or partially integrated into a single physical entity, or they can be physically separated. Furthermore, these modules can be implemented entirely in software via processing element calls; they can be fully implemented in hardware; or some modules can be implemented by processing element calls to software, while others are implemented in hardware. For example, a processing module can be a separate processing element, or it can be integrated into a chip within the above device. Alternatively, it can be stored as program code in the device's memory, and called and executed by a processing element of the device. The implementation of other modules is similar. Moreover, these modules can be fully or partially integrated together, or they can be implemented independently. The processing element mentioned here can be an integrated circuit with signal processing capabilities. In the implementation process, each step of the above method or each of the above modules can be completed through integrated logic circuits in the hardware of the processor element or through software instructions.

[0080] For example, these modules can be one or more integrated circuits configured to implement the above methods, such as one or more application-specific integrated circuits (ASICs), one or more digital signal processors (DSPs), or one or more field-programmable gate arrays (FPGAs). As another example, when a module is implemented using processing element scheduler code, the processing element can be a general-purpose processor, such as a central processing unit (CPU) or other processor capable of calling program code. Furthermore, these modules can be integrated together to implement a system-on-a-chip (SOC).

[0081] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state disk (SSD)).

[0082] For example, Figure 11 A schematic diagram of the structure of an electronic device provided in this application, such as... Figure 11 The electronic device shown can be used to perform the symmetric key generation method as illustrated in any of the foregoing embodiments of this application. In one embodiment, as... Figure 11The illustrated electronic device 2000 includes one or more processors 2001 and a memory 2002; wherein the memory 2002 is used to store computer-executable instructions, and the processor 2001 can execute the computer-executable instructions stored in the memory 2002. When the computer-executable instructions are executed by the processor 2001, the processor 2001 implements the symmetric key generation method executed by the network device 10 as in any of the foregoing embodiments of this application; or, when the computer-executable instructions are executed by the processor 2001, the processor 2001 implements the symmetric key generation method executed by the wireless sensor 20 as in any of the foregoing embodiments of this application.

[0083] In one embodiment, such as Figure 11 The electronic device 2000 shown also includes a communication interface 2003, through which the processor 2001 can communicate with other devices, such as transmitting a first signal and a second signal through the communication interface 2003.

[0084] This application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed, can be used to implement any of the symmetric key generation methods described in the foregoing embodiments of this application.

[0085] This application also provides a chip for executing instructions, the chip being used to execute any of the symmetric key generation methods described above in this application.

[0086] This application also provides a computer program product, including a computer program that, when executed, implements any of the symmetric key generation methods described above.

[0087] The methods provided in the above embodiments can be implemented, in whole or in part, by software, hardware, firmware, or any combination thereof. When implemented in software, they can be implemented, in whole or in part, in the form of a computer program product. This computer program product may include one or more computer instructions. When these computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium may be any available medium accessible to a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium may be a magnetic medium (e.g., floppy disk, hard disk, magnetic disk), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state disk (SSD)).

[0088] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0089] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative. For instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the shown or discussed mutual couplings, direct couplings, or communication connections may be through some interfaces; indirect couplings or communication connections between devices or units may be electrical, mechanical, or other forms. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units; they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0090] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. If this function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, or part of it, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory, random access memory, magnetic disks, or optical disks.

[0091] Furthermore, in this application, firstly, the indication includes explicit indication (also known as direct indication) and implicit indication (also known as indirect indication). Explicit indication information A refers to including information A; implicit indication information A refers to indicating information A through the correspondence between information A and information B, and direct indication information B. The correspondence between information A and information B can be predefined, pre-stored, pre-burned, or pre-configured; or it can refer to indicating information A through information B and preset rules. Secondly, information C is used to determine information D, including determining information D based solely on information C, and determining it based on information C and other information. Furthermore, information C can also be used to determine information D indirectly, for example, information D is determined based on information E, and information E is determined based on information C. Third, "at least one" means one or more, while "more than one" means two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can mean: A alone, A and B simultaneously, or B alone, where A and B can be singular or plural. The character " / " generally indicates an "or" relationship between the preceding and following related objects, but it does not exclude the possibility of an "and" relationship; the specific meaning can be understood in context. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can mean: a, b, c; a and b; a and c; b and c; or a and b and c. Here, a, b, and c can be single or multiple.

[0092] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.

Claims

1. A symmetric key generation method, applied to the generation of symmetric keys for network devices and wireless sensors, characterized in that, The method is applied to the network device, and the key generation method includes: Based on the pilot signal transmitted by the wireless sensor, a second channel characteristic value of the communication channel between the network device and the wireless sensor is calculated. The second channel characteristic value includes at least one of the following: Received Signal Strength (RSS), Channel State Information (CSI), or Carrier Frequency Offset (CFO). Based on the second channel feature value, a target key generation sequence corresponding to the second channel feature value is determined from a plurality of preset key generation sequences, wherein the plurality of key generation sequences are all random number sequences; A first signal is sent to the wireless sensor according to the target key generation sequence, so that the wireless sensor generates a first symmetric key for the wireless sensor according to the first signal, wherein the target key generation sequence is a random number sequence; Receive a second signal from the wireless sensor; the second signal is a sequence generated and sent by the wireless sensor according to the target key. Based on the second signal, a second symmetric key for the network device is generated.

2. The method according to claim 1, characterized in that, The step of generating the second symmetric key for the network device based on the second signal includes: Based on the second signal, calculate a first channel characteristic value of the communication channel between the network device and the wireless sensor; The second symmetric key is generated based on the first channel feature value.

3. The method according to claim 1, characterized in that, The step of determining the target key generation sequence corresponding to the second channel feature value from a preset plurality of key generation sequences based on the second channel feature value includes: Based on the second channel feature value and the mapping relationship, the target key generation sequence corresponding to the second channel feature value is determined, wherein the mapping relationship includes multiple second channel feature values ​​and a correspondence between each second channel feature value and one of the multiple key generation sequences of the target key generation sequence.

4. The method according to claim 3, characterized in that, The mapping relationship is obtained through the following steps: Each second channel feature value is sequentially combined with each key generation sequence in a plurality of key generation sequences, and all combinations are sequentially input into the AI ​​model. The key quality information of each second channel feature value output by the AI ​​model and the plurality of key generation sequences is then obtained. Each second channel feature value output by the AI ​​model and the key generation sequence whose key quality information in the plurality of key generation sequences meets the preset conditions are taken as the target key generation sequence corresponding to the second channel feature value in the mapping relationship.

5. The method according to claim 1, characterized in that, The step of generating a sequence based on the target key and sending a first signal to the wireless sensor includes: Generate a sequence-modulated carrier signal based on the target key, and generate the first signal; The first signal is sent to the wireless sensor.

6. The method according to claim 1, characterized in that, After determining the target key generation sequence from a set of preset key generation sequences, the method further includes: The target key generation sequence is sent to the wireless sensor; Alternatively, an instruction message may be sent to the wireless sensor, causing the wireless sensor to determine the target key generation sequence from the plurality of key generation sequences based on the instruction message.

7. The method according to claim 2, characterized in that, After generating the second symmetric key based on the first channel feature value, the method further includes: Receive the first symmetric key sent by the wireless sensor; When the second symmetric key is the same as the first symmetric key, the first symmetric key is used to communicate with the wireless sensor. If the second symmetric key is different from the first symmetric key, the second symmetric key is regenerated.

8. The method according to claim 2, characterized in that, The first channel characteristic value includes at least one channel parameter or signal parameter that is the same as the signals transmitted by the network device and the wireless sensor through the communication channel.

9. A symmetric key generation method, applied to wireless sensors and network devices for generating symmetric keys, characterized in that, The method is applied to the wireless sensor, and the key generation method includes: The system receives a target key generation sequence sent by the network device, or receives an indication message sent by the network device and determines the target key generation sequence from multiple key generation sequences according to the indication message. The target key generation sequence is a target key generation sequence corresponding to the second channel characteristic value, determined by the network device from multiple preset key generation sequences based on the second channel characteristic value calculated by the network device according to the pilot signal sent by the wireless sensor. The second channel characteristic value includes at least one of: Received Signal Strength (RSS), Channel State Information (CSI), or Carrier Frequency Offset (CFO). All multiple key generation sequences are random number sequences. A second signal is sent to the network device according to the target key generation sequence, so that the network device generates a second symmetric key according to the second signal, wherein the target key generation sequence is a random number sequence; Receive a first signal from the network device, the first signal being sent by the network device based on a sequence generated by the target key; Based on the first signal, a first symmetric key for the wireless sensor is generated.

10. The method according to claim 9, characterized in that, The step of generating the first symmetric key for the wireless sensor based on the first signal includes: Based on the first signal, calculate the first channel characteristic value of the communication channel between the wireless sensor and the network device; The second symmetric key is generated based on the first channel feature value.

11. The method according to claim 9, characterized in that, The step of generating a sequence based on the target key and sending a second signal to the network device includes: Generate a sequence-modulated carrier signal based on the target key, and then generate the second signal; The second signal is sent to the network device.

12. The method according to claim 9, characterized in that, After generating the first symmetric key based on the first signal, the method further includes: Send the first symmetric key to the network device.

13. The method according to claim 10, characterized in that, The first channel characteristic value includes at least one channel parameter or signal parameter that is the same as the signals transmitted by the network device and the wireless sensor through the communication channel.

14. A symmetric key generation device, characterized in that, include: A transmitting module is configured to transmit a first signal to a wireless sensor according to a target key generation sequence, so that the wireless sensor generates a first symmetric key for the wireless sensor according to the first signal, wherein the target key generation sequence is a random number sequence; A receiving module is configured to receive a second signal from the wireless sensor; the second signal is a sequence generated and transmitted by the wireless sensor based on the target key. The processing module is configured to generate a second symmetric key for the network device based on the second signal; The processing module is further configured to calculate a second channel characteristic value of the communication channel between the network device and the wireless sensor based on the pilot signal sent by the wireless sensor, and to determine a target key generation sequence corresponding to the second channel characteristic value from a plurality of preset key generation sequences based on the second channel characteristic value, wherein the second channel characteristic value includes at least one of received signal strength RSS, channel state information CSI, or carrier frequency offset CFO, and the plurality of key generation sequences are all random number sequences.

15. A symmetric key generation device, characterized in that, include: A sending module is configured to send a second signal to a network device based on a target key generation sequence, so that the network device generates a second symmetric key based on the second signal, wherein the target key generation sequence is a random number sequence; A receiving module is configured to receive a first signal from the network device, wherein the first signal is generated and sent by the network device according to the target key; The processing module is used to generate a first symmetric key for the wireless sensor based on the first signal; The receiving module is further configured to receive the target key generation sequence sent by the network device, or to receive indication information sent by the network device. The processing module determines the target key generation sequence from multiple key generation sequences according to the indication information. The target key generation sequence is a target key generation sequence corresponding to the second channel feature value determined by the network device from multiple preset key generation sequences based on the second channel feature value calculated by the network device based on the pilot signal sent by the wireless sensor, and based on the second channel feature value. The second channel feature value includes at least one of received signal strength RSS, channel state information CSI, or carrier frequency offset CFO. The multiple key generation sequences are all random number sequences.

16. An electronic device, characterized in that, include: Memory and processor; The memory stores computer-executable instructions; The processor executes computer-executable instructions stored in the memory, causing the processor to perform the symmetric key generation method as described in any one of claims 1-13.

17. A computer-readable storage medium, characterized in that, The device stores computer-executable instructions that, when executed, implement the symmetric key generation method as described in any one of claims 1-13.

18. A computer program product, characterized in that, It includes a computer program that, when executed, implements the symmetric key generation method as described in any one of claims 1-13.

Citation Information

Patent Citations

  • Pilot frequency sequence generation method and system

    CN102238116A

  • Secret key generation method and data processing method, device and system based on secret key generation method

    CN114513779A