Physical layer group key generation and distribution method, system and device for star-shaped Internet of Things, and medium
By using channel feature extraction and fuzzy extractor calculation methods in the star-type Internet of Things, the problem of inefficient key generation in the prior art is solved, and more efficient key generation and distribution is achieved, reducing communication overhead.
Patent Information
- Application Number
- CN202411386649.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-30
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2044-09-30
AI Technical Summary
Existing paired key generation or group key generation has problems with inefficiency, especially in terms of long-distance transmission and group key generation efficiency.
The physical layer group key generation and distribution method for star-type Internet of Things is used to generate and distribute random keys through channel feature extraction, quantization and fuzzy extractor calculations between the central node and the edge node in the star-type network structure.
It significantly improves the efficiency of key generation and time overhead during communication, reduces the number of key negotiations, and avoids the increase in key exchange overhead in traditional methods.
Smart Images

Figure FT_1 
Figure FT_2 
Figure FT_3
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of communication security and relates to a physical layer group key generation and distribution method, system, device and medium for star-shaped Internet of Things. Background Art
[0002] There are two common schemes for IoT encryption: one is based on the traditional encryption method, that is, the communicating parties obtain the key from the Key Distribution Center (KDC), and the two parties use the other party's public key to encrypt the plaintext and use their own private key to decrypt the ciphertext to achieve information exchange. Obviously, the traditional scheme relies on a trusted third party to manage the key and perform authentication. However, in a large number of IoT scenarios, such as wireless networks with wide coverage, there is generally no trusted third party. The other is Physical Layer-based Secret Key Generation (PLSKG), which is a secure key generation technology based on the physical characteristics of the wireless channel. It has the characteristics of low communication overhead, low hardware requirements, and no reliance on mathematical problems. PLSKG uses channel changes to generate shared keys between legitimate nodes (such as Alice and Bob). For this technology, even if there is an eavesdropping node (such as Eve) listening, Eve cannot extract the same key as the legitimate node because the Eve channel is not sufficiently correlated with the channel between Alice and Bob.
[0003] Although the general PLSKG method can securely generate pairwise keys between communicating parties, there are two challenges: one is the low transmission rate during long-distance transmission, and the other is the low efficiency of group key generation. In view of these two challenges, it is very necessary to use a group key generation and distribution method with higher key generation efficiency and lower time overhead. Summary of the invention
[0004] The purpose of the present invention is to provide a physical layer group key generation and distribution method, system, device and medium for star-shaped Internet of Things, which solves the defect of low efficiency of existing pairwise key generation or group key generation.
[0005] In order to achieve the above object, the technical solution adopted by the present invention is: The present invention provides a physical layer group key generation and distribution method for a star-shaped Internet of Things, based on a star network structure, which includes a central node and N edge nodes, and includes the following steps: Each edge node sends a detection signal to the central node, and the detection signal is a device ID number as tag data; The central node extracts and quantizes the features of each received detection signal to obtain the corresponding quantized feature matrix on the central node side; The obtained quantized feature matrix corresponding to the central node side is input into the fuzzy extractor to generate a vector containing a random key and a marked auxiliary data; Combining the labeled auxiliary data vector corresponding to each detection signal with the corresponding labeled data to form a labeled auxiliary data matrix; Broadcast the obtained labeled auxiliary data matrix to each edge node; Each edge node extracts and quantizes the received detection signal to obtain the quantized feature vector corresponding to the edge node side; The obtained labeled auxiliary data matrix and the quantized feature vector corresponding to the edge node side are used as the input of the fuzzy extractor to generate the binary key corresponding to the edge node side; The binary key corresponding to the edge node side is verified, and the key distribution is completed if the verification succeeds.
[0006] Preferably, the central node extracts and quantizes each received detection signal to obtain a quantized feature matrix corresponding to the central node side. The specific method is: Extracting a channel feature vector corresponding to each detection signal; Each channel feature vector obtained is quantized using a median quantization method, and the obtained quantization results are used to form a quantized feature matrix.
[0007] Preferably, the obtained quantized feature matrix corresponding to the central node side is input into the fuzzy extractor to generate a vector containing a random key and a tag auxiliary data. The specific method is: The quantized feature matrix is used as the input of the fuzzy extractor Gen algorithm to obtain a binary random key, salt value and mask of a specified length corresponding to each quantized feature vector in the quantized feature matrix; The random key with verification is generated by splicing multiple 0s from the binary random key; Extracting a channel feature vector corresponding to each quantized feature vector in the quantized feature matrix; Hash the obtained channel feature vector to generate a binary summary vector; Perform an XOR operation on the obtained binary summary vector and the random key containing the check to generate a binary ciphertext vector; The obtained binary ciphertext vector, salt value vector and mask vector are generated to obtain a marked auxiliary data vector.
[0008] Preferably, each edge node extracts and quantizes the received detection signal to obtain a quantized feature vector corresponding to the edge node side. The specific method is: Extracting a channel feature vector corresponding to the detection signal; The obtained channel feature vector is quantized using a median quantization method to obtain a quantized feature vector.
[0009] Preferably, the obtained label auxiliary data matrix and the quantized feature matrix corresponding to the edge node side are used as the input of the fuzzy extractor to generate the binary key corresponding to the edge node side, and the specific method is: The obtained quantized feature vector and the labeled auxiliary data matrix are used as the input of the fuzzy extractor Rep algorithm to obtain the labeled auxiliary data vector corresponding to the edge node; Obtain a binary ciphertext vector, a salt value vector and a mask vector according to the obtained marked auxiliary data vector; Performing a bitwise AND operation on the obtained quantized feature vector and the mask vector to obtain a binary vector; The obtained binary vector is hashed to obtain a binary summary vector; The obtained binary summary vector is XORed with the binary ciphertext vector to obtain a binary key vector.
[0010] A physical layer group key generation and distribution system for a star-shaped Internet of Things is based on a star-shaped network structure, which includes a central node and N edge nodes, including: The edge node signal sending unit is used for each edge node to send a detection signal to the central node, wherein the detection signal is a device ID number as marking data; The signal processing unit at the central node side is used to extract and quantize the features of each received detection signal to obtain the quantized feature matrix corresponding to the central node side; The key generation unit at the central node side is used to input the obtained quantized feature matrix corresponding to the central node side into the fuzzy extractor to generate a random key containing a check and a marked auxiliary data vector; Combining the labeled auxiliary data vector corresponding to each detection signal with the corresponding labeled data to form a labeled auxiliary data matrix; The auxiliary data distribution unit at the central node side is used to broadcast the obtained labeled auxiliary data matrix to each edge node; The signal processing unit at the edge node side is used to extract and quantize the received detection signal to obtain the quantized feature vector corresponding to the edge node side; The edge node side key extraction unit is used to generate a binary key corresponding to the edge node side according to the obtained label auxiliary data matrix and the quantized feature vector corresponding to the edge node side as the input of the fuzzy extractor; The key distribution unit on the edge node side is used to verify the binary key corresponding to the edge node side, and complete the key distribution if the verification is successful.
[0011] A computer device comprising: a processor suitable for executing a computer program; A computer-readable storage medium, wherein a computer program is stored in the computer-readable storage medium, and when the computer program is executed by the processor, the optimization method is executed.
[0012] A computer-readable storage medium stores a computer program, and the computer program implements the optimization method when executed by a processor.
[0013] A computer program product comprises a computer program, wherein the computer program implements the optimization method when executed by a processor.
[0014] A chip, a memory having a computer program stored thereon; A processor is used to execute the computer program in the memory to implement the steps of the method.
[0015] Compared with the prior art, the present invention has the following beneficial effects: The present invention provides a physical layer group key generation and distribution method for star-shaped Internet of Things. According to the channel features extracted during the communication process as an auxiliary, a fuzzy extractor method is adopted. The central node inputs the channel features to the fuzzy extractor to generate a random key and auxiliary data, and the edge node inputs the channel features and auxiliary data to the fuzzy extractor to extract the random key. Benefiting from the characteristics of the fuzzy extractor, the input channel features can extract the same key as long as they are within a certain Hamming distance. In addition, due to the reciprocity of the channel, the central node and the edge node can extract the same channel features within the coherence time, and then the edge node can extract the same key as the central node without the need for key negotiation. At the same time, the edge nodes all extract the group key through the channel features obtained when the central node broadcasts, and all nodes can extract the group key at the same time, thereby significantly reducing the number of key negotiations, thereby reducing the transmission time overhead caused by the low transmission rate of long-distance communication, and at the same time, all edge nodes jointly extract the group key to avoid the process of first generating paired keys and then gradually XORing to generate group keys, thereby reducing the key exchange overhead, which is generally meaningful and valuable. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 The present invention is a flowchart of group key generation and distribution; Figure 2 This is a functional schematic diagram of the fuzzy extractor of the present invention; Figure 3 This is the pseudo code diagram of the fuzzy extractor Gen algorithm of the present invention; Figure 4It is the pseudo code diagram of the fuzzy extractor Rep algorithm of the present invention; Figure 5 This is a schematic diagram of key information extraction and exchange of the present invention. DETAILED DESCRIPTION
[0017] In the following description, specific details such as specific system structures, technologies, etc. are provided for the purpose of illustration rather than limitation, so as to provide a thorough understanding of the embodiments of the present application. However, it should be clear to those skilled in the art that the present application may also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to prevent unnecessary details from obstructing the description of the present application.
[0018] It should be understood that when used in the present specification and the appended claims, the term "comprising" indicates the presence of described features, wholes, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or combinations thereof.
[0019] It should also be understood that the term “and / or” used in the specification and appended claims refers to any and all possible combinations of one or more of the associated listed items, and includes these combinations.
[0020] As used in the specification and appended claims of this application, the term "if" can be interpreted as "when" or "uponce" or "in response to determining" or "in response to detecting", depending on the context. Similarly, the phrase "if it is determined" or "if [described condition or event] is detected" can be interpreted as meaning "uponce it is determined" or "in response to determining" or "uponce [described condition or event] is detected" or "in response to detecting [described condition or event]", depending on the context.
[0021] In addition, in the description of the present application specification and the appended claims, the terms "first", "second", "third", etc. are only used to distinguish the descriptions and cannot be understood as indicating or implying relative importance.
[0022] References to "one embodiment" or "some embodiments" etc. described in the specification of this application mean that one or more embodiments of the present application include specific features, structures or characteristics described in conjunction with the embodiment. Therefore, the statements "in one embodiment", "in some embodiments", "in some other embodiments", "in some other embodiments", etc. that appear in different places in this specification do not necessarily refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in other ways. The terms "including", "comprising", "having" and their variations all mean "including but not limited to", unless otherwise specifically emphasized in other ways.
[0023] Example 1 See also Figures 1 to 5 This embodiment discloses a physical layer group key generation and distribution method for a star-type Internet of Things, which is used to reduce the number of communications between nodes within a group. It utilizes the characteristics of a fuzzy extractor and a new key distribution process to achieve key generation and distribution without the need for additional key verification and key exchange communication overhead, and more efficiently generates a group key that ensures secure communication within the group. This helps to quickly update the group key in an Internet of Things environment, achieve secure communication within the group, and improve security, which is innovative.
[0024] The specific steps include: Step 1: Channel detection.
[0025] This is the first step of PLSKG, based on a star network structure, which includes a central node Alice and N An edge node Bob; Used to collect channel measurement values of all Bobs. Channel measurement can be channel state information (CSI), RSS or phase.
[0026] In this step, each edge node Bob sends the device ID number, i.e., the tag data, to the central node Alice. a i ( i =1, …, N ), the central node Alice extracts channel features respectively after receiving signals from multiple edge nodes Bob.
[0027] In order to improve the spectrum utilization of carriers, Orthogonal Frequency Division Multiplexing (OFDM) technology has been widely used in current wireless communications. Based on OFDM technology, the channel characteristics of multiple subcarriers can be obtained through a single communication process, thereby enriching the channel characteristic data.
[0028] The measurement results collected by both parties in communication are often affected by fading, interference and noise caused by the equipment hardware, resulting in inconsistent measurement results. In order to improve the consistency of measurement, a signal preprocessing algorithm must be used. The denoising method can use general signal processing methods, such as mean filtering, wavelet transform or wavelet packet transform to filter the high-frequency part of the signal; it can also use machine learning methods such as autoencoders and principal component analysis to process the signal.
[0029] After preprocessing, the signal strength of each subcarrier can be extracted from the denoised signal based on OFDM technology. M The signal has a channel eigenvector of h; for N The star structure of edge nodes is networked, and after extracting the channel characteristics of all edge nodes, the matrix H can be constructed: H={h 1 ,h 2 , ...,h N} Among them, h i Representatives from i The channel feature vector extracted from Bob’s signal; This step is used to collect channel characteristics. The central node collects the channel characteristics of other nodes in the group as the basis for key generation and extraction.
[0030] Step 2: feature quantization.
[0031] This is a crucial step in the physical layer key generation process, which converts the measured continuous channel characteristic values into discrete bit values.
[0032] This aspect adopts the median quantization method, first obtains the median of the channel feature sequence, recorded as median, takes median as the threshold, and quantizes features greater than or equal to the threshold to 1, and features less than the threshold to 0. This method is a lossless quantization, and no eigenvalues will be lost during the quantization process, and it can ensure that 0 and 1 maintain a relatively balanced ratio, thereby ensuring the randomness of the quantized features. The quantized feature vector set is recorded as matrix W:
[0033] Among them, w i Representative i The channel feature vector h i Quantitative results of The feature vector representing the input The i-th component of Represents the median of the signal feature sequence.
[0034] Step 3, fuzzy extractor calculation, which replaces the key negotiation step in the traditional scheme.
[0035] See also Figure 2 ,Fuzzy extractor is a cryptographic technique used to extract stable and reliable keys from unstable or ambiguous data (especially biometric data, such as fingerprints, irises, voiceprints, etc.), even if the data is slightly different each time it is collected, the same key can be extracted.
[0036] The fuzzy extractor consists of two algorithms: key generation (Generate function) and key reconstruction (Reconstruct function).
[0037] 1) Key generation algorithm (Gen(w) → {key,P}): Input biometric information w, output key key and publicly transmitted auxiliary data P.
[0038] 2) Key reconstruction algorithm (Rep(w',P) → {key}): Input biometric information w' and auxiliary data P. If w' and w are similar, that is, their Hamming distance is less than the specified distance, then output the key key.
[0039] By using the above characteristics of the fuzzy extractor, the key negotiation and error correction steps due to inconsistent keys can be avoided. For encrypted communications, slight differences between encryption keys and decryption keys will lead to decryption failures, so a consistent key must be obtained through a negotiation algorithm. Traditional key negotiation methods are based on interactive negotiation algorithms, which require multiple communications to transmit check codes or information that can locate bit positions. The communication overhead is large and certain information will be leaked. In addition, the key generation rate of the traditional scheme also depends on the length of the collected channel characteristics. Even if the quantization algorithm has a key generation rate of 2, to generate a 128-bit key, in a communication environment with 64 subcarriers, 2 detections are required to generate a complete key. However, when using a fuzzy extractor, there is no such problem. By sending auxiliary data, the other party decrypts the key based on the auxiliary data, avoiding multiple transmissions of check code negotiations, and the auxiliary data is data that has no direct relationship with the key, thereby avoiding information leakage. In addition, using a random function to generate a key can avoid the limitation that the key generation rate depends on the number of channel characteristics, further improving the key generation rate; See also Figure 3 Fuzzy extractor Gen algorithm, the central node Alice inputs the quantized feature matrix W, generates a binary random key vector, salt value vector and mask vector of specified length, recorded as vector key, salt, mask respectively, and concatenates multiple zeros to the binary random key vector key to obtain the random key key' containing verification.
[0040] Different from the point-to-point scenario, in the group key scenario, the central node Alice will receive communications from multiple Bobs. After multiple feature quantizations, the quantized feature matrix W is obtained (each component represents the quantized channel feature of one of Bobs). The quantized feature matrix W is traversed and each quantized feature vector w of the quantized feature matrix W is calculated. i Perform feature extraction to obtain the corresponding channel feature vector; The channel feature vector obtained on the central node side is hashed by the pbkdf2_hash function to generate a binary digest vector digest; The summary generation process is expressed as:
[0041] In the formula, represents the pbkdf2 function, Represents the specified hash function, Represents a binary vector, a salt value vector Indicates the salt value used to defend against rainbow table attacks. Indicates the number of iterations. Indicates the length of the last generated digest.
[0042] Among them, the binary vector Calculated by the following formula:
[0043] In the formula, represents the input quantized feature vector, and ^ represents the bitwise AND operation.
[0044] Perform an XOR operation on the obtained binary summary vector digest and the random key key' containing verification to generate a binary ciphertext vector cipher; The ciphertext generation process is expressed as:
[0045] In the formula, Represents a bitwise exclusive-or operation between vectors.
[0046] The obtained binary cipher vector cipher, salt value vector salt and mask vector mask, i Bob's corresponding labeled data a i Generate labeled auxiliary data vector p i ,
[0047] Multiple labeled auxiliary data vectors are constructed into a labeled auxiliary data matrix P for distribution to all Bobs.
[0048] Step 4: Auxiliary data distribution.
[0049] In addition to obtaining the labeled auxiliary data matrix P sent by the central node Alice, the edge node Bobs also needs to extract channel features from the received signal.
[0050] In a steady-state environment, the positions of surrounding objects are relatively fixed, the reflection, scattering and other phenomena experienced by the signal during propagation are reduced, and the multipath effect is weakened; and the signal source and the receiving end remain stationary, and there is no Doppler effect. Since the coherence time is inversely proportional to the Doppler effect, the coherence time of the channel in a steady-state environment is relatively long. Correspondingly, for a time-division duplex (TDD) system, the uplink and downlink signals will experience similar environments in the wireless channel, so the wireless channel is highly correlated during the coherence time, so the edge node Bob can extract channel features similar to those of the central node Alice.
[0051] For each edge node Bob, after receiving the detection signal from the central node Alice, the signal strength of all subcarriers is extracted from the received signal, recorded as vector h'. After extracting the signal features, the edge node Bob uses the same quantization algorithm to perform 01 binary quantization on the features to obtain the corresponding quantized feature vector w' on the edge node side.
[0052] Step 5, key extraction. This is the last step of PLSKG. After obtaining the quantized feature vector w', the edge node Bob inputs the quantized feature vector w' and the labeled auxiliary data matrix P into the fuzzy extractor.
[0053] See also Figure 4 The Rep algorithm of the fuzzy extractor, for the received labeled auxiliary data matrix P, the edge node Bob uses his own labeled data a Extract the corresponding labeled auxiliary data vector p i ; Verify the extracted labeled auxiliary data vector corresponding to the labeled data a i The label data of the corresponding edge node Bob a , if a=a i , then proceed to the next step. Otherwise, the edge node Bob uses his own labeled data a Re-extract the corresponding labeled auxiliary data vector p i ; The binary ciphertext vector cipher, the salt value vector salt and the mask vector mask are obtained by using the verified marked auxiliary data vector; Perform bitwise AND operation on the quantized feature vector w' and the mask vector mask to obtain a binary vector vector'; The obtained binary vector vector' is hashed to obtain the binary summary vector digest'; The obtained binary summary vector digest' is XORed with the binary ciphertext vector cipher to extract the binary key key''. ; Based on the characteristics of the fuzzy extractor, as long as the quantized feature vector w' is close enough to the quantized feature vector w, the extracted binary vector vector' will have the same components as those in vector, the obtained digest digest' will also have the same components as those in digest, and the extracted binary key key'' will have the same components as the original key key.
[0054] Finally, check whether the check bits of the binary key key'' are all 0; if they are all 0, it means that the key component is the original key key, and the key distribution is completed; if the check fails, it means that the key extraction fails, and repeat step 1.
[0055] refer to Figure 5 ,The proposed group key generation and distribution method,the communication process of node key generation within the group only requires the edge node Bobs to send channel detection to the central node Alice and the auxiliary data broadcast of the central node Alice, which can greatly reduce the communication overhead between devices.
[0056] Assume that there is a central node Alice and N When edge nodes Bobs perform group key generation and distribution according to the traditional method and the method of the present invention respectively, their respective time overheads are as follows.
[0057] For the traditional method, it is necessary to generate a point-to-point pairwise key first, and then exchange keys through the pairwise XOR method based on the generated pairwise keys to generate the group key. Assume that the time to generate a pairwise key is T PW , the communication time for exchanging a key is T IR , then the total time of traditional group key generation and distribution is T for:
[0058] Furthermore, regarding the generation time of the pairwise key T PW , assuming that the time for sending a channel probe is T CD , the quantization time is T Q , the time for key negotiation to generate the verification code and verification calculation is TCH , the communication time for a key negotiation / key exchange is T IR , if there is K Key bits need to be negotiated, then . Accordingly, the total duration of group key generation and distribution is T for:
[0059] In an improved solution of the present invention, T CD and T Q The meaning is the same as above. Assume that Alice broadcasts auxiliary data at T P , the computation time of one cycle of the Gen algorithm in the fuzzy extractor is T GEN , the computation time of the Rep algorithm is T REP , then the duration of the improvement plan T for:
[0060] Regarding the two algorithms of the fuzzy extractor, the Gen algorithm requires calculation N times cycle, so the coefficient is N , and the Rep algorithm for key regeneration is executed independently by each Bob, which is equivalent to executing the key extraction process in parallel, so the coefficient is 1. It is not difficult to see that the time for group key generation and distribution is significantly reduced. As the number of devices increases, N The advantages of the method proposed in the present invention will be more obvious.
[0061] The present invention can not only reduce the communication overhead of key negotiation, but also reduce the communication overhead of key exchange to generate group keys, which is conducive to faster generation and distribution of group keys under conditions of more devices in the group or lower communication transmission rate, and is very meaningful and valuable.
[0062] Example 2 The present embodiment provides a physical layer group key generation and distribution system for a star-shaped Internet of Things, based on a star-shaped network structure, which includes a central node and N edge nodes, including: The edge node signal sending unit is used for each edge node to send a detection signal to the central node, wherein the detection signal is a device ID number as marking data; The signal processing unit at the central node side is used to extract and quantize the features of each received detection signal to obtain the quantized feature matrix corresponding to the central node side; The key generation unit at the central node side is used to input the obtained quantized feature matrix corresponding to the central node side into the fuzzy extractor to generate a random key containing a check and a marked auxiliary data vector; Combining the labeled auxiliary data vector corresponding to each detection signal with the corresponding labeled data to form a labeled auxiliary data matrix; The auxiliary data distribution unit at the central node side is used to broadcast the obtained labeled auxiliary data matrix to each edge node; The signal processing unit at the edge node side is used to extract and quantize the received detection signal to obtain the quantized feature vector corresponding to the edge node side; The edge node side key extraction unit is used to generate a binary key corresponding to the edge node side according to the obtained label auxiliary data matrix and the quantized feature vector corresponding to the edge node side as the input of the fuzzy extractor; The key distribution unit on the edge node side is used to verify the binary key corresponding to the edge node side, and complete the key distribution if the verification is successful.
[0063] Example 3 This embodiment 3 provides a computer device, including: a memory for storing a computer program; and a processor for implementing the steps of a computer method when executing the computer program.
[0064] When the processor executes the computer program, the steps of the above-mentioned computer method are implemented, or when the processor executes the computer program, the functions of each module in the above-mentioned system are implemented. Exemplarily, the computer program may be divided into one or more modules / units, which are stored in the memory and executed by the processor to implement the present invention. The one or more modules / units may be a series of computer program instruction segments capable of implementing preset functions, and the instruction segments are used to describe the execution process of the computer program in the computer device.
[0065] The computer device may be a computing device such as a desktop computer, a notebook, a PDA, and a cloud server. The computer device may include, but is not limited to, a processor and a memory. Those skilled in the art will appreciate that the above are examples of computer devices and do not constitute a limitation on computer devices. The computer device may include more components than the above, or a combination of certain components, or different components. For example, the computer device may also include input and output devices, network access devices, buses, etc.
[0066] The processor may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor, etc. The processor is the control center of the computer device, and uses various interfaces and lines to connect various parts of the entire computer device.
[0067] The memory may be used to store the computer programs and / or modules, and the processor implements various functions of the computer device by running or executing the computer programs and / or modules stored in the memory and calling the data stored in the memory.
[0068] The memory may mainly include a program storage area and a data storage area, wherein the program storage area may store an operating system, an application required for at least one function (such as a sound playback function, an image playback function, etc.), etc.; the data storage area may store data created according to the use of the mobile phone (such as audio data, a phone book, etc.), etc. In addition, the memory may include a high-speed random access memory, and may also include a non-volatile memory, such as a hard disk, a memory, a plug-in hard disk, a smart memory card (SmartMediaCard, SMC), a secure digital (SecureDigital, SD) card, a flash card (FlashCard), at least one disk storage device, a flash memory device, or other volatile solid-state storage devices.
[0069] Example 4 This embodiment 4 also provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the steps of the optimization method are implemented.
[0070] If the module / unit integrated in the computer system is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium.
[0071] Based on such understanding, the present invention implements all or part of the processes in the above optimization method, and can also be completed by instructing related hardware through a computer program, and the computer program can be stored in a computer-readable storage medium, and when the computer program is executed by a processor, the steps of the above computer method can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or preset intermediate form, etc.
[0072] The computer-readable storage medium may include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal and software distribution medium, etc.
[0073] It should be noted that the content contained in the computer-readable storage medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable storage media do not include electrical carrier signals and telecommunication signals.
[0074] Example 5 This embodiment 5 provides a computer product, which includes a computer program, and the computer program is stored in a computer-readable storage medium; the processor of the computer device reads the computer program from the computer-readable storage medium, and the processor executes the computer program, so that the computer device can execute the method in embodiment 1, which will not be repeated here.
[0075] It should be noted that a person of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be implemented by instructing related hardware through a computer program. The program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above-mentioned methods.
[0076] Example 6 This embodiment provides a chip.
[0077] The terminal device is a chip, and the chip of this embodiment includes a processor, which may be one or more, and a memory for storing a computer program executable by the processor. The computer program stored in the memory may include one or more modules, each corresponding to a set of instructions. In addition, the processor may be configured to execute the computer program to perform the method described in embodiment 1.
[0078] In addition, the chip may also include a power supply component and a communication component, wherein the power supply component may be configured to perform power management of the chip, and the communication component may be configured to implement communication of the chip, for example, wired or wireless communication. In addition, the chip may also include an input / output (I / O) interface. The chip may operate based on an operating system stored in the memory.
[0079] The embodiments described above are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, a person skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features may be replaced by equivalents. Such modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.
Claims
1. A method for generating and distributing physical layer group keys for star-shaped Internet of Things, characterized in that: Based on the star network structure, the star network structure includes a central node and N The following steps are included: Each edge node sends a detection signal to the central node, and the detection signal is a device ID number as tag data; The central node extracts and quantizes the features of each received detection signal to obtain the corresponding quantized feature matrix on the central node side; The obtained quantized feature matrix corresponding to the central node side is input into the fuzzy extractor to generate a vector containing a random key and a marked auxiliary data; Combining the labeled auxiliary data vector corresponding to each detection signal with the corresponding labeled data to form a labeled auxiliary data matrix; Broadcast the obtained labeled auxiliary data matrix to each edge node; Each edge node extracts and quantizes the received detection signal to obtain the quantized feature vector corresponding to the edge node side; The obtained labeled auxiliary data matrix and the quantized feature vector corresponding to the edge node side are used as the input of the fuzzy extractor to generate the binary key corresponding to the edge node side; The binary key corresponding to the edge node side is verified, and the key distribution is completed if the verification succeeds.
2. According to the method for generating and distributing physical layer group keys for star-shaped Internet of Things according to claim 1, it is characterized in that: The central node extracts and quantizes the features of each received detection signal to obtain the corresponding quantized feature matrix on the central node side. The specific method is: Extracting a channel feature vector corresponding to each detection signal; Each channel feature vector obtained is quantized using a median quantization method, and the obtained quantization results are used to form a quantized feature matrix.
3. According to the method for generating and distributing physical layer group keys for star-shaped Internet of Things according to claim 1, it is characterized in that: The quantized feature matrix corresponding to the central node side is input into the fuzzy extractor to generate a vector containing a random key and a tag auxiliary data. The specific method is: The quantized feature matrix is used as the input of the fuzzy extractor Gen algorithm to obtain a binary random key, salt value and mask of a specified length corresponding to each quantized feature vector in the quantized feature matrix; The random key with verification is generated by splicing multiple 0s from the binary random key; Extracting a channel feature vector corresponding to each quantized feature vector in the quantized feature matrix; Hash the obtained channel feature vector to generate a binary summary vector; Perform an XOR operation on the obtained binary summary vector and the random key containing the check to generate a binary ciphertext vector; The obtained binary ciphertext vector, salt value vector and mask vector are generated to obtain a marked auxiliary data vector.
4. According to the method for generating and distributing physical layer group keys for star-shaped Internet of Things according to claim 1, it is characterized in that: Each edge node extracts and quantizes the received detection signal to obtain the quantized feature vector corresponding to the edge node side. The specific method is: Extracting a channel feature vector corresponding to the detection signal; The obtained channel feature vector is quantized using a median quantization method to obtain a quantized feature vector.
5. The method for generating and distributing physical layer group keys for star-shaped Internet of Things according to claim 1, characterized in that: The obtained labeled auxiliary data matrix and the quantized feature matrix corresponding to the edge node side are used as the input of the fuzzy extractor to generate the binary key corresponding to the edge node side. The specific method is: The obtained quantized feature vector and the labeled auxiliary data matrix are used as the input of the fuzzy extractor Rep algorithm to obtain the labeled auxiliary data vector corresponding to the edge node; Obtain a binary ciphertext vector, a salt value vector and a mask vector according to the obtained marked auxiliary data vector; Performing a bitwise AND operation on the obtained quantized feature vector and the mask vector to obtain a binary vector; The obtained binary vector is hashed to obtain a binary summary vector; The obtained binary summary vector is XORed with the binary ciphertext vector to obtain a binary key vector.
6. A physical layer group key generation and distribution system for star-shaped Internet of Things, characterized in that: Based on the star network structure, the star network structure includes a central node and N edge nodes, including: The edge node signal sending unit is used for each edge node to send a detection signal to the central node, wherein the detection signal is a device ID number as marking data; The signal processing unit at the central node side is used to extract and quantize the features of each received detection signal to obtain the quantized feature matrix corresponding to the central node side; The key generation unit at the central node side is used to input the obtained quantized feature matrix corresponding to the central node side into the fuzzy extractor to generate a random key containing a check and a marked auxiliary data vector; Combining the labeled auxiliary data vector corresponding to each detection signal with the corresponding labeled data to form a labeled auxiliary data matrix; The auxiliary data distribution unit at the central node side is used to broadcast the obtained labeled auxiliary data matrix to each edge node; The signal processing unit at the edge node side is used to extract and quantize the received detection signal to obtain the quantized feature vector corresponding to the edge node side; The edge node side key extraction unit is used to generate a binary key corresponding to the edge node side according to the obtained label auxiliary data matrix and the quantized feature vector corresponding to the edge node side as the input of the fuzzy extractor; The key distribution unit on the edge node side is used to verify the binary key corresponding to the edge node side, and complete the key distribution if the verification is successful.
7. A computer device, characterized in that: include: a processor suitable for executing a computer program; A computer-readable storage medium, wherein a computer program is stored in the computer-readable storage medium, and when the computer program is executed by the processor, the optimization method according to any one of claims 1 to 5 is executed.
8. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the optimization method according to any one of claims 1 to 5 is implemented.
9. A computer program product, characterized in that The computer program product comprises a computer program, and when the computer program is executed by a processor, the optimization method according to any one of claims 1 to 5 is implemented.
10. A chip, characterized in that: a memory having a computer program stored thereon; A processor, configured to execute the computer program in the memory to implement the steps of the method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Efficient random physical layer secrete key generation method based on vector quantization
CN103825725A
Lightweight group key distribution method based on wireless channel feature
CN108696867A
Physical layer secret key generation method and system based on channel characteristics
CN112202511A
Physical layer security key extraction method based on fuzzy extractor negotiation
CN113746624A
Physical layer key extraction method, system and device based on signal intensity and medium
CN114125826A