A method, system, device, and medium for physical layer group key generation and distribution for star-shaped Internet of Things (IoT)

By using fuzzy extractor technology in a star-shaped IoT architecture, the central node generates and broadcasts auxiliary data, and the edge nodes extract the key, thus solving the problems of low transmission rate over long distances and low group key generation efficiency, and achieving efficient secure communication within the group.

CN119997007BActive Publication Date: 2026-04-17XI AN JIAOTONG UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
XI AN JIAOTONG UNIV
Filing Date
2024-09-30
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

Existing physical layer group key generation methods have low transmission rates and low group key generation efficiency over long distances, which cannot meet the high-efficiency and secure communication requirements of star-shaped IoT.

Method used

By employing fuzzy extractor technology, in a star network structure, the central node generates random keys and auxiliary data through feature extraction and quantization, while the edge nodes extract the same keys using the fuzzy extractor and auxiliary data, thereby reducing the number of key negotiations and communication overhead.

Benefits of technology

It significantly reduces the time overhead and transmission time of key negotiation, improves the efficiency of group key generation, and is suitable for fast and secure communication in star-shaped IoT.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119997007B_ABST
    Figure CN119997007B_ABST
Patent Text Reader

Abstract

This invention provides a method, system, device, and medium for generating and distributing physical layer group keys for star-shaped Internet of Things (IoT). It utilizes channel features extracted during communication as an aid, employing a fuzzy extractor method. The central node inputs channel features into the fuzzy extractor to generate a random key and auxiliary data, while edge nodes input channel features and auxiliary data to the fuzzy extractor to extract the random key. This invention significantly reduces the number of key negotiations, thereby reducing transmission time overhead caused by low transmission rates in long-distance communication. Furthermore, the joint extraction of group keys by all edge nodes avoids the process of first generating paired keys and then gradually XORing them to generate the group key, thus reducing key exchange overhead. Overall, this invention is significant and valuable.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of communication security and relates to a method, system, device and medium for generating and distributing physical layer group keys for star-shaped Internet of Things. Background Technology

[0002] There are two common encryption schemes for the Internet of Things (IoT): one is based on traditional encryption methods, where both parties obtain keys from a Key Distribution Center (KDC), each using the other's public key to encrypt plaintext and their own private key to decrypt ciphertext for information exchange. Clearly, traditional schemes rely on a trusted third party to manage keys and perform authentication. However, in many IoT scenarios, such as wide-coverage wireless networks, a trusted third party is generally not present. The other is Physical Layer-based Secret Key Generation (PLSKG), a secure key generation technology based on the physical characteristics of wireless channels. It features low communication overhead, low hardware requirements, and no reliance on mathematical problems. PLSKG utilizes channel variations to generate shared keys between legitimate nodes (e.g., Alice and Bob). With this technology, even if an eavesdropping node (e.g., Eve) is present, Eve cannot extract the same key as the legitimate node because Eve's channel is not sufficiently correlated with the channels between Alice and Bob.

[0003] While the general PLSKG method can securely generate pairwise keys between communicating parties, it faces two challenges: low transmission rates over long distances and low group key generation efficiency. To address these challenges, it is essential to use a group key generation and distribution method that offers higher key generation efficiency and lower time overhead. Summary of the Invention

[0004] The purpose of this invention is to provide a physical layer group key generation and distribution method, system, device and medium for star-shaped Internet of Things, which solves the problem of low efficiency in existing pair key generation or group key generation.

[0005] To achieve the above objectives, the technical solution adopted by the present invention is as follows:

[0006] This invention provides a physical layer group key generation and distribution method for star-shaped Internet of Things (IoT), based on a star network structure including a central node and N edge nodes, comprising the following steps:

[0007] Each edge node sends a probe signal to the central node, and the probe signal is the device ID number used as tag data;

[0008] The central node performs feature extraction and quantization on each received detection signal to obtain the corresponding quantized feature matrix on the central node side;

[0009] The quantized feature matrix corresponding to the central node side is input into the fuzzy extractor to generate a data vector containing a verification random key and a tag auxiliary data vector.

[0010] The tag-aid data vector corresponding to each detection signal is combined with the corresponding tag data to form a tag-aid data matrix;

[0011] The obtained marker auxiliary data matrix is ​​broadcast to each edge node;

[0012] Each edge node performs feature extraction and quantization on the received probe signal to obtain the corresponding quantized feature vector on the edge node side;

[0013] The binary key corresponding to the edge node is generated by using the obtained marker auxiliary data matrix and the quantized feature vector corresponding to the edge node as input to the fuzz extractor.

[0014] The binary key corresponding to the obtained edge node is verified. If the verification is successful, the key distribution is completed.

[0015] Preferably, the central node performs feature extraction and quantization on each received detection signal to obtain the corresponding quantized feature matrix on the central node side. The specific method is as follows:

[0016] Extract the channel feature vector corresponding to each probe signal;

[0017] The median quantization method is used to quantize each channel feature vector, and the quantization results are used to form a quantized feature matrix.

[0018] Preferably, the quantized feature matrix corresponding to the obtained central node side is input into the fuzzy extractor to generate a data vector containing a verification random key and a marker auxiliary data vector. The specific method is as follows:

[0019] The quantized feature matrix is ​​used as input to the Gen algorithm of the fuzz extractor to obtain a binary random key, salt value and mask of a specified length corresponding to each quantized feature vector in the quantized feature matrix;

[0020] A checksum-containing random key is generated by concatenating multiple zeros into a binary random key;

[0021] Extract the channel feature vector corresponding to each quantization feature vector in the quantization feature matrix;

[0022] The obtained channel feature vector is hashed to generate a binary digest vector;

[0023] The obtained binary digest vector is XORed with the check-in random key to generate a binary ciphertext vector.

[0024] The obtained binary ciphertext vector, salt vector, and mask vector are used to generate a marker auxiliary data vector.

[0025] Preferably, each edge node performs feature extraction and quantization on the received detection signal to obtain the corresponding quantized feature vector on the edge node side. The specific method is as follows:

[0026] Extract the channel feature vector corresponding to the probe signal;

[0027] The obtained channel feature vector is quantized using the median quantization method to obtain the quantized feature vector.

[0028] Preferably, the binary key corresponding to the edge node is generated by using the obtained marker auxiliary data matrix and the quantization feature matrix corresponding to the edge node as input to the fuzzy extractor. The specific method is as follows:

[0029] The obtained quantized feature vector and the labeled auxiliary data matrix are used as inputs to the Rep algorithm of the fuzzy extractor to obtain the labeled auxiliary data vectors corresponding to the edge nodes;

[0030] Based on the obtained marker auxiliary data vector, the binary ciphertext vector, salt value vector, and mask vector are obtained;

[0031] The obtained quantized feature vector and mask vector are bitwise ANDed to obtain a binary vector;

[0032] The obtained binary vector is hashed to generate a binary digest vector;

[0033] The binary key vector is obtained by performing an XOR operation between the obtained binary digest vector and the binary ciphertext vector.

[0034] A physical layer group key generation and distribution system for star-shaped Internet of Things (IoT) is provided, based on a star network structure, which includes a central node and N edge nodes, comprising:

[0035] An edge node signal transmitting unit is used for each edge node to send a probe signal to the central node, wherein the probe signal is a device ID number used as marker data;

[0036] The signal processing unit on the central node side is used to extract and quantize the features of each received detection signal to obtain the corresponding quantized feature matrix on the central node side.

[0037] The central node-side key generation unit is used to input the quantized feature matrix corresponding to the central node side into the fuzzy extractor to generate a random key with verification and a labeled auxiliary data vector.

[0038] The tag-aid data vector corresponding to each detection signal is combined with the corresponding tag data to form a tag-aid data matrix;

[0039] The central node-side auxiliary data distribution unit is used to broadcast the obtained tag auxiliary data matrix to each edge node;

[0040] The edge node-side signal processing unit is used to extract and quantize the received detection signals to obtain the corresponding quantized feature vectors at the edge node side.

[0041] The edge node-side key extraction unit is used to generate the binary key corresponding to the edge node side by using the obtained tag auxiliary data matrix and the quantized feature vector corresponding to the edge node side as inputs to the fuzzy extractor.

[0042] The edge node-side key distribution unit is used to verify the binary key corresponding to the edge node side. If the verification is successful, the key distribution is completed.

[0043] A computer device, comprising:

[0044] A processor is used to execute computer programs;

[0045] A computer-readable storage medium storing a computer program, which, when executed by the processor, performs the optimization method.

[0046] A computer-readable storage medium storing a computer program that, when executed by a processor, implements the optimization method described above.

[0047] A computer program product comprising a computer program that, when executed by a processor, implements the optimization method.

[0048] A type of chip,

[0049] A memory on which computer programs are stored;

[0050] A processor for executing the computer program in the memory to implement the steps of the method.

[0051] Compared with the prior art, the beneficial effects of the present invention are:

[0052] This invention provides a physical layer group key generation and distribution method for star-shaped Internet of Things (IoT). Using channel features extracted during communication as an aid, a fuzzy extractor method is employed. The central node inputs the channel features into the fuzzy extractor to generate a random key and auxiliary data, while edge nodes input the same channel features and auxiliary data to extract the random key. Benefiting from the characteristics of the fuzzy extractor, the same key can be extracted as long as the input channel features are within a certain Hamming distance. Furthermore, due to the reciprocity of the channel, the central node and edge nodes can extract the same channel features within the coherence time, allowing edge nodes to extract the same key as the central node without key negotiation. Simultaneously, edge nodes extract the group key using the channel features acquired during the central node's broadcast. All nodes can extract the group key simultaneously, significantly reducing the number of key negotiations and thus reducing the transmission time overhead caused by low transmission rates in long-distance communication. Furthermore, the joint extraction of the group key by all edge nodes avoids the process of generating paired keys first and then XORing them to generate the group key, thereby reducing key exchange overhead. Overall, this method is significant and valuable. Attached Figure Description

[0053] Figure 1 This is a flowchart of the key generation and distribution process for this invention.

[0054] Figure 2 This is a schematic diagram of the fuzz extractor function of the present invention;

[0055] Figure 3 This is a pseudocode diagram of the Gen algorithm for the fuzzy extractor of this invention;

[0056] Figure 4 This is a pseudocode diagram of the Rep algorithm for the fuzzy extractor of this invention;

[0057] Figure 5 This is a schematic diagram illustrating the key information extraction and exchange process of this invention. Detailed Implementation

[0058] In the following description, specific details such as particular system architectures and techniques are set forth for illustrative purposes and not for limitation, in order to provide a thorough understanding of the embodiments of this application. However, those skilled in the art will understand that this application may also be implemented in other embodiments without these specific details. In other instances, detailed descriptions of well-known systems, apparatuses, circuits, and methods have been omitted so as not to obscure the description of this application with unnecessary detail.

[0059] It should be understood that, when used in this application specification and the appended claims, the term "comprising" indicates the presence of the described features, integrals, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or a collection thereof.

[0060] It should also be understood that the term “and / or” as used in this application specification and the appended claims means any combination of one or more of the associated listed items and all possible combinations, and includes such combinations.

[0061] As used in this application specification and the appended claims, the term "if" may be interpreted, depending on the context, as "when," "once," "in response to determination," or "in response to detection." Similarly, the phrase "if determined" or "if detected [the described condition or event]" may be interpreted, depending on the context, as meaning "once determined," "in response to determination," "once detected [the described condition or event]," or "in response to detection [the described condition or event]."

[0062] Furthermore, in the description of this application and the appended claims, the terms "first," "second," "third," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.

[0063] References to "one embodiment" or "some embodiments" as described in this specification mean that one or more embodiments of this application include a specific feature, structure, or characteristic described in connection with that embodiment. Therefore, the phrases "in one embodiment," "in some embodiments," "in other embodiments," "in still other embodiments," etc., appearing in different parts of this specification do not necessarily refer to the same embodiment, but rather mean "one or more, but not all, embodiments," unless otherwise specifically emphasized. The terms "comprising," "including," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.

[0064] Example 1

[0065] See Figures 1 to 5 This embodiment discloses a physical layer group key generation and distribution method for star-shaped Internet of Things (IoT) to reduce the number of communications between nodes within the group. By utilizing the characteristics of a fuzzy extractor and a novel key distribution process, it achieves key generation and distribution without the communication overhead of additional key verification and key exchange. This method generates group keys that ensure secure communication within the group more efficiently, which helps to quickly update group keys in the IoT environment, achieve secure communication within the group, and improve security. It is innovative.

[0066] Specifically, the following steps are included:

[0067] Step 1, Channel Probe.

[0068] This is the first step of PLSKG, based on a star network structure, which includes a central node Alice and... N Bob is an edge node;

[0069] Used to collect channel measurements for all Bobs, which can be Channel State Information (CSI), RSS, or phase.

[0070] In this step, each edge node Bob sends its device ID, i.e., tag data, to the central node Alice. a i ( i =1, …, N After receiving signals from multiple edge nodes, Alice, the central node, extracts channel features.

[0071] To improve the spectral efficiency of carriers, modern wireless communication widely employs Orthogonal Frequency Division Multiplexing (OFDM) technology. Based on OFDM technology, the channel characteristics of multiple subcarriers can be obtained in a single communication process, thereby enriching the channel characteristic data.

[0072] Measurement results collected by both communicating parties are often affected by fading, interference, and noise caused by equipment hardware, leading to inconsistencies in the measurement results. To improve measurement consistency, signal preprocessing algorithms must be employed. Denoising methods can utilize general signal processing techniques, such as mean filtering, wavelet transform, or wavelet packet transform, to filter the high-frequency components of the signal; alternatively, machine learning methods such as autoencoders and principal component analysis can be used to process the signal.

[0073] After preprocessing, the signal strength of each subcarrier can be extracted from the denoised signal using OFDM technology. For a signal with a number of subcarriers... M The channel feature vector of the signal is h; for a signal with N A star-shaped network with edge nodes can be constructed into matrix H after extracting the channel features of all edge nodes:

[0074] H={h1,h2, ...,h N}

[0075] Among them, h i Representative from the first i Channel feature vectors extracted from Bob's signals;

[0076] This step is used for collecting channel features. The central node collects the channel features of other nodes in the group, which serve as the basis for key generation and extraction.

[0077] Step 2, Feature quantization.

[0078] This is a crucial step in the physical layer key generation process, which converts the measured continuous channel characteristic values ​​into discrete bit values.

[0079] This method employs median quantization. First, the median of the channel feature sequence is calculated, denoted as `median`. Using `median` as a threshold, features greater than or equal to the threshold are quantized as 1, and features less than the threshold are quantized as 0. This method is lossless quantization, ensuring no feature values ​​are lost during the quantization process and maintaining a relatively balanced ratio of 0s and 1s. This ensures the randomness of the quantized features. The set of quantized feature vectors is denoted as matrix W.

[0080]

[0081] Among them, w i Representing the i Channel feature vector h i Quantification results; Represents the input feature vector The i-th component, It represents the median of the signal characteristic sequence.

[0082] Step 3, fuzz extractor calculation. This is an alternative to the key negotiation step in the traditional scheme.

[0083] See Figure 2 A fuzz extractor is a cryptographic technique used to extract stable and reliable keys from unstable or fuzzy data (especially biometric data such as fingerprints, irises, and voiceprints). Even if there are slight differences in the data each time it is collected, the same key can still be extracted.

[0084] The fuzz extractor consists of two algorithms: a key generation function and a key reconstruction function.

[0085] 1) Key generation algorithm (Gen(w) → {key,P}): Input biometric information w, output key and auxiliary data P for public transmission.

[0086] 2) Key reconstruction algorithm (Rep(w',P) → {key}): Input biometric information w' and auxiliary data P. If w' and w are close, that is, their Hamming distance is less than a specified distance, then output the key key.

[0087] Using the aforementioned characteristics of the fuzzy extractor, the step of key negotiation for error correction due to key inconsistency can be avoided. For encrypted communication, even slight differences between the encryption and decryption keys can lead to decryption failure; therefore, a consensus key must be obtained through negotiation algorithms. Traditional key negotiation methods are based on interactive negotiation algorithms, which require multiple communications to transmit checksums or information that can locate bit positions, resulting in high communication overhead and potential information leakage. Furthermore, the key generation rate of traditional schemes depends on the length of the acquired channel features. Even with a quantization algorithm with a key generation rate of 2, generating a 128-bit key requires two probes in a communication environment with 64 subcarriers. However, the fuzzy extractor avoids these problems. By sending auxiliary data, the other party decrypts the key based on the auxiliary data, avoiding multiple transmissions of checksums for negotiation. Moreover, the auxiliary data is not directly related to the key, thus preventing information leakage. In addition, using a random function to generate the key avoids the key generation rate being limited by the number of channel features, further improving the key generation rate.

[0088] See Figure 3 The Gen algorithm for fuzzy extractor takes the quantized feature matrix W as input to the central node Alice and generates a binary random key vector, salt vector, and mask vector of a specified length, denoted as key, salt, and mask, respectively. Multiple zeros are concatenated into the binary random key vector key to obtain a random key with verification key'.

[0089] Unlike point-to-point scenarios, in group key scenarios, the central node Alice receives communications from multiple Bobs. Through multiple feature quantizations, a quantization feature matrix W is obtained (each component represents the quantization channel feature of one Bob). The quantization feature matrix W is then traversed, and each quantization feature vector w of the quantization feature matrix W is analyzed. i Feature extraction is performed to obtain the corresponding channel feature vector;

[0090] The obtained channel feature vector from the central node is hashed using the pbkdf2_hash function to generate a binary digest vector.

[0091] The abstract generation process is represented as follows:

[0092]

[0093] In the formula, This refers to the pbkdf2 function. Indicates the specified hash function. Represents a binary vector, a salt vector. This indicates the salt value used to defend against rainbow table attacks. Indicates the number of iterations. This indicates the length of the final generated summary.

[0094] Among them, binary vector Calculated using the following formula:

[0095]

[0096] In the formula, This represents the quantized feature vector of the input, and ^ represents the bitwise AND operation.

[0097] The binary digest vector (digest) is XORed with the check-in random key' to generate the binary cipher vector (cipher).

[0098] The ciphertext generation process is represented as follows:

[0099]

[0100] In the formula, This represents the bitwise XOR operation between vectors.

[0101] The obtained binary cipher vector, salt vector, and mask vector are used to... i The tag data corresponding to each Bob a i Generate a labeled auxiliary data vector p i ,

[0102] Multiple labeled auxiliary data vectors are combined to form a labeled auxiliary data matrix P, which is then distributed to all Bobs.

[0103] Step 4, assisting in data distribution.

[0104] In addition to obtaining the tagging auxiliary data matrix P sent by the central node Alice, the edge node Bobs also needs to extract channel features from the received signals.

[0105] In a steady-state environment, the positions of surrounding objects are relatively fixed, reducing reflections and scattering during signal propagation and weakening multipath effects. Furthermore, both the signal source and receiver remain stationary, eliminating the Doppler effect. Since coherence time is inversely proportional to the Doppler effect, the channel coherence time is relatively long in a steady-state environment. Correspondingly, for Time-Division Duplex (TDD) systems, uplink and downlink signals experience a similar environment in the wireless channel. Therefore, the wireless channel is highly correlated within the coherence time, allowing edge node Bob to extract channel characteristics similar to those of the central node Alice.

[0106] For each edge node Bob, after receiving the probe signal from the central node Alice, it extracts the signal strength of all subcarriers from the received signal, denoted as vector h'. After extracting the signal features, edge node Bob then uses the same quantization algorithm to perform 0-1 binary quantization on the features, obtaining the corresponding quantized feature vector w' on the edge node side.

[0107] Step 5, Key Extraction. This is the final step of PLSKG. After obtaining the quantized feature vector w', the edge node Bob inputs the quantized feature vector w' and the labeled auxiliary data matrix P into the blur extractor.

[0108] See Figure 4 The Rep algorithm of the fuzzy extractor, for the received labeled auxiliary data matrix P, edge node Bob uses its own labeled data... a Extract the corresponding labeled auxiliary data vector p i ;

[0109] Verify the labeled data corresponding to the extracted labeled auxiliary data vector. a i The tag data of the corresponding edge node Bob a , if a=a i If so, proceed to the next step; otherwise, edge node Bob uses its own labeled data. a Re-extract the corresponding labeled auxiliary data vector p i ;

[0110] The binary cipher vector, salt vector, and mask vector are obtained by using the verified marker auxiliary data vector.

[0111] Perform a bitwise AND operation between the quantized feature vector w' and the mask vector mask to obtain the binary vector vector'.

[0112] The obtained binary vector vector' is then hashed to obtain the binary digest vector';

[0113] The resulting binary digest vector 'digest' is XORed with the binary cipher vector 'cipher' to extract the binary key 'key'. ;

[0114] Based on the characteristics of the fuzzy extractor, as long as the quantized feature vector w' is close enough to the quantized feature vector w, the extracted binary vector vector' will have components that are the same as those in vector, the obtained digest' will also have components that are the same as those in digest, and the extracted binary key key'' will have components that are the same as those in the original key key.

[0115] Finally, check if the check bits of the binary key'' are all 0; if they are all 0, it means that the key component is the original key, and the key distribution is complete; if the check fails, it means that the key extraction has failed, and step 1 is repeated.

[0116] refer to Figure 5 The proposed group key generation and distribution method requires only the edge node Bobs to send channel probes to the central node Alice and the central node Alice to broadcast auxiliary data during the key generation communication process within the group, which can greatly reduce the communication overhead between devices.

[0117] Assuming a star-shaped IoT scenario with a central node Alice and N The time overhead for generating and distributing group keys for each edge node Bobs using the traditional method and the method of this invention are as follows.

[0118] Traditional methods require first generating point-to-point pairwise keys, then exchanging these keys using a pairwise XOR operation to generate the group key. Assume the time required to generate one pairwise key is... T PW The communication time for exchanging keys once is T IR The total time for traditional group key generation and distribution is... T for:

[0119]

[0120] Furthermore, regarding the generation time of paired keys T PW Assuming the time for sending one channel probe is T CD Quantified time is T Q The time for key negotiation, generation of checksum, and checksum calculation is... T CH The communication time for one key negotiation / key exchange is T IR If K Each key bit needs to be negotiated, then Correspondingly, the total time for group key generation and distribution. T for:

[0121]

[0122] In the improved embodiment of the present invention, T CD and T QThe meaning is the same as above, assuming Alice broadcasts auxiliary data at a time of [time]. T P The computation time for one loop of the Gen algorithm in the fuzzy extractor is... T GEN The computation time of the Rep algorithm is T REP The duration of the improvement plan T for:

[0123]

[0124] Regarding the two algorithms for fuzzy extractors, the Gen algorithm requires computation. N The cycle repeats, so the coefficient is... N The Rep algorithm for key regeneration is executed independently by each Bob, which is equivalent to parallel execution of the key extraction process, hence the coefficient is 1. It's easy to see that the time for group key generation and distribution is significantly reduced. As the number of devices increases, N As the size increases, the advantages of the method proposed in this invention will become more apparent.

[0125] This invention not only reduces the communication overhead of key negotiation, but also reduces the communication overhead of key exchange to generate group keys. It is beneficial for faster generation and distribution of group keys when there are many devices in the group or the communication transmission rate is low, which is very meaningful and valuable.

[0126] Example 2

[0127] This embodiment provides a physical layer group key generation and distribution system for star-shaped Internet of Things (IoT). Based on a star network structure, this system includes one central node and N edge nodes, comprising:

[0128] An edge node signal transmitting unit is used for each edge node to send a probe signal to the central node, wherein the probe signal is a device ID number used as marker data;

[0129] The signal processing unit on the central node side is used to extract and quantize the features of each received detection signal to obtain the corresponding quantized feature matrix on the central node side.

[0130] The central node-side key generation unit is used to input the quantized feature matrix corresponding to the central node side into the fuzzy extractor to generate a random key with verification and a labeled auxiliary data vector.

[0131] The tag-aid data vector corresponding to each detection signal is combined with the corresponding tag data to form a tag-aid data matrix;

[0132] The central node-side auxiliary data distribution unit is used to broadcast the obtained tag auxiliary data matrix to each edge node;

[0133] The edge node-side signal processing unit is used to extract and quantize the received detection signals to obtain the corresponding quantized feature vectors at the edge node side.

[0134] The edge node-side key extraction unit is used to generate the binary key corresponding to the edge node side by using the obtained tag auxiliary data matrix and the quantized feature vector corresponding to the edge node side as inputs to the fuzzy extractor.

[0135] The edge node-side key distribution unit is used to verify the binary key corresponding to the edge node side. If the verification is successful, the key distribution is completed.

[0136] Example 3

[0137] This embodiment 3 provides a computer device, including: a memory for storing a computer program; and a processor for executing the computer program to implement the steps of a computer method.

[0138] When the processor executes the computer program, it implements the steps of the computer method described above, or, when the processor executes the computer program, it implements the functions of each module in the system described above.

[0139] For example, the computer program may be divided into one or more modules / units, which are stored in the memory and executed by the processor to complete the present invention. The one or more modules / units may be a series of computer program instruction segments capable of performing a preset function, the instruction segments describing the execution process of the computer program in the computer device.

[0140] The computer device may be a desktop computer, laptop, handheld computer, or cloud server, etc. The computer device may include, but is not limited to, a processor and memory. Those skilled in the art will understand that the above are examples of computer devices and do not constitute a limitation on the computer device; it may include more components than described above, or combine certain components, or different components. For example, the computer device may also include input / output devices, network access devices, buses, etc.

[0141] The processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor, or any conventional processor, etc. The processor is the control center of the computer device, connecting various parts of the computer device through various interfaces and lines.

[0142] The memory can be used to store the computer program and / or module, and the processor implements various functions of the computer device by running or executing the computer program and / or module stored in the memory, and by calling the data stored in the memory.

[0143] The memory may primarily include a program storage area and a data storage area. The program storage area may store the operating system and at least one application program required for a function (such as sound playback, image playback, etc.); the data storage area may store data created based on the use of the mobile phone (such as audio data, phonebook, etc.). Furthermore, the memory may include high-speed random access memory, and may also include non-volatile memory, such as hard disks, RAM, plug-in hard disks, SmartMediaCards (SMC), Secure Digital (SD) cards, FlashCards, at least one disk storage device, flash memory device, or other volatile solid-state storage devices.

[0144] Example 4

[0145] This embodiment 4 also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the optimization method.

[0146] If the modules / units integrated in the computer system are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium.

[0147] Based on this understanding, the present invention can implement all or part of the processes in the above-described optimization method by instructing related hardware through a computer program. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the above-described computer method. The computer program includes computer program code, which can be in the form of source code, object code, executable file, or a preset intermediate form, etc.

[0148] The computer-readable storage medium may include: any entity or device capable of carrying the computer program code, recording media, USB flash drive, portable hard drive, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium, etc.

[0149] It should be noted that the content contained in the computer-readable storage medium may be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, the computer-readable storage medium does not include electrical carrier signals and telecommunication signals.

[0150] Example 5

[0151] This embodiment 5 provides a computer product, which includes a computer program stored in a computer-readable storage medium. The processor of the computer device reads the computer program from the computer-readable storage medium and executes the computer program, so that the computer device can perform the method in embodiment 1, which will not be described again here.

[0152] It should be noted that those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods.

[0153] Example 6

[0154] This embodiment provides a chip.

[0155] The terminal device is a chip. In this embodiment, the chip includes a processor, which may be one or more, and a memory for storing a computer program executable by the processor. The computer program stored in the memory may include one or more modules, each corresponding to a set of instructions. Furthermore, the processor may be configured to execute the computer program to perform the method described in Embodiment 1.

[0156] Additionally, the chip may include a power supply component and a communication component. The power supply component can be configured to perform power management for the chip, and the communication component can be configured to enable communication within the chip, such as wired or wireless communication. Furthermore, the chip may include input / output (I / O) interfaces. The chip can operate on an operating system stored in memory.

[0157] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included within the protection scope of this application.

Claims

1. A method for generating and distributing physical layer group keys for star-shaped Internet of Things (IoT), characterized in that, Based on a star network structure, this star network structure includes a central node and N Each edge node includes the following steps: Each edge node sends a probe signal to the central node, and the probe signal is the device ID number used as tag data; The central node performs feature extraction and quantization on each received detection signal to obtain the corresponding quantized feature matrix on the central node side; The quantized feature matrix corresponding to the central node side is input into the fuzzy extractor to generate a data vector containing a verification random key and a tag auxiliary data vector. The tag-aid data vector corresponding to each detection signal is combined with the corresponding tag data to form a tag-aid data matrix; The obtained marker auxiliary data matrix is ​​broadcast to each edge node; Each edge node performs feature extraction and quantization on the received probe signal to obtain the corresponding quantized feature vector on the edge node side; The binary key corresponding to the edge node is generated by using the obtained marker auxiliary data matrix and the quantized feature vector corresponding to the edge node as input to the fuzz extractor. The binary key corresponding to the obtained edge node is verified. If the verification is successful, the key distribution is completed.

2. The method for generating and distributing physical layer keys for a star-shaped Internet of Things (IoT) according to claim 1, characterized in that, The central node performs feature extraction and quantization on each received probe signal to obtain the corresponding quantized feature matrix. The specific method is as follows: Extract the channel feature vector corresponding to each probe signal; The median quantization method is used to quantize each channel feature vector, and the quantization results are used to form a quantized feature matrix.

3. The physical layer group key generation and distribution method for star-shaped Internet of Things according to claim 1, characterized in that, The quantized feature matrix corresponding to the obtained central node is input into the fuzzy extractor to generate a data vector containing a verification random key and a marker auxiliary data vector. The specific method is as follows: The quantized feature matrix is ​​used as input to the Gen algorithm of the fuzz extractor to obtain a binary random key, salt value and mask of a specified length corresponding to each quantized feature vector in the quantized feature matrix; A checksum-containing random key is generated by concatenating multiple zeros into a binary random key; Extract the channel feature vector corresponding to each quantization feature vector in the quantization feature matrix; The obtained channel feature vector is hashed to generate a binary digest vector; The obtained binary digest vector is XORed with the check-in random key to generate a binary ciphertext vector. The obtained binary ciphertext vector, salt vector, and mask vector are used to generate a marker auxiliary data vector.

4. The method for generating and distributing physical layer keys for a star-shaped Internet of Things (IoT) according to claim 1, characterized in that, Each edge node performs feature extraction and quantization on the received probe signal to obtain the corresponding quantized feature vector on the edge node side. The specific method is as follows: Extract the channel feature vector corresponding to the probe signal; The obtained channel feature vector is quantized using the median quantization method to obtain the quantized feature vector.

5. The physical layer group key generation and distribution method for star-shaped Internet of Things according to claim 1, characterized in that, The binary key corresponding to the edge node is generated by using the obtained labeled auxiliary data matrix and the quantized feature matrix corresponding to the edge node as input to the fuzzy extractor. The specific method is as follows: The obtained quantized feature vector and the labeled auxiliary data matrix are used as inputs to the Rep algorithm of the fuzzy extractor to obtain the labeled auxiliary data vectors corresponding to the edge nodes; Based on the obtained marker auxiliary data vector, the binary ciphertext vector, salt value vector, and mask vector are obtained; The obtained quantized feature vector and mask vector are bitwise ANDed to obtain a binary vector; The obtained binary vector is hashed to generate a binary digest vector; The binary key vector is obtained by performing an XOR operation between the obtained binary digest vector and the binary ciphertext vector.

6. A physical layer group key generation and distribution system for star-shaped Internet of Things (IoT), characterized in that, Based on a star network structure, this star network structure includes a central node and N The edge nodes include: An edge node signal transmitting unit is used for each edge node to send a probe signal to the central node, wherein the probe signal is a device ID number used as marker data; The signal processing unit on the central node side is used to extract and quantize the features of each received detection signal to obtain the corresponding quantized feature matrix on the central node side. The central node-side key generation unit is used to input the quantized feature matrix corresponding to the central node side into the fuzzy extractor to generate a random key with verification and a labeled auxiliary data vector. The tag-aid data vector corresponding to each detection signal is combined with the corresponding tag data to form a tag-aid data matrix; The central node-side auxiliary data distribution unit is used to broadcast the obtained tag auxiliary data matrix to each edge node; The edge node-side signal processing unit is used to extract and quantize the received detection signals to obtain the corresponding quantized feature vectors at the edge node side. The edge node-side key extraction unit is used to generate the binary key corresponding to the edge node side by using the obtained tag auxiliary data matrix and the quantized feature vector corresponding to the edge node side as inputs to the fuzzy extractor. The edge node-side key distribution unit is used to verify the binary key corresponding to the edge node side. If the verification is successful, the key distribution is completed.

7. A computer device, characterized in that, include: A processor is used to execute computer programs; A computer-readable storage medium storing a computer program, which, when executed by the processor, performs the generation and distribution method as described in any one of claims 1-5.

8. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the generation and distribution method as described in any one of claims 1-5.

9. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the generation and distribution method as described in any one of claims 1-5.

10. A chip, characterized in that, A memory on which computer programs are stored; A processor for executing the computer program in the memory to implement the steps of the generation and distribution method according to any one of claims 1-5.

Citation Information

Patent Citations

  • Lightweight group key distribution method based on wireless channel feature

    CN108696867A

  • Physical layer security key extraction method based on fuzzy extractor negotiation

    CN113746624A