Method, device and system for determining secret key, and storage medium

By extracting channel randomness information from the estimated channel matrix and quantizing it into the quotient group of discrete integer domains, and generating physical layer keys, the problem of large sum of calculation overhead in the prior art is solved, and efficient and secure key generation is achieved, which is suitable for 6G networks.

CN120264272APending Publication Date: 2025-07-04HUAWEI TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202410012245.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-03
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

The prior art requires obtaining the empirical distribution of the estimated channel and its related information when generating the key, resulting in large calculation overhead and extended processing time, and the generated key quality does not meet the uniform distribution requirements, making it difficult to meet the security needs of the 6G network.

Method used

By extracting channel randomness information from the estimated channel matrix and quantizing it to the quotient group in the discrete integer domain, the quotient group mapping function is used to generate the physical layer key, which avoids dependence on empirical distribution, saves calculation overhead and processing delay, and ensures the uniform distribution of the keys.

Benefits of technology

It realizes the generation of high-quality uniformly distributed keys without obtaining channel experience distribution parameters, which improves the efficiency and security of key generation, and is suitable for the link-level endogenous security mechanism of 6G networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120264272A_ABST
    Figure CN120264272A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a method for determining a secret key, a communication device, a system and a storage medium. In the method, a communication device extracts channel randomness information from an estimated channel matrix. The communication device then quantizes the channel randomness information, where the quantized channel randomness information belongs to a quotient group of the discrete integer field. Next, the communication device determines a physical layer key based on the quantized channel randomness information. Thus, in the embodiment of the invention, the communication device does not need to acquire the empirical distribution of the estimated channel and the related information thereof when generating the key, the calculation overhead and the processing delay are saved, the generated key can meet the uniform distribution requirement, and the key quality is high.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure generally relates to the field of communications, and more particularly to a method, apparatus, system, and computer-readable storage medium for determining a key. Background Art

[0002] Future 6G networks face various security threats. First, the continuous progress of computing technology poses challenges to the cryptographic security system based on computational complexity. For example, since modern cryptography is built on the classical computational complexity theory, with the development of computing technology, especially the increasing maturity of quantum computing, the security of classical cryptographic technologies is challenged. Second, the openness of the wireless channel leads to vulnerability of signal transmission to attacks, and the air interface defense mechanism of cellular networks needs to be further improved. How to strengthen the underlying defense barrier of wireless networks is an important issue that needs to be solved in 6G network security. Moreover, new applications such as positioning and sensing pose new requirements for signal-level security, and high-layer cryptographic technologies are difficult to meet this requirement: In addition to providing enhanced user experiences on the basis of 5G, 6G will also empower many new applications. Due to the lack of a signal-level integrity protection mechanism, if the signals used for ranging and positioning are easily tampered with, serious consequences will occur in some applications (such as smart car keys and contactless payments), and high-layer encryption is difficult to solve the above problems. The "plug-in" security mechanism that solely relies on high-layer cryptography will face severe challenges in the 6G era, and there is an urgent need to study the inborn security mechanism at the link level. Summary of the Invention

[0003] Embodiments of the present disclosure provide a method, apparatus, system, and computer-readable storage medium for determining a key, such that when generating a key, it is not necessary to obtain the empirical distribution of the estimated channel and its related information, and the computational overhead and processing delay are saved. The generated key can meet the uniform distribution requirement, and the key quality is high.

[0004] In a first aspect, a method for determining a key is provided. The execution subject of the method may be a communication device, such as a terminal device or a chip in the terminal device, or a network device or a chip in the network device. Hereinafter, the case where the execution subject is a terminal device or a network device will be taken as an example for description. In this method, the communication device extracts channel randomness information from the estimated channel matrix. In addition, the communication device quantifies the channel randomness information, where the quantified channel randomness information belongs to the quotient group of the discrete integer domain. Moreover, the communication device determines a physical layer key based on the quantified channel randomness information. In this way, the key for security is extracted from the wireless channel itself, without obtaining the empirical distribution of the estimated channel and its related information, and the computational overhead and processing delay are saved. The generated key can meet the uniform distribution requirement, and the key quality is high.

[0005] In some implementations, the channel randomness information is quantized by a first mapping function determined based on quantization levels. In this way, a uniformly distributed key can be obtained.

[0006] In some implementations, during the quantization of the channel randomness information, the communication device maps the channel randomness information from its domain to a first numerical interval based on a second mapping function, obtaining the value of the channel randomness information in the first numerical interval. In addition, the communication device maps the value of the channel randomness information in the first numerical interval to the quotient group of the discrete integer domain through the first mapping function. In this way, using the value of the second mapping function as the parameter of the first mapping function and adopting a mapping method based on the quotient group (or group homomorphism), instead of the hard decision of the truncation interval based on the threshold value, to avoid quantization errors caused by threshold design during the decision process, and a uniformly distributed key can be obtained.

[0007] In some implementations, the first parameter of the first mapping function is obtained based on the output of the second mapping function, and the second parameter of the first mapping function is obtained based on the quantization level. In this way, the parameters of the first mapping function are constructed using the output of the second mapping function and the quantization level, so that the generated key can meet the requirements of uniform distribution, has high key quality, and saves computational overhead and processing delay.

[0008] In some implementations, the channel randomness information is the real part or the imaginary part of the element value of the estimated channel matrix, and the second mapping function is the cumulative distribution function of the standard normal distribution. In this way, randomness information can be obtained from the real part or the imaginary part of the element value of the estimated channel matrix without empirical distribution parameters and a uniformly distributed physical layer key can be generated, and it can also be compatible with scenarios where empirical distribution parameters of the real part or the imaginary part of the element value can be obtained more accurately.

[0009] In some implementations, the channel randomness information is the modulus value of the element value of the estimated channel matrix, and the second mapping function is the cumulative distribution function of the Rayleigh distribution. In this way, randomness information can be obtained from the modulus value of the element value of the estimated channel matrix without empirical distribution parameters and a uniformly distributed physical layer key can be generated, and it can be compatible with scenarios where empirical distribution parameters of the modulus value of the element value can be obtained more accurately.

[0010] In some implementations, the channel randomness information is the square of the modulus value of the element value of the estimated channel matrix, and the second mapping function is a function defined based on the exponential distribution characteristics. In this way, randomness information can be obtained from the square of the modulus value of the element value of the estimated channel matrix without empirical distribution parameters and a uniformly distributed physical layer key can be generated, and it can be compatible with scenarios where empirical distribution parameters of the square of the modulus value of the element value can be obtained more accurately.

[0011] In some implementations, the channel randomness information is the argument of the element value of the estimated channel matrix, and the second mapping function is a function defined based on the argument. It can be compatible with the processes of the above other solutions, and also includes more comprehensive theoretical explanations and calculation methods, saving computational costs.

[0012] In some implementations, the input of the second mapping function can be the channel randomness information normalized based on the empirical distribution parameters. Alternatively, the input of the second mapping function can be the channel randomness information. In this way, scenarios using empirical distribution parameters can be compatible, so that in scenarios where relatively accurate empirical distribution parameters can be obtained, hard decisions on the truncation interval based on the threshold value can be avoided, and high-quality keys can be generated, saving the computational process.

[0013] In some implementations, the channel randomness information is the argument of the element value of the estimated channel matrix, and the second mapping function is the cumulative distribution function of the uniform distribution in the interval [0, 2π]. Based on the value of the cumulative distribution function of the uniform distribution in the interval [0, 2π] corresponding to the argument, as the parameter of the first mapping function, a mapping method based on the quotient group can be realized, and randomness information can be obtained from the argument of the element value of the estimated channel matrix without empirical distribution parameters, and a physically-layer key with a uniform distribution can be generated. Also, it can be compatible with scenarios where relatively accurate empirical distribution parameters of the argument of the element value can be obtained.

[0014] In some implementations, the channel randomness information is the argument of the element value of the estimated channel matrix, the first parameter of the first mapping function is obtained based on the argument, and the second parameter of the first mapping function is obtained based on the quantization level. The argument is directly used as the parameter of the first mapping function, so that a mapping method based on the quotient group can be realized, and randomness information can be obtained from the argument of the element value of the estimated channel matrix without empirical distribution parameters, and a physically-layer key with a uniform distribution can be generated. Also, it can be compatible with scenarios where relatively accurate empirical distribution parameters of the argument of the element value can be obtained.

[0015] In some implementations, the first mapping function is used to scale the interval corresponding to the first parameter from the first interval to the second interval and then map it to the quotient group of the discrete integer domain, where the upper limit of the second interval is an integer multiple of the quantization level. In this way, two adjacent high-probability values can be mapped to different integer values to obtain the discrete integer values for generating keys.

[0016] In some implementations, the first mapping function is used to scale the interval corresponding to the first parameter and then map it to the quotient group of the discrete integer domain. The upper limit of the scaled interval is an integer multiple of the quantization level, and when the input of the second mapping function is the channel randomness information without being normalized using the empirical distribution parameter, the integer multiple is greater than a preset threshold. After the magnification factor, the output integers can follow a uniform distribution. Based on the calculation of group homomorphism, adjacent two high-probability values can be mapped to different integer values to obtain the discrete integer values for generating keys.

[0017] In some implementations, the channel randomness information is determined based on the mode selected by the first communication device that executes the method, and the mode is (i) determined by the protocol, or (ii) determined by the signaling interaction between the first communication device and the second communication device, where the first communication device communicates with the second communication device using the physical layer key, or a combination of (i) and (ii). In this way, keys are generated based on different modes to improve the key quality.

[0018] In some implementations, the selection of the mode is based on the channel condition between the first communication device and the second communication device. In this way, based on different channel conditions, keys can be generated by estimating different amounts of the element values of the channel matrix, resulting in high-quality generated keys.

[0019] In some implementations, it further includes: receiving or sending an indication of an updated mode when at least one of the channel conditions changes. In this way, when the channel condition changes, the element values of the estimated channel matrix on which the key generation is based can be flexibly switched to generate high-quality keys.

[0020] In some implementations, the channel randomness information is extracted based on the indices of the element values in the estimated channel matrix. This enables the determination of the positions of the element values of the estimated channel matrix according to the indices, and thus the selection of the element values that meet the requirements to generate keys.

[0021] In some implementations, the first communication device and the second communication device that execute the method pre-agree on the indices, where the first communication device communicates with the second communication device using the physical layer key, or the first communication device and the second communication device determine the indices through signaling interaction, or a combination of pre-agreement and signaling interaction can be used. In this way, the element values of the estimated channel matrix can be selected in multiple ways, with flexible methods.

[0022] In a second aspect, a communication device is provided. For the beneficial effects, reference can be made to the description of the second aspect and will not be elaborated here. The communication device has the functions to implement the actions in the method examples of the above second aspect. The functions can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions. In a possible design, the communication device includes an extraction unit for extracting channel randomness information from an estimated channel matrix. The communication device further includes a quantization unit for quantizing the channel randomness information, where the quantized channel randomness information belongs to the quotient group of the discrete integer domain. The communication device further includes a determination unit for determining a physical layer key based on the quantized channel randomness information.

[0023] In a third aspect, a device is provided, including: a processor and a memory storing computer programs or instructions, where the computer programs or instructions, when executed by the processor, cause the electronic device to execute any of the methods according to the first aspect and its implementations.

[0024] In a fourth aspect, a computer-readable storage medium is provided. The computer-readable storage medium stores computer programs or instructions, where the computer programs or instructions, when executed by an electronic device, cause the electronic device to execute the methods performed by the device in the above aspects.

[0025] In a fifth aspect, a computer program (product) is provided. The computer program (product) includes computer programs or instructions, where the computer programs or instructions, when executed by an electronic device, cause the electronic device to execute the methods performed by the device in the above aspects.

[0026] In a sixth aspect, an embodiment of the present disclosure provides a chip system. The chip system includes a processor for implementing the functions of the device in the methods of the above aspects. In a possible design, the chip system further includes a memory for storing computer programs or instructions and / or data. The chip system can be composed of chips or can include chips and other discrete devices.

[0027] In a seventh aspect, an embodiment of the present disclosure further provides a system for determining a key, including: a communication device for executing the method of the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] Figure 1A A schematic diagram of a communication system showing some embodiments of the present disclosure is presented.

[0029] Figure 1B A schematic diagram of a key generation process is presented.

[0030] Figure 2 A schematic diagram of a process for determining a key showing some embodiments of the present disclosure is presented.

[0031] Figure 3 The flowchart shows the process of determining the key for some other embodiments of the present disclosure.

[0032] Figure 4 The flowchart shows the process of determining the key in an example scenario for some other embodiments of the present disclosure.

[0033] Figure 5 shows the schematic diagram of the distribution followed by the output of the second mapping function in an example scenario for some embodiments of the present disclosure.

[0034] Figure 6 The flowchart shows the process of determining the key in an example scenario for some other embodiments of the present disclosure.

[0035] Figure 7 The flowchart shows the process of determining the key in an example scenario for some other embodiments of the present disclosure.

[0036] Figure 8 The schematic diagram shows the distribution followed by the output of the second mapping function in an example scenario for some other embodiments of the present disclosure.

[0037] Figure 9 The flowchart shows the process of determining the key in an example scenario for some other embodiments of the present disclosure.

[0038] Figure 10 The schematic diagram shows the distribution followed by the output of the second mapping function in an example scenario for some other embodiments of the present disclosure.

[0039] Figure 11 The flowchart shows the process of determining the key in an example scenario for some other embodiments of the present disclosure.

[0040] Figure 12 The flowchart shows the process of determining the key in an example scenario for some other embodiments of the present disclosure.

[0041] Figure 13 The flowchart shows the signaling configuration process in an example scenario for some embodiments of the present disclosure.

[0042] Figures 14A to 14F The schematic diagram shows the comparison of simulation results for some embodiments of the present disclosure.

[0043] Figure 15 The flowchart shows the schematic process implemented at a communication device for some embodiments of the present disclosure.

[0044] Figure 16 The schematic diagram shows the main components of an example device for a possible implementation manner in the embodiments of the present disclosure.

[0045] Figure 17A simplified block diagram of an example device in a possible implementation manner in an embodiment of the present disclosure is shown. Detailed implementation manners

[0046] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although some embodiments of the present disclosure are shown in the drawings, it should be understood that the embodiments of the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. On the contrary, these embodiments are provided to more thoroughly and completely understand the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are only for exemplary purposes and are not used to limit the protection scope of the present disclosure.

[0047] In the description of the embodiments of the present disclosure, the term "including" and its like should be understood as an open inclusion, that is, "including but not limited to". The term "based on" should be understood as "at least partially based on". The term "one embodiment" or "the embodiment" should be understood as "at least one embodiment". Terms such as "first", "second", etc. may refer to different or the same objects. There may also be other explicit and implicit definitions hereinafter.

[0048] The embodiments of the present disclosure can be implemented according to any suitable communication protocol, including but not limited to, cellular communication protocols such as the third generation (3G), fourth generation (4G), fifth generation (5G), and future communication protocols (e.g., sixth generation (6G)), wireless local area network communication protocols such as Institute of Electrical and Electronics Engineers (IEEE) 802.11, and / or any other protocol known currently or developed in the future. The technical solutions provided in this application can also be applied to device-to-device (D2D) communication, vehicle-to-everything (V2X) communication, machine-to-machine (M2M) communication, machine type communication (MTC), and Internet of Things (IoT) communication systems or other communication systems.

[0049] Figure 1A A schematic diagram of a communication system in some embodiments of the present disclosure is shown. As Figure 1AAs shown, the method for determining a key provided by an embodiment of the present disclosure can be applied to a communication system 100, such as a wireless communication system like 5G, satellite communication, etc. In the communication system 100, a terminal device 110 and a network device 120 are shown. Either the terminal device 110 or the network device 120 can be used to determine a key, and then use the determined key to encrypt the signal / data / information to be sent to the other party. In addition to transmitting the signal / data / information for communication between the terminal device 110 and the network device 120, some signaling configurations for generating the key can also be transmitted, such as information about mode selection, where the mode is related to the channel condition between the terminal device 110 and the network device 120, so as to determine the key through different modes for different channel conditions. The signaling configuration can be sent from the terminal device 110 to the network device 120. Alternatively, the signaling configuration can be sent from the network device 120 to the terminal device 110. It should be noted that Figure 1A the terminal device 110 and the network device 120 are taken as examples for illustration, and the communication system 100 can include any number of terminal devices or network devices.

[0050] The communication system 100 in the embodiments of the present disclosure includes, but is not limited to: narrow band-Internet of things (NB-IoT), global system for mobile communications (GSM), enhanced data rate for GSM evolution (EDGE), wideband code division multiple access (WCDMA), code division multiple access 2000 (CDMA2000), time division-synchronization code division multiple access (TD-SCDMA), long term evolution (LTE), and the three application scenarios of the 5G mobile communication system, namely enhanced mobile broadband (eMBB), ultra-reliable low-latency communication (URLLC), and enhanced machine type communication (eMTC). The solution in the embodiments of the present disclosure can be applied to the time-division duplexing (TDD) scenario to improve the consistency rate of physical layer key generation under non-ideal channel reciprocity conditions. TDD is a duplex mode of a communication system and is used to separate the receiving and transmitting channels (or uplink and downlink) in a mobile communication system. In a mobile communication system with the TDD mode, receiving and transmitting are in different time slots of the same frequency channel, i.e., the carrier, and the receiving and transmitting channels are separated by ensuring time. This solution is applicable to any wireless network scenario including a transmitting end and a legitimate receiving end, and such a scenario can exist in various communication systems, including but not limited to: GSM system, CDMA system, WCDMA system, GPRS system, LTE system, LTE-A system, UMTS system, 5G system, beyond 5G (B5G) system, etc.

[0051] It should be understood that the above wireless communication system can be applicable to high-frequency scenarios such as millimeter waves (above 6G) and low-frequency scenarios (sub6G). The application scenarios of the wireless communication system include, but are not limited to, communication systems such as the fifth-generation system (5G), new radio (NR) communication systems, etc., or future communication systems such as future evolved public land mobile network (PLMN) systems. Embodiments of the present disclosure can also be used in Wi-Fi network scenarios, such as generating physical layer security keys and endogenous security mechanisms in Wi-Fi scenarios. Embodiments of the present disclosure can also be combined with various key generation schemes that require extracting randomness from channel estimation.

[0052] In the embodiments of the present disclosure, the term "terminal" or "terminal device" refers to any terminal device capable of performing wired or wireless communication between a network device and itself or between each other. A terminal device can sometimes be referred to as a user equipment (UE). The terminal device can be any type of mobile terminal, fixed terminal, or portable terminal. The terminal device can be various wireless communication devices with wireless communication functions. For example, the terminal device (such as Figure 1A the terminal device 110 shown) can be a user equipment, a terminal, an access terminal, a terminal unit, a terminal station, a mobile station (MS), a remote station, a remote terminal, a mobile terminal, a wireless communication device, a terminal agent, or a terminal device, etc. The terminal device can also be a communication chip with a communication module, or a vehicle with a communication function, or in-vehicle equipment (such as an in-vehicle communication device, an in-vehicle communication chip), etc. The terminal device can have wireless transceiver functions, and it can communicate (such as wireless communication) with one or more network devices of one or more communication systems and receive network services provided by the network devices. Here, the network devices include, but are not limited to, access network devices. User equipment includes, but is not limited to, mobile terminals, mobile telephones, handsets, portable equipment, mobile stations, computers with wireless communication functions, etc. User equipment can be portable, pocket-sized, handheld, computer-integrated, vehicle-mounted, aircraft-mounted, etc. mobile devices. User equipment can communicate with one or more core networks through a radio access network (RAN).

[0053] Among them, the terminal device can be a cellular phone, cordless phone, session initiation protocol (SIP) phone, wireless local loop (WLL) station, personal digital assistant (PDA) device, handheld device with wireless communication function, computing device or other processing device connected to a wireless modem, vehicle-mounted device, wearable device, terminal device in the future 5G or 6G network, or terminal device in the future evolved PLMN network, etc.

[0054] Specifically, the terminal device can be a mobile phone, tablet (pad), computer with wireless transceiver function, virtual reality (VR) terminal, augmented reality (AR) terminal, wireless terminal in industrial control, wireless terminal in self-driving, wireless terminal in remote medical, wireless terminal in smart grid, wireless terminal in transportation safety, wireless terminal in smart city, wireless terminal in smart home, etc.

[0055] In addition, the terminal device can be deployed on land, including indoor or outdoor, handheld or vehicle-mounted. The terminal device can also be deployed on water (such as ships, etc.). The terminal device can also be deployed in the air (such as airplanes, balloons, satellites, etc.).

[0056] Various devices with wireless communication functions can be used to connect people, things, machines, etc. The terminal device can be widely applied to various scenarios, such as: cellular communication, D2D, V2X, peer to peer (P2P), M2M, MTC, IoT, virtual reality (VR), augmented reality (AR), industrial control, autonomous driving, remote medical, smart grid, smart furniture, smart office, smart wear, smart transportation, smart city drones, robots, remote sensing, passive sensing, positioning, navigation and tracking, autonomous delivery and other scenarios. The terminal device can be the terminal in any of the above scenarios, such as MTC terminal, IoT terminal, etc. The terminal device can be a third-generation partnership project (3 rdUser equipment (UE), terminal, fixed device, mobile station device, or mobile device, subscriber unit, handheld device, in-vehicle device, wearable device, cellular phone, smart phone, SIP phone, wireless data card, personal digital assistant (PDA), computer, tablet computer, laptop computer, wireless modem, handset, laptop computer, computer with wireless transceiver function, smart book, vehicle, satellite, global positioning system (GPS) device, target tracking device, aircraft (such as drone, helicopter, multi-helicopter, quadcopter, or airplane, etc.), ship, remote control device, smart home device, industrial device, or a device built into the above devices (such as a communication module, modem, or chip in the above devices), or other processing devices connected to a wireless modem. For the convenience of description, the terminal device will be described below by taking the terminal or UE as an example. In some scenarios, the terminal device can also be used as a base station. For example, the terminal device can act as a scheduling entity, which provides sidelink signals between UEs in scenarios such as V2X, D2D, or P2P.

[0057] In the embodiments of the present application, the device for implementing the functions of the terminal device can be the terminal device or a device capable of supporting the terminal device to implement the functions, such as a chip system or a chip, and this device can be installed in the terminal device. In the embodiments of the present application, the chip system can be composed of chips or can include chips and other discrete devices.

[0058] The network device in the embodiments of this application can be a device for communicating with a terminal device. This network device can also be referred to as an access network device or a radio access network device. For example, the network device can be an access network device (or an access site). Among them, an access network device refers to a device with network access capabilities, such as a radio access network (RAN) base station, etc. Specifically, the network device can include a base station (BS), or include a base station and a radio resource management device for controlling the base station, etc. The network device can also include a relay station (relay device), an access point, and a base station in a 5G network or an NR base station, a base station in a future evolved PLMN network, etc. The network device can be a wearable device or a vehicle-mounted device. The network device can also be a communication chip with a communication module. The base station includes but is not limited to a general base station (such as a gNB, eNB, or NodeB, etc.), a radio remote unit (RRU), a macro station, a pico station (pico, femto, etc.), a relay, an access point (AP) with wireless transceiver functions, a transmission reception point (TRP), or any other wireless access device.

[0059] The term "network node" or "network device" used in the embodiments of the present disclosure is an entity or node that can be used to communicate with a terminal device. For example, it can be an access network device. An access network device can be a device deployed in a radio access network to provide wireless communication functions for mobile terminals. For example, it can be a radio access network (RAN) network device. The access network device can include various types of base stations. The base station is used to provide wireless access services for terminal devices. For example, network devices (such as access network devices 120, 130) include, but are not limited to: g node B (gNB) in 5G, evolved node B (eNB) in the long term evolution (LTE) system, radio network controller (RNC), radio controller under a cloud radio access network (CRAN) system, base station controller (BSC), home base station (e.g., home evolved node B, or home node B, HNB), baseband unit (BBU), transmitting and receiving point (TRP), transmitting point (TP), mobile switching center. It can also be an evolutional NB (eNB or eNodeB) in LTE, or a base station device in a future 5G network or an access network device in a future evolved PLMN network. It can also be a wearable device or a vehicle-mounted device.

[0060] In some deployments, the network device can be a centralized unit (CU) or a distributed unit (DU). The network device can also include an active antenna unit (AAU). The CU implements some functions of the network device, and the DU implements some functions of the network device. For example, the CU is responsible for processing non-real-time protocols and services and implementing the functions of the radio resource control (RRC) layer and the packet data convergence protocol (PDCP) layer. The DU is responsible for processing physical layer protocols and real-time services and implementing the functions of the radio link control (RLC) layer, the media access control (MAC) layer, and the physical (PHY) layer. The AAU implements some physical layer processing functions, radio frequency processing, and related functions of active antennas. Since the information of the RRC layer will ultimately become the information of the PHY layer, or is transformed from the information of the PHY layer, thus, in this architecture, high-layer signaling, such as RRC layer signaling, can also be considered to be sent by the DU, or sent by the DU + AAU. It can be understood that the network device can be a device including one or more of the CU node, DU node, and AAU node. In addition, the CU can be classified as a network device in the radio access network (RAN), or the CU can be classified as a network device in the core network (CN), and this application does not make a limitation on this. Examples of network devices include but are not limited to Node B (NodeB or NB), evolved Node B (eNodeB or eNB), next-generation Node B (gNB), transmit receive point (TRP), remote radio unit (RRU), radio head (RH), remote radio head (RRH), integrated access and backhaul (IAB) node, low-power nodes such as femto nodes, pico nodes, reconfigurable intelligent surface (RIS), network-controlled repeaters, etc. In different communication systems, the CU (or CU-CP and CU-UP), DU, or RU may also have different names, but those skilled in the art can understand their meanings. For example, in the ORAN system, the CU can also be called O-CU (open CU), the DU can also be called O-DU, the CU-CP can also be called O-CU-CP, the CU-UP can also be called O-CU-UP, and the RU can also be called O-RU.For the convenience of description, in this application, CU, CU-CP, CU-UP, DU, and RU are taken as examples for description. Any one of the CU (or CU-CP, CU-UP), DU, and RU in this application can be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.

[0061] In addition, a network device such as an access network device can be connected to a core network (CN) device, and the core network device can be used to provide core network services for the access network device and the terminal device. The core network device can correspond to different devices under different systems. For example, in 3G, the core network device can correspond to a serving GPRS support node (SGSN) and / or a gateway GPRS support Node (GGSN) of a general packet radio system (GPRS). In 4G, the core network device can correspond to a mobility management entity (MME) and / or a serving gateway (S-GW). In 5G, the core network device can correspond to an access and mobility management function (AMF), a session management function (SMF), or a user plane function (UPF).

[0062] The base station can be fixed or mobile. For example, a helicopter or a drone can be configured to act as a mobile base station, and one or more cells can move according to the position of the mobile base station. In other examples, a helicopter or a drone can be configured to be used as a device for communicating with another base station.

[0063] In the embodiments of this application, the device for implementing the functions of the network device can be a terminal device or a device capable of supporting the network device to implement the functions, such as a chip system or a chip, and the device can be installed in the network device. In the embodiments of this application, the chip system can be composed of chips or can include chips and other discrete devices.

[0064] The network device and the terminal device can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; they can also be deployed on water; they can also be deployed on airplanes, balloons, and satellites in the air. In the embodiments of this application, the scenarios where the network device and the terminal device are located are not limited.

[0065] The RAN can be a 3GPP-related cellular system, for example, a 4G or 5G mobile communication system, or an evolved system for the future (such as a 6G mobile communication system). The RAN can also be an open RAN (O-RAN or ORAN), a cloud RAN (CRAN), or a wireless fidelity (WiFi) system. The RAN can also be a communication system that integrates two or more of the above systems.

[0066] An embodiment of the present disclosure proposes a scheme for determining a key for network security. Currently, the "plug-in" security mechanism that solely relies on high-level cryptography will face severe challenges in the 6G era, and there is an urgent need to study the in-built security mechanism at the link level. The implementation of in-built security at the link level includes: in-built security resources. In-built security resources mean that the resources for achieving security come from within the communication system, such as wireless channels, random noise, terminal hardware, etc., rather than being distributed externally. There are mainly two advantages of in-built resources. One is to ensure the rich and continuous supply of randomness, providing a prerequisite for achieving strong security. The other is to minimize the security risks and additional overheads brought by external distribution.

[0067] Figure 1B A schematic diagram of a key generation process is shown. In the process 100-1 of physical layer key generation, the receiving and transmitting ends need to go through steps such as channel measurement (101), quantization (103), information reconciliation (105), determining whether the information reconciliation is consistent (107), and privacy amplification (109) when the information reconciliation is inconsistent or returning to the channel measurement step when the information reconciliation is consistent in the process 100-1 to obtain a consistent key. Among them, in some schemes, the quantization step needs to determine a quantization threshold so that the finally generated key satisfies a uniform distribution. To achieve this goal, when generating a key based on information of a wireless channel, it is necessary to know the statistical distribution characteristics of the channel h (or a quantity related to it, such as the modulus of h), and the statistical distribution characteristics can be approximated by an empirical distribution.

[0068] To obtain a relatively reliable empirical distribution and determine a reasonable quantization threshold based on it, a large amount of channel observation data usually needs to be collected. In some solutions, single-threshold quantization is used, that is, both the transmitter and the receiver extract random factors from the legitimate channel, perform quantization according to the single threshold, and generate key bits. The transmitter and the receiver respectively estimate the channel state (matrix H) based on a large amount of collected data, and determine the quantization threshold value based on the empirical distribution of the estimated channel. There are also some solutions that use double-threshold quantization. The double-threshold quantization scheme can alleviate the error problem faced by single-threshold quantization and improve the consistency of the key. Double-threshold quantization adds a guard band at both ends of the single threshold value. When the channel information belongs to the range of the guard band, this channel information is not used to generate the key. Double-threshold quantization results in a lower key utilization rate because some channel estimates are discarded. For channel estimates close to the double threshold, a large amount of data still needs to be collected during quantization to obtain a relatively accurate empirical distribution of the channel state.

[0069] The above solutions based on single-threshold quantization or double-threshold quantization will result in additional computational overhead and processing delay, and even if a large amount of observation data is collected, the obtained empirical distribution may still not be accurate enough, which will cause the finally generated key not to meet the uniform distribution requirement and affect the quality of key generation. Some embodiments of the present disclosure can implement the above quantization step 103 by adopting a solution different from the solution for determining the quantization threshold based on this process 100-1. In the process of determining the key in the embodiments of the present disclosure, there is no need to calculate the quantization threshold in the quantization step 103, thus saving computational effort, and in some embodiments, it may not be necessary to utilize the empirical distribution, thereby avoiding the problem that the empirical distribution obtained by collecting a large amount of observation data in the solution using the empirical distribution is still inaccurate, which in turn leads to low-quality generated keys.

[0070] Figure 2 A schematic diagram of the process for determining the key in some embodiments of the present disclosure is shown. As Figure 2 shown, process 200 involves the first communication device 210 or the second communication device 220, where the first communication device 210 can be one of the terminal device 110 or the network device 120, and the second communication device 220 can be the other of the terminal device 110 or the network device 120. For example, an example of the first communication device 210 is a UE (user equipment), and an example of the second communication device 220 is a base station. Or, an example of the first communication device 210 is a base station, and an example of the second communication device 220 is a UE. It should be noted that the first communication device 210 and the second communication device 220 are not limited to the specific examples listed above, and can also be other terminal devices or network devices.

[0071] In process 200, the first communication device 210 extracts (201) channel randomness information from the estimated channel matrix, and the first communication device 210 quantizes (203) the channel randomness information, where the quantized channel randomness information belongs to the quotient group of the discrete integer domain. In some examples, based on the homomorphism mapping of the quotient group, the channel estimate value is mapped from the continuous real number domain to the positive integer quotient group, and a physical layer key with a discrete real number domain and a uniform distribution is obtained. The quotient group is defined as follows:

[0072]

[0073] Among them, the quotient group only contains integers from 0 to n - 1, that is, the value space of the key bits. In some examples, the relationship between the quantization level m and the key length is as follows: If an n-bit key string needs to be generated, the quantization level m = 2 n . For example, to generate a 4-bit key string, the quantization level m = 2 4 , and the quantized value range is [0, 2 4 - 1]. The relationship between the quantization level m and the consistency rate is as follows: In order to ensure that the receiving end (such as the second communication device 220) can correctly decrypt the encrypted signal transmitted by the sending end (such as the first communication device 210), the quantization results used to generate the key must be consistent. When the channel condition is poor and the channel reciprocity between the receiving and sending ends is not ideal, the quantization results with fine granularity (i.e., high quantization level) are prone to cause an increase in the inconsistency rate, and the quantization results with coarse granularity can better solve this problem. The quantization level m can be determined with reference to but not limited to one or a combination of the following two methods: i) Use the feedback mode to compare the consistency rate of key generation at the receiving and sending ends, and use the comparison results of periodic feedback to adjust the quantization level. If the consistency rate is high, the quantization level is high, otherwise the quantization level is low; ii) The channel condition is affected by the real-time results of channel measurement. When the channel condition is good, the quantization level is high, otherwise the quantization level is low.

[0074] In some examples, the channel randomness information can be the real part of the element value of the estimated channel matrix, the imaginary part of the element value of the estimated channel matrix, the modulus value of the element value of the estimated channel matrix, the square of the modulus value of the element value of the estimated channel matrix, or the argument of the element value of the estimated channel matrix. In some embodiments, the channel randomness information can be quantized based on the first mapping function determined by the quantization level. In some examples, a mapping function based on the quotient group is defined using the quantization level m The output of this function is a non-negative integer in the discrete integer domain and belongs to the quotient group defined above. The first mapping function (where m is the quantization level) satisfies the following mapping relationship:

[0075]

[0076] In some examples, in the process of quantifying channel randomness information, the first communication device 210 may map the channel randomness information from its domain to a first numerical interval based on a second mapping function, and obtain the value of the channel randomness information in the first numerical interval. In some embodiments hereinafter, the second mapping function is defined as the function Φ(x). For different examples of channel randomness information, the specific form of the second mapping function Φ(x) may be different. For example, Φ(x) may be determined according to the distribution that the information corresponding to the selected mode follows. In some examples, Φ(x) may be the cumulative distribution function of the standard distribution of the corresponding distribution. Through the first mapping function, the value of the channel randomness information in the first numerical interval is mapped to the quotient group of the discrete integer domain. For example, the first parameter of the first mapping function is obtained based on the output of the second mapping function, the second parameter of the first mapping function is obtained based on the quantization level, the first parameter and the second parameter are used as the inputs of the first mapping function, and the value of the channel randomness information in the first numerical interval is mapped to the quotient group of the discrete integer domain. In different examples, the range of the first numerical interval may be different. For specific details, refer to the description of the embodiments hereinafter. In some other examples, instead of defining the second mapping function Φ(x), the first parameter of the first mapping function may be obtained based on the argument of the estimated element value of the channel matrix, and the second parameter of the first mapping function may be obtained based on the quantization level.

[0077] In some examples where the channel randomness information is the real part or the imaginary part of the estimated element value of the channel matrix, the second mapping function is the cumulative distribution function of the standard normal distribution. In some examples where the channel randomness information is the modulus value of the estimated element value of the channel matrix, the second mapping function is the cumulative distribution function of the Rayleigh distribution. In some examples where the channel randomness information is the square of the modulus value of the estimated element value of the channel matrix, the second mapping function is a function defined based on the exponential distribution characteristic. For example, the second mapping function Φ(x) = e -x , x ≥ 0, where e is the natural constant. In some examples where the channel randomness information is the argument of the estimated element value of the channel matrix, the second mapping function may be a function defined based on the argument. For example, the second mapping function Φ(x) = x. According to different examples, x is the argument θ or θ / α, where 0 ≤ θ ≤ 2π. Specifically refer to the key determination process 1100 for scenario five hereinafter. In some examples where the channel randomness information is the argument of the estimated element value of the channel matrix, the second mapping function may be the cumulative distribution function of the uniform distribution in the interval [0, 2π]. For example, the second mapping function In some examples, empirical distribution parameters can be utilized during the process of determining a key. Then, the input of the second mapping function can be based on the channel randomness information normalized by the empirical distribution parameters. In other examples, empirical distribution parameters may not be used during the process of determining a key. Then, the input of the second mapping function can be the channel randomness information (i.e., without being normalized by the empirical distribution parameters). In some examples, it is determined whether to input the empirical distribution parameter α according to the scenario requirements. If not input, α = 1 is defaulted.

[0078] In some examples, after the first mapping function scales the interval corresponding to the first parameter from the first interval to the second interval, it is then mapped to the quotient group of the discrete integer domain, where the upper limit of the second interval is an integer multiple (l times) of the quantization level. For example, when the input parameter is α, the output result c = Φ(x) of the Φ function follows a uniform distribution. Scale c to the interval [0, m) and map it to the quotient group In some examples, instead of using the channel randomness information normalized by the empirical distribution parameters, the input of the second mapping function uses an integer multiple of the input value of the empirical distribution parameter as the input value of the second mapping function, and the integer multiple of the input value of the empirical distribution parameter is greater than a preset threshold. For example, when the parameter α is not input. Scale c = Φ(x) to the interval [0, lm] and map it to the quotient group At this time, l is a positive integer and l can be greater than or equal to 40. For example, the value of l can be 1000. Among them, 1000 is an example value of the preset threshold. In other embodiments, the preset threshold can also be some other value, such as a certain integer greater than or equal to 40.

[0079] In some embodiments, for example, in the TDD scenario, each element value h of the wireless channel H between the transceiver ends can be modeled, and each element value h follows a complex Gaussian distribution: where α represents the large-scale fading information. Represents small-scale fading information. The angular information (argument) of h is denoted as θ = arg(h). The estimated channel value represented by each h and its related information can be used to generate a key. In some examples, the channel randomness information is determined based on the mode selected by the first communication device 210 that executes process 200. Different examples of the above channel randomness information can correspond to different modes selected for determining the key. The mode is related to the channel conditions, and the selection of the mode can be based on the channel conditions between the first communication device 210 and the second communication device 220. For example, one or more of the radio wave propagation mechanisms such as absorption, scattering, refraction, diffraction, scintillation, dispersion, etc. will have a certain impact on the amplitude and phase of the radio wave. The propagation mechanisms in some environments have a greater impact on the amplitude. When selecting the mode, amplitude-related information can be avoided as much as possible, and phase-related information such as real(h), imag(h), and θ can be preferentially used for quantization. The propagation mechanisms in some environments have a greater impact on the phase, and the amplitude is relatively stable. Then, when selecting the mode, amplitude-related information such as |h| and |h| can be preferentially selected for quantization 2 , where h represents the element value of the estimated channel matrix, and θ represents the argument of h. In some examples, the mode can be specified by a protocol. In other examples, the mode can be determined through signaling interaction between the first communication device 210 and the second communication device 220. For example, the first communication device 210 sends the selected mode to the second communication device 220, or the first communication device 210 receives the selected mode sent by the second communication device 220 from the second communication device 220. In the case where at least one of the channel conditions changes, the first communication device 210 can receive or send an indication for updating the selected mode

[0080] In some examples, the channel randomness information can be extracted based on the index of the element value in the estimated channel matrix. In some examples, the first communication device 210 and the second communication device 220 can pre-agree on this index, or the first communication device 210 and the second communication device 220 determine the index through signaling interaction. For example, the first communication device 210 sends the index to the second communication device 220, or the first communication device 210 receives the index sent by the second communication device 220 from the second communication device 220. For example, for the estimated channel matrix H measured by a channel sounding reference signal (SRS), the same-position h at the receiving and transmitting ends is selected to extract random information and generate key bits. Regarding the position of selecting h, it can be agreed upon by both parties through a protocol or can be used as interaction information to inform the other party

[0081] The first communication device 210 determines (205) the physical layer key based on the quantized channel randomness information. For example The output result η is converted into binary 01 bits, which are the key bits. Refer to Figure 1B In the privacy amplification step (109), in the privacy amplification step, the quantized key bits can generate a key stream through a hash function. As mentioned above, the first communication device 210 can be one of the terminal device 110 or the network device 120, that is, the method for determining the key in the embodiments of the present disclosure can be implemented in both the terminal device 110 and the network device 120. In some examples, after both the terminal device 110 and the network device 120 obtain the quantized key through this method, they respectively input it as the hash function. The values input by both parties to the hash function are the same, so the key stream output by the hash function is also the same.

[0082] In some embodiments, after determining the physical layer key, the first communication device 210 communicates with the second communication device 220 using the physical layer key. For example, the first communication device 210 can use the physical layer key to encrypt (207) the signal / data / information to be sent, and send (209) the encrypted signal / data / information 202 to the second communication device 220. The second communication device 220 can receive (211) the encrypted signal / data / information 202. It should be noted that in some embodiments, the operations corresponding to 207 and 209 can be optional steps.

[0083] Figure 3 A schematic flow chart of determining a key according to other embodiments of the present disclosure is shown. As Figure 3 As shown in process 300, at 301, channel information h is obtained, that is, the element value h in the estimated channel matrix is obtained. At 303, mode selection t is performed according to the channel condition. In some examples, the information of this mode selection can be the interactive signaling between the receiving and transmitting ends. As shown by the exemplary five modes 302a to 302e, they respectively correspond to the real part, imaginary part, modulus, square of the modulus, and argument of the element value h in the estimated channel matrix. Based on the selected mode, the corresponding function to be used is determined. This corresponding function is, for example, the cumulative distribution function of some examples mentioned above as the second mapping function, or another function defined based on the exponential distribution characteristic or argument as another example of the second mapping function. At 305, it is determined whether the input information has an empirical distribution parameter α. If there is this empirical distribution parameter α, then 307 is executed, that is, quantization is performed based on the empirical distribution parameter α and the quantization level m to generate a key. If there is no such empirical distribution parameter α, 309 is executed, that is, quantization is performed based on the quantization level m to generate a key. Embodiments of the present disclosure are based on the above multiple modes, where the real part, imaginary part, modulus |h|, square of the modulus |h| of the element value h in the estimated channel matrix corresponding to the mode 2, Arguments such as θ are information in the channel endogenous information that has an analytical form of mathematical modeling, considering the scenario comprehensively. The physical layer key generation method of the embodiments of the present disclosure can be combined with the physical layer encryption algorithm. In some examples, in the security module of the transmitting end (such as the first communication device 210), randomness information can be extracted from the estimated channel or its related information and quantified to generate a key. Encrypt the original information. In the TDD scenario, the air interface channel between the transceiver has reciprocity. After the receiving end obtains the estimated channel and its related information that is reciprocal to the transmitting end, randomness information is also extracted therefrom and key bits are generated. Decrypt the encrypted information received according to the key. To ensure the quality of the key and reduce the possibility that an illegal eavesdropper can improve the probability of obtaining the correct key according to the distribution law of the key, the solution of the embodiments of the present disclosure makes the keys used at both the transmitting and receiving ends satisfy a uniform distribution. In this way, even if the illegal eavesdropper collects a large amount of data, they can still only guess blindly. According to process 300, the use of the empirical distribution parameters is an optional solution. For example, when the channel condition is good and the empirical distribution approximation is relatively accurate, the empirical distribution parameters can be used to generate a key. When the channel condition is not ideal and the approximation of the empirical distribution is inaccurate, the use of the parameters of the empirical distribution to generate a key can be avoided. Thereby, the problem that due to the fact that the statistical distribution characteristics of the estimated channel cannot be obtained in practice and only the empirical distribution expressed by the sampled data of the estimated channel can be relied on to approximately estimate the statistical distribution of the channel, and the approximation may be inaccurate, and the problem that when the parameter error between the empirical distribution and the statistical distribution is large, the threshold value designed based on the empirical distribution may cause the finally quantified generated key not to conform to the uniform distribution and reduce the key quality are avoided.

[0084] The following Figure 4 (Corresponding to scenario one), Figure 6 (Corresponding to scenario two), Figure 7 (Corresponding to scenario three), Figure 9 (Corresponding to scenario four), Figure 11 (Corresponding to scenario five) and Figure 12 (Corresponding to scenario six) respectively show the processes of determining keys in different scenarios. Among them, the embodiments corresponding to scenarios one to six respectively show how to extract randomness information from the selected estimated channel related information and generate key bits under 5 different mode selections. Among them, scenarios five and six provide two implementation methods for extracting random information from the argument.

[0085] Figure 4 Shows a schematic diagram of the process of determining keys in an example scenario of some other embodiments of the present disclosure, which shows the process 400 of determining keys for the above-mentioned scenario one, and specifically illustrates how to extract randomness information k from the real part of the element value h of the estimated channel H based on the quotient group and quantify it. As Figure 4As shown, the first communication device (such as the first communication device 210) determines the function Φ (an example of the second mapping function) and (an example of the first mapping function), and there are two implementation methods according to whether the empirical distribution parameter α is input.

[0086] When the selected mode extracts random information from the real part of h for quantization, the mathematical modeling of the real part of h needs to be considered. As shown in 401, the random information k = real(h). The real part (real) of h follows a Gaussian distribution, that is:

[0087]

[0088] Determine (403) the function Φ and Specifically, construct the function Φ as the cumulative distribution function of the standard normal distribution as follows:

[0089]

[0090] This function maps the input real part of h defined on the real number field to the interval [0, 1]. In addition to defining the function Φ, a function determined by the quantization level m is also defined This function needs to satisfy the following mapping relationship:

[0091]

[0092] The meaning of this mapping relationship is: the function maps the real number on the interval [0, 1] to the quotient group of the discrete integer field according to the input parameter, and the function is specifically defined as follows:

[0093]

[0094] Among them, the quantization level m ≥ 2. Here, corresponding to the above mapping relationship, the first input parameter a ∈ [0, 1], and the second input parameter

[0095] After determining the definitions of the function Φ and , it is judged (405) whether the empirical distribution parameter α is input. The process of calculating the quantization result η can be implemented in two ways according to whether the empirical distribution parameter α is input:

[0096] Method 1: When α is input, use α to normalize the real part of h and use it as the input of the function Φ. As shown in 407a, when k = real(h), that is:

[0097]

[0098] At this time, the distribution of c follows a uniform distribution on the interval [0, 1], that is Input c and m into the function It can be mapped to the quotient group To achieve a discrete quantization process that follows a uniform distribution. Here, the calculation substitutes into the above function The expression, as shown in 409a, gives:

[0099]

[0100] Among them, the mod function is the modulo operation, and the specific definition is as follows:

[0101] mod(a, m) = a - m * floor(a / m)

[0102] The floor function rounds the input value to the closest integer less than or equal to the input value.

[0103] The function can first scale the value on the interval [0, 1] to [0, m], and then map it to If it is not scaled to [0, m], then all c, because they belong to the interval [0, 1], will be mapped to the integer 0. The second input parameter of the function can also be a positive integer multiple of m.

[0104] Method 2: When the empirical distribution parameter α is not input, it is defaulted that α = 1. Take the real part of h directly as the input value of the function Φ. As shown in 407b, when k = real(h), that is:

[0105] c = Φ(real(h))

[0106] At this time, the value range of c is in interval, following a bell-shaped curve distribution, and the parameters are unknown. In such a scenario, map c to the quotient group and ensure that the output integer η follows a uniform distribution. The function needs to scale c on I to the interval [0, lm], where l is a positive integer and l can be greater than or equal to 40. For example, the value of l can be 1000 (1000 is an example of a preset threshold) as an integer. After the magnification factor, it can make the output integer η follow a uniform distribution, which mainly benefits from the difference between the calculation based on group homomorphism and the traditional scheme (quantizing according to the threshold value so that the entire interval between adjacent threshold values has the same quantization result). Based on the calculation of group homomorphism, two adjacent high-probability values (such as Figure 5A and Figure 5B the values near the middle position in the bell-shaped curve in

[0107]

[0108] Among them, the value of the second input parameter used in the mod function comes from the subscript of, that is, the quantization level m, which does not change with the change of. The above Figure 5A and Figure 5B are examples of the distributions followed by the output of the second mapping function. Among them Figure 5A is a bell-shaped distribution curve in the interval [0, 1], Figure 5B is a bell-shaped distribution curve scaled to the interval [0, lm]. It can be seen that the scaling does not change the shape of the curve.

[0109] After obtaining the quantization result it is necessary to convert it into a binary bit string bist η ∈ {0, 1}, that is, the key bits, to determine the (411) physical layer key.

[0110] Figure 6 shows a schematic diagram of the process of determining the key in an example scenario of some embodiments of the present disclosure. Among them, a process 600 of determining the key for the above-mentioned scenario two is shown. In this process 600, the first communication device (for example, the first communication device 210 above) extracts randomness information from the imaginary part of the element value h of the estimated channel H and quantifies it, and determines the function Φ (an example of the second mapping function) and (an example of the first mapping function) based on the selected mode. Then, according to whether the empirical distribution parameter α is input, there are two implementation methods. When the selected mode is to extract random information from the imaginary part of h for quantization, it is necessary to consider the mathematical modeling of the imaginary part of h, as shown in 601, k = imag(h). Since h itself follows a complex Gaussian distribution, the imaginary part (imag) of h has the same modeling method as the real part of h in scenario one and both follow a Gaussian distribution, that is:

[0111]

[0112] Determine (603) the function Φ and Specifically, construct the function Φ as the cumulative distribution function of the standard normal distribution as follows:

[0113]

[0114] This function Φ maps the imaginary part of h defined on the real number domain to the interval [0, 1]. Here is the domain of the Gaussian distribution, which has nothing to do with whether the information comes from the real part or the imaginary part. Whether it is the information of the real part or the imaginary part, it is a real number. In addition to defining the function Φ, a function determined by the quantization level m is also defined. This function Satisfies the following mapping relationship:

[0115]

[0116] In other words, this function maps real numbers in the interval [0, 1] to the quotient group of the discrete integer domain according to the input parameters. It should be noted that the function is defined solely by the quantization level m and is independent of the mode selection (i.e., what amount of information about h the input source for extracting random information is). Therefore, regarding how to specifically define the function according to the quantization level m, reference can be made to the expression in Scenario 1 above .

[0117] After determining the definitions of the functions Φ and , it is judged whether the empirical distribution parameter α is input in (605). The process of calculating the quantization result η is divided into two implementation methods according to whether the empirical distribution parameter α is input:

[0118] In the first method, when α is input, the imaginary part of h is normalized with α and used as the input of the function Φ. As shown in 607a, when k = imag(h), that is:

[0119]

[0120] At this time, the distribution of c follows a uniform distribution on the interval [0, 1], that is Input c and m into the function to be mapped to the quotient group to achieve a discrete quantization process that follows a uniform distribution. Here, substitute into the expression of η, as shown in 609a:

[0121]

[0122] The function achieves the effect of first scaling the values in the interval [0, 1] to [0, m], and then mapping to If not scaled to [0, m], then all c, because they belong to the interval [0, 1], will be mapped to the integer 0. The second input parameter of the function can also be a positive integer multiple of m.

[0123] In the other method, when the empirical distribution parameter α is not input, it is defaulted that α = 1. The imaginary part of h is directly used as the input value of the function Φ. As shown in 607b, when k = imag(h), that is:

[0124] c = Φ(imag(h))

[0125] At this time, the value range of c is in On the interval, it follows a bell-shaped function distribution with unknown parameters. In such a scenario, map c to the quotient group and ensure that the output integer η follows a uniform distribution. The function needs to scale c on I to the interval [0, lm], where l is a positive integer and l can be greater than or equal to 40. For example, the value of l can be 1000. After the magnification factor, the output integer η can follow a uniform distribution. For specific details, refer to the relevant introduction to Scenario 1 above. Here, substitute into the η expression for calculation. As shown in 609b, when k = real(h):

[0126]

[0127] where the numerical value of the second input parameter used in the mod function comes from the subscript of, that is, the quantization level m, which does not change here with the change of. After obtaining the quantization result it can be converted into a binary bit string bits η ∈ {0, 1}, that is, the key bits, which determines the (611) physical layer key.

[0128] Figure 7 shows a schematic diagram of the process for determining the key in an example scenario of some other embodiments of the present disclosure, where it shows the process 700 for determining the key for the above Scenario 3. In this process 700, the first communication device (such as the first communication device 210 above) extracts randomness information from the modulus value of the element value h of the estimated channel H and quantifies it. Specifically, when extracting random information from the modulus value of h for quantization based on the selection mode, it is necessary to consider the mathematical modeling of the modulus value of h. As shown in 701, k = |h|. Since h itself follows a complex Gaussian distribution, the modulus value of h follows a Rayleigh distribution, that is:

[0129] (that is )

[0130] Determine (703) the function Φ and Specifically, since the input information source follows a Rayleigh distribution, accordingly construct the function Φ as the cumulative distribution function of the standard Rayleigh distribution, that is, when the parameter α = 1, as follows:

[0131]

[0132] The domain of the Rayleigh distribution is the non-negative real number domain Therefore, here the function Φ maps the input information on the non-negative real number domain, that is, the modulus value of h, to the interval [0, 1]. In addition to defining the function Φ, also define the function determined by the quantization level m. This function satisfies the following mapping relationship:

[0133]

[0134] In other words, this function maps real numbers in the interval [0, 1] to the quotient group of the discrete integer domain according to the input parameters. Define the function For details, see the relevant introduction in Scenario 1. After determining the definitions of the function Φ and judge whether the empirical distribution parameter α is input in (705). The process of calculating the quantization result η is divided into two implementation methods according to whether the empirical distribution parameter α is input:

[0135] In the first implementation method, when α is input, use α to complete the normalization of the modulus value of h and use it as the input of the function Φ, as shown in 707a. When k = |h|, that is:

[0136]

[0137] At this time, the distribution of c follows a uniform distribution on the interval [0, 1], that is Input c and m into the function Then it can be mapped to the quotient group to achieve a discrete quantization process that follows a uniform distribution. Calculate and substitute into the expression of η here, as shown in 709a, to obtain:

[0138]

[0139] The function The effect achieved is to first scale the values in the interval [0, 1] to [0, m], and then map them to If it is not scaled to [0, m], then all c, because they belong to the interval [0, 1], will be mapped to the integer 0. In some examples, the second input parameter of the function can also be a positive integer multiple of m.

[0140] In the second implementation method, when the parameter α of the empirical distribution is not input, it is defaulted that α = 1. Directly use the modulus value of h as the input value of the function Φ, as shown in 707b. When k = |h|, that is:

[0141] c = Φ(|h|)

[0142] At this time, the value range of c is in interval, and it follows an exponential curve distribution with unknown parameters. The exponential distribution curve is as Figure 8 shown, which is an example of the distribution followed by the output of the second mapping function. In such a scenario, map c to the quotient group and ensure that the output integer η follows a uniform distribution. The function It is necessary to scale c on I to the interval [0, lm], where l is an integer and l can be greater than or equal to 40. For example, the value of l can be 1000. After the magnification factor, the output integer η follows a uniform distribution. Based on the calculation of group homomorphism, adjacent two high-probability values (such as the values near the left position of the exponential distribution) can be mapped to different integer values. Substitute into the expression of η here, as shown in 709b, to get:

[0143]

[0144] where the numerical value of the second input parameter used in the mod function comes from the subscript of, that is, the quantization level m, which does not change with the change of. After obtaining the quantization result it is necessary to convert it into a binary bit string bits η ∈ {0, 1}, that is, the key bits, to determine the (711) physical layer key.

[0145] Figure 9 FIG. shows a schematic flow chart of determining a key in an example scenario of some embodiments of the present disclosure, in which a flow 900 of determining a key for scenario four above is shown. In this flow 900, the first communication device (such as the first communication device 210 above) extracts randomness information from the square of the modulus value of the element value h of the estimated channel H and quantifies it. Specifically, when the selection mode is to extract random information from the square of the modulus value of h for quantization, considering the mathematical modeling of the square of the modulus value of h, as shown in 901, k = |h| 2 . h itself follows a complex Gaussian distribution, then the square of the modulus value of h follows an exponential distribution, that is:

[0146] (that is )

[0147] Determine (903) the function Φ and Specifically, since the input information source in this example (that is, the square of the modulus value of h) follows an exponential distribution, the function Φ is constructed as follows:

[0148] Φ(x) = e -x , x ≥ 0

[0149] The domain of the exponential distribution is the non-negative real number field Here, the function Φ maps the input information on the non-negative real number field, that is, the square of the modulus value of h, to the interval [0, 1]. In addition to defining the function Φ, a function determined by the quantization level m is also defined This function satisfies the following mapping relationship:

[0150]

[0151] In other words, this function maps real numbers in the interval [0, 1] to the quotient group of the discrete integer domain according to the input parameters. Regarding how to specifically define the function according to the quantization level m reference can be made to the description of in other embodiments and the expression of

[0152] After determining the definitions of the function Φ and it is judged whether the empirical distribution parameter α is input in (905). According to whether the parameter α of the empirical distribution is input, the process of calculating the quantization result η includes two branches to execute. Among them, branch one is the case when the empirical distribution parameter α is input, and branch two is the case when the empirical distribution parameter α is not input. Specifically, for branch one, when α is input, the square of the modulus value of h is normalized with α as the input of the function Φ. That is, as shown in 907a, when k = |h| 2 , then:

[0153]

[0154] At this time, the distribution of c follows a uniform distribution in the interval [0, 1], that is Input c and m into the function and it can be mapped to the quotient group to achieve a discrete quantization process that follows a uniform distribution. Substitute into the expression of η here, as shown in 909a, to obtain:

[0155]

[0156] The function achieves the effect of first scaling the values in the interval [0, 1] to [0, m], and then mapping to If it is not scaled to [0, m], then all c, because they belong to the interval [0, 1], will be mapped to the integer 0. The second input parameter of the function can also be a positive integer multiple of m.

[0157] For branch two, when the empirical distribution parameter α is not input, by default α = 1. The square of the modulus value of h is directly used as the input value of the function Φ. As shown in 907b, when k = |h| 2 , that is:

[0158] c = Φ(|h| 2 )

[0159] At this time, the value range of c is in interval, follows a class-exponential curve distribution, and the parameters are unknown. The class-exponential curve distribution curve is as Figure 10As shown, it is an example of the distribution followed by the output of the second mapping function. Here, the class exponential curve distribution is used because the probability of the general exponential curve distribution decreases as the random variable increases, while the actual distribution of c is the opposite, that is, the probability increases as the random variable increases. In such a scenario, c is mapped to the quotient group and ensure that the output integer η follows a uniform distribution. The function needs to scale c on I to the interval [0, lm]. l is an integer and l can be greater than or equal to 40. For example, the value of l can be 1000. After the magnification factor, the output integer η can follow a uniform distribution. For specific details, please refer to the introduction of the above embodiments. Based on the calculation of group homomorphism, adjacent two high-probability values (such as the values near the right position of the class exponential curve distribution) can be mapped to different integer values. Here, substituting into the expression of η, as shown in 909b, we get:

[0160]

[0161] where the numerical value of the second input parameter used in the mod function comes from the subscript of, that is, the quantization level m, which does not change with the change of. After obtaining the quantization result , it needs to be converted into a binary bit string bits η ∈ {0, 1}, that is, the key bits, to determine the (911) physical layer key.

[0162] Figure 11 shows a schematic diagram of the process of determining the key in an example scenario of some embodiments of the present disclosure. It shows the process 1100 of determining the key for the above scenario five. In this process 1100, the first communication device (such as the above first communication device 210) extracts randomness information from the argument θ of the element value h of the estimated channel H and quantifies it. When the selection mode is to extract random information from the argument of h for quantization, considering the mathematical modeling of the argument of h, as shown in 1101, k = θ. h follows a complex Gaussian distribution, and the argument of h follows a uniform distribution, that is:

[0163]

[0164] According to the value range of the argument, it can be known that α = 2π. Determine (1103) the function Φ and Specifically, here the input information source follows a uniform distribution. In this example, when constructing the function Φ, there is no need to introduce the cumulative fraction function of the uniform distribution in the interval [0, 1], and it can be defined as:

[0165] Φ(x) = x

[0166] In addition to defining the function Φ, it is also necessary to define the function determined by the quantization level m The function satisfies the following mapping relationship:

[0167]

[0168] In other words, the function maps real numbers in the interval [0, 2π] to the quotient group of the discrete integer domain according to the input parameters. Regarding how to specifically define the function according to the quantization level m reference can be made to other embodiments above.

[0169] In some of the above embodiments, the range of the real part or the imaginary part of h is the real number field In some embodiments, the range of the modulus value of h and the square of the modulus value is the non - negative real number field In this example, the range of the argument of h is [0, 2π], not involving ±∞. After determining the functions Φ and judge whether the empirical distribution parameter α is input in (1105). According to whether the empirical distribution parameter α is input, there are two implementation methods.

[0170] In the first implementation method, when the empirical distribution parameter α is input, α is used to normalize the argument of h and used as the input of the function Φ. As shown in 1107a, when k = θ, that is:

[0171]

[0172] At this time, the distribution of c follows a uniform distribution on the interval [0, 1], that is Input c and m into the function and it can be mapped to the quotient group to achieve a discrete quantization process that follows a uniform distribution. Calculate and substitute into the expression of η here, as shown in 1109a, to obtain:

[0173]

[0174] The function achieves the effect of first scaling the values in the interval [0, 1] to [0, m], and then mapping to If it is not scaled to [0, m], then all c, because they belong to the interval [0, 1], will be mapped to the integer 0. The second input parameter of the function can also be a positive integer multiple of m.

[0175] In the second implementation method, when the empirical distribution parameter α is not input, it is defaulted that α = 1. The argument of h is directly used as the input value of the function Φ. As shown in 1107b, when k = θ, that is:

[0176] c = Φ(θ)

[0177] At this time, the value range of c is in the I interval and follows a uniform distribution, but the parameters are unknown. The interval I is not a sub-interval of the [0, 1] interval. In such a scenario, c is mapped to the quotient group and it is ensured that the output integer η follows a uniform distribution. The function needs to scale c on I to the interval [0, lm]. l is an integer and l can be greater than or equal to 40. For example, the value of l can be 1000. After the magnification factor, the output integer η can follow a uniform distribution, mainly due to the difference between the calculation based on group homomorphism and the traditional scheme (quantifying according to the threshold value so that the entire interval between adjacent threshold values has the same quantization result). Based on the calculation of group homomorphism, two adjacent high-probability values can be mapped to different integer values. Substitute into the expression of η here, as shown in 1109b, and get:

[0178]

[0179] where the numerical value of the second input parameter used in the mod function comes from the subscript of, that is, the quantization level m, which does not change with the change of. After obtaining the quantization result , it needs to be converted into a binary bit string bits η ∈ {0, 1}, that is, the key bit, to determine the (1111) physical layer key. In this embodiment, since the statistical distribution of the argument is already a uniform distribution, the function Φ in the calculation process is defined as the identity function, without introducing extra computational complexity.

[0180] Figure 12 shows a schematic diagram of the process of determining the key in an example scenario of some other embodiments of the present disclosure, in which the process 1200 of determining the key for the above scenario six is shown. The process 1200 provides another possibility of extracting randomness information from the argument of h h different from the process 1100, and the function Φ in the process 1200 is different from the function Φ defined in the process 1100. The function Φ in the process 1200 is no longer defined as the identity function. This process 1200 can be executed by the first communication device 210. When the selection mode is to extract random information from the argument of h for quantization, the mathematical modeling of the argument of h needs to be considered, as shown in 1201, k = θ. h follows a complex Gaussian distribution, and the argument of h follows a uniform distribution, that is:

[0181]

[0182] Determine (1203) the function Φ and Specifically, in this example, the input information source (that is, the argument of h) follows a uniform distribution. Since the distribution statistical parameter is known to be 2π. Here, the cumulative fraction function of the uniform distribution in the [0, 2π] interval is introduced, and the function Φ can be defined as follows:

[0183]

[0184] The function Φ maps the input information in the interval [0, 2π], i.e., the argument of h, to the interval [0, 1]. In addition to defining the function Φ, a function determined by the quantization level m is also defined. This function satisfies the following mapping relationship:

[0185]

[0186] This function maps the real numbers in the interval [0, 1] to the quotient group of the discrete integer domain according to the input parameters. Regarding how to specifically define the function according to the quantization level m Reference can be made to other embodiments above. After determining the definitions of the function Φ and judging whether to calculate c in (1205), the process of calculating the quantization result η is divided into two sub-processes according to whether c is calculated.

[0187] In the first sub-process, when calculating c, the argument of h is directly used as the input of the function Φ, as shown in 1207a, i.e.:

[0188]

[0189] At this time, the distribution of c follows a uniform distribution on the interval [0, 1], i.e., Inputting c and m into the function can be mapped to the quotient group to achieve a discrete quantization process that follows a uniform distribution. Here, substituting into the expression of η is calculated, as shown in 1209a, :

[0190]

[0191] The function achieves the effect of first scaling the values in the interval [0, 1] to [0, m], and then mapping to If not scaled to [0, m], then all c, because they belong to the interval [0, 1], will be mapped to the integer 0. The second input parameter of the function can also be a positive integer multiple of m.

[0192] When not calculating c, the argument of h is directly used as the input value of the function to calculate the quantization value η, as shown in 1209b, i.e.:

[0193]

[0194] In such a scenario, c is mapped to the quotient group and it is ensured that the output integer η follows a uniform distribution. The function It is necessary to scale c on I to the interval [0, lm], where l is an integer and l can be greater than or equal to 40. For example, the value of l can be 1000. After the magnification factor, the output integer η follows a uniform distribution, mainly due to the difference between the calculation based on group homomorphism and the traditional scheme (quantifying according to the threshold value so that the entire interval between adjacent threshold values has the same quantization result). Based on the calculation of group homomorphism, two adjacent high-probability values can be mapped to different integer values. For specific details, please refer to the introduction of other embodiments above.

[0195] Obtain the quantization result After that, it is necessary to convert it into a binary bit string bits η ∈{0, 1}, that is, the key bits, to determine the (1211) physical layer key as the input information of the encryption scheme.

[0196] In some or all of the embodiments in Scenarios 1 to 6 above, h represents the element value of the estimated channel matrix. In some embodiments, the selection of the element value of the estimated channel matrix can be determined by signaling interaction between the receiving and transmitting ends. For example, the first communication device 210 sends the index of h to the second communication device 220, or the second communication device 220 sends the index of h to the first communication device 210. Other configured signaling can also be exchanged between the first communication device 210 and the second communication device 220, such as the mode selection t, quantization level m, etc. The mode selection t indicates the selected mode. As described in the above embodiments, the mode can be determined according to the channel conditions. For example, according to the channel conditions, one mode can correspond to one of the above Scenarios 1 to 6.

[0197] Figure 13 Shows a schematic diagram of the signaling configuration process in an example scenario of some embodiments of the present disclosure, as Figure 13In the shown process 1300, the first communication device 210 is, for example, one of the terminal device 110 (such as a UE) or the network device 120 (such as a base station), and the second communication device 220 is, for example, the other one of the terminal device 110 or the network device 120. In some embodiments, the first communication device 210 acts as a sending end and the second communication device 220 acts as a receiving end. For example, the first communication device 210 calculates and selects a mode selection t, etc., and sends it to the second communication device 220. In some other embodiments, the second communication device 220 acts as a sending end and the first communication device 210 acts as a receiving end. For example, the second communication device 220 calculates and selects a mode selection t, etc., and sends it to the first communication device 210. The configuration convention of the signaling can be specifically configured in the RRC, MAC, or the physical downlink control channel (PDCCH) of the PHY. For example, the base station (an example of one of the first communication device 210 or the second communication device 220) can indicate the UE (an example of the other one of the first communication device 210 or the second communication device 220), or the UE can report to the base station. If there are multiple rounds of interactions between the base station and the UE, then this configuration can be sent in each round of interaction, or it can be sent only in one round of interaction, and the configuration is default adopted in subsequent interactions. Examples of the signaling can include the index of h, which is used for the receiving and sending ends to select the same element value h from the estimated channel matrix H to extract randomness information and quantify and generate a key. Examples of the signaling can also include the mode selection t, which is used to select one of the real part, imaginary part, modulus value, square of the modulus value, and argument of the element value of the estimated channel matrix based on the channel condition to obtain channel randomness information. Examples of the signaling can also include the quantization level m, which is determined according to the channel condition and is used to determine (Example of the first mapping function). In some examples, when the channel condition changes, a more appropriate mode can be reselected, and the information of the updated mode is sent to the other party of the communication through the interaction signaling.

[0198] Figure 13The illustrated embodiment notifies or updates the above configuration through signaling interaction. In other embodiments, instead of using the method of transceiver and transmitter-receiver end interaction signaling, the above configuration can be formulated through a protocol and saved in both the receiver and the transmitter. As an example, process 1300 includes that after the establishment of the access stratum (AS) security mode is completed (1301), the first communication device 210 determines (1303) the selected mode. The first communication device 210 sends (1305a), and the second communication device 220 receives (1307a) the index 1302 of h. Optionally or alternatively, the first communication device 210 sends (1305b), and the second communication device 220 receives (1307b) the mode selection t (t indicates the selected mode) (1304). Optionally or alternatively, the first communication device 210 sends (1305c), and the second communication device 220 receives (1307c) the quantization level m (1306).

[0199] The scheme for determining a key based on a quotient group in the embodiments of the present disclosure extracts the information for generating the key from the wireless channel itself. When the empirical distribution of the estimated channel and its related information can be obtained, it can be converted into a uniform distribution through the cumulative distribution function of the standard distribution of the corresponding information, and the information in the continuous real number domain is quantized into a key in the discrete integer domain based on the quotient group mapping corresponding to the quantization level m. When the empirical distribution of the estimated channel and its related information cannot be obtained, after the conversion through the cumulative distribution function of the standard distribution of the corresponding information, by magnifying an integer multiple of the quantization level m, a key with a uniform distribution is obtained based on the quotient group mapping. Thus, a uniformly distributed physical layer key can be generated without obtaining the empirical distribution parameters of the estimated channel and its related information, avoiding the necessity of obtaining the empirical distribution of the estimated channel and its related information. The calculation processes of some embodiments of the present disclosure avoid additional computational overhead and processing delay. Especially in the case where the accuracy of the empirical distribution calculated based on the collected noisy channel information cannot be guaranteed, the scheme of the embodiments of the present disclosure can well avoid the risk that the quantized key may not follow a uniform distribution caused by using the parameters of the empirical distribution to set thresholds and quantize to generate the key.

[0200] Figures 14A to 14F A schematic diagram of the comparison of simulation results of some embodiments of the present disclosure is shown, such as Figures 14A to 14F The illustrated simulation compares the cumulative distribution of the quantization result with the cumulative distribution of the discrete uniform distribution in the interval (0, m - 1). The horizontal axis m represents the quantization level, and the vertical axis is the cumulative distribution function (CDF). The specific parameters used in the simulation are as follows, Figure 14A 、 14B 、14C uses the quantization level m = 4, Figure 14D 、 14E, the quantization level m used in 14F is 16. Figure 14A , 14B , the patterns used in 14C respectively correspond to the real part of h, the modulus value of h, and the square of the modulus value of h. Figure 14D , 14E , the patterns used in 14F respectively correspond to the real part of h, the modulus value of h, and the square of the modulus value of h. Figures 14A to 14F , the thick black dashed line represents the statistical discrete uniform distribution cumulative distribution function, and the thin solid line with hollow circles is the quantization result under one of the above three patterns. Figure 14A , 14B , for the case where 14C corresponds to the input empirical distribution parameters, Figure 14D , 14E , for the case where 14F does not input the empirical distribution parameters.

[0201] Figure 15 shows a schematic flowchart implemented at a communication device according to some embodiments of the present disclosure. As Figure 15 shown, the communication device executing process 1500 can be the first communication device 210 or located in the first communication device 210. For example, it can be the terminal device 110 or a chip, module, or module in the terminal device 110, or for example, it can be the network device 120 or a chip, module, or module in the network device 120. At block 1510, the communication device extracts channel randomness information from the estimated channel matrix. At block 1520, the communication device quantizes the channel randomness information, where the quantized channel randomness information belongs to the quotient group of the discrete integer domain. At block 1530, the communication device determines a physical layer key based on the quantized channel randomness information. In some embodiments, process 1500 may further include other operations performed at the first communication device 210 described in conjunction with Figures 2 to 13 of the embodiments of the present disclosure.

[0202] Figure 16 is a schematic structural diagram of a possible communication device provided by the embodiments of the present disclosure. These communication devices can implement the functions of the communication device in the above method embodiments (such as Figure 15 the communication device mentioned in the embodiments shown), and thus can also achieve the beneficial effects possessed by the above method embodiments. For example, in some embodiments of the present disclosure, the communication device can be the terminal device 110 or the network device 120 as shown in Figure 1A , and can also be a module (such as a chip) applied to the terminal device 110 or the network device 120.

[0203] As Figure 16 shown, the communication device 1600 includes a processing unit 1610, and may further include a communication unit 1620 in some examples. The communication device 1600 can be used to implement the above Figures 2 to 15The functions of the communication device (e.g., the first communication device 210) in the method (or process) of the illustrated embodiment. In the example where the communication device 1600 is used to implement Figure 15 the functions of the illustrated communication device, the processing unit 1610 may include an extraction unit, a quantization unit, and a determination unit. The communication unit 1620 may be specifically implemented as a transmitter and a receiver. For example, the communication unit 1620 may send the data / information / signal encrypted with the physical layer key determined by the determination unit to another communication device (e.g., the second communication device 220). In some examples, the communication device 1600 may, through the communication unit 1620, send configured signaling to another communication device or receive signaling from another communication device. In some examples, the processing unit 1610 may be specifically implemented as a processor.

[0204] When the communication device 1600 is used to implement the functions of the communication device in the above Figure 15 illustrated method embodiment, the extraction unit in the processing unit 1610 may be used to extract channel randomness information from the estimated channel matrix. The quantization unit in the processing unit 1210 may be used to quantize the channel randomness information, where the quantized channel randomness information belongs to the quotient group of the discrete integer domain. The determination unit in the processing unit 1210 may be used to determine the physical layer key based on the quantized channel randomness information. For a more detailed description of the above units, reference may be made to the relevant description in the above method embodiment, which will not be elaborated here.

[0205] As Figure 17 illustrated, the communication device 1700 includes a processor 1710 and an interface circuit 1720. The processor 1710 and the interface circuit 1720 are coupled to each other. It can be understood that the interface circuit 1720 may be a transceiver or an input / output interface. Optionally, the communication device 1700 may further include a memory 1730 for storing instructions executed by the processor 1710 or storing input data required for the processor 1710 to run instructions or storing data generated after the processor 1710 runs instructions. It should be noted that in some embodiments, the processor 1710 and the memory 1730 may be integrated into the same device. When the communication device 1700 is used to implement the method in the above method embodiment, the interface circuit 1720 is used to execute the functions of the above communication unit 1620.

[0206] When the above communication device is a chip applied to a communication device, the chip of the communication device correspondingly implements the functions of the communication device in the above method embodiment. The chip of the communication device sends data to other modules (such as a radio frequency module or an antenna) in the communication device, and the data may be sent to other devices; or, the chip of the communication device receives data from other modules (such as a radio frequency module or an antenna) in the communication device, and the data is received from other devices.

[0207] It can be understood that the processor in the embodiments of the present disclosure may be a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.

[0208] Embodiments of the present disclosure provide a communication system. The communication system may include the above-mentioned Figure 15 communication devices involved in the embodiments shown. Optionally, the communication devices in the communication system may correspondingly execute Figure 15 the communication methods shown.

[0209] Embodiments of the present disclosure also provide a circuit that can be coupled to a memory and can be used to execute the processes related to the communication device in any of the embodiments shown in the above method embodiments. The chip system may include the chip and may also include other components such as a memory or a transceiver.

[0210] It should be understood that the processor mentioned in the embodiments of the present disclosure may be a CPU, or may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), off-the-shelf programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0211] It should also be understood that the memory mentioned in the embodiments of the present disclosure may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable ROM (PROM), an erasable programmable ROM (EPROM), an electrically erasable programmable ROM (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM).

[0212] It should be noted that when the processor is a general-purpose processor, DSP, ASIC, FPGA, or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, the memory (storage module) is integrated in the processor.

[0213] It should be noted that the memory described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0214] It should be understood that in various embodiments of the present disclosure, the magnitudes of the sequence numbers of the above processes do not mean the order of execution, and the execution order of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present disclosure.

[0215] Those of ordinary skill in the art will realize that the modules and algorithm steps of the various examples described in connection with the embodiments disclosed herein can be implemented in electronic hardware, or in a combination of computer software and electronic hardware. Whether these functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. Skilled professionals can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this disclosure.

[0216] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and modules described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.

[0217] In several embodiments provided by this disclosure, it should be understood that the disclosed communication methods and devices can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the modules is only a logical function division, and there can be other division methods in actual implementation. For example, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.

[0218] The modules described as separate components may or may not be physically separated, and the components shown as modules may or may not be physical modules, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0219] In addition, the various functional modules in the various embodiments of this disclosure can be integrated into one processing module, or each module can exist physically alone, or two or more modules can be integrated into one module.

[0220] When this function is implemented in the form of a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the embodiments of the present disclosure, in essence, or the part that makes a contribution, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method in each embodiment of the present disclosure. The aforementioned computer-readable storage medium can be any available medium that a computer can access. Taking this as an example but not limited to: the computer-readable medium may include a random access memory (RAM), a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM), a universal serial bus flash disk, a mobile hard disk, or other optical disc storage, magnetic disk storage media, or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer.

[0221] As used herein, the term "comprising" and its like shall be understood as an open inclusion, i.e., "including but not limited to". The term "based on" shall be understood as "at least partially based on". The term "one embodiment" or "the embodiment" shall be understood as "at least one embodiment". The terms "first", "second", etc. may refer to different or the same objects, and are only used to distinguish the objects referred to, without implying a specific spatial order, temporal order, order of importance, etc. of the objects referred to. In some embodiments, values, processes, selected items, determined items, devices, apparatuses, means, components, assemblies, etc. are referred to as "optimal", "lowest", "highest", "minimum", "maximum", etc. It should be understood that such descriptions are intended to indicate that a selection can be made among many available functional options, and such a selection does not necessarily need to be better, lower, higher, smaller, larger or otherwise preferred in other aspects or all aspects than other options. As used herein, the term "determine" can cover a variety of actions. For example, "determine" can include operations, calculations, processing, derivations, investigations, lookups (e.g., lookups in a table, database or another data structure), ascertainments, etc. In addition, "determine" can include receiving (e.g., receiving information), accessing (e.g., accessing data in a memory), etc. Furthermore, "determine" can include parsing, selecting, choosing, establishing, etc.

[0222] As shown above, it is only the specific implementation manners of the embodiments of the present disclosure, but the protection scope of the embodiments of the present disclosure is not limited thereto. Any person skilled in the art within the technical scope disclosed by the embodiments of the present disclosure can easily think of changes or substitutions, which should all be covered within the protection scope of the embodiments of the present disclosure. Therefore, the protection scope of the embodiments of the present disclosure shall be subject to the protection scope of the claims.

Claims

1. A method for determining a secret key, characterized in that, Including: Extracting channel randomness information from an estimated channel matrix; Quantizing the channel randomness information, where the quantized channel randomness information belongs to a quotient group of a discrete integer domain; And Determining a physical layer key based on the quantized channel randomness information.

2. The method according to claim 1, wherein Quantizing the channel randomness information through a first mapping function determined based on a quantization level.

3. The method according to claim 1 or 2, characterized in that, Quantizing the channel randomness information includes: Based on a second mapping function, mapping the channel randomness information from its domain of definition to a first numerical interval to obtain the value of the channel randomness information in the first numerical interval; and Through the first mapping function, mapping the value of the channel randomness information in the first numerical interval to the quotient group of the discrete integer domain.

4. The method according to claim 3, characterized in that, A first parameter of the first mapping function is obtained based on the output of the second mapping function, and a second parameter of the first mapping function is obtained based on the quantization level.

5. The method according to claim 4, wherein The channel randomness information is the real part or the imaginary part of an element value of the estimated channel matrix, and the second mapping function is a cumulative distribution function of a standard normal distribution.

6. The method according to claim 4, characterized in that The channel randomness information is the modulus value of an element value of the estimated channel matrix, and the second mapping function is a cumulative distribution function of a Rayleigh distribution.

7. The method according to claim 4, characterized in that, The channel randomness information is the square of the modulus value of an element value of the estimated channel matrix, and the second mapping function is a function defined based on exponential distribution characteristics.

8. The method according to claim 4, characterized in that The channel randomness information is the argument of an element value of the estimated channel matrix, and the second mapping function is a function defined based on the argument.

9. The method according to any one of claims 5 - 8, characterized in that, The input of the second mapping function is one of the following: The channel randomness information normalized based on empirical distribution parameters; or The channel randomness information.

10. The method according to claim 3, characterized in that, The channel randomness information is the argument of an element value of the estimated channel matrix, and the second mapping function is a cumulative distribution function of a uniform distribution in the interval [0, 2π].

11. The method according to claim 1 or 2, characterized in that, The channel randomness information is the argument of an element value of the estimated channel matrix, and a first parameter of the first mapping function is obtained based on the argument, and a second parameter of the first mapping function is obtained based on the quantization level.

12. The method according to any one of claims 4-11, characterized in that, The first mapping function is used to scale the interval corresponding to the first parameter from a first interval to a second interval and then map it to the quotient group of the discrete integer domain, where the upper limit of the second interval is an integer multiple of the quantization level.

13. The method according to claim 9, characterized in that, The first mapping function is used to scale the interval corresponding to the first parameter and then map it to the quotient group of the discrete integer domain. The upper limit of the scaled interval is an integer multiple of the quantization level, and when the input of the second mapping function is the channel randomness information not normalized using empirical distribution parameters, the integer multiple is greater than a preset threshold.

14. The method according to any one of claims 1 to 13, characterized in that, The channel randomness information is determined based on a mode selected by a first communication device that executes the method, and at least one of the following: The mode is determined by a protocol; or The mode is determined through signaling interaction between the first communication device and a second communication device, and the first communication device communicates with the second communication device using the physical layer key.

15. The method according to claim 14, characterized in that, The selection of the mode is based on the channel condition between the first communication device and the second communication device.

16. The method according to claim 15, wherein It further includes: Receiving or sending an indication to update the mode when at least one of the channel conditions changes.

17. The method according to any one of claims 1 to 16, characterized in that, The channel randomness information is extracted based on the indices of the element values in the estimated channel matrix.

18. The method according to claim 17, wherein The index is pre-agreed between the first communication device and the second communication device that executes the method, where the first communication device communicates with the second communication device using the physical layer key; or The first communication device and the second communication device determine the index through signaling interaction.

19. A communication device, characterized in that, It includes: An extraction unit for extracting channel randomness information from the estimated channel matrix; A quantization unit for quantizing the channel randomness information, where the quantized channel randomness information belongs to the quotient group of the discrete integer domain; And A determination unit for determining the physical layer key based on the quantized channel randomness information.

20. A communication device, characterized in that, It includes: A processor and a memory storing instructions, where when the instructions are executed by the processor, the method according to any one of claims 1 to 18 is executed.

21. A communication system, characterized in that, It includes: The communication device according to claim 19 or 20.

22. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program or instructions, where when the computer program or instructions are executed, the method according to any one of claims 1 to 18 is executed.

23. A computer program product, characterized in that, It includes a computer program or instructions, where when the computer program or instructions are executed, the method according to any one of claims 1 to 18 is executed.

Citation Information

Cited By

  • Key determination method, apparatus, system, and storage medium

    WO2025145961A1