Physical layer key generation method based on DWT in random access process
By using DWT in the Internet of Things to separate channel state information at high and low frequencies and enhance key consistency, the key inconsistency problem in the scenario of power and delay restriction is solved, and the access rate and system security of legitimate users are improved.
Patent Information
- Application Number
- CN202510196446.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-21
- Publication Date
- 2025-07-04
AI Technical Summary
In the Internet of Things, existing physical layer key generation algorithms are difficult to make full use of channel information in scenarios where power and delay are limited, resulting in key inconsistency problems, affecting the access rate of legitimate users and system security.
Discrete wavelet transform (DWT) is used to divide channel state information into high-frequency and low-frequency channel information, and the statistical information of high-frequency channel information is used to reduce the noise impact, key consistency is enhanced through DWT, and signaling information is encrypted using XOR operation.
It effectively improves the access rate of legitimate users, reduces the access rate of unauthorized users, optimizes the delay performance and key consistency, and improves the security and communication performance of the system.
Smart Images

Figure CN120264485A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of wireless communication security, and particularly relates to a physical layer key generation method based on discrete wavelet transform (DWT) in the random access process. Background Art
[0002] In recent years, with the continuous development of the Internet of Things (IoT), a large number of devices have been connected to the IoT. Security algorithms are an important means to ensure the normal operation of a large number of devices. Traditional security algorithms mainly ensure network security based on upper-layer shared keys, and face challenges in key distribution and management in the scenario of a large number of connections. Physical layer security, as a security algorithm proposed by leveraging the secrecy ability of the propagation channel, can effectively solve the above problems faced by traditional security algorithms. As a research branch of physical layer security, the physical layer key generation security algorithm generates keys by using the reciprocity and randomness of the channel. These advantages have prompted the physical layer key generation algorithm to receive more and more attention.
[0003] There is a risk that unauthorized users accessing the IoT will tamper with and disclose important network data. Existing research mostly uses upper-layer-based authentication methods to organize unauthorized users from accessing the IoT network, which faces problems in key distribution and management. As the first interaction process after downlink synchronization, using the physical layer key generated based on channel state information to encrypt the signaling in this process can well prevent unauthorized users from accessing the network, and solve the problems of key distribution and management difficulties of upper-layer-based authentication methods in the IoT with a large number of devices.
[0004] The main challenge in applying the physical layer key generation algorithm to encrypt the random access process is the consistency of the generated physical layer keys, which will significantly affect the access rate of legitimate users. Existing methods for reducing the key inconsistency rate of the physical layer key generation algorithm include interactive privacy coordination methods and transform-based privacy coordination methods. Interactive privacy coordination methods include the Cascade protocol and privacy coordination methods based on error correction codes, etc. They enhance key consistency by sending encoded key information. This method has good performance in key consistency rate, but it will increase the transmission power and transmission delay. Existing transform-based privacy coordination methods reduce key inconsistency by filtering out the inconsistency of high-frequency channel information, and they cannot make good use of channel information. Therefore, in the IoT scenario where device power and delay are limited, how to make full use of channel information to reduce key inconsistency is a problem that needs to be considered and solved.
[0005] Therefore, it is necessary to study a physical layer key generation algorithm that is suitable for the Internet of Things scenarios with limited power and time delay and makes full use of channel state information, so as to better balance the security and communication performance of the system. Summary of the Invention
[0006] In view of the above problems, the purpose of the present invention is to provide a DWT-based physical layer key generation method during the random access process. By introducing the physical layer key generation algorithm into the random access process, the present invention protects the security of the wireless network from the source of access. By using DWT to divide the channel state information into high-frequency and low-frequency channel information, and adopting the statistical information of the high-frequency channel information and the low-frequency channel information to reduce the influence of high-frequency noise on the consistency of the physical layer key, the security and communication performance requirements of the system are effectively balanced.
[0007] The present invention mainly includes the following parts:
[0008] 1. Construct a mobile secure communication system model with an eavesdropper in the time-division duplex mode;
[0009] The system model includes a total of three terminals: a legitimate base station B, a legitimate mobile terminal U, and an unauthorized terminal Eve. The propagation channel h(t) with multipath propagation at time t is modeled.
[0010]
[0011] Where is a 1×M-dimensional complex vector, M is the number of Demodulation Reference Signals (DMRS), P is the number of resolvable multipaths, and A p (·), δ(·) and τ p represent the amplitude, Doppler frequency, impulse response, and time delay of the p-th multipath respectively. A(·) and represent the amplitude response and impulse response respectively;
[0012] The random access process of the system is as follows: 1) U sends a random preamble sequence Msg1 to B; 2) After receiving Msg1, B sends a random access response message Msg2 to U; 3) U collects channel state information according to the DMRS in the received Msg2 message; 4) U performs DWT-based key consistency enhancement on the collected channel state information and quantizes the enhanced information to obtain a physical layer key; 5) U encrypts the bits carrying information in the radio resource control (RRC) setup request Msg3 using the physical layer key; 6) U sends the encrypted Msg3 to B; 7) B collects channel state information according to the DMRS in the received Msg3 message; 8) B performs DWT-based key consistency enhancement on the collected channel state information and quantizes the enhanced information to obtain a physical layer key; 9) B decrypts the received Msg3 message using the generated physical layer key; 10) Based on the information carried in the obtained msg3, B sends an RRC setup message Msg4 to U; 11) After receiving Msg4, U sends an acknowledgement (ACK) of the hybrid automatic repeat request (HARQ) of the Msg4 message to B.
[0013] 2. Based on DMRS to collect channel state information, U and B use the least squares (LS) channel estimation method to extract the instantaneous characteristics of the transmission channel state information by means of the DMRS in the Msg2 and Msg3 transmission channels;
[0014] The specific steps are as follows:
[0015] Step 201. U performs the LS channel estimation method according to the DMRS in the received Msg2 message, and the instantaneous characteristics of the transmission channel state information extracted can be expressed as:
[0016]
[0017] where U receives the DMRS at time point t1. h U (t1) is the propagation channel of the legitimate mobile terminal U at time t1, is the channel estimation of the instantaneous characteristics of the transmission channel information at time point t1, following a Gaussian distribution with zero mean and variance σ U e U (t1) represents the channel estimation error at U at time point t1 due to channel noise and other reasons;
[0018] Step 202. B performs LS channel estimation based on the DMRS in the received Msg3 message, and the instantaneous characteristics of the extracted transmission channel state information can be expressed as:
[0019]
[0020] where B receives the DMRS at time point t2, and t2 - t1 is less than the coherence time T. c h B (t2) is the propagation channel of the legitimate base station B at time point t2. is the channel estimation of the instantaneous characteristics of the transmission channel information of B at time point t2, following a Gaussian distribution with zero mean and variance σ B respectively. e B (t2) represents the channel estimation error at B due to channel noise and other reasons.
[0021] 3. B and U use DWT to divide the extracted channel state information into high-frequency and low-frequency channel information, then perform statistical operations on the high-frequency channel information, and finally merge the high-frequency information with the low-frequency information;
[0022] The specific steps are as follows:
[0023] Step 301. U uses DWT to divide the extracted channel state information into high-frequency and low-frequency information, which is specifically expressed as:
[0024]
[0025] where * is the convolution operation, and l and g are the low-pass and high-pass filters designed based on the wavelet basis respectively. represents the approximation coefficient of the channel estimation at U, representing the low-frequency channel estimation of U; represents the detail coefficient of the channel estimation at U, representing the high-frequency channel estimation of U;
[0026] Step 302. B uses DWT to divide the extracted channel state information into high-frequency and low-frequency information, which is specifically expressed as:
[0027]
[0028] where represents the approximation coefficient of the channel estimation at B, representing the low-frequency channel estimation of B; represents the detail coefficient of the channel estimation at B, representing the high-frequency channel estimation of B;
[0029] Step 303. U divides the detail coefficients of every N high-frequency channel information after DWT into a group, and obtains g using the statistical information of each group. U Specifically expressed as:
[0030]
[0031] wherein represents the i-th detail coefficient, E(·) is the statistical average of N detail coefficients, and g U represents the statistical average of the detail coefficients of the high-frequency channel information at U.
[0032] Step 304: B divides the detail coefficients of every N pieces of high-frequency channel information after DWT into a group, and obtains the statistical information g of the detail coefficients of this group by using the statistical information of each group B , which is specifically expressed as:
[0033]
[0034] wherein, g B represents the statistical average of the detail coefficients of the high-frequency channel information at B.
[0035] Step 305: U combines each group of approximation coefficients of the channel estimation after DWT and the statistical information g of the detail coefficients U to obtain which is specifically expressed as:
[0036]
[0037] Step 306: B combines each group of approximation coefficients of the channel estimation after DWT and the statistical information of the detail coefficients g B to obtain which is specifically expressed as:
[0038]
[0039] Step 307: U uses binary quantization to quantize into binary to obtain the physical layer key K U , which is specifically expressed as:
[0040]
[0041] wherein, k ∈ [1, L], K U1 = 0, L is the length of the generated key, which is determined by the number of DMRS and N, is the k-th channel estimation value in U(k+1) K U is the (k + 1)-th binary quantization value in the physical layer key K
[0042] Step 308: B uses binary quantization to quantize into binary to obtain the physical layer key KB , specifically expressed as:
[0043]
[0044] Among them, K B1 = 0, is the k-th channel estimation value in B(k+1) and K B is the (k + 1)-th binary quantization value in the physical layer key K.
[0045] 4. U and B use the exclusive OR operation to encrypt the transmitted and received Msg3 signaling information respectively;
[0046] The specific steps are as follows:
[0047] Step 401. U uses the exclusive OR operation to encrypt the transmitted Msg3 message;
[0048] Step 402. B uses the exclusive OR operation to decrypt the received Msg3 message.
[0049] 5. Calculate the access rate of the user
[0050] Step 501. Calculate the access rate of the legitimate user. The specific operation is as follows:
[0051] Legitimate user access rate = Number of successful accesses by legitimate users / Number of accesses;
[0052] Step 502. Calculate the access rate of the unauthorized user. The specific operation is as follows:
[0053] Illegal user access rate = Number of successful accesses by illegal users / Number of accesses;
[0054] 6. Calculate the Key Disagreement Rate (KDR) of the algorithm. The specific operation is as follows:
[0055]
[0056] 7. Use the randomness test suite provided by the National Institute of Standards and Technology (NIST) to evaluate the randomness change of the keys of U and B.
[0057] The advantages of the present invention are as follows:
[0058] 1. A method for generating a physical layer key based on DWT in a random access process effectively guarantees the access rate of legitimate users and at the same time prevents attackers from accessing the network.
[0059] 2. A physical layer key generation method based on DWT in a random access process, with better delay performance and key inconsistency performance than existing physical layer key generation algorithms.
[0060] 3. A physical layer key generation method based on DWT in a random access process, effectively taking into account the security performance and communication performance of the communication system. BRIEF DESCRIPTION OF THE DRAWINGS
[0061] Figure 1 It is a physical layer key generation system model in the access process with an eavesdropper in the present invention.
[0062] Figure 2 It is a flowchart of a physical layer key generation method based on DWT in a random access process of the present invention.
[0063] Figure 3 It is the KDR performance curve of the present invention under different signal-to-noise ratios, different channel conditions, and different statistical levels N.
[0064] Figure 4 It is the user access rate performance curve of the present invention under different signal-to-noise ratios and different channel conditions.
[0065] Figure 5 It is a comparison chart of the delay performance of the present invention and two other different schemes. DETAILED DESCRIPTION OF THE INVENTION
[0066] The present invention will be further described in detail below with reference to the accompanying drawings. The examples given are only for explaining the present invention and are not intended to limit the scope of the present invention.
[0067] A physical layer key system in a random access process of the present invention, the system model is as Figure 1 shown. An attacker attempts to access the network. After accessing the network, it tries to eavesdrop on or tamper with the information of the core network; a legitimate user accesses the network and completes the connection with the core network.
[0068] As Figure 2 shown, the specific content of the present invention includes:
[0069] 1. Construct a mobile secure communication system model with an eavesdropper in the time division duplex mode;
[0070] The system model includes a total of three terminals: a legitimate base station B, a legitimate mobile terminal U, and an unauthorized terminal Eve. The propagation channel h(t) with multipath propagation at time t is modeled.
[0071]
[0072] Among them is a 1×M dimensional complex vector, M is the number of Demodulation Reference Signals (DMRS), P is the number of resolvable multipaths, and A p (·), δ(·) and τ p represent the amplitude, Doppler frequency, impulse response, and time delay of the p-th multipath respectively. A(·) and represent the amplitude response and impulse response respectively;
[0073] The random access process of the system is as follows: 1) U sends a random preamble sequence Msg1 to B; 2) After receiving Msg1, B sends a random access response message Msg2 to U; 3) U collects channel state information according to the DMRS in the received Msg2 message; 4) U performs DWT-based key consistency enhancement on the collected channel state information and quantizes the enhanced information to obtain a physical layer key; 5) Encrypts the radio resource control (RRC) setup request Msg3 using the physical layer key; 6) U sends the encrypted Msg3 to B; 7) B collects channel state information according to the DMRS in the received Msg3 message; 8) B performs DWT-based key consistency enhancement on the collected channel state information and quantizes the enhanced information to obtain a physical layer key; 9) Decrypts the Msg3 message using the generated physical layer key; 10) B sends an RRC setup message Msg4 to U; 11) After receiving Msg4, U sends an acknowledgement (ACK) of the hybrid automatic repeat request (HARQ) of the Msg4 message to B.
[0074] 2. Based on DMRS to collect channel state information, U and B use the least squares (LS) channel estimation method to extract the instantaneous characteristics of the transmission channel state information by means of the DMRS in the Msg2 and Msg3 transmission channels;
[0075] The specific steps are as follows:
[0076] Step 201. U performs the LS channel estimation method according to the DMRS in the received Msg2 message, and the instantaneous characteristics of the transmission channel state information extracted can be expressed as:
[0077]
[0078] where U receives the DMRS at time point t1. is the channel estimation of the instantaneous characteristics of the transmission channel information at, following zero mean and variance σ UGaussian distribution. e U represents the channel estimation error at U due to channel noise and other reasons;
[0079] Step 202: B performs LS channel estimation based on the DMRS in the received Msg3 message. The instantaneous characteristics of the extracted transmission channel state information can be expressed as:
[0080]
[0081] where B receives the DMRS at time point t2, and t2 - t1 is less than the coherence time T c . is the channel estimation of the instantaneous characteristics of B's transmission channel information, following a Gaussian distribution with zero mean and variance σ B e B represents the channel estimation error at B due to channel noise and other reasons.
[0082] 3. B and U use DWT to divide the extracted channel state information into high - and low - frequency channel information, then perform statistical operations on the high - frequency channel information, and finally merge the high - frequency information with the low - frequency information;
[0083] The specific steps are as follows:
[0084] Step 301: U uses DWT to divide the extracted channel state information into high - and low - frequency information, specifically expressed as:
[0085]
[0086] where * is the convolution operation, l and g are the low - pass and high - pass filters designed based on the wavelet basis, represents the approximation coefficient of the channel estimation at U, representing the low - frequency channel estimation of U; represents the detail coefficient of the channel estimation at U, representing the high - frequency channel estimation of U;
[0087] Step 302: B uses DWT to divide the extracted channel state information into high - and low - frequency information, specifically expressed as:
[0088]
[0089] where, represents the approximation coefficient of the channel estimation at B, representing the low - frequency channel estimation of B; represents the detail coefficient of the channel estimation at B, representing the high - frequency channel estimation of B;
[0090] Step 303: At U, the detail coefficients of every N high - frequency channel information after DWT are grouped, and the statistical information of each group is used to obtain g U, specifically represented as:
[0091]
[0092] Where represents the i-th detail, and E(·) is the statistical average of N detail coefficients;
[0093] Step 304: Divide the detail coefficients of every N high-frequency channel information that has undergone DWT at B into a group, and obtain g using the statistical information of each group B , specifically represented as:
[0094]
[0095] Step 305: U combines the statistical information of the approximate coefficients and detail coefficients of the channel estimation that has undergone DWT to obtain Specifically represented as:
[0096]
[0097] Step 306: B combines the statistical information of the approximate coefficients and detail coefficients of the channel estimation that has undergone DWT to obtain Specifically represented as:
[0098]
[0099] Step 307: U uses binary quantization to quantize into binary to obtain the physical layer key K U , specifically represented as:
[0100]
[0101] where k ∈ [1, L], K U1 = 0, L is the length of the generated key, determined by the number of DMRSs and N;
[0102] Step 308: B uses binary quantization to quantize into binary to obtain the physical layer key K B , specifically represented as:
[0103]
[0104] where K B1 = 0.
[0105] 4. U and B use the XOR operation to encrypt the transmitted and received Msg3 signaling information respectively;
[0106] The specific steps are as follows:
[0107] Step 401: U encrypts the sent Msg3 message using the exclusive-or operation;
[0108] Step 402: B decrypts the received Msg3 message using the exclusive-or operation.
[0109] 5. Calculate the access rate of users
[0110] Step 501: Calculate the access rate of legitimate users. The specific operation is as follows:
[0111] Legitimate user access rate = Number of successful accesses by legitimate users / Number of accesses;
[0112] Step 502: Calculate the access rate of unauthorized users. The specific operation is as follows:
[0113] Illegal user access rate = Number of successful accesses by illegal users / Number of accesses.
[0114] 6. Calculate the key disagreement rate (KDR) of the algorithm. The specific operation is as follows:
[0115]
[0116] 7. Use the randomness test suite provided by the National Institute of Standards and Technology (NIST) to evaluate the randomness variation of the keys of U and B.
[0117] Figure 3 The KDRs under different signal-to-noise ratios, channel conditions, and statistical levels N are given. It can be seen from the figure that especially in the case of low signal-to-noise ratio, compared with the physical layer key generation algorithm based on discrete wavelet packet transform (DWPT), the key inconsistency performance of the algorithm proposed in this chapter has been improved by about 14.25%, and it has better KDR performance. As shown in the figure, the KDR decreases with the increase of the signal-to-noise ratio. The KDR decreases with the increase of N. Compared with the statistical level of N = 7, the performance of the KDR under the condition of N = 5 has increased by about 20%. The KDR decreases with the increase of the resolvable paths P. Compared with the channel condition of Rayleigh8, the performance of the KDR under the Rayleigh2 condition has increased by about 7%.
[0118] Figure 4The access rates at U and Eve are given under different signal-to-noise ratios and channel conditions when the statistical level N = 6. The access rate of the proposed algorithm at U increases with the increase of SNR. The performance of the terminal access rate at U decreases with the increase of the resolvable paths P. Compared with the Rayleigh8 condition, the performance of the terminal access rate under the Rayleigh2 condition increases by about 4.23% on average. Under the Rayleigh8 condition, the terminal access rate at Eve is lower than 7%.
[0119] Figure 5 The delays at B and U in the proposed algorithm, the original random access process without a physical layer key generation algorithm defined in the protocol, and the physical layer key algorithm based on DWPT are given under the additive white Gaussian noise (AWGN) channel condition. The results show that compared with the original random access process, the total additional delays of the proposed algorithm at B and U are close to 100 μs. Compared with the physical layer key algorithm based on DWPT, the delay of the proposed algorithm is reduced by 10%.
[0120] Table 1 gives the p-values of the physical layer keys generated under different channel conditions. The gray part indicates that the generated keys do not pass the NIST test. The results show that the randomness of the generated keys increases with the increase of the resolvable paths P.
[0121] Table 1 shows the p-values of the physical layer keys generated under different channel conditions
[0122]
[0123]
[0124] In summary, by implementing a method for generating physical layer keys based on DWT in a random access process according to an embodiment of the present invention, the access rate of legitimate users is guaranteed, while unauthorized users are prevented from accessing the network. Moreover, the proposed algorithm effectively reduces the key inconsistency rate and improves the delay performance. Compared with existing authentication algorithms and key generation algorithms, the present invention effectively avoids the problems of key distribution and management in existing authentication algorithms and the application of key generation algorithms in scenarios with limited power and delay.
[0125] Although specific embodiments of the present invention are disclosed for illustrative purposes, which are intended to help understand the content of the present invention and implement it accordingly, those skilled in the art can understand that various substitutions, changes, and modifications are possible without departing from the spirit and scope of the present invention and the appended claims. Therefore, the present invention should not be limited to the content disclosed in the best embodiments, and the scope of protection claimed by the present invention is defined by the scope of the claims.
Claims
1. A method for generating a physical layer key based on DWT in a random access process, the steps of which include: 1) A legitimate mobile terminal U sends a random preamble sequence Msg1 to a legitimate base station B; 2) After receiving Msg1, the legitimate base station B sends a random access response message Msg2 to the legitimate mobile terminal U; 3) The legitimate mobile terminal U collects channel state information according to the demodulation reference signal DMRS in the received Msg2 message; 4) The legitimate mobile terminal U performs key consistency enhancement based on discrete wavelet transform DWT on the collected channel state information, and performs a quantization operation on the enhanced information to obtain a physical layer key; 5) The legitimate mobile terminal U encrypts the information carried in the radio resource control RRC setup request Msg3 using the physical layer key; 6) The legitimate mobile terminal U sends the encrypted Msg3 to the legitimate base station B; 7) The legitimate base station B collects channel state information according to the demodulation reference signal DMRS in the received Msg3 message; 8) The legitimate base station B performs key consistency enhancement based on discrete wavelet transform DWT on the collected channel state information, and performs a quantization operation on the enhanced information to obtain a physical layer key; 9) The legitimate base station B decrypts the received Msg3 message using the generated physical layer key to obtain the information carried in Msg3; then generates a radio resource control RRC message Msg4 based on the information carried in the obtained Msg3 and sends it to the legitimate mobile terminal U; 10) After receiving Msg4, the legitimate mobile terminal U sends a response ACK of the hybrid automatic repeat request of the Msg4 message to the legitimate base station B.
2. The method according to claim 1, characterized in that, In step 3), the method for the legitimate mobile terminal U to collect channel state information according to the demodulation reference signal DMRS in the received Msg2 message is as follows: The legitimate mobile terminal U performs LS channel estimation according to the demodulation reference signal DMRS in the received Msg2 message to obtain the instantaneous characteristics of the transmission channel state information at time t1. Among them, the legitimate mobile terminal U receives the demodulation reference signal DMRS at time t1, e U (t1) represents the channel estimation error at the legitimate mobile terminal U at time t1, h U (t1) is the propagation channel of the legitimate mobile terminal U at time t1.
3. The method according to claim 2, wherein In step 7), the method for the legitimate base station B to collect channel state information according to the demodulation reference signal DMRS in the received Msg3 message is as follows: the legitimate base station B performs LS channel estimation according to the demodulation reference signal DMRS in the received Msg3 message to obtain the instantaneous characteristics of the transmission channel state information wherein, the legitimate base station B receives the demodulation reference signal DMRS at time t2, and t2 - t1 is less than the coherence time T c ; is the channel estimation of the instantaneous characteristics of the transmission channel information of the legitimate base station B at time t2 e B (t2) represents the channel estimation error at the legitimate base station B at time t2, h B (t2) is the propagation channel of the legitimate base station B at time t2.
4. The method according to claim 2 or 3, characterized in that, The method for the legitimate mobile terminal U to obtain the physical layer key is as follows: The legitimate mobile terminal U uses DWT to divide the extracted channel state information into high and low frequency information. Where, * is the convolution operation, l and g are the low-pass filter and high-pass filter designed based on the wavelet basis respectively. represents the approximate coefficient of the channel estimation of the legitimate mobile terminal U. represents the detail coefficient of the high-frequency channel information of the legitimate mobile terminal U; then the legitimate mobile terminal U divides the detail coefficients of every N high-frequency channel information into a group, and calculates the statistical average value g of the detail coefficients of each group. U ; then the legitimate mobile terminal U combines each group of approximate coefficients of the channel estimation and the statistical average value g of the detail coefficients U to obtain Then the legitimate mobile terminal U quantizes it into binary to obtain the physical layer key K. U , where the (k + 1)-th binary quantization value U in the physical layer key K K U1 = 0, L is the length of the physical layer key K U , is the k-th channel estimation value in 5. The method according to claim 2 or 3, characterized in that, The method for the legitimate base station B to obtain the physical layer key is as follows: The legitimate base station B uses DWT to divide the extracted channel state information into high-frequency and low-frequency information. where * is the convolution operation, represents the approximate coefficient of the channel estimation of the legitimate base station B, and represents the detail coefficient of the high-frequency channel information of the legitimate base station B; then the legitimate base station B divides the detail coefficients of every N high-frequency channel information into a group and calculates the statistical average value g of each group of detail coefficients. B Then the legitimate base station B combines the approximate coefficient of each group of channel estimations B and the statistical average value g of the detail coefficients to obtain Then the legitimate base station B quantizes B into binary to obtain the physical layer key K. B where the (k + 1)-th binary quantization value in the physical layer key K where K B1 = 0, is the k-th channel estimation value in 6. The method according to claim 1, characterized in that In step 5), the legitimate mobile terminal U encrypts the sent Msg3 message using an exclusive or operation; in step 9), the legitimate base station B decrypts the received Msg3 message using an exclusive or operation.