Method and related device for wireless secure communication using physical layer shared security keys in environmental internet of things network
By using wireless channel reciprocity and additional information to generate physical layer shared security keys in the AIoT network, the problems of long time to generate keys in AIoT devices in the prior art are solved, and fast and secure key generation and communication are achieved.
Patent Information
- Application Number
- CN202380081922.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-12-01
- Filing Date
- 2023-12-01
- Publication Date
- 2025-07-04
AI Technical Summary
When generating the physical layer shared security key, the prior art cannot effectively solve the key distribution problem of low-power or passive IoT devices. The existing system is mainly designed for devices with more capabilities, and cannot meet the low storage and low computing power requirements of AIoT devices.
During the communication between the first node and the second node of the AIoT network, wireless channel reciprocity and additional information are used to generate a physical layer shared security key, and a hybrid shared key generation mechanism is adopted to reduce the key generation time and improve security.
It enables faster generation of shared security keys in AIoT devices, reduces key generation time, improves security, and does not require pre-configuration of shared keys, suitable for devices with low storage and low computing power.
Smart Images

Figure CN120266432A_ABST
Abstract
Description
Cross - Reference to Related Applications
[0001] This application claims the priority benefit of U.S. Provisional Application No. 63 / 429,432, filed on December 1, 2022, which is hereby incorporated by reference in its entirety. Technical Field
[0002] This application relates to wireless communication, and more particularly, to a method and related devices for wireless secure communication using a physical - layer shared security key in an ambient internet - of - things (AIoT) network. Background Art
[0003] Ambient - powered Internet of Things (IoT) devices are IoT devices powered by energy harvesting, which have no battery or only limited energy storage capabilities (e.g., using capacitors). 5G ambient IoT (AIoT) services can support various use cases, such as automated warehousing, inventory management, smart grids, non - public logistics, manufacturing, IoT sensors, and smart home applications.
[0004] AIoT devices can be designed without a traditional battery. Instead, AIoT devices are typically powered by energy harvesting. The energy collected by AIoT devices usually depends on radio waves, solar energy, light, motion / vibration, heat, pressure, or any other power source. Thus, AIoT devices can utilize the power generated by using energy harvesting to communicate with 5G UEs or 5G base stations. Security is very important for protecting network connections and data that may be at risk of exposure and compromise, even for low - power or near - zero - power devices (such as AIoT). Other terms such as Passive IoT (PIoT), zero - power IoT, and low - power IoT may be synonymous with AIoT.
[0005] Typical security can be provided by a physical - layer shared security key generation mechanism between an AIoT device and a user equipment (UE) (or a base station), which relies on the wireless channel reciprocity of the communication between the two entities. Then, the generated shared key can be used to provide additional security services, such as encryption and integrity protection for the communication between the two entities.
[0006] Many techniques rely on various properties of wireless channel reciprocity to derive a shared key between two communication entities. Some of the properties used are signal strength, channel impulse response, channel state information, etc. Common bits are then extracted from a combination of information such as wireless channel information or parameter measurements that exist only in the communication between two entities and can only be extracted by the two neighboring entities. Once a sufficient number of bits (e.g., 128 bits or 256 bits) are extracted, these bits form the shared key and can be used by the two entities to protect the information being exchanged.
[0007] There are several drawbacks to physical layer security for key generation in existing systems.
[0008] One drawback is that the mechanism is mainly designed to solve the key distribution problem. In any communication system, typical key distribution relies on pre-configuring a shared key between two communication entities. For example, in 5G (and previous generation networks), a SIM card containing the shared key is delivered to the user (delivered at the time of purchase, sent by mail, or transmitted over the air via the latest used electronic subscriber identification module (eSIM)) and inserted into the handheld device. The same information is also input into the network entity. The distribution of subscriber identification module (SIM) cards needs to be scaled up massively to support billions of users. The generation of physical layer security shared keys does not require such large-scale key distribution.
[0009] A second drawback is that existing systems are designed for more capable devices (e.g., devices equipped with an energy source such as a battery and having higher computing power such as the chipset used in a smartphone), rather than for ambient Internet of Things (IoT) (AIoT) devices. The more power a device has, the easier it is to extract high-quality bits during the exchange, and the longer the device communicates, the more bits can be generated.
[0010] For AIoT devices, there is a lack of storage devices for storing large amounts of data (such as security keys). In large-scale scenarios (such as billions of devices), it is extremely difficult to pre-configure pre-shared keys for the devices. These devices have low costs and lack the more advanced computing capabilities required to provide security services (such as hashing, encryption, etc.). A typical communication cycle involves another device (such as a UE or a base station) starting to radiate energy (during the process of attempting to communicate with the AIoT device). Within a short period of time after the AIoT device is awakened, the AIoT device must collect sufficient energy to perform the tasks required by the device within a very short time, such as establishing a communication channel, preparing the content of the communication, and sending the communication in the established communication channel, and then going offline. Additionally, within the short period of time when the AIoT device is active, necessary security must be provided to protect the communication. Summary of the Invention
[0011] The objective of this application is to provide a method for wireless secure communication and a first node of an Ambient Internet of Things (AIoT) network to solve one or more of the above existing problems.
[0012] In a first aspect, some embodiments of this application provide a method for wireless secure communication, which is applied to a first node of an Ambient Internet of Things (AIoT) network. The method includes: generating a physical layer shared security key based on the wireless channel reciprocity of the communication between the first node and a second node of the AIoT network and additional information that is not derived from the wireless channel reciprocity; and exchanging messages with the second node using the physical layer shared security key.
[0013] In a second aspect, some embodiments of this application provide a first node of an Ambient Internet of Things (AIoT) network, including at least one processor, and the at least one processor is configured to: generate a physical layer shared security key based on the wireless channel reciprocity of the communication between the first node and a second node of the AIoT network and additional information that is not derived from the wireless channel reciprocity; and exchange messages with the second node using the physical layer shared security key.
[0014] In this application, the first node 2 of the AIoT network performs the following operations: generating a physical layer shared security key based on the wireless channel reciprocity of the communication between the first node and a second node of the AIoT network and additional information that is not derived from this wireless channel reciprocity; and exchanging messages with the second node using this physical layer shared security key. By providing additional information during communication to generate the physical layer shared security key, the generation of the shared security key can be achieved more quickly. Brief Description of the Drawings
[0015] To more clearly illustrate the embodiments of the present application or related technologies, the following drawings that will be described in the embodiments are briefly introduced. Apparently, the drawings are only some embodiments of the present application, and those of ordinary skill in the art can obtain other drawings based on these drawings without meeting the prerequisite conditions.
[0016] Figure 1 is a schematic diagram showing an exemplary AIoT communication system.
[0017] Figure 2 is a block diagram showing an AIoT network according to some embodiments of the present application.
[0018] Figure 3 is a flowchart of a method for wireless secure communication of a first node applied to an AIoT network according to some embodiments of the present application.
[0019] Figure 4 is a schematic diagram showing hybrid physical layer key generation with additional inputs in an AIoT network according to some embodiments of the present application. Detailed Embodiments
[0020] The technical problems, structural features, achieved objectives, and effects of the embodiments of the present disclosure are described in detail below with reference to the drawings. Specifically, the terms in the embodiments of the present application are only used for the purpose of describing specific embodiments and do not limit the present disclosure.
[0021] In this document, combinations such as "at least one of A, B, or C", "one or more of A, B, or C", "at least one of A, B, and C", "one or more of A, B, and C", or "A, B, and / or C" can be: only A, only B, only C, A and B, A and C, B and C, or A and B and C, where any combination can include one or more members of A, B, or C.
[0022] The present application provides wireless channel reciprocity for generating one or more keys. The one or more keys are generated by providing additional information during communication, such that the generation of shared security keys can be achieved faster compared to other devices.
[0023] The present application provides a hybrid shared key generation mechanism that improves the generation of physical layer shared keys by introducing additional parameters that are not derived from wireless channel reciprocity.
[0024] In some embodiments, once one or more keys are generated, they can be used as a one-time pad (OTP). The plaintext message (or information) to be protected is XORed with the OTP to form the ciphertext. Then, the ciphertext is sent over the air.
[0025] Figure 1 It is a schematic diagram showing an exemplary Ambient Internet of Things (AIoT) communication system. The AIoT communication system may include a base station (e.g., gNB in 5G), a user equipment (UE), and an AIoT device or tag. Figure 1 Four scenarios to which the present application can be applied are shown:
[0026] Case 1 (UE-assisted power supply / trigged zero-power communication), when receiving a signaling from the base station, the UE supplies power to the AIoT device or tag and / or triggers the AIoT device or tag to perform backscatter communication with the base station.
[0027] Case 2 (network-powered / trigged sidelink-based zero-power communication), the base station supplies power to the AIoT device or tag and / or triggers the AIoT device or tag to perform backscatter communication with the UE, and the UE transmits the information received from the AIoT device or tag to the base station.
[0028] Case 3 (UE-assisted energy supply zero-power communication), when receiving a signaling from the base station, the UE supplies power to the AIoT device or tag, and the base station triggers the AIoT device or tag to perform backscatter communication with the base station.
[0029] Case 4 (network-controlled sidelink-based zero-power communication), when receiving a signaling from the base station, the UE supplies power to the AIoT device or tag and / or triggers the AIoT device or tag to perform backscatter communication with the UE, and the UE transmits the information received from the AIoT device or tag to the base station.
[0030] Figure 2 It is a block diagram showing an AIoT network 1 according to some embodiments of the present application. Referring to Figure 2 , the AIoT network 1 includes a first node 2 and a second node 3, where a wireless secure communication is established between the first node 2 and the second node 3. The first node 2 includes at least one processor 4, and the at least one processor is configured to generate a physical layer shared security key and use the generated physical layer shared security key to exchange messages or information with the second node 3.
[0031] The second node 3 can perform the same or similar operations to generate a physical layer shared security key. The first node 2 can encrypt the message or information using the physical layer shared security key, and then the second node 3 decrypts the encrypted message or information using the physical layer shared security key generated on the second node 3. Alternatively, the second node 3 can encrypt the message or information using the physical layer shared security key, and then the first node 2 decrypts the encrypted message or information using the physical layer shared security key generated on the first node 2.
[0032] In some embodiments, the first node 2 is an AIoT device or tag, and the second node 3 is a user device or base station. In other embodiments, the first node 2 is a user device or base station, and the second node 3 is an AIoT device or tag.
[0033] In some embodiments, Figure 1 Any one of the four communication scenarios shown (i.e., Scenario 1 to Scenario 4) can be applied to the AIoT device or tag, the user device, and the base station.
[0034] Specifically, a physical layer shared security key is generated based on the wireless channel reciprocity of the communication between the first node 2 and the second node 3 of the AIoT network 1 and additional information that is not derived from the wireless channel reciprocity. Further details are provided below.
[0035] As described above, the generation of the physical layer shared security key between the AIoT device or tag and the UE (or base station) depends on the wireless channel reciprocity of the communication between the two entities. The characteristics of the wireless channel reciprocity used to derive the shared key between two communicating entities include but are not limited to signal strength (e.g., reference signal strength (RSS)), channel impulse response (CIR), channel state information (CSI), etc.
[0036] Using the characteristics based on wireless channel reciprocity may require multiple channel sounding, channel measurement, and channel tuning between the two entities in order to extract common bits. If the extracted common bits are used as a long-term shared key, a multiple of 128 bits (e.g., 128 bits or 256 bits) is required. Since the process of extracting common bits is slow, several iterations may be required to extract the required bits. This takes a lot of time and cannot be tolerated by the AIoT device.
[0037] In the present application, during the current AIoT communication cycle and during the process of establishing the communication channel, additional information is input to generate the physical layer shared security key. For example, the additional information can be injected into the randomness generation process (i.e., the randomization process). Some examples of additional information that can be injected into the randomness generation process (i.e., the randomization process) are:
[0038] 1. Additional random numbers (which can be sent during channel establishment);
[0039] 2. System time (which can be the rough system time saved locally or the time required for channel synchronization);
[0040] 3. Counter (which can be sent during channel establishment);
[0041] 4. Device identifier (known only to the device and the UE / BS);
[0042] 5. Serial number (known only to the device and the UE / BS); and
[0043] 6. Other relevant information.
[0044] During the randomization process, the characteristics of wireless channel reciprocity and additional information can be randomly selected to extract common bits in the physical layer shared security key generation process. It can be transmitted between the device and the UE / BS which information has been selected during the randomization process to extract the common bits.
[0045] By adding additional information to the randomization process, fewer iterations are required to extract the same number of required bits to be used as the shared key (or as the key stream). Using parameters in key generation is a practice that does not reduce the security of the key being generated. Therefore, by adopting additional input for the randomization process, the security and quality of the key generated based on channel reciprocity will not decline either.
[0046] In some embodiments, the physical layer shared security key can be used as a one-time pad (OTP). Additionally, at least one processor 4 of the first node 2 can perform an XOR operation on the plaintext message or information to be protected using the OTP to form the ciphertext. Then, the ciphertext can be sent to the second node 3 of the AIoT network 1 via air transmission.
[0047] Figure 3 is a flowchart of a method 100 for wireless secure communication applied to the first node 2 of the AIoT network 1 according to some embodiments of the present application. The method 100 can be applied to Figure 1 the scenarios shown (i.e., Case 1 to Case 4). In combination with Figure 2 referring to Figure 3 , the method 100 executed by the first node 2 (or the second node 3) of the AIoT network 1 includes the following steps.
[0048] In step 110, at least one processor 4 of the first node 2 generates a physical layer shared security key based on the wireless channel reciprocity of the communication between the first node 2 and the second node 3 of the AIoT network 1 and additional information that is not derived from the wireless channel reciprocity.
[0049] The characteristics of the wireless channel reciprocity used to generate the physical layer shared security key between the first node 2 and the second node 3 of the AIoT network can include reference signal strength (RSS), channel impulse response (CIR), channel state information (CSI), etc. The first node 2 and the second node 3 of the AIoT network are aware of such information during the channel establishment process between the two communication entities.
[0050] In addition to the property of wireless channel reciprocity, additional information that is not derived from the wireless channel reciprocity is involved in generating the physical layer shared security key. The additional information includes but is not limited to additional random numbers, system time, count, device identifier, serial number, etc. The first node 2 and the second node 3 can communicate with each other during channel establishment to obtain information on additional random numbers and count. This can improve security compared to transmitting such information after channel establishment, because after channel establishment, secure communication has not been established between the two communication entities. The device identifier or serial number of the first node 2 may already be known to the second node 3. For example, an AIoT device or tag can store its device identifier or serial number in its memory, and the UE / BS can know such information when the AIoT device or tag is registered. The system time can be the rough system time maintained on the first node 2 and the second node 3, or the rough system time synchronized between the two nodes 2 and 3 via channel synchronization.
[0051] Then, the above two types of information can be fed into the randomization process. In the randomization process, the property of wireless channel reciprocity and the additional information are randomly selected for the generation of the physical layer shared security key. That is, some of the property of wireless channel reciprocity and the additional information are randomly selected to extract common bits from this information, thereby generating the physical layer shared security key. Which information is selected in the randomization process can be transmitted between the first node 2 and the second node 3. The random selection can be performed on one of the two nodes 2 and 3, and then that node can transmit the selected information to the other node. Alternatively, both nodes 2 and 3 can also perform random selection. Then, the two nodes 2 and 3 transmit to each other which information they have selected. The common information selected by both nodes 2 and 3 is used to extract common bits to generate the physical layer shared security key.
[0052] In step 120, at least one processor 4 of the first node 2 exchanges messages with the second node 3 using the physical layer shared security key.
[0053] The second node 3 can perform a similar or identical process to generate the physical layer shared security key, which is the same as the physical layer shared security key generated by the first node 2. Then, the first node 2 can encrypt the message using the physical layer shared security key generated by the first node 2 and pass the encrypted message to the second node 3, and then the second node 3 can decrypt the encrypted message using the physical layer shared security key generated by the second node 3. Therefore, messages can be sent and received via a protected communication link between the first node 2 and the second node 3.
[0054] In the present application, the first node 2 of the AIoT network performs the following operations: generating a physical layer shared security key based on the wireless channel reciprocity of the communication between the first node and the second node of the AIoT network and additional information not derived from the wireless channel reciprocity; and using the physical layer shared security key to exchange messages with the second node. By providing additional information during communication to generate the physical layer shared security key, the generation of the shared security key can be achieved more quickly.
[0055] Further details of method 100 can be referred to other parts of the present disclosure and will not be elaborated here.
[0056] Figure 4 FIG. is a schematic diagram showing hybrid physical layer key generation with additional input in an AIoT network according to some embodiments of the present application. It should be noted that the AIoT device and the UE (or base station) perform the same or similar operations to generate the physical layer shared security key and use the physical layer shared security key to exchange messages.
[0057] Refer to Figure 4 , channel establishment 1a and channel establishment 1b are performed by the AIoT device and the UE (or base station). Various characteristics of the wireless channel reciprocity (such as RSS, CIR, CSI, etc.) are transmitted between the two entities. The characteristics of the wireless channel reciprocity and the additional information (such as additional random numbers, system time, counters, device ids, serial numbers, etc.) from step 2a and step 2b are respectively injected into the randomization process 3a and the randomization process 3b.
[0058] In the randomization process 3a and the randomization process 3b, the characteristics of the wireless channel reciprocity and the additional information can be randomly selected for the generation of the physical layer shared security key. After randomization 3a and randomization 3b, quantization 4a and quantization 4b and coordination 5a and coordination 5b are performed. Various randomization, quantization, and coordination techniques can be used in this hybrid physical layer shared key generation mechanism, depending on the implementation. Randomization 3a and randomization 3b can introduce randomness into the key generation process, making it more difficult for an attacker to predict or replicate the key. Quantization 4a and quantization 4b involve discretizing continuous signal values into a finite set of levels and simplifying the signal information into a form that can be used for key generation, making it computationally feasible. The main role of coordination 5a and coordination 5b in the generation of the physical layer shared security key is to resolve and correct the differences between the key sequences generated at different locations. It should be noted that these processes (i.e., randomization 3a and randomization 3b, quantization 4a and quantization 4b, and coordination 5a and coordination 5b) are known in the art and will not be elaborated here.
[0059] In steps 6a and 6b, a shared key stream is generated. The AIoT device can use the shared key stream 6a to encrypt the message from step 7a and transmit the encrypted message via the protected communication 8, and then the UE (or the base station) can use the shared key stream 6b to decrypt the encrypted message to obtain the plaintext message. In addition, the UE (or the base station) can use the shared key stream 6b to encrypt the message from step 7b and transmit the encrypted message via the protected communication 8, and then the AIoT device can use the shared key stream 6a to decrypt the encrypted message to obtain the plaintext message.
[0060] The current hybrid physical layer shared key generation benefits the security of communication between the AIoT device and the UE / base station in many aspects.
[0061] First, compared with existing AIoT devices, the hybrid physical layer shared key generation reduces the time used for communication between the AIoT device and the UE / base station to derive the same number of bits that can be used as a shared key.
[0062] Second, the shared key extracted using this technology can be used as a one-time pad (OTP), which can protect the information sent from the AIoT device to the UE / base station. The OTP provides very high security because the key stream used to protect the communication is not reused, thus eliminating attacks involving collecting ciphertext and plaintext pairs and comparing the two.
[0063] Third, using the OTP does not require an AIoT device with power-consuming operations such as hashing or encryption. Each message (such as the information being sent) is protected by applying the exclusive OR operation to the message and the OTP.
[0064] As an alternative to the hybrid physical layer key generation in the AIoT communication system, a less efficient physical layer key generation method can be adopted. For example, in some embodiments, a shared key in traditional computationally intensive encryption or hashing operations that require a large amount of computation can be used instead of the OTP for protecting communication in the AIoT communication system.
[0065] The embodiments of the present application also provide a computer-readable storage medium for storing a computer program. The computer-readable storage medium enables a computer to execute the corresponding processes implemented in each method of the embodiments of the present application. For the sake of brevity, the details will not be described herein again.
[0066] The embodiments of the present application also provide a computer program product including computer program instructions. The computer program product enables a computer to execute the corresponding processes implemented in each method of the embodiments of the present application. For the sake of brevity, the details will not be described herein again.
[0067] The embodiments of the present application also provide a computer program. This computer program enables a computer to execute the corresponding processes implemented in each method of the embodiments of the present application. For the sake of brevity, the details will not be elaborated here.
[0068] Those skilled in the art will understand that any of a variety of different technologies and processes can be used to represent information and signals. For example, the data, instructions, commands, information, signals, bits, symbols, and chips referred to throughout the above description can be represented by voltages, currents, electromagnetic waves, magnetic fields or magnetic particles, optical fields or optical particles, or any combination thereof.
[0069] In addition, those skilled in the art will understand that the various illustrative logical blocks, modules, circuits, and algorithm steps described in connection with the embodiments disclosed herein can be implemented as electronic hardware, computer software, or a combination of both.
[0070] To clearly illustrate this interchangeability of hardware and software, the various illustrative components, blocks, modules, circuits, and steps have been described above generally in terms of their functionality. Whether this functionality is implemented as hardware or software depends on the particular application and the design constraints imposed on the overall system. Those skilled in the art can implement the described functionality in different ways for each particular application, but such implementation decisions should not be construed as causing a departure from the scope of the present invention.
[0071] The methods, sequences, and / or algorithms described in connection with the embodiments disclosed herein can be directly embodied in hardware, in software modules executed by a processor, or in a combination of both. The software modules can reside in RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor such that the processor can read information from, and write information to, the storage medium. In an alternative, the storage medium can be integrated into the processor.
[0072] It should be understood that any embodiment disclosed herein as "non-transitory" does not exclude any physical storage medium, but only excludes the possibility that the medium can be construed as a transitory propagated signal.
[0073] The elements and components of the embodiments of the present invention can be physically, functionally, and logically implemented in any suitable manner. In fact, the functions can be implemented in a single unit, in multiple units, or as part of other functional units. Although the present invention has been described in conjunction with some embodiments, the present invention is not intended to be limited to the specific forms set forth herein. Instead, the scope of the present invention is only limited by the appended claims. Additionally, although features may seem to be described in connection with specific embodiments, those skilled in the art will recognize that the various features of the described embodiments can be combined in accordance with the present invention. In the claims, the term "comprising" does not exclude the presence of other elements or steps.
[0074] Furthermore, although listed separately, a plurality of devices, elements, or method steps can be implemented by, for example, a single unit or processor. Additionally, although the individual features may be included in different claims, these features can be advantageously combined, and including them in different claims does not mean that the combination of features is not feasible and / or disadvantageous. Moreover, including a feature in a particular class of claims does not mean a limitation to that class, but rather indicates that the feature is equally applicable to other classes of claims where appropriate.
[0075] Moreover, the order of the features in the claims does not mean that the features must be performed in any particular order, and in particular, the order of the individual steps in method claims does not mean that the steps must be performed in that order. Instead, these steps can be performed in any suitable order. Additionally, singular references do not exclude plural. Thus, references to "a", "an", "first", "second", etc. do not exclude plural.
[0076] Most importantly, although the preferred embodiments of the present application have been described in detail and described, various modifications and variations can be made by those of ordinary skill in the art. Therefore, the embodiments of the present application are described in an illustrative rather than a restrictive sense. The present application is not intended to be limited to the specific forms shown, and all modifications and variations that maintain the spirit and scope of the present application are covered within the scope defined by the appended claims.
Claims
1. A method for wireless secure communication, applied to a first node of an Ambient Internet of Things (AIoT) network, the method comprising: Generating a physical layer shared security key based on the wireless channel reciprocity of the communication between the first node and a second node of the AIoT network and additional information not derived from the wireless channel reciprocity; And Exchanging messages with the second node using the physical layer shared security key.
2. The method according to claim 1, wherein The first node is an AIoT device, and the second node is a user equipment or a base station.
3. The method according to claim 1, wherein, The first node is a user equipment or a base station, and the second node is an AIoT device.
4. The method according to claim 1, wherein, The characteristics of the wireless channel reciprocity include at least one of signal strength, channel impulse response, and channel state information.
5. The method according to claim 1, wherein, The additional information includes at least one of an additional random number, system time, counter, device identifier, and serial number.
6. The method according to claim 1, wherein The characteristics of the wireless channel reciprocity and the additional information are input into a randomization process to generate the physical layer shared security key.
7. The method according to claim 1, wherein, The physical layer shared security key is used as a key stream.
8. The method according to claim 1, wherein The physical layer shared security key is used as a one-time pad (OTP).
9. The method according to claim 8, wherein Before the exchanging step, the method further comprises: Performing an exclusive OR (XOR) operation on the plaintext message or information to be protected using the OTP to form a ciphertext.
10. A first node of an Ambient Internet of Things (AIoT) network, comprising at least one processor configured to: Generate a physical layer shared security key based on the wireless channel reciprocity of the communication between the first node and a second node of the AIoT network and additional information not derived from the wireless channel reciprocity; and Exchange messages with the second node using the physical layer shared security key.
11. The first node according to claim 10, wherein, The first node is an AIoT device, and the second node is a user equipment or a base station.
12. The first node according to claim 10, wherein, The first node is a user equipment or a base station, and the second node is an AIoT device.
13. The first node according to claim 10, wherein, The characteristics of the wireless channel reciprocity include at least one of signal strength, channel impulse response, and channel state information.
14. The first node according to claim 10, wherein, The additional information includes at least one of an additional random number, system time, counter, device identifier, and serial number.
15. The first node according to claim 10, wherein, The characteristics of the wireless channel reciprocity and the additional information are input into a randomization process to generate the physical layer shared security key.
16. The first node according to claim 10, wherein, The physical layer shared security key is used as a key stream.
17. The first node according to claim 10, wherein, The physical layer shared security key is used as a one-time pad (OTP).
18. The first node according to claim 17, wherein, The at least one processor is further configured to: Perform an exclusive OR (XOR) operation on the plaintext message or information to be protected using the OTP to form a ciphertext.