Multi-terminal hidden key generation method based on polar code and PPM joint modulation
Through the joint modulation method of polar code and PPM, a multi-terminal hidden key generation algorithm is constructed, which solves the generalization and concealment of key generation in multi-terminal communication, and realizes effective key generation and protection in different channel environments.
Patent Information
- Application Number
- CN202510497575.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-21
- Publication Date
- 2025-07-18
AI Technical Summary
In the prior art, in multi-terminal communication scenarios, hidden key generation algorithms lack generalization capabilities, making it difficult to effectively generate and protect keys in different channel environments, and illegal nodes can easily identify the key generation process.
The combined modulation method of polar code and PPM is adopted to construct the key elements of the legal receiving end by generating a random sequence, polarization processing and a bit set, and generate target messages in combination with shared random information, communicate using discrete memory-free channels, and determine the key through likelihood ratio calculation and decoding.
Generating keys at low frame error rates improves the confidentiality and attack resistance of keys, enhances the applicability to different channels, and makes it difficult for illegal nodes to identify the key generation process.
Smart Images

Figure CN120342594A_ABST
Abstract
Description
Technical Field
[0001] The invention belongs to the technical field of key generation, and in particular relates to a multi-terminal concealed key generation method based on polar code and PPM joint modulation. Background Art
[0002] In today's digital age, information security is of vital importance. With the continuous development of communication technology, multi-terminal communication scenarios are becoming increasingly popular, such as communication between a large number of devices in the Internet of Things and interaction between distributed nodes in smart grids. In these scenarios, ensuring the security and confidentiality of communication has become a key issue that needs to be solved urgently.
[0003] Related research focuses more on one aspect, namely key generation or covert communication, and there is less research on covert key generation algorithms that combine the two. First, existing research focuses more on single-user scenarios and dual legal receivers, while there is almost no research on covert key generation for multiple legal receivers. Even the research on single-user scenarios has limitations: Kadampot et al. proposed a theoretically feasible solution for covert key generation, but did not implement the algorithm in detail. Xu Ming et al. proposed a covert key generation solution under underwater acoustic channel conditions, but it is only applicable to underwater acoustic channels. Secondly, the current implementation of covert key generation basically relies on Polar code encoding and decoding, in which a very important step that affects the results is the channel state estimation of the sub-channel. Different channels often have different channel state estimation algorithms, which makes it difficult to generalize. Summary of the invention
[0004] In view of this, the purpose of the present invention is to provide a multi-terminal hidden key generation method based on polar code and PPM joint modulation to meet the requirements of hidden key generation while ensuring confidentiality and achieving generalization.
[0005] In order to achieve the above object, the present invention provides the following technical solutions:
[0006] According to a first aspect, the present invention provides a multi-terminal hidden key generation method based on polar code and PPM joint modulation, which is applied to a transmitting end, comprising: generating a random sequence according to Bernoulli distribution as an initial signal; performing PPM modulation on the initial signal to obtain a target PPM signal, and the target PPM signal communicates with multiple legitimate receiving ends through a discrete memoryless channel;
[0007] The initial signal is polar processed using a polarization matrix to obtain a polarized signal; multiple groups of bit sets are selected from the polarized signal to respectively construct key elements, first information, and second information of a legitimate receiving end; according to the shared random information, first information, and second information of this round, a target message is generated. The shared random information of this round is determined according to the key elements of the legitimate receiving end in the previous round. This target message is used by the legitimate receiving end to reconstruct and generate a key based on the target message and the observation sequence of the target PPM signal.
[0008] According to a second aspect, the present invention provides a multi-terminal covert key generation method based on joint modulation of polar codes and PPM, which is applied to any legitimate receiving end and includes: obtaining a target message and an observation sequence of the target PPM signal; performing PPM demodulation on the observation sequence to obtain a demodulated signal; calculating the likelihood ratio of each symbol signal according to the intensity of a single symbol signal in the demodulated signal and the total symbol signal intensity detected by the legitimate signal receiving end; performing decoding using a target decoding algorithm according to the likelihood ratio of each symbol signal and the target message to obtain a target polarized signal; determining key elements with the sending end according to the target polarized signal; and determining the key with the sending end according to multiple key elements.
[0009] According to a third aspect, the present invention provides a multi-terminal covert key generation device based on joint modulation of polar codes and PPM, including: an initial signal generation module for generating a random sequence according to a Bernoulli distribution as an initial signal; a PPM signal modulation module for performing PPM modulation on the initial signal to obtain a target PPM signal, and the target PPM signal communicates with multiple legitimate receiving ends through a discrete memoryless channel; a polarization module for polar processing the initial signal using a polarization matrix to obtain a polarized signal; a construction module for selecting multiple groups of bit sets from the polarized signal to respectively construct key elements, first information, and second information of a legitimate receiving end; and a target message generation module for generating a target message according to the shared random information, first information, and second information of this round. The shared random information of this round is determined according to the key elements of the legitimate receiving end in the previous round. This target message is used by the legitimate receiving end to reconstruct and generate a key based on the target message and the observation sequence of the target PPM signal.
[0010] According to a fourth aspect, the present invention provides a multi-terminal covert key generation device based on joint modulation of polar codes and PPM, including: an observation module for acquiring a target message and an observation sequence of a target PPM signal; a demodulation module for demodulating the observation sequence using PPM to obtain a demodulated signal; a likelihood ratio calculation module for calculating the likelihood ratio of each symbol signal according to the intensity of a single symbol signal in the demodulated signal and the total symbol signal intensity detected by a legitimate signal receiver; a decoding module for decoding using a target decoding algorithm according to the likelihood ratio of each symbol signal and the target message to obtain a target polarization signal; a key element determination module for determining key elements corresponding to a transmitter according to the target polarization signal; and a key determination module for determining a key corresponding to the transmitter according to a plurality of key elements.
[0011] According to a fifth aspect, the present invention provides a computer storage medium having computer instructions stored thereon, and when the instructions are executed by a processor, the steps of a method for generating a multi-terminal covert key based on joint modulation of polar codes and PPM according to the first aspect or any implementation manner of the first aspect, or, the second aspect or any implementation manner of the second aspect are implemented.
[0012] This embodiment proposes a method for generating a multi-terminal covert key based on joint modulation of polar codes and PPM. In the scenario of generating a multi-terminal covert key, keys can be effectively generated at a low frame error rate. Through appropriate selection of the code length n and the number of sequences q, it is difficult for an illegal node Willie to distinguish whether key generation is in progress. Moreover, this method uses a discrete memoryless channel, which is a relatively general channel model and has greater applicability than solutions only for specific channels to a certain extent, greater potential for adapting to different channels, and stronger applicability. At the same time, as the number of communication rounds increases, the key elements change continuously, and the generated target message also changes accordingly, improving the confidentiality and anti-attack ability of the key.
[0013] Other advantages, objectives, and features of the present invention will be described in the subsequent specification, and to some extent, will be obvious to those skilled in the art, or those skilled in the art can be taught from the practice of the present invention. The objectives and other advantages of the present invention can be achieved and obtained through the following specification. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] To make the objectives, technical solutions, and beneficial effects of the present invention clearer, the following drawings are provided by the present invention for illustration:
[0015] Figure 1 A schematic diagram of a simple scenario to which a method for generating a multi-terminal covert key based on joint modulation of polar codes and PPM in the present invention is applied;
[0016] Figure 2 Schematic diagram of multi-node covert key generation under DMC channel conditions in the present invention;
[0017] Figure 3 Flowchart of an example method of a multi-terminal covert key generation method based on polar code and PPM joint modulation in the present invention, applied to the transmitter;
[0018] Figure 4 Schematic diagram of the encoding scheme of Alice in the present invention;
[0019] Figure 5 Pseudocode diagram of the Alice encoding algorithm in the present invention;
[0020] Figure 6 In the present invention, for and Definition schematic diagram of the set;
[0021] Figure 7 Schematic diagram of the determination process of conditional entropy in the present invention;
[0022] Figure 8 Schematic diagram of the specific process of obtaining the conditional entropy of all positions by the Monte Carlo method;
[0023] Figure 9 Flowchart of an example method of a multi-terminal covert key generation method based on polar code and PPM joint modulation in the present invention, applied to any legitimate receiver;
[0024] Figure 10 Pseudocode diagram of the decoding algorithm of the legitimate receiver Bob in the present invention;
[0025] Figure 11 Pseudocode diagram of the decoding algorithm of the legitimate receiver Charlie in the present invention;
[0026] Figure 12 In the present invention, when q = 4, the mapping scheme Decoding schematic diagram;
[0027] Figure 13 Flowchart of the multi-user key generation algorithm in the present invention;
[0028] Figure 14 Simulation diagram of the frame error rate of multi-terminal covert key generation in the present invention;
[0029] Figure 15 Simulation diagram of the generation rate of multi-terminal covert key generation in the present invention;
[0030] Figure 16 Simulation diagram of Willie's binary hypothesis test when q is fixed in the present invention;
[0031] Figure 17 In the present invention, with n fixed, it is a simulation diagram of Willie's binary hypothesis test;
[0032] Figure 18 In the present invention, it is a simulation diagram of the CUSUM test value of Willie;
[0033] Figure 19 In the present invention, it is a simulation diagram of the proportion of mutation points in the CUSUM test of Willie;
[0034] Figure 20 In the present invention, it is a simulation diagram of the error probability of each bit of the reproduced key by Willie;
[0035] Figure 21 In the present invention, it is a simulation diagram of the bit error rate of the reproduced key by Willie;
[0036] Figure 22 It is a principle block diagram of a specific example of an electronic device in an embodiment of the present invention. Detailed implementation manners
[0037] Next, the technical solutions of the present invention will be clearly and completely described in conjunction with the accompanying drawings. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without making creative efforts shall fall within the protection scope of the present invention.
[0038] In the description of the present invention, it should be noted that unless otherwise clearly defined and limited, the terms "installed", "connected", and "connected" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, and it can also be the communication inside two components. It can be a wireless connection or a wired connection. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific situations.
[0039] In addition, the technical features involved in different embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.
[0040] The following are the explanations of relevant terms:
[0041] Polar codes are a new type of channel coding proposed by E. Arikan in 2008. Due to the channel polarization phenomenon, Polar codes are the first constructive coding scheme that has been strictly mathematically proven to achieve the channel capacity. Specifically, when the number of combined channels tends to infinity, polarization occurs: some channels will tend to noiseless channels, and the other part will tend to fully noisy channels. The coding strategy of Polar codes exactly applies the characteristics of this phenomenon, using noiseless channels to transmit the useful information of users, and fully noisy channels to transmit agreed information or no information.
[0042] The principle of PPM is to generate pulse signals through coding and attach information to the PPM pulse signals. Specifically, for an n-bit binary information, after PPM coding, it is determined to be at a certain position in 2 n time slots. Polar codes ensure the reliability and security of the key generation process, and PPM modulation ensures the concealment of the key generation process.
[0043] Before elaborating on the specific embodiments of the present invention in detail, first, a schematic diagram of a simple scenario applied by the method of the embodiments of the present invention is given. As Figure 1 shown, there are k legitimate receivers and an illegal node. The legitimate receivers communicate with each other to generate keys. While hoping that the keys are difficult for the illegal node to obtain, the key generation process is difficult for the illegal node to accurately know.
[0044] Without loss of generality, consider a scenario with a sending node Alice, two receiving nodes Bob and Charlie, and an illegal node Willie. As Figure 2 shown, it is a schematic diagram of multi-node covert key generation under DMC channel conditions. In the figure, Alice generates keys by communicating with Bob through a Discrete Memoryless Channel (DMC) and generates keys with Charlie through while avoiding the communication being detected by Willie. Willie observes the signals through another DMC (X, W Z|X , Z), where the signal sent by Alice is X, and the observed signals of Bob, Charlie, and Willie are Y1, Y2, and Z respectively. To ensure that keys can be generated, assume H(X|Z) > H(X|Y1) and H(X|Z) > H(X|Y2)
[0045] Assume that the set of transmission symbols of Alice is a binary set, that is, X ∈ {0, 1}. Define the channel output distribution of Bob as The channel output distribution of Charlie is The channel output distribution of Willie is Qx = W Z|X=x For Alice's transmission sequence X n , the probability distribution of Bob's observation sequence For Charlie's observation sequence the probability distribution For Willie's observation sequence Z the probability distribution n Suppose the keys generated by Alice for Bob and Charlie are K1 and K2 respectively, and the key generated by Bob is The key generated by Charlie is The information M1 and M2 transmitted by Alice through the public channel for Bob and Charlie to reconstruct and generate keys, and the probability distribution guided by the generated covert key is Mainly consider the performance of covert key generation from the following three dimensions:
[0046] Reliability: The ability of Alice and Bob, and Alice and Charlie to generate consistent keys, which can be measured by the error probability, that is:
[0047]
[0048] Security: The randomness of the generated keys K1 and K2 and the ability of the illegal node Willie to recover the keys through the observation sequence Z n and the public messages M1 and M2, which is measured by relative entropy, that is:
[0049]
[0049]
[0050] Among them, represents the probability distribution caused by this method, represents that K AB is uniformly distributed over the value domain, represents that K AC is uniformly distributed over the value domain, and D(P||Q) represents relative entropy.
[0051] Concealment: The ability of the illegal node Willie to obtain whether the covert key generation is in operation, which can be regarded as the difference between the probability distribution P(Z n ) and , which can be measured by relative entropy, that is:
[0052]
[0053] Among them, represents the probability distribution of Willie's observation value when Alice sends all 0 sequences.
[0054] Therefore, a qualified covert key generation method should minimize the evaluation metrics of error probability, security, and covertness.
[0055] Based on the above application scenario, this embodiment provides a multi-terminal covert key generation method based on the combination of polar codes and PPM modulation, which is applied to the sender, i.e., the Alice side, as Figure 3 shown, including:
[0056] S101, generating a random sequence according to the Bernoulli distribution as the initial signal;
[0057] S102, performing PPM modulation on the initial signal to obtain a target PPM signal, and the target PPM signal communicates with multiple legitimate receivers through a discrete memoryless channel;
[0058] S103, using a polarization matrix to polarize the initial signal to obtain a polarized signal;
[0059] S104, selecting multiple groups of bit sets from the polarized signal to construct the key elements, the first information, and the second information of the legitimate receivers respectively;
[0060] S105, generating a target message according to the shared random information, the first information, and the second information of this round. The shared random information of this round is determined according to the key elements of the legitimate receivers in the previous round, and this target message is used for the legitimate receivers to reconstruct and generate the key according to the target message and the observation sequence of the target PPM signal.
[0061] Exemplarily, as Figure 4 shown, it is a schematic diagram of Alice's coding scheme. Alice generates q random sequences (X1, X2,... X q ) of length n according to the Bernoulli distribution B~(0, 0.5) as the initial signal, where X i =(X i,1 , X i,2 ,..., X i,n ). For each column, X 1:q,j =(X 1,j , X 2,j ,..., X q,j ) is used to represent. Actually, Alice generates a q×n two-dimensional matrix in a key generation communication process as follows:
[0062]
[0063] Since it is necessary to conceal the communication process of key generation, it is also necessary to perform PPM modulation on the message sent by the sender Alice. The following relationship is defined: for the binary vector Define To map X 1:q,j to a certain bit in [1, 2 q , for the binary vector X 1:q,j of the entire space, there is a unique position in [1, 2 q that corresponds one-to-one with X 1:q,j . Let m = 2 q . The entire PPM mapping space is the full permutation of m, that is
[0064] The sender Alice maps the sequence X 1:q,j to a sequence of length m . According to the mapping relationship, a certain position in it is 1 and the rest are 0. Alice sends the sequence to the channel and W Z|X . The sequence sent, that is, the target PPM signal is an m×n two-dimensional sparse matrix with a density of . Abstract the channel relationship between the legitimate receiver and the illegal receiver into a DMC channel, that is and The observed sequences of the target PPM signal by the legitimate receivers Bob, Charlie and the illegal receiver Willie are respectively and
[0065] Polar codes effectively ensure that Alice and Bob, Charlie can generate consistent keys and make it impossible for Willie to generate the same key. Alice polarizes X i according to U n = G i X i , where G n is the polarization matrix defined by E. Arikan and U i is the polarization signal. Select different bit sets in the polarization signal to construct the first information, the second information and the key elements of the legitimate receiver Bob or Charlie respectively.
[0066] Taking the legitimate receiver Bob as an example, multiple groups of bit sets are selected from the polarization signal to respectively construct the key elements, the first information, and the second information of the legitimate receiver, including: selecting the bit set belonging to the first target set from the polarization signal to obtain the component of the legitimate receiver's key. The first target set is the set obtained by removing the bits whose second conditional entropy of the legitimate receiver's observation sequence is greater than the second preset threshold from the bit set whose first conditional entropy of the illegal receiver's observation sequence is greater than the first preset threshold. The first conditional entropy and the second conditional entropy are determined with the assistance of conditional entropy; selecting the bit set belonging to the second target set from the polarization signal to obtain the first information. The second target set is the intersection of the bit set whose second conditional entropy of the legitimate receiver's observation sequence is greater than the second preset threshold and the bit set whose first conditional entropy of the illegal receiver's observation sequence is greater than the first preset threshold; selecting the bit set belonging to the third target set from the polarization signal to obtain the second information. The third target set is the set obtained by removing the bits whose first conditional entropy of the illegal receiver's observation sequence is greater than the first preset threshold from the bit set whose second conditional entropy of the legitimate receiver's observation sequence is greater than the second preset threshold.
[0067] Specifically, the key element (first target set) of Bob is K 1,i :
[0068]
[0069] The first information (second target set) is F 1,i :
[0070]
[0071] The second information (third target set) is the message that may be leaked
[0072]
[0073] Among them, the first preset threshold is δ n , and the second preset threshold is 1 - δ n ;
[0074] The second conditional entropy of the legitimate receiver's observation sequence is
[0075] The first conditional entropy of the illegal receiver's observation sequence is
[0076] n represents the code length of the initial signal, and U i,k is the k-th element of the vector U i The vector U i is the polarization signal sequence after the initial signal undergoes polarization transformation, and U i,1:k-1 represents the vector Ui The sub-vector composed of the first element to the (k-1)-th element, U i+1:q Indicates starting from the (i + 1)-th element of the vector U i To the q-th element, the subset formed, Indicates the observed sequence received by the first legitimate receiver (i.e., Bob), Represents the selected threshold, Indicates the observed sequence of the illegal receiver.
[0077] Represents the bits with a relatively large conditional entropy of Bob's observed sequence, that is, the unreliable bits, and the information of these bits needs to rely on Alice to transmit, Represents the bits with a conditional entropy of Willie's observed sequence close to 1. The sub-channels of these bits can be regarded as completely noisy channels. Willie's guess of the information of these bits will not be significantly better than random guessing.
[0078] In most cases, If directly transmitted Will leak some information to Willie. Therefore, in the generated key K 1,i Select a part of the key for confusion This part of the leaked information. To make this process more secure, the key for confusion with Is the key generated in the previous communication In this way, in the first round of communication, the legitimate receiver needs an initialized shared random information Similarly, when there are multiple legitimate receivers, each receiver needs an initialized shared random information.
[0079] Therefore, on the basis of determining the first information F 1,i And the second information Determine the target message according to the following formula:
[0080]
[0081] Among them, Represents the shared random information of this round, determined according to the key elements of the legitimate receiver in the previous round. Taking the key elements of the previous round as K 1,i For illustration, then the Of this round can be determined by the following formula:
[0082]
[0083] Among them, Is of length Of subset.
[0084] When the legitimate receivers also include Charlie:
[0085]
[0086] The above formula represents the bits with a relatively large conditional entropy of Charlie's observed sequence, that is, the unreliable bits, and the information of these bits needs to rely on Alice to transmit; represents the observed sequence received by the second legitimate receiver (i.e., Charlie), then Charlie can reconstruct the bits according to . Regarding the key K2 = (K 2,1 , K 2,2 ,..., K 2,q ) generated by Alice and Charlie, the information M2 = (M 2,1 , M 2,2 , …, M 2,q ) sent to Charlie.
[0087] When the legitimate receivers include Bob and Charlie, the pseudocode of Alice is as Figure 5 shown. In this embodiment, for the case where the legitimate receiver is Charlie, supplementary definitions are made:
[0088]
[0089] 2,i represents Charlie's key sequence, F 2,i represents the first information set used to generate Charlie's corresponding key, represents the second information set used to generate Charlie's corresponding key, represents the shared random information set used to generate Charlie's corresponding key, M 2,i represents the target message set used to generate Charlie's corresponding key, represents the previous round of shared random information used to generate Charlie's corresponding key, is of length and is a subset. The definitions of the above sets are as Figure 6 shown.
[0090] This embodiment proposes a multi-terminal covert key generation method based on the combination of polar codes and PPM modulation. In the scenario of multi-terminal covert key generation, it can effectively generate keys at a low frame error rate. By appropriately selecting the code length n and the number of sequences q, it is difficult for the illegal node Willie to distinguish whether key generation is in progress. Moreover, this method uses a discrete memoryless channel, which is a relatively general channel model and has a wider applicability to a certain extent than solutions only targeting specific channels, greater potential for adapting to different channels, and stronger applicability. At the same time, as the number of communication rounds increases, the key elements change continuously, and the generated target message also changes accordingly, improving the confidentiality and anti-attack ability of the key.
[0091] As an alternative embodiment, the process of determining the conditional entropy is as Figure 7 shown and includes:
[0092] S1. Determine the code length n and the number of sequences q of the initial signal, and initialize the number of simulation times to m and the number of error times to 0;
[0093] S2. Construct simulation channels with the legitimate receiver and the illegal receiver according to the channel parameters of the legitimate receiver and the illegal receiver;
[0094] S3. Input the target PPM signal into the simulation channels with the legitimate receiver and the illegal receiver respectively to obtain the simulated observation signals of the legitimate receiver and the illegal receiver;
[0095] S4. Initialize the number of decoding times to q;
[0096] S5. Determine whether the number of decoding times is greater than the first threshold. If the number of decoding times is greater than the first threshold, go to step S6; if the number of decoding times is less than or equal to the first threshold, go to step S9;
[0097] S6. Decode the simulated observation signals of the legitimate receiver and the illegal receiver using the PPM decoding algorithm to obtain the polarization signals of the legitimate receiver and the illegal receiver;
[0098] S7. Compare the polarization signals of the legitimate receiver and the illegal receiver with the polarization signal of the transmitter. If there is an error, increase the number of error times and correct the parameter at the error position to the correct value;
[0099] S8. Decrease the number of decoding times and go to step S5;
[0100] S9. Determine whether the number of simulation times has reached the value of the number of simulation times. If so, go to step S10; if not, go to step S2;
[0101] S10. Calculate the conditional entropy of each position according to the error counts of all positions of n×q.
[0102] Exemplarily, the commonly used Polar code polarization channel construction methods are mainly the Bhattacharyya iteration method, the density evolution method, and the Gaussian approximation method. The above methods can only construct individual Polar code encodings. Moreover, the Bhattacharyya iteration method is only applicable to the BEC channel and has poor estimation for other channels; the density evolution method has too high a computational complexity and is difficult to implement; the Gaussian approximation method is only applicable to the Gaussian channel. The present invention adopts the joint modulation of Polar code and PPM. The theoretical derivation of the conditional entropy is very difficult. Therefore, the Monte Carlo method is used to calculate the conditional entropy of all positions of q×n. After obtaining the conditional entropy of all positions of q×n by the Monte Carlo method, the information set and can be constructed, thus completing the entire secret key generation process.
[0103] Taking U Y and U comparison as an example, the error count of each sub-channel of U is Then the error frequency of this sub-channel is where m is the number of simulations. Replace the error probability of this sub-channel with the error frequency to estimate the conditional entropy of this sub-channel:
[0104]
[0105] This embodiment gives a specific process diagram of obtaining the conditional entropy of all positions of q×n by the Monte Carlo method. As Figure 7 shown, in Figure 8 the first threshold can be 0, and the way to reduce the decoding times can be to reduce them one by one.
[0106] As an alternative implementation, time-division multiplexing is used to complete information interaction with multiple legitimate receivers. This embodiment relies on time-division multiplexing, and this method can be well transplanted from the one-to-many broadcast channel (BC) model to the many-to-one multiple access channel (MAC) model.
[0107] The embodiment of the present invention provides a multi-terminal covert key generation method based on the joint modulation of polar code and PPM. As Figure 9 shown, it is applied to any legitimate receiver and includes:
[0108] S201. Obtain the target message and the observation sequence of the target PPM signal;
[0109] S202. Demodulate the observation sequence using PPM to obtain the demodulated signal;
[0110] S203. Calculate the likelihood ratio of each symbol signal according to the strength of a single symbol signal in the mediation signal and the total symbol signal strength detected by the legitimate signal receiver.
[0111] S204. Decode using the target decoding algorithm according to the likelihood ratio of each symbol signal and the target message to obtain the target polarization signal.
[0112] S205. Determine the key element corresponding to the sender according to the target polarization signal.
[0113] S206. Determine the key corresponding to the sender according to multiple key elements.
[0114] Exemplarily, as Figure 10 and Figure 11 shown, they are respectively the pseudo-code diagrams of the decoding algorithms with legitimate receivers Bob and Charlie. Taking Bob as the legitimate receiver as an example (i.e., Figure 10 ) for illustration ( Figure 11 not elaborated further):
[0115] First, receive the code length n, the PPM (Pulse Position Modulation) mapping length m = 2 q , the number of communication rounds l1, the initial random seed shared with Alice the subset of with size shared with Alice the information sent by Alice observations
[0116] Set the number of loop iterations according to the number of communication rounds l1 and traverse each round of communication. Perform the following operations in each round of communication: For each round j, when i ∈ [q, 1], according to the decoding index U i+l:q and the PPM mapping rule, select whose size is n × m. Specifically, because PPM modulation is adopted, Bob, Charlie, and Willie need to rely on the decoding data of the i + 1:q layer when decoding the i-th layer (i ∈ [1, q]). Taking the case of q = 4 and the mapping scheme as an example (d(·) is the binary-to-decimal operation), the specific form is as Figure 12 shown.
[0117] When k ∈ [1, n], calculate the strength of a single symbol signal in the mediation signal and the total symbol signal strength detected by the legitimate signal receiver according to the following formula:
[0118]
[0119] where It represents the sum of the received signal strengths at the position with PPM modulation value a in Bob's jth round with sequence number k; It represents the sum of the received signal strengths of all positions with sequence number k in Bob's jth round.
[0120] Then, the likelihood ratio of each symbol signal is calculated according to the following likelihood ratio formula:
[0121]
[0122] in, Represents the log-likelihood ratio of the jth round with sequence number k. If it is greater than 0, it means that the probability of a value being 1 is greater, otherwise the probability of a value being 0 is greater.
[0123] Bob uses PPM demodulation to calculate the likelihood ratio The subscripts represent the sequence numbers 1 to q, the total code length is n, and all likelihood ratios from 1 to n are calculated according to and Decoding using SC decoding algorithm According to the decoding results and PPM mapping rules, the observation values of the q-1 layer are filtered and calculated. at this time and Message Decoding By analogy, Bob decodes the target polarization signal And finally get the key and for the next time to confuse information
[0124]
[0125] In Bob's i-th round of communication, it is similar to the first round of communication, except that the obfuscation key used is no longer the initial random shared information. But it is generated in round i-1 Charlie's i-th round of communication is similarly
[0126] In view of the above, two examples of legal receiving ends are given for description, such as Figure 13 As shown, the initial communication rounds are l1 and l2, and information is shared randomly. Randomly generate a q×n transmission sequence X, and generate K according to the method executed by the sender above, And M, determine whether to send it to Bob, if yes, then X is mapped to Obtained through the channel Bob uses and M, reconstructed using the PPM-SC decoding algorithm Extract the key. If no, enterFigure 11 For the described Charlie part, the specific steps can be referred to the flowchart and will not be elaborated here. When the communication round reaches l1 + l2, a secret key is generated between Alice and Bob. A secret key is generated between Alice and Charlie. If it has not reached, then Alice regenerates K, and M, and enters the next round of communication.
[0127] Finally, an embodiment of the present invention provides a multi - terminal covert key generation algorithm based on the joint modulation of polar code and PPM. The specific process is described as follows:
[0128] 1. Abstract the channel relationship between legitimate nodes and illegal nodes into a DMC channel, that is and Determine the PPM mapping relationship PPM1 between Alice and Bob, the PPM mapping relationship PPM2 between Alice and Charlie, the communication round number l1 between Alice and Bob, the communication round number l2 between Alice and Bob, and the initial shared random information between Alice and Bob and the initial shared random information with Charlie
[0129] 2. In the first round of communication regarding Bob, Alice first generates a q×n random variable X=(X1, X2,..., X q ) according to the Bernoulli distribution B~(0, 0.5), where X i =(X i,1 , X i,2 ,..., X i,n ). Alice performs Polar polarization transformation U=(U1, U2,..., U q ), where U i =G n X i , and G n is the polarization matrix. Alice generates Bob's secret key according to Generate Generate a message Generate a possibly leaked message Encrypt and generate using the initial random shared random information To enable Bob to reconstruct the variable Leave For generating the next message Alice transforms X into through PPM modulation, where m = 2q 。
[0130] Bob's observation value is Bob uses PPM demodulation to calculate the likelihood ratio According to and Decode using the SC decoding algorithm According to the decoding result and the PPM mapping rule, screen and calculate the observation value of the q-1 layer At this time and the message Decode And so on, Bob decodes And finally obtains the key and the used for the next confusion information and
[0131] 3. During Bob's i-th round of communication, similar to the first round of communication, the difference is that the confusion key used is no longer the initial randomly shared information but the one generated in the (i-1)-th round Charlie's i-th round of communication similarly adopts
[0132] 4. After l1 + l2 times of communication, a key is generated between Alice and Bob A key is generated between Alice and Charlie
[0133] 5. During the entire communication process, Willie adopts to perform a binary hypothesis test to determine whether a key is being generated currently. l represents the number of rounds of information interaction between Alice and Bob or Charlie during each key generation; Willie tries to restore based on its own observation value and the message attempt to restore In addition, Willie uses CUSUM to perform a sequential test to detect whether there is a mutation point to determine whether a key generation process has occurred.
[0134] The embodiment of the present invention uses a time-division multiplexing method to complete the key generation between Alice and different legitimate nodes. Benefiting from the fact that the spatial complexity of PPM modulation itself can reach When Alice generates keys with legitimate nodes Bob and Charlie, it can be assumed that different PPM mappings are used between Alice and Bob, and between Alice and Charlie, and Bob and Charlie do not know each other's PPM mapping relationships, so as to ensure that the generated key pairs are opaque to each other; the illegal node Willie knows Alice's encoding algorithm, Bob and Charlie's decoding algorithms, and their PPM mapping relationships, that is, Willie knows all the algorithm information in the generation process. Therefore, in the present invention, Willie uses the LRT (Likehood Ratio Test, LRT) test to determine whether key generation is in progress, which is equivalent to Willie performing a binary hypothesis test: That is, Willie detects that key generation is in progress; Willie believes that the sequence sent by Alice is all 0s, that is, key generation is not in progress. What Alice sends is an m×n sparse matrix with a density of In the sparse matrix, there is a 1 at a randomly located position in each column, and the rest of the positions are 0. Therefore, the expectation can be used to define
[0135]
[0136] where Q0 is the probability distribution of Willie's observed values when Alice sends symbol 0; Q1 is the probability distribution of Willie's observed values when Alice sends 1, and t means that the t-th position of Alice is 1.
[0137] Define the log-likelihood ratio as follows:
[0138]
[0139] Willie selects an appropriate L in order to accurately distinguish whether key generation is in progress.
[0140] In this embodiment, Willie's detection method includes:
[0141] (1) Binary hypothesis test
[0142] The purpose of the binary hypothesis test is to ensure that the distinction between the process of key generation and the process without key generation is extremely small. For a single process, it is difficult for Willie to distinguish whether key generation has been performed. For Willie, there are two hypotheses in the binary hypothesis test:
[0143]
[0144] Let \(H_0\) denote that the signal received by Willie is not sent by Alice for key generation, and \(H_1\) denote that the signal received by Willie is sent by Alice for key generation. Under binary hypothesis testing, there are two error probabilities: when \(H_0\) is true, rejecting \(H_0\) is called a false alarm error, and the false alarm probability is denoted by \(\alpha\); when \(H_0\) is false, accepting \(H_0\) is called a missed detection error, and the missed detection probability is denoted by \(\beta\).
[0145] In this paper, Willie uses the LRT test for judgment. According to the foregoing, For each value of \(\alpha\), Willie simulates the value of \(1 - \beta\) and plots the ROC curve.
[0146] (2) CUSUM test
[0147] The CUSUM (Cumulative Sum) test is a statistical method used to detect change points in a data sequence. It monitors the deviation degree of the data by calculating the cumulative sum of the data sequence. The CUSUM process uses past observations, and even a small change can achieve a significant detection effect. Specifically, CUSUM selects the exceedance relative to its past minimum value to determine whether a deviation has occurred. Suppose there are \(n\) data, and \(W\) n represents its exceedance relative to the past minimum value. According to the recurrence formula:
[0148] where \((x)\) + = max{\(x\), 0}, and \(W_0 = 0\). In the algorithm implementation of the present invention,
[0149] The simulation results for the present invention are as follows:
[0150] (1) Using the BSC channel, where the channel between Alice and Bob has a flip probability \(P(Y_1 = 0|X = 1)=P(Y_1 = 1|X = 0)=0.1\); the channel between Alice and Charlie has a flip probability \(P(Y_2 = 0|X = 1)=P(Y_2 = 1|X = 0)=0.1\); the channel between Alice and Willie has a flip probability \(P(Z = 0|X = 1)=P(Z = 1|X = 0)=0.4\), the number of sequences generated per communication \(q = 10\), and the code length \(n = 2\) 6 ,2 7 ,2 8 ,2 9 ,2 10 。As Figure 14 shown, as the code length increases, the frame error rate is smaller and shows an exponential decay.
[0151] (2) When the above conditions are maintained, the key rate generated by the proposed algorithm is simulated. As Figure 15 shown, the length of the code has little effect on the number of key bits that can be generated per channel use.
[0152] (3) When the flipping probability P(Z = 0|X = 1) = P(Z = 1|X = 0) = 0.4 of the channel between Alice and Willie, with the fixed code length n = 2 6 , and the number of sequences q = 6, 8, 10, 12, 14 generated per communication, Willie performs the LRT test based on the information he observes. The ROC curve is obtained, as shown; with the fixed number of sequences q = 10 generated per communication and the code length n = 2 Figure 16 shown; with the fixed number of sequences q = 10 generated per communication and the code length n = 2 6 , 2 7 , 2 8 , 2 9 , 2 10 , Willie obtains another ROC curve, as Figure 17 shown. In multi-terminal covert key generation, by selecting appropriate values of the number of sequences q and the code length n, it can be ensured that Willie's binary hypothesis test is not significantly better than a random test.
[0153] CUSUM test: With the code length n = 2 6 , and the number of sequences q = 15 generated per communication, Willie performs the CUSUM test based on his own sequence. The CUSUM test values are as Figure 18 shown, where the blue line represents the CUSUM test values when no key generation is performed, and the red line represents the case where key generation accounts for 1 / 100 of the process, that is, in 1e5 simulations, 1e3 positions are randomly selected for key generation.
[0154] Taking the threshold b = [2, 6] of the CUSUM test and performing peak detection on the CUSUM test, the simulation diagram is as Figure 19 shown. At any detection threshold, the proportion of mutation points without key generation is higher than the proportion of mutation points where key generation accounts for 1 / 100, indicating that at any selected test threshold, Willie cannot detect whether key generation has occurred when a mutation occurs.
[0155] (4) With q = 10 and n = 2 10 , when the flipping probability P(Z = 0|X = 1) = P(Z = 1|X = 0) = 0.4 of the channel between Alice and Willie, and Willie knows the decoding algorithms of Bob and Charlie, 10^6 simulations are performed. Willie's frame error rate is 100%, and the number of successful key reproductions is 0. The error probability of each key bit is asFigure 20 As shown, the error probability of each bit is close to 0.5, that is, Willie is close to random guessing.
[0156] Maintaining the above conditions, the bit error rate of Willie is simulated 10^6 times, as Figure 21 shown. The range of the bit error rate of Willie to reproduce the key is 0.2719 - 0.7368, the average value of the bit error rate is 0.5, and the variance is 0.0022. Generally speaking, the bit error rate of Willie to reproduce the key is close to random guessing, and the fluctuation of the bit error rate is relatively random. Willie cannot accurately know what the bit error rate of this key is.
[0157] (5) q = 10, n = 2 10 , according to the GM / T - 0005 - 2021 standard, the randomness and distribution uniformity of the generated key are detected, as shown in Table 1 and Table 2 respectively. According to the national standard, the randomness and distribution uniformity of the generated key meet the requirements.
[0158] Table 1 Key Randomness Detection
[0159]
[0160]
[0161] Table 2 Key Distribution Uniformity Detection
[0162]
[0163]
[0164] This embodiment provides a multi - terminal covert key generation device based on the joint modulation of polar code and PPM, including:
[0165] An initial signal generation module, configured to generate a random sequence according to the Bernoulli distribution as the initial signal;
[0166] A PPM signal modulation module, configured to perform PPM modulation on the initial signal to obtain a target PPM signal, and the target PPM signal communicates with multiple legitimate receivers through a discrete memoryless channel;
[0167] A polarization module, configured to perform polarization processing on the initial signal by using a polarization matrix to obtain a polarization signal;
[0168] A construction module, configured to select multiple groups of bit - bit sets in the polarization signal to respectively construct key elements, first information, and second information of legitimate receivers;
[0169] A target message generation module, which is configured to generate a target message according to the shared random information, the first information, and the second information in the current round. The shared random information in the current round is determined according to the key elements of the legitimate receiver in the previous round. The target message is used by the legitimate receiver to reconstruct and generate a key according to the target message and the observation sequence of the target PPM signal.
[0170] This embodiment provides a multi-terminal covert key generation device based on the joint modulation of polar codes and PPM, including:
[0171] An observation module, which is configured to obtain the target message and the observation sequence of the target PPM signal;
[0172] A demodulation module, which is configured to demodulate the observation sequence using PPM to obtain a demodulated signal;
[0173] A likelihood ratio calculation module, which is configured to calculate the likelihood ratio of each symbol signal according to the single symbol signal strength in the demodulated signal and the total symbol signal strength detected by the legitimate signal receiver;
[0174] A decoding module, which is configured to perform decoding using a target decoding algorithm according to the likelihood ratio of each symbol signal and the target message to obtain a target polarization signal;
[0175] A key element determination module, which is configured to determine the key elements corresponding to the sender according to the target polarization signal;
[0176] A key determination module, which is configured to determine the key corresponding to the sender according to multiple key elements.
[0177] This application embodiment also provides an electronic device, as Figure 22 shown, including a processor 501 and a memory 502, where the processor 501 and the memory 502 can be connected through a bus or other means.
[0178] The processor 501 can be a central processing unit (CPU). The processor 501 can also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. chips, or combinations of the above types of chips.
[0179] The memory 502, as a non-transitory computer-readable storage medium, can be used to store non-transitory software programs, non-transitory computer-executable programs, and modules, such as the program instructions / modules corresponding to the multi-terminal covert key generation method based on the combination of polar codes and PPM modulation in the embodiments of the present invention. The processor executes various functional applications and data processing of the processor by running the non-transitory software programs, instructions, and modules stored in the memory.
[0180] The memory 502 may include a program storage area and a data storage area. Among them, the program storage area can store an operating system and application programs required for at least one function; the data storage area can store data created by the processor, etc. In addition, the memory may include high-speed random access memory, and may also include non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state storage devices. In some embodiments, the memory 502 may optionally include a memory remotely set relative to the processor, and these remote memories can be connected to the processor through a network. Examples of the above network include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0181] The one or more modules are stored in the memory 502 and, when executed by the processor 501, execute the multi-terminal covert key generation method based on the combination of polar codes and PPM modulation in the embodiments shown as Figure 1 shown.
[0182] The specific details of the above electronic device can be understood by referring to the corresponding relevant descriptions and effects in the embodiments shown as Figure 4 、 9 shown, and will not be elaborated here.
[0183] This embodiment also provides a computer storage medium. The computer storage medium stores computer-executable instructions, and these computer-executable instructions can execute the multi-terminal covert key generation method based on the combination of polar codes and PPM modulation in any of the above method embodiments. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only memory (ROM), a random access memory (RAM), a flash memory (Flash Memory), a hard disk (Hard Disk Drive, abbreviation: HDD), or a solid-state drive (SSD), etc.
Claims
1. A multi-terminal covert key generation method based on the joint modulation of polar codes and PPM, characterized in that, Applied to the sending end, including: Generating a random sequence according to the Bernoulli distribution as the initial signal; Performing PPM modulation on the initial signal to obtain a target PPM signal, and the target PPM signal communicates with multiple legitimate receivers through a discrete memoryless channel; Performing polarization processing on the initial signal by using a polarization matrix to obtain a polarized signal; Selecting multiple groups of bit sets from the polarized signal to respectively construct key elements, first information, and second information of the legitimate receivers; Generating a target message according to the shared random information, first information, and second information of this round. The shared random information of this round is determined according to the key elements of the legitimate receivers in the previous round. The target message is used for the legitimate receivers to reconstruct and generate a key according to the target message and the observation sequence of the target PPM signal.
2. The multi-terminal covert key generation method based on the joint modulation of polar code and PPM according to claim 1, characterized in that Selecting multiple groups of bit sets from the polarized signal to respectively construct key elements, first information, and second information of the legitimate receivers, including: Selecting the bit set belonging to the first target set from the polarized signal to obtain the component of the legitimate receiver's key. The first target set is the set obtained by removing the bits whose second conditional entropy of the legitimate receiver's observation sequence is greater than the second preset threshold from the set of bits whose first conditional entropy of the eavesdropper's observation sequence is greater than the first preset threshold; Selecting the bit set belonging to the second target set from the polarized signal to obtain the first information. The second target set is the intersection of the set of bits whose second conditional entropy of the legitimate receiver's observation sequence is greater than the second preset threshold and the set of bits whose first conditional entropy of the eavesdropper's observation sequence is greater than the first preset threshold; Selecting the bit set belonging to the third target set from the polarized signal to obtain the second information. The third target set is the set obtained by removing the bits whose first conditional entropy of the eavesdropper's observation sequence is greater than the first preset threshold from the set of bits whose second conditional entropy of the legitimate receiver's observation sequence is greater than the second preset threshold.
3. The multi-terminal covert key generation method based on polar code and PPM joint modulation according to claim 2, characterized in that: The first conditional entropy of the illegal receiver's observed sequence is: The second conditional entropy of the legal receiver's observation sequence is as follows: The first preset threshold is δ n , and the second preset threshold is 1 - δ n ; The component of the secret key is K 1,i : The first piece of information is F 1,i : The second information is where n represents the code length of the initial signal, U i,k is the k-th element of vector U i , and vector U i is the polarization signal sequence obtained by polarizing the initial signal, U i,1:k-1 represents the sub-vector formed by the elements of vector U i from the 1st element to the (k - 1)-th element, and U i+1:q represents the subset formed by starting from the (i + 1)-th element of vector U i to the q-th element, represents the observation sequence received by the first legitimate receiver, represents the observation sequence of the illegitimate receiver, represents the selection threshold, 4. A multi-terminal covert key generation method based on the joint modulation of polar codes and PPM according to claim 2, characterized in that, The determination process of conditional entropy includes: S1, determining the code length n and the number of sequences q of the initial signal, initializing the number of simulation times to m and the number of error times to 0; S2, constructing simulation channels with the legitimate receivers and the eavesdroppers according to the channel parameters of the legitimate receivers and the eavesdroppers; S3, inputting the target PPM signal into the simulation channels between the legitimate receivers and the simulation channels between the eavesdroppers to obtain the simulated observation signals of the legitimate receivers and the simulated observation signals of the eavesdroppers; S4, initializing the number of decoding times to q; S5, judging whether the number of decoding times is greater than the first threshold. When the number of decoding times is greater than the first threshold, go to step S6; when the number of decoding times is less than or equal to the first threshold, go to step S9; S6, decoding the simulated observation signals of the legitimate receivers and the simulated observation signals of the eavesdroppers by using the PPM decoding algorithm to obtain the polarized signals of the legitimate receivers and the polarized signals of the eavesdroppers; S7. Compare the polarization signals of the legitimate receivers and the illegal receivers with the polarization signal of the transmitter. If there is an error, increase the error count and correct the parameter at the error position to the correct value. S8. Reduce the decoding count and go to step S5. S9. Determine whether the number of simulation times has reached the simulation times value. If so, go to step S10; if not, go to step S2. S10. Calculate the conditional entropy of each position according to the error counts at all positions of n×q.
5. A multi-terminal covert key generation method based on the joint modulation of polar codes and PPM according to claim 1, characterized in that The shared random information in this round is determined according to the key elements of the legitimate receivers in the previous round, including: Among them, represents the i-th shared random information of the first legitimate receiver, K 1,i represents the i-th key element of the first legitimate receiver, represents the length of of subset of n represents the code length of the initial signal, U i,k is the k-th element of vector U i Vector U i is the polarization signal sequence after polarization transformation of the initial signal, U i,1:k-1 represents vector U i from the 1st element to the (k - 1)-th element subvector, U i+1:q represents from vector U i starting from the (i + 1)-th element to the q-th element, the subset formed, represents the observation sequence received by the first legitimate receiver, represents the selection threshold, represents the observation sequence of the illegal receiver.
6. A multi-terminal covert key generation method based on the joint modulation of polar codes and PPM, according to any one of claims 1-5, characterized in that, Use time-division multiplexing to complete information interaction with multiple legitimate receivers.
7. A multi-terminal covert key generation method based on the joint modulation of polar codes and PPM, characterized in that, Applied to any legitimate receiver, including: Obtain the target message and the observation sequence of the target PPM signal; Perform PPM demodulation on the observation sequence to obtain the demodulated signal; Calculate the likelihood ratio of each symbol signal according to the intensity of a single symbol signal in the demodulated signal and the total symbol signal intensity detected by the legitimate signal receiver; Perform decoding using the target decoding algorithm according to the likelihood ratio of each symbol signal and the target message to obtain the target polarization signal; Determine the key elements corresponding to the transmitter according to the target polarization signal; Determine the key corresponding to the transmitter according to multiple key elements.
8. A multi-terminal covert key generation device based on the joint modulation of polar codes and PPM, characterized in that, Including: An initial signal generation module for generating a random sequence according to the Bernoulli distribution as the initial signal; A PPM signal modulation module for performing PPM modulation on the initial signal to obtain the target PPM signal, and the target PPM signal communicates with multiple legitimate receivers through a discrete memoryless channel; A polarization module for polarizing the initial signal using a polarization matrix to obtain a polarization signal; A construction module for selecting multiple groups of bit position sets in the polarization signal and constructing the key elements, the first information, and the second information of the legitimate receivers respectively; A target message generation module for generating a target message according to the shared random information, the first information, and the second information in this round. The shared random information in this round is determined according to the key elements of the legitimate receivers in the previous round, and this target message is used by the legitimate receiver to reconstruct and generate a key according to the target message and the observation sequence of the target PPM signal.
9. A multi-terminal covert key generation device based on the joint modulation of polar codes and PPM, characterized in that, Including: An observation module for obtaining the target message and the observation sequence of the target PPM signal; A demodulation module for performing PPM demodulation on the observation sequence to obtain the demodulated signal; A likelihood ratio calculation module for calculating the likelihood ratio of each symbol signal according to the intensity of a single symbol signal in the demodulated signal and the total symbol signal intensity detected by the legitimate signal receiver; A decoding module for performing decoding using the target decoding algorithm according to the likelihood ratio of each symbol signal and the target message to obtain the target polarization signal; A key element determination module for determining the key elements corresponding to the transmitter according to the target polarization signal; A key determination module for determining the key corresponding to the transmitter according to multiple key elements.
10. A computer storage medium having computer instructions stored thereon, characterized in that, When the instruction is executed by the processor, it implements the steps of a multi-terminal covert key generation method based on the joint modulation of polar code and PPM as described in any one of claims 1-7.