Key generation method, device and system, electronic equipment and storage medium
By allocating time slices and processing channel characteristics among different terminal devices and base stations in a wireless local area network, parallel quantum keys are generated, solving the problem of low efficiency caused by multiple users monopolizing channel bandwidth and realizing resource sharing and efficient key generation.
Patent Information
- Application Number
- CN202511250487.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-03
- Publication Date
- 2026-01-13
AI Technical Summary
In multi-user quantum key distribution scenarios under wireless LAN, each user exclusively occupies the communication channel bandwidth, resulting in low key generation efficiency and difficulty in adapting to the concurrent needs of multiple users.
By having different terminal devices occupy different time slices to communicate with the base station, channel state information is detected, features are extracted, quantization is performed, and equalization is carried out to generate the original bit sequence. This sequence is then corrected and encrypted, enabling multiple terminal devices to share the channel to support parallel key generation.
It eliminates the need for each terminal device to exclusively occupy communication channel bandwidth, reducing resource waste, improving key generation efficiency, meeting the concurrent needs of multiple users, and adapting to quantum key wireless distribution under wireless LAN.
Smart Images

Figure CN121334653A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of wireless communication, and particularly relates to a key generation method and device, system, electronic equipment and storage medium. BACKGROUND
[0002] In the process of the integration of quantum technology and communication technology, quantum key distribution (QKD) technology provides important support for information security transmission, especially in the transmission scene of multi-user and large-scale quantum keys.
[0003] In the multi-user quantum key wireless distribution scene under the wireless local area network, each user needs to exclusively occupy the entire communication channel bandwidth to generate a wireless key, and the multi-users need to generate wireless keys in turn according to time polling, thereby leading to low efficiency of multi-user key generation, making it difficult for the generation of wireless keys to adapt to the concurrent demand of multi-users. Therefore, how to improve the generation efficiency of multi-user wireless keys is a problem to be solved at present. SUMMARY
[0004] The present disclosure provides a key generation method and device, system, electronic equipment and storage medium to solve the problems in the related art, without each terminal device exclusively occupying the communication channel bandwidth, at least one terminal device sharing the channel to reduce resource waste, supporting parallel generation to improve efficiency, and thereby adapting to the concurrent demand of at least one terminal device, and meeting the actual scene of quantum key wireless distribution of at least one terminal device under the wireless local area network.
[0005] According to a first aspect embodiment of the present disclosure, a key generation method is provided, the method is applied to a base station, different terminal devices occupy different time slices to communicate with the base station, and the method comprises the following steps:
[0006] In response to a connection request initiated by a terminal device, a communication connection with the terminal device is established, and a data frame is sent to the terminal device;
[0007] An acknowledgement frame sent by the terminal device is received, and channel sounding is performed based on a preset number of subcarriers in the preamble of the acknowledgement frame to obtain channel state information;
[0008] Channel feature extraction is performed on the channel state information to obtain channel features corresponding to the terminal device, and quantization conversion and equalization processing are performed on the channel features to generate an original bit sequence;
[0009] The original bit sequence is corrected, and the corrected bit sequence is encrypted to determine a first target key.
[0010] In some embodiments, the step of establishing a communication connection with the terminal device in response to a connection request initiated by the terminal device includes:
[0011] Based on the connection request, determine whether the current time slice should be allocated to the terminal device;
[0012] If it is determined that a channel will be allocated to the terminal device, a channel reservation with the terminal device will be initiated to establish a communication connection.
[0013] In some embodiments, determining whether the current time slice is allocated to the terminal device based on the connection request includes:
[0014] Based on the terminal device information, the collected IP address, and the preset time slot allocation rules, determine whether the terminal device identifier in the connection request is consistent with the terminal device identifier corresponding to the current time slot.
[0015] If the terminal device identifier matches the terminal device identifier corresponding to the current time slice, then the current time slice is allocated to the terminal device, and an IP address is assigned to the terminal device.
[0016] In some embodiments, initiating a handshake with the terminal device to establish a communication connection includes:
[0017] If the channel is detected to be idle, after waiting for the distributed inter-frame interval, channel reservation information is sent.
[0018] In response to receiving the reservation permission information sent by the terminal device;
[0019] Based on the channel reservation information and the reservation permission information, a channel reservation with the terminal device is completed to establish a communication connection.
[0020] In some embodiments, receiving the confirmation frame sent by the terminal device includes:
[0021] The data frame is sent to the terminal device, and a short inter-frame interval is waited for; wherein the short inter-frame interval is less than the distributed inter-frame interval;
[0022] After a short inter-frame interval, the confirmation frame sent by the terminal device is received.
[0023] In some embodiments, the channel state information is uplink channel state information;
[0024] The channel probing is performed based on a preset number of subcarriers in the preamble of the acknowledgment frame to obtain channel state information, including:
[0025] Obtain a preset number of subcarriers from the preamble of the confirmation frame;
[0026] Based on a preset number of subcarriers, channel estimation is performed on the preset number of subcarriers to obtain the uplink channel state information.
[0027] In some embodiments, the step of extracting channel features from the channel state information to obtain channel features corresponding to the terminal device includes:
[0028] The uplink channel state information is subjected to amplitude and phase processing to obtain the channel characteristics corresponding to the terminal device.
[0029] In some embodiments, the step of performing amplitude and phase processing on the uplink channel state information to obtain channel features corresponding to the terminal device includes:
[0030] The uplink channel state information is processed by absolute value, and the result of the absolute value processing is normalized to obtain the uplink channel amplitude characteristics.
[0031] Calculate the phase information of the uplink channel state information, and perform smoothing and centering processing on the phase information to obtain the uplink channel phase characteristics;
[0032] Based on the uplink channel amplitude characteristics and the uplink channel phase characteristics, the channel characteristics corresponding to the terminal device are determined.
[0033] In some embodiments, the quantization and equalization processing of the channel features to generate the original bit sequence includes:
[0034] The channel features are quantized to obtain at least one quantization mode;
[0035] Calculate the number of occurrences of the at least one quantization pattern;
[0036] If the occurrence frequency exceeds a preset threshold, the at least one quantization mode is subjected to equalization processing to obtain the original bit sequence.
[0037] In some embodiments, the step of correcting the original bit sequence and encrypting the corrected bit sequence to determine the first target key includes:
[0038] The original bit sequence is subjected to information coordination processing to obtain the corrected bit sequence;
[0039] The privacy amplification algorithm is invoked to encrypt the corrected bit sequence, thereby obtaining the first target key.
[0040] In some embodiments, after encrypting the corrected bit sequence and determining the first target key, the method further includes:
[0041] Based on the device information of the terminal device, the first target key is stored respectively.
[0042] According to a second aspect of this disclosure, a key generation method is provided, the method being applied to terminal devices, wherein different terminal devices occupy different time slices to establish communication connections with a base station, including:
[0043] Send a connection request to the base station to establish a communication connection with the base station;
[0044] Receive data frames sent by the base station and send acknowledgment frames to the base station;
[0045] Channel detection is performed based on a preset number of subcarriers in the preamble of the data frame to obtain channel state information;
[0046] Channel features are extracted from the channel state information to obtain the channel features corresponding to the base station, and the channel features are quantized and equalized to generate the original bit sequence.
[0047] The original bit sequence is corrected, and the corrected bit sequence is encrypted to determine the second target key.
[0048] In some embodiments, sending a connection request to a base station to establish a communication connection with the base station includes:
[0049] Based on the connection request, determine whether to accept the current time slice allocated by the base station;
[0050] If it is determined that the current time slice allocated by the base station has been received, then a channel reservation with the base station is received to establish a communication connection.
[0051] In some embodiments, determining whether to receive the current time slice allocated by the base station based on the connection request includes:
[0052] Determine whether the identifier in the connection request is consistent with the identifier in the current time slice;
[0053] If the identifier in the connection request matches the identifier in the current time slice, then the current time slice is obtained, and the IP address sent by the base station is received.
[0054] In some embodiments, the handshake with the base station to establish a communication connection includes:
[0055] In response to waiting for the distributed inter-frame interval, the system receives channel reservation information sent by the base station.
[0056] Send reservation permission information to the base station;
[0057] Based on the channel reservation information and the reservation permission information, a channel reservation with the base station is completed to establish a communication connection.
[0058] In some embodiments, receiving the data frame sent by the base station and sending an acknowledgment frame to the base station includes:
[0059] Receive the data frame sent by the base station and wait for the short inter-frame interval; wherein the short inter-frame interval is less than the distributed inter-frame interval;
[0060] After a short inter-frame interval, the acknowledgment frame is sent to the base station.
[0061] In some embodiments, the channel state information is downlink channel state information;
[0062] The channel probing is performed based on a preset number of subcarriers in the preamble of the data frame to obtain channel state information, including:
[0063] Obtain a preset number of subcarriers from the preamble of the data frame;
[0064] Based on a preset number of subcarriers, channel estimation is performed on the preset number of subcarriers to obtain the downlink channel state information.
[0065] In some embodiments, the step of extracting channel features from the channel state information to obtain channel features corresponding to the base station includes:
[0066] The downlink channel state information is subjected to amplitude and phase processing to obtain the channel characteristics corresponding to the base station.
[0067] In some embodiments, the step of performing amplitude and phase processing on the downlink channel state information to obtain channel features corresponding to the base station includes:
[0068] The downlink channel state information is processed by absolute value, and the result of the absolute value processing is normalized to obtain the downlink channel amplitude characteristics.
[0069] Calculate the phase information of the downlink channel state information, and perform smoothing and centering processing on the phase information to obtain the downlink channel phase characteristics;
[0070] Based on the downlink channel amplitude characteristics and the downlink channel phase characteristics, the channel characteristics corresponding to the base station are determined.
[0071] In some embodiments, the quantization and equalization processing of the channel features to generate the original bit sequence includes:
[0072] The channel features are quantized to obtain at least one quantization mode;
[0073] Calculate the number of occurrences of the at least one quantization pattern;
[0074] If the occurrence frequency exceeds a preset threshold, the at least one quantization mode is subjected to equalization processing to obtain the original bit sequence.
[0075] In some embodiments, the step of correcting the original bit sequence and encrypting the corrected bit sequence to determine the second target key includes:
[0076] The original bit sequence is subjected to information coordination processing to obtain the corrected bit sequence;
[0077] The privacy amplification algorithm is invoked to encrypt the corrected bit sequence, thereby obtaining the second target key.
[0078] In some embodiments, after encrypting the corrected bit sequence and determining the second target key, the method further includes:
[0079] Based on the equipment information of the base station, the second target key is stored respectively.
[0080] According to a third aspect of this disclosure, a key generation apparatus is provided. The apparatus is applied to a base station, and different terminal devices communicate with the base station using different time slices. The apparatus includes:
[0081] The first establishment unit is configured to establish a communication connection with the terminal device in response to a connection request initiated by the terminal device, and send a data frame to the terminal device.
[0082] A receiving unit is configured to receive an acknowledgment frame sent by the terminal device;
[0083] The first detection unit is used to perform channel detection based on a preset number of subcarriers in the preamble of the confirmation frame to obtain channel state information;
[0084] The first extraction unit is used to extract channel features from the channel state information to obtain channel features corresponding to the terminal device.
[0085] The first processing unit is used to perform quantization conversion and equalization processing on the channel features to generate the original bit sequence;
[0086] The first determining unit is used to correct the original bit sequence and encrypt the corrected bit sequence to determine the first target key.
[0087] In some embodiments, the first establishing unit includes:
[0088] The first judgment module is used to determine, based on the connection request, whether the current time slice is allocated to the terminal device;
[0089] The first initiating module is used to initiate a handshake with the terminal device to establish a communication connection when it is determined that the terminal device will be assigned to it.
[0090] In some embodiments, the first determining module includes:
[0091] The first judgment submodule is used to determine whether the terminal device identifier in the connection request is consistent with the terminal device identifier corresponding to the current time slice, based on the terminal device information of the terminal device, the collected IP address and the preset time slot allocation rules.
[0092] The first allocation submodule is used to allocate the current time slice to the terminal device and assign an IP address to the terminal device when the terminal device identifier matches the terminal device identifier corresponding to the current time slice.
[0093] In some embodiments, the first initiating module includes:
[0094] The first transmitting submodule is used to detect that the channel is idle and, after waiting for the distributed inter-frame interval, transmit channel reservation information;
[0095] The first receiving submodule is configured to respond to receiving reservation permission information sent by the terminal device;
[0096] The first connection submodule is used to complete the channel reservation with the terminal device to establish a communication connection based on the channel reservation information and the reservation permission information.
[0097] In some embodiments, the receiving unit includes:
[0098] A first sending module is configured to send the data frame to the terminal device and wait for a short inter-frame interval; wherein the short inter-frame interval is less than the distributed inter-frame interval.
[0099] The first receiving module is configured to receive the confirmation frame sent by the terminal device after a short frame interval.
[0100] In some embodiments, the channel state information is uplink channel state information;
[0101] The first detection unit includes:
[0102] The first acquisition module is used to acquire a preset number of subcarriers in the preamble of the confirmation frame;
[0103] The first estimation module is used to perform channel estimation on a preset number of subcarriers based on a preset subcarrier to obtain the uplink channel state information.
[0104] In some embodiments, the first extraction unit is further configured to perform amplitude processing and phase processing on the uplink channel state information to obtain channel features corresponding to the terminal device.
[0105] In some embodiments, the first extraction unit includes:
[0106] The first processing module is used to perform absolute value processing on the uplink channel state information and normalize the result of the absolute value processing to obtain the uplink channel amplitude characteristics.
[0107] The second processing module is used to calculate the phase information of the uplink channel state information, and to perform smoothing and centering processing on the phase information to obtain the uplink channel phase characteristics.
[0108] The first determining module is used to determine the channel characteristics corresponding to the terminal device based on the uplink channel amplitude characteristics and the uplink channel phase characteristics.
[0109] In some embodiments, the first processing unit includes:
[0110] The first conversion module is used to perform quantization conversion on the channel features to obtain at least one quantization mode;
[0111] The first calculation module is used to calculate the number of occurrences of the at least one quantization pattern;
[0112] The second determining module is used to perform equalization processing on the at least one quantization mode to obtain the original bit sequence when it is determined that the occurrence frequency exceeds a preset threshold.
[0113] In some embodiments, the first determining unit includes:
[0114] The third processing module is used to perform information coordination processing on the original bit sequence to obtain the corrected bit sequence;
[0115] The fourth processing module is used to call the privacy amplification algorithm to encrypt the corrected bit sequence to obtain the first target key.
[0116] In some embodiments, the apparatus further includes:
[0117] The first storage unit is used to store the first target key based on the device information of the terminal device after the first determining unit encrypts the corrected bit sequence and determines the first target key.
[0118] According to a fourth aspect of this disclosure, a key generation apparatus is provided. The apparatus is applied to terminal devices, and different terminal devices communicate with a base station using different time slices. The apparatus includes:
[0119] The second establishment unit is used to send a connection request to the base station and establish a communication connection with the base station;
[0120] The transmitting unit is configured to receive data frames transmitted by the base station and send acknowledgment frames to the base station.
[0121] The second detection unit is used to perform channel detection based on a preset number of subcarriers in the preamble of the data frame to obtain channel state information.
[0122] The second extraction unit is used to extract channel features from the channel state information to obtain channel features corresponding to the base station;
[0123] The second processing unit is used to perform quantization conversion and equalization processing on the channel features to generate the original bit sequence;
[0124] The second determining unit is used to correct the original bit sequence and encrypt the corrected bit sequence to determine the second target key.
[0125] In some embodiments, the second establishing unit includes:
[0126] The second judgment module is used to determine, based on the connection request, whether to receive the current time slice allocated by the base station;
[0127] The second initiating module is used to establish a communication connection with the base station by handshaking when it is determined that the current time slice allocated by the base station has been received.
[0128] In some embodiments, the second determining module includes:
[0129] The second judgment submodule is used to determine whether the identifier corresponding to the connection request is consistent with the identifier corresponding to the current time slice;
[0130] The second receiving submodule is configured to obtain the current time slice and receive the IP address sent by the base station if the identifier corresponding to the connection request matches the identifier corresponding to the current time slice.
[0131] In some embodiments, the second initiating module includes:
[0132] The third receiving submodule is used to receive channel reservation information sent by the base station in response to waiting for the distributed inter-frame interval;
[0133] The second sending submodule is used to send reservation permission information to the base station;
[0134] The second connection submodule is used to complete the channel reservation with the base station to establish a communication connection based on the channel reservation information and the reservation permission information.
[0135] In some embodiments, the transmitting unit includes:
[0136] The second receiving module is used to receive the data frame sent by the base station and wait for the short inter-frame interval; wherein the short inter-frame interval is smaller than the distributed inter-frame interval;
[0137] The second sending module is used to send the acknowledgment frame to the base station after a short inter-frame interval.
[0138] In some embodiments, the channel state information is downlink channel state information;
[0139] The second detection unit includes:
[0140] The second acquisition module is used to acquire a preset number of subcarriers in the preamble of the data frame;
[0141] The second estimation module is used to perform channel estimation on a preset number of subcarriers based on a preset subcarrier to obtain the downlink channel state information.
[0142] In some embodiments, the second extraction unit is further configured to perform amplitude processing and phase processing on the downlink channel state information to obtain channel features corresponding to the base station.
[0143] In some embodiments, the second extraction unit includes:
[0144] The fifth processing module is used to perform absolute value processing on the downlink channel state information and normalize the result of the absolute value processing to obtain the downlink channel amplitude characteristics.
[0145] The sixth processing module is used to calculate the phase information of the downlink channel state information, and to perform smoothing and centering processing on the phase information to obtain the downlink channel phase characteristics;
[0146] The third determining module is used to determine the channel characteristics corresponding to the base station based on the downlink channel amplitude characteristics and the downlink channel phase characteristics.
[0147] In some embodiments, the second processing unit includes:
[0148] The second conversion module is used to perform quantization conversion on the channel features to obtain at least one quantization mode;
[0149] The second calculation module is used to calculate the number of occurrences of the at least one quantization pattern;
[0150] The fourth determining module is used to perform equalization processing on the at least one quantization mode to obtain the original bit sequence when it is determined that the occurrence frequency exceeds a preset threshold.
[0151] In some embodiments, the second determining unit includes:
[0152] The seventh processing module is used to perform information coordination processing on the original bit sequence to obtain the corrected bit sequence;
[0153] The eighth processing module is used to call the privacy amplification algorithm to encrypt the corrected bit sequence to obtain the second target key.
[0154] In some embodiments, the apparatus further includes:
[0155] The second storage unit is used to store the second target key based on the equipment information of the base station after the second determining unit encrypts the corrected bit sequence and determines the second target key.
[0156] According to a fifth aspect embodiment of this disclosure, a key generation system is provided, the system comprising a base station and at least one terminal device, wherein,
[0157] The base station includes a key generation apparatus as described in the third aspect of the present disclosure;
[0158] The terminal device includes a key generation apparatus as described in the fourth aspect of this disclosure.
[0159] According to a sixth aspect of this disclosure, an electronic device is provided, comprising:
[0160] At least one processor; and
[0161] A memory communicatively connected to the at least one processor; wherein,
[0162] The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method described in the first or second aspect of the preceding embodiments.
[0163] According to a seventh aspect of this disclosure, a non-transitory computer-readable storage medium storing computer instructions is provided, wherein the computer instructions are configured to cause the computer to perform the methods described in the first or second aspect of the present disclosure.
[0164] According to an eighth aspect embodiment of the present disclosure, a computer program product is provided, including a computer program that, when executed by a processor, implements the method described in the foregoing first or second aspect embodiments.
[0165] In summary, according to the key generation method, apparatus, system, electronic device, and storage medium provided in this disclosure, the method includes: responding to a connection request initiated by a terminal device, establishing a communication connection with the terminal device, sending a data frame to the terminal device, receiving an acknowledgment frame sent by the terminal device, performing channel probing based on a preset number of subcarriers in the preamble of the acknowledgment frame to obtain channel state information, extracting channel features from the channel state information to obtain channel features corresponding to the terminal device, performing quantization conversion and equalization processing on the channel features to generate an original bit sequence, correcting the original bit sequence, encrypting the corrected bit sequence, and determining a first target key. This method eliminates the need for each terminal device to exclusively occupy the communication channel bandwidth, enabling at least one terminal device to share the channel to reduce resource waste, supporting parallel generation to improve efficiency, and thus adapting to the concurrent requirements of at least one terminal device, meeting the practical scenario of quantum key wireless distribution for at least one terminal device in a wireless local area network.
[0166] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of this application, nor is it intended to limit the scope of this application. Other features of this application will become readily apparent from the following description. Attached Figure Description
[0167] The accompanying drawings are provided to better understand this solution and do not constitute a limitation of this disclosure. Wherein:
[0168] Figure 1 A schematic flowchart illustrating a key generation method provided in an embodiment of this disclosure;
[0169] Figure 2 A schematic flowchart illustrating another key generation method provided in this embodiment of the disclosure;
[0170] Figure 3 A schematic flowchart illustrating another key generation method provided in this embodiment of the disclosure;
[0171] Figure 4 A schematic diagram of a system network for a key generation method provided in an embodiment of this disclosure;
[0172] Figure 5 A schematic flowchart illustrating another key generation method provided in this embodiment of the disclosure;
[0173] Figure 6 A schematic diagram of channel probing for a key generation method provided in an embodiment of this disclosure;
[0174] Figure 7 A schematic flowchart illustrating another key generation method provided in this embodiment of the disclosure;
[0175] Figure 8 A schematic flowchart illustrating another key generation method provided in this embodiment of the disclosure;
[0176] Figure 9 A schematic flowchart illustrating another key generation method provided in this embodiment of the disclosure;
[0177] Figure 10 A schematic flowchart illustrating another key generation method provided in this embodiment of the disclosure;
[0178] Figure 11 A schematic flowchart illustrating another key generation method provided in this embodiment of the disclosure;
[0179] Figure 12 A schematic flowchart illustrating another key generation method provided in this embodiment of the disclosure;
[0180] Figure 13 A schematic flowchart illustrating a key generation method provided in an embodiment of this disclosure;
[0181] Figure 14 A schematic flowchart illustrating another key generation method provided in this embodiment of the disclosure;
[0182] Figure 15 A schematic flowchart illustrating another key generation method provided in this embodiment of the disclosure;
[0183] Figure 16 A schematic flowchart illustrating another key generation method provided in this embodiment of the disclosure;
[0184] Figure 17 A schematic flowchart illustrating another key generation method provided in this embodiment of the disclosure;
[0185] Figure 18 A schematic flowchart illustrating another key generation method provided in this embodiment of the disclosure;
[0186] Figure 19 A schematic flowchart illustrating another key generation method provided in this embodiment of the disclosure;
[0187] Figure 20 A schematic flowchart illustrating another key generation method provided in this embodiment of the disclosure;
[0188] Figure 21 A schematic flowchart illustrating another key generation method provided in this embodiment of the disclosure;
[0189] Figure 22 This is a schematic diagram illustrating the interaction process between a base station and a terminal device, provided in an embodiment of this disclosure.
[0190] Figure 23 A schematic diagram of a key generation apparatus provided in an embodiment of this disclosure;
[0191] Figure 24 A schematic diagram of another key generation apparatus provided in an embodiment of this disclosure;
[0192] Figure 25 A schematic diagram of a key generation apparatus provided in an embodiment of this disclosure;
[0193] Figure 26 A schematic diagram of another key generation apparatus provided in an embodiment of this disclosure;
[0194] Figure 27 A schematic diagram of the structure of a key generation system provided in an embodiment of this disclosure;
[0195] Figure 28 A schematic block diagram of an example electronic device provided for embodiments of this disclosure. Detailed Implementation
[0196] The exemplary embodiments of this disclosure are described below with reference to the accompanying drawings, including various details of the embodiments to aid understanding, and should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of this disclosure. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.
[0197] In the process of integrating quantum technology and communication technology, QKD technology provides important support for secure information transmission, especially in multi-user, large-scale quantum key transmission scenarios.
[0198] In multi-user quantum key wireless distribution scenarios under wireless LAN, each user needs to exclusively occupy the entire communication channel bandwidth to generate a wireless key, and multiple users need to generate wireless keys in turn according to time polling, which leads to low multi-user key generation efficiency and makes it difficult to adapt the wireless key generation to the concurrent needs of multiple users. Therefore, how to improve the generation efficiency of multi-user wireless keys is an urgent problem to be solved.
[0199] Therefore, in order to solve the problems existing in related technologies, this disclosure proposes a key generation method. The method includes: in response to a connection request initiated by a terminal device, establishing a communication connection with the terminal device and sending a data frame to the terminal device; receiving an acknowledgment frame sent by the terminal device; performing channel probing based on a preset number of subcarriers in the preamble of the acknowledgment frame to obtain channel state information; extracting channel features from the channel state information to obtain channel features corresponding to the terminal device; performing quantization conversion and equalization processing on the channel features to generate an original bit sequence; correcting the original bit sequence; encrypting the corrected bit sequence; and determining a first target key. This method eliminates the need for each terminal device to exclusively occupy the communication channel bandwidth, enabling at least one terminal device to share the channel to reduce resource waste, supports parallel generation to improve efficiency, and adapts to the concurrent requirements of at least one terminal device, thus meeting the practical scenario of quantum key wireless distribution for at least one terminal device in a wireless local area network.
[0200] This disclosure is not exhaustive, but merely illustrative of some embodiments, and is not intended to limit the scope of protection of this disclosure. Unless otherwise specified, each step in a particular embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a particular embodiment can also be implemented as an independent embodiment, and the order of the steps in a particular embodiment can be arbitrarily interchanged. Furthermore, the optional implementation methods in a particular embodiment can be arbitrarily combined; moreover, the embodiments can be arbitrarily combined, for example, some or all steps of different embodiments can be arbitrarily combined, and a particular embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.
[0201] In each of the disclosed embodiments, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions of the embodiments are consistent and can be referenced by each other. Technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships.
[0202] The terminology used in the embodiments of this disclosure is for the purpose of describing particular embodiments only and is not intended to limit the scope of this disclosure.
[0203] In this embodiment of the disclosure, unless otherwise stated, elements expressed in the singular form, such as "a," "an," "the," "the," "the," "the," "the," "the," "this," etc., can mean "one and only one," or "one or more," "at least one," etc. For example, when using articles such as "a," "an," "the," etc. in translation, the noun following the article can be understood as either a singular expression or a plural expression.
[0204] In some embodiments, the terms “in response to…”, “in response to determining…”, “in the case of…”, “when…”, “if…”, “if…”, etc., can be used interchangeably.
[0205] In some embodiments, the terms “greater than,” “greater than or equal to,” “not less than,” “more than,” “more than or equal to,” “not less than,” “higher than,” “higher than or equal to,” “not lower than,” and “above” can be used interchangeably, as can the terms “less than,” “less than or equal to,” “not greater than,” “less than,” “less than or equal to,” “not more than,” “lower than,” “lower than or equal to,” “not higher than,” and “below”.
[0206] The prefixes such as "first" and "second" in the embodiments of this disclosure are only for distinguishing different descriptive objects and do not constitute restrictions on the position, order, priority, number or content of the descriptive objects. For the description of the descriptive objects, please refer to the description in the claims or the context of the embodiments. The use of prefixes should not constitute unnecessary restrictions.
[0207] In the embodiments disclosed herein, "multiple" refers to two or more.
[0208] In the embodiments disclosed herein, terms such as “import”, “input”, and “read in” can be used interchangeably.
[0209] In some embodiments, devices, etc., can be interpreted as physical or virtual, and their names are not limited to the names recorded in the embodiments. Terms such as “device”, “equipment”, “circuit”, “network element”, “node”, “function”, “unit”, “section”, “system”, “network”, “chip”, “chip system”, “entity”, and “subject” can be used interchangeably.
[0210] In some embodiments, the terms "terminal", "terminal device", "user equipment (UE)", "user terminal", "mobile station (MS)", "mobile terminal (MT)", "subscriber station", "mobile unit", "subscriber unit", "wireless unit", "remote unit", "mobile device", "wireless device", "wireless communication device", "remote device", "mobile subscriber station", "access terminal", "mobile terminal", "wireless terminal", "remote terminal", "handset", "user agent", "mobile client", and "client" can be used interchangeably.
[0211] The following description, with reference to the accompanying drawings, outlines a method, apparatus, system, electronic device, and storage medium for generating keys according to embodiments of the present disclosure.
[0212] Figure 1 This is a schematic flowchart illustrating a key generation method provided in an embodiment of the present disclosure.
[0213] like Figure 1 As shown, this method is applied to a base station, and the key generation method includes steps 101-104.
[0214] Step 101: In response to the terminal device initiating a connection request, establish a communication connection with the terminal device and send a data frame to the terminal device.
[0215] In this embodiment of the disclosure, the connection request initiated by the terminal device includes the identification information of the terminal device. After the base station receives the connection request, since different terminal devices need to occupy different time slots to communicate with the base station, the base station will check whether the current time slot corresponds to the terminal device that initiated the request according to the preset time slot allocation rules. If the current time slot belongs to the terminal device, the base station will complete the establishment of a communication connection with the terminal device. After the communication connection is established, the base station sends a data frame to the terminal device. The data frame contains basic data for subsequent channel-related processing.
[0216] By using time-slice allocation to achieve orderly connection between base stations and terminal devices, channel chaos caused by simultaneous connection of multiple terminal devices can be avoided, ensuring stable establishment of communication connections.
[0217] Step 102: Receive the acknowledgment frame sent by the terminal device, and perform channel probing based on a preset number of subcarriers in the preamble of the acknowledgment frame to obtain channel state information.
[0218] After receiving a data frame, the terminal device generates an acknowledgment frame and sends it to the base station. The acknowledgment frame is used to indicate that the data frame has been correctly received. The preamble of the acknowledgment frame is located at the beginning of the frame and contains a fixed sequence for synchronization and channel estimation. The base station selects a preset number of subcarriers from the preamble. The preset number of subcarriers is pre-configured by the base station and serves as the carrier for channel information in the preamble. By detecting the signal amplitude, phase, and other information of the preset number of subcarriers, the base station analyzes the channel transmission characteristics from the terminal device to the base station and obtains channel state information.
[0219] Channel probing using subcarriers in the acknowledgment frame preamble allows for direct acquisition of channel information based on the acknowledgment frame without the need to send additional acknowledgment frames. Furthermore, the fixed nature of the preamble ensures the accuracy of the channel state information.
[0220] Step 103: Extract channel features from the channel state information to obtain channel features corresponding to the terminal device, and perform quantization conversion and equalization processing on the channel features to generate the original bit sequence.
[0221] Channel features are extracted from channel state information to reflect the inherent characteristics of the channel. Channel features are then quantized and converted using preset quantization rules to convert continuous values of channel features into discrete binary bits, forming quantization patterns. The quantization patterns are then balanced by reducing the frequency of some quantization patterns when they occur frequently, thus making the distribution of each quantization pattern more uniform and ultimately generating the original bit sequence.
[0222] The extracted channel features can reflect the unique channel characteristics of terminal devices and base stations, while quantization conversion and equalization processing transform these unique channel characteristics into raw bit sequences that can be used for key generation.
[0223] Step 104: Correct the original bit sequence and encrypt the corrected bit sequence to determine the first target key.
[0224] In some embodiments, the original bit sequence is corrected by comparing the redundant check bits in the original bit sequence, identifying and correcting erroneous bits in the original bit sequence to ensure the accuracy of the original bit sequence, encrypting the corrected bit sequence, and transforming the corrected bit sequence through a preset processing method to enhance the confidentiality of the corrected bit sequence, and finally obtaining the first target key.
[0225] The above methods can eliminate errors in the original bit sequence and ensure the accuracy of the sequence, while the encryption process can improve the sequence's resistance to cracking and ensure that the determined first target key can meet the communication encryption requirements.
[0226] In summary, the key generation method provided in this disclosure includes: responding to a connection request initiated by a terminal device, establishing a communication connection with the terminal device, sending a data frame to the terminal device, receiving an acknowledgment frame sent by the terminal device, performing channel probing based on a preset number of subcarriers in the preamble of the acknowledgment frame to obtain channel state information, extracting channel features from the channel state information to obtain channel features corresponding to the terminal device, performing quantization conversion and equalization processing on the channel features to generate an original bit sequence, correcting the original bit sequence, encrypting the corrected bit sequence, and determining a first target key. This method eliminates the need for each terminal device to exclusively occupy the communication channel bandwidth, enabling at least one terminal device to share the channel to reduce resource waste, supporting parallel generation to improve efficiency, and thus adapting to the concurrent requirements of at least one terminal device, meeting the practical scenario of quantum key wireless distribution for at least one terminal device under a wireless local area network.
[0227] Figure 2 A flowchart illustrating a key generation method provided in an embodiment of this disclosure is further illustrated. Based on Figure 1 The illustrated embodiment further explains step 101. Figure 2 This may include the following steps:
[0228] Step 201: Based on the connection request, determine whether the current time slice is allocated to the terminal device.
[0229] In this embodiment of the disclosure, the connection request carries the identification information of the terminal device initiating the request, such as the device number and unique identifier of the terminal device. The base station has a preset time slot allocation rule, which clarifies the time slot corresponding to each different terminal device. The time slots do not overlap in the time dimension. After receiving the connection request, the base station extracts the identification information of the terminal device and obtains the time slot corresponding to the current time. Then, according to the time slot allocation rule, it queries the identification information of the terminal device corresponding to the current time slot and compares the current time slot with the identification information of the terminal device to determine whether the current time slot is allocated to the corresponding terminal device.
[0230] Step 202: If it is determined that a channel is allocated to the terminal device, then a channel reservation with the terminal device is initiated to establish a communication connection.
[0231] When the current time slice is determined to be allocated to the corresponding terminal device, the base station sends a handshake start signal to the terminal device. After receiving the signal, if the terminal device confirms the communication connection, it returns a handshake response signal to the base station. After receiving the handshake response signal, the base station completes the handshake process with the terminal device, thereby establishing a communication connection between the base station and the terminal device.
[0232] By determining whether a terminal device is within its allocated time slice based on the connection request, and establishing a communication connection through a handshake after determining that the time slice has been allocated to the terminal device, time-division ordered communication between at least one terminal device and the base station can be achieved, avoiding channel conflicts caused by at least one terminal device accessing the network simultaneously.
[0233] Figure 3 A flowchart illustrating a key generation method provided in an embodiment of this disclosure is further illustrated. Based on Figure 2 The illustrated embodiment further explains step 201. Figure 3 This may include the following steps:
[0234] Step 301: Based on the terminal device information of the terminal device, the collected IP address and the preset time slot allocation rules, determine whether the terminal device identifier in the connection request is consistent with the terminal device identifier corresponding to the current time slot.
[0235] Terminal device information includes the hardware and software information of the terminal device. The terminal device information and terminal device identifier are bound and stored in the base station. The collected IP address is the network address recorded when the base station communicates with the terminal device. The preset time slot allocation rules not only include the correspondence between each time slot and the terminal device identifier, but also associate the terminal device information and IP address.
[0236] The base station extracts the terminal device identifier and terminal device information from the connection request, and retrieves the collected IP address. It then uses the time slot allocation rules to locate the terminal device identifier corresponding to the current time slot and completes the consistency judgment by comparing the terminal device identifier in the connection request with the terminal device identifier corresponding to the current time slot.
[0237] Step 302: If the terminal device identifier is consistent with the terminal device identifier corresponding to the current time slice, then the current time slice is allocated to the terminal device, and an IP address is assigned to the terminal device.
[0238] The base station marks the current time slice as the exclusive communication period for the terminal device, and selects an unoccupied IP address or calls an IP address pre-bound to the terminal device's identifier. The base station then sends the time slice allocation result and the IP address to the terminal device.
[0239] In some embodiments, such as Figure 4 This is a system network diagram illustrating a key generation method provided in this embodiment of the present disclosure. Taking four STAs as an example, in the downlink (base station sending information to terminal device), at time t1, the AP (base station) sends the information AP-->STA1 to STA1 (terminal device 1); in the uplink (terminal device sending information to base station), at time t1' (corresponding to t in the downlink...), At time t1, STA1 sends the message STA1-->AP to AP; in the downlink, at time t2, AP sends the message AP-->STA2 to STA2 (terminal device 2); in the uplink, at time t2' (corresponding to time t2 in the downlink), STA2 sends the message STA2-->AP to AP; in the downlink, at time t3, AP sends the message AP-->STA3 (terminal device 3) to STA3; in the uplink, at time t3' (corresponding to time t3 in the downlink), STA3 sends the message STA3-->AP to AP; in the downlink, at time t4, AP sends the message AP-->STA4 to STA4 (terminal device 4); in the uplink, at time t4' (corresponding to time t4 in the downlink), STA4 sends the message STA4-->AP to AP. Specifically, the number of terminal devices is not limited.
[0240] In the first time slice, the AP connects and communicates simultaneously with the first node STA, i.e., the AP connects and communicates with STA1. In the second time slice, the AP connects and communicates simultaneously with the second node STA, i.e., the AP connects and communicates with STA2. In the (n-1)th time slice, the AP connects and communicates simultaneously with the (n-1)th node STA, i.e., the AP connects and communicates with STA n-1 (terminal device n-1). In the nth time slice, the AP connects and communicates simultaneously with the nth node STA, i.e., the AP connects and communicates with STA n (terminal device n). In the (n+1)th time slice, the AP connects and communicates simultaneously with the first node STA, i.e., the AP connects and communicates with STA1. In the (n+2)th time slice, the AP connects and communicates simultaneously with the second node STA, i.e., the AP connects and communicates with STA2. In the (2n-1)th time slice, the AP connects and communicates simultaneously with the (n-1)th node STA, i.e., the AP connects and communicates with STA2. In the n-1 time slice, the AP connects and communicates with the nth node STA simultaneously; that is, the AP connects and communicates with STA n.
[0241] Figure 5 A flowchart illustrating a key generation method provided in an embodiment of this disclosure is further illustrated. Based on Figure 2 The illustrated embodiment further explains step 202. Figure 5 This may include the following steps:
[0242] Step 401: If the channel is detected to be idle, after waiting for the distributed inter-frame interval, channel reservation information is sent.
[0243] The base station determines whether the current communication channel is idle by using a preset channel detection mechanism. For example, it determines whether the channel is idle by detecting whether there are signals transmitted by other terminal devices in the channel. When the channel is detected to be idle, the base station enters a waiting state for a preset distributed inter-frame interval. This distributed inter-frame interval is a fixed time length set in the communication protocol to avoid channel access conflicts between terminal devices. After waiting for the distributed inter-frame interval, the base station sends channel reservation information to the terminal device.
[0244] Step 402: In response to receiving the reservation permission information sent by the terminal device.
[0245] After receiving the channel reservation information sent by the base station, the terminal device verifies the content of the channel reservation information. If it confirms that it can participate in communication within the reserved communication duration, it generates reservation permission information, which includes the terminal device identifier and confirmation information of the reservation content.
[0246] Step 403: Based on the channel reservation information and the reservation permission information, complete the channel reservation with the terminal device to establish a communication connection.
[0247] The base station compares the received reservation permission information with the channel reservation information sent by the terminal device to confirm that the communication duration, channel parameters and other information in the two are consistent. After confirming that the information is consistent, the base station and the terminal device complete the channel reservation. Based on the completed channel reservation, the base station and the terminal device establish a communication connection for data transmission.
[0248] Based on the channel idle detection and distributed inter-frame interval waiting mechanism, conflicts during channel reservation can be reduced; by combining the interaction of channel reservation information and reservation permission information to complete the reservation, the consensus between the base station and terminal equipment on channel use can be guaranteed, thereby establishing a stable communication connection.
[0249] In some embodiments, such as Figure 6 This diagram illustrates a channel probing method for a key generation method provided in this embodiment. When an idle channel is detected, the base station (AP) waits for the Distributed Interframe Space (DIFS) before sending a channel reservation information (RTS frame). Upon receiving the RTS frame, the base station (STA) waits for the Short Interframe Space (SIFS) and then replies with a reservation allowance information (CTS frame). Through this process, the AP and STA complete the channel reservation. When the STA receives a data frame, it waits for SIFS and then replies with an acknowledgment frame (ACK frame), indicating confirmation of the received data. RTS +SIFS is the interval between RTS and CTS frames, T CTS +SIFS is the interval between the CTS frame and the Data frame, and the interval between the interaction between the AP and the STA is T. Data +SIFS, where T Data T represents the duration of sending a Data frame. Data +SIFS has the shortest interval time, utilizing T Data +SIFS deterministic time interval extraction of channel features, for example, T Data The interval of +SIFS is 144us, where T Data The time is 128us, the SIFS time is 16us, and channel features are extracted using 144us; T ACK T is the interval between the terminal device's response to the acknowledgment frame. Contention T is the time interval during which at least two terminal devices compete for the channel. Data +SIFS+T ACK +DIFS+T ContentionThis is the interval between sending a data frame and sending the next data frame. The above example is for illustrative purposes only and is not intended to limit the specific content.
[0250] Figure 7 A flowchart illustrating a key generation method provided in an embodiment of this disclosure is further illustrated. Based on Figure 5 The illustrated embodiment further explains step 102. Figure 7 This may include the following steps:
[0251] Step 501: Send the data frame to the terminal device and wait for the short inter-frame interval; wherein the short inter-frame interval is less than the distributed inter-frame interval.
[0252] After establishing a communication connection with the terminal device, the base station assembles data frames according to a preset frame format. The base station then sends the data frames to the terminal device through the established communication link. After transmission, the base station starts a timer and waits for a preset short inter-frame interval. The short inter-frame interval is the time specified in the communication protocol for the terminal device to process the data frames and prepare to return an acknowledgment frame. The duration of the short inter-frame interval is shorter than the distributed inter-frame interval; for example, the distributed inter-frame interval is 50 microseconds, while the short inter-frame interval is 10 microseconds. The above example is for illustrative purposes only and does not limit the specific content.
[0253] Step 502: After a short frame interval, receive the confirmation frame sent by the terminal device.
[0254] When the short inter-frame interval ends, the base station receives the acknowledgment frame returned by the terminal device. After receiving and parsing the data frame, the terminal device generates an acknowledgment frame containing an identifier of the data frame reception status. The terminal device completes the generation of the acknowledgment frame within the short inter-frame interval and sends it to the base station after the short inter-frame interval. The base station receives the acknowledgment frame.
[0255] The short inter-frame interval is set as the buffer time between data frame transmission and acknowledgment frame reception. The duration of the short inter-frame interval is shorter than that of the distributed inter-frame interval. This not only reserves processing time for the terminal device but also shortens the communication response cycle and ensures the timeliness of acknowledgment frame reception.
[0256] Figure 8 A flowchart illustrating a key generation method provided in an embodiment of this disclosure is further illustrated. Based on Figure 1 The illustrated embodiment further explains step 102. Figure 8 This may include the following steps:
[0257] Step 601: Obtain a preset number of subcarriers in the preamble of the confirmation frame.
[0258] The preamble of the acknowledgment frame consists of a preset number of subcarriers, which are distributed at preset intervals. The preset number of subcarriers are used to carry signals required for synchronization and channel estimation. After receiving the acknowledgment frame, the base station parses the acknowledgment frame to locate the start and end positions of the preamble, and then extracts the preset number of subcarriers from the preamble according to preset selection rules.
[0259] Step 602: Based on a preset number of subcarriers, perform channel estimation on the preset number of subcarriers to obtain the uplink channel state information.
[0260] The preset subcarrier is a reference subcarrier used by the base station for channel estimation. The channel characteristics (such as amplitude and phase) of the preset subcarrier are stored in advance. The base station compares the actual received signals of the preset number of subcarriers with the reference signals of the preset subcarriers, calculates the differences between the two, such as amplitude attenuation and phase offset, and generates uplink channel state information based on the evaluation results by evaluating the channel transmission characteristics from the terminal device to the base station.
[0261] In some embodiments, the wireless local area network protocol specifies that each frame of signal has a preamble, which is determined by the physical layer frame format. The AP uses the preamble of the i-th received DATA frame to contain a preset number of subcarriers for channel estimation, and obtains the uplink channel state information CSI_APi on the corresponding preset number of subcarriers, as shown in Formula 1.
[0262] CSI_APi={CSI_APi(1), CSI_APi(2),..., CSI_APi(j),..., CSI_APi(n)} Formula 1
[0263] Where CSI_APi represents uplink channel state information, j represents uplink channel state information corresponding to the j-th subcarrier, and n represents uplink channel state information corresponding to the n-th subcarrier.
[0264] Figure 9 A flowchart illustrating a key generation method provided in an embodiment of this disclosure is further illustrated. Based on Figure 8 The illustrated embodiment further explains step 103. Figure 9 This may include the following steps:
[0265] Step 701: Perform amplitude and phase processing on the uplink channel state information to obtain the channel characteristics corresponding to the terminal device.
[0266] Uplink channel state information includes amplitude and phase information that reflect the channel transmission characteristics. Amplitude processing is used to process the amplitude information to extract stable amplitude features; phase processing is used to process the phase information to remove fluctuations caused by noise or interference and obtain reliable phase features. By combining the results of amplitude processing and phase processing, a channel feature that can identify the channel characteristics between the terminal device and the base station is formed.
[0267] Step 702: Perform absolute value processing on the uplink channel state information, and normalize the result of the absolute value processing to obtain the uplink channel amplitude characteristics.
[0268] The amplitude information in the uplink channel state information may contain positive and negative values. Absolute value processing can convert these values to non-negative values, eliminating the influence of the sign on key generation. After absolute value processing, the resulting value is normalized to obtain the uplink channel amplitude feature CSI_Mag_AP. i The normalization process is shown in Formula 2.
[0269]
[0270] Among them, |CSI_AP i (n)| represents the absolute value of the amplitude of the uplink channel state information of the nth subcarrier of the i-th base station. The uplink channel state information of all n subcarriers of the i-th base station is normalized.
[0271] Step 703: Calculate the phase information of the uplink channel state information, and perform smoothing and centering processing on the phase information to obtain the uplink channel phase characteristics.
[0272] The phase information of the uplink channel state information is calculated by processing the imaginary and real parts of the uplink channel state information and then calculating the arctangent function of the result of the imaginary and real part processing to obtain the phase information. Since the interval of the arctangent function is (-π, π), the calculated actual phase information will be folded in the range of (-π, π). Therefore, phase expansion processing is required to generate smoother phase information.
[0273] The phase information is calculated as shown in Formulas 3 and 4.
[0274] θ_AP i ={θ_AP i (1),θ_AP i (2),...,θ_AP i (j),...,θ_AP i (n)} Formula 3
[0275]
[0276] Where θ_AP i CSI_AP is the set of phase information for the i-th base station, containing n phase information items (corresponding to n subcarriers), used to describe the phase distribution of the channel on different subcarriers. i (j) represents the channel state information of the i-th base station and the j-th subcarrier, real() and imag() represent the processing of taking the real part and the imaginary part, respectively, and arctan() represents the arctangent function.
[0277] Specifically, For the j-th phase information of the i-th base station, the phase expansion processing on the base station side is as follows:
[0278] make
[0279] Starting from the second subcarrier (j=2), calculate the phase difference θ_AP between the current subcarrier and the previous subcarrier sequentially. i (j)-θ_AP i (j-1);
[0280] If the phase difference θ_AP i (j)-θ_AP i If (j-1) is greater than π, then the current subcarrier phase will be... The phase of each subsequent subcarrier is reduced by 2π.
[0281] If the phase difference θ_AP i (j)-θ_AP i If (j-1) is less than -π, then the current subcarrier phase will be... And add 2π to the phase of each subsequent subcarrier;
[0282] For the expanded phase θ_AP i Centralization processing is performed to remove the fixed phase offset caused by the base station, in order to obtain the uplink channel phase characteristic CSI_Phase_AP. i The centralization process is shown in Formulas 5 and 6.
[0283] CSI_Phase_AP i ={CSI_Phase_AP i (1),...,CSI_Phase_AP i (j), ...,CSI_Phase_AP i (n)} Formula 5
[0284]
[0285] Among them, CSI_Phase_AP iCSI_Phase_AP represents the uplink channel phase characteristics of the i-th base station. i (j) represents the uplink channel phase characteristics of the j-th subcarrier of the i-th base station. Let be the original phase of the i-th base station and the j-th subcarrier. To calculate the average phase of all subcarriers.
[0286] Step 704: Determine the channel characteristics corresponding to the terminal device based on the uplink channel amplitude characteristics and the uplink channel phase characteristics.
[0287] The uplink channel amplitude characteristics and uplink channel phase characteristics are combined in a one-to-one correspondence according to the subcarrier sequence number to form the channel characteristics of each subcarrier.
[0288] By using the above method, different dimensions of channel features are extracted through amplitude processing and phase processing, and then integrated to form complete channel features, which can comprehensively capture the unique attributes of the channel between terminal equipment and base station.
[0289] Figure 10 A flowchart illustrating a key generation method provided in an embodiment of this disclosure is further illustrated. Based on Figure 9 The illustrated embodiment further explains step 103. Figure 10 This may include the following steps:
[0290] Step 801: Quantize the channel features to obtain at least one quantization mode.
[0291] Channel characteristics contain continuous values across multiple dimensions. For example, the amplitude values of each subcarrier in the uplink channel amplitude characteristics and the phase values of each subcarrier in the uplink channel phase characteristics are both continuous values. During quantization conversion, the continuous values are discretized using a preset quantization interval. Each quantization interval corresponds to a set of binary bits. For example, the amplitude value is divided into 8 quantization intervals, and each quantization interval corresponds to 3 binary bits. A similar quantization method is used for the phase value to obtain the corresponding binary bits. The amplitude quantization bits and phase quantization bits of the same subcarrier are concatenated in a preset order to form the quantization mode corresponding to that subcarrier. The quantization modes of all subcarriers together constitute at least one quantization mode.
[0292] In some embodiments, a third-order differential quantization algorithm is used for quantization conversion, and the specific process is as follows:
[0293] g(i) = f(i) - f(i-1)
[0294] h(i) = ||g(i)| - |g(i-1)||
[0295]
[0296] K m =K1K2K3
[0297] in,
[0298]
[0299] Channel characteristics include the amplitude characteristics of subcarriers. After channel detection is completed, differential quantization is performed for quantization conversion. This differential quantization algorithm includes third-order differential quantization and differential compensation. Specifically, the third-order differential quantization algorithm is an adaptive third-order differential quantization algorithm: the subcarrier trend g(i) and the trend h(i) of g(i) are calculated, where g(i) = f(i) - f(i-1), and h(i) = |(|g(i)| - |g(i-1)|)|. f(i) is the amplitude characteristic value of the i-th subcarrier; K1, K2, and K3 are obtained based on g(i) and h(i), where K1 is the result of first-order differential quantization, satisfying K1 = 1 when f(i) > f(i-1) and K1 = 0 when f(i) ≤ f(i-1), used to compare the changing trends of adjacent points; K2 satisfies K2 = 1 when g(i) > t1 and K2 = 0 when g(i) ≤ t1, used to compare the relationship between the variable increase and the threshold t1. K3 satisfies the condition that K3 = 1 when h(i) > t2 and K3 = 0 when h(i) ≤ t2, and is used to compare the relationship between the increase of the variable and the threshold t2. Third-order quantization converts the characteristics of each subcarrier into three binary 0 and 1 bits, forming the quantization mode K. m K m Composed of K1, K2, and K3, multiple subcarriers correspond to form at least one quantization mode.
[0300] Step 802: Calculate the number of occurrences of the at least one quantization pattern.
[0301] Traverse all quantization patterns K m Count the occurrence frequency of each quantization mode in all subcarrier quantization results; if the channel features contain n subcarriers and the quantization order is r, then the preset threshold t is... At the same time, the decimal size of each quantization mode is recorded. For example, the decimal sizes of the eight modes of third-order quantization, 000, 001, 010, 011, 100, 101, 110, and 111, are 0, 1, 2, 3, 4, 5, 6, and 7, respectively, forming a mapping relationship between each quantization mode and its corresponding occurrence frequency and decimal size.
[0302] Step 803: If the occurrence count exceeds a preset threshold, perform equalization processing on the at least one quantization mode to obtain the original bit sequence.
[0303] The differential quantization algorithm reduces the absolute threshold, making the signal change trend more obvious. If there is a single signal change trend or a certain number of significant specific change trends, it will cause the occurrence times of some quantization patterns to exceed the threshold t, which may result in an imbalance in the number of 0 and 1 bits in the key and affect randomness. Therefore, a differential compensation method is used for balancing processing; define ma as the first pattern on the right side of the current pattern m with the occurrence times ka < t, and if it does not exist, search from 000; define mb as the first pattern on the right side of m with the occurrence times kb < t; define mc as the first pattern on the left side of m with the occurrence times kc < t, and if it does not exist, stop the search in this direction; define lb and lc as the distances between mb, mc and m respectively, with the initial value of 2r. If mb is found, lb is updated to dm - db, and if mc is found, lc is updated to dc - db. dm, db, and dc are the decimal sizes of m, mb, and mc respectively; the balancing processing includes the following patterns: Pattern 1 is one-way differential compensation. If ma exists, quantize m to ma; Pattern 2 is two-way differential compensation. If both mb and mc exist, quantize m to the pattern with the smaller value of lb and lc; Pattern 3 is one-way differential compensation. Increase t to t + 1 to reduce error accumulation, and the rest is the same as Pattern 1; Pattern 4 is two-way differential compensation. Increase t to t + 1, and the rest is the same as Pattern 2; Pattern 5 is two-way differential compensation. Use a preset Gray mapping sorting quantization pattern (for example, the 8 patterns of three-order quantization are sorted as 000, 001, 011, 010, 110, 111, 101, 100). Compare the occurrence times of the patterns on the left and right sides near m, and quantize m to the pattern with the smaller occurrence times. If neither is satisfied, no compensation is performed; after the balancing processing, splice all quantization patterns in the subcarrier order to generate the original bit sequence. It should be noted that the number of the above patterns is not limited.
[0304] Through the above method, the quantization conversion transforms the channel characteristics into quantization patterns based on the adaptive three-order differential quantization algorithm, and the balancing processing improves the problem of uneven bit distribution through the differential compensation method, making the generated original bit sequence have better randomness.
[0305] Figure 11 Further shows the flowchart of a method for generating a key provided by an embodiment of the present disclosure. As Figure 11 shown, Figure 11 It may include the following steps:
[0306] Step 901, perform information reconciliation processing on the original bit sequence to obtain the corrected bit sequence.
[0307] Information coordination processing is used to eliminate possible errors in the original bit sequence and make the processed bit sequence consistent. Information coordination methods include at least error detection protocol-based methods (EDPA) and error correction code-based methods (ECCA).
[0308] The original bit sequence is processed by a pre-defined information coordination method to correct errors in the sequence and obtain a corrected bit sequence.
[0309] Step 902: Invoke the privacy amplification algorithm to encrypt the corrected bit sequence to obtain the first target key.
[0310] Privacy amplification algorithms are used to enhance the security of corrected bit sequences by converting them into highly secure keys. Privacy amplification methods include at least an extractor method and a hash function method. The extractor method uses a small number of completely random bits as catalysts, adding these additional bits as part of a nearly uniformly distributed output to extract substantially random bits from the randomness of the source. The hash function method converts the negotiated and agreed-upon key into a completely secure key, and then calls the privacy amplification algorithm to encrypt the corrected bit sequence to obtain the first target key.
[0311] Information coordination processing can eliminate errors in the original bit sequence and ensure the consistency of the sequence; privacy amplification algorithms can improve the security of the bit sequence, thereby obtaining a first target key that meets security requirements.
[0312] Step 903: Based on the device information of the terminal device, store the first target key respectively.
[0313] The device information of the terminal device includes an IP address list and hardware address. Based on the device information, the generated first target key is associated with and stored with the corresponding terminal device. During use, the terminal device and the base station use their respective stored wireless keys and perform operations such as key synchronization, destruction, etc. through information such as IP address list and hardware address to ensure key synchronization and coordination.
[0314] As one feasible approach, the wireless keys of the terminal device and the base station can be merged to form a key chain before being stored and used.
[0315] In some embodiments, such as Figure 12This is a flowchart illustrating a key generation method provided in an embodiment of the present disclosure. Differential quantization (quantization conversion and equalization processing) is performed on the channel state information of a base station (AP CSI) and at least one terminal device (such as STA i CSI, STA j CSI, etc.) to generate a quantization pattern. Error correction is performed on the quantization pattern through information harmonicization (correction processing) to obtain a consistent bit sequence. Privacy amplification (encryption) is called to convert it into a wireless key (such as an AP wireless key, a terminal device wireless key, etc.). The key is then stored in association based on device information and called collaboratively through a synchronization key to complete the process of generating and encrypting a usable key from channel state information and applying the encryption.
[0316] Figure 13 This is a schematic flowchart illustrating a key generation method provided in an embodiment of the present disclosure.
[0317] like Figure 13 As shown, this method is applied to a terminal device, and the key generation method includes steps 1001-1005.
[0318] Step 1001: Send a connection request to the base station to establish a communication connection with the base station.
[0319] The connection request generated by the terminal device contains its own identification information. After the terminal device sends the connection request to the base station, it waits for the base station to provide feedback on whether the current time slot corresponds to itself based on the preset time slot allocation rules. If the base station confirms that the current time slot belongs to the terminal device, the terminal device will complete the establishment of a communication connection with the base station. By initiating a connection in accordance with the base station's preset time slot allocation rules, it can cooperate with the base station to achieve orderly access of at least one terminal device and avoid channel conflicts caused by simultaneous connection initiation.
[0320] Step 1002: Receive the data frame sent by the base station and send an acknowledgment frame to the base station.
[0321] The terminal device receives data frames sent by the base station through the established communication connection. After confirming that the data frame has been received correctly, the terminal device generates an acknowledgment frame. The preamble of the acknowledgment frame is located at the beginning of the frame and contains a preset number of subcarriers (the subcarriers are the carriers of channel information). The terminal device sends the acknowledgment frame to the base station to provide feedback on the reception status.
[0322] Sending an acknowledgment frame containing subcarriers can help the base station complete channel detection without the need to send additional channel acknowledgment frames, thus ensuring communication efficiency.
[0323] Step 1003: Perform channel probing based on a preset number of subcarriers in the preamble of the data frame to obtain channel state information.
[0324] The terminal device selects a preset number of subcarriers from the preamble of the received data frame (the preset number is pre-configured by the terminal device), and analyzes the channel transmission characteristics from the terminal device to the base station by detecting the signal amplitude, phase and other information of the preset number of subcarriers, and obtains channel state information containing the transmission characteristics of each subcarrier.
[0325] Step 1004: Extract channel features from the channel state information to obtain channel features corresponding to the base station, and perform quantization conversion and equalization processing on the channel features to generate the original bit sequence.
[0326] The terminal device extracts channel features from the channel state information, extracting features that reflect the inherent characteristics of the channel; it quantizes the channel features, converting continuous values of the channel features into discrete binary bits using preset quantization rules to form quantization patterns; it then performs equalization processing on the quantization patterns, reducing the frequency of some quantization patterns when they occur frequently, so that the distribution of each quantization pattern is uniform, and finally generates the original bit sequence.
[0327] The extracted channel features can reflect the unique channel characteristics of the terminal equipment and the base station. Quantization conversion and equalization processing then transform these features into a raw bit sequence that can be used for key generation.
[0328] Step 1005: Correct the original bit sequence and encrypt the corrected bit sequence to determine the second target key.
[0329] The terminal device performs correction processing on the original bit sequence. By comparing the redundant check bits in the original bit sequence, it identifies and corrects erroneous bits in the sequence to ensure the accuracy of the original bit sequence. The corrected bit sequence is then encrypted, and the sequence is transformed through a preset processing method to enhance the confidentiality of the sequence. Finally, a second target key corresponding to the first target key on the base station side is obtained.
[0330] Correction processing can eliminate errors in the original bit sequence, while encryption processing enhances the sequence's resistance to cracking, ensuring that the determined second target key can meet the communication encryption requirements.
[0331] In summary, the key generation method provided in this disclosure includes: sending a connection request to a base station to establish a communication connection with the base station; receiving a data frame sent by the base station and sending an acknowledgment frame to the base station; performing channel probing based on a preset number of subcarriers in the preamble of the data frame to obtain channel state information; extracting channel features from the channel state information to obtain channel features corresponding to the base station, and performing quantization conversion and equalization processing on the channel features to generate an original bit sequence; correcting the original bit sequence and encrypting the corrected bit sequence to determine the second target key. This method eliminates the need for each terminal device to exclusively occupy the communication channel bandwidth, enabling at least one terminal device to share the channel to reduce resource waste, supports parallel generation to improve efficiency, and thus adapts to the concurrent requirements of at least one terminal device, meeting the practical scenario of quantum key wireless distribution for at least one terminal device in a wireless local area network.
[0332] Figure 14 A flowchart illustrating a key generation method provided in an embodiment of this disclosure is further illustrated. Based on Figure 13 The illustrated embodiment further explains step 1001. Figure 14 This may include the following steps:
[0333] Step 1101: Based on the connection request, determine whether to receive the current time slice allocated by the base station.
[0334] Step 1102: If it is determined that the current time slice allocated by the base station has been received, then a channel reservation with the base station is received to establish a communication connection.
[0335] Explanation of steps 1101-1102 and Figure 2 The embodiments described above differ only in their application subjects; the other implementation principles are the same, therefore they can be used as a reference. Figure 2 The detailed descriptions in the embodiments disclosed herein will not be repeated here.
[0336] Figure 15 A flowchart illustrating a key generation method provided in an embodiment of this disclosure is further illustrated. Based on Figure 14 The illustrated embodiment further explains step 1101. Figure 15 This may include the following steps:
[0337] Step 1201: Determine whether the identifier corresponding to the connection request is consistent with the identifier corresponding to the current time slice.
[0338] Step 1202: If the identifier corresponding to the connection request is consistent with the identifier corresponding to the current time slice, then obtain the current time slice and receive the IP address sent by the base station.
[0339] Explanation of steps 1201-1202 and Figure 3 The embodiments described herein differ in their application subjects, but the other implementation principles are the same; therefore, they can be referred to. Figure 3 The detailed descriptions in the embodiments disclosed herein will not be repeated here.
[0340] Figure 16 A flowchart illustrating a key generation method provided in an embodiment of this disclosure is further illustrated. Based on Figure 14 The illustrated embodiment further explains step 1102. Figure 16 This may include the following steps:
[0341] Step 1301: In response to waiting for the distributed inter-frame interval, receive the channel reservation information sent by the base station.
[0342] Step 1302: Send reservation permission information to the base station.
[0343] Step 1303: Based on the channel reservation information and the reservation permission information, complete the channel reservation with the base station to establish a communication connection.
[0344] Explanation of steps 1301-1303 and Figure 5 The embodiments described herein differ in their application subjects, but the other implementation principles are the same; therefore, they can be referred to. Figure 5 The detailed descriptions in the embodiments disclosed herein will not be repeated here.
[0345] Figure 17 A flowchart illustrating a key generation method provided in an embodiment of this disclosure is further illustrated. Based on Figure 16 The illustrated embodiment further explains step 1002. Figure 17 This may include the following steps:
[0346] Step 1401: Receive the data frame sent by the base station and wait for the short inter-frame interval; wherein the short inter-frame interval is less than the distributed inter-frame interval.
[0347] Step 1402: After a short inter-frame interval, send the confirmation frame to the base station.
[0348] Explanation of steps 1401-1402 and Figure 7 The embodiments described above differ only in their application subjects; the other implementation principles are the same, therefore they can be used as a reference. Figure 7 The detailed descriptions in the embodiments disclosed herein will not be repeated here.
[0349] Figure 18 A flowchart illustrating a key generation method provided in an embodiment of this disclosure is further illustrated. Based on Figure 13The illustrated embodiment further explains step 1003. Figure 18 This may include the following steps:
[0350] Step 1501: Obtain a preset number of subcarriers in the preamble of the data frame.
[0351] The preamble of a data frame consists of a preset number of subcarriers, which are distributed at preset intervals. The preset number of subcarriers are used to carry signals required for synchronization and channel estimation. After receiving the data frame, the terminal device parses the data frame to locate the start and end positions of the preamble, and then extracts the preset number of subcarriers from the preamble according to preset selection rules.
[0352] Step 1502: Based on a preset number of subcarriers, perform channel estimation on the preset number of subcarriers to obtain the downlink channel state information.
[0353] The preset subcarrier is a reference subcarrier used by the terminal device for channel estimation. The channel characteristics (such as amplitude and phase) of the preset subcarrier are stored in advance. The terminal device compares the actual received signals of the preset number of subcarriers with the reference signals of the preset subcarriers, calculates the differences between the two, such as amplitude attenuation and phase offset, and generates downlink channel state information based on the evaluation results by evaluating the channel transmission characteristics from the base station to the terminal device.
[0354] In some embodiments, the wireless local area network protocol specifies that each frame of signal has a preamble, which is determined by the physical layer frame format. The terminal device uses the preamble of the i-th received DATA frame to contain a preset number of subcarriers for channel estimation, and obtains the downlink channel state information CSI_STAi on the corresponding preset number of subcarriers, as shown in Equation 7.
[0355] CSI_STAi={CSI_APi(1),CSI_APi(2),...,CSI_APi(j),...,CSI_APi(n)} Formula 7
[0356] Where CSI_STAi represents downlink channel state information, j represents downlink channel state information corresponding to the j-th subcarrier, and n represents downlink channel state information corresponding to the n-th subcarrier.
[0357] Figure 19 A flowchart illustrating a key generation method provided in an embodiment of this disclosure is further illustrated. For example... Figure 19 As shown, Figure 19 This may include the following steps:
[0358] Step 1601: Perform amplitude and phase processing on the downlink channel state information to obtain the channel features corresponding to the base station.
[0359] Downlink channel state information includes amplitude and phase information that reflect the channel transmission characteristics. Amplitude processing is used to process the amplitude information to extract stable amplitude features; phase processing is used to process the phase information to remove fluctuations caused by noise or interference and obtain reliable phase features. By combining the results of amplitude processing and phase processing, a channel feature that can identify the channel characteristics between the terminal device and the base station is formed.
[0360] Step 1602: Perform absolute value processing on the downlink channel state information, and normalize the result of the absolute value processing to obtain the downlink channel amplitude characteristics.
[0361] The amplitude information in the downlink channel state information may contain positive and negative values. Absolute value processing can convert them into non-negative values to eliminate the influence of symbols on key generation. After absolute value processing, the obtained values are normalized to obtain the downlink channel amplitude characteristics. The normalization process is shown in Formula 8.
[0362]
[0363] Among them, |CSI_STA i (n)| represents the absolute value of the amplitude of the downlink channel state information of the nth subcarrier for the i-th terminal device. The downlink channel state information of all n subcarriers of the i-th terminal device is normalized.
[0364] Step 1603: Calculate the phase information of the downlink channel state information, and perform smoothing and centering processing on the phase information to obtain the downlink channel phase characteristics.
[0365] The phase information of the downlink channel state information is calculated by processing the imaginary and real parts of the downlink channel state information and then taking the arctangent function of the result of the imaginary and real part processing to obtain the phase information. Since the interval of the arctangent function is (-π, π), the calculated actual phase information will be folded in the range of (-π, π). Therefore, phase expansion processing is required to generate smoother phase information.
[0366] The phase information is calculated as shown in Formulas 9 and 10.
[0367] θ_STA i ={θ_STA i (1),θ_STA i (2)..,θSTA i (j)..,θ_STA i (n} Formula 9
[0368]
[0369] Where θ_STA i CSI_STA is the set of phase information for the i-th terminal device, containing n phase information pieces (corresponding to n subcarriers), used to describe the phase distribution of the channel on different subcarriers. i (j) represents the channel state information of the i-th terminal device and the j-th subcarrier, real() and imag() represent the real part extraction and imaginary part extraction processes respectively, and arctan() represents the arctangent function.
[0370] Specifically, For the j-th phase information of the i-th terminal device, the phase expansion processing on the terminal device side is as follows:
[0371] make
[0372] Starting from the second subcarrier (j=2), calculate the phase difference θ_STA between the current subcarrier and the previous subcarrier sequentially. i (j)-θ_STA i (j-1);
[0373] If the phase difference θ_STA i (j)-θ_STA i If (j-1) is greater than π, then the current subcarrier phase will be... The phase of each subsequent subcarrier is reduced by 2π.
[0374] If the phase difference θ_STA i (j)-θ_STA i If (j-1) is less than -π, then the current subcarrier phase will be... And add 2π to the phase of each subsequent subcarrier;
[0375] For the phase of the expansion Centralized processing is performed to remove fixed phase deviations caused by terminal devices, in order to obtain the downlink channel phase characteristics CSI_Phase_STA. i The centralized processing is shown in Formulas 11 and 12.
[0376]
[0377] Among them, CSI_Phase_STA i CSI_Phase_STA represents the downlink channel phase characteristics of the i-th terminal device. i (j) represents the downlink channel phase characteristics of the j-th subcarrier of the i-th terminal device. For the i-th terminal device and the j-th subcarrier, To calculate the average phase of all subcarriers.
[0378] Step 1604: Determine the channel characteristics corresponding to the base station based on the downlink channel amplitude characteristics and the downlink channel phase characteristics.
[0379] The downlink channel amplitude characteristics and downlink channel phase characteristics are combined in a one-to-one correspondence with the subcarrier numbers to form the channel characteristics of each subcarrier.
[0380] Figure 20 A flowchart illustrating a key generation method provided in an embodiment of this disclosure is further illustrated. Based on Figure 19 The illustrated embodiment further explains step 1004. Figure 20 This may include the following steps:
[0381] Step 1701: Quantize the channel features to obtain at least one quantization mode.
[0382] Step 1702: Calculate the number of occurrences of the at least one quantization pattern.
[0383] Step 1703: If the occurrence count exceeds a preset threshold, perform equalization processing on the at least one quantization mode to obtain the original bit sequence.
[0384] Explanation of steps 1701-1703 and Figure 10 The embodiments described above differ only in their application subjects; the other implementation principles are the same, therefore they can be used as a reference. Figure 10 The detailed descriptions in the embodiments disclosed herein will not be repeated here.
[0385] Figure 21 A flowchart illustrating a key generation method provided in an embodiment of this disclosure is further illustrated. Based on Figure 13 The embodiment shown, Figure 21 This may include the following steps:
[0386] Step 1801: Perform information coordination processing on the original bit sequence to obtain the corrected bit sequence.
[0387] Step 1802: Invoke the privacy amplification algorithm to encrypt the corrected bit sequence to obtain the second target key.
[0388] Step 1803: Based on the equipment information of the base station, store the second target key respectively.
[0389] Explanation of steps 1801-1803 and Figure 11 The embodiments described above differ only in their application subjects; the other implementation principles are the same, therefore they can be used as a reference.Figure 11 The detailed descriptions in the embodiments disclosed herein will not be repeated here.
[0390] As an extension of the embodiments of this disclosure, in order to facilitate a better understanding of the interaction between the base station and the terminal device, such as Figure 22 As shown, Figure 22 A schematic diagram illustrating the interaction process between a base station and a terminal device provided in this disclosure embodiment includes:
[0391] Step 2201: The terminal device generates a connection request and sends the connection request to the base station;
[0392] Step 2202: The base station receives the connection request sent by the terminal device and determines whether the current time slice corresponds to the terminal device based on the preset time slot allocation rules.
[0393] Step 2203: When the base station determines that the current time slice corresponds to the terminal device, it sends a connection response to the terminal device and performs channel reservation with the terminal device.
[0394] Step 2204: The terminal device receives the connection response sent by the base station, completes the channel reservation, and establishes a communication connection with the base station;
[0395] Step 2205: The base station sends a data frame to the terminal device;
[0396] Step 2206: The terminal device receives the data frame sent by the base station, obtains a preset number of subcarriers from the preamble of the received data frame, performs channel estimation based on the preset subcarriers, and obtains downlink channel state information.
[0397] Step 2207: The base station receives the acknowledgment frame sent by the terminal device, obtains a preset number of subcarriers from the preamble of the acknowledgment frame, performs channel estimation based on the preset subcarriers, and obtains uplink channel state information.
[0398] Step 2208: The base station performs channel feature extraction, quantization conversion and equalization processing on the uplink channel state information to generate the original bit sequence, and performs correction and encryption processing on the generated original bit sequence to determine the first target key;
[0399] Step 2209: The terminal device performs channel feature extraction, quantization conversion and equalization processing on the downlink channel state information to generate the original bit sequence, and performs correction and encryption processing on the generated original bit sequence to determine the second target key;
[0400] Step 2210: The base station stores the first target key based on the identification information of the terminal device;
[0401] Step 2211: The terminal device stores the second target key based on the identification information of the base station;
[0402] Step 2212: The base station and the terminal device perform key synchronization verification through their respective stored identification information to confirm that the first target key and the second target key correspond to each other, thus completing the key generation interaction process.
[0403] Figure 23 This is a schematic diagram of a key generation apparatus provided in an embodiment of the present disclosure, as shown below. Figure 23 As shown, the device is applied to a base station and includes:
[0404] The first establishment unit 51 is used to establish a communication connection with the terminal device in response to the terminal device initiating a connection request, and to send a data frame to the terminal device.
[0405] The receiving unit 52 is used to receive the confirmation frame sent by the terminal device;
[0406] The first detection unit 53 is used to perform channel detection based on a preset number of subcarriers in the preamble of the confirmation frame to obtain channel state information;
[0407] The first extraction unit 54 is used to extract channel features from the channel state information to obtain channel features corresponding to the terminal device.
[0408] The first processing unit 55 is used to perform quantization conversion and equalization processing on the channel features to generate the original bit sequence;
[0409] The first determining unit 56 is used to correct the original bit sequence and encrypt the corrected bit sequence to determine the first target key.
[0410] In summary, the key generation apparatus provided in this disclosure includes: responding to a connection request initiated by a terminal device, establishing a communication connection with the terminal device, sending a data frame to the terminal device, receiving an acknowledgment frame sent by the terminal device, performing channel probing based on a preset number of subcarriers in the preamble of the acknowledgment frame to obtain channel state information, extracting channel features from the channel state information to obtain channel features corresponding to the terminal device, performing quantization conversion and equalization processing on the channel features to generate an original bit sequence, correcting the original bit sequence, encrypting the corrected bit sequence, and determining a first target key. This eliminates the need for each terminal device to exclusively occupy the communication channel bandwidth, enabling at least one terminal device to share the channel to reduce resource waste, supporting parallel generation to improve efficiency, and thus adapting to the concurrent requirements of at least one terminal device, meeting the practical scenario of quantum key wireless distribution for at least one terminal device in a wireless local area network.
[0411] Furthermore, in one possible implementation of the embodiments of this disclosure, such as Figure 24As shown, the first establishment unit 51 includes:
[0412] The first judgment module 511 is used to determine, based on the connection request, whether the current time slice is allocated to the terminal device;
[0413] The first initiating module 512 is used to initiate a handshake with the terminal device to establish a communication connection when it is determined that the terminal device will be assigned to it.
[0414] Furthermore, in one possible implementation of the embodiments of this disclosure, such as Figure 24 As shown, the first judgment module 511 includes:
[0415] The first judgment submodule 5111 is used to determine whether the terminal device identifier in the connection request is consistent with the terminal device identifier corresponding to the current time slice, based on the terminal device information of the terminal device, the collected IP address and the preset time slot allocation rules.
[0416] The first allocation submodule 5112 is used to allocate the current time slice to the terminal device and assign an IP address to the terminal device when the terminal device identifier is consistent with the terminal device identifier corresponding to the current time slice.
[0417] Furthermore, in one possible implementation of the embodiments of this disclosure, such as Figure 24 As shown, the first initiating module 512 includes:
[0418] The first transmitting submodule 5121 is used to detect that the channel is idle and, after waiting for the distributed inter-frame interval, transmit channel reservation information.
[0419] The first receiving submodule 5122 is configured to respond to receiving reservation permission information sent by the terminal device;
[0420] The first connection submodule 5123 is used to complete the channel reservation with the terminal device to establish a communication connection based on the channel reservation information and the reservation permission information.
[0421] Furthermore, in one possible implementation of the embodiments of this disclosure, such as Figure 24 As shown, the receiving unit 52 includes:
[0422] The first sending module 521 is used to send the data frame to the terminal device and wait for a short inter-frame interval; wherein the short inter-frame interval is smaller than the distributed inter-frame interval.
[0423] The first receiving module 522 is used to receive the confirmation frame sent by the terminal device after a short frame interval.
[0424] Furthermore, in one possible implementation of the embodiments of this disclosure, such as Figure 24 As shown, the channel state information is uplink channel state information;
[0425] The first detection unit 53 includes:
[0426] The first acquisition module 531 is used to acquire a preset number of subcarriers in the preamble of the confirmation frame;
[0427] The first estimation module 532 is used to perform channel estimation on a preset number of subcarriers based on a preset subcarrier to obtain the uplink channel state information.
[0428] Furthermore, in one possible implementation of the embodiments of this disclosure, such as Figure 24 As shown, the first extraction unit 54 is further configured to perform amplitude and phase processing on the uplink channel state information to obtain channel features corresponding to the terminal device.
[0429] Furthermore, in one possible implementation of the embodiments of this disclosure, such as Figure 24 As shown, the first extraction unit 54 includes:
[0430] The first processing module 541 is used to perform absolute value processing on the uplink channel state information and normalize the result of the absolute value processing to obtain the uplink channel amplitude characteristics.
[0431] The second processing module 542 is used to calculate the phase information of the uplink channel state information, and to perform smoothing and centering processing on the phase information to obtain the uplink channel phase characteristics.
[0432] The first determining module 543 is used to determine the channel characteristics corresponding to the terminal device based on the uplink channel amplitude characteristics and the uplink channel phase characteristics.
[0433] Furthermore, in one possible implementation of the embodiments of this disclosure, such as Figure 24 As shown, the first processing unit 55 includes:
[0434] The first conversion module 551 is used to perform quantization conversion on the channel features to obtain at least one quantization mode;
[0435] The first calculation module 552 is used to calculate the number of occurrences of the at least one quantization pattern;
[0436] The second determining module 553 is used to perform equalization processing on the at least one quantization mode to obtain the original bit sequence when it is determined that the occurrence frequency exceeds a preset threshold.
[0437] Furthermore, in one possible implementation of the embodiments of this disclosure, such as Figure 24 As shown, the first determining unit 56 includes:
[0438] The third processing module 561 is used to perform information coordination processing on the original bit sequence to obtain the corrected bit sequence;
[0439] The fourth processing module 562 is used to call the privacy amplification algorithm to encrypt the corrected bit sequence to obtain the first target key.
[0440] Furthermore, in one possible implementation of the embodiments of this disclosure, such as Figure 24 As shown, the device further includes:
[0441] The first storage unit 57 is used to store the first target key based on the device information of the terminal device after the first determining unit 56 encrypts the corrected bit sequence and determines the first target key.
[0442] Figure 25 This is a schematic diagram of a key generation apparatus provided in an embodiment of the present disclosure, as shown below. Figure 25 As shown, the device is applied to a terminal device and includes:
[0443] The second establishment unit 61 is used to send a connection request to the base station and establish a communication connection with the base station;
[0444] The transmitting unit 62 is used to receive data frames sent by the base station and send acknowledgment frames to the base station;
[0445] The second detection unit 63 is used to perform channel detection based on a preset number of subcarriers in the preamble of the data frame to obtain channel state information;
[0446] The second extraction unit 64 is used to extract channel features from the channel state information to obtain channel features corresponding to the base station.
[0447] The second processing unit 65 is used to perform quantization conversion and equalization processing on the channel features to generate the original bit sequence.
[0448] The second determining unit 66 is used to correct the original bit sequence and encrypt the corrected bit sequence to determine the second target key.
[0449] Furthermore, in one possible implementation of the embodiments of this disclosure, such as Figure 26 As shown, the second establishing unit 61 includes:
[0450] The second judgment module 611 is used to determine, based on the connection request, whether to receive the current time slice allocated by the base station;
[0451] The second initiating module 612 is used to establish a communication connection with the base station by handshaking when it is determined that the current time slice allocated by the base station has been received.
[0452] Furthermore, in one possible implementation of the embodiments of this disclosure, such as Figure 26 As shown, the second judgment module 611 includes:
[0453] The second judgment submodule 6111 is used to determine whether the identifier corresponding to the connection request is consistent with the identifier corresponding to the current time slice;
[0454] The second receiving submodule 6112 is used to obtain the current time slice and receive the IP address sent by the base station when the identifier corresponding to the connection request is consistent with the identifier corresponding to the current time slice.
[0455] Furthermore, in one possible implementation of the embodiments of this disclosure, such as Figure 26 As shown, the second initiating module 612 includes:
[0456] The third receiving submodule 6121 is used to receive channel reservation information sent by the base station in response to waiting for the distributed inter-frame interval;
[0457] The second sending submodule 6122 is used to send reservation permission information to the base station;
[0458] The second connection submodule 6123 is used to complete the channel reservation with the base station to establish a communication connection based on the channel reservation information and the reservation permission information.
[0459] Furthermore, in one possible implementation of the embodiments of this disclosure, such as Figure 26 As shown, the transmitting unit 62 includes:
[0460] The second receiving module 621 is used to receive the data frame sent by the base station and wait for the short inter-frame interval; wherein the short inter-frame interval is smaller than the distributed inter-frame interval;
[0461] The second sending module 622 is used to send the acknowledgment frame to the base station after a short inter-frame interval.
[0462] Furthermore, in one possible implementation of the embodiments of this disclosure, such as Figure 26 As shown, the channel state information is downlink channel state information;
[0463] The second detection unit 63 includes:
[0464] The second acquisition module 631 is used to acquire a preset number of subcarriers in the preamble of the data frame;
[0465] The second estimation module 632 is used to perform channel estimation on the preset number of subcarriers based on the preset subcarriers to obtain the downlink channel state information.
[0466] Furthermore, in one possible implementation of the embodiments of this disclosure, such as Figure 26 As shown, the second extraction unit 64 is also used to perform amplitude processing and phase processing on the downlink channel state information to obtain channel features corresponding to the base station.
[0467] Furthermore, in one possible implementation of the embodiments of this disclosure, such as Figure 26 As shown, the second extraction unit 64 includes:
[0468] The fifth processing module 641 is used to perform absolute value processing on the downlink channel state information and normalize the result of the absolute value processing to obtain the downlink channel amplitude characteristics.
[0469] The sixth processing module 642 is used to calculate the phase information of the downlink channel state information, and to perform smoothing and centering processing on the phase information to obtain the downlink channel phase characteristics;
[0470] The third determining module 643 is used to determine the channel characteristics corresponding to the base station based on the downlink channel amplitude characteristics and the downlink channel phase characteristics.
[0471] Furthermore, in one possible implementation of the embodiments of this disclosure, such as Figure 26 As shown, the second processing unit 65 includes:
[0472] The second conversion module 651 is used to perform quantization conversion on the channel features to obtain at least one quantization mode;
[0473] The second calculation module 652 is used to calculate the number of occurrences of the at least one quantization pattern;
[0474] The fourth determining module 653 is used to perform equalization processing on the at least one quantization mode to obtain the original bit sequence when it is determined that the occurrence frequency exceeds a preset threshold.
[0475] Furthermore, in one possible implementation of the embodiments of this disclosure, such as Figure 26 As shown, the second determining unit 66 includes:
[0476] The seventh processing module 661 is used to perform information coordination processing on the original bit sequence to obtain the corrected bit sequence;
[0477] The eighth processing module 662 is used to call the privacy amplification algorithm to encrypt the corrected bit sequence to obtain the second target key.
[0478] Furthermore, in one possible implementation of the embodiments of this disclosure, such as Figure 26 As shown, the device further includes:
[0479] The second storage unit 67 is used to store the second target key based on the equipment information of the base station after the second determining unit 66 encrypts the corrected bit sequence and determines the second target key.
[0480] It should be noted that the foregoing explanation of the method embodiments also applies to the apparatus of the embodiments of this disclosure, and the principle is the same. Therefore, the embodiments of this disclosure are not limited thereto.
[0481] Figure 27 This is a schematic diagram of a key generation system provided in an embodiment of the present disclosure. The system includes a base station 71 and at least one terminal device 72.
[0482] The base station 71 includes, for example: Figure 23 The aforementioned key generation device;
[0483] The terminal device 72 includes, for example: Figure 25 The aforementioned key generation device.
[0484] According to embodiments of this disclosure, this disclosure also provides an electronic device, a readable storage medium, and a computer program product.
[0485] Figure 28 A schematic block diagram of an example electronic device 600 that can be used to implement embodiments of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present disclosure described and / or claimed herein.
[0486] like Figure 28As shown, the electronic device 600 includes a computing unit 601, which can perform various appropriate actions and processes based on a computer program stored in ROM (Read-Only Memory) 602 or a computer program loaded from storage unit 608 into RAM (Random Access Memory) 603. The RAM 603 can also store various programs and data required for the operation of the electronic device 600. The computing unit 601, ROM 602, and RAM 603 are interconnected via a bus 604. An I / O (Input / Output) interface 605 is also connected to the bus 604.
[0487] Multiple components in electronic device 600 are connected to I / O interface 605, including: input unit 606, such as keyboard, mouse, etc.; output unit 607, such as various types of displays, speakers, etc.; storage unit 608, such as disk, optical disk, etc.; and communication unit 609, such as network card, modem, wireless transceiver, etc. Communication unit 609 allows electronic device 600 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0488] The computing unit 601 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 601 include, but are not limited to, CPUs (Central Processing Units), GPUs (Graphics Processing Units), various special-purpose AI (Artificial Intelligence) computing chips, various computing units running machine learning model algorithms, DSPs (Digital Signal Processors), and any suitable processor, controller, microcontroller, etc. The computing unit 601 performs the various methods and processes described above, such as key generation methods. For example, in some embodiments, the key generation method may be implemented as a computer software program tangibly contained in a machine-readable medium, such as storage unit 608. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 600 via ROM 602 and / or communication unit 609. When the computer program is loaded into RAM 603 and executed by the computing unit 601, one or more steps of the methods described above may be performed. Alternatively, in other embodiments, the computing unit 601 may be configured to perform the aforementioned key generation method by any other suitable means (e.g., by means of firmware).
[0489] Various implementations of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, FPGAs (Field Programmable Gate Arrays), ASICs (Application-Specific Integrated Circuits), ASSPs (Application-Specific Standard Products), SOCs (System-on-Chips), CPLDs (Complex Programmable Logic Devices), computer hardware, firmware, software, and / or combinations thereof. These various implementations may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0490] The program code used to implement the methods of this disclosure may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, such that when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0491] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, RAM, ROM, EPROM (Electrically Programmable Read-Only Memory) or flash memory, optical fiber, CD-ROM (Compact Disc Read-Only Memory), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0492] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a CRT (Cathode-Ray Tube) or LCD (Liquid Crystal Display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the computer. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0493] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication (e.g., communication networks) of any form or medium. Examples of communication networks include LANs (Local Area Networks), WANs (Wide Area Networks), the Internet, and blockchain networks.
[0494] Computer systems can include clients and servers. Clients and servers are generally geographically separated and typically interact via communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. A server can be a cloud server, also known as a cloud computing server or cloud host, a hosting product within the cloud computing service ecosystem, addressing the shortcomings of traditional physical hosts and VPS (Virtual Private Server, or simply "VPS") services, such as high management difficulty and weak business scalability. Servers can also be servers for distributed systems or servers incorporating blockchain technology.
[0495] It's important to note that artificial intelligence (AI) is the study of enabling computers to simulate certain human thought processes and intelligent behaviors (such as learning, reasoning, thinking, and planning). It encompasses both hardware and software technologies. AI hardware technologies generally include sensors, dedicated AI chips, cloud computing, distributed storage, and big data processing. AI software technologies primarily include computer vision, speech recognition, natural language processing, machine learning / deep learning, big data processing, and knowledge graph technologies.
[0496] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this disclosure can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution disclosed in this disclosure can be achieved, and this is not limited herein.
[0497] The specific embodiments described above do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.
Claims
1. A method for generating a key, characterized in that, The method is applied to a base station, where different terminal devices occupy different time slices to establish communication connections with the base station, including: In response to a connection request initiated by a terminal device, a communication connection is established with the terminal device, and a data frame is sent to the terminal device; Upon receiving the acknowledgment frame sent by the terminal device, channel probing is performed based on a preset number of subcarriers in the preamble of the acknowledgment frame to obtain channel state information; Channel features are extracted from the channel state information to obtain channel features corresponding to the terminal device, and the channel features are quantized and equalized to generate the original bit sequence. The original bit sequence is corrected, and the corrected bit sequence is encrypted to determine the first target key.
2. The method according to claim 1, characterized in that, The step of responding to a connection request initiated by a terminal device and establishing a communication connection with the terminal device includes: Based on the connection request, determine whether the current time slice should be allocated to the terminal device; If it is determined that a channel will be allocated to the terminal device, a channel reservation with the terminal device will be initiated to establish a communication connection.
3. The method according to claim 2, characterized in that, The step of determining whether the current time slice is allocated to the terminal device based on the connection request includes: Based on the terminal device information, the collected IP address, and the preset time slot allocation rules, determine whether the terminal device identifier in the connection request is consistent with the terminal device identifier corresponding to the current time slot. If the terminal device identifier matches the terminal device identifier corresponding to the current time slice, then the current time slice is allocated to the terminal device, and an IP address is assigned to the terminal device.
4. The method according to claim 2, characterized in that, The initiation of a handshake with the terminal device to establish a communication connection includes: If the channel is detected to be idle, after waiting for the distributed inter-frame interval, channel reservation information is sent. In response to receiving the reservation permission information sent by the terminal device; Based on the channel reservation information and the reservation permission information, a channel reservation with the terminal device is completed to establish a communication connection.
5. The method according to claim 4, characterized in that, The receipt of the confirmation frame sent by the terminal device includes: The data frame is sent to the terminal device, and a short inter-frame interval is waited for; wherein the short inter-frame interval is less than the distributed inter-frame interval; After a short inter-frame interval, the confirmation frame sent by the terminal device is received.
6. The method according to claim 1, characterized in that, The channel state information is uplink channel state information; The channel probing is performed based on a preset number of subcarriers in the preamble of the acknowledgment frame to obtain channel state information, including: Obtain a preset number of subcarriers from the preamble of the confirmation frame; Based on a preset number of subcarriers, channel estimation is performed on the preset number of subcarriers to obtain the uplink channel state information.
7. The method according to claim 6, characterized in that, The step of extracting channel features from the channel state information to obtain channel features corresponding to the terminal device includes: The uplink channel state information is subjected to amplitude and phase processing to obtain the channel characteristics corresponding to the terminal device.
8. The method according to claim 7, characterized in that, The step of performing amplitude and phase processing on the uplink channel state information to obtain the channel characteristics corresponding to the terminal device includes: The uplink channel state information is processed by absolute value, and the result of the absolute value processing is normalized to obtain the uplink channel amplitude characteristics. Calculate the phase information of the uplink channel state information, and perform smoothing and centering processing on the phase information to obtain the uplink channel phase characteristics; Based on the uplink channel amplitude characteristics and the uplink channel phase characteristics, the channel characteristics corresponding to the terminal device are determined.
9. The method according to claim 8, characterized in that, The step of quantizing and equalizing the channel features to generate the original bit sequence includes: The channel features are quantized to obtain at least one quantization mode; Calculate the number of occurrences of the at least one quantization pattern; If the occurrence frequency exceeds a preset threshold, the at least one quantization mode is subjected to equalization processing to obtain the original bit sequence.
10. The method according to claim 1, characterized in that, The step of correcting the original bit sequence and encrypting the corrected bit sequence to determine the first target key includes: The original bit sequence is subjected to information coordination processing to obtain the corrected bit sequence; The privacy amplification algorithm is invoked to encrypt the corrected bit sequence, thereby obtaining the first target key.
11. The method according to claim 1, characterized in that, After encrypting the corrected bit sequence and determining the first target key, the method further includes: Based on the device information of the terminal device, the first target key is stored respectively.
12. A method for generating a key, characterized in that, The method is applied to terminal devices, where different terminal devices occupy different time slices to establish communication connections with the base station, including: Send a connection request to the base station to establish a communication connection with the base station; Receive data frames sent by the base station and send acknowledgment frames to the base station; Channel detection is performed based on a preset number of subcarriers in the preamble of the data frame to obtain channel state information; Channel features are extracted from the channel state information to obtain the channel features corresponding to the base station, and the channel features are quantized and equalized to generate the original bit sequence. The original bit sequence is corrected, and the corrected bit sequence is encrypted to determine the second target key.
13. The method according to claim 12, characterized in that, Sending a connection request to the base station to establish a communication connection with the base station includes: Based on the connection request, determine whether to accept the current time slice allocated by the base station; If it is determined that the current time slice allocated by the base station has been received, then a channel reservation with the base station is received to establish a communication connection.
14. The method according to claim 13, characterized in that, The step of determining whether to receive the current time slice allocated by the base station based on the connection request includes: Determine whether the identifier in the connection request is consistent with the identifier in the current time slice; If the identifier in the connection request matches the identifier in the current time slice, then the current time slice is obtained, and the IP address sent by the base station is received.
15. The method according to claim 13, characterized in that, The handshake with the base station to establish a communication connection includes: In response to waiting for the distributed inter-frame interval, the system receives channel reservation information sent by the base station. Send reservation permission information to the base station; Based on the channel reservation information and the reservation permission information, a channel reservation with the base station is completed to establish a communication connection.
16. The method according to claim 15, characterized in that, The step of receiving data frames sent by the base station and sending acknowledgment frames to the base station includes: Receive the data frame sent by the base station and wait for the short inter-frame interval; wherein the short inter-frame interval is less than the distributed inter-frame interval; After a short inter-frame interval, the acknowledgment frame is sent to the base station.
17. The method according to claim 12, characterized in that, The channel state information is downlink channel state information; The channel probing is performed based on a preset number of subcarriers in the preamble of the data frame to obtain channel state information, including: Obtain a preset number of subcarriers from the preamble of the data frame; Based on a preset number of subcarriers, channel estimation is performed on the preset number of subcarriers to obtain the downlink channel state information.
18. The method according to claim 17, characterized in that, The step of extracting channel features from the channel state information to obtain channel features corresponding to the base station includes: The downlink channel state information is subjected to amplitude and phase processing to obtain the channel characteristics corresponding to the base station.
19. The method according to claim 18, characterized in that, The step of performing amplitude and phase processing on the downlink channel state information to obtain channel features corresponding to the base station includes: The downlink channel state information is processed by absolute value, and the result of the absolute value processing is normalized to obtain the downlink channel amplitude characteristics. Calculate the phase information of the downlink channel state information, and perform smoothing and centering processing on the phase information to obtain the downlink channel phase characteristics; Based on the downlink channel amplitude characteristics and the downlink channel phase characteristics, the channel characteristics corresponding to the base station are determined.
20. The method according to claim 19, characterized in that, The step of quantizing and equalizing the channel features to generate the original bit sequence includes: The channel features are quantized to obtain at least one quantization mode; Calculate the number of occurrences of the at least one quantization pattern; If the occurrence frequency exceeds a preset threshold, the at least one quantization mode is subjected to equalization processing to obtain the original bit sequence.
21. The method according to claim 12, characterized in that, The step of correcting the original bit sequence and encrypting the corrected bit sequence to determine the second target key includes: The original bit sequence is subjected to information coordination processing to obtain the corrected bit sequence; The privacy amplification algorithm is invoked to encrypt the corrected bit sequence, thereby obtaining the second target key.
22. The method according to claim 12, characterized in that, After encrypting the corrected bit sequence and determining the second target key, the method further includes: Based on the equipment information of the base station, the second target key is stored respectively.
23. A key generation apparatus, characterized in that, The device is used in a base station, where different terminal devices occupy different time slots to establish communication connections with the base station, including: The first establishment unit is configured to establish a communication connection with the terminal device in response to a connection request initiated by the terminal device, and send a data frame to the terminal device. A receiving unit is configured to receive an acknowledgment frame sent by the terminal device; The first detection unit is used to perform channel detection based on a preset number of subcarriers in the preamble of the confirmation frame to obtain channel state information; The first extraction unit is used to extract channel features from the channel state information to obtain channel features corresponding to the terminal device. The first processing unit is used to perform quantization conversion and equalization processing on the channel features to generate the original bit sequence; The first determining unit is used to correct the original bit sequence and encrypt the corrected bit sequence to determine the first target key.
24. A key generation apparatus, characterized in that, The device is applied to terminal equipment, with different terminal equipment occupying different time slots to establish communication connections with the base station, including: The second establishment unit is used to send a connection request to the base station and establish a communication connection with the base station; The transmitting unit is configured to receive data frames transmitted by the base station and send acknowledgment frames to the base station. The second detection unit is used to perform channel detection based on a preset number of subcarriers in the preamble of the data frame to obtain channel state information. The second extraction unit is used to extract channel features from the channel state information to obtain channel features corresponding to the base station; The second processing unit is used to perform quantization conversion and equalization processing on the channel features to generate the original bit sequence; The second determining unit is used to correct the original bit sequence and encrypt the corrected bit sequence to determine the second target key.
25. A key generation system, characterized in that, The system includes a base station and at least one terminal device, wherein... The base station includes the key generation apparatus as described in claim 23; The terminal device includes the key generation apparatus as described in claim 24.
26. An electronic device, characterized in that, include: At least one processor; as well as A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method of any one of claims 1-11 or 12-22.
27. A non-transitory computer-readable storage medium storing computer instructions, characterized in that, The computer instructions are used to cause the computer to perform the method according to any one of claims 1-11 or 12-22.
28. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method according to any one of claims 1-11 or 12-22.