Communication method and device

By adjusting the key verification and generation parameters, the key generation process was optimized, which solved the problem of inconsistent key consistency verification and improved key generation performance and the security of the communication system.

CN121367587APending Publication Date: 2026-01-20HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410981891.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-07-19
Publication Date
2026-01-20

AI Technical Summary

Technical Problem

In the key generation process, existing technologies suffer from inconsistencies in key consistency verification, which leads to a decline in overall key generation performance. Existing methods, such as increasing the power of the reference signal or increasing the number of retransmissions, have failed to effectively address the impact of multiple complex factors.

Method used

Key generation performance can be optimized by adjusting parameters of key verification and generation, such as reducing key verification length, increasing quantization threshold, or reducing the number of quantization bits.

Benefits of technology

It improves the success rate and generation speed of key consistency verification, reduces network transmission overhead, simplifies the communication system architecture, and enhances the security and trustworthiness of the key negotiation process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121367587A_ABST
    Figure CN121367587A_ABST
Patent Text Reader

Abstract

The invention provides a communication method and device, and relates to the field of communication, and the communication method comprises the steps: obtaining first verification information of a first secret key and second verification information of a second secret key, the first verification information and the second verification information being used for determining the consistency of the first secret key and the second secret key; and based on the first verification information and the second verification information, sending first information used for indicating adjustment of parameters of the verification key and / or parameters of the generation key. According to the communication method, the consistency of the first verification information and the second verification information is combined, and the generation performance of the secret key is improved by adjusting the parameters of the verification secret key and / or generating the parameters of the verification secret key.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of communication, in particular to a communication method and device. BACKGROUND

[0002] In a classical channel entropy-based physical layer key generation technology, based on the reciprocity of the channel, the legitimate communication parties can generate consistent keys through their own channel measurement and randomness extraction process without exchanging key information. This consistency is one of the core requirements of the key generation technology. When generating the key, the key is independently generated by the communication parties through channel measurement, randomness extraction, channel quantization, information reconciliation and privacy amplification, etc. To ensure the consistency of the keys of the communication parties, a key verification process needs to be performed, but directly exchanging the keys to verify their consistency may have security risks, so the hash check bits of the exchanged keys (i.e. the one-way mapping of the keys) are usually used for non-direct verification. If the hash check bits are consistent, it is confirmed that the keys are consistent; otherwise, it indicates that there is inconsistency and the current key needs to be discarded.

[0003] In view of the inconsistency problem in key verification, the prior art attempts to improve the channel estimation accuracy by enhancing the transmission power of the reference signal or increasing the number of retransmissions, in order to improve the key consistency. However, this approach ignores the multiple complex factors affecting the key consistency, which may lead to a decrease in the overall key generation performance instead of an increase. SUMMARY

[0004] The present application provides a communication method and device for improving the key generation performance.

[0005] In a first aspect, a communication method is provided, which is applied to a key verification device. The execution subject of the method can be a key verification equipment, or a component or device (such as a processor, a chip, or a chip system, etc.) applied to the key verification equipment, can be a logic module or software capable of realizing all or part of the functions of the key verification equipment, and can also be a device matched with the key verification equipment. The communication method comprises: obtaining first verification information of a first key and second verification information of a second key, the first verification information and the second verification information being used to determine the consistency of the first key and the second key; and based on the first verification information and the second verification information, sending first information used to indicate adjustment of a parameter for verifying the key and / or a parameter for generating the key. Optionally, the parameter for verifying the key comprises a key verification length; and the parameter for generating the key comprises a quantization threshold used for generating the key and / or a quantization bit number used for generating the key.

[0006] In the first aspect, by adjusting the parameter for verifying the key and / or the parameter for generating the key, the generation performance of the key is improved in combination with the consistency of the first verification information and the second verification information.

[0007] In combination with the first aspect, in one design, the first information is used to indicate at least one of: reducing the key verification length, increasing the quantization threshold for generating the key, or reducing the number of quantization bits for generating the key. For example, the first information is sent in a case where the first check information and the second check information are inconsistent. Alternatively, the first information is used to indicate at least one of: increasing the key verification length, reducing the quantization threshold for generating the key, or increasing the number of quantization bits for generating the key. For example, the first information is sent in a case where a proportion of consistent check information in a first set of check information and a second set of check information meets a preset condition. The first set of check information includes the first check information and at least one third check information obtained, and the second set of check information includes the second check information and at least one fourth check information obtained, the third check information and the fourth check information being used to determine consistency of the first key and the second key.

[0008] In this design, the parameter for verifying the key or the parameter for generating the key is changed to improve the performance of generating the key. In one case, if the key check information of the two parties is inconsistent, the key verification length is reduced by reducing the key length, the quantization threshold for generating the key is increased, or the number of quantization bits for generating the key is reduced to improve the consistency of the key check information. In another case, if the proportion of consistent key check information of the two parties is high, the key verification length is increased by increasing the key length, the quantization threshold for generating the key is reduced, or the number of quantization bits for generating the key is increased to reduce the network transmission overhead, thereby comprehensively improving the performance of generating the key.

[0009] In combination with the first aspect, in one design, the method can further include determining an adjustment margin of a parameter according to a difference between a parameter of the first key and a corresponding preset parameter value, the parameter including at least one of: a parameter for verifying the key or a parameter for generating the key; as an alternative implementation, the adjustment margin of the parameter can also be determined according to a difference between a parameter of the second key and a corresponding preset parameter value. The first information is determined according to the first check information, the second check information, and the adjustment margin of the parameter.

[0010] In the design, first, the adjustment margin of each parameter is determined based on the difference between the parameter of the first key (or the second key) and the corresponding preset parameter value, which can determine which parameters can be adjusted based on the adjustment margin of each parameter, and then the first information indicating the adjusted parameters can be finally determined in combination with the adjustment margin of each parameter, the first check information, and the second check information, which can improve the pass rate of the key consistency check when the first information indicates to reduce the key verification length, can improve the key generation rate when the first information indicates to reduce the quantization threshold for generating the key and / or increase the quantization bit number for generating the key, and can reduce the air interface overhead for performing the key consistency check when the first information indicates to increase the key verification length, thereby comprehensively improving the key generation performance.

[0011] In combination with the first aspect, in a design, the first information includes at least one of the following: the adjustment value of the parameter of the verification key, or the adjustment value of the parameter of the generated key; or the first information includes at least one of the following: the value of the adjusted parameter of the verification key, or the value of the adjusted parameter of the generated key.

[0012] In the design, the content of the first information has higher flexibility, which can at least cover any of the following aspects: the adjustment value of the parameter of the verification key, or the adjustment value of the parameter of the generated key. Meanwhile, in order to further improve the expression efficiency and diversity of the information, the first information is designed to include the specific value of the adjusted parameter of the verification key and the specific value of the adjusted parameter of the generated key. These design options provide rich selection space for actual applications. For the design of setting the first information as the adjustment value of the parameter, the data amount of the first information is smaller, and the network bandwidth required for transmitting the first information is smaller. For the design of setting the first information as the specific value of the adjusted parameter, the first information can carry the parameter with higher accuracy, avoids the error generated in the process of calculating the specific value of the adjusted parameter based on the adjustment value, and does not need to perform additional calculation, thereby simplifying the processing procedure.

[0013] In combination with the first aspect, in a design, the method is applied to the first communication device; obtaining the first check information of the first key and the second check information of the second key includes: the first communication device obtains the first check information of the first key and the second check information of the second key, the first communication device is a communication device for generating the first key, and the communication device for generating the second key is a second communication device; sending the first information based on the first check information and the second check information includes: the first communication device sends the first information to the second communication device based on the first check information and the second check information.

[0014] In this design, the role of the key verification device is directly assumed by any party participating in the key negotiation, and at this time, the device generating the first key is referred to as the first communication device, and the device generating the second key is referred to as the first communication device. In this scenario, the first communication device assumes the role of the key verification device, reducing the need for additional devices and simplifying the overall architecture of the communication system. Moreover, since the verification process is built into the key negotiation process and is performed by the direct participants in the key negotiation, the security of the key negotiation process is enhanced. Neither party can unilaterally change the key without being detected by the other party.

[0015] In combination with the first aspect, in one design, the method is applied to a third communication device; obtaining first verification information of the first key and second verification information of the second key includes that the third communication device obtains the first verification information of the first key and the second verification information of the second key; and sending first information based on the first verification information and the second verification information includes that the third communication device sends the first information to the first communication device and the second communication device based on the first verification information and the second verification information, the first communication device being a device generating the first key, and the second communication device being a device generating the second key.

[0016] In this design, the role of the key verification device is assumed by a third-party device independent of the negotiation parties, and the device assuming the role of the key verification device is referred to as the third communication device. The third communication device is responsible for key verification, which can significantly enhance the trustworthiness of the key negotiation process. This is because the third communication device is usually designed to be neutral and trustworthy, and it can provide impartial verification services to ensure that the key negotiated between the negotiation parties is authentic and valid.

[0017] In the second aspect, a communication method is provided, which is applied to a key negotiation device. The execution subject of the method can be a key negotiation apparatus, a component or device (such as a processor, a chip, or a chip system, etc.) applied to the key negotiation apparatus, a logic module or software capable of realizing all or part of the functions of the key negotiation apparatus, or a device matched with the key verification apparatus. The communication method includes: sending second verification information of a second key for verifying the consistency of the second key and a first key; and receiving first information for indicating adjustment of a parameter for verifying the key and / or a parameter for generating the key, the first information being determined based on the second verification information and first verification information of the first key. Optionally, the parameter for verifying the key includes a key verification length. Optionally, the parameter for generating the key includes a quantization threshold for generating the key and / or a quantization bit number for generating the key.

[0018] In a second aspect, the key agreement apparatus receives first information indicating adjustment of a parameter of the verification key and / or a parameter used for generating the key, and then adjusts the parameter of the verification key and / or the parameter used for generating the verification key based on the first information to improve the performance of the key generation.

[0019] In combination with the second aspect, in one design, the method further includes generating a new key based on the first information.

[0020] In this design, the new key is generated based on the first information, which is determined based on the first and second check information and indicates adjustment of the parameter of the verification key and / or the parameter used for generating the verification key, and thus the performance of the key generation can be optimized.

[0021] In combination with the second aspect, in one design, the first information includes at least one of an adjustment value of the parameter of the verification key or an adjustment value of the parameter used for generating the key, or the first information includes at least one of a value of the adjusted parameter of the verification key or a value of the adjusted parameter used for generating the key.

[0022] The content of the first information is designed to be flexible, which can include at least one of an adjustment value of the parameter of the verification key or an adjustment value of the parameter used for generating the key. To further improve the efficiency and diversity of the information, the first information is also designed to include a value of the adjusted parameter of the verification key and a value of the adjusted parameter used for generating the key. These design options provide rich selection space for practical applications.

[0023] In combination with the second aspect, in one design, the first information indicates at least one of increasing a verification length of the key, decreasing a quantization threshold used for generating the key, or increasing a number of quantization bits used for generating the key, or the first information indicates at least one of decreasing the verification length of the key, increasing the quantization threshold used for generating the key, or decreasing the number of quantization bits used for generating the key.

[0024] In the design, the indication content of the first information is flexibly set, and through the indication of the first information, the corresponding parameters can be flexibly adjusted when the key is generated, and the generation performance of the key is improved. Increasing the key verification length can effectively reduce the frequency of key consistency verification and reduce the consumption and overhead of air interface resources. Reducing the quantization threshold for generating the key can improve the key generation efficiency. Increasing the number of quantization bits for generating the key can improve the key generation rate. Reducing the key verification length can improve the success rate of key consistency verification. Increasing the quantization threshold for generating the key can help to improve the key consistency rate, and thus the success rate of key consistency verification is also improved. Reducing the number of quantization bits for generating the key can improve the key consistency rate, and thus the success rate of key consistency verification is also improved.

[0025] In a third aspect, a communication apparatus is provided for implementing the method in any one of the first aspect to the second aspect. For example, the communication apparatus can be the key verification apparatus in the first aspect; or the communication apparatus can be the key negotiation apparatus in the second aspect. When the apparatus is a chip system, the apparatus can be composed of a chip, or can include the chip and other discrete components.

[0026] The communication apparatus includes modules, units, or means corresponding to the method, which can be implemented by hardware, software, or by executing corresponding software by hardware. The hardware or software includes one or more modules or units corresponding to the functions.

[0027] In some possible designs, the communication apparatus can include a processing module and a transceiver module. The processing module can be used to implement the processing functions in any one of the aspects above and any possible implementation manner thereof. The transceiver module, which can also be referred to as a transceiver unit, is used to implement the functions of sending and / or receiving in any one of the aspects above and any possible implementation manner thereof. The transceiver module can be composed of a transceiver circuit, a transceiver, a transceiver, or a communication interface.

[0028] In some possible designs, the transceiver module includes a sending module and / or a receiving module, which are used to implement the functions of sending or receiving in any one of the aspects above and any possible implementation manner thereof.

[0029] In a fourth aspect, a communication apparatus is provided, which includes a processor and a communication interface. The communication interface is used to communicate with modules outside the communication apparatus. The processor is used to execute computer programs or instructions, so that the communication apparatus performs the method in any one of the aspects. For example, the communication apparatus can be the key verification apparatus in the first aspect; or the communication apparatus can be the key negotiation apparatus in the second aspect. When the apparatus is a chip system, the apparatus can be composed of a chip, or can include the chip and other discrete components.

[0030] In a fifth aspect, a communication apparatus is provided, which comprises at least one processor; the processor is configured to execute computer programs or instructions stored in a memory, so as to enable the communication apparatus to perform the method of any one of the aspects. The memory can be integrated with the processor, or the memory can exist independently of the processor, for example, the memory and the processor are two independent modules. The memory can be located outside the communication apparatus, or can be located inside the communication apparatus.

[0031] The communication apparatus is configured to implement the method of any one of the first aspect to the second aspect. For example, the communication apparatus can be the key verification apparatus in the first aspect; or the communication apparatus can be the key negotiation apparatus in the second aspect. When the apparatus is a chip system, the apparatus can be composed of a chip, or can comprise a chip and other discrete devices.

[0032] In a sixth aspect, a computer readable storage medium is provided, which stores computer programs or instructions, when the computer programs or instructions are executed on a communication apparatus, the communication apparatus can perform the method of any one of the aspects.

[0033] In a seventh aspect, a computer program product is provided, which comprises instructions, when the instructions are executed on a communication apparatus, the communication apparatus can perform the method of any one of the aspects.

[0034] In an eighth aspect, a communication apparatus is provided, which is configured to enable the communication apparatus to perform the method of any one of the aspects.

[0035] It can be understood that, when the communication apparatus of any one of the third aspect to the fifth aspect is a chip, the sending action / function of the communication apparatus can be understood as outputting information, and the receiving action / function of the communication apparatus can be understood as inputting information.

[0036] The technical effects brought by any one of the third aspect to the eighth aspect can be referred to the technical effects brought by different design manners of the first aspect and the second aspect, which will not be described herein.

[0037] In a ninth aspect, a communication system is provided, which comprises the key verification apparatus and the key negotiation apparatus of the above aspects. BRIEF DESCRIPTION OF DRAWINGS

[0038] Figure 1 A key generation process schematic diagram provided by an embodiment of the present application;

[0039] Figure 2 A key consistency verification process schematic diagram provided by an embodiment of the present application;

[0040] Figure 3A schematic diagram of a communication system provided by an embodiment of the present application is shown in FIG. 1.

[0041] Figure 4 A flowchart of a communication method provided by an embodiment of the present application is shown in FIG. 2.

[0042] Figure 5 A flowchart of another communication method provided by an embodiment of the present application is shown in FIG. 3.

[0043] Figure 6 A flowchart of another communication method provided by an embodiment of the present application is shown in FIG. 4.

[0044] Figure 7 A flowchart of another communication method provided by an embodiment of the present application is shown in FIG. 5.

[0045] Figure 8 A flowchart of another communication method provided by an embodiment of the present application is shown in FIG. 6.

[0046] Figure 9 A flowchart of another communication method provided by an embodiment of the present application is shown in FIG. 7.

[0047] Figure 10 A flowchart of another communication method provided by an embodiment of the present application is shown in FIG. 8.

[0048] Figure 11 A structural diagram of a communication device provided by an embodiment of the present application is shown in FIG. 9.

[0049] Figure 12 A structural diagram of another communication device provided by an embodiment of the present application is shown in FIG. 10.

[0050] Figure 13 A structural diagram of another communication device provided by an embodiment of the present application is shown in FIG. 11. DETAILED DESCRIPTION

[0051] The network architecture and service scenarios described in the embodiments of the present application are for more clearly explaining the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those skilled in the art can know that, with the evolution of network architecture and the appearance of new service scenarios, the technical solutions provided by the embodiments of the present application are also applicable to similar technical problems.

[0052] Before introducing the embodiments of the present application, some terms related to the embodiments of the present application are explained.

[0053] 1. Key (Key):

[0054] A key is a secret parameter used in encryption and decryption processes to control the encryption and decryption processes and ensure the security of information. In physical layer key generation technology, the key is usually dynamically generated through specific properties of the wireless channel (such as phase, amplitude, etc.), with uniqueness, unpredictability, and randomness.

[0055] 2. Key Verification Length (KVL):

[0056] Key verification length refers to the length of the part of the key used to verify the consistency of the keys generated by both parties during the key generation process. This part of the key is used by both parties after generation to compare and confirm whether the keys generated by both parties are the same. The choice of key verification length will affect the efficiency and security of the key generation process. The relationship between the key and the key verification length: the key is the whole, while the key verification length is a specific part of the key used to verify the consistency of the key. The choice of key verification length can be determined according to specific application scenarios and security requirements to ensure that the key generation process is both efficient and secure.

[0057] 3. Key Verification Bit (KVB):

[0058] Key verification bits refer to specific bits used in the key verification process to actually compare and confirm the consistency of the key. These bits are extracted from the key part specified by the key verification length and used to perform specific verification operations. The consistency of the key verification bits directly reflects the performance and reliability of the key generation technology. The relationship between the key verification length and the key verification bits: the key verification length determines how many bits will be used for key verification, while the key verification bits are the specific values of these bits. Therefore, changes in the key verification length will directly affect the number and consistency of the key verification bits.

[0059] 4. Key Consistency Rate:

[0060] The key agreement rate refers to the probability that both parties successfully generate and agree on a key during the key agreement process. For example, if the key agreement rate is 90%, it means that for every 100 bits of key, on average, 10 bits of key content between the two parties of the key agreement are inconsistent, and the remaining 90 bits are consistent. Under the condition of a certain key agreement rate, the fewer the number of key verification bits in a single verification, the greater the probability of passing the verification. In this context, if 100 key verification bits are used to verify the integrity of every 100 bits of key, due to the existence of 10 inconsistent bits, the verification process has a high probability of determining that the key is inconsistent, resulting in verification failure. If 20 key verification bits are used to verify the integrity of every 100 bits of key, the verification process has a high probability of determining that the key is consistent, resulting in successful verification.

[0061] A classical channel entropy-based physical layer key generation process, as shown in FIG. 1, is a key agreement method that relies on detailed measurements of the physical communication channel by both parties and utilizes the physical property of channel reciprocity, enabling both parties to independently generate highly consistent keys without directly exchanging key information. This process mainly includes the following steps: Figure 1

[0062] S11, Channel Measurement: First, both parties of the communication measure the physical channel between them in detail. These measurements may include signal amplitude, phase, frequency offset, delay, and other parameters, aiming to capture the inherent randomness and uniqueness of the channel. The accuracy and comprehensiveness of channel measurement are crucial to the quality and security of subsequent key generation.

[0063] S12, Randomness Extraction: Extract randomness elements from channel measurement data. Since channel characteristics usually contain a large amount of random noise and interference, these elements can be considered as natural random sources. Through complex algorithm processing, a long enough, statistically independent random sequence can be extracted from the measurement data as the raw material for the key.

[0064] ​S13, Channel quantization: Channel quantization is used to convert continuous channel measurement data into discrete key bits. This step introduces the concept of quantization threshold and quantization bit number. The quantization threshold defines the boundary of the range of measurement data, and the quantization bit number determines how many intervals (i.e. how many possible key bit values) are divided into, each interval corresponds to a key bit value. The degree of quantization (determined by the number of quantization bits) directly affects the generation rate and quality of the key. Too coarse quantization (i.e. too few quantization bits) will increase the correlation between key bits, thereby reducing the security of the key. When the number of quantization bits is sufficient, the continuous channel measurement data can be more finely divided into multiple intervals, each interval corresponding to a key bit value. This means that more key bits can be generated within the same range of measurement data, thereby increasing the key generation rate and reducing the correlation between key bits, thereby improving the security of the key.

[0065] For example, in double-threshold quantization, the threshold value is set to ±0.25, and the coefficients whose absolute values are greater than the threshold are quantized. The quantization process converts these real-valued coefficients into multi-bit representations (called key bits). For example, in one-bit quantization (1 bit is used in quantization), the coefficient 0.5 (greater than 0.25) is quantized to bit 1, and -0.5 (less than -0.25) is quantized to bit 0, i.e. the key bits in this case are 1 or 0. Further, in two-bit quantization (2 bits are used in quantization), the range of 1 is divided into two intervals, [-1, -0.25] and [0.25, 1], each interval is divided into four parts, and each part of the coefficient corresponds to a two-bit code (such as 00, 01, 10, 11, the specific coding method may vary according to system design, which is not limited), i.e. the key bits in this case are 00, 01, 10, or 11. Similarly, three-bit quantization divides the entire range into eight parts, and the key bits in this case are three bits, with more possibilities.

[0066] As can be seen from the above examples, the selection of the quantization threshold value directly affects the number of quantized coefficients. The smaller the threshold value, the more coefficients exceed the threshold, and thus more key bits can be generated. At the same time, the more the number of quantization bits, the more intervals can be theoretically divided, and thus more key bits can be generated. The number of key bits determines the ability of the key to accurately represent or distinguish different information or states. The more the number of key bits, the more states or information the key can represent, and the higher the degree of detail. At the same time, it means that more data needs to be processed in the encryption and decryption process, which may reduce the encryption speed.

[0067] S14, Information reconciliation: Since both parties independently perform channel measurement and key generation, there may be some differences between the key sequences they generate. The information reconciliation step aims to reach an agreement on the inconsistent parts of the key sequence through a negotiation process. This is usually achieved by exchanging a small amount of auxiliary information, but care must be taken to protect this information from being stolen by malicious third parties.

[0068] S15, Privacy amplification: Privacy amplification is a security enhancement step in the physical layer key generation process. It uses a mathematical transformation (such as a hash function) to expand the agreed key sequence between the two parties into a longer, statistically more unpredictable key. The purpose of privacy amplification is to reduce the residual correlation or weakness that may exist in the key, further improving the security of the key.

[0069] In summary, the classic channel entropy-based physical layer key generation technology realizes the key negotiation and generation of both parties without exchanging key information through a series of carefully designed steps. This technology not only improves the security and efficiency of key generation, but also provides new ideas and methods for secure communication in wireless communication networks.

[0070] After the channel entropy-based physical layer key generation, key consistency verification is a key step to ensure the security and reliability of the key. This verification confirms whether the keys of both parties are consistent through indirect means (such as exchanging hash verification bits of the key), which is used to prevent man-in-the-middle attacks and ensure the integrity and robustness of the system.

[0071] The process of key consistency verification is introduced as follows, Figure 2 shows a process of key consistency verification, comprising:

[0072] S21, Key generation:

[0073] This is the starting point of the entire encryption process. In the key generation phase, both parties (usually the sender and the receiver) generate keys according to a certain algorithm or protocol. These keys can be symmetric (i.e. both parties use the same key) or asymmetric (both parties use a pair of public and private keys). The specific process can be referred to in the above Figure 1 introduction of the embodiments shown, which will not be repeated here.

[0074] S22, Calculate key verification bits:

[0075] After key generation, both parties will use their respective keys or some part of the key pair (such as public or private keys) to calculate some key verification bits (or called verification code, digest, etc.) through a certain hash function or other algorithm. These key verification bits are a unique representation of the key or part of the key, which is used for subsequent consistency verification.

[0076] S23, exchange key check bits:

[0077] Both parties exchange these key check bits for key consistency check. This can be done through a secure communication channel to ensure that the key check bits are not tampered with or leaked during transmission.

[0078] S24, key consistency check:

[0079] After receiving the key check bits sent by the sender, the receiver will use the key (or the corresponding part of the key pair) generated by itself and the same algorithm to recalculate the key check bits. Then, the calculated key check bits are compared with the received key check bits.

[0080] If they are consistent, it means that the keys generated by both parties are consistent, and the subsequent encrypted communication can continue.

[0081] If they are not consistent, it means that the key has a problem in the generation or transmission process, which may be tampered with or other errors. At this time, both parties should discard the current key and re-execute the key generation and consistency check process until the verification is successful.

[0082] S25, keep or discard the key:

[0083] According to the result of key consistency check, if the key is consistent, the key is kept for subsequent encrypted communication.

[0084] If the key is not consistent, the key is discarded and the key generation and consistency check process is restarted.

[0085] In summary, key consistency check is an important step in encryption algorithm to ensure the security of the key. Through this step, both parties of communication can ensure that the key they use is consistent, so as to guarantee the confidentiality and integrity of encrypted communication.

[0086] In order to ensure the smooth progress of encrypted communication and the safe transmission of data, it is very important to improve the key consistency. One possible implementation is to improve the channel estimation accuracy by increasing the transmission power of reference signal or increasing the number of retransmissions, in order to improve the key consistency. However, this approach ignores the multiple complex factors affecting key consistency, which may lead to the overall key generation performance not rising but falling. This is reflected in the following aspects:

[0087] 1. Channel characteristics and noise interference: Channel characteristics are complex and changeable, not only affected by natural factors such as path loss, multipath effect, etc., but also possibly affected by human interference or electromagnetic environment changes. Simply increasing the transmission power of the reference signal can improve the signal-to-noise ratio to some extent, but it may also introduce more noise and interference, thereby reducing the accuracy of channel estimation.

[0088] At the same time, Gaussian white noise, communication delay, and hardware fingerprint interference factors will also have adverse effects on channel estimation, and increasing the number of retransmissions cannot completely eliminate these interferences, but may increase the complexity and delay of the system.

[0089] 2. System overhead and complexity: Increasing the number of retransmissions and enhancing the transmission power of the reference signal will increase the system overhead and complexity. This includes the overhead of signal processing, encoding and decoding, resource scheduling, etc. When the system overhead increases to a certain extent, it may exceed the performance improvement brought by improving the accuracy of channel estimation, thereby causing the overall key generation performance to decrease instead of increasing.

[0090] 3. Limitations of channel reciprocity and spatial correlation: In some cases, even if the transmission power of the reference signal is enhanced or the number of retransmissions is increased, the limitations of channel reciprocity and spatial correlation may not be completely overcome. This is because the characteristics of the wireless channel are not only affected by the physical environment, but also by device status, user behavior, and other factors. Therefore, simply relying on enhanced reference signals may not effectively improve the consistency of the key.

[0091] Therefore, the above-mentioned methods may cause the overall key generation performance to decrease instead of increasing.

[0092] To solve the above technical problems, the embodiments of the present application provide a communication method, which is based on the idea of changing the parameters of the verification key or the parameters for generating the key to improve the generation performance of the key. In one case, if the key verification information of the two parties is inconsistent, the consistency of the key verification information is improved by reducing the key length, increasing the quantization threshold for generating the key, or reducing the number of quantization bits for generating the key. In another case, if the proportion of consistent key verification information of the two parties is high, the network transmission overhead is reduced by increasing the key length, reducing the quantization threshold for generating the key, or increasing the number of quantization bits for generating the key, thereby comprehensively improving the generation performance of the key. The method provided by the embodiments of the present application is described below in conjunction with the accompanying drawings.

[0093] The communication method provided by the embodiments of the present application can be applied to various communication systems, for example: a long term evolution (LTE) system, a 5th generation (5G) mobile communication system, a wireless fidelity (WiFi) system, a future communication system, or a system integrating multiple communication systems, and the like, and the embodiments of the present application are not limited thereto. The 5G can also be referred to as new radio (NR).

[0094] The communication method provided by the embodiments of the present application can be applied to various communication scenarios, for example, can be applied to one or more of the following communication scenarios: enhanced mobile broadband (eMBB), ultra reliable low latency communication (URLLC), machine type communication (MTC), massive machine type communication (mMTC), device to device (D2D), vehicle to everything (V2X), vehicle to vehicle (V2V), and internet of things (IoT), and the like.

[0095] In order to facilitate understanding of the embodiments of the present application, the application scenarios used by the present application are described taking the communication system architecture shown in Figure 3 as an example. Figure 3 Fig. 1 shows a possible, non-limiting system diagram. As shown in Figure 3 , the communication system 3000 includes a radio access network (RAN) 100 and a core network (CN) 200. The RAN 100 includes at least one network device (e.g., 101a and 101b in Figure 3 , collectively referred to as 110) and at least one terminal (e.g., 102a-102j in Figure 3 , collectively referred to as 102). The RAN 100 can also include other RAN nodes, such as wireless relay devices and / or wireless backhaul devices (not shown). Figure 3The terminal 102 is connected to the network device 101 in a wireless manner. The network device 101 is connected to the core network 200 in a wireless or wired manner. The core network device in the core network 200 and the network device 101 in the RAN 100 can be different physical devices respectively, or can be the same physical device integrated with the logical functions of the core network and the logical functions of the radio access network.

[0096] The RAN 100 can be a 3rd generation partnership project (3GPP)-related cellular system, for example, a 4G, 5G mobile communication system, or an evolved system after 5G. The RAN 100 can also be an open radio access network (O-RAN or ORAN), a cloud radio access network (CRAN), or a WiFi system. The RAN 100 can also be a communication system in which two or more of the above systems are integrated.

[0097] The apparatus provided by the embodiments of the present application can be applied to the network device 101 or the terminal 102. It can be understood that, Figure 3 Only one possible communication system architecture to which the embodiments of the present application can be applied is shown, and other devices can also be included in the communication system architecture in other possible scenarios.

[0098] The network device 101 is a node in a radio access network (RAN), which can also be referred to as an access network device, and can also be referred to as a RAN node (or device). The network device 101 is used to help the terminal to realize wireless access. The plurality of network devices 101 in the communication system 3000 can be nodes of the same type or nodes of different types. In some scenarios, the roles of the network device 101 and the terminal 102 are relative, for example, Figure 3 The network element 102i can be a helicopter or a drone, which can be configured as a mobile base station. For those terminals 102j that access the RAN 100 through the network element 102i, the network element 102i is a base station; but for the base station 101a, the network element 102i is a terminal. The network device 101 and the terminal 102 are sometimes referred to as communication apparatuses, for example Figure 3 The network elements 101a and 101b can be understood as communication apparatuses with base station functions, and the network elements 102a-102j can be understood as communication apparatuses with terminal functions.

[0099] In a possible scenario, the network device can be a base station, an evolved NodeB (eNodeB), a transmitting and receiving point (TRP), a transmitting point (TP), a next generation NodeB (gNB), a base station in a future mobile communication system, a satellite, or an access point (AP) in a WiFi system, an integrated access and backhaul (IAB) node, a network device in a non-terrestrial network (NTN) communication system, i.e., can be deployed in a high-altitude platform or a satellite, etc. The network device can be a macro base station (e.g., 110a in FIG. 1), a micro base station or an indoor station (e.g., 110b in FIG. 1), a relay node or a donor node, or a radio controller in a cloud radio access network (CRAN) scenario. The network device can also be a device assuming a base station function in device to device (D2D) communication, vehicle-to-everything (V2X) communication, unmanned aircraft communication, or machine communication. Alternatively, the network device can also be a server, a wearable device, a vehicle or a vehicle-mounted device, etc. For example, the access network device in the V2X technology can be a road side unit (RSU). Figure 3 Figure 4

[0100] ​​In another possible scenario, a terminal is assisted by multiple network devices to implement wireless access, and different network devices respectively implement part of functions of a base station. For example, a network device can be a central unit (CU), a distributed unit (DU), a CU-control plane (CP), a CU-user plane (UP), or a radio unit (RU), etc. The CU and the DU can be separately arranged, or can be included in the same network element, for example, a baseband unit (BBU). The RU can be included in a radio frequency device or a radio frequency unit, for example, included in a remote radio unit (RRU), an active antenna unit (AAU), or a remote radio head (RRH). It can be understood that the network device can be a CU node, or a DU node, or a device including a CU node and a DU node. In addition, the CU can be divided into a network device in an access network RAN, or the CU can be divided into a network device in a core network CN, which is not limited here.

[0101] In different systems, the CU (or CU-CP and CU-UP), DU or RU can also have different names, but those skilled in the art can understand their meanings. For example, in an open-radio access network (O-RAN) system, the CU can also be referred to as an O-CU (open CU), the DU can also be referred to as an O-DU, the CU-CP can also be referred to as an O-CU-CP, the CU-UP can also be referred to as an O-CU-UP, and the RU can also be referred to as an O-RU. For the convenience of description, the CU, CU-CP, CU-UP, DU and RU are taken as examples for description in this application. Any one of the CU (or CU-CP, CU-UP), DU and RU in this application can be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.

[0102] In the embodiments of this application, the form of the network device is not limited, and the device for implementing the functions of the network device can be the network device; or can be a device capable of supporting the network device to implement the functions, for example, a chip system. The device can be installed in the network device or used in matching with the network device.

[0103] The terminal device 102, which can also be referred to as a user equipment (UE), a mobile station (MS), a mobile terminal (MT), or the like, or a device configured to provide voice or data connectivity to a user, can also be an Internet of Things (IoT) device. For example, the terminal device can include a handheld device having wireless connection capability, a vehicle-mounted device, or the like. Currently, the terminal device can be a mobile phone, a tablet computer, a notebook computer, a palm computer, a mobile Internet device (MID), a wearable device (e.g., a smart watch, a smart bracelet, a pedometer, smart glasses, or the like), a vehicle-mounted device (e.g., a car, a bicycle, an electric vehicle, an airplane, a ship, a train, a high-speed rail, or the like), a satellite terminal, a virtual reality (VR) device, an augmented reality (AR) device, a point of sale (POS) machine, a customer-premises equipment (CPE), a light UE, a reduced capability UE (REDCAP UE), a wireless terminal in industrial control, a smart home device (e.g., a refrigerator, a television, an air conditioner, an electricity meter, or the like), a smart robot, a mechanical arm, a workshop device, a wireless terminal in unmanned driving, a wireless terminal in telemedicine, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, a wireless terminal in a smart home, a flight device (e.g., a smart robot, a hot air balloon, a drone, an airplane), or the like. The terminal device can also be a vehicle device, such as a whole vehicle device, a vehicle-mounted module, a vehicle-mounted chip, an on board unit (OBU), or a telematics box (T-BOX), or the like. The terminal device can also be other devices having terminal functions, for example, the terminal device can also be a device performing a terminal function in D2D communication.

[0104] Embodiments of the present application do not limit the form of the terminal device, and the device for implementing the function of the terminal device can be a terminal device, or can be a device capable of supporting the terminal device to implement the function, such as a chip system. The device can be installed in the terminal device or used in combination with the terminal device. In embodiments of the present application, the chip system can be composed of a chip, or can include a chip and other discrete devices. All or part of the functions of the terminal device in the present application can also be implemented by software functions running on hardware, or by virtualization functions instantiated on a platform (such as a cloud platform).

[0105] Any two devices in the communication system can be the two parties of the key agreement, for example, different terminals are the two parties of the key agreement (referred to as key agreement devices, for example, a first key agreement device and a second key agreement device), different network devices are the two parties of the key agreement, and a network device and a terminal are the two parties of the key agreement, respectively. The device performing the key consistency check (referred to as a key check device) can be any one of the two parties of the key agreement, for example, if terminal A and terminal B are the two parties of the key agreement, the key check device can be terminal A or terminal B, at this time, terminal A or terminal B simultaneously plays the role of the key agreement device and the key check device; or the key check device can also be a third-party device other than the two parties of the key agreement, for example, if terminal A and terminal B are the two parties of the key agreement, the device performing the key consistency check can be a network device serving terminal A and terminal B.

[0106] In combination with the above communication system, an embodiment of the present application provides a communication method for improving the generation performance of a key by adjusting the parameters of the verification key and / or generating the parameters of the verification key. The communication method is applied to the key check device and the key agreement device. The execution subject of the method can be the key check device or the key agreement device. The key check device or the key agreement device can be the network device or the terminal device introduced in the above communication system, can be a component (for example, a processor, a chip, or a chip system) applied to the network device or the terminal device, can be a logic module or software capable of realizing all or part of the functions of the network device or the terminal device, and can also be a device matched with the network device or the terminal device.

[0107] Figure 4 A flowchart of the communication method provided by an embodiment of the present application is shown. As shown in Figure 1 the method can include the following steps:

[0108] S410, the key check device obtains first check information of a first key and second check information of a second key from the key agreement device.

[0109] In combination with the above communication system, an embodiment of the present application provides a communication method for improving the generation performance of a key by adjusting the parameters of the verification key and / or generating the parameters of the verification key. The communication method is applied to the key check device and the key agreement device. The execution subject of the method can be the key check device or the key agreement device. The key check device or the key agreement device can be the network device or the terminal device introduced in the above communication system, can be a component (for example, a processor, a chip, or a chip system) applied to the network device or the terminal device, can be a logic module or software capable of realizing all or part of the functions of the network device or the terminal device, and can also be a device matched with the network device or the terminal device.

[0110] In the key agreement process, the first key agreement device and the second key agreement device can follow a channel entropy based physical layer key generation mechanism (the detailed process is shown in Figure 5 the embodiments described in detail, which will not be repeated here). According to this mechanism, both parties independently generate a key and at the same time generate the corresponding verification information of the respective key. Specifically, the verification information corresponding to the key generated by the first key agreement device is referred to as the first verification information, and the verification information corresponding to the key generated by the second key agreement device is referred to as the second verification information. The encoding method used to generate the first verification information and the second verification information can include bit mapping, hash function, or polynomial check, etc., without limitation.

[0111] S420, the key verification device sends the first information to the key agreement device based on the first verification information and the second verification information; correspondingly, the key agreement device receives the first information from the key verification device.

[0112] The first information is used to indicate the adjustment of at least one of the following: the parameter of the verification key or the parameter of the generated key. The parameter of the verification key includes the key verification length. The parameter of the generated key includes the quantization threshold for generating the key and / or the quantization bit number for generating the key. The first information can be used for the next key generation.

[0113] For example, the first information can be used to indicate at least one of the following: reducing the key verification length, increasing the quantization threshold for generating the key, or reducing the quantization bit number for generating the key. In another example, the first information can also be used to indicate at least one of the following: increasing the key verification length, reducing the quantization threshold for generating the key, or increasing the quantization bit number for generating the key.

[0114] The key consistency check based on the first verification information and the second verification information may or may not pass. First, the design of the first information when the key consistency check does not pass, i.e., the first verification information and the second verification information are inconsistent, is introduced as follows:

[0115] As shown in Figure 5 , in the case that the first verification information and the second verification information are inconsistent, the first information is used to indicate at least one of the following: reducing the key verification length, increasing the quantization threshold for generating the key, or reducing the quantization bit number for generating the key. In other words, S420 at this time can include: in the case that the first verification information and the second verification information are inconsistent, sending the first information indicating the above content.

[0116] The effect of reducing the key verification length: considering that in the process of performing key consistency verification, if there is any inconsistency between the key negotiation devices, it will directly lead to the generated verification bits not matching, and thus the entire key segment participating in the verification must be discarded. In other words, even in the case of a long key length and only a small number of bits being inconsistent, the entire key will be discarded due to verification failure, which can cause significant waste of resources. Taking a specific scenario as an example, suppose a 1000-bit length key verification is performed. If the entire 1000-bit key is verified at one time (the key verification length is 1000 bits at this time), and the corresponding verification bits are calculated, even if there is only 1-bit inconsistency between the keys of the two parties, the verification bits generated by the two parties will be different, thereby forcing the entire 1000-bit key to be discarded.

[0117] If the key verification length is reduced at this time, for example, the 1000-bit key is verified in ten times (the key verification length is reduced from 1000 bits to 100 bits at this time). In this case, if only the key (100 bits) at one of the ten times is inconsistent, this part of the key needs to be discarded, while the remaining part of the key (900 bits in total) can still be retained and used for subsequent operations due to successful verification. Moreover, due to the reduction of the content to be verified, the success rate of key consistency verification will also be improved, thereby reducing the waste of air interface resources caused by the failure of key consistency verification.

[0118] As for the effect of increasing the quantization threshold for generating the key, if the quantization threshold is set to be relatively loose (i.e., the value of the quantization threshold is small), the channel measurement value is more susceptible to noise, interference and other factors during the quantization process, resulting in deviations in the quantization result. Increasing the quantization threshold can make the quantization interval more explicit and reduce the key inconsistency caused by quantization errors. Therefore, the increase of the quantization threshold helps to improve the key consistency rate, thereby improving the success rate of key consistency verification.

[0119] In addition, the effect of reducing the number of quantization bits for generating the key, the fewer the number of quantization bits, the larger the quantization interval (or quantization step). In the quantization process, a larger quantization interval can reduce the quantization error caused by channel noise, interference and other factors, making the results of the legitimate communication parties after quantization closer, thereby improving the key consistency rate, and thus improving the success rate of key consistency verification.

[0120] In summary, the embodiments of the present application design various strategies to improve the success rate of key consistency verification, including reducing the length of key verification, increasing the quantization threshold when generating a key, and reducing the number of quantization bits used to generate a key. Each strategy can effectively improve the success rate of key consistency verification in different scenarios. It can be understood that, in order to achieve the goal of improving the success rate of key consistency verification, any one of the above strategies or any combination thereof can be flexibly selected, depending on actual requirements and conditions, and there is no limitation.

[0121] In an embodiment, as shown in Figure 6 When the key consistency verification is successful, i.e., the first verification information is consistent with the second verification information, the current generated key can be recorded and put into use. In a possible implementation, the current key verification parameter and the key generation parameter are recorded and used as the reference parameter for the subsequent key generation process. In a possible implementation, if the key consistency verification is successful, it means that the key verification parameter and the key generation parameter can meet the demand of the success rate of key consistency verification, and the first information described above can not be sent.

[0122] In an embodiment, further, if the key consistency verification is passed for multiple times, at this time, the parameter for verifying the key can be adjusted to reduce the network transmission overhead, and the parameter for generating the key can be adjusted to improve the efficiency of generating the key. At this time, as shown in Figure 5 The method can further include:

[0123] S430, the key verification device obtains at least one third verification information and at least one fourth verification information from the key negotiation device.

[0124] The third check information and the fourth check information are used to determine consistency of the first key and the second key. The third check information can be check information generated by the first key agreement device in a key consistency check before the current key consistency check. The fourth check information can be check information generated by the second key agreement device in a key consistency check before the current key consistency check. The first check information and the at least one third check information constitute a first check information set, and similarly, the second check information and the at least one fourth check information constitute a second check information set. Regarding the setting of the first check information set, the first check information set can be set as check information obtained in a period of time, for example, check information obtained every first time period constitutes the current first check information set, for example, the first time period is 5 s. That is, the first check information set includes check information obtained in the first time period. Alternatively, the first check information set can be set to include a fixed number of check information, for example, check information obtained every N times constitutes the current first check information set, for example, N is 10. That is, the first check information set includes N check information obtained by N times of check. The setting of the second check information set is the same as that of the first check information set, and will not be described in detail.

[0125] The content of the first information can be determined according to the consistency check information in the first check information set and the second check information set. That is, the first information is sent based on the first check information, the second check information, the third check information, and the fourth check information.

[0126] In a possible implementation, if the proportion of the consistency check information in the first check information set and the second check information set meets a preset condition, it indicates that the pass rate of the key consistency check is very high, in order to reduce the air interface overhead of the key consistency check and improve the key generation rate, the first information in this case can be set to indicate at least one of the following: increasing the key verification length, reducing the quantization threshold for generating the key, or increasing the quantization bit number for generating the key. Figure 7 The preset condition can be that the pass rate of the key consistency check is greater than or equal to an expected value, for example, the expected value is 90%. It can be understood that the preset condition can also have other settings in different scenarios and use requirements, and is not limited.

[0127] In this implementation, S420 can include: in a case where the proportion of the consistency check information in the first check information set and the second check information set meets a preset condition, sending first information indicating at least one of the following: increasing the key verification length, reducing the quantization threshold for generating the key, and / or increasing the quantization bit number for generating the key.

[0128] In a possible implementation, the first information is not sent if the proportion of consistency check information in the first set of check information and the second set of check information meets a non-preset condition. This implementation can reduce signaling overhead and avoid frequent adjustment of key parameters.

[0129] After the key verification length is increased, the key check bits required for processing each verification are increased, thereby effectively reducing the frequency of key consistency check and reducing the consumption and overhead of air interface resources.

[0130] Reducing the quantization threshold in key generation can improve the efficiency of key generation. First, the reduction of the quantization threshold simplifies the quantization process, reduces the number of quantization levels, and makes the quantization interval more extensive. Thus, more channel measurement values can be quickly classified into a limited number of quantization categories in the same time, thereby accelerating the key generation process. Second, this adjustment also reduces the computational complexity, because each channel measurement value only needs to be compared with fewer thresholds when quantized, thereby reducing the time-consuming calculation and resource occupation.

[0131] Increasing the number of quantization bits in key generation can promote the improvement of the key generation rate. A higher number of quantization bits means that channel measurement values can be mapped to more refined quantization levels when quantized, which is equivalent to generating more abundant key bits while keeping the number of channel characteristics unchanged, thereby accelerating the key generation process.

[0132] To sum up, the embodiments of the present application design various strategies to reduce the air interface overhead of key consistency check and improve the generation rate of keys, including increasing the key verification length, reducing the quantization threshold when generating keys, and increasing the number of quantization bits used to generate keys. It can be understood that, to achieve the above-mentioned goals, any one of the above-mentioned strategies or any combination thereof can be flexibly selected, depending on actual needs and conditions, and no limitation is imposed.

[0133] In an embodiment, as shown in Figure 8 the method can further include:

[0134] S440, determining an adjustment margin of the parameter according to the difference between the parameter of the first key and the corresponding preset parameter value.

[0135] The parameter of the first key includes the parameter of the verification key and / or the parameter of the generated key introduced in the above embodiments. Considering that the communication system can define the adjustable range of the parameter of the key, the parameter of the key is not adjustable without limit. The adjustable range of the parameter of the key can be determined by the preset parameter value. At this time, the adjustment margin of the parameter can be determined according to the difference between the parameter of the key (for example, the first key) and the corresponding preset parameter value. The preset parameter value can include one or more threshold values, for example, the preset parameter value includes [threshold value 1, threshold value 2, …, threshold value n]. For example, taking the key verification length in the parameter of the verification key as an example, the optional set of the key verification length is [1024, 512, 256, 128, 64], at this time, the preset parameter value includes 1024, 512, 256, 128, and 64, and it is assumed that the key verification length of the first key is 64, at this time, the adjustment margin of the key verification length of the first key includes four kinds, that is, increasing 64, increasing 192, increasing 448, and increasing 960.

[0136] As an alternative implementation, the adjustment margin of the parameter can also be determined according to the difference between the parameter of the second key and the corresponding preset parameter value, which is not limited. It can be understood that in this alternative implementation, the first key and the second key are corresponding, so the adjustment margin of the parameter can be determined according to any one of the keys.

[0137] S450, determining the first information according to the first check information, the second check information, and the adjustment margin of the parameter.

[0138] After the adjustment margin is determined, whether the first check information and the second check information are consistent can be combined to determine the first information. Alternatively, after the first information is determined according to whether the first check information and the second check information are consistent, the adjustment margin can be determined, and the order is not limited.

[0139] The application of whether the first check information and the second check information are consistent in determining the first information can refer to the introduction of the above embodiments, which will not be repeated.

[0140] The following takes the parameter of the first key including the key verification length and the quantization threshold when the key is generated as an example to introduce how to determine the first information in various cases: in this example, the optional set of the key verification length (that is, the set of the preset parameter value) is [1024, 512, 256, 128, 64]; the optional set of the quantization threshold (that is, the set of the preset parameter value) is [2, 2.5, 3, 3.5, 4]. In this example, the priority of adjusting the key verification length is higher than that of adjusting the quantization threshold when the key is generated. As shown in FIG. 8, when the first information is determined, it can be divided into the following four cases: Figure 9 ​

[0141] Case one: the first check information is inconsistent with the second check information (the key consistency check fails), at this time, the first information can indicate to reduce the key verification length and / or increase the quantization threshold for generating the key, and there is an adjustment margin for reducing the key verification length, in this example, the first information indicates to reduce the key verification length in priority.

[0142] For example, the current key verification length is 512, and the quantization threshold is 3. The adjustment margin of the key verification length is: increase 512, reduce 256, reduce 384, and reduce 448. The adjustment margin of the quantization threshold is: increase 1, reduce 1, increase 0.5, and reduce 0.5. The priority of adjusting the key verification length is higher than that of adjusting the quantization threshold when generating the key, at this time, there is an adjustment margin for reducing the key verification length, then first try to optimize the key configuration by gradually reducing the key verification length (in the order of reducing amount from small to large, that is, first reduce 256, then 384, and finally 448), until the key consistency check succeeds, or the key verification length reaches the minimum value 64 in the adjustment margin. The first information corresponding to each key consistency check in this process indicates the current adjusted key verification length. For example, after the key consistency check after reducing 256, the first information can include the key verification length of 256, or indicate that the key verification length is reduced by 256.

[0143] If the key consistency check still fails even if the key verification length has been reduced to 64 in this process, then consider increasing the quantization threshold, and the specific increase is determined according to the values in the optional set of quantization thresholds, and a value in the optional set of quantization thresholds can be selected as the adjusted quantization threshold. For example, a small increase close to the current value is selected (such as from 3 to 3.5). Similar to the first information indicating the key verification length, the first information corresponding to each key consistency check indicates the current adjusted quantization threshold. For example, after the key consistency check after increasing from 3 to 3.5, the first information can include the quantization threshold of 3.5, or indicate that the quantization threshold is increased by 0.5. Through the adjustment of a small increment, the adjustment is fine, avoiding over-adjustment or oscillation phenomenon, and ensuring the stable operation of the communication system.

[0144] Case two: the key consistency check fails, at this time, the first information indicates to reduce the key verification length and / or increase the quantization threshold for generating the key, and there is no adjustment margin for reducing the key verification length, the first information indicates to increase the quantization threshold.

[0145] For example, the current key verification length is 64, and the quantization threshold is 3. At this time, there is no adjustment margin for reducing the key verification length 64. At this time, the strategy of increasing the quantization threshold is adopted, and the specific increase is determined according to the values in the optional set of quantization thresholds, for example, a smaller increase close to the current value (such as from 3 to 3.5) is selected, until the key consistency check passes or the maximum quantization threshold 4 is reached. The first information corresponding to each key consistency check indicates the current adjusted quantization threshold. For example, after the key consistency check from 3 to 3.5, the first information can include the quantization threshold of 3.5, or indicate that the quantization threshold is increased by 0.5.

[0146] Case three: the key consistency check passes, and the proportion of consistency check information in the first check information set and the second check information set meets the preset condition, at this time, the first information can indicate to increase the key verification length and / or reduce the quantization threshold for generating the key, and the key verification length has an adjustment margin for increasing, and the first information preferentially indicates to increase the key verification length.

[0147] For example, the current key verification length is 64, and the quantization threshold is 3. At this time, the key verification length can be increased to 128, and if the proportion of consistency check information in the key consistency check meets the preset condition in the subsequent multiple key consistency checks, the key verification length can continue to be increased, until the key consistency check does not pass, or the key verification length reaches the maximum length 1024. The first information corresponding to each key consistency check in this process indicates the current adjusted key verification length. For example, after the key consistency check with the key verification length increased by 64, the first information can include the key verification length of 128, or indicate that the key verification length is increased by 64.

[0148] If the key consistency check still passes at this time, the quantization threshold for generating the key is considered to be reduced, and the specific reduction is determined according to the values in the optional set of quantization thresholds, for example, a smaller increase close to the current value (such as from 3 to 2.5) is selected, until the key consistency check does not pass, or the minimum quantization threshold 2 is reached. The first information corresponding to each key consistency check indicates the current adjusted quantization threshold. For example, after the key consistency check from 3 to 2.5, the first information can include the quantization threshold of 3.5, or indicate that the quantization threshold is increased by 0.5.

[0149] Case four: the proportion of consistency check information in the first check information set and the second check information set meets the preset condition, the first information can indicate to increase the key verification length and / or reduce the quantization threshold for generating the key, and the key verification length does not have an adjustment margin for increasing, and the first information indicates to reduce the quantization threshold for generating the key.

[0150] For example, the current key verification length is 1024, and the quantization threshold is 3. At this time, the key verification length 1024 does not have an adjustment margin for increase. The quantization threshold for generating the key can be reduced as described in case three, and the description is not repeated.

[0151] Cases one to four above take the mechanism of taking a small increment close to the current value as an example to introduce how to determine the specific adjustment range of the adjustment parameter. It can be understood that in addition to taking the mechanism of taking a small increment close to the current value, a more flexible and efficient adjustment mechanism can also be designed according to the needs of the actual application scenario when determining the specific adjustment range of the adjustment parameter. For example, the maximum adjustment range is determined as the specific adjustment range of the adjustment parameter. Using the maximum adjustment range to adjust the parameter can quickly change the state of the communication system, accelerate the convergence to the target (key consistency check pass), and shorten the adjustment period.

[0152] In an embodiment, a dynamic adjustment mechanism based on the inconsistency of the check information can also be introduced, which can significantly improve the accuracy and efficiency of the adjustment. Specifically, this dynamic adjustment mechanism relies on comparing the inconsistency between the first check information and the second check information. When the inconsistency between the above two groups of check information is high, it means that the current parameter setting has a large deviation from the target state. At this time, appropriately increasing the increment of the adjustment parameter can accelerate the system to converge to the target state (key consistency check pass), reduce the adjustment period, and improve the adjustment efficiency. On the contrary, if the inconsistency between the two groups of check information is low, it means that the current parameter setting is close to the ideal state. At this time, reducing the increment of the adjustment parameter helps to achieve more precise adjustment, avoid over-adjustment or oscillation phenomenon, and ensure stable operation of the communication system.

[0153] The above examples take the parameters of the first key including the key verification length and the quantization threshold when generating the key as an example to introduce the content of the first information in each case. The first information indicating the adjusted parameters is specifically determined by combining the adjustment margin of each parameter and the adjustment priority of the parameter. It can be understood that in addition to the parameter content and the adjustment priority of the parameter introduced in the above examples, other parameter content and other parameter adjustment priority can also be designed based on the differences of the scene and the needs of use, which are not limited.

[0154] In a possible implementation, the adjustment priority of each parameter can be pre-agreed by the key check device and the key negotiation device, or can be indicated by the key check device to the key negotiation device through the first information, which is not limited. Optionally, the first information further includes parameter adjustment priority information, for example, the priority information indicates that the adjustment order of the key verification length is prior to the adjustment order of the quantization threshold.

[0155] In another possible implementation, the adjustment priority of the parameters can not be set, and the key agreement device can randomly generate an adjustment sequence from the adjustment parameters indicated by the first information to adjust the parameters.

[0156] In yet another example, in the parameters of the first key, in addition to the key verification length and the quantization threshold when generating the key in the above examples, a quantization bit number for generating the key is introduced. In the scenario where the parameters of the first key include the above three parameters, the specific process of the implementation of setting the adjustment priority of each parameter can refer to the description of the above examples, that is, first determine the adjustment margin of each parameter, and then adjust the corresponding parameters in turn based on the adjustment margin of each parameter and the adjustment priority of each parameter, until the adjustment purpose such as the key consistency check is passed, and details are not repeated. The implementation of the key agreement device randomly generating an adjustment sequence to adjust the parameters is described below.

[0157] In this example, the optional set of the key verification length (i.e., the set of the preset parameter threshold preset parameter value) is set as [1024, 512, 256, 128, 64]; the optional set of the quantization threshold (i.e., the set of the preset parameter threshold preset parameter value) is set as [2, 2.5, 3, 3.5, 4], and the optional set of the quantization bit number for generating the key (i.e., the set of the preset parameter threshold preset parameter value) is set as [1, 2, 3]. When determining the first information, it can be divided into the following two cases:

[0158] Case five is similar to case one, the first check information and the second check information are inconsistent (the key consistency check is not passed), at this time, the first information can indicate reducing the key verification length, increasing the quantization threshold for generating the key, and / or reducing the quantization bit number for generating the key. The above three parameters all have corresponding adjustment margins.

[0159] For example, the current key verification length is 512, the quantization threshold is 3, and the quantization bit number is 3. The adjustment margin of the key verification length is: increasing 512, reducing 256, reducing 384, and reducing 448. The adjustment margin of the quantization threshold is: increasing 1, reducing 1, increasing 0.5, and reducing 0.5, and the adjustment margin of the quantization bit number is: reducing 1 and reducing 2.

[0160] The first information can indicate the adjustment margin of the three types of parameters. The key negotiation device generates an adjustment sequence to adjust the three types of parameters in turn. The adjustment margin of each type of parameter indicated by the first information can be one adjustment margin. When determining which adjustment margin should be indicated, the determination mechanism can be flexibly set. For example, referring to the first case in the previous example, one adjustment margin with a smaller adjustment amount is selected. In an embodiment, the adjustment margin of each type of parameter indicated by the first information can also be multiple adjustment margins. The key negotiation device determines which adjustment margin of the multiple adjustment margins to start adjusting based on, and the determination mechanism can also be flexibly set. For specific descriptions, refer to the description after case 4 in the previous example, which will not be repeated here.

[0161] In case six, the first check information and the second check information are inconsistent (the key consistency check fails), and at this time, the first information can indicate reducing the key verification length, increasing the quantization threshold for generating the key, and / or reducing the quantization bit number for generating the key. The three types of parameters have corresponding adjustment margins.

[0162] For example, the current key verification length is 512, the quantization threshold is 3, and the quantization bit number is 1. The adjustment margin of the key verification length is: increasing 512, reducing 256, reducing 384, and reducing 448. The adjustment margin of the quantization threshold is: increasing 1, reducing 1, increasing 0.5, and reducing 0.5. The quantization bit number does not have a reduction adjustment margin.

[0163] The first information can indicate the adjustment margin of the key verification length and the quantization threshold, and the key negotiation device generates an adjustment sequence to adjust the key verification length and the quantization threshold in turn. The adjustment margin of each type of parameter indicated by the first information can be one adjustment margin. When determining which adjustment margin should be indicated, the determination mechanism can be flexibly set. For example, referring to the first case in the previous example, one adjustment margin with a smaller adjustment amount is selected. In an embodiment, the adjustment margin of each type of parameter indicated by the first information can also be multiple adjustment margins. The key negotiation device determines which adjustment margin of the multiple adjustment margins to start adjusting based on, and the determination mechanism can also be flexibly set. For specific descriptions, refer to the description after case 4 in the previous example, which will not be repeated here. In case seven, the key consistency check passes, and the proportion of the consistency check information in the first check information set and the second check information set meets the preset condition. At this time, the first information can indicate increasing the key verification length, reducing the quantization threshold for generating the key, and / or increasing the quantization bit number for generating the key. The three types of parameters have corresponding adjustment margins.

[0164] For example, the current key verification length is 64, the quantization threshold is 3, and the quantization bit number is 1. The adjustment margin of the key verification length is: increase 64, increase 192, increase 448, and increase 960. The adjustment margin of the quantization threshold is: increase 1, decrease 0.5, and decrease 1. The adjustment margin of the quantization bit number is: increase 1 and increase 2.

[0165] At this time, the first information can indicate the adjustment margin of the above-mentioned three types of parameters, and the key negotiation device randomly generates an adjustment sequence to sequentially adjust the above-mentioned three types of parameters. The adjustment margin of each type of parameter indicated by the first information can be one adjustment margin. When determining which adjustment margin should be indicated, the determination mechanism can be flexibly set. For example, referring to the case one in the previous example, one adjustment margin with a smaller adjustment amount is selected. In an embodiment, the adjustment margin of each type of parameter indicated by the first information can also be multiple adjustment margins. The key negotiation device can determine which adjustment margin of the multiple adjustment margins to start adjusting based on first. The determination mechanism can also be flexibly set. The specific description can be referred to the description after case 4 of the previous example, and will not be repeated here.

[0166] Case eight, the key consistency check passes, and the proportion of consistency check information in the first check information set and the second check information set meets the preset condition. At this time, the first information can indicate increasing the key verification length, decreasing the quantization threshold for generating the key, and / or increasing the quantization bit number for generating the key. The above-mentioned three parameters partially exist corresponding adjustment margins.

[0167] For example, the current key verification length is 64, the quantization threshold is 3, and the quantization bit number is 3. The adjustment margin of the key verification length is: increase 64, increase 192, increase 448, and increase 960. The adjustment margin of the quantization threshold is: increase 1, decrease 0.5, and decrease 1. The adjustment margin of the quantization bit number does not exist.

[0168] At this time, the first information can indicate the adjustment margin of the key verification length and the quantization threshold, and the key negotiation device randomly generates an adjustment sequence to sequentially adjust the key verification length and the quantization threshold. The adjustment margin of each type of parameter indicated by the first information can be one adjustment margin. When determining which adjustment margin should be indicated, the determination mechanism can be flexibly set. For example, referring to the case one in the previous example, one adjustment margin with a smaller adjustment amount is selected. In an embodiment, the adjustment margin of each type of parameter indicated by the first information can also be multiple adjustment margins. The key negotiation device can determine which adjustment margin of the multiple adjustment margins to start adjusting based on first. The determination mechanism can also be flexibly set. The specific description can be referred to the description after case 4 of the previous example, and will not be repeated here.

[0169] As can be seen from the above examples, the content of the first information in the embodiments of the present application has high flexibility, which can at least cover any of the following aspects: the adjusted value of the parameter of the verification key, and the adjusted value of the parameter of the generated key. Meanwhile, in order to further improve the expression efficiency and diversity of the information, the first information can also include the specific value of the adjusted verification key parameter and the specific value of the adjusted generated key parameter. For the design of setting the first information as the adjusted value of the parameter, the data amount of the first information is smaller, and the network bandwidth required for transmitting the first information is smaller. For the design of setting the first information as the adjusted specific value of the parameter, the first information can carry the parameter with high accuracy, avoid the error generated in the process of calculating the adjusted specific value based on the adjusted value, and does not need to perform additional calculation, thereby simplifying the processing procedure. These design options provide rich selection space for actual application, and specific examples can refer to the detailed examples of the content of the first information in the above-mentioned situations 1 to 4, which will not be described herein.

[0170] In an implementation manner, the first information can further include an index indicating the specific value (or the adjusted value) of the parameter.

[0171] The index of the specific value (or the adjusted value) corresponds to the specific value (or the adjusted value). The transceiving two ends store the association relationship of one or more indexes and the specific value (or the adjusted value) corresponding to each index. The specific value (or the adjusted value) can be determined according to the association relationship and the index, which can reduce the transmission overhead and provide higher flexibility and data processing efficiency, and is not limited to the direct or indirect representation of the information, and has high adaptability and configurability.

[0172] In the embodiments of the present application, the first information indicating the adjusted parameter is determined in combination with the adjustment margin of each parameter and the adjustment priority of the parameter, which can improve the pass rate of the key consistency check, improve the key generation rate, and reduce the air interface overhead of the key consistency check in each case.

[0173] In summary, the communication method provided by the embodiments of the present application is based on the idea of changing the parameter of the verification key or the parameter of the generated key to improve the generation performance of the key. In one case, if the key check information of the two parties is inconsistent, the consistency rate of the key check information is improved by reducing the key length, increasing the quantization threshold for generating the key, or reducing the number of quantization bits for generating the key. In another case, if the proportion of the consistent key check information of the two parties is high, the network transmission overhead is reduced by increasing the key length, reducing the quantization threshold for generating the key, or increasing the number of quantization bits for generating the key, thereby comprehensively improving the generation performance of the key.

[0174] As described above, in the embodiments of this application, the communication system is designed to allow any two devices within it to participate in the key negotiation process as one party, thus providing high flexibility. In particular, the role of the key verification device is set more flexibly: it can be directly assumed by either party participating in the key negotiation, or it can be assumed by a third-party device independent of the negotiating parties.

[0175] To illustrate the specific applications and practices of the embodiments of this application in different communication scenarios, the following will describe the implementation details of its communication method from the perspective of the execution flow. Specific explanations of each step will not be repeated here, as they have already been described in the preceding embodiments; please refer to the preceding text for details.

[0176] In one communication scenario, the role of the key verification device is directly assumed by either party participating in the key negotiation. In this case, the device generating the first key is called the first communication device, and the device generating the second key is also called the first communication device. In this scenario, the first communication device simultaneously acts as the key verification device. At this point, as follows... Figure 4 As shown, the communication method includes:

[0177] S910, the first communication device generates the first verification information of the first key.

[0178] In this process, the first communication device, as one of the parties in the key negotiation, is able to generate the first key and the first verification information.

[0179] S920, the second communication device sends the second verification information of the second key to the first communication device. Correspondingly, the second communication device receives the second verification information of the second key.

[0180] For detailed instructions, please refer to [link / reference]. Figure 4 Explanation of step S410 in the illustrated embodiment.

[0181] S930, the first communication device sends the first information to the second communication device based on the first verification information and the second verification information.

[0182] For an explanation of step S930, please refer to [link / reference]. Figure 10 Explanation of step S420 in the illustrated embodiment.

[0183] In this embodiment, the role of the key verification device is directly assumed by any party participating in the key negotiation, reducing the need for additional devices and thus simplifying the overall architecture of the communication system. Furthermore, since the verification process is built into the key negotiation process and executed by the direct participants, the security of the key negotiation process is enhanced. Neither party can unilaterally change the key without the other party's detection.

[0184] In another communication scenario, the role of the key checking device is assumed by a third-party device independent of the two parties of the negotiation, and the device assuming the role of the key checking device is referred to as a third communication device. In this scenario, the third communication device can send the first communication device and the second communication device the parameters for verifying the key and the parameters for generating the key, so that the first communication device and the second communication device generate the key. At this time, as shown in Figure 4 The communication method includes the following steps.

[0185] S110, the first communication device sends the first communication device to the third communication device the first check information of the first key and the second communication device sends the second check information of the second key to the third communication device, and correspondingly, the third communication device receives the first check information of the first key from the first communication device and receives the second check information of the second key from the second communication device.

[0186] The specific description of step S110 can refer to the description of step S410 in the embodiment shown in Figure 4

[0187] S120, the third communication device sends the first information to the first communication device and the second communication device based on the first check information and the second check information. Correspondingly, the first communication device and the second communication device receive the first information from the third communication device.

[0188] The description of step S120 can refer to the description of step S420 in the embodiment shown in Figure 11

[0189] In the embodiments of the present application, the role of the key checking device is assumed by a third-party device independent of the two parties of the negotiation, and the device assuming the role of the key checking device is referred to as a third communication device. The third communication device is responsible for key checking, which can significantly enhance the trustworthiness of the key negotiation process. This is because the third communication device is usually designed to be neutral and trusted, and it can provide fair verification services to ensure that the key negotiated between the two parties is authentic and effective.

[0190] ​​The above describes the scheme provided by the embodiment of the application from the perspective of the logic of each step. It can be understood that each node, for example, the key negotiation device, comprises a hardware structure and / or a software module corresponding to each function for implementing the above functions. Those skilled in the art should easily realize that, in combination with the algorithm steps of each example described in the embodiment disclosed herein, the method of the embodiment of the application can be implemented in the form of hardware, software, or a combination of hardware and computer software. Whether a certain function is implemented in the form of hardware or computer software driven hardware depends on the specific application of the technical scheme and the design constraint conditions. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the application.

[0191] The embodiment of the application can divide the function modules of the key negotiation device according to the above method examples. For example, each function module can be divided according to each function, or two or more functions can be integrated in one processing module. The above integrated module can be implemented in the form of hardware or in the form of a software function module. It should be noted that the division of the modules in the embodiment of the application is illustrative, and is only a logical function division. In actual implementation, there can be another division manner.

[0192] In a specific implementation, each network element shown in the application, for example, the key negotiation device or the key verification device, can adopt the constituent structure shown in Figure 11 or include the components shown in Figure 11 . Figure 11 The structure schematic diagram of a communication device provided by the embodiment of the application, when the communication device has the function of the key negotiation device described in the embodiment of the application, the communication device can be a key verification device, or a component or device (for example, a processor, a chip, or a chip system, etc.) applied to the key verification device, can be a logical module or software capable of implementing all or part of the function of the key verification device, and can also be a device used in matching with the key verification device. When the communication device has the function of the key verification device described in the embodiment of the application, the communication device can be a key negotiation device, or a component or device (for example, a processor, a chip, or a chip system, etc.) applied to the key negotiation device, can also be a logical module or software capable of implementing all or part of the function of the key negotiation device, and can also be a device used in matching with the key verification device.

[0193] For example, Figure 12A structural diagram of a possible communication apparatus is shown. It can be understood that the communication apparatus 110 includes necessary forms of means, such as modules, units, elements, circuits, or interfaces, and the like, which are configured to be appropriately arranged together to perform the present solution. The communication apparatus 110 can be the key negotiation apparatus or the key verification apparatus described in the above method embodiments, or can be a component (for example, a chip) of the apparatus, to implement the methods described in the above method embodiments. The communication apparatus 110 includes one or more processors 1101. The processor 1101 can be a general purpose processor or a special purpose processor, and the like. For example, it can be a baseband processor or a central processing unit. The baseband processor can be used to process communication protocols and communication data, and the central processing unit can be used to control the communication apparatus, execute software programs, and process data of the software programs.

[0194] Optionally, in a design, the processor 1101 can include a program 1103 (which can also be referred to as code or instructions at times), which can be run on the processor 1101, so that the communication apparatus 110 performs the methods described in the above embodiments. Wherein, the processor 1101 including the program 1103 can be that the processor 1101 can be used to store the program 1103, for example, by a memory integrated in the processor 1101.

[0195] Optionally, the communication apparatus 110 can include one or more memories 1102, which have a program 1104 (which can also be referred to as code or instructions at times) stored thereon, which can be run on the processor 1101, so that the communication apparatus 110 performs the methods described in the above method embodiments. Optionally, the memory 1102 can also be located outside the communication apparatus.

[0196] Optionally, the processor 1101 and / or the memory 1102 can include an AI module 1107, 1108, which is used to implement AI-related functions. The AI module can be implemented in a software, hardware, or software-hardware combined manner. For example, the AI module can include a RIC module. For example, the AI module can be a near-real-time RIC or a non-real-time RIC.

[0197] Optionally, the processor 1101 and / or the memory 1102 can also store data. The processor and the memory can be separately arranged, or can be integrated together.

[0198] Optionally, the communication apparatus 110 can further include a transceiver 1105 and / or an antenna 1106. The processor 1101 can also be referred to as a processing unit, which controls the communication apparatus. The transceiver 1105 can also be referred to as a transceiving unit, a transceiver, a transceiving circuit, or a transceiver, etc., which is used to realize the transceiving function of the communication apparatus through the antenna 1106.

[0199] Figure 12 A structural diagram of a communication apparatus 120 applied to a key verification apparatus is shown. Figure 13 The modules in the apparatus shown have the functions of implementing the corresponding steps in the above method embodiments and can achieve their corresponding technical effects. The beneficial effects of the steps performed by the modules can be referred to the descriptions of the corresponding steps in the above method embodiments, which will not be repeated. The functions can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions. The communication apparatus can be a key verification apparatus or a chip or system on chip in the key verification apparatus. For example, the apparatus includes:

[0200] A processing module 1201 is configured to obtain first verification information of a first key and second verification information of a second key, the first verification information and the second verification information being used to determine consistency of the first key and the second key.

[0201] A transceiving module 1202 is configured to send first information based on the first verification information and the second verification information, the first information being used to indicate adjustment of at least one of the following: a parameter of a verification key or a parameter of a generated key.

[0202] In an embodiment, the parameter of the verification key includes a key verification length; and the parameter of the generated key includes a quantization threshold for generating the key and / or a quantization bit number for generating the key.

[0203] In an embodiment, the first information is used to indicate at least one of the following: reduction of the key verification length, increase of the quantization threshold for generating the key, or reduction of the quantization bit number for generating the key; or the first information is used to indicate at least one of the following: increase of the key verification length, reduction of the quantization threshold for generating the key, or increase of the quantization bit number for generating the key.

[0204] In an embodiment, the transceiving module 1202 is specifically configured to send the first information in a case where the first verification information and the second verification information are inconsistent, the first information being used to indicate at least one of the following: reduction of the key verification length, increase of the quantization threshold for generating the key, or reduction of the quantization bit number for generating the key.

[0205] In an embodiment, the processing module 1201 is further configured to obtain at least one third check information and at least one fourth check information, the third check information and the fourth check information being used to determine consistency of the first key and the second key. The transceiver module 1202 is configured to: in a case where a proportion of consistent check information in the first check information set and the second check information set meets a preset condition, send first information, the first check information set comprising the first check information and the at least one third check information, the second check information set comprising the second check information and the at least one fourth check information, the first information being used to indicate at least one of the following: increasing a key verification length, reducing a quantization threshold used to generate a key, or increasing a quantization bit number used to generate a key.

[0206] In an embodiment, the processing module 1201 is further configured to determine an adjustment margin of a parameter according to a difference between the parameter of the first key and a corresponding preset parameter value, the parameter comprising at least one of the following: a parameter of a verification key or a parameter of a generated key; or determine an adjustment margin of a parameter according to a difference between the parameter of the second key and a corresponding preset parameter value, the parameter comprising at least one of the following: a parameter of a verification key or a parameter of a generated key; and determine the first information according to the first check information, the second check information, and the adjustment margin of the parameter.

[0207] In an embodiment, the first information comprises at least one of the following: an adjustment value of a parameter of a verification key or an adjustment value of a parameter of a generated key; or the first information comprises at least one of the following: a value of an adjusted parameter of a verification key or a value of an adjusted parameter of a generated key.

[0208] In an embodiment, the apparatus is a first communication apparatus.

[0209] In an embodiment, the apparatus is a third communication apparatus; and the transceiver module 1202 is configured to send, based on the first check information and the second check information, the first information to a first communication apparatus and a second communication apparatus, the first communication apparatus being an apparatus for generating the first key, and the second communication apparatus being an apparatus for generating the second key.

[0210] Figure 13 A structural diagram of a communication apparatus 130 is shown, which is applied to a key negotiation apparatus. ​The modules in the apparatus shown have the functions of implementing the corresponding steps in the above method embodiments and can achieve their corresponding technical effects. The beneficial effects of the steps performed by the modules can be referred to the descriptions of the corresponding steps in the above method embodiments, which will not be repeated. The functions can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions. The communication apparatus can be a key negotiation apparatus or a chip or system on chip in the key negotiation apparatus. For example, the apparatus includes:

[0211] The transceiver module 1301 is configured to send the verification information of the second key, and the verification information of the key is used to verify the consistency of the second key and the first key. The transceiver module 1301 is configured to receive the first information, and the first information is used to indicate adjustment of at least one of the following: a parameter for verifying the key or a parameter for generating the key.

[0212] In an embodiment, the apparatus further includes a processing module 1302 configured to generate a new key according to the first information.

[0213] In an embodiment, the parameter for verifying the key includes a key verification length, and the parameter for generating the key includes a quantization threshold for generating the key and / or a quantization bit number for generating the key.

[0214] In an embodiment, the first information includes at least one of the following: an adjustment value of the parameter for verifying the key or an adjustment value of the parameter for generating the key; or the first information includes at least one of the following: an adjusted parameter for verifying the key or an adjusted parameter for generating the key.

[0215] In an embodiment, the first information is used to indicate at least one of the following: increasing the key verification length, decreasing the quantization threshold for generating the key, or increasing the quantization bit number for generating the key; or the first information is used to indicate at least one of the following: decreasing the key verification length, increasing the quantization threshold for generating the key, or decreasing the quantization bit number for generating the key.

[0216] Embodiments of the present application also provide a communication system, which is a communication system corresponding to a high-speed private network information transmission scenario of a neighboring area. The communication system can include a key negotiation apparatus and a key verification apparatus. The key negotiation apparatus can have the functions of the communication apparatus 120 described above, and the key verification apparatus can have the functions of the communication apparatus 130 described above.

[0217] The embodiments of the present application further provide a computer readable storage medium. All or part of the processes in the above method embodiments can be instructed by a computer program to relevant hardware to complete, and the program can be stored in the computer readable storage medium. When the program is executed, the program can include the processes of the above method embodiments. The computer readable storage medium can be the communication device of any of the above embodiments, such as an internal storage unit including a data sending end and / or a data receiving end, for example, a hard disk or a memory of the communication device. The computer readable storage medium can also be an external storage device of the communication device, for example, a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, and the like. Further, the computer readable storage medium can include both the internal storage unit and the external storage device of the communication device. The computer readable storage medium is used to store the computer program and other programs and data required by the communication device. The computer readable storage medium can also be used to temporarily store data that has been output or will be output.

[0218] The embodiments of the present application further provide a computer instruction. All or part of the processes in the above method embodiments can be instructed by the computer instruction to relevant hardware (such as a computer, a processor, a network device, and a terminal, etc.) to complete. The program can be stored in the above computer readable storage medium.

[0219] The embodiments of the present application further provide a computer program product, which, when running on a computer, causes the computer to perform the functions or steps of the communication device in the above method embodiments.

[0220] The embodiments of the present application further provide a chip system. The chip system can be composed of a chip, or can include a chip and other discrete devices, without limitation. The chip system includes a processor and a transceiver. All or part of the processes in the above method embodiments can be completed by the chip system, for example, the chip system can be used to implement the functions performed by the key verification device in the above method embodiments, or implement the functions performed by the key negotiation device in the above method embodiments.

[0221] In a possible design, the chip system further includes a memory, configured to store program instructions and / or data. When the chip system is running, the processor executes the program instructions stored in the memory, so that the chip system performs the functions performed by the key verification device in the above method embodiments or performs the functions performed by the key negotiation device in the above method embodiments.

[0222] In the embodiments of the present application, the processor can be one or more central processing units (CPUs). The processor can include one or more combinations of a central processing unit (CPU), an application-specific integrated circuit (ASIC), a digital signal processor (DSP), a microprocessor unit (MPU), a microcontroller unit (MCU), a graphics processing unit (GPU), a field programmable gate array (FPGA), an artificial intelligence processor (AI processor), or a neural processing unit (NPU).

[0223] In the case of a CPU, the CPU can be a single core CPU or a multi-core CPU. The processor can be a general purpose processor, a digital signal processor, an application specific integrated circuit, a field programmable gate array or other programmable logic device, a discrete gate or transistor logic component, a discrete hardware component, and can implement or execute the methods, steps and logic block diagrams disclosed in the embodiments of the present application. The general purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in conjunction with the embodiments of the present application can be directly embodied as hardware processor execution or executed by a combination of hardware and software modules in the processor.

[0224] In the embodiments of the present application, the memory can include, but is not limited to, a cache, a read-only memory (ROM), a random access memory (RAM), a synchronous dynamic random access memory (SDRAM), a hard disk drive (HDD) or a solid-state drive (SSD), an erasable programmable ROM (EPROM), or a compact disc read-only memory (CD-ROM), and the like. The memory is any other medium capable of storing or carrying the desired program code in the form of instructions or data structures and accessible by a computer, but is not limited thereto. The memory in the embodiments of the present application can also be a circuit or any other device capable of realizing a storage function, used for storing computer programs or instructions, and / or data.

[0225] It should be noted that the terms "first" and "second" and the like in the specification of the present application, claims and drawings are used to distinguish different objects, and are not intended to describe a specific order. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units is not limited to the listed steps or units, but can optionally include steps or units not listed, or can optionally include other steps or units inherent to the process, method, product or device.

[0226] It should be understood that in the embodiments of the present application, "at least one" refers to one or more, "multiple" refers to two or more, "at least two" refers to two or three and three or more, and "and / or" is used to describe the association relationship of the associated objects, which means that there can be three relationships, for example, "A and / or B" can mean: only A, only B, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally represents an "or" relationship between the associated objects before and after it. "At least one of the following" or similar expressions means any combination of these items, including any combination of single item or multiple items. For example, at least one of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple. It should be understood that in the embodiments of the present application, "B corresponding to A" means that B is associated with A. For example, B can be determined according to A. It should also be understood that determining B according to A does not mean that B is determined only according to A, but B can also be determined according to A and / or other information. In addition, "connection" appearing in the embodiments of the present application means direct connection or indirect connection and various connection manners to achieve communication between devices, which is not limited by the embodiments of the present application.

[0227] Unless otherwise specified, "transmit" and "transmission" appearing in the embodiments of the present application mean bidirectional transmission, including sending and / or receiving actions. Specifically, "transmit" in the embodiments of the present application includes data sending, data receiving, or data sending and data receiving. Or, the data transmission here includes uplink and / or downlink data transmission. The data can include channels and / or signals, uplink data transmission is uplink channel and / or uplink signal transmission, and downlink data transmission is downlink channel and / or downlink signal transmission. "Network" and "system" appearing in the embodiments of the present application express the same concept, and the communication system is a communication network.

[0228] Through the description of the above embodiments, those skilled in the art can clearly understand that, for the convenience and brevity of description, only the division of the above functional modules is taken as an example for illustration, and in actual application, the above functions can be completed by different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above.

[0229] In several embodiments provided in the present application, it should be understood that the disclosed apparatus and method can be implemented by other manners. For example, the apparatus embodiments described above are merely illustrative, for example, the division of the modules or units is merely a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another apparatus, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units or components shown or discussed can be indirect coupling or communication connection through some interfaces, apparatuses or units, and can be electrical, mechanical or other forms.

[0230] The units described as separate components can or can not be physically separate, and the components shown as units can be one physical unit or multiple physical units, that is, can be located in one place, or can be distributed to multiple different places. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment scheme.

[0231] In addition, each functional unit in each embodiment of the present application can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit. When the integrated unit is realized in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solutions of the embodiments of the present application essentially or say the part that contributes to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product, which is stored in a storage medium and includes a plurality of instructions for causing an apparatus, such as a single-chip microcomputer, a chip, or a processor, to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a ROM, a RAM, a magnetic disk or an optical disk, and various storage media that can store program codes.

[0232] The above is merely a specific implementation manner of the present application, but the protection scope of the present application is not limited thereto, and any change or replacement within the technical scope disclosed in the present application should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A communication method characterized by comprising: The method comprises: obtaining first check information of a first key and second check information of a second key, the first check information and the second check information being used to determine consistency of the first key and the second key; based on the first check information and the second check information, sending first information, the first information being used to indicate adjustment of at least one of the following: a parameter of a verification key or a parameter of a generated key.

2. The method of claim 1, wherein the parameter of the verification key comprises a key verification length; the parameter of the generated key comprises a quantization threshold for generating a key and / or a quantization bit number for generating a key.

3. The method according to claim 1 or 2, characterized in that, the first information is used to indicate at least one of the following: a decrease in the key verification length, an increase in the quantization threshold for generating a key, or a decrease in the quantization bit number for generating a key; alternatively, the first information is used to indicate at least one of the following: an increase in the key verification length, a decrease in the quantization threshold for generating a key, or an increase in the quantization bit number for generating a key.

4. The method according to any one of claims 1 to 3, characterized in that, the sending of the first information based on the first check information and the second check information comprises: in the case where the first check information and the second check information are inconsistent, sending the first information, the first information being used to indicate at least one of the following: a decrease in the key verification length, an increase in the quantization threshold for generating a key, or a decrease in the quantization bit number for generating a key.

5. The method according to any one of claims 1 to 3, characterized in that, The method further comprises: obtaining at least one third check information and at least one fourth check information, the third check information and the fourth check information being used to determine consistency of the first key and the second key; the sending of the first information based on the first check information and the second check information comprises: in the case where a proportion of consistent check information in a first check information set and a second check information set meets a preset condition, sending the first information, the first check information set comprising the first check information and the at least one third check information, the second check information set comprising the second check information and the at least one fourth check information, the first information being used to indicate at least one of the following: an increase in the key verification length, a decrease in the quantization threshold for generating a key, or an increase in the quantization bit number for generating a key.

6. The method according to any one of claims 1 to 5, characterized in that, The method further comprises: determining an adjustment margin of a parameter according to a difference between the parameter of the first key and a corresponding preset parameter value, the parameter comprising at least one of the following: a parameter of a verification key or a parameter of a generated key; or determining an adjustment margin of a parameter according to a difference between the parameter of the second key and a corresponding preset parameter value, the parameter comprising at least one of the following: a parameter of a verification key or a parameter of a generated key; determining the first information according to the first check information, the second check information, and the adjustment margin of the parameter.

7. The method according to any one of claims 1 to 6, characterized in that, the first information comprises at least one of the following: an adjustment value of the parameter of the verification key or an adjustment value of the parameter of the generated key; Or, the first information comprises at least one of: an adjusted value of the parameter of the verification key, or an adjusted value of the parameter of the generation key.

8. The method according to any one of claims 1 to 7, characterized in that, The method is applied to a first communication device; The method comprises: The first communication device obtains the first check information of the first key and the second check information of the second key, the first communication device being a communication device for generating the first key, and a communication device for generating the second key being a second communication device; The method comprises: The first communication device sends the first information to the second communication device based on the first check information and the second check information.

9. The method according to any one of claims 1 to 7, characterized in that, The method is applied to a third communication device; The method comprises: The third communication device sends the first information to the first communication device and the second communication device based on the first check information and the second check information, the first communication device being a device for generating the first key, and the second communication device being a device for generating the second key.

10. A communication method characterized by comprising: The method comprises: The method comprises: The method further comprises:

11. The method of claim 10, wherein, The method further comprises: The parameter of the verification key comprises a key verification length, and the parameter of the generation key comprises a quantization threshold for generating a key and / or a quantization bit number for generating a key.

12. The method according to claim 10 or 11, characterized in that, The first information comprises at least one of: an adjusted value of the parameter of the verification key, or an adjusted value of the parameter of the generation key.

13. The method according to any one of claims 10-12, characterized in that, The first information is used to indicate at least one of: increasing the key verification length, decreasing the quantization threshold for generating a key, or increasing the quantization bit number for generating a key. Or, the first information is used to indicate at least one of: decreasing the key verification length, increasing the quantization threshold for generating a key, or decreasing the quantization bit number for generating a key.

14. The method according to any one of claims 10 to 13, characterized in that, The communication device comprises a processor for causing the communication device to perform the method according to any one of claims 1-14 by means of a logic circuit and / or by executing a program stored in a memory. The communication device further comprises the memory.

15. A communications device, characterized by ​ 16. A communications device, characterized by ​ 17. The communication apparatus according to claim 16, wherein ​ 18. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer instructions that, when executed, cause the method of any of claims 1-14 to be performed.

19. A computer program product comprising instructions, characterized in that, When executed on a computer, cause the method of any of claims 1-14 to be performed.