A data transmission encryption method and system for 5G networks
By leveraging the uplink and downlink reciprocity under TDD co-frequency and co-beam in 5G networks, the correlation characteristics of CSI-RS and SRS are extracted to achieve key consistency correction, solving the latency and overhead problems introduced by key replacement and improving the stability and security of data transmission.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-29
- Publication Date
- 2026-03-13
AI Technical Summary
In 5G networks, existing technologies frequently change keys during session duration, leading to additional handshakes that introduce round-trip latency and control plane overhead, causing brief pauses in the data plane and fluctuations in throughput, especially in TDD and OFDM frame structure systems, which affects transmission efficiency.
Based on the uplink and downlink reciprocity under TDD co-frequency and co-beam, the correlation between adjacent CSI-RS and SRS is utilized. Decorative real-valued features are extracted through amplitude/phase adjacent-frequency differential. Combined with bit quantization and error correction verification features, key consistency correction is achieved, and key generation is completed without additional round trips and signaling.
It significantly reduces latency and overhead during key replacement, improves the unpredictability and resistance to attacks in key generation, and ensures the stability and efficiency of data transmission.
Smart Images

Figure CN121418813B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data transmission technology, and specifically to a data transmission encryption method and system for 5G networks. Background Technology
[0002] During encrypted data transmission, due to security policies and compliance requirements (such as key reuse counts reaching the counter limit, periodic updates of operator configurations), network events (such as base station handover, session channel reconstruction), and anomaly handling (triggering data transmission security issues), keys must be changed multiple times during the session. Existing technologies generally rely on upper-layer security modes and key update procedures such as RRC / PDCP to complete key changes, requiring additional round-trip handshakes and version negotiation and confirmation. This process introduces at least one round-trip delay, and to avoid decryption failures and retransmissions caused by inconsistencies between the old and new keys, the sending and receiving ends typically adopt conservative scheduling strategies before and after the handover boundary, causing a brief pause in the data plane. In systems using TDD and OFDM frame structures, this pause manifests as multiple time slots idling or low-load occupancy, thus interrupting continuous scheduling and causing throughput fluctuations and latency jitter. Especially under the high transmission characteristics of 5G, key changes are triggered more frequently, further amplifying the control plane overhead and energy consumption caused by the additional handshake. Summary of the Invention
[0003] This invention is based on the uplink and downlink reciprocity under TDD co-frequency and co-beam. According to the correlation between adjacent CSI-RS and SRS during the coherence time and the corresponding channel response, it extracts decorrelation real-valued features through amplitude / phase adjacent-frequency differential, without adding extra round trips. Then, error correction is performed through bit quantization and error correction verification features embedded in the control command transmission. This allows the base station to complete the consistency correction of the bit string sequence without adding any round trips or new signaling. Finally, based on the corrected uplink bit string sequence and the uplink bit string sequence, a key seed and the key required for data encryption transmission are constructed. Compared with the traditional key exchange method that requires additional handshake and confirmation, it achieves zero additional security handshake and zero extra round trips, significantly reducing latency and overhead.
[0004] This invention provides a data transmission encryption method for 5G networks, comprising:
[0005] Step S1: During the data transmission process using TDD, uplink channel measurement and downlink channel measurement that meet the time interval constraints are performed. The terminal side obtains the downlink complex channel vector, and the base station side obtains the uplink complex channel vector.
[0006] Step S2: On the base station side and the terminal side, construct corresponding channel mask sequences based on the key seed generated in the previous round, the channel mask sequence from the previous round, and the check error vector from the previous round, respectively. The channel mask sequence has the same dimension as the uplink complex channel vector and the downlink complex channel vector. The channel mask sequence stores several 0s or 1s. If the data corresponding to the subcarrier index in the uplink complex channel vector participated in the subsequent key generation operation in the previous round, then the data corresponding to the subcarrier index in the channel mask sequence is 1, otherwise it is 0. Then, perform filtering operations on the uplink complex channel vector and the downlink complex channel vector using the corresponding channel mask sequences to obtain the uplink complex channel subset vector and the downlink complex channel subset vector.
[0007] Step S3: Perform feature extraction and decorrelation operations on the uplink complex channel subset vector and the downlink complex channel subset vector on the base station side and the terminal side respectively to obtain the corresponding uplink real-valued vector and downlink real-valued vector of the same dimension on both sides.
[0008] Step S4: Quantize the uplink real-valued vector and the downlink real-valued vector into uplink bit string sequences and downlink bit string sequences, respectively, and construct the error correction and verification features corresponding to the downlink real-valued vector based on the downlink real-valued vector;
[0009] Step S5: On the terminal side, the error correction check feature is added to the next control command to be sent, and the control command with the added error correction check feature is sent to the base station side. The base station side corrects the uplink bit string sequence according to the error correction check feature to obtain the corrected uplink bit string sequence and the check error vector.
[0010] In step S6, the base station and the terminal respectively process the corrected uplink bit string sequence and the uplink bit string sequence using a secure hash algorithm to generate corresponding key seeds, and then construct the key required for data encryption transmission through a key derivation function.
[0011] As a preferred aspect, uplink channel measurements and downlink channel measurements that conform to time interval constraints are performed, so that the terminal side obtains the downlink complex channel vector and the base station side obtains the uplink complex channel vector. Specifically, this includes the following steps:
[0012] Step S1.1: On the base station side, traverse the orthogonal frequency division multiplexing (OFDM) symbols on the time axis after the current system time on the base station side, and determine the downlink reference signal transmission time window and uplink reference signal transmission time window that meet the time interval constraint and symbol constraint. The OFDM symbols include uplink, downlink, and flexible. Meeting the time interval constraint means that the interval between the downlink reference signal transmission time window and the uplink reference signal transmission time window satisfies t < β·Tc, where t is the interval between the downlink reference signal transmission time window and the uplink reference signal transmission time window, β is the attention coefficient, and Tc is the coherence time. The symbol constraint means that the OFDM symbols corresponding to the time of the downlink reference signal transmission time window and the uplink reference signal transmission time window are downlink and uplink. Determine the reference signal configuration resources corresponding to the downlink reference signal transmission time window and the uplink reference signal transmission time window. Then, determine the downlink reference signal sequence based on the reference signal configuration resources.
[0013] Step S1.2: On the base station side, the downlink control command before the downlink reference signal transmission time window is recorded as the target control command, and reference signal configuration resources are added to the target control command before the target control command is sent to the terminal side. Then the target control command with added reference signal configuration resources is sent to the terminal side. After that, the downlink reference signal sequence is sent to the terminal side during the downlink reference signal transmission time window.
[0014] Step S1.3: On the terminal side, the reference signal configuration resources are determined according to the target control command, the downlink reference signal sequence is received according to the reference signal configuration resources, the corresponding channel response is determined, the downlink complex channel vector is obtained, the downlink reference signal sequence is determined according to the reference signal configuration resources, and then the downlink reference signal sequence is sent to the base station side during the uplink reference signal transmission time window.
[0015] Step S1.4: On the base station side, the uplink reference signal sequence is received according to the reference signal configuration resources, and the corresponding channel response is determined to obtain the uplink complex channel vector.
[0016] As a preferred aspect, on both the base station and terminal sides, corresponding channel mask sequences are constructed based on the key seed generated in the previous round, the channel mask sequence from the previous round, and the check error vector from the previous round, respectively. Then, filtering operations are performed on the uplink complex channel vector and the downlink complex channel vector using the corresponding channel mask sequences to obtain the uplink complex channel subset vector and the downlink complex channel subset vector, specifically including the following steps:
[0017] Step S2.1: On the base station side and the terminal side, the key seed generated in the previous round, the channel mask sequence in the previous round, the check error vector in the previous round, the round number and the reference signal configuration resource number stored locally are concatenated into the mask calculation input information. Then, the key derivation function is called to process the mask calculation input information to obtain the mask seed.
[0018] Step S2.2: On both the base station and terminal sides, a pseudo-random sequence generator is driven by a mask seed to generate candidate channel mask sequences. The difference between the candidate channel mask sequence and the channel mask sequence from the previous round is calculated. Specifically, the candidate channel mask sequence and the channel mask sequence from the previous round are matched item by item, where each item is data from either the candidate or previous round channel mask sequence. The ratio between the number of different items and the total number of items in the candidate channel mask sequence is counted and recorded as the difference. The difference is then compared with a difference threshold. If the difference is higher than the threshold, the candidate channel mask sequence is directly output as the channel mask for the current round. For the code sequence, proceed to step S2.3. If the difference is not higher than the difference threshold, traverse the candidate channel mask sequence from front to back, record the number h corresponding to the first candidate channel mask sequence encountered and the channel mask sequence of the previous round that are both 1, and replace the h-th item from front to back in the candidate channel mask sequence with 0. Then traverse the candidate channel mask sequence from back to front, record the number g corresponding to the first candidate channel mask sequence encountered and the channel mask sequence of the previous round that are both 0, and replace the g-th item from back to front in the candidate channel mask sequence with 0. Then judge the difference and the difference threshold again until the difference is higher than the difference threshold.
[0019] Step S2.3: On the base station side and the terminal side, filtering operations are performed on the uplink complex channel vector and the downlink complex channel vector respectively through the channel mask sequence. Specifically, the filtering operation is as follows: record the set of valid positions corresponding to the positions where the item is 1 in the channel mask sequence, and retain the data corresponding to the positions in the valid position set in the uplink complex channel vector and the downlink complex channel vector. Record the set of invalid positions corresponding to the positions where the item is 0 in the channel mask sequence, and delete the data corresponding to the positions in the invalid position set in the uplink complex channel vector and the downlink complex channel vector, so as to obtain the uplink complex channel subset vector and the downlink complex channel subset vector.
[0020] As a preferred aspect, feature extraction and decorrelation operations are performed on the uplink complex channel subset vector and the downlink complex channel subset vector at the base station side and the terminal side, respectively, to obtain corresponding uplink real-valued vectors and downlink real-valued vectors of the same dimension on both sides, specifically including the following:
[0021] For the uplink complex channel subset vector, extract the corresponding neighborhood amplitude difference features and neighborhood phase difference features. Then, concatenate the extracted neighborhood amplitude difference features and neighborhood phase difference features from the uplink complex channel subset vector and perform a decorrelation operation to obtain the corresponding uplink real-valued vector. For the downlink complex channel subset vector, extract the corresponding neighborhood amplitude difference features and neighborhood phase difference features. Then, concatenate the extracted neighborhood amplitude difference features and neighborhood phase difference features from the downlink complex channel subset vector and perform a decorrelation operation to obtain the corresponding downlink real-valued vector.
[0022] As a preferred aspect, the uplink real-valued vector and the downlink real-valued vector are quantized into uplink bit string sequences and downlink bit string sequences, respectively, and error correction and detection features corresponding to the downlink real-valued vector are constructed based on the downlink real-valued vector. Specifically, this includes the following steps:
[0023] Step S4.1: On the base station side, traverse the elements in the uplink real value vector and execute the threshold judgment rule. The threshold judgment rule is that if the absolute value of the element value is greater than the threshold value, the output bit is 1; if the absolute value of the element value is not greater than the threshold value, the output bit is 0. Bits corresponding to 0 and 1 are both considered valid. Divide the bits corresponding to the elements in the uplink real value vector according to a fixed window size to obtain uplink bit sequence groups. If the number of uplink bit sequence groups obtained by the division reaches the preset value, output all uplink bit sequence groups and concatenate the valid bits in all uplink bit sequence groups to obtain the uplink bit string sequence. If the number of downlink bit sequence groups obtained by the division does not reach the preset value, return directly to step S1 and execute the next round of measurement.
[0024] Step S4.2: On the terminal side, traverse the elements in the downlink real-valued vector and execute the threshold judgment rule. Divide the bits corresponding to the elements in the downlink real-valued vector according to a fixed window size to obtain downlink bit sequence groups. If the number of downlink bit sequence groups obtained by the division reaches a preset value, output all downlink bit sequence groups and concatenate the valid bits in all downlink bit sequence groups to obtain a downlink bit string sequence. If the number of downlink bit sequence groups obtained by the division does not reach the preset value, return directly to step S1 and execute the next round of measurement. Furthermore, process each downlink bit sequence group through a low-density parity-check code algorithm, output the redundancy code corresponding to each downlink bit sequence group, and then form an error correction check feature from the redundancy codes corresponding to all downlink bit sequence groups.
[0025] As a preferred aspect, the base station corrects the uplink bit string sequence based on the error correction verification characteristics to obtain the corrected uplink bit string sequence and the verification error vector, specifically including the following steps:
[0026] Step S5.1: On the base station side, the error correction verification feature is obtained according to the control command with added error correction verification feature. Based on the error correction verification feature, the uplink bit string sequence is corrected by the low-density parity check code algorithm. If the correction is successful, the corrected uplink bit string sequence and the verification error vector are output. The dimension of the verification error vector is the same as that of the uplink bit string sequence. The verification error vector stores several 0s or 1s. 1 in the verification error vector indicates that the corresponding position of the uplink bit string sequence has been corrected, and 0 in the verification error vector indicates that the corresponding position of the uplink bit string sequence has not been corrected, so that the corrected uplink bit string sequence and the uplink bit string sequence have consistency. If the correction fails, return directly to step S1 and execute the next round of measurement.
[0027] As a preferred aspect, determining the downlink reference signal sequence based on the reference signal configuration resources specifically involves generating the corresponding downlink reference signal sequence according to the CSI-RS standard, and determining the uplink reference signal sequence based on the reference signal configuration resources specifically involves generating the corresponding uplink reference signal sequence with reference to the SRS standard, wherein both the CSI-RS standard and the SRS standard are 3GPP NR physical layer standards.
[0028] This invention also provides a data transmission encryption system for 5G networks, comprising:
[0029] The channel measurement module is used to perform uplink channel measurement and downlink channel measurement that meet the time interval constraints. The terminal side obtains the downlink complex channel subset vector, and the base station side obtains the uplink complex channel subset vector.
[0030] The filtering module is used to construct corresponding channel mask sequences on the base station side and the terminal side, respectively, based on the key seed generated in the previous round, the channel mask sequence of the previous round, and the check error vector of the previous round. The channel mask sequence has the same dimension as the uplink complex channel vector and the downlink complex channel vector. The channel mask sequence stores several 0s or 1s. If the data corresponding to the subcarrier index in the uplink complex channel vector participated in the subsequent key generation operation in the previous round, the data corresponding to the subcarrier index in the channel mask sequence is 1, otherwise it is 0. The filtering module performs filtering operations on the uplink complex channel vector and the downlink complex channel vector respectively through the corresponding channel mask sequence to obtain the uplink complex channel subset vector and the downlink complex channel subset vector.
[0031] The real-valued vector construction module is used to perform feature extraction and decorrelation operations on the uplink complex channel subset vector and the downlink complex channel subset vector on the base station side and the terminal side, respectively, to obtain the corresponding uplink real-valued vector and downlink real-valued vector of the same dimension on both sides;
[0032] The bit quantization module is used to quantize the uplink real-valued vector and the downlink real-valued vector into uplink bit string sequences and downlink bit string sequences, respectively, and to construct the error correction and verification features corresponding to the downlink real-valued vector based on the downlink real-valued vector;
[0033] The bit unification module is used by the base station to correct the uplink bit string sequence based on the error correction and verification characteristics, so as to obtain the corrected uplink bit string sequence and the verification error vector.
[0034] The key construction module is used by the base station side and the terminal side to process the corrected uplink bit string sequence and the uplink bit string sequence respectively through a secure hash algorithm to generate the corresponding key seed, and then construct the key required for data encryption transmission through the key derivation function.
[0035] The present invention has the following advantages:
[0036] 1. This invention is based on the uplink and downlink reciprocity under TDD co-frequency and co-beam. According to the correlation between adjacent CSI-RS and SRS during the coherence time and the corresponding channel response, it extracts decorrelation real-valued features through amplitude / phase adjacent-frequency differential, without adding extra round trips. Then, error correction is performed through bit quantization and error correction verification features embedded in control command transmission, so that the base station can complete the consistency correction of the bit string sequence without adding any round trips or new signaling. Finally, based on the corrected uplink bit string sequence and the uplink bit string sequence, a key seed and the key required for data encryption transmission are constructed. Compared with the traditional key exchange method that requires additional handshake and confirmation, it achieves zero additional security handshake and zero extra round trips, significantly reducing latency and overhead.
[0037] 2. This invention constructs a mask seed using the key seed generated in the previous round, the channel mask sequence from the previous round, and the check error vector from the previous round. Under difference constraints, it constructs a channel mask sequence for performing filtering operations. This allows the selection of subcarrier indices in the complex channel subset vectors and downlink complex channel subset vectors that actually participate in key generation in each round to change with the key changes in the previous round. This makes it impossible to see the hidden mapping corresponding to the selection of subcarrier indices even if all CSI-RS / SRS are completely observed. It makes it difficult for attackers to conduct long-term eavesdropping, interference, or statistical inference on fixed subcarriers, thereby significantly improving the unpredictability and resistance to attacks in the key generation process without adding extra signaling. Attached Figure Description
[0038] Figure 1 This is a schematic diagram of the data transmission encryption system for 5G networks used in an embodiment of the present invention. Detailed Implementation
[0039] To enable those skilled in the art to better understand the technical solutions of this invention, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of this invention.
[0040] Example 1: A data transmission encryption method for 5G networks, comprising:
[0041] When a key exchange operation is triggered during a session, specifically in the following scenarios: base station handover, session channel link reconstruction, key reuse count reaching the counter limit, updates based on the operator's configured time period, and triggering data transmission security issues, the following operations are performed:
[0042] Step S1: During the data transmission process using TDD, uplink channel measurement and downlink channel measurement that meet the time interval constraints are performed. The terminal side obtains the downlink complex channel vector, and the base station side obtains the uplink complex channel vector.
[0043] Step S1.1: On the base station side, traverse the orthogonal frequency division multiplexing (OFDM) symbols on the time axis after the current system time on the base station side, and determine the downlink reference signal transmission time window and uplink reference signal transmission time window that meet the time interval constraint and symbol constraint. It should be noted that in the time division duplex (TDD) data transmission process, the time axis is divided into several time slots according to the subcarrier division interval, and each time slot is further divided into several time segments. Each time segment is marked by an OFDM symbol and an OFDM number. OFDM symbols include uplink, downlink, and flexible (both uplink and downlink are possible). The OFDM number is generally 0-13 in normal CP (cyclic prefix). Meeting the time interval constraint means that the interval between the downlink reference signal transmission time window and the uplink reference signal transmission time window needs to be much smaller than a small portion of the coherence time. The coherence time refers to the duration by which the channel is "almost unchanged" in time, used to maintain the correlation of channel amplitude and phase, and is generally set... The constraint condition is t < β·Tc, where t is the interval between the downlink reference signal transmission time window and the uplink reference signal transmission time window, β is the attention coefficient, set by the developers, usually set to 0.05, used to describe a small part of the coherence time, and Tc is the coherence time, usually calculated using the Clarke / Jakes model. The symbol constraint means that the orthogonal frequency division multiplexing symbols corresponding to the downlink and uplink reference signal transmission time windows are downlink and uplink, respectively. The reference signal configuration resources corresponding to the downlink and uplink reference signal transmission time windows are determined. It should be noted that the reference signal configuration resources include BWP (bandwidth portion) configuration information, RB (resource block) configuration information, port configuration information, and beam configuration information, etc. These configuration information specifies the specific specifications for the transmission of reference signals between the base station side and the terminal side, and these information are all determined by the backend configuration file. The downlink reference signal sequence is then determined based on the reference signal configuration resources.
[0044] It should be noted that after determining the BWP (Bandwidth Part), RB (Resource Block), port configuration information, and beam configuration information based on the reference signal configuration resources, the corresponding downlink reference signal sequence is generated according to the CSI-RS standard, specifically the 3GPP NR physical layer standard.
[0045] Step S1.2: On the base station side, the downlink control commands before the downlink reference signal transmission time window are recorded as target control commands. These control commands generally refer to the downlink control information (DCI) carried by the PDCCH. This is issued by the base station side, using different DCI formats to perform scheduling / triggering / power control / beam control, etc., on the terminal side. Reference signal configuration resources are added to the target control commands before they are sent to the terminal side. Then, the target control commands with added reference signal configuration resources are sent to the terminal side. Afterwards, the downlink reference signal sequence is sent to the terminal side within the downlink reference signal transmission time window. It should be noted that "trigger fields" (such as CSI request, SRS resource indication, TCI / power control / PUCCH resources, etc.) are reserved in the control commands. The scheduler can conveniently send the reference signal configuration resources along with the control commands it is about to send.
[0046] Step S1.3: On the terminal side, the reference signal configuration resources are determined according to the target control command, and the downlink reference signal sequence is received according to the reference signal configuration resources. The corresponding channel response is determined to obtain the downlink complex channel vector. When receiving the downlink reference signal sequence, the specific operation is to enable the bandwidth and port resources specified in the reference signal configuration resources, perform response analysis of the downlink reference signal sequence on the channel specified in the reference signal configuration resources, determine the uplink reference signal sequence according to the reference signal configuration resources, and then send the uplink reference signal sequence to the base station side in the uplink reference signal transmission time window.
[0047] It should be noted that the uplink reference signal sequence is determined by configuring resources based on the reference signal, specifically by generating the corresponding uplink reference signal sequence with reference to the SRS standard, which is the 3GPP NR physical layer standard.
[0048] Step S1.4: On the base station side, the uplink reference signal sequence is received according to the reference signal configuration resources, and the corresponding channel response is determined to obtain the uplink complex channel vector.
[0049] It should be noted that the specific process of determining the corresponding channel response is as follows: receiving the downlink reference signal sequence / uplink reference signal sequence and performing continuous complex baseband sampling to obtain a complex baseband sample stream; then performing cyclic prefix removal and Fourier transform on the complex baseband sample stream to output the corresponding frequency domain raster data; extracting the reference RB (resource unit) from the frequency domain raster data on the orthogonal frequency division multiplexing symbols carrying the reference signal; and performing least squares on the complex numbers read from the reference RB (resource unit) and the corresponding downlink reference signal sequence / uplink reference signal sequence to obtain the complex channel coefficients (amplitude and phase) corresponding to the reference RB (resource unit); subsequently, performing interpolation along the frequency domain to remove the common phase deviation of the orthogonal frequency division multiplexing symbols and the linear phase tilt caused by the residual frequency offset. The corresponding channel response is obtained. If the reference resource is configured as a multi-port, it needs to be merged by port. The channel response flattening is the corresponding uplink complex channel vector and downlink complex channel vector. The channel response can map the known symbols carried by the reference signal to the received observations one by one. First, a high-confidence complex channel gain is obtained on the reference resource elements. Then, through two-dimensional interpolation, denoising and phase error correction, it is finally organized into a complex channel vector with fixed order and dimension. The complex channel vector is actually a one-dimensional complex sequence arranged by subcarrier index, where each element represents the "effective link" response on the subcarrier. The measured uplink complex channel vector and downlink complex channel vector are aligned on resources such as BWP, subcarrier, port and RB, so they have reciprocity in TDD downlink / uplink.
[0050] Step S2: On the base station side and the terminal side, construct corresponding channel mask sequences based on the key seed generated in the previous round, the channel mask sequence from the previous round, and the check error vector from the previous round, respectively. The channel mask sequence has the same dimension as the uplink complex channel vector and the downlink complex channel vector. The channel mask sequence stores several 0s or 1s. If the data corresponding to the subcarrier index in the uplink complex channel vector participated in the subsequent key generation operation in the previous round, then the data corresponding to the subcarrier index in the channel mask sequence is 1, otherwise it is 0. Then, perform filtering operations on the uplink complex channel vector and the downlink complex channel vector using the corresponding channel mask sequences to obtain the uplink complex channel subset vector and the downlink complex channel subset vector.
[0051] Step S2.1: On the base station and terminal sides, the key seed generated in the previous round, the channel mask sequence of the previous round, the parity error vector of the previous round, the round number, and the reference signal configuration resource number stored locally are concatenated into the mask calculation input information. Then, the key derivation function is called to process the mask calculation input information to obtain the mask seed. The round number and the reference signal configuration resource number are both bit strings. The key derivation function here can use standard algorithms such as HKDF. One key derivation function is to use HKDF, first perform HKDF-Extract operation on the key seed generated in the previous round to generate an intermediate pseudo-random key PRK, and then perform HKDF-Expand operation on the output after concatenating PRK, the channel mask sequence of the previous round, and the parity error vector of the previous round. The expected output length can be set to 128 bits to obtain the mask seed. It should be noted that incorporating the channel mask sequence and the parity error vector of the previous round in the process of generating the mask seed can effectively improve the randomness of the mask seed.
[0052] Step S2.2: On the base station and terminal sides, a pseudo-random sequence generator is driven by a mask seed to generate candidate channel mask sequences. The difference between the candidate channel mask sequence and the channel mask sequence of the previous round is calculated. Specifically, the candidate channel mask sequence and the channel mask sequence of the previous round are matched item by item. Each item is data in either the candidate channel mask sequence or the channel mask sequence of the previous round. The ratio between the number of different items and the total number of items in the candidate channel mask sequence is counted and recorded as the difference. The difference reflects the degree of difference between the candidate channel mask sequence and the channel mask sequence of the previous round. The difference and the difference threshold are judged. The difference threshold is set by the operator. If the difference is higher than the difference threshold, it means that the degree of difference between the candidate channel mask sequence and the channel mask sequence of the previous round exceeds the expectation. The candidate channel mask sequence is directly output as the channel mask sequence of the current round, and the process proceeds to step S2.3. If the difference is not higher than the difference threshold, the candidate channel masks are traversed from front to back. The sequence records the number h corresponding to the first encountered candidate channel mask sequence and the channel mask sequence of the previous round where both are 1. The h-th item from the beginning of the candidate channel mask sequence is replaced with 0. The candidate channel mask sequence is traversed from the end to the beginning, and the number g corresponding to the first encountered candidate channel mask sequence and the channel mask sequence of the previous round where both are 0 is recorded. The g-th item from the end of the candidate channel mask sequence is replaced with 0. This improves the difference degree while keeping the total number of subcarrier indexes selected constant. The difference degree and the difference degree threshold are judged again until the difference degree is higher than the difference degree threshold. The constraint of the difference degree ensures that the selection of subcarrier indexes in adjacent rounds has a sufficiently large degree of difference, reducing the correlation of subcarrier index selection, thereby improving the randomness and effective entropy of subsequent key generation, reducing the success rate of key cracking, and ensuring that the mask seed is consistent on both the base station side and the terminal side, the operations performed are consistent, and thus the subcarrier selection is also consistent.
[0053] Step S2.3: On the base station side and the terminal side, filtering operations are performed on the uplink complex channel vector and the downlink complex channel vector using the channel mask sequence, respectively. Specifically, the filtering operation involves recording the set of valid positions corresponding to the positions where an item is 1 in the channel mask sequence, retaining the data corresponding to the positions in the valid position sets of the uplink and downlink complex channel vectors, recording the set of invalid positions corresponding to the positions where an item is 0 in the channel mask sequence, and deleting the data corresponding to the positions in the invalid position sets of the uplink and downlink complex channel vectors, thus obtaining the uplink complex channel subset vector and the downlink complex channel subset vector. It should be noted that after the retention and deletion operations are completed, the uplink complex channel vector and the downlink complex channel vector... The remaining data in the vector are concatenated into the corresponding uplink complex channel subset vector and downlink complex channel subset vector according to the original subcarrier index order. By performing filtering operations on the uplink complex channel vector and downlink complex channel vector, the selection of subcarrier indexes in the complex channel subset vector and downlink complex channel subset vector that actually participate in key generation in each round can change with the key change in the previous round. This makes it impossible to see the hidden mapping corresponding to the selection of subcarrier indexes even if all CSI-RS / SRS are completely observed. It is difficult for attackers to conduct long-term listening, interference or statistical inference on fixed subcarriers, thereby significantly improving the unpredictability and resistance to attack of the key generation process without adding extra signaling.
[0054] Step S3: Perform feature extraction and decorrelation operations on the uplink complex channel subset vector and the downlink complex channel subset vector on the base station side and the terminal side respectively to obtain the corresponding uplink real-valued vector and downlink real-valued vector of the same dimension on both sides.
[0055] Step S4: Quantize the uplink real-valued vector and the downlink real-valued vector into uplink bit string sequences and downlink bit string sequences, respectively, and construct the error correction and verification features corresponding to the downlink real-valued vector based on the downlink real-valued vector;
[0056] Step S4.1: On the base station side, traverse the elements in the uplink real-value vector and execute the threshold judgment rule. The threshold judgment rule is: if the absolute value of the element value is greater than the threshold value, the output bit is 1; if the absolute value of the element value is not greater than the threshold value, the output bit is 0. Bits corresponding to 0 and 1 are both considered valid. The threshold value is set by the operator. During use, if there are many errors between the uplink bit string sequence and the downlink bit string sequence collected in the log, the threshold value needs to be adjusted appropriately to increase the threshold value. The bits corresponding to the elements in the uplink real-value vector are then processed according to a fixed... The window size is divided to obtain uplink bit sequence groups. The fixed window size is generally 224. If the number of uplink bit sequence groups obtained by the division reaches the preset value, which is set by the operator, all uplink bit sequence groups are output, and the valid bits in all uplink bit sequence groups are concatenated to obtain the uplink bit string sequence. If the number of downlink bit sequence groups obtained by the division does not reach the preset value, it means that the number of bits in the constructed bit string does not meet the expectations and is insufficient to meet the requirements of subsequent key seed generation. The process returns directly to step S1 and performs the next round of measurement.
[0057] Step S4.2: On the terminal side, traverse the elements in the downlink real-valued vector and execute the threshold judgment rule. The threshold judgment rule is that if the absolute value of the element value is greater than the threshold value, the output bit is 1; if the absolute value of the element value is not greater than the threshold value, the output bit is 0. Bits corresponding to 0 and 1 are both considered valid. Divide the bits corresponding to the elements in the downlink real-valued vector according to a fixed window size to obtain downlink bit sequence groups. If the number of downlink bit sequence groups obtained by the division reaches a preset value, output all downlink bit sequence groups and concatenate the valid bits in all downlink bit sequence groups to obtain a downlink bit string sequence. If the number of downlink bit sequence groups obtained by the division does not reach the preset value, return directly to step S1 and execute the next round of measurement. Furthermore, process each downlink bit sequence group using the low-density parity-check code (LDPC) algorithm, output the redundancy code corresponding to each downlink bit sequence group, and then form an error correction check feature from the redundancy codes corresponding to all downlink bit sequence groups.
[0058] Step S5: On the terminal side, the error correction check feature is added to the next control command to be sent, and the control command with the added error correction check feature is sent to the base station side. The base station side corrects the uplink bit string sequence according to the error correction check feature to obtain the corrected uplink bit string sequence and the check error vector.
[0059] Step S5.1: On the base station side, the error correction verification feature is obtained according to the control command with added error correction verification feature. Based on the error correction verification feature, the uplink bit string sequence is corrected by the low-density parity check code algorithm. If the correction is successful, the corrected uplink bit string sequence and the verification error vector are output. The dimension of the verification error vector is the same as that of the uplink bit string sequence. The verification error vector stores several 0s or 1s. 1 in the verification error vector indicates that the corresponding position of the uplink bit string sequence has been corrected, and 0 in the verification error vector indicates that the corresponding position of the uplink bit string sequence has not been corrected, so that the corrected uplink bit string sequence and the uplink bit string sequence have consistency. If the correction fails, it means that the noise between the channel responses is large and there is no uniformity, which is insufficient to meet the requirements of subsequent key seed generation. The process returns directly to step S1 and executes the next round of measurement.
[0060] It should be noted that adjacent CSI-RS and SRS are reciprocal under TDD with the same frequency and beam, meaning that the uplink and downlink of the same link should be the same (or highly consistent) within the same coherent block. Furthermore, the channel response of adjacent CSI-RS and SRS under TDD with the same frequency and beam is for the random data of the same instantaneous channel. By using differential characteristics that can cancel out non-reciprocal constants, both parties can obtain highly consistent real-valued sequences that are nearly unpredictable to external observations. After quantization, these sequences become secure seeds that can be used for key derivation.
[0061] In step S6, the base station side and the terminal side process the corrected uplink bit string sequence and the uplink bit string sequence respectively through a secure hash algorithm to generate the corresponding key seed. Then, the key required for data encryption transmission is constructed through the key derivation function. It should be noted that in TDD, data encryption generally adopts symmetric encryption.
[0062] It should be noted that during the key seed update process, no new session channel was established, and no round-trip handshake with back-and-forth queries was used. Instead, the existing uplink and downlink reference signals were reused (in the data transmission process, channel detection corresponding to the reference signals would normally be performed) and auxiliary information was piggybacked by control signals. This effectively reduced the time spent on round-trip handshakes with back-and-forth queries in the traditional key exchange process, reduced the overall latency, and ensured the stability of the 5G network during encrypted data transmission.
[0063] Feature extraction and decorrelation operations are performed on the uplink complex channel subset vector and the downlink complex channel subset vector on both the base station side and the terminal side to obtain the corresponding uplink real-valued vector and downlink real-valued vector of the same dimension on both sides. Specifically, the following are included:
[0064] For the uplink complex channel subset vector, extract the corresponding neighborhood amplitude difference features and neighborhood phase difference features. Then, concatenate the extracted neighborhood amplitude difference features and neighborhood phase difference features from the uplink complex channel subset vector and perform a decorrelation operation. Specifically, a discrete cosine transform can be used to obtain the corresponding uplink real-valued vector. For the downlink complex channel subset vector, extract the corresponding neighborhood amplitude difference features and neighborhood phase difference features. Then, concatenate the extracted neighborhood amplitude difference features and neighborhood phase difference features from the downlink complex channel subset vector and perform a decorrelation operation. Specifically, a discrete cosine transform can be used to obtain the corresponding downlink real-valued vector. It should be noted that, taking the uplink complex channel subset vector as an example, the neighborhood amplitude difference feature refers to the feature composed of the amplitude difference of all adjacent subcarriers, and the neighborhood phase difference feature refers to the feature composed of the phase difference of all adjacent subcarriers.
[0065] This application leverages the uplink and downlink reciprocity under TDD co-frequency and co-beam conditions. Based on the correlation between adjacent CSI-RS and SRS during the coherence time and the corresponding channel response, it extracts decorrelation real-valued features through amplitude / phase adjacent-frequency differential analysis without adding extra round trips. Error correction is then performed through bit quantization and error correction verification features embedded in control command transmission, enabling the base station to complete the consistency correction of the bit string sequence without adding any round trips or new signaling. Finally, based on the corrected uplink bit string sequence and the uplink bit string sequence, a key seed and the key required for encrypted data transmission are constructed. Compared with the traditional key exchange method that requires additional handshakes and confirmations, this application achieves zero additional security handshakes and zero extra round trips, significantly reducing latency and overhead.
[0066] Example 2: A data transmission encryption system for 5G networks, such as... Figure 1 As shown, it includes:
[0067] The channel measurement module is used to perform uplink channel measurement and downlink channel measurement that comply with time interval constraints during TDD data transmission. The terminal side obtains the downlink complex channel vector, and the base station side obtains the uplink complex channel vector.
[0068] The filtering module is used to construct corresponding channel mask sequences on the base station side and the terminal side, respectively, based on the key seed generated in the previous round, the channel mask sequence of the previous round, and the check error vector of the previous round. The channel mask sequence has the same dimension as the uplink complex channel vector and the downlink complex channel vector. The channel mask sequence stores several 0s or 1s. If the data corresponding to the subcarrier index in the uplink complex channel vector participated in the subsequent key generation operation in the previous round, the data corresponding to the subcarrier index in the channel mask sequence is 1, otherwise it is 0. The filtering module performs filtering operations on the uplink complex channel vector and the downlink complex channel vector respectively through the corresponding channel mask sequence to obtain the uplink complex channel subset vector and the downlink complex channel subset vector.
[0069] The real-valued vector construction module is used to perform feature extraction and decorrelation operations on the uplink complex channel subset vector and the downlink complex channel subset vector on the base station side and the terminal side, respectively, to obtain the corresponding uplink real-valued vector and downlink real-valued vector of the same dimension on both sides;
[0070] The bit quantization module is used to quantize the uplink real-valued vector and the downlink real-valued vector into uplink bit string sequences and downlink bit string sequences, respectively, and to construct the error correction and verification features corresponding to the downlink real-valued vector based on the downlink real-valued vector;
[0071] The bit unification module is used by the base station to correct the uplink bit string sequence based on the error correction and verification characteristics, so as to obtain the corrected uplink bit string sequence and the verification error vector.
[0072] The key construction module is used by the base station side and the terminal side to process the corrected uplink bit string sequence and the uplink bit string sequence respectively through a secure hash algorithm to generate the corresponding key seed. Then, the key required for data encryption transmission is constructed through the key derivation function. It should be noted that in TDD, data encryption generally adopts symmetric encryption.
[0073] It should be understood that those skilled in the art can make improvements or modifications based on the above description, and all such improvements and modifications should fall within the protection scope of the appended claims. Parts not described in detail in this specification are prior art known to those skilled in the art.
Claims
1. A data transmission encryption method for 5G networks, characterized in that, include: Step S1: During the data transmission process using TDD, uplink channel measurement and downlink channel measurement that meet the time interval constraints are performed. The terminal side obtains the downlink complex channel vector, and the base station side obtains the uplink complex channel vector. Step S2: On the base station side and the terminal side, construct corresponding channel mask sequences based on the key seed generated in the previous round, the channel mask sequence from the previous round, and the check error vector from the previous round, respectively. The channel mask sequence has the same dimension as the uplink complex channel vector and the downlink complex channel vector. The channel mask sequence stores several 0s or 1s. If the data corresponding to the subcarrier index in the uplink complex channel vector participated in the subsequent key generation operation in the previous round, then the data corresponding to the subcarrier index in the channel mask sequence is 1, otherwise it is 0. Then, perform filtering operations on the uplink complex channel vector and the downlink complex channel vector using the corresponding channel mask sequences to obtain the uplink complex channel subset vector and the downlink complex channel subset vector. Step S3: Perform feature extraction and decorrelation operations on the uplink complex channel subset vector and the downlink complex channel subset vector on the base station side and the terminal side respectively to obtain the corresponding uplink real-valued vector and downlink real-valued vector of the same dimension on both sides. Step S4: Quantize the uplink real-valued vector and the downlink real-valued vector into uplink bit string sequences and downlink bit string sequences, respectively, and construct the error correction and verification features corresponding to the downlink real-valued vector based on the downlink real-valued vector; Step S5: On the terminal side, the error correction check feature is added to the next control command to be sent, and the control command with the added error correction check feature is sent to the base station side. The base station side corrects the uplink bit string sequence according to the error correction check feature to obtain the corrected uplink bit string sequence and the check error vector. Step S6: The base station side and the terminal side process the corrected uplink bit string sequence and the uplink bit string sequence respectively through a secure hash algorithm to generate the corresponding key seed, and then construct the key required for data encryption transmission through the key derivation function. Feature extraction and decorrelation operations are performed on the uplink complex channel subset vector and the downlink complex channel subset vector on both the base station side and the terminal side to obtain the corresponding uplink real-valued vector and downlink real-valued vector of the same dimension on both sides. Specifically, the following are included: For the uplink complex channel subset vector, extract the corresponding neighborhood amplitude difference features and neighborhood phase difference features. Then, concatenate the extracted neighborhood amplitude difference features and neighborhood phase difference features from the uplink complex channel subset vector and perform a decorrelation operation to obtain the corresponding uplink real-valued vector. For the downlink complex channel subset vector, extract the corresponding neighborhood amplitude difference features and neighborhood phase difference features. Then, concatenate the extracted neighborhood amplitude difference features and neighborhood phase difference features from the downlink complex channel subset vector and perform a decorrelation operation to obtain the corresponding downlink real-valued vector.
2. The data transmission encryption method for 5G networks according to claim 1, characterized in that, Performing uplink and downlink channel measurements that comply with time interval constraints, the terminal side obtains the downlink complex channel vector, and the base station side obtains the uplink complex channel vector. Specifically, this includes the following steps: Step S1.1: On the base station side, traverse the orthogonal frequency division multiplexing (OFDM) symbols on the time axis after the current system time on the base station side, and determine the downlink reference signal transmission time window and uplink reference signal transmission time window that meet the time interval constraint and symbol constraint. The OFDM symbols include uplink, downlink, and flexible. Meeting the time interval constraint means that the downlink reference signal transmission time window and the uplink reference signal transmission time window satisfy t < β·Tc, where t is the interval between the downlink reference signal transmission time window and the uplink reference signal transmission time window, β is the attention coefficient, and Tc is the coherence time. The symbol constraint means that the OFDM symbols corresponding to the time of the downlink reference signal transmission time window and the uplink reference signal transmission time window are downlink and uplink. And determine the reference signal configuration resources corresponding to the downlink reference signal transmission time window and the uplink reference signal transmission time window. Then, the downlink reference signal sequence is determined based on the resource allocation of the reference signal; Step S1.2: On the base station side, the downlink control command before the downlink reference signal transmission time window is recorded as the target control command, and reference signal configuration resources are added to the target control command before the target control command is sent to the terminal side. Then the target control command with added reference signal configuration resources is sent to the terminal side. After that, the downlink reference signal sequence is sent to the terminal side during the downlink reference signal transmission time window. Step S1.3: On the terminal side, the reference signal configuration resources are determined according to the target control command, the downlink reference signal sequence is received according to the reference signal configuration resources, the corresponding channel response is determined, the downlink complex channel vector is obtained, the uplink reference signal sequence is determined according to the reference signal configuration resources, and then the uplink reference signal sequence is sent to the base station side during the uplink reference signal transmission time window. Step S1.4: On the base station side, the uplink reference signal sequence is received according to the reference signal configuration resources, and the corresponding channel response is determined to obtain the uplink complex channel vector.
3. The data transmission encryption method for 5G networks according to claim 2, characterized in that, On the base station side and the terminal side, corresponding channel mask sequences are constructed based on the key seed generated in the previous round, the channel mask sequence from the previous round, and the check error vector from the previous round, respectively. Then, filtering operations are performed on the uplink complex channel vector and the downlink complex channel vector using the corresponding channel mask sequences to obtain the uplink complex channel subset vector and the downlink complex channel subset vector, specifically including the following steps: Step S2.1: On the base station side and the terminal side, the key seed generated in the previous round, the channel mask sequence in the previous round, the check error vector in the previous round, the round number and the reference signal configuration resource number stored locally are concatenated into the mask calculation input information. Then, the key derivation function is called to process the mask calculation input information to obtain the mask seed. Step S2.2: On both the base station and terminal sides, a pseudo-random sequence generator is driven by a mask seed to generate candidate channel mask sequences. The difference between the candidate channel mask sequence and the channel mask sequence from the previous round is calculated. Specifically, the candidate channel mask sequence and the channel mask sequence from the previous round are matched item by item, where each item is data from either the candidate or previous round channel mask sequence. The ratio between the number of different items and the total number of items in the candidate channel mask sequence is counted and recorded as the difference. The difference is then compared with a difference threshold. If the difference is higher than the threshold, the candidate channel mask sequence is directly output as the channel mask for the current round. For the code sequence, proceed to step S2.
3. If the difference is not higher than the difference threshold, traverse the candidate channel mask sequence from front to back, record the number h corresponding to the first candidate channel mask sequence encountered and the channel mask sequence of the previous round that are both 1, and replace the h-th item from front to back in the candidate channel mask sequence with 0. Then traverse the candidate channel mask sequence from back to front, record the number g corresponding to the first candidate channel mask sequence encountered and the channel mask sequence of the previous round that are both 0, and replace the g-th item from back to front in the candidate channel mask sequence with 0. Then judge the difference and the difference threshold again until the difference is higher than the difference threshold. Step S2.3: On the base station side and the terminal side, filtering operations are performed on the uplink complex channel vector and the downlink complex channel vector respectively through the channel mask sequence. Specifically, the filtering operation is as follows: record the set of valid positions corresponding to the positions where the item is 1 in the channel mask sequence, and retain the data corresponding to the positions in the valid position set in the uplink complex channel vector and the downlink complex channel vector. Record the set of invalid positions corresponding to the positions where the item is 0 in the channel mask sequence, and delete the data corresponding to the positions in the invalid position set in the uplink complex channel vector and the downlink complex channel vector, so as to obtain the uplink complex channel subset vector and the downlink complex channel subset vector.
4. The data transmission encryption method for 5G networks according to claim 3, characterized in that, The uplink real-valued vector and downlink real-valued vector are quantized into uplink bit string sequences and downlink bit string sequences, respectively. Then, error correction and detection features corresponding to the downlink real-valued vector are constructed based on the downlink real-valued vector. The specific steps include the following: Step S4.1: On the base station side, traverse the elements in the uplink real value vector and execute the threshold judgment rule. The threshold judgment rule is that if the absolute value of the element value is greater than the threshold value, the output bit is 1; if the absolute value of the element value is not greater than the threshold value, the output bit is 0. Bits corresponding to 0 and 1 are both considered valid. Divide the bits corresponding to the elements in the uplink real value vector according to a fixed window size to obtain uplink bit sequence groups. If the number of uplink bit sequence groups obtained by the division reaches the preset value, output all uplink bit sequence groups and concatenate the valid bits in all uplink bit sequence groups to obtain the uplink bit string sequence. If the number of downlink bit sequence groups obtained by the division does not reach the preset value, return directly to step S1 and execute the next round of measurement. Step S4.2: On the terminal side, traverse the elements in the downlink real-valued vector and execute the threshold judgment rule. Divide the bits corresponding to the elements in the downlink real-valued vector according to a fixed window size to obtain downlink bit sequence groups. If the number of downlink bit sequence groups obtained by the division reaches a preset value, output all downlink bit sequence groups and concatenate the valid bits in all downlink bit sequence groups to obtain a downlink bit string sequence. If the number of downlink bit sequence groups obtained by the division does not reach the preset value, return directly to step S1 and execute the next round of measurement. Furthermore, process each downlink bit sequence group through a low-density parity-check code algorithm, output the redundancy code corresponding to each downlink bit sequence group, and then form an error correction check feature from the redundancy codes corresponding to all downlink bit sequence groups.
5. A data transmission encryption method for 5G networks according to claim 4, characterized in that, The base station corrects the uplink bit string sequence based on the error correction verification characteristics to obtain the corrected uplink bit string sequence and the error verification vector. The specific steps include the following: Step S5.1: On the base station side, the error correction verification feature is obtained according to the control command with added error correction verification feature. Based on the error correction verification feature, the uplink bit string sequence is corrected by the low-density parity check code algorithm. If the correction is successful, the corrected uplink bit string sequence and the verification error vector are output. The dimension of the verification error vector is the same as that of the uplink bit string sequence. The verification error vector stores several 0s or 1s. 1 in the verification error vector indicates that the corresponding position of the uplink bit string sequence has been corrected, and 0 in the verification error vector indicates that the corresponding position of the uplink bit string sequence has not been corrected, so that the corrected uplink bit string sequence and the uplink bit string sequence have consistency. If the correction fails, return directly to step S1 and execute the next round of measurement.
6. A data transmission encryption method for 5G networks according to claim 5, characterized in that, The downlink reference signal sequence is determined by configuring resources according to the reference signal, specifically by generating the corresponding downlink reference signal sequence according to the CSI-RS standard. The uplink reference signal sequence is determined by configuring resources according to the reference signal, specifically by generating the corresponding uplink reference signal sequence according to the SRS standard. Both the CSI-RS standard and the SRS standard are 3GPP NR physical layer standards.
7. A data transmission encryption system for 5G networks, characterized in that, The system employs a data transmission encryption method for 5G networks as described in any one of claims 1-6, comprising: The channel measurement module is used to perform uplink channel measurement and downlink channel measurement that meet the time interval constraints. The terminal side obtains the downlink complex channel vector, and the base station side obtains the uplink complex channel vector. The filtering module is used to construct corresponding channel mask sequences on the base station side and the terminal side, respectively, based on the key seed generated in the previous round, the channel mask sequence of the previous round, and the check error vector of the previous round. The channel mask sequence has the same dimension as the uplink complex channel vector and the downlink complex channel vector. The channel mask sequence stores several 0s or 1s. If the data corresponding to the subcarrier index in the uplink complex channel vector participated in the subsequent key generation operation in the previous round, the data corresponding to the subcarrier index in the channel mask sequence is 1, otherwise it is 0. The filtering module performs filtering operations on the uplink complex channel vector and the downlink complex channel vector respectively through the corresponding channel mask sequence to obtain the uplink complex channel subset vector and the downlink complex channel subset vector. The real-valued vector construction module is used to perform feature extraction and decorrelation operations on the uplink complex channel subset vector and the downlink complex channel subset vector on the base station side and the terminal side, respectively, to obtain the corresponding uplink real-valued vector and downlink real-valued vector of the same dimension on both sides; The bit quantization module is used to quantize the uplink real-valued vector and the downlink real-valued vector into uplink bit string sequences and downlink bit string sequences, respectively, and to construct the error correction and verification features corresponding to the downlink real-valued vector based on the downlink real-valued vector; The bit unification module is used by the base station to correct the uplink bit string sequence based on the error correction and verification characteristics, so as to obtain the corrected uplink bit string sequence and the verification error vector. The key construction module is used by the base station side and the terminal side to process the corrected uplink bit string sequence and the uplink bit string sequence respectively through a secure hash algorithm to generate the corresponding key seed, and then construct the key required for data encryption transmission through the key derivation function.
Citation Information
Patent Citations
Wireless physical layer key generation method and system based on deep learning in 5G environment
CN118233888A
Secure data transmission method for wireless communication system
CN120711401A