A method and system for visible light communication

By employing dynamic wavelength allocation and a dual-layer encryption mechanism, the problems of low resource utilization efficiency and insufficient security in visible light communication are solved, enabling efficient and secure point-to-point visible light communication.

CN121462080BActive Publication Date: 2026-07-24CHINA ELECTRONICS CORP 6TH RES INST
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA ELECTRONICS CORP 6TH RES INST
Filing Date
2025-11-10
Publication Date
2026-07-24

AI Technical Summary

Technical Problem

Existing visible light communication technologies cannot dynamically adjust wavelength resources in terms of resource management, resulting in low resource utilization efficiency. Furthermore, their security relies on a single protocol layer encryption, which poses significant security risks.

Method used

Employing dynamic wavelength allocation and a dual-layer encryption mechanism, point-to-point visible light communication is achieved through the collaborative work of base stations, communication terminals, and relay stations. Base stations dynamically allocate non-overlapping data channels, communication terminals encrypt and decrypt data based on session keys and physical layer keys, and relay stations forward light waves.

Benefits of technology

It improves the resource utilization efficiency and security of visible light communication, enhances anti-interference capabilities, and ensures the security and privacy of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121462080B_ABST
    Figure CN121462080B_ABST
Patent Text Reader

Abstract

The application provides a visible light communication method and system, comprising: for each communication terminal establishing a communication link, the communication terminal encrypts target transmission data based on a session key of the communication terminal, determines the encrypted target transmission data as encrypted data, generates a protocol frame based on the encrypted data, performs splicing processing on the protocol frame to obtain at least one frame data block, and transmits corresponding first light waves to a relay station according to a first transmission rule; the relay station transmits second light waves to a target communication terminal corresponding to the communication terminal according to a second transmission rule; and the target communication terminal corresponding to the communication terminal aggregates all frame data blocks to obtain aggregated frame data blocks, and decrypts the encrypted data in the aggregated frame data blocks to obtain target transmission data. The technical scheme provided by the application improves the security and anti-interference capability of visible light communication.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of visible light communication technology, and in particular to a visible light communication method and system. Background Technology

[0002] Visible light communication (VLC) is a technology that uses lighting devices such as light-emitting diodes (LEDs) for communication. It primarily transmits information through high-frequency visible light signals emitted by these devices, offering ease of operation and a large communication capacity. Current VLC technologies mainly employ a broadcast approach, ensuring that all devices within the same channel can receive the signal. In terms of resource utilization, this technology uses preset fixed wavelengths and allocates them statically based on the number of terminals. Regarding security, it primarily relies on protocol-level encryption to protect data transmission.

[0003] However, existing visible light communication technologies cannot dynamically adjust wavelength resources according to communication needs in terms of resource management, resulting in low resource utilization efficiency. In terms of security management, relying solely on protocol-level encryption poses significant security risks. Summary of the Invention

[0004] In view of this, embodiments of this application provide a visible light communication method and system, which improves the security and anti-interference capability of visible light communication.

[0005] This application mainly includes the following aspects: In a first aspect, embodiments of this application provide a visible light communication method, the method being applied to a visible light communication system, the system comprising: a base station, a relay station, at least one communication terminal, and at least one target communication terminal; The method includes: In response to a link request instruction containing target communication terminal identification information received from at least one communication terminal, the base station establishes a communication link between at least one communication terminal and the corresponding target communication terminal. For each communication terminal that establishes a communication link, the communication terminal encrypts the target transmission data based on its session key, determines the encrypted target transmission data as encrypted data, generates a protocol frame based on the encrypted data, segments the protocol frame to obtain at least one frame data block, determines the first transmission rule of the first light wave corresponding to each frame data block based on the physical layer key of the communication terminal, and transmits the corresponding first light wave to the relay station according to the first transmission rule. The relay station receives all frame data blocks according to the light wavelength receiving range corresponding to the communication terminal, determines the second transmission rule of the second light wave corresponding to each frame data block, and transmits the second light wave to the target communication terminal corresponding to the communication terminal according to the second transmission rule. The target communication terminal corresponding to this communication terminal aggregates all frame data blocks to obtain aggregated frame data blocks, and decrypts the encrypted data in the aggregated frame data blocks to obtain the target transmission data.

[0006] Furthermore, the session key of this communication terminal is determined in the following way: Based on the private key of the communication terminal, the public key of the target communication terminal corresponding to the communication terminal, the first initial wavelength corresponding to the communication terminal, and the current timestamp, a shared key for the communication terminal is generated. The session key for the communication terminal is generated based on the shared key of the communication terminal, the protocol key shared between the communication terminal and the target communication terminal corresponding to the communication terminal.

[0007] Furthermore, the step of generating a protocol frame based on encrypted data and then segmenting the protocol frame to obtain at least one frame data block includes: Based on the protocol key, current timestamp, and encrypted data, a message authentication code for the communication terminal is generated; The communication terminal's ID, the target communication terminal's ID, encrypted data, the communication terminal's message authentication code, and the current timestamp are encapsulated to generate a protocol frame containing encrypted data. The protocol frame is sliced ​​according to a preset amount of data carried by the light wave to obtain at least one frame slice data. Each frame slice data is concatenated with the corresponding encrypted fragment identifier, and each concatenated frame slice data is determined as a frame data block of the communication terminal to obtain at least one frame data block.

[0008] Furthermore, the step of determining the first transmission rule of the first light wave corresponding to each frame data block based on the physical layer key of the communication terminal, and transmitting the corresponding first light wave to the relay station according to the first transmission rule, includes: Based on the shared key of the communication terminal, the first initial wavelength, and the current timestamp, a physical layer key for the communication terminal is generated. Using the physical layer key, a wavelength offset sequence of the first light wave is generated; Based on the wavelength offset sequence, determine the wavelength offset corresponding to each period; In each cycle, the first initial wavelength is adjusted according to the corresponding wavelength offset, and in each cycle, the first light wave of the adjusted first initial wavelength carries the corresponding frame data block and is transmitted to the relay station.

[0009] Furthermore, determining the second transmission rule for the second light wave corresponding to each frame data block, and transmitting the second light wave to the relay station according to the second transmission rule, includes: Based on the wavelength offset corresponding to each cycle, the second initial wavelength corresponding to the relay station is adjusted in each cycle, and the second light wave of the adjusted second initial wavelength is used in each cycle to carry the corresponding frame data block and transmit it to the target communication terminal corresponding to the communication terminal.

[0010] Furthermore, the target communication terminal corresponding to this communication terminal aggregates all frame data blocks to obtain aggregated frame data blocks, decrypts the encrypted data in the aggregated frame data blocks, and obtains the target transmission data, including: A shared key for the target communication terminal is generated based on the private key of the target communication terminal corresponding to the communication terminal and the public key of the communication terminal. Based on the shared key of the target communication terminal corresponding to the communication terminal, the first initial wavelength corresponding to the communication terminal, and the current timestamp, the physical layer key of the target communication terminal corresponding to the communication terminal is generated. Using the physical layer key of the target communication terminal corresponding to the communication terminal, the wavelength offset sequence of the first light wave is generated; In each cycle, the second initial wavelength corresponding to the relay station is adjusted according to the corresponding wavelength offset, and in each cycle, the capture wavelength of the target communication terminal corresponding to the communication terminal is tuned to the corresponding adjusted second initial wavelength to receive the corresponding frame data block. Based on the encrypted fragmentation identifier of each frame data block, all frame data blocks are aggregated to obtain the aggregated frame data block; Based on the shared key of the target communication terminal corresponding to the communication terminal, the protocol key, the first initial wavelength, and the current timestamp, a session key for the target communication terminal corresponding to the communication terminal is generated. The session key of the target communication terminal corresponding to the communication terminal is used to decrypt the encrypted data in the aggregated frame data block to obtain the target transmission data.

[0011] Furthermore, the method also includes: In response to a communication termination request received from the communication terminal and / or the target communication terminal corresponding to the communication terminal, the base station marks the data channel used by the communication terminal and the target communication terminal corresponding to the communication terminal when establishing a communication link as an idle data channel.

[0012] Secondly, embodiments of this application also provide a visible light communication system, the visible light communication system comprising: a base station, a relay station, at least one communication terminal, and at least one target communication terminal; In response to a link request instruction containing target communication terminal identification information received from at least one communication terminal, the base station establishes a communication link between at least one communication terminal and the corresponding target communication terminal. For each communication terminal that establishes a communication link, the communication terminal encrypts the target transmission data based on its session key, determines the encrypted target transmission data as encrypted data, generates a protocol frame based on the encrypted data, segments the protocol frame to obtain at least one frame data block, determines the first transmission rule of the first light wave corresponding to each frame data block based on the physical layer key of the communication terminal, and transmits the corresponding first light wave to the relay station according to the first transmission rule. The relay station receives all frame data blocks according to the light wavelength receiving range corresponding to the communication terminal, determines the second transmission rule of the second light wave corresponding to each frame data block, and transmits the second light wave to the target communication terminal corresponding to the communication terminal according to the second transmission rule. The target communication terminal corresponding to this communication terminal aggregates all frame data blocks to obtain aggregated frame data blocks, and decrypts the encrypted data in the aggregated frame data blocks to obtain the target transmission data.

[0013] Thirdly, this application embodiment also provides a communication terminal, which generates a message authentication code based on the protocol key, current timestamp and encrypted data shared by the communication terminal and the target communication terminal corresponding to the communication terminal; The communication terminal ID, the target communication terminal ID corresponding to the communication terminal, the encrypted data, the communication terminal's message authentication code, and the current timestamp are concatenated to generate a protocol frame containing encrypted data. The protocol frame is sliced ​​according to a preset amount of data carried by the light wave to obtain at least one frame slice data. Each frame slice data is concatenated with the corresponding encrypted fragment identifier, and each concatenated frame slice data is determined as a frame data block of the communication terminal to obtain at least one frame data block.

[0014] Furthermore, based on the shared key of the communication terminal, the first initial wavelength corresponding to the communication terminal, and the current timestamp, a physical layer key for the communication terminal is generated; Using the physical layer key, a wavelength offset sequence of the first light wave corresponding to the frame data block is generated; Based on the wavelength offset sequence, determine the wavelength offset corresponding to each period; In each cycle, the first initial wavelength is adjusted according to the corresponding wavelength offset, and in each cycle, the first light wave of the adjusted first initial wavelength carries the corresponding frame data block and is transmitted to the relay station.

[0015] This application provides a visible light communication method and system, comprising: for each communication terminal establishing a communication link, the communication terminal encrypts target transmission data based on its session key, determines the encrypted target transmission data as encrypted data, generates a protocol frame based on the encrypted data, segments the protocol frame to obtain at least one frame data block, the communication terminal transmits a corresponding first light wave to a relay station according to a first transmission rule; the relay station transmits a second light wave to the target communication terminal corresponding to the communication terminal according to a second transmission rule; the target communication terminal corresponding to the communication terminal aggregates all frame data blocks to obtain an aggregated frame data block, decrypts the encrypted data in the aggregated frame data block to obtain the target transmission data.

[0016] This improves the security and anti-interference capabilities of visible light communication.

[0017] To make the above-mentioned objectives, features and advantages of this application more apparent and understandable, preferred embodiments are described below in detail with reference to the accompanying drawings. Attached Figure Description

[0018] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0019] Figure 1 One of the flowcharts of a visible light communication method provided in an embodiment of this application is shown; Figure 2 A block diagram of a visible light communication system provided in an embodiment of this application is shown; Figure 3 A second flowchart of a visible light communication method provided in an embodiment of this application is shown; Figure 4 A flowchart of a visible light communication method provided in an embodiment of this application is shown as third; Figure 5 A flowchart of a visible light communication method provided in an embodiment of this application is shown as fourth; Figure 6 The fifth flowchart of a visible light communication method provided in an embodiment of this application is shown; Figure 7 This illustration shows a visible light bidirectional communication information flow diagram provided in an embodiment of this application. Detailed Implementation

[0020] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. It should be understood that the drawings in this application are for illustrative and descriptive purposes only and are not intended to limit the scope of protection of this application. Furthermore, it should be understood that the schematic drawings are not drawn to scale. The flowcharts used in this application illustrate operations implemented according to some embodiments of this application. It should be understood that the operations in the flowcharts may not be implemented in sequence, and steps without logical contextual relationships may be reversed or implemented simultaneously. In addition, those skilled in the art, guided by the content of this application, may add one or more other operations to the flowcharts, or remove one or more operations from the flowcharts.

[0021] Furthermore, the described embodiments are merely some, not all, of the embodiments of this application. The components of the embodiments of this application described and illustrated herein can typically be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of this application provided in the accompanying drawings is not intended to limit the scope of the claimed application, but merely to illustrate selected embodiments of the application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without inventive effort are within the scope of protection of this application.

[0022] The methods or systems described in this application can be applied to any scenario requiring visible light communication. This application does not limit specific application scenarios, and any scheme using the visible light communication methods and devices provided in this application is within the protection scope of this application.

[0023] It is worth noting that visible light communication (VLC) is a technology that uses lighting devices such as light-emitting diodes (LEDs) for communication. It primarily transmits information through high-frequency visible light signals emitted by these devices, offering ease of operation and a large communication capacity. Existing VLC technologies mainly employ a broadcast approach, ensuring that all devices on the same channel can receive the signal. In terms of resource utilization, this technology uses preset fixed wavelengths and statically allocates wavelengths based on the number of terminals. Regarding security, it primarily relies on protocol-level encryption to protect data transmission. However, existing VLC technologies cannot dynamically adjust wavelength resources according to communication needs, resulting in low resource utilization efficiency. Furthermore, relying solely on protocol-level encryption for security management presents significant security vulnerabilities.

[0024] To address the aforementioned issues, this application proposes a visible light communication method and system, which improves the security and anti-interference capabilities of visible light communication.

[0025] To facilitate understanding of this application, the technical solutions provided in this application will be described in detail below with reference to specific embodiments.

[0026] In this embodiment, existing bidirectional visible light communication technology can receive signals from all devices on the same channel. However, because the channel is fixed, its flexibility is limited, and point-to-point signal transmission and reception cannot be achieved. This technology presets a fixed wavelength and statically allocates wavelengths according to the number of terminals (for example, communication terminal A and communication terminal B are fixedly allocated wavelength λ1, and communication terminal C and communication terminal D are fixedly allocated wavelength λ2). Once a wavelength is allocated, it will be occupied for a long time without a dynamic recycling or reservation mechanism. For example, when the link between communication terminal A and communication terminal B is idle, λ1 is still locked, preventing other communication terminals from reusing the wavelength resource, thus causing the wavelength resource to be idle and reducing the overall efficiency and performance of the system. In addition, this technology adopts a data channel multiplexing control signal mode, that is, control information (such as connection requests, link status, etc.) is directly transmitted in the data wavelength without establishing a separate control channel. In terms of security, the technology mainly relies on protocol layer encryption (such as using the Advanced Encryption Standard AES), with fixed and publicly available wavelengths. Terminal access is restricted only through access authorization, and relying on a single protocol layer encryption means that once the key is leaked, attackers can directly decrypt the data. At the same time, since the physical layer wavelength is not encrypted, it is also easy for third parties to eavesdrop, resulting in insufficient security of existing visible light communication technology.

[0027] Please see Figure 1 , Figure 1 This is one of the flowcharts for a visible light communication method provided in an embodiment of this application.

[0028] like Figure 1 As shown in the figure, the visible light communication method provided in this application embodiment is applied to a visible light communication system, the system including: a base station, a relay station, at least one communication terminal and at least one target communication terminal.

[0029] In the embodiments of this application, such as Figure 2 As shown, the base station mainly consists of the following modules: a main control module, responsible for the overall operation and management of the base station; a wavelength resource pool, which manages control channels and data channels and records the wavelength mapping relationship between communication terminals; a dynamic scheduling module, which processes access requests and allocates non-overlapping data wavelengths to communication terminals; a control channel receiving module, equipped with a narrowband filter for the control channel, which receives visible light requests from communication terminals; a control channel transmitting module, which transmits link information of communication terminals; and an authorized device list, used to record authorized communication terminals. Here, the authorized device list includes information such as communication terminal ID and MAC address.

[0030] The relay station mainly consists of the following modules: a main control module, responsible for the overall operation and management of the relay station; an AOTF group, which locks the input wavelength from the communication terminal; a multi-band adjustable LED group, which locks the wavelength forwarded to the communication terminal; an encrypted forwarding unit, which uses an independent channel for optical-electrical-optical conversion without decryption processing; and a relay coordination module, which receives wavelength instructions from the base station and synchronously controls the operation of the AOTF group and the LED group.

[0031] The communication terminal mainly consists of the following modules: a main control module, responsible for the overall operation and management of the communication terminal; a multi-band adjustable LED group, covering the entire visible light band and supporting narrowband channel switching; a main communication AOTF group, locking the wavelength for data transmission, and a control channel AOTF, locking the control wavelength to send requests; a dual-layer encryption module, performing encryption based on wavelength; an adjustable filter array, matching the data channel and control channel; a photodetector, used to receive signals; and a dual decryption module, using a key for decryption.

[0032] Visible light communication methods include the following steps: In step S101, the base station, in response to a link request instruction containing target communication terminal identification information received from at least one communication terminal, establishes a communication link between at least one communication terminal and the corresponding target communication terminal.

[0033] Here, the identification information includes the target communication terminal's ID and MAC address, etc. In this embodiment, a wavelength resource pool is established in the base station, and the wavelength resource pool is divided into data channels and control channels. For the current state of each channel, a corresponding tag is added, including: allocated, idle, and dedicated to control. In this application, as an example, the base station sets λ0 as the control channel, with an interval of not less than 20nm from the data channel, and marks it as dedicated to control.

[0034] Specifically, for each communication terminal with at least one communication terminal, the base station responds to the link request command of the communication terminal by selecting a channel marked as idle from the wavelength resource pool as the data channel of the communication terminal, and selects another data channel marked as idle as the data channel of the target communication terminal corresponding to the communication terminal.

[0035] As an example, assume there are five communication terminals labeled A, B, C, D, and E. A and C, as initiators, send data to their target terminals B and D, respectively. A and C send a link request command to the base station via control channel λ0 and drive a multi-band adjustable LED array to emit visible light signals. Upon receiving the link request, the base station dynamically allocates four non-overlapping data channels to these two pairs of communication terminals: data channel λ1 from A to the relay station, data channel λ1' from the relay station to B, data channel λ2 from C to the relay station, and data channel λ2' from the relay station to D. The spacing between each pair of channels is no less than 20 nm. Since E is not involved in this request, no channel allocation is performed.

[0036] The base station further generates a wavelength mapping table (λ1 maps to λ1', λ2 maps to λ2'), and sends this mapping table to the relay station via the control channel λ0, and feeds it back to A, B, C, and D. Simultaneously, the base station control channel synchronizes the core parameters of the data channel with A, B, and the relay station: to A, it sends the wavelength value of λ1, the data channel allocation time t1, and the wavelength validity period T; to B, it sends the wavelength value of λ1', the associated λ1 identifier, t1, and T; and to the relay station, it sends the forwarding bandwidth, etc. (only for signal conversion, not involving keys). The relay station configures its AOTF group and multi-band adjustable LED group according to the wavelength mapping table. Finally, the two pairs of communication terminals (A and B, C and D) conduct two parallel, physically isolated point-to-point optical communications according to the allocated wavelengths. Meanwhile, E fails to receive any communication information and remains outside the communication link.

[0037] Step S102: For each communication terminal that establishes a communication link, the communication terminal encrypts the target transmission data based on its session key, determines the encrypted target transmission data as encrypted data, generates a protocol frame based on the encrypted data, segments the protocol frame to obtain at least one frame data block, determines the first transmission rule of the first light wave corresponding to each frame data block based on the physical layer key of the communication terminal, and transmits the corresponding first light wave to the relay station according to the first transmission rule.

[0038] In this application embodiment, the communication method will be described through a communication terminal and its corresponding target communication terminal.

[0039] The following is combined with Figure 3 Please provide a detailed explanation of how the session key is determined.

[0040] Please see Figure 3 , Figure 3 This is a second flowchart of a visible light communication method provided in an embodiment of this application.

[0041] like Figure 3As shown in the image, the session key can be determined through the following steps as an example: Step S11: Generate a shared key for the communication terminal based on the private key of the communication terminal, the public key of the target communication terminal corresponding to the communication terminal, the first initial wavelength corresponding to the communication terminal, and the current timestamp.

[0042] Here, the first initial wavelength is the initial wavelength corresponding to the data channel allocated by the base station to the communication terminal. The shared key of the communication terminal is obtained by hashing the private key of the communication terminal, the public key of the target communication terminal, the first initial wavelength, and the current timestamp. Continuing with the example above, A's shared key K_Ashared=H(Sk_A+Pk_B+λ) A +t0), where Sk_A is A's private key, Pk_B is B's public key, and λ A Let t0 be the initial wavelength of the data channel of A, t0 be the current timestamp, and H be the hash symbol.

[0043] Step S12: Generate a session key for the communication terminal based on the shared key of the communication terminal, the protocol key shared between the communication terminal and the target communication terminal corresponding to the communication terminal.

[0044] Here, the shared key of the communication terminal and the protocol key shared by the communication terminal and the target communication terminal corresponding to the communication terminal are hashed to obtain the session key. Continuing with the example above, A's shared key K_AB = H(K_shared + K_pro + t0), where K_pro is the protocol key shared by A and B.

[0045] The following is combined with Figure 4 To explain in detail step S102, a protocol frame is generated based on encrypted data, and the protocol frame is spliced ​​to obtain at least one frame data block.

[0046] Please see Figure 4 , Figure 4 This is the third flowchart of a visible light communication method provided in an embodiment of this application.

[0047] like Figure 4 As shown, regarding step S102, which involves generating a protocol frame based on encrypted data and then segmenting the protocol frame to obtain at least one frame data block, the specific implementation, as an example, includes the following steps: Step S21: Generate a message authentication code for the communication terminal based on the protocol key, the current timestamp, and the encrypted data.

[0048] Here, the protocol key, current timestamp, and encrypted data shared by the target communication terminal corresponding to the communication terminal are hashed to obtain the message authentication code (MAC) of the communication terminal. The message authentication code of the communication terminal is used to verify the integrity of the target transmission data received by the target communication terminal corresponding to the communication terminal.

[0049] Step S22: Encapsulate the ID of the communication terminal, the ID of the target communication terminal corresponding to the communication terminal, the encrypted data, the message authentication code of the communication terminal, and the current timestamp to generate a protocol frame containing encrypted data.

[0050] Here, the ID of the communication terminal and the ID of the target communication terminal corresponding to the communication terminal are used for relay station routing, and the current timestamp is used to synchronize the system time. Continuing with the example above, the encapsulated protocol frame is [A ID|B ID + encrypted data + MAC + t0].

[0051] Step S23: The protocol frame is sliced ​​according to the preset amount of data carried by the optical wave to obtain at least one frame slice data.

[0052] Here, the maximum frame length that can be carried within a single cycle is pre-configured. When the encapsulated protocol frame exceeds the maximum frame length, data slicing is automatically performed; if the encapsulated frame does not exceed the maximum frame length, the complete protocol frame is transmitted directly.

[0053] Step S24: Concatenate each frame slice data with the corresponding encrypted fragment identifier, and determine each concatenated frame slice data as a frame data block of the communication terminal to obtain at least one frame data block.

[0054] Here, the fragment identifier includes: protocol frame ID, fragment sequence number, and total number of fragments. The fragment identifier is encrypted using the protocol key shared by the communication terminal and the corresponding target communication terminal, and the encrypted fragment identifier is used as the encrypted fragment identifier.

[0055] It should be noted that steps S11-S12 and S21-24 are implemented at the protocol layer of the communication terminal.

[0056] The following is combined with Figure 5 To explain in detail step S102, based on the physical layer key of the communication terminal, the first transmission rule of the first light wave corresponding to each frame data block is determined, and the corresponding first light wave is transmitted to the relay station according to the first transmission rule.

[0057] Please see Figure 5 , Figure 5 This is the fourth flowchart of a visible light communication method provided in an embodiment of this application.

[0058] like Figure 5 As shown, regarding step S102, based on the physical layer key of the communication terminal, the first transmission rule for the first light wave corresponding to each frame data block is determined, and the corresponding first light wave is transmitted to the relay station according to the first transmission rule. In specific implementation, as an example, the following steps are included: Step S31: Generate the physical layer key of the communication terminal based on the shared key of the communication terminal, the first initial wavelength and the current timestamp.

[0059] Here, the shared key of the communication terminal, the first initial wavelength corresponding to the communication terminal, and the current timestamp are hashed to obtain the physical layer key. Continuing with the example above, A's physical layer key K_phys = H(K_shared + λ) A +t0).

[0060] Step S32: Using the physical layer key, generate the wavelength offset sequence of the first light wave.

[0061] Here, the physical layer key is used as the random seed, and a wavelength offset sequence Δλ is generated using a pseudo-random algorithm. As an example, Δλ = [+0.2nm, 0, -0.1nm].

[0062] Step S33: Based on the wavelength offset sequence, determine the wavelength offset corresponding to each period.

[0063] As an example, in the first period T1, the first initial wavelength is increased by 0.2 nm; in the second period T2, the first initial wavelength remains unchanged; and in the third period T3, the first initial wavelength is decreased by 0.1 nm.

[0064] Step S34: Adjust the first initial wavelength according to the corresponding wavelength offset in each cycle, and transmit the corresponding frame data block to the relay station using the first light wave of the adjusted first initial wavelength in each cycle.

[0065] Here, the physical layer first converts the protocol layer's frame data blocks into electrical signals, and then dynamically adjusts the first initial wavelength according to the Δλ sequence. For example, in T1, the wavelength is set to 1550.2 nm; in T2, the wavelength is set to 1550.0 nm. To achieve fragmented transmission, a fragmented transmission coordination mechanism is adopted. Under this mechanism, each frame data block transmission corresponds to a wavelength transition period T. For example, in T1, the frame data block with fragment number 0 is transmitted; in T2, the frame data block with fragment number 1 is transmitted, and so on, periodically, until all frame data blocks are transmitted. The first transmission rule is to transmit the first light wave according to the time sequence and the adjusted first initial wavelength corresponding to each frame data block.

[0066] See again Figure 1 In step S103, the relay station receives all frame data blocks according to the optical wavelength receiving range corresponding to the communication terminal, determines the second transmission rule of the second optical wave corresponding to each frame data block, and transmits the second optical wave to the target communication terminal corresponding to the communication terminal according to the second transmission rule.

[0067] Here, the AOTF group of the relay station captures the signal according to the optical wavelength receiving range (e.g., 1550nm±0.3nm) of the data channel pre-allocated by the base station. The optical wavelength receiving range corresponding to the communication terminal only corresponds to the communication link from the communication terminal to the target communication terminal corresponding to the communication terminal. The relay station keeps the content of the protocol frame completely transparent and does not perform content parsing.

[0068] Regarding the second transmission rule for determining the second light wave corresponding to each frame data block in step S103, and transmitting the second light wave to the target communication terminal corresponding to the communication terminal according to the second transmission rule, in a specific implementation, as an example, the following steps are included: based on the wavelength offset corresponding to each period, adjusting the second initial wavelength corresponding to the relay station in each period, and using the second light wave with the adjusted second initial wavelength to carry the corresponding frame data block to the target communication terminal corresponding to the communication terminal in each period.

[0069] Here, the second initial wavelength is the initial wavelength corresponding to the data channel allocated by the base station to the target communication terminal corresponding to the communication terminal. The second transmission rule is to transmit the second light wave according to the adjusted second initial wavelength corresponding to each frame data block, based on the time sequence.

[0070] The relay station performs wavelength conversion according to the mapping table, maintaining the Δλ jump pattern. Continuing with the example above, λ1 is mapped to λ1', mapping 1550nm±0.3nm to 1552nm±0.3nm. Assuming the first initial wavelength corresponding to A is 1550.0nm, the second initial wavelength corresponding to B is determined to be 1552.0nm through the mapping table. At time T1, the wavelength offset is 0.2nm, so the adjusted first initial wavelength of A at time T1 is 1550.2nm, and the adjusted second initial wavelength of B at time T1 is 1552.2nm. Throughout the process, the relay station does not parse the encryption rules; it only performs physical layer wavelength mapping and frame data block forwarding.

[0071] Step S104: The target communication terminal corresponding to the communication terminal aggregates all frame data blocks to obtain aggregated frame data blocks, and decrypts the encrypted data in the aggregated frame data blocks to obtain the target transmission data.

[0072] The following is combined with Figure 6To explain the specific steps, the target communication terminal corresponding to the communication terminal aggregates all frame data blocks to obtain aggregated frame data blocks, and decrypts the encrypted data in the aggregated frame data blocks to obtain the target transmission data.

[0073] Please see Figure 6 , Figure 6 This is the fifth flowchart of a visible light communication method provided in the embodiments of this application.

[0074] like Figure 6 As shown, regarding step S104, in a specific implementation, as an example, the following steps are included: Step S1041: Generate a shared key for the target communication terminal based on the private key of the target communication terminal corresponding to the communication terminal, the public key of the communication terminal, the first initial wavelength corresponding to the communication terminal, and the current timestamp.

[0075] Here, the private key of the target communication terminal corresponding to the given communication terminal, the public key of the given communication terminal, the first initial wavelength corresponding to the given communication terminal, and the current timestamp are hashed to obtain the shared key of the target communication terminal corresponding to the given communication terminal. Continuing with the example above, the shared key of B is K_Bshared=H(Sk_B+Pk_A+λ B +t0), where Sk_B is B's private key, Pk_A is A's public key, and λ B Let B be the initial wavelength of the data channel. This key generation method relies on the correlation of asymmetric key pairs; that is, due to the characteristics of asymmetric encryption, it ensures that K_Ashared equals K_Bshared. Therefore, the shared keys generated by both parties are completely identical.

[0076] Step S1042: Based on the shared key of the target communication terminal corresponding to the communication terminal, the first initial wavelength corresponding to the communication terminal, and the current timestamp, generate the physical layer key of the target communication terminal corresponding to the communication terminal.

[0077] Here, the shared key of the target communication terminal corresponding to the communication terminal, the first initial wavelength corresponding to the communication terminal, and the current timestamp are hashed to obtain the physical layer key of the target communication terminal corresponding to the communication terminal, wherein the physical layer key of the target communication terminal corresponding to the communication terminal is the same as the physical layer key of the communication terminal.

[0078] Step S1043: Using the physical layer key of the target communication terminal corresponding to the communication terminal, generate the wavelength offset sequence of the first light wave.

[0079] Here, the target communication terminal corresponding to this communication terminal parses the wavelength transition sequence based on the physical layer key.

[0080] Step S1044: In each cycle, adjust the second initial wavelength corresponding to the relay station according to the corresponding wavelength offset, and in each cycle, tune the capture wavelength of the target communication terminal corresponding to the communication terminal to the corresponding adjusted second initial wavelength to receive the corresponding frame data block.

[0081] Here, in each corresponding cycle, the target communication terminal corresponding to the communication terminal locks the adjusted second initial wavelength and extracts frame data blocks through the demodulation process.

[0082] Step S1045: Based on the encrypted fragmentation identifier of each frame data block, aggregate all frame data blocks to obtain the aggregated frame data block.

[0083] Here, the received data frame blocks first undergo an integrity check. For complete frames, they are directly decrypted at the protocol layer; for fragmented frames, the following steps are performed: Frame data blocks synchronized with the local key are filtered using the timestamp t0, and the encrypted fragment identifier is decrypted using the protocol key shared by the communication terminal and the corresponding target communication terminal. Frame data blocks belonging to the same protocol frame are aggregated according to the protocol frame ID. After all frame data blocks are collected and concatenated according to their sequence numbers, a complete protocol frame is restored. If a frame data block is found to be missing, the target communication terminal will request the communication terminal to retransmit only the missing frame data block.

[0084] Step S1046: Based on the shared key of the target communication terminal corresponding to the communication terminal, the protocol key, the first initial wavelength, and the current timestamp, generate the session key of the target communication terminal corresponding to the communication terminal.

[0085] Here, the shared key of the target communication terminal corresponding to the current communication terminal, the protocol key, the first initial wavelength, and the current timestamp are hashed to obtain the session key of the target communication terminal corresponding to the current communication terminal. Here, the session key of the target communication terminal corresponding to the current communication terminal is the same as the session key corresponding to the current communication terminal.

[0086] Step S1047: Use the session key of the target communication terminal corresponding to the communication terminal to decrypt the encrypted data in the aggregated frame data block to obtain the target transmission data.

[0087] Here, the session key of the target communication terminal corresponding to the communication terminal is used to decrypt the encrypted data to obtain the target transmitted data.

[0088] In one possible implementation, the method further includes: the target communication terminal corresponding to the communication terminal generates a message authentication code for determining whether the target transmitted data has been tampered with, based on the protocol key of the communication terminal and the target communication terminal corresponding to the communication terminal, the shared key of the target communication terminal corresponding to the communication terminal, and the received encrypted data; when the target communication terminal corresponding to the communication terminal determines that the received message authentication code is the same as the generated message authentication code, it determines that the target transmitted data has not been tampered with.

[0089] Here, the target communication terminal corresponding to the communication terminal performs a hash calculation based on the protocol key of the communication terminal and the target communication terminal corresponding to the communication terminal, the shared key of the target communication terminal corresponding to the communication terminal, and the received encrypted data to obtain a message authentication code used to determine whether the target transmitted data has been tampered with.

[0090] In one possible implementation, the method further includes: in response to a communication termination request received from the communication terminal and / or the target communication terminal corresponding to the communication terminal, the base station marks the data channel used by the communication terminal and the target communication terminal to establish a communication link as an idle data channel. Here, after the communication task is completed, the base station reclaims the wavelength resources of the data channel into the wavelength resource pool.

[0091] like Figure 7 As shown, in one possible implementation, real-time bidirectional communication between the two communication terminals can also be achieved. Specifically, in response to a link request instruction containing the identifier information of communication terminal B received from communication terminal A and a request instruction containing the identifier information of communication terminal A received from communication terminal B, the base station establishes a bidirectional communication link between the first communication terminal and the second communication terminal.

[0092] To achieve real-time bidirectional communication between two terminals, as an example, a wavelength resource pool is first established, including data channels (covering paired forward and reverse resources) and control channels. The base station sets up control channel λ0 and marks it as dedicated to control to ensure effective interaction of bidirectional communication requests. The AOTF groups of terminals A and B lock the control channel. A sends a request to the base station via λ0, containing B's ID, MAC address, and a bidirectional communication identifier. Upon receiving A's request, the base station sends verification information containing A's ID and MAC address to B via λ0. After confirming the information is correct, terminal B returns a MAC signature-signed response to the base station agreeing to bidirectional communication via λ0. After confirming the communication intentions of both parties, the base station allocates bidirectional wavelength resources and synchronizes key data channel parameters via λ0, including their respective transmit and receive wavelengths, the specific time of allocation, and the validity period of the wavelengths. Furthermore, the base station sends forward and reverse wavelength mapping tables to the relay station, which locks the corresponding receive and forward wavelengths according to the wavelength mapping tables. A and B lock their respective transmit and receive wavelengths. A and B each generate protocol layer and physical layer keys, and transmit data using adjusted wavelengths. The relay station receives and forwards the data according to a mapping table, and B decrypts the received data. This ensures independent operation of the forward and reverse links, achieving conflict-free real-time bidirectional communication. When the communication task is completed, A or B sends a request to the base station to end the communication via λ0. The base station then reclaims all wavelength resources into the resource pool, and λ0 remains in a control-dedicated state for use in the next communication request.

[0093] In this embodiment, a "dynamic wavelength isolation and dual encryption at both the physical and protocol layers" technology is employed to ensure high security and anti-interference capabilities for visible light communication. By allocating non-overlapping wavelengths, physical isolation and directional data transmission between communication terminals are achieved, ensuring that information is received only by designated communication terminals. Furthermore, the relay station forwards signals without decryption, further strengthening the security isolation between the control and data channels. The unified visible light signal transmission mechanism and data link logic enhance system compatibility. The dynamic adaptation capability of the base station allows for flexible wavelength adjustment based on the number of communication terminals and interference conditions, optimizing real-time channel allocation and effectively avoiding crosstalk between multiple communication terminals. Simultaneously, the combination of dynamic keys at the physical layer and keys at the protocol layer achieves strong binding between signals and keys, enhancing data transmission security and supporting conflict-free real-time bidirectional communication.

[0094] This application provides a visible light communication method that improves the security and anti-interference capability of visible light communication.

[0095] Based on the same application concept, this application also provides a visible light communication system corresponding to the visible light communication method provided in the above embodiments. Since the principle of the system in this application is similar to the visible light communication method in the above embodiments of this application, the implementation of the system can refer to the implementation of the method, and the repeated parts will not be described again.

[0096] The visible light communication system provided in this application includes: a base station, a relay station, at least one communication terminal, and at least one target communication terminal; In response to a link request instruction containing target communication terminal identification information received from at least one communication terminal, the base station establishes a communication link between at least one communication terminal and the corresponding target communication terminal. For each communication terminal that establishes a communication link, the communication terminal encrypts the target transmission data based on its session key, determines the encrypted target transmission data as encrypted data, generates a protocol frame based on the encrypted data, segments the protocol frame to obtain at least one frame data block, determines the first transmission rule of the first light wave corresponding to each frame data block based on the physical layer key of the communication terminal, and transmits the corresponding first light wave to the relay station according to the first transmission rule. The relay station receives all frame data blocks according to the light wavelength receiving range corresponding to the communication terminal, determines the second transmission rule of the second light wave corresponding to each frame data block, and transmits the second light wave to the target communication terminal corresponding to the communication terminal according to the second transmission rule. The target communication terminal corresponding to this communication terminal aggregates all frame data blocks to obtain aggregated frame data blocks, and decrypts the encrypted data in the aggregated frame data blocks to obtain the target transmission data.

[0097] This application provides a visible light communication system that improves the security and anti-interference capability of visible light communication.

[0098] This application provides a communication terminal in which the session key is determined in the following way: Based on the private key of the communication terminal, the public key of the target communication terminal corresponding to the communication terminal, the first initial wavelength corresponding to the communication terminal, and the current timestamp, a shared key for the communication terminal is generated. The session key of the communication terminal is generated based on the shared key of the communication terminal, the protocol key shared by the communication terminal and the target communication terminal corresponding to the communication terminal.

[0099] Furthermore, based on the protocol key, current timestamp, and encrypted data shared between the communication terminal and the target communication terminal corresponding to the communication terminal, a message authentication code for the communication terminal is generated; The communication terminal ID, the target communication terminal ID corresponding to the communication terminal, the encrypted data, the communication terminal's message authentication code, and the current timestamp are concatenated to generate a protocol frame containing encrypted data. The protocol frame is sliced ​​according to a preset amount of data carried by the light wave to obtain at least one frame slice data. Each frame slice data is concatenated with the corresponding encrypted fragment identifier, and each concatenated frame slice data is determined as a frame data block of the communication terminal to obtain at least one frame data block.

[0100] Furthermore, based on the shared key of the communication terminal, the first initial wavelength corresponding to the communication terminal, and the current timestamp, a physical layer key for the communication terminal is generated; Using the physical layer key, a wavelength offset sequence of the first light wave corresponding to the frame data block is generated; Based on the wavelength offset sequence, determine the wavelength offset corresponding to each period; In each cycle, the first initial wavelength is adjusted according to the corresponding wavelength offset, and in each cycle, the first light wave of the adjusted first initial wavelength carries the corresponding frame data block and is transmitted to the relay station.

[0101] This application provides a relay station, which adjusts the second initial wavelength corresponding to the relay station in each cycle based on the wavelength offset corresponding to each cycle, and uses the second light wave of the adjusted second initial wavelength to carry the corresponding frame data block to the target communication terminal corresponding to the communication terminal in each cycle.

[0102] This application provides a communication terminal corresponding to a target communication terminal, wherein the communication terminal corresponding to the target communication terminal generates a shared key for the target communication terminal based on the private key of the target communication terminal and the public key of the communication terminal; Based on the shared key of the target communication terminal corresponding to the communication terminal, the first initial wavelength corresponding to the communication terminal, and the current timestamp, a physical layer key of the target communication terminal corresponding to the communication terminal is generated. Using the physical layer key of the target communication terminal corresponding to the communication terminal, the wavelength offset sequence of the first light wave is generated; In each cycle, the second initial wavelength corresponding to the relay station is adjusted according to the corresponding wavelength offset, and in each cycle, the capture wavelength of the target communication terminal corresponding to the communication terminal is tuned to the corresponding adjusted second initial wavelength to receive the corresponding frame data block. Based on the encrypted fragmentation identifier of each frame data block, all frame data blocks are aggregated to obtain the aggregated frame data block; Based on the shared key of the target communication terminal corresponding to the communication terminal, the protocol key, the first initial wavelength, and the current timestamp, a session key for the target communication terminal corresponding to the communication terminal is generated. The encrypted data in the aggregated frame data block is decrypted using the session key of the target communication terminal corresponding to the communication terminal to obtain the target transmission data.

[0103] This application provides a base station that, in response to a communication termination request received from a communication terminal and / or a target communication terminal corresponding to the communication terminal, marks the data channel used by the communication terminal and the target communication terminal to establish a communication link as an idle data channel.

[0104] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems and devices described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. In the several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of units is only a logical functional division; in actual implementation, there may be other division methods. Furthermore, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Another point is that the displayed or discussed mutual coupling or direct coupling or communication connection may be through some communication interfaces; the indirect coupling or communication connection of devices or units may be electrical, mechanical, or other forms.

[0105] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0106] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0107] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a processor-executable, non-volatile, computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0108] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A visible light communication method, characterized in that, The method is applied to a visible light communication system, the system comprising: a base station, a relay station, at least one communication terminal, and at least one target communication terminal; The method includes: In response to a link request instruction containing target communication terminal identification information received from at least one communication terminal, the base station establishes a communication link between at least one communication terminal and the corresponding target communication terminal. For each communication terminal that establishes a communication link, the communication terminal encrypts the target transmission data based on its session key, determines the encrypted target transmission data as encrypted data, generates a protocol frame based on the encrypted data, segments the protocol frame to obtain at least one frame data block, determines the first transmission rule of the first light wave corresponding to each frame data block based on the physical layer key of the communication terminal, and transmits the corresponding first light wave to the relay station according to the first transmission rule. The relay station receives all frame data blocks according to the light wavelength receiving range corresponding to the communication terminal, determines the second transmission rule of the second light wave corresponding to each frame data block, and transmits the second light wave to the target communication terminal corresponding to the communication terminal according to the second transmission rule. The target communication terminal corresponding to the communication terminal aggregates all frame data blocks to obtain aggregated frame data blocks, and decrypts the encrypted data in the aggregated frame data blocks to obtain the target transmission data. The session key of this communication terminal is determined in the following way: Based on the private key of the communication terminal, the public key of the target communication terminal corresponding to the communication terminal, the first initial wavelength corresponding to the communication terminal, and the current timestamp, a shared key for the communication terminal is generated. Based on the shared key of the communication terminal and the protocol key shared by the communication terminal and the target communication terminal corresponding to the communication terminal, a session key for the communication terminal is generated. The process of determining a first transmission rule for the first light wave corresponding to each frame data block based on the physical layer key of the communication terminal, and transmitting the corresponding first light wave to the relay station according to the first transmission rule, includes: Based on the shared key of the communication terminal, the first initial wavelength, and the current timestamp, a physical layer key for the communication terminal is generated. Using the physical layer key, a wavelength offset sequence of the first light wave is generated; Based on the wavelength offset sequence, determine the wavelength offset corresponding to each period; In each cycle, the first initial wavelength is adjusted according to the corresponding wavelength offset, and in each cycle, the first light wave of the adjusted first initial wavelength carries the corresponding frame data block and is transmitted to the relay station. The step of determining the second transmission rule for the second light wave corresponding to each frame data block, and transmitting the second light wave to the relay station according to the second transmission rule, includes: Based on the wavelength offset corresponding to each cycle, the second initial wavelength corresponding to the relay station is adjusted in each cycle, and the second light wave of the adjusted second initial wavelength is used in each cycle to carry the corresponding frame data block and transmit it to the target communication terminal corresponding to the communication terminal.

2. The visible light communication method according to claim 1, characterized in that, The process of generating a protocol frame based on encrypted data and then segmenting the protocol frame to obtain at least one frame data block includes: Based on the protocol key, current timestamp, and encrypted data, a message authentication code for the communication terminal is generated; The communication terminal's ID, the target communication terminal's ID, encrypted data, the communication terminal's message authentication code, and the current timestamp are encapsulated to generate a protocol frame containing encrypted data. The protocol frame is sliced ​​according to a preset amount of data carried by the light wave to obtain at least one frame slice data. Each frame slice data is concatenated with the corresponding encrypted fragment identifier, and each concatenated frame slice data is determined as a frame data block of the communication terminal to obtain at least one frame data block.

3. The visible light communication method according to claim 1, characterized in that, The target communication terminal corresponding to this communication terminal aggregates all frame data blocks to obtain aggregated frame data blocks, decrypts the encrypted data in the aggregated frame data blocks, and obtains the target transmission data, including: A shared key for the target communication terminal is generated based on the private key of the target communication terminal corresponding to the communication terminal and the public key of the communication terminal. Based on the shared key of the target communication terminal corresponding to the communication terminal, the first initial wavelength corresponding to the communication terminal, and the current timestamp, the physical layer key of the target communication terminal corresponding to the communication terminal is generated. Using the physical layer key of the target communication terminal corresponding to the communication terminal, the wavelength offset sequence of the first light wave is generated; In each cycle, the second initial wavelength corresponding to the relay station is adjusted according to the corresponding wavelength offset, and in each cycle, the capture wavelength of the target communication terminal corresponding to the communication terminal is tuned to the corresponding adjusted second initial wavelength to receive the corresponding frame data block. Based on the encrypted fragmentation identifier of each frame data block, all frame data blocks are aggregated to obtain the aggregated frame data block; Based on the shared key of the target communication terminal corresponding to the communication terminal, the protocol key, the first initial wavelength, and the current timestamp, a session key for the target communication terminal corresponding to the communication terminal is generated. The session key of the target communication terminal corresponding to the communication terminal is used to decrypt the encrypted data in the aggregated frame data block to obtain the target transmission data.

4. The visible light communication method according to claim 1, characterized in that, The method further includes: In response to a communication termination request received from the communication terminal and / or the target communication terminal corresponding to the communication terminal, the base station marks the data channel used by the communication terminal and the target communication terminal corresponding to the communication terminal when establishing a communication link as an idle data channel.

5. A visible light communication system, characterized in that, The visible light communication system includes: a base station, a relay station, at least one communication terminal, and at least one target communication terminal; In response to a link request instruction containing target communication terminal identification information received from at least one communication terminal, the base station establishes a communication link between at least one communication terminal and the corresponding target communication terminal. For each communication terminal that establishes a communication link, the communication terminal encrypts the target transmission data based on its session key, determines the encrypted target transmission data as encrypted data, generates a protocol frame based on the encrypted data, segments the protocol frame to obtain at least one frame data block, determines the first transmission rule of the first light wave corresponding to each frame data block based on the physical layer key of the communication terminal, and transmits the corresponding first light wave to the relay station according to the first transmission rule. The relay station receives all frame data blocks according to the light wavelength receiving range corresponding to the communication terminal, determines the second transmission rule of the second light wave corresponding to each frame data block, and transmits the second light wave to the target communication terminal corresponding to the communication terminal according to the second transmission rule. The target communication terminal corresponding to the communication terminal aggregates all frame data blocks to obtain aggregated frame data blocks, and decrypts the encrypted data in the aggregated frame data blocks to obtain the target transmission data. The session key of this communication terminal is determined in the following way: Based on the private key of the communication terminal, the public key of the target communication terminal corresponding to the communication terminal, the first initial wavelength corresponding to the communication terminal, and the current timestamp, a shared key for the communication terminal is generated. Based on the shared key of the communication terminal and the protocol key shared by the communication terminal and the target communication terminal corresponding to the communication terminal, a session key for the communication terminal is generated. The process of determining a first transmission rule for the first light wave corresponding to each frame data block based on the physical layer key of the communication terminal, and transmitting the corresponding first light wave to the relay station according to the first transmission rule, includes: Based on the shared key of the communication terminal, the first initial wavelength, and the current timestamp, a physical layer key for the communication terminal is generated. Using the physical layer key, a wavelength offset sequence of the first light wave is generated; Based on the wavelength offset sequence, determine the wavelength offset corresponding to each period; In each cycle, the first initial wavelength is adjusted according to the corresponding wavelength offset, and in each cycle, the first light wave of the adjusted first initial wavelength carries the corresponding frame data block and is transmitted to the relay station. The step of determining the second transmission rule for the second light wave corresponding to each frame data block, and transmitting the second light wave to the relay station according to the second transmission rule, includes: Based on the wavelength offset corresponding to each cycle, the second initial wavelength corresponding to the relay station is adjusted in each cycle, and the second light wave of the adjusted second initial wavelength is used in each cycle to carry the corresponding frame data block and transmit it to the target communication terminal corresponding to the communication terminal.

6. A communication terminal for executing the visible light communication method of claim 1, characterized in that, Based on the protocol key, current timestamp, and encrypted data shared between the communication terminal and the target communication terminal corresponding to the communication terminal, a message authentication code for the communication terminal is generated. The communication terminal ID, the target communication terminal ID corresponding to the communication terminal, the encrypted data, the communication terminal's message authentication code, and the current timestamp are concatenated to generate a protocol frame containing encrypted data. The protocol frame is sliced ​​according to a preset amount of data carried by the light wave to obtain at least one frame slice data. Each frame slice data is concatenated with the corresponding encrypted fragment identifier, and each concatenated frame slice data is determined as a frame data block of the communication terminal to obtain at least one frame data block.

7. The communication terminal according to claim 6, characterized in that, Based on the shared key of the communication terminal, the first initial wavelength corresponding to the communication terminal, and the current timestamp, a physical layer key for the communication terminal is generated. Using the physical layer key, a wavelength offset sequence of the first light wave corresponding to the frame data block is generated; Based on the wavelength offset sequence, determine the wavelength offset corresponding to each period; In each cycle, the first initial wavelength is adjusted according to the corresponding wavelength offset, and in each cycle, the first light wave of the adjusted first initial wavelength carries the corresponding frame data block and is transmitted to the relay station.