Physical layer group key distribution method and device based on region division and storage medium

By employing a physical layer group key distribution method based on region division and localized updates, the problems of high synchronization update overhead and information leakage in key management in dynamic wireless networks are solved. This method achieves efficient and secure key distribution and updates, and improves the scalability and consistency of the system.

CN121531356APending Publication Date: 2026-02-13NORTHWESTERN POLYTECHNICAL UNIV +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511784015.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-01
Publication Date
2026-02-13

AI Technical Summary

Technical Problem

Existing group key management schemes are difficult to implement secure, efficient and scalable key distribution and updates in dynamic wireless networks. They suffer from problems such as high overhead of network-wide synchronous updates, excessive leakage of key information and insufficient guarantee of consistency and integrity.

Method used

A physical layer group key distribution method based on region partitioning is adopted. By dividing regions according to the order of node addition and capacity threshold, fragmented distribution and localized updates of keys are achieved. Verifiable distribution is carried out by combining integrity verification information, and periodic updates by region and localized updates by role are supported.

Benefits of technology

It effectively reduces communication and coordination overhead, improves system scalability and engineering availability, and ensures forward confidentiality and key consistency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121531356A_ABST
    Figure CN121531356A_ABST
Patent Text Reader

Abstract

The invention provides a physical layer group key distribution method based on region division, which comprises the following steps of: performing network region division according to a node adding sequence and a capacity threshold value, and determining intra-region nodes and cross-region nodes; the newly added node and the preorder node generate paired keys based on a physical layer channel, and the paired keys are segmented; the preorder node constructs information carrying Hash verification based on the selected fragment and the last round of group key fragment and broadcasts the information, the node updates the group key in a fragment splicing mode after completing verification, and each area independently updates the group key according to an agreed period; when the nodes exit, local secret key updating is triggered according to the roles of the nodes; the nodes in the regions only update the regions to which the nodes belong, and the cross-region nodes update the regions to which the nodes belong and adjacent regions at the same time. Through regional division and localized key updating, the communication overhead of a node change scene in a dynamic network is reduced, the exposure of irrelevant keys is reduced, and the safety and expandability of group key distribution are improved on the premise that integrity verification and randomness are kept qualified.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of wireless communication and information security technology, and specifically to a physical layer group key distribution method based on region partitioning. Background Technology

[0002] With the rapid development of technologies such as drone swarm collaboration, IoT terminal interconnection, and mobile ad hoc networks, the application of dynamic wireless networks is becoming increasingly widespread. These networks are characterized by frequent node joining and leaving, heterogeneous link quality, and unstable network topology, making group communication a common occurrence. In this environment, the establishment, distribution, and updating of group keys become crucial for ensuring communication security. The system needs to resist passive eavesdropping and active tampering while meeting the requirements of forward and backward confidentiality, and also taking into account engineering requirements for low latency, low signaling overhead, and high scalability.

[0003] Existing group key management schemes are mainly divided into centralized and distributed types, but neither can effectively cope with the highly dynamic and unstable wireless network environment. Centralized schemes typically rely on a single central controller to be responsible for the unified generation, distribution, and updating of group keys. Although the structure is simple, it has obvious drawbacks. First, the central node is prone to becoming a performance bottleneck and a single point of failure. Once attacked or malfunctioning, the entire key system will be paralyzed. Second, as the group size increases, the computing, storage, and communication pressure on the central node increases sharply, resulting in poor scalability. In addition, the addition or removal of any member requires the central node to regenerate and distribute a completely new group key, leading to network-wide key updates, causing a surge in signaling overhead and the risk of service interruption.

[0004] Distributed solutions achieve key management through inter-node negotiation or local collaboration, which weakens the dependence on a central authority to some extent, but still has many problems. When members change, most solutions still require multiple rounds of negotiation or synchronization across the entire network, resulting in a large number of nodes unrelated to the change passively participating in the update process, causing a waste of communication resources. At the same time, since the key update process involves a wide range of nodes, it increases the risk of leakage of key information during transmission and storage. In addition, existing mechanisms usually use the entire group key as the update unit, failing to limit the update scope to a local area based on network topology or node relationships, resulting in high cross-regional coupling and blurred update boundaries.

[0005] In addition to the aforementioned structural problems, existing group key management schemes also have significant shortcomings in terms of systematic support. On the one hand, the key distribution and update process lacks a minimum leakage design and fails to implement "fragment-level" participation and key concatenation mechanisms, leading to nodes acquiring excessive key information unnecessarily. On the other hand, the key distribution process lacks a lightweight, verifiable authentication path, making it difficult to ensure key integrity and consistency under weak connection conditions. Furthermore, existing update strategies are rigid and cannot dynamically trigger differentiated updates based on member roles, regional capacity, or network status, making it difficult to balance security strength and communication efficiency.

[0006] In summary, existing group key management schemes are insufficient for achieving secure, efficient, and scalable key distribution and updates in dynamic wireless networks. There is an urgent need for a new group key management method with regional management capabilities and support for fragmented key distribution and localized updates, so as to significantly reduce communication overhead and improve the engineering availability of the system while ensuring forward confidentiality and consistency. Summary of the Invention

[0007] To address the problems of high overhead in network-wide synchronous updates, excessive key information leakage, and insufficient consistency and integrity guarantees in existing dynamic wireless network group key management, this invention proposes a physical layer group key distribution method based on region partitioning. This method divides regions according to the order of node joining and capacity thresholds, distributes and updates physical layer keys in fragmented form, and combines this with information carrying integrity verification to achieve verifiable distribution. In scenarios with no new member nodes and member node exits, it employs periodic updates by region and local updates by role, respectively. Through regional management, fragmented distribution, and local updates, this invention reduces communication and coordination overhead and improves system scalability and engineering availability while maintaining integrity verification and forward confidentiality.

[0008] The technical solution of this invention is as follows:

[0009] A physical layer group key distribution method based on region partitioning includes the following steps:

[0010] Step 1: Divide the dynamic wireless network into regions according to the order in which nodes join and based on a preset capacity threshold, and determine the nodes within each region and the nodes across regions;

[0011] Step 2: The newly added node and its predecessor node generate symmetric pair keys using physical layer channel characteristics, and the pair keys are segmented.

[0012] Step 3: The preceding node constructs distribution information based on the selected key fragment and the corresponding fragment of the previous round group key, and broadcasts the distribution information within the region after adding an integrity check;

[0013] Step 4: Enable the nodes within the group to receive the distribution information and perform consistency verification. After the verification is successful, generate a new group key by splicing fragments.

[0014] Step 5: When no new nodes are added, each region updates its group key according to an independently set period;

[0015] Step 6: When a node exits, trigger a localized update based on the node's role: if it is an intra-region node, only its own region is updated; if it is a cross-region node, both its own region and its directly related adjacent regions are updated.

[0016] A further preferred approach, the specific details of the region division in step 1 include:

[0017] Initially connected nodes automatically form an initial region; when subsequent nodes join, if the number of nodes in the target region has not reached the capacity threshold, they are added to the region as intra-region nodes; if the target region has reached the capacity threshold, a new region is created, and the newly joined nodes are marked as cross-region nodes; each region independently maintains a group key, and the visibility of key materials is limited to the region to which it belongs and adjacent regions.

[0018] A further preferred embodiment is that the pairwise key generation and segmentation process in step 2 is as follows:

[0019] Newly added nodes and their predecessor nodes obtain channel response information through physical layer channel probing; both parties generate identical paired keys based on the channel response information; the paired keys are divided into multiple fragments; both parties retain only the key fragments required for the current round of updates.

[0020] In a further preferred embodiment, in step 2, the channel response information obtained by the newly added node and the preceding node are equal-length bit sequences.

[0021] In a further preferred embodiment, step 3, the process of constructing and broadcasting the distribution information, is as follows:

[0022] The distribution information includes at least a key fragment identifier, a previous round key fragment identifier, and combined data composed of the key fragment and the previous round key fragment according to a preset rule; a hash algorithm is used to calculate a verification value for the distribution information; the preceding node broadcasts the distribution information carrying the verification value to all nodes in this region and related cross-regional nodes.

[0023] In a further preferred embodiment, step 4, the process of performing consistency verification and generating a new group key, is as follows:

[0024] The receiving node verifies the integrity of the distributed information; if the verification passes, it extracts a key fragment from the combined data and generates a new group key by splicing the fragments; if the verification fails, it discards the distributed information and maintains the existing group key unchanged; this step only modifies the key fragment specified in the current round.

[0025] In a further preferred embodiment, step 5 involves periodically updating the group key as follows:

[0026] Each region sets an independent update cycle based on its own communication load or security policy; when the update time arrives, only the nodes in this region complete the group key update process; the update operations of each region are independent of each other and do not trigger network-wide synchronization.

[0027] A further preferred approach, in step 6, involves the following localized update process based on the node's role:

[0028] When a node is detected to have exited, determine the node's role; if it is an intra-region node, perform group key updates only within its own region; if it is a cross-region node, perform group key updates within its own region and all directly related adjacent regions.

[0029] Furthermore, the present invention also proposes an electronic device and a computer-readable storage medium:

[0030] An electronic device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, it implements the above-described physical layer group key distribution method based on region partitioning.

[0031] A computer-readable storage medium storing computer instructions thereon, which, when executed by a processor, perform the above-described physical layer group key distribution method based on region partitioning.

[0032] Beneficial effects

[0033] This invention effectively avoids global key reconstruction caused by member changes through the aforementioned region division and localized update mechanism. By employing paired key segmentation and fragment concatenation techniques, only necessary information is leaked during key distribution, significantly enhancing the system's forward confidentiality and anti-leakage capabilities. Simultaneously, by introducing integrity verification and a region-based independent update strategy, key consistency and system availability can be maintained even under weak connectivity and unstable topology conditions. Furthermore, capacity threshold control and role-based update logic give the system good scalability, providing an efficient and secure solution for group key management in large-scale dynamic wireless networks.

[0034] Additional aspects and advantages of the invention will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of the invention. Attached Figure Description

[0035] The above and / or additional aspects and advantages of the present invention will become apparent and readily understood from the description of the embodiments taken in conjunction with the following drawings, in which:

[0036] Figure 1 A block diagram is generated for the physical layer group key distribution method based on region partitioning;

[0037] Figure 2 The topology results for group key distribution for different area capacities. Detailed Implementation

[0038] The embodiments of the present invention are described in detail below. These embodiments are exemplary and intended to explain the present invention, and should not be construed as limiting the present invention.

[0039] This embodiment takes the dynamic wireless networking of a drone swarm as an example, and uses a physical layer group key distribution method based on region division to realize the group key distribution of the drone swarm, specifically including the following steps:

[0040] Step 1: Divide the dynamic wireless network into regions according to the order in which drone nodes join and based on a preset capacity threshold, and determine the nodes within each region and the nodes across regions.

[0041] In this step, the network is dynamically divided into regions according to the order in which nodes join, and the node size of a single region is limited by a preset capacity threshold. When the first batch of nodes join, an initial region is automatically formed. When a subsequent node requests to join and the target region has not reached the capacity threshold, the node is added to the region as an intra-region node. When the target region has reached the capacity threshold, a new region is created, and the newly joined node is marked as a cross-region node to undertake the connection and key coordination between adjacent regions. The system maintains group keys in each region and, based on the roles of intra-region nodes and cross-region nodes, limits the visibility of key materials to the region to which they belong and necessary adjacent regions, in order to support the subsequent generation and distribution of fragmented group keys and localized updates when members change.

[0042] Record the newly added drone node as Its predecessor node is The dynamic wireless network system divides areas based on the order in which nodes join and a set capacity threshold: the first batch of nodes forms the initial area; when... Join and When the area does not reach the threshold, Accepted as a node within the region; when the region has reached its threshold, a new region will be created and... Mark it as a cross-region node, and update the region-node mapping and the relationship with adjacent regions.

[0043] Step 2: The newly added node and its predecessor node generate symmetric pair keys using physical layer channel characteristics, and the pair keys are segmented.

[0044] In this step, the newly joined node and its predecessor node perform channel probing on the physical layer channel within their respective regions to obtain symmetrical channel response information, and generate paired keys for subsequent distribution based on this information. The generation process includes: the newly joined node and the predecessor node respectively sample and process the received signal to obtain a bit sequence of equal length, and both parties independently derive the same paired key based only on their respective observed physical layer characteristics; after obtaining the paired key, it is segmented; after segmentation, both parties only need the segment required for the current round to limit the leakage range of key information and provide a basis for subsequent minimum leakage distribution and localized updates.

[0045] Specifically, after determining the region affiliation and predecessor relationship based on step 1, the newly added node and its predecessor node observe and quantize the instantaneous channel response of the same route based on physical layer channel reciprocity. A consistent pairwise key is independently derived from the bit sequences obtained from their respective observations, denoted as... To support subsequent minimal leakage and fragment-level updates, the generated paired keys... Then immediately divide it into segments:

[0046] K i,i-1 =[ K i,i-1 1 , K i,i-1 2 ]

[0047] in This is the first segment of the paired key. This is the second segment; the two segments can be set to equal length or divided according to a preset ratio, and each segment is assigned a segment identifier for distribution and verification. To maintain consistency with the group key representation, the previous round's group key is denoted as...

[0048] GK i-1 =[G K i-1 1 , GK i-1 2 ]

[0049] It was agreed that this round of updates would only select the first fragment of the paired keys for splicing to limit the scope of leakage. To facilitate verifiable synthesis during subsequent broadcasts, the preceding node constructs a combination intermediate quantity based on the fragment selected in this round.

[0050]

[0051] in This represents a bitwise XOR operation. An integrity check value is calculated for the selected segment to form a distribution message for broadcasting.

[0052] mes=[CI,Hash( K i,i-1 1 )]

[0053] in This is a hash-based integrity verification function used only to verify fragments without revealing their plaintext content.

[0054] The above "generation-segmentation-tokenization" process ensures that: only the required segments are leaked and processed to achieve a single effective update; unselected segments... Intermediate data unrelated to this round is not propagated between nodes and is not stored for a long time, thereby minimizing leakage at the fragment level and providing input and boundaries for subsequent broadcasts carrying integrity verification (step 3) and fragment splicing updates (step 4).

[0055] Step 3: The preceding node constructs distribution information based on the selected key fragment and the corresponding fragment of the previous round group key, and broadcasts the distribution information within the region after adding an integrity check.

[0056] In this step, the preceding node constructs distribution information within its region based on the selected segment obtained in step 2 and the corresponding segment of the previous round's group key. This distribution information is then broadcast after an integrity check is appended. The distribution information includes at least a segment identifier indicating the identity of the selected segment, a segment identifier indicating the identity of the previous round's group key segment, and combined data generated from the selected segment and the previous round's group key segment according to a preset combination relationship. The integrity check uses a hash-based message authentication code to calculate a check value for the identifiers and combined data, which is then appended to the distribution information for the receiver to perform consistency checks in subsequent steps. The distribution information only involves the combination result of the selected segment and the previous round's group key segment and does not contain the complete paired key content, thus achieving a distribution strategy with minimal leakage. The preceding node broadcasts the distribution information carrying the integrity check to all intra-group nodes and relevant cross-regional nodes within its region, providing input for subsequent checks and group key updates.

[0057] Specifically, the preceding node distributes the message generated in step 2. Broadcast within its designated area (synchronizing to relevant cross-regional nodes if necessary); the message contains only combined intermediate quantities. Fragment check value Do not carry or The plaintext content; after the broadcast is completed, no additional data unrelated to this round will be disclosed. Based on this, the receiving side performs consistency verification and completes fragment splicing and updating in step 4.

[0058] Step 4: Enable the nodes within the group to receive the distribution information and perform consistency verification. After the verification is successful, generate a new group key by splicing fragments.

[0059] In this step, after receiving the distribution information carrying integrity verification as described in step 3, the nodes within each group and the relevant cross-regional nodes first perform consistency verification on the combined data based on the fragment identifier and verification value in the distribution information. When the verification passes, the selected fragment for updating and the previous round group key fragment are determined from the distribution information according to the preset fragment combination relationship, and a new group key is generated by fragment splicing. This process only involves the specified fragment in this round and does not modify fragments unrelated to this round, so as to maintain minimal leakage and localized updates. If the consistency verification fails, the receiving node discards the distribution information and maintains the existing group key unchanged, waiting for subsequent valid distribution information.

[0060] Specifically, each receiving node obtains the distribution information described in step 3. First, use the group key fragment from the previous round held locally. Recovering candidate fragments from the combination:

[0061]

[0062] in, This is the fragment recovered by XORing the received data from the node. Consistency verification is then performed.

[0063]

[0064] If the verification passes, the group key update for this round will be completed according to the fragment splicing relationship:

[0065] GK i =[ GK i-1 2 , K ̃ i,i-1 1 ]

[0066] Fragments and intermediate data not involved in this round will not be retained; this step only splices and updates the specified fragments, without modifying fragments unrelated to this round, in order to ensure minimal leakage and localized updates.

[0067] Step 5: When no new nodes are added, each region updates its group key according to an independently set period.

[0068] In this step, without the addition of new nodes, each region independently triggers group key updates according to the update cycle, and the update cycles between regions can be different from each other; when the update cycle of a region is reached, only the nodes in that region initiate another group key distribution process to complete the update; the periodic update does not affect the group key status of other regions, thereby maintaining decoupling between regions and reducing the communication overhead caused by network-wide synchronization.

[0069] Specifically, when a preset update cycle is detected and no new nodes are added during the cycle, a periodic group key update is initiated within the region according to a pre-agreed update sequence. Each time, a node pair with a preceding relationship is selected from the sequence as the update pair. The mechanism of steps 2 to 4 is fully reused to generate and segment paired keys, construct and broadcast messages, and update the group key by splicing fragments after completing consistency verification. The entire process does not involve cross-region messages, and unselected fragments and intermediate data unrelated to the current round are not retained for long periods to maintain minimal leakage and regional autonomy.

[0070] Step 6: When a node exits, trigger a localized update based on the node's role: if it is an intra-region node, only its own region is updated; if it is a cross-region node, both its own region and its directly related adjacent regions are updated.

[0071] In this step, when a node exit event is detected, a localized group key update is triggered based on the role determined by the node in step 1. Specifically, when an intra-regional node exits, the group key update is performed only within its own region; when a cross-regional node exits, the group key update is performed simultaneously in its own region and in its directly associated adjacent regions to remove its permissions on the cross-regional path and prevent its retained keys from affecting adjacent regions. The localized update is limited to the corresponding region and does not require full network synchronization, thereby reducing the communication and coordination overhead caused by exit while ensuring forward confidentiality and minimal leakage.

[0072] Specifically, when a node exit event is detected, it is first determined whether it is an intra-regional node or a cross-regional node based on its role as determined in step 1. Then, a group key update is initiated within the defined scope. The update process fully reuses the generation, segmentation, distribution, and splicing mechanisms of steps 2-4, without performing a full network reconstruction. Specific rules are as follows: If the exiting node is an intra-regional node, the update is only performed within its own region. Nodes with prior relationships are selected according to the established update sequence for this region to complete the update, resulting in a new group key. If the exiting node is a cross-regional node, the above update process is triggered independently in its own region and its directly associated adjacent regions, obtaining a new group key version for the corresponding region. The paths involved in the cross-regional node become invalid simultaneously. In either case, the distributed message only contains intermediate fragment combinations and fragment checksums. Unselected fragments and intermediate data unrelated to this round are not propagated between nodes and are not retained for long periods, thus achieving localized updates and minimal leakage. After the update is completed, the group key status of other regions is unaffected.

[0073] Although embodiments of the present invention have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments within the scope of the present invention without departing from the principles and spirit of the present invention.

Claims

1. A physical layer group key distribution method based on region partitioning, characterized in that: Includes the following steps: Step 1: Divide the dynamic wireless network into regions according to the order in which nodes join and based on a preset capacity threshold, and determine the nodes within each region and the nodes across regions; Step 2: The newly added node and its predecessor node generate symmetric pair keys using physical layer channel characteristics, and the pair keys are segmented. Step 3: The preceding node constructs distribution information based on the selected key fragment and the corresponding fragment of the previous round group key, and broadcasts the distribution information within the region after adding an integrity check; Step 4: Enable the nodes within the group to receive the distribution information and perform consistency verification. After the verification is successful, generate a new group key by splicing fragments. Step 5: When no new nodes are added, each region updates its group key according to an independently set period; Step 6: When a node exits, trigger a localized update based on the node's role: if it is an intra-region node, only its own region is updated; if it is a cross-region node, both its own region and its directly related adjacent regions are updated.

2. The physical layer group key distribution method based on region partitioning according to claim 1, characterized in that: The specific steps for dividing the region in step 1 include: Initially connected nodes automatically form an initial region; when subsequent nodes join, if the number of nodes in the target region has not reached the capacity threshold, they are added to the region as intra-region nodes; if the target region has reached the capacity threshold, a new region is created, and the newly joined nodes are marked as cross-region nodes; each region independently maintains a group key, and the visibility of key materials is limited to the region to which it belongs and adjacent regions.

3. The physical layer group key distribution method based on region partitioning according to claim 1, characterized in that: The process of generating and segmenting the paired keys in step 2 is as follows: The newly added node and the preceding node obtain channel response information through physical layer channel probing; both parties generate the same pair of keys based on the channel response information; and the pair of keys are divided into multiple fragments; Both parties retain only the key fragments required for the current round of updates.

4. The physical layer group key distribution method based on region partitioning according to claim 3, characterized in that: In step 2, the channel response information obtained by the newly added node and the preceding node are equal-length bit sequences.

5. The physical layer group key distribution method based on region partitioning according to claim 1, characterized in that: In step 3, the process of constructing and broadcasting the distribution information is as follows: The distribution information includes at least a key fragment identifier, a previous round key fragment identifier, and combined data composed of the key fragment and the previous round key fragment according to a preset rule; a hash algorithm is used to calculate a verification value for the distribution information; the preceding node broadcasts the distribution information carrying the verification value to all nodes in this region and related cross-regional nodes.

6. The physical layer group key distribution method based on region partitioning according to claim 1, characterized in that: Step 4, the process of performing consistency verification and generating a new group key, is as follows: The receiving node verifies the integrity of the distributed information; if the verification passes, it extracts key fragments from the combined data and generates a new group key by splicing the fragments; if the verification fails, it discards the distributed information and maintains the existing group key unchanged. This step only modifies the key segment specified in the current round.

7. The physical layer group key distribution method based on region partitioning according to claim 1, characterized in that: In step 5, the periodic group key update process is as follows: Each region sets an independent update cycle based on its own communication load or security policy; when the update time arrives, only the nodes in this region complete the group key update process; the update operations of each region are independent of each other and do not trigger network-wide synchronization.

8. The physical layer group key distribution method based on region partitioning according to claim 1, characterized in that: In step 6, the process of performing localized updates based on node roles is as follows: When a node is detected to have exited, determine the node's role; if it is an intra-region node, perform group key updates only within its own region; if it is a cross-region node, perform group key updates within its own region and all directly related adjacent regions.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, it implements the physical layer group key distribution method based on region partitioning as described in any one of claims 1 to 8.

10. A computer-readable storage medium storing computer instructions thereon, characterized in that: When the computer instructions are executed by the processor, the physical layer group key distribution method based on region partitioning as described in any one of claims 1 to 8 is performed.