A ris-assisted multi-user physical layer key generation method against close proximity eavesdropping and replay attacks

CN122533741APending Publication Date: 2026-08-07NANJING UNIV OF POSTS & TELECOMM
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
NANJING UNIV OF POSTS & TELECOMM
Filing Date
2026-05-14
Publication Date
2026-08-07

AI Technical Summary

Technical Problem

[0006]本发明旨在解决RIS辅助多用户物理层密钥生成系统中,当面临攻击者“贴近被动窃听”以及“位置重放攻击”这双重威胁时,现有方案安全性失效的问题

Benefits of technology

[0015] (1) By combining dynamic pilot signals with artificial noise (AN), this invention can not only effectively interfere with passive eavesdroppers close to the base station, causing their signal-to-interference-plus-noise ratio to deteriorate sharply, but also completely block position replay attacks from the physical layer through time-varying characteristics, thus solving the security vulnerabilities of traditional static pilot signals.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122533741A_ABST
    Figure CN122533741A_ABST
Patent Text Reader

Abstract

The application belongs to the technical field of wireless communication security and physical layer key generation, and specifically provides a RIS assisted multi-user physical layer key generation method resisting close eavesdropping and replay attack. In view of the double threats of position replay attack and close passive eavesdropping in the reconfigurable intelligent surface (RIS) assisted multi-user key generation, a "double randomization" protection framework is proposed. By introducing dynamic random pilots and zero space artificial noise in the detection protocol layer, and using statistical channel information to optimize the RIS phase in the configuration layer, the joint protection of the double threats is realized, and the secret key rate (SKR) and robustness in the extreme close eavesdropping scene are guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of wireless communication security and physical layer key generation technology, specifically relating to a RIS-assisted multi-user physical layer key generation method that resists proximity eavesdropping and replay attacks. Background Technology

[0002] Physical Layer Key Generation (PLKG) leverages the randomness and reciprocity of wireless channels to provide a shared key for communicating parties without the need for third-party support, and is considered one of the key technologies for secure 6G communication. However, the effectiveness of PLKG is highly dependent on the "sufficient randomness" and "spatial decorrelation" of the channel. In indoor quasi-static environments or scenarios with severe obstruction, the channel changes slowly and the entropy value is low, resulting in a significant decrease in the secret key rate (SKR).

[0003] Reconfigurable Intelligent Surfaces (RIS) enable controlled reconstruction of the propagation environment through programmable phase shifting, providing a new source of high-entropy randomness for low-entropy environments. However, with the introduction of RIS, the system faces more complex security threats. First, there is passive eavesdropping at close range. When an eavesdropper's physical location is extremely close to a base station antenna or a legitimate user, the scattering environment they experience is highly similar to that of a legitimate link. The strong spatial correlation of the channel causes the extractable key rate to approach zero in an information-theoretic sense. Second, there is location replay attack. Under close-range conditions, attackers can record the probe signal from the legitimate end and replay it at high power in the next round, inducing both parties to generate controlled erroneous keys by "cloning" channel characteristics. Existing research mostly assumes that the eavesdropper and the legitimate node are independent, lacking comprehensive protection capabilities in scenarios where close-range eavesdropping and replay attacks coexist.

[0004] Current research on RIS-assisted PLKG mainly falls into two categories. The first category focuses on "random configuration to generate entropy," such as introducing a rapidly fluctuating equivalent channel in the time domain by randomly switching the RIS phase for one-time pad encryption transmission and providing a key source, or increasing channel randomness through random RIS adjustment in low-entropy environments. The second category focuses on "optimized configuration to improve rate," that is, maximizing the SKR by optimizing RIS cell selection or reflection coefficients, such as optimizing the RIS phase to maximize the total key rate under known eavesdropper statistics.

[0005] Existing technologies are generally based on the ideal assumption that eavesdropping and legitimate channels are statistically independent. This makes them ill-equipped to address the strong spatial correlation threats posed when eavesdroppers are close to base stations or users. When the correlation coefficient approaches 1, existing solutions fail to effectively widen the mutual information difference between legitimate and eavesdropping channels, leading to a sharp drop in the SKR (Signal Detection Rate) that can even approach zero. Furthermore, existing solutions lack verification and protection mechanisms for the timeliness of probed signals, making them unable to defend against "location replay attacks" launched by attackers who record and replay historical pilot signals. This can easily lead to legitimate parties generating incorrect keys or being deceived by attackers. Simultaneously, traditional artificial noise designs or single RIS (Reference-Based Randomization) random configuration strategies often fail in highly correlated eavesdropping scenarios close to users because they cannot effectively distinguish the characteristics of legitimate and eavesdropping channels at the physical layer. This makes it difficult for the system to simultaneously guarantee multi-user communication quality while providing joint protection against both passive eavesdropping and active location replay threats within a unified framework. Summary of the Invention

[0006] This invention aims to address the security failure of existing solutions in RIS-assisted multi-user physical layer key generation systems when facing the dual threats of "close-range passive eavesdropping" and "location replay attacks." In close-range eavesdropping scenarios, strong spatial correlation of the channel leads to severe degradation of key capacity; while in replay attack scenarios, existing static detection mechanisms cannot identify recorded signals, easily causing legitimate parties to generate incorrect keys or leak keys. This invention strives to achieve effective defense against both active and passive attacks while ensuring multi-user key generation rate through joint design of protocol layer and physical layer parameters, further improving SKR (Single Key Generation).

[0007] A RIS-assisted multi-user physical layer key generation method to resist proximity eavesdropping and replay attacks is proposed for communication systems operating in Time Division Duplex (TDD) mode, which includes a base station, RIS, legitimate users, and potential proximity eavesdroppers. At the detection protocol level, this method utilizes uplink orthogonal pilots to separate user channels and introduces dynamic random pilots combined with null-space AN in the downlink to resist replay attacks and proximity eavesdropping at the base station. At the RIS configuration level, RIS phase optimization is performed based on statistical CSI to avoid correlation leakage caused by proximity eavesdropping at the user side. The specific steps are as follows:

[0008] Step 1: System initialization and time slot allocation: A coherent time is divided into multiple detection rounds, each round including uplink detection time slots and downlink detection time slots; before the start of the first round of detection, the base station performs initial random phase configuration on the RIS through the RIS controller; before the start of each subsequent round of detection, the base station configures the RIS phase matrix obtained from the previous round of optimization into the RIS, and keeps it unchanged during the uplink and downlink detection of the current round;

[0009] Step 2: Uplink Channel Probing and Multi-User Separation: Legitimate users simultaneously transmit uplink signals using orthogonal Walsh-Hadamard codes as pilot sequences; after receiving the signals, the base station uses the orthogonality of the Walsh codes to despread the signals and obtain the uplink channel estimate for each user.

[0010] Step 3: Downlink null space artificial noise and dynamic pilot generation: The base station calculates its null space projection matrix based on the uplink estimated channel matrix and constructs the AN vector to ensure that the noise is eliminated when it reaches the legitimate user after RIS reflection, while maintaining high power in other directions; at the same time, the base station generates unit-mode random dynamic pilot symbols independent of the time slot.

[0011] Step 4: Downlink signal transmission and anti-replay: The base station uses maximum ratio transmission MRT beamforming to send dynamic pilot signals superimposed with AN; if an eavesdropper launches a replay attack, since the replay is an old pilot signal that does not match the dynamic pilot signal currently generated by the base station, it will be identified and discarded by the system; if the eavesdropper is close to the base station, it will be subject to strong AN interference and will be unable to demodulate the current pilot signal.

[0012] Step 5: Key Source Extraction and Quantization: The legitimate user receives the downlink signal, and the artificial noise is canceled out, which is used as the initial key source; the base station reconstructs the downlink observation using the parameters it transmits and the uplink channel estimation, which serves as the base station-side key source; the two parties subsequently generate the final key through guard band quantization, information coordination, and privacy enhancement.

[0013] Step 6: RIS Phase Optimization Configuration: For scenarios where eavesdroppers are close to users, a multi-user total security key rate maximization problem is constructed; the non-convex problem is relaxed into a semidefinite programming problem using semidefinite relaxation SDR, and the optimal RIS phase matrix is ​​solved iteratively using successive convex approximation SCA for the next round of channel detection.

[0014] The beneficial effects achieved by this invention are as follows:

[0015] (1) By combining dynamic pilot signals with artificial noise (AN), this invention can not only effectively interfere with passive eavesdroppers close to the base station, causing their signal-to-interference-plus-noise ratio to deteriorate sharply, but also completely block position replay attacks from the physical layer through time-varying characteristics, thus solving the security vulnerabilities of traditional static pilot signals.

[0016] (2) For the most challenging scenario of "close-to-user eavesdropping", the RIS phase is optimized by using the semidefinite relaxation (SDR)-successive convex approximation (SCA) algorithm, which maximizes the difference between the legitimate link and the eavesdropping link in a statistical sense. Simulation experiments show that even in the extreme case where the correlation coefficient approaches 1, it can still maintain a high SKR, which is significantly better than the random phase scheme.

[0017] (3) By utilizing Walsh-Hadamard orthogonal pilot and null space design, simultaneous multi-user detection and key generation are realized without time-division polling, thus improving the overall key generation efficiency of the system.

[0018] (4) In addition, the optimized RIS phase configuration enhances the effective signal power of the legitimate channel, significantly reduces the bit inconsistency rate between the legitimate parties under high signal-to-noise ratio, and reduces the overhead of subsequent information coordination. Attached Figure Description

[0019] Figure 1 This is a schematic diagram of a RIS-assisted multi-user key generation system model in a specific embodiment of the present invention.

[0020] Figure 2 This is a time slot allocation diagram of a specific embodiment of the present invention.

[0021] Figure 3 This is a schematic diagram of SDR-SCA convergence in a specific embodiment of the present invention.

[0022] Figure 4 This is a schematic diagram illustrating the relationship between the number of RIS units N and the total security key rate in a specific embodiment of the present invention.

[0023] Figure 5 This is a schematic diagram of the single-user key capacity in a specific embodiment of the present invention.

[0024] Figure 6 This is a schematic diagram of the zero-space artificial noise time-domain waveform verification in a specific embodiment of the present invention.

[0025] Figure 7 This is a schematic diagram of the bit error rate versus signal-to-noise ratio curve in a specific embodiment of the present invention. Detailed Implementation

[0026] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings.

[0027] This invention proposes a physical layer key generation method with dual randomization protection for RIS-assisted multi-user PLKG, aiming to address the security threats posed by the coexistence of proximity-based passive eavesdropping and location replay attacks. This method first introduces a joint mechanism of downlink dynamic random pilots and null-space artificial noise (AN) at the detection protocol layer. By sending independent unit-modulus random phase pilots in each round of downlink and superimposing them with AN based on the null space of legitimate user channel state information (CSI), the time-varying characteristics of the dynamic pilots force the attacker's recorded historical signals to become invalid "expired data," thereby fundamentally blocking location replay attacks at the protocol layer. Simultaneously, the null-space orthogonality ensures that the AN automatically cancels out at legitimate users, while creating strong interference for eavesdroppers close to the base station, effectively suppressing their observation quality. Secondly, addressing the issue of high-correlation leakage caused by eavesdroppers approaching legitimate users, this invention proposes a phase optimization algorithm based on statistical CSI at the RIS configuration layer. It constructs a multi-user total security key rate maximization model and utilizes an iterative algorithm combining semidefinite relaxation (SDR) and successive convex approximation (SCA) to solve for the optimal RIS reflection phase. This maximizes the legitimate link gain and suppresses the eavesdropping link gain from a physical layer statistical perspective, without requiring knowledge of the eavesdropper's instantaneous channel information, thus significantly improving the robustness of key generation in high-correlation scenarios. Furthermore, this framework, combined with uplink orthogonal Walsh-Hadamard pilot technology, achieves accurate separation and estimation of multi-user channels, providing an accurate basis for downlink null space design. Ultimately, it achieves effective defense against both active and passive threats while ensuring the efficiency of multi-user parallel key generation.

[0028] like Figure 1 As shown, consider a RIS-assisted multi-user physical layer key generation system operating in Time Division Duplexing (TDD) mode, where BS is equipped with The base stations with root antennas, UE1, UE2, ..., UEk, are respectively For a single-antenna user, RIS has There are several reflector units, the phase shift of which is configured by the BS via a controller. Simultaneously, there exists a single-antenna eavesdropper, Eve, whose location is unknown but may be in the area posing the greatest threat to the system. Assuming the direct wireless channels between the base station BS and each user are blocked, RIS-assisted key generation is considered. Let C denote the complex field as the channel from BS to RIS. The channel matrix is ​​an N×M dimensional complex matrix used to characterize the amplitude and phase fading characteristics of the wireless channel, and can be expressed as: A set of column vectors, corresponding to the base station root antenna, let ,in Let represent the channel vector from RIS to the m-th antenna of the base station.

[0029] For RIS to the 1st A legitimate user's channel, The channel from RIS to the eavesdropper Eve. From BS to the... The downlink equivalent concatenated channel model for a legitimate user is as follows:

[0030] (1)

[0031] in This is the coefficient matrix of the RIS reflection unit. This represents the amplitude reflection coefficient of a single reflective unit in the RIS. Indicates RIS Phase reflection coefficient of each reflecting unit, Accordingly, the equivalent cascaded channel model from BS to the eavesdropper Eve is as follows:

[0032] (2)

[0033] Typically, due to the large user-to-user distance (greater than half a wavelength), the channel vectors of different legitimate users... They are assumed to be statistically independent. However, in real-world wireless environments, when two receiving nodes (e.g., two users, or a user and an eavesdropper) are physically very close, they experience highly similar scattering environments, resulting in strong spatial correlation in their channels. To quantify this correlation, a spatial correlation coefficient is introduced. Its value is related to the distance between the two receiving nodes. Related, defined as:

[0034] (3)

[0035] in It is a zero-order Bessel function. λ is the carrier signal wavelength. The spatial correlation strength parameter ρ ranges from [0,1]. This parameter is calculated from the distance d between the two receiving nodes and the carrier wavelength λ, and is used to characterize the strength of the spatial correlation between the legitimate channel and the relevant eavesdropping channel. Under the same carrier, the smaller d is, the closer ρ is to 1, indicating a stronger spatial correlation. The larger d is, the smaller ρ is, indicating a weaker correlation.

[0036] Based on this, the legitimate receiver reference channel and its spatially related eavesdropping channels The correlation between them can be expressed as:

[0037] (4)

[0038] in To statistically independent complex Gaussian random components, This represents the variance of the random component.

[0039] Figure 2 The time slot allocation diagram for this method divides a coherent time period into 2P time slots, performing P rounds of channel estimation. The RIS phase changes once per round but remains unchanged within a single uplink and downlink cycle. One round of channel estimation consists of one odd time slot and one even time slot. The method is designed as follows:

[0040] In odd-slot systems, uplink channel sounding is performed first to allow the base station (BS) to acquire channel state information (CSI) from legitimate users. The uplink ul pilot signal uses... Walsh-Hadamard coding, number 1 The number of legitimate users selects the Walsh-Hadamard matrix. The pilot signal is used as the initial signal, and then the pilot signal is transmitted simultaneously. Let... For the first Pilots sent by individual users. The length of the pilot signal ( The signal received by the BS end is represented as follows:

[0041] (5)

[0042] The total pilot signal matrix can be written as The signal received by the BS at this time can be further represented as:

[0043] (6)

[0044] in This is the total uplink path channel matrix from a legitimate user to the base station (BS). , For the first Uplink cascaded channel from one user to the BS. Indicates from The uplink channel vector from each legitimate user to the RIS. This represents the uplink channel matrix from RIS to base station BS. Let be a noise matrix, where all elements are independent and identically distributed. .because Each line is Walsh encoded and is orthogonal, meaning... I K It is a K-order identity matrix. Assume the base station (BS) knows the total pilot signal matrix transmitted by the user. At this time, the BS will receive the signal matrix. Right-multiply the conjugate transpose of the total pilot matrix By utilizing the orthogonality of Walsh codes, multi-user despreading and channel separation are performed to obtain the estimated total channel matrix. :

[0045] (7)

[0046] By utilizing the row orthogonality of the Walsh coding matrix, the above operation can perfectly eliminate interference between different users, making... The The column directly corresponds to the first Uplink channel estimation results for individual users , It can be represented as .

[0047] To counter eavesdroppers near base stations, dynamic pilot signals were jointly designed. and artificial noise Eliminate the threat posed by strongly correlated eavesdropping channels from eavesdroppers located close to the base station. In even-numbered time slots, the base station (BS) uses the channel estimation matrix obtained from the previous odd-numbered time slot. Calculate its conjugate Joint null projection matrix Through the Perform singular value decomposition (SVD), let Select the left singular vector corresponding to the zero singular value to construct , to satisfy This ensures that artificial noise only interferes with eavesdroppers and not with legitimate users. Simultaneously, to maximize the received signal-to-noise ratio (SNR) for legitimate users, a low-complexity maximum ratio transmission (MRT) beamforming scheme is used to design the beamforming vector. , shaped vector The calculation is as follows:

[0048] (8)

[0049] in The total power of the pilots, This represents the complex conjugate of the k-th legal user channel vector, used for phase pre-compensation at the transmitter to achieve in-phase superposition of received signals and maximize signal-to-noise ratio at the user end.

[0050] Therefore, randomized pilot signal It can be defined as:

[0051] (9)

[0052] To ensure the randomness of key generation and effectively resist eavesdropping, in each downlink transmission time slot (i.e. Figure 2 of Independently and dynamically generated dynamic pilot symbols and artificial noise vector . Designed as a unit modulus random phase scalar, i.e. It acts as a dynamic mask, so even if Eve obtains legitimate channel state information by being physically close to the target, she cannot demodulate the randomly changing channel state information. ,also, This injects a new entropy value into legitimate key sources, improving the overall randomness of the key sources. (Artificial noise) Designed for A dimensional random vector whose elements independently follow a distribution , This represents the average power distribution of artificial noise. Describes an MK-order identity matrix. This indicates that the elements of the artificial noise vector are independent and homoscedastic. The remaining dimensions of the corresponding base station channel null space. Its function is to mask dynamic pilot signals. The information is regenerated in each time slot to prevent eavesdroppers like Eve from eliminating noise through multi-time slot observations.

[0053] At this time, the Signals received by a legitimate user during the downlink channel probing phase for:

[0054] (10)

[0055] in , Indicates the first The received additive Gaussian noise of a legitimate user in the downlink channel sounding slot.

[0056] Due to the projection matrix Based on the channel estimation matrix The zero-space construction, so for the first A legitimate user, ideally satisfying Therefore, the artificial noise term attenuates to a negligible level at the legal end, and the user end receives the signal. Further expressed as:

[0057] (11)

[0058] Meanwhile, Eve, the eavesdropper, received the signal. for:

[0059] (12)

[0060] in , This represents the additive Gaussian noise received by the eavesdropper Eve during the downlink channel probe time slot.

[0061] Artificial noise item It will not be eliminated at Eve, becoming a high-power interference signal, even if Eve steals the legitimate user's channel by being close to the base station (BS) during uplink probing. and beamforming vector It also cannot demodulate the dynamic pilot symbols of the current time slot in the presence of strong interference. Therefore, it is impossible to calculate the real key.

[0062] In near-base station eavesdropping scenarios, even if the eavesdropper Eve is extremely close to the base station BS and obtains the line-of-sight (LOS) signal from the base station BS antenna, the artificial noise design of this method remains effective. This is because the artificial noise projection matrix... Only for cascaded channel characteristics reflected from RIS to legitimate users Constructing zero traps, the LOS direct channel vector from base station BS to Eve is legally concatenated with the RIS. The channel vectors exhibit significant spatial differences. Therefore, Eve on the direct path will still suffer from uncancelled high-power artificial noise. Interference, unable to demodulate dynamic pilot symbols Meanwhile, due to the beamforming vector Pointing towards the RIS direction, the signal energy received by Eve in the direct path will be further reduced. Furthermore, due to the randomized pilot design, this method can resist not only passive eavesdropping attacks where Eve is close to the BS, but also active replay attacks where Eve is close to the BS. Assuming Eve is... The time slot recorded the signal transmitted by the base station (BS). And in the current The time-slot replay of the signal attempts to impersonate a legitimate node or induce a legitimate user to generate an incorrect key. Since Eve is unaware that the base station is sending a dynamic pilot signal, at this point... It contains old pilot symbols. The random pilot of this method Each round is independent, and the synchronous random quantity is only known at the base station (BS). The base station (BS) estimates the random quantity in the uplink and then multiplies it by the random quantity it sent in the current round. The true key source for legitimate nodes is , with Eve trying in the current Time slot induces user-generated expired keys A mismatch can lead to failure in subsequent key negotiation (information coordination) phases, or the generated key may be discarded during the verification phase. Due to the dynamic pilot design employed in this method, any signal intercepted at any historical moment is invalid "expired data" for key generation in the current time slot; Eve cannot predict the current... Therefore, it is impossible to carry out an effective location replay attack.

[0063] This refers to a scenario where an eavesdropper, Eve, is close to a legitimate user. At that time, due to the correlation of the channel Beamforming and artificial noise design may fail in this scenario. Therefore, the goal of this method is to optimize the phase reflection matrix of the RIS. The wireless channel is reconstructed to maximize the total secret key rate (Sum Secret Key Rate) for legitimate users. For ease of calculation, the RIS amplitude coefficient is set to... Let the RIS phase reflection coefficient vector be denoted as , ,in At this point, the cascaded channel from base station BS to eavesdropper Eve is:

[0064] (13)

[0065] To highlight the worst-case scenario of near-user eavesdropping, we assume that Eve is completely unaffected by artificial noise due to the correlation of the eavesdropping channel, and the signal received by Eve in the downlink is:

[0066] (14)

[0067] Record Eve's observations for Let the equivalent channel in the beam direction be:

[0068] (15)

[0069] Similarly, allow legitimate users The beam direction equivalent channel is:

[0070] (16)

[0071] Then the user The received signal and Eve received signal can be written as follows:

[0072] (17)

[0073] (18)

[0074] According to the security principles of information theory, the first The upper bound of the security key rate for each user is the conditional mutual information of the mutual information of the observations of the legitimate parties under the given eavesdropper's observations. A decision can be made and written in the following closed form:

[0075] (19)

[0076] in It is the channel observation of legitimate user k obtained by the base station through uplink pilot. It is a channel observation obtained by user k through downlink pilot signals. These are observations eavesdropped on by the eavesdropper during the downlink phase.

[0077] Normalize the noise variance to , where auxiliary functions , , for:

[0078] (20)

[0079] The power of a legitimate user is Eve the eavesdropper's power is legitimate users Cross-correlation with Eve When users When the channel is unrelated to Eve, The value is approximately 0, and the remaining users are not related to Eve's statistics.

[0080] make ,but It can be represented as:

[0081] (twenty one)

[0082] Among them, v n This represents the reflection coefficient of the nth reflecting unit in the RIS. n (t) represents the nth element of vector a(t), which is the equivalent excitation signal incident on the nth unit of RIS after being transmitted by the base station beam P(t) in the tth time slot.

[0083] make , ,but , Therefore, we can further conclude that:

[0084] (twenty two)

[0085] The second-order statistical matrix , and They are respectively , and According to equation (4). and The correlation is determined by the correlation factors. measure, It can be by and This allows RIS optimization to be performed without directly observing the CSI at the Eve end.

[0086] Define the total security key rate as:

[0087] (twenty three)

[0088] Therefore, the optimization problem (P1) is given:

[0089] (twenty four)

[0090] Since the optimization problem is non-convex, a semi-definite relaxation variable matrix is ​​introduced. , And matrix The rank is Using the trace operator of a matrix ,have , To handle the optimization problem (P1) The fourth term introduces a nonnegative relaxation auxiliary variable. The relaxed auxiliary polynomial function is defined as follows:

[0091] (25)

[0092] in , These are combined covariance constant matrices, which are linear combinations of the covariance matrices of legitimate links and eavesdropping links. DC constraints are applied to... Linked to related leaked items:

[0093] (26)

[0094] exist When, the above formula can make and Equivalent correspondence, and then introduce an upper bound variable. Rewrite the goal as maximization and impose constraints:

[0095] (27)

[0096] The new objective function can be solved iteratively using the successive convex approximation (SCA), let , and then In the Next iteration point At that point, the first-order Taylor expansion yields a linear approximation. and .

[0097] (28)

[0098] (29)

[0099] The gradient is:

[0100] (30)

[0101] The optimization problem (P1) can be transformed into a convex optimization problem (P2), represented as:

[0102] (31)

[0103] Problem (P2) can be solved using the CVX toolbox, and the results are obtained through iterative convergence. .

[0104] like If it is approximately rank-1, then take the eigenvector corresponding to its largest eigenvalue. And project it onto the set of unit modulo:

[0105] (32)

[0106] like For non-rank-one variables, Gaussian randomization can be used: generating ,make Multiple samplings were used to obtain The largest one.

[0107] Through the above steps, this method designs the RIS phase optimization configuration as follows: During the first round of channel probing, the base station (BS) sets the RIS to an initial random phase, which adopts an independent and identically distributed uniform random distribution. After the first round of channel probing, the base station (BS) can obtain the optimal RIS phase configuration for the second round of channel probing. Then, after configuring the RIS phase to the optimal phase, it performs the second round of channel estimation, and so on, performing the optimization-estimation process for subsequent rounds. This maximizes the channel gain for legitimate users while suppressing the gain of eavesdropping channels, reducing the threat posed by eavesdroppers (Eve) approaching the user side.

[0108] To verify the feasibility and effectiveness of the proposed protocol, a series of simulation experiments were conducted in the MATLAB environment. The mutual information was calculated using the Information Theoretical Estimator toolbox (ITE). This chapter employs the Monte Carlo method for 10,000 experiments, with channel and noise data randomly generated for each experiment to ensure accuracy.

[0109] Figure 3 The iterative convergence process of the proposed SDR-SCA phase optimization algorithm is presented. It can be seen that the total security key rate for multiple users monotonically increases with the number of iterations and stabilizes within a finite number of iterations, approximately 10-15. This phenomenon is consistent with the solution framework based on DC decomposition and successive convex approximation (SCA) in the scheme, verifying the effectiveness of the algorithm. Meanwhile, the gap between the projected feasible solution and the relaxation upper bound is small, indicating that the semidefinite matrix solution is approximately rank-one, the loss in the unit modulus recovery stage is controllable, and the actual value fits the theoretical value. The projected feasible solution exhibits slight fluctuations at individual iterations, which are due to discretization errors introduced by randomization sampling and numerical projection, but the overall trend remains upward. As the iteration progresses, the increase in the actual value curve gradually decreases and meets the stopping threshold, reflecting that the algorithm enters the "refinement" stage in the mid-to-late stages. Under different SNRs, the total key capacity after convergence increases with increasing SNR, and the initial iteration gain is more significant at high SNRs. This is because, under the premise of noise variance normalization, the improvement in signal-to-noise ratio is equivalent to amplification. , and The effective signal terms increase the overall conditional mutual information expression, resulting in a higher extractable security key capacity. Considering that each iteration only requires solving the convex SDP once and performing phase recovery once, this convergence performance demonstrates that a stable near-optimal configuration can be obtained under a given iteration limit.

[0110] Figure 4 The curves showing the total key capacity of multi-user applications as a function of the number of RIS reflection units N are presented. Overall, the total key capacity increases with increasing N. This is because the cascaded equivalent channel is composed of the superposition of components from each reflection unit. More units bring greater array gain and phase adjustment freedom, which can simultaneously enhance the effective signal power at the legitimate end and improve channel observability, thereby increasing the extractable common randomness. Compared with the random phase baseline, the proposed phase optimization scheme achieves advantages at different numbers of units N. This is because the proposed optimization scheme aims to maximize the key capacity. The optimization process iteratively adjusts the reflection phase under unit modulus constraints, ensuring that the contributions of the legitimate links are coherently superimposed as much as possible, thus improving the statistical power at the legitimate end. It will also suppress the statistical power of the eavesdropping end. and related leaked items This ultimately widens the gap between legitimate and eavesdropping information. Random phase cannot systematically balance gain enhancement and leakage suppression, resulting in a stable performance gap and an overall lower performance curve. This result fully validates the effectiveness of the proposed phase optimization scheme, which effectively improves key capacity compared to traditional random phase schemes. Furthermore, it demonstrates that, under the same hardware scale, structured phase design is more effective than simply stacking units in releasing RIS gain.

[0111] Figure 5 Both (a) and (b) present the correlation coefficient of the single-user security key rate (SKR) with the eavesdropping channel under the conditions of N=16 and SNR=15 dB. The changing trend, where N is the number of RIS units. Figure 5 (a) Corresponding to near-base station scenario: Eve, positioned close to the base station (BS), can implement close-range passive eavesdropping during the uplink detection phase. For traditional RIS-PLKG, the uplink detection received by Eve shares the RIS scattering environment with the legitimate link. When the correlation between the equivalent RIS-Eve link and the RIS-BS link increases, the observation quality of the legitimate channel by the eavesdropping end improves, leading to a reduction in the mutual information difference between the legitimate parties and the eavesdropper, and a monotonically decreasing security key rate. When When the threshold approaches 1, the eavesdropping channel is highly consistent with the legitimate link, and Eve can obtain statistical characteristics and observational information almost equivalent to the BS, causing the key capacity to approach zero. This demonstrates the vulnerability of traditional RIS-PLKG to close-range eavesdropping. In contrast, this method introduces a "double randomization" mechanism, using random pilots to break the synchronization condition of the eavesdropping end with the detection sequence, while simultaneously injecting null space artificial noise (AN) on the BS side, significantly disrupting or even degrading Eve's equivalent observations into invalid information. This defense, in an information theory sense, is equivalent to weakening or erasing Eve's usable observations; therefore, the curve throughout... The correlation remains relatively stable within the range and does not decrease significantly with increasing correlation. The results indicate that even when Eve is close to the base station and has uplink eavesdropping capabilities, the proposed scheme can still effectively block highly correlated links that are being eavesdropped on from close proximity to the base station, significantly improving anti-eavesdropping capabilities and key generation security. Figure 5 (b) Corresponding to user-near scenarios: Eve is positioned close to the user UE, making its RIS-UE scattering link with the legitimate user terminal more statistically correlated. Overall, with... As the value increases from 0 to 1, the similarity between the legitimate link and the eavesdropping link continuously increases. Eve's similarity to the randomness of the legitimate channel increases, leading to a decrease in the number of extractable independent public random sources and a gradual decrease in the security key rate. When the key capacity approaches 1, legitimate users and Eve approximately obtain observations of the same source channel, and the key capacity approaches 0. Based on this, Figure 5(b) Further comparisons were made between the proposed SDR-SCA optimized phase and random phase RIS configuration strategies. The random phase lacks targeted design and cannot suppress leakage terms while improving legitimate mutual information, thus maintaining a low SKR across the entire range. The proposed SDR-SCA method iteratively optimizes the RIS reflection phase to maximize the equivalent safe rate target under the constraint of unity modulus. Essentially, it jointly enhances the mutual information of legitimate links and reduces leakage related to Eve, thus achieving significant gains in the low-to-medium correlation region. It is worth noting that when… When the value is large, the optimization scheme is still constrained by the information theory upper limit, and the gain of the optimal phase will increase with... The phase density gradually decreases as the phase density increases, but still maintains a lead over the random phase in most intervals. This result verifies that, in the more difficult-to-defend scenario of close proximity to the UE, the proposed RIS phase optimization scheme can effectively improve key generation performance and enhance robustness against related eavesdropping.

[0112] Figure 6 Examples of time-domain waveforms under null-space artificial noise (AN) are given to visually verify the spatial selectivity of the interference injection mechanism. The top two figures show the received signal waveforms of the legitimate user and the eavesdropper Eve, respectively. Given the signal power and AN power allocation, the AN vector is projected onto the null space of the legitimate user's equivalent channel matrix. Therefore, the legitimate user's response to AN is theoretically zero or near zero, and the received signal mainly consists of the effective detection sequence and thermal noise, with relatively stable amplitude changes. Conversely, Eve does not satisfy the null-space constraint; its received signal is superimposed with a strong AN component, exhibiting significant random fluctuations and amplitude increases, thus reducing its usable observation quality of the detection signal. The third subfigure further illustrates the amplitude difference of the AN component at the user and Eve ends. Approximately 0, while A value significantly greater than 0 indicates that the artificial noise has aligned with the null space of the legitimate user's channel. User-side leakage is significantly suppressed, while Eve-side leakage remains at a high level. Even considering residual leakage due to finite dimensions and estimation errors, user-side interference is still significantly weaker than Eve-side interference. Because Eve observations exhibit strong random perturbations, their quantization results are difficult to maintain consistency with those of the legitimate end, thus significantly suppressing the key inference capability of the eavesdropping end. This achieves a security enhancement effect of almost no interference for users and strong interference for Eve.

[0113] Figure 7The bit disagreement rate (BDR) of the phase-optimized scheme and the random phase scheme as a function of SNR is presented under the conditions of N=16 and K=4, where K is the number of legitimate users. BDR measures the proportion of bit discrepancies caused by observation noise and estimation errors between the legitimate parties before quantization to generate key bits, directly determining the overhead of subsequent information coordination and error correction. It can be seen that the BDR of both schemes decreases rapidly with increasing SNR, indicating that the uplink and downlink observation disagreement rate is low at higher SNR, consistent with the general rules of physical layer key generation. Although both schemes use the same channel observation and quantization methods, the RIS phase configuration changes the coherence superposition degree of the equivalent concatenated channel, thus altering the statistical distribution of the observed signal amplitude at the legitimate end; under 2-bit quantization, the greater the relative noise of the effective signal, the lower the BDR. The proposed scheme enhances the coherence gain of the legitimate link and improves the effective observation SNR by optimizing the phase through SDR-SCA, significantly reducing the discrepancy after quantization. Therefore, the BDR is lower than that of the random phase scheme across the entire SNR range, with a more significant advantage in the low to medium SNR region. As the SNR further increases, the BDR of both schemes gradually approaches zero, indicating that the system can achieve high-consistency key generation under high signal-to-noise ratio conditions. In summary, Figure 7 From a reliability perspective, the proposed phase optimization scheme not only improves key capacity but also reduces bit inconsistency rate and protocol overhead.

[0114] The above description is only a preferred embodiment of the present invention. The scope of protection of the present invention is not limited to the above embodiments. Any equivalent modifications or changes made by those skilled in the art based on the content disclosed in the present invention should be included within the scope of protection set forth in the claims.

Claims

1. A RIS-assisted multi-user physical layer key generation method resistant to proximity eavesdropping and replay attacks, characterized in that: For communication systems operating in Time Division Duplex (TDD) mode, which include base stations, RIS (Reference Information System), legitimate users, and potential eavesdroppers, this method, at the detection protocol level, utilizes uplink orthogonal pilots to separate user channels and introduces dynamic random pilots combined with null-space AN (Anti-Numerical Array) in the downlink to resist replay attacks and base station-side eavesdropping. At the RIS configuration level, RIS phase optimization is performed based on statistical CSI (Correlation Sequence Indicator) to avoid correlation leakage caused by user-side eavesdropping. The specific steps are as follows: Step 1: System initialization and time slot allocation: A coherent time is divided into multiple detection rounds, each round including uplink detection time slots and downlink detection time slots; before the start of the first round of detection, the base station performs initial random phase configuration on the RIS through the RIS controller; before the start of each subsequent round of detection, the base station configures the RIS phase matrix obtained from the previous round of optimization into the RIS, and keeps it unchanged during the uplink and downlink detection of the current round; Step 2: Uplink Channel Probing and Multi-User Separation: Legitimate users simultaneously transmit uplink signals using orthogonal Walsh-Hadamard codes as pilot sequences; after receiving the signals, the base station uses the orthogonality of the Walsh codes to despread the signals and obtain the uplink channel estimate for each user. Step 3: Downlink null space artificial noise and dynamic pilot generation: The base station calculates its null space projection matrix based on the uplink estimated channel matrix and constructs the AN vector to ensure that the noise is eliminated when it reaches the legitimate user after RIS reflection, while maintaining high power in other directions; at the same time, the base station generates unit-mode random dynamic pilot symbols independent of the time slot. Step 4: Downlink signal transmission and anti-replay: The base station uses maximum ratio transmission MRT beamforming to send dynamic pilot signals superimposed with AN; if an eavesdropper launches a replay attack, since the replay is an old pilot signal that does not match the dynamic pilot signal currently generated by the base station, it will be identified and discarded by the system. If an eavesdropper gets close to the base station, they will be subjected to strong AN interference and will be unable to demodulate the current pilot signal; Step 5: Key source extraction and quantization: The legitimate user receives the downlink signal, and the artificial noise is canceled out, which is used as the initial key source; The base station reconstructs the downlink observation using the parameters it transmits and the uplink channel estimation, which serves as the base station's key source; the two parties then generate the final key through guard band quantization, information coordination, and privacy enhancement. Step 6: RIS Phase Optimization Configuration: For scenarios where eavesdroppers are close to users, this step addresses the problem of maximizing the total security key rate for multiple users. The non-convex problem is relaxed into a semidefinite programming problem using semidefinite relaxation SDR, and the optimal RIS phase matrix is ​​solved iteratively by successive convex approximation SCA for the next round of channel detection.

2. The RIS-assisted multi-user physical layer key generation method for resisting proximity eavesdropping and replay attacks according to claim 1, characterized in that: In step 1, a coherent time period is divided into 2P time slots, and a total of P rounds of channel estimation are performed. The RIS phase changes once in each round and remains unchanged within an uplink and downlink. One round of channel estimation includes one odd time slot and one even time slot.

3. The RIS-assisted multi-user physical layer key generation method for resisting proximity eavesdropping and replay attacks according to claim 1, characterized in that: In step 2, the uplink pilot signal adopts Walsh-Hadamard coding, the first The number of legitimate users selects the Walsh-Hadamard matrix. The pilot signal is used as a guide signal, and then the pilot signal is transmitted simultaneously. make For the first Pilots sent by individual users; The length of the pilot signal ( The signal received by the BS end is represented as follows: (5) The total pilot signal matrix is ​​written as The signal received by the BS at this time can be further represented as: (6) in This is the total uplink path channel matrix from a legitimate user to the base station (BS). For the first Uplink cascaded channel from one user to the BS Let be a noise matrix, where all elements are independent and identically distributed. ;because Each line is Walsh encoded and is orthogonal, meaning... ; Assume the base station (BS) knows the total pilot signal matrix transmitted by the user. At this time, the BS will receive the signal matrix. Right-multiply the conjugate transpose of the total pilot matrix By utilizing the orthogonality of Walsh codes, multi-user despreading and channel separation are performed to obtain the estimated total channel matrix. : (7) By utilizing the row orthogonality of the Walsh coding matrix, the above operation can perfectly eliminate interference between different users, making... The The column directly corresponds to the first Uplink channel estimation results for individual users , Represented as .

4. The RIS-assisted multi-user physical layer key generation method for resisting proximity eavesdropping and replay attacks according to claim 1, characterized in that: In step 3, in order to defend against eavesdroppers near the base station, dynamic pilot signals are jointly designed. and artificial noise Eliminate the threat posed by strongly correlated eavesdropping channels from eavesdroppers located close to the base station; in even-numbered time slots, the base station (BS) uses the channel estimation matrix obtained from the previous odd-numbered time slot. Calculate its conjugate Joint null projection matrix Through the Perform singular value decomposition (SVD) and let Select the left singular vector corresponding to the zero singular value to construct , to satisfy This ensures that artificial noise only disturbs eavesdroppers and not legitimate users.

5. The RIS-assisted multi-user physical layer key generation method for resisting proximity eavesdropping and replay attacks according to claim 1, characterized in that: In step 4, to maximize the received signal-to-noise ratio (SNR) for legitimate users, a low-complexity maximum ratio transmission MRT beamforming scheme is used to design the beamforming vector. , shaped vector The calculation is as follows: (8) in This represents the total power of the pilot signals; Therefore, randomized pilot signal Defined as: (9) Dynamic pilot symbols are generated independently and dynamically in each downlink transmit time slot. and artificial noise vector ; Designed as a unit-modulus random phase scalar, i.e. It acts as a dynamic mask, so even if Eve obtains legitimate channel state information by being physically close to the target, she cannot demodulate the randomly changing channel state information. ,also, Injecting new entropy values ​​into legitimate key sources improves the overall randomness of the key sources; artificial noise Designed for A dimensional random vector whose elements independently follow a distribution ; Its function is to mask dynamic pilot signals. The information is regenerated in each time slot to prevent eavesdroppers like Eve from eliminating noise through multi-time slot observations.

6. The RIS-assisted multi-user physical layer key generation method for resisting proximity eavesdropping and replay attacks according to claim 1, characterized in that: In step 6, the total security key rate is defined as: (23) Given optimization problem P1: (24) Since the optimization problem is non-convex, a positive semidefinite variable is introduced. , And matrix The rank is ,have , To handle the optimization problem P1 The fourth term introduces an auxiliary variable. ,definition: (25) in , Use DC constraints to Linked to related leaked items: (26) exist When, the above formula can make and Equivalent correspondence, and then introduce an upper bound variable. Rewrite the goal as maximization and impose constraints: (27) The new objective function is solved using the successive convex approximation SCA iterative solution, letting , and then In the Next iteration point At that point, the first-order Taylor expansion yields a linear approximation. and ; (28) (29) The gradient is: (30) The optimization problem P1 is transformed into a convex optimization problem P2, which is represented as: (31) Problem P2 was solved using the CVX toolbox, and the results converged iteratively. ; like If it is approximately rank-1, then take the eigenvector corresponding to its largest eigenvalue. And project it onto the set of unit modulo: (32) like If the result is not rank-one, then Gaussian randomization is used: [Generate...] ,make Multiple samplings were used to obtain The largest one.