基于SDR的IoT设备物理层加密传输系统

By using an SDR-based IoT device physical layer encrypted transmission system, dynamic key embedding and hardware acceleration coprocessor are employed to solve the problems of large encryption module size, high cost and complex key synchronization in existing technologies, thus achieving secure communication with low latency and low power consumption.

CN224521066UActive Publication Date: 2026-07-17HARBIN INST OF TECH

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Utility models(China)
Current Assignee / Owner
HARBIN INST OF TECH
Filing Date
2025-04-15
Publication Date
2026-07-17

Smart Images

  • Figure CN224521066U_ABST
    Figure CN224521066U_ABST
Patent Text Reader

Abstract

本实用新型提供了基于SDR的IoT设备物理层加密传输系统,具体属于电子通信技术领域;通过物理层动态加密机制实现了信道级安全防护,有效抵御中间人攻击和信号窃听风险,提高了系统的安全性能;采用协处理器独立处理加密运算,在保证加密强度的同时降低能耗;系统支持毫秒级动态密钥更新,通过伪随机序列生成器与硬件时间戳协同工作,确保每次通信建立唯一加密参数。本实用新型包括用户终端和IoT设备终端;用户终端包括应用层模块和用户端SDR芯片模块,IoT设备终端包括执行端SDR芯片模块和执行单元,用户端SDR芯片模块包括基带处理单元、物理层加密协处理器和射频前端,执行端SDR芯片模块包括基带处理单元、物理层解密协处理器和射频前端。
Need to check novelty before this filing date? Find Prior Art

Claims

1. A SDR based IoT device physical layer encrypted transmission system characterized in that, Including user terminals (1) and IoT device terminals (2); The user terminal (1) includes an application layer module (3) and a user terminal SDR chip module (4). The IoT device terminal (2) includes an execution terminal SDR chip module (5) and an execution unit (6). The user terminal SDR chip module (4) includes a baseband processing unit (7), a physical layer encryption coprocessor (8), and a radio frequency front end (10). The execution terminal SDR chip module (5) includes a baseband processing unit (7), a physical layer decryption coprocessor (9), and a radio frequency front end (10). The application layer module (3) is used to generate user instructions and trigger key generation requests, and transmit the user instructions and key generation requests to the user-end SDR chip module (4). The baseband processing unit (7) of the user terminal (1) is configured to encode user instructions and add physical layer frame headers, the frame headers containing timestamp hash values ​​as dynamic key indexes, and generate baseband signals; The physical layer encryption coprocessor (8) of the user terminal (1) is configured to encrypt the baseband signal based on the dynamic key parameters and embed the dynamic key parameters into the encrypted baseband signal; The physical layer encryption coprocessor (8) and the physical layer decryption coprocessor (9) are hardware acceleration modules independent of the baseband processing unit (7), and achieve deep integration of encryption algorithm and baseband modulation through clock cycle level signal processing; The radio frequency front-end (10) of the user terminal (1) is used to modulate the encrypted baseband signal into a wireless signal and transmit it. The radio frequency front-end (10) of the IoT device terminal (2) is used to receive the wireless signal and demodulate it into an encrypted baseband signal. The physical layer encryption coprocessor (8) generates a 256-bit dynamic key based on the current hardware timestamp precision of 1ms and the pre-shared channel characteristics, and embeds the key parameters by modifying the phase perturbation value of the OFDM symbol cyclic prefix; the encrypted signal is up-converted to the 2.4GHz band by the DUC and transmitted by the radio frequency front-end (10); The physical layer decryption coprocessor (9) of the IoT device terminal (2) is configured to extract dynamic key parameters from the encrypted baseband signal and decrypt and recover the original baseband signal based on the parameters. The baseband processing unit (7) of the IoT device terminal (2) is configured to demodulate the original baseband signal, verify the legality of the frame header, and transmit the decrypted user instruction to the execution unit (6) for execution. If the decryption is successful and the frame header CRC verification is passed, the execution unit (6) opens the door lock. If the decryption fails 3 times in a row, the key synchronization is requested through the reverse channel and the illegal signal transmission is blocked. The dynamic key parameters are generated by the pseudo-random sequence generator and the hardware timestamp, and support millisecond-level dynamic updates.