Secure key sharing utilizing MIMO based encrypted communication

EP4732493A1Pending Publication Date: 2026-04-29TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Filing Date
2023-06-23
Publication Date
2026-04-29

AI Technical Summary

Technical Problem

Secure key agreement in wireless communication systems is challenging due to the need for secure key distribution methods, especially in scenarios where eavesdroppers may intercept the key exchange, and existing solutions often rely on out-of-band procedures that are difficult to implement effectively.

Method used

A method utilizing Multiple Input Multiple Output (MIMO) wireless communication systems to securely transmit keys via spatially separated channels by encrypting a signal with two related codes and transmitting them through distinct channels, ensuring only the intended receiver can decrypt the key using the relationship between the codes.

Benefits of technology

This approach provides a simple and secure method for key distribution, relying on the physical channel and multi-antenna systems to minimize eavesdropping risks, allowing for increased data rates after key establishment, with advantages including simple encryption, no need for a priori code transmission, and utilization of multi-path environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IB2023056517_26122024_PF_FP_ABST
    Figure IB2023056517_26122024_PF_FP_ABST
Patent Text Reader

Abstract

Various embodiments disclosed herein provide a method for providing a key from a transmitter to a received device via spatially separated channels in a Multiple Input Multiple Output (MIMO) wireless communication system. The transmitter device can determine that a multiple path transmission is possible to a receiver, and take the opportunity to securely provide a key for future use to the receiver via spatially separated channels. The transmitter can encrypt a signal comprising a key with a first code to generate a first encrypted signal, and then encrypt the signal with a second code to generate a second encrypted signal, where the second code is based on some function of the first code. The transmitter can then transmit the first encrypted signal and the second encrypted signals via respective spatially separated channels.
Need to check novelty before this filing date? Find Prior Art

Description

SECURE KEY SHARING UTILIZING MIMO BASED ENCRYPTED COMMUNICATION Technical Field

[0001] The present disclosure relates to a method for transmitting a key to a receiver using encryption via spatially separated channels in a Multiple Input Multiple Output (MIMO) wireless communication system. Background

[0002] In the classical security problem where a first party sends information to a second party and wants to do so that an eavesdropper cannot extract the information from the data that the first party sends to the second party. Here, this problem is considered when the communication is wireless over the air from a transmitter to a receiver. This is a well-known problem where cryptography has been applied to block the eavesdropper from getting access to the information in clear text. Here the data that is carrying the information is transformed by a cryptographic operation in a manner that only the receiver (and maybe also the transmitter) can recover the information from the transmitted transformed (also called encrypted) data. The construction of these cryptographic operations uses keys that the transmitter and the receiver agree on for this purpose prior to sending the information and the problem of arranging the keys is referred to as the problem of secure key agreement. As such, the problem of secure information transmission is essentially the problem of secure key agreement. Indeed, this problem of secure key agreement is easier to handle than the original problem but still is considered a very difficult task to solve. Particularly due to the fact that one has to rely on other secure means to perform the a priori secure exchange of key data. These other means are often, for example in standards, referred to as “out-of-band” procedures. In practice it is because of these procedures that secure key agreement is a difficult task.

[0003] It is worth noting that if the communication between the transmitter and the receiver can be arranged as to establish a key between the transmitter and the receiver that an eavesdropper has no knowledge about, then the transmitter and the receiver can switch to use ordinary cryptographic protection means after they have established the keys to be used. Hence, the solution does not have to be able to dealwith the entire data that the transmitter wants to send to the receiver but only a small portion that will result in a key. Since keys are often between 128 to a few thousand bits such an approach would lower the requirements on the keyless part of the solution only to work for a short amount of time. In addition, to achieve so-called key freshness to combat that the risk that using a key for a very long time is known to increase the chances of an eavesdropper breaking in to a cryptosystem, the procedure can be repeated at well-defined occasions and blend-in new key bits with the key in use or entirely replace the key in use.

[0004] When sending data using multiple antennas, there is a trade-off between using these antennas to send multiple spatial steams or using these antennas to beamform a single spatial stream. The former is the preferred approach when the signal-to-noise-ratio (SNR) is sufficiently high as this then significantly increases the data rate that can be supported. On the other hand, when the SNR is poor, the latter approach is preferred as this is an efficient means to enhance the link budget and, in this way, enable communication in scenarios that otherwise would not have been possible.

[0005] Another inherent property with beamforming is that the emitted signal power in different directions can vary considerably. Ideally the signal power is maximized in the direction of the desired receiver, whereas the signal power in other directions typically will be much lower and may even be zero. In fact, just as it is possible to maximize the transmitted signal power in the direction towards the intended receiver, the transmitter can minimize the power in another specific direction. Minimizing the transmitted power in a specific is an effective approach for reducing interference towards other devices and thereby allow for more efficient communications systems where the same channel resources (time and frequency) can be spatially reused.

[0006] There is a general problem related to how to distribute the keys in a secure way prior to sending information securely. Once the keys have been securely distributed, it is typically not a problem if an eavesdropper will be able to receive the signal as traditional cryptography can provided the necessary protection from then on. Summary

[0007] Various embodiments disclosed herein provide for a method for providing akey from a transmitter to a received device via spatially separated channels in a Multiple Input Multiple Output (MIMO) wireless communication system. The transmitter device can determine that a multiple path transmission is possible to a receiver, and take the opportunity to securely provide a key for future use to the receiver via spatially separated channels. The transmitter can encrypt a signal comprising a key with a first code to generate a first encrypted signal, and then encrypt the signal with a second code to generate a second encrypted signal, where the second code is based on some function of the first code. The transmitter can then transmit the first encrypted signal and the second encrypted signals via respective spatially separated channels. Only a receiver that can receive both transmissions, and optionally has knowledge of the relationship of the first code to the second code can then decrypt the transmissions to receive the key.

[0008] In an embodiment, a method can be performed by a transmitter device for transmitting a key to a receiver device using spatially separated channels. The method can include determining that there is a first channel and a second channel that have spatially separate beams that are available to transmit a transmission to a receiver device. The method can also include encrypting a signal with a first code to generate a first encrypted signal, wherein the signal comprises a key and encrypting the signal with a second code to generate a second encrypted signal, wherein the second code is a function of the first code. The method can also include transmitting to the receiver device, the first encrypted signal via the first channel, and the second encrypted signal via the second channel.

[0009] In an embodiment, the method can include transmitting a subsequent transmission to the receiver device, wherein the subsequent transmission is encrypted based on the key.

[0010] In an embodiment, the subsequent transmission is transmitted via spatial multiplexing.

[0011] In an embodiment, the spatial multiplexing is Reconfigurable Intelligent Surface (RIS) aided spatial multiplexing.

[0012] In an embodiment, the first encrypted signal and the second encrypted signal are transmitted via beamforming.

[0013] In an embodiment, the method can include determining that an eavesdropping device can eavesdrop on the first channel.

[0014] In an embodiment, the key is for a future encryption the signal with the first code and the second code is in response to determining that the eavesdropping device can eavesdrop on the first channel.

[0015] In an embodiment, the first code and the second code are at least one of analog or digital codes, or based on real numbers, complex numbers, or numbers with phase variation.

[0016] In an embodiment, the second code is an inverse of the first code.

[0017] In an embodiment, the second code is determined based on a predefined function of the first code.

[0018] In an embodiment, the transmitter device and receiver device are at least one of a user equipment device or a radio access network node device.

[0019] In an embodiment a transmitter device can be provided for transmitting a key to a receiver device using spatially separated channels, the transmitter device can include radio circuitry and processing circuitry. The processing circuitry can determine that there is a first channel and a second channel that have spatially separate beams that are available to transmit a transmission to a receiver device. The processing circuitry can also encrypt a signal with a first code to generate a first encrypted signal, wherein the signal comprises a key and encrypt the signal with a second code to generate a second encrypted signal, wherein the second code is a function of the first code. The processing circuitry can also transmit to the receiver device, the first encrypted signal via the first channel, and the second encrypted signal via the second channel.

[0020] In an embodiment, a method can be performed by a receiver device for receiving a key via spatially separated channels, the method can include receiving a first encrypted signal on a first channel from a transmitter device, receiving a second encrypted signal on a second channel from the transmitter device that has a spatially separate beam from a beam of the first channel, combining the first encrypted signal and the second encrypted signal to form a combined encrypted signal, and decrypting the combined encrypted signal based on a predefined function, wherein decrypting results in a signal comprising a key.

[0021] In an embodiment, the method can include receiving a subsequent transmission from the transmitter device, wherein the subsequent transmission is encrypted based on the key.

[0022] In an embodiment, the method can include decrypting the subsequent transmission based on the key.

[0023] In an embodiment, the subsequent transmission is transmitted via spatial multiplexing.

[0024] In another embodiment, a receiver device can be provided for receiving a key via spatially separated channels, the receiver device can include radio circuitry and processing circuitry. The processing circuitry can receive a first encrypted signal on a first channel from a transmitter device, receive a second encrypted signal on a second channel from the transmitter device that has a spatially separate beam from a beam of the first channel, combine the first encrypted signal and the second encrypted signal to form a combined encrypted signal, and decrypt the combined encrypted signal based on a predefined function, wherein decrypting results in a signal comprising a key.

[0025] An advantage provided by the solutions presented in the present disclosure is that a simple way to distribute the keys is provided that relies on the physical channel and that with multiple antennas at both the transmitter and the receiver it is possible to have a link that effectively can only be eavesdropped if an individual eavesdropper happens to be located in a very specific region.

[0026] The cost associated with distributing the key in this way is that it will be done at a low data rate lower than a full capacity data rate as the transmission relies on spatial multiplexing rather than using the antennas for spatial multiplexing. However, once the key distribution is completed the data rate is increased by using traditional spatial multiplexing, i.e., MIMO. The advantages can include 1) simple encryption, 2) no need to a-priori send a code for decryption, and 3) utilize a multi-path environment. Brief Description of the Drawings

[0027] The accompanying drawing figures incorporated in and forming a part of this specification illustrate several aspects of the disclosure, and together with the description serve to explain the principles of the disclosure.

[0028] Figure 1 illustrates a block diagram of a transmitter and receiver with spatially separated channels according to some embodiments of the present disclosure;

[0029] Figure 2 illustrates a block diagram of a transmitter capable of transmitting a key via spatially separated channels according to some embodiments of the present disclosure;

[0030] Figure 3 illustrates a block diagram of a receiver capable of receiving a key via spatially separated channels according to some embodiments of the present disclosure;

[0031] Figure 4 illustrates a message sequence chart between a transmitter and receiver for communicating a key to a receiver device using spatially separated channels;

[0032] Figure 5 illustrates one example of a cellular communications system according to some embodiments of the present disclosure;

[0033] Figure 6 is a schematic block diagram of a transmitter device according to some embodiments of the present disclosure;

[0034] Figure 7 is a schematic block diagram of the transmitter device of Figure 6 according to some other embodiments of the present disclosure;

[0035] Figure 8 is a schematic block diagram of a receiver device according to some embodiments of the present disclosure; and

[0036] Figure 9 is a schematic block diagram of the receiver device of Figure 8 according to some other embodiments of the present disclosure. Detailed Description

[0037] The embodiments set forth below represent information to enable those skilled in the art to practice the embodiments and illustrate the best mode of practicing the embodiments. Upon reading the following description in light of the accompanying drawing figures, those skilled in the art will understand the concepts of the disclosure and will recognize applications of these concepts not particularly addressed herein. It should be understood that these concepts and applications fall within the scope of the disclosure.

[0038] Network Node: As used herein, a “network node” or “radio access network node” is any node in a Radio Access Network (RAN) of a cellular communications network that operates to wirelessly transmit and / or receive signals. Some examples of a radio access node include, but are not limited to, a base station (e.g., a New Radio (NR) base station (gNB) in a Third Generation Partnership Project (3GPP) Fifth Generation (5G) NR network or an enhanced or evolved Node B (eNB) in a 3GPP Long Term Evolution (LTE) network), a high-power or macro base station, a low-power base station (e.g., a micro base station, a pico base station, a home eNB, or the like), a relaynode, a network node that implements part of the functionality of a base station or a network node that implements a gNB Distributed Unit (gNB-DU)) or a network node that implements part of the functionality of some other type of radio access node.

[0039] Wireless Communication Device: One type of communication device is a wireless communication device, which may be any type of wireless device that has access to (i.e., is served by) a wireless network (e.g., a cellular network). Some examples of a wireless communication device include, but are not limited to: a User Equipment device (UE) in a 3GPP network, a Machine Type Communication (MTC) device, and an Internet of Things (IoT) device. Such wireless communication devices may be, or may be integrated into, a mobile phone, smart phone, sensor device, meter, vehicle, household appliance, medical appliance, media player, camera, or any type of consumer electronic, for instance, but not limited to, a television, radio, lighting arrangement, tablet computer, laptop, or PC. The wireless communication device may be a portable, hand-held, computer-comprised, or vehicle-mounted mobile device, enabled to communicate voice and / or data via a wireless connection.

[0040] Note that the description given herein focuses on a 3GPP cellular communications system and, as such, 3GPP terminology or terminology similar to 3GPP terminology is oftentimes used. However, the concepts disclosed herein are not limited to a 3GPP system.

[0041] Note that, in the description herein, reference may be made to the term “cell”; however, particularly with respect to 5G NR concepts, beams may be used instead of cells and, as such, it is important to note that the concepts described herein are equally applicable to both cells and beams.

[0042] Various embodiments disclosed herein provide for a method for providing a key from a transmitter to a received device via spatially separated channels in a Multiple Input Multiple Output (MIMO) wireless communication system. The transmitter can determine that a multiple path transmission is possible to a receiver, and take the opportunity to securely provide a key for future use to the receiver via spatially separated channels. The transmitter can encrypt a signal comprising a key with a first code to generate a first encrypted signal, and then encrypt the signal with a second code to generate a second encrypted signal, where the second code is based on some function of the first code. The transmitter can then transmit the first encrypted signal and the second encrypted signals via respective spatially separatedchannels. Only a receiver that can receive both transmissions, and optionally has knowledge of the relationship of the first code to the second code can then decrypt the transmissions to receive the key.

[0043] The present disclosure proposes a solution for secured key communication utilizing Multiple Input Multiple Output (MIMO) communication. The present disclosure considers at least 2x2 MIMO between transmitter and receiver. The transmitter two send same signal in two MIMO paths with their encryption. The encryption of a payload for one transmission on one path is a function of the encryption of the payload for another transmission on the other path. The receiver receives two different encrypted signals, post process and perform a math to extract the intended signal. The two separately encrypted signals of the two MIMO paths could be separately pre-coded. Considering any of the two paths in isolation, the encryption is such that the eavesdropper cannot recover the original signal. For example, by adding a random signal to the original one in one path and adding the additive inverse of the random signal to the signal sent in the other path such encryption can be obtained.

[0044] The present disclosure makes use of multi-antenna transmission and reception to enhance the security of the system in addition to just increase the supported data rate. Specifically, during the initial part of the communication where the keys are distributed, the multi-antenna system is optimized to achieve efficient beamforming in order to minimize the risk that an eavesdropper will be able to receive the signal with sufficient energy. This is achieved by e.g., sending a single stream of data, or distributing a time slot, or using different beam sets or different channels. Then, once the key establishment is completed, the transmission is optimized with respect to achievable data rate, i.e., the beamforming is effectively replaced by spatial multiplexing.

[0045] An advantage provided by the solutions presented in the present disclosure is that a simple way to distribute the keys is provided that relies on the physical channel and that with multiple antennas at both the transmitter and the receiver it is possible to have a link that effectively can only be eavesdropped if the eavesdropper happens to be located in a very specific region.

[0046] The cost associated with distributing the key in this way is that it will be done at a low data rate as the transmission relies on beamforming rather than using theantennas for spatial multiplexing. However, once the key distribution is completed the data rate is increased by using traditional spatial multiplexing, i.e., MIMO. The advantages can include 1) simple encryption, 2) no need to a-priori send a code for decryption, and 3) utilize a multi-path environment.

[0047] The core essence of the solution and method is as follows. To transmit the key in a MIMO system, the transmitter can determine when there is more than one channel with not-overlapping beams. Any potential eavesdropper therefore has minimum probability to listen all the channel needed to decode to learn the key. If the transmitter and receiver pair can communicate using MIMO with at least 2x2 transmitter and receivers, the transmitter can generate two encrypted signals from the same signal to transmit. The two encryptions can be functionally related, and the receiver can in some embodiments know the function for encryption. The receiver receives the two signals in MIMO channel, post process and recreate the intended transmitting signal. The multi-channel can be in the spatial domain, and the transmitter can add a precoder. Transmission in a multi-antenna system characterized of that during the key exchange the beamforming of a single stream of possibly two streams are performed, whereas for the actual data transmission the number of spatial streams is increased to allow for increased data rate.

[0048] In an embodiment, the antenna configuration used during the key exchange can be changed such that the beam in the desired direction is kept essentially the same, but where the antenna / beam patterns in at least some of the other directions are changed such as adding one or more nulls.

[0049] In an embodiment, the beamforming is selected such that a null is placed in the direction of an expected eavesdropper.

[0050] Figure 1 illustrates a block diagram of a transmitter device 102 and receiver device 104 with spatially separated channels according to some embodiments of the present disclosure. In the example shown in Figure 1, a transmitter device 102 can transmit spatially separated transmissions 106 and 108 that each reflect off of surfaces 114 and 116 before reaching the receiver device 104 as reflected transmissions 110 and 112. In other embodiments, one of the transmissions may reach the receiver device 104 directly from the transmitter device 102 without any reflections, while another transmission reflects one or more times. In other embodiments, the transmissions can each reflect one or more times. The surfaces 114 and 116 can be any surface on whichthe wireless transmissions can reflect or refract. In some embodiments, one or more of the surfaces 114 and 116 can be reconfigurable intelligent surfaces (RIS) that can be configured to facilitate spatial multiplexing of the transmissions.

[0051] The transmissions 106 / 110 and 108 / 112 can each comprise a key or part of a key where the transmissions have been encrypted using functionally related, but different codes, and where the receiver device 104 can only derive the key from the transmissions 106 / 110 and 108 / 112 if it receives both of the spatially multiplexed transmissions and has knowledge of the functional difference between the first code and the second code. The key can be shared and refreshed at random time frame when there is a minimum probability that an eavesdrop will be able to listen all the channels between the transmitter and receiver such as when the transmitter device 102 can spatially multiplex transmissions to the receiver device 104. In an embodiment, every time there is that opportunity to send spatially separated transmissions, the transmitter device 102 and the receiver device 104 can refresh or update the key or a portion of the key in this process.

[0052] The key (or a key refresh) is shared when there is more than one channel available to send the same signal which the eavesdropper is unable to listen. In that situation a signal is transmitted utilizing at least two channels in a spatial domain multiplexing scenario. The signal carrying the key is coded with two different, but related random complex code to be transmitted through two channels with two beams in different directions. The “key-less” system is used at certain intervals to transmit fresh key material which can be used to blend with the existing key or to replace the existing key. When this is done for the first time the first instance of the shared key is established.

[0053] Figure 2 illustrates a block diagram of a transmitter capable of transmitting a key via spatially separated channels according to some embodiments of the present disclosure.

[0054] The transmitter device 102 is capable of creating at least 2 beams. A signal 202 comprising the key or part of the key can undergo encoding at encoders 210 and 208 that encode the same signal with a C2 code 212 and a C1 code 206 respectively, thus generating a first encrypted signal and a second encrypted signal. In an embodiment, the C1 code 206 could be a random continuous complex number. The C2 code 212 can be determined based on applying a predefined function at the math block204 to the first code from C1 code 206. The first and second codes can be analog or digital, comprised of real numbers or complex numbers, or even be the same number or function with different phase variations. In other embodiments, the C2 code 212 and the C1 code 206 can be entangled, such that their quantum states can be dependent on each other. In other embodiments, the second code can be an inverse of the first code or some other function such that when the first encrypted signal and the second encrypted signal are received at the receiver device 104, and combined, the encoding / encryption applied to each encrypted signal cancels out, leaving an unencrypted signal with the key.

[0055] The first encrypted signal and the second encrypted signal can then be processed in the transmit chains 216 and 214, where gain and delay functions and other beamforming weights are applied to the encrypted signals, which can then be transmitted as spatially separated transmissions 106 and 108 via antenna 218 on spatially multiplexed channels. In an embodiment, the antenna 218 can be an advanced antenna system (AAS), or an array antenna, or a beam forming antenna.

[0056] At a receiver 104 in Figure 3, the process can work in the reverse, where antenna 302 receives the spatially separate transmissions 110 and 112, and after processing in the receive chains 306 and 302, can be decoded at a math block 308 to derive the signal 310 with the key. Like antenna 218, the antenna 302 can be an advanced antenna system (AAS), or an array antenna, or a beam forming antenna. One of the components of each of the receive chains 306 and 310 is an equalizer function that can normalize the encrypted signals, generally based on a reference signal. After equalization, the signals of the two branches are combined at the math block 308 based on the predefined function as the math block 204 as used in the transmitter 102 and the same starting code from C1 code 206.

[0057] In an embodiment, at least one of the two transmissions 110 or 112 received by the receiver device 104 can have reflected off an obstacle or reflector or a Reconfigurable Intelligent Surface to aid in the spatial multiplexing so the two beams propagate toward the targeted receiver. Thus, receiver device 104 can create two beams to receive the two MIMO streams of the same signals. In an embodiment, the transmitter device 102 will only initiate this key transfer process of encrypting the signal with the key with two codes when the pair of the transmitter device 102 and the receiver device 104 are aware of the presence of possible 2x2 MIMO communicationchannels. As mentioned earlier, the math block 308 combines the two streams of MIMO after the equalization applied in the receive chains 306 and 304. As the math is inverse between transmitter device 102 and the receiver device 104, the combined signal is the reconstruction of the signal the transmitter intends to transmit. The equalization can be done using any prior method and this present disclosure is not dependent on any particular method. Even the two streams can be pre-coded in the transmitter device 102 for reciprocal channels in a Time Division Duplex (TDD) communication system.

[0058] In an embodiment, the reference signals are different for different MIMO beams even if the payload is same. Thus, reference signals are not encrypted while the payload is encrypted differently for each beam 106 / 110 and 108 / 112. This example coding is relevant when the receiver can estimate the channel based on reference signal. For a channel based pre-coded signal, this a complex coding can be applied to reference signal also. The interval of the complex code could be random and would be sufficiently small so the reference signal should have more than one code, not to be decoded.

[0059] In an embodiment, the key can be shared in a single transmission or in multiple transmissions where the key will be split into several parts. Multi-part transmission will be done in a situation when there are more than two spatially distributed paths available.

[0060] In an embodiment, if there are more than two potential paths, the transmitter device 102 can decide to transmit a part of the key using only two of the plurality of paths. Then the next part of the key to be transmitted can be sent via a different set of spatial paths. Thus, even if the location of the eavesdropper is not known, by randomizing the path / direction the probability of the eavesdropper to get the channel at all part of key will be minimum. Furthermore, as the channel will vary over time. The spatially distributed MIMO paths also will be different for each transmission of each part of the key or each time the key is refreshed.

[0061] In an exemplary embodiment where the first and second codes are complex code, let the time varying complex code for 1st direction is: ^^= ^^+ ^^^

[0062] If the transmitting signal is S(t), the signal for 1st direction to be transmitted is:^^^_^^^^^^ = ^^^ − ^^^ ∙ ^^^^ − ^^^ ∙ ^ ^^,^^^^

[0063] Then, the would be:

[0064] Similarly for a code for the 2nddirection would be: ^^= ^^+ ^^^^_^^^^^^^ = ^^^^ ∙ ^^^^^ + ^0^

[0065] Where ^0^and ^0^are noises for each of the beam. The combined signal at the receiver device 104 would be: ^^^^^ = ^^^^ ∙ ^^^^^ + ^0^+ ^^^^ ∙ ^^^^^ + ^0^

[0066] As the received signal supposed to be the ^^^^: ^^^^ ∙ ^^^^^ + ^^^^ ∙ ^^^^^ = ^^^^ + ^^

[0067] Where ^^= ^0^+ ^0^, thus: ^^^^^ + ^^^^^ ≈ 1

[0068] Or: ^^^^^ ≈ "1 − ^^^^^#

[0069] Further with scaling factor (5) can be rewritten to ^^^^^ ≈ ^."1 − ^. ^^^^^#

[0070] Where ^ and ^ are two scalar numbers which can be arbitrarily selected based on the use case.

[0071] Figure 4 illustrates a message sequence chart between a transmitter device 102 and a receiver device 104 for communicating a key to a receiver device 104 using spatially separated channels.

[0072] At 402, the transmitter device 102 can determine that there is a first channel and a second channel that have spatially separate beams that are available to transmit a transmission to a receiver device. In some embodiments, there could be more than two channels, but the transmitter device 102 can select a set of two channels.

[0073] At 404, the transmitter device 102 can optionally identify or determine that there is a potential eavesdropper or eavesdropping device that may be able to eavesdrop on a first channel. The transmitter device 102 can do this by determining that there is another device other than the intended receiver device 104 in a location where the other device may be able to intercept a transmission on the first channel.

[0074] At 406 and 408, based on determining that there is a first channel and a second channel that have spatially separate beams, and optionally also on whether the is a potential eavesdropping device from 404, the transmitter device 102 can encrypt a signal that comprises the key, or part of the key, with a first code to generate a first encrypted signal, and encrypt the signal with a second code to generate a second encrypted signal. The first code can be a predefined code and the second code can be determined based on applying a predefined function to the first code. The first and second codes can be analog or digital, comprised of real numbers or complex numbers, or even be the same number or function with different phase variations. In other embodiments, the first and second codes can be entangled, such that their quantum states can be dependent on each other. In other embodiments, the second code can be an inverse of the first code or some other function such that when the first encrypted signal and the second encrypted signal are received at the receiver device 104, and combined, the encoding / encryption applied to each encrypted signal cancels out, leaving an unencrypted signal with the key.

[0075] At 410, the transmitter device 102 can then transmit the first encrypted signal to the receiver device 104 on a first channel and at 412, the transmitter device 102 can transmit the second encrypted signal to the receiver device 104 on a second channel that is spatially separate from the first channel. In an embodiment, at least one of the two transmissions can reflect off an obstacle or reflector or a Reconfigurable Intelligent Surface to aid in the spatial multiplexing, so the two beams propagate toward the targeted receiver. In an embodiment, the transmission of the first encrypted signal at 410 and the transmission of the second encrypted signal at 412 occur at the same time.

[0076] At 414, the receiver device 104 can combine the first encrypted signal and the second encrypted signal. In an embodiment, if the encrypted signals are not precoded, the receiver device 104 can apply equalization to one or both of the encrypted signals to equalize the signals, where the equalization could be based on a reference signal received from the transmitter device 102.

[0077] At 416, the receiver device 104 can decrypt the combined encrypted signal based on a predefined function, wherein decrypting results in a signal comprising a key for a future use. Then at some later time, the transmitter device 102 can transmit at 418, a subsequent transmission that has been transmitted at a full data rate that has been encrypted using the key, and the receiver device 104, at 420 can decrypt thesubsequent transmission.

[0078] Figure 5 illustrates just one example of a cellular communications system 500 in which embodiments of the present disclosure may be implemented. The embodiments of the present disclosure can also be implemented in a WiFi based system or other wireless communications system. In the embodiments described herein, the cellular communications system 500 is a 5G system (5GS) including a Next Generation RAN (NG-RAN) and a 5G Core (5GC) or an Evolved Packet System (EPS) including an Evolved Universal Terrestrial RAN (E-UTRAN) and an Evolved Packet Core (EPC). In this example, the RAN includes base stations 502-1 and 502-2, [which in the 5GS include NR base stations (gNBs) and optionally next generation eNBs (ng-eNBs) (e.g., LTE RAN nodes connected to the 5GC) and in the EPS include eNBs controlling corresponding (macro) cells 504-1 and 504-2. The base stations 502-1 and 502-2 are generally referred to herein collectively as base stations 502 and individually as base station 502. Likewise, the (macro) cells 504-1 and 504-2 are generally referred to herein collectively as (macro) cells 504 and individually as (macro) cell 504. The RAN may also include a number of low power nodes 506-1 through 506-4 controlling corresponding small cells 508-1 through 508-4. The low power nodes 506-1 through 506-4 can be small base stations (such as pico or femto base stations) or Remote Radio Heads (RRHs), or the like. Notably, while not illustrated, one or more of the small cells 508-1 through 508-4 may alternatively be provided by the base stations 502. The low power nodes 506-1 through 506-4 are generally referred to herein collectively as low power nodes 506 and individually as low power node 506. Likewise, the small cells 508-1 through 508-4 are generally referred to herein collectively as small cells 508 and individually as small cell 508. The cellular communications system 500 also includes a core network 510, which in the 5G System (5GS) is referred to as the 5GC. The base stations 502 (and optionally the low power nodes 506) are connected to the core network 510.

[0079] The base stations 502 and the low power nodes 506 provide service to wireless communication devices 512-1 through 512-5 in the corresponding cells 504 and 508. The wireless communication devices 512-1 through 512-5 are generally referred to herein collectively as wireless communication devices 512 and individually as wireless communication device 512. In the following description, the wireless communication devices 512 are oftentimes UEs, but the present disclosure is not limited thereto.

[0080] The transmitter device 102 and the receiver device 104 as described hereincould be one or more of the wireless communications device 512 or radio access network nodes such as base stations 502 or low power nodes 506.

[0081] Figure 6 is a schematic block diagram of a transmitter device 102 according to some embodiments of the present disclosure. Optional features are represented by dashed boxes. The transmitter device 102 may be, for example, a base station 502 or 506 or a network node that implements all or part of the functionality of the base station 502 or gNB described herein or could be a wireless communication device 512. As illustrated, the transmitter device 102 includes a control system 602 that includes one or more processors 604 (e.g., Central Processing Units (CPUs), Application Specific Integrated Circuits (ASICs), Field Programmable Gate Arrays (FPGAs), and / or the like), memory 606, and a network interface 608. The one or more processors 604 are also referred to herein as processing circuitry. In addition, the transmitter device 102 may include one or more radio units 610 that each includes one or more transmitters 612 and one or more receivers 614 coupled to one or more antennas 616. The radio units 610 may be referred to or be part of radio interface circuitry. In some embodiments, the radio unit(s) 610 is external to the control system 602 and connected to the control system 602 via, e.g., a wired connection (e.g., an optical cable). However, in some other embodiments, the radio unit(s) 610 and potentially the antenna(s) 616 are integrated together with the control system 602. The one or more processors 604 operate to provide one or more functions of a radio access node 600 as described herein. In some embodiments, the function(s) are implemented in software that is stored, e.g., in the memory 606 and executed by the one or more processors 604.

[0082] Figure 7 is a schematic block diagram of the transmitter device 102 according to some other embodiments of the present disclosure. The transmitter device 102 includes one or more modules 700, each of which is implemented in software. The module(s) 700 provide the functionality of the transmitter device 102 described herein.

[0083] Figure 8 is a schematic block diagram of a receiver device 104 according to some embodiments of the present disclosure. As illustrated, the receiver device 104includes one or more processors 802 (e.g., CPUs, ASICs, FPGAs, and / or the like), memory 804, and one or more transceivers 806 each including one or more transmitters 808 and one or more receivers 810 coupled to one or more antennas 812. The transceiver(s) 806 includes radio-front end circuitry connected to the antenna(s) 812 that is configured to condition signals communicated between the antenna(s) 812 andthe processor(s) 802, as will be appreciated by one of ordinary skill in the art. The processors 802 are also referred to herein as processing circuitry. The transceivers 806 are also referred to herein as radio circuitry. In some embodiments, the functionality of the receiver device 104 described above may be fully or partially implemented in software that is, e.g., stored in the memory 804 and executed by the processor(s) 802. Note that the receiver device 104 may include additional components not illustrated in Figure 8 such as, e.g., one or more user interface components (e.g., an input / output interface including a display, buttons, a touch screen, a microphone, a speaker(s), and / or the like and / or any other components for allowing input of information into the receiver device 104 and / or allowing output of information from the receiver device 104), a power supply (e.g., a battery and associated power circuitry), etc.

[0084] In some embodiments, a computer program including instructions which, when executed by at least one processor, causes the at least one processor to carry out the functionality of the receiver device 104 according to any of the embodiments described herein is provided. In some embodiments, a carrier comprising the aforementioned computer program product is provided. The carrier is one of an electronic signal, an optical signal, a radio signal, or a computer readable storage medium (e.g., a non-transitory computer readable medium such as memory).

[0085] Figure 9 is a schematic block diagram of the receiver device 104 according to some other embodiments of the present disclosure. The receiver device 104 includes one or more modules 900, each of which is implemented in software. The module(s) 900 provide the functionality of the receiver device 104 described herein.

[0086] Any appropriate steps, methods, features, functions, or benefits disclosed herein may be performed through one or more functional units or modules of one or more virtual apparatuses. Each virtual apparatus may comprise a number of these functional units. These functional units may be implemented via processing circuitry, which may include one or more microprocessor or microcontrollers, as well as other digital hardware, which may include Digital Signal Processors (DSPs), special-purpose digital logic, and the like. The processing circuitry may be configured to execute program code stored in memory, which may include one or several types of memory such as Read Only Memory (ROM), Random Access Memory (RAM), cache memory, flash memory devices, optical storage devices, etc. Program code stored in memory includes program instructions for executing one or more telecommunications and / ordata communications protocols as well as instructions for carrying out one or more of the techniques described herein. In some implementations, the processing circuitry may be used to cause the respective functional unit to perform corresponding functions according to one or more embodiments of the present disclosure.

[0087] While processes in the figures may show a particular order of operations performed by certain embodiments of the present disclosure, it should be understood that such order is exemplary (e.g., alternative embodiments may perform the operations in a different order, combine certain operations, overlap certain operations, etc.).

[0088] Those skilled in the art will recognize improvements and modifications to the embodiments of the present disclosure. All such improvements and modifications are considered within the scope of the concepts disclosed herein.

Claims

Claims 1. A method performed by a transmitter device (102) for transmitting a key to a receiver device (104) using spatially separated channels, the method comprising: determining (402) that there is a first channel and a second channel that have spatially separate beams that are available to transmit a transmission to a receiver device (104); encrypting (406) a signal with a first code to generate a first encrypted signal, wherein the signal comprises a key; encrypting (408) the signal with a second code to generate a second encrypted signal, wherein the second code is a function of the first code; and transmitting (410, 412), to the receiver device (104), the first encrypted signal via the first channel, and the second encrypted signal via the second channel.

2. The method of claim 1, further comprising: transmitting (418) a subsequent transmission to the receiver device (104), wherein the subsequent transmission is encrypted based on the key.

3. The method of claim 2, wherein the subsequent transmission is transmitted via spatial multiplexing.

4. The method of claim 3, wherein the spatial multiplexing is Reconfigurable Intelligent Surface, RIS, aided spatial multiplexing.

5. The method of any of claims 1 to 4, wherein the first encrypted signal and the second encrypted signal are transmitted via beamforming.

6. The method of any of claims 1 to 5, further comprising: determining (404) that an eavesdropping device can eavesdrop on the first channel.

7. The method of any of claims 1 to 6, wherein the first code and the second code are at least one of analog or digital codes, or based on real numbers, complex numbers,or numbers with phase variation.

8. The method of any of claims 1 to 7, wherein the second code is an inverse of the first code.

9. The method of any of claims 1 to 7, wherein the second code is determined based on a predefined function of the first code.

10. The method of any of claims 1 to 9, wherein the transmitter device (102) and receiver device (104) are at least one of a user equipment device (512) or a radio access network node device (502, 506).

11. A transmitter device (102) for transmitting a key to a receiver device (104) using spatially separated channels, the transmitter device (102) comprising radio circuitry and processing circuitry configured to: determine (402) that there is a first channel and a second channel that have spatially separate beams that are available to transmit a transmission to a receiver device (104); encrypt (406) a signal with a first code to generate a first encrypted signal, wherein the signal comprises a key; encrypt (408) the signal with a second code to generate a second encrypted signal, wherein the second code is a function of the first code; and transmit (410, 412), to the receiver device (104), the first encrypted signal via the first channel, and the second encrypted signal via the second channel.

12. The transmitter device (102) of claim 11, wherein the processing circuitry is further configured to: transmit (418) a subsequent transmission to the receiver device (104), wherein the subsequent transmission is encrypted based on the key.

13. The transmitter device (102) of claim 12, wherein the subsequent transmission is transmitted via spatial multiplexing.

14. The transmitter device (102) of claim 13, wherein the spatial multiplexing is Reconfigurable Intelligent Surface, RIS, aided spatial multiplexing.

15. The transmitter device (102) of any of claims 11 to 14, wherein the first encrypted signal and the second encrypted signal are transmitted via beamforming.

16. The transmitter device (102) of any of claims 11 to 15, wherein the processing circuitry is further configured to: determining (404) that an eavesdropping device can eavesdrop on the first channel.

17. The transmitter device (102) of any of claims 11 to 16, wherein the first code and the second code are at least one of analog or digital codes, or based on real numbers, complex numbers, or numbers with phase variation.

18. The transmitter device (102) of any of claims 11 to 17, wherein the second code is an inverse of the first code.

19. The transmitter device (102) of any of claims 11 to 17, wherein the second code is determined based on a predefined function of the first code.

20. The transmitter device (102) of any of claims 11 to 19, wherein the transmitter device (102) and receiver device (104) are at least one of a user equipment device (512) or a radio access network node device (502, 506).

21. A method performed by a receiver device (104) for receiving a key via spatially separated channels, the method comprising: receiving (410) a first encrypted signal on a first channel from a transmitter device (102); receiving (412) a second encrypted signal on a second channel from the transmitter device (102) that has a spatially separate beam from a beam of the first channel; combining (414) the first encrypted signal and the second encrypted signal toform a combined encrypted signal; and decrypting (416) the combined encrypted signal based on a predefined function, wherein decrypting results in a signal comprising a key.

22. The method of claim 21, further comprising: receiving (418) a subsequent transmission from the transmitter device (102), wherein the subsequent transmission is encrypted based on the key.

23. The method of claim 22, further comprising: decrypting (420) the subsequent transmission based on the key.

24. The method of any of claims 22 and 23, wherein the subsequent transmission is transmitted via spatial multiplexing.

25. A receiver device (104) for receiving a key via spatially separated channels, the receiver device (104) comprising radio circuitry and processing circuitry configured to: receive (410) a first encrypted signal on a first channel from a transmitter device (102); receive (412) a second encrypted signal on a second channel from the transmitter device (102) that has a spatially separate beam from a beam of the first channel; combine (414) the first encrypted signal and the second encrypted signal to form a combined encrypted signal; and decrypt (416) the combined encrypted signal based on a predefined function, wherein decrypting results in a signal comprising a key.

26. The receiver device (104) of claim 25, wherein the processing circuitry is further configured to: receive (418) a subsequent transmission from the transmitter device (102), wherein the subsequent transmission is encrypted based on the key.

27. The receiver device (104) of claim 26, wherein the processing circuitry is further configured to:decrypt (420) the subsequent transmission based on the key.

28. The receiver device (104) of any of claims 26 and 27, wherein the subsequent transmission is transmitted via spatial multiplexing.