wireless communication system

The method modifies message physical characteristics to securely exchange payloads, addressing 5G security challenges by encapsulating keys and data within signal properties, enhancing communication security for diverse devices.

JP2025530988APending Publication Date: 2025-09-19KONINKLIJKE PHILIPS NV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2025505959
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-08-05
Filing Date
2023-08-02
Publication Date
2025-09-19

AI Technical Summary

Technical Problem

Existing communication systems, particularly 5G, face security challenges such as Sparrow attacks, unprotected initial message exchanges, and low-layer signaling vulnerabilities, which compromise the integrity and privacy of communications, especially for devices with varying capabilities like IoT tags and V2X-connected vehicles.

Method used

A method for securely exchanging payloads by modifying physical characteristics of messages using measured incoming signal properties, allowing devices to encapsulate and decapsulate encryption keys or data based on these properties, ensuring secure communication without prior key exchange.

Benefits of technology

Enhances security by enabling secure transmission of encryption keys and data during connection establishment, protecting against eavesdropping and ensuring reliable communication for devices with limited processing power and energy constraints.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025530988000001_ABST
    Figure 2025530988000001_ABST
Patent Text Reader

Abstract

The present invention relates to a method for securely exchanging payloads, the method comprising the steps of: an initiator generating an initiation message, wherein the initiator performs a first modification of one or more physical properties of the initiation message and the initiator sending the modified initiation message to a responder; the responder receiving the modified initiation message from the initiator; the responder measuring one or more incoming physical properties of the received modified initiation message; the responder creating a response message to be sent back to the initiator; the responder modifying the one or more physical properties of the response message based on a second modification including a combination of the measured incoming physical properties and the payload and sending the modified response message to the initiator; the initiator receiving the modified response message; and the initiator modifying the received modified response message based on the first modification and extracting the payload from the received modified response message.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a method for securely communicating messages and to corresponding devices and systems, which are particularly relevant to wired and wireless communication systems, for example cellular systems such as 5G or 6G, Wi-Fi systems, ad-hoc systems, satellite communication systems or optical fiber communication systems. [Background technology]

[0002] In a communication network, messages are exchanged between various stations such as mobile stations (or, in the 5G example, user equipment (UE)), base stations (gNB in ​​a 5G system), repeaters, etc. To guarantee the authenticity of the different stations and to prevent others from eavesdropping on the exchanged messages, it is known to use encryption, such as using a shared encryption key or some kind of authenticity signature.

[0003] However, sharing the encryption key also needs to be done securely so as not to compromise the security of subsequent communications. In some systems, the keys are pre-stored on each device, allowing the sharing step to be omitted. However, this limits the possibility of dynamic keys, which are more robust and reduce the risk of compromising the entire system. This can also raise privacy concerns. Therefore, many systems prefer to share keys dynamically, i.e., share a key generated for the current communication. Key distribution is a crucial step, as the encryption secret is not shared between the parties.

[0004] In practice, key exchange methods have many issues, such as the reliability of the exchanged keys (whether they are intercepted or strong enough due to their limited length) and the lack of authentication between the initiator and the responder. Furthermore, it is necessary to find a specific method that is compatible with communication systems such as 5G. Since 5G does not protect the initial messages and L1 and L2 signaling messages, 5G is prone to certain attacks, such as: Sparrow attacks allow UEs that are not registered in the network to communicate with each other via base stations. Unprotected exchange of certain fields of the initial message (such as priority access) Unprotected exchange of low-layer signaling messages, which allows attacks such as IP spoofing and SUPI catching Unsecured RRC connection setup (e.g. no sensitive information can be shared with the network or base station)

[0005] Furthermore, wireless systems such as cellular networks can support low-power devices such as IoT tags, powerful mobile user equipment devices (UE) (e.g., smartphones, V2X-connected vehicles, etc.), or infrastructure devices (e.g., fixed and / or mobile gNBs, V2X roadside units, etc.) with varying capabilities in terms of processing power, energy consumption, memory space, etc. Therefore, key exchange methods must also take such limitations into account. For example, ambient (or passive) IoT devices are small computing devices that have the same security requirements as other devices (e.g., authentication, data protection, privacy protection, etc.) but rely on energy harvesting from ambient radio waves to power themselves. Summary of the Invention [Problem to be solved by the invention]

[0006] Therefore, it is necessary to find ways to support such devices to meet their security requirements.

[0007] The present invention aims to alleviate the above problems.

[0008] Another object of the present invention is to provide a protocol for securely exchanging messages between two entities of a network, such as, for example, a network identity assigned to a device, an encryption key, or data that is encryption / authentication material.

[0009] It is another object of the present invention to provide a communication system that allows for secure exchange of payloads without the need for prior exchange of cryptographic material or pre-shared stored keys.

[0010] It is yet another object of the present invention to provide a device that has the means to securely transmit payloads, such as encryption keys and secrets, at the time of connection establishment for use at later stages of communication. [Means for solving the problem]

[0011] These objects are achieved by the methods, communication devices, computer program products and systems defined in the appended claims.

[0012] Therefore, according to a first aspect of the present invention, a method for securely transmitting a payload is proposed, the method comprising: receiving, by a responder, a start message from an initiator; the responder measuring one or more incoming physical characteristics of the received initiation message and creating a response message to be sent back to the initiator; modifying one or more physical characteristics of the response message based on a combination of the measured incoming physical characteristics and the payload; and sending the modified response message to the initiator.

[0013] Thus, the invention defined in its first aspect allows for encapsulating a bit stream determined by the responder device by physical characteristics of the message received from the initiator, such as the payload. This set of physical characteristics is therefore related to the initiator and the path link over which the received message has traveled. This allows the initiator device to securely decapsulate it. The bit stream may be a key. In that case, this key (or a value derived from it) can be used for security purposes (e.g., encryption at a later operational stage of the communication). Since the bit stream is entirely determined by the responder, the bit stream may be a key containing redundant information (e.g., error correction) to increase the reliability of the scheme.

[0014] In a first variation of the first aspect, the combination of the measured incoming physical signal characteristic and payload is: encoding the payload as a codeword comprising a set of bits, and mapping the set of bits of the codeword to a mapped set of physical property values; generating a combination as the difference between the measured incoming physical signal property and the mapped set of physical property values.

[0015] In a second variant of the first aspect that can be combined with the first variant, the payload is an encryption key used by the initiator for secure communication with the responder.

[0016] In a third variant of the first aspect, which can be combined with the first variant, the payload is a radio network identifier (e.g., RNTI), a preamble (e.g., RACH preamble), or any data used by the initiator and responder for communication, for example.

[0017] In a fourth variant of the first aspect, which can be combined with the first, second, and / or third variants, the physical characteristics of the initiation message and the physical characteristics of the response message include one or more of a phase or phase difference of each carrier relative to a reference carrier, a gain or gain difference of each carrier relative to a reference carrier, a polarization of each beam relative to a reference beam, a modulation symbol, a gain value applied to each beam, an OAM mode, or a phase pattern in an OAM mode.

[0018] In a fifth variant, which can be combined with other variants, the payload includes a useful payload and one or more sets of parity check bits, one or more sets of cyclic redundancy check bits, or a reliability bit string recognized by the initiator.

[0019] In a sixth variant, which can be combined with the previous variants, the payload is obtained by applying a forward error correction algorithm to the set of information bits.

[0020] In a seventh variant of the first aspect, which may be combined with any of the previous variants, the payload is obtained by interleaving a set of information bits with a corresponding sequence of reliability bits known by the initiator.

[0021] In an eighth variant of the first aspect that can be combined with the previous variants, the payload includes an encapsulated key used to protect encoded (e.g., QAM-encoded) data on the signal carrier, for example, by encrypting the data using the encapsulated key.

[0022] In a ninth variant of the first aspect, which can be combined with the eighth variant, the encapsulated key is concatenated or interleaved with the encrypted or encapsulated data.

[0023] According to a second aspect of the present invention, a method for securely exchanging payloads is proposed, the method comprising: generating an initiation message by an initiator, the initiator making a first modification of one or more physical characteristics of the initiation message, and the initiator sending the modified initiation message to the responder; receiving, by the responder, a modified initiation message from the initiator; the responder measuring one or more incoming physical characteristics of the received modified initiation message; the responder creating a response message to be sent back to the initiator; the responder modifying one or more physical characteristics of the response message based on a second modification including a combination of the measured incoming physical characteristic and the payload; sending the modified response message to the initiator; receiving, by the initiator, the modified response message; The initiator modifies the received modified response message based on the first modification, and extracts the payload from the received modified response message.

[0024] In a first variation of the second aspect, the combination of the measured incoming physical signal characteristic and payload includes: encoding the payload as a codeword comprising a set of bits, and mapping the set of bits of the codeword to a mapped set of physical property values; and generating a combination as the difference between the mapped set of physical property values ​​and the measured incoming physical signal property values.

[0025] In a second variant of the second aspect, which can be combined with the first variant, the payload is an encryption key used by the initiator for secure communication with the responder.

[0026] In a third variant of the second aspect, which can be combined with the first variant, the payload is a radio network identifier (e.g., RNTI), a preamble (e.g., RACH preamble), or any data used by the initiator and responder for communication, for example.

[0027] In a fourth variation of the second aspect that may be combined with any of the previous variations, the first modification is a random modification of one or more physical characteristics of the initiation message.

[0028] In a fifth variant of the second aspect that can be combined with any of the previous variants, the physical characteristics of the initiation message and the physical characteristics of the response message include one or more of a phase or phase difference of each carrier relative to a reference carrier, a gain or gain difference of each carrier relative to a reference carrier, a polarization of each beam relative to a reference beam, a modulation symbol, a gain value applied to each beam, an OAM mode, or a phase pattern in an OAM mode.

[0029] In a sixth variant of the second aspect that can be combined with any of the previous variants, the payload includes a useful payload and one or more of a set of one or more parity check bits, a set of one or more cyclic redundancy check bits, or a reliability bit string recognized by the initiator.

[0030] In a seventh variant of the second aspect, which may be combined with any of the previous variants, the payload is obtained by applying a forward error correction algorithm to the set of information bits.

[0031] In an eighth variant of the second aspect, which can be combined with any of the previous variants, the payload is obtained by interleaving a set of information bits with a corresponding sequence of reliability bits that is known by the initiator.

[0032] In a ninth variant of the second aspect, which may be combined with any of the previous variants, the payload includes an encapsulated key used to protect encoded (e.g., QAM-encoded) data on the signal carrier, e.g., encrypting the data using the encapsulated key.

[0033] In a tenth variant of the second aspect, which may be combined with the ninth variant of the second aspect, the encapsulated key is encrypted or concatenated and / or interleaved with the encapsulated data.

[0034] According to a third aspect of the present invention, there is proposed a computer program product comprising code means for generating the steps of either the first or second aspect of the present invention, or possibly of each of the respective variants, when the program product is executed on a computing device.

[0035] According to a fourth aspect of the present invention, a method for securely receiving a payload is proposed, the method comprising: generating an initiation message by an initiator, the initiator making a first modification of one or more physical characteristics of the initiation message, and the initiator sending the modified initiation message to the responder; The initiator receives the response message, modifies the response message based on the first modification, and extracts the payload from the modified response message.

[0036] In a first variant of the fourth aspect of the invention, the payload corresponds to an encryption key, which the initiator uses to decrypt the additional data sent in the received message.

[0037] Any of the variants of the first or second aspect of the invention may be combined with this fourth aspect of the invention or its first variant.

[0038] The following variations can be combined with any of the previous variations of the introduced aspect. First, the initiator and responder are end devices and / or relays (e.g., UE-to-UE relay or UE-to-network relay) communicating via a sidelink communication link. Furthermore, the initiator can be a UE (e.g., V2X UE, ProSe UE, etc.) or an access device (e.g., gNB), and the responder can be a passive / ambient IoT device. Furthermore, a first responder can play the role of a second initiator exchanging payloads with a second responder, thereby combining the roles of both initiator and responder and performing the functions of each role over separate communication links. Furthermore, the established private key can be used as a fallback option when the device (end UE and / or UE-to-UE relay) has not provisioned discovery security material and / or when long-term credentials have expired.

[0039] Further, the established private key can be combined with established or provisioned security material by a cryptographic function to derive a cryptographic key, a MIC, a scrambling sequence, or an encryption sequence, where the cryptographic function is a key derivation function, an encryption algorithm, or an integrity algorithm.

[0040] According to a fifth aspect of the present invention, there is provided a communications apparatus for securely transmitting a payload, the communications apparatus comprising: A receiver; A transmitter; A controller; a memory for storing instructions; This command: causing the receiver to receive a start message from the initiator; causing the controller to measure one or more incoming physical characteristics of the received initiation message; causing the controller to create a response message to be sent back to the initiator; causing the controller to modify one or more physical characteristics of the response message based on a combination of the measured incoming physical characteristics and the payload; The transmitter causes the modified response message to be sent to the initiator.

[0041] According to a sixth aspect of the present invention, a communication device for securely receiving a payload is proposed, the communication device comprising: a controller, a transmitter, a receiver, and a memory containing instructions; This command: causing a controller to generate an initiation message and perform a first modification of one or more physical characteristics of the initiation message; causing the transmitter to transmit a modified initiation message to the responder; causing the receiver to receive the modified reply message; The controller modifies the received modified response message based on the first modification and extracts the payload from the received modified response message.

[0042] According to a seventh aspect of the present invention, there is proposed a communication system for securely exchanging payloads, the communication system comprising: an initiator and a responder, the initiator includes an initiator controller, an initiator transmitter, an initiator receiver, and an initiator memory containing instructions; This command: causing an initiator controller to generate an initiation message and perform a first modification of one or more physical characteristics of the initiation message; causing the initiator transmitter to transmit a modified initiation message to the responder; causing the initiator receiver to receive the modified response message; causing the initiator controller to modify the received modified response message based on the first modification and extract the payload from the received modified response message; the responder includes a responder receiver, a responder transmitter, a responder controller, and a responder memory containing instructions; This command: causing the responder to receive a modified initiation message from the initiator; causing the responder controller to measure one or more incoming physical characteristics of the received modified initiation message; causing the responder controller to modify one or more physical characteristics of the response message based on a second modification including a combination of the measured incoming physical characteristic and the payload to create a modified response message; The responder-transmitter is caused to transmit the modified response message to the initiator.

[0043] It should be noted that the above apparatus can be realized based on a discrete hardware circuit having an arrangement of discrete hardware components, integrated chips, or chip modules, or based on a signal processing device or chip controlled by software routines or programs stored in memory, written to a computer-readable medium, or downloaded from a network such as the Internet.

[0044] It is to be understood that the method of claim 1, the method of claim 8, the method of claim 17, the computer program product of claim 19, the communication device of claim 20, the communication device of claim 21 and the communication system of claim 22 may have similar and / or identical preferred embodiments, in particular the embodiments defined in the dependent claims.

[0045] It should also be understood that a preferred embodiment of the present invention can be any combination of the dependent claims or the above embodiments with the corresponding independent claims.

[0046] These and other aspects of the invention will be apparent from and elucidated with reference to the embodiments described hereinafter. [Brief explanation of the drawings]

[0047] [Figure 1] FIG. 1 is a block diagram illustrating a network in which an embodiment of the present invention is implemented. [Figure 2] FIG. 2 is a block diagram illustrating a mobile station operating in accordance with an embodiment of the present invention. [Figure 3] FIG. 3 is a block diagram illustrating a base station operating in accordance with an embodiment of the present invention. [Figure 4] FIG. 4 is a flow chart illustrating communication according to a first embodiment of the present invention. [Figure 5] FIG. 5 is a flow chart illustrating communications according to an embodiment of the present invention. [Figure 6] FIG. 6 is a flow chart illustrating communications according to an embodiment of the present invention. [Figure 7] FIG. 7 is a flow chart illustrating communications according to an embodiment of the present invention. [Figure 8] FIG. 8 is a block diagram illustrating operations in a communication unit at the physical layer according to an implementation of the present invention. [Figure 9] FIG. 9 is a diagram illustrating the encoding / decoding process according to an implementation of the present invention. [Figure 10] FIG. 10 is a flowchart illustrating communication according to a second embodiment of the present invention adapted to a 5G network. [Figure 11] FIG. 11 is a block diagram that schematically illustrates a network and devices involved in sidelink communication implementing an embodiment of the present invention. [Figure 12] FIG. 12 is a flowchart illustrating communication according to a third embodiment of the present invention adapted for 5G sidelink communication. [Figure 13] FIG. 13 is a flowchart illustrating communication according to a modified example of the third embodiment of the present invention adapted to 5G sidelink communication. DETAILED DESCRIPTION OF THE INVENTION

[0048] Next, embodiments of the present invention will be described with reference to the drawings. As mentioned above, embodiments of the present invention can be implemented in different types of networks, particularly wireless networks, optical fiber networks, satellite-based communication networks, or visible light communication networks. In the specific example shown in FIG. 1, a cellular network is illustrated. Such a cellular network can be a 3G, 4G, or 5G network, or even a Wi-Fi network. Each cell 10 is served by a base station 100 (e.g., a 5G gNB). Multiple secondary stations 120 are located near the cell 10 and the base station 100. At least some of these secondary stations 120 can communicate directly with the base station 100. Furthermore, some of the secondary stations can function as relay stations, relaying communications between the base station 100 and other secondary stations 110. This relay function can be useful, for example, to extend the coverage of the cell 10 to out-of-coverage (OoC) secondary stations 110. The relay stations can be mobile stations (e.g., UEs) or other types of devices. Since 4G and 5G networks include the possibility of relaying by UEs with sidelink capabilities, the relay station and secondary station 110 in Figure 1 are, in this example, UEs with sidelink capabilities.

[0049] Embodiment 1: Physical Layer Key Encapsulation Scheme According to this first embodiment and with reference to FIG. 2 , the mobile station 120 typically includes an antenna 21 or antenna array (e.g., for a MIMO-compatible wireless terminal). The antenna 21 is coupled to a communication unit 22 including a receiver 221 and a transmitter 222. The communication unit 22 is compatible with a 3GPP® standard, such as UMTS, LTE, or NR, and operates according to the current connection. In an embodiment, a controller 23, such as a microprocessor, is included to control the communication unit and its receiver 221 and transmitter 222. Note that the controller 23 may be dedicated to the communication unit 22 or even included within the communication unit 22. The controller 23 may also operate other systems and is not solely dedicated to the communication unit 22. Typically, some or all of the associated processes are operated by software stored in a memory 24 (e.g., ROM or EEPROM) of the mobile station 120. However, the entire invention may also be embodied in component hardware.

[0050] Similarly, as shown in FIG. 3 , the base station 100 typically includes an antenna 31 or antenna array (e.g., for a MIMO-compatible wireless terminal). The antenna 31 is coupled to a communication unit 32 including a receiver 321 and a transmitter 322. The communication unit 32 is compatible with a 3GPP® standard, such as UMTS, LTE, or NR, and can operate according to the current connection. In an embodiment, a controller 33, such as a microprocessor, is included to control the communication unit and its receiver 321 and transmitter 322. Note that the controller 33 may be dedicated to the communication unit 32 or even included within the communication unit 32. The controller 33 may also operate other systems and is not solely dedicated to the communication unit 32. Typically, some or all of the associated processes are operated by software stored in a memory 34 (e.g., ROM or EEPROM) of the base station 100. However, the entire invention may also be embodied in component hardware.

[0051] In accordance with a first embodiment of the present invention, a mobile station 120 (the initiator) wishing to initiate a connection begins by generating a request message. As shown in Figure 4, the physical characteristics of the request message are possibly randomly modified. In this example, in step 1, the initiator generates the modified request message S, for example by assigning a random phase to the subcarriers carrying the request message. I Next, in step 2, the modified request message S I is transmitted to the responder (e.g., base station 100). For simplicity, FIG. 4 shows only the phase θ of the i-th subcarrier. I,I However, this modification may be made to all or a subset of the carriers.

[0052] These random phases can be applied, for example, to carriers in an Orthogonal Frequency Division Multiplexing (OFDM) system. The use of randomized physical characteristics in this and other embodiments can also be applied to other physical characteristics in OFDM systems, for example, related to the amplitude of the carrier. The physical characteristics of the modified message can also have different properties when different types of digital transmission systems or modulations are applied; for example, in a digital transmission system relying on Orbital Angular Momentum (OAM), the physical characteristics refer to the OAM mode or the initial phase of the OAM mode. For example, in a system relying on a digital transmission system based on polarization division multiplexing, the physical characteristics refer to a phase shift or a sense of polarization. For example, in a spatial modulation system, the physical characteristics is a phase shift randomized constellation mapping.

[0053] In step 3, the responder I and its controller receives the equivalent channel phase Φ I@R,i This is subject to noise due to channel response and phase estimation errors, and therefore Φ I@R,I =Φ h ,i+Φ I,i +Φ ε,iThus, in addition to the initial modification of the phase produced by the initiator, further perturbations occur that are related to the particular propagation path between the initiator and the responder.

[0054] Next, in step 4: the responder generates a message, e.g., a random key K, to be used between the initiator and the responder for subsequent secure communication. Instead of a key, it may be another private data, such as a certificate, or a message K, exclusive to the initiator.

[0055] In step 5, the secret message K is encoded (or transformed) as a set of phases on different carriers. For example, the message K can be mapped to the secret phases as follows:

[0056] Let m be the number of bits to encode per phase, and let K = [K seq,1 ,K seq,2 ,···K seq,N ], K seq,i Let K be a randomly generated secret key such that F is a bit sequence of length m. Let F be a mapping function that is also known by the initiator.

number

[0057] In step 6: the secret phase φ K ,i is encapsulated using the channel phase estimate from step 3 as R,i =φ K ,i -φ I@R,i Encapsulation can be thought of as a form of encryption, and φ I,IOnly a party on the same channel with knowledge of K can extract the correct key K, since the "encryption" is tied to the propagation path of the message between the initiator and the responder.

[0058] In step 7, the responder sends a signal S carrying a secret message encapsulated within its subcarrier phase. R Send.

[0059] In step 8, as in step 3, the initiator R The equivalent channel phase is estimated from R@I ,i =φ h,i +φ R,i +φ ε’,i .

[0060] In step 9, φ I,i is φ R@I,i is added to φ K ,i Indeed, as we will see below, by adding an initial random set of physical properties (here phases), the initiator can obtain a phase Φ K ,I can be obtained.

[0061] In particular, it is shown that: φ R@I ,i =φ h,i +φ R,i +φ ε’,i =φ h,i +φ K ,i -φ I@R,i +φ ε’,i (φ R,i (Substitute its equivalent value from step 6) =φ h ,i+φ K ,i -(φ h ,i+φ I,i +φ ε、i )+φ ε’,i (φ I@R,i (Substitute the equivalent value from step 3 for =φ K ,i -φ I ,i -φ ε,i +φε’,i φ R@I,i +φ I,i =φ K ,i -φ I ,i-φ ε,i +φ ε’,i +φ I ,i (φ I,i Adding φ K ,i (unmask the =φ K ,i -φε,i+φε',i

[0062] Next, in step 10: the initiator sets the phase φ′ K ,i to obtain the bit sequences that they map to. Ideally, these bit sequences are seq,i and ultimately reconstructs the secret message K. The extraction process can be described as follows: Let m be the agreed number of bits to encode per phase, and φ' K ,i =φ K ,i -φ ε,i +φ ε’,i Let φ

[0063] The interval [0,2π] is 2 m The jth subinterval is defined as follows:

number

[0064] In which section φ K’ ,i Based on what is entered, the secret bit sequence is obtained as follows: F -1 (φ' K ,i )=RBC(j)

[0065] If there is no error,

number

[0066] Therefore, by obtaining the bit sequences of all subcarrier phases, the initiator can reconstruct the secret message K.

[0067] In this and other embodiments, the Greek letter "φ" used in Figures 4, 5, 6, and 7 and the Greek letter "θ" used in Figures 9 and 10 refer to the same physical property of a signal (e.g., phase), and the symbol is applicable to represent other physical characteristics as well.

[0068] An example of encoding and decoding a secret bit sequence is shown in Figure 9. The secret key bit sequence K seq,i The respective phases θ K,i and extracting it on the receiving side.

[0069] On the left side of Figure 9, m=2, K seq,i ∈{00,01,10,11}, the bit sequence is mapped to a phase as follows, F(K seq,i ) becomes:

number

[0070] So the bit sequence 11 shown on the left side of Figure 9 is mapped to, for example, π. On the right side of Figure 9, the bit sequence is extracted from the secret phase as follows:

number

[0071] Therefore, it falls into the third subinterval (j=2).

number

[0072] In the above embodiment, please note the following reference symbols:

[0073] Two communication partners can use the same channel h, which is assumed to remain constant during the handshake or communication establishment process, and is further defined as: S I , S R : A signal sent by the initiator and responder to each other. φ I,i , φ R,i : the phase of the i-th subcarrier transmitted by the initiator and the responder, respectively. φ I,i is random and may not be known to the responder. φ ε,i , φ ε ',i: Phase estimation error of the phase extracted from the received signal. φ I@R,i , φ R@I,i : The equivalent channel phase estimated at the time of reception by the responder and initiator, respectively. φ K ,i : A secret phase derived from a randomly generated key K.

[0074] Note that in this example, the initiator is a mobile station 120 and the responder is a base station 100. However, as in the following embodiments, this embodiment is also applicable when the initiator is a base station 100 and the responder is a mobile station 120. The embodiment equally applies when the initiator and responder are the same type of device, e.g., two mobile stations 120 or two base stations 100, or two wireless stations. Furthermore, the initiation medium (e.g., bandwidth) and the response medium are the same (or interchangeable) (here, channel h) in the illustrated embodiment. However, the present invention can also be implemented when the response medium is narrow, but is, e.g., included in the initiation medium, or at least included in the correlation medium, e.g., when the respective sets of carriers are not too far apart.

[0075] Thus, in this first embodiment, like the later embodiments, there are two parties involved: an initiator and a responder. These two parties may be, for example: ○ UE to base station (or vice versa) ○ First UE and second UE ○ Base station and smart repeater (or vice versa) ○ A first wireless repeater and a second wireless repeater (e.g., two IAB nodes or two satellites) ○ Wi-Fi® station and Wi-Fi® access point (or vice versa) o Transmitters and receivers within optical communications links, such as on fiber optic communications links.

[0076] The initiator first sends an initial probe message with modified physical properties, which is received by the responder, who then determines or selects a key K or generates a message K and encapsulates it by modifying the physical properties based on the estimated result. The responder then sends a response message containing the encapsulated message K.

[0077] Finally, the initiator receives the response message and decapsulates it by applying the same modifications as in the initial phase.

[0078] This first embodiment can be complemented by the following modifications.

[0079] The secret message is an encapsulated FEC codeword. This allows for more robust transmission and allows for an increase in the number of bits m (or other physical property) coded per phase. This variation is shown in Figure 5. This second embodiment is similar to the first embodiment in steps 1-4. In step 5, a forward error correction (FEC) algorithm is applied to the randomly generated secret message K to obtain a codeword C.

[0080] In step 6, the codeword C is assigned a phase φ C,i , for example, following a Gray code / folded binary code (RBC) to phase mapping. RBC is an ordering of binary sequences such that two consecutive values ​​differ by one bit. Therefore, by using RBC, the bit error rate is reduced in the decoding process, since only one bit changes between the sequence mapped to interval j and the sequences mapped to intervals j+1 and j-1. Steps 7 to 11 are similar to steps 6 to 10 of the first embodiment in Figure 4. Finally, in step 12, the secret message K is obtained using the received codeword.

[0081] Additionally or alternatively, the encrypted secret may include a reliability bit string and / or a CRC. A third embodiment, shown in Figure 6, is similar to the first embodiment with respect to steps 1-4. In step 5, a reliability bit string (RBS), also known to the initiator, is concatenated with a randomly generated secret message K. Alternatively, the RBS can be interleaved with K.

[0082] Steps 6 to 10 are similar to steps 5 to 9 of the first embodiment of FIG.

[0083] In step 11, Extract(φ' K ,i ) yields: [Table 1] * : [a,b] and [c,d] are binary sequences K' seq,i and represent the start and end positions of the subsequence from RBS', so that (ba)+(dc) equals the number of bits encoded per phase.

[0084] In step 12, RBS K The initiator sends a known RBS to all φ', whether concatenated or interleaved. K ,i The initiator can only compare the RBS' with the RBS' after decryption. If RBS ≠ RBS', K We know that K is likely to contain an inverted bit, and if not, K is reliable.

[0085] Note that instead of agreeing on a predefined reliability bit string, the responder could calculate the CRC in step 5 and the initiator could check the CRC in step 12. As an alternative to RBS, a cyclic redundancy check (CRC) can be used for error detection in the transmission of the secret key K. CRCs are widely used in communication protocols and are built into almost every device in software as well as hardware.

[0086] In a variant of the embodiment, in step 5, the randomly generated secret key K is generated by dividing j equal bit sequences K of length l. i (0≦i≦j-1) i For each, CRCc consisting of m parity bits i is calculated, and K iis added to produce a codeword CW of length l+m bits. i =[K i ,c i ]. Then the j codewords are concatenated to form K In total, m*j overhead bits are added to the secret message K before transmission. In step 11, i Bit is K i Since it is interleaved with the bit sequence, Extract(φ' K ,i ) is K' seq,i , c' i , or K' seq,i [a,b]|c' i In step 12, similar to the RBS scenario, we obtain K' i and c' i After both parts of the transmission are obtained, a check for errors is made in the transmission.

[0087] Optionally, in a variation of the above embodiment, the initiator can determine the requested reliability level (RL) in the previous step 0 and signal it together with the request message in step 2. In steps 5 and 11, different FECs can be applied based on the received RL, as shown in Figure 7.

[0088] This embodiment, and others described further below, are also applicable to other schemes used for key establishment at the physical layer. Further options can be used in combination with these embodiments. · Using multiple carriers to exchange a single key bit (for increased reliability).

[0089] As shown in Figure 4, it is expanded as follows: In step 5, each encoded key bit j is mapped to multiple carriers i. In step 6, multiple carriers transmit information about a single key bit. In step 10, the extraction function uses the phase information of multiple carriers to reconstruct a single key bit.

[0090] Variations of this embodiment, and other embodiments described further below, may be characterized by the use / modification of more than one physical characteristic (e.g., phase), i.e., multiple physical characteristics (e.g., phase and amplitude) may be used / modified, thereby increasing data transfer rates when securely exchanging or encapsulating data.

[0091] Embodiment 2: Physical Layer Key Encapsulation Integrated into 5G Initial Access Procedures In a second embodiment, the first embodiment is adapted to a 5G network and can be used during link establishment between a UE and a gNB. The 5G NR initial access procedure is a form of handshake between a user equipment (UE) and a base station (gNB) prior to an authentication procedure, which synchronizes the DL and UL, grants access to the system, and assigns a unique identifier (e.g., C-RNTI) to the UE. The following section describes how the proposed key encapsulation scheme can be integrated into the 5G NR initial access procedure, where the data to be protected corresponds to a random preamble. It can also be integrated into other similar procedures used, for example, for the initial establishment of a communication link in a cellular system.

[0092] Defining the gNB as the initiator and the UE as the responder (i.e., the UE is the party that generates the private key K), the following is defined: θ SS,i : The random and secret phase of the synchronization signal transmitted by the gNB. θ SS@UE,i :θ estimated by UE SS,i , where 1≦i≦N, and N is the number of subcarriers. θ RP,i :The phase of the random preamble sent to the gNB. θ P,i : random preamble phase after encapsulation (θ SS@UE,i (subtract θ P@gNB,i :θ estimated by gNB P,i Equivalent phase.

[0093] Referring to Figure 10, NR initial access can be explained as follows.

[0094] In steps 1 and 2, the gNB broadcasts a synchronization signal (SS) with a secret random phase. This refers to a synchronization signal that includes the MIB and PCI of the cell. Steps 3 to 5 are similar to the first embodiment, except that instead of generating a random key in step 4, the UE selects a random preamble to transmit on the random access channel (RACH). This random preamble is not encoded by QAM symbols as usual, but instead is used as the payload and has a phase θ RP,i The signal is then transmitted in step 6.

[0095] In step 7, the gNB can estimate the equivalent subchannel phase similar to the procedure performed by the UE in step 3. Then, using the same mechanism as described in the first embodiment, the gNB unmasks the random preamble phase and finally extracts the random preamble bits. This approach ensures that an eavesdropper cannot access data that is considered private.

[0096] In another variation, instead of encapsulating the data (e.g., a random preamble), an encryption key can be exchanged between the gNB and the UE (e.g., as in one of the above embodiments), and this key can be used to encrypt / decrypt the QAM modulated data (e.g., a random preamble) on the subcarriers.

[0097] The above variants may be combined, for example, if enough subcarriers are available, the responder may send the encapsulated key (embodiment 1) and the encrypted or encapsulated data value (the previous variant) in the same message. Note that the ratio of subcarriers allocated to encrypted data and encapsulated secret key depends on the size of the secret key, the number of bits coded per phase, and the size of the encapsulated / encrypted data. In any case, this description assumes that both the secret key and the data are transmitted simultaneously and across the available subcarriers.

[0098] In another variant based on 5G in time division duplex (TDD) mode, the secret key and the encapsulated or encrypted data are transmitted separately. That is, the secret key is first encapsulated and transmitted to the initiator. Then, the data is encapsulated or encrypted and transmitted. At the receiving end, the encapsulated key is first received, unmasked, and decrypted as in embodiment 1. Then, a second message containing the data is received. If encrypted, the secret key extracted from the first message is used to decrypt the message (e.g., demodulated QAM symbols). Otherwise, the encapsulated data is unmasked and decrypted as in embodiment 1.

[0099] In another 5G-based variant, at the transmitter, the bit stream can be expanded by adding FEC and interleaving the bit stream, and then the bits can be mapped to modulation symbols (e.g., QAM symbols). Chunks of N QAM symbols can then be used as input to an IDFT (IFET) using N different subcarriers. The reverse processing can be performed at the receiver.

[0100] It should be noted that the following aspects can be combined with any of the other embodiments and are applicable to other schemes for physical layer security that allow for secure exchange of data or keys. A probe signal is generated by generating randomized input data of sufficient length. This randomized data is then mapped onto (randomized) QAM symbols. m When -QAM is used, the randomized input data is k len / m bits, where k len is the number of bits required for the key+FEC or RBS / CRC as in the first, second and third embodiments. The FEC or CRC may be in addition to those shown in FIG. The probe signal can be generated by generating subcarriers in, for example, an FFT block with an initial random phase. In the above embodiment, step 3 is performed during the synchronization phase of the phase and frequency offset correction, before cyclic prefix removal. Additionally, step 6 (Figure 4) can be introduced by setting the output of the QAM modulation to the phase of step 6 or by setting the initial phase of the generated subcarriers to the calculated phase. Additionally, the vector magnitude can be set to a maximum value (e.g., in QAM-64) to ensure maximum distance between the resulting constellation points.

[0101] In a first embodiment (eg corresponding to FIG. 4), steps 8, 9 and 10 are performed during the synchronization phase of the phase and frequency offset correction, before cyclic prefix removal.

[0102] Embodiment 3: Physical Layer Key Encapsulation Integrated into 5G Sidelink Communications In a third embodiment, also with reference to FIG. 11, 110 acts as a base station (e.g., gNB), 120 acts as a 5G ProSe user-to-network relay or in-coverage UE-to-UE relay, 130 acts as a pair of 5G ProSe end UEs, and 140 acts as an out-of-coverage 5G ProSe UE-to-UE relay. The first embodiment is adapted for 5G sidelink (or device-to-device) communications and is used during secure link establishment between 5G ProSe UEs (e.g., between end UEs and / or between an end UE and a relay UE). Here, the initiator and responder are: 1. Two 5G ProSe UEs (e.g., 130 End UE1 and 130 End UE2) attempting to establish a direct PC5 communication link. 2. 5G ProSe remote UE and 5G ProSe UE-to-network relay (e.g., 130 end UE1 and 120). 3. 5G ProSe source end UE and 5G ProSe UE-to-UE relay (first hop-by-hop link, e.g., 130 end UE1 and 140), and 5G ProSe UE-to-UE relay and 5G ProSe target end UE (second hop-by-hop link, e.g., 140 and 130 end UE2). 4. 5G ProSe UE-to-UE relay and one or more 5G ProSe end UEs.

[0103] In the first scenario, specifically in the 5G ProSe Direct Discovery procedure based on Model A, and with reference to Figure 6.1.3.2.2.1-1 of TS33.503, the announcing UE plays the role of the initiator and the monitoring UE plays the role of the responder. In step 11 of the above figure, the announcing UE announces a ProSe restriction code. This message contains the S that the monitoring UE (responder) uses to encapsulate the payload (e.g., a randomly generated key K). IFollowing the same steps as described in the first, second, or third embodiment, the responder (i.e., monitoring UE) sends the encapsulated payload (e.g., K) to the announcing UE and can establish a security context based on K and / or keys derived therefrom to fall back, for example, if the UE is not configured with discovery security material (e.g., DUIK, DUSK, and / or DUCK). Alternatively, if the monitoring UE needs to perform a match reporting procedure for the MIC check, it can send the encapsulated secret key K to the announcing UE only if the MIC check is successful.

[0104] In the first scenario, specifically in the 5G ProSe Direct Discovery procedure based on Model B, and with reference to Figure 6.1.3.2.2.2-1 of TS33.503, the Discovering UE plays the role of the Initiator and the Discoveree UE plays the role of the Responder. In step 12 of the above figure, the Discoverer UE sends a Query Code, which is transmitted to the S (as described in the first embodiment). I Upon processing the query code in step 13, the discoveree UE (e.g., responder) uses the channel phase estimate of the received signal / message to encapsulate a payload (e.g., a randomly generated key K) as described in the second embodiment, and then transmits it together with the response code in step 14, or encapsulates the response code or encrypts the response code using the randomly generated K or a key derived therefrom and transmits it together with the encrypted payload. The discoverer UE then processes the received message to obtain both the secret key K and the response code. The above embodiments related to transmitting data and secret keys in the same transmission or separately are also applicable to this scenario.

[0105] In a second scenario where a remote UE attempts to establish a PC5 link with a 5G ProSe UE-to-Network Relay, the second embodiment is adapted to establish a secret key between the 5G ProSe remote UE acting as an initiator and the 5G ProSe UE-to-Network Relay acting as a responder, and a Direct Communication Request or discovery message is sent (as described in the first embodiment) to the 5G ProSe UE-to-Network Relay. I After processing the DCR or discovery message and performing any necessary checks (e.g., authorization to use the UE-to-network service), the responder can encapsulate the randomly generated key K and return it to the remote UE (i.e., initiator). As with the previous embodiment, the encapsulated private key (or a key derived therefrom) is a fallback option used to secure the PC5 communication link between the remote UE and the UE-to-network relay, for example, when the UE is not configured with code transmission / reception security material (e.g., DUIK, DUSK, and DUCK) and / or does not have valid long-term credentials.

[0106] In a third scenario where the UE is outside of 3GPP® coverage, the physical layer key encapsulation scheme can provide an alternative means for establishing a secure PC5 communication link between UEs (e.g., end UE and UE-to-UE relay) when, for example, the UE does not have valid long-term credentials or when the UE lacks discovery security material (e.g., DUIK, DUSK, DUCK).

[0107] In a variant of this embodiment, which may be combined with other embodiments or used independently, the key exchanged by the physical layer key encapsulation scheme (denoted KE in this variant of the embodiment) can be used in combination with discovery security material rather than standalone. This addresses the following needs: (1) Because the discovery security material (DUIK, DUSK, DUCK) is typically common to multiple devices, it ensures that a higher level of security is achieved if the security material is leaked or compromised by an attacker. The key KE can be combined with the DUIK, DUSK, or DUCK by using it as input to a cryptographic function (e.g., a key derivation function) used to derive either the final integrity / scrambling / encryption key or the MIC / scrambling / encryption sequence. For example, the MIC is calculated as the least significant bits of the output of a key derivation function that takes the DUIK, the message to be integrity protected, a UTC-based counter, and the KE as input. In this example, this ensures that outsiders (at least not present within the link) cannot interfere with the communication.

[0108] In a related embodiment variant, which may be combined with other embodiments or used independently, the key exchanged by the physical layer key encapsulation scheme (denoted KE in this embodiment variant) is not standalone but can be used in combination on demand with discovered security material or other established keys (e.g., symmetric keys) when these established keys are used, for example, for integrity protection, confidentiality protection, or scrambling. For example, the KE can be used as input in the generation of an MIC, which is generated from a pre-established or pre-configured integrity key Kinc. For example, it can be used as KDF(Kinc, message|KE), where KDF(a, b) refers to the key derivation function (KDF) of b that takes a as an input cryptographic function, where the KDF is, for example, HMAC-SHA256, and a|b refers to the concatenation of a and b. Whether a KE is used at a particular time or for a particular message, or how the KE is obtained (e.g., which physical characteristics (e.g., carrier) or which parameters are used to determine the KE) can be decided by communicating devices A and B, or by a third device. This decision can be made randomly using a secure random generation procedure. When a KE is used is exchanged between A and B and configured securely (i.e., in an integrity and protected manner) by a third device, etc., so that an eavesdropper or man-in-the-middle cannot know when a KE is used as an input in the generation of a MIC or in combination with other established keys. This allows communicating devices A and B to be assured that no MitM exists between them.

[0109] In a third scenario and embodiment related to FIG. 12 where the source-end UE acts as the initiator (e.g., Initiator 1), the UE-to-UE relay acts as both the responder and the initiator (Responder 1 for the first hop-by-hop link and Initiator 2 for the second hop-by-hop link), and the target-end UE acts as the responder (e.g., Responder 2), the first embodiment is adapted to establish secret keys based on physical layer key encapsulation and / or exchange or relay payloads for both hop-by-hop links: Steps 1, 2 and 3, as well as steps 4, 5 and 6, are similar to the initial steps of the first embodiment. - Steps 7, 8, 9 and 10, where Responder 2 (i.e., target UE) encapsulates the randomly generated key and sends it to Initiator 2 / Responder 1 (i.e., UE-to-UE relay). The UE-to-UE relay decapsulates and extracts the payload (e.g., secret key) sent by the target UE in steps 11, 12, and 13. This key (e.g., K) and / or keys derived from it are used to secure the second hop-by-hop link as described in previous embodiments (e.g., as a fallback option if no other security material is available / provisioned). Steps 14, 15, 16, and 17 (similar to steps 7, 8, 9, and 10) in which the UE-to-UE relay encapsulates the payload (e.g., a randomly generated key) and sends it to Initiator 1 (i.e., the source UE). - Steps 18, 19, and 20 (similar to steps 11, 12, and 13) in which the source UE decapsulates and extracts the payload (e.g., secret key K'). This key (e.g., K') and / or keys derived therefrom are used to protect the first hop-by-hop link.

[0110] It should be noted that the steps defined in Figure 12 may be performed in a different order, skipped, or repeated. For example, a variation of this embodiment may skip step 14 and instead have the UE-to-UE relay extract the payload (e.g., data / private key sent by the target UE), encapsulate it, and send it to the source UE. Thus, the payload (e.g., the private key and / or keys derived therefrom) can be the basis for securing both hop-by-hop links.

[0111] In another embodiment variant, step 17 is performed earlier (e.g., before step 10) to establish a secret key that ensures the security of the first hop-by-hop link independently of the exchange on the second hop-by-hop link.

[0112] In another embodiment variant that can be combined with other embodiments, the proposed scheme can be used not only to establish secret keys but also to encapsulate data (e.g., RSC, PRUK-ID) that is communicated to another UE (e.g., UE-to-UE or UE-to-network relay) and that requires protection. For example, if code transmission / reception security material is not provisioned at the remote UE, physical layer key encapsulation can provide an alternative means to protect the RSC and PRUK-ID in a remote UE-to-UE-to-network link establishment scenario.

[0113] In a fourth scenario, also in relation to FIG. 13, an end UE that does not have valid discovery security material and / or long-term credentials may receive a notification broadcast by the UE-to-UE relay (acting as an initiator) (S as described in the first embodiment). I13), the UE-to-UE relay can encapsulate the randomly generated keys (e.g., k and k' generated in steps 3 and 3' and encapsulated in steps 5 and 5') and communicate them to the UE-to-UE relay (as in steps 6 / 6' in FIG. 13). The UE-to-UE relay processes the received response signals from steps 6 and 6' as described in the above embodiments to extract the payload (in this example, k and k'). k and k' (or the keys derived from them) can then be used to secure the PC5 communication link between the end UE and the UE-to-UE relay.

[0114] In a variant of the embodiment related to the fourth scenario, the UE-to-UE relay broadcasts an announcement message periodically (e.g., every T seconds) and processes the response signal received from the ProSe end UE within that time period to establish a secret key with the end UE. This has the advantage that a single broadcasted signal / announcement message can establish several secret keys to protect multiple sidelink, PC5 communication links.

[0115] In a variant of the embodiment, which may be combined with other embodiments or used independently, if applicable, the initiator UE (e.g., discoverer UE or announcing UE) transmits sidelink synchronization signals (e.g., sidelink primary synchronization signal (S-PSS) and sidelink secondary synchronization signal (S-SSS)) instead of discovery and / or direct communication messages, the responder UE (e.g., monitoring UE or discoverer UE) may transmit these signals in the S-PSS and S-SSS modes as described in the first embodiment. Ito encapsulate a payload (e.g., data, secret key) and respond to the initiator UE. This has the advantage of providing a means to establish security keys (e.g., when the payload is a secret key) before or during the initial discovery or direct communication message being sent, thus securing such messages in combination with provisioned discovery security material and / or long-term credentials and / or also providing a fallback option in the event that such higher layer security material has not been provisioned to the UE or has expired.

[0116] These embodiments may be combined with other enhancement techniques for physical layer key encapsulation, such as FEC, CRC / RBS, or used independently.

[0117] Embodiment 4: Collocated Resource Allocation In Figure 4, steps 2 and 7 must be performed using the same subcarriers and within a limited time period so that the channel between the initiator and the responder remains unchanged. Furthermore, the processing of messages in these steps may differ slightly from the processing of messages without key encapsulation. Therefore, o In Figure 4, step 2 performs an implicit resource allocation for step 7. In other words, the initiator device sending a message in step 2 implicitly indicates to the receiving device which frequency subcarriers to use in / for the response message. o A resource allocation message is sent to the responder (and optionally the initiator) before steps 2 and 7 indicating the resources allocated in both steps 2 and 7. o A resource allocation message is sent to the responder (and optionally the initiator) before steps 2 and 7 indicating that the messages processed in steps 2 and 7 require the use of the last embodiment (which extends the normal processing of physical layer messages in Figure 5).

[0118] In all the above embodiments, it is possible to improve the transmission and obtain the secret message and the message, for which the signal transmitted by the responder according to step 7 (e.g. in Fig. 4) containing the secret key in its phase is sufficient to extract the secret key and the content of the transmitted signal. This is applicable for example to the above embodiments used to protect the initial 5G PRACH message.

[0119] In an embodiment related to the second embodiment, the message constructed by the UE in step 6 and transmitted in step 7 is constructed as in embodiment 1. K ,j -θ SS@EU,i The value is used to adjust the initial phase of subcarrier i, and data is encoded on subcarrier i. In step 8, the gNB can measure the phase of subcarrier i when the signal is first received and extract the key as in embodiment 1. Data symbols can then be obtained from the subcarrier.

[0120] In another embodiment related to the previous embodiment, the extracted key is used to correct for phase offsets in the received subcarriers.

[0121] In another embodiment, to allow the initiator to obtain both the private key and the data: ○ The responder encapsulates the private key o The responder encapsulates the data or encrypts it before modulating it (e.g., with QAM symbols) and transmits a signal containing the encapsulated secret key and data. ○ Initiator receives the signal The initiator obtains a secret key topology (e.g., steps 9 and 10 of Figure 4), and / or - The initiator obtains the data (e.g., steps 8 and 9 in Figure 10 if the data is encapsulated, or decrypts the data after demodulation if the data is encrypted).

[0122] In a third embodiment of the present invention, a similar protocol applies to other schemes used for key establishment at the physical layer. Thus, one-way encryption can be provided as follows: First, the responder receives the probe signal, The responder then generates a key and an answer message.

[0123] The responder can use the key to encrypt selected fields in the answer message, for example, at the application layer, L2 layer, or L1 layer with a standard encryption algorithm, such as AES in stream cipher mode (e.g., using counter mode).

[0124] The responder then encodes and encapsulates the key into the phase of the subcarriers, adds the encrypted message (e.g., modulated as QAM symbols), and constructs the signal as described above.

[0125] Finally, at the initiator side, the initiator receives the signal and derives the secret key from the phase of the subcarrier, then uses the derived key to decrypt selected encrypted fields of the message.

[0126] Embodiment 5: Application to Ambient IoT Tags In the above embodiments, we have described how physical layer security can be used to protect data exchanged between an initiator and a responder. Such a procedure would be of particular interest in the ambient IoT scenario described in TR22.840, where a UE or access device plays the role of the initiator and the responder is a resource-constrained device such as an ambient IoT tag. The IoT tag can protect the exchanged information as disclosed in other embodiments. This leads to a simplified design of the ambient IoT tag, where expensive features are not required.

[0127] In an embodiment, an IoT tag receives a request from an initiator needing to retrieve data, the IoT tag determines the information to exchange (e.g., a key or the data itself) and can encode / encapsulate it in a response message (e.g., in the initial phase of the OFDM carrier when OFDM modulation is used, so that the initiator can retrieve the information securely).

[0128] In the above example embodiments, the role of initiator / responder is played by different types of wireless devices such as UE, access devices such as gNB, relays (UE-to-UE or UE-to-network relay), and the responder is taken by either of the aforementioned entities or by an (ambient) IoT tag.

[0129] Other variations of the disclosed embodiments can be understood and effected by those skilled in the art in practicing the claimed invention, from a study of the drawings, the disclosure, and the appended claims. In the claims, the word "comprising" does not exclude other elements or steps, and the singular form of an element does not exclude a plurality. A single processor or other unit may fulfill the functions of several items recited in the claims. The mere fact that certain measures are recited in mutually different dependent claims does not indicate that a combination of these measures cannot be used to advantage. The above description details particular embodiments of the invention. However, no matter how detailed the above description may appear in the text, it will be understood that the invention can be embodied in many ways and is therefore not limited to the disclosed embodiments. It should be noted that the use of a particular term in describing a particular feature or aspect of the invention should not be construed as implying that the term has been redefined herein to be limited to include any particular feature of the feature or aspect of the invention with which the term is associated.

[0130] A single unit or device may fulfill the functions of several items recited in the claims. The mere fact that certain measures are recited in mutually different dependent claims does not indicate that a combination of these measures cannot be used to advantage.

[0131] The operations described above may be implemented as program code means of a computer program and / or as dedicated hardware in an associated communication or access device. The computer program may be stored and / or distributed on a suitable medium, such as an optical storage medium or a solid-state medium, supplied together with or as part of other hardware, but may also be distributed in other forms, such as via the Internet or other wired or wireless communication systems.

Claims

1. 1. A method for securely transmitting a payload, comprising: receiving, by a responder, a start message from an initiator; the responder measuring one or more incoming physical characteristics of the received initiation message and creating a response message to be sent back to the initiator; modifying one or more physical characteristics of the response message based on a combination of the measured incoming physical characteristics and the payload; sending the modified response message to the initiator; A method comprising:

2. The combination of the measured incoming physical property and the payload comprises: encoding the payload as a codeword comprising a set of bits, and mapping the set of bits of the codeword to a mapped set of physical property values; generating the combination as the difference between the measured incoming physical property and the mapped set of physical property values; The method of claim 1 , comprising:

3. The method of claim 1 or 2, wherein the payload is an encryption key used by the initiator for secure communication with the responder.

4. 4. The method of claim 1, wherein the incoming physical characteristics of the initiation message and the physical characteristics of the response message include one or more of the phase or phase difference of each carrier relative to a reference carrier, the gain or gain difference of each carrier relative to a reference carrier, the polarization of each beam relative to a reference beam, a modulation symbol, a gain value respectively applied to each beam, an OAM mode, a phase pattern in an OAM mode, or polarization.

5. 5. The method of claim 1, wherein the payload includes a useful payload and one or more of: one or more sets of parity check bits, one or more sets of cyclic redundancy check bits, or a reliability bit string known by the initiator.

6. The method according to claim 1 , wherein the payload is obtained by applying a forward error correction algorithm to a set of information bits.

7. 7. The method according to claim 1, wherein the payload is obtained by interleaving a set of information bits with at least one of a corresponding reliability bit string, a set of parity check bits, or cyclic redundancy check bits that are known by the initiator.

8. 8. The method of claim 1, wherein the initiator and the responder are end devices and / or relays (e.g., UE-to-UE relays or UE-to-network relays) communicating over a sidelink communication link.

9. 9. The method of claim 1, wherein the initiator is a UE (e.g., a V2X UE, a ProSe UE, etc.) or an access device (e.g., a gNB), and the responder is a passive / ambient IoT device.

10. 10. The method of claim 1, wherein a first responder acts as a second initiator that exchanges payloads with a second responder, thereby combining the roles of both initiator and responder and performing the functions of each role on separate communication links.

11. 11. The method of claim 1, wherein the established secret key is used as a fallback option when a device (end UE and / or UE-to-UE relay) has not provisioned discovery security material and / or when long-term credentials have expired.

12. 12. The method of claim 1, wherein the established private key is combined with established or provisioned security material by a cryptographic function to derive a cryptographic key, a MIC, a scrambling sequence, or an encryption sequence, the cryptographic function being a key derivation function, an encryption algorithm, or an integrity algorithm.

13. 1. A method for securely exchanging payloads, the method comprising: generating an initiation message by an initiator, the initiator making a first modification of one or more physical characteristics of the initiation message, and the initiator sending the modified initiation message to a responder; receiving, by the responder, the modified initiation message from the initiator; the responder measuring one or more incoming physical characteristics of the received modified initiation message; the responder creating a response message to be sent back to the initiator; the responder modifying one or more physical characteristics of the response message based on a second modification including a combination of the measured incoming physical characteristic and the payload, and transmitting the modified response message to the initiator; receiving the modified response message by the initiator; the initiator modifying the received modified response message based on the first modification and extracting the payload from the received modified response message; A method comprising:

14. The combination of the measured incoming physical property and the payload comprises: encoding the payload as a codeword comprising a set of bits, and mapping the set of bits of the codeword to a mapped set of physical property values; generating the combination as the difference between the measured incoming physical property and the mapped set of physical property values; 14. The method of claim 13, comprising:

15. The method of claim 13 or 14, wherein the payload is an encryption key used by the initiator for secure communication with the responder.

16. 16. The method of claim 13, wherein the first alteration is a random modification of one or more physical characteristics of the initiation message.

17. 17. The method of claim 13, wherein the physical characteristics of the initiation message and the physical characteristics of the response message include one or more of: a phase or phase difference of each carrier relative to a reference carrier; a gain or gain difference of each carrier relative to a reference carrier; a polarization of each beam relative to a reference beam; a modulation symbol; a gain value applied to each beam; an OAM mode; a phase pattern in an OAM mode; or polarization.

18. 18. The method of claim 13, wherein the payload includes a useful payload and one or more of: one or more sets of parity check bits, one or more sets of cyclic redundancy check bits, or a reliability bit string known by the initiator.

19. 19. The method of any one of claims 13 to 18, wherein the payload is obtained by applying a forward error correction algorithm to a set of information bits.

20. 20. The method of any one of claims 13 to 19, wherein the payload is obtained by interleaving a set of information bits with a corresponding sequence of reliability bits known by the initiator.

21. The payload is an encapsulated key, a random preamble selected by the responder or encrypted before modulation that is combined with the measured incoming physical characteristic; 21. The method of any one of claims 13 to 20, comprising:

22. 22. The method of claim 13, wherein the initiator and the responder are end devices and / or relays (e.g., UE-to-UE relays or UE-to-network relays) communicating over a sidelink communication link.

23. 23. The method of claim 13, wherein the initiator and the responder are end devices and / or relays (e.g., UE-to-UE relays or UE-to-network relays) communicating over a sidelink communication link.

24. 24. The method of claim 13, wherein the initiator is a UE (e.g., a V2X UE, a ProSe UE, etc.) or an access device (e.g., a gNB), and the responder is a passive / ambient IoT device.

25. 25. The method of claim 13, wherein a first responder acts as a second initiator that exchanges payloads with a second responder, thereby combining the roles of both initiator and responder and performing the functions of each role on separate communication links.

26. 26. The method of any one of claims 13 to 25, wherein the established secret key is used as a fallback option when a device (end UE and / or UE-to-UE relay) has not provisioned discovery security material and / or when long-term credentials have expired.

27. 27. The method of any one of claims 13 to 26, wherein the established private key is combined with established or provisioned security material by a cryptographic function to derive an encryption key, a MIC, a scrambling sequence, or an encryption sequence, wherein the cryptographic function may be a key derivation function, an encryption algorithm, or an integrity algorithm.

28. 1. A method for securely receiving a payload, the method comprising: generating an initiation message by an initiator, the initiator making a first modification of one or more physical characteristics of the initiation message, and the initiator sending the modified initiation message to a responder; the initiator receiving a response message, modifying the response message based on the first modification, and extracting the payload from the modified response message; A method comprising:

29. 30. The method of claim 28, wherein the payload corresponds to an encryption key, and the initiator uses the encryption key to decrypt data sent in the received message.

30. 30. The method of claim 28 or 29, wherein the initiator and responder are end devices and / or relays (e.g., UE-to-UE relays or UE-to-network relays) communicating over a sidelink communication link.

31. 31. The method of claim 28, wherein the initiator is a UE (e.g., a V2X UE, a ProSe UE, etc.) or an access device (e.g., a gNB), and the responder is a passive / ambient IoT device.

32. 32. The method of any one of claims 28 to 31, wherein a first responder acts as a second initiator that exchanges payloads with a second responder, thereby combining the roles of both initiator and responder and performing the functions of each role on separate communication links.

33. 33. The method of any one of claims 28 to 32, wherein the established secret key is used as a fallback option when a device (end UE and / or UE-to-UE relay) has not provisioned discovery security material and / or when long-term credentials have expired.

34. 34. The method of any one of claims 28 to 33, wherein the established private key is combined with established or provisioned security material by a cryptographic function to derive an encryption key, MIC, scrambling sequence, or encryption sequence, wherein the cryptographic function may be a key derivation function, an encryption algorithm, or an integrity algorithm.

35. A computer program comprising code means for generating the steps of the method according to claims 1 to 34 when the computer program is executed on a computing device.

36. 1. A communications device for securely transmitting a payload, comprising: a receiver; A transmitter; A controller; a memory for storing instructions; Including, The instruction: causing the receiver to receive an initiation message from an initiator; causing the controller to measure one or more incoming physical characteristics of the received initiation message; causing the controller to create a response message to be sent back to the initiator; causing the controller to modify one or more physical characteristics of the response message based on a combination of the measured incoming physical characteristics and the payload; The communication device causes the transmitter to transmit the modified response message to the initiator.

37. 1. A communications device for securely receiving a payload, comprising: a controller, a transmitter, a receiver, and a memory containing instructions; Including, The instruction: causing the controller to generate an initiation message and perform a first modification of one or more physical characteristics of the initiation message; causing the transmitter to transmit the modified initiation message to a responder; causing the receiver to receive a modified reply message; The communications device is configured to cause the controller to modify the received modified response message based on the first modification and extract the payload from the received modified response message.

38. A communications device comprising both the device of claim 36 and the device of claim 37.

39. 1. A communications system for securely exchanging payloads, comprising: the communication device includes an initiator and a responder; the initiator includes an initiator controller, an initiator transmitter, an initiator receiver, and an initiator memory containing instructions; The instruction: causing the initiator controller to generate an initiation message and perform a first modification of one or more physical characteristics of the initiation message; causing the initiator-transmitter to transmit the modified initiation message to the responder; causing the initiator-receiver to receive a modified response message; causing the initiator controller to modify the received modified response message based on the first modification and extract the payload from the received modified response message; the responder includes a responder receiver, a responder transmitter, a responder controller, and a responder memory containing instructions; The instruction: causing the responder to receive the modified initiation message from the initiator; causing the responder controller to measure one or more incoming physical characteristics of the received modified initiation message and create a response message to be sent back to the initiator; causing the responder controller to modify one or more physical characteristics of the response message based on a second modification that includes a combination of the measured incoming physical characteristic and the payload; causing the responder-transmitter to transmit a modified response message to the initiator.