A communications system that includes a device with an SDR chip

The integration of a physical unclonable function in SDR chips generates a shared secret key for secure communication, addressing security vulnerabilities by encrypting data and controlling frequency changes, thereby enhancing security in SDR devices.

JP7820387B2Active Publication Date: 2026-02-25NAGRAVISION SA
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2023540507
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-12-30
Filing Date
2021-11-02
Publication Date
2026-02-25
Estimated Expiration
2041-11-02

AI Technical Summary

Technical Problem

Software-defined radio (SDR) devices face security vulnerabilities due to the ability to be reconfigured via software, which can lead to malicious attacks and radio malfunctions, necessitating improved security measures.

Method used

Implementing a physical unclonable function (PUF) in each SDR chip to generate a shared secret key based on unique configuration data during manufacturing, ensuring secure communication between devices using encryption and frequency hopping techniques.

Benefits of technology

Enhances security against cloning and interference by providing a shared secret key for encrypting data and controlling radio frequency changes, improving security at various levels including radio frequency, waveform, and protocol levels.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007820387000001
    Figure 0007820387000001
  • Figure 0007820387000002
    Figure 0007820387000002
  • Figure 0007820387000003
    Figure 0007820387000003
Patent Text Reader

Abstract

The system includes two or more communication devices (1, 2). Each device (1, 2) includes a dedicated SDR chip (10, 20) with a dedicated key generator (10, 20) for generating a secret key (ks) shared by the two SDR chips using a physical unclonable function PUF (121, 221) that receives configuration data (CoD1, CoD2) as input and generates an output. In the dedicated key generator of each SDR chip (10, 20), the PUF (121, 221) receives configuration data (CoD1, CoD2) as input and generates an output that is identical for the two SDR chips (10, 20), i.e. a shared secret key or a seed for deriving it. The configuration data (CoD1, CoD2) is unique for each SDR chip depending on a physical random factor introduced during the manufacture of the SDR chips (10, 20), and the respective key generator (120, 220) is adapted to generate the shared secret key.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to the field of secure wireless communications, and more precisely to the field of wireless communications between two or more communication devices having software radios. [Background technology]

[0002] Software-defined radio (SDR) is a wireless communication system that uses software running on a basic hardware platform to perform many functions traditionally implemented in hardware components (e.g., mixers, filters, amplifiers, modulators / demodulators, detectors, etc.). SDR technology has become increasingly popular in recent years due to advances in digital electronics and processing performance and decreasing costs. Software-defined radio is now used in many applications and fields.

[0003] Typically, a software defined radio chip, or SDR chip, has a radio front-end section that is connected to a radio antenna and acts as an interface between the analog and digital domains, and a digital back-end section for processing digital signals or data. The radio front-end can include an A / D converter (analog-to-digital) and a D / A converter (digital-to-analog).

[0004] The basic concept of SDR is that the radio can be fully configured by software implemented on a hardware platform. Different hardware platforms can be used, such as FPGAs (Field Programmable Gate Arrays), DSPs (Digital Signal Processors), and / or ASICs (Application Specific Integrated Circuits). The software can be stored on the SDR chip during manufacturing or downloaded later from a server, for example, via a communications network. The software can also be modified, updated, and / or upgraded during the life of the SDR chip.

[0005] A key advantage of SDR is that the radio can be easily reconfigured for new applications, to accommodate changes in standards, or to meet user requirements or preferences. A software-defined radio's performance can be changed simply by updating the software.

[0006] Software-defined radio is extremely useful in fields such as mobile and wireless communications. It allows for easy changes to be made to the standards that define wireless communications protocols simply by updating the software. Software updates can also be performed remotely via a communications network. This does not require any hardware changes.

[0007] However, the ability to reconfigure the radio via software raises security concerns. For example, a security breach could allow a malicious third party to modify the software, causing malicious radio reconfiguration and resulting radio malfunction and interference in the RF radio frequency or RF spectrum. SDR devices need to be protected from such malicious attacks.

[0008] There is a need to improve security in wireless communications between SDR devices. Summary of the Invention

[0009] The present disclosure provides a communication system including at least two communication devices, each of the at least two communication devices including a dedicated software defined radio chip having a dedicated key generator configured to generate a secret key shared by two software defined radio chips of the at least two communication devices using a physical unclonable function (PUF) that receives configuration data as an input and generates an output; In the dedicated key generation unit of each of the two software defined radio chips, a physical unclonable function (PUF) generates an output that is the same for the two software defined radio chips and is either a shared secret key or a seed for deriving a shared secret key; the configuration data (received as input by the physical unclonable function PUF) is unique to each of the two software defined radio chips depending on a physical random factor introduced during the manufacture of each of the two software defined radio chips, and each of the two key generating units of each of the two software defined radio chips is adapted to generate a shared secret key; The present invention relates to a communication system characterized by:

[0010] The physical unclonable function, or PUF, in the SDR chip of each of the two (or more) devices receives as input a dedicated configuration data and provides the same output, which can be a direct shared secret key or the same seed for deriving a shared secret key. The configuration data can be stored in the memory of the corresponding SDR chip.

[0011] Advantageously, each software defined radio chip is configured to use a shared secret key as a protection parameter for protecting communications between the at least two communication devices.

[0012] In each software defined radio chip, the PUF provides a secret key or a seed for deriving a secret key that is common to at least two communicating devices and can be used to secure communications between the two communicating devices, for example, by encrypting the data communicated or parameters of wireless transmissions between the two communicating devices with the shared secret key.

[0013] PUFs can provide an additional layer of security against, for example, cloning, and can improve security for radio signals.

[0014] The PUF and the secret key generated by the PUF can be used at different levels to improve the security of wireless signals: at the radio frequency level, waveform level, data level, and protocol level.

[0015] At least two communication devices can be configured to receive a frequency hopping sequence encrypted with a shared secret key from a central server and to communicate with each other using FHSS transmissions, wherein changes in carrier frequency are controlled by the frequency hopping sequence.

[0016] Alternatively, at least two communication devices may be configured to communicate with each other using FHSS transmissions, transmitting frequency hopping sequences to each other encrypted with a shared secret key, and changes in carrier frequency being controlled by the frequency hopping sequences.

[0017] Two software defined radio chips can be configured to communicate data to each other based on modulation of a waveform as a carrier signal, using a shared secret key as a parameter for setting the modulation.

[0018] The two software defined radio chips can be configured to use the shared secret key as an encryption key to encrypt and / or decrypt data transmitted between the two devices.

[0019] Advantageously, the physical unclonable functions are implemented within each software defined radio chip using programmable hardware circuitry.

[0020] In some embodiments, the communication system includes a distribution server configured to store configuration data for software defined radio chips of two or more communication devices and to transmit each configuration data to a corresponding software defined radio chip via a communication network.

[0021] The communication system may also include a secure memory (or a secure database) that stores characterization data for each software defined radio chip, and a configuration data generator configured to generate configuration data for each software defined radio chip from the stored characterization data for the software defined radio chip. The configuration data for each software defined radio chip is generated from the characterization data for the SDR chip, such that a key generator in the SDR chip generates a shared secret key.

[0022] The secure memory may store entitlement data for each software defined radio chip indicating the entitlement of the software defined radio chip to communicate with one or more other software defined radio chips.

[0023] The communication system may include multiple groups of communication devices, each having a software defined radio chip including a key generation unit, and the communication devices in each group share a secret key that is generated by the key generation unit of each of the communication devices in the group and is unique for each group.

[0024] The present disclosure also provides a software defined radio chip for a communication device, comprising: a key generation unit configured to generate the shared secret key using a Physical Unclonable Function (PUF), which receives configuration data as input and generates an output that is either a shared secret key or a seed for deriving a shared secret key, wherein the output of the PUF of the key generation unit is the same for all of the software defined radio chips that share the secret key; a memory for storing configuration data that is unique to the software defined radio chip and that is adapted to cause a key generator to generate a predetermined secret key depending on a physical random factor introduced during the manufacture of the software defined radio chip; The present invention relates to a software defined radio chip comprising:

[0025] Advantageously, the software defined radio chip includes at least one functional module that uses a secret key as a protection parameter for protecting communications.

[0026] The software defined radio chip is configured to decrypt frequency hopping sequences received in encrypted form using a secret key, and can include an FHSS module for communicating using FHSS transmissions, wherein changing of carrier frequency is controlled by the frequency hopping sequence.

[0027] The software defined radio chip can be configured to communicate using a modulation of a waveform as a carrier signal and to use a secret key as a parameter to set the modulation.

[0028] The software defined radio chip may further include an encryption or decryption module configured to encrypt and decrypt data using the secret key as an encryption key.

[0029] A physical unclonable function can be implemented using programmable hardware circuitry.

[0030] The present disclosure also relates to a communication device including a software defined radio chip as defined above. [Brief explanation of the drawings]

[0031] Other features, objects, and advantages of the present disclosure will become more apparent from a reading of the detailed description of non-limiting embodiments thereof, made with reference to the accompanying drawings.

[0032] [Figure 1] A simplified schematic diagram of an SDR chip is shown.

[0033] [Figure 2] 1 illustrates a communication system in accordance with certain embodiments.

[0034] [Figure 3] 1 illustrates a communication system according to another particular embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0035] The present disclosure relates to a wireless communication system 100 including a plurality of Software-Defined Radio (SDR) communication devices capable of wirelessly communicating with each other. The communication devices can communicate via a communication network 3 or via a direct wireless link. The communication devices can be smartphones, mobile phones, tablets, computers, laptops, or any other appliances, devices, machines, or devices capable of wirelessly communicating. First embodiment

[0036] A first embodiment of the system 100 will now be described with reference to Figure 2. In Figure 2, only two devices 1, 2 are depicted as an illustrative example. However, the system 100 may include more than two communication devices.

[0037] In a first embodiment, each of the SDR devices 1, 2 is both a transmitter and a receiver. In another embodiment, one of the SDR devices 1, 2 can be a transmitter and the other a receiver.

[0038] Each SDR communication device 1, 2 includes a software defined radio chip (or module) 10, 20.

[0039] 1 is a simplified schematic diagram of a software defined radio chip 10 in device 1, as well as a software defined radio chip 20 hosted by device 2. Generally, the software defined radio chip 10 includes two parts: a radio front-end part 11, 21 and a digital back-end part 12, 22.

[0040] The radio front-end unit 11, 21 is an interface between the analog and digital domains. It is connected to the radio antenna 15, 25 of the hosting communication device 1, 2. The radio front-end unit 11, 21 may include a radio frequency transceiver (RFT) including conversion units such as an analog-to-digital converter (ADC) and a digital-to-analog converter (DAC). The structure of the radio front-end unit 11, 21 is well known to those skilled in the art and will not be described in further detail herein.

[0041] In each software defined radio chip 10, 20, a digital back-end unit 12, 22 is for processing digital signals or data. Generally, the digital back-end unit 12 includes software 13 and a hardware platform 14 on which the software 13 runs. Many functional modules of the radio system are implemented in the software 13 running on the hardware platform 14. Only the functional modules relevant to the present invention will be described herein.

[0042] The hardware platform 14 may include a digital signal processor, such as a general-purpose processor, and / or a programmable hardware circuit or cell, such as an FPGA (Field Programmable Gate Array), that can be programmed to perform a desired application or functionality requirements.

[0043] Figure 2 shows a distributed system 100 including communication devices 1, 2 that communicate with each other wirelessly, here via a communication network 3. Figure 2 shows a functional block diagram of the digital backend portion 12, 22 of each device 1, 2. It includes different functional modules (described below) that are software modules that run on the hardware platforms of devices 1, 2.

[0044] As shown in Figure 2, the digital backend unit 12, 22 includes a key generation unit 120, 220. The role of this functional module is to generate at least one private key k sThe purpose is to generate this private key k s is shared by the software defined radio chips 10, 20 hosted by two (or more) devices 1, 2 that communicate with each other. This is a predetermined secret key generated by a key management system, which will be described later. In other words, the secret key k s is common to the two or more communication devices 1 and 2. The key generation is based on a Physical Unclonable Function, or PUF. More precisely, in operation, each key generator 120, 220 receives as input a specific configuration data CoD1, CoD2 and generates a secret key k shared by the SDR chips 10, 20. s The configuration data CoD1, CoD2 is unique for each chip 10, 20. It is referred to as CoD1 for the SDR chip 10 and CoD2 for the SDR chip 20. The configuration data CoD1, CoD2 depends on a physical random factor introduced during the manufacturing (production) of the software defined radio chip 10, 20, and is generated by the key generator 120, 220 using its own PUF 121, 221 to generate a predetermined secret key k s The configuration data CoD1, CoD2 are stored in the memories 122, 222 of the SDR chips 12, 22.

[0045] Each physical unclonable function (or PUF) 121, 221 is installed within the software defined radio chip 10, 20 of the corresponding device 1, 2. The installation of the PUF 121, 221 can use a programmable hardware cell or circuit, such as an FPGA (Field Programmable Gate Array). The PUF 121, 221 implemented in the software defined radio chip 10, 20 relies on the uniqueness of the physical microstructure of the software defined radio chip 10, 20, which in turn relies on random physical factors introduced during manufacturing. When configuration data CoD1, CoD2 are provided as input, the PUF 121, 221 generates an output value S in a predictable and repeatable manner resulting from the complex interaction of the input (i.e., the configuration data CoD1, CoD2) with the physical microstructure of the software defined radio chip 10, 20. In other words, each PUF 121, 221 generates a predetermined seed S from the configuration data CoD1, CoD2. The seed value is repeatable, and when the same data is provided as input to a given PUF 121 (or 221) both times, that particular PUF 121 (or 221) will produce the same output value both times. The configuration data CoD (here CoD1, CoD2) can be thought of as "correction data" designed specifically for a given PUF that forces the PUF output to a known value (seed S) in a repeatable way. Since all PUFs are different by definition, but all SDR chips produce the same output, this "correction data" will be different for each SDR chip.

[0046] private key k s may be the output of the PUF 121, 221 directly, or may be derived from the output (seed S) of the PUF 121, 221 using, for example, the key derivation unit 123, 223. The key derivation unit 123, 223 is another functional module of the SDR chip 10, 20 for implementing a key derivation function or key ladder (or any other cryptographic function or structure capable of generating one or more keys). sThe use of a key derivation unit to derive Λ has the advantage that multiple different keys can be generated from a single seed (the output from the PUF), which is useful when several keys are needed in the system.

[0047] The configuration data CoD1, CoD2 of each communication device 1, 2 is generated by the corresponding key generator 120, 220 by generating a shared secret key k that is predetermined to be common to the communication devices 1, 2 that communicate with each other. s (either directly output from the PUF or generated by the key derivation unit).

[0048] In this embodiment, the configuration data CoD1, CoD2 are a series of bits 0 and 1. They are generated from the characterization data ChD1, ChD2 of the software defined radio chips 10, 20 and are unique for each chip. The configuration data CoD1, CoD2 for each SDR chip 10, 20 are generated from the characterization data ChD1, ChD2 of this SDR chip 10, 20 and are stored in a secret key k common to both devices 1, 2. s is adapted to be derived from the output of the PUF 121, 221 to which this configuration data CoD1, CoD2 is provided as input.

[0049] The characterization data ChD1, ChD2 of the software defined radio chips 10, 20 are obtained during a characterization process of the chips 10, 20, typically during manufacturing. The characterization data ChD1, ChD2 are unique for each chip. They are referred to as ChD1 for the SDR chip 10 and as ChD2 for the SDR chip 20. They characterize the inherent properties of the software defined radio chips 10, 20 due to random physical factors introduced during manufacturing. The characterization data ChD1, ChD2 are highly confidential and must be stored in a secure memory 40. For example, the secure memory 40 is hosted by a secure server 4 or a secure network. The characterization data ChD1, ChD2 can be stored in association with identification data of the corresponding device 1, 2 or software defined radio chip 10, 20. The characterization data of the software defined radio chips can also be associated in the memory 40 with rights data indicating the rights to communicate with one or more other software defined radio chips or hosting communication devices.

[0050] The secure server (or network) 4 may also include a configuration data generator 41 that generates configuration data CoD1, CoD2 specifically dedicated to a given communication device 1, 2 or software radio chip 10, 20 from the characterization data ChD1, ChD2 of this SDR chip 10, 20.

[0051] The configuration data CoD1, CoD2 of the different devices 1, 2 may be stored in the memory or database 50 of the distribution server 5. The configuration data CoD1, CoD2 may be stored in association with the identification data of the corresponding devices 1, 2 or software defined radio chips 10, 20.

[0052] The secure server (or network) 4 and the distribution server 5 are part of a key management system.

[0053] For security reasons, the characterization data ChD1, ChD2 (and rights data) of the different software defined radio chips 10, 20 can be kept offline. In that case, the secure server (or secure network) 4 is not connected to the communication network 3, as shown in FIG. 2. In this way, the configuration data of the SDR chips 10, 20 can be calculated in the most secure way. The drawback of such a configuration is that new configuration data cannot be calculated in real time, and therefore the rights of the SDR chips cannot be changed live. For example, the device cannot be (or can hardly be) disabled.

[0054] Alternatively, a secure server (or secure network) 4 can be connected to the communications network 3. In that case, both servers 4 and 5 can be integrated into one server. This configuration is less secure, but typically has the advantage that new configuration data can be generated on the fly as the rights of the communications device hosting the SDR chip change. In this case, the memory or database 50 can be easily updated when a new communications device is added or when a communications device is disabled.

[0055] In some embodiments, the configuration data CoD1, CoD2 are recorded in the software defined radio chips 10, 20 during chip manufacturing. In other embodiments, the configuration data CoD1, CoD2 are downloaded to the corresponding software defined radio chips 10, 20 of the devices 1, 2 from the distribution server 5 via the communication network 3 during or after manufacturing. In each software defined radio chip 10, 20, the configuration data CoD1, CoD2 are stored in an internal memory 122, 222.

[0056] The configuration data CoD1, CoD2 are not confidential data. For example, if the configuration data CoD1 of the SDR chip 10 of the communication device 1 is obtained by another chip and provided as input to the physical unclonable function of this other chip, the common secret key k sThe seed S generates an output value different from the seed S from which the seed S is derived. Therefore, for example, when transmitting the configuration data CoD1, CoD2 from the distribution server 5 to the SDR chips 10, 20, there is no need to protect the configuration data CoD in a confidential state. However, to prevent the two devices from communicating with each other, it may be useful to protect the configuration data CoD1, CoD2 in terms of integrity and / or authenticity to avoid a third party maliciously replacing the configuration data CoD1, CoD2 with other data.

[0057] shared secret key k s The shared secret key k can be used by the communication devices 1 and 2 as a protection parameter to protect their communications with each other. s By using the shared secret key, the communication language between the software defined radio chips 10, 20 of the communication devices 1, 2 is unique and can only be understood by the chips 10, 20. The shared secret key can be used in any cryptographic algorithm or by any cryptographic module of the software defined radio chips 10, 20 to protect at least part of the communication between the communication devices 1, 2. The shared secret key can be used at different levels, e.g. -Radio frequency level, -wave level, -Data level, and / or -Can be used at the protocol level.

[0058] The following embodiment uses a shared secret key k as a protection parameter in communication between communication devices 1 and 2. s This shows different use cases. Second embodiment

[0059] The second embodiment is based on the first embodiment. In this second embodiment, a shared secret key k s is used at the radio frequency level. Two (or more) devices 1, 2 are configured to communicate with each other using FHSS (Frequency Hopping Spread Spectrum) transmission.

[0060] In this second embodiment, each software defined radio chip 10, 20 includes a software FHSS module 124, 224 for implementing the FHSS method of transmitting and receiving radio signals by rapidly changing the carrier frequency among multiple distinct frequencies occupying a given spectrum band. This communication technique can make communications much more difficult to eavesdrop on. This change is controlled by a code commonly referred to as a frequency hopping sequence. This frequency hopping sequence is known to all devices 1, 2 communicating with each other (i.e., both chips 10, 20). Prior to FHSS transmission, the frequency hopping sequence must be shared by the two software defined radio chips 10, 20.

[0061] For example, communicating devices 1 and 2 transmit frequency hopping sequences to each other that are encrypted with a shared secret key. In practice, the frequency hopping sequence needs to be protected to at least a confidential state for its transmission between devices 1 and 2. Thus, the frequency hopping sequence is encrypted by a transmitter device (e.g., device 1) and decrypted by a receiver device (device 2).

[0062] Alternatively, the communication devices can receive the frequency hopping sequence encrypted with a shared secret key from a central server. In that case, the frequency hopping sequence is encrypted centrally by a server, e.g., server 5, and then distributed to all devices that need to communicate with each other. The software defined radio chips in the communication devices receive the encrypted form of the common frequency hopping sequence from the central server and use the shared secret key k s and are configured to communicate with each other using FHSS transmission, with carrier frequency changes controlled by the shared frequency hopping sequence.

[0063] The encryption / decryption of the frequency hopping sequence can be performed by a software or hardware module of the encryption and decryption 125, 225. It uses a common secret key k output from the PUF 121, 221 or derived from the output of the PUF 121, 221. s is used to encrypt and decrypt the frequency hopping sequence. Third embodiment

[0064] The third embodiment is based on the first embodiment. In this third embodiment, a shared secret key k s is used at the waveform level. The communication devices 1, 2 are configured to communicate data with each other based on modulation of a waveform used as a carrier signal.

[0065] In the third embodiment, the software defined radio chips 10 and 20 of each device store a shared secret key k s as a parameter to set the modulation. s Below is a non-exhaustive, exemplary list of modulation parameters that can be set using: - modulation bandwidth, - type of modulation (analog or digital), -Modulation techniques (amplitude, phase, etc.), - modulation alphabet in digital modulation, -symbol rate in digital modulation, -Digital coding techniques: NRZ, Manchester, etc. Fourth embodiment

[0066] The fourth embodiment is based on the first embodiment. In the fourth embodiment, a shared secret key k s The communication devices 1 and 2 communicate with each other. In the fourth embodiment, data transmitted from one device 1(2) to the other device 2(1) is transmitted using a shared secret key k s In this case, the data is encrypted using a key k derived from the output from the PUF 121. sthe same key k derived from the output of PUF221, encrypted by a software or hardware encryption module in the SDR chip of the transmitter device (e.g., Device 1) using s The signal is decoded by a software or hardware decoding module in the SDR chip of the receiver device (e.g., device 2) using

[0067] The key management system may be a distributed system, for example including servers 4 and 5. However, other configurations of the key management system may be implemented. For example, the key management system may be implemented in one secure server (or one secure local network).

[0068] As mentioned above, a key management system can have different modes of operation. In a first mode of operation, the key management system provides remote key management services to communication devices via a communication network. In that case, the communication devices can receive and / or update the information (i.e., configuration data CoD) necessary for remote communication from the key management system through the communication network. In that case, the key management system is "offline" and not connected to a communication network. The communication devices can be pre-programmed with the information (i.e., configuration data CoD) necessary for communication and can operate completely offline.

[0069] The key management system may perform at least some of the following functions: - secure storage of characterization data for each software defined radio chip; - storing rights data for each software defined radio chip indicating other software defined radio chips and / or host communication devices that are authorized to communicate with the software defined radio chip; - determining a secret key shared by a plurality of software defined radio chips (or a plurality of hosting communication devices) that are authorized to communicate with each other; - generating configuration data for each software defined radio chip according to the secret key to be generated from the corresponding characterization data; - storing configuration data for each software defined radio chip; -Distribution of configuration data for each software defined radio chip.

[0070] The communication systems 100 each have a software defined radio chip and share the same secret key k s The communication device may include two or more communication devices that share the same network.

[0071] The system 100 may also include several groups of multiple communication devices. Each communication device has a software defined radio chip that includes a key generator. The communication devices in each group share a common secret key that is unique for the group and is generated by a key generator of each of the communication devices in this group. Figure 3 shows an illustrative example of the system 100 that includes three groups A, B, and C of communication devices that can communicate over a communication network 3 (1a-Na in group A, 1b-Nb in group B, and 1c-Nc in group C). The communication devices in each group share the same secret key k in group A. sa Group B shares k sb In Group C, k sc Each group shares a secret key k sa , k sb and k sc A communication device can belong to several groups.

[0072] As previously mentioned, the characterization data for each software defined radio chip is stored in a secure memory or database within a secure server or secure network that is connected to the communications network or is offline. In some embodiments, the configuration data for each software defined radio chip can be stored on a distribution server that can download the configuration data to the software defined radio chip as needed. Alternatively, the configuration data can be loaded offline into each communications device, for example, at the end of manufacturing.

[0073] Communication devices that have software defined radio chips for communicating with each other can share two or more secret keys derived from seed outputs from their respective physical unclonable function modules.

[0074] The secret key shared by multiple software defined radio chips communicating with each other can be used as a protection parameter to protect the communication between the hosting communication device with different protection mechanisms and / or different protection levels. The different embodiments described above can be implemented together by a communication device.

Claims

1. A communication system comprising at least two communication devices (1, 2), Each of said at least two communication devices (1, 2) stores configuration data (CoD) 1 , CoD 2 ) as an input and generates an output using a physical unclonable function PUF (121, 221) that receives a secret key (k) shared by two software defined radio chips (10, 20) of the at least two communication devices (1, 2). s a dedicated software defined radio chip (10, 20) having a dedicated key generator (10, 20) configured to generate a In the dedicated key generation unit of each of the two software defined radio chips (10, 20), the physical unclonable function PUF (121, 221) generates an output that is the same for the two software defined radio chips (10, 20) and is either a shared secret key or a seed for deriving the shared secret key; The configuration data (CoD 1 , CoD 2 ) is unique to each of the two software defined radio chips (10, 20) depending on a physical random factor introduced during the manufacture of each of the two software defined radio chips (10, 20), and each of the two key generating units (120, 220) of each of the two software defined radio chips (10, 20) generates the shared secret key (k s ) A communication system comprising:

2. Each software defined radio chip (10, 20) stores the shared secret key (k) as a protection parameter for protecting communication between the at least two communication devices (1, 2). s 10. The communication system of claim 1, wherein the communication system is configured to use a .

3. 3. The communication system of claim 1, wherein the at least two communication devices are configured to receive a frequency hopping sequence encrypted with the shared secret key from a central server and to communicate with each other using FHSS transmissions, and wherein changing of carrier frequency is controlled by the frequency hopping sequence.

4. 3. The communication system of claim 1, wherein the at least two communication devices are configured to transmit to each other a frequency hopping sequence encrypted with the shared secret key and to communicate with each other using FHSS transmission, and wherein changing of carrier frequency is controlled by the frequency hopping sequence.

5. 5. The communication system of claim 1, wherein the software defined radio chips (10, 20) are configured to communicate data with each other based on modulation of a waveform as a carrier signal and to use the shared secret key as a parameter for setting the modulation.

6. 6. The communication system according to claim 1, wherein the software defined radio chips (10, 20) are configured to use the shared secret key as a key for encrypting and decrypting data transmitted between the at least two communication devices.

7. The configuration data (CoD) of the software defined radio chips (10, 20) of the at least two communication devices 1 , CoD 2 ) and stores each configuration data (CoD 1 , CoD 2 7. The communication system according to claim 1, further comprising a distribution server (5) configured to transmit the software defined radio chips (10, 20) via a communication network (3).

8. Characterization data (ChD) of each software defined radio chip (10, 20) 1 , ChD 2 a secure memory (40) for storing the stored characterization data (ChD) of the software defined radio chip (10, 20); 1 , ChD 2 ) to the configuration data (CoD) of each software defined radio chip (10, 20). 1 , CoD 2 8. The communication system of claim 1, further comprising a configuration data generator (41) configured to generate a configuration data set.

9. 9. The communication system of claim 8, wherein the secure memory (40) stores entitlement data for each software defined radio chip indicating the entitlement of the software defined radio chip to communicate with one or more other software defined radio chips.

10. 10. The communication system according to claim 1, comprising a plurality of groups (A, B, C) of communication devices (1a, 2a, ..., 1b, 2b, ..., 1c, 2c, ...), each of which has a software defined radio chip including a key generation unit, and the communication devices of each group share a secret key that is generated by the key generation unit of each of the communication devices of the group and is unique for each group.

Citation Information

Patent Citations

  • Semiconductor integrated circuit and software radio equipment

    JP2006108953A

  • Encryption communication system and encryption communication method

    JP2013031151A

  • Spatial modulation in a wireless communications network

    US20060233276A1

  • Unequally powered cryptography using physical unclonable functions

    US20200162271A1

  • A secure software-defined radio chip

    US20200401730A1