Key determination method, apparatus, system, and storage medium
By extracting channel randomness information from the channel matrix and generating uniformly distributed physical layer keys using quantization and mapping functions, the challenge of high-level cryptography at the signal level in 6G networks is solved, and high-quality key generation and security improvement is achieved, which is suitable for a variety of communication systems and scenarios.
Patent Information
- Application Number
- PCT/CN2024/142812
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-03
- Filing Date
- 2024-12-26
- Publication Date
- 2025-07-10
AI Technical Summary
The security threats faced by 6G networks in the future include the challenges of the advancement of computing technology to classical cryptography, the risk of attacks caused by the openness of wireless channels, and the difficulty of high-level cryptography to meet the signal-level security needs of new applications. The existing plug-in security mechanism of high-level cryptography faces severe challenges in the 6G era and lacks link-level endogenous security mechanisms.
By extracting channel randomness information from the estimated channel matrix, using quantization and mapping functions to generate uniformly distributed physical layer keys, avoiding relying on empirical distribution parameters, saving calculation overhead and processing delays, and using the merchandise mapping method to replace hard decision quantization, and generating high-quality keys.
It realizes the generation of high-quality uniformly distributed keys without obtaining channel experience distribution parameters, improves the consistency and security of key generation, reduces computing overhead and delay, and is suitable for various communication systems and scenarios.
Smart Images

Figure CN2024142812_10072025_PF_FP_ABST
Abstract
Description
Method, device, system, and storage medium for determining a key
[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on January 3, 2024, with application number 202410012245.X and application name “A method, device, system, and storage medium for determining a key”, the entire contents of which are incorporated into this application by reference. Technical Field
[0002] The present disclosure relates generally to the field of communications, and more particularly to a method, apparatus, system, and computer-readable storage medium for determining a key. Background Art
[0003] Future 6G networks face various security threats. First, the continuous advancement of computing technology poses challenges to cryptographic security systems based on computational complexity. For example, since modern cryptography is based on classical computational complexity theory, the security of classical cryptography is being challenged with the development of computing technology, especially the increasing maturity of quantum computing. Second, the open nature of wireless channels makes signal transmission vulnerable to attacks, and the air interface defense mechanisms of cellular networks need to be further improved. Strengthening the underlying defense barriers of wireless networks is a key issue that needs to be addressed in 6G network security. Furthermore, new applications such as positioning and sensing impose new security requirements on the signal layer, which high-level cryptographic technologies struggle to meet. In addition to providing an enhanced user experience based on 5G, 6G will also enable numerous new applications. Due to the lack of signal-level integrity protection mechanisms, if the signals used for ranging and positioning are easily tampered with, it will have serious consequences in certain applications (such as smart car keys and contactless payments). High-level encryption cannot address these issues. "Plug-in" security mechanisms that rely solely on high-level cryptography will face severe challenges in the 6G era, and research on intrinsic security mechanisms at the link level is urgently needed. Summary of the Invention
[0004] The embodiments of the present disclosure provide a method, device, system and computer-readable storage medium for determining a key, so that when generating a key, there is no need to obtain the empirical distribution of the estimated channel and its related information, and computing overhead and processing delay are saved. The generated key can meet the uniform distribution requirement and has high key quality.
[0005] In a first aspect, a method for determining a key is provided. The method can be performed by a communication device, such as a terminal device or a chip in a terminal device, or a network device or a chip in a network device. The following description takes the terminal device or network device as an example. In this method, the communication device extracts channel randomness information from an estimated channel matrix. In addition, the communication device quantizes the channel randomness information, wherein the quantized channel randomness information belongs to a quotient group of a discrete integer domain. Furthermore, the communication device determines a physical layer key based on the quantized channel randomness information. In this way, the key used for security is extracted from the wireless channel itself, eliminating the need to obtain an empirical distribution of the estimated channel and its related information, saving computational overhead and processing delay, and the generated key can meet uniform distribution requirements and has high key quality.
[0006] In some implementations, the channel randomness information is quantized by a first mapping function determined based on a quantization level, so that a uniformly distributed key can be obtained.
[0007] In some implementations, during the quantization of channel randomness information, the communication device maps the channel randomness information from its domain to a first numerical interval based on a second mapping function, thereby obtaining a value of the channel randomness information in the first numerical interval. Furthermore, the communication device uses the first mapping function to map the value of the channel randomness information in the first numerical interval to a quotient group in the discrete integer domain. In this manner, using the value of the second mapping function as a parameter of the first mapping function, a mapping method based on a quotient group (or group homomorphism) is employed, replacing a hard decision based on a threshold-based truncated interval. This avoids quantization errors caused by threshold design during the decision process and enables the generation of a uniformly distributed key.
[0008] In some implementations, a first parameter of the first mapping function is derived based on an output of the second mapping function, and a second parameter of the first mapping function is derived based on a quantization level. In this manner, the output of the second mapping function and the quantization level are used to construct the parameters of the first mapping function, so that the generated key can meet the uniform distribution requirement, has high key quality, and reduces computational overhead and processing latency.
[0009] In some implementations, the channel randomness information is the real or imaginary part of an element value of the estimated channel matrix, and the second mapping function is the cumulative distribution function of a standard normal distribution. In this way, randomness information can be obtained from the real or imaginary part of the element value of the estimated channel matrix and a uniformly distributed physical layer key can be generated without empirical distribution parameters. This is also compatible with scenarios where relatively accurate empirical distribution parameters for the real or imaginary part of the element value can be obtained.
[0010] In some implementations, the channel randomness information is the modulus of an element value of the estimated channel matrix, and the second mapping function is a cumulative distribution function of a Rayleigh distribution. In this way, randomness information can be obtained from the modulus of the element value of the estimated channel matrix and a uniformly distributed physical layer key can be generated without requiring empirical distribution parameters. This is also compatible with scenarios where relatively accurate empirical distribution parameters for the modulus of the element value can be obtained.
[0011] In some implementations, the channel randomness information is the square of the modulus of the element values of the estimated channel matrix, and the second mapping function is a function defined based on exponential distribution characteristics. In this way, randomness information can be obtained from the square of the modulus of the element values of the estimated channel matrix and a uniformly distributed physical layer key can be generated without the need for empirical distribution parameters. This is also compatible with scenarios where relatively accurate empirical distribution parameters for the square of the modulus of the element values can be obtained.
[0012] In some implementations, the channel randomness information is the argument of the element values of the estimated channel matrix, and the second mapping function is a function defined based on the argument. This is compatible with the processes of the other solutions described above, and includes a more comprehensive theoretical explanation and calculation method, saving computational costs.
[0013] In some implementations, the input to the second mapping function may be channel randomness information normalized based on empirical distribution parameters. Alternatively, the input to the second mapping function may be channel randomness information. This allows compatibility with scenarios using empirical distribution parameters. Thus, in scenarios where relatively accurate empirical distribution parameters are available, high-quality keys can be generated without requiring hard decisions based on threshold-based truncation intervals, thus saving computational effort.
[0014] In some implementations, the channel randomness information is the argument of the element values of the estimated channel matrix, and the second mapping function is a uniformly distributed cumulative distribution function in the interval [0, 2π]. The value of the uniformly distributed cumulative distribution function in the interval [0, 2π] corresponding to the argument is used as a parameter of the first mapping function, thereby implementing a quotient group-based mapping method. This method can obtain randomness information from the argument of the element values of the estimated channel matrix without the need for empirical distribution parameters and generate a uniformly distributed physical layer key. It is also compatible with scenarios where more accurate empirical distribution parameters for the argument of the element values can be obtained.
[0015] In some implementations, the channel randomness information is the argument of an element value of the estimated channel matrix, and a first parameter of the first mapping function is obtained based on the argument, and a second parameter of the first mapping function is obtained based on the quantization level. By directly using the argument as a parameter of the first mapping function, a quotient group-based mapping approach is implemented. This allows randomness information to be obtained from the argument of the element value of the estimated channel matrix without requiring empirical distribution parameters, and allows for generation of a uniformly distributed physical layer key. Furthermore, this approach is compatible with scenarios where relatively accurate empirical distribution parameters for the argument of the element value can be obtained.
[0016] In some implementations, the first mapping function is configured to scale the interval corresponding to the first parameter from the first interval to the second interval, and then map the interval to a quotient group of a discrete integer domain, where the upper limit of the second interval is an integer multiple of the quantization level. This allows two adjacent high-probability values to be mapped to different integer values to obtain a discrete integer value used to generate the key.
[0017] In some implementations, the first mapping function is used to scale the interval corresponding to the first parameter and then map it to a quotient group in the discrete integer domain, where the upper limit of the scaled interval is an integer multiple of the quantization level, and when the input of the second mapping function is channel randomness information normalized without using empirical distribution parameters, the integer multiple is greater than a preset threshold. After the scaling factor is increased, the output integers can be uniformly distributed, and based on group homomorphism calculations, two adjacent high-probability values can be mapped to different integer values to obtain discrete integer values used to generate the key.
[0018] In some implementations, the channel randomness information is determined based on a mode selected by a first communication device performing the method, and the mode is (i) determined by a protocol, or (ii) determined by a signaling interaction between the first communication device and a second communication device, wherein the first communication device communicates with the second communication device using a physical layer key, or a combination of (i) and (ii). In this way, keys are generated based on different modes, thereby improving key quality.
[0019] In some implementations, the mode is selected based on the channel conditions between the first communication device and the second communication device. In this way, a key can be generated by estimating different values of the elements of the channel matrix based on different channel conditions, so that the generated key is of high quality.
[0020] In some implementations, the method further includes receiving or sending an indication of an update mode when at least one of the channel conditions changes. In this way, when the channel conditions change, the element values of the estimated channel matrix based on which the key is generated can be flexibly switched to generate a high-quality key.
[0021] In some implementations, the channel randomness information is extracted based on the index of the element value in the estimated channel matrix, so that the position of the element value in the estimated channel matrix can be determined according to the index, and the element value that meets the requirements can be selected to generate the key.
[0022] In some implementations, a first communication device executing the method and a second communication device pre-agreed on an index, wherein the first communication device communicates with the second communication device using a physical layer key, or the first communication device and the second communication device determine the index through signaling interaction, or both pre-agreed and signaling interaction methods can be combined. This allows for flexible selection of element values of the estimated channel matrix in a variety of ways.
[0023] In a second aspect, a communication device is provided. The beneficial effects can be found in the description of the second aspect and will not be repeated here. The communication device has the function of implementing the behavior in the method example of the second aspect. The function can be implemented by hardware or by executing corresponding software implementation by hardware. The hardware or software includes one or more modules corresponding to the above functions. In one possible design, the communication device includes an extraction unit, which is used to extract channel randomness information from the estimated channel matrix. The communication device also includes a quantization unit, which is used to quantize the channel randomness information, wherein the quantized channel randomness information belongs to a quotient group of a discrete integer domain. The communication device also includes a determination unit, which is used to determine a physical layer key based on the quantized channel randomness information.
[0024] In a third aspect, a device is provided, comprising: a processor, and a memory storing a computer program or instructions, wherein the computer program or instructions, when executed by the processor, causes the electronic device to perform any method according to the first aspect and its implementation manner.
[0025] In a fourth aspect, a computer-readable storage medium is provided, which stores a computer program or instruction. When the computer program or instruction is executed by an electronic device, the electronic device executes the method executed by the device in the above aspects.
[0026] In a fifth aspect, a computer program (product) includes a computer program or instructions, which, when executed by an electronic device, enables the electronic device to execute the methods executed by the apparatus in the above aspects.
[0027] In a sixth aspect, embodiments of the present disclosure provide a chip system comprising a processor configured to implement the functions of the apparatus described in the methods of the aforementioned aspects. In one possible design, the chip system further comprises a memory configured to store computer programs, instructions, and / or data. The chip system may be comprised solely of a chip or may include a chip and other discrete components.
[0028] In a seventh aspect, an embodiment of the present disclosure further provides a system for determining a key, comprising: a communication device for executing the method of the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] FIG1A shows a schematic diagram of a communication system according to some embodiments of the present disclosure.
[0030] FIG1B shows a schematic diagram of a key generation process.
[0031] FIG2 shows a schematic diagram of a process of determining a key according to some embodiments of the present disclosure.
[0032] FIG3 shows a schematic diagram of a process of determining a key according to other embodiments of the present disclosure.
[0033] FIG4 shows a schematic diagram of a process of determining a key in example scenarios of still other embodiments of the present disclosure.
[0034] FIG5 shows a schematic diagram of the distribution obeyed by the output of the second mapping function in an example scenario of some embodiments of the present disclosure.
[0035] FIG6 shows a schematic diagram of a process of determining a key in example scenarios of still other embodiments of the present disclosure.
[0036] FIG7 shows a schematic diagram of a process of determining a key in example scenarios of still other embodiments of the present disclosure.
[0037] FIG8 shows a schematic diagram of the distribution obeyed by the second mapping function output in example scenarios of other embodiments of the present disclosure.
[0038] FIG9 shows a schematic diagram of a process of determining a key in example scenarios of still other embodiments of the present disclosure.
[0039] FIG10 shows a schematic diagram of the distribution obeyed by the second mapping function output in example scenarios of still other embodiments of the present disclosure.
[0040] FIG11 shows a schematic diagram of a process of determining a key in example scenarios of still other embodiments of the present disclosure.
[0041] FIG12 shows a schematic diagram of a process of determining a key in example scenarios of still other embodiments of the present disclosure.
[0042] FIG13 shows a schematic diagram of a signaling configuration process in an example scenario of some embodiments of the present disclosure.
[0043] 14A to 14F are schematic diagrams showing comparisons of simulation results of some embodiments of the present disclosure.
[0044] FIG15 shows a schematic flowchart of some embodiments of the present disclosure implemented at a communication device.
[0045] FIG16 is a schematic diagram showing the main components of an example device of a possible implementation method of an embodiment of the present disclosure.
[0046] FIG17 shows a simplified block diagram of an example device for one possible implementation of an embodiment of the present disclosure. DETAILED DESCRIPTION
[0047] The following describes embodiments of the present disclosure in more detail with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the embodiments of the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments described herein. Instead, these embodiments are provided to provide a more thorough and complete understanding of the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are for illustrative purposes only and are not intended to limit the scope of protection of the present disclosure.
[0048] In the description of the embodiments of the present disclosure, the term "including" and similar terms should be understood as open inclusion, that is, "including but not limited to." The term "based on" should be understood as "based at least in part on." The term "one embodiment" or "the embodiment" should be understood as "at least one embodiment." The terms "first," "second," etc. may refer to different or the same objects. Other explicit and implicit definitions may also be included below.
[0049] The embodiments of the present disclosure may be implemented according to any appropriate communication protocol, including but not limited to cellular communication protocols such as third generation (3G), fourth generation (4G), fifth generation (5G), and future communication protocols (e.g., sixth generation (6G)), wireless local area network communication protocols such as Institute of Electrical and Electronics Engineers (IEEE) 802.11, and / or any other protocol currently known or developed in the future. The technical solutions provided in this application may also be applied to device-to-device (D2D) communication, vehicle-to-everything (V2X) communication, machine-to-machine (M2M) communication, machine type communication (MTC), and Internet of Things (IoT) communication systems or other communication systems.
[0050] Figure 1A shows a schematic diagram of a communication system according to some embodiments of the present disclosure. As shown in Figure 1A , the key determination method provided by the embodiments of the present disclosure can be applied to a communication system 100, such as a wireless communication system such as 5G or satellite communication. In communication system 100, a terminal device 110 and a network device 120 are shown. Either terminal device 110 or network device 120 can determine a key and then use the determined key to encrypt signals / data / information to be sent to the other party. In addition to transmitting signals / data / information for communication, terminal device 110 and network device 120 can also transmit signaling configurations used to generate keys, such as information regarding mode selection. The mode is related to the channel conditions between terminal device 110 and network device 120, so that different modes are used to determine keys for different channel conditions. The signaling configuration can be sent by terminal device 110 to network device 120, or alternatively, the signaling configuration can be sent by network device 120 to terminal device 110. It should be noted that FIG1A uses the terminal device 110 and the network device 120 as examples for illustration, and the communication system 100 may include any number of terminal devices or network devices.
[0051] The communication system 100 in the embodiment of the present disclosure includes but is not limited to: narrowband Internet of things (NB-IoT), global system for mobile communications (GSM), enhanced data rate for GSM evolution (EDGE), wideband code division multiple access (WCDMA), code division multiple access 2000 (CDMA2000), time division-synchronization code division multiple access (TD-SCDMA), long term evolution (LTE), and three major application scenarios of 5G mobile communication systems: enhanced mobile broadband (eMBB), ultra-reliable low-latency communication (URLLC), and enhanced machine type communication (eMTC). The solution of the disclosed embodiment can be applied to TDD (time-division duplexing) scenarios to improve the consistency rate of physical layer key generation under non-ideal channel reciprocity conditions. TDD is a duplex mode of a communication system, which is used to separate the receiving and transmitting channels (or uplink and downlink) in a mobile communication system. In a TDD mode mobile communication system, reception and transmission are in different time slots of the same frequency channel, i.e., a carrier, and guaranteed time is used to separate the receiving and transmitting channels. This solution is applicable to any wireless network scenario including a transmitter and a legal receiver, and the scenario can exist in a variety of communication systems, including but not limited to: GSM system, CDMA system, WCDMA system, GPRS system, LTE system, LTE-A system, UMTS system, 5G system, beyond5G (B5G) system, etc.
[0052] It should be understood that the above wireless communication system can be applied to high-frequency scenarios such as millimeter waves (above 6G) as well as low-frequency scenarios (sub6G). Application scenarios of wireless communication systems include but are not limited to communication systems such as fifth-generation systems (5G), new radio (NR) communication systems, or future communication systems such as future evolved public land mobile networks (PLMN) systems. The embodiments of the present disclosure can also be used in Wi-Fi network scenarios, such as generating physical layer security keys in Wi-Fi scenarios and intrinsic security mechanisms. The embodiments of the present disclosure can also be combined with various key generation schemes that require extracting randomness from channel estimates.
[0053] The term "terminal" or "terminal device" used in the embodiments of the present disclosure refers to any terminal device that can perform wired or wireless communication with network devices or with each other. Terminal devices may sometimes be referred to as user equipment (UE). Terminal devices may be any type of mobile terminal, fixed terminal or portable terminal. Terminal devices may be various wireless communication devices with wireless communication capabilities. For example, a terminal device (terminal device 110 as shown in FIG1A ) may be a user device, a terminal, an access terminal, a terminal unit, a terminal station, a mobile station (MS), a remote station, a remote terminal, a mobile terminal, a wireless communication device, a terminal agent or a terminal device, etc. The terminal device may also be a communication chip with a communication module, or a vehicle with communication capabilities, or an on-board device (such as an on-board communication device, an on-board communication chip), etc. The terminal device may have a wireless transceiver function, which can communicate (such as wireless communication) with one or more network devices of one or more communication systems and receive network services provided by the network devices, where the network devices include but are not limited to access network devices. User equipment (UE) includes, but is not limited to, mobile terminals, mobile telephones, handsets, portable equipment, mobile stations, and computers with wireless communication capabilities. UEs can be portable, pocket-sized, handheld, built into computers, mounted in vehicles, or mounted on aircraft. UEs can communicate with one or more core networks via a radio access network (RAN).
[0054] Among them, the terminal device can be a cellular phone, a cordless phone, a session initiation protocol (SIP) phone, a wireless local loop (WLL) station, a personal digital assistant (PDA) device, a handheld device with wireless communication function, a computing device or other processing device connected to a wireless modem, an in-vehicle device, a wearable device, a terminal device in a future 5G or 6G network, or a terminal device in a future evolved PLMN network, etc.
[0055] The terminal device can specifically be a mobile phone, a tablet computer, a computer with wireless transceiver function, a virtual reality (VR) terminal, an augmented reality (AR) terminal, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, etc.
[0056] In addition, terminal devices can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted. Terminal devices can also be deployed on water (such as ships). Terminal devices can also be deployed in the air (such as aircraft, balloons, and satellites).
[0057] Various devices with wireless communication capabilities that can be used to connect people, objects, machines, etc. Terminal devices can be widely used in various scenarios, such as: cellular communication, D2D, V2X, peer to peer (P2P), M2M, MTC, IoT, virtual reality (VR), augmented reality (AR), industrial control, autonomous driving, telemedicine, smart grid, smart furniture, smart office, smart wearable, smart transportation, smart city drones, robots, remote sensing, passive sensing, positioning, navigation and tracking, autonomous delivery, etc. Terminal devices can be terminals in any of the above scenarios, such as MTC terminals, IoT terminals, etc. Terminal devices can be 3GPP (3rd Generation Partnership Project) terminals. rdThe present invention relates to user equipment (UE), terminal, fixed device, mobile station device or mobile device, subscriber unit, handheld device, vehicle-mounted device, wearable device, cellular phone, smart phone, SIP phone, wireless data card, personal digital assistant (PDA), computer, tablet computer, notebook computer, wireless modem, handheld device, laptop computer, computer with wireless transceiver function, smart book, vehicle, satellite, global positioning system (GPS) device, target tracking device, aircraft (such as drone, helicopter, multi-copter, quadcopter, or airplane), ship, remote control device, smart home device, industrial equipment, or device built in the above-mentioned device (such as communication module, modem or chip in the above-mentioned device), or other processing equipment connected to the wireless modem. For the convenience of description, the terminal device will be described below with terminal or UE as an example. In some scenarios, the terminal device can also be used to act as a base station. For example, a terminal device may act as a scheduling entity that provides sidelink signals between UEs in scenarios such as V2X, D2D, or P2P.
[0058] In the embodiments of the present application, the device for implementing the function of the terminal device can be the terminal device, or it can be a device that can support the terminal device to implement the function, such as a chip system or chip, which can be installed in the terminal device. In the embodiments of the present application, the chip system can be composed of a chip, or it can include a chip and other discrete devices.
[0059] The network device in the embodiments of the present application may be a device for communicating with a terminal device. The network device may also be referred to as an access network device or a wireless access network device. For example, the network device may be an access network device (or an access network node). An access network device refers to a device that provides network access functionality, such as a radio access network (RAN) base station, etc. The network device may specifically include a base station (BS), or a base station and a radio resource management device for controlling the base station, etc. The network device may also include a relay station (relay device), an access point, a base station in a 5G network, or a NR base station, a base station in a future evolved PLMN network, etc. The network device may be a wearable device or an in-vehicle device. The network device may also be a communication chip with a communication module. Base stations include, but are not limited to, ordinary base stations (such as gNB, eNB, or NodeB), remote radio units (RRUs), macro stations, micro stations (pico, femto, etc.), relays, access points (APs) with wireless transceiver functionality, transmission reception points (TRPs), or any other wireless access devices.
[0060] The terms "network node" or "network device" used in the embodiments of this disclosure refer to entities or nodes that can be used to communicate with terminal devices, such as access network devices. Access network devices can be devices deployed in a radio access network to provide wireless communication capabilities for mobile terminals, such as radio access network (RAN) network devices. Access network devices can include various types of base stations. Base stations are used to provide wireless access services to terminal devices. For example, network equipment (such as access network equipment 120 and 130) include but are not limited to: base stations (g nodeB, gNB) in 5G, evolved node B (evolved node B, eNB) in long term evolution (LTE) system, radio network controller (RNC), wireless controller under cloud radio access network (CRAN) system, base station controller (BSC), home base station (for example, home evolved nodeB, or home node B, HNB), baseband unit (baseBand unit, BBU), transmitting and receiving point (TRP), transmitting point (TP), mobile switching center, and can also be evolved NB (eNB or eNodeB) in LTE, base station equipment in future 5G network or access network equipment in future evolved PLMN network, and can also be wearable device or vehicle-mounted device.
[0061] In some deployments, the network device can be a centralized unit (CU) or a distributed unit (DU). The network device may also include an active antenna unit (AAU). The CU implements some of the network device's functions, while the DU implements some of the network device's functions. For example, the CU is responsible for processing non-real-time protocols and services, and implementing the functions of the radio resource control (RRC) layer and the packet data convergence protocol (PDCP) layer. The DU is responsible for processing physical layer protocols and real-time services, and implementing the functions of the radio link control (RLC) layer, the media access control (MAC) layer, and the physical (PHY) layer. The AAU implements some physical layer processing functions, RF processing, and active antenna-related functions. Because RRC layer information will eventually become PHY layer information, or be converted from PHY layer information, in this architecture, higher-layer signaling, such as RRC layer signaling, can also be considered to be sent by the DU, or by the DU+AAU. It is understandable that the network device may be a device including one or more of a CU node, a DU node, and an AAU node. In addition, the CU may be divided into a network device in an access network (radio access network, RAN), or the CU may be divided into a network device in a core network (core network, CN), which is not limited in this application. Examples of network devices include, but are not limited to, Node B (NodeB or NB), evolved NodeB (eNodeB or eNB), next generation NodeB (gNB), transmit receive point (TRP), remote radio unit (RRU), radio head (radio head, RH), remote radio head (remote radio head, RRH), integrated access and backhaul (IAB) node, low power node, such as a micro-micro node, a micro-micro node, a reconfigurable intelligent surface (RIS), a network controlled repeater, etc. In different communication systems, CU (or CU-CP and CU-UP), DU or RU may also have different names, but those skilled in the art can understand their meaning. For example, in the ORAN system, CU may also be called O-CU (Open CU), DU may also be called O-DU, CU-CP may also be called O-CU-CP, CU-UP may also be called O-CU-UP, and RU may also be called O-RU.For ease of description, this application uses CU, CU-CP, CU-UP, DU, and RU as examples. Any of the CU (or CU-CP, CU-UP), DU, and RU in this application can be implemented through a software module, a hardware module, or a combination of a software module and a hardware module.
[0062] In addition, network devices such as access network devices can be connected to core network (CN) devices, and core network devices can be used to provide core network services for access network devices and terminal devices. Core network devices can correspond to different devices in different systems. For example, in 3G, core network devices can correspond to the serving GPRS support node (SGSN) of the general packet radio system (GPRS) and / or the gateway GPRS support node (GGSN) of GPRS. In 4G, core network devices can correspond to the mobility management entity (MME) and / or the serving gateway (S-GW). In 5G, core network devices can correspond to the access and mobility management function (AMF), the session management function (SMF) or the user plane function (UPF).
[0063] Base stations can be fixed or mobile. For example, a helicopter or drone can be configured to act as a mobile base station, and one or more cells can move based on the location of the mobile base station. In other examples, a helicopter or drone can be configured to act as a device that communicates with another base station.
[0064] In the embodiments of the present application, the device for implementing the function of the network device can be a terminal device, or a device that can support the network device to implement the function, such as a chip system or chip, which can be installed in the network device. In the embodiments of the present application, the chip system can be composed of a chip, or it can include a chip and other discrete devices.
[0065] The network equipment and terminal devices can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; they can also be deployed on water; they can also be deployed in the air on aircraft, balloons, and satellites. The embodiments of this application do not limit the scenarios in which the network equipment and terminal devices are located.
[0066] The RAN can be a 3GPP-related cellular system, such as a 4G or 5G mobile communication system, or a future-oriented evolutionary system (such as a 6G mobile communication system). The RAN can also be an open access network (O-RAN or ORAN), a cloud RAN (CRAN), or a wireless fidelity (WiFi) system. The RAN can also be a communication system that integrates two or more of the above systems.
[0067] The disclosed embodiment proposes a scheme for determining keys for network security. The current "plug-in" security mechanism that relies solely on high-level cryptography will face severe challenges in the 6G era, and it is urgent to study the intrinsic security mechanism at the link level. The realization of intrinsic link-level security includes: intrinsic security resources. Endogenous security resources mean that the resources for achieving security come from within the communication system, such as wireless channels, random noise, terminal hardware, etc., rather than through external distribution. There are two main advantages of endogenous resources. One is that it ensures the richness and continuous supply of randomness, which provides a prerequisite for achieving strong security. The second is to avoid the security risks and additional overhead brought by external distribution to the greatest extent.
[0068] FIG1B shows a schematic diagram of a key generation process. In the physical layer key generation process 100-1, the receiving and transmitting ends need to go through the steps of channel measurement (101), quantization (103), information reconciliation (105), determining whether the information reconciliation is consistent (107), and returning to the channel measurement step if the information reconciliation is consistent, or privacy amplification (109) if the information reconciliation is inconsistent, in order to obtain a consistent key. In some schemes, the quantization step needs to determine a quantization threshold so that the final generated key satisfies a uniform distribution. To achieve this goal, when generating a key based on wireless channel information, it is necessary to know the statistical distribution characteristics of the channel h (or a quantity related to it, such as the modulus of h). The statistical distribution characteristics can be approximated by using an empirical distribution.
[0069] To obtain a reliable empirical distribution and determine a reasonable quantization threshold, a large amount of channel observation data is typically required. Some schemes use single-threshold quantization, where both the transmitter and receiver extract random factors from the legitimate channel, quantize them according to a single threshold, and generate key bits. Each transmitter and receiver estimates the channel state (matrix H) based on the large amount of collected data and determines the quantization threshold based on the estimated empirical distribution of the channel. Other schemes use dual-threshold quantization, which can alleviate the error issues faced by single-threshold quantization and improve key consistency. Dual-threshold quantization adds a guard band at both ends of the single threshold. If the channel information falls within the guard band, it is not used to generate the key. Dual-threshold quantization discards some channel estimates, resulting in lower key utilization. However, even for channel estimates approaching dual-threshold quantization, a large amount of data must be collected to obtain a highly accurate empirical distribution of the channel state.
[0070] The above-mentioned scheme based on single-threshold quantization or double-threshold quantization will result in additional computational overhead and processing delay, and even if a large amount of observation data is collected, the obtained empirical distribution may still not be accurate enough, which will cause the final generated key to not meet the uniform distribution requirement, affecting the quality of key generation. Some embodiments of the present disclosure can be based on the process 100-1, by adopting a scheme different from the scheme for determining the quantization threshold to implement the above-mentioned quantization 103. In the process of determining the key in the embodiment of the present disclosure, there is no need to calculate the quantization threshold in the quantization step 103, thereby saving the amount of calculation, and in some embodiments, there is no need to use the empirical distribution, thereby avoiding the problem that the empirical distribution obtained by collecting a large amount of observation data in the scheme using the empirical distribution is still inaccurate, which in turn leads to the problem of low quality of the generated key.
[0071] FIG2 is a schematic diagram of a process for determining a key according to some embodiments of the present disclosure. As shown in FIG2 , process 200 involves a first communication device 210 or a second communication device 220, wherein the first communication device 210 can be one of the terminal device 110 or the network device 120, and the second communication device 220 can be the other of the terminal device 110 or the network device 120. For example, an example of the first communication device 210 is a UE (user equipment), and an example of the second communication device 220 is a base station. Alternatively, an example of the first communication device 210 is a base station, and an example of the second communication device 220 is a UE. It should be noted that the first communication device 210 and the second communication device 220 are not limited to the specific examples listed above, and can also be other terminal devices or network devices.
[0072] In process 200, a first communication device 210 extracts (201) channel randomness information from an estimated channel matrix. The first communication device 210 quantizes (203) the channel randomness information, wherein the quantized channel randomness information belongs to a quotient group in a discrete integer domain. In some examples, a homomorphic mapping based on the quotient group maps the channel estimate from a continuous real number domain to a quotient group of positive integers, thereby obtaining a physical layer key in a discrete real number domain and uniformly distributed. The quotient group is defined as follows:
[0073] The quotient group only contains integers from 0 to n-1, i.e., the value space of the key bits. In some examples, the relationship between the quantization level m and the key length is as follows: if an n-bit key string needs to be generated, the quantization level m = 2 n For example, to generate a 4-bit key string, the quantization level m = 2 4 , the quantized value range is [0,2 4 -1]. The relationship between the quantization level m and the consistency rate is as follows: In order to ensure that the receiving end (such as the second communication device 220) can correctly decrypt the encrypted signal transmitted by the sending end (such as the first communication device 210), the quantization results used to generate the key must be consistent. When the channel conditions are poor and the channel reciprocity between the receiving and transmitting ends is not ideal, the fine-grained (i.e., high quantization level) quantization results are likely to cause the inconsistency rate to increase, and the coarse-grained quantization results can better solve this problem. The quantization level m can be determined by reference to but not limited to one of the following two methods or a combination: i) using the feedback mode to compare the consistency rate of key generation between the receiving and transmitting ends, and using the comparison results of periodic feedback to adjust the quantization level. If the consistency rate is high, the quantization level is high, otherwise the quantization level is low; ii) the channel condition is affected by the real-time results of the channel measurement. When the channel condition is good, the quantization level is high, otherwise the quantization level is low.
[0074] In some examples, the channel randomness information may be the real part of the element value of the estimated channel matrix, the imaginary part of the element value of the estimated channel matrix, the modulus value of the element value of the estimated channel matrix, the square of the modulus value of the element value of the estimated channel matrix, or the argument of the element value of the estimated channel matrix. In some embodiments, the channel randomness information may be quantized based on a first mapping function determined by a quantization level. In some examples, a quotient group-based mapping function is defined using the quantization level m. The output of this function is a non-negative integer in the discrete integer domain, belonging to the quotient group defined above. (where m is the quantization level) satisfies the following mapping relationship:
[0075] In some examples, during the quantization of channel randomness information, the first communication device 210 may, based on a second mapping function, map the channel randomness information from its domain to a first numerical interval, thereby obtaining a value of the channel randomness information within the first numerical interval. In some embodiments below, the second mapping function is defined as a function Φ(x). The specific form of the second mapping function Φ(x) may vary for different examples of channel randomness information. For example, Φ(x) may be determined based on the distribution of information corresponding to the selected mode. In some examples, Φ(x) may be a cumulative distribution function of a standard distribution of the corresponding distribution. The first mapping function maps the value of the channel randomness information within the first numerical interval to a quotient group in the domain of discrete integers. For example, a first parameter of the first mapping function may be obtained based on the output of the second mapping function, and a second parameter of the first mapping function may be obtained based on the quantization level. The first and second parameters may be used as inputs to the first mapping function, and the value of the channel randomness information within the first numerical interval may be mapped to a quotient group in the domain of discrete integers. The range of the first numerical interval may vary in different examples. For details, see the description of the embodiments below. In other examples, there is no need to define the second mapping function Φ(x), but the first parameter of the first mapping function can be obtained based on the argument of the element value of the estimated channel matrix, and the second parameter of the first mapping function can be obtained based on the quantization level.
[0076] In some examples where the channel randomness information is the real part or imaginary part of the element value of the estimated channel matrix, the second mapping function is the cumulative distribution function of the standard normal distribution. In some examples where the channel randomness information is the modulus of the element value of the estimated channel matrix, the second mapping function is the cumulative distribution function of the Rayleigh distribution. In some examples where the channel randomness information is the square of the modulus of the element value of the estimated channel matrix, the second mapping function is a function defined based on the exponential distribution characteristic, for example, the second mapping function Φ(x)=e -x ,x≥0, e is a natural constant. In some examples where the channel randomness information is the angular value of the element value of the estimated channel matrix, the second mapping function may be a function defined based on the angular value, such as the second mapping function Φ(x)=x, where x is the angular value θ or θ / α according to different examples, where 0≤θ≤2π. For details, refer to the process 1100 for determining the key for the above scenario five below. In some examples where the channel randomness information is the angular value of the element value of the estimated channel matrix, the second mapping function may be a cumulative distribution function of a uniform distribution in the interval [0,2π], such as the second mapping function In some examples, the empirical distribution parameters may be used in the process of determining the key, and the input of the second mapping function may be based on the channel randomness information normalized by the empirical distribution parameters. In other examples, the empirical distribution parameters may not be used in the process of determining the key, and the input of the second mapping function may be the channel randomness information (i.e., not normalized by the empirical distribution parameters). In some examples, whether to input the empirical distribution parameter α is determined based on the scenario requirements. If not input, α=1 is assumed.
[0077] In some examples, the first mapping function may scale the interval corresponding to the first parameter from the first interval to the second interval, and then map it to a quotient group of the discrete integer domain, wherein the upper limit of the second interval is an integer multiple (1 times) of the quantization level. For example, when the input parameter α, the output result c=Φ(x) of the Φ function obeys a uniform distribution, Scale c to the interval [0,m) and map it to the quotient group In some examples, the input of the second mapping function does not use the channel randomness information normalized by the empirical distribution parameter, but uses an integer multiple of the input value of the empirical distribution parameter as the input value of the second mapping function, and the integer multiple of the input value of the empirical distribution parameter is greater than a preset threshold. For example, when the parameter α is not input, Scale c = Φ(x) to the interval [0, lm] and map it to the quotient group At this time, l is a positive integer and l can be greater than or equal to 40. For example, the value of l can be 1000. 1000 is an example value of the preset threshold value. In other embodiments, the preset threshold value may also be another value, such as an integer greater than or equal to 40.
[0078] In some embodiments, for example, in a TDD scenario, each element value h of the wireless channel H between the transmitting and receiving ends may be modeled, where each element value h follows a complex Gaussian distribution: Where α represents the large-scale fading information, Represents small-scale fading information, and the angular information (argument) of h is recorded as θ=arg(h). The estimated channel value represented by each h and its related information can be used to generate a key. In some examples, the channel randomness information is determined based on the mode selected by the first communication device 210 that executes process 200. The different examples of the above-mentioned channel randomness information can correspond to different modes selected for determining the key. The mode is related to the channel conditions. The selection of the mode can be based on the channel conditions between the first communication device 210 and the second communication device 220. For example, the propagation mechanism of radio waves, such as absorption, scattering, refraction, diffraction, scintillation, dispersion, etc., will have a certain impact on the amplitude and phase of the radio waves. The propagation mechanism in some environments has a greater impact on the amplitude. When selecting the mode, it is possible to avoid using amplitude-related information as much as possible, and instead give priority to using phase-related information for quantization, such as real(h), imag(h), and θ. The propagation mechanism in some environments has a greater impact on the phase, while the amplitude is relatively stable. In this case, when selecting the mode, it is possible to give priority to using amplitude-related information for quantization, such as |h| and |h| 2 , where h represents the element value of the estimated channel matrix, and θ represents the argument of h. In some examples, the mode may be specified by a protocol. In other examples, the mode may be determined by signaling interaction between the first communication device 210 and the second communication device 220, for example, the first communication device 210 sends the selected mode to the second communication device 220, or the first communication device 210 receives the selected mode sent by the second communication device 220 from the second communication device 220. When at least one of the channel conditions changes, the first communication device 210 may receive or send an indication for updating the selected mode.
[0079] In some examples, the channel randomness information can be extracted based on the index of the element value in the estimated channel matrix. In some examples, the first communication device 210 can pre-agree on the index with the second communication device 220, or the first communication device 210 and the second communication device 220 determine the index through signaling interaction, for example, the first communication device 210 sends the index to the second communication device 220, or the first communication device 210 receives the index sent by the second communication device 220 from the second communication device 220. For example, for the estimated channel matrix H measured by a sounding reference signal (SRS), the transmitting and receiving ends select h at the same position to extract random information and generate key bits. The position of h can be agreed upon by both parties through an agreement, or it can be notified to the other party as interactive information.
[0080] The first communication device 210 determines (205) a physical layer key based on the quantized channel randomness information. The output result η is converted into a binary 01 bit, which is the key bit. Referring to the privacy amplification step (109) of Figure 1B, in the privacy amplification step, the quantized key bit can generate a key stream through a hash function. As mentioned above, the first communication device 210 can be one of the terminal device 110 or the network device 120, that is, the method for determining the key of the embodiment of the present disclosure can be implemented in the terminal device 110 or the network device 120. In some examples, after the terminal device 110 and the network device 120 obtain the quantized key through this method, they respectively use it as input to the hash function. The values input to the hash function by both parties are the same, so the key stream output by the hash function is also the same.
[0081] In some embodiments, after determining the physical layer key, the first communication device 210 uses the physical layer key to communicate with the second communication device 220. For example, the first communication device 210 may use the physical layer key to encrypt the signal / data / information to be transmitted (207), and transmit the encrypted signal / data / information 202 to the second communication device 220 (209). The second communication device 220 may receive the encrypted signal / data / information 202 (211). It should be noted that, in some embodiments, the operations corresponding to 207 and 209 may be optional steps.
[0082] Figure 3 illustrates a schematic diagram of a key determination process according to other embodiments of the present disclosure. As shown in process 300 in Figure 3, at 301, channel information h is obtained, i.e., the element value h in the estimated channel matrix. At 303, a mode selection t is performed based on channel conditions. In some examples, this mode selection information may be signaling between the transmitter and receiver. Five exemplary modes 302a to 302e correspond to the real part, imaginary part, modulus, square of modulus, and argument of the element value h in the estimated channel matrix, respectively. Based on the selected mode, a corresponding function is determined. This corresponding function may be, for example, the cumulative distribution function mentioned above as some examples of the second mapping function, or a function defined based on exponential distribution characteristics or argument, as other examples of the second mapping function. At 305, it is determined whether the input information has an empirical distribution parameter α. If so, 307 is performed to generate a key by quantization based on the empirical distribution parameter α and the quantization level m. If not, 309 is performed to generate a key by quantization based on the quantization level m. The embodiments of the present disclosure are based on the above-mentioned multiple modes, wherein the real part, imaginary part, modulus |h|, and square of modulus |h| of the element value h in the estimated channel matrix corresponding to the mode are 2, the angle θ, etc. are information in the channel endogenous information that has an analytical form of mathematical modeling, and the scenario is comprehensive. The physical layer key generation method of the embodiment of the present disclosure can be combined with the physical layer encryption algorithm. In some examples, random information can be extracted from the estimated channel or its related information in the security module of the transmitting end (such as the first communication device 210) and quantized to generate a key. In the TDD scenario, the air interface channel between the transmitter and receiver is reciprocal. After the receiver obtains the estimated channel and related information that are reciprocal with the transmitter, it also extracts random information from it and generates the key bits. The received encrypted information is decrypted according to the key. In order to ensure the quality of the key and reduce the possibility of illegal eavesdroppers obtaining the correct key based on the distribution law of the key, the solution of the embodiment of the present disclosure makes the keys used at both ends of the transmitter and receiver meet the uniform distribution. In this way, even if the illegal eavesdropper collects a large amount of data, he can only guess blindly. According to process 300, the use of empirical distribution parameters is an optional solution. For example, when the channel conditions are good and the empirical distribution approximation is relatively accurate, the empirical distribution parameters can be used to generate the key. When the channel conditions are not ideal and the empirical distribution approximation is inaccurate, the use of the parameters of the empirical distribution to generate the key can be avoided. This avoids the problem of inaccurate approximation due to the inability to obtain the characteristics of the estimated channel statistical distribution in practice, and can only rely on the empirical distribution expressed by the sampled data of the estimated channel to approximate the statistical distribution of the channel. It also avoids the problem that when the parameter error between the empirical distribution and the statistical distribution is large, the threshold value designed based on the empirical distribution may cause the final quantized key to not conform to the uniform distribution, thereby reducing the key quality.
[0083] The following Figures 4 (corresponding to Scenario 1), 6 (corresponding to Scenario 2), 7 (corresponding to Scenario 3), 9 (corresponding to Scenario 4), 11 (corresponding to Scenario 5), and 12 (corresponding to Scenario 6) respectively illustrate the process of determining the key in different scenarios. The embodiments corresponding to Scenario 1 to Scenario 6 respectively illustrate how to extract random information from the selected estimated channel-related information and generate key bits under 5 different mode selections. Among them, Scenario 5 and Scenario 6 provide two implementation methods for extracting random information from the angle.
[0084] FIG4 shows a schematic diagram of a process for determining a key in example scenarios of some other embodiments of the present disclosure, which shows a process 400 for determining a key for the above scenario 1, specifically illustrating how to extract and quantize randomness information k from the real part of the element value h of the estimated channel H based on the quotient group. As shown in FIG4 , the first communication device (such as the first communication device 210) determines a function Φ (an example of the second mapping function) based on the selected mode and (Example of the first mapping function) After that, there are two implementation methods depending on whether the empirical distribution parameter α is input.
[0085] When selecting a mode to extract random information from the real part of h for quantization, it is necessary to consider the mathematical modeling of the real part of h, as shown in 401, where the random information k=real(h). The real part of h (real) obeys a Gaussian distribution, that is:
[0086] Determine (403) the function Φ and Specifically, the function Φ is constructed as the cumulative distribution function of the standard normal distribution as follows:
[0087] This function defines the input in the real number domain. The real part of h on is mapped to the interval [0, 1]. In addition to defining the function Φ, we also define the function determined by the quantization level m This function needs to satisfy the following mapping relationship:
[0088] The meaning of this mapping relationship is: function The function maps the real numbers in the interval [0, 1] to the quotient group of the discrete integer domain according to the input parameters. The specific definitions are as follows:
[0089] Among them, the quantization level m≥2. Here corresponds to the above mapping relationship, the first input parameter a∈[0,1], the second input parameter
[0090] Determine the function Φ and After the definition of , it is determined (405) whether the empirical distribution parameter α is input. The process of calculating the quantitative result η can be implemented in two ways depending on whether the empirical distribution parameter α is input:
[0091] Method 1: When α is input, the real part of h is normalized using α and used as the input of the function Φ, as shown in 407a. When k=real(h), that is:
[0092] At this time, the distribution of c obeys the uniform distribution in the interval [0,1], that is, Enter c and m into the function Can be mapped to the quotient group Implement a discrete quantization process that obeys a uniform distribution. Substitute the above function into the calculation here The expression of , as shown in 409a, yields:
[0093] The mod function is a modulo operation, specifically defined as follows: mod(a,m)=am*floor(a / m)
[0094] The floor function rounds the input value to the nearest integer that is less than or equal to the input value.
[0095] function It is possible to first scale the values in the [0,1] interval to [0,m] and then map them to If it is not scaled to [0, m], all c, since they belong to the interval [0, 1], will be mapped to the integer 0. Function The second input parameter can also be a positive integer multiple of m.
[0096] Method 2: When the empirical distribution parameter α is not input, the default value is α = 1. The real part of h is directly used as the input value of the function Φ, as shown in 407b. When k = real(h), that is: c = Φ(real(h))
[0097] At this time, the value range of c is In the interval, it obeys the bell curve distribution and the parameters are unknown. In this scenario, map c to the quotient group And ensure that the output integer η obeys uniform distribution, function It is necessary to scale c on I to the interval [0, lm], where l is a positive integer and l can be greater than or equal to 40, for example, the value of l can be 1000 (1000 is an example of a preset threshold) as an integer. After the magnification, the output integer η can be made to obey a uniform distribution, which is mainly due to the difference between the calculation of group homomorphism and the traditional scheme (quantization according to the threshold value makes the entire interval between adjacent threshold values have the same quantization result). Based on the calculation of group homomorphism, two adjacent high-probability values (such as the values near the middle position in the bell curve in Figures 5A and 5B) can be mapped to different integer values. The expression for substituting η is calculated here, as shown in 409b:
[0098] Among them, the second input parameter value used in the mod function comes from The subscript of the quantization level m is not changed here. . Figures 5A and 5B above are examples of the distribution obeyed by the output of the second mapping function. Figure 5A is a bell-shaped distribution curve in the interval [0, 1], and Figure 5B is a bell-shaped distribution curve scaled to the interval [0, 1m]. It can be seen that scaling does not change the shape of the curve.
[0099] In obtaining quantitative results After that, it needs to be converted into a binary bit string bits η ∈{0, 1}, namely key bits, to determine (411) the physical layer key.
[0100] FIG6 shows a schematic diagram of a process of determining a key in example scenarios of some further embodiments of the present disclosure, wherein a process 600 of determining a key for the above-mentioned scenario 2 is shown. In the process 600, the first communication device (e.g., the first communication device 210 described above) extracts randomness information from the imaginary part of the element value h of the estimated channel H and quantizes it, and determines a function Φ (an example of a second mapping function) and a function Φ based on the selected mode. (Example of the first mapping function) After that, there are two implementation methods depending on whether the empirical distribution parameter α is input. When the selection mode is to extract random information from the imaginary part of h for quantization, it is necessary to consider the mathematical modeling of the imaginary part of h, as shown in 601, k = imag(h). h itself obeys a complex Gaussian distribution, so the imaginary part of h (imag) is modeled in the same way as the real part of h in scenario 1, both obeying a Gaussian distribution, that is:
[0101] Determine (603) the function Φ and Specifically, the function Φ is constructed as the cumulative distribution function of the standard normal distribution as follows:
[0102] The function Φ defines the input in the real number domain. The imaginary part of h on is mapped to the interval [0,1]. Here is the domain of the Gaussian distribution, and has nothing to do with whether the information comes from the real part or the imaginary part. Whether it is the real part or the imaginary part, the information is real. In addition to defining the function Φ, we also define the function determined by the quantization level m This function The following mapping relationship is satisfied:
[0103] In other words, this function maps the real numbers in the interval [0,1] to the quotient group of the discrete integer domain according to the input parameters. It should be noted that the function The definition of is determined by and only by the quantization level m, and has nothing to do with the mode selection (i.e., what information is the input source used to extract random information about h). Therefore, how to define the function according to the quantization level m Please refer to the above scenario 1 expression.
[0104] Determine the function Φ and After the definition of , it is determined (605) whether the empirical distribution parameter α is input. The process of calculating the quantitative result η is divided into two implementation methods according to whether the empirical distribution parameter α is input:
[0105] In the first method, when α is input, the imaginary part of h is normalized using α and used as the input of the function Φ, as shown in 607a. When k = imag(h), that is:
[0106] At this time, the distribution of c obeys the uniform distribution in the interval [0,1], that is, Enter c and m into the function Can be mapped to the quotient group A discrete quantization process that obeys a uniform distribution is implemented. Here, the expression for η is substituted into the calculation, as shown in 609a:
[0107] function The effect achieved is to first scale the values in the [0,1] interval to [0,m], and then map them to If it is not scaled to [0,m], all c, because they belong to the interval [0,1], will be mapped to the integer 0. Function The second input parameter can also be a positive integer multiple of m.
[0108] In another embodiment, when the empirical distribution parameter α is not input, it is assumed to be 1. The imaginary part of h is directly used as the input value of the function Φ, as shown in 607b. When k = imag(h), that is, c = Φ(imag(h))
[0109] At this time, the value range of c is In this case, c is mapped to the quotient group And ensure that the output integer η obeys uniform distribution, function It is necessary to scale c on I to the interval [0, lm], where l is a positive integer greater than or equal to 40, for example, 1000. This scaling factor ensures that the output integer η follows a uniform distribution. For details, see the above description of scenario 1. Substituting the expression for η into the calculation, as shown in 609b, when k = real(h):
[0110] The second input parameter value used in the mod function comes from The subscript of the quantization level m is not changed here. In obtaining quantitative results After that, the quantization result can be converted into a binary bit string bits η ∈{0, 1}, namely the key bit, that is, determining the (611) physical layer key.
[0111] FIG7 is a schematic diagram of a process for determining a key in example scenarios of further embodiments of the present disclosure, which illustrates a process 700 for determining a key for the aforementioned scenario three. In this process 700, a first communication device (e.g., the first communication device 210 described above) extracts and quantizes random information from the modulus of the element value h of the estimated channel H. Specifically, when extracting random information from the modulus of h and quantizing it based on a selection pattern, mathematical modeling of the modulus of h needs to be considered, as shown in 701, where k = |h|. If h itself follows a complex Gaussian distribution, then the modulus of h follows a Rayleigh distribution, i.e.:
[0112] Determine (703) the function Φ and Specifically, since the input information source obeys the Rayleigh distribution, the function Φ is constructed accordingly as the standard Rayleigh distribution, that is, the cumulative distribution function when the parameter σ = 1, as follows:
[0113] The domain of the Rayleigh distribution is the domain of non-negative real numbers Therefore, the function Φ here maps the input information on the non-negative real number domain, that is, the modulus value of h, to the interval [0,1]. In addition to defining the function Φ, we also define the function determined by the quantization level m This function The following mapping relationship is satisfied:
[0114] In other words, the function Maps the real numbers in the interval [0,1] to the quotient group of the discrete integer domain according to the input parameters. Define the function Please refer to the introduction of scenario 1 for details. After the definition of , it is determined (705) whether the empirical distribution parameter α is input. The process of calculating the quantitative result η is divided into two implementation methods according to whether the empirical distribution parameter α is input:
[0115] In the first implementation, when α is input, the modulus of h is normalized using α and used as the input of the function Φ, as shown in 707a. When k = |h|, that is:
[0116] At this time, the distribution of c obeys the uniform distribution in the interval [0,1], that is, Enter c and m into the function Can be mapped to the quotient group This implements a discrete quantization process that obeys a uniform distribution. Substituting the expression for η into the equation, as shown in 709a, yields:
[0117] function The effect achieved is to first scale the values in the [0,1] interval to [0,m], and then map them to If we do not scale to [0,m], then all c, since they belong to the interval [0,1], will be mapped to the integer 0. In some examples, the function The second input parameter can also be a positive integer multiple of m.
[0118] In the second implementation, when the parameter α of the empirical distribution is not input, it is assumed to be 1. The modulus of h is directly used as the input value of the function Φ, as shown in 707b. When k = |h|, that is, c = Φ(|h|)
[0119] At this time, the value range of c is In the interval, it obeys the exponential curve distribution, and the parameters are unknown. The exponential distribution curve is shown in Figure 8, which is an example of the distribution obeyed by the output of the second mapping function. In such a scenario, map c to the quotient group And ensure that the output integer η obeys uniform distribution, function It is necessary to scale c on I to the interval [0, 1 m], where l is an integer and can be greater than or equal to 40, for example, l can be 1000. This scaling factor allows the output integer η to follow a uniform distribution. Based on group homomorphism, two adjacent high-probability values (such as the values near the left of the exponential distribution) can be mapped to different integer values. Substituting this into the expression for η, as shown in 709b, yields:
[0120] The second input parameter value used in the mod function comes from The subscript of the quantization level m is not changed here. Get quantitative results After that, it needs to be converted into a binary bit string bits η ∈{0,1}, i.e. key bits, to determine the (711) physical layer key.
[0121] FIG9 is a schematic diagram of a process for determining a key in example scenarios of further embodiments of the present disclosure, wherein a process 900 for determining a key for the aforementioned scenario 4 is shown. In this process 900, a first communication device (e.g., the first communication device 210 described above) extracts random information from the square of the modulus value of the element value h of the estimated channel H and quantizes the information. Specifically, when selecting a mode for extracting random information from the square of the modulus value of h for quantization, mathematical modeling of the square of the modulus value of h is considered, as shown in 901, k = |h| 2 h itself obeys a complex Gaussian distribution, and the square of the modulus of h obeys an exponential distribution, that is: |h| 2 ~f(x;λ)=λe-λx ,x≥00(i.e. )
[0122] Determine (903) function Φ and Specifically, because the input information source in this example (ie, the square of the modulus of h) obeys an exponential distribution, the function Φ is constructed as follows: Φ(x) = e -x , x≥0
[0123] The domain of the exponential distribution is the domain of non-negative real numbers. Here, the function Φ maps the input information on the non-negative real number domain, that is, the square of the modulus value of h, to the interval [0,1]. In addition to defining the function Φ, we also define the function determined by the quantization level m This function satisfies the following mapping relationship:
[0124] In other words, the function maps the real numbers in the interval [0,1] to the quotient group of the discrete integer domain according to the input parameters. Refer to other embodiments for Description and expression.
[0125] The functions Φ and After the definition of , it is determined (905) whether the empirical distribution parameter α is input. Depending on whether the empirical distribution parameter α is input, the process of calculating the quantization result η includes two branches for execution, wherein the first branch is when the empirical distribution parameter α is input, and the second branch is when the empirical distribution parameter α is not input. Specifically, for the first branch, when α is input, the square of the modulus value of h is normalized by α as the input of the function Φ, that is, as shown in 907a, when k = |h| 2 ,but:
[0126] At this time, the distribution of c obeys the uniform distribution in the interval [0,1], that is, Enter c and m into the function Can be mapped to the quotient group This implements a discrete quantization process that obeys a uniform distribution. Substituting the expression for η into the equation, as shown in 909a, yields:
[0127] function The effect achieved is to first scale the values in the [0,1] interval to [0,m], and then map them to If it is not scaled to [0,m], all c, because they belong to the interval [0,1], will be mapped to the integer 0. Function The second input parameter can also be a positive integer multiple of m.
[0128] For branch 2, when the parameter α of the empirical distribution is not input, the default value is α = 1. The square of the modulus value of h is directly used as the input value of the function Φ, as shown in 907b. When k = |h| 2 , that is: c=Φ(|h| 2 )
[0129] At this time, the value range of c is On the interval, it obeys a quasi-exponential curve distribution, and the parameters are unknown. The quasi-exponential curve distribution curve is shown in Figure 10, which is an example of the distribution obeyed by the output of the second mapping function. The quasi-exponential curve distribution is used here because the probability of a general exponential curve distribution decreases as the random variable increases, while the actual distribution of c is the opposite, that is, the probability increases as the random variable increases. In this scenario, mapping c to the quotient group And ensure that the output integer η obeys uniform distribution, function It is necessary to scale c on I to the interval [0, 1 m], where l is an integer and l can be greater than or equal to 40, for example, the value of l can be 1000. After the magnification, the output integer η can be made to obey a uniform distribution. For details, please refer to the introduction of the above embodiment. Based on the calculation of group homomorphism, two adjacent high-probability values (for example, the values close to the right position of the exponential curve distribution) can be mapped to different integer values. Substituting the expression of η here, as shown in 909b, we obtain:
[0130] The second input parameter value used in the mod function comes from The subscript of the quantization level m is not changed here. Get quantitative results After that, it needs to be converted into a binary bit string bits η ∈{0, 1}, namely key bits, to determine the (911) physical layer key.
[0131] FIG11 is a schematic diagram of a process for determining a key in example scenarios of further embodiments of the present disclosure, wherein a process 1100 for determining a key for the above-mentioned scenario 5 is shown. In this process 1100, a first communication device (e.g., the first communication device 210 described above) extracts random information from the argument θ of the element value h of the estimated channel H and quantizes it. When a mode is selected to extract random information from the argument of h for quantization, mathematical modeling of the argument of h is considered, as shown in 1101, k=θ. h follows a complex Gaussian distribution, and the argument of h follows a uniform distribution, that is:
[0132] According to the range of the argument, we know that α = 2π. Determine the (1103) function Φ and Specifically, the information source input here obeys a uniform distribution. In this example, the function Φ does not need to introduce a cumulative score function uniformly distributed in the interval [0, 1]. It can be defined as: Φ(x) = x
[0133] In addition to defining the function Φ, it is also necessary to define the function determined by the quantization level m This function satisfies the following mapping relationship:
[0134] In other words, the function maps the real numbers in the interval [0, 2π] to the quotient group of the discrete integer domain according to the input parameters. Reference may be made to the other embodiments above.
[0135] In some of the above embodiments, the range of the real part or imaginary part of h is the real number domain In some embodiments, the modulus and the square of the modulus of h range from the non-negative real number domain. In this example, the range of the argument of h is [0, 2π], not involving ±∞. Based on the selected mode, the function Φ and Then, it is determined (1105) whether the empirical distribution parameter α is input. Depending on whether the empirical distribution parameter α is input, there are two implementation methods.
[0136] In the first implementation, when the empirical distribution parameter α is input, α is used to normalize the argument of h and used as the input of the function Φ, as shown in 1107a. When k=θ, that is:
[0137] At this time, the distribution of c obeys the uniform distribution in the interval [0,1], that is, Enter c and m into the function Can be mapped to the quotient group A discrete quantization process that obeys a uniform distribution is implemented. Substituting the expression for η into the equation, as shown in 1109a, yields:
[0138] function The effect achieved is to first scale the values in the [0,1] interval to [0,m], and then map them to If it is not scaled to [0,m], all c, because they belong to the interval [0,1], will be mapped to the integer 0. Function The second input parameter can also be a positive integer multiple of m.
[0139] In the second implementation, when the empirical distribution parameter α is not input, the default value is α = 1. The argument of h is directly used as the input value of the function Φ, as shown in 1107b. When k = θ, that is: c = Φ(θ)
[0140] At this time, the value range of c is in the interval I, which obeys the uniform distribution, but the parameters are unknown. The interval I is not a subinterval of the interval [0,1]. In this scenario, map c to the quotient group And ensure that the output integer η obeys uniform distribution, function It is necessary to scale c on I to the interval [0, 1 m], where l is an integer and can be greater than or equal to 40, for example, the value of l can be 1000. This scaling factor allows the output integer η to follow a uniform distribution, primarily due to the difference between group homomorphism calculations and traditional solutions (which use threshold quantization to ensure that the entire interval between adjacent threshold values has the same quantization result). Group homomorphism-based calculations allow two adjacent high-probability values to be mapped to different integer values. Substituting the expression for η here, as shown in 1109b, yields:
[0141] The second input parameter value used in the mod function comes from The subscript of the quantization level m is not changed here. Get quantitative results After that, it needs to be converted into a binary bit string bits η ∈{0,1}, i.e., key bits, to determine the (1111) physical layer key. In this embodiment, since the statistical distribution of the argument is already uniform, the function Φ in the calculation process is defined as an identity function, and no unnecessary calculation is introduced.
[0142] FIG12 shows a schematic diagram of a process for determining a key in example scenarios of some further embodiments of the present disclosure, wherein a process 1200 for determining a key for the above-mentioned scenario six is shown. Process 1200 provides another possibility of extracting random information from the argument of hh, which is different from process 1100, and wherein the function Φ is different from the function Φ defined in process 1100, and the function Φ in process 1200 is no longer defined as an identity function. Process 1200 can be executed by the first communication device 210. When the selection mode is to extract random information from the argument of h for quantization, it is necessary to consider the mathematical modeling of the argument of h, as shown in 1201, k=θ. h obeys a complex Gaussian distribution, and the argument of h obeys a uniform distribution, that is:
[0143] Determine (1203) the function Φ and Specifically, in this example, the input information source (i.e., the argument of h) follows a uniform distribution. Since the distribution statistical parameter is known to be 2π, we introduce the cumulative score function of the uniform distribution in the interval [0, 2π] to define the construction function Φ:
[0144] The function Φ maps the input information on the interval [0,2π], that is, the argument of h, to the interval [0,1]. In addition to defining the function Φ, we also define the function determined by the quantization level m. This function satisfies the following mapping relationship:
[0145] This function maps real numbers in the interval [0,1] to the quotient group of the discrete integer domain according to the input parameters. Refer to the other embodiments above. After the definition of , it is determined (1205) whether c is calculated. The process of calculating the quantization result η is divided into two sub-processes according to whether c is calculated.
[0146] Sub-process 1: When calculating c, the argument of h is directly used as the input of the function Φ, as shown in 1207a, that is:
[0147] At this time, the distribution of c obeys the uniform distribution in the interval [0,1], that is, Enter c and m into the function Can be mapped to the quotient group A discrete quantization process that obeys a uniform distribution is implemented. Here, the expression for η is substituted into the calculation, as shown in 1209a:
[0148] function The effect achieved is to first scale the values in the [0,1] interval to [0,m], and then map them to If it is not scaled to [0,m], all c, because they belong to the interval [0,1], will be mapped to the integer 0. Function The second input parameter can also be a positive integer multiple of m.
[0149] When c is not calculated, the argument of h is directly used as a function The quantized value η is calculated based on the input value, as shown in 1209b, that is:
[0150] In such a scenario, map c to the quotient group And ensure that the output integer η obeys uniform distribution, function It is necessary to scale c on I to the interval [0, lm], where l is an integer and can be greater than or equal to 40, for example, l can be 1000. This scaling factor allows the output integer η to follow a uniform distribution, primarily due to the difference between group homomorphism calculations and traditional solutions (which use threshold quantization to ensure that the entire interval between adjacent threshold values has the same quantization result). Group homomorphism-based calculations allow two adjacent high-probability values to be mapped to different integer values. For details, please refer to the description of other embodiments above.
[0151] Obtaining quantitative results After that, it needs to be converted into a binary bit string bits η ∈{0,1}, i.e., key bits, to determine the (1211) physical layer key, which serves as the input information of the encryption scheme.
[0152] The h involved in some or all of the embodiments in the above scenarios one to six represents the element value of the estimated channel matrix. In some embodiments, the selection of the element value of the estimated channel matrix can be determined by signaling interaction between the receiving and transmitting ends, for example, the first communication device 210 sends the index of h to the second communication device 220, or the second communication device 220 sends the index of h to the first communication device 210. Other configured signalings can also be exchanged between the first communication device 210 and the second communication device 220, such as mode selection t, quantization level m, etc. The mode selection t indicates the selected mode. As described in the above embodiments, the mode can be determined according to the channel conditions. For example, according to the channel conditions, a mode can correspond to one of the above scenarios one to six.
[0153] FIG13 illustrates a schematic diagram of a signaling configuration process in an example scenario of some embodiments of the present disclosure. In process 1300 shown in FIG13 , the first communication device 210 is, for example, one of the terminal device 110 (e.g., UE) or the network device 120 (e.g., base station), and the second communication device 220 is, for example, the other of the terminal device 110 or the network device 120. In some embodiments, the first communication device 210 serves as a transmitter and the second communication device 220 serves as a receiver. For example, the first communication device 210 calculates selection mode selection t, etc. and sends it to the second communication device 220. In other embodiments, the second communication device 220 serves as a transmitter and the first communication device 210 serves as a receiver. For example, the second communication device 220 calculates selection mode selection t, etc. and sends it to the first communication device 210. The signaling configuration agreement can be specifically configured in the physical downlink control channel (PDCCH) of RRC, MAC, or PHY. For example, the base station (an example of one of the first communication device 210 or the second communication device 220) may instruct the UE (an example of the other of the first communication device 210 or the second communication device 220), or the UE may report to the base station. If multiple rounds of interaction are performed between the base station and the UE, the configuration may be sent in each round of interaction, or the configuration may be sent only in one round of interaction, and the configuration is adopted by default in subsequent interactions. An example of signaling may include an index of h, which is used for both the transmitting and receiving ends to select the same element value h from the estimated channel matrix H to extract randomness information and quantize and generate a key. An example of signaling may also include a mode selection t, which is used to select one of the real part, imaginary part, modulus, square of the modulus, and radian of the element value of the estimated channel matrix based on the channel conditions to obtain channel randomness information. An example of signaling may also include a quantization level m, which is determined according to the channel conditions and is used to determine (Example of the first mapping function) In some examples, when channel conditions change, a more appropriate mode may be reselected, and information about the updated mode may be sent to the other party of the communication through interactive signaling.
[0154] The embodiment shown in FIG13 uses signaling interaction to notify or update the above configuration. In other embodiments, instead of using signaling between the sender and receiver, the above configuration can be established through a protocol and stored in both the sender and receiver. As an example, process 1300 includes: after the access stratum (AS) security mode is established (1301), the first communication device 210 determines (1303) the selected mode. The first communication device 210 sends (1305a), and the second communication device 220 receives (1307a), an index 1302 of h. Optionally or alternatively, the first communication device 210 sends (1305b), and the second communication device 220 receives (1307b), a mode selection t (t indicating the selected mode) (1304). Optionally or alternatively, the first communication device 210 sends (1305c), and the second communication device 220 receives (1307c), a quantization level m (1306).
[0155] In the quotient group-based key determination scheme of the disclosed embodiments, the information used to generate the key is extracted from the wireless channel itself. When an empirical distribution of the estimated channel and its related information is available, the cumulative distribution function of the standard distribution of the corresponding information can be used to convert it into a uniform distribution. The information in the continuous real number domain is quantized into a key in the discrete integer domain based on the quotient group mapping corresponding to the quantization level m. When the empirical distribution of the estimated channel and its related information is unavailable, after conversion using the cumulative distribution function of the standard distribution of the corresponding information, the uniformly distributed key is obtained by amplifying the quantization level m by integer multiples, based on the quotient group mapping. This eliminates the need to obtain the empirical distribution parameters of the estimated channel and its related information, thereby generating a uniformly distributed physical layer key. The computational process of some disclosed embodiments avoids additional computational overhead and processing delay. In particular, when the accuracy of the empirical distribution calculated based on collected noisy channel information cannot be guaranteed, the scheme of the disclosed embodiments effectively avoids the risk of the quantized key not conforming to a uniform distribution, which may result from using the parameters of the empirical distribution to set thresholds and quantize the generated key.
[0156] Figures 14A to 14F show schematic diagrams comparing simulation results of some embodiments of the present disclosure. The simulation shown in Figures 14A to 14F compares the cumulative distribution of the quantization results with the cumulative distribution of the discrete uniform distribution on the interval (0, m-1). The horizontal axis m represents the quantization level, and the vertical axis is the cumulative distribution function (CDF). The parameters used in the simulation are as follows: the quantization level m=4 used in Figures 14A, 14B, and 14C, and the quantization level m=16 used in Figures 14D, 14E, and 14F. The modes used in Figures 14A, 14B, and 14C correspond to the real part of h, the modulus of h, and the square of the modulus of h, respectively. The modes used in Figures 14D, 14E, and 14F correspond to the real part of h, the modulus of h, and the square of the modulus of h, respectively. In Figures 14A to 14F, the thick black dashed line represents the cumulative distribution function of the statistical discrete uniform distribution, and the thin solid line with a hollow circle represents the quantization result under one of the above three modes. 14A , 14B, and 14C correspond to the case where empirical distribution parameters are input, and FIG. 14D , 14E, and 14F correspond to the case where empirical distribution parameters are not input.
[0157] Figure 15 shows a schematic flow chart of some embodiments of the present disclosure implemented at a communication device. As shown in Figure 15, the communication device executing process 1500 can be the first communication device 210 or located in the first communication device 210, for example, it can be the terminal device 110 or a chip, module, or module in the terminal device 110, or it can be the network device 120 or a chip, module, or module in the network device 120. In box 1510, the communication device extracts channel randomness information from the estimated channel matrix. In box 1520, the communication device quantizes the channel randomness information, wherein the quantized channel randomness information belongs to a quotient group of a discrete integer domain. In box 1530, the communication device determines a physical layer key based on the quantized channel randomness information. In some embodiments, process 1500 may also include other operations performed at the first communication device 210 described in conjunction with Figures 2 to 13 in the embodiments of the present disclosure.
[0158] FIG16 is a schematic diagram of the structure of possible communication devices provided by embodiments of the present disclosure. These communication devices can implement the functions of the communication devices in the above-mentioned method embodiments (such as the communication devices mentioned in the embodiment shown in FIG15 ), and thus can also achieve the beneficial effects possessed by the above-mentioned method embodiments. For example, in some embodiments of the present disclosure, the communication device can be the terminal device 110 or the network device 120 as shown in FIG1A , or can be a module (such as a chip) applied to the terminal device 110 or the network device 120.
[0159] As shown in FIG16 , the communication device 1600 includes a processing unit 1610 and, in some examples, may further include a communication unit 1620. The communication device 1600 may be used to implement the functions of the communication device (e.g., the first communication device 210) in the methods (or processes) of the embodiments shown in FIG2 to FIG15 . In the example where the communication device 1600 is used to implement the functions of the communication device shown in FIG15 , the processing unit 1610 may include an extraction unit, a quantization unit, and a determination unit. The communication unit 1620 may be specifically implemented as a transmitter and a receiver. For example, the communication unit 1620 may send data / information / signals encrypted with the physical layer key determined by the determination unit to another communication device (e.g., the second communication device 220). In some examples, the communication device 1600 may send configured signaling to another communication device or receive signaling from another communication device via the communication unit 1620. In some examples, the processing unit 1610 may be specifically implemented as a processor.
[0160] When communication device 1600 is used to implement the functions of the communication device in the method embodiment shown in FIG. 15 , the extraction unit in processing unit 1610 can be used to extract channel randomness information from the estimated channel matrix. The quantization unit in processing unit 1210 can be used to quantize the channel randomness information, where the quantized channel randomness information belongs to a quotient group of a discrete integer domain. The determination unit in processing unit 1210 can be used to determine a physical layer key based on the quantized channel randomness information. For a more detailed description of each of the above units, please refer to the relevant description in the above method embodiment and will not be further described here.
[0161] As shown in Figure 17, the communication device 1700 includes a processor 1710 and an interface circuit 1720. The processor 1710 and the interface circuit 1720 are coupled to each other. It will be understood that the interface circuit 1720 can be a transceiver or an input / output interface. Optionally, the communication device 1700 may also include a memory 1730 for storing instructions executed by the processor 1710 or storing input data required by the processor 1710 to execute instructions or storing data generated after the processor 1710 executes instructions. It should be noted that in some embodiments, the processor 1710 and the memory 1730 can be integrated into the same device. When the communication device 1700 is used to implement the method in the above method embodiment, the interface circuit 1720 is used to perform the functions of the above communication unit 1620.
[0162] When the communication device is a chip used in a communication device, the chip of the communication device implements the functions of the communication device in the above-mentioned method embodiment. The communication device chip sends data to other modules (such as a radio frequency module or an antenna) in the communication device, and the data may be sent to other devices; or the communication device chip receives data from other modules (such as a radio frequency module or an antenna) in the communication device, and the data is received from other devices.
[0163] It is understood that the processor in the embodiments of the present disclosure may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.
[0164] An embodiment of the present disclosure provides a communication system. The communication system may include the communication device involved in the embodiment shown in Figure 15 above. Optionally, the communication device in the communication system may correspondingly execute the communication method shown in Figure 15.
[0165] The present disclosure also provides a circuit that can be coupled to a memory and can be used to execute the communication device-related process in any of the above method embodiments. The chip system may include the chip and other components such as a memory or a transceiver.
[0166] It should be understood that the processor mentioned in the embodiments of the present disclosure may be a CPU, or may be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field programmable gate arrays (FPGAs) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc.
[0167] It should also be understood that the memory mentioned in the embodiments of the present disclosure may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM).
[0168] It should be noted that when the processor is a general-purpose processor, DSP, ASIC, FPGA or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, the memory (storage module) is integrated into the processor.
[0169] It should be noted that the memory described herein is intended to include, but is not limited to, these and any other suitable types of memory.
[0170] It should be understood that in the various embodiments of the present disclosure, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present disclosure.
[0171] Those skilled in the art will appreciate that the modules and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this disclosure.
[0172] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and modules described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0173] In the several embodiments provided in the present disclosure, it should be understood that the disclosed communication methods and devices can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the modules is merely a logical function division. In actual implementation, there may be other division methods, such as multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.
[0174] The modules described as separate components may or may not be physically separate, and the components shown as modules may or may not be physical modules, that is, they may be located in one place or distributed across multiple network elements. Some or all of these elements may be selected to achieve the purpose of this embodiment according to actual needs.
[0175] In addition, each functional module in each embodiment of the present disclosure may be integrated into one processing module, or each module may exist physically separately, or two or more modules may be integrated into one module.
[0176] If this function is implemented in the form of a software function module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiment of the present disclosure, or the part that makes the contribution or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the method of each embodiment of the present disclosure. The aforementioned computer-readable storage medium can be any available medium that can be accessed by a computer. By way of example and not limitation, computer-readable media may include random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM), universal serial bus flash disk, mobile hard disk, or other optical disk storage, magnetic disk storage media or other magnetic storage devices, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer.
[0177] As used herein, the term "including" and similar terms should be understood as open inclusion, i.e., "including but not limited to". The term "based on" should be understood as "based at least in part on". The term "one embodiment" or "the embodiment" should be understood as "at least one embodiment". The terms "first", "second", etc. can refer to different or the same objects and are only used to distinguish the objects referred to, and do not imply a specific spatial order, temporal order, order of importance, etc. of the objects referred to. In some embodiments, values, processes, selected items, determined items, devices, means, components, assemblies, etc. are referred to as "best", "lowest", "highest", "minimum", "maximum", etc. It should be understood that such descriptions are intended to indicate that a selection can be made from a number of available functional options, and that such a selection need not be better, lower, higher, smaller, larger, or otherwise preferred than other options in other aspects or all aspects. As used herein, the term "determine" can encompass a variety of actions. For example, "determine" can include calculating, computing, processing, deriving, investigating, searching (e.g., searching in a table, database, or another data structure), ascertaining, etc. Furthermore, "determining" may include receiving (eg, receiving information), accessing (eg, accessing data in a memory), etc. Furthermore, "determining" may include resolving, selecting, choosing, establishing, etc.
[0178] The above is merely a specific implementation of the embodiments of the present disclosure, but the scope of protection of the embodiments of the present disclosure is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the embodiments of the present disclosure should be included in the scope of protection of the embodiments of the present disclosure. Therefore, the scope of protection of the embodiments of the present disclosure should be based on the scope of protection of the claims.
Claims
1. A method for determining a secret key, characterized in that, Including: Extracting channel randomness information from an estimated channel matrix; Quantizing the channel randomness information, where the quantized channel randomness information belongs to a quotient group of a discrete integer domain; And Determining a physical layer key based on the quantized channel randomness information.
2. The method according to claim 1, wherein Quantizing the channel randomness information by a first mapping function determined based on a quantization level.
3. The method according to claim 1 or 2, characterized in that, Quantizing the channel randomness information includes: Based on a second mapping function, mapping the channel randomness information from its domain of definition to a first numerical interval to obtain the value of the channel randomness information in the first numerical interval; and Mapping the value of the channel randomness information in the first numerical interval to the quotient group of the discrete integer domain by the first mapping function.
4. The method according to claim 3, wherein A first parameter of the first mapping function is obtained based on the output of the second mapping function, and a second parameter of the first mapping function is obtained based on the quantization level.
5. The method according to claim 4, wherein The channel randomness information is the real part or the imaginary part of an element value of the estimated channel matrix, and the second mapping function is a cumulative distribution function of a standard normal distribution.
6. The method according to claim 4, characterized in that The channel randomness information is the modulus value of an element value of the estimated channel matrix, and the second mapping function is a cumulative distribution function of a Rayleigh distribution.
7. The method according to claim 4, wherein The channel randomness information is the square of the modulus value of an element value of the estimated channel matrix, and the second mapping function is a function defined based on exponential distribution characteristics.
8. The method according to claim 4, characterized in that The channel randomness information is the argument of an element value of the estimated channel matrix, and the second mapping function is a function defined based on the argument.
9. The method according to any one of claims 5-8, characterized in that The input of the second mapping function is one of the following: The channel randomness information normalized based on empirical distribution parameters; or The channel randomness information.
10. The method according to claim 3, characterized in that The channel randomness information is the argument of an element value of the estimated channel matrix, and the second mapping function is a cumulative distribution function of a uniform distribution in the interval [0, 2π].
11. The method according to claim 1 or 2, characterized in that, The channel randomness information is the argument of an element value of the estimated channel matrix, and a first parameter of the first mapping function is obtained based on the argument, and a second parameter of the first mapping function is obtained based on the quantization level.
12. The method according to any one of claims 4 to 11, characterized in that, The first mapping function is used to scale an interval corresponding to the first parameter from a first interval to a second interval and then map it to the quotient group of the discrete integer domain, where the upper limit of the second interval is an integer multiple of the quantization level.
13. The method according to claim 9, wherein The first mapping function is used to scale an interval corresponding to the first parameter and then map it to the quotient group of the discrete integer domain, the upper limit of the scaled interval is an integer multiple of the quantization level, and when the input of the second mapping function is the channel randomness information not normalized using empirical distribution parameters, the integer multiple is greater than a preset threshold.
14. The method according to any one of claims 1 to 13, characterized in that, The channel randomness information is determined based on a mode selected by a first communication device that executes the method, and at least one of the following: The mode is determined by a protocol; or The mode is determined by signaling interaction between the first communication device and a second communication device, and the first communication device communicates with the second communication device using the physical layer key.
15. The method according to claim 14, wherein The selection of the mode is based on the channel condition between the first communication device and the second communication device.
16. The method according to claim 15, characterized in that, It further includes: Receiving or sending an indication to update the mode when at least one of the channel conditions changes.
17. The method according to any one of claims 1 to 16, characterized in that, The channel randomness information is extracted based on the indices of the element values in the estimated channel matrix.
18. The method according to claim 17, wherein The index is pre-agreed between the first communication device that executes the method and the second communication device, and the first communication device communicates with the second communication device using the physical layer key; or The first communication device and the second communication device determine the index through signaling interaction.
19. A communication device, characterized in that, It includes: An extraction unit for extracting channel randomness information from the estimated channel matrix; A quantization unit for quantizing the channel randomness information, where the quantized channel randomness information belongs to the quotient group of the discrete integer domain; And A determination unit for determining the physical layer key based on the quantized channel randomness information.
20. A communication device, characterized in that, It includes: A processor and a memory storing instructions, and when the instructions are executed by the processor, the method according to any one of claims 1 to 18 is executed.
21. A communication system, characterized in that, It includes: The communication device according to claim 19 or 20.
22. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program or instructions, and when the computer program or instructions are executed, the method according to any one of claims 1 to 18 is executed.
23. A computer program product, characterized in that, It includes a computer program or instructions, and when the computer program or instructions are executed, the method according to any one of claims 1 to 18 is executed.
Citation Information
Patent Citations
Method, device and system for determining secret key, and storage medium
CN120264272A
Secret key generation method based on wireless channel characteristics in frequency division duplex system
CN103402200A
Physical layer key consistency negotiation method and system based on channel estimation
CN114629647A
Vector quantization based secret key generation device and method
US20170126403A1
Power line communication channel impulse response multilevel quantization for physical layer security
US20230216663A1
Cited By
Communication key generation method and device, equipment and storage medium
CN121711678A