Wireless communication methods of validating key generation in communication system and related apparatuses

A key validation process using encryption and integrity algorithms for AIoT devices ensures secure and efficient communication by verifying shared keys, addressing security vulnerabilities and power consumption issues in existing methods.

WO2025207208A1PCT designated stage Publication Date: 2025-10-02INNOPEAK TECHNOLOGY INC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/US2025/014751
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-27
Filing Date
2025-02-06
Publication Date
2025-10-02

AI Technical Summary

Technical Problem

Existing wireless communication methods for low-powered IoT devices, such as AIoT devices, lack explicit key validation processes during physical layer shared key generation, leading to security vulnerabilities and increased power consumption due to additional signaling for key confirmation.

Method used

Implement a key validation process involving encryption and integrity algorithms to verify the generated shared secret key, ensuring matching decrypted results before using the key for secure communication, thereby reducing power consumption and enhancing security.

Benefits of technology

Ensures consistent and secure key usage, optimizing key generation rounds, and minimizing overhead for resource-constrained AIoT devices by validating keys before encryption, thus improving communication security and efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure US2025014751_02102025_PF_FP_ABST
    Figure US2025014751_02102025_PF_FP_ABST
Patent Text Reader

Abstract

A wireless communication method of validating key generation in a communication system includes generating a shared secret key between a first entity and a second entity, extracting common bits known to the first entity and the second entity to form the shared secret key, and performing a key validation process, wherein the key validation process includes at least one of followings: encrypting a known parameter using the shared secret key with an encryption algorithm and / or an integrity algorithm at the first entity, transmitting at least a portion of an encrypted result to the second entity, decrypting a transmitted portion using the shared secret key at the second entity, determining whether a decrypted result matches the known parameter, and upon successful validation, using the shared secret key for encryption and secure communication.
Need to check novelty before this filing date? Find Prior Art

Description

WIRELESS COMMUNICATION METHODS OF VALIDATING KEY GENERATION IN COMMUNICATION SYSTEM AND RELATED APPARATUSESCROSS REFERENCE TO RELATED APPLICATIONS

[0001] This application claims priority to U.S. Provisional Application No. 63 / 570,654, entitled “METHOD FOR VALIDATING PHYSICAL LAYER SHARED KEY GENERATION IN A COMMUNICATION SYSTEM,” filed on March 27, 2024, which is hereby incorporated in its entirety by this reference.TECHNICAL FIELD

[0002] The present disclosure relates to the field of communication systems, and more particularly, to wireless communication methods of validating key generation in a communication system and related apparatuses such methods for validating physical layer shared key generation in a communication system, a wireless communication device, an ambient intemet-of-things (AIoT), a user equipment (UE), and a base station.BACKGROUND

[0003] Low-powered intemet-of-things (loT) devices, including AIoT devices or passive loT devices, operate without conventional batteries or with limited power, relying on energy harvesting from sources such as wireless radio waves, solar, motion, and heat. The low-powered loT devices communicate with a user equipment (UE) or a base station when sufficient energy is harvested. Security is important for protecting network connections and data, even for low- or near-zero-powered devices. However, adverse wireless channel conditions may impact the quality of generated keys, leading to mismatches. Existing solutions assume correct key generation without explicit validation, which may lead to security vulnerabilities.

[0004] Therefore, there is a need for wireless communication methods of validating key generation in a communication system and related apparatuses such methods for validating physical layer shared key generation in a communication system, a wireless communication device, an ambient intemet-of-things (AIoT), a user equipment (UE), and a base station.SUMMARY

[0005] An object of the present disclosure is to propose wireless communication methods of validating key generation in a communication system and related apparatuses such methods for validating physical layer shared key generation in a communication system, a wireless communication device, an ambient intemet-of-things (AIoT), a user equipment (UE), and a base station, which can provide security of communication.

[0006] In a first aspect of the present disclosure, a wireless communication method of validating key generation in a communication system, includes generating a shared secret key between a first entity and a second entity, extracting common bits known to the first entity and the second entity to form the shared secret key, and performing a key validation process, wherein the key validation process includes at least one of followings: encrypting a known parameter using the shared secret key with an encryption algorithm and / or an integrity algorithm at the first entity, transmitting at least a portion of an encrypted result to the second entity, decrypting a transmitted portion using the shared secret key at the second entity, determining whether adecrypted result matches the known parameter, and upon successful validation, using the shared secret key for encryption and secure communication.

[0007] In a second aspect of the present disclosure, a wireless communication device includes a generator configured to generate a shared secret key between a first entity and a second entity and an executor configured to extract common bits known to the first entity and the second entity to form the shared secret key, wherein the executor is further configured to perform a key validation process, wherein the key validation process includes at least one of followings: encrypting a known parameter using the shared secret key with an encryption algorithm and / or an integrity algorithm at the first entity, transmitting at least a portion of an encrypted result to the second entity, decrypting a transmitted portion using the shared secret key at the second entity, determining whether a decrypted result matches the known parameter, and upon successful validation, using the shared secret key for encryption and secure communication.

[0008] In a third aspect of the present disclosure, an ambient intemet-of-things (AIoT) device includes a memory, a transceiver, and a processor coupled to the memory and the transceiver. The AIoT device is configured to perform the above method.

[0009] In a fourth aspect of the present disclosure, a user equipment (UE) includes a memory, a transceiver, and a processor coupled to the memory and the transceiver. The UE is configured to perform the above method.

[0010] In a fifth aspect of the present disclosure, a base station includes a memory, a transceiver, and a processor coupled to the memory and the transceiver. The base station is configured to perform the above method.

[0011] In a sixth aspect of the present disclosure, an entity includes a memory, a transceiver, and a processor coupled to the memory and the transceiver. The entity is configured to perform the above method.

[0012] In a seventh aspect of the present disclosure, a non-transitory machine-readable storage medium has stored thereon instructions that, when executed by a computer, cause the computer to perform the above method.

[0013] In an eighth aspect of the present disclosure, a chip includes a processor, configured to call and run a computer program stored in a memory, to cause a device in which the chip is installed to execute the above method.

[0014] In a ninth aspect of the present disclosure, a computer readable storage medium, in which a computer program is stored, causes a computer to execute the above method.

[0015] In a tenth aspect of the present disclosure, a computer program product includes a computer program, and the computer program causes a computer to execute the above method.

[0016] In an eleventh aspect of the present disclosure, a computer program causes a computer to execute the above method.BRIEF DESCRIPTION OF DRAWINGS

[0017] In order to illustrate the embodiments of the present disclosure or related art more clearly, the following figures will be described in the embodiments are briefly introduced. It is obvious that the drawings are merely some embodiments of the present disclosure, a person having ordinary skill in this field can obtain other figures according to these figures without paying the premise.

[0018] FIG. 1 is a block diagram of an example of ambient intemet-of-things (AIoT) communication system.

[0019] FIG. 2 is a block diagram of a user equipment (UE), a base station (BS), and an AIoT device of communication in a communication system according to an embodiment of the present disclosure.

[0020] FIG. 3 is a block diagram of a wireless communication device according to an embodiment of the present disclosure.

[0021] FIG. 4 is a block diagram of a wireless communication device according to an embodiment of the present disclosure.

[0022] FIG. 5 is a flowchart illustrating a wireless communication method of validating key generation according to an embodiment of the present disclosure.

[0023] FIG. 6 is a block diagram of an example of physical layer key generation and validation in an AIoT communication system according to an embodiment of the present disclosure.

[0024] FIG. 7 is a block diagram of an example of key validation using system time as input according to an embodiment of the present disclosure.

[0025] FIG. 8 is a block diagram of an example of a computing device according to an embodiment of the present disclosure.

[0026] FIG. 9 is a block diagram of a communication system according to an embodiment of the present disclosure.DETAILED DESCRIPTION OF EMBODIMENTS

[0027] Embodiments of the present disclosure are described in detail with the technical matters, structural features, achieved objects, and effects with reference to the accompanying drawings as follows. Specifically, the terminologies in the embodiments of the present disclosure are merely for describing the purpose of the certain embodiment, but not to limit the disclosure.

[0028] The technical solutions of the embodiments of the present disclosure can be applied to various communication systems, such as a global system of mobile communication (GSM) system, a code division multiple access (CDMA) system, a wideband code division multiple access (WCDMA) system, a general packet radio service (GPRS), a long term evolution (LTE) system, a LTE frequency division duplex (FDD) system, a LTE time division duplex (TDD) system, an advanced long term evolution (LTE-A) system, a future 5th generation (5G) system (may also be called a new radio (NR) system), an evolution system of a NR system, a LTE-based access to unlicensed spectrum (LTE-U) system, a NR-based access to unlicensed spectrum (NR-U) system, an universal mobile telecommunication system (UMTS), a global interoperability for microwave access (WiMAX) communication system, wireless local area networks (WLAN), wireless fidelity (Wi-Fi), or other communication systems, etc.

[0029] Optionally, a user equipment (UE) mentioned in the embodiments of the present application may refer to an access terminal, a subscriber unit, a subscriber station, a mobile station, a remote station, a remote terminal, a mobile device, a user terminal, a terminal, a wireless communication device, a user agent, or a user device. The access terminal may be a cellular radio telephone, a cordless telephone, a session initiation protocol (SIP) telephone, a wireless local loop (WLL) station, a personal digital assistant (PDA), a handheld device with wireless communication functions, a computing device, other processing devices coupled with a wireless modem,an in-vehicle device, a wearable device, a terminal device in a future 5G network, a terminal device in a future evolved public land mobile network (PLMN), etc.

[0030] Optionally, the communication system in the embodiment of the present application may be applied to an unlicensed spectrum, where the unlicensed spectrum may also be considered as a shared spectrum, or the communication system in the embodiment of the present application may also be applied to a licensed spectrum, where the licensed spectrum can also be considered an unshared spectrum.

[0031] Low-powered intemet-of-things (loT) devices are driving a new set of services to the market. A low- powered loT device, sometimes referred to as an ambient loT (AIoT) or passive loT device, operates without a conventional battery or with limited battery capacity and is powered by energy harvesting. AIoT devices typically harvest energy from wireless radio waves, solar, light, motion / vibration, heat, pressure, or other power sources. As a result, an AIoT device can communicate with a user equipment (UE) (e.g., 5G UE) or a base station (BS) (e.g., 5G BS) once sufficient energy has been harvested.

[0032] Security is important to protect network connections and data, which could be vulnerable to exposure or attacks, even for no-powered devices, low-powered devices, or near-zero-powered devices such as an AIoT.

[0033] FIG. 1 is an example of ambient intemet-of-things (AIoT) communication system. FIG. 1 illustrates that, in some embodiments, in the actual deployment of a zero-power communication system, a cellular and sidelink based zero-power communication system can also be flexibly coexisted or combined, so as to allow more potential application scenarios. The system block diagram of the hybrid of cellular and sidelink based zeropower communication system is as follows. It can include a variety of communication modes, for example, case 1, case 2, case 3, and case 4 as illustrated in FIG. 1.

[0034] Case 1 : Zero-power communication with UE assisted power supply / trigger

[0035] In the case 1, a zero -power terminal is powered and triggered by an intelligent terminal in a network, and a backscatter signal of the zero-power terminal is received by a base station. A power supply and trigger operation of the intelligent terminal can be controlled by the base station through air interface signaling.

[0036] Case 2 : Sidelink based zero-power communication with network power supply / trigger

[0037] In the case 2, a base station provides a wireless power supply and trigger signaling to a zero-power terminal. A backscatter signal of the zero-power terminal is received by an intelligent terminal to complete sidelink communication. Further, the intelligent terminal sends data to the base station.

[0038] Case 3 : Zero-power communication with UE assisted energy supply

[0039] In the case 3, a base station provides wireless a power supply and trigger signaling to a zero-power terminal. A backscatter signal of a zero-power terminal is received by an intelligent terminal to complete sidelink communication. Further, the intelligent terminal sends data to the base station. The intelligent terminal in a network provides auxiliary energy for the zero-power terminal. The base station sends trigger information to the zero-power terminal and receives the backscatter signal of the zero-power terminal. The intelligent terminal provides auxiliary energy supply for zero-power terminal, which can be controlled by the base station through air interface signaling.

[0040] Case 4 : Network controlled sidelink based zero-power communication

[0041] In the case 4, an intelligent terminal receives an air interface signaling and data of a network. The intelligent terminal supplies energy and triggers for a zero-power terminal, receives a backscatter signal of the zero-power terminal, and completes sidelink communication.

[0042] A typical security mechanism for AIoT devices involves generating a shared security key at a physical layer based on wireless channel reciprocity between an AIoT device and a UE (or a base station). This shared key can then be used to enhance security services, such as encryption and integrity protection, for communication between the two entities (e.g., an AIoT device and a UE).

[0043] However, key generation based on wireless channel reciprocity can be affected by adverse wireless channel conditions, potentially leading to discrepancies between the key bits generated at the AIoT device and those at the UE. A key validation process is important to ensure that the generated keys can be reliably used for secure communication, particularly when the keys are not employed as one-time pads (OTP) for data protection.

[0044] Existing solutions rely on various wireless channel reciprocity characteristics to derive shared keys between communicating entities. However, these solutions do not incorporate an explicit key validation process, as they assume that the key generation process is inherently accurate.

[0045] Other key exchange protocols mitigate key synchronization issues by exchanging certain bits (e.g., least significant bits) of the keys or using key identifiers to ensure successful key alignment.

[0046] Despite these approaches, current key validation methods have several drawbacks.

[0047] Lack of key validation during the key generation process: Existing methods do not verily the correctness of the generated keys before they are used for secure communication.

[0048] Security risk from explicit signaling: Sending parts of the key or key identifiers as extra signaling exposes the key material, potentially weakening security.

[0049] Overhead for low-power AIoT devices: Additional signaling increases power consumption, which is particularly problematic for AIoT devices with limited energy resources. This can constrain their ability to perform their primary functions, such as capturing sensor data in AIoT -based sensing applications.

[0050] By addressing these limitations, a more efficient and secure key validation mechanism can be developed, enhancing the robustness of AIoT communications without introducing excessive overhead or security risks.

[0051] Some embodiments of the present disclosure improve on physical layer shared key generation mechanism by adding a key validation process to ensure that the keys generated by both entities are the usable after the keys are generated.

[0052] FIG. 2 illustrates that, in some embodiments, a UE 10, a BS 20, and an AIoT device 30 of communication in a communication system 40. The communication system 40 includes the UE 10, the BS 20, and the AIoT device 30. The UE 10 may include a memory 12, a transceiver 13, and a processor 11 coupled to the memory 12 and the transceiver 13. The BS 20 may include a memory 22, a transceiver 23, and a processor 21 coupled to the memory 22 and the transceiver 23. The AIoT device 30 may include a memory 32, a transceiver 33, and a processor 31 coupled to the memory 32 and the transceiver 33. The processor 11, 21, or 31 may be configured to implement proposed functions, procedures and / or methods described in this description. Layers of radio interface protocol may be implemented in the processor 11, 21, or 31. The memory 12, 22, or 32 isoperatively coupled with the processor 11, 21, or 31 and stores a variety of information to operate the processor 11, 21, or 31. The transceiver 13, 23, or 33 is operatively coupled with the processor 11, 21, or 31, and the transceiver 13, 23, or 33 transmits and / or receives a radio signal.

[0053] The processor 11, 21, or 31 may include application-specific integrated circuit (ASIC), other chipset, logic circuit and / or data processing device. The memory 12, 22, or 32 may include read-only memory (ROM), random access memory (RAM), flash memory, memory card, storage medium and / or other storage device. The transceiver 13, 23, or 33 may include baseband circuitry to process radio frequency signals. When the embodiments are implemented in software, the techniques described herein can be implemented with modules (e.g., procedures, functions, and so on) that perform the functions described herein. The modules can be stored in the memory 12, 22, or 32 and executed by the processor 11, 21, or 31. The memory 12, 22, or 32 can be implemented within the processor 11, 21, or 31 or external to the processor 11, 21, or 31 in which case those can be communicatively coupled to the processor 11, 21, or 31 via various means as is known in the art.

[0054] In some embodiments, the processor 11 , 21 , or 31 is configured to generate a shared secret key between a first entity and a second entity, extract common bits known to the first entity and the second entity to form the shared secret key, and perform a key validation process, wherein the key validation process includes at least one of followings: encrypting a known parameter using the shared secret key with an encryption algorithm and / or an integrity algorithm at the first entity, transmitting at least a portion of an encrypted result to the second entity, decrypting a transmitted portion using the shared secret key at the second entity, determining whether a decrypted result matches the known parameter, and upon successful validation, using the shared secret key for encryption and secure communication. This can solve issues in the prior art and other issues. Further, the proposed some embodiments can provide security of communication between an AIoT device and a UE and / or a BS.

[0055] FIG. 3 illustrates a wireless communication device 300 according to an embodiment of the present disclosure. The wireless communication device 300 may be an AIOT device, a UE, or a BS. The wireless communication device 300 is configured to implement some embodiments of the disclosure. Some embodiments of the disclosure may be implemented into the wireless communication device 300 using any suitably configured hardware and / or software. The wireless communication device 300 includes a generator 301 and an executor 302. The generator 301 is configured to generate a shared secret key between a first entity and a second entity. The executor 302 is configured to extract common bits known to the first entity and the second entity to form the shared secret key. The executor 302 is further configured to perform a key validation process, wherein the key validation process includes at least one of followings: encrypting a known parameter using the shared secret key with an encryption algorithm and / or an integrity algorithm at the first entity, transmitting at least a portion of an encrypted result to the second entity, decrypting a transmitted portion using the shared secret key at the second entity, determining whether a decrypted result matches the known parameter, and upon successful validation, using the shared secret key for encryption and secure communication. This can solve issues in the prior art and other issues. Further, the proposed some embodiments can provide security of communication.

[0056] FIG. 4 illustrates a wireless communication device 400 according to an embodiment of the present disclosure. The wireless communication device 400 may be an AIOT device, a UE, or a BS. The wireless communication device 400 is configured to implement some embodiments of the disclosure. Some embodimentsof the disclosure may be implemented into the wireless communication device 400 using any suitably configured hardware and / or software. The wireless communication device 400 may include a memory 401, a transceiver 402, and a processor 403 coupled to the memory 401 and the transceiver 402. The processor 403 may be configured to implement proposed functions, procedures and / or methods described in this description. Layers of radio interface protocol may be implemented in the processor 403. The memory 401 is operatively coupled with the processor 403 and stores a variety of information to operate the processor 403. The transceiver 402 is operatively coupled with the processor 403, and the transceiver 402 transmits and / or receives a radio signal. The processor 403 may include application-specific integrated circuit (ASIC), other chipset, logic circuit and / or data processing device. The memory 401 may include read-only memory (ROM), random access memory (RAM), flash memory, memory card, storage medium and / or other storage device. The transceiver 402 may include baseband circuitry to process radio frequency signals. When the embodiments are implemented in software, the techniques described herein can be implemented with modules (e.g., procedures, functions, and so on) that perform the functions described herein. The modules can be stored in the memory 401 and executed by the processor 403. The memory 401 can be implemented within the processor 403 or external to the processor 403 in which case those can be communicatively coupled to the processor 403 via various means as is known in the art.

[0057] In some embodiments, the processor 403 is configured to generate a shared secret key between a first entity and a second entity, extract common bits known to the first entity and the second entity to form the shared secret key, and perform a key validation process, wherein the key validation process includes at least one of followings: encrypting a known parameter using the shared secret key with an encryption algorithm and / or an integrity algorithm at the first entity, transmitting at least a portion of an encrypted result to the second entity, decrypting a transmitted portion using the shared secret key at the second entity, determining whether a decrypted result matches the known parameter, and upon successful validation, using the shared secret key for encryption and secure communication. This can solve issues in the prior art and other issues. Further, the proposed some embodiments can provide security of communication.

[0058] FIG. 5 illustrates a wireless communication method 500 of validating key generation according to an embodiment of the present disclosure. The wireless communication method 500 of validating key generation is configured to implement some embodiments of the disclosure. Some embodiments of the disclosure may be implemented into the wireless communication method 500 of validating key generation using any suitably configured hardware and / or software. In some embodiments, the wireless communication method 500 of validating key generation includes: an operation 502, generating a shared secret key between a first entity and a second entity, an operation 504, extracting common bits known to the first entity and the second entity to form the shared secret key, and an operation 506, performing a key validation process, wherein the key validation process includes at least one of followings: encrypting a known parameter using the shared secret key with an encryption algorithm and / or an integrity algorithm at the first entity, transmitting at least a portion of an encrypted result to the second entity, decrypting a transmitted portion using the shared secret key at the second entity, determining whether a decrypted result matches the known parameter, and upon successful validation, using the shared secret key for encryption and secure communication. This can solve issues in the prior art and other issues. Further, the proposed some embodiments can provide security of communication.

[0059] In some embodiments, the shared secret key is a 128-bit or 256-bit key. In some embodiments, the known parameter includes at least one of followings: a system time, a random number, and a quantization parameter used during key generation. In some embodiments, the wireless communication method further includes performing multiple rounds of channel probing, channel measurement, and / or channel tuning between the first entity and the second entity to extract the common bits. In some embodiments, the encryption algorithm used in the key validation process is an advanced encryption standard (AES) algorithm. In some embodiments, the integrity algorithm computes an authentication code, and a portion of the authentication code is transmitted by the first entity to the second entity for verification.

[0060] In some embodiments, transmitting at least the portion of the encrypted result to the second entity includes transmitting a subset of least significant bits (LSB) of the encrypted result. In some embodiments, the key validation process is initiated by the first entity or the second entity. In some embodiments, the first entity is an ambient intemet-of-things (AIoT) device and the second entity is a user equipment (UE) or a base station (BS). In some embodiments, the key validation process is performed before the shared secret key is used for encrypting and transmitting data. In some embodiments, the wireless communication method further includes detecting a mismatch between keys generated by the first entity and the second entity, and in response, initiating a new key generation process.

[0061] FIG. 6 is an example of physical layer key generation and validation in an AIoT communication system according to an embodiment of the present disclosure. FIG. 7 is an example of key validation using system time as input according to an embodiment of the present disclosure. FIG. 6 and FIG. 7 illustrate that, some embodiments enhance a physical layer shared key generation mechanism by introducing a key validation process to ensure that keys generated by both entities are usable after generation. Once keys are generated, the keys can be used as a shared secret key between the two entities (e.g., an AIoT device and a UE or a base station ) as input for an encryption algorithm, such as AES. This encryption process converts the plaintext message into ciphertext, which is then transmitted over the air.

[0062] Using characteristics based on channel reciprocity, the physical layer shared key generation mechanism may involve one or more rounds of channel probing, channel measurements, and channel tuning between the two entities to extract common bits. These extracted bits are known only to the two entities engaged in the key generation process. Various well-known techniques, such as randomization, quantization, and reconciliation, can be employed during this process. Once the two entities have extracted a sufficient number of bits (e.g., 128 or 256 bits) to form a shared secret key, the AIoT device and the UE / Base Station (BS) perform a key validation process.

[0063] The key validation process can be initiated by either entity (e.g., the AIoT device or the UE / BS). There are multiple methods for key validation. The initiating entity uses the freshly generated key (e.g., 128-bit or 256- bit) as input to a known encryption algorithm, such as the Advanced Encryption Standard (AES). The second input to the encryption algorithm can be any parameter known to both entities, such as system time, a random number, or a parameter used in the quantization process during key generation. The resulting encrypted output is then sent to the other entity.

[0064] The receiving entity uses the same known parameter and the generated key to produce an expected result. If the received result matches the expected result, the physical layer key generation and validation process is successfully completed. If not, a key generation request is sent to the other entity to restart the process.

[0065] Alternatively, instead of using encryption for validation, an integrity algorithm can be applied to the freshly generated key and a known input.

[0066] For efficiency, the sender does not need to transmit the entire encrypted result to the receiver for validation. Instead, a subset of bits, such as the least significant 8 or 16 bits, can be sent. Similarly, when using an integrity algorithm, only a portion of the authentication code (e.g., 8 or 16 bits instead of the commonly used 32-bit or 64-bit result) may be transmitted.

[0067] For enhanced security, both encryption and integrity validation can be applied to the same known parameter (e.g., system time).

[0068] FIG. 6 illustrates an example of the physical layer key generation process based on channel reciprocity and the key validation mechanism in an AIoT communication system. FIG. 7 presents an example of a key validation process initiated by the UE / Base Station (BS) using system time as an input in the key validation mechanism. Using a parameter such as system time provides the advantage of fresh input (i.e., a value that changes every time), reducing the likelihood of known plaintext-ciphertext pair attacks used for cryptanalysis to recover the encryption key. Since AIoT devices typically communicate infrequently, slow -changing yet unique parameters, such as system time or a counter, are sufficient for key validation. Once the key validation process is successfully completed, the physical layer-generated key can be used at any time thereafter.

[0069] Key validation in a physical layer shared key generation system enhances the security of communication between an AIoT device and a UE / Base Station in at least one of following ways:

[0070] Ensuring Key Consistency: The key validation mechanism ensures that the generated keys are identical before being used in encryption.

[0071] Error Detection and Prevention: The mechanism also functions as an error detection tool to identify incorrect key generation. In traditional key exchange protocols, encryption keys are derived using a pseudorandom number function with a pre-shared secret as input. Since this computation is deterministic, discrepancies between the generated keys are rare. In contrast, physical layer key generation involves extracting identical bits from wireless channels, where errors are more likely due to various factors. For instance, the quantization process directly affects bit extraction quality. Extracting a larger number of bits in each key generation round (e.g., during channel probing, channel measurements, and channel tuning) can degrade the quality of the extracted bits. Poor bit quality increases the likelihood of discrepancies between the two entities. By detecting invalid keys early, the AIoT communication system can promptly correct errors before faulty keys are used for encryption.

[0072] Optimization of Key Generation Rounds: The key validation process can also help fine-tune the physical layer key generation system, determining the optimal number of rounds required to generate reliable keys.

[0073] Alternatives:

[0074] No Key Validation: One alternative is to forgo key validation altogether. If both entities generate different keys, any encrypted data will be unintelligible to the other entity, ultimately leading to failed communication.

[0075] Explicit Key Confirmation via Additional Signaling: Another alternative is to explicitly confirm key validation through additional message exchanges or signaling. However, this approach introduces extra communication overhead, which may not be ideal for resource-constrained AIoT devices.

[0076] Commercial interests for some embodiments are as follows. 1. Solve issues in the prior art. 2. Solve other issues. 3. Provide security of communication. 4. Provide a good communication performance. 5. Provide high reliability. 6. Some embodiments of the present disclosure are used by chipset vendors, video system development vendors, automakers including cars, trains, trucks, buses, bicycles, moto-bikes, helmets, and etc., drones (unmanned aerial vehicles), smartphone makers, communication devices for public safety use, AR / VR / MR device maker for example gaming, conference / seminar, education purposes. Some embodiments of the present disclosure are a combination of “techniques / processes” that can be adopted in video standards to create an end product. Some embodiments of the present disclosure propose technical mechanisms. The at least one proposed solution, method, system, and apparatus of some embodiments of the present disclosure may be used for current and / or new / future standards regarding communication systems such as an AIoT device, a node (UE / BS), and / or a communication system. Compatible products follow at least one proposed solution, method, system, and apparatus of some embodiments of the present disclosure. The proposed solution, method, system, and apparatus are widely used in an AIoT device, a node (UE / BS), and / or a communication system. With the implementation of the at least one proposed solution, method, system, and apparatus of some embodiments of the present disclosure, at least one modification to communication methods and apparatus are considered for standardizing.

[0077] FIG. 8 is an example of a computing device 1400 according to an embodiment of the present disclosure. Any suitable computing device can be used for performing the operations described herein. For example, FIG. 8 illustrates an example of the computing device 1400 that can implement apparatuses and methods of the above embodiments of FIGs. 1 to 7, using any suitably configured hardware and / or software. In some embodiments, the computing device 1400 can include a processor 1412 that is communicatively coupled to a memory 1414 and that executes computer-executable program code and / or accesses information stored in the memory 1414. The processor 1412 may include a microprocessor, an application-specific integrated circuit (“ASIC”), a state machine, or other processing device. The processor 1412 can include any of a number of processing devices, including one. Such a processor can include or may be in communication with a computer-readable medium storing instructions that, when executed by the processor 1412, cause the processor to perform the operations described herein.

[0078] The memory 1414 can include any suitable non-transitory computer-readable medium. The computer- readable medium can include any electronic, optical, magnetic, or other storage device capable of providing a processor with computer-readable instructions or other program code. Non-limiting examples of a computer- readable medium include a magnetic disk, a memory chip, a read-only memory (ROM), a random accessmemory (RAM), an application specific integrated circuit (ASIC), a configured processor, optical storage, magnetic tape or other magnetic storage, or any other medium from which a computer processor can read instructions. The instructions may include processor-specific instructions generated by a compiler and / or an interpreter from code written in any suitable computer-programming language, including, for example, C, C++, C#, visual basic, java, python, perl, javascript, and actionscript.

[0079] The computing device 1400 can also include a bus 1416. The bus 1416 can communicatively couple one or more components of the computing device 1400. The computing device 1400 can also include a number of external or internal devices such as input or output devices. For example, the computing device 1400 is illustrated with an input / output (“I / O”) interface 1418 that can receive input from one or more input devices 1420 or provide output to one or more output devices 1422. The one or more input devices 1420 and one or more output devices 1422 can be communicatively coupled to the I / O interface 1418. The communicative coupling can be implemented via any suitable manner (e.g., a connection via a printed circuit board, connection via a cable, communication via wireless transmissions, etc.). Non-limiting examples of input devices 1420 include a touch screen (e g., one or more cameras for imaging a touch area or pressure sensors for detecting pressure changes caused by a touch), a mouse, a keyboard, or any other device that can be used to generate input events in response to physical actions by a user of a computing device. Non-limiting examples of output devices 1422 include a liquid crystal display (LCD) screen, an external monitor, a speaker, or any other device that can be used to display or otherwise present outputs generated by a computing device.

[0080] The computing device 1400 can execute program code that configures the processor 1412 to perform one or more of the operations described above with respect to methods of the above embodiments of FIGs. 1 to 7. The program code may be resident in the memory 1414 or any suitable computer-readable medium and may be executed by the processor 1412 or any other suitable processor.

[0081] The computing device 1400 can also include at least one network interface device 1424. The network interface device 1424 can include any device or group of devices suitable for establishing a wired or wireless data connection to one or more data networks 1428. Non limiting examples of the network interface device 1424 include an Ethernet network adapter, a modem, and / or the like. The computing device 1400 can transmit messages as electronic or optical signals via the network interface device 1424.

[0082] FIG. 9 is a block diagram of an example of a communication system 1500 according to an embodiment of the present disclosure. Embodiments described herein may be implemented into the communication system 1500 using any suitably configured hardware and / or software. FIG. 9 illustrates the communication system 1500 including a radio frequency (RF) circuitry 1510, a baseband circuitry 1520, an application circuitry 1530, a memory / storage 1540, a display 1550, a camera 1560, a sensor 1570, and an input / output (I / O) interface 1580, coupled with each other at least as illustrated.

[0083] The application circuitry 1530 may include a circuitry such as, but not limited to, one or more singlecore or multi-core processors. The processors may include any combination of general-purpose processors and dedicated processors, such as graphics processors, application processors. The processors may be coupled with the memory / storage and configured to execute instructions stored in the memory / storage to enable variousapplications and / or operating systems running on the system. The communication system 1500 can execute program code that configures the application circuitry 1530 to perform one or more of the operations described above with respect to methods of the above embodiments of FIGs. 1 to 7. The program code may be resident in the application circuitry 1530 or any suitable computer-readable medium and may be executed by the application circuitry 1530 or any other suitable processor.

[0084] The baseband circuitry 1520 may include circuitry such as, but not limited to, one or more single-core or multi-core processors. The processors may include a baseband processor. The baseband circuitry may handle various radio control functions that may enable communication with one or more radio networks via the RF circuitry. The radio control functions may include, but are not limited to, signal modulation, encoding, decoding, radio frequency shifting, etc. In some embodiments, the baseband circuitry may provide for communication compatible with one or more radio technologies. For example, in some embodiments, the baseband circuitry may support communication with an evolved universal terrestrial radio access network (EUTRAN) and / or other wireless metropolitan area networks (WMAN), a wireless local area network (WLAN), a wireless personal area network (WPAN). Embodiments in which the baseband circuitry is configured to support radio communications of more than one wireless protocol may be referred to as multi-mode baseband circuitry.

[0085] In various embodiments, the baseband circuitry 1520 may include circuitry to operate with signals that are not strictly considered as being in a baseband frequency. For example, in some embodiments, baseband circuitry may include circuitry to operate with signals having an intermediate frequency, which is between a baseband frequency and a radio frequency. The RF circuitry 1510 may enable communication with wireless networks using modulated electromagnetic radiation through a non-solid medium. In various embodiments, the RF circuitry may include switches, filters, amplifiers, etc. to facilitate the communication with the wireless network. In various embodiments, the RF circuitry 1510 may include circuitry to operate with signals that are not strictly considered as being in a radio frequency. For example, in some embodiments, RF circuitry may include circuitry to operate with signals having an intermediate frequency, which is between a baseband frequency and a radio frequency.

[0086] In various embodiments, the transmitter circuitry, control circuitry, or receiver circuitry discussed above with respect to apparatuses and methods of the above embodiments of FIGs. 1 to 7 may be embodied in whole or in part in one or more of the RF circuitry, the baseband circuitry, and / or the application circuitry. As used herein, “circuitry” may refer to, be part of, or include an application specific integrated circuit (ASIC), an electronic circuit, a processor (shared, dedicated, or group), and / or a memory (shared, dedicated, or group) that execute one or more software or firmware programs, a combinational logic circuit, and / or other suitable hardware components that provide the described functionality. In some embodiments, the electronic device circuitry may be implemented in, or functions associated with the circuitry may be implemented by, one or more software or firmware modules. In some embodiments, some or all of the constituent components of the baseband circuitry, the application circuitry, and / or the memory / storage may be implemented together on a system on a chip (SOC). The memory / storage 1540 may be used to load and store data and / or instructions, for example, forsystem. The memory / storage for one embodiment may include any combination of suitable volatile memory, such as dynamic random access memory (DRAM)), and / or non-volatile memory, such as flash memory.

[0087] In various embodiments, the I / O interface 1580 may include one or more user interfaces designed to enable user interaction with the system and / or peripheral component interfaces designed to enable peripheral component interaction with the system. User interfaces may include, but are not limited to a physical keyboard or keypad, a touchpad, a speaker, a microphone, etc. Peripheral component interfaces may include, but are not limited to, a non-volatile memory port, a universal serial bus (USB) port, an audio jack, and a power supply interface. In various embodiments, the sensor 1570 may include one or more sensing devices to determine environmental conditions and / or location information related to the system. In some embodiments, the sensors may include, but are not limited to, a gyro sensor, an accelerometer, a proximity sensor, an ambient light sensor, and a positioning unit. The positioning unit may also be part of, or interact with, the baseband circuitry and / or RF circuitry to communicate with components of a positioning network, e.g., a global positioning system (GPS) satellite.

[0088] In various embodiments, the display 1550 may include a display, such as a liquid crystal display and a touch screen display. In various embodiments, the communication system 1500 may be a mobile computing device such as, but not limited to, a laptop computing device, a tablet computing device, a netbook, an ultrabook, a smartphone, an AR / VR glasses, etc. In various embodiments, system may have more or less components, and / or different architectures. Where appropriate, methods described herein may be implemented as a computer program. The computer program may be stored on a storage medium, such as a non-transitory storage medium.

[0089] A person having ordinary skill in the art understands that each of the units, algorithm, and steps described and disclosed in the embodiments of the present disclosure are realized using electronic hardware or combinations of software for computers and electronic hardware. Whether the functions run in hardware or software depends on the condition of application and design requirement for a technical plan. A person having ordinary skill in the art can use different ways to realize the function for each specific application while such realizations should not go beyond the scope of the present disclosure. It is understood by a person having ordinary skill in the art that he / she can refer to the working processes of the system, device, and unit in the above-mentioned embodiment since the working processes of the above-mentioned system, device, and unit are basically the same. For easy description and simplicity, these working processes will not be detailed.

[0090] It is understood that the disclosed system, device, and method in the embodiments of the present disclosure can be realized with other ways. The above-mentioned embodiments are exemplary only. The division of the units is merely based on logical functions while other divisions exist in realization. It is possible that a plurality of units or components are combined or integrated in another system. It is also possible that some characteristics are omitted or skipped. On the other hand, the displayed or discussed mutual coupling, direct coupling, or communicative coupling operate through some ports, devices, or units whether indirectly or communicatively by ways of electrical, mechanical, or other kinds of forms.

[0091] The units as separating components for explanation are or are not physically separated. The units for display are or are not physical units, that is, located in one place or distributed on a plurality of network units.Some or all of the units are used according to the purposes of the embodiments. Moreover, each of the functional units in each of the embodiments can be integrated in one processing unit, physically independent, or integrated in one processing unit with two or more than two units.

[0092] If the software function unit is realized and used and sold as a product, it can be stored in a readable storage medium in a computer. Based on this understanding, the technical plan proposed by the present disclosure can be essentially or partially realized as the form of a software product. Or, one part of the technical plan beneficial to the conventional technology can be realized as the form of a software product. The software product in the computer is stored in a storage medium, including a plurality of commands for a computational device (such as a personal computer, a server, or a network device) to run all or some of the steps disclosed by the embodiments of the present disclosure. The storage medium includes a USB disk, a mobile hard disk, a readonly memory (ROM), a random access memory (RAM), a floppy disk, or other kinds of media capable of storing program codes.

[0093] While the present disclosure has been described in connection with what is considered the most practical and preferred embodiments, it is understood that the present disclosure is not limited to the disclosed embodiments but is intended to cover various arrangements made without departing from the scope of the broadest interpretation of the appended claims.

Claims

What is claimed is:

1. A wireless communication method of validating key generation in a communication system, comprising: generating a shared secret key between a first entity and a second entity; extracting common bits known to the first entity and the second entity to form the shared secret key; and performing a key validation process, wherein the key validation process comprises at least one of followings: encrypting a known parameter using the shared secret key with an encryption algorithm and / or an integrity algorithm at the first entity; transmitting at least a portion of an encrypted result to the second entity; decrypting a transmitted portion using the shared secret key at the second entity; determining whether a decrypted result matches the known parameter; and upon successful validation, using the shared secret key for encryption and secure communication.

2. The wireless communication method of claim 1, wherein the shared secret key is a 128-bit or 256-bit key.

3. The wireless communication method of claim 1 or 2, wherein the known parameter comprises at least one of followings: a system time, a random number, and a quantization parameter used during key generation.

4. The wireless communication method of any one of claims 1 to 3, further comprising performing multiple rounds of channel probing, channel measurement, and / or channel tuning between the first entity and the second entity to extract the common bits.

5. The wireless communication method of any one of claims 1 to 4, wherein the encryption algorithm used in the key validation process is an advanced encryption standard (AES) algorithm.

6. The wireless communication method of any one of claims 1 to 5, wherein the integrity algorithm computes an authentication code, and a portion of the authentication code is transmitted by the first entity to the second entity for verification.

7. The wireless communication method of any one of claims 1 to 6, wherein transmitting at least the portion of the encrypted result to the second entity comprises: transmitting a subset of least significant bits (LSB) of the encrypted result.

8. The wireless communication method of any one of claims 1 to 7, wherein the key validation process is initiated by the first entity or the second entity.

9. The wireless communication method of any one of claims 1 to 8, wherein the first entity is an ambient intemet- of-things (AIoT) device and the second entity is a user equipment (UE) or a base station (BS).

10. The wireless communication method of any one of claims 1 to 9, wherein the key validation process is performed before the shared secret key is used for encrypting and transmitting data.

11. The wireless communication method of any one of claims 1 to 10, further comprising detecting a mismatch between keys generated by the first entity and the second entity, and in response, initiating a new key generation process.

12. A wireless communication device, comprising:a generator configured to generate a shared secret key between a first entity and a second entity; and an executor configured to extract common bits known to the first entity and the second entity to form the shared secret key, wherein the executor is further configured to perform a key validation process, wherein the key validation process comprises at least one of followings: encrypting a known parameter using the shared secret key with an encryption algorithm and / or an integrity algorithm at the first entity; transmitting at least a portion of an encrypted result to the second entity; decrypting a transmitted portion using the shared secret key at the second entity; determining whether a decrypted result matches the known parameter; and upon successful validation, using the shared secret key for encryption and secure communication.

13. The wireless communication device of claim 12, wherein the shared secret key is a 128-bit or 256-bit key.

14. The wireless communication device of claim 12 or 13, wherein the known parameter comprises at least one of followings: a system time, a random number, and a quantization parameter used during key generation.

15. The wireless communication device of any one of claims 12 to 14, wherein the executor is further configured to perform multiple rounds of channel probing, channel measurement, and / or channel tuning between the first entity and the second entity to extract the common bits.

16. The wireless communication device of any one of claims 12 to 15, wherein the encryption algorithm used in the key validation process is an advanced encryption standard (AES) algorithm.

17. The wireless communication device of any one of claims 12 to 16, wherein the integrity algorithm computes an authentication code, and a portion of the authentication code is transmitted by the first entity to the second entity for verification.

18. The wireless communication device of any one of claims 12 to 17, wherein transmitting at least the portion of the encrypted result to the second entity comprises: transmitting a subset of least significant bits (LSB) of the encrypted result.

19. The wireless communication device of any one of claims 12 to 18, wherein the key validation process is initiated by the first entity or the second entity.

20. The wireless communication device of any one of claims 12 to 19, wherein the first entity is an ambient intemet-of-things (AIoT) device and the second entity is a user equipment (UE) or a base station (BS).

21. The wireless communication device of any one of claims 12 to 20, wherein the key validation process is performed before the shared secret key is used for encrypting and transmitting data.

22. The wireless communication device of any one of claims 12 to 21, wherein the executor is further configured to detect a mismatch between keys generated by the first entity and the second entity, and in response, the executor is further configured to initiate a new key generation process.

23. An ambient intemet-of-things (AIoT) device, comprising: a memory; a transceiver; anda processor coupled to the memory and the transceiver; wherein the AIoT device is configured to perform the wireless communication method of any one of claims 1 to 11.

24. A user equipment (UE), comprising: a memory; a transceiver; and a processor coupled to the memory and the transceiver; wherein the UE is configured to perform the wireless communication method of any one of claims 1 to 11.

25. Abase station, comprising: a memory; a transceiver; and a processor coupled to the memory and the transceiver; wherein the base station is configured to perform the wireless communication method of any one of claims 1 to 11.

Citation Information

Patent Citations

  • Method and system for shared key and message authentication over an insecure shared communication medium

    US20170019251A1

  • System and method for pre-enrollment and network pre-configuration of internet of things (IOT) devices

    US20210377112A1