Communication method and apparatus
By adjusting the key verification and generation parameters, the key generation process was optimized, resolving the issue of inconsistent key consistency verification and improving key generation performance and system security.
Patent Information
- Application Number
- PCT/CN2025/104212
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-07-19
- Filing Date
- 2025-06-27
- Publication Date
- 2026-01-22
AI Technical Summary
In the key generation process, existing technologies suffer from inconsistencies in key consistency verification, which leads to a decline in overall key generation performance. Existing methods, such as increasing the power of the reference signal or increasing the number of retransmissions, may introduce noise and system complexity, and cannot effectively improve consistency.
By adjusting the parameters of key verification and generation, such as reducing the key verification length, increasing the quantization threshold, or reducing the number of quantization bits, the key generation process can be optimized to improve the pass rate and generation speed of key consistency verification and reduce network transmission overhead.
It improves key generation performance, enhances the success rate and generation speed of key consistency verification, simplifies the communication system architecture, and improves security and trustworthiness.
Smart Images

Figure CN2025104212_22012026_PF_FP_ABST
Abstract
Description
Communication methods and devices
[0001] This application claims priority to Chinese Patent Application No. 202410981891.7, filed with the State Intellectual Property Office of China on July 19, 2024, entitled "Communication Method and Apparatus", the entire contents of which are incorporated herein by reference. Technical Field
[0002] This application relates to the field of communications, and more particularly to communication methods and apparatus. Background Technology
[0003] In classic physical layer key generation techniques based on channel entropy, the reciprocity of the channel allows legitimate communicating parties to generate a consistent key through their respective channel measurements and randomness extraction processes without exchanging key information. This consistency is one of the core requirements of key generation technology. During key generation, the communicating parties independently generate keys through steps such as channel measurement, randomness extraction, channel quantization, information harmonicization, and privacy amplification. To ensure the consistency of the keys between the communicating parties, a key verification process is required. However, directly exchanging keys to verify consistency poses security risks. Therefore, a non-direct verification is typically performed using hash check bits (i.e., a one-way mapping of the key). If the hash check bits match, the keys are confirmed to be consistent; otherwise, inconsistency exists, and the current key must be discarded.
[0004] To address inconsistencies in key verification, existing techniques attempt to improve channel estimation accuracy by increasing the transmission power of the reference signal or increasing the number of retransmissions, thereby enhancing key consistency. However, this approach overlooks the multiple complex factors affecting key consistency, potentially leading to a decrease in overall key generation performance instead of an improvement. Summary of the Invention
[0005] This application provides a communication method and apparatus for improving key generation performance.
[0006] Firstly, a communication method is provided, applied to a key verification device. The executing entity of this method can be a key verification device, a component or device (e.g., a processor, chip, or chip system) applied to the key verification device, a logic module or software capable of implementing all or part of the functions of the key verification device, or a device compatible with the key verification device. The communication method includes: acquiring first verification information of a first key and second verification information of a second key, the first and second verification information being used to determine the consistency between the first and second keys; and based on the first and second verification information, sending first information indicating the adjustment of parameters for a verification key and / or parameters for a generated key. Optionally, the parameters for the verification key include a key verification length; the parameters for the generated key include a quantization threshold for generating the key and / or the number of quantization bits for generating the key.
[0007] In the first aspect, by combining the consistency of the first verification information and the second verification information, the key generation performance is improved by adjusting the parameters of the verification key and / or the parameters of the generated verification key.
[0008] In conjunction with the first aspect, in one design, the first information is used to indicate at least one of the following: reducing the key verification length, increasing the quantization threshold used to generate the key, or reducing the number of quantization bits used to generate the key. For example, the first information is sent when the first verification information and the second verification information are inconsistent. Alternatively, the first information is used to indicate at least one of the following: increasing the key verification length, decreasing the quantization threshold used to generate the key, or increasing the number of quantization bits used to generate the key. For example, the first information is sent when the ratio of consistency verification information in the first verification information set and the second verification information set meets a preset condition. The first verification information set includes the first verification information and at least one acquired third verification information, and the second verification information set includes the second verification information and at least one acquired fourth verification information, wherein the third and fourth verification information are used to determine the consistency between the first key and the second key.
[0009] This design aims to improve key generation performance by modifying the parameters of either the verification key or the generation key. In one scenario, if the key verification information from both parties is inconsistent, the consistency rate can be improved by reducing the key length (key verification length), increasing the quantization threshold used for key generation, or reducing the number of quantization bits used in key generation. In another scenario, if the consistency rate of the key verification information from both parties is high, the network transmission overhead can be reduced by increasing the key length (key verification length), decreasing the quantization threshold used for key generation, or increasing the number of quantization bits used in key generation, thereby comprehensively improving key generation performance.
[0010] In conjunction with the first aspect, in one design, the method may further include: determining an adjustment margin for parameters based on the difference between the parameters of the first key and the corresponding preset parameter values, wherein the parameters include at least one of the following: parameters of the verification key or parameters of the generation key; as an alternative implementation, the adjustment margin for the above parameters may also be determined based on the difference between the parameters of the second key and the corresponding preset parameter values. The first information is determined based on the first verification information, the second verification information, and the adjustment margin for the parameters.
[0011] In this design, the adjustment margin of each parameter is first determined based on the difference between the parameters of the first key (or the second key) and the corresponding preset parameter values. Based on the adjustment margin of each parameter, it can be determined which parameters can be adjusted. Then, by combining the adjustment margin of each parameter, the first verification information, and the second verification information, the first information indicating the adjusted parameters can be determined. When the first information indicates that the key verification length is reduced, the pass rate of key consistency verification can be improved. When the first information indicates that the quantization threshold used to generate the key is reduced and / or the number of quantization bits used to generate the key is increased, the key generation rate can be improved. And when the first information indicates that the key verification length is increased, the air interface overhead of key consistency verification can be reduced, thereby comprehensively improving the key generation performance.
[0012] In conjunction with the first aspect, in one design, the first information includes at least one of the following: an adjusted value for the parameters of the verification key, or an adjusted value for the parameters of the generation key; or, the first information includes at least one of the following: the adjusted value for the parameters of the verification key, or the adjusted value for the parameters of the generation key.
[0013] In this design, the content of the first information is highly flexible, and it can cover at least one of the following aspects: adjusted values of the verification key parameters and adjusted values of the generation key parameters. Furthermore, to further improve the efficiency and diversity of information expression, the first information is also designed to include the specific values of the adjusted verification key parameters and the specific values of the adjusted generation key parameters. These design options provide a rich selection space for practical applications. For the design where the first information is set as the adjusted parameter values, the data volume of the first information is smaller, and the network bandwidth required for transmitting the first information is less. For the design where the first information is set as the specific adjusted parameter values, it ensures that the first information carries highly accurate parameters, avoids errors arising from calculating the adjusted specific values based on the adjusted values, and eliminates the need for additional calculations, thus simplifying the processing flow.
[0014] In conjunction with the first aspect, in one design, the method is applied to a first communication device; obtaining first verification information of a first key and second verification information of a second key includes: the first communication device obtaining the first verification information of the first key and the second verification information of the second key, wherein the first communication device is a communication device that generates the first key and the communication device that generates the second key is a second communication device; sending first information based on the first verification information and the second verification information includes: the first communication device sending the first information to the second communication device based on the first verification information and the second verification information.
[0015] In this design, the role of the key verification device is directly assumed by either party participating in the key negotiation. In this case, the device generating the first key is called the first communication device, and the device generating the second key is also called the first communication device. In this scenario, the first communication device simultaneously acts as the key verification device, reducing the need for additional devices and thus simplifying the overall architecture of the communication system. Furthermore, since the verification process is built into the key negotiation process and executed by the direct participants in the key negotiation, the security of the key negotiation process is enhanced. Neither party can unilaterally change the key without the other party's detection.
[0016] In conjunction with the first aspect, in one design, the method is applied to a third communication device; obtaining first verification information of a first key and second verification information of a second key includes: the third communication device obtaining the first verification information of the first key and the second verification information of the second key; sending first information based on the first verification information and the second verification information includes: the third communication device sending first information to a first communication device and a second communication device based on the first verification information and the second verification information, wherein the first communication device is a device for generating the first key and the second communication device is a device for generating the second key.
[0017] In this design, the role of key verification is undertaken by a third-party device independent of the negotiating parties. This device, referred to as the third communication device, significantly enhances the trustworthiness of the key negotiation process. This is because the third communication device is typically designed to be neutral and trustworthy, providing impartial verification services to ensure the authenticity and validity of the keys negotiated between the two parties.
[0018] Secondly, a communication method is provided, which is applied to a key negotiation device. The executing entity of this method can be a key negotiation device, a component or device (e.g., a processor, chip, or chip system) applied to the key negotiation device, a logic module or software capable of implementing all or part of the functions of the key negotiation device, or a device used in conjunction with a key verification device. The communication method includes: sending second verification information of the second key for verifying the consistency between the second key and the first key; and receiving first information for instructing the adjustment of parameters of the verification key and / or parameters of the generated key, wherein the first information is determined based on the second verification information and the first verification information of the first key. Optionally, the parameters of the verification key include a key verification length. Optionally, the parameters of the generated key include a quantization threshold for generating the key and / or the number of quantization bits for generating the key.
[0019] In the second aspect, the key negotiation device receives first information for instructing the adjustment of parameters of the verification key and / or parameters of the generation key, and can then adjust the parameters of the verification key and / or the parameters of the generation key accordingly based on the first information to improve the key generation performance.
[0020] In conjunction with the second aspect, in one design, the method further includes: generating a new key based on the first information.
[0021] In this design, a new key is generated based on the first information. Since the first information is determined based on the first verification information and the second verification information, it indicates the information for adjusting the parameters of the verification key and / or generating the parameters of the verification key, thereby optimizing the key generation performance.
[0022] In conjunction with the second aspect, in one design, the first information includes at least one of the following: an adjusted value for the parameters of the verification key, or an adjusted value for the parameters of the generation key; or, the first information includes at least one of the following: the adjusted value for the parameters of the verification key, or the adjusted value for the parameters of the generation key.
[0023] The design of the first message is highly flexible, and it can cover at least one of the following aspects: adjusted values for the verification key parameters and adjusted values for the generation key parameters. Furthermore, to further improve the efficiency and diversity of information expression, the first message is also designed to include the specific values of the adjusted verification key parameters and the specific values of the adjusted generation key parameters. These design options provide ample choice for practical applications.
[0024] In conjunction with the second aspect, in one design, the first information is used to indicate at least one of the following: increasing the key verification length, decreasing the quantization threshold used to generate the key, or increasing the number of quantization bits used to generate the key; or, the first information is used to indicate at least one of the following: decreasing the key verification length, increasing the quantization threshold used to generate the key, or decreasing the number of quantization bits used to generate the key.
[0025] This design flexibly sets the content of the first information instruction. Through this instruction, corresponding parameters can be adjusted flexibly during key generation, thereby improving key generation performance. Increasing the key verification length effectively reduces the frequency of key consistency checks, reducing air interface resource consumption and overhead. Reducing the quantization threshold used for key generation improves key generation efficiency. Increasing the number of quantization bits used for key generation increases the key generation rate. Reducing the key verification length improves the success rate of key consistency checks. Increasing the quantization threshold used for key generation helps improve the key consistency rate, thus increasing the success rate of key consistency checks. Reducing the number of quantization bits used for key generation improves the key consistency rate, thus increasing the success rate of key consistency checks.
[0026] Thirdly, a communication device is provided for implementing the method described in any of the first or second aspects. For example, the communication device can be a key verification device as described in the first aspect; or, the communication device can be a key negotiation device as described in the second aspect. When the device is a chip system, it can be composed of chips or can include chips and other discrete components.
[0027] The communication device includes modules, units, or means corresponding to the implementation method. These modules, units, or means can be implemented in hardware, software, or by hardware executing corresponding software. The hardware or software includes one or more modules or units corresponding to the functions.
[0028] In some possible designs, the communication device may include a processing module and a transceiver module. The processing module can be used to implement the processing functions in any of the above aspects and any possible implementations. The transceiver module, also called a transceiver unit, is used to implement the sending and / or receiving functions in any of the above aspects and any possible implementations. The transceiver module may consist of transceiver circuitry, a transceiver, a transceiver unit, or a communication interface.
[0029] In some possible designs, the transceiver module includes a sending module and / or a receiving module, which are used to implement the sending or receiving functions in any of the above aspects and any possible implementations.
[0030] Fourthly, a communication device is provided, comprising: a processor and a communication interface; the communication interface being used to communicate with a module outside the communication device; the processor being used to execute computer programs or instructions to cause the communication device to perform the methods described in any of the aspects. For example, the communication device may be a key verification device as in the first aspect; or, the communication device may be a key negotiation device as in the second aspect. When the device is a chip system, it may be composed of chips or may include chips and other discrete devices.
[0031] Fifthly, a communication device is provided, comprising: at least one processor; the processor being configured to execute a computer program or instructions stored in a memory to cause the communication device to perform the methods described in any of the aspects. The memory may be integrated with the processor, or it may exist independently of the processor; for example, the memory and the processor may be two separate modules. The memory may be located outside or within the communication device.
[0032] This communication device is used to implement the method described in any of the first or second aspects. For example, the communication device can be a key verification device as described in the first aspect; or, the communication device can be a key negotiation device as described in the second aspect. When the device is a chip system, it can be composed of chips or can include chips and other discrete components.
[0033] In a sixth aspect, a computer-readable storage medium is provided that stores a computer program or instructions that, when executed on a communication device, enable the communication device to perform the methods described in either aspect.
[0034] In a seventh aspect, a computer program product containing instructions is provided, which, when run on a communication device, enables the communication device to perform the method described in either aspect.
[0035] Eighthly, a communication device is provided, configured to cause the communication device to perform the method described in any one of the aspects.
[0036] It is understandable that when the communication device provided by any of the third to fifth aspects is a chip, the sending action / function of the communication device can be understood as outputting information, and the receiving action / function of the communication device can be understood as inputting information.
[0037] The technical effects of any of the design methods in aspects three through eight can be found in the technical effects of different design methods in aspects one and two, and will not be repeated here.
[0038] Ninthly, a communication system is provided, which includes the key verification device and key negotiation device described in the preceding aspects. Attached Figure Description
[0039] Figure 1 is a schematic diagram of a key generation process provided in an embodiment of this application;
[0040] Figure 2 is a schematic diagram of a key consistency verification process provided in an embodiment of this application;
[0041] Figure 3 is a schematic diagram of a communication system provided in an embodiment of this application;
[0042] Figure 4 is a flowchart illustrating a communication method provided in an embodiment of this application;
[0043] Figure 5 is a flowchart illustrating another communication method provided in an embodiment of this application;
[0044] Figure 6 is a flowchart illustrating another communication method provided in an embodiment of this application;
[0045] Figure 7 is a flowchart illustrating another communication method provided in an embodiment of this application;
[0046] Figure 8 is a flowchart illustrating another communication method provided in an embodiment of this application;
[0047] Figure 9 is a flowchart illustrating another communication method provided in an embodiment of this application;
[0048] Figure 10 is a flowchart illustrating another communication method provided in an embodiment of this application;
[0049] Figure 11 is a schematic diagram of the structure of a communication device provided in an embodiment of this application;
[0050] Figure 12 is a schematic diagram of another communication device provided in an embodiment of this application;
[0051] Figure 13 is a schematic diagram of another communication device provided in an embodiment of this application. Detailed Implementation
[0052] The network architecture and business scenarios described in the embodiments of this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided in the embodiments of this application. As those skilled in the art will know, with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.
[0053] Before introducing the embodiments of this application, some terms involved in the embodiments of this application will be explained.
[0054] 1. Key:
[0055] A key is a secret parameter used in encryption and decryption processes to control these processes and ensure information security. In physical layer key generation technology, keys are typically dynamically generated based on specific properties of the wireless channel (such as phase and amplitude), exhibiting uniqueness, unpredictability, and randomness.
[0056] 2. Key Verification Length (KVL):
[0057] Key verification length refers to the length of the portion of the key used during key generation to verify the consistency of the keys generated by both parties. This portion of the key is used by both parties after generation for comparison to confirm that their generated keys are identical. The choice of key verification length affects the efficiency and security of the key generation process. The relationship between the key and key verification length: the key is the whole, while the key verification length is a specific part of the key used to verify its consistency. The choice of key verification length can be determined based on specific application scenarios and security requirements to ensure that the key generation process is both efficient and secure.
[0058] 3. Key verification bit (KVB):
[0059] Key check bits are the specific bits used in the key verification process to actually compare and confirm key consistency. These bits are extracted from the key portion specified by the key verification length and are used to perform the specific verification operation. The consistency of the key check bits directly reflects the performance and reliability of the key generation technology. The relationship between key verification length and key check bits: the key verification length determines how many bits will be used for key verification, while the key check bits are the specific values of these bits. Therefore, changes in the key verification length directly affect the number and consistency of key check bits.
[0060] 4. Key consistency rate:
[0061] Key consistency rate refers to the probability that both parties successfully generate and agree on a key during key negotiation. For example, a 90% key consistency rate means that, in each key generation, for every 100 bits of the key, the negotiating parties will have an average of 10 bits of inconsistent key content, while the remaining 90 bits will be consistent. Given a fixed key consistency rate, the fewer the number of check bits used in a single verification, the higher the probability of successful verification. In this scenario, if 100 check bits are used to verify the integrity of every 100 bits of the key, the verification process will likely fail due to the 10 inconsistent bits, indicating a high probability of key inconsistency. However, if 20 check bits are used to verify the integrity of every 100 bits, the verification process will have a high probability of determining key consistency, leading to successful verification.
[0062] The classic physical layer key generation process based on channel entropy, as shown in Figure 1, is a key negotiation method. It relies on precise measurements of the physical communication channel by both parties and utilizes the physical property of channel reciprocity, enabling each party to independently generate a highly consistent key without directly exchanging key information. This process mainly includes the following steps:
[0063] S11. Channel Measurement: First, both communicating parties perform detailed measurements of the physical channel between them. These measurements may include various parameters such as signal amplitude, phase, frequency offset, and delay, aiming to capture the inherent randomness and uniqueness of the channel. The accuracy and comprehensiveness of the channel measurements are crucial for the quality and security of subsequent key generation.
[0064] S12. Randomness Extraction: Extracting random elements from channel measurement data. Since channel characteristics typically contain a large amount of random noise and interference, these elements can be considered natural sources of randomness. Through complex algorithmic processing, sufficiently long, statistically independent random sequences can be extracted from the measurement data as the raw material for the key.
[0065] S13. Channel Quantization: Channel quantization converts continuous channel measurement data into discrete key bits. This step introduces the concepts of quantization threshold and the number of quantization bits. The quantization threshold defines the boundary for dividing the range of measurement data values, while the number of quantization bits determines how many intervals (i.e., how many possible key bit values) the data is divided into, with each interval corresponding to one key bit value. The fineness of the quantization (determined by the number of quantization bits) directly affects the key generation rate and quality. Excessively coarse quantization (i.e., too few quantization bits) leads to increased correlation between key bits, thus reducing key security. When the number of quantization bits is sufficient, continuous channel measurement data can be divided into multiple intervals more finely, with each interval corresponding to one key bit value. This means that within the same measurement data range, more key bits can be generated, thereby increasing the key generation rate and reducing the correlation between key bits, thus improving key security.
[0066] For example, in dual-threshold quantization, a threshold value of ±0.25 is set. Coefficients with absolute values greater than this threshold are then quantized. The quantization process converts these real-valued coefficients into multi-bit representations (called key bits). For instance, in one-bit quantization (using 1 bit), the coefficient 0.5 (greater than 0.25) is quantized as bit 1, while -0.5 (less than -0.25) is quantized as bit 0. In this case, the key bits are either 1 or 0. Further, in two-bit quantization (using 2 bits), with 1 as the extreme value range, the intervals [-1, -0.25] and [0.25, 1] are each divided into four equal parts. Each part's coefficients correspond to a two-bit code (e.g., 00, 01, 10, 11; the specific encoding method may vary depending on the system design and is not limited). In this case, the key bits are 00, 01, 10, or 11. Similarly, three-bit quantization divides the entire range into eight more detailed parts, in which case the key bits are three bits, allowing for more possibilities.
[0067] As can be seen from the examples above, the choice of quantization threshold directly affects the number of quantized coefficients. A smaller threshold results in more coefficients exceeding it, potentially generating more key bits. Simultaneously, a higher number of quantization bits theoretically allows for more possible intervals, again potentially generating more key bits. The number of key bits determines the key's ability to accurately represent or distinguish different information or states. More key bits mean the key can represent more states or information, resulting in higher precision. However, this also means more data needs to be processed during encryption and decryption, which may reduce encryption speed.
[0068] S14. Information Reconciliation: Since the communicating parties perform channel measurements and key generation independently, there may be some differences between the key sequences they generate. The information reconciliation step aims to enable the two parties to reach an agreement on the inconsistent parts of the key sequences through a negotiation process. This is usually achieved by exchanging a small amount of auxiliary information, but care must be taken to protect this information from being intercepted by malicious third parties.
[0069] S15. Privacy Amplification: Privacy amplification is a security enhancement step in the physical layer key generation process. It uses a mathematical transformation (such as a hash function) to expand the agreed-upon key sequence into a longer, statistically more unpredictable key. The purpose of privacy amplification is to reduce any residual correlations or weaknesses that may exist in the key, thereby further improving key security.
[0070] In summary, the classic physical layer key generation technique based on channel entropy, through a series of carefully designed steps, enables key negotiation and generation between communicating parties without exchanging key information. This technique not only improves the security and efficiency of key generation but also provides new ideas and methods for secure communication in wireless communication networks.
[0071] After physical layer key generation based on channel entropy, key consistency verification is a crucial step to ensure the secure and reliable use of keys. This verification confirms the consistency of keys between the two parties through indirect methods (such as exchanging hash check bits of the keys), preventing man-in-the-middle attacks and ensuring key integrity and system robustness.
[0072] The key consistency verification process is described below. Figure 2 illustrates one such process, which includes:
[0073] S21. Key generation:
[0074] This is the starting point of the entire encryption process. During the key generation phase, both communicating parties (usually the sender and receiver) each generate a key according to a certain algorithm or protocol. These keys can be symmetric (i.e., both parties use the same key) or asymmetric (both parties use a pair of public and private keys). The specific process can be referred to the description of the embodiment shown in Figure 1 above, and will not be repeated here.
[0075] S22. Calculate the key verification bits:
[0076] After the key is generated, both parties use their respective keys or a portion of the key pair (such as the public key or private key) to calculate some key check bits (or checksums, digests, etc.) using a hash function or other algorithm. These key check bits are a unique representation of the key or a portion of the key and are used for subsequent consistency verification.
[0077] S23, Exchange key verification bits:
[0078] Both parties exchange these key verification bits to verify key consistency. This can be done through a secure communication channel to ensure that the key verification bits are not tampered with or leaked during transmission.
[0079] S24. Key consistency verification:
[0080] After receiving the key check bits from the sender, the receiver recalculates the key check bits using its own generated key (or the corresponding part of the key pair) and the same algorithm. Then, it compares the recalculated key check bits with the received key check bits.
[0081] If the two keys match, it means that the keys generated by both parties are consistent, and subsequent encrypted communication can continue.
[0082] If the two keys do not match, it indicates a problem occurred during key generation or transmission, such as tampering or other errors. In this case, both parties should discard the current key and re-execute the key generation and consistency verification process until successful verification.
[0083] S25. Retain or discard the key:
[0084] If the keys match, based on the result of the key consistency check, the key is retained for subsequent encrypted communication.
[0085] If the keys do not match, discard the key and restart the key generation and consistency verification process.
[0086] In summary, key consistency verification is a crucial step in encryption algorithms to ensure key security. Through this step, both communicating parties can ensure that they are using the same key, thereby guaranteeing the confidentiality and integrity of encrypted communication.
[0087] To ensure successful encrypted communication and secure data transmission, improving key consistency is crucial. One possible approach is to enhance channel estimation accuracy by increasing the transmission power of the reference signal or increasing the number of retransmissions, thereby improving key consistency. However, this approach overlooks the multiple complex factors affecting key consistency, potentially leading to a decrease in overall key generation performance. This is reflected in the following aspects:
[0088] 1. Channel Characteristics and Noise Interference: Channel characteristics are complex and variable, affected not only by natural factors such as path loss and multipath effects, but also by human interference or changes in the electromagnetic environment. Simply increasing the transmission power of the reference signal can improve the signal-to-noise ratio to some extent, but it may also introduce more noise and interference, thus reducing the accuracy of channel estimation.
[0089] Meanwhile, interference factors such as Gaussian white noise, communication delay, and hardware fingerprints can also have an adverse effect on channel estimation. Increasing the number of retransmissions cannot completely eliminate these interferences; on the contrary, it may increase the complexity and delay of the system.
[0090] 2. System Overhead and Complexity: Increasing the number of retransmissions and enhancing the transmission power of the reference signal both increase system overhead and complexity. This includes overhead in signal processing, encoding / decoding, resource scheduling, and other aspects. When system overhead increases to a certain level, it may outweigh the performance improvement gained from increasing channel estimation accuracy, resulting in a decrease in overall key generation performance instead of an increase.
[0091] 3. Limitations of Channel Reciprocity and Spatial Correlation: In some cases, even increasing the transmission power of the reference signal or increasing the number of retransmissions may not completely overcome the limitations of channel reciprocity and spatial correlation. This is because the characteristics of wireless channels are affected not only by the physical environment but also by various factors such as device status and user behavior. Therefore, simply relying on enhancing the reference signal may not effectively improve key consistency.
[0092] Therefore, the above methods may lead to a decrease in overall key generation performance instead of an increase.
[0093] To address the aforementioned technical problems, embodiments of this application provide a communication method that improves key generation performance by modifying the parameters of the verification key or the generation key. In one scenario, if the key verification information of two parties is inconsistent, the consistency rate of the key verification information can be improved by reducing the key length (key verification length), increasing the quantization threshold used for key generation, or reducing the number of quantization bits used for key generation. In another scenario, if the consistency rate of the key verification information of two parties is high, the network transmission overhead can be reduced by increasing the key length (key verification length), decreasing the quantization threshold used for key generation, or increasing the number of quantization bits used for key generation, thereby comprehensively improving the key generation performance. The method provided by embodiments of this application will be described below with reference to the accompanying drawings.
[0094] The communication method provided in this application can be applied to various communication systems, such as: Long Term Evolution (LTE) systems, 5th Generation (5G) mobile communication systems, Wireless Fidelity (WiFi) systems, future communication systems, or systems integrating multiple communication systems, etc., and this application does not limit the application. 5G can also be referred to as New Radio (NR).
[0095] The communication method provided in this application can be applied to various communication scenarios, such as one or more of the following communication scenarios: enhanced mobile broadband (eMBB), ultra-reliable low latency communication (URLLC), machine type communication (MTC), massive machine type communications (mMTC), device to device (D2D), vehicle to everything (V2X), vehicle to vehicle (V2V), and Internet of Things (IoT).
[0096] To facilitate understanding of the embodiments of this application, the application scenario used in this application is described using the communication system architecture shown in Figure 3 as an example. Figure 3 is a schematic diagram illustrating a possible, non-limiting system. As shown in Figure 3, the communication system 3000 includes a radio access network (RAN) 100 and a core network (CN) 200. RAN 100 includes at least one network device (101a and 101b in Figure 3, collectively referred to as 110) and at least one terminal (102a-102j in Figure 3, collectively referred to as 102). RAN 100 may also include other RAN nodes, such as wireless relay devices and / or wireless backhaul devices (not shown in Figure 3). Terminal 102 is wirelessly connected to network device 101. Network device 101 is wirelessly or wired connected to core network 200. The core network device in core network 200 and network device 101 in RAN 100 can be different physical devices, or they can be the same physical device integrating core network logical functions and radio access network logical functions.
[0097] RAN 100 can be a cellular system related to the 3rd Generation Partnership Project (3GPP), such as 4G, 5G mobile communication systems, or evolution systems beyond 5G. RAN 100 can also be an open RAN (O-RAN or ORAN), a cloud radio access network (CRAN), or a WiFi system. RAN 100 can also be a communication system that integrates two or more of the above systems.
[0098] The apparatus provided in this application embodiment can be applied to network device 101 or terminal 102. It is understood that Figure 3 only illustrates one possible communication system architecture applicable to this application embodiment; in other possible scenarios, the communication system architecture may also include other devices.
[0099] Network device 101 is a node in the radio access network (RAN), also known as an access network device or an RAN node (or device). Network device 101 assists terminals in achieving wireless access. Multiple network devices 101 in the communication system 3000 can be nodes of the same type or different types. In some scenarios, the roles of network device 101 and terminal 102 are relative. For example, network element 102i in Figure 3 can be a helicopter or drone, which can be configured as a mobile base station. For terminals 102j accessing RAN 100 through network element 102i, network element 102i is a base station; but for base station 101a, network element 102i is a terminal. Network device 101 and terminal 102 are sometimes referred to as communication devices. For example, network elements 101a and 101b in Figure 3 can be understood as communication devices with base station functions, and network elements 102a-102j can be understood as communication devices with terminal functions.
[0100] In one possible scenario, network equipment can be a base station, an evolved NodeB (eNodeB), a transmitting and receiving point (TRP), a transmitting point (TP), a next-generation NodeB (gNB), a base station in a future mobile communication system, a satellite, or an access point (AP) in a WiFi system, an integrated access and backhaul (IAB) node, or a network device in a mobile switching center non-terrestrial network (NTN) communication system, meaning it can be deployed on high-altitude platforms or satellites. Network equipment can be a macro base station (as shown in Figure 3, 110a), a micro base station or indoor station (as shown in Figure 3, 110b), a relay node or donor node, or a wireless controller in a cloud radio access network (CRAN) scenario. Network equipment can also function as a base station in device-to-device (D2D) communication, vehicle-to-everything (V2X) communication, drone communication, and machine-to-machine (M2M) communication. Alternatively, network devices can also be servers, wearable devices, vehicles, or in-vehicle equipment. For example, the access network device in vehicle-to-everything (V2X) technology can be a roadside unit (RSU).
[0101] In another possible scenario, multiple network devices collaborate to assist terminals in achieving wireless access, with each network device performing a portion of the base station's functions. For example, network devices can be central units (CUs), distributed units (DUs), CU-control plane (CPs), CU-user plane (UPs), or radio units (RUs), etc. CUs and DUs can be set up separately or included in the same network element, such as a baseband unit (BBU). RUs can be included in radio equipment or radio units, such as remote radio units (RRUs), active antenna units (AAUs), or remote radio heads (RRHs). It is understood that network devices can be CU nodes, DU nodes, or devices comprising both CU and DU nodes. Furthermore, CUs can be classified as network devices in the access network (RAN) or the core network (CN), without limitation.
[0102] In different systems, CU (or CU-CP and CU-UP), DU, or RU may have different names, but those skilled in the art will understand their meaning. For example, in an open-radio access network (O-RAN) system, CU can also be called O-CU (open CU), DU can also be called O-DU, CU-CP can also be called O-CU-CP, CU-UP can also be called O-CU-UP, and RU can also be called O-RU. For ease of description, this application uses CU, CU-CP, CU-UP, DU, and RU as examples. Any of the units among CU (or CU-CP, CU-UP), DU, and RU in this application can be implemented through software modules, hardware modules, or a combination of software modules and hardware modules.
[0103] In this embodiment, the form of the network device is not limited. The device used to implement the function of the network device can be the network device itself, or it can be a device that supports the network device in implementing the function, such as a chip system. The device can be installed in the network device or used in conjunction with the network device.
[0104] Terminal equipment 102, also known as user equipment (UE), mobile station (MS), mobile terminal (MT), etc., is a device used to provide voice or data connectivity to users, and can also be an Internet of Things (IoT) device. For example, terminal equipment includes handheld devices with wireless connectivity, vehicle-mounted devices, etc. Currently, terminal devices can include: mobile phones, tablets, laptops, PDAs, mobile internet devices (MIDs), wearable devices (such as smartwatches, smart bracelets, pedometers, smart glasses, etc.), in-vehicle devices (such as cars, bicycles, electric vehicles, airplanes, ships, trains, high-speed trains, etc.), satellite terminals, virtual reality (VR) devices, augmented reality (AR) devices, point-of-sale (POS) machines, customer-premises equipment (CPE), light user equipment (UE), reduced capability user equipment (REDCAP UE), wireless terminals in industrial control, smart home devices (such as refrigerators, televisions, air conditioners, electricity meters, etc.), intelligent robots, robotic arms, workshop equipment, wireless terminals in autonomous driving, wireless terminals in telemedicine, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, or wireless terminals in smart homes, and flying equipment (such as intelligent robots, hot air balloons, drones, airplanes), etc. Terminal devices can also be vehicle devices, such as vehicle devices, vehicle modules, vehicle chips, on-board units (OBUs) or telematics boxes (T-BOXs). Terminal devices can also be other devices with terminal functions. For example, a terminal device can also be a device that performs terminal functions in D2D communication.
[0105] The embodiments of this application do not limit the form of the terminal device. The device used to implement the functions of the terminal device can be the terminal device itself, or it can be a device that supports the terminal device in implementing the functions, such as a chip system. The device can be installed in the terminal device or used in conjunction with the terminal device. In the embodiments of this application, the chip system can be composed of chips, or it can include chips and other discrete devices. All or part of the functions of the terminal device in this application can also be implemented by software functions running on hardware, or by virtualization functions instantiated on a platform (such as a cloud platform).
[0106] In this communication system, any two devices can act as parties to the key negotiation. For example, different terminals can act as parties to the key negotiation (referred to as key negotiation devices, such as the first key negotiation device and the second key negotiation device), different network devices can act as parties to the key negotiation, and a network device and a terminal can act as parties to the key negotiation. The device that performs key consistency verification (referred to as the key verification device) can be any one of the parties to the key negotiation. For example, if terminal A and terminal B are the parties to the key negotiation, then the key verification device can be terminal A or terminal B. In this case, terminal A or terminal B simultaneously acts as both the key negotiation device and the key verification device. Alternatively, the key verification device can also be a third-party device other than the parties to the key negotiation. For example, if terminal A and terminal B are the parties to the key negotiation, the device performing key consistency verification can be the network device serving terminal A and terminal B.
[0107] In conjunction with the aforementioned communication system, this application provides a communication method that improves key generation performance by adjusting the parameters of the verification key and / or the parameters of the generated verification key. This communication method is applied to the aforementioned key verification device and key negotiation device. The executing entity of this method can be the key verification device or the key negotiation device. The key verification device or key negotiation device can be a network device or terminal device described in the aforementioned communication system, or it can be a component (e.g., a processor, chip, or chip system) applied in the network device or terminal device, a logic module or software capable of implementing all or part of the functions of the network device or terminal device, or a device used in conjunction with the network device or terminal device.
[0108] Figure 4 shows a flowchart of the communication method provided in an embodiment of this application. As shown in Figure 4, the method may include the following steps:
[0109] S410, the key verification device obtains the first verification information of the first key and the second verification information of the second key from the key negotiation device.
[0110] Referring to the description of the key verification device and key negotiation device in the embodiments introducing the communication system, the key negotiation device includes a first key negotiation device and a second key negotiation device. The first key negotiation device generates a first key and first verification information, and the second key negotiation device generates a second key and second verification information. The first verification information and the second verification information can be used to determine the consistency between the first key and the second key. The first verification information may include key verification bits generated by the first key negotiation device based on the key verification length L and the first key. The second verification information may include key verification bits generated by the second key negotiation device based on the key verification length L and the second key.
[0111] During the key negotiation process, the first key negotiation device and the second key negotiation device can follow a physical layer key generation mechanism based on channel entropy (the specific process is detailed in the embodiment shown in Figure 1, and will not be repeated here). According to this mechanism, each party independently generates a key and simultaneously generates verification information corresponding to its respective key. Specifically, the verification information corresponding to the key generated by the first key negotiation device is called the first verification information, and the verification information corresponding to the key generated by the second key negotiation device is called the second verification information. The encoding method used to generate the first and second verification information can include bit mapping, hash functions, or polynomial checksums, etc., and is not limited.
[0112] S420, the key verification device sends first information to the key negotiation device based on the first verification information and the second verification information; correspondingly, the key negotiation device receives the first information from the key verification device.
[0113] The first information is used to indicate adjustments to at least one of the following: parameters of the verification key or parameters of the key generation key. Parameters of the verification key include the key verification length. Parameters of the key generation key include: a quantization threshold used to generate the key and / or the number of quantization bits used to generate the key. The first information can be applied to the next key generation.
[0114] For example, the first information may be used to indicate at least one of the following: reducing the key verification length, increasing the quantization threshold used to generate the key, or reducing the number of quantization bits used to generate the key. In yet another example, the first information may also be used to indicate at least one of the following: increasing the key verification length, decreasing the quantization threshold used to generate the key, or increasing the number of quantization bits used to generate the key.
[0115] Key consistency verification based on the first and second verification information may pass or fail. The design of the first information will be introduced first, when key consistency verification fails, i.e., when the first and second verification information are inconsistent:
[0116] As shown in Figure 5, when the first verification information and the second verification information are inconsistent, the first information is used to indicate at least one of the following: reducing the key verification length, increasing the quantization threshold used to generate the key, or reducing the number of quantization bits used to generate the key. In other words, S420 at this time may include: sending the first information indicating the above content when the first verification information and the second verification information are inconsistent.
[0117] Regarding the benefits of reducing key verification length: During key consistency verification, any inconsistency between the keys of the two parties in the key negotiation device will directly lead to a mismatch in the generated check bits, thus necessitating the discarding of the entire key segment involved in the verification. In other words, even with a long key length and only a very small number of inconsistent bits, the entire key segment will be discarded due to verification failure, potentially resulting in significant resource waste. For example, consider a 1000-bit key verification. If the entire 1000-bit key is verified at once (in this case, the key verification length is 1000 bits), and the corresponding check bits are calculated, then even a mere 1-bit inconsistency between the two keys will result in different check bits generated by both parties, forcing the entire 1000-bit key segment to be discarded.
[0118] If the key verification length is reduced, for example, a 1000-bit key is verified using ten checks (reducing the key verification length from 1000 bits to 100 bits), then if only one check (100 bits) is inconsistent, that portion of the key needs to be discarded. The remaining 900 bits, having passed the verification, can be retained and used for subsequent operations. Furthermore, the reduced verification content improves the success rate of key consistency checks, thus reducing the waste of air interface resources caused by failed key consistency checks.
[0119] Regarding the effect of increasing the quantization threshold used for key generation, if the quantization threshold is set too loosely (i.e., the value of the quantization threshold is small), then the channel measurements are more susceptible to noise, interference, and other factors during the quantization process, leading to deviations in the quantization results. Increasing the quantization threshold makes the quantization range more defined, reducing key inconsistencies caused by quantization errors. Therefore, increasing the quantization threshold helps improve the key consistency rate, thereby increasing the success rate of key consistency verification.
[0120] Furthermore, regarding the reduction of the number of quantization bits used to generate the key, fewer quantization bits mean a larger quantization interval (or quantization step size). During quantization, a larger quantization interval can reduce quantization errors caused by factors such as channel noise and interference, making the quantized results of legitimate communicating parties more similar, thereby improving the key consistency rate and consequently increasing the success rate of key consistency verification.
[0121] In summary, this application's embodiments design various strategies to improve the success rate of key consistency verification, including reducing the key verification length, increasing the quantization threshold when generating the key, and reducing the number of quantization bits used to generate the key. Each strategy can effectively improve the success rate of key consistency verification in different scenarios. It is understood that, to achieve the goal of improving the success rate of key consistency verification, any one of the above strategies, or any combination thereof, can be flexibly selected, depending on actual needs and conditions, without any restrictions.
[0122] In one embodiment, as shown in Figure 5, when the key consistency verification is successful, i.e., the first verification information matches the second verification information, the currently generated key can be recorded and put into use. In one possible implementation, the current key verification parameters and key generation parameters will be recorded and used as baseline parameters for subsequent key generation processes. In another possible implementation, if the key consistency verification is successful, it means that the key verification parameters and key generation parameters meet the success rate requirements of the key consistency verification, and the aforementioned first information does not need to be sent.
[0123] In one embodiment, further, if the key consistency verification passes multiple times, then adjusting the parameters of the verification key can reduce network transmission overhead, and adjusting the parameters of the generation key can improve the efficiency of key generation. At this time, as shown in Figure 6, the method may further include:
[0124] S430, the key verification device obtains at least one third verification information and at least one fourth verification information from the key negotiation device.
[0125] The third and fourth verification information are used to determine the consistency between the first and second keys. The third verification information can be the verification information generated by the first key negotiation device during a key consistency check prior to the current key consistency check. The fourth verification information can be the verification information generated by the second key negotiation device during a key consistency check prior to the current key consistency check. The first verification information and at least one third verification information constitute the first verification information set; similarly, the second verification information and at least one fourth verification information constitute the second verification information set. Regarding the setting of the first verification information set, it can be set to include verification information acquired within a certain period, for example, the verification information acquired in each first time period, for example, a first time period of 5 seconds. That is, the first verification information set includes the verification information acquired within the first time period. Alternatively, it can be set to include a fixed number of verification information, for example, the verification information acquired every N times constitutes the current first verification information set, for example, N is 10. That is, the first verification information set includes N verification information acquired in N checks. The setting of the second verification information set is based on the same principle as the setting of the first verification information set, and will not be repeated here.
[0126] The content of the first information can be determined based on the consistency check information in the first and second check information sets. In other words, the first information is sent based on the first, second, third, and fourth check information.
[0127] In one possible implementation, if the ratio of consistency verification information in the first and second verification information sets meets a preset condition, it indicates a high pass rate for multiple key consistency verifications. To reduce the overhead of key consistency verification and improve the key generation rate, as shown in Figure 5, the first information in this case can be set to indicate at least one of the following: increasing the key verification length, reducing the quantization threshold used to generate the key, or increasing the number of quantization bits used to generate the key. The preset condition can be that the pass rate of key consistency verification is greater than or equal to an expected value, for example, an expected value of 90%. It is understood that the preset condition can have other settings in different scenarios and usage requirements, without limitation.
[0128] In this implementation, S420 may include: when the ratio of consistency verification information in the first verification information set and the second verification information set meets a preset condition, sending first information indicating the following: increasing the key verification length, decreasing the quantization threshold used to generate the key, and / or increasing the number of quantization bits used to generate the key.
[0129] In one possible implementation, if the ratio of consistency verification information in the first verification information set and the second verification information set meets the condition not preset, the aforementioned first information is not sent. This implementation can reduce signaling overhead and avoid frequent adjustments to key parameters.
[0130] Increasing the key verification length increases the number of key verification bits required for each verification, thereby effectively reducing the frequency of key consistency verification and reducing the consumption and overhead of air interface resources.
[0131] Lowering the quantization threshold in key generation can improve key generation efficiency. First, reducing the quantization threshold simplifies the quantization process, reducing the number of quantization levels and allowing for wider quantization intervals. This means that more channel measurements can be quickly assigned to a limited number of quantization categories within the same timeframe, accelerating the key generation process. Second, this adjustment also reduces computational complexity, as each channel measurement only needs to be compared with fewer thresholds during quantization, thus reducing computational time and resource consumption.
[0132] Increasing the number of quantization bits in key generation improves the key generation rate. A higher number of quantization bits means that channel measurements can be mapped to a finer quantization level during quantization. This is equivalent to generating richer key bits while keeping the number of channel features constant, thus accelerating the key generation process.
[0133] In summary, this application's embodiments design various strategies to reduce the overhead of key consistency verification and improve the key generation rate, including increasing the key verification length, reducing the quantization threshold during key generation, and increasing the number of quantization bits used to generate the key. It is understood that, to achieve the above objectives, any one of the above strategies, or any combination thereof, can be flexibly selected, depending on actual needs and conditions, without any limitations.
[0134] In one embodiment, as shown in FIG7, the method may further include:
[0135] S440, determine the adjustment margin of the parameters based on the difference between the parameters of the first key and the corresponding preset parameter values.
[0136] The parameters of the first key include the parameters of the verification key and / or the parameters of the generation key as described in the above embodiments. Considering that the communication system may define an adjustable range for the key parameters, the key parameters cannot be adjusted indefinitely. The adjustable range of the key parameters can be determined by preset parameter values. In this case, the adjustment margin of the parameters can be determined based on the difference between the parameters of the key (e.g., the first key) and the corresponding preset parameter values. The preset parameter values may include one or more thresholds; for example, the preset parameter values include [threshold 1, threshold 2, ..., threshold n]. For example, taking the key verification length in the parameters of the verification key as an example, the selectable set of key verification lengths is [1024, 512, 256, 128, 64]. In this case, the preset parameter values include 1024, 512, 256, 128, 64. Assuming the key verification length of the first key is 64, the adjustment margin of the key verification length of the first key includes four options: increasing by 64, increasing by 192, increasing by 448, and increasing by 960.
[0137] As an alternative implementation, the adjustment margin of the parameters can also be determined by the difference between the parameters of the second key and the corresponding preset parameter values, without limitation. It is understood that in this alternative implementation, the first key and the second key correspond, so the adjustment margin of the parameters can be determined based on either key.
[0138] S450, determine the first information based on the first verification information, the second verification information, and the adjustment margin of the parameters.
[0139] After determining the aforementioned adjustment margin, the first information can be determined by checking whether the first and second verification information are consistent. Alternatively, the first information can be determined by checking whether the first and second verification information are consistent, and then the aforementioned adjustment margin can be determined. The order of determination is not restricted.
[0140] Regarding the application of whether the first verification information and the second verification information are consistent in determining the first information, please refer to the description in the above embodiments, which will not be repeated here.
[0141] The following example, using the parameters of the first key, including the key verification length and the quantization threshold during key generation, illustrates how to determine the first information in various situations: In this example, the optional set of key verification lengths (i.e., the set of preset parameter values) is set to [1024, 512, 256, 128, 64]; the optional set of quantization thresholds (i.e., the set of preset parameter values) is [2, 2.5, 3, 3.5, 4]. In this example, adjusting the key verification length has a higher priority than adjusting the quantization threshold during key generation. As shown in Figure 8, determining the first information can be divided into the following four cases:
[0142] Scenario 1: The first verification information is inconsistent with the second verification information (key consistency verification fails). In this case, the first information can indicate to reduce the key verification length and / or increase the quantization threshold used to generate the key, and there is an adjustment margin for reducing the key verification length. In this example, the first information preferentially indicates to reduce the key verification length.
[0143] For example, if the current key verification length is 512 and the quantization threshold is 3, then the adjustment margins for the key verification length are: increase by 512, decrease by 256, decrease by 384, and decrease by 448. The adjustment margins for the quantization threshold are: increase by 1, decrease by 1, increase by 0.5, and decrease by 0.5. Adjusting the key verification length has higher priority than adjusting the quantization threshold when generating the key. Since there is an adjustment margin for reducing the key verification length, the key configuration is first optimized by gradually reducing the key verification length (in ascending order of reduction, i.e., first reduce by 256, then 384, and finally 448) until the key consistency check is successful, or the key verification length reaches the minimum adjustment margin of 64. During this process, the first information corresponding to each key consistency check indicates the currently adjusted key verification length. For example, after a key consistency check with a reduction of 256, the first information could include a key verification length of 256, or indicate that the key verification length has been reduced by 256.
[0144] If, during this process, the key consistency check still fails even after the key verification length has been reduced to 64, then increasing the quantization threshold should be considered. The specific increase depends on the values in the optional set of quantization thresholds. A value can be selected from the optional set as the adjusted quantization threshold. For example, a small increment close to the current value can be chosen (e.g., from 3 to 3.5). Similar to the first information indicating the key verification length, the first information corresponding to each key consistency check indicates the currently adjusted quantization threshold. For example, after a key consistency check following an increase from 3 to 3.5, the first information could include a quantization threshold of 3.5, or indicate that the quantization threshold has increased by 0.5. Adjusting with small increments ensures high precision, avoids over-adjustment or oscillation, and ensures stable operation of the communication system.
[0145] Scenario 2: Key consistency verification fails. In this case, the first message indicates to reduce the key verification length and / or increase the quantization threshold used to generate the key. If there is no adjustment margin for reducing the key verification length, the first message indicates to increase the quantization threshold.
[0146] For example, the current key verification length is 64, and the quantization threshold is 3. At this point, there is no margin for reducing the key verification length from 64. The strategy adopted is to increase the quantization threshold. The specific increase is determined by the values in the optional set of quantization thresholds. For example, a smaller increment close to the current value (such as increasing from 3 to 3.5) is chosen until the key consistency check passes, or the maximum quantization threshold of 4 is reached. The first message corresponding to each key consistency check indicates the currently adjusted quantization threshold. For example, after a key consistency check following an increase from 3 to 3.5, the first message could include a quantization threshold of 3.5, or indicate that the quantization threshold has increased by 0.5.
[0147] Scenario 3: The key consistency verification passes, and the ratio of consistency verification information in the first verification information set and the second verification information set meets the preset conditions. In this case, the first information can indicate to increase the key verification length and / or reduce the quantization threshold used to generate the key. There is an adjustment margin for increasing the key verification length, and the first information will preferentially indicate to increase the key verification length.
[0148] For example, the current key verification length is 64, and the quantization threshold is 3. The key verification length can be increased to 128. If the proportion of consistency verification information in subsequent key consistency checks meets preset conditions, the key verification length can continue to be increased until the key consistency check fails or the key verification length reaches the maximum length of 1024. During this process, the first information corresponding to each key consistency check indicates the currently adjusted key verification length. For example, after a key consistency check with a key verification length increased by 64, the first information could include a key verification length of 128, or indicate that the key verification length has increased by 64.
[0149] If the key consistency check still passes at this point, consider reducing the quantization threshold used to generate the key. The specific reduction amount depends on the values in the optional set of quantization thresholds. For example, choose a small increment close to the current value (e.g., reducing from 3 to 2.5) until the key consistency check fails, or the minimum quantization threshold of 2 is reached. The first message corresponding to each key consistency check indicates the currently adjusted quantization threshold. For example, after a key consistency check following a reduction from 3 to 2.5, the first message could include a quantization threshold of 3.5, or indicate that the quantization threshold has increased by 0.5.
[0150] Scenario 4: The ratio of consistency verification information in the first verification information set and the second verification information set meets the preset conditions. The first information can indicate to increase the key verification length and / or decrease the quantization threshold used to generate the key. There is no adjustment margin for increasing the key verification length. The first information indicates to decrease the quantization threshold used to generate the key.
[0151] For example, the current key verification length is 1024, and the quantization threshold is 3. In this case, there is no room for adjustment in increasing the key verification length of 1024. The quantization threshold used to generate the key can be reduced as described in Case 3, which will not be repeated here.
[0152] The above scenarios one through four illustrate how to determine the specific adjustment range of the adjustment parameters using a mechanism that adopts a small increment close to the current value. It is understandable that, in determining the specific adjustment range of the adjustment parameters, besides adopting a small increment close to the current value, more flexible and efficient adjustment mechanisms can be designed according to the needs of the actual application scenario. For example, the maximum adjustment range can be determined as the specific adjustment range of the adjustment parameters. Using the maximum adjustment range for parameter adjustment can quickly change the state of the communication system, accelerate convergence towards the target (passing key consistency verification), and shorten the adjustment cycle.
[0153] In one implementation, a dynamic adjustment mechanism based on inconsistencies in verification information can be introduced, which can significantly improve the accuracy and efficiency of the adjustment. Specifically, this dynamic adjustment mechanism relies on comparing the degree of inconsistency between the first and second sets of verification information. When the degree of inconsistency between the two sets of verification information is high, it means that the current parameter setting deviates significantly from the target state. In this case, appropriately increasing the increment of the adjustment parameter can accelerate the system's convergence to the target state (key consistency verification passed), reduce the adjustment cycle, and improve adjustment efficiency. Conversely, if the degree of inconsistency between the two sets of verification information is low, it indicates that the current parameter setting is close to the ideal state. In this case, reducing the increment of the adjustment parameter helps to achieve more precise adjustments, avoid over-adjustment or oscillation, and ensure the stable operation of the communication system.
[0154] The above example uses the parameters of the first key, including the key verification length and the quantization threshold when generating the key, to illustrate the content of the first information in various cases. Specifically, the first information indicating the adjusted parameters is determined by combining the adjustment margin and adjustment priority of each parameter. It is understood that, in addition to the key parameter content and adjustment priority described in the above example, other parameter content and other parameter adjustment priorities can be designed based on different scenarios and usage needs, without restriction.
[0155] In one possible implementation, the adjustment priority of each parameter can be pre-agreed upon by the key verification device and the key negotiation device, or it can be indicated by the key verification device to the key negotiation device through the first information; there is no restriction. Optionally, the first information also includes parameter adjustment priority information, for example, the priority information indicates that the adjustment order of the key verification length takes precedence over the adjustment order of the quantization threshold.
[0156] In another possible implementation, the adjustment priority of the parameters may not be set, and the key negotiation device may randomly generate an adjustment order from the adjustment parameters indicated by the first information to adjust the parameters.
[0157] In another example, the parameters of the first key, in addition to the key verification length and quantization threshold when generating the key as described above, also introduce the number of quantization bits used to generate the key. In scenarios where the parameters of the first key include the above three parameters, the specific process of setting the adjustment priority for each parameter can be referred to the description of the above embodiments. That is, firstly, the adjustment margin of each parameter is determined, and then, based on the adjustment margin of each parameter and the adjustment priority of each parameter, the corresponding parameters are adjusted sequentially until the adjustment purpose, such as passing the key consistency verification, is achieved, will not be elaborated further. The following describes an implementation method where the adjustment order is randomly generated by the key negotiation device to adjust the parameters.
[0158] In this example, the optional set for setting the key verification length (i.e., the set of preset parameter threshold values) is [1024, 512, 256, 128, 64]; the optional set for the quantization threshold (i.e., the set of preset parameter threshold values) is [2, 2.5, 3, 3.5, 4]; and the optional set for the number of quantization bits in the generated key (i.e., the set of preset parameter threshold values) is [1, 2, 3]. When determining the first piece of information, there are two possible scenarios:
[0159] Scenario 5, similar to Scenario 1, involves inconsistencies between the first and second verification information (key consistency verification fails). In this case, the first information can indicate reducing the key verification length, increasing the quantization threshold used to generate the key, and / or reducing the number of quantization bits used to generate the key. All three parameters have corresponding adjustment margins.
[0160] For example, if the current key verification length is 512, the quantization threshold is 3, and the number of quantization bits is 3, then the adjustment margins for the key verification length are: increase by 512, decrease by 256, decrease by 384, and decrease by 448. The adjustment margins for the quantization threshold are: increase by 1, decrease by 1, increase by 0.5, and decrease by 0.5. The adjustment margins for the number of quantization bits are: decrease by 1 and decrease by 2.
[0161] At this point, the first information can indicate the adjustment margins for the three types of parameters mentioned above. The key negotiation device randomly generates an adjustment order and adjusts the three types of parameters sequentially. The adjustment margin for each type of parameter indicated by the first information can be a single adjustment margin. The determination mechanism for which adjustment margin should be indicated can be flexibly set. For example, referring to Case 1 in the previous example, the smaller adjustment margin can be selected. In one implementation, the adjustment margin for each type of parameter indicated by the first information can also be multiple adjustment margins. The key negotiation device determines which adjustment margin to start adjusting from among the multiple adjustment margins. The determination mechanism can also be flexibly set; for details, please refer to the explanation following Case 4 in the previous example, which will not be repeated here.
[0162] Scenario 6: The first verification information is inconsistent with the second verification information (key consistency verification fails). In this case, the first information can indicate reducing the key verification length, increasing the quantization threshold used to generate the key, and / or reducing the number of quantization bits used to generate the key. There are corresponding adjustment margins for these three parameters.
[0163] For example, if the current key verification length is 512, the quantization threshold is 3, and the number of quantization bits is 1, then the adjustment margins for the key verification length are: increase by 512, decrease by 256, decrease by 384, and decrease by 448. The adjustment margins for the quantization threshold are: increase by 1, decrease by 1, increase by 0.5, and decrease by 0.5. There is no adjustment margin for decreasing the number of quantization bits.
[0164] At this point, the first information can indicate the adjustment margin for the key verification length and quantization threshold. The key negotiation device randomly generates an adjustment order to adjust the key verification length and quantization threshold sequentially. The adjustment margin for each type of parameter indicated by the first information can be one adjustment margin. When determining which adjustment margin should be indicated, a determination mechanism can be flexibly set. For example, referring to Case 1 in the previous example, an adjustment margin with a smaller adjustment amount can be selected. In one implementation, the adjustment margin for each type of parameter indicated by the first information can also be multiple adjustment margins. The key negotiation device determines which adjustment margin to start adjusting based on among the multiple adjustment margins. The determination mechanism can also be flexibly set. For details, please refer to the explanation after Case 4 in the previous example, which will not be repeated here. Case 7: The key consistency verification passes, and the ratio of consistency verification information in the first verification information set and the second verification information set meets the preset conditions. At this point, the first information can indicate increasing the key verification length, decreasing the quantization threshold used to generate the key, and / or increasing the number of quantization bits used to generate the key. All three parameters have corresponding adjustment margins.
[0165] For example, if the current key verification length is 64, the quantization threshold is 3, and the number of quantization bits is 1, then the adjustment margins for the key verification length are: increase by 64, increase by 192, increase by 448, and increase by 960. The adjustment margins for the quantization threshold are: increase by 1, decrease by 0.5, and decrease by 1. The adjustment margins for the number of quantization bits are: increase by 1 and increase by 2.
[0166] At this point, the first information can indicate the adjustment margins for the three types of parameters mentioned above. The key negotiation device randomly generates an adjustment order and adjusts the three types of parameters sequentially. The adjustment margin for each type of parameter indicated by the first information can be a single adjustment margin. The determination mechanism for which adjustment margin should be indicated can be flexibly set. For example, referring to Case 1 in the previous example, the smaller adjustment margin can be selected. In one implementation, the adjustment margin for each type of parameter indicated by the first information can also be multiple adjustment margins. The key negotiation device determines which adjustment margin to start adjusting from among the multiple adjustment margins. The determination mechanism can also be flexibly set; for details, please refer to the explanation following Case 4 in the previous example, which will not be repeated here.
[0167] Case 8: The key consistency verification passes, and the ratio of consistency verification information in the first verification information set and the second verification information set meets the preset conditions. In this case, the first information can indicate to increase the key verification length, reduce the quantization threshold used to generate the key, and / or increase the number of quantization bits used to generate the key. The above three parameters have corresponding adjustment margins.
[0168] For example, if the current key verification length is 64, the quantization threshold is 3, and the number of quantization bits is 3, then the adjustment margins for the key verification length are: increase by 64, increase by 192, increase by 448, and increase by 960. The adjustment margins for the quantization threshold are: increase by 1, decrease by 0.5, and decrease by 1. There is no adjustment margin for increasing the number of quantization bits.
[0169] At this point, the first information can indicate the adjustment margin for the key verification length and quantization threshold. The key negotiation device randomly generates an adjustment order to adjust the key verification length and quantization threshold sequentially. The adjustment margin for each type of parameter indicated by the first information can be a single adjustment margin. The determination mechanism for which adjustment margin should be indicated can be flexibly set; for example, referring to Case 1 in the previous example, a smaller adjustment margin can be selected. In one implementation, the adjustment margin for each type of parameter indicated by the first information can also be multiple adjustment margins. The key negotiation device determines which adjustment margin to start adjusting from among the multiple adjustment margins. The determination mechanism can also be flexibly set; for details, please refer to the explanation following Case 4 in the previous example, which will not be repeated here.
[0170] As can be seen from the above examples, the design of the first information in this application embodiment is highly flexible, and it can cover at least one of the following aspects: the adjusted value of the verification key parameter and the adjusted value of the generation key parameter. Furthermore, to further improve the efficiency and diversity of information expression, the first information can also include the specific values of the adjusted verification key parameters and the specific values of the adjusted generation key parameters. For the design where the first information is set as the adjusted value of the parameters, the amount of data in the first information is smaller, and the network bandwidth required for transmitting the first information is less. For the design where the first information is set as the specific value of the adjusted parameters, it ensures that the first information carries parameters with high accuracy, avoids errors caused by calculating the adjusted specific value based on the adjusted value, and eliminates the need for additional calculations, thus simplifying the processing flow. These design options provide a rich selection space for practical applications. Specific examples can be found in the detailed examples of the first information content in Situations 1 to 4 described above, and will not be repeated here.
[0171] In one implementation, the first information may further include an index indicating the specific value (or adjusted value) of the above-mentioned parameter.
[0172] The index of each specific value (or adjustment value) corresponds to that specific value (or adjustment value). Both the sending and receiving ends store one or more indices and the association between each index and its corresponding specific value (or adjustment value). The specific value (or adjustment value) can be determined based on the association and the index, which reduces transmission overhead and provides greater flexibility and data processing efficiency. It is not limited by the direct or indirect representation of information and possesses high adaptability and configurability.
[0173] In this embodiment of the application, by combining the adjustment margin of each parameter and the adjustment priority of the parameter to determine the first information indicating the adjusted parameter, the pass rate of key consistency verification, the key generation rate, and the air interface overhead of key consistency verification can be improved in each case.
[0174] In summary, the communication method provided in this application improves key generation performance by modifying the parameters of the verification key or the generation key. In one scenario, if the key verification information of the two parties is inconsistent, the consistency rate of the key verification information can be improved by reducing the key length (key verification length), increasing the quantization threshold used for key generation, or reducing the number of quantization bits used for key generation. In another scenario, if the consistency rate of the key verification information of the two parties is high, the network transmission overhead can be reduced by increasing the key length (key verification length), decreasing the quantization threshold used for key generation, or increasing the number of quantization bits used for key generation, thereby comprehensively improving the key generation performance.
[0175] As described above, in the embodiments of this application, the communication system is designed to allow any two devices within it to participate in the key negotiation process as one party, thus providing high flexibility. In particular, the role of the key verification device is set more flexibly: it can be directly assumed by either party participating in the key negotiation, or it can be assumed by a third-party device independent of the negotiating parties.
[0176] To illustrate the specific applications and practices of the embodiments of this application in different communication scenarios, the following will describe the implementation details of its communication method from the perspective of the execution flow. Specific explanations of each step will not be repeated here, as they have already been described in the preceding embodiments; please refer to the preceding text for details.
[0177] In one communication scenario, the role of the key verification device is directly assumed by either party participating in the key negotiation. In this case, the device generating the first key is called the first communication device, and the device generating the second key is also called the first communication device. In this scenario, the first communication device simultaneously acts as the key verification device. As shown in Figure 9, the communication method includes:
[0178] S910, the first communication device generates the first verification information of the first key.
[0179] In this process, the first communication device, as one of the parties in the key negotiation, is able to generate the first key and the first verification information.
[0180] S920, the second communication device sends the second verification information of the second key to the first communication device. Correspondingly, the second communication device receives the second verification information of the second key.
[0181] For a detailed explanation, please refer to the description of step S410 in the embodiment shown in Figure 4.
[0182] S930, the first communication device sends the first information to the second communication device based on the first verification information and the second verification information.
[0183] The explanation of step S930 can be found in the explanation of step S420 in the embodiment shown in Figure 4.
[0184] In this embodiment, the role of the key verification device is directly assumed by any party participating in the key negotiation, reducing the need for additional devices and thus simplifying the overall architecture of the communication system. Furthermore, since the verification process is built into the key negotiation process and executed by the direct participants, the security of the key negotiation process is enhanced. Neither party can unilaterally change the key without the other party's detection.
[0185] In another communication scenario, the role of the key verification device is assumed by a third-party device independent of the negotiating parties. This device is referred to as the third communication device. In this scenario, the third communication device can send parameters for the verification key and parameters for the key generation to the first and second communication devices, so that the first and second communication devices can generate the key. As shown in Figure 10, the communication method includes:
[0186] S110, the first communication device sends the first verification information of the first key to the third communication device and the second communication device sends the second verification information of the second key to the third communication device. Correspondingly, the third communication device receives the first verification information of the first key from the first communication device and receives the second verification information of the second key from the second communication device.
[0187] For a detailed explanation of step S110, please refer to the explanation of step S410 in the embodiment shown in Figure 4.
[0188] S120, the third communication device sends first information to the first and second communication devices based on the first and second verification information. Correspondingly, the first and second communication devices receive the first information from the third communication device.
[0189] The description of step S120 can be found in the description of step S420 in the embodiment shown in Figure 4.
[0190] In this embodiment, the role of the key verification device is undertaken by a third-party device independent of both negotiating parties. This device is referred to as the third communication device. Having the third communication device responsible for key verification significantly enhances the trustworthiness of the key negotiation process. This is because the third communication device is typically designed to be neutral and trustworthy, providing impartial verification services to ensure that the keys negotiated between the two parties are authentic and valid.
[0191] The foregoing mainly describes the solution provided by the embodiments of this application from the perspective of the execution logic of each step. It is understood that each node, such as a key negotiation device, includes corresponding hardware structures and / or software modules to execute each function in order to achieve the above-mentioned functions. Those skilled in the art should readily recognize that, in conjunction with the algorithm steps of the examples described in the embodiments disclosed herein, the method of the embodiments of this application can be implemented in hardware, software, or a combination of hardware and computer software. Whether a function is executed in a hardware or software-driven manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0192] This application embodiment can divide the key negotiation device into functional modules according to the above method example. For example, each function can be divided into its own functional module, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware or as a software functional module. It should be noted that the module division in this application embodiment is illustrative and only represents one logical functional division. In actual implementation, there may be other division methods.
[0193] In specific implementations, the network elements shown in this application, such as key negotiation devices or key verification devices, can adopt the composition structure shown in Figure 11 or include the components shown in Figure 11. Figure 11 is a schematic diagram of the structure of a communication device provided in an embodiment of this application. When the communication device has the function of the key negotiation device described in the embodiment of this application, the communication device can be a key verification device, or a component or device applied to the key verification device (e.g., a processor, chip, or chip system), or a logic module or software that can implement all or part of the key verification device functions, or a device used in conjunction with the key verification device. When the communication device has the function of the key verification device described in the embodiment of this application, the communication device can be a key negotiation device, or a component or device applied to the key negotiation device (e.g., a processor, chip, or chip system), or a logic module or software that can implement all or part of the key negotiation device functions, or a device used in conjunction with the key verification device.
[0194] For example, Figure 11 illustrates a possible structural diagram of a communication device. It is understood that the communication device 110 includes means of the necessary form, such as modules, units, elements, circuits, or interfaces, to be appropriately configured together to execute this solution. The communication device 110 may be a key negotiation device or key verification device as described in the above method embodiments, or it may be a component (e.g., a chip) in these devices used to implement the methods described in the above method embodiments. The communication device 110 includes one or more processors 1101. The processor 1101 may be a general-purpose processor or a dedicated processor, for example, a baseband processor or a central processing unit. The baseband processor can be used to process communication protocols and communication data, while the central processing unit can be used to control the communication device, execute software programs, and process data from the software programs.
[0195] Optionally, in one design, the processor 1101 may include a program 1103 (sometimes also referred to as code or instructions), which can be executed on the processor 1101 to cause the communication device 110 to perform the methods described in the above embodiments. The processor 1101 including the program 1103 may be used to store the program 1103, for example, by a memory integrated in the processor 1101.
[0196] Optionally, the communication device 110 may include one or more memories 1102 storing a program 1104 (sometimes referred to as code or instructions), which can be executed on the processor 1101 to cause the communication device 110 to perform the methods described in the above method embodiments. Optionally, the memory 1102 may also be located outside the communication device.
[0197] Optionally, the processor 1101 and / or memory 1102 may include AI modules 1107 and 1108, which are used to implement AI-related functions. The AI modules can be implemented through software, hardware, or a combination of both. For example, the AI module may include a RIC module. For example, the AI module may be a near real-time RIC or a non-real-time RIC.
[0198] Optionally, the processor 1101 and / or memory 1102 may also store data. The processor and memory may be configured separately or integrated together.
[0199] Optionally, the communication device 110 may further include a transceiver 1105 and / or an antenna 1106. The processor 1101, sometimes referred to as a processing unit, controls the communication device. The transceiver 1105, sometimes referred to as a transceiver unit, transceiver, transceiver circuit, or transceiver, is used to realize the transmission and reception functions of the communication device through the antenna 1106.
[0200] Figure 12 shows a structural diagram of a communication device 120, which is applied to a key verification device. Each module in the device shown in Figure 12 has the function of implementing the corresponding steps in the above method embodiments and can achieve its corresponding technical effect. The beneficial effects of each module performing the steps can be referred to the description of the corresponding steps in the above method embodiments, and will not be repeated here. The functions can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions. The communication device can be a key verification device or a chip or system-on-a-chip in the key verification device. For example, the device includes:
[0201] The processing module 1201 is used to obtain first verification information of the first key and second verification information of the second key, wherein the first verification information and the second verification information are used to determine the consistency between the first key and the second key.
[0202] The transceiver module 1202 is used to send first information based on first verification information and second verification information. The first information is used to indicate the adjustment of at least one of the following: parameters of the verification key or parameters of the generation key.
[0203] In one embodiment, the parameters of the verification key include the key verification length; the parameters of the key generation include: a quantization threshold for generating the key and / or the number of quantization bits for generating the key.
[0204] In one embodiment, the first information is used to indicate at least one of the following: reducing the key verification length, increasing the quantization threshold for generating the key, or reducing the number of quantization bits used to generate the key; or, the first information is used to indicate at least one of the following: increasing the key verification length, decreasing the quantization threshold for generating the key, or increasing the number of quantization bits used to generate the key.
[0205] In one embodiment, the transceiver module 1202 is specifically configured to: send first information when the first verification information and the second verification information are inconsistent, wherein the first information is configured to instruct at least one of the following to reduce the key verification length, increase the quantization threshold used to generate the key, or reduce the number of quantization bits used to generate the key.
[0206] In one embodiment, the processing module 1201 is further configured to acquire at least one third verification information and at least one fourth verification information, the third verification information and the fourth verification information being used to determine the consistency of the first key and the second key. The transceiver module 1202 is specifically configured to: send first information when the ratio of consistency verification information in the first verification information set and the second verification information set meets a preset condition, wherein the first verification information set includes first verification information and at least one third verification information, and the second verification information set includes second verification information and at least one fourth verification information, the first information being used to indicate at least one of the following: increasing the key verification length, decreasing the quantization threshold used to generate the key, or increasing the number of quantization bits used to generate the key.
[0207] In one embodiment, the processing module 1201 is further configured to determine the adjustment margin of the parameters based on the difference between the parameters of the first key and the corresponding preset parameter value, wherein the parameters include at least one of the following: the parameters of the verification key or the parameters of the generation key; or, to determine the adjustment margin of the parameters based on the difference between the parameters of the second key and the corresponding preset parameter value, wherein the parameters include at least one of the following: the parameters of the verification key or the parameters of the generation key; and to determine the first information based on the first verification information, the second verification information, and the adjustment margin of the parameters.
[0208] In one embodiment, the first information includes at least one of the following: an adjusted value for the parameters of the verification key, or an adjusted value for the parameters of the generation key; or, the first information includes at least one of the following: the adjusted value for the parameters of the verification key, or the adjusted value for the parameters of the generation key.
[0209] In one embodiment, the device is a first communication device.
[0210] In one embodiment, the device is a third communication device; the transceiver module 1202 is specifically used to send first information to the first communication device and the second communication device based on the first verification information and the second verification information, wherein the first communication device is a device for generating the first key and the second communication device is a device for generating the second key.
[0211] Figure 13 shows a structural diagram of a communication device 130, which is applied to a key negotiation device. Each module in the device shown in Figure 13 has the function of implementing the corresponding steps in the above method embodiments and can achieve its corresponding technical effect. The beneficial effects of each module performing the steps can be referred to the description of the corresponding steps in the above method embodiments, and will not be repeated here. The functions can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions. The communication device can be a key negotiation device or a chip or system-on-a-chip in the key negotiation device. For example, the device includes:
[0212] The transceiver module 1301 is used to send verification information of the second key, which is used to verify the consistency between the second key and the first key; the transceiver module 1301 is used to receive first information, which is used to instruct the adjustment of at least one of the following: parameters of the verification key or parameters of the generated key.
[0213] In one embodiment, the device further includes a processing module 1302 for generating a new key based on the first information.
[0214] In one embodiment, the parameters of the verification key include the key verification length, and the parameters of the generated key include: a quantization threshold for generating the key and / or the number of quantization bits for generating the key.
[0215] In one embodiment, the first information includes at least one of the following: an adjusted value for the parameters of the verification key, or an adjusted value for the parameters of the generation key; or, the first information includes at least one of the following: the adjusted parameters of the verification key, or the adjusted parameters of the generation key.
[0216] In one embodiment, the first information is used to indicate at least one of the following: increasing the key verification length, decreasing the quantization threshold used to generate the key, or increasing the number of quantization bits used to generate the key; or, the first information is used to indicate at least one of the following: decreasing the key verification length, increasing the quantization threshold used to generate the key, or decreasing the number of quantization bits used to generate the key.
[0217] This application embodiment also provides a communication system for a high-speed private network information transmission scenario in a neighboring area. The communication system may include a key negotiation device and a key verification device. The key negotiation device may have the functions of the aforementioned communication device 120, and the key verification device may have the functions of the aforementioned communication device 130.
[0218] This application also provides a computer-readable storage medium. All or part of the processes in the above method embodiments can be implemented by a computer program instructing related hardware. This program can be stored in the computer-readable storage medium, and when executed, it can include the processes of the above method embodiments. The computer-readable storage medium can be a communication device of any of the foregoing embodiments, such as an internal storage unit including a data transmitting end and / or a data receiving end, like a hard disk or memory of the communication device. The computer-readable storage medium can also be an external storage device of the communication device, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, etc., equipped on the communication device. Further, the computer-readable storage medium can include both the internal storage unit and the external storage device of the communication device. The computer-readable storage medium is used to store the computer program and other programs and data required by the communication device. The computer-readable storage medium can also be used to temporarily store data that has been output or will be output.
[0219] This application also provides computer instructions. All or part of the processes in the above method embodiments can be executed by computer instructions to instruct related hardware (such as computers, processors, network devices, and terminals). The program can be stored in the aforementioned computer-readable storage medium.
[0220] This application also provides a computer program product that, when run on a computer, causes the computer to perform various functions or steps performed by the communication device in the above method embodiments.
[0221] This application also provides a chip system. The chip system can be composed of chips or may include chips and other discrete devices, without limitation. The chip system includes a processor and a transceiver. All or part of the processes in the above method embodiments can be completed by this chip system. For example, the chip system can be used to implement the functions performed by the key verification device in the above method embodiments, or to implement the functions performed by the key negotiation device in the above method embodiments.
[0222] In one possible design, the chip system further includes a memory for storing program instructions and / or data. When the chip system is running, the processor executes the program instructions stored in the memory to enable the chip system to perform the functions performed by the key verification device or the key negotiation device in the above method embodiments.
[0223] In this embodiment of the application, the processor may be one or more central processing units (CPUs), which may include one or more of the following: a central processing unit (CPU), an application-specific integrated circuit (ASIC), a digital signal processor (DSP), a microprocessor unit (MPU), a microcontroller unit (MCU), a graphics processing unit (GPU), a field-programmable gate array (FPGA), an artificial intelligence processor (AI processor), or a neural processing unit (NPU).
[0224] When the processor is a CPU, the CPU can be a single-core CPU or a multi-core CPU. The processor can be a general-purpose processor, a digital signal processor, an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components, capable of implementing or executing the methods, steps, and logic block diagrams disclosed in the embodiments of this application. A general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this application can be directly manifested as being executed by a hardware processor, or executed by a combination of hardware and software modules within the processor.
[0225] In this application embodiment, the memory may include, but is not limited to, cache, read-only memory (ROM), random access memory (RAM), synchronous dynamic random access memory (SDRAM), hard disk drive (HDD) or solid-state drive (SSD), erasable programmable read-only memory (EPROM), or compact disc read-only memory (CD-ROM), etc. Memory is any other medium capable of carrying or storing desired program code having an instruction or data structure form and accessible by a computer, but is not limited thereto. The memory in this application embodiment may also be a circuit or any other device capable of implementing storage functions for storing computer programs or instructions, and / or data.
[0226] It should be noted that the terms "first" and "second," etc., in the specification, claims, and drawings of this application are used to distinguish different objects, not to describe a specific order. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to these processes, methods, products, or apparatuses.
[0227] It should be understood that in the embodiments of this application, "at least one (item)" refers to one or more, "more than one" refers to two or more, "at least two (items)" refers to two or three or more, and "and / or" is used to describe the association relationship of related objects, indicating that there can be three relationships. For example, "A and / or B" can represent: only A exists, only B exists, and A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the related objects before and after are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple. It should be understood that in the embodiments of this application, "B corresponding to A" means that B is associated with A. For example, B can be determined based on A. It should also be understood that determining B based on A does not mean determining B solely based on A; B can also be determined based on A and / or other information. Furthermore, the term "connection" in the embodiments of this application refers to various connection methods, such as direct or indirect connections, to achieve communication between devices; the embodiments of this application do not impose any limitations on this.
[0228] Unless otherwise specified, the term "transmission" in the embodiments of this application refers to bidirectional transmission, encompassing the actions of sending and / or receiving. Specifically, "transmission" in the embodiments of this application includes sending data, receiving data, or both sending and receiving data. In other words, data transmission here includes uplink and / or downlink data transmission. Data may include channels and / or signals; uplink data transmission refers to uplink channel and / or uplink signal transmission, and downlink data transmission refers to downlink channel and / or downlink signal transmission. The terms "network" and "system" in the embodiments of this application refer to the same concept; a communication system is a communication network.
[0229] Through the above description of the embodiments, those skilled in the art can clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.
[0230] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another device, or some features may be ignored or not executed. Furthermore, the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.
[0231] The units described as separate components may or may not be physically separate. A component shown as a unit can be one or more physical units; that is, it can be located in one place or distributed in multiple different locations. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0232] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit. If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of the embodiments of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This software product is stored in a storage medium and includes several instructions to cause a device, such as a microcontroller, chip, or processor, to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, ROM, RAM, magnetic disks, or optical disks.
[0233] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any changes or substitutions within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A communication method characterized by comprising: The method comprises: obtaining first check information of a first key and second check information of a second key, the first check information and the second check information being used to determine consistency of the first key and the second key; based on the first check information and the second check information, sending first information, the first information being used to indicate adjustment of at least one of the following: a parameter of a verification key or a parameter of a generated key.
2. The method of claim 1, wherein the parameter of the verification key comprises a key verification length; the parameter of the generated key comprises a quantization threshold for generating a key and / or a quantization bit number for generating a key.
3. The method according to claim 1 or 2, characterized in that, the first information is used to indicate at least one of the following: a decrease in the key verification length, an increase in the quantization threshold for generating a key, or a decrease in the quantization bit number for generating a key; alternatively, the first information is used to indicate at least one of the following: an increase in the key verification length, a decrease in the quantization threshold for generating a key, or an increase in the quantization bit number for generating a key.
4. The method according to any one of claims 1 to 3, characterized in that, the sending of the first information based on the first check information and the second check information comprises: in the case where the first check information and the second check information are inconsistent, sending the first information, the first information being used to indicate at least one of the following: a decrease in the key verification length, an increase in the quantization threshold for generating a key, or a decrease in the quantization bit number for generating a key.
5. The method according to any one of claims 1 to 3, characterized in that, The method further comprises: obtaining at least one third check information and at least one fourth check information, the third check information and the fourth check information being used to determine consistency of the first key and the second key; the sending of the first information based on the first check information and the second check information comprises: in the case where a proportion of consistent check information in a first check information set and a second check information set meets a preset condition, sending the first information, the first check information set comprising the first check information and the at least one third check information, the second check information set comprising the second check information and the at least one fourth check information, the first information being used to indicate at least one of the following: an increase in the key verification length, a decrease in the quantization threshold for generating a key, or an increase in the quantization bit number for generating a key.
6. The method according to any one of claims 1 to 5, characterized in that, The method further comprises: determining an adjustment margin of a parameter according to a difference between the parameter of the first key and a corresponding preset parameter value, the parameter comprising at least one of the following: a parameter of a verification key or a parameter of a generated key; or determining an adjustment margin of a parameter according to a difference between the parameter of the second key and a corresponding preset parameter value, the parameter comprising at least one of the following: a parameter of a verification key or a parameter of a generated key; determining the first information according to the first check information, the second check information, and the adjustment margin of the parameter.
7. The method according to any one of claims 1 to 6, characterized in that, the first information comprises at least one of the following: an adjustment value of the parameter of the verification key or an adjustment value of the parameter of the generated key; Or, the first information comprises at least one of: an adjusted value of the parameter of the verification key, or an adjusted value of the parameter of the generation key.
8. The method according to any one of claims 1 to 7, characterized in that, The method is applied to a first communication device; The method comprises: The first communication device acquires the first check information of the first key and the second check information of the second key, the first communication device being a communication device for generating the first key, and a communication device for generating the second key being a second communication device; The method comprises: The first communication device sends the first information to the second communication device based on the first check information and the second check information.
9. The method according to any one of claims 1 to 7, characterized in that, The method is applied to a third communication device; The method comprises: The third communication device sends the first information to the first communication device and the second communication device based on the first check information and the second check information, the first communication device being a device for generating the first key, and the second communication device being a device for generating the second key.
10. A communication method characterized by comprising: The method comprises: The method comprises: The method further comprises:
11. The method of claim 10, wherein, The method further comprises: The parameter of the verification key comprises a key verification length, and the parameter of the generation key comprises a quantization threshold for generating a key and / or a quantization bit number for generating a key.
12. The method according to claim 10 or 11, characterized in that, The first information comprises at least one of: an adjusted value of the parameter of the verification key, or an adjusted value of the parameter of the generation key.
13. The method according to any one of claims 10-12, characterized in that, The first information comprises at least one of: an adjusted value of the parameter of the verification key, or an adjusted value of the parameter of the generation key. The first information is used to indicate at least one of: increasing the key verification length, decreasing the quantization threshold for generating a key, or increasing the quantization bit number for generating a key.
14. The method according to any one of claims 10 to 13, characterized in that, The first information is used to indicate at least one of: decreasing the key verification length, increasing the quantization threshold for generating a key, or decreasing the quantization bit number for generating a key. The communication device comprises a processor for causing the communication device to perform the method according to any one of claims 1-14 by means of a logic circuit and / or by executing a program stored in a memory.
15. A communications device, characterized by The communication device comprises a processor for causing the communication device to perform the method according to any one of claims 1-14 by means of a logic circuit and / or by executing a program stored in a memory.
16. A communications device, characterized by The communication device comprises a processor for causing the communication device to perform the method according to any one of claims 1-14 by means of a logic circuit and / or by executing a program stored in a memory.
17. The communication apparatus according to claim 16, wherein 18. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer instructions that, when executed, cause the method of any of claims 1-14 to be performed.
19. A computer program product comprising instructions, characterized in that, When executed on a computer, cause the method of any of claims 1-14 to be performed.
Citation Information
Patent Citations
OFDM channel physical key generation method and device based on USRP and computer equipment
CN112533199A
Physical layer key consistency negotiation method and system based on channel estimation
CN114629647A
Underwater acoustic channel physical layer key generation method and system
CN115776370A
Key generation method and device, storage medium and computer equipment
CN115913510A
Encryption method and device based on channel secret key
CN116866900A