Method for key generation on the physical layer for multi-user wireless communication systems using a central node

WO2026201272A1PCT designated stage Publication Date: 2026-10-01CONSTR UNIV BREMEN GGMBH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/DE2026/100372
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-03-24
Filing Date
2026-03-24
Publication Date
2026-10-01

Smart Images

  • Figure DE2026100372_01102026_PF_FP_ABST
    Figure DE2026100372_01102026_PF_FP_ABST
Patent Text Reader

Abstract

The present invention discloses a method for key generation on a physical layer in a multi-user wireless communication system, wherein a central node (Alice) is connected to a plurality of peripheral nodes (Bobs) for the exchange of information and defines at least one reciprocal, continuous channel parameter, wherein a bit pattern is assigned to the channel parameter by quantisation, wherein the selection of a quantisation interval, in particular "Voronoi interval", and of the associated bit pattern is carried out randomly by Alice, wherein the central node (Alice) determines, by measurement, a paired, continuous channel parameter for each pairing of the central node (Alice) with each of the plurality of peripheral nodes (Bobs), and from this determines a shift and applies the determined shift to the particular reciprocal, continuous channel parameter such that all paired, continuous channel parameters lie within the quantisation interval randomly defined by the central node (Alice).
Need to check novelty before this filing date? Find Prior Art

Description

[0001] DE 102025 111 235.5 P02732

[0002] - 1 -

[0003] Method for key generation at the physical layer for multi-user wireless communication systems using a central node

[0004] The present invention relates to a method for key generation at the physical layer for multi-user wireless communication systems using a central node and, in particular, provides an optimized, group-based mechanism for generating secret keys with low implementation effort, designed for networks with a star topology. In contrast to traditional approaches based on pairwise key agreement and matching, the proposed method directly generates a secret group key, thereby eliminating the need for intermediate, pairwise keys. This innovation effectively reduces computational complexity, communication overhead, and latency, making it particularly suitable for resource-constrained environments such as Internet of Things (IoT) networks.

[0005] With the widespread adoption of wireless communication devices, ensuring secure data transmission has become increasingly critical. The inherent propagation characteristics of wireless signals expose networks to potential eavesdropping and active attacks, necessitating robust cryptographic key generation techniques.

[0006] Prior art key exchange protocols such as Diffie-Hellman are based on the assumption of the computational difficulty of certain problems for securing symmetric key exchange. However, the advent of quantum computing technology poses a fundamental threat to these methods, as quantum algorithms, particularly Shor's algorithm, can efficiently solve the underlying mathematical problems, thereby compromising security. Furthermore, the computationally and energetically intensive nature of conventional cryptographic methods makes them unsuitable for DE 102025 111 235.5 P02732

[0007] - 2 -

[0008] Resource-constrained devices such as embedded sensors, IoT nodes, and RFID tags are unsuitable.

[0009] US patent 2023 / 0171096 discloses a method for pairwise key generation for wireless channels. Keys are generated from reciprocal channel characteristic parameters, checked for correlation, and replaced if necessary. The keys are then stored in a key buffer until a predetermined number is reached.

[0010] German patent DE 10 2020 107 195 discloses a key generation device, a mobile communication device, and associated methods. The key generation device comprises a filter bank with multiple filters for identifying radio signal components of one or more radio signals, as well as one or more processors for generating a key based on these radio signal components. The patent is based on the obvious fact that key generation can be performed in the time domain, the frequency domain, and also in other transformation domains, e.g., wavelets, possibly with suitable filtering or filter banks. The necessary reciprocity is ensured by the channel and is also maintained after such operations.

[0011] German patent DE 10 2022 127 318 discloses a method for generating cryptographic keys from the transmission functions of channels between multiple user nodes. This method assumes a ring structure of user nodes. By using a ring transmission function, all users receive the same key, regardless of the starting node or the direction of travel.

[0012] Physical Layer Key Generation (PLKG) addresses these limitations by leveraging the reciprocity and inherent randomness of wireless channels to establish shared cryptographic keys. PLKG utilizes key-relevant channel characteristics such as Channel State Information (CSI) and Received Signal Strength (RSS) to provide robustness across different wireless environments. DE 102025 111 235.5 P02732

[0013] - 3 -

[0014] to ensure. PLKG has been extensively studied for both Time Division Duplex (TDD) and Frequency Division Duplex (FDD) systems, primarily in pairwise scenarios.

[0015] In practical applications, multi-user key generation has become increasingly important for a wide range of systems, including secure group communication, ad-hoc networks, and collaborative structures such as sensor arrays, industrial automation networks, and IoT ecosystems. These applications require the creation of shared cryptographic keys across multiple nodes to enable secure communication and ensure data integrity within the group. Therefore, the development of efficient and scalable key generation mechanisms for various network topologies is crucial.

[0016] Group-based key generation is inherently more complex than pairwise key generation because it requires precise coordination and synchronization of all participating nodes. A key challenge is ensuring key consistency, as all nodes must derive identical cryptographic keys despite potential differences in channel conditions, measurement noise, and device capabilities. Furthermore, such systems must consider practical limitations, including limited resources, energy efficiency, and the need to maintain robust security against both internal and external threats.

[0017] All conventional methods for group key generation require the prior establishment of pairwise keys. In a star topology, for example, this means that the central node independently generates a pairwise key for each peripheral node. This process typically involves channel probing, quantization, and key matching for each individual pair connection. Once all pairwise keys have been generated, the central node derives the group key from the obtained keys and then distributes it to the peripheral nodes via a predefined distribution mechanism.

[0018] - 4 -

[0019] peripheral nodes. This method was investigated as a standard and potential benchmark approach in the following publication:

[0020] Y. Wei, C. Zhu and J. Ni, "Group Secret Key Generation Algorithm from Wireless Signal Strength," 2012 Sixth International Conference on Internet Computing for Science and Engineering, Zhengzhou, China, 2012, pp. 239-245, doi: 10.1109 / ICICSE.2012.64.

[0021] A star topology is considered, featuring a central node called "Alice" and M peripheral nodes designated Bi, B2, ..., BM, called "Bobs". During the channel probing phase, the central node performs bidirectional channel measurements with each peripheral node individually. The bidirectional measurement between Alice and the / th Bob is represented as / 77A / on the Alice side and as / T?B / on the Bob side.

[0022] Alice and all the Bobs then quantize their respective measurements using a linear, lossless quantization scheme that provides a uniform quantization pattern with 2 nQuantization intervals are used. Each quantization interval is assigned a bit code according to a Gray coding scheme. For example, the key generated between Alice and the / th Bob is represented as KBI = GC(q( / 7?B / )) and KM = GC(q( / 7?A / )), where GC(.) denotes the Gray coding function and q(.) denotes the corresponding linear quantization function. Consequently, an initial version of the pairwise cryptographic keys is established between Alice and the Bobs. The corresponding linear quantization approach and Gray code mapping for generating pairwise keys are detailed in the following reference:

[0023] E. Olyaei Torshizi and W. Henkel, "Pairwise Physical Layer Secret Key Generation for FDD Systems," in IEEE Transactions on Information Forensics and Security, vol. 19, pp. 9518-9533, 2024, doi: 10.1109 / TIFS.2024.3468170.DE 102025 111 235.5 P02732

[0024] - 5 -

[0025] Measurement errors caused by hardware imperfections and uncorrelated noise at both ends lead to key discrepancies and pose a challenge to secure communication. These discrepancies result in deviations in the key sequences KBI and KM, which are quantified by the Key Disagreement Rate (KDR). To address this problem, key matching protocols are used to precisely align the keys between the communicating parties. These protocols not only mitigate information leaks but also ensure reliable correction of mismatches.

[0026] Key matching methods have been extensively studied within the framework of Slepian-Wolf coding, which utilizes principles of distributed source coding for efficient error correction. These include low-density parity-check (LDPC) codes, which are considered among the most effective error-correcting codes and were examined from this perspective in the following publication:

[0027] N. Islam, 0. Graur, A. Filip, and W. Henkel, "LDPC code design aspects for physical layer key reconciliation," 2015 IEEE Global Communications Conference (GLOBECOM), San Diego, CA, 2015, doi: 10.1109 / GLOCQM.2015.7417119.

[0028] Although coding-based key matching methods improve key generation performance, they are computationally complex, result in high latency, and require additional resources due to encoding and decoding. In contrast, non-coding-based approaches offer a simpler and faster alternative but may be less robust against errors. One such approach is explored in the following publications:

[0029] E. Olyaei Torshizi and W. Henkel, "Exploiting FDD Channel Reciprocity for Physical Layer Secret Key Generation in loT Networks," IEEE Communications Letters, vol. 28, no. 6, pp. 1268-1272, June 2024, doi: 10.1109 / LCQMM.2024.3388160.DE 102025 111 235.5 P02732

[0030] - 6 -

[0031] J. Wallace, "Secure Physical Layer Key Generation Schemes: Performance and Information Theoretic Limits," 2009 IEEE International Conference on Communications, Dresden, Germany, 2009, pp. 1-5, doi: 10.1109 / ICC.2009.5199440.

[0032] After the key reconciliation is complete, the corrected versions of the shared keys between Alice and the 7th Bob are designated K and B7. Let Ki = K = KB / ' be the shared key that Alice and the 7th Bob share. Alice then generates the group key KG by performing a bitwise exclusive-OR (XOR) operation on all pairwise keys for 7 = 1, ..., M, expressed as:

[0033] KG = i © K2 © ... © KM.

[0034] The central node then securely distributes the generated group key KG to each Bob individually. Specifically, the central node sends KG © Kj to the nth Bob. Upon receiving this message, the 7th Bob obtains the group key by performing a bitwise XOR operation between the received value KG © Ki and its own key, K, thereby deriving the group key KG.

[0035] The use of similar methods that rely on generating and using pairwise keys to derive the group key results in unnecessary time and energy consumption for group users. Furthermore, as the number of peripheral nodes increases, the required time, computational complexity, and overhead also increase, which can reduce the key generation rate (KGR).

[0036] As an alternative approach, this paper presents a cooperative group key generation algorithm with a star topology, employing a central node and a reference node. After channel estimation, the central node uses secure network coding to help all group members exploit the randomness of the reference channel, enabling them to agree on a secret key in a single information-matching phase. DE 102025 111 235.5 P02732

[0037] - 7 -

[0038] S. Xiao, Y. Guo, K. Huang and L. Jin, "Cooperative Group Secret Key Generation Based on Secure Network Coding," in IEEE Communications Letters, vol. 22, no. 7, pp. 1466-1469, July 2018, doi: 10.1109 / LCOMM.2018.2831703.

[0039] This approach shows that as the number of group members increases, the achievable key rate decreases due to lower correlation between channel observations. Furthermore, each member must estimate and process the reference channel in addition to sampling the central node, which further increases complexity. Errors in channel estimation can also affect the accuracy of key generation.

[0040] The purpose of the invention is to improve the state of the art.

[0041] The problem is solved by a key generation method on a physical layer in a multi-user wireless communication system, wherein a central node (Alice) is connected to a plurality of peripheral nodes (Bobs) for information exchange and defines at least one reciprocal continuous channel parameter, wherein a bit pattern is assigned to the channel parameter by quantization, wherein the selection of a quantization interval by Alice, in particular “Voronoi intervals”, and the associated bit pattern is random, wherein the central node (Alice) determines a pairwise continuous channel parameter for each pairing of the central node (Alice) with each of the plurality of peripheral nodes (Bobs) and determines a shift from this and imposes the determined shift on the respective reciprocal continuous channel parameter, such that all pairwise continuous channel parameters within thefrom the central node (Alice), randomly determined quantization interval.

[0042] Advantageously, the method according to the invention provides an optimal, group-based mechanism for generating secret keys DE 102025 111 235.5 P02732

[0043] - 8 -

[0044] This is provided. Furthermore, it is advantageously particularly suitable for use in networks with a star topology.

[0045] In contrast to conventional approaches that rely on pairwise key agreement and matching, the proposed method advantageously generates a group secret key directly without the need for pairwise keys, thereby reducing computational complexity, communication overhead, and latency.

[0046] In this method, the central node (Alice) randomly selects a quantization interval from a Gray-coded codebook and ensures that all peripheral nodes (Bobs) derive the same key by transmitting a corresponding shift value. This approach eliminates the need for traditional, code-based key matching while simultaneously providing security against eavesdropping. Furthermore, the method can be extended to a chained key generation process, which increases entropy and randomness without requiring multiple channel samples, thereby further improving key generation efficiency.

[0047] The method according to the invention also advantageously ensures key consistency. Furthermore, the method advantageously generates a secret group key directly. Thus, there is advantageously no need for pairwise keys. This advantageously reduces computational complexity and communication overhead. Finally, the method according to the invention also advantageously reduces latency, making it particularly suitable for resource-constrained environments such as Internet of Things (IoT) networks. Therefore, the method according to the invention advantageously addresses practical limitations such as limited resources, energy efficiency, and the need to maintain robust security against both internal and external threats. DE 102025 111 235.5 P02732

[0048] - 9 -

[0049] The invention is particularly suitable for resource-constrained environments such as IoT networks, industrial automation, and secure group communication. By offering a simple, low-cost, and energy-efficient alternative to traditional cryptographic protocols and existing group key generation methods at the physical layer, this method maintains security while minimizing system overhead and latency.

[0050] The following terms will be explained:

[0051] Key generation refers specifically to a process by which cryptographic keys can be generated between nodes. This involves using measurements or parameters of the communication channel to derive a shared, secure key.

[0052] A "physical layer" is specifically the layer of a communication system where bits are directly sent and received via the transmission medium. In other words, it provides the physical basis for data transmission. In this context, channel parameters are measured at this layer in order to derive keys.

[0053] A "multi-user wireless communication system" is understood to be, in particular, a wireless communication system in which several participant nodes interact with each other. Key generation, according to the inventive method, takes place, in particular, between a central node (Alice) and several peripheral nodes (Bobs).

[0054] The "central node," also called Alice, is a main node that initiates key generation. Alice specifically selects random group bit patterns and defines quantization regions for the channel parameters. It also or alternatively controls the adjustment of the DE 102025111 235.5 P02732

[0055] - 10 -

[0056] Parameter values ​​for the peripheral nodes, in particular to ensure shared keys.

[0057] Peripheral nodes, also called Bobs, are nodes that communicate with the central node (Alice). They are specifically designed to measure channel parameters and derive keys from these measurements.

[0058] A "bit pattern," also called a group bit pattern, is in particular a randomly selected bit pattern that serves as a reference for the shift ranges of the channel parameters. The bit pattern corresponds specifically to a quantization interval, or results from a numbering of quantization intervals. Using the bit pattern ensures, in particular, that all nodes derive the same key.

[0059] A "quantization interval" is understood to be, in particular, an interval of a channel parameter that corresponds to or is assigned to a specific bit pattern. Every channel value that falls within this region is essentially mapped to the same bit pattern. This allows, in particular, different nodes to derive identical keys from the same channel values.

[0060] A "channel parameter" is understood to be, in particular, a physical or statistical quantity that describes the properties of a transmission channel and can be measured or estimated from received signals. This includes, in particular, time- and / or frequency-dependent quantities such as amplitude, phase, attenuation, propagation delay, or channel impulse response. The channel parameter can be continuous and is typically mapped to discrete values ​​during processing by sampling and / or quantization. In the context of the invention, the channel parameters are used, in particular, because of their reciprocity, whereby common secret keys are derived from correlated measurements at the transmitter and receiver. Quantization advantageously enables stable key derivation despite disturbances, especially noise. DE 102025111 235.5 P02732

[0061] - 11 -

[0062] In this context, "reciprocal" means, in particular, that a channel parameter is the same in both directions between two nodes. Specifically, this means that the value Alice measures for communicating with Bob matches the value Bob measures for communicating with Alice.

[0063] A "channel parameter shift" refers specifically to the adjustment of the measured value initiated by Alice. This adjustment is made to ensure that the parameter value for the Bobs lies within the quantization region chosen by Alice.

[0064] In the present invention, the conventional group key generation process is significantly streamlined by eliminating the need for pairwise key generation and additional channel estimation phases. After the channel sampling phase between Alice and several Bobs, Alice randomly selects a quantization interval and assigns its corresponding Gray code as the group key.

[0065] KG = GC( G) = GC(rand(qi, <72, ... , 2n)) (Equation (1)),

[0066] where rand(.) is a random selection function that randomly selects one of the quantization intervals.

[0067] In a conventional approach, Alice performs a key matching with each Bob in turn, obtaining individual pairwise keys. She then generates the group key by applying an XOR operation to all matched keys and securely distributes the group key to each Bob, ensuring no information reaches Eve. Ensuring an even distribution of the group key is a critical challenge, typically addressed through post-processing techniques or the use of nonlinear quantization schemes, as explored in the following publication: DE 102025 111 235.5 P02732

[0068] - 12 -

[0069] E. 0. Torshizi and W. Henkel, "Reciprocity and Secret Key Generation for FDD Systems using Non-Linear Quantization," 2022 IEEE Globecom Workshops (GC Wkshps), Rio de Janeiro, Brazil, 2022, pp. 927-932, doi: 10.1109 / GCWkshps56602.2022.10008695.

[0070] Obviously, such an approach leads to considerable complexity and latency in the system. In contrast, the present invention eliminates the need for Alice to generate the group key or to have concerns about its uniform distribution, since she selects this group key randomly. Furthermore, the invention integrates the key matching between Alice and all Bobs, as well as the distribution of the group key to all Bobs, in a single phase, which significantly reduces both complexity and latency.

[0071] To achieve this, Alice, after randomly selecting the group key, transmits auxiliary data to each Bob individually. This auxiliary data allows each Bob to compare their measurement with Alice's and simultaneously provides a clue for deriving the group key. Specifically, this process involves transmitting a required shift value, which each Bob applies to their channel observation to align it with the quantization interval corresponding to the randomly selected group key. This approach is simple and uncomplicated, analogous to a party scenario where a host (Alice) gives each guest (Bob) an individual directional pointer to find the venue (corresponding to the quantization interval of the group key).This pointer represents a shift value that each Bob must apply to their channel observation to achieve alignment within the specified quantization interval of the group key. It is noteworthy that only if a given Bob has a sufficiently correlated measurement with Alice will the received shift value allow them to identify the correct quantization interval of the group key.

[0072] Further embodiments are described in the dependent claims. DE 102025 111 235.5 P02732

[0073] - 13 -

[0074] The invention will now be explained using exemplary embodiments. These will show...

[0075] Figure 1 shows a schematic representation of quantization intervals in a polar representation as well as Gray codes.

[0076] Figure 2 is a flowchart of the method according to the invention,

[0077] Figure 3 is a schematic representation of a star topology.

[0078] Figure 4 shows a schematic representation of a linear quantization scheme, and

[0079] Figure 5 shows a flowchart of the inventive method with variable assignment.

[0080] For further clarification, it is assumed that the reciprocal property used for key generation is phase-related (e.g., absolute phase, phase difference, or on-beam Z-radiation direction) and that the full 2iT variation range is considered. Figure 1 and the accompanying table illustrate the quantization intervals in a polar representation and the Gray codes assigned to each interval.

[0081] Let / 77A / be the joint measurement between Alice and the / -th Bob on Alice's side, and let G be the quantization interval for the group key, chosen randomly by Alice. Assuming that the reciprocal property is derived from phase information with a maximum value of 2TT, Alice calculates the required shift value for the / -th Bob as follows:

[0082] S

[0083]

[0084] At = ~ m At equation (2)

[0085] Alice then publicly transmits the calculated shift value to each individual Bob. Upon receiving this value, the Zth Bob adjusts his measurement as follows:

[0086]

[0087] m'g. £ +6A £ .

[0088] Equation (3)DE 102025 111 235.5 P02732

[0089] - 14 -

[0090] The matched measurement is then quantized by Bob to obtain the group key:

[0091] K

[0092]

[0093] J = GC ) •

[0094] Equation (4)

[0095] Peripheral nodes with insufficiently correlated measurements to Alice are unable to derive the correct group key, effectively filtering out unreliable nodes. This automatic filtering process ensures that only nodes with high channel correlation to Alice gain access to the group key.

[0096] Figure 2 shows a detailed diagram illustrating the proposed group-wise key generation process between Alice A and the various Bobs B / . The figure exemplifies the process between Alice and two Bobs. The procedure for two Bobs is shown in more detail in Figure 5.

[0097] During the transmission phase of the shift values, Alice can implement a partial cooperation strategy, configuring herself to withhold or modify the required shift value for less reliable peripheral nodes. This approach also facilitates the targeted introduction of deviations, particularly as a countermeasure against detected spoofing attempts by one or more peripheral nodes.

[0098] To increase the group key generation rate (KGR) and the randomness of the resulting group keys, Alice can generate longer group keys by randomly combining two or more group keys. g i, K g 2, Kgm selects and concatenates them as follows:

[0099] K

[0100]

[0101] G = K5I||K 52||---||VI Equation (5)DE 102025 111 235.5 P02732

[0102] - 15 -

[0103] To further illustrate this, consider a scenario in which Alice randomly selects two 3-bit Gray codes, Kg\ and K. g It selects two bits and combines them into a 6-bit group key. By using 6 bits instead of 3, the number of possible key outcomes increases by a factor of 2. 3 Consequently, Alice receives 64 possible keys instead of 8 – an eightfold increase, which increases randomness and makes the group key significantly more unpredictable for potential attackers (Eves). Furthermore, this approach effectively doubles the entropy of the generated keys. In cryptographic systems, higher entropy corresponds to increased security, as attackers have to search through a significantly larger key space.

[0104] In this case, Alice must give each Bob two different displacement values ​​- one to translate his measurements to Kg and the other to translate them to K g 2. However, a crucial advantage of this method is that Alice does not need to measure the channel multiple times to create a chained group key. Instead, with a single channel sample per Bob, Alice can determine the required shift values ​​for several randomly selected keys and generate longer keys without having to perform further channel measurements. Furthermore, Alice may also be able to reuse the channel measurements for subsequent rounds of group key generation, simply by changing the randomly selected group keys. These features significantly reduce system complexity while improving randomness and KGR compared to existing solutions.

[0105] The following example serves to further illustrate the invention, without limiting its scope:

[0106] Consider a wireless system consisting of a central node Alice and three peripheral nodes Bob1, Bob2, and Bob3, arranged in a star topology (see Figure 3). A linear quantization scheme, also called a quantization interval, with eight quantization intervals and the DE 102025 111 235.5 P02732

[0107] - 16 -

[0108] The corresponding 3-bit Gray coding assigned to each interval is shown in Figure 4. Alice's measurements for Bob1, Bob2, and Bob3 are denoted as μA2, μRrA3, and mA3, respectively.

[0109] In this example, as shown in Figure 4, Alice selects two keys. gi = 101 and K g 2 = 001, and generates the final group key by concatenating them:

[0110]

[0111] K G = = loiooi

[0112] Accordingly, the final group key is 6 bits long and consists of two 3-bit segments. For all Bobs to be able to reconstruct the group key, Alice must provide each Bob with a shift value for each segment. In other words, Alice determines two shift values ​​for each Bob—one based on K. g and another one based on K g 2, which ensures that all Bobs adjust their measurements so that they fall within the respective quantization intervals q g and q g 2 lie.

[0113] The shift value for the / -th bob, which corresponds to the y-th part of the final

[0114] Group key corresponds to

[0115]

[0116] '- 4 / . These displacement values ​​are also shown in Figure 4.

Claims

DE 102025 111 235.5 P02732 - 17 - REQUIREMENTS 1. A method for key generation at a physical layer in a multi-user wireless communication system, characterized in that a central node (Alice) is connected to a plurality of peripheral nodes (Bobs) for information exchange and defines at least one reciprocal continuous channel parameter, wherein a bit pattern is assigned to the channel parameter by quantization, wherein the selection of a quantization interval, in particular a “Voronoi interval”, and the associated bit pattern is performed randomly by Alice, wherein the central node (Alice) determines a pairwise continuous channel parameter for each pairing of the central node (Alice) with each of the plurality of peripheral nodes (Bobs) and determines a shift from this, and imposes the determined shift on the respective reciprocal continuous channel parameter and / or the quantization interval, such that all pairwisecontinuous channel parameters lie within the quantization interval randomly determined by the central node (Alice).

2. A method for key generation on the physical layer according to claim 1, characterized in that the reciprocal continuous channel parameter is a phase, a phase difference, an amplitude, an arrival time, an incoming or outgoing direction or any other derived quantity of the channel transfer function which has reciprocity such that there is a symmetry between transmission directions Alice-to-Bob and Bob-to-Alice.

3. A method for key generation at the physical layer according to one of the preceding claims, characterized in that the shift is implemented in the direction of the center of the quantization interval randomly selected by Alice. DE 102025 111 235.5 P02732 - 18 - 4. Method for key generation on the bit transmission layer according to one of the preceding claims, characterized in that the shift is imposed exclusively on the respective reciprocal, continuous channel parameter.

5. Method for key generation on the bit transmission layer according to one of the preceding claims, characterized in that the shift is imposed exclusively on the quantization interval.

6. A method for key generation on the physical layer according to one of the preceding claims, characterized in that the mapping between quantization intervals and bit patterns is chosen as Gray code.

7. Method for key generation at the physical layer according to claim 3, characterized in that the center of the quantization interval is held at a predefined distance from the center of the quantization interval after the shift, so that key agreement performance for predefined nodes is weakened and / or completely prevented.

8. A method for key generation at the bit transmission layer according to one of the preceding claims, characterized in that several key segments are generated by Alice selecting new random bit patterns and associated quantization intervals and determining and imposing new shifts using the already known reciprocal pairwise channel parameters, wherein the pairwise channel parameters are used multiple times to generate new key segments.

9. Method for key generation at the bit transmission layer according to one of the preceding claims, characterized in that the random selection of the quantization interval of Alice can be made such that DE 102025111 235.5 P02732 - 19 - Any desired distribution of bit patterns and quantization intervals can be satisfied.