WO2018121756A1 - 一种提取信道特征的方法及网络设备 - Google Patents

一种提取信道特征的方法及网络设备 Download PDF

Info

Publication number
WO2018121756A1
WO2018121756A1 PCT/CN2017/119956 CN2017119956W WO2018121756A1 WO 2018121756 A1 WO2018121756 A1 WO 2018121756A1 CN 2017119956 W CN2017119956 W CN 2017119956W WO 2018121756 A1 WO2018121756 A1 WO 2018121756A1
Authority
WO
WIPO (PCT)
Prior art keywords
network device
pairing
channel
data packet
channel feature
Prior art date
Application number
PCT/CN2017/119956
Other languages
English (en)
French (fr)
Inventor
陈东
杨超
张军
孙军平
胡亨捷
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Publication of WO2018121756A1 publication Critical patent/WO2018121756A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0861Generation of secret information including derivation or calculation of cryptographic keys or passwords
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W24/00Supervisory, monitoring or testing arrangements
    • H04W24/08Testing, supervising or monitoring using real traffic

Definitions

  • the present invention relates to the field of communications, and in particular, to a method and a network device for extracting channel characteristics.
  • the packet interaction and the logical control mechanism are first used to extract the characteristics of the wireless channel.
  • the time interval ⁇ of transmitting and receiving the dual-channel recording channel feature information is an important parameter for measuring the correlation of the channel feature samples. The smaller the ⁇ is, the stronger the correlation of the channel feature samples is, and the subsequent generation is based on the sample. The key accuracy is also higher.
  • the packet interaction and logic control mechanisms employed by the wireless channel feature sample extraction technique are based on the network layer ping tool. Due to the routing and protocol control processes of the network layer and the retransmission confirmation mechanism after the network side data packets reach the link layer, the feature sample time interval ⁇ is greatly increased, and the sample correlation when extracting the wireless channel features is not high.
  • the embodiment of the invention provides a method for extracting channel characteristics and a network device, which solves the problem that the sample correlation is not high and the extraction rate is too slow when extracting the characteristics of the wireless channel.
  • the embodiment of the present invention provides a method for extracting a channel feature, including: a first network device receiving a reference data packet sent by a second network device at a link layer; and a first network device extracting the first according to the reference data packet Channel characteristics between the network device and the second network device.
  • the method for extracting channel features provided by the embodiment of the present invention, because the reference data packets used for extracting channel characteristics are interacted at the link layer, and the routing, protocol control, and the like are omitted compared to the network layer interaction data packet, which can simplify the data packet.
  • the interaction process greatly reduces the time interval for transmitting and receiving dual-issue channel features, that is, reducing the feature sample time interval.
  • the key feature is used to generate the key encryption communication, the correlation of the channel feature samples can be well increased, and the accuracy and extraction rate of the key are improved.
  • the first network device and the second network device are mutually communicating with each other.
  • the first network device may be a sender in communication, and the second network device feeds back the response data packet of the probe data packet by transmitting the probe data packet to the second network device, that is, the reference data packet.
  • the first network device may be a receiving party in the communication, and the receiving second network device sends the probe data packet, that is, the reference data packet, and feeds back the response data packet of the probe data packet to the second network device.
  • the method for extracting a channel feature may further include: the first network device generates a beacon data packet, and sends the beacon data packet to the second network device by using a link layer. Sending a beacon packet; the reference packet is a response packet of the beacon packet.
  • the method may further The method includes: the first network device sends a response data packet of the reference data packet to the second network device by using the link layer; and the response data packet of the reference data packet is used to indicate that the first network device has successfully received the reference data packet.
  • the beacon data packet may include a link layer management frame. Since the management layer of the link layer in 802.11 does not have the interference of the retransmission control mechanism and the acknowledgment mechanism, the time interval for transmitting and receiving dual-issue channel features is further reduced, that is, the feature sample time interval is reduced, and the correlation of channel feature samples is increased. Sexuality, when the key feature is used to generate key encryption communication, the accuracy of the key is better improved.
  • the first network device generates the beacon data packet, and sends the beacon data packet to the second network device by using the link layer. Thereafter, the method may further include: if the first network device does not receive the beacon data packet within a preset time period from when the first network device sends the beacon data packet to the second network device through the link layer In response to the data packet, the first network device retransmits the beacon data packet to the second network device through the link layer. To ensure effective interaction of reference packets.
  • the foregoing channel feature may include channel state information (CSI), and the CSI is included in the reference data packet.
  • the CSI includes feature information of each subchannel in the channel between the first network device and the second network device.
  • the first network device extracts, according to the reference data packet, a channel feature between the first network device and the second network device, where the first network device performs multi-channel sample sensing on the reference data packet to obtain the first network device and A feature of each subchannel between the second network devices.
  • the efficiency of extracting channel features is improved, thereby greatly increasing the key generation rate.
  • the method may further include: the first network device performs channel feature pairing between the first network device and the second network device with the second network device according to the pairing reference information.
  • the pairing reference information includes a timestamp for extracting a channel feature, and the channel feature corresponding to the timestamp with the smallest time interval is a pair of channel features; or the pairing reference information includes a pairing sequence number in the reference data packet for extracting the channel feature, and the pairing sequence
  • the channel characteristics extracted by the same packet are a pair of channel characteristics.
  • channel feature samples paired with each other in the transmitting and receiving parties are used as the same generating factor when the transmitting and receiving parties generate a key according to the channel feature samples.
  • a specific pairing process is provided when the pairing reference information includes a timestamp for extracting channel characteristics.
  • the first network device performs the pairing of the channel characteristics between the first network device and the second network device with the second network device according to the pairing reference information, where the first network device records the first timestamp, and the first timestamp is first.
  • the network device extracts a system time of a channel feature between the first network device and the second network device, the first network device sends a first timestamp to the second network device, where the first timestamp is used by the second network device to use the second network device And extracting channel characteristics between the first network device and the second network device, and matching channel characteristics between the first network device and the second network device extracted by the first network device.
  • the first network device records a first timestamp, where the first timestamp is a system time for the first network device to extract a channel feature between the first network device and the second network device, and the first network device is configured according to the pairing reference information.
  • the second network device performs the channel feature pairing between the first network device and the second network device, where the first network device receives the second timestamp sent by the second network device, and the second timestamp is extracted by the second network device.
  • the system time of the channel feature between the first network device and the second network device, the first network device selects a channel feature between the first network device and the second network device with the smallest time interval between the extracted timestamp and the second timestamp, and And matching channel characteristics between the first network device extracted by the network device and the second network device.
  • the reference data packet includes a pairing sequence number, and the pairing sequence number in the reference data packet in which the pairing reference information includes the extracted channel feature is provided.
  • the specific pairing process the first network device performs the channel feature pairing between the first network device and the second network device with the second network device according to the pairing reference information, which may be implemented as follows: the first network device receives the second network. And the second network device sends a pairing sequence number of the at least one data packet of the channel feature between the first network device and the second network device, where the first network device extracts the first network device according to the pairing sequence number.
  • the channel feature between the network device and the second network device is paired with a channel feature between the first network device and the second network device extracted by the second network device.
  • the reference data packet includes a pairing sequence number, and the pairing sequence number in the reference data packet in which the pairing reference information includes the extracted channel feature is provided.
  • the specific pairing process the first network device performs the channel feature pairing between the first network device and the second network device with the second network device according to the pairing reference information, which may be implemented as: the first network device is connected to the second network.
  • the channel feature between the network device and the second network device is paired with the channel feature between the first network device and the second network device extracted by the first network device.
  • the channel feature that is not paired successfully may be removed.
  • the embodiment of the present invention provides a method for extracting a channel feature, which specifically includes: a first network device receives a reference data packet sent by a second network device; and the first network device extracts the first network device according to the reference data packet.
  • the pairing reference information includes a timestamp of extracting the channel feature, The channel feature corresponding to the timestamp with the smallest time interval is a pair of channel features; or the pairing reference information includes the pairing sequence number in the reference data packet for extracting the channel feature, and the channel feature extracted by the same paired sequence number is a pair of channels. feature.
  • the method for extracting channel features provided by the embodiment of the present invention, by pairing channel characteristics between the two transmitted and received dual-issues, ensures sample pairing of channel features in case of packet loss and retransmission, and improves channel feature samples. Relevance.
  • the key feature is used to generate the key encryption communication, the correlation of the higher channel feature samples ensures the accuracy of the key.
  • a specific pairing process is provided when the pairing reference information includes a timestamp for extracting channel characteristics.
  • the first network device performs channel feature pairing between the first network device and the second network device with the second network device according to the pairing reference information, which may be implemented by: the first network device recording the first timestamp.
  • the first timestamp is a system time for the first network device to extract a channel feature between the first network device and the second network device, and the first network device sends a first timestamp to the second network device, where the first timestamp is used for the second timestamp.
  • the network device pairs the channel feature between the first network device and the second network device extracted by the second network device with the channel feature between the first network device and the second network device extracted by the first network device.
  • the first network device performs the channel feature pairing between the first network device and the second network device with the second network device according to the pairing reference information, which may be implemented as follows: the first network device records the first time.
  • the first network device performs the pairing of the channel characteristics between the first network device and the second network device according to the pairing reference information, where the first network device receives the second network device to send the second a timestamp, the second timestamp is a system time of a channel feature between the first network device and the second network device extracted by the second network device, and the first network device selects a first network with the smallest time interval between the extracted timestamp and the second timestamp
  • the channel feature between the device and the second network device is paired with the channel feature between the first network device and the second network device extracted by the second network device.
  • the reference data packet includes a pairing sequence number, and the pairing sequence number in the reference data packet in which the pairing reference information includes the extracted channel feature is provided.
  • the specific pairing process the first network device performs the channel feature pairing between the first network device and the second network device with the second network device according to the pairing reference information, which may be implemented as follows: the first network device receives the second network. And the second network device sends a pairing sequence number of the at least one data packet of the channel feature between the first network device and the second network device, where the first network device extracts the first network device according to the pairing sequence number.
  • the channel feature between the network device and the second network device is paired with a channel feature between the first network device and the second network device extracted by the second network device.
  • the reference data packet includes a pairing sequence number, and the pairing sequence number in the reference data packet in which the pairing reference information includes the extracted channel feature is provided.
  • the specific pairing process the first network device performs the channel feature pairing between the first network device and the second network device with the second network device according to the pairing reference information, which may be implemented as: the first network device is connected to the second network.
  • the channel feature between the network device and the second network device is paired with the channel feature between the first network device and the second network device extracted by the first network device.
  • the first network device receives the reference data packet sent by the second network device, and may be implemented as: the first network device is in the chain
  • the layer layer receives the reference data packet sent by the second network device. Since the reference data packets used to extract the channel characteristics are interacted at the link layer, the routing, protocol control, and the like are omitted compared to the network layer interaction data packet, which can simplify the interaction process of the data packet and greatly reduce the dual-issue extraction channel.
  • the time interval of the feature that is, the feature sample time interval is reduced.
  • the foregoing channel feature includes CSI.
  • the first network device receives, at the link layer, the reference data packet sent by the second network device, where the CSI is included in the reference data packet, where the CSI includes each of the channels between the first network device and the second network device. Characteristic information of the channel. Specifically, the first network device extracts a channel feature between the first network device and the second network device according to the reference data packet, where the first network device performs multi-channel sample sensing on the reference data packet to obtain the first network. A characteristic of each subchannel between the device and the second network device. By extracting the sample features of the subchannels, the efficiency of extracting channel features is improved, thereby greatly increasing the key generation rate.
  • an embodiment of the present invention provides a network device, where the network device includes: a receiving unit, configured to receive a reference data packet sent by a peer network device at a link layer, and an extracting unit, configured to receive, according to a reference received by the receiving unit, A data packet extracts channel characteristics between the network device and the peer network device.
  • the network device is a sender network device, and the network device further includes: a sending unit, configured to send a beacon data packet to the peer network device by using a link layer; A response packet for the beacon packet.
  • the network device is a sender network device
  • the beacon data packet includes a link layer management frame
  • the sending unit is further configured to: preset from a moment when the beacon data packet is sent to the peer network device by using the link layer. During the time period, if the receiving unit does not receive the response packet of the beacon packet, the beacon packet is retransmitted to the peer network device through the link layer.
  • the channel feature includes a CSI
  • the extracting unit is specifically configured to perform multi-channel sample sensing on the reference data packet to obtain a network device and a pair. Characteristics of each subchannel between end network devices.
  • the network device further includes: a pairing unit, configured to extract, between the network device and the peer network device, according to the reference data packet, by the extracting unit After the channel feature, the channel feature pairing between the network device and the peer network device is performed with the peer network device according to the pairing reference information.
  • the pairing reference information includes a timestamp for extracting the channel feature, and the channel feature corresponding to the timestamp with the smallest time interval is a pair of channel features; or the pairing reference information includes the pairing sequence number in the reference data packet for extracting the channel feature, and the pairing sequence number is the same
  • the channel characteristics extracted by the data packet are a pair of channel characteristics.
  • the pairing reference information includes a timestamp for extracting a channel feature
  • the pairing unit is specifically configured to: record the first timestamp, the first timestamp A system time for extracting a channel feature between the network device and the peer network device for the network device; sending, by the sending unit, the first timestamp to the peer network device, where the first timestamp is used by the peer network device to extract the peer network device
  • the channel feature between the network device and the peer network device is paired with the channel feature between the network device and the peer network device extracted by the network device; or the second timestamp sent by the peer network device is received by the receiving unit, the second time
  • the system time of the channel feature between the network device and the peer network device extracted by the peer network device is selected, and the network device selects a channel feature between the network device and the peer network device with the smallest timestamp and the second timestamp interval, and Pairing the channel characteristics between the network device extracted by the peer network
  • the reference data packet includes a pairing sequence number;
  • the pairing reference information includes a pairing sequence number in a reference data packet for extracting a channel feature;
  • the receiving unit receives, by the receiving unit, a pairing sequence number of at least one data packet sent by the peer network device and the channel feature between the network device extracted by the peer network device and the peer network device, and the network device according to the pairing sequence number
  • the channel characteristics between the network device extracted by the network device and the peer network device are paired with the channel characteristics between the network device extracted by the network device and the peer network device.
  • the channel feature between the network device extracted by the network device and the peer network device is paired with the channel feature between the network device extracted by the network device and the peer network device.
  • the network device provided by the foregoing third aspect is configured to perform the method for extracting channel features according to the foregoing first aspect, which is the same as the specific implementation and the beneficial effects of the method for extracting channel features described in the foregoing first aspect, where Repeatedly.
  • the embodiment of the present invention provides another network device, where the network device may include: a receiving unit, configured to receive a reference data packet sent by the peer network device; and an extracting unit, configured to receive, according to the reference data packet received by the receiving unit, Extracting channel characteristics between the network device and the peer network device; the pairing unit is configured to perform channel feature matching between the network device and the peer network device with the peer network device according to the pairing reference information.
  • the pairing reference information includes a timestamp for extracting the channel feature, and the channel feature corresponding to the timestamp with the smallest time interval is a pair of channel features; or the pairing reference information includes the pairing sequence number in the reference data packet for extracting the channel feature, and the pairing sequence number is the same
  • the channel characteristics extracted by the data packet are a pair of channel characteristics.
  • the pairing reference information includes a timestamp for extracting a channel feature
  • the pairing unit is specifically configured to: record a first timestamp, where the first timestamp is a network device extracting the network device and the peer end The system time of the channel feature between the network devices; sending, by the sending unit, the first timestamp to the peer network device, where the first timestamp is used by the peer network device between the network device extracted by the peer network device and the peer network device
  • the channel feature is paired with the channel feature between the network device extracted by the network device and the peer network device; or the second timestamp sent by the peer network device is received by the receiving unit, and the second timestamp is the network extracted by the peer network device.
  • the system time of the channel feature between the device and the peer network device selects the channel feature between the network device and the peer network device with the smallest timestamp and the second timestamp interval, and the network device extracted by the peer network device Pairing channel characteristics between peer network devices.
  • the reference data packet includes a pairing sequence number;
  • the pairing reference information includes a pairing sequence number in a reference data packet for extracting a channel feature;
  • the receiving unit receives, by the receiving unit, a pairing sequence number of at least one data packet sent by the peer network device and the channel feature between the network device extracted by the peer network device and the peer network device, and the network device according to the pairing sequence number
  • the channel characteristics between the network device extracted by the network device and the peer network device are paired with the channel characteristics between the network device extracted by the network device and the peer network device.
  • the channel feature between the network device extracted by the network device and the peer network device is paired with the channel feature between the network device extracted by the network device and the peer network device.
  • the receiving unit is specifically configured to: receive, at the link layer, a reference data packet sent by the peer network device.
  • the channel feature includes a CSI
  • the extracting unit is specifically configured to perform multi-channel sample sensing on the reference data packet to obtain a network device and a pair. Characteristics of each subchannel between end network devices.
  • the network device provided by the foregoing fourth aspect is configured to perform the method for extracting channel characteristics according to the foregoing second aspect, which is the same as the specific implementation and the beneficial effects of the method for extracting channel features described in the foregoing second aspect. Repeatedly.
  • the embodiment of the present invention provides a network device, where the network device can implement the method for extracting channel features provided by the foregoing first aspect, where the function of the network device can be implemented by hardware or by hardware.
  • the hardware or software includes one or more modules corresponding to the above functions.
  • the network device includes a processor and a transceiver configured to support the network device to perform the foregoing method.
  • the transceiver is used to support communication between the network device and other network elements.
  • the network device can also include a memory for coupling with the processor that holds the necessary program instructions and data for the network device.
  • the embodiment of the present invention provides a network device, where the network device can implement the method for extracting channel features provided by the foregoing second aspect, where the function of the network device can be implemented by hardware or by hardware.
  • the hardware or software includes one or more modules corresponding to the above functions.
  • the network device includes a processor and a transceiver configured to support the network device to perform the foregoing method.
  • the transceiver is used to support communication between the network device and other network elements.
  • the network device can also include a memory for coupling with the processor that holds the necessary program instructions and data for the network device.
  • an embodiment of the present invention provides a computer storage medium for storing computer software instructions used by the network device, which includes a program designed to execute the foregoing method.
  • an embodiment of the present invention provides a system for extracting a channel feature, where the system includes two network devices according to any of the foregoing aspects, and two network devices communicate with each other to extract channel characteristics between the two.
  • 1 is a schematic structural diagram of an entity communication network architecture
  • FIG. 2 is a schematic structural diagram of a network device according to an embodiment of the present invention.
  • FIG. 3 is a schematic flowchart of a method for extracting channel features according to an embodiment of the present disclosure
  • 4a is a schematic flowchart diagram of another method for extracting channel features according to an embodiment of the present invention.
  • FIG. 4b is a schematic flowchart of still another method for extracting channel features according to an embodiment of the present disclosure
  • FIG. 5 is a schematic structural diagram of a data packet according to an embodiment of the present disclosure.
  • FIG. 6 is a schematic structural diagram of an overall network card structure according to an embodiment of the present disclosure.
  • FIG. 7 is a schematic diagram of multi-channel listening of network card firmware according to an embodiment of the present invention.
  • FIG. 8 is a schematic flowchart diagram of still another method for extracting channel features according to an embodiment of the present disclosure.
  • FIG. 9 is a schematic structural diagram of another network device according to an embodiment of the present disclosure.
  • FIG. 10 is a schematic structural diagram of still another network device according to an embodiment of the present disclosure.
  • FIG. 11 is a schematic structural diagram of still another network device according to an embodiment of the present invention.
  • the packet interaction and logic control mechanisms employed by the channel feature sample extraction technique are based on the network layer ping tool. It is well known that the working process of the ping tool based on the network layer increases the data packet interaction time due to the network layer routing and control message protocol (Internet Control Message Protocol, ICMP) protocol control process, and receives data in the sending and receiving parties. When the packet extracts the channel characteristics, the time interval of the channel feature samples is also increased, and the correlation of the channel feature samples is reduced.
  • ICMP Internet Control Message Protocol
  • the data packet interaction of extracting channel characteristics is performed based on the link layer. Due to the transmission characteristics of the link layer data packet, the network layer routing, ICMP protocol control, and the like may be omitted compared to the network layer, thereby reducing packet interaction. Time, when the receiving and receiving parties receive the data packet extraction channel feature, the time interval of the channel feature samples will also be reduced, and the correlation of the channel feature samples is improved.
  • the method for extracting channel features provided by the embodiments of the present invention is applied to the entity communication network architecture shown in FIG. 1.
  • the communication entity 101 and the communication entity 102 are included in the network architecture.
  • the method for extracting channel characteristics may be specifically applied to the communication entity 101 and the communication entity 102.
  • the communication entity 101 and the communication entity 102 interact with each other to extract channel characteristics between the two.
  • the communication entity 101 or the communication entity 102 may be a network device such as a router or a gateway.
  • the embodiment of the present invention does not specifically limit the type of the communication entity.
  • the communication mode between the communication entity 101 and the communication entity 102 may be a wireless communication mode, but the type of the wireless communication mode between the two is in the embodiment of the present invention. This is not specifically limited.
  • the wireless communication method may include, but is not limited to, cellular communication, Bluetooth communication, infrared communication, and the like.
  • the extracted channel characteristics can be used to generate a key for encrypted communication.
  • a communication key is generated based on the channel characteristics.
  • the extracted channel features may also be applied to other scenarios, which are not specifically limited in this embodiment of the present invention.
  • the method for extracting channel characteristics provided by the embodiment of the present invention is implemented by the network device 20 provided by the embodiment of the present invention.
  • the network device 20 provided by the embodiment of the present invention may be the communication entity 101 or the communication entity 102 in the network architecture shown in FIG.
  • FIG. 2 shows a schematic structural diagram of a network device 20 related to various embodiments of the present invention.
  • network device 20 may include processor 201, memory 202, communication bus 203, and transceiver 204.
  • the memory 202 is configured to store program code and transmit the program code to the processor 201, so that the processor 201 executes the program code to implement various functions of the network device 20.
  • the memory 202 can be a volatile memory, such as a random access memory (RAM), or a non-volatile memory (English name: non-volatile memory), such as a read only memory. (English full name: read-only memory, ROM), flash memory (English full name: flash memory), hard disk (English full name: hard disk drive, HDD) or solid state drive (English full name: solid-state drive, SSD); or A combination of the above types of memories.
  • the processor 201 is a control center of the network device 20, and may be a central processing unit (central processing unit, CPU), or a specific integrated circuit (ASIC), or configured.
  • One or more integrated circuits embodying embodiments of the present invention such as one or more microprocessors (digital singnal processors, DSP), or one or more field programmable gate arrays (English full name: field) Programmable gate array, FPGA).
  • the processor 201 can implement various functions of the network device 20 by running or executing program code stored in the memory 202, as well as invoking data stored in the memory 202.
  • the communication bus 203 can be an industry standard architecture (English name: industry standard architecture, ISA) bus, external device interconnection (English full name: peripheral component interconnect, PCI) bus or extended industry standard architecture (English full name: extended industry Standard architecture, EISA) bus, etc.
  • the bus 203 can be divided into an address bus, a data bus, a control bus, and the like. For ease of representation, only one thick line is shown in Figure 2, but it does not mean that there is only one bus or one type of bus.
  • the transceiver 204 can be a network device 20 that can be a network card or a network port for receiving data packets transmitted by other communication entities or for transmitting data packets to other communication entities.
  • the embodiment of the present invention does not specifically limit the type of the transceiver 204.
  • the processor 201 is specifically configured to: receive, at the link layer, a reference data packet sent by the second network device; and extract, according to the reference data packet, a channel feature between the network device 20 and the peer network device.
  • an embodiment of the present invention provides a method for extracting a channel feature, which is applied to a first network device.
  • the method for extracting channel features provided by the embodiment of the present invention may include:
  • the first network device receives, at the link layer, a reference data packet sent by the second network device.
  • the first network device may be any one of the two entities that communicate with each other, which is not specifically limited in this embodiment of the present invention. That is, the first network device may be a sender network device in which both channel characteristics are extracted by mutual communication, or may be a receiver network device.
  • the second network device when the first network device is a sending end network device in the two sides that extract channel characteristics by mutual communication, the second network device is a receiving end network device in the two sides that extract channel characteristics by mutual communication. Conversely, when the first network device is a receiving end network device in which both channel characteristics are extracted by mutual communication, the second network device is a transmitting end network device in which both of the channel characteristics are extracted by mutual communication.
  • the types of reference data packets are different.
  • the reference data packet may include the following two types:
  • the reference data packet is a response data packet of the beacon data packet sent by the first network device to the second network device.
  • the embodiment of the present invention provides The method of extracting channel characteristics may further include S301a.
  • the first network device generates a beacon data packet, and sends a beacon data packet to the second network device by using a link layer.
  • the beacon data packet is a data packet sent by the first network device for extracting the detection property of the channel feature.
  • the embodiment of the present invention does not specifically limit the type and format of the beacon data packet, and any data packet transmitted at the link layer can be used as the beacon data packet. In practical applications, the type and format of the beacon packet can be set according to actual needs.
  • the beacon data packet may include a link layer management frame.
  • the link layer management frame as a beacon packet, the link layer retransmission confirmation mechanism can be bypassed, the packet interaction protocol is further simplified, and the correlation of channel feature samples is improved.
  • the reference data packet is the beacon data packet sent by the second network device to the second network device.
  • the embodiment of the present invention provides The method of extracting channel characteristics may further include S301b.
  • S301b The first network device sends a response data packet of the beacon data packet to the second network device by using the link layer.
  • the beacon data packet described is the same as the content of the beacon data packet described in the above S301a, except that in S301b, the beacon data packet is sent by the second network device to the first network device, and therefore, The contents of the beacon packet are not described here.
  • the response data packet of the beacon data packet is sent by the first network device to the second network device, and is used for feeding back a feedback data packet that the first network device has successfully received the beacon data packet, and the second network device according to the beacon
  • the response packet of the packet can extract the channel characteristics between the two.
  • the type and format of the response data packet of the beacon data packet are not specifically limited in the embodiment of the present invention. In practical applications, the type and format of the response packet of the beacon packet can be set according to actual needs.
  • the first network device extracts channel characteristics between the first network device and the second network device according to the reference data packet.
  • the channel characteristics may include CSI or received signal strength (English name: Received Signal Strength, RSS).
  • a structure of a data packet with a radiotap header (ie, a radio channel physical parameter header) is illustrated.
  • the data portion is also included.
  • the radiotap header includes a Header Revision field, a Header Pad field, a Header Length field, a Present flags field, a Timestamo field, and a Flags field.
  • data transmission rate, channel frequency and signal strength are CSI.
  • the data packet structure illustrated in FIG. 5 is merely an example to describe the CSI included in the packet header, and is not specifically limited to the packet structure.
  • different manners of receiving reference data packets in S301 are configured by setting network cards in the network device to different modes.
  • the network card in the network device can be set to the following two modes:
  • the network card In the first mode, the network card is in a normal mode, and single channel listening is performed in S302, and the channel feature is extracted as RSS.
  • the libpacp library ie, the network data packet is used at the application layer. Capture function library) grab the data packet with the radiotap header, convert it in the driver layer of the wireless network card, convert the data packet into a common 802.3 Ethernet frame format, lose the CSI, and only perform single channel sample listening.
  • the configuration network card supports the mode of recording the channel characteristics of each subchannel, and the multi-channel interception is performed in S302, and the channel feature is extracted as CSI.
  • the original channel is divided into 30 or 60 subchannels, and each subchannel has Different channel characteristics (signal strength, frequency, etc.).
  • the channel characteristics of each subchannel are recorded by the network card for multichannel interception.
  • the network card can be modified to enable the network card to record the channel characteristics of each subchannel.
  • the application layer uses the libpacp library to capture the data packet with the radiotap header, the network card firmware.
  • the channel characteristics of each subchannel are recorded to obtain CSI data.
  • the overall architecture of the network card during multi-channel interception is illustrated, which involves three parts: a physical layer, a network card driver layer, and an application layer, which are respectively introduced below.
  • the NIC firmware is modified so that the NIC supports recording the channel characteristics of each subchannel.
  • the modified network card firmware records the channel characteristics of each subchannel and encapsulates it into the data structure CSI.
  • the firmware provides a programming interface for the driver in an interrupted manner, and the driver can obtain CSI data through the interface. Passed to the application layer capture, that is, the channel characteristics are extracted.
  • the manner in which the network card firmware provides the programming interface to the driver may be other than the above-mentioned interrupt mode.
  • the operation of the wireless network card driver layer is as follows:
  • the command code of the corresponding firmware sets the CSI interrupt handling function at the driver layer:
  • the data packet is filtered in the iwlagn_rx_reply_rx function, the flag is set, and then the qualified CSI samples are transmitted to the application layer capture program using the Netlink Socket according to the previously set flag in the iwlagn_bfee_notif function.
  • a custom Netlink Socket kernel and user space communication socket
  • This work is done by the driver layer and the application layer.
  • Netlink Socket is loaded in the driver layer by module.
  • the custom Netlink Socket is identified by connector_id, and then cn_add_callback, cn_del_callback and cn_netlink_send functions are implemented for the initialization of netlink addition, the processing of netlink deletion and the logic of sending data to the application layer. .
  • Netlink Socket has the same programming interface in the application layer as the conventional socket.
  • Use struct nlmsghdr to indicate the destination address of the socket.
  • the .nl_group field in the address corresponds to the .idx field of the Netlink Socket issued by the driver layer, indicating that the Netlink Socket subscribes to the data of the driver layer Netlink Socket.
  • the data sent by the driver layer through cn_netlink_send can be received in the application layer Netlink Socket.
  • the message queue can be used to cache the CSI, and the worker thread is started to send CSI data to the application layer.
  • the CSI data is cached in the driver layer as follows:
  • the buffering process of the CSI data in the driver layer includes: a message inbound, a message in the publishing queue, and a connector subscribed to CN_IDX_IWLAGN.
  • the processes of the foregoing S301 and S302 may be performed at least once to extract at least one channel feature of a channel between the first network device and the second network device, and used to generate a key for performing the first network. Encrypted communication between the device and the second network device.
  • the at least one channel feature of the channel between the extracted first network device and the second network device may also be used for other purposes, which is not specifically limited in this embodiment of the present invention.
  • the method for extracting channel features provided by the embodiment of the present invention, because the reference data packets used for extracting channel characteristics are interacted at the link layer, and the routing, protocol control, and the like are omitted compared to the network layer interaction data packet, which can simplify the data packet.
  • the interaction process greatly reduces the time interval for transmitting and receiving dual-issue channel features, that is, reducing the feature sample time interval.
  • the key feature is used to generate the key encryption communication, the correlation of the channel feature samples can be well increased, and the accuracy and extraction rate of the key are improved.
  • the method for extracting channel features provided by the embodiment of the present invention may further include S303.
  • S303 Determine whether a response data packet of the beacon data packet is received within a preset time period from when the first network device sends the beacon data packet to the second network device through the link layer.
  • the preset duration can be set according to actual network requirements, which is not specifically limited in this embodiment of the present invention.
  • the timing of the preset duration can be implemented by using a timer or other timing method, which is not specifically limited in the embodiment of the present invention.
  • the execution is performed. S304. Further, after S303, if the first network device sends the beacon data packet to the second network device by using the link layer, the first network device receives the response packet of the beacon data packet. Then, S301 receives the reference data packet.
  • the first network device retransmits the beacon data packet to the second network device by using the link layer.
  • S303 may be re-executed. Through the execution of S303 and S304, a mechanism for timeout retransmission is implemented to avoid the impact of packet loss on the accuracy of packet interaction.
  • the method for extracting channel characteristics provided by the embodiment of the present invention is further provided. S305 can also be included.
  • the first network device performs channel feature pairing between the first network device and the second network device with the second network device according to the pairing reference information.
  • the communication dual-issue pairs the reference information to achieve pairing of channel features.
  • the channel characteristics that are paired with each other are the same considerations in the scenario where channel characteristics are used.
  • the channel characteristics that are paired with each other are the same parameters in the algorithm when generating the key.
  • the communication parties when they send the pairing reference information to the opposite end, they also carry a consideration factor for indicating the pair of feature information obtained by the current pairing, or a parameter position in the calculation.
  • the communication dual-issue only needs to send the pairing parameter information in one direction.
  • the specific embodiment is not specifically limited in this embodiment of the present invention.
  • pairing rules may be defined according to the content of the pairing reference information.
  • the following two matching rules provided by the embodiments of the present invention are described below.
  • the first pairing rule is the first pairing rule
  • the pairing reference information may include a time stamp for extracting channel characteristics, and the pairing rule is that the channel feature corresponding to the timestamp with the smallest time interval is a pair of channel features.
  • the channel feature corresponding to the timestamp with the smallest time interval is a timestamp between the two extracted by the communication parties.
  • the pairing reference information is a time stamp for extracting channel characteristics
  • the communication dual-issue first performs system clock synchronization, and then performs data packet interaction.
  • the timestamp is the system time after synchronization.
  • the embodiment of the present invention does not specifically limit the form of the timestamp.
  • the pairing reference information includes a pairing sequence number in the reference data packet for extracting the channel feature, and the pairing rule is: the channel feature extracted by the data packet with the same pairing sequence number is a pair of channel features.
  • the channel feature extracted by the data packet with the same pairing sequence number is a time stamp between the two extracted by the communication parties.
  • the pairing reference information includes the pairing sequence number in the reference data packet of the extracted channel feature
  • the reference data packet includes the pairing sequence number.
  • the embodiment of the present invention does not limit this, and may be configured according to actual needs.
  • pairing reference information may use other information in addition to the timestamp or the pairing sequence number, which is not specifically limited in the embodiment of the present invention.
  • the following describes the process of pairing channel feature samples by the two communicating parties when the pairing reference information is a time stamp or a pairing sequence number.
  • the first network device performs the channel feature pairing between the first network device and the second network device according to the pairing reference information according to the pairing reference information. This is achieved as steps 1 and 2 below.
  • Step 1 The first network device records a first timestamp, where the first timestamp is a system time for the first network device to extract channel characteristics between the first network device and the second network device.
  • Step 2 The first network device sends a first timestamp to the second network device.
  • the first timestamp is used by the second network device to extract the channel feature between the first network device and the second network device extracted by the second network device, and the first network device and the first network device extracted by the first network device.
  • Channel feature pairing between two network devices is used by the second network device to extract the channel feature between the first network device and the second network device extracted by the second network device, and the first network device and the first network device extracted by the first network device.
  • the second network side device also records the system time for extracting the channel feature between the first network device and the second network device. After the second network device receives the first timestamp sent by the first network device, selecting the channel feature extracted by itself, extracting the channel feature with the smallest timestamp and the first timestamp interval, as the first with the first network device A paired channel characteristic of a channel feature between the first network device and the second network device extracted by the timestamp.
  • the first network device performs the channel feature pairing between the first network device and the second network device according to the pairing reference information according to the pairing reference information. This is achieved as steps a and b below.
  • Step a The first network device records the first timestamp.
  • Step b The first network device receives a second timestamp sent by the second network device, where the first network device selects a channel feature between the first network device and the second network device with the smallest interval between the extracted timestamp and the second timestamp, and The second network device pairs the channel characteristics between the first network device and the second network device extracted by the second timestamp.
  • the second timestamp is a system time of channel characteristics between the first network device and the second network device extracted by the second network device.
  • each channel feature recorded is achieved by the above steps 1 and 2, or steps a and b.
  • the above steps 1 and 2 may be performed once for each channel feature, or once step a and step b, and the above steps 1 and steps may be performed once for all extracted channel features. 2, or, step a and step b at a time. This embodiment of the present invention does not specifically limit this.
  • Alice is the sender network device in the data interaction.
  • the channel feature samples between the two extracted by Alice are shown in Table 1.
  • the channel feature samples between Bob's extracted are shown in Table 2.
  • pairing channel feature samples Alice sends a pairing message 1 to Bob with the following contents: ⁇ (10:05:48,X), (10:10:30,Y), (10:12:10,Z) (10:14:56, R) (10:16:21, Q) ⁇ .
  • X, Y, Z, R, and Q are parameters when the key is generated.
  • the obtained pairing result is:
  • the sample a is paired with the channel feature extracted by Alice 10:05:48.
  • the sample b is paired with the channel feature extracted by Alice 10:14:56, as the R parameter when generating the key, the sample c and Alice10.
  • the sample d is paired with the channel feature extracted by Alice10:10:30, as the Y parameter when generating the key, sample e and Alice10:12:10
  • the extracted channel feature pairing is used as the Z parameter when generating the key.
  • Alice and Bob respectively generate the key of the encrypted communication by substituting the extracted channel feature samples into the X, Y, Z, R, and Q parameters according to the pairing result. It should be noted that the specific algorithm and parameters for generating a key for encrypted communication are not limited in the embodiment of the present invention.
  • the first network device performs channel feature pairing between the first network device and the second network device according to the pairing reference information according to the pairing reference information, which may be implemented as:
  • the first network device may be a sender network device or a receiver network device.
  • the first network device performs channel feature pairing between the first network device and the second network device with the second network device according to the pairing reference information in S305, which may be implemented as:
  • the first network device Transmitting, by the first network device, the pairing sequence number of the at least one data packet of the channel feature between the first network device and the second network device to the second network device, where the second network device uses, according to the pairing sequence number, the second network device And matching a channel feature between the first network device and the second network device extracted by the second network device with a channel feature between the first network device and the second network device extracted by the first network device.
  • Alice is the sender network device in the data interaction.
  • the channel feature samples between the two extracted by Alice are shown in Table 3.
  • the channel feature samples between Bob's extracted are shown in Table 4.
  • X, Y, Z, R, and Q are parameters when the key is generated.
  • the channel feature samples with the same pairing sequence number are paired, and the obtained pairing result is: sample a pairing with the channel feature extracted by Alice from the data packet including the pairing sequence number 100, as the Q parameter at the time of generating the key, the sample b is paired with the channel feature extracted by Alice from the packet including the pairing sequence number 011, as a generation
  • the Y parameter at the time of the key the sample c is paired with the channel feature extracted by Alice from the data packet including the pairing sequence number 101, as the R parameter when the key is generated, and the samples d and Alice are from the data packet including the pairing sequence number 001.
  • the extracted channel feature pairing is used as the X parameter when the key is generated, and the sample e is paired with the channel feature extracted by Alice from the packet including the pairing sequence number 111 as the Z parameter when the key is generated.
  • Alice and Bob respectively generate the key of the encrypted communication by substituting the extracted channel feature samples into the X, Y, Z, R, and Q parameters according to the pairing result. It should be noted that the specific algorithm and parameters for generating a key for encrypted communication are not limited in the embodiment of the present invention.
  • a network device receives the pairing reference information sent by the peer end and performs pairing, if there is an uncompleted paired channel feature in the channel feature extracted by itself, the channel feature of the unpaired pair is removed. Or, when a network device receives the pairing reference information sent by the peer end, and performs pairing, if the received pairing reference information does not find the pairable channel feature, the channel information of the not found pairable is fed back to the peer end.
  • the pairing reference information is such that the peer removes the channel feature corresponding to the paired channel feature pairing reference information.
  • the embodiment of the present invention provides another method for extracting channel features.
  • the method may include:
  • the first network device receives a reference data packet sent by the second network device.
  • the first network device, the second network device, and the reference data packet have been described in detail in the embodiment shown in FIG. 3 or FIG. 4a or FIG. 4b, and details are not described herein again.
  • the first network device and the second network device may perform data packet interaction at the link layer, and may also perform data packet interaction based on the ping work at the network layer, which is not performed by the embodiment of the present invention. Specifically limited.
  • first network device and the second network device can perform data packet interaction at the link layer in S801, the specific process has been detailed in the embodiment shown in FIG. 3 or FIG. 4a or FIG. 4b. Description, no more details here.
  • the first network device and the second network device perform data packet interaction based on the ping work at the network layer, and the specific process is a regular ping tool workflow, and details are not described herein.
  • the first network device extracts channel characteristics between the first network device and the second network device according to the reference data packet.
  • the channel characteristics may include RSS or CSI.
  • the first network device performs channel feature pairing between the first network device and the second network device with the second network device according to the pairing reference information.
  • the pairing reference information includes a timestamp for extracting a channel feature, and the channel feature corresponding to the timestamp with the smallest time interval is a pair of channel features; or the pairing reference information includes a pairing sequence number in the reference data packet for extracting the channel feature.
  • the channel characteristics extracted by the packets with the same pairing sequence number are a pair of channel features.
  • FIG. 8 a specific implementation manner of the other functions in the embodiment shown in FIG. 4a or FIG. 4b with reference to FIG. 4a or FIG. 4b may also be included. Describe it one by one.
  • the method for extracting channel features provided by the embodiment of the present invention, by pairing channel characteristics between the two transmitted and received dual-issues, ensures sample pairing of channel features in case of packet loss and retransmission, and improves channel feature samples. Relevance.
  • the key feature is used to generate the key encryption communication, the correlation of the higher channel feature samples ensures the accuracy of the key.
  • the first network device includes corresponding hardware structures and/or software modules for performing the respective functions.
  • the present application can be implemented in a combination of hardware or hardware and computer software in combination with the elements and algorithm steps of the various examples described in the embodiments disclosed herein. Whether a function is implemented in hardware or computer software to drive hardware depends on the specific application and design constraints of the solution. A person skilled in the art can use different methods for implementing the described functions for each particular application, but such implementation should not be considered to be beyond the scope of the present invention.
  • the embodiment of the present invention may divide the function module into the network device according to the foregoing method example.
  • each function module may be divided according to each function, or two or more functions may be integrated into one processing module.
  • the above integrated modules can be implemented in the form of hardware or in the form of software functional modules. It should be noted that the division of the module in the embodiment of the present invention is schematic, and is only a logical function division, and the actual implementation may have another division manner.
  • FIG. 9 is a schematic diagram showing a possible structure of the network device 90 involved in the foregoing embodiment.
  • the network device 90 includes a receiving unit 901 and an extracting unit 902.
  • the receiving unit 901 is configured to support the network device 90 to perform the process S301 in FIG. 3 or FIG. 4a or FIG. 4b, and the receiving unit 901 can also be used to support the network device 90 to perform the process S801 in FIG. 8.
  • the extracting unit 902 is configured to support the network device 90 to perform the process S302 in FIG. 3 or FIG. 4a or FIG. 4b, and the extracting unit 902 can also be used to support the network device 90 to perform the process S802 in FIG. 8. All the related content of the steps involved in the foregoing method embodiments may be referred to the functional descriptions of the corresponding functional modules, and details are not described herein again.
  • FIG. 10 shows another possible structural diagram of the network device 90 involved in the foregoing embodiment.
  • the network device 90 may further include a sending unit 903, a timing unit 904, and a pairing unit 905.
  • the sending unit 903 is configured to support the network device 90 to perform the processes S301a, S301b in FIG. 4a or 4b;
  • the timing unit 904 can also be used to support the network device 90 to perform the processes S303, S304 in FIG. 4a;
  • the pairing unit 905 can also be used to The support network device 90 performs the process S305 in FIG. 3, or the pairing unit 905 can also be used to support the network device 90 to perform the process S803 in FIG.
  • FIG. 11 shows a possible structural diagram of the network device 110 involved in the above embodiment.
  • the network device 110 may include a processing module 1101 and a communication module 1102.
  • the processing module 1101 is configured to control and manage the actions of the network device 110.
  • the processing module 1101 is configured to support the network device 110 to perform the processes S301 and S302 in FIG. 3
  • the processing module 1101 is configured to support the network device 110 to perform the processes S301, S302, S303, S304, and S305 in FIG. 4a or 4b
  • process Module 1101 is also used to support network device 110 to perform processes S801, S802, and S803 in FIG. 8, and/or other processes for the techniques described herein.
  • the processing module 1101 is also used to support the network device 110 through the communication module 1102 to perform the processes S301a and S301b in FIG. 4a or 4b.
  • the communication module 1102 is for supporting communication of the network device 110 with other network entities.
  • the network device 110 may also include a storage module 1103 for storing program codes and data of the network device 110.
  • the processing module 1101 may be the processor 201 in the physical structure of the network device 20 shown in FIG. 2, and may be a processor or a controller, such as a CPU, a general-purpose processor, a DSP, an ASIC, an FPGA, or other programmable. Logic device, transistor logic device, hardware component, or any combination thereof. It is possible to implement or carry out the various illustrative logical blocks, modules and circuits described in connection with the present disclosure.
  • the processor may also be a combination of computing functions, for example, including one or more microprocessor combinations, a combination of a DSP and a microprocessor, and the like.
  • the communication module 1102 can be a communication port or can be a transceiver, a transceiver circuit, a communication interface, or the like.
  • the storage module 1104 can be the memory 202 in the physical structure of the network device 20 shown in FIG.
  • the network device 110 involved in FIG. 11 of the embodiment of the present invention may be the network device 20 shown in FIG.
  • the steps of a method or algorithm described in connection with the present disclosure may be implemented in a hardware, or may be implemented by a processor executing software instructions.
  • the software instructions may be composed of corresponding software modules, which may be stored in RAM, flash memory, ROM, Erasable Programmable ROM (EPROM), and electrically erasable programmable read only memory (Electrically EPROM).
  • EEPROM electrically erasable programmable read only memory
  • registers hard disk, removable hard disk, compact disk read only (CD-ROM) or any other form of storage medium known in the art.
  • An exemplary storage medium is coupled to the processor to enable the processor to read information from, and write information to, the storage medium.
  • the storage medium can also be an integral part of the processor.
  • the processor and the storage medium can be located in an ASIC. Additionally, the ASIC can be located in a core network interface device.
  • the processor and the storage medium may also exist as discrete components in the core network interface device.
  • the disclosed system, apparatus, and method may be implemented in other manners.
  • the device embodiments described above are merely illustrative.
  • the division of the unit is only a logical function division.
  • there may be another division manner for example, multiple units or components may be combined or Can be integrated into another system, or some features can be ignored or not executed.
  • the mutual coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection through some interface, device or unit, and may be electrical or otherwise.
  • the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, may be located in one place, or may be distributed to multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of the embodiment.
  • each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may be physically included separately, or two or more units may be integrated into one unit.
  • the above integrated unit can be implemented in the form of hardware or in the form of hardware plus software functional units.
  • the above-described integrated unit implemented in the form of a software functional unit can be stored in a computer readable storage medium.
  • the software functional units described above are stored in a storage medium and include instructions for causing a computer device (which may be a personal computer, server, or network device, etc.) to perform portions of the steps of the methods described in various embodiments of the present invention.
  • the foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, and the like, and the program code can be stored. Medium.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本发明实施例提供一种提取信道特征的方法及网络设备,涉及通信领域,解决提取无线信道特征时的样本相关性不高和提取速率过慢的问题。具体方案包括:第一网络设备在链路层接收第二网络设备发送的参考数据包;第一网络设备根据参考数据包,提取第一网络设备与第二网络设备间的信道特征。本发明用于提取信道特征。

Description

一种提取信道特征的方法及网络设备
本申请要求于2016年12月30日提交中国专利局、申请号为201611270754.4、申请名称为“一种提取信道特征的方法及网络设备”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本发明涉及通信领域,尤其涉及一种提取信道特征的方法及网络设备。
背景技术
安全密钥的建立是两个实体间秘密通信的基本要求。目前,对称加密、公钥加密和量子加密等方案已经得到普遍应用。但是,这些加密方案在安全性、成本上存在诸多缺陷,使得应用的局限性很大。
在此基础上,更轻量级并且更加灵活的、利用无线信道的物理特性在两个实体间生成加密密钥的加密方案应运而生。由于无线信号的空时唯一性、短时互易性、快速时变性及不可预测性等特征,使得利用基于无线信道特性提取的密钥作为会话密钥加密通信信道,攻击者很难破解会话密钥。
在利用无线信道的物理特性在两个实体间生成加密密钥时,需先采用数据包交互与逻辑控制机制提取无线信道的特征。在提取无线信道特征的过程中,收发双发记录信道特征信息的时间间隔τ,是度量信道特征样本相关性的重要参数,τ越小表示信道特征样本相关性越强,后续根据样本生成的密钥准确度也越高。
当前,无线信道特征样本提取技术采用的数据包交互和逻辑控制机制是基于网络层的ping工具。由于网络层的路由及协议控制等流程,以及网络侧数据包到达链路层后的重传确认机制,大大增加了特征样本时间间隔τ,造成提取无线信道特征时的样本相关性不高。
发明内容
本发明实施例提供一种提取信道特征的方法及网络设备,解决提取无线信道特征时的样本相关性不高和提取速率过慢的问题。
第一方面,本发明实施例提供一种提取信道特征的方法,包括:第一网络设备在链路层接收第二网络设备发送的参考数据包;第一网络设备根据参考数据包,提取第一网络设备与第二网络设备间的信道特征。
本发明实施例提供的提取信道特征的方法,由于用于提取信道特征的参考数据包是在链路层交互,相比网络层交互数据包,省略了路由、协议控制等流程,可以简化数据包的交互过程,大大减少了收发双发提取信道特征的时间间隔,也就是减少了特征样本时间间隔。在采用信道特征生成密钥加密通信时,能很好的增加信道特征样本的相关性,提高密钥的准确性及提取速率。
其中,第一网络设备、第二网络设备互为通信双方。第一网络设备可以为通信中的发送方,通过向第二网络设备发送探测数据包,第二网络设备则反馈探测数据包的 响应数据包,即为上述参考数据包。或者,第一网络设备可以为通信中的接收方,接收第二网络设备发送探测数据包,即为上述参考数据包,并向第二网络设备反馈探测数据包的响应数据包。
结合第一方面,在一种可能的实现方式中,本发明实施例提供的提取信道特征的方法还可以包括:第一网络设备生成信标数据包,并通过链路层向第二网络设备发送信标数据包;参考数据包为所述信标数据包的响应数据包。
结合第一方面,在一种可能的实现方式中,当第一网络设备为接收端网络设备,在第一网络设备在链路层接收第二网络设备发送的参考数据包之后,该方法还可以包括:第一网络设备通过链路层向第二网络设备发送参考数据包的响应数据包;参考数据包的响应数据包用于指示第一网络设备已成功接收参考数据包。
结合第一方面或上述任一种可能的实现方式,在另一种可能的实现方式中,上述信标数据包可以包括链路层管理帧。由于802.11中链路层的管理帧不存在重传控制机制和确认机制的干扰,进一步减少了收发双发提取信道特征的时间间隔,也就是减少了特征样本时间间隔,增加了信道特征样本的相关性,在采用信道特征生成密钥加密通信时,更好的提高了密钥的准确性。
结合第一方面或上述任一种可能的实现方式,在另一种可能的实现方式中,在第一网络设备生成信标数据包,并通过链路层向第二网络设备发送信标数据包之后,该方法还可以包括:从第一网络设备通过链路层向第二网络设备发送信标数据包的时刻开始的预设时间段内,若第一网络设备未接收到信标数据包的响应数据包,第一网络设备通过链路层重新向所述第二网络设备发送信标数据包。以保证参考数据包的有效交互。
结合第一方面或上述任一种可能的实现方式,在另一种可能的实现方式中,上述信道特征可以包括信道状态信息(英文全称:Channel State Information,CSI),CSI包含于参考数据包中,CSI包括了第一网络设备与第二网络设备之间信道中每个子信道的特征信息。具体的,第一网络设备根据参考数据包,提取第一网络设备与第二网络设备间的信道特征,包括:第一网络设备对参考数据包进行多信道样本侦听,得到第一网络设备与第二网络设备间每个子信道的特征。通过提取子信道的样本特征,提高了提取信道特征的效率,从而将密钥生成速率大大提升。
结合第一方面或上述任一种可能的实现方式,在另一种可能的实现方式中,在第一网络设备根据参考数据包,提取第一网络设备与第二网络设备间的信道特征之后,该方法还可以包括:第一网络设备根据配对参考信息,与第二网络设备进行第一网络设备与第二网络设备间的信道特征配对。其中,配对参考信息包括提取信道特征的时间戳,时间间隔最小的时间戳对应的信道特征为一对信道特征;或者,配对参考信息包括提取信道特征的参考数据包中的配对序列号,配对序列号相同的数据包提取的信道特征为一对信道特征。通过对收发双发提取的两者之间的信道特征进行配对,保证了丢包和重传情况下信道特征的样本配对性,进而降低生成的密钥的误码率,提高密钥的实用性。
进一步的,收发双方中相互配对的信道特征样本,在收发双方根据信道特征样本生成密钥时,作为相同的生成因素。
结合第一方面或上述任一种可能的实现方式,在另一种可能的实现方式中,提供在配对参考信息包括提取信道特征的时间戳时具体的配对过程。第一网络设备根据配对参考信息,与第二网络设备进行第一网络设备与第二网络设备间的信道特征配对具体实现为:第一网络设备记录第一时间戳,第一时间戳为第一网络设备提取第一网络设备与第二网络设备间的信道特征的系统时间,第一网络设备向第二网络设备发送第一时间戳,第一时间戳用于第二网络设备将第二网络设备提取的第一网络设备与第二网络设备间的信道特征,与第一网络设备提取的第一网络设备与第二网络设备间的信道特征配对。或者,第一网络设备记录第一时间戳,第一时间戳为第一网络设备提取第一网络设备与第二网络设备间的信道特征的系统时间,第一网络设备根据配对参考信息,与第二网络设备进行第一网络设备与第二网络设备间的信道特征配对,具体可以实现为:第一网络设备接收第二网络设备发送的第二时间戳,第二时间戳为第二网络设备提取的第一网络设备与第二网络设备间的信道特征的系统时间,第一网络设备选取提取时间戳与第二时间戳间隔最小的第一网络设备与第二网络设备间的信道特征,与第二网络设备提取的第一网络设备与第二网络设备间的信道特征配对。
结合第一方面或上述任一种可能的实现方式,在另一种可能的实现方式中,参考数据包包括配对序列号,提供在配对参考信息包括提取信道特征的参考数据包中的配对序列号时具体的配对过程。在此情况下,第一网络设备根据配对参考信息,与第二网络设备进行第一网络设备与所述第二网络设备间的信道特征配对,具体可以实现为:第一网络设备接收第二网络设备发送的、第二网络设备提取第一网络设备与第二网络设备间的信道特征的至少一个数据包的配对序列号,第一网络设备根据配对序列号,将第一网络设备提取的第一网络设备与所述第二网络设备间的信道特征,与第二网络设备提取的第一网络设备与第二网络设备间的信道特征配对。
结合第一方面或上述任一种可能的实现方式,在另一种可能的实现方式中,参考数据包包括配对序列号,提供在配对参考信息包括提取信道特征的参考数据包中的配对序列号时具体的配对过程。在此情况下,第一网络设备根据配对参考信息,与第二网络设备进行第一网络设备与所述第二网络设备间的信道特征配对,具体可以实现为:第一网络设备向第二网络设备发送、第一网络设备提取第一网络设备与第二网络设备间的信道特征的至少一个数据包的配对序列号,用于第二网络设备根据配对序列号,将第二网络设备提取的第一网络设备与第二网络设备间的信道特征,与第一网络设备提取的第一网络设备与第二网络设备间的信道特征配对。
进一步的,网络设备根据配对序列号进行信道特征配对时,可以未配对成功的信道特征去除。
第二方面,本发明实施例提供一种提取信道特征的方法,具体包括:第一网络设备接收第二网络设备发送的参考数据包;第一网络设备根据参考数据包,提取第一网络设备与第二网络设备间的信道特征;第一网络设备根据配对参考信息,与第二网络设备进行第一网络设备与第二网络设备间的信道特征配对;配对参考信息包括提取信道特征的时间戳,时间间隔最小的时间戳对应的信道特征为一对信道特征;或者,配对参考信息包括提取信道特征的参考数据包中的配对序列号,配对序列号相同的数据包提取的信道特征为一对信道特征。
本发明实施例提供的提取信道特征的方法,通过对收发双发提取的两者之间的信道特征进行配对,保证了丢包和重传情况下信道特征的样本配对性,提高了信道特征样本的相关性。在采用信道特征生成密钥加密通信时,较高的信道特征样本的相关性,保证了密钥的准确性。
结合第二方面,在一种可能的实现方式中,提供在配对参考信息包括提取信道特征的时间戳时具体的配对过程。在此情况下,第一网络设备根据配对参考信息,与第二网络设备进行第一网络设备与第二网络设备间的信道特征配对,具体可以实现为:第一网络设备记录第一时间戳,第一时间戳为第一网络设备提取第一网络设备与第二网络设备间的信道特征的系统时间,第一网络设备向第二网络设备发送第一时间戳,第一时间戳用于第二网络设备将第二网络设备提取的第一网络设备与第二网络设备间的信道特征,与第一网络设备提取的第一网络设备与第二网络设备间的信道特征配对。或者,在此情况下,第一网络设备根据配对参考信息,与第二网络设备进行第一网络设备与第二网络设备间的信道特征配对,具体可以实现为:第一网络设备记录第一时间戳,第一网络设备根据配对参考信息,与第二网络设备进行第一网络设备与第二网络设备间的信道特征配对,具体可以实现为:第一网络设备接收第二网络设备发送的第二时间戳,第二时间戳为第二网络设备提取的第一网络设备与第二网络设备间的信道特征的系统时间,第一网络设备选取提取时间戳与第二时间戳间隔最小的第一网络设备与第二网络设备间的信道特征,与第二网络设备提取的第一网络设备与第二网络设备间的信道特征配对。
结合第二方面或上述任一种可能的实现方式,在另一种可能的实现方式中,参考数据包包括配对序列号,提供在配对参考信息包括提取信道特征的参考数据包中的配对序列号时具体的配对过程。在此情况下,第一网络设备根据配对参考信息,与第二网络设备进行第一网络设备与所述第二网络设备间的信道特征配对,具体可以实现为:第一网络设备接收第二网络设备发送的、第二网络设备提取第一网络设备与第二网络设备间的信道特征的至少一个数据包的配对序列号,第一网络设备根据配对序列号,将第一网络设备提取的第一网络设备与所述第二网络设备间的信道特征,与第二网络设备提取的第一网络设备与第二网络设备间的信道特征配对。
结合第二方面或上述任一种可能的实现方式,在另一种可能的实现方式中,参考数据包包括配对序列号,提供在配对参考信息包括提取信道特征的参考数据包中的配对序列号时具体的配对过程。在此情况下,第一网络设备根据配对参考信息,与第二网络设备进行第一网络设备与所述第二网络设备间的信道特征配对,具体可以实现为:第一网络设备向第二网络设备发送、第一网络设备提取第一网络设备与第二网络设备间的信道特征的至少一个数据包的配对序列号,用于第二网络设备根据配对序列号,将第二网络设备提取的第一网络设备与第二网络设备间的信道特征,与第一网络设备提取的第一网络设备与第二网络设备间的信道特征配对。
结合第二方面或上述任一种可能的实现方式,在另一种可能的实现方式中,第一网络设备接收第二网络设备发送的参考数据包,具体可以实现为:第一网络设备在链路层接收第二网络设备发送的参考数据包。由于用于提取信道特征的参考数据包是在链路层交互,相比网络层交互数据包,省略了路由、协议控制等流程,可以简化数据 包的交互过程,大大减少了收发双发提取信道特征的时间间隔,也就是减少了特征样本时间间隔。在采用信道特征生成密钥加密通信时,能很好的增加信道特征样本的相关性,提高密钥的准确性及提取速率。
结合第二方面或上述任一种可能的实现方式,在另一种可能的实现方式中,上述信道特征包括CSI。第一网络设备在链路层接收第二网络设备发送的参考数据包,具体可以实现为:CSI包含于参考数据包中,CSI包括了第一网络设备与第二网络设备之间信道中每个子信道的特征信息。具体的,第一网络设备根据参考数据包,提取第一网络设备与第二网络设备间的信道特征,包括:第一网络设备对所述参考数据包进行多信道样本侦听,得到第一网络设备与第二网络设备间每个子信道的特征。通过提取子信道的样本特征,提高了提取信道特征的效率,从而将密钥生成速率大大提升。
第三方面,本发明实施例提供一种网络设备,该网络设备包括:接收单元,用于在链路层接收对端网络设备发送的参考数据包;提取单元,用于根据接收单元接收的参考数据包,提取该网络设备与对端网络设备间的信道特征。
结合第三方面,在一种可能的实现方式中,网络设备为发送端网络设备,网络设备还包括:发送单元,用于通过链路层向对端网络设备发送信标数据包;参考数据包为信标数据包的响应数据包。
结合第三方面或上述任一种可能的实现方式,在一种可能的实现方式中,网络设备为发送端网络设备,信标数据包包括链路层管理帧。
结合第三方面或上述任一种可能的实现方式,在一种可能的实现方式中,发送单元还用于,从通过链路层向对端网络设备发送信标数据包的时刻开始的预设时间段内,若接收单元未接收到信标数据包的响应数据包,通过链路层重新向对端网络设备发送所述信标数据包。
结合第三方面或上述任一种可能的实现方式,在一种可能的实现方式中,信道特征包括CSI;提取单元具体用于:对参考数据包进行多信道样本侦听,得到网络设备与对端网络设备间每个子信道的特征。
结合第三方面或上述任一种可能的实现方式,在一种可能的实现方式中,网络设备还包括:配对单元,用于在提取单元根据参考数据包,提取网络设备与对端网络设备间的信道特征之后,根据配对参考信息,与对端网络设备进行网络设备与对端网络设备间的信道特征配对。配对参考信息包括提取信道特征的时间戳,时间间隔最小的时间戳对应的信道特征为一对信道特征;或者,配对参考信息包括提取信道特征的参考数据包中的配对序列号,配对序列号相同的数据包提取的信道特征为一对信道特征。
结合第三方面或上述任一种可能的实现方式,在一种可能的实现方式中,配对参考信息包括提取信道特征的时间戳,配对单元具体用于:记录第一时间戳,第一时间戳为网络设备提取网络设备与对端网络设备间的信道特征的系统时间;通过发送单元向对端网络设备发送第一时间戳,第一时间戳用于对端网络设备将对端网络设备提取的网络设备与对端网络设备间的信道特征,与网络设备提取的网络设备与对端网络设备间的信道特征配对;或者,通过接收单元接收对端网络设备发送的第二时间戳,第二时间戳为对端网络设备提取的网络设备与对端网络设备间的信道特征的系统时间,网络设备选取提取时间戳与第二时间戳间隔最小的网络设备与对端网络设备间的信道 特征,与对端网络设备提取的网络设备与对端网络设备间的信道特征配对。
结合第三方面或上述任一种可能的实现方式,在一种可能的实现方式中,参考数据包包括配对序列号;配对参考信息包括提取信道特征的参考数据包中的配对序列号;配对单元具体用于:通过接收单元接收对端网络设备发送的、对端网络设备提取的网络设备与对端网络设备间的信道特征的至少一个数据包的配对序列号,网络设备根据配对序列号,将网络设备提取的网络设备与对端网络设备间的信道特征,与网络设备提取的网络设备与对端网络设备间的信道特征配对。或者,通过发送单元向对端网络设备发送、网络设备提取的网络设备与对端网络设备间的信道特征的至少一个数据包的配对序列号,用于对端网络设备根据配对序列号,将对端网络设备提取的网络设备与对端网络设备间的信道特征,与网络设备提取的网络设备与所述对端网络设备间的信道特征配对。
上述第三方面提供的网络设备,用于执行上述第一方面所述的提取信道特征的方法,与上述第一方面描述的提取信道特征的方法的具体实现及达到的有益效果相同,此处不再进行赘述。
第四方面,本发明实施例提供另一种网络设备,该网络设备可以包括:接收单元,于接收对端网络设备发送的参考数据包;提取单元,用于根据接收单元接收的参考数据包,提取网络设备与对端网络设备间的信道特征;配对单元,用于根据配对参考信息,与对端网络设备进行网络设备与对端网络设备间的信道特征配对。配对参考信息包括提取信道特征的时间戳,时间间隔最小的时间戳对应的信道特征为一对信道特征;或者,配对参考信息包括提取信道特征的参考数据包中的配对序列号,配对序列号相同的数据包提取的信道特征为一对信道特征。
结合第四方面,在一种可能的实现方式中,配对参考信息包括提取信道特征的时间戳,配对单元具体用于:记录第一时间戳,第一时间戳为网络设备提取网络设备与对端网络设备间的信道特征的系统时间;通过发送单元向对端网络设备发送第一时间戳,第一时间戳用于对端网络设备将对端网络设备提取的网络设备与对端网络设备间的信道特征,与网络设备提取的网络设备与对端网络设备间的信道特征配对;或者,通过接收单元接收对端网络设备发送的第二时间戳,第二时间戳为对端网络设备提取的网络设备与对端网络设备间的信道特征的系统时间,网络设备选取提取时间戳与第二时间戳间隔最小的网络设备与对端网络设备间的信道特征,与对端网络设备提取的网络设备与对端网络设备间的信道特征配对。
结合第四方面或上述任一种可能的实现方式,在一种可能的实现方式中,参考数据包包括配对序列号;配对参考信息包括提取信道特征的参考数据包中的配对序列号;配对单元具体用于:通过接收单元接收对端网络设备发送的、对端网络设备提取的网络设备与对端网络设备间的信道特征的至少一个数据包的配对序列号,网络设备根据配对序列号,将网络设备提取的网络设备与对端网络设备间的信道特征,与网络设备提取的网络设备与对端网络设备间的信道特征配对。或者,通过发送单元向对端网络设备发送、网络设备提取的网络设备与对端网络设备间的信道特征的至少一个数据包的配对序列号,用于对端网络设备根据配对序列号,将对端网络设备提取的网络设备与对端网络设备间的信道特征,与网络设备提取的网络设备与所述对端网络设备间的 信道特征配对。
结合第四方面或上述任一种可能的实现方式,在一种可能的实现方式中,接收单元具体用于:在链路层接收对端网络设备发送的参考数据包。
结合第四方面或上述任一种可能的实现方式,在一种可能的实现方式中,信道特征包括CSI;提取单元具体用于:对参考数据包进行多信道样本侦听,得到网络设备与对端网络设备间每个子信道的特征。
上述第四方面提供的网络设备,用于执行上述第二方面所述的提取信道特征的方法,与上述第二方面描述的提取信道特征的方法的具体实现及达到的有益效果相同,此处不再进行赘述。
第五方面,本发明实施例提供了再一种网络设备,该网络设备可以实现上述第一方面提供的提取信道特征的方法,所述网络设备的功能可以通过硬件实现,也可以通过硬件执行相应的软件实现。所述硬件或软件包括一个或多个上述功能相应的模块。
结合第五方面,在一种可能的实现方式中,该网络设备的结构中包括处理器和收发器,该处理器被配置为支持该网络设备执行上述方法。该收发器用于支持该网络设备与其他网元之间的通信。该网络设备还可以包括存储器,该存储器用于与处理器耦合,其保存该网络设备必要的程序指令和数据。
第六方面,本发明实施例提供了再一种网络设备,该网络设备可以实现上述第二方面提供的提取信道特征的方法,所述网络设备的功能可以通过硬件实现,也可以通过硬件执行相应的软件实现。所述硬件或软件包括一个或多个上述功能相应的模块。
结合第六方面,在一种可能的实现方式中,该网络设备的结构中包括处理器和收发器,该处理器被配置为支持该网络设备执行上述方法。该收发器用于支持该网络设备与其他网元之间的通信。该网络设备还可以包括存储器,该存储器用于与处理器耦合,其保存该网络设备必要的程序指令和数据。
第七方面,本发明实施例提供了一种计算机存储介质,用于储存为上述网络设备所用的计算机软件指令,其包含用于执行上述方法所设计的程序。
第八方面,本发明实施例提供了一种提取信道特征的系统,该系统包括两个上述任一方面所述的网络设备,两个网络设备相互通信提取两者之间的信道特征。
上述第五方面至第八方面提供的方案,可以与第一方面或第二方面达到相同的有益效果,此处不再进行赘述。
附图说明
图1为一种实体通信网络架构的结构示意图;
图2为本发明实施例提供的一种网络设备的结构示意图;
图3为本发明实施例提供的一种提取信道特征的方法的流程示意图;
图4a为本发明实施例提供的另一种提取信道特征的方法的流程示意图;
图4b为本发明实施例提供的再一种提取信道特征的方法的流程示意图;
图5为本发明实施例提供的数据包结构示意图;
图6为本发明实施例提供的一种网卡总体架构的结构示意图;
图7为本发明实施例提供的一种网卡固件多信道侦听示意图;
图8为本发明实施例提供的再一种提取信道特征的方法的流程示意图;
图9为本发明实施例提供的另一种网络设备的结构示意图;
图10为本发明实施例提供的再一种网络设备的结构示意图;
图11为本发明实施例提供的又一种网络设备的结构示意图。
具体实施方式
当前,信道特征样本提取技术采用的数据包交互和逻辑控制机制是基于网络层的ping工具。众所周知,基于网络层的ping工具的工作过程由于网络层的路由、控制报文协议(英文全称:Internet Control Message Protocol,ICMP)协议控制等流程,增加了数据包交互时间,在收发双方接收到数据包提取信道特征时,也将增加信道特征样本的时间间隔,降低了信道特征样本的相关性。
本发明实施例基于链路层进行提取信道特征的数据包交互,由于链路层数据包的传输特性,相比于网络层可以省略网络层的路由、ICMP协议控制等流程,减少了数据包交互时间,在收发双方接收到数据包提取信道特征时,也将减少信道特征样本的时间间隔,提高了信道特征样本的相关性。
本发明实施例提供的提取信道特征的方法,应用于如图1所示的实体通信网络架构中。该网络架构中包括通信实体101及通信实体102。
在图1所示的网络架构中,本发明实施例提供的提取信道特征的方法具体可以应用于通信实体101和通信实体102上。通信实体101和通信实体102,通过相互交互以提取两者之间的信道特征。
其中,通信实体101或者通信实体102可以为路由器、网关等网络设备,本发明实施例对于通信实体的类型不进行具体限定。
需要说明的是,在图1所示的网络架构中,通信实体101与通信实体102之间的通信方式可以为无线通信方式,但是对于两者之间的无线通信方式的类型,本发明实施例对此不进行具体限定。该无线通信方式可以包括但不限于:蜂窝通信、蓝牙通信、红外线通信等等。
提取的信道特征可以用于生成加密通信的密钥。根据信道特征生成通信密钥。当然,提取的信道特征也可以应用于其他场景,本发明实施例对此不进行具体限定。
本发明实施例提供的提取信道特征的方法,由本发明实施例提供的网络设备20实现,本发明实施例提供的网络设备20可以为图1所示的网络架构中通信实体101或者通信实体102。
图2示出的是与本发明各实施例相关的一种网络设备20的结构示意图。
如图2所示,网络设备20可以包括:处理器201、存储器202、通信总线203及收发器204。
存储器202,用于存储程序代码,并将该程序代码传输给该处理器201,以便处理器201执行程序代码实现网络设备20的各种功能。存储器202可以是易失性存储器(volatile memory),例如随机存取存储器(英文全称:random-access memory,RAM);或者非易失性存储器(英文全称:non-volatile memory),例如只读存储器(英文全称:read-only memory,ROM),快闪存储器(英文全称:flash memory),硬盘(英文全称:hard disk drive,HDD)或固态硬盘(英文全称:solid-state drive,SSD);或者上述种类的存储器的组合。
处理器201是网络设备20的控制中心,可以是一个中央处理器(英文全称:central processing unit,CPU),也可以是特定集成电路(英文全称:application specific integrated circuit,ASIC),或者是被配置成实施本发明实施例的一个或多个集成电路,例如:一个或多个微处理器(英文全称:digital singnal processor,DSP),或,一个或者多个现场可编程门阵列(英文全称:field programmable gate array,FPGA)。处理器201可以通过运行或执行存储在存储器202内的程序代码,以及调用存储在存储器202内的数据,实现网络设备20的各种功能。
其中,通信总线203可以是工业标准体系结构(英文全称:industry standard architecture,ISA)总线、外部设备互连(英文全称:peripheral component Interconnect,PCI)总线或扩展工业标准体系结构(英文全称:extended industry standard architecture,EISA)总线等。该总线203可以分为地址总线、数据总线、控制总线等。为便于表示,图2中仅用一条粗线表示,但并不表示仅有一根总线或一种类型的总线。
收发器204可以为网络设备20可以为网卡或者网络端口,用于接收其他通信实体传送的数据包,或者向其他通信实体发送数据包。本发明实施例对于收发器204的类型不进行具体限定。
其中,处理器201具体可以用于:在链路层接收第二网络设备发送的参考数据包;根据参考数据包,提取网络设备20与对端网络设备间的信道特征。
下面结合附图,对本发明的实施例进行具体阐述。
一方面,本发明实施例提供一种提取信道特征的方法,应用于第一网络设备。如图3所示,本发明实施例提供的提取信道特征的方法可以包括:
S301、第一网络设备在链路层接收第二网络设备发送的参考数据包。
其中,第一网络设备可以为相互通信的两个实体中的任一端网络设备,本发明实施例对此不进行具体限定。即第一网络设备可以为通过相互通信提取信道特征的双方中的发送端网络设备,也可以为接收端网络设备。
可选的,当第一网络设备为通过相互通信提取信道特征的双方中的发送端网络设备时,第二网络设备则为通过相互通信提取信道特征的双方中的接收端网络设备。相反的,当第一网络设备为通过相互通信提取信道特征的双方中的接收端网络设备时,第二网络设备则为通过相互通信提取信道特征的双方中的发送端网络设备。
进一步的,根据第一网络设备在数据包交互时的角色不同,参考数据包的类型不同。具体的,参考数据包可以包括下述两种类型:
第一种类型、当第一网络设备为发送端网络设备,参考数据包为第一网络设备向第二网络设备发送的信标数据包的响应数据包。
可选的,当参考数据包为上述第一种类型时,在S301中第一网络设备在链路层接收第二网络设备发送的参考数据包之前,如图4a所示,本发明实施例提供的提取信道特征的方法还可以包括S301a。
S301a、第一网络设备生成信标数据包,并通过链路层向第二网络设备发送信标数据包。
其中,在S301中,信标数据包是第一网络设备发送的,用于提取信道特征的探 测性质的数据包。本发明实施例对于信标数据包的类型及格式均不进行具体限定,凡是在链路层传输的数据包,都可以作为该信标数据包。在实际应用中,可以根据实际需求设置信标数据包的类型及格式。
可选的,信标数据包可以包括链路层管理帧。将链路层管理帧作为信标数据包,可以绕开链路层的重传确认机制,更进一步的简化数据包交互协议,提高信道特征样本的相关性。
第二种类型、当第一网络设备为接收端网络设备,参考数据包为第二网络设备向第二网络设备发送的信标数据包。
可选的,当参考数据包为上述第二种类型时,在S301中第一网络设备在链路层接收第二网络设备发送的参考数据包之后,如图4b所示,本发明实施例提供的提取信道特征的方法还可以包括S301b。
S301b、第一网络设备通过链路层向第二网络设备发送信标数据包的响应数据包。
其中,在S301b中,描述的信标数据包与上述S301a中描述的信标数据包内容相同,只是在S301b中,该信标数据包由第二网络设备向第一网络设备发送,因此,对于信标数据包的内容此处不再进行赘述。
进一步的,信标数据包的响应数据包是第一网络设备向第二网络设备发送的,用于反馈第一网络设备已成功接收信标数据包的反馈数据包,第二网络设备根据信标数据包的响应数据包,可以提取两者之间的信道特征。本发明实施例对于信标数据包的响应数据包的类型及格式均不进行具体限定。在实际应用中,可以根据实际需求设置信标数据包的响应数据包的类型及格式。
S302、第一网络设备根据参考数据包,提取第一网络设备与第二网络设备间的信道特征。
需要说明的是,在图4b所示意的实施例中,S302与S301b的执行顺序不要求先后顺序,可以根据实际需求设定。图4b中仅示意了一种可能的执行顺序,并不是对此的具体限定。
可选的,信道特征可以包括CSI或接收信号强度(英文全称:Received Signal Strength,RSS)。
需要说明的是,对于CSI中包括的具体内容,可以根据实际需求配置,本发明实施例对此不进行具体限定。
通常,如图5所示,示意了一种带有radiotap头(即无线信道物理参数头部)的数据包的结构。在带有radiotap头的数据包中,还包括数据(data)部分。其中,radiotap头中包括包头版本(Header Revision)字段、包头填充(Header Pad)字段、包头长度(Header Length)字段、当前标记(Present flags)字段、时间戳(Timestamo)字段、标记(Flags)字段、数据传输速率、信道频率及信号强度等。其中,数据传输速率、信道频率及信号强度等字段为CSI。
需要说明的是,图5示意的数据包结构,仅仅是通过举例的形式,对包头中包括的CSI进行说明,并不是对数据包结构的具体限定。
具体的,通过将网络设备中网卡设置为不同的模式,配置S301中接收参考数据包的不同方式。可选的,可以将网络设备中网卡设置为下述两种方式:
第一种方式、网卡为正常模式,S302中进行单信道侦听,提取信道特征为RSS。
示例性的,在第一种方式中,在正常的网卡模式下,当网络设备中的网卡接收到数据包后,在网卡设置成侦听模式后,在应用层使用libpacp库(即网络数据包捕捉函数库)抓取带有radiotap头的数据包,在无线网卡的驱动层会进行转换,数据包转换成通用的802.3以太网帧格式,丢失了CSI,只能进行单信道样本侦听。
第二种方式、配置网卡支持记录每个子信道的信道特征的模式,S302中进行多信道侦听,提取信道特征为CSI。
具体的,在802.11n中,由于采用正交频分复用(英文全称:orthogonal frequency division multiplexing,OFDM)技术传输数据包,原本的一个信道被划分成30或60个子信道,每个子信道都有各自不同的信道特征(信号强度,频率等)。通过网卡记录每个子信道的信道特征,以进行多信道侦听。
需要说明的是,可以通过修改网卡固件,使得网卡支持记录每个子信道的信道特征。
示例性的,在第二种方式中,当网络设备中的网卡接收到数据包后,在网卡设置成侦听模式后,在应用层使用libpacp库抓取带有radiotap头的数据包,网卡固件记录每个子信道的信道特征,得到CSI数据。
示例性的,如图6所示,示意了多信道侦听时网卡的总体架构,涉及物理层,网卡驱动层和应用层三个部分,下面分别介绍。
在物理层中,修改网卡固件,使网卡支持记录每个子信道的信道特征。如图7所示,修改过的网卡固件会记录每个子信道的信道特征,并封装到数据结构CSI中,同时固件以中断的方式为驱动程序提供编程接口,驱动程序可以通过该接口获取CSI数据传到应用层捕获,即提取到了信道特征。
需要说明的是,网卡固件向驱动程序提供编程接口的方式,除了上述的中断方式之外,也可以通过其他方式,本发明实施例对此不进行具体限定。
在无线网卡驱动层的操作如下示例:
首先,对应固件的命令码设置CSI在驱动层的中断处理函数:
handlers[REPLY_BFEE_NOTIFICATION]=iwlagn_bfee_notif
handlers[REPLY_RX_MPDU_CMD]=iwlagn_rx_reply_rx
然后,修改网卡正常通信中断处理函数iwlagn_rx_reply_rx和编写CSI中断处理函数iwlagn_bfee_notif。
如图6所示,在iwlagn_rx_reply_rx函数中对数据包进行过滤,设置flag,然后在iwlagn_bfee_notif函数中根据之前设置的flag,将符合条件的CSI样本使用Netlink Socket传到应用层捕获程序。
进一步的,网卡驱动程序和应用层捕获程序之间使用自定义Netlink Socket(内核与用户空间通信套接字)传递数据,这个工作由驱动层和应用层两部分完成。这两部分采用发布-订阅模式。
示例性的,Netlink Socket在驱动层的发布示意如下代码:
Figure PCTCN2017119956-appb-000001
Figure PCTCN2017119956-appb-000002
其中,Netlink Socket在驱动层以模块的方式加载,自定义Netlink Socket由connector_id标识,然后实现cn_add_callback,cn_del_callback和cn_netlink_send函数,分别用于netlink添加的初始化,netlink删除的处理和向应用层发送数据的逻辑。
示例性的,Netlink Socket在应用层的订阅示意如下代码:
Figure PCTCN2017119956-appb-000003
其中,Netlink Socket在应用层的使用方式和常规的socket有着同样的编程接口。使用struct nlmsghdr表示socket的目的地址,该地址中.nl_group字段对应驱动层发布Netlink Socket的.idx字段,表示该Netlink Socket订阅驱动层Netlink Socket的数据。此时驱动层通过cn_netlink_send发送的数据在应用层Netlink Socket中都可以接收到。
进一步的,可以使用消息队列对CSI进行缓存,并启动工作线程一部向应用层发送CSI数据。CSI数据在驱动层的缓存示意为如下代码:
connector_send_msg(*data,size,code)
connector_enqueue_msg(cn_msg*msg)
connector_send_all
cn_netlink_send
其中,CSI数据在驱动层的缓存流程依次包括:消息入队列、发布队列中的消息到订阅了CN_IDX_IWLAGN的connector。
通过上述示例,描述了S302中对参考数据包进行多信道侦听,提取信道特征CSI的过程。
需要说明的是,在实际应用中,可以执行至少一次上述S301和S302的过程,以提取第一网络设备与第二网络设备之间信道的至少一个信道特征,用于生成密钥进行第一网络设备与第二网络设备之间的加密通信。当然,提取的第一网络设备与第二网络设备之间信道的至少一个信道特征,也可以做其他用途,本发明实施例对此不进 行具体限定。
本发明实施例提供的提取信道特征的方法,由于用于提取信道特征的参考数据包是在链路层交互,相比网络层交互数据包,省略了路由、协议控制等流程,可以简化数据包的交互过程,大大减少了收发双发提取信道特征的时间间隔,也就是减少了特征样本时间间隔。在采用信道特征生成密钥加密通信时,能很好的增加信道特征样本的相关性,提高密钥的准确性及提取速率。
进一步的,当第一网络设备为发送端网络设备,如图4a所示,在S301a中第一网络设备生成信标数据包,并通过链路层向第二网络设备发送信标数据包之后,本发明实施例提供的提取信道特征方法还可以包括S303。
S303、判断从执行第一网络设备通过链路层向第二网络设备发送信标数据包的时刻开始的预设时间段内,是否接收到信标数据包的响应数据包。
其中,预设时长可以根据实际网络需求设定,本发明实施例对此不进行具体限定。对于预设时长的计时,可以采用计时器或者其他计时方式实现,本发明实施例对此也不进行具体限定。
具体的,在S303之后,若第一网络设备通过链路层向第二网络设备发送信标数据包的时刻开始的预设时间段内,未接收到信标数据包的响应数据包,则执行S304。进一步的,在S303之后,若第一网络设备通过链路层向第二网络设备发送信标数据包的时刻开始的预设时间段内,第一网络设备接收到信标数据包的响应数据包,则执行S301接收到参考数据包。
S304、第一网络设备重新通过链路层向第二网络设备发送信标数据包。
进一步的,在S304之后,可以重新执行S303。通过S303和S304的执行,实现了超时重传的机制,避免丢包对数据包交互准确性的影响。
进一步的,如图4a或图4b所示,在S302中第一网络设备根据参考数据包,提取第一网络设备与第二网络设备间的信道特征之后,本发明实施例提供的提取信道特征方法还可以包括S305。
S305、第一网络设备根据配对参考信息,与第二网络设备进行第一网络设备与第二网络设备间的信道特征配对。
具体的,通信双发通过交互配对参考信息,以实现信道特征的配对。相互配对的信道特征,在使用信道特征的场景中,为相同的考量因素。例如,相互配对的信道特征,在生成密钥时,为算法中同一参数。
进一步的,通信双方在向对端发送配对参考信息时,还携带了用于指示本次配对得到的一对特征信息在使用时所处的考量因素,或者在计算中的参数位置。
需要说明的是,在上述两种配对参考信息中,通信双发只需要一方向对端发送配对参数信息即可。具体由哪一方发送,可以根据实际需求设定,本发明实施例对此不进行具体限定。
具体的,根据配对参考信息的内容不同,可以定义不同的配对规则。下面描述本发明实施例提供的两种配对规则。
第一种配对规则:
配对参考信息可以包括提取信道特征的时间戳,配对规则为:时间间隔最小的时 间戳对应的信道特征为一对信道特征。
其中,时间间隔最小的时间戳对应的信道特征,是通信双方分别提取的两者之间的时间戳。
需要说明的是,若配对参考信息为提取信道特征的时间戳,在进行数据包交互之前,通信双发先进行系统时钟同步,再进行数据包交互。时间戳即为同步后的系统时间。本发明实施例对于时间戳的形式不进行具体限定。
第二种配对规则:
配对参考信息包括提取信道特征的参考数据包中的配对序列号,配对规则为:配对序列号相同的数据包提取的信道特征为一对信道特征。
其中,配对序列号相同的数据包提取的信道特征,是通信双方分别提取的两者之间的时间戳。
需要说明的是,当配对参考信息包括提取信道特征的参考数据包中的配对序列号时,参考数据包中包括配对序列号。对于配对序列号在参考数据包中的具体位置,以及配对序列号的内容,本发明实施例对此不进行限定,可以根据实际需求配置。
还需要说明的是,配对参考信息除了上述时间戳或配对序列号之外,还可以采用其他信息,本发明实施例对此不进行具体限定。
下面分别描述配对参考信息为时间戳或配对序列号时,通信双方进行信道特征样本配对的过程。
可选的,若配对参考信息为提取信道特征的时间戳,在S305中第一网络设备根据配对参考信息,与第二网络设备进行第一网络设备与第二网络设备间的信道特征配对具体可以实现为下述步骤1和步骤2。
步骤1、第一网络设备记录第一时间戳,第一时间戳为第一网络设备提取第一网络设备与第二网络设备间的信道特征的系统时间。
步骤2、第一网络设备向第二网络设备发送第一时间戳。
其中,步骤2中,第一时间戳用于第二网络设备将第二网络设备提取的第一网络设备与第二网络设备间的信道特征,与第一网络设备提取的第一网络设备与第二网络设备间的信道特征配对。
需要说明的是,在上述S305实现为步骤1和步骤2的过程中,第二网络侧设备也记录了提取第一网络设备与第二网络设备间的信道特征的系统时间。当第二网络设备接收到第一网络设备发送第一时间戳之后,选择自身提取的信道特征中,提取时间戳与第一时间戳时间间隔最小的信道特征,作为与第一网络设备在第一时间戳提取的第一网络设备与第二网络设备间的信道特征的配对信道特征。
可选的,若配对参考信息为提取信道特征的时间戳,在S305中第一网络设备根据配对参考信息,与第二网络设备进行第一网络设备与第二网络设备间的信道特征配对具体可以实现为下述步骤a和步骤b。
步骤a、第一网络设备记录第一时间戳。
步骤b、第一网络设备接收第二网络设备发送的第二时间戳,第一网络设备选取提取时间戳与第二时间戳间隔最小的第一网络设备与第二网络设备间的信道特征,与第二网络设备在第二时间戳提取的第一网络设备与第二网络设备间的信道特征配对。
其中,第二时间戳为第二网络设备提取的第一网络设备与第二网络设备间的信道特征的系统时间。
还需要说明的是,通过上述步骤1和步骤2,或者,步骤a和步骤b,实现对记录的每一个信道特征进行配对的目的。对记录的每一个信道特征进行配对时,可以对每一个信道特征执行一次上述步骤1和步骤2,或者,一次步骤a和步骤b,也可以对提取的所有信道特征执行一次上述步骤1和步骤2,或者,一次步骤a和步骤b。本发明实施例对此不进行具体限定。
示例性的,假设Alice和Bob为通信的双发,Alice为数据交互中的发送端网络设备。通过5次数据包交互,Alice提取的两者之间的信道特征样本如表1所示,Bob提取的两者之间的信道特征样本如表2所示。
表1
信道特征样本 提取时间戳
样本1 10:05:48
样本2 10:10:30
样本3 10:12:10
样本4 10:14:56
样本5 10:16:21
表2
信道特征样本 提取时间戳
样本a 10:05:42
样本b 10:14:44
样本c 10:16:15
样本d 10:10:25
样本e 10:12:00
在进行信道特征样本配对时,Alice向Bob发送配对消息1,其内容为:{(10:05:48,X),(10:10:30,Y),(10:12:10,Z)(10:14:56,R)(10:16:21,Q)}。其中,X、Y、Z、R、Q为生成密钥时的参数。
当Bob接收到配对消息1时,根据配对消息1中的5个时间戳,对比表2中的时间戳,分别选择时间间隔最小的时间戳提取的信道特征样本与其配对,得到的配对结果为:样本a与Alice10:05:48提取的信道特征配对,作为生成密钥时的X参数,样本b与Alice10:14:56提取的信道特征配对,作为生成密钥时的R参数,样本c与Alice10:16:21提取的信道特征配对,作为生成密钥时的Q参数,样本d与Alice10:10:30提取的信道特征配对,作为生成密钥时的Y参数,样本e与Alice10:12:10提取的信道特征配对,作为生成密钥时的Z参数。
之后,Alice和Bob分别将各自提取的信道特征样本按照配对结果代入X、Y、Z、R、Q参数生成加密通信的密钥。需要说明的是,本发明实施例对于生成加密通信的密钥的具体算法及参数不进行限定。
可选的,若配对参考信息为配对序列号,在S305中第一网络设备根据配对参考信息,与第二网络设备进行第一网络设备与第二网络设备间的信道特征配对具体可以 实现为:
第一网络设备接收第二网络设备发送的、第二网络设备提取第一网络设备与所述第二网络设备间的信道特征的至少一个数据包的配对序列号,第一网络设备根据配对序列号,将第一网络设备提取的第一网络设备与所述第二网络设备间的信道特征,与第二网络设备提取的第一网络设备与所述第二网络设备间的信道特征配对。其中,第一网络设备可以为发送端网络设备或者接收端网络设备。
可选的,若配对参考信息为配对序列号,在S305中第一网络设备根据配对参考信息,与第二网络设备进行第一网络设备与第二网络设备间的信道特征配对具体可以实现为:
第一网络设备向第二网络设备发送、第一网络设备提取第一网络设备与第二网络设备间的信道特征的至少一个数据包的配对序列号,用于第二网络设备根据配对序列号,将第二网络设备提取的第一网络设备与第二网络设备间的信道特征,与第一网络设备提取的第一网络设备与第二网络设备间的信道特征配对。
示例性的,假设Alice和Bob为通信的双发,Alice为数据交互中的发送端网络设备。通过5次数据包交互,Alice提取的两者之间的信道特征样本如表3所示,Bob提取的两者之间的信道特征样本如表4所示。
表3
信道特征样本 配对序列号
样本1 001
样本2 011
样本3 111
样本4 101
样本5 100
表4
信道特征样本 配对序列号
样本a 100
样本b 011
样本c 101
样本d 001
样本e 111
在进行信道特征样本配对时,Alice向Bob发送配对消息2,其内容为:{(001,X),(011,Y),(111,Z)(101,R)(100,Q)}。其中,X、Y、Z、R、Q为生成密钥时的参数。
当Bob接收到配对消息2时,根据配对消息2中的5个配对序列号,对比表2中的配对序列号,配对序列号相同的信道特征样本配为一对,得到的配对结果为:样本a与Alice从包括配对序列号100的数据包中提取的信道特征配对,作为生成密钥时的Q参数,样本b与Alice从包括配对序列号011的数据包中提取的信道特征配对,作为生成密钥时的Y参数,样本c与Alice从包括配对序列号101的数据包中提取的信道特征配对,作为生成密钥时的R参数,样本d与Alice从包括配对序列号001的 数据包中提取的信道特征配对,作为生成密钥时的X参数,样本e与Alice从包括配对序列号111的数据包中提取的信道特征配对,作为生成密钥时的Z参数。
之后,Alice和Bob分别将各自提取的信道特征样本按照配对结果代入X、Y、Z、R、Q参数生成加密通信的密钥。需要说明的是,本发明实施例对于生成加密通信的密钥的具体算法及参数不进行限定。
进一步的,当一个网络设备接收到对端发送的配对参考信息,并进行配对之后,若自身提取的信道特征中存在未完成配对的信道特征,则将未完成配对的信道特征去除。或者,当一个网络设备接收到对端发送的配对参考信息,并进行配对之后,若存在接收到的配对参考信息未找到可配对的信道特征,则向对端反馈该未找到可配对的信道特征的配对参考信息,使得对端将该未找到可配对的信道特征配对参考信息对应的信道特征去除。
另一方面,本发明实施例提供再一种提取信道特征的方法,如图8所示,该方法可以包括:
S801、第一网络设备接收第二网络设备发送的参考数据包。
其中,第一网络设备、第二网络设备及参考数据包已经在图3或图4a或图4b所示的实施例中进行了详细描述,此处不再进行赘述。
可选的,在S801中,第一网络设备与第二网络设备可以在链路层进行数据包的交互,也可以在网络层基于ping工作进行数据包的交互,本发明实施例对此不进行具体限定。
进一步的,若在S801中,第一网络设备与第二网络设备可以在链路层进行数据包的交互,其具体过程已经在图3或图4a或图4b所示的实施例中进行了详细描述,此处不再进行赘述。
进一步的,若在S801中,第一网络设备与第二网络设备在网络层基于ping工作进行数据包的交互,其具体过程为常规ping工具工作流程,此处不再进行赘述。
S802、第一网络设备根据参考数据包,提取第一网络设备与第二网络设备间的信道特征。
其中,信道特征可以包括RSS或CSI。
需要说明的是,S802中的内容可以参照S302中的详细描述,此处不再进行赘述。
S803、第一网络设备根据配对参考信息,与第二网络设备进行第一网络设备与所述第二网络设备间的信道特征配对。
其中,配对参考信息包括提取信道特征的时间戳,时间间隔最小的时间戳对应的信道特征为一对信道特征;或者,配对参考信息包括提取信道特征的所述参考数据包中的配对序列号,配对序列号相同的数据包提取的信道特征为一对信道特征。
需要说明的是,S803中的内容可以参照S305中的详细描述,此处不再进行赘述。
还需要说明的是,在图8所示的实施例中,还可以包括图4a或图4b所示的参照图4a或图4b所示的实施例中的其他功能的具体实现方式,此处不再一一进行描述。
本发明实施例提供的提取信道特征的方法,通过对收发双发提取的两者之间的信道特征进行配对,保证了丢包和重传情况下信道特征的样本配对性,提高了信道特征样本的相关性。在采用信道特征生成密钥加密通信时,较高的信道特征样本的相关性, 保证了密钥的准确性。
上述主要从第一网络设备的工作过程的角度对本发明实施例提供的方案进行了介绍。可以理解的是,第一网络设备为了实现上述功能,其包含了执行各个功能相应的硬件结构和/或软件模块。本领域技术人员应该很容易意识到,结合本文中所公开的实施例描述的各示例的单元及算法步骤,本申请能够以硬件或硬件和计算机软件的结合形式来实现。某个功能究竟以硬件还是计算机软件驱动硬件的方式来执行,取决于技术方案的特定应用和设计约束条件。专业技术人员可以对每个特定的应用来使用不同方法来实现所描述的功能,但是这种实现不应认为超出本发明的范围。
本发明实施例可以根据上述方法示例对网络设备进行功能模块的划分,例如,可以对应各个功能划分各个功能模块,也可以将两个或两个以上的功能集成在一个处理模块中。上述集成的模块既可以采用硬件的形式实现,也可以采用软件功能模块的形式实现。需要说明的是,本发明实施例中对模块的划分是示意性的,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式。
在采用对应各个功能划分各个功能模块的情况下,图9示出了上述实施例中所涉及的网络设备90的一种可能的结构示意图,网络设备90包括:接收单元901,提取单元902。接收单元901用于支持网络设备90执行图3或图4a或图4b中的过程S301,接收单元901还可以用于支持网络设备90执行图8中的过程S801。提取单元902用于支持网络设备90执行图3或图4a或图4b中的过程S302,提取单元902还可以用于支持网络设备90执行图8中的过程S802。其中,上述方法实施例涉及的各步骤的所有相关内容均可以援引到对应功能模块的功能描述,在此不再赘述。
进一步的,图10示出了上述实施例中所涉及的网络设备90的另一种可能的结构示意图,网络设备90还可以包括发送单元903,计时单元904、配对单元905。发送单元903用于支持网络设备90执行图4a或图4b中的过程S301a、S301b;计时单元904还可以用于支持网络设备90执行图4a中的过程S303、S304;配对单元905还可以用于支持网络设备90执行图3中的过程S305,或者,配对单元905还可以用于支持网络设备90执行图8中的过程S803。
在采用集成的单元的情况下,图11示出了上述实施例中所涉及的网络设备110的一种可能的结构示意图。网络设备110可以包括:处理模块1101、通信模块1102。处理模块1101用于对网络设备110的动作进行控制管理。例如,处理模块1101用于支持网络设备110执行图3中的过程S301和S302,处理模块1101用于支持网络设备110执行图4a或图4b中的过程S301、S302、S303、S304及S305,处理模块1101还用于支持网络设备110执行图8中的过程S801、S802和S803,和/或用于本文所描述的技术的其它过程。处理模块1101还用于通过通信模块1102支持网络设备110执行图4a或图4b中的过程S301a和S301b。通信模块1102用于支持网络设备110与其他网络实体的通信。网络设备110还可以包括存储模块1103,用于存储网络设备110的程序代码和数据。
其中,处理模块1101可以为图2所示的网络设备20的实体结构中的处理器201,可以是处理器或控制器,例如可以是CPU,通用处理器,DSP,ASIC,FPGA或者其他可编程逻辑器件、晶体管逻辑器件、硬件部件或者其任意组合。其可以实现或执行 结合本发明公开内容所描述的各种示例性的逻辑方框,模块和电路。所述处理器也可以是实现计算功能的组合,例如包含一个或多个微处理器组合,DSP和微处理器的组合等等。通信模块1102可以是通信端口,或者可以是收发器、收发电路或通信接口等。存储模块1104可以是图2所示的网络设备20的实体结构中的存储器202。
当处理模块1101为处理器,通信模块1102为收发器,存储模块1103为存储器时,本发明实施例图11所涉及的网络设备110可以为图2所示的网络设备20。
结合本发明公开内容所描述的方法或者算法的步骤可以硬件的方式来实现,也可以是由处理器执行软件指令的方式来实现。软件指令可以由相应的软件模块组成,软件模块可以被存放于RAM、闪存、ROM、可擦除可编程只读存储器(Erasable Programmable ROM,EPROM)、电可擦可编程只读存储器(Electrically EPROM,EEPROM)、寄存器、硬盘、移动硬盘、只读光盘(CD-ROM)或者本领域熟知的任何其它形式的存储介质中。一种示例性的存储介质耦合至处理器,从而使处理器能够从该存储介质读取信息,且可向该存储介质写入信息。当然,存储介质也可以是处理器的组成部分。处理器和存储介质可以位于ASIC中。另外,该ASIC可以位于核心网接口设备中。当然,处理器和存储介质也可以作为分立组件存在于核心网接口设备中。
所属领域的技术人员可以清楚地了解到,为描述的方便和简洁,上述描述的系统,装置和单元的具体工作过程,可以参考前述方法实施例中的对应过程,在此不再赘述。
在本申请所提供的几个实施例中,应该理解到,所揭露的系统,装置和方法,可以通过其它的方式实现。例如,以上所描述的装置实施例仅仅是示意性的,例如,所述单元的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,例如多个单元或组件可以结合或者可以集成到另一个系统,或一些特征可以忽略,或不执行。另一点,所显示或讨论的相互之间的耦合或直接耦合或通信连接可以是通过一些接口,装置或单元的间接耦合或通信连接,可以是电性或其它的形式。
所述作为分离部件说明的单元可以是或者也可以不是物理上分开的,作为单元显示的部件可以是或者也可以不是物理单元,即可以位于一个地方,或者也可以分布到多个网络单元上。可以根据实际的需要选择其中的部分或者全部单元来实现本实施例方案的目的。
另外,在本发明各个实施例中的各功能单元可以集成在一个处理单元中,也可以是各个单元单独物理包括,也可以两个或两个以上单元集成在一个单元中。上述集成的单元既可以采用硬件的形式实现,也可以采用硬件加软件功能单元的形式实现。
上述以软件功能单元的形式实现的集成的单元,可以存储在一个计算机可读取存储介质中。上述软件功能单元存储在一个存储介质中,包括若干指令用以使得一台计算机设备(可以是个人计算机,服务器,或者网络设备等)执行本发明各个实施例所述方法的部分步骤。而前述的存储介质包括:U盘、移动硬盘、只读存储器(Read-Only Memory,简称ROM)、随机存取存储器(Random Access Memory,简称RAM)、磁碟或者光盘等各种可以存储程序代码的介质。
最后应说明的是:以上实施例仅用以说明本发明的技术方案,而非对其限制;尽管参照前述实施例对本发明进行了详细的说明,本领域的普通技术人员应当理解:其 依然可以对前述各实施例所记载的技术方案进行修改,或者对其中部分技术特征进行等同替换;而这些修改或者替换,并不使相应技术方案的本质脱离本发明各实施例技术方案的精神和范围。

Claims (26)

  1. 一种提取信道特征的方法,其特征在于,所述方法包括:
    第一网络设备在链路层接收第二网络设备发送的参考数据包;
    所述第一网络设备根据所述参考数据包,提取所述第一网络设备与所述第二网络设备间的信道特征。
  2. 根据权利要求1所述的方法,其特征在于,所述方法还包括:
    所述第一网络设备生成信标数据包,并通过链路层向所述第二网络设备发送所述信标数据包;所述参考数据包为所述信标数据包的响应数据包。
  3. 根据权利要求2所述的方法,其特征在于,在所述第一网络设备生成信标数据包,并通过链路层向所述第二网络设备发送所述信标数据包之后,所述方法还包括:
    从所述通过链路层向所述第二网络设备发送所述信标数据包的时刻开始的预设时间段内,若所述第一网络设备未接收到所述信标数据包的响应数据包,所述第一网络设备通过链路层重新向所述第二网络设备发送所述信标数据包。
  4. 根据权利要求1-3任一项所述的方法,其特征在于,所述信道特征包括信道状态信息CSI;
    所述第一网络设备根据所述参考数据包,提取所述第一网络设备与所述第二网络设备间的信道特征,包括:
    所述第一网络设备对所述参考数据包进行多信道样本侦听,得到所述第一网络设备与所述第二网络设备间每个子信道的特征。
  5. 根据权利要求1-4任一项所述的方法,其特征在于,在所述第一网络设备根据所述参考数据包,提取所述第一网络设备与所述第二网络设备间的信道特征之后,所述方法还包括:
    所述第一网络设备根据配对参考信息,与所述第二网络设备进行所述第一网络设备与所述第二网络设备间的信道特征配对;
    所述配对参考信息包括提取信道特征的时间戳,时间间隔最小的时间戳对应的信道特征为一对信道特征;或者,所述配对参考信息包括提取信道特征的所述参考数据包中的配对序列号,配对序列号相同的数据包提取的信道特征为一对信道特征。
  6. 根据权利要求5所述的方法,其特征在于,所述配对参考信息包括提取信道特征的时间戳,所述第一网络设备根据配对参考信息,与所述第二网络设备进行所述第一网络设备与所述第二网络设备间的信道特征配对,包括:
    所述第一网络设备记录第一时间戳,所述第一时间戳为所述第一网络设备提取所述第一网络设备与所述第二网络设备间的信道特征的系统时间;
    所述第一网络设备向所述第二网络设备发送所述第一时间戳,所述第一时间戳用于所述第二网络设备将所述第二网络设备提取的所述第一网络设备与所述第二网络设备间的信道特征,与所述第一网络设备提取的所述第一网络设备与所述第二网络设备间的信道特征配对;或者,所述第一网络设备接收所述第二网络设备发送的第二时间戳,所述第二时间戳为所述第二网络设备提取的所述第一网络设备与所述第二网络设备间的信道特征的系统时间,所述第一网络设备选取提取时间戳与所述第二时间戳间隔最小的所述第一网络设备与所述第二网络设备间的信道特征,与所述第二网络设备 提取的所述第一网络设备与所述第二网络设备间的信道特征配对。
  7. 根据权利要求5所述的方法,其特征在于,所述参考数据包包括配对序列号;所述配对参考信息包括提取信道特征的所述参考数据包中的配对序列号;
    所述第一网络设备根据配对参考信息,与所述第二网络设备进行所述第一网络设备与所述第二网络设备间的信道特征配对,包括:
    所述第一网络设备接收所述第二网络设备发送的、所述第二网络设备提取所述第一网络设备与所述第二网络设备间的信道特征的至少一个数据包的配对序列号,所述第一网络设备根据配对序列号,将所述第一网络设备提取的所述第一网络设备与所述第二网络设备间的信道特征,与所述第二网络设备提取的所述第一网络设备与所述第二网络设备间的信道特征配对;
    或者,
    所述第一网络设备向所述第二网络设备发送、所述第一网络设备提取所述第一网络设备与所述第二网络设备间的信道特征的至少一个数据包的配对序列号,用于所述第二网络设备根据配对序列号,将所述第二网络设备提取的所述第一网络设备与所述第二网络设备间的信道特征,与所述第一网络设备提取的所述第一网络设备与所述第二网络设备间的信道特征配对。
  8. 一种提取信道特征的方法,其特征在于,所述方法包括
    第一网络设备接收第二网络设备发送的参考数据包;
    所述第一网络设备根据所述参考数据包,提取所述第一网络设备与所述第二网络设备间的信道特征;
    所述第一网络设备根据配对参考信息,与所述第二网络设备进行所述第一网络设备与所述第二网络设备间的信道特征配对;
    所述配对参考信息包括提取信道特征的时间戳,时间间隔最小的时间戳对应的信道特征为一对信道特征;或者,所述配对参考信息包括提取信道特征的所述参考数据包中的配对序列号,配对序列号相同的数据包提取的信道特征为一对信道特征。
  9. 根据权利要求8所述的方法,其特征在于,所述配对参考信息包括提取信道特征的时间戳,所述第一网络设备根据配对参考信息,与所述第二网络设备进行所述第一网络设备与所述第二网络设备间的信道特征配对,包括:
    所述第一网络设备记录第一时间戳,所述第一时间戳为所述第一网络设备提取所述第一网络设备与所述第二网络设备间的信道特征的系统时间;
    所述第一网络设备向所述第二网络设备发送所述第一时间戳,所述第一时间戳用于所述第二网络设备将所述第二网络设备提取的所述第一网络设备与所述第二网络设备间的信道特征,与所述第一网络设备提取的所述第一网络设备与所述第二网络设备间的信道特征配对;或者,所述第一网络设备接收所述第二网络设备发送的第二时间戳,所述第二时间戳为所述第二网络设备提取的所述第一网络设备与所述第二网络设备间的信道特征的系统时间,所述第一网络设备选取提取时间戳与所述第二时间戳间隔最小的所述第一网络设备与所述第二网络设备间的信道特征,与所述第二网络设备提取的所述第一网络设备与所述第二网络设备间的信道特征配对。
  10. 根据权利要求8所述的方法,其特征在于,所述参考数据包包括配对序列号; 所述配对参考信息包括提取信道特征的所述参考数据包中的配对序列号;
    所述第一网络设备根据配对参考信息,与所述第二网络设备进行所述第一网络设备与所述第二网络设备间的信道特征配对,包括:
    所述第一网络设备接收所述第二网络设备发送的、所述第二网络设备提取所述第一网络设备与所述第二网络设备间的信道特征的至少一个数据包的配对序列号,所述第一网络设备根据配对序列号,将所述第一网络设备提取的所述第一网络设备与所述第二网络设备间的信道特征,与所述第二网络设备提取的所述第一网络设备与所述第二网络设备间的信道特征配对;
    或者,
    所述第一网络设备向所述第二网络设备发送、所述第一网络设备提取所述第一网络设备与所述第二网络设备间的信道特征的至少一个数据包的配对序列号,用于所述第二网络设备根据配对序列号,将所述第二网络设备提取的所述第一网络设备与所述第二网络设备间的信道特征,与所述第一网络设备提取的所述第一网络设备与所述第二网络设备间的信道特征配对。
  11. 根据权利要求8-10任一项所述的方法,其特征在于,所述第一网络设备接收第二网络设备发送的参考数据包,包括:
    所述第一网络设备在链路层接收所述第二网络设备发送的参考数据包。
  12. 根据权利要求11所述的方法,其特征在于,所述信道特征包括信道状态信息CSI;
    所述第一网络设备根据所述参考数据包,提取所述第一网络设备与所述第二网络设备间的信道特征,包括:
    所述第一网络设备对所述参考数据包进行多信道样本侦听,得到所述第一网络设备与所述第二网络设备间每个子信道的特征。
  13. 一种网络设备,其特征在于,所述网络设备包括:
    接收单元,用于在链路层接收对端网络设备发送的参考数据包;
    提取单元,用于根据所述接收单元接收的所述参考数据包,提取所述网络设备与所述对端网络设备间的信道特征。
  14. 根据权利要求13所述的网络设备,其特征在于,所述网络设备还包括:
    发送单元,用于通过链路层向所述对端网络设备发送所述信标数据包;所述参考数据包为所述信标数据包的响应数据包。
  15. 根据权利要求14所述的网络设备,其特征在于,所述发送单元还用于:
    从通过链路层向所述对端网络设备发送所述信标数据包的时刻开始的预设时间段内,若所述接收单元未接收到所述信标数据包的响应数据包,通过链路层重新向所述对端网络设备发送所述信标数据包。
  16. 根据权利要求13-15任一项所述的网络设备,其特征在于,所述信道特征包括信道状态信息CSI;所述提取单元具体用于:
    对所述参考数据包进行多信道样本侦听,得到所述网络设备与所述对端网络设备间每个子信道的特征。
  17. 根据权利要求13-16任一项所述的网络设备,其特征在于,所述网络设备还 包括:
    配对单元,用于在所述提取单元根据所述参考数据包,提取所述网络设备与所述对端网络设备间的信道特征之后,根据配对参考信息,与所述对端网络设备进行所述网络设备与所述对端网络设备间的信道特征配对;
    所述配对参考信息包括提取信道特征的时间戳,时间间隔最小的时间戳对应的信道特征为一对信道特征;或者,所述配对参考信息包括提取信道特征的所述参考数据包中的配对序列号,配对序列号相同的数据包提取的信道特征为一对信道特征。
  18. 根据权利要求17所述的网络设备,其特征在于,所述配对参考信息包括提取信道特征的时间戳,所述配对单元具体用于:
    记录第一时间戳,所述第一时间戳为所述网络设备提取所述网络设备与所述对端网络设备间的信道特征的系统时间;
    通过所述发送单元向所述对端网络设备发送所述第一时间戳,所述第一时间戳用于所述对端网络设备将所述对端网络设备提取的所述网络设备与所述对端网络设备间的信道特征,与所述网络设备提取的所述网络设备与所述对端网络设备间的信道特征配对;或者,通过所述接收单元接收所述对端网络设备发送的第二时间戳,所述第二时间戳为所述对端网络设备提取的所述网络设备与所述对端网络设备间的信道特征的系统时间,所述网络设备选取提取时间戳与所述第二时间戳间隔最小的所述网络设备与所述对端网络设备间的信道特征,与所述对端网络设备提取的所述网络设备与所述对端网络设备间的信道特征配对。
  19. 根据权利要求17所述的网络设备,其特征在于,所述参考数据包包括配对序列号;所述配对参考信息包括提取信道特征的所述参考数据包中的配对序列号;所述配对单元具体用于:
    通过所述接收单元接收所述对端网络设备发送的、所述对端网络设备提取所述网络设备与所述对端网络设备间的信道特征的至少一个数据包的配对序列号,所述网络设备根据配对序列号,将所述网络设备提取的所述网络设备与所述对端网络设备间的信道特征,与所述网络设备提取的所述网络设备与所述对端网络设备间的信道特征配对;
    或者,
    通过所述发送单元向所述对端网络设备发送、所述网络设备提取的所述网络设备与所述对端网络设备间的信道特征的至少一个数据包的配对序列号,用于所述对端网络设备根据配对序列号,将所述对端网络设备提取的所述网络设备与所述对端网络设备间的信道特征,与所述网络设备提取的所述网络设备与所述对端网络设备间的信道特征配对。
  20. 一种网络设备,其特征在于,所述网络设备包括:
    接收单元,用于接收对端网络设备发送的参考数据包;
    提取单元,用于根据所述接收单元接收的所述参考数据包,提取所述网络设备与所述对端网络设备间的信道特征;
    配对单元,用于根据配对参考信息,与所述对端网络设备进行所述网络设备与所述对端网络设备间的信道特征配对;
    所述配对参考信息包括提取信道特征的时间戳,时间间隔最小的时间戳对应的信道特征为一对信道特征;或者,所述配对参考信息包括提取信道特征的所述参考数据包中的配对序列号,配对序列号相同的数据包提取的信道特征为一对信道特征。
  21. 根据权利要求20所述的网络设备,其特征在于,所述配对参考信息包括提取信道特征的时间戳,所述配对单元具体用于:
    记录第一时间戳,所述第一时间戳为所述网络设备提取所述网络设备与所述对端网络设备间的信道特征的系统时间;
    通过所述发送单元向所述对端网络设备发送所述第一时间戳,所述第一时间戳用于所述对端网络设备将所述对端网络设备提取的所述网络设备与所述对端网络设备间的信道特征,与所述网络设备提取的所述网络设备与所述对端网络设备间的信道特征配对;或者,通过所述接收单元接收所述对端网络设备发送的第二时间戳,所述第二时间戳为所述对端网络设备提取的所述网络设备与所述对端网络设备间的信道特征的系统时间,所述网络设备选取提取时间戳与所述第二时间戳间隔最小的所述网络设备与所述对端网络设备间的信道特征,与所述对端网络设备提取的所述网络设备与所述对端网络设备间的信道特征配对。
  22. 根据权利要求20所述的网络设备,其特征在于,所述参考数据包包括配对序列号;所述配对参考信息包括提取信道特征的所述参考数据包中的配对序列号;所述配对单元具体用于:
    通过所述接收单元接收所述对端网络设备发送的、所述对端网络设备提取所述网络设备与所述对端网络设备间的信道特征的至少一个数据包的配对序列号,所述网络设备根据配对序列号,将所述网络设备提取的所述网络设备与所述对端网络设备间的信道特征,与所述网络设备提取的所述网络设备与所述对端网络设备间的信道特征配对;
    或者,
    通过所述发送单元向所述对端网络设备发送、所述网络设备提取的所述网络设备与所述对端网络设备间的信道特征的至少一个数据包的配对序列号,用于所述对端网络设备根据配对序列号,将所述对端网络设备提取的所述网络设备与所述对端网络设备间的信道特征,与所述网络设备提取的所述网络设备与所述对端网络设备间的信道特征配对。
  23. 根据权利要求20-22任一项所述的网络设备,其特征在于,所述接收单元具体用于:
    在链路层接收所述对端网络设备发送的参考数据包。
  24. 根据权利要求23所述的网络设备,其特征在于,所述信道特征包括信道状态信息CSI;所述提取单元具体用于:
    对所述参考数据包进行多信道样本侦听,得到所述网络设备与所述对端网络设备间每个子信道的特征。
  25. 一种网络设备,其特征在于,包括:处理器和存储器;
    所述存储器用于存储计算机执行指令,当所述网络设备运行时,所述处理器执行所述存储器存储的所述计算机执行指令,以使所述网络设备执行如权利要求1-7任意 一项所述的提取信道特征的方法。
  26. 一种网络设备,其特征在于,包括:处理器和存储器;
    所述存储器用于存储计算机执行指令,当所述网络设备运行时,所述处理器执行所述存储器存储的所述计算机执行指令,以使所述网络设备执行如权利要求8-12任意一项所述的提取信道特征的方法。
PCT/CN2017/119956 2016-12-30 2017-12-29 一种提取信道特征的方法及网络设备 WO2018121756A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201611270754.4A CN108270559A (zh) 2016-12-30 2016-12-30 一种提取信道特征的方法及网络设备
CN201611270754.4 2016-12-30

Publications (1)

Publication Number Publication Date
WO2018121756A1 true WO2018121756A1 (zh) 2018-07-05

Family

ID=62706918

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2017/119956 WO2018121756A1 (zh) 2016-12-30 2017-12-29 一种提取信道特征的方法及网络设备

Country Status (2)

Country Link
CN (1) CN108270559A (zh)
WO (1) WO2018121756A1 (zh)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109286609A (zh) * 2018-08-22 2019-01-29 平安科技(深圳)有限公司 信息采集方法、装置、计算机设备及存储介质

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP1775875A1 (en) * 2004-08-04 2007-04-18 Matsushita Electric Industrial Co., Ltd. Radio communication device, radio communication system, and radio communication method
CN104283677A (zh) * 2014-10-20 2015-01-14 中国运载火箭技术研究院 基于无线信道特征的对称密钥生成与分发的时序瞄齐方法
CN104640110A (zh) * 2015-01-15 2015-05-20 南京邮电大学 一种终端直通通信中基于信道特性的对称密钥生成方法
CN106209355A (zh) * 2016-06-29 2016-12-07 北京理工大学 一种基于信道特征参数的无线通信密钥生成方法

Family Cites Families (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8897157B2 (en) * 2011-12-16 2014-11-25 Maxlinear, Inc. Method and apparatus for providing conditional access based on channel characteristics
EP3425839B1 (en) * 2012-04-30 2024-05-01 InterDigital Patent Holdings, Inc. Method and apparatus for supporting coordinated orthogonal block-based resource allocation (cobra) operations
US9369279B2 (en) * 2013-09-23 2016-06-14 Venafi, Inc. Handling key rotation problems
US9872233B2 (en) * 2014-06-02 2018-01-16 Intel IP Corporation Devices and method for retrieving and utilizing neighboring WLAN information for LTE LAA operation
CN104243147B (zh) * 2014-09-05 2018-02-09 中国运载火箭技术研究院 基于无线信道特征的对称密钥生成与分发的保密增强方法
CN106102055B (zh) * 2016-07-11 2019-03-08 西安电子科技大学 基于特征分布变换的无线信道密钥生成方法

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP1775875A1 (en) * 2004-08-04 2007-04-18 Matsushita Electric Industrial Co., Ltd. Radio communication device, radio communication system, and radio communication method
CN104283677A (zh) * 2014-10-20 2015-01-14 中国运载火箭技术研究院 基于无线信道特征的对称密钥生成与分发的时序瞄齐方法
CN104640110A (zh) * 2015-01-15 2015-05-20 南京邮电大学 一种终端直通通信中基于信道特性的对称密钥生成方法
CN106209355A (zh) * 2016-06-29 2016-12-07 北京理工大学 一种基于信道特征参数的无线通信密钥生成方法

Also Published As

Publication number Publication date
CN108270559A (zh) 2018-07-10

Similar Documents

Publication Publication Date Title
CA2454987C (en) Efficient polled frame exchange on a shared-communications channel
US11637771B2 (en) Technologies for managing network traffic through heterogeneous networks
CN113162727B (zh) 用于多链路通信的链路特定的块确认
CN107104902B (zh) 一种rdma数据传输的方法、相关装置与系统
US11777915B2 (en) Adaptive control of secure sockets layer proxy
CN104184646A (zh) Vpn网络数据交互方法和系统及其网络数据交互设备
CN109905310B (zh) 数据传输方法、装置、电子设备
CN111385068B (zh) 数据传输方法、装置、电子设备及通信系统
WO2018121756A1 (zh) 一种提取信道特征的方法及网络设备
US11984984B2 (en) Link-specific block acknowledgment for multi-link communication
US10476919B2 (en) System and method for reliable messaging between application sessions across volatile networking conditions
EP3989523A1 (en) Protected high-throughput control subfield
CN112929417B (zh) 报文处理方法及装置
US8676993B1 (en) Bundled transmission control protocol connections
WO2024103891A1 (zh) 一种数据处理方法及装置
US20180367446A1 (en) Dual network interface implementation in multipath networking
TW201815193A (zh) 傳輸資訊的方法、網路裝置和終端裝置
KR102347568B1 (ko) 블록체인 시스템에서 블록 전송 방법
WO2023061158A1 (zh) 加解密方法、装置及计算机可读存储介质
WO2022228293A1 (zh) 一种发送报文的方法、处理报文的方法及设备
CN109792408B (zh) 用于数据网络中的传输连接的高效管理的网关
JP6228370B2 (ja) 通信装置、通信方法、及びプログラム

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 17887492

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 17887492

Country of ref document: EP

Kind code of ref document: A1