WO2024243748A1 - 密钥生成方法和设备 - Google Patents
密钥生成方法和设备 Download PDFInfo
- Publication number
- WO2024243748A1 WO2024243748A1 PCT/CN2023/096686 CN2023096686W WO2024243748A1 WO 2024243748 A1 WO2024243748 A1 WO 2024243748A1 CN 2023096686 W CN2023096686 W CN 2023096686W WO 2024243748 A1 WO2024243748 A1 WO 2024243748A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- group
- target
- keys
- devices
- signal
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L5/00—Arrangements affording multiple use of the transmission path
- H04L5/003—Arrangements for allocating sub-channels of the transmission path
- H04L5/0048—Allocation of pilot signals, i.e. of signals known to the receiver
- H04L5/0051—Allocation of pilot signals, i.e. of signals known to the receiver of dedicated pilots, i.e. pilots destined for a single user or terminal
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04B—TRANSMISSION
- H04B7/00—Radio transmission systems, i.e. using radiation field
- H04B7/02—Diversity systems; Multi-antenna system, i.e. transmission or reception using multiple antennas
- H04B7/04—Diversity systems; Multi-antenna system, i.e. transmission or reception using multiple antennas using two or more spaced independent antennas
- H04B7/06—Diversity systems; Multi-antenna system, i.e. transmission or reception using multiple antennas using two or more spaced independent antennas at the transmitting station
- H04B7/0613—Diversity systems; Multi-antenna system, i.e. transmission or reception using multiple antennas using two or more spaced independent antennas at the transmitting station using simultaneous transmission
- H04B7/0615—Diversity systems; Multi-antenna system, i.e. transmission or reception using multiple antennas using two or more spaced independent antennas at the transmitting station using simultaneous transmission of weighted versions of same signal
- H04B7/0619—Diversity systems; Multi-antenna system, i.e. transmission or reception using multiple antennas using two or more spaced independent antennas at the transmitting station using simultaneous transmission of weighted versions of same signal using feedback from receiving side
- H04B7/0621—Feedback content
- H04B7/0626—Channel coefficients, e.g. channel state information [CSI]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/04—Key management, e.g. using generic bootstrapping architecture [GBA]
- H04W12/041—Key generation or derivation
Definitions
- the present application relates to the field of communications, and more specifically, to a key generation method, device, computer-readable storage medium, computer program product, and computer program.
- contactless automatic identification technology With the development of communication technology, contactless automatic identification technology has emerged. This technology usually uses wireless radio frequency to perform contactless data transmission between zero-power devices and other devices (such as readers). Since the communication channel between zero-power devices and readers is an unsecured channel, in order to ensure the data transmission security of zero-power devices, it is further proposed that a key can be used between zero-power devices and readers to encrypt the data or information transmitted between the two.
- the above scheme can only enable a single zero-power device and a reader to use the same key (or unicast key or shared key) to ensure the security of data transmission by a single zero-power device. In the scenario where there are multiple zero-power devices, how to enable the zero-power device to generate a group key in a less complex manner and ensure the security of the group key becomes a problem that needs to be solved.
- Embodiments of the present application provide a key generation method, device, computer-readable storage medium, computer program product, and computer program.
- the present invention provides a method for generating a key, including:
- the first device sends a plurality of signals to each second device among a plurality of second devices, wherein radio frequency coefficients of the plurality of signals are calculated based on channel characteristics between each second device and the first device;
- the first device generates a first set of keys based on relevant information of the multiple signals, where the first set of keys is used for communication between the first device and the multiple second devices.
- the present invention provides a method for generating a key, including:
- the target second device receives a plurality of signals from the first device, wherein radio frequency coefficients of the plurality of signals are calculated based on channel characteristics between the target second device and the first device;
- the target second device generates a second set of keys based on relevant information of the multiple signals, wherein the second set of keys is used for communication between the target second device and the first device, the second set of keys are the same keys for multiple second devices, and the target second device is one of the multiple second devices.
- the embodiment of the present application provides a first device, including:
- a first communication unit configured to send a plurality of signals to each second device among a plurality of second devices, wherein radio frequency coefficients of the plurality of signals are calculated based on channel characteristics between each second device and the first device;
- the first processing unit is configured to generate a first group of keys based on relevant information of the multiple signals, where the first group of keys is used for communication between the first device and the multiple second devices.
- the embodiment of the present application provides a target second device, including:
- a second communication unit configured to receive a plurality of signals from a first device, wherein radio frequency coefficients of the plurality of signals are calculated based on channel characteristics between the target second device and the first device;
- a second processing unit is used to generate a second group of keys based on the relevant information of the multiple signals, wherein the second group of keys is used for communication between the target second device and the first device, the second group of keys are the same keys for multiple second devices, and the target second device is one of the multiple second devices.
- An embodiment of the present application provides a first device, comprising: a processor, and a memory communicating with the processor, the memory being used to store instructions, and when the instructions are executed by the processor, the instructions cause the first device to execute: sending multiple signals to each second device among multiple second devices, wherein the radio frequency coefficients of the multiple signals are calculated based on channel characteristics between each second device and the first device; generating a first group of keys based on relevant information of the multiple signals, and the first group of keys is used for communication between the first device and the multiple second devices.
- An embodiment of the present application provides a target second device, including: a processor, and a memory communicating with the processor, the memory being used to store instructions, and when the instructions are executed by the processor, the instructions cause the target second device to execute: receiving multiple signals from a first device, wherein radio frequency coefficients of the multiple signals are calculated based on channel characteristics between the target second device and the first device; generating a second group of keys based on relevant information of the multiple signals, wherein the second group of keys is used for communication between the target second device and the first device, the second group of keys are the same keys for multiple second devices, and the target second device is one of the multiple second devices.
- the embodiment of the present application provides a chip for implementing the above method.
- the chip includes: a processor, which is used to call and run a computer program from a memory, so that a device equipped with the chip executes the above method.
- An embodiment of the present application provides a computer-readable storage medium for storing a computer program, which enables a device to perform the above method when the computer program is executed by the device.
- An embodiment of the present application provides a computer program product, including computer program instructions, which enable a computer to execute the above method.
- An embodiment of the present application provides a computer program, which, when executed on a computer, enables the computer to execute the above method.
- the first device sends multiple signals to each second device, and the radio frequency coefficients of the multiple signals are calculated based on the channel characteristics between the second device and the first device, and then the first device itself will also generate a group key for communicating with each second device based on the relevant information of each signal.
- the radio frequency coefficients corresponding to different second devices for the signals sent to different second devices, the channel characteristics between the second device and the first device can be accurately offset, that is, the loss or interference of the channel between the second device and the first device can be offset, and the group key can be generated based on only the relevant information of the signal, thereby ensuring that the complexity of generating the group key is reduced while also ensuring the security of the group key.
- FIG. 1 is a schematic diagram of an application scenario according to an embodiment of the present application.
- FIG2 is a schematic flowchart of a key generation method according to an embodiment of the present application.
- FIG3 is a schematic flowchart of a key generation method according to another embodiment of the present application.
- FIG4 is a schematic diagram of a scenario of a key generation method according to an embodiment of the present application.
- FIG5 is a schematic flowchart of a key generation method according to an embodiment of the present application.
- FIG6 is a schematic diagram of simulation results of a key generation method provided according to an embodiment of the present application.
- FIG. 7 and 8 are two other schematic flow charts of a key generation method according to an embodiment of the present application.
- FIG. 9 is a schematic block diagram of a first device according to an embodiment of the present application.
- FIG. 10 is a schematic block diagram of a target second device according to an embodiment of the present application.
- FIG11 is a schematic block diagram of a communication device according to an embodiment of the present application.
- FIG. 12 is a schematic block diagram of a chip according to an embodiment of the present application.
- FIG. 13 is a schematic block diagram of a communication system according to an embodiment of the present application.
- the technical solutions of the embodiments of the present application can be applied to various communication systems, such as LTE, LTE-A, NR, NR evolution, WLAN, WiFi, or other communication systems.
- the embodiments of the present application describe various embodiments in combination with network devices and terminals.
- the terminal may be mobile or fixed, and the terminal may also be referred to as a mobile station, a user unit, etc.
- the terminal may be a site in a WLAN, and may be a smart terminal, a wireless modem, a laptop computer, a tablet computer, or other terminals.
- the terminal may be a VR terminal/AR terminal, an industrial control terminal, an unmanned driving terminal, a telemedicine terminal, a smart grid terminal, a transportation safety terminal, a smart city terminal, or a wireless terminal for a smart home, etc.
- the terminal may also be a wearable device.
- the network device may be a device for communicating with a terminal, the network device may be an access point in a WLAN, or an evolved base station in an LTE, or a relay station, or a vehicle-mounted device, a wearable device, and a network device (gNB) in an NR network, or a network device in a future evolved PLMN network, or a network device in a non-terrestrial network, etc.
- the network device may have a mobile feature, for example, the network device may be a mobile device.
- A indicates B, which can mean that A directly indicates B, for example, B can be obtained through A; it can also mean that A indirectly indicates B, for example, A indicates C, and B can be obtained through C; it can also mean that there is an association relationship between A and B.
- the term "correspondence" can mean that there is a direct or indirect correspondence relationship between the two, or it can mean that there is an association relationship between the two, or it can mean that there is an indication and being indicated, configuration and being configured, etc.
- FIG1 exemplarily shows a communication system 100.
- the communication system includes a network device 110 and two terminals 120.
- the communication system 100 may include multiple network devices 110, and each network device 110 may include other number of terminals 120 within its coverage area, which is not limited in the embodiment of the present application.
- the communication system 100 may also include a mobility management entity, an access and mobility management function, and other network entities, which is not limited in the embodiment of the present application.
- the network device may include an access network device and a core network device. That is, the communication system may also include multiple core networks for communicating with the access network device.
- the access network device may be a base station of an LTE, LTE-A, or NR system.
- the communication device may include a network device and a terminal with a communication function, and the communication device may also include other devices in the communication system, such as a network controller, a mobile management entity, and other network entities, which are not limited in the embodiment of the present application.
- Fig. 2 is a schematic flow chart of a key generation method according to an embodiment of the present application. The method includes at least part of the following contents.
- the first device sends a plurality of signals to each second device among a plurality of second devices, wherein radio frequency coefficients of the plurality of signals are calculated based on channel characteristics between each second device and the first device;
- Fig. 3 is a schematic flow chart of a key generation method according to another embodiment of the present application. The method includes at least part of the following contents.
- the target second device receives multiple signals from the first device, wherein the radio frequency coefficients of the multiple signals are calculated based on the channel characteristics between the target second device and the first device;
- the target second device generates a second group of keys based on the relevant information of the multiple signals, wherein the second group of keys is used for communication between the target second device and the first device, the second group of keys is the same key for multiple second devices, and the target second device is one of the multiple second devices.
- the first device is one of the following: a terminal device, a network device.
- the first device may have one or more antennas.
- the first device may have multiple antennas. It should be understood that the solution provided in this embodiment may also be applied to a first device having only one antenna, which is not limited here.
- the first device is a terminal device.
- the first device and the second device (any second device) can communicate with each other through side link messages.
- the first device may be a network device.
- the network device may be an access network device (such as a base station, gNB, eNB, etc.).
- the first device and the second device may communicate via AS (Access Stratum) messages.
- AS Access Stratum
- the first device may be a network device, for example, the network device may be a core network device.
- the first device and the second device may communicate via NAS (Non-Access Stratum) messages; or, in this embodiment, the first device and the second device may forward messages via an access network device.
- NAS Non-Access Stratum
- the core network side device includes at least one of the following: an authentication server function (AUSF), a unified data management function (UDM), and an ambient power-enabled IoT (AIoT) network element.
- AUSF authentication server function
- UDM unified data management function
- AIoT ambient power-enabled IoT
- the one or more core network devices may also include at least one of the following: ARPF (Authentication credential Repository and Processing Function), AMF (Access and Mobility Management Function), UPF (User Plane Function), SEAF (Security Anchor Function), etc. It should be understood that this is only an exemplary description. In actual processing, the core network side device may also include other core network devices, but they are not exhaustive here.
- ARPF Authentication credential Repository and Processing Function
- AMF Access and Mobility Management Function
- UPF User Plane Function
- SEAF Security Anchor Function
- the above-mentioned AIOT network element may refer to a network element with AIOT function, or a network element with zero power consumption related functions;
- the network element with AIoT function (or network element with zero power consumption related functions) may be a core network element with AIOT function (or with zero power consumption device related service energy supply), or a core network element serving AIOT function (or serving zero power consumption device), or a core network element with at least AIoT function (such as at least AIOT (or zero power consumption device) group key generation energy supply), etc.
- AIOT network element may be a separately set network element specifically used to serve AIOT (or a network element specifically serving zero power consumption devices), or it may be an existing core network element to which AIOT related functions (or related functions serving zero power consumption devices) are added. This embodiment does not enumerate all possible situations.
- the first device may be called a reader, or a reader, or a tag reader, or a tag reader/writer, etc. All possible names or possible devices of the first device are not exhaustively listed here.
- the second device is a zero-power device.
- the zero-power device may be an Ambient Power-enabled IoT (AIoT) device.
- AIoT Ambient Power-enabled IoT
- the zero-power device may be an active zero-power device, or a passive zero-power device, or a semi-passive zero-power device, etc.
- the second device may also be a terminal with lower computing power.
- the second device may be called a tag, and all possible names or possible devices of the second device are not exhaustively listed here.
- the aforementioned multiple second devices may form a device group.
- the target second device is also a zero-power device, and the target second device may be any one of the multiple second devices, that is, the target second device may be any second device in the device group formed by the multiple second devices.
- the channel characteristics between each second device and the first device may be The second device is calculated before sending multiple signals.
- the channel characteristics between each second device and the first device are first calculated.
- the method also includes: the first device sends a group key generation signaling to each second device; the first device receives a pilot signal from each second device, wherein the pilot signal is a reflected signal corresponding to the group key generation signaling; the first device calculates the channel characteristics between each second device and the first device based on the pilot signal of each second device.
- the channel characteristics between each second device and the first device can form a channel characteristic matrix.
- the method further includes: the target second device receives the group key generation signaling from the first device; the target second device sends a pilot signal to the first device, wherein the pilot signal is a reflection signal corresponding to the group key generation signaling, and the pilot signal is used by the first device to calculate the channel characteristics between the target second device and the first device.
- the target second device receives the group key generation signaling from the first device; the target second device sends a pilot signal to the first device, wherein the pilot signal is a reflection signal corresponding to the group key generation signaling, and the pilot signal is used by the first device to calculate the channel characteristics between the target second device and the first device.
- the target second device is used for illustration here.
- each of the plurality of second devices performs the same processing as the target second device. For the sake of brevity, this embodiment does not repeat the processing of each second device one by one.
- the above channel characteristics can be used to indicate the transmission loss of the signal in the channel, and/or to indicate the transmission attenuation of the signal in the channel, etc.
- the channel characteristics can include relevant parameters such as the noise of the channel, and all possible parameters that the channel characteristics may include are not exhaustively listed here.
- the channel characteristics can refer to the channel and can also be alternatively called the channel estimation value, or alternatively called the channel estimation, etc., and all possible names thereof are not exhaustively listed here.
- the function of the group key generation signaling may be used to trigger the second device to send a pilot signal. It should be understood that the group key generation signaling may also have other functions, but in this embodiment, the other functions of the group key generation signaling are not exhaustively listed and limited. In addition, the information content that may be carried by the group key generation signaling is not limited in this embodiment.
- the aforementioned first device may have only one antenna.
- the group of key generation signals is directly transmitted by the antenna.
- the aforementioned first device may have multiple antennas, and the group key generation signaling may be sent through a designated antenna of the first device.
- the designated antenna may be pre-configured or pre-set according to actual conditions.
- the multiple antennas of the first device are arranged as the first antenna to the Mth antenna (M is an integer greater than or equal to 2) according to position or processing order or logical order or other order.
- the designated antenna can be designated as the first antenna according to actual conditions, that is, the group key generation signaling can be transmitted by the first antenna of the first device; this is only an exemplary explanation. In actual processing, as long as any one of the designated M antennas sends the group key generation signaling, it is within the protection scope of this embodiment, and all possible situations are not enumerated here.
- the group key generation signaling may be broadcast or multicast, that is, the first device broadcasts or multicasts the group key generation signaling to multiple second devices, so that each second device can receive the group key generation signaling.
- the group key generation signaling may be unicast, that is, the first device sends the group key generation signaling to each second device respectively.
- the target second device sending the pilot signal to the first device may be: the target second device modulates the pilot signal to the continuous carrier corresponding to the group key generation signaling and reflects it to the first device.
- the continuous carrier corresponding to the group key generation signaling may refer to: the group key generation signaling is a continuous carrier, or the group key generation signaling is sent in the form of a continuous carrier, or the group key generation signaling is carried by a continuous carrier.
- each of the aforementioned multiple second devices may send a pilot signal to the first device according to an anti-collision mechanism.
- the anti-collision mechanism may be pre-configured in each second device.
- the anti-collision mechanism may be a time slot anti-collision mechanism, a time unit anti-collision mechanism, a frequency domain anti-collision mechanism, and the like.
- the anti-collision mechanism may enable each second device to determine a delay time unit after receiving a group key generation signaling, and the delay time unit is used for each second device to determine a sending time unit for sending a pilot signal, and the delay time units corresponding to different second devices may be the same or different.
- the time unit may be any time unit such as a time slot, a symbol, a millisecond, a microsecond, and the like, which are not exhaustive here. It should also be pointed out that the above is only an exemplary description.
- the anti-collision mechanism can also enable each second device to determine the sending frequency range of the pilot signal, and the sending frequency ranges corresponding to different second devices may be the same or different; in addition, the anti-collision mechanism can also enable each second device to determine the corresponding delay time unit and/or the sending frequency range of the pilot signal. As long as the pilot signals sent by different second devices can avoid mutual interference in the time domain and/or frequency domain, it is within the protection scope of this embodiment, and all possible contents of the anti-collision mechanism are not enumerated here.
- the first device has multiple antennas.
- the first device receiving the pilot signal from each second device may refer to the first device receiving the pilot signal from each second device through each antenna of the multiple antennas.
- the first device calculating the channel characteristics between each second device and the first device based on the pilot signal of each second device refers to the first device calculating the channel characteristics between each second device and each antenna of the first device based on the pilot signal of each second device.
- the first device receives the data from each of the plurality of antennas.
- the pilot signal of the second device refers to that the first device receives the pilot signal from the target second device through each antenna of the multiple antennas.
- the first device calculates the channel characteristics between each second device and each antenna of the first device based on the pilot signal of each second device, which means that the first device calculates the channel characteristics between the target second device and each antenna of the first device based on the pilot signal from the target second device received by each antenna of the multiple antennas.
- the multiple second devices are multiple tags
- the target second device is tag1 among the multiple tags
- the first device is a reader
- the reader has M antennas.
- Each of the M antennas of the reader receives a pilot signal reflected by tag1, which can be expressed as: Wherein, ref is the tag reflection coefficient, and the specific value of ref is known at the reader end; s represents the pilot signal sent by the tag (for example, it can be a pilot signal whose content and/or format is known to both the reader and the tag).
- n is equal to 1, that is, s represents the pilot signal sent by tag1
- the reader can first send the aforementioned group key generation signaling through the first antenna (that is, the first antenna is the aforementioned designated antenna), and the pilot signal is modulated and reflected on the continuous carrier corresponding to the group key generation signaling. Therefore, the channel characteristics between the first antenna and the first tag will affect the pilot signal reflected by the first tag received by each antenna of the reader. Based on this, in the above formula, (i.e. the channel characteristics between the first antenna of the reader and the first tag) need to be consistent with each Multiply.
- s can be a pilot signal with known content and/or format by both the reader and the tag, so the reader can calculate the channel characteristics between tag 1 and each antenna of the reader through the above formula, for example, it can be expressed as
- the reader can perform the above processing on each tag. Finally, the reader can obtain the channel features between each tag and the reader. Then, the reader can form a channel feature matrix with the channel features between each tag and the reader. For example, it can be expressed in the following matrix form: Among them, H represents the channel characteristic matrix between each tag in all tags obtained by the reader and multiple antennas of the reader. The description is the same as that of the above-mentioned embodiment and will not be repeated.
- the first device has multiple antennas.
- the aforementioned first device has only one antenna.
- the first device receiving the pilot signal from each of the second devices may refer to the first device receiving the pilot signal from each of the second devices through the antenna.
- the second device taking the second device as a tag, the target second device as tag1 among multiple tags, the first device as a reader, and the first device having one antenna as an example, the one antenna of the reader receives the pilot signal reflected by tag1, which can be expressed as:
- the descriptions of ref and s are the same as those in the above embodiment and will not be repeated here.
- the first device calculates the channel characteristics between each second device and the first device based on the pilot signal of each second device, which may mean: the first device calculates the channel characteristics between each second device and an antenna of the first device based on the pilot signal of each second device; and then the first device can form a channel characteristic matrix with the channel characteristics between each second device and an antenna of the first device, for example, the channel characteristic matrix can be expressed as: Among them, H represents the channel feature matrix between each tag and the reader among all tags obtained by the reader. The description is the same as that of the above-mentioned embodiment and will not be repeated.
- the first device can calculate the radio frequency coefficient.
- the method also includes: the first device calculates one or more radio frequency coefficients based on the channel characteristics between each second device and the first device, wherein different radio frequency coefficients in the one or more radio frequency coefficients correspond to different second devices.
- any RF coefficient may be to offset the corresponding channel characteristics (such as to offset the transmission attenuation or transmission loss of the signal in the channel, etc.), so that the signal transmitted to the corresponding second device on the channel is the same or substantially the same as the signal sent by the first device. All possible roles or functions of the RF coefficient are not exhaustively listed here.
- the RF coefficient can also be called the antenna weight coefficient, or antenna coefficient, or antenna RF transmission coefficient, or RF transmission coefficient, or gain coefficient, or transmission weight coefficient, etc., and all possible names are not exhaustively listed here.
- the plurality of second devices in the device group may be divided into one or more groups. Different radio frequency coefficients in the one or more radio frequency coefficients correspond to different groups of the plurality of second devices, and different groups of the plurality of second devices include different second devices.
- the first device calculates the RF coefficient corresponding to each group (i.e., each group of second devices).
- This embodiment does not limit whether the RF coefficients corresponding to different groups are the same.
- any group, any group of second devices, any group of second devices, and any second device in a group all have the same meaning and will not be repeated. It should be noted that any group of second devices has a different meaning from a device group.
- a device group (or multiple second devices in a device group) means all second devices in the device group, while any group of second devices is any group in the device group, or each second device in any group in the device group. That is, when the concept of group is involved in the following text, as long as it is not emphasized as a device group, it means a group (i.e., a group of second devices in a device group), and no repeated explanation will be given below.
- the first device calculates one or more RF coefficients based on the channel characteristics between each second device and the first device. It can be: the first device forms a kth channel matrix based on the channel characteristics between each second device in the kth group of second devices and the first device, calculates the right inverse matrix of the kth channel matrix, and calculates the kth RF coefficient among the one or more RF coefficients based on the right inverse matrix of the kth channel matrix, and the kth RF coefficient corresponds to the kth group of second devices.
- N and M in the formula are the same as those in the above embodiment and are not repeated here.
- K represents the number of groups, and K is an integer greater than or equal to 1.
- the number of the above one or more RF coefficients can be K, which is the same as the number of the above groups. That is, the kth RF coefficient can have a corresponding relationship with the kth group of second devices, and k is greater than or equal to 1 and less than or equal to K.
- the first device forms the kth group of channel matrices based on the channel characteristics between each second device in the kth group of second devices and the first device. This can be achieved by extracting the channel characteristics corresponding to each second device in the kth group of second devices in the channel characteristic matrix between each second device and the first device to form the kth group of channel matrices.
- the kth group of channel matrices may include: channel characteristics of the (k-1)M+1th second device to the (k-1)M+Mth second device.
- the k-th group of channel matrices can be expressed as (1 ⁇ k ⁇ K):
- H(x) represents the x-th row in H (channel feature matrix).
- x is equal to (k-1)M+1, it is the (k-1)M+1-th row in H, that is, the channel feature corresponding to the (k-1)M+1-th second device.
- x is equal to (k-1)M+M, it is the (k-1)M+M-th row in H, that is, the channel feature corresponding to the (k-1)M+M-th second device.
- the right inverse matrix of the k-th group of channel matrix can be calculated using the following formula: in, represents the right inverse matrix of the k-th group channel matrix, H k represents the k-th group channel matrix, and H k H represents the transposed matrix of the k-th group channel matrix.
- the calculating of the kth RF coefficient among the one or more RF coefficients based on the right inverse matrix of the kth group of channel matrix may refer to: adding all columns of the right inverse matrix of the kth group of channel matrix to obtain the kth RF coefficient among the one or more RF coefficients.
- obtaining the kth RF coefficient may be expressed by the following formula: Among them, w k represents the kth RF coefficient, sum_column() represents the matrix Add all the columns of .
- the first device sends multiple signals to each second device in a plurality of second devices, which may refer to: the first device sends the multiple signals to each second device in the kth group of second devices based on the kth RF coefficient in the one or more RF coefficients, wherein different RF coefficients in the one or more RF coefficients correspond to different groups of the multiple second devices, and different groups of the multiple second devices include different second devices, and the kth group of second devices is one of the one or more groups of the multiple second devices, and k is a positive integer.
- the first device sequentially uses the RF coefficients corresponding to each second device group in the K groups of second devices for the i-th signal in the multiple signals, and sends the i-th signal to each group of second devices in turn, and i is a positive integer.
- i is a positive integer.
- the first device When the first device generates the i-th signal among the multiple signals, it sequentially uses the RF coefficients corresponding to each group of second devices in the K groups of second devices to send the i-th signal to each group of second devices.
- the first device when it generates the i+1-th signal among the multiple signals, it also sequentially uses the RF coefficients corresponding to each group of second devices in the K groups of second devices to send the i+1-th signal to each group of second devices. That is, the i-th signal will be sent K times on the first device side, and different times will be sent to each second device in different groups, so that each second device can receive the same i-th signal; accordingly, the i-th signal is received once on any second device side.
- the i-th signal received by tagn can be expressed as riHkwk , where ri is the i-th signal, and the meaning of other contents is the same as the above-mentioned embodiment; since Hk can be offset by the RF coefficient wk , the signal received at tagn should be ri , that is, 6, where Ik_n ⁇ 1 represents a unit vector of k_n rows and 1 columns, and k_n represents the number of rows of Hk , that is, the number of tags in the k-th group of tags, that is, all tags (each tag) in the k-th group of tags will receive ri .
- the first device does not need to repeatedly perform the aforementioned first device sending a group key generation signaling to each second device to calculate the channel characteristics between each second device and the first device, and calculate the RF coefficient corresponding to each group of second devices. That is, after the first device calculates each RF coefficient, it can perform the process of sending multiple signals to the second devices in each group of second devices, and use the same RF coefficient to send different signals among the multiple signals to the second devices in the same group.
- the first device can repeat the above process. For example, if the process of sending the i-th signal is to be executed, the first device needs to execute the process of sending a group key generation signaling to each second device to calculate the channel characteristics between each second device and the first device, and calculate the RF coefficient corresponding to each group of second devices (that is, each RF coefficient), and then send the i-th signal to each group of second devices based on the RF coefficient corresponding to each group of second devices; if the process of sending the i+1-th signal is to be executed, the first device again executes the process of sending a group key generation signaling to each second device to calculate the channel characteristics between each second device and the first device, and calculate the RF coefficient corresponding to each group of second devices, and then send the i+1-th signal to each group of second devices based on the RF coefficient corresponding to each group of second devices.
- the first device can also determine when to repeat the process of sending group key generation signaling to each second device to calculate the channel characteristics between each second device and the first device, and calculate the RF coefficient corresponding to each group of second devices according to the specific coherence time.
- a signals (A can be an integer greater than or equal to 1) can be sent to each group of second devices within the coherence time. After completing the sending of the 1st to Ath signals and before sending the A+1th signal to each group of second devices, the process of sending group key generation signaling to each group of second devices to calculate the channel characteristics between each second device and the first device and calculate the RF coefficient corresponding to each group of second devices is performed again.
- the A+1th signal is sent to each group of second devices.
- the next cycle is repeated by analogy.
- the aforementioned process of calculating each RF coefficient is performed again. And so on and so forth.
- the coherence time is longer or shorter, which can be determined based on a preset duration threshold value. For example, when the coherence time is greater than the duration threshold value, the coherence time is longer, that is, the channel environment is in a static environment. When the coherence time is less than or equal to the duration threshold value, the coherence time is shorter, that is, the channel environment is time-varying.
- the duration threshold value can be configured according to actual conditions, for example, it can be related to the number of second devices actually included in the device group, and/or to the duration required to send a signal, etc. All possible parameters for determining the duration threshold value and the determination method thereof are not limited here.
- coherence time may also be referred to as coherence duration, and the coherence time may be determined based on actual conditions.
- This embodiment does not limit the method of obtaining or determining the coherence time. As long as the coherence time can be obtained in advance on the first device side before executing all the solutions provided by this embodiment, it is within the protection scope of this embodiment.
- the first device calculates a radio frequency coefficient corresponding to each second device. Whether the radio frequency coefficients corresponding to different second devices are the same is not limited in this embodiment.
- the first device may be to obtain the right inverse matrix of the channel characteristics between the target second device and the first device, and calculate the RF coefficient corresponding to the target second device based on the right inverse matrix.
- Calculating the RF coefficient corresponding to the target second device based on the right inverse matrix may refer to: adding all columns of the right inverse matrix to obtain the RF coefficient corresponding to the target second device.
- the right inverse matrix of the channel characteristics between tagn and the first device can be calculated using the following formula: Where n represents the tag number or sequence number. In this example, n can be equal to 1. represents the right inverse matrix, Hn represents the channel feature matrix between the nth tag and the reader, and HnH represents the transposed matrix of the channel feature matrix between the nth tag and the reader. Taking the above specific value of n as 1 as an example, that is, the channel feature between tag1 and the reader can be expressed as H1 . or, The meanings of the various contents included in the above formula are the same as those in the above embodiment and will not be elaborated on again.
- w n represents the RF coefficient corresponding to tagn
- sum_column() represents the matrix Add all the columns of .
- the first device sends multiple signals to each second device among multiple second devices, which may mean that the first device uses the RF coefficients corresponding to each second device in turn for the i-th signal among the multiple signals, and sends the i-th signal to each second device in turn, where i is a positive integer.
- N is an integer greater than or equal to 2
- the first device uses the RF coefficients corresponding to each second device among the N second devices in turn to send the i-th signal to each second device;
- the first device when the first device generates the i+1-th signal among the multiple signals, it also uses the RF coefficients corresponding to each second device among the N second devices in turn to send the i+1-th signal to each second device. That is, the i-th signal will be sent N times on the first device side, and different times will be sent to different second devices, so that each second device can receive the same i-th signal; accordingly, the i-th signal is received once on any second device side.
- the first device does not need to repeatedly perform the aforementioned first device sending a group key generation signaling to each second device to calculate the channel characteristics between each second device and the first device, and calculate the RF coefficient corresponding to each second device. That is, after the first device calculates the RF coefficient corresponding to each second device, it can perform the process of sending multiple signals to each second device among the multiple second devices, and use the same RF coefficient to send different signals among the multiple signals to the same second device.
- the first device can repeat the above process. For example, if the process of sending the i-th signal is to be executed, the first device needs to execute the process of sending a group key generation signaling to each second device to calculate the channel characteristics between each second device and the first device, and calculate the RF coefficient corresponding to each second device, and then send the i-th signal to each second device based on the RF coefficient corresponding to each second device; if the process of sending the i+1-th signal is to be executed, the first device again executes the process of sending a group key generation signaling to each second device to calculate the channel characteristics between each second device and the first device, and calculate the RF coefficient corresponding to each second device, and then send the i+1-th signal to each second device based on the RF coefficient corresponding to each second device.
- the first device can also determine when to repeat the process of sending group key generation signaling to each second device to calculate the channel characteristics between each second device and the first device, and calculate the corresponding RF coefficient of each second device according to the specific coherence time.
- B signals (B can be an integer greater than or equal to 1) can be sent to each second device within the coherence time.
- the process of sending group key generation signaling to each second device to calculate the channel characteristics between each second device and the first device, and calculate the corresponding RF coefficient of each second device is performed again.
- the A+1th signal is sent to each second device.
- the next cycle is repeated by analogy and will not be repeated.
- the first device generates a first group of keys based on relevant information of the multiple signals, including: the first device obtains multiple first quantization results based on relevant information of the multiple signals; the first device generates the first group of keys based on the multiple first quantization results.
- the first device may send the i-th signal to different second devices based on the radio frequency coefficients of different second devices.
- the i-th signal may be sent to each second device of different groups based on the RF coefficients corresponding to different groups.
- the number of times the i-th signal is sent depends on the number of second devices or the number of groups.
- the first device itself can obtain relevant information of the i-th signal, that is, the first device itself can obtain relevant information of each signal.
- the first device obtains multiple first quantization results based on the relevant information of the multiple signals, including: the first device determines the first quantization range corresponding to the i-th signal based on the relevant information of the i-th signal among the multiple signals, and uses the first quantization value corresponding to the first quantization range as the i-th first quantization result among the multiple first quantization results, wherein the first quantization range is one of multiple first candidate quantization ranges, each of the multiple first candidate quantization ranges has a corresponding first candidate quantization value, and i is a positive integer.
- the first device performs the same processing as the i-th signal on each signal, and finally obtains multiple quantization results.
- This embodiment is described in detail with the i-th signal, and each signal is not described one by one.
- the processing of the first device may also include: the first device may determine the maximum and minimum values of the relevant information value range based on the relevant information of multiple signals; based on the quantization order Q, divide the relevant information value range into Q first candidate quantization ranges, and determine the first candidate quantization value corresponding to each first candidate quantization range in the Q first candidate quantization ranges, where Q is an integer greater than or equal to 2.
- the quantization order Q can be set according to actual conditions, for example, it can be 16, 32, 8, 4, 5, 21 or larger or smaller, and all possible values of Q are not exhaustively listed here.
- the first candidate quantization value corresponding to each of the above-mentioned first candidate quantization ranges can be set according to actual conditions, any first candidate quantization value can be binary, and the length of the first candidate quantization value can be related to the quantization order, for example, the length of the first candidate quantization value can be equal to log 2 Q bits.
- the first candidate quantization value can be a Gray code with a length of log 2 Q.
- the first device determines the first quantization range corresponding to the i-th signal based on the relevant information of the i-th signal among the multiple signals, and uses the first quantization value corresponding to the first quantization range as the i-th first quantization result among the multiple first quantization results, which may mean that the first device determines the relevant information of the i-th signal among the multiple signals, the first quantization range corresponding to the Q first candidate quantization ranges, and uses the first quantization value corresponding to the first quantization range as the i-th first quantization result among the multiple first quantization results.
- the aforementioned determination of the Q first candidate quantization ranges and the first candidate quantization value corresponding to each first candidate quantization range can be performed only once, and then the quantization result corresponding to the relevant information of each signal can be determined respectively based on the aforementioned Q first candidate quantization ranges and the first candidate quantization value corresponding to each first candidate quantization range, which will not be described one by one here.
- the first device in order to reduce the differences in quantization results caused by small errors on the left and right of the quantization boundary, can also round the relevant information of all acquired signals to the nearest integer, and then determine the aforementioned Q first candidate quantization ranges, and the first candidate quantization value corresponding to each first candidate quantization range; and/or, when quantizing each signal, the relevant information of each signal can also be rounded to the nearest integer and then quantized.
- the aforementioned embodiment is only an exemplary description of quantizing the related information of multiple signals.
- the quantization method that can be used in this embodiment may not be limited to the method described herein.
- the singular value decomposition method or other quantization methods may also be used. This embodiment does not limit or exhaustively list them.
- the related information of the multiple signals includes at least one of the following: the strength of each signal in the multiple signals, and the phase of each signal.
- each signal may alternatively be described as the amplitude of each signal.
- the relevant information of the aforementioned multiple signals includes the strength of each signal.
- the processing of the first device may also include: the first device determines the maximum value (P max ) and the minimum value (P min ) of the strength value range of all signals (i.e., the value range of P) based on the strength P of each signal, that is, P min ⁇ P ⁇ P max ; then based on the quantization order Q, the value range of P is divided into Q first candidate quantization ranges, and the Gray code corresponding to each first candidate quantization range in the Q first candidate quantization ranges is determined to have a length of log 2 Q.
- the first device may also round the strength P of all acquired signals to the nearest integer, and then determine the aforementioned Q first candidate quantization ranges and the first candidate quantization value corresponding to each first candidate quantization range; and/or, when quantizing each signal, the strength P of each signal may also be rounded to the nearest integer, and then quantized.
- the Q first candidate quantization ranges may also be referred to as Q first candidate intensity quantization ranges.
- the first device when it sends each signal, it may send a related value of the strength of each signal, such as the square root of the signal's strength, or the original value of the signal's strength, or multiple roots of the signal's strength, etc., and all possible situations are not enumerated here.
- the relevant information of the aforementioned multiple signals includes the phase of each signal.
- the processing of the first device may also include: the first device based on the phase of each signal Determine the phase value range of all signals (i.e. The maximum value of the range of and minimum value That is Then based on the quantization order Q, The value range of is divided into Q first candidate quantization ranges, and the length corresponding to each first candidate quantization range in the Q first candidate quantization ranges is determined to be log 2 Q Gray code.
- the first device can also perform phase Rounding to the nearest integer, and then determining the aforementioned Q first candidate quantization ranges and the first candidate quantization value corresponding to each first candidate quantization range; and/or, when quantizing each signal, the phase of each signal may also be Round to the nearest integer and then perform quantization.
- the Q first candidate quantization ranges may also be referred to as Q first candidate phase quantization ranges.
- the intensity and phase of each signal can be used in combination.
- Q first candidate intensity quantization ranges and Q first candidate phase quantization ranges can be obtained, and then the qth first candidate intensity quantization range and the qth first candidate phase quantization range correspond to the same quantization value, where q is an integer greater than or equal to 1 and less than or equal to Q, or q is an integer greater than or equal to 0 and less than or equal to Q-1.
- the corresponding first quantization range can be determined according to any one of the intensity and phase of the i-th signal, and then the quantization result can be determined.
- the first intensity quantization range and the first phase quantization range corresponding to the intensity and phase of the i-th signal can be used. If the two are consistent, the first quantization value corresponding to any one of the first quantization ranges is determined as the quantization result. If the two are inconsistent, any one of them can be specified as the standard, such as uniformly specifying the intensity of the signal as the standard. All possible examples are not exhaustively listed here.
- the first device generates the first group of keys based on the multiple first quantization results, which may be: the first device merges the multiple first quantization results based on a specified order to obtain the first group of keys.
- the designated order can be set according to actual conditions.
- the designated order can be a positive order, that is, the first group of keys can be "the first first quantization result, the second first quantization result... the last first quantization result” and then merged.
- the designated order can be a reverse order, that is, the first group of keys can be "the last first quantization result, the second to last first quantization result... the first first quantization result” and then merged.
- the designated order can be disordered, for example, there are 4 first quantization results in total, and the designated order can be 2, 4, 3, 1, that is, the first group of keys can be "the second first quantization result, the fourth first quantization result, the third first quantization result, the first first quantization result" and then merged.
- the designated order can be set according to actual conditions, and it is not exhaustive here. It should be understood that the above is only an exemplary description. As long as each second device and the first device adopt the same designated order, it is within the protection scope of this embodiment.
- the first device generates the first group of keys based on the multiple first quantization results, which may be: the first device calculates the first group of keys on the multiple first quantization results based on a preset calculation method.
- the preset calculation method can be set according to the actual situation, for example, it can be any one or more combinations of XOR calculation, direct calculation, function, etc.
- XOR calculation can be used, that is, all the first quantization results are XORed to obtain the first group of keys.
- function calculation can be used, such as the function is a key derivation function (KDF, Key Derivation Function), then multiple first quantization results can be used as inputs of KDF, and the first group of keys can be obtained by KDF calculation.
- KDF Key Derivation Function
- the target second device generates a second set of keys based on relevant information of the multiple signals, including: the target second device obtains multiple second quantization results based on the relevant information of the multiple signals; the target second device generates the second set of keys based on the multiple second quantization results.
- the target second device is any one of all the second devices in the device group, and the processing of each second device in the device group is the same as that of the target second device, so it will not be described one by one here.
- the group key generated by the target second device is called the second group key.
- the target second device generates the second group key based on the received multiple signals, which is different from the execution subject of the first device. It may make the group key obtained by the target second device and the first device the same or different. Further verification is required to determine whether the second group key generated by the target second device is the same as the first group key generated by the first device. Therefore, this embodiment distinguishes between the group key generated by the target second device (that is, any second device) and the group key generated by the first device. It should be understood that, ideally, the group key generated by the target second device (that is, any second device) and the group key generated by the first device should be the same, that is, ideally, the first group key can be equal to the second group key.
- the target second device obtains multiple second quantization results based on the relevant information of the multiple signals, including: the target second device determines the second quantization range corresponding to the i-th signal based on the relevant information of the i-th signal among the multiple signals, and uses the second quantization value corresponding to the second quantization range as the i-th second quantization result among the multiple second quantization results, wherein the second quantization range is one of multiple second candidate quantization ranges, each second candidate quantization range in the multiple second candidate quantization ranges has a corresponding second candidate quantization value, and i is a positive integer.
- the target second device performs the same processing as the i-th signal for each signal, and finally obtains multiple quantization results. This embodiment is illustrated with the i-th signal, and each signal is not described one by one.
- the processing of the target second device may further include: the target second device may determine the maximum value and the minimum value of the relevant information value range based on the relevant information of the multiple signals; based on the quantization order Q, divide the relevant information value range into Q second candidate quantization ranges are provided, and a second candidate quantization value corresponding to each second candidate quantization range in the Q second candidate quantization ranges is determined, where Q is an integer greater than or equal to 2.
- the specific processing method for the target second device to determine Q second candidate quantization ranges and determine the second candidate quantization value corresponding to each of the Q second candidate quantization ranges is the same as the specific processing method for the aforementioned first device to determine Q first candidate quantization ranges and determine the first candidate quantization value corresponding to each of the Q first candidate quantization ranges, so it is not repeated.
- the target second device determines the second quantization range corresponding to the i-th signal based on the relevant information of the i-th signal among the multiple signals, and uses the second quantization value corresponding to the second quantization range as the i-th second quantization result among the multiple second quantization results, which may mean: the target second device determines the relevant information of the i-th signal among the multiple signals, and uses the second quantization range corresponding to the Q second quantization ranges, and uses the second quantization value corresponding to the second quantization range as the i-th second quantization result among the multiple second quantization results.
- the processing of the target second device obtaining the i-th second quantization result is also the same as the way in which the aforementioned first device obtains the i-th first quantization result, and will not be elaborated on.
- the relevant information of the multiple signals also includes at least one of the following: the strength of each signal in the multiple signals, and the phase of each signal.
- the relevant information of the signal is the strength and/or phase
- the specific description of the target second device determining Q second candidate quantization ranges and the second candidate quantization value corresponding to each second candidate quantization range is similar to the specific description of the aforementioned first device determining Q first candidate quantization ranges and the first candidate quantization value corresponding to each first candidate quantization range, and will not be repeated.
- the target second device when the relevant information of the signal is the strength of the signal, when the target second device receives each signal, it may be a relevant value of the strength of each signal, for example, it may be the square root of the signal strength, or the original value of the signal strength, or multiple power values of the signal strength, etc., and all possible situations are not enumerated here; accordingly, the target second device may be the square, or the original value, or multiple power values of the relevant value of the strength of each signal, and then determine Q second candidate quantization ranges and the second candidate quantization value corresponding to each second candidate quantization range.
- the specific processing of determining the Q second candidate quantization ranges and the second candidate quantization value corresponding to each second candidate quantization range is not elaborated here.
- the target second device generates the second group of keys based on the multiple second quantization results, which can be: the target second device merges the multiple second quantization results based on a specified order to obtain the second group of keys.
- the description of the specified order and the specific merging process are the same as the process of the first device merging the multiple first quantization results based on the specified order to obtain the first group of keys, and will not be repeated.
- the target second device generates the second group of keys based on the multiple second quantization results, which can be: the target second device calculates the second group of keys based on the multiple second quantization results based on a preset calculation method.
- the specific description of the preset calculation method is the same as the relevant description of the first device, and will not be repeated.
- the first device and each second device need to respectively generate their own group keys in the same manner, which will not be repeated here.
- the relevant information of the multiple signals includes a key sequence carried by each of the multiple signals; the first device generates a first group of keys based on the relevant information of the multiple signals, including: the first device generates the first group of keys based on the key sequence carried by each of the multiple signals.
- the key sequences carried by different signals may be randomly generated by the first device. This embodiment does not limit the manner in which the first device generates each key sequence.
- the jth signal among the multiple signals carries one or more data segments, different data segments among the one or more data segments are calculated based on identifications of different second devices and the jth key sequence, and j is a positive integer.
- the plurality of signals refers to a plurality of signals sent to each second device.
- the first device may send a signal to each second device based on the radio frequency coefficient corresponding to each second device, that is, the same signal content will be sent to each second device separately in this case, and eventually sent multiple times.
- the first device wants to send a signal with the content of the jth key sequence, it needs to be sent to N second devices respectively.
- the value of N is defined in the same way as in the above embodiment and will not be described in detail.
- the jth signal sent to the nth second device can carry a data segment, which is calculated based on the identifier of the nth second device and the jth key sequence; and by analogy, the jth signal sent to the n+1th second device can carry a data segment, which is calculated based on the identifier of the n+1th second device and the jth key sequence. This is not exhaustive.
- the calculation method can be set according to the actual situation, such as direct calculation, XOR calculation, function calculation or one or more methods.
- the calculation method is XOR calculation
- the j-th signal sent to the n-th second device is represented as r jn .
- the frame structure of r jn (that is, the data segment of r jn ) is designed as: in, represents the XOR operation, represents the ID number of the nth tag, and kj is the jth key sequence randomly generated by the reader.
- the first device may send a signal to each second device in each group of second devices based on the radio frequency coefficient corresponding to each group of second devices, that is, the same signal content will be sent multiple times in groups in this case.
- the first device wants to send a signal with the content of the jth key sequence, it needs to be sent to K groups of second devices respectively, that is, sent K times.
- the value definition of K is the same as that in the previous embodiment and is not elaborated on.
- the jth signal sent to the kth group of second devices can carry one or more data segments, wherein the number of data segments depends on the number of second devices included in the kth group of second devices; the one or more data segments are calculated based on the identifier of each second device in the kth group of second devices and the jth key sequence.
- the jth signal sent to the k+1th group of second devices can also carry one or more data segments, wherein the number of data segments depends on the number of second devices included in the k+1th group of second devices; the one or more data segments are calculated based on the identifier of each second device in the k+1th group of second devices and the jth key sequence, and so on, and are not elaborated on one by one.
- the calculation method is the same as that in the above example and is not described in detail.
- the calculation method is XOR calculation, and different data segments are calculated based on the identifiers of different second devices and the jth key sequence. It can mean that the data segment corresponding to each second device in the kth group of second devices is obtained by XOR calculation using the identifier of each second device and the jth key sequence.
- the jth signal corresponding to the kth group of second devices can be expressed as rjk , and the frame structure of rjk (that is, one or more data segments of rjk ) is designed as: in, represents the XOR operation, represents the ID number (i.e., identification) of the nth tag in the kth group of tags, and kj is the jth key sequence randomly generated by the reader.
- the first device generates the first group of keys based on the key sequence carried by each signal in the multiple signals, which may mean that the first device combines the key sequence carried by each signal based on a specified order to obtain the first group of keys.
- the specified order may be the same as that in the above embodiment and will not be described in detail.
- the first device generates the first group of keys based on the key sequence carried by each of the multiple signals, which may mean that the first device calculates the first group of keys based on the key sequence carried by each signal based on a preset calculation method.
- the preset calculation method may be the same as that in the above embodiment, and will not be described in detail.
- the relevant information of the multiple signals includes a key sequence carried by each of the multiple signals; the target second device generates a second set of keys based on the relevant information of the multiple signals, including: the target second device generates the second set of keys based on the key sequence carried by each of the multiple signals.
- the jth signal carries one or more data segments, and different data segments among the one or more data segments are calculated based on the identification of different second devices and the jth key sequence; the method further includes: the target second device extracts the target data segment corresponding to the target second device from the jth signal, where j is a positive integer; the target second device calculates the jth key sequence carried by the jth signal based on the identification of the target second device and the target data segment.
- the calculation method should be the same as that of the first device, and no repetitive description is given here.
- the calculation method is XOR calculation
- the target second device is the n-th tag
- the extracted data segment can be Then the nth tag uses its own ID to perform XOR with the above data segment again to obtain k j (the jth key sequence).
- k j the jth key sequence
- the first device may send a signal to each second device in each group of second devices based on the RF coefficients corresponding to each group of second devices.
- the target second device if the target second device is one of the second devices in the kth group, the target second device will only receive the jth signal (i.e., the signal carrying the jth key sequence) sent by the first device for the kth time.
- the jth signal sent for the kth time may carry one or more data segments.
- the target second device may directly extract the data segment corresponding to itself from the jth signal as the target data segment, and then calculate based on its own identification and the target data segment to obtain the jth key sequence.
- the position of the data segment corresponding to the target second device can be set according to actual conditions.
- the target second device is the nth second device in the kth group of second devices
- the position of the corresponding data segment can be the nth position, or it can also be other specified positions.
- This embodiment does not limit it. As long as the positions of the data segments corresponding to different second devices in the kth group of second devices are different, it is within the protection scope of this embodiment.
- the calculation method is XOR calculation.
- the jth signal corresponding to the kth group of second devices can be expressed as r jk .
- the frame structure of r jk (that is, one or more data segments of r jk ) is: Assuming that the target second device is the nth tag and the position of its corresponding data segment is the nth position, the nth data segment can be extracted from r jk , that is, As the target data segment, then based on its own identification and By performing XOR calculation again, k j (the jth key sequence) can be obtained.
- the meaning of each content in the above expression is the same as that in the previous example and will not be repeated here.
- the multiple signals are used to generate a second group of keys for each second device, and the method further includes: the first device calculates group key verification information based on the first group of keys, wherein the group key verification information is used by each second device to verify the consistency of the second group of keys with the first group of keys; and the first device sends a first message to each second device, wherein the first message carries the group key verification information.
- the method also includes: the target second device receives a first message from the first device, wherein the first message carries group key verification information, the group key verification information is calculated by the first device based on the first group key, and the first group key is generated by the first device based on the multiple information; the target second device calculates verification information based on the second group key; the target second device verifies the consistency of the second group key with the first group key based on the group key verification information and the verification information.
- the first device may also initiate a verification process to determine whether the second group key generated by each second device is the same as its own first group key.
- the first device calculates the group key verification information based on the first group key, which can be: the first device maps the first group key through a first preset function to obtain a first value, and uses the first value as the group key verification information.
- the first preset function can be a hash function, and the specific algorithm used by the hash function can be set according to actual conditions, and this embodiment does not limit it.
- the first preset function can also be other types of functions, as long as the corresponding mapping value can be obtained through the function, it is within the protection scope of this embodiment.
- the first device calculates the group key verification information based on the first group key, which can be: the first device calculates a cyclic redundancy check (CRC) code of the first group key, and uses the CRC (code) as the group key verification information.
- CRC cyclic redundancy check
- the specific algorithm used for the CRC calculation can be set according to actual conditions, and this embodiment does not limit it.
- the manner in which the first device sends the first message to each of the second devices may be multicast, broadcast or unicast, all of which are within the protection scope of this embodiment.
- the first device may broadcast the first message to all second devices.
- the target second device calculates the verification information based on the second group of keys, which can be: the target second device maps the second group of keys through a first preset function to obtain a second value, and uses the second value as the verification information.
- the first preset function is the same as the above embodiment and is not described in detail.
- the target second device calculates verification information based on the second group of keys, which may be: the target second device calculates a cyclic redundancy check (CRC) code of the second group of keys, and uses the CRC (code) of the second group of keys as verification information.
- CRC cyclic redundancy check
- the specific processing method of calculating the verification information by the target second device should be the same as the method of verifying the information based on the group key by the first device.
- the method also includes at least one of the following: when the second group of keys of the target second device is consistent with the first group of keys, the target second device sends a second message to the first device, wherein the second message is used to indicate that the target second device has successfully verified the consistency of the second group of keys with the first group of keys; when the second group of keys of the target second device is inconsistent with the first group of keys, the target second device sends a third message to the first device, wherein the third message is used to indicate that the target second device has failed to verify the consistency of the second group of keys with the first group of keys.
- the method also includes one of the following: the first device receives a second message from a target second device, wherein the second message is used to indicate that the target second device has successfully verified the consistency of the second group of keys with the first group of keys, and the target second device is one of the multiple second devices; the first device receives a third message from the target second device, wherein the third message is used to indicate that the target second device has failed to verify the consistency of the second group of keys with the first group of keys.
- the first device can record the target second device as the second device that successfully generates the group key, and then use the first group key to communicate with the target second device; here, communication can refer to decrypting the received data based on the first group key and/or encrypting the sent data based on the first group key.
- the first device when the first device receives the second message from any second device, it can determine that the second device has successfully generated the group key, record the second device, and communicate with the second device.
- the target second device can communicate with the first device using the second set of keys; here, communication can refer to decrypting received data based on the second set of keys and/or encrypting sent data based on the second set of keys.
- the first device can continue to perform the aforementioned processing on the target second device next time, so that the target second device generates a second group of keys that are the same as the first group of keys. Similarly, if the target second device sends the third message, the target second device can wait for the next generation of the group key.
- the multiple signals are used to generate a second group of keys for each second device, and the method further includes: the first device calculates group key error correction information based on the first group of keys, wherein the group key error correction information is used by each second device to correct the second group of keys to obtain a group key consistent with the first group of keys; and the first device sends a fourth message to each second device, wherein the fourth message carries the group key error correction information.
- the method also includes: the target second device receives a fourth message from the first device, wherein the fourth message carries group key error correction information, and the group key error correction information is calculated by the first device based on the first group key, and the first group key is generated by the first device based on the multiple information; the target second device corrects the second group key based on the group key error correction information to obtain a group key consistent with the first group key.
- the first device calculates the group key error correction information based on the first group key, which may be that the first device calculates the first group key based on the second preset calculation method to obtain a check code, and uses the check code as the group key error correction information.
- the target second device corrects the second group key based on the group key error correction information to obtain a group key consistent with the first group key, which may be that the target second device decodes and corrects the second group key using the group key error correction information based on the error correction method corresponding to the second preset method to obtain a group key consistent with the first group key.
- the calculation function (or calculation method) adopted by the second preset calculation method can be set according to actual conditions.
- any one or more functions such as LDPC (Low Density Parity-check Codes), Turbo decoding, etc. are used. All possible methods are not enumerated here. As long as the sequence can be encoded to obtain the check code, so that the other end can perform decoding and error correction, it is within the protection scope of this embodiment.
- the first device may trigger updating of the group key.
- the first device may periodically trigger the updating of the group key.
- the periodic duration may be set according to actual conditions, such as 7 days, 1 day, or longer or shorter, which are not exhaustively listed here.
- the first device may trigger the update of the group key when the second device is added or reduced in the device group.
- the first device determines the manner in which the second device is added or reduced in the device group, and the first device may receive indication information sent by a network device, and the indication information is used to indicate the addition of the second device in the device group or the removal of the second device.
- the network device may be an access network device, a core network device, an application function (AF), etc., which are not exhaustively listed here.
- the first device updates the group key by executing the method provided in the above embodiment again, so that the first device and each current second device in the device group updates the group key.
- the key generation method provided in this application is exemplified.
- the system consisting of the reader and N tags is shown in Figure 4: with the reader as the center and d1 as the radius, there are N tags communicating with the reader.
- the purpose of the group key scheme is to generate a common group key Gk between the reader and the N tags.
- N tags are all single-antenna devices, and the reader is configured with M antennas.
- the specific steps are as follows:
- Step 501 the reader broadcasts a group key generation signaling, for example, the group key generation signaling can be represented as message1.
- Step 502 After receiving the group key generation signaling, all tags in the N tags reflect the pilot signal s to the reader in turn according to the time slot anti-collision mechanism.
- Step 503 The reader receives the reflected pilot signal sent by each tag in step 502 in turn, and estimates the channel characteristics between the reader and each tag.
- tag 1 among N tags Take tag 1 among N tags as an example. The details are as follows: a continuous carrier (amplitude is 1) is transmitted by the first antenna of the reader, and the reflected pilot signal of tag 1 received by the reader is: By receiving the pilot signal, the reader can decode the channel between tag 1 and the reader. Finally, the reader obtains the channels between all tags and the reader: The meanings of the contents contained in each formula in this step are the same as those in the previous embodiment and will not be repeated.
- Step 504 The reader calculates the antenna weight coefficient, which is the radio frequency coefficient in the above embodiment.
- Step 505 The reader transmits a signal r, so that the signals received by N tags are all r.
- the reader sends signal r K times, that is, the reader sends the signal r to each group of tags in the K groups of tags divided by the N tags. It has been explained in the previous embodiment that multiple signals can be sent to each group of tags.
- the signal r in this step can be any one of the multiple signals sent to each group of tags.
- the reader does not need to repeat steps 501 to 504.
- the reader only needs to repeat step 505 multiple times, and can change the signal r each time (that is, change the relevant information of the signal) and re-transmit the signal r, that is, change r in step 505, so that the key source can be time-varying and the signal can be re-transmitted.
- the reader can determine whether to change the relevant information of the signal according to actual needs. There are also some possible examples in which the same signal may be sent twice at any time. This embodiment does not exhaust all possible situations.
- steps 501 to 505 may be performed in different coherence times, except that r may be changed each time step 505 is performed, so that the key source is time-varying.
- Step 506 After executing step 505 multiple times, the reader and all tags have accumulated information or features of multiple different r, and can then determine their respective group keys. At this point, the reader obtains the first group key in the aforementioned embodiment, and each tag obtains its own second group key in the aforementioned embodiment.
- Step 507 The reader and the N tags determine a consistent group key.
- This step can provide different methods for determining the final group key based on the tag computing capability.
- Method 1 The reader maps the initial key sequence (i.e. the reader's first group of keys) to a certain value through a hash function, or calculates the cyclic redundancy check code (CRC) of the sequence, and broadcasts the hash mapping value or cyclic redundancy check code.
- N tags calculate their own hash mapping value or cyclic redundancy check code according to their own initial key sequence (i.e. the tag's own second group of keys), and compare it with the data received from the reader. If they are consistent, the success command is returned. If they are inconsistent, the fail command is returned and the next group key generation is waited for.
- the reader records the tags that successfully generate the group key and can use this group key to communicate with these tags.
- Method 2 If the N tags have certain decoding and error correction capabilities (such as LDPC and Turbo decoding), the reader generates a check code from the initial key sequence (i.e., the reader's first set of keys) through a certain encoding method, and sends the check code to the N tags. All tags use the check code for decoding and error correction (i.e., each tag decodes and corrects its own second set of keys), so that the reader and each tag obtain consistent keys.
- decoding and error correction capabilities such as LDPC and Turbo decoding
- Method 1 is not able to correct errors for tags with weak computing power. If the key is inconsistent, it is necessary to wait for the next group key generation.
- Method 2 is a commonly used key error correction method, but for tags, it needs to support a decoding algorithm with a certain degree of complexity.
- N 32.
- the key inconsistency rate between N tags and readers, and the key inconsistency rate between Eve and readers are simulated.
- the results are shown in Figure 6.
- the key inconsistency rate between tags and readers represented by "tag” in Figure 6 specifically refers to the average value of the key inconsistency rate between N tags (the second group of keys) and readers (the first group of keys). It can be seen from Figure 6 that with the increase of the signal-to-noise ratio, the key inconsistency rate between tags and readers becomes smaller and smaller. For example, when the signal-to-noise ratio is 10dB, the key inconsistency rate between tags and readers is about 0.3.
- the key inconsistency rate between tags and readers is close to 0.05, while the key inconsistency rate between the eavesdropper and the reader is stable around 0.45 to 0.5, indicating that the above example can enable readers and tags to securely generate their respective group keys.
- the strength of the signal r is used as the key source, that is, the relevant information of the signal in the aforementioned embodiment is specifically the strength of the signal.
- the strength of the signal r is selected as the key source, that is, the specific content of the signal r is not concerned, and only its signal strength is used. The specific steps are as follows:
- steps 701 to 704 are the same as that of steps 501 to 504 in the above example, and thus will not be repeated.
- Step 705 The reader transmits a signal r so that the signal strengths received by the N tags are the same.
- the specific process is as follows:
- the strength of the signal r transmitted by the reader is recorded as P, and it is transmitted K times.
- the antenna weight coefficient of the kth time is w k
- the signal amplitude received by the tags involved in the kth group is:
- P represents the signal strength (or amplitude)
- the rest of the contents are the same as the above embodiment and will not be described in detail.
- all tags will record the signal strength P, and the reader also knows P, so P will be quantified as a key source.
- the reader does not need to repeatedly perform steps 701 to 704, and only needs to change the P value in step 705 to make the key source time-varying. If the channel environment is time-varying, steps 701 to 705 can be performed at different coherence times.
- Step 706 After multiple executions of step 705, assuming that all tags have obtained L intensity values and the reader also knows these L intensity values, both parties start quantization, and the reader and N tags obtain the initial key sequence, that is, the reader obtains the first set of keys, and each tag obtains its own second set of keys.
- the specific process is as follows: Assume that the reader takes the range of P as: P min ⁇ P ⁇ P max . When the quantization order is Q, the range of P is evenly divided into Q, each range corresponds to a Gray code of length log 2 Q, and each intensity value corresponds to log 2 Qbit.
- the reader and tag can perform rounding on all the obtained intensity values, and then quantize, so that the reader and N tags obtain the initial key sequence.
- the quantization method includes but is not limited to the method described herein.
- Step 707 The reader and the N tags determine a consistent group key. Specifically, using the given method 1 or method 2, the reader and the N tags determine a final consistent key.
- Steps 801 to 804 are the same as steps 501 to 504 in the above example and will not be described again.
- Step 805 The reader transmits a signal r, so that N tags receive the same group key.
- the reader sends signal r K times.
- the frame structure of r jk is designed as follows:
- any tag in the kth group receives r jk , it takes out the data segment corresponding to itself (i.e., the target data segment), and then XORs the data segment with its own ID to obtain k j .
- all tags will get the same k j .
- the meaning of the formula in this step is the same as that in the previous embodiment, and will not be repeated.
- the key source can be time-varied by simply changing k in step 805. Steps 801 to 805 can be performed in different coherence times.
- Step 806 Concatenate the accumulated different k (i.e., key sequences) into a group key sequence.
- the reader obtains the first group key (i.e., the group key sequence obtained by the reader), and each tag obtains its own second group key (i.e., the group key sequence obtained by each tag).
- Step 807 The reader and the N tags determine a consistent group key. That is, using the given method 1 or method 2, the reader and the N tags determine the final consistent key.
- the above examples design a physical layer group key generation scheme for a zero-power communication network with a reader as the central node and multiple tags as sub-nodes.
- This scheme configures weight coefficients for the reader's multiple antennas so that multiple tags can receive the same key source at the same time to obtain the group key. This effectively reduces the time overhead of group key generation.
- the weight coefficients are calculated using the legitimate channel value, the legitimate channel and the eavesdropping channel are different for eavesdroppers, so they cannot receive the same key source as the tag, thereby ensuring security.
- the security of the group key is proved.
- the key source it can resist illegal eavesdropping of different eavesdropping levels, so as to adapt to different application scenarios.
- a first device sends multiple signals to each second device, and the radio frequency coefficients of the multiple signals are calculated based on the channel characteristics between the second device and the first device, and then the first device itself will also generate a group key for communicating with each second device based on the relevant information of each signal.
- the radio frequency coefficients corresponding to different second devices for the signals sent to different second devices, the channel characteristics between the second device and the first device can be accurately offset, that is, the loss or interference of the channel between the second device and the first device can be offset, thereby ensuring the reduction of the time overhead of generating the group key while also ensuring the security of the group key.
- the research on group key generation technology is mainly divided into two categories: one is group key generation based on cryptography; the other is group key generation based on physical layer characteristics.
- the group key generation based on cryptography takes the process of generating group keys by an AP (Access Point) and multiple STAs (Stations) as an example: the AP first performs a four-way handshake with each STA to generate the corresponding pair keys, and the pair keys of different STAs are different; when the group key needs to be generated, the AP generates the group key GTK, and then encrypts the GTK with the pair key, and sends the encrypted data to the STA.
- AP Access Point
- STAs STAs
- the STA uses the pair key to decrypt and obtain the GTK, that is, if there are N STAs, it is necessary to send N GTKs.
- the processing methods of the group key based on the physical layer characteristics may include: in the first method, the central node and the child node exchange pilot signals with each other within a coherent time, and each records the signal strength. Then the central node calculates multiple strength differences and sends them to the child nodes respectively. The child node uses the signal strength recorded by itself and the received strength difference to restore the group key; in the second method, all child nodes are required to be configured with multiple antennas.
- the child node records the antenna that receives the signal as 1 and the antenna that does not receive the signal as 0, and finally obtains a sequence of the signal reception status of the multiple antennas; in the third method, through the specified method, it can be guaranteed that the state sequence of multiple child nodes is the same, so this state sequence can be used as the group key.
- the sub-node device capabilities are high.
- Cryptography-based group key generation requires the device to support key generators and complex encryption and decryption algorithms.
- Some group key solutions based on physical layer characteristics also require sub-node devices to have certain hardware capabilities or algorithm capabilities. These solutions that have special requirements for sub-nodes are not universal in zero-power networks. Zero-power devices in most scenarios have minimalist circuit designs, low computing power, and low storage capacity, and cannot support the requirements of these solutions.
- the time overhead of generating group keys is high.
- T time for a one-way communication from node to node
- N child nodes in total.
- AP Access Point
- STAs Stations
- the time to generate the group key is greater than 2NT.
- the time to generate a group key is 2NT, and within a coherent time, when the channel does not change, the group key can only be generated once. In scenarios with a longer coherent time, the group key will not change.
- the key generation method provided by the embodiment of the present application can first reduce the time overhead of group key generation. Specifically, the time for all tags (i.e., each second device) to obtain the quantization result or key sequence of the group key (i.e., obtain the relevant information of a signal once, or obtain the quantization result or key sequence based on the relevant information of a signal) provided by the key generation method provided by the present application is Less than 2NT, that is, lower than the time overhead of the group key generation scheme in the existing standard (802.11i). Again, the key generation method provided in this application does not require the tag (that is, the second device) to add any additional overhead. For the zero-power device tag, no unnecessary process is added.
- the tag only needs to perform simple reflection and reception of signals to realize the generation of the group key. There is no need to change the technology supported by the zero-power device and the simple circuit design. Finally, even in an environment with a long coherence time, the group key can still be updated to avoid the problem of a single key being used for too long. At the same time, not only can the endogenous channel be used to protect the key source, but the signal r can also be designed to strengthen the protection of the key source to resist eavesdroppers with different degrees of eavesdropping.
- FIG9 is a schematic diagram of the composition structure of a first device according to an embodiment of the present application, including:
- the first communication unit 901 is configured to send a plurality of signals to each second device among the plurality of second devices, wherein the radio frequency coefficients of the plurality of signals are calculated based on the channel characteristics between each second device and the first device;
- the first processing unit 902 is configured to generate a first set of keys based on relevant information of the multiple signals, where the first set of keys is used for communication between the first device and the multiple second devices.
- the first communication unit is configured to send a group key generation signaling to each of the second devices; and receive a pilot signal from each of the second devices, wherein the pilot signal is a reflected signal corresponding to the group key generation signaling;
- the first processing unit is configured to calculate a channel characteristic between each second device and the first device based on a pilot signal of each second device.
- the first processing unit is used to calculate one or more radio frequency coefficients based on the channel characteristics between each second device and the first device, wherein different radio frequency coefficients among the one or more radio frequency coefficients correspond to different second devices.
- the first communication unit is used to send the multiple signals to each second device in the kth group of second devices based on the kth RF coefficient among the one or more RF coefficients, wherein different RF coefficients among the one or more RF coefficients correspond to different groups of the multiple second devices, and different groups of the multiple second devices include different second devices, and the kth group of second devices is one of the one or more groups of the multiple second devices, and k is a positive integer.
- the first processing unit is configured to obtain a plurality of first quantization results based on relevant information of the plurality of signals; and generate the first group of keys based on the plurality of first quantization results.
- the first processing unit is used to determine a first quantization range corresponding to the i-th signal based on relevant information of the i-th signal among the multiple signals, and use a first quantization value corresponding to the first quantization range as the i-th first quantization result among the multiple first quantization results, wherein the first quantization range is one of multiple first candidate quantization ranges, each first candidate quantization range in the multiple first candidate quantization ranges has a corresponding first candidate quantization value, and i is a positive integer.
- the relevant information of the multiple signals includes at least one of the following: the strength of each signal in the multiple signals and the phase of each signal.
- the relevant information of the multiple signals includes a key sequence carried by each of the multiple signals; and the first processing unit is used to generate the first group of keys based on the key sequence carried by each of the multiple signals.
- the j-th signal among the multiple signals carries one or more data segments, and different data segments among the one or more data segments are calculated based on identifications of different second devices and the j-th key sequence, where j is a positive integer.
- the multiple signals are used for each second device to generate a second group of keys;
- the first processing unit is used to calculate group key verification information based on the first group of keys, wherein the group key verification information is used for each second device to verify the consistency of the second group of keys with the first group of keys;
- the first communication unit is used to send a first message to each of the second devices, wherein the first message carries the group key verification information.
- the first communication unit is used to perform one of the following: receiving a second message from a target second device, wherein the second message is used to indicate that the target second device has successfully performed a consistency check on the second group of keys and the first group of keys, and the target second device is one of the multiple second devices; receiving a third message from the target second device, wherein the third message is used to indicate that the target second device has failed a consistency check on the second group of keys and the first group of keys.
- the multiple signals are used for each second device to generate a second group key;
- the first processing unit is used to calculate group key error correction information based on the first group key, wherein the group key error correction information is used for each second device to correct the error of the second group key to obtain a group key consistent with the first group key;
- the first communication unit is used to send a fourth message to each of the second devices, wherein the fourth message carries the group key error correction information.
- the first device is one of the following: a terminal device, a network device; the second device is a zero-power consumption device.
- FIG10 is a schematic diagram of a structure of a target second device according to an embodiment of the present application, including:
- the second communication unit 1001 is used to receive multiple signals from the first device, wherein the radio frequency coefficients of the multiple signals are calculated based on the channel characteristics between the target second device and the first device;
- the second processing unit 1002 is used to generate a second group of keys based on the relevant information of the multiple signals, wherein the second group of keys is used for communication between the target second device and the first device, the second group of keys are the same keys for multiple second devices, and the target second device is one of the multiple second devices.
- the second communication unit is used to receive the group key generation signaling from the first device; and send a pilot signal to the first device, wherein the pilot signal is a reflected signal corresponding to the group key generation signaling, and the pilot signal is used by the first device to calculate the channel characteristics between the target second device and the first device.
- the second processing unit is configured to obtain a plurality of second quantization results based on the relevant information of the plurality of signals; and generate the second group of keys based on the plurality of second quantization results.
- the second processing unit is used to determine a second quantization range corresponding to the i-th signal based on relevant information of the i-th signal among the multiple signals, and use the second quantization value corresponding to the second quantization range as the i-th second quantization result among the multiple second quantization results, wherein the second quantization range is one of multiple second candidate quantization ranges, each second candidate quantization range in the multiple second candidate quantization ranges has a corresponding second candidate quantization value, and i is a positive integer.
- the relevant information of the multiple signals includes one of the following: the strength of each signal in the multiple signals and the phase of each signal.
- the relevant information of the multiple signals includes a key sequence carried by each of the multiple signals; and the second processing unit is used to generate the second group of keys based on the key sequence carried by each of the multiple signals.
- the j-th signal of the plurality of signals carries one or more data segments, and different data segments of the one or more data segments are calculated based on the identification of different second devices and the j-th key sequence; the second processing unit is used to, from the j-th signal, Extract the target data segment corresponding to the target second device, where j is a positive integer; and calculate the jth key sequence carried by the jth signal based on the identifier of the target second device and the target data segment.
- the second communication unit is configured to receive a first message from the first device, wherein the first message carries group key verification information, the group key verification information is calculated by the first device based on a first group key, and the first group key is generated by the first device based on the multiple information;
- the second processing unit is configured to calculate verification information based on the second group of keys; and verify consistency between the second group of keys and the first group of keys based on the group key verification information and the verification information.
- the second communication unit is used to perform at least one of the following: when the second group of keys is consistent with the first group of keys, sending a second message to the first device, wherein the second message is used to indicate that the target second device has successfully verified the consistency of the second group of keys with the first group of keys; when the second group of keys is inconsistent with the first group of keys, sending a third message to the first device, wherein the third message is used to indicate that the target second device has failed to verify the consistency of the second group of keys with the first group of keys.
- the second communication unit is configured to receive a fourth message from the first device, wherein the fourth message carries group key error correction information, the group key error correction information is calculated by the first device based on a first group key, and the first group key is generated by the first device based on the multiple information;
- the second processing unit is configured to perform error correction on the second group key based on the group key error correction information to obtain a group key consistent with the first group key.
- the first device is one of the following: a terminal device, a network device; the target second device is a zero-power consumption device.
- the device of the embodiment of the present application can realize the corresponding functions of each device in the aforementioned key generation method embodiment.
- the process, function, implementation method and beneficial effect corresponding to each module (submodule, unit or component, etc.) in the first device or the target second device can be referred to the corresponding description in the above method embodiment, which will not be repeated here.
- the functions described in the first device of the application embodiment or each module (submodule, unit or component, etc.) in the target second device can be implemented by different modules (submodule, unit or component, etc.), or by the same module (submodule, unit or component, etc.).
- Fig. 11 is a schematic structural diagram of a communication device 1100 according to an embodiment of the present application.
- the communication device 1100 includes a processor 1110, and the processor 1110 can call and run a computer program from a memory to enable the communication device 1100 to implement the method in the embodiment of the present application.
- the communication device 1100 may further include a memory 1120.
- the processor 1110 may call and run a computer program from the memory 1120, so that the communication device 1100 implements the method in the embodiment of the present application.
- the memory 1120 may be a separate device independent of the processor 1110 , or may be integrated into the processor 1110 .
- the communication device 1100 may further include a transceiver 1130, and the processor 1110 may control the transceiver 1130 to communicate with other devices, specifically, may send information or data to other devices, or receive information or data sent by other devices.
- the transceiver 1130 may include a transmitter and a receiver.
- the transceiver 1130 may further include an antenna, and the number of the antennas may be one or more.
- the communication device 1100 may be the first device of an embodiment of the present application, or the target second device, and the communication device 1100 may implement the corresponding processes implemented by the first device or the target second device in each method of the embodiment of the present application, which will not be repeated here for the sake of brevity.
- a first device comprising: a processor, and a memory communicating with the processor, the memory being used to store instructions, and when the instructions are executed by the processor, the instructions cause the first device to execute: sending multiple signals to each second device among multiple second devices, wherein the radio frequency coefficients of the multiple signals are calculated based on channel characteristics between each second device and the first device; generating a first group of keys based on relevant information of the multiple signals, and the first group of keys is used for communication between the first device and the multiple second devices.
- the instruction also causes the first device to execute: sending a group key generation signaling to each of the second devices; receiving a pilot signal from each of the second devices, wherein the pilot signal is a reflected signal corresponding to the group key generation signaling; and calculating the channel characteristics between each of the second devices and the first device based on the pilot signal of each of the second devices.
- the instruction also causes the first device to execute: calculating one or more radio frequency coefficients based on channel characteristics between each of the second devices and the first device, wherein different radio frequency coefficients among the one or more radio frequency coefficients correspond to different second devices.
- the instruction also causes the first device to execute: based on the kth RF coefficient among the one or more RF coefficients, sending the multiple signals to each second device in the kth group of second devices, wherein different RF coefficients among the one or more RF coefficients correspond to different groups of the multiple second devices, and different groups of the multiple second devices include different second devices, the kth group of second devices is one of the one or more groups of the multiple second devices, and k is a positive integer.
- the instructions further cause the first device to execute: obtaining a plurality of first quantization results based on relevant information of the plurality of signals; and generating the first set of keys based on the plurality of first quantization results.
- the instruction also causes the first device to execute: based on relevant information of the i-th signal among the multiple signals, determine a first quantization range corresponding to the i-th signal, and use a first quantization value corresponding to the first quantization range as the i-th first quantization result among the multiple first quantization results, wherein the first quantization range is one of multiple first candidate quantization ranges, each first candidate quantization range in the multiple first candidate quantization ranges has a corresponding first candidate quantization value, and i is a positive integer.
- the relevant information of the multiple signals includes at least one of the following: the strength of each signal in the multiple signals and the phase of each signal.
- the relevant information of the multiple signals includes a key sequence carried by each of the multiple signals; the instructions further cause the first device to execute: generating the first group of keys based on the key sequence carried by each of the multiple signals.
- the j-th signal among the multiple signals carries one or more data segments, and different data segments among the one or more data segments are calculated based on identifications of different second devices and the j-th key sequence, where j is a positive integer.
- the multiple signals are used to generate a second group of keys for each second device; the instruction also causes the first device to execute: based on the first group of keys, calculate group key verification information, wherein the group key verification information is used by each second device to verify the consistency of the second group of keys with the first group of keys; send a first message to each second device, wherein the first message carries the group key verification information.
- the multiple signals are used to generate a second group of keys for each second device; the instruction also causes the first device to execute: based on the first group of keys, calculate group key error correction information, wherein the group key error correction information is used by each second device to correct the second group of keys to obtain a group key consistent with the first group of keys; send a fourth message to each second device, wherein the fourth message carries the group key error correction information.
- the first device is one of the following: a terminal device, a network device; the second device is a zero-power consumption device.
- the instruction also causes the target second device to execute: receiving a group key generation signaling from the first device; sending a pilot signal to the first device, wherein the pilot signal is a reflected signal corresponding to the group key generation signaling, and the pilot signal is used by the first device to calculate the channel characteristics between the target second device and the first device.
- the instruction also causes the target second device to execute: based on relevant information of the i-th signal among the multiple signals, determine a second quantization range corresponding to the i-th signal, and use a second quantization value corresponding to the second quantization range as the i-th second quantization result among the multiple second quantization results, wherein the second quantization range is one of multiple second candidate quantization ranges, each second candidate quantization range in the multiple second candidate quantization ranges has a corresponding second candidate quantization value, and i is a positive integer.
- the relevant information of the multiple signals includes one of the following: the strength of each signal in the multiple signals and the phase of each signal.
- the relevant information of the multiple signals includes a key sequence carried by each of the multiple signals; the instructions further cause the target second device to execute: generating the second set of keys based on the key sequence carried by each of the multiple signals.
- the j-th signal among the multiple signals carries one or more data segments, and different data segments among the one or more data segments are calculated based on the identification of different second devices and the j-th key sequence; the instruction also enables the target second device to execute: extracting the target data segment corresponding to the target second device from the j-th signal, where j is a positive integer; and calculating the j-th key sequence carried by the j-th signal based on the identification of the target second device and the target data segment.
- the instruction also causes the target second device to execute: receiving a first message from the first device, wherein the first message carries group key verification information, the group key verification information is calculated by the first device based on a first group key, and the first group key is generated by the first device based on the multiple information; calculating verification information based on the second group key; and verifying the consistency of the second group key with the first group key based on the group key verification information and the verification information.
- the instruction also causes the target second device to execute: receiving a fourth message from the first device, wherein the fourth message carries group key error correction information, the group key error correction information is calculated by the first device based on the first group key, and the first group key is generated by the first device based on the multiple information; correcting the second group key based on the group key error correction information to obtain a group key consistent with the first group key.
- the first device is one of the following: a terminal device, a network device; the target second device is a zero-power consumption device.
- Fig. 12 is a schematic structural diagram of a chip 1200 according to an embodiment of the present application.
- the chip 1200 includes a processor 1210, and the processor 1210 can call and run a computer program from a memory to implement the method in the embodiment of the present application.
- the chip 1200 may further include a memory 1220.
- the processor 1210 may call and run a computer program from the memory 1220 to implement the method performed by the access network device or the first core network device in the embodiment of the present application.
- the memory 1220 may be a separate device independent of the processor 1210, or may be integrated in the processor 1210.
- the chip 1200 may further include an input interface 1230.
- the processor 1210 may control the input interface 1230 to communicate with other devices or chips, and specifically, may obtain information or data sent by other devices or chips.
- the chip 1200 may further include an output interface 1240.
- the processor 1210 may control the output interface 1240 to communicate with other devices or chips, and specifically, may output information or data to other devices or chips.
- the chip can be applied to the first device or the target second device in the embodiments of the present application, and the chip can implement the corresponding processes implemented by the first device or the target second device in the various methods of the embodiments of the present application. For the sake of brevity, they will not be repeated here.
- the chip mentioned in the embodiments of the present application can also be called a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.
- processors mentioned above can be general-purpose processors, digital signal processors (DSP), field programmable gate arrays (FPGA), application specific integrated circuits (ASIC) or other programmable logic devices, transistor logic devices, discrete hardware components, etc.
- DSP digital signal processors
- FPGA field programmable gate arrays
- ASIC application specific integrated circuits
- the above-mentioned memory may be a volatile memory or a nonvolatile memory, or may include both volatile and nonvolatile memories.
- the memories in the embodiments of the present application are intended to include, but are not limited to, these and any other suitable types of memories.
- FIG. 13 is a schematic block diagram of a communication system 1300 according to an embodiment of the present application.
- the communication system 1300 includes a first device 1310 and a target second device 1320.
- it can be implemented in whole or in part by software, hardware, firmware or any combination thereof.
- software it can be implemented in whole or in part in the form of a computer program product.
- the computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function in accordance with the embodiment of the present application is generated in whole or in part.
- the computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device.
- the computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium.
- the size of the serial numbers of the above-mentioned processes does not mean the order of execution.
- the execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
Landscapes
- Engineering & Computer Science (AREA)
- Signal Processing (AREA)
- Computer Networks & Wireless Communication (AREA)
- Computer Security & Cryptography (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
Description
Claims (76)
- 一种密钥生成方法,包括:第一设备向多个第二设备中的每个第二设备发送多个信号,其中,所述多个信号的射频系数为基于所述每个第二设备与所述第一设备间的信道特征计算得到的;所述第一设备基于所述多个信号的相关信息,生成第一组密钥,所述第一组密钥用于所述第一设备与所述多个第二设备的通信。
- 根据权利要求1所述的方法,其中,所述方法还包括:所述第一设备向所述每个第二设备发送组密钥生成信令;所述第一设备接收来自所述每个第二设备的导频信号,其中,所述导频信号为所述组密钥生成信令所对应的反射信号;所述第一设备基于所述每个第二设备的导频信号,计算所述每个第二设备与所述第一设备间的信道特征。
- 根据权利要求2所述的方法,其中,所述方法还包括:所述第一设备基于所述每个第二设备与所述第一设备间的信道特征,计算一个或多个射频系数,其中,所述一个或多个射频系数中不同的射频系数对应不同的第二设备。
- 根据权利要求3所述的方法,其中,所述第一设备向多个第二设备中的每个第二设备发送多个信号,包括:所述第一设备基于所述一个或多个射频系数中的第k个射频系数,向第k组第二设备中的每个第二设备发送所述多个信号,其中,所述一个或多个射频系数中不同的射频系数对应所述多个第二设备的不同分组、且所述多个第二设备的不同分组中包括不同的第二设备,所述第k组第二设备为所述多个第二设备的一个或多个分组中之一,k为正整数。
- 根据权利要求1-4任一项所述的方法,其中,所述第一设备基于所述多个信号的相关信息,生成第一组密钥,包括:所述第一设备基于所述多个信号的相关信息,得到多个第一量化结果;所述第一设备基于所述多个第一量化结果,生成所述第一组密钥。
- 根据权利要求5所述的方法,其中,所述第一设备基于所述多个信号的相关信息,得到多个第一量化结果,包括:所述第一设备基于所述多个信号中第i个信号的相关信息,确定所述第i个信号对应的第一量化范围,将所述第一量化范围对应的第一量化值作为所述多个第一量化结果中的第i个第一量化结果,其中,所述第一量化范围为多个第一候选量化范围中之一,所述多个第一候选量化范围中每个第一候选量化范围具备对应的第一候选量化值,i为正整数。
- 根据权利要求5或6所述的方法,其中,所述多个信号的相关信息,包括以下至少之一:所述多个信号中每个信号的强度、所述每个信号的相位。
- 根据权利要求1-4任一项所述的方法,其中,所述多个信号的相关信息包括所述多个信号中每个信号携带的密钥序列;所述第一设备基于所述多个信号的相关信息,生成第一组密钥,包括:所述第一设备基于所述多个信号中每个信号携带的密钥序列,生成所述第一组密钥。
- 根据权利要求8所述的方法,其中,所述多个信号中第j个信号携带一个或多个数据段,所述一个或多个数据段中不同的数据段为基于不同的第二设备的标识和第j个密钥序列计算的,j为正整数。
- 根据权利要求1-9任一项所述的方法,其中,所述多个信号用于所述每个第二设备生成第二组密钥,所述方法还包括:所述第一设备基于所述第一组密钥,计算组密钥校验信息,其中,所述组密钥校验信息用于所述每个第二设备校验所述第二组密钥与所述第一组密钥的一致性;所述第一设备向所述每个第二设备发送第一消息,其中,所述第一消息携带所述组密钥校验信息。
- 根据权利要求10所述的方法,其中,所述方法还包括以下之一:所述第一设备接收来自目标第二设备的第二消息,其中,所述第二消息用于指示所述目标第二设备对所述第二组密钥与所述第一组密钥的一致性校验成功,所述目标第二设备为所述多个第二设备中之一;所述第一设备接收来自所述目标第二设备的第三消息,其中,所述第三消息用于指示所述目标第二设备对所述第二组密钥与所述第一组密钥的一致性校验失败。
- 根据权利要求1-9任一项所述的方法,其中,所述多个信号用于所述每个第二设备生成第二组密钥,所述方法还包括:所述第一设备基于所述第一组密钥,计算组密钥纠错信息,其中,所述组密钥纠错信息用于所述每个第二设备对所述第二组密钥纠错得到与所述第一组密钥一致的组密钥;所述第一设备向所述每个第二设备发送第四消息,其中,所述第四消息携带所述组密钥纠错信息。
- 根据权利要求1-12任一项所述的方法,其中,所述第一设备为以下之一:终端设备、网络设备;所述第二设备为零功耗设备。
- 一种密钥生成方法,包括:目标第二设备接收来自第一设备的多个信号,其中,所述多个信号的射频系数为基于所述目标第二设备与所述第一设备间的信道特征计算得到的;所述目标第二设备基于所述多个信号的相关信息,生成第二组密钥,其中,所述第二组密钥用于所述目标第二设备与所述第一设备的通信,所述第二组密钥为多个第二设备相同的密钥、且所述目标第二设备为所述多个第二设备中之一。
- 根据权利要求14所述的方法,其中,所述方法还包括:所述目标第二设备接收来自所述第一设备的组密钥生成信令;所述目标第二设备向所述第一设备发送导频信号,其中,所述导频信号为所述组密钥生成信令所对应的反射信号,所述导频信号用于所述第一设备计算所述目标第二设备与所述第一设备间的信道特征。
- 根据权利要求14或15所述的方法,其中,所述目标第二设备基于所述多个信号的相关信息,生成第二组密钥,包括:所述目标第二设备基于所述多个信号的相关信息,得到多个第二量化结果;所述目标第二设备基于所述多个第二量化结果,生成所述第二组密钥。
- 根据权利要求16所述的方法,其中,所述目标第二设备基于所述多个信号的相关信息,得到多个第二量化结果,包括:所述目标第二设备基于所述多个信号中第i个信号的相关信息,确定所述第i个信号对应的第二量化范围,将所述第二量化范围对应的第二量化值作为所述多个第二量化结果中的第i个第二量化结果,其中,所述第二量化范围为多个第二候选量化范围中之一,所述多个第二候选量化范围中每个第二候选量化范围具备对应的第二候选量化值,i为正整数。
- 根据权利要求16或17所述的方法,其中,所述多个信号的相关信息,包括以下之一:所述多个信号中每个信号的强度、所述每个信号的相位。
- 根据权利要求14或15所述的方法,其中,所述多个信号的相关信息包括所述多个信号中每个信号携带的密钥序列;所述目标第二设备基于所述多个信号的相关信息,生成第二组密钥,包括:所述目标第二设备基于所述多个信号中每个信号携带的密钥序列,生成所述第二组密钥。
- 根据权利要求19所述的方法,其中,所述多个信号中第j个信号携带一个或多个数据段,所述一个或多个数据段中不同的数据段为基于不同的第二设备的标识和第j个密钥序列计算的;所述方法还包括:所述目标第二设备从所述第j个信号中,提取所述目标第二设备对应的目标数据段,j为正整数;所述目标第二设备基于所述目标第二设备的标识和所述目标数据段,计算所述第j个信号携带的第j个密钥序列。
- 根据权利要求14-20任一项所述的方法,其中,所述方法还包括:所述目标第二设备接收来自所述第一设备的第一消息,其中,所述第一消息携带组密钥校验信息,所述组密钥校验信息为所述第一设备基于第一组密钥计算的,所述第一组密钥为所述第一设备基于所述多个信息生成的;所述目标第二设备基于所述第二组密钥计算验证信息;所述目标第二设备基于所述组密钥校验信息和所述验证信息,校验所述第二组密钥与所述第一组密钥的一致性。
- 根据权利要求21所述的方法,其中,所述方法还包括以下至少之一:所述目标第二设备在所述第二组密钥与所述第一组密钥一致的情况下,所述目标第二设备向所述第一设备发送第二消息,其中,所述第二消息用于指示所述目标第二设备对所述第二组密钥与所述第一组密钥的一致性校验成功;所述目标第二设备在所述第二组密钥与所述第一组密钥不一致的情况下,所述目标第二设备向所述第一设备发送第三消息,其中,所述第三消息用于指示所述目标第二设备对所述第二组密钥与所述第一组密钥的一致性校验失败。
- 根据权利要求14-20任一项所述的方法,其中,所述方法还包括:所述目标第二设备接收来自所述第一设备的第四消息,其中,所述第四消息携带组密钥纠错信息,所述组密钥纠错信息为所述第一设备基于第一组密钥计算的,所述第一组密钥为所述第一设备基于所述多个信息生成的;所述目标第二设备基于所述组密钥纠错信息对所述第二组密钥进行纠错,得到与所述第一组密钥一致的组密钥。
- 根据权利要求14-23任一项所述的方法,其中,所述第一设备为以下之一:终端设备、网络设备;所述目标第二设备为零功耗设备。
- 一种第一设备,包括:第一通信单元,用于向多个第二设备中的每个第二设备发送多个信号,其中,所述多个信号的射频系数为基于所述每个第二设备与所述第一设备间的信道特征计算得到的;第一处理单元,用于基于所述多个信号的相关信息,生成第一组密钥,所述第一组密钥用于所述第一设备与所述多个第二设备的通信。
- 根据权利要求25所述的第一设备,其中,所述第一通信单元,用于向所述每个第二设备发送组密钥生成信令;接收来自所述每个第二设备的导频信号,其中,所述导频信号为所述组密钥生成信令所对应的反射信号;所述第一处理单元,用于基于所述每个第二设备的导频信号,计算所述每个第二设备与所述第一设备间的信道特征。
- 根据权利要求26所述的第一设备,其中,所述第一处理单元,用于基于所述每个第二设备与所述第一设备间的信道特征,计算一个或多个射频系数,其中,所述一个或多个射频系数中不同的射频系数对应不同的第二设备。
- 根据权利要求27所述的第一设备,其中,所述第一通信单元,用于基于所述一个或多个射频系数中的第k个射频系数,向第k组第二设备中的每个第二设备发送所述多个信号,其中,所述一个或多个射频系数中不同的射频系数对应所述多个第二设备的不同分组、且所述多个第二设备的不同分组中包括不同的第二设备,所述第k组第二设备为所述多个第二设备的一个或多个分组中之一,k为正整数。
- 根据权利要求25-28任一项所述的第一设备,所述第一处理单元,用于基于所述多个信号的相关信息,得到多个第一量化结果;基于所述多个第一量化结果,生成所述第一组密钥。
- 根据权利要求29所述的第一设备,其中,所述第一处理单元,用于基于所述多个信号中第i个信号的相关信息,确定所述第i个信号对应的第一量化范围,将所述第一量化范围对应的第一量化值作为所述多个第一量化结果中的第i个第一量化结果,其中,所述第一量化范围为多个第一候选量化范围中之一,所述多个第一候选量化范围中每个第一候选量化范围具备对应的第一候选量化值,i为正整数。
- 根据权利要求29或30所述的第一设备,其中,所述多个信号的相关信息,包括以下至少之一:所述多个信号中每个信号的强度、所述每个信号的相位。
- 根据权利要求25-28任一项所述的第一设备,其中,所述多个信号的相关信息包括所述多个信号中每个信号携带的密钥序列;所述第一处理单元,用于基于所述多个信号中每个信号携带的密钥序列,生成所述第一组密钥。
- 根据权利要求32所述的第一设备,其中,所述多个信号中第j个信号携带一个或多个数据段,所述一个或多个数据段中不同的数据段为基于不同的第二设备的标识和第j个密钥序列计算的,j为正整数。
- 根据权利要求25-33任一项所述的第一设备,其中,所述多个信号用于所述每个第二设备生成第二组密钥;所述第一处理单元,用于基于所述第一组密钥,计算组密钥校验信息,其中,所述组密钥校验信息用于所述每个第二设备校验所述第二组密钥与所述第一组密钥的一致性;所述第一通信单元,用于向所述每个第二设备发送第一消息,其中,所述第一消息携带所述组密钥校验信息。
- 根据权利要求34所述的第一设备,其中,所述第一通信单元,用于执行以下之一:接收来自目标第二设备的第二消息,其中,所述第二消息用于指示所述目标第二设备对所述第二组密钥与所述第一组密钥的一致性校验成功,所述目标第二设备为所述多个第二设备中之一;接收来自所述目标第二设备的第三消息,其中,所述第三消息用于指示所述目标第二设备对所述第二组密钥与所述第一组密钥的一致性校验失败。
- 根据权利要求25-33任一项所述的第一设备,其中,所述多个信号用于所述每个第二设备生成 第二组密钥;所述第一处理单元,用于基于所述第一组密钥,计算组密钥纠错信息,其中,所述组密钥纠错信息用于所述每个第二设备对所述第二组密钥纠错得到与所述第一组密钥一致的组密钥;所述第一通信单元,用于向所述每个第二设备发送第四消息,其中,所述第四消息携带所述组密钥纠错信息。
- 根据权利要求25-36任一项所述的第一设备,其中,所述第一设备为以下之一:终端设备、网络设备;所述第二设备为零功耗设备。
- 一种目标第二设备,包括:第二通信单元,用于接收来自第一设备的多个信号,其中,所述多个信号的射频系数为基于所述目标第二设备与所述第一设备间的信道特征计算得到的;第二处理单元,用于基于所述多个信号的相关信息,生成第二组密钥,其中,所述第二组密钥用于所述目标第二设备与所述第一设备的通信,所述第二组密钥为多个第二设备相同的密钥、且所述目标第二设备为所述多个第二设备中之一。
- 根据权利要求38所述的目标第二设备,其中,所述第二通信单元,用于接收来自所述第一设备的组密钥生成信令;向所述第一设备发送导频信号,其中,所述导频信号为所述组密钥生成信令所对应的反射信号,所述导频信号用于所述第一设备计算所述目标第二设备与所述第一设备间的信道特征。
- 根据权利要求38或39所述的目标第二设备,其中,所述第二处理单元,用于基于所述多个信号的相关信息,得到多个第二量化结果;基于所述多个第二量化结果,生成所述第二组密钥。
- 根据权利要求40所述的目标第二设备,其中,所述第二处理单元,用于基于所述多个信号中第i个信号的相关信息,确定所述第i个信号对应的第二量化范围,将所述第二量化范围对应的第二量化值作为所述多个第二量化结果中的第i个第二量化结果,其中,所述第二量化范围为多个第二候选量化范围中之一,所述多个第二候选量化范围中每个第二候选量化范围具备对应的第二候选量化值,i为正整数。
- 根据权利要求40或41所述的目标第二设备,其中,所述多个信号的相关信息,包括以下之一:所述多个信号中每个信号的强度、所述每个信号的相位。
- 根据权利要求38或39所述的目标第二设备,其中,所述多个信号的相关信息包括所述多个信号中每个信号携带的密钥序列;所述第二处理单元,用于基于所述多个信号中每个信号携带的密钥序列,生成所述第二组密钥。
- 根据权利要求43所述的目标第二设备,其中,所述多个信号中第j个信号携带一个或多个数据段,所述一个或多个数据段中不同的数据段为基于不同的第二设备的标识和第j个密钥序列计算的;所述第二处理单元,用于从所述第j个信号中,提取所述目标第二设备对应的目标数据段,j为正整数;基于所述目标第二设备的标识和所述目标数据段,计算所述第j个信号携带的第j个密钥序列。
- 根据权利要求38-44任一项所述的目标第二设备,其中,所述第二通信单元,用于接收来自所述第一设备的第一消息,其中,所述第一消息携带组密钥校验信息,所述组密钥校验信息为所述第一设备基于第一组密钥计算的,所述第一组密钥为所述第一设备基于所述多个信息生成的;所述第二处理单元,用于基于所述第二组密钥计算验证信息;基于所述组密钥校验信息和所述验证信息,校验所述第二组密钥与所述第一组密钥的一致性。
- 根据权利要求45所述的目标第二设备,其中,所述第二通信单元,用于执行以下至少之一:在所述第二组密钥与所述第一组密钥一致的情况下,向所述第一设备发送第二消息,其中,所述第二消息用于指示所述目标第二设备对所述第二组密钥与所述第一组密钥的一致性校验成功;在所述第二组密钥与所述第一组密钥不一致的情况下,向所述第一设备发送第三消息,其中,所述第三消息用于指示所述目标第二设备对所述第二组密钥与所述第一组密钥的一致性校验失败。
- 根据权利要求38-44任一项所述的目标第二设备,其中,所述第二通信单元,用于接收来自所述第一设备的第四消息,其中,所述第四消息携带组密钥纠错信息,所述组密钥纠错信息为所述第一设备基于第一组密钥计算的,所述第一组密钥为所述第一设备基于所述多个信息生成的;所述第二处理单元,用于基于所述组密钥纠错信息对所述第二组密钥进行纠错,得到与所述第一组密钥一致的组密钥。
- 根据权利要求38-47任一项所述的目标第二设备,其中,所述第一设备为以下之一:终端设备、网络设备;所述目标第二设备为零功耗设备。
- 一种第一设备,包括:处理器,与所述处理器通信的存储器,所述存储器用于存储指令,当所述指令被所述处理器执行时,所述指令使所述第一设备执行:向多个第二设备中的每个第二设备发送多个信号,其中,所述多个信号的射频系数为基于所述每个第二设备与所述第一设备间的信道特征计 算得到的;基于所述多个信号的相关信息,生成第一组密钥,所述第一组密钥用于所述第一设备与所述多个第二设备的通信。
- 根据权利要求49所述的第一设备,其中,所述指令还使所述第一设备执行:向所述每个第二设备发送组密钥生成信令;接收来自所述每个第二设备的导频信号,其中,所述导频信号为所述组密钥生成信令所对应的反射信号;基于所述每个第二设备的导频信号,计算所述每个第二设备与所述第一设备间的信道特征。
- 根据权利要求50所述的第一设备,其中,所述指令还使所述第一设备执行:基于所述每个第二设备与所述第一设备间的信道特征,计算一个或多个射频系数,其中,所述一个或多个射频系数中不同的射频系数对应不同的第二设备。
- 根据权利要求51所述的第一设备,其中,所述指令还使所述第一设备执行:基于所述一个或多个射频系数中的第k个射频系数,向第k组第二设备中的每个第二设备发送所述多个信号,其中,所述一个或多个射频系数中不同的射频系数对应所述多个第二设备的不同分组、且所述多个第二设备的不同分组中包括不同的第二设备,所述第k组第二设备为所述多个第二设备的一个或多个分组中之一,k为正整数。
- 根据权利要求49-52任一项所述的第一设备,所述指令还使所述第一设备执行:基于所述多个信号的相关信息,得到多个第一量化结果;基于所述多个第一量化结果,生成所述第一组密钥。
- 根据权利要求53所述的第一设备,其中,所述指令还使所述第一设备执行:基于所述多个信号中第i个信号的相关信息,确定所述第i个信号对应的第一量化范围,将所述第一量化范围对应的第一量化值作为所述多个第一量化结果中的第i个第一量化结果,其中,所述第一量化范围为多个第一候选量化范围中之一,所述多个第一候选量化范围中每个第一候选量化范围具备对应的第一候选量化值,i为正整数。
- 根据权利要求53或54所述的第一设备,其中,所述多个信号的相关信息,包括以下至少之一:所述多个信号中每个信号的强度、所述每个信号的相位。
- 根据权利要求49-52任一项所述的第一设备,其中,所述多个信号的相关信息包括所述多个信号中每个信号携带的密钥序列;所述指令还使所述第一设备执行:基于所述多个信号中每个信号携带的密钥序列,生成所述第一组密钥。
- 根据权利要求56所述的第一设备,其中,所述多个信号中第j个信号携带一个或多个数据段,所述一个或多个数据段中不同的数据段为基于不同的第二设备的标识和第j个密钥序列计算的,j为正整数。
- 根据权利要求49-57任一项所述的第一设备,其中,所述多个信号用于所述每个第二设备生成第二组密钥;所述指令还使所述第一设备执行:基于所述第一组密钥,计算组密钥校验信息,其中,所述组密钥校验信息用于所述每个第二设备校验所述第二组密钥与所述第一组密钥的一致性;向所述每个第二设备发送第一消息,其中,所述第一消息携带所述组密钥校验信息。
- 根据权利要求58所述的第一设备,其中,所述指令还使所述第一设备执行以下之一:接收来自目标第二设备的第二消息,其中,所述第二消息用于指示所述目标第二设备对所述第二组密钥与所述第一组密钥的一致性校验成功,所述目标第二设备为所述多个第二设备中之一;接收来自所述目标第二设备的第三消息,其中,所述第三消息用于指示所述目标第二设备对所述第二组密钥与所述第一组密钥的一致性校验失败。
- 根据权利要求49-57任一项所述的第一设备,其中,所述多个信号用于所述每个第二设备生成第二组密钥;所述指令还使所述第一设备执行:基于所述第一组密钥,计算组密钥纠错信息,其中,所述组密钥纠错信息用于所述每个第二设备对所述第二组密钥纠错得到与所述第一组密钥一致的组密钥;向所述每个第二设备发送第四消息,其中,所述第四消息携带所述组密钥纠错信息。
- 根据权利要求49-60任一项所述的第一设备,其中,所述第一设备为以下之一:终端设备、网络设备;所述第二设备为零功耗设备。
- 一种目标第二设备,包括:处理器,与所述处理器通信的存储器,所述存储器用于存储指令,当所述指令被所述处理器执行时,所述指令使所述目标第二设备执行:接收来自第一设备的多个信号,其中,所述多个信号的射频系数为基于所述目标第二设备与所述第一设备间的信道特征计算得到的;基于所述多个信号的相关信息,生成第二组密钥,其中,所述第二组密钥用于所述目标第二设备与所述第一设备的通信,所述第二组密钥为多个第二设备相同的密钥、且所述目标第二设备为所述多个第二设备中之一。
- 根据权利要求62所述的目标第二设备,其中,所述指令还使所述目标第二设备执行:接收来自所述第一设备的组密钥生成信令;向所述第一设备发送导频信号,其中,所述导频信号为所述组密 钥生成信令所对应的反射信号,所述导频信号用于所述第一设备计算所述目标第二设备与所述第一设备间的信道特征。
- 根据权利要求62或63所述的目标第二设备,其中,所述指令还使所述目标第二设备执行:基于所述多个信号的相关信息,得到多个第二量化结果;基于所述多个第二量化结果,生成所述第二组密钥。
- 根据权利要求64所述的目标第二设备,其中,所述指令还使所述目标第二设备执行:基于所述多个信号中第i个信号的相关信息,确定所述第i个信号对应的第二量化范围,将所述第二量化范围对应的第二量化值作为所述多个第二量化结果中的第i个第二量化结果,其中,所述第二量化范围为多个第二候选量化范围中之一,所述多个第二候选量化范围中每个第二候选量化范围具备对应的第二候选量化值,i为正整数。
- 根据权利要求64或65所述的目标第二设备,其中,所述多个信号的相关信息,包括以下之一:所述多个信号中每个信号的强度、所述每个信号的相位。
- 根据权利要求62或63所述的目标第二设备,其中,所述多个信号的相关信息包括所述多个信号中每个信号携带的密钥序列;所述指令还使所述目标第二设备执行:基于所述多个信号中每个信号携带的密钥序列,生成所述第二组密钥。
- 根据权利要求67所述的目标第二设备,其中,所述多个信号中第j个信号携带一个或多个数据段,所述一个或多个数据段中不同的数据段为基于不同的第二设备的标识和第j个密钥序列计算的;所述指令还使所述目标第二设备执行:从所述第j个信号中,提取所述目标第二设备对应的目标数据段,j为正整数;基于所述目标第二设备的标识和所述目标数据段,计算所述第j个信号携带的第j个密钥序列。
- 根据权利要求62-68任一项所述的目标第二设备,其中,所述指令还使所述目标第二设备执行:接收来自所述第一设备的第一消息,其中,所述第一消息携带组密钥校验信息,所述组密钥校验信息为所述第一设备基于第一组密钥计算的,所述第一组密钥为所述第一设备基于所述多个信息生成的;基于所述第二组密钥计算验证信息;基于所述组密钥校验信息和所述验证信息,校验所述第二组密钥与所述第一组密钥的一致性。
- 根据权利要求69所述的目标第二设备,其中,所述指令还使所述目标第二设备执行以下至少之一:在所述第二组密钥与所述第一组密钥一致的情况下,向所述第一设备发送第二消息,其中,所述第二消息用于指示所述目标第二设备对所述第二组密钥与所述第一组密钥的一致性校验成功;在所述第二组密钥与所述第一组密钥不一致的情况下,向所述第一设备发送第三消息,其中,所述第三消息用于指示所述目标第二设备对所述第二组密钥与所述第一组密钥的一致性校验失败。
- 根据权利要求62-68任一项所述的目标第二设备,其中,所述指令还使所述目标第二设备执行:接收来自所述第一设备的第四消息,其中,所述第四消息携带组密钥纠错信息,所述组密钥纠错信息为所述第一设备基于第一组密钥计算的,所述第一组密钥为所述第一设备基于所述多个信息生成的;基于所述组密钥纠错信息对所述第二组密钥进行纠错,得到与所述第一组密钥一致的组密钥。
- 根据权利要求62-71任一项所述的目标第二设备,其中,所述第一设备为以下之一:终端设备、网络设备;所述目标第二设备为零功耗设备。
- 一种芯片,包括:处理器,用于从存储器中调用并运行计算机程序,使得安装有所述芯片的设备执行如权利要求1至13、或权利要求14至24中任一项所述的方法。
- 一种计算机可读存储介质,用于存储计算机程序,当所述计算机程序被设备运行时使得所述设备执行如权利要求1至13、或权利要求14至24中任一项所述的方法。
- 一种计算机程序产品,包括计算机程序指令,该计算机程序指令使得计算机执行如权利要求1至13、或权利要求14至24中任一项所述的方法。
- 一种计算机程序,所述计算机程序使得计算机执行如权利要求1至13、或权利要求14至24中任一项所述的方法。
Priority Applications (4)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202380098567.4A CN121241537A (zh) | 2023-05-26 | 2023-05-26 | 密钥生成方法和设备 |
| PCT/CN2023/096686 WO2024243748A1 (zh) | 2023-05-26 | 2023-05-26 | 密钥生成方法和设备 |
| EP23938747.5A EP4723541A1 (en) | 2023-05-26 | 2023-05-26 | Key generation method and device |
| US19/393,960 US20260075411A1 (en) | 2023-05-26 | 2025-11-19 | Key generation method, first device, and target second device |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/CN2023/096686 WO2024243748A1 (zh) | 2023-05-26 | 2023-05-26 | 密钥生成方法和设备 |
Related Child Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| US19/393,960 Continuation US20260075411A1 (en) | 2023-05-26 | 2025-11-19 | Key generation method, first device, and target second device |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2024243748A1 true WO2024243748A1 (zh) | 2024-12-05 |
Family
ID=93656219
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2023/096686 Ceased WO2024243748A1 (zh) | 2023-05-26 | 2023-05-26 | 密钥生成方法和设备 |
Country Status (4)
| Country | Link |
|---|---|
| US (1) | US20260075411A1 (zh) |
| EP (1) | EP4723541A1 (zh) |
| CN (1) | CN121241537A (zh) |
| WO (1) | WO2024243748A1 (zh) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN119545338A (zh) * | 2024-12-27 | 2025-02-28 | 甬江实验室 | 对称密钥生成方法、装置、设备、介质及产品 |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN103067042A (zh) * | 2012-12-14 | 2013-04-24 | 中国人民解放军信息工程大学 | 一种保密通信方法及天线设备 |
| US20140307871A1 (en) * | 2013-04-15 | 2014-10-16 | Electronics And Telecommunications Research Institute | Method for key establishment using anti-collision algorithm |
| CN105721142A (zh) * | 2016-01-25 | 2016-06-29 | 广东工业大学 | 基于标签id的rfid系统密钥生成方法及装置 |
| CN106603228A (zh) * | 2016-12-21 | 2017-04-26 | 广东工业大学 | 一种基于Rabin加密的RFID密钥无线生成方法 |
| CN116095677A (zh) * | 2021-11-08 | 2023-05-09 | 中国移动通信有限公司研究院 | 无线密钥生成方法、装置、设备及存储介质 |
-
2023
- 2023-05-26 WO PCT/CN2023/096686 patent/WO2024243748A1/zh not_active Ceased
- 2023-05-26 CN CN202380098567.4A patent/CN121241537A/zh active Pending
- 2023-05-26 EP EP23938747.5A patent/EP4723541A1/en active Pending
-
2025
- 2025-11-19 US US19/393,960 patent/US20260075411A1/en active Pending
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN103067042A (zh) * | 2012-12-14 | 2013-04-24 | 中国人民解放军信息工程大学 | 一种保密通信方法及天线设备 |
| US20140307871A1 (en) * | 2013-04-15 | 2014-10-16 | Electronics And Telecommunications Research Institute | Method for key establishment using anti-collision algorithm |
| CN105721142A (zh) * | 2016-01-25 | 2016-06-29 | 广东工业大学 | 基于标签id的rfid系统密钥生成方法及装置 |
| CN106603228A (zh) * | 2016-12-21 | 2017-04-26 | 广东工业大学 | 一种基于Rabin加密的RFID密钥无线生成方法 |
| CN116095677A (zh) * | 2021-11-08 | 2023-05-09 | 中国移动通信有限公司研究院 | 无线密钥生成方法、装置、设备及存储介质 |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN119545338A (zh) * | 2024-12-27 | 2025-02-28 | 甬江实验室 | 对称密钥生成方法、装置、设备、介质及产品 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN121241537A (zh) | 2025-12-30 |
| EP4723541A1 (en) | 2026-04-08 |
| US20260075411A1 (en) | 2026-03-12 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US7395427B2 (en) | Authenticated key exchange based on pairwise master key | |
| US20090169015A1 (en) | Quantum key distribution method, communication system, and communication device | |
| Kumar et al. | Key less physical layer security for wireless networks: A survey | |
| Rezki et al. | Ergodic secret message capacity of the wiretap channel with finite-rate feedback | |
| Li et al. | A safe approximation approach to secrecy outage design for MIMO wiretap channels | |
| TW201701683A (zh) | 無線設備的靈活配置和認證 | |
| Chorti et al. | Physical layer security: A paradigm shift in data confidentiality | |
| US20260075411A1 (en) | Key generation method, first device, and target second device | |
| Chatterjee et al. | Physically related functions: Exploiting related inputs of PUFs for authenticated-key exchange | |
| KR102054715B1 (ko) | 애드-혹 무선 네트워크에서 협력적 다중홉 라우팅을 위한 물리계층 보안 방법 및 시스템 | |
| Li et al. | Cache content placement optimization in non-orthogonal multiple access networks | |
| EP4597918A1 (en) | Method for carrying out user authentication by applying pre-shared key to basis selection in quantum communication system, and device therefor | |
| US8774410B1 (en) | Secret sharing in cryptographic devices via controlled release of plaintext information | |
| Al-Habob et al. | Multi-client file download time reduction from cloud/fog storage servers | |
| CN111246460B (zh) | 一种低复杂度和低时延的安全传输方法 | |
| Sakai et al. | Dynamic bit encoding for privacy protection against correlation attacks in RFID backward channel | |
| Sharma et al. | Deep learning-based authentication framework for secure terrestrial communications in next generation heterogeneous networks | |
| CN120266432A (zh) | 在环境物联网网络中使用物理层共享安全密钥进行无线安全通信的方法及相关设备 | |
| CN117750368A (zh) | 鉴权方法、装置、通信设备、存储介质和程序产品 | |
| Tsaloli et al. | WiP: Verifiable, secure and energy-efficient private data aggregation in wireless sensor networks | |
| Xu et al. | Maximum Zero-Outage Secrecy Capacity of Fading Wiretap Channels with Finite Alphabets | |
| US20260058820A1 (en) | Authentication methods | |
| WO2025007316A1 (zh) | 密钥生成方法和设备 | |
| US20260006012A1 (en) | Key generation method and device | |
| EP4716268A1 (en) | Authentication method and device |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 23938747 Country of ref document: EP Kind code of ref document: A1 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 202517129434 Country of ref document: IN |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2023938747 Country of ref document: EP |
|
| WWP | Wipo information: published in national office |
Ref document number: 202517129434 Country of ref document: IN |
|
| ENP | Entry into the national phase |
Ref document number: 2023938747 Country of ref document: EP Effective date: 20260102 |
|
| ENP | Entry into the national phase |
Ref document number: 2023938747 Country of ref document: EP Effective date: 20260102 |
|
| ENP | Entry into the national phase |
Ref document number: 2023938747 Country of ref document: EP Effective date: 20260102 |
|
| ENP | Entry into the national phase |
Ref document number: 2023938747 Country of ref document: EP Effective date: 20260102 |
|
| ENP | Entry into the national phase |
Ref document number: 2023938747 Country of ref document: EP Effective date: 20260102 |
|
| WWP | Wipo information: published in national office |
Ref document number: 2023938747 Country of ref document: EP |