WO2024243748A1 - 密钥生成方法和设备 - Google Patents

密钥生成方法和设备 Download PDF

Info

Publication number
WO2024243748A1
WO2024243748A1 PCT/CN2023/096686 CN2023096686W WO2024243748A1 WO 2024243748 A1 WO2024243748 A1 WO 2024243748A1 CN 2023096686 W CN2023096686 W CN 2023096686W WO 2024243748 A1 WO2024243748 A1 WO 2024243748A1
Authority
WO
WIPO (PCT)
Prior art keywords
group
target
keys
devices
signal
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2023/096686
Other languages
English (en)
French (fr)
Inventor
甘露
李猛
王慧明
赵斐斐
熊丽晖
石聪
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Guangdong Oppo Mobile Telecommunications Corp Ltd
Original Assignee
Guangdong Oppo Mobile Telecommunications Corp Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Guangdong Oppo Mobile Telecommunications Corp Ltd filed Critical Guangdong Oppo Mobile Telecommunications Corp Ltd
Priority to CN202380098567.4A priority Critical patent/CN121241537A/zh
Priority to PCT/CN2023/096686 priority patent/WO2024243748A1/zh
Priority to EP23938747.5A priority patent/EP4723541A1/en
Publication of WO2024243748A1 publication Critical patent/WO2024243748A1/zh
Priority to US19/393,960 priority patent/US20260075411A1/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L5/00Arrangements affording multiple use of the transmission path
    • H04L5/003Arrangements for allocating sub-channels of the transmission path
    • H04L5/0048Allocation of pilot signals, i.e. of signals known to the receiver
    • H04L5/0051Allocation of pilot signals, i.e. of signals known to the receiver of dedicated pilots, i.e. pilots destined for a single user or terminal
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04BTRANSMISSION
    • H04B7/00Radio transmission systems, i.e. using radiation field
    • H04B7/02Diversity systems; Multi-antenna system, i.e. transmission or reception using multiple antennas
    • H04B7/04Diversity systems; Multi-antenna system, i.e. transmission or reception using multiple antennas using two or more spaced independent antennas
    • H04B7/06Diversity systems; Multi-antenna system, i.e. transmission or reception using multiple antennas using two or more spaced independent antennas at the transmitting station
    • H04B7/0613Diversity systems; Multi-antenna system, i.e. transmission or reception using multiple antennas using two or more spaced independent antennas at the transmitting station using simultaneous transmission
    • H04B7/0615Diversity systems; Multi-antenna system, i.e. transmission or reception using multiple antennas using two or more spaced independent antennas at the transmitting station using simultaneous transmission of weighted versions of same signal
    • H04B7/0619Diversity systems; Multi-antenna system, i.e. transmission or reception using multiple antennas using two or more spaced independent antennas at the transmitting station using simultaneous transmission of weighted versions of same signal using feedback from receiving side
    • H04B7/0621Feedback content
    • H04B7/0626Channel coefficients, e.g. channel state information [CSI]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • H04W12/041Key generation or derivation

Definitions

  • the present application relates to the field of communications, and more specifically, to a key generation method, device, computer-readable storage medium, computer program product, and computer program.
  • contactless automatic identification technology With the development of communication technology, contactless automatic identification technology has emerged. This technology usually uses wireless radio frequency to perform contactless data transmission between zero-power devices and other devices (such as readers). Since the communication channel between zero-power devices and readers is an unsecured channel, in order to ensure the data transmission security of zero-power devices, it is further proposed that a key can be used between zero-power devices and readers to encrypt the data or information transmitted between the two.
  • the above scheme can only enable a single zero-power device and a reader to use the same key (or unicast key or shared key) to ensure the security of data transmission by a single zero-power device. In the scenario where there are multiple zero-power devices, how to enable the zero-power device to generate a group key in a less complex manner and ensure the security of the group key becomes a problem that needs to be solved.
  • Embodiments of the present application provide a key generation method, device, computer-readable storage medium, computer program product, and computer program.
  • the present invention provides a method for generating a key, including:
  • the first device sends a plurality of signals to each second device among a plurality of second devices, wherein radio frequency coefficients of the plurality of signals are calculated based on channel characteristics between each second device and the first device;
  • the first device generates a first set of keys based on relevant information of the multiple signals, where the first set of keys is used for communication between the first device and the multiple second devices.
  • the present invention provides a method for generating a key, including:
  • the target second device receives a plurality of signals from the first device, wherein radio frequency coefficients of the plurality of signals are calculated based on channel characteristics between the target second device and the first device;
  • the target second device generates a second set of keys based on relevant information of the multiple signals, wherein the second set of keys is used for communication between the target second device and the first device, the second set of keys are the same keys for multiple second devices, and the target second device is one of the multiple second devices.
  • the embodiment of the present application provides a first device, including:
  • a first communication unit configured to send a plurality of signals to each second device among a plurality of second devices, wherein radio frequency coefficients of the plurality of signals are calculated based on channel characteristics between each second device and the first device;
  • the first processing unit is configured to generate a first group of keys based on relevant information of the multiple signals, where the first group of keys is used for communication between the first device and the multiple second devices.
  • the embodiment of the present application provides a target second device, including:
  • a second communication unit configured to receive a plurality of signals from a first device, wherein radio frequency coefficients of the plurality of signals are calculated based on channel characteristics between the target second device and the first device;
  • a second processing unit is used to generate a second group of keys based on the relevant information of the multiple signals, wherein the second group of keys is used for communication between the target second device and the first device, the second group of keys are the same keys for multiple second devices, and the target second device is one of the multiple second devices.
  • An embodiment of the present application provides a first device, comprising: a processor, and a memory communicating with the processor, the memory being used to store instructions, and when the instructions are executed by the processor, the instructions cause the first device to execute: sending multiple signals to each second device among multiple second devices, wherein the radio frequency coefficients of the multiple signals are calculated based on channel characteristics between each second device and the first device; generating a first group of keys based on relevant information of the multiple signals, and the first group of keys is used for communication between the first device and the multiple second devices.
  • An embodiment of the present application provides a target second device, including: a processor, and a memory communicating with the processor, the memory being used to store instructions, and when the instructions are executed by the processor, the instructions cause the target second device to execute: receiving multiple signals from a first device, wherein radio frequency coefficients of the multiple signals are calculated based on channel characteristics between the target second device and the first device; generating a second group of keys based on relevant information of the multiple signals, wherein the second group of keys is used for communication between the target second device and the first device, the second group of keys are the same keys for multiple second devices, and the target second device is one of the multiple second devices.
  • the embodiment of the present application provides a chip for implementing the above method.
  • the chip includes: a processor, which is used to call and run a computer program from a memory, so that a device equipped with the chip executes the above method.
  • An embodiment of the present application provides a computer-readable storage medium for storing a computer program, which enables a device to perform the above method when the computer program is executed by the device.
  • An embodiment of the present application provides a computer program product, including computer program instructions, which enable a computer to execute the above method.
  • An embodiment of the present application provides a computer program, which, when executed on a computer, enables the computer to execute the above method.
  • the first device sends multiple signals to each second device, and the radio frequency coefficients of the multiple signals are calculated based on the channel characteristics between the second device and the first device, and then the first device itself will also generate a group key for communicating with each second device based on the relevant information of each signal.
  • the radio frequency coefficients corresponding to different second devices for the signals sent to different second devices, the channel characteristics between the second device and the first device can be accurately offset, that is, the loss or interference of the channel between the second device and the first device can be offset, and the group key can be generated based on only the relevant information of the signal, thereby ensuring that the complexity of generating the group key is reduced while also ensuring the security of the group key.
  • FIG. 1 is a schematic diagram of an application scenario according to an embodiment of the present application.
  • FIG2 is a schematic flowchart of a key generation method according to an embodiment of the present application.
  • FIG3 is a schematic flowchart of a key generation method according to another embodiment of the present application.
  • FIG4 is a schematic diagram of a scenario of a key generation method according to an embodiment of the present application.
  • FIG5 is a schematic flowchart of a key generation method according to an embodiment of the present application.
  • FIG6 is a schematic diagram of simulation results of a key generation method provided according to an embodiment of the present application.
  • FIG. 7 and 8 are two other schematic flow charts of a key generation method according to an embodiment of the present application.
  • FIG. 9 is a schematic block diagram of a first device according to an embodiment of the present application.
  • FIG. 10 is a schematic block diagram of a target second device according to an embodiment of the present application.
  • FIG11 is a schematic block diagram of a communication device according to an embodiment of the present application.
  • FIG. 12 is a schematic block diagram of a chip according to an embodiment of the present application.
  • FIG. 13 is a schematic block diagram of a communication system according to an embodiment of the present application.
  • the technical solutions of the embodiments of the present application can be applied to various communication systems, such as LTE, LTE-A, NR, NR evolution, WLAN, WiFi, or other communication systems.
  • the embodiments of the present application describe various embodiments in combination with network devices and terminals.
  • the terminal may be mobile or fixed, and the terminal may also be referred to as a mobile station, a user unit, etc.
  • the terminal may be a site in a WLAN, and may be a smart terminal, a wireless modem, a laptop computer, a tablet computer, or other terminals.
  • the terminal may be a VR terminal/AR terminal, an industrial control terminal, an unmanned driving terminal, a telemedicine terminal, a smart grid terminal, a transportation safety terminal, a smart city terminal, or a wireless terminal for a smart home, etc.
  • the terminal may also be a wearable device.
  • the network device may be a device for communicating with a terminal, the network device may be an access point in a WLAN, or an evolved base station in an LTE, or a relay station, or a vehicle-mounted device, a wearable device, and a network device (gNB) in an NR network, or a network device in a future evolved PLMN network, or a network device in a non-terrestrial network, etc.
  • the network device may have a mobile feature, for example, the network device may be a mobile device.
  • A indicates B, which can mean that A directly indicates B, for example, B can be obtained through A; it can also mean that A indirectly indicates B, for example, A indicates C, and B can be obtained through C; it can also mean that there is an association relationship between A and B.
  • the term "correspondence" can mean that there is a direct or indirect correspondence relationship between the two, or it can mean that there is an association relationship between the two, or it can mean that there is an indication and being indicated, configuration and being configured, etc.
  • FIG1 exemplarily shows a communication system 100.
  • the communication system includes a network device 110 and two terminals 120.
  • the communication system 100 may include multiple network devices 110, and each network device 110 may include other number of terminals 120 within its coverage area, which is not limited in the embodiment of the present application.
  • the communication system 100 may also include a mobility management entity, an access and mobility management function, and other network entities, which is not limited in the embodiment of the present application.
  • the network device may include an access network device and a core network device. That is, the communication system may also include multiple core networks for communicating with the access network device.
  • the access network device may be a base station of an LTE, LTE-A, or NR system.
  • the communication device may include a network device and a terminal with a communication function, and the communication device may also include other devices in the communication system, such as a network controller, a mobile management entity, and other network entities, which are not limited in the embodiment of the present application.
  • Fig. 2 is a schematic flow chart of a key generation method according to an embodiment of the present application. The method includes at least part of the following contents.
  • the first device sends a plurality of signals to each second device among a plurality of second devices, wherein radio frequency coefficients of the plurality of signals are calculated based on channel characteristics between each second device and the first device;
  • Fig. 3 is a schematic flow chart of a key generation method according to another embodiment of the present application. The method includes at least part of the following contents.
  • the target second device receives multiple signals from the first device, wherein the radio frequency coefficients of the multiple signals are calculated based on the channel characteristics between the target second device and the first device;
  • the target second device generates a second group of keys based on the relevant information of the multiple signals, wherein the second group of keys is used for communication between the target second device and the first device, the second group of keys is the same key for multiple second devices, and the target second device is one of the multiple second devices.
  • the first device is one of the following: a terminal device, a network device.
  • the first device may have one or more antennas.
  • the first device may have multiple antennas. It should be understood that the solution provided in this embodiment may also be applied to a first device having only one antenna, which is not limited here.
  • the first device is a terminal device.
  • the first device and the second device (any second device) can communicate with each other through side link messages.
  • the first device may be a network device.
  • the network device may be an access network device (such as a base station, gNB, eNB, etc.).
  • the first device and the second device may communicate via AS (Access Stratum) messages.
  • AS Access Stratum
  • the first device may be a network device, for example, the network device may be a core network device.
  • the first device and the second device may communicate via NAS (Non-Access Stratum) messages; or, in this embodiment, the first device and the second device may forward messages via an access network device.
  • NAS Non-Access Stratum
  • the core network side device includes at least one of the following: an authentication server function (AUSF), a unified data management function (UDM), and an ambient power-enabled IoT (AIoT) network element.
  • AUSF authentication server function
  • UDM unified data management function
  • AIoT ambient power-enabled IoT
  • the one or more core network devices may also include at least one of the following: ARPF (Authentication credential Repository and Processing Function), AMF (Access and Mobility Management Function), UPF (User Plane Function), SEAF (Security Anchor Function), etc. It should be understood that this is only an exemplary description. In actual processing, the core network side device may also include other core network devices, but they are not exhaustive here.
  • ARPF Authentication credential Repository and Processing Function
  • AMF Access and Mobility Management Function
  • UPF User Plane Function
  • SEAF Security Anchor Function
  • the above-mentioned AIOT network element may refer to a network element with AIOT function, or a network element with zero power consumption related functions;
  • the network element with AIoT function (or network element with zero power consumption related functions) may be a core network element with AIOT function (or with zero power consumption device related service energy supply), or a core network element serving AIOT function (or serving zero power consumption device), or a core network element with at least AIoT function (such as at least AIOT (or zero power consumption device) group key generation energy supply), etc.
  • AIOT network element may be a separately set network element specifically used to serve AIOT (or a network element specifically serving zero power consumption devices), or it may be an existing core network element to which AIOT related functions (or related functions serving zero power consumption devices) are added. This embodiment does not enumerate all possible situations.
  • the first device may be called a reader, or a reader, or a tag reader, or a tag reader/writer, etc. All possible names or possible devices of the first device are not exhaustively listed here.
  • the second device is a zero-power device.
  • the zero-power device may be an Ambient Power-enabled IoT (AIoT) device.
  • AIoT Ambient Power-enabled IoT
  • the zero-power device may be an active zero-power device, or a passive zero-power device, or a semi-passive zero-power device, etc.
  • the second device may also be a terminal with lower computing power.
  • the second device may be called a tag, and all possible names or possible devices of the second device are not exhaustively listed here.
  • the aforementioned multiple second devices may form a device group.
  • the target second device is also a zero-power device, and the target second device may be any one of the multiple second devices, that is, the target second device may be any second device in the device group formed by the multiple second devices.
  • the channel characteristics between each second device and the first device may be The second device is calculated before sending multiple signals.
  • the channel characteristics between each second device and the first device are first calculated.
  • the method also includes: the first device sends a group key generation signaling to each second device; the first device receives a pilot signal from each second device, wherein the pilot signal is a reflected signal corresponding to the group key generation signaling; the first device calculates the channel characteristics between each second device and the first device based on the pilot signal of each second device.
  • the channel characteristics between each second device and the first device can form a channel characteristic matrix.
  • the method further includes: the target second device receives the group key generation signaling from the first device; the target second device sends a pilot signal to the first device, wherein the pilot signal is a reflection signal corresponding to the group key generation signaling, and the pilot signal is used by the first device to calculate the channel characteristics between the target second device and the first device.
  • the target second device receives the group key generation signaling from the first device; the target second device sends a pilot signal to the first device, wherein the pilot signal is a reflection signal corresponding to the group key generation signaling, and the pilot signal is used by the first device to calculate the channel characteristics between the target second device and the first device.
  • the target second device is used for illustration here.
  • each of the plurality of second devices performs the same processing as the target second device. For the sake of brevity, this embodiment does not repeat the processing of each second device one by one.
  • the above channel characteristics can be used to indicate the transmission loss of the signal in the channel, and/or to indicate the transmission attenuation of the signal in the channel, etc.
  • the channel characteristics can include relevant parameters such as the noise of the channel, and all possible parameters that the channel characteristics may include are not exhaustively listed here.
  • the channel characteristics can refer to the channel and can also be alternatively called the channel estimation value, or alternatively called the channel estimation, etc., and all possible names thereof are not exhaustively listed here.
  • the function of the group key generation signaling may be used to trigger the second device to send a pilot signal. It should be understood that the group key generation signaling may also have other functions, but in this embodiment, the other functions of the group key generation signaling are not exhaustively listed and limited. In addition, the information content that may be carried by the group key generation signaling is not limited in this embodiment.
  • the aforementioned first device may have only one antenna.
  • the group of key generation signals is directly transmitted by the antenna.
  • the aforementioned first device may have multiple antennas, and the group key generation signaling may be sent through a designated antenna of the first device.
  • the designated antenna may be pre-configured or pre-set according to actual conditions.
  • the multiple antennas of the first device are arranged as the first antenna to the Mth antenna (M is an integer greater than or equal to 2) according to position or processing order or logical order or other order.
  • the designated antenna can be designated as the first antenna according to actual conditions, that is, the group key generation signaling can be transmitted by the first antenna of the first device; this is only an exemplary explanation. In actual processing, as long as any one of the designated M antennas sends the group key generation signaling, it is within the protection scope of this embodiment, and all possible situations are not enumerated here.
  • the group key generation signaling may be broadcast or multicast, that is, the first device broadcasts or multicasts the group key generation signaling to multiple second devices, so that each second device can receive the group key generation signaling.
  • the group key generation signaling may be unicast, that is, the first device sends the group key generation signaling to each second device respectively.
  • the target second device sending the pilot signal to the first device may be: the target second device modulates the pilot signal to the continuous carrier corresponding to the group key generation signaling and reflects it to the first device.
  • the continuous carrier corresponding to the group key generation signaling may refer to: the group key generation signaling is a continuous carrier, or the group key generation signaling is sent in the form of a continuous carrier, or the group key generation signaling is carried by a continuous carrier.
  • each of the aforementioned multiple second devices may send a pilot signal to the first device according to an anti-collision mechanism.
  • the anti-collision mechanism may be pre-configured in each second device.
  • the anti-collision mechanism may be a time slot anti-collision mechanism, a time unit anti-collision mechanism, a frequency domain anti-collision mechanism, and the like.
  • the anti-collision mechanism may enable each second device to determine a delay time unit after receiving a group key generation signaling, and the delay time unit is used for each second device to determine a sending time unit for sending a pilot signal, and the delay time units corresponding to different second devices may be the same or different.
  • the time unit may be any time unit such as a time slot, a symbol, a millisecond, a microsecond, and the like, which are not exhaustive here. It should also be pointed out that the above is only an exemplary description.
  • the anti-collision mechanism can also enable each second device to determine the sending frequency range of the pilot signal, and the sending frequency ranges corresponding to different second devices may be the same or different; in addition, the anti-collision mechanism can also enable each second device to determine the corresponding delay time unit and/or the sending frequency range of the pilot signal. As long as the pilot signals sent by different second devices can avoid mutual interference in the time domain and/or frequency domain, it is within the protection scope of this embodiment, and all possible contents of the anti-collision mechanism are not enumerated here.
  • the first device has multiple antennas.
  • the first device receiving the pilot signal from each second device may refer to the first device receiving the pilot signal from each second device through each antenna of the multiple antennas.
  • the first device calculating the channel characteristics between each second device and the first device based on the pilot signal of each second device refers to the first device calculating the channel characteristics between each second device and each antenna of the first device based on the pilot signal of each second device.
  • the first device receives the data from each of the plurality of antennas.
  • the pilot signal of the second device refers to that the first device receives the pilot signal from the target second device through each antenna of the multiple antennas.
  • the first device calculates the channel characteristics between each second device and each antenna of the first device based on the pilot signal of each second device, which means that the first device calculates the channel characteristics between the target second device and each antenna of the first device based on the pilot signal from the target second device received by each antenna of the multiple antennas.
  • the multiple second devices are multiple tags
  • the target second device is tag1 among the multiple tags
  • the first device is a reader
  • the reader has M antennas.
  • Each of the M antennas of the reader receives a pilot signal reflected by tag1, which can be expressed as: Wherein, ref is the tag reflection coefficient, and the specific value of ref is known at the reader end; s represents the pilot signal sent by the tag (for example, it can be a pilot signal whose content and/or format is known to both the reader and the tag).
  • n is equal to 1, that is, s represents the pilot signal sent by tag1
  • the reader can first send the aforementioned group key generation signaling through the first antenna (that is, the first antenna is the aforementioned designated antenna), and the pilot signal is modulated and reflected on the continuous carrier corresponding to the group key generation signaling. Therefore, the channel characteristics between the first antenna and the first tag will affect the pilot signal reflected by the first tag received by each antenna of the reader. Based on this, in the above formula, (i.e. the channel characteristics between the first antenna of the reader and the first tag) need to be consistent with each Multiply.
  • s can be a pilot signal with known content and/or format by both the reader and the tag, so the reader can calculate the channel characteristics between tag 1 and each antenna of the reader through the above formula, for example, it can be expressed as
  • the reader can perform the above processing on each tag. Finally, the reader can obtain the channel features between each tag and the reader. Then, the reader can form a channel feature matrix with the channel features between each tag and the reader. For example, it can be expressed in the following matrix form: Among them, H represents the channel characteristic matrix between each tag in all tags obtained by the reader and multiple antennas of the reader. The description is the same as that of the above-mentioned embodiment and will not be repeated.
  • the first device has multiple antennas.
  • the aforementioned first device has only one antenna.
  • the first device receiving the pilot signal from each of the second devices may refer to the first device receiving the pilot signal from each of the second devices through the antenna.
  • the second device taking the second device as a tag, the target second device as tag1 among multiple tags, the first device as a reader, and the first device having one antenna as an example, the one antenna of the reader receives the pilot signal reflected by tag1, which can be expressed as:
  • the descriptions of ref and s are the same as those in the above embodiment and will not be repeated here.
  • the first device calculates the channel characteristics between each second device and the first device based on the pilot signal of each second device, which may mean: the first device calculates the channel characteristics between each second device and an antenna of the first device based on the pilot signal of each second device; and then the first device can form a channel characteristic matrix with the channel characteristics between each second device and an antenna of the first device, for example, the channel characteristic matrix can be expressed as: Among them, H represents the channel feature matrix between each tag and the reader among all tags obtained by the reader. The description is the same as that of the above-mentioned embodiment and will not be repeated.
  • the first device can calculate the radio frequency coefficient.
  • the method also includes: the first device calculates one or more radio frequency coefficients based on the channel characteristics between each second device and the first device, wherein different radio frequency coefficients in the one or more radio frequency coefficients correspond to different second devices.
  • any RF coefficient may be to offset the corresponding channel characteristics (such as to offset the transmission attenuation or transmission loss of the signal in the channel, etc.), so that the signal transmitted to the corresponding second device on the channel is the same or substantially the same as the signal sent by the first device. All possible roles or functions of the RF coefficient are not exhaustively listed here.
  • the RF coefficient can also be called the antenna weight coefficient, or antenna coefficient, or antenna RF transmission coefficient, or RF transmission coefficient, or gain coefficient, or transmission weight coefficient, etc., and all possible names are not exhaustively listed here.
  • the plurality of second devices in the device group may be divided into one or more groups. Different radio frequency coefficients in the one or more radio frequency coefficients correspond to different groups of the plurality of second devices, and different groups of the plurality of second devices include different second devices.
  • the first device calculates the RF coefficient corresponding to each group (i.e., each group of second devices).
  • This embodiment does not limit whether the RF coefficients corresponding to different groups are the same.
  • any group, any group of second devices, any group of second devices, and any second device in a group all have the same meaning and will not be repeated. It should be noted that any group of second devices has a different meaning from a device group.
  • a device group (or multiple second devices in a device group) means all second devices in the device group, while any group of second devices is any group in the device group, or each second device in any group in the device group. That is, when the concept of group is involved in the following text, as long as it is not emphasized as a device group, it means a group (i.e., a group of second devices in a device group), and no repeated explanation will be given below.
  • the first device calculates one or more RF coefficients based on the channel characteristics between each second device and the first device. It can be: the first device forms a kth channel matrix based on the channel characteristics between each second device in the kth group of second devices and the first device, calculates the right inverse matrix of the kth channel matrix, and calculates the kth RF coefficient among the one or more RF coefficients based on the right inverse matrix of the kth channel matrix, and the kth RF coefficient corresponds to the kth group of second devices.
  • N and M in the formula are the same as those in the above embodiment and are not repeated here.
  • K represents the number of groups, and K is an integer greater than or equal to 1.
  • the number of the above one or more RF coefficients can be K, which is the same as the number of the above groups. That is, the kth RF coefficient can have a corresponding relationship with the kth group of second devices, and k is greater than or equal to 1 and less than or equal to K.
  • the first device forms the kth group of channel matrices based on the channel characteristics between each second device in the kth group of second devices and the first device. This can be achieved by extracting the channel characteristics corresponding to each second device in the kth group of second devices in the channel characteristic matrix between each second device and the first device to form the kth group of channel matrices.
  • the kth group of channel matrices may include: channel characteristics of the (k-1)M+1th second device to the (k-1)M+Mth second device.
  • the k-th group of channel matrices can be expressed as (1 ⁇ k ⁇ K):
  • H(x) represents the x-th row in H (channel feature matrix).
  • x is equal to (k-1)M+1, it is the (k-1)M+1-th row in H, that is, the channel feature corresponding to the (k-1)M+1-th second device.
  • x is equal to (k-1)M+M, it is the (k-1)M+M-th row in H, that is, the channel feature corresponding to the (k-1)M+M-th second device.
  • the right inverse matrix of the k-th group of channel matrix can be calculated using the following formula: in, represents the right inverse matrix of the k-th group channel matrix, H k represents the k-th group channel matrix, and H k H represents the transposed matrix of the k-th group channel matrix.
  • the calculating of the kth RF coefficient among the one or more RF coefficients based on the right inverse matrix of the kth group of channel matrix may refer to: adding all columns of the right inverse matrix of the kth group of channel matrix to obtain the kth RF coefficient among the one or more RF coefficients.
  • obtaining the kth RF coefficient may be expressed by the following formula: Among them, w k represents the kth RF coefficient, sum_column() represents the matrix Add all the columns of .
  • the first device sends multiple signals to each second device in a plurality of second devices, which may refer to: the first device sends the multiple signals to each second device in the kth group of second devices based on the kth RF coefficient in the one or more RF coefficients, wherein different RF coefficients in the one or more RF coefficients correspond to different groups of the multiple second devices, and different groups of the multiple second devices include different second devices, and the kth group of second devices is one of the one or more groups of the multiple second devices, and k is a positive integer.
  • the first device sequentially uses the RF coefficients corresponding to each second device group in the K groups of second devices for the i-th signal in the multiple signals, and sends the i-th signal to each group of second devices in turn, and i is a positive integer.
  • i is a positive integer.
  • the first device When the first device generates the i-th signal among the multiple signals, it sequentially uses the RF coefficients corresponding to each group of second devices in the K groups of second devices to send the i-th signal to each group of second devices.
  • the first device when it generates the i+1-th signal among the multiple signals, it also sequentially uses the RF coefficients corresponding to each group of second devices in the K groups of second devices to send the i+1-th signal to each group of second devices. That is, the i-th signal will be sent K times on the first device side, and different times will be sent to each second device in different groups, so that each second device can receive the same i-th signal; accordingly, the i-th signal is received once on any second device side.
  • the i-th signal received by tagn can be expressed as riHkwk , where ri is the i-th signal, and the meaning of other contents is the same as the above-mentioned embodiment; since Hk can be offset by the RF coefficient wk , the signal received at tagn should be ri , that is, 6, where Ik_n ⁇ 1 represents a unit vector of k_n rows and 1 columns, and k_n represents the number of rows of Hk , that is, the number of tags in the k-th group of tags, that is, all tags (each tag) in the k-th group of tags will receive ri .
  • the first device does not need to repeatedly perform the aforementioned first device sending a group key generation signaling to each second device to calculate the channel characteristics between each second device and the first device, and calculate the RF coefficient corresponding to each group of second devices. That is, after the first device calculates each RF coefficient, it can perform the process of sending multiple signals to the second devices in each group of second devices, and use the same RF coefficient to send different signals among the multiple signals to the second devices in the same group.
  • the first device can repeat the above process. For example, if the process of sending the i-th signal is to be executed, the first device needs to execute the process of sending a group key generation signaling to each second device to calculate the channel characteristics between each second device and the first device, and calculate the RF coefficient corresponding to each group of second devices (that is, each RF coefficient), and then send the i-th signal to each group of second devices based on the RF coefficient corresponding to each group of second devices; if the process of sending the i+1-th signal is to be executed, the first device again executes the process of sending a group key generation signaling to each second device to calculate the channel characteristics between each second device and the first device, and calculate the RF coefficient corresponding to each group of second devices, and then send the i+1-th signal to each group of second devices based on the RF coefficient corresponding to each group of second devices.
  • the first device can also determine when to repeat the process of sending group key generation signaling to each second device to calculate the channel characteristics between each second device and the first device, and calculate the RF coefficient corresponding to each group of second devices according to the specific coherence time.
  • a signals (A can be an integer greater than or equal to 1) can be sent to each group of second devices within the coherence time. After completing the sending of the 1st to Ath signals and before sending the A+1th signal to each group of second devices, the process of sending group key generation signaling to each group of second devices to calculate the channel characteristics between each second device and the first device and calculate the RF coefficient corresponding to each group of second devices is performed again.
  • the A+1th signal is sent to each group of second devices.
  • the next cycle is repeated by analogy.
  • the aforementioned process of calculating each RF coefficient is performed again. And so on and so forth.
  • the coherence time is longer or shorter, which can be determined based on a preset duration threshold value. For example, when the coherence time is greater than the duration threshold value, the coherence time is longer, that is, the channel environment is in a static environment. When the coherence time is less than or equal to the duration threshold value, the coherence time is shorter, that is, the channel environment is time-varying.
  • the duration threshold value can be configured according to actual conditions, for example, it can be related to the number of second devices actually included in the device group, and/or to the duration required to send a signal, etc. All possible parameters for determining the duration threshold value and the determination method thereof are not limited here.
  • coherence time may also be referred to as coherence duration, and the coherence time may be determined based on actual conditions.
  • This embodiment does not limit the method of obtaining or determining the coherence time. As long as the coherence time can be obtained in advance on the first device side before executing all the solutions provided by this embodiment, it is within the protection scope of this embodiment.
  • the first device calculates a radio frequency coefficient corresponding to each second device. Whether the radio frequency coefficients corresponding to different second devices are the same is not limited in this embodiment.
  • the first device may be to obtain the right inverse matrix of the channel characteristics between the target second device and the first device, and calculate the RF coefficient corresponding to the target second device based on the right inverse matrix.
  • Calculating the RF coefficient corresponding to the target second device based on the right inverse matrix may refer to: adding all columns of the right inverse matrix to obtain the RF coefficient corresponding to the target second device.
  • the right inverse matrix of the channel characteristics between tagn and the first device can be calculated using the following formula: Where n represents the tag number or sequence number. In this example, n can be equal to 1. represents the right inverse matrix, Hn represents the channel feature matrix between the nth tag and the reader, and HnH represents the transposed matrix of the channel feature matrix between the nth tag and the reader. Taking the above specific value of n as 1 as an example, that is, the channel feature between tag1 and the reader can be expressed as H1 . or, The meanings of the various contents included in the above formula are the same as those in the above embodiment and will not be elaborated on again.
  • w n represents the RF coefficient corresponding to tagn
  • sum_column() represents the matrix Add all the columns of .
  • the first device sends multiple signals to each second device among multiple second devices, which may mean that the first device uses the RF coefficients corresponding to each second device in turn for the i-th signal among the multiple signals, and sends the i-th signal to each second device in turn, where i is a positive integer.
  • N is an integer greater than or equal to 2
  • the first device uses the RF coefficients corresponding to each second device among the N second devices in turn to send the i-th signal to each second device;
  • the first device when the first device generates the i+1-th signal among the multiple signals, it also uses the RF coefficients corresponding to each second device among the N second devices in turn to send the i+1-th signal to each second device. That is, the i-th signal will be sent N times on the first device side, and different times will be sent to different second devices, so that each second device can receive the same i-th signal; accordingly, the i-th signal is received once on any second device side.
  • the first device does not need to repeatedly perform the aforementioned first device sending a group key generation signaling to each second device to calculate the channel characteristics between each second device and the first device, and calculate the RF coefficient corresponding to each second device. That is, after the first device calculates the RF coefficient corresponding to each second device, it can perform the process of sending multiple signals to each second device among the multiple second devices, and use the same RF coefficient to send different signals among the multiple signals to the same second device.
  • the first device can repeat the above process. For example, if the process of sending the i-th signal is to be executed, the first device needs to execute the process of sending a group key generation signaling to each second device to calculate the channel characteristics between each second device and the first device, and calculate the RF coefficient corresponding to each second device, and then send the i-th signal to each second device based on the RF coefficient corresponding to each second device; if the process of sending the i+1-th signal is to be executed, the first device again executes the process of sending a group key generation signaling to each second device to calculate the channel characteristics between each second device and the first device, and calculate the RF coefficient corresponding to each second device, and then send the i+1-th signal to each second device based on the RF coefficient corresponding to each second device.
  • the first device can also determine when to repeat the process of sending group key generation signaling to each second device to calculate the channel characteristics between each second device and the first device, and calculate the corresponding RF coefficient of each second device according to the specific coherence time.
  • B signals (B can be an integer greater than or equal to 1) can be sent to each second device within the coherence time.
  • the process of sending group key generation signaling to each second device to calculate the channel characteristics between each second device and the first device, and calculate the corresponding RF coefficient of each second device is performed again.
  • the A+1th signal is sent to each second device.
  • the next cycle is repeated by analogy and will not be repeated.
  • the first device generates a first group of keys based on relevant information of the multiple signals, including: the first device obtains multiple first quantization results based on relevant information of the multiple signals; the first device generates the first group of keys based on the multiple first quantization results.
  • the first device may send the i-th signal to different second devices based on the radio frequency coefficients of different second devices.
  • the i-th signal may be sent to each second device of different groups based on the RF coefficients corresponding to different groups.
  • the number of times the i-th signal is sent depends on the number of second devices or the number of groups.
  • the first device itself can obtain relevant information of the i-th signal, that is, the first device itself can obtain relevant information of each signal.
  • the first device obtains multiple first quantization results based on the relevant information of the multiple signals, including: the first device determines the first quantization range corresponding to the i-th signal based on the relevant information of the i-th signal among the multiple signals, and uses the first quantization value corresponding to the first quantization range as the i-th first quantization result among the multiple first quantization results, wherein the first quantization range is one of multiple first candidate quantization ranges, each of the multiple first candidate quantization ranges has a corresponding first candidate quantization value, and i is a positive integer.
  • the first device performs the same processing as the i-th signal on each signal, and finally obtains multiple quantization results.
  • This embodiment is described in detail with the i-th signal, and each signal is not described one by one.
  • the processing of the first device may also include: the first device may determine the maximum and minimum values of the relevant information value range based on the relevant information of multiple signals; based on the quantization order Q, divide the relevant information value range into Q first candidate quantization ranges, and determine the first candidate quantization value corresponding to each first candidate quantization range in the Q first candidate quantization ranges, where Q is an integer greater than or equal to 2.
  • the quantization order Q can be set according to actual conditions, for example, it can be 16, 32, 8, 4, 5, 21 or larger or smaller, and all possible values of Q are not exhaustively listed here.
  • the first candidate quantization value corresponding to each of the above-mentioned first candidate quantization ranges can be set according to actual conditions, any first candidate quantization value can be binary, and the length of the first candidate quantization value can be related to the quantization order, for example, the length of the first candidate quantization value can be equal to log 2 Q bits.
  • the first candidate quantization value can be a Gray code with a length of log 2 Q.
  • the first device determines the first quantization range corresponding to the i-th signal based on the relevant information of the i-th signal among the multiple signals, and uses the first quantization value corresponding to the first quantization range as the i-th first quantization result among the multiple first quantization results, which may mean that the first device determines the relevant information of the i-th signal among the multiple signals, the first quantization range corresponding to the Q first candidate quantization ranges, and uses the first quantization value corresponding to the first quantization range as the i-th first quantization result among the multiple first quantization results.
  • the aforementioned determination of the Q first candidate quantization ranges and the first candidate quantization value corresponding to each first candidate quantization range can be performed only once, and then the quantization result corresponding to the relevant information of each signal can be determined respectively based on the aforementioned Q first candidate quantization ranges and the first candidate quantization value corresponding to each first candidate quantization range, which will not be described one by one here.
  • the first device in order to reduce the differences in quantization results caused by small errors on the left and right of the quantization boundary, can also round the relevant information of all acquired signals to the nearest integer, and then determine the aforementioned Q first candidate quantization ranges, and the first candidate quantization value corresponding to each first candidate quantization range; and/or, when quantizing each signal, the relevant information of each signal can also be rounded to the nearest integer and then quantized.
  • the aforementioned embodiment is only an exemplary description of quantizing the related information of multiple signals.
  • the quantization method that can be used in this embodiment may not be limited to the method described herein.
  • the singular value decomposition method or other quantization methods may also be used. This embodiment does not limit or exhaustively list them.
  • the related information of the multiple signals includes at least one of the following: the strength of each signal in the multiple signals, and the phase of each signal.
  • each signal may alternatively be described as the amplitude of each signal.
  • the relevant information of the aforementioned multiple signals includes the strength of each signal.
  • the processing of the first device may also include: the first device determines the maximum value (P max ) and the minimum value (P min ) of the strength value range of all signals (i.e., the value range of P) based on the strength P of each signal, that is, P min ⁇ P ⁇ P max ; then based on the quantization order Q, the value range of P is divided into Q first candidate quantization ranges, and the Gray code corresponding to each first candidate quantization range in the Q first candidate quantization ranges is determined to have a length of log 2 Q.
  • the first device may also round the strength P of all acquired signals to the nearest integer, and then determine the aforementioned Q first candidate quantization ranges and the first candidate quantization value corresponding to each first candidate quantization range; and/or, when quantizing each signal, the strength P of each signal may also be rounded to the nearest integer, and then quantized.
  • the Q first candidate quantization ranges may also be referred to as Q first candidate intensity quantization ranges.
  • the first device when it sends each signal, it may send a related value of the strength of each signal, such as the square root of the signal's strength, or the original value of the signal's strength, or multiple roots of the signal's strength, etc., and all possible situations are not enumerated here.
  • the relevant information of the aforementioned multiple signals includes the phase of each signal.
  • the processing of the first device may also include: the first device based on the phase of each signal Determine the phase value range of all signals (i.e. The maximum value of the range of and minimum value That is Then based on the quantization order Q, The value range of is divided into Q first candidate quantization ranges, and the length corresponding to each first candidate quantization range in the Q first candidate quantization ranges is determined to be log 2 Q Gray code.
  • the first device can also perform phase Rounding to the nearest integer, and then determining the aforementioned Q first candidate quantization ranges and the first candidate quantization value corresponding to each first candidate quantization range; and/or, when quantizing each signal, the phase of each signal may also be Round to the nearest integer and then perform quantization.
  • the Q first candidate quantization ranges may also be referred to as Q first candidate phase quantization ranges.
  • the intensity and phase of each signal can be used in combination.
  • Q first candidate intensity quantization ranges and Q first candidate phase quantization ranges can be obtained, and then the qth first candidate intensity quantization range and the qth first candidate phase quantization range correspond to the same quantization value, where q is an integer greater than or equal to 1 and less than or equal to Q, or q is an integer greater than or equal to 0 and less than or equal to Q-1.
  • the corresponding first quantization range can be determined according to any one of the intensity and phase of the i-th signal, and then the quantization result can be determined.
  • the first intensity quantization range and the first phase quantization range corresponding to the intensity and phase of the i-th signal can be used. If the two are consistent, the first quantization value corresponding to any one of the first quantization ranges is determined as the quantization result. If the two are inconsistent, any one of them can be specified as the standard, such as uniformly specifying the intensity of the signal as the standard. All possible examples are not exhaustively listed here.
  • the first device generates the first group of keys based on the multiple first quantization results, which may be: the first device merges the multiple first quantization results based on a specified order to obtain the first group of keys.
  • the designated order can be set according to actual conditions.
  • the designated order can be a positive order, that is, the first group of keys can be "the first first quantization result, the second first quantization result... the last first quantization result” and then merged.
  • the designated order can be a reverse order, that is, the first group of keys can be "the last first quantization result, the second to last first quantization result... the first first quantization result” and then merged.
  • the designated order can be disordered, for example, there are 4 first quantization results in total, and the designated order can be 2, 4, 3, 1, that is, the first group of keys can be "the second first quantization result, the fourth first quantization result, the third first quantization result, the first first quantization result" and then merged.
  • the designated order can be set according to actual conditions, and it is not exhaustive here. It should be understood that the above is only an exemplary description. As long as each second device and the first device adopt the same designated order, it is within the protection scope of this embodiment.
  • the first device generates the first group of keys based on the multiple first quantization results, which may be: the first device calculates the first group of keys on the multiple first quantization results based on a preset calculation method.
  • the preset calculation method can be set according to the actual situation, for example, it can be any one or more combinations of XOR calculation, direct calculation, function, etc.
  • XOR calculation can be used, that is, all the first quantization results are XORed to obtain the first group of keys.
  • function calculation can be used, such as the function is a key derivation function (KDF, Key Derivation Function), then multiple first quantization results can be used as inputs of KDF, and the first group of keys can be obtained by KDF calculation.
  • KDF Key Derivation Function
  • the target second device generates a second set of keys based on relevant information of the multiple signals, including: the target second device obtains multiple second quantization results based on the relevant information of the multiple signals; the target second device generates the second set of keys based on the multiple second quantization results.
  • the target second device is any one of all the second devices in the device group, and the processing of each second device in the device group is the same as that of the target second device, so it will not be described one by one here.
  • the group key generated by the target second device is called the second group key.
  • the target second device generates the second group key based on the received multiple signals, which is different from the execution subject of the first device. It may make the group key obtained by the target second device and the first device the same or different. Further verification is required to determine whether the second group key generated by the target second device is the same as the first group key generated by the first device. Therefore, this embodiment distinguishes between the group key generated by the target second device (that is, any second device) and the group key generated by the first device. It should be understood that, ideally, the group key generated by the target second device (that is, any second device) and the group key generated by the first device should be the same, that is, ideally, the first group key can be equal to the second group key.
  • the target second device obtains multiple second quantization results based on the relevant information of the multiple signals, including: the target second device determines the second quantization range corresponding to the i-th signal based on the relevant information of the i-th signal among the multiple signals, and uses the second quantization value corresponding to the second quantization range as the i-th second quantization result among the multiple second quantization results, wherein the second quantization range is one of multiple second candidate quantization ranges, each second candidate quantization range in the multiple second candidate quantization ranges has a corresponding second candidate quantization value, and i is a positive integer.
  • the target second device performs the same processing as the i-th signal for each signal, and finally obtains multiple quantization results. This embodiment is illustrated with the i-th signal, and each signal is not described one by one.
  • the processing of the target second device may further include: the target second device may determine the maximum value and the minimum value of the relevant information value range based on the relevant information of the multiple signals; based on the quantization order Q, divide the relevant information value range into Q second candidate quantization ranges are provided, and a second candidate quantization value corresponding to each second candidate quantization range in the Q second candidate quantization ranges is determined, where Q is an integer greater than or equal to 2.
  • the specific processing method for the target second device to determine Q second candidate quantization ranges and determine the second candidate quantization value corresponding to each of the Q second candidate quantization ranges is the same as the specific processing method for the aforementioned first device to determine Q first candidate quantization ranges and determine the first candidate quantization value corresponding to each of the Q first candidate quantization ranges, so it is not repeated.
  • the target second device determines the second quantization range corresponding to the i-th signal based on the relevant information of the i-th signal among the multiple signals, and uses the second quantization value corresponding to the second quantization range as the i-th second quantization result among the multiple second quantization results, which may mean: the target second device determines the relevant information of the i-th signal among the multiple signals, and uses the second quantization range corresponding to the Q second quantization ranges, and uses the second quantization value corresponding to the second quantization range as the i-th second quantization result among the multiple second quantization results.
  • the processing of the target second device obtaining the i-th second quantization result is also the same as the way in which the aforementioned first device obtains the i-th first quantization result, and will not be elaborated on.
  • the relevant information of the multiple signals also includes at least one of the following: the strength of each signal in the multiple signals, and the phase of each signal.
  • the relevant information of the signal is the strength and/or phase
  • the specific description of the target second device determining Q second candidate quantization ranges and the second candidate quantization value corresponding to each second candidate quantization range is similar to the specific description of the aforementioned first device determining Q first candidate quantization ranges and the first candidate quantization value corresponding to each first candidate quantization range, and will not be repeated.
  • the target second device when the relevant information of the signal is the strength of the signal, when the target second device receives each signal, it may be a relevant value of the strength of each signal, for example, it may be the square root of the signal strength, or the original value of the signal strength, or multiple power values of the signal strength, etc., and all possible situations are not enumerated here; accordingly, the target second device may be the square, or the original value, or multiple power values of the relevant value of the strength of each signal, and then determine Q second candidate quantization ranges and the second candidate quantization value corresponding to each second candidate quantization range.
  • the specific processing of determining the Q second candidate quantization ranges and the second candidate quantization value corresponding to each second candidate quantization range is not elaborated here.
  • the target second device generates the second group of keys based on the multiple second quantization results, which can be: the target second device merges the multiple second quantization results based on a specified order to obtain the second group of keys.
  • the description of the specified order and the specific merging process are the same as the process of the first device merging the multiple first quantization results based on the specified order to obtain the first group of keys, and will not be repeated.
  • the target second device generates the second group of keys based on the multiple second quantization results, which can be: the target second device calculates the second group of keys based on the multiple second quantization results based on a preset calculation method.
  • the specific description of the preset calculation method is the same as the relevant description of the first device, and will not be repeated.
  • the first device and each second device need to respectively generate their own group keys in the same manner, which will not be repeated here.
  • the relevant information of the multiple signals includes a key sequence carried by each of the multiple signals; the first device generates a first group of keys based on the relevant information of the multiple signals, including: the first device generates the first group of keys based on the key sequence carried by each of the multiple signals.
  • the key sequences carried by different signals may be randomly generated by the first device. This embodiment does not limit the manner in which the first device generates each key sequence.
  • the jth signal among the multiple signals carries one or more data segments, different data segments among the one or more data segments are calculated based on identifications of different second devices and the jth key sequence, and j is a positive integer.
  • the plurality of signals refers to a plurality of signals sent to each second device.
  • the first device may send a signal to each second device based on the radio frequency coefficient corresponding to each second device, that is, the same signal content will be sent to each second device separately in this case, and eventually sent multiple times.
  • the first device wants to send a signal with the content of the jth key sequence, it needs to be sent to N second devices respectively.
  • the value of N is defined in the same way as in the above embodiment and will not be described in detail.
  • the jth signal sent to the nth second device can carry a data segment, which is calculated based on the identifier of the nth second device and the jth key sequence; and by analogy, the jth signal sent to the n+1th second device can carry a data segment, which is calculated based on the identifier of the n+1th second device and the jth key sequence. This is not exhaustive.
  • the calculation method can be set according to the actual situation, such as direct calculation, XOR calculation, function calculation or one or more methods.
  • the calculation method is XOR calculation
  • the j-th signal sent to the n-th second device is represented as r jn .
  • the frame structure of r jn (that is, the data segment of r jn ) is designed as: in, represents the XOR operation, represents the ID number of the nth tag, and kj is the jth key sequence randomly generated by the reader.
  • the first device may send a signal to each second device in each group of second devices based on the radio frequency coefficient corresponding to each group of second devices, that is, the same signal content will be sent multiple times in groups in this case.
  • the first device wants to send a signal with the content of the jth key sequence, it needs to be sent to K groups of second devices respectively, that is, sent K times.
  • the value definition of K is the same as that in the previous embodiment and is not elaborated on.
  • the jth signal sent to the kth group of second devices can carry one or more data segments, wherein the number of data segments depends on the number of second devices included in the kth group of second devices; the one or more data segments are calculated based on the identifier of each second device in the kth group of second devices and the jth key sequence.
  • the jth signal sent to the k+1th group of second devices can also carry one or more data segments, wherein the number of data segments depends on the number of second devices included in the k+1th group of second devices; the one or more data segments are calculated based on the identifier of each second device in the k+1th group of second devices and the jth key sequence, and so on, and are not elaborated on one by one.
  • the calculation method is the same as that in the above example and is not described in detail.
  • the calculation method is XOR calculation, and different data segments are calculated based on the identifiers of different second devices and the jth key sequence. It can mean that the data segment corresponding to each second device in the kth group of second devices is obtained by XOR calculation using the identifier of each second device and the jth key sequence.
  • the jth signal corresponding to the kth group of second devices can be expressed as rjk , and the frame structure of rjk (that is, one or more data segments of rjk ) is designed as: in, represents the XOR operation, represents the ID number (i.e., identification) of the nth tag in the kth group of tags, and kj is the jth key sequence randomly generated by the reader.
  • the first device generates the first group of keys based on the key sequence carried by each signal in the multiple signals, which may mean that the first device combines the key sequence carried by each signal based on a specified order to obtain the first group of keys.
  • the specified order may be the same as that in the above embodiment and will not be described in detail.
  • the first device generates the first group of keys based on the key sequence carried by each of the multiple signals, which may mean that the first device calculates the first group of keys based on the key sequence carried by each signal based on a preset calculation method.
  • the preset calculation method may be the same as that in the above embodiment, and will not be described in detail.
  • the relevant information of the multiple signals includes a key sequence carried by each of the multiple signals; the target second device generates a second set of keys based on the relevant information of the multiple signals, including: the target second device generates the second set of keys based on the key sequence carried by each of the multiple signals.
  • the jth signal carries one or more data segments, and different data segments among the one or more data segments are calculated based on the identification of different second devices and the jth key sequence; the method further includes: the target second device extracts the target data segment corresponding to the target second device from the jth signal, where j is a positive integer; the target second device calculates the jth key sequence carried by the jth signal based on the identification of the target second device and the target data segment.
  • the calculation method should be the same as that of the first device, and no repetitive description is given here.
  • the calculation method is XOR calculation
  • the target second device is the n-th tag
  • the extracted data segment can be Then the nth tag uses its own ID to perform XOR with the above data segment again to obtain k j (the jth key sequence).
  • k j the jth key sequence
  • the first device may send a signal to each second device in each group of second devices based on the RF coefficients corresponding to each group of second devices.
  • the target second device if the target second device is one of the second devices in the kth group, the target second device will only receive the jth signal (i.e., the signal carrying the jth key sequence) sent by the first device for the kth time.
  • the jth signal sent for the kth time may carry one or more data segments.
  • the target second device may directly extract the data segment corresponding to itself from the jth signal as the target data segment, and then calculate based on its own identification and the target data segment to obtain the jth key sequence.
  • the position of the data segment corresponding to the target second device can be set according to actual conditions.
  • the target second device is the nth second device in the kth group of second devices
  • the position of the corresponding data segment can be the nth position, or it can also be other specified positions.
  • This embodiment does not limit it. As long as the positions of the data segments corresponding to different second devices in the kth group of second devices are different, it is within the protection scope of this embodiment.
  • the calculation method is XOR calculation.
  • the jth signal corresponding to the kth group of second devices can be expressed as r jk .
  • the frame structure of r jk (that is, one or more data segments of r jk ) is: Assuming that the target second device is the nth tag and the position of its corresponding data segment is the nth position, the nth data segment can be extracted from r jk , that is, As the target data segment, then based on its own identification and By performing XOR calculation again, k j (the jth key sequence) can be obtained.
  • the meaning of each content in the above expression is the same as that in the previous example and will not be repeated here.
  • the multiple signals are used to generate a second group of keys for each second device, and the method further includes: the first device calculates group key verification information based on the first group of keys, wherein the group key verification information is used by each second device to verify the consistency of the second group of keys with the first group of keys; and the first device sends a first message to each second device, wherein the first message carries the group key verification information.
  • the method also includes: the target second device receives a first message from the first device, wherein the first message carries group key verification information, the group key verification information is calculated by the first device based on the first group key, and the first group key is generated by the first device based on the multiple information; the target second device calculates verification information based on the second group key; the target second device verifies the consistency of the second group key with the first group key based on the group key verification information and the verification information.
  • the first device may also initiate a verification process to determine whether the second group key generated by each second device is the same as its own first group key.
  • the first device calculates the group key verification information based on the first group key, which can be: the first device maps the first group key through a first preset function to obtain a first value, and uses the first value as the group key verification information.
  • the first preset function can be a hash function, and the specific algorithm used by the hash function can be set according to actual conditions, and this embodiment does not limit it.
  • the first preset function can also be other types of functions, as long as the corresponding mapping value can be obtained through the function, it is within the protection scope of this embodiment.
  • the first device calculates the group key verification information based on the first group key, which can be: the first device calculates a cyclic redundancy check (CRC) code of the first group key, and uses the CRC (code) as the group key verification information.
  • CRC cyclic redundancy check
  • the specific algorithm used for the CRC calculation can be set according to actual conditions, and this embodiment does not limit it.
  • the manner in which the first device sends the first message to each of the second devices may be multicast, broadcast or unicast, all of which are within the protection scope of this embodiment.
  • the first device may broadcast the first message to all second devices.
  • the target second device calculates the verification information based on the second group of keys, which can be: the target second device maps the second group of keys through a first preset function to obtain a second value, and uses the second value as the verification information.
  • the first preset function is the same as the above embodiment and is not described in detail.
  • the target second device calculates verification information based on the second group of keys, which may be: the target second device calculates a cyclic redundancy check (CRC) code of the second group of keys, and uses the CRC (code) of the second group of keys as verification information.
  • CRC cyclic redundancy check
  • the specific processing method of calculating the verification information by the target second device should be the same as the method of verifying the information based on the group key by the first device.
  • the method also includes at least one of the following: when the second group of keys of the target second device is consistent with the first group of keys, the target second device sends a second message to the first device, wherein the second message is used to indicate that the target second device has successfully verified the consistency of the second group of keys with the first group of keys; when the second group of keys of the target second device is inconsistent with the first group of keys, the target second device sends a third message to the first device, wherein the third message is used to indicate that the target second device has failed to verify the consistency of the second group of keys with the first group of keys.
  • the method also includes one of the following: the first device receives a second message from a target second device, wherein the second message is used to indicate that the target second device has successfully verified the consistency of the second group of keys with the first group of keys, and the target second device is one of the multiple second devices; the first device receives a third message from the target second device, wherein the third message is used to indicate that the target second device has failed to verify the consistency of the second group of keys with the first group of keys.
  • the first device can record the target second device as the second device that successfully generates the group key, and then use the first group key to communicate with the target second device; here, communication can refer to decrypting the received data based on the first group key and/or encrypting the sent data based on the first group key.
  • the first device when the first device receives the second message from any second device, it can determine that the second device has successfully generated the group key, record the second device, and communicate with the second device.
  • the target second device can communicate with the first device using the second set of keys; here, communication can refer to decrypting received data based on the second set of keys and/or encrypting sent data based on the second set of keys.
  • the first device can continue to perform the aforementioned processing on the target second device next time, so that the target second device generates a second group of keys that are the same as the first group of keys. Similarly, if the target second device sends the third message, the target second device can wait for the next generation of the group key.
  • the multiple signals are used to generate a second group of keys for each second device, and the method further includes: the first device calculates group key error correction information based on the first group of keys, wherein the group key error correction information is used by each second device to correct the second group of keys to obtain a group key consistent with the first group of keys; and the first device sends a fourth message to each second device, wherein the fourth message carries the group key error correction information.
  • the method also includes: the target second device receives a fourth message from the first device, wherein the fourth message carries group key error correction information, and the group key error correction information is calculated by the first device based on the first group key, and the first group key is generated by the first device based on the multiple information; the target second device corrects the second group key based on the group key error correction information to obtain a group key consistent with the first group key.
  • the first device calculates the group key error correction information based on the first group key, which may be that the first device calculates the first group key based on the second preset calculation method to obtain a check code, and uses the check code as the group key error correction information.
  • the target second device corrects the second group key based on the group key error correction information to obtain a group key consistent with the first group key, which may be that the target second device decodes and corrects the second group key using the group key error correction information based on the error correction method corresponding to the second preset method to obtain a group key consistent with the first group key.
  • the calculation function (or calculation method) adopted by the second preset calculation method can be set according to actual conditions.
  • any one or more functions such as LDPC (Low Density Parity-check Codes), Turbo decoding, etc. are used. All possible methods are not enumerated here. As long as the sequence can be encoded to obtain the check code, so that the other end can perform decoding and error correction, it is within the protection scope of this embodiment.
  • the first device may trigger updating of the group key.
  • the first device may periodically trigger the updating of the group key.
  • the periodic duration may be set according to actual conditions, such as 7 days, 1 day, or longer or shorter, which are not exhaustively listed here.
  • the first device may trigger the update of the group key when the second device is added or reduced in the device group.
  • the first device determines the manner in which the second device is added or reduced in the device group, and the first device may receive indication information sent by a network device, and the indication information is used to indicate the addition of the second device in the device group or the removal of the second device.
  • the network device may be an access network device, a core network device, an application function (AF), etc., which are not exhaustively listed here.
  • the first device updates the group key by executing the method provided in the above embodiment again, so that the first device and each current second device in the device group updates the group key.
  • the key generation method provided in this application is exemplified.
  • the system consisting of the reader and N tags is shown in Figure 4: with the reader as the center and d1 as the radius, there are N tags communicating with the reader.
  • the purpose of the group key scheme is to generate a common group key Gk between the reader and the N tags.
  • N tags are all single-antenna devices, and the reader is configured with M antennas.
  • the specific steps are as follows:
  • Step 501 the reader broadcasts a group key generation signaling, for example, the group key generation signaling can be represented as message1.
  • Step 502 After receiving the group key generation signaling, all tags in the N tags reflect the pilot signal s to the reader in turn according to the time slot anti-collision mechanism.
  • Step 503 The reader receives the reflected pilot signal sent by each tag in step 502 in turn, and estimates the channel characteristics between the reader and each tag.
  • tag 1 among N tags Take tag 1 among N tags as an example. The details are as follows: a continuous carrier (amplitude is 1) is transmitted by the first antenna of the reader, and the reflected pilot signal of tag 1 received by the reader is: By receiving the pilot signal, the reader can decode the channel between tag 1 and the reader. Finally, the reader obtains the channels between all tags and the reader: The meanings of the contents contained in each formula in this step are the same as those in the previous embodiment and will not be repeated.
  • Step 504 The reader calculates the antenna weight coefficient, which is the radio frequency coefficient in the above embodiment.
  • Step 505 The reader transmits a signal r, so that the signals received by N tags are all r.
  • the reader sends signal r K times, that is, the reader sends the signal r to each group of tags in the K groups of tags divided by the N tags. It has been explained in the previous embodiment that multiple signals can be sent to each group of tags.
  • the signal r in this step can be any one of the multiple signals sent to each group of tags.
  • the reader does not need to repeat steps 501 to 504.
  • the reader only needs to repeat step 505 multiple times, and can change the signal r each time (that is, change the relevant information of the signal) and re-transmit the signal r, that is, change r in step 505, so that the key source can be time-varying and the signal can be re-transmitted.
  • the reader can determine whether to change the relevant information of the signal according to actual needs. There are also some possible examples in which the same signal may be sent twice at any time. This embodiment does not exhaust all possible situations.
  • steps 501 to 505 may be performed in different coherence times, except that r may be changed each time step 505 is performed, so that the key source is time-varying.
  • Step 506 After executing step 505 multiple times, the reader and all tags have accumulated information or features of multiple different r, and can then determine their respective group keys. At this point, the reader obtains the first group key in the aforementioned embodiment, and each tag obtains its own second group key in the aforementioned embodiment.
  • Step 507 The reader and the N tags determine a consistent group key.
  • This step can provide different methods for determining the final group key based on the tag computing capability.
  • Method 1 The reader maps the initial key sequence (i.e. the reader's first group of keys) to a certain value through a hash function, or calculates the cyclic redundancy check code (CRC) of the sequence, and broadcasts the hash mapping value or cyclic redundancy check code.
  • N tags calculate their own hash mapping value or cyclic redundancy check code according to their own initial key sequence (i.e. the tag's own second group of keys), and compare it with the data received from the reader. If they are consistent, the success command is returned. If they are inconsistent, the fail command is returned and the next group key generation is waited for.
  • the reader records the tags that successfully generate the group key and can use this group key to communicate with these tags.
  • Method 2 If the N tags have certain decoding and error correction capabilities (such as LDPC and Turbo decoding), the reader generates a check code from the initial key sequence (i.e., the reader's first set of keys) through a certain encoding method, and sends the check code to the N tags. All tags use the check code for decoding and error correction (i.e., each tag decodes and corrects its own second set of keys), so that the reader and each tag obtain consistent keys.
  • decoding and error correction capabilities such as LDPC and Turbo decoding
  • Method 1 is not able to correct errors for tags with weak computing power. If the key is inconsistent, it is necessary to wait for the next group key generation.
  • Method 2 is a commonly used key error correction method, but for tags, it needs to support a decoding algorithm with a certain degree of complexity.
  • N 32.
  • the key inconsistency rate between N tags and readers, and the key inconsistency rate between Eve and readers are simulated.
  • the results are shown in Figure 6.
  • the key inconsistency rate between tags and readers represented by "tag” in Figure 6 specifically refers to the average value of the key inconsistency rate between N tags (the second group of keys) and readers (the first group of keys). It can be seen from Figure 6 that with the increase of the signal-to-noise ratio, the key inconsistency rate between tags and readers becomes smaller and smaller. For example, when the signal-to-noise ratio is 10dB, the key inconsistency rate between tags and readers is about 0.3.
  • the key inconsistency rate between tags and readers is close to 0.05, while the key inconsistency rate between the eavesdropper and the reader is stable around 0.45 to 0.5, indicating that the above example can enable readers and tags to securely generate their respective group keys.
  • the strength of the signal r is used as the key source, that is, the relevant information of the signal in the aforementioned embodiment is specifically the strength of the signal.
  • the strength of the signal r is selected as the key source, that is, the specific content of the signal r is not concerned, and only its signal strength is used. The specific steps are as follows:
  • steps 701 to 704 are the same as that of steps 501 to 504 in the above example, and thus will not be repeated.
  • Step 705 The reader transmits a signal r so that the signal strengths received by the N tags are the same.
  • the specific process is as follows:
  • the strength of the signal r transmitted by the reader is recorded as P, and it is transmitted K times.
  • the antenna weight coefficient of the kth time is w k
  • the signal amplitude received by the tags involved in the kth group is:
  • P represents the signal strength (or amplitude)
  • the rest of the contents are the same as the above embodiment and will not be described in detail.
  • all tags will record the signal strength P, and the reader also knows P, so P will be quantified as a key source.
  • the reader does not need to repeatedly perform steps 701 to 704, and only needs to change the P value in step 705 to make the key source time-varying. If the channel environment is time-varying, steps 701 to 705 can be performed at different coherence times.
  • Step 706 After multiple executions of step 705, assuming that all tags have obtained L intensity values and the reader also knows these L intensity values, both parties start quantization, and the reader and N tags obtain the initial key sequence, that is, the reader obtains the first set of keys, and each tag obtains its own second set of keys.
  • the specific process is as follows: Assume that the reader takes the range of P as: P min ⁇ P ⁇ P max . When the quantization order is Q, the range of P is evenly divided into Q, each range corresponds to a Gray code of length log 2 Q, and each intensity value corresponds to log 2 Qbit.
  • the reader and tag can perform rounding on all the obtained intensity values, and then quantize, so that the reader and N tags obtain the initial key sequence.
  • the quantization method includes but is not limited to the method described herein.
  • Step 707 The reader and the N tags determine a consistent group key. Specifically, using the given method 1 or method 2, the reader and the N tags determine a final consistent key.
  • Steps 801 to 804 are the same as steps 501 to 504 in the above example and will not be described again.
  • Step 805 The reader transmits a signal r, so that N tags receive the same group key.
  • the reader sends signal r K times.
  • the frame structure of r jk is designed as follows:
  • any tag in the kth group receives r jk , it takes out the data segment corresponding to itself (i.e., the target data segment), and then XORs the data segment with its own ID to obtain k j .
  • all tags will get the same k j .
  • the meaning of the formula in this step is the same as that in the previous embodiment, and will not be repeated.
  • the key source can be time-varied by simply changing k in step 805. Steps 801 to 805 can be performed in different coherence times.
  • Step 806 Concatenate the accumulated different k (i.e., key sequences) into a group key sequence.
  • the reader obtains the first group key (i.e., the group key sequence obtained by the reader), and each tag obtains its own second group key (i.e., the group key sequence obtained by each tag).
  • Step 807 The reader and the N tags determine a consistent group key. That is, using the given method 1 or method 2, the reader and the N tags determine the final consistent key.
  • the above examples design a physical layer group key generation scheme for a zero-power communication network with a reader as the central node and multiple tags as sub-nodes.
  • This scheme configures weight coefficients for the reader's multiple antennas so that multiple tags can receive the same key source at the same time to obtain the group key. This effectively reduces the time overhead of group key generation.
  • the weight coefficients are calculated using the legitimate channel value, the legitimate channel and the eavesdropping channel are different for eavesdroppers, so they cannot receive the same key source as the tag, thereby ensuring security.
  • the security of the group key is proved.
  • the key source it can resist illegal eavesdropping of different eavesdropping levels, so as to adapt to different application scenarios.
  • a first device sends multiple signals to each second device, and the radio frequency coefficients of the multiple signals are calculated based on the channel characteristics between the second device and the first device, and then the first device itself will also generate a group key for communicating with each second device based on the relevant information of each signal.
  • the radio frequency coefficients corresponding to different second devices for the signals sent to different second devices, the channel characteristics between the second device and the first device can be accurately offset, that is, the loss or interference of the channel between the second device and the first device can be offset, thereby ensuring the reduction of the time overhead of generating the group key while also ensuring the security of the group key.
  • the research on group key generation technology is mainly divided into two categories: one is group key generation based on cryptography; the other is group key generation based on physical layer characteristics.
  • the group key generation based on cryptography takes the process of generating group keys by an AP (Access Point) and multiple STAs (Stations) as an example: the AP first performs a four-way handshake with each STA to generate the corresponding pair keys, and the pair keys of different STAs are different; when the group key needs to be generated, the AP generates the group key GTK, and then encrypts the GTK with the pair key, and sends the encrypted data to the STA.
  • AP Access Point
  • STAs STAs
  • the STA uses the pair key to decrypt and obtain the GTK, that is, if there are N STAs, it is necessary to send N GTKs.
  • the processing methods of the group key based on the physical layer characteristics may include: in the first method, the central node and the child node exchange pilot signals with each other within a coherent time, and each records the signal strength. Then the central node calculates multiple strength differences and sends them to the child nodes respectively. The child node uses the signal strength recorded by itself and the received strength difference to restore the group key; in the second method, all child nodes are required to be configured with multiple antennas.
  • the child node records the antenna that receives the signal as 1 and the antenna that does not receive the signal as 0, and finally obtains a sequence of the signal reception status of the multiple antennas; in the third method, through the specified method, it can be guaranteed that the state sequence of multiple child nodes is the same, so this state sequence can be used as the group key.
  • the sub-node device capabilities are high.
  • Cryptography-based group key generation requires the device to support key generators and complex encryption and decryption algorithms.
  • Some group key solutions based on physical layer characteristics also require sub-node devices to have certain hardware capabilities or algorithm capabilities. These solutions that have special requirements for sub-nodes are not universal in zero-power networks. Zero-power devices in most scenarios have minimalist circuit designs, low computing power, and low storage capacity, and cannot support the requirements of these solutions.
  • the time overhead of generating group keys is high.
  • T time for a one-way communication from node to node
  • N child nodes in total.
  • AP Access Point
  • STAs Stations
  • the time to generate the group key is greater than 2NT.
  • the time to generate a group key is 2NT, and within a coherent time, when the channel does not change, the group key can only be generated once. In scenarios with a longer coherent time, the group key will not change.
  • the key generation method provided by the embodiment of the present application can first reduce the time overhead of group key generation. Specifically, the time for all tags (i.e., each second device) to obtain the quantization result or key sequence of the group key (i.e., obtain the relevant information of a signal once, or obtain the quantization result or key sequence based on the relevant information of a signal) provided by the key generation method provided by the present application is Less than 2NT, that is, lower than the time overhead of the group key generation scheme in the existing standard (802.11i). Again, the key generation method provided in this application does not require the tag (that is, the second device) to add any additional overhead. For the zero-power device tag, no unnecessary process is added.
  • the tag only needs to perform simple reflection and reception of signals to realize the generation of the group key. There is no need to change the technology supported by the zero-power device and the simple circuit design. Finally, even in an environment with a long coherence time, the group key can still be updated to avoid the problem of a single key being used for too long. At the same time, not only can the endogenous channel be used to protect the key source, but the signal r can also be designed to strengthen the protection of the key source to resist eavesdroppers with different degrees of eavesdropping.
  • FIG9 is a schematic diagram of the composition structure of a first device according to an embodiment of the present application, including:
  • the first communication unit 901 is configured to send a plurality of signals to each second device among the plurality of second devices, wherein the radio frequency coefficients of the plurality of signals are calculated based on the channel characteristics between each second device and the first device;
  • the first processing unit 902 is configured to generate a first set of keys based on relevant information of the multiple signals, where the first set of keys is used for communication between the first device and the multiple second devices.
  • the first communication unit is configured to send a group key generation signaling to each of the second devices; and receive a pilot signal from each of the second devices, wherein the pilot signal is a reflected signal corresponding to the group key generation signaling;
  • the first processing unit is configured to calculate a channel characteristic between each second device and the first device based on a pilot signal of each second device.
  • the first processing unit is used to calculate one or more radio frequency coefficients based on the channel characteristics between each second device and the first device, wherein different radio frequency coefficients among the one or more radio frequency coefficients correspond to different second devices.
  • the first communication unit is used to send the multiple signals to each second device in the kth group of second devices based on the kth RF coefficient among the one or more RF coefficients, wherein different RF coefficients among the one or more RF coefficients correspond to different groups of the multiple second devices, and different groups of the multiple second devices include different second devices, and the kth group of second devices is one of the one or more groups of the multiple second devices, and k is a positive integer.
  • the first processing unit is configured to obtain a plurality of first quantization results based on relevant information of the plurality of signals; and generate the first group of keys based on the plurality of first quantization results.
  • the first processing unit is used to determine a first quantization range corresponding to the i-th signal based on relevant information of the i-th signal among the multiple signals, and use a first quantization value corresponding to the first quantization range as the i-th first quantization result among the multiple first quantization results, wherein the first quantization range is one of multiple first candidate quantization ranges, each first candidate quantization range in the multiple first candidate quantization ranges has a corresponding first candidate quantization value, and i is a positive integer.
  • the relevant information of the multiple signals includes at least one of the following: the strength of each signal in the multiple signals and the phase of each signal.
  • the relevant information of the multiple signals includes a key sequence carried by each of the multiple signals; and the first processing unit is used to generate the first group of keys based on the key sequence carried by each of the multiple signals.
  • the j-th signal among the multiple signals carries one or more data segments, and different data segments among the one or more data segments are calculated based on identifications of different second devices and the j-th key sequence, where j is a positive integer.
  • the multiple signals are used for each second device to generate a second group of keys;
  • the first processing unit is used to calculate group key verification information based on the first group of keys, wherein the group key verification information is used for each second device to verify the consistency of the second group of keys with the first group of keys;
  • the first communication unit is used to send a first message to each of the second devices, wherein the first message carries the group key verification information.
  • the first communication unit is used to perform one of the following: receiving a second message from a target second device, wherein the second message is used to indicate that the target second device has successfully performed a consistency check on the second group of keys and the first group of keys, and the target second device is one of the multiple second devices; receiving a third message from the target second device, wherein the third message is used to indicate that the target second device has failed a consistency check on the second group of keys and the first group of keys.
  • the multiple signals are used for each second device to generate a second group key;
  • the first processing unit is used to calculate group key error correction information based on the first group key, wherein the group key error correction information is used for each second device to correct the error of the second group key to obtain a group key consistent with the first group key;
  • the first communication unit is used to send a fourth message to each of the second devices, wherein the fourth message carries the group key error correction information.
  • the first device is one of the following: a terminal device, a network device; the second device is a zero-power consumption device.
  • FIG10 is a schematic diagram of a structure of a target second device according to an embodiment of the present application, including:
  • the second communication unit 1001 is used to receive multiple signals from the first device, wherein the radio frequency coefficients of the multiple signals are calculated based on the channel characteristics between the target second device and the first device;
  • the second processing unit 1002 is used to generate a second group of keys based on the relevant information of the multiple signals, wherein the second group of keys is used for communication between the target second device and the first device, the second group of keys are the same keys for multiple second devices, and the target second device is one of the multiple second devices.
  • the second communication unit is used to receive the group key generation signaling from the first device; and send a pilot signal to the first device, wherein the pilot signal is a reflected signal corresponding to the group key generation signaling, and the pilot signal is used by the first device to calculate the channel characteristics between the target second device and the first device.
  • the second processing unit is configured to obtain a plurality of second quantization results based on the relevant information of the plurality of signals; and generate the second group of keys based on the plurality of second quantization results.
  • the second processing unit is used to determine a second quantization range corresponding to the i-th signal based on relevant information of the i-th signal among the multiple signals, and use the second quantization value corresponding to the second quantization range as the i-th second quantization result among the multiple second quantization results, wherein the second quantization range is one of multiple second candidate quantization ranges, each second candidate quantization range in the multiple second candidate quantization ranges has a corresponding second candidate quantization value, and i is a positive integer.
  • the relevant information of the multiple signals includes one of the following: the strength of each signal in the multiple signals and the phase of each signal.
  • the relevant information of the multiple signals includes a key sequence carried by each of the multiple signals; and the second processing unit is used to generate the second group of keys based on the key sequence carried by each of the multiple signals.
  • the j-th signal of the plurality of signals carries one or more data segments, and different data segments of the one or more data segments are calculated based on the identification of different second devices and the j-th key sequence; the second processing unit is used to, from the j-th signal, Extract the target data segment corresponding to the target second device, where j is a positive integer; and calculate the jth key sequence carried by the jth signal based on the identifier of the target second device and the target data segment.
  • the second communication unit is configured to receive a first message from the first device, wherein the first message carries group key verification information, the group key verification information is calculated by the first device based on a first group key, and the first group key is generated by the first device based on the multiple information;
  • the second processing unit is configured to calculate verification information based on the second group of keys; and verify consistency between the second group of keys and the first group of keys based on the group key verification information and the verification information.
  • the second communication unit is used to perform at least one of the following: when the second group of keys is consistent with the first group of keys, sending a second message to the first device, wherein the second message is used to indicate that the target second device has successfully verified the consistency of the second group of keys with the first group of keys; when the second group of keys is inconsistent with the first group of keys, sending a third message to the first device, wherein the third message is used to indicate that the target second device has failed to verify the consistency of the second group of keys with the first group of keys.
  • the second communication unit is configured to receive a fourth message from the first device, wherein the fourth message carries group key error correction information, the group key error correction information is calculated by the first device based on a first group key, and the first group key is generated by the first device based on the multiple information;
  • the second processing unit is configured to perform error correction on the second group key based on the group key error correction information to obtain a group key consistent with the first group key.
  • the first device is one of the following: a terminal device, a network device; the target second device is a zero-power consumption device.
  • the device of the embodiment of the present application can realize the corresponding functions of each device in the aforementioned key generation method embodiment.
  • the process, function, implementation method and beneficial effect corresponding to each module (submodule, unit or component, etc.) in the first device or the target second device can be referred to the corresponding description in the above method embodiment, which will not be repeated here.
  • the functions described in the first device of the application embodiment or each module (submodule, unit or component, etc.) in the target second device can be implemented by different modules (submodule, unit or component, etc.), or by the same module (submodule, unit or component, etc.).
  • Fig. 11 is a schematic structural diagram of a communication device 1100 according to an embodiment of the present application.
  • the communication device 1100 includes a processor 1110, and the processor 1110 can call and run a computer program from a memory to enable the communication device 1100 to implement the method in the embodiment of the present application.
  • the communication device 1100 may further include a memory 1120.
  • the processor 1110 may call and run a computer program from the memory 1120, so that the communication device 1100 implements the method in the embodiment of the present application.
  • the memory 1120 may be a separate device independent of the processor 1110 , or may be integrated into the processor 1110 .
  • the communication device 1100 may further include a transceiver 1130, and the processor 1110 may control the transceiver 1130 to communicate with other devices, specifically, may send information or data to other devices, or receive information or data sent by other devices.
  • the transceiver 1130 may include a transmitter and a receiver.
  • the transceiver 1130 may further include an antenna, and the number of the antennas may be one or more.
  • the communication device 1100 may be the first device of an embodiment of the present application, or the target second device, and the communication device 1100 may implement the corresponding processes implemented by the first device or the target second device in each method of the embodiment of the present application, which will not be repeated here for the sake of brevity.
  • a first device comprising: a processor, and a memory communicating with the processor, the memory being used to store instructions, and when the instructions are executed by the processor, the instructions cause the first device to execute: sending multiple signals to each second device among multiple second devices, wherein the radio frequency coefficients of the multiple signals are calculated based on channel characteristics between each second device and the first device; generating a first group of keys based on relevant information of the multiple signals, and the first group of keys is used for communication between the first device and the multiple second devices.
  • the instruction also causes the first device to execute: sending a group key generation signaling to each of the second devices; receiving a pilot signal from each of the second devices, wherein the pilot signal is a reflected signal corresponding to the group key generation signaling; and calculating the channel characteristics between each of the second devices and the first device based on the pilot signal of each of the second devices.
  • the instruction also causes the first device to execute: calculating one or more radio frequency coefficients based on channel characteristics between each of the second devices and the first device, wherein different radio frequency coefficients among the one or more radio frequency coefficients correspond to different second devices.
  • the instruction also causes the first device to execute: based on the kth RF coefficient among the one or more RF coefficients, sending the multiple signals to each second device in the kth group of second devices, wherein different RF coefficients among the one or more RF coefficients correspond to different groups of the multiple second devices, and different groups of the multiple second devices include different second devices, the kth group of second devices is one of the one or more groups of the multiple second devices, and k is a positive integer.
  • the instructions further cause the first device to execute: obtaining a plurality of first quantization results based on relevant information of the plurality of signals; and generating the first set of keys based on the plurality of first quantization results.
  • the instruction also causes the first device to execute: based on relevant information of the i-th signal among the multiple signals, determine a first quantization range corresponding to the i-th signal, and use a first quantization value corresponding to the first quantization range as the i-th first quantization result among the multiple first quantization results, wherein the first quantization range is one of multiple first candidate quantization ranges, each first candidate quantization range in the multiple first candidate quantization ranges has a corresponding first candidate quantization value, and i is a positive integer.
  • the relevant information of the multiple signals includes at least one of the following: the strength of each signal in the multiple signals and the phase of each signal.
  • the relevant information of the multiple signals includes a key sequence carried by each of the multiple signals; the instructions further cause the first device to execute: generating the first group of keys based on the key sequence carried by each of the multiple signals.
  • the j-th signal among the multiple signals carries one or more data segments, and different data segments among the one or more data segments are calculated based on identifications of different second devices and the j-th key sequence, where j is a positive integer.
  • the multiple signals are used to generate a second group of keys for each second device; the instruction also causes the first device to execute: based on the first group of keys, calculate group key verification information, wherein the group key verification information is used by each second device to verify the consistency of the second group of keys with the first group of keys; send a first message to each second device, wherein the first message carries the group key verification information.
  • the multiple signals are used to generate a second group of keys for each second device; the instruction also causes the first device to execute: based on the first group of keys, calculate group key error correction information, wherein the group key error correction information is used by each second device to correct the second group of keys to obtain a group key consistent with the first group of keys; send a fourth message to each second device, wherein the fourth message carries the group key error correction information.
  • the first device is one of the following: a terminal device, a network device; the second device is a zero-power consumption device.
  • the instruction also causes the target second device to execute: receiving a group key generation signaling from the first device; sending a pilot signal to the first device, wherein the pilot signal is a reflected signal corresponding to the group key generation signaling, and the pilot signal is used by the first device to calculate the channel characteristics between the target second device and the first device.
  • the instruction also causes the target second device to execute: based on relevant information of the i-th signal among the multiple signals, determine a second quantization range corresponding to the i-th signal, and use a second quantization value corresponding to the second quantization range as the i-th second quantization result among the multiple second quantization results, wherein the second quantization range is one of multiple second candidate quantization ranges, each second candidate quantization range in the multiple second candidate quantization ranges has a corresponding second candidate quantization value, and i is a positive integer.
  • the relevant information of the multiple signals includes one of the following: the strength of each signal in the multiple signals and the phase of each signal.
  • the relevant information of the multiple signals includes a key sequence carried by each of the multiple signals; the instructions further cause the target second device to execute: generating the second set of keys based on the key sequence carried by each of the multiple signals.
  • the j-th signal among the multiple signals carries one or more data segments, and different data segments among the one or more data segments are calculated based on the identification of different second devices and the j-th key sequence; the instruction also enables the target second device to execute: extracting the target data segment corresponding to the target second device from the j-th signal, where j is a positive integer; and calculating the j-th key sequence carried by the j-th signal based on the identification of the target second device and the target data segment.
  • the instruction also causes the target second device to execute: receiving a first message from the first device, wherein the first message carries group key verification information, the group key verification information is calculated by the first device based on a first group key, and the first group key is generated by the first device based on the multiple information; calculating verification information based on the second group key; and verifying the consistency of the second group key with the first group key based on the group key verification information and the verification information.
  • the instruction also causes the target second device to execute: receiving a fourth message from the first device, wherein the fourth message carries group key error correction information, the group key error correction information is calculated by the first device based on the first group key, and the first group key is generated by the first device based on the multiple information; correcting the second group key based on the group key error correction information to obtain a group key consistent with the first group key.
  • the first device is one of the following: a terminal device, a network device; the target second device is a zero-power consumption device.
  • Fig. 12 is a schematic structural diagram of a chip 1200 according to an embodiment of the present application.
  • the chip 1200 includes a processor 1210, and the processor 1210 can call and run a computer program from a memory to implement the method in the embodiment of the present application.
  • the chip 1200 may further include a memory 1220.
  • the processor 1210 may call and run a computer program from the memory 1220 to implement the method performed by the access network device or the first core network device in the embodiment of the present application.
  • the memory 1220 may be a separate device independent of the processor 1210, or may be integrated in the processor 1210.
  • the chip 1200 may further include an input interface 1230.
  • the processor 1210 may control the input interface 1230 to communicate with other devices or chips, and specifically, may obtain information or data sent by other devices or chips.
  • the chip 1200 may further include an output interface 1240.
  • the processor 1210 may control the output interface 1240 to communicate with other devices or chips, and specifically, may output information or data to other devices or chips.
  • the chip can be applied to the first device or the target second device in the embodiments of the present application, and the chip can implement the corresponding processes implemented by the first device or the target second device in the various methods of the embodiments of the present application. For the sake of brevity, they will not be repeated here.
  • the chip mentioned in the embodiments of the present application can also be called a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.
  • processors mentioned above can be general-purpose processors, digital signal processors (DSP), field programmable gate arrays (FPGA), application specific integrated circuits (ASIC) or other programmable logic devices, transistor logic devices, discrete hardware components, etc.
  • DSP digital signal processors
  • FPGA field programmable gate arrays
  • ASIC application specific integrated circuits
  • the above-mentioned memory may be a volatile memory or a nonvolatile memory, or may include both volatile and nonvolatile memories.
  • the memories in the embodiments of the present application are intended to include, but are not limited to, these and any other suitable types of memories.
  • FIG. 13 is a schematic block diagram of a communication system 1300 according to an embodiment of the present application.
  • the communication system 1300 includes a first device 1310 and a target second device 1320.
  • it can be implemented in whole or in part by software, hardware, firmware or any combination thereof.
  • software it can be implemented in whole or in part in the form of a computer program product.
  • the computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function in accordance with the embodiment of the present application is generated in whole or in part.
  • the computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device.
  • the computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium.
  • the size of the serial numbers of the above-mentioned processes does not mean the order of execution.
  • the execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

Landscapes

  • Engineering & Computer Science (AREA)
  • Signal Processing (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Computer Security & Cryptography (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本申请涉及一种密钥生成方法、设备、计算机可读存储介质、计算机程序产品和计算机程序。其中方法包括:第一设备向多个第二设备中的每个第二设备发送多个信号,其中,所述多个信号的射频系数为基于所述每个第二设备与所述第一设备间的信道特征计算得到的;所述第一设备基于所述多个信号的相关信息,生成第一组密钥,所述第一组密钥用于所述第一设备与所述多个第二设备的通信。

Description

密钥生成方法和设备 技术领域
本申请涉及通信领域,更具体地,涉及一种密钥生成方法、设备、计算机可读存储介质、计算机程序产品和计算机程序。
背景技术
随着通信技术的发展,出现了非接触式的自动识别技术,这种技术通常是利用无线射频方式在零功耗设备和其他设备(比如读写器)之间进行非接触式数据传输。由于零功耗设备以及读写器之间的通信信道是不安全信道,因此为了保证零功耗设备的数据传输安全性,进一步提出零功耗设备和读写器之间可以采用密钥对两者之间传输的数据或信息进行加密的方案。上述方案也仅可以使得单个零功耗设备和读写器均使用相同的对密钥(或称为单播密钥或称为共享密钥),保证单个零功耗设备传输数据的安全性,而在存在多个零功耗设备的场景中,如何能够使得零功耗设备采用复杂度较低的方式生成组密钥、且保证组密钥的安全性,就成为需要解决的问题。
发明内容
本申请实施例提供一种密钥生成方法、设备、计算机可读存储介质、计算机程序产品和计算机程序。
本申请实施例提供一种密钥生成方法,包括:
第一设备向多个第二设备中的每个第二设备发送多个信号,其中,所述多个信号的射频系数为基于所述每个第二设备与所述第一设备间的信道特征计算得到的;
所述第一设备基于所述多个信号的相关信息,生成第一组密钥,所述第一组密钥用于所述第一设备与所述多个第二设备的通信。
本申请实施例提供一种密钥生成方法,包括:
目标第二设备接收来自第一设备的多个信号,其中,所述多个信号的射频系数为基于所述目标第二设备与所述第一设备间的信道特征计算得到的;
所述目标第二设备基于所述多个信号的相关信息,生成第二组密钥,其中,所述第二组密钥用于所述目标第二设备与所述第一设备的通信,所述第二组密钥为多个第二设备相同的密钥、且所述目标第二设备为所述多个第二设备中之一。
本申请实施例提供第一设备,包括:
第一通信单元,用于向多个第二设备中的每个第二设备发送多个信号,其中,所述多个信号的射频系数为基于所述每个第二设备与所述第一设备间的信道特征计算得到的;
第一处理单元,用于基于所述多个信号的相关信息,生成第一组密钥,所述第一组密钥用于所述第一设备与所述多个第二设备的通信。
本申请实施例提供目标第二设备,包括:
第二通信单元,用于接收来自第一设备的多个信号,其中,所述多个信号的射频系数为基于所述目标第二设备与所述第一设备间的信道特征计算得到的;
第二处理单元,用于基于所述多个信号的相关信息,生成第二组密钥,其中,所述第二组密钥用于所述目标第二设备与所述第一设备的通信,所述第二组密钥为多个第二设备相同的密钥、且所述目标第二设备为所述多个第二设备中之一。
本申请实施例提供一种第一设备,包括:处理器,与所述处理器通信的存储器,所述存储器用于存储指令,当所述指令被所述处理器执行时,所述指令使所述第一设备执行:向多个第二设备中的每个第二设备发送多个信号,其中,所述多个信号的射频系数为基于所述每个第二设备与所述第一设备间的信道特征计算得到的;基于所述多个信号的相关信息,生成第一组密钥,所述第一组密钥用于所述第一设备与所述多个第二设备的通信。
本申请实施例提供一种目标第二设备,包括:处理器,与所述处理器通信的存储器,所述存储器用于存储指令,当所述指令被所述处理器执行时,所述指令使所述目标第二设备执行:接收来自第一设备的多个信号,其中,所述多个信号的射频系数为基于所述目标第二设备与所述第一设备间的信道特征计算得到的;基于所述多个信号的相关信息,生成第二组密钥,其中,所述第二组密钥用于所述目标第二设备与所述第一设备的通信,所述第二组密钥为多个第二设备相同的密钥、且所述目标第二设备为所述多个第二设备中之一。
本申请实施例提供一种芯片,用于实现上述方法。
具体地,该芯片包括:处理器,用于从存储器中调用并运行计算机程序,使得安装有该芯片的设备执行上述的方法。
本申请实施例提供一种计算机可读存储介质,用于存储计算机程序,当该计算机程序被设备运行时使得该设备执行上述方法。
本申请实施例提供一种计算机程序产品,包括计算机程序指令,该计算机程序指令使得计算机执行上述方法。
本申请实施例提供一种计算机程序,当其在计算机上运行时,使得计算机执行上述方法。
通过采用本实施例提供的方案,由第一设备向每个第二设备发送多个信号,该多个信号的射频系数为基于第二设备与第一设备间的信道特征计算得到的,进而第一设备自身也会基于各个信号的相关信息生成用于与各个第二设备通信的组密钥。如此,通过对发送至不同第二设备的信号配置对应于不同第二设备的射频系数,能够准确的抵消该第二设备与第一设备之间的信道特征,即抵消该第二设备与第一设备的信道的损耗或干扰,并且仅需要基于信号的相关信息就可以生成组密钥,从而在保证降低生成组密钥的复杂度的同时,还保证了组密钥的安全性。
附图说明
图1是根据本申请实施例的应用场景的示意图。
图2是根据本申请一实施例的密钥生成方法的示意性流程图。
图3是根据本申请另一实施例的密钥生成方法的示意性流程图。
图4是根据本申请一实施例的密钥生成方法的一种场景示意图。
图5是根据本申请一实施例密钥生成方法的一种示意性流程图。
图6是根据本申请实施例提供的密钥生成方法的仿真结果示意图。
图7~图8是根据本申请一实施例密钥生成方法的另外两种示意性流程图。
图9是根据本申请的一实施例的第一设备的示意性框图。
图10是根据本申请的一实施例的目标第二设备的示意性框图。
图11是根据本申请实施例的通信设备示意性框图。
图12是根据本申请实施例的芯片的示意性框图。
图13是根据本申请实施例的通信系统的示意性框图。
具体实施方式
本申请实施例的技术方案可以应用于各种通信系统,例如LTE、LTE-A、NR、NR的演进、WLAN、WiFi、或其他通信系统等。
本申请实施例结合网络设备和终端描述了各个实施例,终端可以是移动或固定的,终端也可以称为移动站、用户单元等。终端可以是WLAN中的站点,可以是智能终端、无线调制解调器、笔记本电脑、平板电脑等终端。在本申请实施例中,终端可以是VR终端/AR终端、工业控制终端、无人驾驶终端、远程医疗终端、智能电网终端、运输安全终端、智慧城市终端或智慧家庭的无线终端等。作为示例而非限定,在本申请实施例中,该终端还可以是可穿戴设备。
在本申请实施例中,网络设备可以是用于与终端通信的设备,网络设备可以是WLAN中的接入点,还可以是LTE中的演进型基站,或者中继站,或者车载设备、可穿戴设备和NR网络中的网络设备(gNB)或者未来演进的PLMN网络中的网络设备或者非地面网络中的网络设备等。作为示例而非限定,在本申请实施例中,网络设备可以具有移动特性,例如网络设备可以为移动的设备。
应理解,本文中术语“系统”和“网络”在本文中常被可互换使用。本文中术语“和/或”,仅仅是一种描述关联对象的关联关系,表示可以存在三种关系,例如,A和/或B,可以表示:单独存在A,同时存在A和B,单独存在B这三种情况。另外,本文中字符“/”,一般表示前后关联对象是一种“或”的关系。应理解,在本申请的实施例中提到的“指示”可以是直接指示,也可以是间接指示,还可以是表示具有关联关系。举例说明,A指示B,可以表示A直接指示B,例如B可以通过A获取;也可以表示A间接指示B,例如A指示C,B可以通过C获取;还可以表示A和B之间具有关联关系。在本申请实施例的描述中,术语“对应”可表示两者之间具有直接对应或间接对应的关系,也可以表示两者之间具有关联关系,也可以是指示与被指示、配置与被配置等关系。
为便于理解本申请实施例的技术方案,以下对本申请实施例的相关技术进行说明,以下相关技术作为可选方案与本申请实施例的技术方案可以进行任意结合,其均属于本申请实施例的保护范围。
图1示例性地示出了一种通信系统100。该通信系统包括一个网络设备110和两个终端120。在一种可能的实现方式中,该通信系统100可以包括多个网络设备110,并且每个网络设备110的覆盖范围内可以包括其它数量的终端120,本申请实施例对此不做限定。在一种可能的实现方式中,该通信系统100还可以包括移动性管理实体、接入与移动性管理功能、等其他网络实体,本申请实施例对此不作限定。其中,网络设备又可以包括接入网设备和核心网设备。即通信系统还可以包括用于与接入网设备进行通信的多个核心网。接入网设备可以是LTE、LTE-A、或NR系统的基站。以图1示出的通信系统为例,通信设备可包括具有通信功能的网络设备和终端,通信设备还可包括通信系统中的其他设备,例如网络控制器、移动管理实体等其他网络实体,本申请实施例中对此不做限定。
为了便于理解本申请实施例,下面对本申请实施例所涉及到的基本流程以及基本概念进行简单说明。应理解,下文所介绍的基本流程以及基本概念并不对本申请实施例产生限定。
图2是根据本申请一实施例的密钥生成方法的示意性流程图。该方法包括以下内容的至少部分内容。
S210、第一设备向多个第二设备中的每个第二设备发送多个信号,其中,所述多个信号的射频系数为基于所述每个第二设备与所述第一设备间的信道特征计算得到的;
S220、所述第一设备基于所述多个信号的相关信息,生成第一组密钥,所述第一组密钥用于所述第一设备与所述多个第二设备的通信。
图3是根据本申请另一实施例的密钥生成方法的示意性流程图。该方法包括以下内容的至少部分内容。
S310、目标第二设备接收来自第一设备的多个信号,其中,所述多个信号的射频系数为基于所述目标第二设备与所述第一设备间的信道特征计算得到的;
S320、所述目标第二设备基于所述多个信号的相关信息,生成第二组密钥,其中,所述第二组密钥用于所述目标第二设备与所述第一设备的通信,所述第二组密钥为多个第二设备相同的密钥、且所述目标第二设备为所述多个第二设备中之一。
所述第一设备为以下之一:终端设备、网络设备。该第一设备可以具备一个或多个天线,在一种优选的示例中,该第一设备可以具备多个天线。应理解的是,本实施例所提供的方案也可以应用于仅具备一个天线的第一设备,这里不做限定。
在一些实施例中,上述第一设备为终端设备,这种实施例中,第一设备和第二设备(任意一个第二设备)之间可以通过侧行链路消息进行通信。
在一些实施例中,上述第一设备可以为网络设备,比如,该网络设备可以为接入网设备(比如基站、gNB、eNB等等任意一种),这种实施例中,该第一设备和第二设备之间可以通过AS(接入层,Access Stratum)消息进行通信。
在一些实施例中,上述第一设备可以为网络设备,比如,该网络设备可以为核心网设备,这种实施例中,该第一设备和第二设备之间可以通过NAS(非接入层,Non-Access Stratum)消息进行通信;或者,这种实施例中,该第一设备和第二设备之间可以通过接入网设备进行消息转发,本实施例不对其全部可能的消息传输方式进行穷举。另外,所述核心网侧设备包括以下至少之一:认证服务器功能(AUSF,Authentication Server Function)、统一数据管理功能(UDM,Unified Data Management)、环境供能物联网(AIoT,Ambient Power-enabled IoT)网元。在一些其他的示例中,该一个或多个核心网设备中除了上述AUSF、UDM和AIoT网元之外,还可以包括以下至少之一:ARPF(Authentication credential Repository and Processing Function认证凭证存储库和处理功能)、AMF(Access and Mobility Management Function,接入和移动性管理功能)、UPF(User Plane Function,用户平面功能)、SEAF(Security Anchor Function,安全锚点功能)等等。应理解,这里仅为示例性说明,实际处理中,核心网侧设备还可以包括核心网的其他设备,只是这里不做穷举。示例性的,上述AIOT网元可以指的是具备AIOT功能的网元,或具备零功耗相关功能的网元;该具备AIoT功能的网元(或具备零功耗相关功能的网元)可以是具备AIOT功能(或具备零功耗设备相关服务供能)的核心网网元,或者服务于AIOT功能(或服务于零功耗设备)的核心网网元,或者至少具备AIoT功能(比如至少具备AIOT(或零功耗设备)组密钥生成供能)的核心网网元等等任意之一。应理解的是,该AIOT网元可以是单独设置的专门用于服务AIOT的网元(或专门服务于零功耗设备的网元),也可能是已有的核心网网元中添加了AIOT相关功能(或服务于零功耗设备的相关功能),本实施例不对全部可能的情况进行穷举。
在一些实施例中,所述第一设备可以称为读写器(Reader)、或阅读器、或标签阅读器、或标签读写器等等,关于该第一设备全部可能的名称或可能的设备,这里不做穷举。
所述第二设备为零功耗设备。在一些实施例中,该零功耗设备可以为环境供能物联网(AIoT,Ambient Power-enabled IoT)设备。在一些实施例中,所述零功耗设备可以为有源零功耗设备、或无源零功耗设备、或半无源零功耗设备等等。在一些实施例中,该第二设备还可以为运算能力较低的终端。在一些可能的实施例中,该第二设备可以称为标签(Tag),关于该第二设备全部可能的名称或可能的设备,这里不做穷举。
前述多个第二设备可以组成一个设备组。目标第二设备同样为零功耗设备,该目标第二设备可以为该多个第二设备中任意之一,也就是该目标第二设备可以为该多个第二设备所组成的设备组中的任意一个第二设备。
在一些可能的实施方式中,前述每个第二设备与第一设备间的信道特征,可以是在第一设备向每 个第二设备发送多个信号之前计算得到的。
在第一设备侧的处理中,先计算每个第二设备与第一设备间的信道特征。所述方法还包括:所述第一设备向所述每个第二设备发送组密钥生成信令;所述第一设备接收来自所述每个第二设备的导频信号,其中,所述导频信号为所述组密钥生成信令所对应的反射信号;所述第一设备基于所述每个第二设备的导频信号,计算所述每个第二设备与所述第一设备间的信道特征。其中,所述每个第二设备与所述第一设备间的信道特征可以组成信道特征矩阵。
以多个第二设备中任意一个第二设备为目标第二设备来说,该目标第二设备的处理中,所述方法还包括:所述目标第二设备接收来自所述第一设备的组密钥生成信令;所述目标第二设备向所述第一设备发送导频信号,其中,所述导频信号为所述组密钥生成信令所对应的反射信号,所述导频信号用于所述第一设备计算所述目标第二设备与所述第一设备间的信道特征。需要指出,这里仅是以目标第二设备进行说明,实际处理中,多个第二设备中每个第二设备均执行与目标第二设备相同的处理,本实施方式为了简洁,不对每个第二设备的处理进行一一赘述。
上述信道特征可以用于表示信号在信道的传输损耗、和/或用于表示信号在信道的传输衰减等等,比如该信道特征可以包括信道的噪声等相关参数,这里不对该信道特征所可能包含的全部可能的参数进行穷举。该信道特征,可以指的是信道还可以替换性的称为信道估计值、或替换性的称为信道估计等等,这里不对其全部可能的名称进行穷举。
该组密钥生成信令的功能可以是用于触发第二设备发送导频信号。应理解的是,该组密钥生成信令也可以具备其他功能,只是在本实施例中不对该组密钥生成信令的其他功能进行穷举以及限定。另外,该组密钥生成信令所可能携带的信息内容,本实施例不做限定。
在一些实施例中,前述第一设备可以仅具备一个天线,这种情况下,该组密钥生成信令直接由该天线发射。
在一些实施例中,前述第一设备可以具备多个天线,该组密钥生成信令可以是通过该第一设备的指定天线发送的,该指定天线可以根据实际情况预先配置或预先设置,比如将该第一设备的多个天线按照位置或处理顺序或逻辑顺序或其他顺序排列为第一根天线~第M根天线(M为大于或等于2的整数),该指定天线可以根据实际情况指定为第一根天线,也就是组密钥生成信令可以是由该第一设备的第一根天线发射的;这里仅为示例性说明,实际处理中只要指定M根天线中任意一个天线发送该组密钥生成信令就在本实施例保护范围内,这里不做全部可能情况的穷举。
在一些实施例中,组密钥生成信令可以是广播或组播发送的,也就是该第一设备向多个第二设备广播或组播该组密钥生成信令,以使得每个第二设备均可以收到该组密钥生成信令。在一些实施例中,组密钥生成信令可以是单播发送的,也就是该第一设备向每个第二设备分别发送该组密钥生成信令。
以多个第二设备中任意一个第二设备为目标第二设备来说,该目标第二设备向所述第一设备发送导频信号可以为:目标第二设备将导频信号调制至该组密钥生成信令对应的连续载波并反射至第一设备。组密钥生成信令对应的连续载波,可以指的是:该组密钥生成信令为连续载波,或者该组密钥生成信令由连续载波的形式发送的,或该组密钥生成信令由连续载波承载的。
在一些实施例中,前述多个第二设备中每个第二设备可以按照防碰撞机制向第一设备发送导频信号。该防碰撞机制可以是预先在每个第二设备中配置的。该防碰撞机制可以为时隙防碰撞机制、或时间单元防碰撞机制、或频域防碰撞机制等等。举例来说,该防碰撞机制可以使得每个第二设备确定在接收到组密钥生成信令后的延时时间单元,该延时时间单元用于各个第二设备确定发送导频信号的发送时间单元、且不同的第二设备所对应的延时时间单元可能相同也可能不同。该时间单元可以是时隙、符号、毫秒、微秒等等任意一种时间单元,这里不做穷举。还应指出,以上仅为示例性说明,实际处理中,该防碰撞机制还可以使得每个第二设备确定导频信号的发送频率范围,且不同的第二设备对应的发送频率范围可能相同或不同;另外,该防碰撞机制也可以使得每个第二设备确定对应的延时时间单元和/或导频信号的发送频率范围,只要使得不同第二设备所发送的导频信号可以在时域和/或频域上避免相互干扰,就在本实施例保护范围内,这里不对该防碰撞机制的全部可能的内容进行穷举。
在一些实施例中,前述第一设备具备多个天线。
所述第一设备接收来自所述每个第二设备的导频信号,可以指的是第一设备通过多个天线中的每个天线接收来自每个第二设备的导频信号。所述第一设备基于所述每个第二设备的导频信号,计算所述每个第二设备与所述第一设备间的信道特征,指的是:所述第一设备基于所述每个第二设备的导频信号,计算所述每个第二设备与所述第一设备的每个天线之间的信道特征。
以任意一个第二设备为目标第二设备为例,该第一设备通过多个天线中的每个天线接收来自每个 第二设备的导频信号,指的是:第一设备通过多个天线中的每个天线接收来自目标第二设备的导频信号。所述第一设备基于所述每个第二设备的导频信号,计算所述每个第二设备与所述第一设备的每个天线之间的信道特征,指的是:所述第一设备基于多个天线中的每个天线所接收的来自目标第二设备的导频信号,计算所述目标第二设备与所述第一设备的每个天线之间的信道特征。
以多个第二设备为多个tag、目标第二设备为多个tag中的tag1,第一设备为reader、且reader具备M个天线为例,该reader的M个天线中每个天线接收到tag1反射的导频信号,可以表示为:其中,ref为tag反射系数,ref的具体取值在reader端已知;s表示tag发出的导频信号(比如可以是reader和tag双方已知内容和/或格式的导频信号),表示reader的第m根天线(或第m个天线)接收的第n个tag反射的导频信号;表示reader第m个(或第m根)天线与第n个tag之间的信道特征;1≤m≤M、1≤n≤N,N为设备组中全部tag的数量,N为大于或等于2的整数,M为前述reader的天线的数量,M为大于或等于2的整数。上述公式中n等于1,也就是s表示tag1发出的导频信号,表示reader的第m根天线接收的第1个tag反射的导频信号;表示reader第m个(或第m根)天线与第1个tag之间的信道特征。本示例中,该reader可以首先通过第1根天线(即第1根天线为前述指定天线)发送前述组密钥生成信令、且导频信号是在组密钥生成信令对应的连续载波上调制至并反射的,因此该第1根天线与第1个tag之间的信道特征,会对reader的每根天线接收到的第1个tag反射的导频信号产生影响,基于此,上述公式中,(即reader的第1根天线与第1个tag之间的信道特征)需要与每个相乘。
进一步,由于reader侧上述公式中的ref已知,s可以是reader和tag双方已知内容和/或格式的导频信号,因此reader可以通过上述公式计算得到tag1与reader的每个天线之间的信道特征,比如可以表示为
以上仅是以一个tag1为例进行的示例性说明,reader可以对每个tag均执行上述处理,最终该reader可以得到每个tag与reader间的信道特征,然后该reader可以将每个tag与reader间的信道特征组成信道特征矩阵,比如可以表示为以下矩阵形式:其中,H表示reader得到的全部tag中每个tag与reader的多个天线之间的信道特征矩阵,关于该信道特征矩阵中的的说明,与前述实施例相同,不做重复说明。
应理解的是,以上是以第一设备具备多个天线为例进行的示例性说明,在一些可能的实施例中,前述第一设备仅具备一个天线,这种情况下,所述第一设备接收来自所述每个第二设备的导频信号,可以指的是第一设备通过该天线接收来自每个第二设备的导频信号。比如,以第二设备为tag、目标第二设备为多个tag中的tag1,第一设备为reader、且第一设备具备1个天线为例,该reader的1个天线接收到tag1反射的导频信号,可以表示为:其中,ref和s的说明与前述实施例相同,不做赘述;表示reader的1根天线接收的第n个tag反射的导频信号;表示reader的1根天线与第n个tag之间的信道特征;1≤n≤N,N为大于或等于2的整数,上述公式中n等于1,也就是s表示tag1发出的导频信号,关于该公式中各个内容的含义与前述示例相似,不做重复说明。在这种实施例中,所述第一设备基于所述每个第二设备的导频信号,计算所述每个第二设备与所述第一设备间的信道特征,可以指的是:所述第一设备基于所述每个第二设备的导频信号,计算所述每个第二设备与所述第一设备的一个天线之间的信道特征;进而第一设备可以将所述每个第二设备与所述第一设备的一个天线之间的信道特征组成信道特征矩阵,比如该信道特征矩阵可以表示为:其中,H表示reader得到的全部tag中每个tag与reader间的信道特征矩阵,关于该信道特征矩阵中的的说明,与前述实施例相同,不做重复说明。
第一设备在得到上述信道特征之后,可以计算射频系数。所述方法还包括:所述第一设备基于所述每个第二设备与所述第一设备间的信道特征,计算一个或多个射频系数,其中,所述一个或多个射频系数中不同的射频系数对应不同的第二设备。
任意一个射频系数的作用可以是用于抵消对应的信道特征(比如用于抵消信号在信道中的传输衰减或传输损耗等等),进而使得在该信道上传输至对应的第二设备的信号与第一设备所发出的信号相同或基本相同,这里不对该射频系数全部可能的作用或功能进行穷举。示例性的,射频系数还可以称为天线权系数、或天线系数、或天线射频发射系数、或射频发送系数、或增益系数、或发射权重系数等等,这里不对其全部可能的名称进行穷举。
在一些实施例中,设备组中的多个第二设备可以划分为一个或多个分组。所述一个或多个射频系数中不同的射频系数对应所述多个第二设备的不同分组、且所述多个第二设备的不同分组中包括不同的第二设备。
本实施例中,第一设备会计算每个分组(即每组第二设备)对应的射频系数。关于不同分组所对应的射频系数是否相同,本实施例不做限定。在下文中,任意一个分组、第二设备的任意一个分组、任意一组第二设备、任意一个分组中的第二设备均表示相同的含义,不做重复说明。需要注意的是,任意一组第二设备与设备组含义不同,设备组(或设备组中的多个第二设备)表示设备组中的全部第二设备,而任意一组第二设备则为该设备组内的任意一个分组、或设备组内的任意一个分组中的每个第二设备,也就是在下文中涉及到组的概念时,只要没有强调为设备组,均表示分组(即设备组内的第二设备分组),下文不做重复解释。
以任意一个分组为第k组第二设备(k为正整数)为例,所述第一设备基于所述每个第二设备与所述第一设备间的信道特征,计算一个或多个射频系数,可以为:该第一设备基于第k组第二设备中每个第二设备与第一设备间的信道特征组成第k组信道矩阵,计算该第k组信道矩阵的右逆矩阵,基于该第k组信道矩阵的右逆矩阵计算一个或多个射频系数中的第k个射频系数,该第k个射频系数对应于第k组第二设备。
关于前述设备组中的全部第二设备所能够得到的分组的数量,可以是等于设备组中第二设备的数量与第一设备的天线数量相除后向上取整;比如,可以表示为K=ceil(N/M),或者,其中,ceil()表示向上取整,也表示向上取整,两者只是在不同计算工具中使用,公式中N和M的含义与前述实施例相同,不做赘述,K表示分组的数量,K为大于或等于1的整数。前述一个或多个射频系数的数量,与前述分组的数量相同均可以为K。也就是说,第k个射频系数可以与第k组第二设备具备对应关系,且k大于等于1且小于等于K。
该第一设备基于第k组第二设备中每个第二设备与第一设备间的信道特征组成第k组信道矩阵,可以是,将前述每个第二设备与第一设备间的信道特征矩阵中的第k组第二设备中每个第二设备对应的信道特征提取出来,组成第k组信道矩阵。
其中,第k组信道矩阵可以包括:第(k-1)M+1个第二设备至第(k-1)M+M个第二设备的信道特征。
举例来说,第k组信道矩阵可以表示为(1≤k≤K):其中,H(x)表示H(信道特征矩阵)中的第x行,x等于(k-1)M+1时为H中的第(k-1)M+1行,即第(k-1)M+1个第二设备对应的信道特征,x等于(k-1)M+M时为H中的第(k-1)M+M行,也就是第(k-1)M+M个第二设备对应的信道特征。
再举例来说,假设N等于4,M等于2,则且K等于2,在k等于1的情况下,第1组信道矩阵其中,以此类推可以得到k等于2的情况下,第2组信道矩阵不再对其进行重复说明。
所述计算该第k组信道矩阵的右逆矩阵可以采用以下公式计算:其中,表示第k组信道矩阵的右逆矩阵,Hk表示第k组信道矩阵,Hk H则表示第k组信道矩阵的转置矩阵。
所述基于该第k组信道矩阵的右逆矩阵计算一个或多个射频系数中的第k个射频系数,可以指的是:将该第k组信道矩阵的右逆矩阵的所有列相加,得到一个或多个射频系数中的第k个射频系数。举例来说,得到第k个射频系数可以采用以下公式表示:其中,wk表示第k个射频系数,sum_column()表示将矩阵的所有列相加。
在一些实施例中,所述第一设备向多个第二设备中的每个第二设备发送多个信号,可以指的是:所述第一设备基于所述一个或多个射频系数中的第k个射频系数,向第k组第二设备中的每个第二设备发送所述多个信号,其中,所述一个或多个射频系数中不同的射频系数对应所述多个第二设备的不同分组、且所述多个第二设备的不同分组中包括不同的第二设备,所述第k组第二设备为所述多个第二设备的一个或多个分组中之一,k为正整数。也就是,第一设备将该多个信号中的第i个信号依次采用K组第二设备中的每个第二设备分组分别对应的射频系数,依次向每组第二设备发送第i个信号,i为正整数。比如,多个第二设备为N个,N个第二设备划分成K组,则第一设备在生成多个信号中的第i个信号的情况下,依次采用K组第二设备中每组第二设备分别对应的射频系数,向每组第二设备发送该第i个信号;然后第一设备生成多个信号的第i+1个信号的情况下,同样依次采用K组第二设备中每组第二设备分别对应的射频系数,向每组第二设备发送该第i+1个信号。也就是在第一设备侧第i个信号会发送K次、且不同次会发向不同组的每个第二设备,从而使得每个第二设备均可以接收到相同的第i个信号;相应的,在任意一个第二设备侧接收一次第i个信号。
以任意一个第二设备为目标第二设备、目标第二设备为tagn来说,该tagn接收到的第i个信号,可以表示为riHkwk,其中,ri为第i个信号,其他内容的含义与前述实施例相同;由于通过射频系数wk可以抵消掉Hk,因此在tagn接收到的信号应为ri,也就是6,其中,Ik_n×1表示k_n行1列的单位向量,k_n表示Hk的行数,即第k组tag中tag的个数,也就是第k组tag中所有的tag(每个tag)都会接收到ri
在一些实施例中,若相干时间很长、即信道环境处于静态环境,则第一设备无需重复执行前述第一设备向所述每个第二设备发送组密钥生成信令至计算所述每个第二设备与所述第一设备间的信道特征、和计算每组第二设备对应的射频系数的处理。也就是第一设备计算得到每个射频系数之后,可以执行向每组第二设备内的第二设备发送多个信号的处理,并且针对相同组的第二设备采用相同的射频系数发送多个信号中的不同信号。
若相干时间较短、也就是信道环境时变,则第一设备可以重复前述处理。比如,若要执行发送第i个信号的处理,则第一设备需要执行向所述每个第二设备发送组密钥生成信令至计算所述每个第二设备与所述第一设备间的信道特征、计算每组第二设备对应的射频系数(即每个射频系数)的处理,然后基于每组第二设备对应的射频系数,向每组第二设备发送第i个信号;若要执行发送第i+1个信号的处理,则第一设备再次执行向所述每个第二设备发送组密钥生成信令至计算所述每个第二设备与所述第一设备间的信道特征、和计算每组第二设备对应的射频系数的处理,然后基于每组第二设备对应的射频系数,向每组第二设备发送第i+1个信号。
若相干时间较短、也就是信道环境时变,则第一设备还可以根据具体的相干时长,来确定何时重复执行向所述每个第二设备发送组密钥生成信令至计算所述每个第二设备与所述第一设备间的信道特征、计算每组第二设备对应的射频系数的处理。比如,相干时长内可以向每组第二设备分别发送A个信号(A可以为大于或等于1的整数),则在完成发送第1~第A个信号之后、向每组第二设备发送第A+1个信号之前,再次执行向所述每组第二设备发送组密钥生成信令至计算所述每个第二设备与所述第一设备间的信道特征、计算每组第二设备对应的射频系数的处理,然后基于每组第二设备对应的射频系数,向每组第二设备分别发送第A+1个信号,下一次循环依此类推,在向每组第二设备发送第2A+1个信号之前,再次执行前述计算每个射频系数的处理,依此类推不做赘述。
该相干时间较长或相干时间较短,可以是基于预先设置的时长门限值来确定的,比如,该相干时间大于时长门限值的情况下,该相干时间较长,即信道环境处于静态环境,该相干时间小于或等于时长门限值的情况下,该相干时间较短,即信道环境时变。该时长门限值可以根据实际情况配置,比如,可以与设备组中实际包含的第二设备的数量相关、和/或与发送一次信号所需的时长相关等等,这里不对确定该时长门限值的全部可能的参数以及其确定方式进行限定。
另外,前述相干时间也可以称为相干时长,该相干时间可以是根据实际情况确定的,本实施例不对该相干时间的获取或确定方式进行限定,只要在执行本实施例提供的全部方案之前,在第一设备侧可以预先得到该相干时间,就在本实施例保护范围内。
在一些实施例中,第一设备会计算每个第二设备对应的一个射频系数。关于不同第二设备所对应的射频系数是否相同,本实施例不做限定。
以任意一个第二设备为目标第二设备为例,该第一设备可以是对目标第二设备与第一设备间的信道特征求右逆矩阵,基于该右逆矩阵计算该目标第二设备所对应的射频系数。其中,基于该右逆矩阵计算该目标第二设备所对应的射频系数,可以指的是:将该右逆矩阵的所有列相加得到该目标第二设备所对应的射频系数。
比如,以目标第二设备为tagn(或第n个tag)、第一设备为reader为例,对tagn与第一设备间的信道特征求右逆矩阵可以采用以下公式计算:其中,n表示tag的编号或序号,在本示例中n可以等于1,表示右逆矩阵,Hn表示第n个tag与reader间的信道特征矩阵,Hn H则表示第n个tag与reader间的信道特征矩阵的转置矩阵。以前述n具体取值为1为例,也就是tag1与reader间的信道特征可以表示为H1,具体的或者,关于前述公式中包含的各个内容的含义与前述实施例相同,不做赘述。
进一步,将该右逆矩阵的所有列相加得到该tagn所对应的射频系数,可以表示为: 其中,wn表示tagn所对应的射频系数,sum_column()表示将矩阵的所有列相加。
在一些实施例中,所述第一设备向多个第二设备中的每个第二设备发送多个信号,可以指的是:第一设备将该多个信号中的第i个信号依次采用每个第二设备分别对应的射频系数,依次向每个第二设备发送第i个信号,i为正整数。比如,多个第二设备为N个(N为大于或等于2的整数),则第一设备在生成多个信号中的第i个信号的情况下,依次采用N个第二设备中每个第二设备分别对应的射频系数,向每个第二设备发送该第i个信号;然后第一设备生成多个信号的第i+1个信号的情况下,同样依次采用N个第二设备中每个第二设备分别对应的射频系数,向每个第二设备发送该第i+1个信号。也就是在第一设备侧第i个信号会发送N次、且不同次会发向不同的第二设备,从而使得每个第二设备均可以接收到相同的第i个信号;相应的,在任意一个第二设备侧接收一次第i个信号。
以任意一个第二设备为目标第二设备、目标第二设备为tagn来说,该tagn接收到的第i个信号,可以表示为riHnwn,其中,ri为第i个信号,其他内容的含义与前述实施例相同;由于通过射频系数wn可以抵消掉Hn,因此在tagn接收到的信号应为ri,也就是riHnwn=riIn_n×1,其中,In_n×1表示n_n行1列的单位向量,n_n表示Hn的行数,即tag的个数,在本实施例中n_n为1,因为本实施例中一个tag对应一个Hn
在一些实施例中,若相干时间很长、即信道环境处于静态环境,则第一设备无需重复执行前述第一设备向所述每个第二设备发送组密钥生成信令至计算所述每个第二设备与所述第一设备间的信道特征、和计算每个第二设备对应的射频系数的处理。也就是第一设备计算得到每个第二设备对应的射频系数之后,可以执行向多个第二设备中的每个第二设备发送多个信号的处理,针对相同的第二设备采用相同的射频系数发送多个信号中的不同信号。
若相干时间较短、也就是信道环境时变,则第一设备可以重复前述处理。比如,若要执行发送第i个信号的处理,则第一设备需要执行向所述每个第二设备发送组密钥生成信令至计算所述每个第二设备与所述第一设备间的信道特征、计算每个第二设备对应的射频系数的处理,然后基于每个第二设备对应的射频系数,向每个第二设备发送第i个信号;若要执行发送第i+1个信号的处理,则第一设备再次执行向所述每个第二设备发送组密钥生成信令至计算所述每个第二设备与所述第一设备间的信道特征、和计算每个第二设备对应的射频系数的处理,然后基于每个第二设备对应的射频系数,向每个第二设备发送第i+1个信号。
若相干时间较短、也就是信道环境时变,则第一设备还可以根据具体的相干时长,来确定何时重复执行向所述每个第二设备发送组密钥生成信令至计算所述每个第二设备与所述第一设备间的信道特征、计算每个第二设备对应的射频系数的处理。比如,相干时长内可以向每个第二设备发送B个信号(B可以为大于或等于1的整数),则在完成发送第1~第B个信号之后、向每个第二设备发送第B+1个信号之前,再次执行向所述每个第二设备发送组密钥生成信令至计算所述每个第二设备与所述第一设备间的信道特征、计算每个第二设备对应的射频系数的处理,然后基于每个第二设备对应的射频系数,向每个第二设备发送第A+1个信号,下一次循环以此类推,不做赘述。
关于该相干时间的说明与前述实施例为相同,不做重复说明。
在一些可能的实施方式中,所述第一设备基于所述多个信号的相关信息,生成第一组密钥,包括:所述第一设备基于所述多个信号的相关信息,得到多个第一量化结果;所述第一设备基于所述多个第一量化结果,生成所述第一组密钥。
在前述实施例所说明的第一设备向每个第二设备发送多个信号的处理中,以任意一个信号为第i个信号为例,第一设备可以是基于不同的第二设备的射频系数向不同的第二设备发送第i个信号,也 可以是基于不同组对应的射频系数向不同组的每个第二设备发送第i个信号,关于第i个信号发送的次数取决于第二设备的数量、或分组的数量,但是无论哪种方式,第一设备自身均可以得到第i个信号的相关信息,也就是第一设备自身可以得到每个信号的相关信息。
仍然以任意一个信号为第i个信号为例,所述第一设备基于所述多个信号的相关信息,得到多个第一量化结果,包括:所述第一设备基于所述多个信号中第i个信号的相关信息,确定所述第i个信号对应的第一量化范围,将所述第一量化范围对应的第一量化值作为所述多个第一量化结果中的第i个第一量化结果,其中,所述第一量化范围为多个第一候选量化范围中之一,所述多个第一候选量化范围中每个第一候选量化范围具备对应的第一候选量化值,i为正整数。
需要指出,第一设备针对每个信号都执行与第i个信号相同的处理,最终可以得到多个量化结果,本实施例以第i个信号进行详述,不再对每个信号进行一一赘述。
在一些实施例中,所述第一设备的处理还可以包括:所述第一设备可以基于多个信号的相关信息,确定相关信息取值范围的最大值和最小值;基于量化阶数Q,将相关信息取值范围划分为Q个第一候选量化范围,并确定Q个第一候选量化范围中每个第一候选量化范围对应的第一候选量化值,Q为大于或等于2的整数。
这里,所述量化阶数Q可以根据实际情况设置,比如可以是16、32、8、4、5、21或更大或更小,这里不对Q全部可能的取值进行穷举。前述每个第一候选量化范围对应的第一候选量化值可以根据实际情况设置,任意一个第一候选量化值可以为二进制的,且第一候选量化值的长度可以与量化阶数相关,比如第一候选量化值的长度可以等于log2Q个比特(bit)。示例性的,第一候选量化值可以为长度为log2Q的格雷码。
所述第一设备基于所述多个信号中第i个信号的相关信息,确定所述第i个信号对应的第一量化范围,将所述第一量化范围对应的第一量化值作为所述多个第一量化结果中的第i个第一量化结果,可以指的是:所述第一设备确定所述多个信号中第i个信号的相关信息,在Q个第一候选量化范围中所对应的第一量化范围,将所述第一量化范围对应的第一量化值作为所述多个第一量化结果中的第i个第一量化结果。应理解的是,前述确定Q个第一候选量化范围、以及每个第一候选量化范围对应的第一候选量化值可以仅执行一次,然后可以基于前述Q个第一候选量化范围、以及每个第一候选量化范围对应的第一候选量化值,分别确定每个信号的相关信息所对应的量化结果,这里不做一一赘述。
在一些实施例中,为了减少量化边界左右微小误差导致的量化结果的不同,第一设备还可以对所有获取的信号的相关信息就近取整,再确定前述Q个第一候选量化范围、以及每个第一候选量化范围对应的第一候选量化值;和/或,在对每个信号进行量化的处理时,也可以对每个信号的相关信息就近取整,然后进行量化。
需要指出,前述实施例仅为对多个信号的相关信息进行量化的一种示例性说明,实际处理中,本实施例可以使用的量化方法可以不局限于此处所述的方法,比如还可以采用奇异值分解的方法、还可以为其他量化方法,本实施例不对其进行限定和穷举。
在一些实施例中,所述多个信号的相关信息,包括以下至少之一:所述多个信号中每个信号的强度、所述每个信号的相位。
需要指出,每个信号的强度也可以替换性描述为每个信号的幅度。
举例来说,前述多个信号的相关信息包括每个信号的强度。则所述第一设备的处理还可以包括:所述第一设备基于每个信号的强度P,确定全部信号的强度取值范围(即P的取值范围)的最大值(Pmax)和最小值(Pmin),也就是Pmin≤P≤Pmax;然后基于量化阶数Q,将P的取值范围划分为Q个第一候选量化范围,并确定Q个第一候选量化范围中每个第一候选量化范围对应的长度为log2Q的格雷码。为了减少量化边界左右微小误差导致的量化结果的不同,第一设备还可以对所有获取的信号的强度P就近取整,再确定前述Q个第一候选量化范围、以及每个第一候选量化范围对应的第一候选量化值;和/或,在对每个信号进行量化处理时,也可以对每个信号的强度P就近取整,然后进行量化。这种示例中,Q个第一候选量化范围还可以称为Q个第一候选强度量化范围。在一些可能的示例中,所述第一设备发送每个信号时,发送的可以是每个信号的强度的相关值,比如,可以是信号的强度的开平方值、或信号的强度的原值、或信号的强度的开多次方值等等,这里不对其全部可能的情况进行穷举。
举例来说,前述多个信号的相关信息包括每个信号的相位。则所述第一设备的处理还可以包括:所述第一设备基于每个信号的相位确定全部信号的相位取值范围(即的取值范围)的最大值和最小值也就是然后基于量化阶数Q,将的取值范围划分为Q个第一候选量化范围,并确定Q个第一候选量化范围中每个第一候选量化范围对应的长度为log2Q 的格雷码。为了减少量化边界左右微小误差导致的量化结果的不同,第一设备还可以对所有获取的信号的相位就近取整,再确定前述Q个第一候选量化范围、以及每个第一候选量化范围对应的第一候选量化值;和/或,在对每个信号进行量化处理时,也可以对每个信号的相位就近取整,然后进行量化。这种示例中,Q个第一候选量化范围还可以称为Q个第一候选相位量化范围。
应理解,以上仅为示例性说明,实际处理中,可以将每个信号的强度和相位结合使用,比如可以既得到Q个第一候选强度量化范围又得到Q个第一候选相位量化范围,然后第q个第一候选强度量化范围和第q个第一候选相位量化范围对应于同一个量化值,其中,q为大于等于1且小于等于Q的整数,或者q为大于等于0且小于等于Q-1个整数。在对第i个信号进行量化的时候,可以根据第i个信号的强度和相位中任意之一,来确定对应的第一量化范围,进而确定量化结果,又或者,可以将第i个信号的强度和相位均对应的第一强度量化范围和第一相位量化范围,若两者一致,则确定任意一种第一量化范围对应的第一量化值为量化结果,若两者不一致,则可以指定以其中任意之一为准,比如统一指定以信号的强度为准,这里不对全部可能的示例进行穷举。
在一些实施例中,所述第一设备基于所述多个第一量化结果,生成所述第一组密钥,可以为:所述第一设备基于指定顺序将所述多个第一量化结果合并,得到所述第一组密钥。
其中,所述指定顺序可以根据实际情况设置。在一些实施例中,该指定顺序可以是正序,也就是第一组密钥可以是“第1个第一量化结果、第2个第一量化结果…最后一个第一量化结果”这样排列后合并组成的。在一些实施例中,该指定顺序可以是倒序,也就是第一组密钥可以是“最后一个第一量化结果、倒数第2个第一量化结果…第1个第一量化结果”这样排列后合并组成的。在一些实施例中,该指定顺序可以是乱序的,比如一共有4个第一量化结果,指定顺序可以为2、4、3、1,也就是第一组密钥可以是“第2个第一量化结果、第4个第一量化结果、第3个第一量化结果、第1个第一量化结果”这样排列后合并组成的,关于这种实施例下该指定顺序可以根据实际情况来设置,这里不做穷举。应理解,以上也仅为示例性说明,只要保证每个第二设备和第一设备均采用相同的指定顺序,就在本实施例保护范围内。
在一些实施例中,所述第一设备基于所述多个第一量化结果,生成所述第一组密钥,可以为:所述第一设备基于预设计算方式对所述多个第一量化结果计算得到所述第一组密钥。
本实施例中,该预设计算方式可以根据实际情况设置,比如可以是异或计算、直连计算、函数等等任意一种或多种的组合。举例来说,可以采用异或计算,也就是将全部第一量化结果进行异或计算得到第一组密钥。再举例来说,可以采用函数计算,比如函数为密钥派生函数(KDF,Key Derivation Function),则可以将多个第一量化结果均作为KDF的输入,通过KDF计算得到第一组密钥。需要指出,以上也仅为示例性说明,只要保证每个第二设备和第一设备均采用相同的预设计算方式,就在本实施例保护范围内。
在一些可能的实施方式中,所述目标第二设备基于所述多个信号的相关信息,生成第二组密钥,包括:所述目标第二设备基于所述多个信号的相关信息,得到多个第二量化结果;所述目标第二设备基于所述多个第二量化结果,生成所述第二组密钥。
在前述实施例已经说明,目标第二设备为设备组中的全部第二设备中任意之一,关于设备组中每个第二设备的处理与目标第二设备相同,因此这里不做一一赘述。
这里将目标第二设备生成的组密钥称为第二组密钥,原因是目标第二设备基于接收到的多个信号进行第二组密钥的生成,与第一设备的执行主体不同,可能会使得目标第二设备与第一设备所得到的组密钥相同或不同,还需要进一步校验才可以确定目标第二设备生成的第二组密钥是否与第一设备生成的第一组密钥相同,因此,本实施例将目标第二设备(也就是任意一个第二设备)所生成的组密钥、与第一设备所生成的组密钥,区分表示。应理解的是,在理想状态下,目标第二设备(也就是任意一个第二设备)所生成的组密钥、与第一设备所生成的组密钥应为相同的,也就是理想状态下,第一组密钥可以等于第二组密钥。
在一些实施例中,所述目标第二设备基于所述多个信号的相关信息,得到多个第二量化结果,包括:所述目标第二设备基于所述多个信号中第i个信号的相关信息,确定所述第i个信号对应的第二量化范围,将所述第二量化范围对应的第二量化值作为所述多个第二量化结果中的第i个第二量化结果,其中,所述第二量化范围为多个第二候选量化范围中之一,所述多个第二候选量化范围中每个第二候选量化范围具备对应的第二候选量化值,i为正整数。需要指出,目标第二设备针对每个信号都执行与第i个信号相同的处理,最终可以得到多个量化结果,本实施例以第i个信号进行说明,不再对每个信号进行一一赘述。
在一些实施例中,所述目标第二设备的处理还可以包括:所述目标第二设备可以基于多个信号的相关信息,确定相关信息取值范围的最大值和最小值;基于量化阶数Q,将相关信息取值范围划分为 Q个第二候选量化范围,并确定Q个第二候选量化范围中每个第二候选量化范围对应的第二候选量化值,Q为大于或等于2的整数。
关于该目标第二设备确定Q个第二候选量化范围,并确定Q个第二候选量化范围中每个第二候选量化范围对应的第二候选量化值的具体处理方式,与前述第一设备确定Q个第一候选量化范围,并确定Q个第一候选量化范围中每个第一候选量化范围对应的第一候选量化值的具体处理方式是相同的,因此不做重复说明。
所述目标第二设备基于所述多个信号中第i个信号的相关信息,确定所述第i个信号对应的第二量化范围,将所述第二量化范围对应的第二量化值作为所述多个第二量化结果中的第i个第二量化结果,可以指的是:所述目标第二设备确定所述多个信号中第i个信号的相关信息,在Q个第二量化范围中所对应的第二量化范围,将所述第二量化范围对应的第二量化值,作为所述多个第二量化结果中的第i个第二量化结果。关于目标第二设备得到第i个第二量化结果的处理,也与前述第一设备得到第i个第一量化结果的方式相同,不做赘述。
在一些实施例中,所述多个信号的相关信息,同样包括以下至少之一:所述多个信号中每个信号的强度、所述每个信号的相位。关于信号的相关信息为强度和/或相位的不同情况下,目标第二设备确定Q个第二候选量化范围、以及每个第二候选量化范围对应的第二候选量化值的具体说明,与前述第一设备确定Q个第一候选量化范围、以及每个第一候选量化范围对应的第一候选量化值的具体说明是相似的,不做赘述。
在一些可能的示例中,信号的相关信息为信号的强度的情况下,目标第二设备接收每个信号时,可以是接收每个信号的强度的相关值,比如,可以是信号的强度的开平方值、或信号的强度的原值、或信号的强度的开多次方值等等,这里不对其全部可能的情况进行穷举;相应的,目标第二设备可以是对该每个信号的强度的相关值的平方、或原值、或多次方值,然后再确定Q个第二候选量化范围、以及每个第二候选量化范围对应的第二候选量化值,关于确定Q个第二候选量化范围、以及每个第二候选量化范围对应的第二候选量化值的具体处理不做赘述。
在一些实施例中,所述目标第二设备基于所述多个第二量化结果,生成所述第二组密钥,可以为:所述目标第二设备基于指定顺序将所述多个第二量化结果合并,得到所述第二组密钥。关于其中的指定顺序的说明,以及具体的合并处理,均与前述第一设备基于指定顺序将所述多个第一量化结果合并,得到所述第一组密钥的处理是相同的,不做赘述。
在一些实施例中,所述目标第二设备基于所述多个第二量化结果,生成所述第二组密钥,可以为:所述目标第二设备基于预设计算方式对所述多个第二量化结果计算得到所述第二组密钥。关于预设计算方式的具体说明也与前述第一设备的相关说明相同,不做重复说明。
需要指出,无论采用前述指定顺序还是预设计算方式,第一设备和每个第二设备均需要采用相同的方式分别生成各自的组密钥,这里不做重复说明。
在一些可能的实施方式中,所述多个信号的相关信息包括所述多个信号中每个信号携带的密钥序列;所述第一设备基于所述多个信号的相关信息,生成第一组密钥,包括:所述第一设备基于所述多个信号中每个信号携带的密钥序列,生成所述第一组密钥。
这里,不同信号所携带的密钥序列,可以是第一设备随机生成的,关于第一设备生成每个密钥序列的方式,本实施例不做限定。
所述多个信号中第j个信号携带一个或多个数据段,所述一个或多个数据段中不同的数据段为基于不同的第二设备的标识和第j个密钥序列计算的,j为正整数。
在一些实施例中,所述多个信号指的是发送至每个第二设备的多个信号。
一种情况下,该第一设备可以是分别基于每个第二设备对应的射频系数向每个第二设备发送信号的,也就是同一个信号内容在这种情况下会分别向每个第二设备发送,最终发送多次。
这种情况下,若第一设备要发送内容为第j个密钥序列的信号,则需要分别发送给N个第二设备,N的取值定义与前述实施例相同,不做赘述。在发送至第n个第二设备的第j个信号中可以携带一个数据段,该数据段为基于第n个第二设备的标识和第j个密钥序列计算的;依次类推,发送至第n+1个第二设备的第j个信号可以携带一个数据段,该数据段为基于第n+1个第二设备的标识和第j个密钥序列计算的,这里不做穷举。
其中,计算的方式可以根据实际情况设置,比如可以是直连计算、异或计算、函数计算中一种或多种方式。举例来说,计算的方式为异或计算,发送至第n个第二设备的第j个信号表示为rjn,rjn的帧结构(也就是rjn的数据段)设计为:其中,表示异或运算,表示第n个tag的ID号,kj为reader端随机生成的第j个密钥序列。
一种情况下,该第一设备可以是分别基于每组第二设备对应的射频系数向每组第二设备中的每个第二设备发送信号的,也就是同一个信号内容在这种情况下会以分组为单位发送多次。
这种情况下,若第一设备要发送内容为第j个密钥序列的信号,则需要分别发送给K组第二设备,也就是发送K次,关于K的取值定义与前述实施例相同,不做赘述。在发送至第k组第二设备的第j个信号中可以携带一个或多个数据段,其中数据段的数量取决于第k组第二设备中包含的第二设备的数量;该一个或多个数据段为基于第k组第二设备中每个第二设备的标识分别和第j个密钥序列计算的。同样的,在发送至第k+1组第二设备的第j个信号中也可以携带一个或多个数据段,其中数据段的数量取决于第k+1组第二设备中包含的第二设备的数量;该一个或多个数据段为基于第k+1组第二设备中每个第二设备的标识分别和第j个密钥序列计算的,依次类推,不做一一赘述。
其中,计算的方式与前述示例的说明相同,不做赘述。举例来说,计算的方式为异或计算,不同的数据段为基于不同的第二设备的标识和第j个密钥序列计算的,可以指的是,第k组第二设备中每个第二设备所对应的数据段为分别采用每个第二设备的标识和第j个密钥序列异或计算得到的。比如,第k次发送第j个密钥序列的时候,第k组第二设备对应的第j个信号可以表示为rjk,rjk的帧结构(也就是rjk的一个或多个数据段)设计为:其中,表示异或运算,表示第k组tag中第n个tag的ID号(即标识),kj为reader端随机生成的第j个密钥序列。
在一些实施例中,所述第一设备基于所述多个信号中每个信号携带的密钥序列,生成所述第一组密钥,可以指的是:所述第一设备基于指定顺序将所述每个信号携带的密钥序列合并,得到所述第一组密钥。关于该指定顺序可以与前述实施例为相同的,不做赘述。
在一些实施例中,所述第一设备基于所述多个信号中每个信号携带的密钥序列,生成所述第一组密钥,可以指的是:所述第一设备基于预设计算方式对所述每个信号携带的密钥序列计算得到所述第一组密钥。关于该预设计算方式可以与前述实施例为相同的,不做赘述。
在一些实施方式中,所述多个信号的相关信息包括所述多个信号中每个信号携带的密钥序列;所述目标第二设备基于所述多个信号的相关信息,生成第二组密钥,包括:所述目标第二设备基于所述多个信号中每个信号携带的密钥序列,生成所述第二组密钥。
其中,所述多个信号中第j个信号携带一个或多个数据段,所述一个或多个数据段中不同的数据段为基于不同的第二设备的标识和第j个密钥序列计算的;所述方法还包括:所述目标第二设备从所述第j个信号中,提取所述目标第二设备对应的目标数据段,j为正整数;所述目标第二设备基于所述目标第二设备的标识和所述目标数据段,计算所述第j个信号携带的第j个密钥序列。其中,计算的方式应与第一设备的计算方式相同,这里不做重复说明。
一种情况下,该第一设备可以是分别基于每个第二设备对应的射频系数向每个第二设备发送信号的。这种情况下,在第一设备发送至目标第二设备的第j个信号中可以携带一个数据段,该数据段为基于目标第二设备的标识和第j个密钥序列计算的,则目标第二设备可以从该第j个信号中直接提取该数据段作为目标数据段,然后基于自身的标识与目标数据段进行计算,可以得到第j个密钥序列。举例来说,计算的方式为异或计算,目标第二设备为第n个tag,则其提取的数据段可以为则第n个tag仍采用自身的ID与上述数据段再次进行异或,就可以得到kj(第j个密钥序列),关于上述表达式中各个内容的含义与前述示例相同,不做赘述。
一种情况下,该第一设备可以是分别基于每组第二设备对应的射频系数向每组第二设备中的每个第二设备发送信号的。这种情况下,若目标第二设备为第k组第二设备中之一,则目标第二设备仅会接收到第一设备第k次发送的第j个信号(即携带第j个密钥序列的信号),在第k次发送的第j个信号中可以携带一个或多个数据段,目标第二设备可以从该第j个信号中直接提取自身对应的数据段作为目标数据段,然后基于自身的标识与目标数据段进行计算,可以得到第j个密钥序列。
关于这种情况中,目标第二设备所对应的数据段的位置,可以是根据实际情况设置的,比如目标第二设备为第k组第二设备中的第n个第二设备,其对应的数据段的位置可以是第n个位置处、或者也可以是其他指定位置处,本实施例不对其进行限定,只要保证第k组第二设备中不同的第二设备对应的数据段的位置不同,就在本实施例保护范围内。
举例来说,计算的方式为异或计算,第一设备第k次发送第j个密钥序列的时候,第k组第二设备对应的第j个信号可以表示为rjk,rjk的帧结构(也就是rjk的一个或多个数据段)为:假设目标第二设备为第n个tag、且其对应的数据段的位置为第n个位置,则可以从rjk中提取第n个数据段,即作为目标数据段,然后基于自身的标识再次进行异或计算,即可得到kj(第j个密钥序列),关于上述表达式中各个内容的含义与前述示例相同,不做赘述。
在一些可能的实施方式中,所述多个信号用于所述每个第二设备生成第二组密钥,所述方法还包括:所述第一设备基于所述第一组密钥,计算组密钥校验信息,其中,所述组密钥校验信息用于所述每个第二设备校验所述第二组密钥与所述第一组密钥的一致性;所述第一设备向所述每个第二设备发送第一消息,其中,所述第一消息携带所述组密钥校验信息。
以设备组中的任意一个第二设备为目标第二设备为例,该目标第二设备的处理中,所述方法还包括:所述目标第二设备接收来自所述第一设备的第一消息,其中,所述第一消息携带组密钥校验信息,所述组密钥校验信息为所述第一设备基于第一组密钥计算的,所述第一组密钥为所述第一设备基于所述多个信息生成的;所述目标第二设备基于所述第二组密钥计算验证信息;所述目标第二设备基于所述组密钥校验信息和所述验证信息,校验所述第二组密钥与所述第一组密钥的一致性。
关于每个第二设备生成第二组密钥的方式,在前述实施例中已经详述,这里不做重复说明。
本实施方式中,第一设备在得到自身的组密钥即第一组密钥之后,还可以发起校验处理,以确定各个第二设备生成的第二组密钥与自身的第一组密钥是否相同。
在一些实施例中,所述第一设备基于所述第一组密钥,计算组密钥校验信息,可以为:所述第一设备将所述第一组密钥通过第一预设函数进行映射得到第一数值,将该第一数值作为组密钥校验信息。该第一预设函数可以是哈希(hash)函数,该哈希函数所采用的具体算法,可以根据实际情况设置,本实施例不对其进行限定,另外,该第一预设函数也可以是其他类型的函数,只要通过该函数可以得到对应的映射数值,就在本实施例保护范围内。
在一些实施例中,所述第一设备基于所述第一组密钥,计算组密钥校验信息,可以为:所述第一设备计算所述第一组密钥的循环冗余校验(CRC,Cyclic Redundancy Check)码,将CRC(码)作为组密钥校验信息。该CRC计算所采用的具体算法,可以根据实际情况设置,本实施例不对其进行限定。
所述第一设备向所述每个第二设备发送第一消息的方式,可以是组播、广播或单播,均在本实施例保护范围内。在一种优选的示例中,第一设备可以是向全部第二设备广播该第一消息。
在一些实施例中,所述目标第二设备基于所述第二组密钥计算验证信息,可以为:所述目标第二设备将所述第二组密钥通过第一预设函数进行映射得到第二数值,将该第二数值作为验证信息。该第一预设函数与前述实施例相同,不做赘述。
在一些实施例中,所述目标第二设备基于所述第二组密钥计算验证信息,可以为:所述目标第二设备计算所述第二组密钥的循环冗余校验(CRC,Cyclic Redundancy Check)码,将第二组密钥的CRC(码)作为验证信息。
需要指出的是,目标第二设备(也就是任意一个第二设备)计算验证信息的具体处理方式,应与第一设备基于组密钥校验信息的方式为相同的。
在一些实施例中,所述方法还包括以下至少之一:所述目标第二设备在所述第二组密钥与所述第一组密钥一致的情况下,所述目标第二设备向所述第一设备发送第二消息,其中,所述第二消息用于指示所述目标第二设备对所述第二组密钥与所述第一组密钥的一致性校验成功;所述目标第二设备在所述第二组密钥与所述第一组密钥不一致的情况下,所述目标第二设备向所述第一设备发送第三消息,其中,所述第三消息用于指示所述目标第二设备对所述第二组密钥与所述第一组密钥的一致性校验失败。
相应的,第一设备的处理中,所述方法还包括以下之一:所述第一设备接收来自目标第二设备的第二消息,其中,所述第二消息用于指示所述目标第二设备对所述第二组密钥与所述第一组密钥的一致性校验成功,所述目标第二设备为所述多个第二设备中之一;所述第一设备接收来自所述目标第二设备的第三消息,其中,所述第三消息用于指示所述目标第二设备对所述第二组密钥与所述第一组密钥的一致性校验失败。
若第一设备接收到目标第二设备发来第二消息,则第一设备可以记录该目标第二设备为成功生成组密钥的第二设备,然后使用第一组密钥与该目标第二设备进行通信;这里,通信可以指的是基于第一组密钥对接收到的数据进行解密和/或基于第一组密钥对发送的数据进行加密。也就是说,第一设备接收到任意一个第二设备发来的第二消息的情况下,就可以确定该第二设备生成组密钥成功,记录该第二设备并与该第二设备进行通信。
同样的,若目标第二设备发送第二消息,则该目标第二设备可以使用第二组密钥与第一设备进行通信;这里,通信可以指的是基于第二组密钥对接收到的数据进行解密和/或基于第二组密钥对发送的数据进行加密。
若第一设备接收到目标第二设备发来的第三消息,则第一设备可以下一次继续向该目标第二设备执行前述处理,以使得目标第二设备生成与第一组密钥相同的第二组密钥。同样的,若目标第二设备发送第三消息,则该目标第二设备可以等待下一次生成组密钥。
在一些可能的实施方式中,所述多个信号用于所述每个第二设备生成第二组密钥,所述方法还包括:所述第一设备基于所述第一组密钥,计算组密钥纠错信息,其中,所述组密钥纠错信息用于所述每个第二设备对所述第二组密钥纠错得到与所述第一组密钥一致的组密钥;所述第一设备向所述每个第二设备发送第四消息,其中,所述第四消息携带所述组密钥纠错信息。
以设备组中的任意一个第二设备为目标第二设备为例,该目标第二设备的处理中,所述方法还包括:所述目标第二设备接收来自所述第一设备的第四消息,其中,所述第四消息携带组密钥纠错信息,所述组密钥纠错信息为所述第一设备基于第一组密钥计算的,所述第一组密钥为所述第一设备基于所述多个信息生成的;所述目标第二设备基于所述组密钥纠错信息对所述第二组密钥进行纠错,得到与所述第一组密钥一致的组密钥。
所述第一设备基于所述第一组密钥,计算组密钥纠错信息,可以是第一设备基于第二预设计算方式对所述第一组密钥,计算得到校验码,将该校验码作为组密钥纠错信息。所述目标第二设备基于所述组密钥纠错信息对所述第二组密钥进行纠错,得到与所述第一组密钥一致的组密钥,可以为:所述目标第二设备基于第二预设方式所对应的纠错方式,采用组密钥纠错信息对所述第二组密钥进行译码纠错,得到与所述第一组密钥一致的组密钥。
其中,第二预设计算方式所采用的计算函数(或计算方式)可以根据实际情况设置,比如,可以采用LDPC(Low Density Parity-check Codes,低密度奇偶校验码)、Turbo译码等等任意一种或多种函数,这里不对全部可能的方式进行穷举,只要能够对序列进行编码以得到校验码,从而使得对端进行译码纠错,就在本实施例保护范围内。
在一些可能的实施方式中,所述第一设备可以触发更新组密钥。
在一些实施例中,第一设备可以周期性触发更新组密钥。该周期性的周期时长可以根据实际情况设置,比如可以是7天、1天、或更长或更短,这里不对其进行穷举。
在一些实施例中,第一设备可以是在设备组中增加或减少第二设备的情况下触发更新组密钥。该第一设备确定设备组中增加或减少第二设备的方式,可以是该第一设备可以接收网络设备发来的指示信息,该指示信息用于指示设备组中新增第二设备或移除第二设备,该网络设备可以是接入网设备、或核心网设备、或应用功能(AF)等等,这里不对其进行穷举。
该第一设备更新组密钥的处理方式,可以是再次执行前述实施例所提供的方式,以使得自身以及设备组中的当前各个第二设备均更新组密钥。
结合以下多个示例,均以第一设备为reader(读写器),设备组中总共有N个tag(标签)为例,对本申请所提供的密钥生成方法进行示例性说明。该reader和N个tag组成的系统如图4所示:以reader为圆心,d1为半径的区域内,存在N个tag与reader进行通信。组密钥方案的目的是在reader与N个tag之间生成一个共知的组密钥Gk。同时,存在窃听者试图通过窃听组密钥生成过程中的某些信息,也获得k。为更接近实际场景,假设窃听者不会存在于以reader为圆心,d2为半径的区域内,称为安全区域。
结合图5进行一种示例说明,在图5涉及的方案中,N个tag均为单天线设备,reader配置有M根天线,具体步骤如下:
步骤501:reader广播发射一个组密钥生成信令,比如该组密钥生成信令可以表示为message1。
步骤502:N个tag中所有tag收到此组密钥生成信令后,按照时隙防碰撞机制依次向reader反射导频信号s。
步骤503:reader依次接收每个tag在步骤502所发送的反射导频信号,估计与每个tag间的信道特征。
以N个tag中的tag1为例,具体如下:连续载波(幅度记为1)由reader的第一根天线发射出去,则reader接收到的tag1反射导频信号为:通过接收导频信号,reader可解出tag1与reader之间的信道最终,reader获得所有tag与reader之间的信道:关于本步骤中各个公式内包含的内容的含义,均与前述实施例相同,不做重复说明。
步骤504:reader计算天线权系数。该天线权系数即前述实施例中的射频系数。
本步骤的具体过程如下:reader将H按行分为K组,K=ceil(N/M),ceil(*)表示向上取整;得到第k组信道矩阵为(1≤k≤K):求第k组信道矩阵的右逆矩阵: 计算第k组(即第k组tag)对应的天线权系数:本步骤中各个公式包含的内容的含义,均与前述实施例相同,不做赘述。
步骤505:reader发射信号r,使N个tag接收到的信号都为r。
具体的,reader发K次信号r,也就是reader向N个tag所划分的K组tag中,每组tag分别发送该信号r,在前述实施例中已经说明,向每组tag可以发送多个信号,本步骤中的信号r可以是向每组tag发送的多个信号中的任意之一。
以reader发K次信号的处理中的发送第k次信号为例,也就是reader向第k组tag发送的第i个信号,可以将其表示为ri,第k次的天线权系数为wk,则第k组tag中涉及的第n个tag收到的信号为:riHkwk=riIk_n×1,该公式中各个内容的含义与前述实施例相同,不做赘述。
reader经过K次发射后,网络中所有的tag都将会接收到信号ri,reader也知道ri,所以ri中的信息或特征(即信号的相关信息,也就是第i个信号的相关信息)可以作为密钥源进行量化。
若相干时间很长,即信道环境处于静态环境,则reader无需重复执行步骤501到步骤504,reader只需要多次重复执行步骤505,可以每次都改变信号r(也就是改变信号的相关信息)并再次发射信号r,也就是可以改变步骤505中的r,即可使密钥源时变并再次发射信号。应理解的是,不同次发送信号的时候,reader可以根据实际需求来确定是否改变信号的相关信息,也有一些可能的示例中,可能存在任意两次发送相同的信号,本实施例不对其全部可能的情况进行穷举。
若信道环境时变,则在不同的相干时间内执行步骤501到步骤505即可,只是每次执行步骤505时,可以改变r,使得密钥源时变。
步骤506:经过多次执行步骤505后,reader和所有tag都积累了多个不同r的信息或特征,进而可以确定各自的组密钥。至此,reader得到前述实施例中的第一组密钥,每个tag得到了前述实施例中的各自的第二组密钥。
步骤507:reader和N个tag确定一致的组密钥。
本步骤可以基于tag计算能力,给出不同的最终组密钥确定方法。
方法1:reader将初始密钥序列(即reader的第一组密钥)通过某个hash函数映射为某个值,或者计算该序列的循环冗余校验码(CRC),将哈希映射值或循环冗余校验码广播发射出去,N个tag接收到后,分别根据自己的初始密钥序列(即tag自身的第二组密钥)计算自己的哈希映射值或循环冗余校验码,与接收到reader的数据进行比较,若一致,则返回succes指令。不一致,则返回fail指令,等待下一次组密钥生成。reader记录成功生成组密钥的tag,可利用此次组密钥与这些tag进行通信。
方法2:若N个tag具备某些译码纠错能力(如LDPC、Turbo译码),则reader将初始密钥序列(即reader的第一组密钥)通过某编码方法生成校验码,将校验码发送给N个tag,所有tag利用校验码进行译码纠错(即每个tag对自身的第二组密钥进行译码纠错),从而使得reader和各个tag获得一致的密钥。
上述两个方法中,方法1针对计算能力较弱的tag,无法纠错,如果密钥出现不一致,则需等待下一次组密钥生成。方法2是常用的密钥纠错方法,但对于tag,需要支持具有一定复杂程度的译码算法。
进一步结合上述图5所提供的示例的仿真实验进行说明:reader与tag之间的的信道建模如下:其中,表示路径损耗常数,λc表示载波波长,载波频率取900Mhz。满足瑞利分布,drt是指reader与tag的距离。αrt指路径损耗指数,取2。βrt为莱斯因子,取3。其中,c=[c1 … cM], 1≤m≤M,1≤ntag≤Ntag,其中,dr和dt表示reader和tag中天线之间的距离,取0.5,取0,Ntag=1。M=8, θt=π-θr,(xr,yr)是reader的坐标,这里取为原点。(xt,yt)是tag的坐标,N个tag随 机均匀分布,N=32。通信范围半径d1=50m,d2=5m。量化阶数Q取8,信号r的最小功率Pmin=-20dBm,信号r的最大功率Pmax=20dBm,ref=0.9。
基于上述建模,仿真N个tag与reader之间的密钥不一致率、eve与reader之间的密钥不一致率,结果如图6所示,图6中的“tag”所表示的tag与reader之间的密钥不一致率具体指的是N个tag(的第二组密钥)与reader(的第一组密钥)的密钥不一致率的平均值,通过图6可以看出,随着信噪比的增加,tag与reader之间的密钥不一致率越来越小,比如信噪比在10dB时,tag与reader之间的密钥不一致率在0.3左右,信噪比在30dB时,tag与reader之间的密钥不一致率接近0.05,而窃听者与reader之间的密钥不一致率平稳0.45~0.5附近,说明上述示例可以使得Reader和tag安全生成各自的组密钥。
结合图7进行另一种示例说明,在图7涉及的方案中,信号r的强度作为密钥源,也就是前述实施例中信号的相关信息具体为信号的强度,本示例选择信号r的强度作为密钥源,即不关心信号r的具体内容,只利用其信号强度。具体步骤如下:
步骤701~步骤704的具体说明,与前述示例的步骤501~步骤504相同,因此不做重复说明。
步骤705:reader发射信号r,使N个tag接收到的信号强度一样。
具体过程如下:reader发射信号r的强度记为P,发K次。以第k次为例:第k次的天线权系数为wk,则第k组中涉及的tag收到的信号幅度为:公式中处理P表示信号强度(或幅度)之外,其余内容与前述实施例相同,不做赘述。经过K次发射后,所有的tag都将会记录得到信号强度P,reader也知道P,所以P将会作为密钥源进行量化。
若相干时间很长,即信道环境处于静态环境,则reader无需重复执行步骤701到步骤704,只需要改变步骤705中的P值,即可使密钥源时变。若信道环境时变,则在不同的相干时间内执行步骤701到步骤705即可。
步骤706:经过多次执行步骤705的积累后,假设所有tag获得了L个强度值,reader也已知这L个强度值,则双方开始量化,reader和N个tag获得初始密钥序列,也就是reader得到了第一组密钥,每个tag得到了各自的第二组密钥。具体过程如下:设reader取P的范围为:Pmin≤P≤Pmax。量化阶数为Q时,将P的范围均匀分为Q个,每个范围对应长度为log2Q的格雷码,此时每个强度值对应log2Qbit。为了减少量化边界左右微小误差导致的量化结果的不同,reader和tag可对所有获取的强度值执行就近取整,然后进行量化,至此reader和N个tag获得初始密钥序列。量化方法包括但不局限于此处所述的方法。
步骤707:reader和N个tag确定一致的组密钥。具体的,利用给出的方法1或方法2,reader和N个tag确定最终的一致密钥。
结合图8进行一种示例说明,在图8涉及的方案中,信号r的数据信息作为密钥源,本示例设计将信号r中携带的数据信息,将其作为密钥源,以此抵抗Eve贴近tag或合法信道与非法信道差异性较小的的恶劣窃听场景。具体实施包括以下步骤:
步骤801~步骤804与前述示例中的步骤501~步骤504相同,不做重复说明。
步骤805:reader发射信号r,使N个tag接收到相同组密钥。
具体过程如下:reader发K次信号r。当第k次发射rjk时,rjk的帧结构设计为:当第k组中任意一个tag收到rjk后,取出自身对应的数据段(即目标数据段),然后用自己的ID异或该数据段,获得kj。如此,经过K次发射后,所有的tag都将会得到相同的kj。关于本步骤中公式的内容含义与前述实施例相同,不做赘述。
在同一相干时间内,只需要改变步骤805中的k,即可使密钥源时变。在不同的相干时间内执行步骤801到步骤805即可。
步骤806:将多次积累的不同k(即密钥序列)串联作为组密钥序列。至此,reader得到了第一组密钥(也就是reader得到的组密钥序列),每个tag得到了各自的第二组密钥(也就是每个tag得到的组密钥祖列)。
步骤807:reader和N个tag确定一致的组密钥。也就是利用给出的方法1或方法2,reader和N个tag确定最终的一致密钥。
以上多种示例针对以reader为中心节点,多个tag为子节点的零功耗通信网络,设计了一种物理层组密钥生成方案。该方案通过给读写器多天线配置权系数,使多个tag可同时收到相同的密钥源,从而获得组密钥。从而,有效降低了组密钥生成的时间开销。同时,由于权系数是利用合法信道值计算得到,对于窃听者,合法信道与窃听信道具有差异性,使其无法收到与tag一样的密钥源,从而保 证了组密钥的安全性。进一步通过设计密钥源,可以抵抗不同窃听程度的非法窃听,以此适应不同的应用场景。
本实施例提供的方案中,由第一设备向每个第二设备发送多个信号,该多个信号的射频系数为基于第二设备与第一设备间的信道特征计算得到的,进而第一设备自身也会基于各个信号的相关信息生成用于与各个第二设备通信的组密钥。如此,通过对发送至不同第二设备的信号配置对应于不同第二设备的射频系数,从而能够准确的抵消该第二设备与第一设备之间的信道特征,即抵消该第二设备与第一设备的信道的损耗或干扰,从而在保证降低生成组密钥的时间开销的同时,还保证了组密钥的安全性。
最后,结合相关技术对本实施例的有益效果进一步进行说明。
对于组密钥生成技术的研究,主要分为两类,一类是基于密码学的组密钥生成;一类是基于物理层特征的组密钥生成。其中,基于密码学的组密钥生成,以一个AP(AccessPoint,接入点)和多个STA(Station,站点)生成组密钥的处理为例来说:AP首先与每个STA进行四次握手,生成对应的对密钥,不同STA的对密钥不同;当需要生成组密钥时,AP生成组密钥GTK,然后用对密钥对GTK加密,将加密数据发给STA,STA利用对密钥解密得到GTK,也就是如果有N个STA,就需要发N次GTK。基于物理层特征的组密钥的处理方式可以包括:第一种方式中,中心节点和子节点在一个相干时间内相互交互导频,各自记录信号强度,然后中心节点计算多个强度差,分别发送给子节点,子节点利用自己记录的信号强度和收到的强度差恢复出组密钥;第二种方式中,需要所有子节点配置多天线,子节点将多天线中收到信号的天线记为1,未收到信号的天线记为0,最终获得一个多天线接收信号状态的序列;第三种方式中,通过指定方法,可以保证多个子节点的状态序列相同,因此可将这一状态序列作为组密钥。
然而上述相关技术的组密钥生成方案存在以下问题:
第一,对子节点设备能力要求高。基于密码学的组密钥生成,需要设备支持密钥生成器以及复杂的加解密算法。基于物理层特征的组密钥部分方案中也需要子节点设备具有一定的硬件能力或算法能力。这些对子节点有特别要求的方案,在零功耗网络中不具备普适性,大部分场景下的零功耗设备都是极简的电路设计、低计算力、低存储力,无法支撑这些方案所需。
第二,生成组密钥的时间开销大。这里假设节点到节点的一次单向通信时间为T,一共有N个子节点。以一个AP(AccessPoint,接入点)和多个STA(Station,站点)生成组密钥的处理为例来说,每个子节点生成对秘钥就需要四次握手,最后的组密钥还需要依次发送给每个STA,所以生成组密钥的时间大于2NT。对于基于物理层特征的组密钥,以第一种方式为例来说,生成一次组密钥的时间为2NT,且一个相干时间内,信道不变时,只能进行一次组密钥生成,在相干时间较长的场景下,组密钥不会变化。
而采用本申请实施例所提供的密钥生成方法,首先可以降低组密钥生成的时间开销。具体来说,本申请提供的密钥生成方法所有tag(即每个第二设备)获取一次组密钥的量化结果或密钥序列(也就是获取一次信号的相关信息,或基于一个信号的相关信息得到量化结果或密钥序列)的时间为小于2NT,即低于已有标准(802.11i)中组密钥生成方案的时间开销。再次,本申请提供的密钥生成方法不需要tag(也就是第二设备)增加任何额外的开销,对于零功耗设备tag,不增加任何多余过程,tag只需要执行简单的反射和接收信号就可以实现组秘钥的生成,不需要改变零功耗设备支持的技术和简易的电路设计。最后,即使在相干时间较长的环境中,仍可以使组密钥更新,避免单一密钥使用时间过长的问题。同时,不仅可利用内生信道保护密钥源,也可以通过对信号r进行设计,加强密钥源的保护,抵抗不同窃听程度的窃听者。
图9是根据本申请一实施例的第一设备的组成结构示意图,包括:
第一通信单元901,用于向多个第二设备中的每个第二设备发送多个信号,其中,所述多个信号的射频系数为基于所述每个第二设备与所述第一设备间的信道特征计算得到的;
第一处理单元902,用于基于所述多个信号的相关信息,生成第一组密钥,所述第一组密钥用于所述第一设备与所述多个第二设备的通信。
所述第一通信单元,用于向所述每个第二设备发送组密钥生成信令;接收来自所述每个第二设备的导频信号,其中,所述导频信号为所述组密钥生成信令所对应的反射信号;
所述第一处理单元,用于基于所述每个第二设备的导频信号,计算所述每个第二设备与所述第一设备间的信道特征。
所述第一处理单元,用于基于所述每个第二设备与所述第一设备间的信道特征,计算一个或多个射频系数,其中,所述一个或多个射频系数中不同的射频系数对应不同的第二设备。
所述第一通信单元,用于基于所述一个或多个射频系数中的第k个射频系数,向第k组第二设备中的每个第二设备发送所述多个信号,其中,所述一个或多个射频系数中不同的射频系数对应所述多个第二设备的不同分组、且所述多个第二设备的不同分组中包括不同的第二设备,所述第k组第二设备为所述多个第二设备的一个或多个分组中之一,k为正整数。
所述第一处理单元,用于基于所述多个信号的相关信息,得到多个第一量化结果;基于所述多个第一量化结果,生成所述第一组密钥。
所述第一处理单元,用于基于所述多个信号中第i个信号的相关信息,确定所述第i个信号对应的第一量化范围,将所述第一量化范围对应的第一量化值作为所述多个第一量化结果中的第i个第一量化结果,其中,所述第一量化范围为多个第一候选量化范围中之一,所述多个第一候选量化范围中每个第一候选量化范围具备对应的第一候选量化值,i为正整数。
所述多个信号的相关信息,包括以下至少之一:所述多个信号中每个信号的强度、所述每个信号的相位。
所述多个信号的相关信息包括所述多个信号中每个信号携带的密钥序列;所述第一处理单元,用于基于所述多个信号中每个信号携带的密钥序列,生成所述第一组密钥。
所述多个信号中第j个信号携带一个或多个数据段,所述一个或多个数据段中不同的数据段为基于不同的第二设备的标识和第j个密钥序列计算的,j为正整数。
所述多个信号用于所述每个第二设备生成第二组密钥;所述第一处理单元,用于基于所述第一组密钥,计算组密钥校验信息,其中,所述组密钥校验信息用于所述每个第二设备校验所述第二组密钥与所述第一组密钥的一致性;
所述第一通信单元,用于向所述每个第二设备发送第一消息,其中,所述第一消息携带所述组密钥校验信息。
所述第一通信单元,用于执行以下之一:接收来自目标第二设备的第二消息,其中,所述第二消息用于指示所述目标第二设备对所述第二组密钥与所述第一组密钥的一致性校验成功,所述目标第二设备为所述多个第二设备中之一;接收来自所述目标第二设备的第三消息,其中,所述第三消息用于指示所述目标第二设备对所述第二组密钥与所述第一组密钥的一致性校验失败。
所述多个信号用于所述每个第二设备生成第二组密钥;所述第一处理单元,用于基于所述第一组密钥,计算组密钥纠错信息,其中,所述组密钥纠错信息用于所述每个第二设备对所述第二组密钥纠错得到与所述第一组密钥一致的组密钥;
所述第一通信单元,用于向所述每个第二设备发送第四消息,其中,所述第四消息携带所述组密钥纠错信息。
所述第一设备为以下之一:终端设备、网络设备;所述第二设备为零功耗设备。
图10是根据本申请一实施例的目标第二设备的组成结构示意图,包括:
第二通信单元1001,用于接收来自第一设备的多个信号,其中,所述多个信号的射频系数为基于所述目标第二设备与所述第一设备间的信道特征计算得到的;
第二处理单元1002,用于基于所述多个信号的相关信息,生成第二组密钥,其中,所述第二组密钥用于所述目标第二设备与所述第一设备的通信,所述第二组密钥为多个第二设备相同的密钥、且所述目标第二设备为所述多个第二设备中之一。
所述第二通信单元,用于接收来自所述第一设备的组密钥生成信令;向所述第一设备发送导频信号,其中,所述导频信号为所述组密钥生成信令所对应的反射信号,所述导频信号用于所述第一设备计算所述目标第二设备与所述第一设备间的信道特征。
所述第二处理单元,用于基于所述多个信号的相关信息,得到多个第二量化结果;基于所述多个第二量化结果,生成所述第二组密钥。
所述第二处理单元,用于基于所述多个信号中第i个信号的相关信息,确定所述第i个信号对应的第二量化范围,将所述第二量化范围对应的第二量化值作为所述多个第二量化结果中的第i个第二量化结果,其中,所述第二量化范围为多个第二候选量化范围中之一,所述多个第二候选量化范围中每个第二候选量化范围具备对应的第二候选量化值,i为正整数。
所述多个信号的相关信息,包括以下之一:所述多个信号中每个信号的强度、所述每个信号的相位。
所述多个信号的相关信息包括所述多个信号中每个信号携带的密钥序列;所述第二处理单元,用于基于所述多个信号中每个信号携带的密钥序列,生成所述第二组密钥。
所述多个信号中第j个信号携带一个或多个数据段,所述一个或多个数据段中不同的数据段为基于不同的第二设备的标识和第j个密钥序列计算的;所述第二处理单元,用于从所述第j个信号中, 提取所述目标第二设备对应的目标数据段,j为正整数;基于所述目标第二设备的标识和所述目标数据段,计算所述第j个信号携带的第j个密钥序列。
所述第二通信单元,用于接收来自所述第一设备的第一消息,其中,所述第一消息携带组密钥校验信息,所述组密钥校验信息为所述第一设备基于第一组密钥计算的,所述第一组密钥为所述第一设备基于所述多个信息生成的;
所述第二处理单元,用于基于所述第二组密钥计算验证信息;基于所述组密钥校验信息和所述验证信息,校验所述第二组密钥与所述第一组密钥的一致性。
所述第二通信单元,用于执行以下至少之一:在所述第二组密钥与所述第一组密钥一致的情况下,向所述第一设备发送第二消息,其中,所述第二消息用于指示所述目标第二设备对所述第二组密钥与所述第一组密钥的一致性校验成功;在所述第二组密钥与所述第一组密钥不一致的情况下,向所述第一设备发送第三消息,其中,所述第三消息用于指示所述目标第二设备对所述第二组密钥与所述第一组密钥的一致性校验失败。
所述第二通信单元,用于接收来自所述第一设备的第四消息,其中,所述第四消息携带组密钥纠错信息,所述组密钥纠错信息为所述第一设备基于第一组密钥计算的,所述第一组密钥为所述第一设备基于所述多个信息生成的;
所述第二处理单元,用于基于所述组密钥纠错信息对所述第二组密钥进行纠错,得到与所述第一组密钥一致的组密钥。
所述第一设备为以下之一:终端设备、网络设备;所述目标第二设备为零功耗设备。
本申请实施例的设备能够实现前述的密钥生成方法实施例中的各个设备的对应功能。该第一设备、或目标第二设备中的各个模块(子模块、单元或组件等)对应的流程、功能、实现方式和有益效果,可参见上述方法实施例中的对应描述,在此不再赘述。需要说明,关于申请实施例的第一设备、或目标第二设备中的各个模块(子模块、单元或组件等)所描述的功能,可以由不同的模块(子模块、单元或组件等)实现,也可以由同一个模块(子模块、单元或组件等)实现。
图11是根据本申请实施例的通信设备1100示意性结构图。该通信设备1100包括处理器1110,处理器1110可以从存储器中调用并运行计算机程序,以使通信设备1100实现本申请实施例中的方法。
在一种可能的实现方式中,通信设备1100还可以包括存储器1120。其中,处理器1110可以从存储器1120中调用并运行计算机程序,以使通信设备1100实现本申请实施例中的方法。
其中,存储器1120可以是独立于处理器1110的一个单独的器件,也可以集成在处理器1110中。
在一种可能的实现方式中,通信设备1100还可以包括收发器1130,处理器1110可以控制该收发器1130与其他设备进行通信,具体地,可以向其他设备发送信息或数据,或接收其他设备发送的信息或数据。
其中,收发器1130可以包括发射机和接收机。收发器1130还可以进一步包括天线,天线的数量可以为一个或多个。
在一种可能的实现方式中,该通信设备1100可为本申请实施例的第一设备、或目标第二设备,并且该通信设备1100可以实现本申请实施例的各个方法中由第一设备、或目标第二设备实现的相应流程,为了简洁,在此不再赘述。
在本申请的实施例中提供一种第一设备,包括:处理器,与所述处理器通信的存储器,所述存储器用于存储指令,当所述指令被所述处理器执行时,所述指令使所述第一设备执行:向多个第二设备中的每个第二设备发送多个信号,其中,所述多个信号的射频系数为基于所述每个第二设备与所述第一设备间的信道特征计算得到的;基于所述多个信号的相关信息,生成第一组密钥,所述第一组密钥用于所述第一设备与所述多个第二设备的通信。
所述指令还使所述第一设备执行:向所述每个第二设备发送组密钥生成信令;接收来自所述每个第二设备的导频信号,其中,所述导频信号为所述组密钥生成信令所对应的反射信号;基于所述每个第二设备的导频信号,计算所述每个第二设备与所述第一设备间的信道特征。
所述指令还使所述第一设备执行:基于所述每个第二设备与所述第一设备间的信道特征,计算一个或多个射频系数,其中,所述一个或多个射频系数中不同的射频系数对应不同的第二设备。
所述指令还使所述第一设备执行:基于所述一个或多个射频系数中的第k个射频系数,向第k组第二设备中的每个第二设备发送所述多个信号,其中,所述一个或多个射频系数中不同的射频系数对应所述多个第二设备的不同分组、且所述多个第二设备的不同分组中包括不同的第二设备,所述第k组第二设备为所述多个第二设备的一个或多个分组中之一,k为正整数。
所述指令还使所述第一设备执行:基于所述多个信号的相关信息,得到多个第一量化结果;基于所述多个第一量化结果,生成所述第一组密钥。
所述指令还使所述第一设备执行:基于所述多个信号中第i个信号的相关信息,确定所述第i个信号对应的第一量化范围,将所述第一量化范围对应的第一量化值作为所述多个第一量化结果中的第i个第一量化结果,其中,所述第一量化范围为多个第一候选量化范围中之一,所述多个第一候选量化范围中每个第一候选量化范围具备对应的第一候选量化值,i为正整数。
所述多个信号的相关信息,包括以下至少之一:所述多个信号中每个信号的强度、所述每个信号的相位。
所述多个信号的相关信息包括所述多个信号中每个信号携带的密钥序列;所述指令还使所述第一设备执行:基于所述多个信号中每个信号携带的密钥序列,生成所述第一组密钥。
所述多个信号中第j个信号携带一个或多个数据段,所述一个或多个数据段中不同的数据段为基于不同的第二设备的标识和第j个密钥序列计算的,j为正整数。
所述多个信号用于所述每个第二设备生成第二组密钥;所述指令还使所述第一设备执行:基于所述第一组密钥,计算组密钥校验信息,其中,所述组密钥校验信息用于所述每个第二设备校验所述第二组密钥与所述第一组密钥的一致性;向所述每个第二设备发送第一消息,其中,所述第一消息携带所述组密钥校验信息。
所述指令还使所述第一设备执行以下之一:接收来自目标第二设备的第二消息,其中,所述第二消息用于指示所述目标第二设备对所述第二组密钥与所述第一组密钥的一致性校验成功,所述目标第二设备为所述多个第二设备中之一;接收来自所述目标第二设备的第三消息,其中,所述第三消息用于指示所述目标第二设备对所述第二组密钥与所述第一组密钥的一致性校验失败。
所述多个信号用于所述每个第二设备生成第二组密钥;所述指令还使所述第一设备执行:基于所述第一组密钥,计算组密钥纠错信息,其中,所述组密钥纠错信息用于所述每个第二设备对所述第二组密钥纠错得到与所述第一组密钥一致的组密钥;向所述每个第二设备发送第四消息,其中,所述第四消息携带所述组密钥纠错信息。
所述第一设备为以下之一:终端设备、网络设备;所述第二设备为零功耗设备。
在本申请的实施例中提供一种目标第二设备,包括:处理器,与所述处理器通信的存储器,所述存储器用于存储指令,当所述指令被所述处理器执行时,所述指令使所述目标第二设备执行:接收来自第一设备的多个信号,其中,所述多个信号的射频系数为基于所述目标第二设备与所述第一设备间的信道特征计算得到的;基于所述多个信号的相关信息,生成第二组密钥,其中,所述第二组密钥用于所述目标第二设备与所述第一设备的通信,所述第二组密钥为多个第二设备相同的密钥、且所述目标第二设备为所述多个第二设备中之一。
所述指令还使所述目标第二设备执行:接收来自所述第一设备的组密钥生成信令;向所述第一设备发送导频信号,其中,所述导频信号为所述组密钥生成信令所对应的反射信号,所述导频信号用于所述第一设备计算所述目标第二设备与所述第一设备间的信道特征。
所述指令还使所述目标第二设备执行:基于所述多个信号的相关信息,得到多个第二量化结果;基于所述多个第二量化结果,生成所述第二组密钥。
所述指令还使所述目标第二设备执行:基于所述多个信号中第i个信号的相关信息,确定所述第i个信号对应的第二量化范围,将所述第二量化范围对应的第二量化值作为所述多个第二量化结果中的第i个第二量化结果,其中,所述第二量化范围为多个第二候选量化范围中之一,所述多个第二候选量化范围中每个第二候选量化范围具备对应的第二候选量化值,i为正整数。
所述多个信号的相关信息,包括以下之一:所述多个信号中每个信号的强度、所述每个信号的相位。
所述多个信号的相关信息包括所述多个信号中每个信号携带的密钥序列;所述指令还使所述目标第二设备执行:基于所述多个信号中每个信号携带的密钥序列,生成所述第二组密钥。
所述多个信号中第j个信号携带一个或多个数据段,所述一个或多个数据段中不同的数据段为基于不同的第二设备的标识和第j个密钥序列计算的;所述指令还使所述目标第二设备执行:从所述第j个信号中,提取所述目标第二设备对应的目标数据段,j为正整数;基于所述目标第二设备的标识和所述目标数据段,计算所述第j个信号携带的第j个密钥序列。
所述指令还使所述目标第二设备执行:接收来自所述第一设备的第一消息,其中,所述第一消息携带组密钥校验信息,所述组密钥校验信息为所述第一设备基于第一组密钥计算的,所述第一组密钥为所述第一设备基于所述多个信息生成的;基于所述第二组密钥计算验证信息;基于所述组密钥校验信息和所述验证信息,校验所述第二组密钥与所述第一组密钥的一致性。
所述指令还使所述目标第二设备执行以下至少之一:在所述第二组密钥与所述第一组密钥一致的情况下,向所述第一设备发送第二消息,其中,所述第二消息用于指示所述目标第二设备对所述第二 组密钥与所述第一组密钥的一致性校验成功;在所述第二组密钥与所述第一组密钥不一致的情况下,向所述第一设备发送第三消息,其中,所述第三消息用于指示所述目标第二设备对所述第二组密钥与所述第一组密钥的一致性校验失败。
所述指令还使所述目标第二设备执行:接收来自所述第一设备的第四消息,其中,所述第四消息携带组密钥纠错信息,所述组密钥纠错信息为所述第一设备基于第一组密钥计算的,所述第一组密钥为所述第一设备基于所述多个信息生成的;基于所述组密钥纠错信息对所述第二组密钥进行纠错,得到与所述第一组密钥一致的组密钥。
所述第一设备为以下之一:终端设备、网络设备;所述目标第二设备为零功耗设备。
图12是根据本申请实施例的芯片1200的示意性结构图。该芯片1200包括处理器1210,处理器1210可以从存储器中调用并运行计算机程序,以实现本申请实施例中的方法。
在一种可能的实现方式中,芯片1200还可以包括存储器1220。其中,处理器1210可以从存储器1220中调用并运行计算机程序,以实现本申请实施例中由接入网设备、或第一核心网设备执行的方法。其中,存储器1220可以是独立于处理器1210的一个单独的器件,也可以集成在处理器1210中。
在一种可能的实现方式中,该芯片1200还可以包括输入接口1230。其中,处理器1210可以控制该输入接口1230与其他设备或芯片进行通信,具体地,可以获取其他设备或芯片发送的信息或数据。在一种可能的实现方式中,该芯片1200还可以包括输出接口1240。其中,处理器1210可以控制该输出接口1240与其他设备或芯片进行通信,具体地,可以向其他设备或芯片输出信息或数据。
在一种可能的实现方式中,该芯片可应用于本申请实施例中的第一设备、或目标第二设备,并且该芯片可以实现本申请实施例的各个方法中由第一设备、或目标第二设备实现的相应流程,为了简洁,在此不再赘述。
应理解,本申请实施例提到的芯片还可以称为系统级芯片,系统芯片,芯片系统或片上系统芯片等。
上述提及的处理器可以是通用处理器、数字信号处理器(digital signal processor,DSP)、现成可编程门阵列(field programmable gate array,FPGA)、专用集成电路(application specific integrated circuit,ASIC)或者其他可编程逻辑器件、晶体管逻辑器件、分立硬件组件等。
上述提及的存储器可以是易失性存储器或非易失性存储器,或可包括易失性和非易失性存储器两者。
本申请实施例中的存储器旨在包括但不限于这些和任意其它适合类型的存储器。
图13是根据本申请实施例的通信系统1300的示意性框图。该通信系统1300包括第一设备1310、目标第二设备1320。在上述实施例中,可以全部或部分地通过软件、硬件、固件或者其任意组合来实现。当使用软件实现时,可以全部或部分地以计算机程序产品的形式实现。该计算机程序产品包括一个或多个计算机指令。在计算机上加载和执行该计算机程序指令时,全部或部分地产生按照本申请实施例中的流程或功能。该计算机可以是通用计算机、专用计算机、计算机网络、或者其他可编程装置。该计算机指令可以存储在计算机可读存储介质中,或者从一个计算机可读存储介质向另一个计算机可读存储介质传输。
应理解,在本申请的各种实施例中,上述各过程的序号的大小并不意味着执行顺序的先后,各过程的执行顺序应以其功能和内在逻辑确定,而不应对本申请实施例的实施过程构成任何限定。
所属领域的技术人员可以清楚地了解到,为描述的方便和简洁,上述描述的系统、装置和单元的具体工作过程,可以参考前述方法实施例中的对应过程,在此不再赘述。
以上所述仅为本申请的具体实施方式,但本申请的保护范围并不局限于此,任何熟悉本技术领域的技术人员在本申请揭露的技术范围内,可轻易想到变化或替换,都应涵盖在本申请的保护范围之内。因此,本申请的保护范围应以该权利要求的保护范围为准。

Claims (76)

  1. 一种密钥生成方法,包括:
    第一设备向多个第二设备中的每个第二设备发送多个信号,其中,所述多个信号的射频系数为基于所述每个第二设备与所述第一设备间的信道特征计算得到的;
    所述第一设备基于所述多个信号的相关信息,生成第一组密钥,所述第一组密钥用于所述第一设备与所述多个第二设备的通信。
  2. 根据权利要求1所述的方法,其中,所述方法还包括:
    所述第一设备向所述每个第二设备发送组密钥生成信令;
    所述第一设备接收来自所述每个第二设备的导频信号,其中,所述导频信号为所述组密钥生成信令所对应的反射信号;
    所述第一设备基于所述每个第二设备的导频信号,计算所述每个第二设备与所述第一设备间的信道特征。
  3. 根据权利要求2所述的方法,其中,所述方法还包括:
    所述第一设备基于所述每个第二设备与所述第一设备间的信道特征,计算一个或多个射频系数,其中,所述一个或多个射频系数中不同的射频系数对应不同的第二设备。
  4. 根据权利要求3所述的方法,其中,所述第一设备向多个第二设备中的每个第二设备发送多个信号,包括:
    所述第一设备基于所述一个或多个射频系数中的第k个射频系数,向第k组第二设备中的每个第二设备发送所述多个信号,其中,所述一个或多个射频系数中不同的射频系数对应所述多个第二设备的不同分组、且所述多个第二设备的不同分组中包括不同的第二设备,所述第k组第二设备为所述多个第二设备的一个或多个分组中之一,k为正整数。
  5. 根据权利要求1-4任一项所述的方法,其中,所述第一设备基于所述多个信号的相关信息,生成第一组密钥,包括:
    所述第一设备基于所述多个信号的相关信息,得到多个第一量化结果;
    所述第一设备基于所述多个第一量化结果,生成所述第一组密钥。
  6. 根据权利要求5所述的方法,其中,所述第一设备基于所述多个信号的相关信息,得到多个第一量化结果,包括:
    所述第一设备基于所述多个信号中第i个信号的相关信息,确定所述第i个信号对应的第一量化范围,将所述第一量化范围对应的第一量化值作为所述多个第一量化结果中的第i个第一量化结果,其中,所述第一量化范围为多个第一候选量化范围中之一,所述多个第一候选量化范围中每个第一候选量化范围具备对应的第一候选量化值,i为正整数。
  7. 根据权利要求5或6所述的方法,其中,所述多个信号的相关信息,包括以下至少之一:所述多个信号中每个信号的强度、所述每个信号的相位。
  8. 根据权利要求1-4任一项所述的方法,其中,所述多个信号的相关信息包括所述多个信号中每个信号携带的密钥序列;所述第一设备基于所述多个信号的相关信息,生成第一组密钥,包括:
    所述第一设备基于所述多个信号中每个信号携带的密钥序列,生成所述第一组密钥。
  9. 根据权利要求8所述的方法,其中,所述多个信号中第j个信号携带一个或多个数据段,所述一个或多个数据段中不同的数据段为基于不同的第二设备的标识和第j个密钥序列计算的,j为正整数。
  10. 根据权利要求1-9任一项所述的方法,其中,所述多个信号用于所述每个第二设备生成第二组密钥,所述方法还包括:
    所述第一设备基于所述第一组密钥,计算组密钥校验信息,其中,所述组密钥校验信息用于所述每个第二设备校验所述第二组密钥与所述第一组密钥的一致性;
    所述第一设备向所述每个第二设备发送第一消息,其中,所述第一消息携带所述组密钥校验信息。
  11. 根据权利要求10所述的方法,其中,所述方法还包括以下之一:
    所述第一设备接收来自目标第二设备的第二消息,其中,所述第二消息用于指示所述目标第二设备对所述第二组密钥与所述第一组密钥的一致性校验成功,所述目标第二设备为所述多个第二设备中之一;
    所述第一设备接收来自所述目标第二设备的第三消息,其中,所述第三消息用于指示所述目标第二设备对所述第二组密钥与所述第一组密钥的一致性校验失败。
  12. 根据权利要求1-9任一项所述的方法,其中,所述多个信号用于所述每个第二设备生成第二组密钥,所述方法还包括:
    所述第一设备基于所述第一组密钥,计算组密钥纠错信息,其中,所述组密钥纠错信息用于所述每个第二设备对所述第二组密钥纠错得到与所述第一组密钥一致的组密钥;
    所述第一设备向所述每个第二设备发送第四消息,其中,所述第四消息携带所述组密钥纠错信息。
  13. 根据权利要求1-12任一项所述的方法,其中,所述第一设备为以下之一:终端设备、网络设备;所述第二设备为零功耗设备。
  14. 一种密钥生成方法,包括:
    目标第二设备接收来自第一设备的多个信号,其中,所述多个信号的射频系数为基于所述目标第二设备与所述第一设备间的信道特征计算得到的;
    所述目标第二设备基于所述多个信号的相关信息,生成第二组密钥,其中,所述第二组密钥用于所述目标第二设备与所述第一设备的通信,所述第二组密钥为多个第二设备相同的密钥、且所述目标第二设备为所述多个第二设备中之一。
  15. 根据权利要求14所述的方法,其中,所述方法还包括:
    所述目标第二设备接收来自所述第一设备的组密钥生成信令;
    所述目标第二设备向所述第一设备发送导频信号,其中,所述导频信号为所述组密钥生成信令所对应的反射信号,所述导频信号用于所述第一设备计算所述目标第二设备与所述第一设备间的信道特征。
  16. 根据权利要求14或15所述的方法,其中,所述目标第二设备基于所述多个信号的相关信息,生成第二组密钥,包括:
    所述目标第二设备基于所述多个信号的相关信息,得到多个第二量化结果;
    所述目标第二设备基于所述多个第二量化结果,生成所述第二组密钥。
  17. 根据权利要求16所述的方法,其中,所述目标第二设备基于所述多个信号的相关信息,得到多个第二量化结果,包括:
    所述目标第二设备基于所述多个信号中第i个信号的相关信息,确定所述第i个信号对应的第二量化范围,将所述第二量化范围对应的第二量化值作为所述多个第二量化结果中的第i个第二量化结果,其中,所述第二量化范围为多个第二候选量化范围中之一,所述多个第二候选量化范围中每个第二候选量化范围具备对应的第二候选量化值,i为正整数。
  18. 根据权利要求16或17所述的方法,其中,所述多个信号的相关信息,包括以下之一:所述多个信号中每个信号的强度、所述每个信号的相位。
  19. 根据权利要求14或15所述的方法,其中,所述多个信号的相关信息包括所述多个信号中每个信号携带的密钥序列;所述目标第二设备基于所述多个信号的相关信息,生成第二组密钥,包括:
    所述目标第二设备基于所述多个信号中每个信号携带的密钥序列,生成所述第二组密钥。
  20. 根据权利要求19所述的方法,其中,所述多个信号中第j个信号携带一个或多个数据段,所述一个或多个数据段中不同的数据段为基于不同的第二设备的标识和第j个密钥序列计算的;所述方法还包括:
    所述目标第二设备从所述第j个信号中,提取所述目标第二设备对应的目标数据段,j为正整数;
    所述目标第二设备基于所述目标第二设备的标识和所述目标数据段,计算所述第j个信号携带的第j个密钥序列。
  21. 根据权利要求14-20任一项所述的方法,其中,所述方法还包括:
    所述目标第二设备接收来自所述第一设备的第一消息,其中,所述第一消息携带组密钥校验信息,所述组密钥校验信息为所述第一设备基于第一组密钥计算的,所述第一组密钥为所述第一设备基于所述多个信息生成的;
    所述目标第二设备基于所述第二组密钥计算验证信息;
    所述目标第二设备基于所述组密钥校验信息和所述验证信息,校验所述第二组密钥与所述第一组密钥的一致性。
  22. 根据权利要求21所述的方法,其中,所述方法还包括以下至少之一:
    所述目标第二设备在所述第二组密钥与所述第一组密钥一致的情况下,所述目标第二设备向所述第一设备发送第二消息,其中,所述第二消息用于指示所述目标第二设备对所述第二组密钥与所述第一组密钥的一致性校验成功;
    所述目标第二设备在所述第二组密钥与所述第一组密钥不一致的情况下,所述目标第二设备向所述第一设备发送第三消息,其中,所述第三消息用于指示所述目标第二设备对所述第二组密钥与所述第一组密钥的一致性校验失败。
  23. 根据权利要求14-20任一项所述的方法,其中,所述方法还包括:
    所述目标第二设备接收来自所述第一设备的第四消息,其中,所述第四消息携带组密钥纠错信息,所述组密钥纠错信息为所述第一设备基于第一组密钥计算的,所述第一组密钥为所述第一设备基于所述多个信息生成的;
    所述目标第二设备基于所述组密钥纠错信息对所述第二组密钥进行纠错,得到与所述第一组密钥一致的组密钥。
  24. 根据权利要求14-23任一项所述的方法,其中,所述第一设备为以下之一:终端设备、网络设备;所述目标第二设备为零功耗设备。
  25. 一种第一设备,包括:
    第一通信单元,用于向多个第二设备中的每个第二设备发送多个信号,其中,所述多个信号的射频系数为基于所述每个第二设备与所述第一设备间的信道特征计算得到的;
    第一处理单元,用于基于所述多个信号的相关信息,生成第一组密钥,所述第一组密钥用于所述第一设备与所述多个第二设备的通信。
  26. 根据权利要求25所述的第一设备,其中,所述第一通信单元,用于向所述每个第二设备发送组密钥生成信令;接收来自所述每个第二设备的导频信号,其中,所述导频信号为所述组密钥生成信令所对应的反射信号;
    所述第一处理单元,用于基于所述每个第二设备的导频信号,计算所述每个第二设备与所述第一设备间的信道特征。
  27. 根据权利要求26所述的第一设备,其中,所述第一处理单元,用于基于所述每个第二设备与所述第一设备间的信道特征,计算一个或多个射频系数,其中,所述一个或多个射频系数中不同的射频系数对应不同的第二设备。
  28. 根据权利要求27所述的第一设备,其中,所述第一通信单元,用于基于所述一个或多个射频系数中的第k个射频系数,向第k组第二设备中的每个第二设备发送所述多个信号,其中,所述一个或多个射频系数中不同的射频系数对应所述多个第二设备的不同分组、且所述多个第二设备的不同分组中包括不同的第二设备,所述第k组第二设备为所述多个第二设备的一个或多个分组中之一,k为正整数。
  29. 根据权利要求25-28任一项所述的第一设备,所述第一处理单元,用于基于所述多个信号的相关信息,得到多个第一量化结果;基于所述多个第一量化结果,生成所述第一组密钥。
  30. 根据权利要求29所述的第一设备,其中,所述第一处理单元,用于基于所述多个信号中第i个信号的相关信息,确定所述第i个信号对应的第一量化范围,将所述第一量化范围对应的第一量化值作为所述多个第一量化结果中的第i个第一量化结果,其中,所述第一量化范围为多个第一候选量化范围中之一,所述多个第一候选量化范围中每个第一候选量化范围具备对应的第一候选量化值,i为正整数。
  31. 根据权利要求29或30所述的第一设备,其中,所述多个信号的相关信息,包括以下至少之一:所述多个信号中每个信号的强度、所述每个信号的相位。
  32. 根据权利要求25-28任一项所述的第一设备,其中,所述多个信号的相关信息包括所述多个信号中每个信号携带的密钥序列;所述第一处理单元,用于基于所述多个信号中每个信号携带的密钥序列,生成所述第一组密钥。
  33. 根据权利要求32所述的第一设备,其中,所述多个信号中第j个信号携带一个或多个数据段,所述一个或多个数据段中不同的数据段为基于不同的第二设备的标识和第j个密钥序列计算的,j为正整数。
  34. 根据权利要求25-33任一项所述的第一设备,其中,所述多个信号用于所述每个第二设备生成第二组密钥;所述第一处理单元,用于基于所述第一组密钥,计算组密钥校验信息,其中,所述组密钥校验信息用于所述每个第二设备校验所述第二组密钥与所述第一组密钥的一致性;
    所述第一通信单元,用于向所述每个第二设备发送第一消息,其中,所述第一消息携带所述组密钥校验信息。
  35. 根据权利要求34所述的第一设备,其中,所述第一通信单元,用于执行以下之一:接收来自目标第二设备的第二消息,其中,所述第二消息用于指示所述目标第二设备对所述第二组密钥与所述第一组密钥的一致性校验成功,所述目标第二设备为所述多个第二设备中之一;接收来自所述目标第二设备的第三消息,其中,所述第三消息用于指示所述目标第二设备对所述第二组密钥与所述第一组密钥的一致性校验失败。
  36. 根据权利要求25-33任一项所述的第一设备,其中,所述多个信号用于所述每个第二设备生成 第二组密钥;所述第一处理单元,用于基于所述第一组密钥,计算组密钥纠错信息,其中,所述组密钥纠错信息用于所述每个第二设备对所述第二组密钥纠错得到与所述第一组密钥一致的组密钥;
    所述第一通信单元,用于向所述每个第二设备发送第四消息,其中,所述第四消息携带所述组密钥纠错信息。
  37. 根据权利要求25-36任一项所述的第一设备,其中,所述第一设备为以下之一:终端设备、网络设备;所述第二设备为零功耗设备。
  38. 一种目标第二设备,包括:
    第二通信单元,用于接收来自第一设备的多个信号,其中,所述多个信号的射频系数为基于所述目标第二设备与所述第一设备间的信道特征计算得到的;
    第二处理单元,用于基于所述多个信号的相关信息,生成第二组密钥,其中,所述第二组密钥用于所述目标第二设备与所述第一设备的通信,所述第二组密钥为多个第二设备相同的密钥、且所述目标第二设备为所述多个第二设备中之一。
  39. 根据权利要求38所述的目标第二设备,其中,所述第二通信单元,用于接收来自所述第一设备的组密钥生成信令;向所述第一设备发送导频信号,其中,所述导频信号为所述组密钥生成信令所对应的反射信号,所述导频信号用于所述第一设备计算所述目标第二设备与所述第一设备间的信道特征。
  40. 根据权利要求38或39所述的目标第二设备,其中,所述第二处理单元,用于基于所述多个信号的相关信息,得到多个第二量化结果;基于所述多个第二量化结果,生成所述第二组密钥。
  41. 根据权利要求40所述的目标第二设备,其中,所述第二处理单元,用于基于所述多个信号中第i个信号的相关信息,确定所述第i个信号对应的第二量化范围,将所述第二量化范围对应的第二量化值作为所述多个第二量化结果中的第i个第二量化结果,其中,所述第二量化范围为多个第二候选量化范围中之一,所述多个第二候选量化范围中每个第二候选量化范围具备对应的第二候选量化值,i为正整数。
  42. 根据权利要求40或41所述的目标第二设备,其中,所述多个信号的相关信息,包括以下之一:所述多个信号中每个信号的强度、所述每个信号的相位。
  43. 根据权利要求38或39所述的目标第二设备,其中,所述多个信号的相关信息包括所述多个信号中每个信号携带的密钥序列;所述第二处理单元,用于基于所述多个信号中每个信号携带的密钥序列,生成所述第二组密钥。
  44. 根据权利要求43所述的目标第二设备,其中,所述多个信号中第j个信号携带一个或多个数据段,所述一个或多个数据段中不同的数据段为基于不同的第二设备的标识和第j个密钥序列计算的;所述第二处理单元,用于从所述第j个信号中,提取所述目标第二设备对应的目标数据段,j为正整数;基于所述目标第二设备的标识和所述目标数据段,计算所述第j个信号携带的第j个密钥序列。
  45. 根据权利要求38-44任一项所述的目标第二设备,其中,所述第二通信单元,用于接收来自所述第一设备的第一消息,其中,所述第一消息携带组密钥校验信息,所述组密钥校验信息为所述第一设备基于第一组密钥计算的,所述第一组密钥为所述第一设备基于所述多个信息生成的;
    所述第二处理单元,用于基于所述第二组密钥计算验证信息;基于所述组密钥校验信息和所述验证信息,校验所述第二组密钥与所述第一组密钥的一致性。
  46. 根据权利要求45所述的目标第二设备,其中,所述第二通信单元,用于执行以下至少之一:在所述第二组密钥与所述第一组密钥一致的情况下,向所述第一设备发送第二消息,其中,所述第二消息用于指示所述目标第二设备对所述第二组密钥与所述第一组密钥的一致性校验成功;在所述第二组密钥与所述第一组密钥不一致的情况下,向所述第一设备发送第三消息,其中,所述第三消息用于指示所述目标第二设备对所述第二组密钥与所述第一组密钥的一致性校验失败。
  47. 根据权利要求38-44任一项所述的目标第二设备,其中,所述第二通信单元,用于接收来自所述第一设备的第四消息,其中,所述第四消息携带组密钥纠错信息,所述组密钥纠错信息为所述第一设备基于第一组密钥计算的,所述第一组密钥为所述第一设备基于所述多个信息生成的;
    所述第二处理单元,用于基于所述组密钥纠错信息对所述第二组密钥进行纠错,得到与所述第一组密钥一致的组密钥。
  48. 根据权利要求38-47任一项所述的目标第二设备,其中,所述第一设备为以下之一:终端设备、网络设备;所述目标第二设备为零功耗设备。
  49. 一种第一设备,包括:处理器,与所述处理器通信的存储器,所述存储器用于存储指令,当所述指令被所述处理器执行时,所述指令使所述第一设备执行:向多个第二设备中的每个第二设备发送多个信号,其中,所述多个信号的射频系数为基于所述每个第二设备与所述第一设备间的信道特征计 算得到的;基于所述多个信号的相关信息,生成第一组密钥,所述第一组密钥用于所述第一设备与所述多个第二设备的通信。
  50. 根据权利要求49所述的第一设备,其中,所述指令还使所述第一设备执行:向所述每个第二设备发送组密钥生成信令;接收来自所述每个第二设备的导频信号,其中,所述导频信号为所述组密钥生成信令所对应的反射信号;基于所述每个第二设备的导频信号,计算所述每个第二设备与所述第一设备间的信道特征。
  51. 根据权利要求50所述的第一设备,其中,所述指令还使所述第一设备执行:基于所述每个第二设备与所述第一设备间的信道特征,计算一个或多个射频系数,其中,所述一个或多个射频系数中不同的射频系数对应不同的第二设备。
  52. 根据权利要求51所述的第一设备,其中,所述指令还使所述第一设备执行:基于所述一个或多个射频系数中的第k个射频系数,向第k组第二设备中的每个第二设备发送所述多个信号,其中,所述一个或多个射频系数中不同的射频系数对应所述多个第二设备的不同分组、且所述多个第二设备的不同分组中包括不同的第二设备,所述第k组第二设备为所述多个第二设备的一个或多个分组中之一,k为正整数。
  53. 根据权利要求49-52任一项所述的第一设备,所述指令还使所述第一设备执行:基于所述多个信号的相关信息,得到多个第一量化结果;基于所述多个第一量化结果,生成所述第一组密钥。
  54. 根据权利要求53所述的第一设备,其中,所述指令还使所述第一设备执行:基于所述多个信号中第i个信号的相关信息,确定所述第i个信号对应的第一量化范围,将所述第一量化范围对应的第一量化值作为所述多个第一量化结果中的第i个第一量化结果,其中,所述第一量化范围为多个第一候选量化范围中之一,所述多个第一候选量化范围中每个第一候选量化范围具备对应的第一候选量化值,i为正整数。
  55. 根据权利要求53或54所述的第一设备,其中,所述多个信号的相关信息,包括以下至少之一:所述多个信号中每个信号的强度、所述每个信号的相位。
  56. 根据权利要求49-52任一项所述的第一设备,其中,所述多个信号的相关信息包括所述多个信号中每个信号携带的密钥序列;所述指令还使所述第一设备执行:基于所述多个信号中每个信号携带的密钥序列,生成所述第一组密钥。
  57. 根据权利要求56所述的第一设备,其中,所述多个信号中第j个信号携带一个或多个数据段,所述一个或多个数据段中不同的数据段为基于不同的第二设备的标识和第j个密钥序列计算的,j为正整数。
  58. 根据权利要求49-57任一项所述的第一设备,其中,所述多个信号用于所述每个第二设备生成第二组密钥;所述指令还使所述第一设备执行:基于所述第一组密钥,计算组密钥校验信息,其中,所述组密钥校验信息用于所述每个第二设备校验所述第二组密钥与所述第一组密钥的一致性;向所述每个第二设备发送第一消息,其中,所述第一消息携带所述组密钥校验信息。
  59. 根据权利要求58所述的第一设备,其中,所述指令还使所述第一设备执行以下之一:接收来自目标第二设备的第二消息,其中,所述第二消息用于指示所述目标第二设备对所述第二组密钥与所述第一组密钥的一致性校验成功,所述目标第二设备为所述多个第二设备中之一;接收来自所述目标第二设备的第三消息,其中,所述第三消息用于指示所述目标第二设备对所述第二组密钥与所述第一组密钥的一致性校验失败。
  60. 根据权利要求49-57任一项所述的第一设备,其中,所述多个信号用于所述每个第二设备生成第二组密钥;所述指令还使所述第一设备执行:基于所述第一组密钥,计算组密钥纠错信息,其中,所述组密钥纠错信息用于所述每个第二设备对所述第二组密钥纠错得到与所述第一组密钥一致的组密钥;向所述每个第二设备发送第四消息,其中,所述第四消息携带所述组密钥纠错信息。
  61. 根据权利要求49-60任一项所述的第一设备,其中,所述第一设备为以下之一:终端设备、网络设备;所述第二设备为零功耗设备。
  62. 一种目标第二设备,包括:处理器,与所述处理器通信的存储器,所述存储器用于存储指令,当所述指令被所述处理器执行时,所述指令使所述目标第二设备执行:接收来自第一设备的多个信号,其中,所述多个信号的射频系数为基于所述目标第二设备与所述第一设备间的信道特征计算得到的;基于所述多个信号的相关信息,生成第二组密钥,其中,所述第二组密钥用于所述目标第二设备与所述第一设备的通信,所述第二组密钥为多个第二设备相同的密钥、且所述目标第二设备为所述多个第二设备中之一。
  63. 根据权利要求62所述的目标第二设备,其中,所述指令还使所述目标第二设备执行:接收来自所述第一设备的组密钥生成信令;向所述第一设备发送导频信号,其中,所述导频信号为所述组密 钥生成信令所对应的反射信号,所述导频信号用于所述第一设备计算所述目标第二设备与所述第一设备间的信道特征。
  64. 根据权利要求62或63所述的目标第二设备,其中,所述指令还使所述目标第二设备执行:基于所述多个信号的相关信息,得到多个第二量化结果;基于所述多个第二量化结果,生成所述第二组密钥。
  65. 根据权利要求64所述的目标第二设备,其中,所述指令还使所述目标第二设备执行:基于所述多个信号中第i个信号的相关信息,确定所述第i个信号对应的第二量化范围,将所述第二量化范围对应的第二量化值作为所述多个第二量化结果中的第i个第二量化结果,其中,所述第二量化范围为多个第二候选量化范围中之一,所述多个第二候选量化范围中每个第二候选量化范围具备对应的第二候选量化值,i为正整数。
  66. 根据权利要求64或65所述的目标第二设备,其中,所述多个信号的相关信息,包括以下之一:所述多个信号中每个信号的强度、所述每个信号的相位。
  67. 根据权利要求62或63所述的目标第二设备,其中,所述多个信号的相关信息包括所述多个信号中每个信号携带的密钥序列;所述指令还使所述目标第二设备执行:基于所述多个信号中每个信号携带的密钥序列,生成所述第二组密钥。
  68. 根据权利要求67所述的目标第二设备,其中,所述多个信号中第j个信号携带一个或多个数据段,所述一个或多个数据段中不同的数据段为基于不同的第二设备的标识和第j个密钥序列计算的;所述指令还使所述目标第二设备执行:从所述第j个信号中,提取所述目标第二设备对应的目标数据段,j为正整数;基于所述目标第二设备的标识和所述目标数据段,计算所述第j个信号携带的第j个密钥序列。
  69. 根据权利要求62-68任一项所述的目标第二设备,其中,所述指令还使所述目标第二设备执行:接收来自所述第一设备的第一消息,其中,所述第一消息携带组密钥校验信息,所述组密钥校验信息为所述第一设备基于第一组密钥计算的,所述第一组密钥为所述第一设备基于所述多个信息生成的;基于所述第二组密钥计算验证信息;基于所述组密钥校验信息和所述验证信息,校验所述第二组密钥与所述第一组密钥的一致性。
  70. 根据权利要求69所述的目标第二设备,其中,所述指令还使所述目标第二设备执行以下至少之一:在所述第二组密钥与所述第一组密钥一致的情况下,向所述第一设备发送第二消息,其中,所述第二消息用于指示所述目标第二设备对所述第二组密钥与所述第一组密钥的一致性校验成功;在所述第二组密钥与所述第一组密钥不一致的情况下,向所述第一设备发送第三消息,其中,所述第三消息用于指示所述目标第二设备对所述第二组密钥与所述第一组密钥的一致性校验失败。
  71. 根据权利要求62-68任一项所述的目标第二设备,其中,所述指令还使所述目标第二设备执行:接收来自所述第一设备的第四消息,其中,所述第四消息携带组密钥纠错信息,所述组密钥纠错信息为所述第一设备基于第一组密钥计算的,所述第一组密钥为所述第一设备基于所述多个信息生成的;基于所述组密钥纠错信息对所述第二组密钥进行纠错,得到与所述第一组密钥一致的组密钥。
  72. 根据权利要求62-71任一项所述的目标第二设备,其中,所述第一设备为以下之一:终端设备、网络设备;所述目标第二设备为零功耗设备。
  73. 一种芯片,包括:处理器,用于从存储器中调用并运行计算机程序,使得安装有所述芯片的设备执行如权利要求1至13、或权利要求14至24中任一项所述的方法。
  74. 一种计算机可读存储介质,用于存储计算机程序,当所述计算机程序被设备运行时使得所述设备执行如权利要求1至13、或权利要求14至24中任一项所述的方法。
  75. 一种计算机程序产品,包括计算机程序指令,该计算机程序指令使得计算机执行如权利要求1至13、或权利要求14至24中任一项所述的方法。
  76. 一种计算机程序,所述计算机程序使得计算机执行如权利要求1至13、或权利要求14至24中任一项所述的方法。
PCT/CN2023/096686 2023-05-26 2023-05-26 密钥生成方法和设备 Ceased WO2024243748A1 (zh)

Priority Applications (4)

Application Number Priority Date Filing Date Title
CN202380098567.4A CN121241537A (zh) 2023-05-26 2023-05-26 密钥生成方法和设备
PCT/CN2023/096686 WO2024243748A1 (zh) 2023-05-26 2023-05-26 密钥生成方法和设备
EP23938747.5A EP4723541A1 (en) 2023-05-26 2023-05-26 Key generation method and device
US19/393,960 US20260075411A1 (en) 2023-05-26 2025-11-19 Key generation method, first device, and target second device

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2023/096686 WO2024243748A1 (zh) 2023-05-26 2023-05-26 密钥生成方法和设备

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US19/393,960 Continuation US20260075411A1 (en) 2023-05-26 2025-11-19 Key generation method, first device, and target second device

Publications (1)

Publication Number Publication Date
WO2024243748A1 true WO2024243748A1 (zh) 2024-12-05

Family

ID=93656219

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2023/096686 Ceased WO2024243748A1 (zh) 2023-05-26 2023-05-26 密钥生成方法和设备

Country Status (4)

Country Link
US (1) US20260075411A1 (zh)
EP (1) EP4723541A1 (zh)
CN (1) CN121241537A (zh)
WO (1) WO2024243748A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN119545338A (zh) * 2024-12-27 2025-02-28 甬江实验室 对称密钥生成方法、装置、设备、介质及产品

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103067042A (zh) * 2012-12-14 2013-04-24 中国人民解放军信息工程大学 一种保密通信方法及天线设备
US20140307871A1 (en) * 2013-04-15 2014-10-16 Electronics And Telecommunications Research Institute Method for key establishment using anti-collision algorithm
CN105721142A (zh) * 2016-01-25 2016-06-29 广东工业大学 基于标签id的rfid系统密钥生成方法及装置
CN106603228A (zh) * 2016-12-21 2017-04-26 广东工业大学 一种基于Rabin加密的RFID密钥无线生成方法
CN116095677A (zh) * 2021-11-08 2023-05-09 中国移动通信有限公司研究院 无线密钥生成方法、装置、设备及存储介质

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103067042A (zh) * 2012-12-14 2013-04-24 中国人民解放军信息工程大学 一种保密通信方法及天线设备
US20140307871A1 (en) * 2013-04-15 2014-10-16 Electronics And Telecommunications Research Institute Method for key establishment using anti-collision algorithm
CN105721142A (zh) * 2016-01-25 2016-06-29 广东工业大学 基于标签id的rfid系统密钥生成方法及装置
CN106603228A (zh) * 2016-12-21 2017-04-26 广东工业大学 一种基于Rabin加密的RFID密钥无线生成方法
CN116095677A (zh) * 2021-11-08 2023-05-09 中国移动通信有限公司研究院 无线密钥生成方法、装置、设备及存储介质

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN119545338A (zh) * 2024-12-27 2025-02-28 甬江实验室 对称密钥生成方法、装置、设备、介质及产品

Also Published As

Publication number Publication date
CN121241537A (zh) 2025-12-30
EP4723541A1 (en) 2026-04-08
US20260075411A1 (en) 2026-03-12

Similar Documents

Publication Publication Date Title
US7395427B2 (en) Authenticated key exchange based on pairwise master key
US20090169015A1 (en) Quantum key distribution method, communication system, and communication device
Kumar et al. Key less physical layer security for wireless networks: A survey
Rezki et al. Ergodic secret message capacity of the wiretap channel with finite-rate feedback
Li et al. A safe approximation approach to secrecy outage design for MIMO wiretap channels
TW201701683A (zh) 無線設備的靈活配置和認證
Chorti et al. Physical layer security: A paradigm shift in data confidentiality
US20260075411A1 (en) Key generation method, first device, and target second device
Chatterjee et al. Physically related functions: Exploiting related inputs of PUFs for authenticated-key exchange
KR102054715B1 (ko) 애드-혹 무선 네트워크에서 협력적 다중홉 라우팅을 위한 물리계층 보안 방법 및 시스템
Li et al. Cache content placement optimization in non-orthogonal multiple access networks
EP4597918A1 (en) Method for carrying out user authentication by applying pre-shared key to basis selection in quantum communication system, and device therefor
US8774410B1 (en) Secret sharing in cryptographic devices via controlled release of plaintext information
Al-Habob et al. Multi-client file download time reduction from cloud/fog storage servers
CN111246460B (zh) 一种低复杂度和低时延的安全传输方法
Sakai et al. Dynamic bit encoding for privacy protection against correlation attacks in RFID backward channel
Sharma et al. Deep learning-based authentication framework for secure terrestrial communications in next generation heterogeneous networks
CN120266432A (zh) 在环境物联网网络中使用物理层共享安全密钥进行无线安全通信的方法及相关设备
CN117750368A (zh) 鉴权方法、装置、通信设备、存储介质和程序产品
Tsaloli et al. WiP: Verifiable, secure and energy-efficient private data aggregation in wireless sensor networks
Xu et al. Maximum Zero-Outage Secrecy Capacity of Fading Wiretap Channels with Finite Alphabets
US20260058820A1 (en) Authentication methods
WO2025007316A1 (zh) 密钥生成方法和设备
US20260006012A1 (en) Key generation method and device
EP4716268A1 (en) Authentication method and device

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 23938747

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 202517129434

Country of ref document: IN

NENP Non-entry into the national phase

Ref country code: DE

WWE Wipo information: entry into national phase

Ref document number: 2023938747

Country of ref document: EP

WWP Wipo information: published in national office

Ref document number: 202517129434

Country of ref document: IN

ENP Entry into the national phase

Ref document number: 2023938747

Country of ref document: EP

Effective date: 20260102

ENP Entry into the national phase

Ref document number: 2023938747

Country of ref document: EP

Effective date: 20260102

ENP Entry into the national phase

Ref document number: 2023938747

Country of ref document: EP

Effective date: 20260102

ENP Entry into the national phase

Ref document number: 2023938747

Country of ref document: EP

Effective date: 20260102

ENP Entry into the national phase

Ref document number: 2023938747

Country of ref document: EP

Effective date: 20260102

WWP Wipo information: published in national office

Ref document number: 2023938747

Country of ref document: EP