A method and system for enhancing cryptographic capabilities of a wireless device using broadcasted random noise
15 claims: 7 independent, 8 dependent
- 1第1の送受信ユニットにおいて実装される、 セキュアに通信するための方法であって、 セッション期間を第2の送受信ユニットとネゴシエートするステップと、 前記セッション期間に対するランダム公開雑音ストリームからランダム・データを得るステップと、 前記セッション期間が終了すると、前記第2の送受信ユニットから乱数を受信するステップと、 前記乱数を用いて前記ランダム・データ をサンプリングする ことによって、前記ランダム・データからシークレット・キー を抽出するステップと、 暗号化のための前記 シークレット ・キー を使用して 暗号化された データを 送信 するステップとを具備することを特徴とする方法。
- 2前記 得る ステップは、攻撃者の予想される記憶装置限界を超過するのに十分な長い 時間期 間実行されることを特徴とする請求項1に記載の方法。
- 3前記抽出するステップは、前記第1の送受信ユニットがスリープ・モードのときに実行される ことを特徴とする請求項1に記載の方法。
- 4前記送受信ユニットにおいて前記ランダム公開雑音ストリームを生成するステップをさらに具備する ことを特徴とする請求項 1 に記載の方法。
- 5前記ランダム公開雑音ストリームのランダム性速度を調整する要求を受信するステップ をさらに具備することを特徴とする請求項 4 に記載の方法。
- 6前記要求が認定デバイスから受信されたかを判定するステップをさらに具備する ことを特徴とする請求項5に記載の方法。
- 7セキュアに通信するためのWTRU(無線送受信ユニット)であって、 第2のWTRUからセッション期間ネゴシエーションデータを受信し、 ランダム公開雑音を受信し、 セッション期間が終了すると、前記第2のWTRUから乱数を受信する、 ように構成された受信機と、 前記ランダム公開雑音から得られたランダム・データを格納するように構成されたメモリと、 前記セッション期間を決定し、 前記乱数 を使用して 前記ランダム・データ をサンプリング することによって前記ランダム・データから シークレット ・キー を抽出し、 暗号化のための 前 記シ ークレット ・キー を使用して 暗号化された データを 生成 する、 ように構成された処理装置と、 前記暗号化されたデータを送信するための送信機とを具備することを特徴とするWTRU。
- 8前記処理装置は、受信した暗号化されたデータを、前 記シ ークレット ・キー を使用して復号するように構成されることを特徴とする請求項7に記載のWTRU。
- 9前記 送信機は 、 前記ランダム公開雑音のランダム性速度を調整する要求を送信するようにさらに 構成されることを特徴とする請求項7に記載のWTRU。
- 10前記受信機は、前記ランダム公開雑音のランダム性速度を調整する要求を受信するようにさらに構成される ことを特徴とする請求項7に記載のWTRU。
- 11前記処理装置は、前記要求が認定デバイスから受信されたかを判定するようにさらに 構成されることを特徴とする請求項 7 に記載のWTRU。
- 12第1の送受信ユニットにおいて実装される、 通信をセキュアにするための方法であって、 セッション期間を第2の送受信ユニットとネゴシエートするステップと、 ランダム雑音の公開ストリームを送信するステップと、 前記ランダム雑音の前記公開ストリーム を 格納デバイスに 格納するステップと、 前記セッション期間が終了すると、前記第2の 送受信ユニットから 乱数 を受信するステップと、 前記 乱数 を使用して 、格納されたランダム雑音の公開ストリームからシークレット・ キーを生成するステップと、 前記 シークレット・ キーを使用して 、暗号化された データ のストリーム を 送信 するステップとを具備することを特徴とする方法。
- 13前記 シークレット・ キーを使用して、受信したデータを復号するステップをさらに具備すること、を特徴とする請求項12に記載の方法。
- 14第1の送受信ユニットにおいて実装される、 通信をセキュアにするための方法であって、 セッション期間を第2の送受信ユニットとネゴシエートするステップと、 ランダム雑音の公開ストリームを受信するステップと、 所定の記憶容量を有する盗聴者が盗聴することを防ぐ、ランダム雑音の前記公開ストリームの長さをサンプリングするのに十分なサイズの内部的な乱数 を生成するステップと、 前記 内部的な乱数 に基づき ランダム雑音の前記公開ストリームから選択的にビットを格納することによってランダム雑音の前記公開ストリーム をサンプリングして シークレット・ キーを生成するステップと、 前記セッション期間が終了すると、 前記 内部的な乱数 を 前記第2の 送受信ユニットに送信するステップと、 前記 シークレット・ キーを使用して 、暗号化された データ のストリーム を 送信 するステップとを具備することを特徴とする方法。
- 15ランダム雑音の前記公開ストリームは、前記第2の送受信ユニット以外のエンティティから受信される ことを特徴とする請求項14に記載の方法。
Independent claims15
186 paragraphs, as filed
The present invention relates to wireless communication.
Recent developments in cryptography have been information-theoretic, with the assumption that the storage capability of potential attackers / eavesdroppers is bounded (although potentially quite large). Demonstrate that confidentiality can be generated from a publicly accessible source of randomness. These developments may be particularly suitable for use in confidentiality generation in wireless communication systems, depending on the inherent broadcastability of the wireless communication medium.
An approach to generate common secrecy from the inherent correlations in each other's radio channels has been previously presented and disclosed in the following US Patent Application Numbers, commonly assigned in co-pending. .. That is, U.S. Patent Application No. 60 / 826,484 filed on September 21, 2006, U.S. Patent Application No. 60 / 751,803 filed on December 20, 2005, and U.S. Patent Application No. 60 / filed on July 7, 2006. 819,023, U.S. Patent Application Publication No. 11 / 444,558 filed May 31, 2006, and U.S. Patent Application No. 11 / 339,958 filed January 26, 2006.
This confidentiality approach takes advantage of the JRNSO (Joint Randomness Not Shared with Others) characteristic of unique channel responses between radio nodes. However, the randomness generated using this approach is usually slow and is aimed at relatively specific applications.
It is possible to derive information-theoretic security from public (and therefore completely secret) random sources, only under the assumption of finite (bounded) storage for eavesdroppers. Figure 1 shows an example of a wireless system that uses a finite storage device based on information-theoretic security and can protect the communication between Alice and Bob from being discovered by Eve. This process involves the following two steps. That is, the step of sampling a random stream and the step of extracting a "pure secret" from the sampled data. To fully understand mathematics, the following notations are applicable.
T: Overall duration of the session α: Public stream speed β: Input randomness / confidentiality speed γ: Average / amortized rate that allows legitimate parties (Alice / Bob) to sample public streams. If you can read them at different speeds, this is the smaller of the two. N: Total data available during the session N = αT (1) k: shared secret length k = βT (2) n: Total number of bits that Alice and Bob can sample together n = γT (3) n<sub>0</sub>: The total number of bits that Alice and Bob can sample per block for the block-wise algorithm. Since we have some degrees of freedom in selecting the block length (ie T selection), we assume wlog and here n / n<sub>0</sub>And N / (n / n<sub>0</sub>) Is an integer.
<maths num="1"><img file="JP4990366B2_D0001.tif" /></maths>
b: Part of the total data that the attacker (Eve) is supposed to be able to store (ie 0 <b <l). This is the parameter used for analysis. G: The attacker's actual storage capacity. This is the actual state. The relationship between G and b constitutes one of the constraints driving the problem. G = bN (4) a: Back-off parameter of implementation method. This is an implementation loss due to having a finite block length rather than using a theoretically ideal sampler or the like. ε: Probability of error in algorithmic processing (probability that Alice and Bob miss the combined randomness or that it is not secret from Eve). l: The total number of secret bits generated by Alice and Bob in addition to the k bits available at the start.
Sampling is the primary procedure that guarantees the generation of randomness. Processing occurs during a time interval called a predefined session. Each session has a duration T. Therefore, the data during one session can be considered as one block of length N.
In the example of Figure 2, Alice and Bob sample a public random stream in a way unknown to Eve until the end of the session. Moreover, taking into account Eve's limited storage capacity, Eve stores all sampling bits at the end of the sampling procedure, no matter what selective storage strategy Eve uses. Sampling should be done in such a way that it is highly unlikely that it will end up. Eve knows that she can't store the entire stream, so the best opportunity for Eve to eavesdrop is to selectively sample bits, and Eve to have the same bits sampled by Alice and Bob. Is to expect. Alice and Bob are unaware of Eve's sampling strategy, but nevertheless choose their own strategy so that at least some of their data will not be stored by Eve.
To achieve this, Alice and Bob must randomly sample, so they randomly sample the same bits so that they remain completely secret from Eve, at least until the end of the session. There must be some way to agree on the possible ways. For the purposes of this example, it is assumed that such input randomness is available to Alice and Bob only at a finite velocity β or in a finite block of k bits per session.
Alice and Bob are also what they average the parameter n, which represents the minimum of their limits, or the parameter γ, which represents the minimum of their average sampling rate, which they can store. They may be limited to either being able to sample by frequency.
A very simple example of the sampling procedure for Alice and Bob is: That is, (1) Alice and Bob n / n sessions<sub>0</sub>Divide into subsessions. In each subsession, n<sub>0</sub>Sampling bits. (2) Next, the shared random bits are used to define the position.
For example, Alice and Bob have N-bit subsessions of public random data, respectively.
<maths num="2"><img file="JP4990366B2_D0002.tif" /></maths>
Bit N<sub>0</sub>Divide into blocks. Alice and Bob then use their shared random secret to use the same n in their respective subsessions.<sub>0</sub>Select the position of. The index of each position is logN<sub>0</sub>N because it requires a bit<sub>0</sub>logN<sub>0</sub>All bits of are required. Therefore, the first requirement of this example is k> n<sub>0</sub>logN<sub>0</sub>Is. This inequality must actually be strict. If so, it requires some of the available random bits of k for extraction, and these should not be reused for sampling.
The size of each individual subsession is less than Eve's storage limit (ie, N)<sub>0</sub>It should be noted that <G is acceptable), but the global limit N> G must still survive. Moreover, even if the bits used to sample the stream are revealed, they cannot be revealed until the end of the entire session.
The sampling method outlined above is preferred because of its relatively good performance and simplicity, but in the art it is not for the BSM (Bound Storage Model) problem. The sampling method of is known.
<p> Extraction, as applicable in the example of Figure 1, is the problem of extracting a completely random bit of X whose partial information is known to the adversary. This known information is quantified as no more than the Y bit (entropy). The problem is then to extract the (XY) bits completely secretly to the adversary.</p><p> There are various methods, all of which require access to a certain amount of fully shared randomness that may be confidential or leaked to eavesdroppers. In general, at least a large number of extraction bits are required as follows. </p><p><maths num="3"><img file="JP4990366B2_D0003.tif" /></maths></p><p>Here, ε is an error peculiar to the extraction process. The calculations in any of the examples here will use this value. The actual method of implementation will, of course, differ depending on which technique is actually used.</p><p> While it is clear that BSM (Bound Storage Model) will work mathematically, there is a need for a practical implementation for performing BSM secrecy generation. For the above example, it would be beneficial to provide Alice and Bob with a short common secret as well as a reliable source of public randomness.</p>
<p> When the transmission / reception unit receives the public random stream included in the wireless communication signal, the process of generating the secret stream of bits is started. A public random stream is sampled to extract specific bits according to a shared common secret. These extracted bits are used to generate a longer secret stream. Public random streams sample other wireless communication systems, such as terrestrial or satellite television, terrestrial or satellite radio, other unidirectional, bidirectional, or networked radio communications or sensor systems. It can be generated from, or public randomness may be broadcast for the purpose of providing a public random signal. A shared common secret can be generated using JRNSO techniques or supplied to the transmit / receive unit prior to the communication session.</p><p> In another embodiment, one of the transmit and receive units is assumed to be more powerful than any potential eavesdropper. In this state, the powerful transmit / receive unit can broadcast and store a public random stream that no eavesdropper can store as a whole. Weaker transmit and receive units can use a random number generator to select the random bits of their broadcast to sample and create a secret key. After the broadcast is complete, the weaker transmit / receive unit sends its random number to the stronger transmit / receive unit, and the stronger transmit / receive unit uses that random number to create the same secret as that created by the weaker transmit / receive unit. Create a key. Eventually the BSM process is performed using the secret key to create a secret stream.</p><p> A more detailed understanding of the invention can be obtained from the description of the following preferred examples, which should be understood in connection with the drawings given and attached as examples.</p>
<figref num="1">It is a figure which shows the composition of the communication entity and the source of randomness disclosure.</figref><figref num="2">FIG. 5 illustrates an exemplary procedure for confidentiality generation using finite storage techniques.</figref><figref num="3">FIG. 5 illustrates an exemplary procedure for confidentiality generation of a finite storage model using JRNSO for strong secret generation.</figref><figref num="4">It is a figure which shows the lower limit with respect to the time required for the confidentiality generation interval shared according to the first scenario.</figref><figref num="5">It is a figure which shows the bit rate of the result for the confidentiality generation shared according to the first scenario.</figref><figref num="6">It is a figure which shows the lower limit with respect to the time required for the secret generation interval shared according to the second scenario.</figref><figref num="7">FIG. 5 shows the resulting bit rate for shared confidentiality generation according to the second scenario.</figref><figref num="8">FIG. 5 illustrates an exemplary procedure for BSM confidentiality generation using a common stored secret.</figref><figref num="9">It is a figure which shows in the exemplary procedure for BSM secrecy generation that Bob is more powerful than Eve.</figref>
Referenced hereafter, the term "WTRU (Wireless Transmit Receive Unit)" is not limited to UE (User Equipment), mobile terminals, fixed or mobile subscriber units, Includes pagers, mobile phones, personal digital assistants (PDAs), computers, or any other type of user device capable of operating in a wireless environment. As referred to hereafter, the term "base station" is not limited to node B, site controller, AP (Access Point), or any other capable of operating in a wireless environment. Includes any type of interface device.
Figure 3 shows the common key (common) Shown is an exemplary process 300 performed in a transmit / receive unit that uses JRNSO to perform BSM confidentiality generation to provide key). This process can be performed by any pair of communication devices that share a radio channel with sufficient bidirectional characteristics to generate JRNSO. In particular, the transmit / receive unit has a common random and dynamic impulse response that correlates with another transmit / receive unit when observed from Alice to Bob and from Bob to Alice (see Figure 1). Must share the radio communication channel, the device for performing channel estimation, and the ability to generate common randomness. Examples of these transmit and receive units are (1) WTRUs and base stations in cellular networks, (2) terminals and access points in IEE802.xx wireless networks, and (3) two peer-to-peer devices. , Or (4) a pair of sensors in a sensor network that requires secure communication. Alternatively, there may be secure, potentially intermittent, wired channels that allow slow secret sharing.
In FIG. 3, the process of generating a secret stream of bits begins in step 310 by receiving a public random stream contained in a radio communication signal on a standard modem attached to the antenna. In step 320, a radio channel measurement is performed on the signal to make the necessary measurements for JRNSO. At step 325, JRNSO generation is used to generate a common secret. At step 330, a public random stream is sampled at the same time that the JRNSO measurement is made. The public random stream can be a wired or wireless transmission. Public random streams are other wireless communication systems, such as terrestrial or satellite televisions, terrestrial or satellite radios, other unidirectional, bidirectional, or networked radio communications or sensor systems. Can be generated from sampling, or public randomness may be broadcast for the purpose of providing a public random signal. Then, in step 340, BSM processing is executed using the common secret generated by JRNSO, and the secret stream is extracted.
The processing shown in Figure 3 can be mathematically represented using the processing of three different scenarios, each utilizing the data rate for a public random stream. For all three scenarios, the number of variables is reduced according to the following selections. That is, it is assumed that α, β, γ, ε, and G are all constants. l will be maximized. T will be minimized. In addition, n<sub>0</sub>, A, b are used as control parameters. The number of random bits generated is expressed as follows.
<maths num="4"><img file="JP4990366B2_D0004.tif" /></maths>
In order to determine the EVB (EaVesdropper Bound) T, the transmitter / receiver must wait long enough to exceed the storage capacity of any eavesdropper. Therefore, when Eqs. (1) and (4) are combined, it becomes as follows.
<maths num="5"><img file="JP4990366B2_D0005.tif" /></maths>
To determine the SB (Sampling Bound), the transmitter / receiver unit must wait long enough to sample the required data. Therefore,
<maths num="6"><img file="JP4990366B2_D0006.tif" /></maths>Is.
Finally, to determine the OSKB (Original Secret Key Bound), the transmit / receive unit is long enough to generate the required JRNSO randomness, and all the requirements of the BSM algorithm. You have to wait long enough to meet. This results in the next limit.
<maths num="7"><img file="JP4990366B2_D0007.tif" /></maths>
The following parameter settings are used to demonstrate the performance of the results for each of the three public randomness stream velocity scenarios. That is, the eavesdropper's storage limit G = 1x10<sup>12</sup>Bit, error probability ε = 2<sup>-20</sup>(Or about 1x10<sup>-6</sup>), Speculator backoff from optimal: a = 0.1, maximum number of bits the transmit / receive unit is ready to store n = 1x10<sup>8</sup>(100 megabits).
Scenario 1 is generated via JRNSO and augmented using the BSM approach with a 1 Gbps public randomness stream and channel sampling rate γ = 1x10 for Alice and Bob.<sup>6</sup>bps (1Mbps) and shared secret speed (equivalent to JRNSO) β = 1x10<sup>3</sup>It is a shared secret with bps. The results of the scenario 1 assumptions are shown in Figures 4 and 5. Figure 4 shows the minimum required time interval before a single "batch" of BSM secret bits becomes available. Line 410 is EVB (7), line 430 is SB (8), and line 420 is OSKB (9). EVB is shown in the range of 2000 to 10000 seconds (about 1 to 3 hours).
In FIG. 5, line 510 shows the secret bits generated, which appear to be linearly proportional to (1-b) in the order of the number of kilobits per second. High BSM bitrates require longer batches (batch processing), so there are trade-offs.
The second scenario is generated via JRNSO at low speed (1bps), reinforced using the BSM approach, and published randomness velocity α = 1x10.<sup>9</sup>bps (1Gbps) and channel sampling speed γ = 1x10<sup>6</sup>It is a shared secret with bps (1Mbps) and a shared secret speed (equivalent to JRNSO) β = 1bps. The results of the scenario 2 assumptions are shown in Figures 6 and 7. Figure 6 shows the minimum time interval required before a single "batch" of BSM secret bits becomes available. Line 620 is OSKB (9). Line 630 is SB (8) and EVB610 (7), which are very low relative to the scale of limit (9). Line 620 starts at 200,000 seconds (about 60 hours) for b = 0.1 and increases as b increases. For b = 0.9, the speed is tremendous 180,000 seconds (500 hours). The resulting BSM rate is very low as shown in Figure 7 (b = 0.1 vs. @ 45bps and then drops). Therefore, at low confidentiality bitrates, it is advantageous to operate with a very low value of b (ie, greater than the adversary's storage limit of 10). The transmit / receive unit stores its own storage device from 100 megabits to 1 gigabyte (8xl0)<sup>9</sup>If you increase it to (bit), much better performance is observed (about 650 bps higher).
The first two scenarios each assumed that both the public stream rate α and the JRNSO output bit generation rate β were constant. In the third scenario, it is possible that β alone or both α and β change over time. This third example is actually the most practical. For example, a wireless device that changes direction, velocity, or acceleration in a mobile network will cause a change in value β. The public stream can exist as a constant velocity random source, but the velocity at which Alice and Bob may be able to receive them as an error-free random signal is the physical source of the public stream (eg, the public stream). It may fluctuate depending on factors such as changes in the distance of Alice and / or Bob from the transmitting station).
The procedure outlined in FIG. 3 can be extended in a direct way to accommodate a third scenario in which the bit rates β and / or α change over time. In the third scenario, any one or a combination of the following five procedures can be performed by the transmit / receive unit.
First, the transmit / receive unit can try to keep the total bit generation rate constant. Depending on the degree of change in β or β and α velocities, the transmit and receive units operate with sufficient margins or other means at target velocities well below the maximum achievable velocities. By operating, it may be possible to maintain a constant output secret bit generation rate. Margins will have to be agreed in advance between each transmit and receive unit, taking into account system parameters (including considering BSM parameters G or b) and other performance requirements.
Secondly, the transmit / receive unit can agree to reduce the secret bit generation rate by sensing the degradation variation of the output generation rate that depends on the decrease in β and / or α. Such a choice may be useful in situations where the transmit / receive unit can switch to a lower secret bit generation rate and communicate with a reduced level of confidentiality. This method would be useful for new applications that would require a low level of confidentiality.
Third, the transmit / receive unit can again agree to stop secret bit generation and other communications until it recovers a sufficiently strong secret bit generation rate when it senses a degradation variation in the output generation rate. .. This method would be useful where time is not an issue when communicating secret data.
Fourth, the transmit / receive unit can initiate an increase in the output bit generation rate when it senses that the bit generation rate operating at that time is lower than the maximum available one. Measured (and / or accumulated) on a longer time scale by storing and using these unnecessary secret bits and augmenting them with secret bits generated at lower velocities. Then Alice and Bob can maintain a more constant output bit generation rate. Alice and Bob also use longer subsession lengths to the extent that system operation can still satisfy its requirements for averaging the effects of fluctuations at input speeds β and / or α. You may agree with that. In addition, they can use an adaptive strategy for setting the subsession length, which increases the subsession length when either node senses increased β and / or α variability, and β Subsession length will be reduced by increasing and / or α.
Ultimately, any of the four strategies can be properly combined in an adaptive algorithm. However, it should be noted that any adaptive algorithm should be pre-agreed by the transmit and receive units, taking into account application, context, and performance requirements.
FIG. 8 shows an exemplary process 800 performed in a transmit / receive unit for BSM confidentiality generation using a common stored secret 805. At some point, any pair of transmit and receive units provided with a common stored secret can perform this process. Examples of these transmit and receive units are (1) WTRUs and base stations in mobile networks, (2) terminals and access points in IEE802.xx wireless networks, (3) two peer-to-peer devices, or ( 4) Includes a pair of sensors in a sensor network that requires secure communication.
In FIG. 8, the process 800 for generating the secret bitstream is started in step 810 by receiving the public random stream contained in the wireless communication signal. Public random streams can be received via wired or wireless media. Public random streams are other wireless communication systems, such as terrestrial or satellite televisions, terrestrial or satellite radios, other unidirectional, bidirectional, or networked radio communications or sensor systems. Can be generated from sampling, or public randomness may be broadcast for the purpose of providing a public random signal. The public random stream is sampled in step 830. Then, in step 840, BSM processing is performed using the common stored secret 805 to extract the secret stream. The secret stream is established at step 850.
The common stored secret 805 is used in the same way that the JRNSO bits are used in the procedure in Figure 3. Common stored secret 805 sources include: That is, (1) the secret is pre-stored in USIM and is valid only for a certain period of time, after which a new USIM needs to be installed, (2) the sensor is secure with a fixed lifetime. Sensor networks, (3) secure communication networks where each computer must have a new secret installed on a regular basis, (4) while the WTRU is located in a secure area (ie, the user is active (ie, the user is active (ie)) The secret provided before starting mission).
Each of these cases requires different qualities of a common stored secret 805, and the speed at which the JRNSO bits are created is no longer an issue. Instead, lifespan and common stored secret length are limiting factors. For example, in the case of USIM or secure networks, the longest possible lifetime for a common stored secret 805 would be desirable. Alternatively, if a secret is provided while the WTRU is located in a secure area prior to activity, its common storage in case one of the WTRUs falls into the hands of an eavesdropper. It may be desirable that the secret is merely its activity.
K to transmit / receive units (Alice and Bob)<sub>0</sub>If a bit was provided, the eavesdropper's (Eve's) knowledge of their secrets would be
<maths num="8"><img file="JP4990366B2_D0008.tif" /></maths>
Defined through the statistical distance of.
Each session will increase the statistical distance by ε. ε<sub>MAX</sub>Is the maximum statistical distance that Alice and Bob are willing to tolerate. Therefore, the maximum number of sessions that Alice and Bob can maintain is
<maths num="9"><img file="JP4990366B2_D0009.tif" /></maths>
Is.
Since the common stored secret will eventually be used up, the device will
<maths num="10"><img file="JP4990366B2_D0010.tif" /></maths>
It has a finite lifetime defined as. Given ε<sub>0</sub>The following algorithm is used to determine how large a common stored secret is needed for Alice and Bob to maintain a certain device life.
For each session, Alice and Bob determine how long the session is and how many bits should be generated per session. Based on this decision, Alice and Bob determine the number of bits k needed to perform this operation. k k<sub>0</sub>It should be noted that Alice and Bob use an existing k<sub>0</sub>Map bits to k bits. When k bits become available, Alice and Bob will use them for sampling and extraction.
Reduce the number of in play variables according to the following choices: -The value is fixed. α, γ, ε = ε<sub>MAX</sub>, G, T<sub>LIFE</sub> Β is no longer an important parameter Maximize l Minimize T -Required strong secret size (k)<sub>0</sub>) To be defined by the parameter in question. -N as a control parameter to do this<sub>0</sub>, A, b, n are used. In practice, a should be set fairly low (a = 0.1), n<sub>0</sub>Will be defined implicitly, and b will be defined explicitly (see below), so that the problem will be controlled by only one parameter n.
By equations (10) and (11)
<maths num="11"><img file="JP4990366B2_D0011.tif" /></maths>
Is provided. However, also due to them
<maths num="12"><img file="JP4990366B2_D0012.tif" /></maths>
Is provided. Where k is the number of bits required for a single session. Consideration for the lower limit of k is given below.
<maths num="13"><img file="JP4990366B2_D0013.tif" /></maths>
Here, equations (12) to (14) are k<sub>0</sub>Provides an expression for, where C<sub>1</sub>Is a constant that depends on the particular sampling method used. Here C<sub>1</sub>A suitable setting of = 3 is used, but other values can be used.
Then combine (7) and (8),
<maths num="14"><img file="JP4990366B2_D0014.tif" /></maths>
Is produced. Next, the representation for the number of bits generated is via (6) and (15).
<maths num="15"><img file="JP4990366B2_D0015.tif" /></maths>
Given like.
From (16) it is clear that n must be large enough (or b small enough) for (16) to be positive (otherwise no bits will be generated). This sets a natural bound for T.
FIG. 9 is an alternative embodiment where the transmit and receive units Alice and Bob neither share any type of a priori secret or have the ability to generate secrets naturally. .. However, one of the two parties (Bob) has enough storage capacity to store what deserves a random data stream for all sessions. The other (Alice) is still very limited in storage. In this embodiment, it is also assumed that Bob's storage capacity is greater than any potential eavesdropper (Eve). Moreover, Alice has a method for internally generating random numbers at any desired speed.
Processing begins at step 910 when Alice 902 and Bob 907 publicly negotiate the start and end of a communication session. Then in step 920, Alice 902 uses her random number generator to generate a sufficiently large set of random numbers to be used for sampling and extraction. Alice 902 does not communicate these numbers until after the session. Then in step 930 Bob 907 stores all sessions worthy of random data received from the random public stream 909. In step 935, Alice 902 samples random data according to her random number, thereby generating a secret key. At the end of the session, at step 940, Alice 902 publicly communicates the random numbers stored by Alice 902 to Bob. Bob then uses that random number in step 950 to extract the same bits sampled by Alice 902 to create the same secret key. Encrypted communication is initiated at step 960 using the key sampled by Alice 902. This behavior is secure because the session is over by the time Eve (not shown) will learn the random stream and Eve can no longer sample the random stream.
The application of this approach is similar to that described above. Bob 907 is preferably a centralized entity, while Alice 902 is WTRU, as the cost of having a very large storage device is justified. One particular configuration that may be of interest to this approach is for mobile systems where Bob 907 is the base station and Alice 902 is the WTRU. Public random streams are available from external transmissions of normal mobile communications and can be received by both base stations and WTRUs within a cell. Alternatively, the base station itself can be used to generate a public random signal, which is stored after being transmitted. In practice, some base stations may be used in conjunction with a storage device operating somewhere in the network that has access to the transmissions of all base stations. Depending on the network configuration, this is an RNC, which may be a data gateway such as the GGSN. The WTRU procedure for sampling a stream is cell measurement and paging during sleep. channel) -Schedule in the same way as the check procedure, resulting in minimal impact on WTRU.
All the above embodiments more authorized users than two is over it should be noted that would be available. In addition, another embodiment is possible with more than two legitimate users using paired keys. In this embodiment, it is possible for a legitimate party of n to generate n (nl) / 2 pairs, and each pair will generate its own key by the process described above. Is possible.
In another embodiment, Alice or Bob, rather than Eve, affects the randomness of the public stream by, for example, presenting a speed change request given only to authorized users, using slow, uplink-side channels. It is assumed that it is possible to exert. If the randomness rate of the public stream can be increased or decreased at the request of Alice or Bob, then such control has a beneficial purpose, such as maintaining a constant output bit rate as the input rate β decreases. Can be used for. This method ability can also be beneficial when Eve's storage capacity is suspected to have changed.
Although the features and elements of an embodiment are described in a particular combination, each feature or element may be used alone or with or without other features and elements of the embodiment. It can be used in various combinations. The provided method or flow diagram is performed in a computer program, software, or firmware that is substantively embodied in a computer-readable storage medium for execution by a general purpose computer or processing device. can do. Examples of computer-readable storage media include ROM (Read Only Memory), RAM (Random Access Memory), registers, cache memory, semiconductor memory devices, and built-in memory. Includes magnetic media such as hard disks and removable disks, magnetic-optical media, and optical media such as CD-ROM disks and DVDs (Digital Versatile Disks).
Examples of suitable processing devices are general purpose processing devices, dedicated processing devices, conventional processing devices, DSPs (Digital Signal Processors), multiple micro processing devices, and one or more associated with a DSP core. Micro-processing equipment, control equipment, micro-control equipment, ASIC (Application Specific Integrated Circuit), FPGA (Field Programmable Gate Array) circuit, any other type of IC (Integrated Circuit), And / or state machines are included.
Wireless for use with WTRU (Wireless Transmit Receive Unit), UE (User Equipment), terminals, base stations, RNC (Radio Network Controller), or any host computer A processing device associated with the software can be used to implement the frequency transmitter / receiver. WTRU is implemented in hardware and / or software, camera, camcorder module, videophone, speakerphone, vibrating device, speaker, microphone, TV transmitter / receiver, hands-free handset, keyboard, Bluetooth (Bluetooth®) )) Module, FM (Frequency Modulated) wireless unit, LCD (Liquid Crystal Display) display unit, OLED (Organic Light-Emitting) Diode: Works with modules such as display units, digital music players, media players, video game player modules, internet browsers, and / or any WLAN (Wireless Local Access Network) modules. Can be used.
<Embodiment> 1. A method of generating a secret stream of data between terminal A and terminal B, The steps to apply a confidentiality scheme to the data based on the source of disclosure or randomness, With the step of transmitting the data How to equip.
2. The method of embodiment 1, wherein the source of the published randomness is at least partially generated by either terminal A or terminal B and sent to the other party.
3. The method of any one of the previous embodiments, wherein the source of the published randomness is at least partially generated by a third party for a specific purpose of facilitating confidentiality generation.
4. The source of the disclosure of the above randomness, at least in part, based on the by-products of the operation of some other radio system, whose primary purpose has nothing to do with the generation of secrecy between A and B. Any one method of the embodiment.
5. The method of embodiment 4, wherein the other radio system is either a radio system, a television system, or some other radio signal broadcast over a wide area.
6. Any one method of the previous embodiment, wherein the source of the published randomness is at least partially based on natural noise, or noise associated with some other anthropogenic phenomenon.
7. The method of any one of the previous embodiments, wherein the additional user is further receiving the data transmission in addition to terminal A and terminal B.
8. The step of applying the confidentiality scheme to the data based on the source of disclosure or randomness The step of sampling the random stream and With the step of extracting a pure secret from the sampled data Any one method of the previous embodiment comprising.
9. Any one method of the previous embodiment in which the sampling steps occur during a predefined interval.
10. The method of any one of the previous embodiments, wherein the terminal A and the terminal B agree to a sampling scheme unknown to a potential eavesdropper.
11. Any one method of the previous embodiment in which randomness is made available to said Terminal A and said Terminal B at a finite bit rate per session.
12. The terminal A and the terminal B further include a step of dividing the session into several subsessions using the shared random bits to define a position for sampling. Any one of the previous embodiments.
13. Any one of the previous embodiments, further comprising a step defining that the parameter T is equal to the overall duration of the session.
14. The method of embodiment 13 further comprising defining that the parameter α is equal to the public stream velocity and the block length N is equal to αT, which is the amount of data available in the session.
15. One method of any one of the previous embodiments, further comprising the step of defining the parameter β as equal to the input randomness / secrecy rate.
16. Any one method of the previous embodiment further comprising the step of defining the parameter γ as equal to the average / depreciation rate at which Terminal A and Terminal B can sample said public stream.
17. A method of any one of embodiments 13-16, further comprising a step of defining a parameter k as equal to the length of the shared secret, where the parameter k = βT. ..
18. Embodiments 13-17, wherein parameter n is defined as equal to the total number of sampling bits that terminal A and terminal B can sample together, and parameter n = γT. Any one way.
19. Parameter N assuming that terminal A and terminal B are equal to the total number of bits that can be sampled block by block for the block algorithm.<sub>0</sub>Is defined in any one of the previous embodiments.
20. As the total number of bits in each of the N blocks for the block algorithm
<maths num="16"><img file="JP4990366B2_D0016.tif" /></maths>
Any one method of the previous embodiment further comprising.
21. Any one of the previous embodiments, where parameter b is defined as equal to some of the total data that the attacker could store, and 0 <b <l.
22. Any one method of the previous embodiment in which parameter G is defined as equal to the attacker's actual storage capacity and G = bN.
23. A method sufficient to use a finite block length Implementation method for loss Any one method of the previous embodiment in which parameter a is defined as a backoff parameter.
24. The method of embodiment 23, where parameter a = 0.1.
25. The method of any one of the previous embodiments, wherein the parameter ε is defined as equal to the probability of error in the algorithmic processing.
26. The method of any one of the previous embodiments, wherein the parameter l is equal to the total number of secret bits generated by the terminals A and B in addition to the k bits available at the start.
27. Terminals A and B each block an N-bit session of public random data.
<maths num="17"><img file="JP4990366B2_D0017.tif" /></maths>
Bit N<sub>0</sub>Any one method of the previous embodiment further comprising the step of dividing into blocks.
28. Terminals A and B have the same n in their respective subblocks<sub>0</sub>Any one of the previous embodiments, using their shared random secret to select the location.
29. The method of any one of the previous embodiments, wherein the parameter N is greater than the parameter G.
30. The minimum number of bits for extraction
<maths num="18"><img file="JP4990366B2_D0018.tif" /></maths>
Any one method of the previous embodiment equal to.
31. Any one of the previous embodiments in which terminals A and B generate a complete secret stream using a procedure based on JRNSO (Joint Randomness Not Shared With Others).
32. Terminals A and B share a common radio communication channel with a random and dynamic impulse response that correlates when observed from terminal A to terminal B and from terminal B to terminal A. And any one of the previous embodiments, further comprising the step of estimating the shared channel and the step of communicating to generate common randomness.
33. Terminals A and B establish the session length and sample the common source of randomness according to the sampling procedure, while at the same time they perform JRNSO-based processing for the next session, said required. One method of any one of the previous embodiments, in which the extraction is performed to generate the bits.
34. Any one of the previous embodiments, wherein terminals A and B are any pair of communication devices sharing a radio channel with sufficient bidirectional characteristics to generate confidentiality based on JRNSO. Method.
35. The step of generating a randomized bit with a total of l, where
<maths num="19"><img file="JP4990366B2_D0019.tif" /></maths>
Any one method of the previous embodiment further comprising a step that is.
36. The parameters are
<maths num="20"><img file="JP4990366B2_D0020.tif" /></maths>
Is any one method of the previous embodiment.
37. The parameters are
<maths num="21"><img file="JP4990366B2_D0021.tif" /></maths>
Is any one method of the previous embodiment.
38. The parameters are
<maths num="22"><img file="JP4990366B2_D0022.tif" /></maths>
Is any one method of the previous embodiment.
39. The method of any one of the previous embodiments, wherein both the public stream rate α and the JRNSO output bit generation rate β are constant.
40. Any one method of the previous embodiment, in which both α and β change over time.
41. The speed at which terminals A and B may be able to receive an error-free random signal varies depending on factors, including varying distances of A and / or B from said physical source. The method of any one of the previous embodiments, which may be.
42. Any one of the previous embodiments in which terminals A and B maintain a constant total bit generation rate.
43. Any one method of the previous embodiment in which terminals A and B operate at a target speed well below the maximum available.
44. The terminals A and B further include a step of sensing the deterioration fluctuation of the output generation rate and a step of agreeing to the decrease of the secret bit generation rate, depending on the decrease of β and / or α. , Any one of the previous embodiments.
45. When terminals A and B sense the deterioration fluctuation of the output generation rate, they further agree to stop secret bit generation and other communication until a sufficiently strong secret bit generation rate is restored. The method of any one of the previous embodiments.
46. Any of the previous embodiments, further comprising a step of initiating an increase in the output bit generation rate when it senses that the bit generation rate in operation at that time is lower than the maximum available. One way.
47. Longer subsession lengths to the extent that the system operation can still be performed to meet its requirements in order to average the effect of the variation on the input speeds β and / or α. Any one method of the previous embodiment further comprising a step of agreeing to use.
48.k<sub>0</sub>A method of any one of the previous embodiments, wherein the terminals A and B are provided with a fixed reverse of a strong secret bit.
49. The maximum number of sessions that terminals A and B can maintain is
<maths num="23"><img file="JP4990366B2_D0023.tif" /></maths>
The method of embodiment 48.
50. The device life parameter is
<maths num="24"><img file="JP4990366B2_D0024.tif" /></maths>
The method of embodiment 49, defined as.
51. Any one method of the previous embodiment in which terminals A and B determine how long the session is and how many bits should be generated per session.
52. Terminals A and B are the steps to determine the number of bits k required, where k k<sub>0</sub>The existing k using the steps that are and the secure procedure<sub>0</sub>A previous implementation further comprising a step of mapping a bit to a k-bit and a step of using the available bit of K for terminals A and B to sample and extract as soon as the k-bit becomes available. Any one method of morphology.
53. The method of any one of the previous embodiments, in which a long strong secret is embedded in the central terminal unit.
54. The method of embodiment 58, wherein a strong secret is stored in the memory of the WTRU (Wireless Transmit Receive Unit) for a period of time, after which the memory needs to be replaced.
55. The method of any one of the previous embodiments, wherein the method is performed in a secure sensor network in which the sensor has a fixed lifetime.
56. Any one of the previous embodiments, in which the computer is serviced on a regular basis to provide a new secret.
57. The parameters are
<maths num="25"><img file="JP4990366B2_D0025.tif" /></maths>
Is any one method of the previous embodiment.
58. The parameters are
<maths num="26"><img file="JP4990366B2_D0026.tif" /></maths>
Is any one method of the previous embodiment.
59. The parameters are
<maths num="27"><img file="JP4990366B2_D0027.tif" /></maths>
And here C<sub>1</sub>Is a constant that depends on the sampling method adopted, any one of the previous embodiments.
60. The parameters are
<maths num="28"><img file="JP4990366B2_D0028.tif" /></maths>
Is any one method of the previous embodiment.
61. It is possible to physically load the secret into the terminals A and B via a connector, electronic coupling, SIM card, or over one or more of the radio waves. Any one of the previous embodiments.
62. The method of any one of the previous embodiments, wherein terminal A or B has a very large storage capacity.
64. The method of any one of the previous embodiments, wherein the terminal has a method for generating an internal random number at any desired speed.
65. Terminals A and B publicly negotiate the start and end of a session, Terminal A uses a random number generator to generate a set of random numbers large enough to be used for sampling and extraction, and Terminal B Previous implementation in which terminal A stores all sessions worthy of random data, terminal A samples the random data according to its own random number, and terminal A publicly communicates its own random number to terminal B. Any one method of morphology.
66. Any one of the previous embodiments in which terminal A is a WTRU and the stream is sampled by a scheduled method similar to the sleeping cell measurement and paging channel check procedure.
67. Any one of the previous embodiments, further comprising the step of generating their own confidentiality key for additional parties to communicate in secret.
68. If the channel between terminals A and B is not error-free, error compensation for channel errors and authentication for active adversaries are used to make the channel virtually-error-free. Any one method of the previous embodiment to convert to channel).
69. If the public randomness is not received without error, then any one of the previous embodiments, where terminals A and B use additional communication to resolve the error.
70. Any one method of the previous embodiment in which terminals A and B use the error itself to generate shared randomness if the public randomness is not received without error.
71. The method of any one of the previous embodiments, wherein terminal A or B can affect the randomness of the public stream by indicating a speed change request.
72. The method of embodiment 76, wherein terminals A and B utilize said randomness control to generate confidentiality.
73. The method of any one of the previous embodiments, wherein terminal A or terminal B is a WTRU.
74. The method of any one of the previous embodiments, where terminal A or terminal B is node B.
75. A wireless communication system configured to perform any one of the previous embodiments.
76. A wireless communication system configured to perform any of the methods 1-77.
77. A method of any one of embodiments 1 to 74, wherein terminal A and / or terminal B uses an ASIC (Application Specific Integrated Circuit) to perform the method.
78. The system of embodiment 75, wherein the system is an OFDM (Orthogonal Frequency Division Multiplexing) MIMO (Multiple-Output Multiple-Input) system.
79. A digital signal processor configured to perform any one of the methods 1 to 74.
80. A WTRU configured to perform any one of the methods 1 to 74.
81. Node B configured to perform any one of the methods 1 to 74.
82. A wired network configured to perform any one of the methods 1 to 74.
37 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26 Sheet 27 Sheet 28 Sheet 29 Sheet 30 Sheet 31 Sheet 32 Sheet 33 Sheet 34 Sheet 35 Sheet 36 Sheet 37
Every citation, both waysCites: the store holds 3 of 4
| Document | Relation | Office |
|---|---|---|
| WO2006081122A1 | Cites | World Intellectual Property Organization (WIPO) |
| JP2004080663A | Cites | Japan |
| WO2005025178A1 | Cites | World Intellectual Property Organization (WIPO) |
| Maurer, U. M.,Conditionally-Perfect Secrecy and a Provably-Secure Randomized Cipher,Journal of Cryptography,1992年,Volume 5 Number 1,p.53-66 | Non-patent | – |
24 members in 7 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 60829198 | United States of America | – | |
| 82919806 | United States of America | P | |
| 82919806 | United States of America | P | |
| 2007021854 | United States of America | W | |
| 2007021854 | United States of America | W | |
| 2006829198 | – | – | – |
| 2007021854 | – | – | – |
| US20060829198P | – | – | – |
| WO2007US21854 | – | – | – |
Members24
| Document | Office | Kind | |
|---|---|---|---|
| US2008089518A1 | United States of America | A1 | |
| TW200826598A | Taiwan Province of China | A | |
| WO2008118136A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2008118136A3 | World Intellectual Property Organization (WIPO) | A3 | |
| KR20090067209A | Republic of Korea | A | |
| EP2074740A2 | European Patent Office (EPO) | A2 | |
| KR20090085688A | Republic of Korea | A | |
| CN101523796A | China | A | |
| JP2010507276A | Japan | A | |
| JP4990366B2This record | Japan | B2 | |
| US8254574B2 | United States of America | B2 | |
| JP2012182825A | Japan | A | |
| US2012281831A1 | United States of America | A1 | |
| KR20130020924A | Republic of Korea | A | |
| TWI393415B | Taiwan Province of China | B | |
| CN101523796B | China | B | |
| US8634558B2 | United States of America | B2 | |
| US2014133654A1 | United States of America | A1 | |
| KR20140099912A | Republic of Korea | A | |
| US9036821B2 | United States of America | B2 | |
| KR101530391B1 | Republic of Korea | B1 | |
| KR101546165B1 | Republic of Korea | B1 | |
| KR101546205B1 | Republic of Korea | B1 | |
| EP2074740B1 | European Patent Office (EPO) | B1 |
12 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 |
Numbers
- Publication
- 4990366
- Publication, DOCDB
- 4990366
- Publication, EPODOC
- JP4990366B
- Application
- 2009532437
- Application, DOCDB
- 2009532437
- Application, EPODOC
- JP20090532437
Titles2
- Japanese
- ブロードキャストされたランダム雑音を使用して無線デバイスの暗号化能力を向上させるための方法およびシステム
- English
- Methods and systems for improving the encryption capabilities of wireless devices using broadcast random noise
Classification
- CPC, 9
- H04L9/065
- H04L9/08
- H04L2209/08
- H04L2209/80
- H04L9/0875
- H04L63/0457
- H04W12/033
- H04W12/041
- H04L9/0869
- IPC, 1
- H04L9 12
