Source-linked AI summary
Exploiting Channel Diversity in Secret Key Generation from Multipath Fading Randomness
Yanpei Liu, Stark C. Draper, Akbar M. Sayeed
TL;DR
Wireless multipath channels offer shared randomness for secret-key generation, but extracting keys from only one channel parameter limits the usable diversity. The paper models and exploits channel diversity through CSI, compares it with RSSI, and builds LDPC-based reconciliation systems. CSI-based extraction has higher key capacity than RSSI-based extraction, while non-binary LDPC codes approach capacity at high SNR.
Problem
Single-parameter extraction limits the channel randomness available for secret-key generation, motivating methods that exploit multipath channel diversity.
Method
The paper models multipath OFDM channels, compares CSI- and RSSI-based extraction, and implements binary and four-ary LDPC-based key-generation systems.
Results
CSI-based key generation has greater secret-key capacity than RSSI-based generation, while four-ary LDPC decoding improves performance and approaches capacity at high SNR.
Takeaways & Limitations
Making CSI available to higher-layer applications can benefit secret-key generation by enabling exploitation of channel diversity.
Abstract
from arXiv · showhide
We design and analyze a method to extract secret keys from the randomness inherent to wireless channels. We study a channel model for multipath wireless channel and exploit the channel diversity in generating secret key bits. We compare the key extraction methods based both on entire channel state information (CSI) and on single channel parameter such as the received signal strength indicators (RSSI). Due to the reduction in the degree-of-freedom when going from CSI to RSSI, the rate of key extraction based on CSI is far higher than that based on RSSI. This suggests that exploiting channel diversity and making CSI information available to higher layers would greatly benefit the secret key generation. We propose a key generation system based on low-density parity-check (LDPC) codes and describe the design and performance of two systems: one based on binary LDPC codes and the other (useful at higher signal-to-noise ratios) based on four-ary LDPC codes.
I. INTRODUCTION
The paper studies secret-key generation from multipath wireless-channel randomness and argues that exploiting channel diversity can increase key-generation rates. It compares full CSI with RSSI-based extraction and develops an LDPC-based practical system.
- Motivation: Multipath fading channels provide continually changing randomness that is difficult for nearby eavesdroppers to observe because of spatial decorrelation.Motion changes the channel, while an eavesdropper even a few wavelengths away observes a nearly independent channel.
- Contribution: The paper studies OFDM secret-key generation using either full channel state information or only received signal strength indicators available to higher layers.The goal is to characterize both channel suitability and the effect of exposing CSI to security applications.
- Motivation: Existing systems often extract key bits from a single channel parameter, fundamentally limiting the available channel diversity.The paper identifies this limitation in related CSI- and RSSI-based approaches.
- System design: The proposed key-generation process uses reciprocal two-way channel sounding, quantization, public reconciliation, and error-correcting-code syndromes.Alice and Bob rely on a channel static during training so their noisy observations correspond to the same channel coefficients.
- OFDM model: Channel modeling represents the wireless link through multipath impulse-response coefficients and frequency-domain OFDM channel coefficients.The model uses propagation delays, path gains, orthogonal tones, receiver noise, and sampled delay-bin coefficients.
B. Signal-to-noise ratio
This section defines the signal-to-noise relationships for rich-multipath OFDM channel coefficients and sampled delay-bin coefficients. The model distinguishes frequency-domain marginal behavior from dependence across tones.
- Channel model: In rich multipath, the frequency-domain coefficients H_n are modeled as complex Gaussian variables with variance σ_H^2.The passage introduces the per-tone SNR after specifying this channel model.
- SNR relations: A relation connects the channel-coefficient variance and the per-tone SNR, with a simplified form when sampled coefficients have equal variance.The equal-variance condition yields the simplified relationship used in later analysis.
III. SECRET KEY SYSTEMS: DEFINITIONS AND MEASUREMENT MODEL
The paper defines secret-key capacity and the operational key-generation system for noisy reciprocal channel measurements. Its measurement model assumes two-way sounding within one coherence period and treats the eavesdropper’s channel observations as ineffective in rich scattering.
- System definitions: Secret-key generation is organized around a source of correlated observations, public communication, and recovery of a shared key.The paper situates these definitions within the practical system operation.
- System definitions: A secret-key generation system consists of functions mapping Alice’s randomness to a key, producing a public message, and decoding from Bob’s observation and that message.Bob’s estimate can be passed through Alice’s key function when decoding succeeds.
- Capacity: Secret-key capacity is the supremum of achievable rates satisfying near-uniformity, reliable recovery, and secrecy conditions.The rate definition requires these properties for arbitrarily small error parameters and sufficiently large blocklength.
- Threat model: The model omits a correlated eavesdropper observation because rich multipath channels change substantially over a few wavelengths, making useful interception spatially difficult.The paper therefore treats the eavesdropper’s observations as independent and does not include them in the stated definitions.
B. Measurement model
Alice and Bob obtain noisy, correlated multipath channel measurements through reciprocal two-way sounding across coherence periods. The model accounts for receiver noise and phase offsets, showing that channel diversity can mitigate phase-offset loss.
- Measurement model: Alice and Bob exchange identical sounding signals during a static channel interval to obtain noisy observations of the same multipath coefficients.The channel is assumed static during the two-way training, within a coherence period.
- Measurement model: Measurements are represented as sampled complex channel coefficients plus independent receiver noise.The real and imaginary components inherit the coefficient correlation, while the observation noises are modeled as complex Gaussian.
- Measurement model: Repeating sounding across L independent coherence periods supplies multiple independent channel observations for long-block secret-key extraction.The model assumes identically distributed observations across coherence periods and pads unused channel coefficients with zeros.
- Phase Offset: Local-oscillator phase offsets add measurement noise and are modeled as a differential offset between Alice and Bob.The offset is treated as time-invariant within a sounding but not necessarily across channel trainings.
- Phase Offset: The phase-offset loss grows more slowly than the channel-diversity gain, supporting diversity as both a capacity boost and a mitigation mechanism.The variance of offset estimation can decrease at most as 1/L, implying a general loss scaling of log L versus a linear-in-L gain.
- Phase Offset: The LDPC reconciliation design is adapted to estimate the phase offset as part of the reconciliation process.This integrates phase-offset estimation into key extraction rather than treating it only as a separate preprocessing step.
IV. SECRET KEY CAPACITY CALCULATIONS
The paper evaluates secret-key capacity for OFDM channels using sampled channel coefficients under a jointly complex-Gaussian model. It first considers a general time-domain model, then uses equal-variance coefficients to simplify the analysis.
- Capacity evaluation: Secret-key capacity is evaluated for general OFDM time-domain channel coefficients before specializing to an equal-variance model.The specialization is used to draw general lessons about secret-key generation for OFDM channels.
- Capacity evaluation: The capacity analysis uses jointly complex-Gaussian, temporally independent observations from Alice and Bob.This assumption enables evaluation in terms of the channel SNR.
- Equal-variance model: When sampled channel coefficients have equal variance, the capacity expression simplifies under the idealized model.The coefficients are modeled as identically distributed complex Gaussian variables with variance σ2.
- Equal-variance model: The time-domain correlation coefficient is related to the corresponding frequency-domain correlation coefficient.The same correlation structure is used to connect channel representations across domains.
B. Secret key generation based on measurements of RSSI
The paper compares secret-key capacity from full sampled channel coefficients with capacity from RSSI-only measurements. Because RSSI compresses the channel vector to one value, its capacity does not grow with the number of observations.
- RSSI capacity: RSSI summarizes the full channel-state vector, producing a substantial reduction in secret-key capacity.The comparison is motivated by the fact that many commercial transceivers expose RSSI rather than full channel-state information.
- RSSI capacity: RSSI values are modeled as non-standard chi-square variables with 2L degrees of freedom and correlated underlying Gaussian components.The joint distribution is used for numerical mutual-information calculations.
- RSSI capacity: The RSSI secret-key capacity is computed both numerically and with a Gaussian approximation.The Gaussian approximation uses moments obtained from the joint moment-generating function.
- RSSI capacity: For large L, the RSSI variables are approximated as Gaussian using the central limit theorem.Their approximate distribution is N(2L, 4L).
- Capacity comparison: The coefficient-based capacity increases with L, whereas RSSI-based capacity remains constant for fixed SNRτ.With M = 10, the paper compares L = 2, 5, and 10 and reports that the Gaussian approximation is accurate even for relatively small L.
C. Representing complex channel coefficients by their real-and-imaginary parts or by their magnitude-and-phase
The channel’s real and imaginary parts provide independent pieces of randomness without capacity loss, whereas separating magnitude and phase leaves capacity unused because cross-dependencies remain.
- The secret key capacity is at least the sum of mutual informations from channel magnitudes and phases.However, dependence between Alice’s phase and Bob’s magnitude, and vice versa, means magnitude and phase should not be treated separately.
- Real and imaginary parts of Alice’s and Bob’s channel coefficients are independent, so they can be processed as separate randomness sources without capacity loss.
- The capacity gap persists across SNR, and phase information contributes most of the magnitude-and-phase mutual information.The magnitude term corresponds to RSSI and is much smaller than the phase term.
- Key reconciliation with LDPC codes: The reconciliation system uses LDPC codes to decode correlated quantized observations after Alice sends a syndrome identifying the relevant coset.The syndrome reveals little information because many sequences occupy each coset, while Bob uses his observation to decode Alice’s quantized sequence.
- Key reconciliation with LDPC codes: An LDPC code over GF(q) has rate R = (1 − m/N) log2(q), and reliable recovery requires NR < I(XN_A,Q; XN_B).The construction uses a sparse parity-check matrix and cosets containing 2^NR sequences.
- Key reconciliation with LDPC codes: The design studies binary and four-level scalar quantization, with soft decoding avoiding the information loss caused by quantizing Bob’s observations.
A,Q; XN
The four-level design represents each GF(4) symbol with two binary bit planes and decodes them jointly through binary LDPC codes connected by local factor functions.
- As quantization becomes increasingly fine, the achievable secrecy-rate upper bound approaches the stated information-theoretic limit.
- The four-level quantizer represents each symbol xi ∈ {0, 1, 2, 3} with binary components xi,M and xi,L.
- Two length-N binary LDPC codes can be applied separately to the bit planes, while a length-2N code can decode their concatenation.The separate-code design offers more flexibility and simpler implementation, whereas concatenation generally performs somewhat better.
- A factor graph connects each GF(4) symbol to the check nodes of two binary LDPC codes through a local function Fi.
- The four-level decoder passes channel evidence and LDPC messages between the GF(4) symbol nodes and the two binary code planes.The binary-code messages use the corresponding syndromes so decoding respects the correct cosets.
- After iterative message passing, the decoder estimates each symbol as the value with maximum marginal probability.The simulations use up to 50 iterations before stopping when messages converge or the maximum is reached.
C. Phase Offset Estimation
The reconciliation system jointly estimates phase offset and recovers the quantized channel sequence, but supporting this extra unknown requires a lower code rate and reduces secrecy rate.
- Phase offset during two-way training degrades channel measurements, motivating phase-estimation techniques integrated into reconciliation.
- The presentation assumes a constant phase offset across multiple channel trainings, while time-varying offsets are left for future implementation.
- Supporting phase-offset estimation requires a lower code rate, which reduces the secrecy rate through a larger public syndrome and smaller cosets.
- At the original higher code rate, many high-probability coset elements can remain, making decoding erroneous with high probability.A lower-rate code produces fewer candidate elements and can permit a unique solution to the joint decoding problem.
- The proposed joint procedure adds a discretized phase-offset variable connected to the check nodes, allowing message passing to estimate the offset.
VI. SIMULATION RESULTS
This section introduces simulation results and discussion for the proposed secret key generation system.
- The simulations evaluate the proposed secret key generation system.
- The section presents results and discussion rather than a theoretical construction alone.
- The proposed system is assessed through simulation.
A. OFDM simulation results
The OFDM simulations reduce 52 frequency-domain coefficients to 13 sampled coefficients and evaluate their secret-key capacity and LDPC reconciliation performance. Secret-key capacity depends on both SNR and channel degrees of freedom, while soft, irregular, and four-ary LDPC decoding improve performance, with four-ary codes approaching capacity at high SNR_f.
- Secret-key capacity: Smaller coherence time increases secret-key capacity by supplying new randomness at a higher rate, while the relationship with L depends on operating SNR_f.Capacity scales roughly linearly with delay spread and bandwidth, with second-order effects.
- Channel simulation: The simulation uses N_p = 300 transmission paths and reduces M = 52 frequency-domain coefficients to L = 13 independent sampled coefficients.The choice L = 13 follows τ_max = 800 ns and L ≈⌈τ_maxW⌉.
- Secret-key capacity: 104 bits per coherence time are obtained at 20 dB, corresponding to 1040 bits per second when coherence time is 100 ms.This capacity is computed from the first L nonzero sampled channel coefficients and is described as an approximation.
- Secret-key capacity: Secret-key capacity has no single optimal OFDM channel across SNR_f: fewer degrees of freedom are preferred at low SNR_f, while more are preferred at high SNR_f.The paper relates this trade-off to power per degree of freedom and the number of degrees of freedom.
- LDPC performance: Soft decoding improves LDPC performance over hard decoding, irregular codes improve it further, and four-ary LDPC approaches capacity at high SNR_f.Codes with rate below 0.25 are not simulated because lower code rate means less secrecy.
- Overall findings: The study finds CSI-based key generation superior to RSSI-based generation because CSI has larger secret-key capacity, and demonstrates feasibility using sampled channel coefficients.The system is implemented with both regular and irregular LDPC codes.
APPENDIX
The appendix develops information-theoretic lemmas and a theorem concerning mutual information among complex channel coefficients and their magnitude, phase, real, and imaginary components. The proof uses independence, mutual-information chain rules, and non-negativity.
- Lemma 1: Lemma 1 characterizes when independence of Z from X or Y yields an equality involving their mutual informations.Equality holds if and only if Z is independent of the pair (X, Y).
- Theorem: The theorem’s inequality follows from the chain rule, independence of magnitude and phase components, and non-negativity of mutual information.The proof explicitly identifies these properties as the basis for the inequality.
- Theorem: The theorem’s proof decomposes mutual information among channel magnitudes and phases using the chain rule and independence relations.The decomposition includes I(|h_A|; |h_B|), I(|h_A|; φ_B), I(φ_A; |h_B|), and I(φ_A; φ_B).
- Theorem: The appendix establishes the factorization of the joint density of (h_A, h_B) into the corresponding real and imaginary component densities.This factorization supports the theorem’s use of real and imaginary parts.