SearcharxivSearch

arXiv subjects

Aiqun Hu

Publications and source records attributed to Aiqun Hu.

At least 19 recordsLinked to original sources

Physical-Layer Fingerprint-Space Capacity Analysis for 100BASE-TX Devices in IIoT

Industrial Internet of Things (IIoT) networks widely adopt Ethernet technologies, such as 100BASE-TX, for industrial communications. As industrial networks continue to scale, reliable device authentication becomes increasingly important for preventing device impersonation and unauthorized access. Physical-layer fingerprinting (PLF) exploits device-dependent fingerprint features in transmitted signals and provides a hardware-based approach for terminal authentication. However, the distinguishable space supported by 100BASE-TX physical-layer fingerprints and its capacity boundary remain largely unexplored. To analyze the capacity of physical-layer fingerprints, this paper proposes a nonlinear and impulse-response model (NAIM) that characterizes device-dependent waveform differences in 100BASE-TX transmitted waveforms. The nonlinear component captures steady-state level deviations, while the impulse-response component describes the transition response during level transitions. The 100BASE-TX transmitter waveform requirements, the observation resolution determined by noise and analog-to-digital conversion (ADC) quantization, and the target bit-error ratio (BER) constrain the admissible fingerprint space. Under the NAIM model, the fingerprint-space capacity of 100BASE-TX terminals is derived as approximately $2.96\times10^{10}$ distinguishable states. Experiments on signals collected from 48 NICs under two cable conditions estimate a Gaussian-equivalent empirical capacity from the measured inter-device and within-device variations. Under the 5-m cable condition, empirical capacity and closed-set identification consistently rank the three NIC models, and a larger empirical capacity yields higher identification accuracy. These results demonstrate that the proposed capacity analysis provides a pre-deployment assessment for physical-layer fingerprinting in IIoT.

cs.CR

Channel-Robust RFF for Low-Latency 5G Device Identification in SIMO Scenarios

Ultra-low latency, the hallmark of fifth-generation mobile communications (5G), imposes exacting timing demands on identification as well. Current cryptographic solutions introduce additional computational overhead, which results in heightened identification delays. Radio frequency fingerprint (RFF) identifies devices at the physical layer, blocking impersonation attacks while significantly reducing latency. Unfortunately, multipath channels compromise RFF accuracy, and existing channel-resilient methods demand feedback or processing across multiple time points, incurring extra signaling latency. To address this problem, the paper introduces a new RFF extraction technique that employs signals from multiple receiving antennas to address multipath issues without adding latency. Unlike single-domain methods, the Log-Linear Delta Ratio (LLDR) of co-temporal channel frequency responses (CFRs) from multiple antennas is employed to preserve discriminative RFF features, eliminating multi-time sampling and reducing acquisition time. To overcome the challenge of the reliance on minimal channel variation, the frequency band is segmented into sub-bands, and the LLDR is computed within each sub-band individually. Simulation results indicate that the proposed scheme attains a 96.13% identification accuracy for 30 user equipments (UEs) within a 20-path channel under a signal-to-noise ratio (SNR) of 20 dB. Furthermore, we evaluate the theoretical latency using the Roofline model, resulting in the air interface latency of 0.491 ms, which satisfies ultra-reliable and low-latency communications (URLLC) latency requirements.

cs.CR

Collusion-Driven Impersonation Attack on Channel-Resistant RF Fingerprinting

Radio frequency fingerprint (RFF) is a promising device identification technology, with recent research shifting from robustness to security due to growing concerns over vulnerabilities. To date, while the security of RFF against basic spoofing such as MAC address tampering has been validated, its resilience to advanced mimicry remains unknown. To address this gap, we propose a collusion-driven impersonation attack that achieves RF-level mimicry, successfully breaking RFF identification systems across diverse environments. Specifically, the attacker synchronizes with a colluding receiver to match the centralized logarithmic power spectrum (CLPS) of the legitimate transmitter; once the colluder deems the CLPS identical, the victim receiver will also accept the forged fingerprint, completing RF-level spoofing. Given that the distribution of CLPS features is relatively concentrated and has a clear underlying structure, we design a spoofed signal generation network that integrates a variational autoencoder (VAE) with a multi-objective loss function to enhance the similarity and deceptive capability of the generated samples. We carry out extensive simulations, validating cross-channel attacks in environments that incorporate standard channel variations including additive white Gaussian noise (AWGN), multipath fading, and Doppler shift. The results indicate that the proposed attack scheme essentially maintains a success rate of over 95% under different channel conditions, revealing the effectiveness of this attack.

cs.CR

Fighting Fire with Fire: Channel-Independent RF Fingerprinting via the Ratio of Linear to Logarithmic Differential Spectrum

Eliminating the influence of temporally varying channel components on the radio frequency fingerprint (RFF) extraction has been an enduring and challenging issue. To overcome this problem, we propose a channel-independent RFF extraction method inspired by the idea of 'fighting fire with fire'. Specifically, we derive the linear differential spectrum and the logarithmic differential spectrum of the channel frequency responses (CFRs) from the received signals at different times, and then calculate the ratio of the two spectrums. It is found that the division operation effectively counteracts the channel effects, while simultaneously preserving the integrity of the RFFs. Our experiments on LTE-V2X, LoRa and Wi-Fi devices show that the proposed method achieves an average identification accuracy exceeding 95% across various environments.

eess.SP

A Robust Anti-noise Scheme for RF Fingerprint Identification

Radio frequency (RF) fingerprint technology is utilized for wireless device identification, extensively employed in the internet of things (IoT). The operating environment for IoT devices is challenging, with pervasive noise and distortion on the signals which blur the feature space of RF fingerprints. Consequently, the model accuracy obtained through training at high signal-to-noise ratio (SNR) scenarios decreases with the low SNR of the received signals in testing. To solve the noise domain adaptation problem, an anti-noise scheme is proposed to enhance identification accuracy of RF fingerprint at varying SNRs. The squared cross power spectral density (SCPSD) features are first proposed to obtain the same RF fingerprint representation. Subsequently, the specific effect of noise on SCPSD is theoretically derived and the rationality of the scheme is demonstrated through simulation experiments. Finally, 60 off-the-shelf ZigBee devices are employed to evaluate the performance of the anti-noise algorithm. The experimental results show that employing the random subspace k-nearest neighbors (RSKNN) classifier not only effectively classifies devices with multi-cluster feature, but combined with the anti-noise scheme can significantly improve the accuracy by approximately 46% for SNRs not less than 5 dB.

eess.SP

RIS-Jamming: Breaking Key Consistency in Channel Reciprocity-based Key Generation

Channel Reciprocity-based Key Generation (CRKG) exploits reciprocal channel randomness to establish shared secret keys between wireless terminals. This new security technique is expected to complement existing cryptographic techniques for secret key distribution of future wireless networks. In this paper, we present a new attack, reconfigurable intelligent surface (RIS) jamming, and show that an attacker can prevent legitimate users from agreeing on the same key by deploying a malicious RIS to break channel reciprocity. Specifically, we elaborate on three examples to implement the RIS jamming attack: Using active nonreciprocal circuits, performing time-varying controls, and reducing the signal-to-noise ratio. The attack effect is then studied by formulating the secret key rate with a relationship to the deployment of RIS. To resist such RIS jamming attacks, we propose a countermeasure that exploits wideband signals for multipath separation. The malicious RIS path is distinguished from all separated channel paths, and thus the countermeasure is referred to as contaminated path removal-based CRKG(CRP-CRKG). We present simulation results, showing that legitimate users under RIS jamming are still able to generate secret keys from the remaining paths. We also experimentally demonstrate the RIS jamming attack by using commodity Wi-Fi devices in conjunction with a fabricated RIS prototype. In our experiments, we were able to increase the average bit disagreement ratio (BDR) of raw secret keys by 20%. Further, we successfully demonstrate the proposed CRP-CRKG countermeasure to tackle RIS jamming in wideband systems as long as the source of randomness and the RIS propagation paths are separable.

cs.IT

Enabling Deep Learning-based Physical-layer Secret Key Generation for FDD-OFDM Systems in Multi-Environments

Deep learning-based physical-layer secret key generation (PKG) has been used to overcome the imperfect uplink/downlink channel reciprocity in frequency division duplexing (FDD) orthogonal frequency division multiplexing (OFDM) systems. However, existing efforts have focused on key generation for users in a specific environment where the training samples and test samples follow the same distribution, which is unrealistic for real-world applications. This paper formulates the PKG problem in multiple environments as a learning-based problem by learning the knowledge such as data and models from known environments to generate keys quickly and efficiently in multiple new environments. Specifically, we propose deep transfer learning (DTL) and meta-learning-based channel feature mapping algorithms for key generation. The two algorithms use different training methods to pre-train the model in the known environments, and then quickly adapt and deploy the model to new environments. Simulation and experimental results show that compared with the methods without adaptation, the DTL and meta-learning algorithms both can improve the performance of generated keys. In addition, the complexity analysis shows that the meta-learning algorithm can achieve better performance than the DTL algorithm with less cost.

cs.IT

Reconfigurable Intelligent Surface-aided Secret Key Generation in Multi-Cell Systems

Physical-layer key generation (PKG) exploits the reciprocity and randomness of wireless channels to generate a symmetric key between two legitimate communication ends. However, in multi-cell systems, PKG suffers from severe pilot contamination due to the reuse of pilots in different cells. In this paper, we invoke multiple reconfigurable intelligent surfaces (RISs) for adaptively shaping the environment and enhancing the PKG performance. To this end, we formulate an optimization problem to maximize the weighted sum key rate (WSKR) by jointly optimizing the precoding matrices at the base stations (BSs) and the phase shifts at the RISs. For addressing the non-convexity of the problem, we derive an upper bound of the WSKR and prove its tightness. To tackle the upper bound maximization problem, we apply an alternating optimization (AO)-based algorithm to divide the joint optimization into two sub-problems. We apply the Lagrangian dual approach based on the Karush-Kuhn-Tucker (KKT) conditions for the sub-problem of precoding matrices and adopt a projected gradient ascent (PGA) algorithm for the sub-problem of phase shifts. Simulation results confirm the near-optimal performance of the proposed algorithm and the effectiveness of RISs for improving the WSKR via mitigating pilot contamination.

cs.IT

Radio Frequency Fingerprints Extraction for LTE-V2X: A Channel Estimation Based Methodology

The vehicular-to-everything (V2X) technology has recently drawn a number of attentions from both academic and industrial areas. However, the openness of the wireless communication system makes it more vulnerable to identity impersonation and information tampering. How to employ the powerful radio frequency fingerprint (RFF) identification technology in V2X systems turns out to be a vital and also challenging task. In this paper, we propose a novel RFF extraction method for Long Term Evolution-V2X (LTE-V2X) systems. In order to conquer the difficulty of extracting transmitter RFF in the presence of wireless channel and receiver noise, we first estimate the wireless channel which excludes the RFF. Then, we remove the impact of the wireless channel based on the channel estimate and obtain initial RFF features. Finally, we conduct RFF denoising to enhance the quality of the initial RFF. Simulation and experiment results both demonstrate that our proposed RFF extraction scheme achieves a high identification accuracy. Furthermore, the performance is also robust to the vehicle speed.

eess.SP

Information-Theoretic Secure Key Sharing for Wide-Area Mobile Applications

With the rapid growth of handheld devices in the internet of things (IoT) networks, mobile applications have become ubiquitous in everyday life. As technology is developed, so do also the risks and threats associated with it, especially in the forthcoming quantum era. Existing IoT networks, however, lack a quantum-resistant secret key sharing scheme to meet confidential message transmission demands in wide-area mobile applications. To address this issue, this article proposes a new scheme, channel reciprocity (CR) based quantum key distribution (QKD) CR-QKD, which accomplishes the goal of secret key sharing by combining emerging techniques of QKD and CR-based key generation (CRKG). Exploiting laws of quantum physics and properties of wireless channels, the proposed scheme is able to ensure the secrecy of the key, even against computationally unbounded adversaries. The basic mechanism is elaborated for a single-user case and it is extended into a multi-user case by redesigning a multi-user edge forwarding strategy. In addition, to make CR-QKD more practical, some enhancement strategies are studied to reduce the time delay and to improve the secret key generation rate in a secure manner. A prototype of CR-QKD is demonstrated in a metropolitan area network, where secret keys are shared between two remote IoT devices that are roughly fifteen kilometers apart from each other. The experimental results have verified that CR-QKD allows a secret key rate of 424 bits per second with a retransmission rate of 2.1%.

cs.IT

Reconfigurable Intelligent Surface-Assisted Secret Key Generation in Spatially Correlated Channels

Reconfigurable intelligent surface (RIS) is a disruptive technology to enhance the performance of physical-layer key generation (PKG) thanks to its ability to smartly customize the radio environments. Existing RIS-assisted PKG methods are mainly based on the idealistic assumption of an independent and identically distributed (i.i.d.) channel model at both the base station (BS) and the RIS. However, the i.i.d. model is inaccurate for a typical RIS in an isotropic scattering environment and neglecting the existence of channel spatial correlation would possibly degrade the PKG performance. In this paper, we establish a general spatially correlated channel model and propose a new channel probing framework based on the transmit and the reflective beamforming. We derive a closed-form key generation rate (KGR) expression and formulate an optimization problem, which is solved by using the low-complexity Block Successive Upper-bound Minimization (BSUM) with Mirror-Prox method. Simulation results show that compared to the existing methods based on the i.i.d. fading model, our proposed method achieves about $5$ dB transmit power gain when the spacing between two neighboring RIS elements is a quarter of the wavelength. Also, the KGR increases significantly with the number of RIS elements while that increases marginally with the number of BS antennas.

cs.IT

Disentangled Representation Learning for RF Fingerprint Extraction under Unknown Channel Statistics

Deep learning (DL) applied to a device's radio-frequency fingerprint~(RFF) has attracted significant attention in physical-layer authentication due to its extraordinary classification performance. Conventional DL-RFF techniques are trained by adopting maximum likelihood estimation~(MLE). Although their discriminability has recently been extended to unknown devices in open-set scenarios, they still tend to overfit the channel statistics embedded in the training dataset. This restricts their practical applications as it is challenging to collect sufficient training data capturing the characteristics of all possible wireless channel environments. To address this challenge, we propose a DL framework of disentangled representation~(DR) learning that first learns to factor the signals into a device-relevant component and a device-irrelevant component via adversarial learning. Then, it shuffles these two parts within a dataset for implicit data augmentation, which imposes a strong regularization on RFF extractor learning to avoid the possible overfitting of device-irrelevant channel statistics, without collecting additional data from unknown channels. Experiments validate that the proposed approach, referred to as DR-based RFF, outperforms conventional methods in terms of generalizability to unknown devices even under unknown complicated propagation environments, e.g., dispersive multipath fading channels, even though all the training data are collected in a simple environment with dominated direct line-of-sight~(LoS) propagation paths.

eess.SP

Joint Precoding and Phase Shift Design in Reconfigurable Intelligent Surfaces-Assisted Secret Key Generation

Key generation is a promising technique to establish symmetric keys between resource-constrained legitimate users. However, key generation suffers from low secret key rate (SKR) in harsh environments where channel randomness is limited. To address the problem, reconfigurable intelligent surfaces (RISs) are introduced to reshape the channels by controlling massive reflecting elements, which can provide more channel diversity. In this paper, we design a channel probing protocol to fully extract the randomness from the cascaded channel, i.e., the channel through reflecting elements. We derive the analytical expressions of SKR and design a water-filling algorithm based on the Karush-Kuhn-Tucker (KKT) conditions to find the upper bound. To find the optimal precoding and phase shift matrices, we propose an algorithm based on the Grassmann manifold optimization methods. The system is evaluated in terms of SKR, bit disagreement rate (BDR) and randomness. Simulation results show that our protocols significantly improve the SKR as compared to existing protocol.

cs.IT

Joint Transmit and Reflective Beamforming for RIS-assisted Secret Key Generation

Reconfigurable intelligent surface (RIS) is a promising technique to enhance the performance of physical-layer key generation (PKG) due to its ability to smartly customize the radio environments. Existing RIS-assisted PKG methods are mainly based on the idealistic assumption of an independent and identically distributed (i.i.d.) channel model at both the transmitter and the RIS. However, the i.i.d. model is inaccurate for a typical RIS in an isotropic scattering environment. Also, neglecting the existence of channel spatial correlation would degrade the PKG performance. In this paper, we establish a general spatially correlated channel model in multi-antenna systems and propose a new PKG framework based on the transmit and the reflective beamforming at the base station (BS) and the RIS. Specifically, we derive a closed-form expression for characterizing the key generation rate (KGR) and obtain a globally optimal solution of the beamformers to maximize the KGR. Furthermore, we analyze the KGR performance difference between the one adopting the assumption of the i.i.d. model and that of the spatially correlated model. It is found that the beamforming designed for the correlated model outperforms that for the i.i.d. model while the KGR gain increases with the channel correlation. Simulation results show that compared to existing methods based on the i.i.d. fading model, our proposed method achieves about $5$ dB performance gain when the BS antenna correlation $ρ$ is $0.3$ and the RIS element spacing is half of the wavelength.

cs.IT

Reconfigurable Intelligent Surface for Physical Layer Key Generation: Constructive or Destructive?

Physical layer key generation (PKG) is a promising means to provide on-the-fly shared secret keys by exploiting the intrinsic randomness of the radio channel. However, the performance of PKG is highly dependent on the propagation environments. Due to its feature of controlling the wireless environment, reconfigurable intelligent surface~(RIS) is appealing to be applied in PKG. In this paper, in contrast to the existing literature, we investigate both the constructive and destructive effects of RIS on the PKG scheme. For the constructive aspect, we have identified static and wave-blockage environments as two RIS-empowered-PKG applications in future wireless systems. In particular, our experimental results in a static environment showed that RIS can enhance the entropy of the secret key, achieving a key generation rate (KGR) of 97.39 bit/s with a bit disagreement rate (BDR) of 0.083. In multi-user systems where some remote users are in worse channel conditions, the proposed RIS-assisted PKG algorithm improves the sum secret key rate by more than 2 dB, compared to the literature. Furthermore, we point out that RIS could be utilized by an attacker to perform new jamming and leakage attacks and give countermeasures, respectively. Finally, we outline future research directions for PKG systems in light of the RIS.

cs.IT

Fast and Secure Key Generation with Channel Obfuscation in Slowly Varying Environments

The physical-layer secret key generation has emerged as a promising solution for establishing cryptographic keys by leveraging reciprocal and time-varying wireless channels. However, existing approaches suffer from low key generation rates and vulnerabilities under various attacks in slowly varying environments. We propose a new physical-layer secret key generation approach with channel obfuscation, which improves the dynamic property of channel parameters based on random filtering and random antenna scheduling. Our approach makes one party obfuscate the channel to allow the legitimate party to obtain similar dynamic channel parameters yet prevents a third party from inferring the obfuscation information. Our approach allows more random bits to be extracted from the obfuscated channel parameters by a joint design of the K-L transform and adaptive quantization. A testbed implementation shows that our approach, compared to the existing ones that we evaluate, performs the best in generating high entropy bits at a fast rate and a high-security level in slowly varying environments. Specifically, our approach can achieve a significantly faster secret bit generation rate at about $67$ bit/pkt, and the key sequences can pass the randomness tests of the NIST test suite.

cs.CR

Deep Learning-based Physical-Layer Secret Key Generation for FDD Systems

Physical-layer key generation (PKG) establishes cryptographic keys from highly correlated measurements of wireless channels, which relies on reciprocal channel characteristics between uplink and downlink, is a promising wireless security technique for Internet of Things (IoT). However, it is challenging to extract common features in frequency division duplexing (FDD) systems as uplink and downlink transmissions operate at different frequency bands whose channel frequency responses are not reciprocal any more. Existing PKG methods for FDD systems have many limitations, i.e., high overhead and security problems. This paper proposes a novel PKG scheme that uses the feature mapping function between different frequency bands obtained by deep learning to make two users generate highly similar channel features in FDD systems. In particular, this is the first time to apply deep learning for PKG in FDD systems. We first prove the existence of the band feature mapping function for a given environment and a feedforward network with a single hidden layer can approximate the mapping function. Then a Key Generation neural Network (KGNet) is proposed for reciprocal channel feature construction, and a key generation scheme based on the KGNet is also proposed. Numerical results verify the excellent performance of the KGNet-based key generation scheme in terms of randomness, key generation ratio, and key error rate. Besides, the overhead analysis shows that the method proposed in this paper can be used for resource-contrained IoT devices in FDD systems.

cs.CR

On the RIS Manipulating Attack and Its Countermeasures in Physical-layer Key Generation

Reconfigurable Intelligent Surface (RIS) is a new paradigm that enables the reconfiguration of the wireless environment. Based on this feature, RIS can be employed to facilitate Physical-layer Key Generation (PKG). However, this technique could also be exploited by the attacker to destroy the key generation process via manipulating the channel features at the legitimate user side. Specifically, this paper proposes a new RIS-assisted Manipulating attack (RISM) that reduces the wireless channel reciprocity by rapidly changing the RIS reflection coefficient in the uplink and downlink channel probing step in orthogonal frequency division multiplexing (OFDM) systems. The vulnerability of traditional key generation technology based on channel frequency response (CFR) under this attack is analyzed. Then, we propose a slewing rate detection method based on path separation. The attacked path is removed from the time domain and a flexible quantization method is employed to maximize the Key Generation Rate (KGR). The simulation results show that under RISM attack, when the ratio of the attack path variance to the total path variance is 0.17, the Bit Disagreement Rate (BDR) of the CFR-based method is greater than 0.25, and the KGR is close to zero. In addition, the proposed detection method can successfully detect the attacked path for SNR above 0 dB in the case of 16 rounds of probing and the KGR is 35 bits/channel use at 23.04MHz bandwidth.

cs.IT