Jung-Min Park 0001

dblp:66/4019-1 · also Jung-Min "Jerry" Park, Jung-Min Jerry Park · DBLP profile ↗
← Back
68ranked-venue papers
5as first author
8since 2021 · last 2023
0000-0002-4879-8467ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 51 · 1 first-author · 6 since 2021Security and privacy · 8 · 2 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-authorSystems, architecture and hardware · 2 · 1 first-authorArtificial intelligence and machine learning · 1Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2023 iDROP: Robust Localization for Indoor Navigation of Drones With Optimized Beacon Placement
abstract
Drones in many applications need the ability to fly fully or partially autonomously to accomplish their mission. To allow these fully/partially autonomous flights, first, the drone needs to be able to locate itself constantly. Then, the navigation command signal would be generated and passed on to the controller unit of the drone. In this article, we propose a localization scheme for drones called robust localization for indoor navigation of drones with optimized beacon placement (iDROP) that is specifically devised for GPS-denied environments (e.g., indoor spaces). Instead of GPS signals, iDROP relies on speaker-generated ultrasonic acoustic signals to enable a drone to estimate its location. In general, localization error is caused by two factors: the ranging error and the error induced by relative geometry between the transmitters and the receiver. iDROP mitigates these two types of errors and provides a high-precision 3-D localization scheme for drones. iDROP employs a waveform that is robust against multipath fading. Moreover, placing beacons in optimal locations reduces the localization error induced by the relative geometry between the transmitters and the receiver.
Alireza Famili, Angelos Stavrou, Haining Wang 0001, Jung-Min Park 0001
IEEE Internet Things J.4
2023 OFDRA: Optimal Femtocell Deployment for Accurate Indoor Positioning of RIS-Mounted AVs
abstract
The pursuit of high-accuracy localization without relying on the global positioning system (GPS) has gained significant interest in recent years. The deployment of autonomous vehicles (AVs) in diverse indoor applications exemplifies a prominent domain where the demand for a robust positioning system is evident. With the advancements in 5G and beyond radio access networks (RAN), the availability of new positioning signals presents an opportunity to deliver accurate location estimates for these applications. Nevertheless, these signals encounter substantial path losses in indoor environments. Additionally, the precise localization within existing frameworks requires stringent synchronization, which is challenging to meet. In this paper, we propose OFDRA: Optimal Femtocell Deployment for Accurate Indoor Positioning of RIS-Mounted AVs, a novel positioning framework that is robust against multipath and does not require strict synchronization between anchor-anchor or anchor-target entities. Specifically, OFDRA is designed to operate in scenarios where the line of sight (LOS) exists. The first design objective of OFDRA is the mitigation of ranging errors by leveraging a compact reconfigurable intelligent surface (RIS) mounted on top of AVs acting as a programmable mirror in a 5G network. The second design objective is to achieve optimal anchor placement in three-dimensional indoor spaces, thereby reducing the geometric dilution of precision (GDOP) and mitigating geometric-induced errors in the final position estimation. Our experimental verification reveals that the localization error is influenced by GDOP, encompassing both the$X-Y$plane and$Z$-axis estimations. Through optimized anchor placement, OFDRA demonstrates a seven-fold enhancement in$Z$-axis accuracy compared to the state-of-the-art, achieving a sub-1 m three-dimensional accuracy for more than 95% of cases.
Alireza Famili, Tolga O. Atalay, Angelos Stavrou, Haining Wang 0001, Jung-Min Park 0001
IEEE J. Sel. Areas Commun.5
2022 RAIL: Robust Acoustic Indoor Localization for Drones
abstract
Navigating in environments where the GPS signal is unavailable, weak, purposefully blocked, or spoofed has become crucial for a wide range of applications. A prime example is autonomous navigation for drones in indoor environments: to fly fully or partially autonomously, drones demand accurate and frequent updates of their locations. This paper proposes a Robust Acoustic Indoor Localization (RAIL) scheme for drones designed explicitly for GPS-denied environments. Instead of depending on GPS, RAIL leverages ultrasonic acoustic signals to achieve precise localization using a novel hybrid Frequency Hopping Code Division Multiple Access (FH-CDMA) technique. Contrary to previous approaches, RAIL is able to both overcome the multipath fading effect and provide precise signal separation in the receiver. Comprehensive simulations and experiments using a prototype implementation demonstrate that RAIL provides high-accuracy three-dimensional localization with an average error of less than 1.5 cm.
Alireza Famili, Angelos Stavrou, Haining Wang 0001, Jung-Min Park 0001
VTC Spring4
2022 Detecting Out-of-Distribution Data in Wireless Communications Applications of Deep Learning
abstract
Deep learning-based classification algorithms offer no performance guarantees when deployed on testing data not generated by the same process as the training data. Such out-of-distribution (OOD) data often cause classification errors that are hard to detect since they do not generate explicit errors in the model. In real-world applications, there is no way to ensure that the testing data and the training data are drawn from the same or sufficiently similar distributions. This problem is especially challenging in wireless communications applications. Because the radio propagation channel is highly dynamic, it is very difficult to ensure that a deep learning model is not tested on OOD data. In this paper, we propose a novel deep learning model called FOOD (Feature representation for detecting OOD data) to detect OOD data in wireless communications applications. FOOD incorporates a new model architecture to detect OOD data accurately and minimizes the instances of normal data being recognized as OOD. We evaluated the performance of FOOD extensively using transmitter classification and modulation recognition tasks, with both experimental datasets and simulation-generated datasets. As far as we know, this is the first systematic study on the impact and detection of OOD data in deep learning-based wireless communications applications.
Jinshan Liu, Taiwo Oyedare, Jung-Min Park 0001
IEEE Trans. Wirel. Commun.3
2021 Can Wi-Fi 7 Support Real-Time Applications? On the Impact of Multi Link Aggregation on Latency
abstract
Multi Link Aggregation (MLA) is a feature likely to be introduced in Wi-Fi 7, the next-generation of Wi-Fi, which will be based on the IEEE 802.11be specifications. MLA will allow Wi-Fi devices that support multiple bands (such as the 2.4 GHz, 5 GHz, and 6 GHz bands) to operate on them simultaneously. The resulting throughput and latency gains are likely to bring Wi-Fi one step closer to supporting emerging real-time applications like augmented and virtual reality. While throughput gains resulting from the use of MLA are mostly linear, the latency gains exhibit interesting characteristics and are the subject of this paper. We use our in-house simulator to study the latency enhancements resulting from MLA and seek to answer whether Wi-Fi 7 devices can meet the challenging latency requirements demanded by most real-time applications. In this pursuit, we observe that allowing Wi-Fi devices to contend on even a single additional link without changing any physical layer parameters can lead to an order of magnitude improvement in the worst-case latency in many scenarios. In addition, we highlight that even in dense conditions, MLA can help Wi-Fi devices meet the challenging latency requirements of most real-time applications.
Gaurang Naik, Dennis Ogbe, Jung-Min Park 0001
ICC3
2021 Coexistence of Wi-Fi 6E and 5G NR-U: Can We Do Better in the 6 GHz Bands?
abstract
Regulators in the US and Europe have stepped up their efforts to open the 6 GHz bands for unlicensed access. The two unlicensed technologies likely to operate and coexist in these bands are Wi-Fi 6E and 5G New Radio Unlicensed (NR-U). The greenfield 6 GHz bands allow us to take a fresh look at the coexistence between Wi-Fi and 3GPP-based unlicensed technologies. In this paper, using tools from stochastic geometry, we study the impact of Multi User Orthogonal Frequency Division Multiple Access, i.e., MU OFDMA-a feature introduced in 802.11ax-on this coexistence issue. Our results reveal that by disabling the use of the legacy contention mechanism (and allowing only MU OFDMA) for uplink access in Wi-Fi 6E, the performance of both NR-U networks and uplink Wi-Fi 6E can be improved. This is indeed feasible in the 6 GHz bands, where there are no operational Wi-Fi or NR-U users. In so doing, we also highlight the importance of accurate channel sensing at the entity that schedules uplink transmissions in Wi-Fi 6E and NR-U. If the channel is incorrectly detected as idle, factors that improve the uplink performance of one technology contribute negatively to the performance of the other technology.
Gaurang Naik, Jung-Min Park 0001
INFOCOM2
2021 Cumulative Message Authentication Codes for Resource-Constrained IoT Networks
abstract
In resource-constrained Internet-of-Things networks, the use of conventional message authentication codes (MACs) to provide message authentication and integrity is not possible due to the large size of the MAC output. A straightforward yet naive solution to this problem is to employ a truncated MAC which undesirably sacrifices cryptographic strength in exchange for reduced communication overhead. In this article, we address this problem by proposing a novel approach for message authentication called cumulative MAC (CuMAC), which consists of two distinctive procedures: 1) aggregation and 2) accumulation. In aggregation, a sender generates compact authentication tags from segments of multiple MACs by using a systematic encoding procedure. In accumulation, a receiver accumulates the cryptographic strength of the underlying MAC by collecting and verifying the authentication tags. Embodied with these two procedures, CuMAC enables the receiver to achieve an advantageous tradeoff between the cryptographic strength and the latency in the processing of the authentication tags. Furthermore, for some latency-sensitive messages where this tradeoff may be unacceptable, we propose a variant of CuMAC that we refer to as CuMAC with speculation (CuMAC/S). In addition to the aggregation and accumulation procedures, CuMAC/S enables the sender and receiver to employ a speculation procedure for predicting future message values and precomputing the corresponding MAC segments. For the messages which can be reliably speculated, CuMAC/S significantly reduces the MAC verification latency without compromising the cryptographic strength. We have carried out a comprehensive evaluation of CuMAC and CuMAC/S through simulation and a prototype implementation on a real car.
He Li 0007, Vireshwar Kumar, Jung-Min Park 0001, Yaling Yang
IEEE Internet Things J.3
2021 "Seeing is Not Always Believing": Detecting Perception Error Attacks Against Autonomous Vehicles
abstract
Due to the great achievements in artificial intelligence, it is predicted that autonomous vehicles with little or even no human involvement will come to market in the near future. Autonomous vehicles are equipped with multiple types of sensors. An autonomous vehicle relies on its sensors to perceive its environment, and this sensory information plays a key role in the vehicle's driving decisions. Hence, ensuring the trustworthiness of the sensor data is crucial for drivers’ safety. In this article, we discuss the impact ofperception error attacks (PEAs)on autonomous vehicles, and propose a countermeasure called LIFE (LIDAR andImage dataFusion for detecting perceptionErrors). LIFE detects PEAs by analyzing the consistency between camera image data and LIDAR data using novel machine learning and computer vision algorithms. The performance of LIFE has been evaluated extensively using the KITTI dataset.
Jinshan Liu, Jung-Min Park 0001
IEEE Trans. Dependable Secur. Comput.2
2020 ROLATIN: Robust Localization and Tracking for Indoor Navigation of Drones
abstract
In many drone applications, drones need the ability to fly fully or partially autonomously to carry out their mission. To enable such fully/partially autonomous flights, the ground control station that is supporting the drone's operation needs to constantly localize and track the drone, and send this information to the drone's navigation controller to enable autonomous/semiautonomous navigation. In outdoor environments, localization and tracking can be readily carried out using GPS and the drone's Inertial Measurement Units (IMUs). However, in indoor areas or GPS-denied environments, such an approach is not feasible. In this paper, we propose a localization and tracking scheme for drones called ROLATIN (Robust Localization and Tracking for Indoor Navigation of drones) that was specifically devised for GPS-denied environments. Instead of GPS signals, ROLATIN relies on speakergenerated ultrasonic acoustic signals to estimate the target drone's location and track its movement. Compared to vision and RF signal-based methods, our scheme offers a number of advantages in terms of performance and cost.
Alireza Famili, Jung-Min Park 0001
WCNC2
2020 C2 RC: Channel Congestion-based Re-transmission Control for 3GPP-based V2X Technologies
abstract
The 3rd Generation Partnership Project (3GPP) is actively designing New Radio Vehicle-to-Everything (NR V2X)-a 5G NR-based technology for V2X communications. NR V2X, along with its predecessor Cellular V2X (C-V2X), is set to enable low-latency and high-reliability communications in high-speed and dense vehicular environments. A key reliability-enhancing mechanism that is available in C-V2X and is likely to be re-used in NR V2X is packet re-transmissions. In this paper, using a systematic and extensive simulation study, we investigate the impact of this feature on the system performance of C-V2X. We show that statically configuring vehicles to always disable or enable packet re-transmissions either fails to extract the full potential of this feature or leads to performance degradation due to increased channel congestion. Motivated by this, we propose and evaluate Channel Congestion-based Re-transmission Control (C2RC), which, based on the observed channel congestion, allows vehicles to autonomously decide whether or not to use packet re-transmissions without any role of the cellular infrastructure. Using our proposed mechanism, C-V2X-capable vehicles can boost their performance in lightly-loaded environments, while not compromising on performance in denser conditions.
Gaurang Naik, Jung-Min Park 0001, Jonathan D. Ashdown
WCNC2
2020 Dynamic Exclusion Zones for Protecting Primary Users in Database-Driven Spectrum Sharing
abstract
In spectrum sharing, a spatial separation region is defined around a primary user (PU) where co-channel and/or adjacent channel secondary users (SUs) are not allowed to operate. This region is often called anExclusion Zone(EZ), and it protects the PU from harmful interference caused by SUs. Unfortunately, existing methods for defining an EZ prescribe a static and an overly conservative boundary, which often leads to poor spectrum utilization efficiency. In this paper, we propose a novel framework—namely,Multi-tiered dynamic Incumbent Protection Zones(MIPZ)—for prescribing interference protection for PUs. MIPZ can be used to dynamically adjust the PU’s protection boundary based on the changing radio interference environment. MIPZ can also serve as an analytical tool for quantitatively analyzing a given protection region to gain insights on and determine the trade-off between interference protection and spectrum utilization efficiency. Using results from extensive simulations and a real-world case study, we demonstrate the effectiveness of MIPZ in protecting PUs from harmful interference and in improving the overall spectrum utilization efficiency.
Sudeep Bhattarai, Jung-Min Park 0001, William H. Lehr
IEEE/ACM Trans. Netw.2
2020 Spectrum Sharing Among Rapidly Deployable Small Cells: A Hybrid Multi-Agent Approach
abstract
On-demand deployment of small cells plays a key role in augmenting macro-cell coverage for outdoor hotspots, where user devices are brought together and intensively upload self-generated data. In this paper, we study spectrum sharing among rapidly deployable small cells in the uplink, even without a priori global knowledge. We propose a hybrid multi-agent approach, which allows a leading macro-cell base station (MBS) and multiple following small base stations (SBSs) to take part in a user-centric, online joint optimization of small cell deployment and uplink resource allocation. Specifically, we propose a centralized mechanism for the MBS to solve the first subproblem of small cell deployment stage by stage, based on an adversarial bandit model. Furthermore, we propose a distributed mechanism for the group of SBSs to collectively solve the second subproblem of uplink resource allocation stage by stage, based on a stochastic game model. We prove that our approach is guaranteed to produce a joint strategy, which is built upon a mixed strategy with bounded regret on the first tier and an equilibrium solution on the second tier. Our approach is validated by simulations on the aspects of convergence behavior, strategy correctness, power consumption, and spectral efficiency.
Bo Gao 0006, Lingyun Lu, Ke Xiong 0001, Jung-Min Park 0001, Yaling Yang, Yuwei Wang 0003
IEEE Trans. Wirel. Commun.4
2019 Uplink Resource Allocation in IEEE 802.11ax
abstract
One of the notable features of the upcoming Wireless Fidelity (Wi-Fi) standard-namely, IEEE 802.11ax-is the use of Multi-User Orthogonal Frequency Division Multiple Access (MU-OFDMA). MU-OFDMA facilitates multiple users to transmit simultaneously in smaller sub-channels (a.k.a. resource units (RUs)), thereby improving the 802.11ax MAC efficiency. The 802.11ax MAC enables MU-OFDMA transmissions in the uplink (UL) by using two types of RUs: i) Random Access (RA) RUs, and ii) Scheduled Access (SA) RUs. In this paper, we investigate the impact of different distributions of RA RU and SA RU on the MAC layer performance. We leverage our analysis in devising a practical UL RU allocation scheme that maximizes the overall 802.11ax network throughput. We implement the 802.11ax MAC in network simulator-3 (NS-3) and perform extensive simulations to validate the efficacy of our proposed scheme.
Sudeep Bhattarai, Gaurang Naik, Jung-Min Park 0001
ICC3
2019 PeDSS: Privacy Enhanced and Database-Driven Dynamic spectrum Sharing
abstract
Database driven dynamic spectrum sharing is one of the most promising dynamic spectrum access (DSA) solution to address the spectrum scarcity issue. In such a database-driven DSA system, the centralized spectrum management infrastructure, called spectrum access system (SAS), collects sensitive operational data of both incumbent users (IUs) and secondary users (SUs), which makes privacy protection critical in this paradigm. However, the few existing solutions rely on online trusted third party, which requires extra infrastructure and brings the risk of single point failure. To address the shortcomings of existing solutions, we propose a privacy enhanced and database-driven dynamic spectrum sharing (PeDSS) framework in this paper, which preserves the privacy for both IUs and SUs in database-driven DSA systems without the need for online trusted third party. Privacy for both IUs and SUs are formally defined and analyzed, and experiment results show that SAS under PeDSS is able to handle a single spectrum request in 0.51 ms on average, which is three orders of magnitude faster than prior arts.
He Li 0007, Yaling Yang, Yanzhi Dou, Jung-Min Park 0001, Kui Ren 0001
INFOCOM4
2018 Direct Anonymous Attestation with Efficient Verifier-Local Revocation for Subscription System
abstract
For a computing platform that is compliant with the Trusted Platform Module (TPM) standard, direct anonymous attestation (DAA) is an appropriate cryptographic protocol for realizing an anonymous subscription system. This approach takes advantage of a cryptographic key that is securely embedded in the platform's hardware, and enables privacy-preserving authentication of the platform. In all of the existing DAA schemes, the platform suffers from significant computational and communication costs that increase proportionally to the size of the revocation list. This drawback renders the existing schemes to be impractical when the size of the revocation list grows beyond a relatively modest size. In this paper, we propose a novel scheme called Lightweight Anonymous Subscription with Efficient Revocation (LASER) that addresses this very problem. In LASER, the computational and communication costs of the platform's signature are multiple orders of magnitude lower than the prior art. LASER achieves this significant performance improvement by shifting most of the computational and communication costs from the DAA's online procedure (i.e., signature generation) to its offline procedure (i.e., acquisition of keys/credentials). We have conducted a thorough analysis of LASER's performance related features. We have implemented LASER on a laptop with an on-board TPM. To the best of our knowledge, this is the first implementation of a DAA scheme on an actual TPM cryptoprocessor that is compliant with the most recent TPM specification, viz., TPM 2.0.
Vireshwar Kumar, He Li 0007, Noah Luther, Pranav Asokan, Jung-Min Park 0001, Kaigui Bian, Martin B. H. Weiss, Taieb Znati
AsiaCCS5
2018 Performance Analysis of Uplink Multi-User OFDMA in IEEE 802.11ax
abstract
IEEE 802.11ax is the upcoming standard of the IEEE 802.11 wireless local area networks (WLAN) family. Until its most recent standard, i.e. 802.11ac, the primary focus of the 802.11 Working Group has been to increase the overall throughput of the physical (PHY) layer using innovative mechanisms such as multi-user multiple input multiple output (MU- MIMO), higher order modulation and coding schemes etc. However, these PHY layer gains often fail to translate to high throughput at the medium access control (MAC) layer, particularly in dense deployment scenarios. To address this limitation, IEEE 802.11ax introduces new features, most notably the use of Orthogonal Frequency Division Multiple Access (OFDMA), thereby enabling concurrent MU transmissions. In this paper, we first provide an overview of the uplink MU OFDMA in IEEE 802.11ax. Second, we provide an analytical model for characterizing the performance of the 802.11ax MAC layer. We investigate the trade-off between providing high network throughput and supporting new users using a metric-namely,BSR delivery rate. Finally, we validate our analyses using extensive NS-3 simulations, and present the resulting findings.
Gaurang Naik, Sudeep Bhattarai, Jung-Min Park 0001
ICC3
2018 Adaptive Demodulation for Wireless Systems in the Presence of Frequency-Offset Estimation Errors
abstract
Carrier frequency offset (CFO) arises from the intrinsic mismatch between the operating frequencies of the transmitter and the receiver, as well as their relative speeds (i.e., Doppler effect). Despite advances in CFO estimation techniques, estimation errors are still present. Residual CFO creates time-varying phase error. Modern wireless systems, including WLANs, 5G cellular systems, and satellite communications, use high-order modulation schemes, which are characterized by dense constellation maps. Accounting for the phase error is critical for the demodulation performance of such schemes. In this paper, we analyze the post-estimation probability distribution of residual CFO and use it to develop a CFO-aware demodulation approach for a set of modulation schemes (e.g., QAM and APSK). For a given distribution of the residual CFO, symbols with larger amplitudes are less densely distributed on the constellation map. We explore one important application of our adaptive demodulation approach in the context of PHY-layer security, and more specifically modulation obfuscation (MO) mechanisms. In such mechanisms, the transmitter attempts to hide the modulation order of a frame's payload from eavesdroppers, which could otherwise exploit such information to breach user privacy or launch selective attacks. We go further and complement our CFO-aware demodulation scheme by optimizing the design of a low-complexity MO technique with respect to phase errors. Our results show that when combined, our CFO-aware demodulation and optimized MO techniques achieve up to 5 dB gain over conventional demodulation schemes that are not obfuscated and are oblivious to residual CFO.
Hanif Rahbari, Peyman Siyari, Marwan Krunz, Jung-Min Park 0001
INFOCOM4
2017 Co-Existence of NB-IoT and Radar in Shared Spectrum: An Experimental Study
abstract
The 3GPP Release-13 has introduced a narrowband system, namely Narrowband Internet of Things (NB- IoT), to provide low-power, wide-area cellular connectivity for the Internet of Things. NB-IoT uses a design similar to Long Term Evolution (LTE), but it makes essential modifications for reducing the device complexity. NB-IoT is optimized for machine type communications, and it aims to increase coverage, reduce overhead and reduce power consumption while increasing capacity. In this paper, we present our testbed- based experimental study on the operation of NB- IoT systems in the presence of pulsed radar signals. We leverage results from our experiments in providing a comprehensive analysis on the impact of coverage and capacity of a NB-IoT base- station when it shares an uplink channel with S- band pulsed radars. Our results indicate that the NB-IoT cell coverage is affected in the presence of radar interference.
Sudeep Bhattarai, Pradeep Reddy Vaka, Jung-Min Park 0001
GLOBECOM3
2017 Coexistence of DSRC and Wi-Fi: Impact on the performance of vehicular safety applications
abstract
To adequately support high-throughput applications in next-generation WLANs, more spectrum will be needed to accommodate wider channels. To address this issue, spectrum regulators and stakeholders from the wireless industry and the intelligent transportation system communities are exploring possible band sharing approaches in the 5.9 GHz band. Such approaches include techniques that enable the harmonious coexistence of Dedicated Short Range Communications (DSRC) networks and IEEE 802.11ac networks. In this paper, we provide in-depth discussions on how the coexistence of DSRC and 802.11ac impacts the performance of DSRC applications, with a particular focus on vehicular safety applications. We propose an analytical model that provides valuable insights on DSRC network performance and its vulnerability to interference induced by other DSRC nodes as well as 802.11ac nodes. Using the analytical results derived from the model and extensive simulation results, we also propose a methodology for adjusting 802.11ac parameters that enables a DSRC network to meet the performance requirements of safety applications. Using simulations, we also analyze the throughput of the coexisting 802.11ac network.
Jinshan Liu, Gaurang Naik, Jung-Min Park 0001
ICC3
2017 Coexistence of Dedicated Short Range Communications (DSRC) and Wi-Fi: Implications to Wi-Fi performance
abstract
The 5.9 GHz band is being actively explored for possible spectrum sharing opportunities between Dedicated Short Range Communications (DSRC) and IEEE 802.11ac networks in order to address the increasing demand for bandwidth-intensive Wi-Fi applications. In this paper, we study the implications of this spectrum sharing to the performance of Wi-Fi systems. Through experiments performed on our testbed, we first investigate band sharing options available for Wi-Fi devices. Using experimental results, we show the need for using conservative Wi-Fi transmission parameters to enable harmonious coexistence between DSRC and Wi-Fi. Moreover, we show that under the current 802.11ac standard, certain channelization options, particularly the high bandwidth ones, cannot be used by Wi-Fi devices without causing interference to the DSRC nodes. Under these constraints, we propose a Real-time Channelization Algorithm (RCA) for Wi-Fi Access Points (APs) operating in the shared spectrum. Evaluation of the proposed algorithm using a prototype implementation on commodity hardware as well as via simulations show that informed channelization decisions can significantly increase Wi-Fi throughput compared to static channelization schemes.
Gaurang Naik, Jinshan Liu, Jung-Min Park 0001
INFOCOM3
2017 Software-Defined LTE Evolution Testbed Enabling Rapid Prototyping and Controlled Experimentation
abstract
The long-term evolution (LTE) has spread around the globe for deploying 4G cellular networks for commercial use. These days, it is gaining interest for new applications where mobile broadband services can be of benefit to society. Whereas the basic concepts of LTE are well understood, its long-term evolution has just started. New areas of Ramp;amp;D look into operation in unlicensed and shared bands, where new versions of LTE need to coexist with other communication systems and radars. Virginia Tech has developed an LTE testbed with unique features to spur LTE research and education. This pa-per introduces Virginia Tech's LTE testbed, its main features and components, access and configuration mechanisms, and some of the research thrusts that it enables. It is unique in several aspects, including the extensive use of software-defined radio technology, the combination of industry-grade hardware and software-based systems, and the remote access feature for user- defined configurations of experiments and radio frequency paths.
Vuk Marojevic, Deven Chheda, Raghunandan M. Rao, Randall Nealy, Jung-Min Park 0001, Jeffrey H. Reed
WCNC5
2017 Transmitter authentication using hierarchical modulation in dynamic spectrum sharing
Vireshwar Kumar, Jung-Min Park 0001, Kaigui Bian
J. Netw. Comput. Appl.2
2017 Provably Secure Anonymous-yet-Accountable Crowdsensing with Scalable Sublinear Revocation
abstract
Abstract Group signature schemes enable anonymous-yet-accountable communications. Such a capability is extremely useful for applications, such as smartphone-based crowdsensing and citizen science. However, the performance of modern group signature schemes is still inadequate to manage large dynamic groups. In this paper, we design the first provably secure verifier-local revocation (VLR) - based group signature scheme that supports sublinear revocation, namedSublinear Revocation with Backward unlinkability and Exculpability(SRBE). To achieve this performance gain, SRBE introducestime bound pseudonymsfor the signer. By introducing low-cost short-lived pseudonyms with sublinear revocation checking, SRBE drastically improves the efficiency of the group-signature primitive. The backward-unlinkable anonymity of SRBE guarantees that even after the revocation of a signer, her previously generated signatures remain unlinkable across epochs. This behavior favors the dynamic nature of real-world crowdsensing settings. We prove its security and discuss parameters that influence its scalability. Using SRBE, we also implement a prototype named GroupSensefor anonymous-yet-accountable crowdsensing, where our experimental findings confirm GroupSense’s scalability. We point out the open problems remaining in this space.
Sazzadur Rahaman, Long Cheng 0005, Danfeng Yao, He Li 0007, Jung-Min Park 0001
Proc. Priv. Enhancing Technol.5
2017 Understanding Smartphone Sensor and App Data for Enhancing the Security of Secret Questions
abstract
Many web applications provide secondary authentication methods, i.e., secret questions (or password recovery questions), to reset the account password when a user's login fails. However, the answers to many such secret questions can be easily guessed by an acquaintance or exposed to a stranger that has access to public online tools (e.g., online social networks); moreover, a user may forget her/his answers long after creating the secret questions. Today's prevalence of smartphones has granted us new opportunities to observe and understand how the personal data collected by smartphone sensors and apps can help create personalized secret questions without violating the users’ privacy concerns. In this paper, we present aSecret-Question based Authenticationsystem, called “Secret-QA”, that creates a set of secret questions on basic of people's smartphone usage. We develop a prototype on Android smartphones, and evaluate the security of the secret questions by asking the acquaintance/stranger who participates in our user study to guess the answers with and without the help of online tools; meanwhile, we observe the questions’ reliability by asking participants to answer their own questions. Our experimental results reveal that the secret questions related to motion sensors, calendar, app installment, and part of legacy app usage history (e.g., phone calls) have the best memorability for users as well as the highest robustness to attacks.
Kaigui Bian, Tong Zhao 0001, Xintong Song, Jung-Min Park 0001, Xiaoming Li 0001, Fan Ye 0003, Wei Yan 0007
IEEE Trans. Mob. Comput.5
2016 Location Privacy of Non-Stationary Incumbent Systems in Spectrum Sharing
abstract
Although using geolocation databases for spectrum sharing has many pragmatic advantages, it also raises potentially serious operational security (OPSEC) issues. OPSEC is especially a paramount consideration in the light of recent calls in the U.S. for spectrum sharing between federal government (including military) systems and non-government systems (e.g., cellular service providers). In this paper, we explore the OPSEC, location privacy in particular, of incumbent radars in the 3.5 GHz band. First, we show that adversarial secondary users can easily infer the locations of incumbent radars by making seemingly innocuous queries to the database. Then, we propose several obfuscation techniques that can be implemented by the database for countering the inference attacks. We also investigate the inherent tradeoff between the degree of obfuscation and spectrum utilization efficiency. Finally, we validate our discussions by providing results from extensive simulations.
Pradeep Reddy Vaka, Sudeep Bhattarai, Jung-Min Park 0001
GLOBECOM3
2016 Incentivizing spectrum sensing in database-driven dynamic spectrum sharing
abstract
The legacy concept of exclusion zones (EZs) is inept at enabling efficient utilization of fallow spectrum by secondary users (SUs), since legacy EZs are static and overly-conservative. The notion of a static EZ implies that it has to protect incumbent users (IUs) from the union of likely interference scenarios, leading to a worst-case, conservative solution. In this paper, we propose the concept of dynamic, multi-tier EZs, which takes advantage of participatory spectrum sensing carried out by SUs to support efficient database-driven spectrum sharing while protecting IUs against SU-induced aggregate interference. Specifically, the database directly incentivizes SUs to participate in spectrum sensing, which augments geolocation database by defining smaller EZs with dynamic boundaries and creating additional spectrum access opportunities for SUs. We propose an incentive mechanism based on a two-level game-theoretic model, in which the database conducts dynamic pricing in a first-level Stackelberg game in the presence of SUs who strategically contribute to spectrum sensing in a second-level stochastic game. The existence of an equilibrium solution is proven. According to our findings, the proposed incentive mechanism for the concept of dynamic, multi-tier EZs is effective to improve spectrum utilization efficiency while guaranteeing incumbent protection.
Bo Gao 0006, Sudeep Bhattarai, Jung-Min Park 0001, Yaling Yang, Min Liu 0001, Kexiong Curtis Zeng, Yanzhi Dou
INFOCOM3
2016 PHY-Layer Authentication Using Duobinary Signaling for Spectrum Enforcement
abstract
Spectrum security and enforcement is one of the major challenges that need to be addressed before spectrum sharing technologies can be adopted widely. The problem of rogue transmitters is a major threat to the viability of spectrum sharing. One approach for deterring rogue transmissions is to enable receivers to authenticate or uniquely identify transmitters. Although cryptographic mechanisms at the higher layers have been widely used to authenticate transmitters, the ability to authenticate transmitters at the physical (PHY) layer has a number of key advantages over higher layer approaches. In existing schemes, the authentication signal is added to the message signal in such a way that the authentication signal appears as noise to the message signal and vice versa. Hence, existing schemes are constrained by a fundamental tradeoff between the message signal's signal-to-noise ratio (SNR) and the authentication signal's SNR. In this paper, we extend the precoded duobinary signaling (P-DS) technique to devise a new PHY-layer authentication scheme called P-DS for authentication (P-DSA). P-DSA exploits the redundancy introduced by P-DS to embed the authentication signal into the message signal. P-DSA is not constrained by the aforementioned tradeoff between the message and authentication signals. Our results show that P-DSA improves the detection performance compared with the prior art without sacrificing message throughput or increasing transmission power.
Vireshwar Kumar, Jung-Min Park 0001, Kaigui Bian
IEEE Trans. Inf. Forensics Secur.2
2015 Group Signatures with Probabilistic Revocation: A Computationally-Scalable Approach for Providing Privacy-Preserving Authentication
abstract
Group signatures (GSs) is an elegant approach for providing privacy-preserving authentication. Unfortunately, modern GS schemes have limited practical value for use in large networks due to the high computational complexity of their revocation check procedures. We propose a novel GS scheme called the Group Signatures with Probabilistic Revocation (GSPR), which significantly improves scalability with regard to revocation. GSPR employs the novel notion of probabilistic revocation, which enables the verifier to check the revocation status of the private key of a given signature very efficiently. However, GSPR's revocation check procedure produces probabilistic results, which may include false positive results but no false negative results. GSPR includes a procedure that can be used to iteratively decrease the probability of false positives. GSPR makes an advantageous tradeoff between computational complexity and communication overhead, resulting in a GS scheme that offers a number of practical advantages over the prior art. We provide a proof of security for GSPR in the random oracle model using the decisional linear assumption and the bilinear strong Diffie-Hellman assumption.
Vireshwar Kumar, He Li 0007, Jung-Min Park 0001, Kaigui Bian, Yaling Yang
CCS3
2015 Multi-tier exclusion zones for dynamic spectrum sharing
abstract
Reducing the size of exclusion zones (EZs) in spectrum sharing is vital for efficient utilization of fallow spectrum as well as for the economic viability of spectrum sharing itself. In this paper, we explore two approaches for reducing the size of EZs. We show that multi-tiered EZs can be used to improve spectrum utilization efficiency by implementing the concept of differential spectrum access hierarchy. Also, we provide quantitative results that show the impact of using a point-to-point mode terrain profile in calculating an EZ's contour. Such a terrain profile captures the effects of propagation losses due to area-specific topography, which are not considered by the F-curves, a common method of calculating an EZ's boundary. Our results indicate that the use of such a terrain profile results in a noticeable decrease in the size of an EZ.
Abid Ullah, Sudeep Bhattarai, Jung-Min Park 0001, Jeffrey H. Reed, David Gurney, Behnam Bahrak
ICC3
2014 Blind Transmitter Authentication for Spectrum Security and Enforcement
abstract
Recent advances in spectrum access technologies, such as cognitive radios, have made spectrum sharing a viable option for addressing the spectrum shortage problem. However, these advances have also contributed to the increased possibility of "hacked" or "rogue" radios causing harm to the spectrum sharing ecosystem by causing significant interference to other wireless devices. One approach for countering such threats is to employ a scheme that can be used by a regulatory entity (e.g., FCC) to uniquely identify a transmitter by authenticating its waveform. This enables the regulatory entity to collect solid evidence of rogue transmissions that can be used later during an adjudication process. We coin the term Blind Transmitter Authentication (BTA) to refer to this approach. Unlike in the existing techniques for PHY-layer authentication, in BTA, the entity that is authenticating the waveform is not the intended receiver. Hence, it has to extract and decode the authentication signal "blindly" with little or no knowledge of the transmission parameters. In this paper, we propose a novel BTA scheme called Frequency offset Embedding for Authenticating Transmitters (FEAT). FEAT embeds the authentication information into the transmitted waveform by inserting an intentional frequency offset. Our results indicate that FEAT is a practically viable approach and is very robust to harsh channel conditions. Our evaluation of FEAT is based on theoretical bounds, simulations, and indoor experiments using an actual implementation.
Vireshwar Kumar, Jung-Min Park 0001, Kaigui Bian
CCS2
2014 A credit-token-based spectrum etiquette framework for coexistence of heterogeneous cognitive radio networks
abstract
The coexistence of cognitive radio (CR) networks in the same swath of spectrum has become an increasingly important problem, which is especially challenging when coexisting networks are heterogeneous (i.e., use different air interface standards), such as the case in TV white spaces. In this paper, we propose a credit-token-based spectrum etiquette framework that enables spectrum sharing among distributed heterogeneous CR networks with equal priority. Specifically, we propose a game-auction coexistence framework. Each network acts as either an offerer or a requester, and coexists with other networks via a non-cooperative game and a truthful multi-winner auction. The framework addresses the trade-offs among social welfare and offerer's revenue in the auction and requester's utility in the game. We prove that the framework guarantees system stability. Our simulation results show that the proposed coexistence framework always converges to a near-optimal distributed solution and improves coexistence fairness and spectrum utilization.
Bo Gao 0006, Yaling Yang, Jung-Min Park 0001
INFOCOM3
2014 A group-theoretic framework for rendezvous in heterogeneous cognitive radio networks
abstract
In cognitive radio (CR) networks, a pair of CR nodes have to ``rendezvous'' on a common channel for link establishment. Channel hopping (CH) protocols have been proposed for creating rendezvous over multiple channels to reduce the possibility of rendezvous failures caused by the detection of primary user signals. Rendezvous within a minimal bounded time over multiple channels is a challenging problem in heterogeneous CR networks where two CR nodes may have asynchronous clocks, different sensing capabilities, no common universal channel set, and heterogeneous channel index systems. In this paper, we present a systematic approach using group theory for designing CH protocols that guarantee the maximum number of rendezvous channels and the minimal time-to-rendezvous (TTR) in heterogeneous environments. We derive the minimum upper bound of TTR, and propose two types of rendezvous protocols that are independent of environmental heterogeneity. Analytical and simulation results show that these protocols are resistant to rendezvous failures under various network conditions.
Lin Chen 0003, Kaigui Bian, Lin Chen 0002, Cong Liu 0001, Jung-Min Park 0001, Xiaoming Li 0001
MobiHoc5
2014 Supporting mobile users in database-driven opportunistic spectrum access
abstract
In database-driven opportunistic spectrum access, location information of secondary users plays an important role. In a database query-and-update procedure, a secondary user reports to the geolocation database of its location information, so that the updated knowledgebase facilitates location-aided incumbent protection and network coexistence. However, such database-driven spectrum sharing becomes very challenging when the secondary users are mobile. In this paper, we propose a probabilistic coexistence framework that supports mobile users by incorporating the solutions to solve two core problems: (i) white space allocation (WSA) at the database and (ii) location update control (LUC) at the users. We frame the two problems such that they interact through dynamic control of the users' location uncertainty levels. For WSA, we derive a centralized real-time solution to mitigate mutual interference among secondary users and protect primary users against harmful interference. For LUC, we design a local two-level strategy to enable both movement-driven and interference-driven control of location uncertainty. This strategy makes an appropriate trade-off between the effectiveness of interference mitigation and the cost of database queries. To evaluate our algorithms, we have carried out both theoretical model-driven and real-world trace-driven simulation experiments. Our simulation results show that the proposed framework can determine and adapt the database query intervals of mobile users to achieve near-optimal interference mitigation with minimal location updates.
Bo Gao 0006, Jung-Min Park 0001, Yaling Yang
MobiHoc2
2014 Security and Enforcement in Spectrum Sharing
abstract
When different stakeholders share a common resource, such as the case in spectrum sharing, security and enforcement become critical considerations that affect the welfare of all stakeholders. Recent advances in radio spectrum access technologies, such as cognitive radios, have made spectrum sharing a viable option for significantly improving spectrum utilization efficiency. However, those technologies have also contributed to exacerbating the difficult problems of security and enforcement. In this paper, we review some of the critical security and privacy threats that impact spectrum sharing. We propose a taxonomy for classifying the various threats, and describe representative examples for each threat category. We also discuss threat countermeasures and enforcement techniques, which are discussed in the context of two different approaches: ex ante (preventive) and ex post (punitive) enforcement.
Jung-Min Park 0001, Jeffrey H. Reed, A. A. Louis Beex, T. Charles Clancy, Vireshwar Kumar, Behnam Bahrak
Proc. IEEE1
2014 Uplink Soft Frequency Reuse for Self-Coexistence of Cognitive Radio Networks
abstract
The depletion of usable radio frequency spectrum has stimulated increasing interest in dynamic spectrum access technologies, such as cognitive radio (CR). In a scenario where multiple co-located CR networks operate in the same swath of white-space (or unlicensed) spectrum with little or no direct coordination, co-channel self-coexistence is a challenging problem. In this paper, we focus on the problem of spectrum sharing among coexisting CR networks that employ orthogonal frequency division multiple access (OFDMA) in their uplink and do not rely on inter-network coordination. An uplink soft frequency reuse (USFR) technique is proposed to enable globally power-efficient and locally fair spectrum sharing. We frame the self-coexistence problem as a non-cooperative game. In each network cell, uplink resource allocation (URA) problem is decoupled into two subproblems: subchannel allocation (SCA) and transmit power control (TPC). We provide a unique optimal solution to the TPC subproblem, while presenting a low-complexity heuristic for the SCA subproblem. After integrating the SCA and TPC games as the URA game, we design a heuristic algorithm that achieves the Nash equilibrium in a distributed manner. In both multi-operator and single-operator coexistence scenarios, our simulation results show that USFR significantly improves self-coexistence in spectrum utilization, power consumption, and intra-cell fairness.
Bo Gao 0006, Jung-Min Park 0001, Yaling Yang
IEEE Trans. Mob. Comput.2
2014 Coexistence Decision Making for Spectrum Sharing Among Heterogeneous Wireless Systems
abstract
This paper focuses on the problem of spectrum sharing between secondary networks that access spectrum opportunistically in TV spectrum. Compared to the coexistence problem in the ISM (Industrial, Scientific and Medical) bands, the coexistence situation in TV whitespace (TVWS) is potentially more complex and challenging due to the signal propagation characteristics in TVWS and the disparity of PHY/MAC strategies employed by the systems coexisting in it. In this paper, we propose a novel decision making algorithm for a system of coexistence mechanisms, such as an IEEE 802.19.1-compliant system, that enables coexistence of dissimilar TVWS networks and devices. Our algorithm outperforms existing coexistence decision making algorithms in terms of fairness, and percentage of demand serviced.
Behnam Bahrak, Jung-Min Park 0001
IEEE Trans. Wirel. Commun.2
2013 POCKET: A tool for protecting children's privacy online
France Bélanger, Robert E. Crossler, Janine S. Hiller, Jung-Min Park 0001, Michael S. Hsiao
Decis. Support Syst.4
2013 Maximizing Rendezvous Diversity in Rendezvous Protocols for Decentralized Cognitive Radio Networks
abstract
In decentralized cognitive radio (CR) networks, establishing a link between a pair of communicating nodes requires that the radios "rendezvous” in a common channel—such a channel is called a rendezvous channel—to exchange control information. When unlicensed (secondary) users opportunistically share spectrum with licensed (primary or incumbent) users, a given rendezvous channel may become unavailable due to the appearance of licensed user signals. Ideally, every node pair should be able to rendezvous in every available channel (i.e., maximize the rendezvous diversity) so that the possibility of rendezvous failures is minimized. Channel hopping (CH) protocols have been proposed previously for establishing pairwise rendezvous. Some of them enable pairwise rendezvous over all channels but require global clock synchronization, which may be very difficult to achieve in decentralized networks. Maximizing the pairwise rendezvous diversity in decentralized CR networks is a very challenging problem. In this paper, we present a systematic approach for designing CH protocols that maximize the rendezvous diversity of any node pair in decentralized CR networks. The resulting protocols are resistant to rendezvous failures caused by the appearance of primary user (PU) signals and do not require clock synchronization. The proposed approach, called asynchronous channel hopping (ACH), has two noteworthy features: 1) any pair of CH nodes are able to rendezvous on every channel so that the rendezvous process is robust to disruptions caused by the appearance of PU signals; and 2) an upper bounded time-to-rendezvous (TTR) is guaranteed between the two nodes even if their clocks are asynchronous. We propose two optimal ACH designs that maximize the rendezvous diversity between any pair of nodes and show their rendezvous performance via analytical and simulation results.
Kaigui Bian, Jung-Min Park 0001
IEEE Trans. Mob. Comput.2
2012 Uplink soft frequency reuse for self-coexistence of cognitive radio networks operating in white-space spectrum
abstract
Recent advances in cognitive radio (CR) technology have brought about a number of wireless standards that support opportunistic access to available white-space spectrum. Addressing the self-coexistence of CR networks in such an environment is very challenging, especially when coexisting networks operate in the same swath of spectrum with little or no direct coordination. In this paper, we study the problem of co-channel self-coexistence of uncoordinated CR networks that employ orthogonal frequency division multiple access (OFDMA) in the uplink. We frame the self-coexistence problem as a non-cooperative game, and propose an uplink soft frequency reuse (USFR) technique to enable globally power-efficient and locally fair sharing of white-space spectrum. In each network, uplink resource allocation is decoupled into two subproblems: subchannel allocation (SCA) and transmit power control (TPC). We provide a unique optimal solution to the TPC subproblem, and present a low-complexity heuristic for the SCA subproblem. Furthermore, we frame the TPC and SCA games, and integrate them as a heuristic algorithm that achieves the Nash equilibrium in a fully distributed manner. Our simulation results show that the proposed USFR technique significantly improves self-coexistence in several aspects, including spectrum utilization, power consumption, and intra-cell fairness.
Bo Gao 0006, Jung-Min Park 0001, Yaling Yang
INFOCOM2
2012 Spectrum access policy reasoning for policy-based cognitive radios
Behnam Bahrak, Amol Deshpande, Jung-Min Park 0001
Comput. Networks3
2012 Robustness against Byzantine Failures in Distributed Spectrum Sensing
Ruiliang Chen, Jung-Min Park 0001, Kaigui Bian
Comput. Commun.2
2012 Spectrum Access Technologies: The Past, the Present, and the Future
abstract
This paper provides an overview of how our access to the electromagnetic spectrum has evolved and will continue to expand over time. We first focus on the historical origins of technological and regulatory choices, and provide some insight into how these choices have impacted the efficiency with which we currently utilize the spectrum, and how we can better use it in the future. In turn, we summarize the relevant technologies being discussed in today's standardization and research and development efforts. Finally, we provide a vision for the evolution of spectrum access technologies that, intertwined with progressive regulatory and economic policies, will enable flexible and secure sharing of spectrum to deliver seamless mobility with ubiquitous service for users worldwide.
Jeffrey H. Reed, Jennifer T. Bernhard, Jung-Min Park 0001
Proc. IEEE3
2011 Channel Aggregation in Cognitive Radio Networks with Practical Considerations
abstract
In cognitive radio (CR) networks, spectrum resource that can be shared by secondary users (SUs) is always restricted by primary users (PUs). Although channel aggregation (CA) enables each SU to access multiple channels at a time, whether it is beneficial is subject to the PU activity and radio capability. In this paper, we study the feasibility and efficiency of CA in consideration of various such practical constraints and costs. First, we propose a novel channel usage model to analyze the impact of both PU and SU behaviors on the availability of white spaces. This model is very general and can capture a wide range of user behaviors. Next, we model the costs in time for performing CA. User demands in both frequency and time domains are considered to evaluate the costs for making negotiation and renewing transmission. Further, an optimal CA strategy is defined to minimize the cumulative delay for transmitting a certain amount of data. Numerical and simulation results based on real data of PU activity show that user demands on both bandwidth and duration should be carefully chosen to achieve the optimal delay performance in practice.
Bo Gao 0006, Yaling Yang, Jung-Min Park 0001
ICC3
2011 Asynchronous channel hopping for establishing rendezvous in cognitive radio networks
abstract
In Cognitive Radio (CR) networks, establishing a link between a pair of communicating nodes requires that their radios are able to “rendezvous” on a common channel (a.k.a. a rendezvous channel). When unlicensed (secondary) users opportunistically share spectrum with licensed (primary or incumbent) users, a given rendezvous channel may become unavailable due to the appearance of licensed user signals, which makes rendezvous impossible. Ideally, any node pair should be able to rendezvous over every available channel to minimize the possibility of such rendezvous failures. Channel hopping (CH) protocols have been proposed previously for establishing pairwise rendezvous. Some of them enable pairwise rendezvous over all channels but require global clock synchronization, which is very difficult to achieve in decentralized networks. In this paper, we present a systematic approach, called asynchronous channel hopping (ACH), for designing CH-based rendezvous protocols for decentralized CR networks. The resulting protocols are resistant to rendezvous failures caused by the appearance of primary user signals and do not require clock synchronization. We propose an optimal ACH design that maximizes the rendezvous probability between any pair of nodes, and show its rendezvous performance via simulation results.
Kaigui Bian, Jung-Min Park 0001
INFOCOM2
2011 Control Channel Establishment in Cognitive Radio Networks using Channel Hopping
abstract
In decentralized cognitive radio (CR) networks, enabling the radios to establish a control channel (i.e., "rendezvous" to establish a link) is a challenging problem. The use of a dedicated common control channel simplifies the rendezvous process but may not be feasible in many opportunistic spectrum sharing scenarios due to the dynamically changing availability of all the channels, including the control channel. To address this problem, researchers have proposed the use of channel hopping protocols for enabling rendezvous in CR networks. Most, if not all, of the existing channel hopping schemes only provide ad hoc approaches for generating channel hopping sequences and evaluating their properties. In this paper, we present a systematic approach, based on quorum systems, for designing and analyzing channel hopping protocols for the purpose of control channel establishment. The proposed approach, called Quorum-based Channel Hopping (QCH) system, can be used for implementing rendezvous protocols in CR networks that are robust against link breakage caused by the appearance of incumbent user signals. We describe two synchronous QCH systems under the assumption of global clock synchronization, and two asynchronous channel hopping systems that do not require global clock synchronization. Our analytical and simulation results show that the proposed channel hopping schemes outperform existing schemes under various network conditions.
Kaigui Bian, Jung-Min Park 0001, Ruiliang Chen
IEEE J. Sel. Areas Commun.2
2009 A Coexistence-Aware Spectrum Sharing Protocol for 802.22 WRANs
abstract
IEEE 802.22 is the first wireless standard based on cognitive radio (CR) technology. It defines the air interface for a wireless regional area network (WRAN) that uses fallow segments of the TV broadcast bands. CR technology enables unlicensed users in WRANs to utilize licensed (incumbent) spectrum bands on a non-interference basis to incumbent users. The coexistence between incumbent users and unlicensed users is referred to as incumbent coexistence. On the other hand, the coexistence between unlicensed users in different WRAN cells is referred to as self-coexistence. 802.22 defines several inter-base station (BS) dynamic resource sharing mechanisms to enable overlapping cells to share spectrum. However, those mechanisms do not adequately address some of the key issues concerning incumbent and self coexistence. In this paper, we propose an inter-BS coexistence-aware spectrum sharing (CASS) protocol for overlapping 802.22 cells that takes into account coexistence requirements. We show that the proposed protocol outperforms 802.22's self-coexistence solutions using simulation results. To the best of our knowledge, the work presented here is the first systematic study of the self-coexistence problem in the context of 802.22 WRANs.
Kaigui Bian, Jung-Min Park 0001
ICCCN2
2009 A quorum-based framework for establishing control channels in dynamic spectrum access networks
abstract
Establishing a control channel for medium access control is a challenging problem in multi-channel and dynamic spectrum access (DSA) networks. In the design of multi-channel MAC protocols, the use of channel (or frequency) hopping techniques (a.k.a. parallel rendezvous) have been proposed to avoid the bottleneck of a single control channel. In DSA networks, the dynamic and opportunistic use of the available spectrum requires that the radios are able to "rendezvous" -- i.e., find each other to establish a link. The use of a dedicated global control channel simplifies the rendezvous process but may not be feasible in many opportunistic spectrum sharing scenarios due to the dynamically changing availability of all the channels, including the control channel. To address this problem, researchers have proposed the use of channel hopping protocols for enabling rendezvous in DSA networks.
Kaigui Bian, Jung-Min Park 0001, Ruiliang Chen
MobiCom2
2009 Cognitive Radio and Networking Research at Virginia Tech
abstract
More than a dozen Wireless @ Virginia Tech faculty are working to address the broad research agenda of cognitive radio and cognitive networks. Our core research team spans the protocol stack from radio and reconfigurable hardware to communications theory to the networking layer. Our work includes new analysis methods and the development of new software architectures and applications, in addition to work on the core concepts and architectures underlying cognitive radios and cognitive networks. This paper describes these contributions and points towards critical future work that remains to fulfill the promise of cognitive radio. We briefly describe the history of work on cognitive radios and networks at Virginia Tech and then discuss our contributions to the core cognitive processing underlying these systems, focusing on our cognitive engine. We also describe developments that support the cognitive engine and advances in radio technology that provide the flexibility desired in a cognitive radio node. We consider securing and verifying cognitive systems and examine the challenges of expanding the cognitive paradigm up the protocol stack to optimize end-to-end network performance. Lastly, we consider the analysis of cognitive systems using game theory and the application of cognitive techniques to problems in dynamic spectrum sharing and control of multiple-input multiple-output radios.
Allen B. MacKenzie, Jeffrey H. Reed, Peter M. Athanas, Charles W. Bostian, R. Michael Buehrer, Luiz A. DaSilva, Steven W. Ellingson, Y. Thomas Hou 0001, Michael S. Hsiao, Jung-Min Park 0001, Cameron D. Patterson, Sanjay Raman, Claudio R. C. M. da Silva
Proc. IEEE10
2008 Robust Distributed Spectrum Sensing in Cognitive Radio Networks
abstract
Distributed spectrum sensing (DSS) enables a Cognitive Radio (CR) network to reliably detect licensed users and avoid causing interference to licensed communications. The data fusion technique is a key component of DSS. We discuss the Byzantine failure problem in the context of data fusion, which may be caused by either malfunctioning sensing terminals or Spectrum Sensing Data Falsification (SSDF) attacks. In either case, incorrect spectrum sensing data will be reported to a data collector which can lead to the distortion of data fusion outputs. We investigate various data fusion techniques, focusing on their robustness against Byzantine failures. In contrast to existing data fusion techniques that use a fixed number of samples, we propose a new technique that uses a variable number of samples. The proposed technique, which we call Weighted Sequential Probability Ratio Test (WSPRT), introduces a reputation-based mechanism to the Sequential Probability Ratio Test (SPRT). We evaluate WSPRT by comparing it with a variety of data fusion techniques under various network operating conditions. Our simulation results indicate that WSPRT is the most robust against the Byzantine failure problem among the data fusion techniques that were considered.
Ruiliang Chen, Jung-Min Park 0001, Kaigui Bian
INFOCOM2
2008 Defense against Primary User Emulation Attacks in Cognitive Radio Networks
abstract
Cognitive Radio (CR) is a promising technology that can alleviate the spectrum shortage problem by enabling unlicensed users equipped with CRs to coexist with incumbent users in licensed spectrum bands while causing no interference to incumbent communications. Spectrum sensing is one of the essential mechanisms of CRs and its operational aspects are being investigated actively. However, the security aspects of spectrum sensing have garnered little attention. In this paper, we identify a threat to spectrum sensing, which we call theprimary user emulation (PUE) attack. In this attack, an adversary's CR transmits signals whose characteristics emulate those of incumbent signals. The highly flexible, software-based air interface of CRs makes such an attack possible. Our investigation shows that a PUE attack can severely interfere with the spectrum sensing process and significantly reduce the channel resources available to legitimate unlicensed users. To counter this threat, we propose a transmitter verification scheme, calledLocDef (localization-based defense), which verifies whether a given signal is that of an incumbent transmitter by estimating its location and observing its signal characteristics. To estimate the location of the signal transmitter, LocDef employs anon-interactive localizationscheme. Our security analysis and simulation results suggest that LocDef is effective in identifying PUE attacks under certain conditions.
Ruiliang Chen, Jung-Min Park 0001, Jeffrey H. Reed
IEEE J. Sel. Areas Commun.2
2007 Link-Layer Traceback in Ethernet Networks
abstract
The design of the most commonly-used Internet and local area network protocols provide no way of verifying the sender of a packet is who it claims to be. A malicious host can easily launch an attack while pretending to be another host to avoid being discovered. To determine the identity of an attacker, an administrator can use traceback, a technique that determines the path of attack packets from the victim to the coordinator. Most traceback research has focused on IP and stepping-stone techniques and little has been conducted on the problem of data-link layer trace-back (DLT), the process of tracing frames from the network edge to the attack source. We propose a scheme called tagged-frame traceback (TRACK) that provides a secure, reliable DLT technique for Ethernet networks. TRACK defines processes for Ethernet switches and a centralized storage and lookup host. Simulation results indicate that TRACK provides accurate DLT operation while causing minimal impact on network and application performance.
Michael Snow, Jung-Min Park 0001
LANMAN2
2007 An overview of anomaly detection techniques: Existing solutions and latest technological trends
Animesh Patcha, Jung-Min Park 0001
Comput. Networks2
2007 Network anomaly detection with incomplete audit data
Animesh Patcha, Jung-Min Park 0001
Comput. Networks2
2007 Key management for long-lived sensor networks in hostile environments
Michael Chorzempa, Jung-Min Park 0001, Mohamed Eltoweissy
Comput. Commun.2
2007 A Divide-and-Conquer Strategy for Thwarting Distributed Denial-of-Service Attacks
abstract
Attack mitigation schemes actively throttle attack traffic generated in Distributed Denial-of-Service (DDoS) attacks. This paper presents Attack Diagnosis (AD), a novel attack mitigation scheme that adopts a divide-and-conquer strategy. AD combines the concepts of Pushback and packet marking, and its architecture is in line with the ideal DDoS attack countermeasure paradigm—attack detection is performed near the victim host and packet filtering is executed close to the attack sources. AD is a reactive defense mechanism that is activated by a victim host after an attack is detected. By instructing its upstream routers to mark packets deterministically, the victim can trace back one attack source and command an AD-enabled router close to the source to filter the attack packets. This process isolates one attacker and throttles it, which is repeated until the attack is mitigated. We also propose an extension to AD called Parallel Attack Diagnosis (PAD) that is capable of throttling traffic coming from a large number of attackers simultaneously. AD and PAD are analyzed and evaluated using the Skitter Internet map, Lumeta's Internet map, and the 6-degree complete tree topology model. Both schemes are shown to be robust against IP spoofing and to incur low false positive ratios.
Ruiliang Chen, Jung-Min Park 0001, Randy C. Marchany
IEEE Trans. Parallel Distributed Syst.2
2006 Stasis Trap: Cross-Layer Stealthy Attacks in Wireless Ad Hoc Networks
abstract
Denial-of-Service (DoS) attacks pose a major threat to the availability of wireless ad hoc networks. Fault tolerant operation of wireless ad hoc networks will depend on the placement of DoS countermeasures in sufficiently robust form. In this paper, we describe a novel type of DoS attack called the Stasis Trap attack, and propose a technique for detecting such an attack. Stasis Trap attack has two distinguishing characteristics-it has a cross-layer design, and is stealthy. The Stasis Trap attack has a cross-layer design in that it is launched from the MAC layer but its aim is to degrade the end-to-end throughput of flows at the transport layer by exploiting TCP's congestion-control mechanism. Specifically, an adversary launches a Stasis Trap attack against neighboring nodes by periodically preempting the wireless channel in order to cause large variations in the round trip time (RTT) of TCP flows. Channel preemptions are carried out by manipulating the back-off mechanism of the Distributed Coordinating Function of the 802.11 MAC protocol. The periodic preemptions induce large RTT variations in the TCP flows that are within the transmission range of the adversary. This in turn causes a significant drop in the throughput of those flows, thereby creating a "stasis trap" around the adversary that entangles TCP flows. The aforementioned attack severely degrades end-to-end throughput but has very little effect on MAC-layer throughput, and hence it is very hard to detect at the MAC layer, which is its point of attack. In this sense, this attack is stealthy. To detect the Stasis Trap attack, we propose a minimax robust decentralized detection framework with robust hypothesis testing.
Kaigui Bian, Jung-Min Park 0001, Ruiliang Chen
GLOBECOM2
2006 RIM: Router Interface Marking for IP Traceback
abstract
Distributed Denial-of-Service (DDoS) attacks have become a major threat to the Internet. As a countermeasure against DDoS attacks, IP traceback schemes identify the network paths the attack traffic traverses. This paper presents a novel IP traceback scheme called Router Interface Marking (RIM). In RIM, a router probabilistically marks packets with a router interface's identifier. After collecting the packets marked by each router in an attack path, a victim machine can use the information in the marked packets to trace back to the attack source. Different from most existing IP traceback schemes, RIM marks packets with the information of router interfaces rather than that of router IP addresses. This difference endows RIM with several advantageous features, including fast traceback speed, last-hop traceback capability, small computation overhead, low occurrence of false positives, and enhanced security.
Ruiliang Chen, Jung-Min Park 0001, Randy C. Marchany
GLOBECOM2
2006 Defense against Routing Disruption Attacks in Mobile Ad Hoc Networks
abstract
We propose a secure routing architecture for mobile ad hoc networks (MANETs) called throughput-feedback (TUF) routing, which is resilient against a wide range of routing disruption denial-of-service (DoS) attacks. Unlike many existing solutions, TUF does not focus on a particular type of attack, but instead takes an approach that is fundamentally more general. TUF is a cross-layer technique that detects attacks at the transport layer but responds to attacks at the network layer. Because most routing disruption attacks cause a significant drop in end-to-end goodput, monitoring the goodput of a route at the transport layer can detect abnormalities in the network (e.g., node or link failures, DoS attacks, etc.). Once an abnormal event is detected, a route rebuilding process is initiated at the network layer to find a new route. Using analysis and simulation results, we show that the TUF architecture is effective in thwarting a wide range of attacks, including protocol-compliant (also known as "JellyFish") attacks.
Ruiliang Chen, Michael Snow, Jung-Min Park 0001, Mohamed Tamer Refaei, Mohamed Eltoweissy
GLOBECOM3
2006 CARE: Enhancing Denial-of-Service Resilience in Mobile Ad Hoc Networks
abstract
This paper proposes an attack-resilient routing architecture, called cross-layer active re-routing (CARE), for mobile ad hoc networks (MANETs). Different from existing solutions, CARE does not focus on a particular type of attack, but instead takes a fundamentally general approach-it achieves resilience against a wide range of routing disruption Denial- of-Service (DoS) attacks by treating them and "dysfunctional" network events in the same way. Here, dysfunctional network events denote link and routing failures caused by link contention or node mobility. CARE is a cross-layer scheme that detects attacks at the transport layer but responds to them at the network layer. Because dysfunctional network events and routing disruption attacks have a pronounced effect on the size of the TCP congestion window, monitoring the window size is an effective method of detecting such events. Using this method, CARE is able to detect attacks. Once an attack is detected, CARE initiates a re-routing process to find a new route. For this purpose, a re-routing algorithm is proposed that circumvents the nodes that are likely to be misbehaving. Analysis and simulation results show that the CARE architecture is effective in thwarting a number of insider and protocol-compliant attacks. Our results indicate that CARE is also effective in improving network throughput in non-hostile environments because its proactive re-routing mechanism aids in maintaining a reasonable level of throughput when dysfunctional network events occur.
Ruiliang Chen, Jung-Min Park 0001, Michael Snow
ICCCN2
2006 An Adaptive Sampling Algorithm with Applications to Denial-of-Service Attack Detection
abstract
There is an emerging need for the traffic processing capability of network security mechanisms, such as intrusion detection systems (IDS), to match the high throughput of today's high-bandwidth networks. Recent research has shown that the vast majority of security solutions deployed today are inadequate for processing traffic at a sufficiently high rate to keep pace with the network's bandwidth. To alleviate this problem, packet sampling schemes at the front end of network monitoring systems (such as an IDS) have been proposed. However, existing sampling algorithms are poorly suited for this task especially because they are unable to adapt to the trends in network traffic. Satisfying such a criterion requires a sampling algorithm to be capable of controlling its sampling rate to provide sufficient accuracy at minimal overhead. To meet this Utopian goal, adaptive sampling algorithms have been proposed. In this paper, we put forth an adaptive sampling algorithm based on weighted least squares prediction. The proposed sampling algorithm is tailored to enhance the capability of network based IDS at detecting denial-of-service (DoS) attacks. Not only does the algorithm adaptively reduce the volume of data that would be analyzed by an IDS, but it also maintains the intrinsic self-similar characteristic of network traffic. The latter characteristic of the algorithm can be used by an IDS to detect DoS attacks by using the fact that a change in the self-similarity of network traffic is a known indicator of a DoS attack.
Animesh Patcha, Jung-Min Park 0001
ICCCN2
2005 Attack diagnosis: throttling distributed denial-of-service attacks close to the attack sources
abstract
Attack mitigation schemes actively throttle attack traffic generated in distributed denial-of-service (DDoS) attacks. This paper presents attack diagnosis (AD), a novel attack mitigation scheme that combines the concepts of Pushback and packet marking. AD's architecture is inline with the ideal DDoS attack countermeasure paradigm, in which attack detection is performed near the victim host and attack mitigation is executed close to the attack sources. AD is a reactive defense that is activated by a victim host after an attack has been detected. A victim activates AD by sending AD-related commands to its upstream routers. On receipt of such commands, the AD-enabled upstream routers deterministically mark each packet destined for the victim with the information of the input interface that processed that packet. By collecting the router interface information recorded in the packet markings, the victim can trace back the attack traffic to the attack sources. Once the traceback is complete, the victim issues messages that command AD-enabled routers to filter attack packets close to the source. The AD commands can be authenticated by the TTL field of the IP header without relying on any global key distribution infrastructure in Internet. Although AD can effectively filter traffic generated by a moderate number of attack sources, it is not effective against large-scale attacks. To address this problem, we propose an extension to AD called parallel attack diagnosis (PAD) that is capable of throttling traffic coming from a large number of attack sources simultaneously. AD and PAD are analyzed and evaluated using a realistic network topology based on the Skitter Internet map. Both schemes are shown to be robust against IP spoofing and incur low false positive ratios.
Ruiliang Chen, Jung-Min Park 0001
ICCCN2
2005 Detecting denial-of-service attacks with incomplete audit data
abstract
With the ever increasing deployment and usage of gigabit networks, traditional network anomaly detection based intrusion detection systems have not scaled accordingly. Most, if not all, systems deployed assume the availability of complete and clean data for the purpose of intrusion detection. We contend that this assumption is not valid. Factors like noise in the audit data, mobility of the nodes and the large amount of network data generated by the network make it difficult to build a normal traffic profile of the network for the purpose of anomaly detection. From this perspective, we present an anomaly detection scheme, called SCAN (stochastic clustering algorithm for network anomaly detection), that has the capability to detect intrusions with high accuracy even when audit data is not complete. We use the expectation-maximization algorithm to cluster the incoming audit data and compute the missing values in the audit data. We improve the speed of convergence of the clustering process by using Bloom filters and data summaries. We evaluate SCAN using the 1999 DARPA/Lincoln Laboratory intrusion detection evaluation dataset.
Animesh Patcha, Jung-Min Park 0001
ICCCN2
2005 SECK: survivable and efficient clustered keying for wireless sensor networks
abstract
A wireless sensor network (WSN) typically consists of a large number of small sensor nodes and one or more high-end control and data aggregation nodes. Sensor nodes have limited computation and communication capabilities, and communicate via wireless links. Consequently, WSNs are highly vulnerable to attacks. This vulnerability is exacerbated when WSNs have to operate unattended in a hostile environment, such as battlefields. In this paper, we propose a novel self-organizing key management scheme for large-scale WSNs, called Sunivable and efficient clustered keying (SECK). Our scheme was designed specifically to address the key management issues within the low-tier of a hierarchical network architecture. Previous approaches for WSN key management adequately addressed operational issues, but to a large extent, ignored robustness and recoverability issues. Using simulation and analysis, we show that SECK is highly robust against key and node captures, and has noteworthy advantages over other key management schemes.
Michael Chorzempa, Jung-Min Park 0001, Mohamed Eltoweissy
IPCCC2
2005 Performance and Energy Efficiency of Block Ciphers in Personal Digital Assistants
abstract
Encryption algorithms can be used to help secure wireless communications, but securing data also consumes resources. The goal of this research is to provide users or system developers of personal digital assistants and applications with the associated time and energy costs of using specific encryption algorithms. Fouriblock ciphers (RC2, Blowfish, XTEA, and AES) were considered. The experiments included encryption and decryption tasks with different cipher and file size combinations. The resource impact of the block ciphers were evaluated using the latency, throughput, energy-latency product, and throughput/energy ratio metrics. We found that RC2 encrypts faster and uses less energyithan XTEA, followed by AES. The Blowfish cipher is a fast encryption algorithm, but the size of the plaintext affects its encryption speed and energy consumption. Faster algorithms seem to be more energy efficient because of differences in speed rather than differences in power consumption levels while encrypting.
Creighton T. R. Hager, Scott F. Midkiff, Jung-Min Park 0001, Thomas Martin 0001
PerCom3
2003 A certified e-mail protocol suitable for mobile environments
abstract
A novel certified e-mail protocol that is particularly suitable for mobile environments is described. Our protocol uses an off-line trusted third party (TTP). Protocols with an off-line TTP-also known as optimistic protocols-have numerous practical advantages over protocols with an on-line TTP. Nonetheless, many protocols adopt an on-line TTP primarily because optimistic protocols often entail intricate cryptographic primitives that incur considerable overhead. By using a novel signature paradigm, which we call gradational signatures, we show that it is possible to construct optimistic protocols that are comparable to on-line protocols in terms of computation and communication overhead. This makes our scheme especially desirable in the mobile setting.
Jung-Min Park 0001, Indrajit Ray, Edwin K. P. Chong, Howard Jay Siegel
GLOBECOM1
2003 Constructing fair-exchange protocols for E-commerce via distributed computation of RSA signatures
abstract
Applications such as e-commerce payment protocols, elec-tronic contract signing, and certified e-mail delivery require that fair exchange be assured. A fair-exchange protocol al-lows two parties to exchange items in a fair way so that either each party gets the other's item, or neither party does. We describe a novel method of constructing very ef-ficient fair-exchange protocols by distributing the computa-tion of RSA signatures. Specifically, we employ multisig-natures based on the RSA-signature scheme. To date, the vast majority of fair-exchange protocols require the use of zero-knowledge proofs, which is the most computationally intensive part of the exchange protocol. Using the intrinsic features of our multisignature model, we construct protocols that require no zero-knowledge proofs in the exchange proto-col. Use of zero-knowledge proofs is needed only in the pro-tocol setup phase--this is a one-time cost. Furthermore, our scheme uses multisignatures that are compatible with the underlying standard (single-signer) signature scheme, which makes it possible to readily integrate the fair-exchange fea-ture with existing e-commerce systems.
Jung-Min Park 0001, Edwin K. P. Chong, Howard Jay Siegel
PODC1
2003 Efficient multicast stream authentication using erasure codes
abstract
We describe a novel method for authenticating multicast packets that is robust against packet loss. Our focus is to minimize the size of the communication overhead required to authenticate the packets. Our approach is to encode the hash values and the signatures with Rabin's Information Dispersal Algorithm (IDA) to construct an authentication scheme that amortizes a single signature operation over multiple packets. This strategy is especially efficient in terms of space overhead, because just the essential elements needed for authentication (i.e., one hash per packet and one signature per group of packets) are used in conjunction with an erasure code that is space optimal. Using asymptotic techniques, we derive the authentication probability of our scheme using two different bursty loss models. A lower bound of the authentication probability is also derived for one of the loss models. To evaluate the performance of our scheme, we compare our technique with four other previously proposed schemes using empirical results.
Jung-Min Park 0001, Edwin K. P. Chong, Howard Jay Siegel
ACM Trans. Inf. Syst. Secur.1
2002 Efficient Multicast Packet Authentication Using Signature Amortization
abstract
We describe a novel method for authenticating multicast packets that is robust against packet loss. Our main focus is to minimize the size of the communication overhead required to authenticate the packets. Our approach is to encode the hash values and the signatures with Rabin's Information Dispersal Algorithm (IDA) to construct an authentication scheme that amortizes a single signature operation over multiple packets. This strategy is especially efficient in terms of space overhead, because just the essential elements needed for authentication (i.e., one hash per packet and one signature per group of packets) are used in conjunction with an erasure code that is space optimal. To evaluate the performance of our scheme, we compare our technique with four other previously proposed schemes using analytical and empirical results. Two different bursty loss models are considered in the analyses.
Jung-Min Park 0001, Edwin K. P. Chong, Howard Jay Siegel
S&P1