Harald Elders-Boll

dblp:97/7881 · DBLP profile ↗
← Back
10ranked-venue papers
3as first author
5since 2021 · last 2025
0000-0003-4397-7113ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-authorComputer networks · 1
YearPublicationVenuePosition
2025 Anti-Tamper Radio Meets Reconfigurable Intelligent Surface for System-Level Tamper Detection
abstract
Many computing systems need to be protected against physical attacks using active tamper detection based on sensors. One technical solution is to employ an Anti-Tamper Radio (ATR) approach, analyzing the radio wave propagation effects within a protected device to detect unauthorized physical alterations. However, ATR systems face key challenges in terms of susceptibility to signal manipulation attacks, limited reliability due to environmental noise, and regulatory constraints from wide bandwidth usage.
Maryam Shaygan Tabar, Johannes Kortz, Paul Staat, Harald Elders-Boll, Christof Paar, Christian T. Zenger
WISEC4
2024 RIS-Jamming: Breaking Key Consistency in Channel Reciprocity-Based Key Generation
abstract
Channel Reciprocity-based Key Generation (CRKG) exploits reciprocal channel randomness to establish shared secret keys between wireless terminals. This new security technique is expected to complement existing cryptographic techniques for secret key distribution of future wireless networks. In this paper, we present a new attack, reconfigurable intelligent surface (RIS) jamming, and show that an attacker can prevent legitimate users from agreeing on the same key by deploying a malicious RIS to break channel reciprocity. Specifically, we elaborate on three examples to implement the RIS-jamming attack: Using active nonreciprocal circuits, performing time-varying controls, and reducing the signal-to-noise ratio. The attack effect is then studied by formulating the secret key rate with a relationship to the deployment of RIS. To resist such RIS-jamming attacks, we propose a countermeasure that exploits wideband signals for multipath separation. The malicious RIS path is distinguished from all separated channel paths, and thus the countermeasure is referred to as contaminated path removal-based CRKG (CPR-CRKG). We present simulation results, showing that legitimate users under RIS jamming are still able to generate secret keys from the remaining paths. We also experimentally demonstrate the RIS-jamming attack by using commodity Wi-Fi devices in conjunction with a fabricated RIS prototype. In our experiments, we were able to increase the average bit disagreement ratio (BDR) of raw secret keys by 20%. Further, we successfully demonstrate the proposed CPR-CRKG countermeasure to tackle RIS jamming in wideband systems as long as the source of randomness and the RIS propagation paths are separable.
Guyue Li, Paul Staat, Markus Heinrichs, Christian T. Zenger, Rainer Kronberger, Harald Elders-Boll, Christof Paar, Aiqun Hu
IEEE Trans. Inf. Forensics Secur.7
2022 Mirror, Mirror on the Wall: Wireless Environment Reconfiguration Attacks Based on Fast Software-Controlled Surfaces
abstract
The intelligent reflecting surface (IRS) is a promising new paradigm in wireless communications for meeting the growing connectivity demands in next-generation mobile networks. IRS, also known as software-controlled metasurfaces, consist of an array of adjustable radio wave reflectors, enabling smart radio environments, e.g., for enhancing the signal-to-noise ratio (SNR) and spatial diversity of wireless channels. Research on IRS to date has been largely focused on constructive applications.
Paul Staat, Harald Elders-Boll, Markus Heinrichs, Christian T. Zenger, Christof Paar
AsiaCCS2
2022 Analog Physical-Layer Relay Attacks with Application to Bluetooth and Phase-Based Ranging
abstract
Today, we use smartphones as multi-purpose devices that communicate with their environment to implement context-aware services, including asset tracking, indoor localization, contact tracing, or access control. As a de-facto standard, Bluetooth is available in virtually every smartphone to provide short-range wireless communication. Importantly, many Bluetooth-driven applications such as Phone as a Key (PaaK) for vehicles and buildings require proximity of legitimate devices, which must be protected against unauthorized access. In earlier access control systems, attackers were able to violate proximity-verification through relay station attacks. However, the vulnerability of Bluetooth against such attacks was yet unclear as existing relay attack strategies are not applicable or can be defeated through wireless distance measurement.
Paul Staat, Kai Jansen, Christian T. Zenger, Harald Elders-Boll, Christof Paar
WISEC4
2021 Intelligent Reflecting Surface-Assisted Wireless Key Generation for Low-Entropy Environments
abstract
Physical layer key generation is a promising candidate for cryptographic key establishment between two wireless communication parties. It offers information-theoretic security and is an attractive alternative to public-key techniques. Here, the inherent randomness of wireless radio channels is used as a shared entropy source to generate cryptographic key material. However, practical implementations often suffer from static channel conditions which exhibit a limited amount of randomness. In the past, considerable research efforts have been made to address this fundamental limitation. However, current solutions are not generic or require dedicated hardware extensions such as reconfigurable antennas. In this paper, we propose a novel wireless key generation architecture based on randomized channel responses from an intelligent reflecting surface (IRS). Due to its passive nature, a cooperative IRS is well-suited to provide randomness for conventional resource-constrained radios. We conduct the first practical studies to successfully demonstrate IRS-based physical-layer key generation with an OFDM system. In a static environment, using a single subcarrier only, our IRS-assisted prototype system achieves a key generation rate (KGR) of 97.39 bps with 6.5% key disagreement rate (KDR) after quantization, while passing standard randomness tests.
Paul Staat, Harald Elders-Boll, Markus Heinrichs, Rainer Kronberger, Christian T. Zenger, Christof Paar
PIMRC2
2009 2nd Order Cyclostationarity of OFDM Signals: Impact of Pilot Tones and Cyclic Prefix
abstract
This paper deals with 2ndorder cyclostationarity of orthogonal frequency division multiplex (OFDM) signals. A new generalized formula for the spectral correlation density (SCD) function is derived. Compared to related work in the literature, our derivation is not restricted to the case that all sub-carriers of an OFDM signal carry statistically independent data. The reason for that is that correlated data in terms of pilot tones are typically introduced on different carriers for channel estimation and synchronization purposes. The new formula allows us to analyze the impact of such pilot tones on the SCD. In addition, it gives extra information about the impact of the cyclic prefix.
Marc Adrat, Jan Leduc, Stefan Couturier, Markus Antweiler, Harald Elders-Boll
ICC5
2000 Simplified interference-based threshold rule for delay selection in DS-CDMA systems
abstract
Reliable path selection prior to maximum-ratio combining is a crucial operation in any DS-CDMA receiver. We propose a simplified dynamic threshold rule for path delay selection. The new threshold rule is based on the statistical parameters of the interference, which can easily be estimated from the computed power delay profile. By using the new threshold rule, the performance of the RAKE receiver can be improved and/or its complexity can be reduced, considerably.
Harald Elders-Boll
PIMRC1
1998 Implementation of linear multiuser detectors for asynchronous CDMA systems by linear multi-stage interference cancellation
abstract
The decorrelating and the linear, minimum mean-squared error (MMSE) detectors for asynchronous code-division multiple-access communications ideally are infinite memory-length detectors. Finite memory approximations of these detectors require the inversion of a correlation matrix whose dimension is given by the product of the number of active users and the length of the processing window. With increasing number of active users or increasing length of the processing window, the calculation of the inverse may soon become numerically very expensive. In this paper, we prove that the decorrelating and the linear MMSE detector can both be realized by linear multi-stage interference cancellation algorithms with ideally an infinite number of stages. It is shown that for serial multi-stage interference cancellation, depending on the signal-to-noise ratio and the number of active users, only a few stages are necessary to obtain the same BER performance as the ideal detectors. Thus, the complexity can be reduced considerably.
Harald Elders-Boll, Hans D. Schotten, Axel Busboom
ICASSP1
1997 Combinatorial design of near-optimum masks for coded aperture imaging
abstract
In coded aperture imaging the attainable quality of the reconstructed images strongly depends on the choice of the aperture pattern. Optimum mask patterns can be designed from binary arrays with constant sidelobes of their periodic autocorrelation function, the so-called URAs. However, URAs exist for a restricted number of aperture sizes and open fractions only. Using a mismatched filter decoding scheme, artifact-free reconstructions can be obtained even if the aperture array violates the URA condition. A general expression and an upper bound for the signal-to-noise ratio as a function of the aperture array and the relative detector noise level are derived. Combinatorial optimization algorithms, such as the great deluge algorithm, are employed for the design of near-optimum aperture arrays. The signal-to-noise ratio of the reconstructions is predicted to be only slightly inferior to the URA case while no restrictions with respect to the aperture size or open fraction are imposed.
Axel Busboom, Harald Elders-Boll, Hans D. Schotten
ICASSP2
1997 Spreading sequences for zero-forcing DS-CDMA multiuser detectors
abstract
In the past, different multiuser detectors for asynchronous code-division multiple-access communications have been proposed, many of them may be characterized as zero-forcing detectors, e.g., the decorrelation detector. We show that linear interference cancellation schemes are asymptotically zero-forcing which means that they are equivalent to the decorrelating detector if the number of stages approaches infinity. These detectors have been found to be superior to the conventional matched filter detector. However, the design of spreading sequences optimized especially for these receivers has not been considered up to now. Usually, spreading sequences are designed to have a low peak correlation parameter. Pursley (1977) has shown that the average interference parameter (AIP) is an important design parameter since it is related to the average signal-to-interference ratio of the conventional receiver. In this paper, we consider the construction of spreading sequences for zero-forcing multiuser detectors that are optimal in the sense of performance and near-far resistance. It is shown that sequences with a low AIP are near-optimal. This, again, stresses the importance of the AIP for the design of spreading sequences for CDMA systems employing any kind of receiver. Numerical examples indicate that by using optimized sequences the average signal-to-noise ratio (SNR) can be improved by about 1-2 dB for lengths of interest in applications.
Harald Elders-Boll, Axel Busboom, Hans D. Schotten
PIMRC1