EDBT 2026 Demo / reviewers in the wild / expert
Guyue Li
dblp:147/7757
· DBLP profile ↗
55ranked-venue papers
11as first author
43since 2021 · last 2026
0000-0003-1145-1168ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 32 · 6 first-author · 25 since 2021Security and privacy · 12 · 4 first-author · 11 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Deceptive Electricity Theft: New Attacks and Countermeasures in Multiple-Pricing Smart Grids
Chengpeng Huang, Shang Gao 0006, Qingqing Gan, Guyue Li, Bin Xiao 0001 |
ICDCS | 4 |
| 2026 | Channel-Robust RFF for Low-Latency 5G Device Identification in SIMO ScenariosabstractUltra-low latency, the hallmark of fifth-generation mobile communications (5G), imposes exacting timing demands on identification as well. Current cryptographic solutions introduce additional computational overhead, which results in heightened identification delays. Radio frequency fingerprint (RFF) identifies devices at the physical layer, blocking impersonation attacks while significantly reducing latency. Unfortunately, multipath channels compromise RFF accuracy, and existing channel-resilient methods demand feedback or processing across multiple time points, incurring extra signaling latency. To address this problem, the paper introduces a new RFF extraction technique that employs signals from multiple receiving antennas to address multipath issues without adding latency. Unlike single-domain methods, the Log-Linear Delta Ratio (LLDR) of co-temporal channel frequency responses (CFRs) from multiple antennas is employed to preserve discriminative RFF features, eliminating multi-time sampling and reducing acquisition time. To overcome the challenge of the reliance on minimal channel variation, the frequency band is segmented into sub-bands, and the LLDR is computed within each sub-band individually. Simulation results indicate that the proposed scheme attains a 96.13% identification accuracy for 30 user equipments (UEs) within a 20-path channel under a signal-to-noise ratio (SNR) of 20 dB. Furthermore, we evaluate the theoretical latency using the Roofline model, resulting in the air interface latency of 0.491 ms, which satisfies ultra-reliable and low-latency communications (URLLC) latency requirements. Yingjie Sun, Guyue Li, Hongfu Chou, Aiqun Hu |
WCNC | 2 |
| 2026 | Fluid Antenna System-Assisted Physical Layer Secret Key GenerationabstractThis paper investigates physical-layer key generation (PLKG) in multi-antenna base station systems, by leveraging a fluid antenna system (FAS) to dynamically customize radio environments. Without requiring additional nodes or extensive radio frequency (RF) chains, the FAS effectively enables adaptive antenna port selection by exploiting channel spatial correlation to enhance the secret key rate (SKR) at legitimate nodes. To comprehensively evaluate the performance of the FAS in PLKG, we propose an FAS-assisted PLKG model that integrates transmit beamforming and sparse port selection under independent and identically distributed (i.i.d.) and spatially correlated channel models, respectively. Specifically, the PLKG utilizes reciprocal channel probing to derive an approximate SKR expression based on the mutual information between legitimate channel estimates, explicitly accounting for the Eve’s channel observation under spatially correlated channel scenarios. Nonconvex optimization problems for these scenarios are formulated to maximize the SKR subject to transmit power constraints and sparse port activation. We propose an iterative algorithm by capitalizing on successive convex approximation and Cauchy-Schwarz inequality to obtain a locally optimal solution. A reweighted ℓ1-norm-based algorithm is applied to advocate for the sparse port activation of FAS-assisted PLKG. To approximate the optimal activated ports obtained by exhaustive search, a low-complexity sliding window-based port selection is proposed to substitute reweighted ℓ1-norm method based on Rayleigh-quotient analysis. Simulation results demonstrate that the FAS-assisted PLKG scheme significantly outperforms fixed antenna-assisted PLKG schemes in both environments. It is shown that the FAS achieves higher SKR with fewer RF chains through dynamic sparse port selection, which effectively reduces the resource overhead. Also, the sliding window approach closely approximates the globally optimal port selection compared to the reweighted ℓ1-norm method, rendering it suitable for practical deployments. Zhiyu Huang, Guyue Li, Hao Xu 0003, Derrick Wing Kwan Ng |
IEEE J. Sel. Areas Commun. | 2 |
| 2026 | Fine-Grained IoT Device Fingerprinting Using Active Probing
Yubo Song, Yuncong Ma, Guyue Li, Liquan Chen, Shang Gao 0006, Bin Xiao 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | DLM-IDS: Leveraging LLM for Efficient IoT Intrusion Detection with Limited Training DataabstractArtificial intelligence has demonstrated significant potential for traffic analysis in IoT intrusion detection systems. However, existing machine learning (ML) solutions struggle with high false alarm rates due to a lack of malicious data. The advantages of large language models (LLMs), particularly their few-shot learning capabilities, can effectively address this issue. Nonetheless, LLMs face challenges such as high computational overhead and detection latency, which make them impractical for IoT intrusion detection. One promising solution is to leverage knowledge distillation, shrinking the LLM, the teacher model, into a smaller student model that requires limited malicious examples while preserving the low latency characteristic of traditional ML-based models. In this paper, we propose DLM-IDS, an efficient and accurate traffic analysis framework for IoT intrusion detection with small training datasets, empowered by LLM knowledge distillation. Specifically, DLM-IDS introduces a chain-of-thought (CoT) mechanism that enables a pre-trained LLM to interpret network traffic patterns without requiring additional training or fine-tuning. By extracting rationales from the LLM (around 200B parameters), the teacher model, DLM-IDS constructs a small yet highly accurate student traffic analysis model (around 200 million parameters). Experiments show that with only 800 examples in the training dataset, DLM-IDS maintains over 98% AUC while reducing inference time from 3.2s to 0.037s per flow detection, enabling practical low-latency deployment on resource-constrained IoT devices. Mingyang Zhao 0002, Guyue Li, Bin Xiao 0001 |
GLOBECOM | 4 |
| 2025 | The Optimization of XL-RIS-assisted Physical Layer Key Generation in Near-FieldabstractWith the rapid development of 6G technologies, extremely large-scale reconfigurable intelligent surfaces (XL-RIS) have been introduced to enhance spatial diversity and improve signal coverage. Meanwhile, physical-layer key generation (PKG) has emerged as a promising, quantum-resistant solution for securing wireless communications. However, the deployment of XL-RIS significantly expands the near-field region, making traditional far-field planar wave models inadequate for PKG. To address this limitation, this paper proposes an XL-RIS-assisted PKG model based on near-field spherical wave propagation theory. We further derive a expression for the legitimate key generation rate (KGR) under passive eavesdropping attacks. To maximize the achievable KGR, we propose a novel alternating optimization(AO) algorithm ADA that combines Dinkelbach and the Alternating Direction Method of Multipliers (ADMM) to jointly optimize the base station (BS) beamforming vector and RIS reflection coefficients in an iterative manner. Simulation results indicate that the spatial resolution gain provided by the near-field channel helps enhance the independence between the legitimate and eavesdropping channels. The ADA demonstrates robust convergence. Notably, it maintains superior performance even when the eavesdropper and the legitimate user share the same azimuth angle. Jiaping Chen, Guyue Li, Xianghui Cao |
VTC2025-Fall | 3 |
| 2025 | Defeating CSI obfuscation mechanisms: A study on unauthorized Wi-Fi Sensing in wireless sensor network
Zhiming Chu, Guyue Li, Haobo Li 0002, Yuwei Zeng |
Comput. Networks | 2 |
| 2025 | An improved metric-active learning approach for few labeled radio frequency fingerprinting
Guyue Li |
Comput. Networks | 5 |
| 2025 | Privacy-preserving WiFi sensing in WSNs via CSI obfuscation
Zhiming Chu, Guyue Li, Haobo Li 0002, Yuwei Zeng |
Comput. Secur. | 2 |
| 2025 | Securing Wireless Communications via Channel Reciprocity and Dynamic Constellation ObfuscationabstractThe one-time pad secure transmission based on wireless channel reciprocity (CR-OTP) has drawn great attention recently due to its capability of providing perfect secrecy of data, as well as the modulation information. However, existing CR-OTP schemes encounter both reliability and security challenges as their assumptions of channel reciprocity and randomness are not always well satisfied in practical application scenarios. To tackle these issues, we propose a dynamic constellation obfuscation (DCO) method that obfuscates the plaintext by rotating its constellation dynamically. This kind of analog encryption method is proven to be more robust than the existing digital exclusive OR (XOR) encryption method as the former achieves a lower symbol error rate (SER) by reducing the double quantization loss to one. The rotation pattern is jointly dependent on the channel state information (CSI) and the previous message, which guarantees the randomness of the rotation pattern subjected to environmental drifts. Only the legitimate receiver that correctly recovers the previous message correctly and observes a similar CSI is able to decode the newly transmitted message. We proved that the secrecy capacity of the proposed DCO method is higher than that of the state-of-the-art. Simulation results confirm that the proposed method delivers superior performance regarding secrecy capacity and SER, achieving a 4.5 dB signal-to-noise ratio (SNR) gain at a SER of 0.1; moreover, when the secrecy capacity is 0.1, the main channel SNR gain reaches 6.5 dB when the wiretap channel SNR is 20 dB. Yujie Hou, Hai-Xi Sun, Guyue Li, Shuping Dang, Aiqun Hu |
IEEE Internet Things J. | 3 |
| 2025 | Enhancing Wireless Communication Security With Variable Bloom Filter-Based Physical-Layer Secure TransmissionabstractThis paper studies one-time pad (OTP) secure communication by leveraging the unpredictable physical layer channel characteristics. Existing OTP schemes based on physical-layer key generation (PKG) require additional transmission overhead of information reconciliation and may face security threats of information leakage under slow-varying channels. To tackle these challenges, we investigate a fault-tolerant privacy amplification method through variable bloom filters to address the underlying security problems. Specifically, the quantized bit sequence of the channel state information goes through a bloom filter to improve the randomness within the sequence while the parameters of bloom filter vary to avoid the correlations between adjacent sequences. We then optimize the parameters of the error-correcting code used during communication based on the position of the eavesdropper and the length of the quantized bits, thereby further enhancing the system security. Through comprehensive simulations, it is shown that our proposed approach can achieve a near-perfect pass rate in NIST randomness tests, and with a bit replacement rate around 0.45, whilst capable of resisting attacks under slow-varying channels. These results indicate that the proposed scheme significantly outperforms previous OTP secure transmission schemes. Anqi Huo, Guyue Li, Lilin Yang, Zi Long Liu 0001, Aiqun Hu |
IEEE Internet Things J. | 2 |
| 2025 | PPCA: Privacy-Preserving Continuous Authentication Scheme With Consistency Proof for Zero-Trust Architecture NetworksabstractContinuous authentication (CA) has been widely applied by network service providers to verify user identities in finance, healthcare, and e-commerce fields. However, in next-generation networks, CA faces the risk of user privacy leakage due to its dependence on a verifier-centric authentication model, and verifiers may not always be trustworthy, particularly in zero-trust architecture networks. Existing privacy protection schemes face challenges in solving this problem because these schemes will weaken the linkability of context requests, leading to difficulties in consistency checks for fine-grained CA. To fill the gap, this article proposes a privacy-preserving CA (PPCA) scheme by incorporating anonymous self-sovereign identity and fine-grained CA. Specifically, PPCA exploits subset proof to enable users to reveal only the minimum necessary identity data for selective disclosure. To support fine-grained CA, we construct a new consistency proof for the anonymous user to prove that the different credentials are bound to the same attributes set, where the user is responsible for deciding whether to send the consistency proof. PPCA is formalized, defined, and constructed based on BLS signatures, Set Commitment, and Sigma Protocol. The security analysis shows that PPCA is correct and sound and supports user anonymity and credential consistency at the same time. The performance evaluation shows that PPCA requires only minimal additional time cost, achieving an optimal balance between security and efficiency. Guyue Li, Jiaheng Wang 0001, Bin Xiao 0001, Yubo Song |
IEEE Internet Things J. | 2 |
| 2025 | Joint Beamforming Design for Integrated Sensing and Communication Systems With Hybrid-Colluding EavesdroppersabstractIn this paper, we consider the physical layer security (PLS) problem for integrated sensing and communication (ISAC) systems in the presence of hybrid-colluding eavesdroppers, where an active eavesdropper (AE) and a passive eavesdropper (PE) collude to intercept the confidential information. To ensure the accuracy of sensing while preventing the eavesdropping, a base station transmits a signal consisting of information symbols and sensing waveform, in which the sensing waveform can be also used as artificial noise to interfere with eavesdroppers. Under this setup, we propose an alternating optimization-based two stage scheme (AO-TSS) for improving the sensing and communication performance. In the first stage, based on the assumptions that the perfect channel state information (CSI) of the AE and statistical CSI of the PE are known, the communication and sensing beamforming problem is formulated with the objective of minimizing the weighted sum of the beampattern matching mean squared error (MSE) and cross-correlation, subject to the secure transmission constraint. To tackle the non-convexity, we propose a semi-definite relaxation (SDR) algorithm and a reduced-complexity zero-forcing (ZF) algorithm. Then, the scenarios are further extended to more general cases with imperfect AE CSI and unknown PE CSI. To further improve the communication performance, the second-stage problem is developed to optimize the secrecy rate threshold under the radar performance constraint. Finally, numerical results demonstrate the superiority of the proposed scheme in terms of sensing and secure communication. Meiding Liu, Zhengchun Zhou, Qiao Shi, Guyue Li, Zi Long Liu 0001, Pingzhi Fan, Inkyu Lee |
IEEE Trans. Commun. | 4 |
| 2025 | Channel-Robust RF Fingerprint Identification for Multi-Antenna 5G User EquipmentsabstractRadio frequency fingerprint (RFF) is a promising solution for realizing secure and efficient device identification. However, the accuracy of currently existing solutions suffer from multipath effects in practical scenarios. In this paper, we provide a robust RFF identification method that leverages channel state information (CSI) feedback to counteract the effect of the channel on the extracted RFF features. A straightforward zero-forcing (ZF) equalization fails to fully decouple RF impairments from the channel, making conventional approaches ineffective. To overcome this challenge, we utilize the potential of multi-antenna and introduce a new device-specific feature called Relative-RFF (R-RFF), which represents the relation between different RF chains in a multi-antenna transmitter. We propose an enhanced ZF post-equalization algorithm to eliminate the multipath channels and preserve the users’ R-RFF to the greatest extent. We evaluate the robustness of R-RFF under various channel conditions and noise levels and the performance of R-RFF in terms of identification accuracy under different channel scenarios. The results show that the proposed R-RFF method can achieve an identification accuracy of 91.2% for 70 devices in tapped delay line channel with a signal-to-noise ratio (SNR) of 30 dB. Hongyi Luo, Guyue Li, Alessandro Brighente, Mauro Conti, Yuexiu Xing, Aiqun Hu, Xianbin Wang 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | Optimal Subcarrier Allocation Scheme for Physical-Layer Key Generation in an OFDMA NetworkabstractThis paper studies enhanced physical-layer key generation (PKG) for multiuser orthogonal frequency division multiple access (OFDMA) networks. In practical OFDMA systems, our key observation is that there are frequency correlations between different subcarriers which potentially lead to compromised randomness of the generated keys as well as reduced sum secret key rate. Motivated by this, we show that subcarrier allocation plays a key role in enhancing the PKG performance in OFMDA networks. We prove that when a single user terminal selects a finite number of subcarriers for key generation, adopting uniformly spaced subcarriers is the optimal solution as it leads to higher secret key rates and better randomness. Moreover, we derive a closed-form expression for the sum secret key rate and introduce a low-complexity near-optimal algorithm that can achieve an appropriate subcarrier allocation policy in a timely manner. Simulation results show that our proposed near-optimal algorithm exhibits significant advantages in maximizing the sum secret key rate and improving key randomness compared with existing subcarrier allocation algorithms. Qingjiang Xiao, Guyue Li, Zi Long Liu 0001, Aiqun Hu |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | A Robust Radio Frequency Fingerprint Open-Set Recognition Scheme for IoT DevicesabstractRadio frequency fingerprint (RFF) identification is a promising solution for Internet of Things (IoT) device authentication. However, this technique encounters practical challenges such as noise interference, channel coupling, and open-set recognition (OSR). This paper proposes a unified RFF-OSR framework to jointly address these problems in complex environments. Firstly, the framework mitigates the noise interference by employing a low-pass filter-integrated autoencoder, where the low-pass filter is used to obtain a “quasi-clean” signal as the autoencoder reference, thereby reducing the demand for ideal signals. Then, the channel influence on RFF is modeled as three types: frequency offset, phase noise, and amplitude distortion. Based on this model, parameterized channel augmentation is performed to improve the generalization ability of RFF identification in unknown channel scenarios. In terms of OSR, instead of a coarse-grained uniform probability threshold for rogue device recognition, we conduct independent similarity judgments for all legitimate classes, each with an individual threshold. It effectively reduces information loss in the feature probability transformation and increases OSR performance. Under additive white Gaussian noise (AWGN) and multipath channel conditions, our method achieves OSR accuracies of 99.37% and 97.05% in ZigBee device identification, respectively, which demonstrates the effectiveness of our approach. Yuexiu Xing, Guyue Li, Yun Lin 0005, Haitao Zhao 0004 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | Efficient and Error-Free Secret Key Generation Leveraging Sorted Indices MatchingabstractSecret key generation exploiting inherent channel randomness stands as an important paradigm for physical-layer security in wireless networks. However, existing work relying on quantization has some difficulties in eliminating inconsistent key bits due to the impact of ambient noise. Recent studies propose to match the segmented channel samples (i.e., channel episodes) of similar variation patterns between legitimate peers to achieve error-free key generation, but they also suffer from high computational overhead and reduced accuracy for large key lengths. This work proposes a secret key generation method based on sorted indices matching (SIM-SKG), aiming at efficient and error-free key generation. Specifically, we sort the channel samples to ensure each channel episode with a unique variation pattern for accurate matching. To avoid the impact of half-duplex communication mode and ambient noise, we propose to match the indices instead of the channel samples as in existing studies. We also develop a noise perturbation scheme that further mitigates the ambiguity during indices matching. Extensive experimental studies demonstrate the high efficiency and accuracy of SIM-SKG under various scenarios for both RSS and CSI channel measurements. Specifically, SIM-SKG achieves error-free key generation with a length of 2048 bits within as little as 1.7$msec$. Moreover, theoretical analyses and experiments also confirm the security of the SIM-SKG method against various attacks. Yicong Du, Hongbo Liu 0002, Guyue Li, Yanzhi Ren, Ke Zhang 0022 |
IEEE Trans. Mob. Comput. | 4 |
| 2024 | Physical-layer Secret Key Generation with Energy Efficiency MaximizationabstractPhysical-layer secret key generation (PKG) is an emerging technique for secret key sharing. However, researches on it rarely consider the issue of energy efficiency, which results in a limited performance gain at the expense of a large amount of consumed energy. In this paper, we define the secret key energy efficiency (KEE) as the ratio of the generated secret key bits to the total energy consumption in the resource constrained PKG system. An optimization problem with quality of service (QoS) requirement and power consumption constraints is formulated and a multi-layer iterative algorithm to maximize the KEE is proposed. To cope with the difficulty of the non-convex problem, we transform and iterate it until it is equivalent to the primal problem by applying the Dinkelbach algorithm. In each iteration, the penalty algorithm and difference-of-convex-functions (DC) programming algorithm are used to tackle the non-convex constraints and objectives, respectively. Simulation results demonstrate that the KEE which is maximized can be 84% higher than that of the secret key rate (SKR) maximization only at the cost of a 5% decrease in SKR. Sheng Feng, Guyue Li, Bin Xiao 0001, Aiqun Hu |
GLOBECOM | 3 |
| 2024 | Privacy-Preserving and Secure Decentralized Identity Management for Multiple ControllersabstractDecentralized identity (DID) is pivotal to Web3 applications as it empowers users to manage their identities and credentials without relying on any central authority. Multi-controller is a new and indispensable scenario outlined by the W3C DID standards, while its privacy and security issues have not yet been fully explored. In this paper, we find two new attacks caused by multiple controllers toward DID management, and propose a privacy-preserving and secure identity management scheme to defend against both attacks. The first proposed controller-correlation attack allows an attacker to infer relationships between different subjects by correlating the public keys uploaded by multiple controllers to the blockchain. To avoid this kind of privacy leakage, we propose a masking scheme based on the Merkle tree, which allows the controllers to prove their ownership over the multi-controller identities without publicizing the plaintext of their public keys. The other identity impersonation attack exploits insecure controller revocation caused by high block synchronization latency. To resist this attack, we propose a lightweight authentication scheme. The holders provide digest freshness proof while the verifiers only need to download block headers. To evaluate the feasibility of our proposed scheme, we implement our system on the Sepolia TestNet. The experimental result demonstrates that our system can prevent these attacks with acceptable gas consumption and time consumption, compared with the state-of-the-art. Huijiong Yang, Bin Xie 0006, Jianhuan Wang, Guyue Li, Bin Xiao 0001 |
GLOBECOM | 4 |
| 2024 | A Secure and Reliable Blockchain-based Audit Log SystemabstractThe use of log files in digital forensics highlights the importance of ensuring their data integrity for auditing purposes. However, traditional centralized audit log systems face challenges in maintaining data integrity due to log injection attacks and single-point failures. Although blockchain technology can accurately process and replicate log files, existing blockchain-based audit log systems still suffer from security and reliability issues due to their weak threat models and limited scalability. To address these concerns, we propose a blockchain-based audit log system that ensures data integrity under a general threat model where a part of the nodes, including loggers and auditors, are untrusted. First, our proposed system resists collusion attacks by incorporating multiple nodes for system processes and utilizing smart contracts to enforce consensus algorithms. Second, to save blockchain storage space, we design an efficient log integrity proof method, which generates a sub-Non-Fungible Token (sub-NFT) for each log file and keeps it on the blockchain as integrity proof. The single-point failure problem is resolved by outsourcing log files to a distributed file system. To evaluate the proposed system, we implement a prototype based on Hyperledger Fabric. Experimental results show that our proof generation method can reduce storage space usage in comparison to other blockchain-based audit log systems, saving approximately 50% of space in Hyperledger Fabric. The security analysis proves that our system can ensure log file data integrity under the proposed threat model. Zhonghao Liu, Xinwei Zhang 0002, Guyue Li, Helei Cui, Jiaheng Wang 0001, Bin Xiao 0001 |
ICC | 3 |
| 2024 | The Self-Detection Method of the Puppet Attack in Biometric FingerprintingabstractFingerprint authentication has become a staple in securing access to personal devices and sensitive information in our daily lives, with the security level of such systems being paramount. Recent attention has been drawn to the puppet attack, a forced fingerprint unlocking scenario that exploits legitimate user fingerprints for unauthorized access. Traditional authentication methods are constrained by their reliance on additional sensors and are typically limited to static authentication scenarios, lacking versatility in dynamic or mobile contexts. In this study, we employ physical modeling to elucidate puppet attack, unraveling the distinctive stress patterns, and points of application associated with forced interactions. By scrutinizing the physical alterations induced during such attacks, our investigation unveils discernible changes in the texture of fingerprints, specifically reflecting variations linked to different force patterns. Consequently, we introduce a detection system that operates without the need for external sensors, solely utilizing fingerprint images to extract texture features, thereby offering a broadly applicable solution. To address the challenge posed by the absence of puppet attack samples in existing data sets, we constructed a comprehensive database, incorporating a substantial number of puppet attack fingerprints collected from 70 volunteers aged between 20 and 75. This database facilitates a more robust detection of puppet attack. Our system demonstrates accuracy rates of 85.5%, 97.2%, 86.5%, and 78.1% across four distinct scenarios within our puppet attack database. Guyue Li, Yiyun Ma, Junqing Zhang, Hongyi Luo |
IEEE Internet Things J. | 1 |
| 2024 | Wireless Channel Key Generation Based on Multisubcarrier Phase DifferenceabstractWireless channel key generation technology is an important mechanism to guarantee the security of wireless network, but influenced by the key length and the actual electromagnetic environment, wireless channel key generation technology is faced with the challenge of high-key generation rate (KGR) and low-key disagreement rate (KDR). The existing key generation methods also lack the full use of the channel state information (CSI). We propose a key generation method based on multisubcarrier phase difference to expand the randomness source dimension, eliminate the phase bias, offset part of the noise influence, and set the threshold screening data to reduce the influence of measurement error. We further propose a key generation method based on resampling of kernel density estimation (KDE), which yields highly reciprocal randomness sources by resampling the results of KDE of phase difference values. To fill the metric gap of whether a method keeps low KDR while increasing the KGR, the evaluation metric of effective improvement ratio (EIR) is proposed. The two methods we proposed have a higher EIR than the method of using multiple-input and multiple-output (MIMO) and increasing the quantization level, achieving the goal of increasing the KGR while maintaining the low KDR. The KGR can reach about 12146 bits/s, and the KDR is 1.83%. The keys obtained by both methods can effectively prevent passive eavesdropping and meet the randomness requirements. Xiaowei Yuan, Yu Jiang 0020, Guyue Li, Aiqun Hu |
IEEE Internet Things J. | 3 |
| 2024 | RIS-Jamming: Breaking Key Consistency in Channel Reciprocity-Based Key GenerationabstractChannel Reciprocity-based Key Generation (CRKG) exploits reciprocal channel randomness to establish shared secret keys between wireless terminals. This new security technique is expected to complement existing cryptographic techniques for secret key distribution of future wireless networks. In this paper, we present a new attack, reconfigurable intelligent surface (RIS) jamming, and show that an attacker can prevent legitimate users from agreeing on the same key by deploying a malicious RIS to break channel reciprocity. Specifically, we elaborate on three examples to implement the RIS-jamming attack: Using active nonreciprocal circuits, performing time-varying controls, and reducing the signal-to-noise ratio. The attack effect is then studied by formulating the secret key rate with a relationship to the deployment of RIS. To resist such RIS-jamming attacks, we propose a countermeasure that exploits wideband signals for multipath separation. The malicious RIS path is distinguished from all separated channel paths, and thus the countermeasure is referred to as contaminated path removal-based CRKG (CPR-CRKG). We present simulation results, showing that legitimate users under RIS jamming are still able to generate secret keys from the remaining paths. We also experimentally demonstrate the RIS-jamming attack by using commodity Wi-Fi devices in conjunction with a fabricated RIS prototype. In our experiments, we were able to increase the average bit disagreement ratio (BDR) of raw secret keys by 20%. Further, we successfully demonstrate the proposed CPR-CRKG countermeasure to tackle RIS jamming in wideband systems as long as the source of randomness and the RIS propagation paths are separable. Guyue Li, Paul Staat, Markus Heinrichs, Christian T. Zenger, Rainer Kronberger, Harald Elders-Boll, Christof Paar, Aiqun Hu |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | SAMCU: Secure and Anonymous Multi-Channel Updates in Payment Channel NetworksabstractThe Payment Channel Network (PCN) has emerged as an extensively adopted solution to address the scalability issues of Bitcoin by efficient off-chain updates. However, conflicts arise while existing update protocols are pursuing multiple goals of security, privacy, and expressiveness. In this work, we propose a new off-chain update protocol, Secure and Anonymous Multi-Channel Updates (SAMCU), which is developed on the basis of Unspent Transaction Output (UTXO). SAMCU aims at achieving goals of internal anonymity, balance security, and multi-channel updates simultaneously, which has not been done before. To achieve these goals, we exploit the technique of updating graph splitting (UGS) to make participants aware of only the identities of their neighboring sub-graphs, thereby ensuring internal anonymity in multi-channel updates. Then, to avoid security issues arising from equal sub-graphs, we further propose an Enable Payment Transaction Tree (EPTT) to guarantee balance security for each honest protocol participant. Moreover, we optimize the performance of our solution, reducing transaction fees by splitting transactions and the number of communication connections by hierarchical communication. To evaluate the performance of the SAMCU, we implement a prototype involving up to 100 updating payment channels. Experimental results demonstrate that SAMCU outperforms the state-of-the-art, resulting in approximately 70% savings in communication connections and a 66% reduction in on-chain transaction fees when the number of updating payment channels is 100. Jianhuan Wang, Shang Gao 0006, Guyue Li, Keke Gai, Bin Xiao 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | Secret Key Generation Based on Manipulated Channel Measurement MatchingabstractThe physical layer secret key generation exploiting wireless channel reciprocity has demonstrated its viability and effectiveness in various wireless scenarios, such as the Internet of Things (IoT) network, mobile communication network, and industrial control system. Most of the existing studies rely on the quantization technique to convert channel measurements into secret bits for confidential communications. However, non-simultaneous packet exchanges in time-division duplex systems and noise effects usually induce inconsistent quantization results and mismatched secret bits. Although recent research has spent significant effort mitigating such non-reciprocity, it is still far from practical error-free key generation. Unlike previous quantization-based approaches, we take a different viewpoint to match the randomly manipulated (i.e., permuted or edited) channel measurements between a pair of users by minimizing their discrepancy holistically. Specifically, two novel secret key generation algorithms based on bipartite graph matching (BMSKG) and edited sequence alignment (SA-SKG) are developed. BM-SKG allows two users to generate the same secret key based on the permutation order of channel measurements, while SASKG aims to align the edited channel measurements between a pair of users for secret key agreement. In both algorithms, one user can preset the secret key and embed encrypted messages in the exchanged data packets, which reduces communication overheads in key generation. Extensive experimental results show that both BM-SKG and SA-SKG algorithms achieve error-free key agreement on channel measurements at a low cost under various scenarios. Yicong Du, Hongbo Liu 0002, Yan Wang 0003, Guyue Li, Yanzhi Ren, Yingying Chen 0001, Ke Zhang 0022 |
IEEE Trans. Mob. Comput. | 5 |
| 2024 | Reconfigurable Intelligent Surface-Assisted Secret Key Generation in Spatially Correlated ChannelsabstractReconfigurable intelligent surface (RIS) is a disruptive technology to enhance the performance of physical-layer key generation (PKG) thanks to its ability to smartly customize the radio environments. Existing RIS-assisted PKG methods are mainly based on the idealistic assumption of an independent and identically distributed (i.i.d.) channel model at both the base station (BS) and the RIS. However, the i.i.d. model is inaccurate for a typical RIS in an isotropic scattering environment and neglecting the existence of channel spatial correlation would possibly degrade the PKG performance. In this paper, we establish a general spatially correlated channel model and propose a new channel probing framework based on the transmit and the reflective beamforming. We derive a closed-form key generation rate (KGR) expression and formulate an optimization problem, which is solved by using the low-complexity Block Successive Upper-bound Minimization (BSUM) with Mirror-Prox method. Simulation results show that compared to the existing methods based on the i.i.d. fading model, our proposed method achieves about 5 dB transmit power gain when the spacing between two neighboring RIS elements is a quarter of the wavelength. Also, the KGR increases significantly with the number of RIS elements while that increases marginally with the number of BS and user antennas. Lei Hu 0005, Guyue Li, Xuewen Qian, Aiqun Hu, Derrick Wing Kwan Ng |
IEEE Trans. Wirel. Commun. | 2 |
| 2023 | DBE-voting: A Privacy-Preserving and Auditable Blockchain-Based E-Voting SystemabstractBlockchain technology can construct a distributed and trusted ledger, which can be used for electronic voting (E-voting) systems to ensure the security of voting data and improve government credibility. However, existing blockchain-based solutions cannot fully fulfill five core requirements in E-voting, i.e., auditability, privacy, authentication, correctness, and unreusability, which make them unpractical in the reality. In this paper, we propose a Double Blockchain-based E-voting (DBE-voting) system, which consists of a private blockchain and a public blockchain. In the proposed system, the voter information is only recorded in the private blockchain for further auditing and the voting results are recorded in both blockchains. The voter's privacy can be protected in the private blockchain while the voting results can be queried in the public blockchain for verifying the correctness of the election process. Moreover, the ballot recorded in both blockchains is signed with a valid linkable ring signature to ensure authentication and unreusability. We propose an on-chain and off-chain hybrid storage mechanism to ensure the consistency and correctness of voting data in two blockchains. Experimental results demonstrate that the throughput of our system can reach 29 transactions per second when the block size is 512 KB. The security analysis shows that the DBE-voting is the first blockchain-based system that can meet all five requirements simultaneously. Zhonghao Liu, Xinwei Zhang 0002, Laphou Lao, Guyue Li, Bin Xiao 0001 |
ICC | 4 |
| 2023 | RelativeRFF: Multi-Antenna Device Identification in Multipath Propagation ScenariosabstractRadio frequency fingerprinting (RFF) is a promising solution for realizing secure and efficient device authentication. The multipath channel overshadows and disrupts the RFF extraction, which causes difficulties in training new models in the presence of fading. Existing approaches attempt to deal with this challenge by traversing channels through simulated channel models. However, this solution requires a large amount of data for training and it is difficult to guarantee that the training covers all possible channels. To mitigate the multipath channel effect on RFF with less training data, we propose a new method in a multi-antenna system, named Relative-RFF (R-RFF), which utilizes channel state information (CSI) feedback to counteract the multipath channel. The RFF imperfection relation between the different antenna chains of the device is proved to be retained after the counteraction of the multipath channel. Numerical results demonstrate that the proposed R-RFF can achieve an identification accuracy of 95.9% for 30 UEs in Tapped Delay Line channel with a signal-to-noise ratio of 20 dB. Hongyi Luo, Guyue Li, Yuexiu Xing, Junqing Zhang, Aiqun Hu, Xianbin Wang 0001 |
ICC | 2 |
| 2023 | RIS-Assisted Physical-Layer Key Generation with Discrete Phase Shift OptimizationabstractThe artificial electromagnetic characteristics of reconfigurable intelligent surfaces (RIS) offers new opportunities to increase the secret key rate (SKR) in physical-layer key generation (PKG). However, the existing literature has primarily focused on continuous phase shift designs for RIS to enhance the SKR, while in practice the phase shifts are discrete due to hardware implementations. Hence, the extent to which practical RIS with discrete phase shifts can enhance SKR remains uncertain. Moreover, we have observed that existing optimization methods are not directly applicable to RIS with discrete phase shifts and relying solely on the approximation projection algorithm may lead to certain SKR performance degradation. To address these problems, this paper proposes a RIS-assisted PKG model considering the impact of discrete RIS phase shifts. To maximize the SKR by properly designing the RIS phase shifts, we propose an algorithm utilizing linear conic reformulation (LCR) with alternating difference-of-convex (DC) programming and successive convex approximation (SCA). Simulation results unveil that the proposed LCR-DC algorithm has the capability to achieve the SKR close to the optimal solutions. Furthermore, increasing the number of RIS elements or the number of quantization bits for RIS phase shifts enhances SKR but with diminishing returns. It is worth noting that a small number of discrete phase shifts, e.g., 2-3 quantization bits, is generally sufficient to achieve satisfactory SKR performance. Guyue Li, Lei Hu 0005, Aiqun Hu, Derrick Wing Kwan Ng |
VTC Fall | 2 |
| 2023 | Reconfigurable Intelligent Surface-Aided Secret Key Generation in Multi-Cell SystemsabstractPhysical-layer key generation (PKG) exploits the reciprocity and randomness of wireless channels to generate a symmetric key between two legitimate communication ends. However, in multi-cell systems, PKG suffers from severe pilot contamination due to the reuse of pilots in different cells. In this paper, we invoke multiple reconfigurable intelligent surfaces (RISs) for adaptively shaping the environment and enhancing the PKG performance. To this end, we formulate an optimization problem to maximize the weighted sum key rate (WSKR) by jointly optimizing the precoding matrices at the base stations (BSs) and the phase shifts at the RISs. To address the non-convexity of the problem, we adopt an alternating optimization (AO)-based algorithm that divides the joint optimization problem into two subproblems. For the subproblem of precoding matrices, we apply the Lagrangian dual approach based on the Karush-Kuhn-Tucker (KKT) conditions. As for the subproblem of phase shifts, we adopt a projected gradient ascent (PGA) algorithm. Simulation results validate the effectiveness of the proposed scheme, demonstrating significant gains in WSKR. Moreover, compared with a single-RIS case, deploying multiple RISs offer spatial diversity so as to improve the PKG performance of multicell systems. Lei Hu 0005, Chen Sun 0004, Guyue Li, Aiqun Hu, Derrick Wing Kwan Ng |
IEEE Trans. Commun. | 3 |
| 2022 | Joint Transmit and Reflective Beamforming for RIS-assisted Secret Key GenerationabstractReconfigurable intelligent surface (RIS) is a promising technique to enhance the performance of physical-layer key generation (PKG) due to its ability to smartly customize the radio environments. Existing RIS-assisted PKG methods are mainly based on the idealistic assumption of an independent and identically distributed (i.i.d.) channel model at both the transmitter and the RIS. However, the i.i.d. model is inaccurate for a typical RIS in an isotropic scattering environment. Also, neglecting the existence of channel spatial correlation would degrade the PKG performance. In this paper, we establish a general spatially correlated channel model in multi-antenna systems and propose a new PKG framework based on the transmit and the reflective beamforming at the base station (BS) and the RIS. Specifically, we derive a closed-form expression for characterizing the key generation rate (KGR) and obtain a globally optimal solution of the beamformers to maximize the KGR. Furthermore, we analyze the KGR performance difference between the one adopting the assumption of the i.i.d. model and that of the spatially correlated model. It is found that the beamforming designed for the correlated model outperforms that for the i.i.d. model while the KGR gain increases with the channel correlation. Simulation results show that compared to existing methods based on the i.i.d. fading model, our proposed method achieves about 5 dB performance gain when the BS antenna correlation$\rho$is 0.3 and the RIS element spacing is half of the wavelength. Lei Hu 0005, Guyue Li, Xuewen Qian, Derrick Wing Kwan Ng, Aiqun Hu |
GLOBECOM | 2 |
| 2022 | Fast and Secure Key Generation with Channel Obfuscation in Slowly Varying EnvironmentsabstractPhysical-layer secret key generation has emerged as a promising solution for establishing cryptographic keys by leveraging reciprocal and time-varying wireless channels. However, existing approaches suffer from low key generation rates and vulnerabilities under various attacks in slowly varying environments. We propose a new physical-layer secret key generation approach with channel obfuscation, which improves the dynamic property of channel parameters based on random filtering and random antenna scheduling. Our approach makes one party obfuscate the channel to allow the legitimate party to obtain similar dynamic channel parameters, yet prevents a third party from inferring the obfuscation information. Our approach allows more random bits to be extracted from the obfuscated channel parameters by a joint design of the K-L transform and adaptive quantization. Results from a testbed implementation show that our approach, compared to the existing ones that we evaluate, performs the best in generating high entropy bits at a fast rate and is able to resist various attacks in slowly varying environments. Specifically, our approach can achieve a significantly faster secret bit generation rate at roughly 67 bit/pkt, and the key sequences can pass the randomness tests of the NIST test suite. Guyue Li, Haiyu Yang, Junqing Zhang, Hongbo Liu 0002, Aiqun Hu |
INFOCOM | 1 |
| 2022 | Reducing Gas Consumption of Tornado Cash and Other Smart Contracts in EthereumabstractEthereum, the largest blockchain for running smart contracts, has been widely used, especially in financial and cryptocurrency exchange applications. Among them, Tornado Cash is a typical financial application that protects the privacy of users with anonymous transactions. However, users need to pay prohibitively high gas (transaction fees for smart contract calls) for anonymous transactions, which hinders Tornado Cash from wide applications. To address this issue, we introduced a new approach that shifts the high gas-consuming operations on smart contracts to local users. Furthermore, we use zero-knowledge proofs to ensure the operations are properly executed. The smart contract only needs to verify and update the results, which significantly reduces the gas fees of Tornado Cash. To validate our approach, we implemented a prototype and showed that our proposed method could save more than 61% of gas consumption of current operations while maintaining the privacy feature of Tornado Cash. Finally, we discussed further applications and open problems of our approach. Jingyan Yang, Shang Gao 0006, Guyue Li, Rui Song 0010, Bin Xiao 0001 |
TrustCom | 3 |
| 2022 | Physical Layer Encryption Scheme Based on Dynamic Constellation RotationabstractPhysical layer encryption (PLE) has emerged as a promising technique to secure wireless communications. Different from conventional cryptography implemented at higher layers, PLE exploits the randomness of wireless channels to adjust symbol patterns at the physical layer, by which both data and modulation information can be protected. However, existing PLE schemes face challenges of security and robustness in practical usage. In a slowly varying environment, the constellation variation is negligible, which results in the vulnerability of PLE to the differential attack. Moreover, the decryption error rate of PLE is high when the channel reciprocity is not ideal. To tackle these problems, we exploit data randomness to enhance the dynamics of constellation variations between adjacent frames. Then we utilize analog-based encryption instead of digital-based encryption to dynamically rotate constellation, which reduces quantization loss and improves robustness to channel phase errors. Simulation results verify that the proposed scheme can effectively resist the differential attack and provide approximately a 4.5 dB gain when the bit error ratio (BER) is 0.001. Yujie Hou, Guyue Li, Shuping Dang, Lei Hu 0005, Aiqun Hu |
VTC Fall | 2 |
| 2022 | Deep-Learning-Based Physical-Layer Secret Key Generation for FDD SystemsabstractPhysical-layer key generation (PKG) establishes cryptographic keys from highly correlated measurements of wireless channels, which relies on reciprocal channel characteristics between uplink and downlink, is a promising wireless security technique for Internet of Things (IoT). However, it is challenging to extract common features in frequency-division duplexing (FDD) systems as uplink and downlink transmissions operate at different frequency bands whose channel frequency responses are not reciprocal anymore. Existing PKG methods for FDD systems have many limitations, i.e., high overhead and security problems. This article proposes a novel PKG scheme that uses the feature mapping function between different frequency bands obtained by deep learning to make two users generate highly similar channel features in FDD systems. In particular, this is the first time to apply deep learning for PKG in FDD systems. We first prove the existence of the band feature mapping function for a given environment and a feedforward network with a single hidden layer can approximate the mapping function. Then, a key generation neural network (KGNet) is proposed for reciprocal channel feature construction, and a key generation scheme based on the KGNet is also proposed. Numerical results verify the excellent performance of the KGNet-based key generation scheme in terms of randomness, key generation ratio, and key error rate. Besides, the overhead analysis shows that the method proposed in this article can be used for resource-constrained IoT devices in FDD systems. Xinwei Zhang 0002, Guyue Li, Junqing Zhang, Aiqun Hu, Zongyue Hou, Bin Xiao 0001 |
IEEE Internet Things J. | 2 |
| 2022 | On Maximizing the Sum Secret Key Rate for Reconfigurable Intelligent Surface-Assisted Multiuser SystemsabstractChannel reciprocity-based key generation (CRKG) has recently emerged as a new technique to address the problem of key distribution in wireless networks. However, as this approach relies upon the characteristics of fading channels, the corresponding secret key rate may be low when the communication link is blocked. To enhance the applicability of CRKG in harsh propagation scenarios, this paper introduces a novel multiuser key generation scheme, which is referred to as RIS-assisted multiuser key generation (RMK) that leverages the reconfigurable intelligent surface (RIS) technology for appropriately shaping the environment and enhancing the sum secret key rate between an access point and multiple users. In the RMK scheme, an RIS-induced channel, rather than the direct channel, serves as the key source. We derive a general closed-form expression of the secret key rate and optimize the configuration of the RIS to maximize the sum secret key rate over independent and correlated fading channels in the presence of multiple users. In the presence of independent fading, we introduce a low-complexity algorithm based on the Karush-Kuhn-Tucker (KKT) condition. In the presence of correlated fading, the optimization problem is non-convex and challenging to solve. To tackle it, we propose a new optimization algorithm based on the semi-definite relaxation (SDR) and successive convex approximation (SCA) methods. Simulation results demonstrate that the proposed RMK scheme outperforms existing RIS-assisted algorithms and achieves a near-optimal sum secret key rate over independent and correlated fading channels. Guyue Li, Chen Sun 0004, Wei Xu 0001, Marco Di Renzo, Aiqun Hu |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2021 | On the RIS Manipulating Attack and Its Countermeasures in Physical-layer Key GenerationabstractReconfigurable Intelligent Surface (RIS) is a new paradigm that enables the reconfiguration of the wireless environment. Based on this feature, RIS can be employed to facilitate Physical-layer Key Generation (PKG). However, this technique could also be exploited by the attacker to destroy the key generation process via manipulating the channel features at the legitimate user side. Specifically, this paper proposes a new RIS-assisted Manipulating attack (RISM) that reduces the wireless channel reciprocity by rapidly changing the RIS reflection coefficient in the uplink and downlink channel probing step in orthogonal frequency division multiplexing (OFDM) systems. The vulnerability of traditional key generation technology based on channel frequency response (CFR) under this attack is analyzed. Then, we propose a slewing rate detection method based on path separation. The attacked path is removed from the time domain and a flexible quantization method is employed to maximize the Key Generation Rate (KGR). The simulation results show that under RISM attack, when the ratio of the attack path variance to the total path variance is 0.17, the Bit Disagreement Rate (BDR) of the CFR-based method is greater than 0.25, and the KGR is close to zero. In addition, the proposed detection method can successfully detect the attacked path for SNR above 0 dB in the case of 16 rounds of probing and the KGR is 35 bits/channel use at 23.04MHz bandwidth. Lei Hu 0005, Guyue Li, Hongyi Luo, Aiqun Hu |
VTC Fall | 2 |
| 2021 | On the Security of RIS-assisted Manipulating Attack in MISO systemsabstractWith the rapid development of wireless communication, the traditional communication encryption method is not adequate for our needs of high-speed and low latency. As a consequence, Physical Layer-Key Generation (PKG) and Reconfigurable Intelligent Surface (RIS) emerged. The existing researches on the combination of PKG and RIS mainly focus on the randomness increase of the communication environment and the key generation rate under a quasi-static environment. On the other hand, there is little research on the active attack of RIS by eavesdroppers. In this paper, the attack and defense method based on the combination of RIS and PKG is discussed. We propose a random phase attack method derived from the multiple-input single-output (MISO) model and analyze the effectiveness of the attack. To resist the random phase attack under a hypothetical scenario in which RIS is under the control of the attacker, we propose a path separation and path detection defense method according to the Multiple Signal Classification (MUSIC) algorithm. Simulation results show that the Bit Disagreement Rate (BDR) achieves a significant reduction, which proves the effectiveness of the proposed defense method based on path detection and path separation. Hongyi Luo, Guyue Li, Lei Hu 0005 |
VTC Fall | 2 |
| 2021 | Secret Key Generation for FDD Systems Based on Complex-Valued Neural NetworkabstractSecret key generation based on wireless channel reciprocity has received widespread attention. However, in frequency division duplexing (FDD) systems, since the carrier frequencies of the uplink and downlink are different and the channel coefficients are no longer reciprocal, key generation for FDD systems is challenging. In this paper, a Complex-Valued neural Network (CVNet) is proposed to predict the downlink channel and generate reciprocal channel characteristics. Then, based on the trained CVNet, we propose a key generation protocol for FDD systems. Numerical results show that the CVNet achieves better performance in terms of prediction accuracy, bit disagreement rate, and bit generation ratio than a traditional Real-Valued Network (RVNet) under high signal-to-noise ratios. Furthermore, the training parameters required by the CVNet account for only half of that required by the RVNet. Xinwei Zhang 0002, Guyue Li, Zongyue Hou, Aiqun Hu |
VTC Fall | 2 |
| 2021 | Encrypting Wireless Communications on the Fly Using One-Time Pad and Key GenerationabstractThe one-time pad (OTP) secure transmission relies on the random keys to achieve perfect secrecy, while the unpredictable wireless channel is shown to be a good random source. There is very few work of the joint design of OTP and key generation from wireless channels. This article provides a comprehensive and quantitative investigation on secure transmission achieved by OTP and wireless channel randomness. We propose two OTP secure transmission schemes, i.e., identical key-based physical-layer secure transmission (IK-PST) and un-IK-PST (UK-PST). We quantitatively analyze the performance of both schemes and prove that UK-PST outperforms IK-PST. We extend the pairwise schemes to a group of users in networks with star and chain topologies. We implement prototypes of both schemes and evaluate the proposed schemes through both simulations and experiments. The results verify that UK-PST has a higher effective secret transmission rate than that of IK-PST for scenarios with both pairwise and group users. Guyue Li, Zheying Zhang, Junqing Zhang, Aiqun Hu |
IEEE Internet Things J. | 1 |
| 2021 | A Robust Radio-Frequency Fingerprint Extraction Scheme for Practical Device RecognitionabstractRadio-frequency fingerprinting (RFF) exploiting hardware characteristics has been employed for device recognition to enhance the overall security. However, the performance unreliability in long-term experiments, channel fading interference, and unauthorized devices verification are three open problems that restrict the development of RFF recognition. To address these issues, a robust RFF extraction scheme based on three corresponding algorithms is studied. For the first problem, a long-term stacking of repetitive symbols (LSRSs) algorithm is proposed to reduce the acquired signal variance, which contributes to the identification accuracy and long-term stability. For the second issue, we propose an artificial noise adding (ANA) algorithm to enhance the recognition robustness through regularization and channel adaptation. For the third issue, a verification algorithm based on the generative Gaussian probabilistic linear discriminant analysis (GPLDA) model is developed to handle unauthorized devices. Our robust RFF extraction scheme is verified in the experiments with 54 CC2530 ZigBee devices. It enables reliable node identification with the accuracy of 99.50% in the short rang line-of-sight (SLOS) scenarios for signals collected over 18 months, and 95.52% in the extensive multipath fading experiments. The equal error rate (EER) of the verification experiments with six authorized devices versus six unseen unauthorized devices is as low as 0.63%. Xinyu Zhou 0005, Aiqun Hu, Guyue Li, Linning Peng, Yuexiu Xing, Jiabao Yu |
IEEE Internet Things J. | 3 |
| 2021 | Sum Secret Key Rate Maximization for TDD Multi-User Massive MIMO Wireless NetworksabstractPhysical-layer key generation (PKG) based on channel reciprocity has recently emerged as a new technique to establish secret keys between devices. Most works focus on pairwise communication scenarios with single or small-scale antennas. However, the fifth generation (5G) wireless communications employ massive multiple-input multiple-output (MIMO) to support multiple users simultaneously, bringing serious overhead of reciprocal channel acquisition. This paper presents a multi-user secret key generation in massive MIMO wireless networks. We provide a beam domain channel model, in which different elements represent the channel gains from different transmit directions to different receive directions. Based on this channel model, we analyze the secret key rate and derive a closed-form expression under independent channel conditions. To maximize the sum secret key rate, we provide the optimal conditions for the Kronecker product of the precoding and receiving matrices and propose an algorithm to generate these matrices with pilot reuse. The proposed optimization design can significantly reduce the pilot overhead of the reciprocal channel state information acquisition. Furthermore, we analyze the security under the channel correlation between user terminals (UTs), and propose a low overhead multi-user secret key generation with non-overlapping beams between UTs. Simulation results demonstrate the near-optimal performance of the proposed precoding and receiving matrices design and the advantages of the non-overlapping beam allocation. Guyue Li, Chen Sun 0004, Eduard A. Jorswieck, Junqing Zhang, Aiqun Hu, You Chen 0004 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2021 | Robust Key Generation With Hardware Mismatch for Secure MIMO CommunicationsabstractIn practical implementations, physical-layer key generation (PKG) encounters the bottlenecks of imperfect channel reciprocity, nearby attack, and high temporal auto-correlation. Existing One-Band Multiple-Antenna Loop-bAck key generation (OB-MALA) schemes try to address these challenges through establishing bi-directional channels via echoing rotated received signals. However, we find that OB-MALA schemes can be vulnerable to a multiply-divide (MD) attack, as they echo the received signals through the same band with the pilot signals. To overcome this deficiency, we propose a new method, named Two-Band Multiple-Antenna Loop-bAck key generation (TB-MALA), which exploits two separate bands for pilot transmission and echo reception. The TB-MALA is proved to be robust to the imperfect channel reciprocity caused by radio frequency (RF) front-ends and can resist both the nearby attack and the MD attack. It also reduces the auto-correlation of effective channels with the help of a rotation matrix. The secret key rate of TB-MALA is analyzed and the closed-form of a lower bound is derived for the worst case. Numerical results demonstrate that the proposed TB-MALA protects against these attacks and achieves performance comparable to the ideal case with the perfect reciprocity of RF front-ends. It can thus be used to form a robust, fast, and secure key generation in a multiple-input and multiple-output (MIMO) system. Guyue Li, Yinghao Xu 0002, Wei Xu 0001, Eduard A. Jorswieck, Aiqun Hu |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2020 | Beam-Domain Secret Key Generation for Multi-User Massive MIMO NetworksabstractPhysical-layer key generation (PKG) in multi-user massive MIMO networks faces great challenges due to the large length of pilots and the high dimension of channel matrix. To tackle these problems, we propose a novel massive MIMO key generation scheme with pilot reuse based on the beam domain channel model and derive close-form expression of secret key rate. Specifically, we present two algorithms, i.e., beam-domain based channel probing (BCP) algorithm and interference neutralization based multi-user beam allocation (IMBA) algorithm for the purpose of channel dimension reduction and multi-user pilot reuse, respectively. Numerical results verify that the proposed PKG scheme can achieve the secret key rate that approximates the perfect case, and significantly reduce the dimension of the channel estimation and pilot overhead. You Chen 0004, Guyue Li, Chen Sun 0004, Junqing Zhang, Eduard A. Jorswieck, Bin Xiao 0001 |
ICC | 2 |
| 2020 | Design of a Robust Radio-Frequency Fingerprint Identification Scheme for Multimode LFM RadarabstractRadar is an indispensable part of the Internet of Things (IoT). Specific emitter identification is essential to identify the legitimate radars and, more importantly, to reject the malicious radars. Conventional methods rely on pulse parameters that are not capable to identify the specific emitter as two radars may have the same configuration or a malicious radar can perform spoofing attacks. Radio-frequency fingerprint (RFF) is the unique and intrinsic hardware characteristic of devices resulted from hardware imperfection, which can be used as the device identity. This article proposes a robust and reliable radar identification scheme based on the RFF, taking linear frequency modulation (LFM) radar as a case study. This scheme first classifies the operation mode of the pulses, then eliminates the noise effect, and finally identifies the radar emitters based on the transient and modulation-based RFF features. The experimental results verify the effectiveness of our radar identification scheme among three real LFM radars (same model) operating at four modes, each mode with 2000 pulses from each radar. The identification rates of the four modes are all higher than 90% when the signal-to-noise ratio (SNR) is about 5 dB. In addition, mode 3 achieves almost 100% identification accuracy even when the SNR is as low as -10 dB. Yuexiu Xing, Aiqun Hu, Junqing Zhang, Jiabao Yu, Guyue Li, Ting Wang 0029 |
IEEE Internet Things J. | 5 |
| 2019 | An Adaptive Information Reconciliation Protocol for Physical-Layer Based Secret Key GenerationabstractPhysical-layer based secret key generation (SKG) becomes a research focus as it solves key distribution problem which is difficult in traditional cryptographic mechanism. To remove the disagreements caused by imperfect reciprocity of communicating parties, information reconciliation is a critical process in SKG to obtain symmetric keys. Various reconciliation schemes are proposed, e.g. BBBSS, Cascade, BCH code and Turbo code. Reconciliation efficiency is a common evaluation index which takes reconciliation success rate and information leakage rate into account. However, time delay caused by information interaction and computation overhead may affect reconciliation performance under specific scenarios. Therefore, a comprehensive evaluation metric is required to compare existing schemes. Besides, channel condition changes all the time in real mobile communication systems, and most existing reconciliation schemes only work well in certain channel conditions. Hence, a reconciliation scheme which can adapt to time-varying channel condition is required. In this paper, we introduce a novel comprehensive reconciliation efficiency index (CREI) to evaluate existing reconciliation schemes and propose an adaptive information reconciliation scheme selection (AIRSS) protocol to maximize CREI. The simulation results show the superiority of AIRSS and present recommendations of reconciliation scheme selection in different scenarios. Zheying Zhang, Guyue Li, Aiqun Hu |
VTC Spring | 2 |
| 2019 | A Robust Radio Frequency Fingerprint Identification Scheme for LFM Pulse RadarsabstractRadar transmitter identification technology based on pulse descriptor word (PDW) is broadly used in military and civilian applications. However, as the complexity of the electromagnetic environment has increased, radar identification has been challenging. Radio frequency fingerprint (RFF) is an intrinsic hardware characteristic and has been widely employed for device identification. In this paper, we propose a robust RFF identification scheme for linear frequency modulation (LFM) pulse radars. The scheme includes a proposed piecewise curve fitting based denoising (PCFD) algorithm and a hybrid RFF identification algorithm. The PCFD algorithm can reduce the noise of LFM pulses without undermining RFF features. The hybrid RFF identification algorithm extracts both transient-based and modulation-based RFF features. Experimental results demonstrate that the proposed radar identification scheme can achieve a 100% identification accuracy when the SNR is about 0 dB. Yuexiu Xing, Aiqun Hu, Jiabao Yu, Guyue Li, Linning Peng, Fen Zhou 0001 |
WiMob | 4 |
| 2019 | Radio Frequency Fingerprint Identification Based on Denoising AutoencodersabstractRadio Frequency Fingerprinting (RFF) is one of the promising passive authentication approaches for improving the security of the Internet of Things (IoT). However, with the proliferation of low-power IoT devices, it becomes imperative to improve the identification accuracy at low SNR scenarios. To address this problem, this paper proposes a general Denoising AutoEncoder (DAE)-based model for deep learning RFF techniques. Besides, a partially stacking method is designed to appropriately combine the semi-steady and steady-state RFFs of ZigBee devices. The proposed Partially Stacking-based Convolutional DAE (PSC-DAE) aims at reconstructing a high-SNR signal as well as device identification. Experimental results demonstrate that compared to Convolutional Neural Network (CNN), PSCDAE can improve the identification accuracy by 14% to 23.5% at low SNRs (from -10 dB to 5 dB) under Additive White Gaussian Noise (AWGN) corrupted channels. Even at SNR = 10 dB, the identification accuracy is as high as 97.5%. Jiabao Yu, Aiqun Hu, Fen Zhou 0001, Yuexiu Xing, Guyue Li, Linning Peng |
WiMob | 6 |
| 2019 | A Robust RF Fingerprinting Approach Using Multisampling Convolutional Neural NetworkabstractWith the increasing popularity of the Internet of Things (IoT), device identification, and authentication has become a critical security issue. Recently, radio frequency (RF) fingerprint-based identification schemes have attracted wide attention as they extract the inherent characteristics of hardware circuits which is very hard to forge. However, existing RF fingerprint-based approaches face the problems of unstable region of interest (ROI), high-cost feature design, and incomplete automation. To address these problems, this paper proposes a multisampling convolutional neural network (MSCNN) to extract RF fingerprint from the selected ROI for classifying ZigBee devices. A signal-to-noise ratio (SNR) adaptive ROI selection algorithm is also developed to alleviate the effect of semi-steady behavior of ZigBee devices owing to sleep mode switching. The proposed MSCNN uses multiple downsampling transformations for multiscale feature extraction and classification automatically. To validate and evaluate the performance of our proposed method, we design a testbed consisting of one low-cost universal software radio peripheral (USRP) as the receiver and 54 CC2530 devices as targets for identification. Extensive experiments are conducted to demonstrate the feasibility and reliability of MSCNN both in the line-of-sight (LOS) scenarios and non-LOS (NLOS) scenarios. The classification accuracy is as high as 97% under the LOS scenarios around SNR = 30 dB. Our scheme is robust over a wide range of SNRs under the LOS scenarios as well as under the NLOS scenarios. Jiabao Yu, Aiqun Hu, Guyue Li, Linning Peng |
IEEE Internet Things J. | 3 |
| 2019 | An Investigation of Using Loop-Back Mechanism for Channel Reciprocity Enhancement in Secret Key GenerationabstractPhysical layer security key generation exploits unpredictable features from wireless channels to achieve high security, which requires high reciprocity in order to set up symmetric keys between two users. This paper investigates enhancing the channel reciprocity using a loop-back scheme with multiple frequency bands in time-division duplex (TDD) communication systems, in order to mitigate the effect of hardware fingerprint interference and synchronization offset. The scheme is evaluated to be robust to passive eavesdropping and active Man-in-the-Middle attack through both theoretical analyses and practical measurements. A secret key generation protocol is subsequently designed. The performance of the proposed secret key generation method is then evaluated through both numerical simulation and experiments. Results demonstrate that the proposed scheme can effectively mitigate non-reciprocity and outperforms the classical TDD scheme in both key disagreement rate and key generation rate. Linning Peng, Guyue Li, Junqing Zhang, Roger F. Woods, Ming Liu 0010, Aiqun Hu |
IEEE Trans. Mob. Comput. | 2 |
| 2018 | High-Agreement Uncorrelated Secret Key Generation Based on Principal Component Analysis PreprocessingabstractRandom and high-agreement secret key generation from noisy wideband channels is challenging due to the autocorrelation inside the channel samples and compromised cross correlation between channel measurements of two keying parties. This paper studies the signal preprocessing algorithms to establish high-agreement uncorrelated secret key in the presence of channel independent eavesdroppers. We first propose a general mathematical model for various preprocessing schemes, including principal component analysis (PCA), discrete cosine transform (DCT) and wavelet transform (WT). Among preprocessing schemes, PCA is proved to achieve the optimal secret key rate. Next, PCA with common eigenvector has been found to outperform PCA with private eigenvector in terms of an overall consideration of key agreement, information leakage, and computational expense. Then, we propose a system level design of key generation, including quantization, information reconciliation, and privacy amplification. Numerical results verify that the key generation enhanced by PCA with common eigenvector can achieve secret key with high key generation rate, low key error rate, and good randomness. Guyue Li, Aiqun Hu, Junqing Zhang, Linning Peng, Chen Sun 0004, Daming Cao |
IEEE Trans. Commun. | 1 |
| 2017 | Security Analysis of a Novel Artificial Randomness Approach for Fast Key GenerationabstractWireless key generation in slow fading channels is challenging because of the limited channel variation and randomness. This paper proposes a novel artificial randomness (AR) assisted approach for fast key generation in slow fading environments. It integrates user-designed randomness into the channel probing to form a fast-changing combined channel to realize information-theory security. The analytical expressions of secret key capacity are derived. We find that it is possible to improve secret key capacity by introducing AR when legitimate users have a better channel condition than that of eavesdropper. We also find that the improved secret key capacity is proportional to the channel probing number and is bounded by the noise variance and channel condition. Simulation and experimental results show that AR approach can generate secret key effectively in slow fading environments by carefully designing probing numbers. Compared to existing work in literature, the proposed approach does not rely on multiple antennas or extra helpers, and it can be applied in both single antenna and multi-antenna systems. Guyue Li, Aiqun Hu, Junqing Zhang, Bin Xiao 0001 |
GLOBECOM | 1 |
| 2015 | A Novel Transform for Secret Key Generation in Time-Varying TDD Channel under Hardware Fingerprint DeviationabstractChannel reciprocity can be used for providing sufficient key generation in time division duplex (TDD) system. However, in practice, its application is limited by the hardware fingerprint deviation (HFD) problem. In this paper, we propose a novel real-time transform that can cope with this problem in time- varying TDD channel without any calibration period or feedback loops. More specifically, a log-domain differential (LDD) transform is developed and the resulting performance is analyzed in terms of mean square error (MSE) between receptions at Alice and Bob and effective signal to error ratio (ESER). The analysis shows that the proposed transform can eliminate the impact of HFD, yet its performance is very sensitive to channel noise and moving speed. For this purpose, an enhanced version is proposed including an efficient noise reduction technique and the impact of mobility on parameter design is also analyzed. Numerical results show that the proposed LDD advanced transform provides performance comparable to the ideal case without HFD, and thus, can be used to form a simple, practical and flexible solution for secret key generation in time-varying TDD channel. Guyue Li, Aiqun Hu, Yaning Zou, Linning Peng, Mikko Valkama |
VTC Fall | 1 |
| 2014 | Deterministic distributed rendezvous algorithms for multi-radio cognitive radio networksabstractRendezvous is a fundamental process in constructing Cognitive Radio Networks (CRNs), through which the user can communicate with its neighbors by establishing a link on some licensed frequency band (channel). Most of the existing elegant rendezvous algorithms assume each user is equipped with a single radio. Nowadays the multi-radio cognitive radio architecture, where each user can access k ≥ 2 channels at the same time, has become a reality. In this paper, we study the rendezvous problem in multi-radio CRN to see whether and to what extent the multi-radio capability can improve the rendezvous performance. To begin with, we propose a family of deterministic distributed algorithms for two special situations when k=2 and k=O(√n), where n is the number of all channels. These algorithms show that the maximum time to rendezvous (MTTR) can be reduced (largely) in multi-radio CRN. Then we derive a lower bound of MTTR as Ω({|Vi||Vj|}/k2) for arbitrary k (Vi, Vj represents two users' available channel sets) and present a distributed algorithm to guarantee rendezvous in O({|Vi||Vj|}/k2) time slots, which meets the lower bound. Extensive simulations are conducted to corroborate our theoretical analyses. Guyue Li, Zhaoquan Gu, Xiao Lin 0002, Haosen Pu, Qiang-Sheng Hua |
MSWiM | 1 |
| 2013 | Monte Carlo Based Test Pattern Generation for Hardware Trojan DetectionabstractHardware Trojan (HT) has emerged as a serious security threat to many critical systems. HT detection techniques are badly needed to ensure trust in hardware systems. In related works, only a fixed large number of random patterns are applied, with no regard to the pattern's effect to HT detection result. The variations in target signal caused by different sets of input vectors are not addressed. There is also no guarantee that the vector set used is long enough to be representative or whether it is already over testing. To solve these problems, we propose a Monte Carlo based test pattern generation method for HT detection. The proposed approach offers a solution by sampling the detection until the standard deviation of the measured signal over all the samples is within certain accuracy. This gives us the confidence in the signal measurement without having to do exhaustive test. Moreover, it is conducive to simplify test vector sets. Experiment results on ISCAS89 benchmarks showed that the proposed approach usually needs much less time than that required by exhaustive test to achieve reliable results and desired accuracy. Mingfu Xue, Aiqun Hu, Guyue Li |
DASC | 4 |