Dutliff Boshoff

dblp:296/4884 · DBLP profile ↗
← Back
11ranked-venue papers
5as first author
11since 2021 · last 2026
0000-0002-9513-5981ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 5 · 2 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 first-author · 3 since 2021Computer networks · 2 · 2 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Secure and Reliable Indoor Ranging: An Analysis of Industry Protocols, Attacks, and Defences
abstract
Secure indoor ranging is a critical component of modern industrial systems, with applications in access control, contactless payments, and industrial automation. This article presents the first comprehensive survey focusing exclusively on secure-ranging protocols for Bluetooth, ultrawideband (UWB), and Wi-Fi. Unlike localization, which relies on multiple anchors, ranging involves only two devices; therefore, popular attack detection methods based on multianchor data do not generalize to secure ranging. This article begins by detailing industry-standard protocols such as IEEE 802.15.4a for UWB, Bluetooth, and IEEE 802.11 for Wi-Fi, followed by an analysis of their vulnerabilities and distance manipulation attacks. Common attack strategies, including overshadow, early path injection, and relay attacks, are explored. To mitigate these threats, we review countermeasures grouped into two main categories: randomization and channel integrity verification, which incorporate techniques from machine learning, threshold-based anomaly detection, and cryptography. Finally, we highlight cross-technology insights, discuss lessons learned, and propose future research directions to address unresolved challenges in indoor-ranging security.
Dutliff Boshoff, Raphael E. Nkrow, Bruno J. Silva, Gerhard P. Hancke 0002
IEEE Trans. Ind. Informatics1
2025 UWB-based Physical Layer Key Sharing for BAN Devices
abstract
The increasing commercial viability of body area network (BAN) devices has expanded their applications beyond smartwatches and smartphones to include wearables for industrial safety, healthcare monitoring, and augmented reality systems. Secure communication between these devices remains a challenge, as traditional cryptographic key exchange protocols impose significant computational and power constraints. Physically Derived Symmetric Key (PDSK) generation offers a lightweight alternative by leveraging the shared wireless channel characteristics to establish encryption keys without prior trust. Recent studies have demonstrated the effectiveness of PDSK in ultra-wideband (UWB) systems, as UWB’s high-resolution channel measurements capture high-entropy yet highly correlated signal variations at different devices. In this work, we evaluate the feasibility of UWB-based PDSK in BAN wearable devices. Our results show that secret keys can be reliably generated, achieving a bit agreement rate (BAR) of 84.14% and a key success rate (KSR) of 92.7% while generating 240-bit keys in 0.35s. We further analyse key generation performance across different wearable placements and movement conditions, demonstrating that UWB-based PDSK is a viable and practical solution for secure communication in BAN applications.
Dutliff Boshoff, Morgana Mo Zhou, Raphael E. Nkrow, Bruno J. Silva, Gerhard P. Hancke 0002
INDIN1
2025 A Residual Weighting Approach for NLOS Mitigation in Complex Environments
abstract
NLOS and multipath propagation are the main hurdles for accurate localization with time-based localization systems. Over the years, researchers have proposed myriad approaches to mitigate the effects of Non-Line-of-Sight (NLOS) and multipath propagation for accurate indoor localization. Residual Weighting (Rwgh) is a widely used technique for NLOS mitigation in literature. This is because it does not require expensive site surveys or statistical information of the channel. Also, position estimation is possible even if all the nodes (anchors) are in NLOS. We observed that with Ultra-Wideband (UWB), the ranging results in Line-Of-Sight conditions are stable compared to NLOS and multipath ranging scenarios. Based on this, we propose a Rwgh approach by exploring the stability of the range measurements obtained during the localization phase. The stability of the range measurement gives an indication of the veracity of the introduced residuals, which is then weighted to mitigate the NLOS effects directly during localization. We test the performance of the proposed approach with data collected from two distinct real-world environments with heavy NLOS and multipath presence instead of simulated data as used in the preponderance of Rwgh-based approaches.
Raphael E. Nkrow, Dutliff Boshoff, Bruno J. Silva, Gerhard P. Hancke 0002
INDIN2
2025 A classifications framework for continuous biometric authentication (2018-2024)
Dutliff Boshoff, Gerhard P. Hancke 0002
Comput. Secur.1
2025 AdaLOS: A Domain Adaptive UWB NLOS Identification for Dynamic Settings
abstract
A major challenge to Ultra-Wideband (UWB) positioning, especially in indoor environments, is the prevalent presence of Non-Line-Of-Sight (NLOS) and multipath propagations, degrading localization performance. Moreover, indoor settings tend to constantly change, making it difficult to characterize NLOS signals each time these changes occur. Promising approaches have been proposed to identify NLOS signals before localization; however, their performance is limited to the specific environment where measurements were carried out and cannot be extended to new or different environments. This can be attributed to feature discrepancies causing domain shifts and distribution divergence, owing to differences in environments captured by the Channel Impulse Response (CIR) waveforms. In this paper, we propose a domain Adaptive NLOS (AdaLOS) identification framework for UWB positioning systems. First, adaptation knowledge is obtained to align the source and target domains’ CIRs to mitigate the domain shift problem via cross-domain mappings. The distribution gap of the CIRs is further reduced by minimizing the marginal and conditional distribution divergence between the two domains (environments) by employing the Maximum Mean Discrepancy (MMD) criterion. A joint optimization procedure is then formulated to minimize the domain shift, marginal, and conditional distribution differences between CIRs from the two domains simultaneously. After minimizing the domain difference, Transformed Representative Features (TRF) of the source and target domains are obtained to train a domain-invariant classifier. We perform extensive simulations with CIR information collected from four distinct indoor environments characterized by different relative permittivity, signal distortions, noise, etc. AdaLOS is effective in adapting to new, distinct environments and significantly outperforms state-of-the-art works for NLOS identification.
Raphael E. Nkrow, Dutliff Boshoff, Bruno J. Silva, Gerhard P. Hancke 0002
IEEE Internet Things J.2
2025 UWB Physical Layer Key Sharing Using the Frequency Domain CIR Magnitude
abstract
Physical layer key sharing has become a popular topic in today's literature, as it could provide an alternative to computationally expensive key-sharing protocols. Its importance is emphasized by several resource-constrained, battery-powered autonomous robots, and personal devices that must communicate within modern-day industrial complexes. Physical layer key sharing has been explored using temporally and spatially variant characteristics of signals to produce the same secret keys at different devices. In this paper, we propose a novel method for ultra-wideband (UWB)-based physical layer key sharing, leveraging an off-the-shelf plug-and-play UWB module and utilizing the frequency domain of the Channel Impulse Response (CIR) magnitude. The frequency domain effectively aligns and denoises CIR samples, increasing the spatial and temporal uniqueness of channel characteristics. In turn, our approach offers the advantage of creating high-entropy keys with a 92% success rate. Our paper is the first to examine employing an UWB module for key sharing under different dynamic scenarios. Finally, our system maintains a higher level of security against several types of attackers compared to standard CIR methods.
Dutliff Boshoff, Morgana Mo Zhou, Raphael E. Nkrow, Bruno J. Silva, Gerhard P. Hancke 0002
IEEE Trans. Ind. Informatics1
2024 Transfer Learning-Based NLOS Identification for UWB in Dynamic Obstructed Settings
abstract
Positioning with ultrawideband (UWB) is prominent among industrial localization systems, due to its high-range resolution attributes and lower cost. However, one notable challenge with UWB positioning in industrial environments is the prevalent presence of nonline-of-sight (NLOS) components or signals that degrade localization performance drastically. Coupled with this, industrial settings tend to constantly change making NLOS signals challenging to characterize each time these changes occur. Recently, promising approaches have been proposed to identify NLOS components, however their performances are limited to the specific environment where measurements were performed. Their performance cannot be extended to other unknown environments due to the distribution divergence problem, owing to differences in environments captured by the channel impulse response (CIR) waveforms. This therefore requires laborious processes of data collection and training environment-specific models for NLOS identification. In this article, we propose a robust transfer learning-based NLOS identification approach, which harnesses transition information via cross-domain mappings from both source and target domains, to construct representative homogeneous features of both domains. The representative homogeneous features capture discriminative information of both domains, while reducing the distribution divergence between the domains, making it easy to classify LOS and NLOS components from both environments together. To test the robustness of our approach, we perform extensive simulations with CIR data collected from two distinct environments—“hard NLOS” (characterized by high relative permittivity of surrounding objects, e.g., thick concrete walls, metallic objects, etc.) and “soft NLOS” (characterized by low relative permittivity of surrounding objects, e.g., plasterboard walls). Our proposed approach is not just effective in transferring knowledge between distinct environments, but significantly outperforms state-of-the-art works to NLOS identification in UWB positioning networks, while reducing the laborious process of data collection in the target domain.
Raphael E. Nkrow, Bruno J. Silva, Dutliff Boshoff, Gerhard P. Hancke 0002
IEEE Trans. Ind. Informatics3
2023 Knock-to-Enter Authentication: A Rhythm-Based Smartphone Authentication Mechanism
abstract
With 2-factor authentication practices becoming ever more popular, the need for developing new authentication procedures is gaining ever more traction. Rhythm-based gesture authentication appears to be a promising area of research as it encompasses two of the three main authenticator factors: something you know(the chosen rhythm) and something you are(how you enter that rhythm). Rhythm-based authentication approaches have mostly been achieved using touchscreen functions. But accelerometers and gyroscope sensors have the unique ability to capture the small differences in how users enter a set rhythm and how they hold their phone. Additionally, these sensors do not limit our approach to mobile devices with mobile screens but can be expanded to headsets, smart glasses, and screen-less fitness trackers. It also circumvents issues like wearing face masks and gloves. All 12 of our participants were asked to input the same tapping rhythm consisting of 7 taps, 50 times, totaling 600 samples to be used for trial and testing. If our system is able to perform well under these conditions it proves that even an attacker who knows your rhythm, wouldn't be able to access your device. This could be equated to you telling someone your password, but them still not being able to gain access to your phone. Our models were able to achieve an authentication accuracy of 99.65% only using 10 valid samples for training and an identification accuracy of 99.17 %.
Dutliff Boshoff, Raphael E. Nkrow, Gerhard P. Hancke 0002
IECON1
2023 UWB-Based NLOS Identification and Mitigation: A Performance Evaluation in Dynamic Settings
abstract
In the fourth industrial revolution (Industry 4.0), robotics and autonomous navigational systems are essential for smart agriculture. Industrial smart agriculture relies heavily on autonomous navigational systems, which have important uses in unmanned farms, industrial supply chains, etc. For effective navigation of autonomous robotic systems in industrial settings, indoor-based positioning and navigation technologies play key roles. However, positioning performance is severely impacted by the abundance of Non-Line-Of-Sight (NLOS) components due to the dynamic nature of industrial environments. Different approaches have been proposed in literature for identifying and mitigating NLOS components in UWB positioning systems. However, the performance of these proposed approaches on par in multiple distinct environments is unknown. In this paper, we experimentally investigate and compare the performance of recent UWB-based state-of-the-art approaches to NLOS identification and mitigation on par, in distinct and dynamic obstructed settings to ascertain two key insights: i) how the performance of existing approaches change based on the environment type; ii) the impact of the environment type on NLOS identification and mitigation.
Raphael E. Nkrow, Bruno J. Silva, Dutliff Boshoff, Gerhard P. Hancke 0002
IECON3
2022 Feasibility of using Gyroscope to Derive Keys for Mobile Phone and Smart Wearable
abstract
In the past few years, smart healthcare has become a popular topic. Many users wear smart devices to monitor their health conditions. To provide information for health analysis, many sensors are installed in smart wearable devices to collect personal health data. Due to the limitation of space and computational power, private health data is not processed locally. Instead, it is usually sent to a mobile phone for further analysis, which required wireless data exchange between the mobile phone and smart wearable devices. To protect a user’s privacy, it is important to guarantee the connection security of the devices’ network as well as prevent information leakage. A possible method to secure the data exchange process is symmetric encryption. In this paper, we investigate the feasibility of symmetric key generation for communication between a mobile phone and smart wearable device using angular velocity data collected by gyroscopes as data source. We collected over 1000 samples of gait data, totally more than 20000 seconds of movements, using two industrial products including a smart watch and mobile phone placed on wrist and in pocket respectively. We successfully generated the same random number for mobile phone and smart wearable device in 78% samples.
Yuanzhen Liu, Dutliff Boshoff, Gerhard P. Hancke 0002
INDIN2
2021 Privacy-Preserving Group Authentication for RFID Tags Using Bit-Collision Patterns
abstract
When authenticating a group of radio-frequency identification tags, a common method is to authenticate each tag with some challenge-response exchanges. However, sequentially authenticating individual tags one by one might not be desirable, especially when considering that a reader often has to deal with multiple tags within a limited period, since it will incur long scanning time and heavy communication costs. To address these problems, we put forward a novel efficient group authentication protocol, where a group of tags can be authenticated simultaneously with only one challenge and one response. The protocol is built on a newly designed symmetric key-based algorithm and the bit-collision pattern technique, so that authentication responses transmitted by multiple tags in a group at the same time will result in a verifiable bit-collision pattern that represents the authentication response for the entire group. The proposed approach can significantly reduce the authentication time and communication cost in the sense that the verifier can authenticate the entire group within a period that is comparable to the time taken to perform a single-tag authentication and requires only one challenge. In addition, we extend our protocol to support the privacy-preserving property, which prevents the tagged items from being tracked by illegitimate parties. A thorough security analysis shows that the proposed protocol can resist common practical attacks and experimental results show that the protocol is very efficient in terms of time and communication costs. We also discuss important practical aspects that should be considered when implementing these protocols.
Anjia Yang, Dutliff Boshoff, Qiao Hu 0005, Gerhard P. Hancke 0002, Xizhao Luo, Jian Weng 0001, Keith Mayes, Konstantinos Markantonakis
IEEE Internet Things J.2