ConceptioArchivearXiv CS
arXiv CSopen access

When to Use Wireless Challenge-Response Physical Layer Authentication: Design of a Measurable Guideline for OFDM

2026 · arxiv_cs
arXiv CS · Papers · License: Open Access · 2026
Open Source ↗Direct PDF ↓
distributedsystemsinternetnetworkingprotocols
networking, internet, protocols, distributed systems

1

When to Use Wireless Challenge-Response Physical Layer Authentication: Design of a Measurable Guideline for OFDM

arXiv:2605.06750v1 [cs.NI] 7 May 2026

Haiyun Liu, Student Member, IEEE, Shangqing Zhao, Member, IEEE, Yao Liu, Senior Member, IEEE, and Zhuo Lu, Senior Member, IEEE

Abstract—The security of wireless challenge-response Physical Layer Authentication (PLA) based on Orthogonal Frequency Division Multiplexing (OFDM) relies on a sufficiently random fading channel condition, which is commonly assumed in existing studies. However, in practical scenarios, such a condition is not always guaranteed and the responses of OFDM subchannels may exhibit correlation. Consequently, ensuring the security of such PLA systems remains an unsolved problem. In this paper, we propose a novel adversary model, called Maximum Differential Likelihood Generator (MDLG), which exploits the weak correlation property in practical wireless channel to launch effective attacks against PLA. Based on this model, we create a measurable guideline using randomness testing to decide when we can in fact use PLA in a practical wireless channel condition. Extensive real-world experiments validate the effectiveness of the MDLG attack and demonstrate how the proposed guideline can help protect the security of PLA. Index Terms—Physical layer authentication (PLA); Adversary modeling; Randomness testing; Security guideline.

I. I NTRODUCTION Physical Layer Authentication (PLA) is a widely adopted technique for verifying transmitter identities in wireless systems [1]. Compared with conventional cryptographic approaches, PLA verifies device legitimacy by leveraging inherent physical-layer features or wireless channel characteristics [2], offering a lightweight alternative that is better suited for resource-constrained wireless systems such as Internet of Things (IoT) and Radio Frequency Identification (RFID) systems [3]–[5]. In a commonly used PLA scheme [2], [6]– [12], two legitimate users, Alice and Bob, securely verify each other’s identity by combining a shared secret key with the wireless channel response between them. An adversary, Eve, would face a significant challenge in attempting to recover the secret key, as she cannot access the random channel between Alice and Bob. The security of wireless PLA relies on sufficiently random fading conditions. As a result, many existing studies [13]– [15] have pointed out that the wireless PLA designs should be used in rich scattering environments. However, this is not a well-defined standard. A practical wireless fading environment Haiyun Liu and Yao Liu are with the Bellini College of Artificial Intelligence, Cybersecurity and Computing, University of South Florida, Tampa, FL 33620 USA (e-mail: [email protected]; [email protected]). Shangqing Zhao is with the School of Computer Science, University of Oklahoma, OK 73019 USA (e-mail: [email protected]). Zhuo Lu is with the Department of Electrical Engineering, University of South Florida, Tampa, FL 33620 USA (e-mail: [email protected]).

may not be random as assumed in a design, which offers a potential opportunity for the adversary Eve to crack the secret key or compromise the PLA between Alice and Bob. A clear, measurable guideline has yet been established to answer when or under what conditions we can securely use wireless PLA. In this paper, we aim to fill a critical gap between existing research efforts for wireless PLA and the practical issue of its usability: when should Alice and Bob use the PLA? When the wireless subchannels is not quite varying, a PLA design presuming that the channel is sufficiently random and hiding the key behind the channel randomness would fail. But how can the attacker Eve compromise the design under such a condition? It is necessary to design a formal adversary model for Eve that leverages the correlated channel responses to launch an attack. We propose a novel attack model called the Maximum Differential Likelihood Generator (MDLG), which leverages the correlation in wireless channel responses to guess what Alice and Bob’s secret key would be given the observation of their signals received at Eve. We formally derive the attack success probability of the MDLG attack and define the security strength that a PLA design can achieve under a wireless channel condition. Under the MDLG attack model, we should not use wireless PLA when the wireless channel is not sufficiently random to achieve a target security strength. Therefore, the question of when to use such an PLA design depends on whether the wireless channel quality meets the target security strength. This means we need to evaluate the channel to determine when it is random enough to support PLA. As a result, we propose to use randomness tests [16] to evaluate the channel responses and create a design guideline of rejecting the use of PLA when the predicted attack success probability under MDLG is higher than a target security strength (i.e., the maximally allowable attack success probability for a design). To the best of our knowledge, the proposed MDLG model is the first adversary model for formal security analysis in wireless PLA. The proposed design guideline leverages randomness testing to determine when the wireless channel can be securely utilized for PLA and when it cannot. Our work offers important and complementary insights in contrast to existing studies [6], [11], [17]–[23] that primarily concentrate on designing technical procedures of PLA. We conduct extensive real-world experiments to show that our guideline can provide the security guarantee in PLA by using commodity WiFi devices Atheros AR5822/AR9580

2

chipsets and TP-Link WDR4300 AP. The experimental results demonstrate that (i) MDLG is a powerful attack with high attack success probabilities against PLA in practical scenarios, and (ii) by using our design guideline, PLA achieves a highlevel security strength under different (even defective) channel conditions. In summary, the main contributions of this paper are as follows. 1) We introduce a formal adversary model MDLG to formalize the security analysis and evaluation of PLA under different wireless channels. 2) We propose a new design guideline to outline when the random channel can indeed support a target security strength goal and how to maximize the efficiency of using PLA given a security requirement. 3) We use extensive experiments in real-world environments to show our design guideline guarantees the security strength of PLA. The rest of this paper is organized as follows: Section II introduces the background of PLA and our design motivation. Section III presents the detailed MDLG adversary strategy. Section IV proposes the defense guideline for security guarantee. Section V shows the results of real-world experiments. Section VI summarizes related works, followed by the conclusion in Section VII.

shared key 𝑠

challenge signal 𝑆𝐴

Alice

𝑅A

𝑅𝐵 wireless channel ℎ response signal 𝑆𝐵

Bob

Fig. 1: Challenge-response PLA scheme. where βl is a random transmit phase on the l-th subcarrier. This signal will go through the wireless channel with responses denoted as h = [a0 ejθ0 , . . . , aL−1 ejθL−1 ],

(2)

where al is the amplitude response and θl is the phase shift on subcarrier l. Then, Bob’s received signal is h i RB = a0 ej(θ0 +β0 ) , ..., aL−1 ej(θL−1 +βL−1 ) . (3) To send a response signal, Bob first uniformly separates the secret key s into L sub-keys denoted as s0 , . . . , sL−1 , then uses a one-one mapping function M to map each sub-key sl to phase ϕl (l ∈ {0, ..., L − 1}); i.e.,

II. BACKGROUND , M ODELING AND M OTIVATION In this section, we first introduce the background of wireless key-based challenge-response PLA between two users Alice and Bob. Then, we explain why this PLA scheme can ensure security. Finally, we outline a potential vulnerability and introduce our design motivation.

We consider a typical Orthogonal Frequency Division Multiplexing (OFDM) communication system between Alice and Bob as OFDM has been widely adopted in today’s wireless networking and is commonly used in existing PLA designs [24]–[27]. Assume that Alice and Bob use L OFDM subcarriers (or subchannels) for communication and they pre-share a binary sequence unknown to others as their secret key s that consists of S bits. Fig. 1 shows a basic outline of the challenge-response PLA scheme. The PLA process involves four steps [2], [6]–[8], [12], [17]: 1) Alice sends a random challenge signal SA to start the PLA; 2) SA goes through the channel and Bob receives it as RB ; 3) Bob generates his response signal SB based on RB and the shared key s; 4) the response signal SB travels through the channel and is received by Alice as RA , based on which Alice verifies Bob. Specifically, to initiate the PLA, Alice first sends Bob a challenge signal [17], which can be represented as a frequency domain vector as (1)

(4)

where Φ is the set of all possible mapped phases (e.g., Φ = {0, π} in a binary mapping with bits 0 and 1 mapped to phases 0 and π, respectively). All the ϕl values form a key-mapped phase sequence, denoted as ϕ = [ϕ0 , . . . , ϕL−1 ].

A. Basics in Physical Layer Authentication

SA = [ejβ0 , ..., ejβL−1 ],

ϕl = M (sl ) ∈ Φ.

(5)

Next, Bob negates the phases of RB in (3) and adds phase sequence ϕ to obtain the response signal SB as h i SB = a0 ej(ϕ0 −(θ0 +β0 )) , ..., aL−1 ej(ϕL−1 −(θL−1 +βL−1 )) , (6) which is then transmitted by Bob to Alice. Since the duration of the challenge-response procedure is typically within the channel coherence time, the wireless channel can be considered time-invariant during this period. Under such conditions, channel reciprocity holds, and Alice’s received signal is h i RA = a0 2 ej(ϕ0 −β0 ) , ..., aL−1 2 ej(ϕL−1 −βL−1 ) . (7) Since the phases of SA (i.e., [β0 , . . . , βL−1 ]) and the keymapped phases (i.e., [ϕ0 , . . . , ϕL−1 ]) are all known to Alice, she can pre-compute an expected phase of the response signal received on subcarrier l as (ϕl − βl ). Then, she compares the expected phase with the actual phase received in (7) on each subcarrier. If all phases match, Alice can verify that the response signal was indeed sent by the legitimate user Bob.

3

wireless channel ℎ′

Alice

R𝐴𝐸

wireless channel ℎ′′

Bob

R 𝐵𝐸

h = [a0 ejθ0 , ..., aL−1 ejθL−1 ],

(8) ′

Because [θ0 , ..., θL−1 ] is known to Eve, she can extract [β0 , . . . , βL−1 ] from her received signal RAE . Similarly, denote the channel response between Bob and Eve as ′′

′′

′′

′′

′′

h = [a0 ejθ0 , ..., aL−1 ejθL−1 ],

(10) ′′

′′

where al is the amplitude response and ejθl is the phase response on subcarrier l. Bob’s response signal at Eve RBE can be represented as   h ′′ ′′ j ϕ −(θ +β )+θ 0 0 0 0 RBE = a0 a0 e ,  i (11) ′′ ′′ j ϕ −(θ +β )+θ ..., aL−1 aL−1 e L−1 L−1 L−1 L−1 . ′′

4000

10

20

30

′′

Since [θ0 , ..., θL−1 ] and [β0 , . . . , βL−1 ] are known to Eve, the best phase information she can get by comparing the phases between (9) and (11) is z = [z1 , . . . , zL−1 ] = [ϕ0 − θ0 , . . . , ϕL−1 − θL−1 ].

40

50

0 0 0.1 0.2 0.3 0.4 0.5 0.6 0.7 0.8 0.9

Fig. 3: Phase response of sub- Fig. 4: Correlation coefficient between channel responses. carriers.

where al is the amplitude response and ejθl is the phase response on subcarrier l. Then, the signal received by Eve from Alice is h ′ i ′ ′ ′ (9) RAE = a0 ej(θ0 +β0 ) , ..., aL−1 ej(θL−1 +βL−1 ) . ′

6000

Subcarrier

8000

2000

We consider that the eavesdropper Eve can observe the entire PLA process between Alice and Bob, as illustrated in Fig. 2. We assume that Eve has full knowledge of their communication setup (e.g., number of subcarriers, carrier frequencies, communication bandwidth, and the key-phase mapping function M ), and is capable of accurately estimating the channel responses between herself and the legitimate users (i.e., Alice or Bob). Given a possible key candidate s′ , Alice can verify whether s′ is indeed the secret key used by Alice and Bob. However, Eve does not have access to the channel response between Alice and Bob. Eve’s objective is to obtain Alice and Bob’s key s based on Alice’s challenge signal SA and Bob’s response signal SB . When Alice sends the challenge signal SA to Bob, Eve can also receive this as RAE . Denote channel response between Alice and Eve as ′

10000

0

-4

B. Assumptions and Modeling for Attacker Eve

12000

-2

Fig. 2: What Eve can observe from Alice and Bob.

14000

Signal 3 Signal 4

2

Eve response signal 𝑆𝐵

Signal 1 Signal 2

4

Phase

challenge signal 𝑆𝐴

(12)

As Eve lacks access to the channel between Alice and Bob, she has no knowledge of [θ0 , . . . , θL−1 ]. Most existing studies

[28]–[32] implicitly assume that θ0 , . . ., θL−1 are independently random due to scatter-rich wireless environments. Under such an assumption, there is no way for Eve to obtain Alice and Bob’s key-mapped ϕ = [ϕ0 , . . . , ϕL−1 ] by only obtaining z in (12). C. Potential Vulnerability and Attack Design Motivation It is worth noting that the assumption that the channel responses in rich-scattered environments are independent is commonly used for analysis and evaluation of communication performance, rather than security modeling [33]. In a realworld scenario, adjacent OFDM subchannel responses can show a correlation property, especially when the subcarrier spacing is smaller than the coherence bandwidth [34]. This is because practical wireless environments inherently involve multipath propagation, which leads to a time-domain delay spread and hence a corresponding coherence bandwidth. Meanwhile, to mitigate inter-symbol interference (ISI), modern OFDM systems are typically designed with a subcarrier spacing much smaller than the coherence bandwidth. Consequently, adjacent subcarriers often lie within the same coherence bandwidth and thus experience highly similar amplitude and phase fading. To illustrate this correlation intuitively, we conducted an indoor OFDM experiment with a 20MHz bandwidth and 56 subcarriers. As shown in Fig. 3, for the four different signals, the phase responses of adjacent OFDM subchannels do not differ significantly and the overall curves are relatively smooth. Specifically, the phase difference between two adjacent subcarriers is approximately π8 , indicating a non-negligible correlation between their channel responses. By calculating the correlation between adjacent subchannel responses and summarizing the results in Fig. 4, it can be seen that the distribution of the correlation coefficients is similar to a normal distribution, with a mean of approximately 0.35. Due to the weak correlation property observed in practice, we aim to investigate how Eve can extract useful information about the secret key s from the adjacent subcarrier responses during Alice and Bob’s PLA process. III. A DVERSARY S TRATEGY: T HE MDLG ATTACK In this section, we will introduce a new adversary model for Eve to attack the PLA (i.e., aiming to infer Alice and Bob’s secret key s based on Eve’s observed signals). First, we explain how Eve can use her observations to create a potential attack. Then, we propose the MDLG attack strategy and detail the design. Finally, we formalize the attack model and analyze its success probability.

4

A. Leverages Eve’s Observations Under Ideal Scenario From (5) and (12), we know that the key-mapped phase sequence is ϕ = [ϕ0 , . . . , ϕL−1 ] and Eve’s best information inferred from Alice’s challenge signal (9) and Bob’s response signal (11) is z = [ϕ0 − θ0 , . . . , ϕL−1 − θL−1 ] in (12). We let Eve look at the difference between adjacent elements in z. In particular, for any l ∈ {0, ..., L − 2}, (zl+1 − zl ) = (ϕl+1 − ϕl ) − (θl+1 − θl ).

(13)

We first consider an ideal scenario for Eve, where Alice’s and Bob’s OFDM signals both go through flat-fading, noise-free environments [35] (i.e., the correlation coefficient between any pair of OFDM subchannels is 1). In this case, it is clear from (13) that (θl+1 − θl ) = 0 and Eve can further obtain ϕl+1 − ϕl = zl+1 − zl .

(14)

This means Eve can know the difference between any pair of adjacent elements in ϕ, i.e., (ϕ1 − ϕ0 ), ..., (ϕL−1 − ϕL−2 ). If ϕ0 is determined, Eve can in turn obtain the values of ϕ1 , ϕ2 , ..., ϕL−1 one by one as follows: ϕ1 = ϕ0 + (ϕ1 − ϕ0 ), ϕ2 = ϕ1 + (ϕ2 − ϕ1 ), .. .

(15)

ϕL−1 = ϕL−2 + (ϕL−1 − ϕL−2 ). Then, Eve can reconstruct ϕ, and by reversing the key-phase mapping function M in (4), she can eventually determine Alice and Bob’s shared secret key s. More formally, define two differential phase sequences ∆z = [(z1 − z0 ), ..., (zL−1 − zL−2 )]

(16)

This suggests that ∆z can still serve as a reference for estimating ∆ϕ , particularly when the correlation between adjacent subcarriers is strong. This offset decreases as the correlation increases, and approaches zero when the correlation coefficient reaches 1. In this case, the scenario becomes equivalent to the ideal case described in Section III-A. As shown in (18), finding the true key s involves converting a phase sequence into a potential key bit sequence determined by the mapping function M in (4). We first consider M as a binary mapping function, which is commonly used in existing studies [17], [36], [37], to describe the intuitive basic attack design. Without loss of generality, assume that M maps bits 0 and 1 to phases 0 and π, respectively. Under the binary mapping, the bit length S of secret key s is equal to the number of subcarriers L. Based on (13), each phase in ∆z generally does not take a value of exactly 0 or π, as is the case for ∆ϕ . To better exploit the relationship between ∆z and ∆ϕ , Eve first quantizes each phase ∆zl ∈ ∆z in (16) into a bit bzl for l ∈ {0, 1, . . . , L − 2} as ( 0, if ∆l ∈ (− π2 , π2 ] z (19) bl = 1, if ∆l ∈ (−π, − π2 ] ∪ ( π2 , π], where (− π2 , π2 ] and (−π, − π2 ]∪( π2 , π] denote the phase regions close to 0 (bit 0 under binary mapping) and π (bit 1 under binary mapping), respectively. As a result, Eve obtains a differential bit sequence bz = [bz0 , ..., bzL−2 ].

ϕ Similarly, each phase ∆ϕ l ∈ ∆ in (17) is quantized into a ϕ bit bl for l ∈ {0, 1, . . . , L − 2} using the quantization rule in (19), from which we can obtain differential bit sequence ϕ bϕ = [bϕ 0 , ..., bL−2 ].

and ∆ϕ = [(ϕ1 − ϕ0 ), ..., (ϕL−1 − ϕL−2 )].

(17)

In this ideal flat fading example, Eve can obtain the differential key-mapped phase sequence ∆ϕ by directly letting ∆ϕ = ∆z . If ϕ0 is determined, Eve can obtain ϕ based on (15). Subsequently, Eve reverses the mapping M for ϕ to obtain a potential key sequence s′ as s′ = [M −1 (ϕ0 ), ..., M −1 (ϕL−1 )].

(18)

As ϕ0 ∈ Φ in (4), which consists of a limited number of possible phases, Eve can enumerate each possible phase for ϕ0 , obtain a corresponding key candidate based on (15) and (18), then verify whether the candidate is the true key s. B. Attack Design Basics Under Realistic Scenarios Now, we present the attack design under real-world conditions. In practice, adjacent OFDM subchannel responses are typically correlated, and the correlation coefficient does not reach 1 (e.g., with a mean value of 0.35, as shown in Fig. 4). This implies that term (θl+1 − θl ) in (13) is nonzero and (14) does not hold. However, based on (13), (θl+1 − θl ) can be regarded as an offset added to the right-hand side of (14).

(20)

(21)

For each element bϕ l , it represents the bitwise difference between two adjacent bits sl and sl+1 in the key s (i.e., bϕ l is 0 if sl and sl+1 have the same value or 1 otherwise). If Eve knows bϕ , there are only two possible key candidates by setting the first bit to be either 0 or 1. Then, Eve can verify both candidates to find the true key s. As discussed above, since ∆z can serve as a reference for estimating ∆ϕ , the corresponding sequence bz can likewise be used as an estimate of bϕ . In this regard, Eve can set bz as the most likely candidate for bϕ and verify bz first. However, in many cases, bz may not be exactly the same as bϕ . Eve needs to select more other candidates for bϕ to verify. Under weak subcarrier correlation, she can start from changing 1 bit in bz to get more candidates, then change 2 and more bits until the true key s is identified. Specifically, for each candidate for bϕ , denoted by b̂ϕ , Eve would operate as follows to verify its corresponding key candidates: she first initializes the key candidates reconstruction process by assuming the first bit of the secret key to be ŝ0 ∈ {0, 1}; then, the subsequent key bits are determined iteratively based on the candidate sequence b̂ϕ , such that the next key bit ŝl+1 is set equal to ŝl if the candidate bit b̂ϕl = 0 (indicating identical adjacent bits), and ŝl+1 = ŝ¯l if b̂ϕl = 1 (indicating a bit flip), where ŝ¯l denotes

5

𝑅𝐵𝐸

𝒛

Bob

observes

s =[1, 1, 0, 1]

Eve 𝑅𝐴𝐸

quantifies guesses

Alice

∆𝒛 = [∆0𝑧 , ∆1𝑧 ,∆2𝑧 ]

𝒃𝒛 = [ 0, 1, 0 ]

𝒃∅ || [0, 1, 0] [1,1, 0]

generates

𝑠 = 0: candidate 1=[0, 0, 1, 1] ቊ 0 𝑠0 = 1: candidate 2=[1, 1, 0, 0]

generates

𝑠 = 0: candidate 3=[0, 1, 0, 0] ቊ 0 𝑠0 = 1: candidate 4=[1, 0, 1, 1]

generates

𝑠 = 0: candidate 5=[0, 0, 0, 0] ቊ 0 𝑠0 = 1: candidate 6=[1, 1, 1, 1]

generates

𝑠 = 0: candidate 7=[0, 1, 0, 0] ቊ 0 𝑠0 = 1: candidate 8=[1, 1, 0, 1]

[0,0, 0] [0,1, 1]

Fig. 5: A basic attack design. the bitwise inverse of ŝl ; consequently, this procedure yields two key candidates, which Eve then verifies to determine if they match the true secret key s. Fig. 5 illustrates an example of the basic attack design, where the true secret key is s = [1, 1, 0, 1]. In this example, Eve first obtains her observation z, from which she derives the differential phase sequence ∆z , and then quantizes ∆z into a differential bit sequence bz = [0, 1, 0]. Eve uses bz = [0, 1, 0] as the first candidate for bϕ . She sets the first bit of the key s to 0 and 1, and generates two key candidates: [0, 0, 1, 1] and [1, 1, 0, 0], but fails to match the actual key. Then, Eve changes 1 bit in bz = [0, 1, 0], generates new key candidates and continues to verify. After multiple attempts, when Eve flips the last bit in bz = [0, 1, 0] to obtain [0, 1, 1] as a candidate for bϕ and sets the first bit of the key s to 1, she eventually verifies that the key candidate [1, 1, 0, 1] is the true key. C. The MDLG Strategy As shown in the example in Fig. 5, the key idea of Eve’s attack strategy is to use bz as a reference to guess bϕ . This guessing is conducted in descending order of likelihood to select candidates for bϕ : starting from the most likely candidate (i.e., the reference bz ) and moving towards less likely ones by gradually changing more bits in the reference bz . We call this strategy maximum differential likelihood generator (MDLG). It is worth noting that bz and bϕ depend only on the relative phase differences between adjacent OFDM subchannels of z and ϕ (i.e., ∆z and ∆ϕ ), and are independent of the absolute phase values of z and ϕ; therefore, adopting different quantization thresholds for the key mapping function M (·) will not affect the attack performance. In the following, we detail the working steps of MDLG and mathematically analyze its attack performance. 1) Strategy Design: The MDLG strategy consists of two major steps. Step 1: Computing the differential sequence bz . Eve first extracts the phase sequence z from (12) by comparing the phases in the observations (9) and (11). She then computes the differential phase sequence ∆z using (16), and quantizes ∆z based on (19) to obtain the differential bit sequence bz .

Step 2: Selecting and verifying candidates by gradually changing bits in bz . Eve uses bz as the first candidate for bϕ and generates two corresponding key candidates by setting the first bit in key s to 0 and 1, respectively. Eve verifies both candidates to see if she finds the true key s. If Eve cannot, she changes 1 bit in bz , enumerates and verifies all possible key candidates under the 1-bit change. If the true key still cannot be found, Eve proceeds to change 2 or more bits for further verification, until the true key is identified. 2) Performance Analysis of MDLG: It is clear that in practice, Eve has a limited computational capability and cannot enumerate all possible key candidates to verify within a reasonable time period. For example, given a key size of 128 bits, it is computationally infeasible for Eve to verify 2128 possibilities based on today’s computing power. As a result, we assume that Eve can only verify up to N possibilities starting from its reference bz , where N is called Eve’s computing capability. Theorem 1. Given Eve’s capability N and the correlation coefficient among OFDM subchannels ρ, the success probability of MDLG can be expressed as PMDLG = I( 1−ρ ) (L − 1 − nmax , nmax + 1),

(22)

2

 Pn′ where nmax = max{n′ |2 n=0 L−1 ≤ N }, and Ix (a, b) = n B(x;a,b) function B(1;a,b) represents the regularized incomplete beta Rx with incomplete beta function B(x; a, b) = 0 ta−1 (1 − t)b−1 dt and complete beta function B(a, b) = B(1; a, b). Proof: Based on MDLG, Eve changes one or more bits in bz to generate candidates for bϕ and subsequently verifies the corresponding candidates for s. We use bzϕ to represent the difference between bz and bϕ , i.e., bzϕ = bϕ ⊕bz where ⊕ is the exclusive OR (XOR) operation. Then, the candidate for bϕ can be obtained by performing XOR between the candidate for bzϕ and the given bz . For Eve, this MDLG strategy is equivalent to increasing the value of n gradually to find the true s, where n is the number of bits being 1 in the candidate for bzϕ . Let nmax denote the maximum value that n can reach under Eve’s capability N ; that is, the number of bits equals to 1 in the candidate for bzϕ is at most nmax , or Eve can change at most nmax bits in bz to get the candidate for bϕ . If the bit difference between bz and bϕ is no greater than nmax , i.e., the number of bits equal to 1 in bzϕ does not exceed nmax , Eve can succeed in finding the true key s with the capability N . As a result, we proceed to analyze the statistical properties of the bits in bzϕ . We define another differential sequence, similar to ∆z in (16) and ∆ϕ in (17), as ∆θ = [(θ1 − θ0 ), ..., (θL−1 − θL−2 )].

(23)

Given that the analysis targets the correlation between adjacent subchannels, the elements in ∆θ should be independently and identically distributed (i.i.d.). Based on (15), the differences between the corresponding elements of ∆z and ∆ϕ should also follow an i.i.d. distribution. Since bz and bϕ are generated from ∆z and ∆ϕ , respectively, according to the quantization rule in (19), the differences between the corresponding bits in bz and bϕ can likewise be regarded as i.i.d. Therefore,

6

10

10

0

0

10

-5

2

6

10-10

3

P=10 /2

56

P=102/256

-15

10

56

P=10 /2 5 56 P=10 /2 4 56 P=10 /2

0

10-5

N=10 3 N=10 4 N=10 N=105 N=106

0.5

-10

10

1

(a) Under varying N .

=0.1 =0.3 =0.5 =0.7 =0.9 Random guess

10-15 102

104

106

(b) Under varying ρ.

Fig. 6: Attack success probabilities of MDLG.

D. Multiple-Bit Mapping Case

each bit in bzϕ can be modeled as an independent Bernoulli random variable, and the total number of ones in bzϕ follows a Binomial distribution. Let the Bernoulli parameter be denoted by Pb . Then, the probability that n bits in bzϕ are equal to 1 is given by the binomial probability:  n (24) Pn = L−1 Pb (1 − Pb )L−1−n , n  where L−1 is the number of all possible sequences with n n bits being 1, and Pbn (1 − Pb )L−1−n is the probability of each possible sequence. Therefore, Eve’s success probability is the sum of all probability of N bit sequences tried by Eve being the actual key as Xnmax L − 1 PMDLG = Pbn (1 − Pb )L−1−n (25) n n=0 According to the definition of the regularized incomplete beta function Ix (a, b) [38], we rewrite (25) as PMDLG = IPb (L − 1 − nmax , nmax + 1),

(26)

where Xnmax L − 1 n

Pbn (1 − Pb )L−1−n

(27) = IPb (L − 1 − nmax , nmax + 1). Pnmax L−1 Under a given nmax , Eve can verify up to 2 n=0 key n candidates, as one candidate for bϕ corresponds to two key candidates. Given Eve’s  capability N , then we have nmax = Pn′ max{n′ |2 n=0 L−1 ≤ N }. From a statistical perspective, n the probability Pb that a bit in bzϕ equals 1 matches the type of probability discussed in [37], that is, the probability that the quantized bits of adjacent subchannel phase responses differ.  , where ρ is This so-called transition probability equals 1−ρ 2 correlation coefficient [39]. Finally, we can rewrite (26) to get (22). □ We use numerical simulations to illustrate the performance of MDLG. We set the key length and the number of subcarriers to be S = L = 56. Fig. 6a shows Eve’s success probability using MDLG as a function of channel correlation coefficient ρ under Eve’s capability N = 102 , 103 , 104 , and 105 . We can notice that a larger ρ would result in a higher attack success probability. If Eve uses random guessing and guesses the key N = 102 , 103 , 104 , and 105 times, her success probabilities are 102 /256 , 103 /256 , 104 /256 , 105 /256 , and 106 /256 , respectively, which are also shown in Fig. 6a as dashed lines. We can observe that when ρ is 0 (i.e., the OFDM subcarriers are n=0

uncorrelated), MDLG has the same performance as random guessing. However, when the subcarriers become even weakly correlated, MDLG significantly outperforms random guessing. Fig. 6b shows Eve’s success probability as a function of Eve’s capability N . It is clear that a greater N value leads to a higher attack success probability. In practice, there is always a limit for N due to her computational limit. Overall, Fig. 6 shows that MDLG is a powerful attack, which leverages the imperfect wireless channel to attack PLA.

We next consider the attack scenario under a multiple-bit mapping M , where each sub-key contains m bits and the full key s of length S bits is divided into S/m sub-keys. In this context, M is a 2m -ary mapping function that maps each subkey to a phase value that is an integer multiple of 22π m. In this case, Eve’s approach in finding the secret key can be extended from the binary mapping scenario. We call the strategy m-MDLG. Specifically, Eve first obtains ∆z based on (16). Then, she replaces each element in ∆z with its nearest z′ multiple of 22π , which m to get a new differential sequence ∆ serves as the reference for generating candidates for ∆ϕ . Since there are 2m possible values for the first element of ϕ in (5) under multiple-bit mapping, based on (15) and (18), there are 2m key candidates corresponding to one candidate for ∆ϕ (in contrast to 2 key candidates under binary mapping). She ′ uses ∆z as the first candidate for ∆ϕ and generates 2m key candidates accordingly for verification. If the verification fails, ′ Eve proceeds to change one element in ∆z to try other key candidates. If all key candidates under one-element change still fail the verification, Eve then moves on to change 2 and more ′ elements in ∆z until the true key is identified or she reaches ′ her capability N . Since both ∆z and ∆ϕ are determined by the phase differences between adjacent subchannels of z and ϕ and are independent of their absolute phase values, different quantization thresholds for the key mapping function M (.) will not affect the attack performance, just as in the MDLG for the binary mapping case. In the following, we present the performance of m-MDLG. Theorem 2. Given Eve’s capability N and the correlation coefficient among OFDM subchannels ρ, the success probability of m-MDLG can be written as   S Pm-MDLG = I(1− 1+ρ − 1 − n , n + 1 , (28) max max 2m ) m  Pn′ S n where nmax = max{n′ |2m n=0 mn−1 (2m − 1) ≤ N }, B(x;a,b) Ix (a, b) = B(1;a,b) represents the regularized incomplete beta function with incomplete beta function B(x; a, b) = R x a−1 t (1 − t)b−1 dt and complete beta function B(a, b) = 0 B(1; a, b). ′ Proof: Under the m-bit mapping M , the length of ∆z S or ∆ϕ is m − 1, where S denotes the length of the key s. Based on this attack, Eve incrementally changes one or ′ more elements in ∆z to generate candidates for ∆ϕ and subsequently verifies the corresponding key candidates. When S ′ Eve decides to change n elements in ∆z , there are mn−1

7

1

in the presence of Eve with MDLG.

0.8

A. Design Intuition

0.6 = 0.1 = 0.3 = 0.5 = 0.7 = 0.9

0.4 0.2 0

0

5

10

15

Fig. 7: Attack success probabilities of m-MDLG. possible combinations of element positions. Since each element selected for changing has (2m − 1) phase  options, S n the total number of candidates for ∆ϕ is mn−1 (2m − 1) . ϕ Moreover, since each candidate for ∆ corresponds to 2m key candidates, the total number of key candidates for a given S n is 2m mn−1 (2m − 1)n . Let nmax denote the maximum value that n can reach under Eve’s capability N , then we  Pn′ S n have nmax = max{n′ |2m n=0 mn−1 (2m − 1) ≤ N }. z′ If the number of differing elements between ∆ and ∆ϕ does not exceed nmax , Eve can succeed in finding the true key s. Similar to the 1-bit mapping case, each correspond′ ing pair of elements in ∆z and ∆ϕ differs independently with identical probability. Let this probability be Pbm . As a ′ result, the probability that ∆ϕ and ∆z differ in n elements  S S −n−1 n (Pbm ) . Therefore, Eve’s success is mn−1 (1 − Pbm ) m probability is  nX max  S S −1 −n−1 n m Pm-MDLG = (1 − Pbm ) m (Pbm ) . (29) n n=0 As the value of m increases, the key-phase mapping in (4) becomes more fine-grained (i.e., with smaller phase intervals ′ in ∆z and ∆ϕ ), making it more likely that the correspond′ ing elements of ∆z and ∆ϕ are different and increasing the probability Pbm . When m = 1, the probability that z′ ϕ the corresponding   elements of ∆ and ∆ are equal is 1−ρ 1+ρ 1− 2 = 2 . Based on this, for an arbitrary value of m, the probability that a pair of corresponding elements are equal 1+ρ 1+ρ 1 is given by 1+ρ 2 2m−1 = 2m , and thus Pbm = 1 − 2m . Finally, (29) can be rewritten as   S Pm-MDLG = I(1− 1+ρ − 1 − nmax , nmax + 1 . (30) 2m ) m □ We can easily verify that Theorem 1 is a special case of Theorem 2 by setting m = 1 (and thus L = S). Fig. 7 shows the impacts of m and ρ on the success probability of m-MDLG using numerical simulations (S = 64 and N = 10, 000). It is observed from the figure that the success probability increases as m increases for a fixed value of ρ, indicating that the binary mapping (i.e., m = 1) is able to minimize the attack success probability and should be considered as a primary mapping scheme for Alice and Bob. IV. M EASURABLE G UIDELINE FOR S ECURITY In this section, we will create a measurable guideline to determine when PLA should be used between Alice and Bob

From Theorem 1, we know that Eve can use MDLG to take advantage of imperfect channel randomness to have an effective attack to eavesdrop Alice and Bob’s key during their PLA process. Thus, when the channel is not sufficiently random, Alice and Bob should not use PLA and switch back to a traditional cryptography-based authentication method. How can Alice and Bob decide whether the channel is random enough to support their security requirement? Randomness testing, such as the NIST randomness test suite [40], is a commonly used tool to test the randomness of a binary sequence with a well-studied procedure and performance even in wireless context [37]. If we quantify the channel response h in (2) under the mapping function M into a binary sequence, we can in fact use randomness testing to decide whether the channel is random or not. In particular, a randomness test will compute a statistic, called P-value, and compare it with a threshold α to determine whether the sequence is random (i.e., P-value > α) or not (i.e., P-value ≤ α). Changing the value of α will lead to a stricter or looser test [37]. B. Inserting Testing into Authentication Process The randomness testing needs to be inserted into the PLA process in Fig. 1. It involves four steps: 1) Alice sends Bob a challenge signal SA to initialize the authentication; 2) SA goes through the channel between Alice and Bob and is received by Bob as RB . Meanwhile, Bob can estimate the channel response h in (2); 3) Bob quantifies h into a binary sequence and conducts randomness testing on it. 4) Based on the testing result, Bob can decide whether he will continue to send his physical-layer response signal or a traditional cryptographybased signal. C. Maximizing Efficiency while Ensuring Security On one hand, increasing the threshold α will lead to a stricter test. This means that the test will reject more sequences as random and the authentication will switch to traditional ones, making PLA less useful. On the other hand, reducing α leads to a looser test, which can make PLA vulnerable under Eve’s MDLG strategy. As a result, we need to create a guideline to maximize the efficiency of using PLA, while ensuring security. We first look at how Eve’s MDLG can be considered as a successful attack. There are two requirements: 1) Alice and Bob must pass the randomness testing to decide to use PLA and 2) Eve’s MDLG successfully finds their key. As a result, Eve’s success probability is written as P (Eve succeeds) = P (T Accept H0 )PMDLG ,

(31)

where P (T Accept H0 ) denotes the probability that randomness testing accepts the event H0 that the channel is regarded as random, and PMDLG denotes the conditional success probability given that the random test is passed, i.e., P (MDLG succeeds | T Accept H0 ). Since the calculation

8

logic of the MDLG attack is invariant to the outcome of the randomness test, the formulation of PMDLG here remains identical to the expression in (22). To ensure the security, we define a requirement P (Eve succeeds) ≤ PBenchmark ,

(32)

where PBenchmark is the maximum acceptable attack success probability in the PLA. The randomness testing controls when we should use PLA. In order to maximize its use efficiency, we need the channel to pass randomness testing as many times as possible. At the same time, the test should also be strict enough to make sure the security requirement (32) is met, which leads to an optimization problem of finding the optimal test threshold α as arg maxα s.t.

P (T Accept H0 )

(33)

P (Eve succeeds) ≤ PBenchmark .

(34)

Given the security requirement Pbenchmark , we can use the guideline in (33) to set up the randomness testing to maximize the efficiency in using PLA. As both P (T Accept H0 ) and PMDLG are independent of the quantization thresholds, the proposed guideline remains effective regardless of the specific threshold used for the key mapping function. D. Generalizability of the Proposed Guideline 1) Extension to Diverse Wireless Architectures: While the proposed guideline is demonstrated within an OFDM framework, it can be effectively generalized to scenarios beyond OFDM. This is because it fundamentally addresses a universal vulnerability in physical layer security: the inherent physical continuity and statistical correlation between adjacent physical resources (e.g., spatial correlation in MIMO antennas or temporal correlation in fast-fading channels). In fact, these correlation-induced vulnerabilities in non-OFDM systems can still be exploited by attackers utilizing MDLG-like strategies to execute attacks. Specifically, the differential between adjacent wireless physical parameters corresponds to a differential sequence (e.g., ∆θ in this paper). Dictated by the underlying correlation, each element in this sequence is probabilistically more likely to be close to zero. Consequently, the attacker can generate candidates for this differential sequence in descending order of likelihood, where sequences deviating more from an all-zero state possess correspondingly lower likelihoods. With these initial candidates, the attacker can perform further scenariospecific adaptations to derive subsequent target candidates (e.g., in this paper, using bz as a reference to derive bϕ , or ′ using ∆z to obtain candidates for ∆ϕ ). These derived candidates inherently preserve the descending order of likelihood, enabling the attacker to achieve a success rate significantly higher than random guessing. Therefore, strictly applying our proposed randomness testing guideline is imperative across various wireless architectures to fundamentally restrict this widespread vulnerability.

2) Applicability to Dynamic and Mobile Scenarios: Our guideline remains applicable in dynamic and mobile scenarios. From a mechanistic perspective, neither MDLG nor the proposed guideline depends on the restrictive assumption that the nodes remain stationary throughout. Specifically, MDLG exploits the correlation in the current Alice-Bob channel phase response associated with the moment when Alice initiates the challenge in a given authentication round, while the randomness testing performed by Bob under our guideline examines the randomness of that same channel realization. In other words, in dynamic scenarios, node mobility mainly causes the channel realizations corresponding to the moments when Alice initiates the challenge to vary across authentication rounds, but it does not change the basic logic that MDLG and the guideline focus on the same object, namely, the channel condition at the moment when Alice initiates the challenge in the current authentication round. Moreover, in most practical mobility scenarios, the duration of a single authentication procedure is still typically shorter than the channel coherence time. As a result, the channel response between Alice and Bob during that authentication round can usually be approximated as unchanged. From a system-level perspective, this further supports the applicability of the proposed guideline in dynamic scenarios. V. E XPERIMENTAL S TUDY In this section, we use experimental evaluations to demonstrate the attack performance of MDLG and the effectiveness of randomness testing based design guideline. We first introduce the experimental setups and then analyze the results. A. Experimental Setups We conduct experiments in a realistic indoor environment, as shown in Fig. 8. We fix Alice at Location 0, and place Bob at locations 1-2, 3-4, 5-6, or 7-8, which represent the shortdistance line of sight (S-LoS), short-distance Non-LoS (SNLoS), long-distance LoS (L-LoS), and long-distance NLoS (L-NoS) channel conditions, respectively. We place Eve at Location 5. Notably, the location of Eve will not affect the MDLG attack performance or the effectiveness of the proposed guideline. This is because the attack success probability is fundamentally determined by the correlation properties of the OFDM subchannel responses between the legitimate users (i.e., Alice and Bob), and the randomness testing in the guideline is conducted exclusively on these Alice-Bob channel responses. We use commodity WiFi devices based on Atheros AR5822/AR9580 WiFi chipsets and TP-Link WDR4300 AP. On this experimental platform, we collect over 500,000 OFDM channel responses at each location with a carrier frequency of 2.4GHz, 56 subcarriers and 20MHz bandwidth by default. The software toolkit is the Atheros CSI tool [41]. We use the frequency test in the NIST test suite [40] as our typical test in experiments. Alternative tests in the suite can also be used, and they are shown to yield similar testing performance [37], [38], [42], [43]. An alternative test leads to a different mathematical expression of P (T Accept H0 ), making the optimal threshold α slightly different [37].

9

Hallway

0 1

2

5

6

3 4

7

8

Fig. 8: Experimental environment. The evaluation metrics in our experiments are Eve’s success probability P (Eve succeeds) and the test-passing probability P (T Accept H0 ) (i.e., the probability that the OFDM channel passes the randomness testing), which are used to measure security and efficiency, respectively. B. Results Analysis In the following, we will thoroughly analyze the results obtained from various experiments. 1) Phase Responses of OFDM Subchannels: In this experiment, we place Bob at 8 different locations. Fig. 9 shows an example of the channel phase responses on all OFDM subchannels. Because the neighboring locations (i.e., Locations 1-2, Locations 3-4, Locations 5-6, and Locations 7-8) have similar phase responses. We only plot the phase responses at Locations 1, 3, 5, and 7 in Fig. 9. The results show that the phase responses slowly vary over subchannels, confirming that the channel correlation is widespread in practice. 2) Correlation Coefficient at Different Locations: We compute the channel correlation coefficient ρ for each location (i.e., placing Bob at each location and measuring Alice and Bob’s channel). As shown in Fig. 10, the correlation coefficients for 8 locations are 0.74, 0.72, 0.61, 0.58, 0.66, 0.63, 0.46, and 0.41, showing that the OFDM subchannels are moderately or strongly correlated. In particular, the channel responses under the S-LoS environment show the highest correlation (e.g., ρ ≈ 0.7 at Locations 1-2); and the L-NLoS (more scattered and multipath-rich) environment exhibits the lowest (but still moderate) correlation (e.g., ρ ≈ 0.4 at Locations 7-8). 3) Success Probability of MDLG: In Fig. 11, we compute MDLG’s success probability PMDLG as a function of Eve’s capability N at 8 different locations for Bob. The figure shows that MDLG has an order-of-magnitude advantage over random guessing to crack Alice and Bob’s key during the PLA process (i.e., PMDLG ≫ PRG that denotes the success probability of random guessing). For example, at Locations 7 and 8, the MDLG’s success probability is about 108 times higher than random guessing. When the correlation among OFDM subchannels is even higher (at Locations 1 and 2), MDLG is about 1012 times better than random guessing. 4) Impact of Randomness Testing: In this experiment, we let N be 106 and conducted the randomness test T at 8 locations and analyzed the impact of the test with a typical test threshold α = 0.20. In Fig. 12, we measure the testpassing probabilities range from 0.42 to 0.58 at Locations 1-8 with Locations 1 and 8 having the lowest and highest passing probability, respectively. We can see that with α = 0.20, the randomness test T has around 50% probability of rejecting the use of the wireless PLA.

We also compute the average correlation coefficients of channel responses that actually pass the test T at 8 locations (ranging from 0.30 to 0.51). We show the results in Fig. 13 in comparison with the coefficients of all channel responses before the test T (ranging from 0.41 to 0.76). It is noted from Fig. 13 that correlation coefficients of the channel responses accepted by T are smaller than those before T , indicating the test T can help filter out the defective channel cases to combat the MDLG attack. Fig. 14 plots Eve’s success probabilities at 8 locations when Eve uses MDLG to attack the PLA before and after the deployment of test T . It is clear from the figure that Eve has a much lower success probability if the wireless channel is first tested by T before it is used for PLA. For example, at Location 8, P (Eve succeeds) = 2.561 × 10−4 without T and it becomes 2.986 × 10−6 when T is used. 5) Optimal α under Different Conditions: Figs. 12, 13, and Fig. 14 show that randomness testing chosen with a typical value α = 0.20 can substantially reduce Eve’s success. As designed in our guideline in (33), the α value can be optimized to maximize the efficiency of PLA while maintaining security. To see how our guideline (33) determines the optimal α, we consider two locations, Locations 1 and 8, which represent the S-LoS (i.e., strongly correlated) and L-LoS (i.e., weakly correlated) environments, respectively. We let the maximum allowable attack success probability PBenchmark be 10−4 . Based on our guideline (33), we compute the optimal α values at two locations as a function of Eve’s capability N , shown in Fig. 15. The figure demonstrates that Location 1 needs a larger α value than Location 8 in the test T to ensure security because Location 1 leads to a much stronger OFDM subchannel correlation than Location 8. We also notice from the figure that as Eve becomes more capable with a larger N value, the optimal value α increases to 1. This means that the randomness test T will consider more channel cases defective (i.e., not meeting the benchmark security requirement in (33)) to be used for PLA when facing a more powerful attack. Fig. 16 also shows the optimal α value as a function of the benchmark requirement PBenchmark under Eve’s capability N = 106 . Fig. 16 illustrates that as PBenchmark increases, the optimal α value decreases (even to 0). This is because a higher PBenchmark reduces the security requirement (i.e., Alice and Bob become more tolerant of an attack), allowing for a lower testing threshold to enhance the efficiency of using PLA. VI. R ELATED W ORK In this section, we present the research related to our work. Improving PLA security: PLA performance heavily relies on the random wireless channel. Some studies focused on making the PLA procedure appear more random to the adversary [17], [44]. In [17], Tikhonov-distributed artificial noise was introduced to interfere with the key-related signal for resisting potential key recovery attacks. This method not only affects the reception of the eavesdropper but also that of the intended user as signals are both degraded. Due to the presence of noise, the decryption process of the secret key will become more complex. In [44], instead of using all available resources

4 3

Phase

2 1 0

-1 L1 L3

-2 -3

10

20

30

40

L5 L7 50

Correlation Coefficient

10

0.8

100

0.74 0.72 0.61 0.58

0.6

0.66 0.63 0.46

0.41

0.56 0.58

0.6

0.49 0.50 0.42 0.43

10-5

0.4

10-10

0.2

0.46 0.47

0.4 0.2 0

1

2

3

Subcarrier

4 5 6 Location

7

10-15 102

8

104

106

0

1

2

3

4 5 6 Location

7

8

100

0.8 0.6

Before test After test

1

0.6

0.5 Before Randomness Testing After Randomness Testing

0.2

1

2

3

4 5 6 Location

7

8

Location 1 Location 8

0.8

10-2

0.4

0

1

Location 1 Location 8

10-4

0.4 0.2

10-6

0 1

2

3

4 5 6 Location

7

8

10 1 10 2 10 3 10 4 10 5 10 6 10 7 10 8 10 9

Correlation Coefficient

Fig. 9: Channel phase re- Fig. 10: Correlation coeffi- Fig. 11: PMDLG vs PRG for Fig. 12: The test-passing probsponses over subchannels. cients at different locations. different Eve’s capabilities N . abilities with α = 0.20.

0

0

0.05

0.1

0.15

0.2

Fig. 13: Correlation coeffi- Fig. 14: P(Eve succeeds) be- Fig. 15: The optimal α values Fig. 16: The optimal α valcients before and after the test fore and after the test T (α = under different Eve’s capabili- ues under different PBenchmark T (α = 0.20). 0.20). ties N at Locations 1 vs 8. requirements.

for message transmission, a certain part of them were used for randomization by adding “dummy” messages unknown to Eve such that Eve would be saturated with useless information. These studies focused on empirically improving PLA schemes but lacked a scientific guideline to assess whether the enhanced system meets security standards. Our work offers a well-defined guideline via detailed mathematical modeling to determine when PLA is sufficiently secure. Using randomness testing in wireless security: Randomness testing has been proposed to test the key sequence used for authentication [37], [42], [43], [45]–[48]. Although they share the same objective, the methods for generating key sequences and the randomness tests used can differ. For example, [45] establishes the key sequence for Alice and Bob by extracting and quantifying their Received Signal Strength Indicator (RSSI). The work in [48] proposed a reduced set of statistical tests that have low complexity and therefore can be executed at the runtime even on severely resource-constrained devices. The work in [37] investigated how to configure randomness testing to meet the security strength for creating a key from the wireless channel. Compared to these studies, our work focuses on the authentication process rather than the key establishment process. Specifically, our design uses randomness testing to determine when PLA is secure, rather than just establishing a secret key or evaluating its strength. Using other physical layer features for security: Existing studies have explored authentication mechanisms using other physical layer features. For example, [49], [50] utilized the combination of device-dependent biases in radio frequency and the mobility-induced Doppler shift, characterized as a timevarying carrier frequency offset, as a radiometric signature for authentication. The work in [51] leveraged the deep metric learning to train a radio frequency fingerprint identification by exploiting channel randomness features and data augmentation

for authentication on low-power long-range devices. These studies may be hardware-specific and usually require a training process by collecting labeled data for machine learning, which can be cumbersome to perform and adjust over time in practice. Our work is complementary to these studies and offers a measurable guideline to determine when the wireless channel is sufficient to support PLA. VII. C ONCLUSION In this paper, we explored the potential vulnerability of PLA under practical OFDM channel conditions. Based on the correlations among subchannels, we introduce a novel adversary model named MDLG, which helps an eavesdropper to effectively infer Alice and Bob’s secret key from its accessible information. To defend against such a critical attack, we created a measurable guideline that uses randomness testing to first test whether the wireless channel can indeed support the PLA process under the MDLG attack model given a security requirement. We formulated the guideline as an optimization problem to solve the optimal setup for randomness testing. We also conducted comprehensive real-world experiments to show that the guideline can efficiently protect the PLA against the proposed MDLG attack. R EFERENCES [1] M. Bloch and J. Barros, Physical-layer security: from information theory to security engineering. Cambridge University Press, 2011. [2] K. Zeng, K. Govindan, and P. Mohapatra, “Non-cryptographic authentication and identification in wireless networks,” IEEE Wireless Commun., vol. 17, no. 5, 2010. [3] N. Gao, Q. Ni, D. Feng, X. Jing, and Y. Cao, “Physical layer authentication under intelligent spoofing in wireless sensor networks,” Signal Processing, vol. 166, p. 107272, 2020. [4] M. L. Das, “Two-factor user authentication in wireless sensor networks,” IEEE Trans. Wireless Commun., vol. 8, no. 3, pp. 1086–1090, 2009.

11

[5] G. Wang, H. Cai, C. Qian, J. Han, X. Li, H. Ding, and J. Zhao, “Towards replay-resilient rfid authentication,” in Proc. of ACM MOBICOM, 2018. [6] D. Shan, K. Zeng, W. Xiang, P. Richardson, and Y. Dong, “Phy-cram: Physical layer challenge-response authentication mechanism for wireless networks,” IEEE Journal on selected areas in communications, vol. 31, no. 9, pp. 1817–1827, 2013. [7] X. Du, D. Shan, K. Zeng, and L. Huie, “Physical layer challengeresponse authentication in wireless networks with relay,” in IEEE INFOCOM, 2014, pp. 1276–1284. [8] J. Choi, “A coding approach with key-channel randomization for physical-layer authentication,” IEEE Trans. Inf. Forensics Security, vol. 14, no. 1, pp. 175–185, 2018. [9] N. Yang, P. L. Yeoh, M. Elkashlan, R. Schober, and I. B. Collings, “Transmit antenna selection for security enhancement in MIMO wiretap channels,” IEEE Trans. Commun., vol. 61, no. 1, pp. 144–154, 2013. [10] H. Hassanieh, J. Wang, D. Katabi, and T. Kohno, “Securing {RFIDs} by randomizing the modulation and channel,” in NSDI, 2015, pp. 235–249. [11] H. Fang, X. Wang, and L. Hanzo, “Learning-aided physical layer authentication as an intelligent process,” IEEE Transactions on Communications, vol. 67, no. 3, pp. 2260–2273, 2018. [12] X. Wu and Z. Yang, “Physical-layer authentication for multi-carrier transmission,” IEEE Commun. Lett., vol. 19, no. 1, pp. 74–77, 2014. [13] L. Xiao, L. Greenstein, N. Mandayam, and W. Trappe, “Fingerprints in the ether: Using the physical layer for wireless authentication,” in IEEE ICC, 2007. [14] L. Xiao, L. J. Greenstein, N. B. Mandayam, and W. Trappe, “Using the physical layer for wireless authentication in time-variant channels,” IEEE Transactions on Wireless Communications, 2008. [15] N. Gao, Q. Huang, C. Li, S. Jin, and M. Matthaiou, “EsaNet: Environment semantics enabled physical layer authentication,” IEEE Wireless Communications Letters, vol. 13, no. 1, pp. 178–182, 2024. [16] A. Rukhin, J. Soto, J. Nechvatal, M. Smid, and E. Barker, “A statistical test suite for random and pseudorandom number generators for cryptographic applications,” Booz-allen and hamilton inc mclean va, Tech. Rep., 2001. [17] X. Wu, Z. Yang, C. Ling, and X.-G. Xia, “Artificial-noise-aided physical layer phase challenge-response authentication for practical ofdm transmission,” IEEE Trans. on Wireless Commun., 2016. [18] L. Xiao, L. J. Greenstein, N. B. Mandayam, and W. Trappe, “Using the physical layer for wireless authentication in time-variant channels,” IEEE Transactions on Wireless Communications, 2008. [19] N. Xie, J. Chen, and L. Huang, “Physical-layer authentication using multiple channel-based features,” IEEE transactions on Information Forensics and Security, vol. 16, pp. 2356–2366, 2021. [20] L. Xiao, X. Wan, and Z. Han, “Phy-layer authentication with multiple landmarks with reduced overhead,” IEEE Transactions on Wireless Communications, vol. 17, no. 3, pp. 1676–1687, 2017. [21] P. Zhang, Y. Shen, X. Jiang, and B. Wu, “Physical layer authentication jointly utilizing channel and phase noise in mimo systems,” IEEE Transactions on Communications, vol. 68, no. 4, pp. 2446–2458, 2020. [22] S. Wang, K. Huang, X. Xu, Z. Zhong, and Y. Zhou, “Csi-based physical layer authentication via deep learning,” IEEE Wireless Communications Letters, vol. 11, no. 8, pp. 1748–1752, 2022. [23] X. Lu, J. Lei, Y. Shi, and W. Li, “Improved physical layer authentication scheme based on wireless channel phase,” IEEE Wireless Communications Letters, vol. 11, no. 1, pp. 198–202, 2021. [24] R. Melki, H. N. Noura, M. M. Mansour, D. o. E. Chehab American University of Beirut, and A. Computer, “A survey on ofdm physical layer security,” Physical Communication, vol. 32, pp. 1–30, 2019. [25] W. Hou, X. Wang, and J.-Y. Chouinard, “Physical layer authentication in ofdm systems based on hypothesis testing of cfo estimates,” in IEEE ICC, 2012. [26] W.-L. W. Chin, T. N. Le, and C.-L. Tseng, “Authentication scheme for mobile ofdm based on security information technology of physical layer over time-variant and multipath fading channels,” Information Sciences, vol. 321, pp. 238–249, 2015. [27] J. B. Perazzone, L. Y. Paul, B. M. Sadler, and R. S. Blum, “Artificial noise-aided mimo physical layer authentication with imperfect csi,” IEEE Transactions on Information Forensics and Security, 2021. [28] Z. Ilic, A. Bazant, and B. Modlic, “An efficient data rate maximization algorithm for ofdm based wireless networks,” Wireless Netw, 2010. [29] L. Xiaowen and Z. Jinkang, “An adaptive subcarrier allocation algorithm for multiuser ofdm system,” in IEEE VTC-Fall, 2003. [30] H. Yaghoobi, “Scalable OFDMA physical layer in IEEE 802.16 WirelessMAN,” Intel Technology Journal, vol. 8, no. 3, 2004. [31] G. H.-S. Tsao, “Performance characterisation of MIMO-UWB systems for indoor environments,” 2014.

[32] I. B. Mabrouk, L. Talbi, M. Nedil, and K. Hettak, “Effect of mining machinery on MIMO–UWB radiowave propagation within an underground gallery,” IEEE Transactions on Antennas and Propagation, vol. 60, no. 11, pp. 5390–5399, 2012. [33] A. Goldsmith, Wireless Communications. Cambridge Univ. Press, 2005. [34] T. Hwang, C. Yang, G. Wu, S. Li, and G. Y. Li, “OFDM and its wireless applications: A survey,” IEEE transactions on Vehicular Technology, vol. 58, no. 4, pp. 1673–1694, 2008. [35] Z. Ma and Y.-i. Kim, “A novel ofdm receiver in the flat-fading channel,” in The 7th International Conference on Advanced Communication Technology, 2005, ICACT 2005. IEEE, 2005. [36] S.-H. Jeon and S.-K. Gil, “Dual optical encryption for binary data and secret key using phase-shifting digital holography,” Journal of the Optical Society of Korea, vol. 16, no. 3, pp. 263–269, 2012. [37] Z. Qu, S. Zhao, J. Xu, Z. Lu, and Y. Liu, “How to test the randomness from the wireless channel for security?” IEEE Trans. Inf. Forensics Security, vol. 16, pp. 3753–3766, June 2021. [38] J. W. Wallace and R. K. Sharma, “Automatic secret keys from reciprocal MIMO wireless channels: Measurement and analysis,” IEEE Trans. Inf. Forensics Security, vol. 5, no. 3, pp. 381–392, 2010. [39] B. Lindqvist, “A note on bernoulli trials with dependence,” Scandinavian Journal of Statistics, pp. 205–208, 1978. [40] A. Rukhin, J. Soto, J. Nechvatal, M. Smid, ElaineBarker, S. Leigh, M. Levenson, M. Vangel, D. Banks, A. Heckert, J. Dray, and S. Vo, “Statistical test suite for random and pseudorandom number generators for cryptographic applications,” NIST Special Publication, 2010. [41] Y. Xie, Z. Li, and M. Li, “Precise power delay profiling with commodity wi-fi,” IEEE Trans. Mobile Comput., 2018. [42] S. Jana, S. N. Premnath, M. Clark, S. K. Kasera, N. Patwari, and S. V. Krishnamurthy, “On the effectiveness of secret key extraction from wireless signal strength in real environments,” in Proc. of ACM MobiCom, 2009, pp. 321–332. [43] S. Mathur, W. Trappe, N. Mandayam, C. Ye, and A. Reznik, “Radiotelepathy: extracting a secret key from an unauthenticated wireless channel,” in Proc. of ACM MobiCom, 2008, pp. 128–139. [44] H. V. Poor and F. S. Rafael, “Wireless physical layer security,” Proceedings of the National Academy of Sciences., 2017. [45] R. Upadhyay, S. Singh, V. Trivedi, and AnkitSoni, “Randomness test for wireless physical layer key generation,” in ICACAT, 2018, pp. 1–6. [46] J. S. Soto, L. E. Bassham, W. Y. Yang, and C. G. Kang, Randomness testing of the advanced encryption standard finalist candidates. US Department of Commerce, Technology Administration, National Institute of Standards and Technology, 2000. [47] E. Manucom, G. BD, and M. RP, “Analysis of key randomness in improved one-time pad cryptography,” in IEEE ASID, 2017, pp. 11–16. [48] M. Göhring and R. Schmitz, “On randomness testing in physical layer key agreement,” in IEEE WF-IoT, 2015, pp. 733–738. [49] W. Hou, X. Wang, J.-Y. Chouinard, and A. Refaey, “Physical layer authentication for mobile systems with time-varying carrier frequency offsets,” IEEE Trans. Commun., vol. 62, no. 5, pp. 1658–1667, 2014. [50] J. Hua, H. Sun, Z. Shen, Z. Qian, and S. Zhong, “Accurate and efficient wireless device fingerprinting using channel state information,” in IEEE INFOCOM, 2018, pp. 1700–1708. [51] G. Shen, J. Zhang, A. Marshall, and J. R. Cavallaro, “Towards scalable and channel-robust radio frequency fingerprint identification for lora,” IEEE Trans. Inf. Forensics Security, vol. 17, pp. 774–787, 2022.

Haiyun Liu (Student Member, IEEE) received the B.S. degree in electrical engineering and automation from Shanghai University, Shanghai, China, in 2019, and the M.S. degree in signal and information processing from Sichuan University, Chengdu, China, in 2023. He is currently a Ph.D. student in the Bellini College of Artificial Intelligence, Cybersecurity and Computing, University of South Florida, Tampa, FL, USA. His research interests include security and privacy in wireless communications, and federated learning for networks.

12

Shangqing Zhao (Member, IEEE) received the Ph.D. degree in computer science from the University of South Florida in 2021. He is currently an Assistant Professor with the School of Computer Science, University of Oklahoma. His research interests include network and mobile system design and security.

Yao Liu (Senior Member, IEEE) received the Ph.D. degree in computer science from North Carolina State University, in 2012. She is an professor in the Bellini College of Artificial Intelligence, Cybersecurity and Computing, University of South Florida. Her research interests include in the security applications for cyberphysical systems, Internet of Things, and machine learning. She was an NSF CAREER Award recipient in 2016. She also received the ACM CCS Test-of-Time Award by ACM SIGSAC in 2019.

Zhuo Lu (Senior Member, IEEE) received the Ph.D. degree from North Carolina State University, in 2013. He is an associate professor with the Department of Electrical Engineering, University of South Florida. His research has been mainly focused on both theoretical and system perspectives on communication, network, and security. He received the NSF CISE CRII award in 2016, the Best Paper Award from IEEE GlobalSIP in 2019, and the NSF CAREER award in 2021.

Record · ID 175192 · SHA-256 e9ea8a78abd830ac
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.