• 제목/요약/키워드: Physical layer authentication

검색결과 10건 처리시간 0.022초

On the Application of Channel Characteristic-Based Physical Layer Authentication in Industrial Wireless Networks

  • Wang, Qiuhua;Kang, Mingyang;Yuan, Lifeng;Wang, Yunlu;Miao, Gongxun;Choo, Kim-Kwang Raymond
    • KSII Transactions on Internet and Information Systems (TIIS)
    • /
    • 제15권6호
    • /
    • pp.2255-2281
    • /
    • 2021
  • Channel characteristic-based physical layer authentication is one potential identity authentication scheme in wireless communication, such as used in a fog computing environment. While existing channel characteristic-based physical layer authentication schemes may be efficient when deployed in the conventional wireless network environment, they may be less efficient and practical for the industrial wireless communication environment due to the varying requirements. We observe that this is a topic that is understudied, and therefore in this paper, we review the constructions and performance of several commonly used test statistics and analyze their performance in typical industrial wireless networks using simulation experiments. The findings from the simulations show a number of limitations in existing channel characteristic-based physical layer authentication schemes. Therefore, we believe that it is a good idea to combine machine learning and multiple test statistics for identity authentication in future industrial wireless network deployment. Four machine learning methods prove that the scheme significantly improves the authentication accuracy and solves the challenge of choosing a threshold.

Physical Layer Technique to Assist Authentication Based on PKI for Vehicular Communication Networks

  • Wen, Hong;Ho, Pin-Han
    • KSII Transactions on Internet and Information Systems (TIIS)
    • /
    • 제5권2호
    • /
    • pp.440-456
    • /
    • 2011
  • In this paper, we introduce a novel Public Key Infrastructure (PKI) based message authentication scheme that takes advantage of temporal and spatial uniqueness in physical layer channel responses for each transmission pair in vehicular communication networks. The proposed scheme aims at achieving fast authentication and minimizing the packet transmission overhead without compromising the security requirements, in which most messages can be authenticated through an extreme fast physical-layer authentication mechanism. We will demonstrate that the proposed secure authentication scheme can achieve very short message delay and reduced communication overhead through extensive analysis and simulation.

AKA-PLA: Enhanced AKA Based on Physical Layer Authentication

  • Yang, Jing;Ji, Xinsheng;Huang, Kaizhi;Yi, Ming;Chen, Yajun
    • KSII Transactions on Internet and Information Systems (TIIS)
    • /
    • 제11권7호
    • /
    • pp.3747-3765
    • /
    • 2017
  • Existing authentication mechanisms in cellular mobile communication networks are realized in the upper layer by employing cryptographic techniques. Authentication data are broadcasted over the air in plaintext, enabling attackers to completely eavesdrop on the authentication and get some information about the shared secret key between legitimate nodes. Therefore, reusing the same secret key to authenticate several times results in the secret key's information leakage and high attacking rate. In this paper, we consider the most representative authentication mechanism, Authentication and Key Agreement (AKA), in cellular communication networks and propose an enhanced AKA scheme based on Physical Layer Authentication (AKA-PLA). Authentication responses generated by AKA are no longer transmitted in plaintext but masked by wireless channel characteristics, which are not available to adversaries, to generate physical layer authentication responses by a fault-tolerant hash method. The authenticator sets the threshold according to the authentication requirement and channel condition, further verifies the identity of the requester based on the matching result of the physical layer authentication responses. The performance analyses show that the proposed scheme can achieve lower false alarm rate and missing rate, which are a pair of contradictions, than traditional AKA. Besides, it is well compatible with AKA.

A Study of WiMAX Security threats and Their Solution

  • Woo, Seon-mi;Jeong, Gisung
    • International Journal of Internet, Broadcasting and Communication
    • /
    • 제8권2호
    • /
    • pp.66-74
    • /
    • 2016
  • In this study, we have discussed and illustrated the security issues of WiMAX technology including vulnerabilities, threats and some security solution. Both physical layer and data link layer have been considered. Jamming is a major threat in physical layer, and in data link layer we study an authentication problem and see the problem of some unencrypted messages leading to lack of confidentiality. Some of these vulnerabilities have been solved in the recent amendment of 802.16 and some still remain. Moreover WiMax is a new technology yet.

전자식 전력량계용 한전 프로토콜 및 운영 프로그램 개발 (Develpoment of Automatic Meter Reading Program for Electronic Power Meter)

  • 유인협;장문종;현덕화
    • 대한전기학회:학술대회논문집
    • /
    • 대한전기학회 2001년도 하계학술대회 논문집 D
    • /
    • pp.2219-2221
    • /
    • 2001
  • A communication protocol for automatic meter reading is designed for electronic power meter. Communicational functions and data structures are standardized and data reading software is developed according to the developed protocol. The communication protocol is designed with reference specifications, IEC 62056-31 and Distributed Network Protocol(DNP). For design, communicational functions and specifications of the industrial meters were analyzed for the purpose of developing a new one for KEPCO meters. The protocol is designed with 3 layer model, physical layers, data link layer and application layer. A documentation was completed with data gathering, data classification, authentication, error detection. An emulator system was made for testing the protocol. A meter reading software was developed using the protocol. Many different protocols and meter reading softwares are integrated into one with the developed protocol and software as KEPCO's standard.

  • PDF

블록체인을 이용하여 다층 네트워크를 확장한 확률 기반의 IoT 관리 모델 (Probability-based IoT management model using blockchain to expand multilayered networks)

  • 정윤수
    • 한국융합학회논문지
    • /
    • 제11권4호
    • /
    • pp.33-39
    • /
    • 2020
  • 최근 LTE보다 빠른 속도와 안정을 가진 5G 기술에 대한 기대감이 증가하고 있는 가운데 5G 통신 보안에 대한 관심이 증가하고 있다. 그러나, 5G는 현재까지 이질적인 영역이 서로 포함되어 있어서 보안 영역에 대한 문제들을 아직 완벽하게 지원하고 있지 않다. 본 논문은 5G 환경에서 IoT 장치의 인증을 블록체인에 적용한 확률 기반의 IoT 관리모델을 제안한다. 제안 모델은 IoT 장치의 인증을 확률적 이론과 물리적 구조를 효율적으로 융합하기 위해서 n 계층의 IoT 사용자를 n+1 계층과 n-1 계층의 관리자가 쌍방향 인증이 이루어지도록 2개의 랜덤키를 역으로 사용한다. 제안 모델은 5G 환경의 IoT 사용자에 대한 인증을 확률적 기반으로 IoT 정보를 계층화시킨 후 IoT 정보를 가중치에 적용하여 그룹핑된 IoT 정보를 블록체인으로 연결한다. 또한, 제안 모델은 5G 네트워크를 계층화된 다층 네트워크로 분할하기 때문에 기존 블록체인보다 향상된 기능을 가진다.

Usability and Evaluation of a Deployed 4G Network Prototype

  • Cuevas Antonio;Serrano Pablo;Moreno Jose I.;Bernardos Carlos J.;Jahnert Jurgen;Aguiar Rui L.;Marques Victor
    • Journal of Communications and Networks
    • /
    • 제7권2호
    • /
    • pp.222-230
    • /
    • 2005
  • This article presents a field evaluation of an IP-based architecture for heterogeneous environments that has been developed under the aegis of the Moby Dick project, covering UMTS-like (universal mobile telecommunications system) TD-CDMA (time division-code division multiple access) wireless access technology, wireless and wired LANs. The architecture treats all transmission capabilities as basic physical and data-link layers, and replaces all higher-level tasks by IP-based strategies. The Moby Dick architecture incorporates mobile IPv6, fast handovers, AAA-control (authentication, authorisation, accounting), charging and quality of service (QoS) in an integrated framework. The architecture further allows for optimised control on the radio link layer resources. It has been implemented and tested by expert users, and evaluated by real users on field trials with multiple services available.

A Survey of Security Mechanisms with Direct Sequence Spread Spectrum Signals

  • Kang, Taeho;Li, Xiang;Yu, Chansu;Kim, Jong
    • Journal of Computing Science and Engineering
    • /
    • 제7권3호
    • /
    • pp.187-197
    • /
    • 2013
  • Security has long been a challenging problem in wireless networks, mainly due to its broadcast nature of communication. This opens up simple yet effective measures to thwart useful communications between legitimate radios. Spread spectrum technologies, such as direct sequence spread spectrum (DSSS), have been developed as effective countermeasures against, for example, jamming attacks. This paper surveys previous research on securing a DSSS channel even further, using physical layer attributes-keyless DSSS mechanisms, and watermarked DSSS (WDSSS) schemes. The former has been motivated by the fact that it is still an open question to establish and share the secret spread sequence between the transmitter and the receiver without being noticed by adversaries. The basic idea of the latter is to exploit the redundancy inherent in DSSS's spreading process to embed watermark information. It can be considered a counter measure (authentication) for an intelligent attacker who obtains the spread sequence to generate fake messages. This paper also presents and evaluates an adaptive DSSS scheme that takes both jam resistance and communication efficiency into account.

IEEE 802.15.4기반 센서 네트워크에서 슬립거부 공격의 취약성 분석 및 탐지 메커니즘 (Vulnerability Analysis and Detection Mechanism against Denial of Sleep Attacks in Sensor Network based on IEEE 802.15.4)

  • 김아름;김미희;채기준
    • 정보처리학회논문지C
    • /
    • 제17C권1호
    • /
    • pp.1-14
    • /
    • 2010
  • IEEE 802.15.4 표준기술[1]은 센서 네트워크에서 저전력을 위한 기술로 LR-WPANs(Low Rate-Wireless Personal Area Networks)의 물리 계층과 MAC계층을 규정한다. 이 표준은 무선 센서, 가상 선(Virtual Wire)과 같은 제한된 출력과 성능으로 간단한 단거리 무선 통신을 필요로 하는 폭넓은 응용에 활용되고 있지만 보안 측면의 연구는 현재 미비한 상태로 다양한 공격에 대한 취약점을 내포하고 있다. 본 논문에서는 802.15.4 MAC계층의 슬립거부(Denial of Sleep) 공격에 대한 취약성을 분석하고 이를 탐지하는 메커니즘을 제안한다. 분석 결과, 슈퍼프레임 구간 변경, CW(Contention Window)값 변경, 채널스캔 및 PAN 연합과정 등에서 슬립거부 공격의 가능성을 분석할 수 있었고, 이 과정 중 일부에서는 표준에서 정의한 인증과 암호화 기능이 적용되어도 공격 가능함을 알 수 있었다. 또한 본 논문에서는 분석된 취약점 중에 채널스캔 및 PAN 연합과정에서 Beacon/Association Request 메시지 위조를 통한 슬립거부 공격의 탐지 메커니즘을 제안한다. 제안된 메커니즘은 메시지 요청 간격, 요청 노드 ID, 신호 세기 등을 모니터링하여 공격을 식별하여 탐지한다. QualNet 시뮬레이션 툴을 사용하여 공격의 영향 및 제안된 탐지 메커니즘의 탐지 가능성과 성능의 우수성을 입증할 수 있었다.

교량감시를 위한 무선 센서 네트워크 구조 및 보안 프로토콜 (A Wireless Sensor Network Architecture and Security Protocol for Monitoring the State of Bridge)

  • 임화정;전진순;이헌길
    • 한국컴퓨터산업학회논문지
    • /
    • 제6권3호
    • /
    • pp.465-476
    • /
    • 2005
  • 무선 센서 네트워크는 물리적인 제약을 가진 수많은 센서 노드들로 구성되어 있다. 각 센서 노드는 주변의 상태를 감지하고, 감지된 정보를 싱크(Sink)로 보내는 역할을 한다. <중략> 본 논문에서는 교량과 같은 인공구조물에 적합한 비 계층적 무선 센서 네트워크 구조를 제시하였다. 또한, 센서 노드들의 휴면(Sleep)과 활동(Awake) 상태를 이용한 효율적인 보안 라우팅 프로토콜과 센서 노드의 키와 위치 정보를 사전에 노드에 분배하는 사전 키 분배 방식 및 2계층 인증 기법을 제안하였다. 제안하는 방식은 대체 경로 수의 증가로 인한 데이터 전송률의 증가와 에너지 소모율의 감소 효과를 보였다.

  • PDF