RF fingerprinting-based authentication of radio equipment
The RFF-based challenge-response authentication method addresses vulnerabilities in existing RFF techniques by using a machine learning evaluation of randomly challenged RF fingerprints, enhancing security and reducing power consumption.
Patent Information
- Application Number
- PCT/EP2023/087349
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-21
- Publication Date
- 2025-06-26
AI Technical Summary
Existing Radio Frequency Fingerprinting (RFF) based authentication techniques face vulnerabilities such as impersonation attacks, difficulty in maintaining fingerprint database accuracy, and increased power consumption due to active signal transmission.
The proposed method involves an RFF-based challenge-response authentication process where a first radio equipment sends a set of parameter values to a second radio equipment to acquire its RF fingerprint, which is then evaluated using a machine learning technique against a stored dataset, incorporating randomness to enhance security.
This approach adds a layer of security by making it difficult for attackers to mimic RF fingerprints, improves reliability by using machine learning for authentication, and reduces power consumption by not requiring additional hardware on the transmitting device.
Smart Images

Figure EP2023087349_26062025_PF_FP_ABST
Abstract
Description
[0001] RF FINGERPRINTING-BASED AUTHENTICATION OF RADIO EQUIPMENT
[0002] Technical Field
[0003] The present disclosure relates to a method performed in a wireless communication system and a radio equipment for a wireless communication system for authenticating a radio equipment, and.
[0004] Background
[0005] In wireless communication involving transmission from a transmitting radio equipment to a receiving radio equipment, hardware imperfections at the transmitting radio equipment and / or at the receiving radio equipment can introduce distortions and errors in the signal, which can cause the modulation constellation of the transmitted / received signal to deviate from the ideal shape. For example, imperfections in the transmit or receive filters can cause frequency-dependent distortions in the signal, which can cause the constellation to become skewed or tilted. Similarly, imperfections in the Analog-to-Digital Converter (ADC) or Digital-to-Analog Converter (DAC) can cause quantization errors, which can cause the constellation to become distorted or irregular. Moreover, nonlinearities in the amplifiers or mixers can cause intermodulation distortion, which can introduce additional unwanted signals in the spectrum of the transmitted signal.
[0006] Hardware designers try to mitigate hardware imperfections with many different techniques in transmitters such as Digital Predistortion (DPD), post-distortion, interference cancellation circuits, dynamic biasing of amplification elements, etc. However, even with a lot of care and resources, it is impossible to mitigate all these imperfections in transmitters. They are also unique and vary from one transmitter to another, impacted by variables such as, but not limited to, circuit architectures, implementation, technology, processing or manufacturing variations, etc. Operating conditions, temperature of operation, aging, as well as memory effects in the circuit are also sources of unique hardware impairments.
[0007] The Radio Frequency Fingerprinting (RFF) technique has recently emerged as a promising technique for Physical Layer Security (PLS) for 5thGeneration (5G) wireless networks and beyond. The concept of RFF is to exploit these unique hardware impairments in transmitters in order to identify and authenticate radio equipment such as, but not limited to, User Equipments (UEs) and access points, to increase the trustworthiness and security of communications in wireless communication networks, see, e.g., Y. Chen et al., "Emitter Identification of Digital Modulation Transmitter Based on Nonlinearity and Modulation Distortion of Power Amplifier," Sensors, 21(13), June 25, 2021, 4362 (hereinafter referred to as the "Chen Article").
[0008] The basic concept of RFF has been known for some time, but the use of machine learning (ML) for automated RFF recognition is a more recent development. The idea behind using ML for RFF is to train a model using a set of labeled RF fingerprint data, which consists of a collection of signals transmitted by various wireless devices, see, e.g., A. Jagannath et al. "A Comprehensive Survey on Radio Frequency (RF) Fingerprinting: Traditional Approaches, Deep Learning, and Open Challenges," Computer Networks, Vol. 219, December 24, 2022 (hereinafter referred to as the "Jagannath Article"). Labeled RF fingerprint data can be obtained during a registration phase when one collects radio frequency (RF) fingerprint data from each radio equipment and labels it with a unique identifier that corresponds to the identity of the radio equipment. Once the machine learning model has been trained, the unique fingerprint for each radio equipment is stored in a database. During the inference phase, when a radio equipment transmits a signal, the complex (i.e., In-phase (I) / Quadrature-phase (Q)) samples are then fed into the machine learning model, which compares the complex samples to the stored fingerprints in the database to determine the identity of the radio equipment.
[0009] There are two types of RF fingerprinting techniques, namely, passive RF fingerprinting and active RF fingerprinting.
[0010] Passive RF fingerprinting has been studied for some time (see, e.g., K. J. Ellis et al., "Characteristics of radio transmitter fingerprints," Radio Science, Vol. 36, No. 4, pp. 585-597, July-August. 2001) and involves analyzing signals that are already being transmitted by a device in an opportunistic way, meaning without requesting any special signals from the device. Most RFF-based device authentication methods proposed in the literature are based on "passive listening" to the device. A receiver is listening to the device and receives symbols. ML is then used to perform the identification.
[0011] Active RF fingerprinting, on the other hand, involves sending active probing signals or sequence of signals to devices and measuring the corresponding devicetransmitted RF signals to identify unique characteristics (see, e.g., the Chen Article, the Jagannath Article, and Q. Xu et al, "Device Fingerprinting in Wireless Networks: Challenges and Opportunities," IEEE Communications Surveys & Tutorials, Vol. 18, Issue 1, September 3, 2014, pp. 94-104 (hereinafter referred to as the "Xu Article") and build an RF fingerprint database. This approach can provide more accurate and reliable fingerprints, especially in environments with high levels of noise or interference (see, e.g., the Chen Article). However, it may be more intrusive and may require more resources to implement.
[0012] Published Chinese Patent Application CN102904724A entitled "Radio-frequency- fingerprint-based challenge-response authentication protocol method" (hereinafter referred to as "the 724A Patent Application") proposes a challenge-response authentication protocol, i.e., active fingerprinting, based method that utilizes RFF for mutual authentication of communicating pairs. The method aims to verify the legitimacy of a device by comparing the detected RFF to a stored RFF, using answering party (device) and the challenging party (another device). If the detected and stored RFFs match, the devices are considered legitimate, and the communication protocol continues.
[0013] United States Patent No. 11,184,783B1 entitled "Real-time channel-resilient optimization of radio fingerprinting" (hereinafter referred to as "the '783 Patent") focuses on channel-resilient RFF optimization and is applicable for physical layer communication between a transmitting device and a receiving device. The transmitting device uses a physical signal modifier (such as a finite impulse response (FIR) filter) in addition to the classical transmitter circuit as visible in Figure 1A. This physical signal modifier can receive specific "signal modification parameters" to apply from the receiver device in order to enhance the received RF fingerprint. The receiver device uses a convolutional neural network to perform real-time optimization of the RF fingerprint to compensate for non-stationary impairments such as channel-induced distortions. In this regard, in order to optimize the RF fingerprint to be recognized by the convolutional neural network, the physical signal modifier settings can be updated by the receiving device and sent to the transmitting device to be applied for the next communication. The flowcharts related to this method are available in Figure IB, which highlights the steps related to the physical signal modifier embedded in the transmitter device.
[0014] Patent Cooperation Treaty (PCT) Patent Application Publication No. WO2022 / 187627A1 entitled "Methods, architectures, apparatuses and systems directed to data augmentation of radio frequency (rf) data for improved rf fingerprinting" (hereinafter referred to as "the '627 PCT Application") discloses a method to improve RFF by using an estimate of the transmission channel to de-embed the effects of the channel from the RFF process. Further, the channel estimation model is based on statistical distribution of channels, and the key feature of this work is the use of a channel prediction, i.e., trying to find a good enough channel estimate by iterating the RFF step. Finally, the work also proposes the use of an adaptive Finite Impulse Response (FIR) filter to improve the RFF at a specific channel estimation setting. This is similar to the one proposed in the '783 Patent. The RF fingerprinting system disclosed in the '627 PCT Application is shown Figure 1C, highlighting the FIR filter with control parameters and also data collection of the channel data used for the channel deembedding. Figure ID illustrates the method for RF fingerprinting as taught by the '627 PCT Application and consists of two main operations. The first main operation is a passive RF fingerprint, and the second main operation is a channel estimation and channel de-embedding. For channel de-embedding, the channel is measured and converted into a statistical form, and an appropriate channel model is selected and loaded into a neural network (NN). Finally, this is used to perform the RFF.
[0015] Summary
[0016] Systems and methods for Radio Frequency (RF) fingerprinting based authentication are disclosed. In one embodiment, a method for authenticating a radio equipment in a wireless communication network comprises sending to a second radio equipment, values for a set of parameters for acquisition of an RF fingerprint for the second radio equipment. The RF fingerprint comprises data characterizing RF impairments induced by specific hardware of the second radio equipment on a signal received from the second radio equipment, where the RF impairments are unique to the second radio equipment. The method further comprises receiving, a signal from the second radio equipment in response to sending the values for the set of parameters. The method further comprises obtaining an actual RF fingerprint of the second radio equipment based on the signal received from the second radio equipment and performing an evaluation of the RF fingerprint of the second radio equipment based on a RF fingerprint dataset of the second radio equipment, the RF fingerprint dataset comprising a RF fingerprints previously obtained for the second radio equipment for a number, N, of different sets of values for the set of parameters where N is less than a total number, NTOTAL, of all different sets of values for the set of parameters. By providing the values for the set of parameters for acquisition of the RF fingerprint for the second radio equipment, an RF fingerprinting based challenge-response authentication procedure that is secure against an attacker that attempts to mimic an RF fingerprint of the second radio equipment is provided.
[0017] In one embodiment, the method may further comprise deciding whether the second radio equipment is authenticated based on a result of the evaluation.
[0018] In one embodiment, the method may further comprise selecting the values for the set of parameters for acquisition of the RF fingerprint of the second radio equipment. In one embodiment, selecting the values for the set of parameters may be such that the value of at least one parameter in the set of parameters is randomized.
[0019] In one embodiment, the set of parameters may comprise any one or more of the following: transmit power at which the second radio equipment transmits the signal, carrier frequency at which the second radio equipment transmits the signal and carrier bandwidth of the carrier on which the second radio equipment transmits the signal.
[0020] In one embodiment, the set of parameters may comprise any one or more of the following: frequency offset between a baseband frequency and an intermediate frequency used at the second radio equipment when transmitting the signal, frequency offset between an intermediate frequency used at the second radio equipment when transmitting the signal and the carrier frequency at which the second radio equipment transmits the signal, a parameter related to power amplifier biasing at the second radio equipment when transmitting the signal, a parameter related to mixer biasing at the second radio equipment when transmitting the signal, a parameter related to frequencysynthesizer biasing when transmitting the signal, a parameter related to oscillator biasing at the second radio equipment when transmitting the signal, a parameter related to digital-to-analog converter biasing at the second radio equipment when transmitting the signal, a parameter related to tuning the resonance frequency of resonators in the RF transmit chain at the UE when transmitting the signal, a parameter related to tuning of one or more baseband filters at the second radio equipment when transmitting the signal, a parameter related to disabling or changing one or more parameters for digital predistortion at the second radio equipment when transmitting the signal, and a parameter related to disabling or changing one or more parameter for cartesian-error calibration at the second radio equipment when transmitting the signal.
[0021] In one embodiment, the method may further comprise processing the signal to provide data about the signal from which the RF fingerprint can be extracted, wherein obtaining the RF fingerprint of the second radio equipment may comprise extracting the RF fingerprint of the second radio equipment from the data about the signal.
[0022] In one embodiment, performing the evaluation of the RF fingerprint of the second radio equipment may comprise performing the evaluation of the RF fingerprint based on the RF fingerprint dataset of the UE and a particular machine learning (ML) technique.
[0023] In one embodiment, the ML technique may be a Principal Component Analysis (PCA) technique, and performing the evaluation of the RF fingerprint may be based on a PCA-transformed version of the RF fingerprint dataset of the UE and a PCA-transformed version of the RF fingerprint of the second radio equipment. In one embodiment, a result of performing the evaluation of the RF fingerprint of the second radio equipment may comprise a number of standard deviations between the PCA-transformed version of the RF fingerprint of the second radio equipment and a mean of the PCA transformed RF fingerprints comprised in the PCA-transformed version of the RF fingerprint dataset of the second radio equipment.
[0024] In another embodiment, the ML technique may be a one-class Support Vector Machines (SVM) technique.
[0025] In another embodiment, the ML technique may be an autoencoder technique.
[0026] In another embodiment, the ML technique may be a clustering-based technique. In one embodiment, a result of performing the evaluation of the RF fingerprint of the second radio equipment may comprise data about whether the RF fingerprint of the second radio equipment is within a cluster of RF fingerprints identified in the RF fingerprint dataset of the UE identified using the cluster-based technique.
[0027] In one embodiment, the method may further comprise creating the RF fingerprint dataset for the second radio equipment. In one embodiment, creating the RF fingerprint dataset for the second radio equipment may comprise: (a) selecting values for the set of parameters, (b) sending the selected values for the set of to the second radio equipment, (c) receiving a signal from the second radio equipment responsive to sending the selected values for the set of parameters to the second radio equipment, (d) obtaining an RF fingerprint of the second UE for the selected values for the set of parameters, (e) storing the RF fingerprint of the second UE for the selected values of for the set of parameters in the RF fingerprint dataset of the second radio equipment, and (f) repeating (a) - (e) until a predefined stopping criterion is satisfied.
[0028] In one embodiment the method steps initially mentioned at the beginning of this summary chapter may be performed by a first radio equipment.
[0029] In one embodiment, the first radio equipment may be a network node, and the second radio equipment may be a User Equipment (UE).
[0030] In another embodiment, the first radio equipment may be a first User Equipment UE1 and the second radio equipment may be a second User Equipment UE2.
[0031] Corresponding embodiments of a first radio equipment are also disclosed. In one embodiment, a first radio equipment for a wireless communication system is adapted to send, from the first radio equipment to a second radio equipment in the wireless communication system, values for a set of parameters for acquisition of a RF fingerprint for the second radio equipment. The RF fingerprint comprises data characterizing RF impairments induced by specific hardware of the second radio equipment on a signal received from the second radio equipment, wherein the RF impairments are unique to the second radio equipment. The first radio equipment is further adapted to receive a signal from the second radio equipment in response to sending the values for the set of parameters, obtain an actual RF fingerprint of the second radio equipment based on the signal received from the second radio equipment, and perform an evaluation of the RF fingerprint of the second radio equipment based on a RF fingerprint dataset of the second radio equipment. The RF fingerprint dataset comprises RF fingerprints previously obtained for the second radio equipment for a number, N, of different sets of values for the set of parameters where N is less than a total number, NTOTAL, of all different sets of values for the set of parameters.
[0032] Brief Description of the Drawings
[0033] The accompanying drawing figures incorporated in and forming a part of this specification illustrate several aspects of the disclosure, and together with the description serve to explain the principles of the disclosure.
[0034] Figures 1A and IB are marked-up versions of figures from United States Patent No. 11,184,783B1 entitled "Real-time channel-resilient optimization of radio fingerprinting" highlighting a physical signal modifier required in the disclosed system and methods;
[0035] Figures 1C and ID illustrate the Radio Frequency (RF) fingerprinting system and method disclosed in Patent Cooperation Treaty (PCT) Patent Application Publication No. WO2022 / 187627A1 entitled "Methods, architectures, apparatuses and systems directed to data augmentation of radio frequency (rf) data for improved rf fingerprinting";
[0036] Figure 2 illustrates an example scenario to which embodiments of the present disclosure may be applied in which a base station (BS) in a Radio Access Network (RAN) of a cellular communications system performs authentication of a User Equipment (UE);
[0037] Figure 3 illustrates one use case in which the BS performs a Radio Frequency Fingerprinting (RFF)-based challenge-response authentication procedure described herein to authenticate UEs, in accordance with an embodiment of the present disclosure;
[0038] Figure 4 illustrates another use case in which a UE performs authentication of a BS, in accordance with an embodiment of the present disclosure;
[0039] Figure 5 illustrates another use case in which a UE performs authentication of another UE, in accordance with an embodiment of the present disclosure;
[0040] Figure 6 illustrates another use case in which a BS performs authentication of another BS, in accordance with an embodiment of the present disclosure;
[0041] Figure 7 is a flow chart that illustrates a process performed by a BS for triggering an RF-based challenge-response authentication procedure to authenticate a UE in accordance with one embodiment of the present disclosure;
[0042] Figure 8 is a flow chart that illustrates the RF-based challenge-response authentication procedure to authenticate a UE, in accordance with an embodiment of the present disclosure;
[0043] Figure 9 is a flow chart that illustrates one embodiment of the process for creating or updating the RF fingerprint dataset of the UE in step 804 of Figure 8;
[0044] Figure 10 is a flow chart that illustrates one embodiment of the authentication process (Process 3) of step 806 of Figure 8;
[0045] Figure 11 illustrates an embodiment of the active RF fingerprint acquisition process (Process 4) of step 902 of Figure 9 and step 1002 of Figure 10;
[0046] Figure 12 shows different random data sequences with 16 Quadrature Amplitude Modulation (QAM) modulation; Figure 13 illustrates an example of two random data sequences at different transmitter power with points of interest;
[0047] Figure 14 illustrates one example of a cellular communications system according to some embodiments of the present disclosure;
[0048] Figure 15 is a schematic block diagram of a radio access node according to some embodiments of the present disclosure;
[0049] Figure 16 is a schematic block diagram that illustrates a virtualized embodiment of the radio access node of Figure 15 according to some embodiments of the present disclosure;
[0050] Figure 17 is a schematic block diagram of the radio access node of Figure 15 according to some other embodiments of the present disclosure;
[0051] Figure 18 is a schematic block diagram of a User Equipment device (UE) according to some embodiments of the present disclosure; and
[0052] Figure 19 is a schematic block diagram of the UE of Figure 18 according to some other embodiments of the present disclosure.
[0053] Detailed Description
[0054] The embodiments set forth below represent information to enable those skilled in the art to practice the embodiments and illustrate the best mode of practicing the embodiments. Upon reading the following description in light of the accompanying drawing figures, those skilled in the art will understand the concepts of the disclosure and will recognize applications of these concepts not particularly addressed herein. It should be understood that these concepts and applications fall within the scope of the disclosure.
[0055] Radio Equipment: As used herein, a "radio equipment" is either a radio access node or a wireless communication device.
[0056] Radio Access Node: As used herein, a "radio access node" is any node in a Radio Access Network (RAN) of a cellular communications network that operates to wirelessly transmit and / or receive signals. Some examples of a radio access node include, but are not limited to, a base station (e.g., a New Radio (NR) base station (gNB) in a Third Generation Partnership Project (3GPP) Fifth Generation (5G) NR network or an enhanced or evolved Node B (eNB) in a 3GPP Long Term Evolution (LTE) network), a high-power or macro base station, a low-power base station (e.g., a micro base station, a pico base station, a home eNB, or the like), a relay node, a network node that implements part of the functionality of a base station or a network node that implements a gNB Distributed Unit (gNB-DU)) or a network node that implements part of the functionality of some other type of radio access node, an access point, or the like.
[0057] Core Network Node: As used herein, a "core network node" is any type of node in a core network or any node that implements a core network function. Some examples of a core network node include, e.g., a Mobility Management Entity (MME), a Packet Data Network Gateway (P-GW), a Service Capability Exposure Function (SCEF), a Home Subscriber Server (HSS), or the like. Some other examples of a core network node include a node implementing an Access and Mobility Function (AMF), a User Plane Function (UPF), a Session Management Function (SMF), an Authentication Server Function (AUSF), a Network Slice Selection Function (NSSF), a Network Exposure Function (NEF), a Network Function (NF) Repository Function (NRF), a Policy Control Function (PCF), a Unified Data Management (UDM), or the like.
[0058] Wireless Communication Device: One type of communication device is a wireless communication device, which may be any type of wireless device that has access to (i.e., is served by) a wireless access network (e.g., a cellular network) for communication of voice and / or data. Some examples of a wireless communication device include, but are not limited to: a User Equipment device (UE) in a 3GPP network, a Machine Type Communication (MTC) device, and an Internet of Things (loT) device. Such wireless communication devices may be, or may be integrated into, a mobile phone, smart phone, sensor device, meter, vehicle, household appliance, medical appliance, media player, camera, or any type of consumer electronic, for instance, but not limited to, a television, radio, lighting arrangement, tablet computer, laptop, or PC. The wireless communication device may be a portable, hand-held, computer-comprised, or vehicle-mounted mobile device, enabled to communicate voice and / or data via a wireless connection.
[0059] Network Node: As used herein, a "network node" is any node that is either part of the RAN or the core network of a cellular communications network / system. In other words, as used herein, the term "network node" is a general term that refers to either a radio access node or a core network node.
[0060] Note that the description given herein focuses on a 3GPP cellular communications system and, as such, 3GPP terminology or terminology similar to 3GPP terminology is oftentimes used. However, the concepts disclosed herein are not limited to a 3GPP system.
[0061] Note that, in the description herein, reference may be made to the term "cell"; however, particularly with respect to 5G NR concepts, beams may be used instead of cells and, as such, it is important to note that the concepts described herein are equally applicable to both cells and beams.
[0062] There exist certain challenges with existing Radio Frequency Fingerprinting (RFF) based authentication techniques. Passive RFF suffers from the following vulnerabilities:
[0063] • Vulnerability to impersonation attacks by adversaries who can generate fake Radio Frequency (RF) fingerprints and trick the system into thinking they are a legitimate device; and
[0064] • Difficulty in maintaining the accuracy of the fingerprint database over time due to changes in the RF environment or device hardware.
[0065] Active RFF suffers from the following vulnerabilities:
[0066] • Possible exploitation of the active signal transmission process by attackers to gain information or launch attacks on the device or the network; and
[0067] • Additional power consumption by the device during the active signal transmission process, which can impact battery life and user experience.
[0068] Both passive RFF and active RFF also suffer from the vulnerability where possible interference from other devices in the environment can degrade the quality of the collected data and make it difficult to distinguish between devices.
[0069] The existing RFF-based authentication techniques offer the possibility to identify a radio equipment (e.g., a UE) and potentially detect a basic attacker. However, these existing RFF-based authentication techniques remain limited. For example, considering a scenario in which existing active RFF-based authentication techniques are used by a base station to authenticate a UE, the base station never challenges the UE in any way other than comparing an RFF with an already existing measure in the database. An attacker with enough motivation and resources could bypass security by generating fake RF fingerprints that are similar enough to the RF fingerprint of a legitimate UE.
[0070] In addition, in a single challenge-response system, the authentication relies on a single challenge signal (see, e.g., the '724 Chinese Patent Application). This might not be robust enough if, for example, the device goes to an extreme condition (e.g., transmission at a high output power with the power amplifier close to saturation, temperature of operation far from nominal value (e.g., higher than an upper threshold temperature), and / or load impedance far from nominal value).
[0071] The '783 Patent covers an interesting aspect about channel-resilient RFF optimization. However, it suffers from a significant drawback - in order to be used, it requires the implementation of an additional "physical signal modifier" in the transmitting device. This means that, if for example one desires to apply this method to the radio contained within a UE (e.g., phone, XR headset, or the like), then the radio must contain this specific circuit. This implies additional costs and power consumption for the transmitting device. Moreover, the '783 Patent focuses on the optimization of the RFF so the convolutional neural network can "recognize" the transmitter device and authenticate it. In other words, the '783 Patent discloses an enhanced active fingerprinting method, suffering from the same drawbacks as the other fingerprinting methods available today, i.e., the transmitting device is not challenged and, if an attacker with enough motivation uses a transmitting device with the same kind of embedded Finite Impulse Response (FIR) filter, the transmitting device could be impersonated.
[0072] Improving a passive RFF by de-embedding the channel effects (e.g., as in the '627 PCT Application") has limitations. Passive RFF techniques will not further enhance the non-linearities in the fingerprinted transmitter hardware. The first limitation is the fact that an additional channel estimation and channel de-embedding method is only used for the RFF process, due to the required form of the channel data, which is required to interface with the Machine Learning (ML) engine. Another limitation is that this work utilizes passive RFF, so only channel enhancements and no enhancements of the effects used for the RFF are possible.
[0073] Systems and methods are disclosed herein that address at least some of the aforementioned and / or other challenges. More specifically, systems and methods are disclosed herein for RFF-based authentication of a radio equipment (e.g., a UE) using machine learning and randomizations for which another radio equipment (e.g., a base station or other Radio access node) has an active role in challenging the radio equipment based on that radio equipment's RF fingerprint. In some embodiments, a new challenge generation process is utilized. In this new challenge generation process, the decision on the specific challenge to be presented to the radio equipment for which authentication is to be performed is be based on a set of hardware imperfection parameters, which include their correlations.
[0074] In some embodiments, an RFF-based procedure for authenticating a radio equipment (e.g., a UE) in a wireless network (e.g., a RAN of a cellular communications system) may include performing an RFF-based challenge-response authentication process, where the RFF-based challenge-response authentication process may include, at a first radio equipment (e.g., a base station or other Radio access node), sending, to a second radio equipment (e.g., a UE), a set of values for a set of parameters for acquisition of a RF fingerprint for the second radio equipment, the RF fingerprint comprising data characterizing RF impairments induced by specific hardware of the second radio equipment on a signal received from the second radio equipment, the RF impairments being unique to the second radio equipment. Note that, in one example embodiment, the RF fingerprint may be a vector of numerical values, where each element within this vector quantifies a particular aspect or feature of an RF signal that is relevant to identifying unique characteristics of the second radio equipment. The method further comprises, at the first radio equipment, receiving a signal from the second radio equipment in response to sending the values for the set of parameters. The method further comprises, at the first radio equipment or at a third network equipment (e.g., an edge server of the RAN), obtaining an actual RF fingerprint of the second radio equipment based on the signal received from the second radio equipment and performing an evaluation of the actual RF fingerprint based on an RF fingerprint dataset of the second radio equipment, the RF fingerprint dataset comprising RF fingerprints previously obtained for the second radio equipment for a number, N, of different sets of values for the set of parameters where N is less than a total number, NTOTAL, of all different sets of values for the set of parameters.
[0075] In some embodiments, the method may further comprise creating the RF fingerprint dataset of the second radio equipment.
[0076] In some embodiments, performing the evaluation of the actual RF fingerprint may utilize one or more machine learning (ML) techniques (e.g., one or more nonclustering techniques or one or more clustering-based techniques) to determine whether the RF fingerprint of the second radio equipment is consistent with the structure or trend of data included in the RF fingerprint dataset of the second radio equipment. Embodiments of the present disclosure may provide a number of advantages over existing RFF-based authentication processes. Compared to classic RFF-based authentication methods, embodiments of the present disclosure add another layer of security and trustworthiness. If an attacker with enough motivation and resources could mimic the RF fingerprint of the first radio equipment (i.e., the radio equipment being authenticated) to break the RFF-based authentication method, it will be almost impossible for them to break the RFF-based challenge-response authentication process disclosed herein. Indeed, it is extremely difficult for the attacker to know which sequence and random set of parameters will be requested from the first radio equipment for its prediction-based challenge, in addition to compensating for the legit / attacker channel differences. Introducing randomness in the challenge signals can improve the overall security and reliability of the authentication process.
[0077] Furthermore, in some embodiments, Machine Learning (ML) may be used in such a way that does not require additional computational effort compared to classical RFF- based authentication methods. Instead of predicting the actual RF fingerprint of a response signal to the challenge, a lighter procedure can be run to identify if the actual RF fingerprint is an outlier or not.
[0078] Embodiments of the present disclosure may also be more robust to the false negative type of error, i.e., when the authorized device is misclassified, since, in some embodiments, the first radio equipment being authenticated may be probed with a sequence of signals where the authentication decision can then be made based on several responses rather than just one response.
[0079] While the '783 Patent and the '627 PCT Application offer interesting RF fingerprinting enhancement methods, embodiments of the present disclosure may have a number of advantages and differences in comparison:
[0080] • In comparison with other active fingerprinting methods, embodiments of the present disclosure offer an additional level of security by introducing the RFF- based challenge-response based authentication procedure in which the challenge(s) is randomized.
[0081] • Embodiments of the present disclosure do not rely on additional hardware on the transmitting device (e.g., UE) side, thereby avoiding additional power consumption and cost on the transmitting device. • In some embodiments of the present disclosure, transmitter settings may be changed depending on the needs of the system, e.g., database building or authentication challenge. In the '783 Patent, the physical modifier settings are only used to optimize the fingerprint so the convolutional neural network can perform the authentication. For the '627 PCT Application, the channel data is only used to optimize the fingerprint.
[0082] • In the '783 Patent and the '627 PCT Application, the transmitter parameters (other than the physical signal modifier block in the '783 Patent) are not modified, meaning that there is no active control of the main transmitter device to actively build its fingerprint database.
[0083] • In some embodiments of the present disclosure, a ML engine is utilized, where the ML engine is not just used for RFF authentication (and / or optimization as in the '783 Patent and the '627 PCT Application) but also for the active RFF database building, transmitter parameters updates, challenge-related parameters, and challenge-related predictions.
[0084] Now, a more detailed description of embodiments of the present disclosure will be provided. The description is divided into the following sections:
[0085] • Section 1: This section describes the scenario and different use cases for which embodiments of the present disclosure may be applied.
[0086] • Section 2: This section describes procedures for RFF-based challenge-response authentication, in accordance with embodiments of the present disclosure.
[0087] • Section 3: This section described ML procedures associated with the RFF-based challenge-response authentication of Section 2.
[0088] • Section 4: This section provides a list of parameters and how these parameters affect the RFF-based challenge-response authentication of Section 2.
[0089] • Section 5: This section elaborates an example of the RFF-based challengeresponse authentication of Section 2 for authentication of a UE.
[0090] • Section 6: This section deals with one example of a cellular communications system in which embodiments of the present disclosure may be implemented.
[0091] 1 Scenario and Use-Cases
[0092] The RFF-based challenge-response authentication procedure described herein is generally utilized in the context of a wireless network (e.g., a RAN of a cellular communications system, a WiFi network, or the like) in which a first radio equipment (e.g., a base station (e.g., next generation NodeB (gNB) in a RAN of a cellular communications system, an access point in a wireless network such as, e.g., a WiFi network, etc.) performs authentication of a second radio equipment (e.g., a UE). For the sake of clarity, one example scenario is utilized for the description herein. This example scenario is one in which a base station (BS) 200 in a RAN of a cellular communications system performs authentication of a UE 202, as illustrated in Figure 2. Note, however, that the RFF-based challenge-response authentication procedure described herein may be utilized in any type of wireless network such as, e.g., a RAN of a 4thGeneration (4G, LTE), 5G, or in a future 6thGeneration (6G) cellular communications system, a WiFi network, a Bluetooth network, or the like.
[0093] Figure 3 illustrates one use case for such a scenario in which the BS 200 performs the RFF-based challenge-response authentication procedure described herein to authenticate UEs and thereby identify both legitimate UEs (e.g., UE1 202-1 and UE2 202-2 of Figure 3) and also illegitimate (e.g., attacker) UEs (e.g., UE3 202-3 in the example of Figure 3). In the example of Figure 3, UE3 is attempting to impersonate UE2 and, via the RFF-based challenge-response authentication procedure described herein, the BS 200 is able to identify UE3 as an attacker, in which case authentication would fail for UE3.
[0094] It is worth mentioning that the RFF-based challenge-response authentication procedure described herein is also compatible with other scenarios and use-cases. Some non-limiting examples are as follows:
[0095] - A UE performing authentication of a radio access node (e.g., a BS or an access point (AP)). This scenario can be applied to use cases such as detecting a fake BS 200-2 (authentication failure) as compared to detecting a real BS 200-1 (authentication success), as illustrated in Figure 4.
[0096] - A UE performing authentication of another UE. This scenario can be applied to use cases such as detecting an impersonating UE in the network for device-to- device communication. An example is illustrated in Figure 5 in which the UE 202- 1 performs the authentication of the UE 202-3, which is impersonating the UE 202-2. The authentication of the UE 202-3 fails.
[0097] - A radio access node (e.g., a BS) performing authentication of another radio access node (e.g., another BS). This scenario can be applied to use cases such as detecting a fake BS in the network, as illustrated in Figure 6. In the example of Figure 6, BS 200-2 performs authentication of BS 202-1 and BS 202-3, where authentication of the BS 200-1 is successful and authentication of BS 200-3 (i.e., the fake BS) fails.
[0098] 2 RFF-Based Challenge-Response Authentication
[0099] Figure 7 is a flow chart that illustrates a process performed by a BS, such as BS 200 in Fig. 5 for triggering an RF-based challenge-response authentication procedure to authenticate a UE, such as UE 202-1 or UE 202-2 in Fig. 5. in accordance with one embodiment of the present disclosure. Note that the process of Figure 7 is only an example of a procedure that may be used to trigger the authentication procedure. In other words, the RF-based challenge-response authentication procedure described further down in conjunction with Figure 8 may be triggered by a procedure other than that of Figure 7.
[0100] As illustrated, the BS receives, from the UE, a request to connect to the BS (step 700). The BS determines whether RF-based challenge-response authentication is necessary or otherwise desired (step 702). If so, the BS performs channel estimation (step 704). Note that any existing or hereafter developed channel estimation procedure may be used, as channel estimation is not central to the present disclosure. The resulting channel state information (CSI) data is stored (step 706). The BS then initiates, or triggers, the RF-based challenge-response authentication procedure (see Figure 8) to authenticate the UE (step 708). This process is also referred to herein as "Process 1".
[0101] Note that, in this example, if the RF-based challenge-response authentication procedure is not necessary or is otherwise not desired (e.g., UE previously authenticated with the RF-based challenge-response authentication procedure, e.g., within a predefined or configured amount of time, any scenario in which only the sender but not the device (i.e., UE) needs to be verified, RF-based challenge-response authentication procedure is not supported by the BS, or the BS decides or is configured to use some other authentication procedure), the BS may, for example, perform channel estimation (step 710), store the resulting CSI data (step 712), and perform a conventional authentication procedure to authenticate the UE (step 714). Figure 8 is a flow chart that illustrates the RF-based challenge-response authentication procedure to authenticate a UE, in accordance with an embodiment of the present disclosure. In this example, the process of Figure 8 is performed by the BS. Note, however, that some or all of the steps of Figure 8 may be performed by another network node (e.g., an edge node of a RAN of a cellular communications system) that is communicatively coupled to the BS. Optional steps are represented by dashed lines / boxes.
[0102] As illustrated, the BS selects a frequency band (e.g., Frequency Range 1 (FR1) or Frequency Range 2 (FR2) in the case of a 3GPP cellular communications system) and standard (e.g., LTE or NR in the case of a 3GPP cellular communications system) depending on one or more factors (step 800). These factors may include, but are not limited to, UE hardware, Mobile Network Operator (MNO) needs, access point hardware, etc. In another embodiment, the standard and frequency band may be otherwise selected, configured, or predefined.
[0103] The BS determines whether an RF fingerprint dataset for the UE needs to be created or updated (step 802). For example, the RF fingerprint dataset for the UE may need to be created if the UE has never been identified and authenticated by the BS (or alternatively by any other BS in the network in the case where BSs share such RF fingerprint datasets). As another example, an RF fingerprint dataset, or some portion of the RF fingerprint dataset, of the UE may expire after a predefined or configured amount of time, in which case the BS may determine that the RF fingerprint dataset of the UE, or some portion of the RF fingerprint dataset of the UE, has expired.
[0104] The RF fingerprint dataset for the UE includes actual RF fingerprints obtained (e.g., measured) for this particular UE for multiple different sets of values for a set (e.g., a predetermined or preconfigured set) of parameters for acquisition of RF fingerprints for the UE. The set of parameters include one or more, but preferably multiple, parameters that impact the RF fingerprint of the UE. Some example parameters may include, but are not limited to, output power of a transmitter of the UE, carrier frequency that the transmitter of the UE uses for transmitting a signal used for RF fingerprint acquisition, a frequency offset between a Local Oscillator (LO) of the transmitter of the UE and a baseband frequency and / or an Intermediate Frequency (IF) used by the transmitter of the UE, carrier bandwidth of a carrier on which the transmitter of the UE transmits a signal used for RF fingerprint acquisition, etc. Additional details regarding parameters that may additionally or alternatively be used are provided in Section 4 below.
[0105] Importantly, the number (N) of different sets of values for the set of parameters for which actual RF fingerprints are included in the RF fingerprint dataset is less than the total number (NTOTAL) of all possible sets of values for the set of parameters. As discussed below, in some embodiments, the RF fingerprint dataset is used to identify expected, or predicted, behavior for sets of values for the parameters for RF fingerprint acquisition for which actual RF fingerprints have not been obtained and stored in the RF fingerprint dataset. In some other embodiments, the RF fingerprint dataset may be used to train a ML model that outputs a RF fingerprint prediction, which may be a precise RF fingerprint or data that defines a range of fingerprint values, for a given set of values for the parameters for RF fingerprint acquisition.
[0106] If the RF fingerprint dataset for the UE needs to be created or updated (step 802, YES), the BS performs a process for creating, or building, the RF fingerprint dataset or updating the RF fingerprint dataset for the UE (step 804). This process is also referred to herein as "Process 2". The details of this process are described below with respect to Figure 9.
[0107] Whether proceeding from step 804 or the "NO" branch of step 802, the BS performs RFF-based challenge-response authentication of the UE (step 806). This is referred to herein as "Process 3", which is described in detail below with respect to Figure 10.
[0108] The BS then authorizes or rejects the connection request from the UE based on the result of the authorization process of step 806 (step 808). This is done, for example, by sending an appropriate message to the UE.
[0109] Figure 9 is a flow chart that illustrates one embodiment of the process for creating or updating the RF fingerprint dataset of the UE in step 804 (i.e., Process 2). As illustrated, the BS selects initial values for a set of parameters used for RF fingerprint acquisition (step 900). Exemplary parameters that may be included in the set of parameters used for RF fingerprint acquisition are described in Section 4 below. For example, the set of parameters may include transmit power to be used by a transmitter of the UE for transmission of a signal for RF fingerprint acquisition and / or a carrier bandwidth on which the UE is to transmit the signal for RF fingerprint acquisition. In one embodiment, the BS selects the initial values for the set of parameters, or at least initial value(s) for one or more parameters in the set of parameters, are selected randomly (i.e., pseudo-randomly) from respective sets of candidate values (e.g., all possible values) of those parameters. In another embodiment, when creating the RF fingerprint dataset or updating the RF fingerprint dataset for the UE, the different sets of values for the set of parameters may be a predefined or configured subset of all possible sets of values for the set of parameters. For example, if there are NTOTAL possible sets of values for the set of parameters, N< NTOTAL of those NTOTAL possible sets of values to be used to create / update the RF fingerprint dataset of the UE may be predefined or preconfigured, e.g., based on simulations that indicate which sets of values provide the best overall performance of the RFF-based challenge-response authentication procedure described herein.
[0110] The signal to be transmitted by the UE for RF fingerprint acquisition is a pseudorandom data sequence for a given modulation and the initial values for the set of parameters. This pseudo-random data sequence preferably goes through all constellation points of the modulation and, therefore, the length of the data sequence is based on the modulation.
[0111] The BS then runs an active RF fingerprint acquisition process (also referred to herein as "Process 4") (step 902). In one embodiment, the active RF fingerprint acquisition process is a conventional active RF fingerprint acquisition process that uses the values for the set of parameters selected in step 900. Further details regarding step 902 (i.e., Process 4) are provided below with respect to Figure 11. The result of the RF fingerprint acquisition process includes data (referred to herein as "RFF data") from which an RF fingerprint of the UE can be extracted. In one embodiment, the RFF data may be a digital representation of the signal received from the UE for RF fingerprint acquisition (e.g., digital data corresponding to the received signal, or the received modulated symbols, after signaling processing (e.g., filtering, downconversion, ADC, etc.)).
[0112] The BS, or more specifically a Machine Learning Engine (MLE) that is implemented at the BS (or alternatively at another network node such as, e.g., an edge server), retrieves (e.g., from memory or other digital storage or from the output of Process 4) the RFF data obtained via the active RFF acquisition process of step 902 (step 904). The BS, or more specifically the MLE, performs RF fingerprint extraction to thereby extract, from the RFF data, an RF fingerprint of the UE for the given values of the set of parameters (step 906). The RF fingerprint extraction process may, for example, use an ML technique such as, e.g., a supervised learning technique (e.g., see further details in Section 3 below). The BS, or MLE, stores the RF fingerprint of the UE extracted in step 906 in the RF fingerprint dataset of the UE (step 908). In the RF fingerprint dataset of the UE, this RF fingerprint is associated to the values of the set of parameters used in step 902 for the active RFF acquisition process (Process 4).
[0113] The BS, or MLE, determines whether to stop the creation / update process (step 910). For example, if enough (e.g., non-expired) RF fingerprints are stored in the RF fingerprint database for UE authentication (e.g., if a threshold number of (e.g., nonexpired) RF fingerprints are stored in the RF fingerprint database), then the process can be stopped (step 910, YES). Otherwise, the MLE selects a new set of values for the set of parameters for RF fingerprint acquisition for the UE (step 912) and the process returns to step 902 and is repeated. Note that the data sequence used for each iteration may be the same data sequence or a different data sequence. However, at least one value for the set of parameters changes from one iteration to another.
[0114] Figure 10 is a flow chart that illustrates one embodiment of the authentication process (Process 3) of step 806 of Figure 8. This process may be performed by the MLE, which may be implemented at the BS or alternatively at another network node (e.g., an edge node). Note that while actions are performed by the MLE implemented at the BS, these actions may also be referred to herein as being performed by the BS. As illustrated, the MLE selects a set of values for the set of parameters used for RF fingerprint acquisition for the UE (step 1000). Importantly, one or more of the set of values for one or more respective parameters in the set of parameters used for RF fingerprint acquisition are selected randomly (e.g., pseudo-randomly). Thus, it is possible, and likely, that the set of values selected for the set of parameters in step 1000 is different than any set of values for which an RF fingerprint of the UE is stored in the RF fingerprint dataset of the UE. For the remainder of this discussion, it is assumed that the set of values selected for the set of parameters in step 1000 is different than any set of values for which an RF fingerprint of the UE is stored in the RF fingerprint dataset of the UE. It is worth noting that the data sequence used by the UE for transmission of the signal used for RF fingerprint (using the selected values of the set of parameters) can be the same or different that that used when creating the RF fingerprint dataset of the UE and is, in one embodiment, randomized. The MLE then runs an active RF fingerprint acquisition process (also referred to herein as "Process 4") using the values selected for the set of parameters in step 1000 (step 1002). In one embodiment, the active RF fingerprint acquisition process is a conventional active RF fingerprint acquisition process that uses the values for the set of parameters selected in step 1000. Further details regarding step 1002 (i.e., Process 4) are provided below with respect to Figure 11. The result of the RF fingerprint acquisition process includes data (referred to herein as "RFF data") from which an RF fingerprint of the UE can be extracted. In one embodiment, the RFF data is a digital representation of the signal received from the UE for RF fingerprint acquisition (e.g., digital data corresponding to the received signal, or received modulated symbols, after signaling processing (e.g., filtering, downconversion, ADC, etc.)).
[0115] The MLE retrieves (e.g., from memory or other digital storage or from the output of Process 4) the RFF data obtained via the active RFF acquisition process of step 1002 (step 1004). The MLE performs RF fingerprint extraction to thereby extract, from the RFF data, an RF fingerprint of the UE for the selected values of the set of parameters (step 1006). The RF fingerprint extraction process may, for example, use an ML technique such as, e.g., a supervised learning technique (e.g., see further details in Section 3 below).
[0116] The MLE evaluates the RF fingerprint extracted in step 1006 based on the RF fingerprint dataset of the UE to determine whether the UE that transmitted the signal from which the RF fingerprint was extracted in steps 1002 and 1004 is the trusted UE (i.e., determines whether the UE is authenticated) (step 1008). More specifically, as described in detail in Section 3 below, the MLE uses a non-clustering technique (e.g., Principal Component Analysis (PCA), one-class Support Vector Machines (SVM), regression models, or autoencoders) or a cluster-based technique to analyze the RF fingerprint dataset (e.g., to learn the underlying structure of the data). This analysis discerns and models the intricate variations and correlations within the RF fingerprint dataset, thereby interpreting its underlying structural and statistical properties. This can be done as part of step 1008 or as a separate process after completion of Process 2 and before Process 3 begins (or at least before step 1008 begins). The resulting model (e.g., a transformed RF fingerprint dataset resulting from PCA, one or more trained autoencoders, a one-class SVM, or data representing a cluster-based model of the RF fingerprint dataset resulting from a cluster-based analysis of the RF fingerprint dataset) is then utilized by the MLE in step 1008 to evaluate the RF fingerprint extracted in step 1006. A result of this evaluation is data indicative of whether the RF fingerprint is consistent with the model (e.g., number of standard deviations that a PCA transformed version of the RF fingerprint is from the mean of the PCA-transformed RF fingerprints in the PCA-transformed RF fingerprint dataset, the 'residual' in the case of once-class SVM, a reconstruction error in the case of autoencoders, or data that indicates whether the RF fingerprint fits well into an existing cluster identified by a clustering-based technique). The MLE decides whether the UE is authenticated or not or whether an additional challenge is needed, based on the result of the evaluation of step 1008 (step 1010). If additional challenge(s) is needed, the process returns to step 1000 and is repeated. Otherwise, the result of the authentication (i.e., success or fail) is returned (e.g., from Process 3 to Process 2 where the BS sends an appropriate response to the UE) (step 1012).
[0117] Figure 11 illustrates an embodiment of the active RF fingerprint acquisition process (Process 4) of step 902 of Figure 9 and step 1002 of Figure 10. As illustrated, the BS sends a request to the UE transmit a signal including a specific data sequence using a set of values for a set of parameters selected in step 900 of Figure 9 or step 1000 of Figure 10 step 1100).
[0118] In response, the UE transmits a signal including the specific data sequence using the indicated values for the set of parameters (step 1102).
[0119] At the BS, the BS waits for the UE to transmit the signal (step 1104). Once the signal is transmitted by the UE, the BS receives the signal from the UE (step 1106). The BS performs signal processing on the signal (e.g., filtering, downconversion, ADC, etc.) to provide RFF data for the UE (step 1108) and stores the RF data for the UE (1110). The RFF data includes digital data that represents the received signal such as, e.g., digital data that represents the modulated sequence carried by the received signal. This modulated sequence can be demodulated and utilized when extracting the RF fingerprint in step 906 of Figure 9 or step 1006 of Figure 10 and / or during evaluation of the RF fingerprint in step 1008 of Figure 10.
[0120] It is worth noting that the active RFF acquisition process (Process 4) can be summarized as running an RFF acquisition procedure (e.g., a conventional RFF acquisition procedure) but with a custom set of instructions. 3 ML Procedures
[0121] In this section, ML procedures are described which can be used for RF fingerprint extraction in step 906 of Figure 9 and step 1006 of Figure 10. In addition, ML procedures are described which can be used in the evaluation of the actual RF fingerprint of the UE obtained during UE authentication (i.e., in step 1008 of Figure 10). The task of ML procedure in this content is to build an ML model to identify the UE based on its hardware unique imperfections.
[0122] 0)
[0123] In one embodiment, the RF fingerprint dataset is created as a differential database for a single trusted UE depending on variations in the values for the set of parameters used for RF fingerprint acquisition, where the set of parameters define various sources of hardware imperfections at the UE. A set of samples each corresponding to a different set of values for the set of parameters are used as input data for a training phase for the differential database. This set of samples are used in the iterations of the process (Process 2) of Figure 9. The range of possible values of these parameters can vary widely depending on the specific device, technology, and operating conditions. It is desirable to select realistic values for these parameters based on the actual hardware specifications or measurements, as well as the target application's requirements.
[0124] Let us say one has n different sources of hardware imperfections each corresponding to a different parameter. Each parameter has its range of possible values denoted here as [min_i, max_i]. Thus, for n parameters, the minimum and maximum values for the n parameters may be defined by two vectors as: min_values = [min_l, min_2, ..., min_n] max_values = [max_l, max_2, ..., max_n]
[0125] Having a reasonable range of values for each the parameters, different combinations of values can be checked (e.g., used as one of the samples, or sets of values, used to create or update the RF fingerprint dataset for the UE, depending on the correlation between the parameters. For that, the correlations between the parameters are defined and used to build a correlation matrix. To pick a random sample (i.e., a random set of values) for the set of parameters considering their correlations, a multivariate normal distribution, which generates random values for multiple variables while preserving the specified correlation structure, can be used, as an example. The goal is to not simply acquire the RF fingerprint of the UE for a particular set of values for the set of parameters, but to be able to predict the RF fingerprint of the UE for any set of values for the parameters within the permissible ranges of values for those parameters. For the training phase, existing ML models can be used to learn the RF fingerprint of the UE for a particular set of values for the set of parameters (e.g., in step 906 of Figure 9). An example of an existing ML model that can be used is a Convolutional Neural Network (CNN). Another example is RNN. To get a robust RF fingerprint against temporal variations, in one embodiment, channel estimation may be carried out regularly.
[0126] (ii)
[0127] Let us consider one reference point in the modulation constellation for a certain modulation. By varying the values of the parameters mentioned above, different measurements around the reference point would be obtained and, for each of such variations, the RF fingerprint is stored. This would define a cluster in the RF fingerprint feature space for a single UE and single constellation point having different possible variations of values of the parameters. The dimension of the feature space would depend on the number of parameters. The number of clusters would be equal to the number of constellation points in the modulation constellation (i.e., a separate cluster would be created for each constellation point in the modulation constellation). It could also be possible to enhance the method efficiency by using signal crossings as well as the constellation diagram points (mentioned in Section 4), where in this case the number of clusters could differ.
[0128] To make sure that we have enough measurements to capture all possible variations within the set of parameters within one cluster, stability of the clustering can be checked (e.g., in step 910 of Figure 9). If the cluster structure does not change significantly (e.g., more than a predefined or configured threshold degree of change) upon the addition of new points (i.e., addition of new RF fingerprints for new sets of values for the parameters), it may indicate that there are enough points for a reliable prediction (e.g., Process 2 may end).
[0129] After the BS challenges the UE and a new 'unseen' signal is received (i.e., a signal for a set of values for the parameters for which an RF fingerprint is not included in the RF fingerprint dataset of the UE), e.g., in steps 1000 - 1006 of Figure 10, the task is to determine whether the extracted RF fingerprint for this new 'unseen' signal correspond to the UE under consideration or not. This is done in step 1008 of Figure 10. The determination, or evaluation, performed in step 1008 of Figure 10 can be performed, for example, using either a non-clustering approach or a cluster-based approach, examples of which are described below.
[0130] Non-clustering approach (1): To recognize patterns or trends in multidimensional RF fingerprints (also referred to as RF fingerprint feature vectors) (i.e., points in a multi-dimensional space) such as the RF fingerprint dataset of the UE created via the process of Figure 9 (Process 2), a variety of non-clustering techniques such as Principal Component Analysis (PCA), one-class Support Vector Machines (SVM), regression models, or autoencoders can be used. Using such a non-clustering technique, an understanding and modeling of the underlying structure of the data can be made and used to make a further decision for unseen data as within the learned data structure or outside (e.g., decision about about RF fingerprints of the UE for sets of values for the parameter for which an actual RF fingerprint of the UE is not stored in the RF fingerprint dataset of the UE). Depending on the model used, different metrics can be employed to compare the predicted results with the learned pattern, aiding in determining if the result can be trusted or not. In PCA, the number of standard deviations a point lies from the mean of the 'normal' distribution can be used to determine whether the 'unseen' RF fingerprint can be trusted or not (i.e., whether the UE can be authenticated or not). For One-Class SVM, the 'residual' could be interpreted as the distance of a point from the decision boundary. In the case of autoencoders, the reconstruction error can be used. In other words, one can check if the RF fingerprint extracted from the newly received signal belongs to the UE under consideration or not.
[0131] Example (1): The following example elaborates on how PCA could be used in detail. Let us say that data (raw IQ data) from N sets of values of the parameters is obtained step 902 over N iterations of the process (Process 2) of Figure 9. In each iteration of the process (Process 2), in step 906 of Figure 9, this data can be used to extract, or learn, the RF fingerprint of the UE for the respective set of values of the parameters. Here, this means that the feature vector of the RF fingerprint is extracted. The dimensionality of the feature vector will depend on the architecture of the network. If the last fully connected layer before the classification layer has 128 nodes, then the feature vector will be 128-dimensional, which consist of floating-point numbers. In total, there would be N such vectors (i.e., one such vector for each different set of values of the parameters used to create the RF fingerprint dataset of the UE).
[0132] After the RF fingerprints (i.e., the feature vectors defining the RF fingerprints) are generated and saved in the RF fingerprint dataset of the UE, the UE authentication process (Process 3) of Figure 10 can be performed. Let us note that several RF fingerprints would correspond to the one trusted UE, i.e. we are dealing with a one- class problem in machine learning.
[0133] The RF fingerprint feature vectors, i.e., points from this multi-dimensional space) are used as input to a ML model which would learn the trend and map with analytical function if possible (PCA, one-class SVM, regression model, autoencoder). In general, the process of applying these techniques would not be different when it comes to RF fingerprints compared to other types of input data. For example, the general steps of PCA - standardizing the data, calculating the covariance matrix, obtaining the eigenvalues and eigenvectors, and transforming the data - would remain the same. However, there are certain aspects that one needs to consider with RF fingerprints such as, e.g., scaling of the features and noise handling and linear vs non-linear relationships.
[0134] Let's assume that the RF fingerprint dataset of the UE includes 1,000 RF fingerprints (i.e., 1,000 feature vectors), where each feature vector has 128 dimensions, and that PCA is performed on this RF fingerprint dataset. The output of PCA would be another 1000x128 matrix, but this time each row (i.e., each RF fingerprint feature vector) is expressed in terms of principal components instead of the original features.
[0135] Let's now say that only the first 10 principal components are kept because they capture most of the variance in the data. This would reduce the dimensionality of the dataset from 128 to 10. A new PCA-transformed dataset would now be a 1000x10 matrix.
[0136] After one has established the normal operating condition in this reduced- dimensionality space (let's assume it's within 3 standard deviations of the mean), one can use this model to evaluate new RF fingerprints. When a new RF fingerprint is obtained in steps 1000-1006 of the UE authentication process (Process 3) of Figure 10, in the evaluation of step 1008, the MLE would first transform the new RF fingerprint into the principal component basis using the same PCA transformation that was obtained from the RF fingerprint dataset. This will give a 10-dimensional vector for this new RF fingerprint. Then, one would calculate its distance to the mean of the PCA-transformed dataset in this 10-dimensional space. If the distance is within the 3 standard deviations which was defined earlier, the MLE concludes that this new RF fingerprint is behaving normally, i.e., according to the trend and therefore the MLE decides that the UE is to be authenticated.
[0137] This threshold defining a point to be within a 'normal' pattern can be determined by the acceptable level of false positives and false negatives in the specific application, or other relevant metrics such as the desired security level. Setting a lower threshold may increase the false positive rate (i.e., new data points being labeled as 'normal' when they should not be), while setting a higher threshold may increase the false negative rate (i.e., new data points not being labeled as 'normal' when they should be). When dealing with device security, is to reduce the false positive rate as much as possible without significantly increasing the false negative rate.
[0138] Cluster-based approach (2): After the BS challenges the UE in steps 1000 and 1002 of Figure 10 and a new 'unseen' signal is received and processed to extract a new RF fingerprint in steps 1004-1006 of Figure 10, the task in step 1008 is to not only determine whether the new RF fingerprint is within a cluster for each constellation point but also identify a trend or pattern among the points in a specific cluster as discussed in the previous approach. Identification of the RF fingerprint to be within or outside the cluster can be done manually (e.g., based on Euclidean distance between two points in a multidimensional space) or by using additional ML techniques, such as anomaly detection or density-based clustering. These are two commonly used techniques in unsupervised machine learning for identifying anomalies or outliers in data. The choice of the metric depends on the specific clustering or anomaly detection technique being used. For example, in anomaly detection, Mahalanobis distance or z-score can be used to measure the deviation of the new set of features from the normal behavior of the cluster. After that, the classification procedure can be used to assign the new RF fingerprint to the appropriate cluster if it is not an outlier.
[0139] If a certain RF fingerprint is not an outlier, we propose to identify if the new RF fingerprint follows a certain pattern of the stored data.
[0140] In the UE authentication process (Process 3), the BS may ask the UE to transmit several signals (e.g., additional challenges may be needed in which case additional iterations of steps 1000-1010 are performed). In this case, the threshold to decide if the new RF fingerprint is an outlier or not might be not very tight. Alternatively, the MLE one can request from the UE transmission of a signal using a specific change of the values for the parameters for which the MLE would know the direction of the cluster with respect to the known RF fingerprints.
[0141] Example (2): This example illustrates an example of the cluster-based approach in greater detail. Some of the existing clustering approaches make it possible not to just classify a point as inlier or outlier but also to define a direction (or trend) within the data. The recent work on the CDC (Boundary-Seeking Clustering using local Direction Centrality) algorithm (see, e.g., D. Peng et al, "Clustering by measuring local direction centrality for data with heterogeneous density and weak connectivity," Nature Communications, Vol. 13, 5455, September 16, 2022) can do this in high-dimensional space. It calculates the local direction centrality by measuring the directional uniformity of the K-nearest neighbors (KNNs) within a cluster. This means that it analyzes the consistency of the mean-shift directions of neighboring points in each direction. The algorithm measures the directional relationships between data points within a cluster to distinguish between internal and boundary points. By doing so, it can identify the internal points within a cluster that tend to be surrounded by their KNNs in all directions.
[0142] Using this approach for RF fingerprints can be performed as follows:
[0143] • Run the CDC algorithm on the multidimensional RF fingerprint dataset of the UE. This will identify clusters (here, we mean that our input data can be characterized by several clusters), effectively learning the "trends" present in the data. Determine the optimal parameters (k and TDCM) for the dataset as the CDC algorithm is highly dependent on these.
[0144] • For each point in the dataset, calculate the Direction Centrality Metric (DCM) value. Once the DCM values are calculated, use these values to determine whether each point is an internal point or a boundary point.
[0145] • Once the clusters are determined and which points are boundary and which are internal is determined, the clusters are analyzed to understand the characteristics of each cluster. This can include understanding the centroid of the cluster, the density of the cluster, the shape or the range of values in each dimension, etc.
[0146] • When a new RF fingerprint (new data point) is obtained during steps 1000-1006 of the UE authentication process (Process 3) of Figure 10, in step 1008, the MLE calculates a Direction Centrality Metric (DCM) for the new RF fingerprint using the same k that was used for the original dataset. This will help to identify whether it is a boundary point or an internal point.
[0147] • Depending on the characteristics of the new RF fingerprint (new datapoint) and the clusters, the MLE decides to which cluster (if any) the new RF fingerprint belongs. This could be done based on a variety of factors such as, e.g., proximity to cluster centroids, similarity in DCM values, etc.
[0148] • If the new RF fingerprint fits well into an existing cluster, the MLE considers the new RF fingerprint as fitting the trend (i.e., decides that the UE is to be authenticated). If the new RF fingerprint does not fit well into any existing cluster, or if its DCM value suggests that it is significantly different from the DCM values of points in the closest cluster, the MLE considers the new RF fingerprint as not fitting the trend (i.e., decides that the UE is not to be authenticated). In this context, the new RF fingerprint fits well into an existing cluster if any one (or more) of the following is true: the corresponding point is close to the centroid of a cluster; the point lies in a region with a similar density to one of the clusters; the point falls within the general shape or boundary of a cluster when considering the cluster's distribution in the feature space; or the point has a DCM value similar to the points within a cluster. In general, "fit well" is defined by statistical thresholds or cutoffs based on standard deviations or other measures from the cluster's central tendency.
[0149] The choice between a cluster-based (like CDC) and a non-cluster approach may depend on the data. Clustering algorithms, such as CDC, work best when the data has distinct, separable groups or "clusters". They excel at finding structure in the data. If the data does not naturally separate into groups, a clustering approach may not be appropriate. In contrast, PCA or autoencoders can be used to simplify complex datasets by reducing their dimensionality, even if there are not distinct clusters.
[0150] It is also important to note that these methods can often complement each other. For example, one might use PCA to reduce the dimensionality of the data before applying a clustering algorithm or one-class SVM. 4 Parameters
[0151] This section contains a list of the different exemplary parameters that may be used as parameters in the set of parameters used for RF fingerprint acquisition as described herein. Note that the set of parameters may include any one or any combination of two or more of the following parameters. In addition, the set of parameters may include one or more parameters not described below as the following are only examples. In the following description, the parameters are categorized into four different categories, which highlight the level at which they are used. First, "the fundamental parameters", which are parameters on a higher level, i.e. at radio-system level; Secondly, "parameters to enhance / effect the hardware non-idealities, circuit biasing", these affect the active components / circuits in the radio hardware and alter and / or enhances the non-idealities of the active components; Third, "parameters to enhance / effect the hardware non-idealities, frequency tuning", which are parameters, for instance, used to change the center-frequencies of resonators in the radio hardware and / or parameters to change cut-off frequencies in filters (both in the baseband and at RF); and the fourth type, "Parameters to enhance / effect the hardware non-idealities, error calibration", these parameters can change the characteristics of calibration-circuits used to correct for hardware non-idealities within the radio hardware and these can be used to generate unique non-idealities, since the calibration often have a different behavior than the main radio hardware.
[0152] Examples of fundamentalese parameters are:
[0153] • Output power of the transmitter, this relates to average power of the transmitted signal, but also to the peak-to-average of the transmitted signal has a significant effect. o Output power affects the following non-idealities used for RFF, power amplifier (PA) Inter-Modulation Distortion (IMD), which affects Error Vector Magnitude (EVM) and Adjacent-Channel Leakage Ratio (ACLR). Further, output power variance also affects PA Amplitude Modulation (AM)-AM and AM-Phase Modulation (PM) distortion, which relates to EVM, and also has a large effect on the memory-effects in the PA, due to selfheating of the PA itself. Finally, the output power also affects the harmonic content in the transmitted signal. • Carrier frequency is related to the Local-Oscillator (LO), and this relates to changes in the frequency-synthesizer / generator block. o Carrier frequency variation effects the behavior of the IMD in the transmitted signal, the AM-AM and AM-PM distortion (non-linear capacitors in the transmitter have different behavior at different frequencies), and the spurious tones in the LO itself, due to mechanisms in the frequencysynthesizer.
[0154] • Frequency offset relates to the frequency difference between the LO and the baseband frequency, the Intermediate Frequency (IF). o Frequency offset affects the IMD generated within the frequency up- converter (mixer) and also the cartesian-errors (amplitude and phase), while it may also affect the shape of the modulated carrier, due to baseband filtering (BB signals are partly in the stop-band transitions).
[0155] • Carrier Bandwidth (BW) can be changed without changing the BW of the actual channel used for the transmission. o The carrier BW has an effect on the non-idealities with memory, i.e. the memory-effect, and these effects have an impact on EVM and ACLR, also due to the momentaneous temperature of the transmitter hardware. In addition, the carrier BW also has an effect on the RF fingerprint extraction, itself, and mainly because the receiver used for RF fingerprint extraction has full sensitivity in the frequencies around the carrier (i.e., in the "adjacent channels").
[0156] Parameters to enhance / effect the hardware non-idealities, circuit biasing:
[0157] • PA biasing (also includes biasing of the PA driver), functions that control the supply voltage and the transistor bias currents. o PA biasing affects PA, IMD, AM-AM, and AM-PM-distortion, which affects EVM and ACLR. Additionally, PA biasing has a large effect on the memoryeffects in the PA, due to self-heating of the PA.
[0158] • Mixer biasing (may also include biasing of LO drivers), sets the gate-voltages of the LO-switch transistors in both the ON-and OFF-state. o The mixer biasing affects LO-leakage, Cartesian-error, IMD (HD), AM-AM- distortion, in-band-, and out-of-band-noise, mainly amplitude noise, but also phase-noise. • Frequency-synthesizer biasing alters mainly the characteristics of the feedback loop of the synthesizer, this may affect stability and transfer functions (open-loop and closed-loop) of the frequency-synthesizer. o By altering the frequency-synthesizer biasing, spurious-signal content is altered, noise suppression caused by the feedback-loop may also be altered, and alteration of loop-stability causes spurious tones at the unity frequency. Further, poor loop-stability may also cause ringings which results in noise-like spurious content. Finally, biasing of the charger-pump enhances / increases the non-linear behavior / transfer of the charger-pump, which affects noise and spurious content in the LO.
[0159] • Oscillator biasing, functions that control the supply voltage and the transistor bias currents, which sets LO amplitude and voltage-and current-saturation. o Oscillator biasing controls in-band- and out-of-band-phase-noise, but also the out-of-band spurious content.
[0160] • Digital-to-Analog Converter (DAC) biasing sets the performance of the hardware in the DAC. o By varying the biasing of the DAC, the amount of quantization-noise and its characteristics is changed, thermal noise is also affected by the DAC biasing.
[0161] Parameters to enhance / effect the hardware non-idealities, frequency tuning may be:
[0162] • Transmitter radio frequency (RF)-chain frequency tuning, resonators may be tuned with switch-capacitor circuits for a frequency-optimized frequencyresponse of the TX RF signal chain. o Frequency tuning affects the behavior of the IMD in the transmitted signal, the AM-AM and AM-PM distortions, at different frequencies.
[0163] • Frequency tuning of the baseband filters sets the pole-and zero-placement of the filter used in the analog baseband. o The alteration of the pole- and zero-placement affects the pass / in-band ripple and group-delay, the transition between pass- and stop-band, and the dynamic-behavior / range of the filter (assuming an active filter).
[0164] Parameters to enhance / effect the hardware non-idealities, error calibration:
[0165] • Disabling or changing parameters for the Digital Pre-Distortion (DPD). o Enhances some specific distortion components in the transmitter, like IMD, AM-AM, and AM-PM-distortion.
[0166] • Disabling or changing parameters for the cartesian-error calibration system, o Enhances and / or alters the non-linear effects associated with the cartesian / quadrature-error related to the frequency up-converting mixer. The error can be further increased and also the behavior is modified.
[0167] 5 Example Applied to Authentication of a UE
[0168] This is a description of an example implementation of the present solution which describes one possible way of authenticating a UE in relation to a BS using RFF. When a UE wants to connect to the cellular network, it sends a request to the closest BS, and the BS sets up for the initial communication. The choice of frequency band is set by the hardware and operator, the channel between the BS and UE is estimated, and the BS determines that this is first time that this specific UE is connecting to this network. Further, the BS sends the command to start RFF, to send a random data sequence with a 16 Quadrature Amplitude Modulation (QAM) modulation, at a given output power, at peak output power, or at a certain backed-off power. Different random data sequences with 16 QAM modulation are shown in Figure 12. The symbol time (Ts) is the same for both the random data sequences, but they are different statistically, and this randomness is mainly based on the number of constellations points in the modulation, mainly because it is preferred to cross all the constellation points. For the left data sequence, the signal only crosses each constellation point once, in the second data sequence, the signal crosses some constellation points multiple times, and it should also be noted that for the purpose of visual clarity, the constellation points in this example are not crossed between symbol sampling (At<Ts), which could happen in a real-world scenario.
[0169] The modulated data sequence is transmitted by the UE to the BS. Importantly, the non-ideal characteristics of the UE form a part of the transmitted signal. In addition, at the BS, the non-ideal characteristics of the BS receiver, which are assumed to be much smaller compared to the those of the UE, form part of the received signal. In the BS, the received signal is processed in the analog-domain and converted into a digital signal with a given Over-Sampling Ratio (OSR). This signal with all the non-ideal UE transmitter characteristics is stored within the BS. Further, the signal is further processed in the digital domain where the random data sequence is retrieved by a detector / demodulator and is stored within the BS for further use. The stored random data sequence can now be used to generate the ideal modulation of the data sequence, which means that the non-ideal characteristics can be separated from the modulation by subtracting the ideal modulation from the signal with all the UEs non-ideal characteristics . In addition, the separated non-ideal characteristics can now be correlated / mapped to the sequence and / or modulation by the MLE, and this correlated / mapped data can be used for the RFF by the MLE once more modulated data sequences have been transmitted from the UE with, for instance, different output powers. So, the MLE gives the command to the UE through the BS to send the same modulated data sequences (in this example), but with for instance different output powers. The UE complies, and the non-ideal UE characteristics at different output powers are stored. The same holds for the correlation / mapping of the non-ideal characteristics. The random data sequence may still be detected within the BS, if desired.
[0170] Now when enough modulated data sequences have been gathered, the MLE selects points of interest. First, it is the constellation point. These are the same relative coordinates, but at different signal powers. Second, the points of interest also include points where signals have the same coordinates, which also have same signal power, where such points are not of interest for the existing RFF. These crossings may not happen for each transmitted output power. This concept is shown in Figure 13. The main reason for using this method is twofold: the amount of points for RFF is now further increased and the static- and memory-effects of the non-ideal characteristics are different for each point, i.e. when the momentaneous power is different, but also when the momentaneous power is the same. Different carrier frequencies, different frequency offsets, and so on can be used. In these cases, the points of interest will be based on the constellation points and the OSR, since the ideal signals in the constellation diagrams will be the same. However, this gives the frequency dependence of the nonidealities at a given momentaneous power, which gives additional degrees of freedom for the RFF.
[0171] Going forward, the main process for RFF now begins, the MLE starts to predict the behavior of the UE with either a non-clustering approach (e.g., a regression approach) or a cluster-based approach and gives commands to the UE accordingly to converge into a RF fingerprint dataset. The way the MLE works towards the final prediction is by tracking the variance or behavior of the non-ideal characteristics for the different input parameters like UE output power, carrier frequency, frequency offset, the modulation of the random data sequence, and the random data sequence itself, by controlling these variables in a random or quasi-random way. This means, the behavior of non-ideal characteristics can be predicted when a sufficient number training steps have been fulfilled, which in the end means that ML can predict what the non-ideal characteristics should be for a previously not given set (but within the training boundaries) of input parameters of the UE, during RFF authentication. For every challenge of the prediction, the ML algorithm makes a decision and if the prediction has a low relative error, i.e. the relative error is below a given threshold, then a decision is made to stop the RFF process and the authentication is completed. Otherwise, the ML makes the necessary adjustments to the input parameters and makes a new challenge to predict the outcome based on the new input parameters, and the iteration continues until a convergence with low relative error is achieved (i.e. below a given threshold) or if the prediction is far off (related to a second threshold). In the latter case, then the process stops, and the UE is not granted access i.e. the UE is considered fake.
[0172] On a final note, by including more points of interest and not only the constellation points more fingerprinting data can be extracted from a given set of data, and this also means the UE will consume less power during the RFF process. The additional points of interest are coordinates in the constellation diagram where signals cross or are close to each other, and this can be within one signal and / or a signal with different input parameter. Furthermore, when time-dependent input parameter like carrier frequency or frequency offset are used, the same points of interest may be used and signal the continuous signal deviations may be used. By using the most efficient metrics for the RFF, while maximizing the points of interest within a given data sequence, a more efficient RFF process can be achieved.
[0173] 6 Further Details
[0174] Figure 14 illustrates one example of a cellular communications system 1400 in which embodiments of the present disclosure may be implemented. In the embodiments described herein, the cellular communications system 1400 is a 5G system (5GS) including a Next Generation RAN (NG-RAN) and a 5G Core (5GC); however, the cellular communications system 1400 is not limited thereto (e.g., may be a 6thGeneration (6G) system). In this example, the RAN includes base stations 1402-1 and 1402-2, which in the 5GS include NR base stations (gNBs) and optionally next generation eNBs (ng-eNBs) (e.g., LTE radio access nodes connected to the 5GC), controlling corresponding (macro) cells 1404-1 and 1404-2. The base stations 1402-1 and 1402-2 are generally referred to herein collectively as base stations 1402 and individually as base station 1402. Likewise, the (macro) cells 1404-1 and 1404-2 are generally referred to herein collectively as (macro) cells 1404 and individually as (macro) cell 1404. The RAN may also include a number of low power nodes 1406-1 through 1406-4 controlling corresponding small cells 1408-1 through 1408-4. The low power nodes 1406-1 through 1406-4 can be small base stations (such as pico or femto base stations) or RRHs, or the like. Notably, while not illustrated, one or more of the small cells 1408-1 through 1408-4 may alternatively be provided by the base stations 1402. The low power nodes 1406-1 through 1406-4 are generally referred to herein collectively as low power nodes 1406 and individually as low power node 1406. Likewise, the small cells 1408-1 through 1408-4 are generally referred to herein collectively as small cells 1408 and individually as small cell 1408. The cellular communications system 1400 also includes a core network 1410, which in the 5G System (5GS) is referred to as the 5GC. The base stations 1402 (and optionally the low power nodes 1406) are connected to the core network 1410.
[0175] The base stations 1402 and the low power nodes 1406 provide service to wireless communication devices 1412-1 through 1412-5 in the corresponding cells 1404 and 1408. The wireless communication devices 1412-1 through 1412-5 are generally referred to herein collectively as wireless communication devices 1412 and individually as wireless communication device 1412. In the following description, the wireless communication devices 1412 are oftentimes UEs, but the present disclosure is not limited thereto.
[0176] Figure 15 is a schematic block diagram of a radio access node 1500 according to some embodiments of the present disclosure. Optional features are represented by dashed boxes. The radio access node 1500 may be, for example, a base station 1402 or 1406 or a network node that implements all or part of the functionality of a base station as described herein. As illustrated, the radio access node 1500 includes a control system 1502 that includes one or more processors 1504 (e.g., Central Processing Units (CPUs), Application Specific Integrated Circuits (ASICs), Field Programmable Gate Arrays (FPGAs), and / or the like), memory 1506, and a network interface 1508. The one or more processors 1504 are also referred to herein as processing circuitry. In addition, the radio access node 1500 may include one or more radio units 1510 that each includes one or more transmitters 1512 and one or more receivers 1514 coupled to one or more antennas 1516. The radio units 1510 may be referred to or be part of radio interface circuitry. In some embodiments, the radio unit(s) 1510 may be external to the control system 1502 and connected to the control system 1502 via, e.g., a wired connection (e.g., an optical cable). However, in some other embodiments, the radio unit(s) 1510 and potentially the antenna(s) 1516 may be integrated together with the control system 1502. The one or more processors 1504 may operate to provide one or more functions of a radio access node 1500 as described herein. In some embodiments, the function(s) may be implemented in software that is stored, e.g., in the memory 1506 and executed by the one or more processors 1504.
[0177] Figure 16 is a schematic block diagram that illustrates a virtualized embodiment of the radio access node 1500 according to some embodiments of the present disclosure. This discussion is equally applicable to other types of network nodes. Further, other types of network nodes may have similar virtualized architectures. Again, optional features are represented by dashed boxes.
[0178] As used herein, a "virtualized" radio access node is an implementation of the radio access node 1500 in which at least a portion of the functionality of the radio access node 1500 is implemented as a virtual component(s) (e.g., via a virtual machine(s) executing on a physical processing node(s) in a network(s)). As illustrated, in this example, the radio access node 1500 may include the control system 1502 and / or the one or more radio units 1510, as described above. The control system 1502 may be connected to the radio unit(s) 1510 via, for example, an optical cable or the like. The radio access node 1500 includes one or more processing nodes 1600 coupled to or included as part of a network(s) 1602. If present, the control system 1502 or the radio unit(s) are connected to the processing node(s) 1600 via the network 1602. Each processing node 1600 includes one or more processors 1604 (e.g., CPUs, ASICs, FPGAs, and / or the like), memory 1606, and a network interface 1608. In this example, functions 1610 of the radio access node 1500 described herein are implemented at the one or more processing nodes 1600 or distributed across the one or more processing nodes 1600 and the control system 1502 and / or the radio unit(s) 1510 in any desired manner. In some particular embodiments, some or all of the functions 1610 of the radio access node 1500 described herein are implemented as virtual components executed by one or more virtual machines implemented in a virtual environment(s) hosted by the processing node(s) 1600. As will be appreciated by one of ordinary skill in the art, additional signaling or communication between the processing node(s) 1600 and the control system 1502 is used in order to carry out at least some of the desired functions 1610. Notably, in some embodiments, the control system 1502 may not be included, in which case the radio unit(s) 1510 communicate directly with the processing node(s) 1600 via an appropriate network interface(s).
[0179] In some embodiments, a computer program including instructions which, when executed by at least one processor, may cause the at least one processor to carry out the functionality of radio access node 1500 or a node (e.g., a processing node 1600) implementing one or more of the functions 1610 of the radio access node 1500 in a virtual environment according to any of the embodiments described herein is provided. In some embodiments, a carrier comprising the aforementioned computer program product may be provided. The carrier may be one of an electronic signal, an optical signal, a radio signal, or a computer readable storage medium (e.g., a non-transitory computer readable medium such as memory).
[0180] Figure 17 is a schematic block diagram of the radio access node 1500 according to some other embodiments of the present disclosure. The radio access node 1500 includes one or more modules 1700, each of which is implemented in software. The module(s) 1700 provide the functionality of the radio access node 1500 described herein. This discussion is equally applicable to the processing node 1600 of Figure 16 where the modules 1700 may be implemented at one of the processing nodes 1600 or distributed across multiple processing nodes 1600 and / or distributed across the processing node(s) 1600 and the control system 1502.
[0181] Figure 18 is a schematic block diagram of a wireless communication device 1800 according to some embodiments of the present disclosure. As illustrated, the wireless communication device 1800 includes one or more processors 1802 (e.g., CPUs, ASICs, FPGAs, and / or the like), memory 1804, and one or more transceivers 1806 each including one or more transmitters 1808 and one or more receivers 1810 coupled to one or more antennas 1812. The transceiver(s) 1806 includes radio-front end circuitry connected to the antenna(s) 1812 that is configured to condition signals communicated between the antenna(s) 1812 and the processor(s) 1802, as will be appreciated by on of ordinary skill in the art. The processors 1802 are also referred to herein as processing circuitry. The transceivers 1806 are also referred to herein as radio circuitry. In some embodiments, the functionality of the wireless communication device 1800 described above may be fully or partially implemented in software that is, e.g., stored in the memory 1804 and executed by the processor(s) 1802. Note that the wireless communication device 1800 may include additional components not illustrated in Figure 18 such as, e.g., one or more user interface components (e.g., an input / output interface including a display, buttons, a touch screen, a microphone, a speaker(s), and / or the like and / or any other components for allowing input of information into the wireless communication device 1800 and / or allowing output of information from the wireless communication device 1800), a power supply (e.g., a battery and associated power circuitry), etc.
[0182] In some embodiments, a computer program including instructions which, when executed by at least one processor, causes the at least one processor to carry out the functionality of the wireless communication device 1800 according to any of the embodiments described herein may be provided. In some embodiments, a carrier comprising the aforementioned computer program product may be provided. The carrier is one of an electronic signal, an optical signal, a radio signal, or a computer readable storage medium (e.g., a non-transitory computer readable medium such as memory).
[0183] Figure 19 is a schematic block diagram of the wireless communication device 1800 according to some other embodiments of the present disclosure. The wireless communication device 1800 includes one or more modules 1900, each of which is implemented in software. The module(s) 1900 provide the functionality of the wireless communication device 1800 described herein.
[0184] Any appropriate steps, methods, features, functions, or benefits disclosed herein may be performed through one or more functional units or modules of one or more virtual apparatuses. Each virtual apparatus may comprise a number of these functional units. These functional units may be implemented via processing circuitry, which may include one or more microprocessor or microcontrollers, as well as other digital hardware, which may include Digital Signal Processors (DSPs), special-purpose digital logic, and the like. The processing circuitry may be configured to execute program code stored in memory, which may include one or several types of memory such as Read Only Memory (ROM), Random Access Memory (RAM), cache memory, flash memory devices, optical storage devices, etc. Program code stored in memory includes program instructions for executing one or more telecommunications and / or data communications protocols as well as instructions for carrying out one or more of the techniques described herein. In some implementations, the processing circuitry may be used to cause the respective functional unit to perform corresponding functions according to one or more embodiments of the present disclosure.
[0185] While processes in the figures may show a particular order of operations performed by certain embodiments of the present disclosure, it should be understood that such order is exemplary (e.g., alternative embodiments may perform the operations in a different order, combine certain operations, overlap certain operations, etc.).
[0186] Those skilled in the art will recognize improvements and modifications to the embodiments of the present disclosure. All such improvements and modifications are considered within the scope of the concepts disclosed herein.
Claims
Claims1. A method for authenticating aradio equipment in a wireless communication network, the method comprising: o sending (1002; 1100) to a second radio equipment, values for a set of parameters for acquisition of a Radio Frequency, RF, fingerprint for the second radio equipment, the RF fingerprint comprising data characterizing RF impairments induced by specific hardware of the second radio equipment on a signal received from the second radio equipment, the RF impairments being unique to the second radio equipment; o receiving (1002; 1106) a signal from the second radio equipment in response to sending the values for the set of parameters; o obtaining (1004-1006) an actual RF fingerprint of the second radio equipment based on the signal received from the second radio equipment; and o performing (1008) an evaluation of the RF fingerprint of the second radio equipment based on a RF fingerprint dataset of the second radio equipment, the RF fingerprint dataset comprising a RF fingerprints previously obtained for the second radio equipment for a number, N, of different sets of values for the set of parameters where N is less than a total number, NTOTAL, of all different sets of values for the set of parameters.
2. The method of claim 1, further comprising deciding (1010) whether the second radio equipment is authenticated based on a result of the evaluation.
3. The method of claim 1 or 2, further comprising selecting (1000) the values for the set of parameters for acquisition of an RF fingerprint of the second radio equipment.
4. The method of claim 3, wherein selecting (1000) the values for the set of parameters is such that the value of at least one parameter in the set of parameters is randomized.
5. The method of any of claims 1 to 4, wherein the set of parameters comprises any one or more of the following: transmit power at which the second radio equipment transmits the signal; carrier frequency at which the second radio equipment transmits the signal; carrier bandwidth of the carrier on which the second radio equipment transmits the signal.
6. The method of any of claims 1 to 5, wherein the set of parameters comprises any one or more of the following: frequency offset between a baseband frequency and an intermediate frequency used at the second radio equipment when transmitting the signal; frequency offset between an intermediate frequency used at the second radio equipment when transmitting the signal and the carrier frequency at which the second radio equipment transmits the signal; a parameter related to power amplifier biasing at the second radio equipment when transmitting the signal; a parameter related to mixer biasing at the second radio equipment when transmitting the signal; a parameter related to frequency-synthesizer biasing when transmitting the signal; a parameter related to oscillator biasing at the second radio equipment when transmitting the signal; a parameter related to digital-to-analog converter biasing at the second radio equipment when transmitting the signal; a parameter related to tuning the resonance frequency of resonators in the RF transmit chain at the UE when transmitting the signal; a parameter related to tuning of one or more baseband filters at the second radio equipment when transmitting the signal; a parameter related to disabling or changing one or more parameters for digital predistortion at the second radio equipment when transmitting the signal; and a parameter related to disabling or changing one or more parameter for cartesian-error calibration at the second radio equipment when transmitting the signal.
7. The method of any of claims 1 to 6, further comprising: processing (1002; 1108) the signal to provide data about the signal from which the RF fingerprint can be extracted; and wherein obtaining (1004) the RF fingerprint of the second radio equipment comprises extracting (1004) the RF fingerprint of the second radio equipment from the data about the signal.
8. The method of any of claims 1 to 7, wherein performing (1008) the evaluation of the RF fingerprint of the second radio equipment comprises performing (1008) the evaluation of the RF fingerprint based on the RF fingerprint dataset of the UE and a particular machine learning, ML, technique.
9. The method of claim 8, wherein the ML technique is a Principal Component Analysis, PCA, technique, and performing (1008) the evaluation of the RF fingerprint is based on a PCA-transformed version of the RF fingerprint dataset of the UE and a PCA- transformed version of the RF fingerprint of the second radio equipment.
10. The method of claim 9, wherein a result of performing (1008) the evaluation of the RF fingerprint of the second radio equipment comprises a number of standard deviations between the PCA-transformed version of the RF fingerprint of the second radio equipment and a mean of the PCA transformed RF fingerprints comprised in the PCA-transformed version of the RF fingerprint dataset of the second radio equipment.
11. The method of claim 8, wherein the ML technique is a one-class Support Vector Machines, SVM, technique.
12. The method of claim 8, wherein the ML technique is an autoencoder technique.
13. The method of claim 8, wherein the ML technique is clustering-based technique.
14. The method of claim 13, wherein a result of performing (1008) the evaluation of the RF fingerprint of the second radio equipment comprises data about whether the RFfingerprint of the second radio equipment is within a cluster of RF fingerprints identified in the RF fingerprint dataset of the UE identified using the cluster-based technique.
15. The method of any of claims 1 to 14, further comprising creating (900-912) the RF fingerprint dataset for the second radio equipment.
16. The method of claim 15, wherein creating (900-912) the RF fingerprint dataset for the second radio equipment comprises:(a) selecting (900) values for the set of parameters;(b) sending (902) the selected values for the set of to the second radio equipment;(c) receiving (902) a signal from the second radio equipment responsive to sending (902) the selected values for the set of parameters to the second radio equipment;(d) obtaining (906) an RF fingerprint of the second UE for the selected values for the set of parameters;(e) storing (908) the RF fingerprint of the second UE for the selected values of for the set of parameters in the RF fingerprint dataset of the second radio equipment; and(f) repeating (a) - (e) until a predefined stopping criterion is satisfied.
17. The method of any of claims 1 to 16, wherein the steps performed therein are performed by a first radio equipment.
18. The method according to claim 17, wherein the first radio equipment is a network node, and the second radio equipment is a User Equipment, UE.
19. The method according to claim 17, wherein the first radio equipment is a first User Equipment, UE1, and the second radio equipment is a second User Equipment, UE2.
20. A first radio equipment for a wireless communication system for authenticating a radio equipment, the first radio equipment adapted to: send (1002; 1100), from the first radio equipment to a second radio equipment in the wireless communication system, values for a set of parameters for acquisition of a Radio Frequency, RF, fingerprint for the second radio equipment, the RF fingerprint comprising data characterizing RF impairments induced by specific hardware of the second radio equipment on a signal received from the second radio equipment, the RF impairments being unique to the second radio equipment; receive (1002; 1106), at the first radio equipment, a signal from the second radio equipment in response to sending the values for the set of parameters; obtain (1004-1006) an actual RF fingerprint of the second radio equipment based on the signal received from the second radio equipment; and perform (1008) an evaluation of the RF fingerprint of the second radio equipment based on a RF fingerprint dataset of the second radio equipment, the RF fingerprint dataset comprising a RF fingerprints previously obtained for the second radio equipment for a number, N, of different sets of values for the set of parameters where N is less than a total number, NTOTAL, of all different sets of values for the set of parameters.
21. The first radio equipment of claim 20, further adapted to perform the method of any of claims 2 to 18.
22. A computer program comprising instructions which, when executed on at least one processor, cause the processor to carry out the method according to any of claims 1 to 18.
23. A carrier containing the computer program of claim 22, wherein the carrier is one of an electronic signal, an optical signal, a radio signal, or a computer readable storage medium.
24. A non-transitory computer-readable medium comprising instructions executable by processing circuitry of a first radio equipment, whereby the first radio equipment is operable to:send (1002; 1100), from the first radio equipment to a second radio equipment in the wireless communication system, values for a set of parameters for acquisition of a Radio Frequency, RF, fingerprint for the second radio equipment, the RF fingerprint comprising data characterizing RF impairments induced by specific hardware of the second radio equipment on a signal received from the second radio equipment, the RF impairments being unique to the second radio equipment; receive (1002; 1106), at the first radio equipment, a signal from the second radio equipment in response to sending the values for the set of parameters; obtain (1004-1006) an actual RF fingerprint of the second radio equipment based on the signal received from the second radio equipment; and perform (1008) an evaluation of the RF fingerprint of the second radio equipment based on a RF fingerprint dataset of the second radio equipment, the RF fingerprint dataset comprising a RF fingerprints previously obtained for the second radio equipment for a number, N, of different sets of values for the set of parameters where N is less than a total number, NTOTAL, of all different sets of values for the set of parameters.
Citation Information
Patent Citations
Real-time channel-resilient optimization of radio fingerprinting
US11184783B1
Methods, architectures, apparatuses and systems directed to data augmentation of radio frequency (RF) data for improved RF fingerprinting
WO2022187627A1
Radio-frequency-fingerprint-based challenge-response authentication protocol method
CN102904724A
Device and Method for Reliable Classification of Wireless Signals
US20220255775A1